Network to Code Workshop: From Intent to Execution: Nautobot and Ansible, Better Together

Fall 2026

Many organizations that adopt a source of truth already run Ansible. Yet, frequently the two rarely interact; inventory lives in a static file, variables live in group_vars, and every job template asks an operator to retype facts the network already knows. This workshop connects the source of truth with the orchestration controller layer.

Job templates, workflows, approval nodes, credentials and execution environments are the same objects in AWX and in Ansible Automation Platform, and everything taught here applies to both. The lab runs upstream AWX so that no attendee needs an AAP entitlement.

Attendees start with a working job template backed by a static inventory and a six-field survey, then progressively replace each piece with Nautobot  artifacts such as dynamic inventory, Config Contexts, and Dynamic Groups. These objects drive which devices a job targets, and a single GraphQL query supplies a device’s full intent. From there the traffic reverses: playbooks write discovered state back into Nautobot, and a status change fires a workflow template gated by an approval node, producing the audit trail a change-management process actually requires. This session moves from generating intent to executing it through the platform teams already own.

Stack: Nautobot 3.2+ (dynamic inventory plugin, Config Contexts, Dynamic Groups, GraphQL, Secrets Groups, Jobs and Job Buttons, change log, webhooks); upstream Ansible AWX (job and workflow templates, surveys, credentials, approval nodes, execution environments); Ansible; Jinja2; Arista cEOS under ContainerLab for the per-attendee device topology. All open-source; attendees need no AAP entitlement.

Agenda

  • Replace a static inventory with the Nautobot dynamic inventory plugin
  • Move group_vars into Config Contexts, with schema validation
  • Drive job targeting from Nautobot Dynamic Groups
  • Fetch a device’s full intent in one GraphQL query and render its config
  • Launch automation from a Nautobot device page with a Job Button
  • Write operational state back to Nautobot from a playbook
  • Trigger a workflow from a Nautobot event, gated by an approval node
  • Correlate the Nautobot change log with the job that caused it

Educational Goals

  • Configure the Nautobot dynamic inventory plugin as a controller inventory source, and retire a static inventory file without changing the playbook
  • Model host and group variables as Nautobot Config Contexts and validate them against a schema, so bad data is rejected at the source of truth
  • Use Nautobot Dynamic Groups to decide which devices a job acts on, so changing a filter in the source of truth changes what automation targets
  • Retrieve a device’s complete intended state in a single GraphQL query and render device configuration from it
  • Run a playbook in check mode and read the resulting diff of intent against reality
  • Write operational state discovered at runtime – serial, software version, neighbours – back into Nautobot from a playbook
  • Launch automation from a Nautobot device page using a Job Button, and decide when a Nautobot Job is the better home for logic than a playbook
  • Decide where credentials belong: Nautobot Secrets Groups versus controller credentials, and articulate the tradeoff
  • Wire a Nautobot event to a workflow template via webhook and gate execution behind an approval node
  • Correlate a Nautobot change log entry with the job that produced it, to build an audit trail a change-management process will accept
  • Recognize when the controller is the wrong tool, and when Nautobot Jobs, Nornir or Golden Config is the better fit

Difficulty Level

Networking: Intermediate

Systems/Linux: Intermediate

Programming: Intermediate

 

Speakers:

Israel Pineda is a Senior Architect at Network to Code, where he designs and delivers network automation solutions for enterprise clients. He specializes in the Nautobot ecosystem, building source-of-truth-driven automation that connects network intent to execution. Israel works at both the architecture and implementation levels, focusing on automation that holds up in real operational environments.

Chris Murray began his career at Cisco Systems in 2010, supporting global telepresence infrastructure before joining Ford Motor Company to resolve critical collaboration challenges. In 2013, he joined IPsoft, where he developed large-scale network automations and helped pioneer early enterprise automation practices. Returning to Cisco in 2018, Chris led the development of a robotic process automation solution that delivered over $10M in capital recovery within its first year. Today, as a Senior Technical Marketing Engineer at Network to Code, he helps organizations understand and adopt modern network automation strategies that drive measurable business outcomes.

Register Today

Related events