upgrade.yml 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312
  1. ---
  2. ###############################################################################
  3. # Upgrade Masters
  4. ###############################################################################
  5. # Create service signer cert when missing. Service signer certificate
  6. # is added to master config in the master_config_upgrade hook.
  7. - name: Determine if service signer cert must be created
  8. hosts: oo_first_master
  9. tasks:
  10. - name: Determine if service signer certificate must be created
  11. stat:
  12. path: "{{ openshift.common.config_base }}/master/service-signer.crt"
  13. register: service_signer_cert_stat
  14. changed_when: false
  15. - name: verify api server
  16. command: >
  17. curl --silent --tlsv1.2
  18. --cacert {{ openshift.common.config_base }}/master/ca-bundle.crt
  19. {{ openshift.master.api_url }}/healthz/ready
  20. args:
  21. # Disables the following warning:
  22. # Consider using get_url or uri module rather than running curl
  23. warn: no
  24. register: api_available_output
  25. until: api_available_output.stdout == 'ok'
  26. retries: 120
  27. delay: 1
  28. changed_when: false
  29. - import_playbook: create_service_signer_cert.yml
  30. # oc adm migrate storage should be run prior to etcd v3 upgrade
  31. # See: https://github.com/openshift/origin/pull/14625#issuecomment-308467060
  32. - name: Pre master upgrade - Upgrade all storage
  33. hosts: oo_first_master
  34. roles:
  35. - openshift_facts
  36. tasks:
  37. - name: Upgrade all storage
  38. command: >
  39. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  40. migrate storage --include=* --confirm
  41. register: l_pb_upgrade_control_plane_pre_upgrade_storage
  42. when: openshift_upgrade_pre_storage_migration_enabled | default(true) | bool
  43. failed_when:
  44. - l_pb_upgrade_control_plane_pre_upgrade_storage.rc != 0
  45. - openshift_upgrade_pre_storage_migration_fatal | default(true) | bool
  46. # Set openshift_master_facts separately. In order to reconcile
  47. # admission_config's, we currently must run openshift_master_facts and
  48. # then run openshift_facts.
  49. - name: Set OpenShift master facts
  50. hosts: oo_masters_to_config
  51. roles:
  52. - openshift_master_facts
  53. - name: configure vsphere svc account
  54. hosts: oo_first_master
  55. tasks:
  56. - import_role:
  57. name: openshift_cloud_provider
  58. tasks_from: vsphere-svc
  59. when:
  60. - openshift_cloudprovider_kind is defined
  61. - openshift_cloudprovider_kind == 'vsphere'
  62. - openshift_version | version_compare('3.9', '>=')
  63. # The main master upgrade play. Should handle all changes to the system in one pass, with
  64. # support for optional hooks to be defined.
  65. - name: Upgrade master
  66. hosts: oo_masters_to_config
  67. serial: 1
  68. roles:
  69. - openshift_facts
  70. tasks:
  71. # Run the pre-upgrade hook if defined:
  72. - debug: msg="Running master pre-upgrade hook {{ openshift_master_upgrade_pre_hook }}"
  73. when: openshift_master_upgrade_pre_hook is defined
  74. - include_tasks: "{{ openshift_master_upgrade_pre_hook }}"
  75. when: openshift_master_upgrade_pre_hook is defined
  76. - import_role:
  77. name: openshift_control_plane
  78. tasks_from: upgrade
  79. - name: update vsphere provider master config
  80. import_role:
  81. name: openshift_control_plane
  82. tasks_from: update-vsphere
  83. when:
  84. - openshift_cloudprovider_kind is defined
  85. - openshift_cloudprovider_kind == 'vsphere'
  86. - openshift_version | version_compare('3.9', '>=')
  87. # Run the upgrade hook prior to restarting services/system if defined:
  88. - debug: msg="Running master upgrade hook {{ openshift_master_upgrade_hook }}"
  89. when: openshift_master_upgrade_hook is defined
  90. - include_tasks: "{{ openshift_master_upgrade_hook }}"
  91. when: openshift_master_upgrade_hook is defined
  92. - name: Lay down the static configuration
  93. import_role:
  94. name: openshift_control_plane
  95. tasks_from: static.yml
  96. - import_tasks: tasks/restart_hosts.yml
  97. when: openshift_rolling_restart_mode | default('services') == 'system'
