Skip to content

Make admin secrets optional (bsc#1262409) - #769

Merged
mcalmer merged 1 commit into
uyuni-project:mainfrom
aaannz:fix_missing_secrets_on_upgrade
Apr 20, 2026
Merged

Make admin secrets optional (bsc#1262409)#769
mcalmer merged 1 commit into
uyuni-project:mainfrom
aaannz:fix_missing_secrets_on_upgrade

Conversation

@aaannz

@aaannz aaannz commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

What does this PR change?

Admin and some other secrets are used only during the installation. Make them optional so upgrade from non-5.2 installs works.

Codespace

Check if you already have a running container clicking on Running CodeSpace

Create CodeSpace About billing for Github Codespaces CodeSpace Billing Summary CodeSpace Limit

Test coverage

  • Unit tests were added

  • DONE

Links

Issue(s): #

  • DONE

Changelogs

Make sure the changelogs entries you are adding are compliant with https://github.com/uyuni-project/uyuni/wiki/Contributing#changelogs and https://github.com/uyuni-project/uyuni/wiki/Contributing#uyuni-projectuyuni-repository

If you don't need a changelog check, please mark this checkbox:

  • No changelog needed

If you uncheck the checkbox after the PR is created, you will need to re-run changelog_test (see below)

Before you merge

Check How to branch and merge properly!

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR makes certain Podman secrets (admin credentials and DB credentials) optional when generating the Uyuni server systemd unit, enabling upgrades from older installations that don’t have those secrets present.

Changes:

  • Make DB and report DB credential --secret arguments conditional in the systemd service template.
  • Only inject admin/DB/reportDB secret names into the template data when the corresponding secrets exist.
  • Add a unit test case covering template rendering when optional secrets are not provided.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
uyuni-tools.changes.oholecek.optional_admin_secret Adds a changelog entry for the upgrade behavior change.
mgradm/shared/templates/templates_test.go Adds a test covering service template output without optional secrets.
mgradm/shared/templates/serviceTemplate.go Makes DB/reportDB secrets conditional in the generated systemd unit.
mgradm/shared/podman/podman.go Populates template secret fields only when secrets exist to avoid upgrade failures.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread mgradm/shared/templates/serviceTemplate.go
Comment thread mgradm/shared/podman/podman.go
@admd
admd requested a review from cbosdo April 20, 2026 13:50
Admin user secret is needed only for first initialization. Make
them optional so upgrade works.
@aaannz
aaannz force-pushed the fix_missing_secrets_on_upgrade branch from c0d9c0e to db9862d Compare April 20, 2026 14:17
@aaannz aaannz changed the title Make admin secrets optional Make admin secrets optional (bsc#1262409) Apr 20, 2026
@sonarqubecloud

Copy link
Copy Markdown

@mcalmer
mcalmer merged commit d945f7c into uyuni-project:main Apr 20, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants