A Forgotten Variable Overwrote the Vault Password With 'changeme' — Ansible Lint & Testing

Опубликовано: 03 Июль 2026
на канале: TheCodeForge
0

An `include_role` forgot to pass a variable, so a routine deployment overwrote the vaulted `db_password` with the default 'changeme' — production auth failed. This is linting and testing Ansible: ansible-lint, Molecule, testinfra, CI gates, and catching the variable and idempotency bugs that lint/tests would have flagged before prod.

⏳ Timestamps:
0:00 - Cold open: FATAL: password authentication failed for user "app"
0:21 - Intro
0:27 - What Is Linting & Testing?
0:49 - Why Profiles Matter
1:19 - yamllint: YAML Style
1:55 - Molecule with Docker
2:27 - Testinfra Verify Tests
2:57 - Ansible Verify Tests
3:23 - CI/CD Integration
3:53 - Common Lint Violations
4:23 - Molecule Scenarios
4:54 - Advanced Molecule
5:25 - Version Compatibility Caveat
5:46 - Idempotency Test with Testinfra
6:06 - Production Caveat: Docker Socket Permissions
6:32 - Debugging Molecule Failures
7:01 - Idempotency Testing
7:26 - Custom Rules & Ignoring
7:50 - FATAL: password authentication failed for user "app"
8:11 - The Fix
8:31 - ⚠ Gotcha: Default secret values in vars/main.yml
8:44 - Debugging Guide
8:56 - Interview Questions
9:24 - FAQ
9:49 - Key Takeaways
10:08 - Next up
10:17 - Wrap-up

👉 Full article + code: https://thecodeforge.io/devops/ansibl...
⏭ Next up: Ansible Windows Automation

#ansible #devops #automation