12 Commits

Author SHA1 Message Date
bee4b6a526 correctly delete local ressources 2023-06-07 10:57:09 +02:00
e465a877cf switch to fqmn 2023-01-20 12:36:33 +01:00
895f1f15fd solution abr 2022-11-16 15:11:35 +01:00
4bd6eebafd wip 2022-11-16 14:41:55 +01:00
3cdcabd1ac wrong indent 2022-09-22 16:24:28 +02:00
071637a3f8 ajout https 2022-09-22 16:21:42 +02:00
37a75cef65 correct useless indent 2022-04-25 15:05:46 +02:00
b7a25b85b0 cleanup 2021-09-14 09:25:41 +02:00
c3e30f8e9f ok for centos8 2021-05-10 16:43:49 +02:00
e3e35d6dcd rajout install firewalld et dep 2021-04-19 17:10:04 +02:00
00a50bf543 add firewalld dep + block 2021-04-19 16:46:51 +02:00
20fc81cf83 branch solution 2021-03-16 21:07:11 +01:00
4 changed files with 77 additions and 49 deletions

View File

@@ -1,27 +1,6 @@
## Installer apache
# Playbook d'installation apache
**Tâche**: déployer un serveur apache à l'aide d'ansible
LEs fichiers vhost.conf et index.html sont récupérés par le pilote
**Condition**: déploiement d'un serveur apache
**Norme**: playbook et ansible-playbook
**Préparation:**
- Faites un git clone de l'atelier afin de disposer des fichiers index.txt et vhost.conf
**Pratique**: Écrire le playbook permettant sur la machine **centos** uniquement:
1. d'installer le serveur apache
4. d'ouvrir le parefeu
4. de créer le répertoire correspondant au documentRoot: /var/www/html/example.org
5. de déployer le fichier vhost.conf dans /etc/httpd/conf.d/
6. de déployer le fichier index.html dans le répertoire correspondant au documentRoot
7. d'activer le service
8. de lancer le service
**Validation**: on doit pouvoir se connecter en http sur la machine cible
Proposition de solution: voir la branche "solution"
directement depuis le dépôt git

74
apache.yml Normal file
View File

@@ -0,0 +1,74 @@
---
- name: install apache via ansible playbook
hosts: centos
tasks:
- name: retrieve ansible.builtin.files
ansible.builtin.git:
repo: https://infra.opendoor.fr/git/tom/sib_10_premier_playbook
dest: /tmp/sib_10
delegate_to: localhost
become: false
- name: install apache
ansible.builtin.package:
name: httpd
state: present
- name: conf httpd
ansible.builtin.template:
src: /tmp/sib_10/vhost.conf
dest: /etc/httpd/conf.d/vhost.conf
mode: 0640
owner: root
group: apache
- name: activate apache
ansible.builtin.service:
name: httpd
enabled: yes
state: started
- name: setup firewall
block:
- name: install firewalld packages
ansible.builtin.package:
name:
- python3-firewall
- firewalld
state: present
- name: enable firewalld service
ansible.builtin.service:
name: firewalld
enabled: true
state: started
- name: open firewall port
ansible.posix.firewalld:
service: "{{ item }}"
permanent: yes
immediate: yes
state: enabled
loop:
- http
- https
ignore_errors: true
- name: create documentroot
ansible.builtin.file:
name: /var/www/html/example.org/
state: directory
- name: copy index ansible.builtin.file
ansible.builtin.template:
src: /tmp/sib_10/index.txt
dest: /var/www/html/example.org/index.html
mode: 0644
- name: delete temp ansible.builtin.files
ansible.builtin.file:
path: /tmp/sib_10
state: absent
delegate_to: localhost
become: false

View File

@@ -1 +0,0 @@
<h1>hello World</h1>

View File

@@ -1,24 +0,0 @@
<VirtualHost *:80>
ServerName example.org
ServerAlias www.example.org
ServerAlias {{ inventory_hostname }}
DocumentRoot /var/www/html/example.org
CustomLog /var/log/httpd/example.org_access.log combined
ErrorLog /var/log/httpd/example.org_error.log
<Directory />
Options none
Allowoverride none
Require all denied
</Directory>
<Directory /var/www/html/example.org>
Require all granted
</Directory>
<Directory /var/www/html/example.org/Private>
Options indexes
AuthName "stop"
AuthType Basic
AuthUserFile /etc/httpd/passwd
require valid-user
</Directory>
</VirtualHost>