new slides

This commit is contained in:
Ricardo (XenGi) Band 2022-08-29 10:27:19 +02:00
commit 89e849d012
Signed by: xengi
GPG key ID: 56376B6BA63CC9F7
8 changed files with 237 additions and 0 deletions

16
ansible_101/README.md Normal file
View file

@ -0,0 +1,16 @@
How I ansible
=============
How to run the slides:
```sh
pipx install present
present slides.md
```
_[pipx](https://pypa.github.io/pipx/) installs python tools in a dedicated environment to prevent overlapping dependencies_
---
Made with ❤️ and 🐍.

17
ansible_101/ansible.cfg Normal file
View file

@ -0,0 +1,17 @@
[defaults]
nocows = 1
# private_key_file = files/id_ed25519
# remote_user = ansible
inventory = ./inventory
roles_path = ./roles
collections_paths = ./collections
stdout_callback = yaml # readable output
[privilege_escalation]
become_allow_same_user = True
become = True # also be root, su if needed
[ssh_connection]
ssh_args = -C -o ControlMaster=auto -o ControlPersist=60s
control_path = %(directory)s/ansible-ssh-%%h-%%p-%%r
control_path_dir = tmp/

Binary file not shown.

162
ansible_101/index.md Normal file
View file

@ -0,0 +1,162 @@
---
title: Ansible 101
description: A small overview and best practice guide for ansible
author: Ricardo Band
keywords: automation,basics
---
# Ansible 101
## A small overview and best practice guide for ansible
---
# Python
- 🐍 use python 3.6+
- newer = better ✨
- Dedicated virtualenv
- 📦 container
```dockerfile
FROM python:3-slim
ADD .
RUN pip install -r requirements.txt
ENTRYPOINT ["ansible-playbook"]
CMD ["--help"]
```
- `podman run -it --rm ansible my-playbook.yml`
---
# Ansible
- `ansible` package is only the CLI
- `ansible-core` is the actual library
- only versions 2.19 and later are semantic
- CLI versions increase quite fast currently at version 6
- Red Hat Ansible Automation Platform 2.2 (tm)
---
# ansible.cfg
- Define inventory path
- Could be sourced by a plugin from a DCIM
- Define roles path
- Can be ommitted if all roles are externally sourced
- Switch output plugin
`stdout_callback = yaml`
- Always use root
- Easier then writing `become: yes` everywhere
- 90% of tasks require root anyway
- SSH options
- Faster ssh by reusing connections
```ini
[ssh_connection]
pipelining = True
ssh_args = -o ControlMaster=auto -o ControlPersist=600
```
---
# requirements.txt
_Python dependencies_
- Ansible dependencies
- `ansible~=6.0`
- Libraries needed by ansible modules or plugins
- Role dependencies
- Libraries needed by roles
- Collection dependencies
- Libraries needed by collections
---
# requirements.yml
_Ansible dependencies_
- Roles
- Collections
- Get dependencies from Ansible docs, example: [podman](https://docs.ansible.com/ansible/latest/collections/containers/podman/podman_container_module.html)
---
# Variables
- `group_vars`
- `host_vars`
- "Task vars"
- Role vars
- Role defaults
---
# Playbooks
- Simple playbook
- Playbook with roles
---
# Roles
```
roles/<github_username>.<rolename>/
├── defaults
│ └── main.yml
├── files
│ └── etc
│ └── foo
│ └── config.ini
├── meta
│ ├── argument_specs.yml
│ └── main.yml
├── tasks
│ └── main.yml
├── templates
│ └── etc
│ └── foo
│ └── conf.d
│ └── special.ini.j2
└── vars
└── main.yml
```
---
# Roles
- `meta`
- `defaults` vs `vars`
- `files` vs `templates`
- Advanced tasks
---
# Advances topics
- 🔐 Secrets
- Create your own roles
- Create your own collections
- If you need your own plugins or modules
---
# Secrets
`$ ansible-galaxy collection install community.general`
```yaml
password: "{{ lookup('community.general.passwordstore', 'accounts/foobar.com') }}"
aws_secret_key: "{{ lookup('community.general.passwordstore', 'accounts/aws subkey=secret_key') }}"
aws_access_key: "{{ lookup('community.general.passwordstore', 'accounts/aws subkey=access_key') }}"
```
See: https://docs.ansible.com/ansible/latest/collections/community/general/passwordstore_lookup.html
---
# ❓ questions ❓

View file

@ -0,0 +1,8 @@
---
- hosts: all
roles:
- common
- role: that_other_role
some_var: 2342

View file

@ -0,0 +1,6 @@
# ansible
ansible~=6.0
# roles
# collections

View file

@ -0,0 +1,12 @@
---
collections:
- name: community.general
version: '>=2.5.1' # parted, copr module
- name: ansible.posix
version: '>=1.2.0' # mount, firewalld module
- name: community.libvirt
version: '>=1.0.1' # virt_pool, virt_net module
roles: []

View file

@ -0,0 +1,16 @@
---
- hosts: all, !supermicro
tasks:
- name: Install foo
tags: install
ansible.builtin.apt:
name: foo
- name: Setup foo
tags: configure
ansible.builtin.copy:
src: etc/foo/config.ini
dest: /etc/foo/config.ini
notify:
- reload foo