Przeglądaj źródła

Copy Nuage VSD generated user certificates to Openshift master nodes

Sneha Deshpande 8 lat temu
rodzic
commit
51bf0a3d83

+ 0 - 4
roles/nuage_master/defaults/main.yaml

@@ -1,4 +0,0 @@
----
-nuage_master_cspadminpasswd: ""
-nuage_master_adminusername: admin
-nuage_master_adminuserpasswd: admin

+ 8 - 0
roles/nuage_master/tasks/main.yaml

@@ -33,6 +33,14 @@
 
 - include: certificates.yml
 
+- name: Install Nuage VSD user certificate
+  become: yes
+  copy: src="{{ vsd_user_cert_file }}" dest="{{ cert_output_dir }}/{{ vsd_user_cert_file | basename }}"
+
+- name: Install Nuage VSD user key
+  become: yes
+  copy: src="{{ vsd_user_key_file }}" dest="{{ cert_output_dir }}/{{ vsd_user_key_file | basename }}"
+
 - name: Create nuage-openshift-monitor.yaml
   become: yes
   template: src=nuage-openshift-monitor.j2 dest=/usr/share/nuage-openshift-monitor/nuage-openshift-monitor.yaml owner=root mode=0644

+ 4 - 6
roles/nuage_master/templates/nuage-openshift-monitor.j2

@@ -15,12 +15,10 @@ vspVersion: {{ vsp_version }}
 enterpriseName: {{ enterprise }} 
 # Name of the domain in which pods will reside
 domainName: {{ domain }}
-# CSP admin user's password
-cspAdminPassword: {{ nuage_master_cspadminpasswd }}
-# Enterprise admin user name
-enterpriseAdminUser: {{ nuage_master_adminusername }}
-# Enterprise admin password
-enterpriseAdminPassword: {{ nuage_master_adminuserpasswd }}
+# VSD generated user certificate file location on master node
+userCertificateFile: {{ cert_output_dir }}/{{ vsd_user_cert_file | basename }}
+# VSD generated user key file location on master node
+userKeyFile: {{ cert_output_dir }}/{{ vsd_user_key_file | basename }}
 # Location where logs should be saved
 log_dir: {{ nuage_mon_rest_server_logdir }}
 # Monitor rest server parameters

+ 15 - 0
roles/nuage_node/tasks/main.yaml

@@ -20,6 +20,21 @@
   become: yes
   yum: name={{ plugin_rpm }} state=present
 
+- name: Assure CNI conf dir exists
+  become: yes
+  file: path="{{ cni_conf_dir }}" state=directory
+
+- name: Assures Openshift CNI bin dir exists
+  become: yes
+  file: path="{{ cni_bin_dir }}" state=directory
+
+- name: Install CNI loopback plugin
+  become: yes
+  copy:
+    src: "{{ k8s_cni_loopback_plugin }}"
+    dest: "{{ cni_bin_dir }}/{{ k8s_cni_loopback_plugin | basename }}"
+    mode: 0755
+
 - name: Copy the certificates and keys
   become: yes
   copy: src="/tmp/{{ item }}" dest="{{ vsp_openshift_dir }}/{{ item }}"

+ 2 - 0
roles/nuage_node/templates/vsp-openshift.j2

@@ -8,6 +8,8 @@ CACert: {{ ca_cert }}
 enterpriseName: {{ enterprise }} 
 # Name of the domain in which pods will reside
 domainName: {{ domain }}
+# Name of the VSD user in admin group
+vsdUser: {{ vsduser }}
 # IP address and port number of master API server
 masterApiServer: {{ api_server }}
 # REST server URL 

+ 3 - 0
roles/nuage_node/vars/main.yaml

@@ -19,4 +19,7 @@ nuage_plugin_rest_client_crt_dir: "{{ nuage_ca_master_crt_dir }}/{{ ansible_node
 nuage_ca_master_plugin_key: "{{ nuage_plugin_rest_client_crt_dir }}/nuageMonClient.key"
 nuage_ca_master_plugin_crt: "{{ nuage_plugin_rest_client_crt_dir }}/nuageMonClient.crt"
 
+cni_conf_dir: "/etc/cni/net.d/"
+cni_bin_dir: "/opt/cni/bin/"
+
 nuage_plugin_crt_dir: /usr/share/vsp-openshift