Manage domain/workgroup membership for a Windows host
- Manages domain membership or workgroup membership for a Windows host. Also supports hostname changes.
- This module may require subsequent use of the :ref:`ansible.windows.win_reboot <ansible.windows.win_reboot_module>` action if changes are made.
.. seealso:: :ref:`ansible.windows.win_domain_module` The official documentation on the **ansible.windows.win_domain** module. :ref:`ansible.windows.win_domain_controller_module` The official documentation on the **ansible.windows.win_domain_controller** module. :ref:`community.windows.win_domain_computer_module` The official documentation on the **community.windows.win_domain_computer** module. :ref:`community.windows.win_domain_group_module` The official documentation on the **community.windows.win_domain_group** module. :ref:`community.windows.win_domain_user_module` The official documentation on the **community.windows.win_domain_user** module. :ref:`ansible.windows.win_group_module` The official documentation on the **ansible.windows.win_group** module. :ref:`ansible.windows.win_group_membership_module` The official documentation on the **ansible.windows.win_group_membership** module. :ref:`ansible.windows.win_user_module` The official documentation on the **ansible.windows.win_user** module.
# host should be a member of domain ansible.vagrant; module will ensure the hostname is mydomainclient
# and will use the passed credentials to join domain if necessary.
# Ansible connection should use local credentials if possible.
# If a reboot is required, the second task will trigger one and wait until the host is available.
- hosts: winclient
gather_facts: no
tasks:
- ansible.windows.win_domain_membership:
dns_domain_name: ansible.vagrant
hostname: mydomainclient
domain_admin_user: [email protected]
domain_admin_password: password123!
domain_ou_path: "OU=Windows,OU=Servers,DC=ansible,DC=vagrant"
state: domain
register: domain_state
- ansible.windows.win_reboot:
when: domain_state.reboot_required
# Host should be in workgroup mywg- module will use the passed credentials to clean-unjoin domain if possible.
# Ansible connection should use local credentials if possible.
# The domain admin credentials can be sourced from a vault-encrypted variable
- hosts: winclient
gather_facts: no
tasks:
- ansible.windows.win_domain_membership:
workgroup_name: mywg
domain_admin_user: '{{ win_domain_admin_user }}'
domain_admin_password: '{{ win_domain_admin_password }}'
state: workgroup
Common return values are documented here, the following are the fields unique to this module:
Key | Returned | Description |
---|---|---|
reboot_required
boolean
|
always |
True if changes were made that require a reboot.
Sample:
True
|
- Matt Davis (@nitzmahone)