{"id":850,"sha1":"96234c54c65adafb53075e788087b96e0f04b851","playbook":{"id":4,"items":{"plays":107,"tasks":2438,"results":2413,"hosts":13,"files":511,"records":0},"arguments":{"version":null,"verbosity":0,"private_key_file":null,"remote_user":null,"connection":"openstack.osa.ssh","timeout":null,"ssh_common_args":null,"sftp_extra_args":null,"scp_extra_args":null,"ssh_extra_args":null,"ask_pass":false,"connection_password_file":null,"force_handlers":true,"flush_cache":false,"become":false,"become_method":"sudo","become_user":null,"become_ask_pass":false,"become_password_file":null,"tags":["all"],"skip_tags":[],"check":false,"diff":false,"inventory":["/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/dynamic_inventory.py","/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/inventory.ini","/etc/openstack_deploy/inventory.ini"],"listhosts":false,"subset":null,"extra_vars":"Not saved by ARA as configured by 'ignored_arguments'","vault_ids":[],"ask_vault_pass":false,"vault_password_files":[],"forks":4,"module_path":null,"syntax":false,"listtasks":false,"listtags":false,"step":false,"start_at_task":null,"args":["setup-openstack.yml"]},"labels":[{"id":1,"name":"check:False"},{"id":2,"name":"tags:all"}],"started":"2025-12-14T10:21:40.790759Z","ended":"2025-12-14T11:05:36.775743Z","duration":"00:43:55.984984","name":null,"ansible_version":"2.18.6","client_version":"1.7.4","python_version":"3.13.5","server_version":"1.7.4","status":"completed","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible/playbooks/setup-openstack.yml","controller":"aio1.openstack.local","user":"root"},"content":"---\n# Copyright 2015, Rackspace US, Inc.\n#\n# Licensed under the Apache License, Version 2.0 (the \"License\");\n# you may not use this file except in compliance with the License.\n# You may obtain a copy of the License at\n#\n#     http://www.apache.org/licenses/LICENSE-2.0\n#\n# Unless required by applicable law or agreed to in writing, software\n# distributed under the License is distributed on an \"AS IS\" BASIS,\n# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n# See the License for the specific language governing permissions and\n# limitations under the License.\n\n# This script is being created with mode 0755 intentionally. This is so that the\n#  script can be executed by root to rotate the keys as needed. The script being\n#  executed will always change it's user context to the keystone user before\n#  execution and while the script may be world read/executable its contains only\n#  the necessary bits that are required to run the rotate and sync commands.\n- name: Drop credential key auto rotate script\n  ansible.builtin.template:\n    src: \"keystone-credential-rotate.sh.j2\"\n    dest: \"{{ keystone_credential_auto_rotation_script }}\"\n    owner: \"{{ keystone_system_user_name }}\"\n    group: \"{{ keystone_system_group_name }}\"\n    mode: \"0755\"\n\n# This creates the auto rotation job on the first keystone host.\n- name: Create auto rotation job\n  ansible.builtin.cron:\n    name: \"Credential auto rotate job\"\n    special_time: \"{{ keystone_credential_rotation }}\"\n    user: \"{{ keystone_system_user_name }}\"\n    job: \"{{ keystone_credential_auto_rotation_script }}\"\n    cron_file: keystone-credential-rotate\n  when: _keystone_is_first_play_host\n\n# This makes sure that no auto rotation jobs are on any other hosts.\n- name: Remove extra auto rotation job\n  ansible.builtin.cron:\n    name: \"Credential auto rotate job\"\n    user: \"{{ keystone_system_user_name }}\"\n    cron_file: keystone-credential-rotate\n    state: \"absent\"\n  when: not _keystone_is_first_play_host\n","created":"2025-12-14T10:25:02.217652Z","updated":"2025-12-14T10:25:02.217664Z","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible-os_keystone/tasks/keystone_credential_autorotate.yml"}