main.yml 5.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127
  1. ---
  2. - name: Get current installed Docker version
  3. command: "{{ repoquery_cmd }} --installed --qf '%{version}' docker"
  4. when: not openshift.common.is_atomic | bool
  5. register: curr_docker_version
  6. changed_when: false
  7. - name: Error out if Docker pre-installed but too old
  8. fail:
  9. msg: "Docker {{ curr_docker_version.stdout }} is installed, but >= 1.9.1 is required."
  10. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and curr_docker_version.stdout | version_compare('1.9.1', '<') and not docker_version is defined
  11. - name: Error out if requested Docker is too old
  12. fail:
  13. msg: "Docker {{ docker_version }} requested, but >= 1.9.1 is required."
  14. when: docker_version is defined and docker_version | version_compare('1.9.1', '<')
  15. - name: Get latest available version of Docker
  16. command: >
  17. {{ repoquery_cmd }} --qf '%{version}' "docker"
  18. register: avail_docker_version
  19. failed_when: false
  20. changed_when: false
  21. when: docker_version is defined and not openshift.common.is_atomic | bool
  22. # If a docker_version was requested, sanity check that we can install or upgrade to it, and
  23. # no downgrade is required.
  24. - name: Fail if Docker version requested but downgrade is required
  25. fail:
  26. msg: "Docker {{ curr_docker_version.stdout }} is installed, but version {{ docker_version }} was requested."
  27. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and docker_version is defined and curr_docker_version.stdout | version_compare(docker_version, '>')
  28. # This involves an extremely slow migration process, users should instead run the
  29. # Docker 1.10 upgrade playbook to accomplish this.
  30. - name: Error out if attempting to upgrade Docker across the 1.10 boundary
  31. fail:
  32. msg: "Cannot upgrade Docker to >= 1.10, please upgrade or remove Docker manually, or use the Docker upgrade playbook if OpenShift is already installed."
  33. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and curr_docker_version.stdout | version_compare('1.10', '<') and docker_version is defined and docker_version | version_compare('1.10', '>=')
  34. # Make sure Docker is installed, but does not update a running version.
  35. # Docker upgrades are handled by a separate playbook.
  36. - name: Install Docker
  37. package: name=docker{{ '-' + docker_version if docker_version is defined else '' }} state=present
  38. when: not openshift.common.is_atomic | bool
  39. - block:
  40. # Extend the default Docker service unit file when using iptables-services
  41. - name: Ensure docker.service.d directory exists
  42. file:
  43. path: "{{ docker_systemd_dir }}"
  44. state: directory
  45. - name: Configure Docker service unit file
  46. template:
  47. dest: "{{ docker_systemd_dir }}/custom.conf"
  48. src: custom.conf.j2
  49. when: not os_firewall_use_firewalld | default(True) | bool
  50. - include: udev_workaround.yml
  51. when: docker_udev_workaround | default(False) | bool
  52. - stat: path=/etc/sysconfig/docker
  53. register: docker_check
  54. - name: Set registry params
  55. lineinfile:
  56. dest: /etc/sysconfig/docker
  57. regexp: '^{{ item.reg_conf_var }}=.*$'
  58. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val | oo_prepend_strings_in_list(item.reg_flag ~ ' ') | join(' ') }}'"
  59. when: item.reg_fact_val != '' and docker_check.stat.isreg is defined and docker_check.stat.isreg
  60. with_items:
  61. - reg_conf_var: ADD_REGISTRY
  62. reg_fact_val: "{{ docker_additional_registries | default(None, true)}}"
  63. reg_flag: --add-registry
  64. - reg_conf_var: BLOCK_REGISTRY
  65. reg_fact_val: "{{ docker_blocked_registries| default(None, true) }}"
  66. reg_flag: --block-registry
  67. - reg_conf_var: INSECURE_REGISTRY
  68. reg_fact_val: "{{ docker_insecure_registries| default(None, true) }}"
  69. reg_flag: --insecure-registry
  70. notify:
  71. - restart docker
  72. - name: Set Proxy Settings
  73. lineinfile:
  74. dest: /etc/sysconfig/docker
  75. regexp: '^{{ item.reg_conf_var }}=.*$'
  76. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val }}'"
  77. state: "{{ 'present' if item.reg_fact_val != '' else 'absent'}}"
  78. with_items:
  79. - reg_conf_var: HTTP_PROXY
  80. reg_fact_val: "{{ docker_http_proxy | default('') }}"
  81. - reg_conf_var: HTTPS_PROXY
  82. reg_fact_val: "{{ docker_https_proxy | default('') }}"
  83. - reg_conf_var: NO_PROXY
  84. reg_fact_val: "{{ docker_no_proxy | default('') | join(',') }}"
  85. notify:
  86. - restart docker
  87. when:
  88. - docker_check.stat.isreg is defined and docker_check.stat.isreg and '"http_proxy" in openshift.common or "https_proxy" in openshift.common'
  89. - name: Set various Docker options
  90. lineinfile:
  91. dest: /etc/sysconfig/docker
  92. regexp: '^OPTIONS=.*$'
  93. line: "OPTIONS='\
  94. {% if ansible_selinux and ansible_selinux.status == '''enabled''' %} --selinux-enabled{% endif %}\
  95. {% if docker_log_driver is defined %} --log-driver {{ docker_log_driver }}{% endif %}\
  96. {% if docker_log_options is defined %} {{ docker_log_options | oo_split() | oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %}\
  97. {% if docker_options is defined %} {{ docker_options }}{% endif %}\
  98. {% if docker_disable_push_dockerhub is defined %} --confirm-def-push={{ docker_disable_push_dockerhub | bool }}{% endif %}'"
  99. when: docker_check.stat.isreg is defined and docker_check.stat.isreg
  100. notify:
  101. - restart docker
  102. - name: Start the Docker service
  103. systemd:
  104. name: docker
  105. enabled: yes
  106. state: started
  107. daemon_reload: yes
  108. register: start_result
  109. - set_fact:
  110. docker_service_status_changed: start_result | changed
  111. - meta: flush_handlers