ansible issueshttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues2021-09-03T15:42:18+02:00https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/42Fix nfs-server role2021-09-03T15:42:18+02:00sg7149Fix nfs-server roleThe server role has got syntax errors and therefore fails.
Tested on las115 and las127The server role has got syntax errors and therefore fails.
Tested on las115 and las127https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/41Opera role fails on Fedora 292019-01-14T18:26:18+01:00sg7149Opera role fails on Fedora 29Calling host: las127.las.kit.edu (Fedora 29)
Failing nodes: las127
Summary
-------
Role fails with some hints on comparison operator and string.
Steps to reproduce
------------------
Try to run the opera-role on new Fedora 29 insta...Calling host: las127.las.kit.edu (Fedora 29)
Failing nodes: las127
Summary
-------
Role fails with some hints on comparison operator and string.
Steps to reproduce
------------------
Try to run the opera-role on new Fedora 29 installation
What is the current bug behaviour?
----------------------------------
Installation fails.
What is the expected correct behaviour?
---------------------------------------
Installation works
Relevant logs and/or screenshots
--------------------------------
/cc @gethmann @xr4779https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/39nginx not listing directories correctly2021-09-03T15:45:15+02:00sg7149nginx not listing directories correctlynginx returns 403 and logs "directory index of ... is forbidden".
Host: las101
e.g. for the RPM repo (lasrepo)nginx returns 403 and logs "directory index of ... is forbidden".
Host: las101
e.g. for the RPM repo (lasrepo)https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/34Printer defaults to single page printing2020-08-24T17:43:49+02:00sg7149Printer defaults to single page printingFailing nodes: las113, las118 (Fedora 27, 28)
Summary
-------
Default for printing is no-duplex
Steps to reproduce
------------------
Print file from okular
What is the expected correct behaviour?
---------------------------------...Failing nodes: las113, las118 (Fedora 27, 28)
Summary
-------
Default for printing is no-duplex
Steps to reproduce
------------------
Print file from okular
What is the expected correct behaviour?
---------------------------------------
Duplex, long-edge as default.
Possible fixes
--------------
Either edit the files in the `client` role appropriately or change the default settings locally in CUPS (https://localhost:631) via KDE's printing dialogue and diff the files with the aforementioned.
/cc @gethmann @xr4779https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/32sshd template causes error2020-05-04T12:30:17+02:00sg7149sshd template causes errorCalling host: las113.las.kit.edu (Fedora 27)
Failing nodes: localhost -i local
Summary
-------
ansible fails with an error message in the firewalld role complaining about syntax errors.
Steps to reproduce
------------------
run `an...Calling host: las113.las.kit.edu (Fedora 27)
Failing nodes: localhost -i local
Summary
-------
ansible fails with an error message in the firewalld role complaining about syntax errors.
Steps to reproduce
------------------
run `ansible-playbook latex.yml -l localhost --vault-id @prompt -K -i local`
What is the current bug behavior?
---------------------------------
fails with an error on my Fedora 27. Might work on Fedora 28.
What is the expected correct behaviour?
---------------------------------------
continue and install a proper sshd config
Relevant logs and/or screenshots
--------------------------------
```
TASK [common : install firewalld] ******************************************************
fatal: [127.0.0.1]: FAILED! => {"msg": "The conditional check '((ansible_distribution == \"Fedora\" and ansible_distribution_major_version < 28) or (ansible_distribution == \"CentOS\" and ansible_distribution_major_version >= 7))' failed. The error was: Unexpected templating type error occurred on ({% if ((ansible_distribution == \"Fedora\" and ansible_distribution_major_version < 28) or (ansible_distribution == \"CentOS\" and ansible_distribution_major_version >= 7)) %} True {% else %} False {% endif %}): '<' not supported between instances of 'AnsibleUnsafeText' and 'int'\n\nThe error appears to have been in '/home/gethmann/ansible/ansible/roles/common/tasks/sshd.yml': line 8, column 3, but may\nbe elsewhere in the file depending on the exact syntax problem.\n\nThe offending line appears to be:\n\n\n- name: install firewalld\n ^ here\n"}
```
Possible fixes
--------------
/cc @gethmannhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/31DHCPd on Ubuntu validation fails2020-02-24T17:34:58+01:00sg7149DHCPd on Ubuntu validation failsCalling host: las126.las.kit.edu (Fedora 27)
Failing nodes: las93
Summary
-------
The validation of the DHCPd config fails on Ubuntu (Lab computer).
