Compare commits
No commits in common. "master" and "2.6.1" have entirely different histories.
|
@ -0,0 +1,8 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
# TODO: enable later
|
||||||
|
enable_list:
|
||||||
|
- fqcn-builtins
|
||||||
|
|
||||||
|
skip_list:
|
||||||
|
- role-name
|
|
@ -1,12 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
profile: production
|
|
||||||
|
|
||||||
warn_list: []
|
|
||||||
|
|
||||||
skip_list: []
|
|
||||||
|
|
||||||
exclude_paths:
|
|
||||||
- .github/
|
|
||||||
- .venv/
|
|
||||||
- venv/
|
|
|
@ -1,17 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
name: Deploy on Ansible Galaxy
|
|
||||||
|
|
||||||
'on':
|
|
||||||
- push
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: checkout
|
|
||||||
uses: actions/checkout@v2
|
|
||||||
- name: galaxy
|
|
||||||
uses: robertdebock/galaxy-action@1.2.0
|
|
||||||
with:
|
|
||||||
galaxy_api_key: ${{ secrets.galaxy_api_key }}
|
|
|
@ -1,39 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
name: ci
|
|
||||||
'on':
|
|
||||||
pull_request:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
|
|
||||||
yaml-lint:
|
|
||||||
name: YAML Lint
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
|
|
||||||
- name: Fetch code
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
|
|
||||||
- name: Set up Python 3.
|
|
||||||
uses: actions/setup-python@v2
|
|
||||||
with:
|
|
||||||
python-version: '3.x'
|
|
||||||
|
|
||||||
- name: Install test dependencies.
|
|
||||||
run: pip3 install yamllint
|
|
||||||
|
|
||||||
- name: Lint code.
|
|
||||||
run: |
|
|
||||||
yamllint .
|
|
||||||
|
|
||||||
ansible-lint:
|
|
||||||
name: Ansible Lint
|
|
||||||
runs-on: ubuntu-24.04
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Run ansible-lint
|
|
||||||
uses: ansible/ansible-lint@main
|
|
|
@ -1,43 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
name: Molecule
|
|
||||||
|
|
||||||
'on':
|
|
||||||
pull_request:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
scenario:
|
|
||||||
- debian-11
|
|
||||||
- debian-12
|
|
||||||
- ubuntu-20.04
|
|
||||||
- ubuntu-22.04
|
|
||||||
- ubuntu-24.04
|
|
||||||
allowed-to-fail:
|
|
||||||
- false
|
|
||||||
include:
|
|
||||||
- scenario: debian-13
|
|
||||||
allowed-to-fail: true
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@v3
|
|
||||||
with:
|
|
||||||
path: "${{ github.repository }}"
|
|
||||||
|
|
||||||
- name: Molecule
|
|
||||||
uses: gofrolist/molecule-action@v2.7.62
|
|
||||||
with:
|
|
||||||
molecule_options: --base-config molecule/_shared/base.yml
|
|
||||||
molecule_args: --scenario-name ${{ matrix.scenario }}
|
|
||||||
continue-on-error: ${{ matrix.allowed-to-fail }}
|
|
||||||
|
|
||||||
- name: Fake command
|
|
||||||
run: echo "End of job"
|
|
|
@ -1,9 +1,6 @@
|
||||||
|
.vagrant*
|
||||||
*.swp
|
*.swp
|
||||||
*.retry
|
*.retry
|
||||||
*.log
|
*.log
|
||||||
/filter_plugins/*.pyc
|
/filter_plugins/*.pyc
|
||||||
/filter_plugins/__pycache__
|
/filter_plugins/__pycache__
|
||||||
/.idea
|
|
||||||
/.venv
|
|
||||||
/venv
|
|
||||||
/.ansible
|
|
||||||
|
|
|
@ -0,0 +1,55 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
env:
|
||||||
|
global:
|
||||||
|
- VAGRANT_VERSION='2.2.18'
|
||||||
|
jobs:
|
||||||
|
- PLATFORM='docker-debian-stretch-php70' ANSIBLE_VERSION='>=2.11,<2.12'
|
||||||
|
- PLATFORM='docker-debian-stretch-php74' ANSIBLE_VERSION='>=2.11,<2.12'
|
||||||
|
- PLATFORM='docker-debian-buster-php73' ANSIBLE_VERSION='>=2.11,<2.12'
|
||||||
|
- PLATFORM='docker-debian-bullseye-php74' ANSIBLE_VERSION='>=2.11,<2.12'
|
||||||
|
- PLATFORM='docker-debian-bullseye-php80' ANSIBLE_VERSION='>=2.11,<2.12'
|
||||||
|
- PLATFORM='docker-debian-buster-php74' ANSIBLE_VERSION='>=2.11,<2.12'
|
||||||
|
- PLATFORM='docker-ubuntu-bionic-php72' ANSIBLE_VERSION='>=2.11,<2.12'
|
||||||
|
|
||||||
|
os:
|
||||||
|
- linux
|
||||||
|
dist: focal
|
||||||
|
|
||||||
|
language: python
|
||||||
|
python:
|
||||||
|
- 3.8
|
||||||
|
|
||||||
|
services:
|
||||||
|
- docker
|
||||||
|
|
||||||
|
before_install:
|
||||||
|
- sudo apt-get -q update
|
||||||
|
- sudo apt-get install -y yamllint
|
||||||
|
- sudo wget -nv https://releases.hashicorp.com/vagrant/${VAGRANT_VERSION}/vagrant_${VAGRANT_VERSION}_x86_64.deb
|
||||||
|
- sudo dpkg -i vagrant_${VAGRANT_VERSION}_x86_64.deb
|
||||||
|
|
||||||
|
install:
|
||||||
|
- sudo pip install "ansible-core$ANSIBLE_VERSION"
|
||||||
|
- sudo pip install ansible-lint
|
||||||
|
- ansible-galaxy collection install community.general
|
||||||
|
|
||||||
|
script:
|
||||||
|
- VAGRANT_DEFAULT_PROVIDER=docker vagrant up $PLATFORM
|
||||||
|
- >
|
||||||
|
VAGRANT_DEFAULT_PROVIDER=docker vagrant provision $PLATFORM
|
||||||
|
| grep -q 'changed=0.*failed=0'
|
||||||
|
&& (echo 'Idempotence test: pass' && exit 0)
|
||||||
|
|| (echo 'Idempotence test: fail' && exit 1)
|
||||||
|
- VAGRANT_DEFAULT_PROVIDER=docker vagrant status
|
||||||
|
- >
|
||||||
|
yamllint .
|
||||||
|
&& (echo 'YAML lint test: pass' && exit 0)
|
||||||
|
|| (echo 'YAML lint test: fail' && exit 1)
|
||||||
|
- >
|
||||||
|
ansible-lint -v tests/test.yml
|
||||||
|
&& (echo 'Ansible lint test: pass' && exit 0)
|
||||||
|
|| (echo 'Ansible lint test: fail' && exit 1)
|
||||||
|
|
||||||
|
notifications:
|
||||||
|
webhooks: https://galaxy.ansible.com/api/v1/notifications/
|
|
@ -4,5 +4,3 @@ extends: default
|
||||||
|
|
||||||
rules:
|
rules:
|
||||||
line-length: disable
|
line-length: disable
|
||||||
|
|
||||||
ignore-from-file: .gitignore
|
|
||||||
|
|
47
README.md
47
README.md
|
@ -1,14 +1,22 @@
|
||||||
Ansible PHP (+FPM) role for Debian / Ubuntu
|
Ansible PHP (+FPM) role for Debian / Ubuntu / FreeBSD
|
||||||
===========================================
|
=====================================================
|
||||||
|
|
||||||
[](https://galaxy.ansible.com/hanxhx.php) 
|
[](https://galaxy.ansible.com/HanXHX/php) [](https://app.travis-ci.com/HanXHX/ansible-php)
|
||||||
|
|
||||||
Install PHP on Debian / Ubuntu. Manage PHP-FPM, APCu, Opcache and Xdebug.
|
Install PHP on Debian / Ubuntu / FreeBSD. Manage PHP-FPM, APCu, Opcache and Xdebug.
|
||||||
|
|
||||||
Managed OS / Versions
|
Managed OS / Versions
|
||||||
---------------------
|
---------------------
|
||||||
|
|
||||||
On all Debian versions, you can install all PHP versions (from PHP 5.6 to latest version) by using [Sury's APT repository](https://deb.sury.org/).
|
On all Debian versions, you can install all PHP versions (from PHP 5.6 to 8.1 beta) by using [Sury's APT repository](https://deb.sury.org/).
|
||||||
|
|
||||||
|
Other cases:
|
||||||
|
|
||||||
|
| OS | PHP 7.0 | PHP 7.1 | PHP 7.2 | PHP 7.3 | PHP >= 7.4 |
|
||||||
|
|:---------------------:|:-------------------:|:--------------------:|:--------------------:|:--------------------:|:--------------------:
|
||||||
|
| Ubuntu Bionic (18.04) | :x: | :x: | :heavy_check_mark: | :x: | :x: |
|
||||||
|
| FreeBSD 11 | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | Need tests... |
|
||||||
|
| FreeBSD 12 | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | Need tests... |
|
||||||
|
|
||||||
Links:
|
Links:
|
||||||
- [Sury](https://deb.sury.org/)
|
- [Sury](https://deb.sury.org/)
|
||||||
|
@ -20,6 +28,13 @@ Requirements
|
||||||
- Collections: [community.general](https://galaxy.ansible.com/community/general)
|
- Collections: [community.general](https://galaxy.ansible.com/community/general)
|
||||||
- If you need PHP-FPM, you must install a webserver with FastCGI support. You can use my [nginx role](https://github.com/HanXHX/ansible-nginx).
|
- If you need PHP-FPM, you must install a webserver with FastCGI support. You can use my [nginx role](https://github.com/HanXHX/ansible-nginx).
|
||||||
|
|
||||||
|
FreeBSD limitations
|
||||||
|
-------------------
|
||||||
|
|
||||||
|
- It doesn't split ini file for FPM/CLI. It's hardcoded as `/usr/local/etc/php.ini`.
|
||||||
|
- It can't manage multiple PHP versions at the time (like legacy Debian versions)
|
||||||
|
- You must explicitely set xdebug package name (use `pkg search xdebug` to find the good one)
|
||||||
|
|
||||||
Role Variables
|
Role Variables
|
||||||
--------------
|
--------------
|
||||||
|
|
||||||
|
@ -27,7 +42,7 @@ You should look at [default vars](defaults/main.yml).
|
||||||
|
|
||||||
### Writable vars
|
### Writable vars
|
||||||
|
|
||||||
- `php_version`: 7.3, 7.4... depending on OS
|
- `php_version`: 7.3, 7.4... depending OS (see above)
|
||||||
- `php_install_fpm`: boolean, install and manage php-fpm (default is true)
|
- `php_install_fpm`: boolean, install and manage php-fpm (default is true)
|
||||||
- `php_install_xdebug`: boolean, install [Xdebug](http://xdebug.org)
|
- `php_install_xdebug`: boolean, install [Xdebug](http://xdebug.org)
|
||||||
- `php_extra_packages`: additional php packages to install (default is an empty list).
|
- `php_extra_packages`: additional php packages to install (default is an empty list).
|
||||||
|
@ -144,20 +159,16 @@ Example Playbook
|
||||||
|
|
||||||
### Simple Playbook
|
### Simple Playbook
|
||||||
|
|
||||||
```yaml
|
- hosts: servers
|
||||||
- hosts: servers
|
roles:
|
||||||
roles:
|
- { role: HanXHX.php }
|
||||||
- { role: HanXHX.php }
|
|
||||||
```
|
|
||||||
|
|
||||||
### Debian Bullseye with PHP 8.0 CLI (no FPM)
|
### Debian Bullseye with PHP 8.0 CLI (no FPM)
|
||||||
|
|
||||||
```yaml
|
- hosts: servers
|
||||||
- hosts: servers
|
roles:
|
||||||
roles:
|
- { role: HanXHX.sury }
|
||||||
- { role: HanXHX.sury }
|
- { role: HanXHX.php, php_version: '8.0', php_install_fpm: false }
|
||||||
- { role: HanXHX.php, php_version: '8.0', php_install_fpm: false }
|
|
||||||
```
|
|
||||||
|
|
||||||
License
|
License
|
||||||
-------
|
-------
|
||||||
|
@ -174,7 +185,7 @@ If this code helped you, or if you’ve used them for your projects, feel free t
|
||||||
- Litecoin: `LeNDw34zQLX84VvhCGADNvHMEgb5QyFXyD`
|
- Litecoin: `LeNDw34zQLX84VvhCGADNvHMEgb5QyFXyD`
|
||||||
- Monero: `45wbf7VdQAZS5EWUrPhen7Wo4hy7Pa7c7ZBdaWQSRowtd3CZ5vpVw5nTPphTuqVQrnYZC72FXDYyfP31uJmfSQ6qRXFy3bQ`
|
- Monero: `45wbf7VdQAZS5EWUrPhen7Wo4hy7Pa7c7ZBdaWQSRowtd3CZ5vpVw5nTPphTuqVQrnYZC72FXDYyfP31uJmfSQ6qRXFy3bQ`
|
||||||
|
|
||||||
No cryptocurrency? :star: the project is also a way of saying thank you! :sunglasses:
|
No crypto-currency? :star: the project is also a way of saying thank you! :sunglasses:
|
||||||
|
|
||||||
Author Information
|
Author Information
|
||||||
------------------
|
------------------
|
||||||
|
|
|
@ -0,0 +1,91 @@
|
||||||
|
# -*- mode: ruby -*-
|
||||||
|
# vi: set ft=ruby :
|
||||||
|
# vi: set tabstop=2 :
|
||||||
|
# vi: set shiftwidth=2 :
|
||||||
|
|
||||||
|
Vagrant.configure("2") do |config|
|
||||||
|
|
||||||
|
vms_debian = [
|
||||||
|
{ :name => "debian-stretch-php70", :box => "debian/stretch64", :vars => { }},
|
||||||
|
{ :name => "debian-stretch-php74", :box => "debian/stretch64", :vars => { "php_version": '7.4' }},
|
||||||
|
{ :name => "debian-buster-php73", :box => "debian/buster64", :vars => { }},
|
||||||
|
{ :name => "debian-buster-php74", :box => "debian/buster64", :vars => { "php_version": '7.4' }},
|
||||||
|
{ :name => "debian-bullseye-php74", :box => "debian/bullseye64", :vars => { }},
|
||||||
|
{ :name => "debian-bullseye-php80", :box => "debian/bullseye64", :vars => { "php_version": '8.0' }},
|
||||||
|
{ :name => "ubuntu-bionic-php72", :box => "ubuntu/bionic64", :vars => { }},
|
||||||
|
]
|
||||||
|
|
||||||
|
vms_freebsd = [
|
||||||
|
{ :name => "freebsd-11", :box => "freebsd/FreeBSD-11.1-STABLE", :vars => {} },
|
||||||
|
{ :name => "freebsd-12", :box => "freebsd/FreeBSD-12.0-CURRENT", :vars => {} }
|
||||||
|
]
|
||||||
|
|
||||||
|
conts = [
|
||||||
|
{ :name => "docker-debian-stretch-php70", :docker => "hanxhx/vagrant-ansible:debian9", :vars => { }},
|
||||||
|
{ :name => "docker-debian-stretch-php74", :docker => "hanxhx/vagrant-ansible:debian9", :vars => { "php_version": '7.4' }},
|
||||||
|
{ :name => "docker-debian-buster-php73", :docker => "hanxhx/vagrant-ansible:debian10", :vars => { }},
|
||||||
|
{ :name => "docker-debian-buster-php74", :docker => "hanxhx/vagrant-ansible:debian10", :vars => { "php_version": '7.4' }},
|
||||||
|
{ :name => "docker-debian-bullseye-php74", :docker => "hanxhx/vagrant-ansible:debian11", :vars => { }},
|
||||||
|
{ :name => "docker-debian-bullseye-php80", :docker => "hanxhx/vagrant-ansible:debian11", :vars => { "php_version": '8.0' }},
|
||||||
|
{ :name => "docker-ubuntu-bionic-php72", :docker => "hanxhx/vagrant-ansible:ubuntu18.04", :vars => { }},
|
||||||
|
]
|
||||||
|
|
||||||
|
config.vm.network "private_network", type: "dhcp"
|
||||||
|
|
||||||
|
conts.each do |opts|
|
||||||
|
config.vm.define opts[:name] do |m|
