* chore(deps): apply dependency updates in one combined change
- Bump ansible-core to 2.19.11 and jmespath to 1.1.0 in requirements.in
- Regenerate the Python 3.11 pip-compile lock in requirements.txt
- Bump molecule-plugins to 23.6.0 while keeping molecule on the stable 6.x
series (avoids the molecule-plugins 26 major jump that broke vagrant module
resolution in CI)
- Bump ruamel-yaml-clib to 0.2.15
- Bump the zgosalvez/github-actions-ensure-sha-pinned-actions action to 5.0.6
(SHA-pinned) in lint.yml
* fix(server): make log_destination conditional boolean for ansible-core 2.19
- The always block's 'Save logs of k3s-init.service' task used when: log_destination
where log_destination is a path string derived from an env var
- ansible-core 2.19 rejects string-derived conditionals; evaluate the path as a
real boolean (non-empty) check so the conditional is a true boolean
- Required to keep the k3s_server role working with ansible-core 2.19.11 (the
dependency bump in this change)
* fix(verify): coerce regex_search assertions to bool for ansible-core 2.19
- ansible-core 2.19 requires assert conditionals to be boolean; regex_search
returns a string, which is now rejected
- Wrap all regex_search results used in assert.that with | bool so the calico,
cilium, metallb, and kube-vip image-tag checks produce boolean results
* fix(verify): use boolean is regex_search test instead of | bool
- | bool on a regex_search result coerces a tag string like v0.16.0 to False
in ansible-core 2.19, failing the image-tag assertions
- Use the is regex_search test which returns a real boolean without string
coercion for the calico, cilium, metallb, and kube-vip image assertions
* fix(verify): use is not none for regex_search assertions
- ansible-core 2.19 has no "is regex_search" test and rejects bool string
coercion, so use the regex_search filter with an "is not none" comparison,
which yields a real boolean for the image-tag assertions
- Applies to calico, cilium, metallb, and kube-vip image checks
* fix(metallb): retry transient apiserver resets in config tests
- The Layer 2 and BGP final configuration checks ran a kubectl get per
resource with no retry, so a transient connection refused from the kube
API could abort converge
- Mirror the download_retries/download_delay retry pattern used by the
'Wait for MetalLB resources' task so these checks survive api server
resets on slow runners
- Correct the Deploy metallb manifest/pool when condition so MetalLB is
installed whenever kube-vip does not own the VIP range and Cilium BGP
is disabled
- The previous guard (cilium_bgp is not defined or cilium_iface is not
defined) skipped MetalLB whenever cilium_iface was set, breaking the
cilium + MetalLB scenario
- Use cilium_bgp | default(false) | bool to stay safe when Cilium vars are
not in scope (#644) while still deploying MetalLB for non-BGP Cilium
- Retry the converge-side MetalLB resource wait so a transient kube API
ServiceUnavailable does not abort the converge play
- Add a regression test that evaluates both when conditions across flannel,
calico, non-BGP cilium, BGP cilium, and kube-vip scenarios
ci: skip CI for Dependabot pull requests
- Add an actor guard to the CI workflow jobs so automatic Dependabot PRs
do not consume the shared self-hosted runner
- Dependabot CI runs need maintainer approval instead of auto-running
* fix(metallb): guard cilium_bgp variable before evaluating
- The 'Deploy metallb manifest' and 'Deploy metallb pool' conditionals evaluate
'not cilium_bgp' directly, which raises an undefined-variable error when the
k3s_server role runs without cilium_bgp in scope and no Cilium variables are set
- Guard with 'cilium_bgp is not defined' so the condition resolves cleanly when
Cilium BGP is not configured
- Fixes#644
* docs(apiserver): clarify apiserver_endpoint must be a free routable IP
- Note that apiserver_endpoint must be an unassigned, routable IP on the
network and that it is exposed by kube-vip / MetalLB
- Fixes#678
* fix(molecule): wait for MetalLB resources before asserting images
- The MetalLB image-tag assertion crashed with 'list object has no element 0'
when the controller Deployment was not yet observable at verify time
- Retry the MetalLB controller/speaker lookup until the resources appear
- Fail with a clear message if MetalLB is genuinely absent
- delegate cgroups for transient K3s server units\n- verify inventory node registration without legacy role labels\n- wait for bootstrap CRDs before replacing the transient service
- pin kube-vip and cluster traffic to the private guest interface\n- disable disposable guest firewalls and verify API reachability before joins\n- keep control-plane orchestration on the primary and preserve failure diagnostics
- Preserve explicit per-host server initialization overrides\n- Build default join arguments from the delegated host variables\n- Keep initialization commands out of normal task output
* Change to FQCN with ansible-lint fixer
Since ansible-base 2.10 (later ansible-core), FQCN is the new way to go.
Updated .ansible-lint with a production profile and removed fqcn in skip_list.
Updated .yamllint with rules needed.
Ran ansible-lint --fix=all, then manually applied some minor changes.
* Changed octal value in molecule/ipv6/prepare.yml
If k3s_create_kubectl_symlink is set to false the kubectl symlink will
not be created.
If k3s_create_crictl_symlink is set to false the crictl symlink will not
be created.
By default the symlinks will be created. The default behavior is not
changed.
Signed-off-by: Christian Berendt <berendt@osism.tech>
Co-authored-by: Techno Tim <timothystewart6@gmail.com>
* ➕ Add default values to roles
* 🚚 Move to use meta files for roles
* 🛠 Fix descriptions
* ➕ Add meta for server
* 🚧 WIP
* 🌟 Complete
* 🧹 Ran and fix lint errors
* 🔨 Fix required and default conflict
---------
Co-authored-by: Techno Tim <timothystewart6@gmail.com>
* Add option to disable MetalLB, for use w/ ext LBs
* Add option to disable MetalLB, for use w/ ext LBs - add defaults
* Skip MetalLB with tags instead of flag
For improved flexibility and maintainability.
* Update tasks in node role to use 'group_name_master' variable instead
of hardcoded 'master' group name
* Update tasks in master role to use 'group_name_master' variable instead
of hardcoded 'master' group name
* Update tasks in post role to use 'group_name_master' variable instead of
hardcoded 'master' group name
Signed-off-by: Christian Berendt <berendt@23technologies.cloud>
* Update pre-commit actions
This was done by running "pre-commit autoupdate --freeze".
* Remove pre-commit only dependencies from requirements.in
Including them in the file would create the illusion that those were the
versions actually used in CI, but they are not. The exact versions are
determined by the pre-commit hooks which are pinned in
.pre-commit-config.yaml.
* Ansible Lint: Fix role-name[path]
* Ansible Lint: Fix name[play]
* Ansible Lint: Fix key-order[task]
* Ansible Lint: Fix jinja[spacing]
* Ansible Lint: Fix no-free-form
* Ansible Lint: Fix var-naming[no-reserved]
* Ansible Lint: Fix yaml[comments]
* Ansible Lint: Fix yaml[line-length]
* Ansible Lint: Fix name[casing]
* Ansible Lint: Fix no-changed-when
* Ansible Lint: Fix fqcn[action]
* Ansible Lint: Fix args[module]
* Improve task naming