-
Notifications
You must be signed in to change notification settings - Fork 48
Expand file tree
/
Copy pathswarmstack.yml
More file actions
495 lines (429 loc) · 20.8 KB
/
Copy pathswarmstack.yml
File metadata and controls
495 lines (429 loc) · 20.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
---
- hosts: all
gather_facts: true
remote_user: root
roles:
- ../roles/common
tasks:
- name: Install requisite packages on SWARMJOIN host
yum: name=ansible,git,httpd-tools state=latest
when: "inventory_hostname == SWARMJOIN"
### INSTALL/UPDATE NETDATA ON ALL HOSTS
- name: Download packagecloud.io yum repo installer
get_url:
url: "https://packagecloud.io/install/repositories/netdata/netdata/script.rpm.sh"
dest: "/tmp/netdata-script.rpm.sh"
changed_when: false
- name: Execute packagecloud.io yum repo installer
shell: cat /tmp/netdata-script.rpm.sh | /bin/bash
register: netdata_installed
changed_when: False
- name: Install Netdata
yum: name=netdata state=latest
register: NetdataInstalled
- name: Comment out bind port in /etc/netdata/netdata.conf
replace:
path: /etc/netdata/netdata.conf
regexp: '^([\s]*)bind to ='
replace: '\g<1>#bind to = localhost'
register: NetdataCommented
when: NetdataInstalled.changed == True
- name: ensure that netdata user is in adm group so it can read logs such as /var/log/fail2ban.log
user:
name: netdata
groups: adm
append: yes
register: NetdataGroup
- name: systemctl restart netdata if needed
systemd:
state: restarted
enabled: true
daemon_reload: no
name: netdata
when: NetdataInstalled.changed == True and (NetdataCommented.changed == True or NetdataGroup.changed == True)
### INSTALL/UPDATE node_exporter ON ALL HOSTS
- name: download current node_exporter version
get_url:
url: "https://api.github.com/repos/prometheus/node_exporter/releases/latest"
dest: "/tmp/node_exporter_version.tmp"
changed_when: false
#curl --silent "https://api.github.com/repos/prometheus/node_exporter/releases/latest" | egrep -i '"name": "[0-9.]+ / [0-9]+' | cut -f 4 -d '"' | cut -f 1 -d ' '
- name: determine current node_exporter version
shell: cat /tmp/node_exporter_version.tmp | cut -d '"' -f 26 | sed 's/v//'
register: NODE_EXPORTER_VER
- name: download current node_exporter release
get_url:
url: "https://github.com/prometheus/node_exporter/releases/download/v{{item}}/node_exporter-{{item}}.linux-amd64.tar.gz"
dest: "/tmp/node_exporter-{{item}}.linux-amd64.tar.gz"
with_items: "{{NODE_EXPORTER_VER.stdout}}"
changed_when: false
- name: extract node_exporter
unarchive:
src: "/tmp/node_exporter-{{item}}.linux-amd64.tar.gz"
dest: "/tmp"
with_items: "{{NODE_EXPORTER_VER.stdout}}"
changed_when: false
- name: check if node_exporter already installed
stat: path=/usr/local/bin/node_exporter
register: NODE_EXPORTER_EXISTS
- name: stop current node_exporter
systemd:
state: stopped
daemon_reload: no
name: node_exporter
ignore_errors: true
when: NODE_EXPORTER_EXISTS.stat.exists
- name: move extracted node_exporter to /usr/local/bin
command: "mv /tmp/node_exporter-{{item}}.linux-amd64/node_exporter /usr/local/bin"
with_items: "{{NODE_EXPORTER_VER.stdout}}"
- name: install node_exporter systemd service file
copy:
dest: "/etc/systemd/system/node_exporter.service"
