-
Notifications
You must be signed in to change notification settings - Fork 20
Release/679 #720
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Release/679 #720
Changes from all commits
Commits
Show all changes
33 commits
Select commit
Hold shift + click to select a range
a8a5ca1
parameterize cluster user privs
crosmuller c0064a6
make filebeat role working for our real environment
crosmuller 77695e4
default min privileges
crosmuller db1b317
minimal privileges sst_user
crosmuller f1622c5
fix indentationa nd warn non debian users
crosmuller b2b7bfb
fix handler
crosmuller 28ced0e
make services work with simple config
crosmuller a965c7d
use target file
crosmuller b6fde6d
use target file
crosmuller 63e0d00
add todo
crosmuller 16dc596
sst user privs add super
crosmuller 07012ad
real config
crosmuller 5c60295
use real binary
crosmuller d322325
deploy certificate
crosmuller 37268e9
temporarily disable services
crosmuller 7560289
enable services
crosmuller 00d55d3
Merge branch 'feature/filebeat' into release/679
crosmuller 12309c3
binlog monitor is the new name for replication client
crosmuller 0c9823b
Merge branch 'main' into release/679
crosmuller c4a00da
add certificate path
crosmuller a3cf498
disable services
crosmuller 59629a8
filebeat downgrade
crosmuller f2cb5c2
major version is enough
crosmuller 04c2812
fields is a dict not a list
crosmuller 8c771e3
deprecated use is no longer relevant
crosmuller 8db3e45
only works with square brackets
crosmuller a75f526
enable services
crosmuller 37091e4
disable services
crosmuller 38a9f3a
enable services
crosmuller 6271c55
Merge branch 'main' into release/679
crosmuller 5d49b0d
add gpg key
crosmuller 71a48dc
copy gpg key
crosmuller fcc00f6
Merge branch 'main' into release/679
crosmuller File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,2 @@ | ||
| - deploy certificates | ||
| - fix warnings |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,2 +1,20 @@ | ||
| filebeat_tls: False | ||
| filebeat_eblog: False | ||
| filebeat_tls: false | ||
| filebeat_eblog: false | ||
| filebeat_major_version: 7 | ||
| filebeat_apt_url: "https://artifacts.elastic.co/packages/oss-{{ filebeat_major_version }}.x/apt" | ||
| # add instances to group or host vars: | ||
| # filebeat_instances: | ||
| # - name: filebeat_sc_prd | ||
| # description: "Filebeat instance to send logs to logstash" # description for systemd unit file | ||
| # logpaths: | ||
| # - "/opt/openconext/logs/apps/prod_sc/eb/eb.log" | ||
| # - "/opt/openconext/logs/log_logins/prod_sc/eb-authentication.log" | ||
| # fields: | ||
| # - "env: prod_sc" | ||
| # logstash_hosts: '["logstashserver.example.com:5044","logstashserver2.example.com:5044"]' | ||
| # logstash_ca_path: "/etc/pki/tls/certs" | ||
| # logstash_ca: "{{ logstash_ca_path }}/logstash-prod-ca.pem" | ||
| # cacert_content: | | ||
| # -----BEGIN CERTIFICATE----- | ||
| # MIIEKzCCAxOgAwIBAgIJAMjE1SXBf9RJMA0GCSqGSIb3DQEBBQUAMIGqMQswCQYD | ||
| # VQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEVMBMG |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,31 @@ | ||
| -----BEGIN PGP PUBLIC KEY BLOCK----- | ||
|
|
||
| mQENBFI3HsoBCADXDtbNJnxbPqB1vDNtCsqhe49vFYsZN9IOZsZXgp7aHjh6CJBD | ||
| A+bGFOwyhbd7at35jQjWAw1O3cfYsKAmFy+Ar3LHCMkV3oZspJACTIgCrwnkic/9 | ||
| CUliQe324qvObU2QRtP4Fl0zWcfb/S8UYzWXWIFuJqMvE9MaRY1bwUBvzoqavLGZ | ||
| j3SF1SPO+TB5QrHkrQHBsmX+Jda6d4Ylt8/t6CvMwgQNlrlzIO9WT+YN6zS+sqHd | ||
