feat: wire mysql delivery to awx callbacks
This commit is contained in:
+210
-132
@@ -1,56 +1,78 @@
|
||||
---
|
||||
- name: Preflight native MySQL delivery
|
||||
hosts: all
|
||||
- name: Native MySQL delivery
|
||||
hosts: "{{ target_hosts }}"
|
||||
become: true
|
||||
gather_facts: true
|
||||
any_errors_fatal: true
|
||||
vars:
|
||||
# --- identity ---
|
||||
mysql_instance: "{{ instance_name }}"
|
||||
mysql_version_value: "{{ mysql_version | default('8.0') }}"
|
||||
# 版本包映射:8.0 用 Ubuntu 24.04 自带源(精确锁版);8.4 用 MySQL 官方 APT 源的 LTS 组件
|
||||
# (noble 自带源无 8.4,官方源组件内即为该系列,不再锁小版本)。
|
||||
# 5.6/5.7 已官方 EOL 且 Ubuntu 24.04 无可用 apt 包,明确不纳入白名单。
|
||||
mysql_package_map:
|
||||
"8.0": "mysql-server=8.0.46-0ubuntu0.24.04.3"
|
||||
mysql_package_name: "{{ mysql_package_map[mysql_version_value] }}"
|
||||
"8.0":
|
||||
package: "mysql-server=8.0.46-0ubuntu0.24.04.3"
|
||||
repo_component: ""
|
||||
"8.4":
|
||||
package: "mysql-community-server"
|
||||
repo_component: "mysql-8.4-lts"
|
||||
mysql_package_name: "{{ (mysql_package_map[mysql_version_value] | default({})).package | default('') }}"
|
||||
mysql_repo_component: "{{ (mysql_package_map[mysql_version_value] | default({})).repo_component | default('') }}"
|
||||
|
||||
# --- platform-allocated inputs (safe fallbacks when not passed in) ---
|
||||
# 端口池 13306–13999:平台从池分配并传入;未传时兜底池首端口,占用探测在目标机执行。
|
||||
mysql_port_value: "{{ mysql_port | default(13306) | int }}"
|
||||
mysql_cpu_cores_value: "{{ cpu_cores | default(1) | int }}"
|
||||
mysql_memory_gb_value: "{{ memory_gb | default(2) | int }}"
|
||||
mysql_memory_mb_value: "{{ mysql_memory_gb_value | int * 1024 }}"
|
||||
mysql_storage_gb_value: "{{ storage_gb | default(20) | int }}"
|
||||
# GR 组通信端口:仅 mgr_3 使用,平台成对分配;兜底为 SQL 端口 +10000。
|
||||
mysql_gr_port_value: "{{ gr_port | default((mysql_port | default(13306) | int) + 10000) | int }}"
|
||||
# 数据盘挂载点:平台按白名单选定并传入;兜底 /data。
|
||||
mysql_data_disk: "{{ data_disk | default('/data') }}"
|
||||
|
||||
# --- resource quota (Go→AWX 契约单位保持 MB/GB,不擅改) ---
|
||||
mysql_memory_mb_value: "{{ memory_mb | default(4096) | int }}"
|
||||
mysql_storage_gb_value: "{{ storage_gb | default(50) | int }}"
|
||||
|
||||
# --- mount-point-agnostic layout: {data_disk}/mysql-delivery/{instance_id}/... ---
|
||||
mysql_base_dir: "{{ mysql_data_disk }}/mysql-delivery/{{ mysql_instance }}"
|
||||
mysql_install_dir: "/opt/mysql-delivery/{{ mysql_instance }}"
|
||||
mysql_data_dir: "{{ mysql_base_dir }}/data"
|
||||
mysql_log_dir: "{{ mysql_base_dir }}/logs"
|
||||
mysql_binlog_dir: "{{ mysql_base_dir }}/logs/binlog"
|
||||
mysql_redo_dir: "{{ mysql_base_dir }}/logs/redo"
|
||||
mysql_run_dir: "{{ mysql_base_dir }}/run"
|
||||
mysql_tmp_dir: "{{ mysql_base_dir }}/tmp"
|
||||
mysql_conf_dir: "{{ mysql_base_dir }}/conf"
|
||||
mysql_config_file: "{{ mysql_conf_dir }}/my.cnf"
|
||||
mysql_system_config_file: "/etc/mysql/mysql-delivery/{{ mysql_instance }}.cnf"
|
||||
mysql_param_template_value: "{{ param_template | default('default') }}"
|
||||
mysql_timezone_value: "{{ timezone | default('+08:00') }}"
|
||||
mysql_lower_case_table_names_value: "{{ lower_case_table_names | default(1) | int }}"
|
||||
