main
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ansible-lint](https://github.com/ansible/ansible-lint) ([changelog](https://github.com/ansible/ansible-lint/releases)) | minor | `==26.6.0` → `==26.9.0` | --- ### Release Notes <details> <summary>ansible/ansible-lint (ansible-lint)</summary> ### [`v26.9.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.9.0) [Compare Source](https://github.com/ansible/ansible-lint/compare/v26.8.0...v26.9.0) #### Features - feat: support `example` section in file `meta/argument_specs.yml` ([#​5164](https://github.com/ansible/ansible-lint/issues/5164)) [@​berndfinger](https://github.com/berndfinger) #### Fixes - fix: resolve short mock modules during syntax check ([#​5149](https://github.com/ansible/ansible-lint/issues/5149)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: propagate `extra_vars` to `import_playbook` syntax check ([#​5148](https://github.com/ansible/ansible-lint/issues/5148)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: resolve nested `include_tasks` relative paths ([#​5159](https://github.com/ansible/ansible-lint/issues/5159)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: resolve `include_tasks` paths from playbook dir ([#​5184](https://github.com/ansible/ansible-lint/issues/5184)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: apply profile-level skip list during linting ([#​5151](https://github.com/ansible/ansible-lint/issues/5151)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: honor `warn_list` after `--fix` rewrites task names ([#​5085](https://github.com/ansible/ansible-lint/issues/5085)) [@​santosh7676](https://github.com/santosh7676) - fix: mock\_modules clobbering collections and args false positives ([#​5157](https://github.com/ansible/ansible-lint/issues/5157)) [@​djdanielsson](https://github.com/djdanielsson) - fix: inject plain-name mock roles path regardless of `--offline` ([#​5183](https://github.com/ansible/ansible-lint/issues/5183)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: warn users when directory expansion discovers new files ([#​5158](https://github.com/ansible/ansible-lint/issues/5158)) [@​rockygeekz](https://github.com/rockygeekz) - fix: skip auto-fix `no-jinja-when` on string-embedded jinja ([#​5103](https://github.com/ansible/ansible-lint/issues/5103)) [@​f1047](https://github.com/f1047) - fix: do not warn when Jinja block indent is only trim-marker noise ([#​5153](https://github.com/ansible/ansible-lint/issues/5153)) [@​DSeaStar](https://github.com/DSeaStar) - fix: preserve blank lines after flow collections ([#​5178](https://github.com/ansible/ansible-lint/issues/5178)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: add `validate_argspec` to play schema ([#​5187](https://github.com/ansible/ansible-lint/issues/5187)) [@​sameeralam3127](https://github.com/sameeralam3127) - fix: use ThreadPoolExecutor for syntax check workers ([#​5173](https://github.com/ansible/ansible-lint/issues/5173)) [@​rockygeekz](https://github.com/rockygeekz) - fix: drop ruamel.yaml.clib ([#​5163](https://github.com/ansible/ansible-lint/issues/5163)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix(deps): upgrade gitpython 3.1.57 to 3.1.59 ([#​5152](https://github.com/ansible/ansible-lint/issues/5152)) [@​rockygeekz](https://github.com/rockygeekz) - fix: upgrade black to >=25.2.0 to address CVE-2026-32274 ([#​5166](https://github.com/ansible/ansible-lint/issues/5166)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: raise cryptography floor and bump js-yaml for Guardian prod vulns ([#​5174](https://github.com/ansible/ansible-lint/issues/5174)) [@​rockygeekz](https://github.com/rockygeekz) #### Performance - perf: cache `get_deps_versions()` result ([#​5113](https://github.com/ansible/ansible-lint/issues/5113)) [@​BlackDark](https://github.com/BlackDark) #### Maintenance - chore: Add `.github/SECURITY.md` ([#​5165](https://github.com/ansible/ansible-lint/issues/5165)) [@​gundalow](https://github.com/gundalow) - chore(deps): update all dependencies and pep621 ([#​5138](https://github.com/ansible/ansible-lint/issues/5138), [#​5154](https://github.com/ansible/ansible-lint/issues/5154), [#​5155](https://github.com/ansible/ansible-lint/issues/5155), [#​5160](https://github.com/ansible/ansible-lint/issues/5160), [#​5161](https://github.com/ansible/ansible-lint/issues/5161), [#​5172](https://github.com/ansible/ansible-lint/issues/5172), [#​5175](https://github.com/ansible/ansible-lint/issues/5175), [#​5176](https://github.com/ansible/ansible-lint/issues/5176)) @​[renovate\[bot\]](https://github.com/apps/renovate) #### What's Changed - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5138](https://github.com/ansible/ansible-lint/pull/5138) - fix: resolve short mock modules during syntax check by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5149](https://github.com/ansible/ansible-lint/pull/5149) - fix(deps): upgrade gitpython 3.1.57 to 3.1.59 by [@​rockygeekz](https://github.com/rockygeekz) in [#​5152](https://github.com/ansible/ansible-lint/pull/5152) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5155](https://github.com/ansible/ansible-lint/pull/5155) - fix: propagate extra\_vars to import\_playbook syntax check by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5148](https://github.com/ansible/ansible-lint/pull/5148) - fix: warn users when directory expansion discovers new files by [@​rockygeekz](https://github.com/rockygeekz) in [#​5158](https://github.com/ansible/ansible-lint/pull/5158) - fix: resolve nested include\_tasks relative paths by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5159](https://github.com/ansible/ansible-lint/pull/5159) - fix: apply profile-level skip list during linting by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5151](https://github.com/ansible/ansible-lint/pull/5151) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5154](https://github.com/ansible/ansible-lint/pull/5154) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5160](https://github.com/ansible/ansible-lint/pull/5160) - fix: skip auto-fix no-jinja-when on string-embedded jinja by [@​f1047](https://github.com/f1047) in [#​5103](https://github.com/ansible/ansible-lint/pull/5103) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5161](https://github.com/ansible/ansible-lint/pull/5161) - fix: do not warn when Jinja block indent is only trim-marker noise by [@​DSeaStar](https://github.com/DSeaStar) in [#​5153](https://github.com/ansible/ansible-lint/pull/5153) - chore: Add .github/SECURITY.md by [@​gundalow](https://github.com/gundalow) in [#​5165](https://github.com/ansible/ansible-lint/pull/5165) - fix: upgrade black to >=25.2.0 to address CVE-2026-32274 by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5166](https://github.com/ansible/ansible-lint/pull/5166) - Fix/drop ruamel yaml clib fresh by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5163](https://github.com/ansible/ansible-lint/pull/5163) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5172](https://github.com/ansible/ansible-lint/pull/5172) - fix: honor warn\_list after --fix rewrites task names by [@​santosh7676](https://github.com/santosh7676) in [#​5085](https://github.com/ansible/ansible-lint/pull/5085) - feat: support 'example' section in file meta/argument\_specs.yml by [@​berndfinger](https://github.com/berndfinger) in [#​5164](https://github.com/ansible/ansible-lint/pull/5164) - fix: use ThreadPoolExecutor for syntax check workers by [@​rockygeekz](https://github.com/rockygeekz) in [#​5173](https://github.com/ansible/ansible-lint/pull/5173) - fix: mock\_modules clobbering collections and args false positives by [@​djdanielsson](https://github.com/djdanielsson) in [#​5157](https://github.com/ansible/ansible-lint/pull/5157) - fix: raise cryptography floor and bump js-yaml for Guardian prod vulns by [@​rockygeekz](https://github.com/rockygeekz) in [#​5174](https://github.com/ansible/ansible-lint/pull/5174) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5176](https://github.com/ansible/ansible-lint/pull/5176) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5175](https://github.com/ansible/ansible-lint/pull/5175) - fix: preserve blank lines after flow collections by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5178](https://github.com/ansible/ansible-lint/pull/5178) - perf: cache