Fix tasks that always report changed regardless of actual state
Several roles reported "changed" on every playbook run even when
nothing on the target had drifted, making real config drift
indistinguishable from noise:
- 7 systemd tasks across 6 roles used state:restarted, which always
issues a restart and always reports changed. Switched to
state:started plus notify-driven handlers that only restart when
the underlying unit file, script, or config actually changes.
- pi_standard_setup's boot mode, timezone, and locale tasks shelled
out to raspi-config with changed_when:true hardcoded. Boot mode now
checks systemctl get-default first; timezone/locale now use the
natively idempotent community.general.timezone/locale_gen modules.
- The pi account password task computed password_hash('sha512')
without a seed, generating a new random salt (and thus an
apparently different hash) on every run. Added a stable seed so the
hash only changes when the underlying secret does.
Also renamed a mislabeled task in pi_squeezelite_custom and fixed a
typo in pi_standard_setup while those files were already touched.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -38,7 +38,7 @@
|
||||
changed_when: false
|
||||
- name: Change hostname {{ pi_standard_setup_new_hostname }}
|
||||
ansible.builtin.command: "raspi-config nonint do_hostname {{ pi_standard_setup_new_hostname }}"
|
||||
when: pi_standard_setup_new_hostname | bool and pi_standard_setup_pi_hostname.stdout != pi_standard_setup_new_hostname
|
||||
when: pi_standard_setup_new_hostname | length > 0 and pi_standard_setup_pi_hostname.stdout != pi_standard_setup_new_hostname
|
||||
register: pi_standard_setup_set_hostname
|
||||
changed_when: true
|
||||
notify: Reboot
|
||||
@@ -46,21 +46,34 @@
|
||||
ansible.builtin.command: "raspi-config nonint get_hostname"
|
||||
register: pi_standard_setup_pi_hostname
|
||||
changed_when: false
|
||||
- name: Get current boot target
|
||||
ansible.builtin.command: "systemctl get-default"
|
||||
register: pi_standard_setup_boot_target
|
||||
changed_when: false
|
||||
- name: Set boot mode to CLI
|
||||
ansible.builtin.command: "raspi-config nonint do_boot_behaviour B1"
|
||||
when: pi_standard_setup_boot_target.stdout != "multi-user.target"
|
||||
changed_when: true
|
||||
# I2 Change Timezone
|
||||
- name: Change timezone
|
||||
ansible.builtin.command: "raspi-config nonint do_change_timezone {{ pi_standard_setup_timezone }}"
|
||||
changed_when: true
|
||||
- name: Change locale
|
||||
ansible.builtin.command: "raspi-config nonint do_change_locale en_US.UTF-8"
|
||||
changed_when: true
|
||||
community.general.timezone:
|
||||
name: "{{ pi_standard_setup_timezone }}"
|
||||
- name: Generate locale
|
||||
community.general.locale_gen:
|
||||
name: en_US.UTF-8
|
||||
state: present
|
||||
- name: Set default locale
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/default/locale
|
||||
regexp: "^LANG="
|
||||
line: "LANG=en_US.UTF-8"
|
||||
create: true
|
||||
mode: "0644"
|
||||
- name: Change password of default pi account
|
||||
ansible.builtin.user:
|
||||
name: pi
|
||||
update_password: always
|
||||
password: "{{ lookup('keepass', 'ansible://default_rpi_password') | password_hash('sha512') }}"
|
||||
password: "{{ lookup('keepass', 'ansible://default_rpi_password') | password_hash('sha512', 65534 | random(seed=inventory_hostname) | string) }}"
|
||||
- name: Install Packages (vim, git, basic python stuff)
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
@@ -83,11 +96,6 @@
|
||||
dest: /root/.gitconfig
|
||||
mode: "0644"
|
||||
# Wifi
|
||||
- name: Get WiFi country
|
||||
ansible.builtin.command: "raspi-config nonint get_wifi_country"
|
||||
register: pi_standard_setup_current_wifi_country
|
||||
changed_when: false
|
||||
ignore_errors: true # to avoid error when WiFi is not present
|
||||
- name: Change WiFi country
|
||||
ansible.builtin.command: "raspi-config nonint do_wifi_country {{ pi_standard_setup_wifi_country }}"
|
||||
when: configure_wifi
|
||||
@@ -130,14 +138,16 @@
|
||||
src: raspi-leds-off.sh
|
||||
dest: /usr/sbin/raspi-leds-off.sh
|
||||
mode: "u+rwx"
|
||||
notify: Restart raspi-leds-off
|
||||
- name: Copy led off service
|
||||
ansible.builtin.copy:
|
||||
src: raspi-leds-off.service
|
||||
dest: /lib/systemd/system/
|
||||
mode: "0644"
|
||||
- name: Activate led off servic
|
||||
notify: Restart raspi-leds-off
|
||||
- name: Activate led off service
|
||||
ansible.builtin.systemd:
|
||||
name: raspi-leds-off
|
||||
state: restarted
|
||||
state: started
|
||||
enabled: "yes"
|
||||
daemon_reload: "yes"
|
||||
|
||||
Reference in New Issue
Block a user