mirror of
https://github.com/trailofbits/algo.git
synced 2026-08-17 21:25:50 +02:00
* fix: add explicit bool filters for Ansible 12 jinja2_native compatibility Ansible 12 enables jinja2_native by default, which means string values like "true"/"false" are no longer automatically coerced to booleans in when: conditions and Jinja2 if statements. Add | bool filters to all boolean variable references in tasks, templates, and handlers. Also reformats long single-line Jinja2 conditionals into multi-line for readability, fixes GCE default() calls for native mode, adds help command to the algo script, and updates test fixtures to register the bool filter. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * ci: add j2lint for Jinja2 template linting Add j2lint (aristanetworks/j2lint) to catch syntax errors, spacing issues, and operator formatting in Jinja2 templates. Integrated into pre-commit hooks, lint.yml CI, and smart-tests.yml. Rules S3/S5/S6/S7/V1 are ignored — they enforce conventions incompatible with Ansible's config-file-embedded templates. Also fixes int+1 → int + 1 operator spacing in server.conf.j2. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve all ansible-lint warnings and enforce zero-tolerance policy Fix 18 jinja[spacing] errors across 12 files by moving Jinja2 block delimiters to prevent YAML >- folding from introducing trailing spaces. Fix 27 key-order[task] warnings across 17 files by reordering task keys to canonical order (name → when → tags → environment → become → block). Promote key-order[task] and yaml[line-length] from warn_list to hard errors by removing warn_list entirely from .ansible-lint. Add zero-tolerance warning policy to CLAUDE.md explaining why warnings are unacceptable in a security tool and documenting resolution order. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
82 lines
2.4 KiB
YAML
82 lines
2.4 KiB
YAML
---
|
|
- name: Include prompts
|
|
import_tasks: prompts.yml
|
|
|
|
- name: Network configured
|
|
gcp_compute_network:
|
|
auth_kind: serviceaccount
|
|
service_account_file: "{{ credentials_file_path }}"
|
|
project: "{{ project_id }}"
|
|
name: algovpn
|
|
auto_create_subnetworks: true
|
|
routing_config:
|
|
routing_mode: REGIONAL
|
|
register: gcp_compute_network
|
|
|
|
- name: Firewall configured
|
|
gcp_compute_firewall:
|
|
auth_kind: serviceaccount
|
|
service_account_file: "{{ credentials_file_path }}"
|
|
project: "{{ project_id }}"
|
|
name: algovpn
|
|
network: "{{ gcp_compute_network }}"
|
|
direction: INGRESS
|
|
allowed:
|
|
- ip_protocol: udp
|
|
ports:
|
|
- "500"
|
|
- "4500"
|
|
- "{{ wireguard_port | string }}"
|
|
- ip_protocol: tcp
|
|
ports:
|
|
- "{{ ssh_port }}"
|
|
- ip_protocol: icmp
|
|
|
|
- when: cloud_providers.gce.external_static_ip
|
|
block:
|
|
- name: External IP allocated
|
|
gcp_compute_address:
|
|
auth_kind: serviceaccount
|
|
service_account_file: "{{ credentials_file_path }}"
|
|
project: "{{ project_id }}"
|
|
name: "{{ algo_server_name }}"
|
|
region: "{{ algo_region }}"
|
|
register: gcp_compute_address
|
|
|
|
- name: Set External IP as a fact
|
|
set_fact:
|
|
external_ip: "{{ gcp_compute_address.address }}"
|
|
|
|
- name: Instance created
|
|
gcp_compute_instance:
|
|
auth_kind: serviceaccount
|
|
service_account_file: "{{ credentials_file_path }}"
|
|
project: "{{ project_id }}"
|
|
name: "{{ algo_server_name }}"
|
|
zone: "{{ algo_zone }}"
|
|
machine_type: "{{ cloud_providers.gce.size }}"
|
|
disks:
|
|
- auto_delete: true
|
|
boot: true
|
|
initialize_params:
|
|
source_image: projects/ubuntu-os-cloud/global/images/family/{{ cloud_providers.gce.image }}
|
|
metadata:
|
|
ssh-keys: algo:{{ ssh_public_key_lookup }}
|
|
user-data: "{{ lookup('template', 'files/cloud-init/base.yml') }}"
|
|
network_interfaces:
|
|
- network: "{{ gcp_compute_network }}"
|
|
access_configs:
|
|
- name: "{{ algo_server_name }}"
|
|
nat_ip: "{{ gcp_compute_address | default(None) }}"
|
|
type: ONE_TO_ONE_NAT
|
|
tags:
|
|
items:
|
|
- environment-algo
|
|
register: gcp_compute_instance
|
|
|
|
- set_fact:
|
|
cloud_instance_ip: "{{ gcp_compute_instance.networkInterfaces[0].accessConfigs[0].natIP }}"
|
|
ansible_ssh_user: algo
|
|
ansible_ssh_port: "{{ ssh_port }}"
|
|
cloudinit: true
|