Environment variables, set using `environment:`, only affect the tasks that
are run on the target host.  It does not affect how they are communicated
with or ansible itself.

You would have to configure SSH_AUTH_SOCK to the value you need in Ansible,
before executing Ansible.

On Mon, Jan 6, 2020 at 11:24 AM 'Mark Tovey - DSV' via Ansible Project <
[email protected]> wrote:

>
>
>     In my test, the target host is localhost, the same place that the
> lookup runs.  But the lookup call was only to provide a demonstration of
> what is happening here and will not be used in my actual code.
>
>     Ansible uses some form of SSH (Paramiko, directly calling ssh, etc.),
> and that mechanism uses the value contained within SSH_AUTH_SOCK to
> determine how to talk to ssh-agent.  But it is using the shell version of
> SSH_AUTH_SOCK, not the version that I have set within my Ansible playbook.
> I need a way to inform the SSH mechanism to use the Ansible version of
> SSH_AUTH_SOCK, not the shell version (preferred), or I need a way to push
> the Ansible version into the shell version (not as preferred).
>
>     Is there a way to do either of those?
>
>
>
>
>
> *From:* [email protected] <[email protected]>
> *On Behalf Of *Matt Martz
> *Sent:* Monday, January 6, 2020 8:58 AM
> *To:* [email protected]
> *Subject:* Re: [ansible-project] Export environment variables
>
>
>
> lookups do not run on the target host, and are not affected by the
> `environment` keyword.
>
>
>
> On Mon, Jan 6, 2020 at 10:55 AM 'Mark Tovey' via Ansible Project <
> [email protected]> wrote:
>
>
>
> I need to export some environment variables before running a task, but it
> appears that setting variables with "environment" does not export them;
> they remain local.  For test, I wrote the following simple playbook:
>
>
>
> ---
>
> - hosts: localhost
>
>   gather_facts: no
>
>   environment:
>
>       MYVAR: "TEST1"
>
>
>
>   tasks:
>
>     - shell: echo "$MYVAR"
>
>       register: mytest
>
>
>
>     - debug:
>
>         msg:
>
>           - "Ansible MYVAR = {{mytest.stdout}}"
>
>           - "Exported MYVAR = {{lookup('env', 'MYVAR')}}"
>
>
>
> And when I run it with the shell MYVAR set, I get the following results:
>
>
>
> export MYVAR=TEST2;ansible-playbook ~/devansible/playbooks/mytest
>
>
>
> PLAY [localhost]
> ***************************************************************
>
>
>
> TASK [shell]
> *******************************************************************
>
> changed: [localhost]
>
>
>
> TASK [debug]
> *******************************************************************
>
> ok: [localhost] =>
>
>   msg:
>
>   - Ansible MYVAR = TEST1
>
>   - Exported MYVAR = TEST2
>
>
>
> PLAY RECAP
> *********************************************************************
>
> localhost                  : ok=2    changed=1    unreachable=0
> failed=0    skipped=0    rescued=0    ignored=0
>
>
>
> So, "environment" is not exporting the value as I expected.
>
> The main issue I have is that I am trying to set SSH_AUTH_SOCK so that
> subsequent tasks can be executed on remote servers.  In my playbook, I
> start ssh-agent locally, grab the SSH_AUTH_SOCK and SSH_AGENT_PID values,
> and place them into the Ansible environment.  During the next task, I use
> ssh-add to add a SSH key to the now running agent.  That works perfectly,
> and in fact I can query the running agent from outside of Ansible and see
> the SSH key that was added inside of the playbook.  But any remote tasks I
> try to execute after adding the SSH key to the agent fail with
> "UNREACHABLE".  Apparently the remote tasks are using the original shell
> version of SSH_AUTH_SOCK to connect to ssh-agent, not the Ansible version.
> The Ansible version of SSH_AUTH_SOCK needs to be exported first.
>
> Is there a way to actually export variables from within Ansible?  I can
> always start ssh-agent prior to running Ansible so that the SSH_AUTH_SOCK
> environment variable will contain the correct path to the agent socket, but
> I was trying to avoid doing that for various reasons; I want to try to keep
> all of the steps, including starting and stopping the SSH agent, contained
> within a single playbook.
>
> Is there a flag set or something I can do that will cause the variables to
> be truly exported?
>
>
>
>
>
>
>
>
>
>
>
>
>
> --
> You received this message because you are subscribed to the Google Groups
> "Ansible Project" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/ansible-project/1a126537-a388-4a2a-81dc-108aa74ef27d%40googlegroups.com
> <https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2F1a126537-a388-4a2a-81dc-108aa74ef27d%2540googlegroups.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257406141&sdata=28VikHybvNq%2BfVZIsnqos%2F8Ujn8rWejEoAzTjlRktlM%3D&reserved=0>
> .
>
>
>
>
> --
>
> Matt Martz
> @sivel
> sivel.net
> <https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsivel.net&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257416133&sdata=8%2Bxa8IwHdHn4gGyu6ngH28saaxtnCRjERcZ4HolioC0%3D&reserved=0>
>
> --
> You received this message because you are subscribed to a topic in the
> Google Groups "Ansible Project" group.
> To unsubscribe from this topic, visit
> https://groups.google.com/d/topic/ansible-project/W0z5aMfhqDM/unsubscribe
> <https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Ftopic%2Fansible-project%2FW0z5aMfhqDM%2Funsubscribe&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257416133&sdata=fD4BqRg6ScBdbItAVBjJJkpJ0CqPkqYXqw7MxZQrF20%3D&reserved=0>
> .
> To unsubscribe from this group and all its topics, send an email to
> [email protected].
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/ansible-project/CAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%3DtVm3F0tEbPJSjA%40mail.gmail.com
> <https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FCAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%253DtVm3F0tEbPJSjA%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257426129&sdata=rmiMJ6KvcvS1eGqxynXTccu4bntasfxfZnV0dmExpsg%3D&reserved=0>
> .
>
> --
> You received this message because you are subscribed to the Google Groups
> "Ansible Project" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63524B96F5545F064EA39AFC9E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com
> <https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63524B96F5545F064EA39AFC9E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com?utm_medium=email&utm_source=footer>
> .
>


-- 
Matt Martz
@sivel
sivel.net

-- 
You received this message because you are subscribed to the Google Groups 
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/CAD8N0v-yXH7F3Zo1FBQq5pDMPUxo5G1mRvJmsqjtK3JQyXAkGg%40mail.gmail.com.

Reply via email to