Skip to content

feat(roles/apache_solr)!: support Debian, Ubuntu, RHEL 10 and Solr 9.11 - #425

Merged
markuslf merged 1 commit into
mainfrom
feat/apache-solr-debian
Oct 6, 2026
Merged

markuslf merged 1 commit into
mainfrom
feat/apache-solr-debian

Conversation

@markuslf

@markuslf markuslf commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

  • Supports Debian 12/13, RHEL 10 and Ubuntu 22.04/24.04/26.04. The OpenJDK package comes from vars/<platform>.yml per Solr major version: RHEL 10 and Debian 13 ship no Java 17, so Solr 9 runs on Java 21 there. Ubuntu stays on Java 17 deliberately instead of default-jre-headless, since bin/solr silently disables the Security Manager from Java 24 on (Ubuntu 26.04 defaults to 25).
  • Solr 9.11: the run aborts for a user whose password equals the username, since Solr 9.11 rejects such logins (Sha256AuthenticationProvider).
  • Breaking: apache_solr__http_bind_address defaults to 127.0.0.1 and apache_solr__stop_wait to 180, as upstream ships them.
  • Downloads from dlcdn.apache.org, falling back to the throttled archive.apache.org (> 10 min vs. 11 s for 9.11.0).

Fixes to existing behaviour

Found by running the unchanged role against fresh clones:

  • Without EPEL the role failed on RHEL (pwgen).
  • Without xxd (minimal Rocky 9) it wrote an empty password hash, so every login, the admin's included, got 401.
  • A role with several permissions became "name": "health,read,schema-read", which Solr discards as invalid.
  • Not idempotent: 10 changes and a Solr restart on every run (random salt, re-extracting the tarball, conflicting chmod passes).
  • Passwords appeared in the run output; a user without state aborted the run.

Password hashes are now computed on the controller with a salt derived from host and username. security.json holds one permission per name with every role holding it, all last, and a role holding all in every entry. The installation follows install_solr_service.sh (root-owned program files, extracted once per version), plus UMask=0027 on the unit.

Tests

New Molecule scenario extensions/molecule/apache_solr. Its inventory and verify.yml ran against fresh lab clones of Rocky 8/9/10, Debian 12/13 and Ubuntu 22.04/24.04/26.04 (converge, verify, idempotence with changed=0, verify), plus an upgrade of a Rocky 9 host deployed by the previous role with Solr 9.10.1. molecule test itself was not run. Solr 10 is not tested.

Pick the OpenJDK package per platform and Solr major version, since RHEL 10
and Debian 13 ship no Java 17. Compute the security.json password hashes on
the controller with a salt derived from host and username: the shell variant
needed pwgen (EPEL) and xxd, wrote an empty hash where xxd was missing, and
changed security.json on every run. Write one Solr permission per name with
every role holding it, as Solr rejected the joined names. Install and set
modes as install_solr_service.sh does, extract once per version and set
UMask=0027, so that runs are idempotent. Assert that no user has its
username as password (rejected since Solr 9.11.0), that at least one user
remains, and that the platform ships a Java for the Solr major version.

Download from dlcdn.apache.org and fall back to the throttled
archive.apache.org for releases the CDN no longer carries.

BREAKING CHANGE: apache_solr__http_bind_address defaults to 127.0.0.1 and
apache_solr__stop_wait to 180, the upstream defaults, instead of 0.0.0.0
and 15.

Verified against Solr 9.11.0 on Rocky 8/9/10, Debian 12/13 and Ubuntu
22.04/24.04/26.04, plus an upgrade from 9.10.1 deployed by the previous role.
@markuslf
markuslf merged commit 8384c25 into main Oct 6, 2026
13 checks passed
@markuslf
markuslf deleted the feat/apache-solr-debian branch October 6, 2026 07:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant