commit c28551bb639bc301e93f715ef2d849b3e9dac6c8 Author: Frank Agerholm Date: Thu Mar 7 22:38:24 2024 +0100 Initial import diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..66a6a6b --- /dev/null +++ b/.gitignore @@ -0,0 +1,2 @@ +ansible.cfg +collections/ diff --git a/README.adoc b/README.adoc new file mode 100644 index 0000000..046d089 --- /dev/null +++ b/README.adoc @@ -0,0 +1,36 @@ += Ansible Demo "Retwis" + + +== Aufbau des Inventars + +.Dateien im Inventar +[source] +---- +inventory/ +├── hosts +└── host_vars + ├── demo-db01 + │ └── ansible.yml + └── demo-web01 + └── ansible.yml +---- + +.inventory/hosts +[source] +---- +[webserver] +demo-web01 + +[redis] +demo-db01 +---- + +.ansible.yml für einzelne Hosts +[source] +---- +--- +ansible_user: +ansible_host: +---- + + diff --git a/ansible.cfg.dist b/ansible.cfg.dist new file mode 100644 index 0000000..386de84 --- /dev/null +++ b/ansible.cfg.dist @@ -0,0 +1,29 @@ +[defaults] + +inventory = ./inventory/ + +#log_path = ansible.log +roles_path = ./roles +collections_paths = ./collections + +forks = 20 + +#callback_whitelist = profile_roles, profile_tasks, timer + +deprecation_warnings=False + +[inventory] +# fail more helpfully when the inventory file does not parse (Ansible 2.4+) +unparsed_is_failed=true + +enable_plugins = host_list, auto, yaml, ini + +# Additional ssh options for OpenShift Ansible +[ssh_connection] +pipelining = True +ssh_args = -o ControlMaster=auto -o ControlPersist=600s -o StrictHostKeyChecking=no +timeout = 10 +# shorten the ControlPath which is often too long; when it is, +# ssh connection reuse silently fails, making everything slower. +control_path = %(directory)s/%%h-%%r + diff --git a/os_update_etc_hosts.yml b/os_update_etc_hosts.yml new file mode 100644 index 0000000..92c4629 --- /dev/null +++ b/os_update_etc_hosts.yml @@ -0,0 +1,14 @@ +--- +- name: Static DNS Lookup + hosts: all + gather_facts: true + become: true + tasks: + - name: Add all hosts to /etc/hosts + ansible.builtin.lineinfile: + dest: /etc/hosts + regexp: "^{{ hostvars[item]['ansible_facts']['default_ipv4']['address'] }}.+{{ hostvars[item].ansible_facts.fqdn }}.*$" + line: "{{ hostvars[item]['ansible_facts']['default_ipv4']['address'] }} {{ hostvars[item].ansible_facts.fqdn }} {{ hostvars[item].ansible_facts.hostname }}" + state: present + with_items: "{{ groups.all }}" + diff --git a/ping_all.yml b/ping_all.yml new file mode 100644 index 0000000..25d0e5f --- /dev/null +++ b/ping_all.yml @@ -0,0 +1,7 @@ +--- +- name: Ping all hosts + hosts: all + gather_facts: false + tasks: + - name: Ping host + ansible.builtin.ping: {} diff --git a/redis_installation.yml b/redis_installation.yml new file mode 100644 index 0000000..c1f6d32 --- /dev/null +++ b/redis_installation.yml @@ -0,0 +1,8 @@ +--- +- name: Database configuration + hosts: redis + become: true + roles: + - role: redis + vars: + redis_clients_group: webserver diff --git a/requirements.yml b/requirements.yml new file mode 100644 index 0000000..685f81f --- /dev/null +++ b/requirements.yml @@ -0,0 +1,4 @@ +--- +collections: + - name: ansible.posix + version: ">=1.5.0" diff --git a/retwis_installation.yml b/retwis_installation.yml new file mode 100644 index 0000000..434978d --- /dev/null +++ b/retwis_installation.yml @@ -0,0 +1,6 @@ +--- +- name: Webserver configuration + hosts: webserver + become: true + roles: + - retwis diff --git a/roles/redis/defaults/main.yml b/roles/redis/defaults/main.yml new file mode 100644 index 0000000..0b84979 --- /dev/null +++ b/roles/redis/defaults/main.yml @@ -0,0 +1,2 @@ +--- +redis_clients_group: all diff --git