Vendor Galaxy Roles and Collections
Some checks failed
/ Ansible Lint (push) Failing after 5m45s
/ Ansible Lint (pull_request) Failing after 4m59s

This commit is contained in:
Stefan Bethke 2026-02-06 22:07:16 +01:00
commit 2aed20393f
3553 changed files with 387444 additions and 2 deletions

View file

@ -0,0 +1,21 @@
debops.owncloud - Install and manage ownCloud instances
Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
Copyright (C) 2015-2022 Robin Schneider <ypid@riseup.net>
Copyright (C) 2015-2022 DebOps <https://debops.org/>
SPDX-License-Identifier: GPL-3.0-only
This Ansible role is part of DebOps.
DebOps is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License version 3, as
published by the Free Software Foundation.
DebOps is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with DebOps. If not, see https://www.gnu.org/licenses/.

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,73 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2
mQENBFIaurIBCADicvh/agXMz4pI4eXbVCOjvCXjG2dlrqVHGDe6zTsKGvvhuXBW
uP0fyaTMWbU910Mqe0uiNLYyk45O3/YsUDLSpgqXl1sQ2DG1hPnKne5PeoSRF5Gb
HPIJPQIg5HQk5PYbFZFYZa1a3qRW52pH91dNyZO2urA1qVNLxEp69VDoTHqg74IU
dhkoLfO1burfg6mKhgDcCFN6S/WtqiYNAGDu1GvY/+gZoCAz5Nv+8smM6/rlk/oi
t+TPU0pYkrkoa85KjNFYy5Dm7ObBVhA+QYWnJfKXdJKE/tFsVcUhmc672rZsJkYg
5qfyRtHNRhYhwLd2HyRDbbg6dY8TIePGDzEnABEBAAG0KW93bkNsb3VkIGJ1aWxk
IHNlcnZpY2UgPG9ic3J1bkBsb2NhbGhvc3Q+iQE/BBMBCAApAhsDBwsJCAcDAgEG
FQgCCQoLBBYCAwECHgECF4AFAluAUoIFCRLLmVAACgkQR65/ckebyUvcCwf/WKrS
sk7O901UyI3809kAs7eLRdPAKoAHLyymbn9/dLAgPiHjdeBryb9Jlu0VMeGoE0RL
2F3ls59rWfQvs4GP0TaS9O5A4L/o9kS6G9RRMkRqjjF/idPytI2BCDI98k5VY1AK
Wfx+IG2Vl2Z7auiTOCC/Q/e5Sof8BuSl94aC3sl3gBbR4Gvs7sZI3RKiDneftfLL
A3ciJEKaYUkftFkrBOXLy574gM9Ip0Oc0ntEtf+rB3dljzfc05ifapTYjswvHhol
SNeT6GFbDSqUOnKTPMWUZtKgkKZTJk1CnAJfgY9vbH4h65wAZg3L3Slc4PByZ/07
hHL3Cq7hE4zVkBS2bLkBDQRSGrqyAQgAsZJT/D8EHpjVPsn2ASo4vUGOIeiyLfQe
IAWfK65s69uJGlHvQrW1HJSIpobEXCwdVrmxadHDyl0CbEqnppM5ePF2Rc8JqOB+
WuK2tVloboVHHeF8N1PAmsrtQpKvUTbdKKbFBQ1WbTG8rykFV3UBbQDZXRIi6H07
KO0yf15LP95PHSSH7JZIG+IQibHtn/6zi3J40fFsuOp7QxrC0d1QobkBQPOxrtsy
tts+4LWnVewnYfjy+9mlJNIWSHUxMCvZLcAS8u5LO3UD0e3y/RJfo0yAjHNPs3BH
hHAXE1ir3RbdQQogAOjxgNdr7tU0ybaveEYAPDjHtvkLuQznaYxx7wARAQABiQEl
BBgBCAAPAhsMBQJbgFLeBQkSy5msAAoJEEeuf3JHm8lLWPYH/A5OMEcSBus9HaA+
cMMjTnt7prdHaLSu036s1ejw7ne1kS+2bDd4woWYzMzLQLwRFSi6Vgfz7Svxdbwc
vLU+R5SsmjugzxIdi46Ge/+XuhJLxI1iQrK8BW/+YNATyvJpMR/gA2K1Jnqz6yOd
GyKUcGFWR0l9SPh1eXYWTXlyM86Zu8v8Cy+PhUZeX0AK9eQbt5U5uoiQMi291Jt6
Qr+c7YVe2f2CVfkMYCzHbA8eD2ymlyjw1fpHqX+ds3lFPRGThEoOwdw9oCRbmUvw
raTJPAm40R0xPjj06AoiYeaYNvcxlEZJATMe5ROkHDJbaRCaF3JTw3QpN5de0f/x
BBpfkc+5Ay4EUhq7fBEIAKM3GnOm+lkGXs8QinFcG7DwRpk91H15jr8QFYAr3hUi
Lt4JtH3fNoabxQNXkftmtZXfiAcFFRrFGQkAazaE3ugkFNWLgXkIFrHfPdsar0dJ
iCYlKU/DVxduSU74cIDC2YACWyr6KrgD4LinR/W6WEHpadH7KPNWL2DXIW9Fi+Xr
TbkZnzpOPiUII6DcRe59ow3B8p3YMnr821aqjaPHSJoJoxgO4WPQTxCTQJQY8keT
p3Kpt1guxgq1IZiXsqW+DwifkxrxBcSqdcFNNd3xhuDDAHt5PHucMt2dVxvQPWlk
Nu1IozQZ6hLlJ8j5nKpnunh7bDLxZZDFupyX05UU0KMBAP/bxsTSXL2gZDsKXhUs
+LpEk2+xOVdGx8AGS0eEQQBfCACSVYufxaHMc2kBCdNb/BUcyJaJLKI7FGIjBYSs
2GthvnsbScTQRMMb6Rgdol6xUwk3ZQ3xNVEsDsY+BbC7qEqL4xLYSoXniPfdJYPG
CCbglt7/7e32yaSK/CVJByamg4ROOaw2/ymL3nn0NRUNLB4/kxJDNmI+Z5Ig7ZjH
gEwfVkd/53QUV+lDDcmUno2UWLW0EHtryLYhS2F0qVIkO3F3hP+pbnCXKyBAC955
PDREDAk7YyxbOjZKvdwK0dDlTem2/8YjxqHKuSFHmxfvDQVXnnLLcQnnf2+KZ0ro
Bet4XArxbfdEfeGCHjvSa/Z6xDEpdH/CgMSrozlw/mUZNwVxB/9nP6KPMDm7V3qS
Ij4vP1uhfo/n7iYTT3ED4K6hgQhPDaRQQR2M7QigVeM5uLstTd4AsktxghistGX5
LvZtTYuTAjdZ74lm9CAgyobtYs64gPAvoN2duCLrub00v91AdFlmlsJxJn48Rsdl
TFaNFeER78c28GoC8wl0asLaj8IRunSlsO5a5PnsTivA6eYsBcVtPih7N2Vn1Nia
OuUT0tHkAZu9JeJaqjUsMAbYelAIPSAdH3roQ1ZQHwa+KnbSu+m6fH65eUdA9eUD
80Wp6lmBGJLXTEz84/5a8/hXHEyRQhbIRpuBHGs++bF/gYqNfDBCja2B8qJyuhm2
/1lvfsc/iQGFBBgBCAAPAhsCBQJbgFMfBQkSy5kjAGpfIAQZEQgABgUCUhq7fAAK
CRDdJ/RchutgJz6CAP46j07SAMtm4x1GV6K8MMxE5jpwPxwoEk+Pg6ke0ZYzZAD+
OtDkMJ0Dyw5oM1mqPp5Ptr4fM/vGfjvhNQGPylRY8I8JEEeuf3JHm8lLE8kH/2lX
6f8rv+ID1HPnutTziuvSexo4u/kzXoLt1UkQALM8ussFI7esIjx4umKzGZLH7Urp
RYm5mxU/FC+V3aZxdyBgw7Qi6sEX3NkUoLzhb1jeq57w0GlQw7iDHjaTF1+SdcAy
OgagiyGQ1z3TwKr+J2QJrGM/5Yugh46VpY0b4+Bjg40czXW1dUYldHig9RCZaFgz
gvOxQujuJtAQ5AAQCkYB/GYAEiWRxHZxyQpyd8I2KMnp7qY4+XmfcO5JP2ZURNA8
NT/PblRpcufHL8rhVPkYAct6XH7SZ8JoNpJN3/kSKpy0UhLxqqfq7nKNJeGD8Q4e
YFzIIgbQUcY9vXV97TC5Ag0EUhq7vRAIAIufJ5CF8E1yjBL0i2js9NajUioPTXdM
wwm/o3KZbPBxrEkqeMv4cXQDOWhIXcT0oXfcSx3URXI4iUQaKDPn4duvrwAl7JBY
QrW3ary+zgq6iFe5y0yHrqBiL1v1cPyM3i30+CuAgCwpbRMKK9DJpoTpNHd2XMhU
aiH5SMzCh9APA2qOqDNmDfE0cqs6Y08+gRV1oBHe1dtF9XUoTyZ4mO799MG03X4w
dzeyz/Oxzp+NNHTOlvizFrmYZmTBc45L+NBLwdtg6OEclvz8SMbyq4q+Gg0I6Abv
BkJjTfZaJPP2wISnOuMLGUiADLBG1fDuUw0Df7WkzgY3dP7CuMOUZasAAwUH/23u
xwlHunu1tMprUU4cK797ilzmtA09hME8qm0NAHO96+T63kxUmu+0edlySw5W5BfQ
mltW+wSFlPdM1pdNgUIEsf8VkQlGW8ZMIyoeo1QXBhxyXM39VzAsu5Cw0NIquDcd
dZDnv/htq3uI/UdSgTBE7eknE76tEWTfQy2yfr844UA+j3YK0rMqpMUxsf9kUI+m
SPXz4mL0lIGP9sgZphcp95yqW/bvpkkjzEiGkfDlzFQ/tatxDEhRtutddMy3uuit
su/FtZRge2bCInNGNstqVThve59WSwMdPBsv84u3vk8AEzpsybguxTpIEhcqYqnn
itccuDe6MNgnRZYvTrqJASUEGAECAA8FAlIau70CGwwFCQlmAYAACgkQR65/ckeb
yUt4awf/Vps+XySimfCSC11Ml8iHvemM27YqpdeOds4RqtP2nFxvfigndNNOkJC5
FsNDkOs55TG45SU7jBr6CDiM87pwpoDn6YFkFTLUf4Jpxuc2K7gOVnUqIc8af/2x
0gvmCgTGHYqPoJ5OEVXv18ojC3aW9+Xbnt1j/+0o0sq9/yae1/sKamPCZ21iPZsc
OOmwH8YrejR+QkfzQIRkS/No3farvo8Az6r0UeY3TXgPWCXj/QO7bITOi1GP+KvM
2mCjN7eGWtFrprZ1CEngMNg/A8qG0surzDpM0VjAP6bpMI05L9QXYqk8HTIXVMXV
YkJQHR+jNC6dx6SpQyhekzISKlXQ+A==
=jyKE
-----END PGP PUBLIC KEY BLOCK-----

View file

@ -0,0 +1,25 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2.0.19 (GNU/Linux)
mQENBFYWn8IBCADHCFAJOVx4QyEycu9anbwsxkSJL9QmZgyJeQpegi7HshBfvqOi
oYRp+TKalfhFuTywLTIdX5B20RRr7cJ0dESwToWMwHY1+Ca1BTw0RnmUX64DuIAM
7bm94MaKQEsMg/Fdd+Vtoai7yUFtoIiB7gA5H8uKCKNM6SebH69xNQJufaWmuAUm
G64sd3RUs8ZfKbCTi+3wPyCP10pIc4rv6KJrQaCd02SpO3AJFuqjXhZ3zPnkUSdu
pzoftilsGrOaw7PHabwtL4vmSONpojSiaCvNPJoqfYGdSZnfBO/vjgZ/j1yzZ8xB
+fA2o8xSFSY3lFhRV3ERdas/EPmQwv76RQ47ABEBAAG0I2NlIE9CUyBQcm9qZWN0
IDxjZUBzMi5vd25jbG91ZC5jb20+iQE/BBMBAgApBQJWFp/CAhsDBQkEHrAABwsJ
CAcDAgEGFQgCCQoLBBYCAwECHgECF4AACgkQq3wyw1GANQppPQgAnPg32+0MUoGM
Art4UT1IyFwvkcx8c3iK7sL6g2bEkkS5r8sRRAxG4Xr7aGmNWeQfHJwkuYB8YviE
AQSCiqeENW36crKj9zJYddvzNdhZ8YLrikutGdweOe1QuQ4m0vypKhEWLvF/xNOj
Fc0nIBdS46XkGgArxfakDXR4T+cXH+t36O59MtBHHowqSRQ4mH3TwkJLIwxMrxw7
qMCNb7hkSGzzhJl6lM6juNvo78xWgjxcX+hQWxsChywArgax9U+C4jyywvytXnVV
pGD2soA3EZb7dwLIXdE+GZM2HR4mbynO7tpyphtrwWNy8U0jhOknVNVv/KmqAhqv
/po8xYTfJ4kBHAQTAQIABgUCVhafwgAKCRBHrn9yR5vJSwRCCADDHEWShB3Rko/i
Z+u9n8ZbYx2yeasumitCTmPNaJBCz9/I0GMoUM2d3FrKJ9dNX/Q60Is17yHUoE5d
QcEb0/eAu8QeEtp2hAD5ayME1r9hZqBvHrJ4nRn3iWD6nsNRh7ESYeOrfzGSlN5b
w2NRQ0KBwNCIK/gkgK5YxWq/YYTMhRk1N2EjoJipzRkEqYjnmxBWy5EJoayvJngd
/wxPMhVvT4zRoqE6TD++g8ibA1j5o5f+RdxaZAgq6wkbtA+iZI6Z3OPkmU0guyrO
cCqu++L4LegL3mE6iwK1jLx+ytO2JgCTAbk/X4bk8gJtakMAaMtvOGE9yv46IXli
zcwfgwUz
=wdVN
-----END PGP PUBLIC KEY BLOCK-----

