solution
This commit is contained in:
BIN
25_vaults.odt
BIN
25_vaults.odt
Binary file not shown.
11
Readme.md
11
Readme.md
@@ -1,6 +1,4 @@
|
|||||||
|
## Vault
|
||||||
# Vault
|
|
||||||
----------
|
|
||||||
|
|
||||||
*Tâche*: Sécuriser des données sensibles
|
*Tâche*: Sécuriser des données sensibles
|
||||||
|
|
||||||
@@ -8,7 +6,7 @@
|
|||||||
|
|
||||||
*Norme*: en utilisant les vaults
|
*Norme*: en utilisant les vaults
|
||||||
|
|
||||||
## Pratique:*
|
## Pratique:
|
||||||
|
|
||||||
Le mot de passe protégeant l'accès au répertoire /Private est en clair dans le playbook.
|
Le mot de passe protégeant l'accès au répertoire /Private est en clair dans le playbook.
|
||||||
|
|
||||||
@@ -16,8 +14,7 @@ Utiliser un vault pour que ce ne soit plus le cas.
|
|||||||
|
|
||||||
## Performance
|
## Performance
|
||||||
|
|
||||||
On a un fichier vault supplémentaire dans le sous répertoire variables du rôle.
|
Le mot de passe n'est plus en clair dans le playbook
|
||||||
|
|
||||||
Celui-ci n'est pas lisible directement, il faut passer par la commande ansible-vault pour l'éditer ou le consulter.
|
Proposition de solution: voir branche "solution"
|
||||||
|
|
||||||
Notre playbook doit inclure ce fichier et être appelé avec l'option --vault-id afin de disposer de la clé permettant de déchiffrer le vault.
|
|
||||||
|
|||||||
38
ansible_apache_formation/README.md
Normal file
38
ansible_apache_formation/README.md
Normal file
@@ -0,0 +1,38 @@
|
|||||||
|
Role Name
|
||||||
|
=========
|
||||||
|
apache_formation
|
||||||
|
|
||||||
|
NOT FOR PRODUCTION USE
|
||||||
|
|
||||||
|
This role has been designed for training purpose
|
||||||
|
|
||||||
|
Requirements
|
||||||
|
------------
|
||||||
|
|
||||||
|
None
|
||||||
|
|
||||||
|
Role Variables
|
||||||
|
--------------
|
||||||
|
|
||||||
|
Dependencies
|
||||||
|
------------
|
||||||
|
|
||||||
|
None
|
||||||
|
|
||||||
|
Example Playbook
|
||||||
|
----------------
|
||||||
|
|
||||||
|
---
|
||||||
|
- hosts: test
|
||||||
|
roles:
|
||||||
|
- apache_formation
|
||||||
|
|
||||||
|
License
|
||||||
|
-------
|
||||||
|
|
||||||
|
BSD
|
||||||
|
|
||||||
|
Author Information
|
||||||
|
------------------
|
||||||
|
|
||||||
|
Thomas Constans <thomas@opendoor.fr>
|
||||||
1
ansible_apache_formation/defaults/main.yml
Normal file
1
ansible_apache_formation/defaults/main.yml
Normal file
@@ -0,0 +1 @@
|
|||||||
|
---
|
||||||
4
ansible_apache_formation/handlers/main.yml
Normal file
4
ansible_apache_formation/handlers/main.yml
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
- name: reload httpd
|
||||||
|
service:
|
||||||
|
name: "{{ apache_service_name }}"
|
||||||
|
state: reloaded
|
||||||
@@ -1,7 +1,8 @@
|
|||||||
galaxy_info:
|
galaxy_info:
|
||||||
author: your name
|
role_name: apache_formation
|
||||||
description: your description
|
author: Thomas Constans <thomas@opendoor.fr>
|
||||||
company: your company (optional)
|
description: Simple apache role set up for training purpose
|
||||||
|
company: www.opendoor.fr
|
||||||
|
|
||||||
# If the issue tracker for your role is not on github, uncomment the
|
# If the issue tracker for your role is not on github, uncomment the
|
||||||
# next line and provide a value
|
# next line and provide a value
|
||||||
@@ -14,7 +15,7 @@ galaxy_info:
|
|||||||
# - GPLv3
|
# - GPLv3
|
||||||
# - Apache
|
# - Apache
|
||||||
# - CC-BY
|
# - CC-BY
|
||||||
license: license (GPLv2, CC-BY, etc)
|
license: GPLv2
|
||||||
|
|
||||||
min_ansible_version: 1.2
|
min_ansible_version: 1.2
|
||||||
|
|
||||||
@@ -32,19 +33,12 @@ galaxy_info:
