fix(runner-controller): safe dry_run default (true), opt prod in via group_vars #32
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!32
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/runner-controller-dryrun-default"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Summary
Reconciles a code/comment/doc contradiction in the ephemeral runner controller (surfaced by the docs audit in #31).
roles/runner-controller/defaults/main.ymlsetrunner_controller_dry_run: false, but every comment describing it — the default's own header,controller.py("DRY_RUN=true (default) — safe by default"), and the container template — said the default is true. With nogroup_varsoverride, a freshansible-playbook --tags runner-controllerapply therefore ran the controller live (booting and reaping real OpenStack VMs) instead of the documented safe dry-run, making the runbook's "verify a clean dry-run, then flip to false" rollout impossible.Change
roles/runner-controller/defaults/main.yml:runner_controller_dry_run: false→true. This makes the role default match its own comments — a fresh deploy never mutates until an operator opts in.group_vars/all/vars.yml: add explicitrunner_controller_dry_run: falsein the existing runner-controller block, so production keeps running CI live.Production impact: none
group_vars/alloverrides role defaults, so the effective value forgitborg-prodis unchanged. Verified:So applying this is safe — the controller stays live in prod; only fresh deploys (which previously went live silently) now get the safe dry-run default until explicitly opted in.