Ansible 101 by Jeff Geerling – new series on YouTube
jeffgeerling.com
jeffgeerling.com
I'll add these links and your YouTube channel to our README now :).
The "it must be idempotent" argument lead to putting conditional into a a language that was never meant to be, doing the whole "store" danse that could be done with simple function calls and whole lot of conventions instead of a proof tested import system.
It's calling python code behind the scene anyway, and nothing reads the playbook apart from ansible itself.
Ansible is a great tool, but I strongly believe the experience would be 100% better without learning, crafting and debugging those twisted .yml.
There's also a utility to help with the running of Ansible playbooks via Python (https://github.com/ansible/ansible-runner).
However, I've said this many times before—if your playbooks start mixing Python into tasks, you're either doing something wrong (it could be architected better), or it's time to write a custom Ansible module so the Python goes into a `.py` file and not into YAML.
99% of my playbooks are strict YAML with maybe a few Jinja filters, which make everything very readable. But I've also seen a ton of YAML that makes me want to barf.
See, if hello world is:
- name: Hello Ansible
hosts: ansibleclient01.local
tasks:
- name: Copy '/tmp/testfile.txt' into 'hello world'.
copy:
content: hello worldn
dest: /tmp/testfile.txt
Then it would become: from icandream import playbook
pb = playbook("Hello Ansible", hosts=["ansibleclient01.local"])
with db.define_task(Copy '/tmp/testfile.txt' into 'hello world') as task:
task.copy(content="hello worldn", dest="/tmp/testfile.txt)
Instant benefits:- Python interpretter is very good at telling you error messages.
- You get an exception system, stack trace and a debugger for free
- The entire python tooling ecosystem, including full monthy IDE support, linters and formaters, is at your disposal
- Any more complex example is going to be much cleaner than the yaml version, exponentially. And no need to live in the "yaml/python module" dichotomy to keep PB clean.
- No need to reinvent the wheel. Python has elegant import, namespaces, ways to pass data around, conditionals, etc.,
- You can import Python libs. Event if it's just for declarative stuff like pendulum, appdirs..
The only cons are:
- idempotence needs to be enforced culturally. It's already the case for people writing the module behind the scene, and a good API + some warning tricks would be enough IMO.
- can't read the files outside of Python. But nobody does it anyway, and we can always let the Python files output the yaml representation if needed.
Now I don't hold my breath because it's a lot of work and the ansible community usually don't like the idea at all, and I'm not willing to do it. Fair is fair.
It doesn't even really do that. It sets up a rube goldberg mechanism to push a python program containing a base64 encoded zip file containing the module it wants to execute it. Then it runs a shell to run python to run that module. This is why ansible is 2000x slower than it should be.
Getting rid of the yaml would make things faster, but compare to the cost of the network, I don't think it would be that much faster.
So how do people test their ansible playbooks if they can't easily reverse their state?
If linux only, docker is great for that because it's so light, and it easier to compare layers of an image.
Other times, I write a secondary playbook to roll back some deployment if needed. (Though sometimes it's as simple as setting a `state=present` to `state=absent` for a few tasks and that's all that's required.
Molecule 3.x was recently released but there's been some major changes which "broke" my existing setup and I haven't yet gotten around to "fixing" it.
It takes a bit to learn how to use Molecule but, if you do much role development at all, it's definitely worth it!
Ansible makes it easy to do mundane things like delete the default user and set up a new account, copy over ssh keys for easy access, add services and set up the docker container. Docker has the meaty stuff that takes ages to build and install, so I make sure it works and then save the image for easy download later.
What I've currently got going is everything in one repository, it has the playbooks, docker files, tests, service files, etc. I clone that using ansible on the target machine. Ansible then pulls the repo to get new changes and rebuilds the container. The container also adds that repo as a volume so that tests and other things are accessible. I don't store containers, I just spin up a new vm on boot.
I do have a "backup" playbook which installs everything inside the container when I want to test outside docker. This has happened a few times when using custom libraries that are specific to the embedded platform that don't come with the docker images (eg hardware accelerated gstreamer plugins come to mind). On the Pi life is a bit better because there are raspbian docker images anyway.
Ansible is used in the network automation space as well, but some people found they wanted more flexibility so they created 'raw' Python frameworks:
* https://nornir.readthedocs.io/en/latest/
* https://napalm-automation.net
Presentation:
Is it compatible with ansible?
Because ansible has one thing that can't be beaten: the ecosystem is huge. You have recipes for everything.
I was really excited about it, but unfortunately he stopped work on it since it wasn't getting much traction.
With Ansible, you can go _very_ far before you have to know anything about Python (well, most of the time—annoyingly, there are situations like naming groups where Python's variable syntax leaks through currently).
It would be like making people know basic Go syntax just to write or edit a Kubernetes manifest—that immediately limits its appeal to those who have at least a passing interest in Go (which is a much smaller audience than 'willing to learn YAML, which is used all over the place').
Anybody provisioning a machine knows a little bit of bash, and most probably python. Python is way more "used all over the place" than yaml.
Worst of all, when you are a beginner, ansible yaml errors are an utter mystery.