Ansible is an open-source configuration management, deployment, and orchestration tool developed by Red Hat.
It allows you to automate the setup and management of servers using simple YAML files known as playbooks.
Ansible works on the principle of:
In DevOps, Ansible is used to:
Answer:
Ansible is an IT automation tool that allows engineers to manage infrastructure as code.
It simplifies repetitive operations like installing packages, configuring servers, and deploying applications.
Why used in DevOps:
Example use case:
Provision a group of EC2 instances, install Docker, and deploy an application — all via one YAML playbook.
Answer:
Ansible has three main components:
Optional components:
Answer:
Ansible uses YAML (Yet Another Markup Language) for writing Playbooks.
YAML is human-readable and indentation-based, making it easy to define tasks.
Example:
- name: Install and start NGINX
hosts: webservers
become: yes
tasks:
- name: Install NGINX
apt:
name: nginx
state: present
- name: Start service
service:
name: nginx
state: started
Answer:
The inventory file contains the list of servers (hosts) that Ansible manages.
Example (INI format):
[webservers]
web1 ansible_host=10.0.0.10
web2 ansible_host=10.0.0.11
[dbservers]
db1 ansible_host=10.0.0.20
Why important:
You can group servers and apply specific playbooks to different groups (e.g., web vs. database).
Answer:
Modules are reusable units of code that perform specific tasks like installing software, managing files, or creating users.
Examples:
apt → Manage Debian packages.yum → Manage RHEL packages.copy → Copy files.service → Manage services.ec2 → Manage AWS EC2 instances.Example task:
- name: Install Apache
yum:
name: httpd
state: present
Answer:
A Playbook is a YAML file that defines a set of tasks to be executed on a group of hosts.
Example:
- name: Setup web server
hosts: webservers
become: yes
tasks:
- name: Install Nginx
apt:
name: nginx
state: present
Real-world use:
Playbooks automate configuration management, application deployment, and environment provisioning.
Answer:
| Feature | Ansible | Puppet | Chef |
|---|---|---|---|
| Language | YAML | DSL (Ruby-based) | Ruby |
| Agentless | Yes | No | No |
| Setup Complexity | Simple | Moderate | High |
| Communication | SSH | Agent/Server | Agent/Server |
In short:
Ansible’s simplicity and agentless architecture make it preferred for cloud automation.
Answer:
Use the following command:
ansible-playbook playbook.yml -i inventory
Options:
-i → specify inventory file--check → dry-run mode--limit → target specific host/groupAnswer:
Idempotency means running the same playbook multiple times won’t cause changes if the system is already in the desired state.
Example:
If a playbook installs Nginx, rerunning it won’t reinstall Nginx if it’s already present.
Why important:
Ensures safe, repeatable deployments and prevents unintended changes.
Answer:
Used to execute a single, quick task without writing a playbook.
Example:
ansible all -i inventory -m ping
ansible webservers -i inventory -m apt -a "name=nginx state=present" -b
Useful for verifying connectivity or making quick fixes across multiple servers.
Answer:
Ansible Galaxy is a public repository of reusable roles shared by the community.
Example command:
ansible-galaxy install geerlingguy.nginx
Why important:
Reduces effort — you can reuse prebuilt roles for common tasks like installing Nginx, Docker, or Jenkins.
Answer:
Roles help structure large playbooks by separating tasks, variables, templates, and handlers.
Role structure:
roles/
webserver/
tasks/
main.yml
handlers/
main.yml
templates/
vars/
Use case:
Roles improve reusability and maintainability in enterprise-scale automation projects.
Answer:
Variables store dynamic values and can be defined in:
-e)Example:
vars:
app_port: 8080
tasks:
- name: Start app
service:
name: myapp
state: started
Answer:
Handlers are tasks triggered only when notified — typically used to restart services after configuration changes.
Example:
tasks:
- name: Copy nginx config
copy:
src: nginx.conf
dest: /etc/nginx/nginx.conf
notify: restart nginx
handlers:
- name: restart nginx
service:
name: nginx
state: restarted
copy and template modules?Answer:
Example (template):
- name: Create config file
template:
src: config.j2
dest: /etc/myapp/config.conf
Answer:
Use Ansible Vault to encrypt files or variables.
Example:
ansible-vault create secrets.yml
ansible-vault encrypt vars.yml
ansible-playbook playbook.yml --ask-vault-pass
Use case:
Protect credentials, SSH keys, and API tokens in production.
Answer:
Use:
ansible-playbook playbook.yml --check --diff
Why:
Performs a dry-run and shows expected changes — helps prevent accidental misconfiguration in production.
Answer:
ansible-playbook playbook.yml --start-at-task="Install nginx"
Or tag tasks:
- name: Install Nginx
apt:
name: nginx
state: present
tags: web
Then:
ansible-playbook playbook.yml --tags web
Answer:
-v, -vv, or -vvv for verbose output.debug module:- debug:
var: my_variable
Real-world use:
Essential for tracing variable values and playbook flow during troubleshooting.
Answer:
ansible-playbook -i inventory site.yml
Result:
Automated deployments triggered directly from CI/CD pipelines.
Answer:
In AWS:
Use dynamic inventory scripts to manage EC2 instances automatically by tags.
Answer:
Dynamic Inventory fetches host details dynamically from cloud providers instead of static files.
Example:
ansible-inventory -i aws_ec2.yaml --graph
Use case:
When managing auto-scaled EC2 instances or containers where host IPs change frequently.
Answer:
async and poll: 0 for parallel execution.--limit).gather_facts: no
serial for batch execution.These optimizations significantly reduce runtime in large environments.
Answer:
changed: False if no modification needed.Answer:
Ansible Tower is the enterprise version of Ansible providing:
AWX is the open-source upstream project for Tower.
Answer:
Use:
ignore_errors: yes
failed_when: "result.rc != 0"
or block-rescue structure:
- block:
- name: Try task
command: /bin/false
rescue:
- debug: msg="Recovered from error"
Answer:
Example directory:
inventories/
dev/
prod/
roles/
Answer:
Use cloud modules:
- name: Launch EC2 instance
ec2:
key_name: dev-key
instance_type: t2.micro
image: ami-123456
wait: yes
count: 2
Use case:
Automate creation and configuration of AWS infrastructure directly via playbooks.
Q: You had a deployment failure because a configuration file was missing during playbook execution. How did you handle it?
Answer (STAR):
templates/.when: file_exists check.Q: Describe a time you used Ansible to automate a repetitive operational task.
Answer (STAR):
yum module.serial: 10.