功能端部署剧本升级,适配20.04版本
This commit is contained in:
@@ -1,74 +0,0 @@
|
|||||||
maat_redis_server:
|
|
||||||
address: "192.168.41.206"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: "192.168.41.206"
|
|
||||||
port: 7002
|
|
||||||
db: 1
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "192.168.41.204:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "192.168.41.206"
|
|
||||||
port: 9090
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 1
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 58125
|
|
||||||
|
|
||||||
nic_transparent_mode:
|
|
||||||
enable: 0
|
|
||||||
|
|
||||||
run_as_tun_mode: 0
|
|
||||||
package_source: "local"
|
|
||||||
|
|
||||||
install_dns_debug: "yes"
|
|
||||||
install_ftp_debug: "yes"
|
|
||||||
install_http_debug: "yes"
|
|
||||||
install_mail_debug: "yes"
|
|
||||||
install_ssl_debug: "yes"
|
|
||||||
install_fw_dns_plug_debug: "yes"
|
|
||||||
install_fw_ftp_plug_debug: "yes"
|
|
||||||
install_fw_http_plug_debug: "yes"
|
|
||||||
install_fw_mail_plug_debug: "yes"
|
|
||||||
install_tsg_master: "yes"
|
|
||||||
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 10
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
maat:
|
|
||||||
readconf_mode: 2
|
|
||||||
send_logger:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
tfe:
|
|
||||||
nr_threads: 16
|
|
||||||
mc_cache_eth: ens1.100
|
|
||||||
keykeeper:
|
|
||||||
mode: "normal"
|
|
||||||
no_cache: 0
|
|
||||||
|
|
||||||
mrzcpd:
|
|
||||||
iocore: 47
|
|
||||||
|
|
||||||
mrtunnat:
|
|
||||||
lcore_id: 46
|
|
||||||
|
|
||||||
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f4
|
|
||||||
ip: 192.168.1.30
|
|
||||||
mask: 255.255.255.252
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: ens1f5
|
|
||||||
tfe1:
|
|
||||||
name: ens1f6
|
|
||||||
tfe2:
|
|
||||||
name: ens1f7
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens1f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
[all:vars]
|
|
||||||
ansible_user=root
|
|
||||||
package_source=local
|
|
||||||
|
|
||||||
[blade-mxn]
|
|
||||||
192.168.40.170
|
|
||||||
|
|
||||||
[blade-00]
|
|
||||||
192.168.40.166
|
|
||||||
|
|
||||||
[blade-01]
|
|
||||||
192.168.40.167
|
|
||||||
|
|
||||||
[blade-02]
|
|
||||||
192.168.40.168
|
|
||||||
|
|
||||||
[blade-03]
|
|
||||||
192.168.40.169
|
|
||||||
|
|
||||||
[Functional_Host:children]
|
|
||||||
blade-00
|
|
||||||
blade-01
|
|
||||||
blade-02
|
|
||||||
blade-03
|
|
||||||
@@ -1,73 +0,0 @@
|
|||||||
maat_redis_server:
|
|
||||||
address: "192.168.41.206"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: "192.168.41.206"
|
|
||||||
port: 7002
|
|
||||||
db: 1
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "192.168.41.204:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "192.168.41.206"
|
|
||||||
port: 9090
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 1
|
|
||||||
address: "192.168.100.1"
|
|
||||||
port: 58125
|
|
||||||
|
|
||||||
nic_transparent_mode:
|
|
||||||
enable: 0
|
|
||||||
|
|
||||||
run_as_tun_mode: 0
|
|
||||||
package_source: "local"
|
|
||||||
|
|
||||||
install_dns_debug: "yes"
|
|
||||||
install_ftp_debug: "yes"
|
|
||||||
install_http_debug: "yes"
|
|
||||||
install_mail_debug: "yes"
|
|
||||||
install_ssl_debug: "yes"
|
|
||||||
install_fw_dns_plug_debug: "yes"
|
|
||||||
install_fw_ftp_plug_debug: "yes"
|
|
||||||
install_fw_http_plug_debug: "yes"
|
|
||||||
install_fw_mail_plug_debug: "yes"
|
|
||||||
install_tsg_master: "yes"
|
|
||||||
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 10
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
maat:
|
|
||||||
readconf_mode: 2
|
|
||||||
send_logger:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
tfe:
|
|
||||||
nr_threads: 16
|
|
||||||
keykeeper:
|
|
||||||
mode: "normal"
|
|
||||||
no_cache: 0
|
|
||||||
|
|
||||||
mrzcpd:
|
|
||||||
iocore: 47
|
|
||||||
|
|
||||||
mrtunnat:
|
|
||||||
lcore_id: 46
|
|
||||||
|
|
||||||
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f4
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_to_tfe:
|
|
||||||
tfe0:
|
|
||||||
name: ens1f5
|
|
||||||
tfe1:
|
|
||||||
name: ens1f6
|
|
||||||
tfe2:
|
|
||||||
name: ens1f7
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens1f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens1.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens1f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
