You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible跨Linux与Windows执行服务器补丁备份任务遇冲突求助

解决跨系统Ansible任务执行的Become插件冲突问题

针对你遇到的The powershell shell family is incompatible with the sudo become plugin错误,核心原因是委托到Windows主机时继承了原Linux主机的become: yes配置,而Windows不支持sudo插件。以下是具体的解决步骤和示例:

1. 关键修正:在委托任务时直接禁用Become

become是任务级别的执行参数,不能放在vars块中配置,需要直接在include_role或task上声明become: no,覆盖原play的全局become设置:

- name: 调用Veeam备份角色(委托到Windows服务器)
  include_role:
    name: veeam_activities
  delegate_to: your_veeam_server_hostname
  become: no  # 强制禁用become,避免sudo插件冲突
  vars:
    # 传递需要备份的Linux主机名到角色
    backup_target_host: "{{ inventory_hostname }}"

2. 为Windows Veeam服务器单独配置连接参数

避免继承Linux主机的SSH连接设置,建议通过Inventory或Group Vars配置Windows专属连接变量:

方式1:在Inventory中直接配置

[linux_servers]
linux_host1.example.com
linux_host2.example.com

[veeam_servers]
veeam_server.example.com ansible_connection=winrm ansible_winrm_transport=ntlm ansible_winrm_server_cert_validation=ignore ansible_user=DOMAIN\admin ansible_password=your_win_password

方式2:使用Group Vars统一管理

创建group_vars/veeam_servers.yml文件,写入Windows连接配置:

ansible_connection: winrm
ansible_winrm_transport: ntlm
ansible_winrm_server_cert_validation: ignore
ansible_user: "DOMAIN\\admin"
ansible_password: "your_win_password"
ansible_shell_type: powershell

3. 完整Playbook示例

---
- name: Linux服务器补丁安装前执行Veeam备份
  hosts: linux_servers
  gather_facts: true
  become: yes  # Linux主机执行补丁操作需要sudo,全局启用

  tasks:
    - name: 触发Veeam对当前Linux主机的备份
      include_role:
        name: veeam_activities
      delegate_to: veeam_server.example.com
      become: no  # 针对Windows任务禁用become
      vars:
        backup_target: "{{ inventory_hostname }}"

    # 以下是Linux补丁安装任务
    - name: RHEL/CentOS系列安装系统补丁
      yum:
        name: '*'
        state: latest
      when: ansible_os_family == 'RedHat'

    - name: Debian/Ubuntu系列安装系统补丁
      apt:
        upgrade: dist
        update_cache: true
      when: ansible_os_family == 'Debian'

额外检查点

  • 确认veeam_activities角色内的任务没有强制设置become: yes,如果有,需在角色的defaults/main.yml中添加become: no,或在include_role时通过vars: { become: no }覆盖
  • 确保Windows主机的WinRM服务已正确配置,允许Ansible连接

内容的提问来源于stack exchange,提问作者Naga

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 12:43:11