Red Hat Satellite engineering is moving the tracking of its product development work on Satellite to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "Satellite project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs will be migrated starting at the end of May. If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "Satellite project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/SAT-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 2007388 - [RFE] Full Support for Ansible Vault in Satellite
Summary: [RFE] Full Support for Ansible Vault in Satellite
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Ansible - Configuration Management
Version: 6.11.0
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: 6.14.0
Assignee: satellite6-bugs
QA Contact: Satellite QE Team
URL:
Whiteboard:
: 2000229 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-09-23 18:02 UTC by Satyajit Das
Modified: 2024-03-25 18:17 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-04-20 10:23:13 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 35171 0 High New Full Support for Ansible Vault in Satellite 2023-02-01 19:30:55 UTC
Red Hat Issue Tracker SAT-5222 0 None None None 2021-09-24 13:19:31 UTC
Red Hat Knowledge Base (Article) 4088231 0 None None None 2021-09-23 18:06:29 UTC

Description Satyajit Das 2021-09-23 18:02:00 UTC
1. Proposed title of this feature request

   Full Support for Ansible Vault in Satellite

2. What is the nature and description of the request?

   Currently, to use Ansible vault when running a Ansible role from the Satellite, we have to define 
   the  parameter (vault_password_file) in the file (/usr/share/foreman-proxy/.ansible.cfg), however 
   the changes are not persistence across satellite-installer execution.  As the satellite-installer 
   override the custom parameters with default settings. so we need an option in Satellite GUI
   under( Configure > Ansible > something like Credentials page), to add and update vault password.
   Also, add the "Vault ID:" option in the same Credentials page, so that Multi-Vault Credentials can be
   defined and utilized later during role execution.

   Next, need an option in Job template, to pass/assign the vault Credentials, so that specific Credential can 
   be assigned to the job templates directly.
    

3. Why does the customer need this? (List the business requirements here)

   It gives flexibility to the customers to utilize the product to the fullest.
 
4. How would the customer like to achieve this? (List the functional requirements here)

   Add option in Satellite GUI under( Configure > Ansible > something like Credentials page), 
   to add and update vault password. Also, add the "Vault ID:" option in the same Credentials page,
   so that Multi-Vault Credentials can be utilized during role execution.

   Next, need an option in Job template, to pass/assign the vault Credentials, so that specific 
   Credentials can be assigned to the job templates directly.


5. Is there already an existing RFE upstream or in Red Hat Bugzilla?

   Unknown

6. Does the customer have any specific timeline dependencies and which release would they like to target (i.e.satellite 7.0)?

   No

7. Is the sales team involved in this request and do they have any additional input?
   No


8. List any affected packages or components.
   Unknown

Comment 2 Ron Lavi 2022-07-06 17:16:31 UTC
Created redmine issue https://projects.theforeman.org/issues/35171 from this bug

Comment 3 Ron Lavi 2022-07-06 17:24:27 UTC
*** Bug 2000229 has been marked as a duplicate of this bug. ***

Comment 7 Ron Lavi 2023-04-20 10:23:13 UTC
After discussing it with our team, we have come to the conclusion that we will not be able to implement the RFE in the foreseeable future.

The current fix[1] we have implemented for ansible.cfg should help using Vault or additional Ansible configurations from the ansible.cfg without it being overridden by the installer.

Additionally, I want to clarify that our project is not meant to replace AAP, and if you want to utilize Vault's full capabilities, we highly recommend using AAP.

Please let me know if you have any questions or concerns.

[1] - https://bugzilla.redhat.com/show_bug.cgi?id=1786358


Note You need to log in before you can comment on or make changes to this bug.