|
| 1 | +--- |
1 | 2 | - name: Add group engine |
2 | 3 | ansible.builtin.group: |
3 | 4 | name: "engine" |
|
20 | 21 | group: root |
21 | 22 | mode: "0755" |
22 | 23 | with_items: |
23 | | - - "{{ current_release_config_dir_name }}" |
24 | | - - "{{ current_release_config_dir_name }}/certs" |
25 | | - - "{{ current_release_config_dir_name }}/configs" |
26 | | - - "{{ current_release_config_dir_name }}/images" |
27 | | - - "{{ current_release_config_dir_name }}/languages" |
| 24 | + - "{{ _engine_config_dir }}" |
| 25 | + - "{{ _engine_config_dir }}/certs" |
| 26 | + - "{{ _engine_config_dir }}/configs" |
| 27 | + - "{{ _engine_config_dir }}/images" |
| 28 | + - "{{ _engine_config_dir }}/languages" |
28 | 29 |
|
29 | 30 | - name: Place parameters.yml |
30 | 31 | ansible.builtin.template: |
31 | | - src: parameters.yml.j2 |
32 | | - dest: "{{ current_release_config_dir_name }}/configs/parameters.yml" |
| 32 | + src: "{{ item }}.j2" |
| 33 | + dest: "{{ _engine_config_dir }}/configs/{{ item }}" |
33 | 34 | mode: "0640" |
34 | | - owner: root |
35 | | - group: engine |
36 | | - notify: restart engine |
| 35 | + owner: "root" |
| 36 | + group: "engine" |
| 37 | + with_items: |
| 38 | + - "parameters.yml" |
| 39 | + - "monolog.yml" |
| 40 | + notify: "Restart engine" |
37 | 41 |
|
38 | 42 | - name: Check presence of environment specific attributes.json |
39 | 43 | ansible.builtin.stat: |
40 | 44 | path: "{{ inventory_dir }}/files/eb/attributes.json" |
41 | | - register: attributes_json_present |
| 45 | + register: engine_attributes_json_present |
42 | 46 | become: false |
43 | 47 | delegate_to: localhost |
44 | 48 |
|
45 | 49 | - name: Copy environment specific attributes.json |
46 | 50 | ansible.builtin.copy: |
47 | 51 | src: "{{ inventory_dir }}/files/eb/attributes.json" |
48 | | - dest: "{{ current_release_config_dir_name }}/configs/" |
| 52 | + dest: "{{ _engine_config_dir }}/configs/" |
49 | 53 | mode: "0644" |
50 | 54 | owner: root |
51 | 55 | group: engine |
52 | | - when: attributes_json_present.stat.exists |
| 56 | + when: engine_attributes_json_present.stat.exists |
53 | 57 |
|
54 | 58 | - name: Check presence of language specific overrides |
55 | 59 | ansible.builtin.stat: |
56 | 60 | path: "{{ inventory_dir }}/files/eb/languages/" |
57 | | - register: overrides_present |
| 61 | + register: engine_overrides_present |
58 | 62 | become: false |
59 | 63 | delegate_to: localhost |
60 | 64 |
|
61 | 65 | - name: Copy language specific overrides |
62 | 66 | ansible.builtin.template: |
63 | 67 | src: "{{ item }}" |
64 | | - dest: "{{ current_release_config_dir_name }}/languages/" |
| 68 | + dest: "{{ _engine_config_dir }}/languages/" |
65 | 69 | owner: root |
66 | 70 | group: engine |
67 | 71 | mode: "0644" |
68 | | - when: overrides_present.stat.exists |
| 72 | + when: engine_overrides_present.stat.exists |
69 | 73 | with_fileglob: |
70 | 74 | - "{{ inventory_dir }}/files/eb/languages/*" |
71 | | - notify: |
72 | | - - "restart engine" |
| 75 | + notify: "Restart engine" |
73 | 76 |
|
74 | 77 | - name: Check if we have a custom logo |
75 | 78 | ansible.builtin.stat: |
76 | 79 | path: "{{ inventory_dir }}/files/logo.png" |
77 | | - register: customlogo |
| 80 | + register: engine_customlogo |
78 | 81 | become: false |
79 | 82 | delegate_to: localhost |
80 | 83 |
|
81 | 84 | - name: Install environment specific logo |
82 | 85 | ansible.builtin.copy: |
83 | 86 | src: "{{ inventory_dir }}/files/logo.png" |
84 | | - dest: "{{ current_release_config_dir_name }}/images/" |
| 87 | + dest: "{{ _engine_config_dir }}/images/" |
85 | 88 | owner: root |
86 | 89 | group: engine |
87 | 90 | mode: "0644" |
88 | | - when: customlogo.stat.exists |
| 91 | + when: engine_customlogo.stat.exists |
89 | 92 |
|
90 | 93 | - name: Check if we have a custom favicon |
91 | 94 | ansible.builtin.stat: |
92 | 95 | path: "{{ inventory_dir }}/files/favicon.ico" |
