diff options
author | Guilhem Moulin <guilhem@fripost.org> | 2014-04-16 21:33:51 +0200 |
---|---|---|
committer | Guilhem Moulin <guilhem@fripost.org> | 2015-06-07 02:51:45 +0200 |
commit | c2bfdc087c0e5934c3b6836683da20afdb59998b (patch) | |
tree | 56674a70ab6ae339bf1bb68b10238fd6139c8efe /roles/common-SQL/tasks | |
parent | ddb49f59d2ac511a6bf252d4a6f0a05f8ed95c17 (diff) |
Add XXX comments for ad hoc fixes for some known bugs.
(To be removed when the fix enters stable.)
Diffstat (limited to 'roles/common-SQL/tasks')
-rw-r--r-- | roles/common-SQL/tasks/main.yml | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/roles/common-SQL/tasks/main.yml b/roles/common-SQL/tasks/main.yml index 553e269..a26f5f4 100644 --- a/roles/common-SQL/tasks/main.yml +++ b/roles/common-SQL/tasks/main.yml @@ -1,42 +1,45 @@ +# XXX If #742046 gets fixed, we should preseed mysql-server to use +# auth_socket as auth_plugin once the fix enters stable. - name: Install MySQL apt: pkg={{ item }} with_items: # XXX: In non-interactive mode apt-get doesn't put a password on # MySQL's root user; we fix that on the next task, but an intruder # could exploit the race condition and for instance create dummy # users. - mysql-common - mysql-server - python-mysqldb - name: Copy MySQL's configuration copy: src=etc/mysql/my.cnf dest=/etc/mysql/my.cnf owner=root group=root mode=0644 register: r notify: - Restart MySQL # We need to restart now and load the relevant authplugin before we # connect to the database. - meta: flush_handlers +# XXX Dirty fix for #742046 - name: Force root to use UNIX permissions mysql_user: name=root auth_plugin=auth_socket state=present - name: Disallow anonymous and TCP/IP root login mysql_user: name={{ item.name|default('') }} host={{ item.host }} state=absent with_items: - { host: '{{ inventory_hostname_short }}' } - { host: 'localhost' } - { host: '127.0.0.1'} - { host: '::1'} - { name: root, host: '{{ inventory_hostname_short }}' } - { name: root, host: '127.0.0.1'} - { name: root, host: '::1'} - name: Start MySQL service: name=mysql state=started |