112 lines
2.7 KiB
YAML
112 lines
2.7 KiB
YAML
---
|
|
- name: Deploy OpenBao Vault
|
|
hosts: vault0
|
|
gather_facts: false
|
|
tasks:
|
|
- name: Update APT cache and install dependencies
|
|
ansible.builtin.apt:
|
|
name:
|
|
- curl
|
|
- gpg
|
|
- apt-transport-https
|
|
- unzip
|
|
state: present
|
|
update_cache: true
|
|
|
|
- name: Create bao group
|
|
ansible.builtin.group:
|
|
name: bao
|
|
state: present
|
|
|
|
- name: Create bao user
|
|
ansible.builtin.user:
|
|
name: bao
|
|
group: bao
|
|
system: true
|
|
create_home: false
|
|
shell: /usr/sbin/nologin
|
|
state: present
|
|
|
|
- name: Ensure bao configuration directory exists
|
|
ansible.builtin.file:
|
|
path: /etc/bao
|
|
state: directory
|
|
owner: bao
|
|
group: bao
|
|
mode: "0755"
|
|
|
|
- name: Ensure bao data directory exists
|
|
ansible.builtin.file:
|
|
path: /var/lib/bao/data
|
|
state: directory
|
|
owner: bao
|
|
group: bao
|
|
mode: "0750"
|
|
|
|
- name: Download and extract OpenBao binary
|
|
ansible.builtin.unarchive:
|
|
src: https://github.com/openbao/openbao/releases/download/v2.0.1/bao_2.0.1_linux_amd64.zip
|
|
dest: /usr/local/bin
|
|
remote_src: true
|
|
creates: /usr/local/bin/bao
|
|
owner: root
|
|
group: root
|
|
mode: "0755"
|
|
notify: Restart OpenBao
|
|
|
|
- name: Generate OpenBao configuration
|
|
ansible.builtin.copy:
|
|
dest: /etc/bao/vault.hcl
|
|
owner: bao
|
|
group: bao
|
|
mode: "0644"
|
|
content: |
|
|
disable_mlock = true
|
|
ui = true
|
|
storage "file" {
|
|
path = "/var/lib/bao/data"
|
|
}
|
|
listener "tcp" {
|
|
address = "0.0.0.0:8200"
|
|
tls_disable = 1
|
|
}
|
|
notify: Restart OpenBao
|
|
|
|
- name: Create OpenBao systemd service
|
|
ansible.builtin.copy:
|
|
dest: /etc/systemd/system/openbao.service
|
|
owner: root
|
|
group: root
|
|
mode: "0644"
|
|
content: |
|
|
[Unit]
|
|
Description=OpenBao Secrets Management
|
|
After=network.target
|
|
[Service]
|
|
User=bao
|
|
Group=bao
|
|
ExecStart=/usr/local/bin/bao server -config=/etc/bao/vault.hcl
|
|
Restart=on-failure
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
notify: Restart OpenBao
|
|
|
|
- name: Enable and start OpenBao service
|
|
ansible.builtin.systemd:
|
|
name: openbao
|
|
enabled: true
|
|
state: started
|
|
daemon_reload: true
|
|
|
|
- name: Wait for OpenBao port 8200 to become available
|
|
ansible.builtin.wait_for:
|
|
port: 8200
|
|
host: 127.0.0.1
|
|
state: started
|
|
timeout: 30
|
|
|
|
handlers:
|
|
- name: Restart OpenBao
|
|
ansible.builtin.systemd:
|
|
name: openbao
|
|
state: restarted |