2019-07-11 11:17:02 +03:00
|
|
|
---
|
2019-05-08 14:51:56 +03:00
|
|
|
- name: Install the gpg key for docker
|
|
|
|
apt_key:
|
|
|
|
url: "https://download.docker.com/linux/ubuntu/gpg"
|
|
|
|
state: present
|
2019-07-11 11:17:02 +03:00
|
|
|
|
2019-05-08 14:51:56 +03:00
|
|
|
- name: Install the docker repos
|
|
|
|
apt_repository:
|
|
|
|
repo: "deb [arch=amd64] https://download.docker.com/linux/ubuntu {{ ansible_distribution_release }} stable"
|
|
|
|
state: present
|
|
|
|
|
|
|
|
- name: Install apt dependencies
|
|
|
|
apt:
|
|
|
|
update_cache: yes
|
|
|
|
name: "{{ item }}"
|
|
|
|
with_items:
|
|
|
|
- apt-transport-https
|
|
|
|
- ca-certificates
|
|
|
|
- curl
|
|
|
|
- software-properties-common
|
|
|
|
- docker-ce
|
|
|
|
- git
|
2019-07-05 15:39:37 +03:00
|
|
|
- python3
|
|
|
|
- python3-pip
|
2019-05-08 14:51:56 +03:00
|
|
|
|
|
|
|
- name: Install Docker Compose
|
|
|
|
get_url:
|
|
|
|
url: "https://github.com/docker/compose/releases/download/{{ docker_compose_version }}/docker-compose-Linux-x86_64"
|
|
|
|
dest: "/usr/local/bin/docker-compose"
|
|
|
|
force: True
|
|
|
|
owner: "root"
|
|
|
|
group: "root"
|
|
|
|
mode: "0755"
|
2019-07-11 11:17:02 +03:00
|
|
|
|
2019-05-08 14:51:56 +03:00
|
|
|
- name: Install python docker library
|
2019-07-05 15:39:37 +03:00
|
|
|
shell: pip3 install docker docker-compose setuptools
|
2019-05-08 14:51:56 +03:00
|
|
|
|
|
|
|
- name: Add user to run docker-compose
|
|
|
|
user:
|
|
|
|
name: "{{ compose_service_user }}"
|
|
|
|
comment: user to run docker-compose
|
|
|
|
group: docker
|
|
|
|
createhome: yes
|
|
|
|
|
|
|
|
- name: Install auditd
|
|
|
|
apt:
|
|
|
|
name: auditd
|
|
|
|
update_cache: yes
|
|
|
|
|
|
|
|
- name: Configure auditd
|
|
|
|
blockinfile:
|
|
|
|
path: /etc/audit/audit.rules
|
2019-07-11 11:17:02 +03:00
|
|
|
block: |
|
2019-05-08 14:51:56 +03:00
|
|
|
-w /usr/bin/docker -p wa
|
|
|
|
-w /var/lib/docker -p wa
|
|
|
|
-w /etc/docker -p wa
|
|
|
|
-w /lib/systemd/system/docker.service -p wa
|
|
|
|
-w /lib/systemd/system/docker.socket -p wa
|
|
|
|
-w /etc/default/docker -p wa
|
|
|
|
-w /etc/docker/daemon.json -p wa
|
|
|
|
-w /usr/bin/docker-containerd -p wa
|
2019-07-11 11:17:02 +03:00
|
|
|
-w /usr/bin/docker-runc -p wa
|
2019-05-08 14:51:56 +03:00
|
|
|
notify: restart auditd
|
|
|
|
|
|
|
|
- name: Configure docker engine
|
|
|
|
copy:
|
|
|
|
src: daemon.json
|
2019-07-02 14:10:46 +03:00
|
|
|
dest: /etc/docker/
|
2019-05-08 14:51:56 +03:00
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: 0640
|
|
|
|
notify: restart docker
|