ci: run infra steps only when their area changed (+ ansible↔tofu x-dep) #112

Sammanfogat
supernaut sammanfogade 2 incheckningar från chore/ci-path-filters in i main 2026-07-18 18:53:22 +00:00
Ägare

Stops the CI job running the full toolchain (apt install, tofu download, ansible pip, image-pull smokes) on every PR — docs-only PRs now run just prettier + markdownlint.

Stacked on #111 (textfile smoke) — merge that first; this branch's diff includes it until then.

Gating

A Detect changed areas step diffs the PR base and sets outputs; each infra step is if:-gated:

Step Runs when
prettier, markdownlint always (cheap, repo-wide)
OpenTofu fmt opentofu/ changed
ansible-lint + both Tier-0 smokes ansible/ changed (smokes also on scripts/)
shellcheck scripts/ changed
infra-tools install any infra step will use it

Cross-dependency (the part you flagged)

Per the infra-apply model — OpenTofu provisions the host, Ansible configures it ("do OpenTofu first") — the dependency is directional:

  • a tofu change re-triggers the ansible checks (its substrate may have changed);
  • an ansible change does not trigger tofu (can't affect tofu's own fmt).

Anything outside ansible/opentofu/scripts/docs (root config, this workflow, package.json) runs everything; if the base diff can't be resolved it fails safe to all. Full functional cross-stack validation (converge Ansible on a tofu-provisioned host) is Tier-1, not this static CI (bitborg-docs#37 / #105).

Validated

Table-tested the detection logic across docs-only / ansible-only / tofu-only / scripts-only / combined / root / fallback — flags resolve correctly, including tofu-only → ansible=true. Workflow YAML parses (12 steps, gates as intended); prettier clean.

Note: needs fetch-depth: 0 on checkout for the base diff (added).

Stops the CI job running the full toolchain (apt install, tofu download, ansible pip, image-pull smokes) on every PR — docs-only PRs now run just prettier + markdownlint. > **Stacked on #111** (textfile smoke) — merge that first; this branch's diff includes it until then. ## Gating A `Detect changed areas` step diffs the PR base and sets outputs; each infra step is `if:`-gated: | Step | Runs when | | --- | --- | | prettier, markdownlint | always (cheap, repo-wide) | | OpenTofu fmt | `opentofu/` changed | | ansible-lint + both Tier-0 smokes | `ansible/` changed (smokes also on `scripts/`) | | shellcheck | `scripts/` changed | | infra-tools install | any infra step will use it | ## Cross-dependency (the part you flagged) Per the infra-apply model — OpenTofu provisions the host, Ansible configures it ("do OpenTofu first") — the dependency is **directional**: - a **tofu change re-triggers the ansible checks** (its substrate may have changed); - an **ansible change does not trigger tofu** (can't affect tofu's own fmt). Anything outside `ansible/opentofu/scripts/docs` (root config, this workflow, package.json) runs **everything**; if the base diff can't be resolved it **fails safe to all**. Full functional cross-stack validation (converge Ansible on a tofu-provisioned host) is Tier-1, not this static CI (bitborg-docs#37 / #105). ## Validated Table-tested the detection logic across docs-only / ansible-only / tofu-only / scripts-only / combined / root / fallback — flags resolve correctly, including **tofu-only → ansible=true**. Workflow YAML parses (12 steps, gates as intended); prettier clean. Note: needs `fetch-depth: 0` on checkout for the base diff (added).
supernaut lade till 2 incheckningar 2026-07-18 16:56:31 +00:00
feat(ci): Tier-0 textfile-metric safety guard (#104)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m53s
0b37bc6f7f
Second increment of the pre-prod validation epic (gitborg-docs#37):
close the #96 failure class in CI. That bug — token-audit.prom created
by mktemp (0600) then mv'd into the textfile dir — was unreadable by
node_exporter (non-root in the rootless container), so metrics silently
never reached VM despite a green apply and a status-0 run.

scripts/smoke-textfile.py (pure stdlib, runs anywhere): for each script
that publishes a .prom into the node_exporter textfile dir, fail if the
temp it mv's to the .prom comes from mktemp with no world-readable chmod.
It traces the actual mv source, so scripts that publish via '>' (0644 via
umask) and use mktemp only for unrelated work files are not flagged.

Chosen static over behavioural deliberately: the 9 metric scripts call
live curl/jq/GNU-date/podman/skopeo/openstack and use GNU date -d, so a
faithful stubbed run is more fragile than the deterministic file-mode bug
it would catch. The faithful behavioural check — assert
node_textfile_scrape_error==0 after a real converge — is Tier-1 / the
post-apply health gate (#105 / #107).

Validated both directions: all 9 current scripts pass (no false positives
after tracing the real mv source — an earlier coarse 'contains mktemp'
heuristic false-flagged 3 that write via '>'); reverting token-audit's
chmod makes it FAIL. Wired into ci.yml.

Refs #104.
ci: run infra steps only when their area changed (+ ansible↔tofu x-dep)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m31s
c52b7adf3e
The CI job ran the full toolchain (apt install, tofu download, ansible
pip, image-pull smokes) on every PR, including docs-only ones. Gate each
infra step on a change-detection step that diffs the PR base.

- prettier + markdownlint: always (cheap, repo-wide).
- tofu fmt: only when opentofu/ changed.
- ansible-lint + both Tier-0 smokes: when ansible/ (or the smoke scripts
  in scripts/) changed.
- shellcheck: when scripts/ changed.
- infra-tools install: only when some infra step will use it.

Cross-dependency (infra-apply: OpenTofu provisions, Ansible configures on
top — 'do OpenTofu first') is DIRECTIONAL: a tofu change re-triggers the
ansible checks (its substrate may have changed), but an ansible change
does not trigger tofu (can't affect tofu fmt). Any change outside
ansible/opentofu/scripts/docs (root config, this workflow, package.json)
runs everything; if the base diff can't be resolved it fails safe to all.

Full functional cross-stack validation (converge ansible on a
tofu-provisioned host) is Tier-1, not this static CI (gitborg-docs#37 /
#105).

Detection logic table-tested across docs-only / ansible-only / tofu-only
/ scripts-only / combined / root / fallback — flags resolve correctly,
incl. tofu-only → ansible=true.
supernaut sammanfogade incheckning d0097d2d39 till main 2026-07-18 18:53:22 +00:00
supernaut tog bort grenen chore/ci-path-filters 2026-07-18 18:53:22 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!112
Ingen beskrivning angiven.