)]}'
{"doc/source/sysadmin.rst":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"1d2411b76a4685a0c4b76fc25939d7e628078321","unresolved":false,"context_lines":[{"line_number":212,"context_line":"OpenStack CI infrastructure for another project."},{"line_number":213,"context_line":""},{"line_number":214,"context_line":"Force configuration run on a server"},{"line_number":215,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":216,"context_line":""},{"line_number":217,"context_line":"If you need to force a configuration run on a single server before the"},{"line_number":218,"context_line":"usual cron job time, you can use the ``kick.sh`` script on"}],"source_content_type":"text/x-rst","patch_set":3,"id":"9f560f44_8eca624c","side":"PARENT","line":215,"updated":"2020-09-03 21:49:53.000000000","message":"We should keep this section. I think the new version of it is run the service playbook for it with zuul\u0027s disable flag set?","commit_id":"fe56f589051c04018ab31e84ec2d9f90d6da34ad"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"2511422329a849394c2cc1c82f1e6cdbadbc6c79","unresolved":false,"context_lines":[{"line_number":6,"context_line":"#####################"},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"Our infrastructure is code and contributions to it are handled just"},{"line_number":9,"context_line":"like the rest of Opendev.  This means that anyone can contribute to"},{"line_number":10,"context_line":"the installation and long-running maintenance of systems without shell"},{"line_number":11,"context_line":"access, and anyone who is interested can provide feedback and"},{"line_number":12,"context_line":"collaborate on code reviews."}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_56e0dcf8","line":9,"range":{"start_line":9,"start_character":17,"end_line":9,"end_character":24},"updated":"2020-09-04 07:19:57.000000000","message":"OpenDev ?","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c16213d5c976e40760f5b2eea6a30f05180aad3e","unresolved":false,"context_lines":[{"line_number":6,"context_line":"#####################"},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"Our infrastructure is code and contributions to it are handled just"},{"line_number":9,"context_line":"like the rest of Opendev.  This means that anyone can contribute to"},{"line_number":10,"context_line":"the installation and long-running maintenance of systems without shell"},{"line_number":11,"context_line":"access, and anyone who is interested can provide feedback and"},{"line_number":12,"context_line":"collaborate on code reviews."}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_a6677325","line":9,"range":{"start_line":9,"start_character":17,"end_line":9,"end_character":24},"in_reply_to":"9f560f44_56e0dcf8","updated":"2020-09-07 07:14:08.000000000","message":"Done","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"2511422329a849394c2cc1c82f1e6cdbadbc6c79","unresolved":false,"context_lines":[{"line_number":12,"context_line":"collaborate on code reviews."},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"The configuration of every system operated by the infrastructure team"},{"line_number":15,"context_line":"is managed Ansible and driven by continuous integration and deployment"},{"line_number":16,"context_line":"by Zuul."},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"  https://opendev.org/opendev/system-config"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_96b9d416","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":18},"updated":"2020-09-04 07:19:57.000000000","message":"managed by?","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c16213d5c976e40760f5b2eea6a30f05180aad3e","unresolved":false,"context_lines":[{"line_number":12,"context_line":"collaborate on code reviews."},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"The configuration of every system operated by the infrastructure team"},{"line_number":15,"context_line":"is managed Ansible and driven by continuous integration and deployment"},{"line_number":16,"context_line":"by Zuul."},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"  https://opendev.org/opendev/system-config"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_e66deb03","line":15,"range":{"start_line":15,"start_character":0,"end_line":15,"end_character":18},"in_reply_to":"9f560f44_96b9d416","updated":"2020-09-07 07:14:08.000000000","message":"Done","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"2511422329a849394c2cc1c82f1e6cdbadbc6c79","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"These playbooks run on groups of hosts which are defined in"},{"line_number":35,"context_line":":git_file:`inventory/service/groups`.  The production hosts are kept"},{"line_number":36,"context_line":"in an inventory at :git_file:`inventory/base/hosts.yaml`.  