Welcome to TiddlyWiki created by Jeremy Ruston; Copyright © 2004-2007 Jeremy Ruston, Copyright © 2007-2011 UnaMesa Association
Running against all hosts without <html><code>--limit</code></html>, using raw <html><code>shell:</code></html> instead of idempotent modules, applying privilege escalation globally, and misunderstanding variable precedence are each individually unsafe—but together they create a cascade where early mistakes are invisible, making later shortcuts feel justified. Skipping <html><code>--check</code></html> and dry-runs to save time means untested changes hit production. Using <html><code>shell:</code></html> makes re-runs expensive (40 minutes reinstalling packages). Global <html><code>become: yes</code></html> breaks application permissions. Variable precedence confusion wastes hours on debugging. Each mistake alone might be recoverable; together they create an outage. Prevention requires enforcing single practices: always use <html><code>--limit</code></html>, always prefer native modules, always use per-task privilege escalation, always understand your variable sources.
----
''Sources''
* <html><code>training/library/topics/ansible/anti_primer.md</code></html>
''Related atoms''
* [[How cascading mistakes lead to infrastructure incidents]]
* [[Ansible's idempotency guarantee is aspirational, not enforced]]
* [[Shell module instead of apt module for packages (idempotency loss)]]
Q: Explain the use of the -vvv option when running Ansible commands.
A: The -vvv option is used to enable maximum verbosity when running Ansible commands. It produces highly detailed output, including information about each task and the status of module execution, aiding in debugging.
Remember: -v = basic, -vv = more detail, -vvv = connection debugging, -vvvv = adds connection plugin output. Start with -v and increase as needed.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What are the four verbosity levels in Ansible?]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[How do you enable verbose mode for Ansible playbooks?]]
Ansible Modules are standalone scripts or programs that Ansible executes to perform specific tasks on managed nodes. They act as the verbs of Ansible automation, handling operations such as package installation, file manipulation, service management, and shell execution.
Modules are invoked in playbooks or ad-hoc commands. For example, <html><code>ansible all -m ping</code></html> uses the ping module to test connectivity without a playbook.
Commonly used modules:
* ''apt'' / ''yum'': Manage packages on Debian-based and Red Hat-based systems respectively.
* ''copy'': Transfer files to remote nodes.
* ''template'': Render Jinja2 configuration files on remote hosts.
* ''service'' / ''systemd'': Manage daemons and system services.
* ''shell'': Execute arbitrary shell commands on the remote node.
Mastering apt/yum (packages), copy/template (files), and service/systemd (daemons) covers the majority of common automation tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are Ansible plugins?]]
* [[How do you use the "shell" module in Ansible?]]
* [[What is the `ansible.builtin.script` module?]]
Ansible is an open-source IT automation tool written in Python, used for configuration management, application deployment, orchestration, and provisioning. It is agentless — no daemon or agent software is installed on managed nodes. Instead, a control node connects to managed nodes over SSH (or WinRM for Windows) and executes //modules// (discrete task units) to bring systems to a desired state. Tasks are expressed in YAML and are idempotent by convention.
Key properties: agentless, no persistent daemons, SSH/WinRM transport, idempotent execution, YAML-driven playbooks.
The name derives from Ursula K. Le Guin's fiction, where an "ansible" is a device for instantaneous communication across any distance — a metaphor for remote control at scale.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible's agentless design: SSH over a custom control protocol]]
* [[Ansible's SSH-based agentless execution model]]
* [[Ansible managed node]]
Q: Ansible in a Multi-Cloud Environment
A: To manage multi-cloud environments, I would use dynamic inventories and cloud-specific modules for each provider (AWS, Azure, GCP).
Example using multiple dynamic inventories:
<html><pre><code class="language-plaintext">plugin: aws_ec2
regions:
- us-east-1
plugin: azure_rm</code></pre></html>
<html><pre><code class="language-plaintext">ansible-playbook -i aws_ec2.yml -i azure_rm.yml playbook.yml</code></pre></html>
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[Ansible Dynamic Inventory]]
* [[What's your experience with Ansible?]]
* [[Ansible configures running infrastructure; Terraform creates it]]
Q: What are idempotency issues in infrastructure automation and how are they avoided?
A: Idempotency means that running a task multiple times should have the same effect as running it once. To identify and fix idempotency issues:
Identify the Task: Determine which task is causing the issue by reviewing the output of ansible-playbook with the -v (verbose) flag.
Analyze the Task: Check if the task is correctly checking for the desired state before making changes. For example, ensure that file changes, service restarts, or package installations are conditional.
Remember: idempotent = 'run it 100 times, same result as once.' Like pressing an elevator button — pressing it again doesn't call a second elevator.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[Ansible's idempotency guarantee is aspirational, not enforced]]
* [[What makes good Ansible?]]
* [[Prefer native modules over shell/command for idempotency]]
Ansible executes external scripts—written in Python or any executable language—to fetch dynamic inventory. These scripts must return JSON-formatted data following a specific schema Ansible expects, describing hosts and their group memberships along with optional host and group variables.
Ansible calls the script with two flags:
* <html><code>--list</code></html>: returns all groups and their member hosts.
* <html><code>--host <hostname></code></html>: returns variables for a single host.
A common example is a Python script that queries the AWS EC2 API and emits JSON with host groups matching EC2 tags or instance attributes. Ansible parses this output and constructs its in-memory inventory from it.
Modern practice prefers inventory plugins over scripts. Plugins integrate more cleanly with Ansible's architecture, support result caching natively, and avoid the overhead of subprocess execution on every run.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Dynamic Inventory]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[What is an Ansible inventory?]]
The <html><code>ansible-doc</code></html> command provides offline documentation for [[Ansible modules|Ansible Modules]] by reading module docstrings locally — no internet required.
Basic usage:
<html><pre><code class="language-bash">ansible-doc <module_name>
# e.g., ansible-doc copy</code></pre></html>
This displays the module's full documentation including parameters, examples, and usage.
Key flags:
* <html><code>ansible-doc -l</code></html> — list all available modules
* <html><code>ansible-doc -s <module_name></code></html> — show a short snippet of required parameters only
Because documentation is read from local docstrings, <html><code>ansible-doc</code></html> works in air-gapped environments and reflects exactly the module version installed on the control node.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[What is `ansible-doc` used for?]]
* [[Listing and inspecting Ansible modules with ansible-doc]]
* [[ansible-navigator: modern replacement for ansible-playbook]]
Common Ansible module problems include compatibility mismatches, incorrect or missing parameters, and missing modules or collections.
''Troubleshooting steps:''
* Check module documentation for device/platform compatibility and required parameters.
* Verify target device or host connectivity before assuming a module fault.
* Ensure the module is installed — a 'module not found' error typically means a missing collection; install with <html><code>ansible-galaxy collection install <namespace.collection></code></html> (e.g., <html><code>community.general</code></html>).
* Confirm required Python packages are present on the target host, as noted in the module's documentation.
* Examine module-specific logs and task output for error details.
* Use the <html><code>debug</code></html> module to inspect variables and data flow mid-playbook.
* Run ad-hoc commands (e.g., <html><code>ansible all -m ping</code></html>) to isolate connectivity from playbook logic.
''Context:'' Modules are the action verbs of Ansible — <html><code>apt</code></html> installs packages, <html><code>copy</code></html> moves files, <html><code>service</code></html> manages daemons. Most module failures are parameter or dependency problems, not Ansible itself. If troubleshooting becomes complex, simplify: YAML playbooks, agentless SSH, and idempotent modules are Ansible's core strengths.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What steps would you take to troubleshoot a failed Ansible playbook?]]
* [[Troubleshooting Playbook Failures]]
* [[Playbook failure diagnosis pattern]]
Q: How does Ansible connect to managed nodes?
A: It typically uses SSH for Linux and WinRM for Windows.
Under the hood: Ansible copies Python modules to the remote host via SFTP, executes them, captures JSON output, then deletes the temp files. SSH ControlPersist multiplexing keeps connections fast.
Fun fact: Ansible's agentless architecture (2012) was a key differentiator — competitors like Puppet and Chef required a daemon on every node.
Remember: Control Node = where Ansible runs. Managed Node = where Ansible acts. Think 'puppeteer vs. puppet.'
Gotcha: managed nodes need Python installed (except for raw module). Windows nodes use WinRM, not SSH.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[How does Ansible communicate with Linux hosts?]]
* [[Ansible control node]]
* [[Why does Ansible have separate Python requirements for control node vs. managed nodes?]]
Ansible can be installed on Linux via native package managers or pip.
''Package managers:''
* Red Hat-based systems: <html><code>sudo yum install ansible</code></html>
* Debian-based systems: <html><code>sudo apt-get install ansible</code></html>
''pip:''
* <html><code>pip install ansible</code></html> — installs the full distribution including all collections (~7,000 modules).
* <html><code>pip install ansible-core</code></html> — installs only the core engine with a minimal collection set. Preferred for production environments where explicit control over included modules matters.
''Configuration:''
Ansible reads its configuration from <html><code>ansible.cfg</code></html>. Key parameters set there include inventory file location and SSH connection settings. The file is searched in order: path in <html><code>ANSIBLE_CONFIG</code></html> env var, <html><code>./ansible.cfg</code></html>, <html><code>~/.ansible.cfg</code></html>, then <html><code>/etc/ansible/ansible.cfg</code></html>.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Modules]]
* [[What is the relationship between ansible-core and the ansible package?]]
* [[What are the key features of Ansible?]]
Q: How do you execute a single ad-hoc Ansible command?
A: Using the ansible command. For example: ansible all -m ping will run the "ping" module on all hosts in the inventory (useful for quick tasks or to test connectivity).
Example: ansible webservers -m apt -a 'name=nginx state=present' -b installs nginx on all webservers with sudo (-b = become). Ad-hoc commands are great for one-off tasks.
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[How do you install a package using an ad-hoc command?]]
* [[Give an example of an ad-hoc ping command.]]
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
Use <html><code>ansible-doc -l</code></html> (or <html><code>ansible-doc --list</code></html>) to list all available modules. The full list spans 7,000+ modules across all installed collections. Filter results by collection or keyword: <html><code>ansible-doc -l -t module community.general</code></html> lists modules in a specific collection; <html><code>ansible-doc -l -t module | grep aws</code></html> narrows to AWS-specific modules.
Use <html><code>ansible-doc <module_name></code></html> to display detailed documentation — parameters, return values, and examples — for a specific module.
The Ansible online docs are an alternative reference for the same information.
Gotcha: <html><code>ansible-doc -l | wc -l</code></html> will report 7,000+ lines; always filter before browsing manually.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[ansible-doc: offline module documentation reference]]
* [[How many collections are typically included in the Ansible community package?]]
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
Q: How does Ansible support network automation?
A: Ansible supports network automation by providing modules for configuring network devices. It can automate tasks like updating device configurations, managing VLANs, and deploying changes across a network infrastructure.
Example: modules like ios_config (Cisco), junos_config (Juniper), and eos_config (Arista) push configs to devices. Network modules often use network_cli or netconf connections instead of SSH+Python.
Remember: Ansible network automation uses specialized connection types (network_cli, httpapi, netconf) instead of standard SSH + Python, because network devices often lack Python.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What are the three main connection types for network automation?]]
* [[Ansible network modules provide declarative multi-vendor configuration]]
* [[Configuring Ansible for Network Automation]]
Q: What are specific challenges you might face when using Ansible for network automation?
A: Challenges include:
* Vendor-specific syntax and module support.
* Managing device state changes.
* Handling varied device responses.
* Ensuring network reliability for automation tasks.
Gotcha: network devices often lack Python, requiring the raw module or specialized connection types (network_cli, httpapi, netconf) instead of standard SSH + Python.
Remember: Ansible network automation uses specialized connection types (network_cli, httpapi, netconf) instead of standard SSH + Python, because network devices often lack Python.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What is Ansible Networking, and how is it different from traditional Ansible?]]
* [[Ansible became the dominant network automation tool despite being designed for servers]]
* [[What's your experience with Ansible?]]
Q: What is Ansible Networking, and how is it different from traditional Ansible?
A: Ansible Networking is an extension of Ansible designed for network automation. It includes modules tailored for network devices, supporting tasks like configuration management and device provisioning. While traditional Ansible can be used for network automation, Ansible Networking provides specialized modules and features.
Remember: Ansible network automation uses specialized connection types (network_cli, httpapi, netconf) instead of standard SSH + Python, because network devices often lack Python.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[What did Ansible 2.5 introduce that changed how network automation worked?]]
* [[Ansible became the dominant network automation tool despite being designed for servers]]
A managed node is a target device or server that Ansible acts upon, as opposed to the control node where Ansible itself runs.
Managed nodes require SSH access and Python installed — no Ansible agent is needed on the target. The one exception is the <html><code>raw</code></html> module, which bypasses Python entirely. Windows managed nodes use WinRM instead of SSH.
Example: a laptop (control node) runs <html><code>ansible-playbook</code></html>, which SSHes into 50 web servers (managed nodes) and executes tasks on them.
Mnemonic: Control Node = puppeteer. Managed Node = puppet.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible: agentless IT automation tool]]
* [[What does "agentless" mean in the context of Ansible?]]
* [[What are the server requirements for Ansible?]]
Ansible Vault encrypts sensitive data — passwords, API keys, secret strings — within YAML files, playbooks, and roles. Encrypted files can be safely committed to version control.
Encrypt a file:
<html><pre><code class="language-bash">ansible-vault encrypt secrets.yml</code></pre></html>
Include encrypted vars in a playbook:
<html><pre><code class="language-yaml">- hosts: all
vars_files:
- secrets.yml
tasks:
- name: Use secret API key
uri:
url: "https://api.example.com/data"
headers:
Authorization: "Bearer {{ api_key }}"</code></pre></html>
Run with a vault password prompt:
<html><pre><code class="language-bash">ansible-playbook --ask-vault-pass playbook.yml</code></pre></html>
Passwords can also be supplied via external tools or password files instead of interactive prompts.
Gotchas:
* Encrypted and unencrypted variable files can be mixed in the same playbook.
* Use <html><code>--vault-id</code></html> to manage multiple vault passwords across environments (e.g., dev vs. prod).
* YAML indentation must be consistent — 2 spaces throughout. A single misindented line can silently change task behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Explain the process of editing an encrypted file with Ansible Vault.]]
* [[Vault Passwords Must Not Appear in Shell History or Plain Text]]
* [[Passing Variables and Vault to Ansible in Packer]]
Q: Explain the purpose of the "copy" module in Ansible.
A: The copy module is used to copy files from the Ansible controller to remote nodes. It can also set file permissions and ownership during the copy operation.
Example: - copy: src=files/nginx.conf dest=/etc/nginx/nginx.conf owner=root mode=0644 notify: restart nginx
Gotcha: for large files, use synchronize (rsync wrapper) instead of copy — copy loads the entire file into memory on the control node.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What does the `copy` module do?]]
* [[What is the `synchronize` module?]]
* [[What does the `ANSIBLE_KEEP_REMOTE_FILES` setting do?]]
Q: How do you set up passwordless SSH for Ansible?
A: Generate SSH keys using ssh-keygen on the Ansible controller, and copy the public key (~/.ssh/id_rsa.pub) to the ~/.ssh/authorized_keys file on managed nodes.
Gotcha: use ssh-copy-id user@host to automate key distribution. For large fleets, bake the public key into your base image or use a configuration management bootstrap.
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[How can you troubleshoot SSH connection issues with Ansible?]]
* [[How do you securely manage control node credentials?]]
Q: How can you troubleshoot SSH connection issues with Ansible?
A: Troubleshoot SSH issues by checking:
* SSH key permissions.
* User permissions on the target system.
* Connectivity between the Ansible controller and target.
* SSH configuration on the target system.
* Security groups or firewalls blocking SSH traffic.
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[How do you set up passwordless SSH for Ansible?]]
* [[What are the key features of Ansible?]]
An Ansible inventory file defines the managed nodes (hosts) and groups of hosts on which Ansible tasks are executed. It is the answer to 'who to manage'; a playbook answers 'what to do.' Together they answer 'do what, to whom.'
Hosts can be listed by IP address or hostname. The default location is <html><code>/etc/ansible/hosts</code></html>, but this can be overridden with the <html><code>-i path/to/inventory</code></html> CLI flag or the <html><code>ANSIBLE_INVENTORY</code></html> environment variable. Most projects keep inventory alongside playbooks in the repo.
Basic example:
<html><pre><code class="language-plaintext">192.168.1.2
192.168.1.3
[web_servers]
190.40.2.20
190.40.2.21
[dbservers]
db1.example.com</code></pre></html>
Hosts accept per-host variables inline: <html><code>web2.example.com ansible_port=2222</code></html> or <html><code>webserver ansible_host=192.168.1.10</code></html>.
Groups can nest using the <html><code>:children</code></html> suffix:
<html><pre><code class="language-plaintext">[prod:children]
webservers
dbservers</code></pre></html>
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command lists all hosts in an inventory?]]
* [[What is an Ansible inventory?]]
* [[What is a group in an Ansible inventory?]]
A dynamic inventory is an external script, plugin, or program that generates Ansible inventory information at runtime by querying external sources — cloud providers (AWS, Azure, GCP, VMware), CMDBs, or other APIs — rather than reading a static hosts file.
Use a dynamic inventory when infrastructure is fluid: hosts are automatically spun up and shut down, and maintaining a hand-edited static list would be error-prone or lag behind reality. The inventory is rebuilt fresh on each Ansible run by asking the external source who exists right now.
Example: the AWS EC2 inventory plugin queries the AWS API and auto-discovers instances filtered by tags, regions, or VPCs — no manual hosts file required.
Key distinction from static inventory: static inventories are files you maintain; dynamic inventories delegate host discovery to an authoritative external system, so Ansible always reflects current infrastructure state without manual updates.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[What are common issues you might encounter with dynamic inventories, and how would you …]]
* [[Inventory is more than a flat list of hosts]]
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
Idempotence means running the same operation multiple times produces the same end state as running it once. [[Ansible modules|Ansible Modules]] enforce this contract by querying the current state of a resource, comparing it to the desired state declared in the playbook, and acting only if they differ. On the first run a change is needed and the task reports <html><code>changed</code></html>; on subsequent runs the desired state already exists and the task reports <html><code>ok</code></html> without modifying anything.
This property makes playbooks safe to re-run, enables desired-state configuration, supports drift detection and correction, and makes automation predictable.
Non-idempotent modules like <html><code>ansible.builtin.command</code></html> and <html><code>ansible.builtin.shell</code></html> always report <html><code>changed</code></html> because Ansible cannot introspect the side effects of arbitrary shell commands. When no purpose-built idempotent module exists, prefer modules with explicit <html><code>state:</code></html> directives (e.g., <html><code>file</code></html> for directories, <html><code>copy</code></html> for files) over <html><code>shell</code></html> or <html><code>command</code></html>.
Examples:
* <html><code>ansible.builtin.apt</code></html> with <html><code>state: present</code></html> returns <html><code>ok</code></html> on the second run—the package is already installed.
* <html><code>ansible.builtin.user</code></html> and <html><code>ansible.builtin.file</code></html> inspect the target first, then act only if needed.
* A bare <html><code>shell: apt install nginx</code></html> runs every time regardless of current state.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/primer.md</code></html>
* <html><code>training/library/topics/mental-models-core/ansible-idempotence-modules-plugins.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[Ansible ios_command is not idempotent for configuration]]
* [[Idempotency as default, exceptions with shell and command modules]]
Ansible differs from Chef and Puppet across several architectural dimensions:
''Agentless vs. agent-based:'' Ansible communicates over SSH and requires no daemon or client software on target nodes. Chef and Puppet require an agent installed on every managed node (client-server model).
''Push vs. pull:'' Ansible defaults to push-based execution — the control node initiates runs. Chef and Puppet default to pull-based — agents periodically check in with a central server.
''Configuration language:'' Ansible uses YAML playbooks, which have a low learning curve and require no programming background. Chef uses a Ruby DSL; Puppet uses its own declarative DSL (also Ruby-influenced). Chef and Puppet offer more flexibility for complex logic but demand more expertise.
''Prerequisites:'' Ansible requires only Python and SSH on target nodes. Chef/Puppet require their respective agents plus server infrastructure.
''Ease of use vs. flexibility trade-off:'' Ansible prioritizes simplicity and fast onboarding. Chef and Puppet are better suited to large-scale, complex environments where experienced users leverage their richer abstractions.
Mnemonic: ''PAYS'' — Push-based, Agentless, YAML, SSH.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible's agentless design: SSH over a custom control protocol]]
* [[How does Ansible differ from other configuration management tools?]]
* [[What are the key features of Ansible?]]
Q: Why Use Ansible Collections?
A: - Modular and reusable components
** Simplifies management of custom and third-party modules
** Provides a standardized way to distribute automation content
** Helps in version control and dependency management
Example: ansible-galaxy collection install community.general installs the collection. Use FQCN in tasks: community.general.ufw for the firewall module.
Remember: collections replaced the old monolithic module distribution. Think of them as 'Ansible packages' with versioning.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[Modules, plugins, and collections in Ansible architecture]]
* [[When did the collections concept first appear in Ansible?]]
* [[Ansible Galaxy: community hub for roles and collections]]
Q: How do you use the "shell" module in Ansible?
A: The shell module is used to execute shell commands on remote nodes. Example:
<html><pre><code class="language-yaml">- name: Run a shell command
shell: echo "Hello, World!"</code></pre></html>
Gotcha: prefer the command module over shell unless you need pipes, redirects, or shell builtins. shell spawns a full /bin/sh, adding attack surface.
Remember: shell/command modules are not idempotent. Always add creates: or when: to guard against re-execution.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[Why is shell in Ansible dangerous?]]
* [[Ansible Modules]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
Facts are system information automatically collected from managed nodes at the start of each play via the <html><code>setup</code></html> module. They cover OS distribution and family, IP addresses, CPU, memory, disk, and more.
All gathered data is stored in the <html><code>ansible_facts</code></html> dictionary. Since Ansible 2.5, the canonical access pattern is <html><code>ansible_facts['os_family']</code></html> rather than the legacy flat variable <html><code>ansible_os_family</code></html>. The <html><code>{{ ansible_hostname }}</code></html> shorthand still works but is deprecated in favor of <html><code>ansible_facts['hostname']</code></html>.
Example conditional: <html><code>when: ansible_facts['os_family'] == 'Debian'</code></html>. <html><code>ansible_facts['distribution']</code></html> returns values like <html><code>'Ubuntu'</code></html> or <html><code>'CentOS'</code></html>.
Fact gathering runs before any tasks and adds overhead proportional to host count. Disable it per-play with <html><code>gather_facts: false</code></html> when host details are not needed.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[What would be the result of the following play?]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[How do you view all facts for a host?]]
Q: What are common issues you might encounter with dynamic inventories, and how would you troubleshoot them?
A: Common issues include script errors, incomplete data, or connectivity problems. Troubleshoot by running the inventory script manually, checking script permissions, and validating output format.
Gotcha: always test inventory scripts with --list and --host flags manually. Enable ANSIBLE_DEBUG=1 for verbose connection and inventory troubleshooting output.
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[Ansible Dynamic Inventory]]
* [[Dynamic inventory in Ansible]]
* [[Editing inventory during playbook execution causes races]]
Q: Why is Ansible more dangerous than shell scripts at scale?
A: Ansible provides consistent, parallel execution of potentially wrong changes across your entire fleet.
The dangers:
# Consistent blast radius
** Shell script on one host = one host affected
** Ansible playbook = hundreds of hosts simultaneously
** Mistakes replicated perfectly everywhere
# Idempotent repetition of wrong state
** "Idempotent" means it enforces state consistently
** Wrong state enforced consistently is still wrong
** Running again won't fix it, will reinforce it
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What's your experience with Ansible?]]
* [[What makes good Ansible?]]
* [[Idempotence is the core contract of Ansible modules]]
Q: Can you provide an example of a task you've automated to improve data center efficiency?
A: One example of a task automated for data center efficiency is the provisioning of virtual machines (VMs) based on demand. Using tools like Ansible or PowerShell, I created automation scripts that dynamically allocate and configure VMs in response to changing workloads. These scripts assess current resource utilization, determine the required capacity, and automatically spin up or down VMs accordingly. This ensures optimal resource allocation, reduces manual intervention, and improves scalability, contributing to overall data center efficiency.
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
* [[What kind of automation you wouldn't do with Ansible and why?]]
* [[Ansible performance optimization for large inventories]]
Q: How do you approach automating repetitive tasks in a data center?
A: Automating repetitive tasks in a data center involves the following steps: **Task Identification:* • Identify tasks that are repetitive and time-consuming but suitable for automation. **Tool Selection:* • Choose appropriate automation tools based on the task requirements. For server management, tools like Ansible, PowerShell, or configuration management tools may be suitable. **Scripting/Playbook Development:* • Develop scripts or playbooks that automate the identified tasks. Ensure they are well-documented and modular for scalability and maintenance.
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What kind of automation you wouldn't do with Ansible and why?]]
* [[What are idempotency issues in infrastructure automation and how are they avoided?]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
Q: Provide an example of a complex task or process you automated using scripting or automation tools.
A: In a previous role, I automated the deployment and configuration of a multi-tiered application stack using Ansible. **Steps Taken:* • • Infrastructure Provisioning: Wrote Ansible playbooks to automate the provisioning of virtual machines on different environments (development, testing, and production). • Software Installation: Automated the installation and configuration of various software components, including web servers, application servers, and databases, ensuring consistency across environments.
Remember: Ansible's strength is simplicity — YAML playbooks, agentless SSH, and idempotent modules. When you find yourself fighting Ansible, you're probably overcomplicating it.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-core.tsv</code></html>
''Related atoms''
* [[What kind of automation you wouldn't do with Ansible and why?]]
* [[Can you provide an example of a task you've automated to improve data center efficiency?]]
* [[Ansible Modules]]
Without <html><code>become: true</code></html>, a task runs as the SSH user, not root. Package installations and service restarts may fail silently or partially succeed — apt might report 'ok' while the package isn't installed, or files are created in the wrong location. Set <html><code>become: true</code></html> on individual tasks requiring elevated privileges, not at the play level (that runs everything as root). Use <html><code>become_user</code></html> and <html><code>become_method</code></html> for fine-grained control over which user and escalation method (sudo, su, doas) is used.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[What is the `become_method` setting and what values does it support?]]
* [[What is `become_user`?]]
A handler (like 'Restart application') executes only if the task that notified it reports a changed status. If you update a template but the rendered output is identical to what's on disk, Ansible reports 'ok' instead of 'changed', and the handler never fires. The service doesn't restart because it didn't need to — the config didn't actually change. If you need the handler to run regardless, use <html><code>meta: flush_handlers</code></html> to force execution, or call the restart directly with <html><code>changed_when: true</code></html> to unconditionally notify.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[Can a handler notify another handler?]]
* [[Ansible handlers skip entirely if the play fails]]
* [[Handlers run once at play end, triggered by task notifications]]
<html><code>import_tasks</code></html> uses static parsing — conditions are evaluated at parse time and applied to each task individually. If you <html><code>import_tasks setup.yml when: needs_setup</code></html> and setup.yml contains a task that sets <html><code>needs_setup = false</code></html>, that change doesn't affect the other tasks because the condition was already evaluated. <html><code>include_tasks</code></html> is dynamic — the condition is evaluated at runtime and applies to the entire include (all-or-nothing). Use <html><code>import_tasks</code></html> when the file always exists and you want per-task conditional logic. Use <html><code>include_tasks</code></html> when the filename is dynamic or you want all-or-nothing behavior. Test with <html><code>--check -vvv</code></html> to see which tasks get evaluated.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[What is the difference between `include_tasks` and `import_tasks`?]]
* [[Can you use `when` conditions with `import_tasks`?]]
* [[Can you loop over `import_tasks`?]]
By default, Jinja2 tags (<html><code>{% %}</code></html>) preserve their own newlines in template output. A loop over a list produces blank lines between entries because each <html><code>{% endfor %}</code></html> includes a trailing newline. For NGINX configs, Python, or YAML, extra whitespace breaks parsing. Use whitespace control markers: <html><code>{%-</code></html> strips whitespace before, <html><code>-%}</code></html> strips whitespace after. So <html><code>{%- for item in list %}...{%- endfor %}</code></html> eliminates blank lines. Test with <html><code>ansible localhost -m template -a "src=template.j2 dest=/dev/stdout"</code></html> to verify the rendered output before deployment.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[Ansible `template` module]]
* [[Jinja2 Expressions Must Be Quoted in YAML Values]]
Running <html><code>ansible-vault encrypt_string 'mypassword'</code></html> puts the plaintext password in <html><code>~/.bash_history</code></html> permanently. Anyone with shell access — or access to CI logs — can read it and decrypt all vaulted secrets. Storing the vault password in a plain-text file without restrictive permissions is equally dangerous.
Mitigations, in order of preference:
# ''Interactive prompt'' — use <html><code>--ask-vault-pass</code></html> or <html><code>--vault-id prod@prompt</code></html>. The password is not echoed and never logged to history.
# ''Vault password file with strict permissions'' — if automation requires a file, protect it with <html><code>chmod 600</code></html> so only the owning account can read it. Keep it outside the repo.
# ''Secrets manager integration'' — use 1Password, HashiCorp Vault, or AWS Secrets Manager to fetch the password at runtime. Nothing is stored locally in plain text.
# ''Pipe instead of inline'' — when scripting, prefer <html><code>echo -n 'secret' | ansible-vault encrypt_string</code></html> over passing the secret as a positional argument, to avoid shell expansion artifacts.
Never type secrets on the command line, never commit vault passwords to version control, and treat CI log output as potentially readable by anyone with repo access.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
* <html><code>training/library/topics/ansible/footguns.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[How do you manage secrets in Ansible?]]
YAML interprets <html><code>{</code></html> as the start of a mapping. Unquoted Jinja2 expressions like <html><code>message: {{ greeting }} world</code></html> cause cryptic parse errors ('mapping values are not allowed in this context') because the YAML parser tries to parse <html><code>{{</code></html> as a mapping key. Always quote values starting with <html><code>{{</code></html>: <html><code>message: "{{ greeting }} world"</code></html>. This applies to all variable substitutions, filters, and Jinja2 logic in YAML. The quotes tell the YAML parser to treat the content as a string first. Forgetting this quote is the single most common Ansible YAML syntax error.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[Why do you always use `{{ }}` in Ansible except in `when` clauses?]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
<html><code>serial: 1</code></html> updates one host at a time. With 100 hosts and a 3-minute play, total runtime is 5 hours. For rolling updates, <html><code>serial: 1</code></html> is overkill. Use graduated serial instead: run 1 host as a canary (catch obvious failures), then 10% of remaining, then 50%, then the rest. Combine with <html><code>max_fail_percentage: 10</code></html> to circuit-break. This balances safety (canary catches bad patches) with speed — a 100-host fleet might complete in 15–20 minutes instead of 5 hours.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
* [[Fleet diagnostics demand parallelism; forks multiply time]]
A network blip during a playbook run on a large fleet fails one task on one host, halting the entire play. With <html><code>serial</code></html>, this stops the rolling update. Configure retries at the SSH connection level in <html><code>ansible.cfg</code></html> (e.g., <html><code>retries = 3</code></html> under <html><code>[ssh_connection]</code></html>) and at the task level for flaky operations. Use <html><code>retries: 3</code></html>, <html><code>delay: 5</code></html>, and <html><code>until: result is succeeded</code></html> on tasks like downloads or API calls. Network blips are unavoidable at scale — expecting every task to succeed on first attempt is unrealistic.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[One slow host stalls the entire batch unless timeouts are aggressive]]
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
Ansible caches facts (disk layout, network interfaces, CPU count) in files to speed up subsequent runs. With <html><code>fact_caching = jsonfile</code></html> and <html><code>fact_caching_timeout = 86400</code></html> (one day), facts cached yesterday are replayed today. If someone added a disk to a server yesterday, cached facts still show the old layout. A playbook partitioning disks based on stale facts will fail or partition the wrong disk. Set a reasonable cache timeout and refresh facts when they matter. Use <html><code>gather_facts: false</code></html> then <html><code>ansible.builtin.setup:</code></html> as a task before critical decisions, or clear the cache before important runs with <html><code>rm -rf /tmp/ansible_facts/*</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[One slow host blocks the entire play during fact gathering]]
* [[Ansible Facts and the gather_facts task]]
* [[What is `fact_caching`, and what backends does it support?]]
Gathering facts (system information like network config, OS, CPU) on 500+ hosts is slow. Enable smart gathering with <html><code>gathering = smart</code></html> so Ansible only gathers facts if they're not cached. Choose a cache backend (<html><code>jsonfile</code></html>, <html><code>redis</code></html>, <html><code>memcached</code></html>) and set connection parameters and timeout (e.g., <html><code>fact_caching_timeout = 86400</code></html> for 24 hours). This dramatically accelerates repeated playbook runs against stable infrastructure, since Ansible reuses cached facts instead of re-querying every host.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Selective fact gathering skips unnecessary system queries]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[Optimizing Ansible Playbook Performance]]
Gathering facts (system information like <html><code>ansible_os_family</code></html>, <html><code>ansible_distribution_version</code></html>, IP addresses) on a 500-host fleet takes 5+ minutes per playbook run. Enable fact caching in ansible.cfg: set <html><code>gathering = smart</code></html> (only gather if cache is stale), <html><code>fact_caching = jsonfile</code></html>, and <html><code>fact_caching_connection = /tmp/ansible_facts_cache</code></html>. For shared caching across CI runners, use Redis: <html><code>fact_caching = redis</code></html> with <html><code>fact_caching_connection = redis://localhost:6379/0</code></html>. Set <html><code>fact_caching_timeout</code></html> to control cache staleness (86400 seconds = 24 hours is common). For one-off tasks that don't need facts, disable gathering with <html><code>gather_facts: no</code></html> at the play level.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
''Related atoms''
* [[Optimizing Ansible Playbook Performance]]
* [[What is `fact_caching`, and what backends does it support?]]
* [[Ansible performance optimization for large inventories]]
When you use <html><code>delegate_to</code></html> to run a task on a different host, the task executes on the delegated host but variables resolve from the original target host unless you explicitly reference the delegated host. This means <html><code>inventory_hostname</code></html> is the target host, <html><code>ansible_hostname</code></html> is the target's hostname, and accessing facts without qualification returns target facts. This is usually the intended behavior — collecting facts from the target and acting on a different host. The confusion arises when you need the delegated host's facts instead. Be explicit about which host's variables you're referencing, and use debugging output to confirm the execution context. When in doubt, print both the target and delegated context to understand what you're operating on.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[What does `delegate_to` do?]]
* [[What would be the result of the following play?]]
* [[Ansible facts: auto-discovered host variables]]
[[Ansible modules|Ansible Modules]] require Python on the target host, but fresh minimal OS installations often lack Python. Standard modules fail with "ansible requires a python interpreter on the target host". The solution is the <html><code>raw</code></html> module, which executes shell commands directly without Python, bypassing the interpreter requirement. Use raw to install Python before attempting standard modules. Set <html><code>gather_facts: false</code></html> initially (you can't gather facts without Python), then run the bootstrap, then execute <html><code>setup</code></html> to gather facts. This pattern is essential when deploying to immutable images, minimal container bases, or fresh server installations. After Python is installed, normal Ansible modules become available for the rest of the play.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
''Related atoms''
* [[What is the `raw` module, and when is it needed?]]
* [[What is `ansible_python_interpreter`?]]
* [[What Python class must every custom Ansible module import?]]
Inventory can be defined in INI or YAML format, but YAML provides better structure for complex environments. YAML inventory uses a hierarchical tree rooted at <html><code>all</code></html>, with groups as children and hosts under groups. Each host can have individual variables (e.g., <html><code>http_port</code></html>, <html><code>ansible_host</code></html>, <html><code>ansible_port</code></html>), and each group can define shared variables under <html><code>vars:</code></html>. Groups can have children (creating parent groups that aggregate multiple child groups), enabling multi-tier environments. Variables follow inheritance: hosts inherit variables from their groups, and variables closer to the host (host-level) override those farther away (group-level). This structure scales better than INI format and makes variable management explicit and predictable.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[Inventory is one layer in a larger variable precedence system]]
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
* [[Ansible: Managing Multiple Environments with Separate Inventories]]
Ansible supports organizing variables in parallel directories alongside the inventory file: <html><code>group_vars/</code></html> for group-specific variables and <html><code>host_vars/</code></html> for host-specific variables. Each file corresponds to a group or host name (e.g., <html><code>group_vars/webservers.yml</code></html>, <html><code>host_vars/web1.example.com.yml</code></html>). Within <html><code>group_vars/</code></html>, there is a special <html><code>all.yml</code></html> file for organization-wide variables. Variables in <html><code>host_vars/</code></html> override those in <html><code>group_vars/</code></html> for the same host, following the standard precedence hierarchy. This pattern separates variable definition from inventory structure, making it easier to view and modify variables without editing inventory files. It enables version control of variables independently from host definitions and supports a clean workflow where inventory contains structure and host_vars/group_vars contain configuration.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[Ansible variable design: where to put tunables]]
* [[How do you define variables in Ansible Playbooks?]]
* [[Ansible variable precedence footguns]]
A ''host'' is a target machine identified by hostname or IP, and can carry host-specific variables. A ''group'' is a named set of hosts that can nest hierarchically (parent-child relationships). Two implicit groups always exist: <html><code>all</code></html> (every host) and <html><code>ungrouped</code></html> (hosts not assigned to any explicit group). Variables are the configuration data attached to hosts and groups, auto-loaded from dedicated directories: <html><code>host_vars/</code></html> for per-host files and <html><code>group_vars/</code></html> for per-group files. ''Static inventory'' is a file (INI or YAML format) you maintain by hand; ''dynamic inventory'' is a script or plugin that queries an external source (AWS, GCP, Kubernetes, etc.) and returns machines and groups at runtime. Both are functionally equivalent from Ansible's perspective; the format is a matter of convenience and the source is a matter of freshness.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-inventory-targeting.md</code></html>
''Related atoms''
* [[What is a group in an Ansible inventory?]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
* [[Ansible inventory file: definition and configuration]]
Static host files don't scale for cloud infrastructure where instances are created and destroyed continuously. Dynamic inventory plugins query cloud provider APIs at runtime to return current infrastructure as Ansible inventory. Canonical plugins: <html><code>amazon.aws.aws_ec2</code></html>, <html><code>google.cloud.gcp_compute</code></html>, <html><code>azure.azcollection.azure_rm</code></html>.
Each plugin is configured via a YAML inventory file specifying credentials, regions or projects, filters, and <html><code>keyed_groups</code></html>. The AWS EC2 plugin filters by tags and regions, builds groups from environment tags and availability zones (e.g., <html><code>env_production</code></html>, <html><code>role_webserver</code></html>), and composes <html><code>ansible_host</code></html> from the instance's private IP. The GCP plugin filters by project and zone, builds groups from instance labels, and composes the host from network IPs. Azure follows the same pattern with its own label/tag model.
Inspect discovered topology with <html><code>ansible-inventory -i inventory/aws_ec2.yml --graph</code></html>; playbooks then target dynamic groups like <html><code>role_webserver</code></html> rather than hardcoded IPs. New instances appear in groups immediately; destroyed instances disappear automatically — no manual host list maintenance required.
Trade-off: API discovery adds latency to playbook startup. For frequently-run playbooks, cache the inventory output to avoid repeated API calls. Dynamic inventory is essential for auto-scaling environments where instance counts change on every deploy.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Ansible Dynamic Inventory]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
Ansible resolves variables through 22 precedence levels, from role defaults (lowest) to extra vars (highest). Memorizing all 22 is unnecessary; focus on the key ones: role defaults (defaults/main.yml) are lowest and meant to be overridden; role vars (vars/main.yml) are high precedence and hard to override; extra vars from the command line (-e) always win and override everything. In practice: put sensible defaults in role defaults that users can override, store role-specific hard-coded values in role vars, organize shared settings in group_vars/all.yml or environment-specific groups, and reserve extra vars for one-time overrides or ad-hoc customization. When debugging why a variable has an unexpected value, use <html><code>ansible -m debug -a "var=varname"</code></html> against a host to see the resolved value and identify which precedence level is winning.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[How many levels of variable precedence does Ansible have?]]
* [[What is the difference between role defaults and role vars in terms of precedence?]]
* [[What makes good Ansible?]]
Ansible resolves variables by precedence when multiple definitions exist. The hierarchy, from lowest to highest: role defaults (defaults/main.yml), inventory variables (group and host vars), playbook-level vars, task-level vars, and finally command-line extra vars (-e flag) which always win. This precedence enables flexible composition: set sensible defaults in the role, override at inventory for environment-specific values, override at playbook for ad-hoc changes, and use -e for one-off interventions without editing files. Understanding precedence prevents subtle bugs where a variable binding is silently overridden. The rule: tighter scope wins. A task var beats an inventory var; a command-line var beats everything.
----
''Sources''
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
''Related atoms''
* [[List all 22 variable precedence levels from lowest to highest.]]
* [[Directory-based variable organization separates variables from inventory]]
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
Ansible has approximately 22 variable precedence levels, but you only need to understand the bookends: role defaults (lowest priority) lose, and extra vars passed via the <html><code>-e</code></html> flag (highest priority) always win. Everything else falls in between in a predictable gradient from general to specific.
This simplification is powerful because the full 22-level list is largely edge cases — include_vars, vars_prompt, vars_files, and various include/import scenarios each occupy their own slot, but rarely matter in practice. Understanding the bookends and the general-to-specific gradient is enough to predict variable resolution in almost every real playbook.
The key insight is that Ansible's designers intended precedence to flow from general (role defaults, anyone can override) through specific (play vars, task vars) to ultimate (extra vars, no escape). This ordering makes it possible to write predictable, reusable roles and playbooks.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-variable-precedence.md</code></html>
''Related atoms''
* [[How many levels of variable precedence does Ansible have?]]
* [[How do you define variables in Ansible Playbooks?]]
* [[Inventory is one layer in a larger variable precedence system]]
The ~22 total Ansible precedence levels are rarely all relevant. These eight account for almost every real situation, ordered from lowest to highest priority:
# Role defaults (<html><code>roles/x/defaults/main.yml</code></html>) — lowest
# Inventory <html><code>group_vars/</code></html>
# Inventory <html><code>host_vars/</code></html>
# Play <html><code>vars:</code></html>
# Role <html><code>vars/</code></html> (<html><code>roles/x/vars/main.yml</code></html>)
# Task <html><code>vars:</code></html>
# <html><code>set_fact</code></html> / <html><code>register</code></html>
# Extra vars (<html><code>-e</code></html>) — highest, always wins
The full list includes slots for include_vars, vars_prompt, vars_files, and various include/import scenarios. But normal playbooks use only these eight. The ordering reflects design intent: role defaults are safe fallbacks anyone can override; role vars are internal constants (high priority, hard to override on purpose); extra vars are the CLI emergency hatch that bypasses everything else. When variables resolve unexpectedly, trace them through this list to find the source.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-variable-precedence.md</code></html>
''Related atoms''
* [[How do you define variables in Ansible Playbooks?]]
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[Ansible variable precedence silently shadows lower-priority settings]]
The simplified mental model for variable precedence is: role defaults < inventory vars < play/role vars < extra vars. This ordering reflects design intent, which should drive where you place variables.
Role <html><code>defaults/main.yml</code></html> holds user-tunable parameters — safe fallbacks that anyone can override from inventory (group_vars/, host_vars/) or the command line. Make it easy for users to find what they can tweak.
Role <html><code>vars/main.yml</code></html> contains internal constants that the role needs — private implementation details. By sitting near the top of precedence, role vars are intentionally hard to override from outside, so the role's internals don't get accidentally shadowed.
Extra vars (<html><code>-e nginx_port=443</code></html>) are the CLI emergency hatch — they override everything. Use them for one-off overrides and debugging, not for normal configuration.
The pattern: put anything a user might want to adjust in defaults/. Put private implementation constants in vars/. Document which variables are meant for tuning. Let users override via inventory group_vars/host_vars or the -e flag, not by hunting through role internals.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-variable-precedence.md</code></html>
''Related atoms''
* [[Directory-based variable organization separates variables from inventory]]
* [[Roles organize reusable Ansible code into directories]]
* [[What is the difference between role defaults and role vars in terms of precedence?]]
The most damaging mistake is placing user-tunable values in <html><code>roles/x/vars/main.yml</code></html> instead of <html><code>roles/x/defaults/main.yml</code></html>. Role vars sit high in precedence, making them nearly impossible for users to override from inventory — defeating the purpose of parameterization. Put anything users might want to tweak in defaults, not vars.
Setting the same variable in multiple places (defaults, group_vars, play vars, extra vars) without knowing which wins leads to mysterious value changes and long debugging sessions. Use <html><code>ansible-playbook -e "myvar=value" -vvv</code></html> to inspect the final resolved value and trace its origin.
Forgetting that <html><code>set_fact</code></html> and <html><code>register</code></html> override almost everything except extra vars surprises people. If you set a variable in group_vars but a task runs <html><code>set_fact</code></html> on the same name, the fact's value wins — the task-level operation overrides the inventory-level declaration.
Assuming inventory <html><code>group_vars/</code></html> beats play <html><code>vars:</code></html> is backwards. Play vars override inventory vars. If you set a value in both places and the play var wins but you expected inventory to dominate, check the precedence list — this ordering is counterintuitive but intentional.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-variable-precedence.md</code></html>
''Related atoms''
* [[The variable 'whoami' defined in the following places:]]
* [[Directory-based variable organization separates variables from inventory]]
* [[Inventory is one layer in a larger variable precedence system]]
A playbook is a list of plays, each targeting a host group. Within a play, execution order is: pre_tasks, roles, tasks, post_tasks, followed by handlers at the end of each section. Handlers are a mechanism to run tasks once even if notified multiple times — if multiple config changes trigger "Restart service", the handler runs only once. Imports and includes differ in resolution timing: <html><code>import_tasks</code></html> is static (parsed at playbook load time), and conditions/tags apply to each task inside the imported file independently; <html><code>include_tasks</code></html> is dynamic (parsed at runtime), and conditions/tags apply to the include itself (all-or-nothing). Use import when the file is always the same and you want granular control over each task. Use include when the filename is dynamic or you need to conditionally include the entire file. Imports cannot use loops, but includes can run the entire file once per loop iteration.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[How do you include external tasks in an Ansible Playbook?]]
* [[Ansible playbook architecture: plays, tasks, roles]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
Q: What is the difference between <html><code>include_tasks</code></html> and <html><code>import_tasks</code></html>?
A: <html><code>import_tasks</code></html> is static -- processed at playbook parse time, so variables in filenames must be static. <html><code>include_tasks</code></html> is dynamic -- processed at runtime, supporting dynamic filenames, loops, and conditionals. Tags and task attributes behave differently between them.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
* [[How do you include external tasks in an Ansible Playbook?]]
* [[What is `include_role` vs `import_role`?]]
Filters are Jinja2 functions that transform a value or manipulate data during template rendering. Common filters include: <html><code>default('fallback')</code></html> to provide a fallback value if undefined; <html><code>to_json</code></html>, <html><code>to_nice_json</code></html>, <html><code>to_yaml</code></html>, and <html><code>to_nice_yaml</code></html> to serialize data structures; <html><code>regex_replace</code></html> for string manipulation; <html><code>upper</code></html>, <html><code>lower</code></html> for case conversion; <html><code>join(', ')</code></html> to concatenate list elements; <html><code>unique</code></html> to deduplicate; <html><code>flatten</code></html> to un-nest lists; <html><code>select</code></html> and <html><code>map</code></html> for functional operations over lists; <html><code>combine</code></html> to merge dictionaries (with <html><code>recursive=True</code></html> for deep merges); <html><code>password_hash</code></html> to generate secure passwords; <html><code>b64encode</code></html> and <html><code>b64decode</code></html> for base64 encoding; and path filters like <html><code>basename</code></html> and <html><code>dirname</code></html>. Filters can be chained: <html><code>{{ value | default('x') | upper }}</code></html>. In Ansible, filters are implemented as filter plugins and run on the control node during template rendering, not on the target, making them suitable for computations that do not depend on target state.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[How do you create a custom Jinja2 filter for Ansible?]]
Tests are Jinja2 boolean functions used in <html><code>when</code></html> clauses and conditional expressions to make task execution conditional. Common tests include: <html><code>is defined</code></html> (variable exists), <html><code>is match(regex)</code></html> (string matches regex), <html><code>is file</code></html> or <html><code>is directory</code></html> (path types), <html><code>is changed</code></html> or <html><code>is succeeded</code></html> (result status from registered variables), <html><code>is version</code></html> (semantic version comparison). Tests appear in the same template context as filters but serve a different purpose: filters transform values, tests check conditions. A task with <html><code>when: my_var is defined</code></html> runs only if the variable is defined; <html><code>when: inventory_hostname is match("web.*")</code></html> runs if the hostname matches a pattern. Tests are essential for conditional logic in playbooks and enable branching based on host facts, previous task results, or variable presence.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[What are Ansible test plugins?]]
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
Lookups are Jinja2 functions that read data from sources on the control node into playbook variables. Common lookups include: <html><code>file</code></html> to read a file, <html><code>env</code></html> to read environment variables, <html><code>hashi_vault</code></html> to fetch secrets from HashiCorp Vault, <html><code>amazon.aws.aws_ssm</code></html> to read AWS Parameter Store values, <html><code>password</code></html> to generate random passwords, <html><code>csvfile</code></html> to read CSV data, and <html><code>lines</code></html> to split file content into a list. Lookups run on the control node during playbook evaluation, not on the target, making them suitable for reading configuration, secrets, and external data. Unlike filters (which transform a value) or tests (which check a condition), lookups fetch data that didn't exist before. They're commonly used to load secrets from vaults, read dynamic inventory data, or generate one-time passwords during playbook execution.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[What is a lookup plugin in Ansible?]]
* [[Name ten commonly used lookup plugins.]]
* [[What is the difference between a lookup and a filter?]]
Collections bundle Ansible content (roles, modules, plugins) into distributable packages published on Ansible Galaxy or in private repositories. They're installed with <html><code>ansible-galaxy collection install</code></html> and referenced by fully-qualified collection name (FQCN) in playbooks: <html><code>amazon.aws.s3_bucket</code></html> refers to the <html><code>s3_bucket</code></html> module in the <html><code>amazon.aws</code></html> collection. Using FQCNs is recommended because they're unambiguous — if two collections provide a module with the same name, the short name is ambiguous. Collections are versioned, so <html><code>requirements.yml</code></html> can pin versions for reproducible playbooks. Installing collections with <html><code>ansible-galaxy collection install -r requirements.yml</code></html> ensures all team members use the same versions, similar to Python <html><code>requirements.txt</code></html>. This pattern enables managing Ansible content as dependencies with clear versioning.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[Ansible Collections: packaging and distribution format]]
* [[What is `collections` keyword in a playbook?]]
Modules run on target machines and enforce idempotent desired state. Plugins run on the controller machine and extend Ansible's capabilities (lookup plugins retrieve data, filters transform data, callbacks react to events, connection plugins define how to reach targets). Collections are the distribution unit: a namespace-scoped package bundling related modules, plugins, roles, and documentation together with semantic versioning. When a module is imported, its fully qualified collection name (FQCN) is visible in plays—for example, <html><code>amazon.aws.ec2_instance</code></html> indicates the module lives in the <html><code>amazon.aws</code></html> collection. This namespacing allows collections to coexist without name collisions and to be versioned and distributed independently.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-idempotence-modules-plugins.md</code></html>
''Related atoms''
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[Modules execute on targets; plugins run on the controller and extend Ansible]]
* [[Why Use Ansible Collections?]]
Vault is Ansible's built-in encryption system, using AES-256-CTR to encrypt files or individual string values so secrets can safely live in version control. Core operations: <html><code>encrypt</code></html> and <html><code>decrypt</code></html> act on whole files; <html><code>edit</code></html> decrypts, opens an editor, and re-encrypts in place; <html><code>view</code></html> shows plaintext without writing it; <html><code>encrypt_string</code></html> produces an inline-encrypted variable for embedding in YAML. Playbooks consume encrypted data transparently — Ansible decrypts at runtime when given the vault password via <html><code>--ask-vault-pass</code></html> (interactive prompt), <html><code>--vault-password-file</code></html> (path to a file), or the <html><code>ANSIBLE_VAULT_PASSWORD_FILE</code></html> environment variable / <html><code>vault_password_file</code></html> key in <html><code>ansible.cfg</code></html>. For local development, store the password in <html><code>~/.vault_pass.txt</code></html> (mode 600). For CI/CD (GitHub Actions, GitLab CI, etc.), inject the password as a platform secret, write it to a temporary file at runtime, use it, then delete it immediately. Multiple vault IDs let different teams hold different secrets within the same repo: encrypt with <html><code>--vault-id dev@prompt</code></html> or <html><code>--vault-id prod@/path/to/file</code></html>; supply all needed IDs at playbook runtime. Organize vault-encrypted variables in dedicated files (e.g., <html><code>group_vars/production/vault.yml</code></html>) referenced from plaintext variable files, so variable names remain searchable without decrypting. Tradeoffs: the password file itself must be protected and is a single point of failure; rotation is manual. Vault passwords should never be committed to version control, should be rotated periodically, and access should be restricted like database credentials. Vault is appropriate for playbooks checked into internal repos.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[How do you decrypt a file?]]
* [[What encryption algorithm does Ansible Vault use?]]
* [[A playbook fails to decrypt Vault data. What do you check?]]
By default, Ansible uses SSH to connect to remote hosts, but different target types require different connection methods. SSH (the default) connects to Linux/Unix systems. Local runs tasks on the control node itself without SSH. WinRM connects to Windows hosts using the Windows Remote Management protocol. Docker connects to running containers. Network-device plugins (like network_cli) connect to switches and routers using proprietary protocols. Each connection plugin is specified with <html><code>connection:</code></html> at the play or task level, and many require additional variables for configuration (like <html><code>ansible_winrm_transport: ntlm</code></html> for Windows NTLM authentication). Understanding which connection plugin to use is essential for managing heterogeneous infrastructure — a playbook might use SSH for Linux servers, WinRM for Windows, and Docker for container tasks.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[When would you use the `local` connection plugin?]]
* [[Name all the major connection plugin types in Ansible.]]
* [[Ansible manages Windows servers via WinRM]]
The <html><code>become</code></html> directive runs a task with elevated privileges, typically to run as root or a service user. Set <html><code>become: true</code></html> and optionally <html><code>become_user: username</code></html> to escalate at the play level (affecting all tasks) or task level (for individual tasks). The default <html><code>become_method</code></html> is <html><code>sudo</code></html>, but other methods exist: <html><code>su</code></html> (su - command), <html><code>pbrun</code></html> (PowerBroker), <html><code>doas</code></html> (BSD doas), and <html><code>machinectl</code></html> (systemd containers). Windows uses <html><code>runas</code></html>. Become works in conjunction with SSH key-based authentication and sudo configuration — the target must allow the user to become the target user (usually via sudoers). A common pattern: run the play with <html><code>become: true become_user: root</code></html> for most tasks, then override individual tasks with <html><code>become: false</code></html> for operations that must run as the SSH user or <html><code>become_user: appuser</code></html> to run as a service user.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[What are Ansible's default privilege escalation methods?]]
* [[What is the `become_method` setting and what values does it support?]]
The <html><code>block:</code></html> directive groups tasks into a logical unit. If any task in the block fails, execution jumps to the <html><code>rescue:</code></html> section, enabling error recovery (analogous to catch). The <html><code>always:</code></html> section executes regardless of whether the block succeeded or failed, making it suitable for cleanup such as removing temporary files (analogous to finally). Together, block/rescue/always implement try-catch-finally semantics in Ansible playbooks.
Each section can contain multiple tasks. Rescue tasks can access error information through registered variables. This pattern is more powerful than <html><code>failed_when</code></html> alone because it allows multi-step recovery logic — for example, a block that deploys new code and verifies health, a rescue that rolls back to the previous version and sends an alert, and an always section that cleans up temporary files regardless of outcome.
Blocks can be nested; if a rescue section itself fails, the outer block's rescue is triggered, enabling error chains and complex failure hierarchies.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[What is the difference between `ignore_errors: true` and using a `rescue` block?]]
* [[Customize task failure and change status with failed_when and changed_when]]
* [[What does `ignore_errors: true` do?]]
By default, Ansible considers a task failed if the command's exit code is non-zero. Override this with <html><code>failed_when: condition</code></html> to specify what actually constitutes failure. For example, <html><code>systemctl status</code></html> returns exit code 3 if the service is inactive — this isn't a failure, so set <html><code>failed_when: rc not in [0, 3, 4]</code></html> to treat these codes as non-failure. Similarly, <html><code>changed_when: condition</code></html> controls whether a task reports as "changed"; many commands report changed even if they don't change anything. Use <html><code>changed_when: false</code></html> for read-only commands that should never report changed. <html><code>ignore_errors: true</code></html> catches any error and continues, allowing conditional logic downstream (e.g., <html><code>when: previous_task is succeeded</code></html>). These customizations are necessary because shell commands often report status in non-standard ways — the exit code doesn't always reflect whether the task changed anything.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
* [[Check mode simulates changes without executing destructive operations]]
The <html><code>delegate_to:</code></html> directive runs a task on a different host than the play target, useful for coordinating across hosts. For example, <html><code>delegate_to: loadbalancer.example.com</code></html> runs the task on the load balancer (to remove the current host from the pool) while facts and variables refer to the original target. <html><code>delegate_to: localhost</code></html> runs on the control node, useful for local operations like adding DNS records or sending notifications. <html><code>run_once: true</code></html> runs the task only once for the whole play, not per host — use this for operations that should happen once per deployment, not per server. A common pattern: deploy code to all servers (on each server), then run a health check on localhost (run_once), then send a notification (run_once, delegate_to: localhost). Delegation is more powerful than simply running a task on localhost because it combines target-host context with execution on a different host.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[What does `delegate_to` do?]]
* [[What is the `local_action` keyword?]]
* [[What is the "two-stage" or "delegate and register" pattern?]]
Long-running operations can exceed SSH session timeouts or block other work. Ansible's <html><code>async</code></html> and <html><code>poll</code></html> parameters separate task submission from result collection. Set <html><code>async</code></html> to the maximum expected runtime in seconds; <html><code>poll: 0</code></html> fires the task and returns immediately without waiting. Store the job ID from the result using <html><code>register</code></html>, then check status with <html><code>async_status</code></html>, polling until <html><code>finished</code></html> is true.
This pattern lets playbooks do other work while a slow operation runs in the background — for example, start package upgrades on 100 hosts with <html><code>poll: 0</code></html>, perform other tasks (start services, gather facts, run unrelated plays), then loop with <html><code>async_status</code></html> and a conditional retry to wait for each host to finish. Common use cases: package upgrades, builds, database migrations, backups, and data operations.
Only use <html><code>async</code></html> when parallelism is genuinely needed. Synchronous tasks are simpler and easier to debug.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Optimizing Ansible Playbook Performance]]
* [[What does the `async` keyword do?]]
* [[One slow host blocks the entire play during fact gathering]]
Ansible strategy plugins determine how tasks are scheduled across inventory hosts during a play. Three built-in strategies cover the main use cases.
''Linear'' (default): each task runs on all hosts before the play advances to the next task. Execution is predictable and output is easy to read, making it the right choice for complex orchestration and first-time users.
''Free'': each host races through all tasks to the end of the play as fast as it can, without waiting for other hosts to finish the current task. This maximises throughput when hosts have uneven responsiveness, but produces interleaved output that is harder to read. Set with <html><code>strategy: free</code></html> at the play level.
''Debug'': tasks run interactively; on failure Ansible pauses and opens a built-in debugger, letting operators inspect variables and step through execution. Useful for diagnosing failures in production plays without rewriting them.
Strategy choice is a performance-versus-readability tradeoff. Linear is safer and more legible; free is faster when host speeds vary and scrambled output is acceptable; debug is a diagnostic tool, not a production execution strategy.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Optimizing Ansible Playbook Performance]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
Ansible's <html><code>--check</code></html> flag performs a dry run: tasks that would read state execute normally, but state-modifying tasks skip or report what would change (with <html><code>--diff</code></html> flag). Not all modules support check mode; <html><code>command</code></html> and <html><code>shell</code></html> are always skipped in check mode since they're inherently side-effect-prone. Override per-task with <html><code>check_mode: false</code></html> to force execution even during a dry run (useful for gathering live state), or <html><code>check_mode: true</code></html> to force skip (useful for reporting-only tasks). Check mode is essential before production deployments — run your playbook with <html><code>--check --diff</code></html> to see the full manifest of intended changes and catch mistakes (like parameter typos that force resource replacement) before applying.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
''Related atoms''
* [[How do you test Ansible safely?]]
* [[What information is available in the output when using the --check option?]]
* [[Idempotence is the core contract of Ansible modules]]
Q: Explain how to use the --check option for running Ansible in check mode.
A: The --check option runs Ansible in check mode, simulating playbook execution without making changes. It's used to preview potential changes and identify issues without impacting the target systems.
Example: ansible-playbook site.yml --check --diff shows what WOULD change without actually changing anything. Perfect for pre-deployment review.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you test Ansible safely?]]
* [[Explain the purpose of the --diff option in Ansible playbooks.]]
* [[How do you check a playbook's syntax without running it?]]
The <html><code>command:</code></html> and <html><code>shell:</code></html> modules are not idempotent—they run every time a playbook executes, regardless of system state. Experienced operators avoid them in favor of native, idempotent modules (<html><code>apt</code></html>, <html><code>service</code></html>, <html><code>lineinfile</code></html>, etc.). When <html><code>command:</code></html> or <html><code>shell:</code></html> are unavoidable, guard them with <html><code>creates:</code></html> (only run if file doesn't exist), <html><code>removes:</code></html> (only run if file exists), or <html><code>when:</code></html> conditions tied to system state. Check mode (<html><code>--check</code></html>) doesn't work reliably with raw command tasks, so design playbooks to be check-mode compatible. Always test idempotency by running the same playbook twice and verifying the second run reports 0 changed.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
''Related atoms''
* [[What information is available in the output when using the --check option?]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[Why is shell in Ansible dangerous?]]
Q: What does <html><code>ansible_check_mode</code></html> contain?
A: A boolean (True/False) indicating whether the current playbook run is in check mode (--check). Useful for conditionally skipping tasks that don't support check mode.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 8 source atoms.//
''Related atoms''
* [[What is `ansible-galaxy collection verify`?]]
* [[How do you test Ansible safely?]]
* [[How do you check a playbook's syntax without running it?]]
Q: How can you detect check mode inside a playbook?
A: Use the <html><code>ansible_check_mode</code></html> magic variable: <html><code>when: not ansible_check_mode</code></html> to skip a task in check mode.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `check_mode: true` at the task level?]]
* [[How do you check a playbook's syntax without running it?]]
* [[What is `supports_check_mode` in module development?]]
Ansible provides layered debugging tools for different investigation depths.
''Verbosity flags'': <html><code>-v</code></html> shows task results; <html><code>-vv</code></html> adds task input parameters (useful for inspecting variable values); <html><code>-vvv</code></html> surfaces SSH connection details; <html><code>-vvvv</code></html> exposes the full connection plugin protocol.
''Mode flags'': <html><code>--check --diff</code></html> runs a safe dry-run with visible change diffs. <html><code>--syntax-check</code></html> validates YAML without connecting to hosts. <html><code>--step</code></html> pauses before each task for interactive confirmation. <html><code>--start-at-task</code></html> skips directly to a named task (useful in large playbooks). <html><code>--list-tasks</code></html> enumerates all tasks without executing. <html><code>--list-hosts</code></html> shows the resolved target inventory. <html><code>--limit</code></html> restricts execution to a host subset.
''Register'': Capture task output with <html><code>register: result</code></html>. The result object contains <html><code>stdout</code></html>, <html><code>stderr</code></html>, <html><code>stdout_lines</code></html>, <html><code>stderr_lines</code></html>, <html><code>rc</code></html> (return code), <html><code>changed</code></html>, <html><code>failed</code></html>, <html><code>skipped</code></html>, and module-specific keys. Register is read-only and has no side effects, so captured output can be inspected or used in conditionals safely.
''Debug module'': Print entire objects with <html><code>var: result</code></html>, or extract specific fields with <html><code>msg: "{{ result.stdout }}"</code></html>). Common patterns include dumping all facts, inspecting variable types, and alerting on conditions (low memory, failed services).
''Ad-hoc inspection'': <html><code>ansible <host> -m debug -a "var=hostvars[inventory_hostname]"</code></html> inspects host variables without a playbook. Ad-hoc shell commands (<html><code>ansible webservers -m shell -a "df -h"</code></html>) enable quick checks. System logs provide additional context when task output is insufficient.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Ansible debug module: printing messages during playbook execution]]
* [[Explain the use of the -vvv option when running Ansible commands.]]
* [[Ansible strategy plugins control task-execution ordering across hosts]]
Ansible playbooks benefit from three tiers of testing. Linting with <html><code>ansible-lint</code></html> catches style violations and real problems — unused variables, missing task names, files without explicit mode, shell calls instead of modules, command tasks without <html><code>changed_when</code></html>. Run it on roles and playbooks before committing. Role integration testing with Molecule automates full lifecycle testing: create containers, run the role, verify the outcome, destroy containers. Molecule defines platforms (OS versions), provisioner (Ansible), and verifier (Ansible assertions), and sequences them (<html><code>molecule test</code></html>, <html><code>molecule converge</code></html> for development, <html><code>molecule login</code></html> to SSH in mid-test). Idempotency validation ensures running a playbook twice produces the same result — critical for operational safety. Use check mode twice: if the second run shows no changes, the playbook is idempotent. All three layers catch different failure modes: lint finds mistakes, Molecule validates the role works end-to-end, idempotency ensures safety under re-run.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
''Related atoms''
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[How do you test playbooks?]]
* [[What makes good Ansible?]]
John Googin created Molecule in 2015 to solve the problem of testing Ansible roles in isolation. Before Molecule, testing a role meant running it against a manually provisioned test server or VM—slow, error-prone, and hard to iterate on. Molecule abstracts away environment provisioning (Docker, Vagrant, cloud instances) and provides a test framework, letting developers write and run tests against a clean environment on each iteration. This unlocked test-driven Ansible development and is now the standard for role validation.
----
''Sources''
* <html><code>training/library/topics/infra-testing/trivia.md</code></html>
''Related atoms''
* [[What verifiers does Molecule support?]]
* [[How do you test Ansible safely?]]
* [[What drivers does Molecule support for creating test instances?]]
Large deployments cannot update all hosts at once without downtime. The <html><code>serial</code></html> parameter batches task execution: <html><code>serial: 2</code></html> updates 2 hosts at a time, <html><code>serial: 25%</code></html> updates 25% per batch, or a list (<html><code>[1, 5, "25%"]</code></html>) for progressive batches (e.g., canary 1, then 5, then the rest). Pair <html><code>serial</code></html> with pre-tasks and post-tasks to manage state around each batch: pre-task removes the host from the load balancer, tasks do the actual update (stop app, deploy code, start app, wait for health check), post-task re-adds to load balancer. The <html><code>max_fail_percentage</code></html> parameter aborts the entire roll if too many batches fail. Handlers fire within each batch and can trigger mid-update (e.g., restart service). This pattern ensures that at any moment, at least some hosts are serving traffic — partial availability is better than zero availability during a long update window. Test rolling updates in staging before production; verify your health checks catch both ready and not-ready states.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
''Related atoms''
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[Serial Batching and Max-Failure Limit Contain Rollout Risk]]
Playbooks targeting multiple OS families (Debian/Ubuntu vs RHEL/Rocky) need conditional logic. Use <html><code>ansible_os_family</code></html> fact to branch: use <html><code>apt</code></html> module for Debian, <html><code>dnf</code></html> for RedHat, or the generic <html><code>package</code></html> module (less control but simpler). Include OS-specific variable files at runtime with <html><code>include_vars</code></html>, pointing to a file named after the OS family (e.g., <html><code>vars/debian.yml</code></html>, <html><code>vars/redhat.yml</code></html>). This lets each OS define its own package list, service names, and other platform-specific settings. The generic <html><code>package</code></html> module handles most common tasks but doesn't support all module options; conditional <html><code>apt</code></html>/<html><code>dnf</code></html> tasks offer full control at the cost of extra branching. Test on each target OS; Molecule with multiple platforms (ubuntu-noble, rocky-9) catches OS-specific failures automatically. Cross-platform provisioning is unavoidable in heterogeneous infrastructure; good OS abstraction keeps playbooks readable and maintainable.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
''Related atoms''
* [[Audit mixed-distro fleets with Ansible to identify configuration drift]]
* [[Use purpose-built modules over shell; adopt FQCNs to avoid collisions]]
A task is idempotent if running it twice produces the same outcome as running it once — no unexpected side effects on the second run. Prefer built-in modules (<html><code>hostname</code></html>, <html><code>apt</code></html>, <html><code>systemd</code></html>) which are idempotent by design: they check current state, change only what's needed, report <html><code>changed: true</code></html> only when something actually changed. When you must use <html><code>command</code></html> or <html><code>shell</code></html> (which always execute), make them idempotent by adding a <html><code>changed_when</code></html> predicate: first register the current state (<html><code>command: hostname; changed_when: false</code></html>), then conditionally apply the change (<html><code>command: ... when: current_hostname.stdout != desired_hostname</code></html>). This way the task runs every time but only reports <html><code>changed</code></html> when state actually differs. Idempotency is non-negotiable for operational playbooks — a task that always reports <html><code>changed</code></html> is a signal that it's unsafe to re-run, which breaks the main promise of Ansible: safe, repeatable state management. Molecule's <html><code>idempotence</code></html> test verifies this by running the role twice and failing if the second run shows changes.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
''Related atoms''
* [[Customize task failure and change status with failed_when and changed_when]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
SSH pipelining reduces the number of SSH connections per Ansible task by sending the module code and execution instructions in a single SSH session rather than multiple steps (copy module, execute, clean up). Enable with <html><code>pipelining = True</code></html> in the <html><code>[ssh_connection]</code></html> section of <html><code>ansible.cfg</code></html>. The one requirement is that <html><code>requiretty</code></html> must be disabled in the target's sudoers file — uncommon on modern distributions and a one-line change when needed. No code modifications are required, making pipelining one of the easiest performance wins for large deployments.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible performance optimization for large inventories]]
* [[Forks control Ansible parallelism]]
* [[What open-source tool can dramatically speed up Ansible by replacing SSH with a custom …]]
By default, Ansible runs with 5 parallel forks (concurrent task execution threads). Increase this for large inventories to parallelize work across more hosts simultaneously. Set <html><code>forks = 30</code></html> or higher in the <html><code>[defaults]</code></html> section of ansible.cfg, or override at runtime with <html><code>--forks</code></html>. The trade-off is higher resource consumption on the control node — more forks means more memory, file descriptors, and active SSH connections. Tune based on your control node's resources and network capacity.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
''Related atoms''
* [[Explain the Difference between Forks and Serial & Throttle.]]
* [[Optimizing Ansible Playbook Performance]]
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
At scale (20+ hosts), SSH connection overhead becomes a bottleneck. Enable two settings in ansible.cfg: <html><code>pipelining = True</code></html> and <html><code>ssh_args = -o ControlMaster=auto -o ControlPersist=60s</code></html>. Pipelining sends module code and execution commands in a single SSH session instead of multiple round trips per task. ControlPersist reuses SSH connections, avoiding repeated authentication. Together they often provide 2-7x speedup for multi-host deployments. Additionally, tune <html><code>forks</code></html> (default 5) to the number of parallel connections your control node can sustain—<html><code>-f 50</code></html> is often safe for typical infrastructure.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
* [[Fleet diagnostics demand parallelism; forks multiply time]]
* [[What other connection optimizations exist beyond Mitogen?]]
Setting <html><code>forks = 200</code></html> and targeting 1,500 hosts exhausts the control node's memory and SSH connection table. Half the tasks fail with cryptic connection errors. The fix is to keep forks reasonable — 50–100 depending on control node resources — and batch large fleets by group. For example, run <html><code>ansible -f 50</code></html> on dc1-web, then dc1-db, etc., in parallel subprocess jobs. The bottleneck is not Ansible itself but the control node's file descriptor limit and memory. <html><code>ulimit -n</code></html> on the control node determines the upper bound on concurrent connections. Know your control node's limits before scaling.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/street_ops.md</code></html>
''Related atoms''
* [[Ansible performance optimization for large inventories]]
* [[One slow host stalls the entire batch unless timeouts are aggressive]]
* [[Fleet diagnostics demand parallelism; forks multiply time]]
If your playbook doesn't need facts, disable gathering entirely with <html><code>gather_facts: false</code></html> at the play level. If you need only specific facts (network, hardware), use the <html><code>setup</code></html> module with <html><code>gather_subset: [network, hardware]</code></html> to fetch only what you need. This is faster than gathering all facts and reduces load on target hosts. Common subsets include network, hardware, virtual, and osfacts depending on what your tasks consume.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
''Related atoms''
* [[Fact caching avoids expensive repeated gathering]]
* [[What does the `gather_facts: false` optimization do?]]
* [[What is `gather_subset` and how does it speed up fact gathering?]]
Mitogen is a third-party strategy plugin that replaces Ansible's default SSH-based execution model — which uploads a Python script per task via SSH, executes it, then deletes it — with a persistent Python interpreter on each target that receives streamed bytecode. This eliminates per-task SSH connection overhead and temporary file creation. Benchmarks show 2-7x speedup on large fleets depending on network latency and task count; large-scale operators such as Netflix adopted it for fleet automation where task count per host reaches thousands.
Enable it by setting <html><code>strategy_plugins</code></html> and <html><code>strategy = mitogen_linear</code></html> in <html><code>ansible.cfg</code></html>. Trade-offs include additional control-node memory usage (one persistent connection per target) and slightly higher startup latency, making it best suited to scenarios with many serial tasks per host rather than large parallel operations across few tasks. Mitogen is not maintained by Ansible upstream and may not support all connection plugins or newer Ansible features. Test thoroughly in staging before deploying to production.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Mitogen for Ansible?]]
* [[What other connection optimizations exist beyond Mitogen?]]
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
Ansible inventory patterns let you select hosts using set algebra: AND with <html><code>:&</code></html> (e.g., <html><code>webservers:&production</code></html> selects hosts in both groups), OR with <html><code>:</code></html> (e.g., <html><code>webservers:dbservers</code></html>), NOT with <html><code>:!</code></html> (e.g., <html><code>webservers:!maintenance</code></html> excludes), and regex with <html><code>~</code></html> (e.g., <html><code>~web[0-9]+\.example\.com</code></html>). These patterns work in ad-hoc commands, playbook host specifications, and limit flags. They're more powerful than a single group and essential for dynamic host targeting in large multi-tenant or multi-environment inventories where you need precise inclusion/exclusion logic.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
''Related atoms''
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Limit Ansible playbook execution to specific hosts]]
* [[What command lists all hosts in an inventory?]]
ansible-navigator is the recommended replacement for ansible-playbook, providing a TUI (terminal user interface) by default with richer visibility into task execution, logging, and interactive inspection. Unlike ansible-playbook, which runs directly on the control node with no container isolation, ansible-navigator runs playbooks inside execution environments (EE) — containerized images bundling Ansible and its dependencies — using podman or docker, ensuring consistent execution regardless of the control node's installed packages. Use <html><code>--mode stdout</code></html> to get plain-text output matching the legacy ansible-playbook behavior. Beyond playbook execution, ansible-navigator offers subcommands including <html><code>images</code></html>, <html><code>collections</code></html>, <html><code>doc</code></html>, and <html><code>config</code></html>, supports interactive exploration of inventory, displays module documentation inline, and can replay previous runs from saved artifact files. The net effect: the same playbooks run identically, but with container isolation, reproducibility, and a far more inspectable runtime environment.
----
''Sources''
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Execution Environments solved the dependency-conflict problem in Ansible]]
* [[What are Ansible "playbooks"?]]
* [[How do you inspect the contents of an EE image using ansible-navigator?]]
Ad-hoc commands run quick, unscripted tasks directly from the CLI without writing a playbook, using the syntax <html><code>ansible <pattern> -m <module> -a "args" [--become]</code></html>. Common uses include checking connectivity (<html><code>ansible all -m ping</code></html>), gathering facts, copying files, installing packages, running shell commands (<html><code>ansible all -m shell -a 'uptime' -b</code></html>), and restarting services.
Ad-hoc commands are the fastest way to verify connectivity, test new modules, or apply emergency fixes across an inventory. They are less auditable than playbooks — no version control, no idempotency guarantees — so they should be reserved for troubleshooting and one-time tasks. Recurring or repeatable workflows belong in playbooks for maintainability and auditability.
Note: YAML indentation matters in playbooks (2-space indent); while this does not affect ad-hoc commands themselves, it is a common gotcha when graduating ad-hoc tasks into playbook form.
----
''Sources''
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
* <html><code>training/library/topics/ansible-deep-dive/street_ops.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Prefer native modules over shell/command for idempotency]]
* [[Idempotence is the core contract of Ansible modules]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
Executing <html><code>ansible-playbook site.yml</code></html> without an explicit <html><code>--limit</code></html> flag targets every host in the inventory simultaneously, including production databases and critical infrastructure. The mistake stems from treating playbook development like script development — developers test locally and assume the default context is safe. In infrastructure automation, defaults that implicitly include production are dangerous: a half-tested change can hit hundreds of servers at once.
