2015-07-15 17:14:39 +07:00
---
- hosts : all
2015-07-15 21:26:27 +07:00
pre_tasks :
2016-03-05 21:46:54 +07:00
- name : INCLUDE | Pre_tasks related to OS version
include : "includes/pre_{{ ansible_distribution }}.yml"
2016-01-21 21:34:18 +07:00
- name : FILE | Create an internal SSL dir
file : path={{ int_ansible_ssl_dir }} state=directory
- name : COPY | Deploy test certificate
copy : src=file/test.crt dest={{ int_ansible_ssl_dir }}/test.crt
- name : COPY | Deploy test key
copy : src=file/test.key dest={{ int_ansible_ssl_dir }}/test.key
2015-07-15 20:18:51 +07:00
vars :
2016-01-21 21:34:18 +07:00
# Internal vars
int_ansible_ssl_dir : '/etc/ansible-ssl'
# Role vars
2016-03-05 21:07:39 +07:00
nginx_worker_processes : 1 # Ansible+FreeBSD can't detect CPU number
2016-01-11 21:16:24 +07:00
nginx_backports : true
2016-08-09 21:02:09 +07:00
nginx_php5 : true
nginx_php7 : true
2015-10-08 23:21:40 +07:00
nginx_upstreams :
- name : 'test'
servers :
2015-10-09 22:54:07 +07:00
- path : '127.0.0.1:80'
2015-10-08 23:21:40 +07:00
max_conns : 150
weight : 10
down : false
2016-05-11 22:21:52 +07:00
- name : 'test-absent'
servers :
- path : '127.0.0.1:80'
max_conns : 150
weight : 10
down : false
state : 'absent'
2015-12-03 22:32:08 +07:00
nginx_htpasswd :
- name : 'hello'
description : 'Please login!'
users :
- name : 'hx'
password : 'asdfg'
state : 'absent'
- name : 'hanx'
password : 'qwerty'
2016-01-21 21:16:21 +07:00
- name : 'nagios'
description : 'Please login to Nagios!'
users :
- name : 'nagiosadmin'
password : 'nagios'
2015-12-03 22:32:08 +07:00
- name : 'deleteme'
description : 'Please login!'
users : [ ]
state : 'absent'
2016-01-12 00:20:42 +07:00
nginx_ssl_pairs :
2016-01-12 23:26:30 +07:00
- name : 'test-ssl-predeployed.local'
2016-01-21 21:34:18 +07:00
dest_key : "{{ int_ansible_ssl_dir }}/test.key"
dest_cert : "{{ int_ansible_ssl_dir }}/test.crt"
2016-01-12 00:20:42 +07:00
- name : 'test-ssl.local'
key : |
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAvavrJWFp3Al2VwRgKx+4Y2mbRRvoxvyd2pyN0xMJ/tCJscaG
8s60v6WZ9FcCOeMkSI2DXsk4z7pbQdQn0h2GDr/5MOJkPAVWSWEN46tpaLZ3v0zp
88ZIbnEk1G0PsdFuW/pnLsakPlAMrl1VArFsV6YsatLt30UIYYcRO97StkoOehCx
A5w+XqtfHZeQZ0/DS81633gwYUcMuSTUFZ60r7ge1/m77DTSKg3rTVk5sebP8cjS
+aWHvxP/GyvvDsT+3gjRJx2/5O3JkfH0zaOsaU2Avj0PR0c5rhynrNO/l1k+GJJB
cbBrM+yA8Ofzp4oXUrCfaIq3RuL3Pd+khcKsiwIDAQABAoIBAQCPpAMQ7BUfbosQ
m1+5SOx7XR8Z12kSSX3CcY12rJSFRakB2TeZ6rE38lIFmV82N67iw0kaH4nGx3sU
/3aoyXMc+IXfX5RJYEFYkQfTw5ywkH9fgQAsfZ2dBlK+DVo1cEYDoj9CTW1VQ4pX
Ape+0l8agd5hiBxdWgpe0ctbbARnx584viLiA/iPBDNxKi9zEYw+WP7hSj5QWahr
a09tubcC4L6tjvv8CoZTRSKfCW64vWRDvE6vmA+zJN9Arc1WTYzF1KO1Gybwf8h7
stJb191smAgGDFhKo0j58ncyAnrS1k4mapm86QQhlfIA6DKvvC0qm3KdQns5b7HM
PyzW0hwBAoGBAO2mTVTOsziom9vtBwM0nRMMEgynR2X3EKMJz2mjcCf66f1F+aQ5
