uan_shadowThe uan_shadow role configures the root password on UAN nodes.
The root password hash has to be installed in HashiCorp Vault at secret/uan root_password.
Available variables are in the following list, including default values (see defaults/main.yml):
uan_vault_urlThe URL for the HashiCorp Vault
Example:
uan_vault_url: "http://cray-vault.vault:8200"
uan_vault_role_fileThe required Kubernetes role file for HashiCorp Vault access.
Example:
uan_vault_role_file: /var/run/secrets/kubernetes.io/serviceaccount/namespace
uan_vault_jwt_fileThe path to the required Kubernetes token file for HashiCorp Vault access.
Example:
uan_vault_jwt_file: /var/run/secrets/kubernetes.io/serviceaccount/token
uan_vault_pathThe path to use for storing data for UANs in HashiCorp Vault.
Example:
uan_vault_path: secret/uan
uan_vault_keyThe key used for storing the root password in HashiCorp Vault.
Example:
uan_vault_key: root_password
None.
- hosts: Application_UAN
roles:
- { role: uan_shadow }
This role is included in the UAN site.yml play.