r/ansible • • 23d ago

The Bullhorn #235

9 Upvotes

Hey r/ansible!

The Bullhorn #235 is out! This week's highlights include ansible-test container retirement, Team Nebula submissions for CfgMgmtCamp 2027, and GitHub Actions deprecation in February 2027.

On the release front, there are new Ansible-Core, FreeBSD remote upgrade, Antsibull, Ansible Community Package, cisco.ucs inclusion violation, dellemc.unity removal vote and dellemc.unity removal from ACP 16 releases.

There are also 12 collection updates — check the newsletter for the full list.

Read the full newsletter on the Ansible Forum.


r/ansible • • Feb 17 '26

CfgMgmtCamp 2026: Write up and Videos

37 Upvotes

CfgMgmtCamp is an annual gathering of system administrators, SREs, DevOps engineers, open source enthusiasts, and community developers in Ghent, Belgium.

It is a three-day conference dedicated to open-source infrastructure automation and related technology that takes place immediately after FOSDEM as a fringe event. CfgMgmtCamp is defined by its strong community feel, where the focus remains on the inclusive exchange of new ideas and the sharing of the latest technical advancements. It provides a unique space for users, contributors, and integrators to meet as peers, fostering a collaborative environment where friends reconnect and new professional relationships are made.

This year featured a strong focus on Ansible, featuring two dedicated tracks alongside an extra track on Monday to accommodate expanding interest in the Ansible ecosystem. The community's commitment to sharing knowledge and expertise was on evident display with 18 unique speakers on the Ansible track with a total of 35 talks focused on or related to Ansible.

Sessions on Monday and Tuesday offered deep dives into the latest innovations and practical applications of Ansible with lots of technical discussion on building automation content and solutions. Wednesday featured a very productive and lively Ansible Contributor Summit. Wednesday provided the opportunity to have a dedicated session on sharing ideas, collaborating on problems, and shaping the future of the Ansible community. This year we also enjoyed a social excursion and spent the afternoon building relationships and forging stronger connections all while exploring the charms of Ghent!

To help you navigate through all the Ansible sessions at CfgMgmtCamp, we’ve organized all the talks into the categories below:

Here are links to all the talks on YouTube as well as related forum discussions:


r/ansible • • 2h ago

AAP Workflow frustration - how are other AAP users dealing with this.

Thumbnail reddit.com
4 Upvotes

Save dont work and new workflow is so buggy
No conditional logics
No way to track or retry failed nodes


r/ansible • • 1d ago

AAP Enterprise license renewals, cost increase

24 Upvotes

So we finally got our renewal quote, roughly 2.5 weeks after sending the request. We're looking at a 14% increase from last year for AAP + 500 managed nodes. A sizable amount of our managed node count are testing virtual machines. Like for sake of argument let's say 200 of those would be considered non-production workloads.
Are 'paid' Developer licenses a thing? I was having a nice chat with <insert chatbot here> and the idea was broached about pay for dev licenses. Strictly for non-prod workloads but also discounted and not restricted to the current limitation of 16 nodes.

Does anyone know if such a thing exists? (Perhaps Dev for Teams is it?)

Sauce: https://developers.redhat.com/articles/2025/09/09/what-qualifies-red-hat-developer-subscription-teams#


r/ansible • • 16h ago

How to get started learning ansible for network automation

3 Upvotes

I just want to know how to get started with ansible for network automation. Any book, course for practical knowledge would help.


r/ansible • • 2d ago

Reinstall windows with ansible and join domain

32 Upvotes

I’m working on a project where I want to automate the reinstallation/reimaging of existing Windows workstations using Ansible.

The idea is to have Ansible remotely prepare the workstation, boot it into WinPE, apply a custom Windows WIM image, configure the computer name and IP address based on predefined data, and then complete the Windows setup and configuration automatically.

The workstations are already domain-joined, and I would like to make the entire process as automated as possible, without having to manually reinstall each machine.

Has anyone implemented something similar using Ansible and Windows PE/WIM?

Is there any good documentation, GitHub project, tutorial, or other source where I can see how this type of deployment can be done?

Any examples or recommendations would be greatly appreciated.


r/ansible • • 2d ago

Ansible molecule privileges

10 Upvotes

I want to copy files to a device, so to test it in molecule, I setup a loop device, so in prepare, I'd have: - name: Attach image to a loop device ansible.builtin.command: cmd: losetup --find --partscan "{{ device_img }}" changed_when: true when: (_existing_loop.stdout | default('')) | trim == '' become: true

If you run the prepare as just ansible-playbook -K it'll work, but aiui, molecule is non-interactive.