|
||||||
|
m.vm.provider "docker" do |d|
|
||||||
|
d.image = opts[:docker]
|
||||||
|
d.remains_running = true
|
||||||
|
d.has_ssh = true
|
||||||
|
end
|
||||||
|
|
||||||
|
#m.vm.provision "shell", inline: "apt-get update && apt-get install -y python python-apt"
|
||||||
|
m.vm.provision "ansible" do |ansible|
|
||||||
|
ansible.playbook = "tests/test.yml"
|
||||||
|
ansible.verbose = 'vv'
|
||||||
|
ansible.become = true
|
||||||
|
ansible.extra_vars = opts[:vars]
|
||||||
|
end
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
vms_debian.each do |opts|
|
||||||
|
config.vm.define opts[:name] do |m|
|
||||||
|
m.vm.box = opts[:box]
|
||||||
|
m.vm.provider "virtualbox" do |v|
|
||||||
|
v.cpus = 1
|
||||||
|
v.memory = 256
|
||||||
|
end
|
||||||
|
m.vm.provision "shell", inline: "apt-get update && apt-get install -y ifupdown python"
|
||||||
|
|
||||||
|
m.vm.provision "ansible" do |ansible|
|
||||||
|
ansible.playbook = "tests/test.yml"
|
||||||
|
ansible.verbose = 'vv'
|
||||||
|
ansible.become = true
|
||||||
|
ansible.extra_vars = opts[:vars]
|
||||||
|
end
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
vms_freebsd.each do |opts|
|
||||||
|
config.vm.synced_folder ".", "/vagrant", disabled: true
|
||||||
|
config.vm.base_mac = "080027D14C66"
|
||||||
|
config.vm.define opts[:name] do |m|
|
||||||
|
m.vm.box = opts[:box]
|
||||||
|
m.vm.provider "virtualbox" do |v, override|
|
||||||
|
override.ssh.shell = "csh"
|
||||||
|
v.cpus = 2
|
||||||
|
v.memory = 512
|
||||||
|
end
|
||||||
|
m.vm.provision "shell", inline: "pkg install -y python bash"
|
||||||
|
m.vm.provision "ansible" do |ansible|
|
||||||
|
ansible.playbook = "tests/test.yml"
|
||||||
|
ansible.verbose = 'vv'
|
||||||
|
ansible.become = true
|
||||||
|
ansible.extra_vars = opts[:vars].merge({ "ansible_python_interpreter": '/usr/local/bin/python' })
|
||||||
|
end
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
end
|
|
@ -1,7 +1,14 @@
|
||||||
---
|
---
|
||||||
|
|
||||||
- name: Restart php-fpm
|
- name: restart php-fpm
|
||||||
ansible.builtin.service:
|
ansible.builtin.service:
|
||||||
name: '{{ php_fpm_service }}'
|
name: '{{ php_fpm_service }}'
|
||||||
state: restarted
|
state: restarted
|
||||||
when: php_install_fpm
|
when: php_install_fpm
|
||||||
|
notify: docker restart php-fpm
|
||||||
|
|
||||||
|
- name: docker restart php-fpm
|
||||||
|
ansible.builtin.command: 'service {{ php_fpm_service }} restart'
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
when: ansible_virtualization_type == 'docker'
|
||||||
|
|
|
@ -1,6 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
argument_specs:
|
|
||||||
main:
|
|
||||||
short_description: Main entry point
|
|
||||||
options: {}
|
|
|
@ -1,23 +1,24 @@
|
||||||
---
|
---
|
||||||
galaxy_info:
|
galaxy_info:
|
||||||
author: Emilien Mantel
|
author: Emilien Mantel
|
||||||
namespace: HanXHX
|
description: Install and configure PHP 7.0/7.1/7.2/7.3/7.4/8.0
|
||||||
role_name: php
|
company:
|
||||||
description: Install and configure PHP 7.x/8.x
|
|
||||||
company: TripleStack
|
|
||||||
license: GPLv2
|
license: GPLv2
|
||||||
min_ansible_version: "2.18"
|
min_ansible_version: 2.11
|
||||||
platforms:
|
platforms:
|
||||||
- name: Debian
|
- name: Debian
|
||||||
versions:
|
versions:
|
||||||
|
- stretch
|
||||||
|
- buster
|
||||||
- bullseye
|
- bullseye
|
||||||
- bookworm
|
|
||||||
- trixie
|
|
||||||
- name: Ubuntu
|
- name: Ubuntu
|
||||||
versions:
|
versions:
|
||||||
- focal
|
- bionic
|
||||||
- jammy
|
- name: FreeBSD
|
||||||
- noble
|
versions:
|
||||||
|
- 11.0
|
||||||
|
- 11.1
|
||||||
|
- 12.0
|
||||||
galaxy_tags:
|
galaxy_tags:
|
||||||
- development
|
- development
|
||||||
- web
|
- web
|
||||||
|
@ -27,4 +28,5 @@ galaxy_info:
|
||||||
- php8
|
- php8
|
||||||
- debian
|
- debian
|
||||||
- ubuntu
|
- ubuntu
|
||||||
|
- freebsd
|
||||||
dependencies: []
|
dependencies: []
|
||||||
|
|
|
@ -1,19 +0,0 @@
|
||||||
# Molecule managed
|
|
||||||
|
|
||||||
{% if item.registry is defined %}
|
|
||||||
FROM {{ item.registry.url }}/{{ item.image }}
|
|
||||||
{% else %}
|
|
||||||
FROM {{ item.image }}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
{% if item.env is defined %}
|
|
||||||
{% for var, value in item.env.items() %}
|
|
||||||
{% if value %}
|
|
||||||
ENV {{ var }} {{ value }}
|
|
||||||
{% endif %}
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
RUN apt-get update && \
|
|
||||||
apt-get install -y python3 sudo bash ca-certificates iproute2 python-apt-common \
|
|
||||||
&& apt-get clean
|
|
|
@ -1,42 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
scenario:
|
|
||||||
test_sequence:
|
|
||||||
- dependency
|
|
||||||
- syntax
|
|
||||||
- create
|
|
||||||
- prepare
|
|
||||||
- converge
|
|
||||||
- idempotence
|
|
||||||
- verify
|
|
||||||
- destroy
|
|
||||||
dependency:
|
|
||||||
name: galaxy
|
|
||||||
options:
|
|
||||||
requirements-file: ./molecule/_shared/requirements.yml
|
|
||||||
role-file: ./molecule/_shared/requirements.yml
|
|
||||||
driver:
|
|
||||||
name: docker
|
|
||||||
role_name_check: 1
|
|
||||||
provisioner:
|
|
||||||
name: ansible
|
|
||||||
env:
|
|
||||||
ANSIBLE_FILTER_PLUGINS: "../../filter_plugins"
|
|
||||||
config_options:
|
|
||||||
defaults:
|
|
||||||
deprecation_warnings: false
|
|
||||||
callback_whitelist: timer,profile_tasks
|
|
||||||
fact_caching: jsonfile
|
|
||||||
fact_caching_connection: ./cache
|
|
||||||
forks: 100
|
|
||||||
connection:
|
|
||||||
pipelining: true
|
|
||||||
playbooks:
|
|
||||||
converge: ../_shared/converge.yml
|
|
||||||
prepare: ../_shared/prepare.yml
|
|
||||||
verify: ../_shared/verify.yml
|
|
||||||
inventory:
|
|
||||||
links:
|
|
||||||
group_vars: ../_shared/group_vars
|
|
||||||
verifier:
|
|
||||||
name: ansible
|
|
|
@ -1,41 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
- name: Converge # noqa: role-name[path]
|
|
||||||
hosts: all
|
|
||||||
gather_facts: true
|
|
||||||
roles:
|
|
||||||
- ../../../
|
|
||||||
handlers:
|
|
||||||
- name: Reload nginx
|
|
||||||
ansible.builtin.service:
|
|
||||||
name: nginx
|
|
||||||
state: reloaded
|
|
||||||
vars:
|
|
||||||
__nginx_conf: /etc/nginx/nginx.conf
|
|
||||||
post_tasks:
|
|
||||||
- name: TEMPLATE | Nginx site config
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: "templates/nginx.conf.j2"
|
|
||||||
dest: "{{ __nginx_conf }}"
|
|
||||||
mode: "0644"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
notify: Reload nginx
|
|
||||||
|
|
||||||
- name: COMMAND | Fix nginx config
|
|
||||||
ansible.builtin.command: "cp {{ __nginx_conf | dirname }}/fastcgi_params {{ __nginx_conf | dirname }}/fastcgi.conf"
|
|
||||||
args:
|
|
||||||
creates: "{{ __nginx_conf | dirname }}/fastcgi.conf"
|
|
||||||
notify: Reload nginx
|
|
||||||
|
|
||||||
- name: LINEINFILE | Fix nginx config (second step)
|
|
||||||
ansible.builtin.lineinfile:
|
|
||||||
regexp: '^fastcgi_param\s+SCRIPT_FILENAME'
|
|
||||||
line: "fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;"
|
|
||||||
dest: "{{ __nginx_conf | dirname }}/fastcgi.conf"
|
|
||||||
notify: Reload nginx
|
|
||||||
|
|
||||||
- name: SERVICE | Ensure Nginx is started
|
|
||||||
ansible.builtin.service:
|
|
||||||
name: nginx
|
|
||||||
state: started
|
|
|
@ -1,36 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
vhost: 'test.local'
|
|
||||||
|
|
||||||
php_version: null
|
|
||||||
|
|
||||||
php_extra_packages:
|
|
||||||
- '{{ php_package_prefix }}pgsql'
|
|
||||||
|
|
||||||
php_install_xdebug: true
|
|
||||||
php_autoremove_default_pool: true
|
|
||||||
|
|
||||||
php_ini_fpm:
|
|
||||||
display_errors: 'Off'
|
|
||||||
|
|
||||||
php_ini_cli:
|
|
||||||
error_reporting: 'E_ALL'
|
|
||||||
|
|
||||||
php_fpm_poold:
|
|
||||||
- pool_name: 'test_ansible'
|
|
||||||
listen: '/run/php/php-ansible1.sock'
|
|
||||||
pm: 'dynamic'
|
|
||||||
pm_max_children: 250
|
|
||||||
pm_start_servers: 10
|
|
||||||
pm_min_spare_servers: 10
|
|
||||||
pm_max_spare_servers: 20
|
|
||||||
status_path: '/status'
|
|
||||||
ping_path: '/ping'
|
|
||||||
ping_response: 'ok'
|
|
||||||
|
|
||||||
- name: 'test_ansible2'
|
|
||||||
user: 'foo'
|
|
||||||
php_value:
|
|
||||||
display_errors: 'Off'
|
|
||||||
php_admin_value:
|
|
||||||
memory_limit: '98M'
|
|
|
@ -1,41 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
- name: Prepare
|
|
||||||
hosts: all
|
|
||||||
gather_facts: true
|
|
||||||
tasks:
|
|
||||||
- name: APT | Install packages
|
|
||||||
ansible.builtin.apt:
|
|
||||||
pkg: "{{ p }}"
|
|
||||||
update_cache: true
|
|
||||||
cache_valid_time: 3600
|
|
||||||
vars:
|
|
||||||
p:
|
|
||||||
- apt-transport-https
|
|
||||||
- ca-certificates
|
|
||||||
- curl
|
|
||||||
- gpg
|
|
||||||
- lsb-release
|
|
||||||
- nginx
|
|
||||||
- vim
|
|
||||||
|
|
||||||
- name: BLOCK | Setup Sury on Debian
|
|
||||||
when:
|
|
||||||
- php_version is not none
|
|
||||||
- php_version != php_default_version
|
|
||||||
- ansible_distribution == 'Debian'
|
|
||||||
block:
|
|
||||||
- name: APT | Install Sury key
|
|
||||||
ansible.builtin.apt_key:
|
|
||||||
url: 'https://packages.sury.org/php/apt.gpg'
|
|
||||||
|
|
||||||
- name: APT_REPOSITORY | Add Sury repository
|
|
||||||
ansible.builtin.apt_repository:
|
|
||||||
repo: 'deb https://packages.sury.org/php/ {{ ansible_distribution_release }} main'
|
|
||||||
|
|
||||||
- name: USER | Create PHP user
|
|
||||||
ansible.builtin.user:
|
|
||||||
name: 'foo'
|
|
||||||
system: true
|
|
||||||
create_home: false
|
|
||||||
shell: '/usr/sbin/nologin'
|
|
|
@ -1,4 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
collections:
|
|
||||||
- community.general
|
|
|
@ -1,16 +0,0 @@
|
||||||
# {{ ansible_managed }} - custom template
|
|
||||||
|
|
||||||
server {
|
|
||||||
listen 80;
|
|
||||||
listen 8888 http2;
|
|
||||||
listen 9999 http2 proxy_protocol;
|
|
||||||
server_name {{ item.name }};
|
|
||||||
|
|
||||||
index index.html index.htm;
|
|
||||||
|
|
||||||
root {{ item.root }};
|
|
||||||
|
|
||||||
location / {
|
|
||||||
try_files $uri $uri/ =404;
|
|
||||||
}
|
|
||||||
}
|
|
|
@ -1,76 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
- name: Verify
|
|
||||||
hosts: all
|
|
||||||
gather_facts: true
|
|
||||||
vars:
|
|
||||||
nginx_root: "/srv/www"
|
|
||||||
tasks:
|
|
||||||
- name: SHELL | Test php-cli
|
|
||||||
ansible.builtin.shell: set -o pipefail && php -i | grep '^PHP Version => {{ ansible_local.hanxhx_php.php_version }}' | head -n 1
|
|
||||||
changed_when: false
|
|
||||||
register: p
|
|
||||||
failed_when: p.stdout == ''
|
|
||||||
args:
|
|
||||||
executable: /bin/bash
|
|
||||||
|
|
||||||
- name: FILE | Create /var/www
|
|
||||||
ansible.builtin.file:
|
|
||||||
dest: /var/www
|
|
||||||
state: directory
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: "0755"
|
|
||||||
|
|
||||||
- name: COPY | Add phpinfo
|
|
||||||
ansible.builtin.copy:
|
|
||||||
dest: /var/www/phpinfo.php
|
|
||||||
content: '<?php phpinfo();'
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: "0644"
|
|
||||||
|
|
||||||
- name: COPY | Add ini test file
|
|
||||||
ansible.builtin.copy:
|
|
||||||
dest: /var/www/ini.php
|
|
||||||
content: '<?php echo ini_get("memory_limit") . "\n";'
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: "0644"
|
|
||||||
|
|
||||||
- name: SHELL | Check vhost
|
|
||||||
ansible.builtin.shell: "set -o pipefail && curl -v -H 'Host: {{ vhost }}' http://127.0.0.1/phpinfo.php 2> /dev/null | grep h1 | grep -o 'PHP Version {{ ansible_local.hanxhx_php.php_version }}' | sed -r 's/<//g'"
|
|
||||||
args:
|
|
||||||
executable: /bin/bash
|
|
||||||
changed_when: false
|
|
||||||
register: c
|
|
||||||
failed_when: c.stdout == ''
|
|
||||||
|
|
||||||
- name: SHELL | Check custom php value # noqa: command-instead-of-module
|
|
||||||
ansible.builtin.shell: "curl -H 'Host: {{ vhost }}' http://127.0.0.1/ini.php 2> /dev/null"
|
|
||||||
changed_when: false
|
|
||||||
register: c
|
|
||||||
failed_when: 'php_fpm_poold.1.php_admin_value.memory_limit not in c.stdout'
|
|
||||||
|
|
||||||
- name: URI | Check ping
|
|
||||||
ansible.builtin.uri:
|
|
||||||
url: "http://localhost{{ php_fpm_poold.0.ping_path }}"
|
|
||||||
when: php_fpm_poold.0.ping_path is defined
|
|
||||||
|
|
||||||
- name: URI | Check status
|
|
||||||
ansible.builtin.uri:
|
|
||||||
url: "http://localhost{{ php_fpm_poold.0.status_path }}"
|
|
||||||
when: php_fpm_poold.0.status_path is defined
|
|
||||||
|
|
||||||
- name: SHELL | Check if we installed multiple PHP versions
|
|
||||||
ansible.builtin.shell: set -o pipefail && (dpkg -l | grep 'php[[:digit:]].*common' | wc -l)
|
|
||||||
args:
|
|
||||||
executable: /bin/bash
|
|
||||||
failed_when: false
|
|
||||||
changed_when: false
|
|
||||||
register: check_multiple_php
|
|
||||||
|
|
||||||
- name: FAIL | If we have multiple PHP version
|
|
||||||
ansible.builtin.fail:
|
|
||||||
msg: "Multiple PHP versions detected"
|
|
||||||
when: check_multiple_php.stdout != '1'
|
|
|
@ -1,13 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
platforms:
|
|
||||||
- name: debian-11
|
|
||||||
image: dokken/debian-11
|
|
||||||
command: /lib/systemd/systemd
|
|
||||||
