upgrade.yml 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229
  1. ---
  2. ###############################################################################
  3. # Upgrade Masters
  4. ###############################################################################
  5. # Some change makes critical outage on current cluster.
  6. - name: Confirm upgrade will not make critical changes
  7. hosts: oo_first_master
  8. tasks:
  9. - name: Confirm Reconcile Security Context Constraints will not change current SCCs
  10. command: >
  11. {{ openshift_client_binary }} adm policy --config={{ openshift.common.config_base }}/master/admin.kubeconfig reconcile-sccs --additive-only=true -o name
  12. register: check_reconcile_scc_result
  13. when: openshift_reconcile_sccs_reject_change | default(true) | bool
  14. - fail:
  15. msg: "Trying to change SCCs. Run \"{{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig\" and confirm SCCs which will be changed."
  16. when:
  17. - openshift_reconcile_sccs_reject_change | default(true) | bool
  18. - check_reconcile_scc_result.stdout != '' or check_reconcile_scc_result.rc != 0
  19. # Create service signer cert when missing. Service signer certificate
  20. # is added to master config in the master_config_upgrade hook.
  21. - name: Determine if service signer cert must be created
  22. hosts: oo_first_master
  23. tasks:
  24. - name: Determine if service signer certificate must be created
  25. stat:
  26. path: "{{ openshift.common.config_base }}/master/service-signer.crt"
  27. register: service_signer_cert_stat
  28. changed_when: false
  29. - name: verify api server
  30. command: >
  31. curl --silent --tlsv1.2
  32. --cacert {{ openshift.common.config_base }}/master/ca-bundle.crt
  33. {{ openshift.master.api_url }}/healthz/ready
  34. args:
  35. # Disables the following warning:
  36. # Consider using get_url or uri module rather than running curl
  37. warn: no
  38. register: api_available_output
  39. until: api_available_output.stdout == 'ok'
  40. retries: 120
  41. delay: 1
  42. changed_when: false
  43. - import_playbook: create_service_signer_cert.yml
  44. # oc adm migrate storage should be run prior to etcd v3 upgrade
  45. # See: https://github.com/openshift/origin/pull/14625#issuecomment-308467060
  46. - name: Pre master upgrade - Upgrade all storage
  47. hosts: oo_first_master
  48. roles:
  49. - openshift_facts
  50. tasks:
  51. - name: Upgrade all storage
  52. command: >
  53. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  54. migrate storage --include=* --confirm
  55. register: l_pb_upgrade_control_plane_pre_upgrade_storage
  56. when: openshift_upgrade_pre_storage_migration_enabled | default(true) | bool
  57. failed_when:
  58. - l_pb_upgrade_control_plane_pre_upgrade_storage.rc != 0
  59. - openshift_upgrade_pre_storage_migration_fatal | default(true) | bool
  60. # Set openshift_master_facts separately. In order to reconcile
  61. # admission_config's, we currently must run openshift_master_facts and
  62. # then run openshift_facts.
  63. - name: Set OpenShift master facts
  64. hosts: oo_masters_to_config
  65. roles:
  66. - openshift_master_facts
  67. - name: configure vsphere svc account
  68. hosts: oo_first_master
  69. tasks:
  70. - import_role:
  71. name: openshift_cloud_provider
  72. tasks_from: vsphere-svc
  73. when:
  74. - openshift_cloudprovider_kind is defined
  75. - openshift_cloudprovider_kind == 'vsphere'
  76. # The main master upgrade play. Should handle all changes to the system in one pass, with
  77. # support for optional hooks to be defined.
