DEV Community

Mr-T02
Mr-T02

Posted on

I Built and Broke a Real AWS Ansible Setup (So You Don't Have To)

I spent a day going from "what is Ansible" to a working, Vault-secured, dynamically-inventoried, rolling-deploy automation on real AWS EC2 instances. Here's the short version.

What it does: Spins up Nginx on any number of EC2 instances, without me touching each server by hand.

The stack:

🔑 SSH key auth — no agent installed on target servers, ever
📦 A proper Ansible role, not one giant script
🔒 Vault-encrypted secrets — safe even in a public repo
🌐 Dynamic inventory — queries AWS directly, no static IP list to maintain
🚦 Rolling deploys (serial + max_fail_percentage) — update one server at a time, auto-stop if things go wrong

The bugs that actually taught me something (not the happy-path stuff tutorials show you):

EC2 public IPs change on every stop/start — hit this three times before I stopped being surprised
A security group locked to "My IP" breaks the moment your ISP hands you a new one
dpkg lock contention from Ubuntu's own background updates, mid-deploy
WSL2 resolving an EC2 hostname to a dead-end IPv6 NAT64 address — fixed with one line in ~/.ssh/config

None of these are Ansible bugs. They're the actual texture of real infrastructure work, and no tutorial prepares you for them — you just have to hit them.

Full code + README: https://github.com/Mr-T02/ansible-aws-webserver

Top comments (0)