Skip to main content

Ansible

One Ansible environment manages the Ubuntu machines of the fleet, through three inventories in conf/inventory/:

InventoryHosts
isc3_rack.ymlcalypsomaster (mgmt), epyc0 + rumba (temp), tango0/1, pim-checker. Was calypso_rack.yml with a workers group until 2026-08-28; those eight hosts are carnaval PVE nodes now and were dropped
dance.ymlthe CALC@HEI research nodes disco and chacha
infomaniak.ymlthe VPSes marcellus and hannibal

Mambo is not in dance.yml — the login-node part of that configuration was never written (CALC todo). When CALC@HEI gets its own governance the dance parts should move with it — see PHASE2-CALC-EXTRACTION.md in the repository.

It does not manage the Proxmox side: rumba and the carnaval cluster are configured by the scripts in provisioning/pve/. rumba is nevertheless listed in isc3_rack.yml (group temp, with users: null) — a leftover, not a managed host: common asserts Ubuntu 22.04 or 24.04 and aborts against a PVE host before doing anything.

Where it lives

provisioning/ansible/ in this repository — playbooks, roles and configuration together. The README in that directory is the operating manual: layout, setup, the playbook list, the known gaps.

Consolidated 2026-08-05

It used to be two GitHub repositories that a setup script stitched together at clone time: ansible-playbooks (public, the roles) and ansible-playbooks-conf (private, the inventory, users and keys). Both are now here and both are archived on GitHub, still readable for history. The reason for merging: the student roster and the SSH keys lived in one repository while everything consuming them lived elsewhere, so the same facts existed twice and drifted — the UID disagreement below is what that looked like in practice. ansible-playbooks-archive holds the older pre-split history.

Setup is two steps, and nothing is cloned any more:

cd provisioning/ansible
cp setup.cfg.sample setup.cfg # set VAULT_PASSWORD_FILE
./_setup_playbooks.sh # writes ansible.cfg (inventory=conf/inventory)

Some inventory values are vault-encrypted (the mailer@isc-vs.ch credentials), so a vault password is needed for anything that touches them.

The two things worth knowing before you run it

SSH keys are per-person files in conf/authorized_keys/<firstname.lastname>.pub. That directory is the source of truth for the Ansible-managed hosts — add a key there, run users.yml. The carnaval guests do not read it: since 2026-08-16 provisioning/pve/carnaval-lab-vm.sh takes keys from provisioning/keycloak/ssh-keys (the account model).

The UID register overrides the id: columns in conf/users/*.yml. Numeric UIDs come from provisioning/uid/uid-map.csv, seeded from the ownership of the homes on the NAS — which is what NFS actually compares. It is opt-in per inventory via uidmap_path, and only isc3_rack.yml sets it: on dance.yml the YAML numbers still stand on their own, in a different namespace (gregory.mermoud is 1004 on the rack and 25512 there).

So on the rack, where the two disagree the register wins and a run usermods the account — 13 of them as of 2026-08-05. That renumbering was never applied: the nodes carrying the drift were wiped on 2026-08-28 when they became carnaval PVE nodes (why). Still read uid-alloc.py --check-ansible before a run, to know what it would change. What matters instead is that the rebuild creates its accounts from the register — the open item in the todo.

Roles

There are three, and full.yml runs them in that order:

RoleManages
00_setuppre-flight only, no changes: loads conf/users, reads the UID register, checks that names and numbers are unique and that every user gets a number from somewhere. Every playbook starts with it
commonthe base system: the Ubuntu assert, timezone, /etc/hosts, base packages, sendmail via the mailer@isc-vs.ch smarthost, syslog to epyc0, sudoers/admins, and users, groups and authorized_keys
swthe extras, each gated on an inventory variable: zabbix-agent (needs zabbix_server), monit (needs mailer), pimonlinebot, and the MOTD

Per-machine differences come from the inventory, not from separate roles — a host with users: null gets the base system and no accounts, which is how epyc0, the two tango nodes and pim-checker are treated. Per-user account definitions live in conf/users/ (one file per cohort, plus roles.yml mapping cohorts onto machine groups), because ISC has no access to the HES-SO LDAP to manage groups there.

The calypso-sys, vps, isc_compute and slurm_calypso roles named in older notes are gone — they exist only in ansible-playbooks-archive. slurm_calypso and prometheus were never finished, and the SLURM cluster they targeted is gone (archive).

One thing the roles do not do, despite older notes saying otherwise: mount the NFS homes. The export and the ~/nas_home symlink are hand-maintained on the nodes (how); the playbooks only create the accounts that use them.