编写Ansible Role实现向NagiosXI批量添加监控服务
Got it, let's build an Ansible Role to automate this repetitive task. This setup will let you define all your host-service pairs in a single list and run the role once to add everything to Nagios XI.
1. Role Directory Structure
First, create the standard Ansible Role structure:
roles/ └── nagiosxi_add_services/ ├── defaults/ │ └── main.yml └── tasks/ └── main.yml
2. Default Variables (defaults/main.yml)
This file holds all the fixed parameters and the list of services you want to add. You can override these variables in your playbook later if needed.
# defaults/main.yml # Nagios XI API details nagiosxi_api_url: "https://16.231.22.60/nagiosxi/api/v1/config/service" nagiosxi_api_key: "qfOQpKFORCNo7HPunDUsSjW7f2rNNmrdVv3kvYpmQcNdSS2grV2jeXKsgbv3QgfL" # NCPA agent details ncpa_token: "5nidNag" ncpa_port: 5693 # Service check intervals check_interval: 5 retry_interval: 1 # List of services to add - each entry defines a host-service pair nagios_services_to_add: # Example entries - replace with your 50 services - host_name: "server01" service_description: "Service status for: sshd" service_name: "sshd" # Used to build the check command - host_name: "server01" service_description: "Service status for: httpd" service_name: "httpd" - host_name: "server02" service_description: "Service status for: sshd" service_name: "sshd"
3. Main Task (tasks/main.yml)
This task uses Ansible's uri module to replicate your curl command, looping through every entry in the nagios_services_to_add list.
# tasks/main.yml - name: Add services to Nagios XI via API uri: url: "{{ nagiosxi_api_url }}?apikey={{ nagiosxi_api_key }}&pretty=1" method: POST validate_certs: no # Matches -k in curl (skip SSL verification) body: host_name: "{{ item.host_name }}" service_description: "{{ item.service_description }}" use: "xiwizard_ncpa_service" check_command: "check_xi_ncpa! -t {{ ncpa_token }} -P {{ ncpa_port }} -M services -q service={{ item.service_name }},status=running" check_interval: "{{ check_interval }}" retry_interval: "{{ retry_interval }}" body_format: form-urlencoded # Simulates curl's -d (form data) status_code: 200 # Adjust this if Nagios XI returns a different success code (e.g., 201) loop: "{{ nagios_services_to_add }}" register: nagios_api_response until: nagios_api_response.status == 200 retries: 3 delay: 2 # Retry after 2 seconds if API call fails
4. Using the Role in a Playbook
Create a playbook to run the role. You can either define your service list directly in the playbook or load it from an external file.
Option 1: Define Services in the Playbook
# add_nagios_services.yml - name: Bulk add services to Nagios XI hosts: localhost # Run on your control node (where Ansible is installed) roles: - role: nagiosxi_add_services # Override default variables here if needed nagiosxi_api_key: "your_secure_api_key" nagios_services_to_add: - host_name: "webserver01" service_description: "Service status for: nginx" service_name: "nginx" - host_name: "dbserver01" service_description: "Service status for: mysqld" service_name: "mysqld" # Add all 50 of your host-service pairs here
Option 2: Load Services from an External File
If you have 50 entries, it's cleaner to store them in a separate file:
# services_list.yml nagios_services_to_add: - host_name: "server01" service_description: "Service status for: sshd" service_name: "sshd" - host_name: "server02" service_description: "Service status for: sshd" service_name: "sshd" # ... add all 50 entries ...
Then reference it in your playbook:
# add_nagios_services.yml - name: Bulk add services to Nagios XI hosts: localhost vars_files: - services_list.yml roles: - role: nagiosxi_add_services nagiosxi_api_key: "your_secure_api_key"
Notes
- SSL Verification: If your Nagios XI instance uses a valid SSL certificate, set
validate_certs: yesin the task. - Success Status Code: Test your original curl command to see what HTTP status code is returned on success (e.g., 201 for created resources) and update the
status_codeparameter accordingly. - Security: Store sensitive values like
nagiosxi_api_keyandncpa_tokenin Ansible Vault instead of plain text for production use.
内容的提问来源于stack exchange,提问作者user9698169

