Commit b2ce138a authored by Robin Sonnabend's avatar Robin Sonnabend
Browse files

Only setup backup when rsnapshot is configured, don't use password for root auth

parent ee8cddd9
Pipeline #3257 passed with stage
in 28 seconds
...@@ -24,56 +24,41 @@ ...@@ -24,56 +24,41 @@
state: started state: started
enabled: true enabled: true
- name: ensure the mysql root user exists and has the correct password - name: setup mysql backups with rsnapshot
mysql_user: when: '"servers_rsnapshot" in group_names'
name: root block:
password: "{{ mysql_root_password }}" - name: ensure a read-only mysql user for backups exists
login_user: root mysql_user:
login_password: "{{ mysql_root_password }}" name: "{{ mysql_backup_user }}"
register: mysql_root_creation_result password: "{{ mysql_backup_password }}"
no_log: true priv: "*.*:SELECT,LOCK TABLES"
ignore_errors: true no_log: true
- name: initialize the mysql root user - name: ensure the backup procedure can access the backup password
mysql_user: template:
name: root src: my.cnf
password: "{{ mysql_root_password }}" dest: "/root/.mysql-{{ mysql_backup_user }}.cnf"
no_log: true owner: root
when: mysql_root_creation_result is failed group: root
mode: '0600'
- name: ensure a read-only mysql user for backups exists - name: deploy the mysql backup script
mysql_user: template:
name: "{{ mysql_backup_user }}" src: mysqlbackup.sh
password: "{{ mysql_backup_password }}" dest: /usr/local/bin/
login_user: root owner: root
login_password: "{{ mysql_root_password }}" group: root
priv: "*.*:SELECT,LOCK TABLES" mode: '0755'
- name: ensure the backup procedure can access the backup password - name: ensure we backup all the mysql databases with rsnapshot
template: copy:
src: my.cnf src: rsnapshot.conf
dest: "/root/.mysql-{{ mysql_backup_user }}.cnf" dest: /etc/rsnapshot.d/mysql.conf
owner: root owner: root
group: root group: root
mode: '0600' mode: '0644'
- name: deploy the mysql backup script - name: remove obsolete crontab
template: file:
src: mysqlbackup.sh path: /etc/cron.d/mysql-snapshot
dest: /usr/local/bin/ state: absent
owner: root
group: root
mode: '0755'
- name: ensure we backup all the mysql databases with rsnapshot
copy:
src: rsnapshot.conf
dest: /etc/rsnapshot.d/mysql.conf
owner: root
group: root
mode: '0644'
- name: remove obsolete crontab
file:
path: /etc/cron.d/mysql-snapshot
state: absent
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment