Development
Commands for working on this repo's own code, as opposed to deploying with it (see README.md for that).
Install
uv sync --all-extras --all-packages --no-progress
uv --offline run --no-sync --no-progress ansible-galaxy install -r requirements.yml
Syntax check
Validates the playbook without touching a host:
uv --offline run --no-sync --no-progress ansible-playbook playbook.yml -l <host> --syntax-check
Git hooks
The pre-commit hook runs gitleaks (must be installed and
on PATH) to scan for secrets. Enable it once per clone:
chmod +x .git-hooks/*
git config --local core.hooksPath .git-hooks
Lint
Mirrors the jobs in .gitea/workflows/lint.yml:
uv --offline run --no-sync --no-progress ansible-lint
uv --offline run --no-sync --no-progress mypy --verbose ./
uv --offline run --no-sync --no-progress pylint --verbose ./
uv --offline run --no-sync --no-progress isort --check-only --verbose ./
uv --offline run --no-sync --no-progress black --check --verbose ./
uv --offline run --no-sync --no-progress ruff check --verbose ./
uv --offline run --no-sync --no-progress pyright --verbose
uv --offline run --no-sync --no-progress yamllint --strict ./
prettier --check .
Tests
Live integration tests for the secrets client under src/, run against the vault_client_pytest bucket (requires VAULT_* environment variables):
uv --offline run --no-sync --no-progress pytest