Description
For local src files, Ansible’s template and copy modules search relative paths in the context of roles, task files and playbooks. They do not simply use the current directory from which the command was invoked. Changes to roles and inclusion context can select an unintended file or prevent a file from being found.
Relative paths are not inherently incorrect. Managed role directories and a clear file layout can provide consistent deployments.
Potential impact
- An unintended template or file can deploy incorrect configuration.
- Missing files can interrupt automation, or deployment results can differ between environments.
Remediation
- Keep role and playbook file layouts explicit, and inspect the actual search context using tools such as
ansible_search_path. - Use verified role paths, an explicit base directory or absolute paths where needed.
- Restrict write access to source files and directories, and confirm that the intended files are selected in the deployment environment.
Examples
The src files must be available on the control node. Absolute paths also require the same trusted files in each execution environment; destination write permissions are required separately.
Before
---
- name: 설정 파일 배포
hosts: localhost
tasks:
- name: 템플릿 복사
ansible.builtin.template:
src: ../templates/app.conf.j2
dest: /etc/app/app.conf
mode: "0644"
- name: 정적 파일 복사
ansible.builtin.copy:
src: ../files/banner.txt
dest: /etc/app/banner.txt
mode: "0644"
These paths refer to parent directories. Verify which files are selected with the actual role and playbook layout.
After
---
- name: 설정 파일 배포
hosts: localhost
tasks:
- name: 템플릿 복사
ansible.builtin.template:
src: /opt/ansible/templates/app.conf.j2
dest: /etc/app/app.conf
mode: "0644"
- name: 정적 파일 복사
ansible.builtin.copy:
src: /opt/ansible/files/banner.txt
dest: /etc/app/banner.txt
mode: "0644"
The configuration uses explicit /opt/ansible paths. Fixing the path alone does not make the file contents or permissions trustworthy.