Execution
Date 08 Dec 2025 13:39:52 +0000
Duration 00:35:02.03
Controller aio1.openstack.local
User root
Versions
Ansible 2.18.6
ara 1.7.4 / 1.7.4
Python 3.12.3
Summary
2 Hosts
1377 Tasks
1365 Results
104 Plays
504 Files
0 Records

File: /home/zuul/src/opendev.org/openstack/openstack-ansible-os_neutron/tasks/neutron_apparmor.yml

---
# Copyright 2018, SUSE LINUX GmbH.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

- name: Install required apparmor packages on the physical host
  ansible.builtin.package:
    name: "{{ neutron_apparmor_distro_packages }}"
    state: present
  register: apparmor_packages
  until: apparmor_packages is success
  retries: 5
  delay: 2

- name: Ensure apparmor service is running
  ansible.builtin.systemd:
    name: "apparmor"
    enabled: true
    state: "started"

- name: "Place required apparmor overrides"
  ansible.builtin.copy:
    content: "{{ item['content'] }}"
    dest: "/etc/apparmor.d/local/{{ item['profile'] }}"
    mode: "0644"
    owner: root
    group: root
  loop: "{{ neutron_apparmor_profile_overrides }}"
  loop_control:
    label: "{{ item['profile'] }}"
  when:
    - item.condition | default(true)
  notify:
    - Reload apparmor

- name: "Disable apparmor profile"
  ansible.builtin.shell: |
    # empty line to workaround bug in EnvVarsInCommandRule.py lint test
    # https://github.com/willthames/ansible-lint/issues/275
    set -o pipefail
    exit_code=0
    if aa-status | grep -q {{ item.process }} ; then
       aa-disable {{ item.profile }}
       exit_code=$?
       if [[ $exit_code == 0 ]]; then
         exit_code=2
       fi
    fi
    exit ${exit_code}
  register: _apparmor_profile_disabled
  changed_when: _apparmor_profile_disabled.rc == 2
  failed_when: _apparmor_profile_disabled.rc not in [0,2]
  args:
    executable: /bin/bash
  with_items:
    - profile: "usr.sbin.haproxy"
      process: "haproxy"
    - profile: "bin.ping"
      process: "ping"