Ansible切换用户创建临时目录失败,仅可修改Playbook求解决方案
Ansible临时目录权限问题解决方案
问题背景
执行Ansible Playbook时,某删除目录任务因临时目录权限/ACL问题失败,且无法修改ansible.cfg,仅能调整Playbook代码。
涉及的Playbook片段
- name: My Playbook hosts: AppServer gather_facts: true become: yes vars: ansible_remote_tmp: "~/.ansible/tmp" ansible_system_tmpdirs: "/var/tmp" tomcat_home: "{{ hostvars[inventory_hostname]['tomcat_home_input'] }}" tasks: ... ... - name: Ensure the target directory is deleted (if it exists) ansible.builtin.file: path: "{{ tomcat_home_item | trim }}/aredeploy" state: absent register: directory_deleted ignore_errors: yes become: true become_user: "{{ become_user_global }}"
第一次执行报错
TASK [Printing final path] ***************************************************** ok: [remhost77] => { "msg": "/root/mydir/package-571-DEV.zip" } TASK [Execute script to download zip artifacts from JFROG] ********************* changed: [remhost77 -> localhost] TASK [Ensure the target directory is deleted (if it exists)] ******************* fatal: [remhost77]: UNREACHABLE! => {"changed": false, "msg": "Failed to create temporary directory.In some cases, you may have been able to authenticate and did not have permissions on the target directory. Consider changing the remote tmp path in ansible.cfg to a path rooted in \"tmp\", for more error information use -vvv. Failed command was: ( umask 77 && mkdir -p \"` echo /var/tmp `\"&& mkdir \"` echo /var/tmp/ansible-tmp-1708940107.5384886-122-272466693207348 `\" && echo ansible-tmp-1708940107.5384886-122-272466693207348=\"` echo /var/tmp/ansible-tmp-1708940107.5384886-122-272466693207348 `\" ), exited with result 2", "unreachable": true} PLAY RECAP ********************************************************************* localhost : ok=1 changed=0 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 remhost77 : ok=18 changed=4 unreachable=1 failed=0 skipped=2 rescued=0 ignored=0
修改临时目录为tmp后的报错
{ "msg": "Failed to set permissions on the temporary files Ansible needs to create when becoming an unprivileged user (rc: 2, err: chmod: ERROR: Different file system ACL types cannot be merged: /tmp/ansible-tmp-1708941960.8785305-121-146387316011020/ chmod: ERROR: Different file system ACL types cannot be merged: /tmp/ansible-tmp-1708941960.8785305-121-146387316011020/AnsiballZ_file.py }). For information on working around this, see https://docs.ansible.com/ansible-core/2.12/user_guide/become.html#risks-of-becoming-an-unprivileged-user", "_ansible_no_log": false }
关键环境信息
- 执行用户
olamuser在目标主机上的其他任务均正常,排除基础权限问题 - 无法修改
ansible.cfg,仅能调整Playbook代码 - 目标主机
/var/tmp目录权限:
wladmin@remhost77$ ls -ld /var/tmp drwxr-xr-x 3 root root 15 Feb 26 03:37 /var/tmp
/var/tmp目录内文件:
wladmin@remhost77$ ls -ltr /var/tmp total 83 -rw------- 1 root root 4351 Mar 11 2022 log4j_findings_unix_dir.sh -rw------- 1 root root 5090 Mar 11 2022 log4j_findings_unix.sh drwx------ 3 root root 3 Feb 23 10:07 BES -rw------- 1 root root 0 Feb 25 02:51 PowerMT -rw------- 1 root root 20 Feb 25 02:53 centrify_issue.flg
解决方案
方案1:为该任务指定专属临时目录
在报错任务中单独设置ansible_remote_tmp为执行用户的私有可写目录,避开系统临时目录的权限/ACL限制:
- name: Ensure the target directory is deleted (if it exists) ansible.builtin.file: path: "{{ tomcat_home_item | trim }}/aredeploy" state: absent register: directory_deleted ignore_errors: yes become: true become_user: "{{ become_user_global }}" vars: ansible_remote_tmp: "~olamuser/.ansible/tmp"
方案2:跳过临时文件权限加固(需环境安全)
通过设置ansible_become_flags让Ansible跳过临时文件的权限修改,避免ACL冲突:
- name: Ensure the target directory is deleted (if it exists) ansible.builtin.file: path: "{{ tomcat_home_item | trim }}/aredeploy" state: absent register: directory_deleted ignore_errors: yes become: true become_user: "{{ become_user_global }}" vars: ansible_become_flags: "-i"
注:-i参数会保留原用户环境变量,仅在确认环境无权限风险时使用。
方案3:改用命令模块绕开临时文件机制
直接使用command模块执行删除命令,完全避开Ansible的临时文件创建流程:
- name: Ensure the target directory is deleted (if it exists) ansible.builtin.command: rm -rf "{{ tomcat_home_item | trim }}/aredeploy" register: directory_deleted ignore_errors: yes become: true become_user: "{{ become_user_global }}"
注:需提前确认路径准确性,避免误删。
内容的提问来源于stack exchange,提问作者Ashar
相关产品推荐
相关产品推荐