nic_mgr:
|
|
||||||
name: enp6s0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: ens8f1
|
|
||||||
mac: AA:BB:CC:DD:EE:FF
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: ens8.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: ens8f2
|
|
||||||
use_mrzcpd: 1
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
[all:vars]
|
|
||||||
ansible_user=root
|
|
||||||
package_source=local
|
|
||||||
|
|
||||||
[blade-mxn]
|
|
||||||
192.168.40.170
|
|
||||||
|
|
||||||
[blade-00]
|
|
||||||
192.168.40.166
|
|
||||||
|
|
||||||
[blade-01]
|
|
||||||
192.168.40.167
|
|
||||||
|
|
||||||
[blade-02]
|
|
||||||
192.168.40.168
|
|
||||||
|
|
||||||
[blade-03]
|
|
||||||
192.168.40.169
|
|
||||||
|
|
||||||
|
|
||||||
[Functional_Host:children]
|
|
||||||
blade-00
|
|
||||||
blade-01
|
|
||||||
blade-02
|
|
||||||
blade-03
|
|
||||||
|
|
||||||
[Slave_Host:children]
|
|
||||||
blade-01
|
|
||||||
blade-02
|
|
||||||
blade-03
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
- hosts: blade-00
|
|
||||||
tasks:
|
|
||||||
- name: "killall certstore"
|
|
||||||
command: "killall certstore"
|
|
||||||
- name: "clear redis cache"
|
|
||||||
command: "redis-cli flushdb"
|
|
||||||
@@ -10,6 +10,8 @@
|
|||||||
- sapp
|
- sapp
|
||||||
- kni
|
- kni
|
||||||
- firewall
|
- firewall
|
||||||
|
- http_healthcheck
|
||||||
|
- clotho
|
||||||
- certstore
|
- certstore
|
||||||
- cert-redis
|
- cert-redis
|
||||||
|
|
||||||
@@ -44,6 +46,8 @@
|
|||||||
- sapp
|
- sapp
|
||||||
- kni
|
- kni
|
||||||
- firewall
|
- firewall
|
||||||
|
- http_healthcheck
|
||||||
|
- clotho
|
||||||
- certstore
|
- certstore
|
||||||
- cert-redis
|
- cert-redis
|
||||||
- tfe
|
- tfe
|
||||||
|
|||||||
@@ -1,88 +0,0 @@
|
|||||||
maat_redis_server:
|
|
||||||
address: "192.168.40.168"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
dynamic_maat_redis_server:
|
|
||||||
address: "192.168.40.168"
|
|
||||||
port: 7002
|
|
||||||
db: 0
|
|
||||||
|
|
||||||
cert_store_server:
|
|
||||||
address: "127.0.0.1"
|
|
||||||
port: 9991
|
|
||||||
|
|
||||||
log_kafkabrokers:
|
|
||||||
address: "192.168.40.169:9092"
|
|
||||||
|
|
||||||
log_minio:
|
|
||||||
address: "192.168.40.168;"
|
|
||||||
port: 9090
|
|
||||||
|
|
||||||
fs_remote:
|
|
||||||
switch: 1
|
|
||||||
address: "127.0.0.1"
|
|
||||||
port: 8125
|
|
||||||
|
|
||||||
install_dns_debug: "yes"
|
|
||||||
install_ftp_debug: "yes"
|
|
||||||
install_http_debug: "yes"
|
|
||||||
install_mail_debug: "yes"
|
|
||||||
install_ssl_debug: "yes"
|
|
||||||
install_fw_dns_plug_debug: "yes"
|
|
||||||
install_fw_ftp_plug_debug: "yes"
|
|
||||||
install_fw_http_plug_debug: "yes"
|
|
||||||
install_fw_mail_plug_debug: "yes"
|
|
||||||
install_tsg_master: "yes"
|
|
||||||
|
|
||||||
sapp:
|
|
||||||
worker_threads: 16
|
|
||||||
|
|
||||||
kni:
|
|
||||||
global:
|
|
||||||
log_level: 30
|
|
||||||
tfe_node_count: 3
|
|
||||||
watch_dog:
|
|
||||||
switch: 1
|
|
||||||
maat:
|
|
||||||
readconf_mode: 2
|
|
||||||
send_logger:
|
|
||||||
switch: 1
|
|
||||||
tfe_nodes:
|
|
||||||
- tfe0:
|
|
||||||
enabled: 1
|
|
||||||
- tfe1:
|
|
||||||
enabled: 1
|
|
||||||
- tfe2:
|
|
||||||
enabled: 1
|
|
||||||
tfe:
|
|
||||||
nr_threads: 32
|
|
||||||
mc_cache_eth: lo
|
|
||||||
keykeeper:
|
|
||||||
mode: "normal"
|
|
||||||
no_cache: 0
|
|
||||||
|
|
||||||
mrzcpd:
|
|
||||||
iocore: 39
|
|
||||||
|
|
||||||
mrtunnat:
|
|
||||||
lcore_id: 38
|
|
||||||
|
|
||||||
nic_mgr:
|
|
||||||
name: eth0
|
|
||||||
nic_data_incoming:
|
|
||||||
name: tun_kni
|
|
||||||
address: 127.0.0.1
|
|
||||||
nic_inner_ctrl:
|
|
||||||
name: eth0.100
|
|
||||||
nic_traffic_mirror:
|
|
||||||
name: lo
|
|
||||||
use_mrzcpd: 0
|
|
||||||
|
|
||||||
nic_transparent_mode:
|
|
||||||
enable: 1
|
|
||||||
mode: pcap
|
|
||||||
internel_interface: "eth2"
|
|
||||||
external_interface: "eth3"
|
|
||||||
|
|
||||||
run_as_tun_mode: 1
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
[all:vars]
|
|
||||||
ansible_user=root
|
|
||||||
package_source=local
|
|
||||||
|
|
||||||
[pc-as-tun-mode]
|
|
||||||
192.168.40.138
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
- hosts: blade-0*
|
|
||||||
roles:
|
|
||||||
- pulp-consumer
|
|
||||||
Binary file not shown.