View file

@ -0,0 +1,46 @@
---
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
# Ensure that custom Ansible plugins and modules included in the main DebOps
# collection are available to roles in other collections.
collections: [ 'debops.debops' ]
dependencies: []
galaxy_info:
company: 'DebOps'
author: 'Maciej Delmanowski, Hartmut Goebel, Robin Schneider'
description: 'Install and manage ownCloud instance'
license: 'GPL-3.0-only'
min_ansible_version: '2.1.4'
platforms:
- name: Debian
versions:
- stretch
## Main target, used in production.
- buster
- name: Ubuntu
versions:
## CI testing target
- trusty
galaxy_tags:
- cloud
- private
- privacy
- sharing
- files
- calendar
- contacts
- web
- owncloud
- nextcloud

View file

@ -0,0 +1,12 @@
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2022 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2022 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
# Role: owncloud
# Package: nextcloud
# Version: 23.0
version=4
https://download.nextcloud.com/server/releases/ nextcloud-(.+)\.tar\.bz2

View file

@ -0,0 +1,68 @@
---
# .. vim: foldmarker=[[[,]]]:foldmethod=marker
# Skeleton copied from debops.resources.
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Ensure that parent directories exist
ansible.builtin.file:
path: '{{ (owncloud__data_path + "/" + item.dest) | dirname }}'
state: 'directory'
recurse: '{{ item.parent_dirs_recurse | d(True) }}'
owner: '{{ item.parent_dirs_owner | d(owncloud__app_user) }}'
group: '{{ item.parent_dirs_group | d(owncloud__app_group) }}'
mode: '{{ item.parent_dirs_mode | d("0755") }}'
when: ((item.parent_dirs_create | d(True) | bool) and item.dest | d() and item.state | d("present") != 'absent')
loop: '{{ q("flattened", owncloud__user_files
+ owncloud__user_files_group
+ owncloud__user_files_host) }}'
- name: Copy files to ownCloud user profiles
ansible.builtin.copy:
dest: '{{ owncloud__data_path + "/" + item.dest }}'
src: '{{ item.src | d(omit) }}'
content: '{{ item.content | d(omit) }}'
owner: '{{ item.owner | d(owncloud__app_user) }}'
group: '{{ item.group | d(owncloud__app_group) }}'
mode: '{{ item.mode | d("u=rwX,g=rX,o=rX") }}'
selevel: '{{ item.selevel | d(omit) }}'
serole: '{{ item.serole | d(omit) }}'
setype: '{{ item.setype | d(omit) }}'
seuser: '{{ item.seuser | d(omit) }}'
follow: '{{ item.follow | d(omit) }}'
force: '{{ item.force | d(omit) }}'
backup: '{{ item.backup | d(omit) }}'
validate: '{{ item.validate | d(omit) }}'
remote_src: '{{ item.remote_src | d(omit) }}'
directory_mode: '{{ item.directory_mode | d(omit) }}'
register: owncloud__register_create_user_files
loop: '{{ q("flattened", owncloud__user_files
+ owncloud__user_files_group
+ owncloud__user_files_host) }}'
when: ((item.src | d() or item.content | d()) and item.dest | d() and
(item.state | d('present') != 'absent'))
- name: Delete files on remote hosts
ansible.builtin.file:
path: '{{ owncloud__data_path + "/" + item.dest }}'
state: 'absent'
register: owncloud__register_delete_user_files
loop: '{{ q("flattened", owncloud__user_files
+ owncloud__user_files_group
+ owncloud__user_files_host) }}'
when: (item.dest | d() and (item.state | d('present') == 'absent'))
- name: Run occ commands as specified in the inventory
ansible.builtin.include_tasks: 'run_occ.yml' # noqa no-handler
loop_control:
loop_var: 'owncloud__files_scan_item'
when: owncloud__files_scan_item is changed
with_items: '{{ (owncloud__register_create_user_files.results | d([])
+ owncloud__register_delete_user_files.results | d([]))
if (owncloud__register_create_user_files is defined and
owncloud__register_create_user_files is not skipped)
else [] }}'

View file

@ -0,0 +1,14 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Remove shortcut for the occ command
ansible.builtin.file:
path: '{{ owncloud__occ_bin_file_path }}'
state: 'absent'
tags: [ 'role::owncloud:occ' ]

View file

@ -0,0 +1,56 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Check default ldap config exists
ansible.builtin.command: php --file "{{ owncloud__app_home }}/occ" ldap:show-config "{{ owncloud__ldap_config_id }}"
changed_when: False
when: (not ansible_check_mode)
register: owncloud__register_ldap_default_config_exits
become: True
become_user: '{{ owncloud__app_user }}'
failed_when: (owncloud__register_ldap_default_config_exits.rc != 0 and
'Invalid configID' not in owncloud__register_ldap_default_config_exits.stdout)
- name: Create empty LDAP configuration
environment:
LC_ALL: 'C'
ansible.builtin.shell: set -o nounset -o pipefail -o errexit &&
php --file "{{ owncloud__app_home }}/occ" ldap:create-empty-config | awk '{print $NF}'
args:
executable: 'bash'
become: True
become_user: '{{ owncloud__app_user }}'
register: owncloud__register_ldap_config_id
changed_when: owncloud__register_ldap_config_id.changed | bool
when: ((not ansible_check_mode) and 'Invalid configID' in owncloud__register_ldap_default_config_exits.stdout | d(""))
- name: Update ownCloud local facts
ansible.builtin.template:
src: 'etc/ansible/facts.d/owncloud.fact.j2'
dest: '/etc/ansible/facts.d/owncloud.fact'
mode: '0755'
notify: [ 'Refresh host facts' ]
- name: Gather facts if they were modified
ansible.builtin.meta: 'flush_handlers'
- name: Configure LDAP parameters
ansible.builtin.command: php --file '{{ owncloud__app_home }}/occ' ldap:set-config '{{ owncloud__ldap_config_id }}' '{{ item.name }}' '{{ item.value }}'
changed_when: False
become: True
become_user: '{{ owncloud__app_user }}'
loop: '{{ q("flattened", owncloud__ldap_combined_config) | debops.debops.parse_kv_items }}'
loop_control:
label: '{{ {"option": item.name, "value": item.value} }}'
no_log: '{{ debops__no_log | d(True)
if (item.name in ["ldapAgentPassword"])
else False }}'
when: ((not ansible_check_mode) and item.state | d('present') not in ['absent', 'ignore'] and
('Invalid configID' in owncloud__register_ldap_default_config_exits.stdout | d("") or
owncloud_ldap_update_settings | bool))

View file

@ -0,0 +1,46 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Import custom Ansible plugins
ansible.builtin.import_role:
name: 'ansible_plugins'
- name: Import DebOps global handlers
ansible.builtin.import_role:
name: 'global_handlers'
- name: Import DebOps secret role
ansible.builtin.import_role:
name: 'secret'
- name: Manage system package installation
ansible.builtin.include_tasks: 'system_package_management.yml'
tags: [ 'role::owncloud:pkg' ]
- name: Manage tarball installation
ansible.builtin.include_tasks: 'tarball.yml'
when: (owncloud__variant in ["nextcloud"])
tags: [ 'role::owncloud:tarball' ]
- name: Setup ownCloud configuration
ansible.builtin.include_tasks: 'setup_owncloud.yml'
tags: [ 'role::owncloud:config' ]
- name: Configure LDAP integration
ansible.builtin.include_tasks: 'ldap.yml'
when: (owncloud__ldap_enabled | bool)
tags: [ 'role::owncloud:ldap' ]
- name: Manage custom ownCloud theme
ansible.builtin.include_tasks: 'theme.yml'
tags: [ 'role::owncloud:theme' ]
- name: Copy file to user profiles
ansible.builtin.include_tasks: 'copy.yml'
tags: [ 'role::owncloud:copy' ]

View file

@ -0,0 +1,53 @@
---
# .. vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Ensure the custom nginx client body temp directory does exist
ansible.builtin.file:
path: '{{ owncloud__nginx_client_body_temp_path }}'
state: 'directory'
owner: '{{ ansible_local.nginx.user | d("www-data") }}'
group: 'root'
mode: '0700'
when: (owncloud__webserver in ["nginx"] and owncloud__nginx_client_body_temp_path | d())
- name: Ensure the custom temp directories are setup
ansible.builtin.file:
path: '{{ item.path }}'
state: 'directory'
owner: '{{ owncloud__app_user }}'
group: '{{ owncloud__app_group }}'
mode: '{{ item.mode | d("1750") }}'
when: item.path | d()
with_items:
- path: '{{ owncloud__temp_path }}'
- path: '{{ owncloud__php_temp_path }}'
# Ansible local facts [[[
- name: Make sure that Ansible local facts directory is present
ansible.builtin.file:
path: '/etc/ansible/facts.d'
state: 'directory'
owner: 'root'
group: 'root'
mode: '0755'
- name: Save ownCloud local facts
ansible.builtin.template:
src: 'etc/ansible/facts.d/owncloud.fact.j2'
dest: '/etc/ansible/facts.d/owncloud.fact'
owner: 'root'
group: 'root'
mode: '0755'
notify: [ 'Refresh host facts' ]
tags: [ 'meta::facts' ]
- name: Gather facts if they were modified
ansible.builtin.meta: 'flush_handlers'
# ]]]

View file

@ -0,0 +1,89 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
# TODO: Switch to scripting occ interface when available: https://github.com/owncloud/core/issues/16068
#
#
# Already tried to fix:
# The loop variable 'owncloud__occ_item' is already in
# use. You should set the `loop_var` value in the `loop_control` option for the
# task to something else to avoid variable collisions and unexpected behavior.
#
# using owncloud__occ_item. Did not work.
- name: Construct occ command for ownCloud apps configuration
ansible.builtin.set_fact:
owncloud__occ_item:
command: 'config:app:set {{ owncloud__apps_item.key | quote }} {{ owncloud__apps_setting_item.key | quote }}
--value={{ owncloud__apps_setting_item.value | string | quote }}'
when: (owncloud__apps_setting_item is defined)
tags: [ 'role::owncloud:occ' ]
- name: 'Construct occ command for ownCloud files:scan configuration'
ansible.builtin.set_fact:
owncloud__occ_item:
## Does not support JSON output although it is listed in the help as of ownCloud 9.0.4.
## Refer to
## https://doc.owncloud.org/server/9.0/admin_manual/configuration_server/occ_command.html#file-operations
## for details.
command: 'files:scan --path {{ owncloud__files_scan_item.item.dest | quote }}'
when: (owncloud__files_scan_item is defined)
tags: [ 'role::owncloud:occ' ]
# An alternative would be
# https://doc.owncloud.org/server/9.1/admin_manual/configuration_user/user_provisioning_api.html
# but `occ` is preferred in the case of Ansible.
- name: Run given occ commands
ansible.builtin.command: php --file "{{ owncloud__app_home }}/occ" {{ owncloud__occ_item.command }}
{{ "--output=json_pretty" if (owncloud__occ_item.get_output | d() | bool) else "" }}
environment: '{{ owncloud__occ_item.env | d({}) }}'
tags: [ 'role::owncloud:occ' ]
## TODO: Upstream needs to fix proper support for `changed_when`.
changed_when: False
# changed_when: (owncloud__occ_item.command | d(omit) is match("config:app:set") and
## Has changed in ownCloud 9.0 and does not work anymore.
# changed_when: ('No such app enabled:' not in owncloud__occ_run.stdout and
# ' already ' not in owncloud__occ_run.stdout)
failed_when: ((owncloud__occ_run.rc != 0 and 'already exists' not in owncloud__occ_run.stdout and
'already installed' not in owncloud__occ_run.stdout) or
('An unhandled exception has been thrown:' in owncloud__occ_run.stdout))
no_log: '{{ debops__no_log | d(True) }}'
register: owncloud__occ_run
become: True
become_user: '{{ owncloud__app_user }}'
## https://github.com/debops/ansible-owncloud/issues/62
when: (owncloud__do_autosetup | d() | bool and
owncloud__occ_item | d() and
owncloud__occ_item.command | d() and
(owncloud__occ_item.when | d(True) | bool) and not
(ansible_local.owncloud.maintenance | d() | bool and
(owncloud__occ_item.command.startswith("dav") or
owncloud__occ_item.command.startswith("federation") or
owncloud__occ_item.command.startswith("files") or
owncloud__occ_item.command.startswith("trashbin") or
owncloud__occ_item.command.startswith("versions"))))
# - name: Debug occ command
# debug:
# var: 'owncloud__occ_run'
# Note: --format=json does not ensure that a valid JSON is returned:
#
# $ occ status --output=json
# ownCloud or one of the apps require upgrade - only a limited number of commands are available
# You may use your browser or the occ upgrade command to do the upgrade
# {"installed":true,"version":"9.0.3.2","versionstring":"9.0.3","edition":""}
- name: Convert occ output into Ansible data structure
ansible.builtin.set_fact:
## regex_replace: Relies on the fact that `json_pretty` indents the JSON encoded object.
owncloud__occ_run_output: '{{ owncloud__occ_run.stdout_lines
| map("regex_replace", "^[^{} ].*$", "") | join("") | from_json }}'
when: (owncloud__do_autosetup | d() | bool and owncloud__occ_item | d() and (owncloud__occ_item.get_output | d() | bool) and (not ansible_check_mode))
tags: [ 'role::owncloud:occ_config', 'role::owncloud:occ' ]

View file

@ -0,0 +1,19 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Run occ commands for each app setting
ansible.builtin.include_tasks: 'run_occ.yml'
loop_control:
loop_var: 'owncloud__apps_setting_item'
## Would be another use case for `ok_when`: https://github.com/ansible/ansible/issues/12710
when: ("apps" in owncloud__occ_config_current and
owncloud__apps_item.key in owncloud__occ_config_current.apps and
owncloud__occ_config_current.apps[owncloud__apps_item.key][owncloud__apps_setting_item.key] | d(omit)
!= owncloud__apps_setting_item.value)
with_dict: '{{ owncloud__apps_item.value }}'

