3 ms·
Ansible, because I like having an agentless configuration management tool. In my experience, Ansible also seems the most readable (obviously subjective). I've u
by stuffaandthings 9y ago
Ansible, because I like having an agentless configuration management tool. In my experience, Ansible also seems the most readable (obviously subjective). I've used Puppet, and Chef but only through AWS OpsWorks.
That said, I've been playing around with Kubernetes lately and trying to move a lot of our infrastructure onto Kubernetes. The use of Dockerfiles kind of nullifies the need for a full fledged configuration management tool for me and I've been relying on bash scripts and distributed kv stores to manage state and environment variables (using 12 factor approach and managing environment variables with consul and secrets with vault)
- moondev 9y agoKubernetes also has a built-in configmap and secrets api. You can inject them as env vars or even mount files inside the container filesystem via the pod manifest
- dozzie 9y agoOh, but Ansible is not agentless. You do have an agent, and the worst kind at that: the one that you easily cut off by a single configuration mistake, because it serves both to send configuration commands and for diagnostic access. And then, whole Ansible run breaks on first problem on any host, even if it was a planned downtime.
- nikolay 9y agoReally?! Writing pseudo-Bash scripts in YAML? And why do you need this in the age of Docker and Kubernetes and Immutable Infrastructure? For AWS with no cloud-neutral goal on the roadmap, I'd use native services: Declarative Infrastructure via CloudFormation, and HashiCorp's suite for everything else.