2016-07-22 23:44:27 +01:00
|
|
|
---
|
|
|
|
|
- name: Elasticsearch Xpack tests
|
2016-07-23 19:48:50 +01:00
|
|
|
hosts: localhost
|
2016-07-22 23:44:27 +01:00
|
|
|
roles:
|
2016-07-24 12:25:34 +01:00
|
|
|
- { role: elasticsearch, es_config: { "http.port": 9200, "transport.tcp.port":9300, discovery.zen.ping.unicast.hosts: "localhost:9300",
|
|
|
|
|
"shield.authc.realms.file1.type": "file","shield.authc.realms.file1.order": 0, "shield.authc.realms.native1.type": "native","shield.authc.realms.native1.order": 1 },
|
|
|
|
|
es_instance_name: "shield_node" }
|
2016-07-22 23:44:27 +01:00
|
|
|
vars:
|
2016-07-23 20:23:56 +01:00
|
|
|
es_templates: true
|
2016-07-22 23:44:27 +01:00
|
|
|
es_enable_xpack: true
|
2016-07-24 17:39:44 +01:00
|
|
|
es_plugins:
|
|
|
|
|
- plugin: lmenezes/elasticsearch-kopf
|
|
|
|
|
version: master
|
2016-07-22 23:44:27 +01:00
|
|
|
es_xpack_features:
|
|
|
|
|
- shield
|
2016-07-24 15:25:32 +01:00
|
|
|
- watcher
|
2016-07-22 23:44:27 +01:00
|
|
|
es_api_basic_auth_username: es_admin
|
|
|
|
|
es_api_basic_auth_password: changeMe
|
2016-09-19 13:57:09 +01:00
|
|
|
es_role_mapping:
|
|
|
|
|
power_user:
|
|
|
|
|
- "cn=admins,dc=example,dc=com"
|
|
|
|
|
user:
|
|
|
|
|
- "cn=users,dc=example,dc=com"
|
|
|
|
|
- "cn=admins,dc=example,dc=com"
|
2016-07-22 23:44:27 +01:00
|
|
|
es_users:
|
|
|
|
|
native:
|
|
|
|
|
kibana4_server:
|
|
|
|
|
password: changeMe
|
|
|
|
|
roles:
|
|
|
|
|
- kibana4_server
|
|
|
|
|
file:
|
|
|
|
|
es_admin:
|
|
|
|
|
password: changeMe
|
|
|
|
|
roles:
|
|
|
|
|
- admin
|
|
|
|
|
testUser:
|
|
|
|
|
password: changeMeAlso!
|
|
|
|
|
roles:
|
|
|
|
|
- power_user
|
|
|
|
|
- user
|
|
|
|
|
es_roles:
|
|
|
|
|
file:
|
|
|
|
|
admin:
|
|
|
|
|
cluster:
|
|
|
|
|
- all
|
|
|
|
|
indices:
|
|
|
|
|
- names: '*'
|
|
|
|
|
privileges:
|
|
|
|
|
- all
|
|
|
|
|
power_user:
|
|
|
|
|
cluster:
|
|
|
|
|
- monitor
|
|
|
|
|
indices:
|
|
|
|
|
- names: '*'
|
|
|
|
|
privileges:
|
|
|
|
|
- all
|
|
|
|
|
user:
|
|
|
|
|
indices:
|
|
|
|
|
- names: '*'
|
|
|
|
|
privileges:
|
|
|
|
|
- read
|
|
|
|
|
kibana4_server:
|
|
|
|
|
cluster:
|
|
|
|
|
- monitor
|
|
|
|
|
indices:
|
|
|
|
|
- names: '.kibana'
|
|
|
|
|
privileges:
|
|
|
|
|
- all
|
|
|
|
|
native:
|
|
|
|
|
logstash:
|
|
|
|
|
cluster:
|
|
|
|
|
- manage_index_templates
|
|
|
|
|
indices:
|
|
|
|
|
- names: 'logstash-*'
|
|
|
|
|
privileges:
|
|
|
|
|
- write
|
|
|
|
|
- delete
|
|
|
|
|
- create_index
|
|
|
|
|
|