fix(health-check): the concealment gate fails on the monitoring host #350
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#350
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
ansible-playbook site.yml --checkfails on the monitoring host:Cause
The concealment gate asserts the deployed Forgejo and Kanidm image tags. Those two variables are not
scoped the same way:
forgejo_image_tagansible/group_vars/all/vars.ymlkanidm_image_tagansible/roles/kanidm/defaults/main.ymlThe monitoring play runs
base,podman,monitoringandhealth-check— no kanidm role — sokanidm_image_tagis never defined there.health_check_concealmentdefaults totrue, so the gateruns anyway, and the assert dies while templating its
fail_msg.It is not specific to running without tags
health-checkcarries thealwaystag, so the gate runs on every invocation that reaches themonitoring host. Reproduced with an explicitly tagged run:
A tagged apply is not protection.
This is the second time a health gate has failed on the monitoring host
The task immediately above it carries this comment:
Worth considering whether the role should distinguish services-host gates from gates that apply to
every host, rather than each one being scoped by hand as it is discovered.
Fix
Set
health_check_concealment: falseon the monitoring play'shealth-checkinvocation, next to thehealth_check_servicesoverride that is already there.Deliberately not guarded with
kanidm_image_tag is definedinside the role: a gate that silentlyskips when a variable is missing is exactly the trap the role's own comments warn about, and it would
hide the same mistake on the host where the gate does matter.
Done when
ansible-playbook site.yml --checkcompletes without this failure