2015-10-04 04:19:50 +08:00
|
|
|
---
|
2023-07-26 22:36:22 +08:00
|
|
|
- name: Pre-upgrade control plane
|
|
|
|
import_tasks: pre-upgrade.yml
|
2017-10-05 15:43:04 +08:00
|
|
|
tags:
|
|
|
|
- k8s-pre-upgrade
|
2015-12-17 06:49:01 +08:00
|
|
|
|
2018-12-26 17:52:53 +08:00
|
|
|
- name: Create webhook token auth config
|
|
|
|
template:
|
|
|
|
src: webhook-token-auth-config.yaml.j2
|
|
|
|
dest: "{{ kube_config_dir }}/webhook-token-auth-config.yaml"
|
2021-07-12 15:00:47 +08:00
|
|
|
mode: 0640
|
2023-07-05 11:36:54 +08:00
|
|
|
when: kube_webhook_token_auth | default(false)
|
2018-12-26 17:52:53 +08:00
|
|
|
|
2020-08-24 21:29:41 +08:00
|
|
|
- name: Create webhook authorization config
|
|
|
|
template:
|
|
|
|
src: webhook-authorization-config.yaml.j2
|
|
|
|
dest: "{{ kube_config_dir }}/webhook-authorization-config.yaml"
|
2021-07-12 15:00:47 +08:00
|
|
|
mode: 0640
|
2023-07-05 11:36:54 +08:00
|
|
|
when: kube_webhook_authorization | default(false)
|
2020-08-24 21:29:41 +08:00
|
|
|
|
2021-04-06 15:35:35 +08:00
|
|
|
- name: Create kube-scheduler config
|
|
|
|
template:
|
2021-12-21 17:38:46 +08:00
|
|
|
src: kubescheduler-config.yaml.j2
|
2021-04-06 15:35:35 +08:00
|
|
|
dest: "{{ kube_config_dir }}/kubescheduler-config.yaml"
|
|
|
|
mode: 0644
|
|
|
|
|
2023-07-26 22:36:22 +08:00
|
|
|
- name: Apply Kubernetes encrypt at rest config
|
|
|
|
import_tasks: encrypt-at-rest.yml
|
2018-12-06 18:33:38 +08:00
|
|
|
when:
|
|
|
|
- kube_encrypt_secret_data
|
2023-09-21 21:55:29 +08:00
|
|
|
tags:
|
|
|
|
- kube-apiserver
|
2018-03-16 03:20:05 +08:00
|
|
|
|
2018-12-06 18:33:38 +08:00
|
|
|
- name: Install | Copy kubectl binary from download dir
|
2020-12-01 07:12:50 +08:00
|
|
|
copy:
|
2023-06-12 15:39:48 +08:00
|
|
|
src: "{{ downloads.kubectl.dest }}"
|
2018-09-16 10:50:56 +08:00
|
|
|
dest: "{{ bin_dir }}/kubectl"
|
2020-12-01 07:12:50 +08:00
|
|
|
mode: 0755
|
|
|
|
remote_src: true
|
2017-10-05 15:43:04 +08:00
|
|
|
tags:
|
|
|
|
- kubectl
|
|
|
|
- upgrade
|
2015-12-11 18:52:20 +08:00
|
|
|
|
2017-01-18 01:36:58 +08:00
|
|
|
- name: Install kubectl bash completion
|
|
|
|
shell: "{{ bin_dir }}/kubectl completion bash >/etc/bash_completion.d/kubectl.sh"
|
2018-07-30 17:55:25 +08:00
|
|
|
when: ansible_os_family in ["Debian","RedHat"]
|
2017-10-05 15:43:04 +08:00
|
|
|
tags:
|
|
|
|
- kubectl
|
2021-07-12 15:00:47 +08:00
|
|
|
ignore_errors: true # noqa ignore-errors
|
2016-11-14 16:22:46 +08:00
|
|
|
|
2019-08-05 09:15:48 +08:00
|
|
|
- name: Set kubectl bash completion file permissions
|
2017-01-18 01:36:58 +08:00
|
|
|
file:
|
|
|
|
path: /etc/bash_completion.d/kubectl.sh
|
2016-11-14 16:22:46 +08:00
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: 0755
|
2017-01-18 01:36:58 +08:00
|
|
|
when: ansible_os_family in ["Debian","RedHat"]
|
2017-10-05 15:43:04 +08:00
|
|
|
tags:
|
|
|
|
- kubectl
|
|
|
|
- upgrade
|
2021-07-12 15:00:47 +08:00
|
|
|
ignore_errors: true # noqa ignore-errors
