82d0705476
This change imports all of the octavia playbooks and roles from `tripleo-common/playbooks/`. This change ensures all of the resources imported are meeting the required lint checks for import and structures the roles such that they'll automatically be installed in the `usr/share/ansible/roles/` path making them available to the rest of the tripleo ecosystem. Change-Id: Ib4ff59a4c372f95cc7a183e8ef724bb1cbf72fed Signed-off-by: Kevin Carter <kecarter@redhat.com>
76 lines
2.2 KiB
YAML
76 lines
2.2 KiB
YAML
---
|
|
- hosts: keystone
|
|
tasks:
|
|
- name: Check for containerized keystone fernet repository
|
|
stat:
|
|
path: /var/lib/config-data/puppet-generated/keystone/etc/keystone/fernet-keys/
|
|
register: containerized_keystone_dir
|
|
|
|
- name: populate service facts
|
|
service_facts:
|
|
|
|
- name: Set container facts
|
|
set_fact:
|
|
is_container: containerized_keystone_dir.stat.isdir is defined and containerized_keystone_dir.stat.isdir
|
|
podman_enabled: '"tripleo_keystone.service" in ansible_facts.services'
|
|
|
|
- name: Rotate fernet keys for keystone container
|
|
block:
|
|
- name: Set keystone facts
|
|
set_fact:
|
|
keystone_base: /var/lib/config-data/puppet-generated/keystone
|
|
|
|
- name: Remove previous fernet keys
|
|
shell: rm -rf /var/lib/config-data/puppet-generated/keystone/etc/keystone/fernet-keys/*
|
|
args:
|
|
warn: false
|
|
|
|
- name: Persist fernet keys to repository
|
|
copy:
|
|
dest: "{{ keystone_base }}{{ item.key }}"
|
|
content: "{{ item.value.content }}"
|
|
mode: 0600
|
|
with_dict: "{{ fernet_keys }}"
|
|
no_log: true
|
|
|
|
- name: Set permissions to match container's user
|
|
shell: chown --reference={{ keystone_base }}/etc/keystone/fernet-keys {{ keystone_base }}{{ item.key }}
|
|
with_dict: "{{ fernet_keys }}"
|
|
no_log: true
|
|
|
|
- name: Restart keystone container with docker
|
|
shell: docker restart keystone
|
|
when: not podman_enabled
|
|
|
|
- name: Restart keystone container
|
|
service:
|
|
name: tripleo_keystone
|
|
state: restarted
|
|
when: podman_enabled
|
|
when:
|
|
- is_container | bool
|
|
|
|
- name: Rotate fernet keys for keystone (no container)
|
|
block:
|
|
- name: Remove previous fernet keys
|
|
shell: rm -rf /etc/keystone/fernet-keys/*
|
|
args:
|
|
warn: false
|
|
|
|
- name: Persist fernet keys to repository
|
|
copy:
|
|
dest: "{{ item.key }}"
|
|
content: "{{ item.value.content }}"
|
|
mode: 0600
|
|
owner: keystone
|
|
group: keystone
|
|
with_dict: "{{ fernet_keys }}"
|
|
no_log: true
|
|
|
|
- name: Reload apache
|
|
service:
|
|
name: httpd
|
|
state: reloaded
|
|
when:
|
|
- not (is_container | bool)
|