)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"84294aeb7b3be7e9405ff15166473d3aa239bdd2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":16,"id":"e893ec28_49c1a7e5","updated":"2025-07-15 12:45:21.000000000","message":"recheck - stepca job timed out","commit_id":"97f106e179b164e536417d28f335c505dccae613"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c5b382b2e22502386d0a270935f6a5237631b18e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":17,"id":"da675a90_94ea5364","updated":"2025-07-18 10:35:53.000000000","message":"we need to update examples in defaults/main.yml","commit_id":"a720387e21831c363916cfa2148baed760091e4b"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"2ce6cc8f4940f229e7ac8290e23fca164d998b41","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"593e6aa2_0acbd849","updated":"2025-08-12 13:26:56.000000000","message":"i think this one is fine to go? or?","commit_id":"fc7db0207421dc97b484cf2ef04784292cc683f2"}],"molecule/default/group_vars/all.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"7a27ed61ab6e034cfe6061ec78f6cd7e19f10dec","unresolved":true,"context_lines":[{"line_number":136,"context_line":"functional_install_key_name_1_dest: \"{{ \u0027/root/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_name_1.key.pem\u0027 }}\""},{"line_number":137,"context_line":""},{"line_number":138,"context_line":"pki_install_certificates:"},{"line_number":139,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/certs/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1.crt\u0027 }}\""},{"line_number":140,"context_line":"    dest: \"{{ functional_install_cert_1_dest }}\""},{"line_number":141,"context_line":"    owner: \"root\""},{"line_number":142,"context_line":"    group: \"root\""},{"line_number":143,"context_line":"    mode: \"0644\""},{"line_number":144,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/certs/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1-chain.crt\u0027 }}\""},{"line_number":145,"context_line":"    dest: \"{{ functional_install_chain_1_dest }}\""},{"line_number":146,"context_line":"    owner: \"root\""},{"line_number":147,"context_line":"    group: \"root\""},{"line_number":148,"context_line":"    mode: \"0644\""},{"line_number":149,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/certs/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1-ca_bundle.crt\u0027 }}\""},{"line_number":150,"context_line":"    dest: \"{{ functional_install_ca_bundle_1_dest }}\""},{"line_number":151,"context_line":"    owner: \"root\""},{"line_number":152,"context_line":"    group: \"root\""},{"line_number":153,"context_line":"    mode: \"0644\""},{"line_number":154,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/private/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1.key.pem\u0027 }}\""},{"line_number":155,"context_line":"    dest: \"{{ functional_install_key_1_dest }}\""},{"line_number":156,"context_line":"    owner: \"root\""},{"line_number":157,"context_line":"    group: \"root\""},{"line_number":158,"context_line":"    mode: \"0640\""},{"line_number":159,"context_line":"  - name: \"{{ ansible_facts[\u0027hostname\u0027] ~ \u0027_1\u0027 }}\""},{"line_number":160,"context_line":"    dest: \"{{ functional_install_cert_name_1_dest }}\""},{"line_number":161,"context_line":"    type: \"certificate\""}],"source_content_type":"text/x-yaml","patch_set":18,"id":"b670977e_a58640a5","line":158,"range":{"start_line":139,"start_character":0,"end_line":158,"end_character":16},"updated":"2025-08-19 07:19:48.000000000","message":"Wouldn\u0027t this conflict? As both src and dst seems the same?","commit_id":"fc7db0207421dc97b484cf2ef04784292cc683f2"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"e8a72276d8e412c58c6abb293b3d2c77a1905cec","unresolved":false,"context_lines":[{"line_number":136,"context_line":"functional_install_key_name_1_dest: \"{{ \u0027/root/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_name_1.key.pem\u0027 }}\""},{"line_number":137,"context_line":""},{"line_number":138,"context_line":"pki_install_certificates:"},{"line_number":139,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/certs/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1.crt\u0027 }}\""},{"line_number":140,"context_line":"    dest: \"{{ functional_install_cert_1_dest }}\""},{"line_number":141,"context_line":"    owner: \"root\""},{"line_number":142,"context_line":"    group: \"root\""},{"line_number":143,"context_line":"    mode: \"0644\""},{"line_number":144,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/certs/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1-chain.crt\u0027 }}\""},{"line_number":145,"context_line":"    dest: \"{{ functional_install_chain_1_dest }}\""},{"line_number":146,"context_line":"    owner: \"root\""},{"line_number":147,"context_line":"    group: \"root\""},{"line_number":148,"context_line":"    mode: \"0644\""},{"line_number":149,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/certs/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1-ca_bundle.crt\u0027 }}\""},{"line_number":150,"context_line":"    dest: \"{{ functional_install_ca_bundle_1_dest }}\""},{"line_number":151,"context_line":"    owner: \"root\""},{"line_number":152,"context_line":"    group: \"root\""},{"line_number":153,"context_line":"    mode: \"0644\""},{"line_number":154,"context_line":"  - src: \"{{ pki_dir ~ \u0027/certs/private/\u0027 ~ ansible_facts[\u0027hostname\u0027] ~ \u0027_1.key.pem\u0027 }}\""},{"line_number":155,"context_line":"    dest: \"{{ functional_install_key_1_dest }}\""},{"line_number":156,"context_line":"    owner: \"root\""},{"line_number":157,"context_line":"    group: \"root\""},{"line_number":158,"context_line":"    mode: \"0640\""},{"line_number":159,"context_line":"  - name: \"{{ ansible_facts[\u0027hostname\u0027] ~ \u0027_1\u0027 }}\""},{"line_number":160,"context_line":"    dest: \"{{ functional_install_cert_name_1_dest }}\""},{"line_number":161,"context_line":"    type: \"certificate\""}],"source_content_type":"text/x-yaml","patch_set":18,"id":"3b9ea62c_28ac0d09","line":158,"range":{"start_line":139,"start_character":0,"end_line":158,"end_character":16},"in_reply_to":"b670977e_a58640a5","updated":"2025-08-19 07:22:54.000000000","message":"ok, disregard","commit_id":"fc7db0207421dc97b484cf2ef04784292cc683f2"}],"tasks/main_certs.yml":[{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"c5b382b2e22502386d0a270935f6a5237631b18e","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    cert_dir: \"{{ pki_dir }}/certs\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"    # construct the path to the source when \"name\" is specified"},{"line_number":32,"context_line":"    _source_files:"},{"line_number":33,"context_line":"      \"certificate\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027.crt\u0027 }}\""},{"line_number":34,"context_line":"      \"certificate_chain\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-chain.crt\u0027 }}\""},{"line_number":35,"context_line":"      \"ca_bundle\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-ca_bundle.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":17,"id":"e2894eae_d978eda5","line":32,"updated":"2025-07-18 10:35:53.000000000","message":"if we add support for another type: cert+ca_bundle+key (we can call it \"combined\" or something like this), we can get rid of:\n\n\nhttps://opendev.org/openstack/ansible-role-zookeeper/src/branch/master/handlers/main.yml#L16\nhttps://opendev.org/openstack/openstack-ansible-haproxy_server/src/branch/master/handlers/main.yml#L16\n\n\nSo we won\u0027t need to fix them for hashi_vault backend:\nhttps://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/949417\nhttps://review.opendev.org/c/openstack/ansible-role-zookeeper/+/949421","commit_id":"a720387e21831c363916cfa2148baed760091e4b"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"675a7cbb7bd3138a83947e511c6902fe85d11b59","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    cert_dir: \"{{ pki_dir }}/certs\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"    # construct the path to the source when \"name\" is specified"},{"line_number":32,"context_line":"    _source_files:"},{"line_number":33,"context_line":"      \"certificate\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027.crt\u0027 }}\""},{"line_number":34,"context_line":"      \"certificate_chain\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-chain.crt\u0027 }}\""},{"line_number":35,"context_line":"      \"ca_bundle\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-ca_bundle.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":17,"id":"2672c0e6_ec222333","line":32,"in_reply_to":"07e07074_2431debc","updated":"2025-07-23 18:14:38.000000000","message":"Tbh I personally would pick b), as this usecase is relatively niche. And also it\u0027s getting complicated with permissions to such file very quickly.