ansible-ffrgb/roles/netbox/tasks/main.yml

147 lines
3.4 KiB
YAML
Raw Normal View History

2020-07-19 12:43:12 +02:00
---
- name: Create group
group: name={{ netbox_group }}
- name: Create user
user: name={{ netbox_user }} home=/home/{{ netbox_user }} group={{ netbox_group }}
- name: Install dependencies
apt:
name:
- build-essential
- libffi-dev
- libpq-dev
- libssl-dev
- libxml2-dev
- libxslt1-dev
- python3-setuptools
2020-07-19 12:43:12 +02:00
- python3-dev
- python3-pip
- python3-venv
- zlib1g-dev
- name: Install PostgreSQL
apt:
name:
- postgresql
- python3-psycopg2
2020-07-19 12:43:12 +02:00
- name: Configure PostgreSQL database
postgresql_db:
2021-11-03 18:25:33 +01:00
name: "{{ netbox_dbname }}"
2020-07-19 12:43:12 +02:00
become: true
become_user: postgres
- name: Configure PostgreSQL user
postgresql_user:
2021-11-03 18:25:33 +01:00
db: "{{ netbox_dbname }}"
name: "{{ netbox_dbuser }}"
password: "{{ netbox_dbpass }}"
priv: ALL
state: present
2020-07-19 12:43:12 +02:00
become: true
become_user: postgres
- name: Install redis
apt: name=redis-server
- name: Unpack netbox
unarchive:
2021-11-03 18:25:33 +01:00
src: "https://github.com/netbox-community/netbox/archive/v{{ netbox_version }}.tar.gz"
dest: /opt
remote_src: yes
2021-11-03 18:25:33 +01:00
creates: "/opt/netbox-{{ netbox_version }}"
2021-07-12 19:18:07 +02:00
register: netbox_unarchive
2020-07-19 12:43:12 +02:00
- name: Configure netbox
template:
src: configuration.py.j2
2021-11-03 18:25:33 +01:00
dest: "/opt/netbox-{{ netbox_version }}/netbox/netbox/configuration.py"
owner: "{{ netbox_user }}"
group: "{{ netbox_group }}"
2021-12-19 10:11:01 +01:00
notify: Restart netbox
2020-07-19 12:43:12 +02:00
- name: Configure gunicorn
template:
src: gunicorn.py.j2
2021-11-03 18:25:33 +01:00
dest: "/opt/netbox-{{ netbox_version }}/gunicorn.py"
owner: "{{ netbox_user }}"
group: "{{ netbox_group }}"
- name: Netbox file permissions
file:
2021-11-03 18:25:33 +01:00
path: "/opt/netbox-{{ netbox_version }}"
owner: "{{ netbox_user }}"
group: "{{ netbox_group }}"
recurse: yes
2021-07-12 19:18:07 +02:00
- name: Run upgrade script
command:
cmd: ./upgrade.sh
2021-11-03 18:25:33 +01:00
chdir: "/opt/netbox-{{ netbox_version }}"
2021-07-12 19:18:07 +02:00
become: true
2021-11-03 18:25:33 +01:00
become_user: "{{ netbox_user }}"
2021-07-12 19:18:07 +02:00
when: netbox_unarchive.changed
2020-07-19 12:43:12 +02:00
# TODO - still manual work
2021-07-12 19:18:07 +02:00
# * Create a super user
# * Migrate media files
2020-07-19 12:43:12 +02:00
2021-08-31 19:02:20 +02:00
- name: Install netbox housekeeping cronjob
template:
src: netbox-housekeeping.sh.j2
dest: /etc/cron.daily/netbox-housekeeping.sh
mode: 0755
2020-07-19 12:43:12 +02:00
- name: Ensure certificates are available
2020-10-08 22:29:54 +02:00
command:
cmd: >
openssl req -x509 -nodes -newkey rsa:2048
-keyout /etc/nginx/ssl/{{ netbox_domain }}.key -out /etc/nginx/ssl/{{ netbox_domain }}.crt
-days 730 -subj "/CN={{ netbox_domain }}"
2021-11-03 18:25:33 +01:00
creates: "/etc/nginx/ssl/{{ netbox_domain }}.crt"
2020-07-19 12:43:12 +02:00
notify: Restart nginx
2021-11-03 18:25:33 +01:00
- name: Request nsupdate key for certificate
include_role: name=acme-dnskey-generate
vars:
acme_dnskey_san_domains:
- "{{ netbox_domain }}"
when: "'kitchen' in group_names"
2021-07-12 19:18:07 +02:00
- name: Configure certificate manager for netbox
template: src=certs.j2 dest=/etc/acertmgr/{{ netbox_domain }}.conf
notify: Run acertmgr
2020-07-19 12:43:12 +02:00
- name: Configure vhost
template:
src: vhost.j2
dest: /etc/nginx/sites-available/netbox
owner: root
2021-11-03 18:25:33 +01:00
mode: "0644"
2020-07-19 12:43:12 +02:00
notify: Restart nginx
- name: Enable vhost
file:
src: /etc/nginx/sites-available/netbox
dest: /etc/nginx/sites-enabled/netbox
state: link
2020-07-19 12:43:12 +02:00
notify: Restart nginx
- name: Install systemd units
template: src={{ item }}.service.j2 dest=/lib/systemd/system/{{ item }}.service
with_items:
- netbox
- netbox-rq
notify:
- Reload systemd
- Restart netbox
- Restart netbox-rq
- name: Enable services
service: name={{ item }} state=started enabled=yes
with_items:
- netbox
- netbox-rq