mysql_character_set_value: "{{ character_set | default('utf8mb4') }}"
|
||||
mysql_collation_value: "{{ collation | default('utf8mb4_general_ci') }}"
|
||||
mysql_max_connections_value: "{{ max_connections | default('auto') }}"
|
||||
mysql_redo_log_capacity_value: "{{ innodb_redo_log_capacity | default('auto') }}"
|
||||
mysql_flush_log_at_trx_commit_value: "{{ innodb_flush_log_at_trx_commit | default(1) | int }}"
|
||||
mysql_sync_binlog_value: "{{ sync_binlog | default(1) | int }}"
|
||||
mysql_io_capacity_value: "{{ innodb_io_capacity | default(2000) | int }}"
|
||||
mysql_long_query_time_value: "{{ long_query_time | default(1) }}"
|
||||
mysql_binlog_expire_logs_seconds_value: "{{ binlog_expire_logs_seconds | default(604800) | int }}"
|
||||
mysql_max_binlog_size_value: "{{ max_binlog_size | default('256M') }}"
|
||||
# socket/pid 走 /run tmpfs(重启自动清理),由 systemd RuntimeDirectory 创建。
|
||||
mysql_run_dir: "/run/mysql-delivery-{{ mysql_instance }}"
|
||||
mysql_config_file: "/etc/mysql/mysql-delivery/{{ mysql_instance }}.cnf"
|
||||
|
||||
# --- database config (user form, with doc default baselines) ---
|
||||
mysql_timezone: "{{ timezone | default('+08:00') }}"
|
||||
mysql_lower_case_table_names: "{{ lower_case_table_names | default(1) | int }}"
|
||||
mysql_character_set: "{{ character_set | default('utf8mb4') }}"
|
||||
mysql_collation: "{{ collation | default('utf8mb4_general_ci') }}"
|
||||
|
||||
# --- advanced params (overridable; default baseline assumes SSD for io_capacity) ---
|
||||
mysql_flush_log_at_trx_commit: "{{ innodb_flush_log_at_trx_commit | default(1) | int }}"
|
||||
mysql_sync_binlog: "{{ sync_binlog | default(1) | int }}"
|
||||
mysql_io_capacity: "{{ innodb_io_capacity | default(2000) | int }}"
|
||||
mysql_long_query_time: "{{ long_query_time | default(1) }}"
|
||||
mysql_binlog_expire_logs_seconds: "{{ binlog_expire_logs_seconds | default(604800) | int }}"
|
||||
mysql_max_binlog_size: "{{ max_binlog_size | default('256M') }}"
|
||||
mgr_group_name: "{{ group_replication_group_name | default('aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa') }}"
|
||||
|
||||
# --- expected node count per topology ---
|
||||
mysql_expected_hosts: "{{ {'standalone': 1, 'primary_replica': 2, 'mgr_3': 3}[topology | default('standalone')] }}"
|
||||
|
||||
# --- secrets (injected via environment) ---
|
||||
mysql_root_password_value: "{{ lookup('ansible.builtin.env', 'XINFRA_MYSQL_ROOT_PASSWORD') }}"
|
||||
mysql_admin_password_value: "{{ lookup('ansible.builtin.env', 'XINFRA_MYSQL_ADMIN_PASSWORD') }}"
|
||||
|
||||
# --- platform callback ---
|
||||
delivery_callback_url_value: "{{ delivery_callback_url | default('') }}"
|
||||
delivery_callback_token_value: "{{ delivery_callback_token | default('') }}"
|
||||
delivery_callback_enabled: "{{ (delivery_callback_url_value | length > 0) and (delivery_callback_token_value | length > 0) }}"
|
||||
delivery_awx_job_id: "{{ awx_job_id | default('') }}"
|
||||
mysql_root_password_value: "{{ lookup('ansible.builtin.env', 'XINFRA_MYSQL_ROOT_PASSWORD') }}"
|
||||
mysql_admin_password_value: "{{ lookup('ansible.builtin.env', 'XINFRA_MYSQL_ADMIN_PASSWORD') }}"
|
||||
mysql_single_quote: "'"
|
||||
