# SPDX-FileCopyrightText: 2026 Slavi Pantaleev # # SPDX-License-Identifier: AGPL-3.0-or-later --- dependency: name: galaxy options: requirements-file: requirements.yml force: true driver: name: docker platforms: - name: hookshot-${MOLECULE_DISTRO:-ubuntu2604}-default image: "geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2604}-ansible:latest" command: ${MOLECULE_DOCKER_COMMAND:-""} volumes: - /sys/fs/cgroup:/sys/fs/cgroup:rw cgroupns_mode: host privileged: true pre_build_image: true provisioner: name: ansible config_options: defaults: callback_result_format: yaml inventory: group_vars: all: matrix_bridge_hookshot_container_network: hookshot-molecule # The stub prepare.yml stands up. Not a real homeserver, and nothing is asserted # about it. matrix_bridge_hookshot_homeserver_address: http://matrix.molecule.local:8008 # Here these only have to reach the rendered configuration and the registration. matrix_bridge_hookshot_appservice_token: molecule_as_token_4f2a91 matrix_bridge_hookshot_homeserver_token: molecule_hs_token_9b3e77 # Different from the role's default, so the registration's sender_localpart can only # have come from the role. prepare.yml tells the stub to claim this same user id. matrix_bridge_hookshot_bot_localpart: molecule-hookshot # Hookshot's HTTP surface is the point of this scenario. Every port below differs # from BOTH the role's default and Hookshot's own, so an answer can only mean the # role's configuration reached the process. verify.yml also asserts nothing answers # on the defaults these replace. matrix_bridge_hookshot_appservice_port: 9772 matrix_bridge_hookshot_webhook_port: 9741 # Off in the role's defaults. Enabling it renders a second entry in the `listeners` # list, and /metrics is the cheapest listener to assert *content* on. matrix_bridge_hookshot_metrics_enabled: true matrix_bridge_hookshot_metrics_port: 9752 # On in the role's defaults. Off here so the absence of a listener can be asserted: # the widgets port staying closed is what tells "the role rendered the listener list" # apart from "Hookshot binds everything anyway". matrix_bridge_hookshot_widgets_enabled: false # No third-party service is configured here; see the header of verify.yml. # GitLab is the one the role enables by default, so it is explicitly switched off. matrix_bridge_hookshot_gitlab_enabled: false # The generic webhooks listener needs no account anywhere, so it is what this # scenario exercises live. The prefix differs from the role's default. matrix_bridge_hookshot_generic_userIdPrefix: _molecule_hook_ # noqa var-naming # Neither the role's default (600) nor Hookshot's own (600). matrix_bridge_hookshot_feeds_pollIntervalSeconds: 907 # noqa var-naming # The role defaults to `warn`, Hookshot itself to `info`. A third value, so finding # it in config.yml cannot be a coincidence. matrix_bridge_hookshot_logging_level: debug # Traefik is not deployed here, so the labels the role would render for it are # switched off and their absence is asserted instead. matrix_bridge_hookshot_container_labels_traefik_enabled: false # verify.yml runs as its own play, where role defaults are out of scope, so what it # reads is pinned here. These two match the role's own defaults on purpose: they name # things rather than configure them, and nothing is asserted *about* them. matrix_bridge_hookshot_base_path: /matrix/hookshot matrix_bridge_hookshot_identifier: matrix-hookshot env: # Workaround for https://github.com/ansible/molecule/issues/4391 ANSIBLE_ROLES_PATH: ${MOLECULE_PROJECT_DIRECTORY}/../..:/.ansible/roles:/usr/share/ansible/roles:/etc/ansible/roles:${ANSIBLE_HOME:-~/.ansible}/roles scenario: test_sequence: - dependency - cleanup - destroy - syntax - create - prepare - converge - idempotence - verify - cleanup - destroy verifier: name: ansible