10 ms·
Ansible 2.1 Released, with Network Automation, Containers
- code_research 10y agonow with extendended network support one question gets even more important: how do you do rollbacks with ansible? There is no default mechanism or policy that seems to help with that, so I have to hand-roll my rollbacks?
- bovermyer 10y agoYes. There is no way to roll back.
- sgt 10y agoHand-roll them like a fine cuban cigar. Jokes aside, I would not inherently trust an automatic rollback even if Ansible did support it. You must always provision for worst case failures.
- davismwfl 10y agoIMO, the use case for rollbacks with Ansible (or Chef/Puppet etc) are done through redeploying prior releases not through trying to remove/replace software on an instance. Same with if you are rolling out a server configuration update (like a certificate), if you need to roll it back you send out the prior configuration. Am I missing some other detail?
- willthames 10y agoRevert your playbooks and roles to the version of your last good deployment, and redeploy. With good version control, role version management and idempotent library modules, this should be functionally equivalent to a rollback. There are plenty of caveats to the above (like the fact that the yum module won't downgrade [1], and you'll need reversible DB migrations) but that's basically the procedure. [1] https://github.com/ansible/ansible-modules-core/issues/1419 https://github.com/ansible/ansible-modules-core/issues/1419
- bovermyer 10y agoThis isn't quite accurate. It won't uninstall or remove things that a previous version put into place, unless you explicitly remove them before installing them as part of your playbooks/roles.
- JTenerife 10y agoExactly. This whole "declare your environment" thing with Ansible doesn't work. I've completely mixed experiences with Ansible. Yes, it's easy to get started, but it's certainly annoying having to create playbooks for removing stuff to get a clean state.
- bovermyer 10y agoTo be frank, my experience with configuration management has been a mix between "YES! THIS IS WHAT WE NEED!" and "...but it still doesn't adhere to immutable states." That's been true with Chef, Puppet, and Ansible, for me. I haven't experimented with other techs.
- jmcnulty 10y agoDepends how you write your playbooks/roles. You can write a role that will both add and remove depending on the value of a variable in your inventory. Then tweak the inventory and re-run.
- movedx 10y agoThe simple answer is: you don't, you "roll forward." In the event you deploy some code, a DB migration, a server configuration change, etc, and your solution fails after the fact, you move forward, not backwards. Let me explain further. If you deploy v1.0 of your application and it works, great! If you then deploy v1.1 and it falls over, you find out why, apply a fix, test it locally (Vagrant?), deploy it to a testing environment and perform automated tests (Selenium, jMeter, ...), and once it's working there, you deploy it to production. This is called a hot fix, and it will now be working as intended (unless something else is horribly off the mark in which case you have other issues.) The key to this example is the local and remote/network-based testing environment(s.) In my opinion, it's very much a realistic goal for ALL organisations of ALL sizes to operate local development environments using Vagrant and VirtualBox; a testing environment that spreads out the whole solution over multiple boxes (for testing networking code and configuration, among many other things); a staging environment for running performance tests (staging should match production bit-for-bit, cpu-for-cpu, ram-for-ram, ...) using jMeter or your choice of tooling; and finally a production environment to serve clients. This is the absolute minimum all organisations should be aiming for, and it doesn't even have to be fully automated using CI and/or CD. Also tests, such as unit tests, systems tests, integration tests, usability and performance tests, and so on, are also critical to preventing the need to roll back and instead, implementing a roll forward policy.
- brudgers 10y agoCurious if "roll forward only" could create situations where a failed version change could place the system of interest in a non-functional state until the problem was diagnosed, the code revised, and an update released. If that's possible, I would have concerns about the infrastructure meeting the core needs of the business such as providing value to cutomers.
- movedx 10y agoYour systems is already down, rolling back is the same thing, if not more effort than rolling forward. At least that's what I've always found. Another option is to have customers point at stage after it has been upgraded and if it all goes horribly wrong, a load balancer change should be enough to point people back at the older production environment. All this being said, problems in production shouldn't be a thing with configuration management, infrastructure as code (Terraform), and tests, not to mention three environments (development,test, stage - at minimum) to work your way through before pushing to production.
- Aissen 10y agoDoes it support python3 yet ? Also, why do we have to install aptitude to do system updates ? It has been a long time since apt-get had bad resolution issues (and aptitude isn't installed by default anymore (has it ever been?)).
- sethish 10y agoAptitude is installed by default on Debian Jessie.
- Aissen 10y agoIt's not on raspbian or Ubuntu Server.
- therealmarv 10y agohmm, all my cloud images (Digital Ocean, Rackspace) with Ubuntu 12.04 and 14.04 have aptitude installed by default. Only seeing a problem with Ubuntu 16.04 there.
