CI: rename roles and variables to pass ansible-lint var-naming and role-name #65
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#65
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
The infra
ciworkflow (added in PR #64) installs its non-Node tools per job —shellcheck(apt), OpenTofu (pinned binary download from GitHub releases), and
ansible/ansible-lint(pip
--break-system-packages). That adds install latency to every run and pulls the toolchainfrom outside the instance on each run (a sovereignty wrinkle).
Ask
Bake the tools into the runner image. Add
shellcheck, OpenTofu (pinned, currently1.10.6), andansible+ansible-linttoscripts/bake-runner-image.shso thecirunnerships them. Then drop the "Install infra tools" step from
.forgejo/workflows/ci.yml. Fasterruns, and the toolchain stays in-instance. Ties to #35/#38.
Burn down the ansible-lint
skip_list. The rollout established a green baseline by skippingthese rules in
ansible/.ansible-lint(each has a# reason:); revisit and fix rather than skipwhere practical:
var-naming[no-role-prefix](~91) — ~90 vars lack the role prefix; broad rename acrosstemplates/group_vars/inventory/cross-role refs.
role-name(3) — role dirs with hyphens (monitoring-agent,registry-mirror,runner-controller); renaming breakssite.ymlrole refs.command-instead-of-module(2) — deliberatesystemctl --user reset-failed.name[template](3) — Jinja embedded mid task-name for operator readability.no-handler(3) — validate/restart tasks intentionally gated on a priorregister's.changedto fail fast (converting to handlers would change ordering).Notes
The
yamlrule stays skipped by design — Prettier owns YAML formatting (see the formatting-CIrollout). The dummy
.vault_passtheLint Ansiblestep writes is a throwaway (semanticlint only, no decryption); baking tools does not change that.
Refs: PR #64 (formatting-CI rollout) · related #35, #38
Board grooming: this card was in Done but is only partially complete. PR #174 (merged 2026-07-20) baked the infra tools into the ci runner image and burned down the command-instead-of-module / name[template] / no-handler skips to line-level noqa. The two large items — var-naming[no-role-prefix] (~90 vars across 12 roles) and role-name (3 hyphenated role dirs) — were explicitly DEFERRED as broad, risky renames. Moving back to Backlog to track that residual; reopen-as-ready or refile a focused issue when the rename is prioritised.
CI: bake tofu/ansible-lint/shellcheck into the runner image + burn down ansible-lint skipstill CI: rename roles and variables to pass ansible-lint var-naming and role-name