OnCallReady

Commands

ansible-playbook - Runs Ansible playbooks, executing the defined tasks on the targeted hosts

ansible-playbook [-i INVENTORY] [options] PLAYBOOK [PLAYBOOK ...]

Options you will use

--syntax-check
Perform a syntax check on the playbook, but do not execute it.
--list-tasks
List all tasks that would be executed.
--list-hosts
Output a list of matching hosts; does not execute anything else.
--list-tags
List all available tags.
-t, --tags TAGS
Only run plays and tasks tagged with these values (always-tagged tasks run too).
--skip-tags SKIP_TAGS
Only run plays and tasks whose tags do not match these values.
--start-at-task TASK
Start the playbook at the task matching this name.
--step
One-step-at-a-time: confirm each task before running ((N)o/(y)es/(c)ontinue).
--force-handlers
Run handlers even if a task fails (notified handlers still run on the hosts that failed).
--flush-cache
Clear the fact cache for every host in inventory.
-i, --inventory INVENTORY
Inventory host path or comma separated host list ("web-1,web-2,"). May be given more than once. Default: the inventory key of ansible.cfg, else /etc/ansible/hosts.
-l, --limit SUBSET
Further limit selected hosts to an additional pattern (web-1, web:!web-2, @retry_file).
-e, --extra-vars EXTRA_VARS
Set additional variables as key=value or YAML/JSON, or @file. Extra vars beat every other variable source.
-u, --user REMOTE_USER
Connect as this user (default: the remote_user setting, else your own user name).
-b, --become
Run operations with become (sudo by default). Does not imply a password prompt.
-K, --ask-become-pass
Ask for the privilege escalation (sudo) password. Without it, a host that needs one fails with "Missing sudo password".
--become-user BECOME_USER
Run operations as this user (default root).
-k, --ask-pass
Ask for the SSH connection password.
--private-key PRIVATE_KEY_FILE
Use this file to authenticate the connection.
-f, --forks FORKS
Number of parallel processes to use (default 5).
-C, --check
Don't make any changes; try to predict some of the changes that may occur. command/shell are skipped.
-D, --diff
When changing (small) files and templates, show the differences. Works great with --check.
--vault-password-file FILE
Vault password file (an executable file is run and its output is the password).
--vault-id VAULT_ID
The vault identity to use: label@prompt or label@file. May be given more than once.
-J, --ask-vault-pass
Ask for the vault password.
-c, --connection CONNECTION
Connection type to use (default ssh; local runs on the control node).
-T, --timeout TIMEOUT
Override the connection timeout in seconds (default 10).
-v, --verbose
More output: -v results, -vv task paths, -vvv the SSH commands and module arguments (careful: secrets!), -vvvv SSH debugging.
--version
Show program's version number, config file location, module location, python version and exit.

Examples

$ ansible-playbook -i inventory.ini site.yml

run it

$ ansible-playbook site.yml --check --diff

what would change, as diffs

$ ansible-playbook site.yml --syntax-check

YAML and structure only

$ ansible-playbook site.yml -l web-1

one host first

$ ansible-playbook site.yml --tags config

only the tasks tagged config

$ ansible-playbook site.yml --start-at-task "Deploy the app"

resume after a failure

$ ansible-playbook site.yml -e @vars/prod.yml --vault-password-file ~/.vault_pass

extra vars from a file, a vault

Gotchas

Taught in

Try ansible-playbook in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.