a/roles/redis/meta/main.yml b/roles/redis/meta/main.yml new file mode 100644 index 0000000..d5c6409 --- /dev/null +++ b/roles/redis/meta/main.yml @@ -0,0 +1,21 @@ +galaxy_info: + author: Frank Agerholm + description: Redis installation and Configuration + company: serverWG.de + + issue_tracker_url: "https://git.serverwg.de/fager/ansible-demo-retwis/issues/new" + + license: "GPL" + + min_ansible_version: "2.11" + + platforms: + - name: EL + versions: + - "7" + - "8" + - "9" + + galaxy_tags: [] + +dependencies: [] diff --git a/roles/redis/tasks/main.yml b/roles/redis/tasks/main.yml new file mode 100644 index 0000000..8ab5456 --- /dev/null +++ b/roles/redis/tasks/main.yml @@ -0,0 +1,37 @@ +--- +- name: Install Redis Database + ansible.builtin.dnf: + name: redis + state: present + +- name: Configure Redis to listen on all IPs + ansible.builtin.lineinfile: + path: /etc/redis/redis.conf + regexp: '^bind ' + line: 'bind 0.0.0.0' + +- name: Enable and start the redis service + ansible.builtin.service: + name: redis + state: started + enabled: true + +- name: Gather facts from client systems + ansible.builtin.setup: + delegate_to: "{{ item }}" + delegate_facts: true + loop: "{{ groups[redis_clients_group] }}" + +- name: Ensure Firewall is enabled + ansible.builtin.systemd: + name: firewalld.service + state: started + enabled: true + +- name: Open the Firewall + ansible.posix.firewalld: + rich_rule: 'rule family="ipv4" source address="{{ item }}/32" port protocol="tcp" port="6379" accept' + permanent: true + state: enabled + immediate: true + loop: "{{ groups[redis_clients_group] | map('extract', hostvars, ['ansible_facts', 'default_ipv4', 'address']) | list }}" diff --git a/roles/retwis/defaults/main.yml b/roles/retwis/defaults/main.yml new file mode 100644 index 0000000..b652cde --- /dev/null +++ b/roles/retwis/defaults/main.yml @@ -0,0 +1,4 @@ +--- +retwis_download_tgz_url: "https://git.serverwg.de/fager/retwis/archive/1.0.tar.gz" +retwis_version: 1.0 +redis_server_group: redis diff --git a/roles/retwis/meta/main.yml b/roles/retwis/meta/main.yml new file mode 100644 index 0000000..5ffd7d0 --- /dev/null +++ b/roles/retwis/meta/main.yml @@ -0,0 +1,21 @@ +galaxy_info: + author: Frank Agerholm + description: Retwis installation and Configuration + company: serverWg.de + + issue_tracker_url: "https://git.serverwg.de/fager/ansible-demo-retwis/issues/new" + + license: "GPL" + + min_ansible_version: "2.11" + + platforms: + - name: EL + versions: + - "7" + - "8" + - "9" + + galaxy_tags: [] + +dependencies: [] diff --git a/roles/retwis/tasks/main.yml b/roles/retwis/tasks/main.yml new file mode 100644 index 0000000..3cf5aab --- /dev/null +++ b/roles/retwis/tasks/main.yml @@ -0,0 +1,53 @@ +--- +- name: Download Retwis Application + ansible.builtin.get_url: + url: "{{ retwis_download_tgz_url }}" + dest: "/tmp/retwis-{{ retwis_version }}.tar.gz" + validate_certs: false + owner: root + group: root + mode: "0600" + tags: + - install + +- name: Clean up document root + ansible.builtin.file: + path: "/var/www/html/app" + state: directory + mode: "0755" + loop: + - absent + - directory + tags: + - install + +- name: Extract retwis software archive to documentroot + ansible.builtin.unarchive: + src: "/tmp/retwis-{{ retwis_version }}.tar.gz" + dest: /var/www/html/app + remote_src: true + extra_opts: + - --strip-components=1 + - --directory=/var/www/html/app + tags: + - install + +- name: Gather facts from redis server systems + ansible.builtin.setup: + delegate_to: "{{ item }}" + delegate_facts: true + loop: "{{ groups[redis_server_group] }}" + tags: + - install + - configure + +- name: Deploy .htconfig template for Retwis Webapp configuration + ansible.builtin.template: + src: dot-htconfig.php + dest: /var/www/html/app/.htconfig.php + mode: "0644" + owner: apache + group: apache + tags: + - install + - configure diff --git a/roles/retwis/templates/dot-htconfig.php b/roles/retwis/templates/dot-htconfig.php new file mode 100644 index 0000000..552a042 --- /dev/null +++ b/roles/retwis/templates/dot-htconfig.php @@ -0,0 +1,6 @@ + diff --git a/roles/webserver/defaults/main.yml b/roles/webserver/defaults/main.yml new file mode 100644 index 0000000..7bfd21f --- /dev/null +++ b/roles/webserver/defaults/main.yml @@ -0,0 +1,11 @@ +--- + +webserver_packages: + - httpd + - httpd-tools + - php + - php-fpm + - python3-libselinux + - python3-libsemanage + - tar + - zip diff --git a/roles/webserver/files/phpinfo.php b/roles/webserver/files/phpinfo.php new file mode 100644 index 0000000..cf60860 --- /dev/null +++ b/roles/webserver/files/phpinfo.php @@ -0,0 +1,3 @@ + diff --git a/roles/webserver/handlers/main.yml b/roles/webserver/handlers/main.yml new file mode 100644 index 0000000..f25b3bc --- /dev/null +++ b/roles/webserver/handlers/main.yml @@ -0,0 +1,6 @@ +--- + +- name: Restart webserver + ansible.builtin.systemd: + name: httpd.service + state: restarted diff --git a/roles/webserver/meta/main.yml b/roles/webserver/meta/main.yml new file mode 100644 index 0000000..3cdc6d0 --- /dev/null +++ b/roles/webserver/meta/main.yml @@ -0,0 +1,21 @@ +galaxy_info: + author: Frank Agerholm + description: Webserver installation and Configuration + company: serverWg.de + + issue_tracker_url: "https://git.serverwg.de/fager/ansible-demo-retwis/issues/new" + + license: "GPL" + + min_ansible_version: "2.11" + + platforms: + - name: EL + versions: + - "7" + - "8" + - "9" + + galaxy_tags: [] + +dependencies: [] diff --git a/roles/webserver/tasks/main.yml b/roles/webserver/tasks/main.yml new file mode 100644 index 0000000..1f0c409 --- /dev/null +++ b/roles/webserver/tasks/main.yml @@ -0,0 +1,53 @@ +--- +- name: Install all required Packages + ansible.builtin.dnf: + name: "{{ webserver_packages }}" + state: present + +- name: Ensure httpd is running + ansible.builtin.systemd: + name: httpd.service + state: started + enabled: true + +- name: Ensure php-fpm is running + ansible.builtin.systemd: + name: php-fpm.service + state: started + enabled: true + +- name: Set SELinux boolean httpd_can_network_connect to true + ansible.posix.seboolean: + name: httpd_can_network_connect + state: true + persistent: true + notify: Restart webserver + +- name: Create start page + ansible.builtin.template: + src: index.html + dest: /var/www/html/index.html + owner: root + group: root + mode: "0644" + +- name: Ensure Firewalld is running + ansible.builtin.systemd: + name: firewalld.service + state: started + enabled: true + +- name: Open Port 80/tcp in Firewall + ansible.posix.firewalld: + service: http + permanent: true + immediate: true + state: enabled + +- name: Copy phpinfo.php to DocumentRoot + ansible.builtin.copy: + src: phpinfo.php + dest: /var/www/html/phpinfo.php + owner: root + group: root + mode: "0644" diff --git a/templates/index.html b/templates/index.html new file mode 100644 index 0000000..f7a6ec5 --- /dev/null +++ b/templates/index.html @@ -0,0 +1,7 @@ + + +{{ ansible_hostname }} + + +{{ ansible_hostname }} + diff --git a/webserver_installation.yml b/webserver_installation.yml new file mode 100644 index 0000000..c7124b0 --- /dev/null +++ b/webserver_installation.yml @@ -0,0 +1,6 @@ +--- +- name: Webserver configuration + hosts: webserver + become: true + roles: + - webserver