fix(tasks): include verify_vars.yaml as tasks file

The variable verification was included via include_vars, which is meant for variable files only. Additionally the
first_found lookup had no paths defined, so it searched the files/ subdirectory and the role root instead of tasks/ and
failed with "No file was found". Switching to include_tasks and adding the tasks path makes the verification run at all.

The assertion itself was fully commented out and is now active, so a misconfigured entry fails early instead of being
silently skipped by all four sudoers tasks.

Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
2026-09-10 21:41:34 +02:00
co-authored by Copilot
parent fae902ac46
commit 7c76a5cc86
2 changed files with 14 additions and 8 deletions
+4 -2
View File
@@ -14,13 +14,15 @@
- vars - vars
- name: Verify variables - name: Verify variables
ansible.builtin.include_vars: "{{ lookup('first_found', params) }}" ansible.builtin.include_tasks: "{{ lookup('first_found', params) }}"
vars: vars:
params: params:
files: files:
- "{{ ansible_facts['distribution'] }}_verify_vars.yaml" - "{{ ansible_facts['distribution'] }}_verify_vars.yaml"
- "{{ ansible_facts['os_family'] }}_verify_vars.yaml" - "{{ ansible_facts['os_family'] }}_verify_vars.yaml"
- "verify_vars.yaml" - verify_vars.yaml
paths:
- tasks
- name: Install sudo - name: Install sudo
ansible.builtin.package: ansible.builtin.package:
+10 -6
View File
@@ -1,8 +1,12 @@
--- ---
# - name: Verify if not user and group exists for each entry - name: Verify that each entry defines either a user or a group
# ansible.builtin.assert: ansible.builtin.assert:
# that: that:
# - (item.user is defined and item.group is not defined) or - (item.user is defined and item.user | length > 0) !=
# (item.user is not defined and item.group is defined) (item.group is defined and item.group | length > 0)
# with_items: "{{ sudo_users_sudoers }}" fail_msg: >
Each entry of sudo_users_sudoers must define either 'user' or 'group',
but not both and not none.
quiet: true
with_items: "{{ sudo_users_sudoers }}"