From ef76a75125d926c05c290e3daef12e3aee289502 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Fri, 22 May 2026 17:08:25 +0200 Subject: [PATCH 01/13] =?UTF-8?q?chore(meta):=20bump=20=5Fwaves-testing.md?= =?UTF-8?q?=20=E2=80=94=20close=20WAVE=5F02=20(2026-05-22),=20open=20WAVE?= =?UTF-8?q?=5F03?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- _waves-testing.md | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/_waves-testing.md b/_waves-testing.md index cf5f268a..1b00cd68 100644 --- a/_waves-testing.md +++ b/_waves-testing.md @@ -15,7 +15,14 @@ the wave (e.g. WAVE_01 has 3 umbrellas across 3 repos). A single umbrella covering cross-repo work is also valid (e.g. WAVE_02 has 1 umbrella on playbooks that also tracks devkit work via SHA refs in its body). -## WAVE_02 - in progress +## WAVE_03 - in progress + +- range42/range42-playbooks#62 +- range42/range42#174 +- range42/range42-ansible_roles-debug-devkit#110 +- range42/range42-catalog#164 + +## WAVE_02 - 2026-05-22 - range42/range42-playbooks#55 From cfeb7fed9f2162bfaca65b315626f70906c17efa Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Tue, 26 May 2026 16:09:35 +0200 Subject: [PATCH 02/13] chore: rename inventory group proxmox-cli to proxmox_cli (#63) --- .../templates/ubuntu_noble/00-template-vm-nano.yml | 2 +- .../templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml | 2 +- .../templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml | 2 +- .../templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml | 2 +- .../templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml | 2 +- .../templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml | 2 +- .../ubuntu_noble/03-template-vm-medium-02-8g-64g.yml | 2 +- .../ubuntu_noble/03-template-vm-medium-04-8g-64g.yml | 2 +- .../ubuntu_noble/03-template-vm-medium-06-8g-64g.yml | 2 +- .../templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml | 2 +- .../templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml | 2 +- .../templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml | 2 +- .../templates/ubuntu_noble/00-template-vm-nano.yml | 4 ++-- .../templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml | 4 ++-- .../templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-02-8g-64g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-04-8g-64g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-06-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/_apply_apt_proxy.yml | 2 +- .../templates/ubuntu_noble/_update_templates.yml | 4 ++-- .../templates/ubuntu_noble/test_setup_templates.yml | 2 +- .../blank_scenario_2_subnets/templates/ansible-inventory.j2 | 2 +- .../templates/ubuntu_noble/00-template-vm-nano.yml | 4 ++-- .../templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml | 4 ++-- .../templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-02-8g-64g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-04-8g-64g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-06-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/_apply_apt_proxy.yml | 2 +- .../templates/ubuntu_noble/_update_templates.yml | 4 ++-- .../templates/ubuntu_noble/test_setup_templates.yml | 2 +- .../blank_scenario_4_subnets/templates/ansible-inventory.j2 | 2 +- .../templates/ubuntu_noble/00-template-vm-nano.yml | 4 ++-- .../templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml | 4 ++-- .../templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml | 4 ++-- .../templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-02-8g-64g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-04-8g-64g.yml | 4 ++-- .../ubuntu_noble/03-template-vm-medium-06-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml | 4 ++-- .../templates/ubuntu_noble/_apply_apt_proxy.yml | 2 +- .../templates/ubuntu_noble/_update_templates.yml | 4 ++-- .../templates/ubuntu_noble/test_setup_templates.yml | 2 +- .../blank_scenario_6_subnets/templates/ansible-inventory.j2 | 2 +- .../templates/alpine/00-template-vm-alpine-nano.yml | 2 +- .../templates/debian/00-template-vm-debian-nano.yml | 2 +- .../templates/ubuntu_noble/00-template-vm-nano.yml | 2 +- scenarios/debug_scenario_a/templates/ansible-inventory.j2 | 2 +- .../templates/alpine/00-template-vm-alpine-nano.yml | 2 +- .../templates/debian/00-template-vm-debian-nano.yml | 2 +- .../templates/ubuntu_noble/00-template-vm-nano.yml | 2 +- scenarios/debug_scenario_b/templates/ansible-inventory.j2 | 2 +- .../templates/ubuntu_noble/00-template-vm-nano.yml | 2 +- .../templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml | 2 +- .../templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml | 2 +- .../templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml | 2 +- .../templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml | 2 +- .../templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml | 2 +- .../ubuntu_noble/03-template-vm-medium-02-8g-64g.yml | 2 +- .../ubuntu_noble/03-template-vm-medium-04-8g-64g.yml | 2 +- .../ubuntu_noble/03-template-vm-medium-06-8g-64g.yml | 2 +- .../templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml | 2 +- .../templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml | 2 +- .../templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml | 2 +- .../templates/ubuntu_noble/test_setup_templates.yml | 2 +- scenarios/demo_lab/templates/ansible-inventory.j2 | 2 +- scenarios/demo_lab/templates/ssh-config.j2 | 2 +- 83 files changed, 122 insertions(+), 122 deletions(-) diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/00-template-vm-nano.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/00-template-vm-nano.yml index bb30be87..3abfffec 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/00-template-vm-nano.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/00-template-vm-nano.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml index b9ac314e..58faa350 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml index daad0b4e..0611e3ed 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml index 784ee52f..19c8250b 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml index e6ca0d8c..da48f0ca 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml index 92c98e56..b1661cc6 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml index b98ff8f7..a4bfb051 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml index 8897ca62..21c21ef7 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml index 71f53b5f..c0e74da9 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml index 6467440e..b6f784c4 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml index 3daeb807..8018e094 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml index 939ae6a0..9dc9fe3c 100644 --- a/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml +++ b/scenarios/_init_lab/01_init_proxmox/stage_01-create_templates/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml index 53c3bcd5..f35071f0 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9901 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9901 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9901 2>/dev/null | grep -q '^template:' register: tpl_9901_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml index 0a32f6e6..3fcef71d 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9211 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9211 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9211 2>/dev/null | grep -q '^template:' register: tpl_9211_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml index a460654e..6c962ee4 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9212 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9212 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9212 2>/dev/null | grep -q '^template:' register: tpl_9212_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml index fc578bb0..046a2234 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9221 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9221 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9221 2>/dev/null | grep -q '^template:' register: tpl_9221_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml index 67c632fb..7bb1ee66 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9222 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9222 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9222 2>/dev/null | grep -q '^template:' register: tpl_9222_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml index 0f768c72..25e53e40 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9224 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9224 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9224 2>/dev/null | grep -q '^template:' register: tpl_9224_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml index 5749b7be..a6f7c449 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9232 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9232 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9232 2>/dev/null | grep -q '^template:' register: tpl_9232_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml index 2bfa842f..ffceb4bc 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9234 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9234 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9234 2>/dev/null | grep -q '^template:' register: tpl_9234_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml index b29dc387..a08ac96e 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9236 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9236 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9236 2>/dev/null | grep -q '^template:' register: tpl_9236_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml index ac85fd19..630d82fd 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9244 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9244 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9244 2>/dev/null | grep -q '^template:' register: tpl_9244_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml index 92c4243a..60622fc5 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9246 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9246 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9246 2>/dev/null | grep -q '^template:' register: tpl_9246_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml index c6759293..b464a6ab 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9248 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9248 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9248 2>/dev/null | grep -q '^template:' register: tpl_9248_is_template failed_when: false diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml index 72315b8d..93740863 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml @@ -12,7 +12,7 @@ ## Idempotent — re-running is safe. ## -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml index 5d6b6446..47842f6d 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml @@ -11,10 +11,10 @@ ## 6. converts each VM to a template (qm template ) ## ## Reads VM IDs from the scenario manifest (manifest/scenario_vms.json). -## Runs entirely on `proxmox-cli` (= the Proxmox host itself), no SSH involved. +## Runs entirely on `proxmox_cli` (= the Proxmox host itself), no SSH involved. ## -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml index 6e497a34..74956397 100644 --- a/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml +++ b/scenarios/blank_scenario_2_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_2_subnets/templates/ansible-inventory.j2 b/scenarios/blank_scenario_2_subnets/templates/ansible-inventory.j2 index 8c5e8071..106804f5 100644 --- a/scenarios/blank_scenario_2_subnets/templates/ansible-inventory.j2 +++ b/scenarios/blank_scenario_2_subnets/templates/ansible-inventory.j2 @@ -33,6 +33,6 @@ all: ansible_connection: local ansible_python_interpreter: /usr/bin/python3 - proxmox-cli: + proxmox_cli: hosts: {{ INFRASTRUCTURE_CODENAME }}-cli: diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml index 53c3bcd5..f35071f0 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9901 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9901 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9901 2>/dev/null | grep -q '^template:' register: tpl_9901_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml index 0a32f6e6..3fcef71d 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9211 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9211 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9211 2>/dev/null | grep -q '^template:' register: tpl_9211_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml index a460654e..6c962ee4 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9212 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9212 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9212 2>/dev/null | grep -q '^template:' register: tpl_9212_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml index fc578bb0..046a2234 