Build an Inventory and Poke It With Ad-hoc Commands
Goal
You define automation targets in an inventory and learn to handle several servers at once with only ad-hoc commands, without a playbook.
Why it matters
When people learn an automation tool, they first wonder "what should I run", but real incidents almost always come from "who did it run on". The inventory is the device that pins those targets down in a file. A group is not just a nickname; it is also a channel through which variables flow — a value placed in [web:vars] reaches only the hosts of the web group, and a host's own variables override it again. If you don't know this precedence, you spend a whole day on the question "why isn't my setting taking effect". And when you narrow the targets, always use a run option (--limit). The habit of temporarily editing the inventory turns into a long-lived outage the moment that file is committed.
Steps
- Create
/root/ans/inventory/hosts.ini. In thewebgroup putweb1andweb2, and in thedbgroup putdb1; give all three hostsansible_host=127.0.0.1andansible_port=2222. - In the same file, use
[web:vars]to addapp_port=8080and[all:vars]to addansible_user=root.app_portmust not be visible on db1. - Create a
[prod:children]section and put the two groupswebanddbin it as children. Do not list hosts directly under prod. - In
/root/ans/inventory/hosts.yml, express the same structure (3 hosts, groups web/db/prod, theansible_hostvalues) in YAML format. - Run
ansible -i hosts.ini all -m pingand save the entire output to/root/ans/out/ping.txt. All three hosts must be SUCCESS. - With the ad-hoc
filemodule, create the directory/root/ans/artifacts/adhoc.dwith permission0750. - Run the ad-hoc command once more against only the
webgroup and save the output to/root/ans/out/limit.txt. db1 must not appear in the result. - Create
/root/ans/out/report.txt. It contains every host belonging toprodin그룹:호스트form (group name, a colon, then host name), one per line, sorted alphabetically (three lines:db:db1,web:web1,web:web2).
Notes
- With
ansible-inventory -i hosts.ini --listyou can see the actual parsed result as JSON.--graphshows the group hierarchy as a tree. - The sshd in this environment runs at
127.0.0.1:2222with key authentication. - Common mistake 1: writing host names in
[prod:children]. The children section takes group names only. - Common mistake 2: reading
.prod.hostsas it is in step 8. prod has its hosts through its child groups, so you have to descend through the children.
Create the web and db groups in an INI inventory
Create /root/ans/inventory/hosts.ini. In the web group put web1 and web2, and in the db group put db1; give all three hosts ansible_host=127.0.0.1 and ansible_port=2222.
An INI inventory lists hosts one per line under [그룹이름]. Attach connection details after the host in 키=값 form (key and value). Check the sshd port of this environment.
Add group variables and global variables
In the same file, use [web:vars] to add app_port=8080 and [all:vars] to add ansible_user=root. app_port must not be visible on db1.
A [그룹:vars] section applies only to that group, and [all:vars] applies to every host. app_port must not be visible on db.
Group them under the parent group prod
Create a [prod:children] section and put the two groups web and db in it as children. Do not list hosts directly under prod.
A [이름:children] section (the placeholder stands for the parent group's name) takes group names, not hosts. You must not list hosts directly under prod.
Rewrite the same structure in YAML
In /root/ans/inventory/hosts.yml, express the same structure (3 hosts, groups web/db/prod, the ansible_host values) in YAML format.
A YAML inventory has all: at the top level, and children:, hosts:, and vars: under it. Compare the results with ansible-inventory --list to check they are the same.
Throw the ping module at all three hosts
Run ansible -i hosts.ini all -m ping and save the entire output to /root/ans/out/ping.txt. All three hosts must be SUCCESS.
An ad-hoc command has the form ansible -i 인벤토리 대상 -m 모듈. The ping module does not use ICMP; it checks that Python runs. Save the output to a file.
Create a directory with an ad-hoc command
With the ad-hoc file module, create the directory /root/ans/artifacts/adhoc.d with permission 0750.
Pass arguments to the file module with -a. You need three of them, path=, state=, and mode=, and it is safer to wrap mode in quotes.
Narrow the targets to the web group
Run the ad-hoc command once more against only the web group and save the output to /root/ans/out/limit.txt. db1 must not appear in the result.
Don't edit the inventory; narrow the targets on the execution side. Give the group name as the target or use --limit.
Build a per-group host report
Create /root/ans/out/report.txt. It contains every host belonging to prod in 그룹:호스트 form (group name, a colon, then host name), one per line, sorted alphabetically (three lines: db:db1, web:web1, web:web2).
Process the JSON from ansible-inventory --list with jq. Note that prod has its hosts through its child groups. Sorting is needed too.