15 ms·
Pyinfra: Automate Infrastructure Using Python
- deleted 2y ago[deleted]
- manojlds 2y agoDoes it allow me to run a script against an EC2 instance, say, and it spins it up and take care of everything? Something like packer would but without creating an AMI
- verdverm 2y agofyi, in Packer, there is an option to not create the final image
- manojlds 2y agoYes! Which is what I am doing now, but was feeling it was using a tool that wasn't meant for that job a bit.
- letmeinhere 2y agoYou ever try cloud-init? You can specify your config in user-data when launching pretty generic AMIs. https://cloudinit.readthedocs.io/en/latest/index.html https://cloudinit.readthedocs.io/en/latest/index.html
- manojlds 2y agoI don't want to launch instances (and run a script to set it up etc), I want to run my script THROUGH an instance.
- nijave 2y agoI made this a while back that utilizes shell script and AWS cli to spin up and cloud init to run things https://github.com/nijave/cloud-init-golden-image https://github.com/nijave/cloud-init-golden-image For this type of use case AWS has managed services like Batch, ECS, or even auto scaling groups that can make this easier depending on what you're trying to achieve. ECS with Fargate executors is fairly easy to run arbitrary things inside a VPC
- Fizzadar 2y agoYou'd need to create the EC2 instance outside of pyinfra (ie in Terraform). This could be done as part of the inventory itself, but wouldn't self-delete afterwards. If using Terraform there's a connector that allows you to plug Terraform output as a pyinfra inventory: https://docs.pyinfra.com/en/2.x/connectors/terraform.html https://docs.pyinfra.com/en/2.x/connectors/terraform.html
- emacsen 2y agoMaybe this is the best thing ever, but the documentation doesn't answer one simple question: What problem is it solving? It is a configuration management tool, like Ansible? Is it meant for running one-off commands across the infrastructure, like Salt? It says it integrates with Terraform, so it's not a provisioning tool... What does it do different (and presumably better) than other tools? The Getting Started guide doesn't cover this. The FAQ doesn't cover this, and the Docs doesn't have an Introductory section to cover this. It's disheartening to find a potentially interesting project, but not really know what it does and how it might fit in your workflow.
- paulddraper 2y agoIt's like Ansible. That's what I discovered by reading the homepage.
- emacsen 2y agoDigging in the docs, it uses words like "inventories" and "operations" which indeed look like a configuration management system, much like Ansible, it's agent-less. And that's cool- Ansible is a bit of an oddball system, but then I'm still left wondering, why is this better, or why it is better for the author at least? I've used cfengine, Puppet, Chef, bcfg2 (briefly) and ansible. I want to know what makes this tool different and better. :)
- mdaniel 2y agoI would disagree with that since ansible actually does two things simultaneously: cloud provisioning and local provisioning (and that "local" is actually hiding a 3rd axis, actual local, not just local to the managed instance, say for example if you needed the azure libraries or such, you can use a pre_tasks: block to create a virtualenv and install the deps locally before firing up the main workload) Reasonable people can 100% disagree about whether yaml is the correct packaging for those operations, and ansible is a bit too imperative for my liking, but as far as "I have one hammer..." it does all the things
- 2y ago
- activatedgeek 2y agoI current use Ansible to setup both local and remote hosts. I've been very happy with it, and love that Pyinfra intends to support the Ansible connector. My main gripe with Ansible is the YAML specification. Ansible chooses to separate the task specification and task execution. Pyinfra chooses to directly expose the Python layer, instead of using slightly ugly magic functions/variables. I like this approach more since it allows standard Pythonic control flow instead of using a new (arguably ugly and more hassle to maintain) grammar. Excited for Pyinfra!
- WesolyKubeczek 2y agoI'm only using Ansible because of its extensive documentation and mindshare, but my best successes with it were when I let go of the idea that the playbooks specify state "declaratively". I now treat them as imperative steps where each step is being checked as to whether it needs to be done or not, and it has vastly simplified my mental model of what Ansible is actually doing.
