2015-12-31 00:11:33 +08:00
|
|
|
---
|
2017-09-27 21:47:47 +08:00
|
|
|
- include: verify-settings.yml
|
|
|
|
tags: asserts
|
2017-01-02 19:14:03 +08:00
|
|
|
|
2017-01-05 18:35:16 +08:00
|
|
|
- name: Force binaries directory for Container Linux by CoreOS
|
2016-08-27 01:24:47 +08:00
|
|
|
set_fact:
|
|
|
|
bin_dir: "/opt/bin"
|
2017-01-05 23:32:08 +08:00
|
|
|
when: ansible_os_family in ["CoreOS", "Container Linux by CoreOS"]
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: facts
|
2016-08-27 01:24:47 +08:00
|
|
|
|
2016-12-02 19:37:22 +08:00
|
|
|
- name: check bin dir exists
|
|
|
|
file:
|
|
|
|
path: "{{bin_dir}}"
|
|
|
|
state: directory
|
|
|
|
owner: root
|
|
|
|
become: true
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2016-08-22 20:45:42 +08:00
|
|
|
|
2016-07-20 17:35:06 +08:00
|
|
|
- include: set_facts.yml
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: facts
|
2016-07-20 17:35:06 +08:00
|
|
|
|
2016-01-09 17:45:50 +08:00
|
|
|
- name: gather os specific variables
|
|
|
|
include_vars: "{{ item }}"
|
|
|
|
with_first_found:
|
|
|
|
- files:
|
2017-08-24 17:09:52 +08:00
|
|
|
- "{{ ansible_distribution|lower }}-{{ ansible_distribution_version|lower|replace('/', '_') }}.yml"
|
|
|
|
- "{{ ansible_distribution|lower }}-{{ ansible_distribution_release }}.yml"
|
|
|
|
- "{{ ansible_distribution|lower }}-{{ ansible_distribution_major_version|lower|replace('/', '_') }}.yml"
|
|
|
|
- "{{ ansible_distribution|lower }}.yml"
|
|
|
|
- "{{ ansible_os_family|lower }}.yml"
|
|
|
|
- defaults.yml
|
2016-01-09 17:45:50 +08:00
|
|
|
paths:
|
2017-08-24 17:09:52 +08:00
|
|
|
- ../vars
|
2016-02-20 01:48:53 +08:00
|
|
|
skip: true
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: facts
|
2016-02-20 01:48:53 +08:00
|
|
|
|
2017-09-14 02:00:51 +08:00
|
|
|
- name: Create kubernetes directories
|
2016-01-30 23:04:47 +08:00
|
|
|
file:
|
2017-09-14 02:00:51 +08:00
|
|
|
path: "{{ item }}"
|
2016-01-30 23:04:47 +08:00
|
|
|
state: directory
|
2017-02-06 20:58:54 +08:00
|
|
|
owner: kube
|
2017-04-26 20:11:13 +08:00
|
|
|
when: inventory_hostname in groups['k8s-cluster']
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: [kubelet, k8s-secrets, kube-controller-manager, kube-apiserver, bootstrap-os, apps, network, master, node]
|
2017-09-14 02:00:51 +08:00
|
|
|
with_items:
|
|
|
|
- "{{ kube_config_dir }}"
|
|
|
|
- "{{ kube_config_dir }}/ssl"
|
|
|
|
- "{{ kube_manifest_dir }}"
|
|
|
|
- "{{ kube_script_dir }}"
|
2016-01-30 23:04:47 +08:00
|
|
|
|
2016-03-24 00:27:06 +08:00
|
|
|
- name: check cloud_provider value
|
|
|
|
fail:
|
2017-02-17 11:59:40 +08:00
|
|
|
msg: "If set the 'cloud_provider' var must be set either to 'generic', 'gce', 'aws', 'azure', 'openstack' or 'vsphere'"
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- cloud_provider is defined
|
|
|
|
- cloud_provider not in ['generic', 'gce', 'aws', 'azure', 'openstack', 'vsphere']
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: [cloud-provider, facts]
|
2016-03-29 20:50:22 +08:00
|
|
|
|
2017-02-17 11:59:40 +08:00
|
|
|
- include: "{{ cloud_provider }}-credential-check.yml"
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- cloud_provider is defined
|
|
|
|
- cloud_provider in [ 'openstack', 'azure', 'vsphere' ]
|
2017-03-07 00:51:38 +08:00
|
|
|
tags: [cloud-provider, facts]
|
2016-11-29 17:20:28 +08:00
|
|
|
|
2016-01-30 23:04:47 +08:00
|
|
|
- name: Create cni directories
|
|
|
|
file:
|
|
|
|
path: "{{ item }}"
|
|
|
|
state: directory
|
2017-02-06 20:58:54 +08:00
|
|
|
owner: kube
|
2016-01-30 23:04:47 +08:00
|
|
|
with_items:
|
|
|
|
- "/etc/cni/net.d"
|
|
|
|
- "/opt/cni/bin"
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
2017-08-29 02:11:01 +08:00
|
|
|
- kube_network_plugin in ["calico", "weave", "canal", "flannel"]
|
2017-04-26 20:11:13 +08:00
|
|
|
- inventory_hostname in groups['k8s-cluster']
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: [network, calico, weave, canal, bootstrap-os]
|
2016-01-30 23:04:47 +08:00
|
|
|
|
2016-01-26 01:16:56 +08:00
|
|
|
- name: Update package management cache (YUM)
|
2017-02-18 05:22:34 +08:00
|
|
|
yum:
|
|
|
|
update_cache: yes
|
|
|
|
name: '*'
|
2017-03-17 17:55:17 +08:00
|
|
|
register: yum_task_result
|
|
|
|
until: yum_task_result|succeeded
|
|
|
|
retries: 4
|
|
|
|
delay: "{{ retry_stagger | random + 3 }}"
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- ansible_pkg_mgr == 'yum'
|
|
|
|
- not is_atomic
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2016-01-25 09:06:34 +08:00
|
|
|
|
2016-03-30 16:27:29 +08:00
|
|
|
- name: Install latest version of python-apt for Debian distribs
|
2017-02-18 05:22:34 +08:00
|
|
|
apt:
|
|
|
|
name: python-apt
|
|
|
|
state: latest
|
|
|
|
update_cache: yes
|
|
|
|
cache_valid_time: 3600
|
2015-12-31 05:15:18 +08:00
|
|
|
when: ansible_os_family == "Debian"
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2016-01-09 17:45:50 +08:00
|
|
|
|
|
|
|
- name: Install python-dnf for latest RedHat versions
|
2016-02-13 18:59:46 +08:00
|
|
|
command: dnf install -y python-dnf yum
|
2017-03-17 17:55:17 +08:00
|
|
|
register: dnf_task_result
|
|
|
|
until: dnf_task_result|succeeded
|
|
|
|
retries: 4
|
|
|
|
delay: "{{ retry_stagger | random + 3 }}"
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- ansible_distribution == "Fedora"
|
|
|
|
- ansible_distribution_major_version > 21
|
2016-01-09 17:45:50 +08:00
|
|
|
changed_when: False
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2015-12-31 21:07:02 +08:00
|
|
|
|
2016-04-11 04:08:13 +08:00
|
|
|
- name: Install epel-release on RedHat/CentOS
|
2016-10-15 05:46:44 +08:00
|
|
|
shell: rpm -qa | grep epel-release || rpm -ivh {{ epel_rpm_download_url }}
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- ansible_distribution in ["CentOS","RedHat"]
|
|
|
|
- not is_atomic
|
2017-08-20 19:03:10 +08:00
|
|
|
- epel_rpm_download_url != ''
|
2017-03-17 17:55:17 +08:00
|
|
|
register: epel_task_result
|
|
|
|
until: epel_task_result|succeeded
|
|
|
|
retries: 4
|
|
|
|
delay: "{{ retry_stagger | random + 3 }}"
|
2016-04-11 15:33:08 +08:00
|
|
|
changed_when: False
|
2017-02-07 02:13:21 +08:00
|
|
|
check_mode: no
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2016-02-01 04:05:49 +08:00
|
|
|
|
2016-01-09 17:45:50 +08:00
|
|
|
- name: Install packages requirements
|
2015-12-31 21:07:02 +08:00
|
|
|
action:
|
|
|
|
module: "{{ ansible_pkg_mgr }}"
|
|
|
|
name: "{{ item }}"
|
|
|
|
state: latest
|
2016-09-13 21:29:22 +08:00
|
|
|
register: pkgs_task_result
|
2017-03-17 17:55:17 +08:00
|
|
|
until: pkgs_task_result|succeeded
|
2016-09-13 21:29:22 +08:00
|
|
|
retries: 4
|
2016-09-15 17:23:27 +08:00
|
|
|
delay: "{{ retry_stagger | random + 3 }}"
|
2016-02-20 01:48:53 +08:00
|
|
|
with_items: "{{required_pkgs | default([]) | union(common_required_pkgs|default([]))}}"
|
2017-02-25 05:41:27 +08:00
|
|
|
when: not (ansible_os_family in ["CoreOS", "Container Linux by CoreOS"] or is_atomic)
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2016-01-09 17:45:50 +08:00
|
|
|
|
2017-01-13 00:07:28 +08:00
|
|
|
# Todo : selinux configuration
|
2017-02-18 09:13:12 +08:00
|
|
|
- name: Confirm selinux deployed
|
|
|
|
stat:
|
|
|
|
path: /etc/selinux/config
|
|
|
|
when: ansible_os_family == "RedHat"
|
|
|
|
register: slc
|
|
|
|
|
2017-01-13 00:07:28 +08:00
|
|
|
- name: Set selinux policy to permissive
|
2017-02-18 05:22:34 +08:00
|
|
|
selinux:
|
|
|
|
policy: targeted
|
|
|
|
state: permissive
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- ansible_os_family == "RedHat"
|
|
|
|
- slc.stat.exists == True
|
2017-01-13 00:07:28 +08:00
|
|
|
changed_when: False
|
|
|
|
tags: bootstrap-os
|
|
|
|
|
2016-08-08 18:59:20 +08:00
|
|
|
- name: Disable IPv6 DNS lookup
|
|
|
|
lineinfile:
|
|
|
|
dest: /etc/gai.conf
|
|
|
|
line: "precedence ::ffff:0:0/96 100"
|
|
|
|
state: present
|
|
|
|
backup: yes
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- disable_ipv6_dns
|
|
|
|
- not ansible_os_family in ["CoreOS", "Container Linux by CoreOS"]
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2016-08-08 18:59:20 +08:00
|
|
|
|
2017-02-09 17:16:52 +08:00
|
|
|
- name: set default sysctl file path
|
|
|
|
set_fact:
|
|
|
|
sysctl_file_path: "/etc/sysctl.d/99-sysctl.conf"
|
|
|
|
tags: bootstrap-os
|
|
|
|
|
|
|
|
- name: Stat sysctl file configuration
|
2017-02-18 05:22:34 +08:00
|
|
|
stat:
|
|
|
|
path: "{{sysctl_file_path}}"
|
2017-02-09 17:16:52 +08:00
|
|
|
register: sysctl_file_stat
|
|
|
|
tags: bootstrap-os
|
|
|
|
|
|
|
|
- name: Change sysctl file path to link source if linked
