2 Commits

Author SHA1 Message Date
camille.prugnard
45334ef3c3 Refactor user creation tasks to allow multiple hosts with a list 2025-12-19 10:14:09 +01:00
camille.prugnard
c2693caf0e Fix wrong privs in case of list 2025-12-19 09:54:30 +01:00
2 changed files with 31 additions and 9 deletions

View File

@@ -4,7 +4,7 @@ Installs and manages Percona Server on Debian.
## Requirements
None.
- Ansible 10+
## Role Variables

View File

@@ -3,25 +3,47 @@
mysql_user:
name: "{{ item.name }}"
password: "{{ item.password }}"
host: "{{ item.host | default('%') }}"
priv: "{{ item.priv | default('*.*:USAGE') }}"
host: "{{ item.host }}"
priv: "{{ (item.priv | join('/')) if item.priv is iterable and item.priv is not string else (item.priv | default('*.*:USAGE')) }}"
plugin: "mysql_native_password"
state: present
login_user: root
login_password: "{{ percona_root_password }}"
loop: "{{ percona_users }}"
when: item.auth_plugin is defined and item.auth_plugin == 'mysql_native_password'
vars:
user_host_pairs: |
{%- set pairs = [] -%}
{%- for user in percona_users -%}
{%- if user.auth_plugin is defined and user.auth_plugin == 'mysql_native_password' -%}
{%- set hosts = [user.host | default('%')] if user.host is undefined or user.host is string else user.host -%}
{%- for host in hosts -%}
{%- set _ = pairs.append(user | combine({'host': host})) -%}
{%- endfor -%}
{%- endif -%}
{%- endfor -%}
{{ pairs }}
loop: "{{ user_host_pairs }}"
- name: percona | create users
mysql_user:
name: "{{ item.name }}"
host: "{{ item.host | default('%') }}"
priv: "{{ item.priv | default('*.*:USAGE') }}"
host: "{{ item.host }}"
priv: "{{ (item.priv | join('/')) if item.priv is iterable and item.priv is not string else (item.priv | default('*.*:USAGE')) }}"
plugin: caching_sha2_password
plugin_auth_string: "{{ item.password }}"
salt: "{{ percona_caching_sha2_password_salt }}"
state: present
login_user: root
login_password: "{{ percona_root_password }}"
loop: "{{ percona_users }}"
when: item.auth_plugin is not defined or item.auth_plugin == 'caching_sha2_password'
vars:
user_host_pairs: |
{%- set pairs = [] -%}
{%- for user in percona_users -%}
{%- if user.auth_plugin is not defined or user.auth_plugin == 'caching_sha2_password' -%}
{%- set hosts = [user.host | default('%')] if user.host is undefined or user.host is string else user.host -%}
{%- for host in hosts -%}
{%- set _ = pairs.append(user | combine({'host': host})) -%}
{%- endfor -%}
{%- endif -%}
{%- endfor -%}
{{ pairs }}
loop: "{{ user_host_pairs }}"