kustomize, Checked Against The Published Checksums
kustomize on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.txt, and re-checked with sha256sum -c by the live test. The tag carries a slash (kustomize/v5.8.1), URL-encoded in the release path. Pinned; kustomize build against a directory with no kustomization stops where it should. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify
Documentation
kustomize
Kubernetes SIGs kustomize on EL 10 from the vendor's release, checked against the
published SHA-256, pinned to a version, installed as root's binary
in /usr/local/bin. Original role for EL 10, live-tested with podman on
Rocky Linux 10.
No package worth the name. EL 10 carries no kustomize, and a
third-party repository is one more key to trust. This role takes the
release from github.com/kubernetes-sigs/kustomize, has Ansible's get_url refuse the asset unless
its SHA-256 is the published one, and the live test checks the asset on
disk against the same published value again.
Pinned. kustomize_version is what gets installed, kept in a directory
of its own so the checksum file and the asset it names stay together. A
newer release is a variable change and a run; the same version is
changed=0.
Proven to run. The live test runs kustomize build /tmp and expects
"unable to find one of" - the binary ran all the way to the point where it
needed something this host does not have.
A tag with a slash in it. kustomize releases under
kustomize/v<version> in a repository that also tags kyaml/, api/ and
cmd/config/; the download path carries the tag URL-encoded
(kustomize%2Fv5.8.1), which is why the release URL is built from a base
and the version rather than the usual v<version>. kustomize build
against a directory with no kustomization stops at "unable to find one of
'kustomization.yaml'...", the live test's proof that the binary ran.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-argocd-cli
The argocd client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's cli_checksums.txt, and re-checked with sha256sum -c by the live test, which then runs argocd app list with no server and expects 'server address unspecified'. The server is a cluster install, not this role. Original role, live-tested on Rocky Linux 10.
ansible-cilium-cli
cilium on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum Cilium publishes, and re-checked with sha256sum -c by the live test, which then runs cilium config view with no cluster and expects the refused connection. Installing Cilium into a cluster stays yours. Original role, live-tested on Rocky Linux 10.
ansible-flux-cli
flux on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked with sha256sum -c by the live test, which then runs flux check --pre with no cluster and expects the refused connection. Flux also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.
ansible-helm
helm on EL 10 from get.helm.sh, refused by Ansible's get_url unless its SHA-256 is the one in the .sha256sum file published beside the tarball, and re-checked with sha256sum -c by the live test, which then runs helm list with no cluster and expects 'kubernetes cluster unreachable'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-k9s
k9s on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.sha256, and re-checked with sha256sum -c by the live test. A terminal UI needs a kubeconfig to show anything, so the live test uses k9s version and k9s info, which print the version and the per-user config paths. Original role, live-tested on Rocky Linux 10.
ansible-kind
kind on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum kind publishes, and re-checked with sha256sum -c by the live test. kind needs a container runtime it does not bring (podman on EL 10); kind get clusters with none stops at 'failed to list clusters'. Original role, live-tested on Rocky Linux 10.