Skip to content
Snippets Groups Projects
Commit 8b20f9d3 authored by Antoine SCHILDKNECHT's avatar Antoine SCHILDKNECHT
Browse files

Merge branch 't36656-certbot-hook' into 'main'

Remove useless nginx test in post-hook | refs #36656

See merge request sys/ansible-public!27
parents 110c87ff fbe17dcb
No related branches found
No related tags found
No related merge requests found
Showing
with 13 additions and 71 deletions
--- ---
dependencies: dependencies:
- role: conf - role: conf
- role: init - role: init
- role: sysconfig - role: sysconfig
...
--- ---
- name: install bench-worker packages - name: install bench-worker packages
ansible.builtin.apt: ansible.builtin.apt:
force_apt_get: true force_apt_get: true
...@@ -15,7 +14,7 @@ ...@@ -15,7 +14,7 @@
ansible.builtin.file: ansible.builtin.file:
path: /etc/mediaserver path: /etc/mediaserver
state: directory state: directory
mode: '755' mode: "755"
- name: benchmark configuration settings - name: benchmark configuration settings
ansible.builtin.copy: ansible.builtin.copy:
...@@ -30,7 +29,7 @@ ...@@ -30,7 +29,7 @@
"DL_STREAMS":{{ bench_dl_streams }}, "DL_STREAMS":{{ bench_dl_streams }},
"TIME_STATS":{{ bench_time_stat }} "TIME_STATS":{{ bench_time_stat }}
} }
mode: '644' mode: "644"
- name: reload systemd daemon - name: reload systemd daemon
ansible.builtin.systemd: ansible.builtin.systemd:
...@@ -40,5 +39,3 @@ ...@@ -40,5 +39,3 @@
ansible.builtin.systemd: ansible.builtin.systemd:
name: bench-worker name: bench-worker
state: restarted state: restarted
...
--- ---
celerity_signing_key: "{{ envsetup_celerity_signing_key | d('change-me', true) }}" celerity_signing_key: "{{ envsetup_celerity_signing_key | d('change-me', true) }}"
celerity_server: "{{ envsetup_celerity_server | d(envsetup_ms_server_name, true) | d('127.0.0.1', true) }}" celerity_server: "{{ envsetup_celerity_server | d(envsetup_ms_server_name, true) | d('127.0.0.1', true) }}"
...@@ -20,5 +19,3 @@ celerity_ferm_input_rules: ...@@ -20,5 +19,3 @@ celerity_ferm_input_rules:
- 6200 - 6200
celerity_ferm_output_rules: [] celerity_ferm_output_rules: []
celerity_ferm_global_settings: celerity_ferm_global_settings:
...
--- ---
- name: restart celerity-server - name: restart celerity-server
ansible.builtin.service: ansible.builtin.service:
name: celerity-server name: celerity-server
state: restarted state: restarted
...
--- ---
dependencies: dependencies:
- role: base - role: base
...
--- ---
- name: celerity server install - name: celerity server install
ansible.builtin.apt: ansible.builtin.apt:
force_apt_get: true force_apt_get: true
...@@ -14,7 +13,7 @@ ...@@ -14,7 +13,7 @@
ansible.builtin.template: ansible.builtin.template:
src: celerity-config.py.j2 src: celerity-config.py.j2
dest: /etc/celerity/config.py dest: /etc/celerity/config.py
mode: '644' mode: "644"
- name: ensure celerity server is running - name: ensure celerity server is running
ansible.builtin.service: ansible.builtin.service:
...@@ -36,5 +35,3 @@ ...@@ -36,5 +35,3 @@
- name: flush handlers - name: flush handlers
ansible.builtin.meta: flush_handlers ansible.builtin.meta: flush_handlers
...
--- ---
conf_req_packages: conf_req_packages:
- ca-certificates - ca-certificates
- openssh-client - openssh-client
...@@ -18,5 +17,3 @@ skyreach_system_key: "{{ lookup('env', 'SKYREACH_SYSTEM_KEY') }}" ...@@ -18,5 +17,3 @@ skyreach_system_key: "{{ lookup('env', 'SKYREACH_SYSTEM_KEY') }}"
conf_update: false conf_update: false
conf_debug: false conf_debug: false
...
