如何使用Ansible修改JSON文件中指定用户的密码?
Ansible修改JSON中admin用户密码的完整实现方案
需求说明
首次编写Ansible代码处理JSON数据,/home/目录下存在conf.json文件,包含acl、groups、users等字段。需要修改users数组内name为admin的用户的password字段,将更新后的JSON文件保存到/home/location目录,文件名以_updated.json为后缀。已完成读取JSON文件的部分代码,寻求完整实现方案。
输入JSON示例
{ "acl": [ { "browse": true, "create": false }, { "browse": false, "create": true } ], "groups": [ { "name": "abc", "location": "texas" }, { "name": "def", "location": "austin" } ], "users": [ { "name": "admin", "description": "administrator", "password": "windows2011" }, { "name": "testuser", "description": "guest", "password": "testpassword" } ] }
期望输出JSON示例
{ "acl": [ { "browse": true, "create": false }, { "browse": false, "create": true } ], "groups": [ { "name": "abc", "location": "texas" }, { "name": "def", "location": "austin" } ], "users": [ { "name": "admin", "description": "administrator", "password": "updatedpassword" }, { "name": "testuser", "description": "guest", "password": "testpassword" } ] }
现有代码片段
--- - name: Update admin user password in JSON file hosts: localhost gather_facts: no tasks: - name: Read the JSON file ansible.builtin.command: cmd: cat /home/conf.json register: json_content
完整实现代码
推荐使用Ansible原生模块完成,比直接用cat更规范可靠:
--- - name: Update admin user password in JSON file hosts: localhost gather_facts: no vars: src_json_path: "/home/conf.json" dest_dir: "/home/location" new_admin_password: "updatedpassword" dest_json_suffix: "_updated.json" tasks: # 创建目标目录(如果不存在) - name: Ensure destination directory exists ansible.builtin.file: path: "{{ dest_dir }}" state: directory mode: '0755' # 读取JSON文件(用slurp替代command cat,支持权限和特殊字符处理) - name: Read source JSON file ansible.builtin.slurp: path: "{{ src_json_path }}" register: slurped_json # 将读取内容解析为JSON对象 - name: Parse JSON content ansible.builtin.set_fact: parsed_json: "{{ slurped_json.content | b64decode | from_json }}" # 更新admin用户的password字段 - name: Update admin user password ansible.builtin.set_fact: updated_json: > {{ parsed_json | combine( { 'users': parsed_json.users | map('combine', {'password': new_admin_password} if item.name == 'admin' else {}) | list } ) }} # 生成目标文件名(原文件名+_updated.json) - name: Set destination JSON filename ansible.builtin.set_fact: dest_json_path: "{{ dest_dir }}/{{ src_json_path | basename | regex_replace('\\.json$', dest_json_suffix) }}" # 将更新后的JSON写入目标文件 - name: Write updated JSON to file ansible.builtin.copy: content: "{{ updated_json | to_nice_json }}" dest: "{{ dest_json_path }}" mode: '0644'
代码说明
- slurp模块:替代
command: cat,以base64格式读取文件内容,避免权限或特殊字符问题,再通过b64decode解码后用from_json转为JSON对象。 - 更新逻辑:使用
combine过滤器遍历users数组,仅对name为admin的用户替换password字段,其他用户保持原样。 - 目标文件名处理:通过
basename获取原文件名,用regex_replace替换后缀为_updated.json,保证文件名符合要求。 - 目录创建:提前创建目标目录,避免写入时因目录不存在报错。
内容的提问来源于stack exchange,提问作者exceed007
相关产品推荐
相关产品推荐

