diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 50f0626..55e3453 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -256,15 +256,15 @@ jobs: echo "All molecule tests passed." auto-merge: - # Auto-merge runs after validate + molecule-tests pass (or molecule is skipped). - # Uses always() so it evaluates even when molecule-tests is skipped - # (Gitea Actions skips dependent jobs of skipped jobs by default). - needs: [validate, molecule-tests] + # Auto-merge runs after validate passes. molecule-tests is NOT in needs + # because Gitea Actions skips dependent jobs of skipped jobs without + # evaluating if: conditions — having molecule-tests in needs would + # cascade the skip to auto-merge when ansible-changed=false. + needs: [validate] if: >- always() && github.event_name == 'pull_request' && - needs.validate.result == 'success' && - (needs.molecule-tests.result == 'success' || needs.molecule-tests.result == 'skipped') + needs.validate.result == 'success' runs-on: docker container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest timeout-minutes: 10 diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index d1c7acf..e0ed5e0 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -96,3 +96,43 @@ repos: types: [python] pass_filenames: false stages: [pre-push] + + - id: check-ansible-no-log + name: ansible no_log on secret tasks + entry: make check-ansible-no-log + language: system + files: ^ansible/.*\.(yml|yaml)$ + pass_filenames: false + stages: [pre-commit] + + - id: check-ansible-no-state-absent-on-db + name: no state absent on DB paths + entry: make check-ansible-no-state-absent-on-db + language: system + files: ^ansible/.*\.(yml|yaml)$ + pass_filenames: false + stages: [pre-commit] + + - id: check-ansible-patterns + name: ansible failure-masking patterns + entry: make check-ansible-patterns + language: system + files: ^ansible/.*\.(yml|yaml)$ + pass_filenames: false + stages: [pre-commit] + + - id: check-jinja-expr + name: jinja2 expression validation + entry: make check-jinja-expr + language: system + files: ^ansible/.*\.(yml|yaml|j2)$ + pass_filenames: false + stages: [pre-commit] + + - id: check-ansible-set-fact-to-json + name: set_fact to_json misuse check + entry: make check-ansible-set-fact-to-json + language: system + files: ^ansible/.*\.(yml|yaml)$ + pass_filenames: false + stages: [pre-commit] diff --git a/Makefile b/Makefile index 5aa6cea..8b67d57 100644 --- a/Makefile +++ b/Makefile @@ -175,11 +175,36 @@ makefile-lint: echo "checkmake not found, skipping Makefile lint"; \ fi -lint-all: lint ansible-lint makefile-lint workflow-lint check-api-identity-checks +lint-all: lint ansible-lint makefile-lint workflow-lint check-api-identity-checks check-ansible-no-log check-ansible-no-state-absent-on-db check-ansible-patterns check-jinja-expr check-ansible-set-fact-to-json check-api-identity-checks: @$(BIN)/python -m devx.tools.check_api_identity_checks +check-ansible-no-log: + @echo "[check-ansible-no-log] Checking Ansible tasks for missing no_log on secret-handling tasks..." + @$(BIN)/python -m devx.tools.check_ansible_no_log + @echo "[check-ansible-no-log] Passed." + +check-ansible-no-state-absent-on-db: + @echo "[check-ansible-no-state-absent-on-db] Checking for state: absent on DB data directories..." + @$(BIN)/python -m devx.tools.check_ansible_no_state_absent_on_db + @echo "[check-ansible-no-state-absent-on-db] Passed." + +check-ansible-patterns: + @echo "[check-ansible-patterns] Checking for dangerous failure-masking patterns..." + @$(BIN)/python -m devx.tools.check_ansible_patterns + @echo "[check-ansible-patterns] Passed." + +check-jinja-expr: + @echo "[check-jinja-expr] Validating Jinja2 expressions in Ansible files..." + @$(BIN)/python -m devx.tools.check_jinja_expr + @echo "[check-jinja-expr] Passed." + +check-ansible-set-fact-to-json: + @echo "[check-ansible-set-fact-to-json] Checking set_fact tasks for to_json misuse..." + @$(BIN)/python -m devx.tools.check_ansible_set_fact_to_json + @echo "[check-ansible-set-fact-to-json] Passed." + test-integration: $(BIN)/pytest tests/integration/ -v --no-cov diff --git a/pyproject.toml b/pyproject.toml index 4ddd754..3ef3fcb 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -36,7 +36,7 @@ ci = [ "build==1.5.1", "twine==6.2.0", # Reusable CI/CD and dev tools (auto-merge, pr-review, pre-push checks, etc.) - "devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.48.1", + "devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.50.0", ] # Lint and type-checking tools (validate job) lint = [ @@ -56,7 +56,7 @@ molecule = [ dev = [ "grm[ci,lint,molecule]", # Reusable CI/CD and dev tools (pre-push hooks, create-task, create-pr) - "devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.48.1", + "devx @ git+https://git.oblachno.oblachno.fyi/oblachno-oss/devx.git@v0.50.0", # Non-Python dev dependency: checkmake (Makefile linter) # Install via: go install github.com/checkmake/checkmake/cmd/checkmake@latest ]