了解 playbook、inventory、role 和变量之后,本节把它们组合起来,展示自动化 Web 服务的一种配置方式。
示例按功能组织 playbook、角色、清单与变量文件,通过 play 和 task 级标签提供更细粒度控制。这种方式灵活而强大,但并非唯一选择,应根据自己的需求调整。
示例目录布局
大多数任务放在角色中,每个环境一个 inventory,顶层保留少数 playbook:
production # inventory file for production servers
staging # inventory file for staging environment
group_vars/
group1.yml # here we assign variables to particular groups
group2.yml
host_vars/
hostname1.yml # here we assign variables to particular systems
hostname2.yml
library/ # if any custom modules, put them here (optional)
module_utils/ # if any custom module_utils to support modules, put them here (optional)
filter_plugins/ # if any custom filter plugins, put them here (optional)
site.yml # main playbook
webservers.yml # playbook for webserver tier
dbservers.yml # playbook for dbserver tier
tasks/ # task files included from playbooks
webservers-extra.yml # <-- avoids confusing playbook with task files
角色目录进一步组织如下:
roles/
common/ # this hierarchy represents a "role"
tasks/ #
main.yml # <-- tasks file can include smaller files if warranted
handlers/ #
main.yml # <-- handlers file
templates/ # <-- files for use with the template resource
ntp.conf.j2 # <------- templates end in .j2
files/ #
bar.txt # <-- files for use with the copy resource
foo.sh # <-- script files for use with the script resource
vars/ #
main.yml # <-- variables associated with this role
defaults/ #
main.yml # <-- default lower priority variables for this role
meta/ #
main.yml # <-- role dependencies and optional Galaxy info
library/ # roles can also include custom modules
module_utils/ # roles can also include custom module_utils
lookup_plugins/ # or other types of plugins, like lookup in this case
webtier/ # same kind of structure as "common" was above, done for the webtier role
monitoring/ # ""
fooapp/ # ""
注意:Ansible 默认假定 playbook 位于同一目录,角色放在 roles/ 子目录。任务增多后,可以把 playbook 移到 playbooks/,但必须在 ansible.cfg 中通过 roles_path 配置角色路径。
另一种目录布局
也可以让每个 inventory 与对应的 group_vars、host_vars 放在独立目录。不同环境的变量差异较大时,尤其适用:
inventories/
production/
hosts # inventory file for production servers
group_vars/
group1.yml # here we assign variables to particular groups
group2.yml
host_vars/
hostname1.yml # here we assign variables to particular systems
hostname2.yml
staging/
hosts # inventory file for staging environment
group_vars/
group1.yml # here we assign variables to particular groups
group2.yml
host_vars/
stagehost1.yml # here we assign variables to particular systems
stagehost2.yml
library/
module_utils/
filter_plugins/
site.yml
webservers.yml
dbservers.yml
roles/
common/
webtier/
monitoring/
fooapp/
大型环境中,这样更灵活,也让环境间的清单变量完全隔离。但文件更多,维护更难。更多说明见主机与群组变量组织文档。
群组与主机变量示例
这些文件保存适用于某台机器或一组机器的值。例如 Atlanta 数据中心有自己的 NTP 服务器,配置 ntp.conf 时可使用:
---
# file: group_vars/atlanta
ntp: ntp-atlanta.example.com
backup: backup-atlanta.example.com
webservers 群组也有不适用于数据库服务器的配置:
---
# file: group_vars/webservers
apacheMaxRequestsPerChild: 3000
apacheMaxClients: 900