View file

@ -0,0 +1,200 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Enable required Apache modules
community.general.apache2_module:
name: 'php5'
state: 'present'
when: owncloud__webserver == "apache"
loop: '{{ q("flattened", owncloud__apache_modules) }}'
- name: Ensure restrictive permissions are set for the data directory
ansible.builtin.file:
path: '{{ owncloud__data_path }}'
state: 'directory'
owner: '{{ owncloud__app_user }}'
group: '{{ owncloud__app_group }}'
mode: '0770'
# ownCloud ./config/ [[[
- name: Install ownCloud config file
ansible.builtin.template:
src: 'srv/www/sites/config/debops.config.php.j2'
dest: '{{ owncloud__deploy_path }}/config/debops.config.php'
owner: '{{ owncloud__app_user }}'
group: '{{ owncloud__app_group }}'
mode: '0640'
validate: 'php -f %s'
- name: Install ownCloud mail config file
ansible.builtin.template:
src: 'srv/www/sites/config/mail.config.php.j2'
dest: '{{ owncloud__deploy_path }}/config/mail.config.php'
owner: '{{ owncloud__app_user }}'
group: '{{ owncloud__app_group }}'
mode: '0640'
validate: 'php -f %s'
when: ((owncloud__mail_conf_map.keys() | length) >= 1)
tags: [ 'role::owncloud:mail' ]
- name: Ensure the ownCloud mail config file is absent
ansible.builtin.file:
path: '{{ owncloud__deploy_path }}/config/mail.config.php'
state: 'absent'
when: ((owncloud__mail_conf_map.keys() | length) == 0)
- name: Ensure deprecated configuration files are absent
ansible.builtin.file:
path: '{{ item }}'
state: 'absent'
loop:
- '{{ owncloud__deploy_path }}/config/custom.config.php'
# .. ]]]
# Setup the occ command [[[
- name: Remove legacy files
ansible.builtin.file:
state: 'absent'
path: '{{ ansible_local.php.etc_base | d("/etc/php") + "/cli/conf.d/enable_apc.ini" }}'
tags: [ 'role::owncloud:occ' ]
- name: Setup shortcut for the occ command
ansible.builtin.template:
src: 'usr/local/bin/occ.j2'
dest: '{{ owncloud__occ_bin_file_path }}'
owner: 'root'
group: '{{ owncloud__app_group }}'
mode: '0755'
tags: [ 'role::owncloud:occ' ]
# .. ]]]
# Auto setup [[[
- name: Get ownCloud setup status
ansible.builtin.command: '{{ owncloud__occ_bin_file_path | quote }} check'
register: owncloud__register_occ_check
changed_when: False
- name: Determine if ownCloud autosetup should be done
ansible.builtin.set_fact:
owncloud__do_autosetup: '{{ (owncloud__autosetup and
owncloud__admin_username | d() and
(owncloud__register_occ_check is not skipped) and
(("is not installed" in owncloud__register_occ_check.stdout) or
("is not installed" in owncloud__register_occ_check.stderr))) }}'
- name: Automatically finish setup via the occ tool
ansible.builtin.command: |
{{ owncloud__occ_bin_file_path | quote }} maintenance:install
'--data-dir={{ owncloud__data_path }}'
'--database={{ owncloud__database_map[owncloud__database].dbtype }}'
'--database-name={{ owncloud__database_map[owncloud__database].dbname }}'
'--database-host={{ owncloud__database_map[owncloud__database].dbhost }}'
'--database-user={{ owncloud__database_map[owncloud__database].dbuser }}'
'--database-pass={{ owncloud__database_map[owncloud__database].dbpass }}'
{% if owncloud__admin_username %}
'--admin-user={{ owncloud__admin_username }}'
'--admin-pass={{ owncloud__admin_password }}'
{% endif %}
register: owncloud__register_occ_install
changed_when: owncloud__register_occ_install.changed | bool
when: owncloud__do_autosetup | bool
# .. ]]]
# ownCloud applications configuration [[[1
- name: Get current ownCloud configuration via occ config:list
ansible.builtin.include_tasks: 'run_occ.yml'
loop_control:
loop_var: 'owncloud__occ_item'
tags: [ 'role::owncloud:occ_config' ]
when: (owncloud__apps_config_combined is mapping and owncloud__apps_config_combined.keys() | length)
loop:
- command: 'config:list'
get_output: True
- name: Capture occ output in variable
ansible.builtin.set_fact:
owncloud__occ_config_current: '{{ owncloud__occ_run_output }}'
when: (owncloud__do_autosetup | bool and owncloud__apps_config_combined is mapping and owncloud__apps_config_combined.keys() | length and
(not ansible_check_mode))
tags: [ 'role::owncloud:occ_config' ]
- name: Set ownCloud apps configuration for each app
ansible.builtin.include_tasks: 'run_occ_app_set.yml'
loop_control:
loop_var: 'owncloud__apps_item'
with_dict: '{{ owncloud__apps_config_combined | d({}) }}'
when: (owncloud__do_autosetup | d() | bool and not ansible_check_mode)
tags: [ 'role::owncloud:occ_config' ]
# .. ]]]
# Run occ commands as specified in the inventory [[[
- name: Run occ commands as specified in the inventory
ansible.builtin.include_tasks: 'run_occ.yml'
loop_control:
loop_var: 'owncloud__occ_item'
tags: [ 'role::owncloud:occ' ]
loop: '{{ q("flattened", owncloud__role_occ_cmd_list
+ owncloud__occ_cmd_list
+ owncloud__group_occ_cmd_list
+ owncloud__host_occ_cmd_list
+ owncloud__dependent_occ_cmd_list) }}'
# .. ]]]
# Configure cron job for background tasks [[[
- name: Setup cron service (nextcloud)
ansible.builtin.cron:
name: 'ownCloud Background Jobs'
minute: '{{ owncloud__cron_minute }}'
user: '{{ owncloud__app_user }}'
job: 'test -x /usr/bin/php && test -e {{ (owncloud__deploy_path + "/cron.php") | quote }}
&& /usr/bin/php -f {{ (owncloud__deploy_path + "/cron.php") | quote }}'
cron_file: 'owncloud'
when: owncloud__variant == "nextcloud"
- name: Setup cron service (owncloud)
ansible.builtin.cron:
name: 'ownCloud Background Jobs'
minute: '{{ owncloud__cron_minute }}'
user: '{{ owncloud__app_user }}'
job: 'test -x /usr/bin/php && test -e {{ (owncloud__deploy_path + "/occ") | quote }}
&& /usr/bin/php {{ (owncloud__deploy_path + "/occ") | quote }} system:cron'
cron_file: 'owncloud'
when: owncloud__variant == "owncloud"
# .. ]]]
# ownCloud upgrades [[[
- name: Disable the package manager hook script for ownCloud
ansible.builtin.file:
path: '/etc/apt/apt.conf.d/80owncloud-dpkg-hook'
state: 'absent'
# .. ]]]
# ownCloud integrity check [[[
- name: Check ownCloud core integrity
ansible.builtin.command: '{{ owncloud__occ_bin_file_path | quote }} integrity:check-core'
register: owncloud__register_occ_integrity_check_core
failed_when: (owncloud__register_occ_integrity_check_core.rc != 0 or
owncloud__register_occ_integrity_check_core.stdout_lines | length != 0)
changed_when: False
when: owncloud__do_autosetup | bool
# ]]]

