Lesson 8 / 26

Check Mode and Diff

Preview what a playbook would change before applying it.

Look before you leap

--check (dry run) tells you which tasks would change something without changing it, and --diff shows the exact before/after for files and templates. Run both before touching production. Not every module supports check mode and some tasks depend on earlier changes, so treat it as a strong preview, not a perfect guarantee.

Detecting drift, run

I appended a stray line port=1 to web1.conf by hand, then ran with --check --diff. Ansible shows it would remove that line (-port=1) and reports web1 as changed=1 while web2 is unchanged.

ansible-playbook -i inventory.ini site.yml --check --diff

Output:

--- before: .../out/web1.conf
+++ after: .../app.conf.j2
-port=1
web1                       : ok=3    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0
web2                       : ok=1    changed=0    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0

Syntax check

Run this first in CI. It parses the playbook without contacting any host.

ansible-playbook -i inventory.ini site.yml --syntax-check

Output:

playbook: site.yml

Quick check: What does `--check --diff` do?

  • Encrypts the playbook
  • Deletes the target files
  • Shows what would change without changing it
  • Uploads logs to a server
Answer

Shows what would change without changing it — Check mode simulates the run and diff displays the differences.