Separate tasks in kubernetes role
This commit is contained in:
parent
07afd3f694
commit
be70ab72bb
@ -1,5 +1,7 @@
|
|||||||
---
|
---
|
||||||
- hosts: kubernetes
|
- hosts:
|
||||||
|
- k8s-masters
|
||||||
|
- k8s-nodes
|
||||||
remote_user: hybris
|
remote_user: hybris
|
||||||
become: yes
|
become: yes
|
||||||
|
|
||||||
@ -10,7 +12,4 @@
|
|||||||
roles:
|
roles:
|
||||||
- dns
|
- dns
|
||||||
- proxy
|
- proxy
|
||||||
- network
|
|
||||||
- kubernetes
|
- kubernetes
|
||||||
|
|
||||||
# TODO: set ipv6 static so it will stick even on reboots
|
|
||||||
|
35
roles/kubernetes/tasks/firewalld.yml
Normal file
35
roles/kubernetes/tasks/firewalld.yml
Normal file
@ -0,0 +1,35 @@
|
|||||||
|
---
|
||||||
|
########################
|
||||||
|
#### FIREWALL TASKS ####
|
||||||
|
########################
|
||||||
|
|
||||||
|
# ## kubernetes requirements
|
||||||
|
|
||||||
|
# - name: enable port 6443/tcp
|
||||||
|
# firewalld:
|
||||||
|
# port: 6443/tcp
|
||||||
|
# permanent: yes
|
||||||
|
# state: enabled
|
||||||
|
|
||||||
|
# - name: enable port 10250/tcp
|
||||||
|
# firewalld:
|
||||||
|
# port: 10250/tcp
|
||||||
|
# permanent: yes
|
||||||
|
# state: enabled
|
||||||
|
|
||||||
|
# - name: enable port 6443/udp
|
||||||
|
# firewalld:
|
||||||
|
# port: 6443/udp
|
||||||
|
# permanent: yes
|
||||||
|
# state: enabled
|
||||||
|
|
||||||
|
# - name: enable port 10250/udp
|
||||||
|
# firewalld:
|
||||||
|
# port: 10250/udp
|
||||||
|
# permanent: yes
|
||||||
|
# state: enabled
|
||||||
|
|
||||||
|
# ## reload firewalld after setting rules
|
||||||
|
|
||||||
|
# - name: reload firewalld
|
||||||
|
# shell: firewall-cmd --reload
|
@ -1,119 +1,29 @@
|
|||||||
---
|
---
|
||||||
#######################
|
|
||||||
#### NETWORK TASKS ####
|
|
||||||
#######################
|
|
||||||
|
|
||||||
- name: set static ipv6 for hosts
|
- name: upgrade all packages
|
||||||
lineinfile:
|
|
||||||
path: /etc/sysconfig/network-scripts/ifcfg-eth0
|
|
||||||
line: {{ item.line }}
|
|
||||||
regexp: {{ item.regexp }}
|
|
||||||
with_items:
|
|
||||||
- { regexp: "^IPV6INIT=", line: "IPV6INIT=yes" }
|
|
||||||
- { regexp: "^IPV6AUTOCONF=", line: "IPV6AUTOCONF=no" }
|
|
||||||
- { regexp: "^IPV6ADDR=", line: "IPV6ADDR={{ host_ipv6 }}"}
|
|
||||||
- { regexp: "^IPV6_DEFAULTGW=", line: "IPV6_DEFAULTGW={{ network_default_gw }}"}
|
|
||||||
|
|
||||||
- name: reboot
|
|
||||||
reboot:
|
|
||||||
|
|
||||||
########################
|
|
||||||
#### FIREWALL TASKS ####
|
|
||||||
########################
|
|
||||||
|
|
||||||
# ## kubernetes requirements
|
|
||||||
|
|
||||||
# - name: enable port 6443/tcp
|
|
||||||
# firewalld:
|
|
||||||
# port: 6443/tcp
|
|
||||||
# permanent: yes
|
|
||||||
# state: enabled
|
|
||||||
|
|
||||||
# - name: enable port 10250/tcp
|
|
||||||
# firewalld:
|
|
||||||
# port: 10250/tcp
|
|
||||||
# permanent: yes
|
|
||||||
# state: enabled
|
|
||||||
|
|
||||||
# - name: enable port 6443/udp
|
|
||||||
# firewalld:
|
|
||||||
# port: 6443/udp
|
|
||||||
