mirror of
https://github.com/trailofbits/algo.git
synced 2026-08-17 21:25:50 +02:00
* fix: add explicit bool filters for Ansible 12 jinja2_native compatibility Ansible 12 enables jinja2_native by default, which means string values like "true"/"false" are no longer automatically coerced to booleans in when: conditions and Jinja2 if statements. Add | bool filters to all boolean variable references in tasks, templates, and handlers. Also reformats long single-line Jinja2 conditionals into multi-line for readability, fixes GCE default() calls for native mode, adds help command to the algo script, and updates test fixtures to register the bool filter. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * ci: add j2lint for Jinja2 template linting Add j2lint (aristanetworks/j2lint) to catch syntax errors, spacing issues, and operator formatting in Jinja2 templates. Integrated into pre-commit hooks, lint.yml CI, and smart-tests.yml. Rules S3/S5/S6/S7/V1 are ignored — they enforce conventions incompatible with Ansible's config-file-embedded templates. Also fixes int+1 → int + 1 operator spacing in server.conf.j2. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: resolve all ansible-lint warnings and enforce zero-tolerance policy Fix 18 jinja[spacing] errors across 12 files by moving Jinja2 block delimiters to prevent YAML >- folding from introducing trailing spaces. Fix 27 key-order[task] warnings across 17 files by reordering task keys to canonical order (name → when → tags → environment → become → block). Promote key-order[task] and yaml[line-length] from warn_list to hard errors by removing warn_list entirely from .ansible-lint. Add zero-tolerance warning policy to CLAUDE.md explaining why warnings are unacceptable in a security tool and documenting resolution order. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
36 lines
1.1 KiB
YAML
36 lines
1.1 KiB
YAML
---
|
|
# Privacy enhancements for Algo VPN
|
|
# This role implements additional privacy measures to reduce log retention
|
|
# and minimize traces of VPN usage on the server
|
|
|
|
- name: Display privacy enhancements status
|
|
debug:
|
|
msg: "Privacy enhancements are {{ 'enabled' if privacy_enhancements_enabled else 'disabled' }}"
|
|
|
|
- name: Privacy enhancements block
|
|
when: privacy_enhancements_enabled | bool
|
|
block:
|
|
- name: Include log rotation tasks
|
|
include_tasks: log_rotation.yml
|
|
tags: privacy-logs
|
|
|
|
- name: Include history clearing tasks
|
|
include_tasks: clear_history.yml
|
|
tags: privacy-history
|
|
|
|
- name: Include log filtering tasks
|
|
include_tasks: log_filtering.yml
|
|
tags: privacy-filtering
|
|
|
|
- name: Include automatic cleanup tasks
|
|
include_tasks: auto_cleanup.yml
|
|
tags: privacy-cleanup
|
|
|
|
- name: Include advanced privacy tasks
|
|
include_tasks: advanced_privacy.yml
|
|
tags: privacy-advanced
|
|
|
|
- name: Display privacy enhancements completion
|
|
debug:
|
|
msg: "Privacy enhancements have been successfully applied"
|