)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"0148f1dfbe595f6e71ea6aa1272ce23e0a933a37","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"605665cc_51885677","updated":"2025-07-18 15:20:16.000000000","message":"I think this code currently generates the private key and certificate on the vault server.\n\nThere are two different approaches on the vault api, \"issue\" and \"sign\" which don\u0027t have the same behaviour regarding the private key.\n\nSee the example here https://developer.hashicorp.com/vault/api-docs/secret/pki#sample-response-2","commit_id":"b48514da5969c41f3f64d153b397e52a33d62d3b"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"818c03db9953b1acc5dab1b7445605d4d4c3a7b6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":14,"id":"6579b40e_4a9a814c","updated":"2025-08-05 16:19:23.000000000","message":"recheck - `Error pulling image geerlingguy/docker-ubuntu2404-ansible:latest - 429 Client Error for http+docker://localhost/v1.51/images/create?tag\u003dlatest\u0026fromImage\u003dgeerlingguy%2Fdocker-ubuntu2404-ansible: Too Many Requests (\\\"toomanyrequests: You have reached your unauthenticated pull rate limit. https://www.docker.com/increase-rate-limit\\\"` during molecule tests","commit_id":"dfc6465d4ad9a384f715e2ebabfe442fb2eaa0fd"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"ae36bae60d55e7728eacbbbf7f18a94742e92dfd","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":27,"id":"62d5666a_aa318d24","updated":"2025-11-07 17:33:04.000000000","message":"You;\u0027d need to set https://review.opendev.org/c/openstack/ansible-role-python_venv_build/+/966404 as dependency for tls to pass","commit_id":"dfa6c51af69ce89e5cf8f84aaff407a4f9a28f66"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"f8abf3cff5155fed88c4680ffa22c2ee9c739f80","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":29,"id":"2c7979f2_456cbd73","updated":"2025-11-11 08:53:26.000000000","message":"recheck dependent patch updated","commit_id":"a867fa5d59efd7d6095d06fc53e0393ef61a6a8b"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"8aeedf1d53b81d1ed4293721bbc727594d13f9d9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":31,"id":"b151f4ec_fd0103d4","updated":"2025-12-16 20:23:11.000000000","message":"recheck - openstack-ansible-deploy-infra_lxc-debian-trixie\n\n```\n E:Failed to fetch https://deb1.rabbitmq.com/rabbitmq-erlang/debian/trixie/dists/trixie/main/binary-amd64/Packages  404  Not\n        Found [IP: 172.66.137.41 443], E:Failed to fetch https://deb2.rabbitmq.com/rabbitmq-erlang/debian/trixie/dists/trixie/main/binary-amd64/Packages  404  Not\n        Found [IP: 172.66.134.69 443], E:Some index files failed to download. They have\n        been ignored, or old ones used instead.\n```","commit_id":"f489515e51f70822449f523fa218349a69541bd6"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"23540fed2ca431cad59ea6340ed107479a00278c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":31,"id":"219e0d17_4080894f","in_reply_to":"b151f4ec_fd0103d4","updated":"2025-12-16 20:24:12.000000000","message":"ehhh, not sure what I did...I seems like I\u0027m super blind, this recheck wasn\u0027t needed","commit_id":"f489515e51f70822449f523fa218349a69541bd6"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":35,"id":"2742cb65_6c8c48f0","updated":"2025-12-22 14:07:06.000000000","message":"this looks good overall, just couple of nits in docs.","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"6fa70db0ad7db356d94aac068d6f97e04251c93d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":36,"id":"706b709f_4c705627","updated":"2026-01-28 12:09:05.000000000","message":"Lets merge and get this in use for further feedback/fixes","commit_id":"e1aa900db39ede1dece41c9fc96340cd40f1ab13"}],"defaults/main.yml":[{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"be7943b53269eb88c1863f76aa33cd7818d01a5b","unresolved":true,"context_lines":[{"line_number":36,"context_line":"#       - cRLSign"},{"line_number":37,"context_line":"#       - keyCertSign"},{"line_number":38,"context_line":"#     ttl: \"3650d\""},{"line_number":39,"context_line":"#     # standalone backend only"},{"line_number":40,"context_line":"#     provider: selfsigned"},{"line_number":41,"context_line":"#     basic_constraints: \"CA:TRUE\""},{"line_number":42,"context_line":"#     # hashi_vault backend only"},{"line_number":43,"context_line":"#     vault_path: pki"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"#pki_authorities_intermediates:"},{"line_number":46,"context_line":"#   - name: \"SnakeRootIntermediate\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"ee0404e1_b5ac6aae","line":43,"range":{"start_line":39,"start_character":0,"end_line":43,"end_character":21},"updated":"2025-07-01 16:19:06.000000000","message":"i really do not like this where we are putting what look like default values into the input data","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"5726f9906abe16a2e9ee5722c086e11ac66257bc","unresolved":true,"context_lines":[{"line_number":36,"context_line":"#       - cRLSign"},{"line_number":37,"context_line":"#       - keyCertSign"},{"line_number":38,"context_line":"#     ttl: \"3650d\""},{"line_number":39,"context_line":"#     # standalone backend only"},{"line_number":40,"context_line":"#     provider: selfsigned"},{"line_number":41,"context_line":"#     basic_constraints: \"CA:TRUE\""},{"line_number":42,"context_line":"#     # hashi_vault backend only"},{"line_number":43,"context_line":"#     vault_path: pki"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"#pki_authorities_intermediates:"},{"line_number":46,"context_line":"#   - name: \"SnakeRootIntermediate\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"4baaa323_25c4fedd","line":43,"range":{"start_line":39,"start_character":0,"end_line":43,"end_character":21},"in_reply_to":"02c2fa9f_dd15c20b","updated":"2025-10-09 13:52:50.000000000","message":"@jonathan.rosser@rd.bbc.co.uk I tried to make `vault_path` and `vault_root_ca_path` optional and create a fallback to the default value for these vars that is defined in defaults/ of ansible-role-pki role.\n\n\nHowever, it\u0027s not that simple because `vault_path` is supposed to have different value for root CA and different for intermediates. So I cannot just define a static, default value for it.\n\nSo eventually, the least confusing option would be to leave `vault_path` and `vault_root_ca_path` as is :/","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"1dbdee16a4a4fb314dece19daa9a2fd1f6e67313","unresolved":true,"context_lines":[{"line_number":36,"context_line":"#       - cRLSign"},{"line_number":37,"context_line":"#       - keyCertSign"},{"line_number":38,"context_line":"#     ttl: \"3650d\""},{"line_number":39,"context_line":"#     # standalone backend only"},{"line_number":40,"context_line":"#     provider: selfsigned"},{"line_number":41,"context_line":"#     basic_constraints: \"CA:TRUE\""},{"line_number":42,"context_line":"#     # hashi_vault backend only"},{"line_number":43,"context_line":"#     vault_path: pki"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"#pki_authorities_intermediates:"},{"line_number":46,"context_line":"#   - name: \"SnakeRootIntermediate\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"02c2fa9f_dd15c20b","line":43,"range":{"start_line":39,"start_character":0,"end_line":43,"end_character":21},"in_reply_to":"0674bf12_415ac6ab","updated":"2025-09-25 20:32:07.000000000","message":"`vault_path` defines a path where issuing certificate should be stored\n`vault_root_ca_path` is a path where root certificate resides. It\u0027s used only for intermediate certificates. Default issuer from that path will sign an intermediate cert. It\u0027s an equivalent for `signed_by` in standalone backend.\n\nI made `vault_path` explicitly configurable for each CA because:\n- `signed_by` for standalone backend is there, so it makes sense to store its equivalent for hashi_vault backend - `vault_root_ca_path` there as well. And if `vault_root_ca_path` is there, it probably makes sense to keep `vault_path` there as well because the purpose of these 2 vars is very similar\n- I assumed that in most cases people have one issuer per vault path, so having multiple issuers in one vault path is quite rare scenario. That\u0027s why people will define a separate vault_path for each intermediate certificate. But I don\u0027t have much experience with Vault so please correct me if I\u0027m wrong.\n\nThat was my intention. But I don\u0027t have a strong opinion.\nI can change that if you insist.","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"3d2a145cf642b0112d6bac27f2db960f2b285e02","unresolved":true,"context_lines":[{"line_number":36,"context_line":"#       - cRLSign"},{"line_number":37,"context_line":"#       - keyCertSign"},{"line_number":38,"context_line":"#     ttl: \"3650d\""},{"line_number":39,"context_line":"#     # standalone backend only"},{"line_number":40,"context_line":"#     provider: selfsigned"},{"line_number":41,"context_line":"#     basic_constraints: \"CA:TRUE\""},{"line_number":42,"context_line":"#     # hashi_vault backend only"},{"line_number":43,"context_line":"#     vault_path: pki"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"#pki_authorities_intermediates:"},{"line_number":46,"context_line":"#   - name: \"SnakeRootIntermediate\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"0674bf12_415ac6ab","line":43,"range":{"start_line":39,"start_character":0,"end_line":43,"end_character":21},"in_reply_to":"ee0404e1_b5ac6aae","updated":"2025-09-24 20:34:52.000000000","message":"i think i still don\u0027t understand why vault_path needs to be settable per CA?\n\nshouldnt this be a default value for the vault backend with an optional override per CA?\n\nis this the same as signed_by in the standalone backend?","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"be7943b53269eb88c1863f76aa33cd7818d01a5b","unresolved":true,"context_lines":[{"line_number":153,"context_line":"#     owner: \"root\""},{"line_number":154,"context_line":"#     group: \"root\""},{"line_number":155,"context_line":"#     mode: \"0644\""},{"line_number":156,"context_line":"#     # standalone backend only"},{"line_number":157,"context_line":"#     src: \"{{ user_ssl_cert | default(pki_dir ~ \u0027/certs/certs/myservice_\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027.crt\u0027) }}\""},{"line_number":158,"context_line":"#     # hashi_vault backend only"},{"line_number":159,"context_line":"#     cert: \"myservice_{{ ansible_facts[\u0027hostname\u0027] }}\""},{"line_number":160,"context_line":"#     type: certificate"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"9325dfef_58cf5e88","line":157,"range":{"start_line":156,"start_character":0,"end_line":157,"end_character":115},"updated":"2025-07-01 16:19:06.000000000","message":"in a sense we are conflicting two things here, the provision of a user supplied cert from a file, and the standalone pki backend\n\nit might be an idea if we simplified this and explicitly made a \"user-provided\" backend that just copied into place certs provided by the user, we probably have excessive complexity today because of that.