Resource Behavior
PowerShell Desired State Configuration (DSC) resources are designed to manage system configurations by implementing specific operations that define how they interact with the target system. These operations—Get, Set, Test—and the Ensure parameter (where applicable) work together to ensure the system reaches and maintains the desired state. Understanding their roles is critical for writing effective DSC configurations.
Get Method: Retrieve Current State¶
The Get method retrieves the current state of the resource from the target system. It acts as a diagnostic tool to determine what the system currently looks like. For example, in a custom File resource, the Get method might check whether a file exists at the specified path using internal logic rather than external cmdlets.
Example:
function Get-TargetResource {
$fileExists = Test-Path -Path $Path
return @{
Path = $Path
Ensure = $Ensure
FileExists = $fileExists
}
}
Set Method: Apply Desired State¶
The Set method is responsible for making changes to the target system to align it with the desired state. It performs actions like creating, modifying, or deleting resources based on the resource's logic. For instance, the Set method in a File resource might create a file if it doesn't exist or update its contents, using internal logic rather than external cmdlets.
Example:
function Set-TargetResource {
if ($Ensure -eq 'Present') {
if (-not (Test-Path -Path $Path)) {
New-Item -Path $Path -ItemType File -Force
}
Set-Content -Path $Path -Value $Content
} else {
if (Test-Path -Path $Path) {
Remove-Item -Path $Path -Force
}
}
}
Ensure parameter.
Test Method: Validate Desired State¶
The Test method determines whether the current state of the resource matches the desired state. It returns a boolean value ($true or $false) to indicate compliance. This method is essential for determining if the resource is already in the correct state, avoiding unnecessary changes.
Example:
function Test-TargetResource {
$fileExists = Test-Path -Path $Path
return $fileExists -eq ($Ensure -eq 'Present')
}
Ensure parameter to validate compliance.
Ensure Parameter: Control Presence/Absence¶
The Ensure parameter (common in resources like File, Registry, and Service) specifies whether the resource should ensure the presence (Present) or absence (Absent) of a state. It acts as a flag that guides the Set and Test methods.
Example:
Ensure is set to Present, the Set method ensures the file exists; if Absent, it ensures the file is deleted. The Test method uses this parameter to validate whether the current state matches the desired state.
Key takeaways¶
- Get retrieves the current state of the resource using internal logic.
- Set applies changes to achieve the desired state based on the resource's logic.
- Test validates whether the current state matches the desired state, using the
Ensureparameter. - Ensure (where applicable) dictates whether the resource should exist or not, influencing how
SetandTestoperate. - These operations work in concert to ensure the system remains in compliance with the configuration.