Files
ansible/roles/pi_standard_setup
Martin Bauer 3d1675528b Fix tasks that always report changed regardless of actual state
Several roles reported "changed" on every playbook run even when
nothing on the target had drifted, making real config drift
indistinguishable from noise:

- 7 systemd tasks across 6 roles used state:restarted, which always
  issues a restart and always reports changed. Switched to
  state:started plus notify-driven handlers that only restart when
  the underlying unit file, script, or config actually changes.
- pi_standard_setup's boot mode, timezone, and locale tasks shelled
  out to raspi-config with changed_when:true hardcoded. Boot mode now
  checks systemctl get-default first; timezone/locale now use the
  natively idempotent community.general.timezone/locale_gen modules.
- The pi account password task computed password_hash('sha512')
  without a seed, generating a new random salt (and thus an
  apparently different hash) on every run. Added a stable seed so the
  hash only changes when the underlying secret does.

Also renamed a mislabeled task in pi_squeezelite_custom and fixed a
typo in pi_standard_setup while those files were already touched.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 21:28:36 +02:00
..

pi_standard_setup

Baseline provisioning applied to every Pi: apt update/upgrade, detects the Pi model, adds a root SSH key, disables the SSH locale-forwarding warning, optionally configures wifi and the hostname, and rotates the default pi/raspberry credentials via the keepass lookup plugin.

Key vars: pi_standard_setup_wifi_ssid, pi_standard_setup_new_hostname, pi_standard_setup_timezone, pi_standard_setup_wifi_country, ansible_ssh_pass (the OS-default password, used only to reach a freshly-flashed Pi for the first time before its password is rotated)