Ansible CI/CD: an empty --limit ran a play on all 500 hosts

Опубликовано: 30 Июль 2026
на канале: TheCodeForge
No
0

An empty `--limit $HOSTS` ran a restart-postgresql play on all 500 hosts. Root cause: Empty `--limit` means no limit, so Ansible targeted everything. The fix: Require/validate the limit; gate CI with `--check`; fail on empty.

A production war story from the TheCodeForge Ansible series — the incident, why it happened, and the exact fix.

⏳ Timestamps:
0:00 - Cold open: ok=500 changed=500
0:08 - Intro
0:16 - What Is Ansible CI/CD?
0:27 - Jenkins Vault Setup
0:45 - GitHub Actions Vault
1:03 - Limit Hosts in CI
1:19 - Check Mode Gate
1:35 - Molecule Testing
1:54 - ok=500 changed=500
2:14 - Empty --limit string
2:26 - The Fix
2:37 - ⚠ Gotcha: Empty --limit runs on all hosts
2:45 - ⚠ Gotcha: Empty --limit caused production outage
2:55 - ⚠ Gotcha: Action doesn't support multiple vault IDs
3:04 - ⚠ Gotcha: Modules like command always report changed
3:14 - ⚠ Gotcha: Echoing vault password into logs
3:22 - Version Compatibility: Vault ID Syntax
3:51 - Production Caveat: Check Mode Limitations
4:09 - Debugging Guide
4:17 - Interview Questions
4:36 - FAQ
4:55 - Key Takeaways
5:06 - Next up
5:21 - Wrap-up

👉 Full article + code: https://thecodeforge.io/devops/ansibl...
⏭ Next up: Ansible Performance Tuning

#ansible #devops #automation