From 4ac06057c9a77626bb181c22a5f1adc8014b13d2 Mon Sep 17 00:00:00 2001 From: Jason DeTiberus Date: Tue, 17 Feb 2015 22:33:33 -0500 Subject: create openshift_common role - move common openshift logic into openshift_common - set openshift_common as a dependency for openshift_node and openshift_master - rename role variables to openshift_* to be more descriptive - start recording local_facts on the openshift hosts - clean up firewalld config to be a bit more dry - Update firewall ports for https, make sure http rules are removed - Replace references to ansible_eth0.ipv4.address with ansible_default_ipv4.address --- roles/openshift_common/tasks/firewall.yml | 34 ++++++++++++++++++++++++++++++ roles/openshift_common/tasks/main.yml | 14 ++++++++++++ roles/openshift_common/tasks/set_facts.yml | 9 ++++++++ 3 files changed, 57 insertions(+) create mode 100644 roles/openshift_common/tasks/firewall.yml create mode 100644 roles/openshift_common/tasks/main.yml create mode 100644 roles/openshift_common/tasks/set_facts.yml (limited to 'roles/openshift_common/tasks') diff --git a/roles/openshift_common/tasks/firewall.yml b/roles/openshift_common/tasks/firewall.yml new file mode 100644 index 000000000..514466769 --- /dev/null +++ b/roles/openshift_common/tasks/firewall.yml @@ -0,0 +1,34 @@ +--- +# TODO: Ansible 1.9 will eliminate the need for separate firewalld tasks for +# enabling rules and making them permanent with the immediate flag +- name: "Add firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: false + state: enabled + with_items: allow + when: allow is defined + +- name: "Persist firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: true + state: enabled + with_items: allow + when: allow is defined + +- name: "Remove firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: false + state: disabled + with_items: deny + when: deny is defined + +- name: "Persist removal of firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: true + state: disabled + with_items: deny + when: deny is defined diff --git a/roles/openshift_common/tasks/main.yml b/roles/openshift_common/tasks/main.yml new file mode 100644 index 000000000..9043c3d8e --- /dev/null +++ b/roles/openshift_common/tasks/main.yml @@ -0,0 +1,14 @@ +--- +# fixme: Once openshift stops resolving hostnames for node queries remove this... +- name: Set hostname to IP Addr (WORKAROUND) + hostname: name={{ openshift_bind_ip }} + +- name: Configure local facts file + file: path=/etc/ansible/facts.d/ state=directory mode=0750 + +- name: Set common OpenShift facts + include: set_facts.yml + facts: + - { section: common, option: env, value: "{{ openshift_env | default('default') }}" } + - { section: common, option: host_type, value: "{{ openshift_host_type }}" } + - { section: common, option: debug_level, value: "{{ openshift_debug_level }}" } diff --git a/roles/openshift_common/tasks/set_facts.yml b/roles/openshift_common/tasks/set_facts.yml new file mode 100644 index 000000000..349eecd1d --- /dev/null +++ b/roles/openshift_common/tasks/set_facts.yml @@ -0,0 +1,9 @@ +--- +- name: "Setting local_facts" + ini_file: + dest: /etc/ansible/facts.d/openshift.fact + mode: 0640 + section: "{{ item.section }}" + option: "{{ item.option }}" + value: "{{ item.value }}" + with_items: facts -- cgit v1.2.3