DvQFM2V8S2s1nGnPh8NKKZ8DxW1NKuR4qx82zeAXpUs9ibHxOnw4YRC485zqc2Wt
fSO1OEDYeKyzWP1nGGtCntYUXzJnWn/wz0mBGKzLKTuLwyFIKx1b7bybAoGBAMxR
N +lT57rX6d4GUqcgNOuWMZ/D8egnE5+hsoiFnHOisRLOgUgBBSy4rwAZx+rdHYT+
RO11L1PLYEzyvnO0f13R+N7aqKwNXDSzZGA+jb4pjkVidIC2smG/JYKJH5Z+kakw
mwMKP0wdRZJsCaMgScHmWJS8d6Ox/XJJoWrTWTbRAoGAWJlEgVaiaIArwz1F/QLz
gHNik0cWDkSi9jWlFxwwpycbbypUXM5M7dq2g6JoN6sACk6trbgLdlYgl5RKZm06
VuPGs0H9hOSHXkix5jfasDJT2G9r4D9ixRo9w6cwriobBjYWW3612tgzeYYgrkwn
655uhZUkZSfA8rqGIGbyZfsCgYAf5WH8G+wmIATTc1s92epJCOZwUY+XNVp75itP
4sPczX4lOHW4PuiG5cH0GxI5mRE9rNAn3c5on2xGNvMCbyAfDmNyruH8Eg3d8E9w
MvO/xw79x/P2EA9i8QszCKMUxGeK6RqZ6+SbxkoRJKqQe77n9UTI228179hoGhSH
77ySsQKBgQC8SSZn6a8PpSIIFXB9WCFMwfGFYbUz0wvpaeZP8GKx3BEzMeJqSUaJ
hrQgpwQXkueeamlCQcvV3AUCoBRWTYRLDrWiUIXuIgikDWBFp6TBvTnVRI7iktly
fNED7jXOSjJqnFmdkZlAI5V8dM++mVYVykJD6jcaVRQvxqFLrhSaRg==
-----END RSA PRIVATE KEY-----
cert : |
-----BEGIN CERTIFICATE-----
MIIDBTCCAe2gAwIBAgIJALKJfbk5vuieMA0GCSqGSIb3DQEBBQUAMBkxFzAVBgNV
BAMMDnRlc3Qtc3NsLmxvY2FsMB4XDTE2MDExMTE2NDI0NFoXDTI2MDEwODE2NDI0
NFowGTEXMBUGA1UEAwwOdGVzdC1zc2wubG9jYWwwggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQC9q+slYWncCXZXBGArH7hjaZtFG+jG/J3anI3TEwn+0Imx
xobyzrS/pZn0VwI54yRIjYNeyTjPultB1CfSHYYOv/kw4mQ8BVZJYQ3jq2lotne/
TOnzxkhucSTUbQ+x0W5b+mcuxqQ+UAyuXVUCsWxXpixq0u3fRQhhhxE73tK2Sg56
ELEDnD5eq18dl5BnT8NLzXrfeDBhRwy5JNQVnrSvuB7X+bvsNNIqDetNWTmx5s/x
yNL5pYe/E/8bK+8OxP7eCNEnHb/k7cmR8fTNo6xpTYC+PQ9HRzmuHKes07+XWT4Y
kkFxsGsz7IDw5/OnihdSsJ9oirdG4vc936SFwqyLAgMBAAGjUDBOMB0GA1UdDgQW
BBRaSF1L+ivPhmIVGQjtviBqZWDS9DAfBgNVHSMEGDAWgBRaSF1L+ivPhmIVGQjt
viBqZWDS9DAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQCjrgB9+Zuq
Rx7T2mRUl4jf75dLabuBQD0ePALTtvNyBSghhzSr90mE7GlFOYAv0JsmEa3R1LVF
wLPIdrIhNHpt7hN0PkhUlfgmxBnRSCfhpiq4xxsDVFM7ehtDz4+dv1LUDMXo07+E
f24g9aqmypiFzHisUQrYIhtQmHxRpKyGp6kDAW9qNxg6k/Um00aHdYfuD9ER4ksR
f8Hto7f+vssKxCRY2OZXqq13PxEwC5+hgAUkTdrycA/moXFuHJi3lCnCND7sSzvG
tXBggOusyFZFC4bs2m+V+Z+RN+tK2c/c0nq5HR8MV5HwIm4Z8GoT2/0BfJ00cgWL
lVz0gDBfdH8f
-----END CERTIFICATE-----
2015-12-09 23:06:59 +07:00
nginx_custom_http :
- 'add_header X-ansible 1;'
2016-01-21 23:08:01 +07:00
nginx_default_vhost : 'test.local'
nginx_default_vhost_ssl : 'test-ssl-predeployed.local'
2015-07-15 20:18:51 +07:00
nginx_vhosts :
2015-07-30 18:02:21 +07:00
- name :
- 'test.local'
- 'test-alias.local'
- 'test2-alias.local'
template : '_base'
2016-03-04 22:38:40 +07:00
filename : 'first-test'
2015-10-15 21:21:36 +07:00
override_try_files : '$uri $uri index.htm index.html'
2016-03-15 16:51:14 +07:00
headers :
2016-03-15 21:30:22 +07:00
'X-Frame-Options' : 'deny always'
2016-03-15 16:51:14 +07:00
'X-ansible-default' : '1'
2015-10-19 14:39:51 +07:00
manage_local_content : false
2016-03-05 18:00:07 +07:00
use_error_log : false
