main.yaml 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225
  1. ---
  2. - fail:
  3. msg: Application logs destination is required
  4. when: not openshift_logging_mux_app_host or openshift_logging_mux_app_host == ''
  5. - fail:
  6. msg: Operations logs destination is required
  7. when: not openshift_logging_mux_ops_host or openshift_logging_mux_ops_host == ''
  8. - name: Set default image variables based on openshift_deployment_type
  9. include_vars: "{{ var_file_name }}"
  10. with_first_found:
  11. - "{{ openshift_deployment_type }}.yml"
  12. - "default_images.yml"
  13. loop_control:
  14. loop_var: var_file_name
  15. - name: Set mux image facts
  16. set_fact:
  17. openshift_logging_mux_image_prefix: "{{ openshift_logging_mux_image_prefix | default(__openshift_logging_mux_image_prefix) }}"
  18. openshift_logging_mux_image_version: "{{ openshift_logging_mux_image_version | default(__openshift_logging_mux_image_version) }}"
  19. - include_tasks: determine_version.yaml
  20. # allow passing in a tempdir
  21. - name: Create temp directory for doing work in
  22. command: mktemp -d /tmp/openshift-logging-ansible-XXXXXX
  23. register: mktemp
  24. changed_when: False
  25. - set_fact:
  26. tempdir: "{{ mktemp.stdout }}"
  27. - name: Create templates subdirectory
  28. file:
  29. state: directory
  30. path: "{{ tempdir }}/templates"
  31. mode: 0755
  32. changed_when: False
  33. # we want to make sure we have all the necessary components here
  34. # create service account
  35. - name: Create Mux service account
  36. oc_serviceaccount:
  37. state: present
  38. name: "aggregated-logging-mux"
  39. namespace: "{{ openshift_logging_mux_namespace }}"
  40. image_pull_secrets: "{{ openshift_logging_image_pull_secret }}"
  41. when: openshift_logging_image_pull_secret != ''
  42. - name: Create Mux service account
  43. oc_serviceaccount:
  44. state: present
  45. name: "aggregated-logging-mux"
  46. namespace: "{{ openshift_logging_mux_namespace }}"
  47. when:
  48. - openshift_logging_image_pull_secret == ''
  49. # set service account scc
  50. - name: Set privileged permissions for Mux
  51. oc_adm_policy_user:
  52. namespace: "{{ openshift_logging_mux_namespace }}"
  53. resource_kind: scc
  54. resource_name: privileged
  55. state: present
  56. user: "system:serviceaccount:{{ openshift_logging_mux_namespace }}:aggregated-logging-mux"
  57. # set service account permissions
  58. - name: Set cluster-reader permissions for Mux
  59. oc_adm_policy_user:
  60. namespace: "{{ openshift_logging_mux_namespace }}"
  61. resource_kind: cluster-role
  62. resource_name: cluster-reader
  63. state: present
  64. user: "system:serviceaccount:{{ openshift_logging_mux_namespace }}:aggregated-logging-mux"
  65. # set hostmount-anyuid permissions
  66. - name: Set hostmount-anyuid permissions for Mux
  67. oc_adm_policy_user:
  68. namespace: "{{ openshift_logging_mux_namespace }}"
  69. resource_kind: scc
  70. resource_name: hostmount-anyuid
  71. state: present
  72. user: "system:serviceaccount:{{ openshift_logging_mux_namespace }}:aggregated-logging-mux"
  73. # create Mux configmap
  74. - copy:
  75. src: fluent.conf
  76. dest: "{{mktemp.stdout}}/fluent-mux.conf"
  77. changed_when: no
  78. - copy:
  79. src: secure-forward.conf
  80. dest: "{{mktemp.stdout}}/secure-forward-mux.conf"
  81. changed_when: no
  82. - import_role:
  83. name: openshift_logging
  84. tasks_from: patch_configmap_files.yaml
  85. vars:
  86. configmap_name: "logging-mux"
  87. configmap_namespace: "{{ openshift_logging_mux_namespace }}"
  88. configmap_file_names:
  89. - current_file: "fluent.conf"
  90. new_file: "{{ tempdir }}/fluent-mux.conf"
  91. - current_file: "secure-forward.conf"
  92. new_file: "{{ tempdir }}/secure-forward-mux.conf"
  93. - name: Set Mux configmap
  94. oc_configmap:
  95. state: present
  96. name: "logging-mux"
  97. namespace: "{{ openshift_logging_mux_namespace }}"
  98. from_file:
