6.3 KiB
Assignment
The Nautilus Application development team wanted to test some applications on app servers in Stratos Datacenter. They shared some pre-requisites with the DevOps team, and packages need to be installed on app servers. Since we are already using Ansible for automating such tasks, please perform this task using Ansible as per details mentioned below:
Create an inventory file /home/thor/playbook/inventory on jump host and add all app servers in it.
Create an Ansible playbook /home/thor/playbook/playbook.yml to install samba package on all app servers using Ansible yum module.
Make sure user thor should be able to run the playbook on jump host.
Note: Validation will try to run playbook using command ansible-playbook -i inventory playbook.yml so please make sure playbook works this way, without passing any extra arguments.ß
Solution
Ansible Inventory + Playbook — install samba on all App Servers
Set up the jump host so ansible-playbook -i inventory playbook.yml installs the samba package on
all three Stratos DC app servers — with no extra arguments.
Note: this is an Ansible task, not Kubernetes — no manifests to pipe into
kubectl. The heredocs below write the two files.
Step 1 — Inventory (all three app servers)
cat > /home/thor/playbook/inventory <<'EOF'
[app_servers]
stapp01 ansible_user=tony ansible_ssh_pass=Ir0nM@n ansible_become_pass=Ir0nM@n
stapp02 ansible_user=steve ansible_ssh_pass=Am3ric@ ansible_become_pass=Am3ric@
stapp03 ansible_user=banner ansible_ssh_pass=BigGr33n ansible_become_pass=BigGr33n
[app_servers:vars]
ansible_connection=ssh
EOF
Step 2 — Playbook
cat > /home/thor/playbook/playbook.yml <<'EOF'
---
- name: Install samba on all app servers
hosts: all
become: yes
tasks:
- name: Install samba package
ansible.builtin.yum:
name: samba
state: present
EOF
Step 3 — Ensure thor can run it
# thor owns the playbook directory and its contents
sudo chown -R thor:thor /home/thor/playbook
chmod 644 /home/thor/playbook/inventory /home/thor/playbook/playbook.yml
If you created both files as thor (as the heredocs above do), ownership is already correct and
this step is a no-op safety check.
How it works
The inventory
Each app server is keyed by its wiki server name (stapp01, stapp02, stapp03), which
resolves from the jump host — so the inventory name doubles as the connection target and no
ansible_host is needed. Verify with getent hosts stapp01 if unsure.
| Variable | Purpose |
|---|---|
ansible_user |
SSH username, different per server. |
ansible_ssh_pass |
SSH password (these servers use password auth). |
ansible_become_pass |
Sudo password — required because installing packages needs root. |
ansible_connection |
Transport plugin, set once for the group via [app_servers:vars]. |
Verify every credential against your lab's wiki. The pairs shown follow the common Stratos DC pattern but should be confirmed rather than assumed.
Since validation runs the bare command (no -u, -k, -K), all connection and escalation
details must live in the inventory file.
Why become: yes is mandatory here
Installing a package writes to system directories and the RPM database — strictly root-only
operations. The SSH users (tony, steve, banner) are unprivileged, so the play escalates with
become: yes. Without it, the task fails with a permissions error from yum.
Because sudo may prompt for a password and you can't pass -K (no extra arguments allowed),
ansible_become_pass is set per host in the inventory. That's the single most common failure point
on this task — "Missing sudo password" with no way to supply it at runtime.
If the lab's app-server users have passwordless sudo, the variable is simply unused — harmless either way.
The yum module
name: samba— the package to install.state: present— ensures the package is installed, and does nothing if it already is. This makes the task idempotent: the first run reportschanged, subsequent runs reportok. (state: latestwould instead upgrade on every run, which isn't what "install" asks for.)ansible.builtin.yum— the task explicitly requires the yum module. These app servers are RHEL/CentOS-family, so yum is correct. On modern Fedora/RHEL 8+ thednfmodule is the successor, and Ansible'syummodule transparently delegates to dnf where appropriate — soyumworks here regardless.
Why hosts: all
The inventory contains only the three app servers, so all targets exactly them — and it can't
break if the group name and the playbook's hosts: value drift apart. hosts: app_servers also
works given this inventory; all is just the more failure-proof choice.
Requirement 3 — "thor should be able to run the playbook"
The validation runs as thor, so thor must be able to read both files. Creating them with the
heredocs above (as thor) satisfies this automatically. The chown/chmod in Step 3 is a
belt-and-braces check in case the directory was pre-created by another user — a root-owned
playbook.yml that thor can't read would fail validation before Ansible even starts.
Host key checking
First-time SSH connections can fail on host-key verification. The safest fix — needing no extra
command-line arguments — is an ansible.cfg beside the playbook:
cat > /home/thor/playbook/ansible.cfg <<'EOF'
[defaults]
host_key_checking = False
EOF
sshpass must also be installed on the jump host for password auth.
Verify
cd /home/thor/playbook
# All three hosts listed
ansible-inventory -i inventory --list
# Connectivity + credentials across every server
ansible -i inventory all -m ping
# The actual validation command
ansible-playbook -i inventory playbook.yml
# Confirm samba is installed on all three
ansible -i inventory all -b -m command -a "rpm -q samba"
Expected — ping returning SUCCESS for all three; the playbook finishing with failed=0; and
rpm -q samba printing an installed version (e.g. samba-4.x.x-...) on each server rather than
"package samba is not installed."
"Missing sudo password" ⇒
ansible_become_passabsent or wrong. A yum permissions error ⇒become: yesdidn't take effect.UNREACHABLE⇒ hostname resolution or credentials.