2018-11-12 22:29:24 +00:00
|
|
|
---
|
|
|
|
- block:
|
2019-06-15 13:54:22 +00:00
|
|
|
- name: Create tmp folder for pve
|
|
|
|
file:
|
|
|
|
path: "{{ __pve_tmp_dir }}"
|
|
|
|
recurse: yes
|
|
|
|
state: directory
|
|
|
|
|
2018-11-12 22:29:24 +00:00
|
|
|
- name: Configure auth provider
|
|
|
|
template:
|
|
|
|
src: etc/pve/domains.cfg.j2
|
2019-06-15 13:54:22 +00:00
|
|
|
dest: "{{ __pve_tmp_dir }}/domains.cfg"
|
|
|
|
owner: root
|
|
|
|
group: www-data
|
2018-11-12 22:29:24 +00:00
|
|
|
mode: 0640
|
2019-06-15 13:54:22 +00:00
|
|
|
register: __pve_domains_copy
|
|
|
|
|
2019-06-15 14:01:47 +00:00
|
|
|
- name: Copy auth provider to pve filesystem
|
2019-06-15 13:54:22 +00:00
|
|
|
command: "/bin/cp -rf {{ __pve_tmp_dir }}/domains.cfg {{ __pve_base_dir }}/domains.cfg"
|
2019-06-15 14:01:47 +00:00
|
|
|
changed_when: __pve_domains_copy.changed
|
2018-11-12 22:29:24 +00:00
|
|
|
become: True
|
|
|
|
become_user: root
|
|
|
|
|
|
|
|
- block:
|
|
|
|
- name: Ensure path for auth file exists
|
|
|
|
file:
|
|
|
|
path: "{{ __pve_base_dir }}/priv/ldap"
|
|
|
|
recurse: yes
|
2018-11-12 22:49:24 +00:00
|
|
|
state: directory
|
2018-11-12 22:29:24 +00:00
|
|
|
|
|
|
|
- name: Add passwd file for ldap bind
|
|
|
|
template:
|
|
|
|
src: etc/pve/priv/ldap.pw.j2
|
2019-06-15 13:54:22 +00:00
|
|
|
dest: "{{ __pve_tmp_dir }}/{{ pve_auth_ldap_realm }}.pw"
|
|
|
|
owner: root
|
|
|
|
group: www-data
|
2021-02-04 22:03:44 +00:00
|
|
|
mode: 0640
|
2019-06-15 13:54:22 +00:00
|
|
|
register: __pve_auth_copy
|
|
|
|
|
2019-06-15 14:01:47 +00:00
|
|
|
- name: Copy passwd file to pve filesystem
|
2019-06-15 13:54:22 +00:00
|
|
|
command: "/bin/cp -rf {{ __pve_tmp_dir }}/{{ pve_auth_ldap_realm }}.pw {{ __pve_base_dir }}/priv/ldap/{{ pve_auth_ldap_realm }}.pw"
|
2019-06-15 14:01:47 +00:00
|
|
|
changed_when: __pve_auth_copy.changed
|
2018-11-12 22:29:24 +00:00
|
|
|
become: True
|
|
|
|
become_user: root
|
|
|
|
when:
|
2019-06-15 14:01:47 +00:00
|
|
|
- pve_auth_ldap_enabled | bool
|
2018-11-12 22:29:24 +00:00
|
|
|
- pve_auth_ldap_bind_password is defined
|