Two depots ignored the change OPS-2311

Open2 versionsConfiguration management · Hard · Investigate · about 35 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Sasha Lind opened OPS-2311 at 14:10task

With the nightly playbook fixed (OPS-2302), Tuesday's run finally applied CHG-5510. depot-1 moved to 8443. depot-2 and depot-3 still render 8080, and the playbook reports nothing wrong.

"I changed it in the one place everyone changes things. Where else could it possibly be?" (Sasha)

depot-3 is the cold-storage depot and legitimately has its own certificate. Some old settings are still correct; find the one that is not.

Your task

Find where each depot gets its port, remove the stale host-level values so the group decides, keep depot-3's certificate, and run the playbook. Leave site.yml and the template alone.

On the machine

  • inventory.ini, group_vars/, host_vars/
  • ansible-inventory --host depot-2
  • docs/runbooks/ansible-vars.md

Timeline

2025depot-2 gets waybill_port=8080 on its inventory line during a migration.
Springdepot-3 gets its own certificate in host_vars, and a port copied along with it.
TueThe fixed playbook (OPS-2302) reruns CHG-5510: waybill_port 8443 in group_vars/depots.yml.
14:10Two depots still on 8080. OPS-2311.

Done when

  1. Every depot renders port 8443 after a playbook run.
  2. depot-3 keeps its own TLS certificate, and the others keep the shared one.
  3. waybill_port is set in one place: no host-level overrides remain, and the playbook and template are unchanged.

Hints

Hint 1

ansible-inventory --host depot-2 shows the variables Ansible will use for that host.

Hint 2

grep -rn waybill_port . finds every place the variable is set, including groups you did not know about.

Hint 3

Host variables beat group_vars, and between two groups at the same level, the one whose name sorts later wins.

Hint 4

Remove the port from wherever it overrides depots.yml, and keep everything else that file or line sets.

Show the solution

`ansible-inventory --host depot-2` and `grep -rn waybill_port .` show where 8080 comes from: depot-2's inventory line and `host_vars/depot-3.yml`, or `group_vars/legacy_scanners.yml` for a migration group that both depots belong to (it sorts after `depots`, so it wins). Remove the port there, and keep the rest: depot-3's `tls_cert`, the migration group's `scanner_vlan`. Run `ansible-playbook site.yml`.