mirror of
https://github.com/techno-tim/k3s-ansible.git
synced 2026-08-09 07:23:19 +02:00
Compare commits
239 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| bb006cf157 | |||
| b6363cdfc5 | |||
| 83f205177d | |||
| 5c288e8f3e | |||
| dfcfbc1f3f | |||
| c3606a7847 | |||
| 35939315cd | |||
| 997ea63a3b | |||
| 68d03acc68 | |||
| 2babd39c89 | |||
| bbca35331d | |||
| 4c50fbbe10 | |||
| 10bde4eff0 | |||
| 57f234c8da | |||
| fb9a0bebd1 | |||
| 4990157d35 | |||
| 73fae0826c | |||
| 57a22e364d | |||
| 9b220c1629 | |||
| a0d78ff317 | |||
| 999cf3ee05 | |||
| 1402f33108 | |||
| 94dbffaef7 | |||
| a52e2ea72c | |||
| bb3843dbb1 | |||
| 87ea8160c1 | |||
| 5bc347aed4 | |||
| 665e274820 | |||
| 5747bfce0e | |||
| 29b7aa1b72 | |||
| 2fad0a8db6 | |||
| 5cbbf7371b | |||
| 422621c69c | |||
| 39988a9bee | |||
| 133a84b564 | |||
| 6b79057f6c | |||
| 4c0b1ee8f3 | |||
| 11f9505460 | |||
| 850301fbc4 | |||
| 983e11322e | |||
| a4df16cf87 | |||
| f8ababb7bf | |||
| 90eb5e4b41 | |||
| 97ed29b4a2 | |||
| fc2225ab8d | |||
| d99f6a96f2 | |||
| fab302fd91 | |||
| eddbcbfb76 | |||
| 03ae8de0d5 | |||
| d136fa4486 | |||
| b906cfbf72 | |||
| 2c04f38e2c | |||
| 3435f43748 | |||
| 924a2f528c | |||
| 2892ac3858 | |||
| df8e8dd591 | |||
| 3a0303d130 | |||
| b077a49e1f | |||
| 635f0b21b3 | |||
| 4a64ad42df | |||
| d0537736de | |||
| 2149827800 | |||
| 2d0596209e | |||
| 3a20500f9c | |||
| 9ce9fecc5b | |||
| 668d7fb896 | |||
| 6cee0e9051 | |||
| 6823ad51d5 | |||
| 1a521ea0d9 | |||
| e48bb6df26 | |||
| 36893c27fb | |||
| e8cd10d49b | |||
| b86156b995 | |||
| 072f1a321d | |||
| 2f46a54240 | |||
| bf0418d77f | |||
| d88eb80df0 | |||
| f50d335451 | |||
| d6597150c7 | |||
| 353f7ab641 | |||
| c7c727c3dc | |||
| 0422bfa2ac | |||
| 0333406725 | |||
| f4a19d368b | |||
| 02d212c007 | |||
| 80095250e9 | |||
| 4fe2c92795 | |||
| b3f2a4addc | |||
| cb03ee829e | |||
| 9e2e82faeb | |||
| 7c1f6cbe42 | |||
| 604eb7a6e6 | |||
| a204ed5169 | |||
| b6608ca3e4 | |||
| 8252a45dfd | |||
| c99f098c2e | |||
| 7867b87d85 | |||
| dfe19f3731 | |||
| a46d97a28d | |||
| dc9d571f17 | |||
| 6742551e5c | |||
| fb3478a086 | |||
| 518c5bb62a | |||
| 3f5d8dfe9f | |||
| efbfadcb93 | |||
| f81ec04ba2 | |||
| 8432d3bc66 | |||
| 14ae9df1bc | |||
| f175716339 | |||
| 955c6f6b4a | |||
| 3b74985767 | |||
| 9ace193ade | |||
| 83a0be3afd | |||
| 029eba6102 | |||
| 0c8253b3a5 | |||
| 326b71dfa2 | |||
| b95d6dd2cc | |||
| e4146b4ca9 | |||
| 1fb10faf7f | |||
| ea3b3c776a | |||
| 5beca87783 | |||
| 6ffc25dfe5 | |||
| bcd37a6904 | |||
| 8dd3ffc825 | |||
| f6ba208b5c | |||
| a22d8f7aaf | |||
| 05fb6b566d | |||
| 3aeb7d69ea | |||
| 61bf3971ef | |||
| 3f06a11c8d | |||
| 3888a29bb1 | |||
| 98ef696f31 | |||
| de26a79a4c | |||
| ab7ca9b551 | |||
| c5f71c9e2e | |||
| 0f23e7e258 | |||
| 121061d875 | |||
| db53f595fd | |||
| 7b6b24ce4d | |||
| a5728da35e | |||
| cda7c92203 | |||
| d910b83bf3 | |||
| 101313f880 | |||
| 12be355867 | |||
| aa09e3e9df | |||
| 511c410451 | |||
| df9c6f3014 | |||
| 5ae8fd1223 | |||
| e2e9881f0f | |||
| edf0c9eebd | |||
| 7669fd4721 | |||
| cddbfc8e40 | |||
| 70e658cf98 | |||
| 7badfbd7bd | |||
| e880f08d26 | |||
| 95b2836dfc | |||
| 505c2eeff2 | |||
| 9b6d551dd6 | |||
| a64e882fb7 | |||
| 38e773315b | |||
| 70ddf7b63c | |||
| fb3128a783 | |||
| 2e318e0862 | |||
| 0607eb8aa4 | |||
| a9904d1562 | |||
| 9707bc8a58 | |||
| e635bd2626 | |||
| 1aabb5a927 | |||
| 215690b55b | |||
| bd44a9b126 | |||
| 8d61fe81e5 | |||
| c0ff304f22 | |||
| 83077ecdd1 | |||
| 33ae0d4970 | |||
| edd4838407 | |||
| 5c79ea9b71 | |||
| 3d204ad851 | |||
| 13bd868faa | |||
| c564a8562a | |||
| 0d6d43e7ca | |||
| c0952288c2 | |||
| 1c9796e98b | |||
| 288c4089e0 | |||
| 49f0a2ce6b | |||
| 6c4621bd56 | |||
| 3e16ab6809 | |||
| 83fe50797c | |||
| 2db0b3024c | |||
| 6b2af77e74 | |||
| d1d1bc3d91 | |||
| 3a1a7a19aa | |||
| 030eeb4b75 | |||
| 4aeeb124ef | |||
| 511c020bec | |||
| c47da38b53 | |||
| 6448948e9f | |||
| 7bc198ab26 | |||
| 65bbc8e2ac | |||
| dc2976e7f6 | |||
| 5a7ba98968 | |||
| 10c6ef1d57 | |||
| ed4d888e3d | |||
| 49d6d484ae | |||
| 96c49c864e | |||
| 60adb1de42 | |||
| e023808f2f | |||
| 511ec493d6 | |||
| be3e72e173 | |||
| e33cbe52c1 | |||
| c06af919f3 | |||
| b86384c439 | |||
| bf2bd1edc5 | |||
| e98e3ee77c | |||
| 78f7a60378 | |||
| e64fea760d | |||
| 764e32c778 | |||
| e6cf14ea78 | |||
| da049dcc28 | |||
| 2604caa483 | |||
| 82d820805f | |||
| da72884a5b | |||
| 17a74b66c8 | |||
| 88d679ecb6 | |||
| 6bf3bcce92 | |||
| cff815a031 | |||
| f892029fcf | |||
| 6b37ba5e60 | |||
| b1fee44403 | |||
| a1c7175bd1 | |||
| 69d3bdcd88 | |||
| 5268ef305a | |||
| a840571733 | |||
| b1370406ea | |||
| 12d57a07d0 | |||
| 4f3b8ec9e0 | |||
| 45ddd65e74 | |||
| b2a62ea4eb | |||
| a8697edc99 | |||
| d3218f5d5c |
+22
-8
@@ -1,17 +1,31 @@
|
|||||||
---
|
---
|
||||||
|
profile: production
|
||||||
exclude_paths:
|
exclude_paths:
|
||||||
# default paths
|
# default paths
|
||||||
- '.cache/'
|
- .cache/
|
||||||
- '.github/'
|
- .ansible/
|
||||||
- 'test/fixtures/formatting-before/'
|
- .github/
|
||||||
- 'test/fixtures/formatting-prettier/'
|
- test/fixtures/formatting-before/
|
||||||
|
- test/fixtures/formatting-prettier/
|
||||||
|
|
||||||
# The "converge" and "reset" playbooks use import_playbook in
|
# The "converge" and "reset" playbooks use import_playbook in
|
||||||
# conjunction with the "env" lookup plugin, which lets the
|
# conjunction with the "env" lookup plugin, which lets the
|
||||||
# syntax check of ansible-lint fail.
|
# syntax check of ansible-lint fail.
|
||||||
- 'molecule/**/converge.yml'
|
- molecule/**/converge.yml
|
||||||
- 'molecule/**/prepare.yml'
|
- molecule/**/prepare.yml
|
||||||
- 'molecule/**/reset.yml'
|
- molecule/**/reset.yml
|
||||||
|
|
||||||
|
# Scenario verify inputs are plain variable files, not playbooks. They are
|
||||||
|
# loaded as vars, not executed, so ansible-lint must not treat them as plays.
|
||||||
|
- molecule/**/verify-vars.yml
|
||||||
|
|
||||||
|
# The file was generated by galaxy ansible - don't mess with it.
|
||||||
|
- galaxy.yml
|
||||||
|
|
||||||
skip_list:
|
skip_list:
|
||||||
- 'fqcn-builtins'
|
- var-naming[no-role-prefix]
