mrkeyoor.com_
Wed 30 Sept 06:10 UTC
Automationevaluationupdated 30 Sept 2026

ansible review

Ansible runs repeatable infrastructure changes from one control machine, usually over SSH, so managed Linux hosts do not need a resident Ansible agent. This repository contains the ansible-core engine and built-in content; the larger ansible package adds separately packaged modules called collections for more systems and services.

Verdict

Our ansible/ansible run installed 42 packages in 28 seconds and built in 6 seconds, then pytest stopped with 7 collection/setup errors before running a test. The released tool is easy to try, while contributor work needs Ansible's documented test tooling and a closer look at its Python setup. Use it when agentless control from a Unix-like machine fits your operations and you accept that installation is only the start of inventory, credential, and collection work.

We ran it

Lab card: what happened when we ran ansibleScreenshot of ansible (www.ansible.com)
Install✓ · 28s42 packages · 57 MB
Build✓ · 6s
Tests✗ · 4s0 passed · 0 failed · 7 errors of 7 (pytest)
Known vulns0(pip-audit)
Repo5790 files~281,873 lines of source · 15.4 MB · 0 CI workflows · tests dir

Answers from our run

Does ansible build from source?

Dependencies installed in 28 seconds (42 packages), and the build succeeded in 6 seconds. We cloned commit a900ea9 into a clean Debian container with 3 CPUs and no project-specific setup.

Do ansible's tests pass?

Yes: 0 of 7 passed when we ran the project's own test command (pytest), with 7 collection errors. Some failures need services or credentials a bare container does not have.

Does ansible have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use ansible?

Teams that need a daemon on each managed host to enforce state continuously: Ansible's documented model is agentless and runs from a control node.

What are the alternatives to ansible?

Salt, Puppet, Chef Infra. Our ansible/ansible run installed 42 packages in 28 seconds and built in 6 seconds, then pytest stopped with 7 collection/setup errors before running a test.

Setup3/528-second install, but plain pytest ended in 7 errors
Docs5/5Install, inventory, testing, and platform limits are explicit
Community5/5September push with 518 issues and 341 PRs still moving
Maturity5/5v2.21.4 release and a well-defined core architecture

Who it’s for

Infrastructure teams that want one control node to configure Linux, Unix, Windows, network, or cloud targets.
Operators who prefer readable YAML playbooks and SSH over installing a service on every managed Linux host.
Teams prepared to maintain inventory, connection credentials, variables, and a deliberate collection set.
Python contributors willing to use Ansible's own sanity, unit, and integration test commands.

Who it’s NOT for

Teams that need a daemon on each managed host to enforce state continuously: Ansible's documented model is agentless and runs from a control node.
Operators who require a native Windows control node: the official installation guide supports Windows through WSL, while Windows without WSL is unsupported.
Buyers expecting the whole community module catalog in this repository: it contains ansible-core, while broad platform support lives in separately installed collections.
Contributors whose gate is a clean plain-pytest run in a fresh container: our commit a900ea9 run stopped with 7 collection/setup errors before any test passed.
Small teams unwilling to own inventories, SSH access, privilege escalation, and YAML playbooks: the 28-second install configured no target machines.

Setup reality

Our fresh Debian sandbox installed commit a900ea9 in 28 seconds, adding 42 packages and using 57 MB. The build succeeded in 6 seconds. Pytest exited 3 after 4 seconds, with 0 passed, 0 failed, and 7 collection/setup errors. Pip-audit found 0 known vulnerabilities.

Using Ansible against real machines still requires an inventory, reachable targets, and authentication for SSH or another supported transport. Most POSIX managed nodes need Python and an interactive shell account; privilege escalation, cloud plugins, and network modules add their own credentials. The larger ansible package or separate collections supply content beyond ansible-core.

The sandbox had 3 CPUs and 8 GB of RAM, ran unprivileged, and had no secrets. Its image name specified Python 3.12, while the traceback ended inside a Python 3.14.7 argparse path with SystemExit 2. The supplied log does not identify the triggering argument, so we cannot assign a cause. Native Windows control nodes require WSL.

The 28-second install gives you ansible-core alone

Our sandbox installed 42 packages in 28 seconds, which makes ansible-core easy to try. It contains Ansible's language, command-line runtime, and built-in content. The larger ansible package adds a curated set of community collections, and other collections are installed separately. Finding a module online does not mean it ships in this repository. Check the collection name and supported version before writing around it.

