las-it-organisation issueshttps://git.scc.kit.edu/groups/las-it-organisation/-/issues2021-09-03T14:12:42+02:00https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/108Opera installation failing when GNOME group should be installed2021-09-03T14:12:42+02:00sg7149Opera installation failing when GNOME group should be installedCalling host: asterix.las.kit.edu (Fedora 32)
Failing nodes: asterix
Summary
-------
Running the Opera role fails when trying to install GNOME group. It seems that the group was renamed.
Steps to reproduce
------------------
Try to...Calling host: asterix.las.kit.edu (Fedora 32)
Failing nodes: asterix
Summary
-------
Running the Opera role fails when trying to install GNOME group. It seems that the group was renamed.
Steps to reproduce
------------------
Try to install opera via the ansible role on Fedora 32 (GNOME may already be installed).
What is the current bug behavior?
---------------------------------
Fails when trying to group install "@GNOME".
What is the expected correct behaviour?
---------------------------------------
The GNOME group is installed and Opera installation succeeds.
Relevant logs and/or screenshots
--------------------------------
```
TASK [opera : install dependencies] ********************************************************************************************************************************************************************************************************
fatal: [asterix.las.kit.edu]: FAILED! => {"changed": false, "msg": "No group GNOME available.", "results": []}
```
Possible fixes
--------------
Use the correct name for the GNOME group.zx8344samira.fatehi@kit.eduzx8344samira.fatehi@kit.eduhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/107Add the KIT-AD integration2021-04-23T16:03:28+02:00sg7149Add the KIT-AD integrationSummary
-------
The AD integration is not automated so some behaviours are unexpected (las-archiv1 permissions on other computers) and setting up new computers involves manual work.
Steps to reproduce
------------------
1. SSH to a m...Summary
-------
The AD integration is not automated so some behaviours are unexpected (las-archiv1 permissions on other computers) and setting up new computers involves manual work.
Steps to reproduce
------------------
1. SSH to a machine that is not yours and try to access /mnt/las-archiv1.
2. Setup a new computer.
What is the current bug behaviour?
---------------------------------
1. Permission denied, because I'm not in the users group.
2. No login with KIT account possible
What is the expected correct behaviour?
---------------------------------------
1. Access granted (I am part of the group users)
2. Login with KIT account works.
Relevant logs and/or screenshots
--------------------------------
```
[sg7149@methusalix ~]$ ls -la /mnt/las-archiv1/
ls: cannot open directory '/mnt/las-archiv1/': Permission denied
```
Possible fixes
--------------
Implement the KIT-LAS_LDAP guide.yuancun.nieyuancun.niehttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/106Opera 2020 on Fedora 332022-06-29T11:45:44+02:00sg7149Opera 2020 on Fedora 33Failing nodes: methusalix, idefix
Summary
-------
Running operafea-post fails with errors.
Steps to reproduce
------------------
(How one can reproduce the issue - this is very important)
What is the current bug behavior?
--------...Failing nodes: methusalix, idefix
Summary
-------
Running operafea-post fails with errors.
Steps to reproduce
------------------
(How one can reproduce the issue - this is very important)
What is the current bug behavior?
---------------------------------
(What actually happens)
What is the expected correct behaviour?
---------------------------------------
(What you should see instead)
Relevant logs and/or screenshots
--------------------------------
```
/usr/local/share/Opera_2020/code/bin/operafea-post
libGL error: MESA-LOADER: failed to open swrast (search paths /usr/lib64/dri)
libGL error: failed to load driver: swrast
forrtl: severe (174): SIGSEGV, segmentation fault occurred
Image PC Routine Line Source
libifcoremt.so.5 00007F2EBD00F522 for__signal_handl Unknown Unknown
libpthread-2.32.s 00007F2EB68CE1E0 Unknown Unknown Unknown
libQt5OpenGL.so.5 00007F2EB90663E1 _ZN9QGLFormat18op Unknown Unknown
operafea-post 00005625BA7193E0 Unknown Unknown Unknown
operafea-post 00005625BA719D9B Unknown Unknown Unknown
operafea-post 00005625BA7191A3 Unknown Unknown Unknown
operafea-post 00005625BA718069 Unknown Unknown Unknown
operafea-post 00005625B9DBCFED Unknown Unknown Unknown
operafea-post 00005625BA4A2148 Unknown Unknown Unknown
operafea-post 00005625B9DFE281 Unknown Unknown Unknown
libc-2.32.so 00007F2EB34BD1E2 __libc_start_main Unknown Unknown
operafea-post 00005625B9DB7AF9 Unknown Unknown Unknown
```
Possible fixes
--------------
Tried installing `libglvnd-opengl` to provide `/lib64/libOpenGL.so.0.0.0` which was missing, but was on a working Fedora 31 host.ue5734ue5734https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/103get rid of old IPA related tasks and documentation2020-08-14T10:40:38+02:00sg7149get rid of old IPA related tasks and documentationAfter IPA is replaced by KIT-AD's LDAP one needs to clean the roles and the documentationAfter IPA is replaced by KIT-AD's LDAP one needs to clean the roles and the documentationKIT-ADhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/102Environment dependent epics configuration2020-07-15T14:59:38+02:00sg7149Environment dependent epics configurationEPICS is used for different purposes/environments which currently include:
* KARA
* LASMagLab
* TGU measurement
* Jena magnet setup
The configuration so far is only valid for one case only and the other configurations are changed by han...EPICS is used for different purposes/environments which currently include:
* KARA
* LASMagLab
* TGU measurement
* Jena magnet setup
The configuration so far is only valid for one case only and the other configurations are changed by hand which
- needs more steps for the installation and
- is error prone to (re-)running ansible.
This should be fixed.
See also issue #9https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/101Opera binaries to PATH2020-11-18T16:54:27+01:00sg7149Opera binaries to PATHAdd the main Opera binaries to the global PATH environment variable, so that they are available in all terminals.
* operafea-modeller*
* operafea-op3solve*
* operafea-post*
* operafea-readtrack*
* operafea-manager*
* operafea-pp*Add the main Opera binaries to the global PATH environment variable, so that they are available in all terminals.
* operafea-modeller*
* operafea-op3solve*
* operafea-post*
* operafea-readtrack*
* operafea-manager*
* operafea-pp*zx8344samira.fatehi@kit.eduzx8344samira.fatehi@kit.eduhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/96Fix deprecation warning (loop in Jupyter notebbok)2020-05-15T20:10:47+02:00sg7149Fix deprecation warning (loop in Jupyter notebbok)Calling host: obelix.las.kit.edu (Fedora 31)
Failing nodes: idefix
Summary
-------
Deprecation warning for using list as loop for package managers instead of installing the list. See other roles (eg. common) for the fix of this issue....Calling host: obelix.las.kit.edu (Fedora 31)
Failing nodes: idefix
Summary
-------
Deprecation warning for using list as loop for package managers instead of installing the list. See other roles (eg. common) for the fix of this issue.
Steps to reproduce
------------------
Run sites.yml
What is the current bug behavior?
---------------------------------
Deprecation warning
What is the expected correct behaviour?
---------------------------------------
No deprecation warning
Relevant logs and/or screenshots
--------------------------------
```
TASK [ipynb : install Jupyter notebook for Python 3] *****************************************************************
[DEPRECATION WARNING]: Invoking "dnf" only once while using a loop via squash_actions is deprecated. Instead of using
a loop to supply multiple items and specifying `name: "{{ item }}"`, please use `name: ['python3-jupyter-core',
'python3-ipykernel', 'python3-nbformat', 'python3-ipdb', 'python3-ipython']` and remove the loop. This feature will
be removed in version 2.11. Deprecation warnings can be disabled by setting deprecation_warnings=False in
ansible.cfg.
ok: [idefix.las.kit.edu] => (item=['python3-jupyter-core', 'python3-ipykernel', 'python3-nbformat', 'python3-ipdb', 'python3-ipython'])
TASK [ipynb : install Jupyter notebook extensions] *******************************************************************
[DEPRECATION WARNING]: Invoking "pip" only once while using a loop via squash_actions is deprecated. Instead of using
a loop to supply multiple items and specifying `name: "{{ item }}"`, please use `name: ['ipywidgets']` and remove
the loop. This feature will be removed in version 2.11. Deprecation warnings can be disabled by setting
deprecation_warnings=False in ansible.cfg.
ok: [idefix.las.kit.edu] => (item=['ipywidgets'])
```
Possible fixes
--------------
Don't use a loop (with_items), but provide the list as the `name` argument.
/cc @vn4918https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/95lasarchiv1 role fails sometimes2020-05-14T18:00:01+02:00sg7149lasarchiv1 role fails sometimesCalling host: obelix.las.kit.edu (Fedora 31)
Failing nodes: pepe, faulus
Summary
-------
Running the newly merged code !43 it first failed for some hosts, but not for all.
After having a look at https://github.com/ansible/ansible/issu...Calling host: obelix.las.kit.edu (Fedora 31)
Failing nodes: pepe, faulus
Summary
-------
Running the newly merged code !43 it first failed for some hosts, but not for all.
After having a look at https://github.com/ansible/ansible/issues/29814 and changing `remounted` to `mounted` again succeeded.
But `mounted` initially failed, so maybe it is the bug and we cannot do much about it in our role. From the github-issue, I understand the documentation like it should work with `mounted` which is more consistent with the idea of stateless-ness though I read the documentation of the `mount` module differently the last time.
Steps to reproduce
------------------
Run `ansible-playbook --vault-password-file password nfs.yml --skip-tags fonts`.
What is the current bug behavior?
---------------------------------
SOMETIMES:
Hosts with unmounted /mnt/las-archiv1 and not installed fail. Broken, and correctly mounted /mnt/las-archiv1 machines do not fail.
What is the expected correct behaviour?
---------------------------------------
ALWAYS: None of the machines fail and all have a mounted /mnt/las-archiv1
Relevant logs and/or screenshots
--------------------------------
```
TASK [lasarchiv : remount lasarchiv1] ********************************************************************************
fatal: [homoeopatix.las.kit.edu]: FAILED! => {"changed": false, "msg": "Error remounting /mnt/las-archiv1: umount: /mnt/las-archiv1: not mounted.\n"}
changed: [methusalix.las.kit.edu]
changed: [majestix.las.kit.edu]
changed: [troubadix.las.kit.edu]
fatal: [faulus.las.kit.edu]: FAILED! => {"changed": false, "msg": "Error remounting /mnt/las-archiv1: umount: /mnt/las-archiv1: no mount point specified.\n"}
fatal: [pepe.las.kit.edu]: FAILED! => {"changed": false, "msg": "Error remounting /mnt/las-archiv1: umount: /mnt/las-archiv1: not mounted.\n"}
changed: [idefix.las.kit.edu]
```
https://github.com/ansible/ansible/issues/29814
Possible fixes
--------------
(If you can, link to the line of code that might be responsible for the problem)
/cc @vn4918https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/93teamviewer installation stopps updates2020-08-17T09:57:29+02:00sg7149teamviewer installation stopps updatesCalling host: obelix.las.kit.edu (Fedora 31)
Failing nodes: pepe, asterix
Summary
-------
Updates fail, because teamviewer repo cannot be found
Steps to reproduce
------------------
enable the teamviewer repositories () and run `dn...Calling host: obelix.las.kit.edu (Fedora 31)
Failing nodes: pepe, asterix
Summary
-------
Updates fail, because teamviewer repo cannot be found
Steps to reproduce
------------------
enable the teamviewer repositories () and run `dnf update`
What is the current bug behavior?
---------------------------------
```
Failed to synchronize cache for repo 'tvinternal_dev'
Ignoring repositories: tvinternal_dev
```
when running via ansible, it fails due to timeouts.
What is the expected correct behaviour?
---------------------------------------
Update runs without any problems.
Relevant logs and/or screenshots
--------------------------------
```
(Paste any relevant logs - please use code blocks (```) to format console output,
logs, and code as it's very hard to read otherwise.)
```
Possible fixes
--------------
As a workaround one can deactivate the repository, but then teamviewer will not get updates!
/cc @vn4918lp5884lp5884https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/92ansible ipv6 vs root2020-05-13T10:44:29+02:00sg7149ansible ipv6 vs rootansible tries to use IPv6 now that our hosts have proper DNS for IPv6.