dockerfile: ../_shared/Dockerfile.j2
|
|
||||||
capabilities:
|
|
||||||
- SYS_ADMIN
|
|
||||||
cgroupns_mode: host
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
|
||||||
privileged: true
|
|
|
@ -1,13 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
platforms:
|
|
||||||
- name: debian-12
|
|
||||||
image: dokken/debian-12
|
|
||||||
command: /lib/systemd/systemd
|
|
||||||
dockerfile: ../_shared/Dockerfile.j2
|
|
||||||
capabilities:
|
|
||||||
- SYS_ADMIN
|
|
||||||
cgroupns_mode: host
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
|
||||||
privileged: true
|
|
|
@ -1,13 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
platforms:
|
|
||||||
- name: debian-12
|
|
||||||
image: dokken/debian-13
|
|
||||||
command: /lib/systemd/systemd
|
|
||||||
dockerfile: ../_shared/Dockerfile.j2
|
|
||||||
capabilities:
|
|
||||||
- SYS_ADMIN
|
|
||||||
cgroupns_mode: host
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
|
||||||
privileged: true
|
|
|
@ -1,13 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
platforms:
|
|
||||||
- name: ubuntu-20.04
|
|
||||||
image: dokken/ubuntu-20.04
|
|
||||||
command: /lib/systemd/systemd
|
|
||||||
dockerfile: ../_shared/Dockerfile.j2
|
|
||||||
capabilities:
|
|
||||||
- SYS_ADMIN
|
|
||||||
cgroupns_mode: host
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
|
||||||
privileged: true
|
|
|
@ -1,13 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
platforms:
|
|
||||||
- name: ubuntu-22.04
|
|
||||||
image: dokken/ubuntu-22.04
|
|
||||||
command: /lib/systemd/systemd
|
|
||||||
dockerfile: ../_shared/Dockerfile.j2
|
|
||||||
capabilities:
|
|
||||||
- SYS_ADMIN
|
|
||||||
cgroupns_mode: host
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
|
||||||
privileged: true
|
|
|
@ -1,13 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
platforms:
|
|
||||||
- name: ubuntu-24.04
|
|
||||||
image: dokken/ubuntu-24.04
|
|
||||||
command: /lib/systemd/systemd
|
|
||||||
dockerfile: ../_shared/Dockerfile.j2
|
|
||||||
capabilities:
|
|
||||||
- SYS_ADMIN
|
|
||||||
cgroupns_mode: host
|
|
||||||
volumes:
|
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
|
||||||
privileged: true
|
|
|
@ -1,49 +0,0 @@
|
||||||
ansible==11.6.0
|
|
||||||
ansible-compat==25.5.0
|
|
||||||
ansible-core==2.18.6
|
|
||||||
ansible-lint==25.5.0
|
|
||||||
attrs==25.3.0
|
|
||||||
black==25.1.0
|
|
||||||
bracex==2.5.post1
|
|
||||||
certifi==2025.4.26
|
|
||||||
cffi==1.17.1
|
|
||||||
charset-normalizer==3.4.2
|
|
||||||
click==8.2.1
|
|
||||||
click-help-colors==0.9.4
|
|
||||||
cryptography==45.0.3
|
|
||||||
distro==1.9.0
|
|
||||||
docker==7.1.0
|
|
||||||
enrich==1.2.7
|
|
||||||
filelock==3.18.0
|
|
||||||
idna==3.10
|
|
||||||
importlib-metadata==8.7.0
|
|
||||||
jinja2==3.1.6
|
|
||||||
jsonschema==4.24.0
|
|
||||||
jsonschema-specifications==2025.4.1
|
|
||||||
markdown-it-py==3.0.0
|
|
||||||
markupsafe==3.0.2
|
|
||||||
mdurl==0.1.2
|
|
||||||
molecule==25.5.0
|
|
||||||
molecule-plugins==23.7.0
|
|
||||||
mypy-extensions==1.1.0
|
|
||||||
packaging==25.0
|
|
||||||
pathspec==0.12.1
|
|
||||||
platformdirs==4.3.8
|
|
||||||
pluggy==1.6.0
|
|
||||||
pycparser==2.22
|
|
||||||
pygments==2.19.1
|
|
||||||
pyyaml==6.0.2
|
|
||||||
referencing==0.36.2
|
|
||||||
requests==2.32.3
|
|
||||||
resolvelib==1.0.1
|
|
||||||
rich==14.0.0
|
|
||||||
rpds-py==0.25.1
|
|
||||||
ruamel-yaml==0.18.12
|
|
||||||
ruamel-yaml-clib==0.2.12
|
|
||||||
selinux==0.3.0
|
|
||||||
subprocess-tee==0.4.2
|
|
||||||
typing-extensions==4.13.2
|
|
||||||
urllib3==2.4.0
|
|
||||||
wcmatch==10.0
|
|
||||||
yamllint==1.37.1
|
|
||||||
zipp==3.22.0
|
|
|
@ -1,4 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
collections:
|
|
||||||
- community.general
|
|
|
@ -6,6 +6,12 @@
|
||||||
state: "{{ 'present' if php_install_fpm else 'absent' }}"
|
state: "{{ 'present' if php_install_fpm else 'absent' }}"
|
||||||
when: ansible_os_family == 'Debian'
|
when: ansible_os_family == 'Debian'
|
||||||
|
|
||||||
|
- name: SERVICE | Enable service on FreeBSD
|
||||||
|
ansible.builtin.service:
|
||||||
|
name: "{{ php_fpm_service }}"
|
||||||
|
enabled: "{{ 'true' if php_install_fpm else 'false' }}"
|
||||||
|
when: ansible_os_family == 'FreeBSD'
|
||||||
|
|
||||||
- name: LINEINFILE | PHP configuration
|
- name: LINEINFILE | PHP configuration
|
||||||
ansible.builtin.lineinfile:
|
ansible.builtin.lineinfile:
|
||||||
dest: '{{ php_fpm_ini }}'
|
dest: '{{ php_fpm_ini }}'
|
||||||
|
@ -14,9 +20,9 @@
|
||||||
create: true
|
create: true
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: "0644"
|
mode: 0644
|
||||||
loop: "{{ php_ini | combine(php_ini_fpm) | dict2items }}"
|
loop: "{{ php_ini | combine(php_ini_fpm) | dict2items }}"
|
||||||
notify: Restart php-fpm
|
notify: restart php-fpm
|
||||||
|
|
||||||
- name: TEMPLATE | Deploy pool configuration
|
- name: TEMPLATE | Deploy pool configuration
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
|
@ -24,13 +30,13 @@
|
||||||
dest: '{{ php_fpm_pool_dir }}/{{ item.name }}.conf'
|
dest: '{{ php_fpm_pool_dir }}/{{ item.name }}.conf'
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: "0644"
|
mode: 0644
|
||||||
loop: "{{ ansible_local.hanxhx_php.fpm_pool }}"
|
loop: "{{ ansible_local.hanxhx_php.fpm_pool }}"
|
||||||
notify: Restart php-fpm
|
notify: restart php-fpm
|
||||||
|
|
||||||
- name: FILE | Delete default pool if necessary
|
- name: FILE | Delete default pool if necessary
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "{{ php_fpm_pool_dir }}/www.conf"
|
path: "{{ php_fpm_pool_dir }}/www.conf"
|
||||||
state: absent
|
state: absent
|
||||||
when: '"www" not in (ansible_local.hanxhx_php.fpm_pool | map(attribute="name") | list) and php_autoremove_default_pool'
|
when: '"www" not in (ansible_local.hanxhx_php.fpm_pool | map(attribute="name") | list) and php_autoremove_default_pool'
|
||||||
notify: Restart php-fpm
|
notify: restart php-fpm
|
||||||
|
|
|
@ -19,11 +19,6 @@
|
||||||
- "{{ ansible_distribution }}-{{ ansible_distribution_version }}.yml"
|
- "{{ ansible_distribution }}-{{ ansible_distribution_version }}.yml"
|
||||||
- "{{ ansible_distribution }}-{{ ansible_distribution_major_version }}.yml"
|
- "{{ ansible_distribution }}-{{ ansible_distribution_major_version }}.yml"
|
||||||
|
|
||||||
- name: SET_FACT | Prepare PHP version if not defined
|
|
||||||
ansible.builtin.set_fact:
|
|
||||||
php_version: "{{ php_default_version }}"
|
|
||||||
when: php_version is none or php_version == '' or php_version is not defined
|
|
||||||
|
|
||||||
- name: SET_FACT | Transform data
|
