playbook-configuration
Installation
SKILL.md
Playbook Configuration
Use this skill to keep generated and edited playbooks aligned with the repo's registry, inventory, and k3s access model.
Required Shape
- Keep the metadata header at the top of every checked-in playbook:
name,description,target,requires_approval, andtags. - Use
target: controlfor control-node-only work,target: clusterfor worker-node-only work, andtarget: bothwhen a playbook touches both groups. - Set
requires_approval: truefor any playbook that usesbecome, changes host or cluster state, installs packages, restarts services, writes files, or depends on external credentials. - Keep play YAML top-down: first inspect or validate the current goal state, then remediate only when needed, then validate the final state.
- Do not add internal approval variables or assertions such as
*_approve; the registry metadata andansible_run_playbookown execution approval.
Inventory Targets
- The
controlgroup is the local control node and usesansible_connection=local. - The
clustergroup is Raspberry Pi worker nodes reached over SSH aspi. - Prefer control-node plays for
kubectl, Helm, k3s server validation, kubeconfig repair, observability control-plane services, and cluster API checks. - Use cluster plays only when the requested state belongs on the worker hosts, such as node prerequisites, boot/cgroup configuration, or k3s agent state.