During"},{"line_number":37,"context_line":"testing, these same playbooks are run durings tests.  You can note"},{"line_number":38,"context_line":"that the testing hosts are given names that match the group"},{"line_number":39,"context_line":"configuration in the jobs defined in"},{"line_number":40,"context_line":":git_file:`zuul.d/system-config-run.yaml`."}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_964ef435","line":37,"range":{"start_line":36,"start_character":59,"end_line":37,"end_character":51},"updated":"2020-09-04 07:19:57.000000000","message":"This sounds redundant, maybe:\n\nDuring testing, these same playbooks are run on the test nodes.","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c16213d5c976e40760f5b2eea6a30f05180aad3e","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"These playbooks run on groups of hosts which are defined in"},{"line_number":35,"context_line":":git_file:`inventory/service/groups`.  The production hosts are kept"},{"line_number":36,"context_line":"in an inventory at :git_file:`inventory/base/hosts.yaml`.  During"},{"line_number":37,"context_line":"testing, these same playbooks are run durings tests.  You can note"},{"line_number":38,"context_line":"that the testing hosts are given names that match the group"},{"line_number":39,"context_line":"configuration in the jobs defined in"},{"line_number":40,"context_line":":git_file:`zuul.d/system-config-run.yaml`."}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_867cefb6","line":37,"range":{"start_line":36,"start_character":59,"end_line":37,"end_character":51},"in_reply_to":"9f560f44_964ef435","updated":"2020-09-07 07:14:08.000000000","message":"Done","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"2511422329a849394c2cc1c82f1e6cdbadbc6c79","unresolved":false,"context_lines":[{"line_number":88,"context_line":"SSH Access"},{"line_number":89,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"For any of the systems managed by the OpenStack Infrastructure team, the"},{"line_number":92,"context_line":"following practices must be observed for SSH access:"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"* SSH access is only permitted with SSH public/private key"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_96ea74d5","line":91,"range":{"start_line":91,"start_character":38,"end_line":91,"end_character":62},"updated":"2020-09-04 07:19:57.000000000","message":"OpenDev ?","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c16213d5c976e40760f5b2eea6a30f05180aad3e","unresolved":false,"context_lines":[{"line_number":88,"context_line":"SSH Access"},{"line_number":89,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":90,"context_line":""},{"line_number":91,"context_line":"For any of the systems managed by the OpenStack Infrastructure team, the"},{"line_number":92,"context_line":"following practices must be observed for SSH access:"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"* SSH access is only permitted with SSH public/private key"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_c64b8784","line":91,"range":{"start_line":91,"start_character":38,"end_line":91,"end_character":62},"in_reply_to":"9f560f44_96ea74d5","updated":"2020-09-07 07:14:08.000000000","message":"Done","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"2511422329a849394c2cc1c82f1e6cdbadbc6c79","unresolved":false,"context_lines":[{"line_number":113,"context_line":"  is received should be used, and the SSH keys should be added with"},{"line_number":114,"context_line":"  the confirmation constraint (\u0027ssh-add -c\u0027)."},{"line_number":115,"context_line":"* The number of SSH keys that are configured to permit access to"},{"line_number":116,"context_line":"  OpenStack machines should be kept to a minimum."},{"line_number":117,"context_line":"* OpenStack Infrastructure machines must use puppet to centrally manage and"},{"line_number":118,"context_line":"  configure user accounts, and the SSH authorized_keys files from the"},{"line_number":119,"context_line":"  openstack-infra/system-config repository."}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_36b568ef","line":116,"range":{"start_line":116,"start_character":2,"end_line":116,"end_character":11},"updated":"2020-09-04 07:19:57.000000000","message":"OpenDev","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c16213d5c976e40760f5b2eea6a30f05180aad3e","unresolved":false,"context_lines":[{"line_number":113,"context_line":"  is received should be used, and the SSH keys should be added with"},{"line_number":114,"context_line":"  the confirmation constraint (\u0027ssh-add -c\u0027)."},{"line_number":115,"context_line":"* The number of SSH keys that are configured to permit access to"},{"line_number":116,"context_line":"  OpenStack machines should be kept to a minimum."