openstack-ansible-ops/osquery/roles/fleet/handlers/main.yml
Kevin Carter 5aff0b59f4
Cleanup the osquery tooling and vendor roles
The osquery tooling needed a little work to be fully automated and
repeatable. This change tunes up the tools and makes the entire
deployment process multi-node capable and repeatable.

The osquery role was vendored because of bugs within their use of aarmor
profiles and there was no way to disable them.

The fleet use of commands for ssl creation have been removed. The ssl
modules are now being used to generate all of the certificates.

New pre-tasks have been added to check for required variables. If the
required variables are not set the playbooks will fail early and notify
the user of the issue.

Change-Id: I88c2b40ed9d9a88a39bdf07b0dce2900fda50151
Signed-off-by: Kevin Carter <kevin.carter@rackspace.com>
2018-10-15 22:47:10 -05:00

48 lines
1.4 KiB
YAML

---
# Copyright 2016, Rackspace US, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
- name: Enable and restart kolide socket (systemd)
systemd:
name: "kolide-fleet-proxy.socket"
enabled: true
state: started
listen: Restart kolide (systemd)
- name: Enable and restart kolide (systemd)
systemd:
name: "kolide-fleet.service"
enabled: true
state: restarted
notify:
- Enable and restart kolide proxy (systemd)
listen: Restart kolide (systemd)
- name: Enable and restart kolide proxy (systemd)
systemd:
name: "kolide-fleet-proxy.service"
enabled: true
state: restarted
listen: Restart kolide (systemd)
- name: Cleanup certifactes
file:
dest: "{{ item }}"
state: "absent"
delegate_to: localhost
with_items:
- "/tmp/{{ kolide_fleet_ssl_cert | basename }}"
- "/tmp/{{ kolide_fleet_ssl_key | basename }}"
- "/tmp/{{ kolide_fleet_ssl_csr | basename }}"