fetch_base_inputs.yml 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489
  1. # Copyright 2022 Dell Inc. or its subsidiaries. All Rights Reserved.
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. ---
  15. - name: Include base variable file base_vars.yml
  16. include_vars: "{{ base_vars_filename }}"
  17. no_log: true
  18. - name: Validate input parameters of base_vars are not empty
  19. fail:
  20. msg: "{{ input_base_failure_msg }}"
  21. register: input_base_check
  22. when:
  23. - ansible_conf_file_path | length < 1 or
  24. public_nic | length < 1 or
  25. appliance_k8s_pod_net_cidr | length < 1 or
  26. awx_organization | length < 1 or
  27. timezone | length < 1 or
  28. language | length < 1 or
  29. iso_file_path | length < 1 or
  30. mngmnt_network_nic | length < 1 or
  31. mngmnt_network_dhcp_start_range | length < 1 or
  32. mngmnt_network_dhcp_end_range | length < 1 or
  33. host_network_nic | length < 1 or
  34. host_network_dhcp_start_range | length < 1 or
  35. host_network_dhcp_end_range | length < 1 or
  36. provision_method | length < 1 or
  37. default_lease_time | length < 1 or
  38. provision_os | length < 1 or
  39. provision_state | length < 1 or
  40. mount_location | length < 1
  41. - name: Validate default lease time
  42. assert:
  43. that:
  44. - default_lease_time|int
  45. - default_lease_time|int <= 31536000
  46. - default_lease_time|int >= 21600
  47. success_msg: "{{ success_msg_lease_time }}"
  48. fail_msg: "{{ fail_msg_lease_time }}"
  49. - name: Calculate max lease time
  50. set_fact:
  51. max_lease_time: "{{ default_lease_time|int + 10000 }}"
  52. - name: Validate infiniband base_vars are not empty
  53. assert:
  54. that:
  55. - ib_network_nic | length > 2
  56. - ib_network_dhcp_start_range | length > 6
  57. - ib_network_dhcp_end_range | length > 6
  58. success_msg: "{{ success_msg_ib }}"
  59. fail_msg: "{{ fail_msg_ib }}"
  60. register: ib_check
  61. when: ib_switch_support
  62. - name: Set facts to validate snmp support
  63. set_fact:
  64. snmp_enabled: false
  65. mngmnt_mapping_file: false
  66. host_mapping_file: false
  67. - name: Verify snmp_trap_destination IP address
  68. set_fact:
  69. snmp_enabled: true
  70. when: snmp_trap_destination | length > 1
  71. - name: Assert snmp trap destination address
  72. assert:
  73. that:
  74. - snmp_enabled
  75. - snmp_trap_destination | length > 7
  76. - snmp_trap_destination | ipv4
  77. success_msg: "{{ success_snmp_trap_dest }}"
  78. fail_msg: "{{ fail_snmp_trap_dest }}"
  79. when: snmp_enabled
  80. - name: Assert snmp community string
  81. assert:
  82. that:
  83. - snmp_enabled
  84. - snmp_community_name
  85. success_msg: "{{ success_snmp_comm_msg }}"
  86. fail_msg: "{{ fail_snmp_comm_msg }}"
  87. when: snmp_enabled
  88. - name: Check whether ansible config file exists
  89. stat:
  90. path: "{{ ansible_conf_file_path }}/ansible.cfg"
  91. register: ansible_conf_exists
  92. - name: Create the directory if it does not exist
  93. file:
  94. path: "{{ ansible_conf_file_path }}"
  95. state: directory
  96. mode: "{{ file_perm }}"
  97. when: not ansible_conf_exists.stat.exists
  98. changed_when: false
  99. - name: Create ansible config file if it does not exist
  100. copy:
  101. dest: '{{ ansible_conf_file_path }}/ansible.cfg'
  102. mode: "{{ file_perm }}"
  103. content: |
  104. [defaults]
  105. log_path = /var/log/omnia.log
