惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
L
LangChain Blog
I
InfoQ
D
Docker
F
Fortinet All Blogs
Y
Y Combinator Blog
Martin Fowler
Martin Fowler
月光博客
月光博客
B
Blog
Engineering at Meta
Engineering at Meta
T
Tailwind CSS Blog
罗磊的独立博客
博客园_首页
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
IT之家
IT之家
V
V2EX

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Build and deploy the latest open-vm-tools from source wit...
giulio Savin · 2026-05-02 · via DEV Community

giulio Savini

Build and deploy the latest open-vm-tools from source with Ansible and Docker

If you run Linux VMs on VMware, you've probably hit this: your distro ships an open-vm-tools version that's 1-2 years behind upstream. That matters when you need guest OS compatibility fixes for newer ESXi, VMCI socket support, or CVE patches your distro hasn't backported yet.

I built an Ansible role that solves this: vmware-tools-builder — it compiles the latest open-vm-tools inside isolated Docker containers, produces clean .deb/.rpm packages, and deploys them across your entire fleet.


Why not just use the distro package?

Distro package This role
Version Months/years behind Always latest upstream
VMCI socket support Often missing Compiled in
CVE patches Depends on distro backport Upstream fix on release
Multi-distro One at a time Ubuntu, Debian, RHEL, Rocky, Fedora

How it works

The build runs inside Docker containers — one per distro — so your Ansible controller stays clean. No build dependencies polluting your system.

cd containers

# Build for all supported distros
./build-all.sh

# Single distro
./build-all.sh --target rocky9

# Pin a specific upstream version
./build-all.sh --version 12.5.0

Enter fullscreen mode Exit fullscreen mode

Output: .deb and .rpm packages in output/, automatically copied to files/ where Ansible picks them up.


Deploy with Ansible

Install from Galaxy:

ansible-galaxy install giuliosavini.vmware_tools_builder

Enter fullscreen mode Exit fullscreen mode

Write your inventory:

[debian]
srv-web01  ansible_host=10.0.0.1
srv-web02  ansible_host=10.0.0.2

[rhel]
srv-app01  ansible_host=10.0.0.10

[all:vars]
ansible_user=root

Enter fullscreen mode Exit fullscreen mode

Run the playbook:

ansible-playbook -i inventory.ini playbook.yml

Enter fullscreen mode Exit fullscreen mode


Smart deployment logic

The role handles three scenarios automatically — no conditional vars needed:

Current state Action
No open-vm-tools installed Fresh install
Distro open-vm-tools present Remove it, install custom build
Previous custom build present In-place upgrade

For each host the role runs: preflight → deploy → post-install → diagnose → verify. If vmtoolsd fails to start, it collects logs and attempts automatic recovery before reporting failure.


Supported platforms

Distro Build Deploy
Ubuntu 22.04+ Docker container Ansible (apt)
Debian 12+ Docker container Ansible (apt)
RHEL / Rocky / Alma 9 Docker container Ansible (yum)
RHEL / Rocky / Alma 8 Docker container Ansible (yum)
Fedora Docker container Ansible (yum)
SUSE / openSUSE Ansible (zypper)

Example playbook

- name: Deploy custom open-vm-tools
  hosts: all
  become: true
  gather_facts: true
  roles:
    - role: giuliosavini.vmware_tools_builder
      vmtools_remove_standard: true
      vmtools_diagnose_on_failure: true

Enter fullscreen mode Exit fullscreen mode


Requirements

  • Docker on the build host (just for compiling packages)
  • Ansible 2.12+ on the controller
  • SSH access to target machines

That's it. No special build deps, no polluted environments.


If you manage VMware infrastructure and are tired of outdated guest tools, give it a try. The role is on Ansible Galaxy and the source is on GitHub.