controller_token¶
Role Documentation¶
Welcome to the “controller_token” role documentation.
Role Defaults¶
This section highlights all of the defaults and variables set within the “controller_token” role.
keystone_conf_file: /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf
Role Variables: main.yml¶
metadata:
description: 'This validation checks that keystone admin token is disabled on both
undercloud and overcloud controller after deployment.
'
groups:
- post-deployment
name: Verify that keystone admin token is disabled
Molecule Scenarios¶
Molecule is being used to test the “controller_token” role. The following section highlights the drivers in service and provides an example playbook showing how the role is leveraged.
Scenario: default¶
Example default configuration¶
driver:
name: podman
log: true
platforms:
- easy_install:
- pip
environment:
http_proxy: '{{ lookup(''env'', ''http_proxy'') }}'
https_proxy: '{{ lookup(''env'', ''https_proxy'') }}'
hostname: centos7
image: centos:7
name: centos7
pkg_extras: python-setuptools python-enum34 PyYAML
ulimits: &id001
- host
volumes:
- /etc/ci/mirror_info.sh:/etc/ci/mirror_info.sh:ro
- environment:
http_proxy: '{{ lookup(''env'', ''http_proxy'') }}'
https_proxy: '{{ lookup(''env'', ''https_proxy'') }}'
hostname: centos8
image: centos:8
name: centos8
pkg_extras: python*-setuptools python*-enum34 python*-PyYAML
ulimits: *id001
volumes:
- /etc/ci/mirror_info.sh:/etc/ci/mirror_info.sh:ro
provisioner:
env:
ANSIBLE_LIBRARY: ../../../../library:../../../../roles/roles.galaxy/validations-common/validations_common/library
ANSIBLE_STDOUT_CALLBACK: yaml
log: true
name: ansible
scenario:
test_sequence:
- destroy
- create
- prepare
- converge
- verify
- destroy
verifier:
name: testinfra
Example default playbook¶
- gather_facts: false
hosts: all
name: Converge
tasks:
- include_role:
name: controller_token
name: pass validation
- block:
- copy:
content: '[DEFAULT]
admin_token = CHANGEME
'
dest: /keystone.conf
name: provide configuration file
- include_role:
name: controller_token
vars:
keystone_conf_file: /keystone.conf
name: fail validation
rescue:
- meta: clear_host_errors
name: Clear host errors
- debug:
msg: The validation works! End the playbook run
- meta: end_play
name: End play
- fail:
msg: 'Controller-token validation failed finding bad configuration!
'
name: Fail the test