|
||||||
|
|
||||||
|
# The Molecule Vagrant driver injects this module at runtime. The custom create
|
||||||
|
# playbook is syntax-checked separately against the exact pinned plugin module.
|
||||||
|
mock_modules:
|
||||||
|
- vagrant
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
|
|
||||||
<!-- It's a good idea to check this post first for general troubleshooting https://github.com/techno-tim/k3s-ansible/discussions/19 -->
|
<!-- It's a good idea to check this post first for general troubleshooting https://github.com/timothystewart6/k3s-ansible/discussions/19 -->
|
||||||
|
|
||||||
<!--- Provide a general summary of the issue in the Title above -->
|
<!--- Provide a general summary of the issue in the Title above -->
|
||||||
|
|
||||||
@@ -37,6 +37,11 @@ systemd_dir: ""
|
|||||||
|
|
||||||
flannel_iface: ""
|
flannel_iface: ""
|
||||||
|
|
||||||
|
#calico_iface: ""
|
||||||
|
calico_ebpf: ""
|
||||||
|
calico_cidr: ""
|
||||||
|
calico_tag: ""
|
||||||
|
|
||||||
apiserver_endpoint: ""
|
apiserver_endpoint: ""
|
||||||
|
|
||||||
k3s_token: "NA"
|
k3s_token: "NA"
|
||||||
@@ -46,6 +51,9 @@ extra_agent_args: ""
|
|||||||
|
|
||||||
kube_vip_tag_version: ""
|
kube_vip_tag_version: ""
|
||||||
|
|
||||||
|
kube_vip_cloud_provider_tag_version: ""
|
||||||
|
kube_vip_lb_ip_range: ""
|
||||||
|
|
||||||
metal_lb_speaker_tag_version: ""
|
metal_lb_speaker_tag_version: ""
|
||||||
metal_lb_controller_tag_version: ""
|
metal_lb_controller_tag_version: ""
|
||||||
|
|
||||||
@@ -74,4 +82,4 @@ node
|
|||||||
## Possible Solution
|
## Possible Solution
|
||||||
<!--- Not obligatory, but suggest a fix/reason for the bug, -->
|
<!--- Not obligatory, but suggest a fix/reason for the bug, -->
|
||||||
|
|
||||||
- [ ] I've checked the [General Troubleshooting Guide](https://github.com/techno-tim/k3s-ansible/discussions/20)
|
- [ ] I've checked the [General Troubleshooting Guide](https://github.com/timothystewart6/k3s-ansible/discussions/20)
|
||||||
|
|||||||
@@ -11,4 +11,5 @@
|
|||||||
- [ ] Ran `site.yml` playbook
|
- [ ] Ran `site.yml` playbook
|
||||||
- [ ] Ran `reset.yml` playbook
|
- [ ] Ran `reset.yml` playbook
|
||||||
- [ ] Did not add any unnecessary changes
|
- [ ] Did not add any unnecessary changes
|
||||||
|
- [ ] Ran pre-commit install at least once before committing
|
||||||
- [ ] 🚀
|
- [ ] 🚀
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
self-hosted-runner:
|
||||||
|
labels:
|
||||||
|
- k3s-ci
|
||||||
|
- virtualbox
|
||||||
|
- nested-virt
|
||||||
@@ -9,3 +9,18 @@ updates:
|
|||||||
ignore:
|
ignore:
|
||||||
- dependency-name: "*"
|
- dependency-name: "*"
|
||||||
update-types: ["version-update:semver-major"]
|
update-types: ["version-update:semver-major"]
|
||||||
|
|
||||||
|
- package-ecosystem: "github-actions"
|
||||||
|
directory: "/"
|
||||||
|
schedule:
|
||||||
|
interval: "daily"
|
||||||
|
rebase-strategy: "auto"
|
||||||
|
|
||||||
|
- package-ecosystem: "docker"
|
||||||
|
directory: "/"
|
||||||
|
schedule:
|
||||||
|
interval: "daily"
|
||||||
|
rebase-strategy: "auto"
|
||||||
|
ignore:
|
||||||
|
- dependency-name: "*"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
|||||||
+75
-21
@@ -1,37 +1,91 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
# download-boxes.sh
|
# download-boxes.sh
|
||||||
# Check all molecule.yml files for required Vagrant boxes and download the ones that are not
|
# Validate the pinned Vagrant box set and download exact versions that are not
|
||||||
# already present on the system.
|
# already present in VAGRANT_HOME.
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
GIT_ROOT=$(git rev-parse --show-toplevel)
|
GIT_ROOT=$(git rev-parse --show-toplevel)
|
||||||
PROVIDER=virtualbox
|
PROVIDER=virtualbox
|
||||||
|
LOCK_FILE="${VAGRANT_BOX_LOCK_FILE:-${GIT_ROOT}/.github/vagrant-boxes.lock}"
|
||||||
|
|
||||||
# Read all boxes for all platforms from the "molecule.yml" files
|
MOLECULE_YML_PATH=("${GIT_ROOT}"/molecule/*/molecule.yml)
|
||||||
all_boxes=$(cat "${GIT_ROOT}"/molecule/*/molecule.yml |
|
|
||||||
yq -r '.platforms[].box' | # Read the "box" property of each node under "platforms"
|
|
||||||
grep --invert-match --regexp=--- | # Filter out file separators
|
|
||||||
sort |
|
|
||||||
uniq)
|
|
||||||
|
|
||||||
# Read the boxes that are currently present on the system (for the current provider)
|
# Extract the unique boxes referenced by the scenarios.
|
||||||
|
declared_boxes=$(for file in "${MOLECULE_YML_PATH[@]}"; do
|
||||||
|
yq -r '.platforms[].box' "$file"
|
||||||
|
done | sort -u)
|
||||||
|
|
||||||
|
if [[ ! -r "$LOCK_FILE" ]]; then
|
||||||
|
printf 'Vagrant box lock file is missing or unreadable: %s\n' "$LOCK_FILE" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
lock_entries=$(awk '
|
||||||
|
/^[[:space:]]*#/ || NF == 0 { next }
|
||||||
|
NF != 3 {
|
||||||
|
printf "Invalid lock entry on line %d: expected box, version, architecture\n", NR > "/dev/stderr"
|
||||||
|
invalid = 1
|
||||||
|
next
|
||||||
|
}
|
||||||
|
{ print $1 " " $2 " " $3 }
|
||||||
|
END { exit invalid }
|
||||||
|
' "$LOCK_FILE")
|
||||||
|
|
||||||
|
duplicate_boxes=$(printf '%s\n' "$lock_entries" | awk '{ print $1 }' | sort | uniq -d)
|
||||||
|
if [[ -n "$duplicate_boxes" ]]; then
|
||||||
|
printf 'Duplicate Vagrant box lock entries:\n%s\n' "$duplicate_boxes" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
locked_boxes=$(printf '%s\n' "$lock_entries" | sort)
|
||||||
|
locked_names=$(printf '%s\n' "$locked_boxes" | awk '{ print $1 }')
|
||||||
|
missing_locks=$(comm -23 <(printf '%s\n' "$declared_boxes") <(printf '%s\n' "$locked_names"))
|
||||||
|
unused_locks=$(comm -13 <(printf '%s\n' "$declared_boxes") <(printf '%s\n' "$locked_names"))
|
||||||
|
|
||||||
|
if [[ -n "$missing_locks" || -n "$unused_locks" ]]; then
|
||||||
|
if [[ -n "$missing_locks" ]]; then
|
||||||
|
printf 'Scenario boxes missing from the lock file:\n%s\n' "$missing_locks" >&2
|
||||||
|
fi
|
||||||
|
if [[ -n "$unused_locks" ]]; then
|
||||||
|
printf 'Lock entries not referenced by a scenario:\n%s\n' "$unused_locks" >&2
|
||||||
|
fi
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf 'Pinned Vagrant boxes:\n%s\n' "$locked_boxes"
|
||||||
|
|
||||||
|
# Read exact box, provider, version, and architecture tuples already present.
|
||||||
present_boxes=$(
|
present_boxes=$(
|
||||||
(vagrant box list |
|
vagrant box list --machine-readable |
|
||||||
grep "${PROVIDER}" | # Filter by boxes available for the current provider
|
awk -F, -v expected_provider="$PROVIDER" '
|
||||||
awk '{print $1;}' | # The box name is the first word in each line
|
$3 == "box-name" { name = $4; next }
|
||||||
sort |
|
$3 == "box-provider" { provider = $4; next }
|
||||||
uniq) ||
|
$3 == "box-version" { version = $4; next }
|
||||||
echo "" # In case any of these commands fails, just use an empty list
|
$3 == "box-architecture" {
|
||||||
|
architecture = $4
|
||||||
|
if (provider == expected_provider) {
|
||||||
|
print name " " version " " architecture
|
||||||
|
}
|
||||||
|
name = provider = version = architecture = ""
|
||||||
|
}
|
||||||
|
' |
|
||||||
|
sort -u
|
||||||
)
|
)
|
||||||
|
|
||||||
# The boxes that we need to download are the ones present in $all_boxes, but not $present_boxes.
|
download_boxes=$(comm -23 \
|
||||||
download_boxes=$(comm -2 -3 <(echo "${all_boxes}") <(echo "${present_boxes}"))
|
<(printf '%s\n' "$locked_boxes") \
|
||||||
|
<(printf '%s\n' "$present_boxes"))
|
||||||
|
|
||||||
# Actually download the necessary boxes
|
if [[ -n "$download_boxes" ]]; then
|
||||||
if [ -n "${download_boxes}" ]; then
|
printf '%s\n' "$download_boxes" | while read -r box version architecture; do
|
||||||
echo "${download_boxes}" | while IFS= read -r box; do
|
vagrant box add \
|
||||||
vagrant box add --provider "${PROVIDER}" "${box}"
|
--provider "$PROVIDER" \
|
||||||
|
--box-version "$version" \
|
||||||
|
--architecture "$architecture" \
|
||||||
|
"$box"
|
||||||
done
|
done
|
||||||
|
else
|
||||||
|
printf 'All pinned Vagrant boxes are already present.\n'
|
||||||
fi
|
fi
|
||||||
|
|||||||
Executable
+249
@@ -0,0 +1,249 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
usage() {
|
||||||
|
printf '%s\n' \
|
||||||
|
'Usage: cleanup-runner-resources.sh [--snapshot|--dry-run|--apply]' \
|
||||||
|
'' \
|
||||||
|
'Discover and, with --apply, remove only VirtualBox resources referenced by' \
|
||||||
|
'repository-owned Molecule Vagrant state. The default is --dry-run.'