Binary file not shown.
@@ -1,5 +1,4 @@
|
|||||||
---
|
- name: "copy certstore rpm to destination"
|
||||||
- name: "copy redis and dependency to destination"
|
|
||||||
synchronize:
|
synchronize:
|
||||||
src: "{{ role_path }}/files/"
|
src: "{{ role_path }}/files/"
|
||||||
dest: "/tmp/ansible_deploy/"
|
dest: "/tmp/ansible_deploy/"
|
||||||
@@ -9,18 +8,19 @@
|
|||||||
tags: mkdir
|
tags: mkdir
|
||||||
|
|
||||||
- name: install certstore
|
- name: install certstore
|
||||||
unarchive:
|
yum:
|
||||||
src: "{{ role_path }}/files/certstore-base-online-20200119.tar.gz"
|
name:
|
||||||
dest: /home/tsg
|
- /tmp/ansible_deploy/certstore-v20.04.3989072-1.el7.x86_64.rpm
|
||||||
|
state: present
|
||||||
|
|
||||||
- name: template certstore configure file
|
- name: template certstore configure file
|
||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/cert_store.ini.j2"
|
src: "{{ role_path }}/templates/cert_store.ini.j2"
|
||||||
dest: /home/tsg/certstore-base/conf/cert_store.ini
|
dest: /home/tsg/certstore-base/conf/cert_store.ini
|
||||||
|
|
||||||
- name: bootup certstore
|
- name: "start certstore"
|
||||||
blockinfile:
|
systemd:
|
||||||
marker: "## {mark} bootstrap certstore"
|
name: certstore.service
|
||||||
path: /etc/rc.d/rc.local
|
state: started
|
||||||
block: |
|
enabled: yes
|
||||||
cd /home/tsg/certstore-base; ./r2_certstore
|
daemon_reload: yes
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
#1:print on screen, 0:don't
|
#1:print on screen, 0:don't
|
||||||
DEBUG_SWITCH = 1
|
DEBUG_SWITCH = 1
|
||||||
#10:DEBUG, 20:INFO, 30:FATAL
|
#10:DEBUG, 20:INFO, 30:FATAL
|
||||||
RUN_LOG_LEVEL = 30
|
RUN_LOG_LEVEL = 10
|
||||||
RUN_LOG_PATH = ./logs
|
RUN_LOG_PATH = ./logs
|
||||||
[CONFIG]
|
[CONFIG]
|
||||||
#Number of running threads
|
#Number of running threads
|
||||||
@@ -42,4 +42,4 @@ port = 6379
|
|||||||
#Maat monitors the Redsi server IP address and port number
|
#Maat monitors the Redsi server IP address and port number
|
||||||
ip = {{ maat_redis_server.address }}
|
ip = {{ maat_redis_server.address }}
|
||||||
port = {{ maat_redis_server.port }}
|
port = {{ maat_redis_server.port }}
|
||||||
dbindex = {{ maat_redis_server.db }}
|
dbindex = {{ maat_redis_server.db }}
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -4,86 +4,41 @@
|
|||||||
src: "{{ role_path }}/files/"
|
src: "{{ role_path }}/files/"
|
||||||
dest: /tmp/ansible_deploy/
|
dest: /tmp/ansible_deploy/
|
||||||
|
|
||||||
- name: "install dns-debug rpms from localhost"
|
- name: "install firewall packages"
|
||||||
yum:
|
yum:
|
||||||
name:
|
name: "{{ fw_packages }}"
|
||||||
|
state: present
|
||||||
|
vars:
|
||||||
|
fw_packages:
|
||||||
- /tmp/ansible_deploy/dns-debug-1.0.0.-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/dns-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
state: present
|
|
||||||
when: install_dns_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install ftp-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/ftp-debug-1.0.0.-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/ftp-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
state: present
|
|
||||||
when: install_ftp_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install http-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/http-debug-1.0.0.-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/http-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
state: present
|
|
||||||
when: install_http_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install mail-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/mail-debug-1.0.0.-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/mail-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
state: present
|
|
||||||
when: install_mail_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install ssl-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/ssl-debug-1.0.0.-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/ssl-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
state: present
|
- /tmp/ansible_deploy/tsg_conn_record-1.0.0.2155660-1.el7.centos.x86_64.rpm
|
||||||
when: install_ssl_debug == "yes"
|
