mirror of
https://github.com/trailofbits/algo.git
synced 2026-08-17 21:25:50 +02:00
* fix: add explicit bool filters for Ansible 12 jinja2_native compatibility Ansible 12 enables jinja2_native by default, which means string values like "true"/"false" are no longer automatically coerced to booleans in when: conditions and Jinja2 if statements. Add | bool filters to all boolean variable references in tasks, templates, and handlers. Also reformats long single-line Jinja2 conditionals into multi-line for readability, fixes GCE default() calls for native mode, adds help command to the algo script, and updates test fixtures to register the bool filter. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * ci: add j2lint for Jinja2 template linting Add j2lint (aristanetworks/j2lint) to catch syntax errors, spacing issues, and operator formatting in Jinja2 templates. Integrated into pre-commit hooks, lint.yml CI, and smart-tests.yml. Rules S3/S5/S6/S7/V1 are ignored — they enforce conventions incompatible with Ansible's config-file-embedded templates. Also fixes int+1 → int + 1 operator spacing in server.conf.j2. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve all ansible-lint warnings and enforce zero-tolerance policy Fix 18 jinja[spacing] errors across 12 files by moving Jinja2 block delimiters to prevent YAML >- folding from introducing trailing spaces. Fix 27 key-order[task] warnings across 17 files by reordering task keys to canonical order (name → when → tags → environment → become → block). Promote key-order[task] and yaml[line-length] from warn_list to hard errors by removing warn_list entirely from .ansible-lint. Add zero-tolerance warning policy to CLAUDE.md explaining why warnings are unacceptable in a security tool and documenting resolution order. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
51 lines
1.5 KiB
YAML
51 lines
1.5 KiB
YAML
---
|
|
- name: Include prompts
|
|
import_tasks: prompts.yml
|
|
|
|
- name: Upload the SSH key
|
|
digital_ocean_sshkey:
|
|
oauth_token: "{{ algo_do_token }}"
|
|
name: "{{ SSH_keys.comment }}"
|
|
ssh_pub_key: "{{ lookup('file', SSH_keys.public) }}"
|
|
register: do_ssh_key
|
|
|
|
- name: Creating a droplet...
|
|
digital_ocean_droplet:
|
|
state: present
|
|
name: "{{ algo_server_name }}"
|
|
oauth_token: "{{ algo_do_token }}"
|
|
size: "{{ cloud_providers.digitalocean.size }}"
|
|
region: "{{ algo_do_region }}"
|
|
image: "{{ cloud_providers.digitalocean.image }}"
|
|
wait_timeout: 300
|
|
unique_name: true
|
|
ipv6: true
|
|
ssh_keys: "{{ do_ssh_key.data.ssh_key.id }}"
|
|
user_data: "{{ lookup('template', 'files/cloud-init/base.yml') | string }}"
|
|
tags:
|
|
- Environment:Algo
|
|
register: digital_ocean_droplet
|
|
|
|
# Return data is not idempotent
|
|
- set_fact:
|
|
droplet: "{{ digital_ocean_droplet.data.droplet | default(digital_ocean_droplet.data) }}"
|
|
|
|
- when: alternative_ingress_ip | bool
|
|
block:
|
|
- name: Create a Floating IP
|
|
community.digitalocean.digital_ocean_floating_ip:
|
|
state: present
|
|
oauth_token: "{{ algo_do_token }}"
|
|
droplet_id: "{{ droplet.id }}"
|
|
register: digital_ocean_floating_ip
|
|
|
|
- name: Set the static ip as a fact
|
|
set_fact:
|
|
cloud_alternative_ingress_ip: "{{ digital_ocean_floating_ip.data.floating_ip.ip }}"
|
|
|
|
- set_fact:
|
|
cloud_instance_ip: "{{ (droplet.networks.v4 | selectattr('type', '==', 'public')).0.ip_address }}"
|
|
ansible_ssh_user: algo
|
|
ansible_ssh_port: "{{ ssh_port }}"
|
|
cloudinit: true
|