CompTIA Linux+ (XK0-006)Automation, Orchestration and ScriptingMedium
A system administrator is using Ansible to manage server configurations. They need to create a new user account named `devuser` on a target server, ensure it belongs to the `developers` group, and set its primary shell to `/bin/bash`. If the user already exists, Ansible should ensure its properties match these specifications. Which Ansible module and parameters should be used?
- A`ansible.builtin.shell`: `id -u devuser || useradd -s /bin/bash -g developers devuser`
- B`ansible.builtin.user`: `name=devuser shell=/bin/bash groups=developers append=yes state=present`
- C`ansible.builtin.account`: `username=devuser shell=/bin/bash group=developers`
- D`ansible.builtin.command`: `useradd -s /bin/bash -g developers devuser`
Show answer & explanationAnswer & explanation
Correct answer: B. `ansible.builtin.user`: `name=devuser shell=/bin/bash groups=developers append=yes state=present`
The `ansible.builtin.user` module is specifically designed for managing user accounts in an idempotent way. It allows specifying the username, shell, and groups, and `state=present` ensures the user exists with those properties or creates it if not.
Why the other options are wrong
- A. The `shell` module is similar to `command` and suffers from the same idempotency issues. It requires manual checks and is less declarative than dedicated modules.
- C. There is no standard `ansible.builtin.account` module. The correct module for user management is `ansible.builtin.user`.
- D. The `command` module is not idempotent for user management; it would fail if the user already exists unless complex conditional logic is added. It's generally not recommended for managing system resources.
Ansible `user` Module
An Ansible module (`ansible.builtin.user`) used for managing user accounts on remote hosts in an idempotent manner.
- Ensures users exist or are removed (`state=present`/`absent`).
- Can set user properties like `shell`, `groups`, `uid`, `home`, `password`.
- Idempotent: running it multiple times yields the same result without errors.
Memory trick: Ansible modules manage resources perfectly, just like a chef uses specific tools for each ingredient.