community.general.write_binary_file module – Write binary file from Base64 encoded input
Note
This module is part of the community.general collection (version 13.3.0).
You might already have this collection installed if you are using the ansible package.
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install community.general.
To use it in a playbook, specify: community.general.write_binary_file.
New in community.general 13.3.0
Synopsis
Given Base64 encoded content, write it to a file.
This is useful when Base64-encoded binary content (that is not valid UTF-8) is retrieved from a credentials store (or similar sources) and needs to be written to a file. The ansible.builtin.copy module with its
contentparameter can only be used to write content that is valid UTF-8 encoded text.
Parameters
Parameter |
Comments |
|---|---|
The attributes the resulting filesystem object should have. To get supported flags look at the man page for This string should contain the attributes in the same order as the one displayed by The |
|
Create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly. Choices:
|
|
The Base64 encoded content. |
|
Influence whether the remote file must always be replaced. If If Choices:
|
|
Name of the group that should own the filesystem object, as would be fed to When left unspecified, it uses the current group of the current user unless you are root, in which case it can preserve the previous ownership. Specifying a numeric group name (for example, “1000”) will be assumed to be a group ID (GID) and not a group name. To prevent confusion, avoid using purely numeric group names. |
|
The permissions the resulting filesystem object should have. For those used to Giving Ansible a number without following either of these rules will end up with a decimal number which will have unexpected results. As of Ansible 1.8, the mode may be specified as a symbolic mode (for example, If If Specifying |
|
Name of the user that should own the filesystem object, as would be fed to When left unspecified, it uses the current user unless you are root, in which case it can preserve the previous ownership. Specifying a numeric username (for example, “1000”) will be assumed to be a user ID (UID) and not a username. To prevent confusion, avoid using purely numeric usernames. |
|
The file to write to. |
|
The level part of the SELinux filesystem object context. This is the MLS/MCS attribute, sometimes known as the When set to |
|
The role part of the SELinux filesystem object context. When set to |
|
The type part of the SELinux filesystem object context. When set to |
|
The user part of the SELinux filesystem object context. By default it uses the When set to |
|
Influence when to use atomic operation to prevent data corruption or inconsistent reads from the target filesystem object. By default this module uses atomic operations to prevent data corruption or inconsistent reads from the target filesystem objects, but sometimes systems are configured or just broken in ways that prevent this. One example is docker mounted filesystem objects, which cannot be updated atomically from inside the container and can only be written in an unsafe manner. This option allows Ansible to fall back to unsafe methods of updating filesystem objects when atomic operations fail (however, it doesn’t force Ansible to perform unsafe writes). IMPORTANT! Unsafe writes are subject to race conditions and can lead to data corruption. Choices:
|
Attributes
Attribute |
Support |
Description |
|---|---|---|
Support: full |
Can run in |
|
Support: none |
Returns details on what has changed (or possibly needs changing in |
See Also
See also
- community.general.binary_file lookup plugin
Read binary file and return it Base64 encoded.
- ansible.builtin.copy
Copy files to remote locations.
Examples
- name: Write binary file
community.general.write_binary_file:
path: /foo
content: "{{ lookup('community.general.binary_file', '/bar') }}"
mode: "0600"
owner: root
group: root
become: true
- name: Write binary decrypted from SOPS
community.general.write_binary_file:
path: /etc/encrypted.bin
content: "{{ lookup('community.sops.sops', 'encrypted.sops.bin', base64=true, rstrip=false) }}"
mode: "0600"
owner: root
group: root
become: true
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
Name of backup file created. Returned: changed and if Sample: |