diff --git a/roles/service/meta/argument_specs.yaml b/roles/service/meta/argument_specs.yaml index de9a857..b2938dd 100644 --- a/roles/service/meta/argument_specs.yaml +++ b/roles/service/meta/argument_specs.yaml @@ -215,6 +215,14 @@ argument_specs: elements: str required: false default: [] + template_validate_command: + description: >- + Command used to verify templated file validity. + Will be run in a temporary container using the same container image as the main service. + File will be available in the same place as in the service container (destination). + Only applicable if mount type is template + type: str + required: false service_container_devices: description: List of devices to be added inside the service main container. type: list diff --git a/roles/service/tasks/host_mounts.yaml b/roles/service/tasks/host_mounts.yaml index 28d9bf8..653c7e9 100644 --- a/roles/service/tasks/host_mounts.yaml +++ b/roles/service/tasks/host_mounts.yaml @@ -23,8 +23,16 @@ src: "{{ item[0].source }}" dest: "{{ item[1] }}" mode: "{{ item[0].mode | default('0644') }}" + validate: "{{ validate if item[0].template_validate_command is defined else omit }}" notify: Restart container service {{ service_name }} loop: "{{ _service_all_template_mounts | zip(_service_all_template_mount_host_files) }}" + vars: + validate: >- + podman run --rm + -v %s:{{ item[0].destination }}:ro + --entrypoint {{ item[0].template_validate_command.split(' ', 1)[0] }} + {{ service_container_image }} + {{ item[0].template_validate_command.split(' ', 1)[1] }} - name: Copy files for copy mounts ansible.builtin.copy: diff --git a/roles/service/vars/main/additional.yaml b/roles/service/vars/main/additional.yaml index 4c1dd68..7db610f 100644 --- a/roles/service/vars/main/additional.yaml +++ b/roles/service/vars/main/additional.yaml @@ -177,7 +177,7 @@ _service_additional_container_template_mounts: >- ([{'readonly': true}] * _service_additional_template_mounts | length) | zip( _service_additional_template_mounts | - community.general.remove_keys(['mode']), + community.general.remove_keys(['mode', 'template_validate_command']), _service_additional_template_mounts | map(attribute='source') | map('regex_replace', '\.j2$', '') | diff --git a/roles/service/vars/main/mounts.yaml b/roles/service/vars/main/mounts.yaml index 71ff791..c87398b 100644 --- a/roles/service/vars/main/mounts.yaml +++ b/roles/service/vars/main/mounts.yaml @@ -30,7 +30,7 @@ _service_container_template_mounts: >- ([{'readonly': true}] * _service_template_mounts | length) | zip( _service_template_mounts | - community.general.remove_keys(['mode']), + community.general.remove_keys(['mode', 'template_validate_command']), _service_template_mounts | map(attribute='source') | map('regex_replace', '\.j2$', '') |