首次编写Ansible AWX Playbook遭遇YAML语法报错求助
Ansible Playbook YAML报错排错指南
你遇到的did not find expected key解析错误,和缩进是否用2空格、有没有Tab无关,核心是违反了Ansible任务的基础结构规则,附带还有多处逻辑和语法错误,逐一列清:
核心触发报错的原因
Ansible中单个以- name:开头的任务块,有且只能有一个核心动作模块。你在「Verify if the group already exists in AD」任务下,同时并列写了win_shell和debug两个模块,YAML解析器读到第二个同级模块时,无法匹配到对应的任务键,直接抛出语法错误,报错指向的行号就是第二个模块出现的位置。
其余存在的语法/逻辑错误
meta: end_play是独立的动作模块,不能和debug模块放在同一个任务下,必须拆分为单独任务配置触发条件。- AD组创建命令写错:你调用的
New-ADUser是创建AD用户的PowerShell指令,创建AD安全组需要用New-ADGroup。 - 含Jinja2变量的字符串未加引号:
Inform that group already exists任务的msg值没有整体用双引号包裹,YAML解析时容易把插值后的变量识别为嵌套结构,触发随机解析错误。 - 缩进不统一:部分PowerShell代码块、mail模块参数的缩进层级混乱,虽然不会触发当前报错,但会提升后续维护的排错成本。
- 幂等性设计缺陷:手动写PowerShell try/catch判断组是否存在的逻辑冗余,可以直接使用Ansible官方的
community.windows.win_domain_group模块实现AD组操作,模块自带存在性判断,不需要手动写判断逻辑。
修正后的最小可用Playbook示例
--- - name: Create user centric AD-groups hosts: "{{ domainName }}" gather_facts: false vars: GroupNameUpper: "RCWR_UC_APP_{{ appName | upper }}" groupDescription: "{{ appDescription }}" domainDict: "Labo": "DC=whatever" domainDC: '{{domainDict[domainName | default("Labo")] | default("stop") }}' companyDC: "whatever" tasks: - name: Print full groupname for test debug: msg: "{{ GroupNameUpper }}" - name: Check if AD groups already exist register: lookupResult win_shell: | $groups = @("{{ GroupNameUpper }}", "{{ GroupNameUpper }}_GrpMgmt") foreach ($group in $groups) { try { Get-ADGroup -Identity $group | Out-Null Write-Output "Group $group already exists." } catch { Write-Output "Group $group does not exist yet." } } - name: Print group check result debug: msg: "{{ lookupResult.stdout }}" - name: End play if any group already exists meta: end_play when: "'already exists' in lookupResult.stdout" - name: Create AD security groups register: createOutput win_shell: | $groups = @( @{ Name = "{{ GroupNameUpper }}" Sam = ("{{ GroupNameUpper }}" -replace "_","" -replace "RCWRUC","") }, @{ Name = "{{ GroupNameUpper }}_GrpMgmt" Sam = ("{{ GroupNameUpper }}_GrpMgmt" -replace "_","" -replace "RCWRUC","") } ) $ouPath = "OU=Groups,{{ companyDC }},OU=Departments,{{ domainDC }},DC=com" foreach ($group in $groups) { try { New-ADGroup -Name $group.Name -DisplayName $group.Name -SamAccountName $group.Sam -Description "{{ groupDescription }}" -GroupCategory Security -GroupScope DomainLocal -Path $ouPath } catch { Write-Output "Group $($group.Name) creation failed." } } failed_when: "('creation failed' in createOutput.stdout) or (createOutput.rc != 0)" no_log: true - name: Set notification email (Jenkins trigger) set_fact: sendToEmailAddress: "{{ requestorMail }}" when: requestorMail is defined - name: Set notification email (AWX manual trigger) set_fact: sendToEmailAddress: "{{ awx_user_email }}" when: requestorMail is not defined - name: Send creation result notification delegate_to: localhost mail: subject: "Create AD-group {{ GroupNameUpper }}" body: "Groups {{ GroupNameUpper }} have been created in {{ domainName }}" host: "exchangeserver" port: 25 to: "{{ sendToEmailAddress }}" from: "noreply@us.com" secure: starttls subtype: html no_log: true ...
内容的提问来源于stack exchange,提问作者Snak3d0c
相关产品推荐
相关产品推荐

