fix: repair stdout callback + refresh the access recipe

community.general 12 removed the `yaml` stdout callback, so every ansible
invocation died with a [DEPRECATED] error. Use the core default callback
with `callback_result_format = yaml` — identical output, no collection dep.

CLAUDE.md's access recipe still described the retired `-J kuku … 10.8.0.4`
hop; `mamba` is now an ssh alias over the wg overlay. Also record two things
that cost time on the 2026-09-01 bench session: the vaulted admin password
cannot authenticate over SSH at all (RouterOS refuses password auth for a
user holding an SSH key while always-allow-password-login=no), so each
operator seat needs its own key imported; and the checked-in .venv carries
shebangs from the original /home/sjat path.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
This commit is contained in:
sjat 2026-09-01 20:20:46 +02:00
parent 2796616d05
commit d96ec189d4
2 changed files with 22 additions and 3 deletions

View file

@ -36,16 +36,27 @@ The switch is reachable only via the makerspace laptop `mamba`. Ansible's `netwo
uses paramiko, which **ignores ProxyJump**, so port-forward instead of double-hopping: uses paramiko, which **ignores ProxyJump**, so port-forward instead of double-hopping:
```bash ```bash
ssh -J kuku -p 7576 sjat@10.8.0.4 -L 2222:192.168.88.1:22 -N # tunnel to the switch ssh -N -L 2222:192.168.88.1:22 mamba # tunnel to the switch
ansible-playbook play_switch.yml -e ansible_host=127.0.0.1 -e ansible_port=2222 -e ansible_user=sjat ansible-playbook play_switch.yml -e ansible_host=127.0.0.1 -e ansible_port=2222
ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel host key changed ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel host key changed
``` ```
- `mamba` is an ssh alias from boma's `ssh_client` drop-in (`10.99.0.10:7576` over the wg
overlay). It superseded the old `-J kuku … sjat@10.8.0.4` hop; that path is dead.
- `ansible_user: sjat` already comes from `host_vars`, so don't pass it on the CLI.
- **Every operator seat needs its own key on the device** — key auth is the only way in
(see Rules). `ubongo`'s `claude@ubongo` key was added 2026-09-01; a new seat repeats:
`scp -O key.pub sjat@192.168.88.1:` then
`/user/ssh-keys/import public-key-file=key.pub user=sjat`, and delete the uploaded file.
- `mamba` is the mgmt station on **switch port 8** (MGMT VLAN); it must be on port 8 to - `mamba` is the mgmt station on **switch port 8** (MGMT VLAN); it must be on port 8 to
reach `192.168.88.1`. From a data port it gets `10.2.30.x` and **cannot** reach mgmt. reach `192.168.88.1`. From a data port it gets `10.2.30.x` and **cannot** reach mgmt.
- NM profiles on `mamba` `enp0s31f6`: `crs310-bench` (static `.2`) and `Wired connection 1` - NM profiles on `mamba` `enp0s31f6`: `crs310-bench` (static `.2`) and `Wired connection 1`
(DHCP). Moving the cable flaps the link and NM re-selects a profile — pin the intended (DHCP). Moving the cable flaps the link and NM re-selects a profile — pin the intended
one sticky (`autoconnect yes` + higher priority) and the other off, or it reverts. one sticky (`autoconnect yes` + higher priority) and the other off, or it reverts.
Either profile works now that the mgmt VLAN serves DHCP (`.253` from the pool).
- The `.venv` was built under `/home/sjat/…`; on a checkout at another path its console
scripts fail with exit 126 (stale shebang). Fix the shebangs or rebuild the venv —
the system `ansible` is not a substitute (no paramiko, newer `community.general`).
## Rules ## Rules
@ -62,6 +73,11 @@ ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel
- **All real values go in `host_vars`;** the role holds only mechanism + placeholders. - **All real values go in `host_vars`;** the role holds only mechanism + placeholders.
- **Secrets** go to the `makerfloss` vault, never plaintext. Encrypt with - **Secrets** go to the `makerfloss` vault, never plaintext. Encrypt with
`ansible-vault encrypt --encrypt-vault-id makerfloss <file>`. `ansible-vault encrypt --encrypt-vault-id makerfloss <file>`.
- **`vault_switch_admin_password` cannot log in over SSH** and is console/recovery-only.
RouterOS refuses password auth for any user that has an SSH key while
`/ip/ssh always-allow-password-login=no` (the default, and deliberately kept). So
`play_bootstrap.yml`'s password is a one-shot for user creation; after the key import
the only SSH path is key auth. Never "fix" a failed login by flipping that flag.
- **New work:** branch first, implement, verify (lint + syntax + run-twice), then merge. - **New work:** branch first, implement, verify (lint + syntax + run-twice), then merge.
## Status / next ## Status / next

View file

@ -7,7 +7,10 @@ retry_files_enabled = False
interpreter_python = auto_silent interpreter_python = auto_silent
nocows = 1 nocows = 1
timeout = 30 timeout = 30
stdout_callback = yaml # `yaml` was community.general's stdout callback; removed in community.general 12.
# ansible-core 2.13+ gives the same output via the default callback + result format.
stdout_callback = default
callback_result_format = yaml
bin_ansible_callbacks = True bin_ansible_callbacks = True
vault_identity_list = makerfloss@~/.ansible/vault-keys/makerfloss.txt vault_identity_list = makerfloss@~/.ansible/vault-keys/makerfloss.txt