You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWX升级后Jinja2模板循环无法读取变量属性的问题

问题:AWX升级后Jinja2模板无法读取WinUpdates变量属性

版本信息

升级前

  • AWX: 19.4.0
  • AWX-EE: 0.6.0

升级后

  • AWX: 21.11.0
  • AWX-EE: 21.11.0

问题现象

升级后执行send_report_mail角色的Template Rendering任务时,触发如下错误:

AnsibleUndefinedVariable: 'ansible.utils.unsafe_proxy.AnsibleUnsafeText object' has no attribute 'kb'

该流程在旧版本环境下运行正常;尝试切换至最新版或21.12.0版AWX-EE时,又出现credssp: requests auth method is credssp, but requests-credssp is not installed错误。

相关代码片段

winupdates_deploy角色(注册更新结果)

---
# Installation of Windows Updates
- name: Install Windows Updates
  ignore_errors: yes
  ansible.windows.win_updates:
    category_names: "{{ categorylist }}"
    accept_list:  "{{ accepted_kb }}"
    reject_list: "{{ rejected_kb }}"
    reboot: no
    state: installed
    log_path: "{{ loglocation }}\awxlog_winupdates_{{ report_type }}.txt"
  register: list_of_updates

list_of_updates变量结构示例

{
  "list_of_updates": {
    "changed": false,
    "reboot_required": false,
    "found_update_count": 1,
    "failed_update_count": 0,
    "installed_update_count": 0,
    "updates": {
      "88569462-c620-4437-9d8f-baeea24ca37e": {
        "title": "Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.383.1098.0)",
        "kb": ["2267602"],
        "categories": ["Definition Updates", "Microsoft Defender Antivirus"],
        "id": "88569462-c620-4437-9d8f-baeea24ca37e",
        "downloaded": false,
        "installed": false
      }
    },
    "filtered_updates": {
      "8e212273-94f0-4b31-8bb5-00676a5423f4": {
        "title": "Windows Malicious Software Removal Tool x64 - v5.110 (KB890830)",
        "kb": ["890830"],
        "categories": ["Update Rollups", "Windows Server 2016", "Windows Server 2019"],
        "id": "8e212273-94f0-4b31-8bb5-00676a5423f4",
        "downloaded": false,
        "installed": false,
        "filtered_reason": "category_names",
        "filtered_reasons": ["category_names"]
      }
    },
    "failed": false
  },
  "_ansible_verbose_always": true,
  "_ansible_no_log": false,
  "changed": false
}

Jinja2模板片段(individual_vm_report.html.j2)

...
        <tr>
            <td>{{ inventory_hostname }}</td>
            <td>{{ list_of_updates.found_update_count }} </td>
            <td>
               <ul>
{% for win_update in list_of_updates.updates %}
                  <li>{{ win_update.kb }}</li>
{% endfor %}
               </ul>
            </td>
            <td>
               <ul>
{% for win_update in list_of_updates.updates %}
                  <li>{{ win_update.title }}</li>
{% endfor %}
               </ul>
            </td>
            <td>
               <ul>
{% for win_update in list_of_updates.updates %}
                  <li>{{ win_update.installed }}</li>
{% endfor %}
               </ul>
            </td>
            <td><font color="red">{{ report_comment }} </font></td>
         </tr>
...

问题分析

新版本Ansible/AWX中,直接遍历字典(如list_of_updates.updates)时,默认仅返回字典的key值(即更新ID字符串),而非对应的value对象。这导致模板中的win_update变为字符串类型,自然不存在kb、title等属性,触发报错。旧版本AWX/EE可能默认遍历字典的value,或有不同的变量处理逻辑,因此之前能正常运行。

解决方案

1. 修改Jinja2模板遍历逻辑

将模板中遍历list_of_updates.updates的代码改为以下两种方式之一:

方法一:遍历字典的values(推荐)

...
{% for win_update in list_of_updates.updates.values() %}
                  <li>{{ win_update.kb }}</li>
{% endfor %}
...
{% for win_update in list_of_updates.updates.values() %}
                  <li>{{ win_update.title }}</li>
{% endfor %}
...
{% for win_update in list_of_updates.updates.values() %}
                  <li>{{ win_update.installed }}</li>
{% endfor %}
...

方法二:通过key获取对应value

...
{% for update_id in list_of_updates.updates %}
                  <li>{{ list_of_updates.updates[update_id].kb }}</li>
{% endfor %}
...
{% for update_id in list_of_updates.updates %}
                  <li>{{ list_of_updates.updates[update_id].title }}</li>
{% endfor %}
...
{% for update_id in list_of_updates.updates %}
                  <li>{{ list_of_updates.updates[update_id].installed }}</li>
{% endfor %}
...

2. 解决credssp依赖缺失问题

若需使用新版本AWX-EE,可通过以下方式解决requests-credssp缺失问题:

  • 自定义AWX-EE镜像,在Dockerfile中添加pip install requests-credssp命令;
  • 在Playbook的pre_tasks中临时安装依赖(需确保EE具备pip权限):
- name: Install requests-credssp
  pip:
    name: requests-credssp
    state: present
  delegate_to: localhost
  run_once: yes

内容的提问来源于stack exchange,提问作者Phil81

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 04:45:00