|
1 | 1 | # Convenience targets for the deCDN Ansible project. |
2 | 2 | # Always run from the ansible/ directory. |
3 | | -.PHONY: deps lint check deploy molecule build galaxy-check |
| 3 | +.PHONY: deps lint check deploy molecule molecule-serial build galaxy-check |
4 | 4 | SHELL := /bin/bash |
5 | 5 |
|
6 | 6 | # Install the required Galaxy collections (>= constraints in requirements.yml) |
@@ -67,11 +67,51 @@ deploy: |
67 | 67 | # stub daemon (needs Docker; a privileged systemd container). See molecule/. |
68 | 68 | # Scenarios: default (rendered values + idempotence), schema (config key-set drift |
69 | 69 | # against the upstream field list), validation (bad knobs must be rejected by the |
70 | | -# role's own asserts), generate-keystore (opt-in host-side wallet), slow-readiness |
71 | | -# (advisory /metrics probe timeout). |
72 | | -# `--all` runs every scenario: `default` (operator-provisioned keystore) and |
73 | | -# `generate-keystore` (opt-in host-side wallet generation). |
74 | | -molecule: |
| 70 | +# role's own asserts), generate-keystore (opt-in host-side wallet), host-env |
| 71 | +# (host-provisioned /etc/decdn/decdn.env), slow-readiness (advisory /metrics probe |
| 72 | +# timeout). |
| 73 | +# |
| 74 | +# The scenarios run concurrently: distinct container names, no published host ports, |
| 75 | +# per-scenario ephemeral dirs, and what they share on the control machine (the |
| 76 | +# vendored collections, roles/, the stub under default/files/) they only read. |
| 77 | +# 595s -> 151s on a 16-core box. They DO share one Docker daemon and the host cgroup |
| 78 | +# hierarchy — every platform is a privileged systemd container — which is why CI caps |
| 79 | +# JOBS. Output interleaves, hence the [scenario] prefix; `molecule-serial` is the |
| 80 | +# escape hatch when a failure needs reading in order. Override the fan-out width with |
| 81 | +# e.g. `make molecule JOBS=2` on a small machine. |
| 82 | +# |
| 83 | +# Molecule's own --workers is not usable here: it refuses to run outside collection |
| 84 | +# mode ("--workers > 1 is only supported in collection mode (galaxy.yml required)"), |
| 85 | +# and this project deliberately has no galaxy.yml at its root — that would make |
| 86 | +# ansible-lint reinterpret the deploy project as a collection (see galaxy/README.md). |
| 87 | +# |
| 88 | +# Fail loud (hard rule 4), in three places, because a test harness that passes when it |
| 89 | +# did not run is worse than a slow one: |
| 90 | +# - the guard below refuses an empty or truncated scenario set. Discovery moved from |
| 91 | +# molecule to a glob, and a glob that matches nothing (wrong cwd, renamed layout) |
| 92 | +# would otherwise run zero scenarios and exit 0 — a green build that tested nothing. |
| 93 | +# - pipefail stops the [scenario] prefixing pipe from masking molecule's status, and |
| 94 | +# each scenario announces its own failure by name (the bare xargs message does not). |
| 95 | +# - xargs then exits non-zero: 123 for an ordinary failure, or 124 on a status-255 |
| 96 | +# abort, which also skips any scenario it had not started yet. |
| 97 | +SCENARIOS := $(notdir $(patsubst %/,%,$(dir $(wildcard molecule/*/molecule.yml)))) |
| 98 | +SCENARIO_DIRS := $(notdir $(patsubst %/,%,$(wildcard molecule/*/))) |
| 99 | +JOBS ?= $(words $(SCENARIOS)) |
| 100 | + |
| 101 | +molecule: deps |
| 102 | + @test -n "$(strip $(SCENARIOS))" && test "$(strip $(SCENARIOS))" = "$(strip $(SCENARIO_DIRS))" || { \ |
| 103 | + echo "scenario discovery failed: molecule.yml in [$(SCENARIOS)] but scenario dirs are [$(SCENARIO_DIRS)]"; \ |
| 104 | + echo "refusing to run a silently-truncated suite (this target must run from ansible/)"; exit 1; } |
| 105 | + @case '$(JOBS)' in ''|*[!0-9]*|0) \ |
| 106 | + echo "JOBS must be a positive integer (got '$(JOBS)'); note xargs -P 0 means unlimited"; exit 1 ;; esac |
| 107 | + @printf '%s\n' $(SCENARIOS) | xargs -P $(JOBS) -I{} \ |
| 108 | + bash -c 'set -euo pipefail; molecule test -s {} --no-command-borders 2>&1 | sed -u "s/^/[{}] /" \ |
| 109 | + || { echo "[{}] SCENARIO FAILED"; exit 1; }' |
| 110 | + |
| 111 | +# The same suite, one scenario at a time (molecule's own --all). It stops at the FIRST |
| 112 | +# failing scenario (--continue-on-failure defaults off), so it reports less than the |
| 113 | +# parallel target — but readably, which is the point. |
| 114 | +molecule-serial: deps |
75 | 115 | molecule test --all |
76 | 116 |
|
77 | 117 | # --- Galaxy collection (decdn.node) ------------------------------------------ |
|
0 commit comments