Configuration Management Fundamentals
Configuration management keeps systems in a known, consistent state by declaring desired configurations in code and automatically enforcing them. It eliminates manual drift, makes infrastructure reproducible, and provides an audit trail of what changed, when, and why.
itInfrastructure and operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Configuration Management Fundamentals
Configuration management keeps a system's known state understandable and controlled as people change it. You identify what matters, define an approved state, control changes, record what happened, and check the result. Without that discipline, a working server becomes a mystery: small package, permission, or exception changes accumulate until failures are hard to explain and recovery is hard to repeat.
Think of a feedback loop. Identify configuration items. Baseline the approved configuration. Change that baseline through review and implementation. Record current state and history. Verify that actual state matches approved state. Correct unauthorized differences, then repeat. A baseline is a reference for builds and changes, not a claim that the system will never change. Controlling everything creates noise; controlling too little leaves important changes invisible.
Automation helps implement parts of the loop. Desired-state tools declare intent and can be idempotent. Source control preserves reviewable definitions. Monitoring reveals drift. None of those tools chooses the right baseline or approves a risky change for you. Configuration management also does not prove a baseline is secure or available; it makes the chosen state explicit and manageable.
Emergency change still belongs inside a controlled path with limited authority, rapid validation, and retrospective review. A process that is too slow will be bypassed. A process with no evidence cannot show what changed. Start with one service map before expanding the register.
Read the Intro for the control loop and where automation fits. Use the Cheatsheet when you need the stage, evidence, and change-record maps. Updates tracks NIST SP 800-53, where the CM control family this course uses is maintained.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/128/upd1/final
Supports
- Configuration management as a discipline for managing and monitoring information-system configurations while supporting business functions
- Configuration items, baselines, configuration control, status accounting, verification, monitoring, and organizational roles
- Change proposals, impact analysis, testing, approval, implementation, documentation, and monitoring as connected activities
- Drift investigation, remediation, and baseline maintenance
- Security as an integral concern within overall configuration management
- https://csrc.nist.gov/glossary/term/configuration_control
Supports
- Configuration control as control over modifications to hardware, firmware, software, and documentation
- Control before, during, and after system implementation
- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
Supports
- The configuration-management control family and its coverage of policy, baselines, change control, impact analysis, access restrictions, settings, inventories, and planning
- Baselines as reviewed and agreed specifications that support future builds, releases, and changes
- Retention of previous configurations to support rollback
- Configuration items spanning hardware, software, firmware, and documentation across the system life cycle
- Review, approval, implementation, documentation, and monitoring of controlled changes
- https://docs.ansible.com/projects/ansible-core/devel/playbook_guide/playbooks_intro.html
Supports
- Playbooks as repeatable configuration-management and deployment definitions
- Desired-state declaration and idempotent module behavior
- The limit that not all modules and playbooks are idempotent
- Ordered execution, change reporting, check mode, and verification options
