refactor(service-role-loader): retire active_services #13

Merged
claudiomaradonna merged 2 commits from refactor/drop-active-services into main 2026-09-26 12:27:23 +02:00

Why

Every service role is now switched on by its own <role>_enabled flag
through service_roles, so active_services no longer loaded anything a
flag could not. What it still did was outlive the roles it named: a host
that kept a retired iptables-* role in the list failed its run at the
loader with "role not found" — after hardening had applied, before
firewall-apply ran — and no gate can see it, because inventories are
untracked.

What changed

  • service-role-loader fails a host that still sets active_services, No changes this session
    before loading anything, also under --check and a tagged run. The
    message names the flag to set for a service_roles member, and names
    any other entry as one to add to service_roles or drop as retired.
  • The loader's second include loop and the active_services default are
    gone; firewall-apply no longer seeds services from the list.
  • Breaking: a role outside the repository can no longer be loaded ad hoc;
    it has to join service_roles and have its flag set.
  • Docs updated where the list was described; CONTRIBUTING.md also gains
    a note on running the gates from a sandbox that lacks the user's
    collections.

Verification

  • make VENV=.venv-jail check: every gate passes, including the new
    retired gate (tests/gates/check_retired_services.sh) and render,
    whose fx_lab fixture now comes in through a flag.
  • Not run: make test and make propagation (no podman in the
    environment used).

Risks and follow-ups

A tenant inventory or host_vars that still sets active_services now
fails at the loader on its next run, --check included — by design.
Only the one known stale entry existed, and it was already removed
locally. Run make test and make propagation before merging.

## Why Every service role is now switched on by its own `<role>_enabled` flag through `service_roles`, so `active_services` no longer loaded anything a flag could not. What it still did was outlive the roles it named: a host that kept a retired `iptables-*` role in the list failed its run at the loader with "role not found" — after hardening had applied, before `firewall-apply` ran — and no gate can see it, because inventories are untracked. ## What changed - `service-role-loader` fails a host that still sets `active_services`, No changes this session before loading anything, also under `--check` and a tagged run. The message names the flag to set for a `service_roles` member, and names any other entry as one to add to `service_roles` or drop as retired. - The loader's second include loop and the `active_services` default are gone; `firewall-apply` no longer seeds services from the list. - Breaking: a role outside the repository can no longer be loaded ad hoc; it has to join `service_roles` and have its flag set. - Docs updated where the list was described; `CONTRIBUTING.md` also gains a note on running the gates from a sandbox that lacks the user's collections. ## Verification - `make VENV=.venv-jail check`: every gate passes, including the new `retired` gate (`tests/gates/check_retired_services.sh`) and `render`, whose `fx_lab` fixture now comes in through a flag. - Not run: `make test` and `make propagation` (no podman in the environment used). ## Risks and follow-ups A tenant inventory or `host_vars` that still sets `active_services` now fails at the loader on its next run, `--check` included — by design. Only the one known stale entry existed, and it was already removed locally. Run `make test` and `make propagation` before merging.
Every service role is switched on by its own <role>_enabled flag, so the
list no longer loaded anything the flags could not. It did outlive the
roles it named: a host still listing a retired iptables-* role failed its
run at the loader, after hardening and before the firewall.

The loader now fails a host that still sets active_services, before
loading anything and also under --check or a tagged run, naming the flag
to set. firewall-apply no longer reads the list. A role outside the
repository must join service_roles to be loaded. The new 'retired' gate
in make check covers the guard.
claudiomaradonna deleted branch refactor/drop-active-services 2026-09-26 12:27:30 +02:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
claudiomaradonna/castrum!13
No description provided.