Commit Graph
49 Commits
Author SHA1 Message Date
Rich MegginsonandRichard Megginson 7ebc20d774 refactor: fix Ansible 2.19 issues
Cannot write to ansible_managed - it is a special variable

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-06-26 13:40:09 -06:00
Rich MegginsonandRichard Megginson 387004f5d8 docs(changelog): version 1.2.0 [citest skip]
Update changelog and .README.html for version 1.2.0

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-06-16 17:49:01 -06:00
Rich MegginsonandRichard Megginson a12cbffe2c ci: Use ansible 2.19 for fedora 42 testing; support python 3.13
NOTE: This also requires upgrading to tox-lsr 3.11.0

Ansible 2.19 will be released soon and has some changes which will
require fixes in system roles.  This adds 2.19 to our testing matrix
on fedora 42 so that we can start addressing these issues.

python 3.13 is now being used on some platforms.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-06-10 09:06:23 -06:00
Rich MegginsonandRichard Megginson 62a517fa97 ci: Add support for bootc end-to-end validation tests
NOTE: This also requires upgrading to tox-lsr 3.10.0, and some
hacks to workaround a podman issue in ubuntu.

These tests run the role during a bootc container image build, deploy
the container into a QEMU VM, boot that, and validate the expected
configuration there. They run in two different tox environments, and
thus have to be run in two steps (preparation in buildah, validation in
QEMU). The preparation is expected to output a qcow2 image in
`tests/tmp/TESTNAME/qcow2/disk.qcow2`, i.e. the output structure of
<https://github.com/osbuild/bootc-image-builder>.

There are two possibilities:

* Have separate bootc end-to-end tests. These are tagged with
`tests::bootc-e2` and are skipped in the normal qemu-* scenarios.
They run as part of the container-* ones.

* Modify an existing test: These need to build a qcow2 image exactly
*once* (via calling `bootc-buildah-qcow.sh`) and skip setup/cleanup
and role invocations in validation mode, i.e. when
`__bootc_validation` is true.

In the container scenario, run the QEMU validation as a separate step in
the workflow.

See https://issues.redhat.com/browse/RHEL-88396

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-06-03 16:39:13 -06:00
HVSharma12andRichard Megginson 1f335b613e Drop SLES/openSUSE versions from platforms from meta/main.yml 2025-06-02 10:12:19 -06:00
HVSharma12andRichard Megginson b9d20db08d Add SLES and openSUSE entries to meta/main.yml 2025-06-02 10:12:19 -06:00
HVSharma12andRichard Megginson 2a8586898c feat: add Suse support 2025-06-02 10:12:19 -06:00
Rich MegginsonandRichard Megginson 22d787a281 ci: Add Fedora 42; use tox-lsr 3.9.0; use lsr-report-errors for qemu tests
Add Fedora 42 to testing farm test matrix, drop Fedora 40

Use tox-lsr 3.9.0 for the `--lsr-report-errors-url` argument.

Add the argument `--lsr-report-errors-url DEFAULT` to the qemu test so that
the errors will be written to the output log.  This uses the output callback
https://github.com/linux-system-roles/auto-maintenance/blob/main/callback_plugins/lsr_report_errors.py

Use the check_logs.py script
https://github.com/linux-system-roles/auto-maintenance/blob/main/check_logs.py
with the `--github-action-format` argument to format the errors
in a github action friendly manner.

Rename the log files `-FAIL.log` or `-SUCCESS.log` depending on status.
This is compatible with the way the testing farm log files are named, and
makes it easy to tell if a test passed or failed from the log file name.

Upload README.html as artifacts of the build_docs job for debugging

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-05-19 14:30:41 -06:00
Rich MegginsonandMartin Pitt 07da24d05f ci: bump tox-lsr to 3.8.0; rename qemu/kvm tests
This will make the qemu/kvm tests be tested in either
ascending or descending ASCII order.  This should give
us better test coverage of clean up scenarios which may
fail depending on the order of the previous tests.

Rename the qemu/kvm tests so that the statuses are shorter
and more intuitive.

