mirror of
https://pagure.io/fedora-infra/ansible.git
synced 2026-02-02 20:59:02 +08:00
103 lines
2.6 KiB
YAML
103 lines
2.6 KiB
YAML
- import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml myhosts=ipsilon:ipsilon_stg"
|
|
|
|
|
|
- name: make the box be real
|
|
hosts: ipsilon:ipsilon_stg
|
|
user: root
|
|
gather_facts: True
|
|
|
|
vars_files:
|
|
- /srv/web/infra/ansible/vars/global.yml
|
|
- "/srv/private/ansible/vars.yml"
|
|
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
|
|
|
|
vars:
|
|
ipsilon_db_host: "db-fas01{{ env_suffix }}.iad2.fedoraproject.org"
|
|
|
|
roles:
|
|
- base
|
|
- rkhunter
|
|
- nagios_client
|
|
- hosts
|
|
- rsyncd
|
|
- sudo
|
|
- { role: openvpn/client,
|
|
when: env != "staging" }
|
|
- mod_wsgi
|
|
- role: keytab/service
|
|
owner_user: apache
|
|
owner_group: apache
|
|
service: HTTP
|
|
host: "id{{ env_suffix }}.fedoraproject.org"
|
|
|
|
pre_tasks:
|
|
- import_tasks: "{{ tasks_path }}/yumrepos.yml"
|
|
|
|
tasks:
|
|
- import_tasks: "{{ tasks_path }}/motd.yml"
|
|
|
|
handlers:
|
|
- import_tasks: "{{ handlers_path }}/restart_services.yml"
|
|
|
|
- name: deploy ipsilon itself
|
|
hosts: ipsilon:ipsilon_stg
|
|
user: root
|
|
gather_facts: True
|
|
|
|
vars_files:
|
|
- /srv/web/infra/ansible/vars/global.yml
|
|
- "/srv/private/ansible/vars.yml"
|
|
- "{{ vars_path }}/{{ ansible_distribution }}.yml"
|
|
|
|
vars:
|
|
ipsilon_db_host: "db-fas01{{ env_suffix }}.iad2.fedoraproject.org"
|
|
|
|
roles:
|
|
- ipsilon
|
|
|
|
handlers:
|
|
- import_tasks: "{{ handlers_path }}/restart_services.yml"
|
|
|
|
|
|
# This next block configures IPA, it only needs to be run on one member of the cluster.
|
|
# Run it after setting up Ipsilon because the host need to be declared in IPA already.
|
|
- name: setup IPA
|
|
hosts: ipa[0]:ipa_stg[0]
|
|
user: root
|
|
gather_facts: True
|
|
|
|
vars_files:
|
|
- /srv/web/infra/ansible/vars/global.yml
|
|
- "/srv/private/ansible/vars.yml"
|
|
- /srv/web/infra/ansible/vars/{{ ansible_distribution }}.yml
|
|
|
|
tasks:
|
|
- name: Add the ipsilon HBAC service in IPA
|
|
ipahbacsvc:
|
|
name: ipsilon
|
|
description: Ipsilon authentication service
|
|
ipaadmin_password: "{{ ipa_admin_password }}"
|
|
tags:
|
|
- ipsilon
|
|
|
|
- name: Allow login through ipsilon
|
|
ipahbacrule:
|
|
name: ipsilon
|
|
description: Login through ipsilon
|
|
hbacsvc:
|
|
- ipsilon
|
|
usercategory: all
|
|
host: "{{ (env == 'production')|ternary(groups['ipsilon'], groups['ipsilon_stg']) }}"
|
|
ipaadmin_password: "{{ ipa_admin_password }}"
|
|
tags:
|
|
- ipsilon
|
|
|
|
- name: Allow login through ipsilon for the CentOS instance
|
|
ipahbacrule:
|
|
name: ipsilon
|
|
action: member
|
|
host: "{{ (env == 'production')|ternary('ipsilon.iad2.centos.org', 'centos-ipa-client02.stg.iad2.fedoraproject.org') }}"
|
|
ipaadmin_password: "{{ ipa_admin_password }}"
|
|
tags:
|
|
- ipsilon
|