Environment variables, set using `environment:`, only affect the tasks that are run on the target host. It does not affect how they are communicated with or ansible itself.
You would have to configure SSH_AUTH_SOCK to the value you need in Ansible, before executing Ansible. On Mon, Jan 6, 2020 at 11:24 AM 'Mark Tovey - DSV' via Ansible Project < [email protected]> wrote: > > > In my test, the target host is localhost, the same place that the > lookup runs. But the lookup call was only to provide a demonstration of > what is happening here and will not be used in my actual code. > > Ansible uses some form of SSH (Paramiko, directly calling ssh, etc.), > and that mechanism uses the value contained within SSH_AUTH_SOCK to > determine how to talk to ssh-agent. But it is using the shell version of > SSH_AUTH_SOCK, not the version that I have set within my Ansible playbook. > I need a way to inform the SSH mechanism to use the Ansible version of > SSH_AUTH_SOCK, not the shell version (preferred), or I need a way to push > the Ansible version into the shell version (not as preferred). > > Is there a way to do either of those? > > > > > > *From:* [email protected] <[email protected]> > *On Behalf Of *Matt Martz > *Sent:* Monday, January 6, 2020 8:58 AM > *To:* [email protected] > *Subject:* Re: [ansible-project] Export environment variables > > > > lookups do not run on the target host, and are not affected by the > `environment` keyword. > > > > On Mon, Jan 6, 2020 at 10:55 AM 'Mark Tovey' via Ansible Project < > [email protected]> wrote: > > > > I need to export some environment variables before running a task, but it > appears that setting variables with "environment" does not export them; > they remain local. For test, I wrote the following simple playbook: > > > > --- > > - hosts: localhost > > gather_facts: no > > environment: > > MYVAR: "TEST1" > > > > tasks: > > - shell: echo "$MYVAR" > > register: mytest > > > > - debug: > > msg: > > - "Ansible MYVAR = {{mytest.stdout}}" > > - "Exported MYVAR = {{lookup('env', 'MYVAR')}}" > > > > And when I run it with the shell MYVAR set, I get the following results: > > > > export MYVAR=TEST2;ansible-playbook ~/devansible/playbooks/mytest > > > > PLAY [localhost] > *************************************************************** > > > > TASK [shell] > ******************************************************************* > > changed: [localhost] > > > > TASK [debug] > ******************************************************************* > > ok: [localhost] => > > msg: > > - Ansible MYVAR = TEST1 > > - Exported MYVAR = TEST2 > > > > PLAY RECAP > ********************************************************************* > > localhost : ok=2 changed=1 unreachable=0 > failed=0 skipped=0 rescued=0 ignored=0 > > > > So, "environment" is not exporting the value as I expected. > > The main issue I have is that I am trying to set SSH_AUTH_SOCK so that > subsequent tasks can be executed on remote servers. In my playbook, I > start ssh-agent locally, grab the SSH_AUTH_SOCK and SSH_AGENT_PID values, > and place them into the Ansible environment. During the next task, I use > ssh-add to add a SSH key to the now running agent. That works perfectly, > and in fact I can query the running agent from outside of Ansible and see > the SSH key that was added inside of the playbook. But any remote tasks I > try to execute after adding the SSH key to the agent fail with > "UNREACHABLE". Apparently the remote tasks are using the original shell > version of SSH_AUTH_SOCK to connect to ssh-agent, not the Ansible version. > The Ansible version of SSH_AUTH_SOCK needs to be exported first. > > Is there a way to actually export variables from within Ansible? I can > always start ssh-agent prior to running Ansible so that the SSH_AUTH_SOCK > environment variable will contain the correct path to the agent socket, but > I was trying to avoid doing that for various reasons; I want to try to keep > all of the steps, including starting and stopping the SSH agent, contained > within a single playbook. > > Is there a flag set or something I can do that will cause the variables to > be truly exported? > > > > > > > > > > > > > > -- > You received this message because you are subscribed to the Google Groups > "Ansible Project" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion on the web visit > https://groups.google.com/d/msgid/ansible-project/1a126537-a388-4a2a-81dc-108aa74ef27d%40googlegroups.com > <https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2F1a126537-a388-4a2a-81dc-108aa74ef27d%2540googlegroups.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257406141&sdata=28VikHybvNq%2BfVZIsnqos%2F8Ujn8rWejEoAzTjlRktlM%3D&reserved=0> > . > > > > > -- > > Matt Martz > @sivel > sivel.net > <https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsivel.net&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257416133&sdata=8%2Bxa8IwHdHn4gGyu6ngH28saaxtnCRjERcZ4HolioC0%3D&reserved=0> > > -- > You received this message because you are subscribed to a topic in the > Google Groups "Ansible Project" group. > To unsubscribe from this topic, visit > https://groups.google.com/d/topic/ansible-project/W0z5aMfhqDM/unsubscribe > <https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Ftopic%2Fansible-project%2FW0z5aMfhqDM%2Funsubscribe&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257416133&sdata=fD4BqRg6ScBdbItAVBjJJkpJ0CqPkqYXqw7MxZQrF20%3D&reserved=0> > . > To unsubscribe from this group and all its topics, send an email to > [email protected]. > To view this discussion on the web visit > https://groups.google.com/d/msgid/ansible-project/CAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%3DtVm3F0tEbPJSjA%40mail.gmail.com > <https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FCAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%253DtVm3F0tEbPJSjA%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7Ce8096b081fd0451d374e08d792c9b0c1%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139267257426129&sdata=rmiMJ6KvcvS1eGqxynXTccu4bntasfxfZnV0dmExpsg%3D&reserved=0> > . > > -- > You received this message because you are subscribed to the Google Groups > "Ansible Project" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion on the web visit > https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63524B96F5545F064EA39AFC9E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com > <https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63524B96F5545F064EA39AFC9E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com?utm_medium=email&utm_source=footer> > . > -- Matt Martz @sivel sivel.net -- You received this message because you are subscribed to the Google Groups "Ansible Project" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/ansible-project/CAD8N0v-yXH7F3Zo1FBQq5pDMPUxo5G1mRvJmsqjtK3JQyXAkGg%40mail.gmail.com.