2015-09-09 22:44:53 +07:00
more :
2015-09-21 16:47:49 +07:00
- 'autoindex off;'
2015-07-31 05:38:16 +07:00
location :
'/test' :
- 'return 403;'
'/gunther' :
- 'return 404;'
2016-02-09 22:57:13 +07:00
'/status' :
- 'stub_status on;'
- 'access_log off;'
- 'allow 127.0.0.1;'
- 'deny all;'
2015-12-03 22:32:08 +07:00
- name : 'test-htpasswd.local'
template : '_base'
location :
'/hello' :
- htpasswd : 'hello'
- name : 'test-htpasswd-all.local'
template : '_base'
htpasswd : 'hello'
2015-11-03 20:31:50 +07:00
- name : 'test-location.local'
template : '_base'
location :
'/' :
- 'alias /var/tmp;'
2015-10-22 15:25:30 +07:00
- name : 'test-php.local'
2016-08-09 21:02:09 +07:00
php_version : 7
2015-09-21 16:47:49 +07:00
upstream_params :
- 'fastcgi_param FOO bar;'
2015-07-30 20:53:45 +07:00
redirect_from :
- 'www.test-php.local'
2015-07-30 18:02:21 +07:00
template : '_php'
2016-03-05 23:26:05 +07:00
use_error_log : true
use_access_log : true
2015-11-02 22:30:46 +07:00
- name : 'test-php-index.local'
template : '_php_index'
2015-10-22 15:25:30 +07:00
- name : 'test-proxy.local'
2015-10-09 19:31:01 +07:00
listen :
- 8080
2015-10-08 23:21:40 +07:00
template : '_proxy'
upstream_name : 'test'
2016-03-15 23:15:46 +07:00
headers :
'X-proxyfied' : '1'
2015-10-22 15:25:30 +07:00
- name : 'deleted.local'
2015-07-31 06:02:37 +07:00
delete : true
2015-12-01 21:46:57 +07:00
- name : 'redirect-to.local'
redirect_to : 'http://test.local'
2015-12-23 23:37:58 +07:00
- name : 'backuppc.local'
template : '_backuppc'
htpasswd : 'hello'
2016-01-15 21:48:18 +07:00
- name : 'nagios3.local'
template : '_nagios3'
2016-01-21 21:16:21 +07:00
htpasswd : 'nagios'
2016-01-12 00:20:42 +07:00
- name : 'test-ssl.local'
proto : [ 'http' , 'https' ]
template : '_base'
ssl_name : 'test-ssl.local'
2016-01-12 23:26:30 +07:00
- name : 'test-ssl-predeployed.local'
proto : [ 'http' , 'https' ]
template : '_base'
ssl_name : 'test-ssl-predeployed.local'
2016-03-15 23:15:46 +07:00
headers :
'X-ansible-default' : '1'
2016-03-15 18:16:57 +07:00
ssl_template : false
2016-03-15 01:20:08 +07:00
- name : 'test-ssl-redirect.local'
proto : [ 'https' ]
template : '_base'
ssl_name : 'test-ssl.local'
redirect_https : true
2016-01-22 16:06:35 +07:00
nginx_dh_length : 1024
2015-07-15 17:14:39 +07:00
roles :
- ../../
2015-07-15 22:24:50 +07:00
post_tasks :
2016-01-21 21:34:18 +07:00
# --------------------------------
# Apps
# --------------------------------
2016-03-05 21:46:54 +07:00
- name : INCLUDE | Post_tasks related to OS version
include : "includes/post_{{ ansible_distribution }}.yml"
2016-01-21 21:34:18 +07:00
# --------------------------------
# Deploy index files
# --------------------------------
2015-07-16 21:24:44 +07:00
- name : -- Add PHP file --
2015-11-02 22:30:46 +07:00
