fix(forgejo): let the playbook survive --check past the system-webhook task #257
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!257
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/check-mode-system-webhook"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
ansible-playbook site.yml --checkaborts at the forgejo role:Cause
ansible.builtin.uridoes not run under--checkby default, even for a read-only GET. SoCheck for the reconcile-trigger system webhook is skipped,
_fj_system_hooksregisters as askip-dict with no
.json, and thewhenon the following warn task dies on it — taking the wholeplay down before the
web,caddy,renovateandhealth-checkroles are ever evaluated.A real run is unaffected, which is why this went unnoticed: the GET executes,
.jsonexists, theverification works as intended.
Why it matters
It made
--checkunusable past this role. Every production apply is supposed to be gated on a cleandry-run — so in practice that gate could not be satisfied, and the failure appears at task 96 of ~300,
looking like a genuine problem with whatever changed rather than a check-mode artefact.
It also hid real drift. With the dry-run completing, the diff shows two things that had gone
unnoticed: bitborg-infra #250's Caddyfile change (
lb_try_duration 10s → 2s) was merged but neverapplied, and
forgejo: Give the storage mountpoint to the bitborg userfights thepodman unshare chowntask immediately after it, reportingchangedon every single run.Fix
check_mode: falseon the GET — it is read-only, so running it under--checkis safe, and itis what lets the verification below evaluate at all.
| default([])on thewhen— belt-and-braces: if this GET is ever skipped again or madefailure-tolerant, a missing
.jsonshould degrade to "warn" rather than abort the play.Verification
ansible-lint roles/forgejo/passes at theproductionprofile;--syntax-checkpasses.No behaviour change to a real apply:
check_mode: falseis a no-op outside--check, anddefault([])only fires on a value that cannot occur when the GET has run.