blob: ebeeb8ce89da53af95e1ca5ee0647bc640c4c911 [file] [log] [blame]
Andy Baviera17d84b2016-11-16 09:39:26 -08001---
2# file: create-lxd/tasks/main.yml
3- name: Ensure DIG
4 become: yes
5 apt:
6 name: dnsutils=1:9*
7 state: present
8
9- name: Enable trusty-backports
10 become: yes
11 apt_repository:
12 repo: "{{ item }}"
13 state: present
14 with_items:
15 - "deb http://us.archive.ubuntu.com/ubuntu/ trusty-backports main restricted universe"
16 - "deb-src http://us.archive.ubuntu.com/ubuntu/ trusty-backports main restricted universe"
17
18- name: Ensure LXD
19 become: yes
20 apt:
21 name: lxd
22 state: present
23 update_cache: yes
24 default_release: trusty-backports
25
26# For lookup() below
27- name: Fetch remote key
28 fetch:
29 src: .ssh/id_rsa.pub
30 dest: /tmp/id_rsa.pub
31 flat: yes
32
33- name: Create openstack LXD profile
34 become: yes
35 lxd_profile:
36 name: openstack
37 state: present
38 config:
39 user.user-data: |
40 #cloud-config
41 ssh_authorized_keys:
42 - "{{ lookup('file', '/tmp/id_rsa.pub') }}"
43 description: 'OpenStack services on CORD'
44 devices:
45 eth0:
46 nictype: bridged
47 parent: mgmtbr
48 type: nic
49
50- name: Create containers for the OpenStack services
51 become: yes
52 lxd_container:
53 name: "{{ item.name }}"
54 architecture: x86_64
55 state: started
56 source:
57 type: image
58 mode: pull
59 server: https://cloud-images.ubuntu.com/releases
60 protocol: simplestreams
61 alias: "{{ ansible_distribution_release }}"
62 profiles: ["openstack"]
63 wait_for_ipv4_addresses: true
64 timeout: 600
65 with_items: "{{ head_lxd_list }}"
66
67- name: fetch IP of DHCP harvester
68 when: on_maas
69 command: docker-ip harvester
70 register: harvester_ip
71 changed_when: False
72
73- name: force a harvest to get container name resolution
74 when: on_maas
75 uri:
76 url: http://{{ harvester_ip.stdout }}:8954/harvest
77 method: POST
78
79- name: wait for container name resolution
80 when: on_maas
81 host_dns_check:
82 hosts: "{{ head_lxd_list | map(attribute='name') | list | to_json }}"
83 command_on_fail: "curl -sS --connect-timeout 3 -XPOST http://{{ harvester_ip.stdout }}:8954/harvest"
84 register: all_resolved
85 until: all_resolved.everyone == "OK"
86 retries: 5
87 delay: 10
88 failed_when: all_resolved.everyone != "OK"
89
90- name: wait for containers to come up
91 wait_for:
92 host={{ item.name }}
93 port=22
94 with_items: "{{ head_lxd_list }}"
95
96- name: Create /etc/ansible/hosts file
97 become: yes
98 template:
99 src=ansible_hosts.j2
100 dest=/etc/ansible/hosts
101
102- name: Verify that we can log into every container
103 command: ansible containers -m ping -u ubuntu
104 tags:
105 - skip_ansible_lint # connectivity check
106
107- name: Have containers use the apt-cache
108 command: ansible containers -b -u ubuntu -m lineinfile -a "dest=/etc/apt/apt.conf.d/02apt-cacher-ng create=yes mode=0644 owner=root group=root regexp='^Acquire' line='Acquire::http { Proxy \"http://{{ apt_cacher_name }}:{{ apt_cacher_port | default('3142') }}\"; };'"
109 tags:
110 - skip_ansible_lint # running a sub job
111
112- name: Update apt cache
113 command: ansible containers -m apt -b -u ubuntu -a "update_cache=yes cache_valid_time=3600"
114 tags:
115 - skip_ansible_lint # running a sub job
116
117- name: Update software in all the containers
118 when: run_dist_upgrade
119 command: ansible containers -m apt -b -u ubuntu -a "upgrade=dist"
120 tags:
121 - skip_ansible_lint # running a sub job
122
123- name: Create containers' eth0 interface config file for DNS config via resolvconf program
124 when: not on_maas
125 template:
126 src=eth0.cfg.j2
127 dest={{ ansible_user_dir }}/eth0.cfg
128
129- name: Copy eth0 interface config file to all containers
130 when: not on_maas
131 command: ansible containers -b -u ubuntu -m copy -a "src={{ ansible_user_dir }}/eth0.cfg dest=/etc/network/interfaces.d/eth0.cfg owner=root group=root mode=0644"
132
133- name: Restart eth0 interface on all containers
134 when: not on_maas
135 command: ansible containers -b -u ubuntu -m shell -a "ifdown eth0 ; ifup eth0"
136
137- name: Verify that we can log into every container after restarting network interfaces
138 when: not on_maas
139 command: ansible containers -m ping -u ubuntu