Three major improvements:
1. Rootless Docker refactor: Removes docker/binary modes, unifies to
rootless Docker with per-runner system users. Each runner gets its
own rootless Docker daemon, systemd user service, and isolated
environment. Simplifies CLI (removes --mode option), Ansible role
(single code path), and molecule scenarios (removes binary scenario).
2. Auto-merge fix: Fixes status check context mismatch in branch
protection (was requiring "lint", "unit-tests", "molecule-tests" but
actual contexts are "CI / quality", "CI / molecule-tests*"). Adds
retry/wait logic to auto_merge.py that polls commit statuses for up
to 15 minutes before attempting merge, eliminating the chicken-and-egg
problem where auto-merge would fail because CI hadn't completed yet.
3. Molecule platform matrix: Adds OS platform matrix to CI — all 6
scenarios now run on all 4 supported OSes (ubuntu-2204, ubuntu-2404,
debian-12, archlinux) = 24 test pairs distributed across 3 parallel
runners. Updates distribute_molecule.py to distribute (scenario,
platform) pairs. Updates Makefile with molecule-all target for
local multi-platform testing.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- _resolve_runner now returns gitea_url from registry so disable/remove
can reuse the URL stored at install time without requiring env vars.
- Added --url option to install, disable, and remove CLI commands.
- remove(force=True) no longer requires gitea_url or token.
- Moved _parse_status outside the for loop in list_runners.
- Updated all translations and tests to match.
- docker inspect -f "{{.State.Status}}" used Go template braces that
conflicted with Ansible Jinja2 templating in the shell module.
Ansible tried to parse {{.State.Status}} as a Jinja2 variable (which
starts with a dot, making it invalid), causing a local template error.
The outer except Exception caught this immediately, so the fallback
loop never reached the legacy container name or systemctl checks.
- Replaced with: docker inspect <name> | python3 -c JSON parsing,
which avoids any brace syntax and uses python3 (already required by
Ansible on managed nodes).
- Added per-iteration try/except inside the fallback loop so a failure
on one container name continues to the next fallback instead of
aborting the entire check.
- Added tests for fallback behavior and binary mode exception path.
128 tests, 100% coverage, ruff + pyright clean
- Docker mode runners now check container status via docker inspect
instead of systemctl is-active, avoiding false unknown when systemd
service is missing or stderr output is discarded
- Binary mode still uses systemctl is-active with stderr suppressed
- Both modes now show a translated context message before the check so
users know which host/user each BECOME password prompt belongs to
- Better ansible output filtering: strip CHANGED/FAILED/UNREACHABLE
header lines and separator noise
- Map Docker container states (running/exited/dead) to systemd vocabulary
- All new user-facing messages fully translated (en/bg/de/ru/zh)
- 125 tests, 100% coverage, pyright clean, ruff clean
- run_ad_hoc() now accepts ask_become_pass and check parameters
- list_runners() passes ask_become_pass=True so --ask-become-pass is
added when running in a TTY, matching playbook behavior
- list_runners() passes check=False so systemctl is-active non-zero
exit codes (inactive=3, unknown=4) don't raise exceptions; the
actual status string is parsed from stdout instead
- TTY guard prevents --ask-become-pass from hanging in non-interactive
environments (CI, scripts)
- 123 tests, 100% coverage, pyright clean, ruff clean
- run_ad_hoc() now raises AnsibleError on non-zero exit, surfacing
stderr instead of silently returning empty stdout
- list_runners() passes become=True to run_ad_hoc since systemctl
is-active requires root privileges
- Add i18n translations for ad-hoc failure messages
- Add unit test for run_ad_hoc failure case
- Update list_runners test to expect become=True
- 119 tests, 100% coverage, pyright clean, ruff clean
- Add force parameter to RunnerManager.remove() — skips remote Ansible
playbook and only removes the local registry entry
- Add --force/-f CLI flag to grm remove command
- Add translations for --force help text across all 5 languages
- Add unit tests for force skip and CLI flag propagation
- 118 tests, 100% coverage, pyright clean, ruff clean
- Add start, stop, enable, disable, status, remove methods to RunnerManager
- Add corresponding CLI subcommands: grm start/stop/enable/disable/status/remove
- Add i18n translations for lifecycle commands across all supported languages
- Add comprehensive unit tests for lifecycle methods and CLI commands
- Fix environment variable leakage in CLI tests for GITEA_URL