Run Ansible like a Chef
How to run Ansible playbooks automatically on managed hosts using an agent and a systemd timer.
Read articleReliable Linux, open-source and cloud solutions to support everyday business operations.
Service overviewConsulting in product management, business management and development, with specialist support for the gambling industry.
Service overviewReliable Linux, open-source and cloud solutions to support everyday business operations.
Linux and open-source systems are configured and managed alongside commercial software where needed. Tool selection, monitoring and backups are tailored to business requirements.
System administration and software deployment are automated using tools such as Ansible and Salt. Repetitive manual work is reduced, making changes more consistent and easier to manage.
Cloud solutions are selected, configured and managed to suit business needs, including services from AWS and DigitalOcean. Support is also available for building and maintaining private cloud infrastructure.
Technical knowledge, management experience and an understanding of regulated markets are combined in the consulting approach.
Support is provided in shaping product strategy, understanding user needs and setting development priorities. Product development is guided across industries, from initial concept to market launch and ongoing improvement.
Advice is provided on setting objectives, developing business models and improving operations. Change implementation and collaboration between business and technology teams are supported.
Support is provided in incorporating regulatory requirements into product design, technology and operational processes. The team’s experience covers technical compliance, regulated markets, responsible gaming, regulatory affairs and standardisation.
How to run Ansible playbooks automatically on managed hosts using an agent and a systemd timer.
Read articleWhile Ansible is my main tool, i liked also Chef. Now i will try to set up Ansible as Chef - running playbooks completely unattended on managed nodes. I setup Ansible environment so that execution is regular and without need for gui server (AWX) or central service with root access to every machine.
To get this working, i set up Ansible in two parts:
Master contains:
Agent part contains all the playbooks running in managed host.
Agent code is in git repository and will be pulled when running master Ansible playbook in master repository. This could be done also automatically, but whis way i have a bit more control over process. In master i take all host variables from variable host_vars[hostname] and clean it up with filter_plugins/clean.py. Not sure if this is needed, but it won’t hurt.
In agent we save all variables to host_vars/hostname.yml file. This file will contain also unencrypted secrets. That should not be a big problem as those secrets will be saved unencrypted to some other part of filesystem anyway. Those variables will then used in every run as settings for playbooks running in agent.
Agent runs everything as systemd service that is triggered by systemd timer. This way all logs go to systemd journal.
Example code for Ansible agent is here: https://github.com/ljesmin/ansible_example, it contains just couple of roles for setting up sudo and users.
Example code for Ansible master is here: https://github.com/ljesmin/ansible_master
Agent setup in example is written for Ubuntu Bionic.