)]}'
{"playbooks/roles/kerberos-kdc/files/krb5-kpropd.service":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":1,"context_line":"[Unit]"},{"line_number":2,"context_line":"Description\u003dKerberos 5 slave KDC update server"},{"line_number":3,"context_line":""},{"line_number":4,"context_line":"[Service]"},{"line_number":5,"context_line":"ExecReload\u003d/bin/kill -HUP $MAINPID"}],"source_content_type":"application/octet-stream","patch_set":25,"id":"783bbe65_9d71e479","line":2,"range":{"start_line":2,"start_character":23,"end_line":2,"end_character":28},"updated":"2021-03-12 00:02:13.000000000","message":"We have been diligent about using primary and replica elsewhere. Not sure if we want to update this here or maybe we are trying to preserve file contents for now and can update once flipped from puppet to ansible.","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c3119ad3c5f6a959ce952e1d239249f246af7144","unresolved":false,"context_lines":[{"line_number":1,"context_line":"[Unit]"},{"line_number":2,"context_line":"Description\u003dKerberos 5 slave KDC update server"},{"line_number":3,"context_line":""},{"line_number":4,"context_line":"[Service]"},{"line_number":5,"context_line":"ExecReload\u003d/bin/kill -HUP $MAINPID"}],"source_content_type":"application/octet-stream","patch_set":25,"id":"8e5ead55_e7c6ce56","line":2,"range":{"start_line":2,"start_character":23,"end_line":2,"end_character":28},"in_reply_to":"783bbe65_9d71e479","updated":"2021-03-12 04:05:58.000000000","message":"Yep just missed this one.  You\u0027re right, I tried to remove the master/slave references since we\u0027re starting fresh.","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"}],"playbooks/roles/kerberos-kdc/tasks/main.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Setup replica"},{"line_number":39,"context_line":"  include_tasks: replica.yaml"},{"line_number":40,"context_line":"  when: \"\u0027kerberos-kdc-replica\u0027 in group_names\""}],"source_content_type":"text/x-yaml","patch_set":25,"id":"66047945_7a0cc77f","line":40,"updated":"2021-03-12 00:02:13.000000000","message":"Talking out loud here, if we run these tasks sequentially and need to run them separately each time would be be more explicit to have the playbook level call things like:\n\n  - host: kerberos-kdc\n    roles: kerberos-kdc\n\n  - host: kerberos-kdc-primary\n    tasks:\n      - include_role:\n        name: kerberos-kdc\n        tasks_from: primary\n\n  - host: kerberos-kdc-replica\n    tasks:\n      - include_role:\n        name: kerberos-kdc\n        tasks_from: replica\n\nI mention this because then we explicitly say run these tasks for hosts on group foo and then we don\u0027t need to do multiple passes of the same parent tasks (lines 1-32). We do similar to what I describe in places like the zuul process management playbooks.","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c3119ad3c5f6a959ce952e1d239249f246af7144","unresolved":false,"context_lines":[{"line_number":37,"context_line":""},{"line_number":38,"context_line":"- name: Setup replica"},{"line_number":39,"context_line":"  include_tasks: replica.yaml"},{"line_number":40,"context_line":"  when: \"\u0027kerberos-kdc-replica\u0027 in group_names\""}],"source_content_type":"text/x-yaml","patch_set":25,"id":"3583b7e5_f3272fd1","line":40,"in_reply_to":"66047945_7a0cc77f","updated":"2021-03-12 04:05:58.000000000","message":"I\u0027m not sure I knew about tasks_from 😊  Will rework","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"}],"playbooks/roles/kerberos-kdc/tasks/primary.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":17,"context_line":""},{"line_number":18,"context_line":"    - name: Setup primary db"},{"line_number":19,"context_line":"      shell: |"},{"line_number":20,"context_line":"          yes {{ kerberos_kdc_master_key }} | kdb5_util create -r {{ kerberos_kdc_realm }} -s"},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"    - name: Generate and save admin principal password"},{"line_number":23,"context_line":"      copy:"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"99c276c5_1dd0774b","line":20,"updated":"2021-03-12 00:02:13.000000000","message":"Should this be no_log: true?","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":25,"context_line":"        content: \u0027{{ lookup(\"password\", \"/dev/null chars\u003dascii_letters,digits length\u003d12\") }}\u0027"},{"line_number":26,"context_line":"        owner: root"},{"line_number":27,"context_line":"        group: root"},{"line_number":28,"context_line":"        mode: \u00270600\u0027"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"    - name: Setup initial admin principal"},{"line_number":31,"context_line":"      