fix(health-check): do not run the concealment gate on the monitoring host #351
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!351
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/concealment-gate-monitoring-host"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes #350.
ansible-playbook site.yml --checkfailed on the monitoring host:Cause — an asymmetry in how the two tags are scoped
forgejo_image_taggroup_vars/all/vars.ymlkanidm_image_tagroles/kanidm/defaults/main.ymlThe monitoring play runs
base,podman,monitoring,health-check— no kanidm role — sokanidm_image_tagis never defined there.health_check_concealmentdefaults totrue, so the gateran anyway and the assert died while templating its
fail_msg.Not specific to running without tags.
health-checkcarries thealwaystag, so everyinvocation reaching that host failed. Reproduced with an explicitly tagged run before the fix:
Why this shape of fix
Turned off explicitly on the monitoring play, next to the
health_check_servicesoverride alreadythere — rather than guarding the task with
kanidm_image_tag is defined. A gate that silently skipson a missing variable is precisely the trap the role's own comments warn about, and it would hide the
same mistake on the host where the gate does matter.
The task immediately above this one carries the scar from the last occurrence:
That is now the second health gate to fail on the monitoring host. Whether the role should
distinguish services-host gates from universal ones, rather than scoping each by hand as it is
found, is raised in #350 and deliberately not attempted here.
Verification
The gate still runs and passes on the services host — it is not disabled globally:
and skips on monitoring.
The single
changed=1on the services host is theMONITOR_*comment block from #341, which hasmerged but not yet been applied — expected, not drift.
ansible-playbook site.yml --syntax-checkandprettier -care clean.Pre-existing, not addressed here
ansible-lintreportsyaml[indentation]onlocal/render.yml:65. It is onmainuntouched(confirmed by stashing this change), dates from the original local-preview commit, and is a
Prettier-versus-ansible-lint disagreement over a reformatted flow mapping. Left alone to keep this
change to one thing.