ansible.cfg has host_key_checking = False. Any man-in-the-middle between your Ansible machine and OCI instances would be silently accepted — especially dangerous since vault secrets are deployed over these connections.
Fix
Flip the setting:
host_key_checking=True
Then populate ~/.ssh/known_hosts once per host:
ssh-keyscan -H <host-ip> >> ~/.ssh/known_hosts
File:ansible.cfg
## Problem
`ansible.cfg` has `host_key_checking = False`. Any man-in-the-middle between your Ansible machine and OCI instances would be silently accepted — especially dangerous since vault secrets are deployed over these connections.
## Fix
Flip the setting:
```ini
host_key_checking = True
```
Then populate `~/.ssh/known_hosts` once per host:
```bash
ssh-keyscan -H <host-ip> >> ~/.ssh/known_hosts
```
**File:** `ansible.cfg`
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
ansible.cfghashost_key_checking = False. Any man-in-the-middle between your Ansible machine and OCI instances would be silently accepted — especially dangerous since vault secrets are deployed over these connections.Fix
Flip the setting:
Then populate
~/.ssh/known_hostsonce per host:File:
ansible.cfg