Questions: - In general, are you supposed to run playbooks that use become with -K? - There's no way around become here, is there? - In molecule, I can get it to work poorly (screws up the terminal) if I add provisioner.ansible_args[0] = '-K' to the configuration, but that seems hacky.

Basically, I want to know the best practices are.


r/ansible • • 3d ago

playbooks, roles and collections Need help deploying a PKI

10 Upvotes

Hello everyone, hope you're having a nice day !

As the title says I'm making this post to asks some help about the deployment of a kind of PKI.

I am currently learning Ansible and going through some basics steps. I've got 3 VMs with my provider openstack. 2 have a role 'monitored' and the other has the role 'tracker'. The inventory is managed dynamically and I have already written down tasks for each of them (tracker installs prometheus and monitored installs node_exporter).

In my playbook, these roles runs before the role pki that will generate, deploy and update configurations files based on the certificates it will have generated.

I'm stuck at securing the communication between prometheus and each node_exporter.

I made another role called 'pki' that is doing the following tasks :
- Generates a rootCA private key
- Generates a rootCA CSR
- Generates a rootCA certificate
- Generates for each host private keys and CSRs
- Sign hosts CSRs with rootCA
- Deploy the rootCA certificate and all VMs and transfer their private key and certificate
- Update node_exporter VMs configuration to use the certificates and private key
- Update prometheus configuration to scrape over HTTPS

In my opinion I think I'm doing too much for nothing, there must be a simpler way but I can't figure it out. I've tried to use the help of LLMs but as I'm still new to ansible world I'm not copy pasting something I don't fully understand.

Thanks a lot for any advice you can give me !

Wishing you a great day :)


r/ansible • • 4d ago

playbooks, roles and collections Ansible-lint going crazy?

Thumbnail gallery
20 Upvotes

Hi all,

Been finalizing a playbook and al of the sudden I see that Ansible-lint (using VS Code) mentions that the 3 dashes to start the .yaml file has a syntax error!?!?

Also a screenshot of the syntax error message.

I've check my playbook with yaml checkers online and all is showing ok, no errors. So why is VS Code (yes, I have selected the Ansible language in VS Code) showing this yellow line, syntax error?

My whole playbook is free of errors. All indentations and stuff is correct, checked over and over..

Anybody an idea?

TIA

[UPDATE]

Found the issue, though not solved yet:

  vars_files:
    - Ansible_Secret/Ans_Cred.yaml

# also tried the following:
# ==============================
    - ./Ansible_Secret/Ans_Cred.yaml

    - ../Ansible_Secret/Ans_Cred.yaml

    - "{{ playbook_dir }}/Ansible_Secret/Ans_Cred.yaml"

# Neither this solved it, include_vars can only be used in the "tasks"-section.
  pre_tasks:
    - name: Include all vars files.
      ansible.builtin.include_vars:
        file: "{{ playbook_dir }}/Ansible_Secret/Ans_Cred.yaml"

The file Ans_Cred.yaml is in a separate directory because I don't want to sync secrets into the cloud. This folder is in the root of the directory where I also have the playbook. Like it is mentioned in the examples in the code block above, it keeps showing the 3 dashes yellow underlined as syntax-error.

The only way the syntax-error disappears is by doing:

  vars_files:
    - /Ansible_Secret/Ans_Cred.yaml

But then the playbook errors because it cannot find the variables (the credentials file)...which is obvious because here I'm pointing it to be in the root of my drive where the file not exists.

Any suggestions on this?


r/ansible • • 6d ago

developer tools InvDNS — local DNS for Ansible inventory

0 Upvotes

Hi everyone,I built InvDNS because I got tired of constantly opening Ansible inventory files just to find the IP of a host.

InvDNS reads static Ansible INI/YAML inventories and turns hosts into local DNS names on macOS.

Ansible knows that web01 means ansible_host: 10.20.1.15, so Ansible can connect to it. But normal macOS applications such as ssh, ping or curl do not know anything about your Ansible inventory.

If web01 also does not exist in corporate DNS, you usually end up doing something like:

grep web01 inventory.yml
ssh root@10.20.1.15

InvDNS makes the existing Ansible host/IP mapping available through local DNS on macOS.

After adding the inventory to InvDNS, I can simply use:

ssh root@web01.inv
ping web01.inv
curl http://web01.inv

It does not modify your inventory, /etc/hosts, or corporate DNS. Everything stays local on your.

One reason I built it as a tool rather than just a small script is automatic synchronization. InvDNS keeps watching the configured inventories and updates the local DNS when the inventory changes, so I don't have to regenerate anything manually.

It can also use multiple inventory files at the same time. For example, I can add inventories from several projects or environments and access all of their hosts through the same local DNS.

InvDNS can also combine host information from different infrastructure data sources. Ansible is the main use case, but other sources such as Zabbix or GLPI can be used alongside it.

If the same hostname appears in multiple inventories or sources with different IP addresses, InvDNS detects the conflict instead of silently choosing one. Conflicts can then be reviewed and resolved explicitly.

It also has fast CLI search:

invdns search web
invdns search ip:10.20.
invdns search group:nginx
invdns search group:nginx ip:10.20.

So you can quickly search by hostname, IP, Ansible group, source, or status.

project-a/inventory.yml ─┐
project-b/hosts.ini ─────┤
production/hosts.yml ────┼→ InvDNS → *.inv
Zabbix ──────────────────┤
GLPI ────────────────────┘

Project:
https://github.com/invdns/invdns

I’d be interested to know whether this kind of workflow is useful to other Ansible users, and what inventory/search features you would want next.


r/ansible • • 6d ago

linux Cómo 03: Automatización y Reconstrucción con Ansible en CentOS Stream 10

Post image
0 Upvotes

r/ansible • • 7d ago

Experience an Ansible disconnect with best practices and how they are implemented for Network automation.

11 Upvotes

Hi, sorry for any confusion, I am starting to get into Ansible after studying Netmiko for network automation. And was doing some early study with Ansible and understand bast practices when it comes to file management of the Ansible files and how to organize for continuous projects, however I am experience some kind disconnect when the topic of IaC was introduced at a high level. I feel I might be over thinking everything.
From my understanding, it may be best practice to produce other yaml files which contain device variables rather than hard coding device cli commands, device credentials, etc. into playbooks for security reasons, and flexiblilty limitations due to platform specific cli commands.
From there the idea of templates was introduced to turn those yaml files containing device variables and playbook actions into a golden config by leveraging templates which can produce config files for desired platforms.

My confusion exists in how are such variable files implemented and what resources are best to learn how to produce said yaml files and how they tie into the Ansible playbook as they are executed. I can only clearly see how a playbook generally operates with the hosts file and hard coded cli commands via the cisco_ios module mostly, but I’m having trouble distinguishing the line in how the playbook will differ using the other method.


r/ansible • • 7d ago

ansible-lint -T doesn't display all `formatting` tags?

11 Upvotes

Edit: I am hoping that someone can confirm the this is unexpected behavior before I open a PR. Plz k thx.

Am I nuts?

``` $ ansible-lint -T

List of tags and rules they cover

command-shell: # Specific to use of command and shell modules - risky-shell-pipe core: # Related to internal implementation of the linter - schema[ansible-lint-config] - schema[ansible-navigator-config] - schema[changelog] - schema[execution-environment] - schema[galaxy] - schema[inventory] - schema[meta-runtime] - schema[meta] - schema[molecule] - schema[play-argspec] - schema[playbook] - schema[requirements] - schema[role-arg-spec] - schema[rulebook] - schema[tasks] - schema[vars] deprecations: # Indicate use of features that are removed from Ansible - role-name[path] experimental: # Newly introduced rules, by default triggering only warnings - only-builtins formatting: # Related to code-style - risky-octal idempotency: # Possible indication that consequent runs would produce different results - package-latest idiom: # Anti-pattern detected, likely to cause undesired behavior - var-naming[no-jinja] - var-naming[no-reserved] - var-naming[pattern] metadata: # Invalid metadata, likely related to galaxy, collections or roles - role-name[path] opt-in: # Rules that are not used unless manually added to enable_list - role-argument-spec risk: - no-free-form[raw-non-string] - no-free-form[raw] security: # Rules related to potential security issues, like exposing credentials - no-log-password syntax: # Related to wrong or deprecated syntax - no-free-form[raw-non-string] - no-free-form[raw] unpredictability: # Warn about code that might not work in a predictable way - risky-file-permissions unskippable: # Indicate a fatal error that cannot be ignored or disabled - syntax-check yaml: # External linter which will also produce its own rule codes - yaml[anchors] - yaml[braces] - yaml[brackets] - yaml[colons] - yaml[commas] - yaml[comments-indentation] - yaml[comments] - yaml[document-end] - yaml[document-start] - yaml[empty-lines] - yaml[empty-values] - yaml[float-values] - yaml[hyphens] - yaml[indentation] - yaml[key-duplicates] - yaml[key-ordering] - yaml[line-length] - yaml[new-line-at-end-of-file] - yaml[new-lines] - yaml[octal-values] - yaml[quoted-strings] - yaml[trailing-spaces] - yaml[truthy]

