all:
  children:
    controllers:
      hosts:
        controller: null
    zuul_unreachable:
      hosts: {}
  hosts:
    controller:
      ansible_connection: ssh
      ansible_host: 199.204.45.72
      ansible_port: 22
      ansible_python_interpreter: auto
      ansible_user: zuul
      cilium_helm_values:
        operator:
          replicas: 1
      cilium_ipv4_cidr: 172.24.0.0/16
      kube_vip_address: 172.17.0.100
      kube_vip_interface: '{{ ansible_facts[''default_ipv4''].interface }}'
      kubernetes_hostname: '{{ ansible_facts[''default_ipv4''].address }}'
      kubernetes_version: 1.28.13
      molecule_install_collection_siblings: true
      molecule_scenario: secretgen-controller
      nodepool:
        az: nova
        cloud: public
        external_id: efe15eb7-99c0-4ca2-9ffd-f5aba17ee534
        host_id: c9670958829e9c96e47d452d2c9c4ce9edaac336d3dbc4a3c4ec531c
        interface_ip: 199.204.45.72
        label: ubuntu-noble
        node_properties: {}
        private_ipv4: 199.204.45.72
        private_ipv6: null
        provider: yul1
        public_ipv4: 199.204.45.72
        public_ipv6: 2604:e100:1:0:f816:3eff:fe84:55f7
        region: ca-ymq-1
        slot: null
      zuul_node:
        az: nova
        cloud: public
        external_id: efe15eb7-99c0-4ca2-9ffd-f5aba17ee534
        host_id: c9670958829e9c96e47d452d2c9c4ce9edaac336d3dbc4a3c4ec531c
        interface_ip: 199.204.45.72
        label: ubuntu-noble
        node_properties: {}
        private_ipv4: 199.204.45.72
        private_ipv6: null
        provider: yul1
        public_ipv4: 199.204.45.72
        public_ipv6: 2604:e100:1:0:f816:3eff:fe84:55f7
        region: ca-ymq-1
        slot: null
        uuid: null
  vars:
    cilium_helm_values:
      operator:
        replicas: 1
    kubernetes_version: 1.28.13
    molecule_install_collection_siblings: true
    molecule_scenario: secretgen-controller
    zuul:
      _inheritance_path:
      - '<Job base explicit: None implied: {MatchAny:{ImpliedBranchMatcher:main}}
        source: vexxhost/zuul-config/zuul.d/jobs.yaml@main#1>'
      - '<Job molecule explicit: None implied: {MatchAny:{ImpliedBranchMatcher:main}}
        source: vexxhost/zuul-jobs/zuul.d/ansible-jobs.yaml@main#1>'
      - '<Job atmosphere-common-molecule explicit: None implied: {MatchAny:{ImpliedBranchMatcher:main}}
        source: vexxhost/atmosphere.common/.zuul.yaml@main#4>'
      - '<Job atmosphere-common-molecule-secretgen-controller explicit: None implied:
        {MatchAny:{ImpliedBranchMatcher:main}} source: vexxhost/atmosphere.common/.zuul.yaml@main#33>'
      - '<Job atmosphere-common-molecule-secretgen-controller explicit: None implied:
        None source: vexxhost/atmosphere.common/.zuul.yaml@main#114>'
      ansible_version: '9'
      attempts: 1
      branch: main
      build: c80f6dbb70d44bc586867c819787155f
      build_refs:
      - branch: main
        change: '118'
        change_message: 'ci: stabilize molecule and Metal3 jobs


          ## Summary


          Separate the CI stabilization work that was previously bundled into #117
          from the `secretgen_controller` runtime fix.


          ## Changes


          - pin the Molecule Kubernetes Python client to `kubernetes==33.1.0` to avoid
          replacing Debian-provided PyYAML

          - retry the Ironic custom resource apply when the Kubernetes API briefly
          returns a 503

          - allow the Metal3 CI smoke test to disable the IPA downloader it does not
          exercise

          - wait for the Ironic service independently and collect diagnostics when
          Metal3 CI fails


          ## Why


          These changes address failures in the repository-wide `external-secrets-operator`
          and `metal3` jobs. They are not part of the `secretgen_controller` template-rendering
          fix required by vexxhost/atmosphere#4009, so they are moved out of #117
          to keep that PR focused.