  98. - import_tasks: tasks/restart_services.yml
  99. when: openshift_rolling_restart_mode | default('services') == 'services'
  100. # Run the post-upgrade hook if defined:
  101. - debug: msg="Running master post-upgrade hook {{ openshift_master_upgrade_post_hook }}"
  102. when: openshift_master_upgrade_post_hook is defined
  103. - include_tasks: "{{ openshift_master_upgrade_post_hook }}"
  104. when: openshift_master_upgrade_post_hook is defined
  105. - name: Post master upgrade - Upgrade clusterpolicies storage
  106. command: >
  107. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  108. migrate storage --include=clusterpolicies --confirm
  109. register: l_pb_upgrade_control_plane_post_upgrade_storage
  110. when:
  111. - openshift_upgrade_post_storage_migration_enabled | default(true) | bool
  112. - openshift_version is version_compare('3.7','<')
  113. failed_when:
  114. - l_pb_upgrade_control_plane_post_upgrade_storage.rc != 0
  115. - openshift_upgrade_post_storage_migration_fatal | default(false) | bool
  116. run_once: true
  117. delegate_to: "{{ groups.oo_first_master.0 }}"
  118. - set_fact:
  119. master_update_complete: True
  120. ##############################################################################
  121. # Gate on master update complete
  122. ##############################################################################
  123. - name: Gate on master update
  124. hosts: localhost
  125. connection: local
  126. tasks:
  127. - set_fact:
  128. master_update_completed: "{{ hostvars
  129. | lib_utils_oo_select_keys(groups.oo_masters_to_config)
  130. | lib_utils_oo_collect('inventory_hostname', {'master_update_complete': true}) }}"
  131. - set_fact:
  132. master_update_failed: "{{ groups.oo_masters_to_config | difference(master_update_completed) | list }}"
  133. - fail:
  134. msg: "Upgrade cannot continue. The following masters did not finish updating: {{ master_update_failed | join(',') }}"
  135. when: master_update_failed | length > 0
  136. ###############################################################################
  137. # Reconcile Cluster Roles, Cluster Role Bindings and Security Context Constraints
  138. ###############################################################################
  139. - name: Reconcile Cluster Roles and Cluster Role Bindings and Security Context Constraints
  140. hosts: oo_masters_to_config
  141. roles:
  142. - { role: openshift_cli }
  143. - { role: openshift_facts }
  144. vars:
  145. __master_shared_resource_viewer_file: "shared_resource_viewer_role.yaml"
  146. tasks:
  147. - name: Reconcile Cluster Roles
  148. command: >
  149. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  150. policy reconcile-cluster-roles --additive-only=true --confirm -o name
  151. register: reconcile_cluster_role_result
  152. when: openshift_version is version_compare('3.7','<')
  153. changed_when:
  154. - reconcile_cluster_role_result.stdout != ''
  155. - reconcile_cluster_role_result.rc == 0
  156. run_once: true
  157. - name: Reconcile Cluster Role Bindings
  158. command: >
  159. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  160. policy reconcile-cluster-role-bindings
  161. --exclude-groups=system:authenticated
  162. --exclude-groups=system:authenticated:oauth
  163. --exclude-groups=system:unauthenticated
  164. --exclude-users=system:anonymous
  165. --additive-only=true --confirm -o name
  166. when: openshift_version is version_compare('3.7','<')
  167. register: reconcile_bindings_result
  168. changed_when:
  169. - reconcile_bindings_result.stdout != ''
  170. - reconcile_bindings_result.rc == 0
  171. run_once: true
  172. - name: Reconcile Jenkins Pipeline Role Bindings
  173. command: >
  174. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig policy reconcile-cluster-role-bindings system:build-strategy-jenkinspipeline --confirm -o name
  175. run_once: true
  176. register: reconcile_jenkins_role_binding_result
  177. changed_when:
  178. - reconcile_jenkins_role_binding_result.stdout != ''
  179. - reconcile_jenkins_role_binding_result.rc == 0
  180. when:
  181. - openshift_version is version_compare('3.7','<')
