---
tags:
- devops
- l1
- flashcard-deck
- rhce
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [RHCE (EX294) Exam](../../../../library/portal/topics.md) | **Domain:** DevOps & Tooling
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
rhce/001-ansible-cfg-precedence	rhce	medium	rhce, ansible, configuration	What is the precedence order for ansible.cfg files (highest to lowest)?	1. ANSIBLE_CONFIG environment variable\n2. ./ansible.cfg (current directory)\n3. ~/.ansible.cfg (home directory)\n4. /etc/ansible/ansible.cfg (system-wide)\n\nRemember: "RHCE = Red Hat Certified Engineer." It builds on RHCSA with advanced system administration, automation, and Ansible.\n\nFun fact: RHCE is a performance-based exam — no multiple choice, you must actually configure systems.	training/library/topics/rhce/primer.md
rhce/002-control-node-install	rhce	easy	rhce, ansible, installation	How do you install Ansible on a RHEL 9 control node?	sudo dnf install ansible-core\nVerify with: ansible --version\n\nExample: systemctl enable --now httpd starts httpd immediately AND sets it to start on boot.\n\nRemember: "enable = boot, start = now, enable --now = both."	training/library/topics/rhce/primer.md
rhce/003-managed-node-reqs	rhce	easy	rhce, ansible, managed-nodes	What are the requirements for an Ansible managed node?	1. Python 3 installed\n2. SSH access from the control node\n3. A user with sudo privileges (for become)\n4. SSH key-based authentication (recommended)\n\nExample: nmcli con mod eth0 ipv4.addresses 192.168.1.10/24 ipv4.gateway 192.168.1.1 ipv4.method manual && nmcli con up eth0\n\nRemember: "nmcli = NetworkManager CLI. con mod = modify, con up = activate."	training/library/topics/rhce/primer.md
rhce/004-inventory-ini-format	rhce	easy	rhce, ansible, inventory	How do you define host groups and nested groups in an INI inventory?	[webservers]\nweb1.example.com\nweb2.example.com\n\n[dbservers]\ndb1.example.com\n\n[datacenter:children]\nwebservers\ndbservers\n\nRemember: "firewalld uses zones." Default zone is public. Common commands: firewall-cmd --add-service=http --permanent && firewall-cmd --reload.\n\nExample: firewall-cmd --list-all shows current zone rules.	training/library/topics/rhce/primer.md
rhce/005-inventory-yaml-format	rhce	medium	rhce, ansible, inventory	How do you define a YAML-format inventory with groups and variables?	all:\n  children:\n    webservers:\n      hosts:\n        web1.example.com:\n        web2.example.com:\n      vars:\n        http_port: 80\n    dbservers:\n      hosts:\n        db1.example.com:\n\nExample: timedatectl set-timezone America/New_York && chronyc tracking shows sync status.\n\nRemember: "chrony replaced ntpd in RHEL 7+." It syncs faster and handles intermittent connectivity better.	training/library/topics/rhce/primer.md
rhce/006-ad-hoc-commands	rhce	easy	rhce, ansible, ad-hoc	What is the syntax for running an Ansible ad hoc command?	ansible <host-pattern> -m <module> -a "<arguments>"\nExample: ansible all -m ping\nExample: ansible webservers -m dnf -a "name=httpd state=present" --become\n\nRemember: "RHEL 8+ uses dnf (replaces yum)." Key commands: dnf install, dnf update, dnf module list.\n\nExample: dnf module enable php:8.1 && dnf install php selects the PHP 8.1 stream.	training/library/topics/rhce/primer.md
rhce/007-fqcn	rhce	medium	rhce, ansible, collections, fqcn	What is FQCN and why should you always use it in playbooks?	FQCN = Fully Qualified Collection Name. Format: namespace.collection.module (e.g., ansible.builtin.copy, ansible.posix.firewalld). Required to avoid ambiguity when multiple collections provide modules with the same name. Always use FQCN on the exam.\n\nGotcha: The RHCE exam is time-limited — practice speed. Know how to use man pages quickly (man -k keyword).\n\nRemember: "man -k = apropos = search manual page descriptions."	training/library/topics/rhce/primer.md
rhce/008-playbook-structure	rhce	easy	rhce, ansible, playbook	What are the key components of an Ansible playbook?	A playbook is a YAML file containing one or more plays. Each play has:\n- name: description\n- hosts: target pattern\n- become: privilege escalation\n- vars/vars_files: variables\n- tasks: ordered list of module calls\n- handlers: triggered by notify	training/library/topics/rhce/primer.md
rhce/009-handlers	rhce	medium	rhce, ansible, handlers	When do Ansible handlers run, and how do you trigger them?	Handlers run at the end of a play, only when notified by a task that reported "changed". Trigger with:\n  notify: Handler Name\nFlush mid-play with:\n  ansible.builtin.meta: flush_handlers\nHandlers run only once even if notified multiple times.	training/library/topics/rhce/primer.md
rhce/010-tags	rhce	medium	rhce, ansible, tags	How do you use tags to selectively run tasks in a playbook?	Add tags to tasks:\n  tags: [install, packages]\nRun tagged tasks: ansible-playbook site.yml --tags "install"\nSkip tagged tasks: ansible-playbook site.yml --skip-tags "configure"\nSpecial tags: 'always' (always runs), 'never' (skipped unless explicitly tagged)	training/library/topics/rhce/primer.md
rhce/011-when-conditional	rhce	medium	rhce, ansible, conditionals	How do you use the 'when' conditional in Ansible tasks?	when: ansible_facts['os_family'] == "RedHat"\nMultiple conditions (AND): list items under when:\nwhen:\n  - condition1\n  - condition2\nOR condition: when: "'web' in group_names or 'proxy' in group_names"\nCheck defined: when: my_var is defined	training/library/topics/rhce/primer.md
rhce/012-loops	rhce	medium	rhce, ansible, loops	How do you iterate over items in Ansible using loops?	Simple loop:\nloop:\n  - httpd\n  - php\nDict loop:\nloop:\n  - { name: alice, group: devs }\n  - { name: bob, group: admins }\nAccess with {{ item }} or {{ item.name }}\nFor packages, prefer passing a list directly to the name parameter instead of looping.	training/library/topics/rhce/primer.md
rhce/013-loop-control	rhce	medium	rhce, ansible, loops	What does loop_control provide in Ansible?	loop_control options:\n- label: "{{ item.name }}" — cleaner output (hides full dict)\n- index_var: idx — exposes loop index\n- pause: 3 — seconds between iterations\n- extended: true — adds ansible_loop.* vars (first, last, length, etc.)	training/library/topics/rhce/primer.md
rhce/014-error-handling-block	rhce	hard	rhce, ansible, error-handling	How do you implement try/catch/finally error handling in Ansible?	Use block/rescue/always:\nblock:\n  - name: Risky task\n    ...\nrescue:\n  - name: Runs if block fails\n    ...\nalways:\n  - name: Always runs\n    ...\nAlso available: ignore_errors: true, failed_when, changed_when\n\nRemember: "LVM layers: PV → VG → LV." Physical Volume → Volume Group → Logical Volume.\n\nExample: pvcreate /dev/sdb && vgcreate myvg /dev/sdb && lvcreate -L 10G -n mylv myvg	training/library/topics/rhce/primer.md
rhce/015-ansible-vault-create	rhce	easy	rhce, ansible, vault	How do you create and use an Ansible Vault encrypted file?	Create: ansible-vault create secrets.yml\nEncrypt existing: ansible-vault encrypt vars/passwords.yml\nEdit: ansible-vault edit secrets.yml\nView: ansible-vault view secrets.yml\nUse at runtime: ansible-playbook site.yml --ask-vault-pass\nOr: ansible-playbook site.yml --vault-password-file .vault_pass	training/library/topics/rhce/primer.md
rhce/016-vault-encrypt-string	rhce	medium	rhce, ansible, vault	How do you encrypt a single variable value with Ansible Vault?	ansible-vault encrypt_string 'SuperSecret123' --name 'db_password'\nOutput is a !vault tagged YAML value you paste into your vars file.\nThe rest of the vars file remains readable — only that value is encrypted.	training/library/topics/rhce/primer.md
rhce/017-variable-precedence	rhce	hard	rhce, ansible, variables	What is Ansible's variable precedence from lowest to highest?	Lowest to highest:\n1. Role defaults\n2. Inventory group_vars/all\n3. Inventory group_vars/<group>\n4. Inventory host_vars/<host>\n5. Play vars_files\n6. Play vars\n7. Task vars\n8. set_fact / registered vars\n9. Role vars\n10. Extra vars (-e) — ALWAYS WIN\n\nRemember: "tuned = performance profiles." tuned-adm profile throughput-performance for maximum throughput.\n\nExample: tuned-adm list shows available profiles; tuned-adm active shows the current one.	training/library/topics/rhce/primer.md
