Under --check the git task reports "changed" without writing anything, so on a
host that has not been deployed yet there is no checkout to stat and the guard
fired on a perfectly fine configuration - making `just check mediapis.yml
musicdolphin` fail before the first real run.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
musicmouse_version pointed both hosts at rearchitect-backend, a branch that only
ever existed on a laptop - so the previous commit's rework could never actually
have run. Point each host at a deploy/<host> branch on the remote instead. Those
branches are the deployment record: what is installed on that box right now,
moved with a force-push when you mean to deploy.
musicmouse (Kinderzimmer) is the reason this matters. It is in daily use and
still runs the pre-rearchitecture backend out of /opt/musicmouse_venv and
espmusicmouse/host_driver/main.py. That commit has no python-backend/
pyproject.toml, no python-backend/musicmouse.service and no web/ at all, so this
role cannot install it - and a run would have force-checked-out incompatible
code over a working device first and failed afterwards. Set
mediapi_install_kidsmusic: false there and leave it alone;
deploy/musicmouse records the commit that is installed, for rollback. Add a
stat + fail right after the checkout so the same mistake stops with an
explanation instead of failing three tasks deeper.
Also in the role:
- Install the typing game's curriculum next to config.yml. A config with a
tippen: section refuses to start without it - curriculum_file is validated as
must-exist - so musicdolphin's new config needs it present.
- Stop clobbering config.yml. The app writes to it at runtime: parent mode
patches the volume keys and the remote-control page rewrites the remote:
block. A plain copy: undid that on every run. Install-once by default, with
-e pi_musicmouse_force_config=true to push a change deliberately.
- Fill out config-musicdolphin.yml against the current schema: library root and
cache, an absolute static_dir (../web/dist would resolve to /media/web/dist
from /media/musicmouse and silently serve nothing), tippen, and the volume
range for a screen-driven instance. ha: is left commented out until the
Wohnzimmer-oben entity ids are picked - the ones in the dev config are
Arbeitszimmer. No mqtt: (it would publish a device of dead entities on a
simulate-only host) and no lirc:/remote: (this host runs irserver, a serial
daemon, not the lircd this speaks TCP to).
The curriculum is a verbatim copy of app content, so exclude it from
ansible-lint rather than reformat it away from its source.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The app grew a python-backend/ and a web/ frontend, so pi_musicmouse no
longer matches it. Rework the role:
- Install a pinned uv and build the venv with Python 3.13; Raspbian
Bookworm's python3 is 3.11 and the backend uses PEP 695 syntax.
- pip install python-backend/ instead of a requirements.txt, and take
the systemd unit straight from the checkout so it can't drift.
- Build web/ on the control machine (no npm on the Pi) and rsync
web/dist over. Chain the checkout -> install -> build -> sync -> restart
steps through handlers so a run with no repo change does nothing.
- Per-host config files (config-<host>.yml); the schema now differs
between a host with a real mouse and a display-only one.
- Version to deploy is per host (musicmouse_version), no default.
Add pi_kiosk: autologin user running startx with Firefox in kiosk mode
and no window manager, for a Pi with a monitor attached. Enabled by
mediapi_has_monitor, defaulting off.
Turn musicdolphin into a display-only instance: serial and audio
simulated, driven entirely through the kiosk page.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- risky-file-permissions (32): add explicit mode: to copy/template/file tasks,
matching the umask-derived permissions they already had (0644 for configs
and systemd units, 0755 for created directories) — no functional change.
- var-naming (28): prefix role-scoped vars with their role name across
pi_dhtsensor, pi_dhtsensor_circuitpython, pi_shairport, pi_squeezelite,
pi_squeezelite_custom, pi_sispmctl, pi_standard_setup, and pi_sysdweb's
sysdweb_name (shared by 9 consuming roles). Updated every dependent
template, task reference, and matching inventory.yml override, and
verified resolved values with ansible-inventory before/after.
- Fixes a latent bug found while renaming: pi_standard_setup's "Get/Change
WiFi country" tasks reused the name wifi_country for both the role default
and a register, so the register silently clobbered the default before
do_wifi_country ever read it. Split into distinct names so the intended
default value is used.
- package-latest (2): pin docker-ce/docker-compose-plugin installs in
server_debian_docker to state: present.
- no-handler (1): move pi_lirc's "Reboot if boot overlay changed" into a
proper handler notified by the boot-overlay task.
ansible-lint now passes clean at the production profile.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module
syntax via ansible-lint --fix
- Fix comments misplaced inside module args by the auto-fixer
(bluetooth-monitor, pi_standard_setup, pi_musicmouse)
- Fix notify: references left stale (lowercase) after handler names
were re-cased, which would have silently broken reboot/restart
handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp,
pi_squeezelite, pi_standard_setup)
- Fix a task in pis/debmatic-install.yml missing its module name
(apt_repository), which caused a real syntax-check failure
- Add missing play names, fix comment spacing, literal-compare idiom,
and no-changed-when annotations
- Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML)
- Rename all hyphenated role directories to underscore form to satisfy
ansible-lint's role-name rule, updating every playbook/meta reference
Remaining lint findings (var-naming, package-latest, risky-file-permissions,
no-handler) intentionally left for follow-up per user decision.