Ansible vs Flatpak — Configuration vs App Packaging

Introduction

Ansible and Flatpak solve fundamentally different problems. Ansible automates infrastructure configuration and orchestration. Flatpak packages and distributes desktop applications in a sandboxed, distro-agnostic format. They don't compete — they complement each other.

Quick Comparison

AspectAnsibleFlatpak
PurposeInfrastructure automationApplication packaging
ScopeServers, networks, cloudDesktop applications
ModelPush-based, agentlessPull-based, per-user
FormatYAML playbooksOCI-like bundles
IsolationNone (configures the OS)Sandboxed (bubblewrap)
TargetSysadmins, DevOpsDesktop users, app devs
DependenciesPython + SSHOSTree, bubblewrap
UpdatesOn-demand or scheduledAuto-update via Flathub

When to Use Each

Use Ansible when:

  • Configuring servers, networks, and cloud infrastructure
  • Deploying applications to servers (web apps, databases, services)
  • Managing system packages (apt, yum, dnf)
  • Enforcing security policies across a fleet
  • Orchestrating multi-host workflows

Use Flatpak when:

  • Distributing desktop applications (Firefox, LibreOffice, VS Code)
  • Providing sandboxed, distro-independent app packaging
  • Users need to install apps without root access
  • You want automatic application updates

Managing Flatpak with Ansible

The real synergy: use Ansible to manage Flatpak installations across your fleet.

---
- name: Manage Flatpak applications with Ansible
  hosts: workstations
  become: true
  tasks:
    - name: Install Flatpak
      ansible.builtin.package:
        name: flatpak
        state: present

    - name: Add Flathub repository
      community.general.flatpak_remote:
        name: flathub
        flatpakrepo_url: https://dl.flathub.org/repo/flathub.flatpakrepo
        state: present

    - name: Install desktop applications
      community.general.flatpak:
        name: "{{ item }}"
        state: present
        remote: flathub
      loop:
        - org.mozilla.firefox
        - org.libreoffice.LibreOffice
        - com.visualstudio.code
        - org.gimp.GIMP
        - org.signal.Signal

    - name: Remove unwanted Flatpaks
      community.general.flatpak:
        name: "{{ item }}"
        state: absent
      loop:
        - org.example.unwanted-app

    - name: Update all Flatpak applications
      ansible.builtin.command:
        cmd: flatpak update -y
      changed_when: false

Standardize Developer Workstations

---
- name: Developer workstation setup
  hosts: dev_workstations
  become: true
  vars:
    flatpak_apps:
      - com.visualstudio.code
      - com.jetbrains.IntelliJ-IDEA-Community
      - org.mozilla.firefox
      - com.slack.Slack
      - us.zoom.Zoom
      - com.spotify.Client
    system_packages:
      - git
      - docker.io
      - python3-pip
      - nodejs
  tasks:
    - name: Install system packages (Ansible)
      ansible.builtin.apt:
        name: "{{ system_packages }}"
        state: present

    - name: Install desktop apps (Flatpak)
      community.general.flatpak:
        name: "{{ item }}"
        state: present
      loop: "{{ flatpak_apps }}"

    - name: Configure Git
      ansible.builtin.template:
        src: gitconfig.j2
        dest: "/home/{{ ansible_user }}/.gitconfig"
        owner: "{{ ansible_user }}"

Troubleshooting

# List installed Flatpaks
flatpak list --app

# Check Flatpak remotes
flatpak remotes

# Ansible module not found
ansible-galaxy collection install community.general

Conclusion

Ansible and Flatpak aren't alternatives — they work at different layers. Use Ansible for infrastructure and system configuration, Flatpak for sandboxed desktop apps, and combine them to manage Flatpak installations across your fleet with community.general.flatpak.