blob: d17945f0e45a9e8c1718e4337e648ea515497a6c [file] [log] [blame]
David K. Bainbridge317e7d72016-05-11 08:31:44 -07001---
David K. Bainbridge8db2f302016-05-19 23:41:13 -07002- name: Verify Manditory Variables
3 fail: msg="Variable '{{ item }}' is not defined"
4 when: item not in hostvars[inventory_hostname]
5 with_items:
6 - fabric_ip
7 tags:
8 - interface_config
9
David K. Bainbridged4a63e02016-09-14 12:28:00 -070010- name: Verify Network Bits on Network Specifications
11 fail: msg="Network specification '{{ item }}' must include network bits"
12 when: "item != 'dhcp' and item != 'manual' and item | match('^([0-9]{1,3}.){3}[0-9]{1,3}$')"
13 with_items:
14 - "{{ compute_node.addresses.fabric }}"
15 - "{{ compute_node.addresses.management }}"
16 - "{{ compute_node.addresses.external }}"
17
David K. Bainbridge317e7d72016-05-11 08:31:44 -070018- name: Applications
19 become: yes
David K. Bainbridge17248c02016-08-29 17:04:34 -070020 apt: name={{ item }} state=present force=yes
David K. Bainbridge317e7d72016-05-11 08:31:44 -070021 with_items:
David K. Bainbridge8b179042016-11-30 15:38:42 -080022 - whois
David K. Bainbridge17248c02016-08-29 17:04:34 -070023 - build-essential=11.6*
24 - git=1:1.9.*
25 - python-pip=1.5.4*
26 - ifenslave-2.6=2.4*
27 - bridge-utils=1.5-*
28 - ethtool=1:3.13*
29 - minicom=2.7*
30 - curl=7.35.*
Andy Bavierd1ff9272016-09-08 17:11:54 -040031 - jq=1.3*
David K. Bainbridgee9f284d2016-05-18 14:13:43 -070032
David K. Bainbridge8b179042016-11-30 15:38:42 -080033- name: Validate Encyrpted Compute Node Password
34 set_fact:
35 already_encrypted: "{{compute_node.password.startswith('enc:')}}"
36
37# If the compute_node.password begins with 'enc:' then it is an
38# encyrpted password, which is what we need so we are done. Thus
39# if it is not encrypted then we have to encrypt it
40
41- name: Encyrpt Compute Node Password
42 command: "mkpasswd --method=sha-512 {{compute_node.password}}"
43 register: encrypted
44 changed_when: false
45 when: "not already_encrypted"
46
47- name: Update Compute Node Password
48 set_fact:
49 compute_node_update:
50 password: "enc:{{encrypted.stdout}}"
51 when: "not already_encrypted"
52
53- name: Merge Compute Node Properties
54 set_fact:
55 compute_node: "{{compute_node|combine(compute_node_update,recursive=True)}}"
56 when: "not already_encrypted"
57
David K. Bainbridge589a08f2016-06-15 18:14:18 -070058- name: Ensure Docker Insecure Repository
59 become: yes
60 lineinfile:
61 dest: /etc/default/docker
62 line: 'DOCKER_OPTS="$DOCKER_OPTS --insecure-registry docker-registry:5000"'
63 insertafter: '^DOCKER_OPTS'
64 register: docker_config
65
David K. Bainbridgefac79ca2016-07-28 10:00:44 -070066- name: Ensure Docker Registry Mirror
67 become: yes
68 lineinfile:
69 dest: /etc/default/docker
70 line: 'DOCKER_OPTS="$DOCKER_OPTS --registry-mirror=http://docker-registry:5001"'
71 insertafter: '^DOCKER_OPTS'
72 register: docker_config_mirror
73
David K. Bainbridge589a08f2016-06-15 18:14:18 -070074- name: Docker Restart
75 become: yes
76 service:
77 name=docker
78 state=restarted
David K. Bainbridgefac79ca2016-07-28 10:00:44 -070079 when: docker_config.changed or docker_config_mirror.changed
David K. Bainbridge589a08f2016-06-15 18:14:18 -070080
