Agent skill

Ansible Infrastructure Automation

by RightNow-AI in RightNow-AI/openfang

Guidance for writing idempotent Ansible playbooks, roles and inventories, with patterns for handlers, rolling deployments, Vault secrets and error handling.

Apache-2.0Auto-check passedDevOps & Cloud

Install Ansible Infrastructure Automation

skills CLI
$ npx skills add RightNow-AI/openfang --skill ansible -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RightNow-AI/openfang ansible --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RightNow-AI/openfang.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/openfang-skills/bundled/ansible .claude/skills/ansible && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ansible
GitHub stars
18k
Token cost
~730 tokens
SKILL.md length
373 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guidance for writing idempotent Ansible playbooks, roles and inventories, with patterns for handlers, rolling deployments, Vault secrets and error handling.

  • Writing a new playbook or role for server configuration
  • SKILL.md covers Key Principles, Techniques, Common Patterns and Pitfalls to Avoid
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Organizing inventories and variables across many hosts

What it does

This skill sets the agent up as an Ansible automation engineer who writes idempotent, well-structured playbooks. Its principles: every task is safe to run twice, reusable roles and collections replace monolithic playbooks, descriptive task names make dry-run output read like a deployment plan, secrets stay encrypted with Ansible Vault, and playbooks are tested with molecule or ansible-lint before they touch production inventory.

Techniques include a fixed ordering of play sections, scaffolding roles with `ansible-galaxy init`, YAML inventories with group_vars and host_vars, Jinja2 filters such as `default` and `mandatory`, inline encryption with `ansible-vault encrypt_string`, and `block/rescue/always` for error handling. Patterns cover handlers that fire once per play, rolling deployments with `serial` and `max_fail_percentage`, JSON-file fact caching and platform-specific task files chosen by `ansible_os_family`. It also warns against `command` or `shell` where a dedicated module exists.

When your agent uses it

  • Writing a new playbook or role for server configuration
  • Organizing inventories and variables across many hosts
  • Planning a rolling deployment that halts when too many hosts fail
  • Encrypting secrets that live in Ansible variables

Example prompts

  • “Write an Ansible role that installs nginx and restarts it only when the config changes.”
  • “Turn this shell script into idempotent Ansible tasks.”
  • “Set up a rolling update playbook that updates two hosts at a time and stops on failures.”
  • “Encrypt the database password in group_vars with Ansible Vault.”

Requirements

  • Ansible, including `ansible-galaxy` and `ansible-vault`

What it can do on your machine

Read from SKILL.md and the folder at commit acf2587. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ansible Infrastructure Automation loads about 730 tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 373 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~730

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from RightNow-AI/openfang at commit acf2587, republished under its Apache-2.0 licence (© RightNow-AI). 373 words, ~730 tokens.

Download SKILL.mdSave it as .claude/skills/ansible/SKILL.md (or your agent's skills folder).
name
ansible
description
Ansible automation expert for playbooks, roles, inventories, and infrastructure management

Ansible Infrastructure Automation

You are a seasoned infrastructure automation engineer with deep expertise in Ansible. You design playbooks that are idempotent, well-structured, and production-ready. You understand inventory management, role-based organization, Jinja2 templating, and Ansible Vault for secrets. Your automation follows the principle of least surprise and works reliably across diverse environments.

Key Principles

  • Every task must be idempotent: running it twice produces the same result as running it once
  • Use roles and collections to organize reusable automation; avoid monolithic playbooks
  • Name every task descriptively so that dry-run output reads like a deployment plan
  • Keep secrets encrypted with Ansible Vault and never commit plaintext credentials
  • Test playbooks with molecule or ansible-lint before applying to production inventory

Techniques

  • Structure playbooks with hosts:, become:, vars:, pre_tasks:, roles:, and post_tasks: sections in that order
  • Use ansible-galaxy init to scaffold roles with standard directory layout (tasks, handlers, templates, defaults, vars, meta)
  • Write inventories in YAML format with group_vars and host_vars directories for variable hierarchy
  • Apply Jinja2 filters like | default(), | mandatory, | regex_replace() for robust template rendering
  • Use ansible-vault encrypt_string for inline variable encryption within otherwise plaintext files
  • Leverage block/rescue/always for error handling and cleanup tasks within playbooks
Show full SKILL.md (182 more words)Show less

Common Patterns

  • Handler Notification: Use notify: restart nginx on configuration change tasks, with a corresponding handler that only fires once at the end of the play regardless of how many tasks triggered it
  • Rolling Deployment: Set serial: 2 or serial: "25%" on the play to update hosts in batches, combined with max_fail_percentage to halt on excessive failures
  • Fact Caching: Enable fact_caching = jsonfile in ansible.cfg with a cache timeout to speed up subsequent runs against large inventories
  • Conditional Includes: Use include_tasks with when: conditions to load platform-specific task files based on ansible_os_family

Pitfalls to Avoid

  • Do not use command or shell modules when a dedicated module exists; modules provide idempotency and change detection that raw commands lack
  • Do not store vault passwords in plaintext files within the repository; use a vault password file outside the repo or integrate with a secrets manager
  • Do not rely on gather_facts: true for every play; disable it when facts are not needed to reduce execution time on large inventories
  • Do not nest roles more than two levels deep; excessive nesting makes dependency tracking and debugging extremely difficult

© RightNow-AI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/openfang-skills/bundled/ansible of RightNow-AI/openfang.

