add ServiceRadar remote-access enrollment collection #1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/serviceradar-remote-access-enrollment"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds reusable, public Ansible content for ServiceRadar remote-access enrollment without publishing deployment-specific CA material or credentials.
Local verification is green: 8 repository tests, YAML/Ansible lint with zero failures or warnings, every wrapper syntax check, collection dependency install/build, and Windows QGA Molecule syntax.
Remaining before this leaves draft: provision and validate the approved dedicated repository-scoped ephemeral public runner (the current versioned label has no registered runner); complete ServiceRadar callback/AWX rollout; run ServiceRadar-originated Linux and Windows canaries; and record pull-request review. Production import remains explicitly disabled until those gates pass.
WIP: add gated ServiceRadar SSH CA enrollment collectionto WIP: add ServiceRadar remote-access enrollment collectionRunner-contract update (
0875202): both lint and Molecule now request onlyserviceradar-public-ephemeral-ubuntu-24.04-20260701. Each job fail-closes on the repo-85 boundary identity supplied by the one-job LXC supervisor, rejects Kubernetes/host-DinD/signing credential exposure, keeps checkout credentials disabled and repository permissions read-only, and records non-secret source/dependency/runner provenance (plus the four pinned Molecule image digests).Local locked verification is green: 8 tests, repository contract checks, yamllint, production-profile ansible-lint (0 failures/warnings), all wrapper syntax checks, Windows path contract, and Windows QGA Molecule syntax.
This PR intentionally remains draft. The new jobs may remain queued until the separate GitOps implementation provisions and validates the repository-85-scoped ephemeral runner; no generic or trusted runner fallback should be added.
WIP: add ServiceRadar remote-access enrollment collectionto add ServiceRadar remote-access enrollment collection