mlev: hello, I found it yesterday as well, just didn't have time to read it thoroughly yet , from quick scan it seems that the vault has to be updated after new host is added (matching the search)
balexx++
mlev
mhulan:first, thanks a lot man for the effort here. You are very helpful as allways
mhulan: and secondly: yes. In first look it looks like a bit of an overhread, doesn't it?
mhulan
mlev: yes, could be... anyway it means we wouldn't need to store anything extra in foreman, except some vault information, like the search that was used and just say which valuts should be updated
rdark joined the channel
mlev: but I'll have to do some experiments, like what happens if you use different search for updating (would other nodes lose their key?)
rdark has quit
rdark joined the channel
mlev
I do not think that other nodes might be harmedmhulan:
balexx_ joined the channel
dcaro joined the channel
balexx_ has quit
mhulan
if that's true, we could just add another parameter specifying which vaults to update and search would point just to the host that's being provisioned
balexx__ joined the channel
mlev
mhulan: I think that somewhere should be run a `knife update vault <users> <user> -S "role:vault_able / name:*" so the keys will be updated and the access will be there for the new node
balexx has quit
mhulan: I think that this should be right, but as far as I understand the flow, a `knife vault update` must be initiated in between. But how shall it be done?
mhulan
agreed, but we'll need to use API instead of knife (I suppose knife uses some API internally)
mlev
mhulna: sound even more interesting
sobersabre has quit
balexx__ has quit
cliff-hm has quit
tremble joined the channel
Hypnoz has quit
pbeskow joined the channel
gildub joined the channel
vassie joined the channel
ebartz_i has left the channel
Dw_Sn joined the channel
sobersabre joined the channel
straylen joined the channel
jtomasek joined the channel
__endy__ has quit
__endy__ joined the channel
therm85 joined the channel
jtomasek has quit
jtomasek joined the channel
therm85
might there somthing be broken with validation in 1.8.2? I am getting "Validation failed: Identifier Can't add or remove `.` from identifier" when importing facts in production.log
jtomasek has quit
it only brakes with new hosts (deleted an readded)
Dominic
sounds like #11247
nudnik
Dominic: #11247 is http://theforeman.org/issues/11247 "Bug #11247: IP address is invalid, can't add or remove `.` from identifier - Foreman"