如何使用Ansible创建和编辑文件及Ansible角色创建sddm.conf文件失败问题求助
我来帮你搞定这个坑——你遇到的情况其实挺典型的,用shell模块直接写系统文件时,很容易因为一些细节问题导致「Ansible说成功但实际没文件」的情况。咱们先拆解问题,再给你靠谱的解决方案:
首先,你的原始任务为啥没生成文件?
最可能的核心问题是here-doc的结束标记格式不对:
你在shell模块里用了cat <<EOF >/etc/sddm.conf,但最后那个EOF前面加了缩进(和上面的配置内容对齐了)。在bash里,here-doc的结束标记必须顶格写,不能有任何前置空格或缩进,否则bash会认为还在读取输入,不会终止cat命令,自然也就不会生成文件。
另外还有个容易忽略的点:/etc/sddm.conf是系统级文件,需要root权限才能写入,如果你的任务没加become: yes,即使命令看起来执行了,实际也会因为权限不足悄悄失败。
修复方案1:修正shell模块的格式
如果一定要用shell模块,把结束的EOF顶格写,同时加上become: yes获取root权限:
- name: sddm.conf erstellen become: yes shell: | cat <<EOF >/etc/sddm.conf [Autologin] # Whether sddm should automatically log back into sessions when they exit Relogin=false # Name of session file for autologin session (if empty try last logged in) Session= # Username for autologin session User= [General] # Halt command HaltCommand=/bin/systemctl poweroff # Input method module InputMethod=compose # Initial NumLock state. Can be on, off or none. # If property is set to none, numlock won't be changed # NOTE: Currently ignored if autologin is enabled. Numlock=none # Reboot command RebootCommand=/bin/systemctl reboot [Theme] # Current theme name Current=maldives # Cursor theme used in the greeter CursorTheme= # Number of users to use as threshold # above which avatars are disabled # unless explicitly enabled with EnableAvatars DisableAvatarsThreshold=7 # Enable display of custom user avatars EnableAvatars=true # Global directory for user avatars # The files should be named <username>.face.icon FacesDir=/usr/share/sddm/faces # Theme directory path ThemeDir=/usr/share/sddm/themes [Users] # Default $PATH for logged in users DefaultPath=/bin:/usr/bin EOF
注意最后一行的EOF是完全顶格的,没有任何空格。
更推荐的方案2:使用Ansible的copy模块(最佳实践)
其实用shell模块写文件是不太符合Ansible的设计理念的,Ansible专门提供了copy模块来管理文件,更可靠、更易维护,还能自动检查文件状态(只有内容变化时才会执行修改)。
把你的任务换成下面这样:
- name: 创建并配置sddm.conf become: yes copy: dest: /etc/sddm.conf content: | [Autologin] # Whether sddm should automatically log back into sessions when they exit Relogin=false # Name of session file for autologin session (if empty try last logged in) Session= # Username for autologin session User= [General] # Halt command HaltCommand=/bin/systemctl poweroff # Input method module InputMethod=compose # Initial NumLock state. Can be on, off or none. # If property is set to none, numlock won't be changed # NOTE: Currently ignored if autologin is enabled. Numlock=none # Reboot command RebootCommand=/bin/systemctl reboot [Theme] # Current theme name Current=maldives # Cursor theme used in the greeter CursorTheme= # Number of users to use as threshold # above which avatars are disabled # unless explicitly enabled with EnableAvatars DisableAvatarsThreshold=7 # Enable display of custom user avatars EnableAvatars=true # Global directory for user avatars # The files should be named <username>.face.icon FacesDir=/usr/share/sddm/faces # Theme directory path ThemeDir=/usr/share/sddm/themes [Users] # Default $PATH for logged in users DefaultPath=/bin:/usr/bin owner: root group: root mode: '0644'
这个配置会直接把content里的内容写入/etc/sddm.conf,同时设置正确的权限和属主,完全避免了shell命令的各种坑。
最后验证一下
不管用哪种方案,执行完后可以加个任务验证文件是否存在:
- name: 验证sddm.conf是否存在 stat: path: /etc/sddm.conf register: sddm_conf_stat failed_when: not sddm_conf_stat.stat.exists
这样如果文件没生成,Ansible会直接报错,方便你排查问题。
内容的提问来源于stack exchange,提问作者user13876146

