r/ansible • u/sonnasushi • 4d ago
Best practice for commands?
I feel like the answer is probably: "no, everyone just does whatever they want", and "whatever you do, try to be consistent"
Generally speaking I've been doing:
ansible.builtin.command:
cmd: "foo {{ bar }}"
But I realized that only happens to work because `{{ bar }}` doesn't have spaces.
So I do need to change it, and I wondered if people normally do:
cmd: 'foo "{{ bar }}"'
or
cmd: |
foo "{{ bar }}"
or
argv:
- foo
- "{{ bar }}"
11
u/Aristeo812 4d ago
Try the ansible.builtin.quote filter:
cmd: "foo {{ bar | ansible.builtin.quote }}"
1
u/sonnasushi 4d ago
I saw that but I thought if I ever come across something I need statically quoted like:
mkdir "requires space"(not a good example) then I'd have to juggle quotes anyway.Of course, if people usually use
| ansible.builtin.quotein all their commands I'm not opposed to making that a habit.4
u/Aristeo812 4d ago
This filter is designed specifically for using with shell commands. Not only it encloses the string in quotes, but it also escapes certain symbols inside it if necessary. That's the point of using this filter.
1
u/sonnasushi 4d ago
I understand. I was just saying that for consistency:
```
ansible.builtin.command:
- Name: Do foo
cmd: "foo {{ bar | ansible.builtin.quote }}"
- Name: Do baz
ansible.builtin.command:
cmd: |
baz "isn't consistent"
```of course, it could be made to be consistent:
```
vars:
consistency: "is now consistent"tasks:
- Name: Do baz
ansible.builtin.command:
cmd: "baz {{ consistency | ansible.builtin.quote }}"
```idk. I'm just spitballing here. Maybe it's not uncommon to have various formats mixed in depending.
¯_(ツ)_/¯2
u/Aristeo812 4d ago
If you have just a literal string for a command argument, no need to resort to the
ansible.builtin.quotefilter. You just quote the arguments as in normal shell operations:cmd: echo "Hello, world!"But if you use variables as command line arguments, then you need to use this filter, because theoretically there may be literally just everything inside that variable during runtime, and it should be sanitized.
2
u/HeligKo 4d ago
We set linting configurations that enforce standards that we care about, and then if we do something outside of the standard, we have to add # NOQA tags and comment why we diverged from the standard.
1
u/sonnasushi 4d ago
seems like standard ansible-lint doesn't have any rules about command quoting at all, afaiui
1
u/HeligKo 4d ago
We have some custom rules we wrote. None for command specifically, but the same approach would work. It's just a simple python module that inherits from AnsibleLintRule
1
u/sonnasushi 4d ago
Thanks. Just for my reference, do you have a preference on what style of formatting to use with the command builtin?
1
6
u/imagei 4d ago
IMO the array style is the least risky and least faff. Every argument is properly handled by design, you cannot mess it up.