openstack-ansible-os_ironic/tasks/ironic_service_setup.yml
Jesse Pretorius a3c076d5a1 Remove dependency on the Keystone admin auth token
Now that auth token usage is deprecated, prefer the admin
user and password for all service setup tasks run against
keystone.

Change-Id: I177bdff0e789f43f192253dce886d0e5bf10a4b5
2016-03-23 12:54:57 +00:00

108 lines
3.5 KiB
YAML

---
# Copyright 2016, Rackspace US, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# Create a service
- name: Ensure ironic service
keystone:
command: "ensure_service"
login_user: "{{ keystone_admin_user_name }}"
login_password: "{{ keystone_auth_admin_password }}"
login_project_name: "{{ keystone_admin_tenant_name }}"
endpoint: "{{ keystone_service_adminurl }}"
service_name: "{{ ironic_service_name }}"
service_type: "{{ ironic_service_type }}"
description: "{{ ironic_service_description }}"
insecure: "{{ keystone_service_adminuri_insecure }}"
register: add_service
until: add_service|success
retries: 5
delay: 2
tags:
- ironic-api-setup
- ironic-service-add
- ironic-setup
# Create an admin user
- name: Ensure ironic user
keystone:
command: "ensure_user"
login_user: "{{ keystone_admin_user_name }}"
login_password: "{{ keystone_auth_admin_password }}"
login_project_name: "{{ keystone_admin_tenant_name }}"
endpoint: "{{ keystone_service_adminurl }}"
user_name: "{{ ironic_service_user_name }}"
project_name: "{{ ironic_service_project_name }}"
password: "{{ ironic_service_password }}"
insecure: "{{ keystone_service_adminuri_insecure }}"
register: add_service
when: not ironic_service_in_ldap | bool
until: add_service|success
retries: 5
delay: 10
tags:
- ironic-api-setup
- ironic-service-add
- ironic-setup
# Add a role to the user
- name: Ensure ironic user to admin role
keystone:
command: "ensure_user_role"
login_user: "{{ keystone_admin_user_name }}"
login_password: "{{ keystone_auth_admin_password }}"
login_project_name: "{{ keystone_admin_tenant_name }}"
endpoint: "{{ keystone_service_adminurl }}"
user_name: "{{ ironic_service_user_name }}"
project_name: "{{ ironic_service_project_name }}"
role_name: "{{ ironic_service_role_name }}"
insecure: "{{ keystone_service_adminuri_insecure }}"
register: add_service
when: not ironic_service_in_ldap | bool
until: add_service|success
retries: 5
delay: 10
tags:
- ironic-api-setup
- ironic-service-add
- ironic-setup
# Create an endpoint
- name: Ensure ironic endpoint
keystone:
command: "ensure_endpoint"
login_user: "{{ keystone_admin_user_name }}"
login_password: "{{ keystone_auth_admin_password }}"
login_project_name: "{{ keystone_admin_tenant_name }}"
endpoint: "{{ keystone_service_adminurl }}"
region_name: "{{ ironic_service_region }}"
service_name: "{{ ironic_service_name }}"
service_type: "{{ ironic_service_type }}"
insecure: "{{ keystone_service_adminuri_insecure }}"
endpoint_list:
- url: "{{ ironic_service_publicurl }}"
interface: "public"
- url: "{{ ironic_service_internalurl }}"
interface: "internal"
- url: "{{ ironic_service_adminurl }}"
interface: "admin"
register: add_service
until: add_service|success
retries: 5
delay: 10
tags:
- ironic-api-setup
- ironic-service-add
- ironic-setup