  99. fluent.conf: "{{ tempdir }}/fluent-mux.conf"
  100. secure-forward.conf: "{{ tempdir }}/secure-forward-mux.conf"
  101. # create Mux secret
  102. - name: Set logging-mux secret
  103. oc_secret:
  104. state: present
  105. name: logging-mux
  106. namespace: "{{ openshift_logging_mux_namespace }}"
  107. files:
  108. - name: ca
  109. path: "{{ generated_certs_dir }}/ca.crt"
  110. - name: key
  111. path: "{{ generated_certs_dir }}/system.logging.mux.key"
  112. - name: cert
  113. path: "{{ generated_certs_dir }}/system.logging.mux.crt"
  114. - name: shared_key
  115. path: "{{ generated_certs_dir }}/mux_shared_key"
  116. # services
  117. - name: Set logging-mux service for external communication
  118. oc_service:
  119. state: present
  120. name: "logging-mux"
  121. namespace: "{{ openshift_logging_mux_namespace }}"
  122. selector:
  123. component: mux
  124. provider: openshift
  125. labels:
  126. logging-infra: 'support'
  127. ports:
  128. - name: mux-forward
  129. port: "{{ openshift_logging_mux_port }}"
  130. targetPort: "mux-forward"
  131. external_ips:
  132. - "{{ ansible_eth0.ipv4.address }}"
  133. when: openshift_logging_mux_allow_external | bool
  134. - name: Set logging-mux service for internal communication
  135. oc_service:
  136. state: present
  137. name: "logging-mux"
  138. namespace: "{{ openshift_logging_mux_namespace }}"
  139. selector:
  140. component: mux
  141. provider: openshift
  142. labels:
  143. logging-infra: 'support'
  144. ports:
  145. - name: mux-forward
  146. port: "{{ openshift_logging_mux_port }}"
  147. targetPort: "mux-forward"
  148. when: not openshift_logging_mux_allow_external | bool
  149. # create Mux DC
  150. - name: Generating mux deploymentconfig
  151. template:
  152. src: mux.j2
  153. dest: "{{mktemp.stdout}}/templates/logging-mux-dc.yaml"
  154. vars:
  155. component: mux
  156. logging_component: mux
  157. deploy_name: "logging-{{ component }}"
  158. image: "{{ openshift_logging_mux_image_prefix }}logging-fluentd:{{ openshift_logging_mux_image_version }}"
  159. es_host: "{{ openshift_logging_mux_app_host }}"
  160. es_port: "{{ openshift_logging_mux_app_port }}"
  161. ops_host: "{{ openshift_logging_mux_ops_host }}"
  162. ops_port: "{{ openshift_logging_mux_ops_port }}"
  163. mux_cpu_limit: "{{ openshift_logging_mux_cpu_limit }}"
  164. mux_cpu_request: "{{ openshift_logging_mux_cpu_request | min_cpu(openshift_logging_mux_cpu_limit | default(none)) }}"
  165. mux_memory_limit: "{{ openshift_logging_mux_memory_limit }}"
  166. mux_replicas: "{{ openshift_logging_mux_replicas | default(1) }}"
  167. mux_node_selector: "{{ openshift_logging_mux_nodeselector | default({}) }}"
  168. check_mode: no
  169. changed_when: no
  170. - name: Create Mux PVC
  171. oc_pvc:
  172. state: present
  173. name: "{{ openshift_logging_mux_file_buffer_pvc_name }}"
  174. namespace: "{{ openshift_logging_mux_namespace }}"
  175. volume_capacity: "{{ openshift_logging_mux_file_buffer_pvc_size }}"
  176. access_modes: "{{ openshift_logging_mux_file_buffer_pvc_access_modes | list }}"
  177. selector: "{{ openshift_logging_mux_file_buffer_pvc_pv_selector }}"
  178. storage_class_name: "{{ openshift_logging_mux_file_buffer_pvc_storage_class_name | default('', true) }}"
  179. when:
  180. - openshift_logging_mux_file_buffer_storage_type == "pvc"
  181. - name: Set logging-mux DC
  182. oc_obj:
  183. state: present
  184. name: logging-mux
  185. namespace: "{{ openshift_logging_mux_namespace }}"
  186. kind: dc
  187. files:
  188. - "{{ tempdir }}/templates/logging-mux-dc.yaml"
  189. delete_after: true
  190. - name: Add mux namespaces
  191. oc_project:
  192. state: present
  193. name: "{{ item }}"
  194. node_selector: ""
  195. with_items: "{{ openshift_logging_mux_namespaces | union(openshift_logging_mux_default_namespaces) }}"
  196. - name: Delete temp directory
  197. file:
  198. name: "{{ tempdir }}"
  199. state: absent
  200. changed_when: False