🎭
Active Module Path

Ansible

Master enterprise Ansible automation: Agentless SSH, Inventory design (group_vars/host_vars), Idempotent playbooks, Jinja2 templating, Variable precedence, Handlers, Task Blocks & Rescue error handling, Modular Roles & Galaxy, Ansible Vault secrets, and AWX / Ansible Tower job templates.

10 lessons 252 min syllabus

Stage 1 β€” Architecture & Inventory

2 lessons
Lesson 1 β€’ ⏱️ 25m
Ansible Architecture, Agentless SSH Mechanics & Configuration Precedence

Why Ansible requires no target agent, OpenSSH multiplexing, ControlPersist, ad-hoc CLI commands, and the 4-level ansible.cfg precedence hierarchy.

βœ“
Lesson 2 β€’ ⏱️ 25m
Inventory Design: Static INI/YAML, Group Hierarchy & Variables

Master Ansible inventory design, human-meaningful aliases, nested child groups, group_vars and host_vars directory inheritance, and dynamic cloud inventory plugins.

βœ“

Stage 2 β€” Playbooks, Templates & Vars

3 lessons
Lesson 3 β€’ ⏱️ 25m
Playbook Structure, Tasks & Idempotent System Management Modules

Master YAML playbook structure, privilege escalation (become), core system modules (package, service, template, user, file), and the Idempotency state machine.

βœ“
Lesson 4 β€’ ⏱️ 25m
File Manipulation, Text Editing & Jinja2 Template Engine

Compare lineinfile, blockinfile, replace, and template modules, Jinja2 expression syntax, filters, template validation, and ansible_managed headers.

βœ“
Lesson 5 β€’ ⏱️ 25m
Variables, Facts, Variable Precedence & Custom Facts

Master the 22-level Ansible variable precedence hierarchy, system facts (setup module), custom local facts (/etc/ansible/facts.d/), and variable naming standards.

βœ“

Stage 3 β€” Control Flow & Error Handling

2 lessons
Lesson 6 β€’ ⏱️ 25m
Control Flow: Conditionals, Loops, Handlers & Asynchronous Execution

Master playbook control flow: conditional when expressions, Jinja2 tests, loops, delayed execution Handlers, async execution & polling, and serial rolling updates.

βœ“
Lesson 7 β€’ ⏱️ 25m
Error Handling, Defensive Blocks & Dry-Run Testing

Master defensive playbook design: Task Blocks (block, rescue, always), error override flags (ignore_errors, failed_when), smoke testing with uri module, and --check mode.

βœ“

Stage 4 β€” Security, Roles & Enterprise Automation

3 lessons
Lesson 8 β€’ ⏱️ 25m
Modular Architecture: Reusable Roles & Ansible Galaxy

Master Ansible Roles directory structure, generating roles with ansible-galaxy, role dependencies, meta configuration, and Red Hat 1-Git-repo-per-role standards.

βœ“
Lesson 9 β€’ ⏱️ 22m
Security Hardening & Ansible Vault Encryption

Master Ansible Vault AES-256 encryption, encrypting files vs inline string variables, Vault password files, multiple Vault IDs, and CI/CD secret integration.

βœ“
Lesson 10 β€’ ⏱️ 30m
Enterprise Automation: AWX / Ansible Tower & Capstone Project

Master Red Hat Ansible Automation Platform / AWX, Job Templates, Inventories, RBAC, Surveys, Workflows, and a complete multi-tier deployment capstone.

βœ“

πŸ—ΊοΈ Beginner β†’ Expert Roadmap

4 stages with prerequisites and a concrete mastery check at each.

→

🎯 What You'll Learn

  • β€’ Understand Ansible agentless architecture, SSH multiplexing, ad-hoc execution, and ansible.cfg precedence.
  • β€’ Design structured static and dynamic inventories using host groups, nested children, group_vars, and host_vars.
  • β€’ Write production-grade idempotent playbooks using core system modules (package, service, template, user, file).
  • β€’ Differentiate lineinfile, blockinfile, and Jinja2 templates using template validation and ansible_managed headers.
  • β€’ Navigate the 22-level variable precedence hierarchy, leverage system facts, and define local custom facts.
  • β€’ Control playbook execution flow with conditionals (when), Jinja2 tests, loops, async/polling, and handlers.
  • β€’ Build resilient playbooks with Task Blocks (block/rescue/always), smoke tests (uri module), and check mode (--check).
  • β€’ Create modular, reusable Ansible Roles with ansible-galaxy init, meta dependencies, and Red Hat single-repo standards.
  • β€’ Encrypt sensitive secrets, API tokens, and passwords using Ansible Vault AES-256 encryption and vault IDs.
  • β€’ Architect enterprise automation pipelines using AWX / Ansible Tower Job Templates, RBAC credentials, and Workflows.

πŸ›‘οΈ Best Practices in Production

The short version of this path. Every lesson also ends with the specific mistake it exists to prevent.

Do this
  • βœ“ Write tasks that are idempotent, and verify with --check --diff before every real run.
  • βœ“ Prefer purpose-built modules over command/shell; when you must shell out, set creates/removes.
  • βœ“ Keep inventory in Git with group_vars and host_vars, and know the variable precedence order.
  • βœ“ Structure reusable work as roles with a documented defaults/main.yml interface.
  • βœ“ Encrypt secrets with Ansible Vault, and keep the vault password out of the repository.
  • βœ“ Use handlers for restarts so a service bounces once per run, not once per task.
  • βœ“ Target changes with --limit and --serial so a bad play cannot hit the whole fleet at once.
  • βœ“ Pin collection and role versions in requirements.yml.
Avoid this
  • βœ— shell/command for something a module already does β€” you lose idempotency and check mode.
  • βœ— ignore_errors: yes used to make a play green. Use failed_when with a real condition.
  • βœ— Secrets in plain group_vars, or a vault password file committed alongside them.
  • βœ— Running against production with no --limit and no --check first.
  • βœ— Relying on task ordering across hosts without serial, so a rolling change becomes simultaneous.
  • βœ— Roles that reach outside themselves into another role's internal variables.