package_docker.yml 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160
  1. ---
  2. - import_tasks: common/pre.yml
  3. # In some cases, some services may be run as containers and docker may still
  4. # be installed via rpm.
  5. - import_tasks: common/atomic_proxy.yml
  6. when:
  7. - >
  8. (openshift_use_system_containers | default(False)) | bool
  9. or (openshift_use_etcd_system_container | default(False)) | bool
  10. or (openshift_use_node_system_container | default(False)) | bool
  11. or (openshift_use_master_system_container | default(False)) | bool
  12. - name: Get current installed Docker version
  13. command: "{{ repoquery_installed }} --qf '%{version}' docker"
  14. when: not openshift_is_atomic | bool
  15. register: curr_docker_version
  16. retries: 4
  17. until: curr_docker_version is succeeded
  18. changed_when: false
  19. # Some basic checks to ensure the role will complete
  20. - import_tasks: docker_sanity.yml
  21. # Make sure Docker is installed, but does not update a running version.
  22. # Docker upgrades are handled by a separate playbook.
  23. # Note: The curr_docker_version.stdout check can be removed when https://github.com/ansible/ansible/issues/33187 gets fixed.
  24. - name: Install Docker
  25. package:
  26. name: "docker{{ '-' + docker_version if docker_version is defined else '' }}"
  27. state: present
  28. when:
  29. - not (openshift_is_atomic | bool)
  30. - not (curr_docker_version is skipped)
  31. - not (curr_docker_version.stdout != '')
  32. register: result
  33. until: result is succeeded
  34. - block:
  35. # Extend the default Docker service unit file when using iptables-services
  36. - name: Ensure docker.service.d directory exists
  37. file:
  38. path: "{{ docker_systemd_dir }}"
  39. state: directory
  40. - name: Configure Docker service unit file
  41. template:
  42. dest: "{{ docker_systemd_dir }}/custom.conf"
  43. src: custom.conf.j2
  44. notify:
  45. - restart container runtime
  46. when: not (os_firewall_use_firewalld | default(False)) | bool
  47. - stat: path=/etc/sysconfig/docker
  48. register: docker_check
  49. - name: Set registry params
  50. lineinfile:
  51. dest: /etc/sysconfig/docker
  52. regexp: '^{{ item.reg_conf_var }}=.*$'
  53. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val | lib_utils_oo_prepend_strings_in_list(item.reg_flag ~ ' ') | join(' ') }}'"
  54. when:
  55. - item.reg_fact_val != []
  56. - docker_check.stat.isreg is defined
  57. - docker_check.stat.isreg
  58. with_items:
  59. - reg_conf_var: ADD_REGISTRY
  60. reg_fact_val: "{{ l2_docker_additional_registries }}"
  61. reg_flag: --add-registry
  62. - reg_conf_var: BLOCK_REGISTRY
  63. reg_fact_val: "{{ l2_docker_blocked_registries }}"
  64. reg_flag: --block-registry
  65. - reg_conf_var: INSECURE_REGISTRY
  66. reg_fact_val: "{{ l2_docker_insecure_registries }}"
  67. reg_flag: --insecure-registry
  68. notify:
  69. - restart container runtime
  70. - name: Place additional/blocked/insecure registries in /etc/containers/registries.conf
  71. template:
  72. dest: "{{ containers_registries_conf_path }}"
  73. src: registries.conf
  74. when: openshift_docker_use_etc_containers | bool
  75. notify:
  76. - restart container runtime
  77. - name: Set Proxy Settings
  78. lineinfile:
  79. dest: /etc/sysconfig/docker
  80. regexp: '^{{ item.reg_conf_var }}=.*$'
  81. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val }}'"
  82. state: "{{ 'present' if item.reg_fact_val != '' else 'absent'}}"
  83. with_items:
  84. - reg_conf_var: HTTP_PROXY
  85. reg_fact_val: "{{ docker_http_proxy }}"
  86. - reg_conf_var: HTTPS_PROXY
  87. reg_fact_val: "{{ docker_https_proxy }}"
  88. - reg_conf_var: NO_PROXY
  89. reg_fact_val: "{{ docker_no_proxy }}"
  90. notify:
  91. - restart container runtime
  92. when:
  93. - docker_check.stat.isreg is defined
  94. - docker_check.stat.isreg
  95. - docker_http_proxy != '' or docker_https_proxy != ''
  96. - name: Set various Docker options
  97. lineinfile:
  98. dest: /etc/sysconfig/docker
  99. regexp: '^OPTIONS=.*$'
  100. line: "OPTIONS='\
  101. {% if ansible_selinux.status | default(None) == 'enabled' and openshift_docker_selinux_enabled | default(true) | bool %} --selinux-enabled {% endif %} \
  102. {% if openshift_docker_log_driver %} --log-driver {{ openshift_docker_log_driver }}{% endif %} \
  103. {% if l2_docker_log_options != [] %} {{ l2_docker_log_options | lib_utils_oo_split() | lib_utils_oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %} \
  104. {% if (openshift_docker_hosted_registry_insecure | bool) and openshift_docker_hosted_registry_network %} --insecure-registry={{ openshift_docker_hosted_registry_network }} {% endif %} \
  105. {% if docker_options is defined %} {{ docker_options }}{% endif %} \
  106. {% if openshift_docker_options %} {{ openshift_docker_options }}{% endif %} \
  107. {% if openshift_docker_disable_push_dockerhub | bool %} --confirm-def-push={{ openshift_docker_disable_push_dockerhub | bool }}{% endif %} \
  108. --signature-verification={{ openshift_docker_signature_verification | bool }}'"
  109. when: docker_check.stat.isreg is defined and docker_check.stat.isreg
  110. notify:
  111. - restart container runtime
  112. - stat: path=/etc/sysconfig/docker-network
  113. register: sysconfig_docker_network_check
  114. - name: Configure Docker Network OPTIONS
  115. lineinfile:
  116. dest: /etc/sysconfig/docker-network
  117. regexp: '^DOCKER_NETWORK_OPTIONS=.*$'
  118. line: "DOCKER_NETWORK_OPTIONS='\
  119. {% if openshift.node is defined and openshift.node.sdn_mtu is defined %} --mtu={{ openshift.node.sdn_mtu }}{% endif %}'"
  120. when:
  121. - sysconfig_docker_network_check.stat.isreg is defined
  122. - sysconfig_docker_network_check.stat.isreg
  123. notify:
  124. - restart container runtime
  125. # The following task is needed as the systemd module may report a change in
  126. # state even though docker is already running.
  127. - name: Detect if docker is already started
  128. command: "systemctl show docker -p ActiveState"
  129. changed_when: False
  130. register: r_docker_already_running_result
  131. - name: Start the Docker service
  132. systemd:
  133. name: docker
  134. enabled: yes
  135. state: started
  136. daemon_reload: yes
  137. register: r_docker_package_docker_start_result
  138. until: not (r_docker_package_docker_start_result is failed)
  139. retries: 3
  140. delay: 30
  141. - set_fact:
  142. docker_service_status_changed: "{{ (r_docker_package_docker_start_result is changed) and (r_docker_already_running_result.stdout != 'ActiveState=active' ) }}"
  143. - import_tasks: common/post.yml