--- - name: "cluster/gen_kube_node_certs | Ensure kube_cert_dir exists" file: path: "{{ kube_cert_dir }}" state: directory - name: gen_kube_master_certs | Add the kube role uri: url: "https://{{ hostvars[groups.vault|first]['vault_leader'] }}:{{ vault_port }}/v1/pki/roles/kubernetes" headers: "{{ hostvars[groups.vault|first]['vault_headers'] }}" method: POST body_format: json body: "{{ vault_default_role_permissions }}" status_code: 204 when: inventory_hostname == groups["kube-master"]|first - include: ../gen_cert.yml vars: gen_cert_alt_names: "{{ groups['kube-master'] | join(',') }},localhost" gen_cert_copy_ca: "{{ true if item == vault_kube_master_certs_needed|first else false }}" gen_cert_hosts: "{{ groups['kube-master'] }}" gen_cert_ip_sans: >- {%- for host in groups["kube-master"] -%} {{ hostvars[host]["ansible_default_ipv4"]["address"] }} {%- if not loop.last -%},{%- endif -%} {%- endfor -%} ,127.0.0.1,::1 gen_cert_path: "{{ item }}" gen_cert_vault_headers: "{{ hostvars[groups.vault|first]['vault_headers'] }}" gen_cert_vault_role: kubernetes gen_cert_vault_url: "https://{{ hostvars[groups.vault|first]['vault_leader'] }}:{{ vault_port }}" with_items: "{{ vault_kube_master_certs_needed|default([]) }}"