package_docker.yml 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166
  1. ---
  2. - import_tasks: common/pre.yml
  3. - name: Get current installed Docker version
  4. command: "{{ repoquery_installed }} --qf '%{version}' docker"
  5. register: curr_docker_version
  6. retries: 4
  7. until: curr_docker_version is succeeded
  8. changed_when: false
  9. # Some basic checks to ensure the role will complete
  10. - import_tasks: docker_sanity.yml
  11. # Make sure Docker is installed, but does not update a running version.
  12. # Docker upgrades are handled by a separate playbook.
  13. # Note: The curr_docker_version.stdout check can be removed when https://github.com/ansible/ansible/issues/33187 gets fixed.
  14. - name: Install Docker
  15. package:
  16. name: "{{ pkg_list | join(',') }}"
  17. state: present
  18. register: result
  19. until: result is succeeded
  20. vars:
  21. pkg_list:
  22. - "docker{{ '-' + docker_version if docker_version is defined else '' }}"
  23. - atomic
  24. - skopeo
  25. - block:
  26. # Extend the default Docker service unit file when using iptables-services
  27. - name: Ensure docker.service.d directory exists
  28. file:
  29. path: "{{ docker_systemd_dir }}"
  30. state: directory
  31. - name: Configure Docker service unit file
  32. template:
  33. dest: "{{ docker_systemd_dir }}/custom.conf"
  34. src: custom.conf.j2
  35. notify:
  36. - restart container runtime
  37. when: not (os_firewall_use_firewalld | default(False)) | bool
  38. - stat:
  39. path: /etc/sysconfig/docker
  40. get_checksum: false
  41. get_mime: false
  42. register: docker_check
  43. - name: Set registry params
  44. lineinfile:
  45. dest: /etc/sysconfig/docker
  46. regexp: '^{{ item.reg_conf_var }}=.*$'
  47. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val | lib_utils_oo_prepend_strings_in_list(item.reg_flag ~ ' ') | join(' ') }}'"
  48. when:
  49. - item.reg_fact_val != []
  50. - docker_check.stat.isreg is defined
  51. - docker_check.stat.isreg
  52. with_items:
  53. - reg_conf_var: ADD_REGISTRY
  54. reg_fact_val: "{{ l2_docker_additional_registries }}"
  55. reg_flag: --add-registry
  56. - reg_conf_var: BLOCK_REGISTRY
  57. reg_fact_val: "{{ l2_docker_blocked_registries }}"
  58. reg_flag: --block-registry
  59. - reg_conf_var: INSECURE_REGISTRY
  60. reg_fact_val: "{{ l2_docker_insecure_registries }}"
  61. reg_flag: --insecure-registry
  62. notify:
  63. - restart container runtime
  64. - name: Place additional/blocked/insecure registries in /etc/containers/registries.conf
  65. template:
  66. dest: "{{ containers_registries_conf_path }}"
  67. src: registries.conf
  68. when: openshift_docker_use_etc_containers | bool
  69. notify:
  70. - restart container runtime
  71. - name: Set Proxy Settings
  72. lineinfile:
  73. dest: /etc/sysconfig/docker
  74. regexp: '^{{ item.reg_conf_var }}=.*$'
  75. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val }}'"
  76. state: "{{ 'present' if item.reg_fact_val != '' else 'absent'}}"
  77. with_items:
  78. - reg_conf_var: HTTP_PROXY
  79. reg_fact_val: "{{ docker_http_proxy }}"
  80. - reg_conf_var: HTTPS_PROXY
  81. reg_fact_val: "{{ docker_https_proxy }}"
  82. - reg_conf_var: NO_PROXY
  83. reg_fact_val: "{{ docker_no_proxy }}"
  84. notify:
  85. - restart container runtime
  86. when:
  87. - docker_check.stat.isreg is defined
  88. - docker_check.stat.isreg
  89. - docker_http_proxy != '' or docker_https_proxy != ''
  90. - name: Set various Docker options
  91. lineinfile:
  92. dest: /etc/sysconfig/docker
  93. regexp: '^OPTIONS=.*$'
  94. line: "OPTIONS='\
  95. {% if ansible_selinux.status | default(None) == 'enabled' and openshift_docker_selinux_enabled | default(true) | bool %} --selinux-enabled {% endif %} \
  96. {% if openshift_docker_log_driver %} --log-driver {{ openshift_docker_log_driver }}{% endif %} \
  97. {% if l2_docker_log_options != [] %} {{ l2_docker_log_options | lib_utils_oo_split() | lib_utils_oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %} \
  98. {% if (openshift_docker_hosted_registry_insecure | bool) and openshift_docker_hosted_registry_network %} --insecure-registry={{ openshift_docker_hosted_registry_network }} {% endif %} \
  99. {% if docker_options is defined %} {{ docker_options }}{% endif %} \
  100. {% if openshift_docker_options %} {{ openshift_docker_options }}{% endif %} \
  101. --signature-verification={{ openshift_docker_signature_verification | bool }}'"
  102. when: docker_check.stat.isreg is defined and docker_check.stat.isreg
  103. notify:
  104. - restart container runtime
  105. - stat:
  106. path: /etc/sysconfig/docker-network
  107. get_checksum: false
  108. get_mime: false
  109. register: sysconfig_docker_network_check
  110. - name: Configure Docker Network OPTIONS
  111. lineinfile:
  112. dest: /etc/sysconfig/docker-network
  113. regexp: '^DOCKER_NETWORK_OPTIONS=.*$'
  114. line: "DOCKER_NETWORK_OPTIONS='\
  115. {% if openshift.node is defined and openshift.node.sdn_mtu is defined %} --mtu={{ openshift.node.sdn_mtu }}{% endif %}'"
  116. when:
  117. - sysconfig_docker_network_check.stat.isreg is defined
  118. - sysconfig_docker_network_check.stat.isreg
  119. notify:
  120. - restart container runtime
  121. # The following task is needed as the systemd module may report a change in
  122. # state even though docker is already running.
  123. - name: Detect if docker is already started
  124. command: "systemctl show docker -p ActiveState"
  125. changed_when: False
  126. register: r_docker_already_running_result
  127. - name: Start the Docker service
  128. systemd:
  129. name: docker
  130. enabled: yes
  131. state: started
  132. daemon_reload: yes
  133. register: r_docker_package_docker_start_result
  134. until: not (r_docker_package_docker_start_result is failed)
  135. retries: 3
  136. delay: 30
  137. - set_fact:
  138. docker_service_status_changed: "{{ (r_docker_package_docker_start_result is changed) and (r_docker_already_running_result.stdout != 'ActiveState=active' ) }}"
  139. - name: Check for docker_storage_path/overlay2
  140. stat:
  141. path: "{{ docker_storage_path }}/overlay2"
  142. register: dsp_stat
  143. - name: Fixup SELinux permissions for docker
  144. shell: |
  145. semanage fcontext -a -e /var/lib/docker/overlay2 "{{ docker_storage_path }}/overlay2"
  146. restorecon -R -v "{{ docker_storage_path }}/overlay2"
  147. when: dsp_stat.stat.exists
  148. - import_tasks: common/post.yml