ci: bake tofu/ansible-lint/shellcheck into the runner image + burn down ansible-lint skips #174
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!174
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/65-ci-runner-tools"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What & why
Two parts of #65.
1. Bake infra tools into the
cirunner imageThe
ciworkflow installed shellcheck (apt), OpenTofu (pinned binary), andansible + ansible-lint (
pip --break-system-packages) per job — slow, and itpulls the toolchain off-instance on every run.
scripts/bake-runner-image.shso the bakedgitborg-runnerimage ships them:
shellcheck,python3-pip,unzipvia apt; the pinnedOpenTofu binary;
ansible+ansible-lintvia pip. Each is sanity-checked inthe bake so a missing/broken tool fails the bake.
from
.forgejo/workflows/ci.yml. Thetofu fmt,ansible-lintandshellchecksteps now rely on the baked-in tools.TOFU_VERSIONinscripts/bake-runner-image.sh(default1.10.6, unchanged from the old CIpin). The workflow no longer hard-codes a version. (Before this PR the pin
lived only in
ci.yml, so moving it to the bake script keeps a single owner.)roles/runner-controller/files/README-runner-image.mdtoolchain tableto document the three new tools and where the pin lives.
#65comments inci.yml(the smoke step's "pip installabove" reference now points at the baked-in ansible).
2. Burn down the ansible-lint
skip_listConverted the intentional one-off cases from global skips to line-level
# noqa, so a new accidental violation of these rules will now fail CI, whilethe deliberate cases stay green.
command-instead-of-modulesystemctl --user reset-failedinroles/web+roles/runner-controller, plus a third occurrence the issue didn't list:systemctl --user is-activehealth probe inroles/health-check(added since the issue was written). All three noqa'd — read-only / noansible.builtin.systemdequivalent.name[template]roles/forgejo/tasks/create-user.yml×2,roles/kanidm/tasks/reset-links.yml) — deliberate for operator readability.no-handler.changedgating. 4 occurrences (issue estimated 3):roles/caddy×2,roles/monitoring×2 — validate/restart must run inline to fail fast / keep ordering.var-naming[no-role-prefix]skip_listwith a# DEFERRED (#65)reason. A dedicated follow-up may be warranted.role-namemonitoring-agent,registry-mirror,runner-controller); renaming dirs breakssite.ymlrole refs. Kept inskip_listwith a reason.yamlValidation
ansible-lint(fromansible/, throwaway.vault_passas CI does): Passed — 0 failures, 0 warnings, 163 files, profileproduction.pnpm ansible:check(ansible-playbook site.yml --syntax-check): OK.pnpm format:check(Prettier) +pnpm mdlint: clean (README table re-aligned).bash -n scripts/bake-runner-image.sh: OK;shellcheck scripts/*.sh: clean.OpenStack CLI + builder VM). The image must be re-baked (
scripts/bake-runner-image.sh --replace) and promoted before the trimmedci.ymlruns, otherwise the infrasteps will fail on missing tools. The bake script is syntactically sound and
internally consistent with the edited
ci.yml.Refs #65 (the
var-naming/role-nameburn-downs are explicitly out of scopehere and deferred — a follow-up issue may be warranted).
The bake installed Debian trixie's `nodejs` package (Node 20.19.2), but both repos pin Node 24.18.0 (Volta + packageManager pnpm@11) and the runner-image README already specifies 'Node.js 24+'. On the freshly-baked image the ci job's `corepack enable` + `pnpm install --frozen-lockfile` ("Install Node dependencies") ran on Node 20 and failed (run 109 attempt 2). Drop `nodejs` from apt; install the pinned official Node binary to /usr/local (NODE_VERSION=24.18.0, single source of truth == volta.node), enable corepack. bash -n + shellcheck clean.Added commit
c08935f: bake pinned Node 24.18.0 instead of Debian's Node 20.The freshly-baked image shipped Debian trixie's
nodejs(Node 20.19.2), but both repos pin Node 24.18.0 (Volta +packageManagerpnpm@11) and this README already specifies "Node.js 24+". Socorepack enable+pnpm install --frozen-lockfile(the ci job's "Install Node dependencies") ran on Node 20 and failed (run 109 attempt 2).Change: drop
nodejsfrom apt; install the pinned official Node binary to/usr/local(NODE_VERSION=24.18.0, single source of truth ==volta.node),corepack enable. The in-bake sanity checknode --versionnow asserts 24. bash -n + shellcheck clean.Re-bake required from this branch before merge (the previous bake produced the Node-20 image).