mirror of https://github.com/ceph/ceph-ansible.git
Merge pull request #567 from ceph/distribut-keys
ceph-: abitlity to copy admin on all the nodespull/577/head
commit
f4dd00bf4f
|
@ -10,6 +10,11 @@ dummy:
|
|||
|
||||
#fetch_directory: fetch/
|
||||
|
||||
# Even though MDS nodes should not have the admin key
|
||||
# at their disposal, some people might want to have it
|
||||
# distributed on MDS nodes. Setting 'copy_admin_key' to 'true'
|
||||
# will copy the admin key to the /etc/ceph/ directory
|
||||
# copy_admin_key: false
|
||||
|
||||
##########
|
||||
# DOCKER #
|
||||
|
|
|
@ -11,6 +11,12 @@ dummy:
|
|||
|
||||
#fetch_directory: fetch/
|
||||
|
||||
# Even though OSD nodes should not have the admin key
|
||||
# at their disposal, some people might want to have it
|
||||
# distributed on OSD nodes. Setting 'copy_admin_key' to 'true'
|
||||
# will copy the admin key to the /etc/ceph/ directory
|
||||
#copy_admin_key: false
|
||||
|
||||
####################
|
||||
# OSD CRUSH LOCATION
|
||||
####################
|
||||
|
|
|
@ -9,6 +9,12 @@ dummy:
|
|||
#
|
||||
#cephx: true
|
||||
|
||||
# Even though RGW nodes should not have the admin key
|
||||
# at their disposal, some people might want to have it
|
||||
# distributed on RGW nodes. Setting 'copy_admin_key' to 'true'
|
||||
# will copy the admin key to the /etc/ceph/ directory
|
||||
# copy_admin_key: false
|
||||
|
||||
# Used for the sudo exception while starting the radosgw process
|
||||
# a new entry /etc/sudoers.d/ceph will be created
|
||||
# allowing root to not require tty
|
||||
|
|
|
@ -7,6 +7,12 @@
|
|||
|
||||
fetch_directory: fetch/
|
||||
|
||||
# Even though MDS nodes should not have the admin key
|
||||
# at their disposal, some people might want to have it
|
||||
# distributed on MDS nodes. Setting 'copy_admin_key' to 'true'
|
||||
# will copy the admin key to the /etc/ceph/ directory
|
||||
copy_admin_key: false
|
||||
|
||||
cephx: true
|
||||
|
||||
|
||||
|
|
|
@ -9,11 +9,17 @@
|
|||
|
||||
- name: copy mds bootstrap key
|
||||
copy:
|
||||
src: "{{ fetch_directory }}/{{ fsid }}/var/lib/ceph/bootstrap-mds/ceph.keyring"
|
||||
dest: /var/lib/ceph/bootstrap-mds/ceph.keyring
|
||||
src: "{{ fetch_directory }}/{{ fsid }}{{ item.name }}"
|
||||
dest: "{{ item.name }}"
|
||||
owner: "{{ key_owner }}"
|
||||
group: "{{ key_group }}"
|
||||
mode: "{{ key_mode }}"
|
||||
with_items:
|
||||
- { name: /var/lib/ceph/bootstrap-mds/ceph.keyring, copy_key: true }
|
||||
- { name: /etc/ceph/ceph.client.admin.keyring, copy_key: "{{ copy_admin_key }}" }
|
||||
when:
|
||||
cephx and
|
||||
item.copy_key|bool
|
||||
|
||||
- name: create mds directory
|
||||
file:
|
||||
|
|
|
@ -8,6 +8,12 @@
|
|||
|
||||
fetch_directory: fetch/
|
||||
|
||||
# Even though OSD nodes should not have the admin key
|
||||
# at their disposal, some people might want to have it
|
||||
# distributed on OSD nodes. Setting 'copy_admin_key' to 'true'
|
||||
# will copy the admin key to the /etc/ceph/ directory
|
||||
copy_admin_key: false
|
||||
|
||||
####################
|
||||
# OSD CRUSH LOCATION
|
||||
####################
|
||||
|
|
|
@ -23,10 +23,14 @@
|
|||
|
||||
- name: copy osd bootstrap key
|
||||
copy:
|
||||
src: "{{ fetch_directory }}/{{ fsid }}/var/lib/ceph/bootstrap-osd/ceph.keyring"
|
||||
dest: /var/lib/ceph/bootstrap-osd/ceph.keyring
|
||||
src: "{{ fetch_directory }}/{{ fsid }}{{ item.name }}"
|
||||
dest: "{{ item.name }}"
|
||||
owner: "{{ key_owner }}"
|
||||
group: "{{ key_group }}"
|
||||
mode: "{{ key_mode }}"
|
||||
with_items:
|
||||
- { name: /var/lib/ceph/bootstrap-osd/ceph.keyring, copy_key: true }
|
||||
- { name: /etc/ceph/ceph.client.admin.keyring, copy_key: "{{ copy_admin_key }}" }
|
||||
when:
|
||||
cephx
|
||||
cephx and
|
||||
item.copy_key|bool
|
||||
|
|
|
@ -7,6 +7,12 @@
|
|||
|
||||
fetch_directory: fetch/
|
||||
|
||||
# Even though RGW nodes should not have the admin key
|
||||
# at their disposal, some people might want to have it
|
||||
# distributed on RGW nodes. Setting 'copy_admin_key' to 'true'
|
||||
# will copy the admin key to the /etc/ceph/ directory
|
||||
copy_admin_key: false
|
||||
|
||||
## Ceph options
|
||||
#
|
||||
cephx: true
|
||||
|
|
|
@ -12,12 +12,17 @@
|
|||
|
||||
- name: copy rados gateway bootstrap key
|
||||
copy:
|
||||
src: "{{ fetch_directory }}/{{ fsid }}/var/lib/ceph/bootstrap-rgw/ceph.keyring"
|
||||
dest: /var/lib/ceph/bootstrap-rgw/ceph.keyring
|
||||
src: "{{ fetch_directory }}/{{ fsid }}{{ item.name }}"
|
||||
dest: "{{ item.name }}"
|
||||
owner: "{{ key_owner }}"
|
||||
group: "{{ key_group }}"
|
||||
mode: "{{ key_mode }}"
|
||||
when: cephx
|
||||
with_items:
|
||||
- { name: /var/lib/ceph/bootstrap-rgw/ceph.keyring, copy_key: true }
|
||||
- { name: /etc/ceph/ceph.client.admin.keyring, copy_key: "{{ copy_admin_key }}" }
|
||||
when:
|
||||
cephx and
|
||||
item.copy_key|bool
|
||||
|
||||
- name: create rados gateway keyring
|
||||
command: ceph --cluster ceph --name client.bootstrap-rgw --keyring /var/lib/ceph/bootstrap-rgw/ceph.keyring auth get-or-create client.rgw.{{ ansible_hostname }} osd 'allow rwx' mon 'allow rw' -o /var/lib/ceph/radosgw/ceph-rgw.{{ ansible_hostname }}/keyring
|
||||
|
|
Loading…
Reference in New Issue