You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Ansible进行MySQL服务器补丁更新时,委托后台服务器执行任务出现SSH连接异常问题排查

Fixing Ansible Delegate_to & Windows Connection Issues for Stopping Services

Let's break down the problems in your playbook and fix them step by step:

First, here's the corrected playbook

---
- name: MySQL Server Patch Update with Pre-Tasks
  hosts: "{{ host }}"
  gather_facts: no
  serial: 1
  tasks:
    - name: Stop all running services01 on QA background servers
      ansible.windows.win_powershell:
        script: |
          Stop-Service -DisplayName 'services01*' -Force -ErrorAction SilentlyContinue
      delegate_to: "{{ item }}"
      loop: "{{ groups['qa_bg_servers'] }}"

Key Issues & Fixes

  1. Broken Playbook Structure
    Your original code had two separate plays (each - name: block counts as a play), and the second play had no hosts defined. On top of that, you used background_servers as a delegate target—a variable that doesn't exist in your setup. We've moved the stop-service task into the main play's tasks section, and now directly reference your existing qa_bg_servers host group.

  2. Wrong Connection Method for Windows Hosts
    The error shows Ansible trying to connect to your Windows servers via SSH, which won't work—Windows uses WinRM for Ansible management. You need to update your inventory file for the qa_bg_servers group to specify WinRM settings:

    [qa_bg_servers]
    11.111.2.44 ansible_connection=winrm ansible_winrm_transport=ntlm ansible_winrm_server_cert_validation=ignore ansible_user=your_windows_username ansible_password=your_windows_password
    

    Pro tip: Store sensitive credentials in an Ansible vault instead of plaintext for security.

  3. Delegating to a Host Group
    To run the task on all 3 servers in qa_bg_servers, we use loop: "{{ groups['qa_bg_servers'] }}" paired with delegate_to: "{{ item }}". This ensures the stop-service command runs on every server in your target group one by one.

  4. Robust PowerShell Script
    I added -Force to ensure stubborn services get stopped, and -ErrorAction SilentlyContinue to avoid failures if some services01 instances aren't running (adjust this if you want to be notified of missing services instead).

Quick Validation Steps

  • Test WinRM connectivity first: Run ansible qa_bg_servers -m win_ping from your Ansible controller. If this succeeds, your WinRM setup is correct.
  • Verify your inventory has the correct IPs for qa_bg_servers and that the controller can reach those Windows hosts on ports 5985 (HTTP) or 5986 (HTTPS).

内容的提问来源于stack exchange,提问作者shine12

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 17:07:37