- /tmp/ansible_deploy/fw_dns_plug-debug-1.0.3.ea8e0f6-1.el7.centos.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/fw_ftp_plug-debug-1.0.1.a5c1e05-1.el7.centos.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/fw_http_plug-debug-1.0.6.7b34485-1.el7.centos.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/fw_mail_plug-debug-1.0.2.f513698-1.el7.centos.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/fw_ssl_plug-1.0.1.d232f96-1.el7.centos.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/capture_packet_plug-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/clotho-debug-1.0.0.-1.el7.x86_64.rpm
|
||||||
|
|
||||||
- name: "install fw_dns_plug-debug rpms from localhost"
|
- name: "Template the tsgconf/main.conf"
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_dns_plug-debug-1.0.2.1c9d36d-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_dns_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install fw_ftp_plug-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_ftp_plug-debug-1.0.0.bd656e4-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_ftp_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install fw_http_plug-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_http_plug-debug-1.0.3.3c95e78-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_http_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install fw_mail_plug-debug rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/fw_mail_plug-debug-1.0.1.8792ed8-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_fw_mail_plug_debug == "yes"
|
|
||||||
|
|
||||||
- name: "install tsg-master rpms from localhost"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/tsg_master-debug-1.0.1.f624b67-1.el7.centos.x86_64.rpm
|
|
||||||
state: present
|
|
||||||
when: install_tsg_master == "yes"
|
|
||||||
|
|
||||||
- name: Template the tsgconf/main.conf
|
|
||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/main.conf.j2"
|
src: "{{ role_path }}/templates/main.conf.j2"
|
||||||
dest: /home/mesasoft/sapp_run/tsgconf/main.conf
|
dest: /home/mesasoft/sapp_run/tsgconf/main.conf
|
||||||
tags: template
|
tags: template
|
||||||
|
|
||||||
|
|
||||||
- name: Template the tsgconf/maat.conf
|
- name: "Template the tsgconf/maat.conf"
|
||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/maat.conf.j2"
|
src: "{{ role_path }}/templates/maat.conf.j2"
|
||||||
dest: /home/mesasoft/sapp_run/tsgconf/maat.conf
|
dest: /home/mesasoft/sapp_run/tsgconf/maat.conf
|
||||||
tags: template
|
tags: template
|
||||||
|
|
||||||
|
- name: "Template the conf/capture_packet_plug.conf.j2"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/capture_packet_plug.conf.j2"
|
||||||
|
dest: /home/mesasoft/sapp_run/conf/capture_packet_plug.conf
|
||||||
|
tags: template
|
||||||
|
|||||||
@@ -2,21 +2,25 @@
|
|||||||
LOG_PATH=./tsglog/fw_ftp_plug/fw_ftp_plug
|
LOG_PATH=./tsglog/fw_ftp_plug/fw_ftp_plug
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL=10
|
||||||
TIMEOUT=600
|
TIMEOUT=600
|
||||||
|
|
||||||
[MAIL_PLUG]
|
[MAIL_PLUG]
|
||||||
LOG_PATH=./tsglog/fw_mail_plug/fw_mail_plug
|
LOG_PATH=./tsglog/fw_mail_plug/fw_mail_plug
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL=10
|
||||||
TIMEOUT=600
|
TIMEOUT=600
|
||||||
|
|
||||||
[HTTP_PLUG]
|
[HTTP_PLUG]
|
||||||
LOG_PATH=./tsglog/fw_http_plug/fw_http_plug
|
LOG_PATH=./tsglog/fw_http_plug/fw_http_plug
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL=10
|
||||||
|
|
||||||
[DNS_PLUG]
|
[DNS_PLUG]
|
||||||
LOG_PATH=./tsglog/fw_dns_plug/fw_dns_plug
|
LOG_PATH=./tsglog/fw_dns_plug/fw_dns_plug
|
||||||
LOG_LEVEL=10
|
LOG_LEVEL=10
|
||||||
|
|
||||||
[MAAT]
|
[MAAT]
|
||||||
PROFILE=./tsgconf/maat.conf
|
PROFILE=./tsgconf/maat.conf
|
||||||
IP_ADDR_TABLE=TSG_OBJ_IP_ADDR
|
|
||||||
SUBSCRIBER_ID_TABLE=TSG_OBJ_SUBSCRIBER_ID
|
SUBSCRIBER_ID_TABLE=TSG_OBJ_SUBSCRIBER_ID
|
||||||
CB_SUBSCRIBER_IP_TABLE=TSG_DYN_SUBSCRIBER_IP
|
CB_SUBSCRIBER_IP_TABLE=TSG_DYN_SUBSCRIBER_IP
|
||||||
|
IP_ADDR_TABLE=TSG_SECURITY_ADDR
|
||||||
|
|
||||||
[TSG_LOG]
|
[TSG_LOG]
|
||||||
MODE=1
|
MODE=1
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
@@ -1 +0,0 @@
|
|||||||
/opt/MESA/lib/
|
|
||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
- name: "copy framework rpms to destination server"