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9221 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9221 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9221 2>/dev/null | grep -q '^template:' register: tpl_9221_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml index 67c632fb..7bb1ee66 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9222 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9222 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9222 2>/dev/null | grep -q '^template:' register: tpl_9222_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml index 0f768c72..25e53e40 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9224 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9224 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9224 2>/dev/null | grep -q '^template:' register: tpl_9224_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml index 5749b7be..a6f7c449 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9232 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9232 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9232 2>/dev/null | grep -q '^template:' register: tpl_9232_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml index 2bfa842f..ffceb4bc 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9234 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9234 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9234 2>/dev/null | grep -q '^template:' register: tpl_9234_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml index b29dc387..a08ac96e 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9236 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9236 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9236 2>/dev/null | grep -q '^template:' register: tpl_9236_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml index ac85fd19..630d82fd 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9244 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9244 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9244 2>/dev/null | grep -q '^template:' register: tpl_9244_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml index 92c4243a..60622fc5 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9246 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9246 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9246 2>/dev/null | grep -q '^template:' register: tpl_9246_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml index c6759293..b464a6ab 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9248 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9248 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9248 2>/dev/null | grep -q '^template:' register: tpl_9248_is_template failed_when: false diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml index 72315b8d..93740863 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml @@ -12,7 +12,7 @@ ## Idempotent — re-running is safe. ## -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml index 5d6b6446..47842f6d 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml @@ -11,10 +11,10 @@ ## 6. converts each VM to a template (qm template ) ## ## Reads VM IDs from the scenario manifest (manifest/scenario_vms.json). -## Runs entirely on `proxmox-cli` (= the Proxmox host itself), no SSH involved. +## Runs entirely on `proxmox_cli` (= the Proxmox host itself), no SSH involved. ## -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml index 6e497a34..74956397 100644 --- a/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml +++ b/scenarios/blank_scenario_4_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_4_subnets/templates/ansible-inventory.j2 b/scenarios/blank_scenario_4_subnets/templates/ansible-inventory.j2 index 2f202120..1926d49a 100644 --- a/scenarios/blank_scenario_4_subnets/templates/ansible-inventory.j2 +++ b/scenarios/blank_scenario_4_subnets/templates/ansible-inventory.j2 @@ -45,6 +45,6 @@ all: ansible_connection: local ansible_python_interpreter: /usr/bin/python3 - proxmox-cli: + proxmox_cli: hosts: {{ INFRASTRUCTURE_CODENAME }}-cli: diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml index 53c3bcd5..f35071f0 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9901 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9901 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9901 2>/dev/null | grep -q '^template:' register: tpl_9901_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml index 0a32f6e6..3fcef71d 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9211 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9211 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9211 2>/dev/null | grep -q '^template:' register: tpl_9211_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml index a460654e..6c962ee4 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9212 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9212 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9212 2>/dev/null | grep -q '^template:' register: tpl_9212_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml index fc578bb0..046a2234 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9221 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9221 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9221 2>/dev/null | grep -q '^template:' register: tpl_9221_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml index 67c632fb..7bb1ee66 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9222 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9222 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9222 2>/dev/null | grep -q '^template:' register: tpl_9222_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml index 0f768c72..25e53e40 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9224 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9224 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9224 2>/dev/null | grep -q '^template:' register: tpl_9224_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml index 5749b7be..a6f7c449 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9232 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9232 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9232 2>/dev/null | grep -q '^template:' register: tpl_9232_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml index 2bfa842f..ffceb4bc 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9234 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9234 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9234 2>/dev/null | grep -q '^template:' register: tpl_9234_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml index b29dc387..a08ac96e 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9236 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9236 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9236 2>/dev/null | grep -q '^template:' register: tpl_9236_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml index ac85fd19..630d82fd 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9244 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9244 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9244 2>/dev/null | grep -q '^template:' register: tpl_9244_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml index 92c4243a..60622fc5 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9246 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9246 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9246 2>/dev/null | grep -q '^template:' register: tpl_9246_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml index c6759293..b464a6ab 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml @@ -86,13 +86,13 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" tasks: - - name: TEMPLATE 9248 - CHECK if already template (proxmox-cli play) + - name: TEMPLATE 9248 - CHECK if already template (proxmox_cli play) ansible.builtin.shell: qm config 9248 2>/dev/null | grep -q '^template:' register: tpl_9248_is_template failed_when: false diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml index 72315b8d..93740863 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_apply_apt_proxy.yml @@ -12,7 +12,7 @@ ## Idempotent — re-running is safe. ## -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml index 5d6b6446..47842f6d 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/_update_templates.yml @@ -11,10 +11,10 @@ ## 6. converts each VM to a template (qm template ) ## ## Reads VM IDs from the scenario manifest (manifest/scenario_vms.json). -## Runs entirely on `proxmox-cli` (= the Proxmox host itself), no SSH involved. +## Runs entirely on `proxmox_cli` (= the Proxmox host itself), no SSH involved. ## -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml index 6e497a34..74956397 100644 --- a/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml +++ b/scenarios/blank_scenario_6_subnets/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/blank_scenario_6_subnets/templates/ansible-inventory.j2 b/scenarios/blank_scenario_6_subnets/templates/ansible-inventory.j2 index 776faf97..15a9e60d 100644 --- a/scenarios/blank_scenario_6_subnets/templates/ansible-inventory.j2 +++ b/scenarios/blank_scenario_6_subnets/templates/ansible-inventory.j2 @@ -52,6 +52,6 @@ all: ansible_connection: local ansible_python_interpreter: /usr/bin/python3 - proxmox-cli: + proxmox_cli: hosts: {{ INFRASTRUCTURE_CODENAME }}-cli: diff --git a/scenarios/debug_scenario_a/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml b/scenarios/debug_scenario_a/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml index 07c5720d..f43b8e3f 100644 --- a/scenarios/debug_scenario_a/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml +++ b/scenarios/debug_scenario_a/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml @@ -44,7 +44,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/debug_scenario_a/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml b/scenarios/debug_scenario_a/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml index b07590f2..59681220 100644 --- a/scenarios/debug_scenario_a/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml +++ b/scenarios/debug_scenario_a/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml @@ -44,7 +44,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/debug_scenario_a/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml b/scenarios/debug_scenario_a/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml index 12b7f13b..a6b2edde 100644 --- a/scenarios/debug_scenario_a/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml +++ b/scenarios/debug_scenario_a/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml @@ -44,7 +44,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/debug_scenario_a/templates/ansible-inventory.j2 b/scenarios/debug_scenario_a/templates/ansible-inventory.j2 index 2665de9f..be56eaa3 100644 --- a/scenarios/debug_scenario_a/templates/ansible-inventory.j2 +++ b/scenarios/debug_scenario_a/templates/ansible-inventory.j2 @@ -17,6 +17,6 @@ all: ansible_connection: local ansible_python_interpreter: /usr/bin/python3 - proxmox-cli: + proxmox_cli: hosts: {{ INFRASTRUCTURE_CODENAME }}-cli: diff --git a/scenarios/debug_scenario_b/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml b/scenarios/debug_scenario_b/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml index 07c5720d..f43b8e3f 100644 --- a/scenarios/debug_scenario_b/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml +++ b/scenarios/debug_scenario_b/01_init_proxmox/templates/alpine/00-template-vm-alpine-nano.yml @@ -44,7 +44,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/debug_scenario_b/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml b/scenarios/debug_scenario_b/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml index b07590f2..59681220 100644 --- a/scenarios/debug_scenario_b/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml +++ b/scenarios/debug_scenario_b/01_init_proxmox/templates/debian/00-template-vm-debian-nano.yml @@ -44,7 +44,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/debug_scenario_b/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml b/scenarios/debug_scenario_b/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml index 12b7f13b..a6b2edde 100644 --- a/scenarios/debug_scenario_b/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml +++ b/scenarios/debug_scenario_b/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml @@ -44,7 +44,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/debug_scenario_b/templates/ansible-inventory.j2 b/scenarios/debug_scenario_b/templates/ansible-inventory.j2 index 78418d05..2e5039ca 100644 --- a/scenarios/debug_scenario_b/templates/ansible-inventory.j2 +++ b/scenarios/debug_scenario_b/templates/ansible-inventory.j2 @@ -17,6 +17,6 @@ all: ansible_connection: local ansible_python_interpreter: /usr/bin/python3 - proxmox-cli: + proxmox_cli: hosts: {{ INFRASTRUCTURE_CODENAME }}-cli: diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml index ba639a16..17d60402 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/00-template-vm-nano.