Skip to content

ansible-operator

ansible-operator is a Kubernetes operator that runs Ansible playbooks against SSH-reachable hosts, on a schedule, using nothing but Kubernetes resources.

Instead of maintaining an inventory file, a control node, and a cron entry somewhere, you describe your hosts, groups, and playbooks as Custom Resources. The operator generates the Ansible inventory, manages SSH host-key trust, and dispatches playbook runs as Kubernetes CronJobs.

apiVersion: ansible-operator.lightjack.de/v1alpha1
kind: AnsibleReconcileJob
metadata:
  name: nightly-config
  namespace: default
spec:
  schedule: "0 0 * * *"        # every night at midnight
  playbookRef:
    name: base-config          # an AnsiblePlaybook in the same namespace

Why use it

  • Declarative Ansible — hosts, groups, playbooks, and schedules are all Kubernetes objects you can kubectl apply, GitOps, and RBAC like anything else in your cluster.
  • Automatic inventory generation — the operator renders a full Ansible inventory (hosts, groups, subgroups, host/group vars) from your resources on every change.
  • SSH host-key management — host keys are scanned and stored on first connect, so runs stay protected against man-in-the-middle without manual known_hosts juggling.
  • Scheduled reconciliation — every AnsibleReconcileJob becomes a Kubernetes CronJob, so playbook runs get the reliability, history, and observability of native workloads.
  • Status you can watch — each resource reports Kubernetes conditions (Ready, Progressing, Successful, ...) so you can tell at a glance whether the last run worked.

The resources at a glance

Resource Purpose
AnsibleHost A single SSH-reachable host and its credentials.
AnsibleGroup A named group of hosts and/or subgroups.
AnsiblePlaybook A playbook, stored inline or fetched from Git.
AnsibleReconcileJob A schedule that runs a playbook against the inventory.

Where to next

Project status

ansible-operator is at API version v1alpha1. The API may still change between releases.