  106. when: not ansible_conf_exists.stat.exists
  107. - name: Assert ethernet_switch_support
  108. assert:
  109. that:
  110. - ethernet_switch_support == true or ethernet_switch_support == false
  111. success_msg: "{{ ethernet_switch_support_success_msg }}"
  112. fail_msg: "{{ ethernet_switch_support_fail_msg }}"
  113. - name: Assert ib_switch_support
  114. assert:
  115. that:
  116. - ib_switch_support == true or ib_switch_support == false
  117. success_msg: "{{ ib_switch_support_success_msg }}"
  118. fail_msg: "{{ ib_switch_support_fail_msg }}"
  119. - name: Assert powervault_support
  120. assert:
  121. that:
  122. - powervault_support == true or powervault_support == false
  123. success_msg: "{{ powervault_support_success_msg }}"
  124. fail_msg: "{{ powervault_support_fail_msg }}"
  125. - name: Assert enable_security_support
  126. assert:
  127. that:
  128. - enable_security_support == true or enable_security_support == false
  129. success_msg: "{{ enable_security_support_success_msg }}"
  130. fail_msg: "{{ enable_security_support_fail_msg }}"
  131. - name: Fetch the network interfaces in UP state in the system
  132. shell: set -o pipefail && ip a | awk '/state UP/{print $2}'
  133. register: nic_addr_up
  134. changed_when: false
  135. - name: Assert public nic
  136. assert:
  137. that:
  138. - public_nic in nic_addr_up.stdout
  139. success_msg: "{{ success_msg_public_nic }}"
  140. fail_msg: "{{ fail_msg_public_nic }}"
  141. - name: Fetch the system public IP
  142. set_fact:
  143. public_ip: "{{ lookup('vars','ansible_'+public_nic).ipv4.address }}"
  144. - name: Assert kubernetes pod network CIDR
  145. assert:
  146. that:
  147. - appliance_k8s_pod_net_cidr | ipv4
  148. - appliance_k8s_pod_net_cidr | length > 9
  149. - '"/" in appliance_k8s_pod_net_cidr '
  150. success_msg: "{{ success_msg_k8s_pod_network_cidr }}"
  151. fail_msg: "{{ fail_msg_k8s_pod_network_cidr }}"
  152. - name: Assert Organization in awx
  153. assert:
  154. that:
  155. - awx_organization | length >= min_username_length
  156. - awx_organization | length < max_length
  157. - '"-" not in awx_organization '
  158. - '"\\" not in awx_organization '
  159. - '"\"" not in awx_organization '
  160. - " \"'\" not in awx_organization "
  161. success_msg: "{{ success_awx_organization }}"
  162. fail_msg: "{{ fail_awx_organization }}"
  163. - name: Make mount directory for grafana if it doesnt exist
  164. file:
  165. path: "{{ mount_location }}"
  166. state: directory
  167. mode: "{{ mount_dir_perm }}"
  168. group: root
  169. owner: root
  170. - name: Check timezone file
  171. command: grep -Fx "{{ timezone }}" {{ role_path }}/files/timezone.txt
  172. failed_when: false
  173. register: timezone_out
  174. changed_when: false
  175. - name: Assert timezone
  176. assert:
  177. that: timezone in timezone_out.stdout
  178. success_msg: "{{ success_timezone_msg }}"
  179. fail_msg: "{{ fail_timezone_msg }}"
  180. register: timezone_check
  181. - name: Assert language for provisioning nodes
  182. fail:
  183. msg: "{{ fail_language }}"
  184. when: '"en-US" not in language'
  185. - name: Assert provisioning method
  186. assert:
  187. that:
  188. - provision_method == "PXE" or provision_method == "idrac"
  189. success_msg: "{{ success_provision_method }}"
  190. fail_msg: "{{ fail_provision_method }}"
  191. - name: Assert provision_state
  192. assert:
  193. that:
