Chef Test Kitchen连接Windows Vagrant盒时WinRM配置不生效问题
解决Test Kitchen优先使用SSH而非WinRM连接Windows Vagrant盒子的问题
我之前也碰到过一模一样的情况——明明在kitchen.yml里指定了WinRM传输,但Test Kitchen还是固执地尝试SSH连接。结合你的Windows 8.1嵌入式系统场景,咱们可以从这几个方向逐一排查解决:
1. 先确认你的Vagrant盒子本身WinRM配置没问题
Test Kitchen依赖Vagrant提供的通信能力,如果盒子本身的WinRM没配置好,再怎么改kitchen.yml也没用。你可以先手动启动盒子测试:
- 执行
vagrant up启动你的Windows盒子 - 用WinRM命令测试连接:
winrm id -r http://<虚拟机IP>:5985 -u vagrant -p vagrant
如果连接失败,说明盒子里的WinRM需要调整:
- 确保WinRM服务已启动并设置为自动:
Set-Service WinRM -StartupType Automatic -Status Running - 开放防火墙5985端口:
New-NetFirewallRule -Name "WinRM-HTTP" -DisplayName "WinRM HTTP" -Enabled True -Direction Inbound -Protocol TCP -LocalPort 5985 -Action Allow - 允许基本认证:
winrm set winrm/config/service/auth @{Basic="true"} - 允许非加密连接(测试环境可以用):
winrm set winrm/config/service @{AllowUnencrypted="true"}
2. 修正kitchen.yml的关键配置
你的现有配置里,platforms下的WinRM传输设置需要补充细节,同时要明确告诉Vagrant驱动使用WinRM作为通信器:
更新后的kitchen.yml示例:
--- driver: name: vagrant # 关键:告诉Vagrant驱动优先用WinRM通信 communicator: winrm customize: winrm.username: vagrant winrm.password: vagrant provisioner: name: chef_zero always_update_cookbooks: true verifier: name: inspec platforms: - name: testwin transport: name: winrm username: vagrant password: vagrant port: 5985 elevated: true connection_timeout: 30 max_wait_until_ready: 120 suites: - name: default run_list: - recipe[winrm::default] verifier: inspec_tests: - test/integration/default attributes:
这里的核心改动是在driver部分添加了communicator: winrm,强制Vagrant使用WinRM而非默认的SSH。同时补充了WinRM传输的超时和端口参数,避免因连接超时导致的 fallback 到SSH。
3. 检查Test Kitchen及插件版本
旧版本的test-kitchen或kitchen-vagrant插件可能存在WinRM识别的bug,建议更新到最新版本:
gem update test-kitchen gem update kitchen-vagrant
4. 验证配置是否生效
执行 kitchen diagnose 命令,查看输出中的platforms[0].transport和driver部分,确认:
platforms[0].transport.name是winrmdriver.communicator是winrm
如果输出里还是显示SSH相关配置,说明配置没有被正确加载,检查kitchen.yml的缩进是否正确(YAML对缩进非常敏感)。
按照这些步骤调整后,再执行kitchen create,应该就能正常使用WinRM连接你的Windows实例了。
内容的提问来源于stack exchange,提问作者Krishna
相关产品推荐
相关产品推荐

