mirror of
https://github.com/spantaleev/matrix-docker-ansible-deploy.git
synced 2026-08-30 12:33:14 +00:00
`tasks/main.yml` opens with a block tagged `reset-hookshot-encryption`, and Ansible runs tagged tasks unless tags are actually selected. A run that selects no tags therefore reaches `tasks/reset_encryption.yml`: on a host where the service does not exist yet it fails outright, and on one where it does it stops the bridge and resets its crypto store without being asked to. Users of the playbook are shielded from this only because the documented way to run it always passes `--tags=setup-all,start`. Adding `never` makes the block reachable only when its tag is explicitly selected, which is what `--tags=reset-hookshot-encryption` in docs/configuring-playbook-bridge-hookshot.md already does - that keeps working unchanged, as selecting a tag by name overrides `never`. The Molecule scenario no longer needs its `skip-tags` workaround, which is what makes this verifiable: the scenario runs with no tags selected, and is green with the workaround gone. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
42 lines
1.4 KiB
YAML
42 lines
1.4 KiB
YAML
# SPDX-FileCopyrightText: 2022 - 2024 Slavi Pantaleev
|
|
# SPDX-FileCopyrightText: 2022 MDAD project contributors
|
|
# SPDX-FileCopyrightText: 2022 Marko Weltzer
|
|
#
|
|
# SPDX-License-Identifier: AGPL-3.0-or-later
|
|
|
|
---
|
|
|
|
- tags:
|
|
# Resetting the crypto store is destructive and is only ever meant to happen
|
|
# when explicitly asked for. Without `never`, a playbook run that does not
|
|
# select tags at all runs this block along with everything else - which fails
|
|
# on a host where the service does not exist yet, and silently resets the
|
|
# crypto store on one where it does.
|
|
- never
|
|
- reset-hookshot-encryption
|
|
block:
|
|
- when: matrix_bridge_hookshot_enabled | bool
|
|
ansible.builtin.include_tasks: "{{ role_path }}/tasks/reset_encryption.yml"
|
|
|
|
- tags:
|
|
- setup-all
|
|
- setup-hookshot
|
|
- setup-bridge-hookshot
|
|
- install-all
|
|
- install-hookshot
|
|
- install-bridge-hookshot
|
|
block:
|
|
- when: matrix_bridge_hookshot_enabled | bool
|
|
ansible.builtin.include_tasks: "{{ role_path }}/tasks/validate_config.yml"
|
|
|
|
- when: matrix_bridge_hookshot_enabled | bool
|
|
ansible.builtin.include_tasks: "{{ role_path }}/tasks/setup_install.yml"
|
|
|
|
- tags:
|
|
- setup-all
|
|
- setup-hookshot
|
|
- setup-bridge-hookshot
|
|
block:
|
|
- when: not matrix_bridge_hookshot_enabled | bool
|
|
ansible.builtin.include_tasks: "{{ role_path }}/tasks/setup_uninstall.yml"
|