mirror of
https://github.com/freeipa/ansible-freeipa.git
synced 2026-07-27 18:04:45 +00:00
Compare commits
231 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e37f190ee1 | ||
|
|
817ac954ca | ||
|
|
7ba279c09f | ||
|
|
e0d70eeeea | ||
|
|
268d4822f1 | ||
|
|
0e2e6a6653 | ||
|
|
a45b8f0715 | ||
|
|
79aed9ec84 | ||
|
|
21258df45b | ||
|
|
9f7bfb3ec4 | ||
|
|
5e057cfbcd | ||
|
|
fcf4a60de6 | ||
|
|
964345aed8 | ||
|
|
12bbf74d52 | ||
|
|
432c0b75fc | ||
|
|
4f6575b30c | ||
|
|
ad4b343c7e | ||
|
|
62fd1551eb | ||
|
|
fe2e65bd35 | ||
|
|
a24e90ad0c | ||
|
|
0b9718b3ec | ||
|
|
226b8c4d75 | ||
|
|
2f34e1ac6a | ||
|
|
e4ea7c8983 | ||
|
|
b3f024869c | ||
|
|
355438cea9 | ||
|
|
30b72422d9 | ||
|
|
10a84429e2 | ||
|
|
bf384ab1aa | ||
|
|
536b7cb5f3 | ||
|
|
17b100baec | ||
|
|
1488fb7b5e | ||
|
|
a733c031b0 | ||
|
|
ff1a026ef4 | ||
|
|
fa5d056e72 | ||
|
|
e0e3cb041e | ||
|
|
b54aaf127d | ||
|
|
4e16126b29 | ||
|
|
ed62c2f1bf | ||
|
|
dc9b0ce4e8 | ||
|
|
aa3bf1f015 | ||
|
|
f0aa531b28 | ||
|
|
6407fd8b2e | ||
|
|
2a1be13d3e | ||
|
|
2afca1fa5e | ||
|
|
2a40e42b0c | ||
|
|
8a33941188 | ||
|
|
0aef995bbe | ||
|
|
e75efb7a13 | ||
|
|
ed44344519 | ||
|
|
b186a1f28f | ||
|
|
d307635c38 | ||
|
|
74f3817531 | ||
|
|
97378c38cf | ||
|
|
6f15cd093a | ||
|
|
52f7f7848e | ||
|
|
fdd45cc475 | ||
|
|
a1cad32a46 | ||
|
|
7036fa3e1b | ||
|
|
95d935f185 | ||
|
|
dd3bc4fcdd | ||
|
|
c405229553 | ||
|
|
3fa3bf0822 | ||
|
|
7cef44c01d | ||
|
|
cd7d19bfeb | ||
|
|
0e748d372a | ||
|
|
e24340447d | ||
|
|
092ad81d03 | ||
|
|
4d22e917df | ||
|
|
a04a357b6a | ||
|
|
2081a1a8dd | ||
|
|
d1dfdc38c9 | ||
|
|
9fc1b043c1 | ||
|
|
bdf1efde80 | ||
|
|
513d5ee46b | ||
|
|
cd440a2049 | ||
|
|
e2317f304c | ||
|
|
7a23c668fc | ||
|
|
91d818b334 | ||
|
|
902d8b7238 | ||
|
|
d553f9a0b1 | ||
|
|
9cfe835b03 | ||
|
|
668830fc94 | ||
|
|
5ae39ec9de | ||
|
|
3f59332d99 | ||
|
|
30c405cb36 | ||
|
|
7275bbf6a3 | ||
|
|
6df89ad7db | ||
|
|
c5fa54f2cf | ||
|
|
8e3102270d | ||
|
|
89cfb5f4c4 | ||
|
|
5fb22581bb | ||
|
|
6976ef57eb | ||
|
|
0d9b164358 | ||
|
|
8b03e4d007 | ||
|
|
ef73a85320 | ||
|
|
5b3a4729f0 | ||
|
|
7245339934 | ||
|
|
638422e113 | ||
|
|
432376524c | ||
|
|
86701caf8b | ||
|
|
d1857c18ac | ||
|
|
edbdd3af79 | ||
|
|
2d3da2d72c | ||
|
|
329c16f742 | ||
|
|
66c0be06d0 | ||
|
|
f04c90f4db | ||
|
|
dfa4bcb68f | ||
|
|
b1328ba7d5 | ||
|
|
fe58f3a8ba | ||
|
|
4dc6192640 | ||
|
|
e9435410b2 | ||
|
|
de6a0429a0 | ||
|
|
40d85f83e4 | ||
|
|
678927f35c | ||
|
|
f0e6d0c89f | ||
|
|
c095c24950 | ||
|
|
34dc75802c | ||
|
|
feb33e4e3a | ||
|
|
3c50a8121f | ||
|
|
e8688d4cf5 | ||
|
|
d540be425a | ||
|
|
c1d7ed1df6 | ||
|
|
0fc8ddf450 | ||
|
|
012f0deb00 | ||
|
|
f27b0e3011 | ||
|
|
8b4b22dd00 | ||
|
|
91c4b83311 | ||
|
|
6925503a10 | ||
|
|
0da0b22ae7 | ||
|
|
f5f454915c | ||
|
|
8581b79eba | ||
|
|
a9602431ce | ||
|
|
9195494f37 | ||
|
|
81abf6889b | ||
|
|
81906edec6 | ||
|
|
5071653db3 | ||
|
|
df4ec30a51 | ||
|
|
73160a037b | ||
|
|
b7ed9ecfd5 | ||
|
|
a4f608854d | ||
|
|
8e6c5e566d | ||
|
|
431dc8667a | ||
|
|
bc16ccaef7 | ||
|
|
227c95e62e | ||
|
|
5abb515c92 | ||
|
|
1c4b50fa51 | ||
|
|
8fc2de1673 | ||
|
|
8d74fe34ef | ||
|
|
87ad46f7a4 | ||
|
|
4c3f4e6f7d | ||
|
|
489f4d5784 | ||
|
|
29fc03c625 | ||
|
|
651337541a | ||
|
|
e61b8db66c | ||
|
|
2dc1deeb87 | ||
|
|
82a53b9ae4 | ||
|
|
d580431832 | ||
|
|
6c94fe9bd5 | ||
|
|
4fa0621156 | ||
|
|
da775a21b2 | ||
|
|
5a774d2612 | ||
|
|
3e405fd08d | ||
|
|
cb3226910b | ||
|
|
a96611fb3f | ||
|
|
e92f09b920 | ||
|
|
97b0638f30 | ||
|
|
24569b850a | ||
|
|
08a2ba1592 | ||
|
|
3d5ff1f5fd | ||
|
|
2b28626012 | ||
|
|
7c7d98872e | ||
|
|
8956a7a1dd | ||
|
|
25577fa9bc | ||
|
|
f6bd62feb4 | ||
|
|
33c1c00643 | ||
|
|
0f530df092 | ||
|
|
a707d1887d | ||
|
|
e1786c9ddc | ||
|
|
367d30a30c | ||
|
|
77c34aeca2 | ||
|
|
5b33cb5e80 | ||
|
|
c979843b1a | ||
|
|
a8ce235261 | ||
|
|
bdcc8153f8 | ||
|
|
57bc35df80 | ||
|
|
a2f59e1a34 | ||
|
|
16636de681 | ||
|
|
55ec25a759 | ||
|
|
2b10256575 | ||
|
|
907650c746 | ||
|
|
b128a5cb9f | ||
|
|
220c4f0016 | ||
|
|
7f1df9d8f8 | ||
|
|
75d8ea283f | ||
|
|
91a3013513 | ||
|
|
85ef81c842 | ||
|
|
ad44f11887 | ||
|
|
80693c431a | ||
|
|
9ebc365d69 | ||
|
|
50ba326ed8 | ||
|
|
691e5915b9 | ||
|
|
178cf218b9 | ||
|
|
36f26bdf63 | ||
|
|
e2bdbeef6d | ||
|
|
88dc4c6923 | ||
|
|
e05fbce04c | ||
|
|
c2ff12b101 | ||
|
|
7dbe6edbf0 | ||
|
|
02ba890eb4 | ||
|
|
8515c9a48b | ||
|
|
94311f439c | ||
|
|
7aa9483b2c | ||
|
|
68bca84481 | ||
|
|
c9010d52ef | ||
|
|
0c6a7c8a14 | ||
|
|
0d246b1c11 | ||
|
|
785681f100 | ||
|
|
480c83f504 | ||
|
|
928ed30b8b | ||
|
|
fb6fed58cb | ||
|
|
b0e03a032d | ||
|
|
7ac0ec6bd4 | ||
|
|
8153239ef7 | ||
|
|
c2f6a19677 | ||
|
|
0002d4c7f7 | ||
|
|
a95c222ed6 | ||
|
|
d9a20e16c1 | ||
|
|
a4860f7b04 | ||
|
|
e71602be6e | ||
|
|
3dfa026eda |
@@ -7,7 +7,6 @@ exclude_paths:
|
|||||||
- .tox/
|
- .tox/
|
||||||
- .venv/
|
- .venv/
|
||||||
- .yamllint
|
- .yamllint
|
||||||
- molecule/
|
|
||||||
- tests/azure/
|
- tests/azure/
|
||||||
- meta/runtime.yml
|
- meta/runtime.yml
|
||||||
- requirements-docker.yml
|
- requirements-docker.yml
|
||||||
@@ -24,7 +23,7 @@ kinds:
|
|||||||
- tasks: '**/tasks_*.yml'
|
- tasks: '**/tasks_*.yml'
|
||||||
- tasks: '**/env_*.yml'
|
- tasks: '**/env_*.yml'
|
||||||
|
|
||||||
parseable: true
|
# parseable: true
|
||||||
|
|
||||||
quiet: false
|
quiet: false
|
||||||
|
|
||||||
|
|||||||
18
.github/workflows/docs.yml
vendored
18
.github/workflows/docs.yml
vendored
@@ -5,7 +5,7 @@ on:
|
|||||||
- pull_request
|
- pull_request
|
||||||
jobs:
|
jobs:
|
||||||
check_docs_oldest_supported:
|
check_docs_oldest_supported:
|
||||||
name: Check Ansible Documentation with ansible-core 2.13.
|
name: Check Ansible Documentation with ansible-core 2.16.
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4.1.1
|
- uses: actions/checkout@v4.1.1
|
||||||
@@ -14,15 +14,15 @@ jobs:
|
|||||||
- uses: actions/setup-python@v5.1.0
|
- uses: actions/setup-python@v5.1.0
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
- name: Install Ansible 2.13
|
- name: Install Ansible 2.16
|
||||||
run: |
|
run: |
|
||||||
python -m pip install "ansible-core >=2.13,<2.14"
|
python -m pip install "ansible-core >=2.16,<2.17"
|
||||||
- name: Run ansible-doc-test
|
- name: Run ansible-doc-test
|
||||||
run: |
|
run: |
|
||||||
ANSIBLE_LIBRARY="." ANSIBLE_DOC_FRAGMENT_PLUGINS="." python utils/ansible-doc-test -v roles plugins
|
ANSIBLE_LIBRARY="." ANSIBLE_DOC_FRAGMENT_PLUGINS="." python utils/ansible-doc-test -v roles plugins
|
||||||
|
|
||||||
check_docs_previous:
|
check_docs_previous:
|
||||||
name: Check Ansible Documentation with ansible-core 2.14.
|
name: Check Ansible Documentation with ansible-core 2.18.
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4.1.1
|
- uses: actions/checkout@v4.1.1
|
||||||
@@ -31,15 +31,15 @@ jobs:
|
|||||||
- uses: actions/setup-python@v5.1.0
|
- uses: actions/setup-python@v5.1.0
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
- name: Install Ansible 2.14
|
- name: Install Ansible 2.18
|
||||||
run: |
|
run: |
|
||||||
python -m pip install "ansible-core >=2.14,<2.15"
|
python -m pip install "ansible-core >=2.18,<2.19"
|
||||||
- name: Run ansible-doc-test
|
- name: Run ansible-doc-test
|
||||||
run: |
|
run: |
|
||||||
ANSIBLE_LIBRARY="." ANSIBLE_DOC_FRAGMENT_PLUGINS="." python utils/ansible-doc-test -v roles plugins
|
ANSIBLE_LIBRARY="." ANSIBLE_DOC_FRAGMENT_PLUGINS="." python utils/ansible-doc-test -v roles plugins
|
||||||
|
|
||||||
check_docs_current:
|
check_docs_current:
|
||||||
name: Check Ansible Documentation with ansible-core 2.15.
|
name: Check Ansible Documentation with ansible-core 2.19.
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4.1.1
|
- uses: actions/checkout@v4.1.1
|
||||||
@@ -48,9 +48,9 @@ jobs:
|
|||||||
- uses: actions/setup-python@v5.1.0
|
- uses: actions/setup-python@v5.1.0
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
- name: Install Ansible 2.15
|
- name: Install Ansible 2.20
|
||||||
run: |
|
run: |
|
||||||
python -m pip install "ansible-core >=2.15,<2.16"
|
python -m pip install "ansible-core <2.20"
|
||||||
- name: Run ansible-doc-test
|
- name: Run ansible-doc-test
|
||||||
run: |
|
run: |
|
||||||
ANSIBLE_LIBRARY="." ANSIBLE_DOC_FRAGMENT_PLUGINS="." python utils/ansible-doc-test -v roles plugins
|
ANSIBLE_LIBRARY="." ANSIBLE_DOC_FRAGMENT_PLUGINS="." python utils/ansible-doc-test -v roles plugins
|
||||||
|
|||||||
23
.github/workflows/lint.yml
vendored
23
.github/workflows/lint.yml
vendored
@@ -13,12 +13,12 @@ jobs:
|
|||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- uses: actions/setup-python@v5.1.0
|
- uses: actions/setup-python@v5.1.0
|
||||||
with:
|
with:
|
||||||
python-version: "3.x"
|
python-version: "3.13"
|
||||||
- name: Run ansible-lint
|
- name: Run ansible-lint
|
||||||
run: |
|
run: |
|
||||||
pip install "ansible-core>=2.16,<2.17" 'ansible-lint==6.22'
|
pip install "ansible-core>=2.16,<2.17" 'ansible-lint==6.22'
|
||||||
utils/build-galaxy-release.sh -ki
|
utils/build-collection.sh -ki rpm
|
||||||
cd .galaxy-build
|
cd .collection-build
|
||||||
ansible-lint --profile production --exclude tests/integration/ --exclude tests/unit/ --parseable --nocolor
|
ansible-lint --profile production --exclude tests/integration/ --exclude tests/unit/ --parseable --nocolor
|
||||||
|
|
||||||
yamllint:
|
yamllint:
|
||||||
@@ -34,21 +34,6 @@ jobs:
|
|||||||
- name: Run yaml-lint
|
- name: Run yaml-lint
|
||||||
uses: ibiqlik/action-yamllint@v3.1.1
|
uses: ibiqlik/action-yamllint@v3.1.1
|
||||||
|
|
||||||
pydocstyle:
|
|
||||||
name: Verify pydocstyle
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4.1.1
|
|
||||||
with:
|
|
||||||
fetch-depth: 1
|
|
||||||
- uses: actions/setup-python@v5.1.0
|
|
||||||
with:
|
|
||||||
python-version: "3.x"
|
|
||||||
- name: Run pydocstyle
|
|
||||||
run: |
|
|
||||||
pip install pydocstyle
|
|
||||||
pydocstyle
|
|
||||||
|
|
||||||
flake8:
|
flake8:
|
||||||
name: Verify flake8
|
name: Verify flake8
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
@@ -88,3 +73,5 @@ jobs:
|
|||||||
fetch-depth: 1
|
fetch-depth: 1
|
||||||
- name: Run ShellCheck
|
- name: Run ShellCheck
|
||||||
uses: ludeeus/action-shellcheck@master
|
uses: ludeeus/action-shellcheck@master
|
||||||
|
env:
|
||||||
|
SHELLCHECK_OPTS: -x
|
||||||
|
|||||||
1
.gitignore
vendored
1
.gitignore
vendored
@@ -12,3 +12,4 @@ importer_result.json
|
|||||||
/.venv/
|
/.venv/
|
||||||
|
|
||||||
tests/logs/
|
tests/logs/
|
||||||
|
TEST*.xml
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
repos:
|
repos:
|
||||||
- repo: https://github.com/ansible/ansible-lint.git
|
- repo: https://github.com/ansible/ansible-lint.git
|
||||||
rev: v24.5.0
|
rev: v26.4.0
|
||||||
hooks:
|
hooks:
|
||||||
- id: ansible-lint
|
- id: ansible-lint
|
||||||
always_run: false
|
always_run: false
|
||||||
@@ -18,23 +18,18 @@ repos:
|
|||||||
--profile production
|
--profile production
|
||||||
--exclude tests/integration/
|
--exclude tests/integration/
|
||||||
--exclude tests/unit/
|
--exclude tests/unit/
|
||||||
--parseable
|
|
||||||
--nocolor
|
--nocolor
|
||||||
- repo: https://github.com/adrienverge/yamllint.git
|
- repo: https://github.com/adrienverge/yamllint.git
|
||||||
rev: v1.35.1
|
rev: v1.38.0
|
||||||
hooks:
|
hooks:
|
||||||
- id: yamllint
|
- id: yamllint
|
||||||
files: \.(yaml|yml)$
|
files: \.(yaml|yml)$
|
||||||
- repo: https://github.com/pycqa/flake8
|
- repo: https://github.com/pycqa/flake8
|
||||||
rev: 7.0.0
|
rev: 7.3.0
|
||||||
hooks:
|
hooks:
|
||||||
- id: flake8
|
- id: flake8
|
||||||
- repo: https://github.com/pycqa/pydocstyle
|
|
||||||
rev: 6.3.0
|
|
||||||
hooks:
|
|
||||||
- id: pydocstyle
|
|
||||||
- repo: https://github.com/pycqa/pylint
|
- repo: https://github.com/pycqa/pylint
|
||||||
rev: v3.2.2
|
rev: v4.0.6
|
||||||
hooks:
|
hooks:
|
||||||
- id: pylint
|
- id: pylint
|
||||||
args:
|
args:
|
||||||
@@ -54,4 +49,7 @@ repos:
|
|||||||
name: ShellCheck
|
name: ShellCheck
|
||||||
language: system
|
language: system
|
||||||
entry: shellcheck
|
entry: shellcheck
|
||||||
files: \.sh$
|
args: ['-x']
|
||||||
|
files: >
|
||||||
|
\.sh$
|
||||||
|
utils/sh*$
|
||||||
|
|||||||
@@ -20,4 +20,9 @@ rules:
|
|||||||
max: 160
|
max: 160
|
||||||
# Disabled rules
|
# Disabled rules
|
||||||
indentation: disable
|
indentation: disable
|
||||||
comments: disable
|
comments:
|
||||||
|
min-spaces-from-content: 1
|
||||||
|
comments-indentation: disable
|
||||||
|
octal-values:
|
||||||
|
forbid-implicit-octal: true
|
||||||
|
forbid-explicit-octal: true
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ FreeIPA versions 4.4.0 and up are supported by the ipaautomountkey module.
|
|||||||
Requirements
|
Requirements
|
||||||
------------
|
------------
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ FreeIPA versions 4.4.0 and up are supported by the ipaautomountlocation module.
|
|||||||
Requirements
|
Requirements
|
||||||
------------
|
------------
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ FreeIPA versions 4.4.0 and up are supported by the ipaautomountmap module.
|
|||||||
Requirements
|
Requirements
|
||||||
------------
|
------------
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
* Some tool to generate a certificate signing request (CSR) might be needed, like `openssl`.
|
* Some tool to generate a certificate signing request (CSR) might be needed, like `openssl`.
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -145,7 +145,7 @@ Variable | Description | Required
|
|||||||
`selinuxusermaporder` \| `ipaselinuxusermaporder`| Set ordered list in increasing priority of SELinux users | no
|
`selinuxusermaporder` \| `ipaselinuxusermaporder`| Set ordered list in increasing priority of SELinux users | no
|
||||||
`selinuxusermapdefault`\| `ipaselinuxusermapdefault` | Set default SELinux user when no match is found in SELinux map rule | no
|
`selinuxusermapdefault`\| `ipaselinuxusermapdefault` | Set default SELinux user when no match is found in SELinux map rule | no
|
||||||
`pac_type` \| `ipakrbauthzdata` | set default types of PAC supported for services (choices: `MS-PAC`, `PAD`, `nfs:NONE`). Use `""` to clear this variable. | no
|
`pac_type` \| `ipakrbauthzdata` | set default types of PAC supported for services (choices: `MS-PAC`, `PAD`, `nfs:NONE`). Use `""` to clear this variable. | no
|
||||||
`user_auth_type` \| `ipauserauthtype` | set default types of supported user authentication (choices: `password`, `radius`, `otp`, `pkinit`, `hardened`, `idp`, `disabled`, `""`). An additional check ensures that only types can be used that are supported by the IPA version. Use `""` to clear this variable. | no
|
`user_auth_type` \| `ipauserauthtype` | set default types of supported user authentication (choices: `password`, `radius`, `otp`, `pkinit`, `hardened`, `idp`, `passkey`, `disabled`, `""`). An additional check ensures that only types can be used that are supported by the IPA version. Use `""` to clear this variable. | no
|
||||||
`domain_resolution_order` \| `ipadomainresolutionorder` | Set list of domains used for short name qualification | no
|
`domain_resolution_order` \| `ipadomainresolutionorder` | Set list of domains used for short name qualification | no
|
||||||
`ca_renewal_master_server` \| `ipacarenewalmasterserver`| Renewal master for IPA certificate authority. | no
|
`ca_renewal_master_server` \| `ipacarenewalmasterserver`| Renewal master for IPA certificate authority. | no
|
||||||
`enable_sid` | New users and groups automatically get a SID assigned. Cannot be deactivated once activated. Requires IPA 4.9.8+. (bool) | no
|
`enable_sid` | New users and groups automatically get a SID assigned. Cannot be deactivated once activated. Requires IPA 4.9.8+. (bool) | no
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ FreeIPA versions 4.4.0 and up are supported by the ipadnsforwardzone module.
|
|||||||
Requirements
|
Requirements
|
||||||
------------
|
------------
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
|
|||||||
117
README-group.md
117
README-group.md
@@ -8,8 +8,12 @@ The group module allows to ensure presence and absence of groups and members of
|
|||||||
|
|
||||||
The group module is as compatible as possible to the Ansible upstream `ipa_group` module, but additionally offers to add users to a group and also to remove users from a group.
|
The group module is as compatible as possible to the Ansible upstream `ipa_group` module, but additionally offers to add users to a group and also to remove users from a group.
|
||||||
|
|
||||||
## Note
|
|
||||||
Ensuring presence (adding) of several groups with mixed types (`external`, `nonposix` and `posix`) requires a fix in FreeIPA. The module implements a workaround to automatically use `client` context if the fix is not present in the target node FreeIPA and if more than one group is provided to the task using the `groups` parameter. If `ipaapi_context` is forced to be `server`, the module will fail in this case.
|
Notes
|
||||||
|
-----
|
||||||
|
|
||||||
|
* Ensuring presence (adding) of several groups with mixed types (`external`, `nonposix` and `posix`) requires a fix in FreeIPA. The module implements a workaround to automatically use `client` context if the fix is not present in the target node FreeIPA and if more than one group is provided to the task using the `groups` parameter. If `ipaapi_context` is forced to be `server`, the module will fail in this case.
|
||||||
|
* Using `externalmember` or `idoverrideuser` is only supported with `ipaapi_context: server`. With 'client' context, module execution will fail.
|
||||||
|
|
||||||
|
|
||||||
Features
|
Features
|
||||||
@@ -29,7 +33,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -213,7 +217,7 @@ Example playbook to add members from a trusted realm to an external group:
|
|||||||
---
|
---
|
||||||
- name: Playbook to handle groups.
|
- name: Playbook to handle groups.
|
||||||
hosts: ipaserver
|
hosts: ipaserver
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
- name: Create an external group and add members from a trust to it.
|
- name: Create an external group and add members from a trust to it.
|
||||||
ipagroup:
|
ipagroup:
|
||||||
@@ -276,6 +280,100 @@ Example playbook to ensure groups are absent:
|
|||||||
state: absent
|
state: absent
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query a group and print the base fields:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query groups
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query group ops
|
||||||
|
ipagroup:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: ops
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print group info
|
||||||
|
debug:
|
||||||
|
var: result.group
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query specific fields of a group:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query groups
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query description and members of group ops
|
||||||
|
ipagroup:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: ops
|
||||||
|
query_param:
|
||||||
|
- description
|
||||||
|
- gid
|
||||||
|
- user
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print group info
|
||||||
|
debug:
|
||||||
|
var: result.group
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query all fields of a group:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query groups
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query all fields of group ops
|
||||||
|
ipagroup:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: ops
|
||||||
|
query_param: ALL
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print group info
|
||||||
|
debug:
|
||||||
|
var: result.group
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query only the names of all groups:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query groups
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query all group names
|
||||||
|
ipagroup:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
query_param: PKEY_ONLY
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print group names
|
||||||
|
debug:
|
||||||
|
var: result.group.groups
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
Variables
|
Variables
|
||||||
=========
|
=========
|
||||||
|
|
||||||
@@ -299,11 +397,12 @@ Variable | Description | Required
|
|||||||
`service` | List of service name strings assigned to this group. Only usable with IPA versions 4.7 and up. | no
|
`service` | List of service name strings assigned to this group. Only usable with IPA versions 4.7 and up. | no
|
||||||
`membermanager_user` | List of member manager users assigned to this group. Only usable with IPA versions 4.8.4 and up. | no
|
`membermanager_user` | List of member manager users assigned to this group. Only usable with IPA versions 4.8.4 and up. | no
|
||||||
`membermanager_group` | List of member manager groups assigned to this group. Only usable with IPA versions 4.8.4 and up. | no
|
`membermanager_group` | List of member manager groups assigned to this group. Only usable with IPA versions 4.8.4 and up. | no
|
||||||
`externalmember` \| `ipaexternalmember` \| `external_member`| List of members of a trusted domain in DOM\\name or name@domain form. | no
|
`externalmember` \| `ipaexternalmember` \| `external_member`| List of members of a trusted domain in DOM\\name or name@domain form. Requires "server" context. | no
|
||||||
`idoverrideuser` | List of user ID overrides to manage. Only usable with IPA versions 4.8.7 and up.| no
|
`idoverrideuser` | List of user ID overrides to manage. Only usable with IPA versions 4.8.7 and up. Requires "server" context. | no
|
||||||
`rename` \| `new_name` | Rename the user object to the new name string. Only usable with `state: renamed`. | no
|
`rename` \| `new_name` | Rename the group object to the new name string. Only usable with `state: renamed`. | no
|
||||||
`action` | Work on group or member level. It can be on of `member` or `group` and defaults to `group`. | no
|
`action` | Work on group or member level. It can be one of `member` or `group` and defaults to `group`. | no
|
||||||
`state` | The state to ensure. It can be one of `present`, `absent` or `renamed`, default: `present`. | yes
|
`query_param` | The fields to query with `state: query`. Can be `ALL`, `BASE`, `PKEY_ONLY` or a list of specific field names. Only usable with `state: query`. | no
|
||||||
|
`state` | The state to ensure. It can be one of `present`, `absent`, `renamed` or `query`, default: `present`. | yes
|
||||||
|
|
||||||
|
|
||||||
Authors
|
Authors
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -44,7 +44,7 @@ Example playbook to make sure HBAC Rule login exists:
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacrules
|
- name: Playbook to handle hbacrules
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -60,7 +60,7 @@ Example playbook to make sure HBAC Rule login exists with the only HBAC Service
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacrules
|
- name: Playbook to handle hbacrules
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -77,7 +77,7 @@ Example playbook to make sure HBAC Service sshd is present in HBAC Rule login:
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacrules
|
- name: Playbook to handle hbacrules
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -95,7 +95,7 @@ Example playbook to make sure HBAC Service sshd is absent in HBAC Rule login:
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacrules
|
- name: Playbook to handle hbacrules
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -114,7 +114,7 @@ Example playbook to make sure HBAC Rule login is absent:
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacrules
|
- name: Playbook to handle hbacrules
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -44,7 +44,7 @@ Example playbook to make sure HBAC Service Group login exists:
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacsvcgroups
|
- name: Playbook to handle hbacsvcgroups
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -60,7 +60,7 @@ Example playbook to make sure HBAC Service Group login exists with the only HBAC
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacsvcgroups
|
- name: Playbook to handle hbacsvcgroups
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -77,7 +77,7 @@ Example playbook to make sure HBAC Service sshd is present in HBAC Service Group
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacsvcgroups
|
- name: Playbook to handle hbacsvcgroups
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -95,7 +95,7 @@ Example playbook to make sure HBAC Service sshd is absent in HBAC Service Group
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacsvcgroups
|
- name: Playbook to handle hbacsvcgroups
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
@@ -114,7 +114,7 @@ Example playbook to make sure HBAC Service Group login is absent:
|
|||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
- name: Playbook to handle hbacsvcgroups
|
- name: Playbook to handle hbacsvcgroups
|
||||||
hbacsvcs: ipaserver
|
hosts: ipaserver
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -341,7 +341,7 @@ Variable | Description | Required
|
|||||||
`password` \| `user_password` \| `userpassword` | Password used in bulk enrollment for absent or not enrolled hosts. | no
|
`password` \| `user_password` \| `userpassword` | Password used in bulk enrollment for absent or not enrolled hosts. | no
|
||||||
`random` \| `random_password` | Initiate the generation of a random password to be used in bulk enrollment for absent or not enrolled hosts. | no
|
`random` \| `random_password` | Initiate the generation of a random password to be used in bulk enrollment for absent or not enrolled hosts. | no
|
||||||
`certificate` \| `usercertificate` | List of base-64 encoded host certificates | no
|
`certificate` \| `usercertificate` | List of base-64 encoded host certificates | no
|
||||||
`managedby` \| `principalname` \| `krbprincipalname` | List of hosts that can manage this host | no
|
`managedby_host` | List of hosts that can manage this host | no
|
||||||
`principal` \| `principalname` \| `krbprincipalname` | List of principal aliases for this host | no
|
`principal` \| `principalname` \| `krbprincipalname` | List of principal aliases for this host | no
|
||||||
`allow_create_keytab_user` \| `ipaallowedtoperform_write_keys_user` | Users allowed to create a keytab of this host. | no
|
`allow_create_keytab_user` \| `ipaallowedtoperform_write_keys_user` | Users allowed to create a keytab of this host. | no
|
||||||
`allow_create_keytab_group` \| `ipaallowedtoperform_write_keys_group` | Groups allowed to create a keytab of this host. | no
|
`allow_create_keytab_group` \| `ipaallowedtoperform_write_keys_group` | Groups allowed to create a keytab of this host. | no
|
||||||
@@ -354,7 +354,7 @@ Variable | Description | Required
|
|||||||
`mac_address` \| `macaddress` | List of hardware MAC addresses. | no
|
`mac_address` \| `macaddress` | List of hardware MAC addresses. | no
|
||||||
`sshpubkey` \| `ipasshpubkey` | List of SSH public keys | no
|
`sshpubkey` \| `ipasshpubkey` | List of SSH public keys | no
|
||||||
`userclass` \| `class` | Host category (semantics placed on this attribute are for local interpretation) | no
|
`userclass` \| `class` | Host category (semantics placed on this attribute are for local interpretation) | no
|
||||||
`auth_ind` \| `krbprincipalauthind` | Defines an allow list for Authentication Indicators. Use 'otp' to allow OTP-based 2FA authentications. Use 'radius' to allow RADIUS-based 2FA authentications. Use empty string to reset auth_ind to the initial value. Other values may be used for custom configurations. An additional check ensures that only types can be used that are supported by the IPA version. Choices: ["radius", "otp", "pkinit", "hardened", "idp", ""] | no
|
`auth_ind` \| `krbprincipalauthind` | Defines an allow list for Authentication Indicators. Use 'otp' to allow OTP-based 2FA authentications. Use 'radius' to allow RADIUS-based 2FA authentications. Use empty string to reset auth_ind to the initial value. Other values may be used for custom configurations. An additional check ensures that only types can be used that are supported by the IPA version. Choices: ["radius", "otp", "pkinit", "hardened", "idp", "passkey", ""] | no
|
||||||
`requires_pre_auth` \| `ipakrbrequirespreauth` | Pre-authentication is required for the service (bool) | no
|
`requires_pre_auth` \| `ipakrbrequirespreauth` | Pre-authentication is required for the service (bool) | no
|
||||||
`ok_as_delegate` \| `ipakrbokasdelegate` | Client credentials may be delegated to the service (bool) | no
|
`ok_as_delegate` \| `ipakrbokasdelegate` | Client credentials may be delegated to the service (bool) | no
|
||||||
`ok_to_auth_as_delegate` \| `ipakrboktoauthasdelegate` | The service is allowed to authenticate on behalf of a client (bool) | no
|
`ok_to_auth_as_delegate` \| `ipakrboktoauthasdelegate` | The service is allowed to authenticate on behalf of a client (bool) | no
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -68,23 +68,6 @@ Example playbook to ensure a local domain idrange is present:
|
|||||||
name: local_domain_id_range
|
name: local_domain_id_range
|
||||||
base_id: 150000
|
base_id: 150000
|
||||||
range_size: 200000
|
range_size: 200000
|
||||||
```
|
|
||||||
|
|
||||||
Example playbook to ensure a local domain idrange is present, with RID and secondary RID base values:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
---
|
|
||||||
- name: Playbook to manage IPA idrange.
|
|
||||||
hosts: ipaserver
|
|
||||||
become: no
|
|
||||||
|
|
||||||
tasks:
|
|
||||||
- name: Ensure local idrange is present
|
|
||||||
ipaidrange:
|
|
||||||
ipaadmin_password: SomeADMINpassword
|
|
||||||
name: local_domain_id_range
|
|
||||||
base_id: 150000000
|
|
||||||
range_size: 200000
|
|
||||||
rid_base: 1000000
|
rid_base: 1000000
|
||||||
secondary_rid_base: 200000000
|
secondary_rid_base: 200000000
|
||||||
```
|
```
|
||||||
@@ -172,8 +155,8 @@ Variable | Description | Required
|
|||||||
`name` \| `cn` | The list of idrange name strings. | yes
|
`name` \| `cn` | The list of idrange name strings. | yes
|
||||||
`base_id` \| `ipabaseid` | First Posix ID of the range. (int) | yes, if `state: present`
|
`base_id` \| `ipabaseid` | First Posix ID of the range. (int) | yes, if `state: present`
|
||||||
`range_size` \| `ipaidrangesize` | Number of IDs in the range. (int) | yes, if `state: present`
|
`range_size` \| `ipaidrangesize` | Number of IDs in the range. (int) | yes, if `state: present`
|
||||||
`rid_base` \| `ipabaserid` | First RID of the corresponding RID range. (int) | no
|
`rid_base` \| `ipabaserid` | First RID of the corresponding RID range. (int) | yes, if `idrange_type: ipa-local` and `state: present` |
|
||||||
`secondary_rid_base` \| `ipasecondarybaserid` | First RID of the secondary RID range. (int) | no
|
`secondary_rid_base` \| `ipasecondarybaserid` | First RID of the secondary RID range. (int) | yes, if `idrange_type: ipa-local` and `state: present` |
|
||||||
`dom_sid` \| `ipanttrusteddomainsid` | Domain SID of the trusted domain. | no
|
`dom_sid` \| `ipanttrusteddomainsid` | Domain SID of the trusted domain. | no
|
||||||
`idrange_type` \| `iparangetype` | ID range type, one of `ipa-ad-trust`, `ipa-ad-trust-posix`, `ipa-local`. Only valid if idrange does not exist. | no
|
`idrange_type` \| `iparangetype` | ID range type, one of `ipa-ad-trust`, `ipa-ad-trust-posix`, `ipa-local`. Only valid if idrange does not exist. | no
|
||||||
`dom_name` \| `ipanttrusteddomainname` | Name of the trusted domain. Can only be used when `ipaapi_context: server`. | no
|
`dom_name` \| `ipanttrusteddomainname` | Name of the trusted domain. Can only be used when `ipaapi_context: server`. | no
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
88
README-passkeyconfig.md
Normal file
88
README-passkeyconfig.md
Normal file
@@ -0,0 +1,88 @@
|
|||||||
|
Passkeyconfig module
|
||||||
|
============
|
||||||
|
|
||||||
|
Description
|
||||||
|
-----------
|
||||||
|
|
||||||
|
The passkeyconfig module allows to manage FreeIPA passkey configuration settings.
|
||||||
|
|
||||||
|
Features
|
||||||
|
--------
|
||||||
|
|
||||||
|
* Passkeyconfig management
|
||||||
|
|
||||||
|
|
||||||
|
Supported FreeIPA Versions
|
||||||
|
--------------------------
|
||||||
|
|
||||||
|
FreeIPA versions 4.4.0 and up are supported by the ipapasskeyconfig module.
|
||||||
|
|
||||||
|
|
||||||
|
Requirements
|
||||||
|
------------
|
||||||
|
|
||||||
|
**Controller**
|
||||||
|
* Ansible version: 2.15+
|
||||||
|
|
||||||
|
**Node**
|
||||||
|
* Supported FreeIPA version (see above)
|
||||||
|
|
||||||
|
|
||||||
|
Usage
|
||||||
|
=====
|
||||||
|
|
||||||
|
Example inventory file
|
||||||
|
|
||||||
|
```ini
|
||||||
|
[ipaserver]
|
||||||
|
ipaserver.test.local
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
By default, user verification for passkey authentication is turned on (`true`). Example playbook to ensure that the requirement for user verification for passkey authentication is turned off:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA passkeyconfig.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure require_user_verification is false
|
||||||
|
ipapasskeyconfig:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
require_user_verification: false
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to get current passkeyconfig:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to get IPA passkeyconfig.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Retrieve current passkey configuration
|
||||||
|
ipapasskeyconfig:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Variables
|
||||||
|
---------
|
||||||
|
|
||||||
|
Variable | Description | Required
|
||||||
|
-------- | ----------- | --------
|
||||||
|
`ipaadmin_principal` | The admin principal is a string and defaults to `admin` | no
|
||||||
|
`ipaadmin_password` | The admin password is a string and is required if there is no admin ticket available on the node | no
|
||||||
|
`ipaapi_context` | The context in which the module will execute. Executing in a server context is preferred. If not provided context will be determined by the execution environment. Valid values are `server` and `client`. | no
|
||||||
|
`ipaapi_ldap_cache` | Use LDAP cache for IPA connection. The bool setting defaults to true. (bool) | no
|
||||||
|
`require_user_verification` \| `iparequireuserverification` | Require user verification for passkey authentication. (bool) | no
|
||||||
|
|
||||||
|
|
||||||
|
Authors
|
||||||
|
=======
|
||||||
|
|
||||||
|
Rafael Guterres Jeffman
|
||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -230,6 +230,8 @@ Example playbook to ensure that different members are not associated with a role
|
|||||||
- User Administrators
|
- User Administrators
|
||||||
service:
|
service:
|
||||||
- service01
|
- service01
|
||||||
|
sysaccount:
|
||||||
|
- my-app
|
||||||
action: member
|
action: member
|
||||||
state: absent
|
state: absent
|
||||||
```
|
```
|
||||||
@@ -253,7 +255,8 @@ Variable | Description | Required
|
|||||||
`host` | List of hosts to be assigned or not assigned to the role. | no
|
`host` | List of hosts to be assigned or not assigned to the role. | no
|
||||||
`hostgroup` | List of hostgroups to be assigned or not assigned to the role. | no
|
`hostgroup` | List of hostgroups to be assigned or not assigned to the role. | no
|
||||||
`service` | List of services to be assigned or not assigned to the role. | no
|
`service` | List of services to be assigned or not assigned to the role. | no
|
||||||
`action` | Work on role or member level. It can be on of `member` or `role` and defaults to `role`. | no
|
`sysaccount` | List of sysaccounts to be assigned or not assigned to the role. | no
|
||||||
|
`action` | Work on role or member level. It can be one of `member` or `role` and defaults to `role`. | no
|
||||||
`state` | The state to ensure. It can be one of `present`, `absent`, default: `present`. | no
|
`state` | The state to ensure. It can be one of `present`, `absent`, default: `present`. | no
|
||||||
|
|
||||||
|
|
||||||
@@ -261,3 +264,4 @@ Authors
|
|||||||
=======
|
=======
|
||||||
|
|
||||||
Rafael Jeffman
|
Rafael Jeffman
|
||||||
|
Thomas Woerner
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FReeIPA version (see above)
|
* Supported FReeIPA version (see above)
|
||||||
@@ -361,7 +361,7 @@ Variable | Description | Required
|
|||||||
-------- | ----------- | --------
|
-------- | ----------- | --------
|
||||||
`certificate` \| `usercertificate` | Base-64 encoded service certificate. | no
|
`certificate` \| `usercertificate` | Base-64 encoded service certificate. | no
|
||||||
`pac_type` \| `ipakrbauthzdata` | Supported PAC type. It can be one of `MS-PAC`, `PAD`, or `NONE`. Use empty string to reset pac_type to the initial value. | no
|
`pac_type` \| `ipakrbauthzdata` | Supported PAC type. It can be one of `MS-PAC`, `PAD`, or `NONE`. Use empty string to reset pac_type to the initial value. | no
|
||||||
`auth_ind` \| `krbprincipalauthind` | Defines an allow list for Authentication Indicators. It can be any of `otp`, `radius`, `pkinit`, `hardened`, `idp` or `""`. An additional check ensures that only types can be used that are supported by the IPA version. Use empty string to reset auth_ind to the initial value. | no
|
`auth_ind` \| `krbprincipalauthind` | Defines an allow list for Authentication Indicators. It can be any of `otp`, `radius`, `pkinit`, `hardened`, `idp`, `passkey` or `""`. An additional check ensures that only types can be used that are supported by the IPA version. Use empty string to reset auth_ind to the initial value. | no
|
||||||
`requires_pre_auth` \| `ipakrbrequirespreauth` | Pre-authentication is required for the service. Default to true. (bool) | no
|
`requires_pre_auth` \| `ipakrbrequirespreauth` | Pre-authentication is required for the service. Default to true. (bool) | no
|
||||||
`ok_as_delegate` \| `ipakrbokasdelegate` | Client credentials may be delegated to the service. Default to false. (bool) | no
|
`ok_as_delegate` \| `ipakrbokasdelegate` | Client credentials may be delegated to the service. Default to false. (bool) | no
|
||||||
`ok_to_auth_as_delegate` \| `ipakrboktoauthasdelegate` | The service is allowed to authenticate on behalf of a client. Default to false. (bool) | no
|
`ok_to_auth_as_delegate` \| `ipakrboktoauthasdelegate` | The service is allowed to authenticate on behalf of a client. Default to false. (bool) | no
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -129,6 +129,49 @@ Example playbook to make sure Sudo Rule is absent:
|
|||||||
state: absent
|
state: absent
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Example playbook to ensure multiple Sudo Rule are present using batch mode:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to handle sudorules
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
- name: Ensure multiple Sudo Rules are present using batch mode.
|
||||||
|
ipasudorule:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
sudorules:
|
||||||
|
- name: testrule1
|
||||||
|
hostmask:
|
||||||
|
- 192.168.122.1/24
|
||||||
|
- name: testrule2
|
||||||
|
hostcategory: all
|
||||||
|
```
|
||||||
|
|
||||||
|
Example playbook to ensure multiple Sudo Rule members are present using batch mode:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to handle sudorules
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
- name: Ensure multiple Sudo Rules are present using batch mode.
|
||||||
|
ipasudorule:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
action: member
|
||||||
|
sudorules:
|
||||||
|
- name: testrule1
|
||||||
|
user:
|
||||||
|
- user01
|
||||||
|
- user02
|
||||||
|
group:
|
||||||
|
- group01
|
||||||
|
- name: testrule2
|
||||||
|
hostgroup:
|
||||||
|
- hostgroup01
|
||||||
|
- hostgroup02
|
||||||
|
```
|
||||||
|
|
||||||
Variables
|
Variables
|
||||||
=========
|
=========
|
||||||
@@ -139,7 +182,9 @@ Variable | Description | Required
|
|||||||
`ipaadmin_password` | The admin password is a string and is required if there is no admin ticket available on the node | no
|
`ipaadmin_password` | The admin password is a string and is required if there is no admin ticket available on the node | no
|
||||||
`ipaapi_context` | The context in which the module will execute. Executing in a server context is preferred. If not provided context will be determined by the execution environment. Valid values are `server` and `client`. | no
|
`ipaapi_context` | The context in which the module will execute. Executing in a server context is preferred. If not provided context will be determined by the execution environment. Valid values are `server` and `client`. | no
|
||||||
`ipaapi_ldap_cache` | Use LDAP cache for IPA connection. The bool setting defaults to yes. (bool) | no
|
`ipaapi_ldap_cache` | Use LDAP cache for IPA connection. The bool setting defaults to yes. (bool) | no
|
||||||
`name` \| `cn` | The list of sudorule name strings. | yes
|
`name` \| `cn` | The list of sudorule name strings. | no
|
||||||
|
`sudorules` | The list of sudorule dicts. Each `sudorule` dict entry can contain sudorule variables.<br>There is one required option in the `sudorule` dict:| no
|
||||||
|
| `name` - The sudorule name string of the entry. | yes
|
||||||
`description` | The sudorule description string. | no
|
`description` | The sudorule description string. | no
|
||||||
`usercategory` \| `usercat` | User category the rule applies to. Choices: ["all", ""] | no
|
`usercategory` \| `usercat` | User category the rule applies to. Choices: ["all", ""] | no
|
||||||
`hostcategory` \| `hostcat` | Host category the rule applies to. Choices: ["all", ""] | no
|
`hostcategory` \| `hostcat` | Host category the rule applies to. Choices: ["all", ""] | no
|
||||||
|
|||||||
196
README-sysaccount.md
Normal file
196
README-sysaccount.md
Normal file
@@ -0,0 +1,196 @@
|
|||||||
|
Sysaccount module
|
||||||
|
============
|
||||||
|
|
||||||
|
Description
|
||||||
|
-----------
|
||||||
|
|
||||||
|
The sysaccount module allows to ensure presence and absence of system accounts.
|
||||||
|
|
||||||
|
Features
|
||||||
|
--------
|
||||||
|
|
||||||
|
* Sysaccount management
|
||||||
|
|
||||||
|
|
||||||
|
Supported FreeIPA Versions
|
||||||
|
--------------------------
|
||||||
|
|
||||||
|
FreeIPA versions 4.4.0 and up are supported by the ipasysaccount module.
|
||||||
|
|
||||||
|
|
||||||
|
Requirements
|
||||||
|
------------
|
||||||
|
|
||||||
|
**Controller**
|
||||||
|
* Ansible version: 2.15+
|
||||||
|
|
||||||
|
**Node**
|
||||||
|
* Supported FreeIPA version (see above)
|
||||||
|
|
||||||
|
|
||||||
|
Usage
|
||||||
|
=====
|
||||||
|
|
||||||
|
Example inventory file
|
||||||
|
|
||||||
|
```ini
|
||||||
|
[ipaserver]
|
||||||
|
ipaserver.test.local
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to make sure sysaccount "my-app" is present with random password:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA sysaccount.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure sysaccount "my-app" is present with random password
|
||||||
|
ipasysaccount:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: my-app
|
||||||
|
random: true
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print generated random password
|
||||||
|
debug:
|
||||||
|
var: result.sysaccount.randompassword
|
||||||
|
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to make sure sysaccount "my-app" is present with given password:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA sysaccount.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure sysaccount "my-app" is present with given password
|
||||||
|
ipasysaccount:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: my-app
|
||||||
|
password: SomeAPPpassword
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to make sure sysaccount "my-app" is absent:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA sysaccount.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure sysaccount "my-app" is absent
|
||||||
|
ipasysaccount:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: my-app
|
||||||
|
state: absent
|
||||||
|
```
|
||||||
|
|
||||||
|
Example playbook to ensure existing sysaccount my-app is privileged
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA sysaccount.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure existing sysaccount my-app is privileged
|
||||||
|
ipasysaccount:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: my-app
|
||||||
|
privileged: true
|
||||||
|
```
|
||||||
|
|
||||||
|
Example playbook to ensure existing sysaccount my-app is not privileged
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA sysaccount.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure existing sysaccount my-app is not privileged
|
||||||
|
ipasysaccount:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: my-app
|
||||||
|
privileged: false
|
||||||
|
```
|
||||||
|
|
||||||
|
Example playbook to ensure existing sysaccount my-app is disabled
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA sysaccount.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure existing sysaccount my-app is disabled
|
||||||
|
ipasysaccount:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: my-app
|
||||||
|
state: disabled
|
||||||
|
```
|
||||||
|
|
||||||
|
Example playbook to ensure existing sysaccount my-app is enabled
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to manage IPA sysaccount.
|
||||||
|
hosts: ipaserver
|
||||||
|
become: false
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Ensure existing sysaccount my-app is enabled
|
||||||
|
ipasysaccount:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: my-app
|
||||||
|
state: enabled
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Variables
|
||||||
|
---------
|
||||||
|
|
||||||
|
Variable | Description | Required
|
||||||
|
-------- | ----------- | --------
|
||||||
|
`ipaadmin_principal` | The admin principal is a string and defaults to `admin` | no
|
||||||
|
`ipaadmin_password` | The admin password is a string and is required if there is no admin ticket available on the node | no
|
||||||
|
`ipaapi_context` | The context in which the module will execute. Executing in a server context is preferred. If not provided context will be determined by the execution environment. Valid values are `server` and `client`. | no
|
||||||
|
`ipaapi_ldap_cache` | Use LDAP cache for IPA connection. The bool setting defaults to true. (bool) | no
|
||||||
|
`name` \| `login` | The list of sysaccount name strings - internally uid. (list of strings) | yes
|
||||||
|
`description` | A description for the sysaccount. (string) | no
|
||||||
|
`privileged` | Allow password updates without reset. This flag is not replicated. It is needed to set privileged on all servers, where it is needed. (bool) | no
|
||||||
|
`random` | Generate a random user password. (bool) | no
|
||||||
|
`password` \| `userpassword` | Set the password. (string) | no
|
||||||
|
`update_password` | Set password for a sysaccount in present state only on creation or always. It can be one of `always` or `on_create` and defaults to `always`. | no
|
||||||
|
`state` | The state to ensure. It can be one of `present`, `absent`, 'enabled', 'disabled', default: `present`. | no
|
||||||
|
|
||||||
|
|
||||||
|
Return Values
|
||||||
|
=============
|
||||||
|
|
||||||
|
There are only return values if a random passwords has been generated.
|
||||||
|
|
||||||
|
Variable | Description | Returned When
|
||||||
|
-------- | ----------- | -------------
|
||||||
|
`sysaccount` | Sysaccount dict (dict) <br>Options: | Always
|
||||||
|
| `randompassword` - The generated random password | If random is yes and sysaccount did not exist or update_password is yes
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
Authors
|
||||||
|
=======
|
||||||
|
|
||||||
|
Thomas Woerner
|
||||||
@@ -22,7 +22,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ Requirements
|
|||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
|
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
|
|
||||||
|
|||||||
100
README-user.md
100
README-user.md
@@ -24,7 +24,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -368,6 +368,100 @@ Example playbook to ensure users are absent:
|
|||||||
state: absent
|
state: absent
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query a user and print the base fields:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query users
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query user pinky
|
||||||
|
ipauser:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: pinky
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print user info
|
||||||
|
debug:
|
||||||
|
var: result.user
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query specific fields of a user:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query users
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query first and last name of user pinky
|
||||||
|
ipauser:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: pinky
|
||||||
|
query_param:
|
||||||
|
- first
|
||||||
|
- last
|
||||||
|
- email
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print user info
|
||||||
|
debug:
|
||||||
|
var: result.user
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query all fields of a user:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query users
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query all fields of user pinky
|
||||||
|
ipauser:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
name: pinky
|
||||||
|
query_param: ALL
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print user info
|
||||||
|
debug:
|
||||||
|
var: result.user
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
Example playbook to query only the names of all users:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
- name: Playbook to query users
|
||||||
|
hosts: ipaserver
|
||||||
|
become: true
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: Query all user names
|
||||||
|
ipauser:
|
||||||
|
ipaadmin_password: SomeADMINpassword
|
||||||
|
query_param: PKEY_ONLY
|
||||||
|
state: query
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Print user names
|
||||||
|
debug:
|
||||||
|
var: result.user.users
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
When using FreeIPA 4.8.0+, SMB logon script, profile, home directory and home drive can be set for users.
