Sign inSign up

jhidalgo3/ansible

By jhidalgo3

•Updated over 3 years ago

Image
0

960

jhidalgo3/ansible repository overview

⁠Ansible Playbook Docker Image

Source: https://github.com/jhidalgo3/docker-ansible-playbooks/⁠

Software installed

  • Ansible
  • boto3
  • Aws CLI v2

First step, create an inventory-docker file

[localhost]
127.0.0.1  ansible_connection=local

[localhost:vars]
ansible_python_interpreter=/usr/local/bin/python3

Executes ansible-playbook command against an externally mounted set of Ansible playbooks

docker run --rm -it -v PATH_TO_LOCAL_PLAYBOOKS_DIR:/ansible/playbooks jhidalgo3/ansible PLAYBOOK_FILE

For example, assuming your project's structure follows best practices⁠, the command to run ansible-playbook from the top-level directory would look like:

docker run --rm -it -v $(pwd):/ansible/playbooks jhidalgo3/ansible playbook.yml

Ansible playbook variables can simply be added after the playbook name.

RUN BASH

docker run --rm -it -v $(pwd):/ansible/playbooks --entry-point bash jhidalgo3/ansible playbook.yml

⁠SSH Keys

If Ansible is interacting with external machines, you'll need to mount an SSH key pair for the duration of the play:

docker run --rm -it \
    -v ~/.ssh/id_rsa:/root/.ssh/id_rsa \
    -v ~/.ssh/id_rsa.pub:/root/.ssh/id_rsa.pub \
    -v $(pwd):/ansible/playbooks \
    jhidalgo3/ansible_playbook site.yml -e @FILE_VARS.[json | yaml] -i inventary-docker

⁠Ansible Vault

If you've encrypted any data using Ansible Vault⁠, you can decrypt during a play by either passing --ask-vault-pass after the playbook name, or pointing to a password file. For the latter, you can mount an external file:

docker run --rm -it -v $(pwd):/ansible/playbooks \
    -v ~/.vault_pass.txt:/root/.vault_pass.txt \
    jhidalgo3/ansible_playbook site.yml --vault-password-file /root/.vault_pass.txt

Note: the Ansible Vault executable is embedded in this image. To use it, specify a different entrypoint:

docker run --rm -it -v $(pwd):/ansible/playbooks --entrypoint ansible-vault -v ~/.vault_pass.txt:/root/.vault_pass.txt jhidalgo3/ansible encrypt --vault-password-file /root/.vault_pass.txt FILENAME

⁠Testing Playbooks - Ansible Target Container

The Ansible Target Docker image⁠ is an SSH container optimized for testing Ansible playbooks.

First, define your inventory file.

[test]
ansible_target

Be sure your testing playbooks include the correct host and remote user:

- hosts: test
  remote_user: ubuntu

  tasks:
  ... tasks go here ...

When testing the playbook, you'll need to link the two containers:

docker run --rm -it \
    --link ansible_target \
    -v ~/.ssh/id_rsa:/root/.ssh/id_rsa \
    -v ~/.ssh/id_rsa.pub:/root/.ssh/id_rsa.pub \
    -v $(pwd):/ansible/playbooks \
    jhidalgo3/ansible tests.yml -i inventory

Note: the SSH key used above should match the one used to run Ansible Target.

⁠Docker Compose

An sample docker-compose.yml file is in this repo's test directory.

Example:

docker-compose run --rm test remote.yml -i inventory

And if you'd like the ansible_target container to be recreated each time, do:

docker rm -v -f ansible_target

(Eventually Compose will be able to automatically remove services after each run, see https://github.com/docker/compose/issues/2774⁠)

⁠Privileged Operations

Notice the privileged: true option in the compose file. This enables us to better mimic a VM environment and perform operations such as installing the Docker Engine during a playbook run see Docker Reference⁠.

Tag summary

Content type

Image

Digest

sha256:7ba7ce450…

Size

164.9 MB

Last updated

over 3 years ago

docker pull jhidalgo3/ansible