install.yml 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462
  1. ---
  2. # Fact setting and validations
  3. - name: Set default image variables based on deployment type
  4. include_vars: "{{ item }}"
  5. with_first_found:
  6. - "{{ openshift_deployment_type }}.yml"
  7. - "default_images.yml"
  8. - name: set ansible_service_broker facts
  9. set_fact:
  10. ansible_service_broker_image_prefix: "{{ ansible_service_broker_image_prefix | default(__ansible_service_broker_image_prefix) }}"
  11. ansible_service_broker_image_tag: "{{ ansible_service_broker_image_tag | default(__ansible_service_broker_image_tag) }}"
  12. ansible_service_broker_etcd_image_prefix: "{{ ansible_service_broker_etcd_image_prefix | default(__ansible_service_broker_etcd_image_prefix) }}"
  13. ansible_service_broker_etcd_image_tag: "{{ ansible_service_broker_etcd_image_tag | default(__ansible_service_broker_etcd_image_tag) }}"
  14. ansible_service_broker_etcd_image_etcd_path: "{{ ansible_service_broker_etcd_image_etcd_path | default(__ansible_service_broker_etcd_image_etcd_path) }}"
  15. ansible_service_broker_registry_type: "{{ ansible_service_broker_registry_type | default(__ansible_service_broker_registry_type) }}"
  16. ansible_service_broker_registry_name: "{{ ansible_service_broker_registry_name | default(__ansible_service_broker_registry_name) }}"
  17. ansible_service_broker_registry_url: "{{ ansible_service_broker_registry_url | default(__ansible_service_broker_registry_url) }}"
  18. ansible_service_broker_registry_user: "{{ ansible_service_broker_registry_user | default(__ansible_service_broker_registry_user) }}"
  19. ansible_service_broker_registry_password: "{{ ansible_service_broker_registry_password | default(__ansible_service_broker_registry_password) }}"
  20. ansible_service_broker_registry_organization: "{{ ansible_service_broker_registry_organization | default(__ansible_service_broker_registry_organization) }}"
  21. ansible_service_broker_registry_tag: "{{ ansible_service_broker_registry_tag | default(__ansible_service_broker_registry_tag) }}"
  22. ansible_service_broker_registry_whitelist: "{{ ansible_service_broker_registry_whitelist | default(__ansible_service_broker_registry_whitelist) }}"
  23. - name: set ansible-service-broker image facts using set prefix and tag
  24. set_fact:
  25. ansible_service_broker_image: "{{ ansible_service_broker_image_prefix }}ansible-service-broker:{{ ansible_service_broker_image_tag }}"
  26. ansible_service_broker_etcd_image: "{{ ansible_service_broker_etcd_image_prefix }}etcd:{{ ansible_service_broker_etcd_image_tag }}"
  27. - include_tasks: validate_facts.yml
  28. - include_tasks: generate_certs.yml
  29. # Deployment of ansible-service-broker starts here
  30. - name: create openshift-ansible-service-broker project
  31. oc_project:
  32. name: openshift-ansible-service-broker
  33. state: present
  34. - name: create ansible-service-broker serviceaccount
  35. oc_serviceaccount:
  36. name: asb
  37. namespace: openshift-ansible-service-broker
  38. state: present
  39. - name: create ansible-service-broker client serviceaccount
  40. oc_serviceaccount:
  41. name: asb-client
  42. namespace: openshift-ansible-service-broker
  43. state: present
  44. - name: Create asb-auth cluster role
  45. oc_clusterrole:
  46. state: present
  47. name: asb-auth
  48. rules:
  49. - apiGroups: [""]
  50. resources: ["namespaces"]
  51. verbs: ["create", "delete"]
  52. - apiGroups: ["authorization.openshift.io"]
  53. resources: ["subjectrulesreview"]
  54. verbs: ["create"]
  55. - apiGroups: ["authorization.k8s.io"]
  56. resources: ["subjectaccessreviews"]
  57. verbs: ["create"]
  58. - apiGroups: ["authentication.k8s.io"]
  59. resources: ["tokenreviews"]
  60. verbs: ["create"]
  61. - apiGroups: ["image.openshift.io", ""]
  62. resources: ["images"]
  63. verbs: ["get", "list"]