- letmeinhere 2y agoI think of ansible as a declarative-imperative lasagna, where each playbook is a desired state, achieved by an imperative sequence of plays, which themselves are desired states, achieved by a sequence of roles, which have the same properties, and then tasks too below that, finally resolving to plain old imperative Python. It's all pretty messy but useful.
- WesolyKubeczek 2y agoI never grokked this “plays” and “roles” business. All in all, this clever and cute terminology gives me creeps. I only use “playbooks” as series of tasks, more or less. Maybe I need an explanation “like I’m just a programmer/sysadmin and I need to use boring terms years old” of what is what, every explanation so far (when I bothered to look for it last) was too invested in this theatrical terminology, so I gave up and stuck to what worked after a command or two. Same with Chef and its galore of cooking words, but thankfully I don’t have to use Chef.
- Invictus0 2y ago[flagged]
- remram 2y agoSee FAQ #2
- Fizzadar 2y agoHey all, I'm the creator/primary maintainer of pyinfra! Super excited (a little terrified) to see this on the frontpage, happy to answer any questions :) I also hang out on the Matrix room: https://matrix.to/#/#pyinfra:matrix.org https://matrix.to/#/#pyinfra:matrix.org Another thing: the GH repo points at currently in beta v3 and the docs for this are here: https://docs.pyinfra.com/en/next https://docs.pyinfra.com/en/next (highly recommend starting with v3, I just haven't had any time recently to wrap up the release, but it's stable).
- negus 2y agoAs you can see here, the main question is what are the advantages over Ansible, a mature and the most popular agentless configuration management tool written in Python. So I propose putting this answer right to the landing page
- Fizzadar 2y agoI think I tried to shy away from specifically being "Ansible does this bad so pyinfra does this" and instead focus on the features that differentiate like "Instant debugging with realtime stdin/stdout/stderr output (-vvv).". But it seems like that isn't enough and the landing page needs to be more explicit in comparison. Ty for the feedback!
- erikbye 2y agoIs performance better than Ansible? I have used Ansible extensively and find it excruciatingly slow.
- helsinki 2y agoExcruciatingly slow is an understatement :)
- surfingdino 2y agoWhy being slow is a bad thing? Ansible gives me a legitimate excuse to have proper lunch. ;-)
- zbentley 2y agoI think Puppet hits the sweet spot in this area. It's default is a series of idempotent "here's how this should be configured" statements, but it can be used as a full programming language in its more advanced capacity, and it's reasonably extensible (in Puppet-lang and Ruby) to support specific custom applications. I also think that the facts/manifest/apply separation is conducive to nicely testable infra code, and useful dry-run output. I'm always surprised that Puppet isn't still more popular. My theory is that it's passed over because of its age/cruftiness/bad vibes in some cases, and that a couple of technical flaws mess it up for some key userbases: For folks who just want a quick-to-start management tool for a small set of config, Puppet's ugly and clunky client/server model and the hyper-YAML-ification of its best practices (which is pursued to a fault by the community, and not helped by the Hiera pitch that the Puppet stack can also be sort of an asset tracking/catalog system) make small-scale usage and prototyping hard. Puppet doesn't have to be used that way (it can be used just like pyinfra/Ansible with a local-apply or via Bolt, hitting a nice sweet spot between ad-hoc/non-idempotent commands and nice declarative/idempotent Puppet code), but I think the puppetmaster/hiera-all-the-things legacy in the community does Puppet and potential new users a disservice. From the other side, I think a lot of more cloud-oriented users looking for a "better Terraform for server state" end up annoyed by the quality of modules on the Puppet forge and Puppet's lack of a statefile equivalent (meaning that it doesn't support deletes or infrastructure state snapshots in the same way TF does).
- turtlebits 2y agoAdding config management agents to run on your infra is IMO unnecessary operational burden. (ie puppet, chef, saltstack, etc.) In the day and age of everything running on Docker, the closer you are to a bare OS image, the better. Config management that uses SSH is generally good enough.
