Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Ansible can provision EC2 instances and configure their operating systems, but those are separate jobs: AWS-facing tasks run from an Ansible execution host, while guest-configuration tasks connect to the instances. For hosts that change over time, use the amazon.aws.aws_ec2 dynamic inventory plugin instead of relying on a saved IP address. This guide follows the documented workflow and troubleshooting checks; it does not claim a personally tested lab or reproduced failures.

How the Ansible-to-EC2 workflow fits together

Ansible’s AWS modules use Python SDKs to call AWS APIs. The machine executing those modules—the controller or execution host—needs the relevant collection, Python dependencies, and AWS credentials. Once an instance exists, a later play can configure it through SSH or an appropriate Systems Manager connection.

The distinction matters when diagnosing access problems: permission to create an instance is not the same as permission for that instance to access AWS services, and neither guarantees that Ansible can reach the guest operating system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where tasks run

AWS provisioning tasks commonly run locally on the Ansible controller, often in a play targeting localhost. The controller may be a developer workstation, a CI runner, or an EC2-hosted automation machine. If the controller itself runs on EC2, its attached IAM role can provide credentials to supported AWS integrations without embedding static keys.

#1 Best Overall
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

What runs on the instance

Guest configuration targets the launched EC2 host. The play needs a way to identify that host and a working connection. A provisioning result can be registered and placed into a temporary Ansible group for a follow-on play; dynamic inventory is generally more practical when instances are replaced or their addresses change.

Prepare the Ansible execution host

Install the amazon.aws collection and the AWS SDK dependencies on the host that executes the module. The current amazon.aws.ec2_instance reference identifies collection version 11.4.0 and lists Python 3.6 or later, boto3 1.35.0 or later, and botocore 1.35.0 or later as requirements. These are living requirements; check the linked module reference before pinning them in a new environment.

ansible-galaxy collection install amazon.aws:==11.4.0
python -m pip install 'boto3>=1.35.0' 'botocore>=1.35.0'

Use a virtual environment or another controlled Python environment so that the SDK versions Ansible imports are the ones you expect. The collection installation and Python package installation are distinct: having the collection does not by itself install boto3 or botocore.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a credential path without putting secrets in the playbook

Ansible’s AWS modules can use environment variables, AWS profiles, module arguments, or variables protected with Ansible Vault. Prefer an attached role or short-lived credentials when your execution environment supports them. Avoid committing long-lived access keys in plaintext playbooks or inventory files.

Rank #2
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
  • Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

Execution context can explain seemingly inconsistent credential failures. The EC2 module documentation distinguishes the environment and configuration files read in the Ansible host context from the controller context used by lookup and connection plugins. boto3 can also read credentials and Region settings from its applicable configuration files. Confirm which process and host are making each API call instead of assuming the controller shell’s environment reaches every plugin or task.

Controller role versus instance profile

An IAM instance profile passes a role to an EC2 instance; it does not automatically give the Ansible controller that role unless the controller is itself using that instance profile. AWS describes an instance profile as “a container that passes IAM role information to an Amazon Elastic Compute Cloud (Amazon EC2) instance at launch.” See AWS Systems Manager: Configure instance permissions required for Systems Manager.

Keep the two permission paths separate in your design: controller credentials authorize provisioning and inventory queries, while an EC2 instance’s profile authorizes actions performed by that instance, such as Systems Manager management or reading a playbook from S3.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Provision instances with narrow, explicit intent

Use amazon.aws.ec2_instance with an explicitly selected Region, AMI, instance type, subnet, tags, and network-access plan. Tags make later inventory selection clearer; narrow filters reduce the chance that a future play affects unrelated instances. The module supports key-pair and public-IP settings, but a public IP is only one connectivity option, not a requirement.

Rank #3
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
  • CanaKit Raspberry Pi 5 Essentials Starter Kit

Be particularly deliberate about instance counts. The module’s count parameter launches new instances. exact_count can create or terminate instances to achieve the requested count, depending on the matching resources. The documentation includes a deliberately cautionary example in which broad filters can terminate every running instance in a Region. Do not copy broad selectors into a destructive task.

Before a run that can stop, replace, or terminate instances, review the Region, resource IDs, filters, desired state, and count behavior. Prefer selectors tied to explicit tags or IDs and keep teardown separate from routine configuration.

