Ansible in depth · Final challenge

Final challenge: automation you can trust

You've inherited the club's Ansible project in ~/ansible. It "works on my machine", but the linter complains, every run changes something, and one of the web servers doesn't actually serve anything. Make it automation the whole team can rely on.

How this works

No step-by-step instructions: the objectives say what must be true when you're done. The checks read Ansible's own results (lint, recaps, test runs). The rule of the job: every fix goes into the role, never by hand on a server. The cheat sheet and search (/) are allowed, and hints are below.

The brief

  1. Lint-clean. ansible-lint passes with no findings.
  2. Idempotent. Running site.yml twice in a row: the second run changes nothing, on every host.
  3. Really works. The smoke tests in tests.yml pass on every web server.
  4. Fixed in the code. Whatever was missing on the broken server is now a task in roles/web/tasks/main.yml.

Stuck? Hints

Open only as many as you need.

1. Lint-clean

Read each finding: rule name, file and line. The usual suspects are short module names (use FQCNs like ansible.builtin.package), state: latest, task names that don't start with a capital, yes instead of true, and a file without an explicit mode.

Still stuck: lesson 5.

2. Idempotent

A task that reports changed on every run is lying or doing needless work. One task writes today's date into a file: does it need to exist at all?

3. Really works

ansible-playbook tests.yml says which host fails. Ask that host why (ansible HOST -b -a '…' is fine for looking). The old playbook did something the role forgot.

4. Fixed in the code

There's a ready-made task in examples/. Add it to the role's tasks, run site.yml, then the tests again.

Still stuck: lesson 2.

Complete every objective in the terminal and the challenge is marked done automatically. It's optional, but it goes on your certificate.