refactor: read facts through ansible_facts and stop injecting them #5
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "refactor/ansible-facts-access"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
ansible-core deprecates
INJECT_FACTS_AS_VARSand stops injecting top-levelansible_*fact variables in 2.24. Every role still reading them printed adeprecation warning. For firewall-apply the removal would have been silent and
harmful: with injection off, peer derivation filters out every peer, and
from_grouprules for swarm, gluster and ai-stack get dropped.What changes
os_family,distribution,distribution_releaseandservice_mgrareread as
ansible_facts['…'].ansible_facts.default_ipv4.address.The select stays on the leaf key, not the parent (the
d0b5639regression).ansible_facts['default_ipv4']['address']. The value, the empty fallbackand the non-empty asserts are unchanged.
ansible_default_ipv4asan inventory variable, and that never reaches
hostvars[h].ansible_facts.That is why the 2026-08-27 attempt failed. The new
prime.ymlwrites thefacts into a temporary fact cache with
set_fact(cacheableanddelegate_facts). The derivation then reads them in a separate run, withinjection on and with injection off.
inject_facts_as_vars = False, so any new use fails asundefined instead of printing a warning.
Blast radius
peer's address can't be found, its rule is dropped, not opened. The
worst case is lost cluster traffic for swarm, gluster or ai-stack. SSH does
not depend on peer addresses.
the role fails by name.
cached facts, and no tenant
inventory/orhost_vars/file sets or readsinjected facts.
Verification
make check: passes withinject_facts_as_vars = False.ansible_default_ipv4expression, the injection-off run fails;make test(molecule) andmake verify. They need podman.--check --diff --tags firewallon eachtenant, before and after. The rendered nftables table should be
byte-identical.