Description
Using state: latest for package installation can install a new version available from the repository at execution time. The same playbook can produce different results over time, and compatibility or dependency changes can disrupt service.
Automatic updates can be part of a planned security-patching policy. Pinning versions also requires a validation and update process so security fixes continue to be applied.
Potential impact
- Unvalidated package or dependency updates can cause outages or performance degradation.
- Changes between executions can reduce deployment reproducibility.
Remediation
- For production deployments requiring version control, use an explicit package version with
state: present.presentalone does not pin the version. - Manage relevant dependencies and repositories, and test updates in a validation environment first.
update_only: truerestricts new package installations; it does not pin versions. - Review security updates for pinned versions and refresh them regularly.
Examples
These existing yum excerpts require support from the installed Ansible version and package backend. The repository must provide the selected version; 1.24.0 is a comparison value, not a recommendation for current production use.
Before
---
- name: 패키지 설치
hosts: localhost
tasks:
- name: nginx 최신 버전 설치
ansible.builtin.yum:
name: nginx
state: latest
The task installs or updates to the latest version available from the repository at execution time.
After
---
- name: 패키지 설치
hosts: localhost
tasks:
- name: nginx 고정 버전 설치
ansible.builtin.yum:
name: nginx-1.24.0
state: present
The task specifies the nginx version to install. It does not pin every dependency or distribution package release, so manage those separately where required.