ci: ansible and ansible-lint are still unpinned in the runner image bake #400
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#400
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
ansibleandansible-lintare installed into the runner image with no version:Every other tool baked into that image is pinned —
RUNNER_VERSION,TOFU_VERSION,NODE_VERSION,GITLEAKS_VERSION, and nowRUFF_VERSION(#399). These two are what is left.Why it matters, and why it is not urgent
Same failure shape as the ruff pin: CI runs whatever was newest on bake day, a version the repo
cannot name and no developer can reproduce.
ansible-lintin particular adds rules between minorreleases, so a re-bake can fail CI on unchanged code — and the reverse, a stale image quietly
accepting what a current lint would reject, is the worse direction.
It is less acute than ruff was for one reason: a re-bake is a deliberate, infrequent act, and the
image currently in use has been exercised by many green runs. The exposure is a future re-bake,
not today's CI.
Why it is not just "add a pin"
Unlike ruff,
ansibleis not only a linter. It is the thing that configures the entire estate, soits version is coupled to:
ansible/requirements.ymlpinscontainers.podman,ansible.posix,community.general,community.crypto— a core bump can move the minimum each needs)had to reason about carefully (see the
apply-reconciletooling and the--checknotes in therunbook)
So pinning it without deciding which version, and re-running a full
--checkagainst both hoststo confirm nothing moved, would trade an unknown for a differently-shaped unknown.
Suggested approach
ansible --version,ansible-lint --versionon alive runner) — that is today's de facto pin and the safest first value.
post-install assertion
ruffnow has.They are different machines doing different jobs; forcing equality may not be wanted.
ansible-lintshould get a wrapper likescripts/ruff.sh/scripts/shellcheck.shso local and CI cannot disagree at all. It is the same class of tool.Acceptance
site.yml --checkagainst both hosts is unchanged atchanged=0on the pinned version.