  64. - name: Create asb-access cluster role
  65. oc_clusterrole:
  66. state: present
  67. name: asb-access
  68. rules:
  69. - nonResourceURLs: ["/ansible-service-broker", "/ansible-service-broker/*"]
  70. verbs: ["get", "post", "put", "patch", "delete"]
  71. - name: Bind admin cluster-role to asb serviceaccount
  72. oc_adm_policy_user:
  73. state: present
  74. resource_kind: cluster-role
  75. resource_name: admin
  76. user: "system:serviceaccount:openshift-ansible-service-broker:asb"
  77. - name: Bind auth cluster role to asb service account
  78. oc_adm_policy_user:
  79. state: present
  80. resource_kind: cluster-role
  81. resource_name: asb-auth
  82. user: "system:serviceaccount:openshift-ansible-service-broker:asb"
  83. - name: Bind asb-access role to asb-client service account
  84. oc_adm_policy_user:
  85. state: present
  86. resource_kind: cluster-role
  87. resource_name: asb-access
  88. user: "system:serviceaccount:openshift-ansible-service-broker:asb-client"
  89. - name: create asb-client token secret
  90. oc_obj:
  91. name: asb-client
  92. namespace: openshift-ansible-service-broker
  93. state: present
  94. kind: Secret
  95. content:
  96. path: /tmp/asbclientsecretout
  97. data:
  98. apiVersion: v1
  99. kind: Secret
  100. metadata:
  101. name: asb-client
  102. namespace: openshift-ansible-service-broker
  103. annotations:
  104. kubernetes.io/service-account.name: asb-client
  105. type: kubernetes.io/service-account-token
  106. - name: Create etcd-auth secret
  107. oc_secret:
  108. name: etcd-auth-secret
  109. namespace: openshift-ansible-service-broker
  110. contents:
  111. - path: ca.crt
  112. data: '{{ etcd_ca_cert }}'
  113. - name: Create broker-etcd-auth secret
  114. oc_secret:
  115. name: broker-etcd-auth-secret
  116. namespace: openshift-ansible-service-broker
  117. contents:
  118. - path: client.crt
  119. data: '{{ etcd_client_cert }}'
  120. - path: client.key
  121. data: '{{ etcd_client_key }}'
  122. - oc_secret:
  123. state: list
  124. namespace: openshift-ansible-service-broker
  125. name: asb-client
  126. register: asb_client_secret
  127. - set_fact:
  128. service_ca_crt: "{{ asb_client_secret.results.results.0.data['service-ca.crt'] }}"
  129. - name: create ansible-service-broker service
  130. oc_service:
  131. name: asb
  132. namespace: openshift-ansible-service-broker
  133. labels:
  134. app: openshift-ansible-service-broker
  135. service: asb
  136. annotations:
  137. service.alpha.openshift.io/serving-cert-secret-name: asb-tls
  138. ports:
  139. - name: port-1338
  140. port: 1338
  141. targetPort: 1338
  142. protocol: TCP
  143. selector:
  144. app: openshift-ansible-service-broker
  145. service: asb
  146. - name: create asb-etcd service
  147. oc_service:
  148. name: asb-etcd
  149. namespace: openshift-ansible-service-broker
  150. labels:
  151. app: etcd
  152. service: asb-etcd
  153. annotations:
  154. service.alpha.openshift.io/serving-cert-secret-name: etcd-tls
  155. ports:
  156. - name: port-2379
  157. port: 2379
  158. targetPort: 2379
  159. protocol: TCP
  160. selector:
  161. app: etcd
  162. service: asb-etcd
  163. - name: create route for ansible-service-broker service
  164. oc_route:
  165. name: asb-1338
  166. namespace: openshift-ansible-service-broker
  167. state: present
  168. labels:
  169. app: openshift-ansible-service-broker
  170. service: asb
  171. service_name: asb
  172. port: 1338
  173. tls_termination: Reencrypt
  174. - name: create persistent volume claim for etcd
  175. oc_pvc:
  176. name: etcd
  177. namespace: openshift-ansible-service-broker
  178. access_modes:
  179. - ReadWriteOnce
  180. volume_capacity: 1G
  181. - name: Search for existing Ansible Service Broker deployment config
  182. oc_obj:
  183. name: asb
  184. namespace: openshift-ansible-service-broker
