Skip to content

feat: complete lab05 - ansible fundamentals#7

Open
pepegx wants to merge 16 commits intomasterfrom
lab05
Open

feat: complete lab05 - ansible fundamentals#7
pepegx wants to merge 16 commits intomasterfrom
lab05

Conversation

@pepegx
Copy link
Owner

@pepegx pepegx commented Feb 26, 2026

Summary

This PR completes Lab 5 (Ansible Fundamentals) with a role-based Ansible
project for provisioning and application deployment.

What was implemented

  • Role-based Ansible structure in ansible/
  • common role:
    • apt cache update
    • common packages installation
    • timezone configuration
  • docker role:
    • Docker APT repo + GPG key
    • Docker Engine installation
    • Docker service management (enabled/running)
    • user added to docker group
    • python3-docker installation
    • Docker restart handler
  • app_deploy role:
    • Docker Hub login (Vault variables, no_log: true)
    • image pull
    • container deployment/update
    • readiness wait (wait_for)
    • health check (uri + assert)
    • app handler defined
  • Playbooks:
    • provision.yml
    • deploy.yml
    • site.yml
  • Ansible Vault:
    • encrypted group_vars/all.yml
    • plaintext template group_vars/all.yml.example
  • Documentation:
    • detailed report in ansible/docs/LAB05.md

Validation performed (local)

  • ansible-inventory parsing
  • ansible-playbook --syntax-check for provision.yml, deploy.yml,
    site.yml
  • Ansible Vault decryption check (ansible-vault view)
  • End-to-end local execution on Ubuntu 24.04 test target (Docker-based)
  • Idempotency verified:
    • provision.yml: first run changes resources, second run changed=0
    • deploy.yml: repeated runs changed=0 after successful deployment
  • Health endpoint verification: /health returns status=healthy

Important note (environment constraint)

Yandex Cloud VM provisioning from Lab 4 was blocked in this environment due
IAM permissions, so full runtime validation was performed on a local Ubuntu
24.04 test target (Docker + systemd).
The Ansible project is ready to run on a real Lab 4 VM by updating inventory
and Vault credentials.

Security

  • No Vault password file committed
  • Sensitive credentials stored in encrypted Vault file
  • No plaintext secrets intentionally committed

pepega and others added 16 commits January 28, 2026 13:08
- Implement Flask-based DevOps Info Service (Python)
- Add GET / endpoint with service, system, runtime, and request info
- Add GET /health endpoint for monitoring
- Implement environment variable configuration (HOST, PORT, DEBUG)
- Add comprehensive documentation (README.md and LAB01.md)
- Include best practices: PEP 8, error handling, logging
- Add GitHub Community engagement section
- Implement bonus task: Go version of the service
- Add testing screenshots and evidence
- Pin dependencies in requirements.txt
- Configure .gitignore for Python and Go
- Add pytest unit tests (15 tests covering all endpoints)
- Add GitHub Actions workflow with matrix testing (Python 3.11, 3.12)
- Add ruff linter integration
- Add Docker build/push with CalVer versioning
- Add status badge to README
- Add LAB03.md documentation

Best practices:
- Dependency caching via setup-python
- Docker layer caching via Buildx
- Job dependencies (docker needs lint-test)
- Fail-fast matrix strategy
- Concurrency with cancel-in-progress
- Path filters for monorepo efficiency
- Docker build always runs (validates Dockerfile)
- Docker push only when DOCKERHUB secrets are configured
- Graceful handling when secrets not available
- Add .github/workflows/go-ci.yml for Go application
- Language-specific linting with golangci-lint
- Go testing with race detector and coverage
- Snyk security scanning for Go dependencies
- Docker build and push with CalVer versioning
- Path-based triggers for monorepo optimization
- Separate Docker image: pepegx/devops-info-service-go
- Parallel execution with Python CI workflow
…i-app support

Completes all main tasks (10pts) and bonus tasks (2.5pts):

MAIN TASKS (10pts):
- Unit Testing (3pts): pytest framework, 15 tests, 80% coverage
- GitHub Actions CI (4pts): python-ci.yml with matrix build, linting, testing, Docker push
- CI Best Practices (3pts): status badge, caching, Snyk security scanning

BONUS (2.5pts):
- Multi-App CI: go-ci.yml with path-based triggers
- Test Coverage: codecov integration with XML reporting

All requirements verified locally and ready for GitHub Actions execution.
- Fix codecov action file path (app_python/coverage.xml)
- Add CODECOV_TOKEN secret to codecov action
- Fix Snyk actions with proper file paths for both Python and Go
- Add Go CI status badge to app_go/README.md
- Fix codecov badge URL in app_python/README.md (remove token param)

All Lab03 requirements verified:
- 15 unit tests passing with 80% coverage
- Matrix builds for Python 3.11/3.12
- Snyk security scanning configured
- CalVer versioning implemented
- Path filters for monorepo
- Add main_test.go with 12 comprehensive unit tests
- Test all endpoints: /, /health, 404 handler
- Test helper functions: getEnv, getUptime, getSystemInfo
- Test custom mux wrapper with subtests
- Update README with unit testing documentation
- Update LAB03.md with test details

Coverage: 67.2% of statements
- Add pyproject.toml with 70% coverage threshold
- Configure pytest-cov fail-under for CI enforcement
- Add codecov upload for Go workflow
- Update LAB03.md with new coverage stats (98%)
- Simplify pytest command to use pyproject.toml config

Coverage improvements:
- Python: 98% coverage with 70% threshold
- Go: 67.2% coverage with codecov integration
- Refactor main.go: extract setupRouter() and printStartupBanner()
- Add TestSetupRouter to test router configuration
- Add TestPrintStartupBanner to test startup output
- Add TestDebugMode to test handlers with debug=true
- Coverage increased from 67.2% to 87.3% (above 70% threshold)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant