Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -862,11 +862,11 @@ postgresql_yum_repository_url: "http://yum.postgresql.org"
postgresql_pgdg_repository_url: "https://download.postgresql.org/pub/repos/yum"

# YUM (RedHat, CentOS, etc.) baseurl/gpgkey
postgresql_yum_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/{{ ansible_os_family | lower }}/rhel-{{ ansible_distribution_major_version }}-{{ ansible_architecture }}"
postgresql_yum_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/{{ ansible_facts['os_family'] | lower }}/rhel-{{ ansible_facts['distribution_major_version'] }}-{{ ansible_facts['architecture'] }}"
postgresql_yum_repository_gpgkey: "{{ postgresql_pgdg_repository_url }}/keys/PGDG-RPM-GPG-KEY-RHEL"

# DNF (Fedora) baseurl/gpgkey
postgresql_dnf_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/fedora/fedora-{{ ansible_distribution_major_version }}-{{ ansible_architecture }}"
postgresql_dnf_repository_baseurl: "{{ postgresql_yum_repository_url }}/{{ postgresql_version }}/fedora/fedora-{{ ansible_facts['distribution_major_version'] }}-{{ ansible_facts['architecture'] }}"
postgresql_dnf_repository_gpgkey: "{{ postgresql_yum_repository_gpgkey }}"

postgresql_apt_dependencies: ["python3-psycopg2", "locales"]
Expand Down
6 changes: 3 additions & 3 deletions tasks/extensions/contrib.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,22 +6,22 @@
state: present
update_cache: yes
cache_valid_time: "{{ apt_cache_valid_time | default (3600) }}"
when: ansible_os_family == "Debian"
when: ansible_facts['os_family'] == "Debian"
notify:
- restart postgresql

- name: PostgreSQL | Extensions | Make sure the postgres contrib extensions are installed | RedHat
yum:
name: "postgresql{{ postgresql_version_terse }}-contrib"
state: present
when: ansible_pkg_mgr == "yum" and ansible_distribution == "RedHat"
when: ansible_facts['pkg_mgr'] == "yum" and ansible_facts['distribution'] == "RedHat"
notify:
- restart postgresql

- name: PostgreSQL | Extensions | Make sure the postgres contrib extensions are installed | Fedora
dnf:
name: "postgresql{{postgresql_version_terse}}-contrib"
state: present
when: ansible_pkg_mgr == "dnf" and ansible_distribution == "Fedora"
when: ansible_facts['pkg_mgr'] == "dnf" and ansible_facts['distribution'] == "Fedora"
notify:
- restart postgresql
6 changes: 3 additions & 3 deletions tasks/extensions/dev_headers.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
state: present
update_cache: yes
cache_valid_time: "{{ apt_cache_valid_time | default (3600) }}"
when: ansible_os_family == "Debian"
when: ansible_facts['os_family'] == "Debian"
notify:
- restart postgresql

Expand All @@ -17,7 +17,7 @@
- "postgresql{{ postgresql_version_terse }}-devel"
state: present
update_cache: yes
when: ansible_pkg_mgr == "yum" and ansible_os_family == "RedHat"
when: ansible_facts['pkg_mgr'] == "yum" and ansible_facts['os_family'] == "RedHat"
notify:
- restart postgresql

Expand All @@ -27,6 +27,6 @@
- "postgresql{{ postgresql_version_terse }}-libs"
- "postgresql{{ postgresql_version_terse }}-devel"
state: present
when: ansible_pkg_mgr == "dnf" and ansible_distribution == "Fedora"
when: ansible_facts['pkg_mgr'] == "dnf" and ansible_facts['distribution'] == "Fedora"
notify:
- restart postgresql
35 changes: 22 additions & 13 deletions tasks/extensions/extra_packages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,26 +3,35 @@
- include_vars: "../../vars/extra_packages.yml"

# keys
# The deprecated apt_key module is replaced by downloading the key into the
# trusted keyring directly. apt accepts ASCII armored keys, and the repository
# definitions below reference this keyring through signed-by.
- name: PostgreSQL | Extensions | Add repo keys | apt
apt_key:
id: "{{ item.value.id }}"
ansible.builtin.get_url:
url: "{{ item.value.url }}"
state: present
keyring: /etc/apt/trusted.gpg.d/{{ item.value.id }}.gpg
loop: "{{ postgresql_ext_extra_packages.apt_keys | default({}) | dict2items }}"
dest: "/etc/apt/trusted.gpg.d/{{ item.value.id }}.gpg"
owner: root
group: root
mode: "0644"
loop: "{{ postgresql_ext_extra_packages.apt_keys | default({}) | dict2items }}"
when:
- postgresql_ext_extra_packages is defined
- ansible_os_family == "Debian"
- ansible_facts['os_family'] == "Debian"

# repositories
# The deprecated apt_repository module is replaced by writing the one-line
# sources.list entry verbatim, which also keeps apt < 2.4 (Debian 11) working.
- name: PostgreSQL | Extensions | Add repos | apt
apt_repository:
repo: "{{ item.value }}"
state: present
ansible.builtin.copy:
content: "{{ item.value }}\n"
dest: "/etc/apt/sources.list.d/{{ item.key }}.list"
owner: root
group: root
mode: "0644"
loop: "{{ postgresql_ext_extra_packages.apt_repositories | default({}) | dict2items }}"
when:
- postgresql_ext_extra_packages is defined
- ansible_os_family == "Debian"
- ansible_facts['os_family'] == "Debian"
- name: PostgreSQL | Extensions | Add repos | RHEL
yum_repository:
name: "{{ item.value.name }}"
Expand All @@ -33,7 +42,7 @@
loop: "{{ postgresql_ext_extra_packages.yum_repositories | default({}) | dict2items }}"
when:
- postgresql_ext_extra_packages is defined
- ansible_os_family == "RedHat"
- ansible_facts['os_family'] == "RedHat"

# packages
- name: PostgreSQL | Extensions | Add packages | apt
Expand All @@ -44,12 +53,12 @@
cache_valid_time: "{{ apt_cache_valid_time | default (3600) }}"
when:
- postgresql_ext_extra_packages is defined
- ansible_os_family == "Debian"
- ansible_facts['os_family'] == "Debian"
- name: PostgreSQL | Extensions | Add packages | RHEL
yum:
name: "{{ postgresql_ext_extra_packages.names }}"
state: present
update_cache: yes
when:
- postgresql_ext_extra_packages is defined
- ansible_os_family == "RedHat"
- ansible_facts['os_family'] == "RedHat"
33 changes: 21 additions & 12 deletions tasks/install_apt.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
# Purpose: Install PostgreSQL from PGDG on Debian/Ubuntu in a future-proof way
# Notes:
# - No use of deprecated top-level facts (uses ansible_facts[...] instead)
# - No use of deprecated apt_key (uses a keyring + signed-by)
# - No use of the deprecated apt_key module (uses a keyring + signed-by)
# - No use of the deprecated apt_repository module (writes the sources.list
# entry directly so that apt < 2.4 / Debian 11 keeps working)
# - Uses HTTPS and proper keyring location to satisfy apt-secure
# - Adds default_release only when PGDG suite is available

Expand Down Expand Up @@ -39,25 +41,32 @@
when: ansible_facts['pkg_mgr'] == 'apt'

# --- Remove old repository file ---
# We use a new repo file in next task
# Earlier versions of this role wrote an auto-named one-line sources.list
# entry. We now manage the repository in /etc/apt/sources.list.d/pgdg.list,
# so remove the legacy file to avoid defining the same repository twice.
- name: PostgreSQL | Remove old PostgreSQL repository | apt
apt_repository:
repo: "deb http://apt.postgresql.org/pub/repos/apt/ {{ ansible_distribution_release }}-pgdg main {{ postgresql_version }}"
ansible.builtin.file:
path: "/etc/apt/sources.list.d/{{ item }}"
state: absent
loop:
- apt_postgresql_org_pub_repos_apt.list
- apt_postgresql_org_pub_repos_apt.sources
when:
- ansible_facts['pkg_mgr'] == 'apt'
- (postgresql_install_repository | default(true)) | bool

# --- Add the PGDG APT repository (HTTPS + signed-by) ---
# We explicitly build the repo line to ensure the correct suite and signed-by usage.
# The deprecated apt_repository module is replaced by writing the one-line
# sources.list entry directly. This keeps working on apt < 2.4 (Debian 11),
# which does not understand deb822 .sources files yet.
- name: Add PGDG APT repository
ansible.builtin.apt_repository:
repo: >-
deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.gpg]
{{ postgresql_apt_repo_base }}
{{ postgresql_apt_suite }} main
filename: pgdg
state: present
ansible.builtin.copy:
content: |
deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.gpg] {{ postgresql_apt_repo_base }} {{ postgresql_apt_suite }} {{ postgresql_apt_repo_components }}
dest: /etc/apt/sources.list.d/pgdg.list
owner: root
group: root
mode: "0644"
when:
- ansible_facts['pkg_mgr'] == 'apt'
- (postgresql_install_repository | default(true)) | bool
Expand Down
2 changes: 1 addition & 1 deletion tasks/install_fedora.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
- name: PIP install psycopg2-binary on Fedora 33 only if postgresql version < 10
pip:
name: psycopg2-binary
when: postgresql_version_terse | int <= 96 and postgresql_version_terse | int >= 90 and ansible_distribution == 'Fedora' and ansible_distribution_major_version
when: postgresql_version_terse | int <= 96 and postgresql_version_terse | int >= 90 and ansible_facts['distribution'] == 'Fedora' and ansible_facts['distribution_major_version']

- name: PostgreSQL | Add yum Repository | dnf
yum_repository:
Expand Down
2 changes: 1 addition & 1 deletion tasks/install_rhel.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@
- name: PostgreSQL | Disable postgresql module (necessary for RHEL8+)
command:
cmd: dnf module disable postgresql -y
when: "ansible_distribution_major_version == '8' or ansible_distribution_major_version == '9'"
when: "ansible_facts['distribution_major_version'] in ['8', '9']"
register: disable_postgresql_module
changed_when:
- "disable_postgresql_module.rc == 0"
Expand Down
2 changes: 1 addition & 1 deletion vars/Debian_22.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,4 @@

postgresql_service_name: "postgresql"

postgresql_apt_repository: "deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/postgresql.gpg] {{ postgresql_apt_repository_url }}/ {{ ansible_distribution_release }}-pgdg main {{ postgresql_version }}"
postgresql_apt_repository: "deb [arch=amd64 signed-by=/etc/apt/trusted.gpg.d/postgresql.gpg] {{ postgresql_apt_repository_url }}/ {{ ansible_facts['distribution_release'] }}-pgdg main {{ postgresql_version }}"