Skip to content

Add legacy auth bundle format - #892

Open
jakduch wants to merge 1 commit into
theforeman:masterfrom
jakduch:feature/573-legacy-auth-bundle
Open

jakduch wants to merge 1 commit into
theforeman:masterfrom
jakduch:feature/573-legacy-auth-bundle

Conversation

@jakduch

@jakduch jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Why are you introducing these changes? (Problem description, related links)

Foremanctl auth bundles use the new deployment layout, but an N-1 proxy managed by foreman-installer still expects the puppet-certs ssl-build layout.

Fixes #573

What are the changes introduced in this pull request?

  • add an auth-bundle --legacy mode with the exact ssl-build filenames consumed by puppet-certs
  • write the legacy archive to a separate hostname-certs.tar.gz file so it cannot be confused with the current auth bundle
  • preserve the existing auth bundle layout and add regression coverage for both formats

How to test this pull request

  • run ansible-lint on the auth_bundle role
  • run Ruff on tests/auth_bundle_test.py
  • run the auth_bundle role for both formats and inspect both archives with tar tzf

Checklist

  • Tests added/updated
  • Documentation updated

This pull request was created with assistance from OpenAI Codex.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 33 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 0ee3fc52-93dc-4b14-bed1-8c0f21a5d06f

📥 Commits

Reviewing files that changed from the base of the PR and between 6c79648 and f9039ba.

📒 Files selected for processing (8)
  • docs/user/certificates.md
  • docs/user/parameters.md
  • src/playbooks/auth-bundle/metadata.obsah.yaml
  • src/roles/auth_bundle/defaults/main.yml
  • src/roles/auth_bundle/tasks/current.yml
  • src/roles/auth_bundle/tasks/legacy.yml
  • src/roles/auth_bundle/tasks/main.yml
  • tests/auth_bundle_test.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jakduch
jakduch force-pushed the feature/573-legacy-auth-bundle branch from 9c9fb5e to 6a1b192 Compare September 26, 2026 22:27
@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

CI for the latest head is waiting for maintainer approval in this run.

@jakduch
jakduch force-pushed the feature/573-legacy-auth-bundle branch from 6a1b192 to f9039ba Compare September 26, 2026 23:45
@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

The exact-head failures were unrelated to this change. The FIPS Stream 9 job hit an Ansible Galaxy HTTP 500 while downloading community.general. The fapolicyd Stream 9 job and Stream 10 job failed in the existing PostgreSQL backup poll tracked by issue #862 and fixed by the fully green PR #863. All auth-bundle generation and proxy deployment steps passed. I retriggered the complete pipeline with an unchanged tree: run 36280410659.

@jakduch

jakduch commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

The complete exact-head run reached all jobs. The PR-specific auth bundle tests passed; the remaining failures are unrelated to this branch. Satellite and IOP Stream 10 hit the backup success fixture before three Foreman tasks had finished. That race is now tracked in issue #894 and fixed by PR #895. IOP Stream 9 hit the same race and later a VM-wide OOM that killed Candlepin. I left this branch unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Certificate bundle generation should handle a legacy format for N-1

1 participant