View file

@ -0,0 +1,55 @@
---
# .. vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Configure ownCloud APT repository
ansible.builtin.template:
src: 'etc/apt/sources.list.d/debops_owncloud.list.j2'
dest: '/etc/apt/sources.list.d/debops_owncloud.list'
owner: 'root'
group: 'root'
mode: '0644'
register: owncloud__register_apt_repository
when: (owncloud__variant in ["owncloud"])
- name: Update APT repository cache
ansible.builtin.apt: # noqa no-handler
update_cache: True
register: owncloud__register_apt_cache
until: owncloud__register_apt_cache is succeeded
when: owncloud__register_apt_repository is changed
## Use filename when available (2.1.0) https://github.com/ansible/ansible-modules-core/pull/2696
## To avoid multiple of those source files.
## ypid: Does not help much. When the URL changes, the old source entry will
## need to be made absent so stay with the current way.
## Disabled because each repository URLs would need to be made absent
## manually with using `apt_repository`. If that is solved, then go with
## `apt_repository` again.
# - name: Configure ownCloud APT repository
# ansible.builtin.apt_repository:
# repo: '{{ owncloud__apt_repo_source }}'
# state: 'present'
# update_cache: True
- name: Ensure specified packages are in there desired state
ansible.builtin.package:
name: '{{ q("flattened", (owncloud__base_packages
+ owncloud__packages
+ owncloud__group_packages
+ owncloud__host_packages
+ owncloud__dependent_packages)) }}'
state: '{{ "absent"
if (owncloud__deploy_state in ["absent"])
else ("latest"
if (ansible_local | d() and ansible_local.owncloud | d() and
((ansible_local.owncloud.release | d(owncloud__release) != owncloud__release) or
(ansible_local.owncloud.auto_security_updates_enabled | d() | bool)))
else "present") }}'
register: owncloud__register_apt_install
until: owncloud__register_apt_install is succeeded

View file

@ -0,0 +1,149 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
- name: Create Nextcloud group
ansible.builtin.group:
name: '{{ owncloud__system_group }}'
state: 'present'
system: True
tags: [ 'role::nextcloud:download', 'role::nextcloud:verify' ]
- name: Create Nextcloud user
ansible.builtin.user:
name: '{{ owncloud__system_user }}'
group: '{{ owncloud__system_group }}'
home: '{{ owncloud__system_home }}'
comment: '{{ owncloud__comment }}'
shell: '{{ owncloud__shell }}'
system: True
state: 'present'
tags: [ 'role::nextcloud:download', 'role::nextcloud:verify' ]
- name: Create source directory
ansible.builtin.file:
path: '{{ owncloud__src }}'
state: 'directory'
owner: '{{ owncloud__system_user }}'
group: '{{ owncloud__system_group }}'
mode: '0755'
- name: Create deployment directory
ansible.builtin.file:
path: '{{ owncloud__deploy_path }}'
state: 'directory'
owner: '{{ owncloud__app_user }}'
group: '{{ owncloud__app_group }}'
mode: '{{ owncloud__deploy_path_mode }}'
# Application download and validation [[[1
- name: Download and validate the tarball
become: True
become_user: '{{ owncloud__system_user }}'
block:
# Get latest patch version for release [[[2
- name: Query for the full version string of the current release # noqa command-instead-of-module
ansible.builtin.shell: set -o nounset -o pipefail -o errexit &&
curl -s -m 900 {{ (owncloud__variant_download_url_map[owncloud__variant] + "/") | quote }}
| sed --silent 's/.*href="nextcloud-\({{ owncloud__release | regex_escape() }}[^"]\+\).zip.asc".*/\1/p'
| sort --version-sort --reverse
args:
executable: 'bash'
register: owncloud__register_full_version
changed_when: False
check_mode: False
tags: [ 'role::nextcloud:verify' ]
# Nextcloud application archive download [[[2
- name: Create source directories
ansible.builtin.file:
path: '{{ owncloud__src + "/" + owncloud__variant + "/" + owncloud__register_full_version.stdout_lines[0] }}'
state: 'directory'
owner: '{{ owncloud__system_user }}'
group: '{{ owncloud__system_group }}'
mode: '0755'
tags: [ 'role::nextcloud:download', 'role::nextcloud:verify' ]
- name: Download application files needed for verification
ansible.builtin.get_url:
url: '{{ owncloud__variant_download_url_map[owncloud__variant] + "/" +
owncloud__variant + "-" + owncloud__register_full_version.stdout_lines[0] + "." + item }}'
dest: '{{ owncloud__src + "/" + owncloud__variant + "/" + owncloud__register_full_version.stdout_lines[0] }}'
mode: '0644'
with_items:
- 'zip.asc'
- 'zip.sha512'
register: owncloud__register_download_assurance
until: owncloud__register_download_assurance is succeeded
when: not ansible_check_mode
tags: [ 'role::nextcloud:download', 'role::nextcloud:verify' ]
# Nextcloud application archive authenticity verification [[[2
- name: Read checksum from file
ansible.builtin.shell: set -o nounset -o pipefail -o errexit &&
cat {{ owncloud__src + "/" + owncloud__variant + "/"
+ owncloud__register_full_version.stdout_lines[0] + "/"
+ owncloud__variant + "-" + owncloud__register_full_version.stdout_lines[0]
+ ".zip.sha512" }} | grep '.zip$'
args:
executable: 'bash'
changed_when: False
register: owncloud__register_checksum
when: not ansible_check_mode # Latest checksum file may not be available
tags: [ 'role::nextcloud:download', 'role::nextcloud:verify' ]
- name: Download application archive
ansible.builtin.get_url: # noqa no-handler
url: '{{ owncloud__variant_download_url_map[owncloud__variant] + "/" +
owncloud__variant + "-" + owncloud__register_full_version.stdout_lines[0] + ".zip" }}'
dest: '{{ owncloud__src + "/" + owncloud__variant + "/" + owncloud__register_full_version.stdout_lines[0] }}'
checksum: 'sha512:{{ (owncloud__register_checksum.stdout_lines[0]).split(" ") | first }}'
mode: '0644'
register: owncloud__register_download_application
until: owncloud__register_download_application is succeeded
when: owncloud__register_download_assurance is changed
tags: [ 'role::nextcloud:download', 'role::nextcloud:verify' ]
- name: Verify OpenPGP signature
environment:
LC_MESSAGES: 'C'
ansible.builtin.shell: |
set -o nounset -o pipefail -o errexit
gpg --verify {{ owncloud__src + "/" + owncloud__variant + "/"
+ owncloud__register_full_version.stdout_lines[0] + "/"
+ owncloud__variant + "-" + owncloud__register_full_version.stdout_lines[0]
+ ".zip.asc" }} \
{{ owncloud__src + "/" + owncloud__variant + "/"
+ owncloud__register_full_version.stdout_lines[0] + "/"
+ owncloud__variant + "-" + owncloud__register_full_version.stdout_lines[0]
+ ".zip" }} 2>&1 \
| sed --silent 's/^Primary key fingerprint: \(.*\)$/\1/p;'
args:
executable: 'bash'
changed_when: False
register: owncloud__register_verify_authenticity
failed_when: (owncloud__register_verify_authenticity.rc != 0 or
(owncloud__register_verify_authenticity.stdout | replace(" ", ""))
!= (owncloud__upstream_key_fingerprint | replace(" ", "")))
tags: [ 'role::nextcloud:verify' ]
- name: Unpack the application archive
ansible.builtin.unarchive:
remote_src: True
src: '{{ owncloud__src + "/" + owncloud__variant + "/" + owncloud__register_full_version.stdout_lines[0] + "/" +
owncloud__variant + "-" + owncloud__register_full_version.stdout_lines[0] + ".zip" }}'
dest: '{{ owncloud__deploy_path + "/.." }}'
owner: '{{ owncloud__app_user }}'
group: '{{ owncloud__app_group }}'
mode: 'u=rwX,g=rX,o=rX'
creates: '{{ owncloud__deploy_path + "/index.php" }}'

