nova_conf_path: /var/lib/config-data/puppet-generated/nova_libvirt/etc/nova/nova.conf
metadata:
description: 'When using Neutron, the `firewall_driver` option in Nova must be set
to `NoopFirewallDriver`.
'
groups:
- post-deployment
name: Verify NoOpFirewallDriver is set in Nova
driver:
name: podman
log: true
platforms:
- dockerfile: Dockerfile
environment:
http_proxy: '{{ lookup(''env'', ''http_proxy'') }}'
https_proxy: '{{ lookup(''env'', ''https_proxy'') }}'
hostname: ubi8
image: ubi8/ubi-init
name: ubi8
pkg_extras: python*-setuptools python*-pyyaml
privileged: true
registry:
url: registry.access.redhat.com
ulimits:
- host
volumes:
- /etc/ci/mirror_info.sh:/etc/ci/mirror_info.sh:ro
- /etc/pki/rpm-gpg:/etc/pki/rpm-gpg
- /opt/yum.repos.d:/etc/yum.repos.d:rw
provisioner:
env:
ANSIBLE_LIBRARY: ${ANSIBLE_LIBRARY:-/usr/share/ansible/plugins/modules}
ANSIBLE_STDOUT_CALLBACK: yaml
inventory:
hosts:
all:
hosts:
ubi8:
ansible_python_interpreter: /usr/bin/python3
log: true
name: ansible
scenario:
test_sequence:
- destroy
- create
- prepare
- converge
- verify
- destroy
verifier:
name: testinfra
hosts:
all:
hosts:
ubi8:
ansible_python_interpreter: /usr/bin/python3
- gather_facts: false
hosts: all
name: Converge
tasks:
- block:
- copy:
content: '[DEFAULT]
firewall_driver = nova.virt.firewall.NoopFirewallDriver
'
dest: /nova.conf
name: Create a correct Nova config file
- include_role:
name: no_op_firewall_nova_driver
vars:
nova_conf_path: /nova.conf
- debug:
msg: The validation works as expected!
name: Successful Validation
- block:
- ini_file:
backup: true
dest: /nova.conf
option: firewall_driver
section: DEFAULT
value: CHANGEME
name: Modifying Nova config file
- include_role:
name: no_op_firewall_nova_driver
vars:
nova_conf_path: /nova.conf
name: Failing Validation
rescue:
- meta: clear_host_errors
name: Clear host errors
- debug:
msg: The validation fails as expected! End the playbook run
- meta: end_play
name: End play
- fail:
msg: 'No-op-firewall-nova-driver validation failed finding bad configuration!
'
name: Fail the test
vars:
nova_conf_path: /nova.conf
Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.