从Ubuntu用Ansible在Windows运行Docker Compose报错求助
问题
通过Ubuntu使用Ansible管理Windows机器,已成功传输包含Docker Compose文件的目标文件,但执行Ansible启动Docker Compose时出现错误:
error getting credentials - err: exit status 1, out: The specified session does not exist. It may have been closed earlier.
手动在Windows机器执行docker compose up -d可正常运行。
环境配置:
- 通过WinRM连接Windows机器
- Windows已安装Docker Desktop
- Ansible Playbook包含安装Docker、复制文件、启动应用步骤,相关配置如下:
Docker Compose Playbook文件
--- - name: Deploy Redis on Windows hosts: redis_hosts vars_files: - ./vars.yml tasks: - name: Ensure Docker is installed win_chocolatey: name: docker-desktop state: present - name: Create application directory win_file: path: "{{ app_files_dest }}" state: directory - name: Copy application files win_copy: src: "{{ app_files_src }}/" dest: "{{ app_files_dest }}" - name: Start the application with Docker Compose win_command: docker compose -f redis.yml up -d args: chdir: "{{ app_files_dest }}"
inventory.ini配置
[windows] 192.168.2.152 ansible_user=w10 ansible_password=1 ansible_connection=winrm ansible_winrm_transport=basic ansible_port=5985 ansible_winrm_scheme=http
vars.yml配置
app_files_src: "{{ file_path }}/cache" app_files_dest: 'C:\app\cache'
原因分析
核心问题是WinRM会话未加载Docker Desktop的用户上下文:
- Docker Desktop在Windows上是用户级服务,依赖当前登录用户的会话(包括凭据缓存、Docker守护进程连接上下文)
- Ansible通过WinRM执行命令时,默认使用非交互式会话,不会加载用户桌面会话的环境变量和凭据缓存,导致Docker无法找到有效会话
- 手动执行时处于用户交互式桌面会话,Docker能正常访问用户的凭据和守护进程连接
解决方法
方法1:将Docker Desktop设为系统服务运行
修改Docker Desktop设置,脱离用户会话依赖:
- 在Windows机器打开Docker Desktop设置
- 进入General选项卡,勾选"Use the WSL 2 based engine"(若使用WSL后端),或切换到Windows容器后端
- 找到Start Docker Desktop when you log in选项,选择"Run as a service"(部分版本在General或Advanced设置中)
- 重启Docker Desktop,之后WinRM会话可直接访问Docker守护进程
方法2:在Ansible任务中加载用户环境
WinRM默认不加载用户环境变量,可显式设置Docker相关环境或加载用户profile:
修改启动任务为:
- name: Start application with Docker Compose win_shell: | $env:PATH += ";C:\Program Files\Docker\Docker\resources\bin" docker compose -f redis.yml up -d args: chdir: "{{ app_files_dest }}" executable: cmd.exe environment: DOCKER_HOST: "npipe:////./pipe/docker_engine"
或加载用户profile执行:
- name: Start application with Docker Compose win_shell: | powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "& {docker compose -f redis.yml up -d}" args: chdir: "{{ app_files_dest }}" environment: USERPROFILE: "C:\\Users\\w10"
方法3:重新登录Docker注册表(若使用私有镜像)
如果是凭据缓存失效,可在启动前重新登录Docker:
- name: Login to Docker registry win_command: docker login -u <你的用户名> -p <你的密码> <注册表地址> args: chdir: "{{ app_files_dest }}" no_log: true # 避免密码泄露 - name: Start application with Docker Compose win_command: docker compose -f redis.yml up -d args: chdir: "{{ app_files_dest }}"
方法4:调整WinRM连接参数
在inventory.ini中添加会话超时和加密参数,确保会话稳定性:
[windows] 192.168.2.152 ansible_user=w10 ansible_password=1 ansible_connection=winrm ansible_winrm_transport=basic ansible_port=5985 ansible_winrm_scheme=http ansible_winrm_operation_timeout_sec=60 ansible_winrm_read_timeout_sec=70 ansible_winrm_message_encryption=auto
内容的提问来源于stack exchange,提问作者rumeysa yuk
相关产品推荐
相关产品推荐

