install.yml 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476
  1. ---
  2. # Fact setting and validations
  3. - name: Set default image variables based on deployment type
  4. include_vars: "{{ item }}"
  5. with_first_found:
  6. - "{{ openshift_deployment_type }}.yml"
  7. - "default_images.yml"
  8. - name: set ansible_service_broker facts
  9. set_fact:
  10. ansible_service_broker_image_prefix: "{{ ansible_service_broker_image_prefix | default(__ansible_service_broker_image_prefix) }}"
  11. ansible_service_broker_image_tag: "{{ ansible_service_broker_image_tag | default(__ansible_service_broker_image_tag) }}"
  12. ansible_service_broker_etcd_image_prefix: "{{ ansible_service_broker_etcd_image_prefix | default(__ansible_service_broker_etcd_image_prefix) }}"
  13. ansible_service_broker_etcd_image_tag: "{{ ansible_service_broker_etcd_image_tag | default(__ansible_service_broker_etcd_image_tag) }}"
  14. ansible_service_broker_etcd_image_etcd_path: "{{ ansible_service_broker_etcd_image_etcd_path | default(__ansible_service_broker_etcd_image_etcd_path) }}"
  15. ansible_service_broker_registry_type: "{{ ansible_service_broker_registry_type | default(__ansible_service_broker_registry_type) }}"
  16. ansible_service_broker_registry_name: "{{ ansible_service_broker_registry_name | default(__ansible_service_broker_registry_name) }}"
  17. ansible_service_broker_registry_url: "{{ ansible_service_broker_registry_url | default(__ansible_service_broker_registry_url) }}"
  18. ansible_service_broker_registry_user: "{{ ansible_service_broker_registry_user | default(__ansible_service_broker_registry_user) }}"
  19. ansible_service_broker_registry_password: "{{ ansible_service_broker_registry_password | default(__ansible_service_broker_registry_password) }}"
  20. ansible_service_broker_registry_organization: "{{ ansible_service_broker_registry_organization | default(__ansible_service_broker_registry_organization) }}"
  21. ansible_service_broker_registry_tag: "{{ ansible_service_broker_registry_tag | default(__ansible_service_broker_registry_tag) }}"
  22. ansible_service_broker_registry_whitelist: "{{ ansible_service_broker_registry_whitelist | default(__ansible_service_broker_registry_whitelist) }}"
  23. - name: set ansible-service-broker image facts using set prefix and tag
  24. set_fact:
  25. ansible_service_broker_image: "{{ ansible_service_broker_image_prefix }}ansible-service-broker:{{ ansible_service_broker_image_tag }}"
  26. ansible_service_broker_etcd_image: "{{ ansible_service_broker_etcd_image_prefix }}etcd:{{ ansible_service_broker_etcd_image_tag }}"
  27. - include_tasks: validate_facts.yml
  28. - include_tasks: generate_certs.yml
  29. # Deployment of ansible-service-broker starts here
  30. - name: create openshift-ansible-service-broker project
  31. oc_project:
  32. name: openshift-ansible-service-broker
  33. state: present
  34. - name: create ansible-service-broker serviceaccount
  35. oc_serviceaccount:
  36. name: asb
  37. namespace: openshift-ansible-service-broker
  38. state: present
  39. - name: create ansible-service-broker client serviceaccount
  40. oc_serviceaccount:
  41. name: asb-client
  42. namespace: openshift-ansible-service-broker
  43. state: present
  44. - name: Create asb-auth cluster role
  45. oc_clusterrole:
  46. state: present
  47. name: asb-auth
  48. rules:
  49. - apiGroups: [""]
  50. resources: ["namespaces"]
  51. verbs: ["create", "delete"]
  52. - apiGroups: ["authorization.openshift.io"]
  53. resources: ["subjectrulesreview"]
  54. verbs: ["create"]
  55. - apiGroups: ["authorization.k8s.io"]
  56. resources: ["subjectaccessreviews"]
  57. verbs: ["create"]
  58. - apiGroups: ["authentication.k8s.io"]
  59. resources: ["tokenreviews"]
  60. verbs: ["create"]
  61. - apiGroups: ["image.openshift.io", ""]
  62. resources: ["images"]
  63. verbs: ["get", "list"]
  64. - apiGroups: ["network.openshift.io"]
  65. resources: ["clusternetworks", "netnamespaces"]
  66. verbs: ["get"]
  67. - apiGroups: ["network.openshift.io"]
  68. resources: ["netnamespaces"]
  69. verbs: ["update"]
  70. - apiGroups: ["networking.k8s.io"]
  71. resources: ["networkpolicies"]
  72. verbs: ["create", "delete"]
  73. - name: Create asb-access cluster role
  74. oc_clusterrole:
  75. state: present
  76. name: asb-access
  77. rules:
  78. - nonResourceURLs: ["/ansible-service-broker", "/ansible-service-broker/*"]
  79. verbs: ["get", "post", "put", "patch", "delete"]
  80. - name: Bind admin cluster-role to asb serviceaccount
  81. oc_adm_policy_user:
  82. state: present
  83. resource_kind: cluster-role
  84. resource_name: admin
  85. user: "system:serviceaccount:openshift-ansible-service-broker:asb"
  86. - name: Bind auth cluster role to asb service account
  87. oc_adm_policy_user:
  88. state: present
  89. resource_kind: cluster-role
  90. resource_name: asb-auth
  91. user: "system:serviceaccount:openshift-ansible-service-broker:asb"
  92. - name: Bind asb-access role to asb-client service account
  93. oc_adm_policy_user:
  94. state: present
  95. resource_kind: cluster-role
  96. resource_name: asb-access
  97. user: "system:serviceaccount:openshift-ansible-service-broker:asb-client"
  98. - name: create asb-client token secret
  99. oc_obj:
  100. name: asb-client
  101. namespace: openshift-ansible-service-broker
  102. state: present
  103. kind: Secret
  104. content:
  105. path: /tmp/asbclientsecretout
  106. data:
  107. apiVersion: v1
  108. kind: Secret
  109. metadata:
  110. name: asb-client
  111. namespace: openshift-ansible-service-broker
  112. annotations:
  113. kubernetes.io/service-account.name: asb-client
  114. type: kubernetes.io/service-account-token
  115. - name: Create etcd-auth secret
  116. oc_secret:
  117. name: etcd-auth-secret
  118. namespace: openshift-ansible-service-broker
  119. contents:
  120. - path: ca.crt
  121. data: '{{ etcd_ca_cert }}'
  122. - name: Create broker-etcd-auth secret
  123. oc_secret:
  124. name: broker-etcd-auth-secret
  125. namespace: openshift-ansible-service-broker
  126. contents:
  127. - path: client.crt
  128. data: '{{ etcd_client_cert }}'
  129. - path: client.key
  130. data: '{{ etcd_client_key }}'
  131. - oc_secret:
  132. state: list
  133. namespace: openshift-ansible-service-broker
  134. name: asb-client
  135. register: asb_client_secret
  136. - set_fact:
  137. service_ca_crt: "{{ asb_client_secret.results.results.0.data['service-ca.crt'] }}"
  138. - name: create ansible-service-broker service
  139. oc_service:
  140. name: asb
  141. namespace: openshift-ansible-service-broker
  142. labels:
  143. app: openshift-ansible-service-broker
  144. service: asb
  145. annotations:
  146. service.alpha.openshift.io/serving-cert-secret-name: asb-tls
  147. ports:
  148. - name: port-1338
  149. port: 1338
  150. targetPort: 1338
  151. protocol: TCP
  152. selector:
  153. app: openshift-ansible-service-broker
  154. service: asb
  155. - name: create asb-etcd service
  156. oc_service:
  157. name: asb-etcd
  158. namespace: openshift-ansible-service-broker
  159. labels:
  160. app: etcd
  161. service: asb-etcd
  162. annotations:
  163. service.alpha.openshift.io/serving-cert-secret-name: etcd-tls
  164. ports:
  165. - name: port-2379
  166. port: 2379
  167. targetPort: 2379
  168. protocol: TCP
  169. selector:
  170. app: etcd
  171. service: asb-etcd
  172. - name: create route for ansible-service-broker service
  173. oc_route:
  174. name: asb-1338
  175. namespace: openshift-ansible-service-broker
  176. state: present
  177. labels:
  178. app: openshift-ansible-service-broker
  179. service: asb
  180. service_name: asb
  181. port: 1338
  182. tls_termination: Reencrypt
  183. - name: create persistent volume claim for etcd
  184. oc_pvc:
  185. name: etcd
  186. namespace: openshift-ansible-service-broker
  187. access_modes:
  188. - ReadWriteOnce
  189. volume_capacity: 1G
  190. - name: Set Ansible Service Broker deployment config
  191. oc_obj:
  192. force: yes
  193. name: asb
  194. namespace: openshift-ansible-service-broker
  195. state: present
  196. kind: DeploymentConfig
  197. content:
  198. path: /tmp/dcout
  199. data:
  200. apiVersion: v1