Two enforcement layers address this. First, operationally: always pass <html><code>--limit <group></code></html> to restrict scope and run <html><code>--check</code></html> first as a dry-run safety gate. Second, structurally: design playbooks to require explicit target selection by setting <html><code>hosts: "{{ target }}"</code></html> and failing fast when the variable is absent. This forces every invocation to look like <html><code>ansible-playbook site.yml -e target=staging</code></html>, making scope selection mandatory and visible rather than dependent on operator memory.
Many teams enforce this as policy: no playbook runs without an explicit <html><code>--limit</code></html> or a confirmation prompt. The one-second cost of specifying a target is negligible against the blast radius of a fleet-wide misconfiguration.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
* <html><code>training/library/topics/ansible/anti_primer.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[How do you test Ansible safely?]]
* [[Running fleet commands without --limit risks massive misconfiguration]]
* [[Default inventory pointing to production invites unintended changes]]
Tasks using <html><code>shell: apt-get install nginx</code></html> or <html><code>command: systemctl restart app</code></html> run every time a playbook executes, regardless of whether the operation is needed. This violates idempotency — the principle that configuration management must be safe to re-run without unintended side effects. The practical cost is severe: a playbook that should complete in 30 seconds instead takes 20 minutes because packages reinstall and services restart on every run, and actual changes are buried in noise.
Native [[Ansible modules|Ansible Modules]] (<html><code>apt</code></html>, <html><code>service</code></html>, <html><code>file</code></html>, <html><code>template</code></html>, etc.) are idempotent by design: they check current state first and report <html><code>ok</code></html> when the target state already exists, <html><code>changed</code></html> only when a modification is made. Using <html><code>shell</code></html> or <html><code>command</code></html> instead also prevents accurate change reporting, which can cascade into downstream failures triggered by spurious <html><code>changed</code></html> results.
Reserve <html><code>shell</code></html> and <html><code>command</code></html> for work that has no native module equivalent, and even then enforce idempotency explicitly: use <html><code>creates:</code></html> (skip the task if a specified file already exists) or <html><code>when:</code></html> conditions that check current state before acting.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Idempotency as default, exceptions with shell and command modules]]
Setting <html><code>become: true</code></html> at the playbook level or role level escalates privileges for every task, not just those requiring root. A file copy that should be owned by the app user runs as root instead, changing file ownership and breaking application permissions. The operator later wonders why the app can't read its own config files, not realizing that become applies everywhere in scope.
The fix is direct: set <html><code>become: true</code></html> only on individual tasks that require elevated privileges. A package manager task, a user creation task, and a config file install each declare their own privilege requirement. This makes the playbook self-documenting and prevents unintended side effects where tasks change ownership or permissions of resources that should be owned by unprivileged users.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
* <html><code>training/library/topics/ansible/anti_primer.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[What happens when you apply `become: true` with the `local` connection?]]
* [[become: true Must Be Set at Task Level for Privilege Escalation]]
* [[Play and task keywords coexist in YAML; indentation signals scope]]
Ansible evaluates variables in strict precedence order across 22 levels: role defaults lose to inventory vars, which lose to group_vars, which lose to host_vars, which lose to play/task vars, which lose to extra vars passed via <html><code>-e</code></html>. Extra vars always win, overriding everything else including role vars and host vars.
This creates a recurring footgun: a developer sets <html><code>app_port: 8080</code></html> in <html><code>defaults/main.yml</code></html> without realizing <html><code>app_port: 9090</code></html> is already defined in <html><code>group_vars/all.yml</code></html>. The change has no visible effect because the higher-precedence source shadows it silently. A related trap in CI: passing <html><code>-e app_port=8080</code></html> in a pipeline targeting a staging environment where <html><code>group_vars/staging.yml</code></html> sets <html><code>app_port=9000</code></html> — the extra var wins, silently violating the intended environment-specific configuration. Most teams use only 3–4 layers in practice, but interactions between them compound quickly under deadline pressure.
Diagnose the resolved value for a given host:
<html><pre><code class="language-plaintext">ansible hostname -m debug -a "var=app_port"</code></pre></html>
Fix: adopt a single source of truth per scope. Use the inventory-based variable hierarchy (<html><code>group_vars/</code></html>, <html><code>host_vars/</code></html>) for environment-specific settings. Reserve extra vars for temporary debugging or one-off overrides — never for primary configuration. Document which scope owns which variables. Precedence surprises usually signal that variable architecture needs clarification, not just a one-off fix.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
* <html><code>training/library/topics/ansible/anti_primer.md</code></html>
* <html><code>training/library/topics/ansible/primer.md</code></html>
* <html><code>training/library/topics/ansible-deep-dive/footguns.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Ansible variable precedence: bookends and gradient]]
* [[Eight Ansible variable precedence levels you need]]
* [[Directory-based variable organization separates variables from inventory]]
Handlers are a deferred execution mechanism: they collect notifications from changed tasks and run once, in order, at the end of the play — not immediately after the notifying task. If any task fails and the play aborts before that point, all pending handlers are discarded without running.
The practical failure mode: a config file is changed by an earlier task, a <html><code>notify:</code></html> queues a service restart handler, a later task fails the play, and the handler never fires. The service continues running against the new config file without being restarted — a silent state inconsistency that may go unnoticed until symptoms surface under investigation.
Mitigations:
* Use <html><code>meta: flush_handlers</code></html> at any point in a play to force all pending handlers to execute immediately rather than waiting for play end. Place it before any task that could fail if you need the handler to run first.
* For critical state changes (service restarts after config updates), prefer an explicit <html><code>service:</code></html> task in the main task sequence over a handler, so execution order is deterministic and not contingent on play success.
* Handlers are appropriate for idempotent, non-critical side effects; they are a poor fit for state transitions that must not be skipped on failure.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[Handlers Only Fire When Task Status Changes]]
* [[Ansible playbook architecture: plays, tasks, roles]]
<html><code>lineinfile</code></html> manages a single line in a file by matching a regex. If two tasks use <html><code>lineinfile</code></html> with overlapping regex patterns, they conflict — one adds a line, the other removes it (because it doesn't match the next expected pattern), and the playbook reports <html><code>changed</code></html> on every run. The file thrashes.
<html><code>lineinfile</code></html> is designed for surgical one-line edits: uncommenting a sysctl option, adding a flag to a config file. For multi-line blocks, use <html><code>blockinfile</code></html> (which manages content between delimiters). For files you fully manage, use <html><code>template</code></html>. When modifying files owned by other software, avoid multiple <html><code>lineinfile</code></html> tasks on the same file — prefer a single <html><code>blockinfile</code></html> task that clearly marks the section Ansible manages.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
''Related atoms''
* [[File '/tmp/exercise' includes the following content]]
* [[What module adds or modifies lines in files?]]
* [[What does the `lineinfile` module do?]]
Running a playbook against production without <html><code>--check --diff</code></html> first is unnecessary risk. A template with a typo renders broken configuration, the service restarts with it, and the application goes down. The outage is preventable in under a minute.
<html><code>--check</code></html> executes the playbook in dry-run mode: modules report what would change without modifying any state. <html><code>--diff</code></html> shows before-and-after for files, giving visibility into template expansions, config rewrites, and string substitutions. Together they expose typos, template errors, and unintended side effects before they reach real systems.
The workflow is: run with <html><code>--check --diff</code></html>, review the output, fix any issues, then run for real. This one-minute addition to every deployment prevents hours of incident response. Make it automatic habit — check, review, apply.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[How do you test Ansible safely?]]
* [[Explain the purpose of the --diff option in Ansible playbooks.]]
A task that creates a database user, provisions an API key, or passes a password prints the full task output including the secret to stdout. CI systems capture stdout in logs. Anyone with access to CI logs can read your production credentials.
Add <html><code>no_log: true</code></html> to any task that touches secrets: database passwords, API tokens, encryption keys, SSH key material. This suppresses the task output from logs while the playbook executes normally. Audit existing playbooks and CI log archives for leaked credentials. Treat credential exposure as a security incident — rotate the exposed secret immediately, not later.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
''Related atoms''
* [[How do you handle a playbook that exposes sensitive data in logs?]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
Your default inventory file — the one Ansible reads if you don't specify <html><code>-i</code></html> — targets production servers. A new team member runs <html><code>ansible-playbook site.yml</code></html> to test locally and hits production. Your seemingly safe dev workflow just modified production.
Remove production from the default inventory or remove the default entirely. Require explicit <html><code>-i inventory/staging.yml</code></html> or <html><code>-i inventory/prod.yml</code></html> on every invocation. Use separate, clearly named inventory files per environment. Consider a wrapper script or Makefile target that enforces environment selection: <html><code>make deploy-to-staging</code></html> is safer than <html><code>ansible-playbook site.yml</code></html> because the invocation is explicit and the audience knows what will be affected.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible playbooks without --limit run against all inventory]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[Editing inventory during playbook execution causes races]]
To manage multiple environments (development, staging, production) in Ansible, create separate inventory files and environment-specific <html><code>group_vars</code></html> (and optionally <html><code>host_vars</code></html>) for each environment.
Recommended directory structure:
<html><pre><code class="language-plaintext">inventories/
development/
hosts
group_vars/
all.yml
staging/
hosts
group_vars/
all.yml
production/
hosts
group_vars/
all.yml
site.yml</code></pre></html>
At runtime, specify the target environment by passing the appropriate inventory with <html><code>-i</code></html>:
<html><pre><code class="language-plaintext">ansible-playbook -i inventories/development/hosts site.yml
ansible-playbook -i inventories/staging/hosts site.yml
ansible-playbook -i inventories/production/hosts site.yml</code></pre></html>
This pattern keeps environment-specific configuration isolated and explicit. Supporting practices: store all playbooks and inventory files in version control, validate changes in staging before promoting to production, and document the inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Multi-Tier Application Deployment]]
* [[Ansible Dynamic Inventory]]
Q: What steps would you take to debug an issue with Ansible Container?
A: Debug by:
* Reviewing Ansible Container logs.
* Checking container runtime logs.
* Inspecting container build outputs.
* Using the --debug option for detailed debugging information.
Gotcha: Ansible Container was archived/deprecated in 2019. Modern container workflows use ansible-builder for Execution Environments or standard Dockerfiles.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
* [[Troubleshooting Playbook Failures]]
* [[What steps would you take to troubleshoot a failed Ansible playbook?]]
Ansible's default configuration introduces several scalability killers at large inventory sizes.
''Fact gathering'' is the most impactful non-obvious bottleneck. Enabled by default (<html><code>gather_facts: true</code></html>), the setup module collects extensive system information from every host before any tasks execute. Collection runs sequentially per fork and takes 2–10 seconds per host — at 1,000 hosts that is 83 minutes of overhead before the first task runs. Mitigation: disable fact gathering when facts are not needed, or enable fact caching so results are reused across runs.
''SSH connection overhead'' is the second major factor. A new connection is established per host per play, adding handshake latency at scale. Mitigations: enable SSH pipelining (reduces round-trips by streaming modules over an open connection) and set <html><code>ControlPersist</code></html> to reuse existing SSH multiplexed connections.
''Additional optimizations for large inventories:''
* Increase the <html><code>forks</code></html> setting (default 5) to raise parallelism.
* Use <html><code>async</code></html> tasks with <html><code>poll: 0</code></html> for long-running operations so Ansible does not block waiting for each host.
* Combine pipelining and ControlPersist in <html><code>ansible.cfg</code></html> for maximum SSH efficiency.
Operational baseline: version-control all playbooks, test changes in staging before production, and document inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[High fork counts cause connection exhaustion and cascading failures]]
* [[One slow host blocks the entire play during fact gathering]]
* [[What open-source tool can dramatically speed up Ansible by replacing SSH with a custom …]]
Q: What are Ansible "playbooks"?
A: YAML scripts that declare the desired state of a system.
Example: a playbook targeting [webservers] installs nginx, templates the config, and notifies a handler to restart — all in one YAML file.
Name origin: from sports — a 'playbook' is a collection of plays (strategies) to run in sequence.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Playbooks express desired state through ordered tasks]]
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
A playbook file is a container; the meaningful units are the plays and tasks within it. Treating the entire file as "the playbook" without distinguishing between plays (which target different host groups) and tasks (which are individual actions) leads to confusion about what will execute where. The YAML list syntax makes plays, tasks, and role includes look structurally similar—all are list items at varying indentation levels—obscuring the boundaries between these different kinds of directives. Recognizing that a playbook file can contain multiple independent plays, each with its own <html><code>hosts:</code></html> target and task list, is essential to understanding how Ansible executes and how to structure larger automation.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-playbook-play-task-role.md</code></html>
''Related atoms''
* [[What is the difference between an Ansible playbook and a role?]]
* [[What command runs an Ansible playbook?]]
* [[What information is available in the output when using the --check option?]]
Q: What is a play in Ansible?
A: A section within a playbook that maps a group of hosts to a set of tasks. A playbook can contain multiple plays.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
* [[What is `ansible_play_name`?]]
* [[What is the purpose of an Ansible Playbook?]]
Use the <html><code>-l</code></html> / <html><code>--limit</code></html> flag to restrict which hosts a playbook runs against.
''Basic usage:''
<html><pre><code class="language-bash">ansible-playbook -i inventory.ini site.yml --limit webservers
ansible-playbook playbook.yml --limit "webserver1"</code></pre></html>
The flag accepts group names, individual hostnames, or glob patterns:
<html><pre><code class="language-bash">ansible-playbook playbook.yml --limit 'web*'</code></pre></html>
Before running, verify which hosts match a pattern:
<html><pre><code class="language-bash">ansible-playbook playbook.yml --limit 'web*' --list-hosts</code></pre></html>
Combine with <html><code>--check --diff</code></html> to preview changes without applying them:
<html><pre><code class="language-bash">ansible-playbook -i inventory.ini site.yml -l webservers --check --diff</code></pre></html>
Alternatively, scope execution at the playbook level via the <html><code>hosts:</code></html> key in the play definition — <html><code>--limit</code></html> then further narrows that set.
''Gotcha:'' YAML indentation in playbooks must be consistently 2 spaces; a misaligned indent can silently change task scope or cause a parse error, making <html><code>--limit</code></html> appear to misbehave when the real issue is structure.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Optimizing Ansible Playbook Performance]]
* [[Ansible inventory file: definition and configuration]]
* [[Inventory patterns use set operators for host selection]]
Q: What is a task in Ansible?
A: A task is the smallest unit of action in a playbook, typically calling an Ansible module with specific arguments (e.g., a task to install a package or copy a file).
Remember: task = one action on one or more hosts. A task calls a module (apt, copy, service) with parameters. Tasks execute in order within a play.
Example: - name: Install nginx
apt: name=nginx state=present — this is one task calling the apt module.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[What is a play in Ansible?]]
* [[What keyword defines tasks in a playbook?]]
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
Q: Migrating Legacy Scripts to Ansible
A: To migrate legacy scripts to Ansible:
Identify Tasks: Break down the shell script into discrete tasks.
Use [[Ansible Modules]]: Replace shell commands with equivalent Ansible modules.
Structure Playbooks: Organize tasks into roles and playbooks for better management.
Example migration:
Original shell script:
<html><pre><code class="language-plaintext">#!/bin/bash
apt-get update
apt-get install -y nginx
echo "Hello, World!" > /var/www/html/index.html</code></pre></html>
Migrated Ansible playbook:
<html><pre><code class="language-plaintext">- hosts: web
tasks:
- name: Update apt cache
apt:
update_cache: yes
- name: Install Nginx
apt:
name: nginx
state: present
- name: Create index.html
copy:
content: "Hello, World!"
dest: /var/www/html/index.html</code></pre></html>
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Prefer native modules over shell/command for idempotency]]
* [[What are Ansible "playbooks"?]]
* [[Handling Dependencies]]
The <html><code>serial</code></html> keyword limits how many hosts Ansible processes per batch before moving to the next batch. It applies at the play level and works with any execution strategy.
Accepted values:
* ''Integer'': <html><code>serial: 4</code></html> processes exactly 4 hosts per batch.
* ''Percentage'': <html><code>serial: '25%'</code></html> processes a quarter of the inventory group at a time.
* ''Escalating list'': <html><code>serial: [1, 5, 10]</code></html> starts with 1 host, then 5, then 10, allowing cautious rollout verification before widening blast radius.
Example:
<html><pre><code class="language-yaml">- name: Rolling DB update
hosts: databases
serial: 4
max_fail_percentage: 10</code></pre></html>
With 8 hosts and <html><code>serial: 4</code></html>, Ansible runs the full play on the first 4 hosts, then repeats on the remaining 4. Combining with <html><code>max_fail_percentage</code></html> aborts the run if the failure rate within a batch exceeds the threshold, preventing a bad change from propagating to the entire fleet.
<html><code>serial</code></html> is the primary mechanism for rolling updates in Ansible — it ensures only a controlled subset of hosts is ever in a degraded state simultaneously.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
* [[What is the "canary deployment" pattern in Ansible?]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
Q: How do you manage secrets in Ansible?
A: Never inline plaintext secrets. Options:
''Ansible Vault'':
<html><pre><code class="language-bash">ansible-vault create secrets.yml
ansible-vault edit secrets.yml
ansible-playbook --ask-vault-pass playbook.yml</code></pre></html>
Good for: Smaller teams, simple needs.
''External secret managers'':
* HashiCorp Vault (<html><code>hashi_vault</code></html> lookup)
* AWS Secrets Manager
* Azure Key Vault
* CyberArk, etc.
Good for: Enterprise, dynamic secrets, audit requirements.
''Best practices'':
* Separate vault files per environment
* Use vault IDs for multiple passwords
* CI/CD: vault password from secure variable, never committed
* Rotate secrets regularly
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[How do you create an encrypted file using Ansible Vault?]]
* [[How do you manage secrets across multiple environments?]]
* [[Explain the process of editing an encrypted file with Ansible Vault.]]
Q: True or False? By default, Ansible will execute all the tasks in play on a single host before proceeding to the next host
A: False. Ansible will execute a single task on all hosts before moving to the next task in a play. As for today, it uses 5 forks by default.
This behavior is described as "strategy" in Ansible and it's configurable.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[What is the `forks` setting, and what is its default value?]]
* [[What is the gotcha with `run_once` and `serial`?]]
* [[Playbook files contain nested structures that are not visually distinct]]
A strategy plugin in Ansible controls how tasks are executed across targeted hosts. The default strategy is <html><code>linear</code></html>: each task runs on all targeted hosts before Ansible proceeds to the next task.
The four built-in strategy plugins are:
# ''linear'' (default) — runs each task on all hosts before moving to the next task.
# ''free'' — lets each host run through all tasks independently, as fast as possible, without waiting for other hosts.
# ''host_pinned'' — like <html><code>free</code></html>, but does not interrupt execution on a currently-running host to start a new one.
# ''debug'' — pauses on task failure for interactive, step-by-step debugging.
The strategy can be set at the play level via the <html><code>strategy</code></html> keyword, or globally in <html><code>ansible.cfg</code></html> under <html><code>[defaults]</code></html> as <html><code>strategy = free</code></html> (or another value). Custom strategy plugins can also be installed.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[What are strategy plugins?]]
* [[Optimizing Ansible Playbook Performance]]
Q: Why is shell in Ansible dangerous?
A: The <html><code>shell</code></html> and <html><code>command</code></html> modules should be last resort:
''Breaks idempotence'': Shell commands run every time unless you add complex <html><code>creates</code></html>/<html><code>removes</code></html> or <html><code>when</code></html> conditions.
''Hides failures'': Exit codes aren't always meaningful. Silent failures corrupt state.
''Non-portable'': Shell commands vary across distros, versions, shells.
''Hard to test'': No structured output to validate.
''Example - bad'':
<html><pre><code class="language-yaml">- shell: useradd myuser</code></pre></html>
''Example - good'':
<html><pre><code class="language-yaml">- user:
name: myuser
state: present</code></pre></html>
The module handles idempotence, cross-platform differences, and returns structured results.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[How do you test Ansible safely?]]
* [[How do you use the "shell" module in Ansible?]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
Q: Configuring Ansible for Network Automation
A: For network automation, I would use Ansible network modules and collections like ansible.netcommon and vendor-specific collections.
Example playbook for Cisco devices:
<html><pre><code class="language-plaintext">- hosts: cisco_routers
gather_facts: no
tasks:
- name: Configure interface
cisco.ios.ios_interface:
name: GigabitEthernet1
description: "Configured by Ansible"
enabled: yes</code></pre></html>
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[What's your experience with Ansible?]]
* [[How does Ansible support network automation?]]
Ansible provides several mechanisms for error handling in playbooks.
''block / rescue / always'' — structured error handling analogous to try/catch/finally. A <html><code>block</code></html> groups related tasks; if any task in the block fails, <html><code>rescue</code></html> executes (e.g., trigger a rollback); <html><code>always</code></html> executes regardless of success or failure (e.g., cleanup or reporting). Without this structure, a failed task halts the entire playbook, leaving the system in an undefined state.
''ignore_errors: true'' — prevents a task failure from halting the play, but does //not// trigger <html><code>rescue</code></html>. Use for non-critical tasks where failure is acceptable.
''retries / delay / until'' — retries a task up to N times with a delay between attempts until a condition is met. Useful for intermittently failing operations (e.g., waiting for a service to become available).
''failed_when'' — defines custom failure criteria. A task can return exit code 0 yet be marked failed based on output content (e.g., <html><code>failed_when: "'100%' in result.stdout"</code></html> to detect a full disk).
Common pattern: wrap a deploy task in <html><code>block</code></html>, catch failures in <html><code>rescue</code></html> to run rollback logic, and use <html><code>always</code></html> to report or clean up. Combining <html><code>failed_when</code></html> with <html><code>block/rescue</code></html> enables sophisticated, condition-aware error recovery.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[If a rescue section succeeds, does Ansible consider the play failed?]]
* [[Ansible handlers skip entirely if the play fails]]
* [[Playbook failure diagnosis pattern]]
Several techniques reduce Ansible playbook execution time:
''Parallelism:'' Increase forks to run tasks across hosts concurrently.
<html><pre><code class="language-plaintext">ansible-playbook -i inventory playbook.yml -f 10</code></pre></html>
''Limit scope:'' Target only relevant hosts with <html><code>--limit</code></html> to avoid unnecessary work.
<html><pre><code class="language-plaintext">ansible-playbook -i inventory playbook.yml --limit web_servers</code></pre></html>
''Async tasks:'' Offload long-running operations so the controller does not block.
''Skip unnecessary fact gathering:'' Disable <html><code>gather_facts</code></html> when host facts are not needed by the play.
''Delegate tasks:'' Use <html><code>delegate_to</code></html> to shift work to an appropriate host (e.g., localhost for fetches).
<html><pre><code class="language-plaintext">- name: Fetch something
delegate_to: localhost</code></pre></html>
''Minimize loops and conditionals:'' Avoid redundant iteration; restructure tasks to reduce per-host overhead.
General hygiene: version-control all playbooks, test in staging before production, document inventory structure, and use consistent 2-space YAML indentation — a single misindented line can silently alter task behavior or cause a parse error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible strategy plugins control task-execution ordering across hosts]]
* [[One slow host blocks the entire play during fact gathering]]
* [[Ansible async/poll decouples long task submission from completion]]
Q: What are Ansible "tags"?
A: Labels used to selectively run or skip specific tasks.
Example: ansible-playbook site.yml --tags=deploy runs only deploy-tagged tasks.
Gotcha: untagged tasks run by default. Use the special 'always' tag for must-run tasks.
Remember: tags = surgical targeting. --tags=deploy runs only deploy tasks. --skip-tags=setup skips setup tasks. Great for partial runs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
* [[What are tags used for?]]
* [[What does `--tags tagged` mean?]]
Q: What is <html><code>ansible_run_tags</code></html> and <html><code>ansible_skip_tags</code></html>?
A: <html><code>ansible_run_tags</code></html> contains the list of tags specified with --tags. <html><code>ansible_skip_tags</code></html> contains the list of tags specified with --skip-tags. Both are available to conditionals.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the five reserved tag names in Ansible?]]
* [[What are tags used for?]]
* [[If you specify both --tags and --skip-tags for the same tag, what happens?]]
Q: Handling Dependencies
A: To integrate Ansible with a CI/CD pipeline, I would use tools like Jenkins, GitLab CI, or GitHub Actions. The CI/CD pipeline would trigger Ansible playbooks to deploy or update infrastructure.
Example using GitLab CI:
<html><pre><code class="language-plaintext">stages:
- deploy
deploy:
stage: deploy
script:
- ansible-playbook -i inventory playbook.yml</code></pre></html>
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Ansible Dynamic Inventory]]
* [[Explain the role of Ansible Tower in a CI/CD pipeline.]]
* [[Configuring Ansible for Network Automation]]
Q: How can you test and validate a dynamic inventory script?
A: Test the script by running it manually and examining output. Validate by checking if it produces JSON-formatted data with required host information.
Example: ./inventory.py --list | python -m json.tool validates JSON output. Compare against ansible-inventory -i inventory.py --graph to see how Ansible interprets the groups.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Ansible Dynamic Inventory]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
* [[Dynamic inventory in Ansible]]
Q: Rolling Updates with Zero Downtime
A: To implement a rolling update with zero downtime, I would use a combination of Ansible playbooks and a load balancer. The process involves updating a subset of servers at a time while ensuring the load balancer only directs traffic to healthy nodes. Here’s a high-level approach:
Drain Traffic: Use Ansible to interact with the load balancer API to drain traffic from the first subset of servers.
Update Servers: Apply the updates to the drained servers.
Health Check: Ensure the updated servers pass health checks.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[How do you implement zero-downtime deployments?]]
* [[Safe infrastructure patch rollouts use progressive stages and circuit breakers]]
* [[What is a rolling update strategy?]]
AWX is the open-source upstream project for Ansible's web-based control plane, released roughly monthly and free to use. It provides a web UI, REST API, RBAC, job scheduling, credential management, and audit trail for team-scale Ansible operations.
Ansible Tower was Red Hat's commercial product built on AWX, adding SLA support, ISV compatibility guarantees, and supported upgrade paths. In 2021, Red Hat retired the Tower name and rebranded it as Ansible Automation Platform (AAP). AAP now encompasses more than the core orchestrator: it includes the automation controller (the direct successor to Tower and AWX's enterprise build), Automation Hub (for hosting collections and execution environments), and an automation mesh for scaling execution across distributed infrastructure, along with deeper integration into Red Hat's broader ecosystem.
The name progression is: AWX (open-source, always current) → Ansible Tower (commercial, now retired name) → automation controller (current component name inside AAP). Job postings and documentation frequently conflate these names — "Tower" is still used colloquially to mean AAP or automation controller. Understanding the distinction matters when evaluating licensing, support tiers, and feature availability: AWX is free but unsupported; automation controller/AAP carries Red Hat subscription support and enterprise guarantees.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Red Hat open-sourced AWX while selling Ansible Tower as a commercial product]]
* [[What is AWX?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
Q: How do you create and manage inventories in Ansible Tower?
A: Inventories in Ansible Tower can be managed through the web interface. You can create and organize inventories, define variables, and configure sources such as static files, dynamic scripts, or cloud providers. Tower also supports syncing with external inventory systems.
Remember: AWX = free upstream, Tower = paid Red Hat product (now 'Ansible Automation Platform'). Both add web UI, RBAC, scheduling, and REST API.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[What is Ansible Tower?]]
* [[How do you implement RBAC in Ansible Tower?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
Q: What's your experience with Ansible?
A: I've used Ansible heavily for server provisioning, patching, switch configuration, and enforcing consistency across large server fleets. I write clean, modular roles, use inventories effectively, and rely on Jinja2 templating for dynamic configs. I've automated PXE/bootstrap workflows and built idempotent playbooks for both servers and network gear.
Remember: in interviews, structure your experience answer as: scope (how many servers/services), tools used, key challenges solved, and measurable impact (time saved, incidents reduced).
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[How does Ansible differ from other configuration management tools?]]
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[What are the key features of Ansible?]]
Q: Multi-Tier Application Deployment
A: To handle a multi-tier application deployment efficiently, I would use a modular approach with Ansible roles. Each tier (web server, application server, database server) would have its own role. The directory structure might look like this:
```sh
site.yml
roles/
web/
tasks/
main.yml
templates/
web.conf.j2
app/
tasks/
main.yml
templates/
app.conf.j2
db/
tasks/
main.yml
templates/
db.conf.j2
inventory/
production/
hosts
group_vars/
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Ansible: Managing Multiple Environments with Separate Inventories]]
* [[Roles organize reusable Ansible code into directories]]
* [[Handling Dependencies]]
Q: Explain how to view job output and logs in Ansible Tower.
A: View job output in the Ansible Tower UI under the specific job details. Logs can be accessed through the UI or retrieved using the Tower API. Additionally, logs are stored in the Tower log directory on the Tower server.
Remember: AWX = free upstream, Tower = paid Red Hat product (now 'Ansible Automation Platform'). Both add web UI, RBAC, scheduling, and REST API.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[What features does Ansible Tower/AWX provide?]]
* [[How do you troubleshoot failed jobs in Ansible Tower?]]
* [[What is Ansible Tower?]]
Configuration drift occurs when servers diverge from their desired state over time. Ansible addresses this in two complementary ways.
''Detection (non-destructive):'' Run playbooks in check mode to see what would change without applying anything:
<html><pre><code class="language-bash">ansible-playbook -i inventory playbook.yml --check --diff</code></pre></html>
The <html><code>--diff</code></html> flag shows file-level deltas alongside the tasks that would change, making it easy to identify exactly where drift has occurred.
''Enforcement (remediation):'' Schedule regular playbook runs to automatically converge servers back to the desired state. Using a cron job:
<html><pre><code class="language-plaintext">0 2 * * * ansible-playbook -i inventory playbook.yml</code></pre></html>
Alternatively, Ansible Tower/AWX provides scheduled job templates with logging, RBAC, and alerting built in, which is preferable in team environments.
''Best practices:''
* Store all playbooks and inventory in version control.
* Run in <html><code>--check</code></html> mode first in staging; promote to production only after validation.
* Document inventory structure so the team understands the scope of each enforced playbook.
* Use <html><code>--diff</code></html> in scheduled runs (or Tower job output) to log what changed during each enforcement cycle, creating an audit trail of drift events.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Always run --check --diff before production Ansible changes]]
* [[What is configuration drift?]]
Q: Ansible Dynamic Inventory
A: To manage a dynamic infrastructure, I would use Ansible’s dynamic inventory feature. This can be achieved by using inventory scripts or plugins that query external data sources such as cloud provider APIs (e.g., AWS, Azure).
Example using AWS EC2 dynamic inventory:
Install the AWS Inventory Plugin:
<html><pre><code class="language-plaintext">pip install boto boto3</code></pre></html>
Configure the AWS Inventory Plugin:
<html><pre><code class="language-plaintext">plugin: aws_ec2
regions:
- us-east-1
filters:
tag:Environment: production</code></pre></html>
Use the Dynamic Inventory in Playbooks:
<html><pre><code class="language-plaintext">ansible-playbook -i aws_ec2.yml playbook.yml</code></pre></html>
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
* [[What are common issues you might encounter with dynamic inventories, and how would you …]]
* [[Ansible inventory file: definition and configuration]]
Q: Explain the process of editing an encrypted file with Ansible Vault.
A: Use the ansible-vault edit command to edit an encrypted file.
Example:
<html><pre><code class="language-bash">ansible-vault edit secret_file.yml</code></pre></html>
Ansible will prompt for the Vault password before allowing access.
Under the hood: ansible-vault edit decrypts to a temp file, opens your $EDITOR, then re-encrypts on save. The plaintext never touches disk persistently.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[How do you manage secrets in Ansible?]]
* [[How do you run a playbook that uses vault-encrypted files?]]
Q: How do you create an encrypted file using Ansible Vault?
A: Use the ansible-vault create command to create an encrypted file.
Example:
<html><pre><code class="language-bash">ansible-vault create secret_file.yml</code></pre></html>
Under the hood: ansible-vault create opens $EDITOR for a new file and encrypts it on save using AES-256. The encrypted file can be committed to git safely.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
//Merged from 5 source atoms.//
''Related atoms''
* [[How do you edit an encrypted file?]]
* [[How do you manage secrets in Ansible?]]
* [[How do you decrypt a file?]]
Q: How do you edit an encrypted file?
A: <html><code>ansible-vault edit secrets.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you create an encrypted file using Ansible Vault?]]
* [[How do you view an encrypted file without decrypting?]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
Q: Troubleshooting Playbook Failures
A: To troubleshoot a failing playbook:
Check Recent Changes: Review recent changes in the playbook, roles, or inventory files.
Verbose Output: Run the playbook with increased verbosity (-vvv) to get detailed output and identify where it fails.
Environment Consistency: Ensure the environment where the playbook is run hasn’t changed (e.g., different Ansible version, OS updates, or network configurations).
Isolate the Issue: Isolate the failing task by running it independently or within a minimal playbook.
Remember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[Troubleshooting Ansible module issues]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
Q: How do you limit Ansible to run on one host at a time (serial execution)?
A: In a playbook, use the serial keyword (e.g., serial: 1 in a play limits Ansible to configure one host at a time from the inventory).
Gotcha: serial: 1 is essential for rolling updates — it ensures one host is fully configured and healthy before moving to the next, preventing fleet-wide outages from a bad config.
Example: serial: '25%' updates a quarter of your fleet at a time. Combine with max_fail_percentage: 10 to abort if too many hosts fail.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Always limit-test new playbooks before fleet-wide execution]]
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
The control node is the machine where Ansible is installed and from which playbooks and commands are executed. It reads playbooks, resolves inventory, opens SSH connections to managed nodes, and aggregates results.
OS constraint: the control node must run Linux or macOS. Windows is not supported as a control node natively — use WSL2 as a workaround. Windows machines can participate only as managed nodes, communicating via WinRM.
Key distinction: control node is the command center; managed nodes are the targets.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible manages Windows servers via WinRM]]
* [[How does Ansible connect to managed nodes?]]
* [[How does Ansible communicate with Windows hosts?]]
Orchestration is the coordination and sequencing of multiple tasks across servers, networking devices, and external services to achieve a specific objective — typically a complex multi-tier deployment.
Key aspects:
* ''Task sequencing'': Tasks execute in a defined order with explicit dependencies, ensuring each step completes before the next begins.
* ''Workflow automation'': Orchestration tools encode the order and dependencies of tasks so the entire workflow runs without manual intervention.
* ''Cross-platform integration'': A single orchestration run can span heterogeneous systems — Linux servers, network devices, cloud APIs — treating them as a unified pipeline.
In Ansible specifically, orchestration is expressed through:
* ''Plays'': target specific host groups for each phase of work.
* ''<html><code>serial</code></html>'': roll changes across hosts in batches (rolling deployments).
* ''<html><code>delegate_to</code></html>'': route a task to a different host than the one being configured.
The mental model: orchestration = coordinating what runs where, in what order, across multiple systems.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible execution hierarchy: playbook > play > task; roles bundle and reuse]]
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
Q: Have you used automation tools like PowerShell or Ansible for server management tasks?
A: Automation tools such as PowerShell and Ansible streamline server management tasks: • **PowerShell:* • • Windows Environment: PowerShell is a scripting language and automation framework designed for Windows environments. • Task Automation: It allows the automation of various tasks, including server configuration, software deployment, and system administration. • Scripting Capabilities: PowerShell scripts can be written to execute commands and tasks, making it efficient for managing Windows servers.
Remember: PowerShell is Windows-centric (though cross-platform via pwsh). Ansible is Linux-first but supports Windows via WinRM. Choose based on your fleet's OS mix.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
''Related atoms''
* [[Ansible manages Windows servers via WinRM]]
* [[Can Ansible use SSH to manage Windows?]]
* [[What are the server requirements for Ansible?]]
Q: File '/tmp/exercise' includes the following content
A: <html><pre><code class="language-plaintext">- name: Change saiyans levels
lineinfile:
dest: /tmp/exercise
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^Vegeta', line: 'Vegeta = 250' }
- { regexp: '^Trunks', line: 'Trunks = 40' }
...</code></pre></html>
Note: with_items still works but <html><code>loop:</code></html> is preferred since Ansible 2.5.
Remember: import_* = static (parsed at playbook load). include_* = dynamic (parsed at runtime). Use import for roles, include for conditional logic.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you include external tasks in an Ansible Playbook?]]
* [[How do you define variables in Ansible Playbooks?]]
* [[Playbook files contain nested structures that are not visually distinct]]
Ansible Facts are variables automatically collected from managed nodes at playbook runtime. They describe the target system's hardware details, IP addresses, OS version, installed software, and more. On Windows hosts, the same fact-collection mechanism applies — facts expose Windows-specific properties alongside common ones.
The <html><code>gather_facts</code></html> task (enabled by default) triggers this collection at the start of a play. Once gathered, facts are available throughout the playbook as variables — in task conditionals, templates, and registered values. You can disable fact collection with <html><code>gather_facts: false</code></html> to speed up plays that do not need that data.
Facts are accessed via the <html><code>ansible_facts</code></html> dictionary (e.g., <html><code>ansible_facts['os_family']</code></html>) or directly as top-level variables with the <html><code>ansible_</code></html> prefix (e.g., <html><code>ansible_os_family</code></html>) depending on the <html><code>inject_facts_as_vars</code></html> setting.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can silently change a task's scope or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_facts` vs top-level fact variables?]]
* [[If you create a custom fact in the same play, how do you access it?]]
* [[How do you disable fact gathering?]]
Q: The value of a certain variable you use is the string "True". You would like the value to be a boolean. How would you cast it?
A: <html><code>{{ some_string_var | bool }}</code></html>
Under the hood: Jinja2's bool filter converts strings like 'True', 'yes', '1' to Python True, and 'False', 'no', '0' to False. Essential when variables come from external sources as strings.
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
* [[How do you write a conditional in Jinja2?]]
* [[How do you use variables in Jinja2 templates?]]
Ansible Galaxy is a community hub — both a website and the <html><code>ansible-galaxy</code></html> CLI tool — for finding, sharing, and installing reusable Ansible roles and collections. It launched in 2013 with approximately 200 contributed roles and grew to over 40,000 roles and collections by 2024, making it one of the largest repositories of production infrastructure code.
Galaxy hosts two artifact types. Roles are the original unit: single-purpose task bundles installed with <html><code>ansible-galaxy install <author>.<role></code></html> (e.g., <html><code>ansible-galaxy install geerlingguy.docker</code></html>). Collections, the modern packaging format introduced with Ansible 2.10+, bundle roles, modules, plugins, and documentation together and support granular versioning and dependency management. This shift from a simple role registry to a collections-based model reflects the platform's technical maturation alongside community growth.
Use a <html><code>requirements.yml</code></html> file to pin role and collection versions for reproducible builds. Galaxy's growth mirrors broader Ansible adoption and the community's investment in infrastructure code reuse.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[What is the difference between an Ansible playbook and a role?]]
* [[Explain the use of Ansible roles in network automation.]]
* [[Roles organize reusable Ansible code into directories]]
Molecule is a testing framework for Ansible roles. It tests roles in isolated environments — Docker, Vagrant, and other providers — and manages the full test lifecycle: environment creation, role convergence, idempotence verification, and environment destruction. It can run tests against multiple Linux distributions simultaneously, giving confidence that roles behave correctly both during initial development and as they are maintained over time.
Gotcha: YAML indentation matters in playbooks and roles. Use 2-space indentation consistently. A single wrong indent can silently change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you test Ansible safely?]]
* [[Roles organize reusable Ansible code into directories]]
* [[What are best practices for Ansible role organization?]]
Q: What is the purpose of an Ansible Playbook?
A: An Ansible Playbook is a YAML file containing organized instructions (plays) for configuring and managing systems. Playbooks define tasks, roles, and dependencies, providing a structured way to automate complex tasks.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is Ansible Tower, and how does it differ from Ansible?]]
* [[Explain the use of the "hosts" directive in a playbook.]]
* [[What is a play in Ansible?]]
Q: What language are Ansible playbooks written in?
A: YAML (Yet Another Markup Language), a human-readable data serialization format.
Fun fact: YAML stands for 'YAML Ain't Markup Language' (recursive acronym). It was chosen for readability over JSON or XML.
Gotcha: YAML is whitespace-sensitive. Mixing tabs and spaces causes parse errors. Convention is 2-space indentation.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Ansible debug module: printing messages during playbook execution]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
Q: What is the syntax for an Ansible Playbook?
A: Ansible Playbooks use YAML syntax. Example:
<html><pre><code class="language-yaml">---
- name: Install and start Apache
hosts: webserver
tasks:
- name: Install Apache
yum:
name: httpd
state: present
- name: Start Apache
service:
name: httpd
state: started</code></pre></html>
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you enable verbose mode for Ansible playbooks?]]
* [[How can you use tags in Ansible Roles?]]
* [[How do you install and configure Ansible Tower?]]
Q: Explain the key components of Ansible.
A: Ansible consists of:
* Controller Node: The machine running Ansible, orchestrating tasks.
* Managed Nodes: Systems Ansible manages and automates.
* Inventory: A list of managed nodes.
* Modules: Units of work executed by Ansible.
* Playbooks: YAML files defining tasks and configurations.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What are the main components of Ansible's architecture?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
* [[What information is available in the output when using the --check option?]]
Q: What is YAML, and why is it used in Ansible?
A: YAML (YAML Ain't Markup Language) is a human-readable data serialization format. Ansible uses YAML for playbooks and inventories due to its simplicity, readability, and easy mapping to data structures.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What does YAML stand for?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
* [[Why is YAML 1.2 relevant to Ansible's future?]]
Q: How do you troubleshoot failed jobs in Ansible Tower?
A: Troubleshoot by:
* Examining job details and logs in the Ansible Tower UI.
* Reviewing playbook output for error messages.
* Checking inventory, credentials, and playbooks for misconfigurations.
* Analyzing job status and error codes.
Example: assert: that: ansible_memtotal_mb >= 1024 fail_msg: 'Insufficient memory' — validates preconditions before proceeding with the playbook.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Troubleshooting Playbook Failures]]
* [[Playbook failure diagnosis pattern]]
* [[Troubleshooting Ansible module issues]]
Q: What steps would you take to troubleshoot a failed Ansible playbook?
A: Steps include:
* Examining playbook output for error messages.
* Reviewing log files on target hosts.
* Enabling verbose mode (-vvv) for detailed information.
* Validating syntax using ansible-playbook --syntax-check.
* Checking variable values and data.
Example: assert: that: ansible_memtotal_mb >= 1024 fail_msg: 'Insufficient memory' — validates preconditions before proceeding with the playbook.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Troubleshooting Ansible module issues]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
* [[What steps would you take to debug an issue with Ansible Container?]]
<html><code>ansible_ssh_common_args</code></html> appends extra arguments to every SSH-based connection Ansible makes — including <html><code>ssh</code></html>, <html><code>sftp</code></html>, and <html><code>scp</code></html> transports. Because it applies globally, it is the standard mechanism for injecting connection-level options that must be consistent across all targeted hosts.
Common use case: routing connections through a bastion (jump) host to reach hosts on private subnets. This is done by setting the variable to <html><code>-o ProxyJump=bastion.example.com</code></html> or <html><code>-o ProxyCommand=...</code></html> in inventory or group_vars.
Example inventory snippet:
<html><pre><code class="language-yaml">ansible_ssh_common_args: '-o ProxyJump=bastion.example.com'</code></pre></html>
Other typical values include custom identity files, <html><code>StrictHostKeyChecking=no</code></html> in lab environments, or connection timeout overrides (<html><code>-o ConnectTimeout=10</code></html>).
The variable can be set at the host level, group level, or globally in <html><code>ansible.cfg</code></html> (<html><code>ssh_args</code></html> under <html><code>[ssh_connection]</code></html>). Host-level values override group-level values following normal Ansible variable precedence.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you set up a jump host (bastion) in Ansible?]]
* [[Ansible SSH pipelining reduces connection round-trips]]
* [[What connection type does ansible-pull use?]]
Writing clean and maintainable Ansible code requires attention to structure, safety, and reusability.
''Structure and modularity:'' Use roles to modularize and reuse code. Organize playbooks with clear structure and naming conventions. Use meaningful task names so intent is self-documenting.
''Variables and values:'' Avoid hardcoded values; use variables throughout. Keep secrets encrypted with Ansible Vault rather than storing them in plaintext.
''Idempotence and testing:'' Ensure tasks are idempotent — running a playbook multiple times must produce the same result. Test automation in a staging environment before production. Use check mode (<html><code>--check</code></html>) for dry-run validation.
''Code quality:'' Maintain proper YAML formatting; indentation is syntactically significant in YAML (use 2-space indent consistently — a single misindent can change task behavior or cause a syntax error). Document tasks and variables.
''Version control:'' Store all playbooks in version control to track changes, enable collaboration, and support rollback.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Troubleshooting Playbook Failures]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
Q: Explain the use of Ansible roles in network automation.
A: Ansible roles in network automation help organize and modularize tasks. Roles can encapsulate configurations, templates, and tasks specific to network devices, making it easier to reuse and share automation code.
Remember: a role is a self-contained bundle: tasks/, handlers/, templates/, files/, defaults/, vars/, meta/. Think 'reusable Ansible package.'
Example: ansible-galaxy init myrole scaffolds the directory structure. Share roles via Galaxy or private Git repos.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Explain the difference between tasks, handlers, and defaults in an Ansible Role.]]
* [[Ansible Galaxy: community hub for roles and collections]]
* [[Roles standardize reusable automation into a predictable directory structure]]
Q: What is the difference between an Ansible playbook and a role?
A: A playbook is a YAML file that defines automation tasks to run on hosts.
A role is a structured way to organize and reuse playbook content.
Playbook:
* Entry point for Ansible execution
* Defines which hosts to target
* Contains plays with tasks, handlers, variables
* Can be a single file or include others
Role:
* Standardized directory structure
* Reusable, self-contained automation unit
* Automatically loads files from specific directories
* Can be shared via Ansible Galaxy
Remember: a role is a self-contained bundle: tasks/, handlers/, templates/, files/, defaults/, vars/, meta/. Think 'reusable Ansible package.'
Example: ansible-galaxy init myrole scaffolds the directory structure. Share roles via Galaxy or private Git repos.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 7 source atoms.//
''Related atoms''
* [[Playbook files contain nested structures that are not visually distinct]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
* [[Ansible playbook architecture: plays, tasks, roles]]
A role is a directory structure containing tasks, handlers, templates, files, variables, and metadata—everything needed for a reusable function (e.g., install and configure nginx). Roles standardize organization: <html><code>roles/webserver/tasks/main.yml</code></html> for logic, <html><code>roles/webserver/templates/</code></html> for Jinja2 templates, <html><code>roles/webserver/defaults/main.yml</code></html> for low-precedence variables, <html><code>roles/webserver/vars/main.yml</code></html> for high-precedence variables. Roles can declare dependencies in <html><code>meta/main.yml</code></html>, ensuring prerequisite roles run first. Roles are imported into playbooks with a simple list, making complex configurations readable and reusable across projects.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
* <html><code>training/library/topics/ansible-deep-dive/primer.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ANSIBLE_ROLES_PATH`?]]
* [[Explain the role of Ansible Facts in playbooks and how to debug them.]]
* [[Explain the role of Ansible Tower in a CI/CD pipeline.]]
Roles package automation logic into self-contained, reusable units following a standard directory structure: defaults/main.yml (lowest-precedence variables and documentation), tasks/main.yml (the work), handlers/main.yml (notified tasks), templates/ (Jinja2 templates), files/ (static files), vars/main.yml (higher-precedence variables), meta/main.yml (dependencies). This structure decouples role logic from inventory and playbooks. A playbook imports a role by name; the role discovers its dependencies and applies defaults, making the caller's playbook short and declarative. Roles enable sharing: a well-factored role can deploy an application across projects without modification. The directory convention means role users can quickly understand structure without documentation.
----
''Sources''
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
''Related atoms''
* [[What is the standard role directory structure?]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
* [[Explain the use of Ansible roles in network automation.]]
Handlers are special Ansible tasks that execute only when explicitly notified by another task, and only once per play regardless of how many times they are notified. They are designed for actions that should occur once after one or more changes — most commonly restarting or reloading a service after configuration file updates.
How they work:
# A regular task uses <html><code>notify:</code></html> to signal a named handler when it reports a change.
# All pending handlers run at the end of the play, in the order they are defined — not the order they were notified.
# Each handler runs at most once per play, even if notified by multiple tasks.
Key differences from regular tasks:
* Regular tasks always run (unless <html><code>when:</code></html> conditions prevent it); handlers run only when notified.
* Handlers are deduped: multiple notifications collapse into a single execution.
* Handlers execute after all tasks in the play have completed, not inline.
To force immediate handler execution before the end of the play, insert <html><code>meta: flush_handlers</code></html> at the desired point in the task list.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-ops.tsv</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible execution hierarchy: playbook > play > task; roles bundle and reuse]]
* [[Can a handler notify another handler?]]
* [[Idempotence is the core contract of Ansible modules]]
Q: What are some best practices for effective debugging and troubleshooting with Ansible?
A: Best practices include:
* Using the debug module for variable inspection.
* Enabling verbose mode with -vvv for detailed output.
* Breaking down playbooks into smaller tasks for targeted debugging.
* Leveraging Ansible facts for dynamic information.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you enable verbose mode for Ansible playbooks?]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[What steps would you take to debug an issue with Ansible Container?]]
Q: What are some common pitfalls in Ansible, and how can they be avoided?
A: Common pitfalls include unhandled errors, inefficient playbook structures, and lack of idempotence. They can be avoided by:
* Proper error handling.
* Structuring playbooks for clarity.
* Ensuring tasks are idempotent.
* Regularly testing playbooks in non-production environments.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Ansible Collections: packaging and distribution format]]
* [[What's your experience with Ansible?]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
Q: How do you install and configure Ansible Tower?
A: Ansible Tower is installed by following the installation guide provided by Red Hat. It involves downloading the installer, running the installation playbook, and configuring settings. Tower settings are configured using the web interface after installation.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is the syntax for an Ansible Playbook?]]
* [[Explain the key components of Ansible.]]
* [[What is the purpose of an Ansible Playbook?]]
Q: What is Ansible Tower, and how does it differ from Ansible?
A: Ansible Tower is a web-based interface and automation orchestrator for Ansible. It provides a centralized platform for managing and monitoring Ansible automation. While Ansible is the underlying automation engine, Ansible Tower adds features like role-based access control, job scheduling, and a user-friendly interface.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is the purpose of an Ansible Playbook?]]
* [[Explain the key components of Ansible.]]
* [[What is YAML, and why is it used in Ansible?]]
Q: How do you pass variables to Ansible at runtime?
A: You can use the -e flag (extra vars) on the command line, e.g., ansible-playbook play.yml -e "var1=value1 var2=value2".
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Where can variables be defined?]]
* [[Variables set in one play don't automatically carry to the next play]]
* [[What are "magic variables" in Ansible?]]
Q: How do you define variables in Ansible Playbooks?
A: Variables in Ansible Playbooks can be defined in various ways, including:
* Inline: {{ variable_name }} within tasks.
* In a separate YAML file and included using vars_files.
* In the vars section of a playbook.
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Ansible variable precedence: bookends and gradient]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[What are "magic variables" in Ansible?]]
Q: How do you print the values of variables in Ansible playbooks for debugging purposes?
A: Use the debug module to print variable values. Example:
<html><pre><code class="language-yaml">- name: Print variable value
debug:
var: variable_name</code></pre></html>
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How to find out the data type of a certain variable in one of the playbooks?]]
* [[What are variables in Ansible?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
Q: What kind of automation you wouldn't do with Ansible and why?
A: While it's possible to provision resources with Ansible, some prefer to use tools that follow immutable infrastructure paradigm.
Ansible doesn't save state by default. So a task that creates 5 instances for example, when executed again will create additional 5 instances (unless
additional check is implemented or explicit names are provided) while other tools might check if 5 instances exist. If only 4 exist (by checking the state file for example), one additional instance will be created to reach the end goal of 5 instances.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
* [[How do you approach automating repetitive tasks in a data center?]]
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
Ansible Galaxy is a public hub for sharing and downloading reusable roles. To install a single role directly:
<html><pre><code class="language-bash">ansible-galaxy install author_name.role_name</code></pre></html>
Example: <html><code>ansible-galaxy install geerlingguy.docker</code></html> installs a community-maintained Docker role.
To install multiple roles at once — and pin specific versions for reproducible builds — declare them in a <html><code>requirements.yml</code></html> file and run:
<html><pre><code class="language-bash">ansible-galaxy install -r requirements.yml</code></pre></html>
A <html><code>requirements.yml</code></html> entry looks like:
<html><pre><code class="language-yaml">- name: geerlingguy.docker
version: "6.1.0"</code></pre></html>
Using <html><code>requirements.yml</code></html> is the recommended practice for any shared or production playbook, as it ensures every collaborator and CI run installs the same role versions.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
* [[Roles organize reusable Ansible code into directories]]
* [[What is a requirements.yml file for Galaxy?]]
Q: Explain the purpose of the --diff option in Ansible playbooks.
A: The --diff option shows the differences between the current and desired state of files being managed by Ansible. It's useful for understanding changes made during playbook execution.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[True or False? Ansible follows the mutable infrastructure paradigm]]
* [[What is the purpose of an Ansible Playbook?]]
* [[Ansible dry run: --check and --diff for safe change preview]]
Q: When the value '2017'' will be used in this case: <html><code>{{ lookup('env', 'BEST_YEAR') | default('2017', true) }}</code></html>?
A: when the environment variable 'BEST_YEAR' is empty or false.
Example: lookup('file', '/path/to/file') reads a file. lookup('env', 'HOME') reads an environment variable. lookup('pipe', 'date') runs a command. Lookups execute on the control node.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What does the `default` filter do?]]
* [[What is the `lookup` plugin?]]
* [[What Jinja2 filter returns a default value when a variable is undefined?]]
Q: Explain the use of the "ec2.py" script for AWS dynamic inventory.
A: The "ec2.py" script is a dynamic inventory script for AWS in Ansible. It queries AWS API to dynamically generate inventory information, including EC2 instances and their attributes. It enables dynamic and automatic inclusion of AWS resources in Ansible playbooks.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What language are Ansible playbooks written in?]]
* [[Ansible Collections: packaging and distribution format]]
* [[What is the purpose of an Ansible Playbook?]]
Q: What is Ansible Tower Surveys, and how do they work?
A: Ansible Tower Surveys are forms that prompt users for input when launching job templates. They allow dynamic input, making playbook runs customizable. Users provide values for survey questions, influencing the behavior of the playbook.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What happens if you use `vars_prompt` in Ansible Tower/Controller?]]
* [[How do you install and configure Ansible Tower?]]
* [[What is the purpose of an Ansible Playbook?]]
Q: How does Ansible differ from other configuration management tools?
A: Ansible is agentless, relying on SSH for communication, making it easy to deploy. It uses YAML for human-readable playbooks, emphasizing simplicity. Ansible also supports multi-tier orchestration and provides a large collection of modules.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What's your experience with Ansible?]]
* [[Ansible Collections: packaging and distribution format]]
* [[What are the key features of Ansible?]]
Q: Explain the difference between tasks, handlers, and defaults in an Ansible Role.
A: * Tasks: Contain the main work to be done. Defined in the tasks directory.
* Handlers: Define actions to be taken based on notifications. Defined in the handlers directory.
* Defaults: Contain default variables for the role. Defined in the defaults directory.
Remember: a role is a self-contained bundle: tasks/, handlers/, templates/, files/, defaults/, vars/, meta/. Think 'reusable Ansible package.'
Example: ansible-galaxy init myrole scaffolds the directory structure. Share roles via Galaxy or private Git repos.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Explain the use of Ansible roles in network automation.]]
* [[What is the standard directory structure of an Ansible role?]]
* [[Ansible playbook architecture: plays, tasks, roles]]
Q: How do you set breakpoints or pause execution within an Ansible role for debugging?
A: Use the pause module to set breakpoints within roles. Example:
<html><pre><code class="language-yaml">- name: Pause for debugging
pause:
minutes: 30</code></pre></html>
Remember: Ansible playbooks should be idempotent — running them twice produces the same result. Use modules (not shell/command) to ensure this.
Gotcha: always test playbooks with --check --diff before applying. This shows what WOULD change without actually changing anything.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Ansible debug module: printing messages during playbook execution]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[What steps would you take to debug an issue within an Ansible role?]]
Q: Describe each of the following components in Ansible, including the relationship between them:
A: Task – a call to a specific Ansible module
Module – the actual unit of code executed by Ansible on your own host or a remote host. Modules are indexed by category (database, file, network, …) and also referred to as task plugins.
Inventory – An inventory file defines hosts and/or groups of hosts on which Ansible tasks executed upon. The inventory file can be in one of many formats, depending on the inventory plugins you have. The most common formats are INI and YAML.
Play – One or more tasks executed on a given host(s)
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is a play in Ansible?]]
* [[What is an Ansible inventory?]]
* [[What are Ansible "playbooks"?]]
Q: What information is available in the output when using the --check option?
A: The output includes information about tasks that would be changed, added, or removed if the playbook were run normally. It helps identify what actions Ansible would take without actually applying them.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Check mode simulates changes without executing destructive operations]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
The <html><code>template</code></html> module processes a Jinja2 template file on the control node and deploys the rendered result to managed nodes. It supports variable substitution, conditionals, and Jinja2 filters, making it well-suited for generating dynamic configuration files.
Example: a template referencing <html><code>{{ ansible_hostname }}-{{ ansible_date_time.date }}.log</code></html> renders to <html><code>web01-2026-03-21.log</code></html>. Filters transform values inline: <html><code>{{ name | upper }}</code></html>.
Gotcha: always quote Jinja2 expressions in YAML — <html><code>name: '{{ var }}'</code></html>. An unquoted <html><code>{{</code></html> at the start of a YAML value breaks parsing because YAML interprets it as a mapping.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
* [[Jinja2 Whitespace Control Prevents Extra Blank Lines]]
Q: Explain the use of the "hosts" directive in a playbook.
A: The hosts directive in a playbook specifies the target hosts or groups where the playbook tasks should be executed. It can be a single host, a group of hosts, or the special group "all" for all hosts.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is the purpose of an Ansible Playbook?]]
* [[What is the syntax for an Ansible Playbook?]]
* [[What does the `hosts` keyword define in a play?]]
Q: What would be the result of the following play?
A: <html><pre><code class="language-plaintext">---
- name: Print information about my host
hosts: localhost
gather_facts: 'no'
tasks:
- name: Print hostname
debug:
msg: "It's me, {{ ansible_hostname }}"</code></pre></html>
When given a written code, always inspect it thoroughly. If your answer is “this will fail” then you are right. We are using a fact (ansible_hostname), which is a gathered piece of information from the host we are running on. But in this case, we disabled facts gathering (gather_facts: no) so the variable would be undefined which will result in failure.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Ansible facts: auto-discovered host variables]]
* [[One slow host blocks the entire play during fact gathering]]
* [[What module gathers facts by default at the start of each play?]]
Q: Explain the role of Ansible Tower in a CI/CD pipeline.
A: Ansible Tower plays a crucial role in CI/CD by providing a centralized platform for orchestrating and managing automation tasks. It integrates with version control systems, triggers playbooks based on events, and allows for the creation of workflows that automate deployment and testing processes.
Remember: a role is a self-contained bundle: tasks/, handlers/, templates/, files/, defaults/, vars/, meta/. Think 'reusable Ansible package.'
Example: ansible-galaxy init myrole scaffolds the directory structure. Share roles via Galaxy or private Git repos.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is the difference between an Ansible playbook and a role?]]
* [[Roles organize reusable Ansible code into directories]]
* [[Explain the role of Ansible Facts in playbooks and how to debug them.]]
Q: How to find out the data type of a certain variable in one of the playbooks?
A: {{ some_var | type_debug }}
Under the hood: type_debug outputs the Python type name (str, int, list, dict, etc.). Invaluable for debugging when a variable is unexpectedly a string instead of a list or integer.
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
* [[How do you define variables in Ansible Playbooks?]]
* [[How do you pass variables to Ansible at runtime?]]
Q: If the value of certain variable is 1, you would like to use the value "one", otherwise, use "two". How would you do it?
A: <html><code>{{ (certain_variable == 1) | ternary("one", "two") }}</code></html>
Under the hood: ternary is a Jinja2 filter that acts like a C-style ternary operator: condition | ternary(true_val, false_val). Useful for concise conditional assignments in templates.
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you write a conditional in Jinja2?]]
* [[What is the `ternary` filter?]]
* [[How do you use variables in Jinja2 templates?]]
Q: True or False? Ansible uses declarative style to describe the expected end state
A: False. It uses a procedural style.
Under the hood: tasks execute top-to-bottom (procedural), unlike Terraform which builds a dependency graph (declarative). Individual modules like apt with state=present behave declaratively.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What information is available in the output when using the --check option?]]
* [[How do you enable verbose mode for Ansible playbooks?]]
* [[Ansible Collections: packaging and distribution format]]
Q: True or False? Ansible follows the mutable infrastructure paradigm
A: True. In immutable infrastructure approach, you'll replace infrastructure instead of modifying it.
Ansible rather follows the mutable infrastructure paradigm where it allows you to change the configuration of different components, but this approach is not perfect and has its own disadvantages like "configuration drift" where different components may reach different state for different reasons.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Explain the purpose of the --diff option in Ansible playbooks.]]
* [[What is YAML, and why is it used in Ansible?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
Q: How do you enable verbose mode for Ansible playbooks?
A: Verbose mode for Ansible playbooks can be enabled using the -v, -vv, or -vvv options with the ansible-playbook command. It increases the verbosity of output, providing more details during playbook execution.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the syntax for an Ansible Playbook?]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
Q: What steps would you take to debug an issue within an Ansible role?
A: Steps include:
* Adding debug tasks to print variable values.
* Using the --start-at-task option to isolate problematic tasks.
* Setting breakpoints with pause or fail for interactive debugging.
Remember: a role is a self-contained bundle: tasks/, handlers/, templates/, files/, defaults/, vars/, meta/. Think 'reusable Ansible package.'
Example: ansible-galaxy init myrole scaffolds the directory structure. Share roles via Galaxy or private Git repos.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you set breakpoints or pause execution within an Ansible role for debugging?]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
* [[Roles organize reusable Ansible code into directories]]
Q: Explain the role of Ansible Facts in playbooks and how to debug them.
A: Ansible Facts provide information about target systems. Debug them by printing facts with debug tasks or using the -vvv option for increased verbosity.
Remember: a role is a self-contained bundle: tasks/, handlers/, templates/, files/, defaults/, vars/, meta/. Think 'reusable Ansible package.'
Example: ansible-galaxy init myrole scaffolds the directory structure. Share roles via Galaxy or private Git repos.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Roles organize reusable Ansible code into directories]]
* [[Explain the use of Ansible roles in network automation.]]
* [[Roles standardize reusable automation into a predictable directory structure]]
The <html><code>--check</code></html> flag performs a dry run without making actual changes; <html><code>--diff</code></html> shows exactly what would be modified. Together:
<html><pre><code class="language-bash">ansible-playbook site.yml --check --diff</code></pre></html>
This previews exact state changes before committing them to production. It is especially useful for file-modification tasks — <html><code>lineinfile</code></html>, <html><code>template</code></html>, and <html><code>copy</code></html> modules display their exact diffs in this mode.
''Caveats:''
* <html><code>--check</code></html> does not guarantee accuracy. Modules that depend on the result of a previous task may report incorrect changes, because earlier tasks did not actually run.
* <html><code>command</code></html> and <html><code>shell</code></html> modules do not support check mode reliably — they cannot predict whether they would change the system without executing.
''Best practice:'' Design playbooks using native idempotent modules (<html><code>apt</code></html>, <html><code>service</code></html>, <html><code>file</code></html>, <html><code>template</code></html>, etc.) rather than raw commands to ensure reliable check-mode behavior. Adopt check mode as a default pre-deployment workflow: preview first, apply second.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/primer.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What information is available in the output when using the --check option?]]
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[Explain the purpose of the --diff option in Ansible playbooks.]]
Q: How do you structure a good playbook or role?
A: Small, predictable roles. Defaults for variables, handlers for restarts, and clear separation of tasks, files, and templates. Idempotency first. Fail fast with clear messages. Reusability over cleverness.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you include roles in a playbook?]]
* [[What is the difference between an Ansible playbook and a role?]]
* [[Name three strategies to keep playbooks DRY.]]
The <html><code>debug</code></html> module prints messages during Ansible playbook execution. It is the standard tool for troubleshooting: surfacing variable values, confirming task flow, or emitting custom diagnostic output.
Example:
<html><pre><code class="language-yaml">- name: Print debug message
debug:
msg: "This is a debug message."</code></pre></html>
The <html><code>msg</code></html> parameter accepts plain strings or Jinja2 expressions, making it useful for inspecting variable state at any point in a play. The module produces no changes on managed hosts — it is output-only.
Gotcha: YAML indentation is significant in playbooks. Use 2-space indentation consistently. A single misaligned line can alter a task's behavior or produce a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
* [[What language are Ansible playbooks written in?]]
Q: Explain the importance of version control with Ansible playbooks.
A: Version control is crucial for tracking changes, collaborating with teams, and ensuring reproducibility. It allows rollbacks to previous versions, collaboration among team members, and proper management of code changes over time.
Remember: import_* = static (parsed at playbook load). include_* = dynamic (parsed at runtime). Use import for roles, include for conditional logic.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you handle version control for playbooks?]]
* [[Structured Playbooks Provide Auditability and Idempotency]]
* [[What are Ansible "playbooks"?]]
Q: How can you run a specific task or play within an Ansible playbook for testing?
A: Use tags to run specific tasks or plays. Example:
<html><pre><code class="language-bash">ansible-playbook playbook.yml --tags=tag_name</code></pre></html>
Gotcha: if a task's tag is not explicitly listed in --tags, it is skipped entirely. Use the special 'always' tag for tasks that must execute regardless of filtering.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Playbook files contain nested structures that are not visually distinct]]
* [[What information is available in the output when using the --check option?]]
* [[How do you test Ansible safely?]]
Q: What is an Ansible playbook execution plan, and how can you generate it?
A: An execution plan provides a summary of tasks that would be executed. Generate it using the --list-tasks option. Example:
<html><pre><code class="language-bash">ansible-playbook playbook.yml --list-tasks</code></pre></html>
Gotcha: combine --list-tasks with --tags to see which tasks would run with your tag filter, without executing anything. Great for verifying tag coverage before running on production.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible debug module: printing messages during playbook execution]]
* [[What command runs an Ansible playbook?]]
* [[What language are Ansible playbooks written in?]]
Q: How can you use tags in Ansible Roles?
A: Tags in Ansible Roles allow selective execution of tasks. Tags are defined in the tasks themselves, and you can run only tasks with specific tags using the --tags option during playbook execution.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is the syntax for an Ansible Playbook?]]
* [[What is the purpose of an Ansible Playbook?]]
* [[Playbook files contain nested structures that are not visually distinct]]
Ansible Collections are a distribution format that packages modules, roles, plugins, playbooks, and documentation together in a structured layout. They provide a more comprehensive and self-contained unit than individual roles, enabling efficient organization and distribution of automation code—particularly useful in complex environments.
Collections can be installed from Ansible Galaxy or private automation hubs and referenced in playbooks via fully qualified collection names (FQCNs), e.g., <html><code>namespace.collection.module_name</code></html>.
Gotcha: YAML indentation matters throughout Ansible playbooks and collection content. Use 2-space indentation consistently. A single incorrect indent can silently alter a task's behavior or trigger a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[How does Ansible differ from other configuration management tools?]]
* [[What are some common pitfalls in Ansible, and how can they be avoided?]]
Q: Write a playbook to deploy the file ‘/tmp/system_info’ on all hosts except for controllers group, with the following content
A: <html><pre><code class="language-plaintext"> I'm <HOSTNAME> and my operating system is <OS>
</code></pre></html>
Replace <HOSTNAME> and <OS> with the actual data for the specific host you are running on
The playbook to deploy the system_info file
<html><pre><code class="language-plaintext">---
- name: Deploy /tmp/system_info file
hosts: all:!controllers
tasks:
- name: Deploy /tmp/system_info
template:
src: system_info.j2
dest: /tmp/system_info</code></pre></html>
The content of the system_info.j2 template
<html><pre><code class="language-plaintext"># {{ ansible_managed }}
I'm {{ ansible_hostname }} and my operating system is {{ ansible_distribution }</code></pre></html>
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is the syntax for an Ansible Playbook?]]
* [[Write a playbook to install ‘zlib’ and ‘vim’ on all hosts if the file ‘/tmp/mario’ exis…]]
* [[Ansible debug module: printing messages during playbook execution]]
Q: Modify the following task to use a variable instead of the value "zlib" and have "zlib" as the default in case the variable is not defined
A: <html><pre><code class="language-plaintext">- name: Install a package
package:
name: "{{ package_name|default('zlib') }}"
state: present</code></pre></html>
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you define variables in Ansible Playbooks?]]
* [[How do you pass variables to Ansible at runtime?]]
* [[Write a playbook to install ‘zlib’ and ‘vim’ on all hosts if the file ‘/tmp/mario’ exis…]]
Q: How to make the variable "use_var" optional?
A: With "default(omit)"
<html><pre><code class="language-plaintext">- name: Install a package
package:
name: "zlib"
state: present
use: "{{ use_var|default(omit) }}"</code></pre></html>
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you define variables in Ansible Playbooks?]]
* [[What is the `omit` variable in Ansible?]]
* [[What does the `mandatory` filter do?]]
Q: Write a filter to capitalize a string
A: <html><pre><code class="language-plaintext">def cap(self, string):
return string.capitalize()</code></pre></html>
Under the hood: custom Jinja2 filters are Python functions placed in a filter_plugins/ directory alongside your playbook. Ansible auto-discovers them at runtime.
Remember: useful Jinja2 filters: default('fallback'), join(','), replace('old','new'), regex_replace, to_yaml, to_json, combine (merge dicts). Filters chain: {{ var | lower | trim }}.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you create a custom Jinja2 filter for Ansible?]]
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
Q: Write a playbook to install ‘zlib’ and ‘vim’ on all hosts if the file ‘/tmp/mario’ exists on the system.
A: <html><pre><code class="language-plaintext">---
- hosts: all
vars:
mario_file: /tmp/mario
package_list:
- 'zlib'
- 'vim'
tasks:
- name: Check for mario file
stat:
path: "{{ mario_file }}"
register: mario_f
- name: Install zlib and vim if mario file exists
become: "yes"
package:
name: "{{ item }}"
state: present
with_items: "{{ package_list }}"
when: mario_f.stat.exists</code></pre></html>
Note: with_items still works but <html><code>loop:</code></html> is preferred since Ansible 2.5.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Write a playbook to deploy the file ‘/tmp/system_info’ on all hosts except for controll…]]
* [[Write a single task that verifies all the files in files_list variable exist on the host]]
* [[How can you run a specific task or play within an Ansible playbook for testing?]]
Q: What makes good Ansible?
A: Good Ansible code follows these principles:
''Idempotent'': Running twice produces same result as running once. No "changed" on second run if state is correct.
''Readable'': Clear task names, organized variables, logical role structure. Future you (or your team) must understand it.
''Minimal conditionals'': If you have <html><code>when:</code></html> everywhere, your inventory structure is probably wrong.
''Clear variables'': Good naming, appropriate scope (group_vars vs host_vars), documented defaults.
''No shell unless necessary'': Shell/command modules break idempotence. Use proper modules first.
''Tested'': Syntax checks, dry-runs, molecule tests for roles.
Bad Ansible is just scripting with extra steps.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How do you test Ansible safely?]]
* [[Prefer native modules over shell/command for idempotency]]
* [[Variable precedence: learn role defaults and extra vars, not all 22 levels]]
Q: What is Ansible Container, and how does it integrate with Docker?
A: Ansible Container is an extension for managing containerized applications using Ansible. It allows defining container specifications in Ansible playbooks. Integration with Docker involves using Ansible to define Docker container configurations, build images, and deploy containers.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[How does Ansible interact with Docker?]]
* [[What is the purpose of an Ansible Playbook?]]
* [[Explain the key components of Ansible.]]
Q: How do you test Ansible safely?
A: Multiple layers of safety:
''Syntax and lint'':
<html><pre><code class="language-bash">ansible-playbook --syntax-check playbook.yml
ansible-lint playbook.yml</code></pre></html>
''Dry-run (check mode)'':
<html><pre><code class="language-bash">ansible-playbook --check --diff playbook.yml</code></pre></html>
Shows what WOULD change without doing it.
''Target safely'':
* Non-prod environments first
* Small batches: <html><code>--limit 'web[0:2]'</code></html>
* Serial execution for risky changes: <html><code>serial: 1</code></html>
''Role testing with Molecule'':
<html><pre><code class="language-bash">molecule test</code></pre></html>
Spins up containers, applies role, runs verification.
''Canary deployments'': Run on one host, verify, then expand.
Gotcha: YAML indentation matters in playbooks. Use 2-space indent consistently. A single wrong indent can change a task's behavior or cause a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What makes good Ansible?]]
* [[Check mode simulates changes without executing destructive operations]]
* [[Molecule: Ansible role testing framework]]
Q: Explain the Difference between Forks and Serial & Throttle.
A: <html><code>Serial</code></html> is like running the playbook for each host in turn, waiting for completion of the complete playbook before moving on to the next host. <html><code>forks</code></html>=1 means run the first task in a play on one host before running the same task on the next host, so the first task will be run for each host before the next task is touched. Default fork is 5 in ansible.
<html><pre><code class="language-plaintext">[defaults]
forks = 30</code></pre></html>
<html><pre><code class="language-plaintext">- hosts: webservers
serial: 1
tasks:
- name: ...</code></pre></html>
Ansible also supports <html><code>throttle</code></html> This keyword limits the number of workers up to the maximum set via the forks setting or serial. This can be useful in restricting tasks that may be CPU-intensive or interact with a rate-limiting API
<html><pre><code class="language-plaintext">tasks:
- command: /path/to/cpu_intensive_command
throttle: 1</code></pre></html>
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[What is the `forks` setting, and what is its default value?]]
* [[What is the `throttle` keyword?]]
* [[Forks control Ansible parallelism]]
Q: The variable 'whoami' defined in the following places:
A: The answer is 'toad'. Ansible variable precedence (lowest to highest, simplified):
# Role defaults
# Inventory vars (group_vars, host_vars)
# Play vars, vars_files, vars_prompt
# Task vars, block vars
# Role params
# set_fact / registered vars
# Extra vars (-e on CLI) — always win
Rule of thumb: More specific scope beats less specific. CLI extra vars override everything.
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Ansible variable precedence footguns]]
* [[How do you define variables in Ansible Playbooks?]]
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
Ansible added Windows support in version 1.7 (2014) by using WinRM (Windows Remote Management) as the control transport instead of SSH. This allows a Linux-native, Python/SSH-based tool to target Windows hosts without reimplementing the communication layer — the module abstraction layer translates playbook semantics and variable handling to WinRM transparently.
To configure: enable WinRM on Windows hosts, install the <html><code>pywinrm</code></html> Python module on the [[Ansible control node]], and set <html><code>ansible_connection=winrm</code></html> in inventory. Ansible ships with over 200 Windows-specific modules covering domains such as IIS configuration (<html><code>win_feature</code></html>), Active Directory management, and Windows service control (<html><code>win_service</code></html>, <html><code>win_copy</code></html>, etc.), making it capable of managing heterogeneous infrastructure from a single control plane.
Gotcha: YAML indentation in playbooks must be consistent (2-space indent recommended). A single misplaced indent can silently alter a task's behavior or produce a syntax error.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
* <html><code>training/library/topics/ansible/trivia.md</code></html>
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Can you run Ansible on Windows as a control node?]]
* [[Have you used automation tools like PowerShell or Ansible for server management tasks?]]
* [[Ansible control node]]
Q: How do you include external tasks in an Ansible Playbook?
A: External tasks can be included using the include_tasks or import_tasks directives. For example:
<html><pre><code class="language-yaml">- name: Include external tasks
include_tasks: tasks/external_tasks.yml</code></pre></html>
Remember: import_* = static (parsed at playbook load). include_* = dynamic (parsed at runtime). Use import for roles, include for conditional logic.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Playbook execution flows through pre_tasks, roles, tasks, post_tasks with distinct import/include behavior]]
* [[What is the difference between `include_tasks` and `import_tasks`?]]
* [[Playbook files contain nested structures that are not visually distinct]]
Q: Write a single task that verifies all the files in files_list variable exist on the host
A: <html><pre><code class="language-plaintext">- name: Ensure all files exist
assert:
that:
- item.stat.exists
loop: "{{ files_list }}"</code></pre></html>
Remember: variable precedence (low to high): defaults, inventory, playbook, role vars, extra vars (-e). Extra vars always win.
----
''Sources''
* <html><code>training/interactive/knowledge/data/cards/ansible-playbooks.tsv</code></html>
''Related atoms''
* [[Write a playbook to install ‘zlib’ and ‘vim’ on all hosts if the file ‘/tmp/mario’ exis…]]
* [[File '/tmp/exercise' includes the following content]]
* [[List all 22 variable precedence levels from lowest to highest.]]
Ansible automates configuration management, application deployment, and orchestration of systems that already exist. It differs fundamentally from Terraform, which creates infrastructure itself (VMs, networks, storage). Ansible manages what's already running: installing packages, templating config files, deploying applications, and enforcing system state idempotently. This distinction matters for tool selection: use Terraform to provision cloud instances, then Ansible to configure them.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
''Related atoms''
* [[What is the `cloud.terraform` collection?]]
