c12s-kubespray/roles/kubernetes-apps/metallb/templates/layer3.yaml.j2

128 lines
3.6 KiB
Text
Raw Normal View History

2022-07-27 08:47:28 +00:00
#jinja2: trim_blocks: True, lstrip_blocks: True
# yamllint disable-file
---
# Create layer3 configuration
{% for community_name, community in metallb_config.layer3.communities.items() %}
---
apiVersion: metallb.io/v1beta1
kind: Community
metadata:
name: "{{ community_name }}"
namespace: "{{ namespace_name }}"
spec:
2022-09-06 14:52:34 +00:00
communities:
2022-07-27 08:47:28 +00:00
- name: "{{ community_name }}"
value: "{{ community }}"
{% endfor %}
2022-09-06 14:52:34 +00:00
---
apiVersion: metallb.io/v1beta1
kind: Community
metadata:
name: well-known
namespace: "{{ namespace_name }}"
spec:
communities:
- name: no-export
value: 65535:65281
- name: no-advertise
value: 65535:65282
- name: local-as
value: 65535:65283
- name: nopeer
value: 65535:65284
# BGPAdvertisement is used to advertise address pools to the BGP peer. Specific pools can be listed to be advertised.
# Local BGP Advertisement specifies that the IP specified in the address pool will be used as remote source address for traffic entering your cluster from the remote peer.
# When using this option, be sure to use a subnet and routable IP for your address pool.
# This is good: 10.0.0.10/24. This is also good: 10.0.0.129/25. This is bad: 10.0.0.0/24. This is also bad: 10.0.0.128/25.
# In this example, 10.0.0.10 will be used as the remote source address.
# This is also bad: 10.0.0.10-10.0.0.25. Remember: you are working with aggregationLength, which specifies a subnet, not an IP range!
# The no-advertise community is set on the local advertisement to prevent this route from being published to the BGP peer.
# Your aggregationLength ideally is the same size as your address pool.
2022-07-27 08:47:28 +00:00
{% for peer_name, peer in metallb_config.layer3.metallb_peers.items() %}
2022-09-06 14:52:34 +00:00
{% if peer.aggregation_length is defined and peer.aggregation_length <= 30 %}
2022-07-27 08:47:28 +00:00
---
apiVersion: metallb.io/v1beta1
kind: BGPAdvertisement
metadata:
name: "{{ peer_name }}-local"
namespace: "{{ namespace_name }}"
spec:
2022-09-06 14:52:34 +00:00
aggregationLength: 32
aggregationLengthV6: 128
communities:
- no-advertise
localpref: "{{ peer.localpref | default ("100") }}"
2022-07-27 08:47:28 +00:00
ipAddressPools:
{% for address_pool in peer.address_pool %}
- "{{ address_pool }}"
{% endfor %}
2022-09-06 14:52:34 +00:00
{% endif %}
2022-07-27 08:47:28 +00:00
2022-09-06 14:52:34 +00:00
# External BGP Advertisement. The IP range specied in the address pool is advertised to the BGP peer.
2022-07-27 08:47:28 +00:00
---
apiVersion: metallb.io/v1beta1
kind: BGPAdvertisement
metadata:
name: "{{ peer_name }}-external"
namespace: "{{ namespace_name }}"
spec:
2022-09-06 14:52:34 +00:00
{% if peer.aggregation_length is defined and peer.aggregation_length <= 30 %}
aggregationLength: {{ peer.aggregation_length }}
{% endif %}
2022-07-27 08:47:28 +00:00
ipAddressPools:
{% for address_pool in peer.address_pool %}
- "{{ address_pool }}"
{% endfor %}
2022-09-06 14:52:34 +00:00
{% if peer.communities is defined %}
{% for community in peer.communities %}
communities:
- "{{ community }}"
{% endfor %}
2022-07-27 08:47:28 +00:00
{% endif %}
2022-09-06 14:52:34 +00:00
# Configuration for the BGP peer.
2022-07-27 08:47:28 +00:00
---
apiVersion: metallb.io/v1beta2
kind: BGPPeer
metadata:
name: "{{ peer_name }}"
namespace: "{{ namespace_name }}"
spec:
myASN: {{ peer.my_asn }}
peerASN: {{ peer.peer_asn }}
peerAddress: {{ peer.peer_address }}
{% if peer.peer_port is defined %}
peerPort: {{ peer.peer_port }}
{% else %}
peerPort: {{ metallb_config.layer3.defaults.peer_port }}
{% endif %}
{% if peer.password is defined %}
password: "{{ peer.password }}"
{% endif %}
{% if peer.router_id is defined %}
routerID: "{{ peer.router_id }}"
{% endif %}
{% if peer.hold_time is defined %}
holdTime: {{ peer.hold_time }}
2022-09-06 14:52:34 +00:00
{% elif metallb_config.layer3.defaults.hold_time is defined %}
2022-07-27 08:47:28 +00:00
holdTime: {{ metallb_config.layer3.defaults.hold_time }}
{% endif %}
{% if peer.multihop is defined %}
2022-09-06 14:52:34 +00:00
ebgpMultiHop: {{ peer.multihop }}
2022-07-27 08:47:28 +00:00
{% endif %}
{% endfor %}