openstack-ansible-os_keystone/tasks/keystone_key_distribute.yml
Jimmy McCrory 97428cb0a1 Avoid conflicting delegation with authorized_keys
When delegating with the authorized_key module, writes of multiple keys
against the same host's file can occur at the same time, leading to
missing keys.[0]

To avoid conflicting delegation between hosts, the registered
'keystone_pubkey' fact now contains a list of SSH keys of all hosts the
current batch of the play, rather than only the key of the current host.
The first host within each batch will handle distribution of that
batch's keys to all hosts within the play.

[0] https://github.com/ansible/ansible/issues/29693

Change-Id: I386e84eba46aa164db22618b7a6ac53b86eeeaf0
2018-03-13 18:59:07 -07:00

23 lines
867 B
YAML

---
# Copyright 2015, Rackspace US, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
- name: Create authorized keys file from host vars
authorized_key:
user: "{{ keystone_system_user_name }}"
key: "{{ keystone_pubkey | b64decode }}"
when: inventory_hostname == ansible_play_batch[0]
delegate_to: "{{ item }}"
with_items: "{{ ansible_play_hosts }}"