Ansible
Ansible
Beginner
Q1: What is Ansible?
Ansible is an agentless IT automation tool for configuration management, provisioning, and orchestration.
Q2: Why use Ansible?
It provides simple, declarative automation over SSH/WinRM with human-readable YAML.
Q3: What does agentless mean in Ansible?
No persistent agent is required on managed nodes; controller connects remotely when needed.
Q4: What is a control node?
Machine where Ansible is installed and automation is executed.
Q5: What is a managed node?
Target host/device Ansible configures.
Q6: What is inventory in Ansible?
List of hosts/groups Ansible can target.
Q7: Static vs dynamic inventory?
Static is file-defined; dynamic is generated from APIs/cloud sources.
Q8: What is a playbook?
YAML file defining one or more plays/tasks to run on target hosts.
Q9: What is a play?
Mapping of hosts to tasks and execution settings.
Q10: What is a task?
Single unit of automation calling an Ansible module.
Q11: What is a module?
Reusable automation component performing specific operation (package, file, service, etc.).
Q12: What is a role?
Structured reusable bundle of tasks, vars, handlers, templates, and files.
Q13: Why roles are useful?
Promote reuse, standardization, and clean playbook organization.
Q14: What is idempotency in Ansible?
Running automation repeatedly yields same final state without unintended changes.
Q15: Why idempotency matters?
Safe re-runs, predictable outcomes, and reduced drift.
Q16: What is YAML in Ansible context?
Data serialization format used for playbooks and vars files.
Q17: What is ansible.cfg?
Configuration file controlling Ansible behavior (paths, defaults, plugins, etc.).
Q18: What is host pattern?
Expression selecting target hosts/groups for play execution.
Q19: What is all in inventory targeting?
Built-in group including all inventory hosts.
Q20: What is localhost use case?
Run tasks on control node itself.
Q21: What is ad-hoc command?
One-line Ansible command for quick single-task operations.
Q22: Example ad-hoc usage purpose?
Ping all hosts, restart service, gather quick facts.
Q23: What is ansible-playbook command?
Executes Ansible playbooks.
Q24: What is gatherfacts?
Collect system information via setup module before tasks.
Q25: Why facts are useful?
Enable conditional logic based on OS/network/hardware properties.
Q26: What is variable in Ansible?
Named value used to parameterize tasks/templates/logic.
Q27: What is precedence in variables?
Rules determining which variable source wins when duplicates exist.
Q28: What is hostvars/groupvars?
Per-host or per-group variable files.
Q29: What is template module?
Renders Jinja2 templates into destination files on targets.
Q30: What is copy module?
Copies file content from controller to managed host.
Q31: copy vs template?
copy transfers static files; template renders dynamic variables.
Q32: What is command module?
Runs command without shell interpretation features.
Q33: What is shell module?
Runs commands through shell, enabling pipes/redirection (with more risk).
Q34: Why prefer command over shell when possible?
Safer and more predictable execution.
Q35: What is file module?
Manages file/directory state, ownership, permissions, links.
Q36: What is package module?
Installs/removes packages using platform package manager abstraction.
Q37: What is service module?
Manages services state (started/stopped/enabled).
Q38: What is handler?
Task triggered by notify, typically for restart/reload actions.
Q39: Why use handlers?
Avoid unnecessary service restarts; run only on change.
Q40: What is notify?
Mechanism for tasks to trigger handlers when changed.
Q41: What is become?
Privilege escalation (e.g., sudo) for tasks requiring elevated rights.
Q42: Why use become carefully?
Limit privilege scope for security and auditability.
Q43: What is check mode?
Dry-run estimation of changes without applying (module support dependent).
Q44: What is diff mode?
Shows before/after differences for changed files (where supported).
Q45: What is tags in Ansible?
Labels allowing selective task/role execution.
Q46: Why tags help?
Faster targeted runs (e.g., only “config” or “deploy”).
Q47: What is register in Ansible?
Stores task output for later conditions/logic.
Q48: What is when condition?
Conditional task execution expression.
Q49: What is loop in Ansible?
Repeat task over list of items.
Q50: What is withitems legacy pattern?
