fix(forgejo): let the playbook survive --check past the system-webhook task #257

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/check-mode-system-webhook in i main 2026-07-30 16:09:07 +00:00
Ägare

ansible-playbook site.yml --check aborts at the forgejo role:

A 'when' expression failed: Error while evaluating conditional:
object of type 'dict' has no attribute 'json'
roles/forgejo/tasks/system-webhook.yml:27

PLAY RECAP
gitborg-prod : ok=96 changed=1 unreachable=0 failed=1 skipped=45

Cause

ansible.builtin.uri does not run under --check by default, even for a read-only GET. So
Check for the reconcile-trigger system webhook is skipped, _fj_system_hooks registers as a
skip-dict with no .json, and the when on the following warn task dies on it — taking the whole
play down before the web, caddy, renovate and health-check roles are ever evaluated.

A real run is unaffected, which is why this went unnoticed: the GET executes, .json exists, the
verification works as intended.

Why it matters

It made --check unusable past this role. Every production apply is supposed to be gated on a clean
dry-run — so in practice that gate could not be satisfied, and the failure appears at task 96 of ~300,
looking like a genuine problem with whatever changed rather than a check-mode artefact.

It also hid real drift. With the dry-run completing, the diff shows two things that had gone
unnoticed: bitborg-infra #250's Caddyfile change (lb_try_duration 10s → 2s) was merged but never
applied, and forgejo: Give the storage mountpoint to the bitborg user fights the
podman unshare chown task immediately after it, reporting changed on every single run.

Fix

  • check_mode: false on the GET — it is read-only, so running it under --check is safe, and it
    is what lets the verification below evaluate at all.
  • | default([]) on the when — belt-and-braces: if this GET is ever skipped again or made
    failure-tolerant, a missing .json should degrade to "warn" rather than abort the play.

Verification

ansible-playbook site.yml --check --diff --limit gitborg-prod
gitborg-prod : ok=215 changed=13 unreachable=0 failed=0 skipped=85

ansible-lint roles/forgejo/ passes at the production profile; --syntax-check passes.

No behaviour change to a real apply: check_mode: false is a no-op outside --check, and
default([]) only fires on a value that cannot occur when the GET has run.

`ansible-playbook site.yml --check` aborts at the forgejo role: ``` A 'when' expression failed: Error while evaluating conditional: object of type 'dict' has no attribute 'json' roles/forgejo/tasks/system-webhook.yml:27 PLAY RECAP gitborg-prod : ok=96 changed=1 unreachable=0 failed=1 skipped=45 ``` ## Cause `ansible.builtin.uri` does not run under `--check` by default, even for a read-only GET. So **Check for the reconcile-trigger system webhook** is skipped, `_fj_system_hooks` registers as a skip-dict with no `.json`, and the `when` on the following warn task dies on it — taking the whole play down before the `web`, `caddy`, `renovate` and `health-check` roles are ever evaluated. A real run is unaffected, which is why this went unnoticed: the GET executes, `.json` exists, the verification works as intended. ## Why it matters It made `--check` unusable past this role. Every production apply is supposed to be gated on a clean dry-run — so in practice that gate could not be satisfied, and the failure appears at task 96 of ~300, looking like a genuine problem with whatever changed rather than a check-mode artefact. It also hid real drift. With the dry-run completing, the diff shows two things that had gone unnoticed: bitborg-infra #250's Caddyfile change (`lb_try_duration 10s → 2s`) was merged but never applied, and `forgejo: Give the storage mountpoint to the bitborg user` fights the `podman unshare chown` task immediately after it, reporting `changed` on every single run. ## Fix - **`check_mode: false`** on the GET — it is read-only, so running it under `--check` is safe, and it is what lets the verification below evaluate at all. - **`| default([])`** on the `when` — belt-and-braces: if this GET is ever skipped again or made failure-tolerant, a missing `.json` should degrade to "warn" rather than abort the play. ## Verification ``` ansible-playbook site.yml --check --diff --limit gitborg-prod gitborg-prod : ok=215 changed=13 unreachable=0 failed=0 skipped=85 ``` `ansible-lint roles/forgejo/` passes at the `production` profile; `--syntax-check` passes. No behaviour change to a real apply: `check_mode: false` is a no-op outside `--check`, and `default([])` only fires on a value that cannot occur when the GET has run.
supernaut lade till 1 incheckning 2026-07-30 15:38:42 +00:00
fix(forgejo): let the playbook survive --check past the system-webhook task
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m22s
386135a918
`ansible-playbook site.yml --check` aborted at the forgejo role with:

  A 'when' expression failed: object of type 'dict' has no attribute 'json'
  roles/forgejo/tasks/system-webhook.yml:27

ansible.builtin.uri does not run under --check by default, even for a read-only
GET. So "Check for the reconcile-trigger system webhook" was skipped,
`_fj_system_hooks` registered as a skip-dict with no `.json`, and the `when` on
the following warn task died on it — taking the whole play down (failed=1) before
the web, caddy, renovate and health-check roles were ever evaluated.

A real run was unaffected, which is why this went unnoticed: the GET executes,
`.json` exists, the verification works. But it made `--check` unusable past this
role, and every production apply is supposed to be gated on a clean dry-run — so
in practice the gate could not be satisfied.

Two changes:

- `check_mode: false` on the GET. It is read-only, so running it under --check is
  safe and is what lets the verification below evaluate at all.
- `| default([])` on the `when`. Belt-and-braces: if this GET is ever skipped
  again or made failure-tolerant, a missing `.json` should degrade to "warn"
  rather than abort the play.

With this, `--check --diff` completes: ok=215 changed=13 failed=0.
supernaut sammanfogade incheckning 4e5b919f07 till main 2026-07-30 16:09:07 +00:00
supernaut tog bort grenen fix/check-mode-system-webhook 2026-07-30 16:09:08 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!257
Ingen beskrivning angiven.