\n\nIf we were to do that, then it is likley that we would not need different definitions here for the certificates for different backends. Ideally that would just be always `\"myservice_{{ ansible_facts[\u0027hostname\u0027] }}\"`","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"aec6f0730f92b58bafbc0b278b4626a56f59f41e","unresolved":false,"context_lines":[{"line_number":153,"context_line":"#     owner: \"root\""},{"line_number":154,"context_line":"#     group: \"root\""},{"line_number":155,"context_line":"#     mode: \"0644\""},{"line_number":156,"context_line":"#     # standalone backend only"},{"line_number":157,"context_line":"#     src: \"{{ user_ssl_cert | default(pki_dir ~ \u0027/certs/certs/myservice_\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027.crt\u0027) }}\""},{"line_number":158,"context_line":"#     # hashi_vault backend only"},{"line_number":159,"context_line":"#     cert: \"myservice_{{ ansible_facts[\u0027hostname\u0027] }}\""},{"line_number":160,"context_line":"#     type: certificate"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"8e03680a_fa44c68e","line":157,"range":{"start_line":156,"start_character":0,"end_line":157,"end_character":115},"in_reply_to":"9325dfef_58cf5e88","updated":"2025-07-17 22:34:30.000000000","message":"Done","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"be7943b53269eb88c1863f76aa33cd7818d01a5b","unresolved":true,"context_lines":[{"line_number":201,"context_line":"  apt: \"update-ca-certificates\""},{"line_number":202,"context_line":"  dnf: \"update-ca-trust extract\""},{"line_number":203,"context_line":""},{"line_number":204,"context_line":"# hashi_vault backend variables"},{"line_number":205,"context_line":"pki_hashi_vault_auth_method: userpass"},{"line_number":206,"context_line":"pki_hashi_vault_login:"},{"line_number":207,"context_line":"pki_hashi_vault_password:"},{"line_number":208,"context_line":"pki_hashi_vault_token:"},{"line_number":209,"context_line":"pki_hashi_vault_role_id:"},{"line_number":210,"context_line":"pki_hashi_vault_secret_id:"},{"line_number":211,"context_line":"pki_hashi_vault_jwt:"},{"line_number":212,"context_line":""},{"line_number":213,"context_line":"# standalone backend variables"},{"line_number":214,"context_line":"pki_dir: \"/etc/pki\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"02979b8a_438a55b4","line":211,"range":{"start_line":204,"start_character":0,"end_line":211,"end_character":20},"updated":"2025-07-01 16:19:06.000000000","message":"there should be default values for vault_path and vault_root_ca_path here rather than all over the input data.\n\nby all means make it overridable per cert with an optional variable, but not needed globally","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"aec6f0730f92b58bafbc0b278b4626a56f59f41e","unresolved":false,"context_lines":[{"line_number":201,"context_line":"  apt: \"update-ca-certificates\""},{"line_number":202,"context_line":"  dnf: \"update-ca-trust extract\""},{"line_number":203,"context_line":""},{"line_number":204,"context_line":"# hashi_vault backend variables"},{"line_number":205,"context_line":"pki_hashi_vault_auth_method: userpass"},{"line_number":206,"context_line":"pki_hashi_vault_login:"},{"line_number":207,"context_line":"pki_hashi_vault_password:"},{"line_number":208,"context_line":"pki_hashi_vault_token:"},{"line_number":209,"context_line":"pki_hashi_vault_role_id:"},{"line_number":210,"context_line":"pki_hashi_vault_secret_id:"},{"line_number":211,"context_line":"pki_hashi_vault_jwt:"},{"line_number":212,"context_line":""},{"line_number":213,"context_line":"# standalone backend variables"},{"line_number":214,"context_line":"pki_dir: \"/etc/pki\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"dd48b8e3_c71a2b98","line":211,"range":{"start_line":204,"start_character":0,"end_line":211,"end_character":20},"in_reply_to":"02979b8a_438a55b4","updated":"2025-07-17 22:34:30.000000000","message":"Done","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"3d2a145cf642b0112d6bac27f2db960f2b285e02","unresolved":true,"context_lines":[{"line_number":60,"context_line":"#     signed_by: \"SnakeRoot\""},{"line_number":61,"context_line":"#     # hashi_vault backend only"},{"line_number":62,"context_line":"#     vault_path: pki"},{"line_number":63,"context_line":"#     vault_root_ca_path: pki"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"# example variable of CA to install"},{"line_number":66,"context_line":"# pki_install_ca:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"8a242f28_e451e923","line":63,"range":{"start_line":63,"start_character":6,"end_line":63,"end_character":24},"updated":"2025-09-24 20:34:52.000000000","message":"what is this? why is it here :) same for vault_path.....","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"44d450fb6df518f570ba986b7f1b290083985127","unresolved":true,"context_lines":[{"line_number":60,"context_line":"#     signed_by: \"SnakeRoot\""},{"line_number":61,"context_line":"#     # hashi_vault backend only"},{"line_number":62,"context_line":"#     vault_path: pki"},{"line_number":63,"context_line":"#     vault_root_ca_path: pki"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"# example variable of CA to install"},{"line_number":66,"context_line":"# pki_install_ca:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"fa457e64_710a4daa","line":63,"range":{"start_line":63,"start_character":6,"end_line":63,"end_character":24},"in_reply_to":"473fcd78_a2adaf22","updated":"2025-11-05 11:44:38.000000000","message":"But can we use `vault_path` as a default value for `vault_root_ca_path`?","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"9dcb4df3f6fef1bb9a72e7d52f5537bc54878d81","unresolved":true,"context_lines":[{"line_number":60,"context_line":"#     signed_by: \"SnakeRoot\""},{"line_number":61,"context_line":"#     # hashi_vault backend only"},{"line_number":62,"context_line":"#     vault_path: pki"},{"line_number":63,"context_line":"#     vault_root_ca_path: pki"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"# example variable of CA to install"},{"line_number":66,"context_line":"# pki_install_ca:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"d079dd3b_ddfad5d3","line":63,"range":{"start_line":63,"start_character":6,"end_line":63,"end_character":24},"in_reply_to":"86e9756a_25acc9e9","updated":"2025-11-10 11:43:00.000000000","message":"so they way how I wanted to design it was:\n\n`vault_path` - path where this particular certificate will be stored\n`vault_root_ca_path` - path where the issuing certificate is stored\n\nso using `vault_root_ca_path` for `pki_authorities_roots` would break this approach(root certs do not have any issuing cert).\n\nhere\u0027s a diagram explaining the pki structure: https://ibb.co/6R3rGYBC","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"1dbdee16a4a4fb314dece19daa9a2fd1f6e67313","unresolved":true,"context_lines":[{"line_number":60,"context_line":"#     signed_by: \"SnakeRoot\""},{"line_number":61,"context_line":"#     # hashi_vault backend only"},{"line_number":62,"context_line":"#     vault_path: pki"},{"line_number":63,"context_line":"#     vault_root_ca_path: pki"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"# example variable of CA to install"},{"line_number":66,"context_line":"# pki_install_ca:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"473fcd78_a2adaf22","line":63,"range":{"start_line":63,"start_character":6,"end_line":63,"end_character":24},"in_reply_to":"8a242f28_e451e923","updated":"2025-09-25 20:32:07.000000000","message":"ouh, this example was incorrect. Fixed.\n\n`vault_path` defines a path where issuing certificate should be stored(it becomes a default issuer in that path)\n`vault_root_ca_path` is a path where root certificate resides. It\u0027s used only for intermediate certificates. Default issuer from that path will sign an intermediate cert. It\u0027s an equivalent for `signed_by` in standalone backend.","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"ccf2e8aa1dfef6ed83c848094f2dacb5a0283262","unresolved":true,"context_lines":[{"line_number":60,"context_line":"#     signed_by: \"SnakeRoot\""},{"line_number":61,"context_line":"#     # hashi_vault backend only"},{"line_number":62,"context_line":"#     vault_path: pki"},{"line_number":63,"context_line":"#     vault_root_ca_path: pki"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"# example variable of CA to install"},{"line_number":66,"context_line":"# pki_install_ca:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"7f9847b7_3f76a57f","line":63,"range":{"start_line":63,"start_character":6,"end_line":63,"end_character":24},"in_reply_to":"d079dd3b_ddfad5d3","updated":"2025-11-10 11:49:04.000000000","message":"Ok, so how about:\n\n```\npki_authorities_roots\n  vault_path: pki_root\n\npki_authorities_intermediates:\n  vault_path: pki\n  vault_root_ca_path: pki_root\n```\n\nAs it\u0027s kinda root which is special and stored separately from anything else, not vice versa?\n\nAnd also maybe you can add this diagram to docs?","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"98f86a1ec6a6ac078a3d7bdace8ba36af9a13bc5","unresolved":true,"context_lines":[{"line_number":60,"context_line":"#     signed_by: \"SnakeRoot\""},{"line_number":61,"context_line":"#     # hashi_vault backend only"},{"line_number":62,"context_line":"#     vault_path: pki"},{"line_number":63,"context_line":"#     vault_root_ca_path: pki"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"# example variable of CA to install"},{"line_number":66,"context_line":"# pki_install_ca:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"86e9756a_25acc9e9","line":63,"range":{"start_line":63,"start_character":6,"end_line":63,"end_character":24},"in_reply_to":"d8436e41_439162f0","updated":"2025-11-07 17:51:28.000000000","message":"Ok, I trust your judgement if it\u0027s needed or not.\n\nThen I have other level of confusion 😊 It might be unreasonable, but I\u0027m looking 3rd time and each time need some cycles to process.\n\nSo:\n\n\n```\npki_authorities_roots\n  vault_path: pki\n  \npki_authorities_intermediates:\n  vault_path: pki_int\n  vault_root_ca_path: pki\n```\n\nIn this layout relation between root and alternative is not super obvious to me at least. Maybe we can use `vault_root_ca_path` for `pki_authorities_roots`? or dunno. just hard to process for me.","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":true,"context_lines":[{"line_number":60,"context_line":"#     signed_by: \"SnakeRoot\""},{"line_number":61,"context_line":"#     # hashi_vault backend only"},{"line_number":62,"context_line":"#     vault_path: pki"},{"line_number":63,"context_line":"#     vault_root_ca_path: pki"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"# example variable of CA to install"},{"line_number":66,"context_line":"# pki_install_ca:"}],"source_content_type":"text/x-yaml","patch_set":18,"id":"d8436e41_439162f0","line":63,"range":{"start_line":63,"start_character":6,"end_line":63,"end_character":24},"in_reply_to":"fa457e64_710a4daa","updated":"2025-11-07 14:57:28.000000000","message":"it doesn\u0027t make sense in my opinion.\n\nI belive that in 99% cases these values will be different.\n\nMost common scenario would be to set it to:\n\n```\nvault_path: pki_int\nvault_root_ca_path: pki\n```","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"44d450fb6df518f570ba986b7f1b290083985127","unresolved":true,"context_lines":[{"line_number":23,"context_line":"pki_search_authorities_pattern: \"pki_authorities_\""},{"line_number":24,"context_line":""},{"line_number":25,"context_line":"# Example variables defining a certificate authorities"},{"line_number":26,"context_line":"# pki_authorities_roots:"},{"line_number":27,"context_line":"#   - name: \"SnakeRoot\""},{"line_number":28,"context_line":"#     email_address: \"pki@snakeoil.com\""},{"line_number":29,"context_line":"#     cn: \"Snake Oil Corp Root CA\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"c0d82d44_72f9e6f9","line":26,"range":{"start_line":26,"start_character":0,"end_line":26,"end_character":24},"updated":"2025-11-05 11:44:38.000000000","message":"this variable is not used anywhere except this example.