View file

@ -0,0 +1,105 @@
---
# vim: foldmarker=[[[,]]]:foldmethod=marker
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
# Combine theme copy dictionaries [[[
- name: Combine theme copy dictionaries
ansible.builtin.set_fact:
owncloud__theme_copy_files_combined: '{{
owncloud__theme_copy_files
| combine(owncloud__theme_copy_files_host_group)
| combine(owncloud__theme_copy_files_host) }}'
tags: [ 'role::owncloud:theme:copy' ]
# .. ]]]
# Create [[[
- name: Ensure the theme directory is present
ansible.builtin.file:
path: '{{ owncloud__deploy_path + "/themes/" + owncloud__theme_directory_name }}'
state: 'directory'
mode: '0755'
when: (owncloud__theme_directory_name | d())
tags:
- 'role::owncloud:theme:common_settings'
- name: Apply common theming options using the defaults.php file
ansible.builtin.template:
src: 'srv/www/sites/themes/debops-template/defaults.php.j2'
dest: '{{ owncloud__deploy_path + "/themes/" + owncloud__theme_directory_name + "/defaults.php" }}'
owner: 'root'
## ownCloud itself does not need to change this file and does not even allow to do so.
group: '{{ owncloud__app_group }}'
mode: '0640'
validate: 'php -f %s'
when: (owncloud__theme_directory_name | d())
tags: [ 'role::owncloud:theme:common_settings' ]
- name: Ensure that parent directories exist
ansible.builtin.file:
path: '{{ (owncloud__deploy_path + "/themes/" + owncloud__theme_directory_name + "/" + item.key) | dirname }}'
state: 'directory'
owner: '{{ item.value.base_directory_owner | d(omit) }}'
group: '{{ item.value.base_directory_group | d(omit) }}'
mode: '{{ item.value.base_directory_mode | d(omit) }}'
with_dict: '{{ owncloud__theme_copy_files_combined }}'
when: (owncloud__theme_directory_name | d() and item.value.state | d("present") == "present")
tags: [ 'role::owncloud:theme:copy' ]
- name: Copy additional theme files
ansible.builtin.copy:
dest: '{{ (owncloud__deploy_path + "/themes/" + owncloud__theme_directory_name + "/" + item.key)
if (not item.key.startswith("/")) else item.key }}'
backup: '{{ item.value.backup | d(omit) }}'
content: '{{ item.value.content | d(omit) }}'
directory_mode: '{{ item.value.directory_mode | d(omit) }}'
follow: '{{ item.value.follow | d(omit) }}'
force: '{{ item.value.force | d(omit) }}'
owner: '{{ item.value.owner | d(omit) }}'
group: '{{ item.value.group | d(omit) }}'
mode: '{{ item.value.mode | d(omit) }}'
selevel: '{{ item.value.selevel | d(omit) }}'
serole: '{{ item.value.serole | d(omit) }}'
setype: '{{ item.value.setype | d(omit) }}'
seuser: '{{ item.value.seuser | d(omit) }}'
src: '{{ item.value.src | d(omit) }}'
validate: '{{ item.value.validate | d(omit) }}'
with_dict: '{{ owncloud__theme_copy_files_combined }}'
when: (owncloud__theme_directory_name | d() and item.value.state | d("present") == "present")
tags: [ 'role::owncloud:theme:copy' ]
- name: Activate custom theme
ansible.builtin.template:
src: 'srv/www/sites/config/theme.config.php.j2'
dest: '{{ owncloud__deploy_path }}/config/theme.config.php'
owner: 'root'
group: '{{ owncloud__app_group }}'
mode: '0640'
when: (owncloud__theme_active | d())
tags: [ 'role::owncloud:theme:activate' ]
# .. ]]]
# Teardown [[[
- name: Deactivate custom theme
ansible.builtin.file:
path: '{{ owncloud__deploy_path }}/config/theme.config.php'
state: 'absent'
when: (not owncloud__theme_active | d())
tags: [ 'role::owncloud:theme:activate' ]
- name: Delete additional theme files
ansible.builtin.file:
path: '{{ owncloud__deploy_path + "/themes/" + owncloud__theme_directory_name + "/" + item.key }}'
state: 'absent'
when: (owncloud__theme_directory_name | d() and item.value.state | d("present") == "absent")
with_dict: '{{ owncloud__theme_copy_files_combined }}'
tags: [ 'role::owncloud:theme:copy' ]
# .. ]]]

View file

@ -0,0 +1,52 @@
#!{{ ansible_python['executable'] }}
# -*- coding: utf-8 -*-
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
# {{ ansible_managed }}
from __future__ import print_function
import os
from json import loads, dumps
import subprocess
output = loads('''{{ ({
"enabled": (owncloud__deploy_state == "present"),
"webserver": owncloud__webserver | string,
"variant": owncloud__variant | string,
"ldap_config_id": (owncloud__register_ldap_config_id.stdout
if (owncloud__register_ldap_config_id | d() and
owncloud__register_ldap_config_id.stdout | d())
else owncloud__ldap_config_id),
}) | to_nice_json }}''')
owncloud_deploy_path = loads('''{{ owncloud__deploy_path | to_json }}''')
if os.path.isfile(owncloud_deploy_path + '/config/config.php'):
try:
config_cmd = subprocess.Popen(
['php', '-r', 'include "' + owncloud_deploy_path
+ '/config/config.php"; echo json_encode($CONFIG);'],
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
)
except Exception:
pass
else:
std_out, std_err = config_cmd.communicate()
if config_cmd.returncode == 0 and len(std_err) == 0:
config = loads(std_out)
for key in ['instanceid', 'version', 'updatechecker', 'theme',
'maintenance', 'datadirectory', 'trusted_domains']:
if key in config:
output[key] = config[key]
if 'version' in output:
output['release'] = '.'.join(output['version'].split('.')[:2])
print(dumps(output, sort_keys=True, indent=4))

View file

@ -0,0 +1,9 @@
{# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
#}
# {{ ansible_managed }}
{{ owncloud__apt_repo_source }}

View file

@ -0,0 +1,10 @@
{# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
#}
; {{ ansible_managed }}
; Set by debops.owncloud role
apc.enable_cli = 1

View file

@ -0,0 +1,34 @@
{# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
#}
{# vim: foldmarker=[[[,]]]:foldmethod=marker
#}
<?php
/* {{ ansible_managed }} */
{% macro get_value(item) %}{# [[[ #}
{% set filtered_item = item | to_yaml | from_yaml %}{# Copy dict #}
{% if item is mapping %}
{% for k, v in item.items() if v == omit %}
{% set _ = filtered_item.pop(k, None) %}
{% endfor %}
{% endif %}
{{ filtered_item | to_yaml }}
{% endmacro %}{# ]]]
#}
{% set owncloud__tpl_active_config_dict = {} %}
{% for config_key, config_item in owncloud__combined_config.items() %}
{% if config_item is mapping and "state" in config_item and config_item.state and "value" in config_item %}
{% if config_item.state == "present" and config_item.value %}
{% set _ = owncloud__tpl_active_config_dict.update({config_key: (get_value(config_item.value) | from_yaml) }) %}
{% endif %}
{% elif config_item != omit %}
{# Assume it is not a control structure for Ansible but the raw value for ownCloud #}
{% set _ = owncloud__tpl_active_config_dict.update({config_key: config_item}) %}
{% endif %}
{% endfor %}
$CONFIG = json_decode('{{ owncloud__tpl_active_config_dict | to_nice_json }}', true);
?>

