Manual server provisioning is a relic of the past. In 2026, Ansible remains the gold standard for infrastructure automation thanks to its agentless architecture, declarative playbooks, and massive community ecosystem. Here is how to set up a production-grade provisioning pipeline.
Why Ansible Still Dominates
Despite competition from Pulumi and CDK, Ansible holds strong because it requires zero agents on target hosts. SSH is all you need. This makes it ideal for brownfield environments where installing agents is impractical or restricted by security policies.
Project Structure That Scales
infrastructure/
inventories/
production/
hosts.yml
group_vars/
staging/
hosts.yml
roles/
common/
webserver/
database/
monitoring/
playbooks/
site.yml
deploy.yml
ansible.cfg
Separating inventories from roles ensures the same playbook works across environments. Use group_vars to customize per-environment secrets and configuration.
A Real-World Provisioning Playbook
---
- name: Provision web servers
hosts: webservers
become: yes
roles:
- common
- { role: webserver, nginx_workers: "{{ ansible_processor_vcpus }}" }
- { role: monitoring, when: monitoring_enabled | default(true) }
tasks:
- name: Ensure application directory exists
file:
path: /opt/app
state: directory
owner: deploy
mode: '0755'
- name: Deploy application config
template:
src: app.conf.j2
dest: /opt/app/config.yml
notify: restart app
Testing with Molecule
Never push untested playbooks. Molecule spins up Docker or Vagrant instances, runs your roles, and validates with Testinfra assertions. Add it to your CI pipeline so every merge request gets automated verification.
Key Takeaways
- Use roles for reusability, playbooks for orchestration
- Keep secrets in Ansible Vault or an external secrets manager
- Test every change with Molecule before deploying to production
- Version your inventory alongside your playbooks
- Use tags to run specific parts of large playbooks