fix(vars): enforce strict list-only DNS and user.key format for IaC compatibility
This commit is contained in:
@@ -26,12 +26,13 @@
|
||||
group: 1000
|
||||
mode: "0700"
|
||||
|
||||
- name: Add SSH public key to authorized_keys
|
||||
- name: Add SSH public keys to authorized_keys
|
||||
when: system_cfg.user.key | length > 0
|
||||
ansible.builtin.lineinfile:
|
||||
path: /mnt/home/{{ system_cfg.user.name }}/.ssh/authorized_keys
|
||||
line: "{{ system_cfg.user.key }}"
|
||||
line: "{{ item }}"
|
||||
owner: 1000
|
||||
group: 1000
|
||||
mode: "0600"
|
||||
create: true
|
||||
loop: "{{ system_cfg.user.key }}"
|
||||
|
||||
@@ -42,7 +42,7 @@ system_defaults:
|
||||
user:
|
||||
name: ""
|
||||
password: ""
|
||||
key: ""
|
||||
key: []
|
||||
root:
|
||||
password: ""
|
||||
luks:
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
- name: Ensure system input is a dictionary
|
||||
ansible.builtin.set_fact:
|
||||
system: "{{ system | default({}) }}"
|
||||
changed_when: false
|
||||
|
||||
|
||||
- name: Validate system input types
|
||||
ansible.builtin.assert:
|
||||
@@ -16,6 +16,23 @@
|
||||
fail_msg: "system and its nested keys (network, user, root, luks, features) must be dictionaries."
|
||||
quiet: true
|
||||
|
||||
- name: Validate DNS and user.key are lists (not strings)
|
||||
when: system.network is defined and system.network.dns is defined
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- system.network.dns.servers is not defined or (system.network.dns.servers is iterable and system.network.dns.servers is not string)
|
||||
- system.network.dns.search is not defined or (system.network.dns.search is iterable and system.network.dns.search is not string)
|
||||
fail_msg: "system.network.dns.servers and system.network.dns.search must be lists, not strings."
|
||||
quiet: true
|
||||
|
||||
- name: Validate user.key is a list
|
||||
when: system.user is defined and system.user.key is defined
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- system.user.key is iterable and system.user.key is not string
|
||||
fail_msg: "system.user.key must be a list of SSH public key strings."
|
||||
quiet: true
|
||||
|
||||
- name: Validate system features input types
|
||||
when: system.features is defined
|
||||
loop: "{{ system_defaults.features | dict2items | map(attribute='key') | list }}"
|
||||
@@ -69,28 +86,8 @@
|
||||
}}
|
||||
gateway: "{{ system_raw.network.gateway | default('') | string }}"
|
||||
dns:
|
||||
servers: >-
|
||||
{{
|
||||
(
|
||||
system_raw.network.dns.servers
|
||||
if system_raw.network.dns.servers is iterable and system_raw.network.dns.servers is not string
|
||||
else (system_raw.network.dns.servers | string).split(',')
|
||||
)
|
||||
| map('trim')
|
||||
| reject('equalto', '')
|
||||
| list
|
||||
}}
|
||||
search: >-
|
||||
{{
|
||||
(
|
||||
system_raw.network.dns.search
|
||||
if system_raw.network.dns.search is iterable and system_raw.network.dns.search is not string
|
||||
else (system_raw.network.dns.search | string).split(',')
|
||||
)
|
||||
| map('trim')
|
||||
| reject('equalto', '')
|
||||
| list
|
||||
}}
|
||||
servers: "{{ system_raw.network.dns.servers | default([]) }}"
|
||||
search: "{{ system_raw.network.dns.search | default([]) }}"
|
||||
path: "{{ system_raw.path | default('') | string }}"
|
||||
packages: >-
|
||||
{{
|
||||
@@ -107,7 +104,7 @@
|
||||
user:
|
||||
name: "{{ system_raw.user.name | string }}"
|
||||
password: "{{ system_raw.user.password | string }}"
|
||||
key: "{{ system_raw.user.key | string }}"
|
||||
key: "{{ system_raw.user.key | default([]) }}"
|
||||
root:
|
||||
password: "{{ system_raw.root.password | string }}"
|
||||
luks:
|
||||
@@ -152,7 +149,7 @@
|
||||
hostname: "{{ system_name }}"
|
||||
os: "{{ system_os_input if system_os_input | length > 0 else ('archlinux' if system_type == 'physical' else '') }}"
|
||||
os_version: "{{ system_raw.version | default('') | string }}"
|
||||
changed_when: false
|
||||
|
||||
|
||||
- name: Normalize system disks input
|
||||
vars:
|
||||
@@ -187,7 +184,7 @@
|
||||
- name: Initialize normalized disk list
|
||||
ansible.builtin.set_fact:
|
||||
system_disks_cfg: []
|
||||
changed_when: false
|
||||
|
||||
|
||||
- name: Build normalized system disk configuration
|
||||
vars:
|
||||
@@ -247,7 +244,7 @@
|
||||
- name: Update system configuration with normalized disks
|
||||
ansible.builtin.set_fact:
|
||||
system_cfg: "{{ system_cfg | combine({'disks': system_disks_cfg}, recursive=True) }}"
|
||||
changed_when: false
|
||||
|
||||
|
||||
- name: Set install_drive from primary disk
|
||||
when:
|
||||
@@ -255,4 +252,4 @@
|
||||
- system_disks_cfg[0].device | string | length > 0
|
||||
ansible.builtin.set_fact:
|
||||
install_drive: "{{ system_disks_cfg[0].device }}"
|
||||
changed_when: false
|
||||
|
||||
|
||||
Reference in New Issue
Block a user