create_users_keys.yml 5.89 KB
Newer Older
1
---
2
3
- name: set_fact keys_tmp - preserve backward compatibility after the introduction of the ceph_keys module
  set_fact:
4
    keys_tmp: "{{ keys_tmp|default([]) + [ { 'key': item.key, 'name': item.name, 'caps': { 'mon': item.mon_cap, 'osd': item.osd_cap|default(''), 'mds': item.mds_cap|default(''), 'mgr': item.mgr_cap|default('') } , 'mode': item.mode } ] }}"
5
6
7
8
9
10
11
12
13
14
  when:
    - item.get('mon_cap', None) # it's enough to assume we are running an old-fashionned syntax simply by checking the presence of mon_cap since every key needs this cap
  with_items: "{{ keys }}"

- name: set_fact keys - override keys_tmp with keys
  set_fact:
    keys: "{{ keys_tmp }}"
  when:
    - keys_tmp is defined

15
16
17
18
19
20
21
22
23
# dummy container setup is only supported on x86_64
# when running with containerized_deployment: true this task
# creates a group that contains only x86_64 hosts.
# when running with containerized_deployment: false this task
# will add all client hosts to the group (and not filter).
- name: create filtered clients group
  add_host:
    name: "{{ item }}"
    groups: _filtered_clients
24
25
  with_items: "{{ groups[client_group_name] | intersect(ansible_play_batch) }}"
  when: (hostvars[item]['ansible_architecture'] == 'x86_64') or (not containerized_deployment | bool)
26

27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
- name: set_fact delegated_node, condition_copy_admin_key, docker_exec_cmd
  set_fact:
    delegated_node: "{{ groups[mon_group_name][0] if groups.get(mon_group_name, []) | length > 0 else inventory_hostname }}"
    condition_copy_admin_key: "{{ True if groups.get(mon_group_name, []) | length > 0 else copy_admin_key }}"

- name: set_fact docker_exec_cmd
  set_fact:
    docker_exec_cmd: "docker exec {% if groups.get(mon_group_name, []) | length > 0 -%} ceph-mon-{{ hostvars[delegated_node]['ansible_hostname'] }} {% else %} ceph-create-keys {% endif %}"
  when:
    - containerized_deployment

- name: ensure the dummy container is not run already
  command: docker stop ceph-create-keys
  changed_when: false
  failed_when: false
  when:
    - containerized_deployment
    - inventory_hostname == groups.get('_filtered_clients') | first

- name: run a dummy container (sleep infinity) from where we can create pool(s)/key(s)
47
48
  command: >
    docker run \
49
    --rm \
50
    -d \
Sébastien Han's avatar
Sébastien Han committed
51
    -v {{ ceph_conf_key_directory }}:{{ ceph_conf_key_directory }}:z \
52
53
    --name ceph-create-keys \
    --entrypoint=sleep \
54
    {{ ceph_client_docker_registry}}/{{ ceph_client_docker_image }}:{{ ceph_client_docker_image_tag }} \
55
    infinity
56
  changed_when: false
57
58
  when:
    - containerized_deployment
59
    - inventory_hostname == groups.get('_filtered_clients') | first
60

61
62
63
64
65
66
- name: create cephx key(s)
  ceph_key:
    state: present
    name: "{{ item.name }}"
    caps: "{{ item.caps }}"
    secret: "{{ item.key | default('') }}"
67
    containerized: "{{ docker_exec_cmd | default('') }}"
68
69
    cluster: "{{ cluster }}"
    dest: "{{ ceph_conf_key_directory }}"
70
    import_key: "{{ condition_copy_admin_key }}"
71
    mode: "{{ item.mode|default(omit) }}"
72
  with_items: "{{ keys }}"
73
  delegate_to: "{{ delegated_node }}"
74
75
76
  when:
    - cephx
    - keys | length > 0
77
    - inventory_hostname == groups.get('_filtered_clients') | first
78