Discover hosts for guest configuration

Temporary group for a one-run workflow

For a simple sequence, register the result of the provisioning task, add the returned instance to a temporary host group, and run a later play against that group. This avoids manually copying an address between tasks, but the temporary group is not a durable inventory for future runs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Dynamic inventory for changing instances

The amazon.aws.aws_ec2 inventory plugin queries EC2 at runtime. It can select hosts by tags and instance state and can derive Ansible groups from tags. Configure the desired Regions and filters, then inspect what Ansible sees before running configuration or cleanup:

Rank #4
SANOOV Raspberry Pi 5 4GB Kit, 4GB RAM Single Board Computer with Active Cooler and ABS Case, Complete Raspberry Pi 5 Starter Kit for IoT Robotics Retro Gaming
  • All-in-One Complete Kit: This SANOOV RPi 5 bundle comes with Raspberry Pi 5 4GB RAM single board, active cooler, durable ABS case and screwdriver. No extra parts needed, ready to use right out of the box for beginners and hobbyists
  • Powerful Single Board Computer: Equipped with 4GB RAM and high-performance processor, delivers fast running speed for 4K playback, AI projects, programming and daily computing tasks. SANOOV for raspberry pi 5 4GB is equipped with broadcom 64 quad-core Arm Cortex A76 processor with gigabit ethernet and upgraded with IEEE 802.11ac Wi-Fi, Bluetooth 5.0 dual-band 2.4Ghz and 5Ghz and Power Over Ethernet (POE). Upgrading delivers 2-3 x speed vs Pi 4, redefining the experience
  • Efficient Active Cooler: Effectively lowers operating temperature and prevents performance throttling. Runs quietly even under long-time heavy load, ensures stable operation all day long. SANOOV RPi 5 4GB kit offer an active cooler, which combines an aluminium heatsink with a high-performance PWM fan. Active cooler is fully compatible with the Pi OS, which can effectively reduce the temperature of RPi5 and ensure its good performance during long-term high load operation
  • Sturdy ABS Protective Case: Well-fitted for Raspberry Pi 5 board, can be secured with 4 screws to effectively protect the Pi 5 motherboard from damage, reserves full access to all ports and buttons. SANOOV uses ABS material to produce the case, which has a softer texture and feel. Meanwhile, SANOOV case adopts a layered design for easy disassembly and installation. (Tip: The Case cannot install M.2 HAT Add on Board and Solid State Drive!)
  • Wide Application & Full Compatibility: Seamlessly compatible with official OS and mainstream peripheral accessories for Raspberry Pi 5. Whether you are a beginner, student, electronics hobbyist or professional developer, this all-in-one kit meets your diverse needs. It excels in IoT projects, robotics design, retro gaming devices, home media servers and other DIY creations. Backed by a large global community, you can easily find guides, technical support and shared projects online
ansible-inventory -i aws_ec2.yml --graph
ansible-inventory -i aws_ec2.yml --list

Check the selected hosts, generated groups, hostname precedence, tag values, and state. An inventory command is a useful boundary between “what AWS contains” and “what this play will target.” A static inventory remains reasonable for a stable, tiny lab, but saved addresses become stale when instances are replaced.

Choose SSH or Systems Manager access

Connection approach What it needs Useful fit
SSH A compatible key pair, a reachable network path, a security-group rule allowing the connection, and the correct login user and host address. A controlled SSH environment where direct host access is intended.
Systems Manager Managed-node permissions, a functioning SSM Agent, the required instance metadata configuration, and a supported Ansible connection setup. Instances that should be managed without making SSH the access path.

The Ansible AWS guide demonstrates both public-IP provisioning and Systems Manager-based connection options. Do not assign public addresses merely to simplify a tutorial if private-subnet access through Systems Manager or controlled networking better matches the environment.

Systems Manager prerequisites

AWS documents Default Host Management Configuration as a regional setting. Its automatic management path requires IMDSv2 and SSM Agent version 3.2.582.0 or later, along with the appropriate permissions. The configuration must be enabled separately in each Region and can take up to 30 minutes to apply. AWS also documents instance profiles as an alternative, and recommends permissions tailored to the system’s needs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Because the setting is account- and Region-scoped and its role changes affect managed EC2 instances in that scope, review the impact before enabling or changing it. When changing a role associated with an instance profile, AWS notes that removing the role can take up to one hour to take effect; follow its documented association and replacement workflows rather than assuming an immediate change.