|
2016-11-14 16:22:46 +08:00
|
|
|
|
2023-10-31 00:23:19 +08:00
|
|
|
- name: Set bash alias for kubectl
|
|
|
|
blockinfile:
|
|
|
|
path: /etc/bash_completion.d/kubectl.sh
|
|
|
|
block: |-
|
|
|
|
alias {{ kubectl_alias }}=kubectl
|
|
|
|
if [[ $(type -t compopt) = "builtin" ]]; then
|
|
|
|
complete -o default -F __start_kubectl {{ kubectl_alias }}
|
|
|
|
else
|
|
|
|
complete -o default -o nospace -F __start_kubectl {{ kubectl_alias }}
|
|
|
|
fi
|
|
|
|
state: present
|
|
|
|
marker: "# Ansible entries {mark}"
|
|
|
|
when:
|
|
|
|
- ansible_os_family in ["Debian","RedHat"]
|
|
|
|
- kubectl_alias is defined and kubectl_alias != ""
|
|
|
|
tags:
|
|
|
|
- kubectl
|
|
|
|
- upgrade
|
|
|
|
ignore_errors: true # noqa ignore-errors
|
|
|
|
|
2022-01-13 15:12:29 +08:00
|
|
|
- name: Define nodes already joined to existing cluster and first_kube_control_plane
|
|
|
|
import_tasks: define-first-kube-control.yml
|
|
|
|
|
2018-12-06 18:33:38 +08:00
|
|
|
- name: Include kubeadm setup
|
2018-01-29 19:37:48 +08:00
|
|
|
import_tasks: kubeadm-setup.yml
|
2019-06-21 02:12:51 +08:00
|
|
|
|
|
|
|
- name: Include kubeadm etcd extra tasks
|
|
|
|
include_tasks: kubeadm-etcd.yml
|
2022-02-23 00:53:16 +08:00
|
|
|
when: etcd_deployment_type == "kubeadm"
|
2019-09-10 01:33:20 +08:00
|
|
|
|
|
|
|
- name: Include kubeadm secondary server apiserver fixes
|
|
|
|
include_tasks: kubeadm-fix-apiserver.yml
|
2021-03-09 15:55:00 +08:00
|
|
|
|
|
|
|
- name: Include kubelet client cert rotation fixes
|
|
|
|
include_tasks: kubelet-fix-client-cert-rotation.yml
|
|
|
|
when: kubelet_rotate_certificates
|
2021-03-23 02:22:48 +08:00
|
|
|
|
|
|
|
- name: Install script to renew K8S control plane certificates
|
|
|
|
template:
|
|
|
|
src: k8s-certs-renew.sh.j2
|
|
|
|
dest: "{{ bin_dir }}/k8s-certs-renew.sh"
|
2021-07-12 15:00:47 +08:00
|
|
|
mode: 0755
|
2021-03-23 02:22:48 +08:00
|
|
|
|
|
|
|
- name: Renew K8S control plane certificates monthly 1/2
|
|
|
|
template:
|
|
|
|
src: "{{ item }}.j2"
|
|
|
|
dest: "/etc/systemd/system/{{ item }}"
|
2021-07-12 15:00:47 +08:00
|
|
|
mode: 0644
|
2023-11-18 03:01:23 +08:00
|
|
|
validate: "sh -c '[ -f /usr/bin/systemd/system/factory-reset.target ] || exit 0 && systemd-analyze verify %s:{{item}}'"
|
|
|
|
# FIXME: check that systemd version >= 250 (factory-reset.target was introduced in that release)
|
|
|
|
# Remove once we drop support for systemd < 250
|
2021-03-23 02:22:48 +08:00
|
|
|
with_items:
|
|
|
|
- k8s-certs-renew.service
|
|
|
|
- k8s-certs-renew.timer
|
|
|
|
register: k8s_certs_units
|
|
|
|
when: auto_renew_certificates
|
|
|
|
|
|
|
|
- name: Renew K8S control plane certificates monthly 2/2
|
|
|
|
systemd:
|
|
|
|
name: k8s-certs-renew.timer
|
|
|
|
enabled: yes
|
|
|
|
state: started
|
2023-06-30 17:51:57 +08:00
|
|
|
daemon_reload: "{{ k8s_certs_units is changed }}"
|
2021-03-23 02:22:48 +08:00
|
|
|
when: auto_renew_certificates
|