| 1YK/aY5qhoLNhp9G/HxhcSVCkLq8SStj1ZZ1S9juBPoXV1ZWNbxFNGwOh/NYGldD | ||
| 2kmBf3YgCqeLzHahsAEpvAm8TBa7Q9W21C8vABEBAAG0RUVsYXN0aWNzZWFyY2gg | ||
| KEVsYXN0aWNzZWFyY2ggU2lnbmluZyBLZXkpIDxkZXZfb3BzQGVsYXN0aWNzZWFy | ||
| Y2gub3JnPokBTgQTAQgAOAIbAwIXgBYhBEYJWsyFSFgsGiaZqdJ9ZmzYjkK0BQJk | ||
| 9vrZBQsJCAcDBRUKCQgLBRYCAwEAAh4FAAoJENJ9ZmzYjkK00hoH+wYXZKgVb3Wv | ||
| 4AA/+T1IAf7edwgajr58bEyqds6/4v6uZBneUaqahUqMXgLFRX5dBSrAS7bvE/jx | ||
| +BBQx+rpFGxSwvFegRevE1zAGVtpgkFQX0RpRcKSmksucSBxikR/dPn9XdJSEVa8 | ||
| vPcs11V+2E5tq3LEP14zJL4MkJKQF0VJl5UUmKLS7U2F/IB5aXry9UWdMTnwNntX | ||
| kl2iDaViYF4MC6xTS24uLwND2St0Jvjt+xGEwbdBVvp+UZ/kG6IGkYM5eWGPuok/ | ||
| DHvjUdwTfyO9b5xGbqn5FJ3UFOwB/nOSFXHM8rsHRT/67gHcIl8YFqSQXpIkk9D3 | ||
| dCY+KieW0ue5AQ0EUjceygEIAOSVJc3DFuf3LsmUfGpUmnCqoUm76Eqqm8xynFEG | ||
| ZpczTChkwARRtckcfa/sGv376j+jk0c0Q71Uv3MnMLPGF+w3bpu8fLiPeW/cntf1 | ||
| 8uZ6DxJvHA/oaZZ6VPjwUGSeVydiPtZfTYsceO8Dxl3gpS6nHZ9Gsnfr/kcH9/11 | ||
| Ca73HBtmGVIkOI1mZKMbANO8cewY/i7fPxShu7B0Rb3jxVNGUuiRcfRiao0gWx0U | ||
| ZGpvuHplt7loFX2cbsHFAp9WsjYEbSohb/Y0K4NkyFhL82MfbcsEwsXPhRTFgJWw | ||
| s4vpuFg/kFFlnw0NNPVP1jNJLNCsMBMEpP1A7k6MRpylNnUAEQEAAYkBNgQYAQgA | ||
| IAIbDBYhBEYJWsyFSFgsGiaZqdJ9ZmzYjkK0BQJk9vsHAAoJENJ9ZmzYjkK0hWsH | ||
| /ArKtn12HM3+41zYo9qO4rTri7+IYTjSB/JDTOusZgZLd/HCp1xQo4SI2Eur3Rtx | ||
| USMWK1LEeBzsjwDT9yVceYekrBEqUVyRMSVYj+UeZK2s4LbXm9b4jxXVtaivmkMA | ||
| jtznndrD7kmm8ak+UsZplf6p6uZS9TZ9hjwoMmw5oMaS6TZkLT4KYGWeyzHJSUBX | ||
| YikY6vssDQu4SJ07m1f4Hz81J39QOcHln5I5HTK8Rh/VUFcxNnGg9360g55wWpiF | ||
| eUTeMyoXpOtffiUhiOtbRYsmSYC0D4Fd5yJnO3n1pwnVVVsM7RAC22rc5j/Dw8dR | ||
| GIHikRcYWeXTYW7veewK5Ss= | ||
| =ftS0 | ||
| -----END PGP PUBLIC KEY BLOCK----- |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,9 @@ | ||
| --- | ||
| - name: restart filebeat | ||
| service: name=filebeat state=restarted | ||
| - name: Restart filebeat | ||
| ansible.builtin.service: | ||
| name: filebeat_all.target | ||
| state: restarted | ||
|
|
||
| - name: Reload systemd | ||
| ansible.builtin.systemd_service: | ||
| daemon_reload: true |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,25 +1,141 @@ | ||
| --- | ||
| - name: Add Elasticsearch GPG key. | ||
| rpm_key: | ||
| key: http://packages.elasticsearch.org/GPG-KEY-elasticsearch | ||
| state: present | ||
|
|
||
| - name: Add elasticsearch yum repo | ||
| copy: | ||
| src: elasticsearch.repo | ||
| dest: /etc/yum.repos.d/elasticsearch.repo | ||
| mode: 0644 | ||
| - name: "/etc/Message for non redhat family servers" | ||
| when: ansible_facts['os_family'] != 'Debian' | ||
| ansible.builtin.fail: | ||
| msg: "Sorry, this role only works on Debian family servers" | ||
|
|
||
| - name: Install Filebeat | ||
| yum: name=filebeat state=present | ||
| - name: "Install filebeat on Debian" | ||
| when: ansible_facts["os_family"] == "Debian" | ||
| block: | ||
|
|
||
| #- name: Install cacert certificate | ||
| #copy: src={{ inventory_dir }}/files/certs/elastic_ca.pem dest=/etc/pki/elastic/ | ||
| - name: "Gather installed package facts" | ||
| ansible.builtin.package_facts: | ||
| manager: "apt" | ||
|
|
||
| - name: Install filebeat.yml | ||
| template: src=filebeat.yml.j2 dest=/etc/filebeat/filebeat.yml | ||
| - name: "Determine if Filebeat install is needed" | ||
| ansible.builtin.set_fact: | ||
| filebeat_install_needed: "{{ 'filebeat' not in ansible_facts.packages }}" | ||
|
|
||
| - name: "Install or upgrade filebeat when it is not installed already" | ||
