Skip to content
DevOps Architect

    Syllabus / Infrastructure / 06

    STARTUP TO ENTERPRISE
    06 / 14 • CONFIGURATION MANAGEMENT

    ⚙️Ansible

    Push-based, agentless automation over SSH. Write idempotent playbooks and roles. Encrypt secrets. Manage fleets from 1 server to hundreds with Tower or AWX.

    1 Server Rolling 10 hosts AWX + Compliance

    Architecture & How It Works 06.1

    Ansible control node connects to managed nodes over SSH, copies modules, executes them, then removes temporary files. No agents required. Idempotency is guaranteed by most modules.

    graph LR Control[Control Node] -->|SSH| Inventory[Static/Dynamic Inventory] Inventory --> Target1[Host 1] Inventory --> TargetN[Host N] Control --> Playbook[YAML Playbook] Playbook --> Tasks[Tasks + Modules] Tasks --> Handlers[Handlers on change]

    Core Components 06.2

    ComponentDescriptionKey File / Command
    InventoryList of hosts and groupsinventory.ini or dynamic plugin
    PlaybookOrdered list of plays and taskssite.yml
    RoleStandardized reusable unitroles/nginx/tasks/main.yml
    VariablesPrecedence hierarchygroup_vars/all.yml
    VaultEncrypted variablesansible-vault encrypt
    HandlersTriggered on changenotify: restart service

    WSL Hands-On Lab 06.3

    Install • Inventory • Playbook • Role • Vault • Idempotency Test

    install ansible
    $ sudo apt update && sudo apt install -y ansible-core python3-pip
    $ ansible --version
    inventory.yml (modern YAML inventory)
    all:
      children:
        webservers:
          hosts:
            localhost:
              ansible_connection: local
        dbservers:
          hosts:
            db01:
              ansible_host: 127.0.0.1
    playbook.yml
    ---
    - name: Configure web tier
      hosts: webservers
      become: true
      vars_files:
        - group_vars/all/vault.yml
      tasks:
        - name: Install nginx
          ansible.builtin.apt:
            name: nginx
            state: present
            update_cache: true
        - name: Deploy site config
          ansible.builtin.template:
            src: nginx.conf.j2
            dest: /etc/nginx/nginx.conf
          notify: reload nginx
    
      handlers:
        - name: reload nginx
          ansible.builtin.service:
            name: nginx
            state: reloaded
    run & vault
    $ ansible-playbook -i inventory.yml playbook.yml --check
    $ mkdir -p group_vars/all
    $ ansible-vault create group_vars/all/vault.yml
    $ ansible-playbook -i inventory.yml playbook.yml --ask-vault-pass
    • Install ansible-core
    • Create YAML inventory with localhost + docker targets
    • Write and run idempotent nginx playbook
    • Create proper role directory structure
    • Encrypt sensitive data with ansible-vault
    • Test idempotency twice and verify no changes on second run

    Real-World Project 06.4

    Single server hardening playbook

    users, sshd_config, ufw, fail2ban, unattended upgrades.

    3-tier rolling deployment across fleet of 10 servers

    serial: 1, pre/post tasks, rolling service restarts, blue/green strategy.

    AWX + scheduled patching + Lynis compliance + Windows support

    Maintenance windows, credential isolation, job templates, surveys, compliance reporting.

    Troubleshooting 06.5

    Verify ssh keys 600, ansible_user, become_method: sudo, ssh-agent forwarding if using jump hosts.

    Handler name must match notify exactly. Handlers run once at end of play, even if notified multiple times.

    Extra vars > host_vars > group_vars > role defaults. Use -vvv to debug.

    30-Day Roadmap 06.6

    WEEK 1
    Inventory & Playbooks
    • YAML inventory formats
    • Ad-hoc vs playbook
    • Core modules (apt, copy, service)
    WEEK 2
    Roles & Variables
    • Role directory layout
    • Jinja2 templates
    • Precedence & scope
    WEEK 3
    Vault, Security, Idempotency
    • ansible-vault workflow
    • become & privilege
    • Writing idempotent tasks
    WEEK 4
    AWX / Tower + CI
    • AWX installation
    • Job templates & surveys
    • Git integration + schedules

    Deep Dive: Advanced Ansible Patterns 06.7

    Dynamic Inventory

    Use aws_ec2, azure_rm, gcp_compute inventory plugins. Cache results. Tag instances properly so Ansible can select hosts without static lists.

    Testing & CI for Playbooks

    Use molecule + testinfra or ansible-lint in pipelines. Run ansible-playbook --check --diff in PRs. Never merge untested roles into production playbooks.

    Run: sudo apt update && sudo apt install -y ansible-core python3-pip

    Extra commands from this lesson (5) are kept out of this page. Quizzes were not in the source HTML.