Automating Network Configuration on AlmaLinux with RHEL System Roles
Learn how to use AlmaLinux’s built‑in rhel-system-roles networking role to automate static IP configuration and avoid manual drift.
24 Mar 2026, 20:57 UTC

Problem: Manual network setup drifts across AlmaLinux hosts
When you configure IP addresses, DNS, or firewall rules by editing /etc/sysconfig/network-scripts/ifcfg-* files directly, small differences creep in between servers. Over time, troubleshooting becomes harder and compliance audits fail because the expected configuration is not guaranteed.
Thesis: Use the built‑in networking System Role to declare IP settings once and let Ansible enforce them
AlmaLinux ships the rhel-system-roles package, which contains Ansible roles that are idempotent, version‑aligned with RHEL, and usable from the command line. By describing the desired state in a variables file and invoking the networking role, you obtain a repeatable, version‑controlled baseline that can be reapplied without manual drift.
How the networking role works
The role reads variables such as networking_interfaces and writes the appropriate ifcfg-* file. Because the role is idempotent, running it again makes no changes if the target already matches the declared state. The role also respects existing customizations that are not managed by the variables, allowing you to overlay special tweaks when needed.
Worked example: static IP on eth0
Install the System Roles package (requires root or sudo):
# dnf install -y rhel-system-rolesCreate a variables file, e.g.
~/vars/eth0-static.yml:# cat > ~/vars/eth0-static.yml <<'EOF' networking_interfaces: - name: eth0 type: ethernet autoconnect: yes ipv4: address: - 192.168.10.50/24 gateway: 192.168.10.1 dns: - 8.8.8.8 - 8.8.4.4 method: manual EOFRun a minimal playbook that calls the networking role (run as a user with sudo rights):
# cat > ~/playbook.yml <<'EOF' - hosts: localhost become: true roles: - rhel-system-roles.networking EOF ansible-playbook -i localhost, -c local ~/playbook.yml -e @~/vars/eth0-static.ymlVerify that the file reflects the declared address:
# cat /etc/sysconfig/network-scripts/ifcfg-eth0 TYPE=Ethernet NAME=eth0 DEVICE=eth0 ONBOOT=yes IPADDR=192.168.10.50 PREFIX=24 GATEWAY=192.168.10.1 DNS1=8.8.8.8 DNS2=8.8.4.4 EOF
Trade‑off and limitation
The networking role covers the most common static‑IP, DHCP, and basic bonding scenarios. If you need advanced features such as VLAN tagging with complex failover, MACVLAN, or custom script‑based hooks, you will still need to write a dedicated Ansible playbook or shell script. Additionally, the role requires Ansible 2.9 or later; older systems must upgrade the engine first.
Actionable closing
Start by adding the rhel-system-roles package to your baseline image and create a variables repository for network, SELinux, and firewall settings. Treat those variables as the single source of truth; any future change is made there and reapplied with a single ansible-playbook run, eliminating drift and giving you a repeatable, auditable configuration path.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.