mirror of
https://github.com/techno-tim/k3s-ansible.git
synced 2026-08-09 07:23:19 +02:00
feat(prereq): add toggle to disable swap on all cluster nodes (#698)
k3s recommends swap be disabled on every node. Add a disable_swap toggle (default true) to the prereq role that turns swap off now and comments out the swap entries in /etc/fstab so swap stays off across reboots. The change is applied uniformly across all k3s_cluster hosts (all-or-nothing) since leaving swap on for some nodes but not others creates uneven scheduling and latency. - roles/prereq/defaults/main.yml: add disable_swap: true default - roles/prereq/tasks/main.yml: idempotent swapoff -a and fstab comment-out block gated on disable_swap - inventory/sample/group_vars/all.yml: document the new sample variable - README.md: document the disable_swap option - .github/scripts/test-disable-swap.sh: regression test - .pre-commit-config.yaml: wire the test into pre-commit Closes #670
This commit is contained in:
Executable
+37
@@ -0,0 +1,37 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
set -Eeuo pipefail
|
||||
|
||||
repo_root="$(git rev-parse --show-toplevel)"
|
||||
prereq_defaults="$repo_root/roles/prereq/defaults/main.yml"
|
||||
prereq_tasks="$repo_root/roles/prereq/tasks/main.yml"
|
||||
|
||||
# #670: k3s recommends swap be disabled on all nodes. The prereq role must expose
|
||||
# a disable_swap toggle (defaulting to true) that turns swap off now and comments
|
||||
# out the /etc/fstab swap entries so swap stays off across reboots.
|
||||
grep -Eq -- '^disable_swap: true' "$prereq_defaults" || {
|
||||
printf 'prereq defaults are missing disable_swap: true\n' >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
grep -Fq -- 'Disable swap on all cluster nodes' "$prereq_tasks" || {
|
||||
printf 'prereq tasks are missing the swap-disable block\n' >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
grep -Fq -- 'swapoff -a' "$prereq_tasks" || {
|
||||
printf 'swap-disable block does not run swapoff -a\n' >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
grep -Fq -- '/etc/fstab' "$prereq_tasks" || {
|
||||
printf 'swap-disable block does not comment out /etc/fstab swap entries\n' >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
if ! grep -Eq -- 'when: disable_swap' "$prereq_tasks"; then
|
||||
printf 'swap-disable block is not gated on the disable_swap toggle\n' >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
printf 'Swap disable regression test passed\n'
|
||||
@@ -68,6 +68,12 @@ repos:
|
||||
language: system
|
||||
pass_filenames: false
|
||||
files: ^site\.yml$|^\.github/scripts/test-unique-hostname-precheck\.sh$
|
||||
- id: disable-swap-test
|
||||
name: Disable swap test
|
||||
entry: .github/scripts/test-disable-swap.sh
|
||||
language: system
|
||||
pass_filenames: false
|
||||
files: ^roles/prereq/(tasks/main|defaults/main)\.yml$|^\.github/scripts/test-disable-swap\.sh$
|
||||
- id: cilium-bgp-manifest-test
|
||||
name: Cilium BGP manifest test
|
||||
entry: python3 .github/scripts/test-cilium-bgp-manifest.py
|
||||
|
||||
@@ -261,6 +261,7 @@ See the commands [here](https://technotim.com/posts/k3s-etcd-ansible/#testing-yo
|
||||
| `reboot` (playbook) | `concurrent_reboots` | int/string | `100%` | Not required | Number (or percentage) of nodes to reboot at a time for a staggered reboot |
|
||||
| `reboot` (playbook) | `wait_seconds_after_reboot` | int | `0` | Not required | Pause in seconds between staggered reboot batches |
|
||||
| `prereq` | `system_timezone` | string | `null` | Not required | Timezone to be set on all nodes |
|
||||
| `prereq` | `disable_swap` | bool | `true` | Not required | Disable swap on all cluster nodes (swapoff + comment out /etc/fstab swap entries), all-or-nothing |
|
||||
| `proxmox_lxc`, `reset_proxmox_lxc` | `proxmox_lxc_ct_ids` | list | ❌ | Required | Proxmox container ID list |
|
||||
| `raspberrypi` | `state` | string | `present` | Not required | Indicates whether the k3s prerequisites for Raspberry Pi should be set up (possible values are `present` and `absent`) |
|
||||
|
||||
|
||||
@@ -7,6 +7,10 @@ systemd_dir: /etc/systemd/system
|
||||
# Set your timezone
|
||||
system_timezone: Your/Timezone
|
||||
|
||||
# k3s recommends swap be disabled on every cluster node. Applied uniformly to all
|
||||
# nodes (all-or-nothing) in the prereq role. Set to false to leave swap enabled.
|
||||
disable_swap: true
|
||||
|
||||
# interface which will be used for flannel
|
||||
# Defaults to each host's default IPv4 interface (e.g. eth0, enp1s0, ens3)
|
||||
# so KVM/cloud hosts without eth0 work out of the box. Override per-host if needed.
|
||||
|
||||
@@ -1,4 +1,6 @@
|
||||
---
|
||||
disable_swap: true
|
||||
|
||||
secure_path:
|
||||
RedHat: /sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin
|
||||
Suse: /usr/sbin:/usr/bin:/sbin:/bin:/usr/local/bin
|
||||
|
||||
@@ -4,6 +4,28 @@
|
||||
name: "{{ system_timezone }}"
|
||||
when: (system_timezone is defined) and (system_timezone != "Your/Timezone")
|
||||
|
||||
# k3s recommends swap be disabled on all nodes. Disabling swap is all-or-nothing
|
||||
# across the cluster: leaving it enabled on some nodes but not others creates
|
||||
# uneven scheduling/latency behavior. This block turns swap off and comments out
|
||||
# the swap entries in /etc/fstab so it stays off across reboots. It is idempotent
|
||||
# and a no-op when swap is already disabled or swapoff is unavailable.
|
||||
- name: Disable swap on all cluster nodes
|
||||
when: disable_swap
|
||||
block:
|
||||
- name: Turn off swap now
|
||||
ansible.builtin.command: swapoff -a
|
||||
register: swapoff_result
|
||||
changed_when: false
|
||||
failed_when: false
|
||||
|
||||
- name: Comment out swap entries in fstab
|
||||
ansible.builtin.replace:
|
||||
path: /etc/fstab
|
||||
regexp: '^([^#][^\n]*\s+swap\s+)'
|
||||
replace: '# \\1'
|
||||
register: fstab_swap
|
||||
|
||||
|
||||
- name: Set SELinux to disabled state
|
||||
ansible.posix.selinux:
|
||||
state: disabled
|
||||
|
||||
Reference in New Issue
Block a user