|
When using FreeIPA 4.8.0+, SMB logon script, profile, home directory and home drive can be set for users.
|
||||||
|
|
||||||
In the example playbook to set SMB attributes note that `smb_profile_path` and `smb_home_dir` use paths in UNC format, which includes backslashes ('\\`). If the paths are quoted, the backslash needs to be escaped becoming "\\", so the path `\\server\dir` becomes `"\\\\server\\dir"`. If the paths are unquoted the slashes do not have to be escaped.
|
In the example playbook to set SMB attributes note that `smb_profile_path` and `smb_home_dir` use paths in UNC format, which includes backslashes ('\\`). If the paths are quoted, the backslash needs to be escaped becoming "\\", so the path `\\server\dir` becomes `"\\\\server\\dir"`. If the paths are unquoted the slashes do not have to be escaped.
|
||||||
@@ -416,7 +510,7 @@ Variable | Description | Required
|
|||||||
`update_password` | Set password for a user in present state only on creation or always. It can be one of `always` or `on_create` and defaults to `always`. | no
|
`update_password` | Set password for a user in present state only on creation or always. It can be one of `always` or `on_create` and defaults to `always`. | no
|
||||||
`preserve` | Delete a user, keeping the entry available for future use. (bool) | no
|
`preserve` | Delete a user, keeping the entry available for future use. (bool) | no
|
||||||
`action` | Work on user or member level. It can be on of `member` or `user` and defaults to `user`. | no
|
`action` | Work on user or member level. It can be on of `member` or `user` and defaults to `user`. | no
|
||||||
`state` | The state to ensure. It can be one of `present`, `absent`, `enabled`, `disabled`, `renamed`, `unlocked` or `undeleted`, default: `present`. Only `names` or `users` with only `name` set are allowed if state is not `present`. | yes
|
`state` | The state to ensure. It can be one of `present`, `absent`, `enabled`, `disabled`, `renamed`, `unlocked`, `undeleted` or `query`, default: `present`. Only `names` or `users` with only `name` set are allowed if state is not `present`. | yes
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -452,7 +546,7 @@ Variable | Description | Required
|
|||||||
`manager` | List of manager user names. | no
|
`manager` | List of manager user names. | no
|
||||||
`carlicense` | List of car licenses. | no
|
`carlicense` | List of car licenses. | no
|
||||||
`sshpubkey` \| `ipasshpubkey` | List of SSH public keys. | no
|
`sshpubkey` \| `ipasshpubkey` | List of SSH public keys. | no
|
||||||
`userauthtype` \| `ipauserauthtype` | List of supported user authentication types. Choices: `password`, `radius`, `otp`, `pkinit`, `hardened`, `idp` and `""`. An additional check ensures that only types can be used that are supported by the IPA version. Use empty string to reset userauthtype to the initial value. | no
|
`userauthtype` \| `ipauserauthtype` | List of supported user authentication types. Choices: `password`, `radius`, `otp`, `pkinit`, `hardened`, `idp`, `passkey` and `""`. An additional check ensures that only types can be used that are supported by the IPA version. Use empty string to reset userauthtype to the initial value. | no
|
||||||
`userclass` | User category. (semantics placed on this attribute are for local interpretation). | no
|
`userclass` | User category. (semantics placed on this attribute are for local interpretation). | no
|
||||||
`radius` | RADIUS proxy configuration | no
|
`radius` | RADIUS proxy configuration | no
|
||||||
`radiususer` | RADIUS proxy username | no
|
`radiususer` | RADIUS proxy username | no
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
|
|||||||
10
README.md
10
README.md
@@ -38,6 +38,7 @@ Features
|
|||||||
* Modules for idview management
|
* Modules for idview management
|
||||||
* Modules for location management
|
* Modules for location management
|
||||||
* Modules for netgroup management
|
* Modules for netgroup management
|
||||||
|
* Modules for passkeyconfig management
|
||||||
* Modules for permission management
|
* Modules for permission management
|
||||||
* Modules for privilege management
|
* Modules for privilege management
|
||||||
* Modules for pwpolicy management
|
* Modules for pwpolicy management
|
||||||
@@ -50,6 +51,7 @@ Features
|
|||||||
* Modules for sudocmd management
|
* Modules for sudocmd management
|
||||||
* Modules for sudocmdgroup management
|
* Modules for sudocmdgroup management
|
||||||
* Modules for sudorule management
|
* Modules for sudorule management
|
||||||
|
* Modules for sysaccount management
|
||||||
* Modules for topology management
|
* Modules for topology management
|
||||||
* Modules for trust management
|
* Modules for trust management
|
||||||
* Modules for user management
|
* Modules for user management
|
||||||
@@ -66,7 +68,7 @@ Supported Distributions
|
|||||||
-----------------------
|
-----------------------
|
||||||
|
|
||||||
* RHEL/CentOS 7.4+
|
* RHEL/CentOS 7.4+
|
||||||
* Fedora 26+
|
* Fedora 40+
|
||||||
* Ubuntu
|
* Ubuntu
|
||||||
* Debian 10+ (ipaclient only, no server or replica!)
|
* Debian 10+ (ipaclient only, no server or replica!)
|
||||||
|
|
||||||
@@ -74,7 +76,7 @@ Requirements
|
|||||||
------------
|
------------
|
||||||
|
|
||||||
**Controller**
|
**Controller**
|
||||||
* Ansible version: 2.15+
|
* Ansible version: 2.14+
|
||||||
|
|
||||||
**Node**
|
**Node**
|
||||||
* Supported FreeIPA version (see above)
|
* Supported FreeIPA version (see above)
|
||||||
@@ -125,7 +127,7 @@ ansible-freeipa/plugins/module_utils to ~/.ansible/plugins/
|
|||||||
|
|
||||||
**RPM package**
|
**RPM package**
|
||||||
|
|
||||||
There are RPM packages available for Fedora 29+. These are installing the roles and modules into the global Ansible directories for `roles`, `plugins/modules` and `plugins/module_utils` in the `/usr/share/ansible` directory. Therefore is it possible to use the roles and modules without adapting the names like it is done in the example playbooks.
|
There are RPM packages available for Fedora. These are installing the roles and modules into the global Ansible directories for `roles`, `plugins/modules` and `plugins/module_utils` in the `/usr/share/ansible` directory. Therefore is it possible to use the roles and modules without adapting the names like it is done in the example playbooks.
|
||||||
|
|
||||||
**Ansible Galaxy**
|
**Ansible Galaxy**
|
||||||
|
|
||||||
@@ -453,6 +455,7 @@ Modules in plugin/modules
|
|||||||
* [idview](README-idview.md)
|
* [idview](README-idview.md)
|
||||||
* [ipalocation](README-location.md)
|
* [ipalocation](README-location.md)
|
||||||
* [ipanetgroup](README-netgroup.md)
|
* [ipanetgroup](README-netgroup.md)
|
||||||
|
* [ipapasskeyconfig](README-passkeyconfig.md)
|
||||||
* [ipapermission](README-permission.md)
|
* [ipapermission](README-permission.md)
|
||||||
* [ipaprivilege](README-privilege.md)
|
* [ipaprivilege](README-privilege.md)
|
||||||
* [ipapwpolicy](README-pwpolicy.md)
|
* [ipapwpolicy](README-pwpolicy.md)
|
||||||
@@ -465,6 +468,7 @@ Modules in plugin/modules
|
|||||||
* [ipasudocmd](README-sudocmd.md)
|
* [ipasudocmd](README-sudocmd.md)
|
||||||
* [ipasudocmdgroup](README-sudocmdgroup.md)
|
* [ipasudocmdgroup](README-sudocmdgroup.md)
|
||||||
* [ipasudorule](README-sudorule.md)
|
* [ipasudorule](README-sudorule.md)
|
||||||
|
* [ipasysaccount](README-sysaccount.md)
|
||||||
* [ipatopologysegment](README-topology.md)
|
* [ipatopologysegment](README-topology.md)
|
||||||
* [ipatopologysuffix](README-topology.md)
|
* [ipatopologysuffix](README-topology.md)
|
||||||
* [ipatrust](README-trust.md)
|
* [ipatrust](README-trust.md)
|
||||||
|
|||||||
73
infra/azure/azure-pipelines.yml
Normal file
73
infra/azure/azure-pipelines.yml
Normal file
@@ -0,0 +1,73 @@
|
|||||||
|
---
|
||||||
|
trigger:
|
||||||
|
- master
|
||||||
|
|
||||||
|
pool:
|
||||||
|
vmImage: 'ubuntu-24.04'
|
||||||
|
|
||||||
|
variables:
|
||||||
|
ansible_version: "-core >=2.18,<2.19"
|
||||||
|
ansible_latest: "-core"
|
||||||
|
ansible_minimum: "-core <2.16"
|
||||||
|
distros: "fedora-latest,c9s,c10s,fedora-rawhide"
|
||||||
|
|
||||||
|
stages:
|
||||||
|
|
||||||
|
- stage: fedora_latest_ansible_latest
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: fedora-latest
|
||||||
|
ansible_version: ${{ variables.ansible_latest }}
|
||||||
|
skip_git_test: true
|
||||||
|
|
||||||
|
- stage: fedora_latest_ansible_2_15
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: fedora-latest
|
||||||
|
ansible_version: ${{ variables.ansbile_minimum }}
|
||||||
|
skip_git_test: true
|
||||||
|
|
||||||
|
# Supported distros
|
||||||
|
|
||||||
|
- ${{ each distro in split(variables.distros, ',') }}:
|
||||||
|
- stage: ${{ replace(distro, '-', '_') }}_ansible_2_18
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: ${{ distro }}
|
||||||
|
ansible_version: ${{ variables.ansible_version }}
|
||||||
|
skip_git_test: true
|
||||||
|
test_galaxy: false
|
||||||
|
|
||||||
|
# Galaxy on Fedora
|
||||||
|
|
||||||
|
- stage: galaxy_fedora_latest_ansible_2_18
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: fedora-latest
|
||||||
|
ansible_version: ${{ variables.ansible_version }}
|
||||||
|
skip_git_test: true
|
||||||
|
test_galaxy: true
|
||||||
|
|
||||||
|
# CentOS 8 Stream, latest supported Ansible version.
|
||||||
|
|
||||||
|
- stage: c8s_ansible_2_16
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: c8s
|
||||||
|
ansible_version: "-core <2.17"
|
||||||
|
skip_git_test: true
|
||||||
35
infra/azure/build-containers.yml
Normal file
35
infra/azure/build-containers.yml
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
---
|
||||||
|
schedules:
|
||||||
|
- cron: "0 0 * * 0"
|
||||||
|
displayName: Weekly Sunday midnight build
|
||||||
|
branches:
|
||||||
|
include:
|
||||||
|
- master
|
||||||
|
always: true
|
||||||
|
|
||||||
|
trigger: none
|
||||||
|
|
||||||
|
pool:
|
||||||
|
vmImage: 'ubuntu-24.04'
|
||||||
|
|
||||||
|
variables: { distros: "fedora-latest,fedora-rawhide,c9s,c10s" }
|
||||||
|
|
||||||
|
stages:
|
||||||
|
|
||||||
|
- ${{ each distro in split(variables.distros, ',') }}:
|
||||||
|
- stage: build_${{ join('_', split(distro, '-')) }}
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/build_container.yml
|
||||||
|
parameters:
|
||||||
|
distro: ${{ distro }}
|
||||||
|
|
||||||
|
# Special case for CentOS 8 Stream
|
||||||
|
- stage: CentOS_8_Stream
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/build_container.yml
|
||||||
|
parameters:
|
||||||
|
distro: c8s
|
||||||
|
# ansible-core 2.17+ cannot be used to deploy on CentOS 8 Stream.
|
||||||
|
ansible_core_version: "<2.17"
|
||||||
104
infra/azure/nightly.yml
Normal file
104
infra/azure/nightly.yml
Normal file
@@ -0,0 +1,104 @@
|
|||||||
|
---
|
||||||
|
schedules:
|
||||||
|
- cron: "0 19 * * *"
|
||||||
|
displayName: Nightly Builds
|
||||||
|
branches:
|
||||||
|
include:
|
||||||
|
- master
|
||||||
|
always: true
|
||||||
|
|
||||||
|
trigger: none
|
||||||
|
|
||||||
|
pool:
|
||||||
|
vmImage: 'ubuntu-24.04'
|
||||||
|
|
||||||
|
parameters:
|
||||||
|
# Not really a parameter, but variables cannot be arrays or dicts
|
||||||
|
# This maps the distro LATEST version to the avaiable ansible-core
|
||||||
|
# version of the latest released compose.
|
||||||
|
- name: "distro_ansible_map"
|
||||||
|
type: object
|
||||||
|
default:
|
||||||
|
- { distro: "c8s", ansible_version: "<2.17", version_name: "2.16" }
|
||||||
|
# c9s should use 2.14, but this version has an invalid certificate
|
||||||
|
# and so is unsuable against ansible-galaxy.
|
||||||
|
- { distro: "c9s", ansible_version: "<2.17", version_name: "2.16" }
|
||||||
|
- { distro: "c10s", ansible_version: "<2.17", version_name: "2.16" }
|
||||||
|
|
||||||
|
variables:
|
||||||
|
distros: "fedora-latest,c10s,c9s,fedora-rawhide"
|
||||||
|
ansible_version: "-core >=2.18,<2.19"
|
||||||
|
ansible_latest: "-core"
|
||||||
|
ansible_minimum: "-core <2.16"
|
||||||
|
|
||||||
|
stages:
|
||||||
|
|
||||||
|
# Minimum ansible
|
||||||
|
|
||||||
|
- ${{ each distro in split(variables.distros, ',') }}:
|
||||||
|
- stage: ${{ replace(distro, '-', '_') }}_ansible_2_15
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: fedora-latest
|
||||||
|
ansible_version: ${{ variables.ansible_minimum }}
|
||||||
|
skip_git_test: true
|
||||||
|
test_galaxy: false
|
||||||
|
|
||||||
|
# Latest ansible
|
||||||
|
|
||||||
|
- ${{ each distro in split(variables.distros, ',') }}:
|
||||||
|
- stage: ${{ replace(distro, '-', '_') }}_ansible_latest
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: ${{ distro }}
|
||||||
|
ansible_version: ${{ variables.ansible_latest }}
|
||||||
|
skip_git_test: true
|
||||||
|
test_galaxy: false
|
||||||
|
|
||||||
|
# Galaxy with Latest ansible
|
||||||
|
|
||||||
|
- ${{ each distro in split(variables.distros, ',') }}:
|
||||||
|
- stage: galaxy_${{ replace(distro, '-', '_') }}_ansible_latest
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: ${{ distro }}
|
||||||
|
ansible_version: ${{ variables.ansible_latest }}
|
||||||
|
skip_git_test: true
|
||||||
|
test_galaxy: true
|
||||||
|
|
||||||
|
# Test with pinned ansible version for the distro
|
||||||
|
|
||||||
|
- ${{ each config in parameters.distro_ansible_map }}:
|
||||||
|
- stage: ${{ config.distro }}_distro_ansible_${{ replace(config.version_name, '.', '_') }}
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: ${{ config.distro }}
|
||||||
|
ansible_version: -core${{ config.ansible_version }}
|
||||||
|
skip_git_test: true
|
||||||
|
test_galaxy: false
|
||||||
|
|
||||||
|
# Test Galaxy collection with pinned ansible version for the distro
|
||||||
|
|
||||||
|
- ${{ each config in parameters.distro_ansible_map }}:
|
||||||
|
- stage: galaxy_${{ config.distro }}_distro_ansible_${{ replace(config.version_name, '.', '_') }}
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/group_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: ${{ config.distro }}
|
||||||
|
ansible_version: -core${{ config.ansible_version }}
|
||||||
|
skip_git_test: true
|
||||||
|
test_galaxy: true
|
||||||
67
infra/azure/pr-pipeline.yml
Normal file
67
infra/azure/pr-pipeline.yml
Normal file
@@ -0,0 +1,67 @@
|
|||||||
|
---
|
||||||
|
trigger:
|
||||||
|
- master
|
||||||
|
|
||||||
|
pool:
|
||||||
|
vmImage: 'ubuntu-24.04'
|
||||||
|
|
||||||
|
parameters:
|
||||||
|
# Not really a parameter, but variables cannot be arrays or dicts
|
||||||
|
# This maps the distro LATEST version to the avaiable ansible-core
|
||||||
|
# version of the latest released compose.
|
||||||
|
- name: "distro_ansible_map"
|
||||||
|
type: object
|
||||||
|
default:
|
||||||
|
- { distro: "c8s", ansible_version: "<2.17", version_name: "2.16" }
|
||||||
|
# c9s should use 2.14, but this version has an invalid certificate
|
||||||
|
# and so is unsuable against ansible-galaxy.
|
||||||
|
- { distro: "c9s", ansible_version: "<2.17", version_name: "2.16" }
|
||||||
|
- { distro: "c10s", ansible_version: "<2.17", version_name: "2.16" }
|
||||||
|
|
||||||
|
variables:
|
||||||
|
distros: "fedora-latest,c10s,c9s,fedora-rawhide"
|
||||||
|
ansible_version: "-core >=2.18,<2.19"
|
||||||
|
|
||||||
|
stages:
|
||||||
|
|
||||||
|
# Test with repository in all "current" distros
|
||||||
|
|
||||||
|
- ${{ each distro in split(variables.distros, ',') }}:
|
||||||
|
- stage: ${{ replace(distro, '-', '_') }}_ansible_2_18
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/run_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: ${{ distro }}
|
||||||
|
ansible_version: ${{ variables.ansible_version }}
|
||||||
|
skip_git_test: false
|
||||||
|
test_galaxy: false
|
||||||
|
|
||||||
|
# Galaxy on Fedora
|
||||||
|
|
||||||
|
- stage: galaxy_fedora_latest_ansible_2_18
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/run_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: fedora-latest
|
||||||
|
ansible_version: ${{ variables.ansible_version }}
|
||||||
|
skip_git_test: false
|
||||||
|
test_galaxy: true
|
||||||
|
|
||||||
|
|
||||||
|
# Test with pinned ansible version for the distro
|
||||||
|
|
||||||
|
- ${{ each config in parameters.distro_ansible_map }}:
|
||||||
|
- stage: ${{ config.distro }}_distro_ansible_${{ replace(config.version_name, '.', '_') }}
|
||||||
|
dependsOn: []
|
||||||
|
jobs:
|
||||||
|
- template: templates/run_tests.yml
|
||||||
|
parameters:
|
||||||
|
build_number: $(Build.BuildNumber)
|
||||||
|
distro: ${{ config.distro }}
|
||||||
|
ansible_version: -core${{ config.ansible_version }}
|
||||||
|
skip_git_test: false
|
||||||
|
test_galaxy: false
|
||||||
@@ -159,7 +159,7 @@ def map_test_module_sources(base):
|
|||||||
"""Create a map of 'test-modules' to 'plugin-sources', from 'base'."""
