Case study
Private / Offline Ansible Execution Environments
Versioned, custom Ansible execution environments distributed through JFrog Artifactory for an AAP ecosystem with no direct internet access.
- Result
- Reproducible automation runtimes in a private, no-internet AAP ecosystem
- Role
- Built
- Where
- Capital One · Platform engineering
- Key stack
- Ansible Execution Environments · Container builds · JFrog Artifactory · AAP
Sanitized case study based on professional experience. Internal names, accounts, hostnames and configurations are intentionally omitted.
01Problem
The AAP ecosystem has no direct internet access, so default execution environments and on-demand collection installs don’t work. Jobs still need AWS, Git and infrastructure modules.
02Context
In regulated environments, every dependency a job runs with must be known, versioned and sourced from an approved registry.
03Architecture
How it works
- Changes to collections, Python dependencies or system packages go through a container build.
- The build produces a custom execution environment image with AWS, Git and infrastructure modules included.
- Images are versioned and pushed to JFrog Artifactory, the approved internal registry.
- AAP pulls only from that registry, so every job runs with a known, pinned set of dependencies.
04Engineering approach
- Defined execution environments with the collections and libraries required for AWS, Git and infrastructure automation.
- Built and versioned the images so jobs can pin a specific version and roll back.
- Distributed the images through JFrog Artifactory for use by AAP in private environments.
05Security
- No runtime internet dependency, and every package comes from an approved source.
- Versioned images make the job runtime auditable and reproducible.
06Automation
- Repeatable image builds.
- Versioned promotion through the registry to AAP.
07Results
- AAP jobs run reliably in environments without internet access.
- Consistent, versioned runtimes across Development, Production and Restricted Production.
08Lessons learned
- Treat the automation runtime as a software artifact, versioned and promoted like any other.
09Skills & technologies
Supply-chain controlContainersAnsibleArtifact management
Ansible Execution EnvironmentsContainer buildsJFrog ArtifactoryAAPAnsible collectionsPython