7516fe142f
* Ansible: move to Ansible 3.4.0 which uses ansible-base 2.10.10 * Docs: add a note about ansible upgrade post 2.9.x * CI: ensure ansible is removed before ansible 3.x is installed to avoid pip failures * Ansible: use newer ansible-lint * Fix ansible-lint 5.0.11 found issues * syntax issues * risky-file-permissions * var-naming * role-name * molecule tests * Mitogen: use 0.3.0rc1 which adds support for ansible 2.10+ * Pin ansible-base to 2.10.11 to get package fix on RHEL8
45 lines
1.7 KiB
YAML
45 lines
1.7 KiB
YAML
---
|
|
- name: Get clusterrolebindings
|
|
register: "clusterrolebinding_state"
|
|
command: "{{ bin_dir }}/kubectl get clusterrolebinding heketi-gluster-admin -o=name --ignore-not-found=true"
|
|
changed_when: false
|
|
|
|
- name: "Kubernetes Apps | Deploy cluster role binding."
|
|
when: "clusterrolebinding_state.stdout | length > 0"
|
|
command: "{{ bin_dir }}/kubectl create clusterrolebinding heketi-gluster-admin --clusterrole=edit --serviceaccount=default:heketi-service-account"
|
|
|
|
- name: Get clusterrolebindings again
|
|
register: "clusterrolebinding_state"
|
|
command: "{{ bin_dir }}/kubectl get clusterrolebinding heketi-gluster-admin -o=name --ignore-not-found=true"
|
|
changed_when: false
|
|
|
|
- name: Make sure that clusterrolebindings are present now
|
|
assert:
|
|
that: "clusterrolebinding_state.stdout | length > 0"
|
|
msg: "Cluster role binding is not present."
|
|
|
|
- name: Get the heketi-config-secret secret
|
|
register: "secret_state"
|
|
command: "{{ bin_dir }}/kubectl get secret heketi-config-secret -o=name --ignore-not-found=true"
|
|
changed_when: false
|
|
|
|
- name: "Render Heketi secret configuration."
|
|
become: true
|
|
template:
|
|
src: "heketi.json.j2"
|
|
dest: "{{ kube_config_dir }}/heketi.json"
|
|
mode: 0644
|
|
|
|
- name: "Deploy Heketi config secret"
|
|
when: "secret_state.stdout | length > 0"
|
|
command: "{{ bin_dir }}/kubectl create secret generic heketi-config-secret --from-file={{ kube_config_dir }}/heketi.json"
|
|
|
|
- name: Get the heketi-config-secret secret again
|
|
register: "secret_state"
|
|
command: "{{ bin_dir }}/kubectl get secret heketi-config-secret -o=name --ignore-not-found=true"
|
|
changed_when: false
|
|
|
|
- name: Make sure the heketi-config-secret secret exists now
|
|
assert:
|
|
that: "secret_state.stdout != \"\""
|
|
msg: "Heketi config secret is not present."
|