4 ms·
If you have an ansible playbook that creates a certain resource, and you delete that code. Next time you run it, it won’t delete the resource because there is n
by diroussel 5y ago
If you have an ansible playbook that creates a certain resource, and you delete that code. Next time you run it, it won’t delete the resource because there is no state management.
You have to add code to as only to be sure to remove the non-longer needed resource. But how long does that code need to stay there.
Ansible is supposed to engender a decorative approach, but it’s very easy to slip into procedural code. Whereas terraform is much more declarative.
- mr_C 5y agoWho cares if there is a dangling dns records somewhere or an extra allocated floating ip? In practice you could just set state:absent to whatever you are trying to remove or just remove it manually, the latter is most of the time faster than dealing with state management once you have a behemoth in prod that no one wants to break.
- erik_seaberg 5y agoSome cloud resources will cost money every month, forever. (I think this is an unappreciated side of the AWS business model; it’s not cost-effective to have a dev confirm that each resource can be safely decomm’d.) There’s also a risk that your legacy environments only work because some dangling resource wasn’t cleaned up, and a new clone of the environment will fail.
- deleted 5y ago[deleted]
- ncallaway 5y ago> Who cares if there is a dangling dns records somewhere or an extra allocated floating ip What if instead of a dangling dns record, its 15 large EC2 instances? Yes, you can come up with examples of trivial dangling resources, but it's just as easy for me to come up with non-trivial examples of dangling resources.
- mr_C 5y agoI came up with trivial examples because no one forgets about non-trivial resources. In my opinion, if you decrease some instance count from 18 to 3, you'd rather waste 1 minute deleting 15 instances than dealing with all the problems a state management brings to the table.
- ncallaway 5y ago> no one forgets about non-trivial resources The number of articles I've read about someone who left a non-trivial number of resources running unused in AWS and were later surprised by a large bill would seem to be a counterexample to that point.
- sciurus 5y ago> Who cares if there is a dangling dns records somewhere You should care. This opens you up to subdomain takeovers, which have real security implications. https://developer.mozilla.org/en-US/docs/Web/Security/Subdomain_takeovers https://developer.mozilla.org/en-US/docs/Web/Security/Subdom...
- m1keil 5y agoYou pay for some of these (like dangling IP addresses not in use) and some others have a max quota (like security groups).
- matwood 5y agoAny dangling resources may cost money and/or open up security concerns.
- solatic 5y agoPart of the benefit of Terraform is the ability to set up ephemeral resources and tear everything down afterwards with "terraform destroy", which is useful for setting up one-off experiments and tests. That kind of cleanup is completely impossible with Ansible.
- mr_C 5y agoNot true, just set state to absent and run your play again.
- ezrast 5y ago> In practice you could just set state:absent to whatever you are trying to remove If you do this, or in fact anything with Ansible, be REAL careful about double-checking what your tags actually match before committing. Since it doesn't track state, anything in your cloud environment is fair game. I was not careful once, and that was a bad week for me.