| when: filebeat_install_needed | ||
| block: | ||
| - name: "Debug ansible facts packages" | ||
| ansible.builtin.debug: | ||
| msg: "ansible facts packages: {{ ansible_facts.packages }}" | ||
| verbosity: 3 | ||
|
|
||
| - name: "Debug file install needed" | ||
| ansible.builtin.debug: | ||
| msg: "filebeat_install_needed: {{ filebeat_install_needed }}" | ||
| verbosity: 2 | ||
|
|
||
| - name: "Ensure keyrings directory exists" | ||
| ansible.builtin.file: | ||
| path: "/etc/apt/keyrings" | ||
| state: "directory" | ||
| mode: '0755' | ||
|
|
||
| - name: "Copy Elasticsearch GPG key" | ||
| ansible.builtin.copy: | ||
| src: "/files/GPG-KEY-elasticsearch" | ||
| dest: "/tmp/GPG-KEY-elasticsearch" | ||
| mode: '0644' | ||
|
|
||
| - name: "Dearmor and install Elasticsearch GPG key" | ||
| ansible.builtin.command: gpg --dearmor -o /etc/apt/keyrings/elasticsearch.gpg /tmp/GPG-KEY-elasticsearch | ||
| args: | ||
| creates: "/etc/apt/keyrings/elasticsearch.gpg" | ||
|
|
||
| - name: "Add Elasticsearch repository" | ||
| ansible.builtin.template: | ||
| src: "elastic.list.j2" | ||
| dest: "/etc/apt/sources.list.d/elastic.list" | ||
| mode: '0644' | ||
|
|
||
| - name: "Update the repository cache and install filebeat" | ||
| ansible.builtin.apt: | ||
| name: "filebeat" | ||
| state: "present" | ||
| update_cache: true | ||
|
|
||
| - name: "Create configuration directories for all instances" | ||
| ansible.builtin.file: | ||
| path: "/etc/{{ item.name }}" | ||
| state: "directory" | ||
| owner: "root" | ||
| group: "root" | ||
| mode: "0755" | ||
| loop: "{{ filebeat_instances }}" | ||
|
|
||
| - name: "Create configuration files for all instances" | ||
| ansible.builtin.template: | ||
| dest: "/etc/{{ item.name }}/filebeat.yml" | ||
| src: "filebeat.yml.j2" | ||
| owner: "root" | ||
| group: "root" | ||
| mode: "0644" | ||
| loop: "{{ filebeat_instances }}" | ||
| notify: "Restart filebeat" | ||
|
|
||
| - name: "Create pem directory if necessary" | ||
| ansible.builtin.file: | ||
| dest: "{{ item.logstash_ca_path }}" | ||
| state: "directory" | ||
| owner: "root" | ||
| group: "root" | ||
| mode: "0755" | ||
| loop: "{{ filebeat_instances }}" | ||
| when: item.logstash_ca_path is defined | ||
|
|
||
| - name: "Create pem file if necessary" | ||
| ansible.builtin.template: | ||
| dest: "{{ item.logstash_ca }}" | ||
| src: "ca_cert.j2" | ||
| owner: "root" | ||
| group: "root" | ||
| mode: "0644" | ||
| loop: "{{ filebeat_instances }}" | ||
| when: item.logstash_ca is defined | ||
| notify: "Restart filebeat" | ||
|
|
||
| - name: "Create custom systemd files in /etc/systemd/system" | ||
| ansible.builtin.template: | ||
| dest: "/etc/systemd/system/{{ item.name }}.service" | ||
| src: "filebeat.item.service.j2" | ||
| owner: "root" | ||
| group: "root" | ||
| mode: "0755" | ||
| loop: "{{ filebeat_instances }}" | ||
| notify: | ||
| - restart filebeat | ||
| - "Restart filebeat" | ||
| - "Reload systemd" | ||
|
|
||
| - name: "Create systemd file in /etc/systemd/system for managing all filebeat services" | ||
| ansible.builtin.template: | ||
| dest: "/etc/systemd/system/filebeat_all.target" | ||
| src: "filebeat.target.j2" | ||
| owner: "root" | ||
| group: "root" | ||
| mode: "0644" | ||
| notify: | ||
| - "Restart filebeat" | ||
| - "Reload systemd" | ||
|
|
||
| - name: "Disable and stop service filebeat" # Because we have custom instances | ||
