Migrates 20 topic files from claude-foundations/best-practices/ to this standalone repo. Adds BESTPRACTICES.md index, CLAUDE.md conventions, and updated README.md. Container agents clone this repo to /best-practices. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1.7 KiB
1.7 KiB
Ansible
Inventory and Execution
- Always pass
-i inventory.ymlexplicitly or run from the directory containingansible.cfg - Playbooks that can't find inventory skip silently with no error — a common source of "it ran but nothing happened" confusion
- Variables that need customisation go in
inventory.ymlfiles, not scattered across role defaults
Role Structure
- Roles follow standard structure:
tasks/main.yml,templates/*.j2,handlers/main.yml - Jinja2 templates have
.j2extension and include a "managed by Ansible" header comment
Template Safety
- Never use placeholder values with
-efor vars that template config files. Using-e "var=dummy"will overwrite live configs with garbage. Either read real values, use--skip-tagsto skip templating tasks, or restructure roles so sensitive templates are in a separate tag.
Credential Safety
- Pass secrets via
@filenot-eon the command line —-e "key=value"exposes secrets inpsoutput - Use temp files with
trap rmcleanup:-e "@${tmpfile}"
Module Gotchas
docker_compose_v2doesn't supportstate: restarted— userecreate: alwaysinsteadansible.builtin.unarchivewithremote_srcandextra_opts: --strip-componentsis unreliable — useget_url+command: tarseparatelyget_urlwon't re-download when the URL changes but the destination filename stays the same — use a version marker file to detect changes
Service Restarts
- Some services (dnsmasq, etc.) need container restarts for config changes to take effect
- Ansible handlers handle this, but always verify the change took effect (e.g.,
dig @<ip> <record> +short)
Docker Compose
network_mode: hostignoresports:mappings — removeports:to avoid warnings