OVHcloud CLI, Checked Against OVHcloud's Checksums
ovhcloud on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in OVHcloud's checksum file, and re-checked with sha256sum -c by the live test. No package exists; most installs curl the tarball and never open the checksum file. Pinned; an API call without a login stops at 'ovhcloud login'. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-19 · podman 4.9.3 · ansible 2.21.4 · how we verify
Documentation
ovhcloud-cli
The OVHcloud CLI (ovhcloud) on EL 10 from the vendor's GitHub release,
checked against the SHA-256 the vendor published beside it, pinned to a
version, installed as root's binary in /usr/local/bin. Original role for
EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
ovhcloud; OVHcloud ships versioned releases on GitHub with a checksum
file (ovhcloud-cli_0.15.0_checksums.txt) beside the assets. Most installs curl the
asset and never open that file. This role downloads both and has
Ansible's get_url refuse the asset unless its SHA-256 is the one in the
vendor's file; the live test runs sha256sum -c against the same file
afterwards. A download is verified against what OVHcloud published, not
against what happened to arrive.
Pinned. ovhcloud_cli_version is what gets installed, kept in a directory
of its own (/usr/local/src/ovhcloud-<version>) so the checksum file and
the asset it names stay together. A newer release is a variable change
and a run; the same version is changed=0.
Proven to run. The live test calls ovhcloud vps list with no
credentials and expects the CLI to get to "ovhcloud login" - the
binary, its OVHcloud client and its configuration lookup all ran;
only the credentials were missing.
The asset name carries no version. OVHcloud names the tarball
ovhcloud-cli_Linux_x86_64.tar.gz for every release, so only the release
URL and the versioned checksum file say which build it is; the role keeps
each version in its own directory for that reason.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test