mirror of
https://github.com/techno-tim/k3s-ansible.git
synced 2026-08-08 23:13:19 +02:00
fix(k3s-server): serialize control-plane joins
- Wait for each additional master to register before starting the next\n- Keep k3s initialization diagnostics bounded and sanitized
This commit is contained in:
committed by
Techno Tim
parent
a52e2ea72c
commit
94dbffaef7
@@ -9,6 +9,7 @@
|
||||
--unit=k3s-init.service --since=-30min --lines=5000
|
||||
changed_when: false
|
||||
failed_when: false
|
||||
no_log: true
|
||||
register: k3s_init_log
|
||||
|
||||
- name: Fetch k3s-init.service status
|
||||
@@ -38,7 +39,9 @@
|
||||
dest: "{{ log_destination }}/k3s-init@{{ ansible_hostname }}.log"
|
||||
mode: "0644"
|
||||
vars:
|
||||
content: >-
|
||||
{{ ('=== k3s-init.service status ===\n' + k3s_init_status.stdout
|
||||
+ '\n\n=== k3s-init.service journal ===\n' + k3s_init_log.stdout)
|
||||
| regex_replace('--token(?:=|\\s+)[^\\s]+', '--token ***') }}
|
||||
content: |
|
||||
=== k3s-init.service status ===
|
||||
{{ k3s_init_status.stdout | regex_replace('--token(?:=| +)[^ ]+', '--token ***') }}
|
||||
|
||||
=== k3s-init.service journal ===
|
||||
{{ k3s_init_log.stdout | regex_replace('--token(?:=| +)[^ ]+', '--token ***') }}
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
---
|
||||
- name: Verify primary Kubernetes API is reachable from {{ joining_master }}
|
||||
ansible.builtin.wait_for:
|
||||
host: "{{ hostvars[groups[group_name_master | default('master')][0]].k3s_node_ip | split(',') | first }}"
|
||||
port: 6443
|
||||
connect_timeout: 5
|
||||
timeout: "{{ retry_count | default(20) * 2 }}"
|
||||
delegate_to: "{{ joining_master }}"
|
||||
|
||||
- name: Join transient k3s-init service for {{ joining_master }}
|
||||
ansible.builtin.command:
|
||||
cmd: >-
|
||||
systemd-run -p RestartSec=2 -p Restart=on-failure --unit=k3s-init
|
||||
k3s server {{ hostvars[joining_master].server_init_args }}
|
||||
creates: "{{ systemd_dir }}/k3s-init.service"
|
||||
delegate_to: "{{ joining_master }}"
|
||||
|
||||
- name: Wait for primary registration of {{ joining_master }}
|
||||
ansible.builtin.command:
|
||||
cmd: >-
|
||||
{{ k3s_kubectl_binary | default('k3s kubectl') }} get node {{ joining_master }}
|
||||
delegate_to: "{{ groups[group_name_master | default('master')][0] }}"
|
||||
register: joined_master
|
||||
until: joined_master.rc == 0
|
||||
retries: "{{ retry_count | default(20) }}"
|
||||
delay: 2
|
||||
changed_when: false
|
||||
@@ -51,13 +51,13 @@
|
||||
run_once: true
|
||||
when: groups[group_name_master | default('master')] | length > 1
|
||||
|
||||
- name: Join additional masters inside the transient k3s-init service
|
||||
ansible.builtin.command:
|
||||
cmd: systemd-run -p RestartSec=2 -p Restart=on-failure --unit=k3s-init k3s server {{ server_init_args }}
|
||||
creates: "{{ systemd_dir }}/k3s-init.service"
|
||||
when:
|
||||
- groups[group_name_master | default('master')] | length > 1
|
||||
- ansible_hostname != hostvars[groups[group_name_master | default('master')][0]]['ansible_hostname']
|
||||
- name: Join additional masters one at a time
|
||||
ansible.builtin.include_tasks: join_master.yml
|
||||
loop: "{{ groups[group_name_master | default('master')][1:] }}"
|
||||
loop_control:
|
||||
loop_var: joining_master
|
||||
run_once: true
|
||||
when: groups[group_name_master | default('master')] | length > 1
|
||||
|
||||
- name: Verification
|
||||
when: not ansible_check_mode
|
||||
|
||||
Reference in New Issue
Block a user