- eurekin 2y agoCan concur, used puppet a bit at the dayjob and agent issues were common at some point. Also, for bigger inventories on a single vm runtimes shot up quickly in the hour realm
- admin1231111 2y ago[flagged]
- Lucasoato 2y agoShould this be considered some kind of alternative to tools like Ansible? Also CDKTF should be in the space for imperative infrastructure as code definitions. - https://developer.hashicorp.com/terraform/cdktf https://developer.hashicorp.com/terraform/cdktf
- photonthug 2y agoAgree with those saying the landing page needs work. But terraform/docker integration sounds interesting.. after many years of ansible you’d think there is a more comfortable way to replace a hundred lines of hacky bash in dockerfiles. Also, can I just say that cm is extremely frustrating? Not sure this is the fix, but hopefully the story isn’t over. In my experience the maintenance of cm codebases never, ever stops. At first I thought it was a matter of expertise, but experts typically agree and just call it the cost of doing business. Shelve something for three months and it will break on the next run, on the same os/host where it used to work. Blame the package manager, blame the os choice, or the cm tool. But it’s embarrassing and insulting for Devops teams after putting in the effort to do things right, and evangelizing to everyone else about repeatability. I’d rather just see tighter integrations with containers moving forward and never think about it again. Not everyone is using k8s but in the 2020s everyone probably should default to using docker before doing things of even marginal complexity directly on hosts.
- Fizzadar 2y ago> Agree with those saying the landing page needs work. Any & all feedback much appreciated! It's basically just a very rough copy of the README at the moment.
- riffic 2y agothis feels like Michael DeHaan's OpsMop project that existed for like a week before he pulled all the code offline. https://news.ycombinator.com/item?id=18717422 https://news.ycombinator.com/item?id=18717422 Interesting to see all the Ansible comments here. I'll have to check this out asap.
- crispyambulance 2y agoYeah, I like this approach. There's something about YAML that just sucks the joy out of programming. It seems like a giant step backwards when we have plenty of amazing programming languages in existence. Even when infrastructure yaml like cloudformation are wrapped by some SDK, it can still be a pain because you end up with stuff like... do_something("___((!-prickly_config_string_::might as well use yaml _blah-blah:blah))") Back in the days of java and xml, there used to be a distant promise of "binding" the xml to code (remember jaxb?) so that you could then just manipulate it fluently as code and then "marshall" it out back to xml when you were done. Those days and that promise are gone, right?
- mdaniel 2y agohttps://github.com/aws/aws-cdk#at-a-glance https://github.com/aws/aws-cdk#at-a-glance is the "generate cloudformation using code," and is the AWS version of troposphere as best I can tell
- crispyambulance 2y agoCDK looks like it definitely does do that!
- subhro 2y agoWhy does this sound so familiar to Chef?
- 0xbadcafebee 2y agoso, it's Ansible...? Configuration Management tools (that's what this, and Ansible, are) are a nice idea, but get very complicated very quickly. The tools themselves get complicated, the configuration gets complicated, you're constantly finding ways that the state gets broken that you need to re-incorporate into your script, it has to work in a variety of states, and you have to keep re-running and re-running and re-running it, monitoring for problems, investigating, fixing. Very complex, lots of maintenance, lots of potential problems. The "Pets" model from the phrase "Cattle, not Pets." I strongly recommend you do not raise Pets. Instead, use Immutable Infrastructure: build an immutable image one time that works one way. Deploy that image. If you need to change it, change the build script, build a new image (with a new version), deploy a new instance with the new image, take the old one out back and shoot it. (The "Cattle" of "Cattle, not Pets") If the state gets out of whack or there are problems, just shoot it and deploy a new one that you know works. This is the single most revolutionary concept i've seen in over 20 years of doing this job. It is an absolute game-changer. I would not go back to Configuration Management for all the tea in China.
- aprdm 2y agoYou're conflating different things - this has nothing to do with Pet vs cattle. Even in your confusion, State still exists in the real world and needs to live somewhere, it also is unfeasible to always recreate big states.
- 0xbadcafebee 2y agoThis happens so often on HN, and it is so god damn frustrating. I'm literally a fucking expert, telling you the best thing to do, and explain why, and I get downvoted for it. The next person who tells me in a comment "explain your opinion! you're not helping!" when I don't write an entire novel to justify my position, I'm going to link back to this thread. Pointless. I've gone to the trouble of googling these articles for you (it took me a whole 30 seconds!). Please read any of them. https://webcache.googleusercontent.com/search?q=cache:https://medium.com/the-cloud-architect/immutable-infrastructure-21f6613e7a23 https://webcache.googleusercontent.com/search?q=cache:https:... https://devopscube.com/immutable-infrastructure/ https://devopscube.com/immutable-infrastructure/ https://thenewstack.io/a-brief-look-at-immutable-infrastructure-and-why-it-is-such-a-quest/ https://thenewstack.io/a-brief-look-at-immutable-infrastruct... https://www.digitalocean.com/community/tutorials/what-is-immutable-infrastructure https://www.digitalocean.com/community/tutorials/what-is-imm... https://www.hashicorp.com/resources/what-is-mutable-vs-immutable-infrastructure https://www.hashicorp.com/resources/what-is-mutable-vs-immut... https://www.techtarget.com/searchitoperations/definition/immutable-infrastructure https://www.techtarget.com/searchitoperations/definition/imm... https://www.oreilly.com/radar/an-introduction-to-immutable-infrastructure/ https://www.oreilly.com/radar/an-introduction-to-immutable-i... https://www.terraformpilot.com/articles/mutable-vs-immutable-infrastructure/ https://www.terraformpilot.com/articles/mutable-vs-immutable... https://www.bmc.com/blogs/immutable-infrastructure/ https://www.bmc.com/blogs/immutable-infrastructure/ https://www.linode.com/docs/guides/what-is-immutable-infrastructure/ https://www.linode.com/docs/guides/what-is-immutable-infrast... https://devops.com/immutable-infrastructure-the-next-step-for-devops/ https://devops.com/immutable-infrastructure-the-next-step-fo... https://openupthecloud.com/what-is-immutable-infrastructure/ https://openupthecloud.com/what-is-immutable-infrastructure/ https://www.opsramp.com/guides/why-kubernetes/infrastructure-as-code/ https://www.opsramp.com/guides/why-kubernetes/infrastructure... https://www.cloudbees.com/blog/immutable-infrastructure https://www.cloudbees.com/blog/immutable-infrastructure https://www.daily-devops.com/devops/immutable/architecture-patterns/why-immutable-infra/ https://www.daily-devops.com/devops/immutable/architecture-p... http://radar.oreilly.com/2015/06/an-introduction-to-immutable-infrastructure.html http://radar.oreilly.com/2015/06/an-introduction-to-immutabl... https://highops.com/insights/immutable-infrastructure-what-is-it/ https://highops.com/insights/immutable-infrastructure-what-i... https://docs.aws.amazon.com/wellarchitected/latest/financial-services-industry-lens/use-immutable-infrastructure-with-no-human-access.html https://docs.aws.amazon.com/wellarchitected/latest/financial...
- godisdad 2y agoSeems like an interesting generalized mix of something like https://github.com/cloudtools/troposphere https://github.com/cloudtools/troposphere and Ansible from a glance. The value add would be unifying provisioning and configuration management in a Python-y experience? The lifecycle of each is distinct and that's traditionally where the headaches of using a single tool for both has come in
- jdoss 2y agoI just started using Pyinfra to wrangle a bunch of servers and it is a breath of fresh air compared to Ansible. I moved all of my server OS installs to Fedora CoreOS which doesn't ship with Python in the OS and since Pyinfra doesn't need Python on the host node I can kick off tasks in bulk to do server things. It is great. I cannot wait to see where the Pyinfra project goes. On a side note, one of the most hacky things I came up with to get Ansible working on Fedora CoreOS was to bind mount a container rootfs that had python 3 and then symlink it into the right spots. You can of course add Python in with rpm-ostree if you want but I wanted to avoid layering packages at the time. I wasn't proud of it. But it worked. https://github.com/forem/selfhost/blob/main/playbooks/templates/forem.yml.j2#L67-L118 https://github.com/forem/selfhost/blob/main/playbooks/templa...
- shoggouth 2y agoDoesn’t IBM/Red Hat own Ansible and Fedora CoreOS? I would think they would mix together perfectly.
- movedx 2y ago> since Pyinfra doesn't need Python on the host node I can kick off tasks in bulk to do server things. And you can do this with Ansible, too. Check out the raw module/command.
- posix_monad 2y agoPython seems like a really poor choice for infrastructure. - Python is not easy to build into portable binaries - The package ecosystem is very hard to use in a reproducible way - The language is not truly typed - types add massive value for infrastructure and scripts because they are less likely to be unit-tested - The lack of a "let" or "var" keyword makes simple programming errors more likely (again, this code is less likely to be unit-tested) Maybe I'm missing something? I don't know why I would want to introduce Python in this domain.
- aprdm 2y agoMaybe because Python is already in use by pretty much every company that makes money in this (and others) domain ? Some of what you mention looks like pebkac problems as well.
- mhh__ 2y agoWell so is pretty much any configuration language under the sun, and all the other options that aren't python.
- Fizzadar 2y agoExtremely aware of this (see pyinstaller attempt): https://github.com/pyinfra-dev/pyinfra/pull/768 https://github.com/pyinfra-dev/pyinfra/pull/768) I chose Python because it’s what I was writing all day back in 2015. Which makes me realise pyinfra is almost 10! Edit: I mostly write Go or YAML (k8s) these days but Python still makes an appearance from time to time (outside of pyinfra dev).
- bborud 2y agoPython is a nightmare when used for tooling. I’ve wasted so much time wrangling Python tooling for embedded development. Go would be a much better choice.
- JoBrad 2y agoWhat would you have used? All of your issues aside, Python is very approachable to people who are used to managing infrastructure but may not have a strong programming background.
- mhh__ 2y agoI worry about using python for this kind of thing. It's very hard to be confident about python code. If you have a good code review feedback loop and so on then it can be OK but proper types enable lots of good things when dealing with configuration and state.
- Spivak 2y agoI mean Python has your back with static type hints. While Python's type system isn't the most powerful in terms of expressiveness -- TypeScript is stronger, Go is weaker, it's more than capable enough for a config management system.
- mhh__ 2y agoEmphasis on hints. And my point is that it can be way too capable.
- Spivak 2y agoI guess the fact that they're hints doesn't really bother me when you're doing static analysis. You can have strong typing with a weak type system like C and Go where the types will be rigidly enforced but they're also not expressive. There end up being lots of things you can't express in the type system which leads you to do things like void* or `any` with manual casting. But a fully type-hinted Python codebase is extremely expressive, the times where you have to opt-out of the type system is much much rarer and the types you end up writing are much more specific so you get stronger guarantees. It's not without downsides but I don't think it's "because they're hints you can't trust them" since lots of languages erase their types on compilation.
- exceptione 2y agoI am not elbow deep into Python ecosystem, but how many python code bases are fully type-hinted? Maybe I am overlooking because I am not a pythonista, but when looking at this code [1] I see only some superficial hints. Looking at `_make_command`, I need to look inside the body to see that the first argument is expected (?) to be callable (it just ignores otherwise). ____ 1. https://github.com/pyinfra-dev/pyinfra/blob/3.x/pyinfra/api/facts.py https://github.com/pyinfra-dev/pyinfra/blob/3.x/pyinfra/api/...
- cheptsov 2y agoWe build a similar tool except we focus on AI workloads. Also support on-prem clusters now in addition to GPU clouds. https://github.com/dstackai/dstack https://github.com/dstackai/dstack
- rajaravivarma_r 2y agoThis is great. We tried ansible and gave up as it was difficult to keep configuration DRY and annoying to create conditions with no control structure. It was before ansible 2, so probably things are better now. Then we started using Python fabric. Wow it was so freeing. Any helper methods were easily extracted and writing conditions felt natural. Now I am using Python invoke to maintain my local setup.
- Izmaki 2y agoAnsible is strong when done right. Check out the tutorial series by Jeff Geerling on YouTube, he's amazing.
- rajaravivarma_r 2y agoMay be, but moving to Python did not take anything away. It brought more joy that you have more control over things like, on which server to run the migration and choose UAT or prod and just a list of servers specified in the command line. And organizing the modules was straight forward as we already knew/did that in the project. Perhaps, it comes from my programming background, but its true.
- bityard 2y agoI gave up being religiously DRY in Ansible playbooks early on. It's much easier to open a file and read through a list of simple 2- or 3-line tasks that execute sequentially, than it is to chase down a bunch of imports. Same as in programming, over-adherence to DRY leads to spaghetti code.
- rajaravivarma_r 2y agoI have tried this path of not trying to DRY everything, but has regretted and refactored to a more DRY approach eventually. The cost of remembering to fix/alter the logic everywhere is more than trying to keep it DRY. More often a method or a module is enough, nothing fancy. The only place where I have accepted that DRY is not worth it is, unit tests. I used to extract any common behavior in a shared test, but each object will eventually evolve in its own way that the effort to make it DRY will be useless.
- linuxdude314 2y agoShould probably just stick with the Terraform CDK or Chef if you need this level of expressibility. This is no where near the level of readiness needed to be reliably used in a production environment. Verbose logging is not a reason to introduce a non-standard tool into your stack.
- imiric 2y ago> This is no where near the level of readiness needed to be reliably used in a production environment. This is baseless FUD. Pyinfra is 8 years old, just 2 years younger than Terraform. It's well maintained, stable, and used by many teams in production. Just because it's not as widely known or adopted as other tools, doesn't mean it should be avoided. In fact, as you can see from testimonials here, users often prefer it over Ansible. > Should probably just stick with the Terraform CDK or Chef if you need this level of expressibility. Terraform is used for provisioning infrastructure. Pyinfra is a configuration management tool. They're not equivalent. Chef is closer, but it's an older tool that has largely been superseded by Ansible. It shouldn't be anyone's first choice, unless they really need some obscure feature it does better than Ansible, or Puppet for that matter. > Verbose logging is not a reason to introduce a non-standard tool into your stack. Why would that be the only reason to use this? That's not even one of its prominent features, and surely all tools in this space support verbose logging... What a confused comment.
- yjftsjthsd-h 2y ago> Should probably just stick with the Terraform CDK or Chef if you need this level of expressibility. I'm not familiar with Terraform CDK, but I don't see what Chef does/has that this doesn't? > This is no where near the level of readiness needed to be reliably used in a production environment. Why?
- pants2 2y agoThis will tie nicely into my favorite way to deploy services these days: 1. Use PyInfra to set up Docker and Tailscale on remote hosts and any other setup. Open the Docker port to your Tailnet. 2. Use the Docker provider for Terraform to set up and manage containers on those hosts from your dev machine or from a CI/CD tool. Tailscale allows containers on different machines to communicate privately, or you can open a port to the web. This makes for such an easy-to-use and bulletproof setup. In the past I would have used Kubernetes but I've come to realize that's overkill for anything I do and way harder to debug.
- asselinpaul 2y agois there a blog post or github repo with more info on how you do this?
- pants2 2y agoNo but I'll think about writing one up!
- nijave 2y agoThis kind of setup is a nice improvement over golden images with a lot of the benefits. Application setup, upgrades, and rollback become much easier when the whole app is packaged together and has its own copy of dependencies. You can also throw in systemd units for Docker or Podman. I usually create a small shell script that pulls, removes any old container, then runs a new container with correct args in the foreground and toss that in a simple systemd unit
- udev4096 2y agoWhy not go for headscale?
- mixmastamyk 2y agoHow often is this kind of tool needed since containers went mainstream? I had gathered they were not used as often any longer.
