---
tags:
- devops
- l1
- flashcard-deck
- ansible-ops
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Ansible](../../../../library/portal/topics.md) | **Domain:** DevOps & Tooling
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
ansible-ops/06e18cf872fc	ansible-ops	hard	ansible, scenario	Managing Multiple Environments	To manage multiple environments, I would use separate inventory files and group variables for each environment.\n\nExample directory structure:\n\n```\ninventories/\n  development/\n    hosts\n    group_vars/\n      all.yml\n  staging/\n    hosts\n    group_vars/\n      all.yml\n  production/\n    hosts\n    group_vars/\n      all.yml\nsite.yml\n```\n\nIn site.yml, specify the inventory file based on the environment:\n\n```\nansible-playbook -i inventories/development/hosts site.yml\nansible-playbook -i inventories/staging/hosts site.yml\nansible-playbook -i inventories/production/hosts site.yml\n```\n\nThis approach keeps environment-specific configurations separate and manageable.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/128-managing-multiple-environments-scenario-you-need-t.txt
ansible-ops/0affee97a99f	ansible-ops	medium	ansible, module, testing	What steps would you take to debug an issue with Ansible Container?	Debug by:\n* Reviewing Ansible Container logs.\n* Checking container runtime logs.\n* Inspecting container build outputs.\n* Using the --debug option for detailed debugging information.\n\nGotcha: Ansible Container was archived/deprecated in 2019. Modern container workflows use ansible-builder for Execution Environments or standard Dockerfiles.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/111-what-steps-would-you-take-to-debug-an-issue-with-a.txt
ansible-ops/12628f8a3ec7	ansible-ops	easy	ansible, playbooks	What is an Ansible playbook?	"A playbook is a YAML file containing one or more ""plays"", which map a set of tasks to a group of hosts. It defines what tasks to run on which hosts (and in what order) to automate configuration or deployment.\n\nRemember: playbook = 'the script', play = 'a scene', task = 'a line.' A playbook has plays, plays have tasks.\n\nExample: ansible-playbook site.yml runs the playbook. Add -C for check mode (dry run), -D for diff output."	projects/knowledge/interview/ansible/135-what-is-playbook.txt
ansible-ops/13b642d01c22	ansible-ops	hard	ansible, performance, scalability, automation	What's the most common non-obvious Ansible scalability killer?	Fact gathering - enabled by default, runs on every host, before any tasks.\n\nThe problem:\n- `gather_facts: true` is default\n- Collects extensive system info via setup module\n- Runs sequentially per fork\n- Takes 2-10 seconds PER HOST\n- 1000 hosts * 5 seconds = 83 minutes before first task\n\nOther scalability killers:\n\n1. SSH connection setup\n   - New connection per host per play\n   - SSH handshake overhead\n   - Mitigation: pipelining, ControlPersist\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/131-ansible-scalability-killer.txt
ansible-ops/19b95d66ae18	ansible-ops	easy	ansible, playbooks	"What are Ansible ""playbooks""?"	YAML scripts that declare the desired state of a system.\n\nExample: a playbook targeting [webservers] installs nginx, templates the config, and notifies a handler to restart — all in one YAML file.\n\nName origin: from sports — a 'playbook' is a collection of plays (strategies) to run in sequence.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/135-ansible-playbooks.txt
ansible-ops/287fd427b462	ansible-ops	easy	ansible, playbooks, commands	How do you run an Ansible playbook on a specific group of hosts?	"By using the -l (limit) flag or by specifying hosts in the playbook. For example: ansible-playbook site.yml -l webservers would run the playbook only on hosts in the ""webservers"" group.\n\nExample: ansible-playbook -i inventory.ini site.yml -l webservers --check --diff — runs in check mode on webservers only, showing what would change."	projects/knowledge/interview/ansible/139-run-playbook-on-group.txt