  182. - when: openshift_upgrade_target is version_compare('3.7','<')
  183. block:
  184. - name: Retrieve shared-resource-viewer
  185. oc_obj:
  186. state: list
  187. kind: role
  188. name: "shared-resource-viewer"
  189. namespace: "openshift"
  190. register: objout
  191. - name: Determine if shared-resource-viewer is protected
  192. set_fact:
  193. __shared_resource_viewer_protected: true
  194. when:
  195. - "'results' in objout"
  196. - "'results' in objout['results']"
  197. - "'annotations' in objout['results']['results'][0]['metadata']"
  198. - "'openshift.io/reconcile-protect' in objout['results']['results'][0]['metadata']['annotations']"
  199. - "objout['results']['results'][0]['metadata']['annotations']['openshift.io/reconcile-protect'] == 'true'"
  200. - copy:
  201. src: "{{ item }}"
  202. dest: "/tmp/{{ item }}"
  203. with_items:
  204. - "{{ __master_shared_resource_viewer_file }}"
  205. when: __shared_resource_viewer_protected is not defined
  206. - name: Fixup shared-resource-viewer role
  207. oc_obj:
  208. state: present
  209. kind: role
  210. name: "shared-resource-viewer"
  211. namespace: "openshift"
  212. files:
  213. - "/tmp/{{ __master_shared_resource_viewer_file }}"
  214. delete_after: true
  215. when: __shared_resource_viewer_protected is not defined
  216. register: result
  217. retries: 3
  218. delay: 5
  219. until: result.rc == 0
  220. ignore_errors: true
  221. - name: Reconcile Security Context Constraints
  222. command: >
  223. {{ openshift_client_binary }} adm policy --config={{ openshift.common.config_base }}/master/admin.kubeconfig reconcile-sccs --confirm --additive-only=true -o name
  224. register: reconcile_scc_result
  225. changed_when:
  226. - reconcile_scc_result.stdout != ''
  227. - reconcile_scc_result.rc == 0
  228. run_once: true
  229. - name: Migrate storage post policy reconciliation
  230. command: >
  231. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  232. migrate storage --include=* --confirm
  233. run_once: true
  234. register: l_pb_upgrade_control_plane_post_upgrade_storage
  235. when: openshift_upgrade_post_storage_migration_enabled | default(true) | bool
  236. failed_when:
  237. - l_pb_upgrade_control_plane_post_upgrade_storage.rc != 0
  238. - openshift_upgrade_post_storage_migration_fatal | default(false) | bool
  239. - set_fact:
  240. reconcile_complete: True
  241. ##############################################################################
  242. # Gate on reconcile
  243. ##############################################################################
  244. - name: Gate on reconcile
  245. hosts: localhost
  246. connection: local
  247. tasks:
  248. - set_fact:
  249. reconcile_completed: "{{ hostvars
  250. | lib_utils_oo_select_keys(groups.oo_masters_to_config)
  251. | lib_utils_oo_collect('inventory_hostname', {'reconcile_complete': true}) }}"
  252. - set_fact:
  253. reconcile_failed: "{{ groups.oo_masters_to_config | difference(reconcile_completed) | list }}"
  254. - fail:
  255. msg: "Upgrade cannot continue. The following masters did not finish reconciling: {{ reconcile_failed | join(',') }}"
  256. when: reconcile_failed | length > 0
  257. - name: Drain and upgrade master nodes
  258. # There is no need to update nodes in the middle of double upgrade
  259. # This would skip node update to 3.8 during 3.7->3.9 upgrade
  260. hosts: "{{ l_double_upgrade_cp | default(False) | ternary('all:!all', 'oo_masters_to_config:&oo_nodes_to_upgrade') }}"
  261. # This var must be set with -e on invocation, as it is not a per-host inventory var
  262. # and is evaluated early. Values such as "20%" can also be used.
  263. serial: "{{ openshift_upgrade_control_plane_nodes_serial | default(1) }}"
  264. max_fail_percentage: "{{ openshift_upgrade_control_plane_nodes_max_fail_percentage | default(0) }}"
  265. pre_tasks:
  266. - name: Load lib_openshift modules
  267. import_role:
  268. name: lib_openshift
  269. roles:
  270. - openshift_facts
  271. post_tasks:
  272. - import_role:
  273. name: openshift_manage_node
  274. tasks_from: config.yml
  275. vars:
  276. openshift_master_host: "{{ groups.oo_first_master.0 }}"
  277. openshift_manage_node_is_master: true