Older loop syntax; modern loop is generally preferred.
Q51: Beginner anti-pattern in Ansible?
Using many shell commands instead of purpose-built modules.
Q52: Another beginner anti-pattern?
Hardcoding secrets in playbooks.
Q53: Beginner security baseline?
Use Ansible Vault and least-privilege remote users.
Q54: Beginner reliability baseline?
Write idempotent tasks and test in staging first.
Q55: Beginner performance baseline?
Disable unnecessary fact gathering where not needed.
Q56: Beginner governance baseline?
Version-control playbooks/roles and require peer review.
Q57: Beginner troubleshooting command?
Increase verbosity with -v/-vv/-vvv.
Q58: What is inventory group hierarchy?
Groups can contain hosts and child groups.
Q59: Beginner workflow principle?
Model desired state, not imperative command sequences.
Q60: Beginner best practice?
Keep playbooks simple, readable, and role-driven.
Intermediate
Q61: What is Ansible collections?
Packaging format for modules, roles, and plugins with namespacing.
Q62: Why collections matter?
Decouple content lifecycle from core and improve modularity.
Q63: What is ansible-galaxy?
Tool to install/manage roles and collections.
Q64: What is role directory structure?
tasks/, handlers/, templates/, files/, vars/, defaults/, meta/.
Q65: defaults vs vars in role?
defaults are low precedence; vars are high precedence role-specific values.
Q66: Why avoid overusing role vars?
High precedence can make overrides difficult.
Q67: What is includetasks vs importtasks?
include is dynamic at runtime; import is static at parse time.
Q68: includerole vs importrole?
Dynamic vs static role inclusion semantics similarly.
Q69: What is block in Ansible?
Group tasks for shared directives and structured error handling.
Q70: What is rescue/always in block?
Error recovery path and always-run cleanup section.
Q71: What is failedwhen?
Custom condition defining task failure logic.
Q72: What is changedwhen?
Custom condition controlling changed status reporting.
Q73: Why customize changedwhen?
Improve idempotency signal and handler correctness.
Q74: What is delegateto?
Execute task on different host than current inventory target.
Q75: delegateto common use case?
Run load balancer API calls from controller while deploying app hosts.
Q76: What is runonce?
Execute task only once per play (often with delegation).
Q77: What is serial in plays?
Limits batch size of hosts processed simultaneously.
Q78: Why use serial?
Rolling updates and reduced blast radius.
Q79: What is strategy in Ansible?
Task execution behavior across hosts (linear, free, etc.).
Q80: linear vs free strategy?
linear keeps host step lockstep; free lets hosts progress independently.
Q81: What is forks setting?
Max parallel host connections/tasks from controller.
Q82: Forks tradeoff?
Higher speed vs greater controller/target load.
Q83: What is async + poll?
Run long tasks asynchronously and optionally check completion later.
Q84: Why async tasks useful?
Avoid SSH timeouts for lengthy operations.
Q85: What is waitfor module?
Wait for port/file/timeout/condition before proceeding.
Q86: What is until/retries/delay pattern?
Retry task until condition met.
Q87: What is Jinja2 in Ansible?
Templating engine for variable interpolation and logic.
Q88: What is filter in Jinja2?
Function transforming data in templates/expressions.
Q89: Common filter examples?
default, toyaml, fromjson, dict2items, selectattr.
Q90: What is lookup plugin?
Fetch data from external/local sources during playbook execution.
Q91: What is varsprompt?
Interactively ask user for variable input at runtime.
Q92: What is Ansible Vault?
Encryption mechanism for sensitive vars/files.
Q93: Vault best practice?
Encrypt only secrets, keep clear separation from non-secret config.
Q94: What is nolog?
Suppress sensitive task output from logs.
Q95: Why nolog important?
Prevent accidental secret leakage in CI/logging systems.
Q96: What is dynamic inventory source example?
Cloud plugins for AWS/Azure/GCP/OpenStack, etc.
Q97: Why dynamic inventory in cloud?
Automatically reflect ephemeral infrastructure changes.
Q98: What is fact caching?
Persist gathered facts for faster subsequent runs.
Q99: Fact caching benefit?