copy : dest="{{ nginx_root }}/{{ item }}/public/index.php" content="<?php phpinfo();"
with_items : [ 'test-php.local' , 'test-php-index.local' ]
2015-07-16 21:24:44 +07:00
- name : -- Add HTML file --
2015-11-03 20:31:50 +07:00
copy : dest="{{ item }}/index.html" content="Index HTML test OK\n"
2016-01-12 23:26:30 +07:00
with_items : [ '{{ nginx_root }}/test.local/public' , '/var/tmp' , '{{ nginx_root }}/test-htpasswd-all.local/public' , '{{ nginx_root }}/test-ssl.local/public' , '{{ nginx_root }}/test-ssl-predeployed.local/public' ]
2016-03-05 21:36:25 +07:00
- name : -- Create directory --
2016-03-05 23:31:21 +07:00
file : path={{ nginx_root }}/test-htpasswd.local/public/hello state=directory
2016-03-05 21:36:25 +07:00
- name : -- Add HTML file hello --
2016-03-05 23:31:21 +07:00
copy : dest="{{ nginx_root }}/test-htpasswd.local/public/hello/index.html" content="hello\n"
2016-01-21 21:34:18 +07:00
# --------------------------------
# Simple vhosts tests
# --------------------------------
2015-07-15 22:24:50 +07:00
- name : -- VERIFY VHOSTS --
2015-11-02 23:44:09 +07:00
command : "curl -H 'Host: {{ item.name if item.name is string else item.name[0] }}' http://127.0.0.1{% if item.listen is defined %}:{{ item.listen[0] }}{% endif %}/"
2016-03-05 17:37:37 +07:00
with_items : "{{ nginx_vhosts }}"
2015-08-04 17:40:04 +07:00
when : item.delete is undefined or not item.delete
2015-07-15 22:24:50 +07:00
changed_when : false
2015-11-02 22:30:46 +07:00
- name : -- VERIFY FORBIDDEN --
command : "curl -H 'Host: test-php-index.local' http://127.0.0.1/phpinfo.php"
register : f
failed_when : f.stdout.find('403 Forbidden') == -1
changed_when : false
2015-08-04 17:26:38 +07:00
- name : -- VERIFY REDIRECT VHOSTS --
2015-11-02 23:44:09 +07:00
command : "curl -H 'Host: {{ item.redirect_from[0] }}' http://127.0.0.1/"
2016-03-05 17:37:37 +07:00
with_items : "{{ nginx_vhosts }}"
2015-08-04 17:40:04 +07:00
when : item.redirect_from is defined and (item.delete is undefined or not item.delete)
2015-08-04 17:26:38 +07:00
changed_when : false
2015-11-02 22:30:46 +07:00
register : r
failed_when : r.stdout.find('301 Moved Permanently') == -1
2016-01-21 21:34:18 +07:00
2016-01-21 23:54:24 +07:00
# --------------------------------
# PHP
# --------------------------------
- name : -- VERIFY PHP VHOSTS --
command : "curl -H 'Host: {{ item }}' http://127.0.0.1/"
register : p
changed_when : false
failed_when : p.stdout.find('PHP Version') == -1
with_items : [ 'test-php.local' , 'test-php-index.local' ]
2016-08-09 21:02:09 +07:00
- name : -- VERIFY PHP5 VHOSTS (implicit default) --
command : "curl -H 'Host: {{ item }}' http://127.0.0.1/"
register : p
changed_when : false
failed_when : p.stdout.find('PHP Version 5') == -1
