openshift_hosted.yml 6.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162
  1. ---
  2. - name: Create persistent volumes
  3. hosts: oo_first_master
  4. tags:
  5. - hosted
  6. vars:
  7. persistent_volumes: "{{ hostvars[groups.oo_first_master.0] | oo_persistent_volumes(groups) }}"
  8. persistent_volume_claims: "{{ hostvars[groups.oo_first_master.0] | oo_persistent_volume_claims }}"
  9. roles:
  10. - role: openshift_persistent_volumes
  11. when: persistent_volumes | length > 0 or persistent_volume_claims | length > 0
  12. - name: Create Hosted Resources
  13. hosts: oo_first_master
  14. tags:
  15. - hosted
  16. pre_tasks:
  17. - set_fact:
  18. openshift_hosted_router_registryurl: "{{ hostvars[groups.oo_first_master.0].openshift.master.registry_url }}"
  19. openshift_hosted_registry_registryurl: "{{ hostvars[groups.oo_first_master.0].openshift.master.registry_url }}"
  20. when: "'master' in hostvars[groups.oo_first_master.0].openshift and 'registry_url' in hostvars[groups.oo_first_master.0].openshift.master"
  21. - set_fact:
  22. logging_hostname: "{{ openshift_hosted_logging_hostname | default('kibana.' ~ openshift_master_default_subdomain) }}"
  23. logging_ops_hostname: "{{ openshift_hosted_logging_ops_hostname | default('kibana-ops.' ~ openshift_master_default_subdomain) }}"
  24. logging_master_public_url: "{{ openshift_hosted_logging_master_public_url | default(openshift.master.public_api_url) }}"
  25. logging_elasticsearch_cluster_size: "{{ openshift_hosted_logging_elasticsearch_cluster_size | default(1) }}"
  26. logging_elasticsearch_ops_cluster_size: "{{ openshift_hosted_logging_elasticsearch_ops_cluster_size | default(1) }}"
  27. roles:
  28. - role: openshift_cli
  29. - role: openshift_hosted_facts
  30. - role: openshift_projects
  31. # TODO: Move standard project definitions to openshift_hosted/vars/main.yml
  32. # Vars are not accessible in meta/main.yml in ansible-1.9.x
  33. openshift_projects: "{{ openshift_additional_projects | default({}) | oo_merge_dicts({'default':{'default_node_selector':''},'openshift-infra':{'default_node_selector':''},'logging':{'default_node_selector':''}}) }}"
  34. - role: openshift_serviceaccounts
  35. openshift_serviceaccounts_names:
  36. - router
  37. openshift_serviceaccounts_namespace: default
  38. openshift_serviceaccounts_sccs:
  39. - hostnetwork
  40. when: openshift.common.version_gte_3_2_or_1_2
  41. - role: openshift_serviceaccounts
  42. openshift_serviceaccounts_names:
  43. - router
  44. - registry
  45. openshift_serviceaccounts_namespace: default
  46. openshift_serviceaccounts_sccs:
  47. - privileged
  48. when: not openshift.common.version_gte_3_2_or_1_2
  49. - role: openshift_hosted
  50. - role: openshift_metrics
  51. when: openshift.hosted.metrics.deploy | bool
  52. - role: openshift_hosted_logging
  53. when: openshift.hosted.logging.deploy | bool
  54. openshift_hosted_logging_hostname: "{{ logging_hostname }}"
  55. openshift_hosted_logging_ops_hostname: "{{ logging_ops_hostname }}"
  56. openshift_hosted_logging_master_public_url: "{{ logging_master_public_url }}"
  57. openshift_hosted_logging_elasticsearch_cluster_size: "{{ logging_elasticsearch_cluster_size }}"
  58. openshift_hosted_logging_elasticsearch_ops_cluster_size: "{{ logging_elasticsearch_ops_cluster_size }}"
  59. - role: cockpit-ui
  60. when: openshift.common.deployment_subtype == 'registry'
  61. - name: Configure all masters for logging
  62. serial: 1
  63. handlers:
  64. - include: ../../../roles/openshift_master/handlers/main.yml
  65. static: yes
  66. hosts: oo_masters
  67. tasks:
  68. - openshift_facts:
  69. role: master
  70. local_facts:
