mirror of https://github.com/ceph/ceph-ansible.git
60 lines
1.8 KiB
YAML
60 lines
1.8 KiB
YAML
---
|
|
# NOTE (leseb): we use root:ceph for permissions since ganesha
|
|
# does not have the right selinux context to read ceph directories.
|
|
- name: create rados gateway and ganesha directories
|
|
file:
|
|
path: "{{ item }}"
|
|
state: directory
|
|
owner: "ceph"
|
|
group: "ceph"
|
|
mode: "0755"
|
|
with_items:
|
|
- /var/lib/ceph/bootstrap-rgw
|
|
- /var/lib/ceph/radosgw
|
|
- /var/lib/ceph/radosgw/{{ cluster }}-rgw.{{ ansible_hostname }}
|
|
- "{{ rbd_client_admin_socket_path }}"
|
|
- /var/log/ceph
|
|
- /var/run/ceph/
|
|
when:
|
|
- nfs_obj_gw
|
|
|
|
- name: copy rados gateway bootstrap key
|
|
copy:
|
|
src: "{{ fetch_directory }}/{{ fsid }}{{ item.name }}"
|
|
dest: "{{ item.name }}"
|
|
owner: "ceph"
|
|
group: "ceph"
|
|
mode: "0600"
|
|
with_items:
|
|
- { name: "/var/lib/ceph/bootstrap-rgw/{{ cluster }}.keyring", copy_key: true }
|
|
- { name: "/etc/ceph/{{ cluster }}.client.admin.keyring", copy_key: "{{ copy_admin_key }}" }
|
|
when:
|
|
- nfs_obj_gw
|
|
- cephx
|
|
- item.copy_key|bool
|
|
|
|
- name: create rados gateway keyring
|
|
command: ceph --cluster {{ cluster }} --name client.bootstrap-rgw --keyring /var/lib/ceph/bootstrap-rgw/{{ cluster }}.keyring auth get-or-create client.rgw.{{ ansible_hostname }} osd 'allow rwx' mon 'allow rw' -o /var/lib/ceph/radosgw/{{ cluster }}-rgw.{{ ansible_hostname }}/keyring
|
|
args:
|
|
creates: /var/lib/ceph/radosgw/{{ cluster }}-rgw.{{ ansible_hostname }}/keyring
|
|
changed_when: false
|
|
when:
|
|
- nfs_obj_gw
|
|
- cephx
|
|
|
|
- name: set rados gateway key permissions
|
|
file:
|
|
path: /var/lib/ceph/radosgw/{{ cluster }}-rgw.{{ ansible_hostname }}/keyring
|
|
owner: "ceph"
|
|
group: "ceph"
|
|
mode: "0600"
|
|
when:
|
|
- cephx
|
|
|
|
- name: change ownership on /var/log/ganesha
|
|
file:
|
|
path: /var/log/ganesha
|
|
owner: "root"
|
|
group: "root"
|
|
mode: "0755"
|