{"id":624,"sha1":"608e1bac4887c1908a5317133d01e3896691d53b","playbook":{"id":4,"items":{"plays":32,"tasks":1505,"results":1497,"hosts":12,"files":487,"records":0},"arguments":{"version":null,"verbosity":0,"private_key_file":null,"remote_user":null,"connection":"openstack.osa.ssh","timeout":null,"ssh_common_args":null,"sftp_extra_args":null,"scp_extra_args":null,"ssh_extra_args":null,"ask_pass":false,"connection_password_file":null,"force_handlers":true,"flush_cache":false,"become":false,"become_method":"sudo","become_user":null,"become_ask_pass":false,"become_password_file":null,"tags":["all"],"skip_tags":[],"check":false,"diff":false,"inventory":["/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/dynamic_inventory.py","/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/inventory.ini","/etc/openstack_deploy/inventory.ini"],"listhosts":false,"subset":null,"extra_vars":"Not saved by ARA as configured by 'ignored_arguments'","vault_ids":[],"ask_vault_pass":false,"vault_password_files":[],"forks":4,"module_path":null,"syntax":false,"listtasks":false,"listtags":false,"step":false,"start_at_task":null,"args":["setup-openstack.yml"]},"labels":[{"id":1,"name":"check:False"},{"id":2,"name":"tags:all"}],"started":"2025-12-08T13:57:07.871967Z","ended":"2025-12-08T14:21:54.049657Z","duration":"00:24:46.177690","name":null,"ansible_version":"2.18.6","client_version":"1.7.4","python_version":"3.12.11","server_version":"1.7.4","status":"failed","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible/playbooks/setup-openstack.yml","controller":"aio1.openstack.local","user":"root"},"content":"---\n# Copyright 2015, Rackspace US, Inc.\n#\n# Licensed under the Apache License, Version 2.0 (the \"License\");\n# you may not use this file except in compliance with the License.\n# You may obtain a copy of the License at\n#\n#     http://www.apache.org/licenses/LICENSE-2.0\n#\n# Unless required by applicable law or agreed to in writing, software\n# distributed under the License is distributed on an \"AS IS\" BASIS,\n# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n# See the License for the specific language governing permissions and\n# limitations under the License.\n\n- name: Post swift tempURL secret key\n  ansible.builtin.command: >\n    {{ ironic_bin }}/swift {{ keystone_service_adminuri_insecure | bool | ternary('--insecure', '--os-cacert ' ~ _ironic_ssl_truststore_location) }}\n    --os-username \"service:{{ glance_service_user_name }}\"\n    --os-password \"{{ glance_service_password }}\"\n    --os-auth-url {{ keystone_service_internalurl }}\n    --os-identity-api-version {{ keystone_service_internalurl.split('/v')[-1] }}\n    post -m temp-url-key:{{ ironic_swift_temp_url_secret_key }}\n  environment:\n    OS_ENDPOINT_TYPE: internalURL\n  changed_when: false\n  when:\n    - not ironic_enable_web_server_for_images | bool\n    - _ironic_api_is_first_play_host\n    - not ironic_standalone | bool\n  tags:\n    - always\n\n- name: Get swift account\n  ansible.builtin.shell: >\n    {{ ironic_bin }}/swift {{ keystone_service_adminuri_insecure | bool | ternary('--insecure', '--os-cacert ' ~ _ironic_ssl_truststore_location) }}\n    --os-username \"service:{{ glance_service_user_name }}\"\n    --os-password \"{{ glance_service_password }}\"\n    --os-auth-url {{ keystone_service_internalurl }}\n    --os-identity-api-version {{ keystone_service_internalurl.split('/v')[-1] }}\n    stat -v | awk '/StorageURL\\:/ {print $2}'\n  environment:\n    OS_ENDPOINT_TYPE: internalURL\n  changed_when: false\n  register: swift_storage_url\n  when:\n    - not ironic_enable_web_server_for_images | bool\n    - (ironic_swift_auth_account is undefined) or (ironic_swift_endpoint is undefined)\n    - not ironic_standalone | bool\n  tags:\n    - always\n\n- name: Validate swift output\n  ansible.builtin.fail:\n    msg: |\n      No StorageURL output found using the `swift stat` command and either\n      the ``ironic_swift_auth_account`` or ``ironic_swift_auth_account``\n      variables are undefined. Ensure swift is functional and/or define\n      those variables.