          ## Validation


          - `git diff --check origin/main..HEAD`

          - `pre-commit run --files .github/workflows/ci.yaml extensions/molecule/default/prepare.yml
          roles/ironic_standalone/defaults/main.yaml roles/ironic_standalone/tasks/main.yaml`

          - the same patch previously passed pre-commit, ansible-lint, Metal3, external-secrets-operator,
          and `oss/check` while it was present on #117

          '
        change_url: https://github.com/vexxhost/atmosphere.common/pull/118
        commit_id: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
        patchset: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
        project:
          canonical_hostname: github.com
          canonical_name: github.com/vexxhost/atmosphere.common
          name: vexxhost/atmosphere.common
          short_name: atmosphere.common
          src_dir: src/github.com/vexxhost/atmosphere.common
        src_dir: src/github.com/vexxhost/atmosphere.common
        topic: null
      buildset: 518c8878ed0d4a258cdd80afb44c83cc
      buildset_refs:
      - branch: main
        change: '118'
        change_message: 'ci: stabilize molecule and Metal3 jobs


          ## Summary


          Separate the CI stabilization work that was previously bundled into #117
          from the `secretgen_controller` runtime fix.


          ## Changes


          - pin the Molecule Kubernetes Python client to `kubernetes==33.1.0` to avoid
          replacing Debian-provided PyYAML

          - retry the Ironic custom resource apply when the Kubernetes API briefly
          returns a 503

          - allow the Metal3 CI smoke test to disable the IPA downloader it does not
          exercise

          - wait for the Ironic service independently and collect diagnostics when
          Metal3 CI fails


          ## Why


          These changes address failures in the repository-wide `external-secrets-operator`
          and `metal3` jobs. They are not part of the `secretgen_controller` template-rendering
          fix required by vexxhost/atmosphere#4009, so they are moved out of #117
          to keep that PR focused.


          ## Validation


          - `git diff --check origin/main..HEAD`

          - `pre-commit run --files .github/workflows/ci.yaml extensions/molecule/default/prepare.yml
          roles/ironic_standalone/defaults/main.yaml roles/ironic_standalone/tasks/main.yaml`

          - the same patch previously passed pre-commit, ansible-lint, Metal3, external-secrets-operator,
          and `oss/check` while it was present on #117

          '
        change_url: https://github.com/vexxhost/atmosphere.common/pull/118
        commit_id: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
        patchset: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
        project:
          canonical_hostname: github.com
          canonical_name: github.com/vexxhost/atmosphere.common
          name: vexxhost/atmosphere.common
          short_name: atmosphere.common
          src_dir: src/github.com/vexxhost/atmosphere.common
        src_dir: src/github.com/vexxhost/atmosphere.common
        topic: null
      change: '118'
      change_message: 'ci: stabilize molecule and Metal3 jobs


        ## Summary


        Separate the CI stabilization work that was previously bundled into #117 from
        the `secretgen_controller` runtime fix.


        ## Changes


        - pin the Molecule Kubernetes Python client to `kubernetes==33.1.0` to avoid
        replacing Debian-provided PyYAML

        - retry the Ironic custom resource apply when the Kubernetes API briefly returns
        a 503

        - allow the Metal3 CI smoke test to disable the IPA downloader it does not
        exercise

        - wait for the Ironic service independently and collect diagnostics when Metal3
        CI fails


        ## Why


        These changes address failures in the repository-wide `external-secrets-operator`
        and `metal3` jobs. They are not part of the `secretgen_controller` template-rendering
        fix required by vexxhost/atmosphere#4009, so they are moved out of #117 to
        keep that PR focused.


        ## Validation


        - `git diff --check origin/main..HEAD`

        - `pre-commit run --files .github/workflows/ci.yaml extensions/molecule/default/prepare.yml
        roles/ironic_standalone/defaults/main.yaml roles/ironic_standalone/tasks/main.yaml`

        - the same patch previously passed pre-commit, ansible-lint, Metal3, external-secrets-operator,
        and `oss/check` while it was present on #117

        '
      change_url: https://github.com/vexxhost/atmosphere.common/pull/118
      child_jobs: []
      commit_id: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
      event_id: 3b8ac230-818c-11f1-9f07-51d29feea3cc
      executor:
        hostname: 2d72f0692154
        inventory_file: /var/lib/zuul/builds/c80f6dbb70d44bc586867c819787155f/ansible/inventory.yaml
        log_root: /var/lib/zuul/builds/c80f6dbb70d44bc586867c819787155f/work/logs
        result_data_file: /var/lib/zuul/builds/c80f6dbb70d44bc586867c819787155f/work/results.json
        src_root: /var/lib/zuul/builds/c80f6dbb70d44bc586867c819787155f/work/src
        work_root: /var/lib/zuul/builds/c80f6dbb70d44bc586867c819787155f/work
      include_vars: []
      items:
      - branch: main
        change: '118'
        change_message: 'ci: stabilize molecule and Metal3 jobs


          ## Summary


          Separate the CI stabilization work that was previously bundled into #117
          from the `secretgen_controller` runtime fix.


