{"id":857,"sha1":"6b93ebf753d6b1894689cbe85f5672c8a92f2e1b","playbook":{"id":4,"items":{"plays":104,"tasks":1377,"results":1365,"hosts":2,"files":504,"records":0},"arguments":{"version":null,"verbosity":0,"private_key_file":null,"remote_user":null,"connection":"openstack.osa.ssh","timeout":null,"ssh_common_args":null,"sftp_extra_args":null,"scp_extra_args":null,"ssh_extra_args":null,"ask_pass":false,"connection_password_file":null,"force_handlers":true,"flush_cache":false,"become":false,"become_method":"sudo","become_user":null,"become_ask_pass":false,"become_password_file":null,"tags":["all"],"skip_tags":[],"check":false,"diff":false,"inventory":["/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/dynamic_inventory.py","/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/inventory.ini","/etc/openstack_deploy/inventory.ini"],"listhosts":false,"subset":null,"extra_vars":"Not saved by ARA as configured by 'ignored_arguments'","vault_ids":[],"ask_vault_pass":false,"vault_password_files":[],"forks":8,"module_path":null,"syntax":false,"listtasks":false,"listtags":false,"step":false,"start_at_task":null,"args":["setup-openstack.yml"]},"labels":[{"id":1,"name":"check:False"},{"id":2,"name":"tags:all"}],"started":"2025-12-08T13:39:52.478534Z","ended":"2025-12-08T14:14:54.510371Z","duration":"00:35:02.031837","name":null,"ansible_version":"2.18.6","client_version":"1.7.4","python_version":"3.12.3","server_version":"1.7.4","status":"failed","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible/playbooks/setup-openstack.yml","controller":"aio1.openstack.local","user":"root"},"content":"---\n# Copyright 2018, SUSE LINUX GmbH.\n#\n# Licensed under the Apache License, Version 2.0 (the \"License\");\n# you may not use this file except in compliance with the License.\n# You may obtain a copy of the License at\n#\n#     http://www.apache.org/licenses/LICENSE-2.0\n#\n# Unless required by applicable law or agreed to in writing, software\n# distributed under the License is distributed on an \"AS IS\" BASIS,\n# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n# See the License for the specific language governing permissions and\n# limitations under the License.\n\n- name: Install required apparmor packages on the physical host\n  ansible.builtin.package:\n    name: \"{{ neutron_apparmor_distro_packages }}\"\n    state: present\n  register: apparmor_packages\n  until: apparmor_packages is success\n  retries: 5\n  delay: 2\n\n- name: Ensure apparmor service is running\n  ansible.builtin.systemd:\n    name: \"apparmor\"\n    enabled: true\n    state: \"started\"\n\n- name: \"Place required apparmor overrides\"\n  ansible.builtin.copy:\n    content: \"{{ item['content'] }}\"\n    dest: \"/etc/apparmor.d/local/{{ item['profile'] }}\"\n    mode: \"0644\"\n    owner: root\n    group: root\n  loop: \"{{ neutron_apparmor_profile_overrides }}\"\n  loop_control:\n    label: \"{{ item['profile'] }}\"\n  when:\n    - item.condition | default(true)\n  notify:\n    - Reload apparmor\n\n- name: \"Disable apparmor profile\"\n  ansible.builtin.shell: |\n    # empty line to workaround bug in EnvVarsInCommandRule.py lint test\n    # https://github.com/willthames/ansible-lint/issues/275\n    set -o pipefail\n    exit_code=0\n    if aa-status | grep -q {{ item.process }} ; then\n       aa-disable {{ item.profile }}\n       exit_code=$?\n       if [[ $exit_code == 0 ]]; then\n         exit_code=2\n       fi\n    fi\n    exit ${exit_code}\n  register: _apparmor_profile_disabled\n  changed_when: _apparmor_profile_disabled.rc == 2\n  failed_when: _apparmor_profile_disabled.rc not in [0,2]\n  args:\n    executable: /bin/bash\n  with_items:\n    - profile: \"usr.sbin.haproxy\"\n      process: \"haproxy\"\n    - profile: \"bin.ping\"\n      process: \"ping\"\n","created":"2025-12-08T14:04:03.309490Z","updated":"2025-12-08T14:04:03.309525Z","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible-os_neutron/tasks/neutron_apparmor.yml"}