forked from tim/k3s-ansible
bb006cf157
* fix(calico): support split CRDs for current releases - Download the v1_crd_projectcalico_org.yaml bundle before the operator - Apply both files with server-side apply and force-conflicts per the upstream upgrade procedure - Wait for the operator Deployment and for the managed CRDs to be Established after the operator starts - Replace the create/rescue/replace flow with an idempotent apply that no longer conceals partial failures - Verify TigeraStatus for calico and apiserver is Available, not just that Pods exist * feat(dependencies): upgrade supported cluster components - Bump K3s to v1.36.2+k3s1, Calico to v3.32.1, Cilium to v1.20.0, kube-vip to v1.2.2, kube-vip cloud provider to v0.0.12, and MetalLB to v0.16.0 across sample inventory, role defaults, and argument specs - Pin the Cilium CLI with a new cilium_cli_tag (v0.19.7) instead of the floating stable.txt lookup - Replace the CiliumBGPPeeringPolicy v2alpha1 BGP template with the v2 CiliumBGPClusterConfig, CiliumBGPPeerConfig, CiliumBGPAdvertisement, and CiliumLoadBalancerIPPool resource set - Move Cilium load balancer Helm keys from bpf.loadBalancer to the valid top-level loadBalancer path - Add preflight schema validation and remove the deprecated policy after the v2 objects are accepted - Wait for cilium status after installation - Pin kube-vip RBAC in a repository template instead of fetching a mutable URL, and include EndpointSlice permissions - Fix the kube-vip bgppeers format to address:ASN comma-separated peers - Fail clearly when the MetalLB speaker tag replacement does not apply - Drop the obsolete MetalLB webhook service name version branch * test(molecule): verify upgraded cluster components - Assert every node reports the expected K3s kubelet version - Verify the active CNI (Flannel / Calico / Cilium) is Ready and runs the expected image tag, including Calico TigeraStatus Available - Verify the active load balancer (MetalLB / kube-vip) runs the expected image tags and that MetalLB is absent when kube-vip is active - Assert no Flannel DaemonSet remains when Calico or Cilium is enabled - Assert the example LoadBalancer address falls inside the configured pool range - Add a manifest-only Cilium BGP regression test that renders the v2 template with zero, one, and multiple neighbors and rejects any v2alpha1 or CiliumBGPPeeringPolicy output * fix(dependencies): correct dependency version pins - Set the sample kube-vip image to v1.2.2 and repair the damaged comment - Pin the kube-vip cloud provider default to v0.0.12 in the task URL - Set the MetalLB controller argument-spec default to v0.16.0 - Restore the MetalLB available timeout default to 240s * docs(dependencies): document current cluster versions - Update kube-vip, kube-vip cloud provider, and MetalLB defaults - Add cilium_tag and cilium_cli_tag rows - Explain that MetalLB v0.16.0 is the application image target even though a newer chart-only tag (metallb-chart-0.16.1) exists - Add an existing-cluster upgrade warning covering the K3s etcd 3.5.26 bridge and one-minor-at-a-time rule, consecutive Cilium minor upgrades, Calico v3 resource UID handling, and MetalLB app vs chart tags * fix(dependencies): address PR review findings - Read the MetalLB speaker tag check from the managed host with slurp instead of a controller-side file lookup, and match the full image reference - Restore the tigera-operator namespace on the Calico operator Deployment wait while keeping the managed CRD waits cluster-scoped - Make Molecule verify inputs durable and scenario-specific via a per-scenario verify-vars.yml, driven by explicit verify_cni/verify_lb values instead of non-persisted converge facts - Rename the kube-vip multi-peer BGP env var from bgppeers to bgp_peers and vip_cidr to vip_subnet so v1.2.2 actually reads them - Map the legacy Cilium routed mode to tunnel and stop passing the alias directly to the chart - Use return-code based failed_when on apply and preflight commands so non-error failures are no longer treated as success - Clarify the sequential K3s upgrade path and backups in the README - Add kube-vip and MetalLB regression tests and a Cilium mode mapping unit * fix(dependencies): resolve re-review findings - correct the Calico TigeraStatus resource kind\n- document tunnel as the supported Cilium routing mode\n- validate load balancer addresses across range and CIDR pools * fix(molecule): verify embedded flannel instead of a flannel DaemonSet - K3s 1.36 runs flannel embedded in the k3s agent rather than as a kube-flannel-ds DaemonSet, so the flannel verifier queried a workload that no longer exists and failed the verify step - For the flannel scenarios, assert every node is Ready and that neither the Calico nor the Cilium namespace exists - Drop the now-invalid kube-flannel-ds DaemonSet assertion * fix(molecule): wait for the LoadBalancer address before asserting reachability - The nginx LoadBalancer service had no ingress address when the reachability assertion ran, so status.loadBalancer.ingress[0].ip was undefined and the ipwrap filter failed during verify - Poll the service until MetalLB or kube-vip assigns an external IP - Record the assigned address once and reuse it for the reachability probe and the pool membership checks * fix(ci): harden calico apiserver wait and extend molecule job timeout - Bump calico system resources wait retries 30->60 and delay 7->10 so the slow-to-reconcile calico-apiserver deployment has enough time under nested-virt - Raise the molecule step timeout-minutes from 90 to 150 to accommodate contended 5-node scenarios (cilium, kube-vip) that were hitting the 90-min cap * fix(calico): treat optional API server as best-effort on converge - The Calico API server (calico-apiserver) is an optional add-on for managing Calico policy through the projectcalico.org/v3 Kubernetes API; it is not required for Calico CNI data plane operation - With Calico v3.32.1 on K3s 1.36 the tigera-operator never provisions the calico-apiserver namespace, causing the converge wait to fail deterministically - Keep the strict wait for core Calico components (typha, kube-controllers, calico-node, csi-node-driver) and make the API server wait tolerate failure - Restrict the TigeraStatus Available check to the calico status, matching the upstream v3.32.1 K3s quickstart which validates without the API server
