Redhat.rhel_system_roles

Is anyone importing and or using the redhat.rhel_system_roles.ad_integration or fedora.linux_system_roles.ad_integration ?

I am trying to use this to automate our linux servers to authenticate to Active Directory (wasn’t my choice). I would say that 80% of my servers are RHEL 8 and the rest are RHEL 9 or something earlier that RHEL 8. I’m focusing on RHEL =>8. I THINK it might be related with my EE which is built on RHEL 8 using python 3.11 but also has python 3.9 installed to account for RHEL 8. So when I go to run the role in AAP, it ALWAYS fails at the following:

TASK [fedora.linux_system_roles.ad_integration : Build Command - Join to a specific Domain Controller] ***

task path: /runner/requirements_collections/ansible_collections/fedora/linux_system_roles/roles/ad_integration/tasks/main.yml:193

fatal: [$HOSTNAME]: FAILED! => {"censored": "the output has been hidden due to the fact that 'no_log: true' was specified for this result"}

We use the fedora.linux_system_roles.ad_integration flavor, and it works. Without knowing more about your environment or deeper context into what you’ve already tried, here is what I’d recommend.

  1. Check which version of ansible-core is actually declared/installed in your EE; v2.16 is the last to support RHEL 8, IIRC. Since your EE is built on RHEL 8, you’re probably fine, but it’s worth verifying. We build our EE on CentOS 10, but limit the ansible-core version to <2.17 for that reason.

  2. The ad_integration role has a default variable to keep logging secure. Take the appropriate measures (password rotation after, run the role locally without external logging, etc), and temporarily disable the secure logging flag. That will get you some more context as to why that task is failing. ad_integration/tasks/main.yml at 72fa163f24f24caf42a1b03cb6cd7e40ef479450 · linux-system-roles/ad_integration · GitHub

For reference, here are the only vars we are overriding and setting in our environment to make it functional. Some of these are optional, but maybe one is required and you missed it. The password is vaulted, so we also pass the vault credential in AWX at the same time.

ad_integration_realm
ad_integration_user
ad_integration_password
ad_integration_auto_id_mapping
ad_integration_computer_ou
ad_integration_sssd_settings
ad_integration_sssd_custom_settings