On Fri, August 24, 2018 6:34 am, Oleg Artemiev wrote:
> Hello, list.
>
>
> Sorry if this has been already discussed - didn't read the mailing list
> long time. I've found myself in need to change templates once again as
> templates for too old fedora are not even updating at my side and it
> appears I've time to learn Qubes devops.
>
> Since Qubes OS site seem to have no direct link to search dox I used to
> yandex 'qubes os automation' and found this link:
>
>
https://github.com/Rudd-O/ansible-qubes
>
>
> As I understood this project is not from Qubes team and seem to be
> absent in official documentation. Has this any security reason? It could be
> helpful for those who already know some ansible (as I do).
Correct, it's not official but Rudd-O has been around for a while and
active in the mailing lists. If you search them too for ansible-qubes, you
should find some related posts.
> Though some of possible management use cases seem to break Qubes way of
> doing things securely (especially Qubes VM -> Qubes dom0): ---quote---
>
>
> - Qubes VM -> Qubes VM
> - Qubes VM -> Qubes dom0 (see below for enablement instructions)
> - Qubes dom0 -> Qubes VM
> - Qubes VM -> network (SSH) -> Qubes VM on another Qubes host (see below)
> - normal desktop Linux -> network (SSH) -> Qubes VM on another Qubes host
>
>
> ---quote---
>
>
> Also this project claimed to be specific for Qubes 3 (that's not a
> problem for me since I prefer to use old but quite stable releases),
> though an issue related to Qubes 4.0-rc2 .
Qubes 4 uses different means of automation (Salt). I haven't played with
it much. I think 3.2 will go to EOL mode in a few months, so you might not
want to invest a lot of time figuring out ansible automation for it and
instead focus on 4.0?
Don't know about gpg2 vs 1.4.