main.yml 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107
  1. ---
  2. r_openshift_node_firewall_enabled: "{{ os_firewall_enabled | default(True) }}"
  3. r_openshift_node_use_firewalld: "{{ os_firewall_use_firewalld | default(False) }}"
  4. openshift_service_type: "{{ openshift.common.service_type }}"
  5. openshift_image_tag: ''
  6. openshift_node_ami_prep_packages:
  7. - "{{ openshift_service_type }}-master"
  8. - "{{ openshift_service_type }}-node"
  9. - "{{ openshift_service_type }}-docker-excluder"
  10. - "{{ openshift_service_type }}-sdn-ovs"
  11. - ansible
  12. - openvswitch
  13. - docker
  14. - etcd
  15. #- pcs
  16. - haproxy
  17. - dnsmasq
  18. - ntp
  19. - logrotate
  20. - httpd-tools
  21. - bind
  22. - firewalld
  23. - libselinux-python
  24. - conntrack-tools
  25. - openssl
  26. - cloud-init
  27. - iproute
  28. - python-dbus
  29. - PyYAML
  30. - yum-utils
  31. - cloud-utils-growpart
  32. # gluster
  33. - glusterfs-fuse
  34. # nfs
  35. - nfs-utils
  36. - flannel
  37. - bash-completion
  38. # cockpit
  39. - cockpit-ws
  40. - cockpit-system
  41. - cockpit-bridge
  42. - cockpit-docker
  43. # iscsi
  44. - iscsi-initiator-utils
  45. # ceph
  46. - ceph-common
  47. # systemcontainer
  48. # - runc
  49. # - container-selinux
  50. # - atomic
  51. #
  52. openshift_deployment_type: origin
  53. openshift_node_bootstrap: False
  54. r_openshift_node_os_firewall_deny: []
  55. default_r_openshift_node_os_firewall_allow:
  56. - service: Kubernetes kubelet
  57. port: 10250/tcp
  58. - service: http
  59. port: 80/tcp
  60. - service: https
  61. port: 443/tcp
  62. - service: OpenShift OVS sdn
  63. port: 4789/udp
  64. cond: openshift_use_openshift_sdn | bool
  65. - service: Calico BGP Port
  66. port: 179/tcp
  67. cond: "{{ openshift_node_use_calico }}"
  68. - service: Kubernetes service NodePort TCP
  69. port: "{{ openshift_node_port_range | default('') }}/tcp"
  70. cond: "{{ openshift_node_port_range is defined }}"
  71. - service: Kubernetes service NodePort UDP
  72. port: "{{ openshift_node_port_range | default('') }}/udp"
  73. cond: "{{ openshift_node_port_range is defined }}"
  74. # Allow multiple port ranges to be added to the role
  75. r_openshift_node_os_firewall_allow: "{{ default_r_openshift_node_os_firewall_allow | union(openshift_node_open_ports | default([])) }}"
  76. # oreg_url is defined by user input
  77. oreg_host: "{{ oreg_url.split('/')[0] if (oreg_url is defined and '.' in oreg_url.split('/')[0]) else '' }}"
  78. oreg_auth_credentials_path: "{{ openshift_node_data_dir }}/.docker"
  79. oreg_auth_credentials_replace: False
  80. l_bind_docker_reg_auth: False
  81. # NOTE
  82. # r_openshift_node_*_default may be defined external to this role.
  83. # openshift_use_*, if defined, may affect other roles or play behavior.
  84. openshift_node_use_openshift_sdn_default: "{{ openshift_use_openshift_sdn | default(True) }}"
  85. openshift_node_use_openshift_sdn: "{{ openshift_node_use_openshift_sdn_default }}"
  86. openshift_node_sdn_network_plugin_name_default: "{{ os_sdn_network_plugin_name | default('redhat/openshift-ovs-subnet') }}"
  87. openshift_node_sdn_network_plugin_name: "{{ openshift_node_sdn_network_plugin_name_default }}"
  88. openshift_node_use_calico_default: "{{ openshift_use_calico | default(False) }}"
  89. openshift_node_use_calico: "{{ openshift_node_use_calico_default }}"
  90. openshift_node_use_nuage_default: "{{ openshift_use_nuage | default(False) }}"
  91. openshift_node_use_nuage: "{{ openshift_node_use_nuage_default }}"
  92. openshift_node_use_contiv_default: "{{ openshift_use_contiv | default(False) }}"
  93. openshift_node_use_contiv: "{{ openshift_node_use_contiv_default }}"
  94. openshift_node_data_dir_default: "{{ openshift_data_dir | default('/var/lib/origin') }}"
  95. openshift_node_data_dir: "{{ openshift_node_data_dir_default }}"