Improve qemu/kvm test failure error reporting.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-05-07 22:46:44 +02:00
dependabot[bot]andSergei Petrosian eb34d44eb8 ci: Bump sclorg/testing-farm-as-github-action from 3 to 4
Bumps [sclorg/testing-farm-as-github-action](https://github.com/sclorg/testing-farm-as-github-action) from 3 to 4.
- [Release notes](https://github.com/sclorg/testing-farm-as-github-action/releases)
- [Commits](https://github.com/sclorg/testing-farm-as-github-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: sclorg/testing-farm-as-github-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-05-02 09:17:21 +02:00
Rich MegginsonandRichard Megginson 8f1d3c79d6 ci: skip storage scsi, nvme tests in github qemu ci
These tests are problematic in github qemu tests, and that
functionality (scsi, anyway) in the testing farm integration
tests.

Yes, we should have a way to provide tags on a per-role basis . . .

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-04-22 15:50:34 -06:00
Rich MegginsonandRichard Megginson a8418ce31a ci: use tox-lsr 3.6.0; improve qemu test logging
tox-lsr 3.6.0 will guarantee order of qemu test execution, which should
help make tests reproducible and help debug test failures.

Improve qemu test logging - this will help debug the qemu test
failures.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-04-22 15:06:31 -06:00
Rich MegginsonandRichard Megginson fa134b8aab ci: several changes related to new qemu test, ansible-lint, python versions, ubuntu versions
There is a new QEMU based test which uses the qemu/kvm capability of
github action runners.  This is the basis for new bootc/image mode tests
which we will be rolling out in the near future.

ansible-lint requires that the collection path is set so that the requirements
it installs are installed in the correct place.

There has been some general github action deprecation of python versions and
ubuntu versions that we have had to fix.

Remove `CONTRIBUTOR` from the list of users who can trigger citest.

For more information, see

* https://github.com/linux-system-roles/.github/pull/98
* https://github.com/linux-system-roles/.github/pull/94
* https://github.com/linux-system-roles/.github/pull/93
* https://github.com/linux-system-roles/.github/pull/92
* https://github.com/linux-system-roles/.github/pull/91

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-04-11 13:17:45 -06:00
Sergei PetrosianandSergei Petrosian 0aa8f2aff8 ci: Fix bug with ARTIFACTS_URL after prefixing with SR_
Signed-off-by: Sergei Petrosian <spetrosi@redhat.com>
2025-03-21 00:07:43 +01:00
Sergei PetrosianandSergei Petrosian 9649b57c78 ci: In test plans, prefix all relate variables with SR_
Signed-off-by: Sergei Petrosian <spetrosi@redhat.com>
2025-03-19 17:32:04 +01:00
Sergei PetrosianandSergei Petrosian 826f2fc0fa ci: Add test plan that runs CI tests and customize it for each role
* Calculate number of managed nodes with this formula:
    (( number_of_test_playbooks / 10 + 1 ))
* Add README explaining how to run the plan locally and remotely

Signed-off-by: Sergei Petrosian <spetrosi@redhat.com>
2025-02-17 15:49:14 +01:00
Sergei PetrosianandSergei Petrosian 640cbf000a Ignore .pandoc_template.html5 2025-02-13 11:46:25 +01:00
Sergei PetrosianandSergei Petrosian 5d8406eb12 chore: Fix spelling 2025-02-13 11:46:25 +01:00
Sergei PetrosianandSergei Petrosian c9eca28874 ci: Check spelling with codespell
* You can ignore words inline by adding a comment like `# codespell:ignore word`.
* You can ignore words by adding them to the `.codespell_ignores` file.
* You can ignore files and directories by adding them with `skip = ` to the `.codespellrc` file.

Signed-off-by: Sergei Petrosian <spetrosi@redhat.com>
2025-02-13 11:46:25 +01:00
Rich MegginsonandRichard Megginson 21122732bd docs(changelog): version 1.1.1 [citest skip]
Update changelog and .README.html for version 1.1.1

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-02-11 07:48:19 -07:00
Rich MegginsonandRichard Megginson e5990bece0 fix: aide --check should not report changed
The task "Check against AIDE reference database" should not report
changed since it does not change anything.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-02-11 07:42:23 -07:00
Joerg KastningandRichard Megginson 8ce6fe0da5 Changed ansible_db_template to ansible_config_template
As the template is for the aide.conf(5) file I found
that the variable name 'ansible_config_template' is
a better fit than 'ansible_db_template'.