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":true,"context_lines":[{"line_number":23,"context_line":"pki_search_authorities_pattern: \"pki_authorities_\""},{"line_number":24,"context_line":""},{"line_number":25,"context_line":"# Example variables defining a certificate authorities"},{"line_number":26,"context_line":"# pki_authorities_roots:"},{"line_number":27,"context_line":"#   - name: \"SnakeRoot\""},{"line_number":28,"context_line":"#     email_address: \"pki@snakeoil.com\""},{"line_number":29,"context_line":"#     cn: \"Snake Oil Corp Root CA\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"c34fc1bf_13c1f792","line":26,"range":{"start_line":26,"start_character":0,"end_line":26,"end_character":24},"in_reply_to":"c0d82d44_72f9e6f9","updated":"2025-11-07 14:57:28.000000000","message":"okay so:\n\nwe already have it, it wasn\u0027t something implemented in this patch: https://opendev.org/openstack/ansible-role-pki/src/branch/master/defaults/main.yml#L26\n\nit is used here(I know, things like this are super hard to trace):\nhttps://opendev.org/openstack/ansible-role-pki/src/branch/master/defaults/main.yml#L23\nhttps://opendev.org/openstack/ansible-role-pki/src/branch/master/vars/main.yml#L17","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"98f86a1ec6a6ac078a3d7bdace8ba36af9a13bc5","unresolved":false,"context_lines":[{"line_number":23,"context_line":"pki_search_authorities_pattern: \"pki_authorities_\""},{"line_number":24,"context_line":""},{"line_number":25,"context_line":"# Example variables defining a certificate authorities"},{"line_number":26,"context_line":"# pki_authorities_roots:"},{"line_number":27,"context_line":"#   - name: \"SnakeRoot\""},{"line_number":28,"context_line":"#     email_address: \"pki@snakeoil.com\""},{"line_number":29,"context_line":"#     cn: \"Snake Oil Corp Root CA\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"d51a2ac1_9385fcfb","line":26,"range":{"start_line":26,"start_character":0,"end_line":26,"end_character":24},"in_reply_to":"c34fc1bf_13c1f792","updated":"2025-11-07 17:51:28.000000000","message":"Oh, right, fair.\n\nI was really confused, as I realized we\u0027re just using `openstack_pki_authorities` which is passed as `pki_authorities`.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"44d450fb6df518f570ba986b7f1b290083985127","unresolved":true,"context_lines":[{"line_number":42,"context_line":"#     # hashi_vault backend only"},{"line_number":43,"context_line":"#     vault_path: pki"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"#pki_authorities_intermediates:"},{"line_number":46,"context_line":"#   - name: \"SnakeRootIntermediate\""},{"line_number":47,"context_line":"#     email_address: \"pki@snakeoil.com\""},{"line_number":48,"context_line":"#     cn: \"Snake Oil Corp Openstack Infrastructure Intermediate CA\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"0a0cd799_484c3925","line":45,"range":{"start_line":45,"start_character":0,"end_line":45,"end_character":31},"updated":"2025-11-05 11:44:38.000000000","message":"This variable name is not used anywhere, except this example.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":true,"context_lines":[{"line_number":42,"context_line":"#     # hashi_vault backend only"},{"line_number":43,"context_line":"#     vault_path: pki"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"#pki_authorities_intermediates:"},{"line_number":46,"context_line":"#   - name: \"SnakeRootIntermediate\""},{"line_number":47,"context_line":"#     email_address: \"pki@snakeoil.com\""},{"line_number":48,"context_line":"#     cn: \"Snake Oil Corp Openstack Infrastructure Intermediate CA\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"83b00d8c_e2fa6e2a","line":45,"range":{"start_line":45,"start_character":0,"end_line":45,"end_character":31},"in_reply_to":"0a0cd799_484c3925","updated":"2025-11-07 14:57:28.000000000","message":"it\u0027s the same as with `pki_authorities_roots`, I answered it above.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"98f86a1ec6a6ac078a3d7bdace8ba36af9a13bc5","unresolved":false,"context_lines":[{"line_number":42,"context_line":"#     # hashi_vault backend only"},{"line_number":43,"context_line":"#     vault_path: pki"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"#pki_authorities_intermediates:"},{"line_number":46,"context_line":"#   - name: \"SnakeRootIntermediate\""},{"line_number":47,"context_line":"#     email_address: \"pki@snakeoil.com\""},{"line_number":48,"context_line":"#     cn: \"Snake Oil Corp Openstack Infrastructure Intermediate CA\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"49e1dbd4_9a9b52ac","line":45,"range":{"start_line":45,"start_character":0,"end_line":45,"end_character":31},"in_reply_to":"83b00d8c_e2fa6e2a","updated":"2025-11-07 17:51:28.000000000","message":"Acknowledged","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"}],"doc/source/backends/hashi_vault.rst":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":true,"context_lines":[{"line_number":6,"context_line":"Overview"},{"line_number":7,"context_line":"~~~~~~~~"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Hashi_vault backend connects directly to the Vault instance(works with both"},{"line_number":10,"context_line":"HashiCorp Vault and OpenBao)."},{"line_number":11,"context_line":"There are several authentication mechanisms available"},{"line_number":12,"context_line":"(token, userpass, jwt etc.)."}],"source_content_type":"text/x-rst","patch_set":35,"id":"f9f155d8_92af90a5","line":9,"range":{"start_line":9,"start_character":0,"end_line":9,"end_character":11},"updated":"2025-12-22 14:07:06.000000000","message":"I think we either need to write it according to grammar (ie without underscore), or it should be literal (without capital letters), not both.","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":true,"context_lines":[{"line_number":6,"context_line":"Overview"},{"line_number":7,"context_line":"~~~~~~~~"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Hashi_vault backend connects directly to the Vault instance(works with both"},{"line_number":10,"context_line":"HashiCorp Vault and OpenBao)."},{"line_number":11,"context_line":"There are several authentication mechanisms available"},{"line_number":12,"context_line":"(token, userpass, jwt etc.)."}],"source_content_type":"text/x-rst","patch_set":35,"id":"2d9d9122_0fca4f8f","line":9,"range":{"start_line":9,"start_character":59,"end_line":9,"end_character":60},"updated":"2025-12-22 14:07:06.000000000","message":"missing space before the bracket.","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4be3937b57439b6958946c259f30ef45a1b427fe","unresolved":false,"context_lines":[{"line_number":6,"context_line":"Overview"},{"line_number":7,"context_line":"~~~~~~~~"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Hashi_vault backend connects directly to the Vault instance(works with both"},{"line_number":10,"context_line":"HashiCorp Vault and OpenBao)."},{"line_number":11,"context_line":"There are several authentication mechanisms available"},{"line_number":12,"context_line":"(token, userpass, jwt etc.)."}],"source_content_type":"text/x-rst","patch_set":35,"id":"e43e90a9_667c16f2","line":9,"range":{"start_line":9,"start_character":59,"end_line":9,"end_character":60},"in_reply_to":"2d9d9122_0fca4f8f","updated":"2025-12-23 13:35:13.000000000","message":"Done","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4be3937b57439b6958946c259f30ef45a1b427fe","unresolved":false,"context_lines":[{"line_number":6,"context_line":"Overview"},{"line_number":7,"context_line":"~~~~~~~~"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Hashi_vault backend connects directly to the Vault instance(works with both"},{"line_number":10,"context_line":"HashiCorp Vault and OpenBao)."},{"line_number":11,"context_line":"There are several authentication mechanisms available"},{"line_number":12,"context_line":"(token, userpass, jwt etc.)."}],"source_content_type":"text/x-rst","patch_set":35,"id":"3ee3b473_1caa0a98","line":9,"range":{"start_line":9,"start_character":0,"end_line":9,"end_character":11},"in_reply_to":"f9f155d8_92af90a5","updated":"2025-12-23 13:35:13.000000000","message":"Done","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":true,"context_lines":[{"line_number":11,"context_line":"There are several authentication mechanisms available"},{"line_number":12,"context_line":"(token, userpass, jwt etc.)."},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"With this backend, certificates and keys are not stored on ansible controller."},{"line_number":15,"context_line":"Instead, they are installed directly on target hosts."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Prerequisites"}],"source_content_type":"text/x-rst","patch_set":35,"id":"4bd446c2_d755788d","line":14,"range":{"start_line":14,"start_character":17,"end_line":14,"end_character":18},"updated":"2025-12-22 14:07:06.000000000","message":"is comma needed here?","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4be3937b57439b6958946c259f30ef45a1b427fe","unresolved":false,"context_lines":[{"line_number":11,"context_line":"There are several authentication mechanisms available"},{"line_number":12,"context_line":"(token, userpass, jwt etc.)."},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"With this backend, certificates and keys are not stored on ansible controller."},{"line_number":15,"context_line":"Instead, they are installed directly on target hosts."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Prerequisites"}],"source_content_type":"text/x-rst","patch_set":35,"id":"a6fd4976_c86f41d0","line":14,"range":{"start_line":14,"start_character":17,"end_line":14,"end_character":18},"in_reply_to":"4bd446c2_d755788d","updated":"2025-12-23 13:35:13.000000000","message":"Done","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":true,"context_lines":[{"line_number":20,"context_line":"- Fully configured Vault instance(either HashiCorp Vault or OpenBao)"},{"line_number":21,"context_line":"- PKI engine enabled for all used paths (``pki_root/`` and ``pki_int/`` by"},{"line_number":22,"context_line":"  default)"},{"line_number":23,"context_line":"- Vault\u0027s role defined in all paths where service certificates should be"},{"line_number":24,"context_line":"  generated ``engine_mount_point`` (``pki_int/`` by default)."},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Limitations"},{"line_number":27,"context_line":"~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":35,"id":"0272e29e_b39a1aaf","line":24,"range":{"start_line":23,"start_character":2,"end_line":24,"end_character":34},"updated":"2025-12-22 14:07:06.000000000","message":"Can you please re-phrase it? As it\u0027s hard to get the gist what it actually means, and what I as a user should do here.","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4be3937b57439b6958946c259f30ef45a1b427fe","unresolved":false,"context_lines":[{"line_number":20,"context_line":"- Fully configured Vault instance(either HashiCorp Vault or OpenBao)"},{"line_number":21,"context_line":"- PKI engine enabled for all used paths (``pki_root/`` and ``pki_int/`` by"},{"line_number":22,"context_line":"  default)"},{"line_number":23,"context_line":"- Vault\u0027s role defined in all paths where service certificates should be"},{"line_number":24,"context_line":"  generated ``engine_mount_point`` (``pki_int/`` by default)."},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Limitations"},{"line_number":27,"context_line":"~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":35,"id":"a409e043_7cadf5cb","line":24,"range":{"start_line":23,"start_character":2,"end_line":24,"end_character":34},"in_reply_to":"0272e29e_b39a1aaf","updated":"2025-12-23 13:35:13.000000000","message":"Done","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":true,"context_lines":[{"line_number":30,"context_line":"  ``engine_mount_point``"},{"line_number":31,"context_line":"- ``community.hashi_vault.vault_pki_generate_certificate`` does not allow to"},{"line_number":32,"context_line":"  pass ``key_usage`` or ``extended_key_usage`` parameter when generating a"},{"line_number":33,"context_line":"  service certificate. These parameters need to be configured in a role"},{"line_number":34,"context_line":"  configuration. Default role configuration should work perfectly fine"},{"line_number":35,"context_line":"  because it has both \"TLS Web Server Authentication\" and \"TLS Web Client"},{"line_number":36,"context_line":"  Authentication\" in extended key usage)."}],"source_content_type":"text/x-rst","patch_set":35,"id":"2754f94d_5bb71b73","line":33,"range":{"start_line":33,"start_character":67,"end_line":33,"end_character":71},"updated":"2025-12-22 14:07:06.000000000","message":"should we say `backend acl` or smth? As this make a conflict with ansible role in my mind.","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4be3937b57439b6958946c259f30ef45a1b427fe","unresolved":false,"context_lines":[{"line_number":30,"context_line":"  ``engine_mount_point``"},{"line_number":31,"context_line":"- ``community.hashi_vault.vault_pki_generate_certificate`` does not allow to"},{"line_number":32,"context_line":"  pass ``key_usage`` or ``extended_key_usage`` parameter when generating a"},{"line_number":33,"context_line":"  service certificate. These parameters need to be configured in a role"},{"line_number":34,"context_line":"  configuration. Default role configuration should work perfectly fine"},{"line_number":35,"context_line":"  because it has both \"TLS Web Server Authentication\" and \"TLS Web Client"},{"line_number":36,"context_line":"  Authentication\" in extended key usage)."}],"source_content_type":"text/x-rst","patch_set":35,"id":"f1cd5136_91f78b3f","line":33,"range":{"start_line":33,"start_character":67,"end_line":33,"end_character":71},"in_reply_to":"2754f94d_5bb71b73","updated":"2025-12-23 13:35:13.000000000","message":"yeah, it\u0027s easy to mix these two tings but we cannot say `backend acl` because Vault/OpenBao literally calls it \"role\": https://ibb.co/RGM99YMZ\n\nI renamed \"role\" to \"Vault\u0027s role\" to bring some clarity","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":true,"context_lines":[{"line_number":31,"context_line":"- ``community.hashi_vault.vault_pki_generate_certificate`` does not allow to"},{"line_number":32,"context_line":"  pass ``key_usage`` or ``extended_key_usage`` parameter when generating a"},{"line_number":33,"context_line":"  service certificate. These parameters need to be configured in a role"},{"line_number":34,"context_line":"  configuration. Default role configuration should work perfectly fine"},{"line_number":35,"context_line":"  because it has both \"TLS Web Server Authentication\" and \"TLS Web Client"},{"line_number":36,"context_line":"  Authentication\" in extended key usage)."},{"line_number":37,"context_line":""}],"source_content_type":"text/x-rst","patch_set":35,"id":"8a4cc8f3_e3f2883f","line":34,"range":{"start_line":34,"start_character":25,"end_line":34,"end_character":29},"updated":"2025-12-22 14:07:06.000000000","message":"I think here you are talking about hashi role?","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4be3937b57439b6958946c259f30ef45a1b427fe","unresolved":false,"context_lines":[{"line_number":31,"context_line":"- ``community.hashi_vault.vault_pki_generate_certificate`` does not allow to"},{"line_number":32,"context_line":"  pass ``key_usage`` or ``extended_key_usage`` parameter when generating a"},{"line_number":33,"context_line":"  service certificate. These parameters need to be configured in a role"},{"line_number":34,"context_line":"  configuration. Default role configuration should work perfectly fine"},{"line_number":35,"context_line":"  because it has both \"TLS Web Server Authentication\" and \"TLS Web Client"},{"line_number":36,"context_line":"  Authentication\" in extended key usage)."},{"line_number":37,"context_line":""}],"source_content_type":"text/x-rst","patch_set":35,"id":"5f492e5a_d752a442","line":34,"range":{"start_line":34,"start_character":25,"end_line":34,"end_character":29},"in_reply_to":"8a4cc8f3_e3f2883f","updated":"2025-12-23 13:35:13.000000000","message":"yes, i renamed \"role\" to \"Vault\u0027s role\"","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"31cc5611a77ad2113f1d85c55e39d7e4f801f601","unresolved":true,"context_lines":[{"line_number":50,"context_line":"  specified in ``signed_by`` (root certificate is not directly specified, only"},{"line_number":51,"context_line":"  the path where it resides)"},{"line_number":52,"context_line":"- when issuing service cert, ``engine_mount_point`` parameter points to the"},{"line_number":53,"context_line":"  path where certificate will be stored(default issuer from that path will sign"},{"line_number":54,"context_line":"  the certificate)"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":".. image:: ./figures/pki_paths_explained.drawio.png"}],"source_content_type":"text/x-rst","patch_set":35,"id":"2af01fde_9feaae42","line":53,"range":{"start_line":53,"start_character":39,"end_line":53,"end_character":40},"updated":"2025-12-22 14:07:06.000000000","message":"missing space before braket","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4be3937b57439b6958946c259f30ef45a1b427fe","unresolved":false,"context_lines":[{"line_number":50,"context_line":"  specified in ``signed_by`` (root certificate is not directly specified, only"},{"line_number":51,"context_line":"  the path where it resides)"},{"line_number":52,"context_line":"- when issuing service cert, ``engine_mount_point`` parameter points to the"},{"line_number":53,"context_line":"  path where certificate will be stored(default issuer from that path will sign"},{"line_number":54,"context_line":"  the certificate)"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":".. image:: ./figures/pki_paths_explained.drawio.png"}],"source_content_type":"text/x-rst","patch_set":35,"id":"97ae499a_a1bd33c1","line":53,"range":{"start_line":53,"start_character":39,"end_line":53,"end_character":40},"in_reply_to":"2af01fde_9feaae42","updated":"2025-12-23 13:35:13.000000000","message":"Done","commit_id":"cff1dc2fa72d25fdcd17f877e315ac561f3d5a7a"}],"molecule/hashi_vault/group_vars/all.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":18,"context_line":"pki_hashi_vault_password: osa-secret-pass"},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"molecule_packages:"},{"line_number":21,"context_line":"  debian:"},{"line_number":22,"context_line":"    - gnutls-bin"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"pki_setup_host: \"{{ inventory_hostname }}\""},{"line_number":25,"context_line":"pki_backend: hashi_vault"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"f6f55284_b3abbe14","line":22,"range":{"start_line":21,"start_character":0,"end_line":22,"end_character":16},"updated":"2025-11-05 11:18:14.000000000","message":"we need redhat here as well","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":false,"context_lines":[{"line_number":18,"context_line":"pki_hashi_vault_password: osa-secret-pass"},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"molecule_packages:"},{"line_number":21,"context_line":"  debian:"},{"line_number":22,"context_line":"    - gnutls-bin"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"pki_setup_host: \"{{ inventory_hostname }}\""},{"line_number":25,"context_line":"pki_backend: hashi_vault"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"ededbb1c_c4822aeb","line":22,"range":{"start_line":21,"start_character":0,"end_line":22,"end_character":16},"in_reply_to":"f6f55284_b3abbe14","updated":"2025-11-07 14:57:28.000000000","message":"fixed","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"}],"molecule/hashi_vault/molecule.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":22,"context_line":"  name: docker"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"platforms:"},{"line_number":25,"context_line":"  - name: \"pki-hashi-vault-main\""},{"line_number":26,"context_line":"    image: \"geerlingguy/docker-ubuntu2404-ansible\""},{"line_number":27,"context_line":"    pre_build_image: true"},{"line_number":28,"context_line":"    privileged: true"},{"line_number":29,"context_line":"    ansible_python_interpreter: \"/usr/bin/python3.10\""},{"line_number":30,"context_line":"    networks:"},{"line_number":31,"context_line":"      - name: molecule-network"},{"line_number":32,"context_line":"  - name: \"pki-hashi-vault-openbao\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"a489be88_9fbc1183","line":29,"range":{"start_line":25,"start_character":0,"end_line":29,"end_character":53},"updated":"2025-11-05 11:18:14.000000000","message":"This is the wrong one. We should respect `DOCKER_REGISTRY` and `DOCKER_IMAGE_TAG` defined.\n\nAs now CentOS 10 job is actually still ubuntu:\nhttps://zuul.opendev.org/t/openstack/build/252a658744944ea89a0bf61a108fd02d/log/job-output.txt#1118-1119\n\nAny reason not to do same as standalone? ie:\n```\n  - name: \"pki-${MOLECULE_SCENARIO_NAME}\"\n    image: \"${DOCKER_REGISTRY:-quay.io/gotmax23}/${DOCKER_IMAGE_TAG:-debian-systemd:bookworm}\"\n    command: ${DOCKER_COMMAND:-\"\"}\n    pre_build_image: true\n    privileged: true\n    systemd: true\n```","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"98f86a1ec6a6ac078a3d7bdace8ba36af9a13bc5","unresolved":true,"context_lines":[{"line_number":22,"context_line":"  name: docker"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"platforms:"},{"line_number":25,"context_line":"  - name: \"pki-hashi-vault-main\""},{"line_number":26,"context_line":"    image: \"geerlingguy/docker-ubuntu2404-ansible\""},{"line_number":27,"context_line":"    pre_build_image: true"},{"line_number":28,"context_line":"    privileged: true"},{"line_number":29,"context_line":"    ansible_python_interpreter: \"/usr/bin/python3.10\""},{"line_number":30,"context_line":"    networks:"},{"line_number":31,"context_line":"      - name: molecule-network"},{"line_number":32,"context_line":"  - name: \"pki-hashi-vault-openbao\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"f8c20754_a1c19803","line":29,"range":{"start_line":25,"start_character":0,"end_line":29,"end_character":53},"in_reply_to":"3102caee_f26e5ee7","updated":"2025-11-07 17:51:28.000000000","message":"Frankly... I\u0027d prefer to not support this usecase for Debian 12, then install hvac for everyone as a requirement... For instance, in pip I don\u0027t see hvac announcing support for python 3.13.\n\nBut let\u0027s discuss this part on a next meeting.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":true,"context_lines":[{"line_number":22,"context_line":"  name: docker"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"platforms:"},{"line_number":25,"context_line":"  - name: \"pki-hashi-vault-main\""},{"line_number":26,"context_line":"    image: \"geerlingguy/docker-ubuntu2404-ansible\""},{"line_number":27,"context_line":"    pre_build_image: true"},{"line_number":28,"context_line":"    privileged: true"},{"line_number":29,"context_line":"    ansible_python_interpreter: \"/usr/bin/python3.10\""},{"line_number":30,"context_line":"    networks:"},{"line_number":31,"context_line":"      - name: molecule-network"},{"line_number":32,"context_line":"  - name: \"pki-hashi-vault-openbao\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"3102caee_f26e5ee7","line":29,"range":{"start_line":25,"start_character":0,"end_line":29,"end_character":53},"in_reply_to":"a489be88_9fbc1183","updated":"2025-11-07 14:57:28.000000000","message":"very good catch! I thought that supporting different OS is not required because `DOCKER_IMAGE_TAG` is not defined anywhere. Now i se that it is defined...in integrated repo :D \n\nReasoning behind switching to ubuntu 24.04:\n- ansible hashi_vault module requires hvac\u003e\u003d1.2.1 (but in general they recommend the most recent version)\n- debian bookworm contains hvac 0.11.2 in its repositories, so its too old\n\n\nBut indeed, we still support debian bookworm so we need to be able to run molecule tests there...\n\nIn this case, the best option is probably to use hvac using pip with --break-system-packages. It\u0027s only for molecule tests/containers, so shouldn\u0027t be a problem.\n\nFor real deployments, we install hvac in ansible-runtime venv anyway: https://review.opendev.org/c/openstack/openstack-ansible/+/948888/10/requirements.txt","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"}],"molecule/hashi_vault/prepare.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":13,"context_line":"# limitations under the License."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Prepare openbao server"},{"line_number":16,"context_line":"  hosts: all"},{"line_number":17,"context_line":"  vars:"},{"line_number":18,"context_line":"    openbao_root_token: \"secret-root-token\""},{"line_number":19,"context_line":"  tasks:"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"beec9260_5ccfede8","line":16,"range":{"start_line":16,"start_character":9,"end_line":16,"end_character":12},"updated":"2025-11-05 11:18:14.000000000","message":"should it be all, or just the \"pki-hashi-vault-main\"?","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":false,"context_lines":[{"line_number":13,"context_line":"# limitations under the License."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Prepare openbao server"},{"line_number":16,"context_line":"  hosts: all"},{"line_number":17,"context_line":"  vars:"},{"line_number":18,"context_line":"    openbao_root_token: \"secret-root-token\""},{"line_number":19,"context_line":"  tasks:"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"f8257d24_ff2e6989","line":16,"range":{"start_line":16,"start_character":9,"end_line":16,"end_character":12},"in_reply_to":"beec9260_5ccfede8","updated":"2025-11-07 14:57:28.000000000","message":"hmm,\n\nthe other host(pki-hash-vault-openbao) is not a part of any group(even all) so it doesn\u0027t make any different from functional perspective.\n\nBut I fixed it as you said for better clarity.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"}],"tasks/hashi_vault/authenticate.yml":[{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"0148f1dfbe595f6e71ea6aa1272ce23e0a933a37","unresolved":true,"context_lines":[{"line_number":16,"context_line":"  community.hashi_vault.vault_login:"},{"line_number":17,"context_line":"    url: \"{{ pki_hashi_vault_host }}\""},{"line_number":18,"context_line":"    auth_method: \"{{ pki_hashi_vault_auth_method }}\""},{"line_number":19,"context_line":"    username: \"{{ pki_hashi_vault_login }}\""},{"line_number":20,"context_line":"    password: \"{{ pki_hashi_vault_password }}\""},{"line_number":21,"context_line":"    token: \"{{ pki_hashi_vault_token | default(omit) }}\""},{"line_number":22,"context_line":"    role_id: \"{{ pki_hashi_vault_role_id | default(omit) }}\""},{"line_number":23,"context_line":"    secret_id: \"{{ pki_hashi_vault_secret_id | default(omit) }}\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"68a274b2_d1222248","line":20,"range":{"start_line":19,"start_character":0,"end_line":20,"end_character":46},"updated":"2025-07-18 15:20:16.000000000","message":"are these always required? even when authenticating with a token? In a production deployment a vault token would always be the preference over a username/password.","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"dacfdda5cc6cdb3977eadb0552f62bc15616ad6a","unresolved":false,"context_lines":[{"line_number":16,"context_line":"  community.hashi_vault.vault_login:"},{"line_number":17,"context_line":"    url: \"{{ pki_hashi_vault_host }}\""},{"line_number":18,"context_line":"    auth_method: \"{{ pki_hashi_vault_auth_method }}\""},{"line_number":19,"context_line":"    username: \"{{ pki_hashi_vault_login }}\""},{"line_number":20,"context_line":"    password: \"{{ pki_hashi_vault_password }}\""},{"line_number":21,"context_line":"    token: \"{{ pki_hashi_vault_token | default(omit) }}\""},{"line_number":22,"context_line":"    role_id: \"{{ pki_hashi_vault_role_id | default(omit) }}\""},{"line_number":23,"context_line":"    secret_id: \"{{ pki_hashi_vault_secret_id | default(omit) }}\""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"780f1b81_a9556f94","line":20,"range":{"start_line":19,"start_character":0,"end_line":20,"end_character":46},"in_reply_to":"68a274b2_d1222248","updated":"2025-07-21 14:34:35.000000000","message":"ouh, good catch. Thanks!","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"3d2a145cf642b0112d6bac27f2db960f2b285e02","unresolved":true,"context_lines":[{"line_number":13,"context_line":"# limitations under the License."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to vault"},{"line_number":16,"context_line":"  community.hashi_vault.vault_login:"},{"line_number":17,"context_line":"    url: \"{{ pki_hashi_vault_host }}\""},{"line_number":18,"context_line":"    auth_method: \"{{ pki_hashi_vault_auth_method }}\""},{"line_number":19,"context_line":"    username: \"{{ pki_hashi_vault_login | default(omit) }}\""}],"source_content_type":"text/x-yaml","patch_set":18,"id":"cf1222f0_cfeb0689","line":16,"range":{"start_line":16,"start_character":2,"end_line":16,"end_character":35},"updated":"2025-09-24 20:34:52.000000000","message":"What happens when the vault authentication has already been done out of the scope of openstack-ansible?\n\nIn my environment I authenticate to vault on my local machine using a script which launches a browser-interactive OIDC/SSO auth flow against vault.\n\nSo short question - does this approach work when there is an already existing VAULT_TOKEN env var (or .vault-token file) that must be pre-created outside of the ansible code?","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"1dbdee16a4a4fb314dece19daa9a2fd1f6e67313","unresolved":true,"context_lines":[{"line_number":13,"context_line":"# limitations under the License."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to vault"},{"line_number":16,"context_line":"  community.hashi_vault.vault_login:"},{"line_number":17,"context_line":"    url: \"{{ pki_hashi_vault_host }}\""},{"line_number":18,"context_line":"    auth_method: \"{{ pki_hashi_vault_auth_method }}\""},{"line_number":19,"context_line":"    username: \"{{ pki_hashi_vault_login | default(omit) }}\""}],"source_content_type":"text/x-yaml","patch_set":18,"id":"f5dbb463_bab2eaad","line":16,"range":{"start_line":16,"start_character":2,"end_line":16,"end_character":35},"in_reply_to":"cf1222f0_cfeb0689","updated":"2025-09-25 20:32:07.000000000","message":"looking at the docs, it should be possible: https://docs.ansible.com/ansible/latest/collections/community/hashi_vault/vault_login_module.html#parameter-token\n\nyou can either use env vars(`ANSIBLE_HASHI_VAULT_TOKEN` or `VAULT_TOKEN`) to specify a token or store a token in `.vault-token` file.\n\n\nAlternatively, I can define one more parameter for this module, something like:\n\n```\n    token_file: \"{{ pki_hashi_vault_token_file | default(omit) }}\"\n```\n\nso you\u0027re not limited only to `.vault-token` file","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":false,"context_lines":[{"line_number":13,"context_line":"# limitations under the License."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to vault"},{"line_number":16,"context_line":"  community.hashi_vault.vault_login:"},{"line_number":17,"context_line":"    url: \"{{ pki_hashi_vault_host }}\""},{"line_number":18,"context_line":"    auth_method: \"{{ pki_hashi_vault_auth_method }}\""},{"line_number":19,"context_line":"    username: \"{{ pki_hashi_vault_login | default(omit) }}\""}],"source_content_type":"text/x-yaml","patch_set":18,"id":"5d105102_76eca650","line":16,"range":{"start_line":16,"start_character":2,"end_line":16,"end_character":35},"in_reply_to":"f5dbb463_bab2eaad","updated":"2025-11-05 11:18:14.000000000","message":"I think we can add `.vault-token` param in a follow-up if that will be needed. I think having an env var or default file location should be enough.","commit_id":"4eb5dd0cebf89cb0cf6bdaf0bcd98efcbb2efead"}],"tasks/hashi_vault/create_ca.yml":[{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"0148f1dfbe595f6e71ea6aa1272ce23e0a933a37","unresolved":true,"context_lines":[{"line_number":127,"context_line":"        data:"},{"line_number":128,"context_line":"          csr: \"{{ intermediate_csr.data.data.csr }}\""},{"line_number":129,"context_line":"          format: \"pem_bundle\""},{"line_number":130,"context_line":"          ttl: \"87600h\""},{"line_number":131,"context_line":"      register: signed_intermediate_cert"},{"line_number":132,"context_line":"      ignore_errors: \"{{ ansible_check_mode }}\""},{"line_number":133,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"63a56ef4_69831f52","line":130,"range":{"start_line":130,"start_character":16,"end_line":130,"end_character":22},"updated":"2025-07-18 15:20:16.000000000","message":"hardcoded?","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"dacfdda5cc6cdb3977eadb0552f62bc15616ad6a","unresolved":false,"context_lines":[{"line_number":127,"context_line":"        data:"},{"line_number":128,"context_line":"          csr: \"{{ intermediate_csr.data.data.csr }}\""},{"line_number":129,"context_line":"          format: \"pem_bundle\""},{"line_number":130,"context_line":"          ttl: \"87600h\""},{"line_number":131,"context_line":"      register: signed_intermediate_cert"},{"line_number":132,"context_line":"      ignore_errors: \"{{ ansible_check_mode }}\""},{"line_number":133,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":6,"id":"b5c1e3f4_981643a2","line":130,"range":{"start_line":130,"start_character":16,"end_line":130,"end_character":22},"in_reply_to":"63a56ef4_69831f52","updated":"2025-07-21 14:34:35.000000000","message":"fixed","commit_id":"00545ffa46446372b0baf7fdb8a4b99e3eb5926a"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":16,"context_line":"  ansible.builtin.include_tasks: \"{{ ca.backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"- name: Create CA root {{ ca.name }}"},{"line_number":19,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""},{"line_number":20,"context_line":"  when: ca.vault_root_ca_path is not defined"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"d848c462_17caf36d","line":17,"updated":"2025-11-05 11:18:14.000000000","message":"`when: vault_login_data is not defined`?","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"98f86a1ec6a6ac078a3d7bdace8ba36af9a13bc5","unresolved":true,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":16,"context_line":"  ansible.builtin.include_tasks: \"{{ ca.backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"- name: Create CA root {{ ca.name }}"},{"line_number":19,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""},{"line_number":20,"context_line":"  when: ca.vault_root_ca_path is not defined"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"cc351952_1cb4b01d","line":17,"in_reply_to":"c8c10cff_b3dd88d2","updated":"2025-11-07 17:51:28.000000000","message":"\u003e It would require users to define vault_login_data and that requires following its structure etc.\n\nHow comes? As the task will be included if it\u0027s not defined?\n\n\u003e what do we want to achieve here\n\nMinimize amount of times this include happens. As maybe here condition is not needed, but in `hashi_vault/install_ca.yml` - it\u0027s highly likely that authenticate.yml was already called here, so no need to include it one more time.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"9dcb4df3f6fef1bb9a72e7d52f5537bc54878d81","unresolved":false,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":16,"context_line":"  ansible.builtin.include_tasks: \"{{ ca.backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"- name: Create CA root {{ ca.name }}"},{"line_number":19,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""},{"line_number":20,"context_line":"  when: ca.vault_root_ca_path is not defined"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"aa746f4b_23c7d0ca","line":17,"in_reply_to":"cc351952_1cb4b01d","updated":"2025-11-10 11:43:00.000000000","message":"ahh okok, now I understand. fixed.