diff --git a/.ansible-lint b/.ansible-lint index e750c57..6b5f8aa 100644 --- a/.ansible-lint +++ b/.ansible-lint @@ -5,5 +5,3 @@ skip_list: exclude_paths: - .forgejo/ - "**/*.sops.yaml" - - ansible_collections/ - - galaxy_roles/ diff --git a/.forgejo/workflows/lint.yaml b/.forgejo/workflows/lint.yaml index 5113e9f..a867c13 100644 --- a/.forgejo/workflows/lint.yaml +++ b/.forgejo/workflows/lint.yaml @@ -10,7 +10,7 @@ jobs: name: Ansible Lint runs-on: docker steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5 - name: Install pip run: | apt update @@ -24,7 +24,7 @@ jobs: # work in our environmnet. # Rather manually setup python (pip) before instead. - name: Run ansible-lint - uses: https://github.com/ansible/ansible-lint@v26.1.1 + uses: https://github.com/ansible/ansible-lint@d7cd7cfa2469536527aceaef9ef2ec6f2fb331cb # v25.9.2 with: setup_python: "false" requirements_file: "requirements.yml" diff --git a/.sops.yaml b/.sops.yaml index 60da9eb..98aaf3c 100644 --- a/.sops.yaml +++ b/.sops.yaml @@ -33,37 +33,15 @@ keys: - &host_public_reverse_proxy_ansible_pull_age_key age1p7pxgq5kwcpdkhkh3qq4pvnltrdk4gwf60hdhv8ka0mdxmgnjepqyleyen - &host_zammad_ansible_pull_age_key age1sv7uhpnk9d3u3je9zzvlux0kd83f627aclpamnz2h3ksg599838qjgrvqs - &host_ntfy_ansible_pull_age_key age1dkecypmfuj0tcm2cz8vnvq5drpu2ddhgnfkzxvscs7m4e79gpseqyhr9pg - - &host_spaceapiccc_ansible_pull_age_key age1mdtnk78aeqnwqadjqje5pfha04wu92d3ecchyqajjmy434kwq98qksq2wa - - &host_acmedns_ansible_pull_age_key age16pxqxdj25xz6w200sf8duc62vyk0xkhzc7y63nyhg29sm077vp8qy4sywv - external: - age: &host_external_age_keys - - &host_status_ansible_pull_age_key age1yl9ts8k6ceymaxjs72r5puetes5mtuzxuger7qgme9qkagfrm9hqzxx9qr creation_rules: - ## group vars + # group vars - path_regex: inventories/chaosknoten/group_vars/all.* key_groups: - pgp: *admin_gpg_keys age: *host_chaosknoten_age_keys - - path_regex: inventories/external/group_vars/all.* - key_groups: - - pgp: - *admin_gpg_keys - age: - *host_external_age_keys - - path_regex: inventories/z9/group_vars/all.* - key_groups: - - pgp: - *admin_gpg_keys - ## host vars - # chaosknoten hosts - - path_regex: inventories/chaosknoten/host_vars/acmedns.* - key_groups: - - pgp: - *admin_gpg_keys - age: - - *host_acmedns_ansible_pull_age_key + # host vars - path_regex: inventories/chaosknoten/host_vars/cloud.* key_groups: - pgp: @@ -172,20 +150,6 @@ creation_rules: *admin_gpg_keys age: - *host_public_reverse_proxy_ansible_pull_age_key - - path_regex: inventories/chaosknoten/host_vars/spaceapiccc.* - key_groups: - - pgp: - *admin_gpg_keys - age: - - *host_spaceapiccc_ansible_pull_age_key - # external hosts - - path_regex: inventories/external/host_vars/status.* - key_groups: - - pgp: - *admin_gpg_keys - age: - - *host_status_ansible_pull_age_key - # z9 hosts - path_regex: inventories/z9/host_vars/dooris.* key_groups: - pgp: diff --git a/README.md b/README.md index dff670a..5a3d90c 100644 --- a/README.md +++ b/README.md @@ -7,14 +7,12 @@ Folgende Geräte und Server werden duch dieses Ansible Repository verwaltet: Host-spezifische Konfigurationsdateien liegen unter `resources/` und werden für jeweils über eine `host_vars`-Datei im Inventory geladen. -## Galaxy-Collections und -Rollen +## Galaxy-Collections und -Rollen installieren -Für einige Aspekte verwenden wir Collections und Rollen aus Ansible Galaxy. Diese werden in [`ansible_collections`](./ansible_collections/) bzw. [`galaxy-roles`](./galaxy-roles/) hier