This repository has been archived by the owner on Aug 19, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 4
/
Copy pathdeploy_deepsecurity.yml
121 lines (105 loc) · 4.1 KB
/
deploy_deepsecurity.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
---
# #####################################################################
# Deploy PostgreSQL database for Deep Security
# #####################################################################
# #####################################################################
# Query some private ips
# #####################################################################
- hosts: tag_role_jumphost
tasks:
- name: Get ipaddr of Jumphost
set_fact:
remote_ip: "{{ inventory_hostname | ipaddr}}"
- name: Get ipaddr of Jumphost
set_fact:
remote_ip: "{{ hostvars[inventory_hostname]['ansible_default_ipv4']['address'] }}"
when: not remote_ip
- name: Store external ip address of Jumphost
add_host:
name: "{{ remote_ip }}"
groups: "moadsd_ng_jumphost_instance_public"
- name: Store all Groups in Memory
set_fact:
moadsd_ng_groups: "{{ hostvars[inventory_hostname]['groups'] }}"
- hosts: localhost
gather_facts: no
tasks:
- name: Include vars
include: site_vars.yml
- name: Listing Jumphost Environment
debug:
msg:
- "Jumphost : {{ jumphost_ip }}"
when: site_deploy_jumphost == True
- name: Listing Kubernetes Environment
debug:
msg:
- "Kubernetes Master : {{ k8smaster_ip }}"
- "Kubernetes Worker 1 : {{ k8sworker1_ip }}"
when: site_deploy_kubernetes == True
- name: Listing OpenShift Environment
debug:
msg:
- "OpenShift Master : {{ openshift_ip }}"
when: site_deploy_openshift == True
- name: Listing Deep Security Environment
debug:
msg:
- "Deep Security : {{ dsm_ip }}"
- "PostgreSQL : {{ dsmdb_ip }}"
when:
- site_deploy_deepsecurity == True
- deepsecurity_variant == 'dsm'
# #####################################################################
# Deploy PostgreSQL database for Deep Security
# #####################################################################
- name: Create PostgreSQL database for Deep Security
hosts: tag_role_dsm_db:&tag_user_{{ user }}
become: true
vars:
tasks:
- name: Include vars
include: site_vars.yml
- name: Deploy PostgreSQL
include_role:
name: postgresql
vars:
operation: deploy
database_client: "{{ dsmdb_ip }}"
when: site_deploy_deepsecurity == True
- name: Create Database for Deep Security in PostgreSQL
include_role:
name: postgresql
vars:
operation: create_database
database_name: "{{ deepsecurity_database_name }}"
database_user: "{{ deepsecurity_database_user }}"
database_password: "{{ deepsecurity_database_password }}"
database_role_attr_flags: "{{ deepsecurity_database_role_attr_flags }}"
database_priv: "{{ deepsecurity_database_priv }}"
when: site_deploy_deepsecurity == True
# #####################################################################
# Deploy Deep Security
# #####################################################################
- name: Deploy Deep Security
hosts: tag_role_dsm:&tag_user_{{ user }}
become: true
tasks:
- name: Include vars
include: site_vars.yml
- name: Deploy Deep Security
include_role:
name: deepsecurity
vars:
operation: deploy
addressandportsscreen_manageraddress: "{{ dsm_ip }}"
licensescreen_license: '{{ deepsecurity_license }}'
databasescreen_hostname: "{{ dsmdb_ip }}"
databasescreen_databasename: "{{ deepsecurity_database_name }}"
databasescreen_username: "{{ deepsecurity_database_user }}"
databasescreen_password: "{{ deepsecurity_database_password }}"
credentialsscreen_administrator_username: "{{ deepsecurity_administrator_username }}"
credentialsscreen_administrator_password: "{{ deepsecurity_administrator_password }}"
dsm_download_url: "{{ deepsecurity_download_url }}"
dsm_installer: "{{ deepsecurity_installer }}"
# when: site_deploy_deepsecurity == True