Configuration management

Describe the state each host should be in, let the tool converge it, and keep each setting in exactly one place.

A configuration management tool such as Ansible, Puppet, or Salt keeps a fleet of machines in a known state. You describe what each host should look like, and the tool works out what to change. The description is the source of truth; the machines follow it.

Three ideas make that work.

Idempotency. Applying the same description twice must give the same result as applying it once. A task that writes a whole file from a template is idempotent: the second run finds the file already correct and does nothing. A task that appends a line with echo >> is not: every run adds another line. Idempotent tasks make the run report meaningful. changed=0 means the host was already right, and a change on a quiet night means someone touched the machine by hand. That is called drift, and the next run repairs it.

One place for each setting. Ansible merges variables from many sources: role defaults, group variables, host variables, the inventory, play variables, and the command line, in a fixed order of precedence. That flexibility is useful for real differences between hosts, such as one site with its own certificate. It is dangerous for settings that should be the same everywhere, because an old host-level value silently wins over the group value everyone edits. Keep shared settings in group variables, keep host variables for what is truly different, and ask the tool what a host will get (ansible-inventory --host) instead of guessing.

Change triggers restarts. Most services read their configuration at start. Writing a new file does nothing until the process reloads it, and restarting on every run causes needless disruption. Handlers connect the two: a task notifies a handler only when it really changed something, and the handler restarts the service once at the end of the play. Hiding changes, for example with changed_when: false, cuts that link and leaves processes running old configuration.

Configuration management sits next to infrastructure as code. Tools such as OpenTofu create the machines and networks; configuration management shapes what runs on them. Both follow the same rule: change the description, review it, and let the tool apply it, rather than fixing machines by hand.