--- # Copyright 2015, Rackspace US, Inc. # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. - name: Playbook for configuring the LXC host hosts: localhost pre_tasks: - name: Clear iptables rules shell: ./iptables-clear.sh # Make sure OS does not have a stale package cache. - name: Update apt cache apt: update_cache: yes when: ansible_os_family == 'Debian' - name: Ensure root's new public ssh key is in authorized_keys authorized_key: user: root key: "{{ hostvars['localhost']['lxc_container_ssh_key'] }}" manage_dir: no - set_fact: lxc_container_ssh_key: "{{ hostvars['localhost']['lxc_container_ssh_key'] }}" - name: Check if this is an OpenStack-CI nodepool instance stat: path: /etc/nodepool/provider register: nodepool - name: Set the files to copy into the container cache for OpenStack-CI instances set_fact: lxc_container_cache_files: - { src: '/etc/pip.conf', dest: '/etc/pip.conf' } when: nodepool.stat.exists | bool post_tasks: - name: Ensure that /etc/network/interfaces.d/ exists file: path: /etc/network/interfaces.d/ state: directory tags: - networking-dir-create - name: Copy network configuration template: src: test-tempest-interfaces.cfg.j2 dest: /etc/network/interfaces.d/tempest_interfaces.cfg register: tempest_interfaces tags: - networking-interfaces-file - name: Ensure our interfaces.d configuration files are loaded automatically lineinfile: dest: /etc/network/interfaces line: "source /etc/network/interfaces.d/*.cfg" tags: - networking-interfaces-load - name: Shut down the network interfaces command: "ifdown {{ item }}" when: tempest_interfaces | changed with_items: - br-mgmt - br-vlan - br-vxlan tags: - networking-interfaces-stop - name: Start the network interfaces command: "ifup {{ item }}" when: tempest_interfaces | changed with_items: - br-mgmt - br-vlan - br-vxlan tags: - networking-interfaces-start - name: Add iptables rules for lxc natting command: /usr/local/bin/lxc-system-manage iptables-create roles: - role: "lxc_hosts" lxc_net_address: 10.100.100.1 lxc_net_netmask: 255.255.255.0 lxc_net_dhcp_range: 10.100.100.2,10.100.100.99 lxc_net_bridge: lxcbr0 lxc_kernel_options: - { key: 'fs.inotify.max_user_instances', value: 1024 }