Ansible Modules

Introduction

Ansible ships with a number of modules (called the ‘module library’) that can be executed directly on remote hosts or through Playbooks. Users can also write their own modules. These modules can control system resources, like services, packages, or files (anything really), or handle executing system commands.

Let’s review how we execute three different modules from the command line:

ansible webservers -m service -a "name=httpd state=running"
ansible webservers -m ping
ansible webservers -m command -a "/sbin/reboot -t now"

Each module supports taking arguments. Nearly all modules take key=value arguments, space delimited. Some modules take no arguments, and the command/shell modules simply take the string of the command you want to run.

From playbooks, Ansible modules are executed in a very similar way:

- name: reboot the servers
  action: command /sbin/reboot -t now

All modules technically return JSON format data, though if you are using the command line or playbooks, you don’t really need to know much about that. If you’re writing your own module, you care, and this means you do not have to write modules in any particular language – you get to choose.

Modules are idempotent, meaning they will seek to avoid changes to the system unless a change needs to be made. When using Ansible playbooks, these modules can trigger ‘change events’ in the form of notifying ‘handlers’ to run additional tasks.

Let’s see what’s available in the Ansible module library, out of the box:

apt

New in version 0.0.2.

Manages apt-packages (such as for Debian/Ubuntu).

parameter required default choices comments
purge no no
  • yes
  • no
Will force purging of configuration files if the module state is set to absent.
state no present
  • installed
  • latest
  • remove
  • absent
  • present
Indicates the desired package state
force no no
  • yes
  • no
If yes, force installs/removes.
pkg yes
    A package name or package specifier with version, like foo or foo=1.0
    update_cache no no
    • yes
    • no
    Run the equivalent of apt-get update before the operation. Can be run as part of the package installation or as a seperate step
    default_release no
      Corresponds to the -t option for apt and sets pin priorities
      install_recommends no no
      • yes
      • no
      Corresponds to the --no-install-recommends option for apt, default behavior works as apt's default behavior, no does not install recommended packages. Suggested packages are never installed.

      Update repositories cache and install foo package

      apt pkg=foo update-cache=yes
      

      Remove foo package

      apt pkg=foo state=removed
      

      Install the the package foo

      apt pkg=foo state=installed
      

      Install the version '1.00' of package foo

      apt pkg=foo=1.00 state=installed
      

      Update the repository cache and update package ngnix to latest version using default release squeeze-backport

      apt pkg=nginx state=latest default-release=squeeze-backports update-cache=yes
      

      Install latest version of openjdk-6-jdk ignoring install-recomands

      apt pkg=openjdk-6-jdk state=latest install-recommends=no
      


      apt_repository

      New in version 0.7.

      Manages apt repositores (such as for Debian/Ubuntu).

      parameter required default choices comments
      repo yes
        The repository name/value
        state no present
        • present
        • absent
        The repository state

        Add nginx stable repository from PPA

        apt_repository repo=ppa://nginx/stable
        

        Add specified repository into sources.

        apt_repository repo='deb http://archive.canonical.com/ubuntu hardy partner'
        


        Notes

        This module works on Debian and Ubuntu only and requires apt-add-repository be available on destination server. To ensure this package is available use the apt module and install the python-software-properties package before using this module.

        A bug in apt-add-repository always adds deb and deb-src types for repositories (see the issue on Launchpad https://bugs.launchpad.net/ubuntu/+source/software-properties/+bug/987264), if a repo doesn't have source information (eg MongoDB repo from 10gen) the system will fail while updating repositories.

        assemble

        New in version 0.5.

        Assembles a configuration file from fragments. Often a particular program will take a single configuration file and does not support a conf.d style structure where it is easy to build up the configuration from multiple sources. Assemble will take a directory of files that have already been transferred to the system, and concatenate them together to produce a destination file. Files are assembled in string sorting order. Puppet calls this idea fragments.

        parameter required default choices comments
        dest yes
          A file to create using the concatenation of all of the source files.
          src yes
            An already existing directory full of source files.
            backup no no
            • yes
            • no
            Create a backup file (if yes), including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly.
            others no
              all arguments accepted by the file module also work here

              Example from Ansible Playbooks

              assemble src=/etc/someapp/fragments dest=/etc/someapp/someapp.conf
              


              async_status

              New in version 0.5.

              This module gets the status of an asynchronous task. See: http://ansible.cc/docs/playbooks2.html#asynchronous-actions-and-polling

              parameter required default choices comments
              jid yes
                Job or task identifier
                mode no status
                • status
                • cleanup
                if status, obtain the status; if cleanup, clean up the async job cache located in ~/.ansible_async/ for the specified job jid.

                Notes

                See http://ansible.cc/docs/playbooks2.html#asynchronous-actions-and-polling

                authorized_key

                New in version 0.5.

                Adds or removes an SSH authorized key for a user from a remote host.

                parameter required default choices comments
                state no present
                • present
                • absent
                whether the given key should or should not be in the file
                user yes
                  Name of the user who should have access to the remote host
                  key yes
                    the SSH public key, as a string

                    Example from Ansible Playbooks

                    authorized_key user=charlie key="ssh-dss ASDF1234L+8BTwaRYr/rycsBF1D8e5pTxEsXHQs4iq+mZdyWqlW++L6pMiam1A8yweP+rKtgjK2httVS6GigVsuWWfOd7/sdWippefq74nppVUELHPKkaIOjJNN1zUHFoL/YMwAAAEBALnAsQN10TNGsRDe5arBsW8cTOjqLyYBcIqgPYTZW8zENErFxt7ij3fW3Jh/sCpnmy8rkS7FyK8ULX0PEy/2yDx8/5rXgMIICbRH/XaBy9Ud5bRBFVkEDu/r+rXP33wFPHjWjwvHAtfci1NRBAudQI/98DbcGQw5HmE89CjgZRo5ktkC5yu/8agEPocVjdHyZr7PaHfxZGUDGKtGRL2QzRYukCmWo1cZbMBHcI5FzImvTHS9/8B3SATjXMPgbfBuEeBwuBK5EjL+CtHY5bWs9kmYjmeo0KfUMH8hY4MAXDoKhQ7DhBPIrcjS5jPtoGxIREZjba67r6/P2XKXaCZH6Fc= charlie@example.org 2011-01-17"
                    

                    Shorthand available in Ansible 0.8 and later

                    authorized_key user=charlie key=$FILE(/home/charlie/.ssh/id_rsa.pub)
                    


                    command

                    The command module takes the command name followed by a list of space-delimited arguments. The given command will be executed on all selected nodes. It will not be processed through the shell, so variables like $HOME and operations like "<", ">", "|", and "&" will not work. As such, all paths to commands must be fully qualified

                    parameter required default choices comments
                    creates no
                      a filename, when it already exists, this step will not be run.
                      free_form yes
                        the command module takes a free form command to run
                        chdir no
                          cd into this directory before running the command (added in Ansible 0.6)
                          removes no
                            a filename, when it does not exist, this step will not be run. (added in Ansible 0.8)

                            Example from Ansible Playbooks

                            command /sbin/shutdown -t now
                            

                            creates, removes, and chdir can be specified after the command. For instance, if you only want to run a command if a certain file does not exist, use this.

                            command /usr/bin/make_database.sh arg1 arg2 creates=/path/to/database
                            


                            Notes

                            If you want to run a command through the shell (say you are using <, >, |, etc), you actually want the shell module instead. The command module is much more secure as it's not affected by the user's environment.

                            copy

                            The copy module copies a file on the local box to remote locations.

                            parameter required default choices comments
                            dest yes
                              Remote absolute path where the file should be copied to.
                              src yes
                                Local path to a file to copy to the remote server; can be absolute or relative.
                                backup no no
                                • yes
                                • no
                                Create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly. (added in Ansible 0.7)
                                others no
                                  all arguments accepted by the file module also work here

                                  Example from Ansible Playbooks

                                  copy src=/srv/myfiles/foo.conf dest=/etc/foo.conf owner=foo group=foo mode=0644
                                  

                                  Copy a new ntp.conf file into place, backing up the original if it differs from the copied version

                                  copy src=/mine/ntp.conf dest=/etc/ntp.conf owner=root group=root mode=644 backup=yes
                                  


                                  cron

                                  New in version 0.9.

                                  Use this module to manage crontab entries. This module allows you to create named crontab entries, update, or delete them. The module include one line with the description of the crontab entry “#Ansible: <name>” corresponding to the “name” passed to the module, which is used by future ansible/module calls to find/check the state.

                                  parameter required default choices comments
                                  name yes
                                    Description of a crontab entry.
                                    hour no *
                                      Hour when the job should run ( 0-23, *, */2, etc )
                                      job no
                                        The command to execute.Required if state=present.
                                        month no *
                                          Month of the year the job should run ( 1-12, *, */2, etc )
                                          state no present
                                            Whether to ensure the job is present or absent.
                                            user no root
                                              The specific user who's crontab should be modified.
                                              backup no
                                                If set, then create a backup of the crontab before it is modified.The location of the backup is returned in the 'backup' variable by this module.
                                                day no *
                                                  Day of the month the job should run ( 1-31, *, */2, etc )
                                                  minute no *
                                                    Minute when the job should run ( 0-59, *, */2, etc )
                                                    weekday no *
                                                      Day of the week that the job should run ( 0-7 for Sunday - Saturday, or mon, tue, * etc )

                                                      Ensure a job that runs at 2 and 5 exists. Creates an entry like "* 5,2 * * ls -alh > /dev/null"

                                                      cron name="check dirs" hour="5,2" job="ls -alh > /dev/null"
                                                      

                                                      Ensure an old job is no longer present. Removes any job that is preceded by "#Ansible: an old job" in the crontab

                                                      name="an old job" cron job="/some/dir/job.sh" state=absent
                                                      


                                                      debug

                                                      New in version 0.8.

                                                      This module prints statements during execution and can be useful for debugging variables or expressions without necessarily halting the playbook. Useful for debugging together with the only_if directive. In order to see the debug message, you need to run ansible in verbose mode (using the -v option).

                                                      parameter required default choices comments
                                                      msg no Hello world!
                                                        The customized message that is printed. If ommited, prints a generic message.
                                                        fail no no
                                                          A boolean that indicates whether the debug module should fail or not.
                                                          rc no
                                                            The return code of the module. If fail=yes, this will default to 1.

                                                            Example that prints the loopback address and gateway for each host

                                                            [{'local_action': 'debug msg="System $inventory_hostname has uuid $ansible_product_uuid"'}, {'only_if': "is_unset('${ansible_default_ipv4.gateway}')", 'local_action': 'debug msg="System $inventory_hostname lacks a gateway" fail=yes'}, {'only_if': "is_set('${ansible_default_ipv4.gateway}')", 'local_action': 'debug msg="System $inventory_hostname has gateway ${ansible_default_ipv4.gateway}"'}]
                                                            


                                                            easy_install

                                                            New in version 0.7.

                                                            Installs Python libraries, optionally in a virtualenv

                                                            parameter required default choices comments
                                                            virtualenv no
                                                              an optional virtualenv directory path to install into. If the virtualenv does not exist, it is created automatically
                                                              name yes
                                                                A Python library name

                                                                Examples from Ansible Playbooks

                                                                easy_install name=pip
                                                                

                                                                Install Flask (http://flask.pocoo.org/) into the specified virtualenv

                                                                easy_install name=flask virtualenv=/webapps/myapp/venv
                                                                


                                                                Notes

                                                                Please note that the easy_install module can only install Python libraries. Thus this module is not able to remove libraries. It is generally recommended to use the pip module which you can first install using easy_install.

                                                                Also note that virtualenv must be installed on the remote host if the virtualenv parameter is specified.

                                                                facter

                                                                New in version 0.2.

                                                                Runs the facter discovery program (https://github.com/puppetlabs/facter) on the remote system, returning JSON data that can be useful for inventory purposes.

                                                                Example command-line invocation

                                                                ansible  www.example.net -m facter
                                                                


                                                                fail

                                                                New in version 0.8.

                                                                This module fails the progress with a custom message. It can be useful for bailing out when a certain condition is met using only_if.

                                                                parameter required default choices comments
                                                                msg no 'Failed because only_if condition is true'
                                                                  The customized message used for failing execution. If ommited, fail will simple bail out with a generic message.
                                                                  rc no 1
                                                                    The return code of the failure. This is currently not used by Ansible, but might be used in the future.

                                                                    Example playbook using fail and only_if together

                                                                    action: fail msg="The system may not be provisioned according to the CMDB status." rc=100

                                                                    only_if: “’$cmdb_status’ != ‘to-be-staged’”

                                                                    </pre></p> <br/>

                                                                    fetch

                                                                    New in version 0.2.

                                                                    This module works like copy, but in reverse. It is used for fetching files from remote machines and storing them locally in a file tree, organized by hostname.

                                                                    parameter required default choices comments
                                                                    dest yes
                                                                      A directory to save the file into. For example, if the dest directory is /backup a src file named /etc/profile on host host.example.com, would be saved into /backup/host.example.com/etc/profile
                                                                      src yes
                                                                        The file on the remote system to fetch. This must be a file, not a directory. Recursive fetching may be supported in a later release.

                                                                        Example from Ansible Playbooks

                                                                        fetch src=/var/log/messages dest=/home/logtree
                                                                        


                                                                        file

                                                                        Sets attributes of files, symlinks, and directories, or removes files/symlinks/directories. Many other modules support the same options as the file module - including copy, template, and assmeble.

                                                                        parameter required default choices comments
                                                                        src no
                                                                          path of the file to link to (applies only to state=link).
                                                                          group no
                                                                            name of the group that should own the file/directory, as would be fed to chown
                                                                            dest yes
                                                                              defines the file being managed, unless when used with state=link, and then sets the destination to create a symbolic link to using src
                                                                              selevel no s0
                                                                                level part of the SELinux file context. This is the MLS/MCS attribute, sometimes known as the range. _default feature works as for seuser.
                                                                                seuser no
                                                                                  user part of SELinux file context. Will default to system policy, if applicable. If set to _default, it will use the user portion of the the policy if available
                                                                                  state no file
                                                                                  • file
                                                                                  • link
                                                                                  • directory
                                                                                  • absent
                                                                                  If directory, all immediate subdirectories will be created if they do not exist. If file, the file will NOT be created if it does not exist, see the copy or template module if you want that behavior. If link, the symbolic link will be created or changed. If absent, directories will be recursively deleted, and files or symlinks will be unlinked.
                                                                                  serole no
                                                                                    role part of SELinux file context, _default feature works as for seuser.
                                                                                    mode no
                                                                                      mode the file or directory should be, such as 0644 as would be fed to
                                                                                      context no
                                                                                      • default
                                                                                      accepts only default as value. This will restore a file's SELinux context in the policy. Does nothing if no default value is available.
                                                                                      owner no
                                                                                        name of the user that should own the file/directory, as would be fed to chown
                                                                                        force no
                                                                                          force is required when changing an existing file to a directory, or a link to a directory, and so on. Use this with caution.
                                                                                          setype no
                                                                                            type part of SELinux file context, _default feature works as for seuser.

                                                                                            Example from Ansible Playbooks

                                                                                            file path=/etc/foo.conf owner=foo group=foo mode=0644
                                                                                            

                                                                                            file src=/file/to/link/to dest=/path/to/symlink owner=foo group=foo state=link
                                                                                            


                                                                                            Notes

                                                                                            See also copy, template, assemble

                                                                                            fireball

                                                                                            New in version 0.9.

                                                                                            This modules launches an ephemeral fireball ZeroMQ message bus daemon on the remote node which Ansible can to communicate with nodes at high speed. The daemon listens on a configurable port for a configurable amount of time. Starting a new fireball as a given user terminates any existing user fireballs. Fireball mode is AES encrypted

                                                                                            parameter required default choices comments
                                                                                            minutes no 30
                                                                                              The fireball listener daemon is started on nodes and will stay around for this number of minutes before turning itself off.
                                                                                              port no 5099
                                                                                                TCP port for ZeroMQ

                                                                                                This example playbook has two plays: the first launches fireball mode on all hosts via SSH, and the second actually starts using fireball node for subsequent management over the fireball interface

                                                                                                - hosts: devservers
                                                                                                  gather_facts: false
                                                                                                  connection: ssh
                                                                                                  sudo: yes
                                                                                                  tasks:
                                                                                                      - action: fireball
                                                                                                
                                                                                                - hosts: devservers
                                                                                                  connection: fireball
                                                                                                  tasks:
                                                                                                      - action: command /usr/bin/anything
                                                                                                
                                                                                                


                                                                                                Notes

                                                                                                See the advanced playbooks chapter for more about using fireball mode.

                                                                                                get_url

                                                                                                New in version 0.6.

                                                                                                Downloads files from HTTP, HTTPS, or FTP to the remote server. The remote server must have direct access to the remote resource.

