chore(reconciler): drop the rename-transition exempt list #531

Sammanfogat
supernaut sammanfogade 1 incheckning från chore/prune-rename-transition in i main 2026-10-03 00:13:06 +00:00
Ägare

What

Remove reconciler_rename_transition_exempt and its concatenation into reconciler_user_exempt_extra in ansible/group_vars/all/vars.yml. Fix the comment on forgejo_service_accounts that pointed at it.

Why

The list was a temporary bridge for the service-account rename. Its own comment said to remove it when the tranche closed. forgejo_service_accounts already declares the seven bitborg-* accounts, and the role default reconciler_user_exempt derives from it.

The reconciler is authoritative over quota: an account missing from USER_EXEMPT is demoted to participant within one tick. So the removal was checked against live state, not assumed.

Consumers traced

  • reconciler_rename_transition_exempt: only reconciler_user_exempt_extra (vars.yml). No other reference in ansible/, docs/, scripts/.
  • reconciler_user_exempt_extra feeds reconciler_user_exempt (role default) and then USER_EXEMPT in reconciler.env.j2. The reconciler reads it as a plain list (parseList(USER_EXEMPT), exact-name set lookup).
  • All seven bitborg-* names the list added are already in forgejo_service_accounts.
  • No gitborg-* service account exists on the server: fj --host git.bitborg.se user search returns no match for all seven. The bitborg-* names match (negative control). Legacy names in USER_EXEMPT were inert.

Check-mode proof

ansible-playbook site.yml --check --diff --tags reconciler --limit bitborg-prod (from ansible/)

ok changed
main 27 0
this branch 27 1

The one change is reconciler : Install the reconciler environment file (full contract). The diff itself is hidden (the file holds secrets, task is no_log), so the rendered list was evaluated directly with ansible -m debug against the same inventory, before and after:

before: 9 base names + 14 transition names (7 gitborg-*, 7 bitborg-* duplicates)
after:  test-passkey-check, bitborg-renovate, bitborg-reconciler, bitborg-webhook-admin,
        bitborg-runner-controller, bitborg-ci, bitborg-bot, bitborg-token-audit, <operator admin>

The "after" set equals the "before" set minus the 14 transition entries. Every live service account and the operator admin remain.

Other checks

  • ansible-lint: passed, 0 failures, 0 warnings (206 files).
  • lefthook pre-commit (prettier): passed.

Apply (operator)

cd ansible
ansible-playbook site.yml --tags reconciler --limit bitborg-prod

Expected: reconciler : Install the reconciler environment file changed, nothing else. The timer picks up the new env on its next run.

Verify after the next run (Loki, bitborg-grafana):

  • The reconciler run log line appears and reports no demotions (no account moved to participant, no unexpected group removals).
  • Spot check that bitborg-ci and bitborg-renovate can still push (no 413).

Rollback: revert this commit and re-apply.

## What Remove `reconciler_rename_transition_exempt` and its concatenation into `reconciler_user_exempt_extra` in `ansible/group_vars/all/vars.yml`. Fix the comment on `forgejo_service_accounts` that pointed at it. ## Why The list was a temporary bridge for the service-account rename. Its own comment said to remove it when the tranche closed. `forgejo_service_accounts` already declares the seven `bitborg-*` accounts, and the role default `reconciler_user_exempt` derives from it. The reconciler is authoritative over quota: an account missing from `USER_EXEMPT` is demoted to `participant` within one tick. So the removal was checked against live state, not assumed. ## Consumers traced - `reconciler_rename_transition_exempt`: only `reconciler_user_exempt_extra` (vars.yml). No other reference in `ansible/`, `docs/`, `scripts/`. - `reconciler_user_exempt_extra` feeds `reconciler_user_exempt` (role default) and then `USER_EXEMPT` in `reconciler.env.j2`. The reconciler reads it as a plain list (`parseList(USER_EXEMPT)`, exact-name set lookup). - All seven `bitborg-*` names the list added are already in `forgejo_service_accounts`. - No `gitborg-*` service account exists on the server: `fj --host git.bitborg.se user search` returns no match for all seven. The `bitborg-*` names match (negative control). Legacy names in `USER_EXEMPT` were inert. ## Check-mode proof `ansible-playbook site.yml --check --diff --tags reconciler --limit bitborg-prod` (from `ansible/`) | | ok | changed | | --- | --- | --- | | main | 27 | 0 | | this branch | 27 | 1 | The one change is `reconciler : Install the reconciler environment file (full contract)`. The diff itself is hidden (the file holds secrets, task is `no_log`), so the rendered list was evaluated directly with `ansible -m debug` against the same inventory, before and after: ``` before: 9 base names + 14 transition names (7 gitborg-*, 7 bitborg-* duplicates) after: test-passkey-check, bitborg-renovate, bitborg-reconciler, bitborg-webhook-admin, bitborg-runner-controller, bitborg-ci, bitborg-bot, bitborg-token-audit, <operator admin> ``` The "after" set equals the "before" set minus the 14 transition entries. Every live service account and the operator admin remain. ## Other checks - `ansible-lint`: passed, 0 failures, 0 warnings (206 files). - lefthook pre-commit (prettier): passed. ## Apply (operator) ``` cd ansible ansible-playbook site.yml --tags reconciler --limit bitborg-prod ``` Expected: `reconciler : Install the reconciler environment file` changed, nothing else. The timer picks up the new env on its next run. Verify after the next run (Loki, `bitborg-grafana`): - The reconciler run log line appears and reports no demotions (no account moved to `participant`, no unexpected group removals). - Spot check that `bitborg-ci` and `bitborg-renovate` can still push (no 413). Rollback: revert this commit and re-apply.
supernaut lade till 1 incheckning 2026-10-03 00:10:17 +00:00
chore(reconciler): drop the rename-transition exempt list
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m17s
5a525ee11c
The ADR 0039 service-account rename is done. forgejo_service_accounts holds
the bitborg-* names, and no gitborg-* service account exists on the server
(checked by user search, bitborg-* controls found). The extra list only
added names that are already exempt or inert.

The rendered USER_EXEMPT loses the six duplicated and seven legacy entries
and keeps every live service account.
supernaut schemalade den här ändringsförfrågan för automatisk sammanfogning när alla kontroller lyckas 2026-10-03 00:10:56 +00:00
supernaut sammanfogade incheckning ce04f78b37 till main 2026-10-03 00:13:06 +00:00
supernaut tog bort grenen chore/prune-rename-transition 2026-10-03 00:13:07 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!531
Ingen beskrivning angiven.