在Windows服务器上通过Rundeck运行Ansible任务失败求助
在Windows服务器上通过Rundeck运行Ansible任务时出现以下错误,但通过CLI执行相同Ansible代码完全正常,且Rundeck的节点发现功能也能正常工作。当前通过SSH而非WinRM连接Windows服务器,附上相关代码和配置,寻求解决方法。
错误信息
{"changed": false, "msg": "Failed to create temporary directory. In some cases, you may have been able to authenticate and did not have permissions on the target directory. Consider changing the remote tmp path in ansible.cfg to a path rooted in \"/tmp\", for more error information use -vvv. Failed command was: ( umask 77 && mkdir -p \"` echo ~/.ansible/tmp `\"&& mkdir \"` echo ~/.ansible/tmp/ansible-tmp-xxxxxxx `\" && echo ansible-tmp-xxxxxxxx=\"` echo ~/.ansible/tmp/ansible-tmp-xxxxx `\" ), exited with result 1", "unreachable": true}
相关代码与配置
Ansible Playbook内联工作流节点步骤
- name: Example from an Ansible Playbook hosts: server1 tasks: - win_ping:
Rundeck项目配置
project.ansible-binaries-dir-path=/usr/bin project.ansible-config-file-path=/etc/ansible/ansible.cfg project.ansible-generate-inventory=true project.ansible-ssh-auth-type=privateKey project.ansible-ssh-key-storage-path=keys/project/TestProject/Ansible_Test project.ansible-ssh-passphrase-option=option.password project.ansible-ssh-user=ansible project.ansible-windows-executable=powershell.exe project.description= project.disable.executions=false project.disable.schedule=false project.execution.history.cleanup.batch=500 project.execution.history.cleanup.enabled=false project.execution.history.cleanup.retention.days=60 project.execution.history.cleanup.retention.minimum=50 project.execution.history.cleanup.schedule=0 0 0 1/1 * ? * project.jobs.gui.groupExpandLevel=1 project.keep-alive-max-alive-count=5 project.label= project.later.executions.disable=false project.later.executions.enable=false project.later.schedule.disable=false project.later.schedule.enable=false project.name=TestProject project.nodeCache.enabled=true project.nodeCache.firstLoadSynch=true project.output.allowUnsanitized=false project.retry-counter=3 project.ssh-authentication=privateKey resources.source.1.config.ansible-gather-facts=true resources.source.1.config.ansible-ignore-errors=true resources.source.1.config.ansible-inventory=/etc/rundeck/ansible_repo.yml resources.source.1.config.ansible-ssh-auth-type=privateKey resources.source.1.config.ansible-ssh-key-storage-path=keys/project/TestProject/Ansible_Test resources.source.1.config.ansible-ssh-user=ansible resources.source.1.type=com.batix.rundeck.plugins.AnsibleResourceModelSourceFactory resources.source.2.type=local service.FileCopier.default.provider=sshj-scp service.NodeExecutor.default.provider=com.batix.rundeck.plugins.AnsibleNodeExecutor
解决方案
配置Windows兼容的远程临时目录:
编辑Ansible配置文件/etc/ansible/ansible.cfg,在[defaults]段添加Windows路径的临时目录配置:[defaults] remote_tmp = C:\Windows\Temp\ansible-tmp确保
ansible用户对该目录拥有读写权限,可手动登录Windows服务器验证权限。在Playbook中临时覆盖配置:
如果不想修改全局Ansible配置,可在Playbook中直接指定临时目录:- name: Example from an Ansible Playbook hosts: server1 vars: ansible_remote_tmp: C:\Windows\Temp\ansible-tmp tasks: - win_ping:验证Rundeck执行上下文的配置读取权限:
确认Rundeck服务运行用户能读取/etc/ansible/ansible.cfg文件,且配置中的路径对该用户有效。检查Ansible节点执行器插件的Windows参数:
确认Rundeck配置中的project.ansible-windows-executable=powershell.exe已生效,避免插件使用类Unix的Shell命令(如mkdir、umask)在Windows环境执行,导致目录创建失败。手动验证SSH用户的目录创建权限:
通过SSH登录Windows服务器的ansible用户,手动执行New-Item -Path C:\Windows\Temp\ansible-tmp -ItemType Directory命令,确认能成功创建目录,排除权限问题。
内容的提问来源于stack exchange,提问作者Ben Gnom