|
"""Create a map of 'test-modules' to 'plugin-sources', from 'base'."""
|
||||||
# Find root directory of playbook tests.
|
# Find root directory of playbook tests.
|
||||||
script_dir = os.path.dirname(__file__)
|
script_dir = os.path.dirname(__file__)
|
||||||
test_root = os.path.realpath(os.path.join(script_dir, f"../{base}"))
|
test_root = os.path.realpath(os.path.join(script_dir, f"../../../{base}"))
|
||||||
# create modules:source_files map
|
# create modules:source_files map
|
||||||
_result = {}
|
_result = {}
|
||||||
for test_module in [d for d in os.scandir(test_root) if d.is_dir()]:
|
for test_module in [d for d in os.scandir(test_root) if d.is_dir()]:
|
||||||
@@ -170,7 +170,7 @@ def map_test_module_sources(base):
|
|||||||
|
|
||||||
|
|
||||||
def usage(err=0):
|
def usage(err=0):
|
||||||
print("filter_plugins.py [-h|--help] [-p|--pytest] PY_SRC...")
|
print("get_test_modules.py [-h|--help] [-p|--pytest] PY_SRC...")
|
||||||
print(
|
print(
|
||||||
"""
|
"""
|
||||||
Print a comma-separated list of modules that should be tested if
|
Print a comma-separated list of modules that should be tested if
|
||||||
67
infra/azure/scripts/set_test_modules
Normal file
67
infra/azure/scripts/set_test_modules
Normal file
@@ -0,0 +1,67 @@
|
|||||||
|
#!/bin/bash -eu
|
||||||
|
# This file shoud be source'd (. set_test_modules) rather than executed.
|
||||||
|
#
|
||||||
|
# Set SKIP_GIT_TEST="True" or use -a to prevent git modification comparison.
|
||||||
|
#
|
||||||
|
|
||||||
|
RED="\033[31;1m"
|
||||||
|
RST="\033[0m"
|
||||||
|
|
||||||
|
die() {
|
||||||
|
echo -e "${RED}${*}${RST}" >&2
|
||||||
|
}
|
||||||
|
|
||||||
|
BASEDIR="$(readlink -f "$(dirname "${BASH_SOURCE[0]}")")"
|
||||||
|
TOPDIR="$(readlink -f "${BASEDIR}/../../..")"
|
||||||
|
|
||||||
|
[ -n "$(command -v python3)" ] && python="$(command -v python3)" || python="$(command -v python2)"
|
||||||
|
|
||||||
|
pushd "${TOPDIR}" >/dev/null 2>&1 || die "Failed to change directory."
|
||||||
|
|
||||||
|
SKIP_GIT_TEST=${SKIP_GIT_TEST:-"False"}
|
||||||
|
|
||||||
|
while getopts ":a" opt
|
||||||
|
do
|
||||||
|
case "${opt}" in
|
||||||
|
a) SKIP_GIT_TEST="True" ;;
|
||||||
|
*) ;; # ignore other options
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
files_list=$(mktemp)
|
||||||
|
|
||||||
|
enabled_modules="None"
|
||||||
|
enabled_tests="None"
|
||||||
|
|
||||||
|
if [ "${SKIP_GIT_TEST}" != "True" ]
|
||||||
|
then
|
||||||
|
remote="$(basename "$(mktemp -u remote_XXXXXX)")"
|
||||||
|
git remote add "${remote}" https://github.com/freeipa/ansible-freeipa
|
||||||
|
git fetch --prune --no-tags --quiet "${remote}"
|
||||||
|
git diff "${remote}/master" --name-only > "${files_list}"
|
||||||
|
git remote remove "${remote}"
|
||||||
|
|
||||||
|
# shellcheck disable=SC2046
|
||||||
|
enabled_modules="$(${python} "${BASEDIR}/get_test_modules.py" $(cat "${files_list}"))"
|
||||||
|
[ -z "${enabled_modules}" ] && enabled_modules="None"
|
||||||
|
|
||||||
|
# Get individual tests that should be executed
|
||||||
|
mapfile -t tests < <(sed -n 's#.*/\(test_[^/]*\).yml#\1#p' "${files_list}" | tr -d " ")
|
||||||
|
[ ${#tests[@]} -gt 0 ] && enabled_tests=$(IFS=, ; echo "${tests[*]}")
|
||||||
|
[ -z "${enabled_tests}" ] && enabled_tests="None"
|
||||||
|
|
||||||
|
[ -n "${enabled_tests}" ] && IPA_ENABLED_TESTS="${enabled_tests},${IPA_ENABLED_TESTS}"
|
||||||
|
[ -n "${enabled_modules}" ] && IPA_ENABLED_MODULES="${enabled_modules},${IPA_ENABLED_MODULES}"
|
||||||
|
|
||||||
|
rm -f "${files_list}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Get all modules that should have tests executed
|
||||||
|
|
||||||
|
export IPA_ENABLED_MODULES
|
||||||
|
export IPA_ENABLED_TESTS
|
||||||
|
|
||||||
|
echo "IPA_ENABLED_MODULES = [${IPA_ENABLED_MODULES}]"
|
||||||
|
echo "IPA_ENABLED_TESTS = [${IPA_ENABLED_TESTS}]"
|
||||||
|
|
||||||
|
popd >/dev/null 2>&1 || die "Failed to change back to original directory."
|
||||||
45
infra/azure/templates/build_container.yml
Normal file
45
infra/azure/templates/build_container.yml
Normal file
@@ -0,0 +1,45 @@
|
|||||||
|
---
|
||||||
|
parameters:
|
||||||
|
- name: distro
|
||||||
|
type: string
|
||||||
|
- name: python_version
|
||||||
|
type: string
|
||||||
|
default: 3.x
|
||||||
|
- name: ansible_core_version
|
||||||
|
default: ""
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
- job: BuildTestImage_${{ join('_', split(parameters.distro, '-')) }}
|
||||||
|
displayName: Build ${{ parameters.distro }} test container
|
||||||
|
steps:
|
||||||
|
- task: UsePythonVersion@0
|
||||||
|
inputs:
|
||||||
|
versionSpec: '${{ parameters.python_version }}'
|
||||||
|
|
||||||
|
- script: python -m pip install --upgrade pip "ansible-core${{ parameters.ansible_core_version }}"
|
||||||
|
retryCountOnTaskFailure: 5
|
||||||
|
displayName: Install tools
|
||||||
|
|
||||||
|
- script: ansible-galaxy collection install containers.podman
|
||||||
|
displayName: Install Ansible Galaxy collections
|
||||||
|
|
||||||
|
- script: infra/image/build.sh -s ${{ parameters.distro }}
|
||||||
|
displayName: Build ${{ parameters.distro }} base image
|
||||||
|
env:
|
||||||
|
ANSIBLE_ROLES_PATH: "${PWD}/roles"
|
||||||
|
ANSIBLE_LIBRARY: "${PWD}/plugins/modules"
|
||||||
|
ANSIBLE_MODULE_UTILS: "${PWD}/plugins/module_utils"
|
||||||
|
|
||||||
|
- script: podman login -u="$QUAY_ROBOT_USERNAME" -p="$QUAY_ROBOT_TOKEN" quay.io
|
||||||
|
displayName: Registry login
|
||||||
|
env:
|
||||||
|
# Secrets needs to be mapped as env vars to work properly
|
||||||
|
QUAY_ROBOT_TOKEN: $(QUAY_ROBOT_TOKEN)
|
||||||
|
|
||||||
|
- script: |
|
||||||
|
podman push quay.io/ansible-freeipa/upstream-tests:${{parameters.distro}}-base quay.io/ansible-freeipa/upstream-tests:${{ parameters.distro }}-base
|
||||||
|
displayName: Push base image
|
||||||
|
|
||||||
|
- script: |
|
||||||
|
podman push quay.io/ansible-freeipa/upstream-tests:${{ parameters.distro }}-server quay.io/ansible-freeipa/upstream-tests:${{ parameters.distro }}-server
|
||||||
|
displayName: Push server image
|
||||||
30
infra/azure/templates/group_tests.yml
Normal file
30
infra/azure/templates/group_tests.yml
Normal file
@@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
parameters:
|
||||||
|
- name: distro
|
||||||
|
type: string
|
||||||
|
default: fedora-latest
|
||||||
|
- name: build_number
|
||||||
|
type: string
|
||||||
|
- name: ansible_version
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
- name: skip_git_test
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
- name: test_galaxy
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
|
||||||
|
- ${{ each group in split('1,2,3', ',') }}:
|
||||||
|
- template: run_tests.yml
|
||||||
|
parameters:
|
||||||
|
group_number: ${{ group }}
|
||||||
|
number_of_groups: 3
|
||||||
|
build_number: ${{ parameters.build_number }}
|
||||||
|
distro: ${{ parameters.distro }}
|
||||||
|
ansible_version: ${{ parameters.ansible_version }}
|
||||||
|
python_version: '< 3.12'
|
||||||
|
skip_git_test: ${{ parameters.skip_git_test }}
|
||||||
|
test_galaxy: ${{ parameters.test_galaxy }}
|
||||||
30
infra/azure/templates/prepare_environment.yaml
Normal file
30
infra/azure/templates/prepare_environment.yaml
Normal file
@@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
parameters:
|
||||||
|
- name: distro
|
||||||
|
type: string
|
||||||
|
default: fedora-latest
|
||||||
|
- name: ansible_version
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
- name: python_version
|
||||||
|
type: string
|
||||||
|
default: 3.x
|
||||||
|
- name: build_number
|
||||||
|
type: string
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- task: UsePythonVersion@0
|
||||||
|
inputs:
|
||||||
|
versionSpec: '${{ parameters.python_version }}'
|
||||||
|
|
||||||
|
- script: |
|
||||||
|
pip install "ansible${{ parameters.ansible_version }}" -r requirements-tests.txt
|
||||||
|
retryCountOnTaskFailure: 5
|
||||||
|
displayName: Install test dependencies
|
||||||
|
|
||||||
|
- script: ansible-galaxy collection install -r requirements-podman.yml
|
||||||
|
retryCountOnTaskFailure: 5
|
||||||
|
displayName: Install Ansible collections
|
||||||
|
|
||||||
|
- script: infra/image/start.sh ${{ parameters.distro }}-server
|
||||||
|
displayName: Setup target container for ${{ parameters.distro }}
|
||||||
98
infra/azure/templates/run_tests.yml
Normal file
98
infra/azure/templates/run_tests.yml
Normal file
@@ -0,0 +1,98 @@
|
|||||||
|
---
|
||||||
|
parameters:
|
||||||
|
- name: group_number
|
||||||
|
type: number
|
||||||
|
default: 1
|
||||||
|
- name: number_of_groups
|
||||||
|
type: number
|
||||||
|
default: 1
|
||||||
|
- name: distro
|
||||||
|
type: string
|
||||||
|
default: fedora-latest
|
||||||
|
- name: ansible_version
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
- name: python_version
|
||||||
|
type: string
|
||||||
|
default: 3.x
|
||||||
|
- name: build_number
|
||||||
|
type: string
|
||||||
|
- name: skip_git_test
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
- name: test_type
|
||||||
|
type: string
|
||||||
|
default: "playbook"
|
||||||
|
- name: test_galaxy
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
- job: Test_Group${{ parameters.group_number }}
|
||||||
|
displayName: Run playbook tests ${{ parameters.distro }} (${{ parameters.group_number }}/${{ parameters.number_of_groups }})
|
||||||
|
timeoutInMinutes: 360
|
||||||
|
variables:
|
||||||
|
- template: variables.yaml
|
||||||
|
- template: variables_${{ parameters.distro }}.yaml
|
||||||
|
steps:
|
||||||
|
- template: prepare_environment.yaml
|
||||||
|
parameters:
|
||||||
|
build_number: ${{ parameters.build_number }}
|
||||||
|
distro: ${{ parameters.distro }}
|
||||||
|
ansible_version: ${{ parameters.ansible_version }}
|
||||||
|
python_version: ${{ parameters.python_version }}
|
||||||
|
|
||||||
|
- bash: echo "##vso[task.setvariable variable=TOPDIR]${PWD}"
|
||||||
|
displayName: Set repo rootdir
|
||||||
|
|
||||||
|
- script: |
|
||||||
|
. "${TOPDIR}/infra/azure/scripts/set_test_modules"
|
||||||
|
python3 utils/check_test_configuration.py ${{ parameters.distro }}
|
||||||
|
displayName: Check test configuration
|
||||||
|
env:
|
||||||
|
SKIP_GIT_TEST: ${{ parameters.skip_git_test }}
|
||||||
|
|
||||||
|
- script: |
|
||||||
|
git fetch --unshallow
|
||||||
|
utils/build-collection.sh -i rpm
|
||||||
|
retryCountOnTaskFailure: 5
|
||||||
|
displayName: Build Galaxy release
|
||||||
|
condition: ${{ parameters.test_galaxy }}
|
||||||
|
|
||||||
|
- script: |
|
||||||
|
echo "PWD: ${PWD}"
|
||||||
|
echo "TOPDIR: ${TOPDIR}"
|
||||||
|
echo "ROLES: ${ANSIBLE_ROLES_PATH}"
|
||||||
|
echo "LIBRARY: ${ANSIBLE_LIBRARY}"
|
||||||
|
echo "MODULE_UTILS: ${ANSIBLE_MODULE_UTILS}"
|
||||||
|
. "${TOPDIR}/infra/azure/scripts/set_test_modules"
|
||||||
|
[ "${{ parameters.test_galaxy }}" == "True" ] && cd ~/.ansible/collections/ansible_collections/freeipa/ansible_freeipa
|
||||||
|
pytest \
|
||||||
|
-m "${{ parameters.test_type }}" \
|
||||||
|
--verbose \
|
||||||
|
--color=yes \
|
||||||
|
--splits=${{ parameters.number_of_groups }} \
|
||||||
|
--group=${{ parameters.group_number }} \
|
||||||
|
--randomly-seed=$(date "+%Y%m%d") \
|
||||||
|
--suppress-no-test-exit-code \
|
||||||
|
--junit-xml=TEST-results-pr-check.xml
|
||||||
|
displayName: Run playbook tests
|
||||||
|
env:
|
||||||
|
SKIP_GIT_TEST: ${{ parameters.skip_git_test }}
|
||||||
|
${{ if not(parameters.test_galaxy) }}:
|
||||||
|
ANSIBLE_ROLES_PATH: "${PWD}/roles"
|
||||||
|
ANSIBLE_LIBRARY: "${PWD}/plugins"
|
||||||
|
ANSIBLE_MODULE_UTILS: "${PWD}/plugins/module_utils"
|
||||||
|
IPA_SERVER_HOST: ansible-freeipa-tests
|
||||||
|
RUN_TESTS_IN_DOCKER: podman
|
||||||
|
IPA_DISABLED_MODULES: ${{ variables.ipa_disabled_modules }}
|
||||||
|
IPA_DISABLED_TESTS: ${{ variables.ipa_disabled_tests }}
|
||||||
|
IPA_ENABLED_MODULES: ${{ variables.ipa_enabled_modules }}
|
||||||
|
IPA_ENABLED_TESTS: ${{ variables.ipa_enabled_tests }}
|
||||||
|
IPA_VERBOSITY: "-vvv"
|
||||||
|
|
||||||
|
- task: PublishTestResults@2
|
||||||
|
inputs:
|
||||||
|
mergeTestResults: true
|
||||||
|
testRunTitle: PlaybookTests-Build${{ parameters.build_number }}
|
||||||
|
condition: succeededOrFailed()