|
|||||||
#
|
#
|
||||||
# platforms is a list of platforms, and each platform has a name and a list of versions.
|
# platforms is a list of platforms, and each platform has a name and a list of versions.
|
||||||
#
|
#
|
||||||
# platforms:
|
platforms:
|
||||||
# - name: Fedora
|
- name: EL
|
||||||
# versions:
|
versions:
|
||||||
# - all
|
- 7
|
||||||
# - 25
|
|
||||||
# - name: SomePlatform
|
|
||||||
# versions:
|
|
||||||
# - all
|
|
||||||
# - 1.0
|
|
||||||
# - 7
|
|
||||||
# - 99.99
|
|
||||||
|
|
||||||
galaxy_tags: []
|
galaxy_tags: [apache,training]
|
||||||
# List tags for your role here, one per line. A tag is a keyword that describes
|
# List tags for your role here, one per line. A tag is a keyword that describes
|
||||||
# and categorizes the role. Users find roles by searching for tags. Be sure to
|
# and categorizes the role. Users find roles by searching for tags. Be sure to
|
||||||
# remove the '[]' above, if you add tags to this list.
|
# remove the '[]' above, if you add tags to this list.
|
||||||
@@ -52,6 +46,6 @@ galaxy_info:
|
|||||||
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
|
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
|
||||||
# Maximum 20 tags per role.
|
# Maximum 20 tags per role.
|
||||||
|
|
||||||
dependencies: []
|
dependencies: []
|
||||||
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
|
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
|
||||||
# if you add dependencies to this list.
|
# if you add dependencies to this list.
|
||||||
57
ansible_apache_formation/tasks/apache.yml
Normal file
57
ansible_apache_formation/tasks/apache.yml
Normal file
@@ -0,0 +1,57 @@
|
|||||||
|
---
|
||||||
|
- name: installation
|
||||||
|
package:
|
||||||
|
name: "{{ apache_package_name }}"
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: configuration
|
||||||
|
notify: reload httpd
|
||||||
|
template:
|
||||||
|
src: vhost.conf
|
||||||
|
dest: /etc/httpd/conf.d/vhost.conf
|
||||||
|
mode: 0640
|
||||||
|
owner: root
|
||||||
|
group: apache
|
||||||
|
|
||||||
|
- name: enable service
|
||||||
|
service:
|
||||||
|
name: "{{ apache_service_name }}"
|
||||||
|
enabled: yes
|
||||||
|
|
||||||
|
- name: open firewall port
|
||||||
|
firewalld:
|
||||||
|
service: http
|
||||||
|
permanent: yes
|
||||||
|
immediate: yes
|
||||||
|
state: enabled
|
||||||
|
ignore_errors: yes
|
||||||
|
|
||||||
|
- name: create documentroot
|
||||||
|
file:
|
||||||
|
name: "{{ apache_documentroot }}"
|
||||||
|
state: directory
|
||||||
|
|
||||||
|
- name: create index file
|
||||||
|
template:
|
||||||
|
src: index.html
|
||||||
|
dest: "{{ apache_documentroot }}/index.html"
|
||||||
|
mode: 0644
|
||||||
|
|
||||||
|