|
||||||
|
}
|
||||||
|
|
||||||
|
mode="dry-run"
|
||||||
|
case "${1:-}" in
|
||||||
|
"") ;;
|
||||||
|
--snapshot) mode="snapshot" ;;
|
||||||
|
--dry-run) mode="dry-run" ;;
|
||||||
|
--apply) mode="apply" ;;
|
||||||
|
--help|-h) usage; exit 0 ;;
|
||||||
|
*) usage >&2; exit 2 ;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
home_dir="${HOME:?HOME must be set}"
|
||||||
|
molecule_root="${K3S_CI_MOLECULE_ROOT:-${home_dir}/.cache/molecule}"
|
||||||
|
repository_name="${K3S_CI_MOLECULE_PROJECT:-k3s-ansible}"
|
||||||
|
virtualbox_root="${K3S_CI_VIRTUALBOX_ROOT:-${home_dir}/VirtualBox VMs}"
|
||||||
|
hostonly_marker="${K3S_CI_HOSTONLY_MARKER:-${home_dir}/.cache/k3s-ci/hostonly-interfaces}"
|
||||||
|
|
||||||
|
record_hostonly() {
|
||||||
|
local marker_dir="${hostonly_marker%/*}"
|
||||||
|
local marker_tmp="${hostonly_marker}.tmp"
|
||||||
|
local hostonly_inventory
|
||||||
|
if ! hostonly_inventory="$(VBoxManage list hostonlyifs)"; then
|
||||||
|
fail_closed 'unable to inventory VirtualBox host-only interfaces'
|
||||||
|
fi
|
||||||
|
mkdir -p -- "$marker_dir"
|
||||||
|
awk -F': ' '
|
||||||
|
/^Name:/ { name=$2 }
|
||||||
|
/^IPAddress:/ { print name "|" $2 }
|
||||||
|
' <<< "$hostonly_inventory" > "$marker_tmp"
|
||||||
|
mv -- "$marker_tmp" "$hostonly_marker"
|
||||||
|
chmod 600 "$hostonly_marker"
|
||||||
|
printf 'Recorded host-only interface baseline: %s\n' "$hostonly_marker"
|
||||||
|
}
|
||||||
|
|
||||||
|
cleanup_hostonly() {
|
||||||
|
local hostonly_inventory
|
||||||
|
if [[ ! -f "$hostonly_marker" ]]; then
|
||||||
|
printf 'No host-only interface baseline found; leaving interfaces unchanged.\n'
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ! hostonly_inventory="$(VBoxManage list hostonlyifs)"; then
|
||||||
|
fail_closed 'unable to inventory VirtualBox host-only interfaces'
|
||||||
|
fi
|
||||||
|
|
||||||
|
while IFS='|' read -r interface_name interface_ip; do
|
||||||
|
[[ "$interface_name" == vboxnet* ]] || continue
|
||||||
|
[[ "$interface_ip" == 192.168.30.* || "$interface_ip" == fdad:bad:ba55:* ]] || continue
|
||||||
|
if grep -Fqx "${interface_name}|${interface_ip}" "$hostonly_marker"; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
if [[ "$mode" == apply ]]; then
|
||||||
|
VBoxManage hostonlyif remove "$interface_name"
|
||||||
|
printf 'Removed host-only interface %s (%s)\n' "$interface_name" "$interface_ip"
|
||||||
|
else
|
||||||
|
printf 'Would remove host-only interface %s (%s)\n' "$interface_name" "$interface_ip"
|
||||||
|
fi
|
||||||
|
done < <(awk -F': ' '
|
||||||
|
/^Name:/ { name=$2 }
|
||||||
|
/^IPAddress:/ { print name "|" $2 }
|
||||||
|
' <<< "$hostonly_inventory")
|
||||||
|
}
|
||||||
|
|
||||||
|
if [[ "$mode" == snapshot ]]; then
|
||||||
|
record_hostonly
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
resolve_existing_dir() {
|
||||||
|
local candidate="$1"
|
||||||
|
if [[ ! -d "$candidate" ]]; then
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
readlink -f -- "$candidate"
|
||||||
|
}
|
||||||
|
|
||||||
|
root_contains() {
|
||||||
|
local root="$1"
|
||||||
|
local path="$2"
|
||||||
|
[[ "$path" == "$root"/* ]]
|
||||||
|
}
|
||||||
|
|
||||||
|
is_supported_scenario() {
|
||||||
|
case "$1" in
|
||||||
|
default|single_node|calico|cilium|kube-vip|ipv6) return 0 ;;
|
||||||
|
*) return 1 ;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
is_unregistered_vm_error() {
|
||||||
|
grep -Eq 'Could not find a registered machine|VBOX_E_OBJECT_NOT_FOUND'
|
||||||
|
}
|
||||||
|
|
||||||
|
fail_closed() {
|
||||||
|
printf 'cleanup refused: %s\n' "$1" >&2
|
||||||
|
exit 3
|
||||||
|
}
|
||||||
|
|
||||||
|
if [[ ! "$repository_name" =~ ^[A-Za-z0-9._-]+$ ]]; then
|
||||||
|
fail_closed 'invalid Molecule repository name'
|
||||||
|
fi
|
||||||
|
|
||||||
|
print_inventory() {
|
||||||
|
local phase="$1"
|
||||||
|
printf '%s VirtualBox inventory:\n' "$phase"
|
||||||
|
VBoxManage list vms || true
|
||||||
|
VBoxManage list hdds || true
|
||||||
|
VBoxManage list hostonlyifs || true
|
||||||
|
}
|
||||||
|
|
||||||
|
molecule_root_real="$(resolve_existing_dir "$molecule_root" || true)"
|
||||||
|
if [[ -z "$molecule_root_real" ]]; then
|
||||||
|
printf 'No Molecule root exists: %s\n' "$molecule_root"
|
||||||
|
cleanup_hostonly
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
print_inventory before
|
||||||
|
|
||||||
|
repository_root_real="$(resolve_existing_dir "$molecule_root_real/$repository_name" || true)"
|
||||||
|
if [[ -z "$repository_root_real" ]]; then
|
||||||
|
printf 'No repository Molecule state root exists: %s\n' "$molecule_root_real/$repository_name"
|
||||||
|
cleanup_hostonly
|
||||||
|
print_inventory after
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
if ! root_contains "$molecule_root_real" "$repository_root_real"; then
|
||||||
|
fail_closed "repository Molecule state root is outside Molecule root: $repository_root_real"
|
||||||
|
fi
|
||||||
|
|
||||||
|
declare -a state_files=()
|
||||||
|
while IFS= read -r -d '' state_file; do
|
||||||
|
state_files+=("$state_file")
|
||||||
|
done < <(find "$repository_root_real" -mindepth 6 -maxdepth 6 -type f \
|
||||||
|
-path '*/.vagrant/machines/*/virtualbox/id' -print0 2>/dev/null)
|
||||||
|
|
||||||
|
if ((${#state_files[@]} == 0)); then
|
||||||
|
printf 'No repository-owned Molecule Vagrant state found under %s\n' "$repository_root_real"
|
||||||
|
cleanup_hostonly
|
||||||
|
print_inventory after
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
virtualbox_root_real="$(resolve_existing_dir "$virtualbox_root" || true)"
|
||||||
|
|
||||||
|
declare -a vm_records=()
|
||||||
|
for state_file in "${state_files[@]}"; do
|
||||||
|
if [[ ! -f "$state_file" ]]; then
|
||||||
|
printf 'Skipping Vagrant state removed with its stale scenario directory: %s\n' "$state_file"
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
state_file_real="$(readlink -f -- "$state_file")"
|
||||||
|
state_dir="${state_file_real%/.vagrant/machines/*/virtualbox/id}"
|
||||||
|
machine_dir="${state_file_real%/virtualbox/id}"
|
||||||
|
machine_name="${machine_dir##*/}"
|
||||||
|
scenario_name="${state_dir##*/}"
|
||||||
|
|
||||||
|
if ! root_contains "$repository_root_real" "$state_dir"; then
|
||||||
|
fail_closed "state path is outside the repository Molecule root: $state_file_real"
|
||||||
|
fi
|
||||||
|
if ! is_supported_scenario "$scenario_name"; then
|
||||||
|
fail_closed "unexpected Molecule scenario: $scenario_name"
|
||||||
|
fi
|
||||||
|
if [[ "$machine_name" != control* && "$machine_name" != node* ]]; then
|
||||||
|
fail_closed "unexpected Molecule machine name: $machine_name"
|
||||||
|
fi
|
||||||
|
|
||||||
|
