Fix remaining ansible-lint violations: file permissions, var-naming, package pinning

- risky-file-permissions (32): add explicit mode: to copy/template/file tasks,
  matching the umask-derived permissions they already had (0644 for configs
  and systemd units, 0755 for created directories) — no functional change.
- var-naming (28): prefix role-scoped vars with their role name across
  pi_dhtsensor, pi_dhtsensor_circuitpython, pi_shairport, pi_squeezelite,
  pi_squeezelite_custom, pi_sispmctl, pi_standard_setup, and pi_sysdweb's
  sysdweb_name (shared by 9 consuming roles). Updated every dependent
  template, task reference, and matching inventory.yml override, and
  verified resolved values with ansible-inventory before/after.
- Fixes a latent bug found while renaming: pi_standard_setup's "Get/Change
  WiFi country" tasks reused the name wifi_country for both the role default
  and a register, so the register silently clobbered the default before
  do_wifi_country ever read it. Split into distinct names so the intended
  default value is used.
- package-latest (2): pin docker-ce/docker-compose-plugin installs in
  server_debian_docker to state: present.
- no-handler (1): move pi_lirc's "Reboot if boot overlay changed" into a
  proper handler notified by the boot-overlay task.

ansible-lint now passes clean at the production profile.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-08 17:28:12 +02:00
parent bb72eaec10
commit 37b75ecf81
35 changed files with 105 additions and 72 deletions

View File

@@ -3,4 +3,4 @@
Installs `sysdweb` (a small web UI for managing systemd units) and creates
its service user. Other roles register their services with it.
**Key vars:** `sysdweb_name`
**Key vars:** `pi_sysdweb_name`

View File

@@ -19,6 +19,7 @@
ansible.builtin.blockinfile:
path: /etc/sysdweb.conf
create: true
mode: "0644"
marker: "# {mark} ansible user"
block: |
[DEFAULT]
@@ -27,15 +28,17 @@
ansible.builtin.blockinfile:
path: /etc/sysdweb.conf
create: true
marker: "# {mark} ansible managed for {{ sysdweb_name }}"
mode: "0644"
marker: "# {mark} ansible managed for {{ pi_sysdweb_name }}"
block: |
[{{ sysdweb_name }}]
title = {{ sysdweb_name }}
unit = {{ sysdweb_name }}.service
[{{ pi_sysdweb_name }}]
title = {{ pi_sysdweb_name }}
unit = {{ pi_sysdweb_name }}.service
- name: Install systemd service file
ansible.builtin.copy:
src: sysdweb-system.service
dest: /etc/systemd/system/
mode: "0644"
- name: Enable sysdweb autostart
ansible.builtin.systemd:
name: sysdweb-system