openshift_hosted.yml 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166
  1. ---
  2. - name: Create persistent volumes
  3. hosts: oo_first_master
  4. tags:
  5. - hosted
  6. vars:
  7. persistent_volumes: "{{ hostvars[groups.oo_first_master.0] | oo_persistent_volumes(groups) }}"
  8. persistent_volume_claims: "{{ hostvars[groups.oo_first_master.0] | oo_persistent_volume_claims }}"
  9. roles:
  10. - role: openshift_persistent_volumes
  11. when: persistent_volumes | length > 0 or persistent_volume_claims | length > 0
  12. - name: Create Hosted Resources
  13. hosts: oo_first_master
  14. tags:
  15. - hosted
  16. pre_tasks:
  17. - set_fact:
  18. openshift_hosted_router_registryurl: "{{ hostvars[groups.oo_first_master.0].openshift.master.registry_url }}"
  19. openshift_hosted_registry_registryurl: "{{ hostvars[groups.oo_first_master.0].openshift.master.registry_url }}"
  20. when: "'master' in hostvars[groups.oo_first_master.0].openshift and 'registry_url' in hostvars[groups.oo_first_master.0].openshift.master"
  21. - set_fact:
  22. logging_hostname: "{{ openshift_hosted_logging_hostname | default('kibana.' ~ openshift_master_default_subdomain) }}"
  23. logging_ops_hostname: "{{ openshift_hosted_logging_ops_hostname | default('kibana-ops.' ~ openshift_master_default_subdomain) }}"
  24. logging_master_public_url: "{{ openshift_hosted_logging_master_public_url | default(openshift.master.public_api_url) }}"
  25. logging_elasticsearch_cluster_size: "{{ openshift_hosted_logging_elasticsearch_cluster_size | default(1) }}"
  26. logging_elasticsearch_ops_cluster_size: "{{ openshift_hosted_logging_elasticsearch_ops_cluster_size | default(1) }}"
  27. roles:
  28. - role: openshift_cli
  29. - role: openshift_hosted_facts
  30. - role: openshift_projects
  31. # TODO: Move standard project definitions to openshift_hosted/vars/main.yml
  32. # Vars are not accessible in meta/main.yml in ansible-1.9.x
  33. openshift_projects: "{{ openshift_additional_projects | default({}) | oo_merge_dicts({'default':{'default_node_selector':''},'openshift-infra':{'default_node_selector':''},'logging':{'default_node_selector':''}}) }}"
  34. - role: openshift_serviceaccounts
  35. openshift_serviceaccounts_names:
  36. - router
  37. openshift_serviceaccounts_namespace: default
  38. openshift_serviceaccounts_sccs:
  39. - hostnetwork
  40. when: openshift.common.version_gte_3_2_or_1_2
  41. - role: openshift_serviceaccounts
  42. openshift_serviceaccounts_names:
  43. - router
  44. - registry
  45. openshift_serviceaccounts_namespace: default
  46. openshift_serviceaccounts_sccs:
  47. - privileged
  48. when: not openshift.common.version_gte_3_2_or_1_2
  49. - role: openshift_hosted
  50. - role: openshift_metrics
  51. when: openshift.hosted.metrics.deploy | bool
  52. - role: openshift_hosted_logging
  53. when: openshift.hosted.logging.deploy | bool
  54. openshift_hosted_logging_hostname: "{{ logging_hostname }}"
  55. openshift_hosted_logging_ops_hostname: "{{ logging_ops_hostname }}"
  56. openshift_hosted_logging_master_public_url: "{{ logging_master_public_url }}"
  57. openshift_hosted_logging_elasticsearch_cluster_size: "{{ logging_elasticsearch_cluster_size }}"
  58. openshift_hosted_logging_elasticsearch_ops_cluster_size: "{{ logging_elasticsearch_ops_cluster_size }}"
  59. openshift_hosted_logging_elasticsearch_pvc_dynamic: "{{ 'true' if openshift.hosted.logging.storage_kind | default(none) == 'dynamic' else 'false' }}"
  60. openshift_hosted_logging_elasticsearch_pvc_size: "{{ openshift.hosted.logging.storage.volume.size if openshift.hosted.logging.storage_kind | default(none) == 'dynamic' else '' }}"
  61. openshift_hosted_logging_elasticsearch_pvc_prefix: "{{ 'logging-es' if openshift.hosted.logging.storage_kind | default(none) is not none else '' }}"
  62. - role: cockpit-ui
  63. when: openshift.common.deployment_subtype == 'registry'
