Core Concepts
DSC (Desired State Configuration) is a PowerShell-based framework for managing and maintaining the configuration of Windows systems. At its core, DSC relies on three fundamental components: resources, configurations, and the Local Configuration Manager (LCM). These elements work together to ensure systems adhere to a defined, desired state, enabling consistent, scalable, and automated administration.
DSC Resources: The Building Blocks of Configuration¶
Resources are the foundational components of DSC. They represent specific system components or settings that can be configured, such as services, registry keys, files, or Windows features. Each resource has a resource name, properties, and desired state.
Key characteristics of resources:
- Standardized: Resources follow a consistent schema (e.g., ResourceName with Name, Ensure, Value).
- Extensible: Built-in resources (e.g., WindowsFeature, Registry) are complemented by third-party modules (e.g., xPSDesiredStateConfiguration for advanced features).
- Idempotent: Resources ensure a system reaches a target state regardless of its current state.
Example: Configuring a Registry Key
Registry 'SetRegistryKey' {
Ensure = 'Present'
Key = 'HKLM:\Software\MyApp'
ValueName = 'InstallPath'
ValueData = 'C:\ProgramFiles\MyApp'
ValueType = 'String'
}
DSC Configurations: Defining the Desired State¶
A configuration is a PowerShell script that defines the desired state of a system using one or more resources. Configurations are compiled into MOF (Managed Object Format) files, which the LCM uses to apply changes.
Key aspects of configurations:
- Script-based: Written using the Configuration keyword and a script block.
- Target nodes: Specify which nodes (computers) the configuration applies to.
- Compilation: The Start-DscConfiguration cmdlet applies the compiled MOF file.
Example: Ensuring a Service is Running
Configuration EnsureServiceStarted {
Node 'localhost' {
WindowsService 'MyService' {
Name = 'MyService'
Ensure = 'Present'
State = 'Running'
DependsOn = '[Registry]SetRegistryKey'
}
}
}
Local Configuration Manager (LCM): The Execution Engine¶
The LCM is the runtime component responsible for applying and maintaining configurations. It operates on a node (computer) and enforces compliance with the desired state. The LCM can run in push (directly applied via Start-DscConfiguration) or pull (retrieving configurations from a server).
LCM Responsibilities:
- Configuration application: Applies MOF files to ensure the system matches the desired state.
- Compliance reporting: Tracks whether a node is compliant and generates reports.
- Remoting: Manages remote configuration application via PowerShell remoting.
Example: Configuring LCM Settings
Key takeaways¶
- Resources define specific system components and their desired states.
- Configurations compile resources into MOF files, which the LCM applies.
- LCM ensures configurations are enforced, with options for push/pull deployment.
- DSC emphasizes idempotency, allowing systems to reliably reach a target state.
- Third-party modules expand resource capabilities beyond built-in options.