|
| 1 | +- name: Module x509 | Ensure config directory |
| 2 | + ansible.builtin.file: |
| 3 | + state: directory |
| 4 | + dest: "{{ icingaweb2_modules_config_dir }}/{{ _module }}" |
| 5 | + owner: "{{ icingaweb2_httpd_user }}" |
| 6 | + group: "{{ icingaweb2_group }}" |
| 7 | + mode: "2770" |
| 8 | + vars: |
| 9 | + _module: "{{ item.key }}" |
| 10 | + |
| 11 | +- name: Module x509 | Manage config files |
| 12 | + ansible.builtin.include_tasks: manage_module_config.yml |
| 13 | + loop: "{{ _files }}" |
| 14 | + loop_control: |
| 15 | + loop_var: _file |
| 16 | + when: vars['icingaweb2_modules'][_module][_file] is defined |
| 17 | + vars: |
| 18 | + _module: "{{ item.key }}" |
| 19 | + _files: |
| 20 | + - config |
| 21 | + - sni |
| 22 | + |
| 23 | +- name: Module x509 | Manage Schema |
| 24 | + block: |
| 25 | + - name: Module x509 | Prepare _db informations |
| 26 | + ansible.builtin.set_fact: |
| 27 | + _db: |
| 28 | + host: "{{ vars['icingaweb2_modules'][_module]['database']['host'] | default('localhost') }}" |
| 29 | + port: "{{ vars['icingaweb2_modules'][_module]['database']['port'] | default('3306') }}" |
| 30 | + user: "{{ vars['icingaweb2_modules'][_module]['database']['user'] | default('x509') }}" |
| 31 | + password: "{{ vars['icingaweb2_modules'][_module]['database']['password'] | default(omit) }}" |
| 32 | + name: "{{ vars['icingaweb2_modules'][_module]['database']['name'] | default('x509') }}" |
| 33 | + ssl_mode: "{{ vars['icingaweb2_modules'][_module]['database']['ssl_mode'] | default(omit) }}" |
| 34 | + ssl_ca: "{{ vars['icingaweb2_modules'][_module]['database']['ssl_ca'] | default(omit) }}" |
| 35 | + ssl_cert: "{{ vars['icingaweb2_modules'][_module]['database']['ssl_cert'] | default(omit) }}" |
| 36 | + ssl_key: "{{ vars['icingaweb2_modules'][_module]['database']['ssl_key'] | default(omit) }}" |
| 37 | + ssl_cipher: "{{ vars['icingaweb2_modules'][_module]['database']['ssl_cipher'] | default(omit) }}" |
| 38 | + ssl_extra_options: "{{ vars['icingaweb2_modules'][_module]['database']['ssl_extra_options'] | default(omit) }}" |
| 39 | + schema_path: /usr/share/icingaweb2/modules/x509/schema/mysql.schema.sql |
| 40 | + select_query: "select * from x509_certificate" |
| 41 | + when: vars['icingaweb2_modules'][_module]['database']['type'] | default('mysql') == 'mysql' |
| 42 | + |
| 43 | + - ansible.builtin.fail: |
| 44 | + fail_msg: "The Database type select is not supported, {{ vars['icingaweb2_modules'][_module]['database']['type'] }} [Supported=mysql]" |
| 45 | + when: vars['icingaweb2_modules'][_module]['database']['type'] is defined and vars['icingaweb2_modules'][_module]['database']['type'] != 'mysql' |
| 46 | + |
| 47 | + - name: Module x509 | Import Schema |
| 48 | + ansible.builtin.include_tasks: ../manage_mysql_imports.yml |
| 49 | + |
| 50 | + - name: Module x509 | empty _db var |
| 51 | + ansible.builtin.set_fact: |
| 52 | + _db: {} |
| 53 | + when: vars['icingaweb2_modules'][_module]['database']['import_schema'] | default(false) |
| 54 | + vars: |
| 55 | + _module: "{{ item.key }}" |
| 56 | + |
| 57 | +- name: Module x509 | Import Certificates |
| 58 | + ansible.builtin.shell: > |
| 59 | + icingacli {{ _module }} import --file {{ _file }} |
| 60 | + loop: "{{ vars['icingaweb2_modules'][_module]['certificate_files'] }}" |
| 61 | + loop_control: |
| 62 | + loop_var: _file |
| 63 | + vars: |
| 64 | + _module: "{{ item.key }}" |
| 65 | + when: vars['icingaweb2_modules'][_module]['certificate_files'] is defined |
| 66 | + changed_when: false |
0 commit comments