package_docker.yml 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167
  1. ---
  2. - name: Get current installed Docker version
  3. command: "{{ repoquery_installed }} --qf '%{version}' docker"
  4. when: not openshift.common.is_atomic | bool
  5. register: curr_docker_version
  6. retries: 4
  7. until: curr_docker_version | succeeded
  8. changed_when: false
  9. - name: Error out if Docker pre-installed but too old
  10. fail:
  11. msg: "Docker {{ curr_docker_version.stdout }} is installed, but >= 1.9.1 is required."
  12. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and curr_docker_version.stdout | version_compare('1.9.1', '<') and not docker_version is defined
  13. - name: Error out if requested Docker is too old
  14. fail:
  15. msg: "Docker {{ docker_version }} requested, but >= 1.9.1 is required."
  16. when: docker_version is defined and docker_version | version_compare('1.9.1', '<')
  17. # If a docker_version was requested, sanity check that we can install or upgrade to it, and
  18. # no downgrade is required.
  19. - name: Fail if Docker version requested but downgrade is required
  20. fail:
  21. msg: "Docker {{ curr_docker_version.stdout }} is installed, but version {{ docker_version }} was requested."
  22. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and docker_version is defined and curr_docker_version.stdout | version_compare(docker_version, '>')
  23. # This involves an extremely slow migration process, users should instead run the
  24. # Docker 1.10 upgrade playbook to accomplish this.
  25. - name: Error out if attempting to upgrade Docker across the 1.10 boundary
  26. fail:
  27. msg: "Cannot upgrade Docker to >= 1.10, please upgrade or remove Docker manually, or use the Docker upgrade playbook if OpenShift is already installed."
  28. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and curr_docker_version.stdout | version_compare('1.10', '<') and docker_version is defined and docker_version | version_compare('1.10', '>=')
  29. # Make sure Docker is installed, but does not update a running version.
  30. # Docker upgrades are handled by a separate playbook.
  31. # Note: The curr_docker_version.stdout check can be removed when https://github.com/ansible/ansible/issues/33187 gets fixed.
  32. - name: Install Docker
  33. package: name=docker{{ '-' + docker_version if docker_version is defined else '' }} state=present
  34. when: not openshift.common.is_atomic | bool and not curr_docker_version | skipped and not curr_docker_version.stdout != ''
  35. register: result
  36. until: result | success
  37. - block:
  38. # Extend the default Docker service unit file when using iptables-services
  39. - name: Ensure docker.service.d directory exists
  40. file:
  41. path: "{{ docker_systemd_dir }}"
  42. state: directory
  43. - name: Configure Docker service unit file
  44. template:
  45. dest: "{{ docker_systemd_dir }}/custom.conf"
  46. src: custom.conf.j2
  47. notify:
  48. - restart container runtime
  49. when: not (os_firewall_use_firewalld | default(False)) | bool
  50. - stat: path=/etc/sysconfig/docker
  51. register: docker_check
  52. - name: Set registry params
  53. lineinfile:
  54. dest: /etc/sysconfig/docker
  55. regexp: '^{{ item.reg_conf_var }}=.*$'
  56. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val | oo_prepend_strings_in_list(item.reg_flag ~ ' ') | join(' ') }}'"
  57. when:
  58. - item.reg_fact_val != []
  59. - docker_check.stat.isreg is defined
  60. - docker_check.stat.isreg
  61. with_items:
  62. - reg_conf_var: ADD_REGISTRY
  63. reg_fact_val: "{{ l2_docker_additional_registries }}"
  64. reg_flag: --add-registry
  65. - reg_conf_var: BLOCK_REGISTRY
  66. reg_fact_val: "{{ l2_docker_blocked_registries }}"
  67. reg_flag: --block-registry
  68. - reg_conf_var: INSECURE_REGISTRY
  69. reg_fact_val: "{{ l2_docker_insecure_registries }}"
