ansible-playbook - Runs Ansible playbooks, executing the defined tasks on the targeted hosts
ansible-playbook [-i INVENTORY] [options] PLAYBOOK [PLAYBOOK ...]
Options you will use
--syntax-check- Perform a syntax check on the playbook, but do not execute it.
--list-tasks- List all tasks that would be executed.
--list-hosts- Output a list of matching hosts; does not execute anything else.
--list-tags- List all available tags.
-t, --tags TAGS- Only run plays and tasks tagged with these values (always-tagged tasks run too).
--skip-tags SKIP_TAGS- Only run plays and tasks whose tags do not match these values.
--start-at-task TASK- Start the playbook at the task matching this name.
--step- One-step-at-a-time: confirm each task before running ((N)o/(y)es/(c)ontinue).
--force-handlers- Run handlers even if a task fails (notified handlers still run on the hosts that failed).
--flush-cache- Clear the fact cache for every host in inventory.
-i, --inventory INVENTORY- Inventory host path or comma separated host list ("web-1,web-2,"). May be given more than once. Default: the inventory key of ansible.cfg, else /etc/ansible/hosts.
-l, --limit SUBSET- Further limit selected hosts to an additional pattern (web-1, web:!web-2, @retry_file).
-e, --extra-vars EXTRA_VARS- Set additional variables as key=value or YAML/JSON, or @file. Extra vars beat every other variable source.
-u, --user REMOTE_USER- Connect as this user (default: the remote_user setting, else your own user name).
-b, --become- Run operations with become (sudo by default). Does not imply a password prompt.
-K, --ask-become-pass- Ask for the privilege escalation (sudo) password. Without it, a host that needs one fails with "Missing sudo password".
--become-user BECOME_USER- Run operations as this user (default root).
-k, --ask-pass- Ask for the SSH connection password.
--private-key PRIVATE_KEY_FILE- Use this file to authenticate the connection.
-f, --forks FORKS- Number of parallel processes to use (default 5).
-C, --check- Don't make any changes; try to predict some of the changes that may occur. command/shell are skipped.
-D, --diff- When changing (small) files and templates, show the differences. Works great with --check.
--vault-password-file FILE- Vault password file (an executable file is run and its output is the password).
--vault-id VAULT_ID- The vault identity to use: label@prompt or label@file. May be given more than once.
-J, --ask-vault-pass- Ask for the vault password.
-c, --connection CONNECTION- Connection type to use (default ssh; local runs on the control node).
-T, --timeout TIMEOUT- Override the connection timeout in seconds (default 10).
-v, --verbose- More output: -v results, -vv task paths, -vvv the SSH commands and module arguments (careful: secrets!), -vvvv SSH debugging.
--version- Show program's version number, config file location, module location, python version and exit.
Examples
$ ansible-playbook -i inventory.ini site.ymlrun it
$ ansible-playbook site.yml --check --diffwhat would change, as diffs
$ ansible-playbook site.yml --syntax-checkYAML and structure only
$ ansible-playbook site.yml -l web-1one host first
$ ansible-playbook site.yml --tags configonly the tasks tagged config
$ ansible-playbook site.yml --start-at-task "Deploy the app"resume after a failure
$ ansible-playbook site.yml -e @vars/prod.yml --vault-password-file ~/.vault_passextra vars from a file, a vault
Gotchas
- Exit codes: 0 ok, 2 a host failed, 4 a host was unreachable (also: a parse error), 1 other errors, 5 bad options, 99 interrupted.
- PLAY RECAP: ok = tasks that ran (changed ones included), changed = tasks that changed something, failed, unreachable, skipped, rescued (block/rescue), ignored (ignore_errors).
- Run it twice: a second run with changed=0 is the idempotency test.
- In 2.19+ every when: must evaluate to a boolean;
when: my_stringis an error.
Taught in
- 33.5 Playbooks: plays, tasks, modules and idempotency
- 33.8 Variables, facts and precedence
- 33.11 Templates (Jinja2) and files
- 33.14 Handlers, tags, check and diff
- 33.21 Roles, collections and project layout
- 33.23 Secrets: ansible-vault and no_log
- 33.26 Rolling changes: serial, health checks and delegate_to
Try ansible-playbook in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.