main.yml 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143
  1. ---
  2. openshift_node_debug_level: "{{ debug_level | default(2) }}"
  3. openshift_node_dnsmasq_install_network_manager_hook: true
  4. # lo must always be present in this list or dnsmasq will conflict with
  5. # the node's dns service.
  6. openshift_node_dnsmasq_except_interfaces:
  7. - lo
  8. r_openshift_node_firewall_enabled: "{{ os_firewall_enabled | default(True) }}"
  9. r_openshift_node_use_firewalld: "{{ os_firewall_use_firewalld | default(False) }}"
  10. l_is_node_system_container: "{{ (openshift_use_node_system_container | default(openshift_use_system_containers | default(false)) | bool) }}"
  11. openshift_deployment_type: "{{ openshift_deployment_type | default('origin') }}"
  12. openshift_service_type_dict:
  13. origin: origin
  14. openshift-enterprise: atomic-openshift
  15. openshift_service_type: "{{ openshift_service_type_dict[openshift_deployment_type] }}"
  16. system_images_registry_dict:
  17. openshift-enterprise: "registry.access.redhat.com"
  18. origin: "docker.io"
  19. system_images_registry: "{{ system_images_registry_dict[openshift_deployment_type | default('origin')] }}"
  20. l_is_openvswitch_system_container: "{{ (openshift_use_openvswitch_system_container | default(openshift_use_system_containers | default(false)) | bool) }}"
  21. openshift_image_tag: ''
  22. default_r_openshift_node_image_prep_packages:
  23. - "{{ openshift_service_type }}-master"
  24. - "{{ openshift_service_type }}-node"
  25. - "{{ openshift_service_type }}-docker-excluder"
  26. - "{{ openshift_service_type }}-sdn-ovs"
  27. - ansible
  28. - openvswitch
  29. - docker
  30. - etcd
  31. - haproxy
  32. - dnsmasq
  33. - ntp
  34. - logrotate
  35. - httpd-tools
  36. - bind
  37. - firewalld
  38. - libselinux-python
  39. - conntrack-tools
  40. - openssl
  41. - cloud-init
  42. - iproute
  43. - python-dbus
  44. - PyYAML
  45. - yum-utils
  46. # gluster
  47. - glusterfs-fuse
  48. # nfs
  49. - nfs-utils
  50. - flannel
  51. - bash-completion
  52. # cockpit
  53. - cockpit-ws
  54. - cockpit-system
  55. - cockpit-bridge
  56. - cockpit-docker
  57. # iscsi
  58. - iscsi-initiator-utils
  59. # ceph
  60. - ceph-common
  61. # systemcontainer
  62. # - runc
  63. # - container-selinux
  64. # - atomic
  65. #
  66. r_openshift_node_image_prep_packages: "{{ default_r_openshift_node_image_prep_packages | union(openshift_node_image_prep_packages | default([])) }}"
  67. openshift_node_bootstrap: False
  68. r_openshift_node_os_firewall_deny: []
  69. default_r_openshift_node_os_firewall_allow:
  70. - service: Kubernetes kubelet
  71. port: 10250/tcp
  72. - service: http
  73. port: 80/tcp
  74. - service: https
  75. port: 443/tcp
  76. - service: OpenShift OVS sdn
  77. port: 4789/udp
  78. cond: openshift_use_openshift_sdn | bool
  79. - service: Calico BGP Port
  80. port: 179/tcp
  81. cond: "{{ openshift_node_use_calico }}"
  82. - service: Kubernetes service NodePort TCP
  83. port: "{{ openshift_node_port_range | default('') }}/tcp"
  84. cond: "{{ openshift_node_port_range is defined }}"
  85. - service: Kubernetes service NodePort UDP
  86. port: "{{ openshift_node_port_range | default('') }}/udp"
  87. cond: "{{ openshift_node_port_range is defined }}"
  88. # Allow multiple port ranges to be added to the role
  89. r_openshift_node_os_firewall_allow: "{{ default_r_openshift_node_os_firewall_allow | union(openshift_node_open_ports | default([])) }}"
  90. # oreg_url is defined by user input
  91. oreg_host: "{{ oreg_url.split('/')[0] if (oreg_url is defined and '.' in oreg_url.split('/')[0]) else '' }}"
  92. oreg_auth_credentials_path: "{{ openshift_node_data_dir }}/.docker"
  93. oreg_auth_credentials_replace: False
  94. l_bind_docker_reg_auth: False
  95. openshift_use_crio: False
  96. openshift_docker_alternative_creds: "{{ (openshift_docker_use_system_container | default(False)) or (openshift_use_crio_only | default(False)) }}"
  97. openshift_docker_service_name: "{{ 'container-engine' if (openshift_docker_use_system_container | default(False)) else 'docker' }}"
  98. # NOTE
  99. # r_openshift_node_*_default may be defined external to this role.
  100. # openshift_use_*, if defined, may affect other roles or play behavior.
  101. openshift_node_use_openshift_sdn_default: "{{ openshift_use_openshift_sdn | default(True) }}"
  102. openshift_node_use_openshift_sdn: "{{ openshift_node_use_openshift_sdn_default }}"
  103. openshift_node_sdn_network_plugin_name_default: "{{ os_sdn_network_plugin_name | default('redhat/openshift-ovs-subnet') }}"
  104. openshift_node_sdn_network_plugin_name: "{{ openshift_node_sdn_network_plugin_name_default }}"
  105. openshift_node_use_calico_default: "{{ openshift_use_calico | default(False) }}"
  106. openshift_node_use_calico: "{{ openshift_node_use_calico_default }}"
  107. openshift_node_use_nuage_default: "{{ openshift_use_nuage | default(False) }}"
  108. openshift_node_use_nuage: "{{ openshift_node_use_nuage_default }}"
  109. openshift_node_use_contiv_default: "{{ openshift_use_contiv | default(False) }}"
  110. openshift_node_use_contiv: "{{ openshift_node_use_contiv_default }}"
  111. openshift_node_use_kuryr_default: "{{ openshift_use_kuryr | default(False) }}"
  112. openshift_node_use_kuryr: "{{ openshift_node_use_kuryr_default }}"
  113. openshift_node_data_dir_default: "{{ openshift_data_dir | default('/var/lib/origin') }}"
  114. openshift_node_data_dir: "{{ openshift_node_data_dir_default }}"
  115. openshift_node_config_dir_default: "/etc/origin/node"
  116. openshift_node_config_dir: "{{ openshift_node_config_dir_default }}"
  117. openshift_node_image_config_latest_default: "{{ openshift_image_config_latest | default(False) }}"
  118. openshift_node_image_config_latest: "{{ openshift_node_image_config_latest_default }}"
  119. openshift_node_use_instance_profiles: False