          ## Changes


          - pin the Molecule Kubernetes Python client to `kubernetes==33.1.0` to avoid
          replacing Debian-provided PyYAML

          - retry the Ironic custom resource apply when the Kubernetes API briefly
          returns a 503

          - allow the Metal3 CI smoke test to disable the IPA downloader it does not
          exercise

          - wait for the Ironic service independently and collect diagnostics when
          Metal3 CI fails


          ## Why


          These changes address failures in the repository-wide `external-secrets-operator`
          and `metal3` jobs. They are not part of the `secretgen_controller` template-rendering
          fix required by vexxhost/atmosphere#4009, so they are moved out of #117
          to keep that PR focused.


          ## Validation


          - `git diff --check origin/main..HEAD`

          - `pre-commit run --files .github/workflows/ci.yaml extensions/molecule/default/prepare.yml
          roles/ironic_standalone/defaults/main.yaml roles/ironic_standalone/tasks/main.yaml`

          - the same patch previously passed pre-commit, ansible-lint, Metal3, external-secrets-operator,
          and `oss/check` while it was present on #117

          '
        change_url: https://github.com/vexxhost/atmosphere.common/pull/118
        commit_id: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
        patchset: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
        project:
          canonical_hostname: github.com
          canonical_name: github.com/vexxhost/atmosphere.common
          name: vexxhost/atmosphere.common
          short_name: atmosphere.common
          src_dir: src/github.com/vexxhost/atmosphere.common
        topic: null
      job: atmosphere-common-molecule-secretgen-controller
      jobtags: []
      max_attempts: 3
      message: Y2k6IHN0YWJpbGl6ZSBtb2xlY3VsZSBhbmQgTWV0YWwzIGpvYnMKCiMjIFN1bW1hcnkKClNlcGFyYXRlIHRoZSBDSSBzdGFiaWxpemF0aW9uIHdvcmsgdGhhdCB3YXMgcHJldmlvdXNseSBidW5kbGVkIGludG8gIzExNyBmcm9tIHRoZSBgc2VjcmV0Z2VuX2NvbnRyb2xsZXJgIHJ1bnRpbWUgZml4LgoKIyMgQ2hhbmdlcwoKLSBwaW4gdGhlIE1vbGVjdWxlIEt1YmVybmV0ZXMgUHl0aG9uIGNsaWVudCB0byBga3ViZXJuZXRlcz09MzMuMS4wYCB0byBhdm9pZCByZXBsYWNpbmcgRGViaWFuLXByb3ZpZGVkIFB5WUFNTAotIHJldHJ5IHRoZSBJcm9uaWMgY3VzdG9tIHJlc291cmNlIGFwcGx5IHdoZW4gdGhlIEt1YmVybmV0ZXMgQVBJIGJyaWVmbHkgcmV0dXJucyBhIDUwMwotIGFsbG93IHRoZSBNZXRhbDMgQ0kgc21va2UgdGVzdCB0byBkaXNhYmxlIHRoZSBJUEEgZG93bmxvYWRlciBpdCBkb2VzIG5vdCBleGVyY2lzZQotIHdhaXQgZm9yIHRoZSBJcm9uaWMgc2VydmljZSBpbmRlcGVuZGVudGx5IGFuZCBjb2xsZWN0IGRpYWdub3N0aWNzIHdoZW4gTWV0YWwzIENJIGZhaWxzCgojIyBXaHkKClRoZXNlIGNoYW5nZXMgYWRkcmVzcyBmYWlsdXJlcyBpbiB0aGUgcmVwb3NpdG9yeS13aWRlIGBleHRlcm5hbC1zZWNyZXRzLW9wZXJhdG9yYCBhbmQgYG1ldGFsM2Agam9icy4gVGhleSBhcmUgbm90IHBhcnQgb2YgdGhlIGBzZWNyZXRnZW5fY29udHJvbGxlcmAgdGVtcGxhdGUtcmVuZGVyaW5nIGZpeCByZXF1aXJlZCBieSB2ZXh4aG9zdC9hdG1vc3BoZXJlIzQwMDksIHNvIHRoZXkgYXJlIG1vdmVkIG91dCBvZiAjMTE3IHRvIGtlZXAgdGhhdCBQUiBmb2N1c2VkLgoKIyMgVmFsaWRhdGlvbgoKLSBgZ2l0IGRpZmYgLS1jaGVjayBvcmlnaW4vbWFpbi4uSEVBRGAKLSBgcHJlLWNvbW1pdCBydW4gLS1maWxlcyAuZ2l0aHViL3dvcmtmbG93cy9jaS55YW1sIGV4dGVuc2lvbnMvbW9sZWN1bGUvZGVmYXVsdC9wcmVwYXJlLnltbCByb2xlcy9pcm9uaWNfc3RhbmRhbG9uZS9kZWZhdWx0cy9tYWluLnlhbWwgcm9sZXMvaXJvbmljX3N0YW5kYWxvbmUvdGFza3MvbWFpbi55YW1sYAotIHRoZSBzYW1lIHBhdGNoIHByZXZpb3VzbHkgcGFzc2VkIHByZS1jb21taXQsIGFuc2libGUtbGludCwgTWV0YWwzLCBleHRlcm5hbC1zZWNyZXRzLW9wZXJhdG9yLCBhbmQgYG9zcy9jaGVja2Agd2hpbGUgaXQgd2FzIHByZXNlbnQgb24gIzExNwo=
      patchset: fd6d0ae0e5c87929c5ce1089e806facdb1ba7811
      pipeline: check
      playbook_context:
        playbook_projects:
          trusted/project_0/github.com/vexxhost/zuul-config:
            canonical_name: github.com/vexxhost/zuul-config
            checkout: main
            commit: 298983cd1253e6833abdb49d87d912527e0e6597
          trusted/project_1/opendev.org/zuul/zuul-jobs:
            canonical_name: opendev.org/zuul/zuul-jobs
            checkout: master
            commit: 099fd2fd24246f4d89259206430c3a124dcf45ad
          trusted/project_2/github.com/vexxhost/zuul-jobs:
            canonical_name: github.com/vexxhost/zuul-jobs
            checkout: main
            commit: c286bf94224b5660b8e49e9a058289e61062a9a0
          untrusted/project_0/github.com/vexxhost/zuul-jobs:
            canonical_name: github.com/vexxhost/zuul-jobs
            checkout: main
            commit: c286bf94224b5660b8e49e9a058289e61062a9a0
          untrusted/project_1/github.com/vexxhost/zuul-config:
            canonical_name: github.com/vexxhost/zuul-config
            checkout: main
            commit: 298983cd1253e6833abdb49d87d912527e0e6597
          untrusted/project_2/opendev.org/zuul/zuul-jobs:
            canonical_name: opendev.org/zuul/zuul-jobs
            checkout: master
            commit: 099fd2fd24246f4d89259206430c3a124dcf45ad
          untrusted/project_3/github.com/vexxhost/atmosphere.common:
            canonical_name: github.com/vexxhost/atmosphere.common
            checkout: main
            commit: 250893cf8a9a68ff5baded4b06485be9e85a150f
          untrusted/project_4/opendev.org/openstack/openstack-helm:
            canonical_name: opendev.org/openstack/openstack-helm
            checkout: master
            commit: d03dd061a8112c468e2f6529cb0663873f96b50f
        playbooks:
        - path: untrusted/project_0/github.com/vexxhost/zuul-jobs/playbooks/molecule/run.yaml
          roles:
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/playbook_0/role_1/zuul-jobs
            link_target: untrusted/project_2/opendev.org/zuul/zuul-jobs
            role_path: ansible/playbook_0/role_1/zuul-jobs/roles
          - checkout: main
            checkout_description: playbook branch
            link_name: ansible/playbook_0/role_2/zuul-jobs
            link_target: untrusted/project_0/github.com/vexxhost/zuul-jobs
            role_path: ansible/playbook_0/role_2/zuul-jobs/roles
        post_playbooks:
        - path: untrusted/project_3/github.com/vexxhost/atmosphere.common/test-playbooks/molecule/post.yml
          roles:
          - checkout: main
            checkout_description: playbook branch
            link_name: ansible/post_playbook_0/role_0/atmosphere.common
            link_target: untrusted/project_3/github.com/vexxhost/atmosphere.common
            role_path: ansible/post_playbook_0/role_0/atmosphere.common/roles
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/post_playbook_0/role_1/openstack-helm
            link_target: untrusted/project_4/opendev.org/openstack/openstack-helm
            role_path: ansible/post_playbook_0/role_1/openstack-helm/roles
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/post_playbook_0/role_3/zuul-jobs
            link_target: untrusted/project_2/opendev.org/zuul/zuul-jobs
            role_path: ansible/post_playbook_0/role_3/zuul-jobs/roles
          - checkout: main
            checkout_description: zuul branch
            link_name: ansible/post_playbook_0/role_4/zuul-jobs
            link_target: untrusted/project_0/github.com/vexxhost/zuul-jobs
            role_path: ansible/post_playbook_0/role_4/zuul-jobs/roles
        - path: trusted/project_0/github.com/vexxhost/zuul-config/playbooks/base/post.yaml
          roles:
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/post_playbook_1/role_1/zuul-jobs
            link_target: trusted/project_1/opendev.org/zuul/zuul-jobs
            role_path: ansible/post_playbook_1/role_1/zuul-jobs/roles
          - checkout: main
            checkout_description: zuul branch
            link_name: ansible/post_playbook_1/role_2/zuul-jobs
            link_target: trusted/project_2/github.com/vexxhost/zuul-jobs
            role_path: ansible/post_playbook_1/role_2/zuul-jobs/roles
        - path: trusted/project_0/github.com/vexxhost/zuul-config/playbooks/base/post-logs.yaml
          roles:
