- Sep 06, 2022
-
-
Rafael Guterres Jeffman authored
A new test playbook for ipabackup role can be found at: tests/role_backup/test_backup.yml The test is not yet complete, as 'state: restored' is not tested.
-
- Aug 31, 2022
-
-
Thomas Woerner authored
Run tests locally with upstream CI images.
-
Rafael Guterres Jeffman authored
ipaserver: Add missing idstart check
-
- Aug 30, 2022
-
-
Thomas Woerner authored
The idstart needs to be larger than UID_MAX or GID_MAX from /etc/login.defs. This is "Require idstart to be larger than UID_MAX" for freeipa. Fixes: #896 (Invalid RID/SID SSSD backtrace after deployment)
-
Rafael Guterres Jeffman authored
This patch allows local execution of playbook tests using ustream CI testing images. Either 'podman' or 'docker' can be used to execute the tests.
-
Rafael Guterres Jeffman authored
ipaserver: ipaclient part does not need to install packages
-
Rafael Guterres Jeffman authored
fedora rawhide: Temporarily disable failing DNS tests
-
- Aug 29, 2022
-
-
Thomas Woerner authored
upstream CI: Fix list evaluation in IPA_ENABLED/IPA_DISABLED tests
-
Thomas Woerner authored
Some DNS tests have been disabled for Fedora latest, but not for Fedora Rawhide. Therefore these tests are filin still in nighty: - dnsforwardzone - test_dnsconfig_forwarders_ports
-
Thomas Woerner authored
The client part installation is checking for the client packages. These packages are part of the server packages that have been installed with the server role and therefore the task is not needed. This is helping to reduce the deployment time of a server.
-
- Aug 26, 2022
-
-
Rafael Guterres Jeffman authored
Fix short_description flag in plugins, role modules and templates
-
Thomas Woerner authored
Before "short description" was used in most plugins, modules and also in the new module templates. ansible-doc was therefore not showing the short description. To fix the issue the flag was renamed to short_description instead. Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=2121362 'ansible-doc' -l lists most idm modules as 'UNDOCUMENTED'
-
- Aug 25, 2022
-
-
Rafael Guterres Jeffman authored
When enabling or disabling multiple tests, a comma separated list must be used, but current code is using a colon to split the list. This patch fixes this behavior.
-
Rafael Guterres Jeffman authored
Merge pull request #876 from t-woerner/ipareplica_do_not_overwrite_ipaclient_no_ntp_for_client_part_deployment ipareplica: Do not overwrite ipaclient_no_ntp for client part deployment
-
Thomas Woerner authored
ipauser: Add note on attributes 'first' and 'last' requirements
-
Thomas Woerner authored
upstream CI: enable/disable tests based on test image
-
Rafael Guterres Jeffman authored
Attributes 'first' and 'last' are required if user does not exist, but current documentation doesn't make it clear. This patch adds a note on both attributes to make clear the cases where the attribute is required
-
- Aug 24, 2022
-
-
Rafael Guterres Jeffman authored
Since test configuration can vary in different scenarios (test images) this patch adds a script to list the scenarios configuration, and a step to the playbook test jobs to display the scenario configuration.
-
Rafael Guterres Jeffman authored
Currently, all tests are scheduled to execution, even those that are not executed due to being absent from the list of enabled tests configured in the IPA_ENABLED_* variables. The tests that are not executed are marked 'skipped'. This patch change this behavior by not scheduling tests that are not configured to be executed. It means that tests not the IPA_DISABLED_* lists are not skipped anymore, but not scheduled to be executed. If any test is in IPA_ENABLED_* lists, only those tests are marked for execution. A side effect is that there is no visual feedback on which tests were not executed, as disabled tests are not evaluated anymore. Also, when IPA_SERVER_HOST was not set, all tests were skipped, but an error should raised in this case, as there are no hosts to run the tests against. This patch modifies this behavior to fail the test with an exception if IPA_SERVER_HOST is not set.
-
Rafael Guterres Jeffman authored
Sometimes, mostly due do differences in package versions, there are some tests that fail on a single distribution which cannot be fixed by ansible-freeipa, requiring that the offending package is fixed. To keep tests running succesfully we have options to disable the failing tests, but this changes are globally applied, meaning that, by disabling a test, it is disable in all tested distributions. This patch allows tests to be enabled or disabled for a specific distribution, by setting the configuration on the 'variable' template for the specific testing scenario.
-
Thomas Woerner authored
ipasudorule: Fix usage of 'action' and 'state' in examples.
