2016-09-07 18:02:06 +00:00
|
|
|
---
|
2017-04-21 02:51:27 +00:00
|
|
|
- name: Helm | Make sure HELM_HOME directory exists
|
|
|
|
file: path={{ helm_home_dir }} state=directory
|
|
|
|
|
2017-03-17 11:56:25 +00:00
|
|
|
- name: Helm | Set up helm launcher
|
2018-01-29 11:37:48 +00:00
|
|
|
include_tasks: "install_{{ helm_deployment_type }}.yml"
|
2017-03-17 11:56:25 +00:00
|
|
|
|
2017-06-27 04:27:25 +00:00
|
|
|
- name: Helm | Lay Down Helm Manifests (RBAC)
|
|
|
|
template:
|
2019-05-02 21:24:21 +00:00
|
|
|
src: "{{ item.file }}.j2"
|
|
|
|
dest: "{{ kube_config_dir }}/{{ item.file }}"
|
2017-06-27 04:27:25 +00:00
|
|
|
with_items:
|
2018-08-29 09:20:41 +00:00
|
|
|
- {name: tiller, file: tiller-namespace.yml, type: namespace}
|
2017-06-27 04:27:25 +00:00
|
|
|
- {name: tiller, file: tiller-sa.yml, type: sa}
|
|
|
|
- {name: tiller, file: tiller-clusterrolebinding.yml, type: clusterrolebinding}
|
|
|
|
register: manifests
|
2018-09-10 09:39:26 +00:00
|
|
|
when:
|
|
|
|
- dns_mode != 'none'
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
2019-12-12 17:24:32 +00:00
|
|
|
- helm_version is version('v3.0.0', '<')
|
2017-06-27 04:27:25 +00:00
|
|
|
|
|
|
|
- name: Helm | Apply Helm Manifests (RBAC)
|
|
|
|
kube:
|
2019-05-02 21:24:21 +00:00
|
|
|
name: "{{ item.item.name }}"
|
2018-08-29 09:20:41 +00:00
|
|
|
namespace: "{{ tiller_namespace }}"
|
2019-05-02 21:24:21 +00:00
|
|
|
kubectl: "{{ bin_dir }}/kubectl"
|
|
|
|
resource: "{{ item.item.type }}"
|
|
|
|
filename: "{{ kube_config_dir }}/{{ item.item.file }}"
|
2017-09-05 05:23:12 +00:00
|
|
|
state: "latest"
|
2019-04-23 17:37:23 +00:00
|
|
|
with_items: "{{ manifests.results }}"
|
2018-09-10 09:39:26 +00:00
|
|
|
when:
|
|
|
|
- dns_mode != 'none'
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
2019-12-12 17:24:32 +00:00
|
|
|
- helm_version is version('v3.0.0', '<')
|
2017-06-27 04:27:25 +00:00
|
|
|
|
2018-09-06 15:14:18 +00:00
|
|
|
# Generate necessary certs for securing Helm and Tiller connection with TLS
|
|
|
|
- name: Helm | Set up TLS
|
|
|
|
include_tasks: "gen_helm_tiller_certs.yml"
|
2019-12-12 17:24:32 +00:00
|
|
|
when:
|
|
|
|
- tiller_enable_tls
|
|
|
|
- helm_version is version('v3.0.0', '<')
|
2018-09-06 15:14:18 +00:00
|
|
|
|
2019-10-04 12:14:02 +00:00
|
|
|
- name: Helm | Install client on all masters
|
|
|
|
command: >
|
|
|
|
{{ bin_dir }}/helm init --tiller-namespace={{ tiller_namespace }}
|
|
|
|
{% if helm_skip_refresh %} --skip-refresh{% endif %}
|
|
|
|
{% if helm_stable_repo_url is defined %} --stable-repo-url {{ helm_stable_repo_url }}{% endif %}
|
|
|
|
--client-only
|
|
|
|
environment: "{{ proxy_env }}"
|
|
|
|
changed_when: false
|
2019-12-12 17:24:32 +00:00
|
|
|
when:
|
|
|
|
- helm_version is version('v3.0.0', '<')
|
2019-10-04 12:14:02 +00:00
|
|
|
|
2019-09-10 19:06:55 +00:00
|
|
|
# FIXME: https://github.com/helm/helm/issues/6374
|
2020-08-28 08:20:53 +00:00
|
|
|
- name: Helm | Install/upgrade helm
|
2019-09-10 19:06:55 +00:00
|
|
|
shell: >
|
2020-08-28 08:20:53 +00:00
|
|
|
set -o pipefail &&
|
2018-09-10 09:39:26 +00:00
|