|
- name: "copy framework rpms to destination server"
|
||||||
synchronize:
|
synchronize:
|
||||||
src: "{{ role_path }}/files/"
|
src: "{{ role_path }}/files/"
|
||||||
@@ -10,35 +9,13 @@
|
|||||||
state: present
|
state: present
|
||||||
vars:
|
vars:
|
||||||
packages:
|
packages:
|
||||||
- /tmp/ansible_deploy/dkms/dkms-2.7.1-1.el7.noarch.rpm
|
- /tmp/ansible_deploy/framework-debug-2.0.17.1e678c4-1.el7.centos.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/framework/framework-2.0.11.aad8b7e-1.el7.centos.x86_64.rpm
|
- /tmp/ansible_deploy/libmaatframe-2.8.0.5a450d2-1.el7.x86_64.rpm/
|
||||||
|
|
||||||
- name: "install framework ld.conf"
|
- name: "install framework ld.conf"
|
||||||
synchronize:
|
synchronize:
|
||||||
src: "{{ role_path }}/files/framework/framework.conf"
|
src: "{{ role_path }}/files/framework/framework.conf"
|
||||||
dest: /etc/ld.so.conf.d/framework.conf
|
dest: /etc/ld.so.conf.d/framework.conf
|
||||||
|
|
||||||
- name: "install/update rulescan library"
|
|
||||||
synchronize:
|
|
||||||
src: "{{ role_path }}/files/rulescan/librulescan.so"
|
|
||||||
dest: /opt/MESA/lib/librulescan.so
|
|
||||||
|
|
||||||
- name: "install/update maat library files"
|
|
||||||
synchronize:
|
|
||||||
src: "{{ role_path }}/files/maat/lib/"
|
|
||||||
dest: /opt/MESA/lib/
|
|
||||||
|
|
||||||
- name: "create maat library symbol links - A"
|
|
||||||
file:
|
|
||||||
src: "libmaatframe.so.2.8"
|
|
||||||
path: /opt/MESA/lib/libmaatframe.so.2
|
|
||||||
state: link
|
|
||||||
|
|
||||||
- name: "create maat library symbol links - B"
|
|
||||||
file:
|
|
||||||
src: "libmaatframe.so.2"
|
|
||||||
path: /opt/MESA/lib/libmaatframe.so
|
|
||||||
state: link
|
|
||||||
|
|
||||||
- name: "update ld"
|
- name: "update ld"
|
||||||
command: ldconfig
|
command: ldconfig
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
name:
|
name:
|
||||||
- /tmp/ansible_deploy/kernel/kernel-ml-5.1.8-1.el7.elrepo.x86_64.rpm
|
- /tmp/ansible_deploy/kernel/kernel-ml-5.1.8-1.el7.elrepo.x86_64.rpm
|
||||||
- /tmp/ansible_deploy/kernel/kernel-ml-devel-5.1.8-1.el7.elrepo.x86_64.rpm
|
- /tmp/ansible_deploy/kernel/kernel-ml-devel-5.1.8-1.el7.elrepo.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/dkms-2.7.1-1.el7.noarch.rpm
|
||||||
state: present
|
state: present
|
||||||
register: t_kernel_ml
|
register: t_kernel_ml
|
||||||
|
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -7,7 +7,7 @@
|
|||||||
- name: "install kni rpms from localhost"
|
- name: "install kni rpms from localhost"
|
||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
- /tmp/ansible_deploy/kni-3.0.2.57bfa41-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/kni-20.04-1.el7.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Template the kni.conf
|
- name: Template the kni.conf
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ log_path = ./log/kni/kni.log
|
|||||||
log_level = {{ kni.global.log_level }}
|
log_level = {{ kni.global.log_level }}
|
||||||
tfe_node_count = {{ kni.global.tfe_node_count }}
|
tfe_node_count = {{ kni.global.tfe_node_count }}
|
||||||
manage_eth = {{ nic_mgr.name }}
|
manage_eth = {{ nic_mgr.name }}
|
||||||
{% if run_as_tun_mode %}
|
{% if tsg_access_type == 0 %}
|
||||||
deploy_mode = tun
|
deploy_mode = tun
|
||||||
{% else %}
|
{% else %}
|
||||||
deploy_mode = normal
|
deploy_mode = normal
|
||||||
@@ -11,7 +11,7 @@ deploy_mode = normal
|
|||||||
tun_name = tun_kni
|
tun_name = tun_kni
|
||||||
src_mac_addr = 00:0e:c6:d6:72:c1
|
src_mac_addr = 00:0e:c6:d6:72:c1
|
||||||
dst_mac_addr = fe:65:b7:03:50:bd
|
dst_mac_addr = fe:65:b7:03:50:bd
|
||||||
{% if run_as_tun_mode %}
|
{% if tsg_access_type == 0 %}
|
||||||
{% else %}
|
{% else %}
|
||||||
[tfe0]
|
[tfe0]
|
||||||
enabled = 1
|
enabled = 1
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
@@ -6,7 +6,7 @@
|
|||||||
|
|
||||||
- name: "install mrzcpd"
|
- name: "install mrzcpd"
|
||||||
yum:
|
yum:
|
||||||
name: /tmp/ansible_deploy/mrzcpd-4.3.15.7b8ad9e-1.el7.x86_64.rpm
|
name: /tmp/ansible_deploy/mrzcpd-4.3.17.f543325-1.el7.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: "update sysconfig/mrzcpd"
|
- name: "update sysconfig/mrzcpd"
|
||||||
