mirror of
https://github.com/spantaleev/matrix-docker-ansible-deploy.git
synced 2026-08-30 04:23:14 +00:00
Scenarios install their Galaxy dependencies with `force: true`, so two roles running at once re-extract the same collections and roles into ~/.ansible and pull them out from under each other mid-play. It surfaces as a collection that was working moments earlier going missing: the connection plugin 'community.docker.docker' was not found Found while running five scenarios in parallel, where it cost a run. ANSIBLE_HOME relocates both `collections/` and `roles/`, so one variable covers both halves; the scenarios' ANSIBLE_ROLES_PATH workaround now follows it rather than hardcoding ~/.ansible/roles. Left alone if already set, and unset in CI, where each role runs in its own job and has nothing to collide with. Verified by removing var/molecule-ansible-home entirely and running matrix-alertmanager-receiver from cold: green through idempotence, with the collections and roles landing under the per-role directory - which also shows nothing was quietly relying on the shared ~/.ansible being populated. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
99 lines
4.2 KiB
YAML
99 lines
4.2 KiB
YAML
# SPDX-FileCopyrightText: 2026 Slavi Pantaleev
|
|
#
|
|
# SPDX-License-Identifier: AGPL-3.0-or-later
|
|
|
|
---
|
|
dependency:
|
|
name: galaxy
|
|
options:
|
|
requirements-file: requirements.yml
|
|
force: true
|
|
driver:
|
|
name: docker
|
|
platforms:
|
|
- name: matrix-reminder-bot-${MOLECULE_DISTRO:-ubuntu2604}-default
|
|
image: "geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2604}-ansible:latest"
|
|
command: ${MOLECULE_DOCKER_COMMAND:-""}
|
|
volumes:
|
|
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
|
cgroupns_mode: host
|
|
privileged: true
|
|
pre_build_image: true
|
|
provisioner:
|
|
name: ansible
|
|
config_options:
|
|
defaults:
|
|
callback_result_format: yaml
|
|
inventory:
|
|
group_vars:
|
|
all:
|
|
matrix_bot_matrix_reminder_bot_container_network: matrix-reminder-bot-molecule
|
|
|
|
# Unlike the bridges, this bot is not an appservice: it logs into the
|
|
# homeserver as an ordinary user with a password. The stub prepare.yml
|
|
# stands up answers /_matrix/client/v3/login with an access token, which
|
|
# is all the bot needs to get past its login and into its sync loop.
|
|
matrix_bot_matrix_reminder_bot_matrix_homeserver_url: http://matrix.molecule.local:8008
|
|
|
|
# Deliberately different from the role's default localpart
|
|
# (`bot.matrix-reminder-bot`), so verify.yml can tell what the role
|
|
# rendered apart from what it would have rendered anyway.
|
|
matrix_bot_matrix_reminder_bot_matrix_user_id_localpart: molecule.reminder-bot
|
|
matrix_bot_matrix_reminder_bot_matrix_user_password: molecule_bot_password_4f2a91
|
|
|
|
# The role has no default here and refuses to run without one. Also
|
|
# different from the bot's own fallback (`Etc/UTC`), and it reaches the
|
|
# container twice - through the config file and through TZ on the unit.
|
|
matrix_bot_matrix_reminder_bot_reminders_timezone: Europe/Sofia
|
|
|
|
# The role and the bot both default to `!`.
|
|
matrix_bot_matrix_reminder_bot_command_prefix: "%%"
|
|
|
|
# Both lists default to off with no entries, so turning them on with
|
|
# entries of our own exercises the `_auto + _custom` composition.
|
|
matrix_bot_matrix_reminder_bot_allowlist_enabled: true
|
|
matrix_bot_matrix_reminder_bot_allowlist_regexes_custom:
|
|
- "@molecule-allowed:molecule.local"
|
|
matrix_bot_matrix_reminder_bot_blocklist_enabled: true
|
|
matrix_bot_matrix_reminder_bot_blocklist_regexes_custom:
|
|
- ".*:blocked.molecule.local"
|
|
|
|
# The device name is hardcoded in the role's config template, so
|
|
# overriding it is only possible through the extension mechanism. Doing
|
|
# it here means the merge of template + extension is tested too.
|
|
matrix_bot_matrix_reminder_bot_configuration_extension_yaml: |
|
|
matrix:
|
|
device_name: Molecule Reminder Bot
|
|
|
|
# The SQLite database path is moved off the role's default (`bot.db`) so
|
|
# that verify.yml can assert the bot opened the path the role gave it,
|
|
# with the default name as a negative control.
|
|
matrix_bot_matrix_reminder_bot_sqlite_database_path_local: /matrix/matrix-reminder-bot/data/molecule-reminders.db
|
|
matrix_bot_matrix_reminder_bot_sqlite_database_path_in_container: /data/molecule-reminders.db
|
|
|
|
# verify.yml runs as its own play, where the role's defaults are out of
|
|
# scope, so the paths it reads are pinned here as literals. They match
|
|
# what the role derives from `matrix_base_data_path`.
|
|
matrix_bot_matrix_reminder_bot_base_path: /matrix/matrix-reminder-bot
|
|
matrix_bot_matrix_reminder_bot_config_path: /matrix/matrix-reminder-bot/config
|
|
matrix_bot_matrix_reminder_bot_data_path: /matrix/matrix-reminder-bot/data
|
|
matrix_bot_matrix_reminder_bot_data_store_path: /matrix/matrix-reminder-bot/data/store
|
|
env:
|
|
# Workaround for https://github.com/ansible/molecule/issues/4391
|
|
ANSIBLE_ROLES_PATH: ${MOLECULE_PROJECT_DIRECTORY}/../..:/.ansible/roles:/usr/share/ansible/roles:/etc/ansible/roles:${ANSIBLE_HOME:-~/.ansible}/roles
|
|
scenario:
|
|
test_sequence:
|
|
- dependency
|
|
- cleanup
|
|
- destroy
|
|
- syntax
|
|
- create
|
|
- prepare
|
|
- converge
|
|
- idempotence
|
|
- verify
|
|
- cleanup
|
|
- destroy
|
|
verifier:
|
|
name: ansible
|