                                                                                                parameter required default choices comments
                                                                                                url yes
                                                                                                  HTTP, HTTPS, or FTP URL
                                                                                                  dest yes
                                                                                                    absolute path of where to download the file to.If dest is a directory, the basename of the file on the remote server will be used. If a directory, thirsty=yes must also be set.
                                                                                                    thirsty no no
                                                                                                    • yes
                                                                                                    • no
                                                                                                    if yes, will download the file every time and replace the file if the contents change. if no, the file will only be downloaded if the destination does not exist. Generally should be yes only for small local files. prior to 0.6, acts if yes by default. (added in Ansible 0.7)
                                                                                                    others no
                                                                                                      all arguments accepted by the file module also work here

                                                                                                      Example from Ansible Playbooks

                                                                                                      get_url url=http://example.com/path/file.conf dest=/etc/foo.conf mode=0440
                                                                                                      


                                                                                                      Notes

                                                                                                      This module doesn't yet support configuration for proxies or passwords.

                                                                                                      git

                                                                                                      New in version 0.0.1.

                                                                                                      Manage git checkouts of repositories to deploy files or software.

                                                                                                      parameter required default choices comments
                                                                                                      repo yes
                                                                                                        git, ssh, or http protocol address of the git repository.
                                                                                                        dest yes
                                                                                                          Absolute path of where the repository should be checked out to.
                                                                                                          version no HEAD
                                                                                                            What version of the repository to check out. This can be the git SHA, the literal string HEAD, branch name, or a tag name.
                                                                                                            force no yes
                                                                                                            • True
                                                                                                            • False
                                                                                                            (New in 0.7) If yes, any modified files in the working repository will be discarded. Prior to 0.7, this was always 'yes' and could not be disabled.
                                                                                                            remote no origin
                                                                                                              Name of the remote branch.

                                                                                                              Example git checkout from Ansible Playbooks

                                                                                                              git repo=git://foosball.example.org/path/to/repo.git dest=/srv/checkout version=release-0.22
                                                                                                              


                                                                                                              group

                                                                                                              New in version 0.0.2.

                                                                                                              Manage presence of groups on a host.

                                                                                                              parameter required default choices comments
                                                                                                              state no present
                                                                                                              • present
                                                                                                              • absent
                                                                                                              Whether the group should be present or not on the remote host.
                                                                                                              gid no
                                                                                                                Optional GID to set for the group.
                                                                                                                name yes
                                                                                                                  Name of the group to manage.
                                                                                                                  system no no
                                                                                                                  • True
                                                                                                                  • False
                                                                                                                  If yes, indicates that the group created is a system group.

                                                                                                                  Example group command from Ansible Playbooks

                                                                                                                  group name=somegroup state=present
                                                                                                                  


                                                                                                                  hpilo_boot

                                                                                                                  New in version 0.8.

                                                                                                                  This module boots a system through its HP iLO interface. The boot media can be one of: cdrom, floppy, hdd, network or usb. This module requires the hpilo python module.

                                                                                                                  parameter required default choices comments
                                                                                                                  force no
                                                                                                                  • yes
                                                                                                                  • no
                                                                                                                  Whether to force a reboot (even when the system is already booted)
                                                                                                                  media no network
                                                                                                                  • cdrom
                                                                                                                  • floppy
                                                                                                                  • hdd
                                                                                                                  • network
                                                                                                                  • normal
                                                                                                                  • usb
                                                                                                                  The boot media to boot the system from
                                                                                                                  image no
                                                                                                                    The URL of a cdrom, floppy or usb boot media image. protocol://username:password@hostname:port/filenameprotocol is either http or httpsusername:password is optionalport is optional
                                                                                                                    host yes
                                                                                                                      The HP iLO hostname/address that is linked to the physical system.
                                                                                                                      state yes boot_once
                                                                                                                      • boot_always
                                                                                                                      • boot_once
                                                                                                                      • connect
                                                                                                                      • disconnect
                                                                                                                      • no_boot
                                                                                                                      The state of the boot media.no_boot: Do not boot from the deviceboot_once: Boot from the device once and then notthereafterboot_always: Boot from the device each time the serveris rebootedconnect: Connect the virtual media device and set to boot_alwaysdisconnect: Disconnects the virtual media device and set to no_boot
                                                                                                                      login no Administrator
                                                                                                                        The login name to authenticate to the HP iLO interface.
                                                                                                                        password no admin
                                                                                                                          The password to authenticate to the HP iLO interface.
                                                                                                                          match no
                                                                                                                            An optional string to match against the iLO server name.This is a safety measure to prevent accidentally using the wrong HP iLO interface with dire consequences.

                                                                                                                            Task to boot a system using an ISO from an HP iLO interface only if the system is an HP server

                                                                                                                            local_action: hpilo_boot host=$ilo_address login=$ilo_login password=$ilo_password match=$inventory_hostname_short media=cdrom image=$iso_url

                                                                                                                            only_if: “’$cmdb_hwmodel’.startswith(‘HP ‘)

                                                                                                                            </pre></p> <br/>

                                                                                                                            Notes

                                                                                                                            To use a USB key image you need to specify floppy as boot media.

                                                                                                                            This module ought to be run from a system that can access the HP iLO interface directly, either by using local_action or using delegate_to.

                                                                                                                            hpilo_facts

                                                                                                                            New in version 0.8.

                                                                                                                            This module gathers facts for a specific system using its HP iLO interface. These facts include hardware and network related information useful for provisioning (e.g. macaddress, uuid). This module requires the hpilo python module.

                                                                                                                            parameter required default choices comments
                                                                                                                            host yes
                                                                                                                              The HP iLO hostname/address that is linked to the physical system.
                                                                                                                              password no admin
                                                                                                                                The password to authenticate to the HP iLO interface.
                                                                                                                                login no Administrator
                                                                                                                                  The login name to authenticate to the HP iLO interface.
                                                                                                                                  match no
                                                                                                                                    An optional string to match against the iLO server name.This is a safety measure to prevent accidentally using the wrong HP iLO interface with dire consequences.

                                                                                                                                    Task to gather facts from a HP iLO interface only if the system is an HP server

                                                                                                                                    local_action: hpilo_facts host=$ilo_address login=$ilo_login password=$ilo_password match=$inventory_hostname_short

                                                                                                                                    only_if: “’$cmdb_hwmodel’.startswith(‘HP ‘)

                                                                                                                                    </pre></p> <p>Typical output of HP iLO_facts for a physical system</p> <p><pre> - hw_bios_date: “05/05/2011”

                                                                                                                                    hw_bios_version: “P68” hw_eth0: - macaddress: “00:11:22:33:44:55”

                                                                                                                                    macaddress_dash: “00-11-22-33-44-55”

                                                                                                                                    hw_eth1: - macaddress: “00:11:22:33:44:57”

                                                                                                                                    macaddress_dash: “00-11-22-33-44-57”

                                                                                                                                    hw_eth2: - macaddress: “00:11:22:33:44:5A”

                                                                                                                                    macaddress_dash: “00-11-22-33-44-5A”

                                                                                                                                    hw_eth3: - macaddress: “00:11:22:33:44:5C”

                                                                                                                                    macaddress_dash: “00-11-22-33-44-5C”

                                                                                                                                    hw_eth_ilo: - macaddress: “00:11:22:33:44:BA”

                                                                                                                                    macaddress_dash: “00-11-22-33-44-BA”

                                                                                                                                    hw_product_name: “ProLiant DL360 G7” hw_product_uuid: “ef50bac8-2845-40ff-81d9-675315501dac” hw_system_serial: “ABC12345D6” hw_uuid: “123456ABC78901D2”

                                                                                                                                    </pre></p> <br/>

                                                                                                                                    Notes

                                                                                                                                    This module ought to be run from a system that can access the HP iLO interface directly, either by using local_action or using delegate_to.

                                                                                                                                    ini_file

                                                                                                                                    New in version 0.9.

                                                                                                                                    Manage (add, remove, change) individual settings in an INI-style file without having to manage the file as a whole with, say, template or assemble. Adds missing sections if they don’t exist.

                                                                                                                                    parameter required default choices comments
                                                                                                                                    option no
                                                                                                                                      if set (required for changing a value), this is the name of the option.May be omitted if adding/removing a whole section.
                                                                                                                                      others no
                                                                                                                                        all arguments accepted by the file module also work here
                                                                                                                                        dest yes
                                                                                                                                          Path to the INI-style file; this file is created if required
                                                                                                                                          section yes
                                                                                                                                            Section name in INI file. This is added if state=present automatically when a single value is being set.
                                                                                                                                            backup no
                                                                                                                                            • yes
                                                                                                                                            • no
                                                                                                                                            Create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly.
                                                                                                                                            value no
                                                                                                                                              the string value to be associated with an option. May be omitted when removing an option.

