同一Ansible Playbook中不同任务的多连接配置问题求助
问题解决:Ansible切换连接方式执行不同任务
现有Playbook结构
main.yml内容如下:
- name: Install ncpa import_tasks: windows_ncpa.yml when: ansible_facts['os_family']|lower == 'windows' - name: Register XI import_tasks: register_with_xi.yml
任务连接需求
- Windows主机NCPA安装任务(
windows_ncpa.yml):通过WINRM连接执行,可正常运行:
- name: Create download directory win_file: path: C:\\tmp state: directory - name: Copy the executable package to download directory win_copy: src: software/ncpa-2.4.1.exe dest: 'C:\tmp\ncpa-2.4.1.exe' - name: Install NCPA win_package: path: 'C:\tmp\ncpa-2.4.1.exe' arguments: /S /TOKEN='{{ ncpa_token }}' product_id: '{ncpa}' - name: Restart NCPA win_service: name: ncpalistener state: restarted
- Nagios XI注册任务(
register_with_xi.yml):需要通过SSH连接Linux主机执行,但当前执行时始终沿用WINRM连接,导致报错:
原任务代码:
--- - name: Register Host uri: url: "http://{{ xi_ip }}/nagiosxi/api/v1/config/host?apikey={{ xi_api_key }}" body: 'host_name={{ ansible_fqdn }}&address={{ ansible_fqdn }}&check_command=check-host-alive&max_check_attempts=32&check_period=24x7&contacts=nagiosadmin¬ification_interval=25¬ification_period=24x7&hostgroups=grp_so_windows&alias=Consola para soporte sistemas&use=t_host_windows,t_host_ncpa_token1&applyconfig=1&force=1' method: POST validate_certs: no
报错信息
TASK [ncpa_install_windows : Register Host] ********************************************************************************************************************************************************************************************** task path: */ncpa_install_windows/tasks/register_with_xi.yml:2 <*> ESTABLISH WINRM CONNECTION FOR USER: ansible on PORT 5986 TO * fatal: [*]: UNREACHABLE! => { "changed": false, "msg": "kerberos: authGSSClientStep() failed: (('Unspecified GSS failure. Minor code may provide more information', 851968), ('Server not found in Kerberos database', -1765328377))", "unreachable": true }
错误原因及解决方案
问题核心是注册任务默认沿用了之前Windows主机的WINRM连接上下文,需明确切换连接目标和方式。
修改后的register_with_xi.yml配置如下(以委派到Linux主机为例):
--- - name: Clear WINRM connection context meta: reset_connection - name: Register Host to Nagios XI vars_files: - group_vars/common.yml delegate_to: <你的Linux主机IP或主机名> connection: ssh uri: url: "http://{{ xi_ip }}/nagiosxi/api/v1/config/host?apikey={{ xi_api_key }}" body_format: form-urlencoded body: host_name: "{{ ansible_fqdn }}" address: "{{ ansible_fqdn }}" check_command: check-host-alive max_check_attempts: 32 check_period: 24x7 contacts: nagiosadmin notification_interval: 25 notification_period: 24x7 hostgroups: grp_so_windows alias: "Consola para soporte sistemas" use: "t_host_windows,t_host_ncpa_token1" applyconfig: 1 force: 1 method: POST validate_certs: no
关键修改点:
- 添加
meta: reset_connection:清除之前的WINRM连接上下文,确保后续任务使用新配置。 - 配置
delegate_to:指定执行该任务的Linux主机(若直接从控制节点调用API,可设为localhost)。 - 指定
connection: ssh:强制使用SSH连接目标主机。 - 优化请求体格式:用
body_format: form-urlencoded加字典格式body,比字符串拼接更清晰、不易出错。
如果直接从Ansible控制节点(本地)调用Nagios API,可简化为:
--- - name: Clear WINRM connection context meta: reset_connection - name: Register Host to Nagios XI vars_files: - group_vars/common.yml delegate_to: localhost connection: local uri: url: "http://{{ xi_ip }}/nagiosxi/api/v1/config/host?apikey={{ xi_api_key }}" body_format: form-urlencoded body: host_name: "{{ ansible_fqdn }}" address: "{{ ansible_fqdn }}" check_command: check-host-alive max_check_attempts: 32 check_period: 24x7 contacts: nagiosadmin notification_interval: 25 notification_period: 24x7 hostgroups: grp_so_windows alias: "Consola para soporte sistemas" use: "t_host_windows,t_host_ncpa_token1" applyconfig: 1 force: 1 method: POST validate_certs: no
注意事项:
- 确保
group_vars/common.yml中xi_ip和xi_api_key配置正确。 - 若委派到
localhost,无需额外become配置(调用API通常不需要本地提权)。
内容的提问来源于stack exchange,提问作者Bizargorri
相关产品推荐
相关产品推荐

