ipavault: Allow execution of plugin in client host.

Update vault README file and add tests for executing plugin with
`ipaapi_context` set to `client`.

A new test playbook can be found at:

    tests/vault/test_vault_client_context.yml

As `ipavault` only works in client context, an error is raised if it
is explicitly executed in a server context.
This commit is contained in:
Rafael Guterres Jeffman
2021-09-03 13:31:57 -03:00
parent d9dcc8f5dc
commit 7e0624d836
5 changed files with 36 additions and 1 deletions

View File

@@ -26,6 +26,7 @@
- name: Ensure test users do not exist.
ipauser:
ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name:
- user01
- user02
@@ -35,6 +36,7 @@
- name: Ensure test groups do not exist.
ipagroup:
ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: vaultgroup
state: absent

View File

@@ -35,11 +35,13 @@
- name: Ensure vaultgroup exists.
ipagroup:
ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
name: vaultgroup
- name: Ensure testing users exist.
ipauser:
ipaadmin_password: SomeADMINpassword
ipaapi_context: "{{ ipa_context | default(omit) }}"
users:
- name: user01
first: First

View File

@@ -0,0 +1,25 @@
---
- name: Test vault
hosts: ipaserver
become: no
# Need to gather facts for ansible_env.
gather_facts: yes
tasks:
- name: Setup testing environment.
import_tasks: env_setup.yml
# vault requires 'ipaapi_context: client', and uses this
# context by defoult, so we test only for the case where
# 'ipaapi_context: server' is explicitly set.
- name: Execute with server context.
ipavault:
ipaadmin_password: SomeADMINpassword
ipaapi_context: server
name: ThisShouldNotWork
vault_type: standard
register: result
failed_when: not (result.failed and result.msg is regex("Context 'server' for ipavault not yet supported."))
- name: Cleanup testing environment.
import_tasks: env_cleanup.yml