-
Notifications
You must be signed in to change notification settings - Fork 8
/
clusterMigrateToSasLAuth.yml
103 lines (91 loc) · 2.88 KB
/
clusterMigrateToSasLAuth.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
---
# Note:
# this is one-time playbook to migrate non-sasl cluster to sasl cluster config
# Ref: https://cwiki.apache.org/confluence/display/ZOOKEEPER/Server-Server+mutual+authentication
- hosts: clusterNodes
gather_facts: true
become: true
serial: 1
tasks:
- name: MigrateToSasL | regenerate jaas.conf
ansible.builtin.include_role:
name: configure
tasks_from: dynamicConfigs
vars:
zookeeperConfigFile: jaas.conf
- name: MigrateToSasL | regenerate java.env to enable jaas.conf
ansible.builtin.include_role:
name: configure
tasks_from: dynamicConfigs
vars:
zookeeperConfigFile: java.env
zookeeperQuorumAuthEnableSasl: true
- name: MigrateToSasL | enableSasl in zoo.cfg
ansible.builtin.lineinfile:
path: "{{ zookeeperInstallDir }}/zookeeper-{{ zookeeperVersion }}/conf/zoo.cfg"
regexp: "^quorum.auth.enableSasl="
line: "quorum.auth.enableSasl=true"
- name: MigrateToSasL | restarting zookeeper
ansible.builtin.import_role:
name: serviceState
vars:
serviceName: zookeeper
serviceState: restarted
- name: MigrateToSasL | zookeeper Port Status
ansible.builtin.include_role:
name: portCheck
vars:
PortNumber: "{{ item }}"
PortStatus: started
loop:
- "{{ zookeeperClientPort }}"
- hosts: clusterNodes
gather_facts: true
become: true
serial: 1
tasks:
- name: MigrateToSasL | learnerRequireSasl in zoo.cfg
ansible.builtin.lineinfile:
path: "{{ zookeeperInstallDir }}/zookeeper-{{ zookeeperVersion }}/conf/zoo.cfg"
regexp: "^quorum.auth.learnerRequireSasl="
line: "quorum.auth.learnerRequireSasl=true"
- name: MigrateToSasL | restarting zookeeper
ansible.builtin.import_role:
name: serviceState
vars:
serviceName: zookeeper
serviceState: restarted
- name: MigrateToSasL | zookeeper Port Status
ansible.builtin.include_role:
name: portCheck
vars:
PortNumber: "{{ item }}"
PortStatus: started
loop:
- "{{ zookeeperClientPort }}"
- hosts: clusterNodes
gather_facts: true
become: true
serial: 1
tasks:
- name: MigrateToSasL | regenerate zoo.cfg with all parameters
ansible.builtin.include_role:
name: configure
tasks_from: dynamicConfigs
vars:
zookeeperConfigFile: zoo.cfg
zookeeperQuorumAuthEnableSasl: true
- name: MigrateToSasL | restarting zookeeper
ansible.builtin.import_role:
name: serviceState
vars:
serviceName: zookeeper
serviceState: restarted
- name: MigrateToSasL | zookeeper Port Status
ansible.builtin.include_role:
name: portCheck
vars:
PortNumber: "{{ item }}"
PortStatus: started
loop:
- "{{ zookeeperClientPort }}"