-
- Aug 23, 2022
-
-
Rafael Guterres Jeffman authored
Some examples in ipasudorule were using `action: enabled` when it should've been `state: enabled`. The examples were fixed.
-
- Aug 18, 2022
-
-
Thomas Woerner authored
The NTP server chrony was always enabled and set up due to overwriting the parameter ipaclient_no_ntp for the client part deployment. For IPA deployments up to 4.6 no_ntp was always used for the client part deployment in ipa-replica-install. But afterwards ntp was configured in the replica deployment part if no_ntp was not set. The ipareplica roles always relied on the client for setting up the NTP server but overwrote the setting for the client deployment part. This did not result in a failure to enable the chrony server in RHEL and Fedora based distributions as NTP server was always required by the ipa-server package. Fixes: #871 (ipa-replica-install with no-ntp is ignored)
-
- Aug 16, 2022
-
-
Varun Mylaraiah authored
ipavault: Fix missing whitespace after keyword issue
-
Varun Mylaraiah authored
ipareplica: ipareplica_setup_adtrust fails while updating ipaNTFlatName
-
Thomas Woerner authored
flake8 reports an issue in ipavault: plugins/modules/ipavault.py:528:20: E275 missing whitespace after keyword The missing whitespace has been added: "and not(" -> "and not ("
-
- Aug 15, 2022
-
-
Thomas Woerner authored
The internal parameter sid_generation_always is generated in ipareplica_test to enable SID generation if ipareplica_setup_adtrust is not enabled. This parameter was not used for ipareplica_prepare though, therefore adtrust.install_check was not executed and did not set the attribute adtrust.netbios_name. As a result adtrust.netbios_name was None and the try to use this as the new NetBIOS domain name failed with an INVALID_SYNTAX error in adtrustinstance while executing ipareplica_setup_adtrust. This issue only occurs if SIDs are not enabled in the domain yet for example with an old deployment.
-
- Jul 28, 2022
-
-
Thomas Woerner authored
ipaclient: Removed invalid call `logger.info()`
-
Varun Mylaraiah authored
ipaserver/ipareplica: Always generate SIDs
-
- Jul 27, 2022
-
-
jpclipffel authored
- Call was responsible for a `TypeError` exception - Call was not useful (already followed by a proper `logger.warning` call) Should fix issue #865: https://github.com/freeipa/ansible-freeipa/issues/865
-
Thomas Woerner authored
The SID is always generated in the command line installers in newer IPA versions. This also needs to be done in the ipaserver and ipareplica roles. For the IPA versions that are supporting this, the adtrust setup is always executed to generated the SIDs, but only configures AD trust if ipaserver_setup_adtrust or ipareplica_setup_adtrust is also enabled. A check has been added to ipaserver_test and ipareplica_test to only enable the SID generation for the IPA versions supporting this. This is related to https://pagure.io/freeipa/8995 Fixes: - https://bugzilla.redhat.com/show_bug.cgi?id=2110478 - https://bugzilla.redhat.com/show_bug.cgi?id=2110491
-
- Jul 25, 2022
-
-
Varun Mylaraiah authored
ipaserver,ipareplica: Fix Random Serial Numbers always enabled
-
Thomas Woerner authored
ipadnsconfig: Fix boolean values comparison
-
Thomas Woerner authored
The option _random_serial_numbers was using with the wrong type in ipaserver_setup_ca.py and ipareplica_setup_ca.py. Therefore RSN was always enabled. Fixes: - https://bugzilla.redhat.com/show_bug.cgi?id=2110523 - https://bugzilla.redhat.com/show_bug.cgi?id=2110526
-
- Jul 21, 2022
-
-
Rafael Guterres Jeffman authored
This patch disables only the tests that are failing due to python-dns issue in FreeIPA, allowing other tests in the test suite to be executed.
-
Rafael Guterres Jeffman authored
Due to an issue with python-dns, FreeIPA is raising an expection when setting a DNS forwarder with a custom port. Separating the test for ipadnsconfig that use forwarders with custom allows the other tests to be correctly executed.
-
Rafael Guterres Jeffman authored
-
Rafael Guterres Jeffman authored
IPA 4.9.10+ handles LDAP boolean values correctly, and the comparison should be executed with the values itself, instead of a string representation.
-
- Jul 08, 2022
-
-
Thomas Woerner authored
upstream CI: enable tests on Fedora Rawide.
-
Thomas Woerner authored
sanity.sh: Allow use of podman instead of docker
-