- mdaniel 2y agoMy experience has been that for day zero stuff, e.g. how do you get a system _prepared_ for containers, this kind of tooling is handy. I side with the sibling comment that cloud-init is The Way but it also requires (a) some trial and error (b) to think entirely in terms of cattle/pets which some folks/organizations are not there yet
- kureikain 2y agoThanks for making Pyinfra. It's one of the tool that get out of your way and let. you get the work done. The tool works for you instead of you fighting with the tool. Pain point of ansible: storing state and checking later, coordinate state between server is all a breezy with Pyinfra because you write the Python code to perform those check. The system is very well though out. No need to hack around host file, inventory is just a python script that export resource definition. No more static, ad-hoc host var, you get a real python script to define and return your variable. Using pyinfra I was able to focus more on the "compute". the state such as credential, inventory can managed and store outside such as in SSM or just call python ec2 api to filter instance by tag.
- Feathercrown 2y agoThis is really cool! Kinda seems like the Nix config approach.
- dang 2y agoRelated: Pyinfra automates infrastructure super fast at scale - https://news.ycombinator.com/item?id=33286972 https://news.ycombinator.com/item?id=33286972 - Oct 2022 (37 comments) Show HN: pyinfra v2 - https://news.ycombinator.com/item?id=30999030 https://news.ycombinator.com/item?id=30999030 - April 2022 (2 comments) Pyinfra v2.0 Released - https://news.ycombinator.com/item?id=30973976 https://news.ycombinator.com/item?id=30973976 - April 2022 (3 comments) Show HN: Pyinfra v1.4 - https://news.ycombinator.com/item?id=26983266 https://news.ycombinator.com/item?id=26983266 - April 2021 (3 comments) Pyinfra – automate infrastructure super fast at scale - https://news.ycombinator.com/item?id=23487178 https://news.ycombinator.com/item?id=23487178 - June 2020 (64 comments) Pyinfra v0.3 - https://news.ycombinator.com/item?id=13862942 https://news.ycombinator.com/item?id=13862942 - March 2017 (1 comment) Pyinfra v0.2 - https://news.ycombinator.com/item?id=12956784 https://news.ycombinator.com/item?id=12956784 - Nov 2016 (2 comments)
- wg0 2y agoAnsible needs a working Python interpreter on the target machine. Pyifra doesn't even need that. Just needs a shell. Subjective opinion but it is heavily under recognized piece of software. Ansible is really great but you soon end up writing Python in Yaml strings. So why not straight up Python?
- mdaniel 2y agoAs an FYI, "needs" is not correct, it has `raw:` for doing anything the target interpreter understands (sh, bash, powershell, etc), which can then include actually provisioning beefier interpreters (full blown python, pypy, whatever) Ansible plugins can be written in any language, shell, compiled binaries, whatever, and communicate with the control plane via stdin/stdout I suspect you are thinking of Jinja2 when you are writing python in yaml strings, which ... kind of, I guess, but also confusingly not Python, or at least the hacked up copy of Jinja2 that ansible uses can't do all the fun things normal Jinja2 can
- mattbillenstein 2y agoWas there any thought to perhaps do a version with an agent? I really like how fast Saltstack can be as compared to Ansible. I've been using my own homegrown project that does just this - Python roles, server/client, Mako templates: https://github.com/mattbillenstein/salty https://github.com/mattbillenstein/salty It's very very fast to do deploys on long-lived infrastructure, but it hasn't been optimized for large clusters yet; I expect the server process will be a bottleneck with many clients, but still probably faster than Ansible for most setups.
- Fizzadar 2y agopyinfra supports executing on the local machine (@local connector: https://docs.pyinfra.com/en/2.x/connectors/local.html https://docs.pyinfra.com/en/2.x/connectors/local.html). If you store the operation files on the machine that’s basically an agent when executed just without a periodic check for other changes. Adding a mode to do that in a loop would be pretty trivial..
- mattbillenstein 2y agoYeah, I'm talking more about RPC - the server sends a command to the agent - the agent does a thing and returns a response. There's no external sync of the command and given a long-lived connection - client/server what you will - this can all be completed in milliseconds with no new-connection overhead.