93 | | - register: customfavicon |
| 96 | + register: engine_customfavicon |
94 | 97 | become: false |
95 | 98 | delegate_to: localhost |
96 | 99 |
|
|
101 | 104 | owner: root |
102 | 105 | group: root |
103 | 106 | mode: "0644" |
104 | | - when: customfavicon.stat.exists |
| 107 | + when: engine_customfavicon.stat.exists |
105 | 108 |
|
106 | 109 | - name: Check if we have a custom background back image for the feedback page |
107 | 110 | ansible.builtin.stat: |
108 | 111 | path: "{{ inventory_dir }}/files/eb/background-back.svg" |
109 | | - register: eb_customfeedbackbackground |
| 112 | + register: engine_customfeedbackbackground |
110 | 113 | become: false |
111 | 114 | delegate_to: localhost |
112 | 115 |
|
113 | 116 | - name: Install environment specific background back image |
114 | 117 | ansible.builtin.copy: |
115 | 118 | src: "{{ inventory_dir }}/files/eb/background-back.svg" |
116 | | - dest: "{{ current_release_config_dir_name }}/images/" |
| 119 | + dest: "{{ _engine_config_dir }}/images/" |
117 | 120 | owner: root |
118 | 121 | group: engine |
119 | 122 | mode: "0644" |
120 | | - when: eb_customfeedbackbackground.stat.exists |
| 123 | + when: engine_customfeedbackbackground.stat.exists |
121 | 124 |
|
122 | 125 | - name: Check if we have a custom background front image for the feedback page |
123 | 126 | ansible.builtin.stat: |
124 | 127 | path: "{{ inventory_dir }}/files/eb/background-front.svg" |
125 | | - register: eb_customfeedbackforeground |
| 128 | + register: engine_customfeedbackforeground |
126 | 129 | become: false |
127 | 130 | delegate_to: localhost |
128 | 131 |
|
129 | 132 | - name: Install environment specific background front image |
130 | 133 | ansible.builtin.copy: |
131 | 134 | src: "{{ inventory_dir }}/files/eb/background-front.svg" |
132 | | - dest: "{{ current_release_config_dir_name }}/images/" |
| 135 | + dest: "{{ _engine_config_dir }}/images/" |
133 | 136 | owner: root |
134 | 137 | group: engine |
135 | 138 | mode: "0644" |
136 | | - when: eb_customfeedbackforeground.stat.exists |
| 139 | + when: engine_customfeedbackforeground.stat.exists |
137 | 140 |
|
138 | 141 | - name: Check if we have a Stepup GW certificate |
139 | 142 | ansible.builtin.stat: |
140 | 143 | path: "{{ inventory_dir }}/files/certs/stepup_gateway.pem" |
141 | | - register: eb_stepupgwcert |
| 144 | + register: engine_stepupgwcert |
142 | 145 | become: false |
143 | 146 | delegate_to: localhost |
144 | 147 |
|
145 | 148 | - name: Install Stepup GW certificate |
146 | 149 | ansible.builtin.copy: |
147 | 150 | src: "{{ inventory_dir }}/files/certs/stepup_gateway.pem" |
148 | | - dest: "{{ current_release_config_dir_name }}/certs/" |
| 151 | + dest: "{{ _engine_config_dir }}/certs/" |
149 | 152 | owner: root |
150 | 153 | group: engine |
151 | 154 | mode: "0644" |
152 | | - when: eb_stepupgwcert.stat.exists |
| 155 | + when: engine_stepupgwcert.stat.exists |
153 | 156 |
|
154 | 157 | - name: Copy over the engineblock keys |
155 | 158 | ansible.builtin.copy: |
156 | 159 | content: "{{ item.private_key }}" |
157 | | - dest: "{{ current_release_config_dir_name }}/certs/{{ item.name }}.key" |
| 160 | + dest: "{{ _engine_config_dir }}/certs/{{ item.name }}.key" |
158 | 161 | owner: root |
159 | 162 | group: engine |
160 | 163 | mode: "0440" |
|
164 | 167 | - name: Copy engineblock certificates to correct location |
165 | 168 | ansible.builtin.copy: |
166 | 169 | src: "{{ inventory_dir }}/files/certs/{{ item.crt_name }}" |
167 | | - dest: "{{ current_release_config_dir_name }}/certs/{{ item.name }}.crt" |
| 170 | + dest: "{{ _engine_config_dir }}/certs/{{ item.name }}.crt" |
168 | 171 | owner: root |
169 | 172 | group: engine |
170 | 173 | mode: "0644" |
|
189 | 192 | image: ghcr.io/openconext/openconext-engineblock/openconext-engineblock:{{ engine_version }} |
190 | 193 | pull: true |
