Ansible 项目组织示例

了解 playbook、inventory、role 和变量之后,本节把它们组合起来,展示自动化 Web 服务的一种配置方式。

示例按功能组织 playbook、角色、清单与变量文件,通过 play 和 task 级标签提供更细粒度控制。这种方式灵活而强大,但并非唯一选择,应根据自己的需求调整。

示例目录布局

大多数任务放在角色中,每个环境一个 inventory,顶层保留少数 playbook:

production                # inventory file for production servers
staging                   # inventory file for staging environment

group_vars/
   group1.yml             # here we assign variables to particular groups
   group2.yml
host_vars/
   hostname1.yml          # here we assign variables to particular systems
   hostname2.yml

library/                  # if any custom modules, put them here (optional)
module_utils/             # if any custom module_utils to support modules, put them here (optional)
filter_plugins/           # if any custom filter plugins, put them here (optional)

site.yml                  # main playbook
webservers.yml            # playbook for webserver tier
dbservers.yml             # playbook for dbserver tier
tasks/                    # task files included from playbooks
    webservers-extra.yml  # <-- avoids confusing playbook with task files

角色目录进一步组织如下:

roles/
    common/               # this hierarchy represents a "role"
        tasks/            #
            main.yml      #  <-- tasks file can include smaller files if warranted
        handlers/         #
            main.yml      #  <-- handlers file
        templates/        #  <-- files for use with the template resource
            ntp.conf.j2   #  <------- templates end in .j2
        files/            #
            bar.txt       #  <-- files for use with the copy resource
            foo.sh        #  <-- script files for use with the script resource
        vars/             #
            main.yml      #  <-- variables associated with this role
        defaults/         #
            main.yml      #  <-- default lower priority variables for this role
        meta/             #
            main.yml      #  <-- role dependencies and optional Galaxy info
        library/          # roles can also include custom modules
        module_utils/     # roles can also include custom module_utils
        lookup_plugins/   # or other types of plugins, like lookup in this case

    webtier/              # same kind of structure as "common" was above, done for the webtier role
    monitoring/           # ""
    fooapp/               # ""

注意:Ansible 默认假定 playbook 位于同一目录,角色放在 roles/ 子目录。任务增多后,可以把 playbook 移到 playbooks/,但必须在 ansible.cfg 中通过 roles_path 配置角色路径。

另一种目录布局

也可以让每个 inventory 与对应的 group_vars、host_vars 放在独立目录。不同环境的变量差异较大时,尤其适用:

inventories/
   production/
      hosts               # inventory file for production servers
      group_vars/
         group1.yml       # here we assign variables to particular groups
         group2.yml
      host_vars/
         hostname1.yml    # here we assign variables to particular systems
         hostname2.yml

   staging/
      hosts               # inventory file for staging environment
      group_vars/
         group1.yml       # here we assign variables to particular groups
         group2.yml
      host_vars/
         stagehost1.yml   # here we assign variables to particular systems
         stagehost2.yml

library/
module_utils/
filter_plugins/

site.yml
webservers.yml
dbservers.yml

roles/
    common/
    webtier/
    monitoring/
    fooapp/

大型环境中,这样更灵活,也让环境间的清单变量完全隔离。但文件更多,维护更难。更多说明见主机与群组变量组织文档。

群组与主机变量示例

这些文件保存适用于某台机器或一组机器的值。例如 Atlanta 数据中心有自己的 NTP 服务器,配置 ntp.conf 时可使用:

---
# file: group_vars/atlanta
ntp: ntp-atlanta.example.com
backup: backup-atlanta.example.com

webservers 群组也有不适用于数据库服务器的配置:

---
# file: group_vars/webservers
apacheMaxRequestsPerChild: 3000
apacheMaxClients: 900

默认值或所有机器通用的值放在 group_vars/all:

---
# file: group_vars/all
ntp: ntp-boston.example.com
backup: backup-boston.example.com

必要时,可在 host_vars 描述特定主机硬件差异:

---
# file: host_vars/db-bos-1.example.com
foo_agent_port: 86
bar_agent_port: 99

使用动态 inventory 时,Ansible 自动创建很多动态群组。例如 class:webserver 标签会自动加载 group_vars/ec2_tag_class_webserver。

原文提示,可以通过特殊变量 hostvars 访问主机变量,并将其描述为主机专用变量访问方式;相关变量列表见 Special Variables 文档。

按功能组织 playbook

在此结构中,一个 playbook 即可描述整个基础设施。site.yml 导入 Web 与数据库两个 playbook:

---
# file: site.yml
- import_playbook: webservers.yml
- import_playbook: dbservers.yml

顶层 webservers.yml 将 webservers 群组映射到相应角色:

---
# file: webservers.yml
- hosts: webservers
  roles:
    - common
    - webtier

运行 site.yml 可配置全部基础设施,运行 webservers.yml 则只配置一部分。它类似 --limit,但表达更明确:

ansible-playbook site.yml --limit webservers
ansible-playbook webservers.yml

角色中的任务与处理器

Ansible 会加载角色子目录中的 main.yml。以下 tasks/main.yml 配置 NTP:

---
# file: roles/common/tasks/main.yml

- name: be sure ntp is installed
  yum:
    name: ntp
    state: present
  tags: ntp

- name: be sure ntp is configured
  template:
    src: ntp.conf.j2
    dest: /etc/ntp.conf
  notify:
    - restart ntpd
  tags: ntp

- name: be sure ntpd is running and enabled
  ansible.builtin.service:
    name: ntpd
    state: started
    enabled: true
  tags: ntp

下面是 handlers 文件。只有特定任务报告变化时才触发,且在每个 play 结束时运行:

---
# file: roles/common/handlers/main.yml
- name: restart ntpd
  ansible.builtin.service:
    name: ntpd
    state: restarted

更多说明见 Roles 文档。

示例支持的操作

重新配置全部基础设施:

ansible-playbook -i production site.yml

仅重新配置全部机器的 NTP:

ansible-playbook -i production site.yml --tags ntp

只配置 Web 服务器:

ansible-playbook -i production webservers.yml

只配置 Boston 的 Web 服务器:

ansible-playbook -i production webservers.yml --limit boston

先配置 Boston 前十台 Web 服务器,再配置接下来的十台:

ansible-playbook -i production webservers.yml --limit boston[0:9]
ansible-playbook -i production webservers.yml --limit boston[10:19]

也支持基本临时命令:

ansible boston -i production -m ping
ansible boston -i production -m command -a '/sbin/reboot'

查看某条命令将执行哪些任务、影响哪些主机:

# confirm what task names would be run if I ran this command and said "just ntp tasks"
ansible-playbook -i production webservers.yml --tags ntp --list-tasks

# confirm what hostnames might be communicated with if I said "limit to boston"
ansible-playbook -i production webservers.yml --limit boston --list-hosts

面向部署与配置组织内容

本例展示典型配置拓扑。多层应用部署时,可能需要跨层执行的额外 playbook,例如给 site.yml 增加 deploy_exampledotcom.yml。总体原则仍然适用。

Ansible 可以用同一工具完成配置和部署,因此通常会复用群组,但把操作系统配置与应用部署分放在不同 playbook 或角色中。

可以把 playbook 理解为体育战术手册:既有适用于整个基础设施的一组常规战术,也有在不同时间、为不同目的使用的特定战术。

使用本地模块

如果 playbook YAML 文件旁有 ./library 目录,Ansible 会自动把其中模块加入模块路径,让模块与 playbook 一起组织。前面的目录结构就是示例。

另请参阅

  • YAML Syntax:学习 YAML 语法。
  • Working with playbooks:复习基础功能。
  • Collection Index:浏览已有集合、模块和插件。
  • Should you develop a module?:学习自行扩展模块。
  • Patterns: targeting hosts and groups:选择主机。
  • Communication:通过 Ansible 社区沟通指南提问、求助或分享想法。

原文:Sample Ansible setup。作者/维护方:Ansible 文档维护者。本文为中文翻译,代码及命令保留原文。

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容