2024-09-19 23:10:00 +02:00
|
|
|
---
|
|
|
|
- name: "Create postgres user: {{ db.user }}"
|
|
|
|
community.postgresql.postgresql_user:
|
|
|
|
state: present
|
|
|
|
name: "{{ db.user }}"
|
|
|
|
password: "{{ db.password }}"
|
|
|
|
become: true
|
|
|
|
become_user: "{{ db.default_user.user }}"
|
|
|
|
vars:
|
|
|
|
ansible_remote_temp: "/tmp/"
|
|
|
|
|
|
|
|
- name: "Create database: {{ db.name }}"
|
|
|
|
community.postgresql.postgresql_db:
|
|
|
|
state: present
|
|
|
|
name: "{{ db.name }}"
|
|
|
|
encoding: UTF8
|
|
|
|
lc_collate: "en_US.UTF-8"
|
|
|
|
lc_ctype: "en_US.UTF-8"
|
|
|
|
become: yes
|
|
|
|
become_user: postgres
|
|
|
|
vars:
|
|
|
|
ansible_remote_temp: "/tmp/"
|
|
|
|
|
2024-09-20 15:01:33 +02:00
|
|
|
- name: "Grant all privileges on database {{ db.name }} to {{ db.user }};"
|
|
|
|
community.postgresql.postgresql_privs:
|
|
|
|
db: "{{ db.name }}"
|
|
|
|
privs: ALL
|
2024-09-19 23:10:00 +02:00
|
|
|
type: database
|
|
|
|
roles: "{{ db.user }}"
|
2024-09-20 15:01:33 +02:00
|
|
|
become: yes
|
|
|
|
become_user: postgres
|
|
|
|
vars:
|
|
|
|
ansible_remote_temp: "/tmp/"
|
|
|
|
|
|
|
|
- name: "Grant all privileges on schema public to {{ db.user }};"
|
|
|
|
community.postgresql.postgresql_privs:
|
|
|
|
db: "{{ db.name }}"
|
|
|
|
privs: ALL
|
|
|
|
type: schema
|
|
|
|
obj: "public"
|
|
|
|
roles: "{{ db.user }}"
|
2024-09-19 23:10:00 +02:00
|
|
|
become: yes
|
|
|
|
become_user: postgres
|
|
|
|
vars:
|
|
|
|
ansible_remote_temp: "/tmp/"
|
|
|
|
|
|
|
|
- name: "Allow md5 connection for the {{ db.user }} user"
|
|
|
|
postgresql_pg_hba:
|
2024-09-20 15:01:33 +02:00
|
|
|
dest: "/etc/postgresql/15/main/pg_hba.conf"
|
2024-09-19 23:10:00 +02:00
|
|
|
contype: host
|
|
|
|
databases: all
|
|
|
|
method: md5
|
2024-09-20 15:01:33 +02:00
|
|
|
address: "{{ k3s.net }}"
|
2024-09-19 23:10:00 +02:00
|
|
|
users: "{{ db.user }}"
|
2024-09-20 15:01:33 +02:00
|
|
|
create: false
|
2024-09-19 23:10:00 +02:00
|
|
|
become: yes
|
|
|
|
notify:
|
|
|
|
- Restart postgres
|
2024-09-20 15:01:33 +02:00
|
|
|
|
|
|
|
- name: "Set public listen address"
|
|
|
|
become: true
|
|
|
|
lineinfile:
|
|
|
|
dest: "/etc/postgresql/15/main/conf.d/listen.conf"
|
|
|
|
regexp: "^#?listen_addresses="
|
|
|
|
line: "listen_addresses='{{ db.listen_address | default('localhost') }}'"
|
|
|
|
state: present
|
|
|
|
create: yes
|
|
|
|
notify: "Restart postgres"
|