kubespray/roles/kubernetes/master/tasks/main.yml

82 lines
2.2 KiB
YAML
Raw Normal View History

2015-10-04 04:19:50 +08:00
---
- import_tasks: pre-upgrade.yml
tags:
- k8s-pre-upgrade
- import_tasks: users-file.yml
when:
- kube_basic_auth|default(true)
- name: Create webhook token auth config
template:
src: webhook-token-auth-config.yaml.j2
dest: "{{ kube_config_dir }}/webhook-token-auth-config.yaml"
when: kube_webhook_token_auth|default(false)
- import_tasks: encrypt-at-rest.yml
when:
- kube_encrypt_secret_data
- name: Install | Copy kubectl binary from download dir
2018-09-16 10:50:56 +08:00
synchronize:
src: "{{ local_release_dir }}/hyperkube-{{ kube_version }}-{{ image_arch }}"
2018-09-16 10:50:56 +08:00
dest: "{{ bin_dir }}/kubectl"
compress: no
perms: yes
owner: no
group: no
2017-10-26 04:19:40 +08:00
changed_when: false
2018-09-16 10:50:56 +08:00
delegate_to: "{{ inventory_hostname }}"
2017-10-26 04:19:40 +08:00
tags:
- hyperkube
- kubectl
- upgrade
2018-07-30 17:55:25 +08:00
- name: install | Set kubectl binary permissions
file:
path: "{{ bin_dir }}/kubectl"
mode: "0755"
state: file
tags:
- hyperkube
- kubectl
- upgrade
- name: Make sure bash_completion.d folder exists
file:
name: "/etc/bash_completion.d/"
state: directory
when: ansible_os_family in ["ClearLinux"]
tags:
- kubectl
2017-01-18 01:36:58 +08:00
- name: Install kubectl bash completion
shell: "{{ bin_dir }}/kubectl completion bash >/etc/bash_completion.d/kubectl.sh"
2018-07-30 17:55:25 +08:00
when: ansible_os_family in ["Debian","RedHat"]
tags:
- kubectl
2017-01-18 01:36:58 +08:00
- name: Set kubectl bash completion file
file:
path: /etc/bash_completion.d/kubectl.sh
owner: root
group: root
mode: 0755
2017-01-18 01:36:58 +08:00
when: ansible_os_family in ["Debian","RedHat"]
tags:
- kubectl
- upgrade
- name: Disable SecurityContextDeny admission-controller and enable PodSecurityPolicy
set_fact:
kube_apiserver_admission_control: "{{ kube_apiserver_admission_control | default([]) | difference(['SecurityContextDeny']) | union(['PodSecurityPolicy']) | unique }}"
kube_apiserver_enable_admission_plugins: "{{ kube_apiserver_enable_admission_plugins | difference(['SecurityContextDeny']) | union(['PodSecurityPolicy']) | unique }}"
when: podsecuritypolicy_enabled
- name: Include kubeadm setup
import_tasks: kubeadm-setup.yml
- name: Include kubeadm etcd extra tasks
include_tasks: kubeadm-etcd.yml
when: etcd_kubeadm_enabled