Deployment mode added 36/3636/1
authorArvind Patel <arvind.patel@huawei.com>
Wed, 22 Jul 2020 18:03:01 +0000 (23:33 +0530)
committerArvind Patel <arvind.patel@huawei.com>
Wed, 22 Jul 2020 18:06:20 +0000 (23:36 +0530)
Change-Id: I682e0f8b4025e020019cdeff6fbf0db1a5a8e9ee

ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml [new file with mode: 0644]
ocd/infra/playbooks/roles/mepserver/tasks/install.yml
ocd/infra/playbooks/roles/mepserver/tasks/main.yml

diff --git a/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml b/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml
new file mode 100644 (file)
index 0000000..5aa5b43
--- /dev/null
@@ -0,0 +1,70 @@
+# Copyright 2020 Huawei Technologies Co., Ltd.
+#
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+#     http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+---
+- name: mep namespace
+  shell:
+    cmd: kubectl create namespace mep
+  ignore_errors: 'True'
+
+- name: copy deploy folder to mep node to install mepserver
+  copy:
+    src: deploy
+    dest: /tmp/mepserver/
+
+- name: modifying configuration to support https
+  shell:
+    cmd: cp mep-k8s.yaml mep-k8s-ssl.yaml
+    chdir: /tmp/mepserver/deploy/
+
+- name: modifying configuration to support https
+  shell:
+    cmd: cp mep-k8s.yaml kong-k8s-ssl.yaml
+    chdir: /tmp/mepserver/deploy/
+
+- name: modify configuraiton to support https
+  shell:
+    cmd: chmod +x mepScript.sh && ./mepScript.sh
+    chdir: /tmp/mepserver/deploy/
+
+- name: modify configuraiton to support https
+  shell:
+    cmd: chmod +x kongScript.sh && ./kongScript.sh
+    chdir: /tmp/mepserver/deploy/
+
+- name: Create mepssl-secret
+  shell:
+# yamllint disable rule:line-length
+    cmd: kubectl create secret --namespace mep generic mepssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer
+
+- name: Create kongssl-secret
+  shell:
+# yamllint disable rule:line-length
+    cmd: kubectl create secret --namespace mep generic kongssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer
+
+- name: Apply mep-basic.yaml
+  shell:
+    cmd: kubectl apply -f /tmp/mepserver/deploy/mep-basic.yaml
+
+- name: Apply mep-k8s.yaml
+  shell:
+    cmd: kubectl apply -f /tmp/mepserver/deploy/mep-k8s-ssl.yaml
+
+- name: Apply kong-k8s.yaml
+  shell:
+    cmd: kubectl apply -f /tmp/mepserver/deploy/kong-k8s-ssl.yaml
+
+- name: Apply postgres-k8s.yaml
+  shell:
+    cmd: kubectl apply -f /tmp/mepserver/deploy/postgres-k8s.yaml
index b739ae2..fdf7940 100644 (file)
     src: deploy
     dest: /tmp/mepserver/
 
-- name: Generate Certificates
-  shell:
-# yamllint disable rule:line-length
-    cmd: openssl genrsa -out ca.key 2048
-    chdir: /tmp/mepserver/deploy/
-
-- name: Generate Certificate - Step 2
-  shell:
-    cmd: openssl req -new -key ca.key -subj /C=CN/ST=Peking/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out ca.csr
-    chdir: /tmp/mepserver/deploy/
-
-- name: Generate Root Certificate
-  shell:
-    cmd: openssl x509 -req -days 365 -in ca.csr -extensions v3_req -signkey ca.key -out trust.cer
-    chdir: /tmp/mepserver/deploy/
-
-- name: Generate TLS certificate and TLS Key
-  shell:
-    cmd: openssl genrsa -out server_key.pem 2048
-    chdir: /tmp/mepserver/deploy/
-
-- name: Generate TLS Certificate and TLS Key
-  shell:
-    cmd: openssl req -new -key server_key.pem -subj /C=CN/ST=Beijing/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out tls.csr
-    chdir: /tmp/mepserver/deploy/
-
-- name: Generate TLS Certificate and TLS Key
-  shell:
-    cmd: openssl x509 -req -in tls.csr -extensions v3_req -CA trust.cer -CAkey ca.key -CAcreateserial -out server.cer
-    chdir: /tmp/mepserver/deploy/
-
-- name: Create mepssl-secret
-  shell:
-# yamllint disable rule:line-length
-    cmd: kubectl create secret --namespace mep generic mepssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer
-
-- name: Create kongssl-secret
-  shell:
-# yamllint disable rule:line-length
-    cmd: kubectl create secret --namespace mep generic kongssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer
-
 - name: Apply mep-basic.yaml
   shell:
     cmd: kubectl apply -f /tmp/mepserver/deploy/mep-basic.yaml
 - name: Apply postgres-k8s.yaml
   shell:
     cmd: kubectl apply -f /tmp/mepserver/deploy/postgres-k8s.yaml
-
-- name: -----Configuring Kong API Gateway-----
-  shell:
-    cmd: sleep 30
-
-- name: Configuring Kong API Gateway
-  shell:
-    cmd: chmod +x kongconfig.sh && ./kongconfig.sh
-    chdir: /tmp/mepserver/deploy/
index fc34c0a..17cc6ff 100644 (file)
@@ -14,4 +14,7 @@
 
 ---
 - include: "install.yml"
-  when: operation == 'install'
+  when: operation == 'install' and mode == 'dev'
+
+- include: "install-ssl.yml"
+  when: operation == 'install' and mode == 'prod'