CircleCI Windows实例连接VPN失败求助:部署AWS EC2遇阻
CircleCI中连接VPN部署AWS Windows EC2实例报错求助
我在CircleCI中通过SSH将文件部署到AWS Windows EC2实例时,连接VPN环节报错。该EC2实例的22端口入站规则仅允许VPN连接访问。

我的CircleCI配置文件
build-deploy: working_directory: ~/repo executor: name: windows/default steps: - checkout - restore_cache: keys: - v1-dependencies-{{ checksum "package-lock.json" }} - v1-dependencies- - run: name: Install dependencies command: npm install - save_cache: key: v1-dependencies-{{ checksum "package-lock.json" }} paths: - node_modules - run: name: Build command: npm run build - run: name: Connect to VPN command: .\.circleci\connectVPN.ps1 - run: name: Install POSH-SSH command: .\.circleci\install_posh_ssh.ps1 - run: name: Update Host command: .\.circleci\set_known_hosts.ps1 - run: name: Deploy App into EC2 command: .\.circleci\ssh_deploy.ps1
connectVPN.ps1脚本内容
$VPN_NAME = $env:VPN_NAME $VPN_ADDRESS = $env:VPN_ADDRESS $VPN_USERNAME = $env:VPN_USERNAME $VPN_PASSWORD = $env:VPN_PASSWORD # If VPN with this name is present, then remove it if ([bool] (Get-VpnConnection -Name "$VPN_NAME")) { # Remove it Remove-VpnConnection -Name "$VPN_NAME" -Force } # Adds the new VPN Connection Add-VpnConnection -Name "$VPN_NAME" -ServerAddress "$VPN_ADDRESS" -TunnelType Pptp -EncryptionLevel NoEncryption -AuthenticationMethod Pap -RememberCredential -PassThru # Connect the VPN configuration $code = (Start-Process rasdial -NoNewWindow -ArgumentList "$VPN_NAME $VPN_USERNAME $VPN_PASSWORD" -PassThru -Verbose -Wait).ExitCode if ("$code" -eq "0") { Write-Host "Create and connect to VPN server success" -ForegroundColor DarkGreen } else { if ("$code" -eq "691") { Write-Host "Create and connect to VPN server failed with wrong username or password" -ForegroundColor DarkRed } else { Write-Host "Create and connect to VPN server failed with error code: $($code)" -ForegroundColor DarkRed throw "$code" } }
排查建议
- 核对环境变量:确认CircleCI项目中
VPN_NAME、VPN_ADDRESS等4个环境变量是否配置正确,有没有拼写错误或者值不匹配的情况。 - 更换VPN协议:CircleCI的Windows容器可能限制PPTP协议,建议换成L2TP/IPsec或OpenVPN这类更通用的协议测试。
- 提升执行权限:
rasdial命令可能需要管理员权限,在Connect to VPN步骤中添加shell: powershell.exe -ExecutionPolicy Bypass -Verb RunAs参数试试。 - 增加日志输出:在
connectVPN.ps1里添加Get-VpnConnection输出查看配置,或者捕获rasdial的标准错误输出,定位具体失败点。 - 测试网络连通性:VPN连接步骤后加ping命令,确认CircleCI容器能正常访问VPN服务器地址。
内容的提问来源于stack exchange,提问作者Gurkiran Singh
相关产品推荐
相关产品推荐

