Zack Williams | 0e58312 | 2016-04-30 16:57:03 -0700 | [diff] [blame] | 1 | --- |
| 2 | - hosts: nova-compute-1 |
| 3 | remote_user: ubuntu |
| 4 | become: yes |
| 5 | |
| 6 | tasks: |
| 7 | - name: Include configuration vars |
| 8 | include_vars: simulate-fabric-vars.yml |
| 9 | |
| 10 | - name: Install prerequisites |
| 11 | apt: |
| 12 | name={{ item }} |
| 13 | update_cache=yes |
| 14 | cache_valid_time=3600 |
| 15 | become: yes |
Andy Bavier | 66ee901 | 2016-07-20 17:25:51 -0400 | [diff] [blame] | 16 | register: result |
| 17 | until: result | success |
| 18 | retries: 15 |
| 19 | delay: 60 |
Zack Williams | 0e58312 | 2016-04-30 16:57:03 -0700 | [diff] [blame] | 20 | with_items: |
| 21 | - bridge-utils |
| 22 | |
| 23 | - name: Create bridges |
Zack Williams | 5af9191 | 2016-05-01 06:34:16 -0700 | [diff] [blame] | 24 | when: "ansible_{{ item.name }} is not defined" |
Zack Williams | 0e58312 | 2016-04-30 16:57:03 -0700 | [diff] [blame] | 25 | command: brctl addbr "{{ item.name }}" |
| 26 | with_items: "{{ simfabric_bridges }}" |
| 27 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 28 | # note, not idempotent if failed between prior step and this step |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 29 | - name: Set IP addresses to bridges |
| 30 | when: "ansible_{{ item.0.name }} is not defined" |
| 31 | command: "ip addr add {{ item.1 }} dev {{ item.0.name }}" |
| 32 | with_subelements: |
| 33 | - "{{ simfabric_bridges }}" |
| 34 | - addresses |
| 35 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 36 | - name: Run setup again to obtain bridge info |
| 37 | setup: |
| 38 | |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 39 | - name: Start bridges |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 40 | when: "not ansible_{{ item.name }}.active" |
Zack Williams | b994a9e | 2016-05-01 22:21:06 -0700 | [diff] [blame] | 41 | command: "ip link set dev {{ item.name }} up" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 42 | with_items: "{{ simfabric_bridges }}" |
| 43 | |
| 44 | - name: Create ip links |
Andy Bavier | c233512 | 2016-06-25 09:59:22 -0400 | [diff] [blame] | 45 | when: "ansible_{{ item.dev }} is not defined" |
| 46 | command: "ip link add dev {{ item.dev }} address {{ item.mac }} type {{ item.type }} peer name {{ item.peer }}" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 47 | with_items: "{{ simfabric_links }}" |
| 48 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 49 | - name: Run setup again to obtain link info |
| 50 | setup: |
| 51 | |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 52 | - name: Start interfaces |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 53 | when: "not ansible_{{ item }}.active" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 54 | command: "ip link set dev {{ item }} up" |
Andy Bavier | c233512 | 2016-06-25 09:59:22 -0400 | [diff] [blame] | 55 | with_items: |
| 56 | - "{{ simfabric_links | map(attribute='dev') | list }}" |
| 57 | - "{{ simfabric_links | map(attribute='peer') | list }}" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 58 | |
| 59 | - name: Add interfaces to bridges |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 60 | when: "not item.1 in ansible_{{ item.0.name }}.interfaces" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 61 | command: "brctl addif {{ item.0.name }} {{ item.1 }}" |
| 62 | with_subelements: |
| 63 | - "{{ simfabric_bridges }}" |
| 64 | - interfaces |
| 65 | |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 66 | - name: Check for iptables rule |
Zack Williams | 61e17e5 | 2016-05-16 14:40:52 -0700 | [diff] [blame] | 67 | command: "iptables -t nat -C POSTROUTING -s 10.168.0.0/16 ! -d 10.168.0.0/16 -j MASQUERADE" |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 68 | register: iptables_check |
Zack Williams | 61e17e5 | 2016-05-16 14:40:52 -0700 | [diff] [blame] | 69 | failed_when: "iptables_check|failed and 'No chain/target/match by that name' not in iptables_check.stderr" |
Zack Williams | 3562456 | 2016-08-28 17:12:26 -0700 | [diff] [blame] | 70 | tags: |
| 71 | - skip_ansible_lint # FIXME: should use iptables module when it supports inversion of ranges |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 72 | |
| 73 | - name: Create iptables rule |
| 74 | when: "iptables_check.rc != 0" |
Zack Williams | 61e17e5 | 2016-05-16 14:40:52 -0700 | [diff] [blame] | 75 | command: "iptables -t nat -A POSTROUTING -s 10.168.0.0/16 ! -d 10.168.0.0/16 -j MASQUERADE" |
Zack Williams | 4a9b1ad | 2016-05-16 14:24:06 -0700 | [diff] [blame] | 76 | |
| 77 | # the below will likely work when this pull makes it into ansible: |
| 78 | # https://github.com/ansible/ansible-modules-extras/pull/1685 |
| 79 | # - name: Configure iptables |
| 80 | # iptables: "table={{ item.table }} chain={{ item.chain }} source={{ item.source }} destination={{ item.dest }} jump={{ item.jump }}" |
| 81 | # with_items: "{{ simfabric_iptables }}" |
Zack Williams | c11aea5 | 2016-05-01 21:34:37 -0700 | [diff] [blame] | 82 | |
| 83 | - name: Set kernel sysctl values |
| 84 | sysctl: |
| 85 | name="{{ item.name }}" |
| 86 | value="{{ item.value }}" |
| 87 | sysctl_set=yes |
| 88 | state=present |
| 89 | reload=yes |
| 90 | with_items: "{{ simfabric_sysctl }}" |
| 91 | |