diff --git a/.github/ISSUE_TEMPLATE.md b/.github/ISSUE_TEMPLATE.md index fdf9187..d9553de 100644 --- a/.github/ISSUE_TEMPLATE.md +++ b/.github/ISSUE_TEMPLATE.md @@ -35,7 +35,12 @@ k3s_version: "" ansible_user: NA systemd_dir: "" -container_iface: "" +flannel_iface: "" + +#calico_iface: "" +calico_ebpf: "" +calico_cidr: "" +calico_tag: "" apiserver_endpoint: "" diff --git a/inventory/sample/group_vars/all.yml b/inventory/sample/group_vars/all.yml index f997363..3f5a366 100644 --- a/inventory/sample/group_vars/all.yml +++ b/inventory/sample/group_vars/all.yml @@ -7,14 +7,13 @@ systemd_dir: /etc/systemd/system # Set your timezone system_timezone: "Your/Timezone" -# node interface which will be used for the container network interface (flannel or calico) -container_iface: "eth0" +# interface which will be used for flannel +flannel_iface: "eth0" -# set use_calico to true to use tigera operator/calico instead of the default CNI flannel -# install reference: https://docs.tigera.io/calico/latest/getting-started/kubernetes/k3s/multi-node-install#install-calico -use_calico: false +# uncomment calico_iface to use tigera operator/calico cni instead of flannel https://docs.tigera.io/calico/latest/about +#calico_iface: "eth0" calico_ebpf: false # use eBPF dataplane instead of iptables https://docs.tigera.io/calico/latest/operations/ebpf -calico_cidr: "10.52.0.0/16" # pod cidr pool +calico_cidr: "10.52.0.0/16" # calico cluster pod cidr pool calico_tag: "v3.27.0" # calico version tag # apiserver_endpoint is virtual ip-address which will be configured on each master @@ -27,14 +26,14 @@ k3s_token: "some-SUPER-DEDEUPER-secret-password" # The IP on which the node is reachable in the cluster. # Here, a sensible default is provided, you can still override # it for each of your hosts, though. -k3s_node_ip: '{{ ansible_facts[container_iface]["ipv4"]["address"] }}' +k3s_node_ip: "{{ ansible_facts[(calico_iface | default(flannel_iface))]['ipv4']['address'] }}" # Disable the taint manually by setting: k3s_master_taint = false k3s_master_taint: "{{ true if groups['node'] | default([]) | length >= 1 else false }}" # these arguments are recommended for servers as well as agents: extra_args: >- - {{ '--flannel-iface=' + container_iface if not use_calico else '' }} + {{ '--flannel-iface=' + flannel_iface if calico_iface is not defined else '' }} --node-ip={{ k3s_node_ip }} # change these to your liking, the only required are: --disable servicelb, --tls-san {{ apiserver_endpoint }} @@ -42,10 +41,10 @@ extra_args: >- extra_server_args: >- {{ extra_args }} {{ '--node-taint node-role.kubernetes.io/master=true:NoSchedule' if k3s_master_taint else '' }} - {% if use_calico %} + {% if calico_iface is defined %} --flannel-backend=none --disable-network-policy - --cluster-cidr={{ calico_cidr }} + --cluster-cidr={{ calico_cidr | default('10.52.0.0/16') }} {% endif %} --tls-san {{ apiserver_endpoint }} --disable servicelb diff --git a/molecule/default/overrides.yml b/molecule/default/overrides.yml index 7bd9a56..4eea472 100644 --- a/molecule/default/overrides.yml +++ b/molecule/default/overrides.yml @@ -6,7 +6,7 @@ ansible.builtin.set_fact: # See: # https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant - container_iface: eth1 + flannel_iface: eth1 # The test VMs might be a bit slow, so we give them more time to join the cluster: retry_count: 45 diff --git a/molecule/ipv6/overrides.yml b/molecule/ipv6/overrides.yml index 7ac7be3..44bbc07 100644 --- a/molecule/ipv6/overrides.yml +++ b/molecule/ipv6/overrides.yml @@ -6,7 +6,7 @@ ansible.builtin.set_fact: # See: # https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant - container_iface: eth1 + flannel_iface: eth1 # In this scenario, we have multiple interfaces that the VIP could be # broadcasted on. Since we have assigned a dedicated private network @@ -27,13 +27,13 @@ - fdad:bad:ba55::1b:0/112 - 192.168.123.80-192.168.123.90 - # k3s_node_ip is by default set to the IPv4 address of container_iface. + # k3s_node_ip is by default set to the IPv4 address of flannel_iface. # We want IPv6 addresses here of course, so we just specify them # manually below. k3s_node_ip: "{{ node_ipv4 }},{{ node_ipv6 }}" - name: Override host variables (2/2) - # Since "extra_args" depends on "k3s_node_ip" and "container_iface" we have + # Since "extra_args" depends on "k3s_node_ip" and "flannel_iface" we have # to set this AFTER overriding the both of them. ansible.builtin.set_fact: # A few extra server args are necessary: diff --git a/molecule/ipv6/prepare.yml b/molecule/ipv6/prepare.yml index dfeeba7..cea50d8 100644 --- a/molecule/ipv6/prepare.yml +++ b/molecule/ipv6/prepare.yml @@ -30,7 +30,7 @@ name: net.ipv6.conf.{{ item }}.accept_dad value: "0" with_items: - - "{{ container_iface }}" + - "{{ flannel_iface }}" - name: Write IPv4 configuration ansible.builtin.template: diff --git a/molecule/ipv6/templates/55-flannel-ipv4.yaml.j2 b/molecule/ipv6/templates/55-flannel-ipv4.yaml.j2 index 45bd56e..6f68777 100644 --- a/molecule/ipv6/templates/55-flannel-ipv4.yaml.j2 +++ b/molecule/ipv6/templates/55-flannel-ipv4.yaml.j2 @@ -3,6 +3,6 @@ network: version: 2 renderer: networkd ethernets: - {{ container_iface }}: + {{ flannel_iface }}: addresses: - {{ node_ipv4 }}/24 diff --git a/molecule/single_node/overrides.yml b/molecule/single_node/overrides.yml index 191ad6f..799275e 100644 --- a/molecule/single_node/overrides.yml +++ b/molecule/single_node/overrides.yml @@ -6,7 +6,7 @@ ansible.builtin.set_fact: # See: # https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant - container_iface: eth1 + flannel_iface: eth1 # The test VMs might be a bit slow, so we give them more time to join the cluster: retry_count: 45 diff --git a/roles/k3s_server_post/tasks/main.yml b/roles/k3s_server_post/tasks/main.yml index 1cb6122..505eebf 100644 --- a/roles/k3s_server_post/tasks/main.yml +++ b/roles/k3s_server_post/tasks/main.yml @@ -2,7 +2,7 @@ - name: Deploy calico include_tasks: calico.yml tags: calico - when: use_calico == true + when: calico_iface is defined - name: Deploy metallb pool include_tasks: metallb.yml diff --git a/roles/k3s_server_post/templates/calico.crs.j2 b/roles/k3s_server_post/templates/calico.crs.j2 index 26bf645..d33099d 100644 --- a/roles/k3s_server_post/templates/calico.crs.j2 +++ b/roles/k3s_server_post/templates/calico.crs.j2 @@ -9,13 +9,13 @@ spec: calicoNetwork: # Note: The ipPools section cannot be modified post-install. ipPools: - - blockSize: {{ calico_blockSize if calico_blockSize is defined else '26' }} - cidr: {{ calico_cidr if calico_cidr is defined else '10.52.0.0/16' }} - encapsulation: {{ calico_encapsulation if calico_encapsulation is defined else 'VXLANCrossSubnet' }} - natOutgoing: {{ calico_natOutgoing if calico_natOutgoing is defined else 'Enabled' }} - nodeSelector: {{ calico_nodeSelector if calico_nodeSelector is defined else 'all()' }} + - blockSize: {{ calico_blockSize | default('26') }} + cidr: {{ calico_cidr | default('10.52.0.0/16') }} + encapsulation: {{ calico_encapsulation | default('VXLANCrossSubnet') }} + natOutgoing: {{ calico_natOutgoing | default('Enabled') }} + nodeSelector: {{ calico_nodeSelector | default('all()') }} nodeAddressAutodetectionV4: - interface: {{ container_iface if container_iface is defined else 'eth0' }} + interface: {{ calico_iface }} linuxDataplane: {{ 'BPF' if calico_ebpf else 'Iptables' }} ---