Review Ansible file path resolution

Verify Ansible’s file-search context so the intended templates and files are deployed consistently.

Description

For local src files, Ansible’s template and copy modules search relative paths in the context of roles, task files and playbooks. They do not simply use the current directory from which the command was invoked. Changes to roles and inclusion context can select an unintended file or prevent a file from being found.

Relative paths are not inherently incorrect. Managed role directories and a clear file layout can provide consistent deployments.

Potential impact

  • An unintended template or file can deploy incorrect configuration.
  • Missing files can interrupt automation, or deployment results can differ between environments.

Remediation

  • Keep role and playbook file layouts explicit, and inspect the actual search context using tools such as ansible_search_path.
  • Use verified role paths, an explicit base directory or absolute paths where needed.
  • Restrict write access to source files and directories, and confirm that the intended files are selected in the deployment environment.

Examples

The src files must be available on the control node. Absolute paths also require the same trusted files in each execution environment; destination write permissions are required separately.

Before

yaml
---
- name: 설정 파일 배포
  hosts: localhost
  tasks:
    - name: 템플릿 복사
      ansible.builtin.template:
        src: ../templates/app.conf.j2
        dest: /etc/app/app.conf
        mode: "0644"

    - name: 정적 파일 복사
      ansible.builtin.copy:
        src: ../files/banner.txt
        dest: /etc/app/banner.txt
        mode: "0644"

These paths refer to parent directories. Verify which files are selected with the actual role and playbook layout.

After

yaml
---
- name: 설정 파일 배포
  hosts: localhost
  tasks:
    - name: 템플릿 복사
      ansible.builtin.template:
        src: /opt/ansible/templates/app.conf.j2
        dest: /etc/app/app.conf
        mode: "0644"

    - name: 정적 파일 복사
      ansible.builtin.copy:
        src: /opt/ansible/files/banner.txt
        dest: /etc/app/banner.txt
        mode: "0644"

The configuration uses explicit /opt/ansible paths. Fixing the path alone does not make the file contents or permissions trustworthy.

References