⚙️Ansible
Push-based, agentless automation over SSH. Write idempotent playbooks and roles. Encrypt secrets. Manage fleets from 1 server to hundreds with Tower or AWX.
Architecture & How It Works 06.1
Ansible control node connects to managed nodes over SSH, copies modules, executes them, then removes temporary files. No agents required. Idempotency is guaranteed by most modules.
Core Components 06.2
| Component | Description | Key File / Command |
|---|---|---|
| Inventory | List of hosts and groups | inventory.ini or dynamic plugin |
| Playbook | Ordered list of plays and tasks | site.yml |
| Role | Standardized reusable unit | roles/nginx/tasks/main.yml |
| Variables | Precedence hierarchy | group_vars/all.yml |
| Vault | Encrypted variables | ansible-vault encrypt |
| Handlers | Triggered on change | notify: restart service |
WSL Hands-On Lab 06.3
Install • Inventory • Playbook • Role • Vault • Idempotency Test
$ sudo apt update && sudo apt install -y ansible-core python3-pip $ ansible --version
all:
children:
webservers:
hosts:
localhost:
ansible_connection: local
dbservers:
hosts:
db01:
ansible_host: 127.0.0.1---
- name: Configure web tier
hosts: webservers
become: true
vars_files:
- group_vars/all/vault.yml
tasks:
- name: Install nginx
ansible.builtin.apt:
name: nginx
state: present
update_cache: true
- name: Deploy site config
ansible.builtin.template:
src: nginx.conf.j2
dest: /etc/nginx/nginx.conf
notify: reload nginx
handlers:
- name: reload nginx
ansible.builtin.service:
name: nginx
state: reloaded$ ansible-playbook -i inventory.yml playbook.yml --check $ mkdir -p group_vars/all $ ansible-vault create group_vars/all/vault.yml $ ansible-playbook -i inventory.yml playbook.yml --ask-vault-pass
- Install ansible-core
- Create YAML inventory with localhost + docker targets
- Write and run idempotent nginx playbook
- Create proper role directory structure
- Encrypt sensitive data with ansible-vault
- Test idempotency twice and verify no changes on second run
Real-World Project 06.4
Single server hardening playbook
users, sshd_config, ufw, fail2ban, unattended upgrades.
3-tier rolling deployment across fleet of 10 servers
serial: 1, pre/post tasks, rolling service restarts, blue/green strategy.
AWX + scheduled patching + Lynis compliance + Windows support
Maintenance windows, credential isolation, job templates, surveys, compliance reporting.
Troubleshooting 06.5
Verify ssh keys 600, ansible_user, become_method: sudo, ssh-agent forwarding if using jump hosts.
Handler name must match notify exactly. Handlers run once at end of play, even if notified multiple times.
Extra vars > host_vars > group_vars > role defaults. Use -vvv to debug.
30-Day Roadmap 06.6
- YAML inventory formats
- Ad-hoc vs playbook
- Core modules (apt, copy, service)
- Role directory layout
- Jinja2 templates
- Precedence & scope
- ansible-vault workflow
- become & privilege
- Writing idempotent tasks
- AWX installation
- Job templates & surveys
- Git integration + schedules
Deep Dive: Advanced Ansible Patterns 06.7
Dynamic Inventory
Use aws_ec2, azure_rm, gcp_compute inventory plugins. Cache results. Tag instances properly so Ansible can select hosts without static lists.
Testing & CI for Playbooks
Use molecule + testinfra or ansible-lint in pipelines. Run ansible-playbook --check --diff in PRs. Never merge untested roles into production playbooks.