Unfortunately the SSH-key for root only allows the IPv4 of obelix, so that running ansible fail atm.
One should either change the SSH-allowed IP addresses.
Or one sh...ansible tries to use IPv6 now that our hosts have proper DNS for IPv6.
Unfortunately the SSH-key for root only allows the IPv4 of obelix, so that running ansible fail atm.
One should either change the SSH-allowed IP addresses.
Or one should force ansible to use IPv4 only.https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/91Add networking to common role2020-05-13T12:10:22+02:00sg7149Add networking to common roleAdd some basic networking setup to the common role (maybe via nmcli-module)
* [ ] DNS v4, v6
* [ ] Default gateway v4 v6
* [x] Hostname
* [ ] dhclient on start
* [ ] auto negotiationAdd some basic networking setup to the common role (maybe via nmcli-module)
* [ ] DNS v4, v6
* [ ] Default gateway v4 v6
* [x] Hostname
* [ ] dhclient on start
* [ ] auto negotiationhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/90Autoupdate on lab computers2020-07-15T15:40:04+02:00sg7149Autoupdate on lab computersChange the settings from security to all updates.
The computers are not used on a daily basis by one user, but may not be used interactively for some time. Hence the updates aren't triggered by the user, but there is also no user that ex...Change the settings from security to all updates.
The computers are not used on a daily basis by one user, but may not be used interactively for some time. Hence the updates aren't triggered by the user, but there is also no user that expects certain behaviour not to change.https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/89Add fix to missing users at CN login screen2020-03-03T14:43:07+01:00sg7149Add fix to missing users at CN login screenFailing nodes: nichtsalsverdrus (Fedora LXQt)
Summary
-------
Users with UIDs of the IPA range and not the typical Linux user range (1000+) weren't shown in the login screen and one cannot type a user name either.
Steps to reproduce
...Failing nodes: nichtsalsverdrus (Fedora LXQt)
Summary
-------
Users with UIDs of the IPA range and not the typical Linux user range (1000+) weren't shown in the login screen and one cannot type a user name either.
Steps to reproduce
------------------
Log out and have a look at the login screen of the LXQt (SDDM) Fedora.
What is the current bug behavior?
---------------------------------
No users shown with too large UID (until workaround)
What is the expected correct behaviour?
---------------------------------------
All users selectable as login users.
Possible fixes
--------------
Fixed it (but not in ansible and not with a good upper limit, but only a value that is larger than the largest UID that is in use and small enough to show users.
If the UID is too large no user is shown at all.
In the `/etc/sddm.conf` one has to add the following lines:
```
HideUsers=nfsnobody
MaximumUid=1911111111
```
and restart sddm/Xorg.https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/88SDDM not showing users2020-03-01T01:10:33+01:00sg7149SDDM not showing usersOnly the installation (local) user is displayed at the login screen.
[My documentation](https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/systemdocu/-/blob/master/ipa/freeipa.md#sddmlogin-manager)
suggests, that ...Only the installation (local) user is displayed at the login screen.
[My documentation](https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/systemdocu/-/blob/master/ipa/freeipa.md#sddmlogin-manager)
suggests, that it might help to add the network as a dependency to the sddm.service
```
SDDM/Login-Manager
In the case that KDE’s default login manager SDDM does not show any accounts to select for logging in, the following might help: Copy sddm.service from /lib/systemd/system to /etc/systemd/system, and add a line After=network.target to the [Unit] section.
```
Implement it as part of the ipa-hosts role.https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/87Add backup daemon to LASMagLab computer2020-06-09T15:54:01+02:00sg7149Add backup daemon to LASMagLab computerLike done on the CN TGU terminal, it would make sense to have a backup daemon for the measurement data of the LASMagLab (on ueberdrus), too.
See also: las-software/15-1-Controls/Jena_UndulatorDocumentation#5 and las-it-organisation/issu...Like done on the CN TGU terminal, it would make sense to have a backup daemon for the measurement data of the LASMagLab (on ueberdrus), too.
See also: las-software/15-1-Controls/Jena_UndulatorDocumentation#5 and las-it-organisation/issues#8 and https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/systemdocu/-/blob/master/experiment_backup.md
It's not trivial and requires some more advanced knowledge of (Fedora/RHEL) Linux like SELinux and systemd.