@@ -20,17 +20,37 @@
|
|||||||
dest: /opt/mrzcpd/etc/mrglobal.conf
|
dest: /opt/mrzcpd/etc/mrglobal.conf
|
||||||
when: nic_traffic_mirror is defined
|
when: nic_traffic_mirror is defined
|
||||||
|
|
||||||
- name: "update mrglobal.conf - master blade"
|
- name: "update mrglobal.conf.inline - blade00"
|
||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/mrglobal.conf.inline.j2"
|
src: "{{ role_path }}/templates/mrglobal.conf.inline.j2"
|
||||||
dest: /opt/mrzcpd/etc/mrglobal.conf
|
dest: /opt/mrzcpd/etc/mrglobal.conf
|
||||||
when: nic_traffic_mirror is not defined
|
when:
|
||||||
|
- nic_traffic_mirror is not defined
|
||||||
|
- tsg_access_type == 1
|
||||||
|
|
||||||
- name: "update mrtunnat.conf - master blade"
|
- name: "update mrglobal.conf.allot - blade00"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/mrglobal.conf.allot_access.j2"
|
||||||
|
dest: /opt/mrzcpd/etc/mrglobal.conf
|
||||||
|
when:
|
||||||
|
- nic_traffic_mirror is not defined
|
||||||
|
- tsg_access_type == 2
|
||||||
|
|
||||||
|
- name: "update mrtunnat.conf.inline - blade00"
|
||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/mrtunnat.conf.inline.j2"
|
src: "{{ role_path }}/templates/mrtunnat.conf.inline.j2"
|
||||||
dest: /opt/mrzcpd/etc/mrtunnat.conf
|
dest: /opt/mrzcpd/etc/mrtunnat.conf
|
||||||
when: nic_traffic_mirror is not defined
|
when:
|
||||||
|
- nic_traffic_mirror is not defined
|
||||||
|
- tsg_access_type == 1
|
||||||
|
|
||||||
|
- name: "update mrtunnat.conf.allot_access - blade00"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/mrtunnat.conf.allot_access.j2"
|
||||||
|
dest: /opt/mrzcpd/etc/mrtunnat.conf
|
||||||
|
when:
|
||||||
|
- nic_traffic_mirror is not defined
|
||||||
|
- tsg_access_type == 2
|
||||||
|
|
||||||
- name: "enable mrenv"
|
- name: "enable mrenv"
|
||||||
systemd:
|
systemd:
|
||||||
@@ -38,13 +58,6 @@
|
|||||||
enabled: yes
|
enabled: yes
|
||||||
daemon_reload: yes
|
daemon_reload: yes
|
||||||
|
|
||||||
#- name: "mask mrenv"
|
|
||||||
# systemd:
|
|
||||||
# name: mrenv
|
|
||||||
# masked: yes
|
|
||||||
# daemon_reload: yes
|
|
||||||
# when: nic_traffic_mirror.use_mrzcpd == 0
|
|
||||||
|
|
||||||
- name: "enable mrzcpd"
|
- name: "enable mrzcpd"
|
||||||
systemd:
|
systemd:
|
||||||
name: mrzcpd
|
name: mrzcpd
|
||||||
@@ -64,11 +77,3 @@
|
|||||||
enabled: 0
|
enabled: 0
|
||||||
daemon_reload: yes
|
daemon_reload: yes
|
||||||
when: nic_traffic_mirror is defined
|
when: nic_traffic_mirror is defined
|
||||||
|
|
||||||
|
|
||||||
#- name: "mask mrzcpd"
|
|
||||||
# systemd:
|
|
||||||
# name: mrzcpd
|
|
||||||
# masked: yes
|
|
||||||
# daemon_reload: yes
|
|
||||||
# when: nic_traffic_mirror.use_mrzcpd == 0
|
|
||||||
|
|||||||
@@ -1,29 +0,0 @@
|
|||||||
---
|
|
||||||
- name: "Install EPEL"
|
|
||||||
yum:
|
|
||||||
name: http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
|
|
||||||
state: present
|
|
||||||
|
|
||||||
- name: "Install Pulp Consumer Tools Repo"
|
|
||||||
get_url:
|
|
||||||
url: https://repos.fedorapeople.org/repos/pulp/pulp/rhel-pulp.repo
|
|
||||||
dest: /etc/yum.repos.d/rhel-pulp.repo
|
|
||||||
|
|
||||||
- name: "Install Pulp Consumer Tools"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- pulp-admin-client
|
|
||||||
- pulp-rpm-admin-extensions
|
|
||||||
- pulp-consumer-client
|
|
||||||
- pulp-rpm-consumer-extensions
|
|
||||||
- pulp-agent
|
|
||||||
- pulp-rpm-handlers
|
|
||||||
- pulp-rpm-yumplugins
|
|
||||||
- python-gofer-qpid
|
|
||||||
state: present
|
|
||||||
update_cache: yes
|
|
||||||
|
|
||||||
- name: "Start Pulp Message Service"
|
|
||||||
systemd:
|
|
||||||
state: started
|
|
||||||
name: goferd
|
|
||||||
@@ -8,6 +8,7 @@
|
|||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
- /tmp/ansible_deploy/sapp-4.0.5.3385992-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/sapp-4.0.5.3385992-1.el7.x86_64.rpm
|
||||||
|
- /tmp/ansible_deploy/tsg_master-debug-1.0.3.a4e2a7c-1.el7.centos.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: make dir
|
- name: make dir
|
||||||
@@ -37,7 +38,7 @@
|
|||||||
template:
|
template:
|
||||||
src: "{{ role_path }}/templates/gdev.conf.j2"
|
src: "{{ role_path }}/templates/gdev.conf.j2"