  185. kind: DeploymentConfig
  186. state: list
  187. register: asb_dc
  188. - name: Create Ansible Service Broker deployment config
  189. when: asb_dc.results.results.0 | length == 0
  190. oc_obj:
  191. force: yes
  192. name: asb
  193. namespace: openshift-ansible-service-broker
  194. state: present
  195. kind: DeploymentConfig
  196. content:
  197. path: /tmp/dcout
  198. data:
  199. apiVersion: v1
  200. kind: DeploymentConfig
  201. metadata:
  202. name: asb
  203. labels:
  204. app: openshift-ansible-service-broker
  205. service: asb
  206. spec:
  207. replicas: 1
  208. selector:
  209. app: openshift-ansible-service-broker
  210. strategy:
  211. type: Rolling
  212. template:
  213. metadata:
  214. labels:
  215. app: openshift-ansible-service-broker
  216. service: asb
  217. spec:
  218. serviceAccount: asb
  219. containers:
  220. - image: "{{ ansible_service_broker_image }}"
  221. name: asb
  222. imagePullPolicy: IfNotPresent
  223. volumeMounts:
  224. - name: config-volume
  225. mountPath: /etc/ansible-service-broker
  226. - name: asb-tls
  227. mountPath: /etc/tls/private
  228. - name: asb-etcd-auth
  229. mountPath: /var/run/asb-etcd-auth
  230. ports:
  231. - containerPort: 1338
  232. protocol: TCP
  233. env:
  234. - name: BROKER_CONFIG
  235. value: /etc/ansible-service-broker/config.yaml
  236. resources: {}
  237. terminationMessagePath: /tmp/termination-log
  238. readinessProbe:
  239. httpGet:
  240. port: 1338
  241. path: /healthz
  242. scheme: HTTPS
  243. initialDelaySeconds: 15
  244. timeoutSeconds: 1
  245. livenessProbe:
  246. httpGet:
  247. port: 1338
  248. path: /healthz
  249. scheme: HTTPS
  250. initialDelaySeconds: 15
  251. timeoutSeconds: 1
  252. volumes:
  253. - name: config-volume
  254. configMap:
  255. name: broker-config
  256. items:
  257. - key: broker-config
  258. path: config.yaml
  259. - name: asb-tls
  260. secret:
  261. secretName: asb-tls
  262. - name: asb-etcd-auth
  263. secret:
  264. secretName: broker-etcd-auth-secret
  265. - name: Search for existing Ansible Service Broker etcd deployment config
  266. oc_obj:
  267. name: asb-etcd
  268. namespace: openshift-ansible-service-broker
  269. kind: DeploymentConfig
  270. state: list
  271. register: asb_etcd_dc
  272. - name: Create asb-etcd deployment config
  273. when: asb_etcd_dc.results.results.0 | length == 0
  274. oc_obj:
  275. name: asb-etcd
  276. namespace: openshift-ansible-service-broker
  277. state: present
  278. kind: DeploymentConfig
  279. content:
  280. path: /tmp/dcout
  281. data:
  282. apiVersion: v1
  283. kind: DeploymentConfig
  284. metadata:
  285. name: asb-etcd
  286. labels:
  287. app: etcd
  288. service: asb-etcd
  289. spec:
  290. replicas: 1
  291. selector:
  292. app: etcd
  293. strategy:
  294. type: Rolling
  295. template:
  296. metadata:
  297. labels:
  298. app: etcd
  299. service: asb-etcd
  300. spec:
  301. serviceAccount: asb
  302. containers:
  303. - image: "{{ ansible_service_broker_etcd_image }}"
  304. name: etcd
  305. imagePullPolicy: IfNotPresent
  306. terminationMessagePath: /tmp/termination-log
  307. workingDir: /etcd
  308. args:
  309. - "{{ ansible_service_broker_etcd_image_etcd_path }}"
  310. - "--data-dir=/data"
  311. - "--listen-client-urls=https://0.0.0.0:2379"
  312. - "--advertise-client-urls=https://asb-etcd.openshift-ansible-service-broker.svc:2379"
  313. - "--client-cert-auth"
  314. - "--trusted-ca-file=/var/run/etcd-auth-secret/ca.crt"
  315. - "--cert-file=/etc/tls/private/tls.crt"
  316. - "--key-file=/etc/tls/private/tls.key"
  317. ports:
  318. - containerPort: 2379
  319. protocol: TCP
  320. env:
  321. - name: ETCDCTL_API
  322. value: "3"
  323. volumeMounts:
  324. - name: etcd
  325. mountPath: /data
  326. - name: etcd-tls
  327. mountPath: /etc/tls/private
  328. - name: etcd-auth
