main.yml 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239
  1. ---
  2. openshift_node_debug_level: "{{ debug_level | default(2) }}"
  3. openshift_node_iptables_sync_period: '30s'
  4. osn_storage_plugin_deps:
  5. - ceph
  6. - glusterfs
  7. - iscsi
  8. openshift_node_local_quota_per_fsgroup: ""
  9. openshift_node_proxy_mode: iptables
  10. openshift_set_node_ip: False
  11. openshift_config_base: '/etc/origin'
  12. openshift_oreg_url_default_dict:
  13. origin: "openshift/origin-${component}:${version}"
  14. openshift-enterprise: "openshift3/ose-${component}:${version}"
  15. openshift_oreg_url_default: "{{ openshift_oreg_url_default_dict[openshift_deployment_type] }}"
  16. oreg_url_node: "{{ oreg_url | default(openshift_oreg_url_default) | regex_replace('${version}' | regex_escape, openshift_image_tag | default('${version}')) }}"
  17. openshift_dns_ip: "{{ ansible_default_ipv4['address'] }}"
  18. openshift_node_env_vars: {}
  19. # Create list of 'k=v' pairs.
  20. l_node_kubelet_node_labels: "{{ openshift_node_labels | default({}) | lib_utils_oo_dict_to_keqv_list }}"
  21. openshift_node_kubelet_args_dict:
  22. aws:
  23. cloud-provider:
  24. - aws
  25. cloud-config:
  26. - "{{ openshift_config_base ~ '/cloudprovider/aws.conf' }}"
  27. node-labels: "{{ l_node_kubelet_node_labels }}"
  28. openstack:
  29. cloud-provider:
  30. - openstack
  31. cloud-config:
  32. - "{{ openshift_config_base ~ '/cloudprovider/openstack.conf' }}"
  33. node-labels: "{{ l_node_kubelet_node_labels }}"
  34. gce:
  35. cloud-provider:
  36. - gce
  37. cloud-config:
  38. - "{{ openshift_config_base ~ '/cloudprovider/gce.conf' }}"
  39. node-labels: "{{ l_node_kubelet_node_labels }}"
  40. azure:
  41. cloud-provider:
  42. - azure
  43. cloud-config:
  44. - "{{ openshift_config_base ~ '/cloudprovider/azure.conf' }}"
  45. node-labels: "{{ l_node_kubelet_node_labels }}"
  46. vsphere:
  47. cloud-provider:
  48. - vsphere
  49. cloud-config:
  50. - "{{ openshift_config_base ~ '/cloudprovider/vsphere.conf' }}"
  51. node-labels: "{{ l_node_kubelet_node_labels }}"
  52. undefined:
  53. node-labels: "{{ l_node_kubelet_node_labels }}"
  54. l_node_kubelet_args_default: "{{ openshift_node_kubelet_args_dict[openshift_cloudprovider_kind | default('undefined')] }}"
  55. l_openshift_node_kubelet_args: "{{ openshift_node_kubelet_args | default({}) }}"
  56. # Combine the default kubelet_args dictionary (based on cloud provider, if provided)
  57. # with user-supplied openshift_node_kubelet_args.
  58. # openshift_node_kubelet_args will override the defaults, if keys and/or subkeys
  59. # are present in both.
  60. l2_openshift_node_kubelet_args: "{{ l_node_kubelet_args_default | combine(l_openshift_node_kubelet_args, recursive=True) }}"
  61. openshift_node_dnsmasq_install_network_manager_hook: true
  62. # lo must always be present in this list or dnsmasq will conflict with
  63. # the node's dns service.
  64. openshift_node_dnsmasq_except_interfaces:
  65. - lo
  66. r_openshift_node_firewall_enabled: "{{ os_firewall_enabled | default(True) }}"
  67. r_openshift_node_use_firewalld: "{{ os_firewall_use_firewalld | default(False) }}"
  68. l_is_node_system_container: "{{ (openshift_use_node_system_container | default(openshift_use_system_containers | default(false)) | bool) }}"
  69. openshift_node_syscon_auth_mounts_l:
  70. - type: bind
  71. source: "{{ oreg_auth_credentials_path }}"
  72. destination: "/root/.docker"
  73. options:
  74. - ro
  75. - bind
  76. # If we need to add new mounts in the future, or the user wants to mount data.
