Switch tasks from shell to command
This commit is contained in:
parent
534704f115
commit
4f955fe498
@ -60,9 +60,10 @@
|
|||||||
tags: xpack-security
|
tags: xpack-security
|
||||||
|
|
||||||
- name: Generating certificates for Elasticsearch security (generating CA)
|
- name: Generating certificates for Elasticsearch security (generating CA)
|
||||||
shell: >-
|
command: >-
|
||||||
/usr/share/elasticsearch/bin/elasticsearch-certutil cert ca --pem --in
|
/usr/share/elasticsearch/bin/elasticsearch-certutil cert ca --pem
|
||||||
{{ node_certs_source }}/instances.yml --out {{ node_certs_source }}/certs.zip
|
--in {{ node_certs_source }}/instances.yml
|
||||||
|
--out {{ node_certs_source }}/certs.zip
|
||||||
when:
|
when:
|
||||||
- node_certs_generator
|
- node_certs_generator
|
||||||
- not xpack_certs_zip.stat.exists
|
- not xpack_certs_zip.stat.exists
|
||||||
@ -70,10 +71,12 @@
|
|||||||
tags: xpack-security
|
tags: xpack-security
|
||||||
|
|
||||||
- name: Generating certificates for Elasticsearch security (using provided CA | Without CA Password)
|
- name: Generating certificates for Elasticsearch security (using provided CA | Without CA Password)
|
||||||
shell: >-
|
command: >-
|
||||||
/usr/share/elasticsearch/bin/elasticsearch-certutil cert
|
/usr/share/elasticsearch/bin/elasticsearch-certutil cert
|
||||||
--ca-key {{ node_certs_source }}/{{ ca_key_name }} --ca-cert {{ node_certs_source }}/{{ ca_cert_name }}
|
--ca-key {{ node_certs_source }}/{{ ca_key_name }}
|
||||||
--pem --in {{ node_certs_source }}/instances.yml --out {{ node_certs_source }}/certs.zip
|
--ca-cert {{ node_certs_source }}/{{ ca_cert_name }}
|
||||||
|
--pem --in {{ node_certs_source }}/instances.yml
|
||||||
|
--out {{ node_certs_source }}/certs.zip
|
||||||
when:
|
when:
|
||||||
- node_certs_generator
|
- node_certs_generator
|
||||||
- not xpack_certs_zip.stat.exists
|
- not xpack_certs_zip.stat.exists
|
||||||
@ -82,9 +85,10 @@
|
|||||||
tags: xpack-security
|
tags: xpack-security
|
||||||
|
|
||||||
- name: Generating certificates for Elasticsearch security (using provided CA | Using CA Password)
|
- name: Generating certificates for Elasticsearch security (using provided CA | Using CA Password)
|
||||||
shell: >-
|
command: >-
|
||||||
/usr/share/elasticsearch/bin/elasticsearch-certutil cert
|
/usr/share/elasticsearch/bin/elasticsearch-certutil cert
|
||||||
--ca-key {{ node_certs_source }}/{{ ca_key_name }} --ca-cert {{ node_certs_source }}/{{ ca_cert_name }}
|
--ca-key {{ node_certs_source }}/{{ ca_key_name }}
|
||||||
|
--ca-cert {{ node_certs_source }}/{{ ca_cert_name }}
|
||||||
--pem --in {{ node_certs_source }}/instances.yml --out {{ node_certs_source }}/certs.zip
|
--pem --in {{ node_certs_source }}/instances.yml --out {{ node_certs_source }}/certs.zip
|
||||||
--ca-pass {{ ca_password }}
|
--ca-pass {{ ca_password }}
|
||||||
when:
|
when:
|
||||||
@ -175,7 +179,8 @@
|
|||||||
tags: xpack-security
|
tags: xpack-security
|
||||||
|
|
||||||
- name: Set elasticsearch bootstrap password
|
- name: Set elasticsearch bootstrap password
|
||||||
shell: >-
|
command: >-
|
||||||
|
set -o pipefail
|
||||||
echo {{ elasticsearch_xpack_security_password }} | {{ node_certs_source }}/bin/elasticsearch-keystore add -xf bootstrap.password
|
echo {{ elasticsearch_xpack_security_password }} | {{ node_certs_source }}/bin/elasticsearch-keystore add -xf bootstrap.password
|
||||||
when:
|
when:
|
||||||
- node_certs_generator
|
- node_certs_generator
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user