ansible-思科IOS和;“重新加载”;命令

ansible-思科IOS和;“重新加载”;命令,ios,configuration,ansible,ansible-playbook,Ios,Configuration,Ansible,Ansible Playbook,我想向Cisco IOS发送“重新加载”命令,但该特定命令需要确认,如下所示: #reload in 30 Reload scheduled in 30 minutes by admin on vty0 (192.168.253.15) Proceed with reload? [confirm] 它看起来像ios_命令模块不处理这种情况。 我的配置: tasks: - name: do reload in case of "catting off" ios_command:

我想向Cisco IOS发送“重新加载”命令,但该特定命令需要确认,如下所示:

#reload in 30
Reload scheduled in 30 minutes by admin on vty0 (192.168.253.15)
Proceed with reload? [confirm]
它看起来像ios_命令模块不处理这种情况。 我的配置:

 tasks:
   - name: do reload in case of "catting off"
     ios_command:
      commands: reload in 30
      commands: y
      provider: "{{ cli }}"
以及playbook的回应:

TASK [do reload in case of "catting off"] **************************************
    task path: /etc/ansible/test1.yml:14
    <192.168.0.33> ESTABLISH LOCAL CONNECTION FOR USER: root
    <192.168.0.33> EXEC /bin/sh -c '( umask 77 && mkdir -p "` echo $HOME/.ansible/tmp/ansible-tmp-1476454008.17-103724241654271 `" && echo ansible-tmp-1476454008.17-103724241654271="` echo $HOME/.ansible/tmp/ansible-tmp-1476454008.17-103724241654271 `" ) && sleep 0'
    <192.168.0.33> PUT /tmp/tmpAJiZR2 TO /root/.ansible/tmp/ansible-tmp-1476454008.17-103724241654271/ios_command
    <192.168.0.33> EXEC /bin/sh -c 'LANG=pl_PL.UTF-8 LC_ALL=pl_PL.UTF-8 LC_MESSAGES=pl_PL.UTF-8 /usr/bin/python /root/.ansible/tmp/ansible-tmp-1476454008.17-103724241654271/ios_command; rm -rf "/root/.ansible/tmp/ansible-tmp-1476454008.17-103724241654271/" > /dev/null 2>&1 && sleep 0'
    fatal: [192.168.0.33]: FAILED! => {"changed": false, "commands": ["y"], "failed": true, "invocation": {"module_args": {"auth_pass": null, "authorize": false, "commands": ["y"], "host": "192.168.0.33", "interval": 1, "password": "VALUE_SPECIFIED_IN_NO_LOG_PARAMETER", "port": 22, "provider": "{'username': 'admin', 'host': '192.168.0.33', 'password': '********'}", "retries": 10, "ssh_keyfile": null, "timeout": 10, "username": "admin", "waitfor": null}, "module_name": "ios_command"}, "msg": "matched error in response: y\r\n                   ^\r\n% Invalid input detected at '^' marker.\r\n\r\nsw7.test.lab#"}
但连接有一个问题:

oot@Kali:/etc/ansible# ansible-playbook test3 -u admin -k -vvvv 
Using /etc/ansible/ansible.cfg as config file
SSH password: 
Loaded callback default of type stdout, v2.0

PLAYBOOK: test3 ****************************************************************
1 plays in test3

PLAY [some tests] **************************************************************

TASK [do reload in case of "catting off"] **************************************
task path: /etc/ansible/test3:9
<192.168.0.33> ESTABLISH SSH CONNECTION FOR USER: admin
<192.168.0.33> SSH: EXEC sshpass -d12 ssh -C -vvv -o ControlMaster=auto -o ControlPersist=60s -o StrictHostKeyChecking=no -o User=admin -o ConnectTimeout=10 -o ControlPath=/root/.ansible/cp/ansible-ssh-%h-%p-%r 192.168.0.33 '/bin/sh -c '"'"'( umask 77 && mkdir -p "` echo $HOME/.ansible/tmp/ansible-tmp-1476882070.37-92402455055985 `" && echo ansible-tmp-1476882070.37-92402455055985="` echo $HOME/.ansible/tmp/ansible-tmp-1476882070.37-92402455055985 `" ) && sleep 0'"'"''
<192.168.0.33> PUT /tmp/tmp30wGsF TO "` echo $HOME/.ansible/tmp/ansible-tmp-1476882070.37-92402455055985 `" ) && sleep 0'"/expect
<192.168.0.33> SSH: EXEC sshpass -d12 sftp -o BatchMode=no -b - -C -vvv -o ControlMaster=auto -o ControlPersist=60s -o StrictHostKeyChecking=no -o User=admin -o ConnectTimeout=10 -o ControlPath=/root/.ansible/cp/ansible-ssh-%h-%p-%r '[192.168.0.33]'
fatal: [192.168.0.33]: UNREACHABLE! => {"changed": false, "msg": "SSH Error: data could not be sent to the remote host. Make sure this host can be reached over ssh", "unreachable": true}
    to retry, use: --limit @/etc/ansible/test3.retry

PLAY RECAP *********************************************************************
192.168.0.33               : ok=0    changed=0    unreachable=1    failed=0   


root@Kali:/etc/ansible# ansible-playbook test3 -u admin -k -vvvv -c ssh
Using /etc/ansible/ansible.cfg as config file
SSH password: 
Loaded callback default of type stdout, v2.0

PLAYBOOK: test3 ****************************************************************
1 plays in test3

PLAY [some tests] **************************************************************

TASK [do reload in case of "catting off"] **************************************
task path: /etc/ansible/test3:9
<192.168.0.33> ESTABLISH SSH CONNECTION FOR USER: admin
<192.168.0.33> SSH: EXEC sshpass -d12 ssh -C -vvv -o ControlMaster=auto -o ControlPersist=60s -o StrictHostKeyChecking=no -o User=admin -o ConnectTimeout=10 -o ControlPath=/root/.ansible/cp/ansible-ssh-%h-%p-%r 192.168.0.33 '/bin/sh -c '"'"'( umask 77 && mkdir -p "` echo $HOME/.ansible/tmp/ansible-tmp-1476882145.78-139203779538157 `" && echo ansible-tmp-1476882145.78-139203779538157="` echo $HOME/.ansible/tmp/ansible-tmp-1476882145.78-139203779538157 `" ) && sleep 0'"'"''
<192.168.0.33> PUT /tmp/tmpY5qqyW TO "` echo $HOME/.ansible/tmp/ansible-tmp-1476882145.78-139203779538157 `" ) && sleep 0'"/expect
<192.168.0.33> SSH: EXEC sshpass -d12 sftp -o BatchMode=no -b - -C -vvv -o 

ControlMaster=auto -o ControlPersist=60s -o StrictHostKeyChecking=no -o User=admin -o ConnectTimeout=10 -o ControlPath=/root/.ansible/cp/ansible-ssh-%h-%p-%r '[192.168.0.33]'
    fatal: [192.168.0.33]: UNREACHABLE! => {"changed": false, "msg": "SSH Error: data could not be sent to the remote host. Make sure this host can be reached over ssh", "unreachable": true}
        to retry, use: --limit @/etc/ansible/test3.retry

    PLAY RECAP *********************************************************************
    192.168.0.33               : ok=0    changed=0    unreachable=1    failed=0   

root@Kali:/etc/ansible# ansible-playbook test3 -u admin -k -vvvv -c local
Using /etc/ansible/ansible.cfg as config file
SSH password: 
Loaded callback default of type stdout, v2.0

PLAYBOOK: test3 ****************************************************************
1 plays in test3

PLAY [some tests] **************************************************************

TASK [do reload in case of "catting off"] **************************************
task path: /etc/ansible/test3:9
<192.168.0.33> ESTABLISH LOCAL CONNECTION FOR USER: root
<192.168.0.33> EXEC /bin/sh -c '( umask 77 && mkdir -p "` echo $HOME/.ansible/tmp/ansible-tmp-1476882426.62-172601217553809 `" && echo ansible-tmp-1476882426.62-172601217553809="` echo $HOME/.ansible/tmp/ansible-tmp-1476882426.62-172601217553809 `" ) && sleep 0'
<192.168.0.33> PUT /tmp/tmpdq1pYy TO /root/.ansible/tmp/ansible-tmp-1476882426.62-172601217553809/expect
<192.168.0.33> EXEC /bin/sh -c 'chmod u+x /root/.ansible/tmp/ansible-tmp-1476882426.62-172601217553809/ /root/.ansible/tmp/ansible-tmp-1476882426.62-172601217553809/expect && sleep 0'
<192.168.0.33> EXEC /bin/sh -c 'LANG=pl_PL.UTF-8 LC_ALL=pl_PL.UTF-8 LC_MESSAGES=pl_PL.UTF-8 /usr/bin/python /root/.ansible/tmp/ansible-tmp-1476882426.62-172601217553809/expect; rm -rf "/root/.ansible/tmp/ansible-tmp-1476882426.62-172601217553809/" > /dev/null 2>&1 && sleep 0'
fatal: [192.168.0.33]: FAILED! => {"changed": false, "failed": true, "invocation": {"module_args": {"chdir": null, "command": "reload in 30", "creates": null, "echo": true, "removes": null, "responses": {"Reload scheduled in 30 minutes by admin on vty0 (192.168.253.20)\\nProceed with reload? \\[confirm\\]": "y"}, "timeout": 30}, "module_name": "expect"}, "msg": "The command was not found or was not executable: reload."}