  77. # This should be in the same format as auth_mounts_l above.
  78. openshift_node_syscon_add_mounts_l: []
  79. openshift_deployment_type: "{{ openshift_deployment_type | default('origin') }}"
  80. l_openshift_images_dict:
  81. origin: 'openshift/origin-${component}:${version}'
  82. openshift-enterprise: 'openshift3/ose-${component}:${version}'
  83. l_osm_registry_url_default: "{{ l_openshift_images_dict[openshift_deployment_type] }}"
  84. l_os_registry_url: "{{ oreg_url | default(l_osm_registry_url_default) | regex_replace('${version}' | regex_escape, openshift_image_tag | default('${version}')) }}"
  85. l_openshift_prefix_dict:
  86. origin: 'origin-${component}'
  87. openshift-enterprise: 'ose-${component}'
  88. l_os_prefix: "{{ l_openshift_prefix_dict[openshift_deployment_type] }}"
  89. # TODO: we should publish oreg_url component=node
  90. osn_image: "{{ l_os_registry_url | regex_replace(l_os_prefix | regex_escape, 'node') }}"
  91. openshift_service_type_dict:
  92. origin: origin
  93. openshift-enterprise: atomic-openshift
  94. openshift_service_type: "{{ openshift_service_type_dict[openshift_deployment_type] }}"
  95. system_images_registry_dict:
  96. openshift-enterprise: "registry.access.redhat.com"
  97. origin: "docker.io"
  98. system_images_registry: "{{ system_images_registry_dict[openshift_deployment_type | default('origin')] }}"
  99. openshift_image_tag: ''
  100. default_r_openshift_node_image_prep_packages:
  101. - "{{ openshift_service_type }}-node"
  102. - "{{ openshift_service_type }}-docker-excluder"
  103. - ansible
  104. - bash-completion
  105. - docker
  106. - haproxy
  107. - dnsmasq
  108. - ntp
  109. - logrotate
  110. - httpd-tools
  111. - bind-utils
  112. - firewalld
  113. - libselinux-python
  114. - conntrack-tools
  115. - openssl
  116. - cloud-init
  117. - iproute
  118. - python-dbus
  119. - PyYAML
  120. - yum-utils
  121. - glusterfs-fuse
  122. - device-mapper-multipath
  123. - nfs-utils
  124. - cockpit-ws
  125. - cockpit-system
  126. - cockpit-bridge
  127. - cockpit-docker
  128. - iscsi-initiator-utils
  129. - ceph-common
  130. r_openshift_node_image_prep_packages: "{{ default_r_openshift_node_image_prep_packages | union(openshift_node_image_prep_packages | default([])) }}"
  131. openshift_node_bootstrap: False
  132. r_openshift_node_os_firewall_deny: []
  133. default_r_openshift_node_os_firewall_allow:
  134. - service: Kubernetes kubelet
  135. port: 10250/tcp
  136. - service: http
  137. port: 80/tcp
  138. - service: https
  139. port: 443/tcp
  140. - service: OpenShift OVS sdn
  141. port: 4789/udp
  142. cond: openshift_use_openshift_sdn | bool
  143. - service: Calico BGP Port
  144. port: 179/tcp
  145. cond: "{{ openshift_node_use_calico }}"
  146. - service: Kubernetes service NodePort TCP
  147. port: "{{ openshift_node_port_range | default('') }}/tcp"
  148. cond: "{{ openshift_node_port_range is defined }}"
  149. - service: Kubernetes service NodePort UDP
  150. port: "{{ openshift_node_port_range | default('') }}/udp"
  151. cond: "{{ openshift_node_port_range is defined }}"
  152. # Allow multiple port ranges to be added to the role
  153. r_openshift_node_os_firewall_allow: "{{ default_r_openshift_node_os_firewall_allow | union(openshift_node_open_ports | default([])) }}"
  154. # oreg_url is defined by user input
  155. oreg_host: "{{ oreg_url.split('/')[0] if (oreg_url is defined and '.' in oreg_url.split('/')[0]) else '' }}"
