- risky-file-permissions (32): add explicit mode: to copy/template/file tasks,
matching the umask-derived permissions they already had (0644 for configs
and systemd units, 0755 for created directories) — no functional change.
- var-naming (28): prefix role-scoped vars with their role name across
pi_dhtsensor, pi_dhtsensor_circuitpython, pi_shairport, pi_squeezelite,
pi_squeezelite_custom, pi_sispmctl, pi_standard_setup, and pi_sysdweb's
sysdweb_name (shared by 9 consuming roles). Updated every dependent
template, task reference, and matching inventory.yml override, and
verified resolved values with ansible-inventory before/after.
- Fixes a latent bug found while renaming: pi_standard_setup's "Get/Change
WiFi country" tasks reused the name wifi_country for both the role default
and a register, so the register silently clobbered the default before
do_wifi_country ever read it. Split into distinct names so the intended
default value is used.
- package-latest (2): pin docker-ce/docker-compose-plugin installs in
server_debian_docker to state: present.
- no-handler (1): move pi_lirc's "Reboot if boot overlay changed" into a
proper handler notified by the boot-overlay task.
ansible-lint now passes clean at the production profile.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module
syntax via ansible-lint --fix
- Fix comments misplaced inside module args by the auto-fixer
(bluetooth-monitor, pi_standard_setup, pi_musicmouse)
- Fix notify: references left stale (lowercase) after handler names
were re-cased, which would have silently broken reboot/restart
handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp,
pi_squeezelite, pi_standard_setup)
- Fix a task in pis/debmatic-install.yml missing its module name
(apt_repository), which caused a real syntax-check failure
- Add missing play names, fix comment spacing, literal-compare idiom,
and no-changed-when annotations
- Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML)
- Rename all hyphenated role directories to underscore form to satisfy
ansible-lint's role-name rule, updating every playbook/meta reference
Remaining lint findings (var-naming, package-latest, risky-file-permissions,
no-handler) intentionally left for follow-up per user decision.