  329. mountPath: /var/run/etcd-auth-secret
  330. volumes:
  331. - name: etcd
  332. persistentVolumeClaim:
  333. claimName: etcd
  334. - name: etcd-tls
  335. secret:
  336. secretName: etcd-tls
  337. - name: etcd-auth
  338. secret:
  339. secretName: etcd-auth-secret
  340. # TODO: saw a oc_configmap in the library, but didn't understand how to get it to do the following:
  341. - name: Create config map for ansible-service-broker
  342. oc_obj:
  343. name: broker-config
  344. namespace: openshift-ansible-service-broker
  345. state: present
  346. kind: ConfigMap
  347. content:
  348. path: /tmp/cmout
  349. data:
  350. apiVersion: v1
  351. kind: ConfigMap
  352. metadata:
  353. name: broker-config
  354. namespace: openshift-ansible-service-broker
  355. labels:
  356. app: openshift-ansible-service-broker
  357. data:
  358. broker-config: |
  359. registry:
  360. - type: {{ ansible_service_broker_registry_type }}
  361. name: {{ ansible_service_broker_registry_name }}
  362. url: {{ ansible_service_broker_registry_url }}
  363. org: {{ ansible_service_broker_registry_organization }}
  364. tag: {{ ansible_service_broker_registry_tag }}
  365. white_list: {{ ansible_service_broker_registry_whitelist | to_yaml }}
  366. - type: local_openshift
  367. name: localregistry
  368. namespaces: ['openshift']
  369. white_list: {{ ansible_service_broker_local_registry_whitelist | to_yaml }}
  370. dao:
  371. etcd_host: asb-etcd.openshift-ansible-service-broker.svc
  372. etcd_port: 2379
  373. etcd_ca_file: /var/run/secrets/kubernetes.io/serviceaccount/service-ca.crt
  374. etcd_client_cert: /var/run/asb-etcd-auth/client.crt
  375. etcd_client_key: /var/run/asb-etcd-auth/client.key
  376. log:
  377. stdout: true
  378. level: {{ ansible_service_broker_log_level }}
  379. color: true
  380. openshift:
  381. host: ""
  382. ca_file: ""
  383. bearer_token_file: ""
  384. sandbox_role: {{ ansible_service_broker_sandbox_role }}
  385. image_pull_policy: {{ ansible_service_broker_image_pull_policy }}
  386. keep_namespace: {{ ansible_service_broker_keep_namespace | bool | lower }}
  387. keep_namespace_on_error: {{ ansible_service_broker_keep_namespace_on_error | bool | lower }}
  388. broker:
  389. dev_broker: {{ ansible_service_broker_dev_broker | bool | lower }}
  390. bootstrap_on_startup: {{ ansible_service_broker_bootstrap_on_startup | bool | lower }}
  391. refresh_interval: {{ ansible_service_broker_refresh_interval }}
  392. launch_apb_on_bind: {{ ansible_service_broker_launch_apb_on_bind | bool | lower }}
  393. output_request: {{ ansible_service_broker_output_request | bool | lower }}
  394. recovery: {{ ansible_service_broker_recovery | bool | lower }}
  395. ssl_cert_key: /etc/tls/private/tls.key
  396. ssl_cert: /etc/tls/private/tls.crt
  397. auto_escalate: {{ ansible_service_broker_auto_escalate }}
  398. auth:
  399. - type: basic
  400. enabled: false
  401. - oc_secret:
  402. name: asb-registry-auth
  403. namespace: openshift-ansible-service-broker
  404. state: present
  405. contents:
  406. - path: username
  407. data: "{{ ansible_service_broker_registry_user }}"
  408. - path: password
  409. data: "{{ ansible_service_broker_registry_password }}"
  410. - name: Create the Broker resource in the catalog
  411. oc_obj:
  412. name: ansible-service-broker
  413. state: present
  414. kind: ClusterServiceBroker
  415. content:
  416. path: /tmp/brokerout
  417. data:
  418. apiVersion: servicecatalog.k8s.io/v1beta1
  419. kind: ClusterServiceBroker
  420. metadata:
  421. name: ansible-service-broker
  422. spec:
  423. url: https://asb.openshift-ansible-service-broker.svc:1338/ansible-service-broker
  424. authInfo:
  425. bearer:
  426. secretRef:
  427. name: asb-client
  428. namespace: openshift-ansible-service-broker
  429. kind: Secret
  430. caBundle: "{{ service_ca_crt }}"