diff options
| author | Tim Bielawa <tbielawa@redhat.com> | 2017-09-15 17:18:22 -0400 | 
|---|---|---|
| committer | Tim Bielawa <tbielawa@redhat.com> | 2017-10-04 10:48:30 -0400 | 
| commit | 8e10c53974b4b87e483ed0dfec3946383aa071c7 (patch) | |
| tree | 9d1cf76f6e563f9b47fd4f6c6b8bfaa0316ca884 /roles/openshift_nfs/tasks | |
| parent | 42d330a1cf2990fee39dab36250524ebfb303428 (diff) | |
| download | openshift-8e10c53974b4b87e483ed0dfec3946383aa071c7.tar.gz openshift-8e10c53974b4b87e483ed0dfec3946383aa071c7.tar.bz2 openshift-8e10c53974b4b87e483ed0dfec3946383aa071c7.tar.xz openshift-8e10c53974b4b87e483ed0dfec3946383aa071c7.zip | |
Import upstream templates. Do the work. Validate parameters.
Diffstat (limited to 'roles/openshift_nfs/tasks')
| -rw-r--r-- | roles/openshift_nfs/tasks/create_export.yml | 34 | ||||
| -rw-r--r-- | roles/openshift_nfs/tasks/firewall.yml | 40 | ||||
| -rw-r--r-- | roles/openshift_nfs/tasks/setup.yml | 29 | 
3 files changed, 103 insertions, 0 deletions
| diff --git a/roles/openshift_nfs/tasks/create_export.yml b/roles/openshift_nfs/tasks/create_export.yml new file mode 100644 index 000000000..39323904f --- /dev/null +++ b/roles/openshift_nfs/tasks/create_export.yml @@ -0,0 +1,34 @@ +--- +# Makes a new NFS export +# +# Include signature +# +# include_role: +#   role: openshift_nfs +#   tasks_from: create_export +# vars: +#   l_nfs_base_dir: Base dir to exports +#   l_nfs_export_config: Name to prefix the .exports file with +#   l_nfs_export_name: Name of sub-directory of the export +#   l_nfs_options: Mount Options + +- name: Ensure CFME App NFS export directory exists +  file: +    path: "{{ l_nfs_base_dir }}/{{ l_nfs_export_name }}" +    state: directory +    mode: 0777 +    owner: nfsnobody +    group: nfsnobody + +- name: "Create {{ l_nfs_export_name }} NFS export" +  lineinfile: +    path: "/etc/exports.d/{{ l_nfs_export_config }}.exports" +    create: true +    state: present +    line: "{{ l_nfs_base_dir }}/{{ l_nfs_export_name }} {{ l_nfs_options }}" +  register: created_export + +- name: Re-export NFS filesystems +  command: exportfs -ar +  when: +    - created_export | changed diff --git a/roles/openshift_nfs/tasks/firewall.yml b/roles/openshift_nfs/tasks/firewall.yml new file mode 100644 index 000000000..0898b2b5c --- /dev/null +++ b/roles/openshift_nfs/tasks/firewall.yml @@ -0,0 +1,40 @@ +--- +- when: r_openshift_nfs_firewall_enabled | bool and not r_openshift_nfs_use_firewalld | bool +  block: +  - name: Add iptables allow rules +    os_firewall_manage_iptables: +      name: "{{ item.service }}" +      action: add +      protocol: "{{ item.port.split('/')[1] }}" +      port: "{{ item.port.split('/')[0] }}" +    when: item.cond | default(True) +    with_items: "{{ r_openshift_nfs_firewall_allow }}" + +  - name: Remove iptables rules +    os_firewall_manage_iptables: +      name: "{{ item.service }}" +      action: remove +      protocol: "{{ item.port.split('/')[1] }}" +      port: "{{ item.port.split('/')[0] }}" +    when: item.cond | default(True) +    with_items: "{{ r_openshift_nfs_os_firewall_deny }}" + +- when: r_openshift_nfs_firewall_enabled | bool and r_openshift_nfs_use_firewalld | bool +  block: +  - name: Add firewalld allow rules +    firewalld: +      port: "{{ item.port }}" +      permanent: true +      immediate: true +      state: enabled +    when: item.cond | default(True) +    with_items: "{{ r_openshift_nfs_firewall_allow }}" + +  - name: Remove firewalld allow rules +    firewalld: +      port: "{{ item.port }}" +      permanent: true +      immediate: true +      state: disabled +    when: item.cond | default(True) +    with_items: "{{ r_openshift_nfs_os_firewall_deny }}" diff --git a/roles/openshift_nfs/tasks/setup.yml b/roles/openshift_nfs/tasks/setup.yml new file mode 100644 index 000000000..3070de495 --- /dev/null +++ b/roles/openshift_nfs/tasks/setup.yml @@ -0,0 +1,29 @@ +--- +- name: setup firewall +  include: firewall.yml +  static: yes + +- name: Install nfs-utils +  package: name=nfs-utils state=present + +- name: Configure NFS +  lineinfile: +    dest: /etc/sysconfig/nfs +    regexp: '^RPCNFSDARGS=.*$' +    line: 'RPCNFSDARGS="-N 2 -N 3"' +  register: nfs_config + +- name: Restart nfs-config +  systemd: name=nfs-config state=restarted +  when: nfs_config | changed + +- name: Ensure exports directory exists +  file: +    path: "{{ l_nfs_base_dir }}" +    state: directory + +- name: Enable and start NFS services +  systemd: +    name: nfs-server +    state: started +    enabled: yes | 
