ansible - Define and run a single task "playbook" (an ad-hoc command) against a set of hosts
ansible PATTERN [-i INVENTORY] [-m MODULE] [-a ARGS] [-b] [options]
Options you will use
-m, --module-name MODULE_NAME- Name of the action to execute (default command).
-a, --args MODULE_ARGS- The action's options in k=v format, or JSON: -a 'name=nginx state=present'.
-o, --one-line- Condense output to one line per host.
--list-hosts- Output a list of matching hosts; does not execute anything else.
--playbook-dir BASEDIR- Use this directory as the playbook directory (roles/, group_vars/ ...).
-i, --inventory INVENTORY- Inventory host path or comma separated host list ("web-1,web-2,"). May be given more than once. Default: the inventory key of ansible.cfg, else /etc/ansible/hosts.
-l, --limit SUBSET- Further limit selected hosts to an additional pattern (web-1, web:!web-2, @retry_file).
-e, --extra-vars EXTRA_VARS- Set additional variables as key=value or YAML/JSON, or @file. Extra vars beat every other variable source.
-u, --user REMOTE_USER- Connect as this user (default: the remote_user setting, else your own user name).
-b, --become- Run operations with become (sudo by default). Does not imply a password prompt.
-K, --ask-become-pass- Ask for the privilege escalation (sudo) password. Without it, a host that needs one fails with "Missing sudo password".
--become-user BECOME_USER- Run operations as this user (default root).
-k, --ask-pass- Ask for the SSH connection password.
--private-key PRIVATE_KEY_FILE- Use this file to authenticate the connection.
-f, --forks FORKS- Number of parallel processes to use (default 5).
-C, --check- Don't make any changes; try to predict some of the changes that may occur. command/shell are skipped.
-D, --diff- When changing (small) files and templates, show the differences. Works great with --check.
--vault-password-file FILE- Vault password file (an executable file is run and its output is the password).
--vault-id VAULT_ID- The vault identity to use: label@prompt or label@file. May be given more than once.
-J, --ask-vault-pass- Ask for the vault password.
-c, --connection CONNECTION- Connection type to use (default ssh; local runs on the control node).
-T, --timeout TIMEOUT- Override the connection timeout in seconds (default 10).
-v, --verbose- More output: -v results, -vv task paths, -vvv the SSH commands and module arguments (careful: secrets!), -vvvv SSH debugging.
--version- Show program's version number, config file location, module location, python version and exit.
Examples
$ ansible all -m pingcan Ansible log in and run Python everywhere?
$ ansible web -a "uptime"the command module (default): no shell features
$ ansible web -m shell -a 'ps aux | grep nginx'shell when you need pipes
$ ansible web -b -m apt -a 'name=nginx state=present'become root for package installs
$ ansible web-1 -m setup -a filter=ansible_memtotal_mbone fact
$ ansible web --list-hostswhat does the pattern match?
Gotchas
- The default module is command: no pipes, no redirections, no $VARS. Use -m shell for those.
- command and shell always report CHANGED - Ansible cannot know what a command did.
- Patterns: all, a group, a host, web:db (union), web:&prod (intersection), web:!web-2 (exclusion), web-* (glob), ~web-\d (regex).
- "[WARNING]: Host ... is using the discovered Python interpreter" goes away with interpreter_python = auto_silent in ansible.cfg (or ansible_python_interpreter per host).
Taught in
Try ansible in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.