  71. logging_public_url: "https://{{ openshift_hosted_logging_hostname | default('kibana.' ~ openshift_master_default_subdomain) }}"
  72. when: openshift.hosted.logging.deploy | default(openshift.common.version_gte_3_3_or_1_3)
  73. - modify_yaml:
  74. dest: "{{ openshift.common.config_base }}/master/master-config.yaml"
  75. yaml_key: assetConfig.loggingPublicURL
  76. yaml_value: "{{ openshift.master.logging_public_url }}"
  77. notify: restart master
  78. when: openshift.hosted.logging.deploy | default(openshift.common.version_gte_3_3_or_1_3)
  79. - name: Configure CA certificate for secure registry
  80. hosts: oo_nodes_to_config
  81. tags:
  82. - hosted
  83. tasks:
  84. - name: Create temp directory for kubeconfig
  85. command: mktemp -d /tmp/openshift-ansible-XXXXXX
  86. register: mktemp
  87. when: openshift.common.deployment_subtype == 'registry'
  88. changed_when: false
  89. delegate_to: "{{ groups.oo_first_master.0 }}"
  90. run_once: true
  91. - set_fact:
  92. openshift_hosted_kubeconfig: "{{ mktemp.stdout }}/admin.kubeconfig"
  93. when: openshift.common.deployment_subtype == 'registry'
  94. delegate_to: "{{ groups.oo_first_master.0 }}"
  95. run_once: true
  96. - name: Copy the admin client config(s)
  97. command: >
  98. cp {{ openshift.common.config_base }}/master/admin.kubeconfig {{ openshift_hosted_kubeconfig }}
  99. when: openshift.common.deployment_subtype == 'registry'
  100. changed_when: false
  101. delegate_to: "{{ groups.oo_first_master.0 }}"
  102. run_once: true
  103. - name: Retrieve docker-registry route
  104. command: >
  105. {{ openshift.common.client_binary }} get route docker-registry
  106. --template='{{ '{{' }} .spec.host {{ '}}' }}'
  107. --config={{ openshift_hosted_kubeconfig }}
  108. -n default
  109. register: docker_registry_route
  110. when: openshift.common.deployment_subtype == 'registry'
  111. changed_when: false
  112. delegate_to: "{{ groups.oo_first_master.0 }}"
  113. run_once: true
  114. - name: Retrieve registry service IP
  115. command: >
  116. {{ openshift.common.client_binary }} get service docker-registry
  117. --template='{{ '{{' }} .spec.clusterIP {{ '}}' }}'
  118. --config={{ openshift_hosted_kubeconfig }}
  119. -n default
  120. register: docker_registry_service_ip
  121. when: openshift.common.deployment_subtype == 'registry'
  122. changed_when: false
  123. delegate_to: "{{ groups.oo_first_master.0 }}"
  124. run_once: true
  125. - name: Create registry CA directories
  126. file:
  127. path: "/etc/docker/certs.d/{{ item }}"
  128. state: directory
  129. with_items:
  130. - "{{ docker_registry_service_ip.stdout }}:5000"
  131. - "{{ docker_registry_route.stdout }}"
  132. - "docker-registry.default.svc.cluster.local:5000"
  133. when: openshift.common.deployment_subtype == 'registry'
  134. - name: Copy CA to registry CA directories
  135. copy:
  136. src: "{{ openshift.common.config_base }}/node/ca.crt"
  137. dest: "/etc/docker/certs.d/{{ item }}"
  138. remote_src: yes
  139. force: yes
  140. with_items:
  141. - "{{ docker_registry_service_ip.stdout }}:5000"
  142. - "{{ docker_registry_route.stdout }}"
  143. - "docker-registry.default.svc.cluster.local:5000"
  144. when: openshift.common.deployment_subtype == 'registry'
  145. notify:
  146. - Restart docker
  147. - name: Delete temp directory
  148. file:
  149. name: "{{ mktemp.stdout }}"
  150. state: absent
  151. when: openshift.common.deployment_subtype == 'registry'
  152. changed_when: False
  153. delegate_to: "{{ groups.oo_first_master.0 }}"
  154. run_once: true
  155. handlers:
  156. - name: Restart docker
  157. service:
  158. name: docker
  159. state: restarted