ansible-roles/docker-host/tasks/main.yml

97 lines
2.2 KiB
YAML
Raw Normal View History

2017-03-24 15:38:38 +01:00
# This role installs the docker daemon
---
2017-07-24 22:38:08 +02:00
- name: Remove older docker packages
2017-03-24 15:38:38 +01:00
apt:
2017-07-24 22:38:08 +02:00
name: '{{ item }}'
state: absent
with_items:
- docker
- docker-engine
- docker.io
- name: Install source requirements
apt:
name: '{{ item }}'
2017-03-24 15:38:38 +01:00
state: present
update_cache: yes
2017-07-24 22:38:08 +02:00
with_items:
- apt-transport-https
- ca-certificates
- gnupg2
2017-03-24 15:38:38 +01:00
2017-07-24 22:38:08 +02:00
- name: Add Docker repository
2017-03-24 15:38:38 +01:00
apt_repository:
2017-07-24 22:38:08 +02:00
repo: 'deb [arch=amd64] https://download.docker.com/linux/debian {{ ansible_distribution_release }} stable'
2017-03-24 15:38:38 +01:00
state: present
update_cache: no
filename: docker.list
2017-03-24 15:38:38 +01:00
- include: jessie_backports.yml
2017-07-24 22:38:08 +02:00
when: ansible_distribution_release == 'jessie'
2017-03-24 15:38:38 +01:00
2017-07-24 22:38:08 +02:00
- name: Add Docker's official GPG key
2017-03-24 15:38:38 +01:00
apt_key:
#url: https://download.docker.com/linux/debian/gpg
data: "{{ lookup('file', 'docker-debian.gpg') }}"
2017-03-24 15:38:38 +01:00
2017-07-24 22:38:08 +02:00
- name: Install docker and python-docker
2017-03-24 15:38:38 +01:00
apt:
2017-04-06 11:33:56 +02:00
name: "{{ item }}"
2017-03-24 15:38:38 +01:00
update_cache: yes
with_items:
2017-07-24 22:38:08 +02:00
- docker-ce
2017-03-24 15:38:38 +01:00
- python-docker
2017-07-24 22:38:08 +02:00
- name: Copy Docker daemon configuration file
2017-03-24 15:38:38 +01:00
template:
2017-07-24 22:38:08 +02:00
src: daemon.json.j2
dest: /etc/docker/daemon.json
notify: restart docker
2017-03-24 15:38:38 +01:00
- name: Create override directory for docker unit
file:
name: /etc/systemd/system/docker.service.d/
state: directory
mode: "0755"
- name: Remove options in ExecStart from docker unit
copy:
src: docker.conf
dest: /etc/systemd/system/docker.service.d/
mode: "0644"
notify: reload systemd
2017-07-24 22:38:08 +02:00
2017-03-24 15:38:38 +01:00
- name: Creating Docker tmp directory
file:
path: "{{ docker_tmpdir }}"
state: directory
mode: "0644"
owner: root
- name: Creating Docker TLS directory
file:
path: "{{ docker_tls_path }}"
state: directory
mode: "0644"
owner: root
2017-07-24 22:38:08 +02:00
when: docker_tls_enabled
2017-03-24 15:38:38 +01:00
- name: Copy shellpki utility to Docker TLS directory
template:
src: "{{ item }}.j2"
dest: "{{ docker_tls_path }}/{{ item }}"
mode: "0744"
with_items:
- shellpki.sh
- openssl.cnf
2017-07-24 22:38:08 +02:00
when: docker_tls_enabled
- name: Check if certs are already created
stat:
path: "{{ docker_tls_path }}/certs"
register: tls_certs_stat
2017-03-24 15:38:38 +01:00
- name: Creating a CA, server key
command: "{{ docker_tls_path }}/shellpki.sh init"
2017-07-24 22:38:08 +02:00
when: docker_tls_enabled and not tls_certs_stat.stat.isdir is defined