hadolint, A Dockerfile Linted

hadolint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which lints a two-line Dockerfile with four things wrong and expects DL3008 among the findings and exit 1. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

ansibleCloud Tooling

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify

Documentation

hadolint

hadolint hadolint on EL 10 from the vendor's release, checked against the published SHA-256, pinned to a version, installed as root's binary in /usr/local/bin. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No package worth the name. EL 10 carries no hadolint, and a third-party repository is one more key to trust. This role takes the release from github.com/hadolint/hadolint, has Ansible's get_url refuse the asset unless its SHA-256 is the published one, and the live test checks the asset on disk against the same published value again.

Pinned. hadolint_version is what gets installed, kept in a directory of its own so the checksum file and the asset it names stay together. A newer release is a variable change and a run; the same version is changed=0.

Proven to run. The live test runs hadolint --no-color /tmp/hadolint-p/Dockerfile and expects "DL3008" - the binary ran all the way to the point where it needed something this host does not have.

A Dockerfile, linted. The live test writes a two-line Dockerfile that does four things wrong (latest, an unpinned apt-get install without -y or --no-install-recommends) and has hadolint read it: DL3007, DL3008, DL3014 and DL3015 come back and the exit code is 1. The checksum file names each asset with a leading * (binary mode), which Ansible's get_url and sha256sum -c both accept.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-checkov

Checkov pinned in /opt/checkov, a virtual environment apart from the system Python. The live test runs pip check, scans a one-resource module with the built-in checks and --skip-download and expects a 'Failed checks:' summary with no network, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-conftest

conftest on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-rule Rego v1 policy and a one-line document, runs conftest test and expects the denial in the report. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-consul-cli

consul on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs consul members against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gh-cli

gh on EL 10 from the release tarball, refused by Ansible's get_url unless its SHA-256 is the one in GitHub's checksums file, and re-checked with sha256sum -c by the live test; one more file to trust and no more repositories. Tokens are per user; gh auth status with none stops at 'not logged into any GitHub hosts', the live test's proof the client ran. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gitea

Gitea from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; its secrets are generated once and read from files, so app.ini stays root's. The live test creates an administrator with gitea's own command, then a private repository through the API, reads it back, sees it hidden from anonymous eyes, deletes it. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-k6

k6 on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs a script to 100% checks and one whose threshold cannot hold to exit code 99; usage reporting off from profile.d. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module