)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"1fd7cf9913f76fd3ede7baa5c4e538403811593f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"4f2054b8_6468f452","updated":"2023-05-16 07:06:54.000000000","message":"recheck","commit_id":"d7aa23806fd97e708cda9d2e36e912961d80490d"},{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"c5109bd09fa813be7402658e6c05ffe1c0b902dd","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":21,"id":"5cbbb2df_6b2d9937","updated":"2023-06-08 08:05:20.000000000","message":"The last two lines need to be removed","commit_id":"553b50c0cb0262cc05b669bff87cfb112ab273bf"},{"author":{"_account_id":16515,"name":"mbu","email":"mat.bultel@gmail.com","username":"matbu"},"change_message_id":"74a3eab822a7ce6480d8445ec285a4b093c51131","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":23,"id":"d667779f_df9d5666","updated":"2023-06-13 13:29:58.000000000","message":"Can you add more info in the commit message (BZ or LP) and context.\n\nThanks","commit_id":"28eb62e555a0d6efa55fbc9af5f0765336d37525"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"c178439963469ead714ea17033141bffc4765287","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":23,"id":"dcd5a414_8f99e8d9","updated":"2023-06-08 13:38:59.000000000","message":"recheck","commit_id":"28eb62e555a0d6efa55fbc9af5f0765336d37525"},{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"96376561ec6cd2aa1da33d953730571a55e4e9f2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":23,"id":"dd90993a_5de66cea","updated":"2023-06-09 14:41:05.000000000","message":"recheck","commit_id":"28eb62e555a0d6efa55fbc9af5f0765336d37525"}],"tripleo_ansible/playbooks/ssh_key_rotation.yaml":[{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":13,"context_line":"# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the"},{"line_number":14,"context_line":"# License for the specific language governing permissions and limitations"},{"line_number":15,"context_line":"# under the License."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"- name: Initialize undercloud facts"},{"line_number":18,"context_line":"  hosts: undercloud"},{"line_number":19,"context_line":"  gather_facts: yes"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"58c59e18_25fd3e4a","line":16,"updated":"2023-03-02 11:54:57.000000000","message":"Its worth a bit of documentation here explaining exactly whats going on, so that the subsequent steps make sense.  I see the steps as:\n- backup keys directory on overcloud and undercloud nodes\n- on undercloud, create new key in a temporary folder\n- copy over NEW public key to authorized_keys on overcloud nodes using OLD keys as creds\n- replace the OLD public and private keys with the NEW public and private keys on the undercloud node\n- clean up OLD public keys in authorized_keys on the overcloud nodes using NEW keys","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":47,"context_line":"        temp_folder_path: \"{{ temp_folder.path }}\""},{"line_number":48,"context_line":"    - debug: var\u003dtemp_folder_path"},{"line_number":49,"context_line":"    - set_fact:"},{"line_number":50,"context_line":"        private_key_path: \"{{ temp_folder_path }}/{{ key_name }}\""},{"line_number":51,"context_line":"    - set_fact:"},{"line_number":52,"context_line":"        public_key_path: \"{{ private_key_path }}.pub\""},{"line_number":53,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"cda62c17_961678b1","line":50,"range":{"start_line":50,"start_character":8,"end_line":50,"end_character":24},"updated":"2023-03-02 11:54:57.000000000","message":"temp_private_key_path","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":47,"context_line":"        temp_folder_path: \"{{ temp_folder.path }}\""},{"line_number":48,"context_line":"    - debug: var\u003dtemp_folder_path"},{"line_number":49,"context_line":"    - set_fact:"},{"line_number":50,"context_line":"        private_key_path: \"{{ temp_folder_path }}/{{ key_name }}\""},{"line_number":51,"context_line":"    - set_fact:"},{"line_number":52,"context_line":"        public_key_path: \"{{ private_key_path }}.pub\""},{"line_number":53,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"5ff779d9_a891c3f3","line":50,"range":{"start_line":50,"start_character":8,"end_line":50,"end_character":24},"in_reply_to":"cda62c17_961678b1","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":49,"context_line":"    - set_fact:"},{"line_number":50,"context_line":"        private_key_path: \"{{ temp_folder_path }}/{{ key_name }}\""},{"line_number":51,"context_line":"    - set_fact:"},{"line_number":52,"context_line":"        public_key_path: \"{{ private_key_path }}.pub\""},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"# TODO(afaranha): Maybe we shouldn\u0027t create backup directory."