fix(ansible): close audit findings across secrets, timers and templating #474

Sammanfogat
supernaut sammanfogade 5 incheckningar från fix/ansible-audit in i main 2026-09-08 23:31:07 +00:00
Ägare

What

Ansible findings from the 2026-09-09 audit. Rendered output is byte-identical at today's values wherever a literal was replaced by a variable.

Secrets and rotation:

  • Postgres password no longer on the podman exec argv in the web role; passed by name via environment:.
  • Forgejo SECRET_KEY, INTERNAL_TOKEN, oauth2 JWT_SECRET and LFS JWT_SECRET use content-hashed secret names and notify the Forgejo restart, as the metrics token and mailer password already did. A vault rotation now restarts Forgejo instead of leaving the old value live until an unrelated restart.

Drift and templating:

  • Kanidm image and tag promoted to group_vars and the registry-mirror entry templated from it. Closes #441.
  • vmagent remote-write port templated from monitoring_vm_metrics_port.
  • Kanidm OAuth2 redirect URIs for the portal and Grafana derived from the domain variables; monitoring_grafana_domain moved to group_vars because role defaults do not cross plays.
  • Renovate image split into image and tag with a Renovate annotation, so the annotation checker tracks it (21 tracked, was 20).
  • Renovate unit TimeoutStartSec follows a new renovate_unit_timeout: 2h30m, above the 2 h job budget it used to cut off at 30 min.
  • Registry mirror timer moved from Sunday 04:30, where it collided with the backup verify, to Sunday 13:00.
  • Dead forgejo_mailer_user and forgejo_mailer_passwd aliases removed; stale comment fixed.

Behaviour:

  • Reconciler .path watcher restarts when its unit changes (a reload does not re-arm PathExists=).
  • Registry-retention and token-audit timers are stopped and disabled when their flag is turned off, instead of the step being skipped.
  • Runner-controller readiness gate includes the network id the template requires.
  • Backup-drill identity fallback path corrected to .config/gitborg/.
  • DISABLE_GIT_HOOKS = true made explicit in app.ini.
  • The health-check gate no longer fails on a fresh host where bitborg-web cannot start because its image is not in the registry yet.

Not done: a Kanidm HealthCmd. The image ships only /sbin/kanidmd, no shell or curl, and kanidmd has no healthcheck subcommand, so any probe would fail.

Next apply

Expect one Forgejo restart (four secrets renamed), a daemon-reload for the renovate and timer units, and the mirror timer rescheduled. The old static-named podman secrets (gitborg-forgejo-secret-key, -internal-token, -jwt-secret, -lfs-jwt-secret) remain on the host and can be removed by hand afterwards.

Checks

ansible-lint --profile production (0 findings), site.yml --syntax-check, check-renovate-annotations.py, check-metric-names.py, apply-reconcile.py blind, and a localhost render of every changed template.

## What Ansible findings from the 2026-09-09 audit. Rendered output is byte-identical at today's values wherever a literal was replaced by a variable. Secrets and rotation: - Postgres password no longer on the `podman exec` argv in the web role; passed by name via `environment:`. - Forgejo SECRET_KEY, INTERNAL_TOKEN, oauth2 JWT_SECRET and LFS JWT_SECRET use content-hashed secret names and notify the Forgejo restart, as the metrics token and mailer password already did. A vault rotation now restarts Forgejo instead of leaving the old value live until an unrelated restart. Drift and templating: - Kanidm image and tag promoted to group_vars and the registry-mirror entry templated from it. Closes #441. - vmagent remote-write port templated from `monitoring_vm_metrics_port`. - Kanidm OAuth2 redirect URIs for the portal and Grafana derived from the domain variables; `monitoring_grafana_domain` moved to group_vars because role defaults do not cross plays. - Renovate image split into image and tag with a Renovate annotation, so the annotation checker tracks it (21 tracked, was 20). - Renovate unit `TimeoutStartSec` follows a new `renovate_unit_timeout: 2h30m`, above the 2 h job budget it used to cut off at 30 min. - Registry mirror timer moved from Sunday 04:30, where it collided with the backup verify, to Sunday 13:00. - Dead `forgejo_mailer_user` and `forgejo_mailer_passwd` aliases removed; stale comment fixed. Behaviour: - Reconciler `.path` watcher restarts when its unit changes (a reload does not re-arm `PathExists=`). - Registry-retention and token-audit timers are stopped and disabled when their flag is turned off, instead of the step being skipped. - Runner-controller readiness gate includes the network id the template requires. - Backup-drill identity fallback path corrected to `.config/gitborg/`. - `DISABLE_GIT_HOOKS = true` made explicit in app.ini. - The health-check gate no longer fails on a fresh host where `bitborg-web` cannot start because its image is not in the registry yet. Not done: a Kanidm `HealthCmd`. The image ships only `/sbin/kanidmd`, no shell or curl, and `kanidmd` has no healthcheck subcommand, so any probe would fail. ## Next apply Expect one Forgejo restart (four secrets renamed), a daemon-reload for the renovate and timer units, and the mirror timer rescheduled. The old static-named podman secrets (`gitborg-forgejo-secret-key`, `-internal-token`, `-jwt-secret`, `-lfs-jwt-secret`) remain on the host and can be removed by hand afterwards. ## Checks `ansible-lint --profile production` (0 findings), `site.yml --syntax-check`, `check-renovate-annotations.py`, `check-metric-names.py`, `apply-reconcile.py blind`, and a localhost render of every changed template.
supernaut lade till 3 incheckningar 2026-09-08 23:21:19 +00:00
supernaut lade till 2 incheckningar 2026-09-08 23:28:26 +00:00
supernaut sammanfogade incheckning 116701ec53 till main 2026-09-08 23:31:07 +00:00
supernaut tog bort grenen fix/ansible-audit 2026-09-08 23:31:07 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!474
Ingen beskrivning angiven.