package_docker.yml 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147
  1. ---
  2. - include_tasks: common/pre.yml
  3. - name: Get current installed Docker version
  4. command: "{{ repoquery_installed }} --qf '%{version}' docker"
  5. when: not openshift.common.is_atomic | bool
  6. register: curr_docker_version
  7. retries: 4
  8. until: curr_docker_version | succeeded
  9. changed_when: false
  10. # Some basic checks to ensure the role will complete
  11. - include_tasks: docker_sanity.yml
  12. # Make sure Docker is installed, but does not update a running version.
  13. # Docker upgrades are handled by a separate playbook.
  14. # Note: The curr_docker_version.stdout check can be removed when https://github.com/ansible/ansible/issues/33187 gets fixed.
  15. - name: Install Docker
  16. package:
  17. name: "docker{{ '-' + docker_version if docker_version is defined else '' }}"
  18. state: present
  19. when: not openshift.common.is_atomic | bool and not curr_docker_version | skipped and not curr_docker_version.stdout != ''
  20. register: result
  21. until: result | success
  22. - block:
  23. # Extend the default Docker service unit file when using iptables-services
  24. - name: Ensure docker.service.d directory exists
  25. file:
  26. path: "{{ docker_systemd_dir }}"
  27. state: directory
  28. - name: Configure Docker service unit file
  29. template:
  30. dest: "{{ docker_systemd_dir }}/custom.conf"
  31. src: custom.conf.j2
  32. notify:
  33. - restart container runtime
  34. when: not (os_firewall_use_firewalld | default(False)) | bool
  35. - stat: path=/etc/sysconfig/docker
  36. register: docker_check
  37. - name: Set registry params
  38. lineinfile:
  39. dest: /etc/sysconfig/docker
  40. regexp: '^{{ item.reg_conf_var }}=.*$'
  41. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val | oo_prepend_strings_in_list(item.reg_flag ~ ' ') | join(' ') }}'"
  42. when:
  43. - item.reg_fact_val != []
  44. - docker_check.stat.isreg is defined
  45. - docker_check.stat.isreg
  46. with_items:
  47. - reg_conf_var: ADD_REGISTRY
  48. reg_fact_val: "{{ l2_docker_additional_registries }}"
  49. reg_flag: --add-registry
  50. - reg_conf_var: BLOCK_REGISTRY
  51. reg_fact_val: "{{ l2_docker_blocked_registries }}"
  52. reg_flag: --block-registry
  53. - reg_conf_var: INSECURE_REGISTRY
  54. reg_fact_val: "{{ l2_docker_insecure_registries }}"
  55. reg_flag: --insecure-registry
  56. notify:
  57. - restart container runtime
  58. - name: Place additional/blocked/insecure registries in /etc/containers/registries.conf
  59. template:
  60. dest: "{{ containers_registries_conf_path }}"
  61. src: registries.conf
  62. when: openshift_docker_use_etc_containers | bool
  63. notify:
  64. - restart container runtime
  65. - name: Set Proxy Settings
  66. lineinfile:
  67. dest: /etc/sysconfig/docker
  68. regexp: '^{{ item.reg_conf_var }}=.*$'
  69. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val }}'"
  70. state: "{{ 'present' if item.reg_fact_val != '' else 'absent'}}"
  71. with_items:
  72. - reg_conf_var: HTTP_PROXY
  73. reg_fact_val: "{{ docker_http_proxy }}"
  74. - reg_conf_var: HTTPS_PROXY
  75. reg_fact_val: "{{ docker_https_proxy }}"
  76. - reg_conf_var: NO_PROXY
  77. reg_fact_val: "{{ docker_no_proxy }}"
  78. notify:
  79. - restart container runtime
  80. when:
  81. - docker_check.stat.isreg is defined
  82. - docker_check.stat.isreg
  83. - docker_http_proxy != '' or docker_https_proxy != ''
  84. - name: Set various Docker options
  85. lineinfile:
  86. dest: /etc/sysconfig/docker
  87. regexp: '^OPTIONS=.*$'
  88. line: "OPTIONS='\
  89. {% if ansible_selinux.status | default(None) == 'enabled' and openshift_docker_selinux_enabled | default(true) | bool %} --selinux-enabled {% endif %} \
  90. {% if openshift_docker_log_driver | bool %} --log-driver {{ openshift_docker_log_driver }}{% endif %} \
  91. {% if l2_docker_log_options != [] %} {{ l2_docker_log_options | oo_split() | oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %} \
  92. {% if openshift_docker_hosted_registry_insecure and (openshift_docker_hosted_registry_network | bool) %} --insecure-registry={{ openshift_docker_hosted_registry_network }} {% endif %} \
  93. {% if docker_options is defined %} {{ docker_options }}{% endif %} \
  94. {% if openshift_docker_options %} {{ openshift_docker_options }}{% endif %} \
  95. {% if openshift_docker_disable_push_dockerhub %} --confirm-def-push={{ openshift_docker_disable_push_dockerhub | bool }}{% endif %} \
  96. --signature-verification={{ openshift_docker_signature_verification | bool }}'"
  97. when: docker_check.stat.isreg is defined and docker_check.stat.isreg
  98. notify:
  99. - restart container runtime
  100. - stat: path=/etc/sysconfig/docker-network
  101. register: sysconfig_docker_network_check
  102. - name: Configure Docker Network OPTIONS
  103. lineinfile:
  104. dest: /etc/sysconfig/docker-network
  105. regexp: '^DOCKER_NETWORK_OPTIONS=.*$'
  106. line: "DOCKER_NETWORK_OPTIONS='\
  107. {% if openshift.node is defined and openshift.node.sdn_mtu is defined %} --mtu={{ openshift.node.sdn_mtu }}{% endif %}'"
  108. when:
  109. - sysconfig_docker_network_check.stat.isreg is defined
  110. - sysconfig_docker_network_check.stat.isreg
  111. notify:
  112. - restart container runtime
  113. # The following task is needed as the systemd module may report a change in
  114. # state even though docker is already running.
  115. - name: Detect if docker is already started
  116. command: "systemctl show docker -p ActiveState"
  117. changed_when: False
  118. register: r_docker_already_running_result
  119. - name: Start the Docker service
  120. systemd:
  121. name: docker
  122. enabled: yes
  123. state: started
  124. daemon_reload: yes
  125. register: r_docker_package_docker_start_result
  126. until: not r_docker_package_docker_start_result | failed
  127. retries: 3
  128. delay: 30
  129. - set_fact:
  130. docker_service_status_changed: "{{ (r_docker_package_docker_start_result | changed) and (r_docker_already_running_result.stdout != 'ActiveState=active' ) }}"
  131. - include_tasks: common/post.yml