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml index 4b2d5fbf..c18c5266 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-01-2g-24g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml index 36c5a11a..297db933 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/01-template-vm-micro-02-2g-24g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml index 860b9cef..6a32c72a 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml index 1cbd6d42..bd2e3b67 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-02-4g-32g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml index 875f8d91..6451b800 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-04-4g-32g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml index e5e3be41..4897f948 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-02-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml index dca6d00a..815fcda4 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-04-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml index fb792d66..eb42f32a 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/03-template-vm-medium-06-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml index 3e0928cd..d0c1e6c9 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-04-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml index 0424c00e..4978e397 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-06-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml index 4e2bdd23..27914033 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/04-template-vm-large-08-8g-64g.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml index 6e497a34..74956397 100644 --- a/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml +++ b/scenarios/demo_lab/01_init_proxmox/templates/ubuntu_noble/test_setup_templates.yml @@ -46,7 +46,7 @@ #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### -- hosts: proxmox-cli +- hosts: proxmox_cli gather_facts: false vars_files: - "../../../secrets/default_vault.yml" diff --git a/scenarios/demo_lab/templates/ansible-inventory.j2 b/scenarios/demo_lab/templates/ansible-inventory.j2 index 1b2738ab..f5fa0b17 100644 --- a/scenarios/demo_lab/templates/ansible-inventory.j2 +++ b/scenarios/demo_lab/templates/ansible-inventory.j2 @@ -57,6 +57,6 @@ all: ansible_connection: local ansible_python_interpreter: /usr/bin/python3 - proxmox-cli: + proxmox_cli: hosts: {{ INFRASTRUCTURE_CODENAME }}-cli: diff --git a/scenarios/demo_lab/templates/ssh-config.j2 b/scenarios/demo_lab/templates/ssh-config.j2 index 36c5f661..38d63376 100644 --- a/scenarios/demo_lab/templates/ssh-config.j2 +++ b/scenarios/demo_lab/templates/ssh-config.j2 @@ -21,7 +21,7 @@ Host px.{{ INFRASTRUCTURE_CODENAME }}.redirect_www.proxmox #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### # root SSH access to Proxmox — for disk extend, pveum, etc. -# alias: CODENAME-cli matches the inventory group proxmox-cli +# alias: CODENAME-cli matches the inventory group proxmox_cli Host px.{{ INFRASTRUCTURE_CODENAME }}-ssh_cli.root {{ INFRASTRUCTURE_CODENAME }}-cli Hostname {{ INFRASTRUCTURE_PROXMOX_ADDRESS | mandatory }} User root From d797ca4dc5b9b6ffbe2a194e026fe1aa37a11449 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Wed, 27 May 2026 20:19:33 +0200 Subject: [PATCH 03/13] feat(scenarios): add catalog_try scenario for single-element catalog validation (#64) --- .../_main_download_cloudinit_files.yml | 35 +++++ .../02-template-vm-small-01-4g-32g.yml | 99 +++++++++++++++ .../ubuntu_noble/_main_ubuntu_noble.yml | 6 + .../stage_00/catalog_try_vm.yml | 120 ++++++++++++++++++ .../stage_01/_r42_catalog_try_group.yml | 68 ++++++++++ scenarios/catalog_try/README.md | 45 +++++++ .../catalog_try/catalog_try.delete_all.sh | 13 ++ .../catalog_try.delete_vms_only.sh | 47 +++++++ .../catalog_try/catalog_try.reset.setup.sh | 41 ++++++ scenarios/catalog_try/catalog_try.setup.sh | 13 ++ .../catalog_try/catalog_try.setup_vms_only.sh | 14 ++ scenarios/catalog_try/main.yml | 68 ++++++++++ scenarios/catalog_try/main_vms_only.yml | 57 +++++++++ .../catalog_try/manifest/scenario_vms.json | 11 ++ .../templates/ansible-inventory.j2 | 22 ++++ .../catalog_try/templates/ansible-vars.yml | 33 +++++ scenarios/catalog_try/templates/ssh-config.j2 | 52 ++++++++ .../catalog_try/templates/vault-example.yml | 45 +++++++ 18 files changed, 789 insertions(+) create mode 100644 scenarios/catalog_try/01_init_proxmox/templates/_main_download_cloudinit_files.yml create mode 100644 scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml create mode 100644 scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/_main_ubuntu_noble.yml create mode 100644 scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml create mode 100644 scenarios/catalog_try/02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml create mode 100644 scenarios/catalog_try/README.md create mode 100755 scenarios/catalog_try/catalog_try.delete_all.sh create mode 100755 scenarios/catalog_try/catalog_try.delete_vms_only.sh create mode 100755 scenarios/catalog_try/catalog_try.reset.setup.sh create mode 100755 scenarios/catalog_try/catalog_try.setup.sh create mode 100755 scenarios/catalog_try/catalog_try.setup_vms_only.sh create mode 100644 scenarios/catalog_try/main.yml create mode 100644 scenarios/catalog_try/main_vms_only.yml create mode 100644 scenarios/catalog_try/manifest/scenario_vms.json create mode 100644 scenarios/catalog_try/templates/ansible-inventory.j2 create mode 100644 scenarios/catalog_try/templates/ansible-vars.yml create mode 100644 scenarios/catalog_try/templates/ssh-config.j2 create mode 100644 scenarios/catalog_try/templates/vault-example.yml diff --git a/scenarios/catalog_try/01_init_proxmox/templates/_main_download_cloudinit_files.yml b/scenarios/catalog_try/01_init_proxmox/templates/_main_download_cloudinit_files.yml new file mode 100644 index 00000000..475cbc69 --- /dev/null +++ b/scenarios/catalog_try/01_init_proxmox/templates/_main_download_cloudinit_files.yml @@ -0,0 +1,35 @@ +## +## + + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# +# PROXMOX INIT - download cloud init files (catalog_try : ubuntu noble only) +# +# catalog_try uses only the ubuntu noble minimal cloud image (for template 9221). +# Trimmed from demo_lab's download list (which pulls all 3 OS images). +# +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- hosts: proxmox + gather_facts: false + vars_files: + - "../../secrets/default_vault.yml" + + tasks: + - name: PROXMOX INIT - DOWNLOAD - CLOUD INIT image (ubuntu noble minimal) + include_role: + name: range42-ansible_roles-proxmox_controller + + vars: + proxmox_vm_action: "storage_download_iso" + proxmox_storage: "local" + iso_file_content_type: "iso" + iso_url: "{{ item.iso_url }}" + iso_file_name: "{{ item.iso_file_name }}" + + loop: + - { + iso_url: "https://cloud-images.ubuntu.com/minimal/daily/noble/current/noble-minimal-cloudimg-amd64.img", + iso_file_name: "noble-minimal-cloudimg-amd64.img", + } diff --git a/scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml b/scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml new file mode 100644 index 00000000..9210bc55 --- /dev/null +++ b/scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/02-template-vm-small-01-4g-32g.yml @@ -0,0 +1,99 @@ +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# +# PROMOX INIT - create ubuntu noble template : +# +# vm_id : 9221 +# cpu core : 1 +# ram : 4g +# disk : 32g +# ip : 192.168.142.221 +# +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +## +## + +- hosts: proxmox + gather_facts: false + vars_files: + - "../../../secrets/default_vault.yml" + + tasks: + # + - name: PROMOX INIT - TEMPLATES - CREATE TEMPLATE - template-vm-small-01-4g-32g + include_role: + name: range42-ansible_roles-proxmox_controller + vars: + proxmox_vm_action: "vm_create" + # proxmox_node: "px-testing" + vm_id: 9221 + vm_name: "template-vm-small-01-4g-32g" + vm_cpu: "host" + vm_cores: 1 + vm_sockets: 1 + vm_memory: 4096 + vm_net_virtio_bridge: "vmbr140" + + # + - name: PROMOX INIT - TEMPLATES - CONVERT VM TO TEMPLATE - template-vm-small-01-4g-32g + include_role: + name: range42-ansible_roles-proxmox_controller + vars: + proxmox_vm_action: "template_convert_vm_to_template" + # proxmox_node: "px-testing" + proxmox_storage: "local" + vm_id: 9221 + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- hosts: proxmox_cli + gather_facts: false + vars_files: + - "../../../secrets/default_vault.yml" + + tasks: + # + - name: PROMOX INIT - TEMPLATES - IMPORT CLOUD INIT DISK - template-vm-small-01-4g-32g + include_role: + name: range42-ansible_roles-proxmox_controller + vars: + proxmox_vm_action: "template_cloudinit_import_disk" + proxmox_node: "px-testing-cli" + cloudinit_image_full_path: "/var/lib/vz/template/iso/noble-minimal-cloudimg-amd64.img" + vm_id: 9221 + vm_disk_size: "32g" + proxmox_dest_vm_storage_name: "local-lvm" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- hosts: proxmox + gather_facts: false + vars_files: + - "../../../secrets/default_vault.yml" + + tasks: + # + - name: PROMOX INIT - TEMPLATES - SET CLOUD DEFAULT INIT VARIABLE - template-vm-small-01-4g-32g + include_role: + name: range42-ansible_roles-proxmox_controller + vars: + proxmox_vm_action: "cloudinit_set_variables" + # proxmox_node: "px-testing" + vm_id: 9221 + vm_ci_user: "{{ default_admin_vm_ci_user | default('alice') }}" + vm_ci_password: "{{ default_admin_vm_ci_password | default('supersecret') }}" + vm_ci_ssh_key: "{{ default_admin_vm_ci_ssh_key }}" + vm_ci_dns_ips: "1.1.1.1" + vm_ci_ip: "192.168.142.221" + vm_ci_netmask: "24" + vm_ci_ip_gw: "192.168.142.1" + + # + - name: PROMOX INIT - TEMPLATES - SET PROMOX TAG - template-vm-small-01-4g-32g + include_role: + name: range42-ansible_roles-proxmox_controller + vars: + proxmox_vm_action: "vm_set_tag" + # proxmox_node: "px-testing" + vm_id: 9221 + vm_tag_name: "template" diff --git a/scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/_main_ubuntu_noble.yml b/scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/_main_ubuntu_noble.yml new file mode 100644 index 00000000..3bab4771 --- /dev/null +++ b/scenarios/catalog_try/01_init_proxmox/templates/ubuntu_noble/_main_ubuntu_noble.yml @@ -0,0 +1,6 @@ +## +## catalog_try - create only template 9221 (template-vm-small-01-4g-32g). +## Trimmed from demo_lab's _main_ubuntu_noble.yml which creates 12 templates. +## + +- import_playbook: ./02-template-vm-small-01-4g-32g.yml diff --git a/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml new file mode 100644 index 00000000..7402e576 --- /dev/null +++ b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml @@ -0,0 +1,120 @@ +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# +# PROXMOX INIT INFRASTRUCTURE - CATALOG-TRY VM +# +# hostname : catalog-try-vm-docker +# vm_id : 1250 +# cpu core : 1 +# ram : 4g +# disk : 32g +# ip : 192.168.142.250 +# bridge : vmbr142 +# +# template : template-vm-small-01-4g-32g - id : 9221 (same as vuln_box) +# +# Lifted from demo_lab/04_ctf_infrastructure/stage_00/vuln_box_00.yml shape, +# with bridge/gateway adjusted for vmbr142. +# +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +## +## + +- hosts: proxmox + gather_facts: false + vars_files: + - "../../../secrets/default_vault.yml" + + vars: + # + # variables will be overwritten by values in main.yml + # + + tasks: + #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + + - name: CATALOG-TRY INFRASTRUCTURE INIT - "{{ global_vm_name }}" - CLONE TEMPLATE - "{{ global_template_name }}" + + include_role: + name: range42-ansible_roles-proxmox_controller + + vars: + proxmox_vm_action: "vm_clone" + vm_id: "{{ global_template_vm_id }}" + vm_new_id: "{{ global_vm_id }}" + vm_name: "{{ global_vm_name }}" + vm_description: "{{ global_vm_description }}" + + #### + - name: INFRASTRUCTURE INIT - WAITING FOR PROXMOX UNLOCK TO CLEAR (slow setup) + ansible.builtin.shell: qm config {{ global_vm_id }} | grep -q '^lock:' + register: clone_lock_check + until: clone_lock_check.rc != 0 + retries: 60 # 60 x 5s = 5 min max safety + delay: 5 + failed_when: false + changed_when: false + delegate_to: "{{ inventory_hostname }}-cli" + #### + + - name: CATALOG-TRY INFRASTRUCTURE INIT - "{{ global_vm_name }}" - SET PROXMOX TAG + + include_role: + name: range42-ansible_roles-proxmox_controller + + vars: + proxmox_vm_action: "vm_set_tag" + vm_id: "{{ global_vm_id }}" + vm_tag_name: "{{ global_vm_tag_name }}" + + #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + + - name: CATALOG-TRY INFRASTRUCTURE INIT - "{{ global_vm_name }}" - SET CLOUD DEFAULT INIT VARIABLE + + include_role: + name: range42-ansible_roles-proxmox_controller + + vars: + proxmox_vm_action: "cloudinit_set_variables" + + vm_id: "{{ global_vm_id }}" + vm_ci_user: "{{ default_admin_vm_ci_user | default('alice') }}" + vm_ci_password: "{{ default_admin_vm_ci_password | default('supersecret') }}" + vm_ci_ssh_key: "{{ default_admin_vm_ci_ssh_key }}" + vm_ci_dns_ips: "1.1.1.1" + vm_ci_ip: "{{ global_vm_ci_ip }}" + vm_ci_netmask: "24" + vm_ci_ip_gw: "192.168.142.1" + vm_net_virtio_bridge: "vmbr142" + + # + - name: CATALOG-TRY INFRASTRUCTURE INIT - "{{ global_vm_name }}" - CLONE TEMPLATE - START VM + + include_role: + name: range42-ansible_roles-proxmox_controller + + vars: + proxmox_vm_action: "vm_start" + vm_id: "{{ global_vm_id }}" + + # #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- hosts: "{{ global_vm_ssh_name }}" + gather_facts: false + vars_files: + - "../../../secrets/default_vault.yml" + + vars: + deployer_cli_user_ssh_known_hosts: "{{ deployer_cli_user_ssh_known_hosts }}" + ARG_vm_ssh_name: "{{ global_vm_ssh_name }}" + + requested_tasks: + - wait/openssh_server/is_reachable.yml + - wait/cloudinit/is_boot_finished.yml + + tasks: + #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + + - name: TASK DYNAMIC INCLUDE FROM ansible.utils + include_role: + name: ansible.utils diff --git a/scenarios/catalog_try/02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml new file mode 100644 index 00000000..9c7836b6 --- /dev/null +++ b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml @@ -0,0 +1,68 @@ +## +## catalog_try stage_01 - software install on the disposable VM +## +## Lifted from demo_lab/04_ctf_infrastructure/stage_01/_r42_vuln_box_group.yml shape. +## Same Docker baseline (DOCKER=YES + DOCKER_COMPOSE=YES) + zsh dotfiles + firewall. +## Targets the r42_catalog_try_group inventory group (defined in templates/ansible-inventory.j2), +## currently containing a single host : r42.catalog-try-vm-docker. +## + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- name: install basics packages + hosts: r42_catalog_try_group + become: true + roles: + - software.install.warmup.basic_packages + + # + # variables will be overwritten by values in main.yml + # + vars: + INSTALL_PACKAGES_BASICS: "YES" + INSTALL_PACKAGES_FIREWALLS: "YES" + # + INSTALL_PACKAGES_DOCKER: "YES" + INSTALL_PACKAGES_DOCKER_COMPOSE: "YES" + # + INSTALL_PACKAGES_UTILS_JSON: "NO" + INSTALL_PACKAGES_UTILS_NETWORK: "YES" + + INSTALL_PACKAGES_NTP_AND_UPDATE_TIME: "YES" + + SPECIFIC_PACKAGES_CLEANING: "NO" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- name: install dot files + hosts: r42_catalog_try_group + become: true + roles: + - software.install.warmup.dot_files + + vars: + # + # variables will be overwritten by values in main.yml + # + OPERATOR_USER: alice + INSTALL_VIM_DOTFILES: "YES" + INSTALL_ZSH_DOTFILES: "YES" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- name: configure firewall - all + become: true + hosts: r42_catalog_try_group + roles: + - software.configure.firewalls + + vars: + # + # variables will be overwritten by values in main.yml + # + firewall_rules: + - ip: "all" + port: 22 + protocol: "tcp" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### diff --git a/scenarios/catalog_try/README.md b/scenarios/catalog_try/README.md new file mode 100644 index 00000000..88d6b532 --- /dev/null +++ b/scenarios/catalog_try/README.md @@ -0,0 +1,45 @@ +# catalog_try + +Disposable single-VM scenario for fast catalog element validation. + +## Purpose + +Provides a throwaway Proxmox VM (`catalog-try-vm-docker`, VMID 1250, IP `192.168.142.250` on `vmbr142`) provisioned with the Docker baseline. The VM is the target of `range42-context catalog-try ` for iterating on individual `range42-catalog` elements without standing up a full scenario. + +The VM is overwritten on each `catalog-try` invocation : `delete-vms` + `deploy-vms` + apply the element + smoke check. + +## Structure + +This scenario mirrors the `demo_lab` pattern : + +- `01_init_proxmox/` - download Ubuntu noble cloud-init image + create template 9221 (`template-vm-small-01-4g-32g`). Idempotent : skips if already present. +- `02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml` - VM clone from template 9221 + cloud-init + start + wait-for-SSH +- `02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml` - Docker baseline + zsh dotfiles + firewall +- `manifest/scenario_vms.json` - single VM allocation (vm_id 1250, ip 192.168.142.250, bridge vmbr142) +- `templates/` - scenario-specific templates (ansible-inventory.j2, ansible-vars.yml, ssh-config.j2, vault-example.yml) + +## Self-contained + +catalog_try creates its own template (VMID 9221, ubuntu noble, 1cpu/4gb/32gb) via `01_init_proxmox/`. No dependency on another scenario's setup. If the template already exists on the Proxmox (e.g. from a prior `demo_lab.setup.sh` run, which creates the same VMID 9221), the template creation tasks are skipped idempotently. + +## Entry points + +| script | purpose | +|---|---| +| `catalog_try.setup.sh` | full provisioning (template + VM) ; idempotent on the template stage | +| `catalog_try.setup_vms_only.sh` | skips template creation (faster on repeated runs ; assumes template present) | +| `catalog_try.delete_vms_only.sh` | destroys the disposable VM, preserves the template | +| `catalog_try.delete_all.sh` | alias of `delete_vms_only.sh` (no scenario-specific templates beyond 9221 which other scenarios may share) | +| `catalog_try.reset.setup.sh` | convenience : delete VM + redeploy in one shot | + +## Usage + +The scenario is invoked transparently by `range42-context catalog-try `. Direct usage : + +``` +range42-context use catalog_try +range42-context deploy # full setup : template (if missing) + VM +range42-context deploy-vms # VM only (template assumed present) +range42-context catalog-try docker/_ctf/hello # deploys + smoke-tests a catalog element +range42-context delete-vms # destroys the VM +``` diff --git a/scenarios/catalog_try/catalog_try.delete_all.sh b/scenarios/catalog_try/catalog_try.delete_all.sh new file mode 100755 index 00000000..136681d0 --- /dev/null +++ b/scenarios/catalog_try/catalog_try.delete_all.sh @@ -0,0 +1,13 @@ +#!/bin/bash + +## +## catalog_try.delete_all.sh +## +## catalog_try has no scenario-specific templates (it reuses the template from +## another scenario's setup, e.g. demo_lab). So delete_all is functionally +## equivalent to delete_vms_only here. Kept as an alias for interface +## compatibility with range42-context delete-everything. +## + +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" +exec "$SCRIPT_DIR/catalog_try.delete_vms_only.sh" "$@" diff --git a/scenarios/catalog_try/catalog_try.delete_vms_only.sh b/scenarios/catalog_try/catalog_try.delete_vms_only.sh new file mode 100755 index 00000000..31f73e1a --- /dev/null +++ b/scenarios/catalog_try/catalog_try.delete_vms_only.sh @@ -0,0 +1,47 @@ +#!/bin/bash + +## +## delete VMs only - catalog_try VM (single VM, filter by vm_id), keep templates +## +## VM IDs are read from the scenario manifest: +## manifest/scenario_vms.json +## +## Lifted from demo_lab.delete_vms_only.sh, scoped to the catalog_try manifest +## (which currently lists only catalog-try-vm-docker, VMID 1250, IP 192.168.142.250). +## + +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" +MANIFEST="$SCRIPT_DIR/manifest/scenario_vms.json" + +if [[ ! -f "$MANIFEST" ]]; then + echo "ERROR: manifest not found: $MANIFEST" >&2 + exit 1 +fi + +# extract VM IDs + IPs from the manifest (templates kept untouched) +mapfile -t SCENARIO_VM_IDS < <(jq -r '.vms[].vm_id' "$MANIFEST") +mapfile -t INFRASTRUCTURE_IP < <(jq -r '.vms[].ip' "$MANIFEST") +ID_REGEX=$(printf '|%s' "${SCENARIO_VM_IDS[@]}" | sed 's/^|//') + +echo ":: stopping and deleting catalog_try VMs (keeping templates)..." +echo ":: catalog_try VMs: ${SCENARIO_VM_IDS[*]}" +echo "" + +VM_LIST_JSON=$(proxmox_vm.list.to.jsons.sh 2>&1 | grep '"vm_id":[0-9]') +if [ -z "$VM_LIST_JSON" ]; then + echo "ERROR: proxmox_vm.list.to.jsons.sh returned no VM data (no vm_id lines) - aborting" >&2 + printf "output: %.200s\n" "$VM_LIST_JSON" >&2 + exit 1 +fi +echo "$VM_LIST_JSON" | jq -c | grep -E "\"vm_id\":($ID_REGEX)([^0-9]|\$)" | proxmox_vm.vm_id.stop_force.to.jsons.sh +echo "$VM_LIST_JSON" | jq -c | grep -E "\"vm_id\":($ID_REGEX)([^0-9]|\$)" | proxmox_vm.vm_id.delete.to.jsons.sh + +for ip in "${INFRASTRUCTURE_IP[@]}"; do + echo ":: REMOVE SSH KEY FOR : $ip" + ssh-keygen -f "$HOME/.ssh/known_hosts" -R "$ip" +done + +echo "" +echo ":: done - templates preserved" +echo ":: redeploy with: range42-context catalog-try (or range42-context deploy-vms)" +echo "" diff --git a/scenarios/catalog_try/catalog_try.reset.setup.sh b/scenarios/catalog_try/catalog_try.reset.setup.sh new file mode 100755 index 00000000..aaa96175 --- /dev/null +++ b/scenarios/catalog_try/catalog_try.reset.setup.sh @@ -0,0 +1,41 @@ +#!/bin/bash + +## +## reset - delete this scenario's VMs (filter by vm_id from manifest) then re-deploy +## +## Convenience shortcut equivalent to : delete_vms_only.sh + setup.sh. +## Note : range42-context catalog-try does the same internally with the +## additional step of applying a catalog element on the freshly redeployed VM. +## + +SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" +MANIFEST="$SCRIPT_DIR/manifest/scenario_vms.json" + +if [[ ! -f "$MANIFEST" ]]; then + echo "ERROR: manifest not found: $MANIFEST" >&2 + exit 1 +fi + +mapfile -t SCENARIO_VM_IDS < <(jq -r '.vms[].vm_id' "$MANIFEST") +mapfile -t INFRASTRUCTURE_IP < <(jq -r '.vms[].ip' "$MANIFEST") +ID_REGEX=$(printf '|%s' "${SCENARIO_VM_IDS[@]}" | sed 's/^|//') + +echo ":: stopping and deleting scenario VMs (vm_ids: ${SCENARIO_VM_IDS[*]})..." + +VM_LIST_JSON=$(proxmox_vm.list.to.jsons.sh 2>&1 | grep '"vm_id":[0-9]') +if [ -z "$VM_LIST_JSON" ]; then + echo "ERROR: proxmox_vm.list.to.jsons.sh returned no VM data (no vm_id lines) - aborting" >&2 + printf "output: %.200s\n" "$VM_LIST_JSON" >&2 + exit 1 +fi +echo "$VM_LIST_JSON" | jq -c | grep -E "\"vm_id\":($ID_REGEX)([^0-9]|\$)" | proxmox_vm.vm_id.stop_force.to.jsons.sh +echo "$VM_LIST_JSON" | jq -c | grep -E "\"vm_id\":($ID_REGEX)([^0-9]|\$)" | proxmox_vm.vm_id.delete.to.jsons.sh + +for ip in "${INFRASTRUCTURE_IP[@]}"; do + echo ":: REMOVE SSH KEY FOR : $ip" + ssh-keygen -f "$HOME/.ssh/known_hosts" -R "$ip" +done + +ansible-playbook -i "${RANGE42_ANSIBLE_ROLES__INVENTORY_DIR}/inventory_default.yml" \ + -l "all" \ + "./main.yml" --vault-password-file "${RANGE42_VAULT_PASSWORD_FILE:?RANGE42_VAULT_PASSWORD_FILE is not set - run: range42-context use }" diff --git a/scenarios/catalog_try/catalog_try.setup.sh b/scenarios/catalog_try/catalog_try.setup.sh new file mode 100755 index 00000000..8990738d --- /dev/null +++ b/scenarios/catalog_try/catalog_try.setup.sh @@ -0,0 +1,13 @@ +#!/bin/bash + +## +## catalog_try.setup.sh - run the main playbook +## +## Same shape as demo_lab.setup.sh. catalog_try has no template stage, so this +## is functionally equivalent to catalog_try.setup_vms_only.sh ; both kept for +## interface compatibility with range42-context deploy / deploy-vms. +## + +ansible-playbook -i "${RANGE42_ANSIBLE_ROLES__INVENTORY_DIR}/inventory_default.yml" \ + -l "all" \ + "./main.yml" --vault-password-file "${RANGE42_VAULT_PASSWORD_FILE:?RANGE42_VAULT_PASSWORD_FILE is not set - run: range42-context use }" diff --git a/scenarios/catalog_try/catalog_try.setup_vms_only.sh b/scenarios/catalog_try/catalog_try.setup_vms_only.sh new file mode 100755 index 00000000..2816cd23 --- /dev/null +++ b/scenarios/catalog_try/catalog_try.setup_vms_only.sh @@ -0,0 +1,14 @@ +#!/bin/bash + +## +## catalog_try.setup_vms_only.sh - run main_vms_only playbook +## +## catalog_try has no template stage to skip (template is assumed present from +## another scenario's setup). This script is functionally equivalent to +## catalog_try.setup.sh, kept for interface compatibility with +## `range42-context deploy-vms`. +## + +ansible-playbook -i "${RANGE42_ANSIBLE_ROLES__INVENTORY_DIR}/inventory_default.yml" \ + -l "all" \ + "./main_vms_only.yml" --vault-password-file "${RANGE42_VAULT_PASSWORD_FILE:?RANGE42_VAULT_PASSWORD_FILE is not set - run: range42-context use }" diff --git a/scenarios/catalog_try/main.yml b/scenarios/catalog_try/main.yml new file mode 100644 index 00000000..9a1886b5 --- /dev/null +++ b/scenarios/catalog_try/main.yml @@ -0,0 +1,68 @@ +--- +## +## catalog_try - main playbook +## +## Provisions a single disposable VM (catalog-try-vm-docker) with the Docker baseline. +## The VM is used by `range42-context catalog-try ` to deploy individual +## range42-catalog elements for fast iteration. +## +## Mirrors the demo_lab pattern : +## 01_init_proxmox : download cloud-init image + create template 9221 (idempotent skip if already present) +## 02_catalog-try_infrastructure : VM clone + cloud-init + start + wait-for-SSH + Docker baseline +## + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +#### #### #### #### 01_init_proxmox - template creation #### #### #### #### +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- import_playbook: ./01_init_proxmox/templates/_main_download_cloudinit_files.yml +- import_playbook: ./01_init_proxmox/templates/ubuntu_noble/_main_ubuntu_noble.yml + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +#### #### #### #### 02_catalog-try_infrastructure - STAGE 00 #### #### #### +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- import_playbook: ./02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml + + vars: + global_vm_name: "catalog-try-vm-docker" + global_vm_ssh_name: "r42.catalog-try-vm-docker" + global_vm_id: 1250 + global_vm_description: "catalog-try - disposable VM for single-element validation" + global_vm_tag_name: "catalog-try" + global_vm_ci_ip: "192.168.142.250" + # + global_template_vm_id: 9221 + global_template_name: "template-vm-small-01-4g-32g - id : 9221" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +#### #### #### #### 02_catalog-try_infrastructure - STAGE 01 #### #### #### +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- import_playbook: ./02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml + + vars: + OPERATOR_USER: alice + + INSTALL_VIM_DOTFILES: "YES" + INSTALL_ZSH_DOTFILES: "YES" + + INSTALL_PACKAGES_BASICS: "YES" + INSTALL_PACKAGES_FIREWALLS: "YES" + # + INSTALL_PACKAGES_DOCKER: "YES" + INSTALL_PACKAGES_DOCKER_COMPOSE: "YES" + # + INSTALL_PACKAGES_UTILS_JSON: "NO" + INSTALL_PACKAGES_UTILS_NETWORK: "YES" + + INSTALL_PACKAGES_NTP_AND_UPDATE_TIME: "YES" + + INSTALL_TAILSCALE: "NO" + + firewall_rules: + - ip: "all" + port: 22 + protocol: "tcp" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### diff --git a/scenarios/catalog_try/main_vms_only.yml b/scenarios/catalog_try/main_vms_only.yml new file mode 100644 index 00000000..0d5ab641 --- /dev/null +++ b/scenarios/catalog_try/main_vms_only.yml @@ -0,0 +1,57 @@ +--- +## +## catalog_try - main_vms_only playbook +## +## Skips the 01_init_proxmox template creation stage (template assumed already +## present from a prior `catalog_try.setup.sh` run, idempotent). +## Used by `range42-context deploy-vms`. +## + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +#### #### #### #### 02_catalog-try_infrastructure - STAGE 00 #### #### #### +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- import_playbook: ./02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml + + vars: + global_vm_name: "catalog-try-vm-docker" + global_vm_ssh_name: "r42.catalog-try-vm-docker" + global_vm_id: 1250 + global_vm_description: "catalog-try - disposable VM for single-element validation" + global_vm_tag_name: "catalog-try" + global_vm_ci_ip: "192.168.142.250" + # + global_template_vm_id: 9221 + global_template_name: "template-vm-small-01-4g-32g - id : 9221" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +#### #### #### #### 02_catalog-try_infrastructure - STAGE 01 #### #### #### +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +- import_playbook: ./02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml + + vars: + OPERATOR_USER: alice + + INSTALL_VIM_DOTFILES: "YES" + INSTALL_ZSH_DOTFILES: "YES" + + INSTALL_PACKAGES_BASICS: "YES" + INSTALL_PACKAGES_FIREWALLS: "YES" + # + INSTALL_PACKAGES_DOCKER: "YES" + INSTALL_PACKAGES_DOCKER_COMPOSE: "YES" + # + INSTALL_PACKAGES_UTILS_JSON: "NO" + INSTALL_PACKAGES_UTILS_NETWORK: "YES" + + INSTALL_PACKAGES_NTP_AND_UPDATE_TIME: "YES" + + INSTALL_TAILSCALE: "NO" + + firewall_rules: + - ip: "all" + port: 22 + protocol: "tcp" + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### diff --git a/scenarios/catalog_try/manifest/scenario_vms.json b/scenarios/catalog_try/manifest/scenario_vms.json new file mode 100644 index 00000000..f4a9b822 --- /dev/null +++ b/scenarios/catalog_try/manifest/scenario_vms.json @@ -0,0 +1,11 @@ +{ + "scenario": "catalog_try", + "version": 1, + "description": "Disposable single-VM scenario for fast catalog element validation via `range42-context catalog-try `. The VM is overwritten on each invocation. Bridge vmbr142, IP 192.168.142.250, VMID 1250 (convention : last 3 digits of vm_id match the IP last octet). Template VMID 9221 (template-vm-small-01-4g-32g, same as vuln_box) is created by this scenario's `01_init_proxmox/` (idempotent : skipped if already present from another scenario like demo_lab).", + "vms": [ + {"vm_id": 1250, "vm_name": "catalog-try-vm-docker", "ip": "192.168.142.250", "role": "catalog-try", "bridge": "vmbr142"} + ], + "templates": [ + {"vm_id": 9221, "vm_name": "template-vm-small-01-4g-32g", "spec": "1cpu/4gb/32gb", "ip": "192.168.142.221", "bridge": "vmbr140"} + ] +} diff --git a/scenarios/catalog_try/templates/ansible-inventory.j2 b/scenarios/catalog_try/templates/ansible-inventory.j2 new file mode 100644 index 00000000..daaca472 --- /dev/null +++ b/scenarios/catalog_try/templates/ansible-inventory.j2 @@ -0,0 +1,22 @@ +all: + children: + range42_infrastructure: + children: + #### + + r42_catalog_try_group: + hosts: + r42.catalog-try-vm-docker: + + #### + + proxmox: + hosts: + {{ INFRASTRUCTURE_CODENAME }}: + ansible_host: {{ INFRASTRUCTURE_PROXMOX_ADDRESS | mandatory }}:8006 + ansible_connection: local + ansible_python_interpreter: /usr/bin/python3 + + proxmox_cli: + hosts: + {{ INFRASTRUCTURE_CODENAME }}-cli: diff --git a/scenarios/catalog_try/templates/ansible-vars.yml b/scenarios/catalog_try/templates/ansible-vars.yml new file mode 100644 index 00000000..0be97f43 --- /dev/null +++ b/scenarios/catalog_try/templates/ansible-vars.yml @@ -0,0 +1,33 @@ +--- +################################################################################ +# range42 - scenario-specific variables (catalog_try) +# +# These variables are specific to this scenario. catalog_try is a disposable +# single-VM scenario used by `range42-context catalog-try ` to validate +# individual range42-catalog elements. +# +# For shared variables -> group_vars/all/vars.yml +# For secrets -> vault.yml (see vault.yml.example) +# +################################################################################ + + +#### SCENARIO IDENTIFICATION #### + +INFRASTRUCTURE_SCENARIO: "catalog_try" + + +#### CREDENTIAL GENERATION #### + +# auto-generate ssh keys and passwords (YES/NO) +context_auto_generate_ssh_keys: "YES" +context_auto_generate_vm_passwords: "YES" + +# no student extras for catalog_try (disposable test scenario) +student_additionnal_keys_count: 0 + + +#### CLOUD-INIT USERNAMES #### + +# admin vm user (not secret - password and ssh key are in vault) +default_admin_vm_ci_user: "alice" diff --git a/scenarios/catalog_try/templates/ssh-config.j2 b/scenarios/catalog_try/templates/ssh-config.j2 new file mode 100644 index 00000000..a488c505 --- /dev/null +++ b/scenarios/catalog_try/templates/ssh-config.j2 @@ -0,0 +1,52 @@ +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# +# infrastructure code name : {{ INFRASTRUCTURE_CODENAME }} +# infrastructure proxmox address : {{ INFRASTRUCTURE_PROXMOX_ADDRESS }} +# scenario : {{ INFRASTRUCTURE_SCENARIO }} +# +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# PROXMOX WEB UI (port forward) +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +Host px.{{ INFRASTRUCTURE_CODENAME }}.redirect_www.proxmox + RequestTTY no + RemoteCommand none + localforward localhost:18042 {{ INFRASTRUCTURE_PROXMOX_ADDRESS | mandatory }}:8006 + localcommand sh -c '/usr/bin/chromium-browser --incognito --new-window --disable-translate https://127.0.0.1:18042 &' + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# PX ROOT USER SSH ACCESS +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +# root SSH access to Proxmox - for disk extend, pveum, etc. +# alias: CODENAME-cli matches the inventory group proxmox_cli +Host px.{{ INFRASTRUCTURE_CODENAME }}-ssh_cli.root {{ INFRASTRUCTURE_CODENAME }}-cli + Hostname {{ INFRASTRUCTURE_PROXMOX_ADDRESS | mandatory }} + User root + IdentityFile {{ DEPLOYER_CLI__DST_SSH_KEYS_JUMP_DEST_DIR }}/px.{{ INFRASTRUCTURE_CODENAME }}-{{ INFRASTRUCTURE_SCENARIO }}-ssh_cli.root + Port 22 + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# SSH JUMPER +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +Host px.{{ INFRASTRUCTURE_CODENAME }}.jumper + Hostname {{ INFRASTRUCTURE_PROXMOX_ADDRESS | mandatory }} + User jump_user + IdentityFile {{ DEPLOYER_CLI__DST_SSH_KEYS_JUMP_DEST_DIR }}/px.{{ INFRASTRUCTURE_CODENAME }}-{{ INFRASTRUCTURE_SCENARIO }}-ssh_cli.jump_user + Port 22 + +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### +# CATALOG-TRY VM +#### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### + +Host r42.catalog-try-vm-docker + Hostname 192.168.142.250 + +Host r42.catalog-try-* + User alice + IdentityFile {{ DEPLOYER_CLI__DST_SSH_KEYS_BACKEND_DEST_DIR }}/r42.{{ INFRASTRUCTURE_CODENAME }}-{{ INFRASTRUCTURE_SCENARIO }}-deployer-key_alice + Port 22 + ProxyJump px.{{ INFRASTRUCTURE_CODENAME }}.jumper diff --git a/scenarios/catalog_try/templates/vault-example.yml b/scenarios/catalog_try/templates/vault-example.yml new file mode 100644 index 00000000..84fe9d16 --- /dev/null +++ b/scenarios/catalog_try/templates/vault-example.yml @@ -0,0 +1,45 @@ +--- +################################################################################ +# range42 - vault secrets (catalog_try) +# +# This file contains ALL secret values for this CODENAME-SCENARIO. +# catalog_try is a disposable scenario : the vault holds stub values used to +# bring up the single test VM. Operator SSH key and password get auto-generated +# by the wizard at workspace setup ; the Proxmox secrets must be provided. +# +# Usage: +# 1. Copy this file: cp vault.yml.example vault.yml +# 2. Fill in real values +# 3. Encrypt: ansible-vault encrypt vault.yml +# 4. Never commit the unencrypted version +# +# Password format: use only a-z A-Z 0-9 - _ (20+ characters recommended) +# +################################################################################ + + +#### PROXMOX API SECRET #### + +# api token secret - generated by proxmox.api-token or imported from existing +proxmox_api_token_secret: "REPLACE_ME" + + +#### JUMP HOST #### + +# jump user password (initial password, used for user creation) +jump_password: "REPLACE_ME" + + +#### CLOUD-INIT PASSWORDS #### + +# admin vm (alice) password +default_admin_vm_ci_password: "REPLACE_ME" + +# admin vm (alice) ssh public key - populated by credentials.generate +default_admin_vm_ci_ssh_key: "ssh-ed25519 AAAA... alice CODENAME-SCENARIO" + + +#### DEPLOYER-CLI KNOWN HOSTS #### + +# operator-side known_hosts snapshot used by the wait-for-SSH task +deployer_cli_user_ssh_known_hosts: "REPLACE_ME" From 2ed2d9300b386ba86b72e28e77b68c0b9b5261b9 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Wed, 27 May 2026 21:43:14 +0200 Subject: [PATCH 04/13] fix(scenarios): correct vars_files path in catalog_try_vm.yml (#64) --- .../02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml index 7402e576..15e9c298 100644 --- a/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml +++ b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml @@ -23,7 +23,7 @@ - hosts: proxmox gather_facts: false vars_files: - - "../../../secrets/default_vault.yml" + - "../../secrets/default_vault.yml" vars: # @@ -102,7 +102,7 @@ - hosts: "{{ global_vm_ssh_name }}" gather_facts: false vars_files: - - "../../../secrets/default_vault.yml" + - "../../secrets/default_vault.yml" vars: deployer_cli_user_ssh_known_hosts: "{{ deployer_cli_user_ssh_known_hosts }}" From 5f3d783a77aa9c16c638c2829b1854e7505a24cd Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Thu, 28 May 2026 02:07:20 +0200 Subject: [PATCH 05/13] feat(catalog_try): ansible element_deploy playbook + set_fact fix (#64) --- .../stage_00/catalog_try_vm.yml | 14 +- .../catalog_try/catalog_try.element_deploy.sh | 40 ++++++ .../catalog_try.element_deploy.yml | 135 ++++++++++++++++++ 3 files changed, 188 insertions(+), 1 deletion(-) create mode 100755 scenarios/catalog_try/catalog_try.element_deploy.sh create mode 100644 scenarios/catalog_try/catalog_try.element_deploy.yml diff --git a/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml index 15e9c298..67386d04 100644 --- a/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml +++ b/scenarios/catalog_try/02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml @@ -105,13 +105,25 @@ - "../../secrets/default_vault.yml" vars: - deployer_cli_user_ssh_known_hosts: "{{ deployer_cli_user_ssh_known_hosts }}" ARG_vm_ssh_name: "{{ global_vm_ssh_name }}" requested_tasks: - wait/openssh_server/is_reachable.yml - wait/cloudinit/is_boot_finished.yml + pre_tasks: + # Pin the vault var as a concrete fact (precedence #19) BEFORE include_role. + # The previous pattern `deployer_cli_user_ssh_known_hosts: "{{ deployer_cli_user_ssh_known_hosts }}"` + # in play vars: triggered Jinja recursion when the wait-for-SSH task retried + # multiple times on slower VM boots (catalog-try uses Ubuntu noble, slower + # than debug_scenario_a's Alpine — more retries = more re-evaluations of the + # self-ref template). set_fact resolves from vars_files once, freezes the + # value as a concrete string, and survives delegation (delegate_to: localhost + # in ansible.utils' wait-for-SSH task) cleanly. + - name: pin deployer_cli_user_ssh_known_hosts into fact (avoid template recursion) + ansible.builtin.set_fact: + deployer_cli_user_ssh_known_hosts: "{{ deployer_cli_user_ssh_known_hosts }}" + tasks: #### #### #### #### #### #### #### #### #### #### #### #### #### #### #### diff --git a/scenarios/catalog_try/catalog_try.element_deploy.sh b/scenarios/catalog_try/catalog_try.element_deploy.sh new file mode 100755 index 00000000..96703e54 --- /dev/null +++ b/scenarios/catalog_try/catalog_try.element_deploy.sh @@ -0,0 +1,40 @@ +#!/bin/bash +## +## catalog_try.element_deploy.sh - copy + run + smoke check via Ansible +## +## Wrapper around catalog_try.element_deploy.yml. Invoked from _r42_catalog_try +## (range42-context.sh) after deploy-vms completes. Replaces the previous shell +## ssh / scp / docker calls with a single Ansible playbook invocation. +## +## Required env (set by `range42-context use`) : +## RANGE42_ANSIBLE_ROLES__INVENTORY_DIR +## RANGE42_VAULT_PASSWORD_FILE +## Required env (set by _r42_catalog_try before invocation) : +## CATALOG_TRY_ELEMENT_SRC - absolute path to the catalog element dir +## CATALOG_TRY_MODE - "oneshot" | "service" +## CATALOG_TRY_USE_MAKEFILE - "true" | "false" +## CATALOG_TRY_VM_IP - VM IP for HTTP smoke check +## Optional env : +## CATALOG_TRY_EXIT_SIGNATURE - oneshot mode signature to grep +## CATALOG_TRY_PORT - service mode port +## CATALOG_TRY_ENDPOINT - service mode endpoint (default "/") +## CATALOG_TRY_INIT_TIMEOUT - service mode max wait (default 60, max 600) +## + +set -e + +: "${CATALOG_TRY_ELEMENT_SRC:?must be set (absolute path to catalog element)}" +: "${CATALOG_TRY_MODE:?must be set (oneshot|service)}" +: "${CATALOG_TRY_VM_IP:?must be set (VM IP for HTTP smoke check)}" + +ansible-playbook -i "${RANGE42_ANSIBLE_ROLES__INVENTORY_DIR}/inventory_default.yml" \ + -l "r42_catalog_try_group" \ + -e "catalog_try_element_src=${CATALOG_TRY_ELEMENT_SRC}" \ + -e "catalog_try_mode=${CATALOG_TRY_MODE}" \ + -e "catalog_try_use_makefile=${CATALOG_TRY_USE_MAKEFILE:-false}" \ + -e "vm_ip=${CATALOG_TRY_VM_IP}" \ + -e "catalog_try_exit_signature=${CATALOG_TRY_EXIT_SIGNATURE:-}" \ + -e "catalog_try_port=${CATALOG_TRY_PORT:-}" \ + -e "catalog_try_endpoint=${CATALOG_TRY_ENDPOINT:-/}" \ + -e "catalog_try_init_timeout=${CATALOG_TRY_INIT_TIMEOUT:-60}" \ + "./catalog_try.element_deploy.yml" --vault-password-file "${RANGE42_VAULT_PASSWORD_FILE:?RANGE42_VAULT_PASSWORD_FILE is not set - run: range42-context use }" diff --git a/scenarios/catalog_try/catalog_try.element_deploy.yml b/scenarios/catalog_try/catalog_try.element_deploy.yml new file mode 100644 index 00000000..e52ef401 --- /dev/null +++ b/scenarios/catalog_try/catalog_try.element_deploy.yml @@ -0,0 +1,135 @@ +--- +## +## catalog_try - element deploy (copy + run + smoke check) +## +## Invoked by `range42-context catalog-try ` after the test VM is up. +## Replaces the ssh / scp / docker shell calls previously done in +## _r42_catalog_try (range42-context.sh). +## +## All docker operations use become:true (passwordless sudo on alice). The +## file copy stays as alice (no become) so the catalog files are user-owned +## and inspectable via `range42-context ssh r42.catalog-try-vm-docker`. +## +## Required extra-vars : +## catalog_try_element_src : absolute path to the catalog element dir +## catalog_try_mode : "oneshot" | "service" +## catalog_try_use_makefile : "true" | "false" +## vm_ip : VM IP (used by HTTP smoke check) +## +## Optional extra-vars : +## catalog_try_exit_signature : string (oneshot mode) +## catalog_try_port : int (service mode) +## catalog_try_endpoint : string (service mode, default "/") +## catalog_try_init_timeout : int seconds (default 60, max 600) +## + +- hosts: r42_catalog_try_group + gather_facts: false + become: false + + vars: + catalog_try_remote_dir: "/home/alice/catalog-try-element" + _ct_endpoint: "{{ catalog_try_endpoint | default('/') }}" + _ct_timeout: "{{ [(catalog_try_init_timeout | default(60) | int), 600] | min }}" + _ct_retries: "{{ ((_ct_timeout | int) / 5) | int }}" + _ct_use_make: "{{ catalog_try_use_makefile | default(false) | bool }}" + + pre_tasks: + - name: assert required vars + ansible.builtin.assert: + that: + - catalog_try_element_src is defined + - catalog_try_element_src | length > 0 + - catalog_try_mode is defined + - catalog_try_mode in ['oneshot', 'service'] + + tasks: + + # ===== COPY ===== + + - name: ensure remote element dir exists + ansible.builtin.file: + path: "{{ catalog_try_remote_dir }}" + state: directory + mode: '0755' + + - name: copy catalog element to test VM + ansible.builtin.copy: + src: "{{ catalog_try_element_src }}/" + dest: "{{ catalog_try_remote_dir }}/" + mode: preserve + + # ===== RUN ===== + + - name: run element - Makefile detected + become: true + ansible.builtin.shell: make up + args: + chdir: "{{ catalog_try_remote_dir }}" + when: _ct_use_make | bool + + - name: run element - docker compose (oneshot, foreground) + become: true + ansible.builtin.shell: docker compose up --abort-on-container-exit + args: + chdir: "{{ catalog_try_remote_dir }}" + when: + - not (_ct_use_make | bool) + - catalog_try_mode == 'oneshot' + + - name: run element - docker compose (service, detached) + become: true + ansible.builtin.shell: docker compose up -d + args: + chdir: "{{ catalog_try_remote_dir }}" + when: + - not (_ct_use_make | bool) + - catalog_try_mode == 'service' + + # ===== SMOKE CHECK ===== + + # L2 oneshot - grep exit_signature in container logs + - name: smoke check - oneshot exit_signature + become: true + ansible.builtin.shell: "docker compose logs 2>&1 | grep -F -- '{{ catalog_try_exit_signature }}'" + args: + chdir: "{{ catalog_try_remote_dir }}" + register: smoke_signature + changed_when: false + when: + - catalog_try_mode == 'oneshot' + - catalog_try_exit_signature | default('') | length > 0 + + # L2 service - poll HTTP endpoint from deployer-cli with retries + - name: smoke check - service HTTP polling + ansible.builtin.uri: + url: "http://{{ vm_ip }}:{{ catalog_try_port }}{{ _ct_endpoint }}" + status_code: 200 + timeout: 5 + register: smoke_http + retries: "{{ _ct_retries | int }}" + delay: 5 + until: smoke_http.status == 200 + delegate_to: localhost + when: + - catalog_try_mode == 'service' + - catalog_try_port | default('') | length > 0 + + # L1 fallback - docker ps shows at least one container + - name: smoke check - L1 fallback (docker ps) + become: true + ansible.builtin.shell: "docker ps --format '{{ '{{' }}.Names{{ '}}' }} {{ '{{' }}.Status{{ '}}' }}'" + register: smoke_l1 + changed_when: false + failed_when: smoke_l1.stdout | length == 0 + when: + - (catalog_try_mode == 'oneshot' and (catalog_try_exit_signature | default('') | length == 0)) or + (catalog_try_mode == 'service' and (catalog_try_port | default('') | length == 0)) + + - name: smoke L1 - display container list + ansible.builtin.debug: + msg: "{{ smoke_l1.stdout_lines }}" + when: + - smoke_l1 is defined + - smoke_l1.stdout is defined + - smoke_l1.stdout | length > 0 From 6bb21aa556f0079d92f6d0dff8fc56047c1fc21d Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Thu, 28 May 2026 09:48:34 +0200 Subject: [PATCH 06/13] fix(catalog_try): use docker ps -a for oneshot L1 smoke test (#64) --- .../catalog_try.element_deploy.yml | 36 ++++++++++++------- 1 file changed, 24 insertions(+), 12 deletions(-) diff --git a/scenarios/catalog_try/catalog_try.element_deploy.yml b/scenarios/catalog_try/catalog_try.element_deploy.yml index e52ef401..99a5f995 100644 --- a/scenarios/catalog_try/catalog_try.element_deploy.yml +++ b/scenarios/catalog_try/catalog_try.element_deploy.yml @@ -115,21 +115,33 @@ - catalog_try_mode == 'service' - catalog_try_port | default('') | length > 0 - # L1 fallback - docker ps shows at least one container - - name: smoke check - L1 fallback (docker ps) + # L1 fallback - oneshot mode (no exit_signature) : check container ran via + # `docker ps -a` (includes exited containers ; hello-world exits in <1s so + # plain `docker ps` would already be empty by smoke time). + - name: smoke check - L1 oneshot fallback (docker ps -a) + become: true + ansible.builtin.shell: "docker ps -a --format '{{ '{{' }}.Names{{ '}}' }} {{ '{{' }}.Status{{ '}}' }}'" + register: smoke_l1_oneshot + changed_when: false + failed_when: smoke_l1_oneshot.stdout | length == 0 + when: + - catalog_try_mode == 'oneshot' + - catalog_try_exit_signature | default('') | length == 0 + + # L1 fallback - service mode (no port) : check container is still running + # via `docker ps` (running only - dead service = failure). + - name: smoke check - L1 service fallback (docker ps) become: true ansible.builtin.shell: "docker ps --format '{{ '{{' }}.Names{{ '}}' }} {{ '{{' }}.Status{{ '}}' }}'" - register: smoke_l1 + register: smoke_l1_service changed_when: false - failed_when: smoke_l1.stdout | length == 0 + failed_when: smoke_l1_service.stdout | length == 0 when: - - (catalog_try_mode == 'oneshot' and (catalog_try_exit_signature | default('') | length == 0)) or - (catalog_try_mode == 'service' and (catalog_try_port | default('') | length == 0)) + - catalog_try_mode == 'service' + - catalog_try_port | default('') | length == 0 - - name: smoke L1 - display container list + - name: smoke L1 - display container list (whichever ran) ansible.builtin.debug: - msg: "{{ smoke_l1.stdout_lines }}" - when: - - smoke_l1 is defined - - smoke_l1.stdout is defined - - smoke_l1.stdout | length > 0 + msg: "{{ (smoke_l1_oneshot.stdout_lines if smoke_l1_oneshot.stdout is defined else smoke_l1_service.stdout_lines) | default([]) }}" + when: (smoke_l1_oneshot.stdout is defined and smoke_l1_oneshot.stdout | length > 0) or + (smoke_l1_service.stdout is defined and smoke_l1_service.stdout | length > 0) From 4b1b8e9938628c160b8c22f4f5ca8a8eb7b6dcfa Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Thu, 28 May 2026 10:35:46 +0200 Subject: [PATCH 07/13] fix(catalog_try): unify L1 smoke fallback to docker ps -a (default for contract-less elements) (#64) --- .../catalog_try.element_deploy.yml | 40 ++++++++----------- 1 file changed, 16 insertions(+), 24 deletions(-) diff --git a/scenarios/catalog_try/catalog_try.element_deploy.yml b/scenarios/catalog_try/catalog_try.element_deploy.yml index 99a5f995..e2ac1f72 100644 --- a/scenarios/catalog_try/catalog_try.element_deploy.yml +++ b/scenarios/catalog_try/catalog_try.element_deploy.yml @@ -115,33 +115,25 @@ - catalog_try_mode == 'service' - catalog_try_port | default('') | length > 0 - # L1 fallback - oneshot mode (no exit_signature) : check container ran via - # `docker ps -a` (includes exited containers ; hello-world exits in <1s so - # plain `docker ps` would already be empty by smoke time). - - name: smoke check - L1 oneshot fallback (docker ps -a) + # L1 default fallback : runs whenever NO specific contract applies + # (no exit_signature for oneshot, no port for service). Uses `docker ps -a` + # to accept both running AND exited containers - the question L1 answers is + # "did anything happen at all ?", not "is the service still alive ?". + # If you need running-only / HTTP-200 / signature checks, declare them in + # catalog_try.yml (port for service, exit_signature for oneshot). + - name: smoke check - L1 default (docker ps -a) become: true ansible.builtin.shell: "docker ps -a --format '{{ '{{' }}.Names{{ '}}' }} {{ '{{' }}.Status{{ '}}' }}'" - register: smoke_l1_oneshot + register: smoke_l1 changed_when: false - failed_when: smoke_l1_oneshot.stdout | length == 0 + failed_when: smoke_l1.stdout | length == 0 when: - - catalog_try_mode == 'oneshot' - - catalog_try_exit_signature | default('') | length == 0 + - (catalog_try_mode == 'oneshot' and (catalog_try_exit_signature | default('') | length == 0)) or + (catalog_try_mode == 'service' and (catalog_try_port | default('') | length == 0)) - # L1 fallback - service mode (no port) : check container is still running - # via `docker ps` (running only - dead service = failure). - - name: smoke check - L1 service fallback (docker ps) - become: true - ansible.builtin.shell: "docker ps --format '{{ '{{' }}.Names{{ '}}' }} {{ '{{' }}.Status{{ '}}' }}'" - register: smoke_l1_service - changed_when: false - failed_when: smoke_l1_service.stdout | length == 0 - when: - - catalog_try_mode == 'service' - - catalog_try_port | default('') | length == 0 - - - name: smoke L1 - display container list (whichever ran) + - name: smoke L1 - display container list ansible.builtin.debug: - msg: "{{ (smoke_l1_oneshot.stdout_lines if smoke_l1_oneshot.stdout is defined else smoke_l1_service.stdout_lines) | default([]) }}" - when: (smoke_l1_oneshot.stdout is defined and smoke_l1_oneshot.stdout | length > 0) or - (smoke_l1_service.stdout