  194. - provision_state == "stateful"
  195. fail_msg: "{{ provision_state_fail_msg }}"
  196. success_msg: "{{ provision_state_success_msg }}"
  197. - name: Assert operating system
  198. assert:
  199. that:
  200. - provision_os == os_supported_centos or
  201. provision_os == os_supported_rocky or
  202. provision_os == os_supported_leap
  203. fail_msg: "{{ provision_os_fail_msg }}"
  204. success_msg: "{{ provision_os_success_msg }}"
  205. - name: Verify the iso_file_path
  206. stat:
  207. path: "{{ iso_file_path }}"
  208. register: result_path_iso_file
  209. - name : Assert iso_file_path location
  210. fail:
  211. msg: "{{ missing_iso_file_path }}"
  212. when: not result_path_iso_file.stat.exists
  213. - name: Validate iso_file_path name
  214. assert:
  215. that:
  216. - result_path_iso_file.stat.exists
  217. - '".iso" in iso_file_path'
  218. - provision_os in iso_file_path | lower
  219. fail_msg: "{{ invalid_iso_file_path }}"
  220. success_msg: "{{ valid_iso_file_path }}"
  221. #### management_net_dhcp_start_end_range
  222. - name: Assert management network nic
  223. assert:
  224. that:
  225. - mngmnt_network_nic in nic_addr_up.stdout
  226. success_msg: "{{ success_msg_mngmnt_network_nic }}"
  227. fail_msg: "{{ fail_msg_mngmnt_network_nic }}"
  228. - name: Fetch the management network ip, netmask and subnet
  229. set_fact:
  230. mngmnt_network_ip: "{{ lookup('vars','ansible_'+mngmnt_network_nic).ipv4.address }}"
  231. mngmnt_network_netmask: "{{ lookup('vars','ansible_'+mngmnt_network_nic).ipv4.netmask }}"
  232. mngmnt_network_subnet: "{{ lookup('vars','ansible_'+mngmnt_network_nic).ipv4.network }}"
  233. - name: Check the subnet of management network dhcp start range
  234. shell: |
  235. IFS=. read -r i1 i2 i3 i4 <<< "{{ mngmnt_network_dhcp_start_range }}"
  236. IFS=. read -r m1 m2 m3 m4 <<< "{{ mngmnt_network_netmask }}"
  237. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  238. args:
  239. warn: no
  240. register: dhcp_start_mgmnt_result
  241. changed_when: false
  242. - name: Set the start dhcp subnet for management network
  243. set_fact:
  244. dhcp_start_mgmnt: "{{ dhcp_start_mgmnt_result.stdout }}"
  245. - name: Check the subnet of dhcp end range for management network
  246. shell: |
  247. IFS=. read -r i1 i2 i3 i4 <<< "{{ mngmnt_network_dhcp_end_range }}"
  248. IFS=. read -r m1 m2 m3 m4 <<< "{{ mngmnt_network_netmask }}"
  249. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  250. register: dhcp_end_mgmnt_result
  251. changed_when: false
  252. - name: Set the end dhcp subnet for management network
  253. set_fact:
  254. dhcp_end_mgmnt: "{{ dhcp_end_mgmnt_result.stdout }}"
  255. - name: Assert management_net_dhcp_start_range
  256. assert:
  257. that:
  258. - mngmnt_network_dhcp_start_range | length > 1
  259. - mngmnt_network_dhcp_start_range | ipv4
  260. - mngmnt_network_dhcp_start_range != mngmnt_network_ip
  261. - mngmnt_network_dhcp_start_range != mngmnt_network_dhcp_end_range
  262. - dhcp_start_mgmnt == mngmnt_network_subnet
  263. - dhcp_start_mgmnt == dhcp_end_mgmnt
  264. success_msg: "{{ success_dhcp_range }} for management network"
  265. fail_msg: "{{ fail_dhcp_range }} for management network"
  266. - name: Assert management_net_dhcp_end_range
  267. assert:
  268. that:
  269. - mngmnt_network_dhcp_end_range | length > 1
  270. - mngmnt_network_dhcp_end_range | ipv4
