如何用单Ansible Playbook创建Azure VM并在其上执行任务
解决Azure VM创建后动态纳入Inventory执行后续任务的问题
这个问题其实很常见——Azure VM的公网IP是创建后才分配的,没法提前写到静态inventory里。不过Ansible有专门的办法解决这个动态主机管理的问题,核心就是用add_host模块把新创建的VM临时加入inventory,接着就能无缝执行后续任务了。
我给你整理了一个完整的Playbook示例,包含从资源创建到后续VM配置的全流程:
--- - name: 创建Azure VM及关联资源 hosts: localhost gather_facts: false tasks: - name: 创建虚拟网络 azure_rm_virtualnetwork: resource_group: az-test name: az-test-vnet address_prefixes: "10.43.0.0/16" - name: 添加子网 azure_rm_subnet: resource_group: az-test name: az-test-subnet virtual_network: az-test-vnet address_prefix: "10.43.1.0/24" - name: 创建公网IP azure_rm_publicipaddress: resource_group: az-test name: az-test-pip allocation_method: Dynamic # 按需选择静态/动态IP - name: 创建网络安全组(可选但推荐) azure_rm_securitygroup: resource_group: az-test name: az-test-nsg rules: - name: SSH protocol: Tcp destination_port_range: 22 access: Allow priority: 1001 direction: Inbound - name: 创建网络接口 azure_rm_networkinterface: resource_group: az-test name: az-test-nic virtual_network: az-test-vnet subnet: az-test-subnet public_ip_name: az-test-pip security_group: az-test-nsg - name: 创建虚拟机 azure_rm_virtualmachine: resource_group: az-test name: az-test-vm vm_size: Standard_D2s_v3 admin_username: azureuser ssh_public_keys: - path: /home/azureuser/.ssh/authorized_keys key_data: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQ..." # 替换为你的SSH公钥 network_interfaces: az-test-nic image: offer: UbuntuServer publisher: Canonical sku: "20.04-LTS" version: latest - name: 获取公网IP信息 azure_rm_publicipaddress_info: resource_group: az-test name: az-test-pip register: pip_info - name: 将新VM动态添加到临时Inventory add_host: name: az-test-vm groups: azure_vms ansible_host: "{{ pip_info.publicipaddresses[0].ip_address }}" ansible_user: azureuser ansible_ssh_private_key_file: "/path/to/your/private/key" # 替换为你的SSH私钥路径 ansible_ssh_common_args: "-o StrictHostKeyChecking=no" # 首次连接跳过主机密钥检查 - name: 在新VM上执行后续配置任务 hosts: azure_vms gather_facts: true tasks: - name: 更新APT缓存 apt: update_cache: yes cache_valid_time: 3600 - name: 安装Nginx apt: name: nginx state: present - name: 启动并启用Nginx服务 systemd: name: nginx state: started enabled: yes
关键步骤解释
- 资源创建阶段:完成VNet、子网、公网IP、NIC和VM的创建,确保VM关联了公网IP和允许SSH的安全组。
- 获取公网IP:用
azure_rm_publicipaddress_info模块获取刚创建的公网IP详情,存入pip_info变量。 - 动态添加主机:通过
add_host模块把新VM加入名为azure_vms的临时组,同时配置SSH连接所需的参数(IP、用户名、私钥)。 - 后续任务执行:新增一个Play,直接针对
azure_vms组执行配置任务,这样就无需提前编写静态inventory了。
注意事项
- 确保你的SSH公钥/私钥路径正确,且VM的admin用户名与创建时一致。
- 生产环境中建议去掉
StrictHostKeyChecking=no,改用预先导入主机密钥的方式保证安全。 - 如果是Windows VM,需要调整连接参数为WinRM相关配置(比如
ansible_connection: winrm)。
内容的提问来源于stack exchange,提问作者Hexdump
相关产品推荐
相关产品推荐

