Playbook #5

/home/zuul/src/opendev.org/opendev/system-config/playbooks/letsencrypt.yaml

Report Status CLI Date Duration Controller User Versions Hosts Plays Tasks Results Files Records
18 Jul 2025 20:47:32 +0000 00:00:24.78 bridge99.opendev.org root Ansible 2.15.13 ara 1.7.2 (client), 1.7.2 (server) Python 3.10.12 2 5 47 47 33 0

File: /home/zuul/src/opendev.org/opendev/system-config/inventory/service/group_vars/bastion.yaml

bastion_key_exclusive: false
kube_config_template: clouds/bridge_kube_config.yaml.j2
extra_users:
  - zuul
cloud_launcher_profiles:
  # Profile to launch AFS server for nodepool.
  - name: openstackci-projects
    projects:
      - name: openstackci
        description: OpenStack CI project
        domain: default
      - name: openstackzuul
        description: OpenStack zuul project
        domain: default

  - name: openstackci-security
    security_groups:
      - name: default
        description: Default security group
    security_groups_rules:
      - security_group: default
        ethertype: IPv4
        remote_group: default
        state: absent
      - security_group: default
        ethertype: IPv6
        remote_group: default
        state: absent
      - security_group: default
        ethertype: IPv4
        remote_ip_prefix: 0.0.0.0/0
      - security_group: default
        ethertype: IPv6
        remote_ip_prefix: ::/0

  - name: openstackci-keypairs
    keypairs:
      - name: infra-root-keys-2020-05-13
        public_key: |
            ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDLsTZJ8hXTmzjKxYh/7V07mIy8xl2HL+9BaUlt6A6TMsL3LSvaVQNSgmXX5g0XfPWSCKmkZb1O28q49jQI2n7n7+sHkxn0dJDxj1N2oNrzNY7pDuPrdtCijczLFdievygXNhXNkQ2WIqHXDquN/jfLLJ9L0jxtxtsUMbiL2xxZEZcaf/K5MqyPhscpqiVNE1MjE4xgPbIbv8gCKtPpYIIrktOMb4JbV7rhOp5DcSP5gXtLhOF5fbBpZ+szqrTVUcBX0oTYr3iRfOje9WPsTZIk9vBfBtF416mCNxMSRc7KhSW727AnUu85hS0xiP0MRAf69KemG1OE1pW+LtDIAEYp mordred@camelot

            ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAvKYcWK1T7e3PKSFiqb03EYktnoxVASpPoq2rJw2JvhsP0JfS+lKrPzpUQv7L4JCuQMsPNtZ8LnwVEft39k58Kh8XMebSfaqPYAZS5zCNvQUQIhP9myOevBZf4CDeG+gmssqRFcWEwIllfDuIzKBQGVbomR+Y5QuW0HczIbkoOYI6iyf2jB6xg+bmzR2HViofNrSa62CYmHS6dO04Z95J27w6jGWpEOTBjEQvnb9sdBc4EzaBVmxCpa2EilB1u0th7/DvuH0yP4T+X8G8UjW1gZCTOVw06fqlBCST4KjdWw1F/AuOCT7048klbf4H+mCTaEcPzzu3Fkv8ckMWtS/Z9Q== jeblair@operational-necessity

            ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCnfoVhOTkrY7uoebL8PoHXb0Fg4jJqGCbwkxUdNUdheIdbnfyjuRG3iL8WZnzf7nzWnD+IGo6kkAo8BkNMK9L0P0Y+5IjI8NH49KU22tQ1umij4EIf5tzLh4gsqkJmy6QLrlbf10m6UF4rLFQhKzOd4b2H2K6KbP00CIymvbW3BwvNDODM4xRE2uao387qfvXZBUkB0PpRD+7fWPoN58gpFUm407Eba3WwX5PCD+1DD+RVBsG8maIDXerQ7lvFLoSuyMswv1TfkvCj0ZFhSFbfTd2ZysCu6eryFfeixR7NY9SNcp9YTqG6LrxGA7Ci6wz+hycFHXlDrlBgfFJDe5At clark@work

            ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQD3KnRBTH5QPpKjf4RWu4akzYt2gwp796cMkFl5vu8e7G/cHuh4979FeNJXMVP6F3rvZB+yXDHLCU5LBVLq0K+1GbAZT/hH38hpMOIvniwKIquvI6C/drkVPHO6YmVlapw/NI530PGnT/TAqCOycHBO5eF1bYsaqV1yZqvs9v7UZc6J4LukoLZwpmyWZ5P3ltAiiy8+FGq3SLCKWDMmv/Bjz4zTsaNbSWThJi0BydINjC1/0ze5Tyc/XgW1sDuxmmXJxgQp4EvLpronqb2hT60iA52kj8lrmoCIryRpgnbaRA7BrxKF8zIr0ZALHijxEUeWHhFJDIVRGUf0Ef0nrmBv fungi-openstack-2015

            ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILOjz+dkwRWTJcW9Gt3iGHSzRBsvVlTAK6G2oH3+0D41 iwienand+osinfra@redhat.com

            ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCuP0CZE8AYnbm8gxecCxKeRw0wHRyryd+FKmNNsdr0d3UvfCbqNzLigrqEBZsKpofi3M4qCWNpKRyfhnjPynLTQjP1vnX9AbL9UGoiHxScfvh3skntTYMs9ezJRd0rMJJZO76FPo8bJLDlwxAQl8m/nuj3HfYiO5hYE7P+a3rhsJh4nEfBb7xh+Q5yM0PWObkkBl6IRiBYjlcsXNZHgTA5kNuihUk5bHqAw54sHh05DhpgOITpTw4LFbh4Ew2NKq49dEb2xbTuAyAr2DHNOGgIwKEZpwtKZEIGEuiLbb4DQRsfivrvyOjnK2NFjQzGyNOHfsOldWHRQwUKUs8nrxKdXvqcrfMnSVaibeYK2TRL+6jd9kc5SIhWI3XLm7HbX7uXMD7/JQrkL25Rcs6nndDCH72DJLz+ynA/T5umMbNBQ9tybL5z73IOpfShRGjQYego22CxDOy7e/5OEMHNoksbFb1S02viM9O2puS7LDqqfT9JIbbPqCrbRi/zOXo0f4EXo6xKUAmd8qlV+6f/p57/qFihzQDaRFVlFEH3k7qwsw7PYGUTwkPaThe6xyZN6D5jqxCZU3aSYu+FGb0oYo+M5IxOm0Cb4NNsvvkRPxWtwSayfFGu6+m/+/RyA3GBcAMev7AuyKN+K2vGMsLagHOx4i+5ZAcUwGzLeXAENNum3w== pabelanger@redhat.com

            ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGmc5fbzMptjAb5D86zSH13ZYCbf3QuV1jk9hL0r1qHw frickler@os-infra-2017

      - name: infra-root-keys-2024-04-08
        public_key: |
            ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAvKYcWK1T7e3PKSFiqb03EYktnoxVASpPoq2rJw2JvhsP0JfS+lKrPzpUQv7L4JCuQMsPNtZ8LnwVEft39k58Kh8XMebSfaqPYAZS5zCNvQUQIhP9myOevBZf4CDeG+gmssqRFcWEwIllfDuIzKBQGVbomR+Y5QuW0HczIbkoOYI6iyf2jB6xg+bmzR2HViofNrSa62CYmHS6dO04Z95J27w6jGWpEOTBjEQvnb9sdBc4EzaBVmxCpa2EilB1u0th7/DvuH0yP4T+X8G8UjW1gZCTOVw06fqlBCST4KjdWw1F/AuOCT7048klbf4H+mCTaEcPzzu3Fkv8ckMWtS/Z9Q== jeblair@operational-necessity

            ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPMd15RqqpUqBp2f+17HOQEJkPCwpismoKDisVOsFXEr id_ed25519_clarkbwork2024

            ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcArU//VFneyQE82/JbzRx/VRDzFm+gCLX5rK1VMbp7 fungi-opendev-2024

            ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILOjz+dkwRWTJcW9Gt3iGHSzRBsvVlTAK6G2oH3+0D41 iwienand+osinfra@redhat.com

            ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIW7n3n1zAG8VM/ZfIB8tf1191/Ee6DgsOHUzv+9PB8k frickler@os-infra-2024

            ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICEGSGGtTSLe/fEU5bH44XHdT6g0arzPFTHobs6F9z6l tonyb@opendev

      - name: bridge-root-2014-09-15
        public_key: |
            ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDSLlN41ftgxkNeUi/kATYPwMPjJdMaSbgokSb9PSkRPZE7GeNai60BCfhu+ky8h5eMe70Bpwb7mQ7GAtHGXPNU1SRBPhMuVN9EYrQbt5KSiwuiTXtQHsWyYrSKtB+XGbl2PhpMQ/TPVtFoL5usxu/MYaakVkCEbt5IbPYNg88/NKPixicJuhi0qsd+l1X1zoc1+Fn87PlwMoIgfLIktwaL8hw9mzqr+pPcDIjCFQQWnjqJVEObOcMstBT20XwKj/ymiH+6p123nnlIHilACJzXhmIZIZO+EGkNF7KyXpcBSfv9efPI+VCE2TOv/scJFdEHtDFkl2kdUBYPC0wQ92rp puppet-remote-2014-09-15

  - name: openstackci-flavors
    flavors:
      - name: nodepool
        ram: 8192
        vcpus: 8
        disk: 80
      - name: mirror
        ram: 8192
        vcpus: 4
        disk: 250

  - name: admin-roles
    roles:
      - name: Member

  - name: openstackci-user-roles
    user_roles:
      - role: Member
        user: openstackci
        project: openstackci

  - name: openstackzuul-user-roles
    user_roles:
      - role: Member
        user: openstackzuul
        project: openstackzuul

  - name: openstackci-networking
    networks:
      - name: openstackci-network1
    subnets:
      - name: openstackci-subnet1
        network_name: openstackci-network1
        cidr: '10.0.1.0/24'

  - name: openstackzuul-networking
    networks:
      - name: openstackzuul-network1
    subnets:
      - name: openstackzuul-subnet1
        network_name: openstackzuul-network1
        cidr: '10.0.1.0/24'

  - name: opendevci-networking
    networks:
      - name: opendevci-network1
    subnets:
      - name: opendevci-subnet1
        network_name: opendevci-network1
        cidr: '10.0.1.0/24'

  - name: opendevzuul-networking
    networks:
      - name: opendevzuul-network1
    subnets:
      - name: opendevzuul-subnet1
        network_name: opendevzuul-network1
        cidr: '10.0.16.0/20'

cloud_launcher_clouds:
  # ovh
  - name: openstackci-ovh-bhs1
    oscc_cloud: openstackci-ovh
    region_name: BHS1
    profiles:
      - openstackci-keypairs
      - openstackci-security
  - name: openstackjenkins-ovh-bhs1
    oscc_cloud: openstackjenkins-ovh
    region_name: BHS1
    profiles:
      - openstackci-keypairs
      - openstackci-security
  - name: openstackci-ovh-gra1
    oscc_cloud: openstackci-ovh
    region_name: GRA1
    profiles:
      - openstackci-keypairs
      - openstackci-security
  - name: openstackjenkins-ovh-gra1
    oscc_cloud: openstackjenkins-ovh
    region_name: GRA1
    profiles:
      - openstackci-keypairs
      - openstackci-security