mysql_double_single_quote: "''"
|
||||
mysql_root_password_sql: "{{ mysql_root_password_value | replace(mysql_single_quote, mysql_double_single_quote) }}"
|
||||
mysql_admin_password_sql: "{{ mysql_admin_password_value | replace(mysql_single_quote, mysql_double_single_quote) }}"
|
||||
mysql_topology_value: "{{ topology | default('standalone') }}"
|
||||
|
||||
pre_tasks:
|
||||
- name: Notify precheck started
|
||||
ansible.builtin.uri:
|
||||
@@ -70,73 +92,85 @@
|
||||
failed_when: false
|
||||
no_log: true
|
||||
|
||||
- name: Validate prototype parameters
|
||||
- name: Validate delivery parameters
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- mysql_topology_value == 'standalone'
|
||||
- topology in ['standalone', 'primary_replica', 'mgr_3']
|
||||
- mysql_instance is match('^[a-z0-9][a-z0-9-]{0,62}$')
|
||||
- mysql_version_value in mysql_package_map
|
||||
- mysql_data_disk is match('^/.+')
|
||||
- mysql_data_disk != '/'
|
||||
- "'..' not in mysql_data_disk"
|
||||
- "'//' not in mysql_data_disk"
|
||||
- (mysql_port_value | int) >= 13306
|
||||
- (mysql_port_value | int) <= 13999
|
||||
- (mysql_cpu_cores_value | int) in [1, 2, 4, 8, 16]
|
||||
- (mysql_memory_mb_value | int) >= 1024
|
||||
- (mysql_memory_mb_value | int) >= 2048
|
||||
- (mysql_memory_mb_value | int) <= 65536
|
||||
- (mysql_storage_gb_value | int) >= 20
|
||||
- (mysql_storage_gb_value | int) <= 2000
|
||||
- mysql_data_disk in ['/data', '/disk1', '/mnt/vol-1']
|
||||
- mysql_param_template_value in ['default', 'high_performance', 'high_safety']
|
||||
- mysql_timezone_value in ['SYSTEM', '+08:00', '+00:00', 'Asia/Shanghai']
|
||||
- (mysql_lower_case_table_names_value | int) in [0, 1]
|
||||
- mysql_character_set_value in ['utf8mb4', 'utf8', 'gbk', 'latin1']
|
||||
- mysql_collation_value is match('^(utf8mb4_(general_ci|unicode_ci|0900_ai_ci)|utf8_general_ci|gbk_chinese_ci|latin1_swedish_ci)$')
|
||||
- mysql_max_connections_value == 'auto' or mysql_max_connections_value in ['200', '500', '1000', '2000', '4000', '8000', '16000']
|
||||
- mysql_redo_log_capacity_value in ['auto', '128M', '256M', '512M', '1G']
|
||||
- (mysql_flush_log_at_trx_commit_value | int) in [0, 1, 2]
|
||||
- (mysql_sync_binlog_value | int) in [0, 1]
|
||||
- (mysql_io_capacity_value | int) in [200, 2000, 5000]
|
||||
- (mysql_long_query_time_value | float) in [0.5, 1.0, 2.0, 5.0, 10.0]
|
||||
- (mysql_binlog_expire_logs_seconds_value | int) in [86400, 259200, 604800, 1209600]
|
||||
- mysql_max_binlog_size_value in ['128M', '256M', '512M', '1G']
|
||||
fail_msg: The first machine prototype only supports safe standalone parameters
|
||||
|
||||
- name: Validate MySQL delivery secrets
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (mysql_lower_case_table_names | int) in [0, 1]
|
||||
- mysql_root_password_value | length >= 16
|
||||
- mysql_admin_password_value | length >= 16
|
||||
fail_msg: XINFRA_MYSQL_ROOT_PASSWORD and XINFRA_MYSQL_ADMIN_PASSWORD must be configured and at least 16 characters long
|
||||
fail_msg: >-
|
||||
Delivery parameters out of the supported target-state whitelist
|
||||
(topology / version-package-map / port pool 13306-13999 / memory 2-64G / storage 20-2000G).