|
||||||
21
infra/azure/templates/variables_c9s.yaml
Normal file
21
infra/azure/templates/variables_c9s.yaml
Normal file
@@ -0,0 +1,21 @@
|
|||||||
|
#
|
||||||
|
# Variables must be defined as comma separated lists.
|
||||||
|
# For easier management of items to enable/disable,
|
||||||
|
# use one test/module on each line, followed by a comma.
|
||||||
|
#
|
||||||
|
# Example:
|
||||||
|
#
|
||||||
|
# ipa_disabled_modules: >-
|
||||||
|
# dnsconfig,
|
||||||
|
# group,
|
||||||
|
# hostgroup
|
||||||
|
#
|
||||||
|
# If no variables are set, set "empty: true" as at least
|
||||||
|
# one item is needed in the set.
|
||||||
|
---
|
||||||
|
variables:
|
||||||
|
empty: true
|
||||||
|
# ipa_enabled_modules: >-
|
||||||
|
# ipa_enabled_tests: >-
|
||||||
|
# ipa_disabled_modules: >-
|
||||||
|
# ipa_disabled_tests: >-
|
||||||
15
infra/image/build-inventory
Normal file
15
infra/image/build-inventory
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
[ipaserver]
|
||||||
|
ansible-freeipa-image-builder ansible_connection=podman
|
||||||
|
|
||||||
|
[ipaserver:vars]
|
||||||
|
ipaadmin_password=SomeADMINpassword
|
||||||
|
ipadm_password=SomeDMpassword
|
||||||
|
ipaserver_domain=test.local
|
||||||
|
ipaserver_realm=TEST.LOCAL
|
||||||
|
ipaserver_setup_dns=true
|
||||||
|
ipaserver_auto_forwarders=true
|
||||||
|
ipaserver_no_dnssec_validation=true
|
||||||
|
ipaserver_auto_reverse=true
|
||||||
|
ipaserver_setup_kra=true
|
||||||
|
ipaserver_setup_firewalld=false
|
||||||
|
ipaclient_no_ntp=true
|
||||||
130
infra/image/build.sh
Executable file
130
infra/image/build.sh
Executable file
@@ -0,0 +1,130 @@
|
|||||||
|
#!/bin/bash -eu
|
||||||
|
|
||||||
|
BASEDIR="$(readlink -f "$(dirname "$0")")"
|
||||||
|
TOPDIR="$(readlink -f "${BASEDIR}/../..")"
|
||||||
|
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. "${BASEDIR}/shcontainer"
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. "${TOPDIR}/utils/shfun"
|
||||||
|
|
||||||
|
valid_distro() {
|
||||||
|
find "${BASEDIR}/dockerfile" -type f -printf "%f\n" | tr "\n" " "
|
||||||
|
}
|
||||||
|
|
||||||
|
usage() {
|
||||||
|
local prog="${0##*/}"
|
||||||
|
cat << EOF
|
||||||
|
usage: ${prog} [-h] [-n HOSTNAME] [-s] distro
|
||||||
|
${prog} build a container image to test ansible-freeipa.
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
|
||||||
|
help() {
|
||||||
|
cat << EOF
|
||||||
|
positional arguments:
|
||||||
|
|
||||||
|
distro The base distro to build the test container.
|
||||||
|
Availble distros: $(valid_distro)
|
||||||
|
|
||||||
|
optional arguments:
|
||||||
|
|
||||||
|
-n HOSTNAME Container hostname
|
||||||
|
-p Give extended privileges to the container
|
||||||
|
-s Deploy IPA server
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
|
||||||
|
name="ansible-freeipa-image-builder"
|
||||||
|
hostname="ipaserver.test.local"
|
||||||
|
cpus="2"
|
||||||
|
memory="3g"
|
||||||
|
quayname="quay.io/ansible-freeipa/upstream-tests"
|
||||||
|
deploy_server="N"
|
||||||
|
deploy_capabilities="SYS_ADMIN,SYSLOG"
|
||||||
|
capabilities=""
|
||||||
|
|
||||||
|
while getopts ":hn:s" option
|
||||||
|
do
|
||||||
|
case "${option}" in
|
||||||
|
h) help && exit 0 ;;
|
||||||
|
n) hostname="${OPTARG}" ;;
|
||||||
|
s) deploy_server="Y" ;;
|
||||||
|
*) die -u "Invalid option: ${option}" ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
shift $((OPTIND - 1))
|
||||||
|
distro=${1:-}
|
||||||
|
|
||||||
|
[ -n "${distro}" ] || die "Distro needs to be given.\nUse one of: $(valid_distro)"
|
||||||
|
|
||||||
|
[ -f "${BASEDIR}/dockerfile/${distro}" ] \
|
||||||
|
|| die "${distro} is not a valid distro target.\nUse one of: $(valid_distro)"
|
||||||
|
|
||||||
|
container_check
|
||||||
|
|
||||||
|
if [ "${deploy_server}" == "Y" ]
|
||||||
|
then
|
||||||
|
capabilities="${deploy_capabilities}"
|
||||||
|
|
||||||
|
[ -n "$(command -v "ansible-playbook")" ] || die "ansible-playbook is required to install FreeIPA."
|
||||||
|
|
||||||
|
deploy_playbook="${TOPDIR}/playbooks/install-server.yml"
|
||||||
|
[ -f "${deploy_playbook}" ] || die "Can't find playbook '${deploy_playbook}'"
|
||||||
|
|
||||||
|
inventory_file="${BASEDIR}/build-inventory"
|
||||||
|
[ -f "${inventory_file}" ] || die "Can't find inventory '${inventory_file}'"
|
||||||
|
fi
|
||||||
|
|
||||||
|
container_state=$(container_get_state "${name}")
|
||||||
|
|
||||||
|
tag="${distro}-base"
|
||||||
|
server_tag="${distro}-server"
|
||||||
|
|
||||||
|
container_remove_image_if_exists "${tag}"
|
||||||
|
[ "${deploy_server}" == "Y" ] && \
|
||||||
|
container_remove_image_if_exists "${server_tag}"
|
||||||
|
|
||||||
|
container_build "${tag}" "${BASEDIR}/dockerfile/${distro}" "${BASEDIR}"
|
||||||
|
container_create "${name}" "${tag}" \
|
||||||
|
"hostname=${hostname}" \
|
||||||
|
"memory=${memory}" \
|
||||||
|
"cpus=${cpus}" \
|
||||||
|
"${capabilities:+capabilities=$capabilities}"
|
||||||
|
container_commit "${name}" "${quayname}:${tag}"
|
||||||
|
|
||||||
|
if [ "${deploy_server}" == "Y" ]
|
||||||
|
then
|
||||||
|
deployed=false
|
||||||
|
|
||||||
|
# Set path to ansible-freeipa roles
|
||||||
|
[ -z "${ANSIBLE_ROLES_PATH:-""}" ] && export ANSIBLE_ROLES_PATH="${TOPDIR}/roles"
|
||||||
|
|
||||||
|
# Install collection containers.podman if not available
|
||||||
|
if [ -z "$(ansible-galaxy collection list containers.podman)" ]
|
||||||
|
then
|
||||||
|
tmpdir="$(mktemp -d)"
|
||||||
|
export ANSIBLE_COLLECTIONS_PATH="${tmpdir}"
|
||||||
|
ansible-galaxy collection install -p "${tmpdir}" containers.podman
|
||||||
|
fi
|
||||||
|
|
||||||
|
[ "${container_state}" != "running" ] && container_start "${name}"
|
||||||
|
|
||||||
|
container_wait_for_journald "${name}"
|
||||||
|
|
||||||
|
log info "= Deploying IPA ="
|
||||||
|
if ansible-playbook -u root -i "${inventory_file}" "${deploy_playbook}"
|
||||||
|
then
|
||||||
|
deployed=true
|
||||||
|
fi
|
||||||
|
echo
|
||||||
|
|
||||||
|
container_stop "${name}"
|
||||||
|
|
||||||
|
$deployed || die "Deployment failed"
|
||||||
|
|
||||||
|
container_commit "${name}" "${quayname}:${server_tag}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
log info "= DONE: Image created. ="
|
||||||
41
infra/image/dockerfile/c10s
Normal file
41
infra/image/dockerfile/c10s
Normal file
@@ -0,0 +1,41 @@
|
|||||||
|
FROM quay.io/centos/centos:stream10
|
||||||
|
ENV container=podman
|
||||||
|
|
||||||
|
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
||||||
|
dnf makecache; \
|
||||||
|
dnf --assumeyes install \
|
||||||
|
/usr/bin/dnf-3 \
|
||||||
|
sudo \
|
||||||
|
bash \
|
||||||
|
systemd \
|
||||||
|
procps-ng \
|
||||||
|
iproute \
|
||||||
|
hostname; \
|
||||||
|
rm -rf /var/cache/dnf/;
|
||||||
|
|
||||||
|
RUN (cd /lib/systemd/system/; \
|
||||||
|
if [ -e dbus-broker.service ] && [ ! -e dbus.service ]; then \
|
||||||
|
ln -s dbus-broker.service dbus.service; \
|
||||||
|
fi \
|
||||||
|
)
|
||||||
|
COPY system-service/container-ipa.target /lib/systemd/system/
|
||||||
|
RUN systemctl set-default container-ipa.target
|
||||||
|
RUN (cd /etc/systemd/system/; \
|
||||||
|
rm -rf multi-user.target.wants \
|
||||||
|
&& mkdir container-ipa.target.wants \
|
||||||
|
&& ln -s container-ipa.target.wants multi-user.target.wants \
|
||||||
|
)
|
||||||
|
|
||||||
|
COPY system-service/fixnet.sh /root/
|
||||||
|
COPY system-service/fixipaip.sh /root/
|
||||||
|
COPY system-service/fixnet.service /etc/systemd/system/
|
||||||
|
COPY system-service/fixipaip.service /etc/systemd/system/
|
||||||
|
RUN chmod +x /root/fixnet.sh /root/fixipaip.sh
|
||||||
|
RUN systemctl enable fixnet.service
|
||||||
|
RUN systemctl enable fixipaip.service
|
||||||
|
|
||||||
|
STOPSIGNAL RTMIN+3
|
||||||
|
|
||||||
|
VOLUME ["/sys/fs/cgroup"]
|
||||||
|
|
||||||
|
CMD ["/usr/sbin/init"]
|
||||||
46
infra/image/dockerfile/c8s
Normal file
46
infra/image/dockerfile/c8s
Normal file
@@ -0,0 +1,46 @@
|
|||||||
|
FROM quay.io/centos/centos:stream8
|
||||||
|
ENV container=podman
|
||||||
|
|
||||||
|
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
||||||
|
sed -i s/mirror.centos.org/vault.centos.org/g /etc/yum.repos.d/*.repo; \
|
||||||
|
sed -i s/^#.*baseurl=http/baseurl=http/g /etc/yum.repos.d/*.repo; \
|
||||||
|
sed -i s/^mirrorlist=http/#mirrorlist=http/g /etc/yum.repos.d/*.repo; \
|
||||||
|
dnf makecache; \
|
||||||
|
dnf --assumeyes install \
|
||||||
|
/usr/bin/dnf-3 \
|
||||||
|
sudo \
|
||||||
|
bash \
|
||||||
|
systemd \
|
||||||
|
procps-ng \
|
||||||
|
hostname \
|
||||||
|
iproute; \
|
||||||
|
dnf clean all; \
|
||||||
|
rm -rf /var/cache/dnf/;
|
||||||
|
|
||||||
|
RUN (cd /lib/systemd/system/; \
|
||||||
|
if [ -e dbus-broker.service ] && [ ! -e dbus.service ]; then \
|
||||||
|
ln -s dbus-broker.service dbus.service; \
|
||||||
|
fi \
|
||||||
|
)
|
||||||
|
COPY system-service/container-ipa.target /lib/systemd/system/
|
||||||
|
RUN systemctl set-default container-ipa.target
|
||||||
|
RUN (cd /etc/systemd/system/; \
|
||||||
|
rm -rf multi-user.target.wants \
|
||||||
|
&& mkdir container-ipa.target.wants \
|
||||||
|
&& ln -s container-ipa.target.wants multi-user.target.wants \
|
||||||
|
)
|
||||||
|
|
||||||
|
COPY system-service/fixnet.sh /root/
|
||||||
|
COPY system-service/fixipaip.sh /root/
|
||||||
|
COPY system-service/fixnet.service /etc/systemd/system/
|
||||||
|
COPY system-service/fixipaip.service /etc/systemd/system/
|
||||||
|
RUN chmod +x /root/fixnet.sh /root/fixipaip.sh
|
||||||
|
RUN systemctl enable fixnet.service
|
||||||
|
RUN systemctl enable fixipaip.service
|
||||||
|
|
||||||
|
STOPSIGNAL RTMIN+3
|
||||||
|
|
||||||
|
VOLUME ["/sys/fs/cgroup"]
|
||||||
|
|
||||||
|
CMD ["/usr/sbin/init"]
|
||||||
|
|
||||||
41
infra/image/dockerfile/c9s
Normal file
41
infra/image/dockerfile/c9s
Normal file
@@ -0,0 +1,41 @@
|
|||||||
|
FROM quay.io/centos/centos:stream9
|
||||||
|
ENV container=podman
|
||||||
|
|
||||||
|
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
||||||
|
dnf makecache; \
|
||||||
|
dnf --assumeyes install \
|
||||||
|
/usr/bin/dnf-3 \
|
||||||
|
sudo \
|
||||||
|
bash \
|
||||||
|
systemd \
|
||||||
|
procps-ng \
|
||||||
|
hostname \
|
||||||
|
iproute; \
|
||||||
|
rm -rf /var/cache/dnf/;
|
||||||
|
|
||||||
|
RUN (cd /lib/systemd/system/; \
|
||||||
|
if [ -e dbus-broker.service ] && [ ! -e dbus.service ]; then \
|
||||||
|
ln -s dbus-broker.service dbus.service; \
|
||||||
|
fi \
|
||||||
|
)
|
||||||
|
COPY system-service/container-ipa.target /lib/systemd/system/
|
||||||
|
RUN systemctl set-default container-ipa.target
|
||||||
|
RUN (cd /etc/systemd/system/; \
|
||||||
|
rm -rf multi-user.target.wants \
|
||||||
|
&& mkdir container-ipa.target.wants \
|
||||||
|
&& ln -s container-ipa.target.wants multi-user.target.wants \
|
||||||
|
)
|
||||||
|
|
||||||
|
COPY system-service/fixnet.sh /root/
|
||||||
|
COPY system-service/fixipaip.sh /root/
|
||||||
|
COPY system-service/fixnet.service /etc/systemd/system/
|
||||||
|
COPY system-service/fixipaip.service /etc/systemd/system/
|
||||||
|
RUN chmod +x /root/fixnet.sh /root/fixipaip.sh
|
||||||
|
RUN systemctl enable fixnet.service
|
||||||
|
RUN systemctl enable fixipaip.service
|
||||||
|
|
||||||
|
STOPSIGNAL RTMIN+3
|
||||||
|
|
||||||
|
VOLUME ["/sys/fs/cgroup"]
|
||||||
|
|
||||||
|
CMD ["/usr/sbin/init"]
|
||||||
44
infra/image/dockerfile/fedora-latest
Normal file
44
infra/image/dockerfile/fedora-latest
Normal file
@@ -0,0 +1,44 @@
|
|||||||
|
FROM fedora:latest
|
||||||
|
ENV container=podman
|
||||||
|
|
||||||
|
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
||||||
|
dnf makecache; \
|
||||||
|
dnf --assumeyes install \
|
||||||
|
/usr/bin/python3 \
|
||||||
|
/usr/bin/python3-config \
|
||||||
|
python3-libdnf5 \
|
||||||
|
sudo \
|
||||||
|
bash \
|
||||||
|
systemd \
|
||||||
|
procps-ng \
|
||||||
|
hostname \
|
||||||
|
iproute; \
|
||||||
|
dnf clean all; \
|
||||||
|
rm -rf /var/cache/dnf/;
|
||||||
|
|
||||||
|
RUN (cd /lib/systemd/system/; \
|
||||||
|
if [ -e dbus-broker.service ] && [ ! -e dbus.service ]; then \
|
||||||
|
ln -s dbus-broker.service dbus.service; \
|
||||||
|
fi \
|
||||||
|
)
|
||||||
|
COPY system-service/container-ipa.target /lib/systemd/system/
|
||||||
|
RUN systemctl set-default container-ipa.target
|
||||||
|
RUN (cd /etc/systemd/system/; \
|
||||||
|
rm -rf multi-user.target.wants \
|
||||||
|
&& mkdir container-ipa.target.wants \
|
||||||
|
&& ln -s container-ipa.target.wants multi-user.target.wants \
|
||||||
|
)
|
||||||
|
|
||||||
|
COPY system-service/fixnet.sh /root/
|
||||||
|
COPY system-service/fixipaip.sh /root/
|
||||||
|
COPY system-service/fixnet.service /etc/systemd/system/
|
||||||
|
COPY system-service/fixipaip.service /etc/systemd/system/
|
||||||
|
RUN chmod +x /root/fixnet.sh /root/fixipaip.sh
|
||||||
|
RUN systemctl enable fixnet.service
|
||||||
|
RUN systemctl enable fixipaip.service
|
||||||
|
|
||||||
|
STOPSIGNAL RTMIN+3
|
||||||
|
|
||||||
|
VOLUME ["/sys/fs/cgroup"]
|
||||||
|
|
||||||
|
CMD ["/usr/sbin/init"]
|
||||||
44
infra/image/dockerfile/fedora-rawhide
Normal file
44
infra/image/dockerfile/fedora-rawhide
Normal file
@@ -0,0 +1,44 @@
|
|||||||
|
FROM fedora:rawhide
|
||||||
|
ENV container=podman
|
||||||
|
|
||||||
|
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
||||||
|
dnf makecache; \
|
||||||
|
dnf --assumeyes install \
|
||||||
|
/usr/bin/python3 \
|
||||||
|
/usr/bin/python3-config \
|
||||||
|
python3-libdnf5 \
|
||||||
|
sudo \
|
||||||
|
bash \
|
||||||
|
systemd \
|
||||||
|
procps-ng \
|
||||||
|
hostname \
|
||||||
|
iproute; \
|
||||||
|
dnf clean all; \
|
||||||
|
rm -rf /var/cache/dnf/;
|
||||||
|
|
||||||
|
RUN (cd /lib/systemd/system/; \
|
||||||
|
if [ -e dbus-broker.service ] && [ ! -e dbus.service ]; then \
|
||||||
|
ln -s dbus-broker.service dbus.service; \
|
||||||
|
fi \
|
||||||
|
)
|
||||||
|
COPY system-service/container-ipa.target /lib/systemd/system/
|
||||||
|
RUN systemctl set-default container-ipa.target
|
||||||
|
RUN (cd /etc/systemd/system/; \
|
||||||
|
rm -rf multi-user.target.wants \
|
||||||
|
&& mkdir container-ipa.target.wants \
|
||||||
|
&& ln -s container-ipa.target.wants multi-user.target.wants \
|
||||||
|
)
|
||||||
|
|
||||||
|
COPY system-service/fixnet.sh /root/
|
||||||
|
COPY system-service/fixipaip.sh /root/
|
||||||
|
COPY system-service/fixnet.service /etc/systemd/system/
|
||||||
|
COPY system-service/fixipaip.service /etc/systemd/system/
|
||||||
|
RUN chmod +x /root/fixnet.sh /root/fixipaip.sh
|
||||||
|
RUN systemctl enable fixnet.service
|
||||||
|
RUN systemctl enable fixipaip.service
|
||||||
|
|
||||||
|
STOPSIGNAL RTMIN+3
|
||||||
|
|
||||||
|
VOLUME ["/sys/fs/cgroup"]
|
||||||
|
|
||||||
|
CMD ["/usr/sbin/init"]
|
||||||
6
infra/image/inventory
Normal file
6
infra/image/inventory
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
[ipaserver]
|
||||||
|
ansible-freeipa-tests ansible_connection=podman
|
||||||
|
|
||||||
|
[ipaserver:vars]
|
||||||
|
ipaadmin_password=SomeADMINpassword
|
||||||
|
ipadm_password=SomeDMpassword
|
||||||
249
infra/image/shcontainer
Normal file
249
infra/image/shcontainer
Normal file
@@ -0,0 +1,249 @@
|
|||||||
|
#!/bin/bash -eu
|
||||||
|
# This file is meant to be source'd by other scripts
|
||||||
|
|
||||||
|
SCRIPTDIR="$(dirname -- "$(readlink -f "${BASH_SOURCE[0]}")")"
|
||||||
|
TOPDIR="$(readlink -f "${SCRIPTDIR}/../..")"
|
||||||
|
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. "${SCRIPTDIR}/shdefaults"
|
||||||
|
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. "${TOPDIR}/utils/shfun"
|
||||||
|
|
||||||
|
container_create() {
|
||||||
|
local name=${1}
|
||||||
|
local image=${2}
|
||||||
|
shift 2
|
||||||
|
declare -a extra_opts
|
||||||
|
readarray -t extra_opts < \
|
||||||
|
<(sed -e "s/-/--cap-drop=/g" -e "s/+/--cap-add=/g" \
|
||||||
|
<<< "$(printf '%s\n' "${CAP_DEFAULTS[@]}")")
|
||||||
|
for opt in "$@"
|
||||||
|
do
|
||||||
|
[ -z "${opt}" ] && continue
|
||||||
|
case "${opt}" in
|
||||||
|
hostname=*) extra_opts+=("--${opt}") ;;
|
||||||
|
cpus=*) extra_opts+=("--${opt}") ;;
|
||||||
|
memory=*) extra_opts+=("--${opt}") ;;
|
||||||
|
capabilities=*) extra_opts+=("--cap-add=${opt##*=}") ;;
|
||||||
|
volume=*) extra_opts+=("--volume=${opt##*=}") ;;
|
||||||
|
*) log error "container_create: Invalid option: ${opt}" ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
# ensure default values are set
|
||||||
|
[[ " ${extra_opts[*]} " =~ " --cpus=" ]] || extra_opts+=("--cpus=2")
|
||||||
|
[[ " ${extra_opts[*]} " =~ " --hostname=" ]] \
|
||||||
|
|| extra_opts+=("--hostname=ipaserver.test.local")
|
||||||
|
|
||||||
|
log info "= Creating ${name} ="
|
||||||
|
podman create \
|
||||||
|
--security-opt label=disable \
|
||||||
|
--network bridge:interface_name=eth0 \
|
||||||
|
--systemd true \
|
||||||
|
--name "${name}" \
|
||||||
|
--memory-swap -1 \
|
||||||
|
--no-hosts \
|
||||||
|
--replace \
|
||||||
|
"${extra_opts[@]}" \
|
||||||
|
"${image}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_start() {
|
||||||
|
local name="${1}"
|
||||||
|
|
||||||
|
log info "= Starting ${name} ="
|
||||||
|
podman start "${name}"
|
||||||
|
# Add host entry to /etc/hosts
|
||||||
|
ip=$(podman inspect "${name}" --format "{{.NetworkSettings.IPAddress}}")
|
||||||
|
hostname=$(podman inspect "${name}" --format "{{.Config.Hostname}}")
|
||||||
|
if [ -n "${ip}" ] && [ -n "${hostname}" ]; then
|
||||||
|
cmd=$(cat <<EOF
|
||||||
|
sed -i -E "/\s+${hostname}(\s|$)/d" /etc/hosts
|
||||||
|
echo -e "$ip\t${hostname} ${hostname%%.*}" >> /etc/hosts
|
||||||
|
EOF
|
||||||
|
)
|
||||||
|
podman exec "${name}" bash -c "$cmd"
|
||||||
|
fi
|
||||||
|
# Ensure /etc/shadow is readable
|
||||||
|
podman exec "${name}" bash -c "chmod u+r /etc/shadow"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_stop() {
|
||||||
|
local name="${1}"
|
||||||
|
|
||||||
|
log info "= Stopping ${name} ="
|
||||||
|
podman stop "${name}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_wait_for_journald() {
|
||||||
|
local name=${1}
|
||||||
|
|
||||||
|
log info "= Waiting till systemd-journald is running ="
|
||||||
|
max=20
|
||||||
|
wait=2
|
||||||
|
count=0
|
||||||
|
while ! podman exec "${name}" ps -x | grep -q "systemd-journald"
|
||||||
|
do
|
||||||
|
if [ $count -ge $max ]; then
|
||||||
|
die "Timeout: systemd-journald is not starting up"
|
||||||
|
fi
|
||||||
|
count=$((count+1))
|
||||||
|
log info "Waiting ${wait} seconds .."
|
||||||
|
sleep ${wait}
|
||||||
|
done
|
||||||
|
log info "done"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_wait_up() {
|
||||||
|
local name="${1}"
|
||||||
|
|
||||||
|
log info "= Waiting till all services are started ="
|
||||||
|
max=20
|
||||||
|
wait=15
|
||||||
|
count=0
|
||||||
|
while podman exec "${name}" systemctl list-jobs | \
|
||||||
|
grep -qvi "no jobs running"
|
||||||
|
do
|
||||||
|
if [ $count -ge $max ]; then
|
||||||
|
die "Timeout: Services are not starting up"
|
||||||
|
fi
|
||||||
|
count=$((count+1))
|
||||||
|
log info "Waiting ${wait} seconds .."
|
||||||
|
sleep ${wait}
|
||||||
|
done
|
||||||
|
log info "done"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_build() {
|
||||||
|
local tag="${1}"
|
||||||
|
local file="${2}"
|
||||||
|
local dir="${3}"
|
||||||
|
|
||||||
|
log info "= Building ${tag} ="
|
||||||
|
podman build -t "${tag}" -f "${file}" "${dir}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_commit() {
|
||||||
|
local name="${1}"
|
||||||
|
local image="${2}"
|
||||||
|
|
||||||
|
log info "= Committing \"${image}\" ="
|
||||||
|
podman commit "${name}" "${image}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_exec() {
|
||||||
|
local name="${1}"
|
||||||
|
shift 1
|
||||||
|
|
||||||
|
# "@Q" is only needed for the log output, the exec command is properly
|
||||||
|
# working without also for args containing spaces.
|
||||||
|
log info "= Executing \"${*@Q}\" ="
|
||||||
|
podman exec -t "${name}" "${@}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_remove_image_if_exists()
|
||||||
|
{
|
||||||
|
# In older (as in Ubuntu 22.04) podman versions,
|
||||||
|
# 'podman image rm --force' fails if the image
|
||||||
|
# does not exist.
|
||||||
|
local tag_to_remove="${1}"
|
||||||
|
|
||||||
|
if podman image exists "${tag_to_remove}"
|
||||||
|
then
|
||||||
|
log info "= Cleanup ${tag_to_remove} ="
|
||||||
|
podman image rm "${tag_to_remove}" --force
|
||||||
|
echo
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
container_get_state()
|
||||||
|
{
|
||||||
|
local name="${1}"
|
||||||
|
|
||||||
|
state=$(podman ps -q --all --format "{{.State}}" --filter "name=${name}")
|
||||||
|
echo "${state}"
|
||||||
|
}
|
||||||
|
|
||||||
|
container_pull() {
|
||||||
|
local source="${1}"
|
||||||
|
|
||||||
|
image=$(podman pull "${source}")
|
||||||
|
echo "${image}"
|
||||||
|
}
|
||||||
|
|
||||||
|
container_image_list() {
|
||||||
|
local source="${1}"
|
||||||
|
|
||||||
|
# Append "$" for an exact match if the source does not end with ":" to
|
||||||
|
# search for the repo only.
|
||||||
|
if [[ ${source} != *: ]]; then
|
||||||
|
source="${source}$"
|
||||||
|
fi
|
||||||
|
image=$(podman image list --format "{{ .Repository }}:{{ .Tag }}" | \
|
||||||
|
grep "^${source}")
|
||||||
|
echo "${image}"
|
||||||
|
}
|
||||||
|
|
||||||
|
container_check() {
|
||||||
|
[ -n "$(command -v "podman")" ] || die "podman is required."
|
||||||
|
}
|
||||||
|
|
||||||
|
container_copy() {
|
||||||
|
local name="${1}"
|
||||||
|
local source="${2}"
|
||||||
|
local destination="${3}"
|
||||||
|
|
||||||
|
log info "= Copying ${source} to ${name}:${destination} ="
|
||||||
|
podman cp "${source}" "${name}:${destination}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_fetch() {
|
||||||
|
local name="${1}"
|
||||||
|
local source="${2}"
|
||||||
|
local destination="${3}"
|
||||||
|
|
||||||
|
log info "= Copying ${name}:${source} to ${destination} ="
|
||||||
|
podman cp "${name}:${source}" "${destination}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_tee() {
|
||||||
|
local name=${1}
|
||||||
|
local destination=${2}
|
||||||
|
tmpfile=$(mktemp /tmp/container-temp.XXXXXX)
|
||||||
|
|
||||||
|
log info "= Creating ${name}:${destination} from stdin ="
|
||||||
|
cat - > "${tmpfile}"
|
||||||
|
podman cp "${tmpfile}" "${name}:${destination}"
|
||||||
|
rm "${tmpfile}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_save() {
|
||||||
|
local name=${1}
|
||||||
|
|
||||||
|
archive="${name}.tar"
|
||||||
|
log info "= Saving ${name} to ${archive} ="
|
||||||
|
# podman is not able to overwrite the archive
|
||||||
|
[ -f "${archive}" ] && rm "${archive}"
|
||||||
|
podman save -o "${archive}" "${name}"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
container_load() {
|
||||||
|
local name=${1}
|
||||||
|
|
||||||
|
image_name=$(podman load -q -i "${name}" | sed -e "s/^Loaded image: //")
|
||||||
|
image=$(podman image list -q "${image_name}")
|
||||||
|
echo "$image"
|
||||||
|
}
|
||||||
11
infra/image/shdefaults
Normal file
11
infra/image/shdefaults
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
#!/bin/bash -eu
|
||||||
|
# This file is meant to be source'd by other scripts
|
||||||
|
|
||||||
|
# Set default capabilities options for freeipa containers.
|
||||||
|
# Use +CAP to add the capability and -CAP to drop the capability.
|
||||||
|
CAP_DEFAULTS=(
|
||||||
|
"+DAC_READ_SEARCH" # Required for SSSD
|
||||||
|
"+SYS_PTRACE" # Required for debugging
|
||||||
|
"+SYS_ADMIN" # Required to make dbus-brokder for systemd 258 work
|
||||||
|
# Should be "+AUDIT_WRITE", "+SETUID", "+SETGID"
|
||||||
|
)
|
||||||
95
infra/image/start.sh
Executable file
95
infra/image/start.sh
Executable file
@@ -0,0 +1,95 @@
|
|||||||
|
#!/bin/bash -eu
|
||||||
|
|
||||||
|
BASEDIR="$(readlink -f "$(dirname "$0")")"
|
||||||
|
TOPDIR="$(readlink -f "${BASEDIR}/../..")"
|
||||||
|
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. "${BASEDIR}/shcontainer"
|
||||||
|
# shellcheck disable=SC1091
|
||||||
|
. "${TOPDIR}/utils/shfun"
|
||||||
|
|
||||||
|
usage() {
|
||||||
|
local prog="${0##*/}"
|
||||||
|
cat << EOF
|
||||||
|
usage: ${prog} [-h] [-l] [-n HOSTNAME ] image
|
||||||
|
${prog} start a prebuilt ansible-freeipa test container image.
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
|
||||||
|
help() {
|
||||||
|
cat << EOF
|
||||||
|
positional arguments:
|
||||||
|
|
||||||
|
image The image to start, leave empty to get list of images
|
||||||
|
|
||||||
|
optional arguments:
|
||||||
|
|
||||||
|
-h Show this message
|
||||||
|
-l Try to use local image first, if not found download.
|
||||||
|
-n HOSTNAME Set container hostname
|
||||||
|
|
||||||
|
NOTE:
|
||||||
|
- The hostname must be the same as the hostname of the container
|
||||||
|
when FreeIPA was deployed. Use only if you built the image and
|
||||||
|
defined its hostname.
|
||||||
|
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
|
||||||
|
list_images() {
|
||||||
|
local quay_api="https://quay.io/api/v1/repository/ansible-freeipa/upstream-tests/tag"
|
||||||
|
log info "Available images on quay:"
|
||||||
|
curl --silent -L "${quay_api}" | jq '.tags[]|.name' | tr -d '"'| sort | uniq | sed "s/.*/ &/"
|
||||||
|
echo
|
||||||
|
log info "Local images (use -l):"
|
||||||
|
local_image=$(container_image_list "${repo}:")
|
||||||
|
echo "${local_image}" | sed -e "s/.*://" | sed "s/.*/ &/"
|
||||||
|
echo
|
||||||
|
}
|
||||||
|
|
||||||
|
repo="quay.io/ansible-freeipa/upstream-tests"
|
||||||
|
name="ansible-freeipa-tests"
|
||||||
|
hostname="ipaserver.test.local"
|
||||||
|
try_local_first="N"
|
||||||
|
|
||||||
|
while getopts ":hln:" option
|
||||||
|
do
|
||||||
|
case "${option}" in
|
||||||
|
h) help && exit 0 ;;
|
||||||
|
l) try_local_first="Y" ;;
|
||||||
|
n) hostname="${OPTARG}" ;;
|
||||||
|
*) die -u "Invalid option: ${option}" ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
shift $((OPTIND - 1))
|
||||||
|
image=${1:-}
|
||||||
|
|
||||||
|
container_check
|
||||||
|
|
||||||
|
if [ -z "${image}" ]; then
|
||||||
|
list_images
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
local_image=
|
||||||
|
if [ "${try_local_first}" == "Y" ]; then
|
||||||
|
log info "= Trying to use local image first ="
|
||||||
|
local_image=$(container_image_list "${repo}:${image}")
|
||||||
|
[ -n "${local_image}" ] && log info "Found ${local_image}"
|
||||||
|
echo
|
||||||
|
fi
|
||||||
|
if [ -z "${local_image}" ]; then
|
||||||
|
log info "= Downloading from quay ="
|
||||||
|
local_image=$(container_pull "${repo}:${image}")
|
||||||
|
echo
|
||||||
|
fi
|
||||||
|
|
||||||
|
[ -z "${local_image}" ] && die "Image '${image}' is not valid"
|
||||||
|
|
||||||
|
container_create "${name}" "${local_image}" "hostname=${hostname}"
|
||||||
|
container_start "${name}"
|
||||||
|
container_wait_for_journald "${name}"
|
||||||
|
container_wait_up "${name}"
|
||||||
|
|
||||||
|
log info "Container ${name} is ready to be used."
