Infrastructure · Intermediate

Infrastructure Automation with Ansible

Make two Ubuntu servers converge on a declared state with Ansible: inventories, idempotent playbooks, roles, Vault, linting, staged rollouts, rollback and drift detection.

About this course

One server configured by hand is a craft; ten servers configured by hand are ten slightly different servers. This course teaches you to describe the state you want once, in version control, and let Ansible converge every machine on it - repeatably, reviewably and without handing out more privilege than the job needs. You work from **ctl01**, your own Ansible control node, against two managed Ubuntu Server 24.04 machines, **node01** and **node02**, over SSH with a dedicated `automation` account. Everything runs on the software the course was executed on (ansible 9.2.0 with ansible-core 2.16.3, ansible-lint 6.17.2, yamllint 1.33.0), and the lab has no internet access: packages come from an internal mirror and collections from pinned tarballs, as they do in most companies. Ten lessons build one repository step by step: - how Ansible reaches a node, host-key verification, least privilege for the automation account, and rotating the key the platform issued; - playbooks, modules and handlers, and proving idempotence with a second run that changes nothing; - variables, facts and Jinja2 templates; loops, conditionals, blocks, tags and `serial`; - roles and pinned collections, including a PostgreSQL 16 database tier; - secrets with Ansible Vault and `no_log`, and proving no secret reached Git or a log; - `ansible-lint` and `yamllint` as a quality gate on every commit; - a staged rollout through a change record, a pre-change `--check --diff` review, health gates and a rollback play; - scheduled drift detection on a systemd timer, and dynamic inventory from a CMDB export. Two lessons start from a deliberately broken situation - a defective release and a colleague's undocumented hand edits - and you work them the way an operations team does: observe, form a hypothesis, test one thing, fix, verify, record. The final project is an engagement for a synthetic tax-advisory client: a two-tier service built from your own roles, with a vaulted database credential, a rolling deployment and a runbook their staff can follow. Lab checks grade the machines themselves, not your description of them. This is a learning pathway toward systems administrator and platform engineer roles. It awards an Ultiblob Certificate of Completion; it is not a vendor certification and makes no promise about employment.

Content time
11 h 25 min
Lessons
10
Certificate
Yes
on completion
Choose a career path

Lesson 1 is free. Enroll in a career path to access its full courses.

Lesson 1 is a free preview — read it without an account.

Infrastructure — the kind of infrastructure this course is practised on

Outline

Lessons

10 lessons · 11 h 25 min
  1. Lesson 1: Why automation, and how Ansible reaches a nodeFree preview

    What Ansible actually does when it configures a server, how it gets in, and why the account it uses is a security decision you make on day one.

    1 h
  2. Lesson 2: Playbooks, tasks, modules and handlers

    Write the state you want as a playbook, apply it, prove a second run changes nothing, and learn what check mode can and cannot tell you.

    1 h 10 min
  3. Lesson 3: Variables, facts and templates

    Separate the data from the automation: group and host variables, facts gathered from the machine, and Jinja2 templates that render a file per node.

    1 h 10 min
  4. Lesson 4: Control flow and rolling changes

    Loops and conditionals for accounts, changed_when and failed_when for commands, block/rescue/always for risky changes, and serial so a mistake reaches one node at a time.

    1 h 10 min
  5. Lesson 5: Roles and collections

    Refactor a growing playbook into roles, pin the collections your repository depends on, and add a PostgreSQL database tier with community.postgresql.

    1 h 15 min
  6. Lesson 6: Secrets with Ansible Vault

    Put the database password in an encrypted file with a vault id, keep it out of output with no_log, and prove it reached neither Git, the working tree nor the log.

    1 h
  7. Lesson 7: Linting and testing

    Put ansible-lint and yamllint on a colleague's quick playbook, read what they find, fix every finding, and make the gate run before each commit.

    1 h
  8. Lesson 8: Running automation safely

    Take a release through a change record, a check-mode review, a drain, a one-node-at-a-time rollout with health gates, an abort, a rollback and an honest outcome.

    1 h 30 min
  9. Lesson 9: Scheduled and pull-mode automation

    Run check mode on a timer to detect drift, investigate a node somebody edited by hand, remediate it with the playbook, and compare push, pull and controller-based operating models.

    1 h 10 min
  10. Lesson 10: Ansible in the wider toolchain

    Build a dynamic inventory from a CMDB export, see what changes when the source of truth moves, and place Ansible next to cloud-init, infrastructure as code, controllers and Windows.

    1 h

Where it leads

Part of these career paths