ansible-ops/29809b9fd389	ansible-ops	medium	ansible, strategy	What strategies are you familiar with in Ansible?	- Linear: the default strategy in Ansible. Run each task on all hosts before proceeding.\n  - Free: For each host, run all the tasks until the end of the play as soon as possible\n  - Debug: Run tasks in an interactive way\n\nRemember: Linear (default) = task-by-task across all hosts. Free = each host runs independently. Debug = interactive step-through. Set via strategy: free in the play.	projects/knowledge/interview/ansible/024-what-strategies-are-you-familiar-with-in-ansible.txt
ansible-ops/29b5a19f70ac	ansible-ops	medium	ansible, idempotency	How does Ansible ensure idempotence?	Ansible ensures idempotence by executing tasks only if the desired state is different from the current state. Tasks are designed to be repeatable without causing unintended changes, ensuring consistency in configurations.\n\nExample: 'Ensure nginx is installed' is idempotent — it checks first. 'Run apt install nginx' via shell is not — it runs every time.	projects/knowledge/interview/ansible/034-how-does-ansible-ensure-idempotence.txt
ansible-ops/33b59b8c2ef6	ansible-ops	easy	ansible, tasks	What is a task in Ansible?	A task is the smallest unit of action in a playbook, typically calling an Ansible module with specific arguments (e.g., a task to install a package or copy a file).\n\nRemember: task = one action on one or more hosts. A task calls a module (apt, copy, service) with parameters. Tasks execute in order within a play.\n\nExample: - name: Install nginx\n  apt: name=nginx state=present — this is one task calling the apt module.	projects/knowledge/interview/ansible/136-what-is-task.txt
ansible-ops/39065f9e1001	ansible-ops	hard	ansible, scenario	Migrating Legacy Scripts to Ansible	"To migrate legacy scripts to Ansible:\n\nIdentify Tasks: Break down the shell script into discrete tasks.\n\nUse Ansible Modules: Replace shell commands with equivalent Ansible modules.\n\nStructure Playbooks: Organize tasks into roles and playbooks for better management.\n\nExample migration:\n\nOriginal shell script:\n\n```\n#!/bin/bash\napt-get update\napt-get install -y nginx\necho ""Hello, World!"" > /var/www/html/index.html\n```\n\nMigrated Ansible playbook:\n\n\n```\n- hosts: web\n  tasks:\n    - name: Update apt cache\n      apt:\n        update_cache: yes\n\n    - name: Install Nginx\n      apt:\n        name: nginx\n        state: present\n\n    - name: Create index.html\n      copy:\n        content: ""Hello, World!""\n        dest: /var/www/html/index.html\n```\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team."	projects/knowledge/interview/ansible/127-migrating-legacy-scripts-to-ansible-scenario-you-h.txt
ansible-ops/4575e150af71	ansible-ops	medium	ansible, strategy	What the serial keyword is used for?	It's used to specify the number (or percentage) of hosts to run the full play on, before moving to next number of hosts in the group.\n\nFor example:\n```\n- name: Some play\n  hosts: databases\n  serial: 4\n```\n\nIf your group has 8 hosts. It will run the whole play on 4 hosts and then the same play on another 4 hosts.\n\nExample: serial: '25%' updates a quarter of your fleet at a time. Combine with max_fail_percentage: 10 to abort if too many hosts fail.	projects/knowledge/interview/ansible/025-what-the-serial-keyword-is-used-for.txt
ansible-ops/4f43142972f9	ansible-ops	medium	ansible, security	How do you manage secrets in Ansible?	Never inline plaintext secrets. Options:\n\n**Ansible Vault**:\n```bash\nansible-vault create secrets.yml\nansible-vault edit secrets.yml\nansible-playbook --ask-vault-pass playbook.yml\n```\nGood for: Smaller teams, simple needs.\n\n**External secret managers**:\n* HashiCorp Vault (`hashi_vault` lookup)\n* AWS Secrets Manager\n* Azure Key Vault\n* CyberArk, etc.\n\nGood for: Enterprise, dynamic secrets, audit requirements.\n\n**Best practices**:\n* Separate vault files per environment\n* Use vault IDs for multiple passwords\n* CI/CD: vault password from secure variable, never committed\n* Rotate secrets regularly\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/131-how-do-you-manage-secrets-in-ansible.txt
