One of the things that I love about Ansible's model is that we never need an agent on the host. Once you configure something with Ansible, there's no artifact of the configuration left on the machine.
One of the things that I love about Ansible's model is that we never need an agent on the host. Once you configure something with Ansible, there's no artifact of the configuration left on the machine.
So I created `apply`[0].
This small bash thing pushes bash scripts called 'units' through ssh to execute through an uploaded 'run' script:
./push units/update units/sshd units/ssh_authorized_keys root@foo.example.com
By writing those 'unit' scripts to be idempotent you can just run them again and again. 'units' can be aggregated in 'groups', which can themselves reference 'groups': ./push groups/base groups/ruby units/dockerd root@foo.example.com
Finally, you can define 'hosts', which are like 'groups', only they save you some typing, which it could do in sequence or parallel: ./apply hosts/foo.example.com hosts/bar.example.com
And since units/, groups/, and hosts/, are just directories and files, autocompletion works immediately and you could get creative with shell expansion for arguments.It was a deceptively simple experience, immediately accessible, trivially enabled literate coding, and overall extremely useful both to set up and maintain those VPSes as well as creating dev environments, or local VMs to test a e.g one-shot unit performing a change or migration.
[0]: https://gitlab.com/adhoc-gti/apply
[1]: https://github.com/lloeki/apply (personal fork)
With an agent, it’s applying all the time and this doesn’t happen.
We actually moved to salt from ansible and we’re happy..
Machines sitting behind VNets, governed by security review boards makes getting agents approved a bit tricky
That gets you the standard advantages of agentless setups, including not requiring the runtime of your config management tool to be everywhere, being able to reprovision ephemeral + immutable cloud resources, and being able to centrally report errors, without any more risk of configuration drift or bitrot.
I still love Ansible, especially for small quick things. As with many tools, though, it's not the only one I reach for any more.
Ideally, I’d like to see a configuration tool that uses Ansible’s SSH push model but without the Python dependency.
There was a pen-test tool designed on these lines once called Mosquito Lisp, which as far as I can see evolved into something called WaspVM: https://github.com/swdunlop/WaspVM I have no idea if it's in use, alive, or even working these days.
Is anyone working on this side of the problem and I've missed it?