tripleo-ansible/tripleo_ansible/playbooks/cli-grant-local-access.yaml
Rabi Mishra 3fbbd47bdd Remove mistral user access to config-download work dir
The playbooks are run from tripleoclient and not wit mistral.

Change-Id: I1efa73ef2322b5aafefa840f1c79d60ebef0397a
2020-04-21 15:44:15 +05:30

48 lines
1.6 KiB
YAML

---
# Copyright 2020 Red Hat, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License"); you may
# not use this file except in compliance with the License. You may obtain
# a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
- name: Playbook for granting a given user local access
connection: "{{ (tripleo_target_host is defined) | ternary('ssh', 'local') }}"
hosts: "{{ tripleo_target_host | default('localhost') }}"
remote_user: "{{ tripleo_target_user | default(lookup('env', 'USER')) }}"
gather_facts: "{{ (tripleo_target_host is defined) | ternary(true, false) }}"
any_errors_fatal: true
become: true
pre_tasks:
- name: Check for required inputs
fail:
msg: >
Input missing `{{ item }}`
when:
- hostvars[inventory_hostname][item] is undefined
loop:
- access_path
- execution_user
tasks:
- name: Ensure access path exists
file:
path: "{{ access_path }}"
state: directory
- name: Grant privileges to the execution user
acl:
path: "{{ access_path }}"
entry: "user:{{ item }}:rwx"
state: present
recursive: true
loop:
- "{{ execution_user }}"
- tripleo-admin