You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible用户创建Playbook配置:多环境多项目用户分配需求

Solution for Ansible User Creation Based on Environment, Project, and User Profile

Let's break down your requirements and build a clear, maintainable solution step by step.

1. First, Structure Your Inventory Correctly

We need to group hosts by both environment and project so Ansible can dynamically determine which users to create on each host. Here's a sample inventory file:

# inventory.ini
# Project-specific host groups
[project1]
dev-proj1-01  # Development server for project1
prod-proj1-01 # Production server for project1

[project2]
dev-proj2-01
prod-proj2-01

# Environment parent groups (children of project groups)
[development:children]
project1
project2

[prod:children]
project1
project2

This way, every host belongs to both a project group and an environment group—critical for our conditional logic.

2. Refine Your User Definition Variables

Keep all users in a single file (e.g., group_vars/all/users.yml) with clear mappings for profile and project access:

users:
  # Dev users: tied to specific projects, only for development environments
  - username: dev-proj1-john
    profile: dev
    projects: project1
    key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQD..."
    OSgroups: "dev,project1"
    OSpass: "$6$rounds=100000$abc123xyz..."
    shell: /bin/bash

  - username: dev-proj2-jane
    profile: dev
    projects: project2
    key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQE..."
    OSgroups: "dev,project2"
    OSpass: "$6$rounds=100000$def456uvw..."
    shell: /bin/bash

  # Ops users: have access to all projects and environments
  - username: ops-admin-bob
    profile: ops
    projects: all
    key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAF..."
    OSgroups: "sudo,ops"
    OSpass: "$6$rounds=100000$ghi789rst..."
    shell: /bin/bash

  - username: ops-audit-alice
    profile: ops
    projects: all
    key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAG..."
    OSgroups: "ops,audit"
    OSpass: "$6$rounds=100000$jkl012pqr..."
    shell: /bin/bash

3. Fix the Playbook Conditional Logic

The key is to combine three checks in the when clause to match your requirements:

  • Ops users are created on all hosts (regardless of environment/project)
  • Dev users are only created on development hosts that belong to their assigned project

Here's the corrected Playbook snippet:

- name: Create authorized users on target hosts
  become: yes
  user:
    name: "{{ item.username }}"
    shell: "{{ item.shell }}"
    groups: "{{ item.OSgroups }}"
    create_home: yes
    password: "{{ item.OSpass }}"
  with_items: "{{ users }}"
  when:
    # Condition 1: Always create ops users
    item.profile == 'ops'
    # Condition 2: For dev users, only create on development hosts in their project group
    or (
      inventory_hostname in groups['development']
      and item.profile == 'dev'
      and item.projects in group_names
    )

How This Works:

  • group_names: Ansible built-in variable that lists all groups the current host belongs to (e.g., ['project1', 'development'] for dev-proj1-01)
  • inventory_hostname in groups['development']: Checks if the host is in the development environment
  • The or operator ensures either condition is met to create the user

4. Optional: Add a Debug Step to Validate Logic

Before running the user creation, add a debug task to verify which users will be created on each host:

- name: Debug eligible users for current host
  debug:
    msg: "Will create user: {{ item.username }} (Profile: {{ item.profile }}, Project: {{ item.projects }})"
  with_items: "{{ users }}"
  when:
    item.profile == 'ops'
    or (
      inventory_hostname in groups['development']
      and item.profile == 'dev'
      and item.projects in group_names
    )

Key Takeaways

  • Use inventory groups to avoid hardcoding environment/project values in variables
  • Leverage Ansible's built-in variables (group_names, inventory_hostname) for dynamic host context
  • Keep user definitions centralized and explicit for easy maintenance

内容的提问来源于stack exchange,提问作者MSchultz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:48:49