feat(playbooks): check AIDE before and update its database after every run - #419
Open
NavidSassan wants to merge 1 commit into
Open
NavidSassan wants to merge 1 commit into
NavidSassan wants to merge 1 commit into
Conversation
…y run On hosts with an active aidecheck.timer, every playbook stops in its pre_tasks if the last AIDE check failed, and its post_tasks have aide-update.service update the database after the run (--no-block). A request file plus a loop in /usr/local/sbin/aide-update keeps a play that ends during an update from being merged into the running job. New LFOps-wide variables: lfops__skip_aide_check_before_run, lfops__skip_aide_update_db_after_run.
NavidSassan
marked this pull request as ready for review
October 2, 2026 13:24
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With the aide role in
setup_basic, nearly every LFOps run changes monitored files, so the next AIDE check fails and someone has to read the log and update the database by hand. This makes the update part of every playbook run, without accepting a finding that was pending before it.Changes
pre_tasks:aide-check-before-run.yml. On a host with an activeaidecheck.timer, the run stops for that host ifaidecheck.serviceis failed, naming--tags aide:update_db_forceas the remedy. A running check is waited for (5 minutes). If an update is pending (request file present oraide-update.serviceactivating), the run passes without checking.post_tasks:aide-update-db-after-run.yml. Only if the check before the run passed: touches/run/aide-update.requestand startsaide-update.servicewith--no-block, so the play does not wait.--tags aide:update_db_force, in check mode, and on Windows.aide-update.serviceand/usr/local/sbin/aide-update. The script loops: remove the request,aide --updateunder/run/aide.lock,systemctl start --wait aidecheck.service, repeat while a new request exists. A start request for the running oneshot unit is merged into its job by systemd, so the request file is what keeps a play that ends during an update from being lost. Contract for callers: request an update only after a clean check.lfops__skip_aide_check_before_run(deploy to a host with a pending finding; the database is then not updated after the run either) andlfops__skip_aide_update_db_after_run(keep the check, leave the database alone).The update accepts everything that changed since the last clean check, not only the changes of the run, the same trade-off the role's handler and
aide:update_dbalready make. A failed run gets no update, so its changes are reported and the next run stops until they are accepted.Tests
Molecule
aidescenario on Rocky 8, 9 and 10, Debian 12 and 13, Ubuntu 22.04, 24.04 and 26.04: converge, verify, idempotence (0 changed), verify all green. Re-run on Rocky 8 and Debian 13 after renaming the unit toaide-update. New play inverify.yml:/run/aide.lock: the second run passes on the pending update, and the journal shows two updates, the second one for the second run's request.lfops__skip_aide_check_before_run: the run continues, the database is unchanged.lfops__skip_aide_update_db_after_run: the check passes, the database is unchanged.Not run: the
setup_basicscenario. On Rocky it fails the AIDE check because of the stale.pycfiles in the monitoring-plugins v8.0.0 package (fixed upstream, not released), and with this change its idempotence run now stops at the check before the run.Open
ansible-navigator, the READMEs sayansible-playbook.