79
- name: slurp client cephx key(s)
80
81
82
83
84
  slurp:
    src: "{{ ceph_conf_key_directory }}/{{ cluster }}.{{ item.name }}.keyring"
  with_items:
    - "{{ keys }}"
  register: slurp_client_keys
85
  delegate_to: "{{ delegated_node }}"
86
87
88
  when:
    - cephx
    - keys | length > 0
89
    - inventory_hostname == groups.get('_filtered_clients') | first
90

Rishabh Dave's avatar
Rishabh Dave committed
91
- name: pool related tasks
92
  when:
Guillaume Abrioux's avatar
Guillaume Abrioux committed
93
    - condition_copy_admin_key
94
    - inventory_hostname == groups.get('_filtered_clients', []) | first
Rishabh Dave's avatar
Rishabh Dave committed
95
96
97
98
99
100
101
102
103
  block:
    - name: list existing pool(s)
      command: >
        {{ docker_exec_cmd | default('') }} ceph --cluster {{ cluster }}
        osd pool get {{ item.name }} size
      with_items: "{{ pools }}"
      register: created_pools
      failed_when: false
      delegate_to: "{{ delegated_node }}"
104

Rishabh Dave's avatar
Rishabh Dave committed
105
106
107
108
    - name: create ceph pool(s)
      command: >
        {{ docker_exec_cmd | default('') }} ceph --cluster {{ cluster }}
        osd pool create {{ item.0.name }}
109
110
111
        {{ item.0.pg_num | default(osd_pool_default_pg_num) }}
        {{ item.0.pgp_num | default(item.0.pg_num) | default(osd_pool_default_pg_num) }}
        {{ 'replicated_rule' if not item.0.rule_name | default('replicated_rule') else item.0.rule_name | default('replicated_rule') }}
Rishabh Dave's avatar
Rishabh Dave committed
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
        {{ 1 if item.0.type|default(1) == 'replicated' else 3 if item.0.type|default(1) == 'erasure' else item.0.type|default(1) }}
        {%- if (item.0.type | default("1") == '3' or item.0.type | default("1") == 'erasure') and item.0.erasure_profile != '' %}
        {{ item.0.erasure_profile }}
        {%- endif %}
        {{ item.0.expected_num_objects | default('') }}
      with_together:
        - "{{ pools }}"
        - "{{ created_pools.results }}"
      changed_when: false
      delegate_to: "{{ delegated_node }}"
      when:
        - pools | length > 0
        - item.1.rc != 0

    - name: customize pool size
      command: >
        {{ docker_exec_cmd | default('') }} ceph --cluster {{ cluster }}
129
        osd pool set {{ item.name }} size {{ item.size | default(osd_pool_default_size) }}
Rishabh Dave's avatar
Rishabh Dave committed
130
      with_items: "{{ pools | unique }}"
131
      delegate_to: "{{ delegated_node }}"
Rishabh Dave's avatar
Rishabh Dave committed
132
133
134
      changed_when: false
      when:
        - pools | length > 0
135
        - item.size | default(osd_pool_default_size) != ceph_osd_pool_default_size
136

137
- name: get client cephx keys
138
  copy:
139
    dest: "{{ item.source }}"
140
    content: "{{ item.content | b64decode }}"
141
    mode: "{{ item.item.get('mode', '0600') }}"
142
143
    owner: "{{ ceph_uid }}"
    group: "{{ ceph_uid }}"
144
  with_items:
145
    - "{{ hostvars[groups['_filtered_clients'][0]]['slurp_client_keys']['results'] }}"
146
147
  when:
    - not item.get('skipped', False)
148
149
150
151
152
153
154
155

- name: stop the dummy container
  command: docker stop ceph-create-keys
  changed_when: false
  failed_when: false
  when:
    - containerized_deployment
    - inventory_hostname == groups.get('_filtered_clients') | first