get\_deps\_versions() result by [@​BlackDark](https://github.com/BlackDark) in [#​5113](https://github.com/ansible/ansible-lint/pull/5113) - fix: inject plain-name mock roles path regardless of --offline by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5183](https://github.com/ansible/ansible-lint/pull/5183) - fix: resolve include\_tasks paths from playbook dir by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5184](https://github.com/ansible/ansible-lint/pull/5184) - fix: add validate\_argspec to play schema by [@​sameeralam3127](https://github.com/sameeralam3127) in [#​5187](https://github.com/ansible/ansible-lint/pull/5187) #### New Contributors - [@​shvenkat-rh](https://github.com/shvenkat-rh) made their first contribution in [#​5149](https://github.com/ansible/ansible-lint/pull/5149) - [@​f1047](https://github.com/f1047) made their first contribution in [#​5103](https://github.com/ansible/ansible-lint/pull/5103) - [@​DSeaStar](https://github.com/DSeaStar) made their first contribution in [#​5153](https://github.com/ansible/ansible-lint/pull/5153) - [@​berndfinger](https://github.com/berndfinger) made their first contribution in [#​5164](https://github.com/ansible/ansible-lint/pull/5164) - [@​BlackDark](https://github.com/BlackDark) made their first contribution in [#​5113](https://github.com/ansible/ansible-lint/pull/5113) - [@​sameeralam3127](https://github.com/sameeralam3127) made their first contribution in [#​5187](https://github.com/ansible/ansible-lint/pull/5187) **Full Changelog**: <https://github.com/ansible/ansible-lint/compare/v26.8.0...v26.9.0> ### [`v26.8.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.8.0) [Compare Source](https://github.com/ansible/ansible-lint/compare/v26.6.0...v26.8.0) #### What's Changed - Fix/sonarcloud unbounded recursion complexity by [@​sathyapramod](https://github.com/sathyapramod) in [#​5098](https://github.com/ansible/ansible-lint/pull/5098) - feat: honor ANSIBLE\_VAULT\_PASSWORD\_FILE for vault decryption by [@​JohnLahr](https://github.com/JohnLahr) in [#​5019](https://github.com/ansible/ansible-lint/pull/5019) - fix: jinja\[spacing] rule creating invalid syntax for minus modifiers by [@​Dotify71](https://github.com/Dotify71) in [#​5102](https://github.com/ansible/ansible-lint/pull/5102) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5081](https://github.com/ansible/ansible-lint/pull/5081) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5082](https://github.com/ansible/ansible-lint/pull/5082) - fix: remove stale words from cspell dictionary by [@​rockygeekz](https://github.com/rockygeekz) in [#​5109](https://github.com/ansible/ansible-lint/pull/5109) - chore(deps): bump schemas npm packages for Dependabot CVEs by [@​sudhirverma](https://github.com/sudhirverma) in [#​5114](https://github.com/ansible/ansible-lint/pull/5114) - fix(security): update dependencies \[SECURITY] by [@​renovate](https://github.com/renovate)\[bot] in [#​5111](https://github.com/ansible/ansible-lint/pull/5111) - fix: address SonarCloud new code violations by [@​sudhirverma](https://github.com/sudhirverma) in [#​5116](https://github.com/ansible/ansible-lint/pull/5116) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5121](https://github.com/ansible/ansible-lint/pull/5121) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5122](https://github.com/ansible/ansible-lint/pull/5122) - fix(deps): exclude ansible-core 2.17.x (CVE-2026-11332) by [@​rockygeekz](https://github.com/rockygeekz) in [#​5123](https://github.com/ansible/ansible-lint/pull/5123) - fix: expose ansible-galaxy on the uv tool-install path by [@​jeffcpullen](https://github.com/jeffcpullen) in [#​5124](https://github.com/ansible/ansible-lint/pull/5124) - fix: var-naming for register projections by [@​0xTaoZ](https://github.com/0xTaoZ) in [#​5110](https://github.com/ansible/ansible-lint/pull/5110) - chore: Adding OpenWrt 25.12 as platform by [@​sscheib](https://github.com/sscheib) in [#​5132](https://github.com/ansible/ansible-lint/pull/5132) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5134](https://github.com/ansible/ansible-lint/pull/5134) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5133](https://github.com/ansible/ansible-lint/pull/5133) - fix: add timeout to release-check urlopen() call by [@​cooperlees](https://github.com/cooperlees) in [#​5128](https://github.com/ansible/ansible-lint/pull/5128) - fix: respect ANSIBLE\_HOME env var for cache dir selection ([#​5806](https://github.com/ansible/ansible-lint/issues/5806)) by [@​Jkhall81](https://github.com/Jkhall81) in [#​5105](https://github.com/ansible/ansible-lint/pull/5105) - fix: deduplicate ANSIBLE\_HOME isolation check by [@​rockygeekz](https://github.com/rockygeekz) in [#​5140](https://github.com/ansible/ansible-lint/pull/5140) - fix(security): update dependencies \[SECURITY] by [@​renovate](https://github.com/renovate)\[bot] in [#​5141](https://github.com/ansible/ansible-lint/pull/5141) - fix: do not require role prefix for ansible\_ connection variables by [@​Sanjays2402](https://github.com/Sanjays2402) in [#​5130](https://github.com/ansible/ansible-lint/pull/5130) - Adding missing FreeBSD versions. by [@​jmpalacios](https://github.com/jmpalacios) in [#​5143](https://github.com/ansible/ansible-lint/pull/5143) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5139](https://github.com/ansible/ansible-lint/pull/5139) - fix: prepend runtime cache dir to collections paths ([#​5137](https://github.com/ansible/ansible-lint/issues/5137)) by [@​rockygeekz](https://github.com/rockygeekz) in [#​5145](https://github.com/ansible/ansible-lint/pull/5145) #### New Contributors - [@​sathyapramod](https://github.com/sathyapramod) made their first contribution in [#​5098](https://github.com/ansible/ansible-lint/pull/5098) - [@​JohnLahr](https://github.com/JohnLahr) made their first contribution in [#​5019](https://github.com/ansible/ansible-lint/pull/5019) - [@​jeffcpullen](https://github.com/jeffcpullen) made their first contribution in [#​5124](https://github.com/ansible/ansible-lint/pull/5124) - [@​0xTaoZ](https://github.com/0xTaoZ) made their first contribution in [#​5110](https://github.com/ansible/ansible-lint/pull/5110) - [@​cooperlees](https://github.com/cooperlees) made their first contribution in [#​5128](https://github.com/ansible/ansible-lint/pull/5128) - [@​Sanjays2402](https://github.com/Sanjays2402) made their first contribution in [#​5130](https://github.com/ansible/ansible-lint/pull/5130) - [@​jmpalacios](https://github.com/jmpalacios) made their first contribution in [#​5143](https://github.com/ansible/ansible-lint/pull/5143) **Full Changelog**: <https://github.com/ansible/ansible-lint/compare/v26.6.0...v26.8.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuNyIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> --------- Co-authored-by: Renovate Bot <bot@renovateapp.com> Reviewed-on: https://git.ivanch.me/ivanch/haven/pulls/17
Haven
A forever-work-in-progress self-hosted server setup
Runs on a multi-node k3s cluster deployed across VMs and bare-metal hosts.
Application configuration is stored on an NFS share located on a dedicated SSD. This uses nfs-subdir-external-provisioner as a dynamic storage provisioner with PVC-specific paths. Additional data is stored on a NAS exported via NFS.
The cluster runs k3s with nginx as the ingress controller. MetalLB is used in layer 2 mode for load balancing. cert-manager provides a local CA and issues certificates (required by Vaultwarden).
For setup details, see SETUP.md.
The repository name references my local TLD, .haven ;)
Repository Layout
haven/
├── bootstrap/
│ ├── namespaces.yaml # cluster namespaces
│ ├── secretstores.yaml # cluster secret stores for BitWarden ESO
│ ├── address-pool.yaml # cluster IP pool for MetalLB
│ ├── argocd-install/ # Argo CD install manifests + ingress
│ └── root-app.yaml # root Application watching apps/root
├── secrets/
│ ├── adguard.yaml # adguard credentials from BitWarden
│ ├── <app>.yaml # <app> credentials from BitWarden
│ └── ...
├── apps/
│ ├── root/
│ │ ├── kustomization.yaml # points to applicationset.yaml
│ │ └── applicationset.yaml# auto-discovers apps/*/*.yaml
│ └── <namespace>/ # e.g., dev/, default/, infra/, monitoring/
│ ├── <app-1>.yaml # all-in-one manifest per app
│ ├── <app-2>.yaml # ...
| └──── ...
Languages
Markdown
100%