ansible-ops/4fdfa0ddc2b5	ansible-ops	medium	ansible, strategy	True or False? By default, Ansible will execute all the tasks in play on a single host before proceeding to the next host	"False. Ansible will execute a single task on all hosts before moving to the next task in a play. As for today, it uses 5 forks by default. \nThis behavior is described as ""strategy"" in Ansible and it's configurable.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team."	projects/knowledge/interview/ansible/022-true-or-false-by-default-ansible-will-execute-all-.txt
ansible-ops/6a12c4c203e5	ansible-ops	easy	ansible, security	"What is ""Ansible Vault""?"	A tool for encrypting sensitive data like passwords within playbooks.\n\nExample: ansible-vault encrypt secrets.yml encrypts in place. Use --ask-vault-pass at runtime.\n\nUnder the hood: uses AES-256 symmetric encryption. The password never goes in the repo.\n\nRemember: Vault = AES-256 encryption for secrets in YAML. Never commit vault passwords — use --vault-password-file pointing to a CI/CD secret.	projects/knowledge/interview/ansible/140-ansible-vault.txt
ansible-ops/6caeda115b5a	ansible-ops	easy	ansible, strategy	"What is a ""strategy"" in Ansible? What is the default strategy?"	"A strategy in Ansible describes how Ansible will execute the different tasks on the hosts. By default Ansible is using the ""Linear strategy"" which defines that each task will run on all hosts before proceeding to the next task.\n\nRemember: Linear = 'task-at-a-time across all hosts.' Free = 'all tasks on each host as fast as possible.' Debug = 'step-by-step interactive.'"	projects/knowledge/interview/ansible/023-what-is-a-strategy-in-ansible-what-is-the-default-.txt
ansible-ops/7f1dc378176e	ansible-ops	medium	ansible, module, idempotency, testing	Why is shell in Ansible dangerous?	The `shell` and `command` modules should be last resort:\n\n**Breaks idempotence**: Shell commands run every time unless you add complex `creates`/`removes` or `when` conditions.\n\n**Hides failures**: Exit codes aren't always meaningful. Silent failures corrupt state.\n\n**Non-portable**: Shell commands vary across distros, versions, shells.\n\n**Hard to test**: No structured output to validate.\n\n**Example - bad**:\n```yaml\n- shell: useradd myuser\n```\n\n**Example - good**:\n```yaml\n- user:\n    name: myuser\n    state: present\n```\n\nThe module handles idempotence, cross-platform differences, and returns structured results.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/130-why-is-shell-in-ansible-dangerous.txt
ansible-ops/8973884e1f4a	ansible-ops	hard	ansible, scenario	Configuring Ansible for Network Automation	"For network automation, I would use Ansible network modules and collections like ansible.netcommon and vendor-specific collections.\n\nExample playbook for Cisco devices:\n\n```\n- hosts: cisco_routers\n  gather_facts: no\n  tasks:\n    - name: Configure interface\n      cisco.ios.ios_interface:\n        name: GigabitEthernet1\n        description: ""Configured by Ansible""\n        enabled: yes\n```\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team."	projects/knowledge/interview/ansible/125-configuring-ansible-for-network-automation-scenari.txt
ansible-ops/8bc95fc0c8df	ansible-ops	hard	ansible, scenario	Error Handling in Playbooks	"To handle errors:\n\nIgnore Errors: Use ignore_errors: yes for non-critical tasks.\n\n```\n- name: Task that might fail\n  command: /bin/false\n  ignore_errors: yes\n```\n\nRetries: Use retries and delay for tasks that might fail intermittently.\n\n```\n- name: Retry task\n  command: /path/to/command\n  retries: 5\n  delay: 10\n  until: result.rc == 0\n  register: result\n```\n\nRescue and Always: Use block, rescue, and always for structured error handling.\n\n```\n- name: Structured error handling\n  block:\n    - name: Task that might fail\n      command: /bin/false\n  rescue:\n    - name: Handle failure\n      debug:\n        msg: ""Task failed""\n  always:\n    - name: Always run\n      debug:\n        msg: ""This always runs""\n```"	projects/knowledge/interview/ansible/124-error-handling-in-playbooks-scenario-some-tasks-in.txt
