fix(kanidm): detect real changes, and make a failed build retry instead of hiding #266
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!266
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/kanidm-provision-change-signal"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Three fixes in the kanidm-provision path, all found by researching upstream after #265 landed.
1.
changed_when: falsewas needlessly blind — a change signal does exist#265 concluded the tool emits no change signal. That came from grepping the compiled binary for
Created/Updated/Modified— past tense. The tool uses gerunds, so the grep couldn'tmatch and a usable signal was missed. My error.
Upstream reality:
update_entity_attrs()wraps every mutation inif current_values != values, sowhen values match, no request is sent and nothing is printed. Only mutations emit a
log_event, andonly four verbs exist —
Creating,Updating,Deleting,Appending. None of the six unconditionalphase headers contains any of them, so a verb match is sound on v1.3.0 with no upstream change.
Appendingis deliberately excluded. In append mode the comparison is against the declaredmember list only, and every group here sets
overwriteMembers: false— so any group whose realmembership is a superset of what we declare (
idm_people_admins: we declare the service account,Kanidm also holds
idm_admin) compares unequal forever and logsAppendingevery run. Same forTracking provisioned entities, which appends to
ext_idm_provisioned_entities. Matching it would pinchanged: truepermanently — recreating the exact bug #265 fixed.Unanchored
searchon purpose:log_eventcolourises unconditionally (nosupports_colorcheck), soANSI escapes are present even piped, and the
{:>12}padding is computed over the escape-laden string.2. A failed build was invisible on retry
The Containerfile is staged before the build and
is changedwas the rebuild trigger — true onlyon the run that stages it. If that build then failed (a Rust compile on a 2 vCPU / 4 GB host; the
Containerfile warns a link step can be OOM-killed), the next apply found the file unchanged and the
old image still tagged, silently skipped the build, and provisioned against the stale image.
A failure didn't self-heal and became invisible on retry — the same shape as the
merged-but-unapplied Caddyfile in #250.
The trigger now compares the staged Containerfile against a
.built-Containerfilemarker written onlyafter the build task succeeds. A crashed build leaves the mismatch, so the next run retries.
Marker written on
is not skipped, notis changed:podman_imagereportsokwhen the tag existsand needs no rebuild — the steady state — so gating on
is changedwould never write it and leave thegate open forever.
3. The whole provisioning block was invisible to
--check_kanidm_provision_readydepends on auriprobe, anduridoesn't run under--check. So the buildcontext, Containerfile staging, image build, state render and provisioning run were all skipped in
every dry-run.
That is how #265's base-image change reached production without appearing in a single
--check—the dry-run showed
changed=1(an unrelated artefact) while the real apply rebuilt an image. Same trapas #257, third occurrence.
Probe and image-exists check are read-only, so both now run under
--check.podman_imagedeclaressupports_check_mode, so the build reports what it would do rather than compiling, and theprovisioning
commandis still skipped — a dry-run never mutates Kanidm.Verification
--check --tags kanidmon prod now shows the probe, image check, both stats and the build asok(previously all skipped), and the marker task as
changed.--syntax-checkpasses;ansible-lintclean at
production.Also corrected the
CARGO_BUILD_JOBShint:podman build -edoes not exist, so the previous commentwas not copy-pasteable — it needs
ARG+ENVor--build-arg.Not in this PR
The upstream review (
bitborg-internal/copilot/2026-07-30-kanidm-provision-upstream-review.md) foundtwo further items being handled separately: the
service-accountsblock inkanidm-state.json.j2issilently discarded by v1.3.0, and
entry_managed_byis patchable in ~10 lines of Rust — which wouldmake the delegation that caused the 13-day sign-up outage declarative.