diff --git a/ansible_101/README.md b/ansible_101/README.md new file mode 100644 index 0000000..c5ad56f --- /dev/null +++ b/ansible_101/README.md @@ -0,0 +1,16 @@ +How I ansible +============= + +How to run the slides: + +```sh +pipx install present +present slides.md +``` + +_[pipx](https://pypa.github.io/pipx/) installs python tools in a dedicated environment to prevent overlapping dependencies_ + +--- + +Made with ❤️ and 🐍. + diff --git a/ansible_101/ansible.cfg b/ansible_101/ansible.cfg new file mode 100644 index 0000000..bec3b8d --- /dev/null +++ b/ansible_101/ansible.cfg @@ -0,0 +1,17 @@ +[defaults] +nocows = 1 +# private_key_file = files/id_ed25519 +# remote_user = ansible +inventory = ./inventory +roles_path = ./roles +collections_paths = ./collections +stdout_callback = yaml # readable output + +[privilege_escalation] +become_allow_same_user = True +become = True # also be root, su if needed + +[ssh_connection] +ssh_args = -C -o ControlMaster=auto -o ControlPersist=60s +control_path = %(directory)s/ansible-ssh-%%h-%%p-%%r +control_path_dir = tmp/ diff --git a/ansible_101/how-i-ansible-main.zip b/ansible_101/how-i-ansible-main.zip new file mode 100644 index 0000000..a8f918c Binary files /dev/null and b/ansible_101/how-i-ansible-main.zip differ diff --git a/ansible_101/index.md b/ansible_101/index.md new file mode 100644 index 0000000..188e377 --- /dev/null +++ b/ansible_101/index.md @@ -0,0 +1,162 @@ +--- +title: Ansible 101 +description: A small overview and best practice guide for ansible +author: Ricardo Band +keywords: automation,basics +--- + +# Ansible 101 + +## A small overview and best practice guide for ansible + +--- + +# Python + +- 🐍 use python 3.6+ + - newer = better ✨ +- Dedicated virtualenv +- 📦 container + +```dockerfile +FROM python:3-slim +ADD . +RUN pip install -r requirements.txt +ENTRYPOINT ["ansible-playbook"] +CMD ["--help"] +``` + +- `podman run -it --rm ansible my-playbook.yml` + +--- + +# Ansible + +- `ansible` package is only the CLI +- `ansible-core` is the actual library +- only versions 2.19 and later are semantic +- CLI versions increase quite fast currently at version 6 +- Red Hat Ansible Automation Platform 2.2 (tm) + +--- + +# ansible.cfg + +- Define inventory path + - Could be sourced by a plugin from a DCIM +- Define roles path + - Can be ommitted if all roles are externally sourced +- Switch output plugin + `stdout_callback = yaml` +- Always use root + - Easier then writing `become: yes` everywhere + - 90% of tasks require root anyway +- SSH options + - Faster ssh by reusing connections + ```ini + [ssh_connection] + pipelining = True + ssh_args = -o ControlMaster=auto -o ControlPersist=600 + ``` + +--- + +# requirements.txt + +_Python dependencies_ + +- Ansible dependencies + - `ansible~=6.0` + - Libraries needed by ansible modules or plugins +- Role dependencies + - Libraries needed by roles +- Collection dependencies + - Libraries needed by collections + +--- + +# requirements.yml + +_Ansible dependencies_ + +- Roles +- Collections +- Get dependencies from Ansible docs, example: [podman](https://docs.ansible.com/ansible/latest/collections/containers/podman/podman_container_module.html) + +--- + +# Variables + +- `group_vars` +- `host_vars` +- "Task vars" +- Role vars +- Role defaults + +--- + +# Playbooks + +- Simple playbook +- Playbook with roles + +--- + +# Roles + +``` +roles/./ +├── defaults +│ └── main.yml +├── files +│ └── etc +│ └── foo +│ └── config.ini +├── meta +│ ├── argument_specs.yml +│ └── main.yml +├── tasks +│ └── main.yml +├── templates +│ └── etc +│ └── foo +│ └── conf.d +│ └── special.ini.j2 +└── vars + └── main.yml +``` +--- +# Roles + +- `meta` +- `defaults` vs `vars` +- `files` vs `templates` +- Advanced tasks + +--- + +# Advances topics + +- 🔐 Secrets +- Create your own roles +- Create your own collections + - If you need your own plugins or modules + +--- + +# Secrets + +`$ ansible-galaxy collection install community.general` + +```yaml +password: "{{ lookup('community.general.passwordstore', 'accounts/foobar.com') }}" +aws_secret_key: "{{ lookup('community.general.passwordstore', 'accounts/aws subkey=secret_key') }}" +aws_access_key: "{{ lookup('community.general.passwordstore', 'accounts/aws subkey=access_key') }}" +``` + +See: https://docs.ansible.com/ansible/latest/collections/community/general/passwordstore_lookup.html + +--- + +# ❓ questions ❓ + diff --git a/ansible_101/play_w_roles.yml b/ansible_101/play_w_roles.yml new file mode 100644 index 0000000..35d442e --- /dev/null +++ b/ansible_101/play_w_roles.yml @@ -0,0 +1,8 @@ +--- + +- hosts: all + roles: + - common + - role: that_other_role + some_var: 2342 + diff --git a/ansible_101/requirements.txt b/ansible_101/requirements.txt new file mode 100644 index 0000000..243e4c4 --- /dev/null +++ b/ansible_101/requirements.txt @@ -0,0 +1,6 @@ +# ansible +ansible~=6.0 + +# roles + +# collections diff --git a/ansible_101/requirements.yml b/ansible_101/requirements.yml new file mode 100644 index 0000000..cb36e75 --- /dev/null +++ b/ansible_101/requirements.yml @@ -0,0 +1,12 @@ +--- + +collections: + - name: community.general + version: '>=2.5.1' # parted, copr module + - name: ansible.posix + version: '>=1.2.0' # mount, firewalld module + - name: community.libvirt + version: '>=1.0.1' # virt_pool, virt_net module + +roles: [] + diff --git a/ansible_101/simple_play.yml b/ansible_101/simple_play.yml new file mode 100644 index 0000000..e857dd5 --- /dev/null +++ b/ansible_101/simple_play.yml @@ -0,0 +1,16 @@ +--- +- hosts: all, !supermicro + tasks: + - name: Install foo + tags: install + ansible.builtin.apt: + name: foo + + - name: Setup foo + tags: configure + ansible.builtin.copy: + src: etc/foo/config.ini + dest: /etc/foo/config.ini + notify: + - reload foo +