Ansible用户创建Playbook配置:多环境多项目用户分配需求
Let's break down your requirements and build a clear, maintainable solution step by step.
1. First, Structure Your Inventory Correctly
We need to group hosts by both environment and project so Ansible can dynamically determine which users to create on each host. Here's a sample inventory file:
# inventory.ini # Project-specific host groups [project1] dev-proj1-01 # Development server for project1 prod-proj1-01 # Production server for project1 [project2] dev-proj2-01 prod-proj2-01 # Environment parent groups (children of project groups) [development:children] project1 project2 [prod:children] project1 project2
This way, every host belongs to both a project group and an environment group—critical for our conditional logic.
2. Refine Your User Definition Variables
Keep all users in a single file (e.g., group_vars/all/users.yml) with clear mappings for profile and project access:
users: # Dev users: tied to specific projects, only for development environments - username: dev-proj1-john profile: dev projects: project1 key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQD..." OSgroups: "dev,project1" OSpass: "$6$rounds=100000$abc123xyz..." shell: /bin/bash - username: dev-proj2-jane profile: dev projects: project2 key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQE..." OSgroups: "dev,project2" OSpass: "$6$rounds=100000$def456uvw..." shell: /bin/bash # Ops users: have access to all projects and environments - username: ops-admin-bob profile: ops projects: all key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAF..." OSgroups: "sudo,ops" OSpass: "$6$rounds=100000$ghi789rst..." shell: /bin/bash - username: ops-audit-alice profile: ops projects: all key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAG..." OSgroups: "ops,audit" OSpass: "$6$rounds=100000$jkl012pqr..." shell: /bin/bash
3. Fix the Playbook Conditional Logic
The key is to combine three checks in the when clause to match your requirements:
- Ops users are created on all hosts (regardless of environment/project)
- Dev users are only created on development hosts that belong to their assigned project
Here's the corrected Playbook snippet:
- name: Create authorized users on target hosts become: yes user: name: "{{ item.username }}" shell: "{{ item.shell }}" groups: "{{ item.OSgroups }}" create_home: yes password: "{{ item.OSpass }}" with_items: "{{ users }}" when: # Condition 1: Always create ops users item.profile == 'ops' # Condition 2: For dev users, only create on development hosts in their project group or ( inventory_hostname in groups['development'] and item.profile == 'dev' and item.projects in group_names )
How This Works:
group_names: Ansible built-in variable that lists all groups the current host belongs to (e.g.,['project1', 'development']fordev-proj1-01)inventory_hostname in groups['development']: Checks if the host is in the development environment- The
oroperator ensures either condition is met to create the user
4. Optional: Add a Debug Step to Validate Logic
Before running the user creation, add a debug task to verify which users will be created on each host:
- name: Debug eligible users for current host debug: msg: "Will create user: {{ item.username }} (Profile: {{ item.profile }}, Project: {{ item.projects }})" with_items: "{{ users }}" when: item.profile == 'ops' or ( inventory_hostname in groups['development'] and item.profile == 'dev' and item.projects in group_names )
Key Takeaways
- Use inventory groups to avoid hardcoding environment/project values in variables
- Leverage Ansible's built-in variables (
group_names,inventory_hostname) for dynamic host context - Keep user definitions centralized and explicit for easy maintenance
内容的提问来源于stack exchange,提问作者MSchultz

