diff --git a/defaults/main.yml b/defaults/main.yml index 472c683b..dc85eae3 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -333,6 +333,7 @@ glance_glance_swift_store_conf_overrides: {} glance_policy_overrides: {} glance_policy_content: {} glance_api_uwsgi_ini_overrides: {} +glance_rootwrap_conf_overrides: {} # Specify path on the local filesystem for glance-image-import.conf # glance_glance_image_import_conf_location: /path/to/local/glance-image-import.conf diff --git a/vars/main.yml b/vars/main.yml index 0f9ee526..f9291eb0 100644 --- a/vars/main.yml +++ b/vars/main.yml @@ -79,8 +79,19 @@ glance_mount_points: |- {% endfor %} {{ mps }} +_glance_rootwrap_conf_overrides: + DEFAULT: + exec_dirs: "{{ _glance_bin }},/sbin,/usr/sbin,/bin,/usr/bin,/usr/local/bin,/usr/local/sbin" + glance_core_files: - tmp_f: "/tmp/glance-api-paste.ini" target_f: "{{ glance_etc_dir }}/glance-api-paste.ini" config_overrides: "{{ glance_glance_api_paste_ini_overrides }}" config_type: "ini" + - tmp_f: "/tmp/rootwrap.conf" + target_f: "{{ glance_etc_dir }}/rootwrap.conf" + config_overrides: "{{ _glance_rootwrap_conf_overrides | combine(glance_rootwrap_conf_overrides, recursive=True) }}" + config_type: "ini" + owner: "root" + group: "{{ glance_system_group_name }}" + mode: "0640"