You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助:Ansible Jinja模板中字典内列表的正确展开问题

解决Ansible Jinja模板中字典嵌套列表的展开问题

场景还原

假设你的原始配置、变量、预期输出如下:

原始安全组规则配置

security_rules:
  - name: allow_buildslaves_ssh
    port: 22
    source: "{{ ip_addresses['buildslaves'] }}"
  - name: allow_internal_http
    port: 80
    source: "10.0.0.0/24"

变量定义

ip_addresses:
  buildslaves:
    - "192.168.1.10/32"
    - "192.168.1.11/32"
    - "192.168.1.12/32"

预期生成的安全组规则

- name: allow_buildslaves_ssh
  port: 22
  source: "192.168.1.10/32"
- name: allow_buildslaves_ssh
  port: 22
  source: "192.168.1.11/32"
- name: allow_buildslaves_ssh
  port: 22
  source: "192.168.1.12/32"
- name: allow_internal_http
  port: 80
  source: "10.0.0.0/24"

问题分析

你之前尝试的Jinja模板只是简单遍历security_rules,没有处理source为列表的情况,导致ip_addresses['buildslaves']这个列表被直接当作单个值输出,而非展开成多条独立规则。

解决方案

在模板中增加类型判断:如果source是列表,就嵌套遍历列表中的每个元素生成规则;如果是字符串则直接生成单条规则。

正确的Jinja模板代码

{% for rule in security_rules %}
{% if rule.source is list %}
  {% for ip in rule.source %}
- name: {{ rule.name }}
  port: {{ rule.port }}
  source: "{{ ip }}"
  {% endfor %}
{% else %}
- name: {{ rule.name }}
  port: {{ rule.port }}
  source: "{{ rule.source }}"
{% endif %}
{% endfor %}

说明

  • 使用is list直接判断source类型,逻辑精准(适用于source仅为列表或字符串的场景)。
  • 嵌套循环遍历列表中的每个IP地址,为每个IP生成一条独立的安全组规则。
  • 对于非列表的source(比如单个CIDR),直接生成单条规则,兼容原有逻辑。

如果你的场景中source可能出现元组等其他可迭代类型,可以把判断条件改成rule.source is iterable and rule.source is not string,避免字符串被误判为可迭代对象。

内容的提问来源于stack exchange,提问作者Chandu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 15:15:36