Using Ansible for Cisco ACI Deployment and Orchestration
Switch branches/tags
Nothing to show
Clone or download
Pull request Compare This branch is 35 commits behind joelwking:master.
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Failed to load latest commit information.


Using Ansible for Cisco ACI Deployment and Orchestration

This is demonstration of Ansible, an open source automation tool, which is used to configure a Cisco Application Centric Infrastructure (ACI) fabric. Ansible playbooks are used to call a python module ( I developed which configures the fabric through the ACI controller (APIC) northbound REST API interface.

This video clip illustrates building a tenant configuration

Additionally, a second module ( has been developed to issue class queries to the controller and return the results as ansible_facts. A sample playbook for this module is aci_gather_facts.yml

This video - demonstrates how both modules can be used together in a playbook to gather facts from the APIC and then using the variables returned, modify the configuration of the fabric based on the results.

Our use case is to meet the requirements of the network security administrator, implementing security policy filters (TCP_SMALL_SERVERS.xml) on all end-user tenants (ignoring the common, infra and mgmt tenants). The playbook (security_policy_filter.yml) applies a Service Contract to a single tenant for testing, and then illustrates how we can use the ACI fabric to return the operating system version of a specific VM attached to the fabric.

The aci_gather_facts module can return managed object (MO) queries, see aci_mo_example.yml as an example of how to use this feature.