fix(ansible): stop uri tasks reading the operator's ~/.netrc #434

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/uri-tasks-ignore-netrc in i main 2026-08-17 11:50:17 +00:00
Ägare

Every ansible.builtin.uri task in the tree read the operator's ~/.netrc, because that is the default. None of them need it.

Four carry an explicit Authorization header (a Forgejo admin token or a Kanidm bearer token) and two hit unauthenticated health endpoints. So netrc can only do one of two things here: send an unrelated credential to one of our own hosts, or fail the task outright.

It did the second. A single malformed line in a developer's ~/.netrc (a region token, which is not netrc syntax) made every one of these fail:

Status code was -1 and not [200]: An unknown error occurred:
bad follower token 'region' (~/.netrc, line 4)

That reads as an outage. It killed a production dry-run at roles/forgejo/tasks/system-webhook.yml, and killed the credential-reset onboarding flow at roles/kanidm/tasks/reset-links.yml, on a completely healthy host. Diagnosing it costs real time because the message names neither Ansible nor the host.

Sets use_netrc: false on all six, with the reasoning recorded at each site.

Verification

A full --check against production, with no NETRC workaround in the environment:

PLAY RECAP  bitborg-prod : ok=290  changed=2  failed=0

Zero netrc references in the log, and the previously-failing task returns ok. Before this change the same command gave failed=1.

The changed=2 is unrelated pending drift: the merged Alloy bump (#433) is not yet applied.

Every `ansible.builtin.uri` task in the tree read the operator's `~/.netrc`, because that is the default. **None of them need it.** Four carry an explicit `Authorization` header (a Forgejo admin token or a Kanidm bearer token) and two hit unauthenticated health endpoints. So netrc can only do one of two things here: send an unrelated credential to one of our own hosts, or fail the task outright. It did the second. A single malformed line in a developer's `~/.netrc` (a `region` token, which is not netrc syntax) made every one of these fail: ``` Status code was -1 and not [200]: An unknown error occurred: bad follower token 'region' (~/.netrc, line 4) ``` That reads as an outage. It killed a production dry-run at `roles/forgejo/tasks/system-webhook.yml`, and killed the credential-reset onboarding flow at `roles/kanidm/tasks/reset-links.yml`, on a completely healthy host. Diagnosing it costs real time because the message names neither Ansible nor the host. Sets `use_netrc: false` on all six, with the reasoning recorded at each site. ## Verification A full `--check` against production, with **no `NETRC` workaround in the environment**: ``` PLAY RECAP bitborg-prod : ok=290 changed=2 failed=0 ``` Zero netrc references in the log, and the previously-failing task returns `ok`. Before this change the same command gave `failed=1`. The `changed=2` is unrelated pending drift: the merged Alloy bump (#433) is not yet applied.
supernaut lade till 1 incheckning 2026-08-17 11:18:22 +00:00
fix(ansible): stop uri tasks reading the operator's ~/.netrc
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m37s
7794e46d20
Every ansible.builtin.uri task in the tree read the operator's ~/.netrc,
because that is the default. None of them need it.

Four carry an explicit Authorization header (a Forgejo admin token or a Kanidm
bearer token) and two hit unauthenticated health endpoints. So netrc can only
do one of two things here: send an unrelated credential to one of our own
hosts, or fail the task outright.

It did the second. A single malformed line in a developer's ~/.netrc — an
`region` token, which is not netrc syntax — made every one of these fail with

    Status code was -1 and not [200]: An unknown error occurred:
    bad follower token 'region' (~/.netrc, line 4)

That reads as an outage. It killed a production dry-run at
roles/forgejo/tasks/system-webhook.yml, and killed the credential-reset
onboarding flow at roles/kanidm/tasks/reset-links.yml, on a host that was
completely healthy.

Sets use_netrc: false on all six, with the reasoning recorded at each site.

Verified: a full --check against production now completes with failed=0 and
zero netrc references in the log, with no NETRC workaround in the environment.
The task that previously failed returns ok.
supernaut sammanfogade incheckning 4270f8707c till main 2026-08-17 11:50:17 +00:00
supernaut tog bort grenen fix/uri-tasks-ignore-netrc 2026-08-17 11:50:17 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!434
Ingen beskrivning angiven.