Use Ansible to Transfer Files to or from Junos Devices
Use the juniper.device.file_copy module to copy a file between the
Ansible control node and Junos devices.
Juniper Networks provides an Ansible module that you can use to transfer a file between
the Ansible control node and a Junos device. Table 1 outlines the available
module. Ansible also provides standard built-in modules to handle file operations. This
topic discusses how to use the juniper.device.file_copy module.
|
Collection |
Module Set |
Module Name |
|---|---|---|
|
|
||
junipernetworks.junos |
– |
juniper.device.file_copy Module Overview
You can use the juniper.device.file_copy
module to transfer a file between the Ansible control node and a Junos device. Table 2 outlines the module arguments. You must include the action
argument to specify the direction of transfer. You must also specify the local and
remote directories as well as the filename of the file to transfer. You can
optionally include the transfer protocol and destination filename.
|
Module Argument |
Description |
|---|---|
|
|
Action to perform. Specify whether to copy the file to or from the remote device.
|
|
|
(Optional) Specify whether to validate the MD5 checksum of the file.
|
|
|
Filename of the file to copy. |
|
|
Directory on the local Ansible control node. |
|
|
(Optional) Protocol to use for the file transfer.
|
|
|
Directory on the remote device. |
|
|
(Optional) Filename of the destination file. If you omit this parameter, the destination file uses the same filename as the source file. |
By default, the juniper.device.file_copy module uses the SCP
protocol and validates the file checksum to verify the integrity of the copied file.
The file_copy module reports a successful transfer if the module
copies the file to the destination directory and the checksum of the copied file
matches the checksum of the original file.
In some cases, the transfer is successful but the module reports that the task failed
because the checksums do not match. A checksum mismatch might happen if the file is
corrupted during transfer. It can also happen if you transfer a large log file that
is updated frequently. In this case, if the file is updated as it is being
transferred, the transferred file can differ slightly from the original file causing
a checksum mismatch. In these cases, you can set checksum: false to
skip the checksum validation. However, we recommend keeping the checksum validation
for file transfers.
Transfer a File from the Remote Device
You can use the juniper.device.file_copy module to copy a file
from a Junos device to the Ansible control node. For example, you might want to
periodically archive the configuration file or a log file on a device. To
transfer a file from the remote device, specify
action: get.
The following playbook transfers the messages log file from
each device in the inventory group into a logs directory on
the Ansible control node. The module arguments explicitly specify the transfer
protocol as scp, which is the default. The module uses a unique
host-specific filename for each destination file so that each copied file
doesn't overwrite the previous file.
---
- name: Archive the messages log file
hosts: junos
connection: local
gather_facts: false
vars:
host_log_dir: "logs"
source_file: "messages"
tasks:
- name: Create the destination directory
ansible.builtin.file:
path: "{{ host_log_dir }}"
state: directory
run_once: true
- name: Copy the log file from remote device
juniper.device.file_copy:
action: get
file: "{{ source_file }}"
local_dir: "{{ host_log_dir }}"
protocol: scp
remote_dir: /var/log
transfer_filename: "{{ inventory_hostname }}-{{ source_file }}"When you execute the playbook, it first creates a logs directory. The playbook then copies the messages log file from each device to the destination directory and saves each file with a unique filename. Although the copy task appears to fail for all hosts, the file transfer is actually successful. In this case, the Junos devices continue to update the log file as the transfer occurs. As a result, the checksum comparison between the local file and the remote file fails because the original and copied files differ slightly.
user@ansible-cn:~$ ansible-playbook ansible-pb-archive-logs.yaml
PLAY [Archive the messages log file] ************************************************
TASK [Create the destination directory] *********************************************
ok: [r1]
TASK [Copy the log file from remote device] *****************************************
fatal: [r2]: FAILED! => {"changed": false, "msg": "Transfer failed (different MD5 between local and remote) 0b36d9e93cfd523b79eee5927ed42b68 | 3ea1421a5f68476c853180213df96686"}
fatal: [r3]: FAILED! => {"changed": false, "msg": "Transfer failed (different MD5 between local and remote) 7bac31566e5ec8da16d2a199dda628a6 | 40acb378a5e2b7aeacda3eb0337b5bec"}
fatal: [r1]: FAILED! => {"changed": false, "msg": "Transfer failed (different MD5 between local and remote) 7566d1efa73b50081dfee04aa4dbde57 | 2fce0d8a7272fe7e528786dade8cbe1f"}
PLAY RECAP **************************************************************************
r1 : ok=1 changed=0 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0
r2 : ok=0 changed=0 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0
r3 : ok=0 changed=0 unreachable=0 failed=1 skipped=0 rescued=0 ignored=0
A review of the logs directory indicates that the messages log is archived for each host.
user@ansible-cn:~$ ls -l logs -rw-rw-r-- 1 user admin 459462 Jan 10 21:10 r1-messages -rw-rw-r-- 1 user admin 373848 Jan 10 21:10 r2-messages -rw-rw-r-- 1 user admin 374433 Jan 10 21:10 r3-messages
In cases where you know the checksum validation will fail, you can optionally
include checksum: false to skip the validation. If you execute
the previous playbook and skip the checksum validation, the task reports
"changed": true for all hosts.
user@ansible-cn:~$ ansible-playbook ansible-pb-archive-logs.yaml PLAY [Archive the messages log file] ************************************************ TASK [Create the destination directory] ********************************************* ok: [r1] TASK [Copy the log file from remote device] ***************************************** changed: [r1] changed: [r2] changed: [r3] PLAY RECAP ************************************************************************** r1 : ok=2 changed=1 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 r2 : ok=1 changed=1 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 r3 : ok=1 changed=1 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0
Transfer a File to the Remote Device
You can use the juniper.device.file_copy module to copy a file from
the Ansible control node to a Junos device. To transfer the file to the remote
device, specify action: put.
The following playbook copies the bgp.slax script from the Ansible control node to each host in the specified inventory group. The script is copied from the playbook's scripts directory to the /var/db/scripts/op directory on the Junos device.
---
- name: Copy script to the Junos device
hosts: junos
connection: local
gather_facts: false
tasks:
- name: Copy a local script to the Junos device
juniper.device.file_copy:
action: put
file: bgp.slax
local_dir: scripts
remote_dir: /var/db/scripts/op