Freeze break: fix ssh_known_hosts

Kevin Fenzi kevin at scrye.com
Thu Apr 2 15:40:54 UTC 2015


When we moved our proxies from puppet to ansible, we forgot to setup
something to copy the ssh_known_hosts file over to them, so anyone who
goes to https://admin.fedoraproject.org/ssh_known_hosts gets a no such
file. 

I'd like to add the following patch to the proxies playbook and run
that playbook to correct this.

+1s?

kevin
--
diff --git a/roles/httpd/fingerprints/tasks/main.yml b/roles/httpd/fingerprints/tasks/main.yml
index 74dd152..00afe5c 100644
--- a/roles/httpd/fingerprints/tasks/main.yml
+++ b/roles/httpd/fingerprints/tasks/main.yml
@@ -13,3 +13,7 @@
   - fingerprints
   - httpd
   - httpd/fingerprints
+
+- copy: src=/etc/ssh/ssh_known_hosts dest=/etc/ssh/ssh_known_hosts
+  tags:
+  - fingerprints
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.fedoraproject.org/pipermail/infrastructure/attachments/20150402/d8faea0b/attachment.sig>


More information about the infrastructure mailing list