如何修改Ansible user模块手动指定UID后的自动分配行为
问题
按以下步骤创建三个用户:
- 由Ansible自动分配合适UID创建testuserone;
- 手动指定UID为2000创建testusertwo;
- 创建testuserthree,期望其UID从1001开始自动分配,但实际得到2001(这是useradd的默认行为)。
请问无需模块补丁或非常规技巧,能否让ansible.builtin.user模块像adduser那样从低UID范围继续递增分配?
演示任务
- name: Testuser01 ansible.builtin.user: name: "testuserone" comment: "Created by Ansible" state: present - name: Testuser02 ansible.builtin.user: name: "testusertwo" uid: "2000" comment: "Created by Ansible" state: present - name: Testuser03 ansible.builtin.user: name: "testuserthree" comment: "Created by Ansible" state: present
实际结果
testuserone:x:1000:1000:Created by Ansible testusertwo:x:2000:2000:Created by Ansible testuserthree:x:2001:2001:Created by Ansible
预期结果
testuserone:x:1000:1000:Created by Ansible testusertwo:x:2000:2000:Created by Ansible testuserthree:x:1001:1001:Created by Ansible
解决方案
可以实现,核心思路是主动查询普通用户UID范围(默认从1000开始)内的最小可用UID,然后手动指定给ansible.builtin.user模块,替代useradd默认取当前最大UID加1的逻辑。
具体实现步骤如下:
- 读取系统所有用户的UID信息;
- 筛选出普通用户范围内(1000~65535)未被使用的UID,取其中最小的一个;
- 创建testuserthree时指定这个UID。
修改后的Playbook示例:
- name: 获取系统所有用户信息 ansible.builtin.getent: database: passwd register: passwd_data - name: 计算普通用户范围中最小的可用UID ansible.builtin.set_fact: next_free_uid: "{{ range(1000, 65536) | difference(passwd_data.entries | map(attribute='1') | list | map('int')) | first }}" - name: Testuser01 ansible.builtin.user: name: "testuserone" comment: "Created by Ansible" state: present - name: Testuser02 ansible.builtin.user: name: "testusertwo" uid: "2000" comment: "Created by Ansible" state: present - name: Testuser03 ansible.builtin.user: name: "testuserthree" uid: "{{ next_free_uid }}" comment: "Created by Ansible" state: present
说明
- 用
getent模块读取系统passwd数据库,确保能获取所有用户的UID; - 通过Ansible的
range和difference过滤器,找出1000到65535范围内未被使用的UID,first取最小的那个; - 该方法完全依赖Ansible内置模块和过滤器,无需补丁或非常规操作,和adduser的逻辑一致:优先从低UID范围分配可用ID。
内容的提问来源于stack exchange,提问作者Sefer
相关产品推荐
相关产品推荐