rhce/018-registered-variables	rhce	medium	rhce, ansible, variables	How do you capture and use the output of a task in Ansible?	Use register:\n- ansible.builtin.command: cat /etc/hostname\n  register: hostname_output\n  changed_when: false\n\n- ansible.builtin.debug:\n    var: hostname_output.stdout\n\nCommon attributes: .stdout, .stderr, .rc, .changed, .failed, .stat.exists\n\nRemember: "at = one-time, cron = recurring." at runs a command once at a specified time.\n\nExample: echo "reboot" | at 02:00 schedules a reboot at 2 AM.	training/library/topics/rhce/primer.md
rhce/019-magic-variables	rhce	medium	rhce, ansible, variables	What are Ansible's key magic variables?	hostvars — all variables for all hosts\ngroups — dict of all groups and their hosts\ngroup_names — groups the current host belongs to\ninventory_hostname — current host's name from inventory\nansible_play_hosts — active hosts in current play\nansible_check_mode — true if in check mode	training/library/topics/rhce/primer.md
rhce/020-facts	rhce	easy	rhce, ansible, facts	How do you access Ansible facts and what do they contain?	Facts are gathered automatically via the setup module.\nAccess: ansible_facts['distribution'], ansible_default_ipv4.address\nGather manually: ansible host -m setup\nFilter: ansible host -m setup -a "filter=ansible_distribution*"\nDisable: gather_facts: false in the play\nCustom facts: place .fact files in /etc/ansible/facts.d/ → ansible_local.*	training/library/topics/rhce/primer.md
rhce/021-jinja2-template-basics	rhce	medium	rhce, ansible, jinja2, templates	What are the key Jinja2 syntax elements used in Ansible templates?	{{ variable }} — variable substitution\n{% if condition %} ... {% endif %} — conditional\n{% for item in list %} ... {% endfor %} — loop\n{# comment #} — comment\n{{ var | default('fallback') }} — filter\n{{ var | upper }} — string filter\n{{ list | join(', ') }} — join filter	training/library/topics/rhce/primer.md
rhce/022-template-task	rhce	easy	rhce, ansible, templates	How do you deploy a Jinja2 template with Ansible?	- ansible.builtin.template:\n    src: templates/httpd.conf.j2\n    dest: /etc/httpd/conf/httpd.conf\n    owner: root\n    group: root\n    mode: '0644'\n    validate: httpd -t -f %s\n  notify: Restart httpd\n\nExample: ansible-playbook site.yml --limit webservers runs only against the webservers group.\n\nRemember: "Ansible is agentless — it uses SSH. No daemon needed on managed hosts."	training/library/topics/rhce/primer.md
rhce/023-role-structure	rhce	medium	rhce, ansible, roles	What is the directory structure of an Ansible role?	roles/rolename/\n  defaults/main.yml — default variables (lowest precedence)\n  vars/main.yml — role variables (high precedence)\n  tasks/main.yml — main task list\n  handlers/main.yml — handler definitions\n  templates/ — Jinja2 templates\n  files/ — static files\n  meta/main.yml — metadata and dependencies	training/library/topics/rhce/primer.md
rhce/024-role-creation	rhce	easy	rhce, ansible, roles, galaxy	How do you scaffold a new Ansible role?	ansible-galaxy role init <rolename>\nThis creates the full directory structure under roles/<rolename>/ with defaults/, tasks/, handlers/, templates/, files/, vars/, meta/ directories and main.yml files.\n\nRemember: "journalctl -xe = recent errors with explanation." -u filters by unit, -f follows live, --since/--until filter by time.\n\nExample: journalctl -u nginx --since "1 hour ago" shows recent nginx logs.	training/library/topics/rhce/primer.md
rhce/025-galaxy-requirements	rhce	medium	rhce, ansible, galaxy, collections	How do you install roles and collections from a requirements file?	Create requirements.yml:\nroles:\n  - name: geerlingguy.apache\n    version: "3.2.0"\ncollections:\n  - name: ansible.posix\n  - name: community.general\n\nInstall: ansible-galaxy install -r requirements.yml\nCollections: ansible-galaxy collection install -r requirements.yml	training/library/topics/rhce/primer.md
rhce/026-parallelism-forks	rhce	medium	rhce, ansible, parallelism	How do you control parallelism in Ansible?	forks (ansible.cfg): number of parallel host connections (default 5)\nserial: run on N hosts at a time (rolling updates)\n  serial: 2 or serial: "25%"\n  Stepped: serial: [1, 5, "100%"]\nasync/poll: fire-and-forget long tasks\n  async: 3600, poll: 0\nthrottle: limit concurrent task execution\n  throttle: 2	training/library/topics/rhce/primer.md
rhce/027-ansible-doc	rhce	easy	rhce, ansible, documentation	How do you use ansible-doc to find module documentation?	ansible-doc ansible.builtin.dnf — full module docs\nansible-doc -s ansible.builtin.user — short/snippet form\nansible-doc -l — list all modules\nansible-doc -l | grep firewall — search modules\nansible-doc -t callback -l — list plugins by type\nCritical on exam: no internet access, ansible-doc is your only reference.	training/library/topics/rhce/primer.md
rhce/028-collections-key	rhce	medium	rhce, ansible, collections	What are the key Ansible collections needed for the RHCE exam?	ansible.builtin — core modules (dnf, copy, service, template, file, user, group, command, shell, debug, etc.)\nansible.posix — SELinux, firewalld, mount, authorized_key, cron, sysctl\ncommunity.general — nmcli, parted, lvg, lvol, filesystem, sefcontext, seport, timezone	training/library/topics/rhce/primer.md
rhce/029-dnf-module	rhce	easy	rhce, ansible, packages	How do you manage packages with the ansible.builtin.dnf module?	Install: state: present\nRemove: state: absent\nUpdate: state: latest\nSpecific version: name: httpd-2.4.51\nPackage group: name: "@Development Tools"\nModule stream: name: "@postgresql:15/server"\nMultiple: pass a list to name:\n\nRemember: "autofs = automount on access, unmount on idle." It reduces NFS load by only mounting when directories are accessed.\n\nExample: /etc/auto.master defines mount points; /etc/auto.misc defines the actual mounts.	training/library/topics/rhce/primer.md
rhce/030-service-module	rhce	easy	rhce, ansible, services	How do you manage services with Ansible?	ansible.builtin.service:\n  name: httpd\n  state: started/stopped/restarted/reloaded\n  enabled: true/false\nCommon pattern: state: started + enabled: true to ensure service is running and persists across reboots.	training/library/topics/rhce/primer.md
rhce/031-user-module	rhce	medium	rhce, ansible, users	How do you create users with the ansible.builtin.user module?	ansible.builtin.user:\n  name: jdoe\n  uid: 2001\n  group: developers\n  groups: wheel\n  append: true\n  shell: /bin/bash\n  password: "{{ 'P@ss' | password_hash('sha512') }}"\n  state: present\nRemove with state: absent, remove: true	training/library/topics/rhce/primer.md
rhce/032-firewalld-module	rhce	medium	rhce, ansible, firewall	How do you manage firewall rules with Ansible?	ansible.posix.firewalld:\n  service: http (or port: 8080/tcp)\n  permanent: true\n  immediate: true\n  state: enabled\nAlways set BOTH permanent (survives reboot) and immediate (applies now). Forgetting permanent means rules vanish on reboot.	training/library/topics/rhce/primer.md
rhce/033-selinux-modules	rhce	hard	rhce, ansible, selinux	What Ansible modules are used for SELinux management?	ansible.posix.selinux — set enforcing/permissive/disabled\nansible.posix.seboolean — set SELinux booleans (e.g., httpd_can_network_connect)\ncommunity.general.sefcontext — set file context rules\ncommunity.general.seport — set port labels\nAfter sefcontext, always run restorecon to apply to existing files.	training/library/topics/rhce/primer.md
rhce/034-lineinfile-vs-blockinfile	rhce	medium	rhce, ansible, files	What is the difference between lineinfile and blockinfile?	lineinfile: manages a single line (uses regexp to find and replace)\n  Great for: changing one setting in a config file\nblockinfile: manages a multi-line block between markers\n  Uses: marker: "# {mark} ANSIBLE MANAGED BLOCK"\n  Great for: adding a block of config (e.g., hosts entries)\nBoth support backup: true for safety.	training/library/topics/rhce/primer.md
