← All TILs · ansible

Connection variables: ansible_host, ansible_port, ansible_user and ansible_connection, with ssh, docker and local

ansible - 2026-10-03

Fourth entry in the Ansible inventory from scratch series. The inventory so far, from item 1 to item 3, named hosts and groups and connected to all of them on the local machine. This entry reaches three hosts three different ways, and looks at the four variables that decide how: ansible_connection, ansible_host, ansible_port and ansible_user. Everything below ran with ansible-core 2.21.4 and community.docker 5.3.0.

Three hosts, three connection plugins

A connection plugin is the part of Ansible that carries tasks to a host and runs them there. ansible_connection picks it, per host, and defaults to ssh:

The example gave each host its settings in host_vars/<host>/ansible.yml, item 2's layout for one host, and kept the hosts file free of variables:

# host_vars/db1/ansible.yml
ansible_connection: ssh
ansible_host: 127.0.0.1
ansible_port: 2222
ansible_user: dbadmin

# host_vars/app1/ansible.yml
ansible_connection: community.docker.docker
ansible_host: inv04-app1
ansible_user: appuser

# host_vars/jump1/ansible.yml
ansible_connection: local

db1 was an SSH server in a container, published on the controller's port 2222; app1 a second container, named inv04-app1. A playbook gathered, from inside each host, the user it ran as and the machine's name:

app1:   community.docker.docker  →  appuser on app1-container
db1:    ssh                      →  dbadmin on db1-container
jump1:  local                    →  the controller's own user, on the controller

The same variable means something different per plugin

Each connection plugin maps these variables to options of its own, and its documentation says what they mean:

Variable ssh community.docker.docker local
ansible_host the name or address to connect to the container's name not used
ansible_port the SSH port not used not used
ansible_user the user to log in as the user to run as inside the container ignored

The older names, ansible_ssh_host, ansible_ssh_port and ansible_ssh_user, still work with ssh, and ansible_docker_host and ansible_docker_user with docker; the plugins' documentation lists them next to the generic ones.

When ansible_host is missing

The example left ansible_host at its default, the inventory name, for each container host:

So when a docker host is unreachable with a permissions message, check ansible_host against docker ps first.

In short

The example repository

The series' companion repository, abdelhousni/ansible-inventory-series, holds this inventory and the image behind db1 and app1. run.sh needs Docker and an SSH client: it starts both containers, generates a key pair for the run, runs whoami.yml, which writes where each connection landed to its out/ directory, then repeats the three mistakes above. Its CI runs it on every push and compares the output with the expected one.

Sources

Created 2026-10-03T08:56:48+02:00 · Edit