- name: install python passlib package
|
||||||
|
package:
|
||||||
|
name: python-passlib
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: passwd file
|
||||||
|
htpasswd:
|
||||||
|
path: "/etc/httpd/passwd"
|
||||||
|
name: tom
|
||||||
|
password: "123Soleil"
|
||||||
|
mode: 0640
|
||||||
|
owner: root
|
||||||
|
group: "apache"
|
||||||
|
|
||||||
|
- name: start service
|
||||||
|
service:
|
||||||
|
name: "{{ apache_service_name }}"
|
||||||
|
state: restarted
|
||||||
3
ansible_apache_formation/tasks/main.yml
Normal file
3
ansible_apache_formation/tasks/main.yml
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
---
|
||||||
|
- import_tasks: apache.yml
|
||||||
|
tags: httpd
|
||||||
1
ansible_apache_formation/templates/index.html
Normal file
1
ansible_apache_formation/templates/index.html
Normal file
@@ -0,0 +1 @@
|
|||||||
|
<h1>Welcome aboard {{ ansible_hostname }}</h1>
|
||||||
24
ansible_apache_formation/templates/vhost.conf
Normal file
24
ansible_apache_formation/templates/vhost.conf
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
<VirtualHost *:80>
|
||||||
|
ServerName {{ apache_server_name }}
|
||||||
|
ServerAlias www.{{ apache_server_name }}
|
||||||
|
ServerAlias {{ inventory_hostname }}
|
||||||
|
DocumentRoot /var/www/html/{{ apache_server_name }}
|
||||||
|
CustomLog /var/log/httpd/{{ apache_server_name }}_access.log combined
|
||||||
|
ErrorLog /var/log/httpd/{{ apache_server_name }}_error.log
|
||||||
|
<Directory />
|
||||||
|
Options none
|
||||||
|
Allowoverride none
|
||||||
|
Require all denied
|
||||||
|
</Directory>
|
||||||
|
|
||||||
|
<Directory {{ apache_documentroot }}>
|
||||||
|
Require all granted
|
||||||
|
</Directory>
|
||||||
|
<Directory {{ apache_documentroot }}/Private>
|
||||||
|
Options indexes
|
||||||
|
AuthName "stop"
|
||||||
|
AuthType Basic
|
||||||
|
AuthUserFile /etc/httpd/passwd
|
||||||
|
require valid-user
|
||||||
|
</Directory>
|
||||||
|
</VirtualHost>
|
||||||
4
ansible_apache_formation/tests/test.yml
Normal file
4
ansible_apache_formation/tests/test.yml
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
- hosts: centos
|
||||||
|
roles:
|
||||||
|
- tconstans.ansible_apache_formation
|
||||||
1
ansible_apache_formation/vars/main.yml
Normal file
1
ansible_apache_formation/vars/main.yml
Normal file
@@ -0,0 +1 @@
|
|||||||
|
---
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
---
|
|
||||||
- name: install apache via ansible playbook
|
|
||||||
hosts: test
|
|
||||||
user: ansible
|
|
||||||
become: true
|
|
||||||
roles:
|
|
||||||
- myapache
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
Role Name
|
|
||||||
=========
|
|
||||||
|
|
||||||
Rôle de deploiement apache sur une centos.
