Revert "Drop linux capabilities and rework users/groups"

This commit is contained in:
Matthew Mosesohn
2017-02-06 15:58:54 +03:00
committed by GitHub
parent b7bf502e02
commit fd30131dc2
48 changed files with 81 additions and 413 deletions

View File

@@ -4,15 +4,14 @@
path={{ etcd_cert_dir }}
group={{ etcd_cert_group }}
state=directory
mode=0750
owner={{ etcd_user }}
owner=root
recurse=yes
- name: "Gen_certs | create etcd script dir (on {{groups['etcd'][0]}})"
file:
path: "{{ etcd_script_dir }}"
state: directory
owner: "{{ etcd_user }}"
owner: root
run_once: yes
delegate_to: "{{groups['etcd'][0]}}"
@@ -21,8 +20,7 @@
path={{ etcd_cert_dir }}
group={{ etcd_cert_group }}
state=directory
mode=0750
owner={{ etcd_user }}
owner=root
recurse=yes
run_once: yes
delegate_to: "{{groups['etcd'][0]}}"
@@ -126,12 +124,12 @@
path={{ etcd_cert_dir }}
group={{ etcd_cert_group }}
state=directory
owner={{ etcd_user }}
owner=kube
recurse=yes
tags: facts
- name: Gen_certs | set shared group permissions on keys
shell: chmod 0640 {{ etcd_cert_dir}}/*.pem
- name: Gen_certs | set permissions on keys
shell: chmod 0600 {{ etcd_cert_dir}}/*key.pem
when: inventory_hostname in groups['etcd']
changed_when: false