Ansible Replace模块在AIX /etc/inetd.conf中注释行失效求助
Let's work through this issue step by step—your test file works but /etc/inetd.conf doesn't, so there are a few key things to check and fix:
1. The Most Obvious Fix: Wrong File Path
Looking at your playbook, the replace module is targeting /etc/test instead of /etc/inetd.conf! That's definitely why it works on your test file but does nothing to the actual config. First thing to do is correct the path parameter to point to the right file.
2. Regex Special Characters Are Breaking Matches
Your line1 and line2 strings contain regex meta-characters (like ., -, and spaces that might be interpreted differently) that the replace module's regex engine is trying to parse instead of treating as literal text. For example, /usr/sbin/ftpd has a . which regex interprets as "any character", not a literal dot.
To fix this, use the regex_escape filter to automatically escape all special characters so the module matches the exact line:
regexp: "{{ item | regex_escape }}"
3. File Permissions & Attributes (AIX-Specific)
AIX's /etc/inetd.conf typically has strict permissions (usually -rw-r--r-- owned by root:system) and might even have immutable attributes set to prevent accidental edits.
- Check permissions with:
ls -l /etc/inetd.conf - Check for immutable attributes with:
lsattr -E /etc/inetd.conf- If you see an
i(immutable) flag, remove it first with:chattr -E -i /etc/inetd.conf
- If you see an
Also, setting mode: 0777 in your playbook is unnecessary and insecure—stick to the default 0644 for this file.
4. Redundant Backup Step
Your shell task for backing up the file is redundant because the replace module already has a backup: yes parameter, which creates a timestamped backup automatically. If you prefer a custom backup filename, adjust the shell command to use AIX-compatible date formatting (AIX doesn't support %F; use %Y-%m-%d instead):
shell: "cp /etc/inetd.conf /etc/inetd.conf_$(date +%Y-%m-%d)"
Fixed Playbook
Here's the updated playbook with all these fixes:
--- - name: Comment out ftp and telnet lines in inetd.conf hosts: server1 vars: - line1: "ftp stream tcp6 nowait root /usr/sbin/ftpd ftpd -l -u 077 -t 180" - line2: "telnet stream tcp6 nowait root /usr/sbin/telnetd telnetd -a" tasks: - name: Comment ftp and telnet lines replace: path: /etc/inetd.conf # Corrected path regexp: "{{ item | regex_escape }}" # Escape regex special chars replace: "#{{ item }}" backup: yes # Auto-backup with timestamp owner: root group: system mode: '0644' # Secure default permission with_items: - "{{ line1 }}" - "{{ line2 }}"
Additional Debugging Tips
- Run the playbook with verbose output to see exactly what's happening:
ansible-playbook your_playbook.yml -vv- Look for lines like
matched: 0—that means the regex didn't find the line, so double-check that yourline1/line2exactly match the lines in/etc/inetd.conf(including spaces and case, since AIX is case-sensitive).
- Look for lines like
- Manually verify the lines in
/etc/inetd.confto ensure there are no hidden characters or whitespace differences.
内容的提问来源于stack exchange,提问作者ansibleuser

