router.yml 3.3 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970
  1. ---
  2. - fail:
  3. msg: "'certfile', 'keyfile' and 'cafile' keys must be specified when supplying the openshift_hosted_router_certificate variable."
  4. when: openshift_hosted_router_certificate is defined and ('certfile' not in openshift_hosted_router_certificate or 'keyfile' not in openshift_hosted_router_certificate or 'cafile' not in openshift_hosted_router_certificate)
  5. - name: Read router certificate and key
  6. become: no
  7. local_action:
  8. module: slurp
  9. src: "{{ item }}"
  10. register: openshift_router_certificate_output
  11. with_items:
  12. - "{{ openshift_hosted_router_certificate.certfile }}"
  13. - "{{ openshift_hosted_router_certificate.keyfile }}"
  14. - "{{ openshift_hosted_router_certificate.cafile }}"
  15. when: openshift_hosted_router_certificate is defined
  16. - name: Persist certificate contents
  17. openshift_facts:
  18. role: hosted
  19. openshift_env:
  20. openshift_hosted_router_certificate_contents: "{% for certificate in openshift_router_certificate_output.results -%}{{ certificate.content | b64decode }}{% endfor -%}"
  21. when: openshift_hosted_router_certificate is defined
  22. - name: Create PEM certificate
  23. copy:
  24. content: "{{ openshift.hosted.router.certificate.contents }}"
  25. dest: "{{ openshift_master_config_dir }}/openshift-router.pem"
  26. mode: 0600
  27. when: openshift.hosted.router.certificate | default(none) is not none
  28. - name: Retrieve list of openshift nodes matching router selector
  29. command: >
  30. {{ openshift.common.client_binary }} --api-version='v1' -o json
  31. get nodes -n default --config={{ openshift_hosted_kubeconfig }}
  32. --selector={{ openshift.hosted.router.selector | default('') }}
  33. register: openshift_hosted_router_nodes_json
  34. changed_when: false
  35. when: openshift.hosted.router.replicas | default(none) is none
  36. - set_fact:
  37. replicas: "{{ openshift.hosted.router.replicas | default((openshift_hosted_router_nodes_json.stdout | from_json)['items'] | length) }}"
  38. - name: Create OpenShift router
  39. command: >
  40. {{ openshift.common.admin_binary }} router --create
  41. --config={{ openshift_hosted_kubeconfig }}
  42. {% if replicas > 1 -%}
  43. --replicas={{ replicas }}
  44. {% endif -%}
  45. {% if openshift.hosted.router.certificate | default(none) is not none -%}
  46. --default-cert={{ openshift_master_config_dir }}/openshift-router.pem
  47. {% endif -%}
  48. --namespace={{ openshift.hosted.router.namespace | default('default') }}
  49. {% if openshift.hosted.router.force_subdomain | default(none) is not none %}
  50. --force-subdomain={{ openshift.hosted.router.force_subdomain }}
  51. {% endif %}
  52. --service-account=router
  53. {% if openshift.hosted.router.selector | default(none) is not none -%}
  54. --selector='{{ openshift.hosted.router.selector }}'
  55. {% endif -%}
  56. {% if not openshift.common.version_gte_3_2_or_1_2 | bool -%}
  57. --credentials={{ openshift_master_config_dir }}/openshift-router.kubeconfig
  58. {% endif -%}
  59. {% if openshift.hosted.router.registryurl | default(none) is not none -%}
  60. --images='{{ openshift.hosted.router.registryurl }}'
  61. {% endif -%}
  62. register: openshift_hosted_router_results
  63. changed_when: "'service exists' not in openshift_hosted_router_results.stdout"
  64. failed_when: "openshift_hosted_router_results.rc != 0 and 'service exists' not in openshift_hosted_router_results.stdout and 'deployment_config' not in openshift_hosted_router_results.stderr and 'service' not in openshift_hosted_router_results.stderr"