In an effort to support dynamic key-value pairs in Ansible, I am looking to update an existing role which creates an AWS SSM activation to allow the passing of arbitrary tags during runtime.
So far, I have tried leveraging the following Ansible constructs, all to no success: list variable, dict variable, loop, with_dict, with_items and native Python dict methods.
Here are some details on my Ansible environment:
- Ansible version: 2.9.23
- AWS CLI version: 1.18.147
- Python version: 3.7.10
- AWS SSM command reference: https://docs.aws.amazon.com/cli/latest/reference/ssm/create-activation.html
The current role/command with hard-coded tags looks like so:
- name: Generate SSM activation code and ID
command: |
aws ssm create-activation
--tags "Key=key1,Value=value1" "Key=key2,Value=value2"
register: ssm_activation_code
The idea is to update it to look like so:
name: Generate SSM activation code and ID
command: |
aws ssm create-activation
--tags "Key={{ item.key }},Value={{ item.value }}"
register: ssm_activation_code
with_items: "{{ aws_ssm_instance_tags }}"
And have the consumer of the role pass tags like so:
- role: ansible-role-aws-sm-agent
vars:
aws_ssm_instance_tags: {
"key1": "value1",
"key2": "value2",
.....
}
The issue with all loop structures is that the task runs once for each key-value pair, resulting in multiple SSM activations, which is incorrect. Instead, I would like to pass all tags in a single execution. I am happy to provide any additional details if needed. Any help on this is greatly appreciated.