  78. - name: Upgrade master
  79. hosts: oo_masters_to_config
  80. serial: 1
  81. roles:
  82. - openshift_facts
  83. tasks:
  84. # Run the pre-upgrade hook if defined:
  85. - debug: msg="Running master pre-upgrade hook {{ openshift_master_upgrade_pre_hook }}"
  86. when: openshift_master_upgrade_pre_hook is defined
  87. - include_tasks: "{{ openshift_master_upgrade_pre_hook }}"
  88. when: openshift_master_upgrade_pre_hook is defined
  89. - import_role:
  90. name: openshift_control_plane
  91. tasks_from: upgrade
  92. - name: update vsphere provider master config
  93. import_role:
  94. name: openshift_control_plane
  95. tasks_from: update-vsphere
  96. when:
  97. - openshift_cloudprovider_kind is defined
  98. - openshift_cloudprovider_kind == 'vsphere'
  99. # Run the upgrade hook prior to restarting services/system if defined:
  100. - debug: msg="Running master upgrade hook {{ openshift_master_upgrade_hook }}"
  101. when: openshift_master_upgrade_hook is defined
  102. - include_tasks: "{{ openshift_master_upgrade_hook }}"
  103. when: openshift_master_upgrade_hook is defined
  104. - name: Lay down the static configuration
  105. import_role:
  106. name: openshift_control_plane
  107. tasks_from: static.yml
  108. - import_tasks: tasks/restart_hosts.yml
  109. when: openshift_rolling_restart_mode | default('services') == 'system'
  110. - import_tasks: tasks/restart_services.yml
  111. when: openshift_rolling_restart_mode | default('services') == 'services'
  112. # Run the post-upgrade hook if defined:
  113. - debug: msg="Running master post-upgrade hook {{ openshift_master_upgrade_post_hook }}"
  114. when: openshift_master_upgrade_post_hook is defined
  115. - include_tasks: "{{ openshift_master_upgrade_post_hook }}"
  116. when: openshift_master_upgrade_post_hook is defined
  117. - set_fact:
  118. master_update_complete: True
  119. ##############################################################################
  120. # Gate on master update complete
  121. ##############################################################################
  122. - name: Gate on master update
  123. hosts: localhost
  124. connection: local
  125. tasks:
  126. - set_fact:
  127. master_update_completed: "{{ hostvars
  128. | lib_utils_oo_select_keys(groups.oo_masters_to_config)
  129. | lib_utils_oo_collect('inventory_hostname', {'master_update_complete': true}) }}"
  130. - set_fact:
  131. master_update_failed: "{{ groups.oo_masters_to_config | difference(master_update_completed) | list }}"
  132. - fail:
  133. msg: "Upgrade cannot continue. The following masters did not finish updating: {{ master_update_failed | join(',') }}"
  134. when: master_update_failed | length > 0
  135. ###############################################################################
  136. # Reconcile Cluster Roles, Cluster Role Bindings and Security Context Constraints
  137. ###############################################################################
  138. - name: Reconcile Cluster Roles and Cluster Role Bindings and Security Context Constraints
  139. hosts: oo_masters_to_config
  140. roles:
  141. - { role: openshift_cli }
  142. - { role: openshift_facts }
  143. vars:
  144. __master_shared_resource_viewer_file: "shared_resource_viewer_role.yaml"
  145. tasks:
  146. - name: Reconcile Security Context Constraints
  147. command: >
  148. {{ openshift_client_binary }} adm policy --config={{ openshift.common.config_base }}/master/admin.kubeconfig reconcile-sccs --confirm --additive-only=true -o name
  149. register: reconcile_scc_result
  150. changed_when:
  151. - reconcile_scc_result.stdout != ''
  152. - reconcile_scc_result.rc == 0
  153. run_once: true
  154. - name: Migrate storage post policy reconciliation
  155. command: >
  156. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  157. migrate storage --include=* --confirm
  158. run_once: true
  159. register: l_pb_upgrade_control_plane_post_upgrade_storage
  160. when: openshift_upgrade_post_storage_migration_enabled | default(true) | bool
  161. failed_when:
  162. - l_pb_upgrade_control_plane_post_upgrade_storage.rc != 0
  163. - openshift_upgrade_post_storage_migration_fatal | default(false) | bool
  164. - set_fact:
  165. reconcile_complete: True
  166. ##############################################################################
  167. # Gate on reconcile
  168. ##############################################################################
  169. - name: Gate on reconcile
  170. hosts: localhost
  171. connection: local
  172. tasks:
  173. - set_fact:
  174. reconcile_completed: "{{ hostvars
  175. | lib_utils_oo_select_keys(groups.oo_masters_to_config)
  176. | lib_utils_oo_collect('inventory_hostname', {'reconcile_complete': true}) }}"
  177. - set_fact:
  178. reconcile_failed: "{{ groups.oo_masters_to_config | difference(reconcile_completed) | list }}"
  179. - fail:
  180. msg: "Upgrade cannot continue. The following masters did not finish reconciling: {{ reconcile_failed | join(',') }}"
  181. when: reconcile_failed | length > 0
  182. - name: Drain and upgrade master nodes
  183. hosts: oo_masters_to_config:&oo_nodes_to_upgrade
  184. # This var must be set with -e on invocation, as it is not a per-host inventory var
  185. # and is evaluated early. Values such as "20%" can also be used.
  186. serial: "{{ openshift_upgrade_control_plane_nodes_serial | default(1) }}"
  187. max_fail_percentage: "{{ openshift_upgrade_control_plane_nodes_max_fail_percentage | default(0) }}"
  188. pre_tasks:
  189. - name: Load lib_openshift modules
  190. import_role:
  191. name: lib_openshift
  192. roles:
  193. - openshift_facts
  194. post_tasks:
  195. - import_role:
  196. name: openshift_manage_node
  197. tasks_from: config.yml
  198. vars:
  199. openshift_master_host: "{{ groups.oo_first_master.0 }}"
  200. openshift_manage_node_is_master: true