191 | 194 | restart_policy: "always" |
192 | | - networks: "{{ engine_docker_networks}}" |
| 195 | + networks: "{{ engine_docker_networks }}" |
193 | 196 | labels: |
194 | 197 | traefik.http.routers.engine.rule: "Host(`engine.{{ base_domain }}`)" |
195 | 198 | traefik.http.routers.engine.service: "engineblock" |
|
203 | 206 | APACHE_GUID: "#{{ engine_guid.gid }}" |
204 | 207 | TZ: "{{ timezone }}" |
205 | 208 | PHP_MEMORY_LIMIT: "{{ engine_php_memory }}" |
| 209 | + APP_ENV: "prod" |
| 210 | + APP_SECRET: "{{ engine_parameters_secret }}" |
| 211 | + APP_DEBUG: "{{ engine_debug | bool | int }}" |
206 | 212 | etc_hosts: |
207 | 213 | host.docker.internal: host-gateway |
208 | 214 | mounts: |
209 | | - - source: "{{ current_release_config_dir_name }}/configs/parameters.yml" |
210 | | - target: "/var/www/html/app/config/parameters.yml" |
| 215 | + - source: "{{ _engine_config_dir }}/configs/" |
| 216 | + target: "{{ _engine_container_config_dir }}" |
211 | 217 | type: bind |
212 | | - - source: "{{ current_release_config_dir_name }}/languages/overrides.en.php" |
| 218 | + read_only: true |
| 219 | + - source: "{{ _engine_config_dir }}/languages/overrides.en.php" |
213 | 220 | target: "/var/www/html/languages/overrides.en.php" |
214 | 221 | type: bind |
215 | | - - source: "{{ current_release_config_dir_name }}/languages/overrides.nl.php" |
| 222 | + read_only: true |
| 223 | + - source: "{{ _engine_config_dir }}/languages/overrides.nl.php" |
216 | 224 | target: "/var/www/html/languages/overrides.nl.php" |
217 | 225 | type: bind |
218 | | - - source: "{{ current_release_config_dir_name }}/configs/attributes.json" |
219 | | - target: "/var/www/html/app/config/attributes.json" |
| 226 | + read_only: true |
| 227 | + - source: "{{ _engine_config_dir }}/configs/attributes.json" |
| 228 | + target: "{{ _engine_container_config_dir }}/attributes.json" |
220 | 229 | type: bind |
221 | | - - source: "{{ current_release_config_dir_name }}/images/background-back.svg" |
222 | | - target: "/var/www/html/web/images/background-back.svg" |
| 230 | + read_only: true |
| 231 | + - source: "{{ _engine_config_dir }}/images/background-back.svg" |
| 232 | + target: "/var/www/html/public/images/background-back.svg" |
223 | 233 | type: bind |
224 | | - - source: "{{ current_release_config_dir_name }}/images/background-front.svg" |
225 | | - target: "/var/www/html/web/images/background-front.svg" |
| 234 | + read_only: true |
| 235 | + - source: "{{ _engine_config_dir }}/images/background-front.svg" |
| 236 | + target: "/var/www/html/public/images/background-front.svg" |
226 | 237 | type: bind |
227 | | - - source: "{{ current_release_config_dir_name }}/images/logo.png" |
228 | | - target: "/var/www/html/web/images/logo.png" |
| 238 | + read_only: true |
| 239 | + - source: "{{ _engine_config_dir }}/images/logo.png" |
| 240 | + target: "/var/www/html/public/images/logo.png" |
229 | 241 | type: bind |
230 | | - - source: "{{ current_release_config_dir_name }}/certs/" |
| 242 | + read_only: true |
| 243 | + - source: "{{ _engine_config_dir }}/certs/" |
231 | 244 | target: "/var/www/html/certs/" |
232 | 245 | type: bind |
| 246 | + read_only: true |
233 | 247 | - source: "/opt/openconext/common/favicon.ico" |
234 | | - target: "/var/www/html/web/favicon.ico" |
| 248 | + target: "/var/www/html/public/favicon.ico" |
235 | 249 | type: bind |
236 | | - - source: engineblock_sessions |
237 | | - target: /tmp/ |
| 250 | + read_only: true |
| 251 | + - source: "engineblock_sessions" |
| 252 | + target: "/tmp/" |
238 | 253 | type: volume |
239 | | - register: ebcontainer |
| 254 | + healthcheck: |
| 255 | + test: ["CMD-SHELL", "curl --fail -s http://localhost/internal/health | grep -q '\"status\":\"UP\"'"] |
| 256 | + start_period: 60s |
| 257 | + interval: 10s |
| 258 | + timeout: 1s |
| 259 | + retries: 20 |
| 260 | + register: "engine_container" |
0 commit comments