Ansible cookbook
This document contains assorted patterns, tips, tricks etc. that we've collected while working on our Ansible script collection. It supplements the style guide but is not prescriptive and rather meant to be a helpful reference for implementation questions and problems that arise frequently.
Apt
Repositories
When adding additional apt repositories on a host, keep the following in mind:
-
The newer SourcesList ⧉ format is usually preferrable when available.
-
To avoid hardcoding distribution and architecture you can use the
ansible_facts.ansible_facts.distribution_releaseandansible_facts.architecturefacts, e.g. via something like the following invars/main.ymlinside a role:my_role_deb_arch_map: x86_64: amd64 aarch64: arm64 my_role_deb_arch: >- {{ my_role_deb_arch_map[ansible_facts.architecture] | default(ansible_facts.architecture) }} my_role_deb_release: "{{ ansible_facts.distribution_release }}"
Downloads
When downloading keyrings, programs, config files etc. the following can be helpful:
-
Don't use
curldirectly, Ansible ships withansible.builtin.get_url. -
Specify a
checksumwhen possible so that downloads are idempotent. -
Avoid downloading to
/tmpif it would cause the task to be re-executed after a reboot. Rather download to a stable location or only download at all if what you currently have is outdated.