|
||||
quiet: true
|
||||
no_log: true
|
||||
|
||||
- name: Validate topology host count
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- ansible_play_hosts_all | length == 1
|
||||
fail_msg: The selected topology does not match the target host count
|
||||
- (ansible_play_hosts_all | length | int) == (mysql_expected_hosts | int)
|
||||
fail_msg: "topology={{ topology }} expects {{ mysql_expected_hosts }} host(s), got {{ ansible_play_hosts_all | length }}"
|
||||
run_once: true
|
||||
|
||||
- name: Check port ownership
|
||||
ansible.builtin.shell: |
|
||||
set -o pipefail
|
||||
if ss -lntH "sport = :{{ mysql_port_value }}" | grep -q .; then
|
||||
systemctl is-active --quiet "mysql-delivery@{{ mysql_instance }}.service"
|
||||
fi
|
||||
args:
|
||||
- name: Probe target-host port occupancy (SQL + GR)
|
||||
# cmd 字典形式不经过 free-form split_args 解析,避免引号/Jinja 块导致的解析失败。
|
||||
ansible.builtin.shell:
|
||||
cmd: |
|
||||
set -o pipefail
|
||||
{% for port in mysql_probe_ports %}
|
||||
if ss -lntH "sport = :{{ port }}" | grep -q .; then
|
||||
# already listening: only tolerated when owned by this instance service
|
||||
if ! systemctl is-active --quiet "mysql-delivery@{{ mysql_instance }}.service"; then
|
||||
echo "port {{ port }} already in use on target host" >&2
|
||||
exit 3
|
||||
fi
|
||||
fi
|
||||
{% endfor %}
|
||||
executable: /bin/bash
|
||||
vars:
|
||||
mysql_probe_ports: "{{ [mysql_port_value, mysql_gr_port_value] if topology == 'mgr_3' else [mysql_port_value] }}"
|
||||
changed_when: false
|
||||
|
||||
- name: Read currently available memory
|
||||
- name: Read currently available memory (point-in-time guard)
|
||||
ansible.builtin.shell: awk '/^MemAvailable:/ { print int($2 / 1024) }' /proc/meminfo
|
||||
args:
|
||||
executable: /bin/bash
|
||||
register: mysql_available_memory
|
||||
changed_when: false
|
||||
|
||||
- name: Check available memory and disk
|
||||
- name: Read available bytes from the backing filesystem
|
||||
ansible.builtin.shell:
|
||||
cmd: |
|
||||
set -euo pipefail
|
||||
candidate="{{ mysql_data_disk }}"
|
||||
while [ ! -e "$candidate" ] && [ "$candidate" != "/" ]; do
|
||||
candidate="$(dirname "$candidate")"
|
||||
done
|
||||
df -P -B1 "$candidate" | awk 'NR == 2 { print $4 }'
|
||||
executable: /bin/bash
|
||||
register: mysql_available_disk_bytes
|
||||
changed_when: false
|
||||
|
||||
- name: Check available memory and data-disk space
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (mysql_available_memory.stdout | int) >= (mysql_memory_mb_value | int)
|
||||
- (ansible_mounts | selectattr('mount', 'equalto', mysql_data_disk) | map(attribute='size_available') | first | default(0) | int) >= (mysql_storage_gb_value | int) * 1073741824
|
||||
fail_msg: Target host does not have enough available memory or disk
|
||||
- (mysql_available_disk_bytes.stdout | int) >= (mysql_storage_gb_value | int) * 1073741824
|
||||
fail_msg: >-
|
||||
Target host lacks memory or free space on {{ mysql_data_disk }};
|
||||
host-wide Σ-quota budgeting is the platform's responsibility, this is a last-resort guard.
