You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Rundeck执行WinRM协议的Ansible Playbook遇连接异常

问题:Rundeck执行WinRM连接的Ansible Playbook失败,错误尝试SSH连接Windows节点

执行Playbook时,Rundeck未使用WinRM协议,反而尝试通过SSH连接Windows 10主机,报错信息如下:

PLAY [Create Folder on Windows Desktop Using WinRM] ****************************
TASK [create folder on desktop] ************************************************
fatal: [192.168.10.42]: UNREACHABLE! => {"changed": false, "msg": "Failed to connect to the host via ssh: ssh: connect to host 192.168.10.42 port 22: Connection refused", "unreachable": true}
PLAY RECAP *********************************************************************
192.168.10.42              : ok=0    changed=0    unreachable=1    failed=0    skipped=0    rescued=0    ignored=0   
Failed: AnsibleNonZero: ERROR: Ansible execution returned with non zero code.

该Playbook已在Ubuntu Server 22.04 LTS终端成功运行,当前Rundeck端相关配置如下:

项目配置

#edit below
project.ansible-config-file-path=/etc/asnible/ansible.cfg
project.ansible-executable=/bin/sh
project.ansible-generate-inventory=true
project.ansible-ssh-passphrase-option=option.password
project.ansible-windows-executable=powershell.exe
project.description=
project.disable.executions=false
project.disable.schedule=false
project.execution.history.cleanup.batch=500
project.execution.history.cleanup.enabled=false
project.execution.history.cleanup.retention.days=60
project.execution.history.cleanup.retention.minimum=50
project.execution.history.cleanup.schedule=0 0 0 1/1 * ? *
project.jobs.gui.groupExpandLevel=1
project.label=
project.later.executions.disable=false
project.later.executions.enable=false
project.later.schedule.disable=false
project.later.schedule.enable=false
project.name=Ansible
project.nodeCache.enabled=true
project.nodeCache.firstLoadSynch=true
project.output.allowUnsanitized=false
project.ssh-authentication=privateKey
project.ssh-keypath=/var/lib/rundeck/.ssh/id_rsa
resources.source.1.config.ansible-config-file-path=/etc/ansible/anisble.cfg
resources.source.1.config.ansible-gather-facts=true
resources.source.1.config.ansible-ignore-errors=true
resources.source.1.config.ansible-inventory=/etc/ansible/hosts
resources.source.1.config.ansible-ssh-auth-type=password
resources.source.1.config.ansible-ssh-password=*****
resources.source.1.config.ansible-ssh-user=ansible
resources.source.1.type=com.batix.rundeck.plugins.AnsibleResourceModelSourceFactory
service.FileCopier.default.provider=jsch-scp
service.NodeExecutor.default.provider=com.batix.rundeck.plugins.AnsibleNodeExecutor

Inventory配置(仅HTTP协议WinRM测试)

[winrm]
192.168.10.42

[winrm:vars]
ansible_connection=winrm
ansible_winrm_transport=basic
ansible_winrm_port=5985
ansible_user=Admin
ansible_password=Password1

任务配置

- defaultTab: nodes
  description: ''
  executionEnabled: true
  id: 9e1ce2f2-084f-41d5-a34d-117273d3e661
  loglevel: INFO
  name: WinRM Test
  nodeFilterEditable: false
  nodefilters:
    dispatch:
      excludePrecedence: true
      keepgoing: false
      rankOrder: ascending
      successOnEmptyNodeFilter: false
      threadcount: '1'
    filter: 192.168.10.42
  nodesSelectedByDefault: true
  plugins:
    ExecutionLifecycle: null
  scheduleEnabled: true
  sequence:
    commands:
    - configuration:
        ansible-base-dir-path: /etc/ansible
        ansible-become: 'false'
        ansible-playbook: winrm_test.yml
        ansible-ssh-passphrase-option: option.password
        ansible-ssh-use-agent: 'false'
      nodeStep: true
      type: com.batix.rundeck.plugins.AnsiblePlaybookWorflowNodeStep
    keepgoing: false
    strategy: node-first
  uuid: 9e1ce2f2-084f-41d5-a34d-117273d3e661

修复步骤

  1. 修正配置文件路径拼写错误

    • 项目配置中/etc/asnible/ansible.cfg和/etc/ansible/anisble.cfg存在拼写错误,统一改为/etc/ansible/ansible.cfg,确保Rundeck能正确读取Ansible配置。
  2. 调整任务执行策略

    • 当前任务使用node-first策略,会强制Rundeck用节点执行器连接目标节点,覆盖Inventory中的WinRM配置。将任务的strategy改为step-first,让Ansible直接使用Inventory内的连接参数。
  3. 移除资源模型源的SSH参数

    • 资源模型源中配置的ansible-ssh-user=ansible和ansible-ssh-password会覆盖Inventory里的Windows账户信息,删除这两项配置,让Rundeck读取Inventory中的Admin账户。
  4. 清理任务中的SSH冗余配置

    • 任务配置里的ansible-ssh-passphrase-option和ansible-ssh-use-agent是SSH连接参数,WinRM连接不需要,直接移除这些配置项。
  5. 验证Ansible配置文件

    • 确保/etc/ansible/ansible.cfg包含WinRM相关基础配置,示例:
      [defaults]
      inventory = /etc/ansible/hosts
      [winrm_connection]
      timeout = 30
      

内容的提问来源于stack exchange,提问作者cnrdvdsmt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 16:59:59