Practical lab guide
Lab: configure a disposable host and explain the second run
Use scoped inventory, a template, and repeatable verification.
On this page
Prepare the control and managed nodes
Use the named OrbStack Ubuntu machine and inventory from the inventory bite. Install compatible Ansible/Python versions using the official support guidance. Confirm the inventory resolves to only your lab machine and that the ping module succeeds.
Use the complete site.yml from the variables and templates bite: hosts: study, facts enabled, the two play variables, an assertion task, a template task, and the message handler. Save the referenced templates/study.conf.j2. The destination is the regular user's home; no become/root access is needed.
Preview, apply, repeat
ansible-playbook -i inventory.ini site.yml --syntax-check
ansible-playbook -i inventory.ini site.yml --limit study-vm --check --diff
ansible-playbook -i inventory.ini site.yml --limit study-vm --diff
ansible-playbook -i inventory.ini site.yml --limit study-vm --diff
This fixture contains no secret values, making diff output appropriate. Compare the template task's actual change status and the handler output across runs. The second apply should have nothing to change when values and metadata already match; investigate any difference rather than assuming idempotence.
Read the marker through the same SSH target and compare its two lines with the intended values. Change study_port once to another valid port, preview and apply, then restore the original value and apply again. The file is a fixture and no service starts listening on that port.
Explain what changed and what did not
The destination should contain environment=local and port=8080 after the default play. Read it using ssh sk-foundations@orb 'cat ~/learnwithsk-marker.txt'. In that Linux shell, stat -c '%a' ~/learnwithsk-marker.txt should show 600. Read permissions as well as contents: the module manages both.
A first apply may report no change if an earlier bite already installed the same file. That is a valid starting condition, not a reason to falsify a first-run count. Change the port to 8081 deliberately and compare its actual diff. Restore 8080 and check that a following run settles again.
The handler should appear when the template changes. It only prints a message; the fixture does not open a port or configure a running server. An invalid port should fail the assertion before the template is installed. This explains the order of the two tasks.
Cleanup
On the managed machine, remove only ~/learnwithsk-marker.txt after confirming that it is the file created by this lab. Retain the control-side inventory and playbook as evidence, or remove their specific practice files. Do not remove the OrbStack-generated SSH integration.
Checkpoint and revision
Record the target alias, actual execution account, interpreter/version, preview, first and second apply results, changed-input behavior, and cleanup. Explain why hiding changes with changed_when: false would not make a task idempotent.
As an extension, move the fixture into a role without changing its interface and repeat the same checks. Do not call the role reusable across distributions until those platforms are tested.
Revision: inventory is scope; modules express desired state; handlers react to change; check mode has limits; second-run evidence is specific to the tested state.
Answer the checkpoint
changed_when: false can hide a command's change report while that command continues to alter the machine. Idempotence is about the actual repeatable result. A second unchanged template run therefore supports a narrow claim about this file, target, and input—not every role or application.
You now have a tested sequence: identify the host, prove module access, validate inputs, preview, apply, inspect the file, repeat, and clean up. MicroBank uses the same ideas through a local connection on the Mac.
Apply this to MicroBank
After the six foundations modules, render MicroBank runtime configuration from Terraform outputs. Start with the project setup and follow its ordered steps; later implementation stages depend on the earlier files.
Sources and practice status
Primary references: Ansible check mode↗; Template module↗; OrbStack SSH↗.
Reviewed against documentation on 1 October 2026. The exercises still need to be run in your environment. Record your results and tool versions in your notes.
Your notes and evidence
Record observations, questions, or links to your work. Keep credentials out of your notes.
Back up or restore this path
Progress and notes stay in this browser. A backup contains only this learning path.