  271. - mngmnt_network_dhcp_end_range != mngmnt_network_ip
  272. - mngmnt_network_dhcp_start_range != mngmnt_network_dhcp_end_range
  273. - dhcp_end_mgmnt == mngmnt_network_subnet
  274. - dhcp_start_mgmnt == dhcp_end_mgmnt
  275. success_msg: "{{ success_dhcp_range }} for management network"
  276. fail_msg: "{{ fail_dhcp_range }} for management network"
  277. - name: Set the mapping file value for management network
  278. set_fact:
  279. mngmnt_mapping_file: true
  280. when: mngmnt_mapping_file_path | length > 0
  281. - name: Assert valid mngmnt_mapping_file_path
  282. stat:
  283. path: "{{ mngmnt_mapping_file_path }}"
  284. when: mngmnt_mapping_file
  285. register: result_mngmnt_mapping_file
  286. - name : Valid mngmnt_mapping_file_path
  287. fail:
  288. msg: "{{ invalid_mapping_file_path }} for management network"
  289. when: mngmnt_mapping_file and not result_mngmnt_mapping_file.stat.exists
  290. #########
  291. ###Host network####
  292. - name: Fetch the host network ip, netmask and subnet
  293. set_fact:
  294. hpc_ip: "{{ lookup('vars','ansible_'+host_network_nic).ipv4.address }}"
  295. netmask: "{{ lookup('vars','ansible_'+host_network_nic).ipv4.netmask }}"
  296. subnet: "{{ lookup('vars','ansible_'+host_network_nic).ipv4.network }}"
  297. - name: Check the subnet of host network dhcp start range
  298. shell: |
  299. IFS=. read -r i1 i2 i3 i4 <<< "{{ host_network_dhcp_start_range }}"
  300. IFS=. read -r m1 m2 m3 m4 <<< "{{ netmask }}"
  301. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  302. args:
  303. warn: no
  304. register: dhcp_start_host_result
  305. changed_when: false
  306. - name: Set the start dhcp subnet for host network
  307. set_fact:
  308. dhcp_start_host: "{{ dhcp_start_host_result.stdout }}"
  309. - name: Check the subnet of dhcp end range for host network
  310. shell: |
  311. IFS=. read -r i1 i2 i3 i4 <<< "{{ host_network_dhcp_end_range }}"
  312. IFS=. read -r m1 m2 m3 m4 <<< "{{ netmask }}"
  313. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  314. register: dhcp_end_host_result
  315. changed_when: false
  316. - name: Set the end dhcp subnet for host network
  317. set_fact:
  318. dhcp_end_host: "{{ dhcp_end_host_result.stdout }}"
  319. - name: Assert host_network_dhcp_start_range
  320. assert:
  321. that:
  322. - host_network_dhcp_start_range | length > 1
  323. - host_network_dhcp_start_range | ipv4
  324. - host_network_dhcp_start_range != hpc_ip
  325. - host_network_dhcp_start_range != host_network_dhcp_end_range
  326. - dhcp_start_host == subnet
  327. - dhcp_start_host == dhcp_end_host
  328. success_msg: "{{ success_dhcp_range }} for host network"
  329. fail_msg: "{{ fail_dhcp_range }} for host network"
  330. - name: Assert host_network_dhcp_end_range
  331. assert:
  332. that:
  333. - host_network_dhcp_end_range | length > 1
  334. - host_network_dhcp_end_range | ipv4
  335. - host_network_dhcp_end_range != hpc_ip
  336. - host_network_dhcp_start_range != host_network_dhcp_end_range
  337. - dhcp_end_host == subnet
  338. - dhcp_start_host == dhcp_end_host
  339. success_msg: "{{ success_dhcp_range }} for host network"
  340. fail_msg: "{{ fail_dhcp_range }} for host network"
  341. - name: Set the mapping file value for host network
  342. set_fact:
  343. host_mapping_file: true
  344. when: host_mapping_file_path | length > 0
  345. - name: Assert valid mapping_file_path
  346. stat:
  347. path: "{{ host_mapping_file_path }}"
