FOUND IT!!!
I added this to the playbook:

  - name: Test connection
    command:
        id
    vars:
        ansible_ssh_common_args: "-o IdentityAgent={{socket}}"

Ansible variable “socket” contains the path to the ssh-agent socket, the same 
value that is set in SSH_AUTH_SOCKET.  That string (-o 
IdentityAgent={{socket}}) is passed to ssh when connecting to the target host 
and ssh uses that instead of SSH_AUTH_SOCK.  The connection is made and all is 
well!  I added “ansible_ssh_common_args” to the playbook vars section instead 
of at the individual tasks level and that works equally well.
The bottom line here is that I can now dynamically start ssh-agent, add keys to 
it, and then run tasks that use that ssh-agent to authenticate to hosts.  The 
whole point of all of this is that I wanted to fetch keys from safe storage 
elsewhere and use them for client host access, all without ever writing the 
keys to file on the Ansible host.  I think I have found a method of doing that 
here.


From: [email protected] <[email protected]> On 
Behalf Of Matt Martz
Sent: Monday, January 6, 2020 10:58 AM
To: [email protected]
Subject: Re: [ansible-project] Export environment variables

I know exactly the point you are making.  I am telling you it is not feasible, 
and explaining to you what `environment:` does.

What you want, ansible cannot do.  Environment variables needed for the 
operation of Ansible, or SSH, cannot be set by ansible. They must be set before 
you execute ansible.  Ansible cannot impact its own execution, which includes 
the invocation of the SSH command from Ansible.

You will not be able to start the ssh-agent from ansible, and have ansible use 
that, unless you specify a static path to the socket, that can be set before 
ansible is started, and set SSH_AUTH_SOCK to that *before* you execute ansible.

On Mon, Jan 6, 2020 at 11:43 AM 'Mark Tovey - DSV' via Ansible Project 
<[email protected]<mailto:[email protected]>> 
wrote:

    You are missing the point.  I am not trying to set SSH_AUTH_SOCK on the 
target host.  I am trying to set it on the Ansible host, so that the SSH 
mechanism on the Ansible host can use the value of SSH_AUTH_SOCK to connect to 
the ssh-agent that is running on the Ansible host.  The target host is not 
involved at this point; it is all still local on the Ansible host.  Once the 
SSH mechanism has connected to the local ssh-agent, it can use the SSH key that 
is contained within the ssh-agent to establish a connection to the target host. 
 But the SSH mechanism is using the wrong version of SSH_AUTH_SOCK.  I need a 
way to inform it of the Ansible version, or to override the value in the shell 
version with the Ansible version.
    When I use the shell command on the Ansible host (delegate_to: localhost) 
to execute ssh-add, ssh-add uses the Ansible version of SSH_AUTH_SOCK to 
connect to ssh-agent.  But if I try to run a task on a target, the SSH 
mechanism that connects to the target host is clearly using the shell version 
of SSH_AUTH_SOCK.


From: [email protected]<mailto:[email protected]> 
<[email protected]<mailto:[email protected]>> On 
Behalf Of Matt Martz
Sent: Monday, January 6, 2020 9:27 AM
To: [email protected]<mailto:[email protected]>
Subject: Re: [ansible-project] Export environment variables

Environment variables, set using `environment:`, only affect the tasks that are 
run on the target host.  It does not affect how they are communicated with or 
ansible itself.

You would have to configure SSH_AUTH_SOCK to the value you need in Ansible, 
before executing Ansible.

On Mon, Jan 6, 2020 at 11:24 AM 'Mark Tovey - DSV' via Ansible Project 
<[email protected]<mailto:[email protected]>> 
wrote:

    In my test, the target host is localhost, the same place that the lookup 
runs.  But the lookup call was only to provide a demonstration of what is 
happening here and will not be used in my actual code.
    Ansible uses some form of SSH (Paramiko, directly calling ssh, etc.), and 
that mechanism uses the value contained within SSH_AUTH_SOCK to determine how 
to talk to ssh-agent.  But it is using the shell version of SSH_AUTH_SOCK, not 
the version that I have set within my Ansible playbook.  I need a way to inform 
the SSH mechanism to use the Ansible version of SSH_AUTH_SOCK, not the shell 
version (preferred), or I need a way to push the Ansible version into the shell 
version (not as preferred).
    Is there a way to do either of those?


