You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

同一Ansible Playbook中不同任务的多连接配置问题求助

问题解决:Ansible切换连接方式执行不同任务

现有Playbook结构

main.yml内容如下:

- name: Install ncpa
  import_tasks: windows_ncpa.yml
  when: ansible_facts['os_family']|lower == 'windows'

- name: Register XI
  import_tasks: register_with_xi.yml

任务连接需求

  1. Windows主机NCPA安装任务(windows_ncpa.yml):通过WINRM连接执行,可正常运行:
- name: Create download directory
  win_file:
    path: C:\\tmp
    state: directory

- name: Copy the executable package to download directory
  win_copy:
    src: software/ncpa-2.4.1.exe
    dest: 'C:\tmp\ncpa-2.4.1.exe'

- name: Install NCPA
  win_package:
    path: 'C:\tmp\ncpa-2.4.1.exe'
    arguments: /S /TOKEN='{{ ncpa_token }}'
    product_id: '{ncpa}'

- name: Restart NCPA
  win_service:
    name: ncpalistener
    state: restarted
  1. Nagios XI注册任务(register_with_xi.yml):需要通过SSH连接Linux主机执行,但当前执行时始终沿用WINRM连接,导致报错:
    原任务代码:
---
- name: Register Host
  uri:
    url: "http://{{ xi_ip }}/nagiosxi/api/v1/config/host?apikey={{ xi_api_key }}"
    body: 'host_name={{ ansible_fqdn }}&address={{ ansible_fqdn }}&check_command=check-host-alive&max_check_attempts=32&check_period=24x7&contacts=nagiosadmin&notification_interval=25&notification_period=24x7&hostgroups=grp_so_windows&alias=Consola para soporte sistemas&use=t_host_windows,t_host_ncpa_token1&applyconfig=1&force=1'
    method: POST
    validate_certs: no

报错信息

TASK [ncpa_install_windows : Register Host] **********************************************************************************************************************************************************************************************
task path: */ncpa_install_windows/tasks/register_with_xi.yml:2
<*> ESTABLISH WINRM CONNECTION FOR USER: ansible on PORT 5986 TO *
fatal: [*]: UNREACHABLE! => {
    "changed": false,
    "msg": "kerberos: authGSSClientStep() failed: (('Unspecified GSS failure.  Minor code may provide more information', 851968), ('Server not found in Kerberos database', -1765328377))",
    "unreachable": true
}

错误原因及解决方案

问题核心是注册任务默认沿用了之前Windows主机的WINRM连接上下文,需明确切换连接目标和方式。

修改后的register_with_xi.yml配置如下(以委派到Linux主机为例):

---
- name: Clear WINRM connection context
  meta: reset_connection

- name: Register Host to Nagios XI
  vars_files:
    - group_vars/common.yml
  delegate_to: <你的Linux主机IP或主机名>
  connection: ssh
  uri:
    url: "http://{{ xi_ip }}/nagiosxi/api/v1/config/host?apikey={{ xi_api_key }}"
    body_format: form-urlencoded
    body:
      host_name: "{{ ansible_fqdn }}"
      address: "{{ ansible_fqdn }}"
      check_command: check-host-alive
      max_check_attempts: 32
      check_period: 24x7
      contacts: nagiosadmin
      notification_interval: 25
      notification_period: 24x7
      hostgroups: grp_so_windows
      alias: "Consola para soporte sistemas"
      use: "t_host_windows,t_host_ncpa_token1"
      applyconfig: 1
      force: 1
    method: POST
    validate_certs: no

关键修改点:

  • 添加meta: reset_connection:清除之前的WINRM连接上下文,确保后续任务使用新配置。
  • 配置delegate_to:指定执行该任务的Linux主机(若直接从控制节点调用API,可设为localhost)。
  • 指定connection: ssh:强制使用SSH连接目标主机。
  • 优化请求体格式:用body_format: form-urlencoded加字典格式body,比字符串拼接更清晰、不易出错。

如果直接从Ansible控制节点(本地)调用Nagios API,可简化为:

---
- name: Clear WINRM connection context
  meta: reset_connection

- name: Register Host to Nagios XI
  vars_files:
    - group_vars/common.yml
  delegate_to: localhost
  connection: local
  uri:
    url: "http://{{ xi_ip }}/nagiosxi/api/v1/config/host?apikey={{ xi_api_key }}"
    body_format: form-urlencoded
    body:
      host_name: "{{ ansible_fqdn }}"
      address: "{{ ansible_fqdn }}"
      check_command: check-host-alive
      max_check_attempts: 32
      check_period: 24x7
      contacts: nagiosadmin
      notification_interval: 25
      notification_period: 24x7
      hostgroups: grp_so_windows
      alias: "Consola para soporte sistemas"
      use: "t_host_windows,t_host_ncpa_token1"
      applyconfig: 1
      force: 1
    method: POST
    validate_certs: no

注意事项:

  • 确保group_vars/common.yml中xi_ip和xi_api_key配置正确。
  • 若委派到localhost,无需额外become配置(调用API通常不需要本地提权)。

内容的提问来源于stack exchange,提问作者Bizargorri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 01:47:52