Merge pull request #291 from rusnyder/role-mapping-xpack-dir

Moved up the x-pack directory logic to include role_mappings
This commit is contained in:
Dale McDiarmid 2017-08-15 14:59:22 +01:00 committed by GitHub
commit 32ff70601a
2 changed files with 9 additions and 7 deletions

View file

@ -1,12 +1,6 @@
--- ---
- set_fact: manage_file_users=es_users is defined and es_users.file is defined - set_fact: manage_file_users=es_users is defined and es_users.file is defined
#Ensure x-pack conf directory is created
- name: Ensure x-pack conf directory exists (file)
file: path={{ conf_dir }}/x-pack state=directory owner={{ es_user }} group={{ es_group }}
changed_when: False
when: es_enable_xpack and '"security" in es_xpack_features'
#List current users #List current users
- name: List Users - name: List Users
shell: cat {{conf_dir}}/x-pack/users | awk -F':' '{print $1}' shell: cat {{conf_dir}}/x-pack/users | awk -F':' '{print $1}'
@ -70,4 +64,4 @@
#Set permission on security directory. E.g. if 2 nodes are installed on the same machine, the second node will not get the users file created at install, causing the files being created at es_users call and then having the wrong Permissions. #Set permission on security directory. E.g. if 2 nodes are installed on the same machine, the second node will not get the users file created at install, causing the files being created at es_users call and then having the wrong Permissions.
- name: Set Security Directory Permissions Recursive - name: Set Security Directory Permissions Recursive
file: state=directory path={{conf_dir}}/x-pack/ owner={{ es_user }} group={{ es_group }} recurse=yes file: state=directory path={{conf_dir}}/x-pack/ owner={{ es_user }} group={{ es_group }} recurse=yes

View file

@ -3,6 +3,14 @@
#TODO: 1. Skip users with no password defined or error 2. Passwords | length > 6 #TODO: 1. Skip users with no password defined or error 2. Passwords | length > 6
#Ensure x-pack conf directory is created if necessary
- name: Ensure x-pack conf directory exists (file)
file: path={{ conf_dir }}/x-pack state=directory owner={{ es_user }} group={{ es_group }}
changed_when: False
when:
- es_enable_xpack and '"security" in es_xpack_features'
- (es_users is defined and es_users.file) or (es_roles is defined and es_roles.file is defined) or (es_role_mapping is defined)
#-----------------------------FILE BASED REALM---------------------------------------- #-----------------------------FILE BASED REALM----------------------------------------
- include: elasticsearch-security-file.yml - include: elasticsearch-security-file.yml