http://steinim.github.io/slides/fosdem/zero-downtime-ansible/tutorial.html
http://steinim.github.io/slides/fosdem/zero-downtime-ansible/
#!/bin/bash
if $( command -v vim >/dev/null 2>&1 ); then
echo "vim is already installed."
else
apt-get install vim
fi
if $( grep -Fxq "filetype indent off" /etc/vim/vimrc ); then
echo "set filetype indent off is already in /etc/vim/vimrc."
else
echo "filetype indent off" >> /etc/vim/vimrc
# TODO: Do not continue if this fails.
fi
# TODO: Rollback if something fails.
- name: Ensure installed vim
apt:
pkg: vim
state: present
update_cache: no
tags:
- vim
- name: Set filetype indent off
lineinfile:
dest: /etc/vim/vimrc
line: 'filetype indent off'
state: present
tags:
- vim
vagrant up
├── ansible.cfg
├── hosts
├── site.yml
├── group_vars
│ └── <group name>
├── host_vars
│ └── <host name>
├── roles
│ ├── <role>
│ │ ├── files
│ │ └── <file>
│ │ └── templates
│ │ └── <template>.j2
│ │ ├── handlers
│ │ │ └── main.yml
│ │ ├── tasks
│ │ │ └── main.yml
│ │ ├── vars
│ │ │ └── main.yml
ansible-playbook site.yml
ansible -m setup app1.local
git checkout start
Help: http://docs.ansible.com/apt_module.html http://docs.ansible.com/lineinfile_module.html
git diff HEAD origin/task1
git checkout task1 # or keep your own solution
ansible app1.local -a "grep 'filetype indent off' /etc/vim/vimrc"
ansible-playbook site.yml --tags vim
ProTip: Use '--tags', '--skip-tags', '--limit' and/or 'gather_facts: False'
to reduce execution time.
ansible app1.local -a "grep 'filetype indent off' /etc/vim/vimrc"
Help: http://docs.ansible.com/group_module.html http://docs.ansible.com/user_module.html http://docs.ansible.com/lineinfile_module.html (.ssh/authorized_keys) http://docs.ansible.com/playbooks_best_practices.html#group-and-host-variables
git checkout task2_help
git diff HEAD origin/task2
git checkout task2 # or keep your own solution
ansible-playbook site.yml --limit appservers --skip-tags vim,java
ssh devops@app1.local
roles/postgresql
├── files
│ └── postgresql.conf
├── handlers
│ └── main.yml
├── tasks
│ ├── main.yml
│ └── ...
└── templates
└── pg_hba.conf.j2
Use variables (group_vars/all and/or group_vars/dbservers).
Use handler to restart postgresql upon notification
Template: git checkout task3 -- roles/postgresql/templates/pg_hba.conf.j2
Help: http://docs.ansible.com/template_module.html (pg_hba.conf.j2) http://docs.ansible.com/postgresql_user_module.html http://docs.ansible.com/postgresql_db_module.html http://docs.ansible.com/playbooks_intro.html#handlers-running-operations-on-change http://docs.ansible.com/playbooks_best_practices.html#group-and-host-variables
git diff HEAD origin/task3
git checkout task3 # or keep your own solution
ansible-playbook site.yml --limit dbservers --tags pg_install
$ vagrant ssh db
vagrant@db:~$ psql -d devops -U devops -W
devops=> \q
roles/app
├── files
│ └── init.sh
├── tasks
│ └── main.yml
└── templates
└── config.properties.j2
NB! Use variables (./hosts).
Set 'serial: 1' for appservers in the playbook (site.yml).
Help: http://docs.ansible.com/service_module.html
git diff HEAD origin/task4
git checkout task4 # or keep your own solution
ansible-playbook site.yml --limit appservers --tags deploy
/home/devops
├── config.properties
├── current -> /home/devops/devops_1416228023.jar
├── previous -> /home/devops/devops_1416221573.jar
├── devops_1416221573.jar
├── devops_1416228023.jar
└── logs
├── stderr.log
└── stdout.log
/etc/init.d
└── devops
roles/db
├── files
│ └── migrate_db.sql
└── tasks
└── main.yml
Help: http://docs.ansible.com/command_module.html
psql -d {{ db.name }} -q -f /tmp/migrate_db.sql
become_user: postgres
git diff HEAD origin/task5
git checkout task5 # or keep your own solution
ansible-playbook site.yml --limit dbservers --tags deploy
$ vagrant ssh db
vagrant@db:~$ psql -d devops -U devops -W
devops=> \dt
devops=> select * from hello;
devops=> \q
Browse to http://app1.local:1234/
roles/nginx
├── handlers
│ └── main.yml
├── tasks
│ ├── config_nginx.yml
│ ├── install_nginx.yml
│ └── main.yml
└── templates
└── devops.conf.j2
Help: http://jinja.pocoo.org/docs/latest/templates/#for
git diff HEAD origin/task6
git checkout task6 # or keep your own solution
ansible-playbook site.yml --limit proxies --tags nginx
Expand | Contract |
---|---|
|
|
git checkout play
ansible-playbook site.yml --limit appservers,dbservers --tags deploy
ansible-playbook site.yml --limit appservers,dbservers --tags rollback
All will be decrypted on the target host
(assuming a valid vault password is supplied when running the play)
ansible-vault create group_vars/vault
ansible-playbook site.yml --ask-vault-pass
Help: http://docs.ansible.com/ansible/playbooks_vault.html