Final challenge: automation you can trust
You've inherited the club's Ansible project in ~/ansible. It "works on my machine", but the linter complains, every run changes something, and one of the web servers doesn't actually serve anything. Make it automation the whole team can rely on.
No step-by-step instructions: the objectives say what must be true when you're done. The checks read Ansible's own results (lint, recaps, test runs). The rule of the job: every fix goes into the role, never by hand on a server. The cheat sheet and search (/) are allowed, and hints are below.
The brief
- Lint-clean.
ansible-lintpasses with no findings. - Idempotent. Running
site.ymltwice in a row: the second run changes nothing, on every host. - Really works. The smoke tests in
tests.ymlpass on every web server. - Fixed in the code. Whatever was missing on the broken server is now a task in
roles/web/tasks/main.yml.
Stuck? Hints
Open only as many as you need.
1. Lint-clean
Read each finding: rule name, file and line. The usual suspects are short module names (use FQCNs like ansible.builtin.package), state: latest, task names that don't start with a capital, yes instead of true, and a file without an explicit mode.
Still stuck: lesson 5.
2. Idempotent
A task that reports changed on every run is lying or doing needless work. One task writes today's date into a file: does it need to exist at all?
3. Really works
ansible-playbook tests.yml says which host fails. Ask that host why (ansible HOST -b -a '…' is fine for looking). The old playbook did something the role forgot.
4. Fixed in the code
There's a ready-made task in examples/. Add it to the role's tasks, run site.yml, then the tests again.
Still stuck: lesson 2.