xoxys.pve/tasks/auth.yml

43 lines
1.3 KiB
YAML
Raw Normal View History

2018-11-12 23:29:24 +01:00
---
2024-02-19 10:50:15 +01:00
- name: Create tmp folder for pve
ansible.builtin.file:
path: "{{ __pve_tmp_dir }}"
recurse: True
state: directory
2024-02-19 10:50:15 +01:00
- name: Configure auth provider
ansible.builtin.template:
src: etc/pve/domains.cfg.j2
dest: "{{ __pve_tmp_dir }}/domains.cfg"
owner: root
group: www-data
mode: "0640"
register: __pve_domains_copy
2024-02-19 10:50:15 +01:00
- name: Copy auth provider to pve filesystem
ansible.builtin.command: "/bin/cp -rf {{ __pve_tmp_dir }}/domains.cfg {{ __pve_base_dir }}/domains.cfg"
changed_when: __pve_domains_copy.changed
2018-11-12 23:29:24 +01:00
2024-02-19 10:50:15 +01:00
- when:
- pve_auth_ldap_enabled | bool
- pve_auth_ldap_bind_password is defined
block:
2018-11-12 23:29:24 +01:00
- name: Ensure path for auth file exists
2024-02-19 10:50:15 +01:00
ansible.builtin.file:
2018-11-12 23:29:24 +01:00
path: "{{ __pve_base_dir }}/priv/ldap"
2024-02-19 10:50:15 +01:00
recurse: True
2018-11-12 23:49:24 +01:00
state: directory
2018-11-12 23:29:24 +01:00
- name: Add passwd file for ldap bind
2024-02-19 10:50:15 +01:00
ansible.builtin.template:
2018-11-12 23:29:24 +01:00
src: etc/pve/priv/ldap.pw.j2
dest: "{{ __pve_tmp_dir }}/{{ pve_auth_ldap_realm }}.pw"
owner: root
group: www-data
2024-02-19 10:50:15 +01:00
mode: "0640"
register: __pve_auth_copy
- name: Copy passwd file to pve filesystem
2024-02-19 10:50:15 +01:00
ansible.builtin.command: "/bin/cp -rf {{ __pve_tmp_dir }}/{{ pve_auth_ldap_realm }}.pw {{ __pve_base_dir }}/priv/ldap/{{ pve_auth_ldap_realm }}.pw"
changed_when: __pve_auth_copy.changed