CI: rename roles and variables to pass ansible-lint var-naming and role-name #65

Öppen
öppnade 2026-07-10 15:18:26 +00:00 av supernaut · 1 kommentar
Ägare

The infra ci workflow (added in PR #64) installs its non-Node tools per job — shellcheck
(apt), OpenTofu (pinned binary download from GitHub releases), and ansible/ansible-lint
(pip --break-system-packages). That adds install latency to every run and pulls the toolchain
from outside the instance on each run (a sovereignty wrinkle).

Ask

  1. Bake the tools into the runner image. Add shellcheck, OpenTofu (pinned, currently
    1.10.6), and ansible + ansible-lint to scripts/bake-runner-image.sh so the ci runner
    ships them. Then drop the "Install infra tools" step from .forgejo/workflows/ci.yml. Faster
    runs, and the toolchain stays in-instance. Ties to #35/#38.

  2. Burn down the ansible-lint skip_list. The rollout established a green baseline by skipping
    these rules in ansible/.ansible-lint (each has a # reason:); revisit and fix rather than skip
    where practical:

    • var-naming[no-role-prefix] (~91) — ~90 vars lack the role prefix; broad rename across
      templates/group_vars/inventory/cross-role refs.
    • role-name (3) — role dirs with hyphens (monitoring-agent, registry-mirror,
      runner-controller); renaming breaks site.yml role refs.
    • command-instead-of-module (2) — deliberate systemctl --user reset-failed.
    • name[template] (3) — Jinja embedded mid task-name for operator readability.
    • no-handler (3) — validate/restart tasks intentionally gated on a prior register's
      .changed to fail fast (converting to handlers would change ordering).

Notes

The yaml rule stays skipped by design — Prettier owns YAML formatting (see the formatting-CI
rollout). The dummy .vault_pass the Lint Ansible step writes is a throwaway (semantic
lint only, no decryption); baking tools does not change that.

Refs: PR #64 (formatting-CI rollout) · related #35, #38

The infra `ci` workflow (added in PR #64) installs its non-Node tools **per job** — `shellcheck` (apt), OpenTofu (pinned binary download from GitHub releases), and `ansible`/`ansible-lint` (pip `--break-system-packages`). That adds install latency to every run and pulls the toolchain from outside the instance on each run (a sovereignty wrinkle). ## Ask 1. **Bake the tools into the runner image.** Add `shellcheck`, OpenTofu (pinned, currently `1.10.6`), and `ansible` + `ansible-lint` to `scripts/bake-runner-image.sh` so the `ci` runner ships them. Then drop the "Install infra tools" step from `.forgejo/workflows/ci.yml`. Faster runs, and the toolchain stays in-instance. Ties to #35/#38. 2. **Burn down the ansible-lint `skip_list`.** The rollout established a green baseline by skipping these rules in `ansible/.ansible-lint` (each has a `# reason:`); revisit and fix rather than skip where practical: - `var-naming[no-role-prefix]` (~91) — ~90 vars lack the role prefix; broad rename across templates/group_vars/inventory/cross-role refs. - `role-name` (3) — role dirs with hyphens (`monitoring-agent`, `registry-mirror`, `runner-controller`); renaming breaks `site.yml` role refs. - `command-instead-of-module` (2) — deliberate `systemctl --user reset-failed`. - `name[template]` (3) — Jinja embedded mid task-name for operator readability. - `no-handler` (3) — validate/restart tasks intentionally gated on a prior `register`'s `.changed` to fail fast (converting to handlers would change ordering). ## Notes The `yaml` rule stays skipped by design — Prettier owns YAML formatting (see the formatting-CI rollout). The dummy `.vault_pass` the `Lint Ansible` step writes is a throwaway (semantic lint only, no decryption); baking tools does not change that. Refs: PR #64 (formatting-CI rollout) · related #35, #38
Upphovsperson
Ägare

Board grooming: this card was in Done but is only partially complete. PR #174 (merged 2026-07-20) baked the infra tools into the ci runner image and burned down the command-instead-of-module / name[template] / no-handler skips to line-level noqa. The two large items — var-naming[no-role-prefix] (~90 vars across 12 roles) and role-name (3 hyphenated role dirs) — were explicitly DEFERRED as broad, risky renames. Moving back to Backlog to track that residual; reopen-as-ready or refile a focused issue when the rename is prioritised.

Board grooming: this card was in Done but is only partially complete. PR #174 (merged 2026-07-20) baked the infra tools into the ci runner image and burned down the command-instead-of-module / name[template] / no-handler skips to line-level noqa. The two large items — var-naming[no-role-prefix] (~90 vars across 12 roles) and role-name (3 hyphenated role dirs) — were explicitly DEFERRED as broad, risky renames. Moving back to Backlog to track that residual; reopen-as-ready or refile a focused issue when the rename is prioritised.
supernaut ändrade titeln från CI: bake tofu/ansible-lint/shellcheck into the runner image + burn down ansible-lint skips till CI: rename roles and variables to pass ansible-lint var-naming and role-name 2026-10-02 22:47:14 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#65
Ingen beskrivning angiven.