|
|
{{ bin_dir }}/helm init --tiller-namespace={{ tiller_namespace }}
|
2017-11-28 18:33:57 +00:00
|
|
|
{% if helm_skip_refresh %} --skip-refresh{% endif %}
|
|
|
|
{% if helm_stable_repo_url is defined %} --stable-repo-url {{ helm_stable_repo_url }}{% endif %}
|
2018-09-10 09:39:26 +00:00
|
|
|
--upgrade --tiller-image={{ tiller_image_repo }}:{{ tiller_image_tag }}
|
2020-09-21 06:52:30 +00:00
|
|
|
{% if rbac_enabled %} --service-account={{ tiller_service_account }}{% endif %}
|
2017-11-28 18:33:57 +00:00
|
|
|
{% if tiller_node_selectors is defined %} --node-selectors {{ tiller_node_selectors }}{% endif %}
|
2019-07-16 08:39:24 +00:00
|
|
|
--override spec.template.spec.priorityClassName={% if tiller_namespace == 'kube-system' %}system-cluster-critical{% else %}k8s-cluster-critical{% endif %}
|
2019-04-29 06:00:20 +00:00
|
|
|
{% if tiller_override is defined and tiller_override %} --override {{ tiller_override }}{% endif %}
|
2018-06-15 10:50:18 +00:00
|
|
|
{% if tiller_max_history is defined %} --history-max={{ tiller_max_history }}{% endif %}
|
2018-09-06 15:14:18 +00:00
|
|
|
{% if tiller_enable_tls %} --tiller-tls --tiller-tls-verify --tiller-tls-cert={{ tiller_tls_cert }} --tiller-tls-key={{ tiller_tls_key }} --tls-ca-cert={{ tiller_tls_ca_cert }} {% endif %}
|
|
|
|
{% if tiller_secure_release_info %} --override 'spec.template.spec.containers[0].command'='{/tiller,--storage=secret}' {% endif %}
|
2019-10-04 06:41:56 +00:00
|
|
|
--override spec.selector.matchLabels.'name'='tiller',spec.selector.matchLabels.'app'='helm'
|
2019-02-11 22:32:26 +00:00
|
|
|
{% if tiller_wait %} --wait{% endif %}
|
2020-09-21 06:52:30 +00:00
|
|
|
{% if tiller_replicas is defined %} --replicas {{ tiller_replicas | int }}{% endif %}
|
2019-09-10 19:06:55 +00:00
|
|
|
--output yaml
|
|
|
|
| sed 's@apiVersion: extensions/v1beta1@apiVersion: apps/v1@'
|
|
|
|
| {{ bin_dir }}/kubectl apply -f -
|
2020-08-28 08:20:53 +00:00
|
|
|
args:
|
|
|
|
executable: /bin/bash
|
2018-09-03 07:51:55 +00:00
|
|
|
register: install_helm
|
2019-10-04 12:14:02 +00:00
|
|
|
when:
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
2019-12-12 17:24:32 +00:00
|
|
|
- helm_version is version('v3.0.0', '<')
|
2018-09-03 07:51:55 +00:00
|
|
|
changed_when: false
|
2019-05-02 21:24:21 +00:00
|
|
|
environment: "{{ proxy_env }}"
|
2018-09-03 07:51:55 +00:00
|
|
|
|
2018-09-06 14:26:57 +00:00
|
|
|
# FIXME: https://github.com/helm/helm/issues/4063
|
2020-08-28 08:20:53 +00:00
|
|
|
- name: Helm | Force apply tiller overrides if necessary
|
2018-09-03 07:51:55 +00:00
|
|
|
shell: >
|
2020-08-28 08:20:53 +00:00
|
|
|
set -o pipefail &&
|
2018-09-03 07:51:55 +00:00
|
|
|
{{ bin_dir }}/helm init --upgrade --tiller-image={{ tiller_image_repo }}:{{ tiller_image_tag }} --tiller-namespace={{ tiller_namespace }}
|
|
|
|
{% if helm_skip_refresh %} --skip-refresh{% endif %}
|
|
|
|
{% if helm_stable_repo_url is defined %} --stable-repo-url {{ helm_stable_repo_url }}{% endif %}
|
2020-09-21 06:52:30 +00:00
|
|
|
{% if rbac_enabled %} --service-account={{ tiller_service_account }}{% endif %}
|
2018-09-03 07:51:55 +00:00
|
|
|
{% if tiller_node_selectors is defined %} --node-selectors {{ tiller_node_selectors }}{% endif %}
|
2019-07-16 08:39:24 +00:00
|
|
|
--override spec.template.spec.priorityClassName={% if tiller_namespace == 'kube-system' %}system-cluster-critical{% else %}k8s-cluster-critical{% endif %}
|
2019-04-29 06:00:20 +00:00
|
|
|
{% if tiller_override is defined and tiller_override %} --override {{ tiller_override }}{% endif %}
|
2018-09-03 07:51:55 +00:00
|
|
|
{% if tiller_max_history is defined %} --history-max={{ tiller_max_history }}{% endif %}
|
2018-09-06 15:14:18 +00:00
|
|
|
{% if tiller_enable_tls %} --tiller-tls --tiller-tls-verify --tiller-tls-cert={{ tiller_tls_cert }} --tiller-tls-key={{ tiller_tls_key }} --tls-ca-cert={{ tiller_tls_ca_cert }} {% endif %}
|
|
|
|
{% if tiller_secure_release_info %} --override 'spec.template.spec.containers[0].command'='{/tiller,--storage=secret}' {% endif %}
|
2019-10-04 06:41:56 +00:00
|
|
|
--override spec.selector.matchLabels.'name'='tiller',spec.selector.matchLabels.'app'='helm'
|
2019-02-11 22:32:26 +00:00
|
|
|
{% if tiller_wait %} --wait{% endif %}
|
2020-09-21 06:52:30 +00:00
|
|
|
{% if tiller_replicas is defined %} --replicas {{ tiller_replicas | int }}{% endif %}
|
2018-10-12 18:46:39 +00:00
|
|
|
--output yaml
|
2019-09-10 19:06:55 +00:00
|
|
|
| sed 's@apiVersion: extensions/v1beta1@apiVersion: apps/v1@'
|
2019-05-02 21:24:21 +00:00
|
|
|
| {{ bin_dir }}/kubectl apply -f -
|
2020-08-28 08:20:53 +00:00
|
|
|
args:
|
|
|
|
executable: /bin/bash
|
2018-09-03 07:51:55 +00:00
|
|
|
changed_when: false
|
2018-09-10 09:39:26 +00:00
|
|
|
when:
|
|
|
|
- inventory_hostname == groups['kube-master'][0]
|
2019-12-12 17:24:32 +00:00
|
|
|
- helm_version is version('v3.0.0', '<')
|
2019-05-02 21:24:21 +00:00
|
|
|
environment: "{{ proxy_env }}"
|
2017-03-17 11:56:25 +00:00
|
|
|
|
2020-02-19 22:05:46 +00:00
|
|
|
- name: Helm | Add/update stable repo on all masters
|
|
|
|
command: "{{ bin_dir }}/helm repo add stable {{ helm_stable_repo_url }}"
|
|
|
|
environment: "{{ proxy_env }}"
|
|
|
|
when:
|
|
|
|
- helm_version is version('v3.0.0', '>=')
|
|
|
|
- helm_stable_repo_url is defined
|
|
|
|
|
2020-07-27 13:24:17 +00:00
|
|
|
- name: Make sure bash_completion.d folder exists # noqa 503
|
2019-04-18 09:24:10 +00:00
|
|
|
file:
|
|
|
|
name: "/etc/bash_completion.d/"
|
|
|
|
state: directory
|
|
|
|
when:
|
|
|
|
- ((helm_container is defined and helm_container.changed) or (helm_task_result is defined and helm_task_result.changed))
|
|
|
|
- ansible_os_family in ["ClearLinux"]
|
|
|
|
|
2020-07-27 13:24:17 +00:00
|
|
|
- name: Helm | Set up bash completion # noqa 503
|
2017-06-19 06:33:50 +00:00
|
|
|
shell: "umask 022 && {{ bin_dir }}/helm completion bash >/etc/bash_completion.d/helm.sh"
|
2018-09-10 09:39:26 +00:00
|
|
|
when:
|
|
|
|
- ((helm_container is defined and helm_container.changed) or (helm_task_result is defined and helm_task_result.changed))
|
2020-08-28 09:28:53 +00:00
|
|
|
- not ansible_os_family in ["Flatcar Container Linux by Kinvolk"]
|