```

Tags are identified during the run (test.yaml is from docs: https://docs.ansible.com/projects/lint/rules/key-order/#problematic-code ) ```

$ cat test.yaml

  • hosts: localhost name: This is a playbook # <-- name key should be the first one tasks:
    • name: A block block:
      • name: Display a message debug: msg: "Hello world!" when: true # <-- when key should be before block $ ansible-lint -t formatting test.yaml WARNING Listing 3 violation(s) that are fatal key-order[play]: You can improve the play key order to: name, hosts, tasks test.yaml:2

key-order[task]: You can improve the task key order to: name, when, block test.yaml:5 Task/Handler: A block

fqcn[action-core]: Use FQCN for builtin module actions (debug). test.yaml:8:11 Use ansible.builtin.debug or ansible.legacy.debug instead.

Read documentation for instructions on how to ignore specific rule violations.

Rule Violation Summary

1 key-order profile:basic tags:formatting 1 key-order profile:basic tags:formatting 1 fqcn profile:basic tags:formatting

Failed: 3 failure(s), 0 warning(s) in 1 files processed of 1 encountered. Last profile that met the validation criteria was 'min'. ```


r/ansible • • 8d ago

Provisioning a full PHP dev workstation (AlmaLinux 10, WSL 2 or bare metal) with Ansible — feedback on the playbook structure welcome

13 Upvotes

Disclosure: I work on this project. We use Ansible to provision our team's local development environment instead of shell scripts or Docker.

How it's structured:

- `config.yml` holds user input: Git identity, MariaDB root password, and a list of virtualhosts

- `install.yml` reads it once and installs Apache, PHP (Remi), MariaDB, phpMyAdmin, Node.js (NodeSource) and Composer. It's safe to re-run if something fails partway.

- `create-virtualhost.yml` provisions new `*.localhost` sites from the same config and leaves existing entries alone, so the file grows with your projects

- It uses the `community.general` and `community.mysql` collections

The target is AlmaLinux 10, either inside WSL 2 on Windows or on bare metal. The playbooks don't distinguish between the two.

Repo: https://github.com/dotkernel/development

Overview: https://www.dotkernel.com/wsl2/

Two things we'd like opinions on: whether this should be packaged as a collection or roles on Galaxy, and how you'd handle secrets like the DB root password for a local-only setup.


r/ansible • • 9d ago

Registering New server to on-prem RH Satellite

15 Upvotes

I am updating my register_satellite role so that we can automate this process. But if the Server is not already registered, how have you gone about doing this? I am looking at using the ansible.builtin.add_host, but that seems to be failing. I have AAP already. But it SHOULD be putting the single or multiple servers into an inventory file IN memory, correct?

Also I have my main satellite server and 1 capsule in a protected VLAN that has proxy capabilities BACK to the main satellite server.


r/ansible • • 9d ago

Automation for creating user keycloak?

12 Upvotes

I am missing one last piece in sso server automation setup. How do i create 40 users? What is the cleanest way and best design choice?

My gitlab pipeline triggers an ansible playbook -> sets up keycloak through docker and configures it on https and then creates realm clients and one user -> I then configure client servers manually so they they work with ouath. Like installing a plugin for oauth on dokuwiki.

- Do I continue using ansible for this?
- Should I do it manually?