  348. when: host_mapping_file
  349. register: result_host_mapping_file
  350. - name: Valid mapping_file_path
  351. fail:
  352. msg: "{{ invalid_mapping_file_path }} for host_network"
  353. when: host_mapping_file and not result_host_mapping_file.stat.exists
  354. - name: Verify different nics
  355. assert:
  356. that:
  357. - public_nic != mngmnt_network_nic
  358. - mngmnt_network_nic != host_network_nic
  359. - public_nic != host_network_nic
  360. success_msg: "{{ success_msg_different_nics }}"
  361. fail_msg: "{{ fail_msg_different_nics }}"
  362. ########
  363. - name: Fetch the infiniband network ip, netmask and subnet
  364. set_fact:
  365. ib_ip: "{{ lookup('vars','ansible_'+ib_network_nic).ipv4.address }}"
  366. ib_netmask: "{{ lookup('vars','ansible_'+ib_network_nic).ipv4.netmask }}"
  367. ib_subnet: "{{ lookup('vars','ansible_'+ib_network_nic).ipv4.network }}"
  368. when: ib_switch_support
  369. - name: Check the subnet of infiniband network dhcp start range
  370. shell: |
  371. IFS=. read -r i1 i2 i3 i4 <<< "{{ ib_network_dhcp_start_range }}"
  372. IFS=. read -r m1 m2 m3 m4 <<< "{{ ib_netmask }}"
  373. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  374. args:
  375. warn: no
  376. register: dhcp_start_ib_result
  377. when: ib_switch_support
  378. changed_when: false
  379. - name: Set the start dhcp subnet for infiniband network
  380. set_fact:
  381. dhcp_start_ib: "{{ dhcp_start_ib_result.stdout }}"
  382. when: ib_switch_support
  383. - name: Check the subnet of dhcp end range for infiniband network
  384. shell: |
  385. IFS=. read -r i1 i2 i3 i4 <<< "{{ ib_network_dhcp_end_range }}"
  386. IFS=. read -r m1 m2 m3 m4 <<< "{{ ib_netmask }}"
  387. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  388. register: dhcp_end_ib_result
  389. when: ib_switch_support
  390. changed_when: false
  391. - name: Set the end dhcp subnet for infiniband network
  392. set_fact:
  393. dhcp_end_ib: "{{ dhcp_end_ib_result.stdout }}"
  394. when: ib_switch_support
  395. - name: Assert infiniband_net_dhcp_start_range
  396. assert:
  397. that:
  398. - ib_network_dhcp_start_range | length > 1
  399. - ib_network_dhcp_start_range | ipv4
  400. - ib_network_dhcp_start_range != ib_ip
  401. - ib_network_dhcp_start_range != ib_network_dhcp_end_range
  402. - dhcp_start_ib == ib_subnet
  403. - dhcp_start_ib == dhcp_end_ib
  404. success_msg: "{{ success_dhcp_range }} for infiniband network"
  405. fail_msg: "{{ fail_dhcp_range }} for infiniband network"
  406. when: ib_switch_support
  407. - name: Assert infiniband_net_dhcp_end_range
  408. assert:
  409. that:
  410. - ib_network_dhcp_end_range | length > 1
  411. - ib_network_dhcp_end_range | ipv4
  412. - ib_network_dhcp_end_range != ib_ip
  413. - ib_network_dhcp_start_range != ib_network_dhcp_end_range
  414. - dhcp_end_ib == ib_subnet
  415. - dhcp_start_ib == dhcp_end_ib
  416. success_msg: "{{ success_dhcp_range }} for infiniband network"
  417. fail_msg: "{{ fail_dhcp_range }} for infiniband network"
  418. when: ib_switch_support
  419. - name: Verify different nics with infiniband nic
  420. assert:
  421. that:
  422. - public_nic != ib_network_nic
  423. - mngmnt_network_nic != ib_network_nic
  424. - ib_network_nic != host_network_nic
  425. success_msg: "{{ success_msg_different_nics_ib }}"
  426. fail_msg: "{{ fail_msg_different_nics_ib }}"
  427. when: ib_switch_support