with_items : [ 'test-php-index.local' ]
- name : -- VERIFY PHP7 VHOSTS --
command : "curl -H 'Host: {{ item }}' http://127.0.0.1/"
register : p
changed_when : false
failed_when : p.stdout.find('PHP Version 7') == -1
with_items : [ 'test-php.local' ]
2016-01-21 21:34:18 +07:00
# --------------------------------
# Basic Auth
# --------------------------------
2015-12-03 22:32:08 +07:00
- name : -- VERIFY AUTH BASIC NONE --
2016-03-05 23:31:21 +07:00
command : "curl -H 'Host: test-htpasswd.local' http://127.0.0.1/hello/"
2015-12-03 22:32:08 +07:00
changed_when : false
register : authnone
failed_when : authnone.stdout.find('401 Authorization Required') == -1
- name : -- VERIFY AUTH BASIC FAIL --
2016-03-05 23:31:21 +07:00
command : "curl -u fail:fail -H 'Host: test-htpasswd.local' http://127.0.0.1/hello/"
2015-12-03 22:32:08 +07:00
changed_when : false
register : authfail
failed_when : authfail.stdout.find('401 Authorization Required') == -1
- name : -- VERIFY AUTH BASIC OK --
2016-03-05 23:31:21 +07:00
command : "curl -u hanx:qwerty -H 'Host: test-htpasswd.local' http://127.0.0.1/hello/"
2015-12-03 22:32:08 +07:00
changed_when : false
register : authok
failed_when : authok.stdout.find('hello') == -1
2015-12-03 23:09:29 +07:00
- name : -- VERIFY AUTH BASIC FAIL GLOBAL --
command : "curl -u fail:fail -H 'Host: test-htpasswd-all.local' http://127.0.0.1/"
changed_when : false
register : authgfail
failed_when : authgfail.stdout.find('401 Authorization Required') == -1
- name : -- VERIFY AUTH BASIC OK --
command : "curl -u hanx:qwerty -H 'Host: test-htpasswd-all.local' http://127.0.0.1/"
changed_when : false
register : authgok
failed_when : authgok.stdout.find('401 Authorization Required') != -1
2016-01-21 21:34:18 +07:00
# --------------------------------
# BackupPC
# --------------------------------
2015-12-23 23:37:58 +07:00
- name : -- VERIFY BACKUPPC --
command : "curl -u hanx:qwerty -H 'Host: backuppc.local' http://127.0.0.1/"
changed_when : false
register : authbpc
failed_when : authbpc.stdout.find('BackupPC Server Status') == -1
2016-03-06 00:34:04 +07:00
when : ansible_distribution != 'FreeBSD'
2016-01-21 21:16:21 +07:00
# --------------------------------
# Nagios
# --------------------------------
2016-01-15 21:48:18 +07:00
- name : -- VERIFY NAGIOS3 PHP --
2016-01-21 21:16:21 +07:00
command : "curl -u nagiosadmin:nagios -H 'Host: nagios3.local' http://127.0.0.1/side.php"
2016-01-15 21:48:18 +07:00
changed_when : false
2016-01-21 21:16:21 +07:00
register : nagios_php
failed_when : nagios_php.stdout.find('Nagios Core') == -1
2016-01-15 21:48:18 +07:00
- name : -- VERIFY NAGIOS3 CGI --
2016-03-06 00:34:04 +07:00
command : "curl -u nagiosadmin:nagios -H 'Host: nagios3.local' http://127.0.0.1/cgi-bin{% if ansible_distribution == 'Debian' %}/nagios3{% endif %}/summary.cgi"
