Manual

Linting

Your own checks over the declared tree, the ones that come for free because the whole tree is in memory, and then ansible-lint.

lint runs your own checks over the declared tree first, then ansible-lint (falling back to ansible-playbook --syntax-check when it is not installed).

Your own checks#

@check(name="no plaintext passwords")
def no_secrets(tree):
    for path, data in tree.items():
        if b"password:" in data:
            yield f"{path}: plaintext password"

A check is called with {path: bytes} and returns, or yields, problem strings – a failed assert counts too. @check(only="prod") gates it to a profile.

The checks that come for free#

--checks-only skips ansible-lint, --no-checks skips yours, and --no-builtin-checks skips these, which come for free because the whole tree is in memory at once:

  • every play has hosts
  • every role a play uses is declared locally, lives in a local collection, or comes from a galaxy requirement
  • every notify: names a handler the role actually defines
  • every template:/copy: src: exists in the role’s templates//files/
  • every tag is described, every stage has its playbook, every nested group is described, and the variables have their shape (see Describing a script)
  • no file contains something that looks like a credential (the same SECRET_PATTERNS that import uses)

In an editor, the same problems land on the line that declared the file: Editor support.

The source of this page

    Type to search. ↑ ↓ to move, enter to open.