pre.yml 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322
  1. ---
  2. ###############################################################################
  3. # Evaluate host groups and gather facts
  4. ###############################################################################
  5. - name: Load openshift_facts
  6. hosts: oo_masters_to_config:oo_nodes_to_config:oo_etcd_to_config:oo_lb_to_config
  7. roles:
  8. - openshift_facts
  9. - name: Evaluate additional groups for upgrade
  10. hosts: localhost
  11. connection: local
  12. become: no
  13. tasks:
  14. - name: Evaluate etcd_hosts_to_backup
  15. add_host:
  16. name: "{{ item }}"
  17. groups: etcd_hosts_to_backup
  18. with_items: groups.oo_etcd_to_config if groups.oo_etcd_to_config is defined and groups.oo_etcd_to_config | length > 0 else groups.oo_first_master
  19. ###############################################################################
  20. # Pre-upgrade checks
  21. ###############################################################################
  22. - name: Verify upgrade can proceed
  23. hosts: oo_first_master
  24. vars:
  25. target_version: "{{ '1.2' if deployment_type == 'origin' else '3.1.1.900' }}"
  26. g_pacemaker_upgrade_url_segment: "{{ 'org/latest' if deployment_type =='origin' else '.com/enterprise/3.1' }}"
  27. gather_facts: no
  28. tasks:
  29. - fail:
  30. msg: >
  31. This upgrade is only supported for atomic-enterprise, origin, openshift-enterprise, and online
  32. deployment types
  33. when: deployment_type not in ['atomic-enterprise', 'origin','openshift-enterprise', 'online']
  34. - fail:
  35. msg: >
  36. This upgrade does not support Pacemaker:
  37. https://docs.openshift.{{ g_pacemaker_upgrade_url_segment }}/install_config/upgrading/pacemaker_to_native_ha.html
  38. when: openshift.master.cluster_method == 'pacemaker'
  39. - fail:
  40. msg: >
  41. openshift_pkg_version is {{ openshift_pkg_version }} which is not a
  42. valid version for a {{ target_version }} upgrade
  43. when: openshift_pkg_version is defined and openshift_pkg_version.split('-',1).1 | version_compare(target_version ,'<')
  44. - fail:
  45. msg: >
  46. openshift_image_tag is {{ openshift_image_tag }} which is not a
  47. valid version for a {{ target_version }} upgrade
  48. when: openshift_image_tag is defined and openshift_image_tag.split('v',1).1 | version_compare(target_version ,'<')
  49. - name: Verify upgrade can proceed
  50. hosts: oo_masters_to_config
  51. roles:
  52. - openshift_facts
  53. tasks:
  54. - name: Ensure Master is running
  55. service:
  56. name: "{{ openshift.common.service_type }}-master"
  57. state: started
  58. enabled: yes
  59. when: openshift.master.ha is defined and not openshift.master.ha | bool and openshift.common.is_containerized | bool
  60. - name: Ensure HA Master is running
  61. service:
  62. name: "{{ openshift.common.service_type }}-master-api"
  63. state: started
  64. enabled: yes
  65. when: openshift.master.ha is defined and openshift.master.ha | bool and openshift.common.is_containerized | bool
  66. - name: Ensure HA Master is running
  67. service:
  68. name: "{{ openshift.common.service_type }}-master-controllers"
  69. state: started
  70. enabled: yes
  71. when: openshift.master.ha is defined and openshift.master.ha | bool and openshift.common.is_containerized | bool
  72. post_tasks:
  73. - openshift_facts:
  74. role: master
  75. local_facts:
  76. ha: "{{ groups.oo_masters_to_config | length > 1 }}"
  77. - name: Verify upgrade can proceed
  78. hosts: oo_nodes_to_config
  79. roles:
  80. - openshift_facts
  81. tasks:
  82. - name: Ensure Node is running
  83. service:
  84. name: "{{ openshift.common.service_type }}-node"
  85. state: started
  86. enabled: yes
  87. when: openshift.common.is_containerized | bool
  88. - name: Verify upgrade can proceed
  89. hosts: oo_masters_to_config:oo_nodes_to_config
  90. vars:
  91. target_version: "{{ '1.2' if deployment_type == 'origin' else '3.1.1.900' }}"
  92. openshift_docker_hosted_registry_insecure: True
  93. openshift_docker_hosted_registry_network: "{{ hostvars[groups.oo_first_master.0].openshift.master.portal_net }}"
  94. handlers:
  95. - include: ../../../../../roles/openshift_master/handlers/main.yml
  96. - include: ../../../../../roles/openshift_node/handlers/main.yml
  97. roles:
  98. - openshift_cli
  99. tasks:
  100. - name: Clean package cache
  101. command: "{{ ansible_pkg_mgr }} clean all"
  102. when: not openshift.common.is_atomic | bool
  103. - set_fact:
  104. g_new_service_name: "{{ 'origin' if deployment_type =='origin' else 'atomic-openshift' }}"
  105. when: not openshift.common.is_containerized | bool
  106. - name: Determine available versions
  107. script: ../files/rpm_versions.sh {{ g_new_service_name }}
  108. register: g_rpm_versions_result
  109. when: not openshift.common.is_containerized | bool
  110. - set_fact:
  111. g_aos_versions: "{{ g_rpm_versions_result.stdout | from_yaml }}"
  112. when: not openshift.common.is_containerized | bool
  113. - name: Determine available versions
  114. script: ../files/openshift_container_versions.sh {{ openshift.common.service_type }}
  115. register: g_containerized_versions_result
  116. when: openshift.common.is_containerized | bool
  117. - set_fact:
  118. g_aos_versions: "{{ g_containerized_versions_result.stdout | from_yaml }}"
  119. when: openshift.common.is_containerized | bool
  120. - set_fact:
  121. g_new_version: "{{ g_aos_versions.curr_version.split('-', 1).0 if g_aos_versions.avail_version is none else g_aos_versions.avail_version.split('-', 1).0 }}"
  122. when: openshift_pkg_version is not defined
  123. - set_fact:
  124. g_new_version: "{{ openshift_pkg_version | replace('-','') }}"
  125. when: openshift_pkg_version is defined
  126. - set_fact:
  127. g_new_version: "{{ openshift_image_tag | replace('v','') }}"
  128. when: openshift_image_tag is defined
  129. - fail:
  130. msg: Verifying the correct version was found
  131. when: verify_upgrade_version is defined and g_new_version != verify_upgrade_version
  132. - include_vars: ../../../../../roles/openshift_master/vars/main.yml
  133. when: inventory_hostname in groups.oo_masters_to_config
  134. - name: Update systemd units
  135. include: ../../../../../roles/openshift_master/tasks/systemd_units.yml openshift_version=g_aos_versions.curr_version
  136. when: inventory_hostname in groups.oo_masters_to_config
  137. - include_vars: ../../../../../roles/openshift_node/vars/main.yml
  138. when: inventory_hostname in groups.oo_nodes_to_config
  139. - name: Update systemd units
  140. include: ../../../../../roles/openshift_node/tasks/systemd_units.yml openshift_version=g_aos_versions.curr_version
  141. when: inventory_hostname in groups.oo_nodes_to_config
  142. # Note: the version number is hardcoded here in hopes of catching potential
  143. # bugs in how g_aos_versions.curr_version is set
  144. - name: Verifying the correct version is installed for upgrade
  145. shell: grep 3.1.1.6 {{ item }}
  146. with_items:
  147. - /etc/sysconfig/openvswitch
  148. - /etc/sysconfig/{{ openshift.common.service_type }}*
  149. when: verify_upgrade_version is defined
  150. - name: Verifying the image version is used in the systemd unit
  151. shell: grep IMAGE_VERSION {{ item }}
  152. with_items:
  153. - /etc/systemd/system/openvswitch.service
  154. - /etc/systemd/system/{{ openshift.common.service_type }}*.service
  155. when: openshift.common.is_containerized | bool
  156. - fail:
  157. msg: This playbook requires Origin 1.1 or later
  158. when: deployment_type == 'origin' and g_aos_versions.curr_version | version_compare('1.1','<')
  159. - fail:
  160. msg: This playbook requires Atomic Enterprise Platform/OpenShift Enterprise 3.1 or later
  161. when: deployment_type == 'atomic-openshift' and g_aos_versions.curr_version | version_compare('3.1','<')
  162. - fail:
  163. msg: Upgrade packages not found
  164. when: openshift_image_tag is not defined and (g_aos_versions.avail_version | default(g_aos_versions.curr_version, true) | version_compare(target_version, '<'))
  165. - name: Determine available Docker
  166. script: ../files/rpm_versions.sh docker
  167. register: g_docker_version_result
  168. when: not openshift.common.is_atomic | bool
  169. - name: Determine available Docker
  170. shell: "rpm -q --queryformat '---\ncurr_version: %{VERSION}\navail_version: \n' docker"
  171. register: g_atomic_docker_version_result
  172. when: openshift.common.is_atomic | bool
  173. - set_fact:
  174. g_docker_version: "{{ g_docker_version_result.stdout | from_yaml }}"
  175. when: not openshift.common.is_atomic | bool
  176. - set_fact:
  177. g_docker_version: "{{ g_atomic_docker_version_result.stdout | from_yaml }}"
  178. when: openshift.common.is_atomic | bool
  179. - fail:
  180. msg: This playbook requires access to Docker 1.9 or later