|
||||||
dest: /home/mesasoft/sapp_run/etc/gdev.conf
|
dest: /home/mesasoft/sapp_run/etc/gdev.conf
|
||||||
tags: template
|
when: tsg_access_type == 1
|
||||||
|
|
||||||
- name: "enable sapp"
|
- name: "enable sapp"
|
||||||
systemd:
|
systemd:
|
||||||
|
|||||||
@@ -1,5 +1,9 @@
|
|||||||
[platform]
|
[platform]
|
||||||
|
{% if tsg_access_type == 1 %}
|
||||||
./plug/platform/g_device_plug/g_device_plug.inf
|
./plug/platform/g_device_plug/g_device_plug.inf
|
||||||
|
{% else %}
|
||||||
|
#./plug/platform/g_device_plug/g_device_plug.inf
|
||||||
|
{% endif %}
|
||||||
./plug/platform/tsg_master/tsg_master.inf
|
./plug/platform/tsg_master/tsg_master.inf
|
||||||
|
|
||||||
[protocol]
|
[protocol]
|
||||||
@@ -16,4 +20,5 @@
|
|||||||
./plug/business/fw_dns_plug/fw_dns_plug.inf
|
./plug/business/fw_dns_plug/fw_dns_plug.inf
|
||||||
./plug/business/fw_mail_plug/fw_mail_plug.inf
|
./plug/business/fw_mail_plug/fw_mail_plug.inf
|
||||||
./plug/business/fw_ftp_plug/fw_ftp_plug.inf
|
./plug/business/fw_ftp_plug/fw_ftp_plug.inf
|
||||||
./plug/business/tsg_conn_record/tsg_conn_record.inf
|
./plug/business/tsg_conn_record/tsg_conn_record.inf
|
||||||
|
./plug/business/capture_packet_plug/capture_packet_plug.inf
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
[Module]
|
[Module]
|
||||||
pcapdevice={{ nic_data_incoming.name }}
|
pcapdevice={{ nic_data_incoming.name }}
|
||||||
sendto_gdev_card={{ nic_data_incoming.name }}
|
sendto_gdev_card={{ nic_data_incoming.name }}
|
||||||
sendto_gdev_ip={{ nic_data_incoming.address }}
|
sendto_gdev_ip={{ nic_data_incoming.ip }}
|
||||||
gdev_status_switch=1
|
gdev_status_switch=1
|
||||||
|
|||||||
@@ -1,4 +1,7 @@
|
|||||||
tcp_flow_stat struct
|
tcp_flow_stat struct
|
||||||
udp_flow_stat struct
|
udp_flow_stat struct
|
||||||
tcp_deduce_flow_stat struct
|
tcp_deduce_flow_stat struct
|
||||||
POLICY_PRIORITY struct
|
POLICY_PRIORITY struct
|
||||||
|
ESTABLISH_LATENCY long
|
||||||
|
MAIL_IDENTIFY int
|
||||||
|
|
||||||
|
|||||||
@@ -9,16 +9,16 @@
|
|||||||
instance_name = "sapp4"
|
instance_name = "sapp4"
|
||||||
|
|
||||||
[CPU]
|
[CPU]
|
||||||
{% if run_as_tun_mode %}
|
{% if tsg_access_type == 0 %}
|
||||||
worker_threads=1
|
worker_threads=1
|
||||||
{% else %}
|
{% else %}
|
||||||
worker_threads={{ sapp.worker_threads }}
|
worker_threads={{ sapp.worker_threads }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
### note, bind_mask, if you do not want to bind thread to special CPU core, keep it empty as []
|
### note, bind_mask, if you do not want to bind thread to special CPU core, keep it empty as []
|
||||||
{% if run_as_tun_mode %}
|
{% if tsg_access_type == 0 %}
|
||||||
bind_mask=[]
|
bind_mask=[]
|
||||||
{% else %}
|
{% else %}
|
||||||
bind_mask=[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16]
|
bind_mask=[{{ sapp.bind_mask }}]
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
[PACKET_IO]
|
[PACKET_IO]
|
||||||
@@ -27,7 +27,7 @@ BSD_packet_filter=""
|
|||||||
|
|
||||||
### note, depolyment.mode options: [mirror, inline, transparent]
|
### note, depolyment.mode options: [mirror, inline, transparent]
|
||||||
[packet_io.depolyment]
|
[packet_io.depolyment]
|
||||||
{% if nic_transparent_mode.enable %}
|
{% if nic_transparent_mode.enable == 1 %}
|
||||||
mode=transparent
|
mode=transparent
|
||||||
{% else %}
|
{% else %}
|
||||||
mode=inline
|
mode=inline
|
||||||
@@ -35,7 +35,7 @@ BSD_packet_filter=""
|
|||||||
|
|
||||||
### note, interface.type options: [pag,pcap,marsio]
|
### note, interface.type options: [pag,pcap,marsio]
|
||||||
[packet_io.internal.interface]
|
[packet_io.internal.interface]
|
||||||
{% if nic_transparent_mode.enable %}
|
{% if nic_transparent_mode.enable == 1 %}
|
||||||
type={{nic_transparent_mode.mode}}
|
type={{nic_transparent_mode.mode}}
|
||||||
name={{nic_transparent_mode.internel_interface}}
|
name={{nic_transparent_mode.internel_interface}}
|
||||||
{% else %}
|
{% else %}
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
@@ -7,18 +7,9 @@
|
|||||||
- name: "install tfe rpms from localhost"
|
- name: "install tfe rpms from localhost"
|
||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
- /tmp/ansible_deploy/tfe-kmod-v1.0.4.20190923-1dkms.noarch.rpm
