fetch_base_inputs.yml 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480
  1. # Copyright 2021 Dell Inc. or its subsidiaries. All Rights Reserved.
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. ---
  15. - name: Include base variable file base_vars.yml
  16. include_vars: "{{ base_vars_filename }}"
  17. no_log: true
  18. - name: Validate input parameters of base_vars are not empty
  19. fail:
  20. msg: "{{ input_base_failure_msg }}"
  21. register: input_base_check
  22. when:
  23. - ansible_conf_file_path | length < 1 or
  24. public_nic | length < 1 or
  25. appliance_k8s_pod_net_cidr | length < 1 or
  26. awx_organization | length < 1 or
  27. timezone | length < 1 or
  28. language | length < 1 or
  29. iso_file_path | length < 1 or
  30. mngmnt_network_nic | length < 1 or
  31. mngmnt_network_dhcp_start_range | length < 1 or
  32. mngmnt_network_dhcp_end_range | length < 1 or
  33. host_network_nic | length < 1 or
  34. host_network_dhcp_start_range | length < 1 or
  35. host_network_dhcp_end_range | length < 1 or
  36. provision_method | length < 1 or
  37. default_lease_time | length < 1 or
  38. provision_os | length < 1 or
  39. provision_state | length < 1
  40. - name: Validate default lease time
  41. assert:
  42. that:
  43. - default_lease_time|int
  44. - default_lease_time|int <= 31536000
  45. - default_lease_time|int >= 21600
  46. success_msg: "{{ success_msg_lease_time }}"
  47. fail_msg: "{{ fail_msg_lease_time }}"
  48. - name: Calculate max lease time
  49. set_fact:
  50. max_lease_time: "{{ default_lease_time|int + 10000 }}"
  51. - name: Validate infiniband base_vars are not empty
  52. assert:
  53. that:
  54. - ib_network_nic | length > 2
  55. - ib_network_dhcp_start_range | length > 6
  56. - ib_network_dhcp_end_range | length > 6
  57. success_msg: "{{ success_msg_ib }}"
  58. fail_msg: "{{ fail_msg_ib }}"
  59. register: ib_check
  60. when: ib_switch_support
  61. - name: Set facts to validate snmp support
  62. set_fact:
  63. snmp_enabled: false
  64. mngmnt_mapping_file: false
  65. host_mapping_file: false
  66. - name: Verify snmp_trap_destination IP address
  67. set_fact:
  68. snmp_enabled: true
  69. when: snmp_trap_destination | length > 1
  70. - name: Assert snmp trap destination address
  71. assert:
  72. that:
  73. - snmp_enabled
  74. - snmp_trap_destination | length > 7
  75. - snmp_trap_destination | ipv4
  76. success_msg: "{{ success_snmp_trap_dest }}"
  77. fail_msg: "{{ fail_snmp_trap_dest }}"
  78. when: snmp_enabled
  79. - name: Assert snmp community string
  80. assert:
  81. that:
  82. - snmp_enabled
  83. - snmp_community_name
  84. success_msg: "{{ success_snmp_comm_msg }}"
  85. fail_msg: "{{ fail_snmp_comm_msg }}"
  86. when: snmp_enabled
  87. - name: Check whether ansible config file exists
  88. stat:
  89. path: "{{ ansible_conf_file_path }}/ansible.cfg"
  90. register: ansible_conf_exists
  91. - name: Create the directory if it does not exist
  92. file:
  93. path: "{{ ansible_conf_file_path }}"
  94. state: directory
  95. mode: "{{ file_perm }}"
  96. when: not ansible_conf_exists.stat.exists
  97. changed_when: false
  98. - name: Create ansible config file if it does not exist
  99. copy:
  100. dest: '{{ ansible_conf_file_path }}/ansible.cfg'
  101. mode: "{{ file_perm }}"
  102. content: |
  103. [defaults]
  104. log_path = /var/log/omnia.log
  105. when: not ansible_conf_exists.stat.exists
  106. - name: Assert ethernet_switch_support
  107. assert:
  108. that:
  109. - ethernet_switch_support == true or ethernet_switch_support == false
  110. success_msg: "{{ ethernet_switch_support_success_msg }}"
  111. fail_msg: "{{ ethernet_switch_support_fail_msg }}"
  112. - name: Assert ib_switch_support
  113. assert:
  114. that:
  115. - ib_switch_support == true or ib_switch_support == false
  116. success_msg: "{{ ib_switch_support_success_msg }}"
  117. fail_msg: "{{ ib_switch_support_fail_msg }}"
  118. - name: Assert powervault_support
  119. assert:
  120. that:
  121. - powervault_support == true or powervault_support == false
  122. success_msg: "{{ powervault_support_success_msg }}"
  123. fail_msg: "{{ powervault_support_fail_msg }}"
  124. - name: Fetch the network interfaces in UP state in the system
  125. shell: set -o pipefail && ip a | awk '/state UP/{print $2}'
  126. register: nic_addr_up
  127. changed_when: false
  128. - name: Assert public nic
  129. assert:
  130. that:
  131. - public_nic in nic_addr_up.stdout
  132. success_msg: "{{ success_msg_public_nic }}"
  133. fail_msg: "{{ fail_msg_public_nic }}"
  134. - name: Fetch the system public IP
  135. set_fact:
  136. public_ip: "{{ lookup('vars','ansible_'+public_nic).ipv4.address }}"
  137. - name: Assert kubernetes pod network CIDR
  138. assert:
  139. that:
  140. - appliance_k8s_pod_net_cidr | ipv4
  141. - appliance_k8s_pod_net_cidr | length > 9
  142. - '"/" in appliance_k8s_pod_net_cidr '
  143. success_msg: "{{ success_msg_k8s_pod_network_cidr }}"
  144. fail_msg: "{{ fail_msg_k8s_pod_network_cidr }}"
  145. - name: Assert Organization in awx
  146. assert:
  147. that:
  148. - awx_organization | length >= min_username_length
  149. - awx_organization | length < max_length
  150. - '"-" not in awx_organization '
  151. - '"\\" not in awx_organization '
  152. - '"\"" not in awx_organization '
  153. - " \"'\" not in awx_organization "
  154. success_msg: "{{ success_awx_organization }}"
  155. fail_msg: "{{ fail_awx_organization }}"
  156. - name: Check timezone file
  157. command: grep -Fx "{{ timezone }}" {{ role_path }}/files/timezone.txt
  158. failed_when: false
  159. register: timezone_out
  160. changed_when: false
  161. - name: Assert timezone
  162. assert:
  163. that: timezone in timezone_out.stdout
  164. success_msg: "{{ success_timezone_msg }}"
  165. fail_msg: "{{ fail_timezone_msg }}"
  166. register: timezone_check
  167. - name: Assert language for provisioning nodes
  168. fail:
  169. msg: "{{ fail_language }}"
  170. when: '"en-US" not in language'
  171. - name: Assert provisioning method
  172. assert:
  173. that:
  174. - provision_method == "PXE" or provision_method == "idrac"
  175. success_msg: "{{ success_provision_method }}"
  176. fail_msg: "{{ fail_provision_method }}"
  177. - name: Assert provision_state
  178. assert:
  179. that:
  180. - provision_state == "stateful" or
  181. provision_state == "stateless"
  182. fail_msg: "{{ provision_state_fail_msg }}"
  183. success_msg: "{{ provision_state_success_msg }}"
  184. - name: Assert operating system
  185. assert:
  186. that:
  187. - provision_os == os_supported_centos or
  188. provision_os == os_supported_rocky
  189. fail_msg: "{{ provision_os_fail_msg }}"
