2017-09-18 13:30:57 +01:00
|
|
|
---
|
|
|
|
- name: Set external kube-apiserver endpoint
|
|
|
|
set_fact:
|
2019-01-16 16:30:50 +03:00
|
|
|
external_apiserver_address: >-
|
2019-01-21 04:27:42 -05:00
|
|
|
{%- if loadbalancer_apiserver is defined and loadbalancer_apiserver.address is defined -%}
|
|
|
|
{{ loadbalancer_apiserver.address }}
|
2017-09-18 13:30:57 +01:00
|
|
|
{%- else -%}
|
2019-01-16 16:30:50 +03:00
|
|
|
{{ kube_apiserver_access_address }}
|
|
|
|
{%- endif -%}
|
|
|
|
external_apiserver_port: >-
|
2019-01-21 14:43:27 +03:00
|
|
|
{%- if loadbalancer_apiserver is defined and loadbalancer_apiserver.address is defined and loadbalancer_apiserver.port is defined -%}
|
2019-01-16 16:30:50 +03:00
|
|
|
{{ loadbalancer_apiserver.port|default(kube_apiserver_port) }}
|
|
|
|
{%- else -%}
|
|
|
|
{{ kube_apiserver_port }}
|
2017-09-18 13:30:57 +01:00
|
|
|
{%- endif -%}
|
2017-10-05 10:43:04 +03:00
|
|
|
tags:
|
|
|
|
- facts
|
2017-09-18 13:30:57 +01:00
|
|
|
|
2019-06-06 02:06:11 -07:00
|
|
|
- name: Create kube config dir for current/ansible become user
|
2017-09-18 13:30:57 +01:00
|
|
|
file:
|
2019-06-06 02:06:11 -07:00
|
|
|
path: "{{ ansible_env.HOME | default('/root') }}/.kube"
|
2017-09-18 13:30:57 +01:00
|
|
|
mode: "0700"
|
|
|
|
state: directory
|
|
|
|
|
2019-06-06 02:06:11 -07:00
|
|
|
- name: Copy admin kubeconfig to current/ansible become user home
|
2017-09-18 13:30:57 +01:00
|
|
|
copy:
|
|
|
|
src: "{{ kube_config_dir }}/admin.conf"
|
2019-06-06 02:06:11 -07:00
|
|
|
dest: "{{ ansible_env.HOME | default('/root') }}/.kube/config"
|
2017-09-18 13:30:57 +01:00
|
|
|
remote_src: yes
|
2018-05-14 09:29:48 +00:00
|
|
|
mode: "0600"
|
2017-09-18 13:30:57 +01:00
|
|
|
backup: yes
|
|
|
|
|
2019-01-28 12:59:15 +03:00
|
|
|
- name: Create kube artifacts dir
|
|
|
|
file:
|
|
|
|
path: "{{ artifacts_dir }}"
|
|
|
|
mode: "0750"
|
|
|
|
state: directory
|
|
|
|
delegate_to: localhost
|
2020-06-25 17:14:38 +02:00
|
|
|
connection: local
|
2019-01-28 12:59:15 +03:00
|
|
|
become: no
|
|
|
|
run_once: yes
|
2020-04-16 08:32:45 -04:00
|
|
|
when: kubeconfig_localhost
|
2019-01-28 12:59:15 +03:00
|
|
|
|
2019-07-11 09:46:54 +03:00
|
|
|
- name: Wait for k8s apiserver
|
|
|
|
wait_for:
|
|
|
|
host: "{{ kube_apiserver_access_address }}"
|
|
|
|
port: "{{ kube_apiserver_port }}"
|
|
|
|
timeout: 180
|
|
|
|
|
2019-04-19 16:01:54 +03:00
|
|
|
# NOTE(mattymo): Please forgive this workaround
|
2019-01-16 16:30:50 +03:00
|
|
|
- name: Generate admin kubeconfig with external api endpoint
|
|
|
|
shell: >-
|
2019-04-19 16:01:54 +03:00
|
|
|
mkdir -p {{ kube_config_dir }}/external_kubeconfig &&
|
|
|
|
{{ bin_dir }}/kubeadm
|
|
|
|
init phase
|
|
|
|
kubeconfig admin
|
|
|
|
--kubeconfig-dir {{ kube_config_dir }}/external_kubeconfig
|
2019-05-08 22:38:36 +02:00
|
|
|
--cert-dir {{ kube_cert_dir }}
|
2019-01-16 16:30:50 +03:00
|
|
|
--apiserver-advertise-address {{ external_apiserver_address }}
|
|
|
|
--apiserver-bind-port {{ external_apiserver_port }}
|
2019-05-06 12:29:36 +02:00
|
|
|