Reduces repeated collection overhead at scale.
Q100: What is ansible-lint?
Static analysis tool enforcing quality and best practices in Ansible content.
Q101: Why ansible-lint in CI?
Catch anti-patterns and style issues before runtime failures.
Q102: What is Molecule?
Framework for testing Ansible roles/scenarios.
Q103: Molecule use cases?
Role converge/idempotence/verification tests in isolated instances.
Q104: What is intermediate anti-pattern?
Monolithic playbooks with environment logic scattered everywhere.
Q105: Better structure pattern?
Composable roles + env vars files + clear orchestration playbooks.
Q106: What is inventory separation strategy?
Separate inventories per environment (dev/stage/prod).
Q107: Why separate inventories?
Reduce accidental cross-environment changes.
Q108: What is immutable infrastructure relation to Ansible?
Use Ansible for image baking/provisioning rather than in-place mutable drift.
Q109: What is orchestrating across tiers?
Coordinating db/app/lb changes with ordering and health checks.
Q110: What is service rolling update pattern?
serial batches + health checks + traffic control.
Q111: What is canary deployment with Ansible?
Apply changes to small subset first, validate, then expand.
Q112: What is rollback strategy in Ansible?
Reapply previous known-good config/version with controlled playbooks.
Q113: What is intermediate observability baseline?
Track run duration, changed count, failure rate, host coverage.
Q114: What is intermediate reliability baseline?
Idempotence tests + staged rollout + rescue logic.
Q115: What is intermediate security baseline?
Vault, nolog, scoped credentials, audited automation identities.
Q116: What is intermediate governance baseline?
Code review, CI lint/test gates, change approval workflow.
Q117: Intermediate maturity signal?
Team can run playbooks repeatedly with predictable results and low surprises.
Q118: Intermediate collaboration principle?
Platform and app teams share reusable role contracts.
Q119: Intermediate performance principle?
Tune forks/strategy/fact gathering based on measured bottlenecks.
Q120: Intermediate architecture principle?
Separate configuration data from automation logic.
Q121: Intermediate ops principle?
Treat playbook failures as product bugs with root-cause tracking.
Q122: Intermediate compliance principle?
Keep auditable logs of who ran what, where, and when.
Q123: Intermediate cost principle?
Optimize run frequency/scope to avoid unnecessary infrastructure churn.
Q124: Intermediate scaling principle?
Standardize roles and inventories before host count explodes.
Q125: Intermediate best practice?
Engineer Ansible content as tested, reusable automation software.
Advanced
Q126: What is enterprise Ansible control-plane challenge?
Managing content quality, execution scale, and governance across many teams.
Q127: What is Ansible Automation Platform/AWX role?
Centralized job templates, RBAC, credential management, and scheduling.
Q128: Why central automation controller?
Operational visibility, policy enforcement, and delegated self-service.
Q129: What is execution environment (EE) in Ansible?
Containerized runtime bundling ansible-core, collections, and dependencies.
Q130: Why execution environments matter?
Reproducible automation runtime across dev/CI/prod.
Q131: What is content signing/provenance concern?
Ensuring trusted origins of collections/roles and execution artifacts.
Q132: Supply-chain risk in Ansible ecosystem?
Untrusted roles/plugins can execute privileged remote actions.
Q133: Mitigation for supply-chain risk?
Curated internal content repos, pin versions, security scanning, signatures.
Q134: What is policy-as-code for Ansible?
Automated rules enforcing security/compliance patterns in playbooks.
Q135: Example policy checks?
No plain secrets, no unchecked shell usage, become scoping required.
Q136: What is zero-trust automation principle?
Strong identity/authz boundaries for every automation action path.
Q137: What is secret zero challenge in automation?
Secure bootstrap of first credential to access vault/secrets.
Q138: Mitigation for secret zero?
Short-lived identity federation and tightly scoped machine credentials.
Q139: What is multi-tenant automation challenge?
Prevent one team’s playbooks from impacting other environments.
Q140: Multi-tenant mitigation?
RBAC boundaries, isolated inventories, separate execution nodes.
Q141: What is blast radius control in Ansible runs?