                                                                                                                                              Ensure fav=lemonade is in section [drinks] in said file

                                                                                                                                              ini_file dest=/etc/conf section=drinks option=fav value=lemonade mode=0600 backup=true
                                                                                                                                              

                                                                                                                                              ini_file dest=/etc/anotherconf
                                                                                                                                                   section=drinks
                                                                                                                                                   option=temperature
                                                                                                                                                   value=cold
                                                                                                                                                   backup=true
                                                                                                                                              
                                                                                                                                              


                                                                                                                                              Notes

                                                                                                                                              While it is possible to add an option without specifying a value, this makes no sense.

                                                                                                                                              lineinfile

                                                                                                                                              New in version 0.7.

                                                                                                                                              This module will search a file for a line, and ensure that it is present or absent. This is primarily useful when you want to change a single line in a file only. For other cases, see the copy or template modules.

                                                                                                                                              parameter required default choices comments
                                                                                                                                              insertafter no EOF
                                                                                                                                              • BOF
                                                                                                                                              • EOF
                                                                                                                                              Used with state=present. If specified, the line will be inserted after the specified regular expression. Two special values are available; BOF for inserting the line at the beginning of the file, and EOF for inserting the line at the end of the file.
                                                                                                                                              state no present
                                                                                                                                              • present
                                                                                                                                              • absent
                                                                                                                                              Whether the line should be there or not.
                                                                                                                                              dest yes
                                                                                                                                                The file to modify
                                                                                                                                                regexp yes
                                                                                                                                                  The regular expression to look for in the file. For state=present, the pattern to replace. For state=absent, the pattern of the line to remove.
                                                                                                                                                  line no
                                                                                                                                                    Required for state=present. The line to insert/replace into the file. Must match the value given to regexp.
                                                                                                                                                    backup no
                                                                                                                                                      Create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly.

                                                                                                                                                      lineinfile dest=/etc/selinux/config regexp=^SELINUX= line=SELINUX=disabled
                                                                                                                                                      

                                                                                                                                                      lineinfile dest=/etc/sudoers state=absent regexp="^%wheel"
                                                                                                                                                      


                                                                                                                                                      mount

                                                                                                                                                      New in version 0.6.

                                                                                                                                                      This module controls active and configured mount points in /etc/fstab.

                                                                                                                                                      parameter required default choices comments
                                                                                                                                                      src yes
                                                                                                                                                        device to be mounted on name.
                                                                                                                                                        state yes
                                                                                                                                                        • present
                                                                                                                                                        • absent
                                                                                                                                                        • mounted
                                                                                                                                                        • unmounted
                                                                                                                                                        If mounted or unmounted, the device will be actively mounted or unmounted as well as just configured in fstab. absent and present only deal with fstab.
                                                                                                                                                        name yes
                                                                                                                                                          path to the mount point, eg: /mnt/files
                                                                                                                                                          dump no
                                                                                                                                                            dump (see fstab(8))
                                                                                                                                                            passno no
                                                                                                                                                              passno (see fstab(8))
                                                                                                                                                              opts no
                                                                                                                                                                mount options (see fstab(8))
                                                                                                                                                                fstype yes
                                                                                                                                                                  file-system type

                                                                                                                                                                  Mount DVD read-only

                                                                                                                                                                  mount name=/mnt/dvd src=/dev/sr0 fstype=iso9660 opts=ro
                                                                                                                                                                  


                                                                                                                                                                  mysql_db

                                                                                                                                                                  New in version 0.6.

                                                                                                                                                                  Add or remove MySQL databases from a remote host.

                                                                                                                                                                  parameter required default choices comments
                                                                                                                                                                  state no present
                                                                                                                                                                  • present
                                                                                                                                                                  • absent
                                                                                                                                                                  The database state
                                                                                                                                                                  name yes
                                                                                                                                                                    name of the database to add or remove
                                                                                                                                                                    encoding no
                                                                                                                                                                      Encoding mode
                                                                                                                                                                      collation no
                                                                                                                                                                        Collation mode
                                                                                                                                                                        login_user no
                                                                                                                                                                          The username used to authenticate with
                                                                                                                                                                          login_host no localhost
                                                                                                                                                                            Host running the database
                                                                                                                                                                            login_password no
                                                                                                                                                                              The password used to authenticate with

                                                                                                                                                                              Create a new database with name 'bobdata'

                                                                                                                                                                              mysql_db db=bobdata state=present
                                                                                                                                                                              


                                                                                                                                                                              Notes

                                                                                                                                                                              Requires the MySQLdb Python package on the remote host. For Ubuntu, this is as easy as apt-get install python-mysqldb.

                                                                                                                                                                              Both login_password and login_username are required when you are passing credentials. If none are present, the module will attempt to read the credentials from ~/.my.cnf, and finally fall back to using the MySQL default login of 'root' with no password.

                                                                                                                                                                              mysql_user

                                                                                                                                                                              New in version 0.6.

                                                                                                                                                                              Adds or removes a user from a MySQL database.

                                                                                                                                                                              parameter required default choices comments
                                                                                                                                                                              name yes
                                                                                                                                                                                name of the user (role) to add or remove
                                                                                                                                                                                login_user no
                                                                                                                                                                                  The username used to authenticate with
                                                                                                                                                                                  login_host no localhost
                                                                                                                                                                                    Host running the database
                                                                                                                                                                                    host no localhost
                                                                                                                                                                                      the 'host' part of the MySQL username
                                                                                                                                                                                      state no present
                                                                                                                                                                                      • present
                                                                                                                                                                                      • absent
                                                                                                                                                                                      The database state
                                                                                                                                                                                      login_password no
                                                                                                                                                                                        The password used to authenticate with
                                                                                                                                                                                        password no
                                                                                                                                                                                          set the user's password
                                                                                                                                                                                          priv no
                                                                                                                                                                                            MySQL privileges string in the format: db.table:priv1,priv2

                                                                                                                                                                                            Create database user with name 'bob' and password '12345' with all database privileges

                                                                                                                                                                                            mysql_user name=bob password=12345 priv=*.*:ALL state=present
                                                                                                                                                                                            

                                                                                                                                                                                            Ensure no user named 'sally' exists, also passing in the auth credentials.

                                                                                                                                                                                            mysql_user login_user=root login_password=123456 name=sally state=absent
                                                                                                                                                                                            

                                                                                                                                                                                            Example privileges string format

                                                                                                                                                                                            mydb.*:INSERT,UPDATE/anotherdb.*:SELECT/yetanotherdb.*:ALL
                                                                                                                                                                                            


                                                                                                                                                                                            Notes

                                                                                                                                                                                            Requires the MySQLdb Python package on the remote host. For Ubuntu, this is as easy as apt-get install python-mysqldb.

                                                                                                                                                                                            Both login_password and login_username are required when you are passing credentials. If none are present, the module will attempt to read the credentials from ~/.my.cnf, and finally fall back to using the MySQL default login of 'root' with no password.

                                                                                                                                                                                            nagios

                                                                                                                                                                                            New in version 0.7.

                                                                                                                                                                                            The nagios module has two basic functions: scheduling downtime and toggling alerts for services or hosts. All actions require the host parameter to be given explicitly. In playbooks you can use the $inventory_hostname variable to refer to the host the playbook is currently running on. You can specify multiple services at once by separating them with commas, .e.g., services=httpd,nfs,puppet. When specifying what service to handle there is a special service value, host, which will handle alerts/downtime for the host itself, e.g., service=host. This keyword may not be given with other services at the same time. Setting alerts/downtime for a host does not affect alerts/downtime for any of the services running on it. When using the nagios module you will need to specify your nagios server using the delegate_to parameter.

                                                                                                                                                                                            parameter required default choices comments
                                                                                                                                                                                            action yes
                                                                                                                                                                                            • downtime
                                                                                                                                                                                            • enable_alerts
                                                                                                                                                                                            • disable_alerts
                                                                                                                                                                                            • silence
                                                                                                                                                                                            • unsilence
                                                                                                                                                                                            Action to take.
                                                                                                                                                                                            host yes
                                                                                                                                                                                              Host to operate on in Nagios.
                                                                                                                                                                                              author no Ansible
                                                                                                                                                                                                Author to leave downtime comments as. - Only useable with the downtime action.
                                                                                                                                                                                                services yes
                                                                                                                                                                                                  What to manage downtime/alerts for. Separate multiple services with commas.service is an alias for services.Required option when using the downtime, enable_alerts, and disable_alerts actions.
                                                                                                                                                                                                  minutes no 30
                                                                                                                                                                                                    Minutes to schedule downtime for.Only useable with the downtime action.
                                                                                                                                                                                                    cmdfile no auto-detected
                                                                                                                                                                                                      Path to the nagios command file (FIFO pipe).Only required if auto-detection fails.

