since we're now using fsid for the directory name, it should be safe to
just copy the keys from all mon hosts. Once they are copied, the rest of
the hosts will just skip copying. :)
- name: Copy keys to the ansible server
fetch: src={{ item }} dest=fetch/{{ fsid }}/{{ item }} flat=yes
- when: ansible_fqdn == hostvars[groups['mons'][0]]['ansible_fqdn'] and cephx
+ when: cephx
with_items:
- /etc/ceph/ceph.client.admin.keyring # just in case another application needs it
- /var/lib/ceph/bootstrap-osd/ceph.keyring # this handles the non-colocation case