Ansible执行Windows更新时WinRMOperationTimeoutError问题排查求助
问题场景
在Alpine:3.15环境下,使用Ansible Playbook为Windows Server 2019安装安全更新时,出现WinRM超时警告:
TASK [windows_roles : Install all security updates with automatic reboots] *****************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************
Friday 02 June 2023 08:56:04 +0000 (0:00:12.150) 0:00:12.255 ***********
[WARNING]: ERROR DURING WINRM SEND INPUT - attempting to recover: WinRMOperationTimeoutError
相同Playbook、运行器及网络环境下,其他Windows服务器可正常执行。
相关配置信息
Ansible Playbook内容
- name: Install all security updates with automatic reboots ansible.windows.win_updates: category_names: - SecurityUpdates - CriticalUpdates reboot: yes # Optionally, you can increase the reboot_timeout to survive long updates during reboot - name: Ensure we wait long enough for the updates to be applied during reboot ansible.windows.win_updates: reboot: yes reboot_timeout: 3600
WinRM配置
ansible_connection: "winrm" ansible_password: ((service-account-awx.password)) ansible_port: 5985 ansible_user: ((service-account-awx.username)) ansible_winrm_transport: "kerberos" ansible_winrm_kerberos_delegation: "true"
排查思路
- 检查目标服务器资源占用:更新安装过程中CPU、内存、磁盘IO可能冲高,导致WinRM服务响应缓慢。登录目标服务器,查看任务管理器的资源使用情况,确认是否存在资源耗尽的情况。
- 调整WinRM超时参数:在Ansible的WinRM配置中添加超时相关参数,默认
ansible_winrm_operation_timeout_sec为30秒、ansible_winrm_read_timeout_sec为300秒,针对更新场景可适当调大,示例配置:ansible_winrm_operation_timeout_sec: 180 ansible_winrm_read_timeout_sec: 7200 - 验证目标服务器WinRM服务状态:在目标Windows服务器上执行
winrm get winrm/config,检查WinRM的MaxTimeoutms是否过低;同时确认WinRM服务是否正常运行,有无频繁重启的情况。 - 排查网络层面延迟:在Alpine运行器上,用
ping和telnet测试与目标服务器的连通性及延迟,查看是否存在丢包或过高延迟;也可使用traceroute排查网络链路是否有瓶颈。 - 检查目标服务器更新队列:目标服务器可能存在未完成的更新任务或损坏的更新缓存,登录服务器后,打开「设置-更新和安全- Windows更新」,查看是否有挂起或失败的更新记录;可尝试手动清理缓存:停止Windows Update服务,删除
C:\Windows\SoftwareDistribution\Download下的文件,再重启服务。 - 验证Kerberos票据有效性:因使用Kerberos认证,检查运行器上的Kerberos票据是否在更新过程中过期。在Alpine上执行
klist查看票据有效期,若有效期过短,可调整Kerberos配置延长时长,或在Playbook中添加票据刷新步骤。 - 查看目标服务器事件日志:在Windows服务器的事件查看器中,查看「Windows日志-系统」和「Windows日志-应用程序」中与WinRM、Windows Update相关的错误日志,定位具体失败原因。
内容的提问来源于stack exchange,提问作者alphax