                                                                                                                                                                                                      set 30 minutes of apache downtime

                                                                                                                                                                                                      nagios action=downtime minutes=30 service=httpd host=$inventory_hostname
                                                                                                                                                                                                      

                                                                                                                                                                                                      schedule an hour of HOST downtime

                                                                                                                                                                                                      nagios action=downtime minutes=60 service=host host=$inventory_hostname
                                                                                                                                                                                                      

                                                                                                                                                                                                      schedule downtime for a few services

                                                                                                                                                                                                      nagios action=downtime services=frob,foobar,qeuz host=$inventory_hostname
                                                                                                                                                                                                      

                                                                                                                                                                                                      enable SMART disk alerts

                                                                                                                                                                                                      nagios action=enable_alerts service=smart host=$inventory_hostname
                                                                                                                                                                                                      

                                                                                                                                                                                                      two services at once: disable httpd and nfs alerts

                                                                                                                                                                                                      nagios action=disable_alerts service=httpd,nfs host=$inventory_hostname
                                                                                                                                                                                                      

                                                                                                                                                                                                      disable HOST alerts

                                                                                                                                                                                                      nagios action=disable_alerts service=host host=$inventory_hostname
                                                                                                                                                                                                      

                                                                                                                                                                                                      silence ALL alerts

                                                                                                                                                                                                      nagios action=silence host=$inventory_hostname
                                                                                                                                                                                                      

                                                                                                                                                                                                      unsilence all alerts

                                                                                                                                                                                                      nagios action=unsilence host=$inventory_hostname
                                                                                                                                                                                                      


                                                                                                                                                                                                      ohai

                                                                                                                                                                                                      New in version 0.6.

                                                                                                                                                                                                      Similar to the facter module, this runs the ohai discovery program (http://wiki.opscode.com/display/chef/Ohai) on the remote host and returns JSON inventory data. Ohai data is a bit more verbose and nested than facter.

                                                                                                                                                                                                      Retrieve ohai data from all Web servers and store in one-file per host

                                                                                                                                                                                                      ansible webservers -m ohai --tree=/tmp/ohaidata
                                                                                                                                                                                                      


                                                                                                                                                                                                      pause

                                                                                                                                                                                                      New in version 0.8.

                                                                                                                                                                                                      Pauses playbook execution for a set amount of time, or until a prompt is acknowledged. All parameters are optional. The default behavior is to pause with a prompt. You can use ctrl+c if you wish to advance a pause earlier than it is set to expire or if you need to abort a playbook run entirely. To continue early: press ctrl+c and then c. To abort a playbook: press ctrl+c and then a. The pause module integrates into async/parallelized playbooks without any special considerations (see also: Rolling Updates). When using pauses with the serial playbook parameter (as in rolling updates) you are only prompted once for the current group of hosts.

                                                                                                                                                                                                      parameter required default choices comments
                                                                                                                                                                                                      seconds no
                                                                                                                                                                                                        Number of minutes to pause for.
                                                                                                                                                                                                        minutes no
                                                                                                                                                                                                          Number of minutes to pause for.
                                                                                                                                                                                                          prompt no
                                                                                                                                                                                                            Optional text to use for the prompt message.

                                                                                                                                                                                                            Pause for 5 minutes to build app cache.

                                                                                                                                                                                                            pause minutes=5
                                                                                                                                                                                                            

                                                                                                                                                                                                            Pause until you can verify updates to an application were successful.

                                                                                                                                                                                                            pause
                                                                                                                                                                                                            

                                                                                                                                                                                                            A helpful reminder of what to look out for post-update.

                                                                                                                                                                                                            pause prompt=Make sure org.foo.FooOverload exception is not present
                                                                                                                                                                                                            


                                                                                                                                                                                                            ping

                                                                                                                                                                                                            A trivial test module, this module always returns ‘pong’ on successful contact. It does not make sense in playbooks, but is useful from /usr/bin/ansible

                                                                                                                                                                                                            Test 'webservers' status

                                                                                                                                                                                                            ansible webservers -m ping
                                                                                                                                                                                                            


                                                                                                                                                                                                            pip

                                                                                                                                                                                                            New in version 0.7.

                                                                                                                                                                                                            Manage Python library dependencies.

                                                                                                                                                                                                            parameter required default choices comments
                                                                                                                                                                                                            virtualenv no
                                                                                                                                                                                                              An optional path to a virtualenv directory to install into
                                                                                                                                                                                                              state no present
                                                                                                                                                                                                              • present
                                                                                                                                                                                                              • absent
                                                                                                                                                                                                              • latest
                                                                                                                                                                                                              The state of module
                                                                                                                                                                                                              version no
                                                                                                                                                                                                                The version number to install of the Python library specified in the 'name' parameter
                                                                                                                                                                                                                requirements no
                                                                                                                                                                                                                  The path to a pip requirements file
                                                                                                                                                                                                                  name yes
                                                                                                                                                                                                                    The name of a Python library to install

                                                                                                                                                                                                                    Install flask python package.

                                                                                                                                                                                                                    pip name=flask
                                                                                                                                                                                                                    

                                                                                                                                                                                                                    Install flask python package on version 0.8.

                                                                                                                                                                                                                    pip name=flask version=0.8
                                                                                                                                                                                                                    

                                                                                                                                                                                                                    Install Flask (http://flask.pocoo.org/) into the specified virtualenv

                                                                                                                                                                                                                    pip name=flask virtualenv=/srv/webapps/my_app/venv
                                                                                                                                                                                                                    

                                                                                                                                                                                                                    Install specified python requirements.

                                                                                                                                                                                                                    pip requirements=/srv/webapps/my_app/src/requirements.txt
                                                                                                                                                                                                                    

                                                                                                                                                                                                                    Install specified python requirements in indicated virtualenv.

                                                                                                                                                                                                                    pip requirements=/srv/webapps/my_app/src/requirements.txt virtualenv=/srv/webapps/my_app/venv
                                                                                                                                                                                                                    


                                                                                                                                                                                                                    Notes

                                                                                                                                                                                                                    Please note that http://www.virtualenv.org/, virtualenv must be installed on the remote host if the virtualenv parameter is specified.

                                                                                                                                                                                                                    postgresql_db

                                                                                                                                                                                                                    New in version 0.6.

                                                                                                                                                                                                                    Add or remove PostgreSQL databases from a remote host.

                                                                                                                                                                                                                    parameter required default choices comments
                                                                                                                                                                                                                    state no present
                                                                                                                                                                                                                    • present
                                                                                                                                                                                                                    • absent
                                                                                                                                                                                                                    The database state
                                                                                                                                                                                                                    name yes
                                                                                                                                                                                                                      name of the database to add or remove
                                                                                                                                                                                                                      login_password no
                                                                                                                                                                                                                        The password used to authenticate with
                                                                                                                                                                                                                        owner no
                                                                                                                                                                                                                          Name of the role to set as owner of the database
                                                                                                                                                                                                                          login_user no
                                                                                                                                                                                                                            The username used to authenticate with
                                                                                                                                                                                                                            login_host no localhost
                                                                                                                                                                                                                              Host running the database

                                                                                                                                                                                                                              Create a new database with name 'acme'

                                                                                                                                                                                                                              postgresql_db db=acme
                                                                                                                                                                                                                              


                                                                                                                                                                                                                              Notes

                                                                                                                                                                                                                              The default authentication assumes that you are either logging in as or sudo'ing to the postgres account on the host.

                                                                                                                                                                                                                              This module uses psycopg2, a Python PostgreSQL database adapter. You must ensure that psycopg2 is installed on the host before using this module. If the remote host is the PostgreSQL server (which is the default case), then PostgreSQL must also be installed on the remote host. For Ubuntu-based systems, install the postgresql, libpq-dev, and python-psycopg2 packages on the remote host before using this module.

                                                                                                                                                                                                                              postgresql_user

                                                                                                                                                                                                                              New in version 0.6.

                                                                                                                                                                                                                              Add or remove PostgreSQL users (roles) from a remote host and, optionally, grant the users access to an existing database or tables. The fundamental function of the module is to create, or delete, roles from a PostgreSQL cluster. Privilege assignment, or removal, is an optional step, which works on one database at a time. This allows for the module to be called several times in the same module to modify the permissions on different databases, or to grant permissions to already existing users. A user cannot be removed untill all the privileges have been stripped from the user. In such situation, if the module tries to remove the user it will fail. To avoid this from happening the fail_on_user option signals the module to try to remove the user, but if not possible keep going; the module will report if changes happened and separately if the user was removed or not.