| ansible.builtin.service: | ||
| name: "filebeat" | ||
| state: "stopped" | ||
| enabled: false | ||
|
|
||
| - name: Enable filebeat instances services | ||
| ansible.builtin.service: | ||
| name: "{{ item.name }}" | ||
| enabled: true | ||
| loop: "{{ filebeat_instances }}" | ||
|
|
||
| - name: Enable and start filebeat | ||
| service: name=filebeat state=started enabled=yes | ||
| - name: Enable and start service filebeat_all | ||
| ansible.builtin.service: | ||
| name: filebeat_all.target | ||
| state: started | ||
| enabled: true | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| {{ item.cacert_content | default ("") }} |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| deb [signed-by=/etc/apt/keyrings/elasticsearch.gpg] {{ filebeat_apt_url }} stable main |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,14 @@ | ||
| [Unit] | ||
| Description={{ item.description }} | ||
| Documentation=https://www.elastic.co/products/beats/filebeat | ||
| PartOf=filebeat_all.target | ||
|
|
||
| [Service] | ||
| Environment="BEAT_LOG_OPTS=-e" | ||
| Environment="BEAT_CONFIG_OPTS=-c /etc/{{ item.name }}/filebeat.yml" | ||
| Environment="BEAT_PATH_OPTS=--path.home /usr/share/filebeat --path.config /etc/{{ item.name }} --path.data /var/lib/{{ item.name }} --path.logs /var/log/{{ item.name }}" | ||
| ExecStart=/usr/share/filebeat/bin/filebeat $BEAT_LOG_OPTS $BEAT_CONFIG_OPTS $BEAT_PATH_OPTS | ||
| Restart=always | ||
|
|
||
| [Install] | ||
| WantedBy=filebeat_all.target |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| [Unit] | ||
| Description=Filebeat services group | ||
| After=network.target | ||
|
|
||
| [Install] | ||
| WantedBy=multi-user.target |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,29 +1,40 @@ | ||
| filebeat.prospectors: | ||
| # filebeat.inputs: | ||
| # - type: log | ||
| # allow_deprecated_use: true | ||
| # enabled: true | ||
| # paths: | ||
| # - /var/log/*.log | ||
| # | ||
| # output.file: | ||
| # path: "/tmp/filebeat-output" | ||
| # filename: filebeat.json | ||
|
|
||
| {% if filebeat_eblog %} | ||
| filebeat.inputs: | ||
| - type: log | ||
| paths: | ||
| - /var/log/messages | ||
| include_lines: ["EBLOG"] | ||
| fields: | ||
| prog: EBLOG | ||
| env: {{ env }} | ||
| fields_under_root: true | ||
| {% endif %} | ||
| {%- for logpath in item.logpaths %} | ||
|
|
||
| - {{ logpath -}} | ||
| {% endfor %} | ||
|
|
||
| - type: log | ||
| paths: | ||
| - /var/log/messages | ||
| include_lines: ['EBAUTH'] | ||
| exclude_lines: ['influxd'] | ||
| fields: | ||
| prog: EBAUTH | ||
| env: {{ env }} | ||
| fields_under_root: true | ||
| {%- for field in item.fields %} | ||
|
|
||
| {{ field -}} | ||
| {% endfor %} | ||
|
|
||
| fields_under_root: true | ||
| filebeat.config.modules: | ||
| path: ${path.config}/modules.d/*.yml | ||
| reload.enabled: false | ||
| setup.template.settings: | ||
| index.number_of_shards: 1 | ||
| setup.kibana: | ||
| processors: | ||
| - drop_fields: | ||
| fields: ["host"] | ||
| output.logstash: | ||
| hosts: ["logstash.{{ base_domain }}:5044"] | ||
| {% if filebeat_tls %} | ||
| ssl.certificate_authorities: ["/etc/pki/filebeat/filebeat_ca.pem"] | ||
| {% endif %} | ||
| hosts: {{ item.logstash_hosts }} | ||
| {% if item.logstash_ca is defined %} | ||
| ssl.certificate_authorities: ["{{ item.logstash_ca }}"] | ||
| {% endif %} |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.