Repository navigation
fix(decdn_node): key-gen flag is --keystore-password-file on main - #45
Merged
Merged
Conversation
decdn main renamed `key-gen --password-file` -> `--keystore-password-file` (the daemon unit and `config validate` already use the new name). The role's key-gen task still passed the old flag, crash-failing keystore generation on a main build. Fix the task + the two doc references. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
🟢 Approval recommended
The change is small, consistent across code and docs, and removes the last in-role usage of the deprecated --password-file flag.
Pull request overview
Updates the decdn_node Ansible role to match the current decdn CLI surface on main, fixing keystore generation failures caused by the key-gen flag rename from --password-file to --keystore-password-file.
Changes:
- Switch the role’s
key-geninvocation to use--keystore-password-file. - Update the operator-facing inline guidance in
tasks/main.ymlto use the renamed flag. - Update the README’s keystore generation example to use the renamed flag.
File summaries
| File | Description |
|---|---|
| ansible/roles/decdn_node/tasks/main.yml | Fixes the decdn key-gen flag used during keystore generation and in the embedded remediation instructions. |
| ansible/roles/decdn_node/README.md | Updates documentation example to match the renamed key-gen flag. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
alpergundogdu
added a commit
that referenced
this pull request
Sep 11, 2026
Commit #45 renamed the role's key-gen flag from --password-file to --keystore-password-file but left the Molecule stub's key_gen() parsing the old flag, so the generate-keystore scenario's converge fails with "stub key-gen: --output-dir and --password-file are required" and the Molecule workflow is red on main. Point the stub at --keystore-password-file (and update the two doc comments) to match the role's real invocation. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CLI-flag drift the schema sync (#44) didn't cover — that synced
node.toml(types.rs), but thedecdnCLI is a separate surface. decdnmainrenamedkey-gen's--password-file→--keystore-password-file(the daemonExecStartandconfig validatealready use the new name). The role's keystore-generation task still passed the old flag, so on a main build it crash-fails:Fixes the
key-gentask (tasks/main.yml) and the two doc references. No other role CLI call is affected. Caught converging a real main build.🤖 Generated with Claude Code