ansible-roles/docker-host/tasks/main.yml

116 lines
2.9 KiB
YAML
Raw Normal View History

2017-03-24 15:38:38 +01:00
# This role installs the docker daemon
---
2017-07-24 22:38:08 +02:00
- name: Remove older docker packages
2023-03-19 11:44:53 +01:00
ansible.builtin.apt:
2019-12-31 15:25:10 +01:00
name:
- docker
- docker-engine
- docker.io
2017-07-24 22:38:08 +02:00
state: absent
- name: Install source requirements
2023-03-19 11:44:53 +01:00
ansible.builtin.apt:
2019-12-31 15:25:10 +01:00
name:
- ca-certificates
- gnupg2
2017-03-24 15:38:38 +01:00
state: present
2023-03-18 19:52:55 +01:00
- name: Install apt-transport-https (Debian <10)
2023-03-19 11:44:53 +01:00
ansible.builtin.apt:
2023-03-18 19:52:55 +01:00
name:
- apt-transport-https
state: present
when: ansible_distribution_major_version is version('10', '<')
2017-07-24 22:38:08 +02:00
- name: Add Docker's official GPG key
2023-03-19 11:44:53 +01:00
ansible.builtin.copy:
src: docker-debian.asc
dest: "{{ apt_keyring_dir }}/docker-debian.asc"
force: yes
mode: "0644"
2021-05-26 13:47:34 +02:00
owner: root
group: root
2017-03-24 15:38:38 +01:00
2023-03-18 19:52:55 +01:00
- name: Add Docker repository (Debian <12)
2023-03-19 11:44:53 +01:00
ansible.builtin.apt_repository:
repo: 'deb [signed-by={{ apt_keyring_dir }}/docker-debian.asc] https://download.docker.com/linux/debian {{ ansible_distribution_release }} stable'
2023-03-19 11:44:53 +01:00
filename: docker
2023-03-18 19:52:55 +01:00
state: present
2023-03-19 11:44:53 +01:00
update_cache: yes
2023-03-18 19:52:55 +01:00
when: ansible_distribution_major_version is version('12', '<')
2023-03-18 19:52:55 +01:00
- name: Add Docker repository (Debian >=12)
ansible.builtin.template:
src: docker.sources.j2
dest: /etc/apt/sources.list.d/docker.sources
state: present
2023-03-19 11:44:53 +01:00
register: docker_sources
2023-03-18 19:52:55 +01:00
when: ansible_distribution_major_version is version('12', '>=')
2023-03-19 11:44:53 +01:00
- name: Update APT cache
ansible.builtin.apt:
update_cache: yes
when: docker_sources is changed
- name: Install Docker
2023-03-19 11:44:53 +01:00
ansible.builtin.apt:
2019-12-31 15:25:10 +01:00
name:
- docker-ce
- docker-ce-cli
- containerd.io
2017-03-24 15:38:38 +01:00
- name: python-docker is installed
2023-03-19 11:44:53 +01:00
ansible.builtin.apt:
name: python-docker
state: present
when: ansible_python_version is version('3', '<')
- name: python3-docker is installed
2023-03-19 11:44:53 +01:00
ansible.builtin.apt:
name: python3-docker
state: present
when: ansible_python_version is version('3', '>=')
2017-07-24 22:38:08 +02:00
- name: Copy Docker daemon configuration file
2023-03-19 11:44:53 +01:00
ansible.builtin.template:
2017-07-24 22:38:08 +02:00
src: daemon.json.j2
dest: /etc/docker/daemon.json
notify: restart docker
2017-03-24 15:38:38 +01:00
- name: Creating Docker tmp directory
2023-03-19 11:44:53 +01:00
ansible.builtin.file:
2017-03-24 15:38:38 +01:00
path: "{{ docker_tmpdir }}"
state: directory
mode: "0644"
owner: root
- name: Creating Docker TLS directory
2023-03-19 11:44:53 +01:00
ansible.builtin.file:
2017-03-24 15:38:38 +01:00
path: "{{ docker_tls_path }}"
state: directory
mode: "0644"
owner: root
when: docker_tls_enabled | bool
2017-03-24 15:38:38 +01:00
- name: Copy shellpki utility to Docker TLS directory
2023-03-19 11:44:53 +01:00
ansible.builtin.template:
2017-03-24 15:38:38 +01:00
src: "{{ item }}.j2"
dest: "{{ docker_tls_path }}/{{ item }}"
mode: "0744"
loop:
2017-03-24 15:38:38 +01:00
- shellpki.sh
- openssl.cnf
when: docker_tls_enabled | bool
2017-07-24 22:38:08 +02:00
- name: Check if certs are already created
2023-03-19 11:44:53 +01:00
ansible.builtin.stat:
2017-07-24 22:38:08 +02:00
path: "{{ docker_tls_path }}/certs"
register: tls_certs_stat
2017-03-24 15:38:38 +01:00
- name: Creating a CA, server key
2023-03-19 11:44:53 +01:00
ansible.builtin.command:
cmd: "{{ docker_tls_path }}/shellpki.sh init"
when:
- docker_tls_enabled | bool
- not tls_certs_stat.stat.isdir