main.yml 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132
  1. ---
  2. # openshift_master_defaults_in_use is a workaround to detect if we are consuming
  3. # the plays from the role or outside of the role.
  4. openshift_master_defaults_in_use: True
  5. openshift_master_debug_level: "{{ debug_level | default(2) }}"
  6. r_openshift_master_firewall_enabled: "{{ os_firewall_enabled | default(True) }}"
  7. r_openshift_master_use_firewalld: "{{ os_firewall_use_firewalld | default(False) }}"
  8. system_images_registry_dict:
  9. openshift-enterprise: "registry.access.redhat.com"
  10. origin: "docker.io"
  11. system_images_registry: "{{ system_images_registry_dict[openshift_deployment_type | default('origin')] }}"
  12. l_is_master_system_container: "{{ (openshift_use_master_system_container | default(openshift_use_system_containers | default(false)) | bool) }}"
  13. openshift_master_dns_port: 8053
  14. osm_default_node_selector: ''
  15. osm_project_request_template: ''
  16. osm_mcs_allocator_range: 's0:/2'
  17. osm_mcs_labels_per_project: 5
  18. osm_uid_allocator_range: '1000000000-1999999999/10000'
  19. osm_project_request_message: ''
  20. openshift_node_ips: []
  21. r_openshift_master_clean_install: false
  22. r_openshift_master_etcd3_storage: false
  23. r_openshift_master_os_firewall_enable: true
  24. r_openshift_master_os_firewall_deny: []
  25. default_r_openshift_master_os_firewall_allow:
  26. - service: api server https
  27. port: "{{ openshift.master.api_port }}/tcp"
  28. - service: api controllers https
  29. port: "{{ openshift.master.controllers_port }}/tcp"
  30. - service: skydns tcp
  31. port: "{{ openshift_master_dns_port }}/tcp"
  32. - service: skydns udp
  33. port: "{{ openshift_master_dns_port }}/udp"
  34. - service: etcd embedded
  35. port: 4001/tcp
  36. cond: "{{ groups.oo_etcd_to_config | default([]) | length == 0 }}"
  37. r_openshift_master_os_firewall_allow: "{{ default_r_openshift_master_os_firewall_allow | union(openshift_master_open_ports | default([])) }}"
  38. # oreg_url is defined by user input
  39. oreg_host: "{{ oreg_url.split('/')[0] if (oreg_url is defined and '.' in oreg_url.split('/')[0]) else '' }}"
  40. oreg_auth_credentials_path: "{{ r_openshift_master_data_dir }}/.docker"
  41. oreg_auth_credentials_replace: False
  42. l_bind_docker_reg_auth: False
  43. openshift_docker_alternative_creds: "{{ (openshift_docker_use_system_container | default(False)) or (openshift_use_crio_only | default(False)) }}"
  44. containerized_svc_dir: "/usr/lib/systemd/system"
  45. ha_svc_template_path: "native-cluster"
  46. openshift_docker_service_name: "{{ 'container-engine' if (openshift_docker_use_system_container | default(False)) else 'docker' }}"
  47. openshift_master_loopback_config: "{{ openshift_master_config_dir }}/openshift-master.kubeconfig"
  48. loopback_context_string: "current-context: {{ openshift.master.loopback_context_name }}"
  49. openshift_master_session_secrets_file: "{{ openshift_master_config_dir }}/session-secrets.yaml"
  50. openshift_master_policy: "{{ openshift_master_config_dir }}/policy.json"
  51. scheduler_config:
  52. kind: Policy
  53. apiVersion: v1
  54. predicates: "{{ openshift_master_scheduler_predicates
  55. | default(openshift_master_scheduler_current_predicates
  56. | default(openshift_master_scheduler_default_predicates)) }}"
  57. priorities: "{{ openshift_master_scheduler_priorities
  58. | default(openshift_master_scheduler_current_priorities
  59. | default(openshift_master_scheduler_default_priorities)) }}"
  60. openshift_master_valid_grant_methods:
  61. - auto
  62. - prompt
  63. - deny
  64. openshift_master_is_scaleup_host: False
  65. # These defaults assume forcing journald persistence, fsync to disk once
  66. # a second, rate-limiting to 10,000 logs a second, no forwarding to
  67. # syslog or wall, using 8GB of disk space maximum, using 10MB journal
  68. # files, keeping only a days worth of logs per journal file, and
  69. # retaining journal files no longer than a month.
  70. journald_vars_to_replace:
  71. - { var: Storage, val: persistent }
  72. - { var: Compress, val: yes }
  73. - { var: SyncIntervalSec, val: 1s }
  74. - { var: RateLimitInterval, val: 1s }
  75. - { var: RateLimitBurst, val: 10000 }
  76. - { var: SystemMaxUse, val: 8G }
  77. - { var: SystemKeepFree, val: 20% }
  78. - { var: SystemMaxFileSize, val: 10M }
  79. - { var: MaxRetentionSec, val: 1month }
  80. - { var: MaxFileSec, val: 1day }
  81. - { var: ForwardToSyslog, val: no }
  82. - { var: ForwardToWall, val: no }
  83. # NOTE
  84. # r_openshift_master_*_default may be defined external to this role.
  85. # openshift_use_*, if defined, may affect other roles or play behavior.
  86. r_openshift_master_use_openshift_sdn_default: "{{ openshift_use_openshift_sdn | default(True) }}"
  87. r_openshift_master_use_openshift_sdn: "{{ r_openshift_master_use_openshift_sdn_default }}"
  88. r_openshift_master_use_nuage_default: "{{ openshift_use_nuage | default(False) }}"
  89. r_openshift_master_use_nuage: "{{ r_openshift_master_use_nuage_default }}"
  90. r_openshift_master_use_contiv_default: "{{ openshift_use_contiv | default(False) }}"
  91. r_openshift_master_use_contiv: "{{ r_openshift_master_use_contiv_default }}"
  92. r_openshift_master_use_kuryr_default: "{{ openshift_use_kuryr | default(False) }}"
  93. r_openshift_master_use_kuryr: "{{ r_openshift_master_use_kuryr_default }}"
  94. r_openshift_master_data_dir_default: "{{ openshift_data_dir | default('/var/lib/origin') }}"
  95. r_openshift_master_data_dir: "{{ r_openshift_master_data_dir_default }}"
  96. r_openshift_master_sdn_network_plugin_name_default: "{{ os_sdn_network_plugin_name | default('redhat/openshift-ovs-subnet') }}"
  97. r_openshift_master_sdn_network_plugin_name: "{{ r_openshift_master_sdn_network_plugin_name_default }}"
  98. openshift_master_image_config_latest_default: "{{ openshift_image_config_latest | default(False) }}"
  99. openshift_master_image_config_latest: "{{ openshift_master_image_config_latest_default }}"
  100. openshift_master_config_dir_default: "{{ openshift.common.config_base ~ '/master' if openshift is defined and 'common' in openshift else '/etc/origin/master' }}"
  101. openshift_master_config_dir: "{{ openshift_master_config_dir_default }}"
  102. openshift_master_bootstrap_enabled: False
  103. openshift_master_csr_sa: node-bootstrapper
  104. openshift_master_csr_namespace: openshift-infra
  105. openshift_master_config_file: "{{ openshift_master_config_dir }}/master-config.yaml"
  106. openshift_master_scheduler_conf: "{{ openshift_master_config_dir }}/scheduler.json"