Lesson 8 / 26
Check Mode and Diff
Preview what a playbook would change before applying it.
Look before you leap
--check (dry run) tells you which tasks would change something without changing it, and --diff shows the exact before/after for files and templates. Run both before touching production. Not every module supports check mode and some tasks depend on earlier changes, so treat it as a strong preview, not a perfect guarantee.
Detecting drift, run
I appended a stray line port=1 to web1.conf by hand, then ran with --check --diff. Ansible shows it would remove that line (-port=1) and reports web1 as changed=1 while web2 is unchanged.
ansible-playbook -i inventory.ini site.yml --check --diff
Output:
--- before: .../out/web1.conf +++ after: .../app.conf.j2 -port=1 web1 : ok=3 changed=1 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 web2 : ok=1 changed=0 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0
Syntax check
Run this first in CI. It parses the playbook without contacting any host.
ansible-playbook -i inventory.ini site.yml --syntax-check
Output:
playbook: site.yml
Quick check: What does `--check --diff` do?
- Encrypts the playbook
- Deletes the target files
- Shows what would change without changing it
- Uploads logs to a server
Answer
Shows what would change without changing it — Check mode simulates the run and diff displays the differences.