)]}'
{"playbooks/roles/letsencrypt-acme-sh-install/README.rst":[{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"8297e2faf664dc764fc0a6611994e4d21e03985b","unresolved":false,"context_lines":[{"line_number":16,"context_line":"   system default.  Useful if this conflicts with another role that"},{"line_number":17,"context_line":"   assumes a `gid` value."},{"line_number":18,"context_line":""},{"line_number":19,"context_line":".. zuul:rolevar:: letsencrypt_account_email"},{"line_number":20,"context_line":"   :default: undefined"},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"   The email address to register with accounts.  Renewal mail and"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1fa4df85_af6090d0","line":19,"updated":"2020-03-05 05:34:13.000000000","message":"Note we should set this to our private email in infra group_vars on bridge.o.o before merge.","commit_id":"3aaf87ee6d4cfe32b607ed4c2a04044e8ad8ad12"}],"playbooks/roles/letsencrypt-acme-sh-install/defaults/main.yaml":[{"author":{"_account_id":2,"name":"Monty Taylor","email":"mordred@inaugust.com","username":"mordred"},"change_message_id":"791cf1d0662bd21d9c1f0451595703015ce923e1","unresolved":false,"context_lines":[{"line_number":1,"context_line":"letsencrypt_account_email: \u0027infra-root+letsencrypt@openstack.org\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_931cedc1","line":1,"range":{"start_line":1,"start_character":28,"end_line":1,"end_character":64},"updated":"2020-03-04 14:21:05.000000000","message":"Based on past experience I think we should put this into a an ansible secret. People frequently re-use things from us - and any time we put an email address in a public default we wind up getting emails from systems that arent\u0027 ours and we can\u0027t fix it.","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"ba466a035ea133a2c982fc4d2c3489d3dcbf842c","unresolved":false,"context_lines":[{"line_number":1,"context_line":"letsencrypt_account_email: \u0027infra-root+letsencrypt@openstack.org\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_80e32bd9","line":1,"range":{"start_line":1,"start_character":28,"end_line":1,"end_character":64},"in_reply_to":"1fa4df85_931cedc1","updated":"2020-03-04 21:37:21.000000000","message":"fair point and we can hide this","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"}],"playbooks/roles/letsencrypt-acme-sh-install/tasks/main.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"8e4e335aeaefccb81d27b9b7385af226fce73df1","unresolved":false,"context_lines":[{"line_number":56,"context_line":"  lineinfile:"},{"line_number":57,"context_line":"    path: /root/.acme.sh/account.conf"},{"line_number":58,"context_line":"    regexp: \u0027^ACCOUNT_EMAIL\u003d\u0027"},{"line_number":59,"context_line":"    line: \u0027ACCOUNT_EMAIL\u003d{{ letsencrypt_account_email }}\u0027"},{"line_number":60,"context_line":"  register: account_email"},{"line_number":61,"context_line":""},{"line_number":62,"context_line":"# If we updated the email and we have existing accounts, we should"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"1fa4df85_342f2c8f","line":59,"updated":"2020-03-04 00:22:45.000000000","message":"I think we need to set create to true in order for this file to be created on a first pass.\n\nhttps://docs.ansible.com/ansible/latest/modules/lineinfile_module.html#parameter-create","commit_id":"ab11c57f0e2419f588168d6a09d0a9f87e91e8b7"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"a629f3fdc989e132e49a1bf4487139c5a33468c2","unresolved":false,"context_lines":[{"line_number":50,"context_line":"# is revoke a certificate if you lose the private key.  It makes more"},{"line_number":51,"context_line":"# sense to have an account per host with key material that never"},{"line_number":52,"context_line":"# leaves the host rather than keeping a global secret that, if leaked,"},{"line_number":53,"context_line":"# could revoke all keys simltaneously."},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"- name: Configure account email"},{"line_number":56,"context_line":"  lineinfile:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_82f1fd97","line":53,"range":{"start_line":53,"start_character":24,"end_line":53,"end_character":37},"updated":"2020-03-04 11:22:44.000000000","message":"simultaneously","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"ba466a035ea133a2c982fc4d2c3489d3dcbf842c","unresolved":false,"context_lines":[{"line_number":50,"context_line":"# is revoke a certificate if you lose the private key.  It makes more"},{"line_number":51,"context_line":"# sense to have an account per host with key material that never"},{"line_number":52,"context_line":"# leaves the host rather than keeping a global secret that, if leaked,"},{"line_number":53,"context_line":"# could revoke all keys simltaneously."},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"- name: Configure account email"},{"line_number":56,"context_line":"  lineinfile:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_a09bc770","line":53,"range":{"start_line":53,"start_character":24,"end_line":53,"end_character":37},"in_reply_to":"1fa4df85_82f1fd97","updated":"2020-03-04 21:37:21.000000000","message":"Done","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"},{"author":{"_account_id":2,"name":"Monty Taylor","email":"mordred@inaugust.com","username":"mordred"},"change_message_id":"791cf1d0662bd21d9c1f0451595703015ce923e1","unresolved":false,"context_lines":[{"line_number":58,"context_line":"    regexp: \u0027^ACCOUNT_EMAIL\u003d\u0027"},{"line_number":59,"context_line":"    line: \u0027ACCOUNT_EMAIL\u003d{{ letsencrypt_account_email }}\u0027"},{"line_number":60,"context_line":"    create: true"},{"line_number":61,"context_line":"  register: account_email"},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"# If we updated the email and we have existing accounts, we should"},{"line_number":64,"context_line":"# update the address."