|
||||
|
||||
- name: Notify precheck completed
|
||||
ansible.builtin.uri:
|
||||
@@ -175,13 +209,46 @@
|
||||
failed_when: false
|
||||
no_log: true
|
||||
|
||||
- name: Detect an existing Ubuntu MySQL package
|
||||
ansible.builtin.command: dpkg-query -W mysql-server
|
||||
- name: Detect an existing MySQL server package
|
||||
ansible.builtin.command: dpkg-query -W -f '${Package}=${Version}\n' mysql-server mysql-community-server
|
||||
register: mysql_package_before
|
||||
failed_when: false
|
||||
changed_when: false
|
||||
|
||||
- name: Install Ubuntu MySQL package
|
||||
- name: Resolve the installed MySQL server version
|
||||
ansible.builtin.set_fact:
|
||||
mysql_installed_version: >-
|
||||
{{ (mysql_package_before.stdout_lines | select('search', '=') | list
|
||||
| first | default('')).split('=') | last }}
|
||||
|
||||
# /usr 下的 mysqld/mysql 二进制全机共享,一台主机只能承载一个 MySQL 版本系列。
|
||||
- name: Enforce host-level MySQL series consistency
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- mysql_installed_version == '' or mysql_installed_version.startswith(mysql_version_value ~ '.')
|
||||
fail_msg: >-
|
||||
Host already runs MySQL {{ mysql_installed_version }} but {{ mysql_version_value }} was requested;
|
||||
native binaries under /usr are shared host-wide, so one host serves exactly one MySQL series.
|
||||
|
||||
- name: Install the MySQL APT repository signing key
|
||||
ansible.builtin.get_url:
|
||||
url: https://repo.mysql.com/RPM-GPG-KEY-mysql-2023
|
||||
dest: /etc/apt/keyrings/mysql.asc
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
when: mysql_repo_component != ''
|
||||
|
||||
- name: Configure the MySQL APT repository component
|
||||
ansible.builtin.apt_repository:
|
||||
repo: >-
|
||||
deb [signed-by=/etc/apt/keyrings/mysql.asc]
|
||||
http://repo.mysql.com/apt/ubuntu {{ ansible_distribution_release }} {{ mysql_repo_component }}
|
||||
filename: xinfra-mysql-delivery
|
||||
state: present
|
||||
when: mysql_repo_component != ''
|
||||
|
||||
- name: Install the MySQL server package
|
||||
ansible.builtin.apt:
|
||||
name: "{{ mysql_package_name }}"
|
||||
state: present
|
||||
@@ -193,14 +260,14 @@
|
||||
name: mysql.service
|
||||
state: stopped
|
||||
enabled: false
|
||||
when: mysql_package_before.rc != 0
|
||||
when: mysql_installed_version == ''
|
||||
|
||||
- name: Check for the bundled MySQL AppArmor profile
|
||||
ansible.builtin.stat:
|
||||
path: /etc/apparmor.d/usr.sbin.mysqld
|
||||
register: mysql_apparmor_profile
|
||||
|
||||
- name: Allow the delivery data and run paths in the MySQL AppArmor profile
|
||||
- name: Authorize the delivery paths in the MySQL AppArmor profile
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/apparmor.d/local/usr.sbin.mysqld
|
||||
owner: root
|
||||
@@ -210,6 +277,8 @@
|
||||
# Managed by XINFRA MySQL delivery - grant per-instance native paths
|
||||
{{ mysql_data_disk }}/mysql-delivery/ r,
|
||||
{{ mysql_data_disk }}/mysql-delivery/** rwk,
|
||||
/run/mysql-delivery-*/ rw,
|
||||
/run/mysql-delivery-*/** rwk,
|
||||
when: mysql_apparmor_profile.stat.exists
|
||||
register: mysql_apparmor_local
|
||||
|
||||
@@ -218,7 +287,7 @@
|
||||
when: mysql_apparmor_profile.stat.exists and mysql_apparmor_local.changed
|
||||
changed_when: true
|
||||
|
||||
- name: Create instance directories
|
||||
- name: Create instance directories (mount-point-agnostic layout)
|
||||
ansible.builtin.file:
|
||||
path: "{{ item.path }}"
|
||||
state: directory
|
||||
@@ -228,6 +297,7 @@
|
||||
loop:
|
||||
- { path: /etc/mysql/mysql-delivery, owner: root, group: mysql, mode: '0750' }
|
||||
- { path: "{{ mysql_install_dir }}", owner: root, group: root, mode: '0755' }
|
||||
- { path: "{{ mysql_data_disk }}", owner: root, group: root, mode: '0755' }
|
||||
- { path: "{{ mysql_base_dir }}", owner: mysql, group: mysql, mode: '0750' }
|
||||
- { path: "{{ mysql_data_dir }}", owner: mysql, group: mysql, mode: '0750' }
|
||||
- { path: "{{ mysql_log_dir }}", owner: mysql, group: mysql, mode: '0750' }
|
||||
@@ -235,7 +305,6 @@
|
||||
- { path: "{{ mysql_redo_dir }}", owner: mysql, group: mysql, mode: '0750' }
|
||||
- { path: "{{ mysql_run_dir }}", owner: mysql, group: mysql, mode: '0755' }
|
||||
- { path: "{{ mysql_tmp_dir }}", owner: mysql, group: mysql, mode: '0750' }
|
||||
- { path: "{{ mysql_conf_dir }}", owner: root, group: mysql, mode: '0750' }
|
||||
|
||||
- name: Link native binaries into the instance directory
|
||||
ansible.builtin.file:
|
||||
@@ -287,9 +356,36 @@
|
||||
ansible.builtin.set_fact:
|
||||
mysql_node_index: "{{ ansible_play_hosts_all.index(inventory_hostname) }}"
