if check mode, verify packages are installed before continuing

If packages are not installed, commands will fail in check mode.
This commit is contained in:
Robert Welch
2026-07-08 07:16:00 -06:00
committed by Richard Megginson
parent 8ef1897517
commit 96cda3f1d4
+19 -14
View File
@@ -10,39 +10,44 @@
state: present state: present
use: "{{ (__aide_is_ostree | d(false)) | use: "{{ (__aide_is_ostree | d(false)) |
ternary('ansible.posix.rhel_rpm_ostree', omit) }}" ternary('ansible.posix.rhel_rpm_ostree', omit) }}"
register: __aide_install_packages
- name: Get AIDE version - name: Packages are installed
# either run mode or check mode and no changes to packages
when: not ansible_check_mode or (ansible_check_mode and not __aide_install_packages.changed)
block:
- name: Get AIDE version
ansible.builtin.command: ansible.builtin.command:
cmd: aide --version cmd: aide --version
register: __aide_version_register register: __aide_version_register
changed_when: false changed_when: false
# assumes the version starts with a digit and goes to the end of the line # assumes the version starts with a digit and goes to the end of the line
- name: Set AIDE version - name: Set AIDE version
set_fact: set_fact:
aide_version: "{{ __output | regex_search('(?m)^A[iI][dD][eE] (\\d.*)$', '\\1') | first }}" aide_version: "{{ __output | regex_search('(?m)^A[iI][dD][eE] (\\d.*)$', '\\1') | first }}"
vars: vars:
__output: "{{ __aide_version_register.stdout if __aide_version_register.stdout | length > 0 __output: "{{ __aide_version_register.stdout if __aide_version_register.stdout | length > 0
else __aide_version_register.stderr }}" else __aide_version_register.stderr }}"
- name: Ensure required services are enabled and started - name: Ensure required services are enabled and started
ansible.builtin.service: ansible.builtin.service:
name: "{{ item }}" name: "{{ item }}"
state: started state: started
enabled: true enabled: true
loop: "{{ __aide_services }}" loop: "{{ __aide_services }}"
- name: Generate "/etc/{{ __aide_config }}" - name: Generate "/etc/{{ __aide_config }}"
ansible.builtin.template: ansible.builtin.template:
src: "{{ aide_config_template }}" src: "{{ aide_config_template }}"
dest: "/etc/{{ __aide_config }}" dest: "/etc/{{ __aide_config }}"
mode: "0400" mode: "0400"
when: aide_config_template is not none when: aide_config_template is not none
# - name: Print Header # - name: Print Header
# ansible.builtin.command: head /etc/aide.conf || true # ansible.builtin.command: head /etc/aide.conf || true
- name: Initialize AIDE database - name: Initialize AIDE database
when: aide_init | bool when: aide_init | bool
block: block:
- name: Initialize AIDE database - name: Initialize AIDE database
@@ -67,7 +72,7 @@
state: absent state: absent
when: not aide_fetch_db | bool when: not aide_fetch_db | bool
- name: Fetch AIDE database - name: Fetch AIDE database
when: aide_fetch_db | bool when: aide_fetch_db | bool
block: block:
- name: Fetch AIDE database - name: Fetch AIDE database
@@ -80,7 +85,7 @@
path: "{{ __aide_db_new_name }}" path: "{{ __aide_db_new_name }}"
state: absent state: absent
- name: Check AIDE integrity - name: Check AIDE integrity
when: aide_check | bool when: aide_check | bool
block: block:
- name: Copy AIDE reference database - name: Copy AIDE reference database
@@ -98,7 +103,7 @@
cmd: aide --check cmd: aide --check
changed_when: false changed_when: false
- name: Update AIDE database and fetch it - name: Update AIDE database and fetch it
when: aide_update | bool when: aide_update | bool
block: block:
- name: Update AIDE database - name: Update AIDE database
@@ -121,7 +126,7 @@
path: "{{ __aide_db_new_name }}" path: "{{ __aide_db_new_name }}"
state: absent state: absent
- name: Update aide check cron configuration if necessary - name: Update aide check cron configuration if necessary
ansible.builtin.lineinfile: ansible.builtin.lineinfile:
path: /etc/crontab path: /etc/crontab
regexp: "^.* root {{ __aide_bin_path }} --check" regexp: "^.* root {{ __aide_bin_path }} --check"
@@ -130,7 +135,7 @@
- aide_cron_check is not none - aide_cron_check is not none
- aide_cron_check | bool - aide_cron_check | bool
- name: Remove aide check cron configuration if necessary - name: Remove aide check cron configuration if necessary
ansible.builtin.lineinfile: ansible.builtin.lineinfile:
path: /etc/crontab path: /etc/crontab
state: absent state: absent
@@ -139,7 +144,7 @@
- aide_cron_check is not none - aide_cron_check is not none
- not aide_cron_check | bool - not aide_cron_check | bool
- name: Record role success fingerprint - name: Record role success fingerprint
sr_fingerprint: sr_fingerprint:
sr_message: >- sr_message: >-
success system_role:aide ansible_version={{ ansible_version.full }} success system_role:aide ansible_version={{ ansible_version.full }}