shell: |"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"30255983_7ec3b977","line":28,"updated":"2021-03-12 00:02:13.000000000","message":"Should this be no_log: true?","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":29,"context_line":""},{"line_number":30,"context_line":"    - name: Setup initial admin principal"},{"line_number":31,"context_line":"      shell: |"},{"line_number":32,"context_line":"          echo \"addprinc -pw $(cat /etc/krb5kdc/admin.passwd) admin/admin@{{ kerberos_kdc_realm }}\" | kadmin.local"},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"    # https://web.mit.edu/kerberos/krb5-latest/doc/admin/install_kdc.html"},{"line_number":35,"context_line":"    #   It is not strictly necessary to have the primary KDC server in"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"46a0e835_5b728aff","line":32,"updated":"2021-03-12 00:02:13.000000000","message":"Should this be no_log: true?","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":53,"context_line":"- name: Read and save stash file"},{"line_number":54,"context_line":"  slurp:"},{"line_number":55,"context_line":"    src: \u0027/etc/krb5kdc/stash\u0027"},{"line_number":56,"context_line":"  register: kerberos_kdc_stash_file_contents"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"# Export this so replica servers can use this variable to authenicate"},{"line_number":59,"context_line":"# and create keytabs for their host principals, if they need to."}],"source_content_type":"text/x-yaml","patch_set":25,"id":"e6102517_0f2e2ce7","line":56,"updated":"2021-03-12 00:02:13.000000000","message":"Should this be no_log: true?","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":60,"context_line":"- name: Read in admin/admin password"},{"line_number":61,"context_line":"  slurp:"},{"line_number":62,"context_line":"    src: \"/etc/krb5kdc/admin.passwd\""},{"line_number":63,"context_line":"  register: _admin_password"},{"line_number":64,"context_line":"- name: Export admin password"},{"line_number":65,"context_line":"  set_fact:"},{"line_number":66,"context_line":"    kerberos_kdc_admin_password: \u0027{{ _admin_password.content | b64decode }}\u0027"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"6321e2af_28898f33","line":63,"updated":"2021-03-12 00:02:13.000000000","message":"Should this be no_log: true?","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":63,"context_line":"  register: _admin_password"},{"line_number":64,"context_line":"- name: Export admin password"},{"line_number":65,"context_line":"  set_fact:"},{"line_number":66,"context_line":"    kerberos_kdc_admin_password: \u0027{{ _admin_password.content | b64decode }}\u0027"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"# kprop is what pushes the db to replicas.  Set it up to run via cron"},{"line_number":69,"context_line":"# periodically."}],"source_content_type":"text/x-yaml","patch_set":25,"id":"3896478a_8919955c","line":66,"updated":"2021-03-12 00:02:13.000000000","message":"I guess if we set it as a fact then setting no_log: true above isn\u0027t going to help much if vars are dumped.","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c3119ad3c5f6a959ce952e1d239249f246af7144","unresolved":true,"context_lines":[{"line_number":63,"context_line":"  register: _admin_password"},{"line_number":64,"context_line":"- name: Export admin password"},{"line_number":65,"context_line":"  set_fact:"},{"line_number":66,"context_line":"    kerberos_kdc_admin_password: \u0027{{ _admin_password.content | b64decode }}\u0027"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"# kprop is what pushes the db to replicas.  Set it up to run via cron"},{"line_number":69,"context_line":"# periodically."}],"source_content_type":"text/x-yaml","patch_set":25,"id":"0abcef70_ae6d6ec2","line":66,"in_reply_to":"3896478a_8919955c","updated":"2021-03-12 04:05:58.000000000","message":"Yeah; I\u0027m not sure no_log is really that helpful as this is mostly here to exercise the path in CI, where the values aren\u0027t precious and you\u0027d actually want to examine the results if something fails.","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"}],"playbooks/roles/kerberos-kdc/tasks/replica.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":9,"context_line":"- name: Install stash file from primary"},{"line_number":10,"context_line":"  shell:"},{"line_number":11,"context_line":"    cmd: \u0027echo \"{{ hostvars[groups[\"kerberos-kdc-primary\"][0]][\"kerberos_kdc_stash_file_contents\"].content }}\" | base64 -d \u003e /etc/krb5kdc/stash\u0027"},{"line_number":12,"context_line":"    creates: \u0027/etc/krb5kdc/stash\u0027"},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"- name: Ensure stash file permsissions"},{"line_number":15,"context_line":"  file:"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"0e3fb783_393c29e9","line":12,"updated":"2021-03-12 00:02:13.000000000","message":"See comments about no_log: true in the primary.yaml file.","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"}],"playbooks/service-kerberos.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":6,"context_line":"#  4. start replicas listening"},{"line_number":7,"context_line":"#"},{"line_number":8,"context_line":"# In production this is largely a no-op just ensuring things are"},{"line_number":9,"context_line":"# running."},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"- hosts: \"kerberos-kdc-primary:!disabled\""},{"line_number":12,"context_line":"  name: \"Configure Kerberos Primary\""}],"source_content_type":"text/x-yaml","patch_set":25,"id":"90b36d57_d45c08e8","line":9,"updated":"2021-03-12 00:02:13.000000000","message":"This is the file where my talking out loud refactor would go into place.","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c3119ad3c5f6a959ce952e1d239249f246af7144","unresolved":false,"context_lines":[{"line_number":6,"context_line":"#  4. start replicas listening"},{"line_number":7,"context_line":"#"},{"line_number":8,"context_line":"# In production this is largely a no-op just ensuring things are"},{"line_number":9,"context_line":"# running."},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"- hosts: \"kerberos-kdc-primary:!disabled\""},{"line_number":12,"context_line":"  name: \"Configure Kerberos Primary\""}],"source_content_type":"text/x-yaml","patch_set":25,"id":"873f763e_cc4c3abb","line":9,"in_reply_to":"90b36d57_d45c08e8","updated":"2021-03-12 04:05:58.000000000","message":"Done","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"}],"zuul.d/infra-prod.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"75e88dd1d877bf5ced6956c49f8e25df14dac63a","unresolved":true,"context_lines":[{"line_number":598,"context_line":"    parent: infra-prod-service-base"},{"line_number":599,"context_line":"    description: Run Kerberos playbook."},{"line_number":600,"context_line":"    vars:"},{"line_number":601,"context_line":"      playbook_name: service-kerberos.yaml"},{"line_number":602,"context_line":"      infra_prod_ansible_forks: 1"},{"line_number":603,"context_line":"    required-projects:"},{"line_number":604,"context_line":"      - opendev/system-config"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"87bd6b2e_e4c75210","line":601,"updated":"2021-03-12 00:02:13.000000000","message":"Will this job currently noop because there are no production group entries for the kdc servers?","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"c3119ad3c5f6a959ce952e1d239249f246af7144","unresolved":false,"context_lines":[{"line_number":598,"context_line":"    parent: infra-prod-service-base"},{"line_number":599,"context_line":"    description: Run Kerberos playbook."},{"line_number":600,"context_line":"    vars:"},{"line_number":601,"context_line":"      playbook_name: service-kerberos.yaml"},{"line_number":602,"context_line":"      infra_prod_ansible_forks: 1"},{"line_number":603,"context_line":"    required-projects:"},{"line_number":604,"context_line":"      - opendev/system-config"}],"source_content_type":"text/x-yaml","patch_set":25,"id":"7771b89c_74435e8a","line":601,"in_reply_to":"87bd6b2e_e4c75210","updated":"2021-03-12 04:05:58.000000000","message":"yep, they are moved in a follow-up change which we can commit under supervision","commit_id":"eb574cf80d3e1f5e035dab962c25a7a380d144af"}],"zuul.d/system-config-run.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"5d1159f39c2249b02200f17b6ec022a9a5ce406c","unresolved":true,"context_lines":[{"line_number":946,"context_line":"          \u0027/var/krb5kdc/\u0027: logs"},{"line_number":947,"context_line":"    vars:"},{"line_number":948,"context_line":"      run_playbooks:"},{"line_number":949,"context_line":"        - playbooks/service-kerberos.yaml"},{"line_number":950,"context_line":"      run_test_playbook: playbooks/test-kerberos.yaml"},{"line_number":951,"context_line":"    files:"},{"line_number":952,"context_line":"      - playbooks/bridge.yaml"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"6297dd88_c3f1e7da","line":949,"updated":"2021-03-16 20:39:58.000000000","message":"Maybe consider running this playbook twice here to ensure things properly noop after being configured once. This should give us more assurances that running against prod will be happy.\n\nThe gitea jobs do similar with manage-projects.yaml which is what made me think of this.","commit_id":"31b8e2dd7a2ccec3d7bb1dce0b6a8960be5f36ec"}]}