ansible-ops/8fb502a4d3cb	ansible-ops	hard	ansible, scenario	Optimizing Playbook Performance	To optimize playbook performance:\n\nParallelism: Increase the number of forks to run tasks in parallel.\n\n```\nansible-playbook -i inventory playbook.yml -f 10\n```\n\nDelegate Tasks: Delegate tasks to appropriate hosts to distribute the load.\n\n```\n- name: Fetch something\n  delegate_to: localhost\n```\n\nLimit Scope: Use --limit to target specific hosts.\n\n```\nansible-playbook -i inventory playbook.yml --limit web_servers\n```\n\nAsynchronous Tasks: Use asynchronous tasks for long-running operations.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/122-optimizing-playbook-performance-scenario-your-play.txt
ansible-ops/92314c1dae26	ansible-ops	easy	ansible, playbooks	"What are Ansible ""tags""?"	Labels used to selectively run or skip specific tasks.\n\nExample: ansible-playbook site.yml --tags=deploy runs only deploy-tagged tasks.\n\nGotcha: untagged tasks run by default. Use the special 'always' tag for must-run tasks.\n\nRemember: tags = surgical targeting. --tags=deploy runs only deploy tasks. --skip-tags=setup skips setup tasks. Great for partial runs.	projects/knowledge/interview/ansible/142-ansible-tags.txt
ansible-ops/a35354fd2a90	ansible-ops	hard	ansible, scenario	Handling Dependencies	To integrate Ansible with a CI/CD pipeline, I would use tools like Jenkins, GitLab CI, or GitHub Actions. The CI/CD pipeline would trigger Ansible playbooks to deploy or update infrastructure.\n\nExample using GitLab CI:\n\n```\nstages:\n  - deploy\n\ndeploy:\n  stage: deploy\n  script:\n    - ansible-playbook -i inventory playbook.yml\n```\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/123-handling-dependencies-scenario-your-playbook-depen.txt
ansible-ops/a6a565e58e49	ansible-ops	medium	ansible, inventory, testing	How can you test and validate a dynamic inventory script?	Test the script by running it manually and examining output. Validate by checking if it produces JSON-formatted data with required host information.\n\nExample: ./inventory.py --list | python -m json.tool validates JSON output. Compare against ansible-inventory -i inventory.py --graph to see how Ansible interprets the groups.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/099-how-can-you-test-and-validate-a-dynamic-inventory-.txt
ansible-ops/ac52b3b4ca23	ansible-ops	hard	ansible, scenario	Rolling Updates with Zero Downtime	To implement a rolling update with zero downtime, I would use a combination of Ansible playbooks and a load balancer. The process involves updating a subset of servers at a time while ensuring the load balancer only directs traffic to healthy nodes. Here’s a high-level approach:\n\nDrain Traffic: Use Ansible to interact with the load balancer API to drain traffic from the first subset of servers.\n\nUpdate Servers: Apply the updates to the drained servers.\n\nHealth Check: Ensure the updated servers pass health checks.	projects/knowledge/interview/ansible/116-rolling-updates-with-zero-downtime-scenario-you-ar.txt
ansible-ops/b2db3129b00b	ansible-ops	easy	ansible, enterprise	"What is ""Ansible Tower"" or ""AWX""?"	A web-based interface for managing Ansible at scale.\n\nFun fact: AWX is the open-source upstream; Tower (now Ansible Automation Platform) is the Red Hat commercial build.\n\nUnder the hood: adds RBAC, job scheduling, credential vaults, REST API, and audit trail for team-scale Ansible.\n\nRemember: AWX = free upstream, Tower = paid Red Hat product (now 'Ansible Automation Platform'). Both add web UI, RBAC, scheduling, and REST API.	projects/knowledge/interview/ansible/144-ansible-tower.txt
ansible-ops/b65eb5a8be4a	ansible-ops	medium	ansible, playbooks	"What is an Ansible ""handler""?"	A task triggered by another task that only runs if notified.\n\nExample: a handler 'restart nginx' triggers via notify on config change. Runs once at end of play, even if notified multiple times.\n\nGotcha: handlers execute in definition order, not notification order. Use meta: flush_handlers for immediate execution.\n\nRemember: handler = 'only run if something changed.' A notify on config file change triggers a restart handler. Runs once at end of play.	projects/knowledge/interview/ansible/141-ansible-handler.txt
ansible-ops/bb7c7dbe2944	ansible-ops	medium	ansible, inventory, tower	How do you create and manage inventories in Ansible Tower?	Inventories in Ansible Tower can be managed through the web interface. You can create and organize inventories, define variables, and configure sources such as static files, dynamic scripts, or cloud providers. Tower also supports syncing with external inventory systems.\n\nRemember: AWX = free upstream, Tower = paid Red Hat product (now 'Ansible Automation Platform'). Both add web UI, RBAC, scheduling, and REST API.	projects/knowledge/interview/ansible/068-how-do-you-create-and-manage-inventories-in-ansibl.txt
ansible-ops/bef55c07e4ef	ansible-ops	medium	ansible, module, testing	Explain how to use the --debug option with Ansible Container commands.	Append --debug to Ansible Container commands for increased verbosity. Example:\n```bash\nansible-container build --debug\n```\n\nGotcha: Ansible Container has been archived/deprecated since 2019. For modern container builds, use ansible-builder or standard Dockerfile workflows instead.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/112-explain-how-to-use-the-debug-option-with-ansible-c.txt
ansible-ops/c2343e9c46ee	ansible-ops	easy	ansible, configuration-management, automation	What's your experience with Ansible?	I've used Ansible heavily for server provisioning, patching, switch configuration, and enforcing consistency across large server fleets. I write clean, modular roles, use inventories effectively, and rely on Jinja2 templating for dynamic configs. I've automated PXE/bootstrap workflows and built idempotent playbooks for both servers and network gear.\n\nRemember: in interviews, structure your experience answer as: scope (how many servers/services), tools used, key challenges solved, and measurable impact (time saved, incidents reduced).	projects/knowledge/interview/ansible/129-whats-your-experience-with-ansible.txt
ansible-ops/c28e8bd887d6	ansible-ops	hard	ansible, scenario	Multi-Tier Application Deployment	To handle a multi-tier application deployment efficiently, I would use a modular approach with Ansible roles. Each tier (web server, application server, database server) would have its own role. The directory structure might look like this:\n\n```sh\nsite.yml\nroles/\n  web/\n    tasks/\n      main.yml\n    templates/\n      web.conf.j2\n  app/\n    tasks/\n      main.yml\n    templates/\n      app.conf.j2\n  db/\n    tasks/\n      main.yml\n    templates/\n      db.conf.j2\ninventory/\n  production/\n    hosts\n    group_vars/\n\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/115-multi-tier-application-deployment-scenario-you-nee.txt
ansible-ops/c5ac28589767	ansible-ops	medium	ansible, tower	Explain how to view job output and logs in Ansible Tower.	View job output in the Ansible Tower UI under the specific job details. Logs can be accessed through the UI or retrieved using the Tower API. Additionally, logs are stored in the Tower log directory on the Tower server.\n\nRemember: AWX = free upstream, Tower = paid Red Hat product (now 'Ansible Automation Platform'). Both add web UI, RBAC, scheduling, and REST API.	projects/knowledge/interview/ansible/108-explain-how-to-view-job-output-and-logs-in-ansible.txt
