OnCallReady

Commands

ansible - Define and run a single task "playbook" (an ad-hoc command) against a set of hosts

ansible PATTERN [-i INVENTORY] [-m MODULE] [-a ARGS] [-b] [options]

Options you will use

-m, --module-name MODULE_NAME
Name of the action to execute (default command).
-a, --args MODULE_ARGS
The action's options in k=v format, or JSON: -a 'name=nginx state=present'.
-o, --one-line
Condense output to one line per host.
--list-hosts
Output a list of matching hosts; does not execute anything else.
--playbook-dir BASEDIR
Use this directory as the playbook directory (roles/, group_vars/ ...).
-i, --inventory INVENTORY
Inventory host path or comma separated host list ("web-1,web-2,"). May be given more than once. Default: the inventory key of ansible.cfg, else /etc/ansible/hosts.
-l, --limit SUBSET
Further limit selected hosts to an additional pattern (web-1, web:!web-2, @retry_file).
-e, --extra-vars EXTRA_VARS
Set additional variables as key=value or YAML/JSON, or @file. Extra vars beat every other variable source.
-u, --user REMOTE_USER
Connect as this user (default: the remote_user setting, else your own user name).
-b, --become
Run operations with become (sudo by default). Does not imply a password prompt.
-K, --ask-become-pass
Ask for the privilege escalation (sudo) password. Without it, a host that needs one fails with "Missing sudo password".
--become-user BECOME_USER
Run operations as this user (default root).
-k, --ask-pass
Ask for the SSH connection password.
--private-key PRIVATE_KEY_FILE
Use this file to authenticate the connection.
-f, --forks FORKS
Number of parallel processes to use (default 5).
-C, --check
Don't make any changes; try to predict some of the changes that may occur. command/shell are skipped.
-D, --diff
When changing (small) files and templates, show the differences. Works great with --check.
--vault-password-file FILE
Vault password file (an executable file is run and its output is the password).
--vault-id VAULT_ID
The vault identity to use: label@prompt or label@file. May be given more than once.
-J, --ask-vault-pass
Ask for the vault password.
-c, --connection CONNECTION
Connection type to use (default ssh; local runs on the control node).
-T, --timeout TIMEOUT
Override the connection timeout in seconds (default 10).
-v, --verbose
More output: -v results, -vv task paths, -vvv the SSH commands and module arguments (careful: secrets!), -vvvv SSH debugging.
--version
Show program's version number, config file location, module location, python version and exit.

Examples

$ ansible all -m ping

can Ansible log in and run Python everywhere?

$ ansible web -a "uptime"

the command module (default): no shell features

$ ansible web -m shell -a 'ps aux | grep nginx'

shell when you need pipes

$ ansible web -b -m apt -a 'name=nginx state=present'

become root for package installs

$ ansible web-1 -m setup -a filter=ansible_memtotal_mb

one fact

$ ansible web --list-hosts

what does the pattern match?

Gotchas

Taught in

Try ansible in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.