vm_uuid="$(tr -d '[:space:]' < "$state_file_real")"
|
||||||
|
if [[ ! "$vm_uuid" =~ ^[0-9a-fA-F-]{36}$ ]]; then
|
||||||
|
fail_closed "invalid VirtualBox UUID in $state_file_real"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ! vm_info="$(VBoxManage showvminfo "$vm_uuid" --machinereadable 2>&1)"; then
|
||||||
|
if is_unregistered_vm_error <<< "$vm_info"; then
|
||||||
|
printf 'Stale Vagrant state without a registered VM: %s (%s)\n' "$machine_name" "$vm_uuid"
|
||||||
|
if [[ "$mode" == apply ]]; then
|
||||||
|
rm -rf -- "${state_dir}/.vagrant"
|
||||||
|
printf 'Removed stale Vagrant state: %s\n' "${state_dir}/.vagrant"
|
||||||
|
fi
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
fail_closed "unable to inspect VirtualBox VM $vm_uuid: $vm_info"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -z "$virtualbox_root_real" ]]; then
|
||||||
|
fail_closed "VirtualBox VM root does not exist: $virtualbox_root"
|
||||||
|
fi
|
||||||
|
|
||||||
|
cfg_file="$(awk -F= '$1 == "CfgFile" {gsub(/"/, "", $2); print $2; exit}' <<< "$vm_info")"
|
||||||
|
if [[ -z "$cfg_file" ]]; then
|
||||||
|
fail_closed "VirtualBox configuration path missing for $vm_uuid"
|
||||||
|
fi
|
||||||
|
cfg_file_real="$(readlink -f -- "$cfg_file")"
|
||||||
|
if ! root_contains "$virtualbox_root_real" "$cfg_file_real"; then
|
||||||
|
fail_closed "VM configuration is outside VirtualBox root: $cfg_file_real"
|
||||||
|
fi
|
||||||
|
|
||||||
|
while IFS= read -r disk_path; do
|
||||||
|
[[ -z "$disk_path" ]] && continue
|
||||||
|
disk_path_real="$(readlink -f -- "$disk_path" 2>/dev/null || true)"
|
||||||
|
if [[ -z "$disk_path_real" ]] || ! root_contains "$virtualbox_root_real" "$disk_path_real"; then
|
||||||
|
fail_closed "attached disk is outside VirtualBox root: $disk_path"
|
||||||
|
fi
|
||||||
|
done < <(awk -F= '$1 ~ /^(SATA|IDE|SCSI|SAS|VirtioSCSI|NVMe)-[0-9]+-[0-9]+$/ {gsub(/"/, "", $2); print $2}' <<< "$vm_info")
|
||||||
|
|
||||||
|
vm_records+=("$vm_uuid|$machine_name|$cfg_file_real")
|
||||||
|
done
|
||||||
|
|
||||||
|
if ((${#vm_records[@]} == 0)); then
|
||||||
|
printf 'No live repository-owned VirtualBox resources found\n'
|
||||||
|
cleanup_hostonly
|
||||||
|
print_inventory after
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
for record in "${vm_records[@]}"; do
|
||||||
|
IFS='|' read -r vm_uuid machine_name cfg_file_real <<< "$record"
|
||||||
|
if [[ "$mode" == dry-run ]]; then
|
||||||
|
printf 'Would remove VM %s (%s) config=%s\n' "$machine_name" "$vm_uuid" "$cfg_file_real"
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
vm_state="$(VBoxManage showvminfo "$vm_uuid" --machinereadable | awk -F= '$1 == "VMState" {gsub(/"/, "", $2); print $2; exit}')"
|
||||||
|
if [[ "$vm_state" != poweroff && "$vm_state" != saved ]]; then
|
||||||
|
VBoxManage controlvm "$vm_uuid" poweroff
|
||||||
|
fi
|
||||||
|
VBoxManage unregistervm "$vm_uuid" --delete
|
||||||
|
printf 'Removed VM %s (%s)\n' "$machine_name" "$vm_uuid"
|
||||||
|
done
|
||||||
|
|
||||||
|
cleanup_hostonly
|
||||||
|
print_inventory after
|
||||||
|
|
||||||
|
if [[ "$mode" == apply ]]; then
|
||||||
|
printf 'Repository-owned VM and host-only interface cleanup complete.\n'
|
||||||
|
else
|
||||||
|
printf 'Dry run complete. No resources were modified.\n'
|
||||||
|
fi
|
||||||
+47
@@ -0,0 +1,47 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
output_dir="${1:-${RUNNER_TEMP:-/tmp}/k3s-ci-diagnostics}"
|
||||||
|
mkdir -p -- "$output_dir"
|
||||||
|
umask 077
|
||||||
|
|
||||||
|
run_capture() {
|
||||||
|
local output_file="$1"
|
||||||
|
shift
|
||||||
|
{
|
||||||
|
printf '$'
|
||||||
|
printf ' %q' "$@"
|
||||||
|
printf '\n'
|
||||||
|
"$@"
|
||||||
|
} > "$output_dir/$output_file" 2>&1 || true
|
||||||
|
}
|
||||||
|
|
||||||
|
run_capture system.txt uname -a
|
||||||
|
run_capture runner-user.txt id
|
||||||
|
run_capture memory.txt free -h
|
||||||
|
run_capture disk.txt df -h
|
||||||
|
run_capture virtualbox-version VBoxManage --version
|
||||||
|
run_capture virtualbox-vms VBoxManage list vms
|
||||||
|
run_capture virtualbox-running-vms VBoxManage list runningvms
|
||||||
|
run_capture virtualbox-disks VBoxManage list hdds
|
||||||
|
run_capture virtualbox-hostonlyifs VBoxManage list hostonlyifs
|
||||||
|
run_capture virtualbox-groups VBoxManage list groups
|
||||||
|
run_capture vagrant-status vagrant global-status
|
||||||
|
run_capture molecule-state find "${HOME}/.cache/molecule" -maxdepth 6 -type f -path '*/.vagrant/machines/*/virtualbox/id' -print
|
||||||
|
|
||||||
|
scenario_name="${K3S_CI_SCENARIO_NAME:-}"
|
||||||
|
if [[ "$scenario_name" =~ ^[A-Za-z0-9_-]+$ ]]; then
|
||||||
|
molecule_state_dir="${HOME}/.cache/molecule/k3s-ansible/${scenario_name}"
|
||||||
|
for log_name in vagrant.out vagrant.err; do
|
||||||
|
if [[ -r "${molecule_state_dir}/${log_name}" ]]; then
|
||||||
|
cp -- "${molecule_state_dir}/${log_name}" "$output_dir/${scenario_name}-${log_name}"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -r /etc/vbox/networks.conf ]]; then
|
||||||
|
cp -- /etc/vbox/networks.conf "$output_dir/virtualbox-networks.conf"
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf 'Diagnostics written to %s\n' "$output_dir"
|
||||||
Executable
+44
@@ -0,0 +1,44 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
output_dir="${1:?output directory is required}"
|
||||||
|
interval="${2:-10}"
|
||||||
|
[[ "$interval" =~ ^[1-9][0-9]*$ ]] || {
|
||||||
|
printf 'monitor interval must be a positive integer\n' >&2
|
||||||
|
exit 2
|
||||||
|
}
|
||||||
|
|
||||||
|
mkdir -p -- "$output_dir"
|
||||||
|
umask 077
|
||||||
|
|
||||||
|
free -h > "$output_dir/memory-before.txt"
|
||||||
|
df -h > "$output_dir/disk-before.txt"
|
||||||
|
vmstat -w "$interval" > "$output_dir/vmstat.txt" &
|
||||||
|
vmstat_pid=$!
|
||||||
|
|
||||||
|
iostat_pid=""
|
||||||
|
if command -v iostat >/dev/null 2>&1; then
|
||||||
|
iostat -dx "$interval" > "$output_dir/iostat.txt" &
|
||||||
|
iostat_pid=$!
|
||||||
|
else
|
||||||
|
printf 'iostat is not installed on this runner\n' > "$output_dir/iostat-unavailable.txt"
|
||||||
|
fi
|
||||||
|
|
||||||
|
cleanup() {
|
||||||
|
local rc=$?
|
||||||
|
trap - EXIT INT TERM
|
||||||
|
kill "$vmstat_pid" 2>/dev/null || true
|
||||||
|
[[ -z "$iostat_pid" ]] || kill "$iostat_pid" 2>/dev/null || true
|
||||||
|
wait "$vmstat_pid" 2>/dev/null || true
|
||||||
|
[[ -z "$iostat_pid" ]] || wait "$iostat_pid" 2>/dev/null || true
|
||||||
|
free -h > "$output_dir/memory-after.txt"
|
||||||
|
df -h > "$output_dir/disk-after.txt"
|
||||||
|
exit "$rc"
|
||||||
|
}
|
||||||
|
trap cleanup EXIT INT TERM
|
||||||
|
|
||||||
|
while :; do
|
||||||
|
sleep 3600 &
|
||||||
|
wait $!
