# Check Mode and Diff — Ansible: Automate Servers with Playbooks

Source: https://www.geekswithgeeks.com/en/ansible/pb-check-diff

> Preview what a playbook would change before applying it.

## Look before you leap

`--check` (dry run) tells you which tasks **would** change something without changing it, and `--diff` shows the exact before/after for files and templates. Run both before touching production. Not every module supports check mode and some tasks depend on earlier changes, so treat it as a strong preview, not a perfect guarantee.

## Detecting drift, run

I appended a stray line `port=1` to `web1.conf` by hand, then ran with `--check --diff`. Ansible shows it would remove that line (`-port=1`) and reports web1 as changed=1 while web2 is unchanged.

```bash
ansible-playbook -i inventory.ini site.yml --check --diff
```

Output:

```
--- before: .../out/web1.conf
+++ after: .../app.conf.j2
-port=1
web1                       : ok=3    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0
web2                       : ok=1    changed=0    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0
```

## Syntax check

Run this first in CI. It parses the playbook without contacting any host.

```bash
ansible-playbook -i inventory.ini site.yml --syntax-check
```

Output:

```
playbook: site.yml
```

**Quiz:** What does `--check --diff` do?

- [ ] Encrypts the playbook
- [ ] Deletes the target files
- [x] Shows what would change without changing it
- [ ] Uploads logs to a server

*Answer:* Shows what would change without changing it. Check mode simulates the run and diff displays the differences.