\n  when:\n    - not ironic_enable_web_server_for_images | bool\n    - (ironic_swift_auth_account is undefined) and (ironic_swift_endpoint is undefined)\n    - not ironic_standalone | bool\n    - not swift_storage_url.stdout\n  tags:\n    - always\n\n- name: Set the swift auth facts\n  ansible.builtin.set_fact:\n    ironic_swift_auth_account: \"{{ swift_storage_url.stdout.split('/v1/')[-1] }}\"\n  when:\n    - not ironic_enable_web_server_for_images | bool\n    - ironic_swift_auth_account is undefined\n    - not ironic_standalone | bool\n  tags:\n    - always\n\n- name: Set the swift endpoint facts\n  ansible.builtin.set_fact:\n    ironic_swift_endpoint: \"{{ swift_storage_url.stdout.split('/v1/')[0] }}\"\n  when:\n    - not ironic_enable_web_server_for_images | bool\n    - ironic_swift_endpoint is undefined\n    - not ironic_standalone | bool\n  tags:\n    - always\n\n- name: Generate ironic config\n  openstack.config_template.config_template:\n    src: \"{{ item.src }}\"\n    dest: \"{{ item.dest }}\"\n    owner: \"{{ item.owner | default(ironic_system_user_name) }}\"\n    group: \"{{ item.group | default(ironic_system_group_name) }}\"\n    mode: \"0644\"\n    config_overrides: \"{{ item.config_overrides }}\"\n    config_type: \"{{ item.config_type }}\"\n  when: item.condition | default(True)\n  with_items:\n    - src: \"ironic.conf.j2\"\n      dest: \"/etc/ironic/ironic.conf\"\n      config_overrides: \"{{ ironic_ironic_conf_overrides }}\"\n      config_type: \"ini\"\n    - src: \"rootwrap.conf.j2\"\n      dest: \"/etc/ironic/rootwrap.conf\"\n      owner: \"root\"\n      group: \"root\"\n      config_overrides: \"{{ ironic_rootwrap_conf_overrides }}\"\n      config_type: \"ini\"\n    - src: \"inspector.conf.j2\"\n      dest: \"/etc/ironic-inspector/ironic-inspector.conf\"\n      config_overrides: \"{{ ironic_inspector_conf_overrides }}\"\n      config_type: \"ini\"\n      condition: inventory_hostname in groups['ironic-inspector']\n    - src: \"rootwrap.conf.j2\"\n      dest: \"/etc/ironic-inspector/rootwrap.conf\"\n      owner: \"root\"\n      group: \"root\"\n      config_overrides: \"{{ ironic_inspector_rootwrap_conf_overrides }}\"\n      config_type: \"ini\"\n      condition: inventory_hostname in groups['ironic-inspector']\n  notify:\n    - Restart ironic services\n    - Restart uwsgi services\n\n- name: Implement policy.yaml\n  openstack.config_template.config_template:\n    content: \"{{ ironic_policy_overrides }}\"\n    dest: \"/etc/ironic/policy.yaml\"\n    owner: \"{{ ironic_system_user_name }}\"\n    group: \"{{ ironic_system_group_name }}\"\n    mode: \"0644\"\n    config_type: yaml\n  when:\n    - ironic_services['ironic-api']['group'] in group_names\n  tags:\n    - ironic-policy-override\n\n- name: Copy rootwrap filters\n  ansible.builtin.copy:\n    src: \"{{ item }}\"\n    dest: \"/etc/ironic/rootwrap.d/\"\n    owner: \"root\"\n    group: \"root\"\n    mode: \"0644\"\n  with_fileglob:\n    - rootwrap.d/*\n  notify:\n    - Restart ironic services\n    - Restart uwsgi services\n\n- name: Include sudoers file\n  ansible.builtin.template:\n    src: \"sudoers.j2\"\n    dest: \"/etc/sudoers.d/{{ ironic_system_user_name }}_sudoers\"\n    mode: \"0440\"\n    owner: \"root\"\n    group: \"root\"\n","created":"2025-12-08T13:57:18.343094Z","updated":"2025-12-08T13:57:18.343107Z","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible-os_ironic/tasks/ironic_post_install.yml"}