Skip to content

Make Ansible in dconf_ini_file idempotent#13978

Merged
Mab879 merged 1 commit intoComplianceAsCode:masterfrom
jan-cerny:dconf_ini_file
Oct 6, 2025
Merged

Make Ansible in dconf_ini_file idempotent#13978
Mab879 merged 1 commit intoComplianceAsCode:masterfrom
jan-cerny:dconf_ini_file

Conversation

@jan-cerny
Copy link
Copy Markdown
Collaborator

@jan-cerny jan-cerny commented Oct 3, 2025

Resolves: https://issues.redhat.com/browse/OPENSCAP-6252

Review Hints:

  • ./build_product --playbook-per-rule rhel9

  • manually replace hosts by hosts: all in /build/rhel9/playbooks/stig/dconf_gnome_lock_screen_on_smartcard_removal.yml

  • install a VM with a gdm package installed.

  • run ansible-playbook -u root -i YOUR_IP, /build/rhel9/playbooks/stig/dconf_gnome_lock_screen_on_smartcard_removal.yml at least twice and compare the output of the first run with the second run and so on, verify that the second and next runs don't change anything and that the output contains only "ok" or "skipping"

  • apart from that, run automatus Tss with --remediate-using ansible

@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Oct 3, 2025

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Used by openshift-ci bot. label Oct 3, 2025
@jan-cerny jan-cerny added this to the 0.1.79 milestone Oct 6, 2025
@jan-cerny jan-cerny marked this pull request as ready for review October 6, 2025 08:54
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Used by openshift-ci bot. label Oct 6, 2025
@jan-cerny jan-cerny added Ansible Ansible remediation update. do-not-merge/work-in-progress Used by openshift-ci bot. labels Oct 6, 2025
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Oct 6, 2025

@jan-cerny: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-openshift-node-compliance b8bf627 link true /test e2e-aws-openshift-node-compliance

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@Mab879 Mab879 self-assigned this Oct 6, 2025
@Mab879 Mab879 merged commit 6defe86 into ComplianceAsCode:master Oct 6, 2025
133 of 136 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ansible Ansible remediation update. do-not-merge/work-in-progress Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants