Linting
Your own checks over the declared tree, the ones that come for free because the whole tree is in memory, and then ansible-lint.
lint runs your own checks over the declared tree first, then
ansible-lint (falling back to ansible-playbook --syntax-check when it
is not installed).
Your own checks#
@check(name="no plaintext passwords")
def no_secrets(tree):
for path, data in tree.items():
if b"password:" in data:
yield f"{path}: plaintext password"
A check is called with {path: bytes} and returns, or yields, problem
strings – a failed assert counts too. @check(only="prod") gates it to
a profile.
The checks that come for free#
--checks-only skips ansible-lint, --no-checks skips yours, and
--no-builtin-checks skips these, which come for free because the whole
tree is in memory at once:
- every play has
hosts - every role a play uses is declared locally, lives in a local collection, or comes from a galaxy requirement
- every
notify:names a handler the role actually defines - every
template:/copy:src:exists in the role’stemplates//files/ - every tag is described, every stage has its playbook, every nested group is described, and the variables have their shape (see Describing a script)
- no file contains something that looks like a credential (the same
SECRET_PATTERNSthatimportuses)
In an editor, the same problems land on the line that declared the file: Editor support.