skip to content

Ansible

Agentless configuration management over SSH: inventories of hosts, playbooks of idempotent tasks, roles for reuse, and Vault for secrets. Interviewers position it against Terraform — provisioning the box versus configuring what runs on it.

on this pageshow

questions

page 2 of 2

In Ansible, what do the host patterns `webservers:&staging` and `webservers:!decommissioned` select, and how does `--limit` interact with a play's `hosts:` line?

level: seniorimportance: nice to knowfreq 42%

basics

~20 s

The first selects hosts in both webservers and staging (intersection); the second selects hosts in webservers that are not in decommissioned (exclusion). --limit narrows what the play's hosts line already matched — it intersects, and can never add hosts the play did not target.

open as a page

What does the dependencies list in an Ansible role's meta/main.yml do, and how does Ansible handle the same dependency being pulled in by several roles?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

The dependencies list in a role's meta/main.yml names roles Ansible applies before the role itself. Within one play a dependency runs only once for a given set of parameters, unless its own meta/main.yml sets allow_duplicates: true.

open as a page

A CLI-driven operation is repeated across many of your Ansible roles as a shell task. How do you decide whether to leave it, wrap it in a role, or invest in a custom module?

level: principalimportance: nice to knowfreq 22%

basics

~20 s

Decide on repetition, idempotency and blast radius. Search for an existing module in a maintained collection first; wrap in a role when the shell-out is rare and guardable; write a module when the operation is widespread, needs honest changed reporting and check mode, and someone will own it.

open as a page

showing 31–33 of 33