* [[Ansible in a Multi-Cloud Environment]]
* [[How does Ansible differ from other configuration management tools?]]
A playbook is a YAML file containing one or more plays, each targeting a group of hosts and defining the desired system state via an ordered list of tasks. Each task runs a module with specific parameters. Modules are idempotent by design; they check current state and only make changes if needed. A playbook is declarative—you specify "nginx should be installed and running," not "download nginx, compile it, start the service." The task order matters: earlier tasks create prerequisites for later ones. Handlers allow tasks to notify event-driven actions (like restarting a service) that run once at the end of a play, even if notified multiple times.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
''Related atoms''
* [[What are Ansible "playbooks"?]]
* [[Ansible execution hierarchy: playbook > play > task; roles bundle and reuse]]
* [[Prefer native modules over shell/command for idempotency]]
Q: How do you start a playbook at a specific task?
A: <html><code>ansible-playbook playbook.yml --start-at-task "Install Nginx"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command runs an Ansible playbook?]]
* [[How can you run a specific task or play within an Ansible playbook for testing?]]
* [[What is a task in Ansible?]]
Handlers are tasks that run only when notified by other tasks and deduplicate across multiple notifications—even if five tasks notify "Restart nginx," the handler runs only once at the end of the play. This pattern ensures idempotent deployments: a template change, certificate update, and config modification can all notify the same handler without restarting nginx three times. Handlers are declared in a <html><code>handlers:</code></html> section of a playbook or role and triggered via <html><code>notify:</code></html> in a task. Handlers run in the order they are defined, not the order they were notified.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
''Related atoms''
* [[What happens if a handler is notified multiple times?]]
* [[Playbooks express desired state through ordered tasks]]
* [[Ansible handlers skip entirely if the play fails]]
Roles can declare dependencies in <html><code>meta/main.yml</code></html> (e.g., role A depends on role C). If multiple roles depend on the same role, Ansible runs it only once by default (controlled by <html><code>allow_duplicates: true</code></html> if you need otherwise). However, Ansible has no built-in version resolution: if role A needs <html><code>package-x >= 2.0</code></html> and role B needs <html><code>package-x < 2.0</code></html>, both cannot be satisfied. Use <html><code>ansible-galaxy install -r requirements.yml</code></html> with pinned versions to manage dependencies explicitly. A typical requirements.yml pins role versions: <html><code>- { role: geerlingguy.nginx, version: 3.1.0 }</code></html>. Update with <html><code>--force</code></html> flag.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
''Related atoms''
* [[Ansible Galaxy: community hub for roles and collections]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
* [[Roles organize reusable Ansible code into directories]]
To verify a playbook is idempotent, run it twice consecutively against the same target. The first run will show changed tasks; the second run must show all tasks as "ok" (0 changed). If anything shows "changed" on the second run, you have an idempotency bug. Common culprits: <html><code>shell:</code></html> or <html><code>command:</code></html> tasks without guards, <html><code>lineinfile:</code></html> with dynamic values (like timestamps) that change on each run, or tasks that always write output even when content hasn't changed. Use <html><code>creates:</code></html> parameter for command tasks, use <html><code>regexp:</code></html> in lineinfile to match existing lines, and validate that file content actually differs before reporting changed.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
''Related atoms''
* [[Idempotence is the core contract of Ansible modules]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
* [[Idempotent tasks use built-in modules or changed_when predicates]]
The <html><code>validate:</code></html> parameter on Ansible's <html><code>template:</code></html> and <html><code>copy:</code></html> modules runs a syntax checker against a temporary copy of the file before it is written to its final destination. If validation fails, the original file is untouched, preventing partial or corrupted configs from being deployed.
Always use <html><code>validate:</code></html> for config files that have syntax checkers:
* nginx: <html><code>nginx -t -c %s</code></html>
* Apache: <html><code>apachectl configtest</code></html>
* sshd: <html><code>sshd -t -f %s</code></html>
* sudoers: <html><code>visudo -cf %s</code></html>
Example: <html><code>template: src=nginx.conf.j2 dest=/etc/nginx/nginx.conf validate='nginx -t -c %s'</code></html>
Without validation, a broken template silently overwrites <html><code>/etc/nginx/nginx.conf</code></html> across every server in a single playbook run. The restart handler then attempts to restart nginx with invalid config, taking down the entire web tier simultaneously. Recovery requires manual intervention on every affected host. With <html><code>validate:</code></html>, the broken config is detected before any file is written and the original is preserved. Prevention costs one parameter.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible ios_command is not idempotent for configuration]]
* [[Prefer native modules over shell/command for idempotency]]
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
Each play in a playbook has its own variable scope. A variable set in play 1 (via <html><code>set_fact:</code></html> or task output) is not visible in play 2 unless explicitly made global. Use <html><code>set_fact:</code></html> to persist a variable across tasks within a single play. For variables that must survive across plays, define them in <html><code>host_vars/</code></html>, <html><code>group_vars/</code></html>, or inventory. Variables passed via <html><code>-e</code></html> (extra vars) are global and override everything, making them suitable for temporary overrides but dangerous for regular config. Clarify variable scope in playbook documentation to prevent hidden dependencies between plays.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
''Related atoms''
* [[What is `set_fact`?]]
* [[How do you pass variables to Ansible at runtime?]]
* [[Can you set variables with magic variable names?]]
Ansible's privilege escalation operates in two distinct stages. First, connect to the target host via SSH as <html><code>ansible_user</code></html> (defaults to the local username if not set in inventory). Second, escalate privileges via the become chain: <html><code>become: yes</code></html> without <html><code>become_user</code></html> defaults to root; <html><code>become_user: deploy</code></html> escalates to a specific user, provided sudoers permits it.
The SSH connection and the become chain are separate concerns. The SSH user must have sudo access to the target become_user, or escalation fails — often with cryptic errors. Common pattern: SSH as <html><code>ansible_user: ubuntu</code></html>, use <html><code>become: yes</code></html> for package installation and <html><code>/etc</code></html> management, use <html><code>become_user: deploy</code></html> for application deployment and config files.
Apply escalation at the task level rather than globally to avoid unintended privilege grants. To debug escalation failures: verify the sudoers configuration on the target host for the specific (ssh_user, become_user) pair, and test <html><code>sudo -u <become_user></code></html> manually before blaming Ansible.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[become: true Must Be Set at Task Level for Privilege Escalation]]
* [[What happens when you apply `become: true` with the `local` connection?]]
* [[What are Ansible's default privilege escalation methods?]]
By default, Ansible runs tasks on all hosts in a group simultaneously. For services behind a load balancer, simultaneous deployment can cause a full outage if all instances are restarting at once. Use the <html><code>serial:</code></html> parameter to deploy in waves: <html><code>serial: 1</code></html> deploys to one host at a time, <html><code>serial: "25%"</code></html> deploys to 25% of hosts before moving to the next batch. Each wave waits for previous one to complete. Example: with 8 webservers and <html><code>serial: 2</code></html>, Ansible deploys to 2, waits for all tasks in that batch, then deploys to the next 2. Prevents thundering herd and allows quick rollback if a batch fails.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
''Related atoms''
* [[Serial Batching and Max-Failure Limit Contain Rollout Risk]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
* [[What is the "canary deployment" pattern in Ansible?]]
During the <html><code>Gathering Facts</code></html> phase, Ansible waits for all hosts in a play to report their system information. If one host is slow or unreachable, the entire play waits (default timeout ~10 seconds per host). On a 500-host fleet, one problematic host can add minutes of delay. Mitigation: enable fact caching to skip gathering on subsequent runs, use <html><code>gather_facts: no</code></html> at the play level for tasks that don't need facts and gather facts selectively, set <html><code>gather_timeout</code></html> in ansible.cfg to lower timeout threshold, or use <html><code>async:</code></html> for long-running tasks so other hosts don't block.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
''Related atoms''
* [[Optimizing Ansible Playbook Performance]]
* [[Ansible performance optimization for large inventories]]
* [[Ansible Facts and the gather_facts task]]
Rolling out infrastructure changes sequentially through environments — dev, staging, prod-us, prod-eu — catches problems early before they cascade to critical systems. Each environment serves as a validation gate. If an OpenSSL patch causes a service failure or a health check that hangs, you discover it locally, adjust the rollout strategy, and never hit production. The time cost is minimal (dev and staging are fast), but the blast radius reduction is enormous. This pattern treats infrastructure changes the same way code deploys are handled: progressively, with feedback loops at each stage.
----
''Sources''
* <html><code>training/library/topics/ansible/thinking_out_loud.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Safe infrastructure patch rollouts use progressive stages and circuit breakers]]
In Ansible, <html><code>serial</code></html> controls batch size (how many hosts execute simultaneously) and <html><code>max_fail_percentage</code></html> acts as a circuit breaker. Together, they prevent a broken change from rolling across an entire fleet. A typical configuration — <html><code>serial: 25%</code></html> with <html><code>max_fail_percentage: 10</code></html> — processes 25% of targets at a time and aborts the rollout if more than 10% of that batch fail health checks, stopping before the remaining 75% are touched. Without the circuit breaker, a bad patch can partially succeed and leave the fleet in an inconsistent state. Without batching, a fully sequential rollout can take hours. The two controls together balance safety (catch failures early, limit blast radius) with speed (parallel updates within each batch).
----
''Sources''
* <html><code>training/library/topics/ansible/thinking_out_loud.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
Running <html><code>apt upgrade</code></html> on servers one at a time leaves no record, cannot be safely re-run, and scales poorly. A structured Ansible playbook is repeatable, auditable, and idempotent — the procedure is version-controlled, code-reviewed, and reusable for future patches. Automation also enables health checks, pre/post verification, and conditional logic (skip already-patched hosts) without manual state management. For fleets beyond a handful of servers, the investment in playbook infrastructure pays dividends quickly.
----
''Sources''
* <html><code>training/library/topics/ansible/thinking_out_loud.md</code></html>
''Related atoms''
* [[Explain the importance of version control with Ansible playbooks.]]
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[What are Ansible "playbooks"?]]
Deploy infrastructure changes sequentially through dev, staging, then production. Each environment is a checkpoint. Problems caught in dev are fixed before reaching staging; issues caught in staging are resolved before production. This reduces mean time to recovery and prevents a global outage from a single bad patch or misconfiguration.
----
''Sources''
* <html><code>training/library/topics/ansible/thinking_out_loud.md</code></html>
''Related atoms''
* [[Safe infrastructure patch rollouts use progressive stages and circuit breakers]]
Include post-change verification in playbooks: HTTP health endpoints, service status queries, or application-specific tests confirming the service is running and responding correctly. Without verification, an update can appear successful (package installed, service restarted) while the application is actually broken. A service restart that leaves the application unhealthy is worse than a temporary vulnerable-but-working service.
----
''Sources''
* <html><code>training/library/topics/ansible/thinking_out_loud.md</code></html>
''Related atoms''
* [[Structured Playbooks Provide Auditability and Idempotency]]
* [[Safe infrastructure patch rollouts use progressive stages and circuit breakers]]
Michael DeHaan built the first version of Ansible over a single weekend in February 2012, writing approximately 1,200 lines of Python. He was frustrated with Puppet and Chef — both required persistent agents on every managed node, complex PKI infrastructure to secure agent communication, and steep learning curves — and wanted a simpler alternative. That constraint-driven origin shaped Ansible's core philosophy: agentless, SSH-based orchestration, YAML-friendly configuration, and minimal external dependencies. Every subsequent feature decision was filtered through the lens of "is this simpler than the alternatives?" The weekend prototype became the foundation for a tool that, within three years, attracted over 1,200 contributors and was eventually acquired by Red Hat.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Michael DeHaan stepped back from Ansible after Red Hat acquisition]]
* [[What was significant about Ansible 1.0, and when was it released?]]
* [[What other tools did Michael DeHaan create before Ansible?]]
Red Hat purchased Ansible Inc. in October 2015 for approximately $150 million, three years after the project's public creation. At acquisition, Ansible had roughly 1,200 contributors and held the most stars of any infrastructure automation project on GitHub. The acquisition marked a strategic inflection point — it shifted Ansible from independent open-source project to a product within Red Hat's portfolio, eventually leading to the creation of Ansible Tower (later Ansible Automation Platform) as a commercial offering and changes in the project's governance and pace.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Red Hat open-sourced AWX while selling Ansible Tower as a commercial product]]
* [[How many employees did Ansible, Inc. have at the time of the Red Hat acquisition?]]
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
Q: When did Red Hat acquire Ansible?
A: October 2015.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What happened to AnsibleFest after 2022?]]
* [[When was Ansible Lightspeed generally available?]]
* [[Michael DeHaan stepped back from Ansible after Red Hat acquisition]]
Q: How did Ansible end up under IBM's umbrella?
A: IBM acquired Red Hat in 2019 for $34 billion. Since Ansible was a Red Hat product, it became part of IBM's portfolio.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
* [[When did IBM acquire Red Hat?]]
* [[How many employees did Ansible, Inc. have at the time of the Red Hat acquisition?]]
When Michael DeHaan created Ansible in 2012, he deliberately rejected a persistent management agent on every managed node—a direct reaction to Chef and Puppet, both of which require agents installed on targets. His reasoning was twofold: first, if SSH was sufficient for manual sysadmin practice, it was sufficient for automation; second, at fleet scale the agent itself becomes a significant operational burden—crashes must be detected and recovered, version mismatches between controller and agents cause problems, and certificate expirations can block entire operations.
By using SSH—already universally present on Linux servers—Ansible eliminated an entire class of fleet management problems. The core philosophy: if a machine has SSH and Python, it is already ready for configuration management. This zero-bootstrap approach means no pre-installation, no service to manage on target systems, and no dependency on agents staying alive. Compared to agent-based competitors (Puppet uses a TLS-based protocol; Chef uses HTTPS), the tradeoff is that every operation requires SSH connectivity and incurs some per-task latency, but that is a simpler guarantee to meet than managing a shadow fleet of agents.
The agentless design also makes Ansible the default choice for network device automation: switches and routers have SSH but cannot run Ruby or install agents. The name 'Ansible' comes from Ursula K. Le Guin's 1966 novel, where an ansible is a device for instantaneous communication across any distance—fitting for a tool that communicates with hundreds of servers simultaneously.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
* <html><code>training/library/topics/fleet-ops/trivia.md</code></html>
* <html><code>training/library/topics/ansible/primer.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[Ansible vs. Chef/Puppet: key architectural differences]]
* [[Ansible: agentless IT automation tool]]
* [[Ansible became the dominant network automation tool despite being designed for servers]]
Michael DeHaan chose YAML for Ansible playbooks explicitly to make automation readable and writable by non-programmers — sysadmins without software engineering background. This decision remains contentious in the community. Critics point to YAML's whitespace sensitivity, which causes subtle indentation bugs and hidden type conversions (strings becoming booleans). Supporters argue YAML kept Ansible approachable to the target audience, whereas the Ruby DSLs of Puppet and Chef created a barrier for operators who were not developers. The trade-off encapsulates a core tension in automation design: accessibility versus strict syntax safety.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What language are Ansible playbooks written in?]]
* [[What is YAML, and why is it used in Ansible?]]
* [[How does Ansible differ from other configuration management tools?]]
Ansible's foundational documentation emphasizes idempotency — running a playbook twice produces the same result as running it once, with no unintended side effects on subsequent runs. However, the <html><code>shell</code></html> and <html><code>command</code></html> modules explicitly opt out of this guarantee by design; they execute every time regardless of system state, because they are intended for arbitrary scripts where idempotency cannot be assumed. Guardrails like the <html><code>creates</code></html> and <html><code>removes</code></html> parameters were added to help authors avoid accidental repeated execution. A 2019 study analyzing community Galaxy roles found approximately 18% contained non-idempotent tasks, indicating the principle catches even experienced practitioners and remains aspirational rather than enforceable. This gap between documented promise and operational practice is a persistent source of production incidents, particularly for operators new to idempotent thinking.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are idempotency issues in infrastructure automation and how are they avoided?]]
* [[Idempotence is the core contract of Ansible modules]]
* [[Prefer native modules over shell/command for idempotency]]
Michael DeHaan, Ansible's creator, stepped back from active leadership shortly after Red Hat's acquisition in 2015. In later interviews, he expressed mixed feelings about the project's evolution, particularly the increasing complexity of Ansible Tower (later rebranded as Ansible Automation Platform) compared to his original vision of radical simplicity. While he remained involved in an advisory capacity for some time, the day-to-day direction of the project shifted to Red Hat's product and engineering teams. His departure marked a transition from founder-driven project to corporate-maintained open-source product.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible originated from a weekend prototype in February 2012]]
* [[When did Red Hat acquire Ansible?]]
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
Q: What was Michael DeHaan's job before creating Ansible, and why did he leave?
A: He worked briefly at Puppet Labs and then at another company doing integration work. Neither was a good fit, and he wanted to return to building open-source tooling. His frustration with multi-day setup times for DNS/NTP issues led him to create Ansible.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What two open-source projects did Michael DeHaan create before Ansible, both at Red Hat?]]
* [[Who created Ansible and when?]]
* [[Who created Ansible, and in what year was it first released?]]
In 2017, Red Hat open-sourced AWX, the upstream project powering Ansible Tower, its commercial offering. This was strategically unusual: Red Hat was effectively giving away the code for a product it was actively selling. The strategy followed Red Hat's proven playbook with Fedora/RHEL — use the open-source upstream to grow the community and establish mindshare, then monetize support, SaaS hosting, and enterprise features built on top. AWX releases roughly monthly with community contributions, while Tower offered commercial support and bundled products. This dual-licensing model aimed to decouple ecosystem growth from the commercial product's roadmap, allowing enterprise features to be added to Tower without fragmenting the open-source base.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[AWX, Ansible Tower, and Ansible Automation Platform explained]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[How do AWX and Red Hat Ansible Automation Platform differ?]]
In 2020, Ansible underwent its most disruptive change: splitting into <html><code>ansible-core</code></html> (the engine and about 70 built-in modules) and a separate <html><code>collections</code></html> ecosystem for everything else. The <html><code>ansible</code></html> PyPI package changed from shipping 3,400+ modules to becoming a meta-package. Playbooks using short module names like <html><code>yum</code></html> instead of fully qualified names like <html><code>ansible.builtin.yum</code></html> broke overnight. This forced adoption of Fully Qualified Collection Names (FQCN) — e.g., <html><code>community.general.iptables_state</code></html> instead of <html><code>iptables_state</code></html>. The change addressed real problems: decoupling module release cycles from the core engine, allowing community-maintained collections to evolve independently, and providing clear ownership and versioning. However, the migration pain was severe, affecting countless production playbooks and documentation.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[When did Ansible collections replace the monolithic package?]]
* [[Why Use Ansible Collections?]]
Ansible's Jinja2 templating engine silently converts the string <html><code>"true"</code></html> to Python <html><code>True</code></html> and <html><code>"null"</code></html> to <html><code>None</code></html> when interpolated into playbooks. This has caused countless production incidents where configuration files end up with <html><code>True</code></html> instead of <html><code>true</code></html>, breaking downstream JSON and YAML parsers that don't recognize Python literal syntax. The trap catches even experienced users because the conversion is silent — a template rendering <html><code>{{some_var}}</code></html> where <html><code>some_var</code></html> is the string <html><code>"true"</code></html> becomes the boolean literal <html><code>True</code></html> in the task output. The workaround is the <html><code>| string</code></html> filter (forces string output) or <html><code>| to_json</code></html> for values that must survive as strings. Understanding this conversion is essential for anyone writing variable-heavy playbooks or generating configuration files.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[The value of a certain variable you use is the string "True". You would like the value …]]
* [[Ansible `template` module]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
Ansible Execution Environments (EEs), introduced with Ansible Automation Platform 2.0, package <html><code>ansible-core</code></html>, collections, Python dependencies, and system libraries into a container image — solving the #1 support problem in the Ansible ecosystem: different collections requiring incompatible Python library versions on a single control node. For example, one collection might require <html><code>requests >= 2.28.0</code></html> while another needs <html><code>requests < 2.27.0</code></html>; without isolation, only one can be installed. The <html><code>ansible-navigator</code></html> tool runs playbooks inside an EE container, effectively replacing the bare-metal <html><code>ansible-playbook</code></html> command for production workflows. This shifts the problem from dependency management on the control node to OCI image management, a better-understood domain. EEs also enable consistent, reproducible execution across different operators and environments.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[ansible-navigator: modern replacement for ansible-playbook]]
* [[What is an Ansible Execution Environment (EE)?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
Ansible's setup module (which gathers facts) was inspired by equivalent features in Chef (Ohai) and Puppet (Facter), but Ansible made facts a first-class part of the execution model rather than an optional auxiliary step. Facts are collected automatically at the start of every play and populate the <html><code>hostvars</code></html> namespace — making them available to all tasks without explicit invocation. The setup module collects 200+ facts per host: CPU architecture, memory, mounted filesystems, network interfaces, OS version, and kernel configuration. By design, fact gathering is the most-executed module in the entire Ansible ecosystem by orders of magnitude. This design choice reflects Ansible's philosophy that state inspection should happen before action — operators should have visibility into the target environment before applying changes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible facts: auto-discovered host variables]]
* [[What is `ansible_facts` vs top-level fact variables?]]
* [[Fact caching avoids expensive repeated gathering]]
Ansible has 22 levels of variable precedence, from role defaults (lowest priority) to extra variables passed on the command line (highest priority). This is frequently cited as one of Ansible's most confusing features, but it was a deliberate design choice. Michael DeHaan argued that real infrastructure has many configuration layers — datacenter defaults, cluster overrides, environment-specific settings, host-specific values — and the precedence system should mirror that reality. Rather than forcing a flat namespace, precedence lets you compose configuration hierarchically. The rough ordering is: role defaults → inventory → group vars → host vars → play vars → task vars → extra vars. Extra vars (<html><code>-e</code></html> on the command line) always win, making them suitable for one-off overrides but dangerous for regular configuration. The <html><code>ansible-inventory --host <host> -vvv</code></html> command shows which source provided each variable value, making it essential when debugging unexpected values in large fleets.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
* <html><code>training/library/topics/ansible/primer.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[The variable 'whoami' defined in the following places:]]
* [[YAML inventory structure enables hierarchical host groups with inheritance]]
* [[How do you define variables in Ansible Playbooks?]]
Inventory answers two foundational questions: what machines does Ansible manage, and how are they logically organized? An inventory maps host identifiers (hostnames or IPs) to connection details and variables. Hosts are organized into named groups (e.g., <html><code>webservers</code></html>, <html><code>dbservers</code></html>) under an <html><code>all</code></html> parent; groups can be nested via <html><code>children</code></html>, creating multi-level hierarchies. Each group defines <html><code>hosts</code></html> (hostname → connection details) and <html><code>vars</code></html> (variables inherited by all members). Per-host overrides—such as <html><code>ansible_host</code></html> to specify a connection address distinct from the logical identifier—take precedence over group-level variables. Variable layering follows explicit precedence rules: group-level vars apply to all members; host-level vars override them. The grouping layer is essential—without it, every playbook would name individual hosts instead of referring to logical collections. Together, grouping and variable inheritance enable parameterized playbooks: a single template applies to different groups with different variable values, realizing infrastructure-as-code without hardcoding host details.
----
''Sources''
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
* <html><code>training/library/topics/mental-models-core/ansible-inventory-targeting.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Inventory is more than a flat list of hosts]]
* [[Ansible: Managing Multiple Environments with Separate Inventories]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
Playbooks are YAML files defining a sequence of tasks applied to target hosts. A play names the target (hosts: webservers), sets become privileges and play-level variables, then lists ordered tasks. Each task invokes a module (apt, template, service). Tasks are idempotent by design: running the same playbook twice gives the same result as running once. Handlers are special tasks triggered only when a previous task reports a change (via notify). Handlers run once at the end of the play even if triggered multiple times, preventing unnecessary service restarts. This structure enables safe, repeatable automation: a playbook can be run on a cadence without side effects, changes are visible in task output, and dependent operations are decoupled from triggering tasks.
----
''Sources''
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
''Related atoms''
* [[Structured Playbooks Provide Auditability and Idempotency]]
* [[Idempotence is the core contract of Ansible modules]]
* [[Ansible handlers: conditional, once-only task execution]]
Playbooks enable conditional execution, iteration, and stateful branching. Conditionals use <html><code>when: <expression></code></html> to skip tasks (e.g., when: ansible_os_family == "Debian"). Loops use <html><code>loop: [items...]</code></html> to repeat a task with item substitution over a list of dicts to create multiple users or configurations. The register keyword captures a task's output into a variable: <html><code>command: which docker register: docker_check</code></html> captures stdout, stderr, and return code. Subsequent tasks can branch on register results: <html><code>when: docker_check.rc != 0</code></html>. ignore_errors: true prevents a failed task from halting the play. These primitives compose into sophisticated workflows: detect if a service is installed, install only if missing, post-install health checks. Without these, playbooks would be rigid linear sequences.
----
''Sources''
* <html><code>training/library/cheatsheets/ansible.cheatsheet.md</code></html>
''Related atoms''
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
Using <html><code>shell: apt-get install package</code></html> instead of the <html><code>apt</code></html> module breaks idempotency. The shell task runs every time, spending 40 minutes reinstalling packages that are already present. The apt module, by contrast, checks if the package is installed and only runs if needed. Under time pressure, raw shell commands feel faster to write, but they create massive re-run costs. Every execution takes full time, and the playbook becomes fragile: if apt-get hangs or has transient failures, manual recovery is required. The principle: prefer native modules (apt, dnf, pip, yum) over shell commands. Modules are idempotent, handle distribution differences, and report the correct changed/ok status for monitoring and debugging.
----
''Sources''
* <html><code>training/library/topics/ansible/anti_primer.md</code></html>
''Related atoms''
* [[Prefer native modules over shell/command for idempotency]]
* [[Use purpose-built modules over shell; adopt FQCNs to avoid collisions]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
The anti-primer demonstrates that infrastructure incidents often result from multiple small mistakes compounding under time pressure. Running against all hosts (mistake 1) goes unnoticed until non-idempotent shell tasks (mistake 2) cause slow re-runs, then global privilege escalation (mistake 3) creates permission issues, then variable precedence confusion (mistake 4) causes a 3-hour debugging spiral. Each mistake seems minor in isolation and feels justified by deadline pressure, but together they exceed the team's ability to recover. The pattern: visibility of the first mistake is hidden by the success of the initial run, justifying the next shortcut. By hour 3, the compounding failures have reached critical mass and pages are firing. Prevention requires building safety into the workflow from the start: limit testing, check mode, idempotent modules, task-level privilege escalation, single source of truth for variables. These practices cost seconds; skipping them costs hours in incident response and significant engineering time to remediate state drift and data integrity issues.
----
''Sources''
* <html><code>training/library/topics/ansible/anti_primer.md</code></html>
''Related atoms''
* [[Shortcuts under deadline pressure compound into cascading failures]]
Applying a compliance remediation role (e.g., DISA STIG) to a fleet without pre-scanning and testing is hazardous. A STIG role changes 47+ settings, and 3 of them might break your application. Without before-state capture, you cannot identify which changes broke what. A war story: a team applied a DISA STIG role that set <html><code>net.ipv4.ip_forward=0</code></html>, breaking Docker overlay networking. All containerized services lost inter-container communication. The fix requires discipline: (1) scan the baseline first and capture the before state; (2) apply remediation to staging, not production; (3) verify application behavior after remediation; (4) compare before-and-after states; (5) deploy in stages to production. Never apply an unknown compliance role to production.
----
''Sources''
* <html><code>training/library/topics/compliance-automation/footguns.md</code></html>
''Related atoms''
* [[Continuous compliance loop: scan, parse, remediate, verify, archive]]
Compliance automation works as a closed loop: OpenSCAP scans systems against a security profile and produces an XML results file. A parser (Python or jq) extracts the failed controls. Ansible remediation tasks target only the failed controls, keeping remediation idempotent and efficient. A re-scan immediately afterward verifies remediation worked. Results are archived with timestamps and signatures for audit evidence. The entire cycle repeats on schedule (daily or weekly). This makes compliance continuous rather than point-in-time: drift is detected and repaired automatically, and every cycle produces timestamped evidence. The key insight is targeting only failed controls in remediation, not re-running everything — this keeps the feedback loop fast and reduces unintended side effects.
----
''Sources''
* <html><code>training/library/topics/compliance-automation/street_ops.md</code></html>
''Related atoms''
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[Safe infrastructure patch rollouts use progressive stages and circuit breakers]]
* [[Structured Playbooks Provide Auditability and Idempotency]]
fd's straightforward flags (<html><code>-e</code></html>, <html><code>-g</code></html>, <html><code>-d</code></html>, <html><code>-t</code></html>) make it easy to find Kubernetes manifests, Helm charts, Ansible playbooks, and CI/CD configs without mastering find's complex syntax. <html><code>fd -g 'values*.yaml'</code></html> finds Helm value overrides; <html><code>fd -g '*test*' -e py</code></html> finds Python test files; <html><code>fd -g '*.yml' .github/workflows/</code></html> finds GitHub Actions workflows. The pattern-based approach reduces cognitive load and makes ad-hoc searches faster than composing find predicates.
----
''Sources''
* <html><code>training/library/topics/fd/street_ops.md</code></html>
''Related atoms''
* [[What is the `ansible.builtin.find` module?]]
Automation introduces the risk of scale: a typo or logic error that affects 5 servers in testing can silently execute against 1,500 servers in production. Without <html><code>--limit</code></html>, a fleet command applies to all matching hosts. Running a command against all hosts without confirmation is a category error in operational safety. Mitigation: always use <html><code>--limit</code></html> during testing (e.g., <html><code>--limit 5_servers_to_test</code></html>), run with <html><code>--check</code></html> (dry-run mode) first, and configure <html><code>ansible.cfg</code></html> with a safety prompt when targeting more than a threshold number of hosts. Additionally, logging and diff output should be enabled to audit what changed. The 2017 GitLab incident — where an engineer deleted 300 GB of production data by running against the wrong server — exemplifies the cost of missing these guards. Infrastructure scale demands institutional safeguards, not just individual caution.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/footguns.md</code></html>
''Related atoms''
* [[Ansible playbooks without --limit run against all inventory]]
* [[Always limit-test new playbooks before fleet-wide execution]]
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
Ansible's default behavior is to run tasks against all hosts in parallel unless the <html><code>serial</code></html> directive specifies otherwise. A handler task like <html><code>systemctl restart nginx</code></html> with no serial setting will bounce every instance simultaneously, taking the entire service offline. This is especially dangerous during fleet deployments where a restart is part of the change flow. The fix is to always set <html><code>serial:</code></html> explicitly. For canary deployments, use <html><code>serial: 1</code></html> (one host at a time). For rolling updates across a larger fleet, use <html><code>serial: "25%"</code></html> or <html><code>serial: "10%"</code></html> to gradually cycle hosts through restarts while maintaining service availability. The default trap — that <html><code>serial</code></html> defaults to all hosts — catches operators who assume reasonable defaults. Reading the Ansible documentation reveals the trap, but defensive playbookwriting makes the intention clear to the next person who edits the code.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/footguns.md</code></html>
''Related atoms''
* [[Ansible `serial` keyword for batched rolling updates]]
* [[Parallel reboots cause cascading failures across multi-tier stacks]]
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
A fleet script that deletes a directory and then recreates it is not idempotent: if the script runs a second time (due to cron overlap, manual re-run, or retry logic), the second run deletes the newly created data from the first run. The principle of idempotency — that an operation can be safely applied multiple times and end in the same final state — is essential for safe fleet automation. Every operation must check state before acting. The fix is to use idempotent constructs: [[Ansible modules|Ansible Modules]] are idempotent by design (they check state and report changed/ok), whereas shell commands are not. Replace <html><code>shell: rm -rf /data && mkdir /data</code></html> with Ansible's <html><code>file:</code></html> module, which creates the directory only if missing and is safe to re-run. Lock files can prevent concurrent execution of the same operation. Idempotency is not optional in fleet operations; it's the foundation of reliable automation.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/footguns.md</code></html>
''Related atoms''
* [[What are idempotency issues in infrastructure automation and how are they avoided?]]
* [[Idempotence is the core contract of Ansible modules]]
* [[What makes good Ansible?]]
A large fleet represented as a single flat list (one <html><code>hosts.txt</code></html> file with 1,500 entries) is impossible to slice efficiently. Targeting a subset — say, all webservers in datacenter 1 — requires grepping and piping text files, a manual, error-prone process that's slow during incidents. As fleet size grows, operational efficiency depends on the inventory structure. Organize the inventory hierarchically by role (webserver, database, cache), location (dc1, dc2, region), environment (prod, staging), and other meaningful dimensions. Ansible's group hierarchies enable this: a group can contain other groups, allowing queries like <html><code>webserver:&dc1</code></html> to target all webservers in DC1. When an incident hits and you need to target a specific slice of the fleet, a well-structured inventory makes that trivial; a flat list makes it a bottleneck.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/footguns.md</code></html>
''Related atoms''
* [[What does `ansible-inventory --list` do?]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
Quick diagnosis commands for checking uptime, disk usage, package versions across hundreds or thousands of servers require thinking in parallelism from the start. A single 2-second SSH timeout times 1,500 hosts equals 50 minutes of wall time if run serially. Even basic Ansible ad-hoc commands like <html><code>ping</code></html> or <html><code>setup</code></html> must use the <html><code>-f</code></html> (forks) flag tuned to the control node's resources. For 1,500 hosts, <html><code>-f 50</code></html> to <html><code>-f 100</code></html> is typical; higher risks SSH connection table exhaustion; lower wastes wall time. When optimizing fleet operations, always ask: what is the wall time, and is parallelism the bottleneck? Most fleet problems are actually scaling problems.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/street_ops.md</code></html>
''Related atoms''
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
* [[Ansible performance optimization for large inventories]]
* [[Fleet incident response: assessment and targeted remediation]]
When servers are reprovisioned and SSH host keys change, the next fleet command fails on every reprovisioned host with <html><code>Host key verification failed</code></html>. For ephemeral or frequently reprovisioned infrastructure, use <html><code>StrictHostKeyChecking=accept-new</code></html> instead of <html><code>no</code></html> or <html><code>yes</code></html>. The difference matters: <html><code>accept-new</code></html> silently accepts unknown hosts once and rejects changed keys (MITM-safe), while <html><code>no</code></html> accepts any key including MITM keys. Configure in <html><code>ansible.cfg</code></html> under <html><code>[ssh_connection]</code></html> with <html><code>ssh_args = -o StrictHostKeyChecking=accept-new -o UserKnownHostsFile=/dev/null</code></html>. For production with stable host keys, manage known_hosts via configuration management instead.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/street_ops.md</code></html>
''Related atoms''
* [[What is `host_key_checking`?]]
* [[How do you set up passwordless SSH for Ansible?]]
An Ansible playbook with <html><code>serial: 10</code></html> hits a flaky host that hangs on SSH, stalling the entire batch. With 1,500 hosts, one slow server per batch means hours of cumulative delays. The fix is aggressive SSH timeouts in <html><code>ansible.cfg</code></html>: <html><code>ConnectTimeout=10</code></html> (abort SSH connection attempt after 10 seconds), <html><code>ServerAliveInterval=15</code></html> and <html><code>ServerAliveCountMax=3</code></html> (detect dead connections quickly), and <html><code>timeout = 30</code></html> (Ansible task timeout). The three timeouts work together: connect quickly, detect death quickly, abandon the task quickly. Without these, a single flaky NIC driver or unresponsive DNS resolver can cascade into hours of lost time.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/street_ops.md</code></html>
''Related atoms''
* [[Transient SSH Failures Should Be Retried Automatically]]
* [[One slow host blocks the entire play during fact gathering]]
* [[High fork counts cause connection exhaustion and cascading failures]]
Running <html><code>ansible all -m command -a 'reboot'</code></html> does not guarantee execution order. Load balancer backends, database replicas, and app servers reboot in random order, causing cascading failures (all backends down simultaneously, databases vote out the cluster, etc.). The fix is explicit <html><code>serial</code></html> constraints in playbooks: reboot databases one at a time (<html><code>serial: 1</code></html>), then app servers in 10% batches (<html><code>serial: "10%"</code></html>), then load balancers one at a time. Use groups to define the order. Validate health checks between groups — ensure the database is back and healthy before rebooting app servers. This pattern applies to any multi-tier operation: rolling restarts, configuration pushes, major upgrades.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/street_ops.md</code></html>
''Related atoms''
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[Transient SSH Failures Should Be Retried Automatically]]
Collecting facts from the entire fleet at once with <html><code>ansible all -m setup -a 'filter=ansible_*' --tree /tmp/facts</code></html> dumps JSON fact files for each host. Parse them with <html><code>jq</code></html> to extract structured data (hostname, OS, vCPU count, memory, IP address) into CSV. This is the foundation for fleet audits, capacity planning, and compliance checks. The tree-based output scales better than live Ansible output because you can reparse facts without re-collecting them. Use <html><code>ansible_facts</code></html> filters to limit bandwidth and parsing time. A single run captures a snapshot of fleet state; compare snapshots over time to track growth and drift. This pattern also enables offline analysis and archival.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/street_ops.md</code></html>
''Related atoms''
* [[Flat inventory prevents efficient fleet targeting]]
* [[Fact caching avoids expensive repeated gathering]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
When a fleet-wide incident affects multiple hosts, the response sequence is: (1) assess scope using parallel service-status checks across all hosts to count affected instances; (2) gather logs from affected hosts only, using a file-based limit to target specific IPs; (3) apply the hotfix to the affected subset with appropriate concurrency; (4) validate the fix using health checks against the same targeted hosts. This workflow assumes you've identified problem hosts into a file (e.g., <html><code>/tmp/affected-hosts.txt</code></html>). The parallel factor (<html><code>-f</code></html> flag) trades throughput against SSH connection overhead—100 is reasonable for most fleets; scale down for constrained controllers. A common debug pattern: unreachable hosts may indicate network loss, connectivity degradation, or host failure. Cross-reference UNREACHABLE output with reboot times and network topology to spot systematic patterns (e.g., all unreachable hosts in one rack or VLAN). This detective work narrows the blast radius and helps distinguish between host-local issues and infrastructure failure.
----
''Sources''
* <html><code>training/library/topics/fleet-ops/street_ops.md</code></html>
''Related atoms''
* [[Fleet diagnostics demand parallelism; forks multiply time]]
* [[Running fleet commands without --limit risks massive misconfiguration]]
* [[One slow host stalls the entire batch unless timeouts are aggressive]]
Using <html><code>lineinfile</code></html> to manage a file with multiple lines you control creates self-conflict. Two tasks adding different lines based on the same regex will fight: one task adds a line, the next removes it looking for its own line, the first adds again. Every run shows <html><code>changed: true</code></html>. This isn't a bug in lineinfile — it's the wrong tool. Use <html><code>blockinfile</code></html> for multi-line sections, <html><code>template</code></html> for files you fully control, and <html><code>lineinfile</code></html> strictly for surgical one-line edits where the rest of the file is unmanaged.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
''Related atoms''
* [[What does the `lineinfile` module do?]]
* [[What is `ansible.builtin.lineinfile` vs `ansible.builtin.blockinfile`?]]
* [[What module adds or modifies lines in files?]]
By default, Ansible logs all task output, including variable values. A task that sets a database password or API key will print it to stdout. If your CI system archives logs, that credential is now stored in searchable plain text. The fix is one line: <html><code>no_log: true</code></html> on any task that handles secrets. This suppresses output for that task. Also audit existing CI logs for leaked credentials — use <html><code>grep -r 'password\|token\|secret'</code></html> on archived logs as a sanity check.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
''Related atoms''
* [[Vault Passwords Must Not Appear in Shell History or Plain Text]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
Adding <html><code>ignore_errors: true</code></html> because a task fails intermittently silences all failures, not just the intermittent ones. Six months later, a background cleanup task has been failing silently every run, your disk fills up, and nobody noticed because errors were being swallowed. The solution is precision: use <html><code>failed_when</code></html> with specific conditions to fail only on errors you care about. Or use <html><code>register</code></html> + <html><code>when</code></html> patterns to handle expected failures gracefully. Blanket <html><code>ignore_errors</code></html> is a band-aid; conditional failure handling is the real fix.
----
''Sources''
* <html><code>training/library/topics/ansible/footguns.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `failed_when: false` idiom?]]
* [[What does `ignore_errors: true` do?]]
Store all homelab configuration—Ansible playbooks, Helm values, Kubernetes manifests, network diagrams, IP assignments, and recovery scripts—in a single Git repository organized by purpose (ansible/, helm-values/, k8s-manifests/, docs/, scripts/). The most critical file is a <html><code>restore-from-scratch.sh</code></html> script that takes a bare Proxmox installation from network boot to fully operational lab, including cluster setup, storage, networking, Kubernetes deployment, and all services. This script is the actual documentation; if you can't rebuild from scratch using it, your docs have gaps. Without this discipline, a hardware failure forces weekend-long manual reconstruction. With it, recovery time drops from days to hours. The repository becomes the single source of truth—humans read it for context, scripts execute it for consistency, and version control preserves all past decisions.
----
''Sources''
* <html><code>training/library/topics/homelab/street_ops.md</code></html>
Homelab operators increasingly manage their labs with the same tooling used in production: Terraform for VM provisioning, Ansible for configuration management, ArgoCD for Kubernetes deployments, Grafana for monitoring. This is not aspirational architecture. It is pragmatic: learning these tools in a homelab makes you more effective at your job, and experience at work informs what you build at home. The feedback loop accelerates adoption of both hobbyist experiments and production-grade features. A monitoring pattern you try in your homelab gets pulled into your company's stack; a production lesson learned gets implemented at home. The same individual bridges both worlds.
----
''Sources''
* <html><code>training/library/topics/homelab/trivia.md</code></html>
You have Ansible playbooks. You run them against an inherited server to "bring it into compliance." The playbooks revert three hotfixes applied directly during past incidents. The incidents return. Those hotfixes encoded tribal knowledge: a sysctl setting that prevents OOM killer from targeting the database, an iptables rule that blocks a specific attack pattern, a kernel parameter tuned for a particular failure mode. Always run config management in check/diff mode first (<html><code>--check --diff</code></html>) and review every proposed change. If production config differs from the playbook, investigate why before assuming the playbook is right. Production is the source of truth. Config drift is not always accidental or wrong.
----
''Sources''
* <html><code>training/library/topics/legacy-archaeology/footguns.md</code></html>
''Related atoms''
* [[What is configuration drift?]]
* [[Always run --check --diff before production Ansible changes]]
* [[You deploy configuration but servers show inconsistent settings. How do you detect and …]]
Running multiple distros in one fleet creates friction: different package managers require different Ansible tasks, different MAC systems (SELinux vs AppArmor) need different hardening profiles, different networking stacks (nmcli vs netplan) need different config management, and security patching cadences diverge. The naive solution—standardize on one distro everywhere—is rigid and ignores specialization. The better approach: standardize within each workload role. All production servers are Ubuntu LTS (or RHEL if compliance mandates). All container hosts are Fedora CoreOS. All CI runners are Ubuntu LTS. All container images are Alpine (small) or Debian-slim (compatibility). Developer workstations can be Fedora, Ubuntu, or Arch (team choice). This reduces friction for each category while allowing specialization where it matters. In Ansible, use ansible_os_family conditionals to handle the few distro-specific tasks (firewall, networking, package names). This pattern scales to 10+ distros without becoming unmanageable.
----
''Sources''
* <html><code>training/library/topics/linux-distro-comparison/primer.md</code></html>
In fleets running multiple Linux distros, use Ansible to gather distro information across all systems at once: <html><code>ansible all -m setup -a "filter=ansible_distribution*"</code></html> or <html><code>ansible all -m shell -a "cat /etc/os-release | grep PRETTY_NAME"</code></html>. Pipe results through <html><code>grep</code></html> and <html><code>sort</code></html> to produce a human-readable inventory. This reveals which systems are running what—useful for planning migrations, identifying outliers, and ensuring you have parity in your testing environments. For cross-distro playbooks, use <html><code>ansible.builtin.package</code></html> instead of <html><code>apt</code></html> or <html><code>dnf</code></html> directly, which handles manager selection automatically. For packages with different names across distros (like <html><code>build-essential</code></html> vs <html><code>@"Development Tools"</code></html>), use <html><code>ansible_os_family</code></html> conditionals to select the right package name for each family.
----
''Sources''
* <html><code>training/library/topics/linux-distro-comparison/street_ops.md</code></html>
''Related atoms''
* [[Cross-platform provisioning uses OS-family conditionals and variable includes]]
* [[Detecting and Handling Configuration Drift with Ansible]]
Q: When did IBM acquire Red Hat?
A: July 2019, for approximately $34 billion.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How did Ansible end up under IBM's umbrella?]]
* [[When did Red Hat acquire Ansible?]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
A module is a small Python program that Ansible ships to the target host and executes there. It manages a single resource type—a user, a file, a package, a service. The module queries target state, compares to desired state, acts if needed, and returns whether it made changes. A plugin is Python code that runs on the Ansible controller (your laptop or Ansible server) and extends how Ansible works: connection plugins handle SSH/WinRM/other transports, lookup plugins fetch external data at playbook evaluation time, filter plugins transform data in Jinja2 templates, callback plugins hook into Ansible events, inventory plugins generate dynamic host lists, and strategy plugins control playbook execution. Both modules and plugins are Python, but the distinction is execution location—target vs controller. Collections bundle modules and plugins together as namespaced, distributable units.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-idempotence-modules-plugins.md</code></html>
''Related atoms''
* [[Modules, plugins, and collections in Ansible architecture]]
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
* [[Ansible execution hierarchy: playbook > play > task; roles bundle and reuse]]
Use purpose-built modules like <html><code>ansible.builtin.apt</code></html> or <html><code>ansible.builtin.user</code></html> instead of <html><code>command</code></html> or <html><code>shell</code></html>. Purpose-built modules give you idempotence, check mode (--check), diff mode (--diff), and proper error handling for free. Using <html><code>shell "apt-get install foo"</code></html> loses all these benefits—the module will report "changed" every time because Ansible cannot inspect what the shell command did. Always use Fully Qualified Collection Names (FQCNs) like <html><code>amazon.aws.ec2_instance</code></html> or <html><code>community.postgresql.postgresql_user</code></html> instead of short names like <html><code>ec2_instance</code></html> or <html><code>postgresql_user</code></html>. FQCNs prevent namespace collisions when multiple collections define modules with the same short name and make playbooks more portable and maintainable across different environments.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-idempotence-modules-plugins.md</code></html>
''Related atoms''
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[Prefer native modules over shell/command for idempotency]]
* [[Audit mixed-distro fleets with Ansible to identify configuration drift]]
Inventory supports grouping, variable layering, and dynamic generation—capabilities often overlooked by teams that treat it as a simple enumeration of IP addresses. The grouping system allows hosts to be organized hierarchically and to belong to multiple groups simultaneously. Variables can be set per-group and per-host in dedicated directories (<html><code>group_vars/</code></html>, <html><code>host_vars/</code></html>), and they merge according to precedence. Dynamic inventory sources—scripts or plugins that query cloud APIs or other backends at runtime—eliminate the need to maintain stale hardcoded host lists. These capabilities make inventory a flexible, centralized system for managing machine identity and configuration across environments, not merely a roster.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-inventory-targeting.md</code></html>
''Related atoms''
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Dynamic inventory in Ansible]]
* [[Common inventory mistakes: hardcoding, secrets, group membership, ungrouped hosts]]
Variables in Ansible come from many sources: inventory files and directories, playbooks, roles, CLI arguments, and discovered facts. Inventory contributes only one layer to this precedence stack. Additionally, inventory can be defined in multiple formats (INI and YAML) that look completely different visually but perform the same job—both compile to the same logical structure. This format agnosticism and the interleaving of variables from many sources can create confusion about where values are coming from and which will take precedence in a given context. Understanding that inventory variables are one input among many—and that the format is merely a syntax choice—helps reduce that confusion.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-inventory-targeting.md</code></html>
''Related atoms''
* [[YAML inventory structure enables hierarchical host groups with inheritance]]
* [[Ansible variable precedence: bookends and gradient]]
* [[Ansible variable precedence footguns]]
Four footguns plague inventory designs. Hardcoding IP addresses or hostnames instead of using DNS or dynamic inventory means your inventory becomes stale as infrastructure changes. Storing secrets directly in inventory files (passwords, API keys) instead of using <html><code>ansible-vault</code></html> or an external secrets manager exposes credentials to anyone with read access to version control. Forgetting that hosts can belong to multiple groups leads to missed variable merges—variables from all a host's groups apply and combine according to precedence. The implicit <html><code>ungrouped</code></html> group exists for hosts not assigned to any explicit group; forgetting this group can cause unintended variables to apply or config to be skipped.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-inventory-targeting.md</code></html>
''Related atoms''
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Inventory structure: hosts, groups, variables, and sources]]
* [[Inventory is more than a flat list of hosts]]
Ansible organizes work into nested layers. A ''playbook'' is a YAML file containing an ordered list of ''plays''. Each ''play'' maps a group of hosts to a list of tasks and roles, along with play-level configuration like <html><code>hosts:</code></html>, <html><code>vars:</code></html>, <html><code>become:</code></html>, and other directives. A ''task'' is the atomic unit of work—a single module invocation with parameters, executed once per targeted host. A ''role'' is a reusable directory structure bundling tasks, handlers, variables, defaults, templates, and files under a standard layout, eliminating the need to repeat common configurations. A ''handler'' is a special task that only runs when notified by name from another task, and only once per play (even if multiple tasks notify it), enabling patterns like "restart nginx only if the config file changed." This layering allows plays to be independent units within a playbook, and roles to be shared across many playbooks.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-playbook-play-task-role.md</code></html>
''Related atoms''
* [[Playbooks express desired state through ordered tasks]]
* [[Ansible handlers: conditional, once-only task execution]]
* [[What is the purpose of an Ansible Playbook?]]
A ''playbook'' is a YAML file containing an ordered list of plays. A ''play'' maps a group of hosts to a list of tasks and roles, with play-level keywords like <html><code>hosts:</code></html>, <html><code>vars:</code></html>, <html><code>become:</code></html>. A ''task'' is one action—a call to a single module with parameters—and is the atomic unit of work. A ''role'' is a reusable, standardized directory structure that bundles tasks, handlers, variables, defaults, templates, and files under <html><code>tasks/</code></html>, <html><code>handlers/</code></html>, <html><code>defaults/</code></html>, <html><code>vars/</code></html>, <html><code>templates/</code></html>, and <html><code>files/</code></html> subdirectories. A ''handler'' is a task that only runs when notified by name from another task and only fires once per play, even if multiple tasks notify it. This structure allows tasks to be organized into reusable roles, plays to target independent host groups, and handlers to respond to state changes efficiently.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-playbook-play-task-role.md</code></html>
''Related atoms''
* [[What is the difference between an Ansible playbook and a role?]]
* [[Each play targets hosts independently; handlers deduplicate and roles standardize structure]]
* [[Roles standardize reusable automation into a predictable directory structure]]
A playbook is a list of plays. Each play targets one or more hosts with the <html><code>hosts:</code></html> key, optionally using <html><code>become:</code></html> for privilege escalation, and contains handlers, roles, and tasks. Plays use structural keys like <html><code>hosts</code></html>, <html><code>become</code></html>, and <html><code>roles</code></html>. Tasks use different keys: <html><code>name</code></html>, <html><code>module</code></html>, <html><code>register</code></html>, <html><code>when</code></html>. Roles bundle tasks and defaults into reusable units following a predictable layout: <html><code>tasks/main.yml</code></html>, <html><code>defaults/main.yml</code></html>, <html><code>vars/main.yml</code></html>, <html><code>handlers/main.yml</code></html>.
Handlers are tasks that only run when explicitly notified by another task via the <html><code>notify:</code></html> key. Critically, handlers do not execute immediately after the notifying task — they run at the end of the play. If you need handlers to run mid-play before continuing, use <html><code>meta: flush_handlers</code></html>.
Common mistakes stem from not internalizing this hierarchy. Confusing play-level keys with task-level keys leads to syntax errors. Putting everything in one giant play instead of splitting by host group or logical phase makes playbooks harder to understand and reuse. Writing roles without <html><code>defaults/main.yml</code></html> makes variable overrides unnecessarily difficult — put user-tunable variables in defaults/main.yml and internal constants in vars/main.yml.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-playbook-play-task-role.md</code></html>
''Related atoms''
* [[What is the difference between an Ansible playbook and a role?]]
* [[Optimizing Ansible Playbook Performance]]
* [[Explain the difference between tasks, handlers, and defaults in an Ansible Role.]]
In a playbook YAML file, play-level keywords (like <html><code>hosts:</code></html>, <html><code>become:</code></html>, <html><code>vars:</code></html>) and task-level keywords (like <html><code>name:</code></html>, <html><code>register:</code></html>) appear at different indentation levels within the same list structure. The boundaries between these scopes are not visually marked—they depend entirely on indentation depth. A task list appears as <html><code>tasks:</code></html> (play-level) followed by a list of task items; within each task item, parameters like <html><code>name:</code></html>, <html><code>module:</code></html>, and module-specific arguments appear. Roles add another layer of indirection: the <html><code>roles:</code></html> key points to role directories that contain their own <html><code>tasks/main.yml</code></html>, <html><code>handlers/main.yml</code></html>, etc., hiding the actual tasks from the playbook file. Misalignment or misunderstanding of indentation can lead to keywords being attached to the wrong scope, causing the play to behave unexpectedly.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-playbook-play-task-role.md</code></html>
''Related atoms''
* [[What is the purpose of an Ansible Playbook?]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
* [[Ansible playbook architecture: plays, tasks, roles]]
Playbooks can contain multiple plays, and each play independently specifies its <html><code>hosts:</code></html> target. This means different plays in the same file can target different host groups without interference—the first play might configure web servers, the second might configure databases. Handlers are designed to solve a common pattern: "run this action only if something changed." Multiple tasks can notify the same handler by name, but that handler only executes once at the end of the play (or when explicitly flushed), preventing redundant restarts or reloads. Roles enforce a standard directory structure that makes playbook composition predictable and reusable: any role named <html><code>nginx</code></html> is expected to follow the convention of having <html><code>roles/nginx/{tasks,handlers,defaults,vars,templates,files}/</code></html>, allowing teams to combine roles from different sources without surprises about where files will be found.
----
''Sources''
* <html><code>training/library/topics/mental-models-core/ansible-playbook-play-task-role.md</code></html>
''Related atoms''
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
* [[Ansible playbook architecture: plays, tasks, roles]]
* [[Playbook execution flows through pre_tasks, roles, tasks, post_tasks with distinct import/include behavior]]
If you edit <html><code>hosts.yaml</code></html> while a Nornir or Ansible job is reading the inventory, Python may read a partially-written file. The result is either a YAML parse error mid-execution, or the job silently misses devices because they were added after the inventory was loaded. Treat inventory files as read-only during job execution. For static inventory, use file locks or atomic file operations (write to a temporary file, then rename). For dynamic inventory backed by an API (Netbox, cloud inventory services), ensure the API is read-consistent and not being modified concurrently. This is especially critical for production automation that runs frequently.
----
''Sources''
* <html><code>training/library/topics/network-automation/footguns.md</code></html>
''Related atoms''
* [[Troubleshooting Playbook Failures]]
* [[Default inventory pointing to production invites unintended changes]]
* [[What are common issues you might encounter with dynamic inventories, and how would you …]]
The Ansible <html><code>ios_command</code></html> module runs arbitrary commands (show or config) unconditionally. It does not check whether the configuration already exists, does not prevent re-application, and does not diff before applying. Running a playbook twice applies the same config commands twice. On some devices, applying the same command twice causes an error ("already configured") and the task fails on the second run. Use Ansible network resource modules (<html><code>cisco.ios.ios_ntp_global</code></html>, <html><code>cisco.ios.ios_bgp_global</code></html>, <html><code>arista.eos.eos_interfaces</code></html>, etc.) for configuration tasks — they are idempotent, they diff, and they check state before applying. Reserve <html><code>ios_command</code></html> for read-only show commands and verification tasks.
----
''Sources''
* <html><code>training/library/topics/network-automation/footguns.md</code></html>
''Related atoms''
* [[Idempotence is the core contract of Ansible modules]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
* [[Prefer native modules over shell/command for idempotency]]
Ansible's network modules (e.g., <html><code>eos_interfaces</code></html>, <html><code>ios_bgp_global</code></html>, <html><code>nxos_vlans</code></html>) are declarative—you describe the desired state, and the module handles idempotency. They support state parameters: <html><code>merged</code></html> (add/update, don't delete), <html><code>replaced</code></html> (replace only specified sections), <html><code>deleted</code></html> (remove specific items), and <html><code>overridden</code></html> (full replacement). Example: the <html><code>eos_interfaces</code></html> module with <html><code>state: merged</code></html> stages interface descriptions and enablement without affecting other config. Free-form modules like <html><code>eos_command</code></html> and <html><code>ios_command</code></html> send arbitrary CLI and parse output—they're not idempotent and are meant for read-only show commands or one-time operations. The connection plugin <html><code>network_cli</code></html> handles authentication, enable mode, and per-vendor quirks. Ansible network automation works well for straightforward configuration changes across homogeneous or semi-homogeneous networks where Playbook-level sequencing suffices. For complex conditional logic or tight integration with external APIs, Nornir or custom scripts are often clearer.
----
''Sources''
* <html><code>training/library/topics/network-automation/primer.md</code></html>
''Related atoms''
* [[How does Ansible support network automation?]]
* [[How does Ansible manage network devices?]]
* [[Configuring Ansible for Network Automation]]
Ansible was created for server configuration management, not networking. However, its agentless, SSH-based architecture proved to be a natural fit for network devices, which lack the ability to run agents and expect interactive SSH sessions. The addition of the <html><code>network_cli</code></html> connection plugin in Ansible 2.5 (2018) formalized network support with proper handling of enable mode, config prompts, and per-vendor quirks. By 2020, adoption surveys showed Ansible as the most commonly used tool for network automation, surpassing purpose-built network tools like Oxidized and Nornir. This happened because Ansible already had the trust and usage footprint of infrastructure teams—adding network support meant teams could unify their server and network automation under one tool. Simplicity and familiarity trumped purpose-built alternatives.
----
''Sources''
* <html><code>training/library/topics/network-automation/trivia.md</code></html>
''Related atoms''
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[What is `ansible_network_os`, and why is it critical for network automation?]]
* [[What is Ansible Networking, and how is it different from traditional Ansible?]]
Packer provisioners execute in sequence: shell runs inline commands or scripts, Ansible runs playbooks over SSH, file copies configuration, powershell runs on Windows. A critical gotcha: shell provisioners run in a non-interactive, non-login shell, so .bashrc and .profile are not sourced — expected environment variables from login shells will be missing. Always use <html><code>apt-get -y</code></html> (no prompts) and explicitly <html><code>source /etc/profile</code></html> if login environment is needed, or use <html><code>inline_shebang</code></html> to override the shell. The informal ordering mnemonic is FAP: File (copy configs in), Ansible (configure system), Post-processor (output artifact). If one provisioner fails, the entire build fails.
----
''Sources''
* <html><code>training/library/topics/packer/primer.md</code></html>
''Related atoms''
* [[Ansible provisioner integrates configuration management into Packer builds]]
* [[How does Ansible differ from other configuration management tools?]]
* [[What makes good Ansible?]]
Packer's Ansible provisioner runs a playbook against the build instance over SSH, exactly as Ansible would target a production server. Packer creates a temporary SSH key, passes connection details (instance IP, port, user) to Ansible, and executes the playbook. Extra arguments can be passed to Ansible (vault passwords, variable files, tags). This allows teams to reuse existing Ansible playbooks for image configuration rather than writing Packer-specific provisioning logic.
----
''Sources''
* <html><code>training/library/topics/packer/primer.md</code></html>
''Related atoms''
* [[Passing Variables and Vault to Ansible in Packer]]
* [[Shell provisioners run in non-interactive context; use Ansible for complex configuration]]
Pass variables to Ansible provisioners in Packer using the <html><code>extra_arguments</code></html> field. Example: <html><code>extra_arguments = ["--extra-vars", "app_version=${var.app_version} env=${var.env}", "-v"]</code></html>. For Ansible Vault, pass <html><code>--vault-password-file</code></html> with the path to a password file. Set <html><code>ansible_env_vars = ["ANSIBLE_HOST_KEY_CHECKING=False"]</code></html> to speed up connections — Packer generates a temporary SSH key and Ansible will use it without host key verification. Do not bake vault-encrypted secrets into the image; Vault in Packer builds is fine for non-secret configuration you want to keep out of plain text, but all actual credentials must be injected at runtime.
----
''Sources''
* <html><code>training/library/topics/packer/street_ops.md</code></html>
''Related atoms''
* [[Ansible provisioner integrates configuration management into Packer builds]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[How do you encrypt a single string variable?]]
Ansible operates on a control-node-to-managed-nodes model via SSH (or WinRM for Windows). The control node—your laptop or CI server—connects to target servers, pushes modules, executes them, and returns results. No agent is required on managed nodes; only Python and SSH are needed. This agentless design eliminates the bootstrap problem: servers are ready to be managed as soon as they have network connectivity and SSH access. The execution flow is: connection via SSH, module push, execution, result collection. This model scales from a few servers to thousands because it's stateless—each connection is independent, and there's no agent state to manage or troubleshoot on target systems.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
''Related atoms''
* [[Ansible: agentless IT automation tool]]
* [[Ansible managed node]]
* [[How does Ansible connect to managed nodes?]]
[[Ansible modules|Ansible Modules]] are idempotent by default: running the same playbook twice produces the same result as running it once. This means configuration changes are safe to re-run without side effects. The guarantee is about observable state, not code path—a module can run expensive logic internally and still be idempotent as long as the system ends up in the same place. The critical exception: <html><code>command</code></html> and <html><code>shell</code></html> modules are not idempotent. They execute every time, regardless of whether the operation is needed. To make them safe, add <html><code>creates:</code></html> or <html><code>when:</code></html> conditions. For example, <html><code>command: createdb mydb creates=/var/lib/postgresql/mydb</code></html> runs only if the database doesn't exist. Better practice: use the specialized <html><code>postgresql_db</code></html> module instead. Raw shell commands in playbooks are a footgun because they break the idempotency guarantee that makes Ansible automation trustworthy.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
''Related atoms''
* [[Idempotence is the core contract of Ansible modules]]
* [[Prefer native modules over shell/command for idempotency]]
* [[Why is shell in Ansible dangerous?]]
Before running a playbook against dozens or hundreds of servers, test it against a single host first using <html><code>ansible-playbook site.yml --limit hostname</code></html>. This catches syntax errors, missing variables, permission issues, and logic bugs at zero blast radius. Once you're confident in a single host, expand to a small group: <html><code>--limit group_name | head -3</code></html> or <html><code>--limit '5'</code></html> (first 5 hosts in group). Only after successful testing on a small sample should you run fleet-wide. This practice is especially critical under time pressure—the few minutes saved by skipping the limit test are always lost during incident response. Similarly, use <html><code>--check --diff</code></html> for a dry run preview of what would change before applying changes.
----
''Sources''
* <html><code>training/library/topics/ansible/primer.md</code></html>
''Related atoms''
* [[Optimizing Ansible Playbook Performance]]
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
* [[Running fleet commands without --limit risks massive misconfiguration]]
Q: What is Jinja2 in the context of Ansible?
A: The templating engine Ansible uses for dynamic content generation in templates and playbooks. It allows variables, filters, loops, and conditionals.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
* [[Ansible `template` module]]
When a playbook fails, read the error output carefully: the TASK name tells you exactly which task failed, the "msg" field gives the specific error, and "stdout" / "stderr" fields show command output. Common failure patterns: "Unreachable" indicates SSH connectivity or authentication issues (check SSH manually, verify ansible_user and ansible_ssh_private_key_file in inventory, handle SSH host key changes with ssh-keygen -R). "Permission denied" indicates privilege escalation failure (verify become: yes is set, provide sudo password with --ask-become-pass, or check sudoers config on target). "Module failure" is task-specific (verify package names for the OS, service names differ between distributions, template paths are correct, Python dependencies exist on target). Recover with <html><code>--start-at-task="Task Name"</code></html> to resume from the failed task, or use the auto-generated retry file: <html><code>ansible-playbook site.yml --limit @site.retry</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/street_ops.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[Troubleshooting Ansible module issues]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
Infrastructure patches and updates must follow a staged approach to catch problems before they spread. The pattern: deploy first to development, verify success, then staging, then production regions (staging before prod-us before prod-eu). Use Ansible with serial batches rather than blasting all servers simultaneously. Include health checks in the playbook itself, after applying changes. Set max_fail_percentage as a circuit breaker: if too many hosts fail (e.g., 10%), stop the rollout immediately rather than contaminating the entire fleet. The contrast with ad-hoc manual updates is sharp: manual <html><code>apt upgrade</code></html> on individual servers leaves no audit trail, can't be rolled back, and offers no observability. Progressive rollout catches issues early; manual one-shot updates export the cost of failure to all downstream servers.
----
''Sources''
* <html><code>training/library/topics/ansible/thinking_out_loud.md</code></html>
''Related atoms''
* [[Rolling Updates with Zero Downtime]]
* [[Structured Playbooks Provide Auditability and Idempotency]]
* [[Config drift encodes production fixes; reverting it re-introduces the problems]]
Q: Who created Ansible and when?
A: Michael DeHaan created Ansible in February 2012. He had previously created Cobbler (a provisioning tool) and Func (a remote command framework).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
* [[What year was Ansible first released?]]
* [[What is `ansible-creator`?]]
Q: What two open-source projects did Michael DeHaan create before Ansible, both at Red Hat?
A: Cobbler (a PXE-based bare-metal provisioning tool) and Func (a remote command execution framework). Concepts from both influenced Ansible's design.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Who created Ansible, and in what year was it first released?]]
* [[What was Michael DeHaan's job before creating Ansible, and why did he leave?]]
* [[When did Red Hat acquire Ansible?]]
Q: What other tools did Michael DeHaan create before Ansible?
A: Cobbler (provisioning tool) and Func (remote command framework).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible originated from a weekend prototype in February 2012]]
* [[Michael DeHaan stepped back from Ansible after Red Hat acquisition]]
* [[Who created Ansible, and in what year was it first released?]]
Q: When and by whom was Ansible acquired?
A: Red Hat acquired Ansible in October 2015.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
* [[Who created Ansible and when?]]
Q: Where does the name "Ansible" come from?
A: The name comes from science fiction -- specifically a faster-than-light communication device. The term was first coined by Ursula K. Le Guin in her 1966 novel "Rocannon's World" and later popularized by Orson Scott Card in "Ender's Game" (1985), where the ansible is used to command a fleet of distant ships instantaneously.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Many people attribute the word "ansible" to Orson Scott Card's *Ender's Game*. Why is t…]]
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
* [[Who created Ansible and when?]]
Q: What science fiction novel first coined the word "ansible," and who wrote it?
A: Ursula K. Le Guin coined the term in her 1966 novel //Rocannon's World//. It referred to a device enabling instantaneous faster-than-light communication.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the etymology of the word "ansible"?]]
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
* [[Many people attribute the word "ansible" to Orson Scott Card's *Ender's Game*. Why is t…]]
Q: What language is Ansible written in?
A: Python (and PowerShell for Windows modules).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_python_interpreter`?]]
* [[What is the `ansible.windows` collection?]]
* [[What language is Ansible written in? What about Puppet, Chef, and SaltStack?]]
Q: What are the key features of Ansible?
A: Agentless architecture, SSH-based communication, human-readable YAML syntax, idempotent operations, push-based model, extensive module library, inventory management, and a large community ecosystem.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What's your experience with Ansible?]]
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[How does Ansible differ from other configuration management tools?]]
Q: What are the main components of Ansible's architecture?
A: Control node, managed nodes, inventory, playbooks, modules, tasks, roles, handlers, variables, facts, plugins, and the Ansible configuration file (ansible.cfg).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the key components of Ansible.]]
* [[What are the three main components of an Ansible rulebook?]]
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
Q: What does "agentless" mean in the context of Ansible?
A: No software agents need to be installed on managed nodes. Ansible connects via SSH (Linux) or WinRM (Windows) directly from the control node.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Which of the "big four" (Ansible, Puppet, Chef, Salt) are agentless?]]
* [[Ansible managed node]]
* [[Ansible's agentless design: SSH over a custom control protocol]]
Q: How does Ansible differ from Puppet?
A: Ansible is agentless (push-based, YAML syntax) while Puppet is agent-based (pull-based, uses its own DSL). Ansible is simpler to set up; Puppet is more mature for large-scale, complex environments.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible is sometimes described as "procedural" while Puppet is "declarative." What does…]]
* [[How does Ansible differ from other configuration management tools?]]
* [[Ansible: agentless IT automation tool]]
Q: How does Ansible differ from SaltStack?
A: Both can be agentless, but SaltStack also supports an agent-based (minion) model. SaltStack uses its own DSL and is typically faster at scale due to ZeroMQ messaging, while Ansible is simpler and uses SSH.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What language is Ansible written in? What about Puppet, Chef, and SaltStack?]]
* [[Which of the "big four" (Ansible, Puppet, Chef, Salt) are agentless?]]
* [[How does Ansible differ from Puppet?]]
Q: What makes SaltStack's execution speed notably faster than Ansible for large fleets?
A: Salt uses persistent ZeroMQ connections to pre-installed minion agents, enabling near-simultaneous command execution across thousands of nodes. Ansible must establish SSH connections serially (limited by forks), which is inherently slower.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
* [[Ansible performance optimization for large inventories]]
* [[Forks control Ansible parallelism]]
Q: What are the server requirements for Ansible?
A: The control node requires Linux/macOS with Python 2.6+ (or Python 3.5+). Managed nodes need SSH access and Python. Windows managed nodes need WinRM and PowerShell.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
* [[Ansible managed node]]
* [[Ansible control node]]
Q: How does Ansible communicate with Linux hosts?
A: Via SSH (Secure Shell). It pushes modules to the managed node, executes them, and retrieves results as JSON.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible connect to managed nodes?]]
* [[How does Ansible communicate with Windows hosts?]]
* [[Ansible Modules]]
Q: How does Ansible communicate with Windows hosts?
A: Via WinRM (Windows Remote Management) with PowerShell modules.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Connection plugins determine how Ansible communicates with targets]]
* [[What is the `ansible.windows` collection?]]
* [[How does Ansible communicate with Linux hosts?]]
Q: What protocol does Ansible use to manage Windows hosts?
A: WinRM (Windows Remote Management), a SOAP-based protocol over HTTP/HTTPS. Ansible can use it through the <html><code>psrp</code></html> or <html><code>winrm</code></html> connection plugins.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Can Ansible use SSH to manage Windows?]]
* [[Can you run Ansible on Windows as a control node?]]
* [[What is the `ansible.windows` collection?]]
Q: What is the push-based model in Ansible?
A: The control node initiates connections and pushes configurations to managed nodes, as opposed to pull-based models where agents on nodes poll a central server.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Which tools are push-based vs. pull-based by default?]]
* [[When is ansible-pull appropriate?]]
* [[What does ansible-pull require on each managed node?]]
Q: When would you use ansible-pull instead of the default push model?
A: For decentralized environments, self-healing systems, edge devices, or scenarios where nodes should independently fetch and apply configurations from a Git repository on a schedule.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When is ansible-pull appropriate?]]
* [[Which tools are push-based vs. pull-based by default?]]
* [[How is ansible-pull typically scheduled?]]
Q: When is ansible-pull preferred over the normal push model?
A: Auto-scaling environments (new instances configure themselves), edge deployments, large fleets where a central control node would be a bottleneck, and environments where nodes can't be reached from a central point (firewalled, NAT'd).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Which tools are push-based vs. pull-based by default?]]
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
While Ansible is known as a push-based tool — control node connects to targets and runs plays — <html><code>ansible-pull</code></html> inverts the entire execution model. Each managed node pulls its playbook from a git repository and runs it locally via cron or systemd timer. This eliminates the SSH fan-out bottleneck of push-mode and scales to thousands of nodes without overwhelming the control node's network I/O. Several large organizations use ansible-pull for server baseline configuration and compliance checking, reserving push-mode for orchestrated deployments that require cross-host coordination (rolling updates, database migrations, blue-green deploys) where sequencing matters. Both modes solve different scaling problems.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How is ansible-pull typically scheduled?]]
* [[What does ansible-pull require on each managed node?]]
* [[Which tools are push-based vs. pull-based by default?]]
Q: What is Infrastructure as Code (IaC) and how does Ansible align with it?
A: IaC manages infrastructure through version-controlled code rather than manual processes. Ansible aligns by using YAML playbooks to define infrastructure tasks in a readable, code-like format, ensuring repeatability and idempotency.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How is Ansible used in a CI/CD pipeline?]]
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
Q: When did Ansible collections replace the monolithic package?
A: Ansible 2.10 (September 2020) split the package into <html><code>ansible-core</code></html> (runtime engine) and separate collections. Ansible 2.9 was the last monolithic release.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was "ansible-base" and when did it appear?]]
* [[How many modules were in the monolithic Ansible 2.9 repository before the split?]]
* [[What was the major architectural change in Ansible 2.0?]]
Q: When was Ansible 2.10 (the first "split" release) published?
A: September 2020 -- the first release with the monolithic content split into ansible-base + collections.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was "ansible-base" and when did it appear?]]
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
* [[When did the collections concept first appear in Ansible?]]
Q: What was the major architectural change in Ansible 2.0?
A: A complete rewrite of the core engine with a new execution framework, improved variable handling, and better error reporting.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was "ansible-base" and when did it appear?]]
* [[When did Ansible collections replace the monolithic package?]]
* [[What are the key features of Ansible?]]
Q: What is the relationship between ansible-core and the ansible package?
A: <html><code>ansible-core</code></html> contains the runtime engine, CLI tools, and built-in plugins/modules. The <html><code>ansible</code></html> package is a meta-package that installs <html><code>ansible-core</code></html> plus a curated set of community collections.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are Ansible plugins?]]
* [[What is the `ansible.builtin.package` module?]]
* [[What are the main components of Ansible's architecture?]]
Q: What is the difference between ansible-dev-tools and ansible-core?
A: ansible-core is the automation engine itself. ansible-dev-tools is a meta-package bundling development and testing tools: ansible-lint, molecule, ansible-navigator, ansible-builder, ansible-creator, and more.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the two categories of Ansible modules?]]
* [[What is Ansible Networking, and how is it different from traditional Ansible?]]
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
Q: What versioning scheme does ansible-core follow vs the ansible package?
A: <html><code>ansible-core</code></html> uses traditional semver (e.g., 2.15.x, 2.16.x). The <html><code>ansible</code></html> package uses independent versioning (e.g., 7.x, 8.x, 9.x) where each major version pins a specific ansible-core version.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
* [[How long is each ansible-core major version maintained?]]
* [[How often does ansible-core release a new major version?]]
Q: Explain the versioning split that happened at Ansible 2.10. What are the two separate packages?
A: Starting with 2.10, Ansible split into two packages: (1) ansible-core (originally ansible-base), which is the automation engine with minimal built-in content, and (2) the "ansible" community package, which bundles ansible-core with a curated set of community collections.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_version`?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[What was "ansible-base" and when did it appear?]]
Q: Why do Ansible community package version numbers jump from 2.10 to 3.0, 4.0, etc., while ansible-core continues with 2.11, 2.12, etc.?
A: The community package adopted a new versioning scheme (3.x, 4.x, 5.x...) to differentiate it from ansible-core versioning. ansible-core continues the 2.x line. For example, Ansible 4.0.0 shipped with ansible-core 2.11, Ansible 5.0.0 with ansible-core 2.12, and so on.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
* [[What is `ansible_version`?]]
* [[When did Ansible collections replace the monolithic package?]]
Q: When was Ansible Tower renamed to automation controller?
A: With the release of Ansible Automation Platform 2.0 in late 2021.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was "ansible-base" and when did it appear?]]
* [[What is the Ansible Tower rebrand name?]]
* [[What year did Ansible Tower (the commercial UI product) first appear?]]
Q: What is the relationship between Ansible Tower and Automation Controller?
A: Automation Controller is the rebranded name for Ansible Tower, starting with AAP 2.x. The underlying technology (AWX upstream) remains the same, but "Tower" branding was retired in favor of "Automation Controller."
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Ansible Tower?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
Q: Who created Ansible, and in what year was it first released?
A: Michael DeHaan created Ansible and released it as an open-source project in February 2012.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was the first AnsibleFest, and when did it take place?]]
* [[What year did Ansible Galaxy launch?]]
* [[What two open-source projects did Michael DeHaan create before Ansible, both at Red Hat?]]
Q: What year was Ansible first released?
A: 2012.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What year was Ansible Lightspeed announced?]]
* [[What was the first commit to the Ansible GitHub repository, and approximately when?]]
* [[What was the first AnsibleFest, and when did it take place?]]
Q: Many people attribute the word "ansible" to Orson Scott Card's //Ender's Game//. Why is that incorrect for the original coinage?
A: Card popularized the term in //Ender's Game// (1985), but Le Guin invented it 19 years earlier in 1966. Card's usage spread the word to a much wider audience, creating the common misattribution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where does the name "Ansible" come from?]]
* [[What is the etymology of the word "ansible"?]]
* [[What science fiction novel first coined the word "ansible," and who wrote it?]]
Q: What is the etymology of the word "ansible"?
A: It is a contraction of "answerable" -- reflecting the device's ability to deliver responses across interstellar distances in reasonable time.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What science fiction novel first coined the word "ansible," and who wrote it?]]
* [[What is `ansible_port`?]]
* [[Many people attribute the word "ansible" to Orson Scott Card's *Ender's Game*. Why is t…]]
Q: What was the original company name behind Ansible before it became "Ansible, Inc."?
A: AnsibleWorks, Inc., founded in 2013 by Michael DeHaan, Timothy Gerla, and Said Ziouani.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
* [[Who created Ansible and when?]]
* [[Where does the name "Ansible" come from?]]
Q: How many employees did Ansible, Inc. have at the time of the Red Hat acquisition?
A: Approximately 50 employees worldwide, headquartered in Durham, North Carolina.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[How did Ansible end up under IBM's umbrella?]]
Q: Where was Ansible, Inc. originally based before the Red Hat acquisition?
A: The company was based out of Durham, N.C., though some sources also reference Santa Barbara, California as an early location.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
* [[How many employees did Ansible, Inc. have at the time of the Red Hat acquisition?]]
* [[How did Ansible end up under IBM's umbrella?]]
Q: What was the first AnsibleFest, and when did it take place?
A: The first AnsibleFest was held in 2013 in the early days of the Ansible community, organized by AnsibleWorks (later Ansible, Inc.) to bring together early adopters.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Who created Ansible, and in what year was it first released?]]
* [[What year was Ansible first released?]]
* [[What year did Ansible Galaxy launch?]]
Q: What happened to AnsibleFest after 2022?
A: Starting in 2024, AnsibleFest was merged with Red Hat Summit into a combined "Red Hat Summit and AnsibleFest" event, rather than running as a separate standalone conference.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When did Red Hat acquire Ansible?]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[How did Ansible end up under IBM's umbrella?]]
Q: What was significant about Ansible 1.0, and when was it released?
A: Ansible 1.0 was released in early 2013 (around February). It marked the project's first stable release, establishing the core push-based, agentless, SSH-driven architecture.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Who created Ansible, and in what year was it first released?]]
* [[What was "ansible-base" and when did it appear?]]
* [[What year did Ansible Tower (the commercial UI product) first appear?]]
Q: What did Ansible 2.5 introduce that changed how network automation worked?
A: Ansible 2.5 introduced the network_cli, httpapi, and netconf connection plugins, fundamentally changing how Ansible connected to network devices by using persistent connections instead of spawning a new connection per task.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Ansible Networking, and how is it different from traditional Ansible?]]
* [[How does Ansible manage network devices?]]
* [[What are specific challenges you might face when using Ansible for network automation?]]
Q: What was "ansible-base" and when did it appear?
A: ansible-base was the name for the stripped-down core engine introduced with the 2.10 release cycle (mid-2020). It contained only the command-line tools, core modules (like copy, file, command, shell), and essential plugins. It was renamed to "ansible-core" starting with version 2.11.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[When was Ansible Tower renamed to automation controller?]]
* [[When did Ansible collections replace the monolithic package?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
Q: What Ansible community package version corresponds to ansible-core 2.14?
A: Ansible 7.x ships with ansible-core 2.14.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What command shows the Ansible version?]]
* [[What versioning scheme does ansible-core follow vs the ansible package?]]
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
Q: How often does ansible-core release a new major version?
A: Approximately every six months, typically in May and November, with a 4-week Z-release patch cycle for bugfixes and security fixes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What versioning scheme does ansible-core follow vs the ansible package?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[Why do Ansible community package version numbers jump from 2.10 to 3.0, 4.0, etc., whil…]]
Q: How long is each ansible-core major version maintained?
A: Each ansible-core major release is maintained for approximately 18 months (the current release plus two prior versions are actively maintained).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What versioning scheme does ansible-core follow vs the ansible package?]]
* [[What is the deprecation cycle length in ansible-core for features?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
Q: When was the last time the migration script (migrate.py) was run to move content from the monolithic ansible repo to collections?
A: The final migration run happened on Friday, March 6, 2020. The ansible-community/collection_migration repository was left as a historical record.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When did Ansible collections replace the monolithic package?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[When did the collections concept first appear in Ansible?]]
Q: What is the <html><code>ansible_managed</code></html> variable?
A: A special variable that expands to a string (configurable in ansible.cfg) containing metadata about the Ansible template. Default: "Ansible managed". Commonly placed in template file headers to warn humans not to edit managed files.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What are variables in Ansible?]]
* [[What is the `ansible.builtin.debug` module's `var` vs `msg` parameter?]]
* [[What are "magic variables" in Ansible?]]
Q: Can you run Ansible on Windows as a control node?
A: No. Ansible's control node must run on a Unix-like system (Linux, macOS, BSDs). Windows can only be a managed node (via WinRM or PSRP). WSL (Windows Subsystem for Linux) is the workaround for running Ansible on Windows.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Ansible manages Windows servers via WinRM]]
* [[What protocol does Ansible use to manage Windows hosts?]]
* [[Can Ansible use SSH to manage Windows?]]
Q: What is the "cow" in Ansible output?
A: Ansible can display output using cowsay (ASCII art cow). If cowsay is installed, Ansible uses it by default for playbook output. It can be disabled with <html><code>ANSIBLE_NOCOWS=1</code></html> or <html><code>nocows = 1</code></html> in ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What information is available in the output when using the --check option?]]
* [[What file format does Ansible use for its return data from modules?]]
Q: What environment variable disables Ansible's cowsay output?
A: <html><code>ANSIBLE_NOCOWS=1</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible's cowsay Easter egg was designed for morale]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
Q: What does <html><code>ANSIBLE_NOCOWS</code></html> do?
A: Disables the cowsay output formatting that Ansible uses when cowsay is installed.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `no_log: true` directive?]]
* [[What does `ansible_check_mode` contain?]]
* [[What information is available in the output when using the --check option?]]
Q: What is <html><code>ansible-inventory --graph</code></html>?
A: A command that displays the inventory hierarchy as an ASCII tree graph, showing groups, subgroups, and hosts. Adding <html><code>--vars</code></html> also shows the variables for each host.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is an Ansible inventory?]]
* [[Ansible inventory file: definition and configuration]]
* [[What command lists all hosts in an inventory?]]
Q: What is the <html><code>.retry</code></html> file that Ansible creates?
A: When a playbook fails on some hosts, Ansible creates a <html><code>.retry</code></html> file containing the hostnames that failed. You can re-run only the failed hosts with <html><code>--limit @playbook.retry</code></html>. This behavior can be disabled in ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `retry_until` pattern in Ansible?]]
* [[What is the `ansible.builtin.reboot` module?]]
* [[What is `ansible_play_hosts`?]]
Q: What is <html><code>ansible-doc</code></html> used for?
A: Viewing documentation for modules, plugins, filters, and other Ansible components from the command line without needing internet access. Example: <html><code>ansible-doc ansible.builtin.copy</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[ansible-doc: offline module documentation reference]]
* [[What is the `ansible.posix` collection?]]
* [[What is `ansible-builder`?]]
Q: What does the <html><code>ANSIBLE_KEEP_REMOTE_FILES</code></html> setting do?
A: When set to True, Ansible does NOT delete the temporary module files it copies to the remote host after execution. Extremely useful for debugging module behavior -- you can SSH to the target and inspect/run the module code manually.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Where are remote temporary files stored on managed nodes?]]
* [[Explain the purpose of the "copy" module in Ansible.]]
* [[What is the `ansible.builtin.reboot` module?]]
Q: Where are remote temporary files stored on managed nodes?
A: By default in <html><code>~/.ansible/tmp/</code></html> on the remote host (configurable via <html><code>remote_tmp</code></html> in ansible.cfg).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `ANSIBLE_KEEP_REMOTE_FILES` setting do?]]
Q: What is <html><code>ansible-config dump</code></html>?
A: Displays all current configuration settings with their values and sources (default, config file, environment variable). <html><code>ansible-config dump --only-changed</code></html> shows only settings that differ from defaults.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 10 source atoms.//
''Related atoms''
* [[What is ansible.cfg?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
Q: What does <html><code>meta: flush_handlers</code></html> do?
A: Forces all pending handlers to execute at that point in the play, instead of waiting until the end of the play. Useful when subsequent tasks depend on services being restarted.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[How do you force handlers to run mid-play?]]
* [[What is `meta: end_play`?]]
* [[What does `force_handlers: yes` do?]]
Q: What is the <html><code>ANSIBLE_STDOUT_CALLBACK</code></html> environment variable?
A: Selects which stdout callback plugin to use (e.g., <html><code>yaml</code></html>, <html><code>json</code></html>, <html><code>minimal</code></html>, <html><code>debug</code></html>). Equivalent to <html><code>stdout_callback</code></html> in ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is a callback plugin?]]
* [[What is the `ansible.builtin.debug` module's `var` vs `msg` parameter?]]
* [[What internal arguments does Ansible automatically inject into every module call?]]
Q: What is <html><code>ansible-galaxy collection verify</code></html>?
A: Verifies the integrity of installed collections by comparing checksums against the Galaxy server manifest. Detects if collection files have been modified locally.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What does `ansible_check_mode` contain?]]
* [[What is `ansible-playbook --syntax-check`?]]
* [[What is the galaxy.yml file in a collection?]]
Q: What is the <html><code>COLLECTIONS_PATHS</code></html> configuration?
A: Defines the search paths where Ansible looks for installed collections. Default: <html><code>~/.ansible/collections:/usr/share/ansible/collections</code></html>. Can be set in ansible.cfg or via the <html><code>ANSIBLE_COLLECTIONS_PATH</code></html> environment variable.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What does `ansible_search_path` contain?]]
* [[What subcommand in ansible-navigator lists available collections inside an EE?]]
* [[What is `ANSIBLE_ROLES_PATH`?]]
Q: What is the obscure <html><code>ANSIBLE_FORCE_COLOR</code></html> environment variable?
A: Forces colored output even when Ansible detects it's not running in a terminal (e.g., in CI/CD pipelines). Useful for readable CI logs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What environment variable disables Ansible's cowsay output?]]
* [[How do you implement blue-green deployments with Ansible?]]
Q: What is the <html><code>ansible.cfg</code></html> <html><code>[inventory]</code></html> section's <html><code>enable_plugins</code></html> setting?
A: Controls which inventory plugins are loaded. By default, only <html><code>host_list</code></html>, <html><code>script</code></html>, <html><code>auto</code></html>, <html><code>yaml</code></html>, <html><code>ini</code></html>, and <html><code>toml</code></html> are enabled. Cloud inventory plugins (aws_ec2, gcp_compute) must be explicitly enabled.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `ansible-inventory --list` do?]]
* [[What is ansible.cfg?]]
* [[Where is the default inventory file located?]]
Q: What is the <html><code>INTERPRETER_PYTHON</code></html> configuration, and why was <html><code>auto</code></html> mode added?
A: Controls which Python interpreter Ansible uses on managed nodes. The <html><code>auto</code></html> mode (default since 2.8) uses a lookup table to find the correct Python path per platform, avoiding the <html><code>/usr/bin/python</code></html> vs <html><code>/usr/bin/python3</code></html> headache.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Why does Ansible have separate Python requirements for control node vs. managed nodes?]]
Q: What is <html><code>ansible_python_interpreter</code></html>?
A: Specifies the path to Python on the managed node (useful when the default <html><code>/usr/bin/python</code></html> is incorrect).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What language is Ansible written in?]]
* [[What is the `ansible.builtin.package` module?]]
Q: What is the <html><code>auto</code></html> interpreter discovery in Ansible?
A: Starting in Ansible 2.8, when <html><code>ansible_python_interpreter</code></html> is not set, Ansible uses a platform-specific discovery table to find the correct Python interpreter, preferring <html><code>/usr/bin/python3</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What language is Ansible written in?]]
* [[What is the `ansible.builtin.package` module?]]
* [[What is the `ansible.builtin.find` module?]]
Q: What is an "action plugin" and how does it differ from a module?
A: An action plugin runs on the control node before (and sometimes instead of) the module on the remote host. Some modules are actually action plugins in disguise (e.g., template, copy, fetch). The action plugin handles local processing and file transfer, while the module handles remote state.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `local_action` keyword?]]
* [[Modules execute on targets; plugins run on the controller and extend Ansible]]
* [[What are Ansible plugins?]]
Q: What is the <html><code>ansible_become_exe</code></html> variable?
A: Specifies the path to the privilege escalation binary. Default: <html><code>/usr/bin/sudo</code></html>. Useful when sudo is installed in a non-standard location.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `become_method` setting and what values does it support?]]
* [[What are Ansible's default privilege escalation methods?]]
* [[What happens when you apply `become: true` with the `local` connection?]]
Q: What is <html><code>gather_subset</code></html> and how does it speed up fact gathering?
A: Instead of gathering all facts, you can specify a subset: <html><code>gather_subset: [network, hardware]</code></html> or <html><code>gather_subset: [!hardware, !virtual]</code></html>. Minimizing gathered facts reduces setup time.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[Selective fact gathering skips unnecessary system queries]]
* [[What are the available gather_subset categories?]]
* [[What does the `gather_facts: false` optimization do?]]
Q: What are the <html><code>gather_subset</code></html> and <html><code>gather_timeout</code></html> options?
A: <html><code>gather_subset</code></html> limits which facts to collect (e.g., <html><code>network</code></html>, <html><code>hardware</code></html>, <html><code>virtual</code></html>, <html><code>!facter</code></html>). <html><code>gather_timeout</code></html> sets the maximum time for fact gathering.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the available gather_subset categories?]]
* [[Selective fact gathering skips unnecessary system queries]]
* [[What does the `gather_facts: false` optimization do?]]
Q: What are the available gather_subset categories?
A: all, min (always gathered), network, hardware, virtual, ohai, facter, env (environment variables), and several more depending on the platform.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `gather_subset` and how does it speed up fact gathering?]]
* [[What are the `gather_subset` and `gather_timeout` options?]]
* [[Selective fact gathering skips unnecessary system queries]]
Q: What are custom facts (local facts) and where do they live?
A: Custom facts are files placed in <html><code>/etc/ansible/facts.d/</code></html> on managed hosts. They can be INI, JSON, or executable files returning JSON. They appear under <html><code>ansible_local</code></html> in gathered facts.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is `ansible_facts` vs top-level fact variables?]]
* [[If you create a custom fact in the same play, how do you access it?]]
* [[What is the `INJECT_FACTS_AS_VARS` configuration?]]
Q: Under what namespace are custom local facts accessible?
A: <html><code>ansible_local</code></html> -- e.g., <html><code>ansible_local.custom_fact_name.key</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible facts: auto-discovered host variables]]
* [[What is the `INJECT_FACTS_AS_VARS` configuration?]]
* [[What module gathers facts by default at the start of each play?]]
Q: What is <html><code>ansible_local</code></html>?
A: Facts defined in local .fact files placed in /etc/ansible/facts.d/ on the managed host. These are custom facts that persist on the target machine and are gathered automatically.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[If you create a custom fact in the same play, how do you access it?]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[What module gathers facts by default at the start of each play?]]
Q: What is <html><code>ansible.builtin.set_stats</code></html>?
A: A module that sets custom statistics for playbook runs, visible in Automation Controller/AWX. Stats are displayed in the job summary and can be used for reporting.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `set_fact`?]]
* [[What module gathers facts by default at the start of each play?]]
* [[What are Ansible "playbooks"?]]
Q: What is the <html><code>set_stats</code></html> module?
A: Sets custom statistics that are displayed at the end of a playbook run. Useful for reporting.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `set_fact`?]]
Q: What happens if you use <html><code>vars_prompt</code></html> in Ansible Tower/Controller?
A: Tower/Controller presents a survey form to the user before job execution, mapping survey fields to the prompt variables. In CLI mode, the user is prompted interactively.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Ansible Tower Surveys, and how do they work?]]
* [[What is `vars_prompt`?]]
* [[What is the difference between `vars`, `vars_files`, and `vars_prompt`?]]
Q: What is the <html><code>ansible_date_time</code></html> fact?
A: A fact containing the managed host's date/time in multiple formats: date, time, epoch, iso8601, tz, weekday, year, month, day, hour, minute, second, and more.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_local`?]]
* [[What module gathers facts by default at the start of each play?]]
Q: What happens when you apply <html><code>become: true</code></html> with the <html><code>local</code></html> connection?
A: Privilege escalation happens on the control node itself. Ansible will sudo on the machine running the playbook, which can be dangerous and is often unintended.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `become_method` setting and what values does it support?]]
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[What is the `ansible_become_exe` variable?]]
Q: What is the <html><code>environment</code></html> keyword at the task/play/block level?
A: Sets environment variables for the remote execution context. Example: setting <html><code>http_proxy</code></html>, <html><code>PATH</code></html>, or <html><code>LD_LIBRARY_PATH</code></html> for tasks that need them on the remote host.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[How do you set the PATH or environment variables for a task?]]
Q: What is the <html><code>environment</code></html> keyword used for?
A: Sets environment variables for task execution on the remote host.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
Q: What happens if two collections provide a module with the same short name?
A: Ansible uses the <html><code>collections</code></html> keyword search order to resolve ambiguity. If no <html><code>collections</code></html> keyword is set, it falls back to <html><code>ansible.builtin</code></html>. This is exactly why FQCNs are recommended -- they eliminate ambiguity entirely.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Fully Qualified Collection Name (FQCN), and why does it matter post-migration?]]
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[Collections are distributable packages of roles, modules, and plugins]]
Q: What happens if you use a short module name (e.g., "copy") instead of the FQCN in a post-2.10 playbook?
A: Ansible resolves it using the collections keyword search path or falls back to ansible.builtin. It still works for built-in modules, but using short names for collection modules is ambiguous and deprecated behavior. Best practice is always FQCN.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Fully Qualified Collection Name (FQCN), and why does it matter post-migration?]]
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[What does the `fqcn` lint rule require?]]
Q: Can a handler notify another handler?
A: Yes, since Ansible 2.2. Handlers can chain notifications to other handlers, creating cascading restart sequences.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Handlers Only Fire When Task Status Changes]]
* [[Ansible handlers: conditional, once-only task execution]]
* [[Handlers run once at play end, triggered by task notifications]]
Q: Can handlers notify other handlers?
A: Yes. Handlers can contain <html><code>notify</code></html> directives to trigger other handlers, creating a chain.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `listen` directive on handlers?]]
* [[What happens if a handler is notified multiple times?]]
* [[What is the `notify` keyword?]]
Q: What is the <html><code>listen</code></html> directive on handlers?
A: Allows a handler to respond to a generic notification topic rather than being called by exact name. Multiple handlers can listen to the same topic. Example: all handlers with <html><code>listen: "restart web stack"</code></html> run when any task notifies "restart web stack".
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[Can handlers notify other handlers?]]
* [[Handlers run once at play end, triggered by task notifications]]
* [[What is the `notify` keyword?]]
Q: What is <html><code>ansible-playbook --syntax-check</code></html>?
A: Parses the playbook and checks for YAML/Ansible syntax errors without executing anything. Faster than --check but only catches structural problems.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you test Ansible safely?]]
* [[What is the purpose of an Ansible Playbook?]]
* [[What command runs an Ansible playbook?]]
Q: How do you check a playbook's syntax without running it?
A: <html><code>ansible-playbook --syntax-check playbook.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How can you detect check mode inside a playbook?]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
* [[How do you enable verbose mode for Ansible playbooks?]]
Q: What is the <html><code>debug</code></html> module's <html><code>verbosity</code></html> parameter?
A: Controls at which verbosity level (-v, -vv, -vvv, -vvvv) the debug message appears. <html><code>verbosity: 2</code></html> means the message only shows with -vv or higher.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the four verbosity levels in Ansible?]]
* [[What does the `debug` module do?]]
Q: What are the four verbosity levels in Ansible?
A: -v (verbose -- task results), -vv (more verbose -- task input), -vvv (even more -- connection debugging), -vvvv (maximum -- includes connection plugin details and local script execution).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the use of the -vvv option when running Ansible commands.]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[How do you enable verbose mode for Ansible playbooks?]]
Q: What Ansible module is used to create scheduled tasks on Windows?
A: <html><code>win_scheduled_task</code></html> (now <html><code>ansible.windows.win_scheduled_task</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible.windows` collection?]]
* [[What protocol does Ansible use to manage Windows hosts?]]
* [[Ansible manages Windows servers via WinRM]]
Q: What is <html><code>ansible-test</code></html>?
A: The testing tool bundled with ansible-core for testing collections. It supports sanity tests (code style, import checks), unit tests (Python unittest), and integration tests (full playbook runs).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you test Ansible safely?]]
* [[How do you test playbooks?]]
Q: What are Ansible test plugins?
A: Jinja2 test functions used in <html><code>when</code></html> conditionals: <html><code>is defined</code></html>, <html><code>is undefined</code></html>, <html><code>is match</code></html>, <html><code>is search</code></html>, <html><code>is regex</code></html>, <html><code>is file</code></html>, <html><code>is directory</code></html>, <html><code>is link</code></html>, etc.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Jinja2 tests check conditions in when clauses and conditionals]]
* [[What are Ansible plugins?]]
* [[What is Jinja2 in the context of Ansible?]]
Q: What file format does Ansible use for its return data from modules?
A: JSON. Every Ansible module returns a JSON dictionary to stdout, which the controller parses. This is why modules can be written in any language -- they just need to output valid JSON.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Why does Ansible mark all strings returned by modules as "Unsafe"?]]
* [[What language is Ansible written in?]]
* [[What Python class must every custom Ansible module import?]]
Q: What is an "Execution Environment" in the Ansible ecosystem?
A: A container image containing ansible-core, Python dependencies, collections, and system libraries needed to run automation. Built with <html><code>ansible-builder</code></html> and used by Automation Controller and ansible-navigator.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the difference between a Decision Environment and an Execution Environment in E…]]
* [[Execution Environments solved the dependency-conflict problem in Ansible]]
Q: What is an Ansible Execution Environment (EE)?
A: An EE is an OCI-compliant container image that serves as a portable, reproducible [[Ansible control node]]. It packages ansible-core, Python dependencies, system libraries, and Ansible collections into a single container image, eliminating "works on my machine" inconsistencies.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What tool is used to build Execution Environments?]]
* [[Execution Environments solved the dependency-conflict problem in Ansible]]
* [[What is `ansible-builder`?]]
Q: What is <html><code>ansible-builder</code></html>?
A: A tool that creates Execution Environment container images from a definition file (execution-environment.yml) that specifies Python requirements, system packages, collections, and the base image.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-creator`?]]
* [[What is the `ansible.builtin.package` module?]]
Q: What tool is used to build Execution Environments?
A: <html><code>ansible-builder</code></html>. It reads an <html><code>execution-environment.yml</code></html> definition file and uses a container runtime (podman or docker) to build the EE image.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is an Ansible Execution Environment (EE)?]]
* [[What are the key sections in an `execution-environment.yml` file?]]
Q: What is <html><code>until</code></html> / <html><code>retries</code></html> / <html><code>delay</code></html> in a task?
A: Retry loop configuration. <html><code>until</code></html> specifies the success condition, <html><code>retries</code></html> is the max attempts (default 3), and <html><code>delay</code></html> is seconds between retries. Example: poll an API until it returns healthy.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `wait_for` module do?]]
* [[What is `wait_for_connection` used for?]]
Q: What is <html><code>register</code></html> and what does the registered variable contain?
A: <html><code>register</code></html> captures a task's return data into a variable. The variable contains: changed, failed, rc (return code), stdout, stderr, stdout_lines, stderr_lines, msg, and module-specific keys.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "two-stage" or "delegate and register" pattern?]]
* [[What is the `failed_when: false` idiom?]]
Q: What is the <html><code>register</code></html> keyword?
A: Captures the output of a task into a variable for use in subsequent tasks. Enables conditional logic based on previous task results.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "two-stage" or "delegate and register" pattern?]]
* [[What is the `failed_when: false` idiom?]]
Q: What is <html><code>register</code></html> in Ansible?
A: Captures the return value of a task into a variable for use in subsequent tasks. The registered variable contains <html><code>stdout</code></html>, <html><code>stderr</code></html>, <html><code>rc</code></html>, <html><code>changed</code></html>, <html><code>failed</code></html>, and module-specific keys.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_loop`?]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
Q: What is <html><code>ansible_play_name</code></html>?
A: A magic variable containing the name of the currently executing play.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_play_hosts`?]]
* [[What is a play in Ansible?]]
* [[What command runs an Ansible playbook?]]
Q: What is <html><code>ansible_play_batch</code></html>?
A: A magic variable containing the list of hosts in the current batch when using <html><code>serial</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible.builtin.add_host`?]]
* [[What is `ansible_host` in inventory?]]
* [[What is the gotcha with `run_once` and `serial`?]]
Q: What is the <html><code>omit</code></html> variable in Ansible?
A: A special variable used to conditionally exclude a module parameter entirely. Example: <html><code>mode: "{{ file_mode | default(omit) }}"</code></html> -- if file_mode is undefined, the mode parameter is not passed to the module at all (as if it wasn't written).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happens if you reference an undefined variable?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[What does `ansible_check_mode` contain?]]
Q: What is <html><code>omit</code></html>?
A: A special variable that, when used as a module parameter value, causes that parameter to be omitted entirely. Useful with conditional defaults: <html><code>mode: "{{ item.mode | default(omit) }}"</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `mandatory` filter do?]]
* [[How to make the variable "use_var" optional?]]
* [[What does the `default` filter do?]]
Q: What is <html><code>ansible_loop</code></html>?
A: A magic variable available inside loops (with loop/with_*) that contains metadata about the current iteration: index0, index, first, last, length, previtem, nextitem, revindex0, revindex.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `loop_control` directive?]]
* [[What happened to `with_items`, `with_dict`, `with_file`, etc.?]]
* [[What is `ansible_play_batch`?]]
Q: What does <html><code>loop_control: extended</code></html> provide?
A: Access to <html><code>ansible_loop.allitems</code></html>, <html><code>ansible_loop.index</code></html>, <html><code>ansible_loop.index0</code></html>, <html><code>ansible_loop.first</code></html>, <html><code>ansible_loop.last</code></html>, <html><code>ansible_loop.length</code></html>, <html><code>ansible_loop.revindex</code></html>, <html><code>ansible_loop.revindex0</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `loop_control` directive?]]
* [[What happened to `with_items`, `with_dict`, `with_file`, etc.?]]
* [[What is the `ansible.posix` collection?]]
Q: What happened to <html><code>with_items</code></html>, <html><code>with_dict</code></html>, <html><code>with_fileglob</code></html> etc.?
A: They still work but are considered legacy. The modern replacement is the <html><code>loop</code></html> keyword combined with filters: <html><code>loop: "{{ my_list }}"</code></html>, <html><code>loop: "{{ my_dict | dict2items }}"</code></html>, <html><code>loop: "{{ query('fileglob', '*.conf') }}"</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `with_items` and `loop`?]]
* [[What does `loop_control: extended` provide?]]
* [[What is `ansible_loop`?]]
Q: What happened to <html><code>with_items</code></html>, <html><code>with_dict</code></html>, <html><code>with_file</code></html>, etc.?
A: These are legacy loop constructs. Modern Ansible uses <html><code>loop:</code></html> with filters: <html><code>loop: "{{ my_list }}"</code></html>, <html><code>loop: "{{ my_dict | dict2items }}"</code></html>, etc.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `with_items` and `loop`?]]
* [[What is `ansible_loop`?]]
* [[What does `loop_control: extended` provide?]]
Q: What is the <html><code>ansible.builtin.pause</code></html> module?
A: Pauses playbook execution for a specified time or until the user presses Enter. Can also prompt for user input. Example: <html><code>pause: seconds=30</code></html> or <html><code>pause: prompt="Are you sure?"</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you set breakpoints or pause execution within an Ansible role for debugging?]]
* [[What does `ansible_check_mode` contain?]]
* [[What is `ansible-playbook --syntax-check`?]]
Q: What is the <html><code>pause</code></html> module?
A: Pauses playbook execution for a specified duration or until user input is provided.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is callback plugin `timer`?]]
* [[What does the `wait_for` module do?]]
* [[What does the `debug` module do?]]
Q: What is the <html><code>failed_when: false</code></html> idiom?
A: Makes a task NEVER fail, regardless of return code or output. The task always succeeds. Often combined with <html><code>register</code></html> to capture the result and handle it in subsequent tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `fail` module?]]
* [[What does `ignore_errors: true` do?]]
* [[What is `any_errors_fatal` and when would you use it?]]
Q: How does <html><code>failed_when</code></html> work?
A: It defines a custom condition for when a task should be considered failed, overriding the module's default success/failure determination. Example: <html><code>failed_when: "'ERROR' in result.stdout"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[How does a custom module return data to Ansible?]]
* [[What does `ignore_errors: true` do?]]
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
Q: What is the precedence order if the same variable is defined in group_vars for a parent group and a child group?
A: Child group variables override parent group variables. Ansible merges variables from parent to child, with the child winning. If a host is in multiple groups at the same level, alphabetical group name ordering determines precedence (last alphabetically wins).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
* [[Ansible variable precedence from lowest to highest: defaults → inventory → playbook → task → -e flag]]
* [[A variable is defined in playbook group_vars/all and also in inventory group_vars/webse…]]
Q: What is <html><code>hash_behaviour</code></html> in ansible.cfg?
A: Controls how dictionary variables are handled when the same variable is defined in multiple places. <html><code>replace</code></html> (default) replaces the entire dictionary. <html><code>merge</code></html> does a deep merge. The merge behavior is deprecated and being removed.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[Why is `hash_behaviour: merge` deprecated?]]
* [[What does `changed_when` do?]]
Q: Why is <html><code>hash_behaviour: merge</code></html> deprecated?
A: It causes globally unpredictable behavior, makes debugging variable values extremely difficult, and is a constant source of bugs. The recommended approach is explicit merging with the <html><code>combine</code></html> filter.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `hash_behaviour` in ansible.cfg?]]
* [[What does the `combine` filter do, and why is it so useful?]]
* [[What does the `combine` filter do?]]
Q: What is the maximum recommended inventory size for a single [[Ansible control node]]?
A: There is no hard limit, but practical performance degrades beyond several thousand hosts without tuning (increasing forks, enabling pipelining, using fact caching, using pull mode or AWX/Controller for very large fleets).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[High fork counts cause connection exhaustion and cascading failures]]
* [[Forks control Ansible parallelism]]
* [[Flat inventory prevents efficient fleet targeting]]
Q: What port does Ansible use by default for SSH connections?
A: Port 22 (standard SSH). Configurable via <html><code>ansible_port</code></html> per host or <html><code>remote_port</code></html> in ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is `ansible_connection` and where can it be set?]]
* [[What connection type does ansible-pull use?]]
Q: What is <html><code>ansible_port</code></html>?
A: An inventory variable that specifies the SSH port to use for connecting to the host.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happens with `port: 22` vs `port: "22"` in Ansible YAML?]]
* [[What is an Ansible inventory?]]
* [[What is `ansible_play_batch`?]]
Q: What port does WinRM use by default for Ansible Windows management?
A: Port 5985 for HTTP, port 5986 for HTTPS.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible communicate with Windows hosts?]]
* [[Ansible manages Windows servers via WinRM]]
Q: What was the first commit to the Ansible GitHub repository, and approximately when?
A: Michael DeHaan made the first commit to the ansible/ansible GitHub repository in February 2012.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What year was Ansible first released?]]
* [[What was the first AnsibleFest, and when did it take place?]]
* [[What was significant about Ansible 1.0, and when was it released?]]
Q: What year did Ansible Galaxy launch?
A: Ansible Galaxy launched in 2013, as a community hub for sharing Ansible roles.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Who created Ansible, and in what year was it first released?]]
* [[What was the first AnsibleFest, and when did it take place?]]
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
Q: What year did Ansible Tower (the commercial UI product) first appear?
A: Ansible Tower 1.0 was released in 2013 by AnsibleWorks, providing a web UI, REST API, and RBAC on top of Ansible.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What year was Ansible first released?]]
* [[What was significant about Ansible 1.0, and when was it released?]]
* [[Who created Ansible, and in what year was it first released?]]
Q: What year did Ansible 2.0 introduce the new execution engine?
A: January 2016.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was significant about Ansible 1.0, and when was it released?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[When did Ansible collections replace the monolithic package?]]
Q: When did the collections concept first appear in Ansible?
A: Collections were introduced as a concept in Ansible 2.8 (2019) and became the primary content distribution mechanism in Ansible 2.10 (2020).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[Why Use Ansible Collections?]]
* [[When did Ansible collections replace the monolithic package?]]
Q: What year was Event-Driven Ansible (EDA) first introduced?
A: 2022 as a technology preview, generally available in AAP 2.4 (2023).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What year was Ansible first released?]]
* [[What year was Ansible Lightspeed announced?]]
* [[Who created Ansible, and in what year was it first released?]]
Q: What is Event-Driven Ansible (EDA) and when was it introduced?
A: EDA was introduced as a technology preview in AAP 2.3 (2023) and became generally available in AAP 2.4. It allows automation to be triggered by events from external sources (monitoring tools, webhooks, ServiceNow, GitHub/GitLab) using rulebooks that define conditions and actions.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Name three event source plugins in the `ansible.eda` collection.]]
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[What is the structure of an EDA rulebook?]]
Q: What year was Ansible Lightspeed announced?
A: 2023, with integration into AAP and the VS Code Ansible extension.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What year was Ansible first released?]]
* [[What year was Event-Driven Ansible (EDA) first introduced?]]
* [[When did Red Hat acquire Ansible?]]
Q: When was Ansible Lightspeed generally available?
A: November 2023.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When did Red Hat acquire Ansible?]]
* [[What year was Ansible first released?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
Q: How many modules were in the monolithic Ansible 2.9 repository before the split?
A: Over 3,400 modules lived in the single ansible/ansible repository before the collections migration.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[How many collections are typically included in the Ansible community package?]]
* [[When did Ansible collections replace the monolithic package?]]
Q: How many collections are typically included in the Ansible community package?
A: The Ansible community package (e.g., Ansible 9.x, 10.x) bundles approximately 85-100+ collections alongside ansible-core.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How many modules were in the monolithic Ansible 2.9 repository before the split?]]
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[Listing and inspecting Ansible modules with ansible-doc]]
Q: What is ansible.cfg?
A: The central configuration file that controls how Ansible behaves -- connection settings, defaults, module paths, plugin paths, etc.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_connection` and where can it be set?]]
* [[What is `ansible-config dump`?]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
Q: What is <html><code>host_key_checking</code></html>?
A: Controls whether Ansible verifies SSH host keys. Disabling it (<html><code>host_key_checking = False</code></html>) can speed up initial connections but reduces security.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[SSH host key verification modes differ in security properties]]
* [[What does `ansible_check_mode` contain?]]
* [[What is the `ask_pass` setting?]]
Q: What is fact caching?
A: Storing gathered facts between playbook runs to avoid re-gathering. Backends include jsonfile, redis, and memcached. Configured in ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Ansible Facts and the gather_facts task]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[If you create a custom fact in the same play, how do you access it?]]
Q: What is <html><code>fact_caching</code></html>, and what backends does it support?
A: Fact caching stores gathered facts between playbook runs so they don't need to be re-gathered. Supported backends include: jsonfile, redis, memcached, mongodb, yaml, and others via plugins.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Fact caching avoids expensive repeated gathering]]
* [[Fact Caching Returns Stale System Information]]
* [[Fact caching avoids multi-minute delays on large fleets]]
Q: What is the <html><code>ask_pass</code></html> setting?
A: Controls whether Ansible prompts for an SSH password by default. Default is <html><code>no</code></html> (assumes SSH keys).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is `host_key_checking`?]]
* [[What is the default connection plugin in Ansible?]]
* [[What is the `become_method` setting and what values does it support?]]
Q: What is the security concern with <html><code>./ansible.cfg</code></html> in the current directory?
A: If Ansible is run in a world-writable directory, a malicious user could place an <html><code>ansible.cfg</code></html> that modifies behavior (e.g., pointing to a rogue callback plugin). Ansible warns or ignores current-directory config files in world-writable directories.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is ansible.cfg?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
* [[If both ANSIBLE_CONFIG and a local ansible.cfg exist in the current directory, which wins?]]
Q: Why does Ansible refuse to load an ansible.cfg from a world-writable current directory?
A: This is a security measure introduced in Ansible 2.7. If the current directory is world-writable (e.g., /tmp), Ansible ignores the ansible.cfg found there to prevent privilege escalation attacks where a malicious user plants a crafted config file.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is ansible.cfg?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
* [[If both ANSIBLE_CONFIG and a local ansible.cfg exist in the current directory, which wins?]]
Q: What language is Ansible written in? What about Puppet, Chef, and SaltStack?
A: Ansible: Python. Puppet: Ruby (with its own Puppet DSL). Chef: Ruby (with Ruby DSL for recipes). SaltStack: Python.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What language is Ansible written in?]]
* [[Which tool came first chronologically: Puppet, Chef, Ansible, or Salt?]]
* [[How does Ansible differ from SaltStack?]]
Q: Which of the "big four" (Ansible, Puppet, Chef, Salt) are agentless?
A: Ansible is fully agentless (SSH/WinRM). Salt can run agentless via salt-ssh but normally uses agents (minions). Puppet and Chef both typically require agents, though Puppet can run agentless via bolt.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does "agentless" mean in the context of Ansible?]]
* [[How does Ansible differ from SaltStack?]]
* [[Ansible's agentless design: SSH over a custom control protocol]]
Q: Which tools are push-based vs. pull-based by default?
A: Ansible: push-based (pull available via ansible-pull). Salt: push-based (pull available). Puppet: pull-based (push via bolt). Chef: pull-based (push via knife/chef-push-jobs).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When would you use ansible-pull instead of the default push model?]]
* [[When is ansible-pull preferred over the normal push model?]]
* [[What is the push-based model in Ansible?]]
Q: What configuration language does each tool use?
A: Ansible: YAML (playbooks) + Jinja2 (templates). Puppet: Puppet DSL (declarative). Chef: Ruby DSL (imperative "recipes"). Salt: YAML (state files) + Jinja2 (templates).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible differ from other configuration management tools?]]
* [[Ansible Modules]]
* [[Which tool came first chronologically: Puppet, Chef, Ansible, or Salt?]]
Q: Which tool came first chronologically: Puppet, Chef, Ansible, or Salt?
A: Puppet (2005), Chef (2009), Salt (2011), Ansible (2012).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What language is Ansible written in? What about Puppet, Chef, and SaltStack?]]
* [[What configuration language does each tool use?]]
* [[Who created Ansible and when?]]
Q: Which config management tool uses a "master-minion" architecture with a ZeroMQ message bus?
A: SaltStack (Salt). The master communicates with minions over a ZeroMQ or TCP transport bus, which gives it very fast command execution across large fleets.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What makes SaltStack's execution speed notably faster than Ansible for large fleets?]]
* [[How does Ansible differ from SaltStack?]]
Q: What is Puppet Bolt, and how is it similar to Ansible?
A: Puppet Bolt is an agentless task-running tool from Puppet that connects via SSH/WinRM to execute tasks without requiring the Puppet agent. It is conceptually similar to Ansible ad-hoc commands and playbooks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible differ from Puppet?]]
* [[Ansible: agentless IT automation tool]]
* [[Ansible vs. Chef/Puppet: key architectural differences]]
Q: Ansible is sometimes described as "procedural" while Puppet is "declarative." What does this mean in practice?
A: Ansible playbooks execute tasks in the order written (procedural) -- the order matters. Puppet manifests describe the desired end state (declarative) -- Puppet's engine determines the order of operations to converge to that state.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible differ from Puppet?]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
* [[Explain the key components of Ansible.]]
Q: What open-source tool can dramatically speed up Ansible by replacing SSH with a custom Python-based protocol?
A: Mitogen for Ansible. It replaces SSH with a bootstrapped Python interpreter tunnel, reducing the per-task overhead from multiple SSH round-trips to a single connection with multiplexed execution.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible performance optimization for large inventories]]
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
* [[Ansible SSH pipelining reduces connection round-trips]]
Q: What is an Ansible inventory?
A: A file or script that defines the list of managed hosts (machines) that Ansible targets. It organizes systems into groups for task targeting.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible inventory file: definition and configuration]]
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
* [[What is `ansible_host` in inventory?]]
Q: What are the two types of inventory?
A: Static inventory (manually defined in INI or YAML files) and dynamic inventory (generated at runtime using scripts or plugins from external sources like cloud providers).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the two built-in inventory file formats?]]
* [[What are inventory plugins?]]
* [[What is the difference between an inventory script and an inventory plugin?]]
Q: Where is the default inventory file located?
A: <html><code>/etc/ansible/hosts</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you specify a custom inventory file?]]
* [[What is `inventory_hostname`?]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
Q: How do you specify a custom inventory file?
A: Use the <html><code>-i</code></html> flag: <html><code>ansible-playbook -i /path/to/inventory playbook.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Where is the default inventory file located?]]
* [[Ansible inventory file: definition and configuration]]
* [[Ansible Dynamic Inventory]]
Q: What command lists all hosts in an inventory?
A: <html><code>ansible-inventory --list</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible inventory file: definition and configuration]]
* [[What special group exists in every Ansible inventory?]]
* [[What is `ansible_play_hosts`?]]
Q: What does <html><code>ansible-inventory --list</code></html> do?
A: Outputs the complete inventory as JSON, including all groups, hosts, and variables.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is a group in an Ansible inventory?]]
* [[Ansible inventory file: definition and configuration]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
Q: What is a group in an Ansible inventory?
A: A named collection of hosts that allows you to target multiple servers with a single reference. Example: <html><code>[webservers]</code></html> containing multiple web server hostnames.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `ansible-inventory --list` do?]]
* [[Inventory structure: hosts, groups, variables, and sources]]
* [[Ansible inventory file: definition and configuration]]
Q: What special group exists in every Ansible inventory?
A: The <html><code>all</code></html> group, which contains every host. Also, <html><code>ungrouped</code></html> contains hosts not assigned to any other group.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command lists all hosts in an inventory?]]
* [[What is the `ungrouped` group?]]
* [[What does `group_names` contain?]]
Q: What is <html><code>groups</code></html> in Ansible?
A: A dictionary/map of all groups in the inventory, where each group key maps to a list of hosts belonging to that group.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `group_names` contain?]]
* [[What does `ansible-inventory --list` do?]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
Q: What is the <html><code>all</code></html> group?
A: A special built-in group that contains every host in the inventory.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a group in an Ansible inventory?]]
* [[What is `groups` in Ansible?]]
* [[What does the `groups` magic variable contain?]]
Q: What is the <html><code>ungrouped</code></html> group?
A: A special built-in group containing hosts that are not members of any other group.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What special group exists in every Ansible inventory?]]
* [[What is the `all` group?]]
* [[What is `groups` in Ansible?]]
Q: What are <html><code>group_vars</code></html> and <html><code>host_vars</code></html>?
A: Directories for storing variables that apply to groups or individual hosts respectively. <html><code>group_vars/webservers.yml</code></html> applies to all hosts in the webservers group; <html><code>host_vars/server1.yml</code></html> applies only to server1.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `groups` magic variable contain?]]
* [[Directory-based variable organization separates variables from inventory]]
* [[Inventory structure: hosts, groups, variables, and sources]]
Q: How do you configure a dynamic inventory for AWS EC2?
A: Install boto/boto3, configure AWS credentials, create an <html><code>aws_ec2.yml</code></html> inventory plugin configuration file, and reference it with the <html><code>-i</code></html> flag.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Dynamic Inventory]]
* [[Dynamic inventory in Ansible]]
* [[What are inventory plugins?]]
Q: What are Ansible plugins?
A: Extensions that add functionality to Ansible core. They run on the control node (unlike modules which run on managed nodes).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the relationship between ansible-core and the ansible package?]]
* [[What are the two categories of Ansible modules?]]
* [[Ansible Modules]]
Q: What are connection plugins?
A: Control how Ansible connects to managed nodes. Examples: <html><code>ssh</code></html>, <html><code>winrm</code></html>, <html><code>local</code></html>, <html><code>docker</code></html>, <html><code>network_cli</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `network_cli` connection plugin used for?]]
* [[What are Ansible plugins?]]
* [[What is the default connection plugin in Ansible?]]
Q: Name all the major connection plugin types in Ansible.
A: ssh, paramiko_ssh, local, docker, kubectl, podman, network_cli, httpapi, netconf, winrm, psrp (PowerShell Remoting Protocol), lxd, jail (FreeBSD), zone (Solaris), chroot, funcd, and community-contributed options.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Connection plugins determine how Ansible communicates with targets]]
* [[What connection type does ansible-pull use?]]
* [[What port does Ansible use by default for SSH connections?]]
Q: What are lookup plugins?
A: Retrieve data from external sources. Examples: <html><code>file</code></html>, <html><code>env</code></html>, <html><code>password</code></html>, <html><code>aws_ssm</code></html>, <html><code>pipe</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a lookup plugin in Ansible?]]
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[What method must a lookup plugin implement?]]
Q: Name ten commonly used lookup plugins.
A: (1) file -- read file contents; (2) template -- render a Jinja2 template; (3) env -- read environment variables; (4) password -- generate or retrieve passwords; (5) pipe -- run a command and capture output; (6) csvfile -- read from CSV files; (7) ini -- read from INI files; (8) url -- fetch content from a URL; (9) hashi_vault -- read from HashiCorp Vault; (10) aws_ssm -- read from AWS Systems Manager Parameter Store.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `lookup` plugin?]]
* [[How do you handle external secret lookups?]]
* [[Lookups read external data into variables during playbook execution]]
Q: What are inventory plugins?
A: Generate dynamic inventory from external sources. Examples: <html><code>aws_ec2</code></html>, <html><code>azure_rm</code></html>, <html><code>gcp_compute</code></html>, <html><code>vmware_vm_inventory</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the two types of inventory?]]
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
* [[What is the difference between an inventory script and an inventory plugin?]]
Q: Name five dynamic inventory plugins included in popular collections.
A: (1) amazon.aws.aws_ec2; (2) google.cloud.gcp_compute; (3) azure.azcollection.azure_rm; (4) community.vmware.vmware_vm_inventory; (5) kubernetes.core.k8s.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
* [[Dynamic inventory in Ansible]]
* [[What is the `auto` inventory plugin?]]
Q: What are strategy plugins?
A: Control the order of task execution across hosts. Examples: <html><code>linear</code></html> (default -- tasks in order), <html><code>free</code></html> (each host runs independently), <html><code>debug</code></html> (interactive stepping).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible strategy plugins: built-in options and defaults]]
* [[What is the default strategy, and what is its key characteristic?]]
* [[What is the `debug` strategy?]]
Q: How do you enable a callback plugin?
A: Configure in <html><code>ansible.cfg</code></html> under <html><code>[defaults]</code></html>: <html><code>callbacks_enabled = profile_tasks, timer</code></html> (note: the old name <html><code>callback_whitelist</code></html> was renamed to <html><code>callbacks_enabled</code></html> in Ansible 2.15)
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a callback plugin?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[How many stdout-type callback plugins can be active at once?]]
Q: How do you enable a notification callback plugin?
A: Add it to the <html><code>callback_whitelist</code></html> (or <html><code>callbacks_enabled</code></html> in newer versions) setting in <html><code>ansible.cfg</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is an Ansible callback whitelist?]]
* [[What is a callback plugin?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
Q: What is the difference between an inventory script and an inventory plugin?
A: Inventory scripts are standalone executables that output JSON. Inventory plugins are Python classes integrated with Ansible's plugin system, supporting caching, configuration via <html><code>ansible.cfg</code></html>, and the <html><code>constructed</code></html> features. Plugins are recommended over scripts.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
* [[What are inventory plugins?]]
* [[What are the two types of inventory?]]
Q: What two methods must a custom inventory plugin implement?
A: <html><code>verify_file(self, path)</code></html> (validates the inventory source) and <html><code>parse(self, inventory, loader, path, cache=True)</code></html> (populates the inventory).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What key inventory object methods are used in plugin development?]]
* [[What is the difference between an inventory script and an inventory plugin?]]
* [[What are inventory plugins?]]
Q: What key inventory object methods are used in plugin development?
A: <html><code>self.inventory.add_group()</code></html>, <html><code>self.inventory.add_host()</code></html>, <html><code>self.inventory.add_child()</code></html>, <html><code>self.inventory.set_variable()</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
* [[Inventory structure: hosts, groups, variables, and sources]]
* [[What is the `constructed` inventory plugin?]]
Q: What does the <html><code>Constructable</code></html> base class provide to inventory plugins?
A: The ability to create host variables and groups from Jinja2 expressions using <html><code>compose</code></html>, <html><code>keyed_groups</code></html>, and <html><code>groups</code></html> options -- without writing custom code.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Inventory structure: hosts, groups, variables, and sources]]
* [[What are inventory plugins?]]
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
Q: What is the <html><code>constructed</code></html> inventory plugin?
A: An inventory plugin that creates groups and variables dynamically based on Jinja2 expressions evaluated against existing inventory data. It lets you create groups based on facts or other variables without modifying the source inventory.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What are inventory plugins?]]
* [[What key inventory object methods are used in plugin development?]]
* [[What is the `auto` inventory plugin?]]
Q: How does inventory caching work?
A: Inventory plugins can use configured cache plugins (jsonfile, Redis, memcached, etc.) to store and retrieve data, avoiding repeated costly external API calls. Controlled by <html><code>cache</code></html>, <html><code>cache_plugin</code></html>, <html><code>cache_timeout</code></html>, and <html><code>cache_connection</code></html> settings.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are inventory plugins?]]
* [[What is the difference between an inventory script and an inventory plugin?]]
* [[What is `fact_caching`, and what backends does it support?]]
Q: What file extension does the AWS EC2 inventory plugin expect?
A: Files ending in <html><code>aws_ec2.yml</code></html> or <html><code>aws_ec2.yaml</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `auto` inventory plugin?]]
* [[What are the two built-in inventory file formats?]]
* [[What is the galaxy.yml file in a collection?]]
Q: What are the two built-in inventory file formats?
A: INI format and YAML format.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the two types of inventory?]]
* [[What file extension does the AWS EC2 inventory plugin expect?]]
* [[Inventory is one layer in a larger variable precedence system]]
Q: What is the <html><code>auto</code></html> inventory plugin?
A: A meta-plugin that automatically detects and delegates to the correct inventory plugin based on the inventory source file name or content. For example, a file ending in <html><code>aws_ec2.yml</code></html> triggers the aws_ec2 plugin.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are inventory plugins?]]
* [[What file extension does the AWS EC2 inventory plugin expect?]]
* [[What is the `constructed` inventory plugin?]]
Q: What was the old-style dynamic inventory approach before inventory plugins?
A: Executable inventory scripts (e.g., ec2.py). These scripts output JSON to stdout when called with <html><code>--list</code></html> or <html><code>--host <hostname></code></html>. This approach is now deprecated in favor of inventory plugins.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between an inventory script and an inventory plugin?]]
* [[What are inventory plugins?]]
* [[Dynamic inventory in Ansible]]
Q: What is <html><code>ansible_host</code></html> in inventory?
A: A variable that overrides the hostname or IP used to connect to a host. The inventory name stays the same for variable lookups, but <html><code>ansible_host</code></html> tells Ansible the actual connection address.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[What is `ansible_play_batch`?]]
* [[What is an Ansible inventory?]]
* [[What does the `hostvars` magic variable contain?]]
Q: What is the difference between <html><code>inventory_hostname</code></html> and <html><code>ansible_hostname</code></html>?
A: <html><code>inventory_hostname</code></html> is the name of the host as defined in the inventory file (set before any connection to the host). <html><code>ansible_hostname</code></html> is the actual hostname discovered from the remote machine via fact gathering (it comes from the OS).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Ansible inventory file: definition and configuration]]
* [[What is an Ansible inventory?]]
* [[What does `ansible-inventory --list` do?]]
Q: What is the difference between a playbook and a play?
A: A playbook is a YAML file containing one or more plays. A play is a set of tasks and roles that run on one or more managed hosts within that playbook.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Playbook files contain nested structures that are not visually distinct]]
* [[What is the purpose of an Ansible Playbook?]]
* [[What is the difference between an Ansible playbook and a role?]]
Q: What is the difference between a playbook and an ad-hoc command?
A: Playbooks are YAML files with multiple organized tasks for complex, repeatable automation. Ad-hoc commands are one-off CLI commands for quick, simple tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[What is the difference between a playbook and a play?]]
* [[What are Ansible "playbooks"?]]
Q: When should you use ad-hoc commands vs playbooks?
A: Ad-hoc for quick checks, testing connectivity, gathering info, or one-time fixes. Playbooks for repeatable, complex, multi-step automation.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[Structured Playbooks Provide Auditability and Idempotency]]
* [[How do you test playbooks?]]
Q: What command runs an Ansible playbook?
A: <html><code>ansible-playbook playbook.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What playbook filename does ansible-pull look for by default?]]
* [[What is `playbook_dir`?]]
* [[How does ansible-pull know which playbook to run?]]
Q: What command runs a rulebook?
A: <html><code>ansible-rulebook --inventory inventory.yml --rulebook rulebook.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the three main components of an Ansible rulebook?]]
* [[What are Ansible "playbooks"?]]
* [[How do you specify a custom inventory file?]]
Q: What is diff mode?
A: <html><code>--diff</code></html> flag displays the difference between the current state and the proposed changes, useful for validating before applying.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `diff: true` at the task level?]]
Q: How do you run a playbook in verbose mode?
A: Add <html><code>-v</code></html> (basic), <html><code>-vv</code></html> (more detail), <html><code>-vvv</code></html> (connection debugging), or <html><code>-vvvv</code></html> (maximum verbosity).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the four verbosity levels in Ansible?]]
* [[How do you check a playbook's syntax without running it?]]
* [[What is the `debug` module's `verbosity` parameter?]]
Q: What does the <html><code>hosts</code></html> keyword define in a play?
A: The target hosts or groups that the play will execute against.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `ansible_play_hosts` and `ansible_play_hosts_all`?]]
* [[Explain the use of the "hosts" directive in a playbook.]]
* [[What is a play in Ansible?]]
Q: What is <html><code>play_hosts</code></html>?
A: A list of all hosts in the current play that are still active (not failed or unreachable).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_play_batch`?]]
* [[What is `ansible.builtin.add_host`?]]
* [[What is a play in Ansible?]]
Q: What is <html><code>ansible_play_hosts</code></html>?
A: A magic variable containing the list of active hosts in the current play (excludes failed hosts).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_play_name`?]]
* [[What is a play in Ansible?]]
* [[What does the `hostvars` magic variable contain?]]
Q: What keyword defines tasks in a playbook?
A: <html><code>tasks:</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a task in Ansible?]]
* [[Playbook files contain nested structures that are not visually distinct]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
Q: What is the <html><code>serial</code></html> keyword?
A: Controls how many hosts are updated at a time during a playbook run. <html><code>serial: 2</code></html> updates two hosts at a time, enabling rolling updates.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_play_batch`?]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[Can `serial` accept a list? What does that do?]]
Q: How does <html><code>serial</code></html> support rolling updates?
A: It limits how many hosts are updated at a time: <html><code>serial: 2</code></html> updates two hosts at a time. It can also be a list: <html><code>serial: [1, 5, 10]</code></html> for gradual rollout.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a rolling update strategy?]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[Can `serial` accept a list? What does that do?]]
Q: What is <html><code>max_fail_percentage</code></html>?
A: A play-level setting that stops a rolling update if the failure rate exceeds the specified percentage.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `fail` module?]]
* [[What is `any_errors_fatal` and when would you use it?]]
* [[Serial Batching and Max-Failure Limit Contain Rollout Risk]]
Q: What is <html><code>max_fail_percentage</code></html> used for?
A: Stops a rolling update if more than the specified percentage of hosts fail, preventing cascading failures.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Serial Batching and Max-Failure Limit Contain Rollout Risk]]
* [[What is the `fail` module?]]
* [[Ansible `serial` keyword for batched rolling updates]]
Q: What is the syntax of an ad-hoc command?
A: <html><code>ansible [host-pattern] -m [module] -a "[module arguments]"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you execute a single ad-hoc Ansible command?]]
* [[Give an example of an ad-hoc ping command.]]
* [[How do you install a package using an ad-hoc command?]]
Q: Give an example of an ad-hoc ping command.
A: <html><code>ansible all -m ping</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you execute a single ad-hoc Ansible command?]]
* [[What is the syntax of an ad-hoc command?]]
* [[What does the `ping` module do?]]
Q: How do you check disk space on all hosts ad-hoc?
A: <html><code>ansible all -m shell -a "df -h"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you view all facts for a host?]]
* [[What command lists all hosts in an inventory?]]
Q: How do you install a package using an ad-hoc command?
A: <html><code>ansible webservers -m apt -a "name=nginx state=present" --become</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you execute a single ad-hoc Ansible command?]]
* [[What is the syntax of an ad-hoc command?]]
* [[What is the `ansible.builtin.package` module?]]
Q: What are the two categories of [[Ansible modules|Ansible Modules]]?
A: Core modules (maintained by the Ansible team) and community/extras modules (maintained by the community). Both are fully usable.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are Ansible plugins?]]
* [[What are the main components of Ansible's architecture?]]
* [[Ansible Modules]]
Q: What does the <html><code>ping</code></html> module do?
A: Tests connectivity between the control node and managed nodes. It verifies SSH connection, authentication, and Python availability. Returns "pong" on success.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Give an example of an ad-hoc ping command.]]
Q: What does the <html><code>setup</code></html> module do?
A: Gathers facts (system information) from managed nodes -- OS details, IP addresses, memory, disk, CPU, etc.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `gathered` state in network resource modules?]]
* [[What does the `package` module do?]]
* [[What does the `apt` module do?]]
Q: What does the <html><code>copy</code></html> module do?
A: Copies files from the control node to managed nodes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the purpose of the "copy" module in Ansible.]]
* [[What does the `fetch` module do?]]
Q: What does the <html><code>fetch</code></html> module do?
A: Fetches (downloads) files from managed nodes to the control node. The inverse of <html><code>copy</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What module copies files from remote to local?]]
* [[What does the `copy` module do?]]
* [[What does the `synchronize` module do?]]
Q: What does the <html><code>file</code></html> module do?
A: Manages files and directories -- create, delete, set permissions, ownership, and symlinks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What module creates directories?]]
Q: What does the <html><code>apt</code></html> module do?
A: Manages packages on Debian/Ubuntu systems (install, remove, update).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `yum` module do?]]
* [[What is the `ansible.builtin.package` module?]]
Q: What does the <html><code>package</code></html> module do?
A: A generic OS-independent package manager module that auto-detects the appropriate package manager.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible.builtin.package` module?]]
* [[What does the `yum` module do?]]
Q: What does the <html><code>yum</code></html> module do?
A: Manages packages on RHEL/CentOS systems (install, remove, update).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `package` module do?]]
* [[What does the `apt` module do?]]
Q: What does the <html><code>service</code></html> module do?
A: Manages system services -- start, stop, restart, enable, disable.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What module manages systemd services?]]
Q: What does the <html><code>user</code></html> module do?
A: Manages user accounts -- create, remove, modify users, set passwords, manage groups.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What module manages users?
A: <html><code>user</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `become_user`?]]
Q: What does the <html><code>cron</code></html> module do?
A: Manages cron jobs on managed nodes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What module manages cron jobs?
A: <html><code>cron</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What does the <html><code>shell</code></html> module do?
A: Executes commands through the shell (<html><code>/bin/sh</code></html>), supporting pipes, redirects, and environment variable expansion.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `command` and `shell` modules?]]
* [[How do you use the "shell" module in Ansible?]]
Q: What does the <html><code>command</code></html> module do?
A: Executes commands directly without shell processing. Safer than shell but doesn't support pipes or redirects.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `removes` parameter in command/shell modules?]]
Q: What is the difference between <html><code>command</code></html> and <html><code>shell</code></html> modules?
A: <html><code>command</code></html> runs commands directly without shell processing (no pipes, redirects, or variable expansion). <html><code>shell</code></html> executes through a shell, allowing all shell features. <html><code>command</code></html> is more secure; <html><code>shell</code></html> is more flexible.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `shell` module do?]]
* [[How do you use the "shell" module in Ansible?]]
* [[What is the security risk of using `shell` or `command` modules with user-supplied vari…]]
Q: What does the <html><code>lineinfile</code></html> module do?
A: Ensures a particular line is present (or absent) in a file. Useful for managing configuration files.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible.builtin.lineinfile` vs `ansible.builtin.blockinfile`?]]
* [[lineinfile is for single lines, not file management]]
* [[What does the `file` module do?]]
Q: What module adds or modifies lines in files?
A: <html><code>lineinfile</code></html> (for single lines) or <html><code>blockinfile</code></html> (for blocks of text).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible.builtin.lineinfile` vs `ansible.builtin.blockinfile`?]]
* [[lineinfile is unsuited for multi-line or overlapping content]]
* [[lineinfile is for single lines, not file management]]
Q: What does the <html><code>debug</code></html> module do?
A: Prints variable values or custom messages during playbook execution. Useful for troubleshooting.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `debug` strategy allow?]]
* [[Ansible debug module: printing messages during playbook execution]]
* [[What is the `ansible.builtin.debug` module's `var` vs `msg` parameter?]]
Q: What does the <html><code>wait_for</code></html> module do?
A: Waits for a specific condition (port open, file exists, string in file) before continuing. Supports customizable timeouts.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `wait_for_connection` used for?]]
Q: What does the <html><code>synchronize</code></html> module do?
A: A wrapper around rsync for efficient file transfer between control node and managed nodes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `copy` module do?]]
Q: What is the <html><code>synchronize</code></html> module?
A: An Ansible wrapper around rsync. Requires rsync on both source and destination. Key gotchas: must use <html><code>delegate_to</code></html> to change source, and full paths are needed when using sudo.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the purpose of the "copy" module in Ansible.]]
* [[What does the `async` keyword do?]]
Q: What does the <html><code>docker_container</code></html> module do?
A: Manages Docker containers -- create, start, stop, remove containers.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What is the <html><code>service_facts</code></html> module?
A: Gathers data about all services on a managed node, returning their states.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are custom facts (local facts) and where do they live?]]
* [[What does the `service` module do?]]
* [[What is `ansible_facts` vs top-level fact variables?]]
Q: What does <html><code>state: present</code></html> mean in a module?
A: Ensures the resource exists (e.g., a package is installed, a user exists).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `state: latest` mean in package modules?]]
* [[What is the `gathered` state in network resource modules?]]
* [[What does the `package` module do?]]
Q: What does <html><code>state: absent</code></html> mean in a module?
A: Ensures the resource does NOT exist (e.g., a package is removed, a user is deleted).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `state: latest` mean in package modules?]]
* [[What is `removes` parameter in command/shell modules?]]
Q: What does <html><code>state: latest</code></html> mean in package modules?
A: Ensures the package is installed AND updated to the latest available version.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `state: present` mean in a module?]]
* [[What does the `package` module do?]]
* [[What does `state: absent` mean in a module?]]
Q: What is the <html><code>raw</code></html> module, and when is it needed?
A: <html><code>raw</code></html> executes a raw SSH command without the Ansible module subsystem. It's needed when the target has no Python installed (bootstrapping Python on a new host) or for network devices that don't support the Ansible module system.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Bootstrap Python on fresh OS installs with raw module]]
* [[Ansible Modules]]
* [[What is the `ansible.builtin.script` module?]]
Q: What is the <html><code>raw</code></html> module?
A: Executes a low-level command via SSH without requiring Python on the remote host. Useful for bootstrapping Python.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the `_raw_params` in free-form modules?]]
* [[What is the `script` module?]]
* [[What does the `command` module do?]]
Q: What module would you use to wait for a port to become available?
A: <html><code>wait_for</code></html> -- can wait for a port, file, or regex match in a file. Common use: <html><code>wait_for: port=8080 delay=5 timeout=300</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `wait_for_connection` used for?]]
Q: What is <html><code>include_role</code></html> vs <html><code>import_role</code></html>?
A: Same distinction: <html><code>import_role</code></html> is static (parsed at load time), <html><code>include_role</code></html> is dynamic (loaded at runtime). <html><code>import_role</code></html> tasks show up in --list-tasks; <html><code>include_role</code></html> tasks do not until runtime.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the difference between `include_tasks` and `import_tasks`?]]
* [[How do you include roles in a playbook?]]
* [[What is the fundamental difference between `import_*` and `include_*`?]]
Q: What are variables in Ansible?
A: Named values that store data for use in playbooks, templates, and tasks. They make automation flexible and dynamic.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where can variables be defined?]]
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
* [[Can you set variables with magic variable names?]]
Q: What are "magic variables" in Ansible?
A: Variables automatically set by Ansible that provide information about the current play, host, and inventory. They cannot be set by the user directly and are always available during execution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[How do you define variables in Ansible Playbooks?]]
* [[What does the `hostvars` magic variable contain?]]
* [[What is `ansible_play_batch`?]]
Q: Where can variables be defined?
A: In playbook <html><code>vars</code></html> sections, <html><code>vars_files</code></html>, <html><code>group_vars/</code></html>, <html><code>host_vars/</code></html>, role defaults, role vars, inventory files, command line (<html><code>-e</code></html>/<html><code>--extra-vars</code></html>), registered variables, and set_fact.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are variables in Ansible?]]
* [[How do you pass variables to Ansible at runtime?]]
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
Q: What is the difference between <html><code>vars</code></html>, <html><code>vars_files</code></html>, and <html><code>vars_prompt</code></html>?
A: <html><code>vars</code></html> declares variables inline in a play. <html><code>vars_files</code></html> references separate YAML files containing variables. <html><code>vars_prompt</code></html> prompts the user for input during execution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `vars_prompt`?]]
* [[Where can variables be defined?]]
* [[What is the difference between `defaults/main.yml` and `vars/main.yml`?]]
Q: How do you reference a variable in a playbook?
A: Using Jinja2 double-curly-brace syntax: <html><code>{{ variable_name }}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you pass variables to Ansible at runtime?]]
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
Q: What is <html><code>set_fact</code></html>?
A: A module that sets host-level variables dynamically during playbook execution. Values persist for the rest of the play.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Variables set in one play don't automatically carry to the next play]]
* [[What is the `set_fact` module's `cacheable` option?]]
* [[What module gathers facts by default at the start of each play?]]
Q: How is <html><code>set_fact</code></html> different from <html><code>vars</code></html>?
A: <html><code>set_fact</code></html> creates variables dynamically at runtime after on-the-fly processing/filtering. <html><code>vars</code></html> defines variables with predetermined values before execution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[What is `set_fact`?]]
* [[What is `ansible_facts` vs top-level fact variables?]]
Q: How are facts gathered?
A: By the <html><code>setup</code></html> module, which runs automatically at the start of each play (unless <html><code>gather_facts: no</code></html> is set).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you disable fact gathering?]]
* [[How do you disable automatic fact gathering?]]
* [[Ansible Facts and the gather_facts task]]
Q: What module gathers facts by default at the start of each play?
A: <html><code>ansible.builtin.setup</code></html> (called automatically by <html><code>gather_facts: true</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_local`?]]
* [[What is `ansible_facts` vs top-level fact variables?]]
* [[What would be the result of the following play?]]
Q: How do you disable fact gathering?
A: Set <html><code>gather_facts: no</code></html> in the play definition. This speeds up playbook execution when facts are not needed.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Facts and the gather_facts task]]
* [[How are facts gathered?]]
* [[What does the `gather_facts: false` optimization do?]]
Q: How do you disable automatic fact gathering?
A: Set <html><code>gather_facts: false</code></html> at the play level.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How are facts gathered?]]
* [[What does the `gather_facts: false` optimization do?]]
* [[What module gathers facts by default at the start of each play?]]
Q: How do you view all facts for a host?
A: <html><code>ansible hostname -m setup</code></html> or filter with <html><code>ansible hostname -m setup -a "filter=ansible_os_family"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible facts: auto-discovered host variables]]
* [[What command lists all hosts in an inventory?]]
* [[Under what namespace are custom local facts accessible?]]
Q: What is <html><code>inventory_hostname</code></html>?
A: The name of the current host as defined in the inventory file.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where is the default inventory file located?]]
* [[What is `inventory_dir`?]]
* [[What does the `hostvars` magic variable contain?]]
Q: What is <html><code>inventory_hostname_short</code></html>?
A: The first part of <html><code>inventory_hostname</code></html> before the first dot. For example, if <html><code>inventory_hostname</code></html> is "web01.example.com", then <html><code>inventory_hostname_short</code></html> is "web01".
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `inventory_hostname` and `ansible_hostname`?]]
* [[What is `ansible_host` in inventory?]]
* [[What is `inventory_dir`?]]
Q: How do you access a variable of the first host in a group?
A: <html><code>{{ hostvars[groups['webservers'][0]]['ansible_eth0']['ipv4']['address'] }}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a group in an Ansible inventory?]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[What does the `hostvars` magic variable contain?]]
Q: What is the difference between variable names and environment variables?
A: Variable names are Ansible-internal. Environment variables reference system environment values using <html><code>{{ ansible_env.SOME_VARIABLE }}</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the naming convention for Ansible environment variable overrides?]]
* [[How do you define variables in Ansible Playbooks?]]
* [[Can you set variables with magic variable names?]]
Q: What is the difference between dot notation and array notation for variables?
A: Dot notation (<html><code>{{ user.name }}</code></html>) is for simple, readable access. Array notation (<html><code>{{ user['first name'] }}</code></html>) is required for keys with special characters, spaces, or dynamic variable names.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you access nested variables?]]
Q: How many levels of variable precedence does Ansible have?
A: 22 levels, from lowest (command line values like <html><code>-u user</code></html>) to highest (<html><code>--extra-vars</code></html>/<html><code>-e</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible variable precedence: bookends and gradient]]
* [[Variable precedence: learn role defaults and extra vars, not all 22 levels]]
* [[The variable 'whoami' defined in the following places:]]
Q: What has the highest variable precedence?
A: Extra vars (<html><code>--extra-vars</code></html> or <html><code>-e</code></html>), at level 22.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the single most important thing to remember about extra vars (-e)?]]
* [[What has the lowest variable precedence?]]
* [[How does `include_vars` compare to `vars_files` in precedence?]]
Q: What has the lowest variable precedence?
A: Command line values (e.g., <html><code>-u my_user</code></html>), followed by role defaults (<html><code>roles/x/defaults/main.yml</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between role defaults and role vars in terms of precedence?]]
* [[How many levels of variable precedence does Ansible have?]]
* [[What is the difference between `defaults/main.yml` and `vars/main.yml`?]]
Q: Where do <html><code>set_fact</code></html> and registered vars fall in precedence?
A: Level 19 -- above include_vars, task vars, block vars, role vars, play vars_files, play vars_prompt, play vars, and all inventory variables. Below role parameters, include parameters, and extra-vars.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Can you override an extra var with set_fact?]]
* [[How is `set_fact` different from `vars`?]]
* [[Eight Ansible variable precedence levels you need]]
Q: How does <html><code>include_vars</code></html> compare to <html><code>vars_files</code></html> in precedence?
A: <html><code>include_vars</code></html> (level 18) has higher precedence than <html><code>vars_files</code></html> (level 14).
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[What has the highest variable precedence?]]
* [[What is the difference between `defaults/main.yml` and `vars/main.yml`?]]
Q: What is <html><code>inventory_dir</code></html>?
A: The directory path of the inventory source (the folder containing the inventory file).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `inventory_hostname`?]]
* [[Where is the default inventory file located?]]
* [[What is `inventory_hostname_short`?]]
Q: Can you set variables with magic variable names?
A: No. Magic variable names are reserved and setting them will be overridden by Ansible's internal values.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are variables in Ansible?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
Q: If you create a custom fact in the same play, how do you access it?
A: You must explicitly re-run the <html><code>setup</code></html> module to refresh facts: <html><code>ansible.builtin.setup: filter=ansible_local</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Facts and the gather_facts task]]
* [[What is `ansible_local`?]]
* [[What are custom facts (local facts) and where do they live?]]
Q: What is the exact search order for ansible.cfg files (highest to lowest priority)?
A: (1) ANSIBLE_CONFIG environment variable (pointing to a specific file); (2) ansible.cfg in the current working directory; (3) ~/.ansible.cfg in the user's home directory; (4) /etc/ansible/ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[If both ANSIBLE_CONFIG and a local ansible.cfg exist in the current directory, which wins?]]
* [[What is ansible.cfg?]]
* [[How many levels of variable precedence does Ansible have?]]
Q: If both ANSIBLE_CONFIG and a local ansible.cfg exist in the current directory, which wins?
A: ANSIBLE_CONFIG always wins -- it has the highest precedence.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the exact search order for ansible.cfg files (highest to lowest priority)?]]
* [[What is ansible.cfg?]]
* [[What is the security concern with `./ansible.cfg` in the current directory?]]
Q: Can individual ansible.cfg settings be overridden by environment variables?
A: Yes. Every ansible.cfg setting can be overridden by a corresponding environment variable, typically named ANSIBLE_ followed by the uppercase setting name. Environment variables have higher precedence than ansible.cfg file entries.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Can you set variables with magic variable names?]]
* [[What is the naming convention for Ansible environment variable overrides?]]
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
Q: What is the naming convention for Ansible environment variable overrides?
A: The pattern is ANSIBLE_ + the uppercase setting name. For settings in specific sections, the section name is included. For example, ssh_args in [ssh_connection] becomes ANSIBLE_SSH_ARGS.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between variable names and environment variables?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
Q: List all 22 variable precedence levels from lowest to highest.
A: 1. command line values (e.g., -u my_user -- these are NOT extra vars)
# role defaults (roles/x/defaults/main.yml)
# inventory file or script group vars
# inventory group_vars/all
# playbook group_vars/all
# inventory group_vars/*
# playbook group_vars/*
# inventory file or script host vars
# inventory host_vars/*
# playbook host_vars/*
# host facts / cached set_facts
# play vars
# play vars_prompt
# play vars_files
# role vars (roles/x/vars/main.yml)
# block vars (only for tasks in the block)
# task vars (only for the task)
# include_vars
# set_facts / registered vars
# role parameters (roles listed in play with vars:)
# include parameters
# extra vars (-e / --extra-vars) -- ALWAYS WIN
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Ansible variable precedence from lowest to highest: defaults → inventory → playbook → task → -e flag]]
* [[Variable precedence: learn role defaults and extra vars, not all 22 levels]]
* [[Ansible variable precedence: bookends and gradient]]
Q: What is the single most important thing to remember about extra vars (-e)?
A: Extra vars always win. They have the highest precedence of any variable source and cannot be overridden by anything else. This makes them useful for emergency overrides but dangerous if overused.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What has the highest variable precedence?]]
Q: What is the difference between role defaults and role vars in terms of precedence?
A: Role defaults (defaults/main.yml) are level 2 -- the second-lowest precedence, designed to be easily overridden. Role vars (vars/main.yml) are level 15 -- much higher precedence, intended for values that should NOT be easily overridden by inventory or group/host vars.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[What has the lowest variable precedence?]]
* [[Variable precedence: learn role defaults and extra vars, not all 22 levels]]
* [[Ansible variable design: where to put tunables]]
Q: A variable is defined in playbook group_vars/all and also in inventory group_vars/webservers. Which wins?
A: The inventory group_vars/webservers (level 6) wins over playbook group_vars/all (level 5), because specific group vars have higher precedence than "all" group vars, and inventory group vars and playbook group vars of the same type are on the same level but specific groups win over "all."
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where can variables be defined?]]
* [[Ansible variable precedence from lowest to highest: defaults → inventory → playbook → task → -e flag]]
* [[What is the precedence order if the same variable is defined in group_vars for a parent…]]
Q: If you set a fact with set_fact and also define the same variable as a role parameter, which wins?
A: Role parameters (level 20) win over set_facts (level 19).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[Can you override an extra var with set_fact?]]
* [[How is `set_fact` different from `vars`?]]
Q: Can you override an extra var with set_fact?
A: No. Extra vars (level 22) always have the highest precedence. set_fact (level 19) cannot override them.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[If you set a fact with set_fact and also define the same variable as a role parameter, …]]
* [[How is `set_fact` different from `vars`?]]
Q: What does the <html><code>hostvars</code></html> magic variable contain?
A: A dictionary of all variables for every host in the inventory, keyed by hostname. You can access another host's variables with <html><code>hostvars['other_host']['variable_name']</code></html>, even from a different play or role.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[What are "magic variables" in Ansible?]]
* [[What is `ansible_play_hosts`?]]
* [[What is `ansible_host` in inventory?]]
Q: What does the <html><code>groups</code></html> magic variable contain?
A: A dictionary mapping every group name in the inventory to a list of hosts in that group. For example, <html><code>groups['webservers']</code></html> returns all hosts in the webservers group.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `group_names` contain?]]
* [[What is a group in an Ansible inventory?]]
* [[What are `group_vars` and `host_vars`?]]
Q: What does <html><code>group_names</code></html> contain?
A: A list of all groups the current host belongs to. It always reflects the <html><code>inventory_hostname</code></html> and is not affected by delegation.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What does the `groups` magic variable contain?]]
* [[What is a group in an Ansible inventory?]]
* [[What is `groups` in Ansible?]]
Q: What is the difference between <html><code>ansible_play_hosts</code></html> and <html><code>ansible_play_hosts_all</code></html>?
A: <html><code>ansible_play_hosts</code></html> contains only hosts still active (not failed). <html><code>ansible_play_hosts_all</code></html> contains all hosts originally targeted by the play, regardless of failures.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `hosts` keyword define in a play?]]
* [[What is `ansible.builtin.add_host`?]]
* [[What is a play in Ansible?]]
Q: What is <html><code>ansible_version</code></html>?
A: A dictionary containing Ansible version information, including 'full' (e.g., "2.16.0"), 'major', 'minor', and 'revision' keys.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
* [[What is `ansible.builtin.apt_key` and why is it deprecated?]]
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
Q: What command shows the Ansible version?
A: <html><code>ansible --version</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
Q: What is <html><code>role_path</code></html>?
A: A magic variable available inside roles that contains the absolute path to the currently executing role's directory. Useful for referencing files relative to the role.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `include_role` vs `import_role`?]]
* [[What does `ansible_search_path` contain?]]
* [[Roles organize reusable Ansible code into directories]]
Q: What is <html><code>playbook_dir</code></html>?
A: The absolute path to the directory containing the playbook that was originally invoked by ansible-playbook.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command runs an Ansible playbook?]]
* [[What does `ansible_search_path` contain?]]
* [[What are Ansible "playbooks"?]]
Q: What does <html><code>ansible_search_path</code></html> contain?
A: The current search path for file lookups, templates, and other file-based operations. It includes the playbook directory, role directories, and any paths added via the <html><code>roles_path</code></html> configuration.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the standard directory structure of an Ansible role?]]
* [[What is `playbook_dir`?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
Q: What is <html><code>ANSIBLE_ROLES_PATH</code></html>?
A: Specifies additional directories where Ansible searches for roles beyond the default <html><code>./roles</code></html> and <html><code>~/.ansible/roles</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Roles organize reusable Ansible code into directories]]
* [[What is the difference between an Ansible playbook and a role?]]
* [[Explain the use of Ansible roles in network automation.]]
Q: What file extension is used for Jinja2 templates?
A: <html><code>.j2</code></html> (e.g., <html><code>nginx.conf.j2</code></html>)
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Jinja2 in the context of Ansible?]]
Q: How do you use variables in Jinja2 templates?
A: <html><code>{{ variable_name }}</code></html> for variable substitution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible `template` module]]
* [[How do you write a conditional in Jinja2?]]
* [[How do you write a loop in Jinja2?]]
Q: How do you write a conditional in Jinja2?
A: <html><code>{% if condition %} ... {% elif condition %} ... {% else %} ... {% endif %}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[If the value of certain variable is 1, you would like to use the value "one", otherwise…]]
* [[How do you use variables in Jinja2 templates?]]
* [[How do you write a loop in Jinja2?]]
Q: How do you write a loop in Jinja2?
A: <html><code>{% for item in list %} {{ item }} {% endfor %}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you write a conditional in Jinja2?]]
* [[How do you use variables in Jinja2 templates?]]
* [[Jinja2 Whitespace Control Prevents Extra Blank Lines]]
Q: What does the <html><code>default</code></html> filter do?
A: Provides a fallback value if the variable is undefined: <html><code>{{ var | default('fallback_value') }}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happens if you reference an undefined variable?]]
* [[What does the `mandatory` filter do?]]
Q: What Jinja2 filter returns a default value when a variable is undefined?
A: <html><code>default()</code></html> or <html><code>d()</code></html> -- e.g., <html><code>{{ var | default('fallback') }}</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happens if you reference an undefined variable?]]
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
Q: Why do you always use <html><code>{{ }}</code></html> in Ansible except in <html><code>when</code></html> clauses?
A: The <html><code>when</code></html> clause is always processed through Jinja2 automatically, so adding braces would cause errors. Everywhere else, braces are required to distinguish variables from plain strings.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Jinja2 Expressions Must Be Quoted in YAML Values]]
* [[Ansible `template` module]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
Q: What does the <html><code>combine</code></html> filter do?
A: Merges two or more dictionaries: <html><code>{{ dict1 | combine(dict2) }}</code></html>. Later dictionaries override earlier ones for duplicate keys.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Why is `hash_behaviour: merge` deprecated?]]
* [[What does `{{ list | map('extract', dict) }}` do?]]
Q: What does the <html><code>combine</code></html> filter do, and why is it so useful?
A: It merges two or more dictionaries. With <html><code>recursive=True</code></html>, it does deep merging. This is essential for combining default values with overrides in complex variable structures. Example: <html><code>{{ defaults | combine(overrides, recursive=True) }}</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Why is `hash_behaviour: merge` deprecated?]]
* [[What does the `flatten` filter do?]]
* [[What does the `default` filter do?]]
Q: What does the <html><code>map</code></html> filter do with the <html><code>attribute</code></html> keyword?
A: Extracts a specific attribute from each item in a list: <html><code>{{ users | map(attribute='name') | list }}</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `{{ list | map('extract', dict) }}` do?]]
* [[How do `selectattr` and `rejectattr` work?]]
* [[Jinja2 filters transform values during template rendering]]
Q: How do <html><code>selectattr</code></html> and <html><code>rejectattr</code></html> work?
A: They filter a list of objects based on an attribute's value: <html><code>{{ users | selectattr('active', 'equalto', true) | list }}</code></html> returns only users where <html><code>active</code></html> is true.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `map` filter do with the `attribute` keyword?]]
Q: What is the <html><code>ternary</code></html> filter?
A: A conditional filter: <html><code>{{ condition | ternary('true_value', 'false_value') }}</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[If the value of certain variable is 1, you would like to use the value "one", otherwise…]]
Q: What does <html><code>regex_replace</code></html> do?
A: Performs regex substitution: <html><code>{{ 'hello-world' | regex_replace('-', '_') }}</code></html> produces <html><code>hello_world</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What is the <html><code>to_json</code></html> and <html><code>from_json</code></html> filter pair used for?
A: <html><code>to_json</code></html> serializes a Python object to a JSON string. <html><code>from_json</code></html> parses a JSON string into a Python data structure.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the relationship between Jinja2's built-in filters and Ansible's filters?]]
Q: What is the <html><code>ipaddr</code></html> filter?
A: A network-focused filter from <html><code>ansible.utils</code></html> that validates and manipulates IP addresses: <html><code>{{ '192.168.1.0/24' | ipaddr('network') }}</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible_connection` variable set to for network devices?]]
* [[How does Ansible manage network devices?]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
Q: What collection is the <html><code>ipaddr</code></html> filter now in, and why?
A: <html><code>ansible.utils</code></html> collection. It was moved there during the collections migration because it depends on the <html><code>netaddr</code></html> Python library, which is not part of ansible-core's dependencies.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[Collections split in 2020 broke thousands of existing Ansible playbooks]]
* [[What is the relationship between Jinja2's built-in filters and Ansible's filters?]]
Q: What is the "Norway Problem" in YAML, and how does it affect Ansible?
A: In YAML 1.1 (which Ansible uses), the string "NO" is interpreted as boolean false. This means the country code for Norway becomes false if unquoted. Similarly, "YES" becomes true and "OFF" becomes false. The fix is to always quote strings that could be misinterpreted as booleans.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Why is YAML 1.2 relevant to Ansible's future?]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
Q: List all the string values that YAML 1.1 interprets as boolean false.
A: false, False, FALSE, no, No, NO, off, Off, OFF.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What ansible-lint rule catches boolean value problems in YAML?]]
* [[Why is YAML 1.2 relevant to Ansible's future?]]
* [[What symbol starts a list item in YAML?]]
Q: What is the YAML octal number gotcha?
A: YAML 1.1 interprets numbers starting with 0 as octal. So <html><code>0777</code></html> is fine (it's an intentional octal for file permissions), but <html><code>0123</code></html> becomes decimal 83 -- not 123 as you might expect. If you mean the string "0123" or the integer 123, you must quote it or remove the leading zero.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does the YAML octal gotcha specifically bite Ansible users?]]
* [[What happens if you write `version: 1.0` in YAML without quotes?]]
* [[List all the string values that YAML 1.1 interprets as boolean false.]]
Q: How does the YAML octal gotcha specifically bite Ansible users?
A: Most commonly with file permission modes. Writing <html><code>mode: 0644</code></html> works as expected because 0644 octal is what you want. But writing <html><code>mode: 644</code></html> (no leading zero) gives you decimal 644, which is octal 1204 -- not what you wanted. Best practice: always quote file modes as strings: <html><code>mode: "0644"</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the YAML octal number gotcha?]]
* [[What happens with `port: 22` vs `port: "22"` in Ansible YAML?]]
* [[What is YAML, and why is it used in Ansible?]]
Q: What happens if you write <html><code>version: 1.0</code></html> in YAML without quotes?
A: YAML interprets it as the floating-point number 1.0, not the string "1.0". This can cause issues when version strings need to remain as strings. Always quote version numbers.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the YAML octal number gotcha?]]
* [[Why is YAML 1.2 relevant to Ansible's future?]]
* [[List all the string values that YAML 1.1 interprets as boolean false.]]
Q: What happens with <html><code>port: 22</code></html> vs <html><code>port: "22"</code></html> in Ansible YAML?
A: <html><code>port: 22</code></html> creates an integer. <html><code>port: "22"</code></html> creates a string. Most [[Ansible modules|Ansible Modules]] handle this transparently, but some modules or Jinja2 operations are type-sensitive and may behave differently.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_port`?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[What port does Ansible use by default for SSH connections?]]
Q: What YAML multiline syntax options does Ansible support, and what are the key differences?
A: (1) Literal block scalar (<html><code>|</code></html>) -- preserves newlines exactly as written. (2) Folded block scalar (<html><code>></code></html>) -- folds newlines into spaces (paragraph-style). Both support <html><code>+</code></html> (keep trailing newline) and <html><code>-</code></html> (strip trailing newline) modifiers.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is YAML, and why is it used in Ansible?]]
* [[What is the syntax for an Ansible Playbook?]]
* [[What language are Ansible playbooks written in?]]
Q: What is the "naked variable" gotcha in Ansible YAML?
A: If a variable reference is the entire value (e.g., <html><code>var: {{ some_var }}</code></html>), YAML may parse it as a dictionary if the value looks like a mapping. The fix is to always quote full-line Jinja2 expressions: <html><code>var: "{{ some_var }}"</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Jinja2 Expressions Must Be Quoted in YAML Values]]
* [[How do you define variables in Ansible Playbooks?]]
* [[Ansible `template` module]]
Q: What ansible-lint rule catches boolean value problems in YAML?
A: The <html><code>yaml[truthy]</code></html> rule. It flags bare truthy values (yes/no/on/off) and recommends using <html><code>true</code></html>/<html><code>false</code></html> instead for clarity and YAML 1.2 forward-compatibility.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[List all the string values that YAML 1.1 interprets as boolean false.]]
* [[Name five ansible-lint rules.]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
Q: Why is YAML 1.2 relevant to Ansible's future?
A: YAML 1.2 drops the boolean interpretation of yes/no/on/off (only true/false are booleans) and changes octal syntax from 0777 to 0o777. If Ansible ever migrates from PyYAML (YAML 1.1) to a YAML 1.2 parser, many playbooks using yes/no values would break.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is YAML, and why is it used in Ansible?]]
* [[What is the "Norway Problem" in YAML, and how does it affect Ansible?]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
Q: What is the relationship between Jinja2's built-in filters and Ansible's filters?
A: Ansible supports all standard Jinja2 filters (e.g., default, join, length, upper, lower, replace) PLUS Ansible-specific filters (e.g., to_yaml, to_json, from_json, ipaddr, regex_search, vault, combine). Users can also create custom filter plugins.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[What is Jinja2 in the context of Ansible?]]
* [[Ansible `template` module]]
Q: Name five Jinja2 built-in filters commonly used in Ansible playbooks.
A: (1) <html><code>default(value)</code></html> -- provides a fallback if variable is undefined; (2) <html><code>join(separator)</code></html> -- joins list items; (3) <html><code>length</code></html> -- returns count of items; (4) <html><code>upper</code></html>/<html><code>lower</code></html> -- case conversion; (5) <html><code>replace(old, new)</code></html> -- string replacement.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Jinja2 in the context of Ansible?]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[Jinja2 tests check conditions in when clauses and conditionals]]
Q: Name five Ansible-specific filters not found in stock Jinja2.
A: (1) <html><code>to_yaml</code></html> / <html><code>to_nice_yaml</code></html> -- convert to YAML; (2) <html><code>to_json</code></html> / <html><code>to_nice_json</code></html> -- convert to JSON; (3) <html><code>from_json</code></html> / <html><code>from_yaml</code></html> -- parse JSON/YAML strings; (4) <html><code>ipaddr</code></html> -- IP address manipulation (now in ansible.utils); (5) <html><code>regex_search</code></html> / <html><code>regex_replace</code></html> -- regex operations; (6) <html><code>combine</code></html> -- merge dictionaries; (7) <html><code>hash</code></html> / <html><code>password_hash</code></html> -- cryptographic hashing.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
* [[What is the relationship between Jinja2's built-in filters and Ansible's filters?]]
* [[Jinja2 filters transform values during template rendering]]
Q: How do you create a custom Jinja2 filter for Ansible?
A: Create a Python file in a <html><code>filter_plugins/</code></html> directory relative to your playbook or role, or in a path specified by ANSIBLE_FILTER_PLUGINS. Define a class with a <html><code>filters()</code></html> method that returns a dictionary mapping filter names to Python functions.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[Jinja2 filters transform values during template rendering]]
* [[Write a filter to capitalize a string]]
Q: What does the <html><code>mandatory</code></html> filter do?
A: It forces a variable to be defined. If the variable is undefined, the playbook fails with a clear error message instead of silently using an empty value. Usage: <html><code>{{ my_var | mandatory }}</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `default` filter do?]]
* [[What happens if you reference an undefined variable?]]
* [[What is the `omit` variable in Ansible?]]
Q: What does <html><code>{{ list | map('extract', dict) }}</code></html> do?
A: It uses each item in <html><code>list</code></html> as a key to look up values in <html><code>dict</code></html>, returning the corresponding values. This is a powerful pattern for transforming lists of keys into lists of values.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `map` filter do with the `attribute` keyword?]]
Q: What filter would you use to base64-encode a string in Ansible?
A: <html><code>{{ my_string | b64encode }}</code></html> to encode, <html><code>{{ my_string | b64decode }}</code></html> to decode.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you encrypt a single string variable?]]
* [[What is `ansible-vault encrypt_string` used for?]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
Q: How do you generate a password hash suitable for /etc/shadow in Ansible?
A: Use the <html><code>password_hash</code></html> filter: <html><code>{{ 'mypassword' | password_hash('sha512', 'mysalt') }}</code></html>. Supported algorithms include sha256, sha512, and blowfish.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `password_hash` filter?]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
Q: How do you generate an encrypted password for the user module?
A: <html><code>ansible all -i localhost, -m debug -a "msg={{ 'password' | password_hash('sha512', 'salt') }}"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[What is the `password_hash` filter?]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
Q: How do you write a conditional task in Ansible?
A: Use the <html><code>when</code></html> keyword: <html><code>when: ansible_os_family == "Debian"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How can you run a specific task or play within an Ansible playbook for testing?]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
Q: How do you loop over a list of items?
A: Use the <html><code>loop</code></html> keyword: <html><code>loop: [httpd, git, curl]</code></html> and reference <html><code>{{ item }}</code></html> in the task.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `with_items` and `loop`?]]
* [[How do you write a loop in Jinja2?]]
* [[What is `ansible_loop`?]]
Q: What is the difference between <html><code>with_items</code></html> and <html><code>loop</code></html>?
A: <html><code>with_items</code></html> is the legacy syntax for looping. <html><code>loop</code></html> is the modern, preferred keyword with cleaner syntax and more advanced features.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happened to `with_items`, `with_dict`, `with_file`, etc.?]]
* [[What happened to `with_items`, `with_dict`, `with_fileglob` etc.?]]
* [[What is `ansible_loop`?]]
Q: What is the <html><code>block</code></html> keyword?
A: Groups multiple tasks together as a single logical unit. Allows applying common attributes (like <html><code>when</code></html>, <html><code>become</code></html>) and error handling to the group.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What is <html><code>ignore_errors</code></html>?
A: Setting <html><code>ignore_errors: yes</code></html> allows a playbook to continue execution even if the task fails.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `any_errors_fatal` and when would you use it?]]
* [[What is `ignore_unreachable`?]]
* [[What is the `fail` module?]]
Q: What does <html><code>ignore_errors: true</code></html> do?
A: Forces Ansible to continue executing subsequent tasks even if the current task fails.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ignore_unreachable`?]]
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
* [[What is the difference between `ignore_errors: true` and using a `rescue` block?]]
Q: What does <html><code>changed_when</code></html> do?
A: Overrides when Ansible considers a task as "changed." Useful for command/shell tasks where you want to control change reporting: <html><code>changed_when: result.rc != 0</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Customize task failure and change status with failed_when and changed_when]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Idempotence is the core contract of Ansible modules]]
Q: How does <html><code>changed_when</code></html> work?
A: It overrides when a task reports "changed" status. Example: <html><code>changed_when: false</code></html> to suppress change reporting, or <html><code>changed_when: "'Created' in result.stdout"</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does `failed_when` work?]]
* [[Customize task failure and change status with failed_when and changed_when]]
* [[Idempotent tasks use built-in modules or changed_when predicates]]
Q: What is <html><code>changed_when: false</code></html> used for?
A: Marks a task as never having made changes, useful for read-only commands that should not show as "changed" in output.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `diff: true` at the task level?]]
* [[What is `check_mode: true` at the task level?]]
* [[What does `no_log: true` do?]]
Q: What does <html><code>no_log: true</code></html> do?
A: Suppresses task input/output from being logged, preventing sensitive data from appearing in logs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `no_log` lint rule about?]]
* [[What is `changed_when: false` used for?]]
* [[What does the `never` tag do?]]
Q: What does <html><code>no_log: true</code></html> do, and how does it relate to Vault?
A: <html><code>no_log: true</code></html> prevents a task's input/output from being logged or displayed. This is critical for tasks that handle decrypted secrets -- Vault protects data at rest, but <html><code>no_log</code></html> protects data during execution output.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the security warning about Vault and "data at rest" vs. "data in use"?]]
* [[What is the `no_log` lint rule about?]]
Q: What is <html><code>delegate_to</code></html>?
A: Runs a task on a different host than the current play target. Useful for orchestration like removing a host from a load balancer before updating it.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `delegate_facts: true`?]]
* [[What is the `local_action` keyword?]]
* [[What is the "two-stage" or "delegate and register" pattern?]]
Q: What does <html><code>delegate_to</code></html> do?
A: Runs a task on a different host than the current target, while still using the original host's variables and facts.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Delegated tasks see target host facts, not delegation-target facts]]
* [[Delegation runs a task on a different host while preserving target context]]
* [[What tasks cannot be delegated?]]
Q: How do you run tasks asynchronously?
A: Use <html><code>async: <seconds></code></html> to set max runtime and <html><code>poll: <seconds></code></html> to set check interval. <html><code>poll: 0</code></html> means fire-and-forget.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What do `async` and `poll` do together in a task?]]
* [[How do you fire-and-forget a long-running task?]]
* [[Can async tasks run in check mode?]]
Q: What tasks cannot be delegated?
A: <html><code>include</code></html>, <html><code>add_host</code></html>, and <html><code>debug</code></html> tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `delegate_to` do?]]
* [[What is `delegate_to`?]]
* [[Delegated tasks see target host facts, not delegation-target facts]]
Q: What does <html><code>run_once: true</code></html> do?
A: Executes the task on only one host in the play, regardless of how many hosts are targeted. Typically runs on the first host in the batch.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[What is `ansible_play_batch`?]]
* [[Delegation runs a task on a different host while preserving target context]]
Q: What happens when <html><code>run_once</code></html> is combined with <html><code>serial</code></html>?
A: The task runs once per serial batch, not once for the entire play.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[What is `ansible_play_batch`?]]
* [[Can `serial` accept a list? What does that do?]]
Q: Can <html><code>serial</code></html> be expressed as a percentage?
A: Yes: <html><code>serial: "25%"</code></html> processes 25% of hosts per batch.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Can `serial` accept a list? What does that do?]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[What is the `serial` keyword?]]
Q: What is the fundamental difference between <html><code>import_*</code></html> and <html><code>include_*</code></html>?
A: <html><code>import_*</code></html> is static -- processed at playbook parse time. <html><code>include_*</code></html> is dynamic -- processed at runtime when the task is encountered. This affects tag inheritance, <html><code>when</code></html> evaluation, and loop behavior.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `include_role` vs `import_role`?]]
* [[Playbook execution flows through pre_tasks, roles, tasks, post_tasks with distinct import/include behavior]]
Q: Can you use <html><code>when</code></html> conditions with <html><code>import_tasks</code></html>?
A: Yes, but the condition is applied to every task inside the imported file, not to the import itself. This is a common gotcha.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
* [[Can you loop over `import_tasks`?]]
* [[How do you write a conditional task in Ansible?]]
Q: Can you loop over <html><code>import_tasks</code></html>?
A: No. Loops only work with <html><code>include_tasks</code></html>. Import is static and cannot be looped.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Can you use `when` conditions with `import_tasks`?]]
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
* [[What is the difference between `include_tasks` and `import_tasks`?]]
Q: What is the Ansible equivalent of try/catch/finally?
A: block/rescue/always. <html><code>block</code></html> contains the tasks to try, <html><code>rescue</code></html> runs if block fails, <html><code>always</code></html> runs regardless.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[If a rescue section succeeds, does Ansible consider the play failed?]]
* [[What is the `retry_until` pattern in Ansible?]]
* [[What is the difference between `ignore_errors: true` and using a `rescue` block?]]
Q: What types of errors do NOT trigger the rescue block?
A: Invalid task definitions (syntax errors) and unreachable hosts. Only task execution failures trigger rescue.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the difference between `ignore_errors: true` and using a `rescue` block?]]
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
Q: What is the difference between <html><code>ignore_errors: true</code></html> and using a <html><code>rescue</code></html> block?
A: <html><code>ignore_errors</code></html> marks a failed task as "ok" and continues unconditionally. <html><code>rescue</code></html> provides structured error handling -- you can run specific recovery tasks, log failures, or take corrective action.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
* [[What types of errors do NOT trigger the rescue block?]]
* [[What does `ignore_errors: true` do?]]
Q: What is <html><code>any_errors_fatal</code></html> and when would you use it?
A: When set to <html><code>true</code></html> at the play level, if ANY host fails a task, all hosts in the play are immediately marked as failed and execution stops. Useful for critical tasks where partial success is dangerous (e.g., database migrations).
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 8 source atoms.//
''Related atoms''
* [[What is the `fail` module?]]
* [[What is `ignore_errors`?]]
* [[What is `meta: clear_host_errors`?]]
Q: What is the <html><code>notify</code></html> keyword?
A: Used in a task to trigger a handler by name when the task reports a change.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `listen` directive on handlers?]]
* [[Can handlers notify other handlers?]]
Q: When do handlers execute?
A: At the end of each play, after all tasks have completed. You can force earlier execution with <html><code>meta: flush_handlers</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible handlers: conditional, once-only task execution]]
* [[Ansible handlers skip entirely if the play fails]]
* [[What is `meta: end_play`?]]
Q: How do you force handlers to run mid-play?
A: Use the <html><code>meta: flush_handlers</code></html> task.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `meta: flush_handlers` do?]]
* [[What is `meta: end_play`?]]
* [[Ansible handlers skip entirely if the play fails]]
Q: What happens if a handler is notified multiple times?
A: It runs only once, regardless of how many tasks notified it.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Handlers run once at play end, triggered by task notifications]]
* [[Ansible handlers: conditional, once-only task execution]]
* [[Can handlers notify other handlers?]]
Q: What is the standard role directory structure?
A: <html><code>tasks/main.yml</code></html> (core tasks), <html><code>handlers/main.yml</code></html> (triggered actions), <html><code>defaults/main.yml</code></html> (default variables, lowest precedence), <html><code>vars/main.yml</code></html> (role variables, higher precedence), <html><code>files/</code></html> (static files), <html><code>templates/</code></html> (Jinja2 templates), <html><code>meta/main.yml</code></html> (role metadata and dependencies), <html><code>tests/</code></html> (test playbooks).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Roles standardize reusable automation into a predictable directory structure]]
* [[What does `meta/main.yml` in a role contain?]]
* [[What is the standard collection directory structure?]]
Q: What is the standard directory structure of an Ansible role?
A: <html><code>tasks/</code></html>, <html><code>handlers/</code></html>, <html><code>defaults/</code></html>, <html><code>vars/</code></html>, <html><code>files/</code></html>, <html><code>templates/</code></html>, <html><code>meta/</code></html>, <html><code>library/</code></html>, <html><code>module_utils/</code></html>, <html><code>lookup_plugins/</code></html>, and optionally <html><code>tests/</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `ansible_search_path` contain?]]
* [[Explain the difference between tasks, handlers, and defaults in an Ansible Role.]]
* [[How do you create a new role skeleton?]]
Q: What is the difference between <html><code>defaults/main.yml</code></html> and <html><code>vars/main.yml</code></html>?
A: <html><code>defaults</code></html> has the lowest variable precedence and is meant to be overridden by users. <html><code>vars</code></html> has higher precedence and contains internal variables that should not normally be overridden.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What has the lowest variable precedence?]]
* [[What is the difference between `vars`, `vars_files`, and `vars_prompt`?]]
Q: How do you create a new role skeleton?
A: <html><code>ansible-galaxy init role_name</code></html> creates the standard directory structure.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the standard directory structure of an Ansible role?]]
* [[Roles organize reusable Ansible code into directories]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
Q: What command initializes a new role skeleton?
A: <html><code>ansible-galaxy role init my_role_name</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command initializes a new collection skeleton?]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
* [[What is the standard directory structure of an Ansible role?]]
Q: How do you specify role dependencies?
A: In <html><code>meta/main.yml</code></html> under the <html><code>dependencies</code></html> key, listing other roles that must execute first.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `meta/main.yml` in a role contain?]]
* [[What is the standard role directory structure?]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
Q: When should you use a role vs a simple task file?
A: Use roles for reusable, well-organized automation with standard layouts shared across projects. Task files suffice for simple, lightweight, one-off automation.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the use of Ansible roles in network automation.]]
* [[What is the difference between an Ansible playbook and a role?]]
* [[Roles standardize reusable automation into a predictable directory structure]]
Q: How do you include roles in a playbook?
A: Using the <html><code>roles:</code></html> keyword in a play, or dynamically with <html><code>include_role</code></html> or <html><code>import_role</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you structure a good playbook or role?]]
* [[Roles standardize reusable automation into a predictable directory structure]]
* [[What is the difference between an Ansible playbook and a role?]]
Q: What is a Fully Qualified Collection Name (FQCN)?
A: The format <html><code>namespace.collection.module_name</code></html> used to reference content within collections (e.g., <html><code>community.general.docker_container</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `collections:` at the play level?]]
* [[What is the namespace.collection format, and why does it matter?]]
* [[What is `collections` keyword in a playbook?]]
Q: What is a Fully Qualified Collection Name (FQCN), and why does it matter post-migration?
A: An FQCN is the complete namespace.collection.module_name identifier (e.g., ansible.builtin.copy, community.general.docker_container). After the migration, FQCNs became the authoritative way to specify which collection a module comes from, preventing ambiguity when multiple collections provide similarly-named modules.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happens if two collections provide a module with the same short name?]]
* [[What happens if you use a short module name (e.g., "copy") instead of the FQCN in a pos…]]
* [[What is the namespace.collection format, and why does it matter?]]
Q: What is a "fully qualified collection name" (FQCN)?
A: The complete namespace.collection.module path, e.g., <html><code>ansible.builtin.copy</code></html>, <html><code>community.general.ufw</code></html>, <html><code>amazon.aws.ec2_instance</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[Modules, plugins, and collections in Ansible architecture]]
* [[What happens if two collections provide a module with the same short name?]]
Q: How do you install a collection?
A: <html><code>ansible-galaxy collection install namespace.collection_name</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you install a specific version of a collection?]]
* [[How do you install a collection from a specific Git repository?]]
* [[What command initializes a new collection skeleton?]]
Q: How do you install collections from a requirements file?
A: <html><code>ansible-galaxy collection install -r requirements.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you install a collection from a specific Git repository?]]
* [[What is the galaxy.yml file in a collection?]]
* [[Collections are distributable packages of roles, modules, and plugins]]
Q: Can you install collections from a tarball?
A: Yes: <html><code>ansible-galaxy collection install /path/to/collection-1.0.0.tar.gz</code></html>
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you install a specific version of a collection?]]
* [[How do you install a collection from a specific Git repository?]]
* [[Collections are distributable packages of roles, modules, and plugins]]
Q: What is a collection namespace?
A: A unique name prefix that organizes collections and prevents naming conflicts between different authors.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `collections` keyword in a playbook?]]
* [[What is a Fully Qualified Collection Name (FQCN)?]]
Q: What does <html><code>meta/main.yml</code></html> in a role contain?
A: Role metadata: dependencies, minimum Ansible version, supported platforms, Galaxy metadata (author, license, description, tags).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Roles organize reusable Ansible code into directories]]
* [[What is the standard role directory structure?]]
* [[Ansible Galaxy: community hub for roles and collections]]
Q: What file must exist in the root of an Ansible Galaxy role for it to be recognized?
A: A <html><code>meta/main.yml</code></html> file containing role metadata (author, description, license, platforms, dependencies, galaxy_info).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Installing Ansible Galaxy roles from CLI and requirements file]]
* [[What is a requirements.yml file for Galaxy?]]
* [[What is the galaxy.yml file in a collection?]]
Q: What is the standard collection directory structure?
A: <html><code>galaxy.yml</code></html>, <html><code>plugins/</code></html> (modules, filter, lookup, inventory, callback, etc.), <html><code>roles/</code></html>, <html><code>playbooks/</code></html>, <html><code>docs/</code></html>, <html><code>meta/runtime.yml</code></html>, <html><code>tests/</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the galaxy.yml file in a collection?]]
* [[What is the standard role directory structure?]]
* [[What is the standard directory structure of an Ansible role?]]
Q: What does <html><code>meta/runtime.yml</code></html> in a collection do?
A: Defines routing information: module/plugin redirects, deprecations, and tombstones for backward compatibility.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "routing" configuration in the context of collections migration?]]
* [[What is the galaxy.yml file in a collection?]]
* [[What does `meta/main.yml` in a role contain?]]
Q: What cannot collection role names contain?
A: Hyphens. When migrating roles to collections, hyphens must be replaced with underscores.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you include roles in a playbook?]]
* [[What is a collection namespace?]]
* [[What is the difference between a Galaxy role and a Galaxy collection?]]
Q: How do you install a collection from a specific Git repository?
A: <html><code>ansible-galaxy collection install git+https://github.com/org/repo.git,branch_or_tag</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you install a collection?]]
* [[How do you install a specific version of a collection?]]
* [[Can you install collections from a tarball?]]
Q: What is <html><code>collections:</code></html> at the play level?
A: A list of collections to search for modules/plugins, allowing short names instead of FQCNs within that play.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[What is a Fully Qualified Collection Name (FQCN)?]]
* [[What happens if you use a short module name (e.g., "copy") instead of the FQCN in a pos…]]
Q: What is <html><code>collections</code></html> keyword in a playbook?
A: Specifies which collections to search for modules/plugins, eliminating the need for FQCNs in tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[When did the collections concept first appear in Ansible?]]
Q: What is the default Ansible Galaxy server URL?
A: <html><code>https://galaxy.ansible.com</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where is the default inventory file located?]]
* [[What port does Ansible use by default for SSH connections?]]
* [[What playbook filename does ansible-pull look for by default?]]
Q: Before Ansible 2.10, how was all community-contributed content structured?
A: Everything -- thousands of modules, plugins, and roles -- lived in a single monolithic GitHub repository (ansible/ansible). This made Ansible an outlier among open-source projects.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How many modules were in the monolithic Ansible 2.9 repository before the split?]]
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
Q: Why was the monolithic repo problematic?
A: The core dev team was burdened with thousands of issues and PRs for thousands of components they could not even test. It slowed releases, made testing unwieldy, and prevented module maintainers from releasing independently.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When did Ansible collections replace the monolithic package?]]
* [[Before Ansible 2.10, how was all community-contributed content structured?]]
Q: Name five major collections that were extracted from the monolithic Ansible repo during the migration.
A: (1) community.general -- miscellaneous modules that didn't fit elsewhere; (2) community.network -- network device modules; (3) community.crypto -- cryptographic modules; (4) community.docker -- Docker modules; (5) community.mysql -- MySQL modules; (6) amazon.aws / community.aws -- AWS modules; (7) ansible.posix -- POSIX-specific modules; (8) ansible.windows -- Windows modules.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How many modules were in the monolithic Ansible 2.9 repository before the split?]]
* [[What is the `ansible.posix` collection?]]
* [[Collections split in 2020 broke thousands of existing Ansible playbooks]]
Q: What is the "routing" configuration in the context of collections migration?
A: Routing configuration (meta/routing.yml) in a collection defines redirects and tombstones for modules/plugins that have moved or been removed. It helps Ansible resolve old short names to new FQCNs and displays deprecation/removal warnings.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `meta/runtime.yml` in a collection do?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
* [[What is a Fully Qualified Collection Name (FQCN), and why does it matter post-migration?]]
Q: What is a "tombstone" entry in Ansible's collection routing?
A: When a module has been deprecated and then fully removed, a tombstone entry is placed in the routing config. Instead of the module code, users see a message directing them to the replacement module or collection.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `COLLECTIONS_PATHS` configuration?]]
* [[Modules, plugins, and collections in Ansible architecture]]
* [[What is `hash_behaviour` in ansible.cfg?]]
Q: What is the deprecation cycle length in ansible-core for features?
A: Features are deprecated across 4 feature releases and normally removed in the 4th release after deprecation. For example, something deprecated in 2.10 would be removed in 2.14.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How long is each ansible-core major version maintained?]]
* [[Why do Ansible community package version numbers jump from 2.10 to 3.0, 4.0, etc., whil…]]
* [[What is `ansible_version`?]]
Q: What is the difference between a Galaxy role and a Galaxy collection?
A: A role is a structured set of tasks, handlers, vars, templates, and files for a specific purpose. A collection is a broader distribution format that can contain roles, modules, plugins, playbooks, and documentation -- it is the modern packaging standard post-2.10.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Galaxy: community hub for roles and collections]]
* [[What is the difference between an Ansible playbook and a role?]]
* [[Collections are distributable packages of roles, modules, and plugins]]
Q: What command initializes a new collection skeleton?
A: <html><code>ansible-galaxy collection init namespace.collection_name</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you install a collection?]]
* [[What command initializes a new role skeleton?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
Q: What is the namespace.collection format, and why does it matter?
A: Collections use a two-part name: namespace.collection (e.g., ansible.builtin, community.general, amazon.aws). The namespace prevents naming collisions and identifies the maintainer or organization.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Modules, plugins, and collections in Ansible architecture]]
* [[How do you install a collection?]]
* [[Collections are distributable packages of roles, modules, and plugins]]
Q: What is the galaxy.yml file in a collection?
A: The collection manifest file containing metadata: namespace, name, version, authors, description, license, dependencies on other collections, repository URL, and required Ansible version.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the standard collection directory structure?]]
* [[What is a requirements.yml file for Galaxy?]]
* [[How do you install a collection?]]
Q: How do you install a specific version of a collection?
A: <html><code>ansible-galaxy collection install community.general:==5.0.0</code></html> or use a requirements.yml file with version pinning.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you install a collection?]]
* [[How do you install a collection from a specific Git repository?]]
* [[Can you install collections from a tarball?]]
Q: What is a requirements.yml file for Galaxy?
A: A YAML file listing roles and/or collections with optional version constraints to install. Example:
<html><pre><code class="language-yaml">collections:
- name: community.general
version: ">=5.0.0,<6.0.0"
roles:
- name: geerlingguy.docker</code></pre></html>
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the galaxy.yml file in a collection?]]
* [[Installing Ansible Galaxy roles from CLI and requirements file]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
Q: What is the Red Hat Certified Specialist in Ansible Automation exam called?
A: EX374 -- Red Hat Certified Specialist in Developing Automation with Ansible Automation Platform. There is also EX467 for older Tower-specific content.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When did Red Hat acquire Ansible?]]
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
* [[What is Ansible Tower?]]
Q: What is <html><code>ansible-creator</code></html>?
A: A scaffolding tool that generates new Ansible content projects (collections, roles, playbooks) with best-practice directory structures and boilerplate.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-builder`?]]
* [[Who created Ansible and when?]]
* [[What does the `ansible-galaxy` CLI do?]]
Q: What Python package manager does Ansible recommend for installation?
A: pip (pipx for isolated installations). The recommended approach is <html><code>pipx install ansible</code></html> or <html><code>pip install ansible</code></html> in a virtual environment.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What's your experience with Ansible?]]
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
Q: How do you decrypt a file?
A: <html><code>ansible-vault decrypt secrets.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[A playbook fails to decrypt Vault data. What do you check?]]
* [[How do you create an encrypted file using Ansible Vault?]]
Q: How do you view an encrypted file without decrypting?
A: <html><code>ansible-vault view secrets.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you edit an encrypted file?]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[How do you run a playbook that uses vault-encrypted files?]]
Q: How do you encrypt a single string variable?
A: <html><code>ansible-vault encrypt_string 'secret_value' --name 'variable_name'</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you reference vault-encrypted variables in a playbook?]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
Q: What is <html><code>ansible-vault encrypt_string</code></html> used for?
A: It encrypts a single string value (rather than an entire file) for embedding directly in a YAML file as an inline encrypted variable. This lets you mix encrypted and plain-text variables in the same file.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Can you encrypt only specific variables in a file?]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[What encryption algorithm does Ansible Vault use?]]
Q: How do you run a playbook that uses vault-encrypted files?
A: <html><code>ansible-playbook playbook.yml --ask-vault-pass</code></html> (interactive) or <html><code>--vault-password-file /path/to/password-file</code></html> (automated).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you reference vault-encrypted variables in a playbook?]]
* [[What is `--vault-password-file`?]]
* [[Explain the process of editing an encrypted file with Ansible Vault.]]
Q: A playbook fails to decrypt Vault data. What do you check?
A: Verify the vault password is correct, check the file path, ensure the correct Vault ID is specified, verify the file was encrypted with the expected password.
----
*Total: 300+ Q&A pairs covering Ansible core concepts, architecture, configuration, modules, plugins,
Galaxy/Collections, Vault, Tower/AWX, facts/variables, Jinja2, best practices, networking, cloud,
CI/CD, performance, security, testing, and history/trivia.*
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[How do you decrypt a file?]]
* [[Explain the process of editing an encrypted file with Ansible Vault.]]
Q: What are Vault IDs?
A: Labels that allow using multiple vault passwords in a single playbook run, enabling different encryption keys for different secrets.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Can you use multiple vault passwords in a single playbook run?]]
* [[What does `ansible-vault rekey` do?]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
Q: What is a Vault ID, and why would you use multiple?
A: A Vault ID labels an encrypted value with a name (e.g., "dev", "prod"), allowing different passwords for different environments. You can then pass multiple <html><code>--vault-id</code></html> arguments to decrypt values from different vaults in a single playbook run.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[How do you run a playbook that uses vault-encrypted files?]]
* [[How do you reference vault-encrypted variables in a playbook?]]
Q: How do you reference vault-encrypted variables in a playbook?
A: Include the encrypted file with <html><code>vars_files: - secrets.yml</code></html> and reference variables normally with <html><code>{{ variable_name }}</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you run a playbook that uses vault-encrypted files?]]
* [[How do you encrypt a single string variable?]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
Q: What does <html><code>become</code></html> do?
A: Enables privilege escalation (like sudo) to run tasks with elevated permissions.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the default become method?]]
* [[What is `become_user`?]]
* [[What is `become_method`?]]
Q: What is <html><code>become_user</code></html>?
A: Specifies which user to escalate to (default is <html><code>root</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `become_method`?]]
* [[What does `become` do?]]
* [[What is the default become method?]]
Q: What is <html><code>become_method</code></html>?
A: Specifies the escalation method (default is <html><code>sudo</code></html>). Other options: <html><code>su</code></html>, <html><code>pbrun</code></html>, <html><code>pfexec</code></html>, <html><code>doas</code></html>, <html><code>dzdo</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `become_method` setting and what values does it support?]]
* [[What is `become_user`?]]
* [[What does `become` do?]]
Q: What is the default become method?
A: <html><code>sudo</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `become_method` setting and what values does it support?]]
* [[What does `become` do?]]
* [[What is `become_user`?]]
Q: How do you specify the SSH user for Ansible?
A: Via CLI with <html><code>-u username</code></html>, in inventory with <html><code>ansible_user=username</code></html>, or in playbooks/ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[What command runs an Ansible playbook?]]
* [[The variable 'whoami' defined in the following places:]]
Q: How do you set up a jump host (bastion) in Ansible?
A: Configure <html><code>ProxyJump</code></html> in SSH config, or use <html><code>ansible_ssh_common_args: '-o ProxyJump=jump_host'</code></html> in inventory/playbooks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[ansible_ssh_common_args: appending SSH args to all SSH connections]]
* [[What is `ansible_port`?]]
Q: How do you securely manage control node credentials?
A: Use SSH key agents, keep credentials out of playbooks, use Ansible Vault for encryption, set <html><code>no_log: true</code></html> for sensitive tasks, and limit control node access.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you manage secrets in Ansible?]]
Q: How do you handle external secret lookups?
A: Use lookup plugins for cloud secret managers (aws_ssm, hashi_vault), or integrate with HashiCorp Vault, AWS Secrets Manager, etc.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you manage secrets across multiple environments?]]
* [[Name ten commonly used lookup plugins.]]
Q: What encryption algorithm does Ansible Vault use?
A: AES-256 in CTR mode with HMAC-SHA256 authentication.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[What is `ansible-vault encrypt_string` used for?]]
* [[How do you decrypt a file?]]
Q: Can you use multiple vault passwords in a single playbook run?
A: Yes. Pass multiple <html><code>--vault-id</code></html> options: <html><code>ansible-playbook --vault-id dev@dev_pass --vault-id prod@prod_pass site.yml</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[How do you run a playbook that uses vault-encrypted files?]]
* [[What are Vault IDs?]]
Q: What does <html><code>ansible-vault rekey</code></html> do?
A: Changes the encryption password on vault-encrypted files. Useful for password rotation. Can also change the vault ID with <html><code>--new-vault-id</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `--vault-password-file`?]]
* [[What is `ansible-vault encrypt_string` used for?]]
* [[What encryption algorithm does Ansible Vault use?]]
Q: Can you encrypt only specific variables in a file?
A: Yes, using <html><code>ansible-vault encrypt_string</code></html> to create inline encrypted values within an otherwise plaintext YAML file.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-vault encrypt_string` used for?]]
* [[How do you create an encrypted file using Ansible Vault?]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
Q: How do you use a script to provide vault passwords?
A: Pass an executable script as the password source: <html><code>--vault-id label@/path/to/script.py</code></html>. The script must output the password to stdout.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Vault Passwords Must Not Appear in Shell History or Plain Text]]
* [[What is `--vault-password-file`?]]
* [[What does the `--ask-vault-pass` flag do?]]
Q: Can Ansible Vault encrypt an entire directory?
A: No. Vault operates on individual files. You must encrypt each file separately or use encrypt_string for individual variables.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[How do you create an encrypted file using Ansible Vault?]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
Q: What is the security warning about Vault and "data at rest" vs. "data in use"?
A: Vault ONLY protects data at rest (on disk). Once decrypted during play execution, secrets are in memory and potentially in logs. Play authors must use <html><code>no_log</code></html> to prevent disclosure during task execution.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `no_log: true` do, and how does it relate to Vault?]]
* [[How do you handle a playbook that exposes sensitive data in logs?]]
Q: What are Ansible's default privilege escalation methods?
A: sudo (default), su, pbrun, pfexec, doas, dzdo, ksu, runas (Windows), enable (network), machinectl (systemd).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible_become_exe` variable?]]
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[What happens when you apply `become: true` with the `local` connection?]]
Q: What is the security risk of using <html><code>shell</code></html> or <html><code>command</code></html> modules with user-supplied variables?
A: Command injection. If variables are interpolated into command strings without proper quoting/validation, an attacker could inject arbitrary commands. Prefer purpose-built modules over shell/command when possible.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `command` and `shell` modules?]]
* [[Why is shell in Ansible dangerous?]]
Q: What does the <html><code>--ask-vault-pass</code></html> flag do?
A: Prompts the user to enter the Vault password at runtime instead of storing it in a file. More secure for interactive use.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `--vault-password-file`?]]
* [[What does `ansible-vault rekey` do?]]
Q: What is <html><code>--vault-password-file</code></html>?
A: Points to a file (or executable script) containing the Vault password. If it's a script, Ansible executes it and uses stdout as the password. Useful for integration with secret managers (HashiCorp Vault, AWS Secrets Manager).
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you run a playbook that uses vault-encrypted files?]]
* [[What does the `--ask-vault-pass` flag do?]]
* [[How do you decrypt a file?]]
Q: What is ansible-lint?
A: A linting tool that checks playbooks and roles for style, best practices, and potential errors.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What configuration file does ansible-lint use?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What is the `shared` lint profile intended for?]]
Q: How do you test playbooks?
A: Use <html><code>--syntax-check</code></html> for syntax, <html><code>--check</code></html> for dry runs, ansible-lint for linting, Molecule for role testing, and integration with CI/CD for automated testing.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you test Ansible safely?]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[Playbook testing combines linting, role integration tests, and idempotency checks]]
Q: What is the <html><code>debug</code></html> strategy?
A: A strategy plugin that enables interactive task-by-task debugging, allowing you to step through playbook execution.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are strategy plugins?]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
* [[Ansible strategy plugins control task-execution ordering across hosts]]
Q: What does the <html><code>debug</code></html> strategy allow?
A: Interactive step-through execution. When a task fails, it drops into a debug prompt where you can inspect variables, re-run the task, or continue execution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `debug` module do?]]
Q: If a rescue section succeeds, does Ansible consider the play failed?
A: No. If the rescue task succeeds, Ansible reverts the failed status and continues the play as if the original task succeeded.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[What is the Ansible equivalent of try/catch/finally?]]
* [[What does `ignore_errors: true` do?]]
Q: What is <html><code>ignore_unreachable</code></html>?
A: A directive that tells Ansible to continue with remaining tasks even when a host becomes unreachable, rather than removing it from the play.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `ignore_errors: true` do?]]
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[What is `ignore_errors`?]]
Q: What is SSH ControlPersist?
A: An SSH feature that keeps connections open for reuse, reducing connection overhead. Configure in SSH config or ansible.cfg.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
* [[What are connection plugins?]]
Q: How many forks does Ansible use by default?
A: 5 (configurable in ansible.cfg or with <html><code>-f</code></html> flag).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[Forks control Ansible parallelism]]
* [[Explain the Difference between Forks and Serial & Throttle.]]
Q: What is the <html><code>forks</code></html> setting, and what is its default value?
A: <html><code>forks</code></html> controls how many hosts Ansible connects to in parallel. The default is 5. Increasing this number can dramatically speed up playbook execution across large inventories.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[Explain the Difference between Forks and Serial & Throttle.]]
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[High fork counts cause connection exhaustion and cascading failures]]
Q: What are the three main things to investigate for a slow playbook on 500 hosts?
A: 1) Enable SSH pipelining, 2) increase forks for more parallelism, 3) configure fact caching to avoid re-gathering facts.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible performance optimization for large inventories]]
* [[Optimizing Ansible Playbook Performance]]
* [[Fleet diagnostics demand parallelism; forks multiply time]]
Q: You have a slow playbook on 500 hosts. What do you investigate first?
A: Enable SSH pipelining, increase forks, configure fact caching, check for unnecessary gather_facts, optimize slow tasks, consider async for long-running operations.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible performance optimization for large inventories]]
* [[One slow host stalls the entire batch unless timeouts are aggressive]]
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
Q: What is Mitogen for Ansible?
A: A completely redesigned UNIX connection layer that replaces Ansible's shell-centric SSH implementation with pure-Python equivalents using efficient remote procedure calls to persistent interpreters tunnelled over SSH.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
* [[What other connection optimizations exist beyond Mitogen?]]
* [[How does Mitogen achieve its performance gains?]]
Q: How does Mitogen achieve its performance gains?
A: Instead of opening a new SSH channel, transferring a module file, executing it, and cleaning up for every task, Mitogen establishes persistent Python interpreters on remote hosts and sends module code through an efficient RPC protocol.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Mitogen transfer data?]]
* [[What are key limitations of Mitogen?]]
* [[What is Mitogen for Ansible?]]
Q: What speedup can Mitogen provide?
A: 1.25x to 7x speedup and at least 2x CPU usage reduction. One real-world example showed playbook runtime dropping from 45 minutes to under 3 minutes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are key limitations of Mitogen?]]
* [[How does Mitogen achieve its performance gains?]]
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
Q: How does Mitogen transfer data?
A: Using UNIX pipes on remote machines, passing "pickled" Python code compressed with zlib. It caches unmodified modules in RAM after first use.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Mitogen achieve its performance gains?]]
* [[What are key limitations of Mitogen?]]
* [[What is Mitogen for Ansible?]]
Q: What are the three Mitogen strategy plugins?
A: <html><code>mitogen_linear</code></html>, <html><code>mitogen_free</code></html>, and <html><code>mitogen_host_pinned</code></html> -- corresponding to Ansible's built-in strategy plugins.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Mitogen for Ansible?]]
* [[What are strategy plugins?]]
* [[What other connection optimizations exist beyond Mitogen?]]
Q: What are key limitations of Mitogen?
A: The <html><code>raw</code></html> action requires Python on targets (preventing Python bootstrapping); only doas, su, and sudo are supported for become (not arbitrary become plugins); actions serialize per (host, user) combination; Python 3 performance lags behind Python 2.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Mitogen achieve its performance gains?]]
* [[What speedup can Mitogen provide?]]
* [[What is Mitogen for Ansible?]]
Q: What other connection optimizations exist beyond Mitogen?
A: Enable <html><code>pipelining = True</code></html> in ansible.cfg (reduces SSH operations), increase <html><code>forks</code></html> for parallelism, configure SSH <html><code>ControlPersist</code></html> to keep connections open, and use fact caching to avoid repeated gathering.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
* [[What is Mitogen for Ansible?]]
Q: How does the <html><code>free</code></html> strategy differ from <html><code>linear</code></html>?
A: With <html><code>free</code></html>, each host runs through tasks as fast as it can independently, without waiting for other hosts to complete the current task. Fast hosts finish the entire play before slow hosts.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the default strategy, and what is its key characteristic?]]
* [[What is the difference between `free` and `host_pinned`?]]
* [[Ansible strategy plugins control task-execution ordering across hosts]]
Q: When would you use the <html><code>free</code></html> strategy?
A: When hosts are independent and don't need to synchronize between tasks. Each host runs through the playbook as fast as it can without waiting for others. Useful when tasks on different hosts have varying execution times.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible strategy plugins control task-execution ordering across hosts]]
* [[What is the difference between `free` and `host_pinned`?]]
* [[What is the default strategy, and what is its key characteristic?]]
Q: What is the <html><code>host_pinned</code></html> strategy?
A: Similar to <html><code>free</code></html>, but it pins each host to a dedicated worker, ensuring one host doesn't monopolize workers. This is useful for debugging or when tasks have varying execution times.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `free` and `host_pinned`?]]
* [[Ansible strategy plugins: built-in options and defaults]]
* [[When would you use the `free` strategy?]]
Q: How do you set the strategy for a play?
A: With the <html><code>strategy:</code></html> keyword at the play level: <html><code>strategy: free</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Can you set strategy globally?]]
* [[What are strategy plugins?]]
* [[What keyword defines tasks in a playbook?]]
Q: Can you set strategy globally?
A: Yes, via <html><code>DEFAULT_STRATEGY</code></html> in <html><code>ansible.cfg</code></html> or the <html><code>ANSIBLE_STRATEGY</code></html> environment variable.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible strategy plugins: built-in options and defaults]]
* [[Can you set variables with magic variable names?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
Q: What does the <html><code>async</code></html> keyword do?
A: Sets the maximum time (in seconds) an asynchronous task is allowed to run before Ansible terminates it.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible async/poll decouples long task submission from completion]]
* [[How do you fire-and-forget a long-running task?]]
* [[What happens if a task exceeds its `async` timeout?]]
Q: What do <html><code>async</code></html> and <html><code>poll</code></html> do together in a task?
A: <html><code>async</code></html> sets the maximum runtime (seconds) for the task. <html><code>poll</code></html> sets how often (seconds) to check if the task is done. If <html><code>poll: 0</code></html>, the task fires and forgets -- Ansible moves on immediately without waiting.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[How do you run tasks asynchronously?]]
* [[How do you fire-and-forget a long-running task?]]
* [[Does `poll: 0` automatically clean up the async job cache file?]]
Q: How do you check the status of a fire-and-forget async task?
A: Use the <html><code>async_status</code></html> module with the <html><code>jid</code></html> (job ID) returned by the original async task registered in a variable.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you fire-and-forget a long-running task?]]
* [[How do you run tasks asynchronously?]]
* [[Can async tasks run in check mode?]]
Q: What module checks the status of a previously fired async task?
A: <html><code>async_status</code></html>, using the <html><code>jid</code></html> (job ID) from the registered result of the original task.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you fire-and-forget a long-running task?]]
* [[What do `async` and `poll` do together in a task?]]
* [[How do you run tasks asynchronously?]]
Q: What happens if a task exceeds its <html><code>async</code></html> timeout?
A: The process on the remote node is terminated.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `async` keyword do?]]
* [[How do you fire-and-forget a long-running task?]]
* [[What is a practical use case for async with poll > 0?]]
Q: Does <html><code>poll: 0</code></html> automatically clean up the async job cache file?
A: No. You must manually clean up using <html><code>async_status</code></html> with <html><code>mode: cleanup</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What do `async` and `poll` do together in a task?]]
* [[What is a practical use case for async with poll > 0?]]
* [[How do you run tasks asynchronously?]]
Q: Can async tasks run in check mode?
A: No. Asynchronous mode does not support check mode and will fail.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Can you force a specific task to always or never run in check mode?]]
* [[What is the major limitation of check mode?]]
* [[How do you run tasks asynchronously?]]
Q: What is the default poll interval?
A: Controlled by the <html><code>DEFAULT_POLL_INTERVAL</code></html> configuration setting (default is typically 15 seconds).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What do `async` and `poll` do together in a task?]]
* [[How do you run tasks asynchronously?]]
* [[Does `poll: 0` automatically clean up the async job cache file?]]
Q: What is a practical use case for async with poll > 0?
A: Long-running tasks that might exceed the SSH connection timeout, like large package installations. Ansible keeps polling the task status rather than holding the SSH connection open for the duration.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you fire-and-forget a long-running task?]]
* [[What does the `async` keyword do?]]
* [[How do you run tasks asynchronously?]]
Q: What is the default strategy, and what is its key characteristic?
A: <html><code>linear</code></html>. It waits for all hosts to complete a task before moving to the next task. This means a slow host delays all others.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does the `free` strategy differ from `linear`?]]
* [[What are strategy plugins?]]
* [[When would you use the `free` strategy?]]
Q: What is the difference between <html><code>free</code></html> and <html><code>host_pinned</code></html>?
A: <html><code>free</code></html> allows Ansible to interleave tasks across hosts (start task 3 on host A while host B is on task 1). <html><code>host_pinned</code></html> runs all tasks for a single host consecutively without interruption before moving to another host.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `host_pinned` strategy?]]
* [[Ansible strategy plugins: built-in options and defaults]]
* [[When would you use the `free` strategy?]]
Q: How do you fire-and-forget a long-running task?
A: Set <html><code>async: <timeout></code></html> and <html><code>poll: 0</code></html>. The task starts in the background and Ansible continues. You can check on it later with <html><code>async_status</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What do `async` and `poll` do together in a task?]]
* [[How do you check the status of a fire-and-forget async task?]]
* [[How do you run tasks asynchronously?]]
Q: What does the <html><code>gather_facts: false</code></html> optimization do?
A: It skips the automatic fact-gathering step at the beginning of a play. If your play doesn't use any host facts, this saves the time of running the setup module on every host (which can be significant with hundreds of hosts).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Selective fact gathering skips unnecessary system queries]]
* [[How do you disable fact gathering?]]
* [[How do you disable automatic fact gathering?]]
Q: What are tags used for?
A: Selective execution of tasks, roles, or plays. Run only tagged items with <html><code>--tags</code></html> or skip them with <html><code>--skip-tags</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `--tags tagged` mean?]]
* [[What are Ansible "tags"?]]
* [[What is `ansible_run_tags` and `ansible_skip_tags`?]]
Q: What are the special tags <html><code>always</code></html> and <html><code>never</code></html>?
A: Tasks tagged <html><code>always</code></html> run even when <html><code>--tags</code></html> is specified (unless explicitly skipped with <html><code>--skip-tags always</code></html>). Tasks tagged <html><code>never</code></html> only run when explicitly requested with <html><code>--tags never</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[If you specify both --tags and --skip-tags for the same tag, what happens?]]
* [[What are Ansible "tags"?]]
* [[What are tags used for?]]
Q: What does the <html><code>never</code></html> tag do?
A: Tasks tagged with <html><code>never</code></html> never run unless you explicitly request them with <html><code>--tags never</code></html> or another tag also applied to that task.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are Ansible "tags"?]]
* [[If you specify both --tags and --skip-tags for the same tag, what happens?]]
* [[What are tags used for?]]
Q: What does <html><code>--tags tagged</code></html> mean?
A: Run only tasks that have at least one tag (skip all untagged tasks). The <html><code>never</code></html> tag still overrides -- tagged tasks with <html><code>never</code></html> won't run.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[If you specify both --tags and --skip-tags for the same tag, what happens?]]
* [[What are tags used for?]]
* [[What are Ansible "tags"?]]
Q: Can tags be applied to roles?
A: Yes. Tags applied to a role import apply to all tasks within that role.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How can you use tags in Ansible Roles?]]
* [[What are tags used for?]]
* [[Can tags be inherited through `include_tasks`?]]
Q: Can you apply tags to roles, blocks, and imports?
A: Yes. Tags applied to <html><code>roles:</code></html>, <html><code>import_tasks</code></html>, <html><code>import_role</code></html>, or <html><code>block</code></html> are inherited by all tasks within. Tags on <html><code>include_tasks</code></html> apply only to the include task itself, NOT to the tasks inside.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How can you use tags in Ansible Roles?]]
* [[What is `include_role` vs `import_role`?]]
* [[What is the difference between `include_tasks` and `import_tasks`?]]
Q: Can tags be inherited through <html><code>include_tasks</code></html>?
A: Tags on <html><code>include_tasks</code></html> apply to the include statement itself, not to the tasks inside the included file. Use <html><code>import_tasks</code></html> for tag inheritance.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `include_tasks` and `import_tasks`?]]
* [[What is the fundamental difference between `import_*` and `include_*`?]]
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
Q: What are the five reserved tag names in Ansible?
A: <html><code>always</code></html>, <html><code>never</code></html>, <html><code>tagged</code></html>, <html><code>untagged</code></html>, and <html><code>all</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_run_tags` and `ansible_skip_tags`?]]
* [[How can you use tags in Ansible Roles?]]
* [[Name five ansible-lint rules.]]
Q: If you specify both --tags and --skip-tags for the same tag, what happens?
A: --skip-tags takes precedence. For example, <html><code>--tags tag1,tag3 --skip-tags tag3</code></html> runs only tag1 tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `--tags tagged` mean?]]
* [[What is `ansible_run_tags` and `ansible_skip_tags`?]]
* [[What are the special tags `always` and `never`?]]
Q: What Python class must every custom Ansible module import?
A: <html><code>AnsibleModule</code></html> from <html><code>ansible.module_utils.basic</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible.builtin.package` module?]]
* [[What are the two categories of Ansible modules?]]
* [[What is `ansible_python_interpreter`?]]
Q: How does a custom module return data to Ansible?
A: By calling <html><code>module.exit_json(**result)</code></html> for success or <html><code>module.fail_json(msg="error message", **result)</code></html> for failure. These methods print JSON to stdout and exit.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does `failed_when` work?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[Modules execute on targets; plugins run on the controller and extend Ansible]]
Q: What is the <html><code>argument_spec</code></html> in a custom module?
A: A dictionary defining all supported module parameters, their types, defaults, required status, choices, mutually_exclusive groups, and other validation constraints.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What valid `type` values can be used in argument_spec?]]
* [[What are the `_raw_params` in free-form modules?]]
Q: What valid <html><code>type</code></html> values can be used in argument_spec?
A: <html><code>str</code></html>, <html><code>list</code></html>, <html><code>dict</code></html>, <html><code>bool</code></html>, <html><code>int</code></html>, <html><code>float</code></html>, <html><code>path</code></html>, <html><code>raw</code></html>, <html><code>jsonarg</code></html>, <html><code>json</code></html>, <html><code>bytes</code></html>, <html><code>bits</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `argument_spec` in a custom module?]]
Q: What is the Ansiballz framework?
A: The mechanism Ansible uses to package Python modules for remote execution. It creates a zipfile containing the module file, imported <html><code>module_utils</code></html> files, and boilerplate code. This is Base64-encoded, wrapped in a small Python script, transferred to the remote host, and executed.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
* <html><code>training/library/topics/python-infra/trivia-compendium.md</code></html>
//Merged from 3 source atoms.//
''Related atoms''
* [[How are module arguments passed to the remote module under Ansiballz?]]
* [[What is the `ansible.builtin.package` module?]]
Q: How are module arguments passed to the remote module under Ansiballz?
A: The JSON arguments are included in the wrapper script. Before importing the module, the wrapper monkey-patches <html><code>_ANSIBLE_ARGS</code></html> in <html><code>basic.py</code></html>, which the module reads during initialization.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the Ansiballz framework?]]
* [[What internal arguments does Ansible automatically inject into every module call?]]
* [[What is the syntax of an ad-hoc command?]]
Q: What internal arguments does Ansible automatically inject into every module call?
A: <html><code>_ansible_no_log</code></html>, <html><code>_ansible_debug</code></html>, <html><code>_ansible_diff</code></html>, <html><code>_ansible_verbosity</code></html>, <html><code>_ansible_selinux_special_fs</code></html>, <html><code>_ansible_syslog_facility</code></html>, <html><code>_ansible_version</code></html>, <html><code>_ansible_module_name</code></html>, <html><code>_ansible_keep_remote_files</code></html>, <html><code>_ansible_socket</code></html>, <html><code>_ansible_shell_executable</code></html>, <html><code>_ansible_tmpdir</code></html>, <html><code>_ansible_remote_tmp</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How are module arguments passed to the remote module under Ansiballz?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[Ansible Modules]]
Q: Why does Ansible mark all strings returned by modules as "Unsafe"?
A: To prevent Jinja2 template injection attacks. Without this, malicious code embedded in module output could execute on the control node during template rendering.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
* [[Ansible `template` module]]
* [[What happens with `port: 22` vs `port: "22"` in Ansible YAML?]]
Q: What is <html><code>supports_check_mode</code></html> in module development?
A: A boolean parameter passed to <html><code>AnsibleModule()</code></html> indicating the module can run in check (dry-run) mode. When True, the module should report what would change without making actual changes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How can you detect check mode inside a playbook?]]
* [[Check mode simulates changes without executing destructive operations]]
* [[What is `check_mode: true` at the task level?]]
Q: What are the <html><code>mutually_exclusive</code></html>, <html><code>required_together</code></html>, <html><code>required_one_of</code></html>, <html><code>required_if</code></html>, and <html><code>required_by</code></html> parameters?
A: Validation constraints in <html><code>AnsibleModule()</code></html> that enforce relationships between arguments: mutually exclusive prevents using certain args together, required_together mandates certain args appear together, required_one_of needs at least one from a set, required_if requires args conditionally, and required_by specifies arg dependencies.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five ansible-lint rules.]]
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
* [[What does the `mandatory` filter do?]]
Q: What is the Module Replacer framework?
A: The older (legacy) module packaging mechanism, primarily used for PowerShell modules. It performs string substitution, replacing patterns like <html><code>from ansible.module_utils.MOD_LIB_NAME import *</code></html> with actual file contents.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How are Windows modules different from Linux modules internally?]]
* [[What is the `ansible.builtin.package` module?]]
Q: Where should custom filter plugins be placed?
A: In a <html><code>filter_plugins/</code></html> directory adjacent to the playbook, inside a role's <html><code>filter_plugins/</code></html> directory, in a collection's <html><code>plugins/filter/</code></html> directory, or in a path configured in <html><code>ansible.cfg</code></html> under <html><code>DEFAULT_FILTER_PLUGIN_PATH</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you create a custom Jinja2 filter for Ansible?]]
* [[What must a filter plugin Python file contain?]]
* [[What is the standard directory structure of an Ansible role?]]
Q: What must a filter plugin Python file contain?
A: A <html><code>FilterModule</code></html> class with a <html><code>filters()</code></html> method that returns a dictionary mapping filter names to Python callables.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where should custom filter plugins be placed?]]
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[What is the relationship between Jinja2's built-in filters and Ansible's filters?]]
Q: How are lookup plugins different from filter plugins in how they execute?
A: Lookup plugins run on the control node (not the remote host), pull data from external sources, and are expected to return lists. Filter plugins transform data inline within Jinja2 expressions.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are lookup plugins?]]
* [[What is the difference between a lookup and a filter?]]
* [[What is the `lookup` plugin?]]
Q: What base class do lookup plugins inherit from?
A: <html><code>LookupBase</code></html> from <html><code>ansible.plugins.lookup</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a lookup plugin in Ansible?]]
* [[What is the `lookup` plugin?]]
* [[What are lookup plugins?]]
Q: What method must a lookup plugin implement?
A: The <html><code>run(self, terms, variables=None, **kwargs)</code></html> method.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are lookup plugins?]]
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[What is a lookup plugin in Ansible?]]
Q: How do you invoke a lookup plugin in a playbook?
A: Using <html><code>lookup('plugin_name', 'arg')</code></html> or the <html><code>with_<plugin_name></code></html> loop syntax, or <html><code>query('plugin_name', 'arg')</code></html> which always returns a list.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a lookup plugin in Ansible?]]
* [[What base class do lookup plugins inherit from?]]
* [[Lookups read external data into variables during playbook execution]]
Q: What is the difference between <html><code>lookup()</code></html> and <html><code>query()</code></html> in Ansible?
A: <html><code>query()</code></html> always returns a list. <html><code>lookup()</code></html> returns a comma-separated string by default (unless <html><code>wantlist=True</code></html> is passed). <html><code>query()</code></html> is the preferred modern form.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What does `wantlist=True` do in a lookup?]]
* [[What is a lookup plugin in Ansible?]]
* [[What is the difference between a lookup and a filter?]]
Q: What is the <html><code>query</code></html> function, and how does it differ from <html><code>lookup</code></html>?
A: <html><code>query</code></html> (or <html><code>q</code></html>) always returns a list. <html><code>lookup</code></html> returns a comma-separated string by default. <html><code>query('file', '/etc/hosts')</code></html> returns a list with one element; <html><code>lookup('file', '/etc/hosts')</code></html> returns a string.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: How many stdout-type callback plugins can be active at once?
A: Only one. The <html><code>stdout_callback</code></html> setting in ansible.cfg controls which one is active. Other non-stdout callback plugins can be enabled simultaneously.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the two categories of callback plugins?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What is an Ansible callback whitelist?]]
Q: What are the two categories of callback plugins?
A: <html><code>stdout</code></html> callbacks (control terminal output; only one active at a time) and <html><code>notification</code></html>/<html><code>aggregate</code></html> callbacks (multiple can be active simultaneously for logging, metrics, etc.).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five notable callback plugins.]]
* [[What is a callback plugin?]]
* [[What class attributes must a callback plugin define?]]
Q: What is the difference between stdout callbacks and non-stdout callbacks?
A: Only ONE stdout callback can be active (it controls terminal output). Multiple non-stdout callbacks can run simultaneously for logging, notifications, or metrics.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How many stdout-type callback plugins can be active at once?]]
* [[What is a callback plugin?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
Q: Name some built-in callback plugins.
A: <html><code>default</code></html> (standard output), <html><code>minimal</code></html>, <html><code>json</code></html>, <html><code>yaml</code></html>, <html><code>debug</code></html>, <html><code>timer</code></html>, <html><code>profile_tasks</code></html>, <html><code>profile_roles</code></html>, <html><code>log_plays</code></html>, <html><code>mail</code></html>, <html><code>slack</code></html>, <html><code>splunk</code></html>, <html><code>grafana_annotations</code></html>, <html><code>cgroup_perf_recap</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a callback plugin?]]
* [[What class attributes must a callback plugin define?]]
* [[What is callback plugin `profile_tasks`?]]
Q: Name five notable callback plugins.
A: (1) <html><code>default</code></html> -- the standard verbose output; (2) <html><code>minimal</code></html> -- super-brief output (task name + result); (3) <html><code>json</code></html> -- JSON-formatted output for machine parsing; (4) <html><code>yaml</code></html> -- YAML-formatted output; (5) <html><code>timer</code></html>/<html><code>profile_tasks</code></html> -- displays per-task and total execution timing.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is callback plugin `profile_tasks`?]]
* [[What are the two categories of callback plugins?]]
* [[What is a callback plugin?]]
Q: What method prefix do v2 callback plugin methods use?
A: <html><code>v2_</code></html> -- for example, <html><code>v2_runner_on_ok</code></html>, <html><code>v2_runner_on_failed</code></html>, <html><code>v2_playbook_on_start</code></html>, <html><code>v2_runner_on_async_poll</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five notable callback plugins.]]
* [[What class attributes must a callback plugin define?]]
* [[What are the two categories of callback plugins?]]
Q: What class attributes must a callback plugin define?
A: <html><code>CALLBACK_VERSION</code></html>, <html><code>CALLBACK_TYPE</code></html> (stdout, notification, or aggregate), and <html><code>CALLBACK_NAME</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the two categories of callback plugins?]]
* [[Name some built-in callback plugins.]]
* [[What is a callback plugin?]]
Q: What is the default connection plugin in Ansible?
A: <html><code>ssh</code></html> (using OpenSSH). Prior to Ansible 2.0, paramiko was the default.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are connection plugins?]]
* [[What connection type does ansible-pull use?]]
* [[Connection plugins determine how Ansible communicates with targets]]
Q: When would you use the <html><code>local</code></html> connection plugin?
A: When running tasks on the [[Ansible control node]] itself (localhost). It bypasses SSH entirely and executes directly. Used with <html><code>connection: local</code></html> or <html><code>delegate_to: localhost</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_connection` and where can it be set?]]
* [[Connection plugins determine how Ansible communicates with targets]]
* [[What are connection plugins?]]
Q: What is the <html><code>network_cli</code></html> connection plugin used for?
A: Connecting to network devices (routers, switches, firewalls) over SSH using a persistent CLI session. It loads platform-specific Terminal plugins based on <html><code>ansible_network_os</code></html> to handle prompts, privilege escalation, and command execution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are connection plugins?]]
* [[What is the `ansible_connection` variable set to for network devices?]]
* [[What is `ansible_connection` and where can it be set?]]
Q: What Python library does the <html><code>netconf</code></html> connection plugin use under the hood?
A: The ncclient Python library, which provides a NETCONF client implementation for initiating NETCONF sessions over SSH.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What connection plugin is used for network devices?]]
* [[What is the `network_cli` connection plugin used for?]]
Q: What is the <html><code>httpapi</code></html> connection plugin?
A: A plugin for communicating with devices that expose HTTP(S) APIs. It uses HTTPAPI plugins as adapters for specific vendor APIs (e.g., Arista EOS eAPI, F5 BIG-IP REST). Useful for devices where SSH-based management is limited.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What connection plugin is used for network devices?]]
* [[What is the `uri` module?]]
* [[What is the difference between `network_cli` and `httpapi` for network devices?]]
Q: What is the <html><code>psrp</code></html> connection plugin, and how does it differ from <html><code>winrm</code></html>?
A: PSRP (PowerShell Remoting Protocol) is an alternative to WinRM for managing Windows hosts. It uses the same underlying protocol but is implemented in Python using the pypsrp library, offering better performance and more reliable stream handling than the winrm plugin.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What Python packages are required on the control node for WinRM?]]
* [[What protocol does Ansible use to manage Windows hosts?]]
Q: Can you use more than one connection plugin per host in a single play?
A: No. Only one connection plugin can be active per host at a time. However, you can use <html><code>delegate_to</code></html> with a different connection type for specific tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are connection plugins?]]
* [[Name all the major connection plugin types in Ansible.]]
* [[Connection plugins determine how Ansible communicates with targets]]
Q: What is <html><code>ansible_connection</code></html> and where can it be set?
A: It specifies which connection plugin to use for a host. It can be set in inventory (per host or group), playbook vars, or command line. Examples: ssh, local, docker, network_cli, winrm.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What port does Ansible use by default for SSH connections?]]
* [[When would you use the `local` connection plugin?]]
* [[What is ansible.cfg?]]
Q: What is the <html><code>ansible_connection</code></html> variable set to for network devices?
A: Typically <html><code>ansible.netcommon.network_cli</code></html>, <html><code>ansible.netcommon.netconf</code></html>, or <html><code>ansible.netcommon.httpapi</code></html>, depending on the platform and API type.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What collection provides platform-independent network modules?]]
* [[What is the `network_cli` connection plugin used for?]]
* [[What are the three main connection types for network automation?]]
Q: What is a lookup plugin in Ansible?
A: A plugin that retrieves data from external sources during playbook execution. Lookups run on the control node (not on managed hosts) and return data to the playbook.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you invoke a lookup plugin in a playbook?]]
* [[What base class do lookup plugins inherit from?]]
* [[What are lookup plugins?]]
Q: What is the difference between a lookup and a filter?
A: A lookup fetches data from an external source (file, URL, API) and runs on the control node. A filter transforms data that already exists in the playbook (string manipulation, type conversion, etc.).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[What is the difference between `lookup()` and `query()` in Ansible?]]
* [[Lookups read external data into variables during playbook execution]]
Q: What does <html><code>wantlist=True</code></html> do in a lookup?
A: Forces the lookup to return a list instead of a comma-separated string. <html><code>lookup('file', '/etc/hosts', wantlist=True)</code></html> is equivalent to <html><code>query('file', '/etc/hosts')</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `lookup()` and `query()` in Ansible?]]
Q: What is a callback plugin?
A: A plugin that hooks into Ansible's event system to modify output, perform logging, send notifications, or track metrics. The standard terminal output you see is itself a callback plugin.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What are the two categories of callback plugins?]]
* [[How do you enable a callback plugin?]]
Q: What callback plugin would you use to profile task execution times?
A: <html><code>profile_tasks</code></html> -- shows execution time for each task. Also <html><code>profile_roles</code></html> for per-role timing and <html><code>timer</code></html> for total playbook time.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is callback plugin `timer`?]]
* [[Name five notable callback plugins.]]
Q: What callback plugin profiles memory usage of Ansible tasks?
A: <html><code>cgroup_memory_recap</code></html> -- uses cgroups to measure maximum memory usage per task and overall.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[How do you enable a callback plugin?]]
* [[How many stdout-type callback plugins can be active at once?]]
Q: What is Ansible Tower?
A: A web-based enterprise solution (now called Red Hat Ansible Automation Platform) providing a UI, RBAC, job scheduling, dashboards, and REST API for managing Ansible automation.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you create and manage inventories in Ansible Tower?]]
* [[What is the relationship between Ansible Tower and Automation Controller?]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
Q: What is AWX?
A: The open-source upstream project for Ansible Tower. Ideal for development and testing; lacks enterprise support and hardening.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do AWX and Red Hat Ansible Automation Platform differ?]]
* [[Name three enterprise features that Ansible Tower/Controller has that AWX lacks.]]
* [[AWX, Ansible Tower, and Ansible Automation Platform explained]]
Q: How do AWX and Red Hat Ansible Automation Platform differ?
A: AWX is free/open-source for dev/test. Ansible Automation Platform (AAP) is the commercial, enterprise-grade solution with official Red Hat support, SLAs, security hardening, and additional components like Automation Hub and Event-Driven Ansible.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is AWX?]]
* [[Name three enterprise features that Ansible Tower/Controller has that AWX lacks.]]
* [[Red Hat open-sourced AWX while selling Ansible Tower as a commercial product]]
Q: What features does Ansible Tower/AWX provide?
A: Web dashboard, role-based access control (RBAC), job scheduling, workflow orchestration, credential management, real-time job monitoring, REST API, activity logging, audit trails, integration with Git/SCM, and notifications.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is AWX?]]
* [[What are the key features of Ansible?]]
* [[How do you create and manage inventories in Ansible Tower?]]
Q: Name three enterprise features that Ansible Tower/Controller has that AWX lacks.
A: (1) Red Hat SLA-backed support with guaranteed security vulnerability response; (2) Supported, tested upgrade migration paths between versions; (3) ISV (Independent Software Vendor) compatibility certifications. AWX is community-supported only.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do AWX and Red Hat Ansible Automation Platform differ?]]
* [[What is AWX?]]
* [[Red Hat open-sourced AWX while selling Ansible Tower as a commercial product]]
Q: How do you implement RBAC in Ansible Tower?
A: Create users and teams, assign roles (Admin, User, Auditor) at global or object level, and set permissions on projects, inventories, job templates, and credentials.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you create and manage inventories in Ansible Tower?]]
* [[What features does Ansible Tower/AWX provide?]]
* [[What is Ansible Tower?]]
Q: What is a Workflow in Tower/AWX?
A: A chain of job templates linked by success/failure/always conditions, enabling multi-step automation pipelines.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the Tower/AWX REST API used for?]]
* [[What is a Workflow Job Template?]]
* [[What features does Ansible Tower/AWX provide?]]
Q: What is the Tower/AWX REST API used for?
A: Programmatic access to launch jobs, manage inventory, check job status, and integrate Tower with CI/CD tools and external systems.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Workflow in Tower/AWX?]]
* [[What features does Ansible Tower/AWX provide?]]
* [[AWX, Ansible Tower, and Ansible Automation Platform explained]]
Q: What is a Job Template in AWX/automation controller?
A: A definition that combines a playbook, inventory, credentials, and configuration into a reusable, launchable unit.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is a Workflow Job Template?]]
* [[What is a Workflow in Tower/AWX?]]
* [[What are Surveys in AWX/automation controller?]]
Q: What is a Workflow Job Template?
A: A template that chains multiple job templates together with conditional logic (on success, on failure, always), enabling complex multi-step automation pipelines.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Workflow in Tower/AWX?]]
* [[What is a Job Template in AWX/automation controller?]]
* [[Can rulebooks call Ansible Automation Platform job templates?]]
Q: What are Surveys in AWX/automation controller?
A: Interactive forms that prompt users for input when launching a job template, passing responses as extra variables. They support text, passwords, dropdowns, multiple choice, integers, and floats.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Job Template in AWX/automation controller?]]
* [[What is Ansible Tower Surveys, and how do they work?]]
* [[What happens if you use `vars_prompt` in Ansible Tower/Controller?]]
Q: What is the automation controller REST API used for?
A: Programmatic interaction with all controller features: launching jobs, managing inventory, credentials, templates, users, and organizations. Enables CI/CD integration.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the Tower/AWX REST API used for?]]
* [[What is a Job Template in AWX/automation controller?]]
Q: What is automation mesh?
A: A scalable overlay network in AAP that distributes automation execution across multiple nodes, including hop nodes (relays) and execution nodes, enabling automation across network boundaries.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are execution nodes vs hop nodes in automation mesh?]]
* [[What did Ansible 2.5 introduce that changed how network automation worked?]]
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
Q: What are execution nodes vs hop nodes in automation mesh?
A: Execution nodes run Ansible playbooks. Hop nodes relay traffic between the controller and execution nodes without running playbooks, useful for crossing network boundaries.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is automation mesh?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
Q: What is Instance Groups in AWX?
A: A way to group execution capacity, allowing specific job templates to run on specific sets of instances for resource isolation or geographic distribution.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What is a Smart Inventory?
A: A dynamic inventory in automation controller defined by a filter query against existing inventories. It automatically updates as source inventories change.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the two types of inventory?]]
* [[What is an Ansible inventory?]]
* [[What are inventory plugins?]]
Q: What are the key sections in an <html><code>execution-environment.yml</code></html> file?
A: <html><code>version</code></html> (schema version), <html><code>build_arg_defaults</code></html> (base image settings), <html><code>dependencies</code></html> (galaxy requirements, Python requirements, system packages), <html><code>additional_build_steps</code></html> (prepend/append custom build commands), and <html><code>images</code></html> (base and builder image references).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What tool is used to build Execution Environments?]]
* [[What is a requirements.yml file for Galaxy?]]
* [[What is `ansible-builder`?]]
Q: Why do Execution Environments exist when Python virtual environments (venvs) already exist?
A: Virtual environments only isolate Python packages. They cannot bundle system-level tools like <html><code>openssh-clients</code></html>, vendor CLI utilities, or non-Python dependencies. EEs wrap everything into a container so the runtime is identical everywhere it executes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What is the default base image used by ansible-builder?
A: The default base image is the Red Hat-provided <html><code>ee-minimal-rhel8</code></html> or the community <html><code>quay.io/ansible/ansible-runner:latest</code></html>, depending on the version and configuration.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-builder`?]]
* [[What is the "golden image" pattern using Ansible?]]
* [[What was "ansible-base" and when did it appear?]]
Q: How do you specify which Ansible collections to include in an EE?
A: Add them to a <html><code>requirements.yml</code></html> file referenced in the <html><code>dependencies.galaxy</code></html> field of <html><code>execution-environment.yml</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the galaxy.yml file in a collection?]]
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[What is a requirements.yml file for Galaxy?]]
Q: What is the difference between a Decision Environment and an Execution Environment in Event-Driven Ansible?
A: A Decision Environment handles event logic -- listening for events, filtering, and evaluating conditions in rulebooks. An Execution Environment runs the actual Ansible playbooks triggered when a condition is matched.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Decision Environment?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
* [[What happens after a rulebook condition matches an event?]]
Q: What are the two display modes in ansible-navigator?
A: <html><code>stdout</code></html> mode (output goes directly to terminal, similar to traditional ansible-playbook) and <html><code>interactive</code></html> mode (TUI with navigable, drill-down views of playbook results).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[ansible-navigator: modern replacement for ansible-playbook]]
* [[What subcommand in ansible-navigator lists available collections inside an EE?]]
* [[What configuration file does ansible-navigator use?]]
Q: What configuration file does ansible-navigator use?
A: <html><code>ansible-navigator.yml</code></html> (or <html><code>.ansible-navigator.yml</code></html>), placed in the project directory or home directory. It can also read from <html><code>ANSIBLE_NAVIGATOR_CONFIG</code></html> environment variable.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What subcommand in ansible-navigator lists available collections inside an EE?]]
* [[How do you run ansible-navigator without an Execution Environment (in local mode)?]]
* [[Where is the default inventory file located?]]
Q: How do you run ansible-navigator without an Execution Environment (in local mode)?
A: Set <html><code>execution-environment.enabled: false</code></html> in <html><code>ansible-navigator.yml</code></html> or pass <html><code>--execution-environment false</code></html> on the command line.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What configuration file does ansible-navigator use?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
* [[ansible-navigator: modern replacement for ansible-playbook]]
Q: What subcommand in ansible-navigator lists available collections inside an EE?
A: <html><code>ansible-navigator collections</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `COLLECTIONS_PATHS` configuration?]]
* [[What configuration file does ansible-navigator use?]]
* [[What command lists all hosts in an inventory?]]
Q: How do you inspect the contents of an EE image using ansible-navigator?
A: <html><code>ansible-navigator images</code></html> shows available EE images and lets you drill into their Python packages, Ansible collections, and system packages.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[ansible-navigator: modern replacement for ansible-playbook]]
* [[What subcommand in ansible-navigator lists available collections inside an EE?]]
* [[What is an Ansible Execution Environment (EE)?]]
Q: What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?
A: (1) Automation Controller (formerly Ansible Tower) -- the web UI and API for running playbooks; (2) Automation Hub -- a repository for certified/validated collections; (3) Event-Driven Ansible (EDA) Controller -- event-driven automation triggers; (4) Ansible Lightspeed with IBM watsonx Code Assistant -- AI-powered playbook generation; (5) Platform Gateway -- unified web UI consolidating all components (introduced in AAP 2.5).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the main components of Ansible's architecture?]]
* [[What is the Ansible Tower rebrand name?]]
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
Q: What was the approximate annual cost of Ansible Tower licensing before the AAP rebrand?
A: Standard licensing ranged from approximately $13,000/year to $17,500/year for up to 100 managed nodes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[What is the Ansible Tower rebrand name?]]
* [[What year did Ansible Tower (the commercial UI product) first appear?]]
Q: What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?
A: Automation Hub is Red Hat's curated repository of certified and validated Ansible collections for AAP subscribers. Galaxy is the free community repository. Hub content is tested, supported, and signed by Red Hat; Galaxy content is community-maintained with no support guarantees.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[What year did Ansible Galaxy launch?]]
* [[What is the relationship between ansible-core and the ansible package?]]
Q: What is Private Automation Hub?
A: A self-hosted instance of Automation Hub that organizations deploy internally to host their own custom collections, curate approved content, and serve as a proxy/mirror for certified collections.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
* [[Ansible: agentless IT automation tool]]
Q: What is the structure of an EDA rulebook?
A: A rulebook contains three main components: (1) sources -- where events come from (webhooks, Kafka, alertmanager, etc.); (2) rules -- conditions evaluated against incoming events; (3) actions -- what to do when conditions match (run a playbook, module, or trigger a workflow in Controller).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happens after a rulebook condition matches an event?]]
* [[What command runs a rulebook?]]
* [[What is Event-Driven Ansible (EDA) and when was it introduced?]]
Q: What are the key parts of an EDA rulebook?
A: Sources (provide events), rules (check conditions), and actions (trigger automation). Together they form "if this, then that" logic.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the three main components of an Ansible rulebook?]]
* [[What happens after a rulebook condition matches an event?]]
* [[What is Event-Driven Ansible (EDA) and when was it introduced?]]
Q: What major AAP 2.5 feature unified the user experience across components?
A: The Platform Gateway introduced a single unified web UI that consolidates Automation Controller, Automation Hub, and EDA Controller interfaces with centralized authentication and management.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[What shift in AAP 2.5 changed how the platform is deployed?]]
* [[What is automation mesh?]]
Q: What shift in AAP 2.5 changed how the platform is deployed?
A: AAP 2.5 introduced a containerized installer using Podman, while the traditional RPM-based installer was deprecated, signaling a move toward container-native deployments.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What module creates and manages Podman containers?]]
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
Q: What are the three main components of an Ansible rulebook?
A: Sources (define event origins like webhooks, Kafka, Alertmanager), Rules (define conditions to match against events), and Actions (specify what happens when conditions are met, like <html><code>run_playbook</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the main components of Ansible's architecture?]]
* [[What command runs a rulebook?]]
* [[What are Ansible "playbooks"?]]
Q: What Python and Java versions does ansible-rulebook require?
A: Python 3.8+ and Java 17 (OpenJDK).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
* [[What Python version does ansible-core 2.17+ require on managed nodes?]]
* [[What command runs a rulebook?]]
Q: Name three event source plugins in the <html><code>ansible.eda</code></html> collection.
A: <html><code>ansible.eda.webhook</code></html>, <html><code>ansible.eda.kafka</code></html>, <html><code>ansible.eda.alertmanager</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Event-Driven Ansible (EDA) and when was it introduced?]]
* [[What year was Event-Driven Ansible (EDA) first introduced?]]
* [[What are the three main components of an Ansible rulebook?]]
Q: How does an event payload get passed to a triggered playbook?
A: Through the <html><code>event</code></html> variable, which contains the full event payload accessible in playbook tasks (e.g., <html><code>event.payload.message</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What happens after a rulebook condition matches an event?]]
* [[Playbooks compose idempotent tasks with handlers for change notification]]
* [[What are the three main components of an Ansible rulebook?]]
Q: What happens after a rulebook condition matches an event?
A: The specified action executes -- typically <html><code>run_playbook</code></html>, which launches an Ansible playbook with the event data available as extra variables.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does an event payload get passed to a triggered playbook?]]
* [[What command runs a rulebook?]]
* [[What are Ansible "playbooks"?]]
Q: Can rulebooks call Ansible Automation Platform job templates?
A: Yes. EDA integrates with AAP's automation controller, allowing rulebooks to trigger job templates via the <html><code>run_job_template</code></html> action.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command runs a rulebook?]]
* [[What are Ansible "playbooks"?]]
* [[What is a Job Template in AWX/automation controller?]]
Q: What is Ansible Lightspeed?
A: An AI-powered automation content creation tool from Red Hat, integrated into VS Code and Ansible Automation Platform, that generates Ansible task code from natural language descriptions.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What year was Ansible Lightspeed announced?]]
* [[When was Ansible Lightspeed generally available?]]
Q: What AI model powers Ansible Lightspeed?
A: IBM watsonx Code Assistant, trained on Ansible community content and code patterns.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What year was Ansible Lightspeed announced?]]
* [[What is BYOM in the context of Ansible Lightspeed?]]
* [[When was Ansible Lightspeed generally available?]]
Q: What is the Ansible Lightspeed "intelligent assistant"?
A: A generative AI chat assistant embedded within AAP that helps administrators install, configure, maintain, and optimize Ansible Automation Platform, and helps operators troubleshoot automation jobs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[What year was Ansible Lightspeed announced?]]
* [[What is the etymology of the word "ansible"?]]
Q: What is BYOM in the context of Ansible Lightspeed?
A: "Bring Your Own Model" -- introduced in AAP 2.6, it allows customers to use LLM providers other than IBM watsonx, including Red Hat AI, OpenAI, and Azure OpenAI.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the Ansible Lightspeed "intelligent assistant"?]]
* [[What is Ansible Lightspeed?]]
* [[What AI model powers Ansible Lightspeed?]]
Q: What controversy surrounds Ansible Lightspeed and the community?
A: The LLM was trained on community-contributed code, and some contributors felt they wouldn't receive credit despite having built and shared that code publicly.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Before Ansible 2.10, how was all community-contributed content structured?]]
* [[What year was Ansible Lightspeed announced?]]
* [[What is Ansible Lightspeed?]]
Q: What are the key phases in a Molecule test sequence?
A: dependency, cleanup, destroy, syntax, create, prepare, converge, idempotence, side_effect, verify, cleanup, destroy. This is the default sequence; it can be customized.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the "idempotence" test phase in Molecule?]]
* [[What is the `converge` step in Molecule?]]
* [[What is a Molecule scenario?]]
Q: What is the default driver in modern Molecule?
A: The <html><code>delegated</code></html> driver (previously called <html><code>default</code></html>). Podman and Docker drivers are provided via separate packages like <html><code>molecule-plugins</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What drivers does Molecule support for creating test instances?]]
* [[What collection provides Podman modules and connection plugins?]]
* [[What module creates and manages Podman containers?]]
Q: What is the <html><code>converge</code></html> step in Molecule?
A: It runs the role or playbook under test against the test instance. It is the core "apply the automation" step.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What Molecule command runs only the verify step without re-converging?]]
* [[What are the key phases in a Molecule test sequence?]]
* [[What is the "idempotence" test phase in Molecule?]]
Q: What does the <html><code>idempotence</code></html> step verify?
A: It runs the converge playbook a second time and checks that no tasks report "changed." This validates that the role is idempotent.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "idempotence" test phase in Molecule?]]
* [[What is idempotency?]]
* [[What are idempotency issues in infrastructure automation and how are they avoided?]]
Q: What is a Molecule scenario?
A: A scenario is a self-contained test suite within a role or collection. Each scenario has its own <html><code>molecule.yml</code></html>, converge playbook, and verify playbook. A single role can have multiple scenarios testing different configurations.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where does Molecule store scenario configuration?]]
* [[How do you test a specific scenario when multiple exist?]]
* [[What are the key phases in a Molecule test sequence?]]
Q: What verifiers does Molecule support?
A: Ansible (default, using assert/stat/command tasks in a verify.yml playbook), testinfra (Python-based infrastructure testing), and third-party plugins like InSpec.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Molecule made test-driven Ansible development practical]]
* [[What drivers does Molecule support for creating test instances?]]
* [[Playbook testing combines linting, role integration tests, and idempotency checks]]
Q: Where does Molecule store scenario configuration?
A: In <html><code>molecule/<scenario_name>/molecule.yml</code></html> within the role directory.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Molecule scenario?]]
* [[What verifiers does Molecule support?]]
* [[What is the default verifier in Molecule 6+?]]
Q: What Molecule command runs only the verify step without re-converging?
A: <html><code>molecule verify</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `converge` step in Molecule?]]
* [[What is the "idempotence" test phase in Molecule?]]
* [[What are the key phases in a Molecule test sequence?]]
Q: How do you test a specific scenario when multiple exist?
A: <html><code>molecule test -s <scenario_name></code></html>
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a Molecule scenario?]]
* [[What are the key phases in a Molecule test sequence?]]
* [[What is the "idempotence" test phase in Molecule?]]
Q: What are the six ansible-lint profiles in order from least to most strict?
A: min, basic, moderate, safety, shared, production. Each profile includes all rules from profiles below it.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is ansible-lint?]]
* [[What does the `production` lint profile add on top of `shared`?]]
* [[What is the `shared` lint profile intended for?]]
Q: What does the <html><code>min</code></html> lint profile enforce?
A: Only rules that prevent fatal errors: <html><code>internal-error</code></html>, <html><code>load-failure</code></html>, <html><code>parser-error</code></html>, <html><code>syntax-check</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `safety` lint profile add?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What is the `shared` lint profile intended for?]]
Q: What does the <html><code>safety</code></html> lint profile add?
A: Rules that avoid non-determinant outcomes or security concerns: <html><code>avoid-implicit</code></html>, <html><code>latest</code></html>, <html><code>package-latest</code></html>, <html><code>risky-file-permissions</code></html>, <html><code>risky-octal</code></html>, <html><code>risky-shell-pipe</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `min` lint profile enforce?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What is the `shared` lint profile intended for?]]
Q: What is the <html><code>shared</code></html> lint profile intended for?
A: Content creators publishing to galaxy.ansible.com, automation-hub, or private instances. It adds rules like <html><code>ignore-errors</code></html>, <html><code>no-changed-when</code></html>, <html><code>no-handler</code></html>, <html><code>meta-incorrect</code></html>, and <html><code>meta-no-tags</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is ansible-lint?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What configuration file does ansible-lint use?]]
Q: What does the <html><code>production</code></html> lint profile add on top of <html><code>shared</code></html>?
A: Rules for inclusion in Ansible Automation Platform as validated or certified content, including <html><code>fqcn</code></html> (require fully qualified collection names) and <html><code>sanity</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `fqcn` lint rule require?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What configuration file does ansible-lint use?]]
Q: What rule does <html><code>no-changed-when</code></html> enforce?
A: Tasks using <html><code>command</code></html>, <html><code>shell</code></html>, <html><code>raw</code></html>, or <html><code>script</code></html> modules must include a <html><code>changed_when</code></html> condition to prevent always reporting "changed."
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Customize task failure and change status with failed_when and changed_when]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Check mode simulates changes without executing destructive operations]]
Q: What does the <html><code>fqcn</code></html> lint rule require?
A: That all module references use Fully Qualified Collection Names (e.g., <html><code>ansible.builtin.copy</code></html> instead of just <html><code>copy</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `production` lint profile add on top of `shared`?]]
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[Name five ansible-lint rules.]]
Q: How do you select a specific lint profile on the command line?
A: <html><code>ansible-lint --profile production playbook.yml</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What configuration file does ansible-lint use?]]
* [[What is ansible-lint?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
Q: What configuration file does ansible-lint use?
A: <html><code>.ansible-lint</code></html> (YAML format) in the project root directory.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you select a specific lint profile on the command line?]]
* [[What is ansible-lint?]]
* [[Name five ansible-lint rules.]]
Q: What is the "idempotence" test phase in Molecule?
A: Molecule runs the converge playbook a second time and checks that zero tasks report "changed." If any task reports changed on the second run, the idempotence test fails -- indicating the role is not properly idempotent.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `idempotence` step verify?]]
* [[What are the key phases in a Molecule test sequence?]]
* [[What is the `converge` step in Molecule?]]
Q: What drivers does Molecule support for creating test instances?
A: Docker (default), Podman, Delegated (custom), and community-maintained drivers for Vagrant, EC2, GCE, Azure, DigitalOcean, LXD, and more.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the default driver in modern Molecule?]]
* [[What verifiers does Molecule support?]]
* [[Molecule made test-driven Ansible development practical]]
Q: What is the default verifier in Molecule 6+?
A: Ansible itself (using assert/debug tasks). Testinfra (Python-based) was the previous default and is now optional.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Molecule made test-driven Ansible development practical]]
* [[Playbook testing combines linting, role integration tests, and idempotency checks]]
* [[Molecule: Ansible role testing framework]]
Q: Name five ansible-lint rules.
A: (1) <html><code>yaml[truthy]</code></html> -- flags bare yes/no booleans; (2) <html><code>no-changed-when</code></html> -- flags command/shell tasks without changed_when; (3) <html><code>name[missing]</code></html> -- flags tasks without names; (4) <html><code>fqcn[action-core]</code></html> -- flags non-FQCN module names; (5) <html><code>deprecated-module</code></html> -- flags usage of deprecated modules.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What ansible-lint rule catches boolean value problems in YAML?]]
* [[What configuration file does ansible-lint use?]]
* [[What does the `fqcn` lint rule require?]]
Q: What is the <html><code>no_log</code></html> lint rule about?
A: It warns when tasks handle potentially sensitive data (passwords, tokens) without <html><code>no_log: true</code></html> to prevent secrets from appearing in logs.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `no_log: true` do?]]
* [[What is the `no_log: true` directive?]]
* [[What does `no_log: true` do, and how does it relate to Vault?]]
Q: How does Ansible manage network devices?
A: Using network-specific modules (ios_config, junos_config, eos_config, nxos_config) and connection plugins (network_cli, netconf, httpapi).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_network_os`, and why is it critical for network automation?]]
* [[What did Ansible 2.5 introduce that changed how network automation worked?]]
* [[What collection provides platform-independent network modules?]]
Q: What connection plugin is used for network devices?
A: <html><code>network_cli</code></html> for CLI-based devices, <html><code>netconf</code></html> for NETCONF-enabled devices, <html><code>httpapi</code></html> for API-based devices.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `httpapi` connection plugin?]]
* [[What Python library does the `netconf` connection plugin use under the hood?]]
* [[What is the `ansible_connection` variable set to for network devices?]]
Q: How do you backup router configurations with Ansible?
A: Use <html><code>ios_config</code></html> module with <html><code>backup: yes</code></html> parameter. Backup files are stored in a backup directory.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-config dump`?]]
* [[Configuring Ansible for Network Automation]]
* [[What configuration file does ansible-navigator use?]]
Q: What are the three main connection types for network automation?
A: <html><code>ansible.netcommon.network_cli</code></html> (CLI over SSH), <html><code>ansible.netcommon.netconf</code></html> (NETCONF over SSH), and <html><code>ansible.netcommon.httpapi</code></html> (REST/HTTP APIs).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible support network automation?]]
* [[What is the `ansible_connection` variable set to for network devices?]]
* [[What did Ansible 2.5 introduce that changed how network automation worked?]]
Q: Where do network modules execute -- on the control node or managed node?
A: On the control node. Unlike Linux automation, network modules do not execute on the network device itself because most network devices cannot run Python.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible manage network devices?]]
* [[What is `ansible_network_os`, and why is it critical for network automation?]]
* [[How does Ansible support network automation?]]
Q: How does privilege escalation work on network devices like Cisco IOS?
A: Using <html><code>ansible_become: yes</code></html>, <html><code>ansible_become_method: enable</code></html>, and <html><code>ansible_become_password: <enable_password></code></html>. This tells Ansible to enter enable mode after connecting.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[What is the `become_method` setting and what values does it support?]]
* [[What happens when you apply `become: true` with the `local` connection?]]
Q: What are network resource modules?
A: Modules that manage specific network resource configurations (interfaces, VLANs, ACLs, etc.) through a declarative state-based model with states like <html><code>merged</code></html>, <html><code>replaced</code></html>, <html><code>overridden</code></html>, <html><code>deleted</code></html>, and <html><code>gathered</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `gathered` state in network resource modules?]]
* [[What collection provides platform-independent network modules?]]
Q: What are "resource modules" in network automation?
A: Modules that manage a specific network resource declaratively (e.g., ios_interfaces, nxos_vlans, eos_bgp_global). They accept a desired state and determine the necessary commands to achieve it, providing true idempotency for network configurations.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `gathered` state in network resource modules?]]
* [[Where do network modules execute -- on the control node or managed node?]]
* [[What is `cli_command` vs platform-specific modules (e.g., ios_command)?]]
Q: What is the <html><code>gathered</code></html> state in network resource modules?
A: It retrieves the current configuration from the device and returns it as structured data without making any changes.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are network resource modules?]]
* [[What are "resource modules" in network automation?]]
* [[What does `state: present` mean in a module?]]
Q: Why don't Juniper Junos [[Ansible modules|Ansible Modules]] require Python on the device?
A: They use Junos PyEZ and the Junos XML API over NETCONF to interface with the device, all executed from the control node.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Why does Ansible have separate Python requirements for control node vs. managed nodes?]]
* [[How does Ansible support network automation?]]
* [[What is `ansible_network_os`, and why is it critical for network automation?]]
Q: What is the <html><code>cli_parse</code></html> module used for?
A: Parsing unstructured CLI output from network devices into structured data using parsers like TextFSM, TTP, xmltodict, or pyATS.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `cli_command` vs platform-specific modules (e.g., ios_command)?]]
Q: What collection provides platform-independent network modules?
A: <html><code>ansible.netcommon</code></html> -- it includes <html><code>cli_command</code></html>, <html><code>cli_config</code></html>, <html><code>netconf_config</code></html>, <html><code>netconf_get</code></html>, and <html><code>cli_parse</code></html>.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible manage network devices?]]
* [[What is the `ansible_connection` variable set to for network devices?]]
* [[How does Ansible support network automation?]]
Q: What is <html><code>ansible_network_os</code></html>, and why is it critical for network automation?
A: It identifies the network operating system (e.g., ios, nxos, eos, junos) so Ansible loads the correct Terminal, cliconf, and httpapi plugins for that platform. Without it, network modules cannot function.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible became the dominant network automation tool despite being designed for servers]]
* [[How does Ansible manage network devices?]]
* [[What are specific challenges you might face when using Ansible for network automation?]]
Q: What is the difference between <html><code>network_cli</code></html> and <html><code>httpapi</code></html> for network devices?
A: <html><code>network_cli</code></html> uses SSH to interact with the device's CLI (like a human at a terminal). <html><code>httpapi</code></html> uses REST API calls over HTTP(S). The choice depends on which interface the device exposes and which provides better functionality.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What connection plugin is used for network devices?]]
* [[What is the `network_cli` connection plugin used for?]]
* [[What is the `httpapi` connection plugin?]]
Q: What is <html><code>cli_command</code></html> vs platform-specific modules (e.g., ios_command)?
A: <html><code>cli_command</code></html> is a generic module that works across any network_cli-connected device. Platform-specific modules (ios_command, nxos_command) add platform awareness, resource modules (declarative state management), and better idempotency.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `network_cli` connection plugin used for?]]
* [[What collection provides platform-independent network modules?]]
Q: Can Ansible use SSH to manage Windows?
A: Yes, since Windows 10/Server 2019 include OpenSSH. However, WinRM remains the primary and most mature connection method.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What protocol does Ansible use to manage Windows hosts?]]
* [[Can you run Ansible on Windows as a control node?]]
* [[How does Ansible communicate with Windows hosts?]]
Q: What Python packages are required on the control node for WinRM?
A: <html><code>pywinrm</code></html> (for the winrm connection plugin) or <html><code>pypsrp</code></html> (for the psrp connection plugin).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `psrp` connection plugin, and how does it differ from `winrm`?]]
* [[What authentication methods does WinRM support?]]
* [[What port does WinRM use by default for Ansible Windows management?]]
Q: What authentication methods does WinRM support?
A: Basic, Certificate, NTLM, Kerberos, and CredSSP. Each has different security characteristics and delegation capabilities.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Why is CredSSP sometimes needed for Windows automation?]]
* [[What Python packages are required on the control node for WinRM?]]
* [[What is the `psrp` connection plugin, and how does it differ from `winrm`?]]
Q: Why is CredSSP sometimes needed for Windows automation?
A: Because most WinRM auth methods don't delegate credentials, causing "double hop" authentication failures when accessing network resources. CredSSP forwards credentials, enabling access to network shares, SQL servers, etc.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What authentication methods does WinRM support?]]
* [[What is the `psrp` connection plugin, and how does it differ from `winrm`?]]
Q: How does <html><code>become</code></html> work differently on Windows?
A: On Windows, <html><code>become</code></html> uses <html><code>runas</code></html> to bypass WinRM's non-interactive session restrictions. It creates an interactive token, allowing access to APIs blocked under WinRM (Windows Update API, DPAPI, etc.).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `become` do?]]
* [[Become escalates task privileges to a different user or method]]
* [[What is the `win_updates` module used for?]]
Q: What is the <html><code>win_updates</code></html> module used for?
A: Installing Windows updates by category (Security, Critical, etc.). The <html><code>win_hotfix</code></html> module handles individual hotfix files.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `apt` module do?]]
* [[How are Windows modules different from Linux modules internally?]]
Q: What is the <html><code>ansible.windows</code></html> collection?
A: The official collection containing Windows-specific modules like <html><code>win_copy</code></html>, <html><code>win_file</code></html>, <html><code>win_service</code></html>, <html><code>win_user</code></html>, <html><code>win_group</code></html>, <html><code>win_regedit</code></html>, <html><code>win_shell</code></html>, <html><code>win_command</code></html>, <html><code>win_dsc</code></html>, etc.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What Ansible module is used to create scheduled tasks on Windows?]]
* [[What language is Ansible written in?]]
* [[Ansible manages Windows servers via WinRM]]
Q: How are Windows modules different from Linux modules internally?
A: Windows modules are written in PowerShell (not Python) and use the Module Replacer framework instead of Ansiballz.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the Module Replacer framework?]]
* [[What is the `ansible.windows` collection?]]
Q: How does Ansible interact with Kubernetes?
A: Using the <html><code>kubernetes.core</code></html> collection modules to deploy workloads, manage resources, apply manifests, and bootstrap clusters.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Modules]]
* [[How does Ansible interact with Docker?]]
Q: How does Ansible interact with Docker?
A: Using <html><code>community.docker</code></html> collection modules (docker_container, docker_image, docker_network, docker_compose).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Ansible Container, and how does it integrate with Docker?]]
* [[What does the `docker_container` module do?]]
* [[How does Ansible interact with Kubernetes?]]
Q: How do you provision AWS EC2 instances with Ansible?
A: Use the <html><code>amazon.aws.ec2_instance</code></html> module with appropriate parameters (image_id, instance_type, key_name, security groups, etc.).
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you specify which Ansible collections to include in an EE?]]
* [[Ansible in a Multi-Cloud Environment]]
* [[Ansible Dynamic Inventory]]
Q: What is the FQCN for the AWS EC2 module?
A: <html><code>amazon.aws.ec2_instance</code></html> (or <html><code>amazon.aws.ec2</code></html> for the legacy version).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[What is a Fully Qualified Collection Name (FQCN)?]]
* [[What collection provides AWS modules?]]
Q: What collection provides AWS modules?
A: <html><code>amazon.aws</code></html> for core AWS modules, and <html><code>community.aws</code></html> for community-contributed modules.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Modules, plugins, and collections in Ansible architecture]]
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[What are the two categories of Ansible modules?]]
Q: What is the <html><code>cloud.terraform</code></html> collection?
A: An Ansible collection that integrates Terraform CLI operations within Ansible playbooks, allowing management of Terraform-provisioned infrastructure alongside Ansible configuration.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible configures running infrastructure; Terraform creates it]]
* [[What are Ansible Validated Content collections for cloud?]]
* [[Modules, plugins, and collections in Ansible architecture]]
Q: What are Ansible Validated Content collections for cloud?
A: Pre-tested, Red Hat-supported collections with curated roles and playbooks that encapsulate industry best practices for cloud automation (e.g., <html><code>cloud.gcp_ops</code></html> for Google Cloud).
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `cloud.terraform` collection?]]
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[Ansible Collections: packaging and distribution format]]
Q: What collection provides Podman modules and connection plugins?
A: <html><code>containers.podman</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are connection plugins?]]
Q: What collection provides Docker modules and connection plugins?
A: <html><code>community.docker</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `community.docker.docker` and `community.docker.docker_a…]]
* [[How does Ansible interact with Docker?]]
Q: How do you run Ansible tasks inside an existing container?
A: Use the container's connection plugin: <html><code>ansible_connection: containers.podman.podman</code></html> or <html><code>ansible_connection: community.docker.docker</code></html> with the container name/ID as the host.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is Ansible Container, and how does it integrate with Docker?]]
* [[How does Ansible interact with Docker?]]
Q: What is the difference between <html><code>community.docker.docker</code></html> and <html><code>community.docker.docker_api</code></html> connection plugins?
A: <html><code>docker</code></html> uses the Docker CLI to execute commands. <html><code>docker_api</code></html> connects directly to the Docker daemon API, bypassing the CLI.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What collection provides Docker modules and connection plugins?]]
* [[How does Ansible interact with Docker?]]
Q: What module creates and manages Podman containers?
A: <html><code>containers.podman.podman_container</code></html>
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `docker_container` module do?]]
Q: How is Ansible used in a CI/CD pipeline?
A: Ansible automates infrastructure provisioning, application deployment, and configuration management, triggered by code commits or merge requests via tools like Jenkins, GitHub Actions, or GitLab CI.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does Ansible differ from other configuration management tools?]]
* [[Ansible Modules]]
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
Q: How do you integrate Ansible with Jenkins?
A: Create Jenkins jobs that call <html><code>ansible-playbook</code></html> commands, use Jenkins Ansible plugin, pass build parameters as extra-vars, and archive job logs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Handling Dependencies]]
* [[How is Ansible used in a CI/CD pipeline?]]
* [[What are Ansible plugins?]]
Q: How do you handle version control for playbooks?
A: Treat playbooks as code in Git. Use branches for changes, tags for versioning, code reviews for quality, and publish roles to Galaxy.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the importance of version control with Ansible playbooks.]]
* [[Name three strategies to keep playbooks DRY.]]
* [[Structured Playbooks Provide Auditability and Idempotency]]
Q: What is a Decision Environment?
A: A containerized runtime that runs EDA rulebook logic, handling event listening and filtering before passing decisions to Execution Environments.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between a Decision Environment and an Execution Environment in E…]]
* [[What is the structure of an EDA rulebook?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
Q: What is a rolling update strategy?
A: Using <html><code>serial</code></html> to update hosts in batches, draining servers from load balancers before updating, performing health checks after each batch, and using block/rescue for rollback.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How does `serial` support rolling updates?]]
* [[Rolling Updates with Zero Downtime]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
Q: How do you implement blue-green deployments with Ansible?
A: Maintain two identical environments (blue/green), deploy to the inactive environment, run health checks, then switch traffic at the load balancer.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you implement canary deployments with Ansible?]]
* [[Serial deployment prevents cascading outages during rolling updates]]
Q: How do you implement canary deployments with Ansible?
A: Route traffic gradually to new version hosts, monitor health metrics, and roll back quickly if issues arise using <html><code>serial: 1</code></html> and load balancer manipulation.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[How do you implement blue-green deployments with Ansible?]]
Q: What is configuration drift?
A: Changes on a host that cause it to differ from the desired/synced state, often from ad-hoc manual modifications. Ansible combats drift through idempotent playbook runs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Config drift encodes production fixes; reverting it re-introduces the problems]]
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[You deploy configuration but servers show inconsistent settings. How do you detect and …]]
Q: Name three strategies to keep playbooks DRY.
A: Use roles for reusable components, use includes/imports for shared task files, and use variables/defaults to eliminate hardcoded values.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you structure a good playbook or role?]]
* [[Roles standardize reusable automation into a predictable directory structure]]
* [[How would you design a reusable playbook for multiple environments?]]
Q: What are best practices for Ansible role organization?
A: Follow naming conventions, modularize functionality, document roles thoroughly, use version control, implement testing with Molecule, minimize dependencies, and reuse community roles when appropriate.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the use of Ansible roles in network automation.]]
* [[What's your experience with Ansible?]]
* [[What is the standard directory structure of an Ansible role?]]
Q: What indentation is recommended for YAML?
A: 2 spaces (never tabs).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is YAML, and why is it used in Ansible?]]
* [[What language are Ansible playbooks written in?]]
* [[What is the syntax for an Ansible Playbook?]]
Q: What symbol starts a list item in YAML?
A: A dash followed by a space (<html><code>- </code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[List all the string values that YAML 1.1 interprets as boolean false.]]
* [[What does YAML stand for?]]
* [[What is YAML, and why is it used in Ansible?]]
Q: What does YAML stand for?
A: YAML Ain't Markup Language (originally "Yet Another Markup Language").
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is YAML, and why is it used in Ansible?]]
* [[What symbol starts a list item in YAML?]]
Q: What is the "two-stage" or "delegate and register" pattern?
A: Running a task on one host (via <html><code>delegate_to</code></html>), registering the result, and using that result on the original host. Common for checking load balancer status before making changes to a backend server.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `delegate_to`?]]
* [[Delegation runs a task on a different host while preserving target context]]
* [[What does `delegate_to` do?]]
Q: What is the "canary deployment" pattern in Ansible?
A: Using <html><code>serial: [1, 5, "100%"]</code></html> to deploy to one host first (canary), then a small batch, then the rest. If the canary fails, the entire play stops before affecting other hosts.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[What is `ansible_play_batch`?]]
Q: What is the "pre_tasks / post_tasks" idiom for rolling updates?
A: <html><code>pre_tasks</code></html> remove a host from a load balancer, the main <html><code>roles/tasks</code></html> deploy updates, and <html><code>post_tasks</code></html> re-add the host to the load balancer.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a pre_task and post_task?]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
* [[What is a rolling update strategy?]]
Q: What is the "include_role with conditionals" anti-pattern?
A: Putting <html><code>when</code></html> on <html><code>include_role</code></html> only evaluates the condition once (at include time). If you need per-task conditions inside the role, use variables instead. This is a common source of bugs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `include_role` vs `import_role`?]]
* [[Can you use `when` conditions with `import_tasks`?]]
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
Q: What is the "golden image" pattern using Ansible?
A: Using Ansible with Packer to provision a base VM/container image with all required software, then deploying instances from that image. Ansible handles the configuration during image build time rather than at runtime.
----
//Total: 220+ Q&A pairs covering Ansible history, ecosystem, trivia, deep internals, and edge cases.//
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-builder`?]]
* [[Ansible provisioner integrates configuration management into Packer builds]]
* [[What is the default base image used by ansible-builder?]]
Q: You deploy configuration but servers show inconsistent settings. How do you detect and fix it?
A: Use check_mode to detect changes, <html><code>--diff</code></html> to show differences, re-run playbooks to enforce idempotency, implement scheduled cron-based ansible-pull for continuous compliance.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Config drift encodes production fixes; reverting it re-introduces the problems]]
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[Always run --check --diff before production Ansible changes]]
Q: How would you apply BGP configuration across 100 routers with minimum downtime?
A: Use ios_config module, implement serial batching (serial: 5), verify with --check mode, validate BGP status with ios_command after each batch.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you implement zero-downtime deployments?]]
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
Q: How would you design a reusable playbook for multiple environments?
A: Use separate inventory files per environment, environment-specific group_vars, roles for modularity, parameterized configurations, and conditional logic based on environment variables.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible: Managing Multiple Environments with Separate Inventories]]
* [[Ansible Dynamic Inventory]]
* [[Roles standardize reusable automation into a predictable directory structure]]
Q: How do you implement zero-downtime deployments?
A: Rolling updates with <html><code>serial</code></html>, drain servers from load balancer before update, health checks after deployment, block/rescue for rollback capability.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Rolling Updates with Zero Downtime]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
Q: How do you handle a playbook that exposes sensitive data in logs?
A: Use <html><code>no_log: true</code></html> on sensitive tasks, store secrets in Ansible Vault, use callback plugins for redaction, avoid echoing passwords in debug statements.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Tasks handling secrets need no_log: true]]
* [[What is the `no_log: true` directive?]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
Q: How do you manage secrets across multiple environments?
A: Separate vault files per environment, use Vault IDs for different passwords, integrate with external secret managers (HashiCorp Vault, AWS Secrets Manager), rotate secrets regularly.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you manage secrets in Ansible?]]
* [[How do you handle external secret lookups?]]
Q: What is the default number of forks?
A: 5.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How many forks does Ansible use by default?]]
* [[What is the `forks` setting, and what is its default value?]]
Q: What module is used to gather system information?
A: <html><code>setup</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `gathered` state in network resource modules?]]
* [[What module manages systemd services?]]
Q: What module creates directories?
A: <html><code>file</code></html> (with <html><code>state: directory</code></html>)
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `file` module do?]]
Q: What module copies files from remote to local?
A: <html><code>fetch</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `fetch` module do?]]
* [[What module tests if a file exists on a remote host?]]
* [[What is the `synchronize` module?]]
Q: What module is used to reboot a host?
A: <html><code>reboot</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What timeout does the reboot module use by default?]]
* [[What is the default reboot timeout?]]
Q: What is the default reboot timeout?
A: 600 seconds (10 minutes). Can be changed with <html><code>reboot_timeout</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What module is used to reboot a host?]]
* [[How do you reboot a host and wait for it to come back?]]
Q: What timeout does the reboot module use by default?
A: 600 seconds (10 minutes) for the host to become reachable again after reboot.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you reboot a host and wait for it to come back?]]
* [[What module is used to reboot a host?]]
* [[What is the `ansible.builtin.reboot` module?]]
Q: Is Ansible open-source?
A: Yes, Ansible Core is open-source (GPL v3). Red Hat Ansible Automation Platform is the commercial enterprise product.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do AWX and Red Hat Ansible Automation Platform differ?]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[What is the relationship between ansible-core and the ansible package?]]
Q: What is the Ansible Tower rebrand name?
A: Red Hat Ansible Automation Platform (AAP). "Ansible Tower" is the legacy name for the web UI component.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[When was Ansible Tower renamed to automation controller?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
Q: What is idempotency?
A: The property that running the same operation multiple times produces the same result as running it once. No unnecessary changes are made on subsequent runs.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `idempotence` step verify?]]
* [[What are idempotency issues in infrastructure automation and how are they avoided?]]
* [[What is the "idempotence" test phase in Molecule?]]
Q: What is provisioning?
A: The process of setting up new servers and infrastructure. Ansible can automate the creation and initial configuration of systems.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible provisioner integrates configuration management into Packer builds]]
* [[Ansible configures running infrastructure; Terraform creates it]]
* [[Shell provisioners run in non-interactive context; use Ansible for complex configuration]]
Q: What does the <html><code>ansible-galaxy</code></html> CLI do?
A: Manages roles and collections -- install, create, remove, list, and search for reusable content.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between an Ansible playbook and a role?]]
* [[What is the `ansible.posix` collection?]]
* [[Ansible execution hierarchy: playbook > play > task; roles bundle and reuse]]
Q: How do you set the PATH or environment variables for a task?
A: Use the <html><code>environment</code></html> keyword: <html><code>environment: PATH: "{{ ansible_env.PATH }}:/new/path"</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between variable names and environment variables?]]
* [[How do you define variables in Ansible Playbooks?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
Q: How do you loop over hosts in a group inside a template?
A: <html><code>{% for host in groups['db_servers'] %} {{ host }} {% endfor %}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you access a variable of the first host in a group?]]
* [[How do you write a loop in Jinja2?]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
Q: What is the <html><code>retry_until</code></html> pattern in Ansible?
A: Using <html><code>until</code></html>, <html><code>retries</code></html>, and <html><code>delay</code></html> to retry a task until a condition is met or max retries is reached.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `.retry` file that Ansible creates?]]
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[What is the Ansible equivalent of try/catch/finally?]]
Q: What is <html><code>meta: end_play</code></html>?
A: Immediately ends the current play without executing remaining tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `meta: flush_handlers` do?]]
* [[When do handlers execute?]]
* [[What is the `meta` module used for?]]
Q: What does <html><code>meta: end_host</code></html> do?
A: Stops executing tasks on the current host for the remainder of the play without failing it. Other hosts continue normally.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is `meta: clear_host_errors`?]]
* [[What is the `meta` module used for?]]
* [[What does `meta: flush_handlers` do?]]
Q: What is <html><code>meta: clear_facts</code></html>?
A: Removes all cached facts for the current host.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `meta` module used for?]]
* [[What is `meta: clear_host_errors`?]]
* [[What is the `set_fact` module's `cacheable` option?]]
Q: What is <html><code>meta: clear_host_errors</code></html>?
A: Clears the failed state from hosts, allowing them to continue in subsequent tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `meta: end_host` do?]]
* [[What is `any_errors_fatal` and when would you use it?]]
* [[What is `meta: clear_facts`?]]
Q: What does <html><code>force_handlers: yes</code></html> do?
A: Forces handlers to run even if a task fails, ensuring cleanup actions still execute.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `meta: flush_handlers` do?]]
* [[When do handlers execute?]]
* [[What happens if a handler is notified multiple times?]]
Q: What module tests if a file exists on a remote host?
A: <html><code>stat</code></html> module -- returns file information including whether it exists.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What module copies files from remote to local?]]
* [[What are Ansible test plugins?]]
* [[What is the `ansible.builtin.find` module?]]
Q: What is the <html><code>assert</code></html> module used for?
A: Validates conditions and fails the playbook with a custom message if assertions are not met. Useful for pre-flight checks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `fail` module?]]
* [[What does the `debug` module do?]]
Q: What is the <html><code>fail</code></html> module?
A: Explicitly fails a play with a custom error message. Often used with <html><code>when</code></html> for conditional failures.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `failed_when: false` idiom?]]
* [[What is `any_errors_fatal` and when would you use it?]]
* [[What is `ignore_errors`?]]
Q: What is the <html><code>script</code></html> module?
A: Transfers a script to the remote host and executes it. The script runs in the remote host's shell.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `command` module do?]]
* [[What does the `shell` module do?]]
* [[What is the `raw` module?]]
Q: What is the <html><code>ansible.builtin.script</code></html> module?
A: Transfers and executes a local script on the remote host. The script runs in the remote host's shell.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible.builtin.package` module?]]
* [[Ansible Modules]]
* [[What is `ansible.builtin.add_host`?]]
Q: What is the <html><code>expect</code></html> module?
A: Handles interactive command prompts by providing automated responses (requires <html><code>pexpect</code></html> library).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `raw` module?]]
* [[What is the `script` module?]]
Q: What is the <html><code>local_action</code></html> keyword?
A: Runs a task on the control node instead of the remote host. Equivalent to <html><code>delegate_to: localhost</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `delegate_to`?]]
* [[What does `delegate_to` do?]]
* [[What is an "action plugin" and how does it differ from a module?]]
Q: What is callback plugin <html><code>profile_tasks</code></html>?
A: Displays timing information for each task, helping identify performance bottlenecks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five notable callback plugins.]]
* [[What is callback plugin `timer`?]]
* [[Name some built-in callback plugins.]]
Q: What is callback plugin <html><code>timer</code></html>?
A: Shows the total playbook execution time.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What callback plugin would you use to profile task execution times?]]
* [[What is callback plugin `profile_tasks`?]]
* [[What is the `pause` module?]]
Q: What happens if you reference an undefined variable?
A: Ansible raises a fatal error and stops execution, unless you use the <html><code>default</code></html> filter: <html><code>{{ var | default('fallback') }}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `default` filter do?]]
* [[What Jinja2 filter returns a default value when a variable is undefined?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
Q: What is the <html><code>lookup</code></html> plugin?
A: Retrieves data from external sources at the control node level. Example: <html><code>{{ lookup('file', '/path/to/file') }}</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name ten commonly used lookup plugins.]]
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[What base class do lookup plugins inherit from?]]
Q: How do you access nested variables?
A: Use dot notation (<html><code>{{ user.address.city }}</code></html>) or bracket notation (<html><code>{{ user['address']['city'] }}</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between dot notation and array notation for variables?]]
* [[How do you use variables in Jinja2 templates?]]
* [[How do you reference a variable in a playbook?]]
Q: What is an Ansible callback whitelist?
A: The list of enabled callback plugins in ansible.cfg. Only whitelisted callbacks are active.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How do you enable a notification callback plugin?]]
* [[What is a callback plugin?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
Q: Can you write custom [[Ansible modules|Ansible Modules]]?
A: Yes, write Python scripts using <html><code>AnsibleModule</code></html> from <html><code>ansible.module_utils.basic</code></html>, define argument specs, implement logic, and place in a <html><code>library/</code></html> directory.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Modules]]
* [[What Python class must every custom Ansible module import?]]
* [[How do you specify a custom inventory file?]]
Q: What is <html><code>creates</code></html> parameter in command/shell modules?
A: If the specified file already exists, the task is skipped. Helps enforce idempotency for command tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `command` module do?]]
* [[What internal arguments does Ansible automatically inject into every module call?]]
* [[What are the `_raw_params` in free-form modules?]]
Q: What is <html><code>removes</code></html> parameter in command/shell modules?
A: If the specified file does NOT exist, the task is skipped. The inverse of <html><code>creates</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `command` module do?]]
* [[What is the `omit` variable in Ansible?]]
Q: How do you reboot a host and wait for it to come back?
A: Use the <html><code>reboot</code></html> module which handles both rebooting and waiting for reconnection automatically.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What timeout does the reboot module use by default?]]
* [[What is the `ansible.builtin.reboot` module?]]
* [[What is the default reboot timeout?]]
Q: What is the <html><code>throttle</code></html> keyword?
A: Limits the number of concurrent hosts for a specific task (not the entire play like <html><code>serial</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the Difference between Forks and Serial & Throttle.]]
* [[What is the `serial` keyword?]]
Q: What does <html><code>throttle</code></html> do at the task level?
A: Limits the number of hosts executing that specific task simultaneously, regardless of the <html><code>forks</code></html> setting. Useful for tasks that hit rate-limited APIs or shared resources.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the `forks` setting, and what is its default value?]]
Q: What is <html><code>order</code></html> in a play?
A: Controls the order in which hosts are processed: <html><code>inventory</code></html> (default), <html><code>reverse_inventory</code></html>, <html><code>sorted</code></html>, <html><code>reverse_sorted</code></html>, <html><code>shuffle</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What does the `hosts` keyword define in a play?]]
* [[What is `ansible_play_batch`?]]
Q: What is a pre_task and post_task?
A: <html><code>pre_tasks</code></html> run before roles; <html><code>post_tasks</code></html> run after roles and tasks. Useful for load balancer manipulation.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "pre_tasks / post_tasks" idiom for rolling updates?]]
* [[What keyword defines tasks in a playbook?]]
* [[What is a task in Ansible?]]
Q: What is a playbook <html><code>import_playbook</code></html>?
A: Imports another entire playbook into the current one, allowing playbook composition.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `playbook_dir`?]]
* [[What is the difference between a playbook and a play?]]
* [[What are Ansible "playbooks"?]]
Q: What is the <html><code>timeout</code></html> connection parameter?
A: Sets the SSH connection timeout in seconds. Configurable per host or globally.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `wait_for_connection` used for?]]
Q: What module manages SELinux?
A: <html><code>selinux</code></html> module (set mode to enforcing, permissive, or disabled).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What module manages firewall rules?
A: <html><code>firewalld</code></html> (for firewalld) or <html><code>iptables</code></html> (for iptables).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What module manages systemd services?
A: <html><code>systemd</code></html> (provides more systemd-specific options than the generic <html><code>service</code></html> module).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What does the `service` module do?]]
Q: When is ansible-pull appropriate?
A: When central coordination of task completion isn't required and eventual consistency is acceptable. It scales well because processing is distributed across the fleet.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When would you use ansible-pull instead of the default push model?]]
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[Ansible strategy plugins control task-execution ordering across hosts]]
Q: What does ansible-pull require on each managed node?
A: Ansible must be installed, along with Git (to clone the playbook repository) and any Python dependencies needed by the playbooks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
* [[How does ansible-pull know which playbook to run?]]
* [[ansible-pull inverts the model to pull-based configuration management]]
Q: How does ansible-pull know which playbook to run?
A: Via the <html><code>-U</code></html> (repository URL) and optionally <html><code>-C</code></html> (branch/tag) and playbook file path arguments. It clones/pulls the repo, then runs the specified playbook locally.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command runs an Ansible playbook?]]
* [[What is `playbook_dir`?]]
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
Q: What playbook filename does ansible-pull look for by default?
A: It looks for <html><code><hostname>.yml</code></html> (matching the host's hostname) or <html><code>local.yml</code></html> in the repository root.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What command runs an Ansible playbook?]]
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
* [[What is `ansible_play_name`?]]
Q: What connection type does ansible-pull use?
A: <html><code>local</code></html> -- since it runs on the target host itself, no SSH connection is needed.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_connection` and where can it be set?]]
* [[What port does Ansible use by default for SSH connections?]]
* [[Name all the major connection plugin types in Ansible.]]
Q: What is the <html><code>set_fact</code></html> module's <html><code>cacheable</code></html> option?
A: When <html><code>cacheable: true</code></html>, the fact is stored in the fact cache and persists across playbook runs (if fact caching is enabled).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `set_fact`?]]
* [[Fact Caching Returns Stale System Information]]
Q: What is the <html><code>meta</code></html> module used for?
A: Executing Ansible internal operations: <html><code>flush_handlers</code></html>, <html><code>refresh_inventory</code></html>, <html><code>noop</code></html>, <html><code>clear_facts</code></html>, <html><code>clear_host_errors</code></html>, <html><code>end_play</code></html>, <html><code>end_host</code></html>, <html><code>end_batch</code></html>, <html><code>reset_connection</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `meta: reset_connection` do?]]
* [[What does `meta: end_host` do?]]
* [[What does `meta/main.yml` in a role contain?]]
Q: What does <html><code>meta: reset_connection</code></html> do?
A: Forces Ansible to close and re-establish the connection to the current host. Useful after making changes that affect the connection (e.g., changing the SSH key or restarting sshd).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `meta` module used for?]]
* [[What is `ansible_connection` and where can it be set?]]
* [[What does `meta: end_host` do?]]
Q: What is the <html><code>no_log: true</code></html> directive?
A: Prevents Ansible from logging task parameters and results, useful for tasks handling sensitive data like passwords.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `no_log` lint rule about?]]
* [[What does `ANSIBLE_NOCOWS` do?]]
* [[How do you handle a playbook that exposes sensitive data in logs?]]
Q: What does <html><code>module_defaults</code></html> do at the play or block level?
A: Sets default parameter values for specific modules across multiple tasks. Example: setting <html><code>become: true</code></html> for all <html><code>yum</code></html> module calls without repeating it per task.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What module gathers facts by default at the start of each play?]]
* [[What is `set_fact`?]]
Q: What is the <html><code>INJECT_FACTS_AS_VARS</code></html> configuration?
A: When true (default), facts are injected as top-level variables (e.g., <html><code>ansible_hostname</code></html>). When false, facts are only accessible via <html><code>ansible_facts['hostname']</code></html>. Disabling it reduces variable namespace pollution and improves security.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Under what namespace are custom local facts accessible?]]
* [[Ansible Facts and the gather_facts task]]
* [[What is `ansible_local`?]]
Q: What is <html><code>ansible_facts</code></html> vs top-level fact variables?
A: <html><code>ansible_facts</code></html> is a dictionary namespace containing all gathered facts. When <html><code>INJECT_FACTS_AS_VARS</code></html> is true (default), facts are also available as top-level variables prefixed with <html><code>ansible_</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Ansible Facts and the gather_facts task]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[What are custom facts (local facts) and where do they live?]]
Q: What is <html><code>wait_for_connection</code></html> used for?
A: Waiting until a host becomes reachable, typically after a reboot. It repeatedly attempts to connect until successful or timeout.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `wait_for` module do?]]
* [[What is the `timeout` connection parameter?]]
Q: What is <html><code>group_by</code></html> module?
A: Dynamically creates groups during playbook execution based on facts or variables: <html><code>group_by: key=os_{{ ansible_distribution }}</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is a group in an Ansible inventory?]]
* [[What special group exists in every Ansible inventory?]]
* [[What does `group_names` contain?]]
Q: What is the <html><code>template</code></html> module's <html><code>output_encoding</code></html> parameter?
A: Specifies the character encoding for the rendered template output file (default: utf-8).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What does <html><code>connection: local</code></html> do?
A: Executes tasks on the control node itself instead of connecting to a remote host. Used with <html><code>delegate_to: localhost</code></html> or for local operations.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_connection` and where can it be set?]]
* [[What are connection plugins?]]
* [[What is `delegate_to`?]]
Q: What is the difference between <html><code>is match</code></html> and <html><code>is search</code></html> tests?
A: <html><code>match</code></html> anchors to the beginning of the string (like <html><code>re.match</code></html>). <html><code>search</code></html> finds a pattern anywhere in the string (like <html><code>re.search</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
Q: What is the <html><code>ansible.builtin.package</code></html> module?
A: A generic OS package module that automatically selects the appropriate backend (yum, apt, dnf, zypper) based on the target OS.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible.builtin.script` module?]]
* [[What is `ansible-builder`?]]
* [[What is the relationship between ansible-core and the ansible package?]]
Q: What is the <html><code>loop_control</code></html> directive?
A: Controls loop behavior: <html><code>loop_var</code></html> (rename loop variable), <html><code>index_var</code></html> (expose loop index), <html><code>label</code></html> (customize output display), <html><code>pause</code></html> (delay between iterations), <html><code>extended</code></html> (expose extended loop info).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does `loop_control: extended` provide?]]
* [[What is `ansible_loop`?]]
* [[What is the difference between `with_items` and `loop`?]]
Q: What is <html><code>vars_prompt</code></html>?
A: A play-level directive that prompts the user for input at playbook start. Supports <html><code>private</code></html> (hide input), <html><code>default</code></html>, <html><code>confirm</code></html>, and <html><code>encrypt</code></html> options.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the difference between `vars`, `vars_files`, and `vars_prompt`?]]
* [[What happens if you use `vars_prompt` in Ansible Tower/Controller?]]
* [[What is the `ansible.builtin.pause` module?]]
Q: What is the <html><code>uri</code></html> module?
A: Makes HTTP/HTTPS requests from the control node (or remote host if delegated). Used for API calls, health checks, and webhook triggers.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the `httpapi` connection plugin?]]
Q: What is the <html><code>ansible.builtin.find</code></html> module?
A: Searches for files/directories on remote hosts matching specified criteria (patterns, age, size). Returns a list of matching paths.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ansible.builtin.script` module?]]
* [[What is the `ansible.builtin.package` module?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
Q: What are the <html><code>_raw_params</code></html> in free-form modules?
A: The internal parameter name used by modules like <html><code>command</code></html>, <html><code>shell</code></html>, and <html><code>raw</code></html> that accept a free-form command string instead of structured key=value arguments.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `argument_spec` in a custom module?]]
* [[What is the `raw` module?]]
Q: What is the <html><code>ansible.builtin.reboot</code></html> module?
A: Reboots the remote host and waits for it to come back. Handles the connection drop and reconnection automatically.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `.retry` file that Ansible creates?]]
* [[What is the `ansible.builtin.script` module?]]
* [[What does `meta: reset_connection` do?]]
Q: What is <html><code>check_mode: true</code></html> at the task level?
A: Forces a specific task to run in check mode even when the playbook is run normally. The inverse (<html><code>check_mode: false</code></html>) forces a task to run even in check mode.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Can you force a specific task to always or never run in check mode?]]
* [[How can you detect check mode inside a playbook?]]
* [[What is the major limitation of check mode?]]
Q: What is <html><code>diff: true</code></html> at the task level?
A: Shows a unified diff of changes made by the task (for modules that support it, like <html><code>copy</code></html>, <html><code>template</code></html>, <html><code>lineinfile</code></html>).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is diff mode?]]
Q: What does <html><code>--diff</code></html> do?
A: It shows before-and-after comparisons for tasks that modify files (template, copy, lineinfile, etc.). Very useful for reviewing what a playbook will change.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Explain the purpose of the --diff option in Ansible playbooks.]]
Q: What is <html><code>ansible.builtin.lineinfile</code></html> vs <html><code>ansible.builtin.blockinfile</code></html>?
A: <html><code>lineinfile</code></html> manages single lines in files (insert, replace, ensure present/absent). <html><code>blockinfile</code></html> manages multi-line blocks surrounded by markers.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `lineinfile` module do?]]
* [[What module adds or modifies lines in files?]]
* [[What YAML multiline syntax options does Ansible support, and what are the key differences?]]
Q: What is <html><code>ansible.builtin.add_host</code></html>?
A: Dynamically adds a host to the in-memory inventory during playbook execution. Useful for adding newly provisioned hosts.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_play_batch`?]]
* [[Ansible inventory file: definition and configuration]]
* [[What is the `ansible.builtin.script` module?]]
Q: What is the <html><code>ansible.builtin.debug</code></html> module's <html><code>var</code></html> vs <html><code>msg</code></html> parameter?
A: <html><code>var</code></html> prints a variable's value (auto-evaluated, no Jinja2 braces needed). <html><code>msg</code></html> prints a formatted message string (supports Jinja2 expressions in braces).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[Ansible debug module: printing messages during playbook execution]]
Q: What is <html><code>ansible-console</code></html>?
A: An interactive REPL-style console for running ad-hoc Ansible tasks against an inventory, with tab completion.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is an Ansible inventory?]]
* [[What is `ansible_port`?]]
* [[What does `ansible-inventory --list` do?]]
Q: What is the <html><code>ansible.posix</code></html> collection?
A: A collection of POSIX-system modules including <html><code>acl</code></html>, <html><code>at</code></html>, <html><code>authorized_key</code></html>, <html><code>firewalld</code></html>, <html><code>mount</code></html>, <html><code>patch</code></html>, <html><code>seboolean</code></html>, <html><code>selinux</code></html>, <html><code>synchronize</code></html>, <html><code>sysctl</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[What does the `ansible-galaxy` CLI do?]]
* [[What is the `ansible.windows` collection?]]
Q: What is <html><code>ansible.builtin.apt_key</code></html> and why is it deprecated?
A: It managed APT repository GPG keys. Deprecated because modern apt recommends storing keys in <html><code>/etc/apt/keyrings/</code></html> and referencing them with <html><code>signed-by</code></html> in sources.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_version`?]]
* [[What is the `ansible.builtin.package` module?]]
Q: What is the <html><code>become_method</code></html> setting and what values does it support?
A: Controls how Ansible escalates privileges. Values: <html><code>sudo</code></html> (default), <html><code>su</code></html>, <html><code>pbrun</code></html>, <html><code>pfexec</code></html>, <html><code>doas</code></html>, <html><code>dzdo</code></html>, <html><code>ksu</code></html>, <html><code>runas</code></html> (Windows), <html><code>machinectl</code></html>, <html><code>enable</code></html> (network devices).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What is the `ansible_become_exe` variable?]]
* [[What is `become_method`?]]
* [[What happens when you apply `become: true` with the `local` connection?]]
Q: What does the <html><code>flatten</code></html> filter do?
A: Recursively flattens nested lists into a single flat list: <html><code>{{ [[1,2],[3,[4,5]]] | flatten }}</code></html> produces <html><code>[1,2,3,4,5]</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `combine` filter do, and why is it so useful?]]
Q: What is the <html><code>password_hash</code></html> filter?
A: Generates a system-compatible password hash: <html><code>{{ 'mypassword' | password_hash('sha512', 'salt') }}</code></html>. Used for setting user passwords idempotently.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 6 source atoms.//
''Related atoms''
* [[How do you generate a password hash suitable for /etc/shadow in Ansible?]]
* [[How do you generate an encrypted password for the user module?]]
Q: What happens when you use <html><code>creates</code></html> or <html><code>removes</code></html> with command/shell modules?
A: <html><code>creates: /path/to/file</code></html> skips the task if the file already exists. <html><code>removes: /path/to/file</code></html> skips the task if the file does NOT exist. Both enable idempotency for command-based tasks.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What does the `command` module do?]]
* [[Ansible's idempotency guarantee is aspirational, not enforced]]
* [[Idempotency as default, exceptions with shell and command modules]]
Q: When did Ansible drop Python 2 support on the control node?
A: ansible-core 2.12 dropped Python 2.7 support on the control node (requires Python 3.8+). However, managed nodes could still use Python 2.7 until ansible-core 2.17.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[When did Ansible collections replace the monolithic package?]]
* [[What year did Ansible 2.0 introduce the new execution engine?]]
Q: What Python version does ansible-core 2.17+ require on managed nodes?
A: Python 3.7+ on managed nodes. Python 2.7 support on managed nodes was dropped.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What Python and Java versions does ansible-rulebook require?]]
* [[What does ansible-pull require on each managed node?]]
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
Q: What is the latest ansible-core Python requirement (as of 2.20)?
A: Python 3.12+ on the control node.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 8 source atoms.//
''Related atoms''
* [[What Python and Java versions does ansible-rulebook require?]]
* [[What are the server requirements for Ansible?]]
* [[Why does Ansible have separate Python requirements for control node vs. managed nodes?]]
Q: Why does Ansible have separate Python requirements for control node vs. managed nodes?
A: The control node runs the full Ansible engine and needs a modern Python for its dependencies. Managed nodes only need Python to execute transferred module code, so older Python versions are supported longer to accommodate legacy systems.
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
* [[How does Ansible connect to managed nodes?]]
* [[What are the server requirements for Ansible?]]
Q: What is the major limitation of check mode?
A: It's a simulation. Tasks that use registered variables from prior tasks may not work correctly because those prior tasks didn't actually run. Conditional logic depending on real execution results will be unreliable.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `check_mode: true` at the task level?]]
* [[Can you force a specific task to always or never run in check mode?]]
* [[Can async tasks run in check mode?]]
Q: Can you force a specific task to always or never run in check mode?
A: Yes. <html><code>check_mode: true</code></html> makes a task always run in check mode even during a normal run. <html><code>check_mode: false</code></html> makes a task always execute normally even during a check mode run.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `check_mode: true` at the task level?]]
* [[Can async tasks run in check mode?]]
* [[What is the major limitation of check mode?]]
Q: What is <html><code>delegate_facts: true</code></html>?
A: When used with <html><code>delegate_to</code></html>, it assigns any gathered facts to the delegated host rather than the original target host. Without it, facts from the delegated task go to the inventory host being processed.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `delegate_to`?]]
* [[What tasks cannot be delegated?]]
* [[What is `ansible_facts` vs top-level fact variables?]]
Q: What is the gotcha with <html><code>run_once</code></html> and <html><code>serial</code></html>?
A: With <html><code>serial</code></html>, <html><code>run_once</code></html> executes once PER BATCH, not once for the entire play. If you have <html><code>serial: 5</code></html> and 20 hosts, <html><code>run_once</code></html> executes 4 times (once per batch of 5). To truly run once, use <html><code>when: inventory_hostname == ansible_play_hosts_all[0]</code></html>.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible_play_batch`?]]
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
Q: Can <html><code>serial</code></html> accept a list? What does that do?
A: Yes. <html><code>serial: [1, 5, "20%"]</code></html> runs the first batch with 1 host, the second with 5, then subsequent batches with 20% of remaining hosts. This is the "canary deployment" pattern -- test on one host first, then gradually expand.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the "canary deployment" pattern in Ansible?]]
* [[How does `serial` support rolling updates?]]
* [[What is `ansible_play_batch`?]]
Q: What is <html><code>ansible-pull</code></html> and how does it invert Ansible's normal model?
A: Instead of a central control node pushing to targets, each target runs <html><code>ansible-pull</code></html> to clone a Git repository containing playbooks and execute them locally. This creates a pull-based (agent-like) model.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 4 source atoms.//
''Related atoms''
* [[What playbook filename does ansible-pull look for by default?]]
* [[How does ansible-pull know which playbook to run?]]
* [[What does ansible-pull require on each managed node?]]
Q: How is ansible-pull typically scheduled?
A: Via a cron job (commonly every 15-30 minutes). Example: <html><code>*/30 * * * * ansible-pull -U git@repo.example.com/config.git</code></html>
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When would you use ansible-pull instead of the default push model?]]
* [[ansible-pull inverts the model to pull-based configuration management]]
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
Q: Besides git, what other VCS does ansible-pull support?
A: Subversion, Mercurial (hg), and Bazaar (bzr). Git is the default.
----
----
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[When would you use ansible-pull instead of the default push model?]]
* [[ansible-pull inverts the model to pull-based configuration management]]
* [[What does ansible-pull require on each managed node?]]
Q: What is the Ansible Community Steering Committee?
A: The governing body that provides continuity, guidance, and technical direction for the Ansible community project. It approves new proposals, policies, collection inclusion requests, and packaging decisions.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are Ansible Working Groups?]]
* [[What are the two categories of Ansible modules?]]
* [[What are the main components of Ansible's architecture?]]
Q: How are Steering Committee members selected?
A: Based on their active contribution to the Ansible project and community. New members are nominated and voted on by existing committee members.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Where does the Steering Committee conduct business?]]
* [[What are best practices for Ansible role organization?]]
* [[When and by whom was Ansible acquired?]]
Q: Where does the Steering Committee conduct business?
A: Primarily on the Ansible Forum (forum.ansible.com) for asynchronous discussions and voting on proposals. Regular Community Working Group meetings are also held.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[How are Steering Committee members selected?]]
* [[Where did the Ansible community move after leaving IRC?]]
* [[What are Ansible Working Groups?]]
Q: What are Ansible Working Groups?
A: Self-organized teams of community members focused on specific topics -- often centered around particular collections (e.g., AWS, Windows, Network) or cross-cutting concerns (documentation, testing, security).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What special group exists in every Ansible inventory?]]
* [[What is the Ansible Community Steering Committee?]]
* [[What is an Ansible inventory?]]
Q: What is the Community Working Group specifically?
A: A "catch-all" working group that focuses on keeping other working groups running and handles community activities not covered by specialized groups.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What are Ansible Working Groups?]]
* [[What is the `ungrouped` group?]]
* [[What is the `all` group?]]
Q: Where did the Ansible community move after leaving IRC?
A: The community moved to the Ansible Forum (forum.ansible.com) based on Discourse, and Matrix for real-time chat (replacing IRC on Libera.Chat).
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the Ansible Community Steering Committee?]]
* [[When was the last time the migration script (migrate.py) was run to move content from t…]]
* [[Before Ansible 2.10, how was all community-contributed content structured?]]
Q: Who is Jeff Geerling and why is he significant to the Ansible community?
A: Jeff Geerling is one of the most prolific Ansible community contributors, author of "Ansible for DevOps" (the most popular Ansible book), maintainer of dozens of the most-downloaded Galaxy roles (geerlingguy.docker, geerlingguy.mysql, geerlingguy.java, etc.), and a frequent speaker at AnsibleFest.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is the most downloaded Ansible Galaxy role author namespace?]]
* [[What was Michael DeHaan's job before creating Ansible, and why did he leave?]]
* [[What is `ansible-creator`?]]
Q: What is the most downloaded Ansible Galaxy role author namespace?
A: <html><code>geerlingguy</code></html> -- Jeff Geerling's roles collectively have hundreds of millions of downloads, with roles like geerlingguy.docker, geerlingguy.java, geerlingguy.apache, and geerlingguy.nginx being among the most popular on Galaxy.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia-compendium.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[Who is Jeff Geerling and why is he significant to the Ansible community?]]
* [[Ansible Galaxy: community hub for roles and collections]]
* [[Installing Ansible Galaxy roles from CLI and requirements file]]
Cowsay is a deliberately included feature that renders Ansible output through ASCII cow art if the program is installed on the control node. Michael DeHaan added this intentionally as a morale feature — automation runs can be long and repetitive, so moments of levity were considered valuable to the experience. The feature can be disabled with the <html><code>ANSIBLE_NOCOWS=1</code></html> environment variable.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What environment variable disables Ansible's cowsay output?]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[Ansible debug module: printing messages during playbook execution]]
Zuul, OpenStack's project gating CI system, became the primary CI for Ansible itself, running thousands of integration tests across multiple operating systems for every PR. The irony is self-referential: Zuul's own configuration is written in Ansible playbooks. This creates a bootstrap cycle where Ansible tests itself using a system configured by the tool it tests. It's a form of dogfooding that validates both the testing infrastructure and the tool, though it means any misconfiguration in Ansible can break its own CI.
----
''Sources''
* <html><code>training/library/topics/ansible/trivia.md</code></html>
//Merged from 2 source atoms.//
''Related atoms''
* [[What is `ansible-test`?]]
* [[How is Ansible used in a CI/CD pipeline?]]
* [[What are Ansible test plugins?]]
!! MOC — compendium q&a
Every atom extracted from a ''compendium-qa'' source (746 total).
* [[A playbook fails to decrypt Vault data. What do you check?]]
* [[A variable is defined in playbook group_vars/all and also in inventory group_vars/webse…]]
* [[Ansible SSH pipelining reduces connection round-trips]]
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
* [[Ansible is sometimes described as "procedural" while Puppet is "declarative." What does…]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[Before Ansible 2.10, how was all community-contributed content structured?]]
* [[Besides git, what other VCS does ansible-pull support?]]
* [[Can Ansible Vault encrypt an entire directory?]]
* [[Can Ansible use SSH to manage Windows?]]
* [[Can `serial` accept a list? What does that do?]]
* [[Can `serial` be expressed as a percentage?]]
* [[Can a handler notify another handler?]]
* [[Can async tasks run in check mode?]]
* [[Can handlers notify other handlers?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
* [[Can rulebooks call Ansible Automation Platform job templates?]]
* [[Can tags be applied to roles?]]
* [[Can tags be inherited through `include_tasks`?]]
* [[Can you apply tags to roles, blocks, and imports?]]
* [[Can you encrypt only specific variables in a file?]]
* [[Can you force a specific task to always or never run in check mode?]]
* [[Can you install collections from a tarball?]]
* [[Can you loop over `import_tasks`?]]
* [[Can you override an extra var with set_fact?]]
* [[Can you run Ansible on Windows as a control node?]]
* [[Can you set strategy globally?]]
* [[Can you set variables with magic variable names?]]
* [[Can you use `when` conditions with `import_tasks`?]]
* [[Can you use more than one connection plugin per host in a single play?]]
* [[Can you use multiple vault passwords in a single playbook run?]]
* [[Can you write custom Ansible modules?]]
* [[Does `poll: 0` automatically clean up the async job cache file?]]
* [[Dynamic inventory plugins auto-discover cloud hosts via provider APIs]]
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
* [[Give an example of an ad-hoc ping command.]]
* [[How are Steering Committee members selected?]]
* [[How are Windows modules different from Linux modules internally?]]
* [[How are facts gathered?]]
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[How are module arguments passed to the remote module under Ansiballz?]]
* [[How can you detect check mode inside a playbook?]]
* [[How did Ansible end up under IBM's umbrella?]]
* [[How do AWX and Red Hat Ansible Automation Platform differ?]]
* [[How do `selectattr` and `rejectattr` work?]]
* [[How do you access a variable of the first host in a group?]]
* [[How do you access nested variables?]]
* [[How do you backup router configurations with Ansible?]]
* [[How do you check a playbook's syntax without running it?]]
* [[How do you check disk space on all hosts ad-hoc?]]
* [[How do you check the status of a fire-and-forget async task?]]
* [[How do you configure a dynamic inventory for AWS EC2?]]
* [[How do you create a custom Jinja2 filter for Ansible?]]
* [[How do you create a new role skeleton?]]
* [[How do you decrypt a file?]]
* [[How do you disable automatic fact gathering?]]
* [[How do you disable fact gathering?]]
* [[How do you edit an encrypted file?]]
* [[How do you enable a callback plugin?]]
* [[How do you enable a notification callback plugin?]]
* [[How do you encrypt a single string variable?]]
* [[How do you fire-and-forget a long-running task?]]
* [[How do you force handlers to run mid-play?]]
* [[How do you generate a password hash suitable for /etc/shadow in Ansible?]]
* [[How do you generate an encrypted password for the user module?]]
* [[How do you handle a playbook that exposes sensitive data in logs?]]
* [[How do you handle external secret lookups?]]
* [[How do you handle version control for playbooks?]]
* [[How do you implement RBAC in Ansible Tower?]]
* [[How do you implement blue-green deployments with Ansible?]]
* [[How do you implement canary deployments with Ansible?]]
* [[How do you implement zero-downtime deployments?]]
* [[How do you include roles in a playbook?]]
* [[How do you inspect the contents of an EE image using ansible-navigator?]]
* [[How do you install a collection from a specific Git repository?]]
* [[How do you install a collection?]]
* [[How do you install a package using an ad-hoc command?]]
* [[How do you install a specific version of a collection?]]
* [[How do you install collections from a requirements file?]]
* [[How do you integrate Ansible with Jenkins?]]
* [[How do you invoke a lookup plugin in a playbook?]]
* [[How do you loop over a list of items?]]
* [[How do you loop over hosts in a group inside a template?]]
* [[How do you manage secrets across multiple environments?]]
* [[How do you provision AWS EC2 instances with Ansible?]]
* [[How do you reboot a host and wait for it to come back?]]
* [[How do you reference a variable in a playbook?]]
* [[How do you reference vault-encrypted variables in a playbook?]]
* [[How do you run Ansible tasks inside an existing container?]]
* [[How do you run a playbook in verbose mode?]]
* [[How do you run a playbook that uses vault-encrypted files?]]
* [[How do you run ansible-navigator without an Execution Environment (in local mode)?]]
* [[How do you run tasks asynchronously?]]
* [[How do you securely manage control node credentials?]]
* [[How do you select a specific lint profile on the command line?]]
* [[How do you set the PATH or environment variables for a task?]]
* [[How do you set the strategy for a play?]]
* [[How do you set up a jump host (bastion) in Ansible?]]
* [[How do you specify a custom inventory file?]]
* [[How do you specify role dependencies?]]
* [[How do you specify the SSH user for Ansible?]]
* [[How do you specify which Ansible collections to include in an EE?]]
* [[How do you start a playbook at a specific task?]]
* [[How do you test a specific scenario when multiple exist?]]
* [[How do you test playbooks?]]
* [[How do you use a script to provide vault passwords?]]
* [[How do you use variables in Jinja2 templates?]]
* [[How do you view all facts for a host?]]
* [[How do you view an encrypted file without decrypting?]]
* [[How do you write a conditional in Jinja2?]]
* [[How do you write a conditional task in Ansible?]]
* [[How do you write a loop in Jinja2?]]
* [[How does Ansible communicate with Linux hosts?]]
