# Revision: Cheat Sheet and Self-Check — Ansible: Automate Servers with Playbooks

Source: https://www.geekswithgeeks.com/en/ansible/wrap-revision

> Review the commands, concepts and production habits from the whole course.

## Cheat sheet

**Core**: agentless over SSH; control node; inventory + groups; playbook → plays → tasks → modules; idempotent. **Commands**: `ansible -m ping`, `ansible-inventory --graph`, `ansible-playbook` with `--check --diff`, `--syntax-check`, `--tags`, `--limit`, `-e`, `-v`; `ansible-doc`, `ansible-galaxy`, `ansible-vault`. **Data**: variables (precedence, `-e` wins), facts via `setup`, Jinja2 templates with filters, `group_vars`/`host_vars`. **Logic**: `loop`, `when`, `register`, `handlers` (notify on change), tags, `block/rescue`. **Reuse**: roles, collections, `requirements.yml`, import vs include. **Security**: Vault, `no_log`, least privilege `become`. **Production**: lint + Molecule, dynamic inventory, `serial`, canary, controller (AWX/AAP).

## Questions interviewers ask

Be ready to explain: what idempotency is and how `command` breaks it, how handlers work, variable precedence, the difference between roles and collections, how you would keep secrets safe, and how you would roll out a risky change to 200 servers.

**Quiz:** A task using `shell: apt install nginx` shows changed on every run. What is the best fix?

- [x] Use the apt module with state: present
- [ ] Add more shell commands
- [ ] Ignore the output
- [ ] Run it twice

*Answer:* Use the apt module with state: present. A purpose-built module is idempotent and reports changed only when it installs something.

**Quiz:** Which command previews file changes without applying them?

- [ ] ansible-doc copy
- [ ] ansible-vault encrypt
- [ ] ansible-galaxy role init
- [x] ansible-playbook site.yml --check --diff

*Answer:* ansible-playbook site.yml --check --diff. Check mode simulates and diff displays what would be modified.

**Quiz:** You must update 200 web servers with minimal risk. What is the best approach?

- [ ] Update all 200 simultaneously
- [x] Canary one host, then serial batches with health checks and a failure threshold
- [ ] Skip testing
- [ ] Do it manually over SSH

*Answer:* Canary one host, then serial batches with health checks and a failure threshold. Gradual rollout limits the impact of a bad change and gives time to detect and stop it.
