Files
matrix-docker-ansible-deploy/roles/custom/matrix-bridge-mautrix-meta-messenger/molecule/default/molecule.yml
T
Slavi PantaleevandClaude Opus 5 85f80a3c7e Test the Molecule scenarios against Postgres rather than sqlite
`group_vars/matrix_servers` selects postgres whenever postgres is enabled, which
is the default, so postgres is what essentially every deployment runs. The
scenarios were testing sqlite - a path almost nobody is on.

How little that path is used is not a guess: the mautrix-meta bridges could not
start at all under sqlite, and nobody reported it. Testing the engine users are
actually on is worth more than keeping coverage of the one they are not, so no
scenario is left behind on sqlite.

Four of the eight scenarios have a database and are converted; the other four
have none and are untouched.

molecule-shared/tasks/postgres.yml stands Postgres up on the scenario's network,
with the data directory on a tmpfs since it is thrown away with the container.
The image is pinned at the major the postgres role deploys to new installations
and left to Renovate: when a new major lands, the PR bumping that pin runs every
scenario against it, which is the earliest warning we get that a component does
not cope.

Each scenario gives its database and user names that differ from the role's
defaults, so the component reaching the database proves the role built its
connection string out of them. The assertions moved from "a file appeared at the
path we configured" to "these tables exist", which is strictly stronger: tables
can only appear once the component has resolved the hostname, authenticated with
the credentials the role rendered, and run its migrations to completion.

Costs about 10 seconds per affected scenario (115s to 125s locally for
mautrix-whatsapp), on jobs that run in parallel.

Gotcha worth recording: since Postgres 18 the image puts PGDATA in a versioned
subdirectory and refuses to start if it finds a mount at the old
/var/lib/postgresql/data, so the tmpfs is mounted at /var/lib/postgresql.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SEH3vxYSQ5SV4N5z61eyGT
2026-08-27 18:02:53 +03:00

99 lines
4.7 KiB
YAML

# SPDX-FileCopyrightText: 2026 Slavi Pantaleev
#
# SPDX-License-Identifier: AGPL-3.0-or-later
---
dependency:
name: galaxy
options:
requirements-file: requirements.yml
force: true
driver:
name: docker
platforms:
- name: mautrix-meta-messenger-${MOLECULE_DISTRO:-ubuntu2604}-default
image: "geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2604}-ansible:latest"
command: ${MOLECULE_DOCKER_COMMAND:-""}
volumes:
- /sys/fs/cgroup:/sys/fs/cgroup:rw
cgroupns_mode: host
privileged: true
pre_build_image: true
provisioner:
name: ansible
config_options:
defaults:
callback_result_format: yaml
inventory:
group_vars:
all:
matrix_bridge_mautrix_meta_messenger_container_network: mautrix-meta-messenger-molecule
# The stub prepare.yml stands up. Not a real homeserver, and nothing is asserted
# about it.
matrix_bridge_mautrix_meta_messenger_homeserver_address: http://matrix.molecule.local:8008
matrix_bridge_mautrix_meta_messenger_homeserver_domain: molecule.local
# Postgres, because that is what `group_vars/matrix_servers` selects whenever postgres
# is enabled - which is the default, so it is what essentially every real deployment
# runs. prepare.yml stands one up. Name and user differ from the role's defaults, so
# reaching the database proves the role built its connection string out of these.
matrix_bridge_mautrix_meta_messenger_database_engine: postgres
matrix_bridge_mautrix_meta_messenger_database_hostname: matrix-postgres-molecule
matrix_bridge_mautrix_meta_messenger_database_name: molecule_meta_messenger
matrix_bridge_mautrix_meta_messenger_database_username: molecule_meta_messenger
matrix_bridge_mautrix_meta_messenger_database_password: molecule_pg_password_d24e70
# Here these only have to reach the rendered configuration and the registration.
matrix_bridge_mautrix_meta_messenger_appservice_token: molecule_meta_as_token_5c81de
matrix_bridge_mautrix_meta_messenger_homeserver_token: molecule_meta_hs_token_a70f24
# What makes this role family unusual: one upstream codebase serves several Meta
# networks, and this variable picks which. It reaches the rendered configuration in
# four places at once - appservice id, ghost username prefix, bot displayname and the
# bridge's `tor` switch - so a value other than the role's default is what tells
# verify.yml the role propagated the choice rather than everything agreeing by accident.
#
# `facebook-tor` is used because it is the only mode that also flips a boolean.
# Nothing logs in during the scenario, so the bridge never connects to Meta.
matrix_bridge_mautrix_meta_messenger_meta_mode: facebook-tor
# Different from the role's defaults and from what the bridge would pick on its own,
# so verify.yml can tell what the role rendered apart from a coincidence.
matrix_bridge_mautrix_meta_messenger_appservice_username: molecule-metabot
matrix_bridge_mautrix_meta_messenger_bridge_command_prefix: "!molecule-meta"
matrix_bridge_mautrix_meta_messenger_bridge_displayname_suffix: "(Molecule)"
matrix_bridge_mautrix_meta_messenger_logging_min_level: debug
# Traefik is not deployed here, so nothing routes to it. What is tested is that the
# role turns these three variables into both the container's Traefik labels and the
# `appservice.public_address` the bridge itself reads.
matrix_bridge_mautrix_meta_messenger_exposure_enabled: true
matrix_bridge_mautrix_meta_messenger_exposure_hostname: bridges.molecule.local
matrix_bridge_mautrix_meta_messenger_exposure_path_prefix: /bridges/meta-messenger
matrix_bridge_mautrix_meta_messenger_scheme: https
# verify.yml runs as its own play, where the role's defaults are out of scope,
# so the paths it reads are pinned here to match what the role derives.
matrix_bridge_mautrix_meta_messenger_base_path: /matrix/mautrix-meta-messenger
matrix_bridge_mautrix_meta_messenger_config_path: /matrix/mautrix-meta-messenger/config
matrix_bridge_mautrix_meta_messenger_data_path: /matrix/mautrix-meta-messenger/data
env:
# Workaround for https://github.com/ansible/molecule/issues/4391
ANSIBLE_ROLES_PATH: ${MOLECULE_PROJECT_DIRECTORY}/../..:/.ansible/roles:/usr/share/ansible/roles:/etc/ansible/roles:${ANSIBLE_HOME:-~/.ansible}/roles
scenario:
test_sequence:
- dependency
- cleanup
- destroy
- syntax
- create
- prepare
- converge
- idempotence
- verify
- cleanup
- destroy
verifier:
name: ansible