2016-01-15 21:48:18 +07:00
changed_when : false
2016-01-21 21:16:21 +07:00
register : nagios_cgi
failed_when : nagios_cgi.stdout.find('Nagios Event Summary') == -1
2016-01-21 23:08:01 +07:00
# --------------------------------
# SSL
# --------------------------------
2016-01-12 00:20:42 +07:00
- name : -- VERIFY SSL --
2016-01-12 23:26:30 +07:00
command : "curl --insecure -H 'Host: {{ item }}' https://127.0.0.1/"
2016-01-12 00:20:42 +07:00
changed_when : false
2016-01-21 21:34:18 +07:00
register : sslok
failed_when : sslok.stdout.find('Index HTML test OK') == -1
2016-01-12 23:26:30 +07:00
with_items :
- 'test-ssl-predeployed.local'
- 'test-ssl.local'
2016-03-15 01:20:08 +07:00
- name : -- VERIFY SSL REDIRECT --
command : "curl -v --insecure -H 'Host: {{ item }}' http://127.0.0.1/"
changed_when : false
register : sslredirok
failed_when : >
sslredirok.stderr.find('< Location') == -1 and
sslredirok.stderr.find('https://{{ item }}/') == -1
with_items :
- 'test-ssl-redirect.local'
2016-01-12 00:20:42 +07:00
2016-01-21 23:08:01 +07:00
# --------------------------------
# Default vhosts
# --------------------------------
- name : -- VERIFY DEFAULT VHOST --
command : "curl -v http://127.0.0.1/"
changed_when : false
register : vdefault
failed_when : >
vdefault.stdout.find('Index HTML test OK') == -1 or
vdefault.stderr.find('X-ansible-default') == -1
- name : -- VERIFY DEFAULT SSL VHOST --
command : "curl --insecure -v https://127.0.0.1/"
changed_when : false
register : defaultssl
failed_when : >
defaultssl.stdout.find('Index HTML test OK') == -1 or
defaultssl.stderr.find('X-ansible-default') == -1
- name : -- VERIFY NOT DEFAULT VHOST --
command : "curl -v -H 'Host: test-php.local' http://127.0.0.1/"
changed_when : false
register : vphp
failed_when : vphp.stderr.find('X-ansible-default') != -1
- name : -- VERIFY NOT DEFAULT SSL VHOST --
command : "curl --insecure -v -H 'Host: test-ssl.local' https://127.0.0.1/"
changed_when : false
register : notdefaultssl
failed_when : notdefaultssl.stderr.find('X-ansible-default') != -1
2016-02-09 22:57:13 +07:00
- name : -- VERIFY DEFAULT VHOST + STUB_STATUS --
command : "curl -v http://127.0.0.1/status"
changed_when : false
register : vdefault_status
failed_when : >
vdefault_status.stderr.find('X-ansible-default') == -1 or
vdefault_status.stdout.find('Active connections') == -1
2016-03-05 17:29:37 +07:00
# --------------------------------
# Check HTTP2
# --------------------------------
2016-03-09 01:37:39 +07:00
- name : SHELL | Check HTTP2
shell : nghttp -nv https://localhost 2> /dev/null | grep -q h2
args :
executable : /bin/sh
changed_when : false
when : nginx_auto_config_httpv2 and 'http_v2' in nginx_modules