Skip to content

fix: add packer as its own opt-in role - #112

Merged
catinspace-au merged 2 commits into
mainfrom
fix/packer-role
Oct 6, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/packer-role

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Packer now has its own opt-in role. --tags packer installs it from HashiCorp's signed repo, and nothing else ever runs it.

  • The role is wired with tags: ['packer', 'never']. --tags all, every persona and --tags removals list zero packer tasks.
  • Ubuntu uses deb822 hashicorp.sources. Fedora uses a hashicorp yum repo with gpgcheck and repo_gpgcheck. macOS uses hashicorp/tap.
    • The key must be exactly D55C0D1AC78A8D8126CB631CFC9CA96ACA026560 (https://www.hashicorp.com/en/trust/security) before anything trusts it. A mismatch removes our repo, keeps the trusted key, and lands in the end-of-run report.
  • A host still trusting the superseded key 798A...E701, which signed the repos until 2026-09-10, heals on the next --tags packer run. A failed apt refresh drops the HashiCorp source, retries, then writes it back with the verified key.
  • --tags removals still removes terraform and vault. It removes HashiCorp's repo, keys and tap only when Packer is not installed. That fixes apt on hosts left with the old repo and no Packer, and keeps the repo where Packer needs it.

Tested in containers:

  • fresh installs on ubuntu:26.04, ubuntu:24.04, fedora:44 and fedora:43; Packer v1.16.1, and the second run changed=0;
  • an old-key host with stale apt lists heals;
  • a wrong fingerprint fails closed;
  • removals on a no-Packer orphan host takes apt from rc=100 to rc=0, while a Packer host keeps its repo.

Not run: macOS, and molecule itself (the scenarios were driven by hand). Also known: a host with Packer AND the old key still fails --tags removals at the terraform step until --tags packer runs.

Done when --tags packer gives a working Packer from a verified repo and no default run ever touches HashiCorp.

Packer is the one HashiCorp tool we install: it is BUSL with no open-source fork, and image builds need it. It gets its own role, run only by --tags packer and pulled in by no persona, so a default or persona run installs nothing from HashiCorp.

Ubuntu and Fedora take HashiCorp's repo. The signing key is staged, checked for exactly one primary key matching the fingerprint HashiCorp publishes (D55C0D1A...CA026560), and only then trusted. A mismatch removes the repo, keeps the previously trusted key and lands in the end-of-run warnings. A host still trusting the expired 798A...E701 key gets the new one, and the legacy hashicorp.list is removed so apt does not see the repo twice. macOS takes hashicorp/tap.

--tags removals now takes terraform and vault only. It used to delete the HashiCorp repo, keyrings and tap as well, which broke Packer on every host it ran on. The remediation scenario asserts the repo and keys survive.
A host still trusting the superseded HashiCorp key fails every apt refresh, so the packer role could not get as far as replacing the key. The prerequisite install now drops the HashiCorp sources and retries when that refresh fails, and the repo is written back with the verified key further down.

--tags removals unhooks the HashiCorp repo, its key and the tap again, but only where Packer is not installed. It runs before the terraform and vault removal, because that removal refreshes the apt cache too. The remediation scenario checks both branches, with a stand-in packer package on one host.

Fedora now also checks the signature on HashiCorp's repo metadata. The molecule matrix converges packer on all four releases.
@catinspace-au
catinspace-au merged commit 38f3646 into main Oct 6, 2026
18 checks passed
@catinspace-au
catinspace-au deleted the fix/packer-role branch October 6, 2026 23:17
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant