Skip to content

Commit

Permalink
Improve vault processing
Browse files Browse the repository at this point in the history
Fixes: #2506
  • Loading branch information
ssbarnea committed Apr 19, 2023
1 parent fd23b3a commit 749fd0a
Show file tree
Hide file tree
Showing 4 changed files with 22 additions and 3 deletions.
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
---
$ANSIBLE_VAULT;1.1;AES256
35366433323361393130396530643233373262666636646439303032366431303363316232313738
3738636130636431623936303932306430316635663136610a353737333966353462333532393631
Expand Down
8 changes: 8 additions & 0 deletions examples/playbooks/vars/vault_partial.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
ldap_password: !vault |
$ANSIBLE_VAULT;1.1;AES256
35323062386261383633623963303361313937653837333033613933623434343138663331336164
3534373564393166656664306537633035613962356662645a316562353832363736313935383665
33306432623765646338303236363061326538653163643466643446716164326364643937623365
6239383765373639390a646361343566353934633532376231653838386231653865386665303733
34336534613538326639306139363538306636383463663437643466653064646363
1 change: 1 addition & 0 deletions src/ansiblelint/rules/schema.py
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,7 @@ def matchyaml(self, file: Lintable) -> list[MatchError]:
if errors[0].startswith("Failed to load YAML file"):
_logger.debug(
"Ignored failure to load %s for schema validation, as !vault may cause it.",
file,
)
return []

Expand Down
15 changes: 12 additions & 3 deletions test/test_examples.py
Original file line number Diff line number Diff line change
Expand Up @@ -54,10 +54,19 @@ def test_example_custom_module(default_rules_collection: RulesCollection) -> Non
assert len(result) == 0, f"{app.runtime.cache_dir}"


def test_full_vault(default_rules_collection: RulesCollection) -> None:
"""custom_module.yml is expected to pass."""
def test_vault_full(default_rules_collection: RulesCollection) -> None:
"""Check ability to process fully vaulted files."""
result = Runner(
"examples/playbooks/vars/vault_full.yml",
rules=default_rules_collection,
).run()
assert len(result) == 0


def test_vault_partial(default_rules_collection: RulesCollection) -> None:
"""Check ability to precess files that container !vault inside."""
result = Runner(
"examples/playbooks/vars/not_decryptable.yml",
"examples/playbooks/vars/vault_partial.yml",
rules=default_rules_collection,
).run()
assert len(result) == 0
Expand Down

0 comments on commit 749fd0a

Please sign in to comment.