You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible Playbook下载CrowdStrike传感器报错求助:列表无元素0

Ansible Playbook下载CrowdStrike传感器报错:列表对象无元素0

错误信息

TASK [CrowdStrike Falcon | Download Falcon Sensor Installation Package] ************************************************************************************
fatal: [localhost]: FAILED! => {"msg": "The task includes an option with an undefined variable. The error was: list object has no element 0\n\nThe error appears to be in '/var/log/download3.yml': line 131, column 7, but may\nbe elsewhere in the file depending on the exact syntax problem.\n\nThe offending line appears to be:\n\n\n    - name: CrowdStrike Falcon | Download Falcon Sensor Installation Package\n      ^ here\n"}

问题相关代码

Ansible Playbook(需补充falcon_client_id和falcon_client_secret)

---
- hosts: localhost

  vars:

    falcon_api_url1: "https://api.us-2.crowdstrike.com"
    ##falcon_cloud: "api.crowdstrike.com"
    falcon_cloud: "https://api.us-2.crowdstrike.com"
    falcon_oauth2_token_url: "https://api.us-2.crowdstrike.com/oauth2/token"
    falcon_os_family: "{{ ansible_system | lower }}"
    falcon_target_os: "{{ ansible_distribution }}"
    falcon_os_version: "{{ ansible_distribution_major_version }}"
    falcon_install_tmp_dir: "/tmp"
    falcon_install_temp_directory: "/var/deploy/roles/crowdstrike/tasks"
    falcon_client_id: ""
    falcon_client_secret: ""
    falcon_sensor_update_policy_name: ""
    falcon_sensor_version_decrement: 0
    falcon_sensor_version: ""

  tasks:

    - name: Set fact for api url
      set_fact:
        falcon_api_url: "{{ falcon_api_url1 }}"
        falcon_oauth2_token_url: "{{ falcon_oauth2_token_url }}"
        falcon_os_family: "{{ falcon_os_family }}"
        falcon_target_os: "{{ falcon_target_os }}"
        falcon_install_tmp_dir: "{{ falcon_install_tmp_dir }}"
        falcon_client_id: "{{ falcon_client_id }}"

    - name: Show Fact
      debug:
        var: hostvars[inventory_hostname]

    - name: CROWDSTRIKE - AUTHENTICATE API
      ansible.builtin.uri:
        url: "{{ falcon_oauth2_token_url | d(falcon_api_url + '/oauth2/token') }}"
        return_content: yes
        method: POST
        body_format: form-urlencoded
        status_code: 201
        body:
          client_id: "{{ falcon_client_id }}"
          client_secret: "{{ falcon_client_secret }}"
      register: oauth_request

    ##- name: CrowdStrike Falcon | Get list of installers
    ##  uri:
    ##    url: "https://{{ falcon_api_url }}/sensors/combined/installers/v1?filter=platform%3A%22{{ falcon_os_family }}*%22%2Bos%3A%22{{ falcon_target_os }}%22&=&sort=version.desc"
        ##method: GET
        ##return_content: true
        ##headers:
          ##authorization: "Bearer {{ falcon_oauth2_token_url.json.access_token }}"
      ##register: falcon_api_installer_list

    - name: CrowdStrike Falcon | Filter to installers for OS major version
      set_fact:
        falcon_api_sha_hash: "{{ falcon_api_installer_list.json.resources | selectattr('os_version', 'equalto', ansible_distribution_major_version | list ) }}"

    - name: "CrowdStrike Falcon | Default Operating System configuration"
      ansible.builtin.set_fact:
        falcon_target_os: "{{ ansible_distribution }}"
        falcon_os_family: "{{ ansible_system | lower }}"
        falcon_os_version: "{{ ansible_distribution_major_version }}"
        falcon_sensor_update_policy_platform: "{{ ansible_system }}"
        falcon_os_vendor: "{{ ansible_os_family | lower if (ansible_os_family == 'RedHat' and ansible_distribution != 'Amazon') else ansible_distribution | lower }}"

    # Block when falcon_sensor_update_policy_name is supplied
    - name: Sensor Update Policy Block
      block:
        - name: "CrowdStrike Falcon | Build Sensor Update Policy API Query"
          ansible.builtin.set_fact:
            falcon_sensor_update_policy_query: "{{ 'platform_name:\"' + falcon_sensor_update_policy_platform + '\"+name.raw:\"' + falcon_sensor_update_policy_name + '\"' }}"

    - name: CrowdStrike Falcon | Authenticate to CrowdStrike API
      ansible.builtin.uri:
        url: "https://{{ falcon_cloud }}/oauth2/token"
        method: POST
        body_format: json
        body:
          "client_id={{ falcon_client_id }}&client_secret={{ falcon_client_secret }}"
        return_content: true
        follow_redirects: all
        status_code: 201
        headers:
          content-type: application/x-www-form-urlencoded
      register: falcon_api_oauth2_token
      ##no_log: "{{ falcon_api_enable_no_log }}"

    - name: Show fact falcon_api_oauth2_token
      debug:
        var: falcon_api_oauth2_token

    - name: "CrowdStrike Falcon | Build Sensor Update Policy API Query"
      ansible.builtin.set_fact:
        falcon_sensor_update_policy_query: "{{ 'platform_name:\"' + falcon_sensor_update_policy_platform + '\"+name.raw:\"' + falcon_sensor_update_policy_name + '\"' }}"

    ##- name: "CrowdStrike Falcon | Build API Sensor Query based on Sensor Update Policy"
      ##ansible.builtin.set_fact:
        ##falcon_os_query: "{{ 'os:\"' + falcon_target_os + '\"+os_version:\"' + falcon_os_version + '\"+version:\"' }}"

    - name: "CrowdStrike Falcon | Build API Query"
      set_fact:
        falcon_os_query: "{{ 'os:\"' + falcon_target_os + '\"+os_version:\"' + falcon_os_version + '\"' }}"

    - name: CrowdStrike Falcon | Get list of filtered Falcon sensors
      uri:
        url: "https://{{ falcon_cloud }}/sensors/combined/installers/v1?filter={{ falcon_os_query | urlencode }}"
        method: GET
        return_content: true
        headers:
          authorization: "Bearer {{ falcon_api_oauth2_token.json.access_token }}"
          Content-Type: application/json
      register: falcon_api_installer_list

    - name: Show Fact
      debug:
        var: falcon_api_installer_list

    - name: CrowdStrike Falcon | Filter to installers for OS major version
      set_fact:
        falcon_api_sha_hash: "{{ falcon_api_installer_list.json.resources | selectattr('os_version', 'equalto', ansible_distribution_major_version ) }}"

    - name: Show Fact
      debug:
        var: falcon_api_installer_list.json.resources

    - name: CrowdStrike Falcon | Download Falcon Sensor Installation Package
      ansible.builtin.get_url:
        url: "https://{{ falcon_cloud }}/sensors/entities/download-installer/v1?id={{ falcon_api_installer_list.json.resources[falcon_sensor_version_decrement | int].sha256 }}"
        dest: "{{ falcon_install_temp_directory.path }}"
        checksum: "sha256:{{ falcon_api_installer_list.json.resources[falcon_sensor_version_decrement | int].sha256 }}"
        mode: 0640
        headers:
          authorization: "Bearer {{ falcon_api_oauth2_token.json.access_token }}"
      changed_when: false
      register: falcon_sensor_download
      ##no_log: "{{ falcon_api_enable_no_log }}"

API返回的falcon_api_installer_list内容

{
    "falcon_api_installer_list": {
        "changed": false,
        "connection": "close",
        "content": "{\n \"meta\": {\n  \"query_time\": 0.096845979,\n  \"powered_by\": \"binserv\",\n  \"trace_id\": \".......\"\n },\n \"errors\": [],\n \"resources\": []\n}",
        "content_length": "159",
        "content_type": "application/json",
        "cookies": {},
        "cookies_string": "",
        "date": "Fri, 23 Sep 2022 02:56:28 GMT",
        "elapsed": 0,
        "failed": false,
        "json": {
            "errors": [],
            "meta": {
                "powered_by": "binserv",
                "query_time": 0.096845979,
                "trace_id": "........"
            },
            "resources": []
        },
        "msg": "OK (159 bytes)",
        "redirected": false,
        "server": "nginx",
        "status": 200,
        "strict_transport_security": "max-age=15724800; includeSubDomains, max-age=31536000; includeSubDomains",
        "url": "https://api.us-2.crowdstrike.com/sensors/combined/installers/v1?filter=os%3A%22CentOS%22%2Bos_version%3A%227%22",
        "x_cs_region": "us-2",
        "x_cs_traceid": ".........",
        "x_ratelimit_limit": "6000",
        "x_ratelimit_remaining": "5999"
    }
}

根本原因

从API返回结果可以明确看到,falcon_api_installer_list.json.resources是一个空数组[]。而下载任务中直接通过索引falcon_api_installer_list.json.resources[falcon_sensor_version_decrement | int]访问列表元素,当列表为空时,访问索引0必然触发“list object has no element 0”的错误。

导致resources为空的可能原因:

  • 查询条件不匹配:当前设置的os:"CentOS"+os_version:"7"在CrowdStrike平台上没有对应的传感器安装包,可能需要调整OS标识(比如CentOS可能对应平台的"RHEL"类别)
  • 权限不足:falcon_client_id和falcon_client_secret对应的账号没有权限获取该版本的安装包
  • API查询格式错误:filter参数的语法不符合CrowdStrike API的要求

修复建议

  1. 验证API查询有效性:手动用curl测试API请求,确认是否能返回安装包数据,示例命令:
curl -H "Authorization: Bearer YOUR_ACCESS_TOKEN" "https://api.us-2.crowdstrike.com/sensors/combined/installers/v1?filter=os%3A%22CentOS%22%2Bos_version%3A%227%22"
  1. 添加空列表检查:在下载任务前增加校验逻辑,避免空列表导致报错:
- name: Verify installers exist
  fail:
    msg: "No Falcon sensor installers found for OS: {{ falcon_target_os }} {{ falcon_os_version }}"
  when: falcon_api_installer_list.json.resources | length == 0
  1. 检查账号权限:确认falcon_client_id对应的账号拥有Sensor Download相关权限,可在CrowdStrike控制台的权限设置中验证
  2. 调整查询条件:参考CrowdStrike官方API文档,修改falcon_os_query的过滤规则,比如尝试用platform:"linux"替代具体OS名称,或者调整os_version的匹配方式

内容的提问来源于stack exchange,提问作者sdevops

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 04:15:43