4 Commits

Author SHA1 Message Date
8cd3f13dac fix: nopasswdlogin-PAM-Zeile nicht duplizieren (Debian-Familie)
lineinfile matchte bisher nur exakten Text - Debian/LightDM liefert eine
Zeile mit identischer Wirkung, aber anderer Formatierung mit, wurde also
nicht erkannt und stattdessen dupliziert. regexp behebt das für den
present-Task; der absent-Task bleibt bewusst beim exakten String-Match,
damit er nie die von der Distribution mitgelieferte Zeile entfernt.

Gefunden bei der E2E-Verifikation auf der QEMU-Test-VM.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 15:48:52 +02:00
770c3a6c95 feat: echte Rolleninhalte für guest-session/brave-fedora/onlyoffice-fedora
Ersetzt die reinen Marker-Datei-Platzhalter durch echte Anforderungen des
Schulcomputer-Workspace:

- guest-session: flüchtige Gastsitzung über lokalen gast-User +
  pam_namespace-tmpfs-Polyinstantiation, nopasswdlogin-Login. PAM-Layout
  wird über ansible_facts os_family erkannt (RedHat vs. Debian), da der
  Rollenname für beide Backends geteilt wird.
- brave-fedora: Installation via Flatpak/Flathub, neue optionale
  standardbrowser-Option (tuxflotte_optionen) setzt/entfernt den
  System-Default in /etc/xdg/mimeapps.list, mit Firefox-Fallback.
- onlyoffice-fedora: Installation via Flatpak/Flathub.

site.yml reicht zusätzlich zu tuxflotte_auftrag_states auch
tuxflotte_auftrag_optionen pro Rolle durch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 15:28:57 +02:00
28e6c067a1 feat: add present/absent branching for Auftragskatalog roles
Adds a tuxflotte_state variable, threaded from a new
tuxflotte_auftrag_states dict in site.yml (role name -> present/absent,
populated by the agent from the checkin response's "auftraege" list,
see ADR-0010) down into each role via include_role vars. Roles not
present in that dict default to "present" via .get(), so today's
purely workspace-composed, additive-only behavior is unchanged.

Retrofits all three existing placeholder roles with the present/absent
branch as the reference implementation of the convention, and
documents it in the README for future catalog-eligible roles. This is
what makes deselecting an Auftrag actually revert something instead of
just stopping future re-application.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 09:34:05 +02:00
a998949081 feat: initial ansible-content repo with placeholder roles for agent verification
Ein Platzhalter je Merkmal aus der Schulcomputer-Bereitstellungsvorlage (guest-session, brave-fedora, onlyoffice-fedora), zum Beweis der ansible-pull-Pipeline des Provisioning Agent.
2026-08-01 15:35:21 +02:00