Stop your Ansible temporary files from filling up /tmp on remote nodes

DevOps Tooling On Linux (CI/CD Runners, Ansible)

Stop your Ansible temporary files from filling up /tmp on remote nodes

Technical Briefing | 10/12/2026

I watched a server grind to a halt last week because /tmp hit 100 percent usage. It wasn’t some runaway application or a leak in a web service. It was Ansible. If you are running modules against a fleet of nodes with default settings, Ansible creates these tiny, executable wrapper scripts in /tmp for every single task. And if your disk is small, or your execution frequency is high, you are eventually going to see a flood of abandoned .ansible files.

Where Ansible hides its junk

By default, Ansible targets /tmp because it is guaranteed to exist. But if you have strict security policies or limited partitions for /tmp, this becomes a liability. Most folks ignore the remote_tmp setting in ansible.cfg, assuming the cleanup logic is foolproof. It usually is, but when a runner gets killed mid-task by a CI/CD timeout, those artifacts stay behind, and over months, your nodes get littered with thousands of orphaned files.

find /tmp -name ".ansible-*" -mtime +1 -exec rm -rf {} +

  • Change the remote_tmp path to a dedicated directory with proper cleanup policies
  • Mount your temporary path with noexec if you really want to lock things down
  • Set up a dedicated tmpwatch or systemd-tmpfiles clean policy for these directories

The right move here is to point remote_tmp to a directory that gets wiped by your local systemd-tmpfiles timers instead of relying on the default. If you move it to something like /var/cache/ansible, you get better control over disk quotas and auditing. Don’t wait for your monitoring to scream about a full partition; just move the mess somewhere else.

Linux Admin Automation  |  © www.ngelinux.com  |  10/12/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted