Ansible · Cheat sheet
Ansible cheat sheet
Ansible cheat sheet: inventory, ad-hoc modules, playbooks, Vault, roles, Galaxy, and debugging with examples.
Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.
Inventory & connectivity
Beginneransible --version- Core version and config file in use.
ansible all -m ping -i hosts- Check SSH + Python on every host.Example output
web1 | SUCCESS => { "changed": false, "ping": "pong" } ansible-inventory -i hosts --list- Dump the parsed inventory as JSON.
ansible-inventory --graph- Tree view of groups and hosts.Example output
@all: |--@web: | |--web1 | |--web2 |--@db: | |--db1
ansible web -m ping --limit web1- Target one host in a group.
ansible all --list-hosts- Show which hosts a pattern matches.
Ad-hoc commands
Beginneransible all -a "uptime"- Run a shell command everywhere (command module).
ansible all -m shell -a "df -h | grep /$"- Use shell when you need pipes/redirects.
ansible all -m copy -a "src=a.conf dest=/etc/a.conf"Caution- Push a file.Caution: Overwrites the file on every matched host; scope with --limit and --check.
ansible all -m apt -a "name=nginx state=present" -bCaution- Install a package as root (-b = become).Caution: Changes packages on every matched host at once; scope with --limit.
ansible all -m service -a "name=nginx state=restarted" -bCaution- Restart a service.Caution: Restarts nginx on every matched host at once; scope with --limit.
ansible all -m setup- Gather and print all facts about a host.
ansible all -m setup -a "filter=ansible_mem*"- Show only matching facts.
Running playbooks
Beginneransible-playbook site.yml- Run a playbook against its inventory.Example output
PLAY RECAP *** web1 : ok=7 changed=2 unreachable=0 failed=0
ansible-playbook site.yml --check- Dry run: predict changes (check_mode: false tasks still run).
ansible-playbook site.yml --diffExposes secrets- Show before/after for changed files.Exposes secrets: Diffs can print secrets from templated files; set diff: false there.
ansible-playbook site.yml --check --diffExposes secrets- Safest preview: no changes + full diff.Exposes secrets: Diffs can print secrets from templated files; set diff: false there.
ansible-playbook site.yml --syntax-check- Validate YAML/structure without running.
ansible-playbook site.yml --list-tasks- Show the tasks that would run.
Controlling a run
Intermediateansible-playbook site.yml --limit web- Restrict the run to a host/group.
ansible-playbook site.yml --tags deploy- Run only tasks with these tags.
ansible-playbook site.yml --skip-tags slow- Run everything except these tags.
ansible-playbook site.yml --start-at-task="Copy config"- Resume from a named task.
ansible-playbook site.yml --step- Confirm each task interactively.
ansible-playbook site.yml -e "ver=1.4.0"- Pass extra variables (highest precedence).
ansible-playbook site.yml -f 20- Run on 20 hosts at once (forks).
ansible-playbook site.yml -b -K- Become root and prompt for the sudo password.
Variables & facts
Intermediateansible-playbook s.yml -e @vars.yml- Load extra vars from a file.
group_vars/web.yml- Variables automatically applied to the web group.
host_vars/web1.yml- Variables scoped to a single host.
{{ ansible_facts.default_ipv4.address }}- Use a gathered fact in a template/task.
gather_facts: false- Skip fact gathering to speed up a play.
register: result- Capture a task’s output into a variable.
when: result.rc != 0- Run a task conditionally on prior output.
Ansible Vault
Intermediateansible-vault create secrets.yml- Create a new encrypted file.
ansible-vault edit secrets.yml- Decrypt to $EDITOR, re-encrypt on save.
ansible-vault view secrets.ymlExposes secrets- Print decrypted contents without editing.Exposes secrets: Prints decrypted vault contents to the terminal.
ansible-vault encrypt vars.yml- Encrypt an existing plaintext file.
ansible-vault rekey secrets.yml- Change the vault password.
ansible-vault encrypt_string "s3cr3t" --name db_passExposes secrets- Encrypt one value to paste inline.Exposes secrets: Plaintext lands in shell history; use --prompt or --stdin-name.
ansible-playbook s.yml --ask-vault-pass- Prompt for the vault password at run time.
ansible-playbook s.yml --vault-password-file .vpass- Read the password from a file (CI).
ansible-playbook s.yml --vault-id prod@prompt- Label vault secrets per environment and prompt for that ID's password.
Roles & Galaxy
Intermediateansible-galaxy init myrole- Scaffold a role (tasks/, handlers/, templates/…).Example output
- Role myrole was created successfully
ansible-galaxy install geerlingguy.nginx- Install a role from Galaxy.
ansible-galaxy install -r requirements.yml- Install all pinned roles/collections.
ansible-galaxy collection install community.docker- Install a collection.
ansible-galaxy role list- List installed roles and versions.
Templating & handlers
Advanced{{ var | default("x") }}- Jinja2 filter — fall back when unset.
{{ items | length }}- Filters: length, upper, join, to_json, b64encode…
{% for h in groups["web"] %}...{% endfor %}- Loop in a template (e.g. build a config).
notify: Restart nginx- Trigger a handler when a task changes something.
loop: "{{ users }}"- Iterate a task over a list.
block: / rescue: / always:- Group tasks with error handling (try/catch/finally).
delegate_to: localhost- Run a task on a different host than the target.
Debug & performance
Advancedansible-playbook s.yml -vvv- Verbose (add v’s up to -vvvv for connection debug).
- debug: var=result- Print a variable mid-play.
- debug: msg="ip is {{ ip }}"- Print a formatted message.
ANSIBLE_STRATEGY=free ansible-playbook s.yml- Let hosts run ahead independently.
ansible-lint site.yml- Lint for anti-patterns and deprecations.
ansible-doc ansible.builtin.copy- Module docs and examples offline (-l lists, -s prints a snippet).
ANSIBLE_CALLBACK_RESULT_FORMAT=yaml ansible-playbook s.yml- YAML task results via the default callback (core 2.13+).
ansible-config dump --only-changed- Only the settings that differ from defaults: the first check when a run behaves oddly.
Related
Primary references
Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.
Go deeper
Hands-on courses for Ansible