fix: fail-open molecule selection and honest fast-path contract
CI / validate (pull_request) Successful in 47s
CI / auto-merge (pull_request) Successful in 19s

S09/REQ-9: detect_changed_roles silently skipped unmapped ansible paths
(restore.yml, build-image.yml, group_vars, playbook _tasks), emitted
nonexistent make targets for absent roles (sso_config), and fast_molecule
documented a converge+verify contract that diverged from the executed
full molecule test sequence.

- Map all infra playbooks; unmapped playbooks/ and group_vars/ now fail
  open to all testable roles.
- Role selection filtered to dirs present on disk with molecule/ dirs.
- Make targets derived by convention (molecule-<role>) instead of a
  stale hardcoded map.
- fast_molecule emits the exact commands CI runs and documents the real
  full-test sequence.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
Emil Simeonov
2026-09-23 10:08:41 +02:00
co-authored by Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
parent 6d3622465e
commit 2a94860e12
6 changed files with 290 additions and 139 deletions
+1 -1
View File
@@ -172,7 +172,7 @@ Every change starts with a spec. No spec, no code.
**CI gates (pre-merge):**
- `devx.ci.validate_spec` — checks spec exists, has required sections, REQ-IDs, all ACs checked
- `devx.ci.check_pr_size` — max 500 lines / 10 files (excludes CHANGELOG, badges, locks)
- `devx.ci.fast_molecule` — converge+verify only for changed roles, single platform
- `devx.ci.fast_molecule` — full `molecule test` for changed roles only (scoped, single platform)
**Nightly (infra only):**
- Full molecule suite (all scenarios, all platforms) + staging deploy + integration tests