You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Ansible amazon.aws的aws_service_ip_ranges插件获取CloudFront IP段

正确的Ansible Playbook写法

运行前请先在控制节点安装依赖集合:
ansible-galaxy collection install amazon.aws

以下是可直接运行的完整示例:

---
- hosts: <hostname>
  remote_user: ansible
  collections:
    - amazon.aws
  tasks:
    - name: 获取CloudFront服务IP段
      ansible.builtin.set_fact:
        cloudfront_ranges: "{{ lookup('aws_service_ip_ranges', region='us-east-1', service='CLOUDFRONT', wantlist=True) }}"

    - name: 拼接打印所有CloudFront IP段
      ansible.builtin.debug:
        msg: "{% for cidr in cloudfront_ranges %}{{ cidr }} {% endfor %}"

    # 可选:逐行打印每个IP段,方便直接复制使用
    - name: 逐行输出IP段
      ansible.builtin.debug:
        var: item
      loop: "{{ cloudfront_ranges }}"

核心调整点:

  • 移除了错误的plugin字段配置:aws_service_ip_ranges是lookup插件,直接在Jinja2表达式内调用即可,不需要单独作为task的执行插件
  • 修正lookup参数语法:所有键值参数之间用逗号分隔,参数名和参数值之间用=连接,修复原写法缺少符号的语法错误
  • 改用set_fact模块存储获取到的IP段列表,变量作用域符合task执行逻辑,避免了原写法vars缩进错误的问题
  • 补充了可选的逐行打印task,方便直接查看和使用每个IP段

内容的提问来源于stack exchange,提问作者Matthew Allen-Goebel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 12:18:00