You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible主机组创建与引用方法及Windows节点补丁排障求助

Docker Swarm Windows节点补丁自动化问题

我正在开发一套补丁解决方案,需要逐个将Windows worker节点置为drain状态、安装所有可用Windows补丁后恢复为active状态。环境中manager节点运行Linux,worker节点运行Windows(业务应用不兼容Linux)。目前尝试通过manager节点向worker节点发送drain命令时遇到问题:playbook设置了serial:1逐个处理节点,用delegate_to指定在manager节点执行docker node update命令,但报错'workernode' is undefined;直接指定节点名称时playbook可正常运行,引用主机组则失败。


现有Playbook内容

---
- hosts: all
  serial: 1 #to make sure we are only hitting a single worker node at a time

  tasks: 
    - name: drain worker node
      shell: docker node update --availability drain "{{ workernode }}"
      delegate_to: "{{ managernode }}" #run drain command from management node
      become: true

Inventory配置

[managernode]
FBLDKRDEVLD08.develop.fcbt

[workernode]
FBLDKRDEVWD02.develop.fcbt
FBLDKRDEVWD03.develop.fcbt
FBLDKRDEVWD04.develop.fcbt
FBLDKRDEVWD05.develop.fcbt
FBLDKRDEVWD09.develop.fcbt
FBLDKRDEVWD10.develop.fcbt
FBLDKRDEVWD11.develop.fcbt
FBLDKRDEVWD12.develop.fcbt
FBLDKRDEVWD13.develop.fcbt

错误信息

fatal: [FBLDKRDEVLD08.develop.fcbt -> {{ managernode }}]: FAILED! =>
{"msg": "The task includes an option with an undefined variable. The
error was: 'workernode' is undefined

The error appears to be in
'/runner/project/ansible/Server Tasks/Swarm_Patching_Test.yml': line
8, column 7, but may
be elsewhere in the file depending on the exact
syntax problem.

The offending line appears to be:


    - name:
drain worker node
      ^ here
"}

问题分析与修复

  1. 变量未定义原因:workernode是inventory中的主机组名,并非可直接引用的变量。当playbook遍历节点时,当前处理的节点主机名需要用inventory_hostname变量获取。
  2. delegate_to变量问题:managernode是主机组名,需通过groups['managernode'][0]引用组内的manager节点地址。

修复后的Playbook

---
- hosts: workernode  # 直接指定目标为workernode组,避免遍历manager节点
  serial: 1

  tasks: 
    - name: drain worker node
      shell: docker node update --availability drain "{{ inventory_hostname }}"
      delegate_to: "{{ groups['managernode'][0] }}"
      become: true

额外优化建议

  • 若需后续恢复节点为active状态,可添加对应任务:
- name: restore worker node to active
      shell: docker node update --availability active "{{ inventory_hostname }}"
      delegate_to: "{{ groups['managernode'][0] }}"
      become: true
      # 可在补丁安装完成后执行此任务
  • 使用win_updates模块处理Windows补丁安装,无需手动执行命令:
- name: install all available Windows updates
      win_updates:
        category_names:
          - CriticalUpdates
          - SecurityUpdates
          - UpdateRollups
        state: installed
      # 此任务直接在Windows worker节点执行,无需代理

内容的提问来源于stack exchange,提问作者jwilson0122

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 00:27:53