fix(runner-controller): safe dry_run default (true), opt prod in via group_vars #32

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/runner-controller-dryrun-default in i main 2026-07-09 15:28:27 +00:00
Ägare

Summary

Reconciles a code/comment/doc contradiction in the ephemeral runner controller (surfaced by the docs audit in #31).

roles/runner-controller/defaults/main.yml set runner_controller_dry_run: false, but every comment describing it — the default's own header, controller.py ("DRY_RUN=true (default) — safe by default"), and the container template — said the default is true. With no group_vars override, a fresh ansible-playbook --tags runner-controller apply therefore ran the controller live (booting and reaping real OpenStack VMs) instead of the documented safe dry-run, making the runbook's "verify a clean dry-run, then flip to false" rollout impossible.

Change

  • roles/runner-controller/defaults/main.yml: runner_controller_dry_run: false → true. This makes the role default match its own comments — a fresh deploy never mutates until an operator opts in.
  • group_vars/all/vars.yml: add explicit runner_controller_dry_run: false in the existing runner-controller block, so production keeps running CI live.

Production impact: none

group_vars/all overrides role defaults, so the effective value for gitborg-prod is unchanged. Verified:

$ ansible gitborg-prod -m debug -a "msg=effective_dry_run={{ runner_controller_dry_run }}"
    "msg": "effective_dry_run=False"

So applying this is safe — the controller stays live in prod; only fresh deploys (which previously went live silently) now get the safe dry-run default until explicitly opted in.

## Summary Reconciles a code/comment/doc contradiction in the ephemeral runner controller (surfaced by the docs audit in #31). `roles/runner-controller/defaults/main.yml` set `runner_controller_dry_run: false`, but every comment describing it — the default's own header, `controller.py` ("DRY_RUN=true (default) — safe by default"), and the container template — said the default is **true**. With no `group_vars` override, a fresh `ansible-playbook --tags runner-controller` apply therefore ran the controller **live** (booting and reaping real OpenStack VMs) instead of the documented safe dry-run, making the runbook's "verify a clean dry-run, then flip to false" rollout impossible. ## Change - **`roles/runner-controller/defaults/main.yml`**: `runner_controller_dry_run: false` → **`true`**. This makes the role default match its own comments — a fresh deploy never mutates until an operator opts in. - **`group_vars/all/vars.yml`**: add explicit **`runner_controller_dry_run: false`** in the existing runner-controller block, so production keeps running CI live. ## Production impact: none `group_vars/all` overrides role defaults, so the effective value for `gitborg-prod` is unchanged. Verified: ``` $ ansible gitborg-prod -m debug -a "msg=effective_dry_run={{ runner_controller_dry_run }}" "msg": "effective_dry_run=False" ``` So applying this is safe — the controller stays live in prod; only *fresh* deploys (which previously went live silently) now get the safe dry-run default until explicitly opted in.
supernaut lade till 1 incheckning 2026-07-09 15:24:48 +00:00
The role default was `runner_controller_dry_run: false` while every comment
(defaults, controller.py, container template) said 'default is true'. With no
group_vars override, a fresh `--tags runner-controller` apply ran the controller
LIVE — booting/reaping real OpenStack VMs — contradicting the documented
safe-rollout (verify a clean dry-run, then flip to false).

Flip the default to true so a fresh deploy never mutates until an operator opts
in, and add an explicit `runner_controller_dry_run: false` in group_vars so prod
stays live. Net effect on prod is zero (verified: effective value resolves to
False for gitborg-prod). Reconciles the code with its own comments and the
runbook.
supernaut sammanfogade incheckning 78745c3bbb till main 2026-07-09 15:28:27 +00:00
supernaut tog bort grenen fix/runner-controller-dryrun-default 2026-07-09 15:28:27 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!32
Ingen beskrivning angiven.