A network administrator is comparing configuration management tools and wants to use one that is agentless, uses YAML for playbooks, and communicates with Cisco IOS XE devices over SSH. Which tool best meets these requirements?
Trap 1: Puppet
Puppet typically requires an agent installed on managed nodes, although it can operate in agentless mode with SSH for some modules. However, its manifests are written in a Ruby-based DSL, not YAML, and its primary model is agent-based. For Cisco network devices, Puppet support often relies on dedicated modules and may not be as straightforward for pure SSH-based configuration as the tool described.
Trap 2: Chef
Chef uses Ruby-based recipes and cookbooks, not YAML, and traditionally requires a Chef client agent on managed nodes. While Chef can manage network devices through specific resources, it does not natively use YAML for its configuration definitions. The requirement for agentless operation over SSH with YAML playbooks does not align with Chef's standard architecture.
Trap 3: SaltStack
SaltStack can operate in an agentless mode using SSH, but its default communication model uses a master-minion architecture with agents. Its configuration files are written in YAML, but the typical deployment for network devices often relies on proxy minions rather than direct SSH. The scenario emphasizes agentless SSH and YAML playbooks, which is more characteristic of Ansible's standard workflow.
- A
Puppet
Why it fails: Puppet typically requires an agent installed on managed nodes, although it can operate in agentless mode with SSH for some modules. However, its manifests are written in a Ruby-based DSL, not YAML, and its primary model is agent-based. For Cisco network devices, Puppet support often relies on dedicated modules and may not be as straightforward for pure SSH-based configuration as the tool described.
- B
Chef
Why it fails: Chef uses Ruby-based recipes and cookbooks, not YAML, and traditionally requires a Chef client agent on managed nodes. While Chef can manage network devices through specific resources, it does not natively use YAML for its configuration definitions. The requirement for agentless operation over SSH with YAML playbooks does not align with Chef's standard architecture.
- C
SaltStack
Why it fails: SaltStack can operate in an agentless mode using SSH, but its default communication model uses a master-minion architecture with agents. Its configuration files are written in YAML, but the typical deployment for network devices often relies on proxy minions rather than direct SSH. The scenario emphasizes agentless SSH and YAML playbooks, which is more characteristic of Ansible's standard workflow.
- D
Ansible
Ansible is agentless, connecting to devices over SSH, and uses YAML-formatted playbooks to define automation tasks. It includes modules such as ios_config and ios_command that specifically target Cisco IOS XE devices. This matches all stated requirements: no agent, YAML syntax, and SSH communication, making it the correct choice for this scenario.