You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用puppet-r10k模块部署r10k-webhook时遇连接拒绝问题求助

问题

我使用puppet-r10k模块部署r10k环境,配置如下:

node 'puppet-master.example.com' {
  class { 'r10k':
    sources => {
      'puppet' => {
        'remote'  => 'git@test-gitlab.example.com:puppet/control-repository.git',
        'basedir' => "${::settings::codedir}/environments",
        'prefix'  => false,
      },
    },
  }

  class { 'r10k::webhook':
    ensure => true,
    server => {
      protected => false,
    },
  }
}

配置完成后生成了两个文件:

/etc/voxpupuli/webhook.yml

---
server:
  protected: false
chatops:
  enabled: false
  service:
  channel:
  user:
  auth_token:
  server_uri:
r10k:
  command_path: "/opt/puppetlabs/puppet/bin/r10k"
  config_path: "/etc/puppetlabs/r10k/r10k.yaml"
  default_branch: production
  prefix:
  allow_uppercase: false
  verbose: true
  deploy_modules: true
  generate_types: true

/etc/puppetlabs/r10k/r10k.yaml

---
pool_size: 2
deploy:
  generate_types: true
  exclude_spec: true
cachedir: "/opt/puppetlabs/puppet/cache/r10k"
sources:
  puppet:
    remote: git@test-gitlab.example.com:puppet/control-repository.git
    basedir: "/etc/puppetlabs/code/environments"
    prefix: false

在GitLab服务器(192.168.1.50)添加webhook,URL为http://192.168.1.52:8088/payload,但出现错误:

Hook execution failed: Failed to open TCP connection to 192.168.1.52:8088 (Connection refused - connect(2) for "192.168.1.52" port 8088)

请问我是否遗漏了配置步骤?应该先执行哪些操作?


排查与解决步骤

1. 确认r10k webhook服务状态

在puppet master节点(192.168.1.52)执行命令检查服务是否启动:

systemctl status voxpupuli-webhook

若服务未启动,启动并设置开机自启:

systemctl start voxpupuli-webhook
systemctl enable voxpupuli-webhook

2. 检查端口8088监听状态

在puppet master节点执行以下命令,确认端口是否被webhook服务占用:

ss -tulpn | grep 8088

如果无监听记录,查看服务启动日志排查故障:

journalctl -u voxpupuli-webhook -f

3. 验证网络连通性与防火墙规则

  • 在GitLab服务器测试与puppet master的端口连通性:
    nc -zv 192.168.1.52 8088
    
  • 在puppet master节点检查防火墙是否放行8088端口:
    # firewalld环境
    firewall-cmd --list-ports | grep 8088
    # 若未放行,添加规则
    firewall-cmd --add-port=8088/tcp --permanent
    firewall-cmd --reload
    
    # iptables环境
    iptables -L INPUT -n | grep 8088
    # 若未放行,添加规则
    iptables -A INPUT -p tcp --dport 8088 -j ACCEPT
    service iptables save
    

4. 修正webhook监听配置

检查/etc/voxpupuli/webhook.yml,确保服务监听所有网卡(而非仅本地回环):

server:
  protected: false
  host: 0.0.0.0
  port: 8088

修改后重启服务:

systemctl restart voxpupuli-webhook

5. 本地测试webhook端点

在puppet master本地发起请求,验证服务是否正常响应:

curl http://localhost:8088/payload

若返回{"message":"Invalid request format"},说明服务运行正常,问题出在网络层面;若仍提示连接拒绝,需重新排查服务启动故障。


内容的提问来源于stack exchange,提问作者CosciaDiPolloo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 00:09:53