Files
openstack-ansible/playbooks/roles/rabbitmq_server/tasks/rabbitmq_ssl_key_distribute.yml
Hugh Saunders f665acc796 Remove dir_mode from rabbit key distribution
Setting dir_mode to 0750 prevents rabbit from reading /etc/rabbitmq as
the owner and group are root.

This patch removes the dir_mode paramter so that the memcahed module's
default of 0755 is used.

Closes-Bug #1506992

Change-Id: I3936a6bf181e3cf3f22b712d16d9181017f949cd
2015-10-23 13:18:55 +01:00

44 lines
1.4 KiB
YAML

---
# Copyright 2015, Rackspace US, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
- name: Distribute self signed ssl
memcached:
name: "{{ item.name }}"
file_path: "{{ item.src }}"
state: "retrieve"
file_mode: "{{ item.file_mode }}"
server: "{{ memcached_servers }}"
encrypt_string: "{{ memcached_encryption_key }}"
with_items:
- { src: "{{ rabbitmq_ssl_cert }}", name: "rabbitmq_ssl_cert", file_mode: "0640" }
- { src: "{{ rabbitmq_ssl_key }}", name: "rabbitmq_ssl_key", file_mode: "0640" }
register: memcache_keys
until: memcache_keys|success
retries: 5
delay: 2
tags:
- rabbitmq-ssl
- name: Ensure rabbitmq user owns the self-signed key and certificate
file:
path: "{{ item }}"
owner: rabbitmq
group: rabbitmq
with_items:
- "{{ rabbitmq_ssl_key }}"
- "{{ rabbitmq_ssl_cert }}"
tags:
- rabbitmq-ssl