Regular playbooks now use state: present, so they no longer upgrade
packages as a side effect. This adds two separate, explicit mechanisms
to keep the fleet patched instead:
- update-packages.yml: ad hoc / to-be-scheduled fleet-wide upgrade
(safe by default, dist available via -e), plus
update-packages-pinned-example.yml as a template for pinning or
bumping a single package outside that.
- roles/unattended_upgrades: automatic security-only patching via
unattended-upgrades, with a scheduled reboot window and mail
left disabled pending a configured MTA. Applied to every host in
full.yml and server.yml.
Also removes a leftover `upgrade: yes` apt task from pi_standard_setup
and server_basic_environment that was still doing a full upgrade on
every routine run, defeating the point of the state: present switch.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module
syntax via ansible-lint --fix
- Fix comments misplaced inside module args by the auto-fixer
(bluetooth-monitor, pi_standard_setup, pi_musicmouse)
- Fix notify: references left stale (lowercase) after handler names
were re-cased, which would have silently broken reboot/restart
handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp,
pi_squeezelite, pi_standard_setup)
- Fix a task in pis/debmatic-install.yml missing its module name
(apt_repository), which caused a real syntax-check failure
- Add missing play names, fix comment spacing, literal-compare idiom,
and no-changed-when annotations
- Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML)
- Rename all hyphenated role directories to underscore form to satisfy
ansible-lint's role-name rule, updating every playbook/meta reference
Remaining lint findings (var-naming, package-latest, risky-file-permissions,
no-handler) intentionally left for follow-up per user decision.