Re: [PATCH 1/8] terraform: Use directory checksum in SSH key filenames

"Chuck Lever" <[email protected]> Fri, 12 Dec 2025 14:14:20 -0500
Newsgroups dev.linux.lists.kdevops
Message-ID <[email protected]>

On Sat, Dec 6, 2025, at 5:28 PM, Chuck Lever wrote:
> On Sat, Dec 6, 2025, at 11:56 AM, Luis Chamberlain wrote:
>> SSH keys now use directory-based checksums to support multiple kdevops
>> installations coexisting without conflicts. The SSH key filename format
>> is now ~/.ssh/kdevops_terraform_<checksum> where checksum is the first
>> 8 characters of the SHA256 hash of the kdevops directory path.
>>
>> This was previously only applied to Lambda Labs provider but is now the
>> default for all providers, as it solves the general problem of multiple
>> installations sharing the same home directory.
>
>> Also fix OCI Kconfig generation scripts to use --quiet flag correctly
>> to suppress progress output when generating dynamic Kconfig files.
>
> Instead of duplicating the same logic in all the terraform scripts, can
> you add it just to scripts/generate_cloud_config.py ?

If this isn't a good fit for generate_cloud_config.py, then another
approach would be to add the .oci/config check in a helper in
terraform/oci/scripts/oci_common.py and have the three menu generator
scripts use that common helper.

But I'm a little surprised because Claude /promised/ that these
scripts fail gracefully when there's no authentication material ;-)


> And can this fix go in a separate commit from the ssh change above?
>
>
>> Generated-by: Claude AI
>> Signed-off-by: Luis Chamberlain <[email protected]>
>> ---
>>  terraform/Kconfig.ssh                      | 7 +++++--
>>  terraform/oci/scripts/gen_kconfig_image    | 6 ++++++
>>  terraform/oci/scripts/gen_kconfig_location | 6 ++++++
>>  terraform/oci/scripts/gen_kconfig_shape    | 6 ++++++
>>  4 files changed, 23 insertions(+), 2 deletions(-)
>>
>> diff --git a/terraform/Kconfig.ssh b/terraform/Kconfig.ssh
>> index 4e239a35..b03f962f 100644
>> --- a/terraform/Kconfig.ssh
>> +++ b/terraform/Kconfig.ssh
>> @@ -21,14 +21,17 @@ config TERRAFORM_SSH_CONFIG_USER
>> 
>>  config TERRAFORM_SSH_CONFIG_PUBKEY_FILE
>>  	string "File containing Ansible's ssh public key"
>> -	default "~/.ssh/kdevops_terraform_$(shell, echo $(TOPDIR_PATH) | 
>> sha256sum | cut -c1-8).pub" if TERRAFORM_LAMBDALABS
>> -	default "~/.ssh/kdevops_terraform.pub"
>> +	default "~/.ssh/kdevops_terraform_$(shell, echo $(TOPDIR_PATH) | 
>> sha256sum | cut -c1-8).pub"
>>  	help
>>  	  The filename of the file containing an ssh public key
>>  	  Ansible is to use to manage its target nodes. The
>>  	  matching private key should be located in a file using
>>  	  the same basename (without the ".pub").
>> 
>> +	  The filename includes an 8-character hash of the current
>> +	  directory path, allowing multiple kdevops installations to
>> +	  use separate SSH keys without conflicts.
>> +
>>  config TERRAFORM_SSH_CONFIG_GENKEY
>>  	bool "Should we create a new random key for you?"
>>  	default y
>> diff --git a/terraform/oci/scripts/gen_kconfig_image 
>> b/terraform/oci/scripts/gen_kconfig_image
>> index 977446fd..55dfcf6c 100755
>> --- a/terraform/oci/scripts/gen_kconfig_image
>> +++ b/terraform/oci/scripts/gen_kconfig_image
>> @@ -718,6 +718,12 @@ def main():
>>      """Main function to run the program."""
>>      args = parse_arguments()
>> 
>> +    # Check for OCI config early - exit silently if not configured
>> +    if not os.path.exists(os.path.expanduser("~/.oci/config")):
>> +        if not args.quiet:
>> +            print("OCI not configured - skipping (optional)", 
>> file=sys.stderr)
>> +        sys.exit(0)
>> +
>>      if args.publishers:
>>          # Show both known and discovered publishers
>>          compartment_ocid = get_default_compartment()
>> diff --git a/terraform/oci/scripts/gen_kconfig_location 
>> b/terraform/oci/scripts/gen_kconfig_location
>> index 17ec8266..b397f534 100755
>> --- a/terraform/oci/scripts/gen_kconfig_location
>> +++ b/terraform/oci/scripts/gen_kconfig_location
>> @@ -432,6 +432,12 @@ def main():
>>      """Main function to run the program."""
>>      args = parse_arguments()
>> 
>> +    # Check for OCI config early - exit silently if not configured
>> +    if not os.path.exists(os.path.expanduser("~/.oci/config")):
>> +        if not args.quiet:
>> +            print("OCI not configured - skipping (optional)", 
>> file=sys.stderr)
>> +        sys.exit(0)
>> +
>>      if not args.quiet:
>>          print("Fetching list of OCI region subscriptions...", 
>> file=sys.stderr)
>>      regions = get_all_regions()
>> diff --git a/terraform/oci/scripts/gen_kconfig_shape 
>> b/terraform/oci/scripts/gen_kconfig_shape
>> index 09dd6d6f..d65ff37d 100755
>> --- a/terraform/oci/scripts/gen_kconfig_shape
>> +++ b/terraform/oci/scripts/gen_kconfig_shape
>> @@ -887,6 +887,12 @@ def main():
>>      """Main function to run the program."""
>>      args = parse_arguments()
>> 
>> +    # Check for OCI config early - exit silently if not configured
>> +    if not os.path.exists(os.path.expanduser("~/.oci/config")):
>> +        if not args.quiet:
>> +            print("OCI not configured - skipping (optional)", file=sys.stderr)
>> +        sys.exit(0)
>> +
>>      compartment_ocid = get_default_compartment()
>>      if not compartment_ocid:
>>          print("Error: Could not determine compartment OCID", file=sys.stderr)
>> -- 
>> 2.51.0
>
> -- 
> Chuck Lever

-- 
Chuck Lever