Skip to content

fix(baseline): make the check-mode key-install conditional boolean - #37

Merged
thiras merged 1 commit into
mainfrom
fix/check-mode-sudo-key-conditional
Sep 1, 2026
Merged

thiras merged 1 commit into
mainfrom
fix/check-mode-sudo-key-conditional

Conversation

@thiras

@thiras thiras commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Problem

make check fails on any host where a sudo operator account already exists:

[ERROR]: Task failed: A 'when' expression failed: Conditional result (True) was
derived from value of type 'list' at roles/baseline/tasks/sudo_account.yml:106:9.
Conditionals must have a boolean result.

getent with fail_key: false stores a hit as the passwd field list —
["x","1000","1000","Ant Somers","/home/user","/bin/bash"] — not a boolean, and
ansible-core 2.19+ rejects a non-boolean conditional outright rather than coercing it.

Why it only shows up under --check

when: not ansible_check_mode or (getent_passwd | default({})).get(sudo_account['name'])

A real run short-circuits on the left operand and yields a clean True, so the right
operand is never evaluated. In check mode not ansible_check_mode is False, the list
is returned as the conditional's result, and the task dies.

So make deploy is unaffected — but the documented pre-deploy dry run is broken. That
asymmetry is also why CI never caught it: no molecule scenario runs in check mode
(grep -rn 'check_mode\|--check' ansible/molecule/ is empty), even though this task
exists specifically to handle check mode.

Introduced by 589b9b1 (#30).

Fix

Compare the getent hit to None explicitly — which is what the comment on the line
already said the test was for.

Verification

Against a real provisioned host (Ubuntu 26.04, two existing operator accounts):

before after
make check ok=17 failed=1 ok=206 changed=7 failed=0

make lint and make lint-ansible (production profile, 0 failures/warnings) both pass.

Follow-up, not in this PR

ansible/galaxy/CHANGELOG.md documents every decdn_node breaking rename from the
recent syncs but has no entry for the ssh_admin_* → baseline_sudo_users removal
in 589b9b1. Those variables are now silently ignored — no shim, no assert — so an
inventory written against the old names still "works" while quietly provisioning the
auto-detected runner instead of the pinned account. Worth a changelog entry.

🤖 Generated with Claude Code

https://claude.ai/code/session_019WB9m9pHjptvDCThR4z6Lj

`make check` fails on any host where a sudo operator account already exists:

  [ERROR]: Task failed: A 'when' expression failed: Conditional result (True)
  was derived from value of type 'list' ... Conditionals must have a boolean
  result.

`getent` with fail_key:false stores a hit as the passwd field LIST
(["x","1000","1000","Ant Somers","/home/user","/bin/bash"]), not a boolean, and
ansible-core 2.19+ rejects a non-boolean conditional outright rather than
coercing it.

It only bites under --check. A real run short-circuits on the left operand of
the `or` and yields a clean True, so the right operand is never evaluated; in
check mode `not ansible_check_mode` is False, the list is returned as the
result, and the task dies. That asymmetry is also why no molecule scenario
catches it — none of them run in check mode.

Compare the getent hit to None explicitly, which is what the comment on the line
already said the test was for.

Verified against a real provisioned host (Ubuntu 26.04, two existing operator
accounts): `make check` went from failed=1 to ok=206 changed=7 failed=0.
`make lint` and `make lint-ansible` (production profile) both pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019WB9m9pHjptvDCThR4z6Lj
Copilot AI lite review requested due to automatic review settings September 1, 2026 19:58

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an Ansible check-mode failure in the baseline role’s sudo operator provisioning by ensuring the authorized_key task’s when clause always evaluates to a boolean under ansible-core 2.19+.

Changes:

  • Makes the check-mode “skip key install if user is missing” conditional explicitly boolean by comparing the getent lookup result against none.
  • Expands inline comments to document why the check-mode path differs and why ansible-core 2.19+ rejects the prior expression.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@thiras
thiras merged commit 3368c6e into main Sep 1, 2026
9 checks passed
@thiras
thiras deleted the fix/check-mode-sudo-key-conditional branch September 1, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants