cloud-bulldozer / cloud-bulldozer/scale-ci-deploy

[OCP-4.x][AWS] Playbook clobbers AWS cred file

Open
#89 0 comments 1 reaction 0 assignees View on GitHub
docs
Dominant language
Jinja
Stars
16
Forks
37
PR merge metrics
No merged PRs in 30d

Description

**Version** git hash: 23de699bb57043e6a30ebaa3b9053791f2d17a0d

**Location**
[OCP-4.X/roles/install-on-aws/templates/credentials.j2](https://github.com/openshift-scale/scale-ci-deploy/blob/23de699bb57043e6a30ebaa3b9053791f2d17a0d/OCP-4.X/roles/install-on-aws/templates/credentials.j2#L1)
[OCP-4.X/roles/install-on-aws/tasks/main.yml](https://github.com/openshift-scale/scale-ci-deploy/blob/23de699bb57043e6a30ebaa3b9053791f2d17a0d/OCP-4.X/roles/install-on-aws/tasks/main.yml#L118)

**Environment**

AWS_ACCESS_KEY_ID=1232414321234 # or unset
AWS_SECRET_ACCESS_KEY=1232412341234 # or unset

**Issue**
The playbook will clobber the $HOME/.aws/credentials variable values, _even if the env vars are set_. This behavior is undocumented. Overwriting the default credential file results in loss of those keys, forcing users to regenerate them (or having to ask an admin to do it for them).

**Behavior**
The installer will hang indefinitely at the credential check:
`time="2020-08-19T10:31:08-04:00" level=debug msg=" Generating Platform Credentials Check..."`
This is because the installer cannot find the keys and is prompting the user for them, but the prompt is hidden from the openshift logs and playbook output.

**Suggested Behavior**
The playbook should _not_ overwrite the $HOME/.aws/credentials file. The playbook should, at most, validate that either the env vars or the credential file exists, and fail if none do. This will prevent the hang and provide the user an indication of what's wrong.

**Additionally..**
This behavior also exists for the $HOME/.aws/config file, which again should not be overwritten, at least if the env vars are not set or are null.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with OCP-4.X/roles/install-on-aws/templates/credentials.j2 and OCP-4.X/roles/install-on-aws/tasks/main.yml around the referenced task. Reproduce with AWS environment variables set and unset, then inspect the credential check behavior. Done means existing $HOME/.aws/credentials and config values are preserved, and missing credentials fail clearly instead of hanging.

Written by the indexing model from the issue text.

Assessment

Tech stack
ansible, aws
Domain
cloud, devops, infrastructure
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.