fix(ansible): close audit findings across secrets, timers and templating #474
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!474
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/ansible-audit"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Ansible findings from the 2026-09-09 audit. Rendered output is byte-identical at today's values wherever a literal was replaced by a variable.
Secrets and rotation:
podman execargv in the web role; passed by name viaenvironment:.Drift and templating:
monitoring_vm_metrics_port.monitoring_grafana_domainmoved to group_vars because role defaults do not cross plays.TimeoutStartSecfollows a newrenovate_unit_timeout: 2h30m, above the 2 h job budget it used to cut off at 30 min.forgejo_mailer_userandforgejo_mailer_passwdaliases removed; stale comment fixed.Behaviour:
.pathwatcher restarts when its unit changes (a reload does not re-armPathExists=)..config/gitborg/.DISABLE_GIT_HOOKS = truemade explicit in app.ini.bitborg-webcannot start because its image is not in the registry yet.Not done: a Kanidm
HealthCmd. The image ships only/sbin/kanidmd, no shell or curl, andkanidmdhas no healthcheck subcommand, so any probe would fail.Next apply
Expect one Forgejo restart (four secrets renamed), a daemon-reload for the renovate and timer units, and the mirror timer rescheduled. The old static-named podman secrets (
gitborg-forgejo-secret-key,-internal-token,-jwt-secret,-lfs-jwt-secret) remain on the host and can be removed by hand afterwards.Checks
ansible-lint --profile production(0 findings),site.yml --syntax-check,check-renovate-annotations.py,check-metric-names.py,apply-reconcile.py blind, and a localhost render of every changed template.