- djrobstep 10y agoI love Ansible, and have been using it since it was a humble little git repo with a single author. Unfortunately it's probably the most important python package that doesn't support Python 3, it would be cool to see it upgraded. Apparently the hold-up is supporting very old 2.x python versions because of RHEL.
- benhoyt 10y agoI think it actually makes sense for something like Ansible to use Python 2 because it's about controlling lots of remote machines on various Linux distros, and the idea is that it's agentless. If you suddenly have to install an "agent" (Python 3) on all the remote machines before you control them with Ansible, that wouldn't be great. On the other hand, Ansible itself could have a tiny bootstrap step which installs Python 3 on all the remote machines before it does any work. In our case, we use Ansible daily for deployments, but haven't actually written any custom Python modules -- it's all just straight Ansible YAML. So I'm guessing for a lot of use cases it doesn't really matter what language Ansible is written in.
- Aissen 10y agoOr, they could support both so that they can be an agent for distros that won't have python2 installed and only python3 (AFAIK they don't exist yet).
- rlpb 10y agoUbuntu Server no longer has Python 2 installed by default (though it's available if you want it). This is the case on 16.04.
- Aissen 10y agoAh, I thought I heard about that somewhere. I did tests on 16.04 recently with ansible, but python2 was here, so I guess the image I was using wasn't a vanilla ubuntu (from a VPS provider).
- 10y ago
- hackerboos 10y agoI hope open sourcing Ansible Tower is still on the cards after it was promised at a conference shortly after acquisition.
- bovermyer 10y agoWe've found Rundeck to be a more flexible alternative to Ansible Tower, and Rundeck is open source: https://github.com/rundeck/rundeck https://github.com/rundeck/rundeck
- coredog64 10y agoNot to hijack the thread, but any pointers to good resources to sell mgmt on Rundeck? We're currently using Jenkins(!?) for role, something that enforces a divide where developers are allowed to automate, but operations isn't.
- acveilleux 10y agoI'm trying to parse your statement and I'm not sure if you want something to enforce that divide or if your complaint with Jenkins is that it enforces a divide between dev and ops?
- coredog64 10y agoSorry for not being clear. We're using Jenkins because it was the shortest path to a solution. It's not easy for non-devs to use, so I'd like something that is ops friendly and won't cause the devs to want to repeatedly bang their head on the desk.
- bovermyer 10y agoNot specifically Rundeck, no. I don't think anyone has written a blog post on that yet. Depending on how you're using Jenkins, Rundeck may not be a feature-for-feature replacement. You'll have to weigh Rundeck's feature set against your specific requirements.
- 10y ago
- mmgutz 10y agoUnarchive module gets cert error on get.docker.com on Ubuntu 14.04 LTS. System Python is too old.
- therealmarv 10y agoI also had this problems in the past with SNI certs. Very annoying old python bug, it's possible to fix old python but this makes no sense for an Ansible deployment http://stackoverflow.com/a/29099439/756056 http://stackoverflow.com/a/29099439/756056 Better approach: Use curl to download in some temp directory/file and then extract from there. Curl does not have this errors. Example: https://github.com/ansible/ansible-modules-core/issues/1716#issuecomment-121001546 https://github.com/ansible/ansible-modules-core/issues/1716#... My dream would be that whole Ansible would use rockstable libcurl instead of the requests library which has problems with Certs on (not so) old python versions.
- bcoca 10y agowe actually avoid the requests lib for this and many other reasons, we don't use libcurl as we try to avoid extra dependencies when possible. The issue is more basic than requests, the actual python http/url and ssl implementations have these issues, we have patched and added warnings to indicate which minimal python versions you can use and have SNI work.
- therealmarv 10y agothanks for clarifying!
- adamors 10y agoCan anyone comment on the speed of Ansible 2+? I have a bunch of playbooks that still use 1.8 and they are dog slow. Changing the contents of one file can take ~10 minutes. (Interestingly, running the entire playbook on a clean server is actually faster).
- vacri 10y ago>Changing the contents of one file can take ~10 minutes. O_o That kind of simple operation just zipped by for me on Ansible 1.6, 1.8, 1.9, and 2.0. The only noticeably slow kinds of operations for me are generally the package installs (understandably). I don't use a ton of variables in my templates, though.
- adamors 10y agoI have quite a few variables, yes. One of the files I change frequently is an external configuration file filled with credentials which is managed through variables. It looks something like this: {% for cred in credentials %} {{cred.key}}: {{cred.value}} {% endfor %}
- mewm 10y agohey, kind of off-topic, but wouldn't you be able to like this? {{ credentials | to_nice_json }}
- thenewwazoo 10y agoI'm curious to hear this too. We use Ansible to manage a fleet of a few thousand hosts, and runs take hours and hours and hours.