  156. oreg_auth_credentials_path: "{{ openshift_node_data_dir }}/.docker"
  157. oreg_auth_credentials_replace: False
  158. l_bind_docker_reg_auth: False
  159. openshift_use_crio: False
  160. l_crio_use_new_var_sock: "{{ openshift_version | version_compare('3.9', '>=') }}"
  161. l_crio_var_sock: "{{ l_crio_use_new_var_sock | ternary('/var/run/crio/crio.sock', '/var/run/crio.sock') }}"
  162. openshift_docker_alternative_creds: "{{ (openshift_docker_use_system_container | default(False) | bool) or (openshift_use_crio_only | default(False) | bool) }}"
  163. openshift_docker_service_name: "{{ 'container-engine' if (openshift_docker_use_system_container | default(False) | bool) else 'docker' }}"
  164. # These defaults assume forcing journald persistence, fsync to disk once
  165. # a second, rate-limiting to 10,000 logs a second, no forwarding to
  166. # syslog or wall, using 8GB of disk space maximum, using 10MB journal
  167. # files, keeping only a days worth of logs per journal file, and
  168. # retaining journal files no longer than a month.
  169. journald_vars_to_replace:
  170. - { var: Storage, val: persistent }
  171. - { var: Compress, val: yes }
  172. - { var: SyncIntervalSec, val: 1s }
  173. - { var: RateLimitInterval, val: 1s }
  174. - { var: RateLimitBurst, val: 10000 }
  175. - { var: SystemMaxUse, val: 8G }
  176. - { var: SystemKeepFree, val: 20% }
  177. - { var: SystemMaxFileSize, val: 10M }
  178. - { var: MaxRetentionSec, val: 1month }
  179. - { var: MaxFileSec, val: 1day }
  180. - { var: ForwardToSyslog, val: no }
  181. - { var: ForwardToWall, val: no }
  182. # NOTE
  183. # r_openshift_node_*_default may be defined external to this role.
  184. # openshift_use_*, if defined, may affect other roles or play behavior.
  185. openshift_node_use_openshift_sdn_default: "{{ openshift_use_openshift_sdn | default(True) }}"
  186. openshift_node_use_openshift_sdn: "{{ openshift_node_use_openshift_sdn_default }}"
  187. openshift_node_sdn_network_plugin_name_default: "{{ os_sdn_network_plugin_name | default('redhat/openshift-ovs-subnet') }}"
  188. openshift_node_sdn_network_plugin_name: "{{ openshift_node_sdn_network_plugin_name_default }}"
  189. openshift_node_use_calico_default: "{{ openshift_use_calico | default(False) }}"
  190. openshift_node_use_calico: "{{ openshift_node_use_calico_default }}"
  191. openshift_node_use_nuage_default: "{{ openshift_use_nuage | default(False) }}"
  192. openshift_node_use_nuage: "{{ openshift_node_use_nuage_default }}"
  193. openshift_node_use_contiv_default: "{{ openshift_use_contiv | default(False) }}"
  194. openshift_node_use_contiv: "{{ openshift_node_use_contiv_default }}"
  195. openshift_node_use_kuryr_default: "{{ openshift_use_kuryr | default(False) }}"
  196. openshift_node_use_kuryr: "{{ openshift_node_use_kuryr_default }}"
  197. openshift_node_data_dir_default: "{{ openshift_data_dir | default('/var/lib/origin') }}"
  198. openshift_node_data_dir: "{{ openshift_node_data_dir_default }}"
  199. openshift_node_config_dir_default: "/etc/origin/node"
  200. openshift_node_config_dir: "{{ openshift_node_config_dir_default }}"
  201. openshift_node_image_config_latest_default: "{{ openshift_image_config_latest | default(False) }}"
  202. openshift_node_image_config_latest: "{{ openshift_node_image_config_latest_default }}"
  203. openshift_node_use_instance_profiles: False