Ansible Cisco IOS Config Backup and Drift Check Playbook - 夜莺博客

Ansible Cisco IOS Config Backup and Drift Check Playbook

Two automation jobs pay for themselves before any configuration push does: collecting a reliable configuration backup, and detecting drift from the standard. Both are read-only, which means they can run daily against production without a change record — and both make every later change safer. This article builds them as Ansible playbooks using the cisco.ios collection.

Inventory and connection variables

# inventory/group_vars/switches.yml
ansible_connection: ansible.netcommon.network_cli
ansible_network_os: cisco.ios.ios
ansible_become: yes
ansible_become_method: enable
ansible_user: netadmin
ansible_password: "{{ vault_network_password }}"
ansible_become_password: "{{ vault_enable_password }}"

Put credentials in an ansible-vault encrypted file from day one. network_cli tells Ansible to treat the target as a network device, and become_method: enable enters privileged EXEC before tasks run.

Playbook 1: configuration backup

- name: Backup Cisco IOS running configurations
  hosts: switches
  gather_facts: false
  vars:
    backup_dir: "/opt/network-backups/{{ ansible_date_time.date }}"
  tasks:
    - name: Create backup directory
      ansible.builtin.file:
        path: "{{ backup_dir }}"
        state: directory
        mode: "0755"
      delegate_to: localhost
      run_once: true

    - name: Collect running configuration
      cisco.ios.ios_command:
        commands: show running-config
      register: config_out

    - name: Save the configuration
      ansible.builtin.copy:
        content: "{{ config_out.stdout[0] }}"
        dest: "{{ backup_dir }}/{{ inventory_hostname }}_running-config.txt"
      delegate_to: localhost

gather_facts: false is required on network devices — the default fact gathering assumes a Python interpreter on the target. Schedule this with cron (0 2 * * *) or a CI job, and keep the files under version control so a diff between yesterday and today is a one-command answer to "what changed".

Playbook 2: drift check in check mode

- name: Standard access-port block (report-only)
  hosts: switches
  gather_facts: false
  tasks:
    - name: Detect drift on standard access ports
      cisco.ios.ios_config:
        lines:
          - switchport mode access
          - switchport access vlan 30
          - spanning-tree portfast
          - spanning-tree bpduguard enable
        parents: "interface {{ item }}"
        match: line
      loop: "{{ access_ports }}"
      check_mode: yes
      changed_when: false
      register: drift

    - name: Report interfaces that would change
      ansible.builtin.debug:
        msg: "{{ item.item }} needs the standard block"
      loop: "{{ drift.results }}"
      when: item.changed

check_mode: yes makes the module report what would change without touching the device, and changed_when: false stops the play reporting a failure-free run as "changed". The result is a list of interfaces that have drifted from the standard — which is exactly what a compliance report should contain.

Turning detection into remediation

Once the drift report runs clean for a few weeks and the standard block is trusted, promote the same task out of check mode and add save_when: modified, which writes the running configuration to NVRAM only when a change was actually made. Keep the backup playbook running regardless: a change without a pre-change backup is the one thing automation should never make easy to skip.

Related reading: Ansible Cisco network automation 101, Ansible network resource modules, NTC templates and TextFSM parsing.

原文链接:https://packet-switched.com/ansible-network-automation-managing-cisco-ios-at-scale-with-netdevops