ci: bake tofu/ansible-lint/shellcheck into the runner image + burn down ansible-lint skips #174

Sammanfogat
supernaut sammanfogade 2 incheckningar från feat/65-ci-runner-tools in i main 2026-07-20 18:05:56 +00:00
Ägare

What & why

Two parts of #65.

1. Bake infra tools into the ci runner image

The ci workflow installed shellcheck (apt), OpenTofu (pinned binary), and
ansible + ansible-lint (pip --break-system-packages) per job — slow, and it
pulls the toolchain off-instance on every run.

  • Added them to scripts/bake-runner-image.sh so the baked gitborg-runner
    image ships them: shellcheck, python3-pip, unzip via apt; the pinned
    OpenTofu binary; ansible + ansible-lint via pip. Each is sanity-checked in
    the bake so a missing/broken tool fails the bake.
  • Dropped the "Install infra tools (shellcheck, opentofu, ansible-lint)" step
    from .forgejo/workflows/ci.yml. The tofu fmt, ansible-lint and
    shellcheck steps now rely on the baked-in tools.
  • OpenTofu pin is one source of truth: TOFU_VERSION in
    scripts/bake-runner-image.sh (default 1.10.6, unchanged from the old CI
    pin). The workflow no longer hard-codes a version. (Before this PR the pin
    lived only in ci.yml, so moving it to the bake script keeps a single owner.)
  • Updated roles/runner-controller/files/README-runner-image.md toolchain table
    to document the three new tools and where the pin lives.
  • Fixed two now-stale #65 comments in ci.yml (the smoke step's "pip install
    above" reference now points at the baked-in ansible).

2. Burn down the ansible-lint skip_list

Converted the intentional one-off cases from global skips to line-level
# noqa, so a new accidental violation of these rules will now fail CI, while
the deliberate cases stay green.

Rule Status Notes
command-instead-of-module ✅ burned down (noqa) systemctl --user reset-failed in roles/web + roles/runner-controller, plus a third occurrence the issue didn't list: systemctl --user is-active health probe in roles/health-check (added since the issue was written). All three noqa'd — read-only / no ansible.builtin.systemd equivalent.
name[template] ✅ burned down (noqa) 3 tasks with Jinja mid-name (roles/forgejo/tasks/create-user.yml ×2, roles/kanidm/tasks/reset-links.yml) — deliberate for operator readability.
no-handler ✅ burned down (noqa) Intentional register/.changed gating. 4 occurrences (issue estimated 3): roles/caddy ×2, roles/monitoring ×2 — validate/restart must run inline to fail fast / keep ordering.
var-naming[no-role-prefix] ⏸️ deferred ~90 vars across 12 roles/templates/group_vars/inventory — a broad, risky cross-repo rename. Kept in skip_list with a # DEFERRED (#65) reason. A dedicated follow-up may be warranted.
role-name ⏸️ deferred 3 hyphenated role dirs (monitoring-agent, registry-mirror, runner-controller); renaming dirs breaks site.yml role refs. Kept in skip_list with a reason.
yaml — kept by design Prettier owns YAML formatting.

Validation

  • ansible-lint (from ansible/, throwaway .vault_pass as CI does): Passed — 0 failures, 0 warnings, 163 files, profile production.
  • pnpm ansible:check (ansible-playbook site.yml --syntax-check): OK.
  • pnpm format:check (Prettier) + pnpm mdlint: clean (README table re-aligned).
  • bash -n scripts/bake-runner-image.sh: OK; shellcheck scripts/*.sh: clean.
  • Not verifiable here: an actual runner-image rebuild (needs the authenticated
    OpenStack CLI + builder VM). The image must be re-baked (scripts/bake-runner-image.sh --replace) and promoted before the trimmed ci.yml runs, otherwise the infra
    steps will fail on missing tools. The bake script is syntactically sound and
    internally consistent with the edited ci.yml.

Refs #65 (the var-naming / role-name burn-downs are explicitly out of scope
here and deferred — a follow-up issue may be warranted).