David K. Bainbridgee9f284d2016-05-18 14:13:43 -070081- name: Ensure Docker Ansible Support
82 become: yes
83 pip:
84 name=docker-py
David K. Bainbridge2dd2ddd2016-09-06 08:22:52 -070085 version=1.9
David K. Bainbridge317e7d72016-05-11 08:31:44 -070086
87- name: Set Default Password
88 become: yes
89 user:
Zack Williams4d09b3b2017-04-12 22:39:15 -070090 name: "{{ ansible_user_id }}"
David K. Bainbridge8b179042016-11-30 15:38:42 -080091 password: "{{compute_node.password.split(':',1)[1]}}"
Zack Williams4d09b3b2017-04-12 22:39:15 -070092 when: '"{{ ansible_user_id }}" == "ubuntu"'
David K. Bainbridge8b179042016-11-30 15:38:42 -080093 tags:
94 - set_compute_node_password
David K. Bainbridge317e7d72016-05-11 08:31:44 -070095
David K. Bainbridge39d0c782016-05-11 13:27:57 -070096- name: Authorize SSH Key
97 become: yes
98 authorized_key:
David K. Bainbridge8b179042016-11-30 15:38:42 -080099 key: "{{ pub_ssh_key }}"
Zack Williams4d09b3b2017-04-12 22:39:15 -0700100 user: "{{ ansible_user_id }}"
David K. Bainbridge8b179042016-11-30 15:38:42 -0800101 state: present
David K. Bainbridge39d0c782016-05-11 13:27:57 -0700102
103- name: Verify Private SSH Key
104 become: yes
105 stat:
Zack Williams4d09b3b2017-04-12 22:39:15 -0700106 path=/home/{{ ansible_user_id }}/.ssh/id_rsa
David K. Bainbridge39d0c782016-05-11 13:27:57 -0700107 register: private_key
108
David K. Bainbridge8b179042016-11-30 15:38:42 -0800109- name: Ensure SSH Key Pair
110 become: yes
111 copy:
112 src: "/etc/maas/.ssh/{{item.src}}"
113 dest: "{{ansible_env['PWD']}}/.ssh/{{item.dest}}"
Zack Williams4d09b3b2017-04-12 22:39:15 -0700114 owner: "{{ ansible_user_id }}"
David K. Bainbridge8b179042016-11-30 15:38:42 -0800115 group: "docker"
116 mode: "0600"
117 with_items:
118 - { "src": "cord_rsa", "dest": "id_rsa" }
119 - { "src": "cord_rsa.pub", "dest": "id_rsa.pub" }
120
121- name: Ensure SSH config
Andy Bavierceab2302016-07-07 09:04:07 -0400122 become: no
David K. Bainbridge39d0c782016-05-11 13:27:57 -0700123 copy:
David K. Bainbridge8b179042016-11-30 15:38:42 -0800124 src: "files/{{item}}"
125 dest: "{{ansible_env['PWD']}}/.ssh/{{item}}"
Zack Williams4d09b3b2017-04-12 22:39:15 -0700126 owner: "{{ ansible_user_id }}"
David K. Bainbridge8b179042016-11-30 15:38:42 -0800127 mode: "0600"
David K. Bainbridge39d0c782016-05-11 13:27:57 -0700128 with_items:
David K. Bainbridge81bda332016-06-14 22:58:41 -0700129 - config
David K. Bainbridge39d0c782016-05-11 13:27:57 -0700130
131- name: Ensure CORD SUDO
132 become: yes
133 copy:
134 src=files/99-cord-sudoers
135 dest=/etc/sudoers.d/99-cord-sudoers
136 owner=root
137 group=root
David K. Bainbridge8b179042016-11-30 15:38:42 -0800138 mode="0600"
David K. Bainbridge39d0c782016-05-11 13:27:57 -0700139
David K. Bainbridgef3071012016-08-04 09:29:55 -0700140- name: Ensure Utility Scripts
141 become: yes
142 copy:
143 src=files/{{ item }}
144 dest=/usr/local/bin/{{ item }}
145 owner=root
146 group=root
David K. Bainbridge8b179042016-11-30 15:38:42 -0800147 mode="0755"
David K. Bainbridgef3071012016-08-04 09:29:55 -0700148 with_items:
149 - delete-fabric-config
150 - delete-node-prov-state
151 - docker-ip
152 - fabric-pingall
153 - get-fabric-config
