Re: [PATCH 1/8] terraform: Use directory checksum in SSH key filenames
"Chuck Lever" <[email protected]> Sat, 06 Dec 2025 17:28:45 -0500
| Newsgroups | dev.linux.lists.kdevops |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Dec 6, 2025, at 11:56 AM, Luis Chamberlain wrote: > SSH keys now use directory-based checksums to support multiple kdevops > installations coexisting without conflicts. The SSH key filename format > is now ~/.ssh/kdevops_terraform_<checksum> where checksum is the first > 8 characters of the SHA256 hash of the kdevops directory path. > > This was previously only applied to Lambda Labs provider but is now the > default for all providers, as it solves the general problem of multiple > installations sharing the same home directory. > Also fix OCI Kconfig generation scripts to use --quiet flag correctly > to suppress progress output when generating dynamic Kconfig files. Instead of duplicating the same logic in all the terraform scripts, can you add it just to scripts/generate_cloud_config.py ? And can this fix go in a separate commit from the ssh change above? > Generated-by: Claude AI > Signed-off-by: Luis Chamberlain <[email protected]> > --- > terraform/Kconfig.ssh | 7 +++++-- > terraform/oci/scripts/gen_kconfig_image | 6 ++++++ > terraform/oci/scripts/gen_kconfig_location | 6 ++++++ > terraform/oci/scripts/gen_kconfig_shape | 6 ++++++ > 4 files changed, 23 insertions(+), 2 deletions(-) > > diff --git a/terraform/Kconfig.ssh b/terraform/Kconfig.ssh > index 4e239a35..b03f962f 100644 > --- a/terraform/Kconfig.ssh > +++ b/terraform/Kconfig.ssh > @@ -21,14 +21,17 @@ config TERRAFORM_SSH_CONFIG_USER > > config TERRAFORM_SSH_CONFIG_PUBKEY_FILE > string "File containing Ansible's ssh public key" > - default "~/.ssh/kdevops_terraform_$(shell, echo $(TOPDIR_PATH) | > sha256sum | cut -c1-8).pub" if TERRAFORM_LAMBDALABS > - default "~/.ssh/kdevops_terraform.pub" > + default "~/.ssh/kdevops_terraform_$(shell, echo $(TOPDIR_PATH) | > sha256sum | cut -c1-8).pub" > help > The filename of the file containing an ssh public key > Ansible is to use to manage its target nodes. The > matching private key should be located in a file using > the same basename (without the ".pub"). > > + The filename includes an 8-character hash of the current > + directory path, allowing multiple kdevops installations to > + use separate SSH keys without conflicts. > + > config TERRAFORM_SSH_CONFIG_GENKEY > bool "Should we create a new random key for you?" > default y > diff --git a/terraform/oci/scripts/gen_kconfig_image > b/terraform/oci/scripts/gen_kconfig_image > index 977446fd..55dfcf6c 100755 > --- a/terraform/oci/scripts/gen_kconfig_image > +++ b/terraform/oci/scripts/gen_kconfig_image > @@ -718,6 +718,12 @@ def main(): > """Main function to run the program.""" > args = parse_arguments() > > + # Check for OCI config early - exit silently if not configured > + if not os.path.exists(os.path.expanduser("~/.oci/config")): > + if not args.quiet: > + print("OCI not configured - skipping (optional)", > file=sys.stderr) > + sys.exit(0) > + > if args.publishers: > # Show both known and discovered publishers > compartment_ocid = get_default_compartment() > diff --git a/terraform/oci/scripts/gen_kconfig_location > b/terraform/oci/scripts/gen_kconfig_location > index 17ec8266..b397f534 100755 > --- a/terraform/oci/scripts/gen_kconfig_location > +++ b/terraform/oci/scripts/gen_kconfig_location > @@ -432,6 +432,12 @@ def main(): > """Main function to run the program.""" > args = parse_arguments() > > + # Check for OCI config early - exit silently if not configured > + if not os.path.exists(os.path.expanduser("~/.oci/config")): > + if not args.quiet: > + print("OCI not configured - skipping (optional)", > file=sys.stderr) > + sys.exit(0) > + > if not args.quiet: > print("Fetching list of OCI region subscriptions...", > file=sys.stderr) > regions = get_all_regions() > diff --git a/terraform/oci/scripts/gen_kconfig_shape > b/terraform/oci/scripts/gen_kconfig_shape > index 09dd6d6f..d65ff37d 100755 > --- a/terraform/oci/scripts/gen_kconfig_shape > +++ b/terraform/oci/scripts/gen_kconfig_shape > @@ -887,6 +887,12 @@ def main(): > """Main function to run the program.""" > args = parse_arguments() > > + # Check for OCI config early - exit silently if not configured > + if not os.path.exists(os.path.expanduser("~/.oci/config")): > + if not args.quiet: > + print("OCI not configured - skipping (optional)", file=sys.stderr) > + sys.exit(0) > + > compartment_ocid = get_default_compartment() > if not compartment_ocid: > print("Error: Could not determine compartment OCID", file=sys.stderr) > -- > 2.51.0 -- Chuck Lever