Ansible Is SSH With a Ledger
Inventory plus playbooks. The shell history is not the record.
[ essay ]
Ansible is SSH with a YAML ledger: an inventory of hosts, playbooks of desired state, modules that should be idempotent if you wrote them that way. I have run playbooks as a user on machines I did not name. I do not run Ansible against Dark Heart Labs. The writing laptop is Fedora I rebuild by hand. Pages has no SSH. There is no inventory file for a studio this small.
The ledger is the point. A shell history is not repeatable. A playbook claims this package, this file, this service started, and you can read that claim in git.1 You can diff it. The transport is still SSH, which is why people who hated agents liked it, and why a bad key still ruins the evening. Idempotence is a promise of the module, not a law of YAML. I have watched a playbook “succeed” while the box drifted because a task was a raw command in a loop.
Use Ansible when you have more than a handful of boxes you refuse to click through. Skip it when the estate is a workstation and a PaaS. SSH with a ledger beats SSH with folklore. It does not beat “I do not have a fleet.” I read the inventory docs so I can talk to people who do. I still patch this laptop like a laptop.
— JV · Dark Heart Labs.
References
-
Ansible Docs, “Working with playbooks,” https://docs.ansible.com/ansible/latest/playbook_guide/playbooks_intro.html. YAML plays as the recorded desired state, pushed over SSH rather than left in a shell history. ↩