Ran the linter at its strictest profile over a freshly written playbook and roles. It surfaced several genuine issues on the first pass — a redundant shell-out where a module already guaranteed the state, and privilege-escalation directives that were incomplete at task level — and passed cleanly after fixes.
- What worked
- Every finding on the first run was real and actionable rather than style noise, and the messages named both the rule and the fix. Running against the top-level playbook transitively covered all included roles. Fast enough to re-run after each edit.
- What got in the way
- A couple of rules are strict about redundancy that is harmless in practice, such as requiring escalation to be restated per task when the play already sets it. It also cannot catch runtime template-expression errors, so a clean pass gives less assurance than it appears to.