                                                                                                                                                                                                                              parameter required default choices comments
                                                                                                                                                                                                                              name yes
                                                                                                                                                                                                                                name of the user (role) to add or remove
                                                                                                                                                                                                                                login_user no postgres
                                                                                                                                                                                                                                  User (role) used to authenticate with PostgreSQL
                                                                                                                                                                                                                                  login_host no localhost
                                                                                                                                                                                                                                    Host running PostgreSQL.
                                                                                                                                                                                                                                    db no
                                                                                                                                                                                                                                      name of database where permissions will be granted
                                                                                                                                                                                                                                      state no present
                                                                                                                                                                                                                                      • present
                                                                                                                                                                                                                                      • absent
                                                                                                                                                                                                                                      The database state
                                                                                                                                                                                                                                      login_password no
                                                                                                                                                                                                                                        Password used to authenticate with PostgreSQL
                                                                                                                                                                                                                                        password yes
                                                                                                                                                                                                                                          set the user's password
                                                                                                                                                                                                                                          fail_on_user no True
                                                                                                                                                                                                                                          • yes
                                                                                                                                                                                                                                          • no
                                                                                                                                                                                                                                          if yes, fail when user can't be removed. Otherwise just log and continue
                                                                                                                                                                                                                                          priv no
                                                                                                                                                                                                                                            PostgreSQL privileges string in the format: table:priv1,priv2

                                                                                                                                                                                                                                            Create django user and grant access to database and products table

                                                                                                                                                                                                                                            postgresql_user db=acme user=django password=ceec4eif7ya priv=CONNECT/products:ALL
                                                                                                                                                                                                                                            

                                                                                                                                                                                                                                            Remove test user privileges from acme

                                                                                                                                                                                                                                            postgresql_user db=acme user=test priv=ALL/products:ALL state=absent fail_on_user=no
                                                                                                                                                                                                                                            

                                                                                                                                                                                                                                            Remove test user from test database and the cluster

                                                                                                                                                                                                                                            postgresql_user db=test user=test priv=ALL state=absent
                                                                                                                                                                                                                                            

                                                                                                                                                                                                                                            Example privileges string format

                                                                                                                                                                                                                                            INSERT,UPDATE/table:SELECT/anothertable:ALL
                                                                                                                                                                                                                                            


                                                                                                                                                                                                                                            Notes

                                                                                                                                                                                                                                            The default authentication assumes that you are either logging in as or sudo'ing to the postgres account on the host.

                                                                                                                                                                                                                                            This module uses psycopg2, a Python PostgreSQL database adapter. You must ensure that psycopg2 is installed on the host before using this module. If the remote host is the PostgreSQL server (which is the default case), then PostgreSQL must also be installed on the remote host. For Ubuntu-based systems, install the postgresql, libpq-dev, and python-psycopg2 packages on the remote host before using this module.

                                                                                                                                                                                                                                            raw

                                                                                                                                                                                                                                            Executes a low-down and dirty SSH command, not going through the module subsystem. This is useful and should only be done in two cases. The first case is installing python-simplejson on older (Python 2.4 and before) hosts that need it as a dependency to run modules, since nearly all core modules require it. Another is speaking to any devices such as routers that do not have any Python installed. In any other case, using the shell or command module is much more appropriate. Arguments given to raw are run directly through the configured remote shell and only output is returned. There is no error detection or change handler support for this module

                                                                                                                                                                                                                                            Example from /usr/bin/ansible to bootstrap a legacy python 2.4 host

                                                                                                                                                                                                                                            ansible newhost.example.com -m raw -a "yum -y install python-simplejson"
                                                                                                                                                                                                                                            


                                                                                                                                                                                                                                            seboolean

                                                                                                                                                                                                                                            New in version 0.7.

                                                                                                                                                                                                                                            Toggles SELinux booleans.

                                                                                                                                                                                                                                            parameter required default choices comments
                                                                                                                                                                                                                                            state yes
                                                                                                                                                                                                                                            • true
                                                                                                                                                                                                                                            • false
                                                                                                                                                                                                                                            Desired boolean value
                                                                                                                                                                                                                                            name yes
                                                                                                                                                                                                                                              Name of the boolean to configure
                                                                                                                                                                                                                                              persistent no
                                                                                                                                                                                                                                              • yes
                                                                                                                                                                                                                                              • no
                                                                                                                                                                                                                                              Set to 'yes' if the boolean setting should survive a reboot

                                                                                                                                                                                                                                              Set httpd_can_network_connect SELinux flag to true and persistent

                                                                                                                                                                                                                                              seboolean name=httpd_can_network_connect state=true persistent=yes
                                                                                                                                                                                                                                              


                                                                                                                                                                                                                                              Notes

                                                                                                                                                                                                                                              Not tested on any debian based system

                                                                                                                                                                                                                                              selinux

                                                                                                                                                                                                                                              New in version 0.7.

                                                                                                                                                                                                                                              Configures the SELinux mode and policy. A reboot may be required after usage. Ansible will not issue this reboot but will let you know when it is required.

                                                                                                                                                                                                                                              parameter required default choices comments
                                                                                                                                                                                                                                              policy yes
                                                                                                                                                                                                                                                name of the SELinux policy to use (example: 'targeted')
                                                                                                                                                                                                                                                state yes
                                                                                                                                                                                                                                                • enforcing
                                                                                                                                                                                                                                                • permissive
                                                                                                                                                                                                                                                • disabled
                                                                                                                                                                                                                                                The SELinux mode
                                                                                                                                                                                                                                                conf no /etc/selinux/config
                                                                                                                                                                                                                                                  path to the SELinux configuration file, if non-standard

                                                                                                                                                                                                                                                  selinux policy=targeted state=enforcing
                                                                                                                                                                                                                                                  

                                                                                                                                                                                                                                                  selinux policy=targeted state=disabled
                                                                                                                                                                                                                                                  


                                                                                                                                                                                                                                                  Notes

                                                                                                                                                                                                                                                  Not tested on any debian based system

                                                                                                                                                                                                                                                  service

                                                                                                                                                                                                                                                  New in version 0.1.

                                                                                                                                                                                                                                                  Controls services on remote hosts.

                                                                                                                                                                                                                                                  parameter required default choices comments
                                                                                                                                                                                                                                                  pattern no
                                                                                                                                                                                                                                                    If the service does not respond to the status command, name a substring to look for as would be found in the output of the ps command as a stand-in for a status result. If the string is found, the service will be assumed to be running. (added in Ansible 0.7)
                                                                                                                                                                                                                                                    state no
                                                                                                                                                                                                                                                    • running
                                                                                                                                                                                                                                                    • started
                                                                                                                                                                                                                                                    • stopped
                                                                                                                                                                                                                                                    • restarted
                                                                                                                                                                                                                                                    • reloaded
                                                                                                                                                                                                                                                    started, stopped, reloaded, restarted. Started/stopped are idempotent actions that will not run commands unless necessary. restarted will always bounce the service. reloaded will always reload.
                                                                                                                                                                                                                                                    enabled no
                                                                                                                                                                                                                                                    • yes
                                                                                                                                                                                                                                                    • no
                                                                                                                                                                                                                                                    Whether the service should start on boot.
                                                                                                                                                                                                                                                    name yes
                                                                                                                                                                                                                                                      Name of the service.

                                                                                                                                                                                                                                                      Example action from Ansible Playbooks

                                                                                                                                                                                                                                                      service name=httpd state=started
                                                                                                                                                                                                                                                      

                                                                                                                                                                                                                                                      Example action from Ansible Playbooks

                                                                                                                                                                                                                                                      service name=httpd state=stopped
                                                                                                                                                                                                                                                      

                                                                                                                                                                                                                                                      Example action from Ansible Playbooks

                                                                                                                                                                                                                                                      service name=httpd state=restarted
                                                                                                                                                                                                                                                      

                                                                                                                                                                                                                                                      Example action from Ansible Playbooks

                                                                                                                                                                                                                                                      service name=httpd state=reloaded
                                                                                                                                                                                                                                                      

                                                                                                                                                                                                                                                      Example action from Ansible Playbooks

                                                                                                                                                                                                                                                      service name=foo pattern=/usr/bin/foo state=started
                                                                                                                                                                                                                                                      


                                                                                                                                                                                                                                                      setup

                                                                                                                                                                                                                                                      This module is automatically called by playbooks to gather useful variables about remote hosts that can be used in playbooks. It can also be executed directly by /usr/bin/ansible to check what variables are available to a host. Ansible provides many facts about the system, automatically.

                                                                                                                                                                                                                                                      Obtain facts from all hosts and store them indexed by hostname at /tmp/facts.

                                                                                                                                                                                                                                                      ansible all -m setup -tree /tmp/facts
                                                                                                                                                                                                                                                      


                                                                                                                                                                                                                                                      Notes

                                                                                                                                                                                                                                                      More ansible facts will be added with successive releases. If facter or ohai are installed, variables from these programs will also be snapshotted into the JSON file for usage in templating. These variables are prefixed with facter_ and ohai_ so it's easy to tell their source. All variables are bubbled up to the caller. Using the ansible facts and choosing to not install facter and ohai means you can avoid Ruby-dependencies on your remote systems.

                                                                                                                                                                                                                                                      shell

                                                                                                                                                                                                                                                      New in version 0.2.

                                                                                                                                                                                                                                                      The shell module takes the command name followed by a list of arguments, space delimited. It is almost exactly like the command module but runs the command through a shell (/bin/sh) on the remote node.

                                                                                                                                                                                                                                                      parameter required default choices comments
                                                                                                                                                                                                                                                      creates no
                                                                                                                                                                                                                                                        a filename, when it already exists, this step will NOT be run
                                                                                                                                                                                                                                                        chdir no
                                                                                                                                                                                                                                                          cd into this directory before running the command (0.6 and later)
                                                                                                                                                                                                                                                          (free form) no
                                                                                                                                                                                                                                                            The command module takes a free form command to run

                                                                                                                                                                                                                                                            Execute the command in remote shell

                                                                                                                                                                                                                                                            shell somescript.sh >> somelog.txt
                                                                                                                                                                                                                                                            


                                                                                                                                                                                                                                                            Notes

                                                                                                                                                                                                                                                            If you want to execute a command securely and predicably, it may be better to use the command module instead. Best practices when writing playbooks will follow the trend of using command unless shell is explicitly required. When running ad-hoc commands, use your best judgement.

                                                                                                                                                                                                                                                            slurp

                                                                                                                                                                                                                                                            This module works like fetch. It is used for fetching a base64- encoded blob containing the data in a remote file.

                                                                                                                                                                                                                                                            parameter required default choices comments
                                                                                                                                                                                                                                                            src yes
                                                                                                                                                                                                                                                              The file on the remote system to fetch. This must be a file, not a directory.

                                                                                                                                                                                                                                                              Example using /usr/bin/ansible

                                                                                                                                                                                                                                                              ansible host -m slurp -a 'src=/tmp/xx'
                                                                                                                                                                                                                                                              host | success >> {
                                                                                                                                                                                                                                                                 "content": "aGVsbG8gQW5zaWJsZSB3b3JsZAo=",
                                                                                                                                                                                                                                                                 "encoding": "base64"
                                                                                                                                                                                                                                                              }
                                                                                                                                                                                                                                                              
                                                                                                                                                                                                                                                              


                                                                                                                                                                                                                                                              Notes

                                                                                                                                                                                                                                                              See also: fetch

                                                                                                                                                                                                                                                              subversion

                                                                                                                                                                                                                                                              New in version 0.7.

                                                                                                                                                                                                                                                              This module is really simple, so for now this checks out from the given branch of a repo at a particular SHA or tag. Latest is not supported, you should not be doing that.

                                                                                                                                                                                                                                                              parameter required default choices comments
                                                                                                                                                                                                                                                              repo yes
                                                                                                                                                                                                                                                                The subversion URL to the repository.
                                                                                                                                                                                                                                                                dest yes
                                                                                                                                                                                                                                                                  Absolute path where the repository should be deployed.
                                                                                                                                                                                                                                                                  force no True
                                                                                                                                                                                                                                                                  • yes
                                                                                                                                                                                                                                                                  • no
                                                                                                                                                                                                                                                                  If yes, any modified files in the working repository will be discarded. If no, this module will fail if it encounters modified files.

                                                                                                                                                                                                                                                                  Export subversion repository in a specified folder

                                                                                                                                                                                                                                                                  subversion repo=svn+ssh://an.example.org/path/to/repo dest=/src/checkout
                                                                                                                                                                                                                                                                  


                                                                                                                                                                                                                                                                  Notes

                                                                                                                                                                                                                                                                  Requires subversion and grep on the client.

                                                                                                                                                                                                                                                                  supervisorctl

                                                                                                                                                                                                                                                                  New in version 0.7.

                                                                                                                                                                                                                                                                  Manage the state of a program or group of programs running via Supervisord

                                                                                                                                                                                                                                                                  parameter required default choices comments
                                                                                                                                                                                                                                                                  state yes
                                                                                                                                                                                                                                                                  • started
                                                                                                                                                                                                                                                                  • stopped
                                                                                                                                                                                                                                                                  • restarted
                                                                                                                                                                                                                                                                  The state of service
                                                                                                                                                                                                                                                                  name yes
                                                                                                                                                                                                                                                                    The name of the supervisord program/process to manage

                                                                                                                                                                                                                                                                    Manage the state of program my_app to be in started state.

                                                                                                                                                                                                                                                                    supervisorctl name=my_app state=started
                                                                                                                                                                                                                                                                    


                                                                                                                                                                                                                                                                    template

                                                                                                                                                                                                                                                                    Templates are processed by the Jinja2 templating language (http://jinja.pocoo.org/docs/) - documentation on the template formatting can be found in the Template Designer Documentation (http://jinja.pocoo.org/docs/templates/).

                                                                                                                                                                                                                                                                    parameter required default choices comments
                                                                                                                                                                                                                                                                    dest yes
                                                                                                                                                                                                                                                                      Location to render the template to on the remote machine.
                                                                                                                                                                                                                                                                      src yes
                                                                                                                                                                                                                                                                        Path of a Jinja2 formatted template on the local server. This can be a relative or absolute path.
                                                                                                                                                                                                                                                                        backup no no
                                                                                                                                                                                                                                                                        • yes
                                                                                                                                                                                                                                                                        • no
                                                                                                                                                                                                                                                                        Create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly.
                                                                                                                                                                                                                                                                        others no
                                                                                                                                                                                                                                                                          all arguments accepted by the file module also work here

                                                                                                                                                                                                                                                                          Example from Ansible Playbooks

                                                                                                                                                                                                                                                                          template src=/mytemplates/foo.j2 dest=/etc/file.conf owner=bin group=wheel mode=0644
                                                                                                                                                                                                                                                                          


                                                                                                                                                                                                                                                                          Notes

                                                                                                                                                                                                                                                                          Since Ansible version 0.9, templates are loaded with trim_blocks=True.

                                                                                                                                                                                                                                                                          user

                                                                                                                                                                                                                                                                          New in version 0.2.

                                                                                                                                                                                                                                                                          Manage user accounts and user attributes.

                                                                                                                                                                                                                                                                          parameter required default choices comments
                                                                                                                                                                                                                                                                          comment no
                                                                                                                                                                                                                                                                            Optionally sets the description (aka GECOS) of user account.
                                                                                                                                                                                                                                                                            shell no
                                                                                                                                                                                                                                                                              Optionally set the user's shell.
                                                                                                                                                                                                                                                                              force no no
                                                                                                                                                                                                                                                                              • True
                                                                                                                                                                                                                                                                              • False
                                                                                                                                                                                                                                                                              When used with state=absent, behavior is as with userdel --force.
                                                                                                                                                                                                                                                                              name yes
                                                                                                                                                                                                                                                                                Name of the user to create, remove or modify.
                                                                                                                                                                                                                                                                                createhome no yes
                                                                                                                                                                                                                                                                                • True
                                                                                                                                                                                                                                                                                • False
                                                                                                                                                                                                                                                                                Unless set to no, a home directory will be made for the user when the account is created.
                                                                                                                                                                                                                                                                                system no no
                                                                                                                                                                                                                                                                                • True
                                                                                                                                                                                                                                                                                • False
                                                                                                                                                                                                                                                                                When creating an account, setting this to yes makes the user a system account. This setting cannot be changed on existing users.
                                                                                                                                                                                                                                                                                remove no no
                                                                                                                                                                                                                                                                                • True
                                                                                                                                                                                                                                                                                • False
                                                                                                                                                                                                                                                                                When used with state=absent, behavior is as with userdel --remove.
                                                                                                                                                                                                                                                                                state no present
                                                                                                                                                                                                                                                                                • present
                                                                                                                                                                                                                                                                                • absent
                                                                                                                                                                                                                                                                                Whether the account should exist. When absent, removes the user account.
                                                                                                                                                                                                                                                                                groups no
                                                                                                                                                                                                                                                                                  Puts the user in this comma-delimited list of groups.
                                                                                                                                                                                                                                                                                  home no
                                                                                                                                                                                                                                                                                    Optionally set the user's home directory.
                                                                                                                                                                                                                                                                                    group no
                                                                                                                                                                                                                                                                                      Optionally sets the user's primary group (takes a group name).
                                                                                                                                                                                                                                                                                      password no
                                                                                                                                                                                                                                                                                        Optionally set the user's password to this crypted value. See the user example in the github examples directory for what this looks like in a playbook.
                                                                                                                                                                                                                                                                                        append no
                                                                                                                                                                                                                                                                                          If yes, will only add groups, not set them to just the list in groups.
                                                                                                                                                                                                                                                                                          uid no
                                                                                                                                                                                                                                                                                            Optionally sets the UID of the user.