- name: SET_FACT | Transform data
|
||||||
ansible.builtin.set_fact:
|
ansible.builtin.set_fact:
|
||||||
__php_fpm_full_pool: |
|
__php_fpm_full_pool: |
|
||||||
|
@ -34,11 +29,10 @@
|
||||||
listen: "{{ p.listen | default(php_version | php_socket(p.name | default(p.pool_name))) }}",
|
listen: "{{ p.listen | default(php_version | php_socket(p.name | default(p.pool_name))) }}",
|
||||||
user: "{{ p.user | default(php_default_user_group) }}",
|
user: "{{ p.user | default(php_default_user_group) }}",
|
||||||
group: "{% if p.user is defined %}{{ p.group | default(p.user) }}{% else %}{{ p.group | default(php_default_user_group) }}{% endif %}",
|
group: "{% if p.user is defined %}{{ p.group | default(p.user) }}{% else %}{{ p.group | default(php_default_user_group) }}{% endif %}",
|
||||||
php_env: {% if p.php_env is defined %}{{ p.php_env | to_nice_json }}{% else %}{}{% endif %},
|
|
||||||
php_value: {% if p.php_value is defined %}{{ p.php_value | to_nice_json }}{% else %}{}{% endif %},
|
php_value: {% if p.php_value is defined %}{{ p.php_value | to_nice_json }}{% else %}{}{% endif %},
|
||||||
php_admin_value: {% if p.php_admin_value is defined %}{{ p.php_admin_value | to_nice_json }}{% else %}{}{% endif %},
|
php_admin_value: {% if p.php_admin_value is defined %}{{ p.php_admin_value | to_nice_json }}{% else %}{}{% endif %},
|
||||||
{% for k, v in p.items() | list %}
|
{% for k, v in p.items() | list %}
|
||||||
{% if k not in ['name', 'pool_name', 'listen', 'user', 'group', 'php_env', 'php_value', 'php_admin_value'] %}
|
{% if k not in ['name', 'pool_name', 'listen', 'user', 'group', 'php_value', 'php_admin_value'] %}
|
||||||
{{ k }}: "{{ v }}"{% if not loop.last %},{% endif %}
|
{{ k }}: "{{ v }}"{% if not loop.last %},{% endif %}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
@ -56,18 +50,16 @@
|
||||||
state: directory
|
state: directory
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: "0755"
|
mode: 0755
|
||||||
|
|
||||||
- name: COPY | Manage facts
|
- name: COPY | Manage facts
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
content: "{ \"fpm_pool\": {{ php_fpm_full_pool | to_nice_json }}, \"php_version\": \"{{ php_version }}\" }"
|
content: "{ \"fpm_pool\": {{ php_fpm_full_pool | to_nice_json }} }"
|
||||||
dest: /etc/ansible/facts.d/hanxhx_php.fact
|
dest: /etc/ansible/facts.d/hanxhx_php.fact
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: "0644"
|
mode: 0644
|
||||||
register: f
|
register: f
|
||||||
tags:
|
|
||||||
- skip_ansible_lint
|
|
||||||
|
|
||||||
- name: SETUP | Gathers new facts
|
- name: SETUP | Gathers new facts
|
||||||
ansible.builtin.setup:
|
ansible.builtin.setup:
|
||||||
|
@ -84,7 +76,14 @@
|
||||||
install_recommends: false
|
install_recommends: false
|
||||||
vars:
|
vars:
|
||||||
pkgs: "{{ php_packages + php_extra_packages | flatten }}"
|
pkgs: "{{ php_packages + php_extra_packages | flatten }}"
|
||||||
notify: Restart php-fpm
|
notify: restart php-fpm
|
||||||
|
when: ansible_os_family == 'Debian'
|
||||||
|
|
||||||
|
- name: PKGNG | Install PHP packages
|
||||||
|
community.general.pkgng:
|
||||||
|
name: "{{ php_packages + php_extra_packages | flatten | join(',') }}"
|
||||||
|
notify: restart php-fpm
|
||||||
|
when: ansible_os_family == 'FreeBSD'
|
||||||
|
|
||||||
- name: IMPORT_TASKS | PHP-FPM
|
- name: IMPORT_TASKS | PHP-FPM
|
||||||
ansible.builtin.import_tasks: fpm.yml
|
ansible.builtin.import_tasks: fpm.yml
|
||||||
|
@ -102,9 +101,26 @@
|
||||||
- name: APT | Install and configure opcache
|
- name: APT | Install and configure opcache
|
||||||
ansible.builtin.import_tasks: opcache.yml
|
ansible.builtin.import_tasks: opcache.yml
|
||||||
|
|
||||||
- name: SERVICE | Ensure PHP-FPM is started and enabled
|
- name: SERVICE | Ensure PHP-FPM is started
|
||||||
when: php_install_fpm
|
|
||||||
ansible.builtin.service:
|
ansible.builtin.service:
|
||||||
name: '{{ php_fpm_service }}'
|
name: '{{ php_fpm_service }}'
|
||||||
state: started
|
state: started
|
||||||
enabled: true
|
when: php_install_fpm and ansible_virtualization_type != 'docker'
|
||||||
|
|
||||||
|
- block:
|
||||||
|
|
||||||
|
- name: COMMAND | Check if PHP-FPM is started (Docker)
|
||||||
|
ansible.builtin.command: 'service {{ php_fpm_service }} status'
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
register: dps
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
|
||||||
|
- name: COMMAND | Ensure PHP-FPM is started (Docker)
|
||||||
|
ansible.builtin.command: 'service {{ php_fpm_service }} start'
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
when: dps.stdout.find('is not running') != -1
|
||||||
|
|
||||||
|
when: php_install_fpm and ansible_virtualization_type == 'docker'
|
||||||
|
|
|
@ -1,14 +1,30 @@
|
||||||
---
|
---
|
||||||
|
|
||||||
- name: APT | Install APCu
|
- block:
|
||||||
ansible.builtin.apt:
|
|
||||||
pkg: "{{ php_apcu_package }}"
|
|
||||||
install_recommends: false
|
|
||||||
|
|
||||||
- name: APT | Install Opcache
|
- name: APT | Install APCu
|
||||||
ansible.builtin.apt:
|
ansible.builtin.apt:
|
||||||
pkg: "{{ php_package_prefix }}opcache"
|
pkg: "{{ php_apcu_package }}"
|
||||||
install_recommends: false
|
install_recommends: false
|
||||||
|
|
||||||
|
- name: APT | Install Opcache
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg: "{{ php_package_prefix }}opcache"
|
||||||
|
install_recommends: false
|
||||||
|
|
||||||
|
when: ansible_os_family == 'Debian'
|
||||||
|
|
||||||
|
- block:
|
||||||
|
|
||||||
|
- name: PKGNG | Install APCu
|
||||||
|
community.general.pkgng:
|
||||||
|
name: "php{{ php_version | replace('.', '') }}-pecl-APCu"
|
||||||
|
|
||||||
|
- name: PKGNG | Install Opcache
|
||||||
|
community.general.pkgng:
|
||||||
|
name: "{{ php_package_prefix }}opcache"
|
||||||
|
|
||||||
|
when: ansible_os_family == 'FreeBSD'
|
||||||
|
|
||||||
- name: TEMPLATE | Configure Opcache
|
- name: TEMPLATE | Configure Opcache
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
|
@ -16,8 +32,8 @@
|
||||||
dest: "{{ php_mods_dir }}/opcache.ini"
|
dest: "{{ php_mods_dir }}/opcache.ini"
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: "0644"
|
mode: 0644
|
||||||
notify: Restart php-fpm
|
notify: restart php-fpm
|
||||||
|
|
||||||
- name: TEMPLATE | Configure APCu
|
- name: TEMPLATE | Configure APCu
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
|
@ -25,5 +41,5 @@
|
||||||
dest: "{{ php_mods_dir }}/apcu.ini"
|
dest: "{{ php_mods_dir }}/apcu.ini"
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: "0644"
|
mode: 0644
|
||||||
notify: Restart php-fpm
|
notify: restart php-fpm
