package_docker.yml 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156
  1. ---
  2. - name: Get current installed Docker version
  3. command: "{{ repoquery_cmd }} --installed --qf '%{version}' docker"
  4. when: not openshift.common.is_atomic | bool
  5. register: curr_docker_version
  6. retries: 4
  7. until: curr_docker_version | succeeded
  8. changed_when: false
  9. - name: Error out if Docker pre-installed but too old
  10. fail:
  11. msg: "Docker {{ curr_docker_version.stdout }} is installed, but >= 1.9.1 is required."
  12. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and curr_docker_version.stdout | version_compare('1.9.1', '<') and not docker_version is defined
  13. - name: Error out if requested Docker is too old
  14. fail:
  15. msg: "Docker {{ docker_version }} requested, but >= 1.9.1 is required."
  16. when: docker_version is defined and docker_version | version_compare('1.9.1', '<')
  17. # If a docker_version was requested, sanity check that we can install or upgrade to it, and
  18. # no downgrade is required.
  19. - name: Fail if Docker version requested but downgrade is required
  20. fail:
  21. msg: "Docker {{ curr_docker_version.stdout }} is installed, but version {{ docker_version }} was requested."
  22. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and docker_version is defined and curr_docker_version.stdout | version_compare(docker_version, '>')
  23. # This involves an extremely slow migration process, users should instead run the
  24. # Docker 1.10 upgrade playbook to accomplish this.
  25. - name: Error out if attempting to upgrade Docker across the 1.10 boundary
  26. fail:
  27. msg: "Cannot upgrade Docker to >= 1.10, please upgrade or remove Docker manually, or use the Docker upgrade playbook if OpenShift is already installed."
  28. when: not curr_docker_version | skipped and curr_docker_version.stdout != '' and curr_docker_version.stdout | version_compare('1.10', '<') and docker_version is defined and docker_version | version_compare('1.10', '>=')
  29. # Make sure Docker is installed, but does not update a running version.
  30. # Docker upgrades are handled by a separate playbook.
  31. - name: Install Docker
  32. package: name=docker{{ '-' + docker_version if docker_version is defined else '' }} state=present
  33. when: not openshift.common.is_atomic | bool
  34. - block:
  35. # Extend the default Docker service unit file when using iptables-services
  36. - name: Ensure docker.service.d directory exists
  37. file:
  38. path: "{{ docker_systemd_dir }}"
  39. state: directory
  40. - name: Configure Docker service unit file
  41. template:
  42. dest: "{{ docker_systemd_dir }}/custom.conf"
  43. src: custom.conf.j2
  44. when: not os_firewall_use_firewalld | default(False) | bool
  45. - name: Add enterprise registry, if necessary
  46. set_fact:
  47. l2_docker_additional_registries: "{{ l2_docker_additional_registries + [openshift_docker_ent_reg] }}"
  48. when:
  49. - openshift.common.deployment_type == 'openshift-enterprise'
  50. - openshift_docker_ent_reg != ''
  51. - openshift_docker_ent_reg not in l2_docker_additional_registries
  52. - stat: path=/etc/sysconfig/docker
  53. register: docker_check
  54. - name: Comment old registry params in /etc/sysconfig/docker
  55. lineinfile:
  56. dest: /etc/sysconfig/docker
  57. regexp: '^{{ item.reg_conf_var }}=.*$'
  58. line: "#{{ item.reg_conf_var }}=''# Moved to {{ containers_registries_conf_path }}"
  59. with_items:
  60. - reg_conf_var: ADD_REGISTRY
  61. - reg_conf_var: BLOCK_REGISTRY
  62. - reg_conf_var: INSECURE_REGISTRY
  63. notify:
  64. - restart docker
  65. - name: Place additional/blocked/insecure registies in /etc/containers/registries.conf
  66. template:
  67. dest: "{{ containers_registries_conf_path }}"
  68. src: registries.conf
  69. notify:
  70. - restart docker
  71. - name: Set Proxy Settings
  72. lineinfile:
  73. dest: /etc/sysconfig/docker
  74. regexp: '^{{ item.reg_conf_var }}=.*$'
  75. line: "{{ item.reg_conf_var }}='{{ item.reg_fact_val }}'"
  76. state: "{{ 'present' if item.reg_fact_val != '' else 'absent'}}"
  77. with_items:
  78. - reg_conf_var: HTTP_PROXY
  79. reg_fact_val: "{{ docker_http_proxy | default('') }}"
  80. - reg_conf_var: HTTPS_PROXY
  81. reg_fact_val: "{{ docker_https_proxy | default('') }}"
  82. - reg_conf_var: NO_PROXY
  83. reg_fact_val: "{{ docker_no_proxy | default('') }}"
  84. notify:
  85. - restart docker
  86. when:
  87. - docker_check.stat.isreg is defined and docker_check.stat.isreg and '"http_proxy" in openshift.common or "https_proxy" in openshift.common'
  88. - name: Set various Docker options
  89. lineinfile:
  90. dest: /etc/sysconfig/docker
  91. regexp: '^OPTIONS=.*$'
  92. line: "OPTIONS='\
  93. {% if ansible_selinux.status | default(None) == 'enabled' and docker_selinux_enabled | default(true) | bool %} --selinux-enabled {% endif %}\
  94. {% if docker_log_driver is defined %} --log-driver {{ docker_log_driver }}{% endif %}\
  95. {% if docker_log_options is defined %} {{ docker_log_options | oo_split() | oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %}\
  96. {% if docker_options is defined %} {{ docker_options }}{% endif %}\
  97. {% if docker_disable_push_dockerhub is defined %} --confirm-def-push={{ docker_disable_push_dockerhub | bool }}{% endif %}'"
  98. when: docker_check.stat.isreg is defined and docker_check.stat.isreg
  99. notify:
  100. - restart docker
  101. - stat: path=/etc/sysconfig/docker-network
  102. register: sysconfig_docker_network_check
  103. - name: Configure Docker Network OPTIONS
  104. lineinfile:
  105. dest: /etc/sysconfig/docker-network
  106. regexp: '^DOCKER_NETWORK_OPTIONS=.*$'
  107. line: "DOCKER_NETWORK_OPTIONS='\
  108. {% if openshift.node is defined and openshift.node.sdn_mtu is defined %} --mtu={{ openshift.node.sdn_mtu }}{% endif %}'"
  109. when:
  110. - sysconfig_docker_network_check.stat.isreg is defined
  111. - sysconfig_docker_network_check.stat.isreg
  112. notify:
  113. - restart docker
  114. - name: Check for credentials file for registry auth
  115. stat:
  116. path: "{{ docker_cli_auth_config_path }}/config.json"
  117. when: oreg_auth_user is defined
  118. register: docker_cli_auth_credentials_stat
  119. - name: Create credentials for docker cli registry auth
  120. command: "docker --config={{ docker_cli_auth_config_path }} login -u {{ oreg_auth_user }} -p {{ oreg_auth_password }} {{ oreg_host }}"
  121. when:
  122. - oreg_auth_user is defined
  123. - (not docker_cli_auth_credentials_stat.stat.exists or oreg_auth_credentials_replace) | bool
  124. - name: Start the Docker service
  125. systemd:
  126. name: docker
  127. enabled: yes
  128. state: started
  129. daemon_reload: yes
  130. register: r_docker_package_docker_start_result
  131. until: not r_docker_package_docker_start_result | failed
  132. retries: 3
  133. delay: 30
  134. - set_fact:
  135. docker_service_status_changed: "{{ r_docker_package_docker_start_result | changed }}"
  136. - meta: flush_handlers