Ansible lineinfile模块insertafter失效:内容被追加至文件末尾
Ansible lineinfile模块插入指定行位置失败问题排查
问题场景
在Ansible Playbook中配置任务,希望将指定行添加到/etc/ssh/sshd_config文件的第17行之后,但执行后该行被追加到文件末尾,而非目标位置。该文件共有41行。
初始任务代码
- name: Add GSSAPIKexAlgorithms in /etc/ssh/sshd_config file lineinfile: path: /etc/ssh/sshd_config line: 'GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-' insertafter: '17' state: present create: true become: true become_method: sudo
执行结果
Protocol 2 ListenAddress 127.0.0.1 ListenAddress 10.224.122.141 SyslogFacility AUTHPRIV LogLevel VERBOSE PermitRootLogin no MaxAuthTries 3 PubkeyAuthentication yes AuthorizedKeysFile .ssh/authorized_keys AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys AuthorizedKeysCommandUser nobody HostbasedAuthentication no IgnoreRhosts yes PermitEmptyPasswords no PasswordAuthentication yes Ciphers=aes256-gcm@openssh.com,chacha20-poly1305@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr MACs=hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,umac-128@openssh.com,hmac-sha2-512 KexAlgorithms=curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha1 HostKeyAlgorithms=ecdsa-sha2-nistp256,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521,ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512,rsa-sha2-512-cert-v01@openssh.com,ssh-rsa,ssh-rsa-cert-v01@openssh.com ChallengeResponseAuthentication no GSSAPIAuthentication no UsePAM yes AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT AcceptEnv LC_IDENTIFIcatION LC_ALL LANGUAGE AcceptEnv XMODIFIERS X11Forwarding no AllowTCPForwarding yes AllowAgentForwarding yes ClientAliveCountMax 0 ClientAliveInterval 900 Banner /etc/issue Subsystem sftp /usr/libexec/openssh/sftp-server DenyGroups service Match User AWS_GDIT_Nessus,AWS_GDIT_Retina,AWS_IP360,nessus_service PasswordAuthentication yes Match Group ansible PasswordAuthentication no GSSAPIAuthentication no KerberosAuthentication no PubkeyAuthentication yes GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512- sh-4.4$
问题原因
Ansible的lineinfile模块中,insertafter参数接受的是正则表达式,而非行号。当设置insertafter: '17'时,模块会在文件中查找匹配字符串17的行,由于目标文件中没有包含纯字符串17的行,模块默认将内容追加到文件末尾。
修正后的任务代码
- name: Add GSSAPIKexAlgorithms in /etc/ssh/sshd_config file lineinfile: path: /etc/ssh/sshd_config line: 'GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-' insertafter: '^.*MACs=hmac-sha2-256' state: present create: true become: true become_method: sudo
修正说明
使用正则表达式^.*MACs=hmac-sha2-256匹配文件中包含MACs=hmac-sha2-256的行,模块会在该行之后插入指定内容,符合预期的位置要求。
完整Ansible Playbook
--- - name: MAC SSH Vulnerability FIX hosts: all tasks: - name: Backing up /etc/ssh/sshd_config shell: cp -prf /etc/ssh/sshd_config /etc/ssh/sshd_config.10-19-23 become: true become_method: sudo - name: Uncomment the CRYPTO_POLICY setting in /etc/sysconfig/sshd file replace: path: /etc/sysconfig/sshd regexp: '# CRYPTO_POLICY=' replace: 'CRYPTO_POLICY=' become: true become_method: sudo - name: Updating ciphers directive in /etc/ssh/sshd_config file lineinfile: path: /etc/ssh/sshd_config regexp: '^Ciphers' line: 'Ciphers=aes256-gcm@openssh.com,chacha20-poly1305@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr' become: true become_method: sudo - name: Updating MACs directive in /etc/ssh/sshd_config file lineinfile: path: /etc/ssh/sshd_config regexp: '^Macs' line: 'MACs=hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,umac-128@openssh.com,hmac-sha2-512' become: true become_method: sudo - name: Add GSSAPIKexAlgorithms in /etc/ssh/sshd_config file lineinfile: path: /etc/ssh/sshd_config line: 'GSSAPIKexAlgorithms=gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-' insertafter: '^.*MACs=hmac-sha2-256' state: present create: true become: true become_method: sudo - name: Updating KexAlgorithms in /etc/ssh/sshd_config file lineinfile: path: /etc/ssh/sshd_config regexp: '^KexAlgorithms' line: 'KexAlgorithms=curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha1' become: true become_method: sudo - name: Updating HostKeyAlgorithms in /etc/ssh/sshd_config file lineinfile: path: /etc/ssh/sshd_config line: 'HostKeyAlgorithms=ecdsa-sha2-nistp256,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521,ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512,rsa-sha2-512-cert-v01@openssh.com,ssh-rsa,ssh-rsa-cert-v01@openssh.com' insertafter: '18' become: true become_method: sudo - name: Restarting sshd service become: yes become_user: root ansible.builtin.service: name: sshd state: restarted
内容的提问来源于stack exchange,提问作者01Tech
相关产品推荐
相关产品推荐

