Introduction
The community.general.zypper module manages packages on SUSE Linux Enterprise Server (SLES) and openSUSE using the zypper package manager. It's the SUSE equivalent of ansible.builtin.apt (Debian/Ubuntu) or ansible.builtin.yum (RHEL/CentOS). This article covers installation, removal, updates, repository management, and production patterns.
Module Overview
| Property | Value |
|---|---|
| FQCN | community.general.zypper |
| Collection | community.general |
| OS Support | SLES, openSUSE Leap, openSUSE Tumbleweed |
| Become | Required (become: true) |
Key Parameters
| Parameter | Type | Default | Description |
|---|---|---|---|
name | string/list | — | Package name(s) or pattern |
state | string | present | present, absent, latest, dist-upgrade |
type | string | package | package, patch, pattern, product, srcpackage |
update_cache | bool | false | Refresh repo metadata before operation |
disable_recommends | bool | true | Don't install recommended packages |
force | bool | false | Force package installation |
oldpackage | bool | false | Allow downgrade |
extra_args | string | — | Additional zypper CLI arguments |
Basic Operations
Install a Package
---
- name: Install package on SUSE
hosts: suse_servers
become: true
tasks:
- name: Install nginx
community.general.zypper:
name: nginx
state: present
Install Multiple Packages
- name: Install multiple packages
community.general.zypper:
name:
- nginx
- postgresql15-server
- python3-pip
- git-core
- htop
state: present
Install with Cache Refresh
- name: Update cache and install
community.general.zypper:
name: dos2unix
state: present
update_cache: true
Equivalent to running zypper refresh && zypper install dos2unix.
Install a Specific Version
- name: Install specific version
community.general.zypper:
name: nginx-1.24.0
state: present
Install from a URL
- name: Install RPM from URL
community.general.zypper:
name: https://example.com/packages/myapp-1.0.0.x86_64.rpm
state: present
disable_gpg_check: true
Remove Packages
- name: Remove a package
community.general.zypper:
name: nginx
state: absent
- name: Remove package and dependencies
community.general.zypper:
name: nginx
state: absent
extra_args: '--clean-deps'
Update Operations
Update a Single Package
- name: Update nginx to latest
community.general.zypper:
name: nginx
state: latest
Update All Packages
- name: Update all packages
community.general.zypper:
name: '*'
state: latest
update_cache: true
Distribution Upgrade
- name: Full distribution upgrade
community.general.zypper:
name: '*'
state: dist-upgrade
update_cache: true
Apply Security Patches Only
- name: Apply security patches
community.general.zypper:
name: '*'
type: patch
state: latest
extra_args: '--category security'
Repository Management
Use the community.general.zypper_repository module:
- name: Add a repository
community.general.zypper_repository:
name: nginx-stable
repo: "https://nginx.org/packages/sles/15/"
state: present
auto_import_keys: true
- name: Refresh repositories
community.general.zypper:
name: '*'
update_cache: true
changed_when: false
Add and Use a Repository
---
- name: Configure custom repos and install
hosts: suse_servers
become: true
tasks:
- name: Add EPEL-like repo for SUSE
community.general.zypper_repository:
name: server_monitoring
repo: "https://download.opensuse.org/repositories/server:/monitoring/15.5/"
state: present
auto_import_keys: true
- name: Install monitoring tools
community.general.zypper:
name:
- nagios-plugins
- monitoring-plugins-all
state: present
update_cache: true
Patterns and Best Practices
Pattern: Install Pattern (Meta-Package Group)
# Patterns are like package groups in yum
- name: Install LAMP pattern
community.general.zypper:
name: lamp_server
type: pattern
state: present
Pattern: Conditional by OS
- name: Install web server (cross-platform)
block:
- name: Install on SUSE
community.general.zypper:
name: nginx
state: present
when: ansible_os_family == 'Suse'
- name: Install on Debian
ansible.builtin.apt:
name: nginx
state: present
when: ansible_os_family == 'Debian'
- name: Install on RedHat
ansible.builtin.yum:
name: nginx
state: present
when: ansible_os_family == 'RedHat'
Pattern: Full Server Setup
---
- name: Configure SUSE web server
hosts: suse_web
become: true
vars:
packages:
- nginx
- php8-fpm
- php8-mysql
- mariadb
- certbot
tasks:
- name: Refresh repository cache
community.general.zypper:
name: '*'
update_cache: true
changed_when: false
- name: Install required packages
community.general.zypper:
name: "{{ packages }}"
state: present
- name: Enable and start nginx
ansible.builtin.service:
name: nginx
state: started
enabled: true
- name: Enable and start MariaDB
ansible.builtin.service:
name: mariadb
state: started
enabled: true
Pattern: Rolling Update with Reboot
---
- name: Patch SUSE servers
hosts: suse_servers
serial: 2
become: true
tasks:
- name: Apply all updates
community.general.zypper:
name: '*'
state: latest
update_cache: true
register: update_result
- name: Check if reboot needed
ansible.builtin.stat:
path: /boot/do_purge_kernels
register: reboot_hint
- name: Reboot if required
ansible.builtin.reboot:
reboot_timeout: 300
when: reboot_hint.stat.exists or update_result.changed
- name: Verify services after reboot
ansible.builtin.service_facts:
- name: Ensure nginx is running
ansible.builtin.assert:
that:
- ansible_facts.services['nginx.service'].state == 'running'
Comparison with Other Package Modules
| Feature | zypper (SUSE) | apt (Debian) | yum/dnf (RHEL) |
|---|---|---|---|
| FQCN | community.general.zypper | ansible.builtin.apt | ansible.builtin.yum |
| Refresh cache | update_cache: true | update_cache: true | implicitly on install |
| Install group | type: pattern | N/A (use apt) | name: "@group" |
| Security patches | extra_args: --category security | ansible.builtin.apt with upgrade: dist | security: true |
| Downgrade | oldpackage: true | allow_downgrade: true | allow_downgrade: true |
| Lock version | state: present + zypper locks | dpkg --set-selections | versionlock plugin |
Troubleshooting
Repository Errors
# Error: "No provider of 'package' found"
# Fix: Refresh cache or check repo URL
- name: Force cache refresh
community.general.zypper:
name: '*'
update_cache: true
changed_when: false
GPG Key Issues
# Error: "Package is not signed"
- name: Install with GPG check disabled (use cautiously)
community.general.zypper:
name: custom_package
state: present
disable_gpg_check: true
Lock Conflicts
# Error: "System management is locked"
# Another zypper process is running
- name: Wait for zypper lock to clear
ansible.builtin.shell: |
while fuser /var/run/zypp.pid 2>/dev/null; do
sleep 5
done
changed_when: false
- name: Install package after lock cleared
community.general.zypper:
name: nginx
state: present
Related Articles
Conclusion
The community.general.zypper module is the standard way to manage packages on SUSE and openSUSE systems with Ansible. Use update_cache: true to refresh repos, type: pattern for package groups, and extra_args for security-only patches. For cross-platform playbooks, use conditionals on ansible_os_family == 'Suse' or the generic ansible.builtin.package module.