Best Value
RasTech Raspberry Pi 5 8GB Kit with Active Cooler and Pi5 Case
  • 【What you Get】You will get 1*Pi 5 8GB Single Board,1*RasTech Case,1*Active Cooler,1*Screwdriver,1*Installation instructions,12-month free warranty, lifetime service, 24-hour prompt and friendly response.
  • 【More Connectors】There are two USB 3.0 ports(5Gbps simultaneously) and two USB 2.0 ports, which triple total bandwidth ,support any combination of up to two cameras or displays. Peak SD card performance is doubled through support for the SDR104 high-speed mode. It provides a smooth desktop experience for you. Offer Gigabit Ethernet and a PCIe interface, along with dual-band Wi-Fi and Bluetooth 5.0/BLE wireless capability. The RasTech Pi 5 Kit use the new 27W 5.1V 5A USB-C power connector.
  • 【 Support Dual 4Kp60 Display 】Each of the two microHDMI sockets can control a 4K display at 60 Hertz, now support HDR, offering super HD video for media streaming projects. RPi 5 is the first RPi model that comes with a PCI Express port (PCIe 2.0 x1 with 500 MB/s) to attach SSDs (requires separate M.2 HAT).
  • 【 Excellent Chips And Applications】Pi 5 is a full-size Pi computer using silicon built in-house at Pi. The RP1 “southbridge” provides the bulk of the I/O capabilities for Pi 5. Pi 5 is more friendly and convenient in the development of Internet of Things, Web development, machine identification, automatic control and other electronic equipment applications and network.
  • 【 Faster CPU, Better GPU 】 Pi 5 features a Broadcom BCM2712 64-bit quad-core Arm Cortex-A76 processor running at 2.4GHz, it delivers a 2–3× increase in CPU performance relative to RaspberryPi 4. The 800MHz VideoCore VII GPU is compatible to OpenGL ES 3.1 and Vulkan 1.2, substantial uplift in graphics performance. Pi 5 Offers lightning-fast CPU speed, a PCI Express interface, a Real Time Clock (RTC) and a power button and runs significantly cooler than Pi 4.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When Systems Manager runs the playbook

If Systems Manager itself is being used to execute Ansible playbooks on managed nodes, AWS recommends the AWS-ApplyAnsiblePlaybooks document. The older AWS-RunAnsiblePlaybook document is deprecated and retained for legacy use. AWS supports playbook sources such as GitHub and S3, including bundled ZIP or directory structures.

For an S3 source, the managed node’s instance profile needs access to the bucket. If execution output is sent to S3, the node role also needs write permission there; the initiating user’s permissions do not substitute for the managed node’s access. Dependency installation behavior can vary by operating system, so verify the target’s prerequisites rather than assuming every environment installs them automatically.

Troubleshoot by separating provisioning, discovery, and connection

AWS module cannot import boto3 or botocore

  • Check Python and SDK versions on the host that executes the module, not merely on the machine where you edit the playbook.
  • Confirm that the expected amazon.aws collection is installed for the Ansible environment in use.

Credentials work in one task but not a lookup or connection plugin

  • Identify the execution context of the failing component: module host, controller, or managed node.
  • Check the relevant environment variables, AWS profile, configuration file, and Region in that context.

The instance launches, but configuration cannot reach it

First inspect the registered provisioning result and the inventory or temporary host group. Then check that the chosen hostname is the intended public or private address, the subnet and security group permit the planned path, the SSH key and login user match the image, or the SSM prerequisites are satisfied. These are architecture checks implied by the documented separation between provisioning and guest configuration, not a claim that a particular failure was reproduced.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SSM node does not appear or respond

  • Verify the node’s permissions and role, SSM Agent prerequisite, and IMDSv2 status.
  • Confirm Default Host Management Configuration is enabled in the instance’s Region and allow time for the setting to apply.

SSM runs commands but cannot retrieve or save playbooks

Check the managed node’s instance profile and the S3 bucket policy. The node needs read access for an S3 playbook source and write access if it is responsible for output logging to S3.

Inventory omits hosts or selects too many

Inspect the configured Region, tag filters and values, instance state, hostname precedence, and generated groups. Run ansible-inventory --graph or --list before a destructive play to see the actual target set.

An instance is unexpectedly created, stopped, replaced, or terminated

Review whether the task uses count or exact_count, plus its filters, IDs, and requested state. Broad matching combined with exact_count can affect instances beyond the intended lab. Use explicit selectors and examine the target set before executing destructive changes.

Pick an operating model that matches the scale

Decision Option A Option B
Provisioning execution Developer or CI controller uses its configured AWS credentials. EC2-hosted controller uses its assigned IAM role.
Host discovery Static inventory for a stable, very small environment. aws_ec2 dynamic inventory for changing instances and tag-based selection.
Guest access SSH with a key and an intentionally reachable network path. Systems Manager with IAM, agent, and metadata prerequisites.
Configuration timing Configure after launch with Ansible. Bake more configuration into an image with a tool such as Packer, then use Ansible for remaining changes.
Automation operations A straightforward playbook or pull workflow for a small setup. Ansible Automation Platform callbacks can support autoscaling use cases and centrally record job results.

These are design choices, not prerequisites for using Ansible with EC2. Ansible’s AWS guide discusses image building with Packer and post-provisioning configuration, and describes Automation Platform callbacks as an autoscaling option. Choose based on how often hosts change, how outcomes must be recorded, and who needs to operate the automation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$259.95
Bestseller No. 2
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$419.99
Bestseller No. 3
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
CanaKit Raspberry Pi 5 Essentials Starter Kit
$189.99

Official references

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.