--- ---
- name: proxy - name: proxy
when: when:
- proxy_http | d() - proxy_http | d()
...@@ -83,7 +82,7 @@ ...@@ -83,7 +82,7 @@
return_content: true return_content: true
validate_certs: "{{ conf_valid_cert }}" validate_certs: "{{ conf_valid_cert }}"
- name: save generated conf # noqa no-handler - name: save generated conf # noqa no-handler
loop: loop:
- "{{ conf_dl_ak }}" - "{{ conf_dl_ak }}"
- "{{ conf_dl_sk }}" - "{{ conf_dl_sk }}"
...@@ -93,7 +92,7 @@ ...@@ -93,7 +92,7 @@
dest: "{{ conf_dir }}/auto-generated-conf.sh" dest: "{{ conf_dir }}/auto-generated-conf.sh"
force: true force: true
backup: true backup: true
mode: '644' mode: "644"
- name: check if auto-generated-conf.sh exists - name: check if auto-generated-conf.sh exists
check_mode: false check_mode: false
...@@ -129,5 +128,3 @@ ...@@ -129,5 +128,3 @@
when: conf_debug when: conf_debug
ansible.builtin.debug: ansible.builtin.debug:
var: ansible_facts var: ansible_facts
...
...@@ -58,5 +58,3 @@ ...@@ -58,5 +58,3 @@
register: apt_status register: apt_status
retries: 60 retries: 60
until: apt_status is success or ('Failed to lock apt for exclusive operation' not in apt_status.msg and '/var/lib/dpkg/lock' not in apt_status.msg) until: apt_status is success or ('Failed to lock apt for exclusive operation' not in apt_status.msg and '/var/lib/dpkg/lock' not in apt_status.msg)
...
--- ---
kibana_default_port: 5601 kibana_default_port: 5601
kibana_server_host: localhost kibana_server_host: localhost
...
...@@ -8,5 +8,3 @@ ...@@ -8,5 +8,3 @@
ansible.builtin.service: ansible.builtin.service:
name: apm-server name: apm-server
state: restarted state: restarted
...
...@@ -13,7 +13,7 @@ ...@@ -13,7 +13,7 @@
ansible.builtin.template: ansible.builtin.template:
src: kibana.yml.j2 src: kibana.yml.j2
dest: /etc/kibana/kibana.yml dest: /etc/kibana/kibana.yml
mode: '644' mode: "644"
notify: restart kibana notify: restart kibana
- name: install apm-server package - name: install apm-server package
...@@ -30,7 +30,5 @@ ...@@ -30,7 +30,5 @@
ansible.builtin.template: ansible.builtin.template:
src: apm-server.yml.j2 src: apm-server.yml.j2
dest: /etc/apm-server/apm-server.yml dest: /etc/apm-server/apm-server.yml
mode: '644' mode: "644"
notify: restart apm-server notify: restart apm-server
...
--- ---
f2b_packages: f2b_packages:
- fail2ban - fail2ban
- rsyslog - rsyslog
...@@ -28,5 +27,3 @@ f2b_destemail_admins: > ...@@ -28,5 +27,3 @@ f2b_destemail_admins: >
{% endif %}" {% endif %}"
f2b_action: "{% if envsetup_fail2ban_send_email | default(false) %}action_mwl{% else %}action_{% endif %}" f2b_action: "{% if envsetup_fail2ban_send_email | default(false) %}action_mwl{% else %}action_{% endif %}"
...
--- ---
- name: restart fail2ban - name: restart fail2ban
ansible.builtin.systemd: ansible.builtin.systemd:
name: fail2ban name: fail2ban
state: restarted state: restarted
...
--- ---
- name: packages - name: packages
ansible.builtin.apt: ansible.builtin.apt:
force_apt_get: true force_apt_get: true
...@@ -15,12 +14,10 @@ ...@@ -15,12 +14,10 @@
ansible.builtin.template: ansible.builtin.template:
src: jail.local.j2 src: jail.local.j2
dest: /etc/fail2ban/jail.local dest: /etc/fail2ban/jail.local
mode: '644' mode: "644"
- name: service - name: service
ansible.builtin.systemd: ansible.builtin.systemd:
name: fail2ban name: fail2ban
enabled: true enabled: true
state: started state: started
...
