Fix repos tag and add base tag

The `repos` tag was slightly broken because it was applied to the
include task but not to the included tasks. This is now fixed by simply
adding the necessary tag declaration to the included tasks.

Furthermore, I experienced a bad deadlock when the PGP key for the
Spotify packages expired. Because of that, every APT operation failed
and Ansible was unable to gather the facts required by package-related
tasks. Since the installation of the base utilities was coupled to the
`repos` tag, that tag failed as well. Because I use that tag to update
repository keys, I ended up in a deadlock.

The solution is the new `base` tag, which is only responsible for
installing the base utilities. This allows repository keys to be updated
independently of any preceding APT installations.
This commit is contained in:
2026-07-15 01:42:22 +02:00
parent 52c42c5bc7
commit 37364e5204
3 changed files with 4 additions and 1 deletions

View File

@@ -68,6 +68,7 @@ To restrict the scope of execution the playbook uses a couple of tags as describ
|===
| Tag | Scope description
| base | Install install-utils, needed to make the other installs work
| repos | Install 3rd party apt-repositories (only useful on linux)
| packages | Install system-packages
| dotfiles | Install my dotfiles and apply them

View File

@@ -1,5 +1,6 @@
- name: "Download key for {{ item.name }}"
become: yes
tags: [repos]
get_url:
url: "{{ key.url }}"
dest: "/etc/apt/keyrings/{{ key.name | default(item.name) }}.{{ key.format | default('asc') }}"
@@ -10,6 +11,7 @@
- name: "Setup apt repository for {{ item.name }}"
become: yes
tags: [repos]
deb822_repository:
name: "{{ item.name }}"
types: "{{ item.types | default('deb') }}"

View File

@@ -4,8 +4,8 @@
use: systemd
- name: Ensure tools to add additional apt sources
tags: [repos]
become: yes
tags: [base]
package:
name:
- ca-certificates