ansible-ops/c9aba3638120	ansible-ops	hard	ansible, scenario	Handling Configuration Drift	To ensure servers remain in the desired state, I would implement regular configuration enforcement using Ansible Tower/AWX or a cron job that runs playbooks periodically. Additionally, I would use Ansible’s check mode to detect drift without making changes.\n\nExample cron job:\n\n```\n0 2 * * * ansible-playbook -i inventory playbook.yml\n```\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/121-handling-configuration-drift-scenario-over-time-th.txt
ansible-ops/da5b3dd00e98	ansible-ops	hard	ansible, scenario	Ansible Dynamic Inventory	To manage a dynamic infrastructure, I would use Ansible’s dynamic inventory feature. This can be achieved by using inventory scripts or plugins that query external data sources such as cloud provider APIs (e.g., AWS, Azure).\n\nExample using AWS EC2 dynamic inventory:\n\nInstall the AWS Inventory Plugin:\n\n```\npip install boto boto3\n```\n\nConfigure the AWS Inventory Plugin:\n\n```\nplugin: aws_ec2\nregions:\n  - us-east-1\nfilters:\n  tag:Environment: production\n\n```\n\nUse the Dynamic Inventory in Playbooks:\n\n```\nansible-playbook -i aws_ec2.yml playbook.yml\n\n```\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/120-ansible-dynamic-inventory-scenario-you-need-to-man.txt
ansible-ops/e5da86d76655	ansible-ops	medium	ansible, vault	Explain the process of editing an encrypted file with Ansible Vault.	Use the ansible-vault edit command to edit an encrypted file. \nExample:\n```bash\nansible-vault edit secret_file.yml\n```\nAnsible will prompt for the Vault password before allowing access.\n\nUnder the hood: ansible-vault edit decrypts to a temp file, opens your $EDITOR, then re-encrypts on save. The plaintext never touches disk persistently.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/060-explain-the-process-of-editing-an-encrypted-file-w.txt
ansible-ops/eee4c27ebfee	ansible-ops	medium	idempotency, best-practices, state	What does idempotency mean in Ansible and why is it important?	"Idempotency means running the same operation multiple times produces the same\nresult as running it once. In Ansible, a task is idempotent if running it\nrepeatedly doesn't change the system after the first application.\n\nWhy it matters:\n- Safe to re-run playbooks (won't break things)\n- Enables ""desired state"" configuration\n- Allows for drift detection and correction\n- Makes automation predictable and reliable\n\nGood (idempotent):\n```yaml\n- name: Ensure nginx is installed\n  apt:\n    name: nginx\n    state: present\n\nExample: 'Ensure nginx is installed' is idempotent — it checks first. 'Run apt install nginx' via shell is not — it runs every time."	projects/knowledge/interview/ansible/165-idempotency.txt
ansible-ops/ef0f7773b7c3	ansible-ops	hard	ansible, scenario	Troubleshooting Playbook Failures	To troubleshoot a failing playbook:\n\nCheck Recent Changes: Review recent changes in the playbook, roles, or inventory files.\n\nVerbose Output: Run the playbook with increased verbosity (-vvv) to get detailed output and identify where it fails.\n\nEnvironment Consistency: Ensure the environment where the playbook is run hasn’t changed (e.g., different Ansible version, OS updates, or network configurations).\n\nIsolate the Issue: Isolate the failing task by running it independently or within a minimal playbook.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/119-troubleshooting-playbook-failures-scenario-your-pl.txt
ansible-ops/f45679752575	ansible-ops	medium	ansible, serial, execution	How do you limit Ansible to run on one host at a time (serial execution)?	In a playbook, use the serial keyword (e.g., serial: 1 in a play limits Ansible to configure one host at a time from the inventory).\n\nGotcha: serial: 1 is essential for rolling updates — it ensures one host is fully configured and healthy before moving to the next, preventing fleet-wide outages from a bad config.\n\nExample: serial: '25%' updates a quarter of your fleet at a time. Combine with max_fail_percentage: 10 to abort if too many hosts fail.	projects/knowledge/interview/ansible/143-serial-execution.txt