|
||||||
|
done
|
||||||
+211
@@ -0,0 +1,211 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
fail() {
|
||||||
|
printf 'Vagrant box master preparation refused: %s\n' "$1" >&2
|
||||||
|
exit 3
|
||||||
|
}
|
||||||
|
|
||||||
|
root_contains() {
|
||||||
|
local root="$1"
|
||||||
|
local path="$2"
|
||||||
|
[[ "$path" == "$root"/* ]]
|
||||||
|
}
|
||||||
|
|
||||||
|
read_machine_value() {
|
||||||
|
local machine_info="$1"
|
||||||
|
local key="$2"
|
||||||
|
awk -F= -v key="$key" '$1 == key {gsub(/"/, "", $2); print $2; exit}' <<< "$machine_info"
|
||||||
|
}
|
||||||
|
|
||||||
|
read_extra_data() {
|
||||||
|
local uuid="$1"
|
||||||
|
local key="$2"
|
||||||
|
local value
|
||||||
|
value="$(VBoxManage getextradata "$uuid" "$key" 2>/dev/null || true)"
|
||||||
|
[[ "$value" == 'Value: '* ]] || return 1
|
||||||
|
printf '%s\n' "${value#Value: }"
|
||||||
|
}
|
||||||
|
|
||||||
|
validate_owned_master() {
|
||||||
|
local uuid="$1"
|
||||||
|
local box="$2"
|
||||||
|
local version="$3"
|
||||||
|
local architecture="$4"
|
||||||
|
local machine_info cfg_file cfg_file_real vm_state groups disk_path disk_path_real
|
||||||
|
|
||||||
|
[[ "$uuid" =~ ^[0-9a-fA-F-]{36}$ ]] || return 1
|
||||||
|
machine_info="$(VBoxManage showvminfo "$uuid" --machinereadable 2>/dev/null)" || return 1
|
||||||
|
vm_state="$(read_machine_value "$machine_info" VMState)"
|
||||||
|
groups="$(read_machine_value "$machine_info" groups)"
|
||||||
|
cfg_file="$(read_machine_value "$machine_info" CfgFile)"
|
||||||
|
[[ "$vm_state" == poweroff ]] || return 1
|
||||||
|
[[ ",$groups," == *,/k3s-ansible/box-masters,* ]] || return 1
|
||||||
|
[[ -n "$cfg_file" ]] || return 1
|
||||||
|
cfg_file_real="$(readlink -f -- "$cfg_file" 2>/dev/null || true)"
|
||||||
|
[[ -n "$cfg_file_real" ]] || return 1
|
||||||
|
root_contains "$virtualbox_root_real" "$cfg_file_real" || return 1
|
||||||
|
|
||||||
|
[[ "$(read_extra_data "$uuid" k3s-ansible/owner || true)" == box-master ]] || return 1
|
||||||
|
[[ "$(read_extra_data "$uuid" k3s-ansible/box || true)" == "$box" ]] || return 1
|
||||||
|
[[ "$(read_extra_data "$uuid" k3s-ansible/version || true)" == "$version" ]] || return 1
|
||||||
|
[[ "$(read_extra_data "$uuid" k3s-ansible/architecture || true)" == "$architecture" ]] || return 1
|
||||||
|
|
||||||
|
while IFS= read -r disk_path; do
|
||||||
|
[[ -z "$disk_path" || "$disk_path" == none ]] && continue
|
||||||
|
disk_path_real="$(readlink -f -- "$disk_path" 2>/dev/null || true)"
|
||||||
|
[[ -n "$disk_path_real" ]] || return 1
|
||||||
|
root_contains "$virtualbox_root_real" "$disk_path_real" || return 1
|
||||||
|
done < <(awk -F= '$1 ~ /^(SATA|IDE|SCSI|SAS|VirtioSCSI|NVMe)-[0-9]+-[0-9]+$/ {
|
||||||
|
gsub(/"/, "", $2); print $2
|
||||||
|
}' <<< "$machine_info")
|
||||||
|
}
|
||||||
|
|
||||||
|
write_prewarm_vagrantfile() {
|
||||||
|
local destination="$1"
|
||||||
|
local box="$2"
|
||||||
|
local version="$3"
|
||||||
|
{
|
||||||
|
printf '%s\n' "Vagrant.configure('2') do |config|"
|
||||||
|
printf ' config.vm.box = "%s"\n' "$box"
|
||||||
|
printf ' config.vm.box_version = "%s"\n' "$version"
|
||||||
|
printf '%s\n' \
|
||||||
|
' config.vm.synced_folder ".", "/vagrant", disabled: true' \
|
||||||
|
' config.vm.hostname = "k3s-ansible-box-prewarm"' \
|
||||||
|
' config.vm.boot_timeout = 600' \
|
||||||
|
' config.vm.provider "virtualbox" do |virtualbox|' \
|
||||||
|
' virtualbox.linked_clone = true' \
|
||||||
|
' virtualbox.memory = 1024' \
|
||||||
|
' virtualbox.cpus = 2' \
|
||||||
|
' end' \
|
||||||
|
'end'
|
||||||
|
} > "$destination"
|
||||||
|
}
|
||||||
|
|
||||||
|
cleanup_prewarm() {
|
||||||
|
local rc=$?
|
||||||
|
trap - EXIT
|
||||||
|
if [[ -n "${prewarm_dir:-}" && -d "$prewarm_dir" ]]; then
|
||||||
|
VAGRANT_CWD="$prewarm_dir" vagrant destroy --force >/dev/null 2>&1 || true
|
||||||
|
rm -rf -- "$prewarm_dir"
|
||||||
|
fi
|
||||||
|
exit "$rc"
|
||||||
|
}
|
||||||
|
|
||||||
|
create_owned_master() {
|
||||||
|
local box="$1"
|
||||||
|
local version="$2"
|
||||||
|
local architecture="$3"
|
||||||
|
local master_id_file="$4"
|
||||||
|
local mapping_file="$5"
|
||||||
|
local uuid machine_info cfg_file cfg_file_real vm_state mapping_tmp
|
||||||
|
|
||||||
|
# A master_id restored from an immutable cache is only a hint. Without the
|
||||||
|
# runner-local ownership record and matching VirtualBox metadata it is not
|
||||||
|
# trusted, adopted, modified, or deleted.
|
||||||
|
rm -f -- "$master_id_file"
|
||||||
|
|
||||||
|
prewarm_dir="$(mktemp -d "${master_root}/prewarm.XXXXXX")"
|
||||||
|
trap cleanup_prewarm EXIT
|
||||||
|
write_prewarm_vagrantfile "$prewarm_dir/Vagrantfile" "$box" "$version"
|
||||||
|
|
||||||
|
printf 'Creating runner-owned linked-clone master for %s %s %s\n' \
|
||||||
|
"$box" "$version" "$architecture"
|
||||||
|
VAGRANT_CWD="$prewarm_dir" vagrant up --provider virtualbox --no-provision
|
||||||
|
|
||||||
|
[[ -r "$master_id_file" ]] || fail "Vagrant did not record a master UUID for $box"
|
||||||
|
uuid="$(tr -d '[:space:]' < "$master_id_file")"
|
||||||
|
[[ "$uuid" =~ ^[0-9a-fA-F-]{36}$ ]] || fail "Vagrant recorded an invalid master UUID for $box"
|
||||||
|
|
||||||
|
machine_info="$(VBoxManage showvminfo "$uuid" --machinereadable 2>/dev/null)" || \
|
||||||
|
fail "Vagrant master $uuid for $box is not registered"
|
||||||
|
vm_state="$(read_machine_value "$machine_info" VMState)"
|
||||||
|
cfg_file="$(read_machine_value "$machine_info" CfgFile)"
|
||||||
|
cfg_file_real="$(readlink -f -- "$cfg_file" 2>/dev/null || true)"
|
||||||
|
[[ "$vm_state" == poweroff ]] || fail "new Vagrant master $uuid is not powered off"
|
||||||
|
if [[ -z "$cfg_file_real" ]] || ! root_contains "$virtualbox_root_real" "$cfg_file_real"; then
|
||||||
|
fail "new Vagrant master $uuid is outside the runner VirtualBox root"
|
||||||
|
fi
|
||||||
|
|
||||||
|
VAGRANT_CWD="$prewarm_dir" vagrant destroy --force
|
||||||
|
VBoxManage modifyvm "$uuid" --groups /k3s-ansible/box-masters
|
||||||
|
VBoxManage setextradata "$uuid" k3s-ansible/owner box-master
|
||||||
|
VBoxManage setextradata "$uuid" k3s-ansible/box "$box"
|
||||||
|
VBoxManage setextradata "$uuid" k3s-ansible/version "$version"
|
||||||
|
VBoxManage setextradata "$uuid" k3s-ansible/architecture "$architecture"
|
||||||
|
validate_owned_master "$uuid" "$box" "$version" "$architecture" || \
|
||||||
|
fail "new Vagrant master $uuid failed ownership validation"
|
||||||
|
|
||||||
|
rm -rf -- "$prewarm_dir"
|
||||||
|
prewarm_dir=""
|
||||||
|
trap - EXIT
|
||||||
|
|
||||||
|
mapping_tmp="${mapping_file}.tmp"
|
||||||
|
printf '%s\n' "$uuid" > "$mapping_tmp"
|
||||||
|
chmod 600 "$mapping_tmp"
|
||||||
|
mv -- "$mapping_tmp" "$mapping_file"
|
||||||
|
printf '%s\n' "$uuid" > "$master_id_file"
|
||||||
|
chmod 600 "$master_id_file"
|
||||||
|
printf 'Created and recorded owned master %s for %s\n' "$uuid" "$box"
|
||||||
|
}
|
||||||
|
|
||||||
|
repository_root="${K3S_CI_REPOSITORY_ROOT:-$(git rev-parse --show-toplevel)}"
|
||||||
|
lock_file="${VAGRANT_BOX_LOCK_FILE:-${repository_root}/.github/vagrant-boxes.lock}"
|
||||||
|
vagrant_home="${VAGRANT_HOME:?VAGRANT_HOME must be set}"
|
||||||
|
master_root="${K3S_CI_VAGRANT_MASTER_ROOT:-${HOME:?HOME must be set}/.cache/k3s-ci/vagrant-masters}"
|
||||||
|
virtualbox_root="${K3S_CI_VIRTUALBOX_ROOT:-${HOME}/VirtualBox VMs}"
|
||||||
|
|
||||||
|
[[ -r "$lock_file" ]] || fail "box lock file is missing or unreadable: $lock_file"
|
||||||
|
[[ -d "$vagrant_home/boxes" ]] || fail "Vagrant box directory is missing: $vagrant_home/boxes"
|
||||||
|
[[ -d "$virtualbox_root" ]] || fail "VirtualBox root is missing: $virtualbox_root"
|
||||||
|
|
||||||
|
box_root_real="$(readlink -f -- "$vagrant_home/boxes")"
|
||||||
|
virtualbox_root_real="$(readlink -f -- "$virtualbox_root")"
|
||||||
|
mkdir -p -- "$master_root"
|
||||||
|
chmod 700 "$master_root"
|
||||||
|
|
||||||
|
exec 9> "${master_root}/prepare.lock"
|
||||||
|
flock 9
|
||||||
|
|
||||||
|
lock_entries="$(awk '
|
||||||
|
/^[[:space:]]*#/ || NF == 0 { next }
|
||||||
|
NF != 3 { invalid = 1; next }
|
||||||
|
{ print $1 " " $2 " " $3 }
|
||||||
|
END { exit invalid }
|
||||||
|
' "$lock_file")" || fail 'invalid Vagrant box lock entry'
|
||||||
|
[[ -n "$lock_entries" ]] || fail 'Vagrant box lock is empty'
|
||||||
|
|
||||||
|
while read -r box version architecture; do
|
||||||
|
[[ "$box" =~ ^[A-Za-z0-9._-]+/[A-Za-z0-9._-]+$ ]] || fail "invalid box name: $box"
|
||||||
|
[[ "$version" =~ ^[A-Za-z0-9._-]+$ ]] || fail "invalid box version: $version"
|
||||||
|
[[ "$architecture" =~ ^[A-Za-z0-9._-]+$ ]] || fail "invalid box architecture: $architecture"
|
||||||
|
|
||||||
|
box_slug="${box//\//-VAGRANTSLASH-}"
|
||||||
|
record_slug="${box//\//_}-${version}-${architecture}"
|
||||||
|
box_dir="${vagrant_home}/boxes/${box_slug}/${version}/${architecture}/virtualbox"
|
||||||
|
[[ -d "$box_dir" ]] || fail "pinned box is not installed: $box $version $architecture"
|
||||||
|
box_dir_real="$(readlink -f -- "$box_dir")"
|
||||||
|
root_contains "$box_root_real" "$box_dir_real" || fail "box directory is outside VAGRANT_HOME: $box_dir_real"
|
||||||
|
|
||||||
|
master_id_file="${box_dir_real}/master_id"
|
||||||
|
mapping_file="${master_root}/${record_slug}.uuid"
|
||||||
|
uuid=""
|
||||||
|
if [[ -r "$mapping_file" ]]; then
|
||||||
|
uuid="$(tr -d '[:space:]' < "$mapping_file")"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -n "$uuid" ]] && validate_owned_master "$uuid" "$box" "$version" "$architecture"; then
|
||||||
|
printf '%s\n' "$uuid" > "$master_id_file"
|
||||||
|
chmod 600 "$master_id_file"
|
||||||
|
printf 'Reusing owned master %s for %s %s %s\n' "$uuid" "$box" "$version" "$architecture"
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ -e "$mapping_file" ]]; then
|
||||||
|
printf 'Owned master record is stale for %s; rebuilding without deleting any VM or disk.\n' "$box"
|
||||||
|
fi
|
||||||
|
create_owned_master "$box" "$version" "$architecture" "$master_id_file" "$mapping_file"
|
||||||
|
done <<< "$lock_entries"
|
||||||
|
|
||||||
|
printf 'All pinned Vagrant box masters are ready.\n'
|
||||||
@@ -0,0 +1,134 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Render the Cilium BGP CRD template and assert it uses the v2 API.