At commit a900ea9, the checkout held 5,790 files and about 281,873 lines of source, yet used 15.4 MB. Day-one use can still be a short YAML play sent over SSH. Working on the engine is another scale of job: plugin boundaries, collection ownership, inventory behavior, and Ansible's test tools all enter the picture. A 57 MB environment made the code cheap to install in our run. It did not make the codebase small.

What happened when we ran it

Our run of commit a900ea9 installed in 28 seconds and built in another 6 seconds on 3 CPUs with 8 GB of RAM. The unprivileged Debian container had no secrets. Pip-audit reported 0 known vulnerabilities, and the environment occupied 57 MB after 42 packages arrived. We measured repository setup only. No managed host, live playbook, task-speed benchmark, or collection integration was part of this run.

Pytest failed after 4 seconds with exit code 3. Its summary was 0 passed, 0 failed, and 7 collection/setup errors out of 7. The tail ends in Python's argparse code, where an error path raises SystemExit 2. It does not expose the invalid argument or name a missing system package. The container image specified Python 3.12, while that traceback path named Python 3.14.7. We cannot tell from the supplied tail whether that difference caused the failure.

Contributors are directed to ansible-test sanity, ansible-test units, and targeted integration runs. Our scan found 0 CI workflow files and no Dockerfile. The README still carries an Azure Pipelines badge, and the testing guide says pull requests run there. A scanner looking only for repository workflow files misses that setup.

SSH removes the target agent, while inventory becomes operating data

Ansible v2.21.4 uses an agentless model: install it on a Unix-like control node, then reach managed machines through SSH, PowerShell remoting, or another transport. Most POSIX targets need Python and an account with an interactive shell. Network modules are one documented exception. You avoid maintaining an Ansible service on every Linux host, but reachability and authentication move to the control side.

The 28-second install configured no hosts. Inventory must name targets, arrange groups, and provide connection variables. A static file can cover a small fleet; plugins can discover changing cloud resources. Both become production data, since a stale group can aim a correct playbook at the wrong machines.

Readable YAML lowers the entry cost, but it cannot promise a safe second run. Module behavior, check-mode support, variable precedence, handlers, and collection versions decide what changes. The 281,873 source lines in our checkout are a warning against treating Ansible as a thin SSH wrapper. Begin with one bounded task, inspect the changed result, and test failure recovery before widening the host pattern. That work matters more than shaving seconds from installation.

Windows can be managed, but the control node needs WSL

For the current v2.21 line, the installation guide supports nearly any Unix-like control machine with Python, including Windows through a WSL distribution. Windows without WSL is not natively supported as a control node. Teams with Windows-only administrative machines must therefore add a Linux environment somewhere, then patch it and connect it to enterprise credentials.

Managed Windows machines are a different case because Ansible can reach them through PowerShell remoting. POSIX targets usually use SSH, and some network modules do not require Python on the device. Each transport brings separate authentication and failure modes. Our 3-CPU sandbox exercised none of them. A successful 6-second build says nothing about domain authentication, host keys, proxies, or privilege escalation in your network.

A September 29 push matters more than the 859-item queue

GitHub showed 70,816 stars, 518 open issues, and 341 open pull requests when checked on September 30, 2026. The repository was pushed on September 29, recent items were updated on September 30, and v2.21.4 was released on September 8. Those dates show current maintenance despite a large public queue. They do not promise a quick answer for a niche bug, which may compete with hundreds of discussions and patches.

Ansible is the first tool I would trial for readable, central automation where installing an Ansible daemon on every target is unwanted. Inventory discipline, connection management, and collection selection are the price. If your team will develop against the core repository, reproduce ansible-test on the Python line you support. Our a900ea9 run ended with 7 collection/setup errors and no executed tests, the question its 28-second installation could not answer.

Alternatives

ProjectWhat it isPick it when
SaltAn event-driven infrastructure automation system built around remote execution and desired state.pick this instead when event-driven reactions and a master/minion operating model suit the fleet better than agentless runs.
PuppetA declarative configuration engine that applies a centralized specification across managed systems.pick this instead when resident agents and recurring desired-state enforcement are requirements.
Chef InfraA Ruby-based configuration management system centered on cookbooks and the Chef Infra Client.pick this instead when your team already uses Ruby cookbooks or the wider Chef operating model.

What people are saying

  1. [velocity-scout] ansible/ansible

Sources

  1. Ansible README
  2. Ansible repository activity
  3. Ansible-core v2.21.4 release
  4. Installing Ansible
  5. How to build your inventory
  6. Testing Ansible

More automation reviews

huashu-mac-use · cloudflare-turnstile-solver · stop-stutter · warp-masque-actions · ffmpeg-skill · fable-orchestrator · the whole board →