Open the folder on GitHubat commit acf2587

Compare with similar skills

Ansible Infrastructure Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ansible Infrastructure Automation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ansible Infrastructure Automation this skillRightNow-AI/openfang18k—~730Automated safety check: PassApache-2.0
Django Deployment Test Loophashgraph-online/awesome-codex-plugins1.3k—~851Automated safety check: PassMIT
Spa Create Configsplunk/splunk-platform-automator138—~3.5kAutomated safety check: PassProprietary
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Spa Add Test Scenariosplunk/splunk-platform-automator138—~2.2kAutomated safety check: PassProprietary
Managing Configurationancoleman/ai-design-components525—~2.9kAutomated safety check: PassMIT

Similar skills

  • Django Deployment Test Loop

    hashgraph-online/awesome-codex-plugins

    Make Django deployment changes test-driven across Docker, production settings, Gunicorn, WhiteNoise/static files, environment variables, Ansible/server setup, staging smoke tests, and release checks.

    1.3k GitHub stars~851 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Spa Create Config

    splunk/splunk-platform-automator

    A skill your agent uses when creating or updating splunkconfig.yml, designing Splunk Enterprise lab topology, multisite IDXC, SHC layout, architecture plan before config, or AWS Terraform block for…

    138 GitHub stars~3.5k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Spa Add Test Scenario

    splunk/splunk-platform-automator

    A skill your agent uses when adding app scope/routing test coverage (deployer, CM, DS, direct).

    138 GitHub stars~2.2k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Managing Configuration

    ancoleman/ai-design-components

    Guide users through creating, managing, and testing server configuration automation using Ansible.

    525 GitHub stars~2.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • Sdaf Ha Topology

    Azure/sap-automation

    Official

    Choose the documented SDAF high-availability design before SAP-system deployment.

    146 GitHub stars~1.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from RightNow-AI/openfang

All 68 skills in this repo
  • Reference of CSS selectors, step-by-step web workflows and error recovery tactics for an agent that browses, fills forms and compares prices on live sites.

    18k GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction.

    18k GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Lead Generation Research Guide

    RightNow-AI/openfang

    Reference knowledge for AI lead generation: building an ideal customer profile, researching prospects on the web, enriching lead records and finding email formats.

    18k GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Video Clipping Reference

    RightNow-AI/openfang

    Command reference for cutting clips from online video: yt-dlp downloads, whisper transcription, SRT subtitle files and ffmpeg processing, with Windows, macOS and Linux differences.

    18k GitHub stars~4.1k tokensUpdated 3 mo ago
    Auto-check: warnings
  • Forecasting Expert Knowledge

    RightNow-AI/openfang

    Reference knowledge for AI forecasting: superforecasting principles, a signal taxonomy, confidence calibration rules and reasoning chains for making and tracking predictions.

    18k GitHub stars~2.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Deep Research Methodology

    RightNow-AI/openfang

    Reference knowledge for AI deep research: a five-phase process, strategies by question type, CRAAP source scoring, cross-referencing, synthesis and citation formats.

    18k GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Ansible Infrastructure Automation

What does Ansible Infrastructure Automation do?

Guidance for writing idempotent Ansible playbooks, roles and inventories, with patterns for handlers, rolling deployments, Vault secrets and error handling. This skill sets the agent up as an Ansible automation engineer who writes idempotent, well-structured playbooks. Its principles: every task is safe to run twice, reusable roles and collections replace monolithic playbooks, descriptive task names make dry-run output read like a deployment plan, secrets stay encrypted with Ansible Vault, and playbooks are tested with molecule or ansible-lint before they touch production inventory.

When should I use Ansible Infrastructure Automation?

Ansible Infrastructure Automation fits situations like: writing a new playbook or role for server configuration; organizing inventories and variables across many hosts; planning a rolling deployment that halts when too many hosts fail; encrypting secrets that live in Ansible variables.

How do I install Ansible Infrastructure Automation in Claude Code?

Run `npx skills add RightNow-AI/openfang --skill ansible -a claude-code`. Or copy the skill folder (crates/openfang-skills/bundled/ansible in RightNow-AI/openfang) into .claude/skills/ansible in your project. Claude Code loads it when a task matches its description.

How do I install Ansible Infrastructure Automation in Codex?

Run `npx skills add RightNow-AI/openfang --skill ansible -a codex`. Or copy the skill folder (crates/openfang-skills/bundled/ansible in RightNow-AI/openfang) into .agents/skills/ansible in your project. Codex loads it when a task matches its description.

Can I use Ansible Infrastructure Automation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RightNow-AI/openfang --skill ansible -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ansible, .gemini/skills/ansible, .github/skills/ansible and .opencode/skills/ansible in your project.

What does Ansible Infrastructure Automation need to run?

SKILL.md names no scripts, command-line tools or credentials: Ansible Infrastructure Automation is instructions for the agent only. Our summary lists: Ansible, including `ansible-galaxy` and `ansible-vault`.

Does Ansible Infrastructure Automation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ansible Infrastructure Automation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ansible Infrastructure Automation use?

Ansible Infrastructure Automation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ansible Infrastructure Automation use?

About 730 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ansible Infrastructure Automation?

Skills that share tags, products or a category with Ansible Infrastructure Automation: Django Deployment Test Loop (hashgraph-online/awesome-codex-plugins, 1.3k stars), Spa Create Config (splunk/splunk-platform-automator, 138 stars), Azure Bicep Skill (timothywarner-org/claude-code, 224 stars) and Spa Add Test Scenario (splunk/splunk-platform-automator, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ansible Infrastructure Automation?

RightNow-AI (a GitHub organization) maintains it in RightNow-AI/openfang, which has 18,214 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on July 2, 2026.

Source: RightNow-AI/openfang on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.