--- # Copyright 2018, Rackspace US, Inc. # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. - name: Install Kolide Fleet hosts: "fleet" become: true vars_files: - vars/variables.yml environment: "{{ deployment_environment_variables | default({}) }}" gather_facts: "{{ osa_gather_facts | default(True) }}" pre_tasks: - name: Store ssl cert slurp: src: "{{ kolide_fleet_ssl_cert }}" register: _kolide_fleet_ssl_cert - name: Store ssl ca cert slurp: src: "{{ kolide_fleet_ssl_ca_cert }}" register: _kolide_fleet_ssl_ca_cert when: kolide_fleet_user_ssl_ca_cert is defined - name: Register a fact for the cert and key set_fact: kolide_fleet_ssl_cert_fact: "{{ _kolide_fleet_ssl_cert.content }}" - name: Register a fact for the cert and key set_fact: kolide_fleet_ssl_ca_cert_fact: "{{ _kolide_fleet_ssl_ca_cert.content }}" when: kolide_fleet_user_ssl_ca_cert is defined - name: Distribute self signed ssl cert copy: dest: "{{ kolide_fleet_ssl_cert }}" content: "{{ hostvars[groups['fleet'][0]]['kolide_fleet_ssl_cert_fact'] | b64decode }}" mode: "0640" - name: Distribute self signed CA ssl cert copy: dest: "{{ kolide_fleet_ca_ssl_cert }}" content: "{{ hostvars[groups['fleet'][0]]['kolide_fleet_ssl_ca_cert_fact'] | b64decode }}" mode: "0640" when: kolide_fleet_user_ssl_ca_cert is defined - name: retrieve Enrollment Token command: /usr/local/bin/fleetctl get enroll-secret register: _enrollment_token - name: Set kolide fleet enrollment token fact set_fact: kolide_fleet_enroll_secret: "{{ _enrollment_token.stdout }}" - name: write enroll secret copy: dest: "{{ osquery_enroll_secret_dir }}" content: "{{ hostvars[groups['fleet'][0]]['kolide_fleet_enroll_secret'] }}" mode: "0640"