- beefnugs 2y agoDoes anyone have any info on if saltstack is going to be enshittified? That is the situation that would get me to go looking for a replacement such as this
- umen 2y agoThere is need for python module that complies to ansible code
- ornornor 2y agoI use pyinfra through molecule for testing sensible roles, it’s made it possible to have a process resembling TDD and have automated tests for my roles and playbooks. I actually don’t know how else to do it than with molecule and pyinfra, being able to have automated tests on ansible “code” made a big difference for me!
- lodriv 2y agoHowever the email address was not being processed
- Maledictus 2y agoIMHO Ruby is better for creating DSLs, so I wrote a small thing to scratch my own itch: https://github.com/marius/koch https://github.com/marius/koch This is not meant to scale to more than a handful of machines, but you get the idea how nice straight Ruby is for a machine specification DSL.
- lnxg33k1 2y agoAnecdata: maybe yes, but when I was using puppet it would take 45 minutes just to load
- mdaniel 2y agohttps://github.com/marius/koch/blob/main/example/Rezeptfile https://github.com/marius/koch/blob/main/example/Rezeptfile suffers from the same problem I have with every single ruby ever: what are the available verbs I can type? Contrast that with https://docs.pyinfra.com/en/next/examples/client_side_assets.html https://docs.pyinfra.com/en/next/examples/client_side_assets... where any sane setup will show completions after both the `from` and the `local.` typing
- Maledictus 2y agoThank you for the feedback! I agree that completion would be nice to have, and probably relatively hard to implement for koch. However, I prefer the cleanliness, dare I say beauty, of the config file and Ruby.
- BodyCulture 2y agoI would like to point to a virtual machine or a set of virtual machines that I have configured and make the tool reproduce / translate the state of these „model machines „ to some hosting environment. Can this or any other tool do that?
- mdaniel 2y agoaws ec2 create-image :-D In all seriousness, I would guess this requirement has a hidden 80/20 in it because it is very unlikely that one wishes every machine to be a perfect copy of each other, unless the config files have been very, very disciplined about the hard-coded strings and assumptions made So even in my glib "create-image" response, even then there's almost certainly going to be some cloud-init that subsequently stamps the booted instance with its actual identity
- betimsl 2y ago[flagged]
- crabbone 2y agoAs someone who had to write infrastructure in Python, every time from scratch, for large projects: pyinfra isn't it (and neither is Ansible, if you care about that). It will probably work for some simple and common cases, but they barely need any automation anyways... The problem isn't even the tool itself, it's the lack of standards. Every large enough system is too unique to be easily managed by cookie-cutter tools like this one. Some people will bite the bullet anyways, and try to adapt general-purpose infra tools to their case. I've seen that too. This is a very miserable experience. Frustrating in that very obviously simple and necessary things are sometimes described as "impossible" due to how the chosen framework works. To contrast that, the home-brewed systems usually suffer from the lack of generality, worse user experience in general, quickly start lagging behind the underlying technology updates... Also, out of popular languages, Python would be somewhere towards the bottom of the hierarchy if I had to choose a language to manage infrastructure. The only redeeming quality of Python is its popularity. On engineering merits alone its unremarkable at best. ---- PS. import click If I see this in the project source code, I blacklist it and never look at it again. This is a red flag, a sure sign that the person writing it are clueless.
- mleonhard 2y agoVery cool. One question: Can Pyinfra create container-like objects and objects inside them? Example: create an RDS database, create a user inside that database, and assign the user a role. Terraform cannot deploy such a configuration in a single config, since its planning stage requires that all containers already exist. Terraform crashes when planning the user and role changes, saying that the database doesn't exist. This is a large pain-point when using Terraform. How does Pyinfra handle such deployments?
- voiprodrigo 2y agoIs this something that would be a good fit to automate node reboots/restarts of complex clustered systems? Think Kafka, Elasticsearch or Flink, where you can’t restart the next node without revalidating the state of the cluster and the rejoining of the previous node. Please feel free to suggest other tools for this purpose.