You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible通过SSH密钥连接Windows主机执行win_ping无响应问题排查

Ansible通过SSH密钥连接Windows无响应问题排查方案
  • 检查Windows SSH服务子系统配置
    Windows OpenSSH默认未配置PowerShell为子系统,Ansible依赖它执行模块。修改C:\ProgramData\ssh\sshd_config,添加或确保存在以下行:

    Subsystem powershell c:/windows/system32/WindowsPowerShell/v1.0/powershell.exe -sshs -NoLogo -NoProfile
    

    重启OpenSSH服务:Restart-Service sshd

  • 确认Ansible连接参数配置
    在inventory或host_vars中明确Windows主机的连接参数:

    [win]
    windows_host_ip ansible_connection=ssh ansible_user=Administrator ansible_ssh_private_key_file=/home/ubuntu/.ssh/id_rsa ansible_shell_type=powershell
    

    注意Windows用户名格式,域用户需写成DOMAIN\username

  • 调整PowerShell执行策略
    Windows默认执行策略可能限制脚本运行,以管理员身份打开PowerShell执行:

    Set-ExecutionPolicy RemoteSigned -Force
    
  • 排查PowerShell初始化脚本阻塞
    重命名Windows用户目录下的Documents\WindowsPowerShell\profile.ps1(临时禁用初始化脚本),再测试ansible win -m win_ping,排除脚本导致的会话卡住问题

  • 修正密钥权限
    Ubuntu端私钥权限必须为600:

    chmod 600 ~/.ssh/your_private_key
    

    Windows端authorized_keys需放在C:\Users\<username>\.ssh\下,权限设置为仅当前用户可读,移除其他用户的写入权限

  • 禁用Ansible SSH控制主连接
    如果手动SSH命令正常但Ansible卡住,在ansible.cfg中添加配置禁用控制主连接:

    [ssh_connection]
    ssh_args = -o ControlMaster=no
    

内容的提问来源于stack exchange,提问作者Yannick25

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 02:42:37