Limit host scope/batch size and require approvals for high-risk changes.
Q142: What is progressive rollout at scale?
Canary -> phased batches -> full rollout with health gates.
Q143: What is automation SLO concept?
Reliability targets for run success rate, latency, and recovery times.
Q144: Why define SLOs for automation platform?
Treat automation as critical service, not ad-hoc scripts.
Q145: What is drift remediation strategy?
Scheduled compliance runs with controlled auto-remediation policies.
Q146: Auto-remediation risk?
Bad playbook logic can propagate failures rapidly.
Q147: Mitigation for remediation risk?
Dry-run checks, approvals, staged enforcement, circuit breakers.
Q148: What is event-driven Ansible concept?
Trigger automation from monitoring/security/ITSM events.
Q149: Event-driven benefit?
Faster response and reduced manual toil.
Q150: Event-driven caution?
Prevent alert loops and uncontrolled repeated executions.
Q151: What is large inventory performance bottleneck?
Connection setup, fact gathering, and serial task overhead.
Q152: Scale optimization tactics?
Fact caching, targeted patterns, async ops, tuned forks, EE efficiency.
Q153: What is controller HA consideration?
Redundant control components and shared persistent state for continuity.
Q154: What is disaster recovery for automation platform?
Backup inventories/projects/credentials metadata and rehearse restore.
Q155: Why restore rehearsal is essential?
Backups without tested recovery are unreliable during incidents.
Q156: What is compliance evidence in Ansible operations?
Job logs, approvals, diffs, artifact versions, operator identity trails.
Q157: What is segregation of duties pattern?
Separate content authors, approvers, and production executors.
Q158: What is change window enforcement?
Allow high-risk job templates only during approved periods.
Q159: What is advanced anti-pattern?
Using Ansible as generic shell runner without declarative state modeling.
Q160: Better long-term model?
Module-first, idempotent, tested roles with controlled orchestration.
Q161: What is hybrid IaC relationship (Terraform + Ansible)?
Provision infrastructure with Terraform; configure software/state with Ansible.
Q162: Why combine Terraform and Ansible?
Clear separation of resource lifecycle vs configuration lifecycle concerns.
Q163: What is immutable image pipeline with Ansible?
Use Ansible in image baking, then deploy immutable artifacts.
Q164: Why immutable pipelines improve reliability?
Reduce in-place drift and simplify rollback mechanics.
Q165: What is advanced observability gold standard?
Per-task telemetry, change impact correlation, and failure taxonomy dashboards.
Q166: What is run cost governance?
Track automation runtime/resource consumption and optimize low-value jobs.
Q167: What is resilience game day for Ansible platform?
Simulate credential failures, unreachable hosts, partial rollouts, and recovery.
Q168: What is final reliability principle?
Automation must be idempotent, testable, and safely rerunnable.
Q169: What is final security principle?
Every automation credential/action must be scoped, auditable, and ephemeral when possible.
Q170: What is final governance principle?
Codify standards in CI and controller policies, not tribal knowledge.
Q171: What is final architecture principle?
Design reusable role interfaces and isolate environment data cleanly.
Q172: What is final operations principle?
Continuously measure run quality and eliminate recurring toil patterns.
Q173: What is final collaboration principle?
Treat automation content as shared product with owners and SLAs.
Q174: What is final scaling principle?
Standardize execution environments and role contracts before hyper-growth.
Q175: What is final compliance principle?
Preserve immutable audit trails for all production automation runs.
Q176: What is final performance principle?
Optimize for fast safe feedback, not maximum uncontrolled parallelism.
Q177: What is final recovery principle?
Every critical playbook needs tested rollback and rescue paths.
Q178: What is final platform principle?
Operate Ansible control plane as mission-critical infrastructure.
Q179: What is final strategy principle?
Automate high-value repetitive operations first, then expand responsibly.
Q180: Final maturity principle?
Ansible excellence is secure, predictable, and scalable automation engineering.
Bonus: Minimal Role-Oriented Playbook Example
---
- name: Configure web tier
hosts: web
become: true
vars:
app_port: 8080
roles:
- common
- nginx
- app_deploy