controller_token

Role Documentation

Welcome to the “controller_token” role documentation.

Role Defaults

This section highlights all of the defaults and variables set within the “controller_token” role.

keystone_conf_file: /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf

Role Variables: main.yml

metadata:
  description: 'This validation checks that keystone admin token is disabled on both
    undercloud and overcloud controller after deployment.

    '
  groups:
  - post-deployment
  name: Verify that keystone admin token is disabled

Molecule Scenarios

Molecule is being used to test the “controller_token” role. The following section highlights the drivers in service and provides an example playbook showing how the role is leveraged.

Scenario: default

Example default configuration
driver:
  name: docker
log: true
platforms:
- easy_install:
  - pip
  environment:
    http_proxy: '{{ lookup(''env'', ''http_proxy'') }}'
    https_proxy: '{{ lookup(''env'', ''https_proxy'') }}'
  hostname: centos7
  image: centos:7
  name: centos7
  pkg_extras: python-setuptools python-enum34 PyYAML
  volumes:
  - /etc/ci/mirror_info.sh:/etc/ci/mirror_info.sh:ro
- environment:
    http_proxy: '{{ lookup(''env'', ''http_proxy'') }}'
    https_proxy: '{{ lookup(''env'', ''https_proxy'') }}'
  hostname: centos8
  image: centos:8
  name: centos8
  pkg_extras: python*-setuptools python*-enum34 python*-PyYAML
  volumes:
  - /etc/ci/mirror_info.sh:/etc/ci/mirror_info.sh:ro
provisioner:
  env:
    ANSIBLE_LIBRARY: ../../../../library
    ANSIBLE_STDOUT_CALLBACK: yaml
  log: true
  name: ansible
scenario:
  test_sequence:
  - destroy
  - create
  - prepare
  - converge
  - verify
  - destroy
verifier:
  name: testinfra
Example default playbook
- gather_facts: false
  hosts: all
  name: Converge
  tasks:
  - include_role:
      name: controller_token
    name: pass validation
  - block:
    - copy:
        content: '[DEFAULT]

          admin_token = CHANGEME

          '
        dest: /keystone.conf
      name: provide configuration file
    - include_role:
        name: controller_token
      vars:
        keystone_conf_file: /keystone.conf
    name: fail validation
    rescue:
    - meta: clear_host_errors
      name: Clear host errors
    - debug:
        msg: The validation works! End the playbook run
    - meta: end_play
      name: End play
  - fail:
      msg: 'Controller-token validation failed finding bad configuration!

        '
    name: Fail the test