Ansible
- Pronunciation
- AN-sih-bul
In short
Ansible is an open-source automation tool that configures servers and deploys applications by running YAML playbooks over SSH, with no agent on the machines.
What is Ansible?
Ansible was created by Michael DeHaan in 2012 and has been part of Red Hat since 2015. It automates the jobs people used to do by logging into servers one by one: installing packages, editing configuration files, creating users, restarting services and rolling out new versions of an application.
Work is described in playbooks, YAML files that list tasks to run on groups of hosts. Each task calls a module, such as apt to install a package, copy to place a file or service to restart a daemon. The machines to manage are listed in an inventory, and Ansible connects to them over SSH, or WinRM for Windows, so nothing needs to be installed on them beyond Python.
Most modules are idempotent: they check the current state first and only act if something differs. Running a playbook twice therefore leaves the servers in the same state, which makes it safe to apply a playbook again and again to keep a fleet consistent. Roles bundle reusable sets of tasks, and Ansible Galaxy shares community-built roles and collections.
A common misconception is that Ansible and Terraform compete. Terraform is usually used to create the infrastructure itself, while Ansible configures what runs on the machines; containers and immutable images have also replaced some of this work. Unlike tools such as Puppet or Chef, Ansible pushes changes from a control machine instead of running an agent on every server.
Key takeaways
- Ansible automates server configuration and application deployment.
- Tasks are written in YAML playbooks and run against an inventory of hosts.
- It is agentless: it connects over SSH and needs only Python on the hosts.
- Idempotent modules make it safe to run a playbook repeatedly.
- It usually configures machines that tools like Terraform create.
Example
- name: Set up web servers
hosts: web
become: true
tasks:
- name: Install nginx
ansible.builtin.apt:
name: nginx
state: present
update_cache: true
- name: Make sure nginx is running
ansible.builtin.service:
name: nginx
state: started
enabled: true
# Run with: ansible-playbook -i inventory.ini site.ymlReaders ask
Does Ansible need an agent on each server?
No. Ansible is agentless: it connects from a control machine over SSH (or WinRM on Windows) and runs its modules there, needing only Python on the managed hosts.
What is an Ansible playbook?
A YAML file that lists plays, each mapping a group of hosts to a series of tasks, such as installing packages, copying files and restarting services.
What does idempotent mean in Ansible?
That running the same task twice has the same result as running it once. A module that installs a package does nothing if the package is already installed.
Often compared
See also
- Configuration ManagementDevOps & Cloud, p. 11Configuration management is the practice of defining the desired state of servers and software in code and using tools to apply and keep it automatically.
- Infrastructure as CodeDevOps & Cloud, p. 29Infrastructure as code is the practice of defining servers, networks, and other infrastructure in version-controlled files that tools apply automatically.
- TerraformDevOps & Cloud, p. 52Terraform is an infrastructure-as-code tool: you describe cloud resources in configuration files, and one command creates or updates them to match.
- SSHNetworking, p. 28SSH is a cryptographic network protocol for securely logging in to and running commands on remote computers, encrypting all traffic between the two machines.
- YAMLDevOps & Cloud, p. 54YAML is a human-readable data format that uses indentation instead of brackets, widely used for configuration files in DevOps tools and CI/CD pipelines.
- DevOpsDevOps & Cloud, p. 14DevOps is a set of practices and a culture that brings software development and IT operations together to deliver software faster and more reliably.
Spotted a mistake or something missing on this page?Suggest an edit