fix(ansible): --check survives a not-yet-converged Guest (Closes #50) #51
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!51
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/50-fix-make-prod-check"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What this fixes
make prodandmake predied at the service step on any Guest that had not been converged. TheserviceTarget rehearses withansible-playbook --check --diff(Makefile:266-271), and the rehearsal itself failed, so the real run never happened.Check mode skips the steps that create the inputs, and several modules do not tolerate a missing input even under
--check:get_url—dest's parent directory absentunarchive/copywithremote_src— source absentsystemd: state=started|restarted— unit file never renderedbecome_user: postgres— the user the skipped apt install would have created (Unprivileged become user would be unable to read the file)uriandwait_forare unaffected (auto-skipped without check-mode support).Approach
Guard only what
--checkgenuinely cannot produce, with one read per fact — and keep it declarative:forgejo_tree(/srv/forgejo/bin) around theget_urls, the twosystemdstarts and the two handlers in theforgejoroleforgejo_pg(/usr/bin/psql) around the fivepostgrestasksforgejo_mcp_tree(/srv/forgejo-mcp/releases) around the install block, the start block and the handler inforgejo_mcpThe check writes nothing; a converged Guest previews exactly as before.
Also folds the
forgejo_mcpinstall:unarchivestraight intobin/with--strip-components=1, dropping the separate copy task and the intermediatereleases/<stem>/tree.get_urlstays:unarchivehas nochecksumparameter, so fetching inside it would drop the pinned-sha256 verification, andget_urlis also the cache — it revalidates with a HEAD rather than re-downloading the ~5.7 MB on every run and check.Verification (live on PRE 142; PROD not touched)
--check, fresh PRE, beforefailed=1(Destination /srv/forgejo/bin does not exist)--check, fresh PRE, afterfailed=0, nothing writtenforgejorole onlychanged=22site.yml(+forgejo_mcp)changed=7, MCP 401 probe oksite.ymlchanged=0--check, converged PREfailed=0curl -X POST http://10.12.0.142:8089/mcp401Host403systemctl is-activeforgejo / runner / mcpCloses #50
b63f56777eto588573e066