Field Notes
"Already compliant" is a success state
From the chapter: The cluster that almost wasn't
An Ansible task should succeed when the machine is already in the desired state.
swapoff -a exits with rc=64 when there's no swap to disable — which failed an Ansible task on nodes that were already correct.
Idempotent automation treats the desired state as success, including when there is nothing to change:
yaml
- name: Swap off if any swap exists
shell: |
if swapon --show | grep -q .; then
swapoff -a && echo "swap disabled"
else
echo "no swap present - already compliant"
fi
register: swap_task
changed_when: "'swap disabled' in swap_task.stdout"Related: changed_when: 'stdout is defined' fails on newer ansible-core — use register: and reference the variable. Registering the result makes the condition portable.
Discussion
Questions, corrections, or a different approach? Join the discussion. Comments are public and hosted on GitHub; a GitHub account is needed to comment.