>/dev/null && cat {{ kube_config_dir }}/external_kubeconfig/admin.conf &&
|
2019-04-19 16:01:54 +03:00
|
|
|
rm -rf {{ kube_config_dir }}/external_kubeconfig
|
2019-03-26 11:03:19 +01:00
|
|
|
environment: "{{ proxy_env }}"
|
2019-01-16 16:30:50 +03:00
|
|
|
run_once: yes
|
2020-04-16 08:32:45 -04:00
|
|
|
register: raw_admin_kubeconfig
|
|
|
|
when: kubeconfig_localhost
|
|
|
|
|
|
|
|
- name: Convert kubeconfig to YAML
|
|
|
|
set_fact:
|
|
|
|
admin_kubeconfig: "{{ raw_admin_kubeconfig.stdout | from_yaml }}"
|
|
|
|
when: kubeconfig_localhost
|
|
|
|
|
|
|
|
- name: Override username in kubeconfig
|
|
|
|
set_fact:
|
|
|
|
final_admin_kubeconfig: "{{ admin_kubeconfig | combine(override_cluster_name, recursive=true) | combine(override_context, recursive=true) | combine(override_user, recursive=true) }}"
|
|
|
|
vars:
|
|
|
|
cluster_infos: "{{ admin_kubeconfig['clusters'][0]['cluster'] }}"
|
|
|
|
user_certs: "{{ admin_kubeconfig['users'][0]['user'] }}"
|
|
|
|
username: "kubernetes-admin-{{ cluster_name }}"
|
|
|
|
context: "kubernetes-admin-{{ cluster_name }}@{{ cluster_name }}"
|
|
|
|
override_cluster_name: "{{ { 'clusters': [ { 'cluster': cluster_infos, 'name': cluster_name } ] } }}"
|
|
|
|
override_context: "{{ { 'contexts': [ { 'context': { 'user': username, 'cluster': cluster_name }, 'name': context } ], 'current-context': context } }}"
|
|
|
|
override_user: "{{ { 'users': [ { 'name': username, 'user': user_certs } ] } }}"
|
|
|
|
when: kubeconfig_localhost
|
2019-01-16 16:30:50 +03:00
|
|
|
|
|
|
|
- name: Write admin kubeconfig on ansible host
|
|
|
|
copy:
|
2020-04-16 08:32:45 -04:00
|
|
|
content: "{{ final_admin_kubeconfig | to_nice_yaml(indent=2) }}"
|
2017-09-18 13:30:57 +01:00
|
|
|
dest: "{{ artifacts_dir }}/admin.conf"
|
2019-01-16 16:30:50 +03:00
|
|
|
mode: 0640
|
|
|
|
delegate_to: localhost
|
2020-06-25 17:14:38 +02:00
|
|
|
connection: local
|
2019-01-16 16:30:50 +03:00
|
|
|
become: no
|
2017-09-18 13:30:57 +01:00
|
|
|
run_once: yes
|
2020-04-16 08:32:45 -04:00
|
|
|
when: kubeconfig_localhost
|
2017-09-18 13:30:57 +01:00
|
|
|
|
|
|
|
- name: Copy kubectl binary to ansible host
|
2019-10-17 08:26:37 -04:00
|
|
|
fetch:
|
2017-09-18 13:30:57 +01:00
|
|
|
src: "{{ bin_dir }}/kubectl"
|
2018-04-09 13:19:26 +03:00
|
|
|
dest: "{{ artifacts_dir }}/kubectl"
|
2019-10-17 08:26:37 -04:00
|
|
|
flat: yes
|
|
|
|
validate_checksum: no
|
2017-09-18 13:30:57 +01:00
|
|
|
become: no
|
|
|
|
run_once: yes
|
2020-04-16 08:32:45 -04:00
|
|
|
when: kubectl_localhost
|
2018-02-16 20:53:35 +08:00
|
|
|
|
|
|
|
- name: create helper script kubectl.sh on ansible host
|
|
|
|
copy:
|
|
|
|
content: |
|
|
|
|
#!/bin/bash
|
2020-06-14 23:57:57 +03:00
|
|
|
${BASH_SOURCE%/*}/kubectl --kubeconfig=${BASH_SOURCE%/*}/admin.conf "$@"
|
2018-02-16 20:53:35 +08:00
|
|
|
dest: "{{ artifacts_dir }}/kubectl.sh"
|
|
|
|
mode: 0755
|
|
|
|
become: no
|
|
|
|
run_once: yes
|
|
|
|
delegate_to: localhost
|
2020-06-25 17:14:38 +02:00
|
|
|
connection: local
|
2020-04-16 08:32:45 -04:00
|
|
|
when: kubectl_localhost and kubeconfig_localhost
|