# permanent: yes
|
|
||||||
# state: enabled
|
|
||||||
|
|
||||||
# - name: enable port 10250/udp
|
|
||||||
# firewalld:
|
|
||||||
# port: 10250/udp
|
|
||||||
# permanent: yes
|
|
||||||
# state: enabled
|
|
||||||
|
|
||||||
# ## reload firewalld after setting rules
|
|
||||||
|
|
||||||
# - name: reload firewalld
|
|
||||||
# shell: firewall-cmd --reload
|
|
||||||
|
|
||||||
######################
|
|
||||||
#### UPDATE TASKS ####
|
|
||||||
######################
|
|
||||||
|
|
||||||
- name: upgrade all packages
|
|
||||||
yum:
|
yum:
|
||||||
name: '*'
|
name: '*'
|
||||||
state: latest
|
state: latest
|
||||||
|
|
||||||
######################
|
- name: permanently disable selinux
|
||||||
#### KERNEL TASKS ####
|
|
||||||
######################
|
|
||||||
|
|
||||||
|
|
||||||
# TODO: get rid of inline http_proxy and fetch repo with the yum-repository ansible module
|
|
||||||
- name: import elrepo gpg key
|
|
||||||
shell: rpm -httpproxy http://[2001:470:6d:22c::1]:3128 --import https://www.elrepo.org/RPM-GPG-KEY-elrepo.org
|
|
||||||
|
|
||||||
- name: enable elrepo-release rpm
|
|
||||||
shell: rpm -httpproxy http://[2001:470:6d:22c::1]:3128 -Uvh http://www.elrepo.org/elrepo-release-7.0-3.el7.elrepo.noarch.rpm
|
|
||||||
|
|
||||||
# - name: Add repository
|
|
||||||
# yum_repository:
|
|
||||||
# name: elrepo-kernel
|
|
||||||
# description: elrepo-release
|
|
||||||
# baseurl: http://www.elrepo.org/elrepo-release-7.0-3.el7.elrepo.noarch.rpm
|
|
||||||
|
|
||||||
- name: install mainline kernel
|
|
||||||
shell: yum --enablerepo=elrepo-kernel install kernel-ml -y
|
|
||||||
|
|
||||||
- name: set default kernel version in grub
|
|
||||||
lineinfile:
|
|
||||||
dest: /etc/default/grub
|
|
||||||
regexp: "^GRUB_DEFAULT"
|
|
||||||
line: "GRUB_DEFAULT=0"
|
|
||||||
|
|
||||||
- name: write grub config
|
|
||||||
shell: grub2-mkconfig -o /boot/grub2/grub.cfg
|
|
||||||
|
|
||||||
####################
|
|
||||||
#### MAIN TASKS ####
|
|
||||||
####################
|
|
||||||
|
|
||||||
- name: permanently disable selinux
|
|
||||||
lineinfile:
|
lineinfile:
|
||||||
dest: /etc/sysconfig/selinux
|
dest: /etc/sysconfig/selinux
|
||||||
regexp: "^SELINUX="
|
regexp: "^SELINUX="
|
||||||
line: "SELINUX=disabled"
|
line: "SELINUX=disabled"
|
||||||
|
|
||||||
- name: temporarily disable swap
|
- name: temporarily disable swap
|
||||||
shell: swapoff -a
|
shell: swapoff -a
|
||||||
|
|
||||||
- name: permanently disable swap
|
- name: permanently disable swap
|
||||||
lineinfile:
|
lineinfile:
|
||||||
dest: /etc/fstab
|
dest: /etc/fstab
|
||||||
regexp: "^/dev/mapper/centos-swap"
|
regexp: "^/dev/mapper/centos-swap"
|
||||||
line: "# /dev/mapper/centos-swap swap swap defaults 0 0"
|
line: "# /dev/mapper/centos-swap swap swap defaults 0 0"
|
||||||
|
|
||||||
- name: activate kernel module
|
- name: activate kernel module
|
||||||
shell: modprobe br_netfilter
|
shell: modprobe br_netfilter
|
||||||
|
|
||||||
- name: enable bridge-nf-call-iptables
|
- name: enable bridge-nf-call-iptables
|
||||||
sysctl:
|
sysctl:
|
||||||
name: net.bridge.bridge-nf-call-iptables
|
name: net.bridge.bridge-nf-call-iptables
|
||||||
value: 1
|
value: 1
|
||||||
@ -121,7 +31,7 @@
|
|||||||
state: present
|
state: present
|
||||||
reload: yes
|
reload: yes
|
||||||
|
|
||||||
- name: enable bridge-nf-call-ip6tables
|
- name: enable bridge-nf-call-ip6tables
|
||||||
sysctl:
|
sysctl:
|
||||||
name: net.bridge.bridge-nf-call-ip6tables
|
name: net.bridge.bridge-nf-call-ip6tables
|
||||||
value: 1
|
value: 1
|
||||||
@ -129,7 +39,7 @@
|
|||||||
state: present
|
state: present
|
||||||
reload: yes
|
reload: yes
|
||||||
|
|
||||||
- name: enable ipv6 default forwarding
|
- name: enable ipv6 default forwarding
|
||||||
sysctl:
|
sysctl:
|
||||||
name: net.ipv6.conf.default.forwarding
|
name: net.ipv6.conf.default.forwarding
|
||||||
value: 1
|
value: 1
|
||||||
@ -137,16 +47,30 @@
|
|||||||
state: present
|
state: present
|
||||||
reload: yes
|
reload: yes
|
||||||
|
|
||||||
- name: add docker-ce yum repository
|
- name: add docker-ce yum repository
|
||||||
shell: yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo
|
shell: yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo
|
||||||
|
|
||||||
|
|
||||||
- name: copy kubernetes repo config
|
- name: copy kubernetes repo config
|
||||||
copy:
|
copy:
|
||||||
src: ../files/kubernetes.repo
|
src: ../files/kubernetes.repo
|
||||||
dest: /etc/yum.repos.d/kubernetes.repo
|
dest: /etc/yum.repos.d/kubernetes.repo
|
||||||
|
|
||||||
- name: install packages
|
- name: create cni config directory
|
||||||
|
file:
|
||||||
|
path: /etc/cni/net.d
|
||||||
|
state: directory
|
||||||
|
|
||||||
|
# TODO: this
|
||||||
|
# - name: copy cni config
|
||||||
|
# template:
|
||||||
|
# src: "../files/####CNI CONFIG####"
|
||||||
|
# dest: /etc/cni/net.d/####CNI CONFIG####
|
||||||
|
# owner: root
|
||||||
|
# group: root
|
||||||
|
# with_items: "{{ kubernetes }}"
|
||||||
|
|
||||||
|
- name: install packages
|
||||||
yum:
|
yum:
|
||||||
name:
|
name:
|
||||||
- yum-utils
|
- yum-utils
|
||||||
@ -156,26 +80,27 @@
|
|||||||
- kubelet
|
- kubelet
|
||||||
- kubeadm
|
- kubeadm
|
||||||
- kubectl
|
- kubectl
|
||||||
|
- kubernetes-cni
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: set cgroup
|
- name: set cgroup
|
||||||
lineinfile:
|
lineinfile:
|
||||||
dest: /etc/systemd/system/kubelet.service.d/10-kubeadm.conf
|
dest: /etc/systemd/system/kubelet.service.d/10-kubeadm.conf
|
||||||
regexp: "^cgroup-driver="
|
regexp: "^cgroup-driver="
|
||||||
line: "cgroup-driver=cgroupfs"
|
line: "cgroup-driver=cgroupfs"
|
||||||
|
|
||||||
- name: force systemd to reread configs and restart service kubelet
|
- name: force systemd to reread configs and restart service docker
|
||||||
systemd:
|
systemd:
|
||||||
name: docker
|
name: docker
|
||||||
enabled: yes
|
enabled: yes
|
||||||
state: restarted
|
state: restarted
|
||||||
|
|
||||||
- name: force systemd to reread configs and restart service kubelet
|