|
||||||
6
infra/image/system-service/container-ipa.target
Normal file
6
infra/image/system-service/container-ipa.target
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Minimal target for containerized FreeIPA server
|
||||||
|
DefaultDependencies=false
|
||||||
|
AllowIsolate=yes
|
||||||
|
Requires=systemd-tmpfiles-setup.service systemd-journald.service dbus.service
|
||||||
|
After=systemd-tmpfiles-setup.service systemd-journald.service dbus.service
|
||||||
13
infra/image/system-service/fixipaip.service
Normal file
13
infra/image/system-service/fixipaip.service
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Fix IPA server IP in IPA Server
|
||||||
|
After=ipa.service
|
||||||
|
PartOf=ipa.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
ExecStart=/root/fixipaip.sh
|
||||||
|
StandardOutput=journal
|
||||||
|
StandardError=journal
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=ipa.service
|
||||||
85
infra/image/system-service/fixipaip.sh
Executable file
85
infra/image/system-service/fixipaip.sh
Executable file
@@ -0,0 +1,85 @@
|
|||||||
|
#!/bin/bash -eu
|
||||||
|
|
||||||
|
function valid_fqdn()
|
||||||
|
{
|
||||||
|
local name="${1}"
|
||||||
|
|
||||||
|
[[ "${name}" =~ [[:space:]] ]] && return 1
|
||||||
|
[[ "${name}" =~ \. ]] || return 1
|
||||||
|
[[ "${name}" =~ \.\. ]] && return 1
|
||||||
|
for i in ${name//./ }; do
|
||||||
|
[[ "${i}" =~ ^[a-z0-9_/]+$ ]] || return 1
|
||||||
|
done
|
||||||
|
[[ "${name}" == "localhost.localdomain" ]] && return 1
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
function valid_ipv4()
|
||||||
|
{
|
||||||
|
local ip="${1}"
|
||||||
|
local rematch="^([0-9]{1,3}\.){3}[0-9]{1,3}$"
|
||||||
|
|
||||||
|
[[ "${ip}" =~ ${rematch} ]] || return 1
|
||||||
|
for i in ${ip//./ }; do
|
||||||
|
[[ ${i} -le 255 ]] || return 1
|
||||||
|
done
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
HOSTNAME=$(hostname)
|
||||||
|
IP=$(hostname -I | cut -d " " -f 1)
|
||||||
|
export KRB5CCNAME=ansible_freeipa_cache
|
||||||
|
|
||||||
|
if [ -z "${HOSTNAME}" ] || ! valid_fqdn "${HOSTNAME}" ; then
|
||||||
|
echo "ERROR: Got invalid hostname: '${HOSTNAME}'"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if [ -z "${IP}" ] || ! valid_ipv4 "${IP}" ; then
|
||||||
|
echo "ERROR: Got invalid IPv4 address: '${IP}'"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
PTR=$(echo "${IP}" | awk -F"." '{print $4}')
|
||||||
|
if [ -z "${PTR}" ] || [ -n "${PTR//[0-9]}" ]; then
|
||||||
|
echo "ERROR: Failed to get PTR from IPv4 address: '${PTR}'"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
FORWARDER=$(grep -s -m 1 ^nameserver /etc/resolv.conf.fixnet | cut -d" " -f 2)
|
||||||
|
if [ -z "${FORWARDER}" ] || [ "${FORWARDER}" == "127.0.0.1" ]; then
|
||||||
|
FORWARDER="8.8.8.8"
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Fix IPA:"
|
||||||
|
echo " HOSTNAME: '${HOSTNAME}'"
|
||||||
|
echo " IP: '${IP}'"
|
||||||
|
echo " PTR: '${PTR}'"
|
||||||
|
echo " FORWARDER: '${FORWARDER}'"
|
||||||
|
|
||||||
|
ZONES=$(ipa -e in_server=true dnszone-find --name-from-ip="${HOSTNAME}." \
|
||||||
|
--raw --pkey-only | grep "idnsname:" | awk -F": " '{print $2}')
|
||||||
|
for zone in ${ZONES}; do
|
||||||
|
echo
|
||||||
|
if [[ "${zone}" == *".in-addr.arpa."* ]]; then
|
||||||
|
echo "Fixing reverse zone ${zone}:"
|
||||||
|
OLD_PTR=$(ipa -e in_server=true dnsrecord-find "${zone}" \
|
||||||
|
--ptr-rec="${HOSTNAME}." --raw | grep "idnsname:" | \
|
||||||
|
awk -F": " '{print $2}')
|
||||||
|
if [ -z "${OLD_PTR}" ] || [ -n "${OLD_PTR//[0-9]}" ]; then
|
||||||
|
echo "ERROR: Failed to get old PTR from '${zone}': '${OLD_PTR}'"
|
||||||
|
else
|
||||||
|
ipa -e in_server=true dnsrecord-mod "${zone}" "${OLD_PTR}" \
|
||||||
|
--ptr-rec="${HOSTNAME}." --rename="${PTR}" || true
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "Fixing forward zone ${zone}:"
|
||||||
|
ipa -e in_server=true dnsrecord-mod test.local "${HOSTNAME%%.*}" \
|
||||||
|
--a-rec="$IP" || true
|
||||||
|
ipa -e in_server=true dnsrecord-mod test.local ipa-ca \
|
||||||
|
--a-rec="$IP" || true
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
ipa -e in_server=true dnsserver-mod "${HOSTNAME}" \
|
||||||
|
--forwarder="${FORWARDER}" || true
|
||||||
|
|
||||||
|
exit 0
|
||||||
11
infra/image/system-service/fixnet.service
Normal file
11
infra/image/system-service/fixnet.service
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Fix /etc/hosts and with local DNS also /etc/resolv.conf
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
ExecStart=/root/fixnet.sh
|
||||||
|
StandardOutput=journal
|
||||||
|
StandardError=journal
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=container-ipa.target
|
||||||
75
infra/image/system-service/fixnet.sh
Executable file
75
infra/image/system-service/fixnet.sh
Executable file
@@ -0,0 +1,75 @@
|
|||||||
|
#!/bin/bash -eu
|
||||||
|
|
||||||
|
function valid_fqdn()
|
||||||
|
{
|
||||||
|
local name="${1}"
|
||||||
|
|
||||||
|
[[ "${name}" =~ [[:space:]] ]] && return 1
|
||||||
|
[[ "${name}" =~ \. ]] || return 1
|
||||||
|
[[ "${name}" =~ \.\. ]] && return 1
|
||||||
|
for i in ${name//./ }; do
|
||||||
|
[[ "${i}" =~ ^[a-z0-9_/]+$ ]] || return 1
|
||||||
|
done
|
||||||
|
[[ "${name}" == "localhost.localdomain" ]] && return 1
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
function valid_ipv4()
|
||||||
|
{
|
||||||
|
local ip="${1}"
|
||||||
|
local rematch="^([0-9]{1,3}\.){3}[0-9]{1,3}$"
|
||||||
|
|
||||||
|
[[ "${ip}" =~ ${rematch} ]] || return 1
|
||||||
|
for i in ${ip//./ }; do
|
||||||
|
[[ ${i} -le 255 ]] || return 1
|
||||||
|
done
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
HOSTNAME=$(hostname)
|
||||||
|
IP=$(hostname -I | cut -d " " -f 1)
|
||||||
|
|
||||||
|
if [ -z "${HOSTNAME}" ] || ! valid_fqdn "${HOSTNAME}" ; then
|
||||||
|
echo "ERROR: Failed to retrieve hostname."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if [ -z "${IP}" ] || ! valid_ipv4 "${IP}" ; then
|
||||||
|
echo "ERROR: Got invalid IPv4 address: '${IP}'"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
DOMAIN=${HOSTNAME#*.}
|
||||||
|
|
||||||
|
echo "Fix NET:"
|
||||||
|
echo " HOSTNAME: '${HOSTNAME}'"
|
||||||
|
echo " DOMAIN: '${DOMAIN}'"
|
||||||
|
echo " IP: '${IP}'"
|
||||||
|
echo
|
||||||
|
|
||||||
|
# /etc/hosts
|
||||||
|
|
||||||
|
sed -i -E "/\s+${HOSTNAME}(\s|$)/d" /etc/hosts
|
||||||
|
echo -e "$IP\t${HOSTNAME} ${HOSTNAME%%.*}" >> /etc/hosts
|
||||||
|
|
||||||
|
echo "/etc/hosts:"
|
||||||
|
cat "/etc/hosts"
|
||||||
|
|
||||||
|
# /etc/resolv.conf
|
||||||
|
|
||||||
|
# If bind is not installed, exit
|
||||||
|
[ -f "/etc/named.conf" ] || exit 0
|
||||||
|
# If dyndb is not enabled for bind, exit
|
||||||
|
grep -q '^dyndb "ipa"' "/etc/named.conf" || exit 0
|
||||||
|
|
||||||
|
cp -a /etc/resolv.conf /etc/resolv.conf.fixnet
|
||||||
|
cat > /etc/resolv.conf <<EOF
|
||||||
|
search ${DOMAIN}
|
||||||
|
nameserver 127.0.0.1
|
||||||
|
EOF
|
||||||
|
|
||||||
|
echo
|
||||||
|
echo "/etc/resolv.conf:"
|
||||||
|
cat "/etc/resolv.conf"
|
||||||
|
|
||||||
|
exit 0
|
||||||
@@ -1,2 +1,2 @@
|
|||||||
---
|
---
|
||||||
requires_ansible: ">=2.15.0"
|
requires_ansible: ">=2.14.0"
|
||||||
|
|||||||
@@ -1,30 +0,0 @@
|
|||||||
FROM quay.io/centos/centos:stream8
|
|
||||||
ENV container=docker
|
|
||||||
|
|
||||||
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
|
||||||
dnf makecache; \
|
|
||||||
dnf --assumeyes install \
|
|
||||||
/usr/bin/python3 \
|
|
||||||
/usr/bin/python3-config \
|
|
||||||
/usr/bin/dnf-3 \
|
|
||||||
sudo \
|
|
||||||
bash \
|
|
||||||
systemd \
|
|
||||||
procps-ng \
|
|
||||||
iproute && \
|
|
||||||
dnf clean all; \
|
|
||||||
(cd /lib/systemd/system/sysinit.target.wants/; for i in *; do [ $i == systemd-tmpfiles-setup.service ] || rm -f $i; done); \
|
|
||||||
rm -f /lib/systemd/system/multi-user.target.wants/*;\
|
|
||||||
rm -f /etc/systemd/system/*.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/local-fs.target.wants/*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*udev*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*initctl*; \
|
|
||||||
rm -f /lib/systemd/system/basic.target.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/anaconda.target.wants/*; \
|
|
||||||
rm -rf /var/cache/dnf/;
|
|
||||||
|
|
||||||
STOPSIGNAL RTMIN+3
|
|
||||||
|
|
||||||
VOLUME ["/sys/fs/cgroup"]
|
|
||||||
|
|
||||||
CMD ["/usr/sbin/init"]
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: c8s-build
|
|
||||||
image: "quay.io/centos/centos:stream8"
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 8.8.8.8
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare-build.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: c8s
|
|
||||||
image: quay.io/ansible-freeipa/upstream-tests:c8s
|
|
||||||
pre_build_image: true
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 127.0.0.1
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
FROM quay.io/centos/centos:stream9
|
|
||||||
ENV container=docker
|
|
||||||
|
|
||||||
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
|
||||||
dnf makecache; \
|
|
||||||
dnf --assumeyes install \
|
|
||||||
/usr/bin/python3 \
|
|
||||||
/usr/bin/dnf-3 \
|
|
||||||
sudo \
|
|
||||||
bash \
|
|
||||||
systemd \
|
|
||||||
procps-ng \
|
|
||||||
iproute && \
|
|
||||||
dnf clean all; \
|
|
||||||
(cd /lib/systemd/system/sysinit.target.wants/; for i in *; do [ $i == systemd-tmpfiles-setup.service ] || rm -f $i; done); \
|
|
||||||
rm -f /lib/systemd/system/multi-user.target.wants/*;\
|
|
||||||
rm -f /etc/systemd/system/*.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/local-fs.target.wants/*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*udev*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*initctl*; \
|
|
||||||
rm -f /lib/systemd/system/basic.target.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/anaconda.target.wants/*; \
|
|
||||||
rm -rf /var/cache/dnf/;
|
|
||||||
|
|
||||||
STOPSIGNAL RTMIN+3
|
|
||||||
|
|
||||||
VOLUME ["/sys/fs/cgroup"]
|
|
||||||
|
|
||||||
CMD ["/usr/sbin/init"]
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: c9s-build
|
|
||||||
image: "quay.io/centos/centos:stream9"
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 8.8.8.8
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare-build.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: c9s
|
|
||||||
image: quay.io/ansible-freeipa/upstream-tests:c9s
|
|
||||||
pre_build_image: true
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 127.0.0.1
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: centos-7-build
|
|
||||||
image: centos/systemd
|
|
||||||
pre_build_image: true
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 8.8.8.8
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare-build.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: centos-7
|
|
||||||
image: quay.io/ansible-freeipa/upstream-tests:centos-7
|
|
||||||
pre_build_image: true
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 127.0.0.1
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
fedora-latest
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
FROM fedora:latest
|
|
||||||
ENV container=docker
|
|
||||||
|
|
||||||
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
|
||||||
dnf makecache; \
|
|
||||||
dnf --assumeyes install \
|
|
||||||
/usr/bin/python3 \
|
|
||||||
/usr/bin/python3-config \
|
|
||||||
/usr/bin/dnf-3 \
|
|
||||||
sudo \
|
|
||||||
bash \
|
|
||||||
systemd \
|
|
||||||
procps-ng \
|
|
||||||
iproute && \
|
|
||||||
dnf clean all; \
|
|
||||||
(cd /lib/systemd/system/sysinit.target.wants/; for i in *; do [ $i == systemd-tmpfiles-setup.service ] || rm -f $i; done); \
|
|
||||||
rm -f /lib/systemd/system/multi-user.target.wants/*;\
|
|
||||||
rm -f /etc/systemd/system/*.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/local-fs.target.wants/*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*udev*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*initctl*; \
|
|
||||||
rm -f /lib/systemd/system/basic.target.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/anaconda.target.wants/*; \
|
|
||||||
rm -rf /var/cache/dnf/;
|
|
||||||
|
|
||||||
STOPSIGNAL RTMIN+3
|
|
||||||
|
|
||||||
VOLUME ["/sys/fs/cgroup"]
|
|
||||||
|
|
||||||
CMD ["/usr/sbin/init"]
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: fedora-latest-build
|
|
||||||
image: "fedora:latest"
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 8.8.8.8
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare-build.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: fedora-latest
|
|
||||||
image: quay.io/ansible-freeipa/upstream-tests:fedora-latest
|
|
||||||
pre_build_image: true
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 127.0.0.1
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
FROM fedora:rawhide
|
|
||||||
ENV container=docker
|
|
||||||
|
|
||||||
RUN rm -fv /var/cache/dnf/metadata_lock.pid; \
|
|
||||||
dnf makecache; \
|
|
||||||
dnf --assumeyes install \
|
|
||||||
/usr/bin/python3 \
|
|
||||||
/usr/bin/python3-config \
|
|
||||||
/usr/bin/dnf-3 \
|
|
||||||
sudo \
|
|
||||||
bash \
|
|
||||||
systemd \
|
|
||||||
procps-ng \
|
|
||||||
iproute && \
|
|
||||||
dnf clean all; \
|
|
||||||
(cd /lib/systemd/system/sysinit.target.wants/; for i in *; do [ $i == systemd-tmpfiles-setup.service ] || rm -f $i; done); \
|
|
||||||
rm -f /lib/systemd/system/multi-user.target.wants/*;\
|
|
||||||
rm -f /etc/systemd/system/*.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/local-fs.target.wants/*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*udev*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*initctl*; \
|
|
||||||
rm -f /lib/systemd/system/basic.target.wants/*;\
|
|
||||||
rm -f /lib/systemd/system/anaconda.target.wants/*; \
|
|
||||||
rm -rf /var/cache/dnf/;
|
|
||||||
|
|
||||||
STOPSIGNAL RTMIN+3
|
|
||||||
|
|
||||||
VOLUME ["/sys/fs/cgroup"]
|
|
||||||
|
|
||||||
CMD ["/usr/sbin/init"]
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: fedora-rawhide-build
|
|
||||||
image: "fedora:rawhide"
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 8.8.8.8
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare-build.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
platforms:
|
|
||||||
- name: fedora-rawhide
|
|
||||||
image: quay.io/ansible-freeipa/upstream-tests:fedora-rawhide
|
|
||||||
pre_build_image: true
|
|
||||||
hostname: ipaserver.test.local
|
|
||||||
dns_servers:
|
|
||||||
- 127.0.0.1
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:ro
|
|
||||||
command: /usr/sbin/init
|
|
||||||
privileged: true
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
playbooks:
|
|
||||||
prepare: ../resources/playbooks/prepare.yml
|
|
||||||
prerun: false
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
../../../plugins/modules/
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user