From d96ec189d4d2cd98ffb41fa67c708dd0d510e3fc Mon Sep 17 00:00:00 2001 From: sjat Date: Tue, 1 Sep 2026 20:20:46 +0200 Subject: [PATCH] fix: repair stdout callback + refresh the access recipe MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit community.general 12 removed the `yaml` stdout callback, so every ansible invocation died with a [DEPRECATED] error. Use the core default callback with `callback_result_format = yaml` — identical output, no collection dep. CLAUDE.md's access recipe still described the retired `-J kuku … 10.8.0.4` hop; `mamba` is now an ssh alias over the wg overlay. Also record two things that cost time on the 2026-09-01 bench session: the vaulted admin password cannot authenticate over SSH at all (RouterOS refuses password auth for a user holding an SSH key while always-allow-password-login=no), so each operator seat needs its own key imported; and the checked-in .venv carries shebangs from the original /home/sjat path. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE --- CLAUDE.md | 20 ++++++++++++++++++-- ansible.cfg | 5 ++++- 2 files changed, 22 insertions(+), 3 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 20115f3..d0ba127 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -36,16 +36,27 @@ The switch is reachable only via the makerspace laptop `mamba`. Ansible's `netwo uses paramiko, which **ignores ProxyJump**, so port-forward instead of double-hopping: ```bash -ssh -J kuku -p 7576 sjat@10.8.0.4 -L 2222:192.168.88.1:22 -N # tunnel to the switch -ansible-playbook play_switch.yml -e ansible_host=127.0.0.1 -e ansible_port=2222 -e ansible_user=sjat +ssh -N -L 2222:192.168.88.1:22 mamba # tunnel to the switch +ansible-playbook play_switch.yml -e ansible_host=127.0.0.1 -e ansible_port=2222 ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel host key changed ``` +- `mamba` is an ssh alias from boma's `ssh_client` drop-in (`10.99.0.10:7576` over the wg + overlay). It superseded the old `-J kuku … sjat@10.8.0.4` hop; that path is dead. +- `ansible_user: sjat` already comes from `host_vars`, so don't pass it on the CLI. +- **Every operator seat needs its own key on the device** — key auth is the only way in + (see Rules). `ubongo`'s `claude@ubongo` key was added 2026-09-01; a new seat repeats: + `scp -O key.pub sjat@192.168.88.1:` then + `/user/ssh-keys/import public-key-file=key.pub user=sjat`, and delete the uploaded file. - `mamba` is the mgmt station on **switch port 8** (MGMT VLAN); it must be on port 8 to reach `192.168.88.1`. From a data port it gets `10.2.30.x` and **cannot** reach mgmt. - NM profiles on `mamba` `enp0s31f6`: `crs310-bench` (static `.2`) and `Wired connection 1` (DHCP). Moving the cable flaps the link and NM re-selects a profile — pin the intended one sticky (`autoconnect yes` + higher priority) and the other off, or it reverts. + Either profile works now that the mgmt VLAN serves DHCP (`.253` from the pool). +- The `.venv` was built under `/home/sjat/…`; on a checkout at another path its console + scripts fail with exit 126 (stale shebang). Fix the shebangs or rebuild the venv — + the system `ansible` is not a substitute (no paramiko, newer `community.general`). ## Rules @@ -62,6 +73,11 @@ ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel - **All real values go in `host_vars`;** the role holds only mechanism + placeholders. - **Secrets** go to the `makerfloss` vault, never plaintext. Encrypt with `ansible-vault encrypt --encrypt-vault-id makerfloss `. +- **`vault_switch_admin_password` cannot log in over SSH** and is console/recovery-only. + RouterOS refuses password auth for any user that has an SSH key while + `/ip/ssh always-allow-password-login=no` (the default, and deliberately kept). So + `play_bootstrap.yml`'s password is a one-shot for user creation; after the key import + the only SSH path is key auth. Never "fix" a failed login by flipping that flag. - **New work:** branch first, implement, verify (lint + syntax + run-twice), then merge. ## Status / next diff --git a/ansible.cfg b/ansible.cfg index c189fc8..f3b53f4 100644 --- a/ansible.cfg +++ b/ansible.cfg @@ -7,7 +7,10 @@ retry_files_enabled = False interpreter_python = auto_silent nocows = 1 timeout = 30 -stdout_callback = yaml +# `yaml` was community.general's stdout callback; removed in community.general 12. +# ansible-core 2.13+ gives the same output via the default callback + result format. +stdout_callback = default +callback_result_format = yaml bin_ansible_callbacks = True vault_identity_list = makerfloss@~/.ansible/vault-keys/makerfloss.txt