如何在Nginxinc Ansible Role剧本中生效自定义日志配置?
问题:Nginxinc Ansible Role无法启用自定义日志配置
我通过Ansible Galaxy安装了Nginxinc的Ansible Role,但无法在剧本中启用自定义日志配置。尝试多种方法后,自定义日志格式仍不生效,日志文件的名称和格式还是和默认配置一致。
简化后的剧本
- name: Install NGINX and configure a simple reverse proxy in front of a web server hosts: "{{ host }}" become: true collections: - nginxinc.nginx_core tasks: - name: Install NGINX include_role: name: nginx - name: Configure NGINX include_role: name: nginx_config vars: nginx_config_http_template_enable: true log: # Configure logs format: - name: main escape: default format: | '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer"' '"$http_user_agent" "$http_x_forwarded_for"' access: - path: /var/log/nginx/reverse-access.log format: main if: $loggable error: file: /var/log/nginx/reverse-error.log level: notice format: main nginx_config_http_template: - template_file: http/default.conf.j2 deployment_location: /etc/nginx/conf.d/default.conf config: upstreams: - name: upstr least_conn: true servers: - address: 0.0.0.0:8089 servers: - core: listen ssl http2: - port: 443 ssl_certificate: /etc/letsencrypt/live/service.company.com/fullchain.pem ssl_certificate_key: /etc/letsencrypt/live/service.company.com/privkey.pem locations: - location: /bladash_test/dashboard_test
我试过在剧本中如上配置,也尝试过在模板里配置,但都没用。期望自定义的日志格式和文件名称能按配置生效。
补充排查
我发现有一个默认的nginx.conf配置文件(在molecule示例中)负责日志配置,请问该在哪里覆盖这个配置?
解答
核心问题:日志配置的层级错误
你当前的log变量是作为独立变量存在的,但Nginxinc的nginx_config Role要求日志配置必须嵌套在nginx_config_http_template的config字段下,否则不会被识别并应用到生成的配置文件中。
修正后的剧本片段
调整Configure NGINX任务的变量结构,将日志配置移到nginx_config_http_template.config内部:
- name: Configure NGINX include_role: name: nginx_config vars: nginx_config_http_template_enable: true nginx_config_http_template: - template_file: http/default.conf.j2 deployment_location: /etc/nginx/conf.d/default.conf config: # 将日志配置移到此处,与upstreams、servers同级 log: format: - name: main escape: default format: | '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer"' '"$http_user_agent" "$http_x_forwarded_for"' access: - path: /var/log/nginx/reverse-access.log format: main if: $loggable error: file: /var/log/nginx/reverse-error.log level: notice format: main upstreams: - name: upstr least_conn: true servers: - address: 0.0.0.0:8089 servers: - core: listen ssl http2: - port: 443 ssl_certificate: /etc/letsencrypt/live/service.company.com/fullchain.pem ssl_certificate_key: /etc/letsencrypt/live/service.company.com/privkey.pem locations: - location: /bladash_test/dashboard_test
覆盖默认主配置文件(nginx.conf)
如果需要替换默认的nginx.conf,可以使用Role提供的nginx_config_main_template变量来生成自定义主配置:
# 在Configure NGINX任务的vars中添加以下配置 nginx_config_main_template_enable: true nginx_config_main_template: template_file: main/nginx.conf.j2 # 可使用自定义模板,或直接用config字段定义参数 deployment_location: /etc/nginx/nginx.conf config: user: nginx worker_processes: auto error_log: /var/log/nginx/error.log warn # 按需添加其他主配置参数
验证步骤
- 运行剧本后,检查
/etc/nginx/conf.d/default.conf是否包含自定义的日志格式与路径 - 重启Nginx服务:
systemctl restart nginx - 查看目标日志文件是否生成,格式是否符合预期
内容的提问来源于stack exchange,提问作者Jochen
相关产品推荐
相关产品推荐

