diff --git a/defaults/main.yml b/defaults/main.yml index 64d71a09..4cd366c9 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -862,11 +862,11 @@ postgresql_yum_repository_url: "http://yum.postgresql.org" postgresql_pgdg_repository_url: "https://download.postgresql.org/pub/repos/yum" # YUM (RedHat, CentOS, etc.) baseurl/gpgkey -postgresql_yum_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/{{ ansible_os_family | lower }}/rhel-{{ ansible_distribution_major_version }}-{{ ansible_architecture }}" +postgresql_yum_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/{{ ansible_facts['os_family'] | lower }}/rhel-{{ ansible_facts['distribution_major_version'] }}-{{ ansible_facts['architecture'] }}" postgresql_yum_repository_gpgkey: "{{ postgresql_pgdg_repository_url }}/keys/PGDG-RPM-GPG-KEY-RHEL" # DNF (Fedora) baseurl/gpgkey -postgresql_dnf_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/fedora/fedora-{{ ansible_distribution_major_version }}-{{ ansible_architecture }}" +postgresql_dnf_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/fedora/fedora-{{ ansible_facts['distribution_major_version'] }}-{{ ansible_facts['architecture'] }}" postgresql_dnf_repository_gpgkey: "{{ postgresql_yum_repository_gpgkey }}" postgresql_apt_dependencies: ["python3-psycopg2", "locales"] diff --git a/tasks/extensions/contrib.yml b/tasks/extensions/contrib.yml index c95b22ab..ed78eeb2 100644 --- a/tasks/extensions/contrib.yml +++ b/tasks/extensions/contrib.yml @@ -6,7 +6,7 @@ state: present update_cache: yes cache_valid_time: "{{ apt_cache_valid_time | default (3600) }}" - when: ansible_os_family == "Debian" + when: ansible_facts['os_family'] == "Debian" notify: - restart postgresql @@ -14,7 +14,7 @@ yum: name: "postgresql{{ postgresql_version_terse }}-contrib" state: present - when: ansible_pkg_mgr == "yum" and ansible_distribution == "RedHat" + when: ansible_facts['pkg_mgr'] == "yum" and ansible_facts['distribution'] == "RedHat" notify: - restart postgresql @@ -22,6 +22,6 @@ dnf: name: "postgresql{{postgresql_version_terse}}-contrib" state: present - when: ansible_pkg_mgr == "dnf" and ansible_distribution == "Fedora" + when: ansible_facts['pkg_mgr'] == "dnf" and ansible_facts['distribution'] == "Fedora" notify: - restart postgresql diff --git a/tasks/extensions/dev_headers.yml b/tasks/extensions/dev_headers.yml index 343a51bd..33ce3de5 100644 --- a/tasks/extensions/dev_headers.yml +++ b/tasks/extensions/dev_headers.yml @@ -6,7 +6,7 @@ state: present update_cache: yes cache_valid_time: "{{ apt_cache_valid_time | default (3600) }}" - when: ansible_os_family == "Debian" + when: ansible_facts['os_family'] == "Debian" notify: - restart postgresql @@ -17,7 +17,7 @@ - "postgresql{{ postgresql_version_terse }}-devel" state: present update_cache: yes - when: ansible_pkg_mgr == "yum" and ansible_os_family == "RedHat" + when: ansible_facts['pkg_mgr'] == "yum" and ansible_facts['os_family'] == "RedHat" notify: - restart postgresql @@ -27,6 +27,6 @@ - "postgresql{{ postgresql_version_terse }}-libs" - "postgresql{{ postgresql_version_terse }}-devel" state: present - when: ansible_pkg_mgr == "dnf" and ansible_distribution == "Fedora" + when: ansible_facts['pkg_mgr'] == "dnf" and ansible_facts['distribution'] == "Fedora" notify: - restart postgresql diff --git a/tasks/extensions/extra_packages.yml b/tasks/extensions/extra_packages.yml index 6973136b..4563b167 100644 --- a/tasks/extensions/extra_packages.yml +++ b/tasks/extensions/extra_packages.yml @@ -3,26 +3,35 @@ - include_vars: "../../vars/extra_packages.yml" # keys +# The deprecated apt_key module is replaced by downloading the key into the +# trusted keyring directly. apt accepts ASCII armored keys, and the repository +# definitions below reference this keyring through signed-by. - name: PostgreSQL | Extensions | Add repo keys | apt - apt_key: - id: "{{ item.value.id }}" + ansible.builtin.get_url: url: "{{ item.value.url }}" - state: present - keyring: /etc/apt/trusted.gpg.d/{{ item.value.id }}.gpg - loop: "{{ postgresql_ext_extra_packages.apt_keys | default({}) | dict2items }}" + dest: "/etc/apt/trusted.gpg.d/{{ item.value.id }}.gpg" + owner: root + group: root + mode: "0644" + loop: "{{ postgresql_ext_extra_packages.apt_keys | default({}) | dict2items }}" when: - postgresql_ext_extra_packages is defined - - ansible_os_family == "Debian" + - ansible_facts['os_family'] == "Debian" # repositories +# The deprecated apt_repository module is replaced by writing the one-line +# sources.list entry verbatim, which also keeps apt < 2.4 (Debian 11) working. - name: PostgreSQL | Extensions | Add repos | apt - apt_repository: - repo: "{{ item.value }}" - state: present + ansible.builtin.copy: + content: "{{ item.value }}\n" + dest: "/etc/apt/sources.list.d/{{ item.key }}.list" + owner: root + group: root + mode: "0644" loop: "{{ postgresql_ext_extra_packages.apt_repositories | default({}) | dict2items }}" when: - postgresql_ext_extra_packages is defined - - ansible_os_family == "Debian" + - ansible_facts['os_family'] == "Debian" - name: PostgreSQL | Extensions | Add repos | RHEL yum_repository: name: "{{ item.value.name }}" @@ -33,7 +42,7 @@ loop: "{{ postgresql_ext_extra_packages.yum_repositories | default({}) | dict2items }}" when: - postgresql_ext_extra_packages is defined - - ansible_os_family == "RedHat" + - ansible_facts['os_family'] == "RedHat" # packages - name: PostgreSQL | Extensions | Add packages | apt @@ -44,7 +53,7 @@ cache_valid_time: "{{ apt_cache_valid_time | default (3600) }}" when: - postgresql_ext_extra_packages is defined - - ansible_os_family == "Debian" + - ansible_facts['os_family'] == "Debian" - name: PostgreSQL | Extensions | Add packages | RHEL yum: name: "{{ postgresql_ext_extra_packages.names }}" @@ -52,4 +61,4 @@ update_cache: yes when: - postgresql_ext_extra_packages is defined - - ansible_os_family == "RedHat" + - ansible_facts['os_family'] == "RedHat" diff --git a/tasks/install_apt.yml b/tasks/install_apt.yml index ff8fbb7c..adc8c305 100644 --- a/tasks/install_apt.yml +++ b/tasks/install_apt.yml @@ -2,7 +2,9 @@ # Purpose: Install PostgreSQL from PGDG on Debian/Ubuntu in a future-proof way # Notes: # - No use of deprecated top-level facts (uses ansible_facts[...] instead) -# - No use of deprecated apt_key (uses a keyring + signed-by) +# - No use of the deprecated apt_key module (uses a keyring + signed-by) +# - No use of the deprecated apt_repository module (writes the sources.list +# entry directly so that apt < 2.4 / Debian 11 keeps working) # - Uses HTTPS and proper keyring location to satisfy apt-secure # - Adds default_release only when PGDG suite is available @@ -39,25 +41,32 @@ when: ansible_facts['pkg_mgr'] == 'apt' # --- Remove old repository file --- -# We use a new repo file in next task +# Earlier versions of this role wrote an auto-named one-line sources.list +# entry. We now manage the repository in /etc/apt/sources.list.d/pgdg.list, +# so remove the legacy file to avoid defining the same repository twice. - name: PostgreSQL | Remove old PostgreSQL repository | apt - apt_repository: - repo: "deb http://apt.postgresql.org/pub/repos/apt/ {{ ansible_distribution_release }}-pgdg main {{ postgresql_version }}" + ansible.builtin.file: + path: "/etc/apt/sources.list.d/{{ item }}" state: absent + loop: + - apt_postgresql_org_pub_repos_apt.list + - apt_postgresql_org_pub_repos_apt.sources when: - ansible_facts['pkg_mgr'] == 'apt' - (postgresql_install_repository | default(true)) | bool # --- Add the PGDG APT repository (HTTPS + signed-by) --- -# We explicitly build the repo line to ensure the correct suite and signed-by usage. +# The deprecated apt_repository module is replaced by writing the one-line +# sources.list entry directly. This keeps working on apt < 2.4 (Debian 11), +# which does not understand deb822 .sources files yet. - name: Add PGDG APT repository - ansible.builtin.apt_repository: - repo: >- - deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.gpg] - {{ postgresql_apt_repo_base }} - {{ postgresql_apt_suite }} main - filename: pgdg - state: present + ansible.builtin.copy: + content: | + deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.gpg] {{ postgresql_apt_repo_base }} {{ postgresql_apt_suite }} {{ postgresql_apt_repo_components }} + dest: /etc/apt/sources.list.d/pgdg.list + owner: root + group: root + mode: "0644" when: - ansible_facts['pkg_mgr'] == 'apt' - (postgresql_install_repository | default(true)) | bool diff --git a/tasks/install_fedora.yml b/tasks/install_fedora.yml index 4a25b417..066912ec 100644 --- a/tasks/install_fedora.yml +++ b/tasks/install_fedora.yml @@ -15,7 +15,7 @@ - name: PIP install psycopg2-binary on Fedora 33 only if postgresql version < 10 pip: name: psycopg2-binary - when: postgresql_version_terse | int <= 96 and postgresql_version_terse | int >= 90 and ansible_distribution == 'Fedora' and ansible_distribution_major_version + when: postgresql_version_terse | int <= 96 and postgresql_version_terse | int >= 90 and ansible_facts['distribution'] == 'Fedora' and ansible_facts['distribution_major_version'] - name: PostgreSQL | Add yum Repository | dnf yum_repository: diff --git a/tasks/install_rhel.yml b/tasks/install_rhel.yml index 40860ed2..2a189858 100644 --- a/tasks/install_rhel.yml +++ b/tasks/install_rhel.yml @@ -22,7 +22,7 @@ - name: PostgreSQL | Disable postgresql module (necessary for RHEL8+) command: cmd: dnf module disable postgresql -y - when: "ansible_distribution_major_version == '8' or ansible_distribution_major_version == '9'" + when: "ansible_facts['distribution_major_version'] in ['8', '9']" register: disable_postgresql_module changed_when: - "disable_postgresql_module.rc == 0" diff --git a/vars/Debian_22.yml b/vars/Debian_22.yml index ca1d3942..fbc6f0fb 100644 --- a/vars/Debian_22.yml +++ b/vars/Debian_22.yml @@ -3,4 +3,4 @@ postgresql_service_name: "postgresql" -postgresql_apt_repository: "deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/postgresql.gpg] {{ postgresql_apt_repository_url }}/ {{ ansible_distribution_release }}-pgdg main {{ postgresql_version }}" +postgresql_apt_repository: "deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/postgresql.gpg] {{ postgresql_apt_repository_url }}/ {{ ansible_facts['distribution_release'] }}-pgdg main {{ postgresql_version }}"