Zack Williams | 0e58312 | 2016-04-30 16:57:03 -0700 | [diff] [blame] | 1 | --- |
| 2 | - hosts: nova-compute-1 |
| 3 | remote_user: ubuntu |
| 4 | become: yes |
| 5 | |
| 6 | tasks: |
| 7 | - name: Include configuration vars |
| 8 | include_vars: simulate-fabric-vars.yml |
| 9 | |
| 10 | - name: Install prerequisites |
| 11 | apt: |
| 12 | name={{ item }} |
| 13 | update_cache=yes |
| 14 | cache_valid_time=3600 |
| 15 | become: yes |
| 16 | with_items: |
| 17 | - bridge-utils |
| 18 | |
| 19 | - name: Create bridges |
Zack Williams | 5af9191 | 2016-05-01 06:34:16 -0700 | [diff] [blame] | 20 | when: "ansible_{{ item.name }} is not defined" |
Zack Williams | 0e58312 | 2016-04-30 16:57:03 -0700 | [diff] [blame] | 21 | command: brctl addbr "{{ item.name }}" |
| 22 | with_items: "{{ simfabric_bridges }}" |
| 23 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 24 | # note, not idempotent if failed between prior step and this step |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 25 | - name: Set IP addresses to bridges |
| 26 | when: "ansible_{{ item.0.name }} is not defined" |
| 27 | command: "ip addr add {{ item.1 }} dev {{ item.0.name }}" |
| 28 | with_subelements: |
| 29 | - "{{ simfabric_bridges }}" |
| 30 | - addresses |
| 31 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 32 | - name: Run setup again to obtain bridge info |
| 33 | setup: |
| 34 | |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 35 | - name: Start bridges |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 36 | when: "not ansible_{{ item.name }}.active" |
Zack Williams | b994a9e | 2016-05-01 22:21:06 -0700 | [diff] [blame] | 37 | command: "ip link set dev {{ item.name }} up" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 38 | with_items: "{{ simfabric_bridges }}" |
| 39 | |
| 40 | - name: Create ip links |
Andy Bavier | c233512 | 2016-06-25 09:59:22 -0400 | [diff] [blame] | 41 | when: "ansible_{{ item.dev }} is not defined" |
| 42 | command: "ip link add dev {{ item.dev }} address {{ item.mac }} type {{ item.type }} peer name {{ item.peer }}" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 43 | with_items: "{{ simfabric_links }}" |
| 44 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 45 | - name: Run setup again to obtain link info |
| 46 | setup: |
| 47 | |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 48 | - name: Start interfaces |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 49 | when: "not ansible_{{ item }}.active" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 50 | command: "ip link set dev {{ item }} up" |
Andy Bavier | c233512 | 2016-06-25 09:59:22 -0400 | [diff] [blame] | 51 | with_items: |
| 52 | - "{{ simfabric_links | map(attribute='dev') | list }}" |
| 53 | - "{{ simfabric_links | map(attribute='peer') | list }}" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 54 | |
| 55 | - name: Add interfaces to bridges |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 56 | when: "not item.1 in ansible_{{ item.0.name }}.interfaces" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 57 | command: "brctl addif {{ item.0.name }} {{ item.1 }}" |
| 58 | with_subelements: |
| 59 | - "{{ simfabric_bridges }}" |
| 60 | - interfaces |
| 61 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 62 | - name: Check for iptables rule |
Zack Williams | 61e17e5 | 2016-05-16 14:40:52 -0700 | [diff] [blame] | 63 | command: "iptables -t nat -C POSTROUTING -s 10.168.0.0/16 ! -d 10.168.0.0/16 -j MASQUERADE" |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 64 | register: iptables_check |
Zack Williams | 61e17e5 | 2016-05-16 14:40:52 -0700 | [diff] [blame] | 65 | failed_when: "iptables_check|failed and 'No chain/target/match by that name' not in iptables_check.stderr" |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 66 | |
| 67 | - name: Create iptables rule |
| 68 | when: "iptables_check.rc != 0" |
Zack Williams | 61e17e5 | 2016-05-16 14:40:52 -0700 | [diff] [blame] | 69 | command: "iptables -t nat -A POSTROUTING -s 10.168.0.0/16 ! -d 10.168.0.0/16 -j MASQUERADE" |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 70 | |
| 71 | # the below will likely work when this pull makes it into ansible: |
| 72 | # https://github.com/ansible/ansible-modules-extras/pull/1685 |
| 73 | # - name: Configure iptables |
| 74 | # iptables: "table={{ item.table }} chain={{ item.chain }} source={{ item.source }} destination={{ item.dest }} jump={{ item.jump }}" |
| 75 | # with_items: "{{ simfabric_iptables }}" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 76 | |
| 77 | - name: Set kernel sysctl values |
| 78 | sysctl: |
| 79 | name="{{ item.name }}" |
| 80 | value="{{ item.value }}" |
| 81 | sysctl_set=yes |
| 82 | state=present |
| 83 | reload=yes |
| 84 | with_items: "{{ simfabric_sysctl }}" |
| 85 | |