Ansible SSL error "unable to get local issuer certificate" when triggered by vagrant

Viewed 3717

I have set the following ansible variables:

ansible_port: 5986
ansible_connection: winrm
ansible_winrm_server_cert_validation: ignore

and running my playbook via ansible-playbook -i ansible/inventory.ini -vvvvv ansible/playbook.yml works fine.

Now I would like vagrant to trigger the ansible provision via vagrant. The Vagrantfilelooks like this:

Vagrant.configure(2) do |config|
  config.vm.define "virtualbox_windows_server_2016_1" do |s|
    ...
    s.vm.provision "ansible" do |ansible|
      ansible.playbook = "ansible/playbook.yml"
      ansible.inventory_path = "ansible/inventory.ini"
      ansible.config_file = "ansible/ansible.cfg"
      ansible.verbose = "-vvvvv"
    end
  end  
end

Doing a vagrant provision or vagrant up --provision results in the following error:

fatal: [virtualbox_windows_server_2016_1]: UNREACHABLE! => {
    "changed": false,
    "msg": "ssl: HTTPSConnectionPool(host='192.168.57.3', port=5986): Max retries exceeded with url: /wsman (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1056)')))",
    "unreachable": true
}

The vagrant log info says it runs the following ansible command:

PYTHONUNBUFFERED=1 ANSIBLE_FORCE_COLOR=true ANSIBLE_CONFIG='ansible/ansible.cfg' ANSIBLE_HOST_KEY_CHECKING=false ANSIBLE_SSH_ARGS='-o UserKnownHostsFile=/dev/null -o IdentitiesOnly=yes -o IdentityFile=/Users/user/.vagrant.d/insecure_private_key -o ControlMaster=auto -o ControlPersist=60s' ansible-playbook --connection=ssh --timeout=30 --extra-vars=ansible_user\=\'vagrant\' --limit="virtualbox_windows_server_2016_1" --inventory-file=ansible/inventory.ini -vvvvv ansible/playbook.yml

Interestingly, when I copy and paste the above command and run it separately (i.e. on the terminal not via vagrant), there is no error and everything works just like the short ansible-playbook command I mentioned above.

It also works with and without vagrant if I set

ansible_port: 5985 # not 5986

What is the problem here?

  • Vagrant 2.2.4
  • ansible 2.8.1
  • Python 3.7.3
  • macOS 10.13.6
0 Answers
Related