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_b36ec92c","line":61,"updated":"2020-03-04 14:21:05.000000000","message":"then obviously if the email moves to a secret we\u0027ll want a\n\n  when: letsencrypt_account_email is defined\n\nor something here.","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"ba466a035ea133a2c982fc4d2c3489d3dcbf842c","unresolved":false,"context_lines":[{"line_number":58,"context_line":"    regexp: \u0027^ACCOUNT_EMAIL\u003d\u0027"},{"line_number":59,"context_line":"    line: \u0027ACCOUNT_EMAIL\u003d{{ letsencrypt_account_email }}\u0027"},{"line_number":60,"context_line":"    create: true"},{"line_number":61,"context_line":"  register: account_email"},{"line_number":62,"context_line":""},{"line_number":63,"context_line":"# If we updated the email and we have existing accounts, we should"},{"line_number":64,"context_line":"# update the address."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_a0a9877c","line":61,"in_reply_to":"1fa4df85_b36ec92c","updated":"2020-03-04 21:37:21.000000000","message":"i don\u0027t think a secret as in a .zuul.d secret works, since it will be running on bridge which won\u0027t be decoding them?\n\nbut I can blank it, assert it is set, and add it to the private config on bridge.o.o?","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"a629f3fdc989e132e49a1bf4487139c5a33468c2","unresolved":false,"context_lines":[{"line_number":65,"context_line":"# NOTE(ianw) 2020-03-04 : acme.sh dumps the account details into this"},{"line_number":66,"context_line":"# config file but doesn\u0027t actually update it in response to"},{"line_number":67,"context_line":"# --updateaccount; although the account *is* updated.  I have filed:"},{"line_number":68,"context_line":"#   https://github.com/acmesh-official/acme.sh/pull/2769"},{"line_number":69,"context_line":"- name: Check for existing account setup"},{"line_number":70,"context_line":"  stat:"},{"line_number":71,"context_line":"    path: \u0027{{ item }}\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_e2f8f17b","line":68,"updated":"2020-03-04 11:22:44.000000000","message":"So currently the update would run again on every pulse until we manually fix the file? Maybe we should hold off doing this until the script is fixed?","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"ba466a035ea133a2c982fc4d2c3489d3dcbf842c","unresolved":false,"context_lines":[{"line_number":65,"context_line":"# NOTE(ianw) 2020-03-04 : acme.sh dumps the account details into this"},{"line_number":66,"context_line":"# config file but doesn\u0027t actually update it in response to"},{"line_number":67,"context_line":"# --updateaccount; although the account *is* updated.  I have filed:"},{"line_number":68,"context_line":"#   https://github.com/acmesh-official/acme.sh/pull/2769"},{"line_number":69,"context_line":"- name: Check for existing account setup"},{"line_number":70,"context_line":"  stat:"},{"line_number":71,"context_line":"    path: \u0027{{ item }}\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"1fa4df85_402a132c","line":68,"in_reply_to":"1fa4df85_e2f8f17b","updated":"2020-03-04 21:37:21.000000000","message":"No, sorry if it\u0027s not clear -- when acme.sh registers the account it dumps the server\u0027s 200 json response into this file which records details for updating if required.\n\nIf/when it does update, it doesn\u0027t dump the *new* details back into the file.  so it\u0027s updated on the server end, but this file doesn\u0027t show the new email address in it.  It\u0027s a bit confusing if you look at the .json file and think the email isn\u0027t updated, but it really is (i confirmed this with the change dumping the new values, which shows the updated email).\n\nwe only test for the presence of the file below (implying there is already an account) and only run update if we changed the email in the config file -- the actual status of the account email in the .json file isn\u0027t part of it and this and i believe this won\u0027t trigger unnecessarily","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"}],"testinfra/test_letsencrypt.py":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"a629f3fdc989e132e49a1bf4487139c5a33468c2","unresolved":false,"context_lines":[{"line_number":137,"context_line":""},{"line_number":138,"context_line":"    config \u003d host.file(\u0027/root/.acme.sh/account.conf\u0027)"},{"line_number":139,"context_line":"    assert config.exists"},{"line_number":140,"context_line":"    assert config.contains(\u0027ACCOUNT_EMAIL\u003d\u0027)"}],"source_content_type":"text/x-python","patch_set":3,"id":"1fa4df85_6232c161","line":140,"updated":"2020-03-04 11:22:44.000000000","message":"Regarding the bug you found, shouldn\u0027t you actually verify the correct email here?","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"ba466a035ea133a2c982fc4d2c3489d3dcbf842c","unresolved":false,"context_lines":[{"line_number":137,"context_line":""},{"line_number":138,"context_line":"    config \u003d host.file(\u0027/root/.acme.sh/account.conf\u0027)"},{"line_number":139,"context_line":"    assert config.exists"},{"line_number":140,"context_line":"    assert config.contains(\u0027ACCOUNT_EMAIL\u003d\u0027)"}],"source_content_type":"text/x-python","patch_set":3,"id":"1fa4df85_00cadb4c","line":140,"in_reply_to":"1fa4df85_6232c161","updated":"2020-03-04 21:37:21.000000000","message":"I think prior comment addresses the bug; this is the config file, not the dumped json response from LE","commit_id":"3c31f83dd5e12f90672796304d034c8859365f3f"}]}
