Ansible · Cheat sheet

Ansible cheat sheet

Ansible cheat sheet: inventory, ad-hoc modules, playbooks, Vault, roles, Galaxy, and debugging with examples.

63 commands·9 sections·Updated ·By SecOpsLog

Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.

Inventory & connectivity

Beginner
ansible --version
Core version and config file in use.
ansible all -m ping -i hosts
Check SSH + Python on every host.Example output
web1 | SUCCESS => {
  "changed": false,
  "ping": "pong"
}
ansible-inventory -i hosts --list
Dump the parsed inventory as JSON.
ansible-inventory --graph
Tree view of groups and hosts.Example output
@all:
  |--@web:
  |  |--web1
  |  |--web2
  |--@db:
  |  |--db1
ansible web -m ping --limit web1
Target one host in a group.
ansible all --list-hosts
Show which hosts a pattern matches.

Ad-hoc commands

Beginner
ansible all -a "uptime"
Run a shell command everywhere (command module).
ansible all -m shell -a "df -h | grep /$"
Use shell when you need pipes/redirects.
ansible all -m copy -a "src=a.conf dest=/etc/a.conf"Caution
Push a file.Caution: Overwrites the file on every matched host; scope with --limit and --check.
ansible all -m apt -a "name=nginx state=present" -bCaution
Install a package as root (-b = become).Caution: Changes packages on every matched host at once; scope with --limit.
ansible all -m service -a "name=nginx state=restarted" -bCaution
Restart a service.Caution: Restarts nginx on every matched host at once; scope with --limit.
ansible all -m setup
Gather and print all facts about a host.
ansible all -m setup -a "filter=ansible_mem*"
Show only matching facts.

Running playbooks

Beginner
ansible-playbook site.yml
Run a playbook against its inventory.Example output
PLAY RECAP ***
web1 : ok=7  changed=2  unreachable=0  failed=0
ansible-playbook site.yml --check
Dry run: predict changes (check_mode: false tasks still run).
ansible-playbook site.yml --diffExposes secrets
Show before/after for changed files.Exposes secrets: Diffs can print secrets from templated files; set diff: false there.
ansible-playbook site.yml --check --diffExposes secrets
Safest preview: no changes + full diff.Exposes secrets: Diffs can print secrets from templated files; set diff: false there.
ansible-playbook site.yml --syntax-check
Validate YAML/structure without running.
ansible-playbook site.yml --list-tasks
Show the tasks that would run.

Controlling a run

Intermediate
ansible-playbook site.yml --limit web
Restrict the run to a host/group.
ansible-playbook site.yml --tags deploy
Run only tasks with these tags.
ansible-playbook site.yml --skip-tags slow
Run everything except these tags.
ansible-playbook site.yml --start-at-task="Copy config"
Resume from a named task.
ansible-playbook site.yml --step
Confirm each task interactively.
ansible-playbook site.yml -e "ver=1.4.0"
Pass extra variables (highest precedence).
ansible-playbook site.yml -f 20
Run on 20 hosts at once (forks).
ansible-playbook site.yml -b -K
Become root and prompt for the sudo password.

Variables & facts

Intermediate
ansible-playbook s.yml -e @vars.yml
Load extra vars from a file.
group_vars/web.yml
Variables automatically applied to the web group.
host_vars/web1.yml
Variables scoped to a single host.
{{ ansible_facts.default_ipv4.address }}
Use a gathered fact in a template/task.
gather_facts: false
Skip fact gathering to speed up a play.
register: result
Capture a task’s output into a variable.
when: result.rc != 0
Run a task conditionally on prior output.

Ansible Vault

Intermediate
ansible-vault create secrets.yml
Create a new encrypted file.
ansible-vault edit secrets.yml
Decrypt to $EDITOR, re-encrypt on save.
ansible-vault view secrets.ymlExposes secrets
Print decrypted contents without editing.Exposes secrets: Prints decrypted vault contents to the terminal.
ansible-vault encrypt vars.yml
Encrypt an existing plaintext file.
ansible-vault rekey secrets.yml
Change the vault password.
ansible-vault encrypt_string "s3cr3t" --name db_passExposes secrets
Encrypt one value to paste inline.Exposes secrets: Plaintext lands in shell history; use --prompt or --stdin-name.
ansible-playbook s.yml --ask-vault-pass
Prompt for the vault password at run time.
ansible-playbook s.yml --vault-password-file .vpass
Read the password from a file (CI).
ansible-playbook s.yml --vault-id prod@prompt
Label vault secrets per environment and prompt for that ID's password.

Roles & Galaxy

Intermediate
ansible-galaxy init myrole
Scaffold a role (tasks/, handlers/, templates/…).Example output
- Role myrole was created successfully
ansible-galaxy install geerlingguy.nginx
Install a role from Galaxy.
ansible-galaxy install -r requirements.yml
Install all pinned roles/collections.
ansible-galaxy collection install community.docker
Install a collection.
ansible-galaxy role list
List installed roles and versions.

Templating & handlers

Advanced
{{ var | default("x") }}
Jinja2 filter — fall back when unset.
{{ items | length }}
Filters: length, upper, join, to_json, b64encode…
{% for h in groups["web"] %}...{% endfor %}
Loop in a template (e.g. build a config).
notify: Restart nginx
Trigger a handler when a task changes something.
loop: "{{ users }}"
Iterate a task over a list.
block: / rescue: / always:
Group tasks with error handling (try/catch/finally).
delegate_to: localhost
Run a task on a different host than the target.

Debug & performance

Advanced
ansible-playbook s.yml -vvv
Verbose (add v’s up to -vvvv for connection debug).
- debug: var=result
Print a variable mid-play.
- debug: msg="ip is {{ ip }}"
Print a formatted message.
ANSIBLE_STRATEGY=free ansible-playbook s.yml
Let hosts run ahead independently.
ansible-lint site.yml
Lint for anti-patterns and deprecations.
ansible-doc ansible.builtin.copy
Module docs and examples offline (-l lists, -s prints a snippet).
ANSIBLE_CALLBACK_RESULT_FORMAT=yaml ansible-playbook s.yml
YAML task results via the default callback (core 2.13+).
ansible-config dump --only-changed
Only the settings that differ from defaults: the first check when a run behaves oddly.

Primary references

Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.

Go deeper
Hands-on courses for Ansible