Ansible安装Kibana插件幂等性测试失败求助(含--check模式)
解决Kibana插件安装Ansible任务的幂等性失败问题
问题背景
编写了一个用于安装Kibana插件的Ansible任务,配置了changed_when语句,playbook运行在--check mode下且要求满足幂等性,但每次都会触发“Idempotency failure for test $name”报错。
任务代码
- name: Install kibana plugins command: "/usr/share/kibana/bin/kibana-plugin install {{ name_of_plugin }} --allow-root" register: InstallingPluginsResult changed_when: InstallingPluginsResult.stdout is search("Extraction complete") tags: - kibana-plugins
任务执行输出
TASK [kibana : Install kibana plugins ] *************************** Thursday 16 March 2023 11:57:56 +0000 (0:00:00.043) 0:01:27.698 ******** changed: [localhost] => {"changed": true, "cmd": ["/usr/share/kibana/bin/kibana-plugin", "install", "https://repo.xxxx.zip", "--allow-root"], "delta": "0:00:04.902068", "end": "2023-03-16 11:58:01.359526", "msg": "", "rc": 0, "start": "2023-03-16 11:57:56.457458", "stderr": "", "stderr_lines": [], "stdout": "Attempting to transfer from https://repos.xxxx.zip\nTransferring 30732982 bytes....................\nTransfer complete\nRetrieving metadata from plugin archive\nExtracting plugin archive\nExtraction complete\nPlugin installation complete", "stdout_lines": ["Attempting to transfer from https://repos.xxxx.zip", "Transferring 30732982 bytes....................", "Transfer complete", "Retrieving metadata from plugin archive", "Extracting plugin archive", "Extraction complete", "Plugin installation complete"]}
最终失败信息
Idempotence test ${test_name}: fail Failure for test ${test_name} Cleaning up project directory and file based variables ERROR: Job failed: command terminated with exit code 42
GitLab CI测试配置
# check_mode + normal run + idempotence - > for something in $test ; do echo "Testing check_mode with tag $something" && ansible-playbook tests/test.yml --check -v --diff --tags "test,$something" -e tag="$something" && echo "Currently testing with tag $something" && (ansible-playbook tests/test.yml -v --diff --tags "test,$something" -e tag="$something" || (pgrep --list-full node ; ss -ant ;echo "Run $something: fail"; exit 2)) && echo "Testing idempotence with tag $something" && ((set +o pipefail ; ansible-playbook tests/test.yml -v -- diff --tags "test,$something" -e tag="$something" -e idempotency=True | tee idempotence.log | grep -qE 'changed=0.*failed=0') && (echo "Idempotence test $something: pass" && exit 0) || (cat idempotence.log && echo "Idempotence test $something: fail" && exit 1)) || (echo "Failure for test $something" && exit 3) || exit 42 ; done
问题原因与修复方案
问题根源
- 不管插件是否已安装,执行
kibana-plugin install命令都会输出包含“Extraction complete”的内容,导致changed_when始终判定为true,二次执行仍标记为changed,触发幂等性检查失败。 --check mode下command模块默认不执行实际命令,InstallingPluginsResult变量为空,会导致changed_when判断逻辑出错。
修复后的任务代码
- name: 获取已安装的Kibana插件列表 command: "/usr/share/kibana/bin/kibana-plugin list --allow-root" register: installed_plugins changed_when: false check_mode: false - name: 安装Kibana插件 command: "/usr/share/kibana/bin/kibana-plugin install {{ name_of_plugin }} --allow-root" register: install_result changed_when: "'Extraction complete' in install_result.stdout" when: name_of_plugin not in installed_plugins.stdout tags: - kibana-plugins
针对URL形式插件的优化
如果插件通过URL安装(如示例中的https://repo.xxxx.zip),建议提取插件名称避免URL变化导致误判:
- name: 从URL中提取插件名称 set_fact: plugin_name: "{{ name_of_plugin | urlsplit('path') | basename | regex_replace('\\.zip$', '') }}" when: name_of_plugin is match('^https?://') - name: 获取已安装的Kibana插件列表 command: "/usr/share/kibana/bin/kibana-plugin list --allow-root" register: installed_plugins changed_when: false check_mode: false - name: 安装Kibana插件 command: "/usr/share/kibana/bin/kibana-plugin install {{ name_of_plugin }} --allow-root" register: install_result changed_when: "'Extraction complete' in install_result.stdout" when: plugin_name not in installed_plugins.stdout tags: - kibana-plugins
修改后,第一次执行会安装插件并标记为changed,第二次执行时因插件已存在会跳过安装命令,确保changed=0满足幂等性要求;同时check_mode下会执行插件列表查询,正确判断是否需要安装。
内容的提问来源于stack exchange,提问作者Ciocoiu Petrisor
相关产品推荐
相关产品推荐