|
||||||
|
|
|
@ -1,8 +1,7 @@
|
||||||
---
|
---
|
||||||
|
|
||||||
- name: BLOCK | Install Xdebug
|
- block:
|
||||||
when: php_install_xdebug
|
|
||||||
block:
|
|
||||||
- name: APT | Install xdebug
|
- name: APT | Install xdebug
|
||||||
ansible.builtin.apt:
|
ansible.builtin.apt:
|
||||||
pkg: "{{ php_xdebug_package }}"
|
pkg: "{{ php_xdebug_package }}"
|
||||||
|
@ -12,16 +11,33 @@
|
||||||
install_recommends: false
|
install_recommends: false
|
||||||
when: ansible_os_family == 'Debian'
|
when: ansible_os_family == 'Debian'
|
||||||
|
|
||||||
|
- name: PKGNG | Install xdebug
|
||||||
|
community.general.pkgng:
|
||||||
|
name: "{{ php_xdebug_package }}"
|
||||||
|
when: ansible_os_family == 'FreeBSD' and php_xdebug_package is defined
|
||||||
|
|
||||||
- name: TEMPLATE | Deploy module configurations
|
- name: TEMPLATE | Deploy module configurations
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
src: "etc/__php__/mods-available/xdebug.ini.j2"
|
src: "etc/__php__/mods-available/xdebug.ini.j2"
|
||||||
dest: "{{ php_mods_dir }}/xdebug.ini"
|
dest: "{{ php_mods_dir }}/xdebug.ini"
|
||||||
owner: root
|
owner: root
|
||||||
mode: "0644"
|
mode: 0644
|
||||||
notify: Restart php-fpm
|
notify: restart php-fpm
|
||||||
|
|
||||||
|
when: php_install_xdebug
|
||||||
|
|
||||||
|
- block:
|
||||||
|
|
||||||
|
- name: APT | Uninstall xdebug
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg: "{{ php_xdebug_package }}"
|
||||||
|
state: absent
|
||||||
|
when: ansible_os_family == 'Debian'
|
||||||
|
|
||||||
|
- name: PKGNG | Uninstall xdebug
|
||||||
|
community.general.pkgng:
|
||||||
|
name: "{{ php_xdebug_package }}"
|
||||||
|
state: absent
|
||||||
|
when: ansible_os_family == 'FreeBSD'
|
||||||
|
|
||||||
- name: APT | Uninstall xdebug
|
|
||||||
ansible.builtin.apt:
|
|
||||||
pkg: "{{ php_xdebug_package }}"
|
|
||||||
state: absent
|
|
||||||
when: not php_install_xdebug
|
when: not php_install_xdebug
|
||||||
|
|
|
@ -421,19 +421,10 @@ catch_workers_output = {{ item.catch_workers_output | default('no') }}
|
||||||
;php_admin_value[error_log] = /var/log/fpm-php.www.log
|
;php_admin_value[error_log] = /var/log/fpm-php.www.log
|
||||||
;php_admin_flag[log_errors] = on
|
;php_admin_flag[log_errors] = on
|
||||||
;php_admin_value[memory_limit] = 32M
|
;php_admin_value[memory_limit] = 32M
|
||||||
{% if item.php_env is defined %}
|
|
||||||
{% for k, v in item.php_env.items() | list %}
|
|
||||||
env[{{ k }}] = {{ v }}
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
{% if item.php_value is defined %}
|
|
||||||
{% for k, v in item.php_value.items() | list %}
|
{% for k, v in item.php_value.items() | list %}
|
||||||
php_value[{{ k }}] = {{ v }}
|
php_value[{{ k }}] = {{ v }}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
|
||||||
{% if item.php_admin_value is defined %}
|
|
||||||
{% for k, v in item.php_admin_value.items() | list %}
|
{% for k, v in item.php_admin_value.items() | list %}
|
||||||
php_admin_value[{{ k }}] = {{ v }}
|
php_admin_value[{{ k }}] = {{ v }}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
|
||||||
; vim:filetype=dosini
|
; vim:filetype=dosini
|
||||||
|
|
|
@ -0,0 +1,9 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
- name: APT | Install Sury key
|
||||||
|
ansible.builtin.apt_key:
|
||||||
|
url: 'https://packages.sury.org/php/apt.gpg'
|
||||||
|
|
||||||
|
- name: APT_REPOSITORY | Add Sury repository
|
||||||
|
ansible.builtin.apt_repository:
|
||||||
|
repo: 'deb https://packages.sury.org/php/ {{ ansible_distribution_release }} main'
|
|
@ -0,0 +1,24 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
- name: SET_FACT | Prepare test vars
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
__nginx_conf: /etc/nginx/nginx.conf
|
||||||
|
|
||||||
|
- name: APT | Install packages
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg: "{{ p }}"
|
||||||
|
update_cache: true
|
||||||
|
cache_valid_time: 3600
|
||||||
|
vars:
|
||||||
|
p:
|
||||||
|
- apt-transport-https
|
||||||
|
- ca-certificates
|
||||||
|
- curl
|
||||||
|
- gpg
|
||||||
|
- lsb-release
|
||||||
|
- nginx
|
||||||
|
- vim
|
||||||
|
|
||||||
|
- name: INCLUDE_TASKS | Sury
|
||||||
|
ansible.builtin.include_tasks: Debian/sury.yml
|
||||||
|
when: php_version != php_default_version
|
|
@ -0,0 +1,10 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
- name: SET_FACT | Prepare test vars
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
__nginx_conf: /usr/local/etc/nginx/nginx.conf
|
||||||
|
php_xdebug_package: 'php72-pecl-xdebug-2.6.1'
|
||||||
|
|
||||||
|
- name: PKGNG | Install packages
|
||||||
|
community.general.pkgng:
|
||||||
|
name: ['curl', 'nginx']
|
|
@ -1,12 +1,8 @@
|
||||||
events {
|
events {
|
||||||
worker_connections 512;
|
worker_connections 1024;
|
||||||
multi_accept on;
|
|
||||||
use epoll;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
user www-data;
|
user {{ php_default_user_group }};
|
||||||
worker_processes 1;
|
|
||||||
pid /run/nginx.pid;
|
|
||||||
|
|
||||||
http {
|
http {
|
||||||
include mime.types;
|
include mime.types;
|
|
@ -0,0 +1,187 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
- hosts: all
|
||||||
|
vars:
|
||||||
|
vhost: 'test.local'
|
||||||
|
php_extra_packages:
|
||||||
|
- '{{ php_package_prefix }}pgsql'
|
||||||
|
php_install_xdebug: true
|
||||||
|
php_autoremove_default_pool: true
|
||||||
|
php_ini_fpm:
|
||||||
|
display_errors: 'Off'
|
||||||
|
php_ini_cli:
|
||||||
|
error_reporting: 'E_ALL'
|
||||||
|
php_fpm_poold:
|
||||||
|
- pool_name: 'test_ansible'
|
||||||
|
listen: '/run/php/php-ansible1.sock'
|
||||||
|
pm: 'dynamic'
|
||||||
|
pm_max_children: 250
|
||||||
|
pm_start_servers: 10
|
||||||
|
pm_min_spare_servers: 10
|
||||||
|
pm_max_spare_servers: 20
|
||||||
|
status_path: '/status'
|
||||||
|
ping_path: '/ping'
|
||||||
|
ping_response: 'ok'
|
||||||
|
- name: 'test_ansible2'
|
||||||
|
user: 'foo'
|
||||||
|
php_value:
|
||||||
|
display_errors: 'Off'
|
||||||
|
php_admin_value:
|
||||||
|
memory_limit: '98M'
|
||||||
|
|
||||||
|
pre_tasks:
|
||||||
|
|
||||||
|
- name: INCLUDE_TASKS | Pre tasks related to OS
|
||||||
|
ansible.builtin.include_tasks: "includes/pre_{{ ansible_os_family }}.yml"
|
||||||
|
|
||||||
|
- name: USER | Create PHP user
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: 'foo'
|
||||||
|
system: true
|
||||||
|
create_home: false
|
||||||
|
shell: '/usr/sbin/nologin'
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
|
||||||
|
- name: TEMPLATE | Nginx site config
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: "templates/nginx.conf.j2"