- bcoca 10y agospeed has been both better and worse, so depends a lot on what your playbook is doing, size of your inventory, vars, etc the only answer i can give you is: test. We do try to keep decent performance, but this is not our main focus.
- therealmarv 10y agoCan I kill Vagrant with this Docker compose approach on OS X? https://www.ansible.com/blog/six-ways-ansible-makes-docker-compose-better https://www.ansible.com/blog/six-ways-ansible-makes-docker-c... Does anyone know or has tested this with a normal (non beta) Docker install on OS X?
- devy 10y agoI have not been a big fan of Ansible due to some critical bugs (at least in 1.x) and the way how its community core committers are treating community requests like this. For one: Ansible 1.x cannot even print out the syntax error file and line number in the offending Playbook. [1] And their core committers ignored the issue and refuse to backport the basic debugging requirement after issue being opened 2 years. That itself, is a deal breaker for me. [1]: https://github.com/ansible/ansible/issues/5797 https://github.com/ansible/ansible/issues/5797 Edit: Downvoting me doesn't make this issue go away. What was requested is a simple basic debugging requirement - any mature syntax tree parsers should be able to do it.
- therealmarv 10y agoWhen it's that easy then implement it yourself and make a PR to Ansible ;)
- bcoca 10y agodisclaimer: i'm an ansible dev. As the ticket shows, this was added in the 2.x release of Ansible, that is why the ticket was closed. Adding this info required a major revamp of the parser, which we did in 2.x, for this and many other reasons. This is not a simple change in 1.x and we decided not to backport it.
- bpchaps 10y agoCould you? Tons and tons of companies are forced into using outdated versions (for tons of reasons) where point release updates are still possible. I'm sure it's a lot of work, but a lot of your core and original users would appreciate it. Not implementing something as useful as that just has a "we got 'em, no need to do anything else for them" vibe.
- carrja99 10y agoIt is unfortunate that Ansible has a complete lack of test cases around core modules and, as a result, people act surprise when they're broken in a new release. For example see this fairly critical defect with the s3 module in today's release: https://github.com/ansible/ansible-modules-core/pull/3347 https://github.com/ansible/ansible-modules-core/pull/3347
- shlant 10y agoDefinitely agree with this. I use the docker module extensively and found 2 regressions[1][2] that I went through the trouble of debugging down to a single commit, but still have no idea whether anyone is going to fix them. I'm hoping now that they are done rewriting the docker modules, and considering they are using docker as a selling point for 2.1, they will be more proactive with these issues. 1. https://github.com/ansible/ansible-modules-core/issues/3219 https://github.com/ansible/ansible-modules-core/issues/3219 2. https://github.com/ansible/ansible-modules-core/issues/3231 https://github.com/ansible/ansible-modules-core/issues/3231
- willejs 10y agoLook at Chef. Its extensively unit tested in both the core client & server, but also the cookbooks associated with it. Check out the docker one for example https://github.com/chef-cookbooks/docker https://github.com/chef-cookbooks/docker The interfaces and primitives for docker in this cookbook are great too.
- shlant 10y agoI used to be a Chef user, and although I do love it, it's overkill for the current infra I am supporting. I haven't had too many issues with Ansible, I love it's simplicity, just lately there have been some annoying regressions. I do really appreciate that testing is a priority in the Chef community, cause it definitely isn't with Ansible. It also seems like based on the naming conventions in the Chef cookbook, that Ansible is playing catchup with 2.1 (imitation is the sincerest form of flattery?)
- JTenerife 10y agoI love and hate Ansible. It has simplified so many things for me, but also had some annoying bugs and regressions. Somehow I've lost trust in the codebase. Also performance is a showstopper. I need a tool to develop, I just can't wait > 10 min for an iteration. I usually end up modifying my server's config files manually and then build the Ansible templates. Unfortunately I'm not aware of a better alternative.
- squeaky-clean 10y agoBy Windows support, do they mean as a Control Machine? Because I thought it has supported automating Windows remote hosts for a while now? The documentation still reads as though it doesn't support Windows as control. I just tried it out, and "pip install ansible" fails because of pycrypto. If I install pycrypto manually from another source, ansible installs successfully, but isn't recognized as a command. (I've double-checked it's installing ansible 2.1.0).
- dflock 10y agoCould you guys stop doing new features and write some unit tests for core modules please? So many regressions.
- itaifrenkel 10y agoCan anyone comment on ansible for CIS hardening (and docker CIS benchmark). If not, perhaps other tools?
- chucky_z 10y agoI use Ansible to do all of the CIS recommendations. Took about a day and following along with the CIS guide to do it.