The playbook that always says changed OPS-2302

OpenConfiguration management · Easy · Fix · about 25 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Sasha Lind opened OPS-2302 at 09:30task

Waybill moved to port 8443 a week ago. The depots still listen on 8080, and the nightly playbook reports changed=5 on every host, every night.

The playbook appends each setting to waybill.conf on every run. After three weeks each file has the old port first and the new one repeated below it, and Waybill uses the first value it finds.

"The report says changed on every host every night, so I stopped reading it. Which I guess is the real bug." (Sasha)

A playbook describes the state a host should be in. Run twice, it should change nothing the second time. That quiet second run is what makes changed worth reading.

Your task

Rewrite site.yml with modules that describe the end state, run it to repair the fleet, and run it again to see changed=0 everywhere. Do not hide changes with changed_when: false.

On the machine

  • site.yml, group_vars/, files/labeld.conf
  • hosts/depot-N/etc/waybill/waybill.conf on each simulated host
  • The PLAY RECAP of ansible-playbook site.yml

Timeline

3 weeks agosite.yml is written in a hurry with shell: echo >>.
Last MonCHG-5510 sets waybill_port: 8443. The playbook runs nightly.
Every nightchanged=5 on every host. Nobody reads the report any more.
09:30A depot still answers on 8080. OPS-2302.

Done when

  1. Running the playbook repairs every host, including changes someone made by hand.
  2. A second run in a row reports changed=0 on every host, without hiding changes behind changed_when: false.
  3. Each host's waybill.conf sets port, depot, and log_level exactly once, with port 8443 and its own depot name.

Hints

Hint 1

Run ansible-playbook site.yml twice and compare the PLAY RECAP lines.

Hint 2

shell: echo ... >> appends on every run. Which module describes the whole file instead?

Hint 3

ansible.builtin.copy with content:, or ansible.builtin.template, writes the full file and only reports changed when it differs.

Hint 4

Replace mkdir -p with ansible.builtin.file state: directory, and the cp with ansible.builtin.copy src:.

Show the solution

Rewrite site.yml with modules that state the end result: ansible.builtin.file for the directory, ansible.builtin.copy (with content:) or ansible.builtin.template for waybill.conf, and ansible.builtin.copy for labeld.conf. Run it once to repair the hosts and once more to see changed=0.