Skip to content

Improve Debian 13 support: hammer, IPA auth, bug fixes - #427

Open
jakduch wants to merge 10 commits into
theforeman:debianfrom
jakduch:debian-13-improvements
Open

jakduch wants to merge 10 commits into
theforeman:debianfrom
jakduch:debian-13-improvements

Conversation

@jakduch

@jakduch jakduch commented Mar 28, 2026 •

Copy link
Copy Markdown
Contributor

Rebased onto the current debian branch. Changes that are already present in the base branch, including Debian repository setup, were dropped during the rebase.

The remaining changes:

  • Make HTTPD IPA external authentication OS-aware, using Debian module packages and a2enmod/a2dismod where appropriate
  • Fix the httpd_conf_path expansion in the external-auth cleanup task
  • Use OS-specific Hammer package names for Debian and Red Hat systems
  • Use the OS-specific Apache account for the Foreman and Pulp systemd sockets
  • Deploy Hammer in the Debian CI job and run its feature tests instead of marking them as expected failures

@jakduch jakduch mentioned this pull request Mar 28, 2026
@jakduch

jakduch commented Mar 28, 2026

Copy link
Copy Markdown
Contributor Author

This PR builds on @evgeni's Debian 13 work in #235. It targets the debian branch directly so the commits can be cherry-picked or merged into #235.

See my comment on #235 for the full description of changes.

@evgeni
evgeni force-pushed the debian branch 4 times, most recently from 5fe9467 to feb639e Compare June 3, 2026 13:49
@evgeni
evgeni force-pushed the debian branch 7 times, most recently from a757829 to a7faf2e Compare June 25, 2026 07:21
@ehelms
ehelms marked this pull request as draft July 22, 2026 01:45
@ehelms

ehelms commented Jul 22, 2026

Copy link
Copy Markdown
Member

Moving to draft as this will need a rebase and update to match the current state of the code base.

@evgeni
evgeni force-pushed the debian branch 2 times, most recently from 90ad408 to b1948f3 Compare September 9, 2026 11:04
- Use OS-specific package names for IPA Apache modules
  (mod_* on RedHat, libapache2-mod-* on Debian)
- On RedHat: load modules via conf files in conf.modules.d
- On Debian: enable modules via apache2_module (a2enmod)
- Add httpd_ipa_packages and httpd_ipa_load_modules to
  both RedHat.yaml and Debian.yaml vars
Add OS-specific vars files for hammer role to use correct package
naming conventions (hammer-cli-plugin-* on RedHat, ruby-hammer-cli-*
on Debian). Load OS vars via include_vars and remove hardcoded
package name pattern from defaults.
- Fix spurious space in httpd_conf_path variable expansion
- On RedHat: remove module conf files from conf.modules.d
- On Debian: disable modules via apache2_module (a2dismod)
- Use httpd_ipa_load_modules flag to select correct method
Ran the Hammer deployment and its feature tests on Debian after adding OS-specific package names.
@jakduch
jakduch force-pushed the debian-13-improvements branch from 1416454 to 573c2d5 Compare September 25, 2026 08:17
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: d6bac859-822b-48b7-b717-60ab699b5f5c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jakduch
jakduch marked this pull request as ready for review September 25, 2026 08:17
@jakduch

jakduch commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Rebased onto the current debian branch and updated the remaining changes to match the current code. The Debian commits already present upstream were dropped, including the repository setup that is now handled by setup_repositories. The remaining diff keeps the OS-aware IPA and Hammer setup, enables Hammer in the Debian CI job, and removes the Debian xfails so the Hammer feature tests actually run. Marking this ready for review again.

Used the OS-specific Apache account for Foreman and Pulp systemd sockets so Debian does not fail with status 217/USER.
@jakduch

jakduch commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

The first rebased CI run exposed one real Debian failure: foreman.socket used the hard-coded apache account and systemd failed with 217/USER. I switched the Foreman and Pulp sockets to the existing OS-specific httpd_user value (www-data on Debian, apache on Red Hat). The other matrix failures all happened before deployment while Vagrant Cloud returned HTTP 502 for box metadata; the new push has started a full pipeline again.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

The latest run had two real Debian packaging failures in addition to the Vagrant Cloud 502s. I fixed the Hammer mapping so plugin underscores become Debian package hyphens (foreman_tasks → ruby-hammer-cli-foreman-tasks) and added a focused unit test; all 16 filter tests pass.\n\nThe sosreport failure comes from the shared forklift role. I opened the minimal fix in theforeman/forklift#1992, linked to its own issue. This push starts a fresh full pipeline; the sos collection step remains externally blocked until that helper fix lands.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

The Debian job exposed one more package mapping issue: the official trixie repository has ruby-hammer-cli-foreman-tasks, but no ruby-hammer-cli-katello. I now skip that unsupported plugin on Debian and added it to the mapping regression test. The focused unit suite is 16/16 green and Ruff passes.

The separate sosreport failure is already fixed by theforeman/forklift#1992; this branch will pick it up once that PR is merged.

@jakduch
jakduch force-pushed the debian-13-improvements branch from 8f1445d to 91dc232 Compare September 26, 2026 19:49
@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

The Debian job got past the initial Hammer deployment and then failed in Deploy features on the missing ruby-hammer-cli-foreman-azure-rm package. I checked the complete current Trixie Hammer package index instead of adding another one-off exception. 91dc232 now uses an explicit allowlist for every packaged plugin and skips the currently unpackaged Azure RM, Katello, and RH Cloud plugins. The focused unit suite is 16/16 green and Ruff passes. The remaining sosreport failure is still the separate theforeman/forklift#1992 issue.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

The fresh Debian job on 91dc232 has passed both Deploy hammer and the previously failing Deploy features step. The test suite is running now.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Found the Debian test failure in the fresh job. Apache is enabled by the package before the role writes its WantedBy=foreman.target drop-in, so the later enabled: true does not re-enable it and the foreman.target.wants/apache2.service link is missing. Backup stops Apache through PartOf, but starting the target cannot bring it back; the later API failures are a cascade from that.

Fixed in e58f67e by explicitly ensuring the idempotent wants link before daemon reload. The existing httpd and target lifecycle integration checks cover the link and stop/start behavior. Local YAML/diff checks and all 16 focused unit tests pass.

The separate sosreport package failure is still covered by theforeman/forklift#1992.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Also fixed the independent Debian SELinux test failure in 103127c. The test now checks contexts only when SELinux is actually enabled and uses the OS-specific Apache config/module paths. Ruff, diff checks, and collection of all 27 httpd tests pass locally.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

I checked all 14 current matrix failures individually. Every one fails only in Start VMs with The requested URL returned error: 502 while downloading Vagrant box metadata, before any branch code or deployment runs. This is the shared external outage tracked in #886.

Ansible/Python lint are green, and the Debian job is still running.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Fixed the remaining Debian-specific test gaps in 9421116:

  • the Debian server job now uses a CentOS Stream 10 client, since the client scenarios explicitly require dnf, subscription-manager, and RHSM
  • the SSL probe uses POSIX printf; the failed job showed that Debian dash sent literal -e GET /ssl-error-test
  • the webhook listener now uses the netcat-traditional listen syntax required by Debian; the same job showed the listener exiting before Dynflow got ECONNREFUSED

The focused regression checks pass locally (19 tests). The remaining katello_events / hammer ping failure is a separate stale PID issue after the backup restart and is tracked in #889. The missing Debian sosreport package is already covered by forklift#1992.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

The fresh head run is blocked before any branch code executes. I checked all 15 failed jobs individually; every one fails only in Start VMs with the exact Vagrant metadata error The requested URL returned error: 502.

The Debian job also confirms the new split is applied (debian/trixie64 server, centos/stream10 client): the Debian VM comes up, then the client box metadata request gets the same 502.

This external failure is covered by #886, which is fully green and mergeable. I am not starting another blind rerun while Vagrant Cloud is still returning 502s.

@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

Verified the current heads. PR #427 at 9421116 and its debian base b1948f3 still use a one-shot vagrant up; neither contains the bounded retry from PR #886 at 1f904a2.

In run 36273545722, all 15 executing jobs fail in Start VMs with the exact Vagrant metadata HTTP 502 error; the 16th failure is only the aggregate gate.

Because PR #886 targets master while this PR targets debian, merging it alone will not update this branch. The retry must reach debian or be applied here before another CI run is useful. I have not started a blind rerun.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants