mirror of
https://github.com/trailofbits/algo.git
synced 2026-08-17 21:25:50 +02:00
* fix: add explicit bool filters for Ansible 12 jinja2_native compatibility Ansible 12 enables jinja2_native by default, which means string values like "true"/"false" are no longer automatically coerced to booleans in when: conditions and Jinja2 if statements. Add | bool filters to all boolean variable references in tasks, templates, and handlers. Also reformats long single-line Jinja2 conditionals into multi-line for readability, fixes GCE default() calls for native mode, adds help command to the algo script, and updates test fixtures to register the bool filter. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * ci: add j2lint for Jinja2 template linting Add j2lint (aristanetworks/j2lint) to catch syntax errors, spacing issues, and operator formatting in Jinja2 templates. Integrated into pre-commit hooks, lint.yml CI, and smart-tests.yml. Rules S3/S5/S6/S7/V1 are ignored — they enforce conventions incompatible with Ansible's config-file-embedded templates. Also fixes int+1 → int + 1 operator spacing in server.conf.j2. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve all ansible-lint warnings and enforce zero-tolerance policy Fix 18 jinja[spacing] errors across 12 files by moving Jinja2 block delimiters to prevent YAML >- folding from introducing trailing spaces. Fix 27 key-order[task] warnings across 17 files by reordering task keys to canonical order (name → when → tags → environment → become → block). Promote key-order[task] and yaml[line-length] from warn_list to hard errors by removing warn_list entirely from .ansible-lint. Add zero-tolerance warning policy to CLAUDE.md explaining why warnings are unacceptable in a security tool and documenting resolution order. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
55 lines
1.6 KiB
YAML
55 lines
1.6 KiB
YAML
---
|
|
- pause:
|
|
prompt: |
|
|
Enter your ACCESS token. (https://developers.linode.com/api/v4/#access-and-authentication):
|
|
echo: false
|
|
register: _linode_token
|
|
when:
|
|
- linode_token is undefined
|
|
- lookup('env', 'LINODE_API_TOKEN')|length <= 0
|
|
no_log: true
|
|
|
|
- name: Set the token as a fact
|
|
set_fact:
|
|
algo_linode_token: "{{ linode_token | default(_linode_token.user_input | default(None)) | default(lookup('env', 'LINODE_API_TOKEN'), true) }}"
|
|
no_log: true
|
|
|
|
- name: Get regions
|
|
uri:
|
|
url: https://api.linode.com/v4/regions
|
|
method: GET
|
|
status_code: 200
|
|
register: _linode_regions
|
|
|
|
- name: Set facts about the regions
|
|
set_fact:
|
|
linode_regions: "{{ _linode_regions.json.data | sort(attribute='id') }}"
|
|
|
|
- name: Set default region
|
|
set_fact:
|
|
default_region: >-
|
|
{%- for r in linode_regions -%}
|
|
{%- if r['id'] == "us-east" %}{{ loop.index }}{% endif -%}
|
|
{%- endfor %}
|
|
|
|
- pause:
|
|
prompt: |
|
|
What region should the server be located in?
|
|
{% for r in linode_regions %}
|
|
{{ loop.index }}. {{ r['id'] }}
|
|
{% endfor %}
|
|
|
|
Enter the number of your desired region
|
|
[{{ default_region }}]
|
|
register: _algo_region
|
|
when: region is undefined
|
|
|
|
- name: Set additional facts
|
|
set_fact:
|
|
algo_linode_region: >-
|
|
{%- if region is defined -%}{{ region }}{%-
|
|
elif _algo_region.user_input -%}{{ linode_regions[_algo_region.user_input | int - 1]['id'] }}{%-
|
|
else -%}{{ linode_regions[default_region | int - 1]['id'] }}{%-
|
|
endif -%}
|
|
public_key: "{{ lookup('file', SSH_keys.public) }}"
|