},{"line_number":55,"context_line":"- name: Create undercloud backup directory"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"f8bfa48e_13d3ee51","line":52,"range":{"start_line":52,"start_character":8,"end_line":52,"end_character":23},"updated":"2023-03-02 11:54:57.000000000","message":"temp_public_key_path","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":49,"context_line":"    - set_fact:"},{"line_number":50,"context_line":"        private_key_path: \"{{ temp_folder_path }}/{{ key_name }}\""},{"line_number":51,"context_line":"    - set_fact:"},{"line_number":52,"context_line":"        public_key_path: \"{{ private_key_path }}.pub\""},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"# TODO(afaranha): Maybe we shouldn\u0027t create backup directory."},{"line_number":55,"context_line":"- name: Create undercloud backup directory"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7305cfae_a984a8be","line":52,"range":{"start_line":52,"start_character":8,"end_line":52,"end_character":23},"in_reply_to":"f8bfa48e_13d3ee51","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":52,"context_line":"        public_key_path: \"{{ private_key_path }}.pub\""},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"# TODO(afaranha): Maybe we shouldn\u0027t create backup directory."},{"line_number":55,"context_line":"- name: Create undercloud backup directory"},{"line_number":56,"context_line":"  hosts: undercloud"},{"line_number":57,"context_line":"  remote_user: \"{{ deployment_user }}\""},{"line_number":58,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"9a58f2e4_1c8128e8","line":55,"range":{"start_line":55,"start_character":2,"end_line":55,"end_character":42},"updated":"2023-03-02 11:54:57.000000000","message":"Is this step needed?  Won\u0027t copy create the relevant directory if it doesn\u0027t exist?\nWe could just backup the whole directory and not worry about creating this.","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":52,"context_line":"        public_key_path: \"{{ private_key_path }}.pub\""},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"# TODO(afaranha): Maybe we shouldn\u0027t create backup directory."},{"line_number":55,"context_line":"- name: Create undercloud backup directory"},{"line_number":56,"context_line":"  hosts: undercloud"},{"line_number":57,"context_line":"  remote_user: \"{{ deployment_user }}\""},{"line_number":58,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"0d827072_1089abec","line":55,"range":{"start_line":55,"start_character":2,"end_line":55,"end_character":42},"in_reply_to":"9a58f2e4_1c8128e8","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":63,"context_line":"        state: directory"},{"line_number":64,"context_line":"        mode: \u0027700\u0027"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"- name: Create overcloud backup directory"},{"line_number":67,"context_line":"  hosts: overcloud"},{"line_number":68,"context_line":"  remote_user: heat-admin"},{"line_number":69,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"b74b3f2a_a9ea09cf","line":66,"range":{"start_line":66,"start_character":1,"end_line":66,"end_character":41},"updated":"2023-03-02 11:54:57.000000000","message":"ditto as above","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":63,"context_line":"        state: directory"},{"line_number":64,"context_line":"        mode: \u0027700\u0027"},{"line_number":65,"context_line":""},{"line_number":66,"context_line":"- name: Create overcloud backup directory"},{"line_number":67,"context_line":"  hosts: overcloud"},{"line_number":68,"context_line":"  remote_user: heat-admin"},{"line_number":69,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"d2d50e07_e7bae32b","line":66,"range":{"start_line":66,"start_character":1,"end_line":66,"end_character":41},"in_reply_to":"b74b3f2a_a9ea09cf","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":85,"context_line":"        src: \"{{ keys_folder_path }}/\""},{"line_number":86,"context_line":"        dest: \"{{ backup_folder_path }}\""},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"- name: Backup heat-admin overcloud keys"},{"line_number":89,"context_line":"  hosts: overcloud"},{"line_number":90,"context_line":"  remote_user: heat-admin"},{"line_number":91,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"8caaea68_cc026de9","line":88,"range":{"start_line":88,"start_character":0,"end_line":88,"end_character":14},"updated":"2023-03-02 11:54:57.000000000","message":"We need to see if this is still relevant or use tripleo-admin instead?","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":85,"context_line":"        src: \"{{ keys_folder_path }}/\""},{"line_number":86,"context_line":"        dest: \"{{ backup_folder_path }}\""},{"line_number":87,"context_line":""},{"line_number":88,"context_line":"- name: Backup heat-admin overcloud keys"},{"line_number":89,"context_line":"  hosts: overcloud"},{"line_number":90,"context_line":"  remote_user: heat-admin"},{"line_number":91,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"c3659bfb_78e80eaa","line":88,"range":{"start_line":88,"start_character":0,"end_line":88,"end_character":14},"in_reply_to":"8caaea68_cc026de9","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":97,"context_line":"      dest: \"{{ backup_folder_path }}\""},{"line_number":98,"context_line":"      remote_src: yes"},{"line_number":99,"context_line":""},{"line_number":100,"context_line":"- name: Generate new stack keys"},{"line_number":101,"context_line":"  hosts: undercloud"},{"line_number":102,"context_line":"  remote_user: \"{{ deployment_user }}\""},{"line_number":103,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e25a75c4_4eb2e21a","line":100,"range":{"start_line":100,"start_character":8,"end_line":100,"end_character":31},"updated":"2023-03-02 11:54:57.000000000","message":"Generate new stack keys in temporary directory","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":97,"context_line":"      dest: \"{{ backup_folder_path }}\""},{"line_number":98,"context_line":"      remote_src: yes"},{"line_number":99,"context_line":""},{"line_number":100,"context_line":"- name: Generate new stack keys"},{"line_number":101,"context_line":"  hosts: undercloud"},{"line_number":102,"context_line":"  remote_user: \"{{ deployment_user }}\""},{"line_number":103,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e12f819f_9ad05b6d","line":100,"range":{"start_line":100,"start_character":8,"end_line":100,"end_character":31},"in_reply_to":"e25a75c4_4eb2e21a","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":104,"context_line":"  tasks:"},{"line_number":105,"context_line":"    - name: Generate private key"},{"line_number":106,"context_line":"      openssh_keypair:"},{"line_number":107,"context_line":"        path: \"{{ private_key_path }}\""},{"line_number":108,"context_line":"        size: \"{{ key_size | default(\u00274096\u0027) }}\""},{"line_number":109,"context_line":"        type: \"{{ key_type | default(\u0027rsa\u0027) }}\""},{"line_number":110,"context_line":"        force: True"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"fabafa90_2de24c67","line":107,"range":{"start_line":107,"start_character":18,"end_line":107,"end_character":34},"updated":"2023-03-02 11:54:57.000000000","message":"temp_private_key_path","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":104,"context_line":"  tasks:"},{"line_number":105,"context_line":"    - name: Generate private key"},{"line_number":106,"context_line":"      openssh_keypair:"},{"line_number":107,"context_line":"        path: \"{{ private_key_path }}\""},{"line_number":108,"context_line":"        size: \"{{ key_size | default(\u00274096\u0027) }}\""},{"line_number":109,"context_line":"        type: \"{{ key_type | default(\u0027rsa\u0027) }}\""},{"line_number":110,"context_line":"        force: True"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"bcb198f6_de1cfb06","line":107,"range":{"start_line":107,"start_character":18,"end_line":107,"end_character":34},"in_reply_to":"fabafa90_2de24c67","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":109,"context_line":"        type: \"{{ key_type | default(\u0027rsa\u0027) }}\""},{"line_number":110,"context_line":"        force: True"},{"line_number":111,"context_line":""},{"line_number":112,"context_line":"- name: Add stack key to heat-admin overcloud authorized_keys"},{"line_number":113,"context_line":"  hosts: overcloud"},{"line_number":114,"context_line":"  remote_user: heat-admin"},{"line_number":115,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"49831b1a_8fdd1eb1","line":112,"range":{"start_line":112,"start_character":8,"end_line":112,"end_character":61},"updated":"2023-03-02 11:54:57.000000000","message":"Add new stack public key to heat-admin overcloud authorized_keys\n\nNote:  You need to make sure heat-admin is the correct thing to use here and not tripleo-admin","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":109,"context_line":"        type: \"{{ key_type | default(\u0027rsa\u0027) }}\""},{"line_number":110,"context_line":"        force: True"},{"line_number":111,"context_line":""},{"line_number":112,"context_line":"- name: Add stack key to heat-admin overcloud authorized_keys"},{"line_number":113,"context_line":"  hosts: overcloud"},{"line_number":114,"context_line":"  remote_user: heat-admin"},{"line_number":115,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"c8d621c4_f10a9cbe","line":112,"range":{"start_line":112,"start_character":8,"end_line":112,"end_character":61},"in_reply_to":"49831b1a_8fdd1eb1","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":118,"context_line":"      authorized_key:"},{"line_number":119,"context_line":"        user: heat-admin"},{"line_number":120,"context_line":"        state: present"},{"line_number":121,"context_line":"        key: \"{{ lookup(\u0027file\u0027, \u0027{{ hostvars[\u0027undercloud\u0027][\u0027public_key_path\u0027] }}\u0027) }}\""},{"line_number":122,"context_line":""},{"line_number":123,"context_line":"- name: Update stack keys on undercloud"},{"line_number":124,"context_line":"  hosts: undercloud"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"223b482e_574b4640","line":121,"range":{"start_line":121,"start_character":60,"end_line":121,"end_character":75},"updated":"2023-03-02 11:54:57.000000000","message":"temp_public_key_path","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":118,"context_line":"      authorized_key:"},{"line_number":119,"context_line":"        user: heat-admin"},{"line_number":120,"context_line":"        state: present"},{"line_number":121,"context_line":"        key: \"{{ lookup(\u0027file\u0027, \u0027{{ hostvars[\u0027undercloud\u0027][\u0027public_key_path\u0027] }}\u0027) }}\""},{"line_number":122,"context_line":""},{"line_number":123,"context_line":"- name: Update stack keys on undercloud"},{"line_number":124,"context_line":"  hosts: undercloud"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"6865f4d8_fb0a22af","line":121,"range":{"start_line":121,"start_character":60,"end_line":121,"end_character":75},"in_reply_to":"223b482e_574b4640","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":120,"context_line":"        state: present"},{"line_number":121,"context_line":"        key: \"{{ lookup(\u0027file\u0027, \u0027{{ hostvars[\u0027undercloud\u0027][\u0027public_key_path\u0027] }}\u0027) }}\""},{"line_number":122,"context_line":""},{"line_number":123,"context_line":"- name: Update stack keys on undercloud"},{"line_number":124,"context_line":"  hosts: undercloud"},{"line_number":125,"context_line":"  remote_user: \"{{ deployment_user }}\""},{"line_number":126,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"03dda7e6_585423fd","line":123,"range":{"start_line":123,"start_character":8,"end_line":123,"end_character":39},"updated":"2023-03-02 11:54:57.000000000","message":"Replace old public and private keys for stack on the undercloud","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":120,"context_line":"        state: present"},{"line_number":121,"context_line":"        key: \"{{ lookup(\u0027file\u0027, \u0027{{ hostvars[\u0027undercloud\u0027][\u0027public_key_path\u0027] }}\u0027) }}\""},{"line_number":122,"context_line":""},{"line_number":123,"context_line":"- name: Update stack keys on undercloud"},{"line_number":124,"context_line":"  hosts: undercloud"},{"line_number":125,"context_line":"  remote_user: \"{{ deployment_user }}\""},{"line_number":126,"context_line":"  gather_facts: no"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"766e5e56_2043e385","line":123,"range":{"start_line":123,"start_character":8,"end_line":123,"end_character":39},"in_reply_to":"03dda7e6_585423fd","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":140,"context_line":"        src: \"{{ public_key_path }}\""},{"line_number":141,"context_line":"        dest: \"{{ keys_folder_path }}/\""},{"line_number":142,"context_line":""},{"line_number":143,"context_line":"- name: Remove old stack key from heat-admin overcloud authorized_keys"},{"line_number":144,"context_line":"  hosts: overcloud"},{"line_number":145,"context_line":"  remote_user: heat-admin"},{"line_number":146,"context_line":"  gather_facts: no"},{"line_number":147,"context_line":"  tasks:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"4afbece7_455e354f","line":144,"range":{"start_line":143,"start_character":7,"end_line":144,"end_character":18},"updated":"2023-03-02 11:54:57.000000000","message":"This may need to be tripleo-admin instead.","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":140,"context_line":"        src: \"{{ public_key_path }}\""},{"line_number":141,"context_line":"        dest: \"{{ keys_folder_path }}/\""},{"line_number":142,"context_line":""},{"line_number":143,"context_line":"- name: Remove old stack key from heat-admin overcloud authorized_keys"},{"line_number":144,"context_line":"  hosts: overcloud"},{"line_number":145,"context_line":"  remote_user: heat-admin"},{"line_number":146,"context_line":"  gather_facts: no"},{"line_number":147,"context_line":"  tasks:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e64b95e6_46a4c4b3","line":144,"range":{"start_line":143,"start_character":7,"end_line":144,"end_character":18},"in_reply_to":"4afbece7_455e354f","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":161,"context_line":"        user: deployment_user"},{"line_number":162,"context_line":"        state: absent"},{"line_number":163,"context_line":"        key: \"{{ lookup(\u0027file\u0027, \u0027{{ backup_folder_path }}/{{ key_name }}.pub\u0027) }}\""},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"- name: Remove old mistral key"},{"line_number":166,"context_line":"  hosts: undercloud"},{"line_number":167,"context_line":"  remote_user: \"{{ deployment_user }}\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"42851dd6_03de47eb","line":164,"updated":"2023-03-02 11:54:57.000000000","message":"All this mistral stuff below may or may not be relevant anymore","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":161,"context_line":"        user: deployment_user"},{"line_number":162,"context_line":"        state: absent"},{"line_number":163,"context_line":"        key: \"{{ lookup(\u0027file\u0027, \u0027{{ backup_folder_path }}/{{ key_name }}.pub\u0027) }}\""},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"- name: Remove old mistral key"},{"line_number":166,"context_line":"  hosts: undercloud"},{"line_number":167,"context_line":"  remote_user: \"{{ deployment_user }}\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"0cc6282b_7b1f8a85","line":164,"in_reply_to":"42851dd6_03de47eb","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"94b26f0a1895e273603d7edcb7e70f2a0bd4e671","unresolved":true,"context_lines":[{"line_number":191,"context_line":"  tasks:"},{"line_number":192,"context_line":"    - name: Authorizing new mistral ssh_key"},{"line_number":193,"context_line":"      shell: openstack overcloud admin authorize"},{"line_number":194,"context_line":""},{"line_number":195,"context_line":"- name: Replace old nova keypair on undercloud"},{"line_number":196,"context_line":"  hosts: undercloud"},{"line_number":197,"context_line":"  remote_user: \"{{ deployment_user }}\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"81e7d34d_33f83d8f","line":194,"updated":"2023-03-02 11:54:57.000000000","message":"Not sure if this is relevant anymore. As I recall, nova has been removed from the undercloud.","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":34120,"name":"Andre Aranha","display_name":"afariasa","email":"afariasa@redhat.com","username":"afariasa"},"change_message_id":"681a4dc10164d9ce8114620ab4195c0b79cd2caf","unresolved":false,"context_lines":[{"line_number":191,"context_line":"  tasks:"},{"line_number":192,"context_line":"    - name: Authorizing new mistral ssh_key"},{"line_number":193,"context_line":"      shell: openstack overcloud admin authorize"},{"line_number":194,"context_line":""},{"line_number":195,"context_line":"- name: Replace old nova keypair on undercloud"},{"line_number":196,"context_line":"  hosts: undercloud"},{"line_number":197,"context_line":"  remote_user: \"{{ deployment_user }}\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"cf635955_699bf1af","line":194,"in_reply_to":"81e7d34d_33f83d8f","updated":"2023-04-20 