What Ansible is and how it works
Ansible is a free, open-source automation tool, backed by Red Hat. From one control node it connects to the machines it manages over SSH, with no agent to install on them, runs small programs called modules to bring each machine to the state you described, and reports what it changed.
The idea
You describe the state you want, for example 'this package is installed, this file has this content, this service is running', and Ansible makes it so on ten machines or a thousand. You write that description once, keep it in Git, and run it as often as you like. It replaces long manual runbooks and one-off scripts that only their author understands.
Control node and managed nodes
Agentless: what that means
Many automation tools need an agent, a program running on every server and talking to a central server. Ansible does not. For each task it connects over SSH, copies a small module across, runs it, reads the JSON result and removes it. There is nothing extra to install, patch or monitor on the managed nodes, and an SSH connection is something most teams already have and already secure.
Push, and describe the end state
- Push: you run Ansible from the control node when you choose: by hand, from a pipeline, or on a schedule.
- Declarative: most tasks say *what* should be true ('package nginx: present'), not the commands to get there. Ansible checks first, and acts only if something differs.
- YAML: inventories and playbooks are plain text files in YAML, so they can be reviewed in pull requests like code.
What does Ansible use to connect to Linux and z/OS managed nodes? (one word or abbreviation)
Show a hint
The same protocol you use to log on to a server remotely.
Show the solution
SSH.
Common mistakes
Ansible is agentless. It needs SSH access and, for most modules, Python on the managed node.
Its strength is describing the end state with modules. Long lists of shell commands lose most of the benefits.
Production runs belong in a controlled place, such as a pipeline or Automation Platform, with logs and approvals.
What you will see at work
- Teams use Ansible to build servers, deploy applications, apply configuration and run routine operations the same way every time.
- Jenkins often calls Ansible in its deploy stage: Jenkins orchestrates the pipeline and Ansible does the deployment work.
- Mainframe teams use Ansible for z/OS through IBM's certified collections, covered in the last lesson.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.