Repository navigation
feat(roles/apache_solr)!: support Debian, Ubuntu, RHEL 10 and Solr 9.11 - #425
Merged
Merged
Conversation
Pick the OpenJDK package per platform and Solr major version, since RHEL 10 and Debian 13 ship no Java 17. Compute the security.json password hashes on the controller with a salt derived from host and username: the shell variant needed pwgen (EPEL) and xxd, wrote an empty hash where xxd was missing, and changed security.json on every run. Write one Solr permission per name with every role holding it, as Solr rejected the joined names. Install and set modes as install_solr_service.sh does, extract once per version and set UMask=0027, so that runs are idempotent. Assert that no user has its username as password (rejected since Solr 9.11.0), that at least one user remains, and that the platform ships a Java for the Solr major version. Download from dlcdn.apache.org and fall back to the throttled archive.apache.org for releases the CDN no longer carries. BREAKING CHANGE: apache_solr__http_bind_address defaults to 127.0.0.1 and apache_solr__stop_wait to 180, the upstream defaults, instead of 0.0.0.0 and 15. Verified against Solr 9.11.0 on Rocky 8/9/10, Debian 12/13 and Ubuntu 22.04/24.04/26.04, plus an upgrade from 9.10.1 deployed by the previous role.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vars/<platform>.ymlper Solr major version: RHEL 10 and Debian 13 ship no Java 17, so Solr 9 runs on Java 21 there. Ubuntu stays on Java 17 deliberately instead ofdefault-jre-headless, sincebin/solrsilently disables the Security Manager from Java 24 on (Ubuntu 26.04 defaults to 25).Sha256AuthenticationProvider).apache_solr__http_bind_addressdefaults to127.0.0.1andapache_solr__stop_waitto180, as upstream ships them.dlcdn.apache.org, falling back to the throttledarchive.apache.org(> 10 min vs. 11 s for 9.11.0).Fixes to existing behaviour
Found by running the unchanged role against fresh clones:
pwgen).xxd(minimal Rocky 9) it wrote an empty password hash, so every login, the admin's included, got 401."name": "health,read,schema-read", which Solr discards as invalid.stateaborted the run.Password hashes are now computed on the controller with a salt derived from host and username.
security.jsonholds one permission per name with every role holding it,alllast, and a role holdingallin every entry. The installation followsinstall_solr_service.sh(root-owned program files, extracted once per version), plusUMask=0027on the unit.Tests
New Molecule scenario
extensions/molecule/apache_solr. Its inventory andverify.ymlran against fresh lab clones of Rocky 8/9/10, Debian 12/13 and Ubuntu 22.04/24.04/26.04 (converge, verify, idempotence withchanged=0, verify), plus an upgrade of a Rocky 9 host deployed by the previous role with Solr 9.10.1.molecule testitself was not run. Solr 10 is not tested.