Files
fedora-infra_ansible/playbooks/openshift-apps/webhook2fedmsg.yml
Ryan Lerch 4a4e7e07cb [ansible-lint] prefix variable names for rabbit/user role
ansible-lint requires that variables for roles are prefixed with the
name of the role. This commit prefixes the variables for the
rabbit/user role with user_ as required by ansible-lint

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2024-12-03 10:48:45 +01:00

126 lines
3.6 KiB
YAML

#
# Webhook to Fedora Messaging
#
---
- name: Setup the database
hosts: db01.iad2.fedoraproject.org:db01.stg.iad2.fedoraproject.org
gather_facts: no
become: yes
become_user: postgres
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- /srv/private/ansible/vars.yml
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
tasks:
- name: Webhook2fedmsg DB user
community.postgresql.postgresql_user:
name: webhook2fedmsg
password: "{{ (env == 'production') | ternary(webhook2fedmsg_prod_db_password, webhook2fedmsg_stg_db_password) }}"
- name: Webhook2fedmsg database creation
community.postgresql.postgresql_db:
name: webhook2fedmsg
owner: webhook2fedmsg
encoding: UTF-8
- name: Make the app be real
hosts: os_control[0]:os_control_stg[0]
user: root
gather_facts: false
vars_files:
- /srv/web/infra/ansible/vars/global.yml
- "/srv/private/ansible/vars.yml"
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
roles:
- role: rabbit/user
user_username: "webhook2fedmsg{{ env_suffix }}"
user_sent_topics: ^org\.fedoraproject\.{{ env_short }}\.(github|discourse)\..*
- role: openshift/project
project_app: webhook2fedmsg
project_description: "Relay webhooks to Fedora Messaging"
project_appowners:
- ryanlerch
- abompard
- t0xic0der
- kevin
tags:
- apply-appowners
- role: openshift/secret-file
app: webhook2fedmsg
secret_name: fedora-messaging-ca
key: cacert.pem
privatefile: "rabbitmq/{{env}}/pki/ca.crt"
- role: openshift/secret-file
app: webhook2fedmsg
secret_name: fedora-messaging-crt
key: webhook2fedmsg-cert.pem
privatefile: "rabbitmq/{{env}}/pki/issued/webhook2fedmsg{{env_suffix}}.crt"
- role: openshift/secret-file
app: webhook2fedmsg
secret_name: fedora-messaging-key
key: webhook2fedmsg-key.pem
privatefile: "rabbitmq/{{env}}/pki/private/webhook2fedmsg{{env_suffix}}.key"
- role: openshift/imagestream
app: webhook2fedmsg
imagename: webhook2fedmsg
- role: openshift/object
object_app: webhook2fedmsg
object_template: buildconfig.yml
object_objectname: buildconfig.yml
- role: openshift/object
object_app: webhook2fedmsg
object_template: configmap.yml
object_objectname: configmap.yml
- role: openshift/object
object_app: webhook2fedmsg
object_file: service.yml
object_objectname: service.yml
# Routes
- role: openshift/route
route_app: webhook2fedmsg
route_routename: web
route_host: "webhook{{ env_suffix }}.fedoraproject.org"
route_serviceport: web
route_servicename: web
- role: openshift/route
route_app: webhook2fedmsg
route_routename: web-alt
route_host: "webhook2fedmsg.apps.ocp{{env_suffix}}.fedoraproject.org"
route_serviceport: web
route_servicename: web
# FASJSON access
- role: openshift/ipa-client
app: webhook2fedmsg
- role: openshift/keytab
app: webhook2fedmsg
key: service.keytab
secret_name: keytab
service: webhook2fedmsg
# Deployment config
- role: openshift/object
object_app: webhook2fedmsg
object_template: deploymentconfig.yml
object_objectname: deploymentconfig.yml
# - role: openshift/start-build
# app: webhook2fedmsg
# buildname: webhook2fedmsg
# tags:
# - never
# - build
# - role: openshift/rollout
# rollout_app: webhook2fedmsg
# rollout_dcname: webhook2fedmsg