使用Rundeck执行WinRM协议的Ansible Playbook遇连接异常
问题:Rundeck执行WinRM连接的Ansible Playbook失败,错误尝试SSH连接Windows节点
执行Playbook时,Rundeck未使用WinRM协议,反而尝试通过SSH连接Windows 10主机,报错信息如下:
PLAY [Create Folder on Windows Desktop Using WinRM] **************************** TASK [create folder on desktop] ************************************************ fatal: [192.168.10.42]: UNREACHABLE! => {"changed": false, "msg": "Failed to connect to the host via ssh: ssh: connect to host 192.168.10.42 port 22: Connection refused", "unreachable": true} PLAY RECAP ********************************************************************* 192.168.10.42 : ok=0 changed=0 unreachable=1 failed=0 skipped=0 rescued=0 ignored=0 Failed: AnsibleNonZero: ERROR: Ansible execution returned with non zero code.
该Playbook已在Ubuntu Server 22.04 LTS终端成功运行,当前Rundeck端相关配置如下:
项目配置
#edit below project.ansible-config-file-path=/etc/asnible/ansible.cfg project.ansible-executable=/bin/sh project.ansible-generate-inventory=true project.ansible-ssh-passphrase-option=option.password project.ansible-windows-executable=powershell.exe project.description= project.disable.executions=false project.disable.schedule=false project.execution.history.cleanup.batch=500 project.execution.history.cleanup.enabled=false project.execution.history.cleanup.retention.days=60 project.execution.history.cleanup.retention.minimum=50 project.execution.history.cleanup.schedule=0 0 0 1/1 * ? * project.jobs.gui.groupExpandLevel=1 project.label= project.later.executions.disable=false project.later.executions.enable=false project.later.schedule.disable=false project.later.schedule.enable=false project.name=Ansible project.nodeCache.enabled=true project.nodeCache.firstLoadSynch=true project.output.allowUnsanitized=false project.ssh-authentication=privateKey project.ssh-keypath=/var/lib/rundeck/.ssh/id_rsa resources.source.1.config.ansible-config-file-path=/etc/ansible/anisble.cfg resources.source.1.config.ansible-gather-facts=true resources.source.1.config.ansible-ignore-errors=true resources.source.1.config.ansible-inventory=/etc/ansible/hosts resources.source.1.config.ansible-ssh-auth-type=password resources.source.1.config.ansible-ssh-password=***** resources.source.1.config.ansible-ssh-user=ansible resources.source.1.type=com.batix.rundeck.plugins.AnsibleResourceModelSourceFactory service.FileCopier.default.provider=jsch-scp service.NodeExecutor.default.provider=com.batix.rundeck.plugins.AnsibleNodeExecutor
Inventory配置(仅HTTP协议WinRM测试)
[winrm] 192.168.10.42 [winrm:vars] ansible_connection=winrm ansible_winrm_transport=basic ansible_winrm_port=5985 ansible_user=Admin ansible_password=Password1
任务配置
- defaultTab: nodes description: '' executionEnabled: true id: 9e1ce2f2-084f-41d5-a34d-117273d3e661 loglevel: INFO name: WinRM Test nodeFilterEditable: false nodefilters: dispatch: excludePrecedence: true keepgoing: false rankOrder: ascending successOnEmptyNodeFilter: false threadcount: '1' filter: 192.168.10.42 nodesSelectedByDefault: true plugins: ExecutionLifecycle: null scheduleEnabled: true sequence: commands: - configuration: ansible-base-dir-path: /etc/ansible ansible-become: 'false' ansible-playbook: winrm_test.yml ansible-ssh-passphrase-option: option.password ansible-ssh-use-agent: 'false' nodeStep: true type: com.batix.rundeck.plugins.AnsiblePlaybookWorflowNodeStep keepgoing: false strategy: node-first uuid: 9e1ce2f2-084f-41d5-a34d-117273d3e661
修复步骤
修正配置文件路径拼写错误
- 项目配置中
/etc/asnible/ansible.cfg和/etc/ansible/anisble.cfg存在拼写错误,统一改为/etc/ansible/ansible.cfg,确保Rundeck能正确读取Ansible配置。
- 项目配置中
调整任务执行策略
- 当前任务使用
node-first策略,会强制Rundeck用节点执行器连接目标节点,覆盖Inventory中的WinRM配置。将任务的strategy改为step-first,让Ansible直接使用Inventory内的连接参数。
- 当前任务使用
移除资源模型源的SSH参数
- 资源模型源中配置的
ansible-ssh-user=ansible和ansible-ssh-password会覆盖Inventory里的Windows账户信息,删除这两项配置,让Rundeck读取Inventory中的Admin账户。
- 资源模型源中配置的
清理任务中的SSH冗余配置
- 任务配置里的
ansible-ssh-passphrase-option和ansible-ssh-use-agent是SSH连接参数,WinRM连接不需要,直接移除这些配置项。
- 任务配置里的
验证Ansible配置文件
- 确保
/etc/ansible/ansible.cfg包含WinRM相关基础配置,示例:[defaults] inventory = /etc/ansible/hosts [winrm_connection] timeout = 30
- 确保
内容的提问来源于stack exchange,提问作者cnrdvdsmt
相关产品推荐
相关产品推荐

