gator, A Gatekeeper Policy Evaluated With No Cluster

gator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a ConstraintTemplate, a constraint requiring an owner label and two namespaces, and has gator test report the violation (exit 1) and pass the labelled one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

ansibleCloud Tooling

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-21 · podman 4.9.3 · ansible 2.21.4 · how we verify

Documentation

gator

OPA Gatekeeper gator on EL 10 from the vendor's release, checked against the published SHA-256, pinned to a version, installed as root's binary in /usr/local/bin. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No package worth the name. EL 10 carries no gator, and a third-party repository is one more key to trust. This role takes the release from open-policy-agent.github.io/gatekeeper, has Ansible's get_url refuse the asset unless its SHA-256 is the published one, and the live test checks the asset on disk against the same published value again.

Pinned. gator_version is what gets installed, kept in a directory of its own so the checksum file and the asset it names stay together. A newer release is a variable change and a run; the same version is changed=0.

Proven to run. The live test runs gator test -f /tmp/gator-p/template.yaml -f /tmp/gator-p/constraint.yaml -f /tmp/gator-p/ns.yaml and expects "you must provide labels" - the binary ran all the way to the point where it needed something this host does not have.

A Gatekeeper policy evaluated with no cluster. The live test writes a ConstraintTemplate (Rego that requires labels), a constraint that requires owner on namespaces, and two namespaces; gator test reports the violation for the unlabelled one with exit code 1 and passes the labelled one with exit code 0. This is the same policy engine the Gatekeeper admission controller runs, exercised in CI before a policy reaches a cluster. The vendor's sha256sums.txt names assets with a ./ prefix, which get_url strips.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-argocd-cli

The argocd client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's cli_checksums.txt, and re-checked with sha256sum -c by the live test, which then runs argocd app list with no server and expects 'server address unspecified'. The server is a cluster install, not this role. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-argo

argo on EL 10 from the GitHub release; the asset is a bare gzip; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has lint --offline pass a valid Workflow and fail one whose entrypoint is missing (exit 1); list stops at the missing cluster. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-cilium-cli

cilium on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum Cilium publishes, and re-checked with sha256sum -c by the live test, which then runs cilium config view with no cluster and expects the refused connection. Installing Cilium into a cluster stays yours. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-flux-cli

flux on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked with sha256sum -c by the live test, which then runs flux check --pre with no cluster and expects the refused connection. Flux also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-helm

helm on EL 10 from get.helm.sh, refused by Ansible's get_url unless its SHA-256 is the one in the .sha256sum file published beside the tarball, and re-checked with sha256sum -c by the live test, which then runs helm list with no cluster and expects 'kubernetes cluster unreachable'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-helmfile

helmfile on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then runs helmfile list on a one-release file with no helm on the host and expects it to read the file and stop at the missing helm; pair it with the helm role. Original role, live-tested on Rocky Linux 10.

View module