|
||||
mysql_node_role: >-
|
||||
{{ 'standalone' if mysql_topology_value == 'standalone' else
|
||||
{{ 'standalone' if topology == 'standalone' else
|
||||
('primary' if ansible_play_hosts_all.index(inventory_hostname) == 0 else
|
||||
('replica' if mysql_topology_value == 'primary_replica' else 'mgr')) }}
|
||||
('replica' if topology == 'primary_replica' else 'mgr')) }}
|
||||
# host-wide unique: platform may pass explicit mysql_server_id; otherwise derive
|
||||
# port + node index (ports are unique per host in the pool model).
|
||||
mysql_server_id_value: >-
|
||||
{{ mysql_server_id | default((mysql_port_value | int)
|
||||
+ (ansible_play_hosts_all.index(inventory_hostname))) | int }}
|
||||
|
||||
- name: Resolve memory tier (GB)
|
||||
ansible.builtin.set_fact:
|
||||
mysql_memory_gb: "{{ ((mysql_memory_mb_value | int) // 1024) | int }}"
|
||||
|
||||
- name: Resolve linkage-derived defaults (illustrative tiers, pending hardware calibration)
|
||||
ansible.builtin.set_fact:
|
||||
mysql_max_connections: >-
|
||||
{{ (max_connections | int) if (max_connections is defined and (max_connections | string) != 'auto')
|
||||
else (200 if (mysql_memory_gb | int) <= 2
|
||||
else 500 if (mysql_memory_gb | int) <= 4
|
||||
else 1000 if (mysql_memory_gb | int) <= 8
|
||||
else 2000 if (mysql_memory_gb | int) <= 16
|
||||
else 4000 if (mysql_memory_gb | int) <= 32
|
||||
else 8000 if (mysql_memory_gb | int) <= 64
|
||||
else 16000) }}
|
||||
mysql_redo_capacity: >-
|
||||
{{ innodb_redo_log_capacity if (innodb_redo_log_capacity is defined and (innodb_redo_log_capacity | string) != 'auto')
|
||||
else ('128M' if (mysql_memory_gb | int) <= 4
|
||||
else '256M' if (mysql_memory_gb | int) <= 16
|
||||
else '512M' if (mysql_memory_gb | int) <= 32
|
||||
else '1G') }}
|
||||
|
||||
- name: Write instance configuration
|
||||
ansible.builtin.template:
|
||||
@@ -300,13 +396,6 @@
|
||||
mode: '0640'
|
||||
notify: Restart MySQL delivery instance
|
||||
|
||||
- name: Link instance configuration into system path
|
||||
ansible.builtin.file:
|
||||
src: "{{ mysql_config_file }}"
|
||||
dest: "{{ mysql_system_config_file }}"
|
||||
state: link
|
||||
force: true
|
||||
|
||||
- name: Initialize the data directory once
|
||||
ansible.builtin.command:
|
||||
argv:
|
||||
@@ -316,7 +405,6 @@
|
||||
- --user=mysql
|
||||
args:
|
||||
creates: "{{ mysql_data_dir }}/auto.cnf"
|
||||
no_log: true
|
||||
|
||||
- name: Install the delivery systemd template
|
||||
ansible.builtin.copy:
|
||||
@@ -327,30 +415,10 @@
|
||||
mode: '0644'
|
||||
register: mysql_systemd_unit
|
||||
|
||||
- name: Create per-instance systemd override directory
|
||||
ansible.builtin.file:
|
||||
path: "/etc/systemd/system/mysql-delivery@{{ mysql_instance }}.service.d"
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0755'
|
||||
|
||||
- name: Write per-instance systemd resource limits
|
||||
ansible.builtin.copy:
|
||||
dest: "/etc/systemd/system/mysql-delivery@{{ mysql_instance }}.service.d/resources.conf"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
content: |
|
||||
[Service]
|
||||
CPUQuota={{ mysql_cpu_cores_value | int * 100 }}%
|
||||
register: mysql_systemd_resources
|
||||
notify: Restart MySQL delivery instance
|
||||
|
||||
- name: Reload systemd units
|
||||
ansible.builtin.systemd_service:
|
||||
daemon_reload: true
|
||||
when: mysql_systemd_unit.changed or mysql_systemd_resources.changed
|
||||
when: mysql_systemd_unit.changed
|
||||
|
||||
- name: Start the MySQL delivery instance
|
||||
ansible.builtin.systemd_service:
|
||||
@@ -364,32 +432,33 @@
|
||||
timeout: 60
|
||||
|
||||
- name: Configure local administrative accounts
|
||||
ansible.builtin.shell: |
|
||||
set -euo pipefail
|
||||
client_file="$(mktemp)"
|
||||
sql_file="$(mktemp)"
|
||||
trap 'rm -f "$client_file" "$sql_file"' EXIT
|
||||
chmod 600 "$client_file" "$sql_file"
|
||||
cat >"$client_file" <<'EOF'
|
||||
[client]
|
||||
user=root
|
||||
password={{ mysql_root_password_value }}
|
||||
socket={{ mysql_run_dir }}/mysql.sock
|
||||
EOF
|
||||
if ! /usr/bin/mysql --defaults-extra-file="$client_file" -e 'SELECT 1' >/dev/null 2>&1; then
|
||||
# cmd 字典形式不经过 free-form split_args 解析,heredoc SQL 中的奇数个单引号才不会报错。
|
||||
ansible.builtin.shell:
|
||||
cmd: |
|
||||
set -euo pipefail
|
||||
client_file="$(mktemp)"
|
||||
sql_file="$(mktemp)"
|
||||
trap 'rm -f "$client_file" "$sql_file"' EXIT
|
||||
chmod 600 "$client_file" "$sql_file"
|
||||
cat >"$client_file" <<'EOF'
|
||||
[client]
|
||||
user=root
|
||||
password={{ mysql_root_password_value }}
|
||||
socket={{ mysql_run_dir }}/mysql.sock
|
||||
EOF
|
||||
if ! /usr/bin/mysql --defaults-extra-file="$client_file" -e 'SELECT 1' >/dev/null 2>&1; then
|
||||
cat >"$sql_file" <<'EOF'
|
||||
ALTER USER 'root'@'localhost' IDENTIFIED BY '{{ mysql_root_password_value | replace("'", "''") }}';
|
||||
EOF
|
||||
/usr/bin/mysql --protocol=socket --socket={{ mysql_run_dir }}/mysql.sock -uroot <"$sql_file"
|
||||
fi
|
||||
cat >"$sql_file" <<'EOF'
|
||||
ALTER USER 'root'@'localhost' IDENTIFIED BY '{{ mysql_root_password_sql }}';
|
||||
EOF
|
||||
/usr/bin/mysql --protocol=socket --socket={{ mysql_run_dir }}/mysql.sock -uroot <"$sql_file"
|
||||
fi
|
||||
cat >"$sql_file" <<'EOF'
|
||||
CREATE USER IF NOT EXISTS 'xinfra_admin'@'%' IDENTIFIED BY '{{ mysql_admin_password_sql }}';
|
||||
ALTER USER 'xinfra_admin'@'%' IDENTIFIED BY '{{ mysql_admin_password_sql }}';
|
||||
GRANT ALL PRIVILEGES ON *.* TO 'xinfra_admin'@'%' WITH GRANT OPTION;
|
||||
FLUSH PRIVILEGES;
|
||||
EOF
|
||||
/usr/bin/mysql --defaults-extra-file="$client_file" <"$sql_file"
|
||||
args:
|
||||
CREATE USER IF NOT EXISTS 'xinfra_admin'@'%' IDENTIFIED BY '{{ mysql_admin_password_value | replace("'", "''") }}';
|
||||
ALTER USER 'xinfra_admin'@'%' IDENTIFIED BY '{{ mysql_admin_password_value | replace("'", "''") }}';
|
||||
GRANT ALL PRIVILEGES ON *.* TO 'xinfra_admin'@'%' WITH GRANT OPTION;
|
||||
FLUSH PRIVILEGES;
|
||||
EOF
|
||||
/usr/bin/mysql --defaults-extra-file="$client_file" <"$sql_file"
|
||||
executable: /bin/bash
|
||||
changed_when: false
|
||||
no_log: true
|
||||
@@ -454,6 +523,15 @@
|
||||
failed_when: false
|
||||
no_log: true
|
||||
|
||||
- name: Note pending HA runtime orchestration
|
||||
ansible.builtin.debug:
|
||||
msg: >-
|
||||
topology={{ topology }} deployed with HA-ready config (GTID/binlog/relay/GR settings in place),
|
||||
but replication wiring (CHANGE REPLICATION SOURCE) and Group Replication bootstrap
|
||||
(START GROUP_REPLICATION) are not yet automated — nodes start config-ready only.
|
||||
when: topology != 'standalone'
|
||||
run_once: true
|
||||
|
||||
- name: Notify platform registration handoff
|
||||
ansible.builtin.uri:
|
||||
url: "{{ delivery_callback_url_value }}"
|
||||
|
||||
Reference in New Issue
Block a user