upgrade.yml 9.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241
  1. ---
  2. ###############################################################################
  3. # Upgrade Masters
  4. ###############################################################################
  5. # Create service signer cert when missing. Service signer certificate
  6. # is added to master config in the master_config_upgrade hook.
  7. - name: Determine if service signer cert must be created
  8. hosts: oo_first_master
  9. tasks:
  10. - name: Determine if service signer certificate must be created
  11. stat:
  12. path: "{{ openshift.common.config_base }}/master/service-signer.crt"
  13. get_checksum: false
  14. get_attributes: false
  15. get_mime: false
  16. register: service_signer_cert_stat
  17. changed_when: false
  18. - name: verify api server
  19. command: >
  20. curl --silent --tlsv1.2
  21. --cacert {{ openshift.common.config_base }}/master/ca-bundle.crt
  22. {{ openshift.master.api_url }}/healthz/ready
  23. args:
  24. # Disables the following warning:
  25. # Consider using get_url or uri module rather than running curl
  26. warn: no
  27. register: api_available_output
  28. until: api_available_output.stdout == 'ok'
  29. retries: 120
  30. delay: 1
  31. changed_when: false
  32. - import_playbook: create_service_signer_cert.yml
  33. # oc adm migrate storage should be run prior to etcd v3 upgrade
  34. # See: https://github.com/openshift/origin/pull/14625#issuecomment-308467060
  35. - name: Pre master upgrade - Upgrade all storage
  36. hosts: oo_first_master
  37. roles:
  38. - openshift_facts
  39. tasks:
  40. - name: Wait for API health
  41. import_role:
  42. name: openshift_control_plane
  43. tasks_from: check_master_api_is_ready.yml
  44. - name: Upgrade all storage
  45. command: >
  46. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  47. migrate storage --include=*
  48. register: l_pb_upgrade_control_plane_pre_upgrade_storage
  49. when: openshift_upgrade_pre_storage_migration_enabled | default(true) | bool
  50. until: l_pb_upgrade_control_plane_pre_upgrade_storage.rc == 0
  51. failed_when:
  52. - l_pb_upgrade_control_plane_pre_upgrade_storage.rc != 0
  53. - openshift_upgrade_pre_storage_migration_fatal | default(true) | bool
  54. retries: 6
  55. delay: 30
  56. - name: Migrate legacy HPA scale target refs
  57. command: >
  58. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  59. migrate legacy-hpa --confirm
  60. register: migrate_legacy_hpa_result
  61. when: openshift_upgrade_pre_storage_migration_enabled | default(true) | bool
  62. failed_when:
  63. - migrate_legacy_hpa_result.rc != 0
  64. - openshift_upgrade_pre_storage_migration_fatal | default(true) | bool
  65. # Set openshift_master_facts separately. In order to reconcile
  66. # admission_config's, we currently must run openshift_master_facts and
  67. # then run openshift_facts.
  68. - name: Set OpenShift master facts and image prepull
  69. hosts: oo_masters_to_config
  70. roles:
  71. - openshift_master_facts
  72. tasks:
  73. - import_role:
  74. name: openshift_control_plane
  75. tasks_from: pre_pull.yml
  76. - import_role:
  77. name: openshift_control_plane
  78. tasks_from: pre_pull_poll.yml
  79. - name: configure vsphere svc account
  80. hosts: oo_first_master
  81. tasks:
  82. - import_role:
  83. name: openshift_cloud_provider
  84. tasks_from: vsphere-svc.yml
  85. when:
  86. - openshift_cloudprovider_kind is defined
  87. - openshift_cloudprovider_kind == 'vsphere'
  88. # The main master upgrade play. Should handle all changes to the system in one pass, with
  89. # support for optional hooks to be defined.