is defined and smoke_l1_service.stdout | length > 0) + msg: "{{ smoke_l1.stdout_lines | default([]) }}" + when: + - smoke_l1.stdout is defined + - smoke_l1.stdout | length > 0 From cd169f97c0a006391a8a2c05378d911dddb0aa45 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Thu, 28 May 2026 10:49:18 +0200 Subject: [PATCH 08/13] chore(scenarios): regenerate _reserved.json (catalog_try entries) (#64) --- scenarios/_reserved.json | 2 ++ 1 file changed, 2 insertions(+) diff --git a/scenarios/_reserved.json b/scenarios/_reserved.json index 7c332380..cc86a5e9 100644 --- a/scenarios/_reserved.json +++ b/scenarios/_reserved.json @@ -90,6 +90,8 @@ {"vm_id":9244,"vm_name":"template-vm-large-04-8g-64g","spec":"4cpu/8gb/64gb","ip":"192.168.140.244","bridge":"vmbr140","scenario":"blank_scenario_6_subnets","role":"template"} {"vm_id":9246,"vm_name":"template-vm-large-06-8g-64g","spec":"6cpu/8gb/64gb","ip":"192.168.140.246","bridge":"vmbr140","scenario":"blank_scenario_6_subnets","role":"template"} {"vm_id":9248,"vm_name":"template-vm-large-08-8g-64g","spec":"8cpu/8gb/64gb","ip":"192.168.140.248","bridge":"vmbr140","scenario":"blank_scenario_6_subnets","role":"template"} +{"vm_id":1250,"vm_name":"catalog-try-vm-docker","ip":"192.168.142.250","role":"catalog-try","bridge":"vmbr142","scenario":"catalog_try"} +{"vm_id":9221,"vm_name":"template-vm-small-01-4g-32g","spec":"1cpu/4gb/32gb","ip":"192.168.142.221","bridge":"vmbr140","scenario":"catalog_try","role":"template"} {"vm_id":8001,"vm_name":"dsa-vm-01","ip":"192.168.147.250","role":"debug","bridge":"vmbr147","scenario":"debug_scenario_a"} {"vm_id":9903,"vm_name":"template-vm-alpine-nano","spec":"1cpu/512mb/4gb","ip":"192.168.142.203","bridge":"vmbr140","scenario":"debug_scenario_a","role":"template"} {"vm_id":8501,"vm_name":"dsb-vm-01","ip":"192.168.148.250","role":"debug","bridge":"vmbr148","scenario":"debug_scenario_b"} From 3b503e3d127f4d89dcd7f473df599142abfb7930 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Thu, 28 May 2026 16:48:13 +0200 Subject: [PATCH 09/13] docs(catalog_try): expand README (single-use + concurrency + scope + vulnerability-lookup motivation + vmbr142 allocation + element_deploy) (#64) --- scenarios/catalog_try/README.md | 97 ++++++++++++++++++++++++++------- 1 file changed, 77 insertions(+), 20 deletions(-) diff --git a/scenarios/catalog_try/README.md b/scenarios/catalog_try/README.md index 88d6b532..1f86d55a 100644 --- a/scenarios/catalog_try/README.md +++ b/scenarios/catalog_try/README.md @@ -1,45 +1,102 @@ # catalog_try -Disposable single-VM scenario for fast catalog element validation. +One usage single-VM scenario for fast catalog element validation. -## Purpose +Provides a quick way to spin up a Proxmox VM (`catalog-try-vm-docker`, VMID 1250, IP `192.168.142.250` on `vmbr142`) provisioned with the Docker baseline. The VM is the target of `range42-context catalog-try ` for iterating on individual `range42-catalog` elements without standing up a full scenario. -Provides a throwaway Proxmox VM (`catalog-try-vm-docker`, VMID 1250, IP `192.168.142.250` on `vmbr142`) provisioned with the Docker baseline. The VM is the target of `range42-context catalog-try ` for iterating on individual `range42-catalog` elements without standing up a full scenario. +The VM is **overwritten on each `catalog-try` invocation** : `delete-vms` + `deploy-vms` + apply the element + smoke check. -The VM is overwritten on each `catalog-try` invocation : `delete-vms` + `deploy-vms` + apply the element + smoke check. +> **This is not a regular scenario.** Unlike `demo_lab`, `debug_scenario_a`, `blank_scenario_*` etc., `catalog_try` is **a single-use validation playground**, not a deployment target. It exists only to provide a disposable VM for the `range42-context catalog-try ` switch. Nothing persists between runs. + +> **Concurrency constraint** : **only one `catalog-try` invocation at a time per deployer-cli**. The VM (VMID 1250 / IP `192.168.142.250`) is fixed — two concurrent `range42-context catalog-try ...` calls from the same deployer-cli would clash on the same VM (the second one destroys the first one's VM mid-run). Run them sequentially. + +> **Scope (current)** : Docker elements only — paths under `range42-catalog/03_container_layer/docker/`. The test VM is hostnamed `catalog-try-vm-docker` to signal this. Support for `02_ansible_layer/` and `lxc/` elements may come later (tracked in the catalog-try work plan). + + + +## Usage + +Once the workspace is configured (Proxmox connection set via `range42-context init`), the scenario is invoked transparently by the `catalog-try` switch. + +**1. First, activate the `catalog_try` workspace (once per shell session)** : + +``` +range42-context use catalog_try +``` + +**2. Then spin up a one usage lab on demand** : + +``` +range42-context catalog-try docker/_ctf/hello +range42-context catalog-try docker/_ctf/cve/blank_template +``` + +The standard scenario operations stay available if you need them directly : + +``` +range42-context deploy # full setup : template (if missing) + VM +range42-context deploy-vms # VM only (template assumed present) +range42-context delete-vms # destroys the VM, keeps the template +range42-context delete # same as delete-vms here (the template 9221 is shared with demo_lab, never owned by catalog_try) +``` + + +## Vulnerability-Lookup integration (motivation) + +The broader idea behind `catalog-try` is to offer a way to **spin up a one usage vulnerable lab VM** that can be **linked directly from a Vulnerability-Lookup CVE insight** (a "sighting"), so an analyst can move from reading a CVE to running a reproduction VM in seconds. + +Concrete pattern : + +- A CVE page on Vulnerability-Lookup (e.g. [CVE-2018-15473](https://vulnerability.circl.lu/vuln/CVE-2018-15473#sightings), [CVE-2022-0778](https://vulnerability.circl.lu/vuln/CVE-2022-0778#sightings)) references a `range42-catalog` element that holds a reproducible vulnerable setup. +- The operator runs `range42-context catalog-try ` and gets a fresh VM with that element deployed, ready for testing or analysis. +- The VM is overwritten on the next invocation, so each CVE is investigated in isolation, with no cross-contamination. + +In short : **read the vuln → click the lab link → reproduce → analyze**. `catalog_try` is the throwaway VM substrate that makes this loop fast. ## Structure This scenario mirrors the `demo_lab` pattern : -- `01_init_proxmox/` - download Ubuntu noble cloud-init image + create template 9221 (`template-vm-small-01-4g-32g`). Idempotent : skips if already present. -- `02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml` - VM clone from template 9221 + cloud-init + start + wait-for-SSH -- `02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml` - Docker baseline + zsh dotfiles + firewall -- `manifest/scenario_vms.json` - single VM allocation (vm_id 1250, ip 192.168.142.250, bridge vmbr142) -- `templates/` - scenario-specific templates (ansible-inventory.j2, ansible-vars.yml, ssh-config.j2, vault-example.yml) +- `01_init_proxmox/` — download Ubuntu noble cloud-init image + create template 9221 (`template-vm-small-01-4g-32g`). Idempotent : skips if already present. +- `02_catalog-try_infrastructure/stage_00/catalog_try_vm.yml` — VM clone from template 9221 + cloud-init + start + wait-for-SSH +- `02_catalog-try_infrastructure/stage_01/_r42_catalog_try_group.yml` — Docker baseline + zsh dotfiles + firewall +- `manifest/scenario_vms.json` — single VM allocation (vm_id 1250, ip 192.168.142.250, bridge vmbr142) +- `templates/` — scenario-specific templates (ansible-inventory.j2, ansible-vars.yml, ssh-config.j2, vault-example.yml) + ## Self-contained -catalog_try creates its own template (VMID 9221, ubuntu noble, 1cpu/4gb/32gb) via `01_init_proxmox/`. No dependency on another scenario's setup. If the template already exists on the Proxmox (e.g. from a prior `demo_lab.setup.sh` run, which creates the same VMID 9221), the template creation tasks are skipped idempotently. +`catalog_try` creates its own template (VMID 9221, ubuntu noble, 1cpu/4gb/32gb) via `01_init_proxmox/`. No dependency on another scenario's setup. If the template already exists on the Proxmox (e.g. from a prior `demo_lab.setup.sh` run, which creates the same VMID 9221), the template creation tasks are skipped idempotently. + ## Entry points +### Standard scenario scripts (same shape as other range42 scenarios) + | script | purpose | |---|---| | `catalog_try.setup.sh` | full provisioning (template + VM) ; idempotent on the template stage | | `catalog_try.setup_vms_only.sh` | skips template creation (faster on repeated runs ; assumes template present) | | `catalog_try.delete_vms_only.sh` | destroys the disposable VM, preserves the template | -| `catalog_try.delete_all.sh` | alias of `delete_vms_only.sh` (no scenario-specific templates beyond 9221 which other scenarios may share) | +| `catalog_try.delete_all.sh` | alias of `delete_vms_only.sh` (no scenario-specific templates beyond 9221, which is shared with `demo_lab`) | | `catalog_try.reset.setup.sh` | convenience : delete VM + redeploy in one shot | -## Usage +### Specific to catalog_try (no equivalent in other scenarios) -The scenario is invoked transparently by `range42-context catalog-try `. Direct usage : +| script / playbook | purpose | +|---|---| +| `catalog_try.element_deploy.yml` | Ansible playbook : copies a single catalog element to the test VM (`ansible.builtin.copy`, SFTP), runs it (`docker compose up` / `make up`), and smoke-checks per the element's `catalog_try.yml` contract (L2 oneshot grep / L2 service HTTP poll / L1 fallback) | +| `catalog_try.element_deploy.sh` | thin wrapper around the playbook ; invoked internally by `range42-context catalog-try` — translates env vars (mode, port, signature, etc.) into ansible `-e` extra-vars | -``` -range42-context use catalog_try -range42-context deploy # full setup : template (if missing) + VM -range42-context deploy-vms # VM only (template assumed present) -range42-context catalog-try docker/_ctf/hello # deploys + smoke-tests a catalog element -range42-context delete-vms # destroys the VM -``` + +## IP / VMID allocation on `vmbr142` + +This scenario shares the `vmbr142` bridge with `demo_lab`'s admin VMs (NAT egress to the internet for `apt` and `docker pull`). VMID and IP last octet are kept in sync per the project convention (last 3 digits of VMID = IP last octet). + +Reserved by this scenario : + +| VMID | IP | Owner | Notes | +|------|----|-------|-------| +| **1250** | **192.168.142.250** | **catalog_try** | **catalog-try-vm-docker (overwritten on each run)** | + +Free range on `vmbr142` for future scenarios : `.104` to `.249` and `.251` to `.254` (the `.100`–`.103` slot is currently held by `demo_lab` admin VMs). From d8ebe7ca393f0348b286e99afd48f1c4a9e676bf Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Sat, 30 May 2026 15:34:38 +0200 Subject: [PATCH 10/13] fix(catalog_try): seed .env from .env.example on the test VM before docker-compose up (#65) --- .../catalog_try.element_deploy.yml | 31 +++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/scenarios/catalog_try/catalog_try.element_deploy.yml b/scenarios/catalog_try/catalog_try.element_deploy.yml index e2ac1f72..6b409ef4 100644 --- a/scenarios/catalog_try/catalog_try.element_deploy.yml +++ b/scenarios/catalog_try/catalog_try.element_deploy.yml @@ -59,6 +59,37 @@ dest: "{{ catalog_try_remote_dir }}/" mode: preserve + # ===== ENV SEED ===== + # If the element ships a `.env.example` (standard Docker pattern, used by + # docker-compose `${VAR:?...}` or `${VAR:-...