News

Enroll 0.9.0: better manifests for real hosts

This release makes the Ansible output more useful when you have several hosts, and more faithful to the services and packages on each one.

Build a project one host at a time

You can start with enroll manifest --harvest ./harvest-web1 --host web1 --out ./ansible, then add another host with --host web2 --out ./ansible --extend. Each host gets its own variables, capture notes and ordered play. Matching files stay in reusable roles; when a file differs, Enroll moves each host's version into inventory and keeps the role's tasks shared. Enroll checks the existing project before extending it and publishes the completed update atomically on supported Linux filesystems.

The old --fqdn option has been replaced by explicit --host and --extend. A plain manifest without --host still creates a standalone project in a new directory. For an existing encrypted project, unpack it before extending it.

Roles with the same tasks and handlers can now serve hosts with different captured files. When a role needs distinct tasks or handlers, its name includes the host so you can recognise it in the project. Grouped service roles share one handler driven by each host's inventory: a configuration change restarts the active services listed for that role on that host.

Services and packages belong together

A service may come from one package while its useful configuration belongs to a closely related package. Enroll now checks installed direct dependencies and source package identity on Debian/Ubuntu and RPM systems to associate those packages conservatively. It records its reasoning and leaves ambiguous matches alone. Separately captured items with similar names keep distinct roles.

Generated plays install prerequisites before configuration and defer service activation until deployment is complete. Changed symlinks and systemd units can trigger the appropriate service handlers. Drift reports now cover more managed resources and application inventories, including automatically installed packages.

Choose live runtime capture deliberately

Live firewall and sysctl capture now require --harvest-firewall and --harvest-sysctl. Enroll continues to collect persistent configuration under its normal rules. If you capture a live firewall and want the generated rules restored after reboot, you can opt in to firewall_runtime_persist in the resulting Ansible variables.

Safe-mode screening now checks Flatpak metadata and opted-in runtime output for credentials. Manifest output is staged before publication, and additional checks cover special files, role collisions and conflicting account identities.

Review a generated project and test its application on a suitable host before using it in production. Service lifecycle and firewall reboot behaviour depend on the target system.