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":true,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":16,"context_line":"  ansible.builtin.include_tasks: \"{{ ca.backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"- name: Create CA root {{ ca.name }}"},{"line_number":19,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""},{"line_number":20,"context_line":"  when: ca.vault_root_ca_path is not defined"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"c8c10cff_b3dd88d2","line":17,"in_reply_to":"d848c462_17caf36d","updated":"2025-11-07 14:57:28.000000000","message":"hmm, I don\u0027t think so. It would require users to define `vault_login_data` and that requires following its structure etc.\n\nMaybe lets start with the basics, what do we want to achieve here? Allow users to use VAULT_TOKEN they already have and skip the authentication process?\nIn this case, if I understand it correctly, it\u0027s just the matter of setting `pki_hashi_vault_auth_method` to `token`.\n\nModule will read the token in the following order(first found wins):\n\ntoken param -\u003e ansible var -\u003e ANSIBLE_HASHI_VAULT_TOKEN -\u003e VAULT_TOKEN -\u003e token fil","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"36ef405717c46f7457d18393cc724f834542db7d","unresolved":true,"context_lines":[{"line_number":18,"context_line":""},{"line_number":19,"context_line":"- name: Create CA root {{ ca.name }}"},{"line_number":20,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""},{"line_number":21,"context_line":"  when: ca.vault_root_ca_path is not defined"},{"line_number":22,"context_line":"  block:"},{"line_number":23,"context_line":"    - name: Check if CA root already exists ({{ ca.name }})"},{"line_number":24,"context_line":"      community.hashi_vault.vault_read:"}],"source_content_type":"text/x-yaml","patch_set":28,"id":"e7b356f7_6c2cba87","line":21,"range":{"start_line":21,"start_character":0,"end_line":21,"end_character":44},"updated":"2025-11-10 11:55:14.000000000","message":"Hm, is this condition is correct?\n\nShouldn\u0027t it be just `vault_path`?\n\nAs thinking of the usecase, when a user does not want to have an intermediate, just root and certs under the same path.\n\nBut now we mandate to have both of them, as the condition for root and alternate are the same?","commit_id":"e2d65a5ab2a5e659505b3ad6e9ea058b072ecbca"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"26666713231b62130cc12aa89496c03ca9b98d51","unresolved":true,"context_lines":[{"line_number":18,"context_line":""},{"line_number":19,"context_line":"- name: Create CA root {{ ca.name }}"},{"line_number":20,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""},{"line_number":21,"context_line":"  when: ca.vault_root_ca_path is not defined"},{"line_number":22,"context_line":"  block:"},{"line_number":23,"context_line":"    - name: Check if CA root already exists ({{ ca.name }})"},{"line_number":24,"context_line":"      community.hashi_vault.vault_read:"}],"source_content_type":"text/x-yaml","patch_set":28,"id":"fecb7694_67c7215c","line":21,"range":{"start_line":21,"start_character":0,"end_line":21,"end_character":44},"in_reply_to":"e7b356f7_6c2cba87","updated":"2025-11-10 13:07:28.000000000","message":"both intermediate and root certs have `vault_path` defined, while this step should be performed only for root certificates.\n\nSo...how to differentiate root certs from intermediate certs?\nOnly intermediate certs have `vault_root_ca_path`. That\u0027s why it\u0027s used in this condition.\n\n\u003e But now we mandate to have both of them, as the condition for root and alternate are the same?\n\nwhy do you think so?\n\nfor roots: `when: ca.vault_root_ca_path is not defined`\nfor certs: `when: ca.vault_root_ca_path is defined`\n\nUsing just root certificate without intermediates and signing service certs directly by root certificate should be totally doable.","commit_id":"e2d65a5ab2a5e659505b3ad6e9ea058b072ecbca"}],"tasks/hashi_vault/install_ca.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":12,"context_line":"# See the License for the specific language governing permissions and"},{"line_number":13,"context_line":"# limitations under the License."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":16,"context_line":"  ansible.builtin.include_tasks: \"{{ ca_backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"- name: Fetch CA cert ({{ ca.name }})"},{"line_number":19,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"32805b94_e7d892b4","line":16,"range":{"start_line":15,"start_character":0,"end_line":16,"end_character":91},"updated":"2025-11-05 11:18:14.000000000","message":"should we add `when: vault_login_data is not defined`?","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"4abd9bf6d99fca36544ff97e241215aa00390c91","unresolved":false,"context_lines":[{"line_number":12,"context_line":"# See the License for the specific language governing permissions and"},{"line_number":13,"context_line":"# limitations under the License."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":16,"context_line":"  ansible.builtin.include_tasks: \"{{ ca_backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"- name: Fetch CA cert ({{ ca.name }})"},{"line_number":19,"context_line":"  delegate_to: \"{{ pki_setup_host }}\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"1e09c0f1_88eb569a","line":16,"range":{"start_line":15,"start_character":0,"end_line":16,"end_character":91},"in_reply_to":"32805b94_e7d892b4","updated":"2025-11-10 11:43:48.000000000","message":"Done","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":26,"context_line":"- name: Copy CA certificate to target host ({{ ca.name }})"},{"line_number":27,"context_line":"  ansible.builtin.copy:"},{"line_number":28,"context_line":"    content: \"{{ ca_cert.data.data.certificate }}\""},{"line_number":29,"context_line":"    dest: \"{{ pki_trust_store_location[ansible_facts[\u0027pkg_mgr\u0027]] }}/{{ ca.filename | default(ca.name ~ \u0027.crt\u0027) }}\""},{"line_number":30,"context_line":"  register: ca_copy"},{"line_number":31,"context_line":"  ignore_errors: \"{{ ansible_check_mode }}\""},{"line_number":32,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"eaf4c31c_2a7287f1","line":29,"updated":"2025-11-05 11:18:14.000000000","message":"`mode` is missing here, this should kinda trigger a linting issue","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":false,"context_lines":[{"line_number":26,"context_line":"- name: Copy CA certificate to target host ({{ ca.name }})"},{"line_number":27,"context_line":"  ansible.builtin.copy:"},{"line_number":28,"context_line":"    content: \"{{ ca_cert.data.data.certificate }}\""},{"line_number":29,"context_line":"    dest: \"{{ pki_trust_store_location[ansible_facts[\u0027pkg_mgr\u0027]] }}/{{ ca.filename | default(ca.name ~ \u0027.crt\u0027) }}\""},{"line_number":30,"context_line":"  register: ca_copy"},{"line_number":31,"context_line":"  ignore_errors: \"{{ ansible_check_mode }}\""},{"line_number":32,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"3833d111_78f62463","line":29,"in_reply_to":"eaf4c31c_2a7287f1","updated":"2025-11-07 14:57:28.000000000","message":"fixed","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"}],"tasks/hashi_vault/install_cert.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":1,"context_line":"# just a placeholder"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"af01033c_23b3535f","line":1,"range":{"start_line":1,"start_character":0,"end_line":1,"end_character":20},"updated":"2025-11-05 11:18:14.000000000","message":"Would be nice to have a better explanation of what\u0027s going on here","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":false,"context_lines":[{"line_number":1,"context_line":"# just a placeholder"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"3be80429_353f551d","line":1,"range":{"start_line":1,"start_character":0,"end_line":1,"end_character":20},"in_reply_to":"af01033c_23b3535f","updated":"2025-11-07 14:57:28.000000000","message":"Done","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"}],"tasks/hashi_vault/sign_cert.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"413dd95140c9dba5d3cc7a9b907110da3527c66f","unresolved":true,"context_lines":[{"line_number":75,"context_line":"        _mode : \"{{ item.mode | d(pki_file_mode[item.type | d(\u0027certificate\u0027)]) }}\""},{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # some cert types are presented in a list, we need to make sure they are flattened and newline is added between them"},{"line_number":78,"context_line":"        content: \"{{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) }}\""},{"line_number":79,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":80,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":81,"context_line":"        group: \"{{ _group }}\""}],"source_content_type":"text/x-yaml","patch_set":16,"id":"97df3a8b_7745cff5","line":78,"range":{"start_line":78,"start_character":0,"end_line":78,"end_character":104},"updated":"2025-09-12 07:24:57.000000000","message":"I think this also should work to add a new line at the end?\n\n```suggestion\n        content: |\n          {{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) }}\n```","commit_id":"1817cbb5d9c19f91696568c1fe5b9f01610dfef1"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"6a9bfaeafd1af45ec4e824d01dea7b68d952cb29","unresolved":true,"context_lines":[{"line_number":75,"context_line":"        _mode : \"{{ item.mode | d(pki_file_mode[item.type | d(\u0027certificate\u0027)]) }}\""},{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # some cert types are presented in a list, we need to make sure they are flattened and newline is added between them"},{"line_number":78,"context_line":"        content: \"{{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) }}\""},{"line_number":79,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":80,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":81,"context_line":"        group: \"{{ _group }}\""}],"source_content_type":"text/x-yaml","patch_set":16,"id":"d647638c_c403dcaa","line":78,"range":{"start_line":78,"start_character":0,"end_line":78,"end_character":104},"in_reply_to":"7e6f22bc_0734aec1","updated":"2025-10-09 13:20:48.000000000","message":"Oh, yes, you\u0027re right. As I was testing it a bit differently which worked, but then when I simplified it - it does not 😄\n\nAs I did like that:\n```\n- hosts: localhost\n  tasks:\n    - ansible.builtin.copy:\n        dest: /tmp/content\n        content: |\n          {{ content }}\n      vars:\n        _data: [\u0027cert\u0027, \u0027ca\u0027]\n        content: \"{{ _data | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) }}\"\n        cert_data:\n          data:\n              data:\n                cert: some content\n                ca: more content\n```","commit_id":"1817cbb5d9c19f91696568c1fe5b9f01610dfef1"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"1dbdee16a4a4fb314dece19daa9a2fd1f6e67313","unresolved":true,"context_lines":[{"line_number":75,"context_line":"        _mode : \"{{ item.mode | d(pki_file_mode[item.type | d(\u0027certificate\u0027)]) }}\""},{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # some cert types are presented in a list, we need to make sure they are flattened and newline is added between them"},{"line_number":78,"context_line":"        content: \"{{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) }}\""},{"line_number":79,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":80,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":81,"context_line":"        group: \"{{ _group }}\""}],"source_content_type":"text/x-yaml","patch_set":16,"id":"7e6f22bc_0734aec1","line":78,"range":{"start_line":78,"start_character":0,"end_line":78,"end_character":104},"in_reply_to":"97df3a8b_7745cff5","updated":"2025-09-25 20:32:07.000000000","message":"ehh, I wrote the answer 2 weeks ago but I forgot to publish it :|\n\n\n\nit adds newline at the end of file - yes.\nBut it breaks the behavior of adding newline between certificates :D it just puts \u0027\\n\u0027(string) instead of actual newline.