2016-02-11 22:08:16 +00:00
|
|
|
---
|
2016-04-07 15:08:39 +00:00
|
|
|
- include: check-certs.yml
|
2016-12-08 13:36:00 +00:00
|
|
|
tags: [k8s-secrets, facts]
|
2017-02-17 21:22:34 +00:00
|
|
|
|
2016-05-06 17:17:59 +00:00
|
|
|
- include: check-tokens.yml
|
2016-12-08 13:36:00 +00:00
|
|
|
tags: [k8s-secrets, facts]
|
2016-04-07 15:08:39 +00:00
|
|
|
|
2016-02-11 22:08:16 +00:00
|
|
|
- name: Make sure the certificate directory exits
|
|
|
|
file:
|
2017-02-17 21:22:34 +00:00
|
|
|
path: "{{ kube_cert_dir }}"
|
|
|
|
state: directory
|
|
|
|
mode: o-rwx
|
|
|
|
group: "{{ kube_cert_group }}"
|
2016-02-11 22:08:16 +00:00
|
|
|
|
|
|
|
- name: Make sure the tokens directory exits
|
|
|
|
file:
|
2017-02-17 21:22:34 +00:00
|
|
|
path: "{{ kube_token_dir }}"
|
|
|
|
state: directory
|
|
|
|
mode: o-rwx
|
|
|
|
group: "{{ kube_cert_group }}"
|
2016-02-11 22:08:16 +00:00
|
|
|
|
|
|
|
- name: Make sure the users directory exits
|
|
|
|
file:
|
2017-02-17 21:22:34 +00:00
|
|
|
path: "{{ kube_users_dir }}"
|
|
|
|
state: directory
|
|
|
|
mode: o-rwx
|
|
|
|
group: "{{ kube_cert_group }}"
|
2016-02-11 22:08:16 +00:00
|
|
|
|
|
|
|
- name: Populate users for basic auth in API
|
|
|
|
lineinfile:
|
|
|
|
dest: "{{ kube_users_dir }}/known_users.csv"
|
|
|
|
create: yes
|
|
|
|
line: '{{ item.value.pass }},{{ item.key }},{{ item.value.role }}'
|
|
|
|
backup: yes
|
|
|
|
with_dict: "{{ kube_users }}"
|
2017-02-27 13:15:50 +00:00
|
|
|
when: inventory_hostname in "{{ groups['kube-master'] }}" and kube_basic_auth|default(true)
|
2016-02-11 22:08:16 +00:00
|
|
|
notify: set secret_changed
|
|
|
|
|
2017-01-15 05:24:34 +00:00
|
|
|
#
|
|
|
|
# The following directory creates make sure that the directories
|
|
|
|
# exist on the first master for cases where the first master isn't
|
|
|
|
# being run.
|
|
|
|
#
|
2017-01-18 20:06:50 +00:00
|
|
|
- name: "Gen_certs | Create kubernetes config directory (on {{groups['kube-master'][0]}})"
|
2017-01-15 05:24:34 +00:00
|
|
|
file:
|
|
|
|
path: "{{ kube_config_dir }}"
|
|
|
|
state: directory
|
|
|
|
owner: kube
|
|
|
|
run_once: yes
|
|
|
|
delegate_to: "{{groups['kube-master'][0]}}"
|
|
|
|
tags: [kubelet, k8s-secrets, kube-controller-manager, kube-apiserver, bootstrap-os, apps, network, master, node]
|
|
|
|
when: gen_certs|default(false) or gen_tokens|default(false)
|
|
|
|
|
2017-01-18 20:06:50 +00:00
|
|
|
- name: "Gen_certs | Create kubernetes script directory (on {{groups['kube-master'][0]}})"
|
2017-01-15 05:24:34 +00:00
|
|
|
file:
|
|
|
|
path: "{{ kube_script_dir }}"
|
|
|
|
state: directory
|
|
|
|
owner: kube
|
|
|
|
run_once: yes
|
|
|
|
delegate_to: "{{groups['kube-master'][0]}}"
|
|
|
|
tags: [k8s-secrets, bootstrap-os]
|
|
|
|
when: gen_certs|default(false) or gen_tokens|default(false)
|
|
|
|
|
2017-01-18 20:06:50 +00:00
|
|
|
- name: "Get_tokens | Make sure the tokens directory exits (on {{groups['kube-master'][0]}})"
|
2017-01-15 05:24:34 +00:00
|
|
|
file:
|
2017-02-17 21:22:34 +00:00
|
|
|
path: "{{ kube_token_dir }}"
|
|
|
|
state: directory
|
|
|
|
mode: o-rwx
|
|
|
|
group: "{{ kube_cert_group }}"
|
2017-01-15 05:24:34 +00:00
|
|
|
run_once: yes
|
|
|
|
delegate_to: "{{groups['kube-master'][0]}}"
|
|
|
|
when: gen_tokens|default(false)
|
|
|
|
|
2017-03-03 13:33:00 +00:00
|
|
|
- include: "gen_certs_{{ cert_management }}.yml"
|
2016-12-08 13:36:00 +00:00
|
|
|
tags: k8s-secrets
|
2017-02-08 21:41:36 +00:00
|
|
|
|
|
|
|
- include: sync_kube_master_certs.yml
|
|
|
|
when: cert_management == "vault" and inventory_hostname in groups['kube-master']
|
|
|
|
tags: k8s-secrets
|
2017-02-17 21:22:34 +00:00
|
|
|
|
2017-02-08 21:41:36 +00:00
|
|
|
- include: sync_kube_node_certs.yml
|
|
|
|
when: cert_management == "vault" and inventory_hostname in groups['k8s-cluster']
|
|
|
|
tags: k8s-secrets
|
2017-02-17 21:22:34 +00:00
|
|
|
|
2016-02-11 22:08:16 +00:00
|
|
|
- include: gen_tokens.yml
|
2016-12-08 13:36:00 +00:00
|
|
|
tags: k8s-secrets
|