fix(health-check): do not run the concealment gate on the monitoring host #351

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/concealment-gate-monitoring-host in i main 2026-08-02 16:35:04 +00:00
Ägare

Closes #350.

ansible-playbook site.yml --check failed on the monitoring host:

TASK [health-check : Health gate — identity concealment was verified against the deployed image tags (ADR 0038)]
[ERROR]: Error while resolving value for 'fail_msg': 'kanidm_image_tag' is undefined
fatal: [gitborg-monitoring]: FAILED!

Cause — an asymmetry in how the two tags are scoped

Variable Defined in Visible to
forgejo_image_tag group_vars/all/vars.yml every host
kanidm_image_tag roles/kanidm/defaults/main.yml only plays including the kanidm role

The monitoring play runs base, podman, monitoring, health-check — no kanidm role — so
kanidm_image_tag is never defined there. health_check_concealment defaults to true, so the gate
ran anyway and the assert died while templating its fail_msg.

Not specific to running without tags. health-check carries the always tag, so every
invocation reaching that host failed. Reproduced with an explicitly tagged run before the fix:

ansible-playbook site.yml --check --limit monitoring --tags health-check
→ gitborg-monitoring : ok=1 changed=0 unreachable=0 failed=1

Why this shape of fix

Turned off explicitly on the monitoring play, next to the health_check_services override already
there — rather than guarding the task with kanidm_image_tag is defined. A gate that silently skips
on a missing variable is precisely the trap the role's own comments warn about, and it would hide the
same mistake on the host where the gate does matter.

The task immediately above this one carries the scar from the last occurrence:

gated on not ansible_check_mode this task was skipped in every dry-run, which is why a gate that
fails on the monitoring host reached production before anyone saw it. Same trap as #257.

That is now the second health gate to fail on the monitoring host. Whether the role should
distinguish services-host gates from universal ones, rather than scoping each by hand as it is
found, is raised in #350 and deliberately not attempted here.

Verification

site.yml --check --diff (full, no tags, both hosts)
  exit=0
  gitborg-monitoring : ok=56   changed=0  unreachable=0  failed=0  skipped=26
  gitborg-prod       : ok=254  changed=1  unreachable=0  failed=0  skipped=86
  fatal/ERROR lines: 0

The gate still runs and passes on the services host — it is not disabled globally:

TASK [health-check : Health gate — identity concealment ...]
ok: [gitborg-prod] => "Concealment selectors verified against the deployed Forgejo + Kanidm tags."

and skips on monitoring.

The single changed=1 on the services host is the MONITOR_* comment block from #341, which has
merged but not yet been applied — expected, not drift.

ansible-playbook site.yml --syntax-check and prettier -c are clean.

Pre-existing, not addressed here

ansible-lint reports yaml[indentation] on local/render.yml:65. It is on main untouched
(confirmed by stashing this change), dates from the original local-preview commit, and is a
Prettier-versus-ansible-lint disagreement over a reformatted flow mapping. Left alone to keep this
change to one thing.

Closes #350. `ansible-playbook site.yml --check` failed on the monitoring host: ```text TASK [health-check : Health gate — identity concealment was verified against the deployed image tags (ADR 0038)] [ERROR]: Error while resolving value for 'fail_msg': 'kanidm_image_tag' is undefined fatal: [gitborg-monitoring]: FAILED! ``` ## Cause — an asymmetry in how the two tags are scoped | Variable | Defined in | Visible to | | --- | --- | --- | | `forgejo_image_tag` | `group_vars/all/vars.yml` | every host | | `kanidm_image_tag` | `roles/kanidm/defaults/main.yml` | only plays including the kanidm role | The monitoring play runs `base`, `podman`, `monitoring`, `health-check` — no kanidm role — so `kanidm_image_tag` is never defined there. `health_check_concealment` defaults to `true`, so the gate ran anyway and the assert died while templating its `fail_msg`. **Not specific to running without tags.** `health-check` carries the `always` tag, so every invocation reaching that host failed. Reproduced with an explicitly tagged run before the fix: ```text ansible-playbook site.yml --check --limit monitoring --tags health-check → gitborg-monitoring : ok=1 changed=0 unreachable=0 failed=1 ``` ## Why this shape of fix Turned off explicitly on the monitoring play, next to the `health_check_services` override already there — rather than guarding the task with `kanidm_image_tag is defined`. A gate that silently skips on a missing variable is precisely the trap the role's own comments warn about, and it would hide the same mistake on the host where the gate does matter. The task immediately above this one carries the scar from the last occurrence: > gated on `not ansible_check_mode` this task was skipped in every dry-run, which is why a gate that > fails on the monitoring host reached production before anyone saw it. Same trap as #257. That is now the second health gate to fail on the monitoring host. Whether the role should distinguish services-host gates from universal ones, rather than scoping each by hand as it is found, is raised in #350 and deliberately not attempted here. ## Verification ```text site.yml --check --diff (full, no tags, both hosts) exit=0 gitborg-monitoring : ok=56 changed=0 unreachable=0 failed=0 skipped=26 gitborg-prod : ok=254 changed=1 unreachable=0 failed=0 skipped=86 fatal/ERROR lines: 0 ``` The gate still **runs and passes** on the services host — it is not disabled globally: ```text TASK [health-check : Health gate — identity concealment ...] ok: [gitborg-prod] => "Concealment selectors verified against the deployed Forgejo + Kanidm tags." ``` and skips on monitoring. The single `changed=1` on the services host is the `MONITOR_*` comment block from #341, which has merged but not yet been applied — expected, not drift. `ansible-playbook site.yml --syntax-check` and `prettier -c` are clean. ### Pre-existing, not addressed here `ansible-lint` reports `yaml[indentation]` on `local/render.yml:65`. It is on `main` untouched (confirmed by stashing this change), dates from the original local-preview commit, and is a Prettier-versus-ansible-lint disagreement over a reformatted flow mapping. Left alone to keep this change to one thing.
supernaut lade till 1 incheckning 2026-08-02 16:32:52 +00:00
fix(health-check): do not run the concealment gate on the monitoring host
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m23s
e2af1baa2f
The ADR 0038 gate asserts the deployed Forgejo and Kanidm image tags, but the
two are not scoped alike: forgejo_image_tag is a group_var and so visible
everywhere, while kanidm_image_tag is a kanidm role default and therefore
undefined in the monitoring play, which runs base, podman, monitoring and
health-check only. The gate is on by default, so the assert died resolving its
fail_msg and took the whole run with it.

Not specific to running without tags — health-check carries the always tag, so
any invocation reaching that host failed, a tagged apply included.

Turned off explicitly on the monitoring play rather than guarded with
'kanidm_image_tag is defined' inside the role: a gate that silently skips on a
missing variable is the trap the role's own comments warn about, and it would
hide the same mistake on the host where the gate does matter.

Verified: full 'site.yml --check --diff' now exits 0 with both hosts clean, the
gate still runs and passes on the services host, and skips on monitoring.

Closes #350
supernaut sammanfogade incheckning 983b138d53 till main 2026-08-02 16:35:04 +00:00
supernaut tog bort grenen fix/concealment-gate-monitoring-host 2026-08-02 16:35:04 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!351
Ingen beskrivning angiven.