rhce/035-copy-vs-template	rhce	easy	rhce, ansible, files	What is the difference between the copy and template modules?	copy: deploys static files as-is from files/ directory\ntemplate: processes Jinja2 templates from templates/ directory, substituting variables\nBoth support: owner, group, mode, backup\ntemplate supports: validate (run a command to check syntax before deploying)	training/library/topics/rhce/primer.md
rhce/036-storage-lvm	rhce	hard	rhce, ansible, storage, lvm	How do you automate LVM setup with Ansible?	1. community.general.lvg: create VG (vg: datavg, pvs: /dev/sdb)\n2. community.general.lvol: create LV (vg: datavg, lv: datalv, size: 5g)\n3. community.general.filesystem: create FS (fstype: xfs, dev: /dev/datavg/datalv)\n4. ansible.posix.mount: mount (path: /mnt/data, src: /dev/datavg/datalv, fstype: xfs, state: mounted)	training/library/topics/rhce/primer.md
rhce/037-cron-module	rhce	easy	rhce, ansible, cron	How do you manage cron jobs with Ansible?	ansible.builtin.cron:\n  name: "Backup database"\n  minute: "0"\n  hour: "2"\n  job: "/usr/local/bin/backup.sh"\n  user: root\nSpecial time: special_time: daily/weekly/monthly/yearly/reboot\nRemove: state: absent\n\nRemember: "podman = docker without daemon." It runs rootless containers by default, uses the same CLI as Docker.\n\nExample: podman run -d -p 8080:80 nginx — same syntax as docker run.	training/library/topics/rhce/primer.md
rhce/038-nmcli-module	rhce	hard	rhce, ansible, networking	How do you configure network interfaces with Ansible?	community.general.nmcli:\n  conn_name: eth0\n  ifname: eth0\n  type: ethernet\n  ip4: 192.168.1.100/24\n  gw4: 192.168.1.1\n  dns4: [8.8.8.8, 8.8.4.4]\n  state: present\nAlso: ansible.builtin.hostname for setting hostname\nansible.builtin.lineinfile for /etc/hosts entries	training/library/topics/rhce/primer.md
rhce/039-check-diff-mode	rhce	easy	rhce, ansible, debugging	What do --check and --diff do in ansible-playbook?	--check: dry run mode, shows what WOULD change without making changes\n--diff: shows file content differences (like diff output)\nCombine both: ansible-playbook site.yml --check --diff\nAlso: --syntax-check validates YAML syntax\n--list-tasks shows all tasks without running\n--list-tags shows all available tags	training/library/topics/rhce/primer.md
rhce/040-idempotency	rhce	medium	rhce, ansible, best-practices	What does idempotency mean in Ansible and why does it matter?	Idempotent = running the playbook multiple times produces the same result. Second run should show zero changes. The exam expects idempotent playbooks.\nCommon violations: command/shell without changed_when, using 'latest' state when not needed.\nFix: use changed_when: false for read-only commands, prefer state: present over state: latest.	training/library/topics/rhce/primer.md
rhce/041-host-vars-group-vars	rhce	medium	rhce, ansible, inventory, variables	How do host_vars and group_vars directories work?	Create directories alongside inventory:\ninventory/\n  hosts\n  host_vars/\n    web1.example.com.yml\n  group_vars/\n    all.yml\n    webservers.yml\nFiles are automatically loaded. host_vars override group_vars. Child group vars override parent group vars.	training/library/topics/rhce/primer.md
rhce/042-include-vs-import	rhce	hard	rhce, ansible, roles	What is the difference between include_role and import_role?	import_role: static, parsed at playbook load time. Tags inherited by all tasks. Cannot be used in loops.\ninclude_role: dynamic, parsed at runtime. Tags only on the include task. Can be used in loops and with conditionals.\nSimplest approach: use roles: section in the play. Use include_role only when you need conditional or looped role inclusion.	training/library/topics/rhce/primer.md
rhce/043-serial-rolling	rhce	medium	rhce, ansible, parallelism	How do you perform rolling updates with Ansible?	Use serial in the play:\n- hosts: webservers\n  serial: 2  (2 hosts at a time)\nPercentage: serial: "25%"\nStepped: serial: [1, 5, "100%"] — first 1 host (canary), then 5, then the rest.\nCombine with max_fail_percentage to abort if too many hosts fail.	training/library/topics/rhce/primer.md
rhce/044-async-tasks	rhce	hard	rhce, ansible, parallelism	How do you run long-running tasks asynchronously in Ansible?	Fire and forget:\n  async: 3600 (max seconds)\n  poll: 0 (don't wait)\n  register: long_job\n\nCheck later:\n  ansible.builtin.async_status:\n    jid: "{{ long_job.ansible_job_id }}"\n  register: result\n  until: result.finished\n  retries: 60\n  delay: 10\n\nRemember: "LUKS = Linux Unified Key Setup." It encrypts entire block devices.\n\nExample: cryptsetup luksFormat /dev/sdb1 && cryptsetup open /dev/sdb1 mydata && mkfs.xfs /dev/mapper/mydata	training/library/topics/rhce/primer.md
rhce/045-vault-rekey	rhce	easy	rhce, ansible, vault	How do you change the password on a vault-encrypted file?	`ansible-vault rekey secrets.yml` prompts for the old password and then the new password to re-encrypt the file. With vault IDs: `ansible-vault rekey --vault-id dev@prompt secrets.yml`. This is essential when rotating credentials or when a team member with vault access leaves. \nGotcha: rekey does not change the file contents, only the encryption key protecting them.	training/library/topics/rhce/primer.md
rhce/046-command-vs-shell	rhce	medium	rhce, ansible, modules	What is the difference between command and shell modules?	command: runs a command directly (no shell). No pipes, redirects, env vars, or glob expansion. Safer (no injection risk).\nshell: runs through /bin/sh. Supports pipes, redirects, env vars, globs.\nRule: use command by default, shell only when you need shell features.\nBoth need changed_when for idempotency.	training/library/topics/rhce/primer.md
rhce/047-become-escalation	rhce	easy	rhce, ansible, privilege-escalation	How does privilege escalation work in Ansible?	Set in ansible.cfg or per-play/per-task:\nbecome: true\nbecome_method: sudo\nbecome_user: root\nbecome_ask_pass: false\nPrecedence: task > play > ansible.cfg\nThe remote user needs passwordless sudo (sudoers.d entry).\n\nGotcha: The RHCE exam expects you to use Ansible for automation tasks. Know playbook structure, handlers, templates, and roles.\n\nRemember: "Playbook = YAML, Play = host group + tasks, Task = module + args."	training/library/topics/rhce/primer.md
rhce/048-file-module	rhce	easy	rhce, ansible, files	What can the ansible.builtin.file module do?	Create directory: state: directory\nCreate symlink: state: link, src: target\nDelete: state: absent\nSet permissions: owner, group, mode\nTouch: state: touch\nRecursive ownership: recurse: true	training/library/topics/rhce/primer.md
rhce/049-get-url-unarchive	rhce	medium	rhce, ansible, files	How do you download and extract files with Ansible?	Download:\n  ansible.builtin.get_url:\n    url: https://example.com/file.tar.gz\n    dest: /tmp/file.tar.gz\n    checksum: sha256:abc123\n\nExtract:\n  ansible.builtin.unarchive:\n    src: /tmp/file.tar.gz\n    dest: /opt/app/\n    remote_src: true\nNote: remote_src: true means the archive is already on the managed node.	training/library/topics/rhce/primer.md
rhce/050-exam-tips	rhce	easy	rhce, exam	What are the top exam day tips for the RHCE (EX294)?	1. Use ansible-doc extensively (no internet)\n2. Always use FQCN for module names\n3. Test with --syntax-check then --check --diff\n4. Playbooks must be idempotent (second run = 0 changes)\n5. Set both permanent: true and immediate: true for firewall rules\n6. After sefcontext, always restorecon\n7. Note the vault password immediately\n8. Run playbooks twice to verify idempotency\n9. Use handlers for service restarts after config changes\n10. Extra vars (-e) always override everything	training/library/topics/rhce/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [RHCE (EX294) Exam Preparation](../../../../library/topics/rhce/index.md) (Topic Pack, L2) — RHCE (EX294) Exam

<!-- wiki:related:end -->
