2018-09-04 12:17:23 +00:00
|
|
|
---
|
2019-09-26 11:21:06 +00:00
|
|
|
- name: "Kubernetes Apps | Check cluster settings for MetalLB"
|
|
|
|
fail:
|
|
|
|
msg: "MetalLB require kube_proxy_strict_arp = true, see https://github.com/danderson/metallb/issues/153#issuecomment-518651132"
|
|
|
|
when:
|
|
|
|
- "kube_proxy_mode == 'ipvs' and not kube_proxy_strict_arp"
|
2020-04-11 06:48:03 +00:00
|
|
|
|
2020-06-29 22:11:59 +00:00
|
|
|
- name: Kubernetes Apps | Check cluster settings for MetalLB
|
|
|
|
fail:
|
|
|
|
msg: "metallb_ip_range is mandatory to be specified for MetalLB"
|
|
|
|
when:
|
|
|
|
- metallb_ip_range is not defined or not metallb_ip_range
|
|
|
|
|
2020-04-11 06:48:03 +00:00
|
|
|
- name: Kubernetes Apps | Check AppArmor status
|
|
|
|
command: which apparmor_parser
|
|
|
|
register: apparmor_status
|
|
|
|
when:
|
|
|
|
- podsecuritypolicy_enabled
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
|
|
|
failed_when: false
|
|
|
|
|
|
|
|
- name: Kubernetes Apps | Set apparmor_enabled
|
|
|
|
set_fact:
|
|
|
|
apparmor_enabled: "{{ apparmor_status.rc == 0 }}"
|
|
|
|
when:
|
|
|
|
- podsecuritypolicy_enabled
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
|
|
|
|
2018-09-04 12:17:23 +00:00
|
|
|
- name: "Kubernetes Apps | Lay Down MetalLB"
|
|
|
|
become: true
|
|
|
|
template: { src: "{{ item }}.j2", dest: "{{ kube_config_dir }}/{{ item }}" }
|
|
|
|
with_items: ["metallb.yml", "metallb-config.yml"]
|
|
|
|
register: "rendering"
|
|
|
|
when:
|
|
|
|
- "inventory_hostname == groups['kube-master'][0]"
|
2020-04-11 06:48:03 +00:00
|
|
|
|
2018-09-04 12:17:23 +00:00
|
|
|
- name: "Kubernetes Apps | Install and configure MetalLB"
|
|
|
|
kube:
|
2019-04-23 17:37:23 +00:00
|
|
|
name: "MetalLB"
|
2019-05-02 21:24:21 +00:00
|
|
|
kubectl: "{{ bin_dir }}/kubectl"
|
2019-04-23 17:37:23 +00:00
|
|
|
filename: "{{ kube_config_dir }}/{{ item.item }}"
|
2018-09-04 12:17:23 +00:00
|
|
|
state: "{{ item.changed | ternary('latest','present') }}"
|
2019-03-18 01:15:09 +00:00
|
|
|
become: true
|
2019-04-23 17:37:23 +00:00
|
|
|
with_items: "{{ rendering.results }}"
|
2018-09-04 12:17:23 +00:00
|
|
|
when:
|
|
|
|
- "inventory_hostname == groups['kube-master'][0]"
|
2020-06-29 22:11:59 +00:00
|
|
|
|
|
|
|
- name: Kubernetes Apps | Check existing secret of MetalLB
|
|
|
|
command: "{{ bin_dir }}/kubectl --kubeconfig /etc/kubernetes/admin.conf -n metallb-system get secret memberlist"
|
|
|
|
register: metallb_secret
|
|
|
|
become: true
|
|
|
|
ignore_errors: yes
|
|
|
|
when:
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
|
|
|
|
|
|
|
- name: Kubernetes Apps | Create random bytes for MetalLB
|
|
|
|
command: "openssl rand -base64 32"
|
|
|
|
register: metallb_rand
|
|
|
|
when:
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
|
|
|
- metallb_secret.rc != 0
|
|
|
|
|
|
|
|
- name: Kubernetes Apps | Install secret of MetalLB if not existing
|
|
|
|
command: "{{ bin_dir }}/kubectl --kubeconfig /etc/kubernetes/admin.conf -n metallb-system create secret generic memberlist --from-literal=secretkey={{ metallb_rand.stdout }}"
|
|
|
|
become: true
|
|
|
|
when:
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
|
|
|
- metallb_secret.rc != 0
|