@ue5734 hopefully understands my documentation and can do it or assist you (@vn4918 @updzh).ue5734ue5734https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/85Opera on Fedora 312020-03-02T14:52:39+01:00sg7149Opera on Fedora 31To work around Opera not starting on Fedora 31 I linked the libhwloc.so.5->libhwloc.so.15.
Maybe one should also copy libhwloc.so.5 from CentOS7 (kantine) instead of linking the new one.
Probably also the new Opera 2020 will not depend ...To work around Opera not starting on Fedora 31 I linked the libhwloc.so.5->libhwloc.so.15.
Maybe one should also copy libhwloc.so.5 from CentOS7 (kantine) instead of linking the new one.
Probably also the new Opera 2020 will not depend on libhwloc.so.15, because their webpage claims to support RHEL7, but not RHEL8 and even RHEL8 seems to have libhwloc.so.5 instead of .15.https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/84Rename [lab] to [maglab]2020-07-15T16:08:35+02:00sg7149Rename [lab] to [maglab]Rename `[lab]` role to avoid ambiguities between eg. LASMagLab and TGU-measurement stand.
(incomplete) list of its occurrence:
* hosts
* roles/lab
* sites.yml
* lab.yml
* README?Rename `[lab]` role to avoid ambiguities between eg. LASMagLab and TGU-measurement stand.
(incomplete) list of its occurrence:
* hosts
* roles/lab
* sites.yml
* lab.yml
* README?yuancun.nieyuancun.niehttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/83LASMagLab DHCPd with template instead of static file2020-02-29T23:16:35+01:00sg7149LASMagLab DHCPd with template instead of static fileOne might want to use a template for the DHCPd server entry in the `dhcpd.conf`, so that one does not have to change it for a new computer.
Hints/Ideas for the template:
* MAC address: ('ansible_interfaces' starts with 'enp') ['ansible_...One might want to use a template for the DHCPd server entry in the `dhcpd.conf`, so that one does not have to change it for a new computer.
Hints/Ideas for the template:
* MAC address: ('ansible_interfaces' starts with 'enp') ['ansible_enp????']['macaddress'] when ['ansible_enp???']['ipv4']['network'] == '192.168.0.0'
* Hostname: ['ansible_fqdn']
* IP: '192.168.0.1'
```
# DHCPd host
host {{'ansible_hostname'}} {
hardware ethernet {{ macaddress }};
fixed-address {{ ip }};
}
```https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/82Install LASMagLab software on terminal computer2020-02-24T17:16:42+01:00sg7149Install LASMagLab software on terminal computerInstall the LASMagLab software on the terminal [lab] computer and add the GitLab-Token automatically.
Atm. the computer is only setup as a normal epics client and DHCPd server, but not with all the Control system components installed, y...Install the LASMagLab software on the terminal [lab] computer and add the GitLab-Token automatically.
Atm. the computer is only setup as a normal epics client and DHCPd server, but not with all the Control system components installed, yet.
Also the (Python) dependencies might be missing.
Checking out all the software at `/usr/local/share` would make sense.
The computer needed to be replaced quite often in the near past and might be replaced in the not too far future, so it would make sense to automate it.
At least one should do it when setting it up as a CSS host (if one sticks to our Fedora/ansible deployment and does not change completely to CN-machine-group's Ubuntu/salt-stack deployment)https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/80VGA-port @ ThinkCentres2020-02-17T15:54:47+01:00sg7149VGA-port @ ThinkCentresThe VGA-port on ThinkCentres seems to misbehave on Linux.
ThinkCentres (new M920t) with VGA connected to a VGA-Display boots and when switching to a higher resolution during booting (the monitor searches for signal and turns off).
Durin...The VGA-port on ThinkCentres seems to misbehave on Linux.
ThinkCentres (new M920t) with VGA connected to a VGA-Display boots and when switching to a higher resolution during booting (the monitor searches for signal and turns off).
During installation with KDE-Live-System it was possible to switch to a non-graphical console (ctrl+alt+2) and to login there and reboot (killing X did not help).
Probably it's possible to fix it with the right boot-flags.