fix: repair stdout callback + refresh the access recipe
community.general 12 removed the `yaml` stdout callback, so every ansible invocation died with a [DEPRECATED] error. Use the core default callback with `callback_result_format = yaml` — identical output, no collection dep. CLAUDE.md's access recipe still described the retired `-J kuku … 10.8.0.4` hop; `mamba` is now an ssh alias over the wg overlay. Also record two things that cost time on the 2026-09-01 bench session: the vaulted admin password cannot authenticate over SSH at all (RouterOS refuses password auth for a user holding an SSH key while always-allow-password-login=no), so each operator seat needs its own key imported; and the checked-in .venv carries shebangs from the original /home/sjat path. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
This commit is contained in:
parent
2796616d05
commit
d96ec189d4
2 changed files with 22 additions and 3 deletions
20
CLAUDE.md
20
CLAUDE.md
|
|
@ -36,16 +36,27 @@ The switch is reachable only via the makerspace laptop `mamba`. Ansible's `netwo
|
|||
uses paramiko, which **ignores ProxyJump**, so port-forward instead of double-hopping:
|
||||
|
||||
```bash
|
||||
ssh -J kuku -p 7576 sjat@10.8.0.4 -L 2222:192.168.88.1:22 -N # tunnel to the switch
|
||||
ansible-playbook play_switch.yml -e ansible_host=127.0.0.1 -e ansible_port=2222 -e ansible_user=sjat
|
||||
ssh -N -L 2222:192.168.88.1:22 mamba # tunnel to the switch
|
||||
ansible-playbook play_switch.yml -e ansible_host=127.0.0.1 -e ansible_port=2222
|
||||
ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel host key changed
|
||||
```
|
||||
|
||||
- `mamba` is an ssh alias from boma's `ssh_client` drop-in (`10.99.0.10:7576` over the wg
|
||||
overlay). It superseded the old `-J kuku … sjat@10.8.0.4` hop; that path is dead.
|
||||
- `ansible_user: sjat` already comes from `host_vars`, so don't pass it on the CLI.
|
||||
- **Every operator seat needs its own key on the device** — key auth is the only way in
|
||||
(see Rules). `ubongo`'s `claude@ubongo` key was added 2026-09-01; a new seat repeats:
|
||||
`scp -O key.pub sjat@192.168.88.1:` then
|
||||
`/user/ssh-keys/import public-key-file=key.pub user=sjat`, and delete the uploaded file.
|
||||
- `mamba` is the mgmt station on **switch port 8** (MGMT VLAN); it must be on port 8 to
|
||||
reach `192.168.88.1`. From a data port it gets `10.2.30.x` and **cannot** reach mgmt.
|
||||
- NM profiles on `mamba` `enp0s31f6`: `crs310-bench` (static `.2`) and `Wired connection 1`
|
||||
(DHCP). Moving the cable flaps the link and NM re-selects a profile — pin the intended
|
||||
one sticky (`autoconnect yes` + higher priority) and the other off, or it reverts.
|
||||
Either profile works now that the mgmt VLAN serves DHCP (`.253` from the pool).
|
||||
- The `.venv` was built under `/home/sjat/…`; on a checkout at another path its console
|
||||
scripts fail with exit 126 (stale shebang). Fix the shebangs or rebuild the venv —
|
||||
the system `ansible` is not a substitute (no paramiko, newer `community.general`).
|
||||
|
||||
## Rules
|
||||
|
||||
|
|
@ -62,6 +73,11 @@ ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel
|
|||
- **All real values go in `host_vars`;** the role holds only mechanism + placeholders.
|
||||
- **Secrets** go to the `makerfloss` vault, never plaintext. Encrypt with
|
||||
`ansible-vault encrypt --encrypt-vault-id makerfloss <file>`.
|
||||
- **`vault_switch_admin_password` cannot log in over SSH** and is console/recovery-only.
|
||||
RouterOS refuses password auth for any user that has an SSH key while
|
||||
`/ip/ssh always-allow-password-login=no` (the default, and deliberately kept). So
|
||||
`play_bootstrap.yml`'s password is a one-shot for user creation; after the key import
|
||||
the only SSH path is key auth. Never "fix" a failed login by flipping that flag.
|
||||
- **New work:** branch first, implement, verify (lint + syntax + run-twice), then merge.
|
||||
|
||||
## Status / next
|
||||
|
|
|
|||
|
|
@ -7,7 +7,10 @@ retry_files_enabled = False
|
|||
interpreter_python = auto_silent
|
||||
nocows = 1
|
||||
timeout = 30
|
||||
stdout_callback = yaml
|
||||
# `yaml` was community.general's stdout callback; removed in community.general 12.
|
||||
# ansible-core 2.13+ gives the same output via the default callback + result format.
|
||||
stdout_callback = default
|
||||
callback_result_format = yaml
|
||||
bin_ansible_callbacks = True
|
||||
vault_identity_list = makerfloss@~/.ansible/vault-keys/makerfloss.txt
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue