From: Arvind Patel Date: Wed, 22 Jul 2020 18:03:01 +0000 (+0530) Subject: Deployment mode added X-Git-Url: https://gerrit.akraino.org/r/gitweb?a=commitdiff_plain;h=42ca3fcbed3996d68e1e7d3035e5e859eef7edb5;p=ealt-edge.git Deployment mode added Change-Id: I682e0f8b4025e020019cdeff6fbf0db1a5a8e9ee --- diff --git a/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml b/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml new file mode 100644 index 0000000..5aa5b43 --- /dev/null +++ b/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml @@ -0,0 +1,70 @@ +# Copyright 2020 Huawei Technologies Co., Ltd. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +--- +- name: mep namespace + shell: + cmd: kubectl create namespace mep + ignore_errors: 'True' + +- name: copy deploy folder to mep node to install mepserver + copy: + src: deploy + dest: /tmp/mepserver/ + +- name: modifying configuration to support https + shell: + cmd: cp mep-k8s.yaml mep-k8s-ssl.yaml + chdir: /tmp/mepserver/deploy/ + +- name: modifying configuration to support https + shell: + cmd: cp mep-k8s.yaml kong-k8s-ssl.yaml + chdir: /tmp/mepserver/deploy/ + +- name: modify configuraiton to support https + shell: + cmd: chmod +x mepScript.sh && ./mepScript.sh + chdir: /tmp/mepserver/deploy/ + +- name: modify configuraiton to support https + shell: + cmd: chmod +x kongScript.sh && ./kongScript.sh + chdir: /tmp/mepserver/deploy/ + +- name: Create mepssl-secret + shell: +# yamllint disable rule:line-length + cmd: kubectl create secret --namespace mep generic mepssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer + +- name: Create kongssl-secret + shell: +# yamllint disable rule:line-length + cmd: kubectl create secret --namespace mep generic kongssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer + +- name: Apply mep-basic.yaml + shell: + cmd: kubectl apply -f /tmp/mepserver/deploy/mep-basic.yaml + +- name: Apply mep-k8s.yaml + shell: + cmd: kubectl apply -f /tmp/mepserver/deploy/mep-k8s-ssl.yaml + +- name: Apply kong-k8s.yaml + shell: + cmd: kubectl apply -f /tmp/mepserver/deploy/kong-k8s-ssl.yaml + +- name: Apply postgres-k8s.yaml + shell: + cmd: kubectl apply -f /tmp/mepserver/deploy/postgres-k8s.yaml diff --git a/ocd/infra/playbooks/roles/mepserver/tasks/install.yml b/ocd/infra/playbooks/roles/mepserver/tasks/install.yml index b739ae2..fdf7940 100644 --- a/ocd/infra/playbooks/roles/mepserver/tasks/install.yml +++ b/ocd/infra/playbooks/roles/mepserver/tasks/install.yml @@ -23,47 +23,6 @@ src: deploy dest: /tmp/mepserver/ -- name: Generate Certificates - shell: -# yamllint disable rule:line-length - cmd: openssl genrsa -out ca.key 2048 - chdir: /tmp/mepserver/deploy/ - -- name: Generate Certificate - Step 2 - shell: - cmd: openssl req -new -key ca.key -subj /C=CN/ST=Peking/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out ca.csr - chdir: /tmp/mepserver/deploy/ - -- name: Generate Root Certificate - shell: - cmd: openssl x509 -req -days 365 -in ca.csr -extensions v3_req -signkey ca.key -out trust.cer - chdir: /tmp/mepserver/deploy/ - -- name: Generate TLS certificate and TLS Key - shell: - cmd: openssl genrsa -out server_key.pem 2048 - chdir: /tmp/mepserver/deploy/ - -- name: Generate TLS Certificate and TLS Key - shell: - cmd: openssl req -new -key server_key.pem -subj /C=CN/ST=Beijing/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out tls.csr - chdir: /tmp/mepserver/deploy/ - -- name: Generate TLS Certificate and TLS Key - shell: - cmd: openssl x509 -req -in tls.csr -extensions v3_req -CA trust.cer -CAkey ca.key -CAcreateserial -out server.cer - chdir: /tmp/mepserver/deploy/ - -- name: Create mepssl-secret - shell: -# yamllint disable rule:line-length - cmd: kubectl create secret --namespace mep generic mepssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer - -- name: Create kongssl-secret - shell: -# yamllint disable rule:line-length - cmd: kubectl create secret --namespace mep generic kongssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer - - name: Apply mep-basic.yaml shell: cmd: kubectl apply -f /tmp/mepserver/deploy/mep-basic.yaml @@ -79,12 +38,3 @@ - name: Apply postgres-k8s.yaml shell: cmd: kubectl apply -f /tmp/mepserver/deploy/postgres-k8s.yaml - -- name: -----Configuring Kong API Gateway----- - shell: - cmd: sleep 30 - -- name: Configuring Kong API Gateway - shell: - cmd: chmod +x kongconfig.sh && ./kongconfig.sh - chdir: /tmp/mepserver/deploy/ diff --git a/ocd/infra/playbooks/roles/mepserver/tasks/main.yml b/ocd/infra/playbooks/roles/mepserver/tasks/main.yml index fc34c0a..17cc6ff 100644 --- a/ocd/infra/playbooks/roles/mepserver/tasks/main.yml +++ b/ocd/infra/playbooks/roles/mepserver/tasks/main.yml @@ -14,4 +14,7 @@ --- - include: "install.yml" - when: operation == 'install' + when: operation == 'install' and mode == 'dev' + +- include: "install-ssl.yml" + when: operation == 'install' and mode == 'prod'