  190. success_msg: "{{ provision_os_success_msg }}"
  191. - name: Assert provision_method when provision_state == stateless
  192. assert:
  193. that: provision_method == "PXE"
  194. fail_msg: "{{ stateless_provision_fail_msg }}"
  195. success_msg: "{{ success_provision_method }}"
  196. when: provision_state == "stateless"
  197. - name: Verify the iso_file_path
  198. stat:
  199. path: "{{ iso_file_path }}"
  200. register: result_path_iso_file
  201. - name : Assert iso_file_path location
  202. fail:
  203. msg: "{{ missing_iso_file_path }}"
  204. when: not result_path_iso_file.stat.exists
  205. - name: Validate iso_file_path name
  206. assert:
  207. that:
  208. - result_path_iso_file.stat.exists
  209. - '".iso" in iso_file_path'
  210. - provision_os in iso_file_path | lower
  211. fail_msg: "{{ invalid_iso_file_path }}"
  212. success_msg: "{{ valid_iso_file_path }}"
  213. #### management_net_dhcp_start_end_range
  214. - name: Assert management network nic
  215. assert:
  216. that:
  217. - mngmnt_network_nic in nic_addr_up.stdout
  218. success_msg: "{{ success_msg_mngmnt_network_nic }}"
  219. fail_msg: "{{ fail_msg_mngmnt_network_nic }}"
  220. - name: Fetch the management network ip, netmask and subnet
  221. set_fact:
  222. mngmnt_network_ip: "{{ lookup('vars','ansible_'+mngmnt_network_nic).ipv4.address }}"
  223. mngmnt_network_netmask: "{{ lookup('vars','ansible_'+mngmnt_network_nic).ipv4.netmask }}"
  224. mngmnt_network_subnet: "{{ lookup('vars','ansible_'+mngmnt_network_nic).ipv4.network }}"
  225. - name: Check the subnet of management network dhcp start range
  226. shell: |
  227. IFS=. read -r i1 i2 i3 i4 <<< "{{ mngmnt_network_dhcp_start_range }}"
  228. IFS=. read -r m1 m2 m3 m4 <<< "{{ mngmnt_network_netmask }}"
  229. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  230. args:
  231. warn: no
  232. register: dhcp_start_mgmnt_result
  233. changed_when: false
  234. - name: Set the start dhcp subnet for management network
  235. set_fact:
  236. dhcp_start_mgmnt: "{{ dhcp_start_mgmnt_result.stdout }}"
  237. - name: Check the subnet of dhcp end range for management network
  238. shell: |
  239. IFS=. read -r i1 i2 i3 i4 <<< "{{ mngmnt_network_dhcp_end_range }}"
  240. IFS=. read -r m1 m2 m3 m4 <<< "{{ mngmnt_network_netmask }}"
  241. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  242. register: dhcp_end_mgmnt_result
  243. changed_when: false
  244. - name: Set the end dhcp subnet for management network
  245. set_fact:
  246. dhcp_end_mgmnt: "{{ dhcp_end_mgmnt_result.stdout }}"
  247. - name: Assert management_net_dhcp_start_range
  248. assert:
  249. that:
  250. - mngmnt_network_dhcp_start_range
  251. - mngmnt_network_dhcp_start_range | ipv4
  252. - mngmnt_network_dhcp_start_range != mngmnt_network_ip
  253. - mngmnt_network_dhcp_start_range != mngmnt_network_dhcp_end_range
  254. - dhcp_start_mgmnt == mngmnt_network_subnet
  255. - dhcp_start_mgmnt == dhcp_end_mgmnt
  256. success_msg: "{{ success_dhcp_range }} for management network"
  257. fail_msg: "{{ fail_dhcp_range }} for management network"
  258. - name: Assert management_net_dhcp_end_range
  259. assert:
  260. that:
  261. - mngmnt_network_dhcp_end_range
  262. - mngmnt_network_dhcp_end_range | ipv4
  263. - mngmnt_network_dhcp_end_range != mngmnt_network_ip
  264. - mngmnt_network_dhcp_start_range != mngmnt_network_dhcp_end_range
