mirror of
https://github.com/trailofbits/algo.git
synced 2026-09-22 17:45:00 +02:00
The wait_for_connection task hangs in certain Docker environments when using the local provider because Ansible's local connection plugin doesn't implement the reset method, causing the warning "Reset is not implemented for this connection" and potential indefinite hangs. This change adds a condition to skip the task for localhost connections, following the same pattern used elsewhere in the codebase (e.g., the SSH wait task on line 40 and the wait_for_connection in ubuntu.yml). The task is unnecessary for localhost since it always completes instantly (elapsed: 0) - localhost is always reachable. Fixes #14627 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude <noreply@anthropic.com>
60 lines
2.3 KiB
YAML
60 lines
2.3 KiB
YAML
---
|
|
- name: Set subjectAltName as a fact
|
|
set_fact:
|
|
IP_subject_alt_name: "{{ (IP_subject_alt_name if algo_provider == 'local' else cloud_instance_ip) | lower }}"
|
|
|
|
- name: Add the server to an inventory group
|
|
add_host:
|
|
name: "{% if cloud_instance_ip == 'localhost' %}localhost{% else %}{{ cloud_instance_ip }}{% endif %}"
|
|
groups: vpn-host
|
|
ansible_connection: "{% if cloud_instance_ip == 'localhost' %}local{% else %}ssh{% endif %}"
|
|
ansible_ssh_user: "{{ ansible_ssh_user | default('root') }}"
|
|
ansible_ssh_port: "{{ ansible_ssh_port | default(22) }}"
|
|
ansible_python_interpreter: /usr/bin/python3
|
|
algo_provider: "{{ algo_provider }}"
|
|
algo_server_name: "{{ algo_server_name }}"
|
|
algo_ondemand_cellular: "{{ algo_ondemand_cellular }}"
|
|
algo_ondemand_wifi: "{{ algo_ondemand_wifi }}"
|
|
algo_ondemand_wifi_exclude: "{{ algo_ondemand_wifi_exclude }}"
|
|
algo_dns_adblocking: "{{ algo_dns_adblocking }}"
|
|
algo_ssh_tunneling: "{{ algo_ssh_tunneling }}"
|
|
algo_store_pki: "{{ algo_store_pki }}"
|
|
IP_subject_alt_name: "{{ IP_subject_alt_name }}"
|
|
alternative_ingress_ip: "{{ alternative_ingress_ip | default(omit) }}"
|
|
cloudinit: "{{ cloudinit | default(false) }}"
|
|
|
|
- name: Additional variables for the server
|
|
add_host:
|
|
name: "{% if cloud_instance_ip == 'localhost' %}localhost{% else %}{{ cloud_instance_ip }}{% endif %}"
|
|
ansible_ssh_private_key_file: "{{ SSH_keys.private_tmp }}"
|
|
when: algo_provider != 'local'
|
|
|
|
- name: Wait until SSH becomes ready...
|
|
wait_for:
|
|
port: "{{ ansible_ssh_port | default(22) }}"
|
|
host: "{{ cloud_instance_ip }}"
|
|
search_regex: OpenSSH
|
|
delay: 10
|
|
timeout: 320
|
|
state: present
|
|
when: cloud_instance_ip != "localhost"
|
|
|
|
- name: Mount tmpfs
|
|
import_tasks: tmpfs/main.yml
|
|
when:
|
|
- pki_in_tmpfs
|
|
- not algo_store_pki
|
|
- ansible_system == "Darwin" or ansible_system == "Linux"
|
|
|
|
- debug:
|
|
var: IP_subject_alt_name
|
|
|
|
- name: Wait for target connection to become reachable/usable
|
|
wait_for_connection:
|
|
delay: 10 # Wait 10 seconds before first attempt (conservative)
|
|
timeout: 480 # Reduce from 600 to 480 seconds (8 minutes - safer)
|
|
sleep: 10 # Check every 10 seconds (less aggressive polling)
|
|
delegate_to: "{{ item }}"
|
|
loop: "{{ groups['vpn-host'] }}"
|
|
when: cloud_instance_ip != "localhost"
|