- Shell 53.5%
- Dockerfile 46.5%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| .forgejo/workflows | ||
| .gitea/workflows | ||
| scripts | ||
| tests | ||
| .dockerignore | ||
| .gitignore | ||
| Containerfile | ||
| entrypoint | ||
| README.md | ||
| renovate.json5 | ||
| requirements.txt | ||
| requirements.yml | ||
awx-debian-ee
AWX execution environment built on Debian 13 (trixie) with a working ansible-runner.
Built directly from a Containerfile instead of ansible-builder, which only supports RPM base images.
Why not ansible-builder
ansible-builder assumes an RPM image. On Debian it needs several workarounds:
ensurepipis disabled for the system python.- It defaults to
dnfas the package manager. - Its bindep/assemble steps call
dnf clean.
A plain multi-stage Containerfile avoids all of that.
Build
podman build -t awx-debian-ee:test .
Test
tests/smoke-test.sh
The smoke test builds the image and runs tests/playbook.yml through ansible-runner.
Contents
- ansible-core 2.20, ansible 13
- ansible-runner 2.4
- collections: awx.awx, ansible.posix, community.general, ansible.utils, community.hashi_vault, community.crypto, containers.podman, nginxinc.nginx_core
- receptor + receptorctl
- kerberos, winrm, psrp and network python deps
- podman-remote, git, ssh, sshpass, rsync, git-lfs
hvac(Python client required bycommunity.hashi_vault, for Vault/OpenBao)
Design
- Multi-stage: python deps build in a
buildstage and are copied into the runtime stage, so compilers and headers stay out of the final image. - Runtime deps are installed in a venv at
/opt/venv. - Runs as uid 1000 with gid 0.
entrypointadds an/etc/passwdentry for ephemeral UIDs and ensures/runneris writable.
CI
.gitea/workflows/build.yml builds and pushes :13, :13-latest and :13-<calver> tags,
then runs the smoke test against the pushed image.
Builds use BuildKit cache mounts for apt and pip, so package downloads are reused between rebuilds without being stored in a layer.
Dependency updates
Image references are pinned by digest in the Containerfile:
- the Debian base image in
ARG BASE_IMAGE receptorin theCOPY --from=...
Renovate refreshes those digests (and the Python requirements) and opens PRs.
Config lives in renovate.json5; .gitea/workflows/renovate.yaml runs it nightly
on the shared global runner.
Required Actions secrets:
RENOVATE_TOKEN- renovate-bot's Forgejo tokenRENOVATE_GITHUB_COM_TOKEN- GitHub read-only PAT, foractions/*lookups
Set them with the bootstrap scripts:
scripts/set-renovate-secret.sh
scripts/set-renovate-github-token.sh
A Debian major bump is deliberately not proposed; update the allowedVersions
rule in renovate.json5 when moving to the next release.