
There has been one confirmed denial-of-service against the opendev git servers due to an openstack-ansible deployment failing to correctly use cached wheels from the repo server and instead clone and build the source code for each openstack service on each target host. Whilst we wait for further information to understand the root cause of that DOS, it is possible to adjust the user-agent that git uses on a per-domain basis. This patch sets the user-agent to a string which identifies that OSA is responsible for git operations, which version of OSA is in use, and if the host is a deploy host or an AIO build. Change-Id: I8157c744a58a8ade56776e8cb29956a8abed081c
179 lines
5.1 KiB
YAML
179 lines
5.1 KiB
YAML
---
|
|
# Copyright 2015, Rackspace US, Inc.
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
# Identify AIO builds in the git user-agent
|
|
- include_tasks: prepare_git_useragent.yml
|
|
|
|
# Attempt data device detection if enabled
|
|
- include_tasks: detect_data_disk_device.yml
|
|
when:
|
|
- bootstrap_host_data_disk_device is none
|
|
- bootstrap_host_data_disk_device_detect | bool
|
|
|
|
# Before we do anything, check the minimum requirements
|
|
- include: check-requirements.yml
|
|
tags:
|
|
- check-requirements
|
|
|
|
# We will look for the most specific variable files first and eventually
|
|
# end up with the least-specific files.
|
|
- name: Gather variables for each operating system
|
|
include_vars: "{{ item }}"
|
|
with_first_found:
|
|
- "{{ ansible_facts['distribution'] | lower }}-{{ ansible_facts['distribution_version'] | lower }}.yml"
|
|
- "{{ ansible_facts['distribution'] | lower }}-{{ ansible_facts['distribution_major_version'] | lower }}.yml"
|
|
- "{{ ansible_facts['os_family'] | lower }}-{{ ansible_facts['distribution_major_version'] | lower }}.yml"
|
|
- "{{ ansible_facts['distribution'] | lower }}.yml"
|
|
- "{{ ansible_facts['os_family'] | lower }}.yml"
|
|
tags:
|
|
- always
|
|
|
|
- name: Gather nodepool variables
|
|
include: gather_nodepool_vars.yml
|
|
|
|
- name: Create the required directories
|
|
file:
|
|
path: "{{ item }}"
|
|
state: directory
|
|
with_items:
|
|
- "/openstack"
|
|
tags:
|
|
- create-directories
|
|
|
|
- include: install_packages.yml
|
|
tags:
|
|
- install-packages
|
|
|
|
# Prepare the data disk, if one is provided
|
|
- include: prepare_data_disk.yml
|
|
when:
|
|
- bootstrap_host_data_disk_device != None
|
|
tags:
|
|
- prepare-data-disk
|
|
|
|
# Symlink host repos to /openstack/src to match the lxc continer bind mount
|
|
# NOTE(jrosser) this must happen *after* prepare_data_disk as /openstack may remounted
|
|
- name: Symlink /openstack/src to /home/zuul/src
|
|
file:
|
|
src: "{{ lookup('env', 'ZUUL_SRC_PATH') }}"
|
|
dest: '/openstack/src'
|
|
state: link
|
|
when:
|
|
- "lookup('env', 'ZUUL_SRC_PATH') | length > 0"
|
|
|
|
# Prepare the swap space loopback disk
|
|
# This is only necessary if there isn't swap already
|
|
- include: prepare_loopback_swap.yml
|
|
static: no
|
|
when:
|
|
- bootstrap_host_loopback_swap | bool
|
|
- ansible_facts['swaptotal_mb'] < 1
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the Machines storage loopback disk
|
|
- include: prepare_loopback_machines.yml
|
|
when:
|
|
- bootstrap_host_loopback_machines | bool
|
|
- bootstrap_host_data_disk_device == None
|
|
- lxc_container_backing_store == 'machinectl' or bootstrap_host_container_tech == 'nspawn'
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the zfs storage loopback disk
|
|
- include: prepare_loopback_zfs.yml
|
|
when:
|
|
- bootstrap_host_loopback_zfs | bool
|
|
- bootstrap_host_data_disk_device == None
|
|
- lxc_container_backing_store == 'zfs'
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the btrfs storage loopback disk
|
|
- include: prepare_loopback_btrfs.yml
|
|
when:
|
|
- bootstrap_host_loopback_btrfs | bool
|
|
- bootstrap_host_data_disk_device == None
|
|
- lxc_container_backing_store == 'btrfs'
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the Cinder LVM VG loopback disk
|
|
# This is only necessary if bootstrap_host_loopback_cinder is set to yes
|
|
- include: prepare_loopback_cinder.yml
|
|
when:
|
|
- bootstrap_host_loopback_cinder | bool
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the Nova instance storage loopback disk
|
|
- include: prepare_loopback_nova.yml
|
|
when:
|
|
- bootstrap_host_loopback_nova | bool
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the Swift data storage loopback disks
|
|
- include: prepare_loopback_swift.yml
|
|
when:
|
|
- bootstrap_host_loopback_swift | bool
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the Manila data storage loopback disks
|
|
- include: prepare_loopback_manila.yml
|
|
when:
|
|
- bootstrap_host_loopback_manila | bool
|
|
tags:
|
|
- prepare-loopback
|
|
|
|
# Prepare the Ceph cluster UUID and loopback disks
|
|
- include: prepare_ceph.yml
|
|
when:
|
|
- bootstrap_host_ceph | bool
|
|
tags:
|
|
- prepare-ceph
|
|
|
|
# Ensure hostname/ip is consistent with inventory
|
|
- include: prepare_hostname.yml
|
|
tags:
|
|
- prepare-hostname
|
|
|
|
# Prepare the network interfaces
|
|
- include: prepare_networking.yml
|
|
when:
|
|
- bootstrap_host_container_tech != 'nspawn'
|
|
tags:
|
|
- prepare-networking
|
|
|
|
# Ensure that there are both private and public ssh keys for root
|
|
- include: prepare_ssh_keys.yml
|
|
tags:
|
|
- prepare-ssh-keys
|
|
|
|
# Prepare local squid proxy
|
|
- include: prepare_squid.yml
|
|
when:
|
|
- "'proxy' in bootstrap_host_scenarios_expanded"
|
|
tags:
|
|
- prepare-squid
|
|
|
|
# Put the OpenStack-Ansible configuration for an All-In-One on the host
|
|
- include: prepare_aio_config.yml
|
|
when:
|
|
- bootstrap_host_aio_config | bool
|
|
tags:
|
|
- prepare-aio-config
|