Ansible
Automation for everyone No matter your role, or what your automation goals are, Ansible can help you demonstrate value, connect teams, and deliver efficiencies for your organization. Built on open source, Red Hat® Ansible® Automation Platform is a hardened, tested subscription product that offers full life cycle support for organizations. Explore how Ansible can help you automate today—and scale for the future.
Tutorials, Resources
- Learn Linux TV - Getting started with Ansible
- Laying out roles, inventories and playbooks
- An evolving set of mac user creation, setup and maintenance playbooks being used at Ideas On Purpose
- Variable precedence: Where should I put a variable?
Directory structure
ansible– Configuration of the host OS & required softwareansible/roles– Roles for Debian-based Docker & admin hosts and a Mac-based DevOps/SRE toolsetansible/playbooks– Host-role assignments. The playbooks can be executed with theapply-*.shscriptsansible/inventory– Host specific environment configuration
Setup steps
- From the repository root, install Ansible on the selected admin environment with
sudo ansible/bootstrap-ansible.sh. This can be the Docker host in single-host mode. (See: Ansible control node) - Copy
config-example/ansibleto the ignoredconfig/ansibleoverlay and configure its inventory and secret variables. - Add hosts to
config/ansible/inventory/inventory.yaml. - Assign roles by adding hosts to the corresponding inventory groups, such as
docker_hosts. - Run
ansible/apply-<playbook>.shfrom the repository root to execute a playbook.- If you use a non-root user and
sudorequires a password (indicated by the “Missing sudo password” error message), useansible/apply-<playbook>.sh --ask-become-passand specify the password when requested (“BECOME password” message) - The playbook will set up passwordless
sudo, so next time the--ask-become-passparameter will not be required
- If you use a non-root user and
- When the administrative user is already created, use that user in the inventory instead of
root(ansible_user: <adminuser>). This is more secure and also required by Homebrew.
For the complete infrastructure setup walkthrough using these playbooks, see Getting Started.
Bootstrapping hosts with authentication
- Copy public SSH key, e.g.:
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@192.168.1.50 - Run playbook with existing user (
rootor your admin user if already created) - From the repository root, verify one host with both inventory sources:
ansible <host> -m ping -i ansible/inventory/inventory.yaml -i config/ansible/inventory/inventory.yaml
Useful options
The following parameters can be applied to ansible-playbook and the “apply…” scripts.
-l,--limit- Limit Ansible run for a specific host (or host group). Example:./apply-homelab.sh --limit <host>-v,--verbose- Causes Ansible to print more debug messages. Adding multiple -v will increase the verbosity, the builtin plugins currently evaluate up to -vvvvvv. A reasonable level to start is -vvv, connection debugging might require -vvvv. Example:./apply-homelab.sh -v
See man ansible-playbook for more.