content: |
[Unit]
Description=Node Exporter
After=network.target
[Service]
User=node_exporter
Group=node_exporter
Type=simple
ExecStart=/usr/local/bin/node_exporter
[Install]
WantedBy=multi-user.target
- name: (re)start node_exporter service
systemd:
state: started
enabled: true
daemon_reload: yes
name: node_exporter
### DOWNLOAD SWARMSTACK FILES TO SWARMJOIN HOST, COPY SOME LOCAL FILES TO SWARMJOIN HOST
- name: Use git to download latest swarmstack
git:
repo: "{{ SWARMSTACK_REPO }}"
dest: "{{ SWARMSTACK_SRC_DIR }}"
version: "{{ SWARMSTACK_REPO_VERSION }}"
ignore_errors: true
when: "inventory_hostname == SWARMJOIN"
- name: Check if local copy of swarmstack exists
stat: path={{ SWARMSTACK_LOCAL_DIR }}
changed_when: false
register: localswarmstack
when: "inventory_hostname == SWARMJOIN"
- name: Create a local copy of swarmstack for editing
shell: "rsync -aq --exclude=.git --exclude=.gitignore {{SWARMSTACK_SRC_DIR}}/ {{SWARMSTACK_LOCAL_DIR}}/"
when: "inventory_hostname == SWARMJOIN and not localswarmstack.stat.exists"
- name: gather name of host running ansible playbooks currently
command: hostname
delegate_to: localhost
register: hostname
- set_fact:
ANSIBLE_HOST: hostname.stdout
- name: Check if local copy of ansible role exists
stat: path={{ SWARMSTACK_LOCAL_DIR }}/ansible/roles/{{ CLUSTER }}
changed_when: false
register: localrole
when: "inventory_hostname == SWARMJOIN"
- name: move roles/swarmstack to roles/CLUSTER if directory doesn't exist on SWARMJOIN host
command: mv {{ SWARMSTACK_LOCAL_DIR }}/ansible/roles/swarmstack {{ SWARMSTACK_LOCAL_DIR }}/ansible/roles/{{ CLUSTER }}
when: "CLUSTER != 'swarmstack' and inventory_hostname == SWARMJOIN and ANSIBLE_HOST != SWARMJOIN and not localrole.stat.exists"
- name: copy cluster file to SWARMJOIN host if different
copy: src=../clusters/{{ CLUSTER }} dest={{ SWARMSTACK_LOCAL_DIR }}/ansible/clusters/{{ CLUSTER }} owner=root group=root mode="u=rw,g=r,o=r"
when: "inventory_hostname == SWARMJOIN and ANSIBLE_HOST != SWARMJOIN"
- name: copy common.rules to SWARMJOIN host if different
copy: src=../roles/common/files/etc/swarmstack_fw/rules/common.rules dest={{ SWARMSTACK_LOCAL_DIR }}/ansible/roles/common/files/etc/swarmstack_fw/rules/common.rules owner=root group=root mode="u=rw,g=r,o=r"
when: "inventory_hostname == SWARMJOIN and ANSIBLE_HOST != SWARMJOIN"
- name: copy cluster.rules to SWARMSTACK_LOCAL_DIR on SWARMJOIN host
copy: src=../roles/{{ CLUSTER }}/files/etc/swarmstack_fw/rules/cluster.rules dest={{ SWARMSTACK_LOCAL_DIR }}/ansible/roles/{{ CLUSTER }}/files/etc/swarmstack_fw/rules/cluster.rules owner=root group=root mode="u=rw,g=r,o=r"
when: "inventory_hostname == SWARMJOIN and ANSIBLE_HOST != SWARMJOIN"
- name: copy docker.rules to SWARMSTACK_LOCAL_DIR on SWARMJOIN host
copy: src=../roles/{{ CLUSTER }}/files/etc/swarmstack_fw/rules/docker.rules dest={{ SWARMSTACK_LOCAL_DIR }}/ansible/roles/{{ CLUSTER }}/files/etc/swarmstack_fw/rules/docker.rules owner=root group=root mode="u=rw,g=r,o=r"
when: "inventory_hostname == SWARMJOIN and ANSIBLE_HOST != SWARMJOIN"
- name: copy alertmanager.yml to SWARMSTACK_LOCAL_DIR on SWARMJOIN host