NO MORE HOSTS LEFT *************************************************************
    to retry, use: --limit @/etc/ansible/test3.retry

PLAY RECAP *********************************************************************
192.168.0.33               : ok=0    changed=0    unreachable=0    failed=1   
但我还是犯了一个错误。我认为这是因为ios模块总是等待promt作为响应。另外,在按下“y”键后,重新加载命令的确认没有“Enter”,因此这可能是另一个问题

  $ sudo  ansible-playbook test1.yml -vvvv
    Using /etc/ansible/ansible.cfg as config file
    Loading callback plugin default of type stdout, v2.0 from /usr/local/lib/python2.7/dist-packages/ansible/plugins/callback/__init__.pyc

    PLAYBOOK: test1.yml ************************************************************
    1 plays in test1.yml

    PLAY [testowe dzialania] *******************************************************

    TASK [do reload in case of "catting off"] **************************************
    task path: /home/user1/test1.yml:13
    Using module file /usr/local/lib/python2.7/dist-packages/ansible/modules/core/network/ios/ios_command.py
    <192.168.0.33> ESTABLISH LOCAL CONNECTION FOR USER: root
    <192.168.0.33> EXEC /bin/sh -c '( umask 77 && mkdir -p "` echo $HOME/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324 `" && echo ansible-tmp-1477557527.56-157304653717324="` echo $HOME/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324 `" ) && sleep 0'
    <192.168.0.33> PUT /tmp/tmphf8EWO TO /home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/ios_command.py
    <192.168.0.33> EXEC /bin/sh -c 'chmod u+x /home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/ /home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/ios_command.py && sleep 0'
    <192.168.0.33> EXEC /bin/sh -c '/usr/bin/python /home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/ios_command.py; rm -rf "/home/user1/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/" > /dev/null 2>&1 && sleep 0'
    fatal: [192.168.0.33]: FAILED! => {
        "changed": false,
        "failed": true,
        "invocation": {
            "module_args": {
                "auth_pass": null,
                "authorize": false,
                "commands": [
                    "reload in 30",
                    "y"
                ],
                "host": "192.168.0.33",
                "interval": 1,
                "match": "all",
                "password": "VALUE_SPECIFIED_IN_NO_LOG_PARAMETER",
                "port": null,
                "provider": {
                    "host": "192.168.0.33",
                    "password": "VALUE_SPECIFIED_IN_NO_LOG_PARAMETER",
                    "username": "admin"
                },
                "retries": 10,
                "ssh_keyfile": null,
                "timeout": 10,
                "transport": null,
                "use_ssl": true,
                "username": "admin",
                "validate_certs": true,
                "wait_for": [
                    "result[0] contains \"Proceed with reload\""
                ]
            },
            "module_name": "ios_command"
        },
        "msg": "timeout trying to send command: reload in 30\r"
    }
            to retry, use: --limit @/home/user1/test1.retry

    PLAY RECAP *********************************************************************
    192.168.0.33               : ok=0    changed=0    unreachable=0    failed=1
$sudo ansible playbook test1.yml-vvv
使用/etc/ansible/ansible.cfg作为配置文件
从/usr/local/lib/python2.7/dist-packages/ansible/plugins/callback/__;init.pyc加载默认类型stdout、v2.0的回调插件
剧本:test1.yml************************************************************
1在test1.yml中播放
播放[testowe dzialania]*******************************************************
任务[在“拖离”的情况下重新加载]**************************************
任务路径:/home/user1/test1.yml:13
使用模块文件/usr/local/lib/python2.7/dist-packages/ansible/modules/core/network/ios/ios_command.py
为用户建立本地连接:root
EXEC/bin/sh-c'(umask 77和&mkdir-p“`echo$HOME/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324`”和&echo-ansible-tmp-1477557527.56-157304653717324=“`echo$HOME/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324`&&0”
将/tmp/tmphf8EWO放到/home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/ios_command.py
EXEC/bin/sh-c'chmod u+x/home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324//home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/ios_command.py&&sleep 0'
EXEC/bin/sh-c'/usr/bin/python/home/mszczesniak/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/ios_command.py;rm-rf“/home/user1/.ansible/tmp/ansible-tmp-1477557527.56-157304653717324/”>/dev/null 2>&1&&sleep 0'
致命:[192.168.0.33]:失败!=>{
“更改”:错误,
“失败”:对,
“调用”:{
“模块参数”:{
“验证通过”:空,
“授权”:假,
“命令”:[
“30分钟后重新加载”,
“y”
],
“主机”:“192.168.0.33”,
“间隔”:1,
“匹配”:“全部”,
“密码”:“没有日志参数中指定的值”,
“端口”:空,
“提供者”:{
“主机”:“192.168.0.33”,
“密码”:“没有日志参数中指定的值”,
“用户名”:“管理员”
},
“重试”:10次,
“ssh_密钥文件”:null,
“超时”:10,
“传输”:空,
“使用ssl”:正确,
“用户名”:“管理员”,
“验证证书”:正确,
“等待”:[
结果[0]包含“继续重新加载”
]
},
“模块名称”:“ios\U命令”
},
“msg”:“尝试发送命令超时:30分钟后重新加载\r”
}
要重试,请使用:--limit@/home/user1/test1.retry
重演*********************************************************************
192.168.0.33:正常=0更改=0无法访问=0失败=1

有人知道如何用ansible或maby解决这个问题吗?唯一的方法是使用纯python脚本或编写自己的ansible模块

仅限Ansible 2.2

您可以使用以下内容:

 name: some tests
  hosts: sw-test
  gather_facts: False
#  connection: local

  tasks:
  - name: do reload in case of "catting off"
    expect:
     command: reload in 30
     responses:
      'Reload scheduled in 30 minutes by admin on vty0 (192.168.253.20)\nProceed with reload? \[confirm\]' : y
     echo: yes
  - name: send reload command inc confirmation
    ios_command:
      commands: 
        - reload in 30
        - y
      wait_for: 
        - result[0] contains "Proceed with reload" 
      provider: "{{ cli }}"
- name: do reload in case of "catting off"
  ios_command:
    commands:
      - reload in 30
      - y
  provider: "{{ cli }}"
未测试,但与模块的最后一个示例类似

不过要注意Ansible 2.2,它还没有发布,新发布的Ansible可能会有显著的倒退


Ansible 2.0+包括但需要在远程设备上使用Python,因此无法在IOS或类似设备上使用。

命令
IOS\u命令的参数
模块需要一个
YAML
格式的命令列表。但是,在提供的代码示例中,
命令
参数设置了多次。请尝试执行以下任务:

 name: some tests
  hosts: sw-test
  gather_facts: False
#  connection: local

  tasks:
  - name: do reload in case of "catting off"
    expect:
     command: reload in 30
     responses:
      'Reload scheduled in 30 minutes by admin on vty0 (192.168.253.20)\nProceed with reload? \[confirm\]' : y
     echo: yes
  - name: send reload command inc confirmation
    ios_command:
      commands: 
        - reload in 30
        - y
      wait_for: 
        - result[0] contains "Proceed with reload" 
      provider: "{{ cli }}"
- name: do reload in case of "catting off"
  ios_command:
    commands:
      - reload in 30
      - y
  provider: "{{ cli }}"

最简单的方法似乎是使用“raw”模块向设备发送raw SSH命令

这避免了必须使用expect和必须使用ios_命令模块

原始模块将运行命令,而不关心设备的响应或提示

您可以使用:

- name: reload device
  ios_command:
    commands:
      - "reload in 1\ny"
    provider: "{{ cli }}"
这将在1分钟内重新加载设备,并接受重新加载提示。它对ansible很有效,因为ios的默认提示将返回(重新加载将在1分钟内触发)

问候,,
下面的Simon使用ansible playbook 2.9.0和Python 3.7为我工作。请注意,在使用
-command
时,请确保使用双引号
而不是单引号
。不要忘记在命令末尾添加
\n

    - name: Reloading switch using ios_command.
      ios_command:
        commands: 
          - command: "reload\n"
            prompt: 'Proceed with reload? [confirm]'
            answer: "\r"

我使用Ansible的
expect
模块开始回答问题,但这可能没有帮助,因为您已经在使用
iosāu命令
模块。是否可以在Cisco ios设备上使用expect模块?现在我得到这样的回答:'code'任务[在“catting off”的情况下重新加载]******************************************************************致命:[192.168.0.33]:FAILED!=>{“changed”:false,“commands”:[“重新加载30”,“y”],“FAILED”:true,“msg”:“尝试发送命令超时”}“code”我想这是因为ansible在发送“重新加载30”后正在等待常规提示“@el_Magnetor-查看我的答案,在发送“y”之前等待确认提示。”#ansible——版本ansible 2.1.1.0任务[在“catting off”的情况下重新加载]*********************************************致命:[192.168.0.33]:失败!=>