## What & why Two parts of #65. ### 1. Bake infra tools into the `ci` runner image The `ci` workflow installed shellcheck (apt), OpenTofu (pinned binary), and ansible + ansible-lint (`pip --break-system-packages`) **per job** — slow, and it pulls the toolchain off-instance on every run. - Added them to `scripts/bake-runner-image.sh` so the baked `gitborg-runner` image ships them: `shellcheck`, `python3-pip`, `unzip` via apt; the pinned OpenTofu binary; `ansible` + `ansible-lint` via pip. Each is sanity-checked in the bake so a missing/broken tool fails the bake. - **Dropped** the "Install infra tools (shellcheck, opentofu, ansible-lint)" step from `.forgejo/workflows/ci.yml`. The `tofu fmt`, `ansible-lint` and `shellcheck` steps now rely on the baked-in tools. - **OpenTofu pin is one source of truth:** `TOFU_VERSION` in `scripts/bake-runner-image.sh` (default `1.10.6`, unchanged from the old CI pin). The workflow no longer hard-codes a version. (Before this PR the pin lived only in `ci.yml`, so moving it to the bake script keeps a single owner.) - Updated `roles/runner-controller/files/README-runner-image.md` toolchain table to document the three new tools and where the pin lives. - Fixed two now-stale `#65` comments in `ci.yml` (the smoke step's "pip install above" reference now points at the baked-in ansible). ### 2. Burn down the ansible-lint `skip_list` Converted the intentional one-off cases from **global skips** to line-level `# noqa`, so a *new* accidental violation of these rules will now fail CI, while the deliberate cases stay green. | Rule | Status | Notes | | --- | --- | --- | | `command-instead-of-module` | ✅ burned down (noqa) | `systemctl --user reset-failed` in `roles/web` + `roles/runner-controller`, **plus** a third occurrence the issue didn't list: `systemctl --user is-active` health probe in `roles/health-check` (added since the issue was written). All three noqa'd — read-only / no `ansible.builtin.systemd` equivalent. | | `name[template]` | ✅ burned down (noqa) | 3 tasks with Jinja mid-name (`roles/forgejo/tasks/create-user.yml` ×2, `roles/kanidm/tasks/reset-links.yml`) — deliberate for operator readability. | | `no-handler` | ✅ burned down (noqa) | Intentional register/`.changed` gating. **4** occurrences (issue estimated 3): `roles/caddy` ×2, `roles/monitoring` ×2 — validate/restart must run inline to fail fast / keep ordering. | | `var-naming[no-role-prefix]` | ⏸️ **deferred** | ~90 vars across 12 roles/templates/group_vars/inventory — a broad, risky cross-repo rename. Kept in `skip_list` with a `# DEFERRED (#65)` reason. A dedicated follow-up may be warranted. | | `role-name` | ⏸️ **deferred** | 3 hyphenated role dirs (`monitoring-agent`, `registry-mirror`, `runner-controller`); renaming dirs breaks `site.yml` role refs. Kept in `skip_list` with a reason. | | `yaml` | — kept by design | Prettier owns YAML formatting. | ## Validation - `ansible-lint` (from `ansible/`, throwaway `.vault_pass` as CI does): **Passed — 0 failures, 0 warnings**, 163 files, profile `production`. - `pnpm ansible:check` (`ansible-playbook site.yml --syntax-check`): **OK**. - `pnpm format:check` (Prettier) + `pnpm mdlint`: **clean** (README table re-aligned). - `bash -n scripts/bake-runner-image.sh`: **OK**; `shellcheck scripts/*.sh`: **clean**. - Not verifiable here: an actual runner-image **rebuild** (needs the authenticated OpenStack CLI + builder VM). The image must be re-baked (`scripts/bake-runner-image.sh --replace`) and promoted before the trimmed `ci.yml` runs, otherwise the infra steps will fail on missing tools. The bake script is syntactically sound and internally consistent with the edited `ci.yml`. Refs #65 (the `var-naming` / `role-name` burn-downs are explicitly out of scope here and deferred — a follow-up issue may be warranted).
supernaut lade till 1 incheckning 2026-07-20 15:12:38 +00:00
feat(ci): bake infra tools into runner image + burn down ansible-lint skips
En del kontroller misslyckades
ci / ci (pull_request) Failing after 9s
e42421a154
Bake shellcheck, OpenTofu (pinned via TOFU_VERSION, single source of
truth) and ansible + ansible-lint into the `ci` runner image instead of
installing them per job, and drop the "Install infra tools" step from
.forgejo/workflows/ci.yml.

Convert three intentional ansible-lint global skips to line-level
`# noqa`: command-instead-of-module, name[template] and no-handler. The
broad var-naming[no-role-prefix] and role-name skips stay deferred.

Refs #65
supernaut lade till 1 incheckning 2026-07-20 17:54:45 +00:00
fix(runner-image): bake pinned Node 24, not Debian's Node 20 (#65)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m28s
c08935fa35
The bake installed Debian trixie's `nodejs` package (Node 20.19.2), but both
repos pin Node 24.18.0 (Volta + packageManager pnpm@11) and the runner-image
README already specifies 'Node.js 24+'. On the freshly-baked image the ci job's
`corepack enable` + `pnpm install --frozen-lockfile` ("Install Node
dependencies") ran on Node 20 and failed (run 109 attempt 2).

Drop `nodejs` from apt; install the pinned official Node binary to /usr/local
(NODE_VERSION=24.18.0, single source of truth == volta.node), enable corepack.
bash -n + shellcheck clean.
Upphovsperson
Ägare

Added commit c08935f: bake pinned Node 24.18.0 instead of Debian's Node 20.

The freshly-baked image shipped Debian trixie's nodejs (Node 20.19.2), but both repos pin Node 24.18.0 (Volta + packageManager pnpm@11) and this README already specifies "Node.js 24+". So corepack enable + pnpm install --frozen-lockfile (the ci job's "Install Node dependencies") ran on Node 20 and failed (run 109 attempt 2).

Change: drop nodejs from apt; install the pinned official Node binary to /usr/local (NODE_VERSION=24.18.0, single source of truth == volta.node), corepack enable. The in-bake sanity check node --version now asserts 24. bash -n + shellcheck clean.

Re-bake required from this branch before merge (the previous bake produced the Node-20 image).

Added commit `c08935f`: **bake pinned Node 24.18.0 instead of Debian's Node 20.** The freshly-baked image shipped Debian trixie's `nodejs` (Node 20.19.2), but both repos pin Node 24.18.0 (Volta + `packageManager` pnpm@11) and this README already specifies "Node.js 24+". So `corepack enable` + `pnpm install --frozen-lockfile` (the ci job's "Install Node dependencies") ran on Node 20 and failed (run 109 attempt 2). Change: drop `nodejs` from apt; install the pinned official Node binary to `/usr/local` (`NODE_VERSION=24.18.0`, single source of truth == `volta.node`), `corepack enable`. The in-bake sanity check `node --version` now asserts 24. bash -n + shellcheck clean. **Re-bake required** from this branch before merge (the previous bake produced the Node-20 image).
supernaut sammanfogade incheckning 0589a5e023 till main 2026-07-20 18:05:56 +00:00
supernaut tog bort grenen feat/65-ci-runner-tools 2026-07-20 18:05:56 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!174
Ingen beskrivning angiven.