  181. when: not openshift.common.is_atomic | bool
  182. and (g_docker_version.avail_version | default(g_docker_version.curr_version, true) | version_compare('1.9','<'))
  183. # TODO: add check to upgrade ostree to get latest Docker
  184. - set_fact:
  185. pre_upgrade_complete: True
  186. ##############################################################################
  187. # Gate on pre-upgrade checks
  188. ##############################################################################
  189. - name: Gate on pre-upgrade checks
  190. hosts: localhost
  191. connection: local
  192. become: no
  193. vars:
  194. pre_upgrade_hosts: "{{ groups.oo_masters_to_config | union(groups.oo_nodes_to_config) }}"
  195. tasks:
  196. - set_fact:
  197. pre_upgrade_completed: "{{ hostvars
  198. | oo_select_keys(pre_upgrade_hosts)
  199. | oo_collect('inventory_hostname', {'pre_upgrade_complete': true}) }}"
  200. - set_fact:
  201. pre_upgrade_failed: "{{ pre_upgrade_hosts | difference(pre_upgrade_completed) }}"
  202. - fail:
  203. msg: "Upgrade cannot continue. The following hosts did not complete pre-upgrade checks: {{ pre_upgrade_failed | join(',') }}"
  204. when: pre_upgrade_failed | length > 0
  205. ###############################################################################
  206. # Backup etcd
  207. ###############################################################################
  208. - name: Backup etcd
  209. hosts: etcd_hosts_to_backup
  210. vars:
  211. embedded_etcd: "{{ openshift.master.embedded_etcd }}"
  212. timestamp: "{{ lookup('pipe', 'date +%Y%m%d%H%M%S') }}"
  213. roles:
  214. - openshift_facts
  215. tasks:
  216. # Ensure we persist the etcd role for this host in openshift_facts
  217. - openshift_facts:
  218. role: etcd
  219. local_facts: {}
  220. when: "'etcd' not in openshift"
  221. - stat: path=/var/lib/openshift
  222. register: var_lib_openshift
  223. - stat: path=/var/lib/origin
  224. register: var_lib_origin
  225. - name: Create origin symlink if necessary
  226. file: src=/var/lib/openshift/ dest=/var/lib/origin state=link
  227. when: var_lib_openshift.stat.exists == True and var_lib_origin.stat.exists == False
  228. # TODO: replace shell module with command and update later checks
  229. # We assume to be using the data dir for all backups.
  230. - name: Check available disk space for etcd backup
  231. shell: df --output=avail -k {{ openshift.common.data_dir }} | tail -n 1
  232. register: avail_disk
  233. # TODO: replace shell module with command and update later checks
  234. - name: Check current embedded etcd disk usage
  235. shell: du -k {{ openshift.etcd.etcd_data_dir }} | tail -n 1 | cut -f1
  236. register: etcd_disk_usage
  237. when: embedded_etcd | bool
  238. - name: Abort if insufficient disk space for etcd backup
  239. fail:
  240. msg: >
  241. {{ etcd_disk_usage.stdout }} Kb disk space required for etcd backup,
  242. {{ avail_disk.stdout }} Kb available.
  243. when: (embedded_etcd | bool) and (etcd_disk_usage.stdout|int > avail_disk.stdout|int)
  244. - name: Install etcd (for etcdctl)
  245. action: "{{ ansible_pkg_mgr }} name=etcd state=latest"
  246. when: not openshift.common.is_atomic | bool
  247. - name: Generate etcd backup
  248. command: >
  249. etcdctl backup --data-dir={{ openshift.etcd.etcd_data_dir }}
  250. --backup-dir={{ openshift.common.data_dir }}/etcd-backup-{{ timestamp }}
  251. - set_fact:
  252. etcd_backup_complete: True
  253. - name: Display location of etcd backup
  254. debug:
  255. msg: "Etcd backup created in {{ openshift.common.data_dir }}/etcd-backup-{{ timestamp }}"
  256. ##############################################################################
  257. # Gate on etcd backup
  258. ##############################################################################
  259. - name: Gate on etcd backup
  260. hosts: localhost
  261. connection: local
  262. become: no
  263. tasks:
  264. - set_fact:
  265. etcd_backup_completed: "{{ hostvars
  266. | oo_select_keys(groups.etcd_hosts_to_backup)
  267. | oo_collect('inventory_hostname', {'etcd_backup_complete': true}) }}"
  268. - set_fact:
  269. etcd_backup_failed: "{{ groups.etcd_hosts_to_backup | difference(etcd_backup_completed) }}"
  270. - fail:
  271. msg: "Upgrade cannot continue. The following hosts did not complete etcd backup: {{ etcd_backup_failed | join(',') }}"
  272. when: etcd_backup_failed | length > 0