  201. kind: DeploymentConfig
  202. metadata:
  203. name: asb
  204. labels:
  205. app: openshift-ansible-service-broker
  206. service: asb
  207. spec:
  208. replicas: 1
  209. selector:
  210. app: openshift-ansible-service-broker
  211. strategy:
  212. type: Rolling
  213. template:
  214. metadata:
  215. labels:
  216. app: openshift-ansible-service-broker
  217. service: asb
  218. spec:
  219. serviceAccount: asb
  220. containers:
  221. - image: "{{ ansible_service_broker_image }}"
  222. name: asb
  223. imagePullPolicy: IfNotPresent
  224. volumeMounts:
  225. - name: config-volume
  226. mountPath: /etc/ansible-service-broker
  227. - name: asb-tls
  228. mountPath: /etc/tls/private
  229. - name: asb-etcd-auth
  230. mountPath: /var/run/asb-etcd-auth
  231. ports:
  232. - containerPort: 1338
  233. protocol: TCP
  234. env:
  235. - name: BROKER_CONFIG
  236. value: /etc/ansible-service-broker/config.yaml
  237. - name: HTTP_PROXY
  238. value: "{{ openshift.common.http_proxy | default('') }}"
  239. - name: HTTPS_PROXY
  240. value: "{{ openshift.common.https_proxy | default('') }}"
  241. - name: NO_PROXY
  242. value: "{{ ([openshift.common.no_proxy, '.default'] | join(',')) if openshift.get('common', {}).get('no_proxy') else '' }}"
  243. resources: {}
  244. terminationMessagePath: /tmp/termination-log
  245. readinessProbe:
  246. httpGet:
  247. port: 1338
  248. path: /healthz
  249. scheme: HTTPS
  250. initialDelaySeconds: 15
  251. timeoutSeconds: 1
  252. livenessProbe:
  253. httpGet:
  254. port: 1338
  255. path: /healthz
  256. scheme: HTTPS
  257. initialDelaySeconds: 15
  258. timeoutSeconds: 1
  259. volumes:
  260. - name: config-volume
  261. configMap:
  262. name: broker-config
  263. items:
  264. - key: broker-config
  265. path: config.yaml
  266. - name: asb-tls
  267. secret:
  268. secretName: asb-tls
  269. - name: asb-etcd-auth
  270. secret:
  271. secretName: broker-etcd-auth-secret
  272. - name: Search for existing Ansible Service Broker etcd deployment config
  273. oc_obj:
  274. name: asb-etcd
  275. namespace: openshift-ansible-service-broker
  276. kind: DeploymentConfig
  277. state: list
  278. register: asb_etcd_dc
  279. - name: Create asb-etcd deployment config
  280. when: asb_etcd_dc.results.results.0 | length == 0
  281. oc_obj:
  282. name: asb-etcd
  283. namespace: openshift-ansible-service-broker
  284. state: present
  285. kind: DeploymentConfig
  286. content:
  287. path: /tmp/dcout
  288. data:
  289. apiVersion: v1
  290. kind: DeploymentConfig
  291. metadata:
  292. name: asb-etcd
  293. labels:
  294. app: etcd
  295. service: asb-etcd
  296. spec:
  297. replicas: 1
  298. selector:
  299. app: etcd
  300. strategy:
  301. type: Rolling
  302. template:
  303. metadata:
  304. labels:
  305. app: etcd
  306. service: asb-etcd
  307. spec:
  308. serviceAccount: asb
  309. containers:
  310. - image: "{{ ansible_service_broker_etcd_image }}"
  311. name: etcd
  312. imagePullPolicy: IfNotPresent
  313. terminationMessagePath: /tmp/termination-log
  314. workingDir: /etcd
  315. args:
  316. - "{{ ansible_service_broker_etcd_image_etcd_path }}"
  317. - "--data-dir=/data"
  318. - "--listen-client-urls=https://0.0.0.0:2379"
  319. - "--advertise-client-urls=https://asb-etcd.openshift-ansible-service-broker.svc:2379"
  320. - "--client-cert-auth"
  321. - "--trusted-ca-file=/var/run/etcd-auth-secret/ca.crt"
  322. - "--cert-file=/etc/tls/private/tls.crt"
  323. - "--key-file=/etc/tls/private/tls.key"
  324. ports:
  325. - containerPort: 2379
  326. protocol: TCP
  327. env:
  328. - name: ETCDCTL_API
  329. value: "3"
  330. volumeMounts:
  331. - name: etcd
  332. mountPath: /data
  333. - name: etcd-tls
  334. mountPath: /etc/tls/private
  335. - name: etcd-auth
  336. mountPath: /var/run/etcd-auth-secret
  337. volumes:
  338. - name: etcd
  339. persistentVolumeClaim:
  340. claimName: etcd
  341. - name: etcd-tls
  342. secret:
  343. secretName: etcd-tls
  344. - name: etcd-auth
  345. secret:
  346. secretName: etcd-auth-secret
  347. - name: set auth name and type facts if needed
  348. set_fact:
  349. ansible_service_broker_registry_auth_type: "secret"
  350. ansible_service_broker_registry_auth_name: "asb-registry-auth"
  351. when: ansible_service_broker_registry_user != "" and ansible_service_broker_registry_password != ""
  352. # TODO: saw a oc_configmap in the library, but didn't understand how to get it to do the following:
  353. - name: Create config map for ansible-service-broker
  354. oc_obj:
  355. name: broker-config
  356. namespace: openshift-ansible-service-broker
  357. state: present
  358. kind: ConfigMap
  359. content:
  360. path: /tmp/cmout
  361. data:
  362. apiVersion: v1
  363. kind: ConfigMap
  364. metadata:
  365. name: broker-config
  366. namespace: openshift-ansible-service-broker
  367. labels:
  368. app: openshift-ansible-service-broker
  369. data:
  370. broker-config: |
  371. registry:
  372. - type: {{ ansible_service_broker_registry_type }}
  373. name: {{ ansible_service_broker_registry_name }}
  374. url: {{ ansible_service_broker_registry_url }}
  375. org: {{ ansible_service_broker_registry_organization }}
  376. tag: {{ ansible_service_broker_registry_tag }}
  377. white_list: {{ ansible_service_broker_registry_whitelist | to_yaml }}
  378. auth_type: "{{ ansible_service_broker_registry_auth_type | default("") }}"
  379. auth_name: "{{ ansible_service_broker_registry_auth_name | default("") }}"
  380. - type: local_openshift
  381. name: localregistry
  382. namespaces: ['openshift']
  383. white_list: {{ ansible_service_broker_local_registry_whitelist | to_yaml }}
  384. dao:
  385. etcd_host: asb-etcd.openshift-ansible-service-broker.svc
  386. etcd_port: 2379
  387. etcd_ca_file: /var/run/secrets/kubernetes.io/serviceaccount/service-ca.crt
  388. etcd_client_cert: /var/run/asb-etcd-auth/client.crt
  389. etcd_client_key: /var/run/asb-etcd-auth/client.key
  390. log:
  391. stdout: true
  392. level: {{ ansible_service_broker_log_level }}
  393. color: true
  394. openshift:
  395. host: ""
  396. ca_file: ""
  397. bearer_token_file: ""
  398. sandbox_role: {{ ansible_service_broker_sandbox_role }}
  399. image_pull_policy: {{ ansible_service_broker_image_pull_policy }}
  400. keep_namespace: {{ ansible_service_broker_keep_namespace | bool | lower }}
  401. keep_namespace_on_error: {{ ansible_service_broker_keep_namespace_on_error | bool | lower }}
  402. broker:
  403. dev_broker: {{ ansible_service_broker_dev_broker | bool | lower }}
  404. bootstrap_on_startup: {{ ansible_service_broker_bootstrap_on_startup | bool | lower }}
  405. refresh_interval: {{ ansible_service_broker_refresh_interval }}
  406. launch_apb_on_bind: {{ ansible_service_broker_launch_apb_on_bind | bool | lower }}
  407. output_request: {{ ansible_service_broker_output_request | bool | lower }}
  408. recovery: {{ ansible_service_broker_recovery | bool | lower }}
  409. ssl_cert_key: /etc/tls/private/tls.key
  410. ssl_cert: /etc/tls/private/tls.crt
  411. auto_escalate: {{ ansible_service_broker_auto_escalate }}
  412. auth:
  413. - type: basic
  414. enabled: false
  415. - oc_secret:
  416. name: asb-registry-auth
  417. namespace: openshift-ansible-service-broker
  418. state: present
  419. contents:
  420. - path: username
  421. data: "{{ ansible_service_broker_registry_user }}"
  422. - path: password
  423. data: "{{ ansible_service_broker_registry_password }}"
  424. when: ansible_service_broker_registry_user != "" and ansible_service_broker_registry_password != ""
  425. - name: Create the Broker resource in the catalog
  426. oc_obj:
  427. name: ansible-service-broker
  428. state: present
  429. kind: ClusterServiceBroker
  430. content:
  431. path: /tmp/brokerout
  432. data:
  433. apiVersion: servicecatalog.k8s.io/v1beta1
  434. kind: ClusterServiceBroker
  435. metadata:
  436. name: ansible-service-broker
  437. spec:
  438. url: https://asb.openshift-ansible-service-broker.svc:1338/ansible-service-broker
  439. authInfo:
  440. bearer:
  441. secretRef:
  442. name: asb-client
  443. namespace: openshift-ansible-service-broker
  444. kind: Secret
  445. caBundle: "{{ service_ca_crt }}"