--- ---
# filename into which rules will be written # filename into which rules will be written
# /etc/ferm/{ferm|input|output|forward}.d/<filename>.conf # /etc/ferm/{ferm|input|output|forward}.d/<filename>.conf
ferm_rules_filename: default ferm_rules_filename: default
# input rule # input rule
ferm_input_rules: [] ferm_input_rules: []
# ouput rule # ouput rule
ferm_output_rules: [] ferm_output_rules: []
# forward rule # forward rule
ferm_forward_rules: [] ferm_forward_rules: []
# global settings to be put in ferm.d directory # global settings to be put in ferm.d directory
ferm_global_settings: ferm_global_settings:
...
--- ---
- name: restart ferm - name: restart ferm
when: ansible_facts.services['ferm.service'] is defined when: ansible_facts.services['ferm.service'] is defined
ansible.builtin.systemd: ansible.builtin.systemd:
...@@ -11,4 +10,3 @@ ...@@ -11,4 +10,3 @@
ansible.builtin.systemd: ansible.builtin.systemd:
name: fail2ban name: fail2ban
state: started state: started
...
--- ---
- name: populate service facts - name: populate service facts
ansible.builtin.service_facts: ansible.builtin.service_facts:
- name: directories - name: directories
loop: loop:
- /etc/ferm/ferm.d - /etc/ferm/ferm.d
...@@ -12,7 +10,7 @@ ...@@ -12,7 +10,7 @@
ansible.builtin.file: ansible.builtin.file:
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
mode: '755' mode: "755"
- name: global - name: global
when: ferm_global_settings | d(false) when: ferm_global_settings | d(false)
...@@ -22,7 +20,7 @@ ...@@ -22,7 +20,7 @@
ansible.builtin.copy: ansible.builtin.copy:
dest: /etc/ferm/ferm.d/{{ ferm_rules_filename }}.conf dest: /etc/ferm/ferm.d/{{ ferm_rules_filename }}.conf
content: "{{ ferm_global_settings }}" content: "{{ ferm_global_settings }}"
mode: '644' mode: "644"
- name: input - name: input
when: ferm_input_rules | length > 0 when: ferm_input_rules | length > 0
...@@ -32,7 +30,7 @@ ...@@ -32,7 +30,7 @@
ansible.builtin.template: ansible.builtin.template:
src: ferm_rules_input.conf.j2 src: ferm_rules_input.conf.j2
dest: /etc/ferm/input.d/{{ ferm_rules_filename }}.conf dest: /etc/ferm/input.d/{{ ferm_rules_filename }}.conf
mode: '644' mode: "644"
- name: output - name: output
when: ferm_output_rules | length > 0 when: ferm_output_rules | length > 0
...@@ -42,7 +40,7 @@ ...@@ -42,7 +40,7 @@
ansible.builtin.template: ansible.builtin.template:
src: ferm_rules_output.conf.j2 src: ferm_rules_output.conf.j2
dest: /etc/ferm/output.d/{{ ferm_rules_filename }}.conf dest: /etc/ferm/output.d/{{ ferm_rules_filename }}.conf
mode: '644' mode: "644"
- name: forward - name: forward
when: ferm_forward_rules | length > 0 when: ferm_forward_rules | length > 0
...@@ -52,6 +50,4 @@ ...@@ -52,6 +50,4 @@
ansible.builtin.template: ansible.builtin.template:
src: ferm_rules_forward.conf.j2 src: ferm_rules_forward.conf.j2
dest: /etc/ferm/forward.d/{{ ferm_rules_filename }}.conf dest: /etc/ferm/forward.d/{{ ferm_rules_filename }}.conf
mode: '644' mode: "644"
...
--- ---
# packages to install # packages to install
ferm_packages: ferm_packages:
- ferm - ferm
...@@ -21,5 +20,3 @@ ferm_forward_log_prefix: "{{ ferm_forward_policy }} FORWARD " ...@@ -21,5 +20,3 @@ ferm_forward_log_prefix: "{{ ferm_forward_policy }} FORWARD "
# enable anti-lockout rule # enable anti-lockout rule
ferm_antilockout_enabled: true ferm_antilockout_enabled: true
...
--- ---
- name: restart ferm - name: restart ferm
ansible.builtin.systemd: ansible.builtin.systemd:
name: ferm name: ferm
state: restarted state: restarted
...
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment