Description
The recent CUE-validation work (#34/#39, #40) introduced a `requires_cue` skip marker on tests that need the `cue` binary. Locally these tests run because the developer has cue installed; in CI they currently skip silently. That defeats the point of CI for the cue-using parts of the codebase.
`ansible-vault` is already installed in CI (via `uv pip install ansible-core`); the same treatment for `cue` makes the test suite truly green-or-broken with no skipped-but-unverified middle ground.
Fix
Add a step to `.github/workflows/ci.yml`, mirroring the existing `uv` install pattern:
```yaml
The `uv` step already extends `$GITHUB_PATH` with `$HOME/.local/bin`, so `cue` is on PATH for subsequent steps without an extra echo line.
`v0.16.1` matches the version used in local development. Pinning makes CI deterministic; bumps are deliberate, not drive-by.
Scope
- `ci.yml` only. `release.yml` doesn't run tests, so it doesn't need cue.
- Skip markers (`requires_cue`, `requires_ansible_vault`) stay in test code as graceful local-dev fallbacks; they don't fire in CI when both tools are present.
Priority
P2 — silent skips obscure real failures.
Description
The recent CUE-validation work (#34/#39, #40) introduced a `requires_cue` skip marker on tests that need the `cue` binary. Locally these tests run because the developer has cue installed; in CI they currently skip silently. That defeats the point of CI for the cue-using parts of the codebase.
`ansible-vault` is already installed in CI (via `uv pip install ansible-core`); the same treatment for `cue` makes the test suite truly green-or-broken with no skipped-but-unverified middle ground.
Fix
Add a step to `.github/workflows/ci.yml`, mirroring the existing `uv` install pattern:
```yaml
run: |
CUE_VERSION=v0.16.1
mkdir -p "$HOME/.local/bin"
curl -fsSL "https://github.com/cue-lang/cue/releases/download/${CUE_VERSION}/cue_${CUE_VERSION}_linux_amd64.tar.gz" \
| tar -xz -C "$HOME/.local/bin" cue
"$HOME/.local/bin/cue" version
```
The `uv` step already extends `$GITHUB_PATH` with `$HOME/.local/bin`, so `cue` is on PATH for subsequent steps without an extra echo line.
`v0.16.1` matches the version used in local development. Pinning makes CI deterministic; bumps are deliberate, not drive-by.
Scope
Priority
P2 — silent skips obscure real failures.