copy: src=../../alertmanager/conf/alertmanager.yml dest={{ SWARMSTACK_LOCAL_DIR }}/alertmanager/conf/alertmanager.yml owner=root group=root mode="u=rw,g=r,o=r"
when: "inventory_hostname == SWARMJOIN and ANSIBLE_HOST != SWARMJOIN"
- name: copy prometheus.yml to SWARMSTACK_LOCAL_DIR on SWARMJOIN host
copy: src=../../prometheus/conf/prometheus.yml dest={{ SWARMSTACK_LOCAL_DIR }}/prometheus/conf/prometheus.yml owner=root group=root mode="u=rw,g=r,o=r"
when: "inventory_hostname == SWARMJOIN and ANSIBLE_HOST != SWARMJOIN"
### CONFIGURE PASSWORDS IN LOCAL COMPOSE FILE
- name: Generate admin password hash for portainer
shell: "htpasswd -nbB admin '{{ADMIN_PASSWORD}}' | cut -d ':' -f 2 | sed 's/\\$/\\$\\$/g'"
register: portaineradminpw
when: "inventory_hostname == SWARMJOIN"
- name: Update docker-compose.yml with portainer admin password hash
lineinfile:
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
regexp: "command: -H tcp://tasks.portainer-agent:9001 --tlsskipverify"
line: " command: -H tcp://tasks.portainer-agent:9001 --tlsskipverify --admin-password {{ item }}"
backrefs: yes
with_items: "{{portaineradminpw.stdout}}"
when: "inventory_hostname == SWARMJOIN"
- name: Update docker-compose.yml with web.external-url for alertmanager
lineinfile:
insertbefore: 'cluster.peer=alertmanagerB:9094'
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
line: " - '--web.external-url=https://{{ EXTERNAL_ENDPOINT }}:9093/'"
when: "inventory_hostname == SWARMJOIN"
- name: Update docker-compose.yml with web.external-url for alertmanagerB
lineinfile:
insertbefore: 'cluster.peer=alertmanager:9094'
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
line: " - '--web.external-url=https://{{ EXTERNAL_ENDPOINT }}:9095/'"
when: "inventory_hostname == SWARMJOIN"
- name: Update docker-compose.yml with web.external-url for Prometheus
lineinfile:
insertafter: 'storage.tsdb.retention'
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
line: " - '--web.external-url=https://{{ EXTERNAL_ENDPOINT }}:9090/'"
when: "inventory_hostname == SWARMJOIN"
### PROXY SETTINGS
- name: Update docker-compose.yml with proxy settings for Caddy
blockinfile:
marker_begin: "SWARMSTACK_BEGIN Caddy PROXY"
marker_end: "SWARMSTACK_END Caddy PROXY"
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
insertafter: ' - CADDYPATH='
block: |2
- http_proxy={{item.http_proxy}}
- https_proxy={{item.https_proxy}}
- no_proxy={{item.no_proxy}},{% for host in groups['swarm'] %}{{ hostvars[host].inventory_hostname }}{{ '' if loop.last else ','}}{% endfor %}
with_items:
- { http_proxy: "{{PROXY_HTTP}}", https_proxy: "{{PROXY_HTTPS}}", no_proxy: "{{PROXY_NOPROXY}}" }
when: "inventory_hostname == SWARMJOIN and PROXY_ENABLED=='true'"
- name: Update docker-compose.yml with proxy settings for Grafana
blockinfile:
marker_begin: "SWARMSTACK_BEGIN Grafana PROXY"
marker_end: "SWARMSTACK_END Grafana PROXY"
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
insertbefore: ' - GF_SECURITY_ADMIN_USER='
block: |2
- http_proxy={{item.http_proxy}}
- https_proxy={{item.https_proxy}}
- no_proxy={{item.no_proxy}},{% for host in groups['swarm'] %}{{ hostvars[host].inventory_hostname }}{{ '' if loop.last else ','}}{% endfor %}
with_items:
