3 KiB
3 KiB
| title | description | author | keywords |
|---|---|---|---|
| Ansible 101 | A small overview and best practice guide for ansible | Ricardo Band | automation,basics |
Ansible 101
A small overview and best practice guide for ansible
Python
- 🐍 use python 3.6+
- newer = better ✨
- Dedicated virtualenv
- 📦 container
FROM python:3-slim
ADD .
RUN pip install -r requirements.txt
ENTRYPOINT ["ansible-playbook"]
CMD ["--help"]
podman run -it --rm ansible my-playbook.yml
Ansible
ansiblepackage is only the CLIansible-coreis the actual library- only versions 2.19 and later are semantic
- CLI versions increase quite fast currently at version 6
- Red Hat Ansible Automation Platform 2.2 (tm)
ansible.cfg
- Define inventory path
- Could be sourced by a plugin from a DCIM
- Define roles path
- Can be ommitted if all roles are externally sourced
- Switch output plugin
stdout_callback = yaml - Always use root
- Easier then writing
become: yeseverywhere - 90% of tasks require root anyway
- Easier then writing
- SSH options
- Faster ssh by reusing connections
[ssh_connection] pipelining = True ssh_args = -o ControlMaster=auto -o ControlPersist=600
- Faster ssh by reusing connections
requirements.txt
Python dependencies
- Ansible dependencies
ansible~=6.0- Libraries needed by ansible modules or plugins
- Role dependencies
- Libraries needed by roles
- Collection dependencies
- Libraries needed by collections
requirements.yml
Ansible dependencies
- Roles
- Collections
- Get dependencies from Ansible docs, example: podman
Variables
group_varshost_vars- "Task vars"
- Role vars
- Role defaults
Playbooks
- Simple playbook
- Playbook with roles
Roles
roles/<github_username>.<rolename>/
├── defaults
│ └── main.yml
├── files
│ └── etc
│ └── foo
│ └── config.ini
├── meta
│ ├── argument_specs.yml
│ └── main.yml
├── tasks
│ └── main.yml
├── templates
│ └── etc
│ └── foo
│ └── conf.d
│ └── special.ini.j2
└── vars
└── main.yml
Roles
metadefaultsvsvarsfilesvstemplates- Advanced tasks
Advances topics
- 🔐 Secrets
- Create your own roles
- Create your own collections
- If you need your own plugins or modules
Secrets
$ ansible-galaxy collection install community.general
password: "{{ lookup('community.general.passwordstore', 'accounts/foobar.com') }}"
aws_secret_key: "{{ lookup('community.general.passwordstore', 'accounts/aws subkey=secret_key') }}"
aws_access_key: "{{ lookup('community.general.passwordstore', 'accounts/aws subkey=access_key') }}"
See: https://docs.ansible.com/ansible/latest/collections/community/general/passwordstore_lookup.html