|
||||||
|
|
||||||
|
This is a manifest-only regression test used where no real BGP peer is
|
||||||
|
available. It renders roles/k3s_server_post/templates/cilium.crs.j2 with
|
||||||
|
zero, one, and multiple neighbors, then checks that the output:
|
||||||
|
- never contains CiliumBGPPeeringPolicy or cilium.io/v2alpha1
|
||||||
|
- emits the Cilium v2 BGP resources
|
||||||
|
- emits deterministic DNS-safe peer and instance names
|
||||||
|
- advertises Pod CIDRs only when cilium_exportPodCIDR is true
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import print_function
|
||||||
|
|
||||||
|
import os
|
||||||
|
import subprocess
|
||||||
|
|
||||||
|
from jinja2 import Environment, FileSystemLoader, StrictUndefined
|
||||||
|
|
||||||
|
|
||||||
|
def repo_root():
|
||||||
|
return subprocess.check_output(
|
||||||
|
["git", "rev-parse", "--show-toplevel"], text=True
|
||||||
|
).strip()
|
||||||
|
|
||||||
|
|
||||||
|
def fail(message):
|
||||||
|
raise SystemExit("Cilium BGP manifest test failed: " + message)
|
||||||
|
|
||||||
|
|
||||||
|
def render(env, extra_vars):
|
||||||
|
base_vars = {
|
||||||
|
"cilium_bgp_my_asn": "64513",
|
||||||
|
"cilium_bgp_peer_asn": "64512",
|
||||||
|
"cilium_bgp_peer_address": "192.168.30.1",
|
||||||
|
"cilium_exportPodCIDR": True,
|
||||||
|
"cilium_bgp_lb_cidr": "192.168.31.0/24",
|
||||||
|
}
|
||||||
|
base_vars.update(extra_vars)
|
||||||
|
template = env.get_template("cilium.crs.j2")
|
||||||
|
return template.render(**base_vars)
|
||||||
|
|
||||||
|
|
||||||
|
def check_common(output):
|
||||||
|
if "cilium.io/v2alpha1" in output:
|
||||||
|
fail("rendered output still contains cilium.io/v2alpha1")
|
||||||
|
if "kind: CiliumBGPPeeringPolicy" in output:
|
||||||
|
fail("rendered output still contains CiliumBGPPeeringPolicy")
|
||||||
|
for kind in (
|
||||||
|
"CiliumBGPPeerConfig",
|
||||||
|
"CiliumBGPClusterConfig",
|
||||||
|
"CiliumBGPAdvertisement",
|
||||||
|
"CiliumLoadBalancerIPPool",
|
||||||
|
):
|
||||||
|
if ("kind: " + kind) not in output:
|
||||||
|
fail("rendered output is missing kind: " + kind)
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
root = repo_root()
|
||||||
|
template_dir = os.path.join(
|
||||||
|
root, "roles", "k3s_server_post", "templates"
|
||||||
|
)
|
||||||
|
env = Environment(
|
||||||
|
loader=FileSystemLoader(template_dir), undefined=StrictUndefined
|
||||||
|
)
|
||||||
|
|
||||||
|
# Zero neighbors -> fall back to the single default peer.
|
||||||
|
output = render(env, {"_cilium_bgp_neighbors": []})
|
||||||
|
check_common(output)
|
||||||
|
if "peer-64512-1" not in output:
|
||||||
|
fail("default single peer name was not rendered")
|
||||||
|
if "peerAddress: 192.168.30.1" not in output:
|
||||||
|
fail("default peer address was not rendered")
|
||||||
|
if 'advertisementType: "PodCIDR"' not in output:
|
||||||
|
fail("PodCIDR advertisement missing when exportPodCIDR is true")
|
||||||
|
|
||||||
|
# One neighbor via the merged list.
|
||||||
|
output = render(
|
||||||
|
env,
|
||||||
|
{"_cilium_bgp_neighbors": [{"peer_address": "10.0.0.1", "peer_asn": "65001"}]},
|
||||||
|
)
|
||||||
|
check_common(output)
|
||||||
|
if "peer-65001-1" not in output:
|
||||||
|
fail("single merged peer name was not rendered")
|
||||||
|
if "peerAddress: 10.0.0.1" not in output:
|
||||||
|
fail("single merged peer address was not rendered")
|
||||||
|
|
||||||
|
# Multiple neighbors.
|
||||||
|
output = render(
|
||||||
|
env,
|
||||||
|
{
|
||||||
|
"_cilium_bgp_neighbors": [
|
||||||
|
{"peer_address": "10.0.0.1", "peer_asn": "65001"},
|
||||||
|
{"peer_address": "10.0.0.2", "peer_asn": "65002"},
|
||||||
|
]
|
||||||
|
},
|
||||||
|
)
|
||||||
|
check_common(output)
|
||||||
|
if "peer-65001-1" not in output or "peer-65002-2" not in output:
|
||||||
|
fail("multiple merged peer names were not rendered")
|
||||||
|
if "peerAddress: 10.0.0.2" not in output:
|
||||||
|
fail("second merged peer address was not rendered")
|
||||||
|
|
||||||
|
# exportPodCIDR false -> no PodCIDR advertisement, service remains.
|
||||||
|
output = render(
|
||||||
|
env, {"_cilium_bgp_neighbors": [], "cilium_exportPodCIDR": False}
|
||||||
|
)
|
||||||
|
check_common(output)
|
||||||
|
if 'advertisementType: "PodCIDR"' in output:
|
||||||
|
fail("PodCIDR advertisement present when exportPodCIDR is false")
|
||||||
|
if 'advertisementType: "Service"' not in output:
|
||||||
|
fail("Service advertisement missing when exportPodCIDR is false")