\n\nI implemented slightly different approach of fixing it.","commit_id":"1817cbb5d9c19f91696568c1fe5b9f01610dfef1"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"8080e27df5fd94e359ee5849d6b697304e303fe4","unresolved":false,"context_lines":[{"line_number":75,"context_line":"        _mode : \"{{ item.mode | d(pki_file_mode[item.type | d(\u0027certificate\u0027)]) }}\""},{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # some cert types are presented in a list, we need to make sure they are flattened and newline is added between them"},{"line_number":78,"context_line":"        content: \"{{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) }}\""},{"line_number":79,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":80,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":81,"context_line":"        group: \"{{ _group }}\""}],"source_content_type":"text/x-yaml","patch_set":16,"id":"9f81ae9e_c3f525a6","line":78,"range":{"start_line":78,"start_character":0,"end_line":78,"end_character":104},"in_reply_to":"d647638c_c403dcaa","updated":"2025-10-09 14:23:51.000000000","message":"Done","commit_id":"1817cbb5d9c19f91696568c1fe5b9f01610dfef1"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"6a9bfaeafd1af45ec4e824d01dea7b68d952cb29","unresolved":true,"context_lines":[{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # NOTE: Some cert types are presented in a list. It\u0027s required to make sure they are flattened and newline is"},{"line_number":78,"context_line":"        #       added between them."},{"line_number":79,"context_line":"        # NOTE: Blank string is added as last element of the list to make sure that newline is added and the end of"},{"line_number":80,"context_line":"        #       file. It\u0027s required when when other roles(like haproxy or zookeper) combine cert, ca_chain and private"},{"line_number":81,"context_line":"        #       key into a single file."},{"line_number":82,"context_line":"        content: \"{{ (_format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten + [\u0027\u0027]) | join(\u0027\\n\u0027) }}\""},{"line_number":83,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":84,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":85,"context_line":"        group: \"{{ _group }}\""}],"source_content_type":"text/x-yaml","patch_set":25,"id":"04a1f38c_d0bbfc38","line":82,"range":{"start_line":79,"start_character":0,"end_line":82,"end_character":113},"updated":"2025-10-09 13:20:48.000000000","message":"your variant does work indeed. Do you think it might be more readable if do just like this?\n\n`\"{{ _data | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) ~ \u0027\\n\u0027 }}\"`","commit_id":"f27c9c46ce159de2176297eb0b45319f3089ab65"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"57abd1ca080b0ba79dc21423dc2e4468e76f9872","unresolved":false,"context_lines":[{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # NOTE: Some cert types are presented in a list. It\u0027s required to make sure they are flattened and newline is"},{"line_number":78,"context_line":"        #       added between them."},{"line_number":79,"context_line":"        # NOTE: Blank string is added as last element of the list to make sure that newline is added and the end of"},{"line_number":80,"context_line":"        #       file. It\u0027s required when when other roles(like haproxy or zookeper) combine cert, ca_chain and private"},{"line_number":81,"context_line":"        #       key into a single file."},{"line_number":82,"context_line":"        content: \"{{ (_format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten + [\u0027\u0027]) | join(\u0027\\n\u0027) }}\""},{"line_number":83,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":84,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":85,"context_line":"        group: \"{{ _group }}\""}],"source_content_type":"text/x-yaml","patch_set":25,"id":"2e3a82c2_00827896","line":82,"range":{"start_line":79,"start_character":0,"end_line":82,"end_character":113},"in_reply_to":"04a1f38c_d0bbfc38","updated":"2025-10-09 14:01:38.000000000","message":"fixed","commit_id":"f27c9c46ce159de2176297eb0b45319f3089ab65"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Find certificates to install for {{ cert.name }}"},{"line_number":16,"context_line":"  ansible.builtin.set_fact:"},{"line_number":17,"context_line":"    matching_install_certificates: \u003e-"},{"line_number":18,"context_line":"      {{ _pki_install_certificates_defs"},{"line_number":19,"context_line":"         | selectattr(\u0027name\u0027, \u0027defined\u0027)"},{"line_number":20,"context_line":"         | selectattr(\u0027name\u0027, \u0027equalto\u0027, cert.name)"},{"line_number":21,"context_line":"         | list }}"},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"- name: Check if certificate files exist ({{ cert.name }})"},{"line_number":24,"context_line":"  ansible.builtin.stat:"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"08a59753_f548bec2","line":21,"range":{"start_line":17,"start_character":0,"end_line":21,"end_character":18},"updated":"2025-11-05 11:18:14.000000000","message":"Still unsure if there\u0027s a use-case to have a backend-related vars file. As this is a good candidate to go to vars file.\n\nBut it can go to `vars/main.yml` even...","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":false,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"- name: Find certificates to install for {{ cert.name }}"},{"line_number":16,"context_line":"  ansible.builtin.set_fact:"},{"line_number":17,"context_line":"    matching_install_certificates: \u003e-"},{"line_number":18,"context_line":"      {{ _pki_install_certificates_defs"},{"line_number":19,"context_line":"         | selectattr(\u0027name\u0027, \u0027defined\u0027)"},{"line_number":20,"context_line":"         | selectattr(\u0027name\u0027, \u0027equalto\u0027, cert.name)"},{"line_number":21,"context_line":"         | list }}"},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"- name: Check if certificate files exist ({{ cert.name }})"},{"line_number":24,"context_line":"  ansible.builtin.stat:"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"99a20f10_dcc41264","line":21,"range":{"start_line":17,"start_character":0,"end_line":21,"end_character":18},"in_reply_to":"08a59753_f548bec2","updated":"2025-11-07 14:57:28.000000000","message":"fixed","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":19,"context_line":"         | selectattr(\u0027name\u0027, \u0027defined\u0027)"},{"line_number":20,"context_line":"         | selectattr(\u0027name\u0027, \u0027equalto\u0027, cert.name)"},{"line_number":21,"context_line":"         | list }}"},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"- name: Check if certificate files exist ({{ cert.name }})"},{"line_number":24,"context_line":"  ansible.builtin.stat:"},{"line_number":25,"context_line":"    path: \"{{ item }}\""},{"line_number":26,"context_line":"  loop: \"{{ matching_install_certificates | map(attribute\u003d\u0027dest\u0027) }}\""},{"line_number":27,"context_line":"  register: stat_results"},{"line_number":28,"context_line":""},{"line_number":29,"context_line":"- name: Determine if certificate needs to be generated ({{ cert.name }})"},{"line_number":30,"context_line":"  ansible.builtin.set_fact:"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"c1720402_29de1c3e","line":27,"range":{"start_line":22,"start_character":0,"end_line":27,"end_character":24},"updated":"2025-11-05 11:18:14.000000000","message":"Um, maybe it\u0027s worth to use `community.crypto.x509_certificate_info` here? As this will allow also to renew certificate if it\u0027s near expiration?\n\nWould require also \"expiration\" variable. \n\nBut we can work on that as a follow-up as well.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":false,"context_lines":[{"line_number":19,"context_line":"         | selectattr(\u0027name\u0027, \u0027defined\u0027)"},{"line_number":20,"context_line":"         | selectattr(\u0027name\u0027, \u0027equalto\u0027, cert.name)"},{"line_number":21,"context_line":"         | list }}"},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"- name: Check if certificate files exist ({{ cert.name }})"},{"line_number":24,"context_line":"  ansible.builtin.stat:"},{"line_number":25,"context_line":"    path: \"{{ item }}\""},{"line_number":26,"context_line":"  loop: \"{{ matching_install_certificates | map(attribute\u003d\u0027dest\u0027) }}\""},{"line_number":27,"context_line":"  register: stat_results"},{"line_number":28,"context_line":""},{"line_number":29,"context_line":"- name: Determine if certificate needs to be generated ({{ cert.name }})"},{"line_number":30,"context_line":"  ansible.builtin.set_fact:"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"05d0c1c7_06bd4644","line":27,"range":{"start_line":22,"start_character":0,"end_line":27,"end_character":24},"in_reply_to":"c1720402_29de1c3e","updated":"2025-11-07 14:57:28.000000000","message":"yeah, please work on this in a follow-up.\nOtherwise we may never be able to merge the \"initial\" PKI patches :D","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":42,"context_line":"      loop: \"{{ matching_install_certificates | map(attribute\u003d\u0027dest\u0027) | map(\u0027dirname\u0027) | unique }}\""},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"    - name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":45,"context_line":"      ansible.builtin.include_tasks: \"{{ cert.backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"    - name: Generate certificate {{ cert.name }}"},{"line_number":48,"context_line":"      delegate_to: \"{{ pki_setup_host }}\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"a789a90a_7e726f6e","line":45,"range":{"start_line":45,"start_character":0,"end_line":45,"end_character":97},"updated":"2025-11-05 11:18:14.000000000","message":"should we add `when: vault_login_data is not defined`?","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"26666713231b62130cc12aa89496c03ca9b98d51","unresolved":false,"context_lines":[{"line_number":42,"context_line":"      loop: \"{{ matching_install_certificates | map(attribute\u003d\u0027dest\u0027) | map(\u0027dirname\u0027) | unique }}\""},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"    - name: Authenticate to {{ pki_hashi_vault_host }}"},{"line_number":45,"context_line":"      ansible.builtin.include_tasks: \"{{ cert.backend | default(pki_backend) }}/authenticate.yml\""},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"    - name: Generate certificate {{ cert.name }}"},{"line_number":48,"context_line":"      delegate_to: \"{{ pki_setup_host }}\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"cc707123_505f09ab","line":45,"range":{"start_line":45,"start_character":0,"end_line":45,"end_character":97},"in_reply_to":"a789a90a_7e726f6e","updated":"2025-11-10 13:07:28.000000000","message":"Done","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":83,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":84,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":85,"context_line":"        group: \"{{ _group }}\""},{"line_number":86,"context_line":"        mode : \"{{ _mode }}\""},{"line_number":87,"context_line":"      loop: \"{{ matching_install_certificates }}\""},{"line_number":88,"context_line":"      loop_control:"},{"line_number":89,"context_line":"        label: \u003e-"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"efb64da3_314a84fa","line":86,"range":{"start_line":86,"start_character":12,"end_line":86,"end_character":13},"updated":"2025-11-05 11:18:14.000000000","message":"2 spaces here","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":false,"context_lines":[{"line_number":83,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":84,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":85,"context_line":"        group: \"{{ _group }}\""},{"line_number":86,"context_line":"        mode : \"{{ _mode }}\""},{"line_number":87,"context_line":"      loop: \"{{ matching_install_certificates }}\""},{"line_number":88,"context_line":"      loop_control:"},{"line_number":89,"context_line":"        label: \u003e-"}],"source_content_type":"text/x-yaml","patch_set":26,"id":"e3db7de5_8a2d244d","line":86,"range":{"start_line":86,"start_character":12,"end_line":86,"end_character":13},"in_reply_to":"efb64da3_314a84fa","updated":"2025-11-07 14:57:28.000000000","message":"Done","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e4f5e5cd7328223ae186904592aafe1d1e8f7719","unresolved":true,"context_lines":[{"line_number":62,"context_line":"        engine_mount_point: \"{{ cert.engine_mount_point | default(pki_hashi_vault_engine_mount_point) }}\""},{"line_number":63,"context_line":"      register: cert_data"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"    - name: Write certificate data ({{ cert.name }})"},{"line_number":66,"context_line":"      vars:"},{"line_number":67,"context_line":"        # match user-provided cert types with the hashi_vault internal types"},{"line_number":68,"context_line":"        _format:"},{"line_number":69,"context_line":"          \"certificate\": [\u0027certificate\u0027]"},{"line_number":70,"context_line":"          \"certificate_chain\": [\u0027certificate\u0027, \u0027ca_chain\u0027]"},{"line_number":71,"context_line":"          \"ca_bundle\": [\u0027ca_chain\u0027]"},{"line_number":72,"context_line":"          \"private_key\": [\u0027private_key\u0027]"},{"line_number":73,"context_line":"        _owner: \"{{ item.owner | default(pki_install_owner) }}\""},{"line_number":74,"context_line":"        _group: \"{{ item.group | default(pki_install_group) }}\""},{"line_number":75,"context_line":"        _mode : \"{{ item.mode | d(pki_file_mode[item.type | d(\u0027certificate\u0027)]) }}\""},{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # NOTE: Some cert types are presented in a list. It\u0027s required to make sure they are flattened and newline is"},{"line_number":78,"context_line":"        #       added between them."},{"line_number":79,"context_line":"        # NOTE: Blank string is added as last element of the list to make sure that newline is added and the end of"},{"line_number":80,"context_line":"        #       file. It\u0027s required when when other roles(like haproxy or zookeper) combine cert, ca_chain and private"},{"line_number":81,"context_line":"        #       key into a single file."},{"line_number":82,"context_line":"        content: \"{{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) ~ \u0027\\n\u0027 }}\""},{"line_number":83,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":84,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":85,"context_line":"        group: \"{{ _group }}\""},{"line_number":86,"context_line":"        mode : \"{{ _mode }}\""},{"line_number":87,"context_line":"      loop: \"{{ matching_install_certificates }}\""},{"line_number":88,"context_line":"      loop_control:"},{"line_number":89,"context_line":"        label: \u003e-"},{"line_number":90,"context_line":"          name: {{ item.name }},"},{"line_number":91,"context_line":"          dest: {{ item.dest }},"},{"line_number":92,"context_line":"          type: {{ item.type }},"},{"line_number":93,"context_line":"          mode: {{ _mode }},"},{"line_number":94,"context_line":"          owner: {{ _owner }},"},{"line_number":95,"context_line":"          group: {{ _group }}"},{"line_number":96,"context_line":"      ignore_errors: \"{{ ansible_check_mode }}\""},{"line_number":97,"context_line":"      notify:"},{"line_number":98,"context_line":"        - \"{{ pki_handler_cert_installed }}\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"2eb4aad6_8dafb0bf","line":98,"range":{"start_line":65,"start_character":0,"end_line":98,"end_character":44},"updated":"2025-11-05 11:18:14.000000000","message":"Just as thought for discussion.\n\nMaybe we can do some kind of `set_fact` here for a variable matching `pki_search_install_certificates_pattern` (or just `_pki_install_certificates_candidates`, `_pki_install_certificates_def`)?\n\nThen we can move this task to `install_cert` which would somehow make it more and less confusing at the same time?\n\nNot sure if it makes much sense, but it kinda may be more slightly more clear to read.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c3da6c56af005f8a40eeb6adffdd77d52ba7c0cc","unresolved":true,"context_lines":[{"line_number":62,"context_line":"        engine_mount_point: \"{{ cert.engine_mount_point | default(pki_hashi_vault_engine_mount_point) }}\""},{"line_number":63,"context_line":"      register: cert_data"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"    - name: Write certificate data ({{ cert.name }})"},{"line_number":66,"context_line":"      vars:"},{"line_number":67,"context_line":"        # match user-provided cert types with the hashi_vault internal types"},{"line_number":68,"context_line":"        _format:"},{"line_number":69,"context_line":"          \"certificate\": [\u0027certificate\u0027]"},{"line_number":70,"context_line":"          \"certificate_chain\": [\u0027certificate\u0027, \u0027ca_chain\u0027]"},{"line_number":71,"context_line":"          \"ca_bundle\": [\u0027ca_chain\u0027]"},{"line_number":72,"context_line":"          \"private_key\": [\u0027private_key\u0027]"},{"line_number":73,"context_line":"        _owner: \"{{ item.owner | default(pki_install_owner) }}\""},{"line_number":74,"context_line":"        _group: \"{{ item.group | default(pki_install_group) }}\""},{"line_number":75,"context_line":"        _mode : \"{{ item.mode | d(pki_file_mode[item.type | d(\u0027certificate\u0027)]) }}\""},{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # NOTE: Some cert types are presented in a list. It\u0027s required to make sure they are flattened and newline is"},{"line_number":78,"context_line":"        #       added between them."},{"line_number":79,"context_line":"        # NOTE: Blank string is added as last element of the list to make sure that newline is added and the end of"},{"line_number":80,"context_line":"        #       file. It\u0027s required when when other roles(like haproxy or zookeper) combine cert, ca_chain and private"},{"line_number":81,"context_line":"        #       key into a single file."},{"line_number":82,"context_line":"        content: \"{{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) ~ \u0027\\n\u0027 }}\""},{"line_number":83,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":84,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":85,"context_line":"        group: \"{{ _group }}\""},{"line_number":86,"context_line":"        mode : \"{{ _mode }}\""},{"line_number":87,"context_line":"      loop: \"{{ matching_install_certificates }}\""},{"line_number":88,"context_line":"      loop_control:"},{"line_number":89,"context_line":"        label: \u003e-"},{"line_number":90,"context_line":"          name: {{ item.name }},"},{"line_number":91,"context_line":"          dest: {{ item.dest }},"},{"line_number":92,"context_line":"          type: {{ item.type }},"},{"line_number":93,"context_line":"          mode: {{ _mode }},"},{"line_number":94,"context_line":"          owner: {{ _owner }},"},{"line_number":95,"context_line":"          group: {{ _group }}"},{"line_number":96,"context_line":"      ignore_errors: \"{{ ansible_check_mode }}\""},{"line_number":97,"context_line":"      notify:"},{"line_number":98,"context_line":"        - \"{{ pki_handler_cert_installed }}\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"e82fe9b6_f06272fc","line":98,"range":{"start_line":65,"start_character":0,"end_line":98,"end_character":44},"in_reply_to":"2eb4aad6_8dafb0bf","updated":"2025-11-07 14:57:28.000000000","message":"I have a mixed feelings about this...\n\nFrom one perspective, you\u0027re right.\n\nBut from other perspective, moving some content to install_cert.yml may be misleading by indicating that sign_cert.yml and install_cert.yml are completely separate processes(like in standalone backend), while they always need to be executed together(so basically it\u0027s just one process).\n\nI looked at this from that perspective when writing the code - to make it clear that sign\u0026install processes always come together.\nFor now, I just improved the placeholder message in install_cert.yml as you asked.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"98f86a1ec6a6ac078a3d7bdace8ba36af9a13bc5","unresolved":false,"context_lines":[{"line_number":62,"context_line":"        engine_mount_point: \"{{ cert.engine_mount_point | default(pki_hashi_vault_engine_mount_point) }}\""},{"line_number":63,"context_line":"      register: cert_data"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"    - name: Write certificate data ({{ cert.name }})"},{"line_number":66,"context_line":"      vars:"},{"line_number":67,"context_line":"        # match user-provided cert types with the hashi_vault internal types"},{"line_number":68,"context_line":"        _format:"},{"line_number":69,"context_line":"          \"certificate\": [\u0027certificate\u0027]"},{"line_number":70,"context_line":"          \"certificate_chain\": [\u0027certificate\u0027, \u0027ca_chain\u0027]"},{"line_number":71,"context_line":"          \"ca_bundle\": [\u0027ca_chain\u0027]"},{"line_number":72,"context_line":"          \"private_key\": [\u0027private_key\u0027]"},{"line_number":73,"context_line":"        _owner: \"{{ item.owner | default(pki_install_owner) }}\""},{"line_number":74,"context_line":"        _group: \"{{ item.group | default(pki_install_group) }}\""},{"line_number":75,"context_line":"        _mode : \"{{ item.mode | d(pki_file_mode[item.type | d(\u0027certificate\u0027)]) }}\""},{"line_number":76,"context_line":"      ansible.builtin.copy:"},{"line_number":77,"context_line":"        # NOTE: Some cert types are presented in a list. It\u0027s required to make sure they are flattened and newline is"},{"line_number":78,"context_line":"        #       added between them."},{"line_number":79,"context_line":"        # NOTE: Blank string is added as last element of the list to make sure that newline is added and the end of"},{"line_number":80,"context_line":"        #       file. It\u0027s required when when other roles(like haproxy or zookeper) combine cert, ca_chain and private"},{"line_number":81,"context_line":"        #       key into a single file."},{"line_number":82,"context_line":"        content: \"{{ _format[item.type] | map(\u0027extract\u0027, cert_data.data.data) | flatten | join(\u0027\\n\u0027) ~ \u0027\\n\u0027 }}\""},{"line_number":83,"context_line":"        dest: \"{{ item.dest }}\""},{"line_number":84,"context_line":"        owner: \"{{ _owner }}\""},{"line_number":85,"context_line":"        group: \"{{ _group }}\""},{"line_number":86,"context_line":"        mode : \"{{ _mode }}\""},{"line_number":87,"context_line":"      loop: \"{{ matching_install_certificates }}\""},{"line_number":88,"context_line":"      loop_control:"},{"line_number":89,"context_line":"        label: \u003e-"},{"line_number":90,"context_line":"          name: {{ item.name }},"},{"line_number":91,"context_line":"          dest: {{ item.dest }},"},{"line_number":92,"context_line":"          type: {{ item.type }},"},{"line_number":93,"context_line":"          mode: {{ _mode }},"},{"line_number":94,"context_line":"          owner: {{ _owner }},"},{"line_number":95,"context_line":"          group: {{ _group }}"},{"line_number":96,"context_line":"      ignore_errors: \"{{ ansible_check_mode }}\""},{"line_number":97,"context_line":"      notify:"},{"line_number":98,"context_line":"        - \"{{ pki_handler_cert_installed }}\""}],"source_content_type":"text/x-yaml","patch_set":26,"id":"e539cd57_5a383dc8","line":98,"range":{"start_line":65,"start_character":0,"end_line":98,"end_character":44},"in_reply_to":"e82fe9b6_f06272fc","updated":"2025-11-07 17:51:28.000000000","message":"Yes, let\u0027s do that in follow-up when re-working how we handle logic for standalone.","commit_id":"d8fc1dc4bfd9d86c127edcf346a903c34b6e79e8"}]}
