In my test, the target host is localhost, the same place that the lookup
runs. But the lookup call was only to provide a demonstration of what is
happening here and will not be used in my actual code.
Ansible uses some form of SSH (Paramiko, directly calling ssh, etc.), and
that mechanism uses the value contained within SSH_AUTH_SOCK to determine how
to talk to ssh-agent. But it is using the shell version of SSH_AUTH_SOCK, not
the version that I have set within my Ansible playbook. I need a way to inform
the SSH mechanism to use the Ansible version of SSH_AUTH_SOCK, not the shell
version (preferred), or I need a way to push the Ansible version into the shell
version (not as preferred).
Is there a way to do either of those?
From: [email protected] <[email protected]> On
Behalf Of Matt Martz
Sent: Monday, January 6, 2020 8:58 AM
To: [email protected]
Subject: Re: [ansible-project] Export environment variables
lookups do not run on the target host, and are not affected by the
`environment` keyword.
On Mon, Jan 6, 2020 at 10:55 AM 'Mark Tovey' via Ansible Project
<[email protected]<mailto:[email protected]>>
wrote:
I need to export some environment variables before running a task, but it
appears that setting variables with "environment" does not export them; they
remain local. For test, I wrote the following simple playbook:
---
- hosts: localhost
gather_facts: no
environment:
MYVAR: "TEST1"
tasks:
- shell: echo "$MYVAR"
register: mytest
- debug:
msg:
- "Ansible MYVAR = {{mytest.stdout}}"
- "Exported MYVAR = {{lookup('env', 'MYVAR')}}"
And when I run it with the shell MYVAR set, I get the following results:
export MYVAR=TEST2;ansible-playbook ~/devansible/playbooks/mytest
PLAY [localhost] ***************************************************************
TASK [shell] *******************************************************************
changed: [localhost]
TASK [debug] *******************************************************************
ok: [localhost] =>
msg:
- Ansible MYVAR = TEST1
- Exported MYVAR = TEST2
PLAY RECAP *********************************************************************
localhost : ok=2 changed=1 unreachable=0 failed=0
skipped=0 rescued=0 ignored=0
So, "environment" is not exporting the value as I expected.
The main issue I have is that I am trying to set SSH_AUTH_SOCK so that
subsequent tasks can be executed on remote servers. In my playbook, I start
ssh-agent locally, grab the SSH_AUTH_SOCK and SSH_AGENT_PID values, and place
them into the Ansible environment. During the next task, I use ssh-add to add
a SSH key to the now running agent. That works perfectly, and in fact I can
query the running agent from outside of Ansible and see the SSH key that was
added inside of the playbook. But any remote tasks I try to execute after
adding the SSH key to the agent fail with "UNREACHABLE". Apparently the remote
tasks are using the original shell version of SSH_AUTH_SOCK to connect to
ssh-agent, not the Ansible version. The Ansible version of SSH_AUTH_SOCK needs
to be exported first.
Is there a way to actually export variables from within Ansible? I can always
start ssh-agent prior to running Ansible so that the SSH_AUTH_SOCK environment
variable will contain the correct path to the agent socket, but I was trying to
avoid doing that for various reasons; I want to try to keep all of the steps,
including starting and stopping the SSH agent, contained within a single
playbook.
Is there a flag set or something I can do that will cause the variables to be
truly exported?
--
You received this message because you are subscribed to the Google Groups
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ansible-project/1a126537-a388-4a2a-81dc-108aa74ef27d%40googlegroups.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2F1a126537-a388-4a2a-81dc-108aa74ef27d%2540googlegroups.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257406141&sdata=28VikHybvNq%2BfVZIsnqos%2F8Ujn8rWejEoAzTjlRktlM%3D&reserved=0>.
--
Matt Martz
@sivel
sivel.net<https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsivel.net&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257416133&sdata=8%2Bxa8IwHdHn4gGyu6ngH28saaxtnCRjERcZ4HolioC0%3D&reserved=0>
--
You received this message because you are subscribed to a topic in the Google
Groups "Ansible Project" group.
To unsubscribe from this topic, visit
https://groups.google.com/d/topic/ansible-project/W0z5aMfhqDM/unsubscribe<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Ftopic%2Fansible-project%2FW0z5aMfhqDM%2Funsubscribe&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257416133&sdata=fD4BqRg6ScBdbItAVBjJJkpJ0CqPkqYXqw7MxZQrF20%3D&reserved=0>.
To unsubscribe from this group and all its topics, send an email to
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ansible-project/CAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%3DtVm3F0tEbPJSjA%40mail.gmail.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FCAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%253DtVm3F0tEbPJSjA%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257426129&sdata=rmiMJ6KvcvS1eGqxynXTccu4bntasfxfZnV0dmExpsg%3D&reserved=0>.
--
You received this message because you are subscribed to the Google Groups
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63524B96F5545F064EA39AFC9E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com.