{"id":471,"sha1":"a9c88ea4e00e5250a206ba25ec4bc1284236d216","playbook":{"id":4,"items":{"plays":107,"tasks":2438,"results":2413,"hosts":13,"files":511,"records":0},"arguments":{"version":null,"verbosity":0,"private_key_file":null,"remote_user":null,"connection":"openstack.osa.ssh","timeout":null,"ssh_common_args":null,"sftp_extra_args":null,"scp_extra_args":null,"ssh_extra_args":null,"ask_pass":false,"connection_password_file":null,"force_handlers":true,"flush_cache":false,"become":false,"become_method":"sudo","become_user":null,"become_ask_pass":false,"become_password_file":null,"tags":["all"],"skip_tags":[],"check":false,"diff":false,"inventory":["/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/dynamic_inventory.py","/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/inventory.ini","/etc/openstack_deploy/inventory.ini"],"listhosts":false,"subset":null,"extra_vars":"Not saved by ARA as configured by 'ignored_arguments'","vault_ids":[],"ask_vault_pass":false,"vault_password_files":[],"forks":4,"module_path":null,"syntax":false,"listtasks":false,"listtags":false,"step":false,"start_at_task":null,"args":["setup-openstack.yml"]},"labels":[{"id":1,"name":"check:False"},{"id":2,"name":"tags:all"}],"started":"2025-12-14T10:21:40.790759Z","ended":"2025-12-14T11:05:36.775743Z","duration":"00:43:55.984984","name":null,"ansible_version":"2.18.6","client_version":"1.7.4","python_version":"3.13.5","server_version":"1.7.4","status":"completed","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible/playbooks/setup-openstack.yml","controller":"aio1.openstack.local","user":"root"},"content":"---\n# Copyright 2014, Rackspace US, Inc.\n#\n# Licensed under the Apache License, Version 2.0 (the \"License\");\n# you may not use this file except in compliance with the License.\n# You may obtain a copy of the License at\n#\n#     http://www.apache.org/licenses/LICENSE-2.0\n#\n# Unless required by applicable law or agreed to in writing, software\n# distributed under the License is distributed on an \"AS IS\" BASIS,\n# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n# See the License for the specific language governing permissions and\n# limitations under the License.\n\n- name: Deploy Glance configuration files\n  openstack.config_template.config_template:\n    src: \"{{ item.src | default(omit) }}\"\n    content: \"{{ item.content | default(omit) }}\"\n    dest: \"{{ item.dest }}\"\n    owner: \"root\"\n    group: \"{{ glance_system_group_name }}\"\n    mode: \"0640\"\n    config_overrides: \"{{ item.config_overrides }}\"\n    config_type: \"{{ item.config_type }}\"\n  when: item.condition | default(True)\n  with_items:\n    - src: \"glance-api.conf.j2\"\n      dest: \"{{ glance_etc_dir }}/glance-api.conf\"\n      config_overrides: \"{{ glance_glance_api_conf_overrides }}\"\n      config_type: \"ini\"\n    - src: \"glance-cache.conf.j2\"\n      dest: \"{{ glance_etc_dir }}/glance-cache.conf\"\n      config_overrides: \"{{ glance_glance_cache_conf_overrides }}\"\n      config_type: \"ini\"\n    - src: \"glance-manage.conf.j2\"\n      dest: \"{{ glance_etc_dir }}/glance-manage.conf\"\n      config_overrides: \"{{ glance_glance_manage_conf_overrides }}\"\n      config_type: \"ini\"\n    - src: \"glance-scrubber.conf.j2\"\n      dest: \"{{ glance_etc_dir }}/glance-scrubber.conf\"\n      config_overrides: \"{{ glance_glance_scrubber_conf_overrides }}\"\n      config_type: \"ini\"\n    - src: \"glance-swift-store.conf.j2\"\n      dest: \"{{ glance_etc_dir }}/glance-swift-store.conf\"\n      config_overrides: \"{{ glance_glance_swift_store_conf_overrides }}\"\n      config_type: \"ini\"\n    - src: \"schema-image.json.j2\"\n      dest: \"{{ glance_etc_dir }}/schema-image.json\"\n      config_overrides: \"{{ glance_glance_scheme_json_overrides }}\"\n      config_type: \"json\"\n  notify:\n    - Restart glance services\n    - Restart uwsgi services\n\n- name: Place policy.yaml file\n  openstack.config_template.config_template:\n    dest: \"{{ glance_etc_dir }}/{{ glance_policy_file }}\"\n    config_overrides: \"{{ glance_policy_overrides }}\"\n    config_type: \"yaml\"\n    owner: \"root\"\n    group: \"{{ glance_system_group_name }}\"\n    mode: \"0640\"\n    content: \"{{ glance_policy_content }}\"\n  tags:\n    - glance-policy-override\n\n- name: Implement property protection\n  openstack.config_template.config_template:\n    dest: \"{{ glance_etc_dir }}/{{ glance_property_protection_file }}\"\n    config_type: \"ini\"\n    owner: \"root\"\n    group: \"{{ glance_system_group_name }}\"\n    mode: \"0640\"\n    config_overrides: \"{{ glance_property_protection_file_overrides }}\"\n  when: glance_property_protection_file_overrides | length > 0\n  tags:\n    - glance-property-protection\n  notify:\n    - Restart glance services\n    - Restart uwsgi services\n\n- name: Deploy Glance image import configuration file\n  ansible.builtin.template:\n    src: \"{{ glance_glance_image_import_conf_location }}\"\n    dest: \"{{ glance_etc_dir }}/glance-image-import.conf\"\n    mode: \"0640\"\n    owner: root\n    group: \"{{ glance_system_group_name }}\"\n  when: glance_glance_image_import_conf_location is defined\n  notify:\n    - Restart glance services\n    - Restart uwsgi services\n\n# NOTE(cloudnull): This is using \"cp\" instead of copy with a remote_source\n#                  because we only want to copy the original files once. and we\n#                  don't want to need multiple tasks.\n- name: Preserve original configuration file(s)\n  ansible.builtin.command: \"cp {{ item.target_f }} {{ item.target_f }}.original\"\n  args:\n    creates: \"{{ item.target_f }}.original\"\n  with_items: \"{{ glance_core_files }}\"\n\n- name: Fetch override files\n  ansible.builtin.fetch:\n    src: \"{{ item.target_f }}\"\n    dest: \"{{ item.tmp_f }}\"\n    flat: true\n  changed_when: false\n  run_once: true\n  check_mode: false\n  with_items: \"{{ glance_core_files }}\"\n\n- name: Copy common config\n  openstack.config_template.config_template:\n    src: \"{{ item.tmp_f }}\"\n    dest: \"{{ item.target_f_override | default(item.target_f) }}\"\n    owner: \"{{ item.owner | default('root') }}\"\n    group: \"{{ item.group | default(glance_system_group_name) }}\"\n    mode: \"{{ item.mode | default('0640') }}\"\n    config_overrides: \"{{ item.config_overrides }}\"\n    config_type: \"{{ item.config_type }}\"\n  with_items: \"{{ glance_core_files }}\"\n  notify:\n    - Restart glance services\n    - Restart uwsgi services\n\n- name: Cleanup fetched temp files\n  ansible.builtin.file:\n    path: \"{{ item.tmp_f }}\"\n    state: absent\n  changed_when: false\n  delegate_to: localhost\n  run_once: true\n  with_items: \"{{ glance_core_files }}\"\n\n# NOTE(cloudnull): This will ensure strong permissions on all rootwrap files.\n- name: Set rootwrap.d permissions\n  ansible.builtin.file:\n    path: \"{{ glance_etc_dir }}/rootwrap.d\"\n    owner: \"root\"\n    group: \"root\"\n    mode: \"u=rwX,g=rX,o=\"\n    recurse: true\n\n- name: Run the systemd mount role\n  ansible.builtin.include_role:\n    name: systemd_mount\n  vars:\n    systemd_mounts:\n      - config_overrides: \"{{ mount_var.config_overrides | default({}) }}\"\n        what: \"{{ mount_var.what | default(mount_var.server | default('') ~ ':' ~ mount_var.remote_path | default('')) }}\"\n        where: \"{{ mount_var.where | default(mount_var.local_path) }}\"\n        type: \"{{ mount_var.type }}\"\n        options: \"{{ mount_var.options }}\"\n        unit:\n          After:\n            - network.target rpcbind.service rpc-statd.service\n          Conflicts:\n            - umount.target\n          Requires:\n            - rpcbind.service rpc-statd.service\n          Before:\n            - glance-api.service\n        state: \"{{ mount_var.state | default('started') }}\"\n        enabled: \"{{ mount_var.enabled | default(True) }}\"\n  with_items: \"{{ glance_remote_client }}\"\n  loop_control:\n    loop_var: mount_var\n  tags:\n    - glance-config\n\n- name: Create glance cache management cron jobs\n  ansible.builtin.cron:\n    name: \"{{ item.name }}\"\n    minute: \"{{ 59 | random(seed=inventory_hostname, start=1) }}\"\n    day: \"*\"\n    hour: \"{{ item.hour }}\"\n    month: \"*\"\n    state: present\n    job: \"{{ item.name }}\"\n    user: glance\n  with_items:\n    - name: \"{{ glance_bin }}/glance-cache-pruner\"\n      hour: \"*\"\n    - name: \"{{ glance_bin }}/glance-cache-cleaner\"\n      hour: \"*/5\"\n  when: glance_flavor is search(\"cache\")\n\n- name: Drop sudoers file\n  ansible.builtin.template:\n    src: \"sudoers.j2\"\n    dest: \"/etc/sudoers.d/{{ glance_system_user_name }}_sudoers\"\n    mode: \"0440\"\n    owner: \"root\"\n    group: \"root\"\n    validate: \"/usr/sbin/visudo -cf %s\"\n  tags:\n    - sudoers\n    - glance-sudoers\n","created":"2025-12-14T10:21:44.220080Z","updated":"2025-12-14T10:21:44.220090Z","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible-os_glance/tasks/glance_post_install.yml"}