* Update pre-commit actions This was done by running "pre-commit autoupdate --freeze". * Remove pre-commit only dependencies from requirements.in Including them in the file would create the illusion that those were the versions actually used in CI, but they are not. The exact versions are determined by the pre-commit hooks which are pinned in .pre-commit-config.yaml. * Ansible Lint: Fix role-name[path] * Ansible Lint: Fix name[play] * Ansible Lint: Fix key-order[task] * Ansible Lint: Fix jinja[spacing] * Ansible Lint: Fix no-free-form * Ansible Lint: Fix var-naming[no-reserved] * Ansible Lint: Fix yaml[comments] * Ansible Lint: Fix yaml[line-length] * Ansible Lint: Fix name[casing] * Ansible Lint: Fix no-changed-when * Ansible Lint: Fix fqcn[action] * Ansible Lint: Fix args[module] * Improve task naming
48 lines
1.2 KiB
YAML
48 lines
1.2 KiB
YAML
---
|
|
- name: Check for container files that exist on this host
|
|
stat:
|
|
path: "/etc/pve/lxc/{{ item }}.conf"
|
|
loop: "{{ proxmox_lxc_ct_ids }}"
|
|
register: stat_results
|
|
|
|
- name: Filter out files that do not exist
|
|
set_fact:
|
|
proxmox_lxc_filtered_files:
|
|
'{{ stat_results.results | rejectattr("stat.exists", "false") | map(attribute="stat.path") }}'
|
|
|
|
- name: Remove LXC apparmor profile
|
|
lineinfile:
|
|
dest: "{{ item }}"
|
|
regexp: "^lxc.apparmor.profile"
|
|
line: "lxc.apparmor.profile: unconfined"
|
|
state: absent
|
|
loop: "{{ proxmox_lxc_filtered_files }}"
|
|
notify: reboot containers
|
|
|
|
- name: Remove lxc cgroups
|
|
lineinfile:
|
|
dest: "{{ item }}"
|
|
regexp: "^lxc.cgroup.devices.allow"
|
|
line: "lxc.cgroup.devices.allow: a"
|
|
state: absent
|
|
loop: "{{ proxmox_lxc_filtered_files }}"
|
|
notify: reboot containers
|
|
|
|
- name: Remove lxc cap drop
|
|
lineinfile:
|
|
dest: "{{ item }}"
|
|
regexp: "^lxc.cap.drop"
|
|
line: "lxc.cap.drop: "
|
|
state: absent
|
|
loop: "{{ proxmox_lxc_filtered_files }}"
|
|
notify: reboot containers
|
|
|
|
- name: Remove lxc mounts
|
|
lineinfile:
|
|
dest: "{{ item }}"
|
|
regexp: "^lxc.mount.auto"
|
|
line: 'lxc.mount.auto: "proc:rw sys:rw"'
|
|
state: absent
|
|
loop: "{{ proxmox_lxc_filtered_files }}"
|
|
notify: reboot containers
|