From d225a33637477a8f61ce31ac5f7e2cbd393ac8e6 Mon Sep 17 00:00:00 2001
From: Florian Pritz <bluewind@xinu.at>
Date: Sat, 2 Dec 2017 17:44:12 +0100
Subject: [PATCH] Store postgres passwords encrypted on server

Seems to be required with postgres 10 now.

Signed-off-by: Florian Pritz <bluewind@xinu.at>
---
 roles/kanboard/tasks/main.yml      | 2 +-
 roles/matrix/tasks/main.yml        | 2 +-
 roles/quassel/tasks/main.yml       | 2 +-
 roles/zabbix-server/tasks/main.yml | 2 +-
 4 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/roles/kanboard/tasks/main.yml b/roles/kanboard/tasks/main.yml
index 30a1e5113..bbc093269 100644
--- a/roles/kanboard/tasks/main.yml
+++ b/roles/kanboard/tasks/main.yml
@@ -30,7 +30,7 @@
   become_user: kanboard
 
 - name: create kanboard db user
-  postgresql_user: name={{ kanboard_db_user }} password={{ kanboard_db_password }}
+  postgresql_user: name={{ kanboard_db_user }} password={{ kanboard_db_password }} encrypted=true
   become: yes
   become_user: postgres
   become_method: su
diff --git a/roles/matrix/tasks/main.yml b/roles/matrix/tasks/main.yml
index 04ab19443..412ea99a1 100644
--- a/roles/matrix/tasks/main.yml
+++ b/roles/matrix/tasks/main.yml
@@ -74,7 +74,7 @@
   become_method: su
 
 - name: add synapse postgres user
-  postgresql_user: db=synapse name=synapse password={{ postgres_users.synapse }}
+  postgresql_user: db=synapse name=synapse password={{ postgres_users.synapse }} encrypted=true
   become: yes
   become_user: postgres
   become_method: su
diff --git a/roles/quassel/tasks/main.yml b/roles/quassel/tasks/main.yml
index 8a20ea130..a1aa76281 100644
--- a/roles/quassel/tasks/main.yml
+++ b/roles/quassel/tasks/main.yml
@@ -10,7 +10,7 @@
   become_method: su
 
 - name: add quassel postgres user
-  postgresql_user: db=quassel name=quassel password={{ postgres_users.quassel }}
+  postgresql_user: db=quassel name=quassel password={{ postgres_users.quassel }} encrypted=true
   become: yes
   become_user: postgres
   become_method: su
diff --git a/roles/zabbix-server/tasks/main.yml b/roles/zabbix-server/tasks/main.yml
index 33e700e5c..182142ea9 100644
--- a/roles/zabbix-server/tasks/main.yml
+++ b/roles/zabbix-server/tasks/main.yml
@@ -19,7 +19,7 @@
   file: path=/var/log/nginx/{{ zabbix_domain }} state=directory owner=root group=root mode=0755
 
 - name: create zabbix db user
-  postgresql_user: name={{ zabbix_db_user }} password={{ zabbix_db_password }}
+  postgresql_user: name={{ zabbix_db_user }} password={{ zabbix_db_password }} encrypted=true
   become: yes
   become_user: postgres
   become_method: su
-- 
GitLab