Lesson 26 / 26

Revision: Cheat Sheet and Self-Check

Review the commands, concepts and production habits from the whole course.

Cheat sheet

Core: agentless over SSH; control node; inventory + groups; playbook → plays → tasks → modules; idempotent. Commands: ansible -m ping, ansible-inventory --graph, ansible-playbook with --check --diff, --syntax-check, --tags, --limit, -e, -v; ansible-doc, ansible-galaxy, ansible-vault. Data: variables (precedence, -e wins), facts via setup, Jinja2 templates with filters, group_vars/host_vars. Logic: loop, when, register, handlers (notify on change), tags, block/rescue. Reuse: roles, collections, requirements.yml, import vs include. Security: Vault, no_log, least privilege become. Production: lint + Molecule, dynamic inventory, serial, canary, controller (AWX/AAP).

Questions interviewers ask

Be ready to explain: what idempotency is and how command breaks it, how handlers work, variable precedence, the difference between roles and collections, how you would keep secrets safe, and how you would roll out a risky change to 200 servers.

Quick check: A task using `shell: apt install nginx` shows changed on every run. What is the best fix?

  • Use the apt module with state: present
  • Add more shell commands
  • Ignore the output
  • Run it twice
Answer

Use the apt module with state: present — A purpose-built module is idempotent and reports changed only when it installs something.

Quick check: Which command previews file changes without applying them?

  • ansible-doc copy
  • ansible-vault encrypt
  • ansible-galaxy role init
  • ansible-playbook site.yml --check --diff
Answer

ansible-playbook site.yml --check --diff — Check mode simulates and diff displays what would be modified.

Quick check: You must update 200 web servers with minimal risk. What is the best approach?

  • Update all 200 simultaneously
  • Canary one host, then serial batches with health checks and a failure threshold
  • Skip testing
  • Do it manually over SSH
Answer

Canary one host, then serial batches with health checks and a failure threshold — Gradual rollout limits the impact of a bad change and gives time to detect and stop it.