The ansible.builtin.get_url Module

The get_url module downloads files from HTTP, HTTPS, and FTP URLs to remote hosts — like wget or curl, but idempotent and integrated with Ansible.

Basic Download

- name: Download a file
  ansible.builtin.get_url:
    url: https://example.com/app-v2.1.0.tar.gz
    dest: /tmp/app-v2.1.0.tar.gz

Download with Checksum Verification

- name: Download with SHA256 checksum
  ansible.builtin.get_url:
    url: https://example.com/app-v2.1.0.tar.gz
    dest: /tmp/app-v2.1.0.tar.gz
    checksum: sha256:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

- name: Download with checksum from URL
  ansible.builtin.get_url:
    url: https://example.com/app-v2.1.0.tar.gz
    dest: /tmp/app-v2.1.0.tar.gz
    checksum: "sha256:https://example.com/app-v2.1.0.tar.gz.sha256"

Set Permissions

- name: Download and make executable
  ansible.builtin.get_url:
    url: https://example.com/scripts/setup.sh
    dest: /opt/scripts/setup.sh
    mode: '0755'
    owner: deploy
    group: deploy

Download with Authentication

Basic Auth

- name: Download from authenticated endpoint
  ansible.builtin.get_url:
    url: https://artifacts.example.com/releases/app.tar.gz
    dest: /tmp/app.tar.gz
    url_username: "{{ artifact_user }}"
    url_password: "{{ vault_artifact_password }}"
    force_basic_auth: true
  no_log: true

Bearer Token

- name: Download with bearer token
  ansible.builtin.get_url:
    url: https://api.github.com/repos/myorg/myapp/tarball/v2.0
    dest: /tmp/myapp.tar.gz
    headers:
      Authorization: "Bearer {{ vault_github_token }}"
  no_log: true

Proxy Support

- name: Download through proxy
  ansible.builtin.get_url:
    url: https://example.com/package.tar.gz
    dest: /tmp/package.tar.gz
  environment:
    http_proxy: "http://proxy.example.com:3128"
    https_proxy: "http://proxy.example.com:3128"

Conditional Download

- name: Only download if not present
  ansible.builtin.get_url:
    url: https://example.com/large-dataset.tar.gz
    dest: /opt/data/dataset.tar.gz
    force: false  # Default — skip if file exists

- name: Always re-download (force)
  ansible.builtin.get_url:
    url: https://example.com/config.json
    dest: /opt/app/config.json
    force: true  # Download even if file exists

Practical Examples

Install Binary from GitHub Release

- name: Download kubectl
  ansible.builtin.get_url:
    url: "https://dl.k8s.io/release/v1.30.0/bin/linux/amd64/kubectl"
    dest: /usr/local/bin/kubectl
    mode: '0755'
    checksum: "sha256:https://dl.k8s.io/release/v1.30.0/bin/linux/amd64/kubectl.sha256"
  become: true

Download and Extract

- name: Download archive
  ansible.builtin.get_url:
    url: https://example.com/app-v2.tar.gz
    dest: /tmp/app-v2.tar.gz
    checksum: sha256:abc123...

- name: Extract archive
  ansible.builtin.unarchive:
    src: /tmp/app-v2.tar.gz
    dest: /opt/app/
    remote_src: true

Download Multiple Files

- name: Download dependencies
  ansible.builtin.get_url:
    url: "{{ item.url }}"
    dest: "{{ item.dest }}"
    checksum: "{{ item.checksum }}"
  loop:
    - url: https://example.com/lib1.jar
      dest: /opt/app/lib/lib1.jar
      checksum: sha256:abc123
    - url: https://example.com/lib2.jar
      dest: /opt/app/lib/lib2.jar
      checksum: sha256:def456

Download with Timeout and Retries

- name: Download large file with retries
  ansible.builtin.get_url:
    url: https://example.com/large-file.iso
    dest: /tmp/large-file.iso
    timeout: 300
  retries: 3
  delay: 10
  register: download_result
  until: download_result is success

Windows: win_get_url

For Windows hosts, use ansible.windows.win_get_url:

- name: Download on Windows
  ansible.windows.win_get_url:
    url: https://example.com/installer.msi
    dest: C:\Temp\installer.msi
    checksum: abc123
    checksum_algorithm: sha256

Parameters

ParameterDescriptionExample
urlSource URLhttps://example.com/file
destDestination path/tmp/file
checksumVerify integritysha256:abc123...
modeFile permissions'0755'
ownerFile ownerdeploy
groupFile groupdeploy
forceRe-download if existstrue
timeoutDownload timeout (sec)300
headersCustom HTTP headers{Authorization: "Bearer ..."}
url_usernameBasic auth usernameadmin
url_passwordBasic auth passwordsecret
validate_certsVerify SSLtrue

Browse 800+ Ansible tutorials on AnsibleByExample.