2022-10-09 19:24:44 +08:00
|
|
|
- block:
|
|
|
|
- name: 创建calico 证书请求
|
|
|
|
template: src=calico-csr.json.j2 dest={{ cluster_dir }}/ssl/calico-csr.json
|
|
|
|
|
|
|
|
- name: 创建 calico证书和私钥
|
|
|
|
shell: "cd {{ cluster_dir }}/ssl && {{ base_dir }}/bin/cfssl gencert \
|
|
|
|
-ca=ca.pem \
|
|
|
|
-ca-key=ca-key.pem \
|
|
|
|
-config=ca-config.json \
|
|
|
|
-profile=kubernetes calico-csr.json|{{ base_dir }}/bin/cfssljson -bare calico"
|
|
|
|
|
2022-11-26 10:56:52 +08:00
|
|
|
- name: 删除旧 calico-etcd-secrets
|
|
|
|
shell: "{{ base_dir }}/bin/kubectl -n kube-system delete secrets calico-etcd-secrets || echo NotFound"
|
2022-10-09 19:24:44 +08:00
|
|
|
|
|
|
|
- name: 创建 calico-etcd-secrets
|
|
|
|
shell: "cd {{ cluster_dir }}/ssl && \
|
|
|
|
{{ base_dir }}/bin/kubectl create secret generic -n kube-system calico-etcd-secrets \
|
|
|
|
--from-file=etcd-ca=ca.pem \
|
|
|
|
--from-file=etcd-key=calico-key.pem \
|
|
|
|
--from-file=etcd-cert=calico.pem"
|
|
|
|
|
|
|
|
- name: 配置 calico DaemonSet yaml文件
|
|
|
|
template: src=calico-{{ calico_ver_main }}.yaml.j2 dest={{ cluster_dir }}/yml/calico.yaml
|
|
|
|
|
2022-11-26 10:56:52 +08:00
|
|
|
- name: 删除 calico网络
|
|
|
|
shell: "{{ base_dir }}/bin/kubectl delete -f {{ cluster_dir }}/yml/calico.yaml || echo NotFound"
|
|
|
|
|
2022-10-09 19:24:44 +08:00
|
|
|
- name: 运行 calico网络
|
2022-11-26 10:56:52 +08:00
|
|
|
shell: "sleep 5 && {{ base_dir }}/bin/kubectl apply -f {{ cluster_dir }}/yml/calico.yaml"
|
2022-10-09 19:24:44 +08:00
|
|
|
run_once: true
|
|
|
|
connection: local
|
2022-11-26 10:56:52 +08:00
|
|
|
tags: force_change_certs
|
2022-10-09 19:24:44 +08:00
|
|
|
|
2019-05-31 00:00:01 +08:00
|
|
|
- name: 在节点创建相关目录
|
2017-11-22 12:34:51 +08:00
|
|
|
file: name={{ item }} state=directory
|
|
|
|
with_items:
|
2021-01-10 21:25:05 +08:00
|
|
|
- /etc/calico/ssl
|
2017-11-11 19:14:21 +08:00
|
|
|
|
2020-12-30 11:25:54 +08:00
|
|
|
- name: 分发calico证书相关
|
2021-01-10 21:25:05 +08:00
|
|
|
copy: src={{ cluster_dir }}/ssl/{{ item }} dest=/etc/calico/ssl/{{ item }}
|
2020-12-30 11:25:54 +08:00
|
|
|
with_items:
|
|
|
|
- ca.pem
|
|
|
|
- calico.pem
|
|
|
|
- calico-key.pem
|
2022-11-26 10:56:52 +08:00
|
|
|
tags: force_change_certs
|
2019-05-31 00:00:01 +08:00
|
|
|
|
2018-01-02 22:12:51 +08:00
|
|
|
- name: 删除默认cni配置
|
|
|
|
file: path=/etc/cni/net.d/10-default.conf state=absent
|
|
|
|
|
|
|
|
- name: 下载calicoctl 客户端
|
2017-11-11 19:14:21 +08:00
|
|
|
copy: src={{ base_dir }}/bin/{{ item }} dest={{ bin_dir }}/{{ item }} mode=0755
|
|
|
|
with_items:
|
2018-01-02 22:12:51 +08:00
|
|
|
#- calico
|
2017-11-22 12:34:51 +08:00
|
|
|
- calicoctl
|
2019-06-08 16:07:46 +08:00
|
|
|
ignore_errors: true
|
2017-11-11 19:14:21 +08:00
|
|
|
|
2017-11-22 12:34:51 +08:00
|
|
|
- name: 准备 calicoctl配置文件
|
|
|
|
template: src=calicoctl.cfg.j2 dest=/etc/calico/calicoctl.cfg
|
2018-06-18 00:04:00 +08:00
|
|
|
|
2022-10-09 19:24:44 +08:00
|
|
|
- name: 轮询等待calico-node 运行
|
|
|
|
shell: "{{ base_dir }}/bin/kubectl get pod -n kube-system -o wide|grep 'calico-node'|grep ' {{ inventory_hostname }} '|awk '{print $3}'"
|
2018-06-18 00:04:00 +08:00
|
|
|
register: pod_status
|
|
|
|
until: pod_status.stdout == "Running"
|
2018-08-30 20:17:05 +08:00
|
|
|
retries: 15
|
2018-11-21 23:04:59 +08:00
|
|
|
delay: 15
|
2019-02-25 23:11:08 +08:00
|
|
|
ignore_errors: true
|
2022-10-09 19:24:44 +08:00
|
|
|
connection: local
|
2022-11-26 10:56:52 +08:00
|
|
|
tags: force_change_certs
|
2022-06-29 19:02:54 +08:00
|
|
|
|
|
|
|
- import_tasks: calico-rr.yml
|
|
|
|
when: 'CALICO_RR_ENABLED|bool'
|
2022-11-26 10:56:52 +08:00
|
|
|
tags: force_change_certs
|