},{"line_number":117,"context_line":"* OpenStack Infrastructure machines must use puppet to centrally manage and"},{"line_number":118,"context_line":"  configure user accounts, and the SSH authorized_keys files from the"},{"line_number":119,"context_line":"  openstack-infra/system-config repository."}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_06429f68","line":116,"range":{"start_line":116,"start_character":2,"end_line":116,"end_character":11},"in_reply_to":"9f560f44_36b568ef","updated":"2020-09-07 07:14:08.000000000","message":"Done","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"2511422329a849394c2cc1c82f1e6cdbadbc6c79","unresolved":false,"context_lines":[{"line_number":116,"context_line":"  OpenStack machines should be kept to a minimum."},{"line_number":117,"context_line":"* OpenStack Infrastructure machines must use puppet to centrally manage and"},{"line_number":118,"context_line":"  configure user accounts, and the SSH authorized_keys files from the"},{"line_number":119,"context_line":"  openstack-infra/system-config repository."},{"line_number":120,"context_line":"* SSH keys should be periodically rotated (at least once per year)."},{"line_number":121,"context_line":"  During rotation, a new key can be added to puppet for a time, and"},{"line_number":122,"context_line":"  then the old one removed.  Be sure to run puppet on the backup"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_16b824e3","line":119,"range":{"start_line":119,"start_character":2,"end_line":119,"end_character":17},"updated":"2020-09-04 07:19:57.000000000","message":"opendev","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c16213d5c976e40760f5b2eea6a30f05180aad3e","unresolved":false,"context_lines":[{"line_number":116,"context_line":"  OpenStack machines should be kept to a minimum."},{"line_number":117,"context_line":"* OpenStack Infrastructure machines must use puppet to centrally manage and"},{"line_number":118,"context_line":"  configure user accounts, and the SSH authorized_keys files from the"},{"line_number":119,"context_line":"  openstack-infra/system-config repository."},{"line_number":120,"context_line":"* SSH keys should be periodically rotated (at least once per year)."},{"line_number":121,"context_line":"  During rotation, a new key can be added to puppet for a time, and"},{"line_number":122,"context_line":"  then the old one removed.  Be sure to run puppet on the backup"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_86550f21","line":119,"range":{"start_line":119,"start_character":2,"end_line":119,"end_character":17},"in_reply_to":"9f560f44_16b824e3","updated":"2020-09-07 07:14:08.000000000","message":"Done","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"2511422329a849394c2cc1c82f1e6cdbadbc6c79","unresolved":false,"context_lines":[{"line_number":119,"context_line":"  openstack-infra/system-config repository."},{"line_number":120,"context_line":"* SSH keys should be periodically rotated (at least once per year)."},{"line_number":121,"context_line":"  During rotation, a new key can be added to puppet for a time, and"},{"line_number":122,"context_line":"  then the old one removed.  Be sure to run puppet on the backup"},{"line_number":123,"context_line":"  servers to make sure they are updated."},{"line_number":124,"context_line":""},{"line_number":125,"context_line":""},{"line_number":126,"context_line":"GitHub Access"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_d6a22cad","line":123,"range":{"start_line":122,"start_character":29,"end_line":123,"end_character":40},"updated":"2020-09-04 07:19:57.000000000","message":"Is this still needed?\n\nAlso I haven\u0027t seen anyone rotate their keys since I\u0027m infra-root, either be stricter with this, or drop it?","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c16213d5c976e40760f5b2eea6a30f05180aad3e","unresolved":false,"context_lines":[{"line_number":119,"context_line":"  openstack-infra/system-config repository."},{"line_number":120,"context_line":"* SSH keys should be periodically rotated (at least once per year)."},{"line_number":121,"context_line":"  During rotation, a new key can be added to puppet for a time, and"},{"line_number":122,"context_line":"  then the old one removed.  Be sure to run puppet on the backup"},{"line_number":123,"context_line":"  servers to make sure they are updated."},{"line_number":124,"context_line":""},{"line_number":125,"context_line":""},{"line_number":126,"context_line":"GitHub Access"}],"source_content_type":"text/x-rst","patch_set":4,"id":"9f560f44_265c034a","line":123,"range":{"start_line":122,"start_character":29,"end_line":123,"end_character":40},"in_reply_to":"9f560f44_d6a22cad","updated":"2020-09-07 07:14:08.000000000","message":"no.\n\nas for rotation ... i\u0027ll leave that :)","commit_id":"1854040807917995cf98c0ded4d4d06e14b31bbb"}]}
