CompTIA Linux+ (XK0-006)Automation, Orchestration and ScriptingMedium

A system administrator is using Ansible to manage server configurations. They need to create a new user account named `devuser` on a target server, ensure it belongs to the `developers` group, and set its primary shell to `/bin/bash`. If the user already exists, Ansible should ensure its properties match these specifications. Which Ansible module and parameters should be used?

  1. A`ansible.builtin.shell`: `id -u devuser || useradd -s /bin/bash -g developers devuser`
  2. B`ansible.builtin.user`: `name=devuser shell=/bin/bash groups=developers append=yes state=present`
  3. C`ansible.builtin.account`: `username=devuser shell=/bin/bash group=developers`
  4. D`ansible.builtin.command`: `useradd -s /bin/bash -g developers devuser`
Show answer & explanation

Correct answer: B. `ansible.builtin.user`: `name=devuser shell=/bin/bash groups=developers append=yes state=present`

The `ansible.builtin.user` module is specifically designed for managing user accounts in an idempotent way. It allows specifying the username, shell, and groups, and `state=present` ensures the user exists with those properties or creates it if not.

Why the other options are wrong

  • A. The `shell` module is similar to `command` and suffers from the same idempotency issues. It requires manual checks and is less declarative than dedicated modules.
  • C. There is no standard `ansible.builtin.account` module. The correct module for user management is `ansible.builtin.user`.
  • D. The `command` module is not idempotent for user management; it would fail if the user already exists unless complex conditional logic is added. It's generally not recommended for managing system resources.

Ansible `user` Module

An Ansible module (`ansible.builtin.user`) used for managing user accounts on remote hosts in an idempotent manner.

  • Ensures users exist or are removed (`state=present`/`absent`).
  • Can set user properties like `shell`, `groups`, `uid`, `home`, `password`.
  • Idempotent: running it multiple times yields the same result without errors.

Memory trick: Ansible modules manage resources perfectly, just like a chef uses specific tools for each ingredient.

More Automation, Orchestration and Scripting questions