Repository navigation
Expand file tree
/
Copy pathaction.yml
More file actions
265 lines (253 loc) · 10.7 KB
/
Copy pathaction.yml
File metadata and controls
265 lines (253 loc) · 10.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
---
name: "Play Ansible Playbook"
description: "Github Action for running Ansible Playbooks with advanced configuration options."
inputs:
execution_timeout:
description: "Timeout in minutes for the playbook execution (1-1440, default: 30)."
required: false
default: "30"
retries:
description: "Number of times to retry on failure (0-100, 0 = no retries, default: 0)."
required: false
default: "0"
retry_delay:
description: "Delay in seconds between retries (0-3600, default: 30)."
required: false
default: "30"
# Galaxy Configuration
galaxy_file:
description: "Name of the galaxy file in your workspace."
required: false
galaxy_force:
description: "Forces the reinstallation of roles or collections from the Galaxy file."
required: false
galaxy_api_key:
description: "Sets the API key used for authenticating to Ansible Galaxy."
required: false
galaxy_api_server_url:
description: "Defines the URL of the Ansible Galaxy API server to interact with."
required: false
galaxy_collections_path:
description: "Sets the path to the directory where Galaxy collections are stored."
required: false
galaxy_disable_gpg_verify:
description: "Disables GPG signature verification for Ansible Galaxy operations."
required: false
galaxy_force_with_deps:
description: "Forces the installation of collections with their dependencies from Galaxy."
required: false
galaxy_ignore_certs:
description: "Ignores SSL certificate validation for Ansible Galaxy requests."
required: false
galaxy_ignore_signature_status_codes:
description: "Lists HTTP status codes to ignore during Galaxy signature validation."
required: false
galaxy_keyring:
description: "Specifies the path to the GPG keyring used with Ansible Galaxy."
required: false
galaxy_offline:
description: "Enables offline mode, preventing any requests to Ansible Galaxy."
required: false
galaxy_pre:
description: "Allows the installation of pre-release versions from Ansible Galaxy."
required: false
galaxy_required_valid_signature_count:
description: "Sets the required number of valid GPG signatures for Galaxy content."
required: false
galaxy_requirements_file:
description: "Defines the path to the Ansible Galaxy requirements file."
required: false
galaxy_signature:
description: "Specifies a specific GPG signature to verify for Galaxy content."
required: false
galaxy_timeout:
description: "Sets the timeout in seconds for Ansible Galaxy operations."
required: false
galaxy_upgrade:
description: "Enables automatic upgrading of Galaxy collections to the latest version."
required: false
galaxy_no_deps:
description: "Disables automatic resolution of dependencies in Ansible Galaxy."
required: false
# Playbook Configuration
inventory:
description: "One or more inventory host files. Supports comma-separated ('inv1.yml,inv2.yml') or multiline YAML syntax."
required: true
playbook:
description: "One or more playbooks to apply. Supports comma-separated ('play1.yml,play2.yml') or multiline YAML syntax."
required: true
limit:
description: "Limits the playbook execution to a specific group of hosts."
required: false
skip_tags:
description: "Only run plays and tasks whose tags do not match these values."
required: false
start_at_task:
description: "Start the playbook at the task matching this name."
required: false
tags:
description: "Executes only tasks and plays with specified tags."
required: false
extra_vars:
description: "Additional variables in key=value format. Supports comma-separated or multiline YAML syntax for multiple values."
required: false
module_path:
description: "Prepend directories to the module library path. Supports comma-separated or multiline YAML syntax for multiple paths."
required: false
# Pre-execution
lint:
description: "Run ansible-lint on playbooks before execution."
default: 'false'
required: false
# Output Options
output_file:
description: "Save Ansible stdout to a file (useful for capturing diff output for PR comments)."
required: false
# Execution Options
check:
description: "Executes a dry run, showing what changes would be made without making them."
required: false
diff:
description: "Shows the differences in files and templates when changing them."
required: false
dry_run:
description: "Enables both check and diff mode for a dry run without making changes."
required: false
default: 'false'
flush_cache:
description: "Clears the fact cache for every host in the inventory."
required: false
force_handlers:
description: "Runs all handlers even if a task fails."
required: false
list_hosts:
description: "Outputs a list of matching hosts."
required: false
list_tags:
description: "List all available tags."
required: false
list_tasks:
description: "List all tasks that would be executed."
required: false
syntax_check:
description: "Performs a syntax check on the playbook, without executing it."
required: false
forks:
description: "Defines the number of parallel processes to use during playbook execution (1-1000, default: 5)."
required: false
# Authentication and Vault
vault_id:
description: "Specifies the identity to use when accessing an Ansible Vault."
required: false
vault_password:
description: "Sets the password to use for decrypting an Ansible Vault."
required: false
verbose:
description: "Sets the verbosity level, ranging from 0 (minimal output) to 4 (maximum verbosity)."
required: false
private_key:
description: "Specifies the SSH private key content for connections. The key is loaded into ssh-agent, making it available to ProxyCommand and bastion host connections. Should be stored in a GitHub Secret."
required: false
private_key_passphrase:
description: "Passphrase for the SSH private key. If provided, the passphrase is used to unlock the key when adding it to ssh-agent. Should be stored in a GitHub Secret."
required: false
additional_private_keys:
description: "Additional SSH private keys to load into ssh-agent. Supports multiline YAML syntax for multiple keys. Requires private_key to be set."
required: false
user:
description: "Defines the username for making connections."
required: false
connection:
description: "Sets the type of connection to use (e.g., SSH)."
required: false
timeout:
description: "Overrides the default connection timeout in seconds."
required: false
ssh_common_args:
description: "Specifies common arguments to pass to all SSH-based connection methods (SSH, SCP, SFTP)."
required: false
sftp_extra_args:
description: "Provides extra arguments to pass only to SFTP."
required: false
scp_extra_args:
description: "Provides extra arguments to pass only to SCP."
required: false
ssh_extra_args:
description: "Provides extra arguments to pass only to SSH."
required: false
known_hosts:
description: "SSH known hosts entries for host key verification. Supports multiline YAML syntax."
required: false
# Privilege Escalation
become:
description: "Enables privilege escalation, allowing operations to run as another user."
required: false
become_method:
description: "Specifies the method to use for privilege escalation (e.g., sudo)."
required: false
become_user:
description: "Sets the user to impersonate when using privilege escalation."
required: false
# Advanced Configuration
config_file:
description: "Path to an ansible.cfg configuration file to use (sets ANSIBLE_CONFIG)."
required: false
no_color:
description: "Disables colorized output."
required: false
output_callback:
description: "Sets the stdout callback plugin for Ansible output (e.g. 'yaml', 'json', 'minimal')."
required: false
callbacks_enabled:
description: "Comma-separated list of enabled callback plugins (e.g. 'profile_tasks,timer')."
required: false
strategy_plugin:
description: "Specifies the strategy plugin to use (e.g. 'linear', 'free', 'mitogen_linear')."
required: false
gather_subset:
description: "Limits the scope of gathered facts (e.g. '!all,!min,network')."
required: false
gather_timeout:
description: "Timeout in seconds for gathering facts (0-3600, 0 = ansible default)."
required: false
fact_path:
description: "Path to local fact files loaded as host facts."
required: false
fact_caching:
description: "Caching method to use for facts (e.g. 'jsonfile', 'redis', 'memory')."
required: false
fact_caching_timeout:
description: "Timeout in seconds for the fact cache (0 = no expiry)."
required: false
poll_interval:
description: "Interval in seconds for polling async tasks (0-3600, 0 = ansible default)."
required: false
max_fail_percentage:
description: "Maximum percentage of hosts that can fail before the playbook aborts (0-100)."
required: false
any_errors_fatal:
description: "Treats any task error as fatal, aborting the whole play."
required: false
ssh_transfer_method:
description: "Method for file transfer over SSH (e.g. 'scp' or 'sftp')."
required: false
vault_password_file:
description: "Path to a file containing the vault password (alternative to vault_password)."
required: false
private_key_file:
description: "Path to a file containing the SSH private key (alternative to private_key)."
required: false
temp_dir:
description: "Directory for Ansible temporary files."
required: false
outputs:
status:
description: "Execution status: 'success' or 'failed'"
exit_code:
description: "Ansible exit code (0=success, 2=host failed, 4=unreachable)"
runs:
using: "docker"
image: "docker://ghcr.io/arillso/action.playbook:0.5.0"
branding:
icon: "play-circle"
color: "black"