- name: force systemd to reread configs and restart service kubelet
|
||||||
systemd:
|
systemd:
|
||||||
name: kubelet
|
name: kubelet
|
||||||
enabled: yes
|
enabled: yes
|
||||||
state: restarted
|
state: restarted
|
||||||
daemon_reload: yes
|
daemon_reload: yes
|
||||||
|
|
||||||
- name: reboot
|
- name: reboot
|
||||||
reboot:
|
reboot:
|
30
roles/kubernetes/tasks/update_kernel.yml
Normal file
30
roles/kubernetes/tasks/update_kernel.yml
Normal file
@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
######################
|
||||||
|
#### KERNEL TASKS ####
|
||||||
|
######################
|
||||||
|
|
||||||
|
|
||||||
|
# TODO: get rid of inline http_proxy and fetch repo with the yum-repository ansible module
|
||||||
|
- name: import elrepo gpg key
|
||||||
|
shell: rpm -httpproxy http://[2001:470:6d:22c::1]:3128 --import https://www.elrepo.org/RPM-GPG-KEY-elrepo.org
|
||||||
|
|
||||||
|
- name: enable elrepo-release rpm
|
||||||
|
shell: rpm -httpproxy http://[2001:470:6d:22c::1]:3128 -Uvh http://www.elrepo.org/elrepo-release-7.0-3.el7.elrepo.noarch.rpm
|
||||||
|
|
||||||
|
# - name: Add repository
|
||||||
|
# yum_repository:
|
||||||
|
# name: elrepo-kernel
|
||||||
|
# description: elrepo-release
|
||||||
|
# baseurl: http://www.elrepo.org/elrepo-release-7.0-3.el7.elrepo.noarch.rpm
|
||||||
|
|
||||||
|
- name: install mainline kernel
|
||||||
|
shell: yum --enablerepo=elrepo-kernel install kernel-ml -y
|
||||||
|
|
||||||
|
- name: set default kernel version in grub
|
||||||
|
lineinfile:
|
||||||
|
dest: /etc/default/grub
|
||||||
|
regexp: "^GRUB_DEFAULT"
|
||||||
|
line: "GRUB_DEFAULT=0"
|
||||||
|
|
||||||
|
- name: write grub config
|
||||||
|
shell: grub2-mkconfig -o /boot/grub2/grub.cfg
|
@ -1,67 +1,56 @@
|
|||||||
---
|
---
|
||||||
- name: install packages
|
|
||||||
yum:
|
|
||||||
name:
|
|
||||||
- libvirt-devel
|
|
||||||
- git
|
|
||||||
- gcc
|
|
||||||
- unzip
|
|
||||||
state: present
|
|
||||||
become: yes
|
|
||||||
|
|
||||||
- name: download and install terraform 0.11.11 release
|
- name: remove files and directories
|
||||||
unarchive:
|
|
||||||
src: https://releases.hashicorp.com/terraform/0.11.11/terraform_0.11.11_linux_amd64.zip
|
|
||||||
dest: /usr/local/bin
|
|
||||||
remote_src: yes
|
|
||||||
become: yes
|
|
||||||
|
|
||||||
- name: download and install golang 1.11.4 release
|
|
||||||
unarchive:
|
|
||||||
src: https://dl.google.com/go/go1.11.4.linux-amd64.tar.gz
|
|
||||||
dest: /usr/local
|
|
||||||
remote_src: yes
|
|
||||||
become: yes
|
|
||||||
|
|
||||||
- name: export path
|
|
||||||
lineinfile:
|
|
||||||
path: /etc/profile
|
|
||||||
regexp: '^export PATH=$PATH:/usr/local/go/bin'
|
|
||||||
line: 'export PATH=$PATH:/usr/local/go/bin'
|
|
||||||
become: yes
|
|
||||||
|
|
||||||
- name: go get terraform-provider-libvirt
|
|
||||||
shell: /usr/local/go/bin/go get github.com/dmacvicar/terraform-provider-libvirt
|
|
||||||
|
|
||||||
- name: go install terraform-provider-libvirt
|
|
||||||
shell: /usr/local/go/bin/go install
