Build and run an ansible-playbook command by answering a few questions:
- Inventory: picks up your
ansible.cfg/ANSIBLE_INVENTORYdefault, INI and YAML inventory files, inventory plugin configs, andinventory/orinventories/*directories. - Hosts: choose groups or single hosts for
--limit, or none to run on all hosts. - Playbook: any YAML file in the current directory or
./playbooksthat contains plays. - Tags: every tag the playbook uses (plays, roles, blocks, imports), or none to run all tags.
- Mode: check mode (
--check --diff) or live mode (--diff).
Live runs wait a few seconds so you can back out. Each command is saved to .ansible-interactive-history, so next time you can re-run it in check or live mode.
- An Apple Silicon Mac or Linux (on Windows, use WSL: Ansible can't run on Windows directly). Intel Macs can use the npm install.
- Ansible (
ansible-core2.12 or newer) on yourPATH. The tool usesansible-inventory,ansible-configandansible-playbook --list-tagsto read your project, so it sees what Ansible sees.
curl -fsSL https://github.com/glhd/ansible-interactive/releases/latest/download/install.sh | shThis downloads the single-file binary for your platform, checks it against the release's SHA256SUMS.txt, and puts it in ~/.local/bin (or /usr/local/bin as root). It doesn't need Node.js. Options:
# A specific version
curl -fsSL https://github.com/glhd/ansible-interactive/releases/latest/download/install.sh | sh -s 1.2.0
# Somewhere else
curl -fsSL https://github.com/glhd/ansible-interactive/releases/latest/download/install.sh | INSTALL_DIR=/opt/bin shYou can also download a binary from the releases page. Builds exist for Apple Silicon Macs and Linux (x64 and arm64, glibc and musl). The macOS binary is signed and notarized by Apple. On an Intel Mac, install with npm instead.
To install with npm instead (needs Node.js 22 or newer):
npm install --global github:glhd/ansible-interactiveOnce a day, ansible-interactive asks GitHub whether a new release is out. If one is, it says so after your run finishes. The check never delays or blocks a run.
ansible-interactive update # install the latest release
ansible-interactive update 1.2.0 # install a specific version| Variable | Effect |
|---|---|
ANSIBLE_INTERACTIVE_AUTO_UPDATE=1 |
Install new releases after each run, without asking |
ANSIBLE_INTERACTIVE_DISABLE_UPDATE_CHECK=1 |
Never check for updates (also off when CI is set) |
Updates check the download against SHA256SUMS.txt before replacing the binary. npm installs can't update themselves; the notice tells you the npm command instead.
Run it from your Ansible project:
ansible-interactive| Option | Description |
|---|---|
-i, --inventory <path> |
Inventory source to use (repeatable) |
-p, --playbook <path> |
Playbook to run |
--no-history |
Don't read or write .ansible-interactive-history |
--delay <seconds> |
Pause before a live run starts (default: 3) |
-v, --verbose |
Show stack traces on errors |
Anything after -- goes to ansible-playbook as-is:
ansible-interactive -- --ask-become-pass -e env=staging| Key | Action |
|---|---|
↑ ↓ |
Move |
space |
Select (in lists that allow several) |
ctrl+a |
Select all shown |
| any text | Filter the list |
enter |
Confirm |
esc |
Clear the filter, or go back a step |
ctrl+c |
Quit |
npm install
npm run dev # run from source
npm test
npm run build # compile to dist/
npm run build:binaries # standalone binaries in build/ (needs Bun)Publish a release on GitHub with a new tag such as v1.2.0, or v1.2.0-beta.1 for a pre-release. Pushing the tag yourself works too:
git tag v1.2.0 && git push origin v1.2.0The tag starts the release workflow. It builds with the tag's version, so you don't need to change package.json first. It runs the tests, builds the binaries with bun build --compile, signs and notarizes the macOS binary, and adds the binaries, SHA256SUMS.txt and install.sh to the release (creating it if you only pushed a tag). Finally it sets package.json on the default branch to the new version, unless that's already newer.
Tags with a hyphen become pre-releases, which the installer and update check skip. To rebuild an existing tag, run the workflow by hand from the Actions tab and enter the tag.
Signing the macOS binary needs these repository secrets:
| Secret | Contents |
|---|---|
MACOS_CERTIFICATE_P12 |
Developer ID Application certificate as a base64-encoded .p12 |
MACOS_CERTIFICATE_PASSWORD |
Password for the .p12 |
KEYCHAIN_PASSWORD |
Any password, for the temporary keychain on the runner |
ASC_KEY_ID |
App Store Connect API key ID, for notarization |
ASC_ISSUER_ID |
App Store Connect API issuer ID |
ASC_PRIVATE_KEY |
Contents of the App Store Connect API .p8 key |
The release fails early if any of them is missing.