  70. reg_flag: --insecure-registry
  71. notify:
  72. - restart container runtime
  73. - name: Place additional/blocked/insecure registries in /etc/containers/registries.conf
  74. template:
  75. dest: "{{ containers_registries_conf_path }}"
  76. src: registries.conf
  77. when: openshift_docker_use_etc_containers | bool
  78. notify:
  79. - restart container runtime
  80. - name: Set Proxy Settings
  81. lineinfile:
  82. dest: /etc/sysconfig/docker
  83. regexp: '^{{ item.reg_conf_var }}=.*$'
  84. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val }}'"
  85. state: "{{ 'present' if item.reg_fact_val != '' else 'absent'}}"
  86. with_items:
  87. - reg_conf_var: HTTP_PROXY
  88. reg_fact_val: "{{ docker_http_proxy }}"
  89. - reg_conf_var: HTTPS_PROXY
  90. reg_fact_val: "{{ docker_https_proxy }}"
  91. - reg_conf_var: NO_PROXY
  92. reg_fact_val: "{{ docker_no_proxy }}"
  93. notify:
  94. - restart container runtime
  95. when:
  96. - docker_check.stat.isreg is defined
  97. - docker_check.stat.isreg
  98. - docker_http_proxy != '' or docker_https_proxy != ''
  99. - name: Set various Docker options
  100. lineinfile:
  101. dest: /etc/sysconfig/docker
  102. regexp: '^OPTIONS=.*$'
  103. line: "OPTIONS='\
  104. {% if ansible_selinux.status | default(None) == 'enabled' and openshift_docker_selinux_enabled | default(true) | bool %} --selinux-enabled {% endif %} \
  105. {% if openshift_docker_log_driver | bool %} --log-driver {{ openshift_docker_log_driver }}{% endif %} \
  106. {% if l2_docker_log_options != [] %} {{ l2_docker_log_options | oo_split() | oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %} \
  107. {% if openshift_docker_hosted_registry_insecure and (openshift_docker_hosted_registry_network | bool) %} --insecure-registry={{ openshift_docker_hosted_registry_network }} {% endif %} \
  108. {% if docker_options is defined %} {{ docker_options }}{% endif %} \
  109. {% if openshift_docker_options %} {{ openshift_docker_options }}{% endif %} \
  110. {% if openshift_docker_disable_push_dockerhub %} --confirm-def-push={{ openshift_docker_disable_push_dockerhub | bool }}{% endif %} \
  111. --signature-verification={{ openshift_docker_signature_verification | bool }}'"
  112. when: docker_check.stat.isreg is defined and docker_check.stat.isreg
  113. notify:
  114. - restart container runtime
  115. - stat: path=/etc/sysconfig/docker-network
  116. register: sysconfig_docker_network_check
  117. - name: Configure Docker Network OPTIONS
  118. lineinfile:
  119. dest: /etc/sysconfig/docker-network
  120. regexp: '^DOCKER_NETWORK_OPTIONS=.*$'
  121. line: "DOCKER_NETWORK_OPTIONS='\
  122. {% if openshift.node is defined and openshift.node.sdn_mtu is defined %} --mtu={{ openshift.node.sdn_mtu }}{% endif %}'"
  123. when:
  124. - sysconfig_docker_network_check.stat.isreg is defined
  125. - sysconfig_docker_network_check.stat.isreg
  126. notify:
  127. - restart container runtime
  128. # The following task is needed as the systemd module may report a change in
  129. # state even though docker is already running.
  130. - name: Detect if docker is already started
  131. command: "systemctl show docker -p ActiveState"
  132. changed_when: False
  133. register: r_docker_already_running_result
  134. - name: Start the Docker service
  135. systemd:
  136. name: docker
  137. enabled: yes
  138. state: started
  139. daemon_reload: yes
  140. register: r_docker_package_docker_start_result
  141. until: not r_docker_package_docker_start_result | failed
  142. retries: 3
  143. delay: 30
  144. - set_fact:
  145. docker_service_status_changed: "{{ (r_docker_package_docker_start_result | changed) and (r_docker_already_running_result.stdout != 'ActiveState=active' ) }}"
  146. - meta: flush_handlers
  147. # This needs to run after docker is restarted to account for proxy settings.
  148. - include_tasks: registry_auth.yml