93 lines
2.4 KiB
Django/Jinja
93 lines
2.4 KiB
Django/Jinja
# Cilium BGP Control Plane v2 resources.
|
|
# Replace the deprecated v2alpha1 CiliumBGPPeeringPolicy that was removed
|
|
# in Cilium 1.19.
|
|
{% set _cilium_default_peer = {'peer_address': cilium_bgp_peer_address, 'peer_asn': cilium_bgp_peer_asn} %}
|
|
{% set _cilium_peers = _cilium_bgp_neighbors if _cilium_bgp_neighbors | length > 0 else [_cilium_default_peer] %}
|
|
apiVersion: cilium.io/v2
|
|
kind: CiliumBGPPeerConfig
|
|
metadata:
|
|
name: cilium-peer
|
|
spec:
|
|
# Matches the timers and multihop used by the previous v2alpha1 policy.
|
|
ebgpMultihop: 10
|
|
timers:
|
|
connectRetryTimeSeconds: 120
|
|
holdTimeSeconds: 90
|
|
keepAliveTimeSeconds: 30
|
|
gracefulRestart:
|
|
enabled: true
|
|
restartTimeSeconds: 120
|
|
families:
|
|
- afi: ipv4
|
|
safi: unicast
|
|
advertisements:
|
|
matchLabels:
|
|
advertise: "bgp"
|
|
---
|
|
apiVersion: cilium.io/v2
|
|
kind: CiliumBGPClusterConfig
|
|
metadata:
|
|
name: cilium-bgp
|
|
spec:
|
|
# Explicitly select every node so the BGP instance runs across the cluster.
|
|
nodeSelector:
|
|
matchExpressions:
|
|
- key: somekey
|
|
operator: NotIn
|
|
values: ['never-used-value']
|
|
bgpInstances:
|
|
- name: "instance-{{ cilium_bgp_my_asn }}"
|
|
localASN: {{ cilium_bgp_my_asn }}
|
|
peers:
|
|
{% for peer in _cilium_peers %}
|
|
- name: "peer-{{ peer.peer_asn }}-{{ loop.index }}"
|
|
peerASN: {{ peer.peer_asn }}
|
|
peerAddress: {{ peer.peer_address }}
|
|
peerConfigRef:
|
|
name: cilium-peer
|
|
{% endfor %}
|
|
{% if cilium_exportPodCIDR %}
|
|
---
|
|
apiVersion: cilium.io/v2
|
|
kind: CiliumBGPAdvertisement
|
|
metadata:
|
|
name: cilium-pod-cidrs
|
|
labels:
|
|
advertise: "bgp"
|
|
spec:
|
|
advertisements:
|
|
- advertisementType: "PodCIDR"
|
|
{% endif %}
|
|
---
|
|
apiVersion: cilium.io/v2
|
|
kind: CiliumBGPAdvertisement
|
|
metadata:
|
|
name: cilium-lb-services
|
|
labels:
|
|
advertise: "bgp"
|
|
spec:
|
|
advertisements:
|
|
- advertisementType: "Service"
|
|
service:
|
|
addresses:
|
|
- LoadBalancerIP
|
|
# Advertise all Services carrying an ingress address from the pool.
|
|
selector:
|
|
matchExpressions:
|
|
- key: somekey
|
|
operator: NotIn
|
|
values: ['never-used-value']
|
|
---
|
|
apiVersion: cilium.io/v2
|
|
kind: CiliumLoadBalancerIPPool
|
|
metadata:
|
|
name: "01-lb-pool"
|
|
spec:
|
|
blocks:
|
|
{% if "/" in cilium_bgp_lb_cidr %}
|
|
- cidr: {{ cilium_bgp_lb_cidr }}
|
|
{% else %}
|
|
- start: {{ cilium_bgp_lb_cidr.split('-')[0] }}
|
|
stop: {{ cilium_bgp_lb_cidr.split('-')[1] }}
|
|
{% endif %}
|