You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWX执行Cisco IOSXR配置任务报错无法连接127.0.0.1:10022

AWX连接本地IOSXR网络模拟器连接故障排障

基础环境与前置配置

  • 部署架构:0.23.0版本AWX Operator全新部署的AWX实例,运行在K8s集群上
  • 待纳管设备:本地宿主机运行的搭载Cisco IOSXR元素驱动的网络模拟器
  • 清单全局配置:
ansible_connection: network_cli  
ansible_network_os: cisco.iosxr.iosxr
  • 主机组主机变量配置(单台模拟设备):
ansible_host: 127.0.0.1 
ansible_ssh_port: 10022
  • 凭证配置:仅在项目关联的机器凭证中配置SSH连接所用的用户名、密码
  • 依赖配置:通过项目下的requirements.yaml安装Cisco自动化所需的官方集合模块
  • 测试Playbook内容:
---
    - name: testDir sample
      hosts: net_sims
      gather_facts: no
      #ansible_network_cli_ssh_type: libssh
      become: yes
      connection: local
      tasks:
        - name: playbook dir print
          debug:
            msg: "{{playbook_dir}}"
          #second task
    - name: Configure netsim
      hosts: net_sims
      gather_facts: no
      become: yes
      tasks:
          - name: Configure a device
            cisco.iosxr.iosxr_interfaces:
             config:
             - name: GigabitEthernet0/0/0/2
               description: Configured by Ansible
               enabled: true
             - name: GigabitEthernet0/0/0/3
               description: Configured by Ansible Network
               enabled: false
               duplex: full
             state: merged

故障现象

  • 第一个指定connection: local的debug任务可正常执行,输出符合预期
  • 第二个调用cisco.iosxr.iosxr_interfaces模块配置接口的任务执行失败,核心报错为无法连接127.0.0.1的10022端口,完整报错片段:
[Errno None] Unable to connect to port 10022 on 127.0.0.1

task path: /runner/project/myPlaybooks/configureNetsim.yaml:19
redirecting (type: connection) ansible.builtin.network_cli to ansible.netcommon.network_cli
Loading collection ansible.netcommon from /runner/requirements_collections/ansible_collections/ansible/netcommon
<127.0.0.1> attempting to start connection
<127.0.0.1> using connection plugin ansible.netcommon.network_cli
Found ansible-connection at path /usr/local/bin/ansible-connection
<127.0.0.1> found existing local domain socket, using it!
<127.0.0.1> updating play_context for connection
<127.0.0.1> local domain socket path is /home/runner/.ansible/pc/45cc4656c5
<127.0.0.1> Using network group action cisco.iosxr.iosxr for cisco.iosxr.iosxr_interfaces
<127.0.0.1> ANSIBLE_NETWORK_IMPORT_MODULES: enabled
<127.0.0.1> ANSIBLE_NETWORK_IMPORT_MODULES: found cisco.iosxr.iosxr_interfaces  at /runner/requirements_collections/ansible_collections/cisco/iosxr/plugins/modules/iosxr_interfaces.py
<127.0.0.1> ANSIBLE_NETWORK_IMPORT_MODULES: running cisco.iosxr.iosxr_interfaces
<127.0.0.1> ANSIBLE_NETWORK_IMPORT_MODULES: complete
The full traceback is:
  File "/runner/requirements_collections/ansible_collections/ansible/netcommon/plugins/module_utils/network/common/network.py", line 249, in get_capabilities
    capabilities = Connection(module._socket_path).get_capabilities()
  File "/usr/local/lib/python3.8/site-packages/ansible/module_utils/connection.py", line 200, in __rpc__
    raise ConnectionError(to_text(msg, errors='surrogate_then_replace'), code=code)
fatal: [new_dev0]: FAILED! => {
    "changed": false,
    "invocation": {
  • 任务运行时输出警告:

[WARNING]: ansible-pylibssh not installed, falling back to paramiko

  • 本地宿主机直接执行SSH命令可正常连接模拟器,排除模拟器本身SSH服务异常:
➜  ~ ssh -p 10022 admin@127.0.0.1 
admin@127.0.0.1's password:
        
admin connected from 127.0.0.1 using ssh on Garretts-Mac-mini.local
  • 已尝试排查方向:检查connection.py源码、重置AWX配置、修改模拟器SSH映射端口、查阅官方文档、在K8s集群层面安装ansible-pylibssh依赖(安装失败),均未解决问题,无法确认pylibssh缺失是否为故障诱因。

根因定位

核心问题是地址配置错误,和pylibssh依赖缺失无关:

  • AWX的任务实际运行在K8s集群内的EE(执行环境)容器中,主机变量里配置的127.0.0.1指向的是EE容器自身的回环地址,不是运行模拟器的宿主机地址。
  • 第一个任务指定connection: local,动作是在EE容器本地执行debug打印路径,不涉及对外连接,所以可以正常运行;第二个任务走network_cli插件连接127.0.0.1:10022,实际是在访问容器自身的10022端口,容器内没有运行对应SSH服务,自然连接失败。
  • 运行时的pylibssh警告仅表示当前SSH客户端用的是paramiko而非libssh,paramiko本身完全支持IOSXR的SSH连接,不是本次故障的原因。

修复步骤

  1. 修正主机地址配置
    将主机变量中的ansible_host从127.0.0.1替换为AWX EE容器可路由到的宿主机物理内网IP,不要使用回环地址。
    校验点:确认模拟器SSH服务监听地址为0.0.0.0而非仅绑定127.0.0.1,同时宿主机本地防火墙放开10022端口的入站规则,允许K8s Pod网段访问该端口。
  2. 验证容器到模拟器的网络连通性
    新增临时测试任务,指定connection: local在EE容器内执行端口探测,确认到宿主机IP的10022端口可达后,再运行设备配置任务。
  3. (可选)消除pylibssh警告
    无需在K8s节点层面安装依赖,直接构建自定义EE镜像,在镜像构建过程中预装ansible-pylibssh包,将AWX项目绑定到自定义EE即可消除警告。
  4. 配置一致性校验
    确认第二个配置任务没有额外覆盖连接相关参数,保证清单中配置的ansible_connection: network_cli、ansible_network_os: cisco.iosxr.iosxr正常生效。

内容的提问来源于stack exchange,提问作者garandre

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 13:27:19