* [[How does Ansible communicate with Windows hosts?]]
* [[How does Ansible differ from Puppet?]]
* [[How does Ansible differ from SaltStack?]]
* [[How does Ansible interact with Docker?]]
* [[How does Ansible interact with Kubernetes?]]
* [[How does Ansible manage network devices?]]
* [[How does Mitogen achieve its performance gains?]]
* [[How does Mitogen transfer data?]]
* [[How does `become` work differently on Windows?]]
* [[How does `changed_when` work?]]
* [[How does `failed_when` work?]]
* [[How does `include_vars` compare to `vars_files` in precedence?]]
* [[How does `serial` support rolling updates?]]
* [[How does a custom module return data to Ansible?]]
* [[How does an event payload get passed to a triggered playbook?]]
* [[How does ansible-pull know which playbook to run?]]
* [[How does inventory caching work?]]
* [[How does privilege escalation work on network devices like Cisco IOS?]]
* [[How does the YAML octal gotcha specifically bite Ansible users?]]
* [[How does the `free` strategy differ from `linear`?]]
* [[How is Ansible used in a CI/CD pipeline?]]
* [[How is `set_fact` different from `vars`?]]
* [[How is ansible-pull typically scheduled?]]
* [[How long is each ansible-core major version maintained?]]
* [[How many collections are typically included in the Ansible community package?]]
* [[How many employees did Ansible, Inc. have at the time of the Red Hat acquisition?]]
* [[How many forks does Ansible use by default?]]
* [[How many levels of variable precedence does Ansible have?]]
* [[How many modules were in the monolithic Ansible 2.9 repository before the split?]]
* [[How many stdout-type callback plugins can be active at once?]]
* [[How often does ansible-core release a new major version?]]
* [[How would you apply BGP configuration across 100 routers with minimum downtime?]]
* [[How would you design a reusable playbook for multiple environments?]]
* [[If a rescue section succeeds, does Ansible consider the play failed?]]
* [[If both ANSIBLE_CONFIG and a local ansible.cfg exist in the current directory, which wins?]]
* [[If you create a custom fact in the same play, how do you access it?]]
* [[If you set a fact with set_fact and also define the same variable as a role parameter, …]]
* [[If you specify both --tags and --skip-tags for the same tag, what happens?]]
* [[Is Ansible open-source?]]
* [[Jinja2 filters transform values during template rendering]]
* [[List all 22 variable precedence levels from lowest to highest.]]
* [[List all the string values that YAML 1.1 interprets as boolean false.]]
* [[Many people attribute the word "ansible" to Orson Scott Card's *Ender's Game*. Why is t…]]
* [[Name all the major connection plugin types in Ansible.]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
* [[Name five ansible-lint rules.]]
* [[Name five dynamic inventory plugins included in popular collections.]]
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[Name five notable callback plugins.]]
* [[Name some built-in callback plugins.]]
* [[Name ten commonly used lookup plugins.]]
* [[Name three enterprise features that Ansible Tower/Controller has that AWX lacks.]]
* [[Name three event source plugins in the `ansible.eda` collection.]]
* [[Name three strategies to keep playbooks DRY.]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[Under what namespace are custom local facts accessible?]]
* [[What AI model powers Ansible Lightspeed?]]
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
* [[What Ansible module is used to create scheduled tasks on Windows?]]
* [[What Jinja2 filter returns a default value when a variable is undefined?]]
* [[What Molecule command runs only the verify step without re-converging?]]
* [[What Python and Java versions does ansible-rulebook require?]]
* [[What Python class must every custom Ansible module import?]]
* [[What Python library does the `netconf` connection plugin use under the hood?]]
* [[What Python package manager does Ansible recommend for installation?]]
* [[What Python packages are required on the control node for WinRM?]]
* [[What Python version does ansible-core 2.17+ require on managed nodes?]]
* [[What YAML multiline syntax options does Ansible support, and what are the key differences?]]
* [[What ansible-lint rule catches boolean value problems in YAML?]]
* [[What are "magic variables" in Ansible?]]
* [[What are "resource modules" in network automation?]]
* [[What are Ansible Validated Content collections for cloud?]]
* [[What are Ansible Working Groups?]]
* [[What are Ansible plugins?]]
* [[What are Ansible test plugins?]]
* [[What are Ansible's default privilege escalation methods?]]
* [[What are Surveys in AWX/automation controller?]]
* [[What are Vault IDs?]]
* [[What are `group_vars` and `host_vars`?]]
* [[What are best practices for Ansible role organization?]]
* [[What are connection plugins?]]
* [[What are custom facts (local facts) and where do they live?]]
* [[What are execution nodes vs hop nodes in automation mesh?]]
* [[What are inventory plugins?]]
* [[What are key limitations of Mitogen?]]
* [[What are lookup plugins?]]
* [[What are network resource modules?]]
* [[What are strategy plugins?]]
* [[What are tags used for?]]
* [[What are the `_raw_params` in free-form modules?]]
* [[What are the `gather_subset` and `gather_timeout` options?]]
* [[What are the `mutually_exclusive`, `required_together`, `required_one_of`, `required_if…]]
* [[What are the available gather_subset categories?]]
* [[What are the five reserved tag names in Ansible?]]
* [[What are the four verbosity levels in Ansible?]]
* [[What are the key features of Ansible?]]
* [[What are the key parts of an EDA rulebook?]]
* [[What are the key phases in a Molecule test sequence?]]
* [[What are the key sections in an `execution-environment.yml` file?]]
* [[What are the main components of Ansible's architecture?]]
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[What are the server requirements for Ansible?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What are the special tags `always` and `never`?]]
* [[What are the three Mitogen strategy plugins?]]
* [[What are the three main components of an Ansible rulebook?]]
* [[What are the three main connection types for network automation?]]
* [[What are the three main things to investigate for a slow playbook on 500 hosts?]]
* [[What are the two built-in inventory file formats?]]
* [[What are the two categories of Ansible modules?]]
* [[What are the two categories of callback plugins?]]
* [[What are the two display modes in ansible-navigator?]]
* [[What are the two types of inventory?]]
* [[What are variables in Ansible?]]
* [[What authentication methods does WinRM support?]]
* [[What base class do lookup plugins inherit from?]]
* [[What callback plugin profiles memory usage of Ansible tasks?]]
* [[What callback plugin would you use to profile task execution times?]]
* [[What cannot collection role names contain?]]
* [[What class attributes must a callback plugin define?]]
* [[What collection is the `ipaddr` filter now in, and why?]]
* [[What collection provides AWS modules?]]
* [[What collection provides Docker modules and connection plugins?]]
* [[What collection provides Podman modules and connection plugins?]]
* [[What collection provides platform-independent network modules?]]
* [[What command initializes a new collection skeleton?]]
* [[What command initializes a new role skeleton?]]
* [[What command lists all hosts in an inventory?]]
* [[What command runs a rulebook?]]
* [[What command runs an Ansible playbook?]]
* [[What command shows the Ansible version?]]
* [[What configuration file does ansible-lint use?]]
* [[What configuration file does ansible-navigator use?]]
* [[What configuration language does each tool use?]]
* [[What connection plugin is used for network devices?]]
* [[What connection type does ansible-pull use?]]
* [[What controversy surrounds Ansible Lightspeed and the community?]]
* [[What did Ansible 2.5 introduce that changed how network automation worked?]]
* [[What do `async` and `poll` do together in a task?]]
* [[What does "agentless" mean in the context of Ansible?]]
* [[What does YAML stand for?]]
* [[What does `--diff` do?]]
* [[What does `--tags tagged` mean?]]
* [[What does `ANSIBLE_NOCOWS` do?]]
* [[What does `ansible-inventory --list` do?]]
* [[What does `ansible-vault rekey` do?]]
* [[What does `ansible_check_mode` contain?]]
* [[What does `ansible_search_path` contain?]]
* [[What does `become` do?]]
* [[What does `changed_when` do?]]
* [[What does `connection: local` do?]]
* [[What does `delegate_to` do?]]
* [[What does `force_handlers: yes` do?]]
* [[What does `group_names` contain?]]
* [[What does `ignore_errors: true` do?]]
* [[What does `loop_control: extended` provide?]]
* [[What does `meta/main.yml` in a role contain?]]
* [[What does `meta/runtime.yml` in a collection do?]]
* [[What does `meta: end_host` do?]]
* [[What does `meta: flush_handlers` do?]]
* [[What does `meta: reset_connection` do?]]
* [[What does `module_defaults` do at the play or block level?]]
* [[What does `no_log: true` do, and how does it relate to Vault?]]
* [[What does `no_log: true` do?]]
* [[What does `regex_replace` do?]]
* [[What does `run_once: true` do?]]
* [[What does `state: absent` mean in a module?]]
* [[What does `state: latest` mean in package modules?]]
* [[What does `state: present` mean in a module?]]
* [[What does `throttle` do at the task level?]]
* [[What does `wantlist=True` do in a lookup?]]
* [[What does `{{ list | map('extract', dict) }}` do?]]
* [[What does ansible-pull require on each managed node?]]
* [[What does the `--ask-vault-pass` flag do?]]
* [[What does the `ANSIBLE_KEEP_REMOTE_FILES` setting do?]]
* [[What does the `Constructable` base class provide to inventory plugins?]]
* [[What does the `ansible-galaxy` CLI do?]]
* [[What does the `apt` module do?]]
* [[What does the `async` keyword do?]]
* [[What does the `combine` filter do, and why is it so useful?]]
* [[What does the `combine` filter do?]]
* [[What does the `command` module do?]]
* [[What does the `copy` module do?]]
* [[What does the `cron` module do?]]
* [[What does the `debug` module do?]]
* [[What does the `debug` strategy allow?]]
* [[What does the `default` filter do?]]
* [[What does the `docker_container` module do?]]
* [[What does the `fetch` module do?]]
* [[What does the `file` module do?]]
* [[What does the `flatten` filter do?]]
* [[What does the `fqcn` lint rule require?]]
* [[What does the `gather_facts: false` optimization do?]]
* [[What does the `groups` magic variable contain?]]
* [[What does the `hosts` keyword define in a play?]]
* [[What does the `hostvars` magic variable contain?]]
* [[What does the `idempotence` step verify?]]
* [[What does the `lineinfile` module do?]]
* [[What does the `mandatory` filter do?]]
* [[What does the `map` filter do with the `attribute` keyword?]]
* [[What does the `min` lint profile enforce?]]
* [[What does the `never` tag do?]]
* [[What does the `package` module do?]]
* [[What does the `ping` module do?]]
* [[What does the `production` lint profile add on top of `shared`?]]
* [[What does the `safety` lint profile add?]]
* [[What does the `service` module do?]]
* [[What does the `setup` module do?]]
* [[What does the `shell` module do?]]
* [[What does the `synchronize` module do?]]
* [[What does the `user` module do?]]
* [[What does the `wait_for` module do?]]
* [[What does the `yum` module do?]]
* [[What drivers does Molecule support for creating test instances?]]
* [[What encryption algorithm does Ansible Vault use?]]
* [[What environment variable disables Ansible's cowsay output?]]
* [[What features does Ansible Tower/AWX provide?]]
* [[What file extension does the AWS EC2 inventory plugin expect?]]
* [[What file extension is used for Jinja2 templates?]]
* [[What file format does Ansible use for its return data from modules?]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
* [[What filter would you use to base64-encode a string in Ansible?]]
* [[What happened to AnsibleFest after 2022?]]
* [[What happened to `with_items`, `with_dict`, `with_file`, etc.?]]
* [[What happened to `with_items`, `with_dict`, `with_fileglob` etc.?]]
* [[What happens after a rulebook condition matches an event?]]
* [[What happens if a handler is notified multiple times?]]
* [[What happens if a task exceeds its `async` timeout?]]
* [[What happens if two collections provide a module with the same short name?]]
* [[What happens if you reference an undefined variable?]]
* [[What happens if you use `vars_prompt` in Ansible Tower/Controller?]]
* [[What happens if you use a short module name (e.g., "copy") instead of the FQCN in a pos…]]
* [[What happens if you write `version: 1.0` in YAML without quotes?]]
* [[What happens when `run_once` is combined with `serial`?]]
* [[What happens when you apply `become: true` with the `local` connection?]]
* [[What happens when you use `creates` or `removes` with command/shell modules?]]
* [[What happens with `port: 22` vs `port: "22"` in Ansible YAML?]]
* [[What has the highest variable precedence?]]
* [[What has the lowest variable precedence?]]
* [[What indentation is recommended for YAML?]]
* [[What internal arguments does Ansible automatically inject into every module call?]]
* [[What is AWX?]]
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
* [[What is Ansible Lightspeed?]]
* [[What is Ansible Tower?]]
* [[What is BYOM in the context of Ansible Lightspeed?]]
* [[What is Event-Driven Ansible (EDA) and when was it introduced?]]
* [[What is Infrastructure as Code (IaC) and how does Ansible align with it?]]
* [[What is Instance Groups in AWX?]]
* [[What is Jinja2 in the context of Ansible?]]
* [[What is Mitogen for Ansible?]]
* [[What is Private Automation Hub?]]
* [[What is Puppet Bolt, and how is it similar to Ansible?]]
* [[What is SSH ControlPersist?]]
* [[What is `--vault-password-file`?]]
* [[What is `ANSIBLE_ROLES_PATH`?]]
* [[What is `ansible-builder`?]]
* [[What is `ansible-config dump`?]]
* [[What is `ansible-console`?]]
* [[What is `ansible-creator`?]]
* [[What is `ansible-doc` used for?]]
* [[What is `ansible-galaxy collection verify`?]]
* [[What is `ansible-inventory --graph`?]]
* [[What is `ansible-playbook --syntax-check`?]]
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
* [[What is `ansible-test`?]]
* [[What is `ansible-vault encrypt_string` used for?]]
* [[What is `ansible.builtin.add_host`?]]
* [[What is `ansible.builtin.apt_key` and why is it deprecated?]]
* [[What is `ansible.builtin.lineinfile` vs `ansible.builtin.blockinfile`?]]
* [[What is `ansible.builtin.set_stats`?]]
* [[What is `ansible_connection` and where can it be set?]]
* [[What is `ansible_facts` vs top-level fact variables?]]
* [[What is `ansible_host` in inventory?]]
* [[What is `ansible_local`?]]
* [[What is `ansible_loop`?]]
* [[What is `ansible_network_os`, and why is it critical for network automation?]]
* [[What is `ansible_play_batch`?]]
* [[What is `ansible_play_hosts`?]]
* [[What is `ansible_play_name`?]]
* [[What is `ansible_port`?]]
* [[What is `ansible_python_interpreter`?]]
* [[What is `ansible_run_tags` and `ansible_skip_tags`?]]
* [[What is `ansible_version`?]]
* [[What is `any_errors_fatal` and when would you use it?]]
* [[What is `become_method`?]]
* [[What is `become_user`?]]
* [[What is `changed_when: false` used for?]]
* [[What is `check_mode: true` at the task level?]]
* [[What is `cli_command` vs platform-specific modules (e.g., ios_command)?]]
* [[What is `collections:` at the play level?]]
* [[What is `collections` keyword in a playbook?]]
* [[What is `creates` parameter in command/shell modules?]]
* [[What is `delegate_facts: true`?]]
* [[What is `delegate_to`?]]
* [[What is `diff: true` at the task level?]]
* [[What is `fact_caching`, and what backends does it support?]]
* [[What is `gather_subset` and how does it speed up fact gathering?]]
* [[What is `group_by` module?]]
* [[What is `groups` in Ansible?]]
* [[What is `hash_behaviour` in ansible.cfg?]]
* [[What is `host_key_checking`?]]
* [[What is `ignore_errors`?]]
* [[What is `ignore_unreachable`?]]
* [[What is `include_role` vs `import_role`?]]
* [[What is `inventory_dir`?]]
* [[What is `inventory_hostname_short`?]]
* [[What is `inventory_hostname`?]]
* [[What is `max_fail_percentage` used for?]]
* [[What is `max_fail_percentage`?]]
* [[What is `meta: clear_facts`?]]
* [[What is `meta: clear_host_errors`?]]
* [[What is `meta: end_play`?]]
* [[What is `omit`?]]
* [[What is `order` in a play?]]
* [[What is `play_hosts`?]]
* [[What is `playbook_dir`?]]
* [[What is `register` and what does the registered variable contain?]]
* [[What is `register` in Ansible?]]
* [[What is `removes` parameter in command/shell modules?]]
* [[What is `role_path`?]]
* [[What is `set_fact`?]]
* [[What is `supports_check_mode` in module development?]]
* [[What is `until` / `retries` / `delay` in a task?]]
* [[What is `vars_prompt`?]]
* [[What is `wait_for_connection` used for?]]
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[What is a "tombstone" entry in Ansible's collection routing?]]
* [[What is a Decision Environment?]]
* [[What is a Fully Qualified Collection Name (FQCN), and why does it matter post-migration?]]
* [[What is a Fully Qualified Collection Name (FQCN)?]]
* [[What is a Job Template in AWX/automation controller?]]
* [[What is a Molecule scenario?]]
* [[What is a Smart Inventory?]]
* [[What is a Vault ID, and why would you use multiple?]]
* [[What is a Workflow Job Template?]]
* [[What is a Workflow in Tower/AWX?]]
* [[What is a callback plugin?]]
* [[What is a collection namespace?]]
* [[What is a group in an Ansible inventory?]]
* [[What is a lookup plugin in Ansible?]]
* [[What is a play in Ansible?]]
* [[What is a playbook `import_playbook`?]]
* [[What is a practical use case for async with poll > 0?]]
* [[What is a pre_task and post_task?]]
* [[What is a requirements.yml file for Galaxy?]]
* [[What is a rolling update strategy?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
* [[What is an "action plugin" and how does it differ from a module?]]
* [[What is an Ansible Execution Environment (EE)?]]
* [[What is an Ansible callback whitelist?]]
* [[What is an Ansible inventory?]]
* [[What is ansible-lint?]]
* [[What is ansible.cfg?]]
* [[What is automation mesh?]]
* [[What is callback plugin `profile_tasks`?]]
* [[What is callback plugin `timer`?]]
* [[What is configuration drift?]]
* [[What is diff mode?]]
* [[What is fact caching?]]
* [[What is idempotency?]]
* [[What is provisioning?]]
* [[What is the "Norway Problem" in YAML, and how does it affect Ansible?]]
* [[What is the "canary deployment" pattern in Ansible?]]
* [[What is the "cow" in Ansible output?]]
* [[What is the "golden image" pattern using Ansible?]]
* [[What is the "idempotence" test phase in Molecule?]]
* [[What is the "include_role with conditionals" anti-pattern?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[What is the "pre_tasks / post_tasks" idiom for rolling updates?]]
* [[What is the "routing" configuration in the context of collections migration?]]
* [[What is the "two-stage" or "delegate and register" pattern?]]
* [[What is the Ansiballz framework?]]
* [[What is the Ansible Community Steering Committee?]]
* [[What is the Ansible Lightspeed "intelligent assistant"?]]
* [[What is the Ansible Tower rebrand name?]]
* [[What is the Ansible equivalent of try/catch/finally?]]
* [[What is the Community Working Group specifically?]]
* [[What is the FQCN for the AWS EC2 module?]]
* [[What is the Module Replacer framework?]]
* [[What is the Red Hat Certified Specialist in Ansible Automation exam called?]]
* [[What is the Tower/AWX REST API used for?]]
* [[What is the YAML octal number gotcha?]]
* [[What is the `.retry` file that Ansible creates?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
* [[What is the `INJECT_FACTS_AS_VARS` configuration?]]
* [[What is the `INTERPRETER_PYTHON` configuration, and why was `auto` mode added?]]
* [[What is the `all` group?]]
* [[What is the `ansible.builtin.debug` module's `var` vs `msg` parameter?]]
* [[What is the `ansible.builtin.find` module?]]
* [[What is the `ansible.builtin.package` module?]]
* [[What is the `ansible.builtin.pause` module?]]
* [[What is the `ansible.builtin.reboot` module?]]
* [[What is the `ansible.builtin.script` module?]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
* [[What is the `ansible.posix` collection?]]
* [[What is the `ansible.windows` collection?]]
* [[What is the `ansible_become_exe` variable?]]
* [[What is the `ansible_connection` variable set to for network devices?]]
* [[What is the `ansible_date_time` fact?]]
* [[What is the `ansible_managed` variable?]]
* [[What is the `argument_spec` in a custom module?]]
* [[What is the `ask_pass` setting?]]
* [[What is the `assert` module used for?]]
* [[What is the `auto` interpreter discovery in Ansible?]]
* [[What is the `auto` inventory plugin?]]
* [[What is the `become_method` setting and what values does it support?]]
* [[What is the `block` keyword?]]
* [[What is the `cli_parse` module used for?]]
* [[What is the `cloud.terraform` collection?]]
* [[What is the `constructed` inventory plugin?]]
* [[What is the `converge` step in Molecule?]]
* [[What is the `debug` module's `verbosity` parameter?]]
* [[What is the `debug` strategy?]]
* [[What is the `environment` keyword at the task/play/block level?]]
* [[What is the `environment` keyword used for?]]
* [[What is the `expect` module?]]
* [[What is the `fail` module?]]
* [[What is the `failed_when: false` idiom?]]
* [[What is the `forks` setting, and what is its default value?]]
* [[What is the `gathered` state in network resource modules?]]
* [[What is the `host_pinned` strategy?]]
* [[What is the `httpapi` connection plugin?]]
* [[What is the `ipaddr` filter?]]
* [[What is the `listen` directive on handlers?]]
* [[What is the `local_action` keyword?]]
* [[What is the `lookup` plugin?]]
* [[What is the `loop_control` directive?]]
* [[What is the `meta` module used for?]]
* [[What is the `network_cli` connection plugin used for?]]
* [[What is the `no_log: true` directive?]]
* [[What is the `no_log` lint rule about?]]
* [[What is the `notify` keyword?]]
* [[What is the `omit` variable in Ansible?]]
* [[What is the `password_hash` filter?]]
* [[What is the `pause` module?]]
* [[What is the `psrp` connection plugin, and how does it differ from `winrm`?]]
* [[What is the `query` function, and how does it differ from `lookup`?]]
* [[What is the `raw` module, and when is it needed?]]
* [[What is the `raw` module?]]
* [[What is the `register` keyword?]]
* [[What is the `retry_until` pattern in Ansible?]]
* [[What is the `script` module?]]
* [[What is the `serial` keyword?]]
* [[What is the `service_facts` module?]]
* [[What is the `set_fact` module's `cacheable` option?]]
* [[What is the `set_stats` module?]]
* [[What is the `shared` lint profile intended for?]]
* [[What is the `synchronize` module?]]
* [[What is the `template` module's `output_encoding` parameter?]]
* [[What is the `ternary` filter?]]
* [[What is the `throttle` keyword?]]
* [[What is the `timeout` connection parameter?]]
* [[What is the `to_json` and `from_json` filter pair used for?]]
* [[What is the `ungrouped` group?]]
* [[What is the `uri` module?]]
* [[What is the `win_updates` module used for?]]
* [[What is the automation controller REST API used for?]]
* [[What is the default Ansible Galaxy server URL?]]
* [[What is the default base image used by ansible-builder?]]
* [[What is the default become method?]]
* [[What is the default connection plugin in Ansible?]]
* [[What is the default driver in modern Molecule?]]
* [[What is the default number of forks?]]
* [[What is the default poll interval?]]
* [[What is the default reboot timeout?]]
* [[What is the default strategy, and what is its key characteristic?]]
* [[What is the default verifier in Molecule 6+?]]
* [[What is the deprecation cycle length in ansible-core for features?]]
* [[What is the difference between `ansible_play_hosts` and `ansible_play_hosts_all`?]]
* [[What is the difference between `command` and `shell` modules?]]
* [[What is the difference between `community.docker.docker` and `community.docker.docker_a…]]
* [[What is the difference between `defaults/main.yml` and `vars/main.yml`?]]
* [[What is the difference between `free` and `host_pinned`?]]
* [[What is the difference between `ignore_errors: true` and using a `rescue` block?]]
* [[What is the difference between `include_tasks` and `import_tasks`?]]
* [[What is the difference between `inventory_hostname` and `ansible_hostname`?]]
* [[What is the difference between `is match` and `is search` tests?]]
* [[What is the difference between `lookup()` and `query()` in Ansible?]]
* [[What is the difference between `network_cli` and `httpapi` for network devices?]]
* [[What is the difference between `vars`, `vars_files`, and `vars_prompt`?]]
* [[What is the difference between `with_items` and `loop`?]]
* [[What is the difference between a Decision Environment and an Execution Environment in E…]]
* [[What is the difference between a Galaxy role and a Galaxy collection?]]
* [[What is the difference between a lookup and a filter?]]
* [[What is the difference between a playbook and a play?]]
* [[What is the difference between a playbook and an ad-hoc command?]]
* [[What is the difference between an inventory script and an inventory plugin?]]
* [[What is the difference between ansible-dev-tools and ansible-core?]]
* [[What is the difference between dot notation and array notation for variables?]]
* [[What is the difference between role defaults and role vars in terms of precedence?]]
* [[What is the difference between stdout callbacks and non-stdout callbacks?]]
* [[What is the difference between variable names and environment variables?]]
* [[What is the etymology of the word "ansible"?]]
* [[What is the exact search order for ansible.cfg files (highest to lowest priority)?]]
* [[What is the fundamental difference between `import_*` and `include_*`?]]
* [[What is the galaxy.yml file in a collection?]]
* [[What is the gotcha with `run_once` and `serial`?]]
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
* [[What is the major limitation of check mode?]]
* [[What is the maximum recommended inventory size for a single Ansible control node?]]
* [[What is the most downloaded Ansible Galaxy role author namespace?]]
* [[What is the namespace.collection format, and why does it matter?]]
* [[What is the naming convention for Ansible environment variable overrides?]]
* [[What is the obscure `ANSIBLE_FORCE_COLOR` environment variable?]]
* [[What is the precedence order if the same variable is defined in group_vars for a parent…]]
* [[What is the push-based model in Ansible?]]
* [[What is the relationship between Ansible Tower and Automation Controller?]]
* [[What is the relationship between Jinja2's built-in filters and Ansible's filters?]]
* [[What is the relationship between ansible-core and the ansible package?]]
* [[What is the security concern with `./ansible.cfg` in the current directory?]]
* [[What is the security risk of using `shell` or `command` modules with user-supplied vari…]]
* [[What is the security warning about Vault and "data at rest" vs. "data in use"?]]
* [[What is the single most important thing to remember about extra vars (-e)?]]
* [[What is the standard collection directory structure?]]
* [[What is the standard directory structure of an Ansible role?]]
* [[What is the standard role directory structure?]]
* [[What is the structure of an EDA rulebook?]]
* [[What is the syntax of an ad-hoc command?]]
* [[What key inventory object methods are used in plugin development?]]
* [[What keyword defines tasks in a playbook?]]
* [[What language is Ansible written in?]]
* [[What language is Ansible written in? What about Puppet, Chef, and SaltStack?]]
* [[What major AAP 2.5 feature unified the user experience across components?]]
* [[What makes SaltStack's execution speed notably faster than Ansible for large fleets?]]
* [[What method must a lookup plugin implement?]]
* [[What method prefix do v2 callback plugin methods use?]]
* [[What module adds or modifies lines in files?]]
* [[What module checks the status of a previously fired async task?]]
* [[What module copies files from remote to local?]]
* [[What module creates and manages Podman containers?]]
* [[What module creates directories?]]
* [[What module gathers facts by default at the start of each play?]]
* [[What module is used to gather system information?]]
* [[What module is used to reboot a host?]]
* [[What module manages SELinux?]]
* [[What module manages cron jobs?]]
* [[What module manages firewall rules?]]
* [[What module manages systemd services?]]
* [[What module manages users?]]
* [[What module tests if a file exists on a remote host?]]
* [[What module would you use to wait for a port to become available?]]
* [[What must a filter plugin Python file contain?]]
* [[What open-source tool can dramatically speed up Ansible by replacing SSH with a custom …]]
* [[What other connection optimizations exist beyond Mitogen?]]
* [[What other tools did Michael DeHaan create before Ansible?]]
* [[What playbook filename does ansible-pull look for by default?]]
* [[What port does Ansible use by default for SSH connections?]]
* [[What port does WinRM use by default for Ansible Windows management?]]
* [[What protocol does Ansible use to manage Windows hosts?]]
* [[What rule does `no-changed-when` enforce?]]
* [[What science fiction novel first coined the word "ansible," and who wrote it?]]
* [[What shift in AAP 2.5 changed how the platform is deployed?]]
* [[What special group exists in every Ansible inventory?]]
* [[What speedup can Mitogen provide?]]
* [[What subcommand in ansible-navigator lists available collections inside an EE?]]
* [[What symbol starts a list item in YAML?]]
* [[What tasks cannot be delegated?]]
* [[What timeout does the reboot module use by default?]]
* [[What tool is used to build Execution Environments?]]
* [[What two methods must a custom inventory plugin implement?]]
* [[What two open-source projects did Michael DeHaan create before Ansible, both at Red Hat?]]
* [[What types of errors do NOT trigger the rescue block?]]
* [[What valid `type` values can be used in argument_spec?]]
* [[What verifiers does Molecule support?]]
* [[What versioning scheme does ansible-core follow vs the ansible package?]]
* [[What was "ansible-base" and when did it appear?]]
* [[What was Michael DeHaan's job before creating Ansible, and why did he leave?]]
* [[What was significant about Ansible 1.0, and when was it released?]]
* [[What was the approximate annual cost of Ansible Tower licensing before the AAP rebrand?]]
* [[What was the first AnsibleFest, and when did it take place?]]
* [[What was the first commit to the Ansible GitHub repository, and approximately when?]]
* [[What was the major architectural change in Ansible 2.0?]]
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
* [[What year did Ansible 2.0 introduce the new execution engine?]]
* [[What year did Ansible Galaxy launch?]]
* [[What year did Ansible Tower (the commercial UI product) first appear?]]
* [[What year was Ansible Lightspeed announced?]]
* [[What year was Ansible first released?]]
* [[What year was Event-Driven Ansible (EDA) first introduced?]]
* [[When and by whom was Ansible acquired?]]
* [[When did Ansible collections replace the monolithic package?]]
* [[When did Ansible drop Python 2 support on the control node?]]
* [[When did IBM acquire Red Hat?]]
* [[When did Red Hat acquire Ansible?]]
* [[When did the collections concept first appear in Ansible?]]
* [[When do handlers execute?]]
* [[When is ansible-pull appropriate?]]
* [[When is ansible-pull preferred over the normal push model?]]
* [[When should you use a role vs a simple task file?]]
* [[When should you use ad-hoc commands vs playbooks?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[When was Ansible Lightspeed generally available?]]
* [[When was Ansible Tower renamed to automation controller?]]
* [[When was the last time the migration script (migrate.py) was run to move content from t…]]
* [[When would you use ansible-pull instead of the default push model?]]
* [[When would you use the `free` strategy?]]
* [[When would you use the `local` connection plugin?]]
* [[Where are remote temporary files stored on managed nodes?]]
* [[Where can variables be defined?]]
* [[Where did the Ansible community move after leaving IRC?]]
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[Where do network modules execute -- on the control node or managed node?]]
* [[Where does Molecule store scenario configuration?]]
* [[Where does the Steering Committee conduct business?]]
* [[Where does the name "Ansible" come from?]]
* [[Where is the default inventory file located?]]
* [[Where should custom filter plugins be placed?]]
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
* [[Which config management tool uses a "master-minion" architecture with a ZeroMQ message …]]
* [[Which of the "big four" (Ansible, Puppet, Chef, Salt) are agentless?]]
* [[Which tool came first chronologically: Puppet, Chef, Ansible, or Salt?]]
* [[Which tools are push-based vs. pull-based by default?]]
* [[Who created Ansible and when?]]
* [[Who created Ansible, and in what year was it first released?]]
* [[Who is Jeff Geerling and why is he significant to the Ansible community?]]
* [[Why do Ansible community package version numbers jump from 2.10 to 3.0, 4.0, etc., whil…]]
* [[Why do Execution Environments exist when Python virtual environments (venvs) already ex…]]
* [[Why do you always use `{{ }}` in Ansible except in `when` clauses?]]
* [[Why does Ansible have separate Python requirements for control node vs. managed nodes?]]
* [[Why does Ansible mark all strings returned by modules as "Unsafe"?]]
* [[Why does Ansible refuse to load an ansible.cfg from a world-writable current directory?]]
* [[Why don't Juniper Junos Ansible modules require Python on the device?]]
* [[Why is CredSSP sometimes needed for Windows automation?]]
* [[Why is YAML 1.2 relevant to Ansible's future?]]
* [[Why is `hash_behaviour: merge` deprecated?]]
* [[Why was the monolithic repo problematic?]]
* [[You deploy configuration but servers show inconsistent settings. How do you detect and …]]
* [[You have a slow playbook on 500 hosts. What do you investigate first?]]
* [[ansible-navigator: modern replacement for ansible-playbook]]
!! MOC — flashcards
Every atom extracted from a ''flashcard'' source (135 total).
* [[AWX, Ansible Tower, and Ansible Automation Platform explained]]
* [[Ansible Collections: packaging and distribution format]]
* [[Ansible Dynamic Inventory]]
* [[Ansible Facts and the gather_facts task]]
* [[Ansible Galaxy: community hub for roles and collections]]
* [[Ansible Modules]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[Ansible `template` module]]
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[Ansible control node]]
* [[Ansible debug module: printing messages during playbook execution]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
* [[Ansible facts: auto-discovered host variables]]
* [[Ansible handlers: conditional, once-only task execution]]
* [[Ansible in a Multi-Cloud Environment]]
* [[Ansible installation and configuration on Linux]]
* [[Ansible inventory file: definition and configuration]]
* [[Ansible managed node]]
* [[Ansible manages Windows servers via WinRM]]
* [[Ansible performance optimization for large inventories]]
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[Ansible strategy plugins control task-execution ordering across hosts]]
* [[Ansible strategy plugins: built-in options and defaults]]
* [[Ansible vs. Chef/Puppet: key architectural differences]]
* [[Ansible: Managing Multiple Environments with Separate Inventories]]
* [[Ansible: agentless IT automation tool]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[Can you provide an example of a task you've automated to improve data center efficiency?]]
* [[Configuring Ansible for Network Automation]]
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[Dynamic inventory in Ansible]]
* [[Explain how to use the --check option for running Ansible in check mode.]]
* [[Explain how to view job output and logs in Ansible Tower.]]
* [[Explain the Difference between Forks and Serial & Throttle.]]
* [[Explain the difference between tasks, handlers, and defaults in an Ansible Role.]]
* [[Explain the importance of version control with Ansible playbooks.]]
* [[Explain the key components of Ansible.]]
* [[Explain the process of editing an encrypted file with Ansible Vault.]]
* [[Explain the purpose of the "copy" module in Ansible.]]
* [[Explain the purpose of the --diff option in Ansible playbooks.]]
* [[Explain the role of Ansible Facts in playbooks and how to debug them.]]
* [[Explain the role of Ansible Tower in a CI/CD pipeline.]]
* [[Explain the use of Ansible roles in network automation.]]
* [[Explain the use of the "ec2.py" script for AWS dynamic inventory.]]
* [[Explain the use of the "hosts" directive in a playbook.]]
* [[Explain the use of the -vvv option when running Ansible commands.]]
* [[File '/tmp/exercise' includes the following content]]
* [[Handling Dependencies]]
* [[Have you used automation tools like PowerShell or Ansible for server management tasks?]]
* [[How can you run a specific task or play within an Ansible playbook for testing?]]
* [[How can you test and validate a dynamic inventory script?]]
* [[How can you troubleshoot SSH connection issues with Ansible?]]
* [[How can you use tags in Ansible Roles?]]
* [[How do you approach automating repetitive tasks in a data center?]]
* [[How do you create an encrypted file using Ansible Vault?]]
* [[How do you create and manage inventories in Ansible Tower?]]
* [[How do you define variables in Ansible Playbooks?]]
* [[How do you enable verbose mode for Ansible playbooks?]]
* [[How do you execute a single ad-hoc Ansible command?]]
* [[How do you include external tasks in an Ansible Playbook?]]
* [[How do you install and configure Ansible Tower?]]
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
* [[How do you manage secrets in Ansible?]]
* [[How do you pass variables to Ansible at runtime?]]
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
* [[How do you set breakpoints or pause execution within an Ansible role for debugging?]]
* [[How do you set up passwordless SSH for Ansible?]]
* [[How do you structure a good playbook or role?]]
* [[How do you test Ansible safely?]]
* [[How do you troubleshoot failed jobs in Ansible Tower?]]
* [[How do you use the "shell" module in Ansible?]]
* [[How does Ansible connect to managed nodes?]]
* [[How does Ansible differ from other configuration management tools?]]
* [[How does Ansible support network automation?]]
* [[How to find out the data type of a certain variable in one of the playbooks?]]
* [[How to make the variable "use_var" optional?]]
* [[Idempotence is the core contract of Ansible modules]]
* [[If the value of certain variable is 1, you would like to use the value "one", otherwise…]]
* [[Installing Ansible Galaxy roles from CLI and requirements file]]
* [[Limit Ansible playbook execution to specific hosts]]
* [[Listing and inspecting Ansible modules with ansible-doc]]
* [[Migrating Legacy Scripts to Ansible]]
* [[Modify the following task to use a variable instead of the value "zlib" and have "zlib"…]]
* [[Molecule: Ansible role testing framework]]
* [[Multi-Tier Application Deployment]]
* [[Optimizing Ansible Playbook Performance]]
* [[Orchestration in Ansible: coordinating tasks across systems]]
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
* [[Rolling Updates with Zero Downtime]]
* [[The value of a certain variable you use is the string "True". You would like the value …]]
* [[The variable 'whoami' defined in the following places:]]
* [[Troubleshooting Ansible module issues]]
* [[Troubleshooting Playbook Failures]]
* [[True or False? Ansible follows the mutable infrastructure paradigm]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[What are Ansible "playbooks"?]]
* [[What are Ansible "tags"?]]
* [[What are common issues you might encounter with dynamic inventories, and how would you …]]
* [[What are idempotency issues in infrastructure automation and how are they avoided?]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
* [[What are some common pitfalls in Ansible, and how can they be avoided?]]
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[What information is available in the output when using the --check option?]]
* [[What is Ansible Container, and how does it integrate with Docker?]]
* [[What is Ansible Networking, and how is it different from traditional Ansible?]]
* [[What is Ansible Tower Surveys, and how do they work?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
* [[What is YAML, and why is it used in Ansible?]]
* [[What is a task in Ansible?]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
* [[What is the difference between an Ansible playbook and a role?]]
* [[What is the purpose of an Ansible Playbook?]]
* [[What is the syntax for an Ansible Playbook?]]
* [[What kind of automation you wouldn't do with Ansible and why?]]
* [[What language are Ansible playbooks written in?]]
* [[What makes good Ansible?]]
* [[What steps would you take to debug an issue with Ansible Container?]]
* [[What steps would you take to debug an issue within an Ansible role?]]
* [[What steps would you take to troubleshoot a failed Ansible playbook?]]
* [[What would be the result of the following play?]]
* [[What's your experience with Ansible?]]
* [[When the value '2017'' will be used in this case: `{{ lookup('env', 'BEST_YEAR') | defa…]]
* [[Why Use Ansible Collections?]]
* [[Why is Ansible more dangerous than shell scripts at scale?]]
* [[Why is shell in Ansible dangerous?]]
* [[Write a filter to capitalize a string]]
* [[Write a playbook to deploy the file ‘/tmp/system_info’ on all hosts except for controll…]]
* [[Write a playbook to install ‘zlib’ and ‘vim’ on all hosts if the file ‘/tmp/mario’ exis…]]
* [[Write a single task that verifies all the files in files_list variable exist on the host]]
* [[ansible-doc: offline module documentation reference]]
* [[ansible_ssh_common_args: appending SSH args to all SSH connections]]
!! MOC — footguns
Every atom extracted from a ''footgun'' source (8 total).
* [[Ansible playbooks without --limit run against all inventory]]
* [[Ansible variable precedence footguns]]
* [[Ansible variable precedence silently shadows lower-priority settings]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
* [[Ansible's idempotency guarantee is aspirational, not enforced]]
* [[Common inventory mistakes: hardcoding, secrets, group membership, ungrouped hosts]]
* [[Global become: true escalates all tasks]]
* [[Shell module instead of apt module for packages (idempotency loss)]]
!! MOC — other
Every atom extracted from a ''other'' source (128 total).
* [[Always limit-test new playbooks before fleet-wide execution]]
* [[Always run --check --diff before production Ansible changes]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[Ansible async/poll decouples long task submission from completion]]
* [[Ansible became the dominant network automation tool despite being designed for servers]]
* [[Ansible configures running infrastructure; Terraform creates it]]
* [[Ansible execution hierarchy: playbook > play > task; roles bundle and reuse]]
* [[Ansible handlers skip entirely if the play fails]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Ansible ios_command is not idempotent for configuration]]
* [[Ansible network modules provide declarative multi-vendor configuration]]
* [[Ansible originated from a weekend prototype in February 2012]]
* [[Ansible playbook architecture: plays, tasks, roles]]
* [[Ansible provisioner integrates configuration management into Packer builds]]
* [[Ansible template/copy validate: prevents config file disasters]]
* [[Ansible variable design: where to put tunables]]
* [[Ansible variable precedence from lowest to highest: defaults → inventory → playbook → task → -e flag]]
* [[Ansible variable precedence: bookends and gradient]]
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
* [[Ansible's SSH-based agentless execution model]]
* [[Ansible's agentless design: SSH over a custom control protocol]]
* [[Ansible's cowsay Easter egg was designed for morale]]
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[Audit mixed-distro fleets with Ansible to identify configuration drift]]
* [[Become escalates task privileges to a different user or method]]
* [[Bootstrap Python on fresh OS installs with raw module]]
* [[Bulk fact collection enables fleet-wide inventory and audits]]
* [[Check mode simulates changes without executing destructive operations]]
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[Collections split in 2020 broke thousands of existing Ansible playbooks]]
* [[Compliance remediation requires baseline capture and staged testing]]
* [[Config drift encodes production fixes; reverting it re-introduces the problems]]
* [[Connection plugins determine how Ansible communicates with targets]]
* [[Continuous compliance loop: scan, parse, remediate, verify, archive]]
* [[Cross-platform provisioning uses OS-family conditionals and variable includes]]
* [[Customize task failure and change status with failed_when and changed_when]]
* [[Default inventory pointing to production invites unintended changes]]
* [[Delegated tasks see target host facts, not delegation-target facts]]
* [[Delegation runs a task on a different host while preserving target context]]
* [[Directory-based variable organization separates variables from inventory]]
* [[Each play targets hosts independently; handlers deduplicate and roles standardize structure]]
* [[Editing inventory during playbook execution causes races]]
* [[Eight Ansible variable precedence levels you need]]
* [[Execution Environments solved the dependency-conflict problem in Ansible]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
* [[Fact Caching Returns Stale System Information]]
* [[Fact caching avoids expensive repeated gathering]]
* [[Fact caching avoids multi-minute delays on large fleets]]
* [[Flat inventory prevents efficient fleet targeting]]
* [[Fleet diagnostics demand parallelism; forks multiply time]]
* [[Fleet incident response: assessment and targeted remediation]]
* [[Forks control Ansible parallelism]]
* [[Git repository as source of truth for homelab infrastructure]]
* [[Handlers Only Fire When Task Status Changes]]
* [[Handlers run once at play end, triggered by task notifications]]
* [[Health Checks Verify Service Availability After Changes]]
* [[High fork counts cause connection exhaustion and cascading failures]]
* [[Homelabs mirror enterprise IaC, creating bidirectional feedback loops]]
* [[How cascading mistakes lead to infrastructure incidents]]
* [[Idempotency as default, exceptions with shell and command modules]]
* [[Idempotency verification requires two consecutive runs showing zero changes]]
* [[Idempotent tasks use built-in modules or changed_when predicates]]
* [[Inventory is more than a flat list of hosts]]
* [[Inventory is one layer in a larger variable precedence system]]
* [[Inventory patterns use set operators for host selection]]
* [[Inventory structure: hosts, groups, variables, and sources]]
* [[Jinja2 Expressions Must Be Quoted in YAML Values]]
* [[Jinja2 Whitespace Control Prevents Extra Blank Lines]]
* [[Jinja2 tests check conditions in when clauses and conditionals]]
* [[Lookups read external data into variables during playbook execution]]
* [[Michael DeHaan stepped back from Ansible after Red Hat acquisition]]
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
* [[Modules execute on targets; plugins run on the controller and extend Ansible]]
* [[Modules, plugins, and collections in Ansible architecture]]
* [[Molecule made test-driven Ansible development practical]]
* [[Non-idempotent destructive operations cause data loss on re-runs]]
* [[One slow host blocks the entire play during fact gathering]]
* [[One slow host stalls the entire batch unless timeouts are aggressive]]
* [[Parallel reboots cause cascading failures across multi-tier stacks]]
* [[Passing Variables and Vault to Ansible in Packer]]
* [[Play and task keywords coexist in YAML; indentation signals scope]]
* [[Playbook execution flows through pre_tasks, roles, tasks, post_tasks with distinct import/include behavior]]
* [[Playbook failure diagnosis pattern]]
* [[Playbook files contain nested structures that are not visually distinct]]
* [[Playbook testing combines linting, role integration tests, and idempotency checks]]
* [[Playbooks compose idempotent tasks with handlers for change notification]]
* [[Playbooks express desired state through ordered tasks]]
* [[Playbooks support flow control through conditionals, loops, and stateful command execution]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
* [[Prefer native modules over shell/command for idempotency]]
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[Progressive Environment-Based Rollout Reduces Blast Radius]]
* [[Progressive Rollout Validates Changes at Each Environment Stage]]
* [[Red Hat open-sourced AWX while selling Ansible Tower as a commercial product]]
* [[Role dependencies require explicit version pinning to prevent conflicts]]
* [[Roles organize reusable Ansible code into directories]]
* [[Roles standardize reusable automation into a predictable directory structure]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
* [[Running fleet commands without --limit risks massive misconfiguration]]
* [[SSH host key verification modes differ in security properties]]
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
* [[Safe infrastructure patch rollouts use progressive stages and circuit breakers]]
* [[Selective fact gathering skips unnecessary system queries]]
* [[Serial Batching and Max-Failure Limit Contain Rollout Risk]]
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[Shell provisioners run in non-interactive context; use Ansible for complex configuration]]
* [[Shortcuts under deadline pressure compound into cascading failures]]
* [[Standardize distro families by workload role, not globally]]
* [[Structured Playbooks Provide Auditability and Idempotency]]
* [[Tasks handling secrets need no_log: true]]
* [[Transient SSH Failures Should Be Retried Automatically]]
* [[Use failed_when instead of blanket ignore_errors]]
* [[Use no_log: true on tasks handling secrets]]
* [[Use purpose-built modules over shell; adopt FQCNs to avoid collisions]]
* [[Variable precedence: learn role defaults and extra vars, not all 22 levels]]
* [[Variables set in one play don't automatically carry to the next play]]
* [[Vault Passwords Must Not Appear in Shell History or Plain Text]]
* [[YAML choice for Ansible prioritized non-programmer accessibility]]
* [[YAML inventory structure enables hierarchical host groups with inheritance]]
* [[Zuul's circular dependency: testing Ansible with Ansible]]
* [[ansible-pull inverts the model to pull-based configuration management]]
* [[become: true Must Be Set at Task Level for Privilege Escalation]]
* [[fd's simple syntax handles DevOps file searches efficiently]]
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
* [[lineinfile is for single lines, not file management]]
* [[lineinfile is unsuited for multi-line or overlapping content]]
* [[serial: 1 is Unnecessarily Slow for Large Fleets]]
!! MOC — confidence high
Atoms with confidence in the ''high'' band (992 total).
* [[A playbook fails to decrypt Vault data. What do you check?]]
* [[A variable is defined in playbook group_vars/all and also in inventory group_vars/webse…]]
* [[AWX, Ansible Tower, and Ansible Automation Platform explained]]
* [[Always limit-test new playbooks before fleet-wide execution]]
* [[Always run --check --diff before production Ansible changes]]
* [[Ansible Collections: packaging and distribution format]]
* [[Ansible Dynamic Inventory]]
* [[Ansible Galaxy: community hub for roles and collections]]
* [[Ansible Modules]]
* [[Ansible SSH pipelining reduces connection round-trips]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[Ansible `template` module]]
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[Ansible async/poll decouples long task submission from completion]]
* [[Ansible became the dominant network automation tool despite being designed for servers]]
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
* [[Ansible configures running infrastructure; Terraform creates it]]
* [[Ansible control node]]
* [[Ansible debug module: printing messages during playbook execution]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Ansible execution hierarchy: playbook > play > task; roles bundle and reuse]]
* [[Ansible facts: auto-discovered host variables]]
* [[Ansible handlers skip entirely if the play fails]]
* [[Ansible handlers: conditional, once-only task execution]]
* [[Ansible in a Multi-Cloud Environment]]
* [[Ansible inventory file: definition and configuration]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Ansible ios_command is not idempotent for configuration]]
* [[Ansible is sometimes described as "procedural" while Puppet is "declarative." What does…]]
* [[Ansible managed node]]
* [[Ansible manages Windows servers via WinRM]]
* [[Ansible network modules provide declarative multi-vendor configuration]]
* [[Ansible originated from a weekend prototype in February 2012]]
* [[Ansible playbook architecture: plays, tasks, roles]]
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[Ansible playbooks without --limit run against all inventory]]
* [[Ansible provisioner integrates configuration management into Packer builds]]
* [[Ansible strategy plugins control task-execution ordering across hosts]]
* [[Ansible strategy plugins: built-in options and defaults]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[Ansible template/copy validate: prevents config file disasters]]
* [[Ansible variable design: where to put tunables]]
* [[Ansible variable precedence footguns]]
* [[Ansible variable precedence from lowest to highest: defaults → inventory → playbook → task → -e flag]]
* [[Ansible variable precedence silently shadows lower-priority settings]]
* [[Ansible variable precedence: bookends and gradient]]
* [[Ansible vs. Chef/Puppet: key architectural differences]]
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
* [[Ansible's SSH-based agentless execution model]]
* [[Ansible's agentless design: SSH over a custom control protocol]]
* [[Ansible's cowsay Easter egg was designed for morale]]
* [[Ansible's default serial (100%) causes simultaneous service restarts]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[Ansible's idempotency guarantee is aspirational, not enforced]]
* [[Ansible: Managing Multiple Environments with Separate Inventories]]
* [[Ansible: agentless IT automation tool]]
* [[Become escalates task privileges to a different user or method]]
* [[Before Ansible 2.10, how was all community-contributed content structured?]]
* [[Besides git, what other VCS does ansible-pull support?]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[Bootstrap Python on fresh OS installs with raw module]]
* [[Bulk fact collection enables fleet-wide inventory and audits]]
* [[Can Ansible Vault encrypt an entire directory?]]
* [[Can Ansible use SSH to manage Windows?]]
* [[Can `serial` accept a list? What does that do?]]
* [[Can `serial` be expressed as a percentage?]]
* [[Can a handler notify another handler?]]
* [[Can async tasks run in check mode?]]
* [[Can handlers notify other handlers?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
* [[Can rulebooks call Ansible Automation Platform job templates?]]
* [[Can tags be applied to roles?]]
* [[Can tags be inherited through `include_tasks`?]]
* [[Can you apply tags to roles, blocks, and imports?]]
* [[Can you encrypt only specific variables in a file?]]
* [[Can you force a specific task to always or never run in check mode?]]
* [[Can you install collections from a tarball?]]
* [[Can you loop over `import_tasks`?]]
* [[Can you override an extra var with set_fact?]]
* [[Can you provide an example of a task you've automated to improve data center efficiency?]]
* [[Can you run Ansible on Windows as a control node?]]
* [[Can you set strategy globally?]]
* [[Can you set variables with magic variable names?]]
* [[Can you use `when` conditions with `import_tasks`?]]
* [[Can you use more than one connection plugin per host in a single play?]]
* [[Can you use multiple vault passwords in a single playbook run?]]
* [[Can you write custom Ansible modules?]]
* [[Check mode simulates changes without executing destructive operations]]
* [[Collections are distributable packages of roles, modules, and plugins]]
* [[Collections split in 2020 broke thousands of existing Ansible playbooks]]
* [[Compliance remediation requires baseline capture and staged testing]]
* [[Config drift encodes production fixes; reverting it re-introduces the problems]]
* [[Configuring Ansible for Network Automation]]
* [[Cross-platform provisioning uses OS-family conditionals and variable includes]]
* [[Customize task failure and change status with failed_when and changed_when]]
* [[Default inventory pointing to production invites unintended changes]]
* [[Delegated tasks see target host facts, not delegation-target facts]]
* [[Delegation runs a task on a different host while preserving target context]]
* [[Describe each of the following components in Ansible, including the relationship betwee…]]
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[Directory-based variable organization separates variables from inventory]]
* [[Does `poll: 0` automatically clean up the async job cache file?]]
* [[Dynamic inventory in Ansible]]
* [[Dynamic inventory plugins auto-discover cloud hosts via provider APIs]]
* [[Each play targets hosts independently; handlers deduplicate and roles standardize structure]]
* [[Eight Ansible variable precedence levels you need]]
* [[Execution Environments solved the dependency-conflict problem in Ansible]]
* [[Experienced Ansible practitioners avoid command/shell modules]]
* [[Explain how to use the --check option for running Ansible in check mode.]]
* [[Explain how to view job output and logs in Ansible Tower.]]
* [[Explain the Difference between Forks and Serial & Throttle.]]
* [[Explain the difference between tasks, handlers, and defaults in an Ansible Role.]]
* [[Explain the importance of version control with Ansible playbooks.]]
* [[Explain the key components of Ansible.]]
* [[Explain the process of editing an encrypted file with Ansible Vault.]]
* [[Explain the purpose of the "copy" module in Ansible.]]
* [[Explain the purpose of the --diff option in Ansible playbooks.]]
* [[Explain the role of Ansible Facts in playbooks and how to debug them.]]
* [[Explain the role of Ansible Tower in a CI/CD pipeline.]]
* [[Explain the use of Ansible roles in network automation.]]
* [[Explain the use of the "ec2.py" script for AWS dynamic inventory.]]
* [[Explain the use of the "hosts" directive in a playbook.]]
* [[Explain the use of the -vvv option when running Ansible commands.]]
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
* [[Fact Caching Returns Stale System Information]]
* [[Fact caching avoids expensive repeated gathering]]
* [[Fact caching avoids multi-minute delays on large fleets]]
* [[File '/tmp/exercise' includes the following content]]
* [[Flat inventory prevents efficient fleet targeting]]
* [[Fleet diagnostics demand parallelism; forks multiply time]]
* [[Fleet incident response: assessment and targeted remediation]]
* [[Forks control Ansible parallelism]]
* [[Git repository as source of truth for homelab infrastructure]]
* [[Give an example of an ad-hoc ping command.]]
* [[Global become: true escalates all tasks]]
* [[Handlers Only Fire When Task Status Changes]]
* [[Handlers run once at play end, triggered by task notifications]]
* [[Handling Dependencies]]
* [[Have you used automation tools like PowerShell or Ansible for server management tasks?]]
* [[High fork counts cause connection exhaustion and cascading failures]]
* [[How are Steering Committee members selected?]]
* [[How are Windows modules different from Linux modules internally?]]
* [[How are facts gathered?]]
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[How are module arguments passed to the remote module under Ansiballz?]]
* [[How can you detect check mode inside a playbook?]]
* [[How can you run a specific task or play within an Ansible playbook for testing?]]
* [[How can you test and validate a dynamic inventory script?]]
* [[How can you troubleshoot SSH connection issues with Ansible?]]
* [[How can you use tags in Ansible Roles?]]
* [[How did Ansible end up under IBM's umbrella?]]
* [[How do AWX and Red Hat Ansible Automation Platform differ?]]
* [[How do `selectattr` and `rejectattr` work?]]
* [[How do you access a variable of the first host in a group?]]
* [[How do you access nested variables?]]
* [[How do you approach automating repetitive tasks in a data center?]]
* [[How do you backup router configurations with Ansible?]]
* [[How do you check a playbook's syntax without running it?]]
* [[How do you check disk space on all hosts ad-hoc?]]
* [[How do you check the status of a fire-and-forget async task?]]
* [[How do you configure a dynamic inventory for AWS EC2?]]
* [[How do you create a custom Jinja2 filter for Ansible?]]
* [[How do you create a new role skeleton?]]
* [[How do you create an encrypted file using Ansible Vault?]]
* [[How do you create and manage inventories in Ansible Tower?]]
* [[How do you decrypt a file?]]
* [[How do you define variables in Ansible Playbooks?]]
* [[How do you disable automatic fact gathering?]]
* [[How do you disable fact gathering?]]
* [[How do you edit an encrypted file?]]
* [[How do you enable a callback plugin?]]
* [[How do you enable a notification callback plugin?]]
* [[How do you enable verbose mode for Ansible playbooks?]]
* [[How do you encrypt a single string variable?]]
* [[How do you execute a single ad-hoc Ansible command?]]
* [[How do you fire-and-forget a long-running task?]]
* [[How do you force handlers to run mid-play?]]
* [[How do you generate a password hash suitable for /etc/shadow in Ansible?]]
* [[How do you generate an encrypted password for the user module?]]
* [[How do you handle a playbook that exposes sensitive data in logs?]]
* [[How do you handle external secret lookups?]]
* [[How do you handle version control for playbooks?]]
* [[How do you implement RBAC in Ansible Tower?]]
* [[How do you implement blue-green deployments with Ansible?]]
* [[How do you implement canary deployments with Ansible?]]
* [[How do you implement zero-downtime deployments?]]
* [[How do you include external tasks in an Ansible Playbook?]]
* [[How do you include roles in a playbook?]]
* [[How do you inspect the contents of an EE image using ansible-navigator?]]
* [[How do you install a collection from a specific Git repository?]]
* [[How do you install a collection?]]
* [[How do you install a package using an ad-hoc command?]]
* [[How do you install a specific version of a collection?]]
* [[How do you install and configure Ansible Tower?]]
* [[How do you install collections from a requirements file?]]
* [[How do you integrate Ansible with Jenkins?]]
* [[How do you invoke a lookup plugin in a playbook?]]
* [[How do you limit Ansible to run on one host at a time (serial execution)?]]
* [[How do you loop over a list of items?]]
* [[How do you loop over hosts in a group inside a template?]]
* [[How do you manage secrets across multiple environments?]]
* [[How do you manage secrets in Ansible?]]
* [[How do you pass variables to Ansible at runtime?]]
* [[How do you print the values of variables in Ansible playbooks for debugging purposes?]]
* [[How do you provision AWS EC2 instances with Ansible?]]
* [[How do you reboot a host and wait for it to come back?]]
* [[How do you reference a variable in a playbook?]]
* [[How do you reference vault-encrypted variables in a playbook?]]
* [[How do you run Ansible tasks inside an existing container?]]
* [[How do you run a playbook in verbose mode?]]
* [[How do you run a playbook that uses vault-encrypted files?]]
* [[How do you run ansible-navigator without an Execution Environment (in local mode)?]]
* [[How do you run tasks asynchronously?]]
* [[How do you securely manage control node credentials?]]
* [[How do you select a specific lint profile on the command line?]]
* [[How do you set breakpoints or pause execution within an Ansible role for debugging?]]
* [[How do you set the PATH or environment variables for a task?]]
* [[How do you set the strategy for a play?]]
* [[How do you set up a jump host (bastion) in Ansible?]]
* [[How do you set up passwordless SSH for Ansible?]]
* [[How do you specify a custom inventory file?]]
* [[How do you specify role dependencies?]]
* [[How do you specify the SSH user for Ansible?]]
* [[How do you specify which Ansible collections to include in an EE?]]
* [[How do you start a playbook at a specific task?]]
* [[How do you structure a good playbook or role?]]
* [[How do you test Ansible safely?]]
* [[How do you test a specific scenario when multiple exist?]]
* [[How do you test playbooks?]]
* [[How do you troubleshoot failed jobs in Ansible Tower?]]
* [[How do you use a script to provide vault passwords?]]
* [[How do you use the "shell" module in Ansible?]]
* [[How do you use variables in Jinja2 templates?]]
* [[How do you view all facts for a host?]]
* [[How do you view an encrypted file without decrypting?]]
* [[How do you write a conditional in Jinja2?]]
* [[How do you write a conditional task in Ansible?]]
* [[How do you write a loop in Jinja2?]]
* [[How does Ansible communicate with Linux hosts?]]
* [[How does Ansible communicate with Windows hosts?]]
* [[How does Ansible connect to managed nodes?]]
* [[How does Ansible differ from Puppet?]]
* [[How does Ansible differ from SaltStack?]]
* [[How does Ansible differ from other configuration management tools?]]
* [[How does Ansible interact with Docker?]]
* [[How does Ansible interact with Kubernetes?]]
* [[How does Ansible manage network devices?]]
* [[How does Ansible support network automation?]]
* [[How does Mitogen achieve its performance gains?]]
* [[How does Mitogen transfer data?]]
* [[How does `become` work differently on Windows?]]
* [[How does `changed_when` work?]]
* [[How does `failed_when` work?]]
* [[How does `include_vars` compare to `vars_files` in precedence?]]
* [[How does `serial` support rolling updates?]]
* [[How does a custom module return data to Ansible?]]
* [[How does an event payload get passed to a triggered playbook?]]
* [[How does ansible-pull know which playbook to run?]]
* [[How does inventory caching work?]]
* [[How does privilege escalation work on network devices like Cisco IOS?]]
* [[How does the YAML octal gotcha specifically bite Ansible users?]]
* [[How does the `free` strategy differ from `linear`?]]
* [[How is Ansible used in a CI/CD pipeline?]]
* [[How is `set_fact` different from `vars`?]]
* [[How is ansible-pull typically scheduled?]]
* [[How long is each ansible-core major version maintained?]]
* [[How many collections are typically included in the Ansible community package?]]
* [[How many employees did Ansible, Inc. have at the time of the Red Hat acquisition?]]
* [[How many forks does Ansible use by default?]]
* [[How many levels of variable precedence does Ansible have?]]
* [[How many modules were in the monolithic Ansible 2.9 repository before the split?]]
* [[How many stdout-type callback plugins can be active at once?]]
* [[How often does ansible-core release a new major version?]]
* [[How to find out the data type of a certain variable in one of the playbooks?]]
* [[How to make the variable "use_var" optional?]]
* [[How would you apply BGP configuration across 100 routers with minimum downtime?]]
* [[How would you design a reusable playbook for multiple environments?]]
* [[Idempotence is the core contract of Ansible modules]]
* [[Idempotency as default, exceptions with shell and command modules]]
* [[Idempotency verification requires two consecutive runs showing zero changes]]
* [[Idempotent tasks use built-in modules or changed_when predicates]]
* [[If a rescue section succeeds, does Ansible consider the play failed?]]
* [[If both ANSIBLE_CONFIG and a local ansible.cfg exist in the current directory, which wins?]]
* [[If the value of certain variable is 1, you would like to use the value "one", otherwise…]]
* [[If you create a custom fact in the same play, how do you access it?]]
* [[If you set a fact with set_fact and also define the same variable as a role parameter, …]]
* [[If you specify both --tags and --skip-tags for the same tag, what happens?]]
* [[Installing Ansible Galaxy roles from CLI and requirements file]]
* [[Inventory patterns use set operators for host selection]]
* [[Inventory structure: hosts, groups, variables, and sources]]
* [[Is Ansible open-source?]]
* [[Jinja2 Expressions Must Be Quoted in YAML Values]]
* [[Jinja2 Whitespace Control Prevents Extra Blank Lines]]
* [[Jinja2 filters transform values during template rendering]]
* [[Limit Ansible playbook execution to specific hosts]]
* [[List all 22 variable precedence levels from lowest to highest.]]
* [[List all the string values that YAML 1.1 interprets as boolean false.]]
* [[Listing and inspecting Ansible modules with ansible-doc]]
* [[Many people attribute the word "ansible" to Orson Scott Card's *Ender's Game*. Why is t…]]
* [[Michael DeHaan stepped back from Ansible after Red Hat acquisition]]
* [[Migrating Legacy Scripts to Ansible]]
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
* [[Modify the following task to use a variable instead of the value "zlib" and have "zlib"…]]
* [[Modules execute on targets; plugins run on the controller and extend Ansible]]
* [[Modules, plugins, and collections in Ansible architecture]]
* [[Molecule made test-driven Ansible development practical]]
* [[Molecule: Ansible role testing framework]]
* [[Multi-Tier Application Deployment]]
* [[Name all the major connection plugin types in Ansible.]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
* [[Name five ansible-lint rules.]]
* [[Name five dynamic inventory plugins included in popular collections.]]
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[Name five notable callback plugins.]]
* [[Name some built-in callback plugins.]]
* [[Name ten commonly used lookup plugins.]]
* [[Name three enterprise features that Ansible Tower/Controller has that AWX lacks.]]
* [[Name three event source plugins in the `ansible.eda` collection.]]
* [[Name three strategies to keep playbooks DRY.]]
* [[Non-idempotent destructive operations cause data loss on re-runs]]
* [[One slow host stalls the entire batch unless timeouts are aggressive]]
* [[Optimizing Ansible Playbook Performance]]
* [[Orchestration in Ansible: coordinating tasks across systems]]
* [[Parallel reboots cause cascading failures across multi-tier stacks]]
* [[Passing Variables and Vault to Ansible in Packer]]
* [[Playbook execution flows through pre_tasks, roles, tasks, post_tasks with distinct import/include behavior]]
* [[Playbook failure diagnosis pattern]]
* [[Playbooks compose idempotent tasks with handlers for change notification]]
* [[Playbooks express desired state through ordered tasks]]
* [[Playbooks support flow control through conditionals, loops, and stateful command execution]]
* [[Playbooks, plays, tasks, roles, and handlers are distinct structural units]]
* [[Prefer native modules over shell/command for idempotency]]
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[Progressive Environment-Based Rollout Reduces Blast Radius]]
* [[Progressive Rollout Validates Changes at Each Environment Stage]]
* [[Provide an example of a complex task or process you automated using scripting or automa…]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[Red Hat open-sourced AWX while selling Ansible Tower as a commercial product]]
* [[Role dependencies require explicit version pinning to prevent conflicts]]
* [[Roles organize reusable Ansible code into directories]]
* [[Roles standardize reusable automation into a predictable directory structure]]
* [[Rolling Updates with Zero Downtime]]
* [[Rolling updates with serial and pre/post task hooks minimize downtime]]
* [[Running fleet commands without --limit risks massive misconfiguration]]
* [[SSH host key verification modes differ in security properties]]
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
* [[Safe infrastructure patch rollouts use progressive stages and circuit breakers]]
* [[Selective fact gathering skips unnecessary system queries]]
* [[Serial Batching and Max-Failure Limit Contain Rollout Risk]]
* [[Serial deployment prevents cascading outages during rolling updates]]
* [[Shell module instead of apt module for packages (idempotency loss)]]
* [[Shell provisioners run in non-interactive context; use Ansible for complex configuration]]
* [[Structured Playbooks Provide Auditability and Idempotency]]
* [[Tasks handling secrets need no_log: true]]
* [[The value of a certain variable you use is the string "True". You would like the value …]]
* [[The variable 'whoami' defined in the following places:]]
* [[Transient SSH Failures Should Be Retried Automatically]]
* [[Troubleshooting Playbook Failures]]
* [[True or False? Ansible follows the mutable infrastructure paradigm]]
* [[True or False? Ansible uses declarative style to describe the expected end state]]
* [[True or False? By default, Ansible will execute all the tasks in play on a single host …]]
* [[Under what namespace are custom local facts accessible?]]
* [[Use failed_when instead of blanket ignore_errors]]
* [[Use no_log: true on tasks handling secrets]]
* [[Use purpose-built modules over shell; adopt FQCNs to avoid collisions]]
* [[Variable precedence: learn role defaults and extra vars, not all 22 levels]]
* [[Variables set in one play don't automatically carry to the next play]]
* [[Vault Passwords Must Not Appear in Shell History or Plain Text]]
* [[What AI model powers Ansible Lightspeed?]]
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
* [[What Ansible module is used to create scheduled tasks on Windows?]]
* [[What Jinja2 filter returns a default value when a variable is undefined?]]
* [[What Molecule command runs only the verify step without re-converging?]]
* [[What Python and Java versions does ansible-rulebook require?]]
* [[What Python class must every custom Ansible module import?]]
* [[What Python library does the `netconf` connection plugin use under the hood?]]
* [[What Python package manager does Ansible recommend for installation?]]
* [[What Python packages are required on the control node for WinRM?]]
* [[What Python version does ansible-core 2.17+ require on managed nodes?]]
* [[What YAML multiline syntax options does Ansible support, and what are the key differences?]]
* [[What ansible-lint rule catches boolean value problems in YAML?]]
* [[What are "magic variables" in Ansible?]]
* [[What are "resource modules" in network automation?]]
* [[What are Ansible "playbooks"?]]
* [[What are Ansible "tags"?]]
* [[What are Ansible Validated Content collections for cloud?]]
* [[What are Ansible Working Groups?]]
* [[What are Ansible plugins?]]
* [[What are Ansible test plugins?]]
* [[What are Ansible's default privilege escalation methods?]]
* [[What are Surveys in AWX/automation controller?]]
* [[What are Vault IDs?]]
* [[What are `group_vars` and `host_vars`?]]
* [[What are best practices for Ansible role organization?]]
* [[What are common issues you might encounter with dynamic inventories, and how would you …]]
* [[What are connection plugins?]]
* [[What are custom facts (local facts) and where do they live?]]
* [[What are execution nodes vs hop nodes in automation mesh?]]
* [[What are idempotency issues in infrastructure automation and how are they avoided?]]
* [[What are inventory plugins?]]
* [[What are key limitations of Mitogen?]]
* [[What are lookup plugins?]]
* [[What are network resource modules?]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
* [[What are some common pitfalls in Ansible, and how can they be avoided?]]
* [[What are specific challenges you might face when using Ansible for network automation?]]
* [[What are strategy plugins?]]
* [[What are tags used for?]]
* [[What are the `_raw_params` in free-form modules?]]
* [[What are the `gather_subset` and `gather_timeout` options?]]
* [[What are the `mutually_exclusive`, `required_together`, `required_one_of`, `required_if…]]
* [[What are the available gather_subset categories?]]
* [[What are the five reserved tag names in Ansible?]]
* [[What are the four verbosity levels in Ansible?]]
* [[What are the key features of Ansible?]]
* [[What are the key parts of an EDA rulebook?]]
* [[What are the key phases in a Molecule test sequence?]]
* [[What are the key sections in an `execution-environment.yml` file?]]
* [[What are the main components of Ansible's architecture?]]
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[What are the server requirements for Ansible?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What are the special tags `always` and `never`?]]
* [[What are the three Mitogen strategy plugins?]]
* [[What are the three main components of an Ansible rulebook?]]
* [[What are the three main connection types for network automation?]]
* [[What are the three main things to investigate for a slow playbook on 500 hosts?]]
* [[What are the two built-in inventory file formats?]]
* [[What are the two categories of Ansible modules?]]
* [[What are the two categories of callback plugins?]]
* [[What are the two display modes in ansible-navigator?]]
* [[What are the two types of inventory?]]
* [[What are variables in Ansible?]]
* [[What authentication methods does WinRM support?]]
* [[What base class do lookup plugins inherit from?]]
* [[What callback plugin profiles memory usage of Ansible tasks?]]
* [[What callback plugin would you use to profile task execution times?]]
* [[What cannot collection role names contain?]]
* [[What class attributes must a callback plugin define?]]
* [[What collection is the `ipaddr` filter now in, and why?]]
* [[What collection provides AWS modules?]]
* [[What collection provides Docker modules and connection plugins?]]
* [[What collection provides Podman modules and connection plugins?]]
* [[What collection provides platform-independent network modules?]]
* [[What command initializes a new collection skeleton?]]
* [[What command initializes a new role skeleton?]]
* [[What command lists all hosts in an inventory?]]
* [[What command runs a rulebook?]]
* [[What command runs an Ansible playbook?]]
* [[What command shows the Ansible version?]]
* [[What configuration file does ansible-lint use?]]
* [[What configuration file does ansible-navigator use?]]
* [[What configuration language does each tool use?]]
* [[What connection plugin is used for network devices?]]
* [[What connection type does ansible-pull use?]]
* [[What controversy surrounds Ansible Lightspeed and the community?]]
* [[What did Ansible 2.5 introduce that changed how network automation worked?]]
* [[What do `async` and `poll` do together in a task?]]
* [[What does "agentless" mean in the context of Ansible?]]
* [[What does YAML stand for?]]
* [[What does `--diff` do?]]
* [[What does `--tags tagged` mean?]]
* [[What does `ANSIBLE_NOCOWS` do?]]
* [[What does `ansible-inventory --list` do?]]
* [[What does `ansible-vault rekey` do?]]
* [[What does `ansible_check_mode` contain?]]
* [[What does `ansible_search_path` contain?]]
* [[What does `become` do?]]
* [[What does `changed_when` do?]]
* [[What does `connection: local` do?]]
* [[What does `delegate_to` do?]]
* [[What does `force_handlers: yes` do?]]
* [[What does `group_names` contain?]]
* [[What does `ignore_errors: true` do?]]
* [[What does `loop_control: extended` provide?]]
* [[What does `meta/main.yml` in a role contain?]]
* [[What does `meta/runtime.yml` in a collection do?]]
* [[What does `meta: end_host` do?]]
* [[What does `meta: flush_handlers` do?]]
* [[What does `meta: reset_connection` do?]]
* [[What does `module_defaults` do at the play or block level?]]
* [[What does `no_log: true` do, and how does it relate to Vault?]]
* [[What does `no_log: true` do?]]
* [[What does `regex_replace` do?]]
* [[What does `run_once: true` do?]]
* [[What does `state: absent` mean in a module?]]
* [[What does `state: latest` mean in package modules?]]
* [[What does `state: present` mean in a module?]]
* [[What does `throttle` do at the task level?]]
* [[What does `wantlist=True` do in a lookup?]]
* [[What does `{{ list | map('extract', dict) }}` do?]]
* [[What does ansible-pull require on each managed node?]]
* [[What does the `--ask-vault-pass` flag do?]]
* [[What does the `ANSIBLE_KEEP_REMOTE_FILES` setting do?]]
* [[What does the `Constructable` base class provide to inventory plugins?]]
* [[What does the `ansible-galaxy` CLI do?]]
* [[What does the `apt` module do?]]
* [[What does the `async` keyword do?]]
* [[What does the `combine` filter do, and why is it so useful?]]
* [[What does the `combine` filter do?]]
* [[What does the `command` module do?]]
* [[What does the `copy` module do?]]
* [[What does the `cron` module do?]]
* [[What does the `debug` module do?]]
* [[What does the `debug` strategy allow?]]
* [[What does the `default` filter do?]]
* [[What does the `docker_container` module do?]]
* [[What does the `fetch` module do?]]
* [[What does the `file` module do?]]
* [[What does the `flatten` filter do?]]
* [[What does the `fqcn` lint rule require?]]
* [[What does the `gather_facts: false` optimization do?]]
* [[What does the `groups` magic variable contain?]]
* [[What does the `hosts` keyword define in a play?]]
* [[What does the `hostvars` magic variable contain?]]
* [[What does the `idempotence` step verify?]]
* [[What does the `lineinfile` module do?]]
* [[What does the `mandatory` filter do?]]
* [[What does the `map` filter do with the `attribute` keyword?]]
* [[What does the `min` lint profile enforce?]]
* [[What does the `never` tag do?]]
* [[What does the `package` module do?]]
* [[What does the `ping` module do?]]
* [[What does the `production` lint profile add on top of `shared`?]]
* [[What does the `safety` lint profile add?]]
* [[What does the `service` module do?]]
* [[What does the `setup` module do?]]
* [[What does the `shell` module do?]]
* [[What does the `synchronize` module do?]]
* [[What does the `user` module do?]]
* [[What does the `wait_for` module do?]]
* [[What does the `yum` module do?]]
* [[What drivers does Molecule support for creating test instances?]]
* [[What encryption algorithm does Ansible Vault use?]]
* [[What environment variable disables Ansible's cowsay output?]]
* [[What features does Ansible Tower/AWX provide?]]
* [[What file extension does the AWS EC2 inventory plugin expect?]]
* [[What file extension is used for Jinja2 templates?]]
* [[What file format does Ansible use for its return data from modules?]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
* [[What filter would you use to base64-encode a string in Ansible?]]
* [[What happened to AnsibleFest after 2022?]]
* [[What happened to `with_items`, `with_dict`, `with_file`, etc.?]]
* [[What happened to `with_items`, `with_dict`, `with_fileglob` etc.?]]
* [[What happens after a rulebook condition matches an event?]]
* [[What happens if a handler is notified multiple times?]]
* [[What happens if a task exceeds its `async` timeout?]]
* [[What happens if two collections provide a module with the same short name?]]
* [[What happens if you reference an undefined variable?]]
* [[What happens if you use `vars_prompt` in Ansible Tower/Controller?]]
* [[What happens if you use a short module name (e.g., "copy") instead of the FQCN in a pos…]]
* [[What happens if you write `version: 1.0` in YAML without quotes?]]
* [[What happens when `run_once` is combined with `serial`?]]
* [[What happens when you apply `become: true` with the `local` connection?]]
* [[What happens when you use `creates` or `removes` with command/shell modules?]]
* [[What happens with `port: 22` vs `port: "22"` in Ansible YAML?]]
* [[What has the highest variable precedence?]]
* [[What has the lowest variable precedence?]]
* [[What indentation is recommended for YAML?]]
* [[What information is available in the output when using the --check option?]]
* [[What internal arguments does Ansible automatically inject into every module call?]]
* [[What is AWX?]]
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
* [[What is Ansible Container, and how does it integrate with Docker?]]
* [[What is Ansible Lightspeed?]]
* [[What is Ansible Networking, and how is it different from traditional Ansible?]]
* [[What is Ansible Tower Surveys, and how do they work?]]
* [[What is Ansible Tower, and how does it differ from Ansible?]]
* [[What is Ansible Tower?]]
* [[What is BYOM in the context of Ansible Lightspeed?]]
* [[What is Event-Driven Ansible (EDA) and when was it introduced?]]
* [[What is Infrastructure as Code (IaC) and how does Ansible align with it?]]
* [[What is Instance Groups in AWX?]]
* [[What is Jinja2 in the context of Ansible?]]
* [[What is Mitogen for Ansible?]]
* [[What is Private Automation Hub?]]
* [[What is Puppet Bolt, and how is it similar to Ansible?]]
* [[What is SSH ControlPersist?]]
* [[What is YAML, and why is it used in Ansible?]]
* [[What is `--vault-password-file`?]]
* [[What is `ANSIBLE_ROLES_PATH`?]]
* [[What is `ansible-builder`?]]
* [[What is `ansible-config dump`?]]
* [[What is `ansible-console`?]]
* [[What is `ansible-creator`?]]
* [[What is `ansible-doc` used for?]]
* [[What is `ansible-galaxy collection verify`?]]
* [[What is `ansible-inventory --graph`?]]
* [[What is `ansible-playbook --syntax-check`?]]
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
* [[What is `ansible-test`?]]
* [[What is `ansible-vault encrypt_string` used for?]]
* [[What is `ansible.builtin.add_host`?]]
* [[What is `ansible.builtin.apt_key` and why is it deprecated?]]
* [[What is `ansible.builtin.lineinfile` vs `ansible.builtin.blockinfile`?]]
* [[What is `ansible.builtin.set_stats`?]]
* [[What is `ansible_connection` and where can it be set?]]
* [[What is `ansible_facts` vs top-level fact variables?]]
* [[What is `ansible_host` in inventory?]]
* [[What is `ansible_local`?]]
* [[What is `ansible_loop`?]]
* [[What is `ansible_network_os`, and why is it critical for network automation?]]
* [[What is `ansible_play_batch`?]]
* [[What is `ansible_play_hosts`?]]
* [[What is `ansible_play_name`?]]
* [[What is `ansible_port`?]]
* [[What is `ansible_python_interpreter`?]]
* [[What is `ansible_run_tags` and `ansible_skip_tags`?]]
* [[What is `ansible_version`?]]
* [[What is `any_errors_fatal` and when would you use it?]]
* [[What is `become_method`?]]
* [[What is `become_user`?]]
* [[What is `changed_when: false` used for?]]
* [[What is `check_mode: true` at the task level?]]
* [[What is `cli_command` vs platform-specific modules (e.g., ios_command)?]]
* [[What is `collections:` at the play level?]]
* [[What is `collections` keyword in a playbook?]]
* [[What is `creates` parameter in command/shell modules?]]
* [[What is `delegate_facts: true`?]]
* [[What is `delegate_to`?]]
* [[What is `diff: true` at the task level?]]
* [[What is `fact_caching`, and what backends does it support?]]
* [[What is `gather_subset` and how does it speed up fact gathering?]]
* [[What is `group_by` module?]]
* [[What is `groups` in Ansible?]]
* [[What is `hash_behaviour` in ansible.cfg?]]
* [[What is `host_key_checking`?]]
* [[What is `ignore_errors`?]]
* [[What is `ignore_unreachable`?]]
* [[What is `include_role` vs `import_role`?]]
* [[What is `inventory_dir`?]]
* [[What is `inventory_hostname_short`?]]
* [[What is `inventory_hostname`?]]
* [[What is `max_fail_percentage` used for?]]
* [[What is `max_fail_percentage`?]]
* [[What is `meta: clear_facts`?]]
* [[What is `meta: clear_host_errors`?]]
* [[What is `meta: end_play`?]]
* [[What is `omit`?]]
* [[What is `order` in a play?]]
* [[What is `play_hosts`?]]
* [[What is `playbook_dir`?]]
* [[What is `register` and what does the registered variable contain?]]
* [[What is `register` in Ansible?]]
* [[What is `removes` parameter in command/shell modules?]]
* [[What is `role_path`?]]
* [[What is `set_fact`?]]
* [[What is `supports_check_mode` in module development?]]
* [[What is `until` / `retries` / `delay` in a task?]]
* [[What is `vars_prompt`?]]
* [[What is `wait_for_connection` used for?]]
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[What is a "tombstone" entry in Ansible's collection routing?]]
* [[What is a Decision Environment?]]
* [[What is a Fully Qualified Collection Name (FQCN), and why does it matter post-migration?]]
* [[What is a Fully Qualified Collection Name (FQCN)?]]
* [[What is a Job Template in AWX/automation controller?]]
* [[What is a Molecule scenario?]]
* [[What is a Smart Inventory?]]
* [[What is a Vault ID, and why would you use multiple?]]
* [[What is a Workflow Job Template?]]
* [[What is a Workflow in Tower/AWX?]]
* [[What is a callback plugin?]]
* [[What is a collection namespace?]]
* [[What is a group in an Ansible inventory?]]
* [[What is a lookup plugin in Ansible?]]
* [[What is a play in Ansible?]]
* [[What is a playbook `import_playbook`?]]
* [[What is a practical use case for async with poll > 0?]]
* [[What is a pre_task and post_task?]]
* [[What is a requirements.yml file for Galaxy?]]
* [[What is a rolling update strategy?]]
* [[What is a task in Ansible?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
* [[What is an "action plugin" and how does it differ from a module?]]
* [[What is an Ansible Execution Environment (EE)?]]
* [[What is an Ansible callback whitelist?]]
* [[What is an Ansible inventory?]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
* [[What is ansible-lint?]]
* [[What is ansible.cfg?]]
* [[What is automation mesh?]]
* [[What is callback plugin `profile_tasks`?]]
* [[What is callback plugin `timer`?]]
* [[What is configuration drift?]]
* [[What is diff mode?]]
* [[What is fact caching?]]
* [[What is idempotency?]]
* [[What is provisioning?]]
* [[What is the "Norway Problem" in YAML, and how does it affect Ansible?]]
* [[What is the "canary deployment" pattern in Ansible?]]
* [[What is the "cow" in Ansible output?]]
* [[What is the "golden image" pattern using Ansible?]]
* [[What is the "idempotence" test phase in Molecule?]]
* [[What is the "include_role with conditionals" anti-pattern?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[What is the "pre_tasks / post_tasks" idiom for rolling updates?]]
* [[What is the "routing" configuration in the context of collections migration?]]
* [[What is the "two-stage" or "delegate and register" pattern?]]
* [[What is the Ansiballz framework?]]
* [[What is the Ansible Community Steering Committee?]]
* [[What is the Ansible Lightspeed "intelligent assistant"?]]
* [[What is the Ansible Tower rebrand name?]]
* [[What is the Ansible equivalent of try/catch/finally?]]
* [[What is the Community Working Group specifically?]]
* [[What is the FQCN for the AWS EC2 module?]]
* [[What is the Module Replacer framework?]]
* [[What is the Red Hat Certified Specialist in Ansible Automation exam called?]]
* [[What is the Tower/AWX REST API used for?]]
* [[What is the YAML octal number gotcha?]]
* [[What is the `.retry` file that Ansible creates?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
* [[What is the `INJECT_FACTS_AS_VARS` configuration?]]
* [[What is the `INTERPRETER_PYTHON` configuration, and why was `auto` mode added?]]
* [[What is the `all` group?]]
* [[What is the `ansible.builtin.debug` module's `var` vs `msg` parameter?]]
* [[What is the `ansible.builtin.find` module?]]
* [[What is the `ansible.builtin.package` module?]]
* [[What is the `ansible.builtin.pause` module?]]
* [[What is the `ansible.builtin.reboot` module?]]
* [[What is the `ansible.builtin.script` module?]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
* [[What is the `ansible.posix` collection?]]
* [[What is the `ansible.windows` collection?]]
* [[What is the `ansible_become_exe` variable?]]
* [[What is the `ansible_connection` variable set to for network devices?]]
* [[What is the `ansible_date_time` fact?]]
* [[What is the `ansible_managed` variable?]]
* [[What is the `argument_spec` in a custom module?]]
* [[What is the `ask_pass` setting?]]
* [[What is the `assert` module used for?]]
* [[What is the `auto` interpreter discovery in Ansible?]]
* [[What is the `auto` inventory plugin?]]
* [[What is the `become_method` setting and what values does it support?]]
* [[What is the `block` keyword?]]
* [[What is the `cli_parse` module used for?]]
* [[What is the `cloud.terraform` collection?]]
* [[What is the `constructed` inventory plugin?]]
* [[What is the `converge` step in Molecule?]]
* [[What is the `debug` module's `verbosity` parameter?]]
* [[What is the `debug` strategy?]]
* [[What is the `environment` keyword at the task/play/block level?]]
* [[What is the `environment` keyword used for?]]
* [[What is the `expect` module?]]
* [[What is the `fail` module?]]
* [[What is the `failed_when: false` idiom?]]
* [[What is the `forks` setting, and what is its default value?]]
* [[What is the `gathered` state in network resource modules?]]
* [[What is the `host_pinned` strategy?]]
* [[What is the `httpapi` connection plugin?]]
* [[What is the `ipaddr` filter?]]
* [[What is the `listen` directive on handlers?]]
* [[What is the `local_action` keyword?]]
* [[What is the `lookup` plugin?]]
* [[What is the `loop_control` directive?]]
* [[What is the `meta` module used for?]]
* [[What is the `network_cli` connection plugin used for?]]
* [[What is the `no_log: true` directive?]]
* [[What is the `no_log` lint rule about?]]
* [[What is the `notify` keyword?]]
* [[What is the `omit` variable in Ansible?]]
* [[What is the `password_hash` filter?]]
* [[What is the `pause` module?]]
* [[What is the `psrp` connection plugin, and how does it differ from `winrm`?]]
* [[What is the `query` function, and how does it differ from `lookup`?]]
* [[What is the `raw` module, and when is it needed?]]
* [[What is the `raw` module?]]
* [[What is the `register` keyword?]]
* [[What is the `retry_until` pattern in Ansible?]]
* [[What is the `script` module?]]
* [[What is the `serial` keyword?]]
* [[What is the `service_facts` module?]]
* [[What is the `set_fact` module's `cacheable` option?]]
* [[What is the `set_stats` module?]]
* [[What is the `shared` lint profile intended for?]]
* [[What is the `synchronize` module?]]
* [[What is the `template` module's `output_encoding` parameter?]]
* [[What is the `ternary` filter?]]
* [[What is the `throttle` keyword?]]
* [[What is the `timeout` connection parameter?]]
* [[What is the `to_json` and `from_json` filter pair used for?]]
* [[What is the `ungrouped` group?]]
* [[What is the `uri` module?]]
* [[What is the `win_updates` module used for?]]
* [[What is the automation controller REST API used for?]]
* [[What is the default Ansible Galaxy server URL?]]
* [[What is the default base image used by ansible-builder?]]
* [[What is the default become method?]]
* [[What is the default connection plugin in Ansible?]]
* [[What is the default driver in modern Molecule?]]
* [[What is the default number of forks?]]
* [[What is the default poll interval?]]
* [[What is the default reboot timeout?]]
* [[What is the default strategy, and what is its key characteristic?]]
* [[What is the default verifier in Molecule 6+?]]
* [[What is the deprecation cycle length in ansible-core for features?]]
* [[What is the difference between `ansible_play_hosts` and `ansible_play_hosts_all`?]]
* [[What is the difference between `command` and `shell` modules?]]
* [[What is the difference between `community.docker.docker` and `community.docker.docker_a…]]
* [[What is the difference between `defaults/main.yml` and `vars/main.yml`?]]
* [[What is the difference between `free` and `host_pinned`?]]
* [[What is the difference between `ignore_errors: true` and using a `rescue` block?]]
* [[What is the difference between `include_tasks` and `import_tasks`?]]
* [[What is the difference between `inventory_hostname` and `ansible_hostname`?]]
* [[What is the difference between `is match` and `is search` tests?]]
* [[What is the difference between `lookup()` and `query()` in Ansible?]]
* [[What is the difference between `network_cli` and `httpapi` for network devices?]]
* [[What is the difference between `vars`, `vars_files`, and `vars_prompt`?]]
* [[What is the difference between `with_items` and `loop`?]]
* [[What is the difference between a Decision Environment and an Execution Environment in E…]]
* [[What is the difference between a Galaxy role and a Galaxy collection?]]
* [[What is the difference between a lookup and a filter?]]
* [[What is the difference between a playbook and a play?]]
* [[What is the difference between a playbook and an ad-hoc command?]]
* [[What is the difference between an Ansible playbook and a role?]]
* [[What is the difference between an inventory script and an inventory plugin?]]
* [[What is the difference between ansible-dev-tools and ansible-core?]]
* [[What is the difference between dot notation and array notation for variables?]]
* [[What is the difference between role defaults and role vars in terms of precedence?]]
* [[What is the difference between stdout callbacks and non-stdout callbacks?]]
* [[What is the difference between variable names and environment variables?]]
* [[What is the etymology of the word "ansible"?]]
* [[What is the exact search order for ansible.cfg files (highest to lowest priority)?]]
* [[What is the fundamental difference between `import_*` and `include_*`?]]
* [[What is the galaxy.yml file in a collection?]]
* [[What is the gotcha with `run_once` and `serial`?]]
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
* [[What is the major limitation of check mode?]]
* [[What is the maximum recommended inventory size for a single Ansible control node?]]
* [[What is the most downloaded Ansible Galaxy role author namespace?]]
* [[What is the namespace.collection format, and why does it matter?]]
* [[What is the naming convention for Ansible environment variable overrides?]]
* [[What is the obscure `ANSIBLE_FORCE_COLOR` environment variable?]]
* [[What is the precedence order if the same variable is defined in group_vars for a parent…]]
* [[What is the purpose of an Ansible Playbook?]]
* [[What is the push-based model in Ansible?]]
* [[What is the relationship between Ansible Tower and Automation Controller?]]
* [[What is the relationship between Jinja2's built-in filters and Ansible's filters?]]
* [[What is the relationship between ansible-core and the ansible package?]]
* [[What is the security concern with `./ansible.cfg` in the current directory?]]
* [[What is the security risk of using `shell` or `command` modules with user-supplied vari…]]
* [[What is the security warning about Vault and "data at rest" vs. "data in use"?]]
* [[What is the single most important thing to remember about extra vars (-e)?]]
* [[What is the standard collection directory structure?]]
* [[What is the standard directory structure of an Ansible role?]]
* [[What is the standard role directory structure?]]
* [[What is the structure of an EDA rulebook?]]
* [[What is the syntax for an Ansible Playbook?]]
* [[What is the syntax of an ad-hoc command?]]
* [[What key inventory object methods are used in plugin development?]]
* [[What keyword defines tasks in a playbook?]]
* [[What kind of automation you wouldn't do with Ansible and why?]]
* [[What language are Ansible playbooks written in?]]
* [[What language is Ansible written in?]]
* [[What language is Ansible written in? What about Puppet, Chef, and SaltStack?]]
* [[What major AAP 2.5 feature unified the user experience across components?]]
* [[What makes SaltStack's execution speed notably faster than Ansible for large fleets?]]
* [[What makes good Ansible?]]
* [[What method must a lookup plugin implement?]]
* [[What method prefix do v2 callback plugin methods use?]]
* [[What module adds or modifies lines in files?]]
* [[What module checks the status of a previously fired async task?]]
* [[What module copies files from remote to local?]]
* [[What module creates and manages Podman containers?]]
* [[What module creates directories?]]
* [[What module gathers facts by default at the start of each play?]]
* [[What module is used to gather system information?]]
* [[What module is used to reboot a host?]]
* [[What module manages SELinux?]]
* [[What module manages cron jobs?]]
* [[What module manages firewall rules?]]
* [[What module manages systemd services?]]
* [[What module manages users?]]
* [[What module tests if a file exists on a remote host?]]
* [[What module would you use to wait for a port to become available?]]
* [[What must a filter plugin Python file contain?]]
* [[What open-source tool can dramatically speed up Ansible by replacing SSH with a custom …]]
* [[What other connection optimizations exist beyond Mitogen?]]
* [[What other tools did Michael DeHaan create before Ansible?]]
* [[What playbook filename does ansible-pull look for by default?]]
* [[What port does Ansible use by default for SSH connections?]]
* [[What port does WinRM use by default for Ansible Windows management?]]
* [[What protocol does Ansible use to manage Windows hosts?]]
* [[What rule does `no-changed-when` enforce?]]
* [[What science fiction novel first coined the word "ansible," and who wrote it?]]
* [[What shift in AAP 2.5 changed how the platform is deployed?]]
* [[What special group exists in every Ansible inventory?]]
* [[What speedup can Mitogen provide?]]
* [[What steps would you take to debug an issue with Ansible Container?]]
* [[What steps would you take to debug an issue within an Ansible role?]]
* [[What steps would you take to troubleshoot a failed Ansible playbook?]]
* [[What subcommand in ansible-navigator lists available collections inside an EE?]]
* [[What symbol starts a list item in YAML?]]
* [[What tasks cannot be delegated?]]
* [[What timeout does the reboot module use by default?]]
* [[What tool is used to build Execution Environments?]]
* [[What two methods must a custom inventory plugin implement?]]
* [[What two open-source projects did Michael DeHaan create before Ansible, both at Red Hat?]]
* [[What types of errors do NOT trigger the rescue block?]]
* [[What valid `type` values can be used in argument_spec?]]
* [[What verifiers does Molecule support?]]
* [[What versioning scheme does ansible-core follow vs the ansible package?]]
* [[What was "ansible-base" and when did it appear?]]
* [[What was Michael DeHaan's job before creating Ansible, and why did he leave?]]
* [[What was significant about Ansible 1.0, and when was it released?]]
* [[What was the approximate annual cost of Ansible Tower licensing before the AAP rebrand?]]
* [[What was the first AnsibleFest, and when did it take place?]]
* [[What was the first commit to the Ansible GitHub repository, and approximately when?]]
* [[What was the major architectural change in Ansible 2.0?]]
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
* [[What would be the result of the following play?]]
* [[What year did Ansible 2.0 introduce the new execution engine?]]
* [[What year did Ansible Galaxy launch?]]
* [[What year did Ansible Tower (the commercial UI product) first appear?]]
* [[What year was Ansible Lightspeed announced?]]
* [[What year was Ansible first released?]]
* [[What year was Event-Driven Ansible (EDA) first introduced?]]
* [[What's your experience with Ansible?]]
* [[When and by whom was Ansible acquired?]]
* [[When did Ansible collections replace the monolithic package?]]
* [[When did Ansible drop Python 2 support on the control node?]]
* [[When did IBM acquire Red Hat?]]
* [[When did Red Hat acquire Ansible?]]
* [[When did the collections concept first appear in Ansible?]]
* [[When do handlers execute?]]
* [[When is ansible-pull appropriate?]]
* [[When is ansible-pull preferred over the normal push model?]]
* [[When should you use a role vs a simple task file?]]
* [[When should you use ad-hoc commands vs playbooks?]]
* [[When the value '2017'' will be used in this case: `{{ lookup('env', 'BEST_YEAR') | defa…]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[When was Ansible Lightspeed generally available?]]
* [[When was Ansible Tower renamed to automation controller?]]
* [[When was the last time the migration script (migrate.py) was run to move content from t…]]
* [[When would you use ansible-pull instead of the default push model?]]
* [[When would you use the `free` strategy?]]
* [[When would you use the `local` connection plugin?]]
* [[Where are remote temporary files stored on managed nodes?]]
* [[Where can variables be defined?]]
* [[Where did the Ansible community move after leaving IRC?]]
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[Where do network modules execute -- on the control node or managed node?]]
* [[Where does Molecule store scenario configuration?]]
* [[Where does the Steering Committee conduct business?]]
* [[Where does the name "Ansible" come from?]]
* [[Where is the default inventory file located?]]
* [[Where should custom filter plugins be placed?]]
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
* [[Which config management tool uses a "master-minion" architecture with a ZeroMQ message …]]
* [[Which of the "big four" (Ansible, Puppet, Chef, Salt) are agentless?]]
* [[Which tool came first chronologically: Puppet, Chef, Ansible, or Salt?]]
* [[Which tools are push-based vs. pull-based by default?]]
* [[Who created Ansible and when?]]
* [[Who created Ansible, and in what year was it first released?]]
* [[Who is Jeff Geerling and why is he significant to the Ansible community?]]
* [[Why Use Ansible Collections?]]
* [[Why do Ansible community package version numbers jump from 2.10 to 3.0, 4.0, etc., whil…]]
* [[Why do Execution Environments exist when Python virtual environments (venvs) already ex…]]
* [[Why do you always use `{{ }}` in Ansible except in `when` clauses?]]
* [[Why does Ansible have separate Python requirements for control node vs. managed nodes?]]
* [[Why does Ansible mark all strings returned by modules as "Unsafe"?]]
* [[Why does Ansible refuse to load an ansible.cfg from a world-writable current directory?]]
* [[Why don't Juniper Junos Ansible modules require Python on the device?]]
* [[Why is Ansible more dangerous than shell scripts at scale?]]
* [[Why is CredSSP sometimes needed for Windows automation?]]
* [[Why is YAML 1.2 relevant to Ansible's future?]]
* [[Why is `hash_behaviour: merge` deprecated?]]
* [[Why is shell in Ansible dangerous?]]
* [[Why was the monolithic repo problematic?]]
* [[Write a filter to capitalize a string]]
* [[Write a playbook to deploy the file ‘/tmp/system_info’ on all hosts except for controll…]]
* [[Write a playbook to install ‘zlib’ and ‘vim’ on all hosts if the file ‘/tmp/mario’ exis…]]
* [[Write a single task that verifies all the files in files_list variable exist on the host]]
* [[YAML choice for Ansible prioritized non-programmer accessibility]]
* [[YAML inventory structure enables hierarchical host groups with inheritance]]
* [[You deploy configuration but servers show inconsistent settings. How do you detect and …]]
* [[You have a slow playbook on 500 hosts. What do you investigate first?]]
* [[Zuul's circular dependency: testing Ansible with Ansible]]
* [[ansible-doc: offline module documentation reference]]
* [[ansible-navigator: modern replacement for ansible-playbook]]
* [[ansible-pull inverts the model to pull-based configuration management]]
* [[ansible_ssh_common_args: appending SSH args to all SSH connections]]
* [[become: true Must Be Set at Task Level for Privilege Escalation]]
* [[import_tasks vs include_tasks Have Different Condition Semantics]]
* [[lineinfile is for single lines, not file management]]
* [[lineinfile is unsuited for multi-line or overlapping content]]
* [[serial: 1 is Unnecessarily Slow for Large Fleets]]
!! MOC — confidence mid
Atoms with confidence in the ''mid'' band (25 total).
* [[Ansible Facts and the gather_facts task]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
* [[Ansible installation and configuration on Linux]]
* [[Ansible performance optimization for large inventories]]
* [[Audit mixed-distro fleets with Ansible to identify configuration drift]]
* [[Common inventory mistakes: hardcoding, secrets, group membership, ungrouped hosts]]
* [[Connection plugins determine how Ansible communicates with targets]]
* [[Continuous compliance loop: scan, parse, remediate, verify, archive]]
* [[Editing inventory during playbook execution causes races]]
* [[Health Checks Verify Service Availability After Changes]]
* [[Homelabs mirror enterprise IaC, creating bidirectional feedback loops]]
* [[How cascading mistakes lead to infrastructure incidents]]
* [[Inventory is more than a flat list of hosts]]
* [[Inventory is one layer in a larger variable precedence system]]
* [[Jinja2 tests check conditions in when clauses and conditionals]]
* [[Lookups read external data into variables during playbook execution]]
* [[One slow host blocks the entire play during fact gathering]]
* [[Play and task keywords coexist in YAML; indentation signals scope]]
* [[Playbook files contain nested structures that are not visually distinct]]
* [[Playbook testing combines linting, role integration tests, and idempotency checks]]
* [[Shortcuts under deadline pressure compound into cascading failures]]
* [[Standardize distro families by workload role, not globally]]
* [[Troubleshooting Ansible module issues]]
* [[fd's simple syntax handles DevOps file searches efficiently]]
!! MOC — merged atoms
Atoms that were consolidated from 2+ source concepts during cross-dedup (833 total). Reading these is a cheap way to see where the pipeline found duplication worth collapsing.
* [[A playbook fails to decrypt Vault data. What do you check?]]
* [[A variable is defined in playbook group_vars/all and also in inventory group_vars/webse…]]
* [[AWX, Ansible Tower, and Ansible Automation Platform explained]]
* [[Always run --check --diff before production Ansible changes]]
* [[Ansible Collections: packaging and distribution format]]
* [[Ansible Facts and the gather_facts task]]
* [[Ansible Galaxy: community hub for roles and collections]]
* [[Ansible Modules]]
* [[Ansible SSH pipelining reduces connection round-trips]]
* [[Ansible Vault: AES-256 secret encryption for version-controlled playbooks]]
* [[Ansible Vault: encrypting sensitive data in playbooks]]
* [[Ansible `serial` keyword for batched rolling updates]]
* [[Ansible `template` module]]
* [[Ansible ad-hoc commands execute one-off tasks without playbooks]]
* [[Ansible async/poll decouples long task submission from completion]]
* [[Ansible block/rescue/always implements try-catch-finally error handling]]
* [[Ansible control node]]
* [[Ansible debug module: printing messages during playbook execution]]
* [[Ansible dry run: --check and --diff for safe change preview]]
* [[Ansible dynamic inventory scripts: execution and JSON schema]]
* [[Ansible facts: auto-discovered host variables]]
* [[Ansible handlers skip entirely if the play fails]]
* [[Ansible handlers: conditional, once-only task execution]]
* [[Ansible installation and configuration on Linux]]
* [[Ansible inventory file: definition and configuration]]
* [[Ansible inventory maps hosts into groups with hierarchical variables]]
* [[Ansible is sometimes described as "procedural" while Puppet is "declarative." What does…]]
* [[Ansible managed node]]
* [[Ansible manages Windows servers via WinRM]]
* [[Ansible originated from a weekend prototype in February 2012]]
* [[Ansible performance optimization for large inventories]]
* [[Ansible playbook error handling: block/rescue/always, retries, and ignore_errors]]
* [[Ansible playbooks without --limit run against all inventory]]
* [[Ansible strategy plugins control task-execution ordering across hosts]]
* [[Ansible strategy plugins: built-in options and defaults]]
* [[Ansible task debugging: verbosity, register, and mode flags]]
* [[Ansible template/copy validate: prevents config file disasters]]
* [[Ansible variable precedence silently shadows lower-priority settings]]
* [[Ansible vs. Chef/Puppet: key architectural differences]]
* [[Ansible's 22 variable precedence levels mirror infrastructure hierarchy]]
* [[Ansible's Jinja2 converter silently changes strings to booleans, a common footgun]]
* [[Ansible's agentless design: SSH over a custom control protocol]]
* [[Ansible's cowsay Easter egg was designed for morale]]
* [[Ansible's fact gathering was inspired by Chef Ohai and Puppet Facter]]
* [[Ansible's idempotency guarantee is aspirational, not enforced]]
* [[Ansible: Managing Multiple Environments with Separate Inventories]]
* [[Ansible: agentless IT automation tool]]
* [[Before Ansible 2.10, how was all community-contributed content structured?]]
* [[Besides git, what other VCS does ansible-pull support?]]
* [[Best practices for writing clean, maintainable Ansible playbooks]]
* [[Can Ansible Vault encrypt an entire directory?]]
* [[Can Ansible use SSH to manage Windows?]]
* [[Can `serial` accept a list? What does that do?]]
* [[Can `serial` be expressed as a percentage?]]
* [[Can a handler notify another handler?]]
* [[Can async tasks run in check mode?]]
* [[Can handlers notify other handlers?]]
* [[Can individual ansible.cfg settings be overridden by environment variables?]]
* [[Can rulebooks call Ansible Automation Platform job templates?]]
* [[Can tags be applied to roles?]]
* [[Can tags be inherited through `include_tasks`?]]
* [[Can you apply tags to roles, blocks, and imports?]]
* [[Can you encrypt only specific variables in a file?]]
* [[Can you force a specific task to always or never run in check mode?]]
* [[Can you install collections from a tarball?]]
* [[Can you loop over `import_tasks`?]]
* [[Can you override an extra var with set_fact?]]
* [[Can you run Ansible on Windows as a control node?]]
* [[Can you set strategy globally?]]
* [[Can you set variables with magic variable names?]]
* [[Can you use `when` conditions with `import_tasks`?]]
* [[Can you use more than one connection plugin per host in a single play?]]
* [[Can you use multiple vault passwords in a single playbook run?]]
* [[Can you write custom Ansible modules?]]
* [[Collections split in 2020 broke thousands of existing Ansible playbooks]]
* [[Default inventory pointing to production invites unintended changes]]
* [[Detecting and Handling Configuration Drift with Ansible]]
* [[Does `poll: 0` automatically clean up the async job cache file?]]
* [[Dynamic inventory in Ansible]]
* [[Dynamic inventory plugins auto-discover cloud hosts via provider APIs]]
* [[Execution Environments solved the dependency-conflict problem in Ansible]]
* [[Explain the versioning split that happened at Ansible 2.10. What are the two separate p…]]
* [[Fact caching avoids expensive repeated gathering]]
* [[Give an example of an ad-hoc ping command.]]
* [[Global become: true escalates all tasks]]
* [[How are Steering Committee members selected?]]
* [[How are Windows modules different from Linux modules internally?]]
* [[How are facts gathered?]]
* [[How are lookup plugins different from filter plugins in how they execute?]]
* [[How are module arguments passed to the remote module under Ansiballz?]]
* [[How can you detect check mode inside a playbook?]]
* [[How can you run a specific task or play within an Ansible playbook for testing?]]
* [[How did Ansible end up under IBM's umbrella?]]
* [[How do AWX and Red Hat Ansible Automation Platform differ?]]
* [[How do `selectattr` and `rejectattr` work?]]
* [[How do you access a variable of the first host in a group?]]
* [[How do you access nested variables?]]
* [[How do you backup router configurations with Ansible?]]
* [[How do you check a playbook's syntax without running it?]]
* [[How do you check disk space on all hosts ad-hoc?]]
* [[How do you check the status of a fire-and-forget async task?]]
* [[How do you configure a dynamic inventory for AWS EC2?]]
* [[How do you create a custom Jinja2 filter for Ansible?]]
* [[How do you create a new role skeleton?]]
* [[How do you create an encrypted file using Ansible Vault?]]
* [[How do you decrypt a file?]]
* [[How do you disable automatic fact gathering?]]
* [[How do you disable fact gathering?]]
* [[How do you edit an encrypted file?]]
* [[How do you enable a callback plugin?]]
* [[How do you enable a notification callback plugin?]]
* [[How do you enable verbose mode for Ansible playbooks?]]
* [[How do you encrypt a single string variable?]]
* [[How do you fire-and-forget a long-running task?]]
* [[How do you force handlers to run mid-play?]]
* [[How do you generate a password hash suitable for /etc/shadow in Ansible?]]
* [[How do you generate an encrypted password for the user module?]]
* [[How do you handle a playbook that exposes sensitive data in logs?]]
* [[How do you handle external secret lookups?]]
* [[How do you handle version control for playbooks?]]
* [[How do you implement RBAC in Ansible Tower?]]
* [[How do you implement blue-green deployments with Ansible?]]
* [[How do you implement canary deployments with Ansible?]]
* [[How do you implement zero-downtime deployments?]]
* [[How do you include roles in a playbook?]]
* [[How do you inspect the contents of an EE image using ansible-navigator?]]
* [[How do you install a collection from a specific Git repository?]]
* [[How do you install a collection?]]
* [[How do you install a package using an ad-hoc command?]]
* [[How do you install a specific version of a collection?]]
* [[How do you install collections from a requirements file?]]
* [[How do you integrate Ansible with Jenkins?]]
* [[How do you invoke a lookup plugin in a playbook?]]
* [[How do you loop over a list of items?]]
* [[How do you loop over hosts in a group inside a template?]]
* [[How do you manage secrets across multiple environments?]]
* [[How do you pass variables to Ansible at runtime?]]
* [[How do you provision AWS EC2 instances with Ansible?]]
* [[How do you reboot a host and wait for it to come back?]]
* [[How do you reference a variable in a playbook?]]
* [[How do you reference vault-encrypted variables in a playbook?]]
* [[How do you run Ansible tasks inside an existing container?]]
* [[How do you run a playbook in verbose mode?]]
* [[How do you run a playbook that uses vault-encrypted files?]]
* [[How do you run ansible-navigator without an Execution Environment (in local mode)?]]
* [[How do you run tasks asynchronously?]]
* [[How do you securely manage control node credentials?]]
* [[How do you select a specific lint profile on the command line?]]
* [[How do you set the PATH or environment variables for a task?]]
* [[How do you set the strategy for a play?]]
* [[How do you set up a jump host (bastion) in Ansible?]]
* [[How do you specify a custom inventory file?]]
* [[How do you specify role dependencies?]]
* [[How do you specify the SSH user for Ansible?]]
* [[How do you specify which Ansible collections to include in an EE?]]
* [[How do you start a playbook at a specific task?]]
* [[How do you test a specific scenario when multiple exist?]]
* [[How do you test playbooks?]]
* [[How do you use a script to provide vault passwords?]]
* [[How do you use variables in Jinja2 templates?]]
* [[How do you view all facts for a host?]]
* [[How do you view an encrypted file without decrypting?]]
* [[How do you write a conditional in Jinja2?]]
* [[How do you write a conditional task in Ansible?]]
* [[How do you write a loop in Jinja2?]]
* [[How does Ansible communicate with Linux hosts?]]
* [[How does Ansible communicate with Windows hosts?]]
* [[How does Ansible differ from Puppet?]]
* [[How does Ansible differ from SaltStack?]]
* [[How does Ansible differ from other configuration management tools?]]
* [[How does Ansible interact with Docker?]]
* [[How does Ansible interact with Kubernetes?]]
* [[How does Ansible manage network devices?]]
* [[How does Mitogen achieve its performance gains?]]
* [[How does Mitogen transfer data?]]
* [[How does `become` work differently on Windows?]]
* [[How does `changed_when` work?]]
* [[How does `failed_when` work?]]
* [[How does `include_vars` compare to `vars_files` in precedence?]]
* [[How does `serial` support rolling updates?]]
* [[How does a custom module return data to Ansible?]]
* [[How does an event payload get passed to a triggered playbook?]]
* [[How does ansible-pull know which playbook to run?]]
* [[How does inventory caching work?]]
* [[How does privilege escalation work on network devices like Cisco IOS?]]
* [[How does the YAML octal gotcha specifically bite Ansible users?]]
* [[How does the `free` strategy differ from `linear`?]]
* [[How is Ansible used in a CI/CD pipeline?]]
* [[How is `set_fact` different from `vars`?]]
* [[How is ansible-pull typically scheduled?]]
* [[How long is each ansible-core major version maintained?]]
* [[How many collections are typically included in the Ansible community package?]]
* [[How many employees did Ansible, Inc. have at the time of the Red Hat acquisition?]]
* [[How many forks does Ansible use by default?]]
* [[How many levels of variable precedence does Ansible have?]]
* [[How many modules were in the monolithic Ansible 2.9 repository before the split?]]
* [[How many stdout-type callback plugins can be active at once?]]
* [[How often does ansible-core release a new major version?]]
* [[How would you apply BGP configuration across 100 routers with minimum downtime?]]
* [[How would you design a reusable playbook for multiple environments?]]
* [[Idempotence is the core contract of Ansible modules]]
* [[If a rescue section succeeds, does Ansible consider the play failed?]]
* [[If both ANSIBLE_CONFIG and a local ansible.cfg exist in the current directory, which wins?]]
* [[If you create a custom fact in the same play, how do you access it?]]
* [[If you set a fact with set_fact and also define the same variable as a role parameter, …]]
* [[If you specify both --tags and --skip-tags for the same tag, what happens?]]
* [[Installing Ansible Galaxy roles from CLI and requirements file]]
* [[Is Ansible open-source?]]
* [[Jinja2 filters transform values during template rendering]]
* [[Limit Ansible playbook execution to specific hosts]]
* [[List all 22 variable precedence levels from lowest to highest.]]
* [[List all the string values that YAML 1.1 interprets as boolean false.]]
* [[Listing and inspecting Ansible modules with ansible-doc]]
* [[Many people attribute the word "ansible" to Orson Scott Card's *Ender's Game*. Why is t…]]
* [[Michael DeHaan stepped back from Ansible after Red Hat acquisition]]
* [[Mitogen strategy plugin accelerates Ansible by replacing SSH execution]]
* [[Molecule: Ansible role testing framework]]
* [[Name all the major connection plugin types in Ansible.]]
* [[Name five Ansible-specific filters not found in stock Jinja2.]]
* [[Name five Jinja2 built-in filters commonly used in Ansible playbooks.]]
* [[Name five ansible-lint rules.]]
* [[Name five dynamic inventory plugins included in popular collections.]]
* [[Name five major collections that were extracted from the monolithic Ansible repo during…]]
* [[Name five notable callback plugins.]]
* [[Name some built-in callback plugins.]]
* [[Name ten commonly used lookup plugins.]]
* [[Name three enterprise features that Ansible Tower/Controller has that AWX lacks.]]
* [[Name three event source plugins in the `ansible.eda` collection.]]
* [[Name three strategies to keep playbooks DRY.]]
* [[Optimizing Ansible Playbook Performance]]
* [[Orchestration in Ansible: coordinating tasks across systems]]
* [[Playbook failure diagnosis pattern]]
* [[Prefer native modules over shell/command for idempotency]]
* [[Privilege escalation chain: SSH user → become → become_user]]
* [[Progressive Environment-Based Rollout Reduces Blast Radius]]
* [[Red Hat acquired Ansible in 2015 for $150M]]
* [[Red Hat open-sourced AWX while selling Ansible Tower as a commercial product]]
* [[Roles organize reusable Ansible code into directories]]
* [[SSH pipelining and ControlPersist are the single biggest performance wins]]
* [[Serial Batching and Max-Failure Limit Contain Rollout Risk]]
* [[Troubleshooting Ansible module issues]]
* [[Under what namespace are custom local facts accessible?]]
* [[Use failed_when instead of blanket ignore_errors]]
* [[Vault Passwords Must Not Appear in Shell History or Plain Text]]
* [[What AI model powers Ansible Lightspeed?]]
* [[What Ansible community package version corresponds to ansible-core 2.14?]]
* [[What Ansible module is used to create scheduled tasks on Windows?]]
* [[What Jinja2 filter returns a default value when a variable is undefined?]]
* [[What Molecule command runs only the verify step without re-converging?]]
* [[What Python and Java versions does ansible-rulebook require?]]
* [[What Python class must every custom Ansible module import?]]
* [[What Python library does the `netconf` connection plugin use under the hood?]]
* [[What Python package manager does Ansible recommend for installation?]]
* [[What Python packages are required on the control node for WinRM?]]
* [[What Python version does ansible-core 2.17+ require on managed nodes?]]
* [[What YAML multiline syntax options does Ansible support, and what are the key differences?]]
* [[What ansible-lint rule catches boolean value problems in YAML?]]
* [[What are "magic variables" in Ansible?]]
* [[What are "resource modules" in network automation?]]
* [[What are Ansible "playbooks"?]]
* [[What are Ansible "tags"?]]
* [[What are Ansible Validated Content collections for cloud?]]
* [[What are Ansible Working Groups?]]
* [[What are Ansible plugins?]]
* [[What are Ansible test plugins?]]
* [[What are Ansible's default privilege escalation methods?]]
* [[What are Surveys in AWX/automation controller?]]
* [[What are Vault IDs?]]
* [[What are `group_vars` and `host_vars`?]]
* [[What are best practices for Ansible role organization?]]
* [[What are connection plugins?]]
* [[What are custom facts (local facts) and where do they live?]]
* [[What are execution nodes vs hop nodes in automation mesh?]]
* [[What are inventory plugins?]]
* [[What are key limitations of Mitogen?]]
* [[What are lookup plugins?]]
* [[What are network resource modules?]]
* [[What are some best practices for effective debugging and troubleshooting with Ansible?]]
* [[What are strategy plugins?]]
* [[What are tags used for?]]
* [[What are the `_raw_params` in free-form modules?]]
* [[What are the `gather_subset` and `gather_timeout` options?]]
* [[What are the `mutually_exclusive`, `required_together`, `required_one_of`, `required_if…]]
* [[What are the available gather_subset categories?]]
* [[What are the five reserved tag names in Ansible?]]
* [[What are the four verbosity levels in Ansible?]]
* [[What are the key features of Ansible?]]
* [[What are the key parts of an EDA rulebook?]]
* [[What are the key phases in a Molecule test sequence?]]
* [[What are the key sections in an `execution-environment.yml` file?]]
* [[What are the main components of Ansible's architecture?]]
* [[What are the main components of Red Hat Ansible Automation Platform (AAP) 2.x?]]
* [[What are the server requirements for Ansible?]]
* [[What are the six ansible-lint profiles in order from least to most strict?]]
* [[What are the special tags `always` and `never`?]]
* [[What are the three Mitogen strategy plugins?]]
* [[What are the three main components of an Ansible rulebook?]]
* [[What are the three main connection types for network automation?]]
* [[What are the three main things to investigate for a slow playbook on 500 hosts?]]
* [[What are the two built-in inventory file formats?]]
* [[What are the two categories of Ansible modules?]]
* [[What are the two categories of callback plugins?]]
* [[What are the two display modes in ansible-navigator?]]
* [[What are the two types of inventory?]]
* [[What are variables in Ansible?]]
* [[What authentication methods does WinRM support?]]
* [[What base class do lookup plugins inherit from?]]
* [[What callback plugin profiles memory usage of Ansible tasks?]]
* [[What callback plugin would you use to profile task execution times?]]
* [[What cannot collection role names contain?]]
* [[What class attributes must a callback plugin define?]]
* [[What collection is the `ipaddr` filter now in, and why?]]
* [[What collection provides AWS modules?]]
* [[What collection provides Docker modules and connection plugins?]]
* [[What collection provides Podman modules and connection plugins?]]
* [[What collection provides platform-independent network modules?]]
* [[What command initializes a new collection skeleton?]]
* [[What command initializes a new role skeleton?]]
* [[What command lists all hosts in an inventory?]]
* [[What command runs a rulebook?]]
* [[What command runs an Ansible playbook?]]
* [[What command shows the Ansible version?]]
* [[What configuration file does ansible-lint use?]]
* [[What configuration file does ansible-navigator use?]]
* [[What configuration language does each tool use?]]
* [[What connection plugin is used for network devices?]]
* [[What connection type does ansible-pull use?]]
* [[What controversy surrounds Ansible Lightspeed and the community?]]
* [[What did Ansible 2.5 introduce that changed how network automation worked?]]
* [[What do `async` and `poll` do together in a task?]]
* [[What does "agentless" mean in the context of Ansible?]]
* [[What does YAML stand for?]]
* [[What does `--diff` do?]]
* [[What does `--tags tagged` mean?]]
* [[What does `ANSIBLE_NOCOWS` do?]]
* [[What does `ansible-inventory --list` do?]]
* [[What does `ansible-vault rekey` do?]]
* [[What does `ansible_check_mode` contain?]]
* [[What does `ansible_search_path` contain?]]
* [[What does `become` do?]]
* [[What does `changed_when` do?]]
* [[What does `connection: local` do?]]
* [[What does `delegate_to` do?]]
* [[What does `force_handlers: yes` do?]]
* [[What does `group_names` contain?]]
* [[What does `ignore_errors: true` do?]]
* [[What does `loop_control: extended` provide?]]
* [[What does `meta/main.yml` in a role contain?]]
* [[What does `meta/runtime.yml` in a collection do?]]
* [[What does `meta: end_host` do?]]
* [[What does `meta: flush_handlers` do?]]
* [[What does `meta: reset_connection` do?]]
* [[What does `module_defaults` do at the play or block level?]]
* [[What does `no_log: true` do, and how does it relate to Vault?]]
* [[What does `no_log: true` do?]]
* [[What does `regex_replace` do?]]
* [[What does `run_once: true` do?]]
* [[What does `state: absent` mean in a module?]]
* [[What does `state: latest` mean in package modules?]]
* [[What does `state: present` mean in a module?]]
* [[What does `throttle` do at the task level?]]
* [[What does `wantlist=True` do in a lookup?]]
* [[What does `{{ list | map('extract', dict) }}` do?]]
* [[What does ansible-pull require on each managed node?]]
* [[What does the `--ask-vault-pass` flag do?]]
* [[What does the `ANSIBLE_KEEP_REMOTE_FILES` setting do?]]
* [[What does the `Constructable` base class provide to inventory plugins?]]
* [[What does the `ansible-galaxy` CLI do?]]
* [[What does the `apt` module do?]]
* [[What does the `async` keyword do?]]
* [[What does the `combine` filter do, and why is it so useful?]]
* [[What does the `combine` filter do?]]
* [[What does the `command` module do?]]
* [[What does the `copy` module do?]]
* [[What does the `cron` module do?]]
* [[What does the `debug` module do?]]
* [[What does the `debug` strategy allow?]]
* [[What does the `default` filter do?]]
* [[What does the `docker_container` module do?]]
* [[What does the `fetch` module do?]]
* [[What does the `file` module do?]]
* [[What does the `flatten` filter do?]]
* [[What does the `fqcn` lint rule require?]]
* [[What does the `gather_facts: false` optimization do?]]
* [[What does the `groups` magic variable contain?]]
* [[What does the `hosts` keyword define in a play?]]
* [[What does the `hostvars` magic variable contain?]]
* [[What does the `idempotence` step verify?]]
* [[What does the `lineinfile` module do?]]
* [[What does the `mandatory` filter do?]]
* [[What does the `map` filter do with the `attribute` keyword?]]
* [[What does the `min` lint profile enforce?]]
* [[What does the `never` tag do?]]
* [[What does the `package` module do?]]
* [[What does the `ping` module do?]]
* [[What does the `production` lint profile add on top of `shared`?]]
* [[What does the `safety` lint profile add?]]
* [[What does the `service` module do?]]
* [[What does the `setup` module do?]]
* [[What does the `shell` module do?]]
* [[What does the `synchronize` module do?]]
* [[What does the `user` module do?]]
* [[What does the `wait_for` module do?]]
* [[What does the `yum` module do?]]
* [[What drivers does Molecule support for creating test instances?]]
* [[What encryption algorithm does Ansible Vault use?]]
* [[What environment variable disables Ansible's cowsay output?]]
* [[What features does Ansible Tower/AWX provide?]]
* [[What file extension does the AWS EC2 inventory plugin expect?]]
* [[What file extension is used for Jinja2 templates?]]
* [[What file format does Ansible use for its return data from modules?]]
* [[What file must exist in the root of an Ansible Galaxy role for it to be recognized?]]
* [[What filter would you use to base64-encode a string in Ansible?]]
* [[What happened to AnsibleFest after 2022?]]
* [[What happened to `with_items`, `with_dict`, `with_file`, etc.?]]
* [[What happened to `with_items`, `with_dict`, `with_fileglob` etc.?]]
* [[What happens after a rulebook condition matches an event?]]
* [[What happens if a handler is notified multiple times?]]
* [[What happens if a task exceeds its `async` timeout?]]
* [[What happens if two collections provide a module with the same short name?]]
* [[What happens if you reference an undefined variable?]]
* [[What happens if you use `vars_prompt` in Ansible Tower/Controller?]]
* [[What happens if you use a short module name (e.g., "copy") instead of the FQCN in a pos…]]
* [[What happens if you write `version: 1.0` in YAML without quotes?]]
* [[What happens when `run_once` is combined with `serial`?]]
* [[What happens when you apply `become: true` with the `local` connection?]]
* [[What happens when you use `creates` or `removes` with command/shell modules?]]
* [[What happens with `port: 22` vs `port: "22"` in Ansible YAML?]]
* [[What has the highest variable precedence?]]
* [[What has the lowest variable precedence?]]
* [[What indentation is recommended for YAML?]]
* [[What internal arguments does Ansible automatically inject into every module call?]]
* [[What is AWX?]]
* [[What is Ansible Automation Hub, and how does it differ from Ansible Galaxy?]]
* [[What is Ansible Lightspeed?]]
* [[What is Ansible Tower?]]
* [[What is BYOM in the context of Ansible Lightspeed?]]
* [[What is Event-Driven Ansible (EDA) and when was it introduced?]]
* [[What is Infrastructure as Code (IaC) and how does Ansible align with it?]]
* [[What is Instance Groups in AWX?]]
* [[What is Jinja2 in the context of Ansible?]]
* [[What is Mitogen for Ansible?]]
* [[What is Private Automation Hub?]]
* [[What is Puppet Bolt, and how is it similar to Ansible?]]
* [[What is SSH ControlPersist?]]
* [[What is `--vault-password-file`?]]
* [[What is `ANSIBLE_ROLES_PATH`?]]
* [[What is `ansible-builder`?]]
* [[What is `ansible-config dump`?]]
* [[What is `ansible-console`?]]
* [[What is `ansible-creator`?]]
* [[What is `ansible-doc` used for?]]
* [[What is `ansible-galaxy collection verify`?]]
* [[What is `ansible-inventory --graph`?]]
* [[What is `ansible-playbook --syntax-check`?]]
* [[What is `ansible-pull` and how does it invert Ansible's normal model?]]
* [[What is `ansible-test`?]]
* [[What is `ansible-vault encrypt_string` used for?]]
* [[What is `ansible.builtin.add_host`?]]
* [[What is `ansible.builtin.apt_key` and why is it deprecated?]]
* [[What is `ansible.builtin.lineinfile` vs `ansible.builtin.blockinfile`?]]
* [[What is `ansible.builtin.set_stats`?]]
* [[What is `ansible_connection` and where can it be set?]]
* [[What is `ansible_facts` vs top-level fact variables?]]
* [[What is `ansible_host` in inventory?]]
* [[What is `ansible_local`?]]
* [[What is `ansible_loop`?]]
* [[What is `ansible_network_os`, and why is it critical for network automation?]]
* [[What is `ansible_play_batch`?]]
* [[What is `ansible_play_hosts`?]]
* [[What is `ansible_play_name`?]]
* [[What is `ansible_port`?]]
* [[What is `ansible_python_interpreter`?]]
* [[What is `ansible_run_tags` and `ansible_skip_tags`?]]
* [[What is `ansible_version`?]]
* [[What is `any_errors_fatal` and when would you use it?]]
* [[What is `become_method`?]]
* [[What is `become_user`?]]
* [[What is `changed_when: false` used for?]]
* [[What is `check_mode: true` at the task level?]]
* [[What is `cli_command` vs platform-specific modules (e.g., ios_command)?]]
* [[What is `collections:` at the play level?]]
* [[What is `collections` keyword in a playbook?]]
* [[What is `creates` parameter in command/shell modules?]]
* [[What is `delegate_facts: true`?]]
* [[What is `delegate_to`?]]
* [[What is `diff: true` at the task level?]]
* [[What is `fact_caching`, and what backends does it support?]]
* [[What is `gather_subset` and how does it speed up fact gathering?]]
* [[What is `group_by` module?]]
* [[What is `groups` in Ansible?]]
* [[What is `hash_behaviour` in ansible.cfg?]]
* [[What is `host_key_checking`?]]
* [[What is `ignore_errors`?]]
* [[What is `ignore_unreachable`?]]
* [[What is `include_role` vs `import_role`?]]
* [[What is `inventory_dir`?]]
* [[What is `inventory_hostname_short`?]]
* [[What is `inventory_hostname`?]]
* [[What is `max_fail_percentage` used for?]]
* [[What is `max_fail_percentage`?]]
* [[What is `meta: clear_facts`?]]
* [[What is `meta: clear_host_errors`?]]
* [[What is `meta: end_play`?]]
* [[What is `omit`?]]
* [[What is `order` in a play?]]
* [[What is `play_hosts`?]]
* [[What is `playbook_dir`?]]
* [[What is `register` and what does the registered variable contain?]]
* [[What is `register` in Ansible?]]
* [[What is `removes` parameter in command/shell modules?]]
* [[What is `role_path`?]]
* [[What is `set_fact`?]]
* [[What is `supports_check_mode` in module development?]]
* [[What is `until` / `retries` / `delay` in a task?]]
* [[What is `vars_prompt`?]]
* [[What is `wait_for_connection` used for?]]
* [[What is a "fully qualified collection name" (FQCN)?]]
* [[What is a "tombstone" entry in Ansible's collection routing?]]
* [[What is a Decision Environment?]]
* [[What is a Fully Qualified Collection Name (FQCN), and why does it matter post-migration?]]
* [[What is a Fully Qualified Collection Name (FQCN)?]]
* [[What is a Job Template in AWX/automation controller?]]
* [[What is a Molecule scenario?]]
* [[What is a Smart Inventory?]]
* [[What is a Vault ID, and why would you use multiple?]]
* [[What is a Workflow Job Template?]]
* [[What is a Workflow in Tower/AWX?]]
* [[What is a callback plugin?]]
* [[What is a collection namespace?]]
* [[What is a group in an Ansible inventory?]]
* [[What is a lookup plugin in Ansible?]]
* [[What is a play in Ansible?]]
* [[What is a playbook `import_playbook`?]]
* [[What is a practical use case for async with poll > 0?]]
* [[What is a pre_task and post_task?]]
* [[What is a requirements.yml file for Galaxy?]]
* [[What is a rolling update strategy?]]
* [[What is a task in Ansible?]]
* [[What is an "Execution Environment" in the Ansible ecosystem?]]
* [[What is an "action plugin" and how does it differ from a module?]]
* [[What is an Ansible Execution Environment (EE)?]]
* [[What is an Ansible callback whitelist?]]
* [[What is an Ansible inventory?]]
* [[What is an Ansible playbook execution plan, and how can you generate it?]]
* [[What is ansible-lint?]]
* [[What is ansible.cfg?]]
* [[What is automation mesh?]]
* [[What is callback plugin `profile_tasks`?]]
* [[What is callback plugin `timer`?]]
* [[What is configuration drift?]]
* [[What is diff mode?]]
* [[What is fact caching?]]
* [[What is idempotency?]]
* [[What is provisioning?]]
* [[What is the "Norway Problem" in YAML, and how does it affect Ansible?]]
* [[What is the "canary deployment" pattern in Ansible?]]
* [[What is the "cow" in Ansible output?]]
* [[What is the "golden image" pattern using Ansible?]]
* [[What is the "idempotence" test phase in Molecule?]]
* [[What is the "include_role with conditionals" anti-pattern?]]
* [[What is the "naked variable" gotcha in Ansible YAML?]]
* [[What is the "pre_tasks / post_tasks" idiom for rolling updates?]]
* [[What is the "routing" configuration in the context of collections migration?]]
* [[What is the "two-stage" or "delegate and register" pattern?]]
* [[What is the Ansiballz framework?]]
* [[What is the Ansible Community Steering Committee?]]
* [[What is the Ansible Lightspeed "intelligent assistant"?]]
* [[What is the Ansible Tower rebrand name?]]
* [[What is the Ansible equivalent of try/catch/finally?]]
* [[What is the Community Working Group specifically?]]
* [[What is the FQCN for the AWS EC2 module?]]
* [[What is the Module Replacer framework?]]
* [[What is the Red Hat Certified Specialist in Ansible Automation exam called?]]
* [[What is the Tower/AWX REST API used for?]]
* [[What is the YAML octal number gotcha?]]
* [[What is the `.retry` file that Ansible creates?]]
* [[What is the `ANSIBLE_STDOUT_CALLBACK` environment variable?]]
* [[What is the `COLLECTIONS_PATHS` configuration?]]
* [[What is the `INJECT_FACTS_AS_VARS` configuration?]]
* [[What is the `INTERPRETER_PYTHON` configuration, and why was `auto` mode added?]]
* [[What is the `all` group?]]
* [[What is the `ansible.builtin.debug` module's `var` vs `msg` parameter?]]
* [[What is the `ansible.builtin.find` module?]]
* [[What is the `ansible.builtin.package` module?]]
* [[What is the `ansible.builtin.pause` module?]]
* [[What is the `ansible.builtin.reboot` module?]]
* [[What is the `ansible.builtin.script` module?]]
* [[What is the `ansible.cfg` `[inventory]` section's `enable_plugins` setting?]]
* [[What is the `ansible.posix` collection?]]
* [[What is the `ansible.windows` collection?]]
* [[What is the `ansible_become_exe` variable?]]
* [[What is the `ansible_connection` variable set to for network devices?]]
* [[What is the `ansible_date_time` fact?]]
* [[What is the `ansible_managed` variable?]]
* [[What is the `argument_spec` in a custom module?]]
* [[What is the `ask_pass` setting?]]
* [[What is the `assert` module used for?]]
* [[What is the `auto` interpreter discovery in Ansible?]]
* [[What is the `auto` inventory plugin?]]
* [[What is the `become_method` setting and what values does it support?]]
* [[What is the `block` keyword?]]
* [[What is the `cli_parse` module used for?]]
* [[What is the `cloud.terraform` collection?]]
* [[What is the `constructed` inventory plugin?]]
* [[What is the `converge` step in Molecule?]]
* [[What is the `debug` module's `verbosity` parameter?]]
* [[What is the `debug` strategy?]]
* [[What is the `environment` keyword at the task/play/block level?]]
* [[What is the `environment` keyword used for?]]
* [[What is the `expect` module?]]
* [[What is the `fail` module?]]
* [[What is the `failed_when: false` idiom?]]
* [[What is the `forks` setting, and what is its default value?]]
* [[What is the `gathered` state in network resource modules?]]
* [[What is the `host_pinned` strategy?]]
* [[What is the `httpapi` connection plugin?]]
* [[What is the `ipaddr` filter?]]
* [[What is the `listen` directive on handlers?]]
* [[What is the `local_action` keyword?]]
* [[What is the `lookup` plugin?]]
* [[What is the `loop_control` directive?]]
* [[What is the `meta` module used for?]]
* [[What is the `network_cli` connection plugin used for?]]
* [[What is the `no_log: true` directive?]]
* [[What is the `no_log` lint rule about?]]
* [[What is the `notify` keyword?]]
* [[What is the `omit` variable in Ansible?]]
* [[What is the `password_hash` filter?]]
* [[What is the `pause` module?]]
* [[What is the `psrp` connection plugin, and how does it differ from `winrm`?]]
* [[What is the `query` function, and how does it differ from `lookup`?]]
* [[What is the `raw` module, and when is it needed?]]
* [[What is the `raw` module?]]
* [[What is the `register` keyword?]]
* [[What is the `retry_until` pattern in Ansible?]]
* [[What is the `script` module?]]
* [[What is the `serial` keyword?]]
* [[What is the `service_facts` module?]]
* [[What is the `set_fact` module's `cacheable` option?]]
* [[What is the `set_stats` module?]]
* [[What is the `shared` lint profile intended for?]]
* [[What is the `synchronize` module?]]
* [[What is the `template` module's `output_encoding` parameter?]]
* [[What is the `ternary` filter?]]
* [[What is the `throttle` keyword?]]
* [[What is the `timeout` connection parameter?]]
* [[What is the `to_json` and `from_json` filter pair used for?]]
* [[What is the `ungrouped` group?]]
* [[What is the `uri` module?]]
* [[What is the `win_updates` module used for?]]
* [[What is the automation controller REST API used for?]]
* [[What is the default Ansible Galaxy server URL?]]
* [[What is the default base image used by ansible-builder?]]
* [[What is the default become method?]]
* [[What is the default connection plugin in Ansible?]]
* [[What is the default driver in modern Molecule?]]
* [[What is the default number of forks?]]
* [[What is the default poll interval?]]
* [[What is the default reboot timeout?]]
* [[What is the default strategy, and what is its key characteristic?]]
* [[What is the default verifier in Molecule 6+?]]
* [[What is the deprecation cycle length in ansible-core for features?]]
* [[What is the difference between `ansible_play_hosts` and `ansible_play_hosts_all`?]]
* [[What is the difference between `command` and `shell` modules?]]
* [[What is the difference between `community.docker.docker` and `community.docker.docker_a…]]
* [[What is the difference between `defaults/main.yml` and `vars/main.yml`?]]
* [[What is the difference between `free` and `host_pinned`?]]
* [[What is the difference between `ignore_errors: true` and using a `rescue` block?]]
* [[What is the difference between `include_tasks` and `import_tasks`?]]
* [[What is the difference between `inventory_hostname` and `ansible_hostname`?]]
* [[What is the difference between `is match` and `is search` tests?]]
* [[What is the difference between `lookup()` and `query()` in Ansible?]]
* [[What is the difference between `network_cli` and `httpapi` for network devices?]]
* [[What is the difference between `vars`, `vars_files`, and `vars_prompt`?]]
* [[What is the difference between `with_items` and `loop`?]]
* [[What is the difference between a Decision Environment and an Execution Environment in E…]]
* [[What is the difference between a Galaxy role and a Galaxy collection?]]
* [[What is the difference between a lookup and a filter?]]
* [[What is the difference between a playbook and a play?]]
* [[What is the difference between a playbook and an ad-hoc command?]]
* [[What is the difference between an Ansible playbook and a role?]]
* [[What is the difference between an inventory script and an inventory plugin?]]
* [[What is the difference between ansible-dev-tools and ansible-core?]]
* [[What is the difference between dot notation and array notation for variables?]]
* [[What is the difference between role defaults and role vars in terms of precedence?]]
* [[What is the difference between stdout callbacks and non-stdout callbacks?]]
* [[What is the difference between variable names and environment variables?]]
* [[What is the etymology of the word "ansible"?]]
* [[What is the exact search order for ansible.cfg files (highest to lowest priority)?]]
* [[What is the fundamental difference between `import_*` and `include_*`?]]
* [[What is the galaxy.yml file in a collection?]]
* [[What is the gotcha with `run_once` and `serial`?]]
* [[What is the latest ansible-core Python requirement (as of 2.20)?]]
* [[What is the major limitation of check mode?]]
* [[What is the maximum recommended inventory size for a single Ansible control node?]]
* [[What is the most downloaded Ansible Galaxy role author namespace?]]
* [[What is the namespace.collection format, and why does it matter?]]
* [[What is the naming convention for Ansible environment variable overrides?]]
* [[What is the obscure `ANSIBLE_FORCE_COLOR` environment variable?]]
* [[What is the precedence order if the same variable is defined in group_vars for a parent…]]
* [[What is the push-based model in Ansible?]]
* [[What is the relationship between Ansible Tower and Automation Controller?]]
* [[What is the relationship between Jinja2's built-in filters and Ansible's filters?]]
* [[What is the relationship between ansible-core and the ansible package?]]
* [[What is the security concern with `./ansible.cfg` in the current directory?]]
* [[What is the security risk of using `shell` or `command` modules with user-supplied vari…]]
* [[What is the security warning about Vault and "data at rest" vs. "data in use"?]]
* [[What is the single most important thing to remember about extra vars (-e)?]]
* [[What is the standard collection directory structure?]]
* [[What is the standard directory structure of an Ansible role?]]
* [[What is the standard role directory structure?]]
* [[What is the structure of an EDA rulebook?]]
* [[What is the syntax of an ad-hoc command?]]
* [[What key inventory object methods are used in plugin development?]]
* [[What keyword defines tasks in a playbook?]]
* [[What language is Ansible written in?]]
* [[What language is Ansible written in? What about Puppet, Chef, and SaltStack?]]
* [[What major AAP 2.5 feature unified the user experience across components?]]
* [[What makes SaltStack's execution speed notably faster than Ansible for large fleets?]]
* [[What method must a lookup plugin implement?]]
* [[What method prefix do v2 callback plugin methods use?]]
* [[What module adds or modifies lines in files?]]
* [[What module checks the status of a previously fired async task?]]
* [[What module copies files from remote to local?]]
* [[What module creates and manages Podman containers?]]
* [[What module creates directories?]]
* [[What module gathers facts by default at the start of each play?]]
* [[What module is used to gather system information?]]
* [[What module is used to reboot a host?]]
* [[What module manages SELinux?]]
* [[What module manages cron jobs?]]
* [[What module manages firewall rules?]]
* [[What module manages systemd services?]]
* [[What module manages users?]]
* [[What module tests if a file exists on a remote host?]]
* [[What module would you use to wait for a port to become available?]]
* [[What must a filter plugin Python file contain?]]
* [[What open-source tool can dramatically speed up Ansible by replacing SSH with a custom …]]
* [[What other connection optimizations exist beyond Mitogen?]]
* [[What other tools did Michael DeHaan create before Ansible?]]
* [[What playbook filename does ansible-pull look for by default?]]
* [[What port does Ansible use by default for SSH connections?]]
* [[What port does WinRM use by default for Ansible Windows management?]]
* [[What protocol does Ansible use to manage Windows hosts?]]
* [[What rule does `no-changed-when` enforce?]]
* [[What science fiction novel first coined the word "ansible," and who wrote it?]]
* [[What shift in AAP 2.5 changed how the platform is deployed?]]
* [[What special group exists in every Ansible inventory?]]
* [[What speedup can Mitogen provide?]]
* [[What steps would you take to debug an issue with Ansible Container?]]
* [[What steps would you take to troubleshoot a failed Ansible playbook?]]
* [[What subcommand in ansible-navigator lists available collections inside an EE?]]
* [[What symbol starts a list item in YAML?]]
* [[What tasks cannot be delegated?]]
* [[What timeout does the reboot module use by default?]]
* [[What tool is used to build Execution Environments?]]
* [[What two methods must a custom inventory plugin implement?]]
* [[What two open-source projects did Michael DeHaan create before Ansible, both at Red Hat?]]
* [[What types of errors do NOT trigger the rescue block?]]
* [[What valid `type` values can be used in argument_spec?]]
* [[What verifiers does Molecule support?]]
* [[What versioning scheme does ansible-core follow vs the ansible package?]]
* [[What was "ansible-base" and when did it appear?]]
* [[What was Michael DeHaan's job before creating Ansible, and why did he leave?]]
* [[What was significant about Ansible 1.0, and when was it released?]]
* [[What was the approximate annual cost of Ansible Tower licensing before the AAP rebrand?]]
* [[What was the first AnsibleFest, and when did it take place?]]
* [[What was the first commit to the Ansible GitHub repository, and approximately when?]]
* [[What was the major architectural change in Ansible 2.0?]]
* [[What was the old-style dynamic inventory approach before inventory plugins?]]
* [[What was the original company name behind Ansible before it became "Ansible, Inc."?]]
* [[What year did Ansible 2.0 introduce the new execution engine?]]
* [[What year did Ansible Galaxy launch?]]
* [[What year did Ansible Tower (the commercial UI product) first appear?]]
* [[What year was Ansible Lightspeed announced?]]
* [[What year was Ansible first released?]]
* [[What year was Event-Driven Ansible (EDA) first introduced?]]
* [[When and by whom was Ansible acquired?]]
* [[When did Ansible collections replace the monolithic package?]]
* [[When did Ansible drop Python 2 support on the control node?]]
* [[When did IBM acquire Red Hat?]]
* [[When did Red Hat acquire Ansible?]]
* [[When did the collections concept first appear in Ansible?]]
* [[When do handlers execute?]]
* [[When is ansible-pull appropriate?]]
* [[When is ansible-pull preferred over the normal push model?]]
* [[When should you use a role vs a simple task file?]]
* [[When should you use ad-hoc commands vs playbooks?]]
* [[When was Ansible 2.10 (the first "split" release) published?]]
* [[When was Ansible Lightspeed generally available?]]
* [[When was Ansible Tower renamed to automation controller?]]
* [[When was the last time the migration script (migrate.py) was run to move content from t…]]
* [[When would you use ansible-pull instead of the default push model?]]
* [[When would you use the `free` strategy?]]
* [[When would you use the `local` connection plugin?]]
* [[Where are remote temporary files stored on managed nodes?]]
* [[Where can variables be defined?]]
* [[Where did the Ansible community move after leaving IRC?]]
* [[Where do `set_fact` and registered vars fall in precedence?]]
* [[Where do network modules execute -- on the control node or managed node?]]
* [[Where does Molecule store scenario configuration?]]
* [[Where does the Steering Committee conduct business?]]
* [[Where does the name "Ansible" come from?]]
* [[Where is the default inventory file located?]]
* [[Where should custom filter plugins be placed?]]
* [[Where was Ansible, Inc. originally based before the Red Hat acquisition?]]
* [[Which config management tool uses a "master-minion" architecture with a ZeroMQ message …]]
* [[Which of the "big four" (Ansible, Puppet, Chef, Salt) are agentless?]]
* [[Which tool came first chronologically: Puppet, Chef, Ansible, or Salt?]]
* [[Which tools are push-based vs. pull-based by default?]]
* [[Who created Ansible and when?]]
* [[Who created Ansible, and in what year was it first released?]]
* [[Who is Jeff Geerling and why is he significant to the Ansible community?]]
* [[Why do Ansible community package version numbers jump from 2.10 to 3.0, 4.0, etc., whil…]]
* [[Why do Execution Environments exist when Python virtual environments (venvs) already ex…]]
* [[Why do you always use `{{ }}` in Ansible except in `when` clauses?]]
* [[Why does Ansible have separate Python requirements for control node vs. managed nodes?]]
* [[Why does Ansible mark all strings returned by modules as "Unsafe"?]]
* [[Why does Ansible refuse to load an ansible.cfg from a world-writable current directory?]]
* [[Why don't Juniper Junos Ansible modules require Python on the device?]]
* [[Why is CredSSP sometimes needed for Windows automation?]]
* [[Why is YAML 1.2 relevant to Ansible's future?]]
* [[Why is `hash_behaviour: merge` deprecated?]]
* [[Why was the monolithic repo problematic?]]
* [[YAML choice for Ansible prioritized non-programmer accessibility]]
* [[You deploy configuration but servers show inconsistent settings. How do you detect and …]]
* [[You have a slow playbook on 500 hosts. What do you investigate first?]]
* [[Zuul's circular dependency: testing Ansible with Ansible]]
* [[ansible-doc: offline module documentation reference]]
* [[ansible-navigator: modern replacement for ansible-playbook]]
* [[ansible-pull inverts the model to pull-based configuration management]]
* [[ansible_ssh_common_args: appending SSH args to all SSH connections]]
!! Maps of Content
! By kind
* [[MOC: compendium q&a]]
* [[MOC: flashcards]]
* [[MOC: footguns]]
* [[MOC: other]]
! By confidence
* [[MOC: confidence high]]
* [[MOC: confidence mid]]
! Quality
* [[MOC: merged atoms]]
canonical atomic concepts, deduplicated across all ansible sources
GettingStarted
[[MOC: index]]
[[GettingStarted]]
[[MOC: index]]
----
''By kind''
* [[MOC: footguns]]
* [[MOC: trivia]]
* [[MOC: flashcards]]
* [[MOC: compendium q&a]]
* [[MOC: primer]]
* [[MOC: anti-primer]]
* [[MOC: street ops]]
* [[MOC: cheatsheet]]
----
''By confidence''
* [[MOC: confidence high]]
* [[MOC: confidence mid]]
----
''Quality''
* [[MOC: merged atoms]]
!! Ansible — atoms deck
''1017 atoms'' — canonical atomic concepts, deduplicated across all ansible sources
//Each tiddler is one atomic concept. Sources and related atoms are listed in the footer. Cross-dedup has already merged duplicates, so every concept should appear exactly once.//
! Start here
* [[MOC: index]] — master index of MOCs
* [[MOC: merged atoms]] — concepts consolidated from multiple sources
! Breakdown — by kind
|!Kind|!Count|!Jump|h
|Compendium Q&A|746|[[MOC: compendium q&a]]|
|Flashcards|135|[[MOC: flashcards]]|
|Other|128|[[MOC: other]]|
|Footguns|8|[[MOC: footguns]]|
! Breakdown — by confidence
|!Band|!Count|!Jump|h
|high|992|[[MOC: confidence high]]|
|mid|25|[[MOC: confidence mid]]|
! Pipeline provenance
* Raw extracted atoms (whole corpus): 17641
* After intra-source dedup (whole corpus): 7753
* In this deck (domain = ansible, post cross-dedup): 1017
* Atoms in this deck merged from multiple sources: 833
See ''FULL-CORPUS-REPORT.md'' in the grokzett repo for full metrics.
/* grokzett TWC deck theme overrides */
body, #contentWrapper { font-family: -apple-system, "Segoe UI", Roboto, "Helvetica Neue", sans-serif; }
.tiddler { margin-bottom: 1.5em; }
.tiddler .title { font-size: 1.4em; letter-spacing: -0.01em; }
.viewer { line-height: 1.55; }
.viewer h1, .viewer h2, .viewer h3 { border-bottom: none; margin-top: 1.2em; }
.viewer h1 { font-size: 1.35em; }
.viewer h2 { font-size: 1.20em; }
.viewer h3 { font-size: 1.05em; color: #444; }
.viewer blockquote { border-left: 3px solid #c9d6df; margin: 1em 0; padding: 0.2em 1em; background: #f6f9fb; color: #333; }
.viewer code { background: #f2f2f2; padding: 1px 5px; border-radius: 3px; font-size: 0.92em; }
.viewer pre { background: #282c34; color: #abb2bf; padding: 0.8em 1em; border-radius: 6px; overflow-x: auto; font-size: 0.88em; line-height: 1.4; }
.viewer pre code { background: transparent; padding: 0; color: inherit; border-radius: 0; }
.viewer pre.literal { background: #282c34; color: #abb2bf; }
.viewer table { border-collapse: collapse; margin: 1em 0; font-size: 0.92em; width: auto; }
.viewer th, .viewer td { border: 1px solid #d8dee4; padding: 6px 10px; }
.viewer th { background: #eef2f6; text-align: left; }
.viewer tr:nth-child(even) td { background: #fbfcfd; }
.viewer hr { border: none; border-top: 1px solid #dde3e9; margin: 1.5em 0; }
.tagged { background: #eef5fb; padding: 4px 8px; border-radius: 4px; margin-right: 4px; }
/* grokzett status controls (injected by features.js per tiddler) */
.grokzett-status {
font-size: 0.85em; margin: 0.3em 0 1em; color: #555;
display: flex; align-items: center; gap: 6px;
}
.grokzett-status .gz-label { color: #888; letter-spacing: 0.02em; }
.grokzett-status button {
border: 1px solid #c9d6df; background: #f7f9fb; padding: 2px 10px;
font-size: 0.92em; cursor: pointer; border-radius: 12px; color: #333;
}
.grokzett-status button:hover { background: #e6edf3; }
.grokzett-status button.active { background: #2b6cb0; color: white; border-color: #2b6cb0; }
/* Fixed filter bar (top-right) */
.grokzett-filter-bar {
position: fixed; top: 10px; right: 10px; z-index: 10000;
background: #2d3748; color: #e2e8f0;
padding: 8px 14px; border-radius: 8px;
font-size: 0.85em; font-family: -apple-system, "Segoe UI", Roboto, sans-serif;
display: flex; align-items: center; gap: 12px;
box-shadow: 0 3px 12px rgba(0,0,0,0.25);
}
.grokzett-filter-bar .gz-title { font-weight: 600; letter-spacing: 0.02em; }
.grokzett-filter-bar select, .grokzett-filter-bar button {
background: #4a5568; color: #e2e8f0; border: 1px solid #718096;
border-radius: 4px; padding: 2px 8px; font: inherit;
}
.grokzett-filter-bar button { cursor: pointer; }
.grokzett-filter-bar button:hover { background: #5a6678; }
.grokzett-filter-bar label { display: flex; align-items: center; gap: 4px; }
.grokzett-filter-bar #gz-counts { opacity: 0.75; font-size: 0.95em; }
/* Subtle status badge on each tiddler (color bar at left) */
.tiddler[data-gz-status="learning"] { border-left: 3px solid #ed8936; padding-left: 8px; }
.tiddler[data-gz-status="known"] { border-left: 3px solid #48bb78; padding-left: 8px; opacity: 0.7; }
/* Cloze spans — trivia mode */
.gz-cloze {
background: #f6e05e; color: #f6e05e; border-radius: 3px; padding: 0 4px;
cursor: pointer; user-select: none; transition: color 0.15s;
}
.gz-cloze.revealed { color: #533f03; background: #fef6ad; }
/* Flashcard Q/A layout */
.gz-flash-a {
margin-top: 1em; padding: 0.8em 1em; background: #f7fafc;
border-radius: 6px; border: 1px solid #e2e8f0; position: relative;
}
.gz-flash-a.hidden > * { filter: blur(5px); user-select: none; }
.gz-flash-a.hidden { cursor: pointer; }
.gz-flash-a.hidden::after {
content: "click to reveal answer";
position: absolute; left: 0; right: 0; top: 50%; transform: translateY(-50%);
text-align: center; color: #718096; font-size: 0.9em; letter-spacing: 0.05em;
pointer-events: none;
}
.gz-flash-a:not(.hidden) { border-left: 4px solid #48bb78; }