|
- /tmp/ansible_deploy/tfe-kmod-v1.0.5.20200408-1dkms.noarch.rpm
|
||||||
- /tmp/ansible_deploy/tfe-4.3.0.202001081429550800.92060ee-1.el7.x86_64.rpm
|
- /tmp/ansible_deploy/tfe-4.3.1.cc89b5b-1.el7.x86_64.rpm
|
||||||
state: present
|
state: present
|
||||||
when: package_source == "local"
|
|
||||||
|
|
||||||
- name: "install tfe rpms from pulp"
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- /tmp/ansible_deploy/tfe-kmod-v1.0.4.20190923-1dkms.noarch.rpm
|
|
||||||
- tfe
|
|
||||||
state: latest
|
|
||||||
when: package_source == "pulp"
|
|
||||||
|
|
||||||
- name: "template tfe-env config"
|
- name: "template tfe-env config"
|
||||||
template:
|
template:
|
||||||
@@ -56,14 +47,6 @@
|
|||||||
name: tfe-env
|
name: tfe-env
|
||||||
enabled: yes
|
enabled: yes
|
||||||
daemon_reload: yes
|
daemon_reload: yes
|
||||||
when: not run_as_tun_mode
|
|
||||||
|
|
||||||
- name: "enable tfe-env-tun"
|
|
||||||
systemd:
|
|
||||||
name: tfe-env-tun-mode
|
|
||||||
enabled: yes
|
|
||||||
daemon_reload: yes
|
|
||||||
when: run_as_tun_mode
|
|
||||||
|
|
||||||
- name: "enable tfe"
|
- name: "enable tfe"
|
||||||
systemd:
|
systemd:
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ TFE_PEER_MAC_DATA_INCOMING=aa:bb:cc:dd:ee:ff
|
|||||||
TFE_LOCAL_IP_DATA_INCOMING=172.16.241.2
|
TFE_LOCAL_IP_DATA_INCOMING=172.16.241.2
|
||||||
TFE_PEER_IP_DATA_INCOMING=172.16.241.1
|
TFE_PEER_IP_DATA_INCOMING=172.16.241.1
|
||||||
|
|
||||||
{% if run_as_tun_mode %}
|
{% if tsg_access_type == 0 %}
|
||||||
TFE_WATCHDOG_DEVICE={{ nic_inner_ctrl.name }}
|
TFE_WATCHDOG_DEVICE={{ nic_inner_ctrl.name }}
|
||||||
TFE_WATCHDOG_IP=192.168.100.1
|
TFE_WATCHDOG_IP=192.168.100.1
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
@@ -2,8 +2,16 @@
|
|||||||
- name: "copy setup script"
|
- name: "copy setup script"
|
||||||
copy:
|
copy:
|
||||||
src: "{{ role_path }}/files/setup"
|
src: "{{ role_path }}/files/setup"
|
||||||
dest: "/opt/tsg/env/"
|
dest: /opt/tsg/env/
|
||||||
mode: 0755
|
mode: 0755
|
||||||
|
when: tsg_access_type == 1
|
||||||
|
|
||||||
|
- name: "Template setup script"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/setup.AllotAccess.j2"
|
||||||
|
dest: /opt/tsg/env/setup
|
||||||
|
mode: 0755
|
||||||
|
when: tsg_access_type == 2
|
||||||
|
|
||||||
- name: "copy switch_control_client_non_block"
|
- name: "copy switch_control_client_non_block"
|
||||||
copy:
|
copy:
|
||||||
|
|||||||
@@ -23,3 +23,10 @@
|
|||||||
enabled: yes
|
enabled: yes
|
||||||
daemon_reload: yes
|
daemon_reload: yes
|
||||||
|
|
||||||
|
- name: "Template PM1.13_vlan_mac_flipping_saved_startup"
|
||||||
|
template:
|
||||||
|
src: "{{ role_path }}/templates/PM1.13_vlan_mac_flipping_saved_startup"
|
||||||
|
dest: /usr/local/testpoint/perl/Config/libertyTrail/saved_startup
|
||||||
|
when: tsg_access_type == 2
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,30 +0,0 @@
|
|||||||
- hosts: blade-00
|
|
||||||
tasks:
|
|
||||||
- name: "blade incpt - find corefiles to delete"
|
|
||||||
find:
|
|
||||||
paths:
|
|
||||||
- /
|
|
||||||
- /home/tsg/certstore-base/
|
|
||||||
- /home/mesasoft/sapp_run/
|
|
||||||
patterns: core.*
|
|
||||||
register: blade_incpt_corefiles_to_delete
|
|
||||||
|
|
||||||
- name: "blade incpt cleanup coredump"
|
|
||||||
file:
|
|
||||||
state: absent
|
|
||||||
path: '{{ item.path }}'
|
|
||||||
with_items: "{{ blade_incpt_corefiles_to_delete.files }}"
|
|
||||||
|
|
||||||
- hosts: blade-01:blade-02:blade-03
|
|
||||||
tasks:
|
|
||||||
- name: "find corefiles to delete"
|
|
||||||
find:
|
|
||||||
paths: /opt/tsg/tfe/
|
|
||||||
patterns: core.*
|
|
||||||
register: ctrl_corefiles_to_delete
|
|
||||||
|
|
||||||
- name: "cleanup coredump"
|
|
||||||
file:
|
|
||||||
state: absent
|
|
||||||
path: '{{ item.path }}'
|
|
||||||
with_items: "{{ ctrl_corefiles_to_delete.files }}"
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
#- hosts: all
|
|
||||||
# tasks:
|
|
||||||
# - name: "reboot all"
|
|
||||||
# reboot:
|
|
||||||
|
|
||||||
- hosts: Functional_Host
|
|
||||||
tasks:
|
|
||||||
- name: "reboot all compute blade"
|
|
||||||
reboot:
|
|
||||||
Reference in New Issue
Block a user