\n\nAnd `regen pem` is not _that_ terrible problem tbh for such usecase.","commit_id":"a720387e21831c363916cfa2148baed760091e4b"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"883e4e5292e7129a2899f92351e53eb078ed24a3","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    cert_dir: \"{{ pki_dir }}/certs\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"    # construct the path to the source when \"name\" is specified"},{"line_number":32,"context_line":"    _source_files:"},{"line_number":33,"context_line":"      \"certificate\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027.crt\u0027 }}\""},{"line_number":34,"context_line":"      \"certificate_chain\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-chain.crt\u0027 }}\""},{"line_number":35,"context_line":"      \"ca_bundle\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-ca_bundle.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":17,"id":"3ea9b2ff_883e7133","line":32,"in_reply_to":"2672c0e6_ec222333","updated":"2025-07-24 09:40:38.000000000","message":"\u003e They would need to prepare that file outside ansible-role-pki(like we do with this \u0027regen pem\u0027 handler) which just doesn\u0027t look optimal to me.\n\nDunno, this looks totally fine to me. As this could be extended waaay longer, ie - what if somebody need to import the certificate in java certstore? Should we cover this as well?\n\nSo as long as we return cert/chain and key, and notify about changes - that should be fine and other role calling for `pki` should be able to handle that.","commit_id":"a720387e21831c363916cfa2148baed760091e4b"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"9213b78fb55f047dd48fc10ec6d85d3cde618255","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    cert_dir: \"{{ pki_dir }}/certs\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"    # construct the path to the source when \"name\" is specified"},{"line_number":32,"context_line":"    _source_files:"},{"line_number":33,"context_line":"      \"certificate\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027.crt\u0027 }}\""},{"line_number":34,"context_line":"      \"certificate_chain\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-chain.crt\u0027 }}\""},{"line_number":35,"context_line":"      \"ca_bundle\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-ca_bundle.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":17,"id":"783a2059_6f96ec07","line":32,"in_reply_to":"67c0afc7_27724a23","updated":"2025-07-21 13:28:14.000000000","message":"hmm, I don\u0027t think so.\n\nMy proposal aims to let pki role install certificate on a target host in a format that is really expected on the target host. It will eliminate the need to run the awkward \u0027Regen PEM\u0027 handler just to convert the certificate into the expected format.\nIn this case, private key does not have to be always available from the PKI role. It has to be available when cert is installed - but it\u0027s already the case now.\n\nOf course, there\u0027s another scenario where user deploys zookeeper without the PKI role. But in this case, it\u0027s totally okay to expect user to store certificate in a format expected by zookeeper(cert, ca_bundle and private key in a single file) on a target host.","commit_id":"a720387e21831c363916cfa2148baed760091e4b"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"235d3634d9fc7b450aba1ffc60ef3f0d738b2463","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    cert_dir: \"{{ pki_dir }}/certs\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"    # construct the path to the source when \"name\" is specified"},{"line_number":32,"context_line":"    _source_files:"},{"line_number":33,"context_line":"      \"certificate\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027.crt\u0027 }}\""},{"line_number":34,"context_line":"      \"certificate_chain\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-chain.crt\u0027 }}\""},{"line_number":35,"context_line":"      \"ca_bundle\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-ca_bundle.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":17,"id":"fb9f0f8c_c78e81d5","line":32,"in_reply_to":"783a2059_6f96ec07","updated":"2025-07-23 08:44:41.000000000","message":"\u003e In this case, private key does not have to be always available from the PKI role. \u003e It has to be available when cert is installed - but it\u0027s already the case now.\n\nSo what Jonathan means, I assume, is that in ideal world, which we wanna reach, private key is not gonna be stored on deploy host as today. Potentially, neither will certs (why to store them without the private key).