View file

@ -0,0 +1,15 @@
{# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
#}
<?php
/* {{ ansible_managed }} */
{#
Copyright 2015 by Steffen Lindner <mail@steffen-lindner.de>
SPDX-License-Identifier: GPL-3.0-only
#}
$CONFIG = json_decode('{{ owncloud__mail_conf_map | to_nice_json }}', true);
?>

View file

@ -0,0 +1,11 @@
{# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
#}
<?php
/* {{ ansible_managed }} */
$CONFIG = json_decode('{{ owncloud__theme_conf_map | to_nice_json }}', true);
?>

View file

@ -0,0 +1,202 @@
{#
The current upstream version can be found here: https://github.com/owncloud/core/blob/master/themes/example/defaults.php
Raw: https://raw.githubusercontent.com/owncloud/core/master/themes/example/defaults.php
* Escape quotes to prevent PHP code injection via variables?
No, to allow more flexibility for users of the role. Injecting PHP code can
be useful.
#}
<?php
/**
* {{ ansible_managed }}
*
* @author Björn Schießle <schiessle@owncloud.com>
* @author Jan-Christoph Borchardt, http://jancborchardt.net
* @copyright Copyright (c) 2015, ownCloud, Inc.
* @license AGPL-3.0-only
* SPDX-License-Identifier: AGPL-3.0-only
*
* This code is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License, version 3,
* as published by the Free Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License, version 3,
* along with this program. If not, see <https://www.gnu.org/licenses/>
*/
class OC_Theme {
/**
* Returns the base URL
* @return string URL
*/
{% if owncloud__theme_base_url != '' %}
public function getBaseUrl() {
return '{{ owncloud__theme_base_url }}';
}
{% else %}
/* Not otherwise defined. Falling back to ownCloud default value. */
{% endif %}
/**
* Returns the URL where the sync clients are listed
* @return string URL
*/
public function getSyncClientUrl() {
return 'https://owncloud.org/install';
}
/**
* Returns the URL to the App Store for the iOS Client
* @return string URL
*/
public function getiOSClientUrl() {
return 'https://itunes.apple.com/us/app/owncloud/id543672169?mt=8';
}
/**
* Returns the AppId for the App Store for the iOS Client
* @return string AppId
*/
public function getiTunesAppId() {
return '543672169';
}
/**
* Returns the URL to Google Play for the Android Client
* @return string URL
*/
public function getAndroidClientUrl() {
return 'https://play.google.com/store/apps/details?id=com.owncloud.android';
}
{#
Fallback not possible as of 9.0.2.
#}
/**
* Returns the documentation URL
* @return string URL
*/
public function getDocBaseUrl() {
return 'https://doc.owncloud.org';
}
/**
* Returns the title
* @return string title
*/
public function getTitle() {
return '{{ owncloud__theme_title }}';
}
/**
* Returns the short name of the software
* @return string title
*/
public function getName() {
return '{{ owncloud__theme_name }}';
}
/**
* Returns the short name of the software containing HTML strings
* @return string title
*/
public function getHTMLName() {
return '{{ owncloud__theme_name_html }}';
}
/**
* Returns entity (e.g. company name) - used for footer, copyright
* @return string entity name
*/
public function getEntity() {
return '{{ owncloud__theme_entity_name }}';
}
/**
* Returns slogan
* @return string slogan
*/
{% if owncloud__theme_slogan != '' %}
public function getSlogan() {
return '{{ owncloud__theme_slogan }}';
}
{% else %}
/* Not otherwise defined. Falling back to ownCloud default value. */
{% endif %}
{#
# .. envvar:: owncloud__theme_logo_claim
#
# The logo claim can be used to add a hidden claim about the logo.
# This feature seems to be rarely used and it is not sure if that is the intention behind this variable.
# Checkout `this comment about
# <https://github.com/owncloud/core/issues/5676#issuecomment-27649493>`_ for a
# for discussion.
#
# https://github.com/owncloud/core/issues/5676#issuecomment-228990394
# > The use is simply for the ownCloud Enterprise Edition to display »Enterprise
# > Edition« next to the logo/appname in the header when logged in. Its used for
# > nothing else. I would strongly advise against ever using it because it will
# > just distract and clutter up the header (wont work on mobile anyway).
owncloud__theme_logo_claim: ''
#}
/**
* Returns logo claim
* @return string logo claim
*/
{% if owncloud__theme_logo_claim | d('') != '' %}
public function getLogoClaim() {
return '{{ owncloud__theme_logo_claim }}';
}
{% else %}
/* Not otherwise defined. Falling back to ownCloud default value. */
{% endif %}
{#
Fallback not possible as of 9.0.1.
#}
/**
* Returns short version of the footer
* @return string short footer
*/
public function getShortFooter() {
$footer = {{ owncloud__theme_footer_short }};
return $footer;
}
{#
Fallback not possible as of 9.0.1.
#}
/**
* Returns long version of the footer
* @return string long footer
*/
public function getLongFooter() {
$footer = {{ owncloud__theme_footer_long }};
return $footer;
}
public function buildDocLinkToKey($key) {
return {{ owncloud__theme_doc_link_to_key }};
}
/**
* Returns mail header color
* @return string
*/
public function getMailHeaderColor() {
return '#745bca';
}
}

View file

@ -0,0 +1,47 @@
#!/usr/bin/env bash
# Copyright (C) 2015-2016 Maciej Delmanowski <drybjed@gmail.com>
# Copyright (C) 2015 Hartmut Goebel <h.goebel@crazy-compilers.com>
# Copyright (C) 2015-2019 Robin Schneider <ypid@riseup.net>
# Copyright (C) 2015-2019 DebOps <https://debops.org/>
# SPDX-License-Identifier: GPL-3.0-only
# Shortcut for running ownClouds `occ` command when not logged in as {{ owncloud__app_user }} user and sudo allows it.
# https://doc.owncloud.org/server/9.0/admin_manual/configuration_server/occ_command.html
# {{ ansible_managed }}
set -o nounset -o pipefail -o errexit
# Environment variable `OC_PASS` is striped normally by `sudo`.
# `--preserve-env` would preserve all environment variables.
# This should be OK for this command.
# It seems to be impossible to set "env_keep" via the command line?
# Other possibility would be to configure it properly via Defaults!{{ owncloud__app_home }}/occ env_keep=OC_PASS
# The occ command should be invoked with PWD set to `owncloud__app_home` to avoid occ not finding its DB spec:
# https://github.com/owncloud/core/issues/17583
# It is fixed in 8.2 but lets call `occ` like the documentation suggests it:
# https://doc.owncloud.org/server/9.0/admin_manual/configuration_server/occ_command.html?highlight=occ#using-the-occ-command
cd '{{ owncloud__app_home }}' || exit 1
# Long command line options seem to be not supported as of 1.8.3 in Ubuntu precise.
# sudo --preserve-env --user '{{ owncloud__app_user }}' php --file '{{ owncloud__app_home }}/occ' "$@"
# {#
# Example cron entry:
# - name: 'owncloud-some-job'
# cron_file: 'owncloud-something'
# minute: 23
# hour: 05
# job: 'USER={{ owncloud__app_user | quote }} {{ some_script | quote }}'
# user: '{{ owncloud__app_user }}'
#
#}
if [ "$USER" == '{{ owncloud__app_user }}' ]
then
php --file '{{ owncloud__app_home }}/occ' "$@"
else
sudo -E -u '{{ owncloud__app_user }}' php --file '{{ owncloud__app_home }}/occ' "$@"
fi