|
||||||
|
|
||||||
|
# Load balancer pools: CIDR and start/stop forms.
|
||||||
|
output = render(env, {"_cilium_bgp_neighbors": []})
|
||||||
|
if "cidr: 192.168.31.0/24" not in output:
|
||||||
|
fail("CIDR load balancer pool was not rendered")
|
||||||
|
output = render(
|
||||||
|
env,
|
||||||
|
{
|
||||||
|
"_cilium_bgp_neighbors": [],
|
||||||
|
"cilium_bgp_lb_cidr": "192.168.31.80-192.168.31.90",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
check_common(output)
|
||||||
|
if "start: 192.168.31.80" not in output or "stop: 192.168.31.90" not in output:
|
||||||
|
fail("start/stop load balancer pool was not rendered")
|
||||||
|
|
||||||
|
print("Cilium BGP manifest regression test passed")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
+129
@@ -0,0 +1,129 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
# shellcheck disable=SC2016
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
repo_root="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/../.." && pwd)"
|
||||||
|
test_root="$(mktemp -d "${TMPDIR:-/tmp}/k3s-ci-cleanup-test.XXXXXX")"
|
||||||
|
trap 'rm -rf -- "$test_root"' EXIT
|
||||||
|
|
||||||
|
molecule_root="$test_root/molecule"
|
||||||
|
virtualbox_root="$test_root/VirtualBox VMs"
|
||||||
|
fake_bin="$test_root/bin"
|
||||||
|
mkdir -p -- "$molecule_root/k3s-ansible/single_node/.vagrant/machines/control1/virtualbox" \
|
||||||
|
"$molecule_root/k3s-ansible/single_node/.vagrant/machines/control2/virtualbox" \
|
||||||
|
"$virtualbox_root/control1" "$virtualbox_root/unmarked" "$fake_bin"
|
||||||
|
printf '%s\n' '11111111-1111-1111-1111-111111111111' \
|
||||||
|
> "$molecule_root/k3s-ansible/single_node/.vagrant/machines/control1/virtualbox/id"
|
||||||
|
printf '%s\n' '22222222-2222-2222-2222-222222222222' \
|
||||||
|
> "$molecule_root/k3s-ansible/single_node/.vagrant/machines/control2/virtualbox/id"
|
||||||
|
touch "$virtualbox_root/control1/control1.vbox" "$virtualbox_root/control1/disk.vdi" \
|
||||||
|
"$virtualbox_root/unmarked/unmarked.vbox"
|
||||||
|
|
||||||
|
printf '%s\n' \
|
||||||
|
'#!/usr/bin/env bash' \
|
||||||
|
'set -Eeuo pipefail' \
|
||||||
|
'case "${1:-}" in' \
|
||||||
|
' list)' \
|
||||||
|
' if [[ "${2:-}" == hostonlyifs && "${FAKE_HOSTONLY_FAIL:-false}" == true ]]; then exit 1; fi' \
|
||||||
|
' exit 0' \
|
||||||
|
' ;;' \
|
||||||
|
' showvminfo)' \
|
||||||
|
' if [[ "${FAKE_VM_MODE:-normal}" == missing ]]; then' \
|
||||||
|
' printf '\''VBoxManage: error: Could not find a registered machine named "missing"\n'\'' >&2' \
|
||||||
|
' exit 1' \
|
||||||
|
' fi' \
|
||||||
|
' if [[ "${FAKE_VM_MODE:-normal}" == fault ]]; then' \
|
||||||
|
' printf '\''VBoxManage: error: VirtualBox service is unavailable\n'\'' >&2' \
|
||||||
|
' exit 1' \
|
||||||
|
' fi' \
|
||||||
|
' printf '\''CfgFile="%s"\n'\'' "${FAKE_VBOX_ROOT}/control1/control1.vbox"' \
|
||||||
|
' printf '\''SATA-0-0="%s"\n'\'' "${FAKE_VBOX_ROOT}/control1/disk.vdi"' \
|
||||||
|
' printf '\''VMState="running"\n'\''' \
|
||||||
|
' ;;' \
|
||||||
|
' controlvm) printf '\''controlvm %s\n'\'' "$*" >> "${FAKE_LOG}" ;;' \
|
||||||
|
' unregistervm)' \
|
||||||
|
' printf '\''unregistervm %s\n'\'' "$*" >> "${FAKE_LOG}"' \
|
||||||
|
' rm -f -- "${FAKE_VBOX_ROOT}/control1/control1.vbox" "${FAKE_VBOX_ROOT}/control1/disk.vdi"' \
|
||||||
|
' ;;' \
|
||||||
|
' *) : ;;' \
|
||||||
|
'esac' > "$fake_bin/VBoxManage"
|
||||||
|
chmod 700 "$fake_bin/VBoxManage"
|
||||||
|
|
||||||
|
output="$test_root/output.txt"
|
||||||
|
if PATH="$fake_bin:$PATH" \
|
||||||
|
HOME="$test_root/home" \
|
||||||
|
K3S_CI_MOLECULE_ROOT="$molecule_root" \
|
||||||
|
K3S_CI_MOLECULE_PROJECT=k3s-ansible \
|
||||||
|
K3S_CI_VIRTUALBOX_ROOT="$virtualbox_root" \
|
||||||
|
K3S_CI_HOSTONLY_MARKER="$test_root/hostonly-baseline" \
|
||||||
|
FAKE_VM_MODE=fault \
|
||||||
|
FAKE_VBOX_ROOT="$virtualbox_root" \
|
||||||
|
FAKE_LOG="$test_root/vbox.log" \
|
||||||
|
bash "$repo_root/.github/scripts/cleanup-runner-resources.sh" --apply > "$output" 2>&1; then
|
||||||
|
printf '%s\n' 'cleanup unexpectedly accepted a VirtualBox inspection failure' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
grep -Fq 'cleanup refused: unable to inspect VirtualBox VM' "$output"
|
||||||
|
[[ -f "$molecule_root/k3s-ansible/single_node/.vagrant/machines/control1/virtualbox/id" ]]
|
||||||
|
|
||||||
|
printf '%s\n' 'vboxnet0|192.168.30.1' > "$test_root/hostonly-baseline"
|
||||||
|
if PATH="$fake_bin:$PATH" \
|
||||||
|
HOME="$test_root/home" \
|
||||||
|
K3S_CI_MOLECULE_ROOT="$molecule_root" \
|
||||||
|
K3S_CI_MOLECULE_PROJECT=k3s-ansible \
|
||||||
|
K3S_CI_VIRTUALBOX_ROOT="$virtualbox_root" \
|
||||||
|
K3S_CI_HOSTONLY_MARKER="$test_root/hostonly-baseline" \
|
||||||
|
FAKE_HOSTONLY_FAIL=true \
|
||||||
|
FAKE_VBOX_ROOT="$virtualbox_root" \
|
||||||
|
FAKE_LOG="$test_root/vbox.log" \
|
||||||
|
bash "$repo_root/.github/scripts/cleanup-runner-resources.sh" --dry-run > "$output" 2>&1; then
|
||||||
|
printf '%s\n' 'cleanup unexpectedly accepted a host-only inventory failure' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
grep -Fq 'cleanup refused: unable to inventory VirtualBox host-only interfaces' "$output"
|
||||||
|
|
||||||
|
PATH="$fake_bin:$PATH" \
|
||||||
|
HOME="$test_root/home" \
|
||||||
|
K3S_CI_MOLECULE_ROOT="$molecule_root" \
|
||||||
|
K3S_CI_MOLECULE_PROJECT=k3s-ansible \
|
||||||
|
K3S_CI_VIRTUALBOX_ROOT="$virtualbox_root" \
|
||||||
|
K3S_CI_HOSTONLY_MARKER="$test_root/hostonly-baseline" \
|
||||||
|
FAKE_VBOX_ROOT="$virtualbox_root" \
|
||||||
|
FAKE_LOG="$test_root/vbox.log" \
|
||||||
|
bash "$repo_root/.github/scripts/cleanup-runner-resources.sh" --dry-run > "$output"
|
||||||
|
|
||||||
|
grep -Fq 'Would remove VM control1 (11111111-1111-1111-1111-111111111111)' "$output"
|
||||||
|
[[ ! -e "$test_root/vbox.log" ]]
|
||||||
|
|
||||||
|
PATH="$fake_bin:$PATH" \
|
||||||
|
HOME="$test_root/home" \
|
||||||
|
K3S_CI_MOLECULE_ROOT="$molecule_root" \
|
||||||
|
K3S_CI_MOLECULE_PROJECT=k3s-ansible \
|
||||||
|
K3S_CI_VIRTUALBOX_ROOT="$virtualbox_root" \
|
||||||
|
K3S_CI_HOSTONLY_MARKER="$test_root/hostonly-baseline" \
|
||||||
|
FAKE_VBOX_ROOT="$virtualbox_root" \
|
||||||
|
FAKE_LOG="$test_root/vbox.log" \
|
||||||
|
bash "$repo_root/.github/scripts/cleanup-runner-resources.sh" --apply > "$output"
|
||||||
|
|
||||||
|
grep -Fq 'controlvm 11111111-1111-1111-1111-111111111111 poweroff' "$test_root/vbox.log"
|
||||||
|
grep -Fq 'unregistervm unregistervm 11111111-1111-1111-1111-111111111111 --delete' "$test_root/vbox.log"
|
||||||
|
[[ ! -e "$virtualbox_root/control1/control1.vbox" ]]
|
||||||
|
[[ -e "$virtualbox_root/unmarked/unmarked.vbox" ]]
|
||||||
|
|
||||||
|
PATH="$fake_bin:$PATH" \
|
||||||
|
HOME="$test_root/home" \
|
||||||
|
K3S_CI_MOLECULE_ROOT="$molecule_root" \
|
||||||
|
K3S_CI_MOLECULE_PROJECT=k3s-ansible \
|
||||||
|
K3S_CI_VIRTUALBOX_ROOT="$virtualbox_root" \
|
||||||
|
K3S_CI_HOSTONLY_MARKER="$test_root/hostonly-baseline" \
|
||||||
|
FAKE_VM_MODE=missing \
|
||||||
|
FAKE_VBOX_ROOT="$virtualbox_root" \
|
||||||
|
FAKE_LOG="$test_root/vbox.log" \
|
||||||
|
bash "$repo_root/.github/scripts/cleanup-runner-resources.sh" --apply > "$output"
|
||||||
|
|
||||||
|
grep -Fq 'Stale Vagrant state without a registered VM' "$output"
|
||||||
|
[[ ! -d "$molecule_root/k3s-ansible/single_node/.vagrant" ]]
|
||||||
|
|
||||||
|
printf 'cleanup-runner-resources fixture test passed\n'
|
||||||
Executable
+4
@@ -0,0 +1,4 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
[[ "${1:-}" =~ ^[0-9]+$ ]]
|
||||||
Executable
+30
@@ -0,0 +1,30 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
printf '%s\n' "$*" >> "$MOCK_VAGRANT_LOG"
|
||||||
|
case "${1:-}" in
|
||||||
|
up)
|
||||||
|
if [[ -n "${MOCK_VAGRANTFILE_CAPTURE:-}" ]]; then
|
||||||
|
cp -- "$VAGRANT_CWD/Vagrantfile" "$MOCK_VAGRANTFILE_CAPTURE"
|
||||||
|
fi
|
||||||
|
counter_file="$MOCK_VBOX_STATE/counter"
|
||||||
|
counter=0
|
||||||
|
[[ ! -r "$counter_file" ]] || counter="$(cat "$counter_file")"
|
||||||
|
counter=$((counter + 1))
|
||||||
|
printf '%s\n' "$counter" > "$counter_file"
|
||||||
|
uuid="00000000-0000-4000-8000-$(printf '%012d' "$counter")"
|
||||||
|
vm_dir="$MOCK_VBOX_ROOT/master-$counter"
|
||||||
|
mkdir -p -- "$vm_dir"
|
||||||
|
: > "$vm_dir/master.vbox"
|
||||||
|
: > "$vm_dir/master.vdi"
|
||||||
|
printf '%s\n' \
|
||||||
|
'VMState="poweroff"' \
|
||||||
|
'groups="/"' \
|
||||||
|
"CfgFile=\"$vm_dir/master.vbox\"" \
|
||||||
|
"SATA-0-0=\"$vm_dir/master.vdi\"" > "$MOCK_VBOX_STATE/vm-$uuid"
|
||||||
|
printf '%s\n' "$uuid" > "$MOCK_BOX_DIR/master_id"
|
||||||
|
;;
|
||||||
|
destroy) ;;
|
||||||
|
*) exit 2 ;;
|
||||||
|
esac
|
||||||
+40
@@ -0,0 +1,40 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
printf '%s\n' "$*" >> "$MOCK_VBOX_LOG"
|
||||||
|
command_name="${1:-}"
|
||||||
|
uuid="${2:-}"
|
||||||
|
|
||||||
|
case "$command_name" in
|
||||||
|
showvminfo)
|
||||||
|
[[ -r "$MOCK_VBOX_STATE/vm-$uuid" ]] || exit 1
|
||||||
|
cat "$MOCK_VBOX_STATE/vm-$uuid"
|
||||||
|
;;
|
||||||
|
getextradata)
|
||||||
|
key_slug="${3//\//_}"
|
||||||
|
if [[ ! -r "$MOCK_VBOX_STATE/extra-$uuid-$key_slug" ]]; then
|
||||||
|
printf '%s\n' 'No value set!'