ansible-ops/f9294bca8875	ansible-ops	easy	ansible, architecture	"What is the ""Control Node""?"	The machine where Ansible is installed and commands are run.\n\nGotcha: must run Linux or macOS — Windows is not supported as control node (use WSL2). Windows works only as a managed node via WinRM.\n\nUnder the hood: reads playbooks, resolves inventory, opens SSH connections, aggregates results.\n\nRemember: control node = 'command center.' Must be Linux/macOS. Windows support is managed-node only (via WinRM).	projects/knowledge/interview/ansible/146-control-node.txt
ansible-ops/fd173fc0fbde	ansible-ops	medium	ansible, vault	How do you create an encrypted file using Ansible Vault?	Use the ansible-vault create command to create an encrypted file. \nExample:\n```bash\nansible-vault create secret_file.yml\n```\n\nUnder the hood: ansible-vault create opens $EDITOR for a new file and encrypts it on save using AES-256. The encrypted file can be committed to git safely.\n\nRemember: Ansible operations best practice — always use version control for playbooks, test in staging before production, and document your inventory structure for the team.	projects/knowledge/interview/ansible/059-how-do-you-create-an-encrypted-file-using-ansible-.txt
ansible-ops/8a37e8976ce3	ansible-ops	medium	miscellaneous, ansible, containers, control-flow	Explain the role of orchestration in automating complex tasks across servers and networking devices.	• Task Sequencing: Orchestration involves the coordination and sequencing of multiple tasks across servers and networking devices to achieve a specific objective. • Workflow Automation: Orchestration tools automate workflows by defining the order and dependencies of tasks, ensuring that each step is executed in the correct sequence. • Cross-Platform Integration: Orchestration facilitates the integration of tasks across diverse platforms, allowing for the automation of complex processes involving servers, networking devices, and external services.\n\nRemember: orchestration = coordinating tasks across multiple systems in a defined order. Ansible handles orchestration through plays (host targeting), serial (rolling), and delegation (task routing).	
ansible-ops/c944df4f2363	ansible-ops	medium	miscellaneous, ansible, control-flow, networking	Have you used automation tools like PowerShell or Ansible for server management tasks?	Automation tools such as PowerShell and Ansible streamline server management tasks: • **PowerShell:* •  • Windows Environment: PowerShell is a scripting language and automation framework designed for Windows environments. • Task Automation: It allows the automation of various tasks, including server configuration, software deployment, and system administration. • Scripting Capabilities: PowerShell scripts can be written to execute commands and tasks, making it efficient for managing Windows servers.\n\nRemember: PowerShell is Windows-centric (though cross-platform via pwsh). Ansible is Linux-first but supports Windows via WinRM. Choose based on your fleet's OS mix.	

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Ansible Automation](../../../../library/topics/ansible/index.md) (Topic Pack, L1) — Ansible
- Ansible Core Flashcards *(CLI)* (flashcard_deck, L1) — Ansible
- [Ansible Deep Dive](../../../../library/topics/ansible-deep-dive/index.md) (Topic Pack, L2) — Ansible
- [Ansible Drills](../../../../library/drills/ansible_drills.md) (Drill, L1) — Ansible
- Ansible Exercises (Quest Ladder) *(CLI)* (Exercise Set, L1) — Ansible
- Ansible Lab: Conditionals and Loops *(CLI)* (Lab, L1) — Ansible
- Ansible Lab: Facts and Variables *(CLI)* (Lab, L0) — Ansible
- Ansible Lab: Install Nginx (Idempotency) *(CLI)* (Lab, L1) — Ansible
- Ansible Lab: Ping and Debug *(CLI)* (Lab, L0) — Ansible
- Ansible Lab: Roles *(CLI)* (Lab, L1) — Ansible

<!-- wiki:related:end -->