  64. - name: Configure all masters for logging
  65. serial: 1
  66. handlers:
  67. - include: ../../../roles/openshift_master/handlers/main.yml
  68. static: yes
  69. hosts: oo_masters
  70. tasks:
  71. - openshift_facts:
  72. role: master
  73. local_facts:
  74. logging_public_url: "https://{{ openshift_hosted_logging_hostname | default('kibana.' ~ openshift_master_default_subdomain) }}"
  75. when: openshift.hosted.logging.deploy | default(openshift.common.version_gte_3_3_or_1_3)
  76. - modify_yaml:
  77. dest: "{{ openshift.common.config_base }}/master/master-config.yaml"
  78. yaml_key: assetConfig.loggingPublicURL
  79. yaml_value: "{{ openshift.master.logging_public_url }}"
  80. notify: restart master
  81. when: openshift.hosted.logging.deploy | default(openshift.common.version_gte_3_3_or_1_3)
  82. - name: Configure CA certificate for secure registry
  83. hosts: oo_nodes_to_config
  84. tags:
  85. - hosted
  86. tasks:
  87. - name: Create temp directory for kubeconfig
  88. command: mktemp -d /tmp/openshift-ansible-XXXXXX
  89. register: mktemp
  90. when: openshift.common.deployment_subtype == 'registry'
  91. changed_when: false
  92. delegate_to: "{{ groups.oo_first_master.0 }}"
  93. run_once: true
  94. - set_fact:
  95. openshift_hosted_kubeconfig: "{{ mktemp.stdout }}/admin.kubeconfig"
  96. when: openshift.common.deployment_subtype == 'registry'
  97. delegate_to: "{{ groups.oo_first_master.0 }}"
  98. run_once: true
  99. - name: Copy the admin client config(s)
  100. command: >
  101. cp {{ openshift.common.config_base }}/master/admin.kubeconfig {{ openshift_hosted_kubeconfig }}
  102. when: openshift.common.deployment_subtype == 'registry'
  103. changed_when: false
  104. delegate_to: "{{ groups.oo_first_master.0 }}"
  105. run_once: true
  106. - name: Retrieve docker-registry route
  107. command: >
  108. {{ openshift.common.client_binary }} get route docker-registry
  109. --template='{{ '{{' }} .spec.host {{ '}}' }}'
  110. --config={{ openshift_hosted_kubeconfig }}
  111. -n default
  112. register: docker_registry_route
  113. when: openshift.common.deployment_subtype == 'registry'
  114. changed_when: false
  115. delegate_to: "{{ groups.oo_first_master.0 }}"
  116. run_once: true
  117. - name: Retrieve registry service IP
  118. command: >
  119. {{ openshift.common.client_binary }} get service docker-registry
  120. --template='{{ '{{' }} .spec.clusterIP {{ '}}' }}'
  121. --config={{ openshift_hosted_kubeconfig }}
  122. -n default
  123. register: docker_registry_service_ip
  124. when: openshift.common.deployment_subtype == 'registry'
  125. changed_when: false
  126. delegate_to: "{{ groups.oo_first_master.0 }}"
  127. run_once: true
  128. - name: Create registry CA directories
  129. file:
  130. path: "/etc/docker/certs.d/{{ item }}"
  131. state: directory
  132. with_items:
  133. - "{{ docker_registry_service_ip.stdout }}:5000"
  134. - "{{ docker_registry_route.stdout }}"
  135. - "docker-registry.default.svc.cluster.local:5000"
  136. when: openshift.common.deployment_subtype == 'registry'
  137. - name: Copy CA to registry CA directories
  138. copy:
  139. src: "{{ openshift.common.config_base }}/node/ca.crt"
  140. dest: "/etc/docker/certs.d/{{ item }}"
  141. remote_src: yes
  142. force: yes
  143. with_items:
  144. - "{{ docker_registry_service_ip.stdout }}:5000"
  145. - "{{ docker_registry_route.stdout }}"
  146. - "docker-registry.default.svc.cluster.local:5000"
  147. when: openshift.common.deployment_subtype == 'registry'
  148. notify:
  149. - Restart docker
  150. - name: Delete temp directory
  151. file:
  152. name: "{{ mktemp.stdout }}"
  153. state: absent
  154. when: openshift.common.deployment_subtype == 'registry'
  155. changed_when: False
  156. delegate_to: "{{ groups.oo_first_master.0 }}"
  157. run_once: true
  158. handlers:
  159. - name: Restart docker
  160. service:
  161. name: docker
  162. state: restarted