Signed-off-by: Joerg Kastning <joerg@redhat.com>
2025-02-10 09:33:34 -07:00
Rich MegginsonandRichard Megginson 3bca54f29b docs(changelog): version 1.1.0 [citest skip]
Update changelog and .README.html for version 1.1.0

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-01-31 15:43:14 -07:00
Rich MegginsonandRichard Megginson cc5de8664f feat: ensure role works on ostree systems
Ensure role works on ostree systems

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-01-31 15:35:25 -07:00
Rich MegginsonandRichard Megginson c9f0262b04 ci: bump ansible-lint to v25; provide collection requirements for ansible-lint
There is a new version of ansible-lint - v25.
Newer versions of ansible-lint require the collection requirements to be
installed so it can find the modules/plugins.
Enhance our ansible-lint ci job to provide the collection requirements,
including merging the runtime meta/collection-requirements.yml with
the testing tests/collection-requirements.yml.
This should somewhat mitigate the loss of ansible-plugin-scan.
We have to remove mock_modules that are actually present now.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-01-31 05:16:18 -07:00
Rich MegginsonandRichard Megginson 22d8e5aa41 ci: ansible-plugin-scan is disabled for now
ansible-plugin-scan is broken due to lack of support for older versions
of python in ci.
One of the main reasons for using this scan is to check if the roles/tests
are using plugins that are not compatible with ansible 2.9.  Since 2.9
is EOL, this is no longer necessary.
The other reason for using the scan is to check that the role/test
author has correctly listed dependencies in meta/collection-requirements.yml
and tests/collection-requirements.yml - that is - that the author has
correctly specified the dependencies for any plugins used that are
not built-in.  This will mostly be caught in CI testing now.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-01-29 13:30:43 -07:00
Rich MegginsonandRichard Megginson a4307661b7 docs(changelog): version 1.0.0 [citest skip]
Update changelog and .README.html for version 1.0.0

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-01-09 08:32:54 -07:00
Rich MegginsonandRichard Megginson 129feb1ac1 test: add cleanup for cron test; fix formatting
Ensure cron test restores state of crontab after test.
Fix formatting in a few places.
Do not check ansible managed header and fingerprint unless the test
uses a custom template with header and fingerprint.
Use default for gather_facts unless otherwise needed.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-01-07 11:31:56 -07:00
Radovan SrokaandSergei Petrosian 2c0be7a450 Use command instead of shell
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2025-01-07 13:06:03 +01:00
Radovan SrokaandSergei Petrosian e9ddf8804c Fix suggestions
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2025-01-07 13:06:03 +01:00
Radovan SrokaandSergei Petrosian 24f5af0f92 Add crontabs package as a requirement
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2025-01-07 13:06:03 +01:00
Radovan SrokaandSergei Petrosian 49e267a29b feat: Allow setup aide inside of cron job
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2025-01-07 13:06:03 +01:00
Rich MegginsonandRichard Megginson cdfdd3523d ci: Use Fedora 41, drop Fedora 39 - part two
Fedora 41 is released, and Fedora 39 will soon be unsupported
Part two - first part did not work

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2024-12-02 17:53:37 -07:00
Rich MegginsonandRichard Megginson 0cc6d3d650 ci: Use Fedora 41, drop Fedora 39
Fedora 41 is released, and Fedora 39 will soon be unsupported

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2024-12-02 13:53:05 -07:00
Rich MegginsonandRichard Megginson 86685b0f5b docs(changelog): version 0.0.1 [citest skip]
Update changelog and .README.html for version 0.0.1

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2024-11-12 14:02:47 -07:00
Radovan SrokaandSergei Petrosian 68466e7380 Add link to original role
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian 19d326275e Fix whens on one line
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian 1409ace70d Revert "Remove environment_settings from github workflows"
This reverts commit 21c764541dbce1a1b5f9249a69e1ee0c72d3bbda.
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian 75f11dfe94 Remove aide_install phase and do it uncoditionally
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian c4e5a2d8f0 Fix other suggestions
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian 21907fc7bc Remove environment_settings from github workflows
due to broken environment processing in a testing farm

Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian a1b37cd6c7 Fix review items and enable rhel8
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian f11746b2d3 Added custom template functionality
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian 2b5660d4ce Splited init and fetch
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian 7826ac05c6 Switch from using tags to variables
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian 82cb4bbf35 Fix suggestions
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Radovan SrokaandSergei Petrosian b84e29c40e feat: Import code for role
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-11-12 11:15:10 +01:00
Rich MegginsonandRichard Megginson 1b526b93ea refactor: Use vars/RedHat_N.yml symlink for CentOS, Rocky, Alma wherever possible
We have a lot of requests to support Rocky and Alma in various system roles. The
first part of adding support is adding `vars/` files for these platforms. In
almost every case, for a given major version N, the vars file RedHat_N.yml can
be used for CentOS, Rocky, and Alma.  Rather than making a copy of the
RedHat_N.yml file, just use a symlink to reduce size and maintenance burden, and
standardize this across all system roles for consistency.

