The role gathers the facts it uses. For example, if the user uses `ANSIBLE_GATHERING=explicit`, the role uses the `setup` module with the facts and subsets it requires. This change allows us to test this. Before every role invocation, the test will use `meta: clear_facts` so that the role starts with no facts. Create a task file tests/tasks/run_role_with_clear_facts.yml to do the tasks to clear the facts and run the role. Note that this means we don't need to use `gather_facts` for the tests. Some vars defined using `ansible_facts` have been changed to be defined with `set_fact` instead. This is because of the fact that `vars` are lazily evaluated - the var might be referenced when the facts have been cleared, and will issue an error like `ansible_facts["distribution"] is undefined`. This is typically done for blocks that have a `when` condition that uses `ansible_facts` and the block has a role invocation using run_role_with_clear_facts.yml These have been rewritten to define the `when` condition using `set_fact`. This is because the `when` condition is evaluated every time a task is invoked in the block, and if the facts are cleared, this will raise an undefined variable error. Signed-off-by: Rich Megginson <rmeggins@redhat.com>
96 lines
2.8 KiB
YAML
96 lines
2.8 KiB
YAML
# SPDX-License-Identifier: MIT
|
|
---
|
|
- name: Ensure that the cron is set up
|
|
hosts: all
|
|
tasks:
|
|
- name: Determine if system is ostree and set flag
|
|
when: not __aide_is_ostree is defined
|
|
block:
|
|
- name: Check if system is ostree
|
|
stat:
|
|
path: /run/ostree-booted
|
|
register: __ostree_booted_stat
|
|
|
|
- name: Set flag to indicate system is ostree
|
|
set_fact:
|
|
__aide_is_ostree: "{{ __ostree_booted_stat.stat.exists }}"
|
|
|
|
- name: Install crontabs
|
|
package:
|
|
name: crontabs
|
|
state: present
|
|
use: "{{ (__aide_is_ostree | d(false)) |
|
|
ternary('ansible.posix.rhel_rpm_ostree', omit) }}"
|
|
|
|
- name: Create tempfile for crontab backup
|
|
tempfile:
|
|
prefix: aide_
|
|
suffix: _crontab
|
|
register: __aide_crontab_backup
|
|
|
|
- name: Backup crontab
|
|
copy:
|
|
src: /etc/crontab
|
|
dest: "{{ __aide_crontab_backup.path }}"
|
|
remote_src: true
|
|
mode: preserve
|
|
|
|
- name: Run tests
|
|
block:
|
|
- name: Run the role and set up cron
|
|
include_tasks: tasks/run_role_with_clear_facts.yml
|
|
vars:
|
|
aide_init: true
|
|
aide_cron_check: true
|
|
aide_cron_interval: "0 12 * * *"
|
|
|
|
- name: Check file content
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/crontab
|
|
regexp: "^.* root /usr/sbin/aide --check"
|
|
line: "0 12 * * * root /usr/sbin/aide --check"
|
|
state: present
|
|
register: result
|
|
failed_when: result is changed
|
|
|
|
- name: Run the role and and do not touch cron
|
|
include_tasks: tasks/run_role_with_clear_facts.yml
|
|
vars:
|
|
aide_cron_interval: "0 1 * * *"
|
|
|
|
- name: Ensure file is not changed
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/crontab
|
|
regexp: "^.* root /usr/sbin/aide --check"
|
|
line: "0 12 * * * root /usr/sbin/aide --check"
|
|
state: present
|
|
register: result
|
|
failed_when: result is changed
|
|
|
|
- name: Run the role and disable cron
|
|
include_tasks: tasks/run_role_with_clear_facts.yml
|
|
vars:
|
|
aide_cron_check: false
|
|
|
|
- name: Ensure aide cron is removed
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/crontab
|
|
regexp: "^.* root /usr/sbin/aide --check"
|
|
line: "0 12 * * * root /usr/sbin/aide --check"
|
|
state: present
|
|
register: result
|
|
failed_when: not result is changed
|
|
|
|
always:
|
|
- name: Restore crontab
|
|
copy:
|
|
src: "{{ __aide_crontab_backup.path }}"
|
|
dest: /etc/crontab
|
|
remote_src: true
|
|
mode: preserve
|
|
|
|
- name: Delete tempfile
|
|
file:
|
|
path: "{{ __aide_crontab_backup.path }}"
|
|
state: absent
|