| --- |
| - hosts: {{ sliver_name }} |
| gather_facts: False |
| connection: ssh |
| user: ubuntu |
| sudo: yes |
| vars: |
| cdn_enable: {{ cdn_enable }} |
| dnsdemux_ip: {{ dnsdemux_ip }} |
| firewall_enable: {{ firewall_enable }} |
| url_filter_enable: {{ url_filter_enable }} |
| vlan_ids: |
| {% for vlan_id in vlan_ids %} |
| - {{ vlan_id }} |
| {% endfor %} |
| firewall_rules: |
| {% for firewall_rule in firewall_rules.split("\n") %} |
| - {{ firewall_rule }} |
| {% endfor %} |
| cdn_prefixes: |
| {% for prefix in cdn_prefixes %} |
| - {{ prefix }} |
| {% endfor %} |
| bbs_addrs: |
| {% for bbs_addr in bbs_addrs %} |
| - {{ bbs_addr }} |
| {% endfor %} |
| nat_ip: {{ nat_ip }} |
| lan_ip: {{ lan_ip }} |
| wan_ip: {{ wan_ip }} |
| private_ip: {{ private_ip }} |
| hpc_client_ip: {{ hpc_client_ip }} |
| wan_mac: {{ wan_mac }} |
| |
| tasks: |
| {% if full_setup %} |
| - name: Docker repository |
| copy: src=/opt/xos/observers/vcpe/files/docker.list |
| dest=/etc/apt/sources.list.d/docker.list |
| |
| - name: Import the repository key |
| apt_key: keyserver=keyserver.ubuntu.com id=36A1D7869245C8950F966E92D8576A8BA88D21E9 |
| |
| - name: install Docker |
| apt: name=lxc-docker-1.5.0 state=present update_cache=yes |
| |
| - name: install python-setuptools |
| apt: name=python-setuptools state=present |
| |
| - name: install pip |
| easy_install: name=pip |
| |
| - name: install docker-py |
| pip: name=docker-py version=0.5.3 |
| |
| - name: install Pipework |
| get_url: url=https://raw.githubusercontent.com/jpetazzo/pipework/master/pipework |
| dest=/usr/local/bin/pipework |
| mode=0755 |
| |
| - name: make sure /etc/dnsmasq.d exists |
| file: path=/etc/dnsmasq.d state=directory owner=root group=root |
| |
| - name: Disable resolvconf updates (to avoid overwriting /etc/resolv.conf on host) |
| shell: service resolvconf disable-updates |
| |
| - name: vCPE upstart |
| copy: src=/opt/xos/observers/vcpe/files/vcpe.conf dest=/etc/init/vcpe.conf |
| {% endif %} |
| |
| - name: vCPE startup script |
| template: src=/opt/xos/observers/vcpe/templates/start-vcpe.sh.j2 dest=/usr/local/sbin/start-vcpe.sh mode=0755 |
| notify: |
| - restart vcpe |
| |
| - name: vCPE basic dnsmasq config |
| copy: src=/opt/xos/observers/vcpe/files/vcpe.dnsmasq dest=/etc/dnsmasq.d/vcpe.conf owner=root group=root |
| notify: |
| - stop dnsmasq |
| - start dnsmasq |
| |
| - name: dnsmasq config |
| template: src=/opt/xos/observers/vcpe/templates/dnsmasq_servers.j2 dest=/etc/dnsmasq.d/servers.conf owner=root group=root |
| notify: |
| - stop dnsmasq |
| - start dnsmasq |
| |
| # These are samples, not necessary for correct function of demo |
| |
| # - name: networking info |
| # template: src=/opt/xos/observers/vcpe/templates/vlan_sample.j2 dest=/etc/vlan_sample owner=root group=root |
| |
| # - name: firewall info |
| # template: src=/opt/xos/observers/vcpe/templates/firewall_sample.j2 dest=/etc/firewall_sample owner=root group=root |
| |
| - name: Make sure vCPE service is running |
| service: name=vcpe state=started |
| |
| handlers: |
| - name: stop dnsmasq |
| shell: docker exec vcpe /usr/bin/killall dnsmasq |
| |
| - name: start dnsmasq |
| shell: docker exec vcpe /usr/sbin/service dnsmasq start |
| |
| - name: restart vcpe |
| shell: service vcpe stop; sleep 1; service vcpe start |