mirror of
https://github.com/techno-tim/k3s-ansible.git
synced 2026-08-09 07:23:19 +02:00
fix(metallb): deploy MetalLB with a non-BGP Cilium CNI (#692)
- Correct the Deploy metallb manifest/pool when condition so MetalLB is installed whenever kube-vip does not own the VIP range and Cilium BGP is disabled - The previous guard (cilium_bgp is not defined or cilium_iface is not defined) skipped MetalLB whenever cilium_iface was set, breaking the cilium + MetalLB scenario - Use cilium_bgp | default(false) | bool to stay safe when Cilium vars are not in scope (#644) while still deploying MetalLB for non-BGP Cilium - Retry the converge-side MetalLB resource wait so a transient kube API ServiceUnavailable does not abort the converge play - Add a regression test that evaluates both when conditions across flannel, calico, non-BGP cilium, BGP cilium, and kube-vip scenarios ci: skip CI for Dependabot pull requests - Add an actor guard to the CI workflow jobs so automatic Dependabot PRs do not consume the shared self-hosted runner - Dependabot CI runs need maintainer approval instead of auto-running
This commit is contained in:
@@ -23,6 +23,13 @@ cilium_mode: native
|
||||
cilium_tag: v1.20.0
|
||||
cilium_cli_tag: v0.19.7
|
||||
|
||||
# Shared retry/delay for remote manifest, asset downloads, and waiting on
|
||||
# Kubernetes resources. The CI runner's resolver intermittently times out on
|
||||
# GitHub-hosted domains and the kube API can transiently return
|
||||
# ServiceUnavailable, so retry transient DNS/network/API failures.
|
||||
download_retries: 5
|
||||
download_delay: 10
|
||||
|
||||
cluster_cidr: 10.52.0.0/16
|
||||
enable_bpf_masquerade: true
|
||||
kube_proxy_replacement: true
|
||||
|
||||
@@ -12,7 +12,11 @@
|
||||
- name: Deploy metallb pool
|
||||
ansible.builtin.include_tasks: metallb.yml
|
||||
tags: metallb
|
||||
when: kube_vip_lb_ip_range is not defined and (cilium_bgp is not defined or cilium_iface is not defined)
|
||||
# Deploy MetalLB unless kube-vip owns the load balancer IP range, or Cilium
|
||||
# BGP is enabled (Cilium then provides its own load balancing). The cilium_bgp
|
||||
# default keeps this safe when Cilium variables are not in scope at all (#644)
|
||||
# while still deploying MetalLB when a non-BGP Cilium CNI is in use.
|
||||
when: kube_vip_lb_ip_range is not defined and not (cilium_bgp | default(false) | bool)
|
||||
|
||||
- name: Remove tmp directory used for manifests
|
||||
ansible.builtin.file:
|
||||
|
||||
@@ -54,6 +54,12 @@
|
||||
{% if item.condition | default(False) -%}{{ item.condition }}{%- endif %}
|
||||
--timeout='{{ metal_lb_available_timeout }}'
|
||||
changed_when: false
|
||||
# The kube API can briefly return ServiceUnavailable while MetalLB converges,
|
||||
# which would otherwise abort the whole converge play on a transient error.
|
||||
register: metallb_wait_result
|
||||
until: metallb_wait_result.rc == 0
|
||||
retries: "{{ download_retries }}"
|
||||
delay: "{{ download_delay }}"
|
||||
run_once: true
|
||||
with_items:
|
||||
- description: controller
|
||||
|
||||
Reference in New Issue
Block a user