  265. - dhcp_end_mgmnt == mngmnt_network_subnet
  266. - dhcp_start_mgmnt == dhcp_end_mgmnt
  267. success_msg: "{{ success_dhcp_range }} for management network"
  268. fail_msg: "{{ fail_dhcp_range }} for management network"
  269. - name: Set the mapping file value for management network
  270. set_fact:
  271. mngmnt_mapping_file: true
  272. when: mngmnt_mapping_file_path | length > 0
  273. - name: Assert valid mngmnt_mapping_file_path
  274. stat:
  275. path: "{{ mngmnt_mapping_file_path }}"
  276. when: mngmnt_mapping_file
  277. register: result_mngmnt_mapping_file
  278. - name : Valid mngmnt_mapping_file_path
  279. fail:
  280. msg: "{{ invalid_mapping_file_path }} for management network"
  281. when: mngmnt_mapping_file and not result_mngmnt_mapping_file.stat.exists
  282. #########
  283. ###Host network####
  284. - name: Fetch the host network ip, netmask and subnet
  285. set_fact:
  286. hpc_ip: "{{ lookup('vars','ansible_'+host_network_nic).ipv4.address }}"
  287. netmask: "{{ lookup('vars','ansible_'+host_network_nic).ipv4.netmask }}"
  288. subnet: "{{ lookup('vars','ansible_'+host_network_nic).ipv4.network }}"
  289. - name: Check the subnet of host network dhcp start range
  290. shell: |
  291. IFS=. read -r i1 i2 i3 i4 <<< "{{ host_network_dhcp_start_range }}"
  292. IFS=. read -r m1 m2 m3 m4 <<< "{{ netmask }}"
  293. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  294. args:
  295. warn: no
  296. register: dhcp_start_host_result
  297. changed_when: false
  298. - name: Set the start dhcp subnet for host network
  299. set_fact:
  300. dhcp_start_host: "{{ dhcp_start_host_result.stdout }}"
  301. - name: Check the subnet of dhcp end range for host network
  302. shell: |
  303. IFS=. read -r i1 i2 i3 i4 <<< "{{ host_network_dhcp_end_range }}"
  304. IFS=. read -r m1 m2 m3 m4 <<< "{{ netmask }}"
  305. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  306. register: dhcp_end_host_result
  307. changed_when: false
  308. - name: Set the end dhcp subnet for host network
  309. set_fact:
  310. dhcp_end_host: "{{ dhcp_end_host_result.stdout }}"
  311. - name: Assert host_network_dhcp_start_range
  312. assert:
  313. that:
  314. - host_network_dhcp_start_range
  315. - host_network_dhcp_start_range | ipv4
  316. - host_network_dhcp_start_range != hpc_ip
  317. - host_network_dhcp_start_range != host_network_dhcp_end_range
  318. - dhcp_start_host == subnet
  319. - dhcp_start_host == dhcp_end_host
  320. success_msg: "{{ success_dhcp_range }} for host network"
  321. fail_msg: "{{ fail_dhcp_range }} for host network"
  322. - name: Assert host_network_dhcp_end_range
  323. assert:
  324. that:
  325. - host_network_dhcp_end_range
  326. - host_network_dhcp_end_range | ipv4
  327. - host_network_dhcp_end_range != hpc_ip
  328. - host_network_dhcp_start_range != host_network_dhcp_end_range
  329. - dhcp_end_host == subnet
  330. - dhcp_start_host == dhcp_end_host
  331. success_msg: "{{ success_dhcp_range }} for host network"
  332. fail_msg: "{{ fail_dhcp_range }} for host network"
  333. - name: Set the mapping file value for host network
  334. set_fact:
  335. host_mapping_file: true
  336. when: host_mapping_file_path | length > 0
  337. - name: Assert valid mapping_file_path
  338. stat:
  339. path: "{{ host_mapping_file_path }}"
  340. when: host_mapping_file