默认值或所有机器通用的值放在 group_vars/all:
---
# file: group_vars/all
ntp: ntp-boston.example.com
backup: backup-boston.example.com
必要时,可在 host_vars 描述特定主机硬件差异:
---
# file: host_vars/db-bos-1.example.com
foo_agent_port: 86
bar_agent_port: 99
使用动态 inventory 时,Ansible 自动创建很多动态群组。例如 class:webserver 标签会自动加载 group_vars/ec2_tag_class_webserver。
原文提示,可以通过特殊变量 hostvars 访问主机变量,并将其描述为主机专用变量访问方式;相关变量列表见 Special Variables 文档。
按功能组织 playbook
在此结构中,一个 playbook 即可描述整个基础设施。site.yml 导入 Web 与数据库两个 playbook:
---
# file: site.yml
- import_playbook: webservers.yml
- import_playbook: dbservers.yml
顶层 webservers.yml 将 webservers 群组映射到相应角色:
---
# file: webservers.yml
- hosts: webservers
roles:
- common
- webtier
运行 site.yml 可配置全部基础设施,运行 webservers.yml 则只配置一部分。它类似 --limit,但表达更明确:
ansible-playbook site.yml --limit webservers
ansible-playbook webservers.yml
角色中的任务与处理器
Ansible 会加载角色子目录中的 main.yml。以下 tasks/main.yml 配置 NTP:
---
# file: roles/common/tasks/main.yml
- name: be sure ntp is installed
yum:
name: ntp
state: present
tags: ntp
- name: be sure ntp is configured
template:
src: ntp.conf.j2
dest: /etc/ntp.conf
notify:
- restart ntpd
tags: ntp
- name: be sure ntpd is running and enabled
ansible.builtin.service:
name: ntpd
state: started
enabled: true
tags: ntp
下面是 handlers 文件。只有特定任务报告变化时才触发,且在每个 play 结束时运行:
---
# file: roles/common/handlers/main.yml
- name: restart ntpd
ansible.builtin.service:
name: ntpd
state: restarted
更多说明见 Roles 文档。
示例支持的操作
重新配置全部基础设施:
ansible-playbook -i production site.yml
仅重新配置全部机器的 NTP:
ansible-playbook -i production site.yml --tags ntp
只配置 Web 服务器:
ansible-playbook -i production webservers.yml
只配置 Boston 的 Web 服务器:
ansible-playbook -i production webservers.yml --limit boston
先配置 Boston 前十台 Web 服务器,再配置接下来的十台:
ansible-playbook -i production webservers.yml --limit boston[0:9]
ansible-playbook -i production webservers.yml --limit boston[10:19]
也支持基本临时命令:
ansible boston -i production -m ping
ansible boston -i production -m command -a '/sbin/reboot'
查看某条命令将执行哪些任务、影响哪些主机:
# confirm what task names would be run if I ran this command and said "just ntp tasks"
ansible-playbook -i production webservers.yml --tags ntp --list-tasks
# confirm what hostnames might be communicated with if I said "limit to boston"
ansible-playbook -i production webservers.yml --limit boston --list-hosts
面向部署与配置组织内容
本例展示典型配置拓扑。多层应用部署时,可能需要跨层执行的额外 playbook,例如给 site.yml 增加 deploy_exampledotcom.yml。总体原则仍然适用。
Ansible 可以用同一工具完成配置和部署,因此通常会复用群组,但把操作系统配置与应用部署分放在不同 playbook 或角色中。
可以把 playbook 理解为体育战术手册:既有适用于整个基础设施的一组常规战术,也有在不同时间、为不同目的使用的特定战术。
使用本地模块
如果 playbook YAML 文件旁有 ./library 目录,Ansible 会自动把其中模块加入模块路径,让模块与 playbook 一起组织。前面的目录结构就是示例。
另请参阅
- YAML Syntax:学习 YAML 语法。
- Working with playbooks:复习基础功能。
- Collection Index:浏览已有集合、模块和插件。
- Should you develop a module?:学习自行扩展模块。
- Patterns: targeting hosts and groups:选择主机。
- Communication:通过 Ansible 社区沟通指南提问、求助或分享想法。
原文:Sample Ansible setup。作者/维护方:Ansible 文档维护者。本文为中文翻译,代码及命令保留原文。











暂无评论内容