                                                                                                                                                                                                                                                                                            virt

                                                                                                                                                                                                                                                                                            New in version 0.2.

                                                                                                                                                                                                                                                                                            Manages virtual machines supported by libvirt.

                                                                                                                                                                                                                                                                                            parameter required default choices comments
                                                                                                                                                                                                                                                                                            state no no
                                                                                                                                                                                                                                                                                            • running
                                                                                                                                                                                                                                                                                            • shutdown
                                                                                                                                                                                                                                                                                            • destroyed
                                                                                                                                                                                                                                                                                            • undefined
                                                                                                                                                                                                                                                                                            Note that there may be some lag for state requests like shutdown since these refer only to VM states. After starting a guest, it may not be immediately accessible.
                                                                                                                                                                                                                                                                                            command no
                                                                                                                                                                                                                                                                                              in addition to state management, various non-idempotent commands are available. See examples
                                                                                                                                                                                                                                                                                              name yes
                                                                                                                                                                                                                                                                                                name of the guest VM being managed

                                                                                                                                                                                                                                                                                                Example from Ansible Playbooks

                                                                                                                                                                                                                                                                                                virt guest=alpha state=running
                                                                                                                                                                                                                                                                                                

                                                                                                                                                                                                                                                                                                Example guest management with /usr/bin/ansible

                                                                                                                                                                                                                                                                                                ansible host -m virt -a "guest=alpha command=status"
                                                                                                                                                                                                                                                                                                


                                                                                                                                                                                                                                                                                                Notes

                                                                                                                                                                                                                                                                                                Other non-idempotent commands are: status, pause, unpause, get_xml, autostart, freemem, list_vms, info, nodeinfo, virttype

                                                                                                                                                                                                                                                                                                vsphere_facts

                                                                                                                                                                                                                                                                                                New in version 0.8.

                                                                                                                                                                                                                                                                                                This module gathers facts for a specific guest on VMWare vSphere. These facts include hardware and network related information useful for provisioning (e.g. macaddress, uuid). This module requires the pysphere python module.

                                                                                                                                                                                                                                                                                                parameter required default choices comments
                                                                                                                                                                                                                                                                                                host yes
                                                                                                                                                                                                                                                                                                  The vSphere server from the cluster the virtual server is located on.
                                                                                                                                                                                                                                                                                                  password yes
                                                                                                                                                                                                                                                                                                    The password to authenticate on the vSphere cluster.
                                                                                                                                                                                                                                                                                                    login yes
                                                                                                                                                                                                                                                                                                      The login name to authenticate on the vSphere cluster.
                                                                                                                                                                                                                                                                                                      guest yes
                                                                                                                                                                                                                                                                                                        The virtual server to gather facts for on the vSphere cluster.

                                                                                                                                                                                                                                                                                                        Task to gather facts from a vSphere cluster only if the system is a VMWare guest

                                                                                                                                                                                                                                                                                                        local_action: vsphere_facts host=$esxserver login=$esxlogin password=$esxpassword guest=$inventory_hostname_short

                                                                                                                                                                                                                                                                                                        only_if: “’$cmdb_hwmodel’.startswith(‘VMWare ‘)

                                                                                                                                                                                                                                                                                                        </pre></p> <p>Typical output of a vsphere_facts run on a guest</p> <p><pre> [{‘hw_name’: ‘centos6’, ‘hw_processor_count’: 1, ‘hw_guest_id’: ‘rhel6_64Guest’, ‘hw_memtotal_mb’: 2048, ‘hw_eth0’: [{‘macaddress’: ‘00:11:22:33:44:55’, ‘label’: ‘Network adapter 1’, ‘addresstype’: ‘assigned’, ‘summary’: ‘VLAN-321’, ‘macaddress_dash’: ‘00-11-22-33-44-55’}], ‘hw_product_uuid’: ‘ef50bac8-2845-40ff-81d9-675315501dac’, ‘hw_guest_full_name’: ‘Red Hat Enterprise Linux 6 (64-bit)’}] </pre></p> <br/>

                                                                                                                                                                                                                                                                                                        Notes

                                                                                                                                                                                                                                                                                                        This module ought to be run from a system that can access vSphere directly. Either by using local_action, or using delegate_to.

                                                                                                                                                                                                                                                                                                        wait_for

                                                                                                                                                                                                                                                                                                        New in version 0.7.

                                                                                                                                                                                                                                                                                                        This is useful for when services are not immediately available after their init scripts return - which is true of certain Java application servers. It is also useful when starting guests with the virt module and needing to pause until they are ready.

                                                                                                                                                                                                                                                                                                        parameter required default choices comments
                                                                                                                                                                                                                                                                                                        delay no
                                                                                                                                                                                                                                                                                                          number of seconds to wait before starting to poll
                                                                                                                                                                                                                                                                                                          host no 127.0.0.1
                                                                                                                                                                                                                                                                                                            hostname or IP address to wait for
                                                                                                                                                                                                                                                                                                            port yes
                                                                                                                                                                                                                                                                                                              port number to poll
                                                                                                                                                                                                                                                                                                              timeout no 300
                                                                                                                                                                                                                                                                                                                maximum number of seconds to wait for
                                                                                                                                                                                                                                                                                                                state no started
                                                                                                                                                                                                                                                                                                                • started
                                                                                                                                                                                                                                                                                                                • stopped
                                                                                                                                                                                                                                                                                                                either started, or stopped depending on whether the module should poll for the port being open or closed.

                                                                                                                                                                                                                                                                                                                Example from Ansible Playbooks

                                                                                                                                                                                                                                                                                                                wait_for port=8000 delay=10
                                                                                                                                                                                                                                                                                                                


                                                                                                                                                                                                                                                                                                                yum

                                                                                                                                                                                                                                                                                                                Will install, upgrade, remove, and list packages with the yum package manager.

                                                                                                                                                                                                                                                                                                                parameter required default choices comments
                                                                                                                                                                                                                                                                                                                state no present
                                                                                                                                                                                                                                                                                                                • present
                                                                                                                                                                                                                                                                                                                • latest
                                                                                                                                                                                                                                                                                                                • absent
                                                                                                                                                                                                                                                                                                                whether to install (present, latest), or remove (absent) a package.
                                                                                                                                                                                                                                                                                                                list no
                                                                                                                                                                                                                                                                                                                  various non-idempotent commands for usage with /usr/bin/ansible and not playbooks. See examples.
                                                                                                                                                                                                                                                                                                                  name yes
                                                                                                                                                                                                                                                                                                                    package name, or package specifier with version, like name-1.0.

                                                                                                                                                                                                                                                                                                                    yum name=httpd state=latest
                                                                                                                                                                                                                                                                                                                    

                                                                                                                                                                                                                                                                                                                    yum name=httpd state=removed
                                                                                                                                                                                                                                                                                                                    

                                                                                                                                                                                                                                                                                                                    yum name=httpd state=installed
                                                                                                                                                                                                                                                                                                                    


                                                                                                                                                                                                                                                                                                                    Additional Contrib Modules

                                                                                                                                                                                                                                                                                                                    In addition to the following built-in modules, community modules are available at Ansible Resources.

                                                                                                                                                                                                                                                                                                                    Writing your own modules

                                                                                                                                                                                                                                                                                                                    See Module Development.

                                                                                                                                                                                                                                                                                                                    See also

                                                                                                                                                                                                                                                                                                                    Ansible Resources (Contrib)
                                                                                                                                                                                                                                                                                                                    User contributed playbooks, modules, and articles
                                                                                                                                                                                                                                                                                                                    Command Line Examples And Next Steps
                                                                                                                                                                                                                                                                                                                    Examples of using modules in /usr/bin/ansible
                                                                                                                                                                                                                                                                                                                    Playbooks
                                                                                                                                                                                                                                                                                                                    Examples of using modules with /usr/bin/ansible-playbook
                                                                                                                                                                                                                                                                                                                    Module Development
                                                                                                                                                                                                                                                                                                                    How to write your own modules
                                                                                                                                                                                                                                                                                                                    API & Integrations
                                                                                                                                                                                                                                                                                                                    Examples of using modules with the Python API
                                                                                                                                                                                                                                                                                                                    Mailing List
                                                                                                                                                                                                                                                                                                                    Questions? Help? Ideas? Stop by the list on Google Groups
                                                                                                                                                                                                                                                                                                                    irc.freenode.net
                                                                                                                                                                                                                                                                                                                    #ansible IRC chat channel