All my work machines are set up using a single, parameterized Ansible playbook.
All my work machines are set up using a single, parameterized Ansible playbook.
Unfortunately I still have to use Ansible for stuff that isn't my dotfiles, but the less Ansible, the better. It feels like whatever use cases I have for Ansible are weird and not what other people are doing, because everything I try to do is difficult and poorly documented. For example, when I try to spin up a machine running Alpine Linux using Ansible, I've encountered all sorts of strange bugs, some of which I've reported and are (being) fixed, but it boggles my mind that what I thought would be really basic stuff, like setting the hostname or the timezone, is buggy as heck.
I used to use bash scripts myself, however, I did transition to Ansible because I often ran into problems with replayability of scripts (running them multiple times).
Ansible (and other tools like it) handle stuff like "change a line in this config file to that" or "add this flag here when xyz" easily and you can run it as many times as you like.
Also, Ansible Galaxy offers a lot of roles ready-to-use such as docker setup or asdf version manager plugin management. Though a lot of it is often not that well maintained.
I copied some of it into an example repository to showcase the structure and left the playbook.yaml intact for reference. You can find it on: https://github.com/cybrox/ansible-setup-example
I don't want to claim that this structure is in any way better or worse than anything else, it's just one that works for me. There's a lot of discussion on how Ansible projects should be structured. This allows me to simply run `WORKSTATION=home DESKTOP=wayland ansible-playbook playbook.yaml` on a fresh Arch Linux install and everything is ready to go.
For maintaining the repository, I got used to changing things in there and deploying them instead of changing dotfiles directly. However, I do also deploy a bash script to copy all the files from the system back to the repo to catch dotfile edits I did hastily at 3am.
An example of dotfiles being deployed with this approach is roles/shell/tasks/zsh.yaml