|
|
||||||
|
|
||||||
1 seul vhost
|
|
||||||
|
|
||||||
Requirements
|
|
||||||
------------
|
|
||||||
|
|
||||||
None
|
|
||||||
|
|
||||||
Role Variables
|
|
||||||
--------------
|
|
||||||
|
|
||||||
http_port: 80
|
|
||||||
servername: orsys.fr
|
|
||||||
serveralias: "www.{{ servername }}"
|
|
||||||
documentroot: /var/www/html/orsys.fr
|
|
||||||
accesslog: /var/log/httpd/access_orsys.fr_log
|
|
||||||
errorlog: /var/log/httpd/error_orsys.fr_log
|
|
||||||
|
|
||||||
Dependencies
|
|
||||||
------------
|
|
||||||
|
|
||||||
None
|
|
||||||
|
|
||||||
Example Playbook
|
|
||||||
----------------
|
|
||||||
|
|
||||||
Including an example of how to use your role (for instance, with variables passed in as parameters) is always nice for users too:
|
|
||||||
|
|
||||||
- hosts: servers
|
|
||||||
roles:
|
|
||||||
- { myapache }
|
|
||||||
|
|
||||||
License
|
|
||||||
-------
|
|
||||||
|
|
||||||
BSD
|
|
||||||
|
|
||||||
Author Information
|
|
||||||
------------------
|
|
||||||
|
|
||||||
Thomas Constans <thomas@opendoor.fr>
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
---
|
|
||||||
# defaults file for myapache
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
<h1>hello World</h1>
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
---
|
|
||||||
# handlers file for myapache
|
|
||||||
- name: reload httpd
|
|
||||||
service:
|
|
||||||
name: "{{ service_name }}"
|
|
||||||
state: reloaded
|
|
||||||
|
|
||||||
- name: reload firewalld
|
|
||||||
service:
|
|
||||||
name: firewalld
|
|
||||||
state: reloaded
|
|
||||||
@@ -1,74 +0,0 @@
|
|||||||
---
|
|
||||||
# tasks file for myapache
|
|
||||||
- name: import distribution specific variables
|
|
||||||
tags: http
|
|
||||||
include_vars: "{{ ansible_distribution|lower }}.yml"
|
|
||||||
|
|
||||||
- name: include sensitive information
|
|
||||||
tags: http
|
|
||||||
include_vars: apache_sensitive_data.yml
|
|
||||||
|
|
||||||
- name: install apache
|
|
||||||
tags: httpd
|
|
||||||
package:
|
|
||||||
name: "{{ package_name }}"
|
|
||||||
state: latest
|
|
||||||
|
|
||||||
- name: conf httpd
|
|
||||||
tags: httpd
|
|
||||||
notify: reload httpd
|
|
||||||
template:
|
|
||||||
src: vhost.conf.jj
|
|
||||||
dest: "{{ apache_conf_dir }}/vhost.conf"
|
|
||||||
mode: 0640
|
|
||||||
owner: root
|
|
||||||
group: "{{ apache_group }}"
|
|
||||||
|
|
||||||
- name: activate apache
|
|
||||||
tags: httpd
|
|
||||||
service:
|
|
||||||
name: "{{ service_name }}"
|
|
||||||
enabled: yes
|
|
||||||
|
|
||||||
- name: open firewall port
|
|
||||||
tags: httpd
|
|
||||||
firewalld:
|
|
||||||
service: http
|
|
||||||
permanent: yes
|
|
||||||
immediate: yes
|
|
||||||
state: enabled
|
|
||||||
ignore_errors: yes
|
|
||||||
notify: reload firewalld
|
|
||||||
when: ansible_distribution|lower != "debian"
|
|
||||||
|
|
||||||
- name: create documentroot
|
|
||||||
tags: httpd
|
|
||||||
file:
|
|
||||||
name: "{{ item.documentroot }}"
|
|
||||||
state: directory
|
|
||||||
with_items:
|
|
||||||
- "{{ apache_vhosts }}"
|
|
||||||
|
|
||||||
- name: install python passlib package
|
|
||||||
tags: req,httpd
|
|
||||||
package:
|
|
||||||
name: python-passlib
|
|
||||||
state: latest
|
|
||||||
|
|
||||||
- name: create index file
|
|
||||||
tags: httpd
|
|
||||||
copy:
|
|
||||||
src: index.html
|
|
||||||
dest: "{{ item.documentroot }}/index.html"