- { http_proxy: "{{PROXY_HTTP}}", https_proxy: "{{PROXY_HTTPS}}", no_proxy: "{{PROXY_NOPROXY}}" }
when: "inventory_hostname == SWARMJOIN and PROXY_ENABLED=='true'"
### LDAP SETTINGS
- name: Add LDAP settings to new caddy/Caddyfile.ldap
replace:
path: "{{SWARMSTACK_LOCAL_DIR}}/caddy/Caddyfile.ldap"
regexp: '^ ldap url=.*$'
replace: " ldap url={{ (LDAP_USE_SSL == 'true') | ternary('ldaps','ldap') }}://{{LDAP_HOST}}:{{LDAP_PORT}},insecure={{LDAP_INSECURE}},timeout=5s,username={{LDAP_BIND_DN}},password={{LDAP_BIND_PASSWORD}},base=\"{{LDAP_SEARCH_BASE_DNS}}\",filter=\"{{LDAP_SEARCH_FILTER}}\""
when: "inventory_hostname == SWARMJOIN and LDAP_ENABLED == 'true'"
ignore_errors: true
- name: Add LDAP settings to grafana/ldap.toml
lineinfile:
path: "{{SWARMSTACK_LOCAL_DIR}}/grafana/ldap.toml"
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
with_items:
- { regexp: '^host =', line: "host = \"{{LDAP_HOST}}\"" }
- { regexp: '^port =', line: "port = {{LDAP_PORT}}" }
- { regexp: '^use_ssl =', line: "use_ssl = {{LDAP_USE_SSL}}" }
- { regexp: '^start_tls =', line: "start_tls = {{LDAP_START_TLS}}" }
- { regexp: '^bind_dn =', line: "bind_dn = \"{{LDAP_BIND_DN}}\"" }
- { regexp: '^bind_password =', line: "bind_password = \"\"\"{{LDAP_BIND_PASSWORD}}\"\"\"" }
- { regexp: '^search_filter =', line: "search_filter = \"{{LDAP_SEARCH_FILTER}}\"" }
- { regexp: '^search_base_dns =', line: "search_base_dns = [\"{{LDAP_SEARCH_BASE_DNS}}\"]" }
- { regexp: '^username =', line: "username = \"{{LDAP_ATTRIBUTE_USERNAME}}\"" }
- { regexp: '^group_dn =', line: "group_dn = \"{{LDAP_GROUP_DN}}\"" }
when: "inventory_hostname == SWARMJOIN and LDAP_ENABLED == 'true'"
ignore_errors: true
- name: Update docker-compose.yml with caddy settings
lineinfile:
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
regexp: "^ file: ./caddy/Caddyfile$"
line: " file: ./caddy/Caddyfile.ldap"
backrefs: yes
when: "inventory_hostname == SWARMJOIN and LDAP_ENABLED == 'true'"
- name: Update docker-compose.yml with grafana LDAP settings 1 of 4
blockinfile:
marker_begin: "SWARMSTACK_BEGIN Grafana LDAP 1 of 4"
marker_end: "SWARMSTACK_END Grafana LDAP 1 of 4"
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
insertbefore: ' grafana_provisioning_datasources:'
block: |2
grafana_configuration:
file: ./grafana/grafana.ini
when: "inventory_hostname == SWARMJOIN and LDAP_ENABLED == 'true'"
- name: Update docker-compose.yml with grafana LDAP settings 2 of 4
blockinfile:
marker_begin: "SWARMSTACK_BEGIN Grafana LDAP 2 of 4"
marker_end: "SWARMSTACK_END Grafana LDAP 2 of 4"
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
insertbefore: ' grafana_provisioning_datasources:'
block: |2
grafana_ldap:
file: ./grafana/ldap.toml
when: "inventory_hostname == SWARMJOIN and LDAP_ENABLED == 'true'"
- name: Update docker-compose.yml with grafana LDAP settings 3 of 4
blockinfile:
marker_begin: "SWARMSTACK_BEGIN Grafana LDAP 3 of 4"
marker_end: "SWARMSTACK_END Grafana LDAP 3 of 4"
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
insertbefore: ' - source: grafana_dashboards_nodes'
block: |2
- source: grafana_configuration
target: /etc/grafana/grafana.ini
when: "inventory_hostname == SWARMJOIN and LDAP_ENABLED == 'true'"
- name: Update docker-compose.yml with grafana LDAP settings 4 of 4
blockinfile:
marker_begin: "SWARMSTACK_BEGIN Grafana LDAP 4 of 4"
marker_end: "SWARMSTACK_END Grafana LDAP 4 of 4"
path: "{{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml"
insertbefore: ' - source: grafana_dashboards_nodes'
block: |2
- source: grafana_ldap
target: /etc/grafana/ldap.toml
when: "inventory_hostname == SWARMJOIN and LDAP_ENABLED == 'true'"
### ADD PROMETHEUS SCRAPE CONFIGS FOR HOSTS
- name: Add NetData to local Prometheus scrapes
blockinfile:
marker_begin: "SWARMSTACK_BEGIN NetData"
marker_end: "SWARMSTACK_END NetData"
path: "{{SWARMSTACK_LOCAL_DIR}}/prometheus/conf/prometheus.yml"
block: |2
- job_name: 'netdata'
metrics_path: '/api/v1/allmetrics'
params:
format: [prometheus_all_hosts]
honor_labels: true
static_configs:
- targets: [{% for host in groups['all'] %}'{{ hostvars[host].inventory_hostname }}:19999'{{ '' if loop.last else ','}}{% endfor %}]
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add node_exporter to local Prometheus scrapes
blockinfile:
marker_begin: "SWARMSTACK_BEGIN node_exporter"
marker_end: "SWARMSTACK_END node_exporter"
path: "{{SWARMSTACK_LOCAL_DIR}}/prometheus/conf//prometheus.yml"
block: |2
- job_name: 'node_exporter'
static_configs:
- targets: [{% for host in groups['all'] %}'{{ hostvars[host].inventory_hostname }}:9100'{{ '' if loop.last else ','}}{% endfor %}]
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add docker to local Prometheus scrapes
blockinfile:
marker_begin: "SWARMSTACK_BEGIN dockerd"
marker_end: "SWARMSTACK_END dockerd"
path: "{{SWARMSTACK_LOCAL_DIR}}/prometheus/conf/prometheus.yml"
block: |2
- job_name: 'dockerd'
metrics_path: '/metrics'
honor_labels: true
static_configs:
- targets: [{% for host in groups['swarm'] %}'{{ hostvars[host].inventory_hostname }}:9323'{{ '' if loop.last else ','}}{% endfor %}]
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add etcd to local Prometheus scrapes
blockinfile:
marker_begin: "SWARMSTACK_BEGIN etcd"
marker_end: "SWARMSTACK_END etcd"
path: "{{SWARMSTACK_LOCAL_DIR}}/prometheus/conf/prometheus.yml"
block: |2
- job_name: 'etcd'
metrics_path: '/metrics'
honor_labels: true
static_configs:
- targets: [{% for host in groups['etcd'] %}'{{ hostvars[host].inventory_hostname }}:2379'{{ '' if loop.last else ','}}{% endfor %}]
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add Portworx to local Prometheus scrapes
blockinfile:
marker_begin: "SWARMSTACK_BEGIN Portworx"
marker_end: "SWARMSTACK_END Portworx"
path: "{{SWARMSTACK_LOCAL_DIR}}/prometheus/conf/prometheus.yml"
block: |2
- job_name: 'portworx'
metrics_path: '/metrics'
honor_labels: true
static_configs:
- targets: [{% for host in groups['portworx'] %}'{{ hostvars[host].inventory_hostname }}:9001'{{ '' if loop.last else ','}}{% endfor %}]
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
### MODIFY CADDY CONFIGS
- name: Add all hosts to caddy/index.html javascript
blockinfile:
marker_begin: "//SWARMSTACK_BEGIN js {{item}}"
marker_end: "//SWARMSTACK_END js {{item}}"
marker: "{mark}"
insertbefore: 'SWARMSTACK JS MARKER'
path: "{{SWARMSTACK_LOCAL_DIR}}/caddy/index.html"
block: |
document.getElementById('{{hostvars[item]['inventory_hostname']}}').href = window.location.protocol + '//' + window.location.hostname + ':19998/{{hostvars[item]['inventory_hostname']}}/';
with_items: "{{groups['all']}}"
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add all hosts to caddy/index.html BODY
blockinfile:
marker_begin: "<!-- SWARMSTACK_BEGIN html {{item}} -->"
marker_end: "<!-- SWARMSTACK_END html {{item}} -->"
marker: "{mark}"
insertbefore: 'SWARMSTACK HTML MARKER'
path: "{{SWARMSTACK_LOCAL_DIR}}/caddy/index.html"
block: |
<div class="boxes">
<div class="linkbox"><a href="" id="{{hostvars[item]['inventory_hostname']}}"><h3>NetData - {{hostvars[item]['inventory_hostname']}}</h3></a></div>
<div class="box">Everything happening on your systems and applications</div>
</div>
with_items: "{{groups['all']}}"
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add NetData proxy for all hosts to Caddyfile
blockinfile:
marker_begin: "SWARMSTACK_BEGIN NetData {{item}}"
marker_end: "SWARMSTACK_END NetData {{item}}"
insertbefore: 'SWARMSTACK MARKER'
path: "{{SWARMSTACK_LOCAL_DIR}}/caddy/Caddyfile"
block: |2
proxy /{{hostvars[item]['inventory_hostname']}} http://{{item}}:19999/ {
without /{{hostvars[item]['inventory_hostname']}}
transparent
}
with_items: "{{groups['all']}}"
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add NetData proxy for all hosts to Caddyfile.ldap example
blockinfile:
marker_begin: "SWARMSTACK_BEGIN NetData {{item}}"
marker_end: "SWARMSTACK_END NetData {{item}}"
insertbefore: 'SWARMSTACK MARKER'
path: "{{SWARMSTACK_LOCAL_DIR}}/caddy/Caddyfile.ldap"
block: |2
proxy /{{hostvars[item]['inventory_hostname']}} http://{{item}}:19999/ {
without /{{hostvars[item]['inventory_hostname']}}
transparent
}
with_items: "{{groups['all']}}"
when: "inventory_hostname == SWARMJOIN"
ignore_errors: true
- name: Add CADDY_KEY template to Caddyfile if defined
replace:
path: "{{SWARMSTACK_LOCAL_DIR}}/caddy/Caddyfile"
regexp: '^.*CADDY_CERT.*$'
replace: ' tls {$CADDY_CERT} {$CADDY_KEY}'
ignore_errors: true
when: "inventory_hostname == SWARMJOIN and CADDY_KEY != ''"
- name: Add CADDY_KEY template to Caddyfile.ldap if defined
replace:
path: "{{SWARMSTACK_LOCAL_DIR}}/caddy/Caddyfile.ldap"
regexp: '^.*CADDY_CERT.*$'
replace: ' tls {$CADDY_CERT} {$CADDY_KEY}'
ignore_errors: true
when: "inventory_hostname == SWARMJOIN and CADDY_KEY != ''"
### BOUNCE SWARMSTACK IF ALREADY RUNNING
- name: Check if swarmstack is running
shell: docker service ls | grep swarmstack_caddy; if [ $? -eq 1 ]; then echo 'notrunning'; else echo 'isrunning'; fi
ignore_errors: true
changed_when: false
register: swarmstackrunning
when: "inventory_hostname == SWARMJOIN"
- name: Bring down swarmstack
shell: "docker stack rm swarmstack; sleep 10"
ignore_errors: true
when: "inventory_hostname == SWARMJOIN and swarmstackrunning.stdout.find('isrunning') != -1"
- name: Bring up swarmstack
shell: "ADMIN_PASSWORD={{ADMIN_PASSWORD}} CADDY_CERT={{CADDY_CERT}} CADDY_KEY={{CADDY_KEY}} CADDY_URL={{CADDY_URL}} PUSH_USER={{PUSH_USER}} PUSH_PASSWORD={{PUSH_PASSWORD}} docker stack deploy -c {{SWARMSTACK_LOCAL_DIR}}/docker-compose.yml swarmstack"
ignore_errors: true
when: "inventory_hostname == SWARMJOIN"
...