NOTE: There is no Alma or Rocky version 7 or less.

NOTE: OracleLinux is not a strict clone, so we are not going to do this for
OracleLinux at this time.  Support for OracleLinux will need to be done in
separate PRs. For more information, see
https://github.com/linux-system-roles/cockpit/issues/130

**Question**: Why not just use `ansible_facts["os_family"] == "RedHat"`?

**Answer**:  This is what Ansible uses as the RedHat os_family:
https://github.com/ansible/ansible/blob/1e6ffc1d02559a26def6c9c3b07baf27032865a2/lib/ansible/module_utils/facts/system/distribution.py#L511
There are a lot of distributions in there. I know that Fedora is not a clone of
RHEL, but it is very closely related. Most of the others are not clones, and it
would generally not work to replace ansible_distribution in ['CentOS', 'Fedora',
'RedHat'] with ansible_facts['os_family'] == 'RedHat' (but it would probably
work in specific cases with specific distributions).  For example, OracleLinux
is in there, and we know that doesn't generally work.  The only ones we can be
pretty sure about are `RedHat`, `CentOS`, `Fedora`, `AlmaLinux`, and `Rocky`.

**Question**: Does my role really need this because it should already work on
RHEL clones?

**Answer**: Maybe not - but:

* it doesn't hurt anything
* it's there if we need it in the future
* the role will be inconsistent with the other system roles if we don't have this

**Question**: Why do I need the `tests/vars/rh_distros_vars.yml` file?  Doesn't
the test load the vars from the role?

**Answer**: No, the test does not load the vars from the role until the role is
included, and many tests use version and distribution before including the role.

**Question**: Do we need to change the code now to use the new variables?

**Answer**: No, not now, in subsequent PRs, hopefully by Alma and Rocky users.

Note that there may be more work to be done to the role to fully support Rocky
and Alma.  Many roles have conditionals like this:

```yaml
some_var: "{{ 'some value' if ansible_distribution in ['CentOS', 'RedHat'] else 'other value' }}"
another_var: "{{ 'some value' if ansible_distribution in ['CentOS', 'Fedora', 'RedHat'] else 'other value' }}"

...

- name: Do something
  when: ansible_distribution in ['CentOS', 'RedHat']
  ...
- name: Do something else
  when: ansible_distribution in ['CentOS', 'Fedora', 'RedHat']
  ...
```

Adding Rocky and AlmaLinux to these conditionals will have to be done
separately. In order to simplify the task, some new variables are being
introduced:

```yaml
__$rolename_rh_distros:
  - AlmaLinux
  - CentOS
  - RedHat
  - Rocky

__$rolename_rh_distros_fedora: "{{ __$rolename_rh_distros + ['Fedora'] }}"

__$rolename_is_rh_distro: "{{ ansible_distribution in __$rolename_rh_distros }}"
__$rolename_is_rh_distro_fedora: "{{ ansible_distribution in __$rolename_rh_distros_fedora }}"
```

Then the conditionals can be rewritten as:

```yaml
some_var: "{{ 'some value' if __$rolename_is_rh_distro else 'other value' }}"
another_var: "{{ 'some value' if __$rolename_is_rh_distro_fedora else 'other value' }}"

...

- name: Do something
  when: __$rolename_is_rh_distro | bool
  ...
- name: Do something else
  when: __$rolename_is_rh_distro_fedora | bool
  ...
```

For tests - tests that use such conditionals will need to use `vars_files` or
`include_vars` to load the variables that are defined in
`tests/vars/rh_distros_vars.yml`:

```yaml
vars_files:
  - vars/rh_distros_vars.yml
```

We don't currently have CI testing for Rocky or Alma, so someone wanting to run
tests on those platforms would need to change the test code to use these.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2024-10-25 14:08:09 -06:00
Richard MegginsonandGitHub e898442752 Initial commit 2024-10-22 10:07:09 -06:00