chef / chef/chef-server

chef-server-ctl cleanse --with-external deletes private-chef-secrets.json before cleaning up the database, hilarity ensues

Open
#1,340 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Status: Good First Issue Triage: Confirmed Type: Bug
Dominant language
Erlang
Stars
303
Forks
211
Avg merge
1d 8h
Merged PRs (30d)
5

Description

I think we may have an order-of-operations problem here: https://github.com/chef/omnibus-ctl/blob/master/lib/omnibus-ctl.rb#L861 - the external_cleanse_X methods shouldn't fire after cleanse because the secrets files will be gone by then.

[root@ip-10-42-49-198 ~]# ls -la /etc/opscode
total 84
drwxr-xr-x  3 root    root  4096 Jul 24 21:19 .
drwxr-xr-x 80 root    root  4096 Jul 24 21:16 ..
-rw-r-----  1 root    root  1452 Jul 24 21:14 chef-server.rb
-rw-r--r--  1 root    root     0 Jul 24 21:14 chef-server.rb.bak
-rw-------  1 opscode root 22636 Jul 24 21:19 chef-server-running.json
-rw-r--r--  1 opscode root   382 Jul 24 21:16 dark_launch_features.json
-rw-r--r--  1 root    root    63 Jul 24 21:19 logrotate.conf
drwxr-xr-x  2 root    root  4096 Jul 24 21:19 logrotate.d
-rw-------  1 opscode root  1679 Jul 24 21:16 pivotal.pem
-rw-r--r--  1 root    root   636 Jul 24 21:19 pivotal.rb
-rw-------  1 root    root 13699 Jul 24 21:19 private-chef-secrets.json
-rw-r--r--  1 root    root   305 Jul 24 21:19 private-chef.sh
-rw-------  1 opscode root  1675 Jul 24 21:16 webui_priv.pem
-rw-r--r--  1 root    root   451 Jul 24 21:16 webui_pub.pem
[root@ip-10-42-49-198 ~]# chef-server-ctl cleanse --with-external
    *******************************************************************
    * * * * * * * * * * *       STOP AND READ       * * * * * * * * * *
    *******************************************************************
    This command will delete *all* local configuration, log, and
    variable data associated with Chef Server.
    This will also delete externally hosted Chef Server data.
    This means that any service you have configured as 'external'
    will have any Chef Server permanently deleted.

    You have 60 seconds to hit CTRL-C before configuration,
    logs, local, and remote data for this application are permanently
    deleted.
    *******************************************************************

ok: down: bookshelf: 0s, normally up
ok: down: nginx: 0s, normally up
ok: down: oc_bifrost: 1s, normally up
ok: down: oc_id: 0s, normally up
ok: down: opscode-chef-mover: 2563s, normally up
ok: down: opscode-erchef: 1s, normally up
ok: down: redis_lb: 0s, normally up
bookshelf disabled, not stopping
nginx disabled, not stopping
oc_bifrost disabled, not stopping
oc_id disabled, not stopping
opscode-chef-mover disabled, not stopping
opscode-erchef disabled, not stopping
redis_lb disabled, not stopping
Terminating processes running under application users. This will take a few seconds.
Your config files have been backed up to /root/opscode-cleanse-2017-07-24T21:59.
Deleting data from external service: opscode-solr4
Cleansing data in a remote Sol4 instance is not currently supported.
Deleting data from external service: postgresql
CLEANSE001: While local cleanse of Chef Server succeeded, an error
            occurred while deleting Chef Server data from the external
            PostgreSQL server at idhz110eswaam1.csenmsxeypge.us-west-2.rds.amazonaws.com.

            The error reported was:

                /etc/opscode/private-chef-secrets.json does not exist

            To complete cleanup of PostgreSQL, please log into PostgreSQL
            on idhz110eswaam1.csenmsxeypge.us-west-2.rds.amazonaws.com as superuser and execute the statements
            that have been saved to the file below:

              /root/2017-07-24T21:59-chef-server-manual-postgresql-cleanup.sql

            See https://docs.chef.io/error_messages.html#cleanse001-postgres-failed
            for more information.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in lib/omnibus-ctl.rb around line 861 and trace the order used by chef-server-ctl cleanse --with-external. Check how the external_cleanse methods access private-chef-secrets.json and how local cleansing removes it. Done means external PostgreSQL cleanup no longer fails because the secrets file was deleted first.

Written by the indexing model from the issue text.

Assessment

Tech stack
postgresql, ruby
Domain
cli, databases
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.