|
|
||||||
mode: 0644
|
|
||||||
with_items:
|
|
||||||
- "{{ apache_vhosts }}"
|
|
||||||
|
|
||||||
- name: passwd file
|
|
||||||
htpasswd:
|
|
||||||
path: "{{ apache_conf_dir }}/passwd"
|
|
||||||
name: tom
|
|
||||||
password: "{{ httpasswd }}"
|
|
||||||
mode: 0640
|
|
||||||
owner: root
|
|
||||||
group: "{{ apache_group }}"
|
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
{% for vhost in apache_vhosts %}
|
|
||||||
<VirtualHost *:{{ http_port }}>
|
|
||||||
ServerName {{ vhost.servername|lower }}
|
|
||||||
ServerAlias {{ vhost.serveralias }}
|
|
||||||
DocumentRoot {{ vhost.documentroot }}
|
|
||||||
CustomLog {{ vhost.accesslog }} combined
|
|
||||||
ErrorLog {{ vhost.errorlog }}
|
|
||||||
<Directory />
|
|
||||||
Options none
|
|
||||||
Allowoverride none
|
|
||||||
Require all denied
|
|
||||||
</Directory>
|
|
||||||
|
|
||||||
<Directory {{ vhost.documentroot }}>
|
|
||||||
Options {{ vhost.documentrootoptions|default( "none" ) }}
|
|
||||||
Require all granted
|
|
||||||
</Directory>
|
|
||||||
|
|
||||||
Alias /private /usr/share/doc
|
|
||||||
<Directory /usr/share/doc>
|
|
||||||
Options indexes
|
|
||||||
AuthName "stop"
|
|
||||||
AuthType Basic
|
|
||||||
AuthUserFile {{ apache_conf_dir }}/passwd
|
|
||||||
require valid-user
|
|
||||||
</Directory>
|
|
||||||
</VirtualHost>
|
|
||||||
{% endfor %}
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
---
|
|
||||||
- hosts: localhost
|
|
||||||
remote_user: root
|
|
||||||
roles:
|
|
||||||
- myapache
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
|
||||||
31653731393732623239623030633932666534613931666630313335346338306362356263366261
|
|
||||||
6465393132643537613161343263613530656263623236390a633835613663643464313930613562
|
|
||||||
31306535323538633664393032386665396239626563343736636266333436336265386639323035
|
|
||||||
6530326539336236320a613631653861303464353066353961383738396639313831323065623639
|
|
||||||
32663763333138613435653438363734343739303838303232313337313230646364
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
redhat.yml
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
---
|
|
||||||
apache_conf_dir: /etc/apache2/sites-enabled
|
|
||||||
apache_log_dir: /var/log/apache2
|
|
||||||
package_name: apache2
|
|
||||||
service_name: apache2
|
|
||||||
apache_user: www-data
|
|
||||||
apache_group: www-data
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
# vars file for myapache
|
|
||||||
http_port: 80
|
|
||||||
apache_vhosts:
|
|
||||||
- servername: ORSYS.Fr
|
|
||||||
serveralias: www.orsys.fr
|
|
||||||
documentroot: /var/www/html/orsys.fr
|
|
||||||
accesslog: "{{ apache_log_dir }}/access_orsys.fr_log"
|
|
||||||
errorlog: "{{ apache_log_dir }}/error_orsys.fr_log"
|
|
||||||
- servername: thomas.fr
|
|
||||||
serveralias: www.thomas.fr
|
|
||||||
documentroot: /var/www/html/thomas.fr
|
|
||||||
accesslog: "{{ apache_log_dir }}/access_thomas.fr_log"
|
|
||||||
errorlog: "{{ apache_log_dir }}/error_thomas.fr_log"
|
|
||||||
documentrootoptions: indexes
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
---
|
|
||||||
apache_conf_dir: /etc/httpd/conf.d/
|
|
||||||
apache_log_dir: /var/log/httpd
|
|
||||||
package_name: httpd
|
|
||||||
service_name: httpd
|
|
||||||
apache_user: apache
|
|
||||||
apache_group: apache
|
|
||||||
Reference in New Issue
Block a user