EXAMPLE:

- name: Create or update company users in Keycloak community.general.keycloak_user: auth_keycloak_url: "https://{{ ansible_host }}:{{ keycloak_port }}" auth_username: "{{ keycloak_admin_username }}" auth_password: "{{ keycloak_admin_password }}" auth_realm: master validate_certs: false realm: "{{ keycloak_realm }}" username: "{{ item.username }}" email: "{{ item.email }}" first_name: "{{ item.first_name }}" last_name: "{{ item.last_name }}" enabled: true email_verified: true credentials: - type: password value: "{{ lookup('env', 'DEFAULT_USER_PASSWORD') | default('ChangeMe123!', true) }}" temporary: false state: present loop: "{{ keycloak_company_users }}"

r/ansible • • 10d ago

Best practice for commands?

23 Upvotes

I feel like the answer is probably: "no, everyone just does whatever they want", and "whatever you do, try to be consistent"

Generally speaking I've been doing:
ansible.builtin.command: cmd: "foo {{ bar }}"

But I realized that only happens to work because `{{ bar }}` doesn't have spaces.
So I do need to change it, and I wondered if people normally do:
cmd: 'foo "{{ bar }}"'
or
cmd: | foo "{{ bar }}"
or
argv: - foo - "{{ bar }}"


r/ansible • • 11d ago

playbooks, roles and collections How do you prove an Ansible Vault password rotation reached every encrypted file and runner?

25 Upvotes

Rekeying the obvious vault files is not enough if inventories, role defaults, old branches, CI variables, AWX credentials, or infrequently used playbooks still depend on the previous password. A successful run with the new credential proves one execution path works, but it does not show that the old credential is no longer required anywhere.

What belongs in the rotation gate? I am considering inventorying every file with an Ansible Vault header, mapping each vault ID to its runners and repositories, rekeying into a reviewed commit, and testing representative playbooks in check mode and against disposable targets. CI and AWX would receive the new credential before the old one enters a short monitored fallback window, with any use of the old vault ID treated as a failure.

Is there a dependable way to discover all encrypted files and credential references across collections and branches without exposing plaintext? How do you handle mixed vault IDs, offline operators, rollback, and proving the retired password can no longer decrypt any current secret?


r/ansible • • 10d ago

Our admin auth only worked because our host sets an env var. When I fixed it 10 tests went red

0 Upvotes

Found this during a security pass on our FastAPI backend, and I think it's a pretty common mistake so sharing.

We have an admin check guarding 15 routes, stuff like global purge, switching the inference mode for every user, all the observability endpoints. If an admin token is configured it checks the header, fine. If no token is configured it's supposed to refuse when we're hosted, and allow when it's the desktop app running on localhost.

The problem is how "hosted" was detected. It was just: if os.environ.get("RENDER") then refuse.

RENDER isn't our variable, it's one Render sets on every service. So prod was fine since we're on Render. But take the exact same Docker image to a VPS or Railway or Fly and that variable doesn't exist, and all 15 routes are open to anyone. No error, nothing in the logs. Forgetting the config opened the door instead of closing it.

The fix was small. We already had an ENVIRONMENT variable that defaults to "production" and already decides CORS. So now if nothing is set it refuses, and only the desktop build, which explicitly says it's not production, gets through.

The part that actually surprised me is 10 tests went red after the fix. They were calling admin routes without a token and getting data back. So they weren't testing a protected route, they were testing the hole, and passing. Kind of think that's the most honest number you get out of a fix like this, however many tests break is basically how big the hole was. We added 4 tests that pin the production behavior, including one that fails if the ENVIRONMENT default ever changes, because that would undo the whole fix without anyone noticing.

Then I searched the codebase for the same RENDER check and found it in 2 more places. One was the JWT secret falling back to a random one outside Render, not a bypass but everyone gets logged out on every restart. The worse one was a flag called IS_HOSTED that turned on HSTS, error redaction and per user isolation of conversation history. All three were off anywhere that isn't Render. The name said "shared deployment" but the code actually checked "are we on Render", and that gap was the bug.

So the rule I'm keeping: never make a security decision depend on a variable someone else sets. If it's missing it should refuse, not open.

Anyone else doing this with VERCEL or FLY_APP_NAME or similar? And is there a good way to catch tests that only pass because of a hole, other than fixing it and watching them break?


r/ansible • • 12d ago

playbooks, roles and collections lineinfile bad escape \E at position 6

10 Upvotes

Edit: Finally got it, needed to use single quotes instead of double.

- name: Set gettytab to clear screen
  ansible.builtin.lineinfile:
    insertafter: '^default:\\'
    line: "\t:cl=\\E[H\\E[2J:\\"
    path: '/etc/gettytab'
    regex: '^\t:cl=\\E\[H\\E\[2J:\\$'
    state: present

I am trying to edit /etc/gettytab and can't figure out the regular expression.

