diff --git a/roles/services/defaults/main.yaml b/roles/services/defaults/main.yaml index 6c51a67..ef1a3d9 100644 --- a/roles/services/defaults/main.yaml +++ b/roles/services/defaults/main.yaml @@ -8,7 +8,6 @@ mariadb_requeriments: certificates: - { content: '{{ ca_mysql }}', dest: '/etc/mysql/ca.pem', mode: 'u=rw,g=r,o=r' } - { content: '{{ cert_mysql }}', dest: '/etc/mysql/cert.pem', mode: 'u=rw,g=r,o=r' } - - { content: '{{ private_mysql }}', dest: '/etc/mysql/key.pem', mode: 'u=rw,g=,o=' } required_directories: - { path: /mnt/local-backup, owner: root, group: root, mode: 'u=rwx,g=rx,o=rx' } - { path: /mnt/mysqlbin, owner: root, group: root, mode: 'u=rwx,g=rx,o=rx' } diff --git a/roles/services/tasks/mariadb.yml b/roles/services/tasks/mariadb.yml index 64c4198..d56dd94 100644 --- a/roles/services/tasks/mariadb.yml +++ b/roles/services/tasks/mariadb.yml @@ -1,5 +1,4 @@ # Revisar /root/scripts/check-memory.sh --> No es óptimo hacer lo que hace ese programa -# Ver como lanzar el mysqltuner.pl # Revisar la tarea del cron tambien /root/scripts/scheduler-log.sh - name: Ensure Install requirements for MariaDB repository setup script @@ -81,6 +80,14 @@ loop: "{{ certificates }}" notify: restart-mariadb +- name: Configure MySQL master cert + copy: + content: "{{ lookup(passbolt, 'private_mysql', folder_parent_id=passbolt_folder).description }}" + dest: /etc/mysql/key.pem + owner: mysql + group: mysql + mode: u=rw,g=,o= + - name: Set MariaDB custom configuration copy: src: "{{ item }}"