Ansible playbook用curl上传.xml文件遇路径及域名解析问题
问题1:Ansible提示'/tmp/oscap'不是目录(实际目录存在)
可能原因
- Ansible执行用户无该目录的访问权限,导致模块无法识别为有效目录
- 目标路径是软链接,Ansible默认不跟随软链接进行路径检查
- 使用的Ansible模块(如
find/file)参数配置不当,触发误判
解决步骤
- 先验证目标主机上目录的权限与属性:
- name: 检查/tmp/oscap目录信息 command: ls -ld /tmp/oscap register: dir_details - name: 输出目录信息 debug: var: dir_details.stdout - 若为权限问题,修正目录权限:
- name: 修复/tmp/oscap目录权限 file: path: /tmp/oscap state: directory mode: '0755' owner: "{{ ansible_user }}" group: "{{ ansible_user }}" - 若为软链接问题,使用
file模块的follow: yes参数,或直接替换为实际物理路径:- name: 确认/tmp/oscap目录(跟随软链接) file: path: /tmp/oscap state: directory follow: yes
问题2:Ansible中curl命令域名解析失败(CLI执行正常)
可能原因
- Ansible执行环境未加载用户的环境变量(如
.bashrc/.profile),导致DNS配置与CLI不一致 - 目标主机的SELinux/防火墙规则限制了Ansible进程的DNS解析请求
- curl命令在Ansible中执行时未使用完整的系统环境
解决步骤
- 检查目标主机的DNS配置:
- name: 查看目标主机DNS配置 command: cat /etc/resolv.conf register: dns_config - name: 输出DNS配置 debug: var: dns_config.stdout - 执行curl时加载完整用户环境:
- name: 加载环境变量后执行curl上传 shell: | source ~/.bashrc curl -X POST -F "file=@/tmp/oscap/{{ item }}" https://your-upload-domain.com/api args: executable: /bin/bash loop: "{{ lookup('fileglob', '/tmp/oscap/*.xml', wantlist=True) }}" - 临时关闭SELinux测试(若开启):
- name: 检查SELinux状态 command: getenforce register: selinux_state - name: 临时关闭SELinux(仅测试用) command: setenforce 0 when: selinux_state.stdout == 'Enforcing' - 或直接在curl命令中指定DNS服务器:
- name: 指定DNS服务器执行curl上传 command: curl --dns-servers 8.8.8.8 -X POST -F "file=@/tmp/oscap/{{ item }}" https://your-upload-domain.com/api loop: "{{ lookup('fileglob', '/tmp/oscap/*.xml', wantlist=True) }}"
内容的提问来源于stack exchange,提问作者Robert_IT
相关产品推荐
相关产品推荐

