Skip to content

Resource Behavior

PowerShell Desired State Configuration (DSC) resources are designed to manage system configurations by implementing specific operations that define how they interact with the target system. These operations—Get, Set, Test—and the Ensure parameter (where applicable) work together to ensure the system reaches and maintains the desired state. Understanding their roles is critical for writing effective DSC configurations.


Get Method: Retrieve Current State

The Get method retrieves the current state of the resource from the target system. It acts as a diagnostic tool to determine what the system currently looks like. For example, in a custom File resource, the Get method might check whether a file exists at the specified path using internal logic rather than external cmdlets.

Example:

function Get-TargetResource {
    $fileExists = Test-Path -Path $Path
    return @{
        Path = $Path
        Ensure = $Ensure
        FileExists = $fileExists
    }
}
This function internally checks the file's existence and returns its state, which DSC uses to compare against the desired state.


Set Method: Apply Desired State

The Set method is responsible for making changes to the target system to align it with the desired state. It performs actions like creating, modifying, or deleting resources based on the resource's logic. For instance, the Set method in a File resource might create a file if it doesn't exist or update its contents, using internal logic rather than external cmdlets.

Example:

function Set-TargetResource {
    if ($Ensure -eq 'Present') {
        if (-not (Test-Path -Path $Path)) {
            New-Item -Path $Path -ItemType File -Force
        }
        Set-Content -Path $Path -Value $Content
    } else {
        if (Test-Path -Path $Path) {
            Remove-Item -Path $Path -Force
        }
    }
}
This logic ensures the file is created, updated, or deleted based on the Ensure parameter.


Test Method: Validate Desired State

The Test method determines whether the current state of the resource matches the desired state. It returns a boolean value ($true or $false) to indicate compliance. This method is essential for determining if the resource is already in the correct state, avoiding unnecessary changes.

Example:

function Test-TargetResource {
    $fileExists = Test-Path -Path $Path
    return $fileExists -eq ($Ensure -eq 'Present')
}
This logic compares the file's existence with the Ensure parameter to validate compliance.


Ensure Parameter: Control Presence/Absence

The Ensure parameter (common in resources like File, Registry, and Service) specifies whether the resource should ensure the presence (Present) or absence (Absent) of a state. It acts as a flag that guides the Set and Test methods.

Example:

Ensure = 'Present'
If Ensure is set to Present, the Set method ensures the file exists; if Absent, it ensures the file is deleted. The Test method uses this parameter to validate whether the current state matches the desired state.


Key takeaways

  • Get retrieves the current state of the resource using internal logic.
  • Set applies changes to achieve the desired state based on the resource's logic.
  • Test validates whether the current state matches the desired state, using the Ensure parameter.
  • Ensure (where applicable) dictates whether the resource should exist or not, influencing how Set and Test operate.
  • These operations work in concert to ensure the system remains in compliance with the configuration.