Ansible URI模块调用REST认证接口时出现密码相关错误的原因排查
Let's break down your problems and fix them step by step:
Why You're Seeing These Errors
1. "password not registered error"
This happens because Ansible variable names cannot contain hyphens (-). Your attempt to use {{DD-Old_Password}} is invalid—Ansible interprets hyphens as subtraction operators, so it tries to evaluate DD - Old_Password instead of recognizing it as a single variable name. Since neither DD nor Old_Password are defined in your playbook, you get a "variable not registered" error.
2. "Value of 'password' is empty"
When Ansible can't resolve a variable (like the invalid DD-Old_Password), it passes an empty string as the value. That's why the REST interface receives an empty password field and returns the 400 Bad Request error with code 5437.
Looking at your playbook, you actually have the password stored in the Instance_id variable—but you're hardcoding the password value in the body instead of referencing this variable. That's a separate inconsistency that likely led you to test the invalid DD-Old_Password variable.
Fixed Playbook
Here's the corrected version of your playbook, addressing all issues:
vars: DDVE_public_IP: 34.107.103.175 destination_port: 3009 # Use underscores instead of hyphens for valid, compliant variable names dd_old_password: 8529834022607504819 S3_bucket_name: bucket_for_ddve_6 tasks: - name: Retrieve login access token uri: validate_certs: false url: https://{{ DDVE_public_IP }}:{{ destination_port }}/{{ resource_path }} method: POST # body_format: json automatically sets Content-Type: application/json # No need to manually define this header to avoid redundancy/conflicts body: username: sysadmin # Reference the valid variable correctly to pass the password password: "{{ dd_old_password }}" body_format: json return_content: true register: rest_post vars: resource_path: rest/v1.0/auth
Key Fixes Explained
- Valid Variable Naming: Changed
DD-Old_Passwordtodd_old_password(lowercase with underscores—Ansible variables are case-sensitive, and using lowercase with underscores is a widely accepted best practice). - Correct Variable Reference: Replaced the hardcoded password with a reference to the properly named variable, ensuring the correct value is passed to the REST API.
- Simplified Headers: Removed the manual
Content-Typeheader becausebody_format: jsonautomatically sets this header for you, matching the JSON format of the request body.
Verifying the Fix
After applying these changes, run the playbook again. The URI module will send a valid JSON body with the correct username and password, and you should receive a 200 OK response. The X-DD-AUTH-TOKEN will be available in the registered rest_post variable (accessible via rest_post.x_dd_auth_token for use in subsequent tasks).
内容的提问来源于stack exchange,提问作者Juergen Schubert