  341. register: result_host_mapping_file
  342. - name: Valid mapping_file_path
  343. fail:
  344. msg: "{{ invalid_mapping_file_path }} for host_network"
  345. when: host_mapping_file and not result_host_mapping_file.stat.exists
  346. - name: Verify different nics
  347. assert:
  348. that:
  349. - public_nic != mngmnt_network_nic
  350. - mngmnt_network_nic != host_network_nic
  351. - public_nic != host_network_nic
  352. success_msg: "{{ success_msg_different_nics }}"
  353. fail_msg: "{{ fail_msg_different_nics }}"
  354. ########
  355. - name: Fetch the infiniband network ip, netmask and subnet
  356. set_fact:
  357. ib_ip: "{{ lookup('vars','ansible_'+ib_network_nic).ipv4.address }}"
  358. ib_netmask: "{{ lookup('vars','ansible_'+ib_network_nic).ipv4.netmask }}"
  359. ib_subnet: "{{ lookup('vars','ansible_'+ib_network_nic).ipv4.network }}"
  360. when: ib_switch_support
  361. - name: Check the subnet of infiniband network dhcp start range
  362. shell: |
  363. IFS=. read -r i1 i2 i3 i4 <<< "{{ ib_network_dhcp_start_range }}"
  364. IFS=. read -r m1 m2 m3 m4 <<< "{{ ib_netmask }}"
  365. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  366. args:
  367. warn: no
  368. register: dhcp_start_ib_result
  369. when: ib_switch_support
  370. changed_when: false
  371. - name: Set the start dhcp subnet for infiniband network
  372. set_fact:
  373. dhcp_start_ib: "{{ dhcp_start_ib_result.stdout }}"
  374. when: ib_switch_support
  375. - name: Check the subnet of dhcp end range for infiniband network
  376. shell: |
  377. IFS=. read -r i1 i2 i3 i4 <<< "{{ ib_network_dhcp_end_range }}"
  378. IFS=. read -r m1 m2 m3 m4 <<< "{{ ib_netmask }}"
  379. printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"
  380. register: dhcp_end_ib_result
  381. when: ib_switch_support
  382. changed_when: false
  383. - name: Set the end dhcp subnet for infiniband network
  384. set_fact:
  385. dhcp_end_ib: "{{ dhcp_end_ib_result.stdout }}"
  386. when: ib_switch_support
  387. - name: Assert infiniband_net_dhcp_start_range
  388. assert:
  389. that:
  390. - ib_network_dhcp_start_range
  391. - ib_network_dhcp_start_range | ipv4
  392. - ib_network_dhcp_start_range != ib_ip
  393. - ib_network_dhcp_start_range != ib_network_dhcp_end_range
  394. - dhcp_start_ib == ib_subnet
  395. - dhcp_start_ib == dhcp_end_ib
  396. success_msg: "{{ success_dhcp_range }} for infiniband network"
  397. fail_msg: "{{ fail_dhcp_range }} for infiniband network"
  398. when: ib_switch_support
  399. - name: Assert infiniband_net_dhcp_end_range
  400. assert:
  401. that:
  402. - ib_network_dhcp_end_range
  403. - ib_network_dhcp_end_range | ipv4
  404. - ib_network_dhcp_end_range != ib_ip
  405. - ib_network_dhcp_start_range != ib_network_dhcp_end_range
  406. - dhcp_end_ib == ib_subnet
  407. - dhcp_start_ib == dhcp_end_ib
  408. success_msg: "{{ success_dhcp_range }} for infiniband network"
  409. fail_msg: "{{ fail_dhcp_range }} for infiniband network"
  410. when: ib_switch_support
  411. - name: Verify different nics with infiniband nic
  412. assert:
  413. that:
  414. - public_nic != ib_network_nic
  415. - mngmnt_network_nic != ib_network_nic
  416. - ib_network_nic != host_network_nic
  417. success_msg: "{{ success_msg_different_nics_ib }}"
  418. fail_msg: "{{ fail_msg_different_nics_ib }}"
  419. when: ib_switch_support