|
|
||||||
args:
|
|
||||||
chdir: /home/{{ remote_user }}/go/src/github.com/dmacvicar/terraform-provider-libvirt
|
|
||||||
|
|
||||||
- name: create terraform config directory
|
|
||||||
file:
|
file:
|
||||||
path: /home/{{ remote_user }}/.terraform.d/
|
path: "/home/{{ ansible_ssh_user }}/terraform/"
|
||||||
state: directory
|
state: "{{ item }}"
|
||||||
|
with_items:
|
||||||
|
- absent
|
||||||
|
- directory
|
||||||
|
|
||||||
- name: create terraform plugin directory
|
- name: "download qcow2 cloud image"
|
||||||
file:
|
|
||||||
path: /home/{{ remote_user }}/.terraform.d/plugins
|
|
||||||
state: directory
|
|
||||||
|
|
||||||
- name: install terraform-provider-libvirt
|
|
||||||
copy:
|
copy:
|
||||||
src: /home/{{ remote_user }}/go/bin/terraform-provider-libvirt
|
src: "/home/{{ ansible_ssh_user }}/images/{{ source_cloud_image_name }}"
|
||||||
dest: /home/{{ remote_user }}/.terraform.d/plugins/terraform-provider-libvirt
|
dest: "/home/{{ ansible_ssh_user }}/terraform/{{ source_cloud_image_name }}"
|
||||||
mode: 0777
|
|
||||||
owner: {{ remote_user }}
|
|
||||||
remote_src: yes
|
remote_src: yes
|
||||||
|
|
||||||
- name: delete terraform directory
|
- name: create vm definitions
|
||||||
file:
|
template:
|
||||||
path: /home/{{ remote_user }}/terraform
|
src: "../files/cloud-init.tf.j2"
|
||||||
state: absent
|
dest: "/home/{{ ansible_ssh_user }}/terraform/{{ item.hostname }}.tf"
|
||||||
|
owner: "{{ ansible_ssh_user }}"
|
||||||
|
group: "{{ ansible_ssh_user }}"
|
||||||
|
with_items: "{{ kubernetes }}"
|
||||||
|
|
||||||
- name: create terraform directory
|
- name: create cloud-init config
|
||||||
file:
|
template:
|
||||||
path: /home/{{ remote_user }}/terraform
|
src: "../files/cloud-init.cfg.j2"
|
||||||
state: directory
|
dest: "/home/{{ ansible_ssh_user }}/terraform/{{ item.hostname }}.cloud_init.cfg"
|
||||||
|
owner: "{{ ansible_ssh_user }}"
|
||||||
|
group: "{{ ansible_ssh_user }}"
|
||||||
|
with_items: "{{ kubernetes }}"
|
||||||
|
|
||||||
|
- name: create cloud-init network config
|
||||||
|
template:
|
||||||
|
src: "../files/cloud-init-network.cfg.j2"
|
||||||
|
dest: "/home/{{ ansible_ssh_user }}/terraform/{{ item.hostname }}.cloud_init_network.cfg"
|
||||||
|
owner: "{{ ansible_ssh_user }}"
|
||||||
|
group: "{{ ansible_ssh_user }}"
|
||||||
|
with_items: "{{ kubernetes }}"
|
||||||
|
|
||||||
|
- name: create libvirt_provider config
|
||||||
|
template:
|
||||||
|
src: "../files/libvirt_provider.tf.j2"
|
||||||
|
dest: "/home/{{ ansible_ssh_user }}/terraform/libvirt_provider.tf"
|
||||||
|
owner: "{{ ansible_ssh_user }}"
|
||||||
|
group: "{{ ansible_ssh_user }}"
|
||||||
|
|
||||||
|
- name: initialize terraform
|
||||||
|
shell: terraform init
|
||||||
|
args:
|
||||||
|
chdir: /home/{{ ansible_ssh_user }}/terraform/
|
||||||
|
|
||||||
|
- name: terraform deploy
|
||||||
|
terraform:
|
||||||
|
project_path: /home/{{ ansible_ssh_user }}/terraform
|
||||||
|
state: present
|
||||||
|
Loading…
Reference in New Issue
Block a user