}` interpolation) and no `.env` + # is already present, seed `.env` from `.env.example`. Compose then picks + # up the operator-intended defaults without the operator having to + # `cp .env.example .env` by hand on the catalog-try VM. + # + # `.env` always wins over `.env.example` : if the contributor shipped a + # real `.env` (rare), the copy step above already placed it on the VM + # and this seed task skips. + + - name: detect .env.example on remote + ansible.builtin.stat: + path: "{{ catalog_try_remote_dir }}/.env.example" + register: _ct_env_example + + - name: detect existing .env on remote + ansible.builtin.stat: + path: "{{ catalog_try_remote_dir }}/.env" + register: _ct_env_existing + + - name: seed .env from .env.example (when present and .env absent) + ansible.builtin.copy: + src: "{{ catalog_try_remote_dir }}/.env.example" + dest: "{{ catalog_try_remote_dir }}/.env" + remote_src: true + mode: '0644' + when: + - _ct_env_example.stat.exists + - not _ct_env_existing.stat.exists + # ===== RUN ===== - name: run element - Makefile detected From a5846a74472233270554c03d8e3ab524254089a6 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Sun, 31 May 2026 00:13:14 +0200 Subject: [PATCH 11/13] fix(catalog_try): [quick-fix] open service port in UFW before the L2 HTTP smoke check (#65) --- .../catalog_try/catalog_try.element_deploy.yml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/scenarios/catalog_try/catalog_try.element_deploy.yml b/scenarios/catalog_try/catalog_try.element_deploy.yml index 6b409ef4..adfb886f 100644 --- a/scenarios/catalog_try/catalog_try.element_deploy.yml +++ b/scenarios/catalog_try/catalog_try.element_deploy.yml @@ -117,6 +117,23 @@ - not (_ct_use_make | bool) - catalog_try_mode == 'service' + # ===== FIREWALL ===== + # The catalog-try VM hardening enables UFW with only port 22 open. The L2 + # service smoke check polls `http://:` from the + # deployer-cli (delegate_to: localhost), which is an EXTERNAL request to + # the VM and gets blocked by UFW. Open the element's declared port before + # the smoke check fires. Rule persists for the lifetime of the disposable + # VM (no cleanup needed - the VM is destroyed on next catalog-try run). + + - name: firewall - allow catalog_try_port through UFW (service mode) + become: true + ansible.builtin.command: "ufw allow {{ catalog_try_port }}/tcp" + register: _ct_ufw_result + changed_when: "'Rules updated' in (_ct_ufw_result.stdout | default(''))" + when: + - catalog_try_mode == 'service' + - catalog_try_port | default('') | length > 0 + # ===== SMOKE CHECK ===== # L2 oneshot - grep exit_signature in container logs From 00593d1b9ef5172821d8d8105fd4fb200f2d5363 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Wed, 3 Jun 2026 01:27:39 +0200 Subject: [PATCH 12/13] fix(catalog_try): load catalog_try.yml via include_vars + normalise catalog_try_port to list (#65) --- .../catalog_try.element_deploy.yml | 69 +++++++++++++++---- 1 file changed, 56 insertions(+), 13 deletions(-) diff --git a/scenarios/catalog_try/catalog_try.element_deploy.yml b/scenarios/catalog_try/catalog_try.element_deploy.yml index adfb886f..c4a6ffc3 100644 --- a/scenarios/catalog_try/catalog_try.element_deploy.yml +++ b/scenarios/catalog_try/catalog_try.element_deploy.yml @@ -43,6 +43,31 @@ - catalog_try_mode is defined - catalog_try_mode in ['oneshot', 'service'] + # Load catalog_try.yml directly via Ansible's native YAML parser (handles + # int, list, nested, anything) instead of relying on the shell-side + # grep/sed parser in range42-context.sh which can only extract scalar + # inline values. Loaded into the `_ct_yml` namespace to avoid clashing + # with the extra-vars passed by the shell (those have higher precedence + # than include_vars per Ansible's variable precedence rules). + - name: load catalog_try.yml from element source (controller-side) + ansible.builtin.include_vars: + file: "{{ catalog_try_element_src }}/catalog_try.yml" + name: _ct_yml + delegate_to: localhost + when: catalog_try_element_src is defined + + # Normalise `_ct_yml.catalog_try_port` to a list. The element-side + # `catalog_try.yml` may use single int (legacy : `catalog_try_port: 3000`) + # OR list syntax (future-friendly : `catalog_try_port: [3000, 2222]`). Both + # supported transparently. `set_fact` preserves native types (the value + # stored in `_ct_ports` is an actual Python list, iterable by `loop:`). + - name: compute _ct_ports (normalised port list from catalog_try.yml) + ansible.builtin.set_fact: + _ct_ports: >- + {{ [_ct_yml.catalog_try_port] + if (_ct_yml is defined and _ct_yml.catalog_try_port is defined and _ct_yml.catalog_try_port is integer) + else (_ct_yml.catalog_try_port if (_ct_yml is defined and _ct_yml.catalog_try_port is defined) else []) }} + tasks: # ===== COPY ===== @@ -125,14 +150,15 @@ # the smoke check fires. Rule persists for the lifetime of the disposable # VM (no cleanup needed - the VM is destroyed on next catalog-try run). - - name: firewall - allow catalog_try_port through UFW (service mode) + - name: firewall - allow catalog_try ports through UFW (service mode) become: true - ansible.builtin.command: "ufw allow {{ catalog_try_port }}/tcp" + ansible.builtin.command: "ufw allow {{ item }}/tcp" register: _ct_ufw_result changed_when: "'Rules updated' in (_ct_ufw_result.stdout | default(''))" + loop: "{{ _ct_ports }}" when: - catalog_try_mode == 'service' - - catalog_try_port | default('') | length > 0 + - _ct_ports | length > 0 # ===== SMOKE CHECK ===== @@ -148,20 +174,37 @@ - catalog_try_mode == 'oneshot' - catalog_try_exit_signature | default('') | length > 0 - # L2 service - poll HTTP endpoint from deployer-cli with retries - - name: smoke check - service HTTP polling - ansible.builtin.uri: - url: "http://{{ vm_ip }}:{{ catalog_try_port }}{{ _ct_endpoint }}" - status_code: 200 - timeout: 5 - register: smoke_http + # L2 service - verify container is running AND ALL declared ports are listening. + # Replaces the previous HTTP poll which exposed catalog-try smoke to + # cross-cutting filter concerns (UFW, Host header trust, OAuth callbacks). + # The check runs locally on the catalog-try VM (no delegate_to: localhost), + # so it bypasses host-network filters entirely. + # 1. `docker ps --filter status=running` : at least one container of the + # compose stack is RUNNING (stricter than L1 `docker ps -a` which also + # counts exited containers). + # 2. For EACH port in `_ct_ports` : `ss -tplln | grep ':'` confirms + # the port is bound on the host (Docker port-mapping is live + the + # service inside the container has actually started listening). All + # ports must pass ; a single missing port fails the smoke. + # Retries until both conditions pass OR `_ct_retries` exhausted. + - name: smoke check - service container running + all declared ports listening + become: true + ansible.builtin.shell: | + set -e + docker ps --filter "status=running" --format '{{ '{{' }}.Names{{ '}}' }}' | grep -q . + {% for p in _ct_ports %} + ss -tplln | grep -qE ':{{ p }}\b' + {% endfor %} + args: + chdir: "{{ catalog_try_remote_dir }}" + register: smoke_listen + changed_when: false retries: "{{ _ct_retries | int }}" delay: 5 - until: smoke_http.status == 200 - delegate_to: localhost + until: smoke_listen.rc == 0 when: - catalog_try_mode == 'service' - - catalog_try_port | default('') | length > 0 + - _ct_ports | length > 0 # L1 default fallback : runs whenever NO specific contract applies # (no exit_signature for oneshot, no port for service). Uses `docker ps -a` From 6aa720bc101923894bf9b82395a599102d862f32 Mon Sep 17 00:00:00 2001 From: Benjamin Collas <129123125+hyde-repo@users.noreply.github.com> Date: Wed, 3 Jun 2026 01:41:32 +0200 Subject: [PATCH 13/13] docs(catalog_try): document catalog_try.yml contract + UFW/smoke semantics in scenario README (#65) --- scenarios/catalog_try/README.md | 85 ++++++++++++++++++++++++++++++++- 1 file changed, 84 insertions(+), 1 deletion(-) diff --git a/scenarios/catalog_try/README.md b/scenarios/catalog_try/README.md index 1f86d55a..59885156 100644 --- a/scenarios/catalog_try/README.md +++ b/scenarios/catalog_try/README.md @@ -85,7 +85,7 @@ This scenario mirrors the `demo_lab` pattern : | script / playbook | purpose | |---|---| -| `catalog_try.element_deploy.yml` | Ansible playbook : copies a single catalog element to the test VM (`ansible.builtin.copy`, SFTP), runs it (`docker compose up` / `make up`), and smoke-checks per the element's `catalog_try.yml` contract (L2 oneshot grep / L2 service HTTP poll / L1 fallback) | +| `catalog_try.element_deploy.yml` | Ansible playbook : copies a single catalog element to the test VM (`ansible.builtin.copy`, SFTP), seeds `.env` from `.env.example` if absent, opens declared ports through UFW (service mode), runs it (`docker compose up` / `make up`), and smoke-checks per the element's `catalog_try.yml` contract (L2 oneshot signature grep / L2 service local port-binding check / L1 fallback) — see [Element contract](#element-contract--catalog_tryyml) below | | `catalog_try.element_deploy.sh` | thin wrapper around the playbook ; invoked internally by `range42-context catalog-try` — translates env vars (mode, port, signature, etc.) into ansible `-e` extra-vars | @@ -100,3 +100,86 @@ Reserved by this scenario : | **1250** | **192.168.142.250** | **catalog_try** | **catalog-try-vm-docker (overwritten on each run)** | Free range on `vmbr142` for future scenarios : `.104` to `.249` and `.251` to `.254` (the `.100`–`.103` slot is currently held by `demo_lab` admin VMs). + + +## Element contract : `catalog_try.yml` + +Each catalog element that wants a stricter smoke check than the default L1 fallback (`docker ps -a` presence) can ship a `catalog_try.yml` file in its directory. The file is the **contract** between the element (in `range42-catalog`) and the playbook (`catalog_try.element_deploy.yml` in this repo) — a small declarative spec that tells the playbook what mode the element runs in, which ports to expect, and how long to wait. + +The playbook loads it via `ansible.builtin.include_vars` from the element source path on the controller (before the copy step), so YAML is parsed natively — single ints, lists, anything supported by Ansible's YAML loader. + +### Fields + +| Field | Type | Required | Applies to | Default | Purpose | +|---|---|---|---|---|---| +| `catalog_try_mode` | string | yes | both | — | `oneshot` (compose runs to completion) or `service` (compose stays up) | +| `catalog_try_exit_signature` | string | no | oneshot | — | String to `grep -F` in `docker compose logs` ; presence ⇒ L2 oneshot smoke pass | +| `catalog_try_port` | int **or** list[int] | no | service | — | Host port(s) the element binds. Used for UFW opens + binding smoke check (see below) | +| `catalog_try_endpoint` | string | no | service | `/` | Reserved for future HTTP-based extensions ; currently inert (the smoke check verifies port binding, not HTTP response) | +| `catalog_try_init_timeout` | int (seconds, max 600) | no | service | 60 | Upper bound on the smoke retry loop (retries = timeout / 5s delay) | + +`catalog_try_port` accepts **single int or list of ints** transparently — all three syntaxes below are valid : + +```yaml +catalog_try_port: 8080 # single port, legacy syntax +catalog_try_port: [3000, 2222] # multi-port, list (flow) syntax +catalog_try_port: # multi-port, block syntax + - 3000 + - 2222 +``` + +The playbook normalises any of these to a list internally before consuming the value, so element authors pick whichever reads best for their case. The 5 admin elements currently use block-list syntax even when a single port is declared, for API-surface consistency and future-friendliness. + +### Smoke check semantics + +The playbook picks the strictest applicable check : + +- **L2 oneshot** — `catalog_try_mode: oneshot` + `catalog_try_exit_signature` set : container runs to completion, smoke greps the exit signature in `docker compose logs`. A missing signature fails the smoke. +- **L2 service** — `catalog_try_mode: service` + `catalog_try_port` set : the playbook polls **locally on the VM** (no `delegate_to: localhost`, so cross-cutting filters like UFW, Host header trust, OAuth callbacks are out of scope) until two conditions hold simultaneously : + 1. `docker ps --filter status=running` lists at least one container of the compose stack. + 2. For **each** port in the declared list : `ss -tplln | grep ':'` confirms the port is bound on the host. A single missing port fails the smoke. + + The check retries every 5s up to `catalog_try_init_timeout / 5` times. +- **L1 fallback** — no L2 fields applicable : `docker ps -a` is enough to prove the element produced *something*. Both running and exited containers count. + +### Network behaviour (UFW) + +The catalog-try VM hardening enables UFW with **only port 22 open**. For service-mode elements with declared ports, the playbook iterates the declared list and runs `ufw allow /tcp` for each, **before** the smoke check fires. Rules persist for the lifetime of the disposable VM ; no cleanup needed since the VM is destroyed on the next `catalog-try` invocation. + +If `catalog_try_port` is not declared, no UFW rule is added (and the L2 service check is not run — the element falls back to L1). + +### Examples + +**Single-port service** (Nextcloud) : + +```yaml +catalog_try_mode: service +catalog_try_port: + - 8080 +catalog_try_endpoint: /status.php +catalog_try_init_timeout: 180 +``` + +→ UFW opens `8080/tcp` ; smoke waits for `ss -tplln` to show `:8080` bound (up to 36 retries × 5s = 180s). + +**Multi-port service** (Gitea : HTTP + SSH) : + +```yaml +catalog_try_mode: service +catalog_try_port: + - 3000 # HTTP (web UI + API) + - 2222 # SSH (git clone) +catalog_try_endpoint: /api/v1/version +catalog_try_init_timeout: 90 +``` + +→ UFW opens `3000/tcp` **and** `2222/tcp` ; smoke requires **both** ports bound on the host (single missing port fails the smoke). + +**Oneshot with exit signature** : + +```yaml +catalog_try_mode: oneshot +catalog_try_exit_signature: "All checks passed" +``` + +→ `docker compose up --abort-on-container-exit` runs the stack to completion, smoke greps the signature in logs.