|
|
|
|
set_fact:
|
|
|
|
sysctl_file_path: "{{sysctl_file_stat.stat.lnk_source}}"
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- sysctl_file_stat.stat.islnk is defined
|
|
|
|
- sysctl_file_stat.stat.islnk
|
2017-02-09 17:16:52 +08:00
|
|
|
tags: bootstrap-os
|
|
|
|
|
2017-01-13 00:07:28 +08:00
|
|
|
- name: Enable ip forwarding
|
2017-02-09 16:28:44 +08:00
|
|
|
sysctl:
|
2017-02-09 17:16:52 +08:00
|
|
|
sysctl_file: "{{sysctl_file_path}}"
|
2017-02-09 16:28:44 +08:00
|
|
|
name: net.ipv4.ip_forward
|
|
|
|
value: 1
|
2017-01-13 00:07:28 +08:00
|
|
|
state: present
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: bootstrap-os
|
2015-12-31 05:15:18 +08:00
|
|
|
|
2017-02-17 11:59:40 +08:00
|
|
|
- name: Write cloud-config
|
2016-11-29 17:20:28 +08:00
|
|
|
template:
|
2016-11-07 19:11:16 +08:00
|
|
|
src: "{{ cloud_provider }}-cloud-config.j2"
|
2016-11-29 17:20:28 +08:00
|
|
|
dest: "{{ kube_config_dir }}/cloud_config"
|
|
|
|
group: "{{ kube_cert_group }}"
|
|
|
|
mode: 0640
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- inventory_hostname in groups['k8s-cluster']
|
|
|
|
- cloud_provider is defined
|
|
|
|
- cloud_provider in [ 'openstack', 'azure', 'vsphere' ]
|
2017-03-07 00:51:38 +08:00
|
|
|
tags: [cloud-provider]
|
2016-11-29 17:20:28 +08:00
|
|
|
|
2016-01-21 00:37:23 +08:00
|
|
|
- include: etchosts.yml
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: [bootstrap-os, etchosts]
|
2016-12-07 23:57:05 +08:00
|
|
|
|
|
|
|
- include: resolvconf.yml
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- dns_mode != 'none'
|
|
|
|
- resolvconf_mode == 'host_resolvconf'
|
2016-12-07 23:57:05 +08:00
|
|
|
tags: [bootstrap-os, resolvconf]
|
2017-01-02 19:14:03 +08:00
|
|
|
|
2017-01-11 22:08:24 +08:00
|
|
|
- include: dhclient-hooks.yml
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- dns_mode != 'none'
|
|
|
|
- resolvconf_mode == 'host_resolvconf'
|
|
|
|
- not ansible_os_family in ["CoreOS", "Container Linux by CoreOS"]
|
2017-01-11 22:08:24 +08:00
|
|
|
tags: [bootstrap-os, resolvconf]
|
|
|
|
|
|
|
|
- include: dhclient-hooks-undo.yml
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- dns_mode != 'none'
|
|
|
|
- resolvconf_mode != 'host_resolvconf'
|
|
|
|
- not ansible_os_family in ["CoreOS", "Container Linux by CoreOS"]
|
2017-01-11 22:08:24 +08:00
|
|
|
tags: [bootstrap-os, resolvconf]
|
|
|
|
|
2016-12-12 21:14:22 +08:00
|
|
|
- name: Check if we are running inside a Azure VM
|
2017-02-18 05:22:34 +08:00
|
|
|
stat:
|
|
|
|
path: /var/lib/waagent/
|
2016-12-12 21:14:22 +08:00
|
|
|
register: azure_check
|
|
|
|
tags: bootstrap-os
|
|
|
|
|
|
|
|
- include: growpart-azure-centos-7.yml
|
2017-04-26 20:11:13 +08:00
|
|
|
when:
|
|
|
|
- azure_check.stat.exists
|
|
|
|
- ansible_distribution in ["CentOS","RedHat"]
|
2016-12-09 20:27:50 +08:00
|
|
|
tags: bootstrap-os
|