  # vexxhost
  - name: openstackci-vexxhost-mtl1
    oscc_cloud: openstackci-vexxhost
    region_name: ca-ymq-1
    profiles:
      - openstackci-keypairs
      - openstackci-security
  - name: openstackjenkins-vexxhost-mtl1
    oscc_cloud: openstackjenkins-vexxhost
    region_name: ca-ymq-1
    profiles:
      - openstackci-keypairs
      - openstackci-security
  - name: openstackci-vexxhost-sjc1
    oscc_cloud: openstackci-vexxhost
    region_name: sjc1
    profiles:
      - openstackci-keypairs
      - openstackci-security
  - name: openstackjenkins-vexxhost-sjc1
    oscc_cloud: openstackjenkins-vexxhost
    region_name: sjc1
    profiles:
      - openstackci-keypairs
      - openstackci-security

  # rackspace
  - name: openstackci-rax-dfw
    oscc_cloud: openstackci-rax
    region_name: DFW
    profiles:
      - openstackci-keypairs
  - name: openstackjenkins-rax-dfw
    oscc_cloud: openstackjenkins-rax
    region_name: DFW
    profiles:
      - openstackci-keypairs
  - name: openstackci-rax-ord
    oscc_cloud: openstackci-rax
    region_name: ORD
    profiles:
      - openstackci-keypairs
  - name: openstackjenkins-rax-ord
    oscc_cloud: openstackjenkins-rax
    region_name: ORD
    profiles:
      - openstackci-keypairs
  - name: openstackci-rax-iad
    oscc_cloud: openstackci-rax
    region_name: IAD
    profiles:
      - openstackci-keypairs
  - name: openstackjenkins-rax-iad
    oscc_cloud: openstackjenkins-rax
    region_name: IAD
    profiles:
      - openstackci-keypairs

  # rackspace flex
  - name: opendevci-rax-flex-dfw3
    oscc_cloud: opendevci-rax-flex
    region_name: DFW3
    profiles:
      - openstackci-keypairs
      - openstackci-security
      - opendevci-networking
    # we manually set the MTU to 1500 since it's unusually high otherwise
    routers:
      - name: opendevci-router1
        network: PUBLICNET
        interfaces:
          - opendevci-subnet1
  - name: opendevci-rax-flex-sjc3
    oscc_cloud: opendevci-rax-flex
    region_name: SJC3
    profiles:
      - openstackci-keypairs
      - openstackci-security
      - opendevci-networking
    # we manually set the MTU to 1500 since it's unusually high otherwise
    routers:
      - name: opendevci-router1
        network: PUBLICNET
        interfaces:
          - opendevci-subnet1
  - name: opendevzuul-rax-flex-dfw3
    oscc_cloud: opendevzuul-rax-flex
    region_name: DFW3
    profiles:
      - openstackci-keypairs
      - openstackci-security
      - opendevzuul-networking
    # we manually set the MTU to 1500 since it's unusually high otherwise
    routers:
      - name: opendevzuul-router1
        network: PUBLICNET
        interfaces:
          - opendevzuul-subnet1
  - name: opendevzuul-rax-flex-sjc3
    oscc_cloud: opendevzuul-rax-flex
    region_name: SJC3
    profiles:
      - openstackci-keypairs
      - openstackci-security
      - opendevzuul-networking
    # we manually set the MTU to 1500 since it's unusually high otherwise
    routers:
      - name: opendevzuul-router1
        network: PUBLICNET
        interfaces:
          - opendevzuul-subnet1

  # OSUOSL
  - name: opendevci-osuosl
    oscc_cloud: opendevci-osuosl
    region_name: RegionOne
    profiles:
      - openstackci-keypairs
      - openstackci-security

  - name: opendevzuul-osuosl
    oscc_cloud: opendevzuul-osuosl
    region_name: RegionOne
    profiles:
      - openstackci-keypairs
      - openstackci-security

  # OpenMetal Cloud
  - name: opendevci-openmetal
    oscc_cloud: opendevci-openmetal
    region_name: IAD3
    profiles:
      - openstackci-keypairs
      - openstackci-security

  - name: opendevzuul-openmetal
    oscc_cloud: opendevzuul-openmetal
    region_name: IAD3
    profiles:
      - openstackci-keypairs
      - openstackci-security