\nThus, we would need to have things formatted on destination directly, but that would also assume implementation of certs verification and renewal.\n\nBut I can be wrong in these assumptions ofc.","commit_id":"a720387e21831c363916cfa2148baed760091e4b"},{"author":{"_account_id":25023,"name":"Jonathan Rosser","email":"jonathan.rosser@rd.bbc.co.uk","username":"jrosser"},"change_message_id":"ed369d40ad85aedaa00860a5d2da9b436b8d46ff","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    cert_dir: \"{{ pki_dir }}/certs\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"    # construct the path to the source when \"name\" is specified"},{"line_number":32,"context_line":"    _source_files:"},{"line_number":33,"context_line":"      \"certificate\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027.crt\u0027 }}\""},{"line_number":34,"context_line":"      \"certificate_chain\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-chain.crt\u0027 }}\""},{"line_number":35,"context_line":"      \"ca_bundle\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-ca_bundle.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":17,"id":"67c0afc7_27724a23","line":32,"in_reply_to":"e2894eae_d978eda5","updated":"2025-07-18 15:22:07.000000000","message":"This assumes that the key is always available from the PKI role. In a completely pure implementation the private key would be generated on the target host and never leave it, so would not be available to create such a bundle including the private key.","commit_id":"a720387e21831c363916cfa2148baed760091e4b"},{"author":{"_account_id":32666,"name":"Damian Dąbrowski","email":"damian@dabrowski.cloud","username":"ddabrowski"},"change_message_id":"e358fd022d5f74a911987343730121947fa6a398","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    cert_dir: \"{{ pki_dir }}/certs\""},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"    # construct the path to the source when \"name\" is specified"},{"line_number":32,"context_line":"    _source_files:"},{"line_number":33,"context_line":"      \"certificate\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027.crt\u0027 }}\""},{"line_number":34,"context_line":"      \"certificate_chain\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-chain.crt\u0027 }}\""},{"line_number":35,"context_line":"      \"ca_bundle\": \"{{ cert_dir ~ \u0027/certs/\u0027 ~ item.name ~ \u0027-ca_bundle.crt\u0027 }}\""}],"source_content_type":"text/x-yaml","patch_set":17,"id":"07e07074_2431debc","line":32,"in_reply_to":"fb9f0f8c_c78e81d5","updated":"2025-07-23 15:29:24.000000000","message":"we had a discussion about this on IRC recently.\nIt\u0027s not directly related to storing certs and keys on a deploy host. It\u0027s about being aware of the private key when ansible-role-pki installs certficiate.\n\nFor standalone backend, pki role is aware of it because cert \u0026 key is stored on a deploy host.\nHashi_vault backend is also aware of it, even though we don\u0027t store cert or key on a deploy host(because on each cert installation it generates new cert\u0026key).\n\nBut if we implement \"standalone v2\" backend in the future which will be completely unaware of private keys because it will just sign CSRs, then we have a problem and implementing `cert+ca_bundle+key` format would not be possible without adding some complexity into this backend(it would need to be aware of the path on the target host where the key is stored).\n\nBut current behavior(`regen pem` handler in haproxy and zookeeper role to combine cert+ca_bundle+key) may be problematic as well.\nLet\u0027s imagine that someone uses ansible-role-pki with some custom software that also expects cert+key combined in a single file.\nThey would need to prepare that file outside ansible-role-pki(like we do with this \u0027regen pem\u0027 handler) which just doesn\u0027t look optimal to me.\nso idk...maybe there is no perfect solution and we need to choose the lesser evil.\n\nBut we need to decide what to choose:\n\na) get rid of the `regen pem` handlers(it will work flawlessly for standalone and hashi-vault backends) o combine cert+key in a single file when needed, and deal with `standalone v2` backend in the future\nb) accept the fact that pki role can install certs in different formats, but it cannot combine cert and key into a single file","commit_id":"a720387e21831c363916cfa2148baed760091e4b"}]}
