Execution
Date 15 Dec 2025 10:19:13 +0000
Duration 00:23:12.82
Controller aio1.openstack.local
User root
Versions
Ansible 2.18.6
ara 1.7.4 / 1.7.4
Python 3.12.3
Summary
9 Hosts
618 Tasks
960 Results
108 Plays
456 Files
0 Records

File: /etc/ansible/ansible_collections/openstack/osa/playbooks/keystone.yml

---
# Copyright 2014, Rackspace US, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.


# The openstack_openrc role gets executed on a designated service
# host which will handle all service/user/domain/project/role
# management for the roles. It is executed here as this is the
# first role which will use it and the implementation of the
# clouds.yaml file is useless until keystone is in place.
- name: Implement openrc/clouds.yaml on the designated service host
  hosts: "{{ openstack_service_setup_host | default('localhost') }}"
  gather_facts: "{{ osa_gather_facts | default(true) }}"
  module_defaults:
    ansible.builtin.setup:
      gather_subset: "{{ osa_gather_subset | default(lookup('ansible.builtin.env', 'ANSIBLE_GATHER_SUBSET', default='!all,min')) }}"
  become: true
  tags:
    - openrc
  pre_tasks:
    - name: Setup installation variables
      ansible.builtin.include_role:
        name: openstack.osa.install_defaults
        defaults_from: "{{ install_method }}"
        public: true
        apply:
          tags:
            - always
      tags:
        - always
  roles:
    - role: "openstack_openrc"

- name: Gather keystone facts
  hosts: keystone_all
  gather_facts: "{{ osa_gather_facts | default(true) }}"
  module_defaults:
    ansible.builtin.setup:
      gather_subset: "{{ osa_gather_subset | default(lookup('ansible.builtin.env', 'ANSIBLE_GATHER_SUBSET', default='!all,min')) }}"
  tasks:
    - name: Gather additional facts
      ansible.builtin.include_role:
        name: openstack.osa.gather_extra_facts
      when: osa_gather_facts | default(true)
  tags:
    - always

- name: Pre-service deployment
  hosts: keystone_all
  gather_facts: false
  environment: "{{ deployment_environment_variables | default({}) }}"
  tasks:
    - name: "Pre-service deployment tasks from os_keystone role"
      ansible.builtin.include_role:
        name: os_keystone
        tasks_from: main_pre.yml

- name: Configure haproxy services
  ansible.builtin.import_playbook: openstack.osa.haproxy_service_config
  vars:
    service_group: keystone_all
    service_variable: "keystone_haproxy_services"
  when:
    - groups[service_group] | length > 0
    - groups['haproxy'] | length > 0
  tags:
    - haproxy-service-config

- name: Installation and setup of Keystone
  hosts: keystone_all
  serial: "{{ keystone_serial | default(['1', '100%']) }}"
  gather_facts: false
  user: root
  environment: "{{ deployment_environment_variables | default({}) }}"
  pre_tasks:
    - name: Setup installation variables
      ansible.builtin.include_role:
        name: openstack.osa.install_defaults
        defaults_from: "{{ install_method }}"
        public: true
        apply:
          tags:
            - always
      tags:
        - always

    # In order to ensure that any container, software or
    # config file changes which causes a container/service
    # restart do not cause an unexpected outage, we drain
    # the load balancer back end for this container.
    - name: Disabling haproxy backends
      ansible.builtin.include_role:
        name: openstack.osa.haproxy_endpoint_manage
        apply:
          tags:
            - always
      vars:
        haproxy_backend: "keystone_service-back"
        haproxy_state: disabled
      when:
        - "'keystone_all' in group_names"
        - "groups['keystone_all'] | length > 1"
      tags:
        - always

    - name: Configure container
      ansible.builtin.include_role:
        name: "openstack.osa.{{ container_tech | default('lxc') }}_container_setup"
      vars:
        extra_container_config_no_restart:
          - "lxc.start.order=19"
      when: not is_metal

    - name: Including unbound-clients tasks
      ansible.builtin.include_role:
        name: openstack.osa.unbound_clients
      when:
        - hostvars['localhost']['resolvconf_enabled'] | bool

  roles:
    - role: "os_keystone"
    - role: "openstack.osa.system_crontab_coordination"
      tags:
        - crontab

  post_tasks:
    # Now that container changes are done, we can set
    # the load balancer back end for this container
    # to available again.
    - name: Enabling haproxy backends
      ansible.builtin.include_role:
        name: openstack.osa.haproxy_endpoint_manage
        apply:
          tags:
            - always
      vars:
        haproxy_backend: "keystone_service-back"
        haproxy_state: enabled
      when:
        - "'keystone_all' in group_names"
        - "groups['keystone_all'] | length > 1"
      tags:
        - always

# These facts are set against the deployment host to ensure that
# they are fast to access. This is done in preference to setting
# them against each target as the hostvars extraction will take
# a long time if executed against a large inventory.
- name: Finalise data migrations if required
  hosts: keystone_all
  gather_facts: false
  user: root
  environment: "{{ deployment_environment_variables | default({}) }}"
  tasks:
    - name: Setup installation variables
      ansible.builtin.include_role:
        name: openstack.osa.install_defaults
        defaults_from: "{{ install_method }}"
        public: true
        apply:
          tags:
            - always
      tags:
        - always

    - name: Refresh local facts
      ansible.builtin.setup:
        filter: ansible_local
        gather_subset: "!all"

    # This variable contains the values of the local fact set for the keystone
    # venv tag for all hosts in the 'keystone_all' host group.
    - name: Gather software version list
      ansible.builtin.set_fact:
        keystone_all_software_versions: "{{ (groups['keystone_all'] |
                                             map('extract', hostvars, ['ansible_local', 'openstack_ansible', 'keystone', 'venv_tag'])) |
                                             list }}"
      delegate_to: localhost
      run_once: true

    # This variable outputs a boolean value which is True when
    # keystone_all_software_versions contains a list of defined
    # values. If they are not defined, it means that not all
    # hosts have their software deployed yet.
    - name: Set software deployed fact
      ansible.builtin.set_fact:
        keystone_all_software_deployed: "{{ (keystone_all_software_versions | select('defined')) | list == keystone_all_software_versions }}"
      delegate_to: localhost
      run_once: true

    # This variable outputs a boolean when all the values in
    # keystone_all_software_versions are the same and the software
    # has been deployed to all hosts in the group.
    - name: Set software updated fact
      ansible.builtin.set_fact:
        keystone_all_software_updated: "{{ ((keystone_all_software_versions | unique) | length == 1) and (keystone_all_software_deployed | bool) }}"
      delegate_to: localhost
      run_once: true

    - name: Perform a Keystone DB sync contract
      ansible.builtin.command: "{{ keystone_bin }}/keystone-manage db_sync --contract" # noqa: no-changed-when
      become: true
      become_user: "{{ keystone_system_user_name | default('keystone') }}"
      when:
        - "keystone_all_software_updated | bool"
        - "ansible_local['openstack_ansible']['keystone']['need_db_contract'] | bool"
      register: dbsync_contract
      run_once: true

    - name: Disable the need for any further db sync
      community.general.ini_file:
        dest: "/etc/ansible/facts.d/openstack_ansible.fact"
        section: keystone
        option: "need_db_contract"
        value: "False"
        mode: "0644"
      when:
        - "dbsync_contract is succeeded"

# note(jrosser) this can only be done once the DB contract has completed so we must put it as
# the last part of the keystone setup
- name: SP/IDP setup
  hosts: keystone_all
  gather_facts: false
  user: root
  environment: "{{ deployment_environment_variables | default({}) }}"
  tasks:
    - name: Setup installation variables
      include_role:
        name: openstack.osa.install_defaults
        defaults_from: "{{ install_method }}"
        public: true

    - name: "Post configure SP/IDP"
      include_role:
        name: os_keystone
        tasks_from: main_keystone_federation_sp_idp_setup.yml