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/post_playbook_2/role_1/zuul-jobs
            link_target: trusted/project_1/opendev.org/zuul/zuul-jobs
            role_path: ansible/post_playbook_2/role_1/zuul-jobs/roles
          - checkout: main
            checkout_description: zuul branch
            link_name: ansible/post_playbook_2/role_2/zuul-jobs
            link_target: trusted/project_2/github.com/vexxhost/zuul-jobs
            role_path: ansible/post_playbook_2/role_2/zuul-jobs/roles
        pre_playbooks:
        - path: trusted/project_0/github.com/vexxhost/zuul-config/playbooks/base/pre.yaml
          roles:
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/pre_playbook_0/role_1/zuul-jobs
            link_target: trusted/project_1/opendev.org/zuul/zuul-jobs
            role_path: ansible/pre_playbook_0/role_1/zuul-jobs/roles
          - checkout: main
            checkout_description: zuul branch
            link_name: ansible/pre_playbook_0/role_2/zuul-jobs
            link_target: trusted/project_2/github.com/vexxhost/zuul-jobs
            role_path: ansible/pre_playbook_0/role_2/zuul-jobs/roles
        - path: untrusted/project_0/github.com/vexxhost/zuul-jobs/playbooks/molecule/pre.yaml
          roles:
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/pre_playbook_1/role_1/zuul-jobs
            link_target: untrusted/project_2/opendev.org/zuul/zuul-jobs
            role_path: ansible/pre_playbook_1/role_1/zuul-jobs/roles
          - checkout: main
            checkout_description: playbook branch
            link_name: ansible/pre_playbook_1/role_2/zuul-jobs
            link_target: untrusted/project_0/github.com/vexxhost/zuul-jobs
            role_path: ansible/pre_playbook_1/role_2/zuul-jobs/roles
        - path: untrusted/project_3/github.com/vexxhost/atmosphere.common/test-playbooks/molecule/pre.yml
          roles:
          - checkout: main
            checkout_description: playbook branch
            link_name: ansible/pre_playbook_2/role_0/atmosphere.common
            link_target: untrusted/project_3/github.com/vexxhost/atmosphere.common
            role_path: ansible/pre_playbook_2/role_0/atmosphere.common/roles
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/pre_playbook_2/role_1/openstack-helm
            link_target: untrusted/project_4/opendev.org/openstack/openstack-helm
            role_path: ansible/pre_playbook_2/role_1/openstack-helm/roles
          - checkout: master
            checkout_description: project default branch
            link_name: ansible/pre_playbook_2/role_3/zuul-jobs
            link_target: untrusted/project_2/opendev.org/zuul/zuul-jobs
            role_path: ansible/pre_playbook_2/role_3/zuul-jobs/roles
          - checkout: main
            checkout_description: zuul branch
            link_name: ansible/pre_playbook_2/role_4/zuul-jobs
            link_target: untrusted/project_0/github.com/vexxhost/zuul-jobs
            role_path: ansible/pre_playbook_2/role_4/zuul-jobs/roles
      post_review: false
      post_timeout: null
      pre_timeout: null
      project:
        canonical_hostname: github.com
        canonical_name: github.com/vexxhost/atmosphere.common
        name: vexxhost/atmosphere.common
        short_name: atmosphere.common
        src_dir: src/github.com/vexxhost/atmosphere.common
      projects:
        github.com/vexxhost/atmosphere.common:
          canonical_hostname: github.com
          canonical_name: github.com/vexxhost/atmosphere.common
          checkout: main
          checkout_description: zuul branch
          commit: 250893cf8a9a68ff5baded4b06485be9e85a150f
          name: vexxhost/atmosphere.common
          required: false
          short_name: atmosphere.common
          src_dir: src/github.com/vexxhost/atmosphere.common
      ref: refs/pull/118/head
      resources: {}
      tenant: oss
      timeout: 1800
      topic: null
      voting: true
