Skip to main content
The AWX CLI supports multiple configuration methods including command-line flags, environment variables, and configuration files. This guide covers all available configuration options.

Authentication

The AWX CLI requires authentication to interact with AWX or Ansible Automation Platform instances. There are several methods to provide credentials.

Command-Line Authentication

Provide credentials directly with each command:

Environment Variables

Set environment variables for persistent authentication:
For backward compatibility, TOWER_HOST, TOWER_USERNAME, and TOWER_PASSWORD are also supported but deprecated.

Credential Files

The CLI can load credentials from a configuration file. Create a credentials file:
Then reference it:

Authentication Methods

Session-Based Authentication (Default)

By default, the CLI uses session-based authentication, which is more efficient for multiple commands:
Sessions are stored in ~/.awx/sessions/ and automatically managed.

Basic Authentication

For environments like AAP Gateway where session login is restricted, force Basic authentication:
Basic authentication requires credentials on every request. Ensure both username and password are provided when AWXKIT_FORCE_BASIC_AUTH is enabled.

Connection Settings

Host Configuration

Specify the AWX/AAP host URL:
Default: https://127.0.0.1:443

SSL Certificate Verification

By default, SSL certificates are verified. For self-signed certificates or testing:
Disabling SSL verification exposes you to man-in-the-middle attacks. Only use this in trusted development environments.

API Base Path

For Red Hat Ansible Automation Platform 2.5+, set the API base path:
For AWX instances:
Default: /api/

Output Formatting

Format Options

The CLI supports multiple output formats: JSON (default)
YAML
Human-readable table
JQ filtering (requires jq extra)

Filter Output

Use the --filter flag to select specific fields:

Color Output

Control colored output:

Verbose Output

Enable debug logging to see HTTP requests:

Configuration Priority

When multiple configuration sources are present, they are evaluated in this order (highest to lowest priority):
  1. Command-line flags (--conf.*)
  2. Environment variables (CONTROLLER_*)
  3. Credential files (AWXKIT_CREDENTIAL_FILE)
  4. Default values

Complete Configuration Example

Create a comprehensive shell configuration:
Source it in your shell profile:

Verify Configuration

To verify your current configuration:
This displays:
  • Base URL
  • Session authentication status
  • Current credentials (username only, not password)

Environment Variable Reference

Command-Line Flag Reference

Troubleshooting

Connection Errors

Error: Connection refused
Error: SSL verification failed

Authentication Errors

Error: Unauthorized (401)
Error: Basic authentication required

AAP 2.5+ Path Issues

Error: Unable to fetch /api/v2/

Security Best Practices

  1. Never commit credentials to version control
  2. Use environment variables instead of command-line flags in scripts (flags may appear in process lists)
  3. Restrict credential file permissions: chmod 600 ~/.awx/credentials.yml
  4. Use separate credentials for automation vs. interactive use
  5. Enable SSL verification in production environments
  6. Rotate passwords regularly
  7. Use RBAC to limit CLI user permissions to only what’s needed