You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible lineinfile模块insertafter失效:内容被追加至文件末尾

Ansible lineinfile模块插入指定行位置失败问题排查

问题场景

在Ansible Playbook中配置任务,希望将指定行添加到/etc/ssh/sshd_config文件的第17行之后,但执行后该行被追加到文件末尾,而非目标位置。该文件共有41行。

初始任务代码

- name: Add GSSAPIKexAlgorithms in /etc/ssh/sshd_config file
  lineinfile:
    path: /etc/ssh/sshd_config
    line: 'GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-'
    insertafter: '17'
    state: present
    create: true
  become: true
  become_method: sudo

执行结果

Protocol 2
ListenAddress 127.0.0.1
ListenAddress  10.224.122.141
SyslogFacility AUTHPRIV
LogLevel VERBOSE
PermitRootLogin no
MaxAuthTries 3
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys
AuthorizedKeysCommandUser nobody
HostbasedAuthentication no
IgnoreRhosts yes
PermitEmptyPasswords no
PasswordAuthentication yes
Ciphers=aes256-gcm@openssh.com,chacha20-poly1305@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr
MACs=hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,umac-128@openssh.com,hmac-sha2-512
KexAlgorithms=curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha1
HostKeyAlgorithms=ecdsa-sha2-nistp256,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521,ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512,rsa-sha2-512-cert-v01@openssh.com,ssh-rsa,ssh-rsa-cert-v01@openssh.com
ChallengeResponseAuthentication no
GSSAPIAuthentication no
UsePAM yes
AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
AcceptEnv LC_IDENTIFIcatION LC_ALL LANGUAGE
AcceptEnv XMODIFIERS
X11Forwarding no
AllowTCPForwarding yes
AllowAgentForwarding yes
ClientAliveCountMax 0
ClientAliveInterval 900
Banner /etc/issue
Subsystem sftp /usr/libexec/openssh/sftp-server
DenyGroups service

Match User AWS_GDIT_Nessus,AWS_GDIT_Retina,AWS_IP360,nessus_service
    PasswordAuthentication yes
Match Group ansible
    PasswordAuthentication no
    GSSAPIAuthentication no
    KerberosAuthentication no
    PubkeyAuthentication yes
GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-
sh-4.4$

问题原因

Ansible的lineinfile模块中,insertafter参数接受的是正则表达式,而非行号。当设置insertafter: '17'时,模块会在文件中查找匹配字符串17的行,由于目标文件中没有包含纯字符串17的行,模块默认将内容追加到文件末尾。

修正后的任务代码

- name: Add GSSAPIKexAlgorithms in /etc/ssh/sshd_config file
  lineinfile:
    path: /etc/ssh/sshd_config
    line: 'GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-'
    insertafter: '^.*MACs=hmac-sha2-256'
    state: present
    create: true
  become: true
  become_method: sudo

修正说明

使用正则表达式^.*MACs=hmac-sha2-256匹配文件中包含MACs=hmac-sha2-256的行,模块会在该行之后插入指定内容,符合预期的位置要求。

完整Ansible Playbook

---
- name: MAC SSH Vulnerability FIX
  hosts: all
  tasks:
    - name: Backing up /etc/ssh/sshd_config
      shell: cp -prf /etc/ssh/sshd_config /etc/ssh/sshd_config.10-19-23
      become: true
      become_method: sudo

    - name: Uncomment the CRYPTO_POLICY setting in /etc/sysconfig/sshd file
      replace:
        path: /etc/sysconfig/sshd
        regexp: '# CRYPTO_POLICY='
        replace: 'CRYPTO_POLICY='
      become: true
      become_method: sudo

    - name: Updating ciphers directive in /etc/ssh/sshd_config file
      lineinfile:
        path: /etc/ssh/sshd_config
        regexp: '^Ciphers'
        line: 'Ciphers=aes256-gcm@openssh.com,chacha20-poly1305@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr'
      become: true
      become_method: sudo

    - name: Updating MACs directive in /etc/ssh/sshd_config file
      lineinfile:
        path: /etc/ssh/sshd_config
        regexp: '^Macs'
        line: 'MACs=hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,umac-128@openssh.com,hmac-sha2-512'
      become: true
      become_method: sudo

    - name: Add GSSAPIKexAlgorithms in /etc/ssh/sshd_config file
      lineinfile:
        path: /etc/ssh/sshd_config
        line: 'GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-'
        insertafter: '^.*MACs=hmac-sha2-256'
        state: present
        create: true
      become: true
      become_method: sudo

    - name: Updating KexAlgorithms in /etc/ssh/sshd_config file
      lineinfile:
        path: /etc/ssh/sshd_config
        regexp: '^KexAlgorithms'
        line: 'KexAlgorithms=curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha1'
      become: true
      become_method: sudo

    - name: Updating HostKeyAlgorithms in /etc/ssh/sshd_config file
      lineinfile:
        path: /etc/ssh/sshd_config
        line: 'HostKeyAlgorithms=ecdsa-sha2-nistp256,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521,ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512,rsa-sha2-512-cert-v01@openssh.com,ssh-rsa,ssh-rsa-cert-v01@openssh.com'
        insertafter: '18'
      become: true
      become_method: sudo

    - name: Restarting sshd service
      become: yes
      become_user: root
      ansible.builtin.service: 
        name: sshd 
        state: restarted

内容的提问来源于stack exchange,提问作者01Tech

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 20:57:33