Re: [PATCH 1/8] terraform: Use directory checksum in SSH key filenames

"Chuck Lever" <[email protected]> Mon, 15 Dec 2025 10:41:40 -0500
Newsgroups dev.linux.lists.kdevops
Message-ID <[email protected]>

On Fri, Dec 12, 2025, at 2:14 PM, Chuck Lever wrote:
> On Sat, Dec 6, 2025, at 5:28 PM, Chuck Lever wrote:
>> On Sat, Dec 6, 2025, at 11:56 AM, Luis Chamberlain wrote:
>>> SSH keys now use directory-based checksums to support multiple kdevops
>>> installations coexisting without conflicts. The SSH key filename format
>>> is now ~/.ssh/kdevops_terraform_<checksum> where checksum is the first
>>> 8 characters of the SHA256 hash of the kdevops directory path.
>>>
>>> This was previously only applied to Lambda Labs provider but is now the
>>> default for all providers, as it solves the general problem of multiple
>>> installations sharing the same home directory.
>>
>>> Also fix OCI Kconfig generation scripts to use --quiet flag correctly
>>> to suppress progress output when generating dynamic Kconfig files.
>>
>> Instead of duplicating the same logic in all the terraform scripts, can
>> you add it just to scripts/generate_cloud_config.py ?
>
> If this isn't a good fit for generate_cloud_config.py, then another
> approach would be to add the .oci/config check in a helper in
> terraform/oci/scripts/oci_common.py and have the three menu generator
> scripts use that common helper.
>
> But I'm a little surprised because Claude /promised/ that these
> scripts fail gracefully when there's no authentication material ;-)
>
>
>> And can this fix go in a separate commit from the ssh change above?

I've sorted the review comments and merged 1/8 and 3/8. I'm now working
on "[PATCH 4/8] terraform: Add DataCrunch GPU cloud provider integration".


>>> Generated-by: Claude AI
>>> Signed-off-by: Luis Chamberlain <[email protected]>
>>> ---
>>>  terraform/Kconfig.ssh                      | 7 +++++--
>>>  terraform/oci/scripts/gen_kconfig_image    | 6 ++++++
>>>  terraform/oci/scripts/gen_kconfig_location | 6 ++++++
>>>  terraform/oci/scripts/gen_kconfig_shape    | 6 ++++++
>>>  4 files changed, 23 insertions(+), 2 deletions(-)
>>>
>>> diff --git a/terraform/Kconfig.ssh b/terraform/Kconfig.ssh
>>> index 4e239a35..b03f962f 100644
>>> --- a/terraform/Kconfig.ssh
>>> +++ b/terraform/Kconfig.ssh
>>> @@ -21,14 +21,17 @@ config TERRAFORM_SSH_CONFIG_USER
>>> 
>>>  config TERRAFORM_SSH_CONFIG_PUBKEY_FILE
>>>  	string "File containing Ansible's ssh public key"
>>> -	default "~/.ssh/kdevops_terraform_$(shell, echo $(TOPDIR_PATH) | 
>>> sha256sum | cut -c1-8).pub" if TERRAFORM_LAMBDALABS
>>> -	default "~/.ssh/kdevops_terraform.pub"
>>> +	default "~/.ssh/kdevops_terraform_$(shell, echo $(TOPDIR_PATH) | 
>>> sha256sum | cut -c1-8).pub"
>>>  	help
>>>  	  The filename of the file containing an ssh public key
>>>  	  Ansible is to use to manage its target nodes. The
>>>  	  matching private key should be located in a file using
>>>  	  the same basename (without the ".pub").
>>> 
>>> +	  The filename includes an 8-character hash of the current
>>> +	  directory path, allowing multiple kdevops installations to
>>> +	  use separate SSH keys without conflicts.
>>> +
>>>  config TERRAFORM_SSH_CONFIG_GENKEY
>>>  	bool "Should we create a new random key for you?"
>>>  	default y
>>> diff --git a/terraform/oci/scripts/gen_kconfig_image 
>>> b/terraform/oci/scripts/gen_kconfig_image
>>> index 977446fd..55dfcf6c 100755
>>> --- a/terraform/oci/scripts/gen_kconfig_image
>>> +++ b/terraform/oci/scripts/gen_kconfig_image
>>> @@ -718,6 +718,12 @@ def main():
>>>      """Main function to run the program."""
>>>      args = parse_arguments()
>>> 
>>> +    # Check for OCI config early - exit silently if not configured
>>> +    if not os.path.exists(os.path.expanduser("~/.oci/config")):
>>> +        if not args.quiet:
>>> +            print("OCI not configured - skipping (optional)", 
>>> file=sys.stderr)
>>> +        sys.exit(0)
>>> +
>>>      if args.publishers:
>>>          # Show both known and discovered publishers
>>>          compartment_ocid = get_default_compartment()
>>> diff --git a/terraform/oci/scripts/gen_kconfig_location 
>>> b/terraform/oci/scripts/gen_kconfig_location
>>> index 17ec8266..b397f534 100755
>>> --- a/terraform/oci/scripts/gen_kconfig_location
>>> +++ b/terraform/oci/scripts/gen_kconfig_location
>>> @@ -432,6 +432,12 @@ def main():
>>>      """Main function to run the program."""
>>>      args = parse_arguments()
>>> 
>>> +    # Check for OCI config early - exit silently if not configured
>>> +    if not os.path.exists(os.path.expanduser("~/.oci/config")):
>>> +        if not args.quiet:
>>> +            print("OCI not configured - skipping (optional)", 
>>> file=sys.stderr)
>>> +        sys.exit(0)
>>> +
>>>      if not args.quiet:
>>>          print("Fetching list of OCI region subscriptions...", 
>>> file=sys.stderr)
>>>      regions = get_all_regions()
>>> diff --git a/terraform/oci/scripts/gen_kconfig_shape 
>>> b/terraform/oci/scripts/gen_kconfig_shape
>>> index 09dd6d6f..d65ff37d 100755
>>> --- a/terraform/oci/scripts/gen_kconfig_shape
>>> +++ b/terraform/oci/scripts/gen_kconfig_shape
>>> @@ -887,6 +887,12 @@ def main():
>>>      """Main function to run the program."""
>>>      args = parse_arguments()
>>> 
>>> +    # Check for OCI config early - exit silently if not configured
>>> +    if not os.path.exists(os.path.expanduser("~/.oci/config")):
>>> +        if not args.quiet:
>>> +            print("OCI not configured - skipping (optional)", file=sys.stderr)
>>> +        sys.exit(0)
>>> +
>>>      compartment_ocid = get_default_compartment()
>>>      if not compartment_ocid:
>>>          print("Error: Could not determine compartment OCID", file=sys.stderr)
>>> -- 
>>> 2.51.0
>>
>> -- 
>> Chuck Lever
>
> -- 
> Chuck Lever

-- 
Chuck Lever