main.yml 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384
  1. ---
  2. docker_cli_auth_config_path: '/root/.docker'
  3. openshift_docker_signature_verification: False
  4. openshift_docker_selinux_enabled: True
  5. openshift_docker_service_name: "docker"
  6. openshift_docker_hosted_registry_insecure: False # bool
  7. openshift_docker_hosted_registry_network: "{{ openshift.common.portal_net }}"
  8. openshift_docker_additional_registries: []
  9. openshift_docker_blocked_registries: []
  10. openshift_docker_insecure_registries: []
  11. openshift_docker_ent_reg: 'registry.redhat.io'
  12. openshift_docker_options: False # str
  13. openshift_docker_log_driver: False # str
  14. openshift_docker_log_options_defaults:
  15. json-file:
  16. - "max-size=50m"
  17. openshift_docker_log_options: "{{ openshift_docker_log_options_defaults[openshift_docker_log_driver] | default([]) }}"
  18. # The l2_docker_* variables convert csv strings to lists, if
  19. # necessary. These variables should be used in place of their respective
  20. # openshift_docker_* counterparts to ensure the properly formatted lists are
  21. # utilized.
  22. l2_docker_additional_registries: "{% if openshift_docker_additional_registries is string %}{% if openshift_docker_additional_registries == '' %}[]{% elif ',' in openshift_docker_additional_registries %}{{ openshift_docker_additional_registries.split(',') | list }}{% else %}{{ [ openshift_docker_additional_registries ] }}{% endif %}{% else %}{{ openshift_docker_additional_registries }}{% endif %}"
  23. l2_docker_blocked_registries: "{% if openshift_docker_blocked_registries is string %}{% if openshift_docker_blocked_registries == '' %}[]{% elif ',' in openshift_docker_blocked_registries %}{{ openshift_docker_blocked_registries.split(',') | list }}{% else %}{{ [ openshift_docker_blocked_registries ] }}{% endif %}{% else %}{{ openshift_docker_blocked_registries }}{% endif %}"
  24. l2_docker_insecure_registries: "{% if openshift_docker_insecure_registries is string %}{% if openshift_docker_insecure_registries == '' %}[]{% elif ',' in openshift_docker_insecure_registries %}{{ openshift_docker_insecure_registries.split(',') | list }}{% else %}{{ [ openshift_docker_insecure_registries ] }}{% endif %}{% else %}{{ openshift_docker_insecure_registries }}{% endif %}"
  25. l2_docker_log_options: "{% if openshift_docker_log_options is string %}{% if ',' in openshift_docker_log_options %}{{ openshift_docker_log_options.split(',') | list }}{% else %}{{ [ openshift_docker_log_options ] }}{% endif %}{% else %}{{ openshift_docker_log_options }}{% endif %}"
  26. openshift_docker_use_etc_containers: False
  27. containers_registries_conf_path: /etc/containers/registries.conf
  28. r_crio_firewall_enabled: "{{ os_firewall_enabled | default(True) }}"
  29. r_crio_use_firewalld: "{{ os_firewall_use_firewalld | default(False) }}"
  30. r_crio_os_firewall_deny: []
  31. r_crio_os_firewall_allow:
  32. - service: crio
  33. port: 10010/tcp
  34. r_crio_use_openshift_sdn: "{{ openshift_use_openshift_sdn | default(True) }}"
  35. docker_alt_storage_path: /var/lib/containers/docker
  36. docker_default_storage_path: /var/lib/docker
  37. docker_storage_path: "{{ docker_default_storage_path }}"
  38. docker_storage_size: 40G
  39. docker_storage_setup_options:
  40. vg: docker_vg
  41. data_size: 99%VG
  42. storage_driver: overlay2
  43. root_lv_name: docker-root-lv
  44. root_lv_size: 100%FREE
  45. root_lv_mount_path: "{{ docker_storage_path }}"
  46. docker_storage_extra_options:
  47. - "--storage-opt overlay2.override_kernel_check=true"
  48. - "{{ '--storage-opt overlay2.size=' ~ docker_storage_size if container_runtime_docker_storage_setup_device is defined and container_runtime_docker_storage_setup_device != '' else '' }}"
  49. - "--graph={{ docker_storage_path}}"
  50. container_runtime_extra_storage: []
  51. # Set local versions of facts that must be in json format for container-daemon.json
  52. # NOTE: When jinja2.9+ is used the container-daemon.json file can move to using tojson
  53. l_docker_log_options: "{{ l2_docker_log_options | to_json }}"
  54. l_docker_log_options_dict: "{{ l2_docker_log_options | lib_utils_oo_list_to_dict | to_json }}"
  55. l_docker_additional_registries: "{{ l2_docker_additional_registries | to_json }}"
  56. l_docker_blocked_registries: "{{ l2_docker_blocked_registries | to_json }}"
  57. l_docker_insecure_registries: "{{ l2_docker_insecure_registries | to_json }}"
  58. l_docker_selinux_enabled: "{{ openshift_docker_selinux_enabled | to_json }}"
  59. docker_http_proxy: "{{ openshift_http_proxy | default('') }}"
  60. docker_https_proxy: "{{ openshift.common.https_proxy | default('') }}"
  61. docker_no_proxy: "{{ openshift.common.no_proxy | default('') }}"
  62. openshift_crio_pause_image: "{{ l_os_registry_url | regex_replace('${component}' | regex_escape, 'pod') }}"
  63. l_required_docker_version: '1.13'
  64. l_insecure_crio_registries: "{{ '\"{}\"'.format('\", \"'.join(l2_docker_insecure_registries)) }}"
  65. l_crio_registries: "{{ l2_docker_additional_registries + ['docker.io'] }}"
  66. l_additional_crio_registries: "{{ '\"{}\"'.format('\", \"'.join(l_crio_registries)) }}"