13:02:06.000000000","message":"Done","commit_id":"ddfd0b8a9664ae8e270c4193327bb649c7966fc2"},{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"bf21ac13134b3c7f8968856e1e1b37daf85ccab7","unresolved":true,"context_lines":[{"line_number":107,"context_line":"  hosts: allovercloud"},{"line_number":108,"context_line":"  gather_facts: false"},{"line_number":109,"context_line":"  tasks:"},{"line_number":110,"context_line":"  - name: Copy"},{"line_number":111,"context_line":"    copy:"},{"line_number":112,"context_line":"      backup: true"},{"line_number":113,"context_line":"      src: /home/{{ ansible_user_id }}/.ssh/"}],"source_content_type":"text/x-yaml","patch_set":11,"id":"9568bbf4_6ff34345","line":110,"range":{"start_line":110,"start_character":10,"end_line":110,"end_character":14},"updated":"2023-05-19 20:50:34.000000000","message":"More descriptive name would be nice","commit_id":"fc0b13f728848d1b151c88cbbf258706449f0690"},{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"bf21ac13134b3c7f8968856e1e1b37daf85ccab7","unresolved":true,"context_lines":[{"line_number":130,"context_line":"      register: ssh_output"},{"line_number":131,"context_line":"    - debug: var\u003dssh_output"},{"line_number":132,"context_line":""},{"line_number":133,"context_line":"- name: Add stack key to tripleo-admin overcloud authorized_keys"},{"line_number":134,"context_line":"  hosts: allovercloud"},{"line_number":135,"context_line":"  gather_facts: false"},{"line_number":136,"context_line":"  tasks:"}],"source_content_type":"text/x-yaml","patch_set":11,"id":"b3b88537_957b6d87","line":133,"range":{"start_line":133,"start_character":25,"end_line":133,"end_character":38},"updated":"2023-05-19 20:50:34.000000000","message":"{{ ansible_user_id }}","commit_id":"fc0b13f728848d1b151c88cbbf258706449f0690"},{"author":{"_account_id":22954,"name":"Juan Badia Payno","email":"jbadiapa@redhat.com","username":"jbadiapa"},"change_message_id":"bf21ac13134b3c7f8968856e1e1b37daf85ccab7","unresolved":true,"context_lines":[{"line_number":166,"context_line":"        src: \"{{ temp_public_key_path }}\""},{"line_number":167,"context_line":"        dest: \"{{ keys_folder_path }}/{{ tripleo_key_name }}.pub\""},{"line_number":168,"context_line":""},{"line_number":169,"context_line":"- name: Remove old stack key from tripleo-admin overcloud authorized_keys"},{"line_number":170,"context_line":"  hosts: allovercloud"},{"line_number":171,"context_line":"  gather_facts: false"},{"line_number":172,"context_line":"  tasks:"}],"source_content_type":"text/x-yaml","patch_set":11,"id":"742b7c36_1f1610f0","line":169,"range":{"start_line":169,"start_character":34,"end_line":169,"end_character":47},"updated":"2023-05-19 20:50:34.000000000","message":"this should be {{ ansible_user_id }}","commit_id":"fc0b13f728848d1b151c88cbbf258706449f0690"},{"author":{"_account_id":8833,"name":"Rabi Mishra","email":"ramishra@redhat.com","username":"rabi"},"change_message_id":"14db6221d64e9db9f1ac7018985f799e62103916","unresolved":true,"context_lines":[{"line_number":21,"context_line":"    - name: Register undercloud variabled"},{"line_number":22,"context_line":"      set_fact:"},{"line_number":23,"context_line":"        backup_folder_path: \"/home/{{ ansible_user_id }}/backup_keys/{{ ansible_date_time.epoch }}\""},{"line_number":24,"context_line":"        keys_folder_path: \"/home/{{ ansible_user_id }}/.ssh\""},{"line_number":25,"context_line":"        key_name: \"{{ key_name | default(\u0027id_rsa\u0027) }}\""},{"line_number":26,"context_line":"        key_size: \"{{ key_size | default(\u00274096\u0027) }}\""},{"line_number":27,"context_line":"        tripleo_key_name: \"{{ tripleo_key_name | default(\u0027id_rsa_tripleo\u0027) }}\""}],"source_content_type":"text/x-yaml","patch_set":24,"id":"1fbc10ff_bae045f8","line":24,"updated":"2023-09-07 07:12:53.000000000","message":"This default won\u0027t work for upgrade.\n\nDuring undercloud upgrade we fetch the keys from mistral environment and keep them in default_Working_dir[1] for the stack. They\u0027re the ones used dueing overcloud upgrade[2]. If we\u0027re rotating the keys we should also change them in the `default_working_dir`.\n\n\n[1] https://github.com/openstack/tripleo-heat-templates/blob/stable/wallaby/scripts/undercloud-upgrade-ephemeral-heat.py#L415-L429\n[2] https://github.com/openstack/python-tripleoclient/blob/stable/wallaby/tripleoclient/utils.py#L1641-L1647","commit_id":"34088a2083b81cd904601a42ea14f580a3734e40"}]}