  90. - name: Upgrade master
  91. hosts: oo_masters_to_config
  92. serial: 1
  93. roles:
  94. - openshift_facts
  95. tasks:
  96. # Run the pre-upgrade hook if defined:
  97. - debug: msg="Running master pre-upgrade hook {{ openshift_master_upgrade_pre_hook }}"
  98. when: openshift_master_upgrade_pre_hook is defined
  99. - include_tasks: "{{ openshift_master_upgrade_pre_hook }}"
  100. when: openshift_master_upgrade_pre_hook is defined
  101. - import_role:
  102. name: openshift_control_plane
  103. tasks_from: upgrade.yml
  104. - name: update vsphere provider master config
  105. import_role:
  106. name: openshift_cloud_provider
  107. tasks_from: update-vsphere.yml
  108. when:
  109. - openshift_cloudprovider_kind is defined
  110. - openshift_cloudprovider_kind == 'vsphere'
  111. # Run the upgrade hook prior to restarting services/system if defined:
  112. - debug: msg="Running master upgrade hook {{ openshift_master_upgrade_hook }}"
  113. when: openshift_master_upgrade_hook is defined
  114. - include_tasks: "{{ openshift_master_upgrade_hook }}"
  115. when: openshift_master_upgrade_hook is defined
  116. - name: Lay down the static configuration
  117. import_role:
  118. name: openshift_control_plane
  119. tasks_from: static.yml
  120. - import_tasks: tasks/restart_hosts.yml
  121. when: openshift_rolling_restart_mode | default('services') == 'system'
  122. - import_tasks: tasks/restart_services.yml
  123. when: openshift_rolling_restart_mode | default('services') == 'services'
  124. # Run the post-upgrade hook if defined:
  125. - debug: msg="Running master post-upgrade hook {{ openshift_master_upgrade_post_hook }}"
  126. when: openshift_master_upgrade_post_hook is defined
  127. - include_tasks: "{{ openshift_master_upgrade_post_hook }}"
  128. when: openshift_master_upgrade_post_hook is defined
  129. - set_fact:
  130. master_update_complete: True
  131. ##############################################################################
  132. # Gate on master update complete
  133. ##############################################################################
  134. - name: Gate on master update
  135. hosts: localhost
  136. connection: local
  137. tasks:
  138. - set_fact:
  139. master_update_completed: "{{ hostvars
  140. | lib_utils_oo_select_keys(groups.oo_masters_to_config)
  141. | lib_utils_oo_collect('inventory_hostname', {'master_update_complete': true}) }}"
  142. - set_fact:
  143. master_update_failed: "{{ groups.oo_masters_to_config | difference(master_update_completed) | list }}"
  144. - fail:
  145. msg: "Upgrade cannot continue. The following masters did not finish updating: {{ master_update_failed | join(',') }}"
  146. when: master_update_failed | length > 0
  147. ###############################################################################
  148. # Reconcile Cluster Roles, Cluster Role Bindings and Security Context Constraints
  149. ###############################################################################
  150. - name: Reconcile Cluster Roles and Cluster Role Bindings and Security Context Constraints
  151. hosts: oo_masters_to_config
  152. roles:
  153. - openshift_cli
  154. - openshift_facts
  155. vars:
  156. __master_shared_resource_viewer_file: "shared_resource_viewer_role.yaml"
  157. tasks:
  158. - name: Wait for API health
  159. import_role:
  160. name: openshift_control_plane
  161. tasks_from: check_master_api_is_ready.yml
  162. - name: Reconcile Security Context Constraints
  163. command: >
  164. {{ openshift_client_binary }} adm policy --config={{ openshift.common.config_base }}/master/admin.kubeconfig reconcile-sccs --confirm --additive-only=true -o name
  165. register: reconcile_scc_result
  166. changed_when:
  167. - reconcile_scc_result.stdout != ''
  168. - reconcile_scc_result.rc == 0
  169. run_once: true
  170. - name: Migrate storage post policy reconciliation
  171. command: >
  172. {{ openshift_client_binary }} adm --config={{ openshift.common.config_base }}/master/admin.kubeconfig
  173. migrate storage --include=*
  174. run_once: true
  175. register: l_pb_upgrade_control_plane_post_upgrade_storage
  176. when: openshift_upgrade_post_storage_migration_enabled | default(true) | bool
  177. until: l_pb_upgrade_control_plane_post_upgrade_storage.rc == 0
  178. failed_when:
  179. - l_pb_upgrade_control_plane_post_upgrade_storage.rc != 0
  180. - openshift_upgrade_post_storage_migration_fatal | default(false) | bool
  181. retries: 6
  182. delay: 30
  183. - set_fact:
  184. reconcile_complete: True
  185. ##############################################################################
  186. # Gate on reconcile
  187. ##############################################################################
  188. - name: Gate on reconcile
  189. hosts: localhost
  190. connection: local
  191. tasks:
  192. - set_fact:
  193. reconcile_completed: "{{ hostvars
  194. | lib_utils_oo_select_keys(groups.oo_masters_to_config)
  195. | lib_utils_oo_collect('inventory_hostname', {'reconcile_complete': true}) }}"
  196. - set_fact:
  197. reconcile_failed: "{{ groups.oo_masters_to_config | difference(reconcile_completed) | list }}"
  198. - fail:
  199. msg: "Upgrade cannot continue. The following masters did not finish reconciling: {{ reconcile_failed | join(',') }}"
  200. when: reconcile_failed | length > 0
  201. - name: Drain and upgrade master nodes
  202. hosts: oo_masters_to_config:&oo_nodes_to_upgrade
  203. # This var must be set with -e on invocation, as it is not a per-host inventory var
  204. # and is evaluated early. Values such as "20%" can also be used.
  205. serial: "{{ openshift_upgrade_control_plane_nodes_serial | default(1) }}"
  206. max_fail_percentage: "{{ openshift_upgrade_control_plane_nodes_max_fail_percentage | default(0) }}"
  207. roles:
  208. - lib_openshift
  209. - openshift_facts
  210. tasks:
  211. - import_role:
  212. name: openshift_manage_node
  213. tasks_from: config.yml
  214. vars:
  215. openshift_master_host: "{{ groups.oo_first_master.0 }}"