add var to make the creds optional
This commit is contained in:
parent
ceda4c41cc
commit
0e701bbece
|
@ -885,6 +885,8 @@ matrix_synapse_ext_synapse_s3_storage_provider_config_region_name: ''
|
||||||
matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url: ''
|
matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url: ''
|
||||||
matrix_synapse_ext_synapse_s3_storage_provider_config_access_key_id: ''
|
matrix_synapse_ext_synapse_s3_storage_provider_config_access_key_id: ''
|
||||||
matrix_synapse_ext_synapse_s3_storage_provider_config_secret_access_key: ''
|
matrix_synapse_ext_synapse_s3_storage_provider_config_secret_access_key: ''
|
||||||
|
# Enable this to use EC2 instance profile metadata to grab IAM credentials instead of passing credentials directly.
|
||||||
|
matrix_synapse_ext_synapse_s3_storage_provider_config_ec2_instance_profile: false
|
||||||
matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_enabled: false
|
matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_enabled: false
|
||||||
matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_key: ''
|
matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_key: ''
|
||||||
matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_algo: 'AES256'
|
matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_algo: 'AES256'
|
||||||
|
|
|
@ -1,14 +1,27 @@
|
||||||
---
|
---
|
||||||
|
- name: Set base required s3-storage-provider settings
|
||||||
|
set_fact:
|
||||||
|
base_s3_storage_provider_config:
|
||||||
|
- "matrix_synapse_ext_synapse_s3_storage_provider_config_bucket"
|
||||||
|
- "matrix_synapse_ext_synapse_s3_storage_provider_config_region_name"
|
||||||
|
- "matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url"
|
||||||
|
|
||||||
|
- name: Set optional required s3-storage-provider settings
|
||||||
|
set_fact:
|
||||||
|
optional_s3_storage_provider_config:
|
||||||
|
- "matrix_synapse_ext_synapse_s3_storage_provider_config_access_key_id"
|
||||||
|
- "matrix_synapse_ext_synapse_s3_storage_provider_config_secret_access_key"
|
||||||
|
|
||||||
|
- name: Prepare a list of required s3-storage-provider settings
|
||||||
|
set_fact:
|
||||||
|
required_s3_settings: "{{ base_s3_storage_provider_config + (optional_s3_storage_provider_config if not matrix_synapse_ext_synapse_s3_storage_provider_config_ec2_instance_profile|default(false)|bool else []) }}"
|
||||||
|
|
||||||
- name: Fail if required s3-storage-provider settings not defined
|
- name: Fail if required s3-storage-provider settings not defined
|
||||||
ansible.builtin.fail:
|
ansible.builtin.fail:
|
||||||
msg: >-
|
msg: >-
|
||||||
You need to define a required configuration setting (`{{ item }}`) for using s3-storage-provider.
|
You need to define a required configuration setting (`{{ item }}`) for using s3-storage-provider.
|
||||||
when: "vars[item] == ''"
|
when: "vars[item] == ''"
|
||||||
with_items:
|
with_items: "{{ required_s3_settings }}"
|
||||||
- "matrix_synapse_ext_synapse_s3_storage_provider_config_bucket"
|
|
||||||
- "matrix_synapse_ext_synapse_s3_storage_provider_config_region_name"
|
|
||||||
- "matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url"
|
|
||||||
|
|
||||||
- name: Fail if required matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url looks invalid
|
- name: Fail if required matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url looks invalid
|
||||||
ansible.builtin.fail:
|
ansible.builtin.fail:
|
||||||
|
|
|
@ -1,3 +1,7 @@
|
||||||
|
{% if not matrix_synapse_ext_synapse_s3_storage_provider_config_ec2_instance_profile|default(false)|bool %}
|
||||||
|
AWS_ACCESS_KEY_ID={{ matrix_synapse_ext_synapse_s3_storage_provider_config_access_key_id }}
|
||||||
|
AWS_SECRET_ACCESS_KEY={{ matrix_synapse_ext_synapse_s3_storage_provider_config_secret_access_key }}
|
||||||
|
{% endif %}
|
||||||
AWS_DEFAULT_REGION={{ matrix_synapse_ext_synapse_s3_storage_provider_config_region_name }}
|
AWS_DEFAULT_REGION={{ matrix_synapse_ext_synapse_s3_storage_provider_config_region_name }}
|
||||||
|
|
||||||
ENDPOINT={{ matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url }}
|
ENDPOINT={{ matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url }}
|
||||||
|
|
|
@ -6,6 +6,10 @@ config:
|
||||||
bucket: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_bucket | to_json }}
|
bucket: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_bucket | to_json }}
|
||||||
region_name: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_region_name | to_json }}
|
region_name: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_region_name | to_json }}
|
||||||
endpoint_url: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url | to_json }}
|
endpoint_url: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_endpoint_url | to_json }}
|
||||||
|
{% if not matrix_synapse_ext_synapse_s3_storage_provider_config_ec2_instance_profile|default(false)|bool %}
|
||||||
|
access_key_id: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_access_key_id | to_json }}
|
||||||
|
secret_access_key: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_secret_access_key | to_json }}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
{% if matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_enabled %}
|
{% if matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_enabled %}
|
||||||
sse_customer_key: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_key | to_json }}
|
sse_customer_key: {{ matrix_synapse_ext_synapse_s3_storage_provider_config_sse_customer_key | to_json }}
|
||||||
|
|
Loading…
Reference in a new issue