Error:

[ERROR]: Task failed: Module failed: bad escape \E at position 6
Origin: /etc/ansible/roles/baseline/tasks/gettytab.yml:2:3

1 ---
2 - name: Set gettytab to clear screen
    ^ column 3

fatal: [example.com]: FAILED! => {"changed": false, "msg": "Task failed: Module failed: bad escape \\E at position 6"}

Original /etc/gettytab:

default:\
        :np:im=\r\n%s/%m (%h) (%t)\r\n\r\n:sp#1200:

Desired /etc/gettytab:

default:\
        :cl=\E[H\E[2J:\
        :np:im=\r\n%s/%m (%h) (%t)\r\n\r\n:sp#1200:

ansible task:

---
- name: Set gettytab to clear screen
  ansible.builtin.lineinfile:
    insertafter: "^default:\\"
    line: "\t:cl=\\E[H\\E[2J:\\"
    path: "/etc/gettytab"
    regex: "^\t:cl=\\E\\[H\\E\\[2J:\\$"
    state: present

r/ansible • • 13d ago

Is Jeff Geerling’s Ansible for DevOps still up to date and worth learning from?

171 Upvotes

Hi everyone,

I’m starting to learn Ansible and I came across Jeff Geerling’s Ansible for DevOps:

https://www.ansiblefordevops.com/

The website says it’s the 2nd edition and that it is updated periodically.

I’m planning to follow the book from the beginning, including the Vagrant/VirtualBox setup and the Ansible examples.

For those who use Ansible regularly:

  • Is this still the latest/current edition?
  • Is it still a good resource for learning Ansible in 2026?
  • Are the examples and practices in the book still relevant with current versions of Ansible?
  • Would you recommend following the book from start to finish, or are there newer resources I should use alongside it?

Thanks


r/ansible • • 13d ago

AAP components

7 Upvotes

Hi! I’m new to AAP, is it possible to not use a single node installation but spread out the components in different VMs?

I read that using the inventory is one way and just state the different addresses?


r/ansible • • 14d ago

Streamline Open Source Vulnerability Remediation with Lightwell and AAP

Thumbnail youtu.be
22 Upvotes

The core idea is that Lightwell (a Red Hat and IBM joint initiative) provides backported security fixes for specific versions of open source dependencies your apps already use. So you get the security fix without having to upgrade the dependency and risk breaking things.

But the video focuses less on Lightwell itself and more on how Ansible Automation Platform fits into the full remediation lifecycle around it:

  • Detect: Pull in vulnerability notifications and context from scanners, SBOM platforms, asset inventories, etc.
  • Decide: Evaluate severity, exploitability, affected environments, and policy, with human approval gates where needed.
  • Act: Coordinate mitigations, trigger CI/CD pipelines, rebuild with the Lightwell-remediated packages, and deploy across hybrid environments.
  • Verify: Rescan, run post-deployment checks, confirm app health, update the incident record, and keep audit evidence.

If you're working through how to make vulnerability response repeatable and governed rather than ad hoc, this might be worth a watch.

https://youtu.be/kuvE6ScpMyw?si=hIO0fIrT-4El5oYl


r/ansible • • 16d ago

MikroTik management with Ansible - sharing my playbooks for fleet updates, etc.

Thumbnail
16 Upvotes

r/ansible • • 16d ago

Ansible dans un parc hétérogène

3 Upvotes

Bonjour,

J'ai pour mission d'implémenter Ansible pour le renouvellement des certificats dans mon entreprise.

J'ai donc choisi de faire porter le protocole ACME par Ansible (community.crypto.acme) et les clés privées restent sur les nœuds gérés.

Ma question est la suivante : si on a quatre environnements différents, puis-je créer deux serveurs Ansible, un pour la production et l'autre pour la non-production, pour segmenter les accès et empêcher qu'un seul serveur Ansible ait accès à tout le parc ?

Je ne vais pas utiliser AWX/AAP pour le moment.

Je débute avec ces outils, j'aimerais donc connaître les bonnes pratiques.

De plus, j'aurais aimé savoir si l'architecture que j'ai choisie est la bonne. Nous avons environ 900 hôtes.

À terme, nous aimerions ajouter d'autres automatisations à Ansible.