im Repo vorgehalten. +Für einige Aspekte verwenden wir Rollen aus Ansible Galaxy. Die müssen zunächst installiert werden: -Um unsere gevendorte Version zu aktualisieren, kann man folgendes machen: ```bash ansible-galaxy install -r requirements.yml -ansible-galaxy role install -r requirements.yml ``` ## Secrets diff --git a/ansible.cfg b/ansible.cfg index 805406f..654da28 100644 --- a/ansible.cfg +++ b/ansible.cfg @@ -2,5 +2,3 @@ inventory = ./inventories/z9/hosts.yaml pipelining = True vars_plugins_enabled = host_group_vars,community.sops.sops -collections_path = ./ -roles_path = ./galaxy-roles diff --git a/ansible_collections/community/docker/.ansible-lint b/ansible_collections/community/docker/.ansible-lint deleted file mode 100644 index bd65000..0000000 --- a/ansible_collections/community/docker/.ansible-lint +++ /dev/null @@ -1,30 +0,0 @@ ---- -# Copyright (c) Ansible Project -# GNU General Public License v3.0+ (see LICENSES/GPL-3.0-or-later.txt or https://www.gnu.org/licenses/gpl-3.0.txt) -# SPDX-License-Identifier: GPL-3.0-or-later - -skip_list: - # Ignore rules that make no sense: - - galaxy[tags] - - galaxy[version-incorrect] - - meta-runtime[unsupported-version] - - no-changed-when - - sanity[cannot-ignore] # some of the rules you cannot ignore actually MUST be ignored, like yamllint:unparsable-with-libyaml - - yaml # we're using yamllint ourselves - - run-once[task] # wtf??? - - # To be checked and maybe fixed: - - ignore-errors - - key-order[task] - - name[casing] - - name[missing] - - name[play] - - name[template] - - no-free-form - - no-handler - - risky-file-permissions - - risky-shell-pipe - - var-naming[no-reserved] - - var-naming[no-role-prefix] - - var-naming[pattern] - - var-naming[read-only] diff --git a/ansible_collections/community/docker/.azure-pipelines/README.md b/ansible_collections/community/docker/.azure-pipelines/README.md deleted file mode 100644 index 9e8ad74..0000000 --- a/ansible_collections/community/docker/.azure-pipelines/README.md +++ /dev/null @@ -1,9 +0,0 @@ - - -## Azure Pipelines Configuration - -Please see the [Documentation](https://github.com/ansible/community/wiki/Testing:-Azure-Pipelines) for more information. diff --git a/ansible_collections/community/docker/.azure-pipelines/azure-pipelines.yml b/ansible_collections/community/docker/.azure-pipelines/azure-pipelines.yml deleted file mode 100644 index 1919fe7..0000000 --- a/ansible_collections/community/docker/.azure-pipelines/azure-pipelines.yml +++ /dev/null @@ -1,280 +0,0 @@ ---- -# Copyright (c) Ansible Project -# GNU General Public License v3.0+ (see LICENSES/GPL-3.0-or-later.txt or https://www.gnu.org/licenses/gpl-3.0.txt) -# SPDX-License-Identifier: GPL-3.0-or-later - -trigger: - batch: true - branches: - include: - - main - - stable-* - -pr: - autoCancel: true - branches: - include: - - main - - stable-* - -schedules: - - cron: 0 9 * * * - displayName: Nightly - always: true - branches: - include: - - main - - cron: 0 12 * * 0 - displayName: Weekly (old stable branches) - always: true - branches: - include: - - stable-4 - -variables: - - name: checkoutPath - value: ansible_collections/community/docker - - name: coverageBranches - value: main - - name: entryPoint - value: tests/utils/shippable/shippable.sh - - name: fetchDepth - value: 0 - -resources: - containers: - - container: default - image: quay.io/ansible/azure-pipelines-test-container:7.0.0 - -pool: Standard - -stages: - -### Sanity & units - - stage: Ansible_devel - displayName: Sanity & Units devel - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - targets: - - name: Sanity - test: 'devel/sanity/1' - - name: Units - test: 'devel/units/1' - - stage: Ansible_2_20 - displayName: Sanity & Units 2.20 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - targets: - - name: Sanity - test: '2.20/sanity/1' - - name: Units - test: '2.20/units/1' - - stage: Ansible_2_19 - displayName: Sanity & Units 2.19 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - targets: - - name: Sanity - test: '2.19/sanity/1' - - name: Units - test: '2.19/units/1' - - stage: Ansible_2_18 - displayName: Sanity & Units 2.18 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - targets: - - name: Sanity - test: '2.18/sanity/1' - - name: Units - test: '2.18/units/1' - -### Docker - - stage: Docker_devel - displayName: Docker devel - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: devel/linux/{0} - targets: - - name: Fedora 42 - test: fedora42 - - name: Ubuntu 22.04 - test: ubuntu2204 - - name: Ubuntu 24.04 - test: ubuntu2404 - - name: Alpine 3.22 - test: alpine322 - groups: - - 4 - - 5 - - stage: Docker_2_20 - displayName: Docker 2.20 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: 2.20/linux/{0} - targets: - - name: Fedora 42 - test: fedora42 - - name: Alpine 3.22 - test: alpine322 - groups: - - 4 - - 5 - - stage: Docker_2_19 - displayName: Docker 2.19 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: 2.19/linux/{0} - targets: - - name: Fedora 41 - test: fedora41 - - name: Alpine 3.21 - test: alpine321 - groups: - - 4 - - 5 - - stage: Docker_2_18 - displayName: Docker 2.18 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: 2.18/linux/{0} - targets: - - name: Fedora 40 - test: fedora40 - - name: Ubuntu 22.04 - test: ubuntu2204 - - name: Alpine 3.20 - test: alpine320 - groups: - - 4 - - 5 - -### Community Docker - - stage: Docker_community_devel - displayName: Docker (community images) devel - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: devel/linux-community/{0} - targets: - - name: Debian 11 Bullseye - test: debian-bullseye/3.9 - - name: Debian 12 Bookworm - test: debian-bookworm/3.11 - - name: Debian 13 Trixie - test: debian-13-trixie/3.13 - - name: ArchLinux - test: archlinux/3.13 - groups: - - 4 - - 5 - -### Remote - - stage: Remote_devel - displayName: Remote devel - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: devel/{0} - targets: - - name: RHEL 10.0 - test: rhel/10.0 - - name: RHEL 9.6 with Docker SDK, urllib3, requests from sources - test: rhel/9.6-dev-latest - # For some reason, Ubuntu 24.04 is *extremely* slower than RHEL 9.6 - # - name: Ubuntu 24.04 - # test: ubuntu/24.04 - groups: - - 1 - - 2 - - 3 - - 4 - - 5 - - stage: Remote_2_20 - displayName: Remote 2.20 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: 2.20/{0} - targets: - - name: RHEL 9.6 - test: rhel/9.6 - groups: - - 1 - - 2 - - 3 - - 4 - - 5 - - stage: Remote_2_19 - displayName: Remote 2.19 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: 2.19/{0} - targets: - - name: RHEL 9.5 - test: rhel/9.5 - - name: Ubuntu 22.04 - test: ubuntu/22.04 - groups: - - 1 - - 2 - - 3 - - 4 - - 5 - - stage: Remote_2_18 - displayName: Remote 2.18 - dependsOn: [] - jobs: - - template: templates/matrix.yml - parameters: - testFormat: 2.18/{0} - targets: - - name: RHEL 9.4 - test: rhel/9.4 - groups: - - 1 - - 2 - - 3 - - 4 - - 5 - - ## Finally - - - stage: Summary - condition: succeededOrFailed() - dependsOn: - - Ansible_devel - - Ansible_2_20 - - Ansible_2_19 - - Ansible_2_18 - - Remote_devel - - Remote_2_20 - - Remote_2_19 - - Remote_2_18 - - Docker_devel - - Docker_2_20 - - Docker_2_19 - - Docker_2_18 - - Docker_community_devel - jobs: - - template: templates/coverage.yml diff --git a/ansible_collections/community/docker/.azure-pipelines/scripts/aggregate-coverage.sh b/ansible_collections/community/docker/.azure-pipelines/scripts/aggregate-coverage.sh deleted file mode 100755 index 0ccef35..0000000 --- a/ansible_collections/community/docker/.azure-pipelines/scripts/aggregate-coverage.sh +++ /dev/null @@ -1,28 +0,0 @@ -#!/usr/bin/env bash -# Aggregate code coverage results for later processing. - -# Copyright (c) Ansible Project -# GNU General Public License v3.0+ (see LICENSES/GPL-3.0-or-later.txt or https://www.gnu.org/licenses/gpl-3.0.txt) -# SPDX-License-Identifier: GPL-3.0-or-later - -set -o pipefail -eu - -agent_temp_directory="$1" - -PATH="${PWD}/bin:${PATH}" - -mkdir "${agent_temp_directory}/coverage/" - -if [[ "$(ansible --version)" =~ \ 2\.9\. ]]; then - exit -fi - -options=(--venv --venv-system-site-packages --color -v) - -ansible-test coverage combine --group-by command --export "${agent_temp_directory}/coverage/" "${options[@]}" - -if ansible-test coverage analyze targets generate --help >/dev/null 2>&1; then - # Only analyze coverage if the installed version of ansible-test supports it. - # Doing so allows this script to work unmodified for multiple Ansible versions. - ansible-test coverage analyze targets generate "${agent_temp_directory}/coverage/coverage-analyze-targets.json" "${options[@]}" -fi diff --git a/ansible_collections/community/docker/.azure-pipelines/scripts/combine-coverage.py b/ansible_collections/community/docker/.azure-pipelines/scripts/combine-coverage.py deleted file mode 100755 index 3b2fd99..0000000 --- a/ansible_collections/community/docker/.azure-pipelines/scripts/combine-coverage.py +++ /dev/null @@ -1,64 +0,0 @@ -#!/usr/bin/env python -# Copyright (c) Ansible Project -# GNU General Public License v3.0+ (see LICENSES/GPL-3.0-or-later.txt or https://www.gnu.org/licenses/gpl-3.0.txt) -# SPDX-License-Identifier: GPL-3.0-or-later - -""" -Combine coverage data from multiple jobs, keeping the data only from the most recent attempt from each job. -Coverage artifacts must be named using the format: "Coverage $(System.JobAttempt) {StableUniqueNameForEachJob}" -The recommended coverage artifact name format is: Coverage $(System.JobAttempt) $(System.StageDisplayName) $(System.JobDisplayName) -Keep in mind that Azure Pipelines does not enforce unique job display names (only names). -It is up to pipeline authors to avoid name collisions when deviating from the recommended format. -""" - -from __future__ import (absolute_import, division, print_function) -__metaclass__ = type - -import os -import re -import shutil -import sys - - -def main(): - """Main program entry point.""" - source_directory = sys.argv[1] - - if '/ansible_collections/' in os.getcwd(): - output_path = "tests/output" - else: - output_path = "test/results" - - destination_directory = os.path.join(output_path, 'coverage') - - if not os.path.exists(destination_directory): - os.makedirs(destination_directory) - - jobs = {} - count = 0 - - for name in os.listdir(source_directory): - match = re.search('^Coverage (?P[0-9]+) (?P