Infrastructure as Code (IaC) means managing servers, networks, and services through code instead of manual configuration. Ansible is one of the most accessible ways to start with IaC.
Ansible vs Other IaC Tools
| Feature | Ansible | Terraform | CloudFormation |
|---|---|---|---|
| Approach | Procedural | Declarative | Declarative |
| Agent | Agentless (SSH) | Agentless (API) | Agentless (API) |
| Language | YAML | HCL | JSON/YAML |
| Best for | Configuration | Provisioning | AWS only |
| Learning curve | Low | Medium | Medium |
| State file | No | Yes | Managed |
Key insight: Ansible and Terraform are complementary. Use Terraform to provision infrastructure (create VMs, networks, databases) and Ansible to configure it (install software, deploy apps, manage services).
IaC with Ansible Playbooks
A playbook is your infrastructure definition:
---
- name: Configure web server fleet
hosts: webservers
become: true
vars:
app_port: 8080
node_version: "22"
tasks:
- name: Update system packages
apt:
upgrade: dist
update_cache: true
cache_valid_time: 3600
- name: Install required packages
apt:
name:
- nginx
- certbot
- python3-certbot-nginx
state: present
- name: Deploy Nginx configuration
template:
src: templates/nginx.conf.j2
dest: /etc/nginx/sites-available/default
notify: Reload Nginx
- name: Enable and start Nginx
service:
name: nginx
state: started
enabled: true
handlers:
- name: Reload Nginx
service:
name: nginx
state: reloadedThis playbook is: - Version controlled in Git - Repeatable across any number of servers - Idempotent — safe to run multiple times - Self-documenting — readable YAML
Structuring IaC Projects
Organize your infrastructure code:
infrastructure/
inventory/
production.yml
staging.yml
group_vars/
webservers.yml
dbservers.yml
roles/
common/
nginx/
postgresql/
monitoring/
playbooks/
site.yml
deploy.yml
backup.yml
ansible.cfgMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Roles as Reusable Modules
Roles are the building blocks of Ansible IaC:
ansible-galaxy init roles/nginxroles/nginx/tasks/main.yml:
---
- name: Install Nginx
apt:
name: nginx
state: present
when: ansible_os_family == "Debian"
- name: Deploy configuration
template:
src: nginx.conf.j2
dest: /etc/nginx/nginx.conf
notify: Restart Nginx
- name: Ensure Nginx is running
service:
name: nginx
state: started
enabled: trueUse roles in your main playbook:
---
- name: Full infrastructure setup
hosts: all
become: true
roles:
- common
- { role: nginx, when: "'webservers' in group_names" }
- { role: postgresql, when: "'dbservers' in group_names" }
- monitoringEnvironment Management
Use inventory files per environment:
inventory/production.yml:
all:
children:
webservers:
hosts:
web1.prod.example.com:
web2.prod.example.com:
dbservers:
hosts:
db1.prod.example.com:
postgresql_max_connections: 200inventory/staging.yml:
all:
children:
webservers:
hosts:
web1.staging.example.com:
dbservers:
hosts:
db1.staging.example.com:
postgresql_max_connections: 50Deploy to staging:
ansible-playbook -i inventory/staging.yml playbooks/site.ymlDeploy to production:
ansible-playbook -i inventory/production.yml playbooks/site.ymlSame code, different environments.
Secrets Management
Use Ansible Vault for sensitive data:
# Create encrypted variables
ansible-vault create group_vars/dbservers/vault.ymlvault_db_password: "supersecret123"
vault_api_key: "ak_live_abc123"Reference in playbooks:
- name: Configure database
postgresql_user:
name: app
password: "{{ vault_db_password }}"Run with vault:
ansible-playbook site.yml --ask-vault-passGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →CI/CD Integration
Add Ansible to your deployment pipeline:
# .github/workflows/deploy.yml
name: Deploy Infrastructure
on:
push:
branches: [main]
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Ansible
run: pip install ansible
- name: Run playbook
run: |
ansible-playbook \
-i inventory/production.yml \
playbooks/deploy.yml
env:
ANSIBLE_VAULT_PASSWORD: ${{ secrets.VAULT_PASSWORD }}IaC Best Practices
- Version control everything — playbooks, roles, inventory, variables
- Use roles for reusability and organization
- Encrypt secrets with Ansible Vault
- Test in staging first — identical to production, smaller scale
- Use
--checkmode for dry runs before applying changes - Tag tasks for selective execution
- Document with comments in your YAML files
What's Next?
Our Ansible Automation in 30 Minutes course walks through real IaC scenarios with hands-on labs. The first lesson is free — no setup required.
---
Ready to go deeper? Check out our hands-on course: Ansible Quickstart — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Ansible vs Terraform When to Use
Ansible and Terraform solve different infrastructure problems. Learn when to use each, when to use both together, and how they complement each other.
Ansible Inventory: Static and Dynamic
Master Ansible inventory in INI and YAML formats. Learn host groups, variables, dynamic inventory plugins for AWS and Azure, and patterns for scaling.
Terraform Ansible Kubernetes Stack
Combine Terraform, Ansible, and Kubernetes for complete DevOps infrastructure. Provision, configure, and deploy end to end.
Ansible Inventory Management Guide
Master Ansible inventory management with static and dynamic inventories, host groups, variables, patterns, and seamless cloud provider integration.
Ansible Jinja2 Templates Guide
Master Jinja2 templates in Ansible for dynamic configuration. Variables, filters, loops, conditionals, and real-world config file generation examples.
Ansible Playbook for Docker Install
Automate Docker installation on Ubuntu and RHEL with an Ansible playbook. Includes Compose plugin and post-install steps.
Explore topics
Browse more articles on the topics covered here.