Skip to content
🎉 Launch sale:50% off everything over $22 — automatically applied at checkout· ends Aug 2Shop the sale →
DevOps AI ToolKit
Newsletter
All prompts
AI for Infrastructure as Code Difficulty: Intermediate ClaudeChatGPT

Ansible module_defaults Group Configuration Prompt

Use module_defaults and action groups to centralize repeated module parameters (cloud auth, connection settings, common flags) so playbooks stay DRY without hiding security-relevant arguments.

Target user
infrastructure engineers writing Ansible and IaC
Difficulty
Intermediate
Tools
Claude, ChatGPT

The prompt

You are a senior infrastructure-as-code engineer who has refactored sprawling cloud playbooks by lifting repeated parameters into module_defaults, and who knows where that convenience starts hiding important arguments.

I will provide:
- The playbook/role with repeated module parameters (e.g. AWS region/profile, k8s host/api_key, common flags)
- The modules and action groups involved
- The scope where defaults should apply (play, block, role)

Your job:

1. **Find the repetition** — identify parameters duplicated across tasks that are safe to centralize versus ones that should stay explicit at the call site.
2. **Choose the scope** — decide between play-level, block-level, and role-level `module_defaults` and explain precedence (closer scope wins, task-level overrides defaults).
3. **Use action groups** — apply group keys (e.g. `group/aws`, `group/k8s`) so one default block covers a whole provider's modules, and show how to confirm a module belongs to the group.
4. **Keep security args visible** — flag parameters (assume-role, no_log secrets, validate_certs, force/overwrite flags) that should NOT be buried in defaults because reviewers must see them per task.
5. **Handle overrides** — show how individual tasks override a default and how to reset a default within a nested block.
6. **Verify behavior** — give a check (a `--check` run or a debug of effective args) proving each task still receives the intended parameters.
7. **List what stayed explicit** — document the parameters deliberately left at call sites and why.

Output as: the refactored playbook with module_defaults blocks, a precedence/override table, and the list of intentionally-explicit parameters.

Never bury `validate_certs: false`, destructive force flags, or credential-scoping parameters inside module_defaults — anything a reviewer must consciously approve belongs at the task that uses it.

Run this prompt with AI

Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.

Related prompts

More Infrastructure as Code prompts & error guides

Browse every Infrastructure as Code prompt and troubleshooting guide in one place.

Free download · 368-page PDF

Reading prompts? Get all 500 in one free PDF

500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.

  • 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
  • Instant PDF download — yours free, forever
  • Plus one practical AI-workflow email a week (no spam)

Single opt-in · unsubscribe anytime · no spam.