Several roles reported "changed" on every playbook run even when
nothing on the target had drifted, making real config drift
indistinguishable from noise:
- 7 systemd tasks across 6 roles used state:restarted, which always
issues a restart and always reports changed. Switched to
state:started plus notify-driven handlers that only restart when
the underlying unit file, script, or config actually changes.
- pi_standard_setup's boot mode, timezone, and locale tasks shelled
out to raspi-config with changed_when:true hardcoded. Boot mode now
checks systemctl get-default first; timezone/locale now use the
natively idempotent community.general.timezone/locale_gen modules.
- The pi account password task computed password_hash('sha512')
without a seed, generating a new random salt (and thus an
apparently different hash) on every run. Added a stable seed so the
hash only changes when the underlying secret does.
Also renamed a mislabeled task in pi_squeezelite_custom and fixed a
typo in pi_standard_setup while those files were already touched.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
pi_standard_setup
Baseline provisioning applied to every Pi: apt update/upgrade, detects the
Pi model, adds a root SSH key, disables the SSH locale-forwarding warning,
optionally configures wifi and the hostname, and rotates the default
pi/raspberry credentials via the keepass lookup plugin.
Key vars: pi_standard_setup_wifi_ssid, pi_standard_setup_new_hostname,
pi_standard_setup_timezone, pi_standard_setup_wifi_country,
ansible_ssh_pass (the OS-default password, used only to reach a
freshly-flashed Pi for the first time before its password is rotated)