AWX in Action
L'orchestration Ansible à grande échelle
Formats : Cours en ligne, Kindle, Broché
Ce que vous apprendrez
- Installer AWX sur Docker ou Kubernetes avec l'AWX Operator, et déboguer l'architecture
- Structurer organisations, équipes et RBAC au-delà d'une équipe de cinq personnes
- Bâtir des inventaires statiques, dynamiques, construits et intelligents pour votre environnement
- Créer modèles de tâche, questionnaires et modèles de workflow avec approbations et branches
- Bâtir des environnements d'exécution prêts pour la production avec Ansible Builder et Ansible Runner
- Exploiter AWX en haute disponibilité : instances d'exécution et de relais, groupes d'instances, réglage de capacité
- Lancer des tâches AWX depuis vos chaînes d'intégration avec la CLI et l'API
À propos de ce livre
Vous connaissez Ansible et vos playbooks fonctionnent, mais l'équipe se noie dans la prolifération de YAML, les planifications manquées et les "qui a lancé quoi et quand" auxquels personne ne sait répondre. AWX règle cela, à condition de savoir s'en servir. Voici le guide pratique pour les utilisateurs d'Ansible prêts à passer des exécutions en ligne de commande à une plateforme d'automatisation de qualité production.
Il couvre l'installation d'AWX sur Docker ou Kubernetes avec l'AWX Operator, et la compréhension de l'architecture - pods web, pods de tâches, PostgreSQL, receptor - assez finement pour la déboguer et pas seulement la déployer. Puis les organisations, les équipes et un RBAC fin ; les types de justificatifs et les coffres de secrets externes ; les inventaires statiques, dynamiques, construits et intelligents ; les modèles de tâche, les questionnaires et les modèles de workflow avec nœuds d'approbation et branches conditionnelles ; la CLI et l'API d'AWX ; les environnements d'exécution sur mesure bâtis avec Ansible Builder et Ansible Runner ; la haute disponibilité avec instances d'exécution et de relais, groupes d'instances et groupes de conteneurs ; et les vues d'état, les flux d'activité, les notifications, les métriques Prometheus et les journaux structurés. Il se clôt sur un exemple de bout en bout qui lance des tâches depuis la CI.
Table des matières
-
Why This Book Exists
- Who This Guide Is For
- What You Will Learn
- About the Author
- Join the Community
- Your Feedback Matters
-
How to Get the Most Out of This Book
- What This Book Asks of You
- Conventions
-
AWX Decoded: Architecture, Ecosystem, and the Tradeoffs That Matter
- How Ansible Became AWX
- Ansible Core vs. AWX: When Each One Wins
- What Upstream AWX Doesn't Give You
- Which One Should You Actually Pick?
- Under the Hood: The AWX Architecture
-
From Zero to AWX: A Kubernetes Install That Actually Works
- What You'll Need: Hardware, OS, and Network
- Deploying AWX on K3s With the Operator
-
The AWX Object Model: Organizations, Teams, and RBAC From Day One
- Organizations: Where Everything Lives
- Users and the Three User Types
- Teams: Less Permission Pain
- The Object Model in One Page
-
Inventories Done Right: From Static Hosts to Dynamic Cloud Discovery
- What Inventories Actually Do
- Creating Your First Inventory
- Credentials: How AWX Connects to Hosts
- Constructed Inventories in Depth
- Dynamic Inventories: Letting the Cloud Build Your Inventory
-
Execution Environments Demystified: Build Once, Run Anywhere, Pin Every Version
- Why Execution Environments Exist
- What Happens Between "Launch" and the Pod
- Meet Ansible Builder
- Ansible Runner: The Wrapper Inside Every EE
- Adding and Managing EEs in AWX
- Building Your First Custom EE
- What Builder Actually Does Under the Hood
-
Scale AWX Without Breaking It: Mesh, Hop Nodes, and Capacity Planning
- Control Nodes: The Brain of the Cluster
- Execution Instances: Where Jobs Actually Run
- Hop Nodes: Reaching Across Firewalls and NATs
- Hybrid Nodes (and Why You Won't Use Them on Kubernetes)
- Instance Groups: Splitting Workloads by Intent
- Capacity, Forks, and the Math Behind Scheduling
- Container Groups: Running Jobs as Kubernetes Pods
- Seeing the Whole Mesh: The Topology View
-
From Playbook to Production: Projects, Templates, Jobs, and Workflows in Practice
- Ad-Hoc Commands: One-Liners Without a Playbook
- Projects: Where Your Playbooks Live
- Job Templates: The Reusable Definition
- Launching Your First Job
- Scheduling Jobs (the Right and Wrong Ways)
- Workflow Templates: Chaining Jobs Into a DAG
- Surveys: Turning Templates Into Forms
- Key Objects and Their Relationships in Task Automation
-
What Really Happens When You Hit Launch: The AWX Job Lifecycle
- Step 1: User launches a job
- Step 2: Task Manager picks up the pending job
- Step 3: pg_notify hands off to the dispatcher
- Step 4: TaskWorker prepares the payload
- Step 5: Receptor routes the work
- Step 6: The playbook runs in the EE container
- Step 7: Events flow back
-
Skip the UI: Driving AWX Entirely From the Command Line
- What the AWX CLI Actually Is
- Why Bother With the CLI?
- Installing the CLI on Any Platform
- Three Ways to Authenticate
- OAuth Applications: Per-Integration Credentials
- Generating Tokens From an Application
- Using the CLI in Real Workflows
-
From Git Push to Running PostgreSQL: An End-to-End AWX Workflow
- The Building Blocks: Custom EE, Project, and Job Templates
- Chaining Deploy and Check Into One Workflow
- Monitoring on a Schedule, Alerting on Failure
- Launching the Workflow From the CLI
- Triggering Workflows From CI: A GitHub Actions Example
-
Inside the AWX Settings Menu: Auth Methods, Job Limits, and the Defaults Worth Changing
- Authentication: SSO, LDAP, OIDC, and the Local Fallback
- Jobs: Ad Hoc Module Allowlist, Fact Cache TTL, and Job Limits
- System: Activity Stream, Base URL, and Reverse Proxy Headers
- Auth Behaviors: Basic Auth, Sessions, and OAuth2 Tokens
- Logging: Shipping AWX Events to an Aggregator
- UI: Custom Logo and Login Message
- Troubleshooting: Keep Job Dirs, Profile Requests, Receptor Cleanup
-
Watching AWX: Status Views, Notifications, Logs, and Prometheus Metrics
- Status Views in the AWX UI
- Management Jobs: AWX's Built-In Cleanup Schedules
- Notifications: Templates, Custom Messages, and Inheritance Rules
- Logs: AWX Pods, Receptor Nodes, and Where to Look First
- Metrics: The Prometheus Endpoint and What It Exposes
-
Afterword: Where to Go From Here
- What's Next?
- Your Feedback Matters
Pour qui
Utilisateurs Ansible confirmés, ingénieurs DevOps, SRE, administrateurs système et équipes plateforme qui exploitent Ansible comme une infrastructure de production.
À propos de l'auteur
Aymen El Amri est ingénieur logiciel, auteur et maker. Il dirige eralabs, a construit FAUN.dev, et écrit sur les systèmes cloud native, l'ingénierie de l'IA et les outils pour développeurs (developer tooling). Qui est Aymen.