fix(ansible): install Herdr's omp state integration on every apply - #32
Merged
Merged
Conversation
added 2 commits
October 1, 2026 22:51
Without herdr-omp-agent-state.ts Herdr shows every omp agent as idle. herdr.yml now runs `herdr integration install omp` with the managed herdr (agents profile), reporting changed only when the file's checksum changed; verify.yml asserts `herdr integration status` reports `omp: current`. Docs drop the manual host-move step.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
dot not updating its tatus despite secondmate working
Context: the dot is the state icon on each entry of the Herdr sidebar on the fleet host. Every dot stayed hollow (idle) while a second mate was visibly working. Cause, measured:
herdr integration statusreportedomp: not installed (~/.omp/agent/extensions/herdr-omp-agent-state.ts), andherdr agent explain <pane>for an omp pane reportedmanifest: none,fallback_reason: default_known_agent_idle_fallback. So Herdr had no state reporting from omp and showed every omp agent as idle. Runningherdr integration install ompinstalled the extension (status thenomp: current (v10)). Code-Factory's docs/agent-host-move.md names that command as a manual host-move step, but no Code-Factory apply runs it, so every host built or moved with Code-Factory comes up with idle-forever dots. Generic host setup on this host must be reproduced by Code-Factory on every run.im using herdr --remote, so i need to update my macbooks herdr too
What Changed
ansible/tasks/herdr.ymlandansible/group_vars/all.yml: with theagentsprofile on, apply now creates the omp extensions directory and runsherdr integration install omp. This installsherdr-omp-agent-state.ts, so Herdr gets pane state from omp instead of showing every omp agent as idle. Apply reports a change only when the file's checksum changes, and the install is skipped in check mode.ansible/tasks/verify.yml: verification now readsherdr integration statusand fails unless it reportsomp: current.docs/herdr.mdanddocs/agent-host-move.md: added a "Pane state" section. The host-move step no longer tells you to run the install by hand and now excludesherdr-omp-agent-state.tsfrom the omp extensions rsync. For machines that view a host withherdr --remote, the docs say to runherdr updateand compareherdr --versionwith the host's.Risk Assessment
herdr integration install ompon every apply and the docs match, but the new verify task can fail spuriously when the connecting user is not the target account.Testing
I drove the changed Ansible tasks with real ansible-core and the real
herdragainst disposable homes. Fresh install, idempotent re-run, stale-file refresh, profile-off skip, and the verify assert failing when the integration is missing all behaved as intended. The playbook ran as a non-root user withbecomedisabled, so the missingbecomeon the verify status task (review round 2, declined) was not exercised. The transcript is saved as evidence and the temp dirs were removed. The docs scenario is untested because it is documentation only and was verified by reading, not by a live run. I did not exercise theherdr --remoteviewer-side update, which is documentation only.omp: currentomp: current (v10)omp: outdatedbefore, changed=1 thenomp: current (v10)omp: not installedherdr --remoteviewer version noteEvidence: Ansible run transcript for all five scenarios
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
docs/herdr.md:126- The intent's second sentence says "im using herdr --remote, so i need to update my macbooks herdr too". The change covers only host-side provisioning: apply now installs the omp extension, and verify assertsomp: current. Nothing handles or documents the viewing machine. docs/herdr.md has no step for updating or checking the client Herdr, and no stated requirement about client/host version compatibility for pane state underherdr --remote. The extension runs on the host, so the macbook may need nothing beyond a Herdr update, but the change does not say so. This may be a manual step for the user rather than repo work. Decision needed: is a docs note or client-version check expected, or is the macbook update out of scope for this change?🔧 Fix applied.
1 warning still open:
ansible/tasks/verify.yml:229-Read the Herdr integration statusis the only new command that does not run as the target account. It has nobecome,become_userorenvironment: factory_user_env. The verify tasks that read the target account's state usebecome: "{{ factory_become_target | bool }}",become_user: "{{ factory_cfg.user }}"andfactory_user_env, for example verify.yml:319-321 and 345-347. Verify runs inpost_taskswith the play defaultbecome: false, unlike the install task in herdr.yml, which inherits the import-level become andHOMEfrom site.yml. Concrete failure: when Ansible connects as an account other thanfactory_cfg.user,factory_become_targetis true. The install task then writes~<factory user>/.omp/agent/extensions/herdr-omp-agent-state.ts. The status check runs under the connecting user'sHOMEand reportsomp: not installed, so the new assert fails on a correctly provisioned host. If the connecting user can run herdr and has no omp extension, the failure is spurious. The fix is to add the same three keys that the verify.yml:319-321 tasks use.✅ **Test** - passed
✅ No issues found.
omp: currentomp: current (v10)omp: outdatedbefore, changed=1 thenomp: current (v10)omp: not installedherdr --remoteviewer version noteRan the changed 'Install Herdr's omp state integration' block and the two new verify tasks through real ansible-core (via uvx) with the realherdr, in throwaway HOMEs under /tmp, using a throwaway playbook.Fresh home with no ~/.omp dir: the directory is created, the extension is installed, status reportsomp: current (v10), and the verify assert passes (changed=2).Second apply on the same home: changed=0, so it is idempotent.Stale extension file (statusomp: outdated): apply rewrites it, reports one change, and status returns toomp: current.agentsprofile off: all six tasks are skipped and the home stays empty.Integration file removed, then verify run alone: the assert fails with the 'shows every omp agent as idle' message andomp: not installed.Read docs/herdr.md and docs/agent-host-move.md to confirm the Pane state section and theherdr --remoteviewer note are present, and that the host-move row no longer asks for a manualherdr integration install omp. This was reading only, not a live run.Read ansible/tasks/verify.yml to confirm verification is skipped in check mode, so a plan run on a fresh host cannot fail the new assert. This was reading only.✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.