Skip to content

feat: Add the Red Hat Ansible certification checker workflow and update collection - #12

Open
aknot242 wants to merge 6 commits into
mainfrom
certification-checker
Open

aknot242 wants to merge 6 commits into
mainfrom
certification-checker

Conversation

@aknot242

@aknot242 aknot242 commented Aug 12, 2026 •

Copy link
Copy Markdown
Collaborator

Proposed changes

Add Red Hat's reusable GitHub Actions to check whether an Ansible collection is ready for certification on Red Hat Ansible Automation Hub.

What it checks
The certification checker runs the same types of checks used during the Automation Hub import process, including:

Galaxy importer checks
Ansible Lint checks
Ansible sanity tests

Update the collection to the latest version in preparation for release.

Checklist

Before creating a PR, run through this checklist and mark each as complete.

@aknot242 aknot242 self-assigned this Aug 14, 2026
@aknot242 aknot242 changed the title Feat: Add the Red Hat Ansible certification checker workflow Feat: Add the Red Hat Ansible certification checker workflow and update collection Aug 14, 2026
@alessfg
alessfg requested a balanced review from Copilot August 14, 2026 20:18
@alessfg alessfg added the enhancement New feature or request label Aug 14, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds Red Hat certification checks and prepares collection metadata and documentation for release 0.9.0.

Changes:

  • Adds certification, lint, and Dependabot configuration.
  • Raises dependency and Ansible requirements.
  • Updates playbooks to fully qualified role names.

Reviewed changes

Copilot reviewed 14 out of 14 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
.ansible-lint Configures production linting exclusions.
.github/SECURITY.md Normalizes apostrophes.
.github/dependabot.yml Enables weekly action updates.
.github/workflows/certification.yml Adds certification checks.
README.md Updates release and dependency guidance.
galaxy.yml Bumps version and dependencies.
meta/runtime.yml Raises the Ansible minimum.
playbooks/deploy-nginx.yml Uses a fully qualified role name.
playbooks/deploy-nginx-web-server.yml Qualifies included roles.
playbooks/deploy-nginx-web-server-proxy.yml Qualifies included roles.
playbooks/deploy-nginx-plus.yml Qualifies the NGINX role.
playbooks/deploy-nginx-plus-app-protect.yml Qualifies included roles.
playbooks/deploy-nginx-plus-app-protect-web-server-proxy.yml Qualifies included roles.
playbooks/deploy-nginx-app-protect.yml Qualifies the App Protect role.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread README.md
Comment on lines +18 to +20
| [nginxinc.nginx](https://github.com/nginxinc/ansible-role-nginx) | Install NGINX | 0.26.0 |
| [nginxinc.nginx_config](https://github.com/nginxinc/ansible-role-nginx-config) | Configure NGINX | 0.7.1 |
| [nginxinc.nginx_app_protect](https://github.com/nginxinc/ansible-role-nginx-app-protect) | Install and configure NGINX App Protect | 0.10.0 |
# for each affected version of ansible-core (for example, `tests/sanity/ignore-2.18.txt`) and add corresponding entries.
jobs:
call:
uses: ansible-collections/partner-certification-checker/.github/workflows/certification-reusable.yml@v4.0.0
Comment thread README.md Outdated
Comment thread galaxy.yml
@@ -0,0 +1,50 @@
---
# This workflow calls a pinned version of the

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lets add a comment up top here saying that this got workflow was copied from the certification repo per the quickstart https://github.com/nginxinc/ansible-collection-nginx/pull/12/changes#diff-d519a9b910e45c00725de9beec3fbc97be24eaf1586c66943a17b7908b115f1cR22-R24

# for each affected version of ansible-core (for example, `tests/sanity/ignore-2.18.txt`) and add corresponding entries.
jobs:
call:
uses: ansible-collections/partner-certification-checker/.github/workflows/certification-reusable.yml@v4.0.0

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should use a SHA. Related conversation here ansible-collections/partner-certification-checker#65 but version tags vs SHAs are simply not great from a security perspective even if the user experience is better

Comment thread .github/dependabot.yml
Comment thread playbooks/deploy-nginx-app-protect.yml
@alessfg alessfg changed the title Feat: Add the Red Hat Ansible certification checker workflow and update collection feat: Add the Red Hat Ansible certification checker workflow and update collection Aug 14, 2026
@github-project-automation github-project-automation Bot moved this from In progress to Review in progress in NGINX Ansible roles & collection Aug 14, 2026
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: aknot242 <4582399+aknot242@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

Status: Review in progress

Development

Successfully merging this pull request may close these issues.

4 participants