Debian-based AWX execution environment with working ansible-runner
  • Shell 53.5%
  • Dockerfile 46.5%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-27 19:15:54 +00:00
.forgejo/workflows [work-4pp.1] Close beads after merged PRs 2026-09-26 23:55:46 +00:00
.gitea/workflows chore(deps): update renovate/renovate:44 docker digest to e262ed5 (#16) 2026-09-27 12:13:29 +00:00
scripts Pin image digests and add Renovate for dependency updates 2026-09-19 14:34:25 +02:00
tests [work-2ad] Add Fractal collections to execution environment (#19) 2026-09-27 19:15:54 +00:00
.dockerignore Pin image digests and add Renovate for dependency updates 2026-09-19 14:34:25 +02:00
.gitignore Build the execution environment from a Containerfile instead of ansible-builder 2026-09-19 13:40:33 +02:00
Containerfile chore(deps): update quay.io/ansible/receptor:devel docker digest to 2f23bc7 (#14) 2026-09-24 06:29:57 +00:00
entrypoint Build the execution environment from a Containerfile instead of ansible-builder 2026-09-19 13:40:33 +02:00
README.md [work-2ad] Add Fractal collections to execution environment (#19) 2026-09-27 19:15:54 +00:00
renovate.json5 Pin image digests and add Renovate for dependency updates 2026-09-19 14:34:25 +02:00
requirements.txt [work-4r0] feat(ee): add community.hashi_vault and hvac for OpenBao reads (#18) 2026-09-27 19:09:37 +00:00
requirements.yml [work-2ad] Add Fractal collections to execution environment (#19) 2026-09-27 19:15:54 +00:00

awx-debian-ee

AWX execution environment built on Debian 13 (trixie) with a working ansible-runner.

Built directly from a Containerfile instead of ansible-builder, which only supports RPM base images.

Why not ansible-builder

ansible-builder assumes an RPM image. On Debian it needs several workarounds:

  • ensurepip is disabled for the system python.
  • It defaults to dnf as the package manager.
  • Its bindep/assemble steps call dnf clean.

A plain multi-stage Containerfile avoids all of that.

Build

podman build -t awx-debian-ee:test .

Test

tests/smoke-test.sh

The smoke test builds the image and runs tests/playbook.yml through ansible-runner.

Contents

  • ansible-core 2.20, ansible 13
  • ansible-runner 2.4
  • collections: awx.awx, ansible.posix, community.general, ansible.utils, community.hashi_vault, community.crypto, containers.podman, nginxinc.nginx_core
  • receptor + receptorctl
  • kerberos, winrm, psrp and network python deps
  • podman-remote, git, ssh, sshpass, rsync, git-lfs
  • hvac (Python client required by community.hashi_vault, for Vault/OpenBao)

Design

  • Multi-stage: python deps build in a build stage and are copied into the runtime stage, so compilers and headers stay out of the final image.
  • Runtime deps are installed in a venv at /opt/venv.
  • Runs as uid 1000 with gid 0. entrypoint adds an /etc/passwd entry for ephemeral UIDs and ensures /runner is writable.

CI

.gitea/workflows/build.yml builds and pushes :13, :13-latest and :13-<calver> tags, then runs the smoke test against the pushed image.

Builds use BuildKit cache mounts for apt and pip, so package downloads are reused between rebuilds without being stored in a layer.

Dependency updates

Image references are pinned by digest in the Containerfile:

  • the Debian base image in ARG BASE_IMAGE
  • receptor in the COPY --from=...

Renovate refreshes those digests (and the Python requirements) and opens PRs. Config lives in renovate.json5; .gitea/workflows/renovate.yaml runs it nightly on the shared global runner.

Required Actions secrets:

  • RENOVATE_TOKEN - renovate-bot's Forgejo token
  • RENOVATE_GITHUB_COM_TOKEN - GitHub read-only PAT, for actions/* lookups

Set them with the bootstrap scripts:

scripts/set-renovate-secret.sh
scripts/set-renovate-github-token.sh

A Debian major bump is deliberately not proposed; update the allowedVersions rule in renovate.json5 when moving to the next release.