154 - get-node-prov-state
155 - remove-xos-components
David K. Bainbridgea677d4e2016-09-11 20:01:32 -0700156 - remove-maas-components
David K. Bainbridge1e4142d2016-08-04 10:01:58 -0700157 - post-fabric-config
David K. Bainbridgee80fd392016-08-19 15:46:19 -0700158 - pull-latest-docker-images
David K. Bainbridgef3071012016-08-04 09:29:55 -0700159
alshabibe16ef4c2016-05-27 17:13:23 -0700160- name: Verify Mellanox 40Gb NIC
161 shell: /usr/bin/lspci | grep "Ethernet controller" | grep -c ConnectX-3 || true
162 register: mlx_nic_present
David K. Bainbridge0820cab2016-06-02 17:43:32 -0700163 changed_when: False
alshabibe16ef4c2016-05-27 17:13:23 -0700164
165- name: Verify Intel 40Gb NIC
breezestarsd625aba2016-11-21 06:44:38 +0800166 shell: /usr/bin/lspci | grep "Ethernet controller" | grep -c -E "XL710 for 40GbE QSFP+|X710 for 10GbE SFP+" || true
alshabibe16ef4c2016-05-27 17:13:23 -0700167 register: intel_nic_present
David K. Bainbridge0820cab2016-06-02 17:43:32 -0700168 changed_when: False
alshabibe16ef4c2016-05-27 17:13:23 -0700169
David K. Bainbridge317e7d72016-05-11 08:31:44 -0700170- name: Verify i40e Driver
171 command: modinfo --field=version i40e
172 register: i40e_version
David K. Bainbridge10a8b982016-06-28 10:43:44 -0700173 when: intel_nic_present.stdout != "0"
David K. Bainbridge317e7d72016-05-11 08:31:44 -0700174 changed_when: False
David K. Bainbridgeb5415042016-05-13 17:06:10 -0700175 failed_when: False
David K. Bainbridge4ec841c2016-05-11 22:10:15 -0700176 tags:
177 - interface_config
David K. Bainbridge317e7d72016-05-11 08:31:44 -0700178
alshabibe16ef4c2016-05-27 17:13:23 -0700179- name: Verify mlx4 Driver
180 command: modinfo --field=version mlx4_core
181 register: mlx4_version
David K. Bainbridge10a8b982016-06-28 10:43:44 -0700182 when: mlx_nic_present.stdout != "0"
alshabibe16ef4c2016-05-27 17:13:23 -0700183 changed_when: False
184 failed_when: False
185 tags:
186 - interface_config
187
188- name: Update mlx4 Driver
David K. Bainbridge17248c02016-08-29 17:04:34 -0700189 include: mlx4_driver.yml
David K. Bainbridge10a8b982016-06-28 10:43:44 -0700190 when: mlx_nic_present.stdout != "0" and mlx4_version.stdout != '3.1-1.0.4'
alshabibe16ef4c2016-05-27 17:13:23 -0700191 tags:
192 - interface_config
193
David K. Bainbridge317e7d72016-05-11 08:31:44 -0700194- name: Update i40e Driver
David K. Bainbridge17248c02016-08-29 17:04:34 -0700195 include: i40e_driver.yml
David K. Bainbridge10a8b982016-06-28 10:43:44 -0700196 when: intel_nic_present.stdout != "0" and i40e_version.stdout != '1.4.25'
David K. Bainbridge4ec841c2016-05-11 22:10:15 -0700197 tags:
198 - interface_config
David K. Bainbridge317e7d72016-05-11 08:31:44 -0700199
alshabib54cdbb22016-06-03 16:37:01 -0700200- name: Load modules at boot
201 become: yes
202 lineinfile:
203 dest: /etc/modules
204 line: "{{ item }}"
205 with_items:
206 - lp
207 - loop
208 - rtc
209 - bonding
210
David K. Bainbridgea677d4e2016-09-11 20:01:32 -0700211- name: Ensure Network Configuration
David K. Bainbridge317e7d72016-05-11 08:31:44 -0700212 become: yes
David K. Bainbridgea677d4e2016-09-11 20:01:32 -0700213 include: networking.yml
David K. Bainbridge4ec841c2016-05-11 22:10:15 -0700214 tags:
215 - interface_config