There is at least one person experiencing the same issue,
https://superuser.com/quest...Calling host: las126.las.kit.edu (Fedora 27)
Failing nodes: las93
Summary
-------
The validation of the DHCPd config fails on Ubuntu (Lab computer).
There is at least one person experiencing the same issue,
https://superuser.com/questions/1286948/ansible-template-validation-fails-on-isc-dhcp-server , but no answer so far.
The file is not copied and the task aborts.
Steps to reproduce
------------------
Run the lab role with `validate: "{{ bin_path }} -t -cf %s"` activated.
What is the current bug behavior?
---------------------------------
The role fails and the files `host-list-maglab` and `dhcpd.conf` are not copied to the node.
What is the expected correct behaviour?
---------------------------------------
The task succeeds and the dhcpd.conf and the decrypted host-list-maglab file are at the node.
Relevant logs and/or screenshots
--------------------------------
```
failed: [las93.las.kit.edu] (item=maglab.hosts) => {"changed": false, "checksum": "6ba7f7faa00e05e763266888a31054cc20a58909", "exit_status": 1, "item": "maglab.hosts", "msg": "failed to validate", "stderr": "Internet Systems Consortium DHCP Server 4.2.4\nCopyright 2004-2012 Internet Systems Consortium.\nAll rights reserved.\nFor info, please visit https://www.isc.org/software/dhcp/\nCan't open /root/.ansible/tmp/ansible-tmp-1528358315.88-158600528943595/source: Permission denied\n", "stderr_lines": ["Internet Systems Consortium DHCP Server 4.2.4", "Copyright 2004-2012 Internet Systems Consortium.", "All rights reserved.", "For info, please visit https://www.isc.org/software/dhcp/", "Can't open /root/.ansible/tmp/ansible-tmp-1528358315.88-158600528943595/source: Permission denied"], "stdout": "", "stdout_lines": []}
failed: [las93.las.kit.edu] (item=dhcpd.conf) => {"changed": false, "checksum": "c8f8782d9486025107e622108f35cbea7f6da629", "exit_status": 1, "item": "dhcpd.conf", "msg": "failed to validate", "stderr": "Internet Systems Consortium DHCP Server 4.2.4\nCopyright 2004-2012 Internet Systems Consortium.\nAll rights reserved.\nFor info, please visit https://www.isc.org/software/dhcp/\nCan't open /root/.ansible/tmp/ansible-tmp-1528358317.34-230984934434610/source: Permission denied\n", "stderr_lines": ["Internet Systems Consortium DHCP Server 4.2.4", "Copyright 2004-2012 Internet Systems Consortium.", "All rights reserved.", "For info, please visit https://www.isc.org/software/dhcp/", "Can't open /root/.ansible/tmp/ansible-tmp-1528358317.34-230984934434610/source: Permission denied"], "stdout": "", "stdout_lines": []}
```
Possible fixes
--------------
Work around: Check the validity at your own host and don't use the validity check on the node.
/cc @gethmannhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/30Opera HTML Manual is not readable2021-09-03T15:51:45+02:00ll5790Opera HTML Manual is not readableCalling host: las118.las.kit.edu (Fedora 28)
Failing nodes: las118
Summary
-------
Oper Manual owned by root: Opera can not open the file.
Steps to reproduce
------------------
Opera -> Help Manual (HTML)
What is the current bug ...Calling host: las118.las.kit.edu (Fedora 28)
Failing nodes: las118
Summary
-------
Oper Manual owned by root: Opera can not open the file.
Steps to reproduce
------------------
Opera -> Help Manual (HTML)
What is the current bug behavior?
---------------------------------
see above.
What is the expected correct behaviour?
---------------------------------------
Open Manual in Browser.
Possible fixes
--------------
Change reading rights: Grant access.
/cc @gethmannhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/29opera_manager fails starting2018-06-07T15:38:00+02:00sg7149opera_manager fails startingFailing nodes: las113 (Fedora 27)
Summary
-------
`opera_manager` did not start.
Steps to reproduce
------------------
run `opera_manager` in the terminal
What is the current bug behavior?
---------------------------------
Fails ...Failing nodes: las113 (Fedora 27)
Summary
-------
`opera_manager` did not start.
Steps to reproduce
------------------
run `opera_manager` in the terminal
What is the current bug behavior?
---------------------------------
Fails with error message
What is the expected correct behaviour?
---------------------------------------
Opera starts
Relevant logs and/or screenshots
--------------------------------
```
~ opera_manager
/usr/local/share/Opera_18R2/code/bin/opera_manager: error while loading shared libraries: libpcre16.so.0: cannot open shared object file: No such file or directory
```
Possible fixes
--------------
Install `pcre-utf16`
/cc @gethmannsg7149sg7149https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/26EPICS_CA_ADDR_LIST hard is coded2020-02-24T17:39:28+01:00sg7149EPICS_CA_ADDR_LIST hard is codedCalling host: las113.las.kit.edu (Fedora 27)
Failing nodes: las115
Summary
-------
Because the EPICS_CA_ADDR_LIST is hard coded for KARA in the `profile.d` file it is not practical for the Jena/TGU setup.
What is the current bug beh...Calling host: las113.las.kit.edu (Fedora 27)
Failing nodes: las115
Summary
-------
Because the EPICS_CA_ADDR_LIST is hard coded for KARA in the `profile.d` file it is not practical for the Jena/TGU setup.
What is the current bug behavior?
---------------------------------
The environment variable `EPICS_CA_ADDR_LIST` is set to a server that is responsible for the KARA PVs, but not depending on the use-case for KARA, FLUTE or JENA/TGU.
What is the expected correct behaviour?
---------------------------------------
The variable should be like it is for a KARA role, and different or not set for a JENA/TGU role.
Iff it is not set, it should be noted in the docu and as a `msg`.
Possible fixes
--------------
Create a role for KARA/CSS and a role for Jena/TGU control system and one without it being set.
/cc @project-managerhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/25texlive package names might change in future Fedora releases2021-09-03T14:43:48+02:00sg7149texlive package names might change in future Fedora releasesFedora 27 does not use the current stable TexLive version 2017.
For the next Fedora release the names of the texlive packages might change, because there is an [issue about renaming](https://bugzilla.redhat.com/show_bug.cgi?id=1505342) f...Fedora 27 does not use the current stable TexLive version 2017.
For the next Fedora release the names of the texlive packages might change, because there is an [issue about renaming](https://bugzilla.redhat.com/show_bug.cgi?id=1505342) from `texlive` into `texlive-base` and `texlive`.
Test via copr:
```
dnf copr enable spot/texlive
```https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/23EPICS installation fails due to (invalid) certificates2021-09-03T15:53:58+02:00sg7149EPICS installation fails due to (invalid) certificatesCalling host: las113.las.kit.edu (Fedora 27)
Failing nodes: las117
Summary
--------
epics role fails at installation/downloading of the files
Steps to reproduce
-------------------
run the `epics` role, e.g. by ``site.yml``
What is...Calling host: las113.las.kit.edu (Fedora 27)
Failing nodes: las117
Summary
--------
epics role fails at installation/downloading of the files
Steps to reproduce
-------------------
run the `epics` role, e.g. by ``site.yml``
What is the current bug behaviour?
----------------------------------
Role fails and EPICS will not install
What is the expected correct behavior?
---------------------------------------
Installation of epics
Relevant logs and/or screenshots
---------------------------------
```
TASK [epics : unarchived] ********************************************************************************************************************************************************
fatal: [las117.las.kit.edu]: FAILED! => {"changed": false, "msg": "Failed to validate the SSL certificate for www.aps.anl.gov:443. Make sure your managed systems have a valid CA certificate installed. You can use validate_certs=False if you do not need to confirm the servers identity but this is unsafe and not recommended. Paths checked for this platform: /etc/ssl/certs, /etc/pki/ca-trust/extracted/pem, /etc/pki/tls/certs, /usr/share/ca-certificates/cacert.org, /etc/ansible. The exception msg was: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:661)."}
```
Possible fixes
(If you can, link to the line of code that might be responsible for the problem)
/cc @project-managerhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/21(KIT)Latex installation fails because of failing copy2020-08-24T17:49:50+02:00sg7149(KIT)Latex installation fails because of failing copyCalling host: las113.las.kit.edu (Fedora 27)
Failing nodes: las117 (Fedora 27)
Summary
``with_glob`` fails when used with ``copy`` and ``tempdir``
Steps to reproduce
Run the KITLaTeX tasks.
What is the current bug behavior?
Task...Calling host: las113.las.kit.edu (Fedora 27)
Failing nodes: las117 (Fedora 27)
Summary
``with_glob`` fails when used with ``copy`` and ``tempdir``
Steps to reproduce
Run the KITLaTeX tasks.
What is the current bug behavior?
Task `hack Helvetica into KIT styles due to broken font installation` fails because `copy tex files` does not work.
What is the expected correct behavior?
Files are copied and the task can run.
Relevant logs and/or screenshots
```
TASK [latex : copy pdf files] *********************************************************************************************************
task path: /home/gethmann/ansible/ansible/roles/latex/tasks/KITLaTeX.yml:68
[WARNING]: Unable to find '/tmp/ansiEtob1c/doc/latex/KIT' in expected paths.
```
/cc @gethmannhttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/20ipynb fails2020-08-24T17:48:49+02:00sg7149ipynb fails```
RUNNING HANDLER [ipynb : activate ipywidgets] *****************************************************************************************
fatal: [las117.las.kit.edu]: FAILED! => {"changed": false, "cmd": "jupyter-nbextension enable --p...```
RUNNING HANDLER [ipynb : activate ipywidgets] *****************************************************************************************
fatal: [las117.las.kit.edu]: FAILED! => {"changed": false, "cmd": "jupyter-nbextension enable --py --sys-prefix widgetsnbextension", "failed": true, "msg": "[Errno 2] No such file or directory", "rc": 2}
```https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/19Opera depends on a user with access rights to las-archiv2021-09-03T15:55:28+02:00sg7149Opera depends on a user with access rights to las-archivAdd IPA client as a dependency in the meta. See #13 and #5
So atm it is only possible to install Opera on an already running system.Add IPA client as a dependency in the meta. See #13 and #5
So atm it is only possible to install Opera on an already running system.https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/18elegant for Fedora 272017-11-22T09:24:15+01:00sg7149elegant for Fedora 27No RPMs available yetNo RPMs available yethttps://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/17Installation of neo2 support fail2017-11-21T18:24:54+01:00sg7149Installation of neo2 support fail```
TASK [latex : compile package docu] ********************************************************************************
fatal: [127.0.0.1]: FAILED! => {"changed": true, "cmd": ["pdflatex", "-interaction=nonstopmode", "uniinput.dtx"], "d...```
TASK [latex : compile package docu] ********************************************************************************
fatal: [127.0.0.1]: FAILED! => {"changed": true, "cmd": ["pdflatex", "-interaction=nonstopmode", "uniinput.dtx"], "delta": "0:00:00.044006", "end": "2017-11-07 17:44:07.041620", "failed": true, "msg": "non-zero return code", "rc": 1, "start": "2017-11-07 17:44:06.997614", "stderr": "", "stderr_lines": [], "stdout": "This is pdfTeX, Version 3.14159265-2.6-1.40.17 (TeX Live 2016) (preloaded format=pdflatex)\n restricted \\write18 enabled.\nentering extended mode\n! I can't find file `uniinput.dtx'.\n<*> uniinput.dtx\n \n(Press Enter to retry, or Control-D to exit)\nPlease type another input file name\n! Emergency stop.\n<*> uniinput.dtx\n \n! ==> Fatal error occurred, no output PDF file produced!\nTranscript written on texput.log.", "stdout_lines": ["This is pdfTeX, Version 3.14159265-2.6-1.40.17 (TeX Live 2016) (preloaded format=pdflatex)", " restricted \\write18 enabled.", "entering extended mode", "! I can't find file `uniinput.dtx'.", "<*> uniinput.dtx", " ", "(Press Enter to retry, or Control-D to exit)", "Please type another input file name", "! Emergency stop.", "<*> uniinput.dtx", " ", "! ==> Fatal error occurred, no output PDF file produced!", "Transcript written on texput.log."]}
```
and
```
TASK [latex : compile package] *************************************************************************************
fatal: [127.0.0.1]: FAILED! => {"changed": true, "cmd": ["latex", "uniinput.ins"], "delta": "0:00:00.047986", "end": "2017-11-07 17:44:07.256987", "failed": true, "msg": "non-zero return code", "rc": 1, "start": "2017-11-07 17:44:07.209001", "stderr": "", "stderr_lines": [], "stdout": "This is pdfTeX, Version 3.14159265-2.6-1.40.17 (TeX Live 2016) (preloaded format=latex)\n restricted \\write18 enabled.\nentering extended mode\n! I can't find file `uniinput.ins'.\n<*> uniinput.ins\n \n(Press Enter to retry, or Control-D to exit)\nPlease type another input file name: \n! Emergency stop.\n<*> uniinput.ins\n \nNo pages of output.\nTranscript written on texput.log.", "stdout_lines": ["This is pdfTeX, Version 3.14159265-2.6-1.40.17 (TeX Live 2016) (preloaded format=latex)", " restricted \\write18 enabled.", "entering extended mode", "! I can't find file `uniinput.ins'.", "<*> uniinput.ins", " ", "(Press Enter to retry, or Control-D to exit)", "Please type another input file name: ", "! Emergency stop.", "<*> uniinput.ins", " ", "No pages of output.", "Transcript written on texput.log."]}
```https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/16Fix latex role: handler mktexlsr2017-11-21T18:24:54+01:00sg7149Fix latex role: handler mktexlsr`mktexlsr` is not run correctly with the handler.
Package is not available immediately after installation, but after running `mktexlsr` as root (`$ sudo su ; # mktexlsr`)`mktexlsr` is not run correctly with the handler.
Package is not available immediately after installation, but after running `mktexlsr` as root (`$ sudo su ; # mktexlsr`)https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/14skipping of elegant SDDSToolKit fails on F WS 252017-10-09T13:05:30+02:00sg7149skipping of elegant SDDSToolKit fails on F WS 25Though this should be skipped (like it does, when using the debug module), it does not and therefore fails.
role: elegant/tasks/elegant.yml lines 44 onwards
computer: las-gethmann.las.kit.edu
```
TASK [elegant : install SDDSToolKit] ...Though this should be skipped (like it does, when using the debug module), it does not and therefore fails.
role: elegant/tasks/elegant.yml lines 44 onwards
computer: las-gethmann.las.kit.edu
```
TASK [elegant : install SDDSToolKit] ********************************************************************************************************************************************************************************************************
fatal: [127.0.0.1]: FAILED! => {"changed": false, "failed": true, "module_stderr": "No handlers could be found for logger \"dnf\"\nTraceback (most recent call last):\n File \"/tmp/ansible__ZtL8C/ansible_module_dnf.py\", line 534, in <module>\n main()\n File \"/tmp/ansible__ZtL8C/ansible_module_dnf.py\", line 530, in main\n ensure(module, base, params['state'], params['name'], params['autoremove'])\n File \"/tmp/ansible__ZtL8C/ansible_module_dnf.py\", line 364, in ensure\n _install_remote_rpms(base, filenames)\n File \"/tmp/ansible__ZtL8C/ansible_module_dnf.py\", line 322, in _install_remote_rpms\n pkgs.append(base.add_remote_rpm(filename))\n File \"/usr/lib/python2.7/site-packages/dnf/base.py\", line 925, in add_remote_rpm\n return self.sack.add_cmdline_package(path)\nIOError: Can not load RPM file: 26: u'3.5.1-1'}.fedora.25.x86_64.rpm.\n", "module_stdout": "", "msg": "MODULE FAILURE", "rc": 0}
```https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/102Environment dependent epics configuration2020-07-15T14:59:38+02:00sg7149Environment dependent epics configurationEPICS is used for different purposes/environments which currently include:
* KARA
* LASMagLab
* TGU measurement
* Jena magnet setup
The configuration so far is only valid for one case only and the other configurations are changed by han...EPICS is used for different purposes/environments which currently include:
* KARA
* LASMagLab
* TGU measurement
* Jena magnet setup
The configuration so far is only valid for one case only and the other configurations are changed by hand which
- needs more steps for the installation and
- is error prone to (re-)running ansible.
This should be fixed.
See also issue #9https://git.scc.kit.edu/las-it-organisation/32-0-IT-InstructionsAndRules/ansible/-/issues/92ansible ipv6 vs root2020-05-13T10:44:29+02:00sg7149ansible ipv6 vs rootansible tries to use IPv6 now that our hosts have proper DNS for IPv6.
Unfortunately the SSH-key for root only allows the IPv4 of obelix, so that running ansible fail atm.
One should either change the SSH-allowed IP addresses.
Or one sh...ansible tries to use IPv6 now that our hosts have proper DNS for IPv6.
Unfortunately the SSH-key for root only allows the IPv4 of obelix, so that running ansible fail atm.
One should either change the SSH-allowed IP addresses.
Or one should force ansible to use IPv4 only.