|
||||||
|
dest: "{{ __nginx_conf }}"
|
||||||
|
mode: 0644
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
notify: reload nginx
|
||||||
|
|
||||||
|
- name: COMMAND | Fix nginx config
|
||||||
|
ansible.builtin.command: "cp {{ __nginx_conf | dirname }}/fastcgi_params {{ __nginx_conf | dirname }}/fastcgi.conf"
|
||||||
|
args:
|
||||||
|
creates: "{{ __nginx_conf | dirname }}/fastcgi.conf"
|
||||||
|
notify: reload nginx
|
||||||
|
|
||||||
|
- name: LINEINFILE | Fix nginx config (second step)
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
regexp: '^fastcgi_param\s+SCRIPT_FILENAME'
|
||||||
|
line: "fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;"
|
||||||
|
dest: "{{ __nginx_conf | dirname }}/fastcgi.conf"
|
||||||
|
notify: reload nginx
|
||||||
|
|
||||||
|
- name: SERVICE | Ensure nginx is started
|
||||||
|
ansible.builtin.service:
|
||||||
|
name: nginx
|
||||||
|
state: started
|
||||||
|
when: ansible_virtualization_type != 'docker'
|
||||||
|
|
||||||
|
- block:
|
||||||
|
|
||||||
|
- name: COMMAND | Docker nginx status
|
||||||
|
ansible.builtin.command: service nginx status
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
register: ngs
|
||||||
|
|
||||||
|
- name: COMMAND | Docker start nginx
|
||||||
|
ansible.builtin.command: service nginx start
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
when: ngs.stdout.find('nginx is not running') != -1
|
||||||
|
|
||||||
|
when: ansible_virtualization_type == 'docker'
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
|
||||||
|
- name: reload nginx
|
||||||
|
ansible.builtin.service:
|
||||||
|
name: nginx
|
||||||
|
state: reloaded
|
||||||
|
notify: docker reload nginx
|
||||||
|
|
||||||
|
- name: docker reload nginx
|
||||||
|
ansible.builtin.command: service nginx reload
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
notify: docker reload nginx
|
||||||
|
when: ansible_virtualization_type == 'docker'
|
||||||
|
|
||||||
|
roles:
|
||||||
|
- ../../
|
||||||
|
|
||||||
|
post_tasks:
|
||||||
|
|
||||||
|
- name: SHELL | Test php-cli
|
||||||
|
ansible.builtin.shell: set -o pipefail && php -i | grep '^PHP Version => {{ php_version }}' | head -n 1
|
||||||
|
changed_when: false
|
||||||
|
register: p
|
||||||
|
failed_when: p.stdout == ''
|
||||||
|
args:
|
||||||
|
executable: /bin/bash
|
||||||
|
|
||||||
|
- name: FILE | Create /var/www
|
||||||
|
ansible.builtin.file:
|
||||||
|
dest: /var/www
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0755
|
||||||
|
|
||||||
|
- name: COPY | Add phpinfo
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /var/www/phpinfo.php
|
||||||
|
content: '<?php phpinfo();'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0644
|
||||||
|
|
||||||
|
- name: COPY | Add ini test file
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /var/www/ini.php
|
||||||
|
content: '<?php echo ini_get("memory_limit") . "\n";'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: 0644
|
||||||
|
|
||||||
|
- name: SHELL | Check vhost
|
||||||
|
ansible.builtin.shell: "set -o pipefail && curl -v -H 'Host: {{ vhost }}' http://127.0.0.1/phpinfo.php 2> /dev/null | grep h1 | grep -o 'PHP Version {{ php_version }}' | sed -r 's/<//g'"
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
executable: /bin/bash
|
||||||
|
changed_when: false
|
||||||
|
register: c
|
||||||
|
failed_when: c.stdout == ''
|
||||||
|
|
||||||
|
- name: SHELL | Check custom php value
|
||||||
|
ansible.builtin.shell: "curl -H 'Host: {{ vhost }}' http://127.0.0.1/ini.php 2> /dev/null"
|
||||||
|
args:
|
||||||
|
warn: false
|
||||||
|
changed_when: false
|
||||||
|
register: c
|
||||||
|
failed_when: 'php_fpm_poold.1.php_admin_value.memory_limit not in c.stdout'
|
||||||
|
|
||||||
|
- name: URI | Check ping
|
||||||
|
ansible.builtin.uri:
|
||||||
|
url: "http://localhost{{ php_fpm_poold.0.ping_path }}"
|
||||||
|
when: php_fpm_poold.0.ping_path is defined
|
||||||
|
|
||||||
|
- name: URI | Check status
|
||||||
|
ansible.builtin.uri:
|
||||||
|
url: "http://localhost{{ php_fpm_poold.0.status_path }}"
|
||||||
|
when: php_fpm_poold.0.status_path is defined
|
||||||
|
|
||||||
|
- block:
|
||||||
|
|
||||||
|
- name: SHELL | Check if we installed multiple PHP versions
|
||||||
|
ansible.builtin.shell: set -o pipefail && (dpkg -l | grep 'php[[:digit:]].*common' | wc -l)
|
||||||
|
args:
|
||||||
|
executable: /bin/bash
|
||||||
|
failed_when: false
|
||||||
|
changed_when: false
|
||||||
|
register: check_multiple_php
|
||||||
|
|
||||||
|
|
||||||
|
- name: FAIL | If we have multiple PHP version
|
||||||
|
ansible.builtin.fail:
|
||||||
|
msg: "Multiple PHP versions detected"
|
||||||
|
when: check_multiple_php.stdout != '1'
|
||||||
|
|
||||||
|
when: ansible_os_family == 'Debian'
|
|
@ -1,3 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
php_default_version: '8.2'
|
|
|
@ -0,0 +1,3 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
php_default_version: '7.3'
|
|
@ -0,0 +1,3 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
php_default_version: '7.0'
|
|
@ -1,3 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
php_default_version: '8.4'
|
|
|
@ -0,0 +1,3 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
php_default_version: '7.2'
|
|
@ -0,0 +1,3 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
php_default_version: '7.2'
|
|
@ -0,0 +1,20 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
php_packages:
|
||||||
|
- '{{ php_package_prefix }}curl'
|
||||||
|
- '{{ php_package_prefix }}gd'
|
||||||
|
- '{{ php_package_prefix }}mysqli'
|
||||||
|
- '{{ php_package_prefix }}intl'
|
||||||
|
|
||||||
|
php_package_prefix: 'php{{ php_version | replace(".", "") }}-'
|
||||||
|
|
||||||
|
php_mods_dir: '/usr/local/etc/php'
|
||||||
|
php_fpm_pool_dir: '/usr/local/etc/php-fpm.d'
|
||||||
|
|
||||||
|
php_fpm_service: 'php-fpm'
|
||||||
|
php_default_fpm_sock: '/var/run/php-fpm.sock'
|
||||||
|
|
||||||
|
php_cli_ini: '/usr/local/etc/php.ini'
|
||||||
|
php_fpm_ini: '/usr/local/etc/php.ini'
|
||||||
|
|
||||||
|
php_default_user_group: 'www'
|
|
@ -0,0 +1,3 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
php_default_version: '7.2'
|
|
@ -1,3 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
php_default_version: '7.4'
|
|
|
@ -1,3 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
php_default_version: '8.1'
|
|
|
@ -1,3 +0,0 @@
|
||||||
---
|
|
||||||
|
|
||||||
php_default_version: '8.3'
|
|
|
@ -0,0 +1,3 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
php_default_version: '7.0'
|
Loading…
Reference in New Issue