From 5b1279c3dd28a2c0252624c36e937c59db15270d Mon Sep 17 00:00:00 2001 From: Trygve Laugstøl Date: Fri, 8 Jan 2021 16:54:04 +0100 Subject: minio --- ansible/ansible.cfg | 4 +- ansible/minio-policies.yml | 49 ------------------- ansible/minio/backup-policy.yml | 67 -------------------------- ansible/minio/group_vars/all/vault.yml | 13 +++++ ansible/minio/minio.yml | 19 ++++++++ ansible/minio/policies/backup-conflatorio.json | 1 - ansible/minio/policies/backup-fuckaduck.json | 1 - ansible/minio/templates/docker-compose.yml | 17 +++++++ ansible/minio/vars.yml | 39 --------------- ansible/requirements.txt | 1 + ansible/terraform-to-ansible-inventory.py | 13 +++++ 11 files changed, 65 insertions(+), 159 deletions(-) delete mode 100644 ansible/minio-policies.yml delete mode 100644 ansible/minio/backup-policy.yml create mode 100644 ansible/minio/group_vars/all/vault.yml create mode 100644 ansible/minio/minio.yml delete mode 100644 ansible/minio/policies/backup-conflatorio.json delete mode 100644 ansible/minio/policies/backup-fuckaduck.json create mode 100644 ansible/minio/templates/docker-compose.yml delete mode 100644 ansible/minio/vars.yml create mode 100644 ansible/terraform-to-ansible-inventory.py (limited to 'ansible') diff --git a/ansible/ansible.cfg b/ansible/ansible.cfg index 4712f76..e7dde87 100644 --- a/ansible/ansible.cfg +++ b/ansible/ansible.cfg @@ -1,12 +1,12 @@ [defaults] become_method = sudo connection_plugins = ./connection_plugins -inventory = ./inventory +inventory = ./inventory,./inventory-terraform nocows = True stdout_callback = debug vault_password_file = ./.vault-password roles_path = roles:thirdparty retry_files_enabled = False -strategy_plugins = env/lib/python3.8/site-packages/ansible_mitogen/plugins/strategy +strategy_plugins = env/lib/python3.9/site-packages/ansible_mitogen/plugins/strategy strategy = mitogen_linear diff --git a/ansible/minio-policies.yml b/ansible/minio-policies.yml deleted file mode 100644 index 536314c..0000000 --- a/ansible/minio-policies.yml +++ /dev/null @@ -1,49 +0,0 @@ -- hosts: localhost - tasks: - - command: mc admin user list --json "{{ minio_config }}" - register: cmd_users - # - debug: var=cmd_users.stdout - -- hosts: localhost - tasks: - - with_items: "{{ backup_policies }}" - include_tasks: minio/backup-policy.yml - vars: - hostname: "{{ item }}" - host: "{{ minio_users['backup-' + item] }}" - -- hosts: localhost - vars: - registered_minio_users: "{{ cmd_users.stdout_lines | map('from_json') | list }}" - present_users: "{{ minio_users | dict2items | json_query('[] | [?value.state == `present`]') | items2dict }}" - absent_users: "{{ minio_users | dict2items | json_query('[] | [?value.state == `absent`]') | items2dict }}" - tasks: - - name: all present users - debug: - msg: "{{ present_users | join(', ') }}" - when: false - - - name: all absent users - debug: - msg: "{{ absent_users | join(', ') }}" - when: false - - - name: all minio users - debug: - msg: "{{ registered_minio_users }}" - when: false - - - name: Adding user to Minio - command: "mc admin user add {{ minio_config }} {{ item }} {{ user.secret }} {{ user.policy }}" - when: user_count == "0" - vars: - user: "{{ minio_users[item] }}" - user_count: "{{ registered_minio_users | json_query('[] | [?accessKey == `' + item + '`]') | length }}" - with_items: "{{ present_users }}" - - - name: Removing user from Minio - command: "mc admin user remove {{ minio_config }} {{ item }}" - when: user_count - vars: - user_count: "{{ registered_minio_users | json_query('[] | [?accessKey == `' + item + '`]') | length }}" - with_items: "{{ absent_users }}" diff --git a/ansible/minio/backup-policy.yml b/ansible/minio/backup-policy.yml deleted file mode 100644 index e0b8376..0000000 --- a/ansible/minio/backup-policy.yml +++ /dev/null @@ -1,67 +0,0 @@ -- register: policy - when: host.state == 'present' - local_action: - module: copy - dest: minio/policies/backup-{{ hostname }}.json - content: | - { - "Version": "2012-10-17", - "Statement": [ - { - "Action": [ - "s3:ListBucket" - ], - "Effect": "Allow", - "Resource": [ - "arn:aws:s3:::backup-{{ hostname }}/*" - ], - "Sid": "" - }, - { - "Action": [ - "s3:GetObject", - "s3:DeleteObject", - "s3:PutObject" - ], - "Effect": "Allow", - "Resource": [ - "arn:aws:s3:::backup-{{ hostname }}/*" - ], - "Sid": "" - } - ] - } - -- name: Registering policy - when: policy.changed - command: mc admin policy add {{ minio_config }} backup-{{ hostname }} minio/policies/backup-{{ hostname }}.json - -- name: checking if bucked exists - command: mc ls --json "{{ minio_config }}" - register: cmd_ls - failed_when: false - -#- debug: var=foo -# vars: -# foo: "{{ cmd_ls.stdout_lines | map('from_json') | list }}" - -#- debug: var=foo -# vars: -# foo: "{{ cmd_ls.stdout_lines | map('from_json') | list | json_query('[?key==`backup-' + hostname + '/`]') }}" - -- name: Creating backup bucket - vars: - len: "{{ cmd_ls.stdout_lines | map('from_json') | list | json_query('[?key==`backup-' + hostname + '/`]') | length }}" - when: len == "0" - command: mc mb {{ minio_config }}/backup-{{ hostname }} - -- name: Removing policy file - when: host.state != 'present' - register: removed - file: - path: minio/policies/backup-{{ hostname }}.json - state: absent - -- name: Unregistering policy - when: removed.changed - command: mc admin policy remove {{ minio_config }} backup-{{ hostname }} diff --git a/ansible/minio/group_vars/all/vault.yml b/ansible/minio/group_vars/all/vault.yml new file mode 100644 index 0000000..f8c5f3c --- /dev/null +++ b/ansible/minio/group_vars/all/vault.yml @@ -0,0 +1,13 @@ +$ANSIBLE_VAULT;1.1;AES256 +37316439376635346334323665326364636264623536646662346333333831356233386266326565 +6666613663303766373933346233323831333065353266630a363062333237323736636138643563 +39613864326262323138326236633163616366363635306335323331663636313332383538343434 +3364623632383033380a303332666165393031333237333533616233353936353337633266386336 +39363066396362343531373138353562626430626435386361653036313330363037326139663666 +34646530386537613162373931373462653463336136643232343261653961653434363631613964 +36373239393436366133663065343930343064623336323364333437626132326134653336623135 +62303930623135303933343634666439643935643966323937303266313463346538613163646532 +62353336323132376339616230636637636530353537363064666361303138633664343462613161 +61653566343537636162376463323731343236656637363631333262386631363666323136303165 +66366336326666653266363538653937333535643262316566653365316663393962366364663738 +37613136333634303330 diff --git a/ansible/minio/minio.yml b/ansible/minio/minio.yml new file mode 100644 index 0000000..d4687a6 --- /dev/null +++ b/ansible/minio/minio.yml @@ -0,0 +1,19 @@ +- hosts: + - birgitte + vars: + minio_zfs: "pool1/minio/data" + minio_data: "/{{ minio_zfs }}" + minio_version: RELEASE.2020-12-29T23-29-29Z + tasks: + - name: ZFS for minio + become: yes + zfs: + name: "{{ minio_zfs }}" + state: present + + - import_role: + name: docker-service + tags: docker-service + vars: + service: minio + template: templates/docker-compose.yml diff --git a/ansible/minio/policies/backup-conflatorio.json b/ansible/minio/policies/backup-conflatorio.json deleted file mode 100644 index 97ea158..0000000 --- a/ansible/minio/policies/backup-conflatorio.json +++ /dev/null @@ -1 +0,0 @@ -{"Version": "2012-10-17", "Statement": [{"Action": ["s3:ListBucket"], "Resource": ["arn:aws:s3:::backup-conflatorio/*"], "Effect": "Allow", "Sid": ""}, {"Action": ["s3:GetObject", "s3:DeleteObject", "s3:PutObject"], "Resource": ["arn:aws:s3:::backup-conflatorio/*"], "Effect": "Allow", "Sid": ""}]} \ No newline at end of file diff --git a/ansible/minio/policies/backup-fuckaduck.json b/ansible/minio/policies/backup-fuckaduck.json deleted file mode 100644 index 0f25369..0000000 --- a/ansible/minio/policies/backup-fuckaduck.json +++ /dev/null @@ -1 +0,0 @@ -{"Version": "2012-10-17", "Statement": [{"Action": ["s3:ListBucket"], "Resource": ["arn:aws:s3:::backup-fuckaduck/*"], "Effect": "Allow", "Sid": ""}, {"Action": ["s3:GetObject", "s3:DeleteObject", "s3:PutObject"], "Resource": ["arn:aws:s3:::backup-fuckaduck/*"], "Effect": "Allow", "Sid": ""}]} \ No newline at end of file diff --git a/ansible/minio/templates/docker-compose.yml b/ansible/minio/templates/docker-compose.yml new file mode 100644 index 0000000..4377d0b --- /dev/null +++ b/ansible/minio/templates/docker-compose.yml @@ -0,0 +1,17 @@ +version: "3" +services: + minio: + image: minio/minio:{{ minio_version }} + environment: + # It seems like minio want to replace access_key/secret_key with root_, but it doesn't work yet. + MINIO_ROOT_USER: {{ MINIO_ROOT_USER }} + MINIO_ROOT_PASSWORD: {{ MINIO_ROOT_PASSWORD }} + MINIO_ACCESS_KEY: {{ MINIO_ROOT_USER }} + MINIO_SECRET_KEY: {{ MINIO_ROOT_PASSWORD }} + command: + - server + - /data + ports: + - "9000:9000" + volumes: + - {{ minio_data }}:/data diff --git a/ansible/minio/vars.yml b/ansible/minio/vars.yml deleted file mode 100644 index 67f65f6..0000000 --- a/ansible/minio/vars.yml +++ /dev/null @@ -1,39 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -38623132333131643666333832396131366536303864616161386562613735383938643566663639 -6562383332623834623538313262323765353666313562640a303538383939376231366537613433 -65333766303731323661366437313132333332373130386637306537613332653264383330313931 -6131303363386639650adiff --git a/ansible/requirements.txt b/ansible/requirements.txt index 4375bc0..42251bf 100644 --- a/ansible/requirements.txt +++ b/ansible/requirements.txt @@ -1 +1,2 @@ mitogen==0.2.9 +pyyaml==5.3.1 diff --git a/ansible/terraform-to-ansible-inventory.py b/ansible/terraform-to-ansible-inventory.py new file mode 100644 index 0000000..25b402b --- /dev/null +++ b/ansible/terraform-to-ansible-inventory.py @@ -0,0 +1,13 @@ +from collections.abc import Iterable +import os +import sys +import json + +j = blob = json.load(sys.stdin) + +new = {} +for k, v in blob.items(): + new[k] = v["value"] + +new = {"all": {"vars": new}} +json.dump(new, fp=sys.stdout) -- cgit v1.2.3