always create pidfile folder

add keycloak_service_runas feature flag
fix previous installs permissions
This commit is contained in:
Massimo Schiavon 2023-08-29 21:41:38 +02:00
commit 40c015d3e1
No known key found for this signature in database
GPG key ID: 5C896DA797460833
3 changed files with 16 additions and 9 deletions

View file

@ -53,20 +53,14 @@
group: "{{ keycloak_service_group }}"
mode: 0750
- name: Check pidfile folder
ansible.builtin.stat:
path: "{{ keycloak_service_pidfile | dirname }}"
register: keycloak_service_pidfile_stat
- name: Create pidfile folder
become: yes
become_user: root
ansible.builtin.file:
dest: "{{ keycloak_service_pidfile | dirname }}"
state: directory
owner: "{{ keycloak_service_user }}"
group: "{{ keycloak_service_group }}"
mode: "0750"
when: not keycloak_service_pidfile_stat.stat.exists
owner: "{{ keycloak_service_user if keycloak_service_runas else omit }}"
group: "{{ keycloak_service_group if keycloak_service_runas else omit }}"
mode: 0750
## check remote archive
- name: Set download archive path
@ -209,6 +203,12 @@
become: yes
changed_when: false
- name: Ensure permissions are correct on existing deploy
ansible.builtin.command: chown -R "{{ keycloak_service_user }}:{{ keycloak_service_group }}" "{{ keycloak.home }}"
when: keycloak_service_runas
become: yes
changed_when: false
# driver and configuration
- name: "Install {{ keycloak_jdbc_engine }} driver"
ansible.builtin.include_tasks: jdbc_driver.yml