From: [email protected]<mailto:[email protected]> 
<[email protected]<mailto:[email protected]>> On 
Behalf Of Matt Martz
Sent: Monday, January 6, 2020 8:58 AM
To: [email protected]<mailto:[email protected]>
Subject: Re: [ansible-project] Export environment variables

lookups do not run on the target host, and are not affected by the 
`environment` keyword.

On Mon, Jan 6, 2020 at 10:55 AM 'Mark Tovey' via Ansible Project 
<[email protected]<mailto:[email protected]>> 
wrote:

I need to export some environment variables before running a task, but it 
appears that setting variables with "environment" does not export them; they 
remain local.  For test, I wrote the following simple playbook:

---
- hosts: localhost
  gather_facts: no
  environment:
      MYVAR: "TEST1"

  tasks:
    - shell: echo "$MYVAR"
      register: mytest

    - debug:
        msg:
          - "Ansible MYVAR = {{mytest.stdout}}"
          - "Exported MYVAR = {{lookup('env', 'MYVAR')}}"

And when I run it with the shell MYVAR set, I get the following results:

export MYVAR=TEST2;ansible-playbook ~/devansible/playbooks/mytest

PLAY [localhost] ***************************************************************

TASK [shell] *******************************************************************
changed: [localhost]

TASK [debug] *******************************************************************
ok: [localhost] =>
  msg:
  - Ansible MYVAR = TEST1
  - Exported MYVAR = TEST2

PLAY RECAP *********************************************************************
localhost                  : ok=2    changed=1    unreachable=0    failed=0    
skipped=0    rescued=0    ignored=0

So, "environment" is not exporting the value as I expected.
The main issue I have is that I am trying to set SSH_AUTH_SOCK so that 
subsequent tasks can be executed on remote servers.  In my playbook, I start 
ssh-agent locally, grab the SSH_AUTH_SOCK and SSH_AGENT_PID values, and place 
them into the Ansible environment.  During the next task, I use ssh-add to add 
a SSH key to the now running agent.  That works perfectly, and in fact I can 
query the running agent from outside of Ansible and see the SSH key that was 
added inside of the playbook.  But any remote tasks I try to execute after 
adding the SSH key to the agent fail with "UNREACHABLE".  Apparently the remote 
tasks are using the original shell version of SSH_AUTH_SOCK to connect to 
ssh-agent, not the Ansible version.  The Ansible version of SSH_AUTH_SOCK needs 
to be exported first.
Is there a way to actually export variables from within Ansible?  I can always 
start ssh-agent prior to running Ansible so that the SSH_AUTH_SOCK environment 
variable will contain the correct path to the agent socket, but I was trying to 
avoid doing that for various reasons; I want to try to keep all of the steps, 
including starting and stopping the SSH agent, contained within a single 
playbook.
Is there a flag set or something I can do that will cause the variables to be 
truly exported?






--
You received this message because you are subscribed to the Google Groups 
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to 
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/1a126537-a388-4a2a-81dc-108aa74ef27d%40googlegroups.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2F1a126537-a388-4a2a-81dc-108aa74ef27d%2540googlegroups.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446788139&sdata=MjQJnkPHqniJB7XlRxVKWvYB%2BZOV4vN2malxxeGQ%2F5A%3D&reserved=0>.


--
Matt Martz
@sivel
sivel.net<https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsivel.net&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446788139&sdata=HmRAk6cifDbCOcvuxIxKh0jkGEow8Hzk0VLTc6m1vII%3D&reserved=0>
--
You received this message because you are subscribed to a topic in the Google 
Groups "Ansible Project" group.
To unsubscribe from this topic, visit 
https://groups.google.com/d/topic/ansible-project/W0z5aMfhqDM/unsubscribe<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Ftopic%2Fansible-project%2FW0z5aMfhqDM%2Funsubscribe&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446798137&sdata=F3gqIbViNXcKNMs%2FcA4IlENqtl30lwRrvbXjzX%2BjBcg%3D&reserved=0>.
To unsubscribe from this group and all its topics, send an email to 
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/CAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%3DtVm3F0tEbPJSjA%40mail.gmail.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FCAD8N0v9a4L-cpT6MkKn4RTsND8QguR89qVD%253DtVm3F0tEbPJSjA%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446798137&sdata=KeIwGIPTKNW%2Feu66%2FT0E6UP0nUB5%2B5JGKair%2Ff3bUcQ%3D&reserved=0>.
--
You received this message because you are subscribed to the Google Groups 
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to 
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63524B96F5545F064EA39AFC9E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FVE1PR06MB63524B96F5545F064EA39AFC9E3C0%2540VE1PR06MB6352.eurprd06.prod.outlook.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C0%7C637139339446808125&sdata=ARcr3WicJq6rzVvO8%2FUcFkTina%2F8Rc28R3YMF49KuN4%3D&reserved=0>.


--
Matt Martz
@sivel
sivel.net<https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsivel.net&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446808125&sdata=zJX8j7kM0BX2h7iSRNE1Syn7Q%2BdEpgVyQov8plDgzFE%3D&reserved=0>
--
You received this message because you are subscribed to a topic in the Google 
Groups "Ansible Project" group.
To unsubscribe from this topic, visit 
https://groups.google.com/d/topic/ansible-project/W0z5aMfhqDM/unsubscribe<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Ftopic%2Fansible-project%2FW0z5aMfhqDM%2Funsubscribe&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446818122&sdata=lXd1X3G65wNzcRyiOIDDsH7Rq3UbIXO3UsaWmYyPXDc%3D&reserved=0>.
To unsubscribe from this group and all its topics, send an email to 
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/CAD8N0v-yXH7F3Zo1FBQq5pDMPUxo5G1mRvJmsqjtK3JQyXAkGg%40mail.gmail.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FCAD8N0v-yXH7F3Zo1FBQq5pDMPUxo5G1mRvJmsqjtK3JQyXAkGg%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446828134&sdata=yH14Aft8iDFvn7FNZcJpCWJboabCPRrsPPp60dr62s8%3D&reserved=0>.
--
You received this message because you are subscribed to the Google Groups 
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to 
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63522E11EC557DA9123FFB2B9E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FVE1PR06MB63522E11EC557DA9123FFB2B9E3C0%2540VE1PR06MB6352.eurprd06.prod.outlook.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C0%7C637139339446828134&sdata=YmekDVbBk9WYFCAmpxmR8%2FECS0pJNGYCmJJDCnkUYu4%3D&reserved=0>.


--
Matt Martz
@sivel
sivel.net<https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsivel.net&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446838109&sdata=4RXVVsHQmP0XzrlAsr6H4MhuYoyGeFqVM3ypshpL194%3D&reserved=0>
--
You received this message because you are subscribed to a topic in the Google 
Groups "Ansible Project" group.
To unsubscribe from this topic, visit 
https://groups.google.com/d/topic/ansible-project/W0z5aMfhqDM/unsubscribe<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Ftopic%2Fansible-project%2FW0z5aMfhqDM%2Funsubscribe&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C1%7C637139339446838109&sdata=sITIHBlfSvwS4pJ8FmNzfIgDLC6CnLTy%2B6EKN8t7vcw%3D&reserved=0>.
To unsubscribe from this group and all its topics, send an email to 
[email protected]<mailto:[email protected]>.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/CAD8N0v_Vaf8k4%3DnPajbm_2e4oCv1Ayp%3DzRJiktD-qzXyuONN%2BA%40mail.gmail.com<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgroups.google.com%2Fd%2Fmsgid%2Fansible-project%2FCAD8N0v_Vaf8k4%253DnPajbm_2e4oCv1Ayp%253DzRJiktD-qzXyuONN%252BA%2540mail.gmail.com%3Futm_medium%3Demail%26utm_source%3Dfooter&data=02%7C01%7Cmark.tovey%40dsv.com%7C89eb89b8cce541f9c3bc08d792da7fab%7C4a90c23a3ece4ef2b857522f23b8204c%7C0%7C0%7C637139339446848106&sdata=%2BFDaNb4ANiAwHIdGNpMIcC9z1%2ByCrB9Csm5icCstBIU%3D&reserved=0>.

-- 
You received this message because you are subscribed to the Google Groups 
"Ansible Project" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ansible-project/VE1PR06MB63526D9A6F0302944130C7209E3C0%40VE1PR06MB6352.eurprd06.prod.outlook.com.

Reply via email to