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
printf 'Value: '
|
||||||
|
cat "$MOCK_VBOX_STATE/extra-$uuid-$key_slug"
|
||||||
|
;;
|
||||||
|
modifyvm)
|
||||||
|
[[ "${3:-}" == --groups ]]
|
||||||
|
awk -v groups="${4:-}" '
|
||||||
|
$1 !~ /^groups=/ { print }
|
||||||
|
END { printf "groups=\"%s\"\n", groups }
|
||||||
|
' "$MOCK_VBOX_STATE/vm-$uuid" > "$MOCK_VBOX_STATE/vm-$uuid.tmp"
|
||||||
|
mv "$MOCK_VBOX_STATE/vm-$uuid.tmp" "$MOCK_VBOX_STATE/vm-$uuid"
|
||||||
|
;;
|
||||||
|
setextradata)
|
||||||
|
key_slug="${3//\//_}"
|
||||||
|
printf '%s\n' "${4:-}" > "$MOCK_VBOX_STATE/extra-$uuid-$key_slug"
|
||||||
|
;;
|
||||||
|
unregistervm|closemedium)
|
||||||
|
printf '%s\n' 'destructive VirtualBox command invoked' >&2
|
||||||
|
exit 99
|
||||||
|
;;
|
||||||
|
*) exit 2 ;;
|
||||||
|
esac
|
||||||
Executable
+35
@@ -0,0 +1,35 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
repo_root="$(git rev-parse --show-toplevel)"
|
||||||
|
main_tasks="$repo_root/roles/k3s_server/tasks/main.yml"
|
||||||
|
join_tasks="$repo_root/roles/k3s_server/tasks/join_master.yml"
|
||||||
|
|
||||||
|
for task_file in "$main_tasks" "$join_tasks"; do
|
||||||
|
for property in \
|
||||||
|
'Delegate=yes' \
|
||||||
|
'TasksMax=infinity' \
|
||||||
|
'KillMode=process' \
|
||||||
|
'LimitNOFILE=1048576' \
|
||||||
|
'LimitNPROC=infinity' \
|
||||||
|
'LimitCORE=infinity'; do
|
||||||
|
grep -Fq -- "$property" "$task_file" || {
|
||||||
|
printf '%s is missing transient K3s property %s\n' "$task_file" "$property" >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
done
|
||||||
|
done
|
||||||
|
|
||||||
|
if grep -Fq -- "node-role.kubernetes.io/master=true' -o=jsonpath" "$main_tasks"; then
|
||||||
|
printf 'control-plane registration still depends on the optional legacy master role key\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
grep -Fq -- "map('extract', hostvars, 'ansible_hostname')" "$main_tasks"
|
||||||
|
grep -Fq -- 'difference(nodes.stdout.split())' "$main_tasks"
|
||||||
|
grep -Fq -- 'crd/addons.k3s.cattle.io' "$main_tasks"
|
||||||
|
grep -Fq -- 'crd/helmcharts.helm.cattle.io' "$main_tasks"
|
||||||
|
grep -Fq -- 'crd/helmchartconfigs.helm.cattle.io' "$main_tasks"
|
||||||
|
|
||||||
|
printf 'K3s transient bootstrap regression test passed\n'
|
||||||
@@ -0,0 +1,130 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Render the kube-vip DaemonSet template and assert env key correctness.
|
||||||
|
|
||||||
|
kube-vip v1.2.2 reads `bgp_peers` and `vip_subnet`; it ignores the older
|
||||||
|
`bgppeers` and `vip_cidr` names. This test proves the rendered manifest uses
|
||||||
|
the keys the target image actually parses.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import print_function
|
||||||
|
|
||||||
|
import os
|
||||||
|
import subprocess
|
||||||
|
|
||||||
|
from jinja2 import Environment, FileSystemLoader, StrictUndefined
|
||||||
|
|
||||||
|
|
||||||
|
def repo_root():
|
||||||
|
return subprocess.check_output(
|
||||||
|
["git", "rev-parse", "--show-toplevel"], text=True
|
||||||
|
).strip()
|
||||||
|
|
||||||
|
|
||||||
|
def fail(message):
|
||||||
|
raise SystemExit("kube-vip manifest test failed: " + message)
|
||||||
|
|
||||||
|
|
||||||
|
def fake_ipsubnet(value):
|
||||||
|
# ansible.utils.ipsubnet -> network of the address as x.y.z.0/24
|
||||||
|
parts = value.split(".")
|
||||||
|
return ".".join(parts[:3]) + ".0/24"
|
||||||
|
|
||||||
|
|
||||||
|
def fake_ipaddr(_value, expr=None):
|
||||||
|
# ansible.utils.ipaddr('prefix') -> prefix length
|
||||||
|
return "24"
|
||||||
|
|
||||||
|
|
||||||
|
def fake_bool(value):
|
||||||
|
# Minimal stand-in for Ansible's truthiness filter used by the template.
|
||||||
|
if isinstance(value, bool):
|
||||||
|
return value
|
||||||
|
return str(value).lower() in ("1", "true", "yes", "on")
|
||||||
|
|
||||||
|
|
||||||
|
def fake_map(seq, *args, **kwargs):
|
||||||
|
# Minimal stand-in for Ansible's map() filter in the two forms used by the
|
||||||
|
# template: map(attribute='x') on a list of dicts, and map('join', sep) on
|
||||||
|
# a list of sequences.
|
||||||
|
if "attribute" in kwargs:
|
||||||
|
return [item[kwargs["attribute"]] for item in seq]
|
||||||
|
if kwargs:
|
||||||
|
# e.g. map(default='x') not used here; ignore unknown kwargs.
|
||||||
|
return list(seq)
|
||||||
|
if args:
|
||||||
|
filter_name = args[0]
|
||||||
|
sep = args[1] if len(args) > 1 else ""
|
||||||
|
if filter_name == "join":
|
||||||
|
return [sep.join(str(x) for x in item) for item in seq]
|
||||||
|
return list(seq)
|
||||||
|
|
||||||
|
|
||||||
|
def fake_zip(*seqs):
|
||||||
|
return list(zip(*seqs))
|
||||||
|
|
||||||
|
|
||||||
|
def render(env, extra_vars):
|
||||||
|
base_vars = {
|
||||||
|
"apiserver_endpoint": "192.168.30.222",
|
||||||
|
"kube_vip_iface": "",
|
||||||
|
"kube_vip_arp": True,
|
||||||
|
"kube_vip_bgp": True,
|
||||||
|
"kube_vip_bgp_routerid": "127.0.0.1",
|
||||||
|
"_kube_vip_bgp_peers": [
|
||||||
|
{"peer_address": "192.168.30.1", "peer_asn": "64512"},
|
||||||
|
{"peer_address": "192.168.30.2", "peer_asn": "64513"},
|
||||||
|
],
|
||||||
|
"kube_vip_tag_version": "v1.2.2",
|
||||||
|
}
|
||||||
|
base_vars.update(extra_vars)
|
||||||
|
template = env.get_template("vip.yaml.j2")
|
||||||
|
return template.render(**base_vars)
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
root = repo_root()
|
||||||
|
template_dir = os.path.join(root, "roles", "k3s_server", "templates")
|
||||||
|
env = Environment(
|
||||||
|
loader=FileSystemLoader(template_dir), undefined=StrictUndefined
|
||||||
|
)
|
||||||
|
env.filters["ansible.utils.ipsubnet"] = fake_ipsubnet
|
||||||
|
env.filters["ansible.utils.ipaddr"] = fake_ipaddr
|
||||||
|
env.filters["bool"] = fake_bool
|
||||||
|
env.filters["map"] = fake_map
|
||||||
|
env.filters["zip"] = fake_zip
|
||||||
|
|
||||||
|
# Multi-peer BGP armed: must emit bgp_peers, never bgppeers.
|
||||||
|
output = render(env, {})
|
||||||
|
if "name: bgp_peers" not in output:
|
||||||
|
fail("rendered manifest is missing bgp_peers")
|
||||||
|
if "name: bgppeers" in output:
|
||||||
|
fail("rendered manifest still uses the ignored bgppeers key")
|
||||||
|
if "name: vip_subnet" not in output:
|
||||||
|
fail("rendered manifest is missing vip_subnet")
|
||||||
|
if "name: vip_cidr" in output:
|
||||||
|
fail("rendered manifest still uses the ignored vip_cidr key")
|
||||||
|
if "192.168.30.1:64512,192.168.30.2:64513" not in output:
|
||||||
|
fail("bgp_peers value is not comma-separated address:ASN entries")
|
||||||
|
if "ghcr.io/kube-vip/kube-vip:v1.2.2" not in output:
|
||||||
|
fail("kube-vip image tag is not v1.2.2")
|
||||||
|
|
||||||
|
# BGP enabled with no merged peers: single-peer fallback vars, no bgp_peers.
|
||||||
|
output = render(
|
||||||
|
env,
|
||||||
|
{
|
||||||
|
"_kube_vip_bgp_peers": [],
|
||||||
|
"kube_vip_bgp_as": "64513",
|
||||||
|
"kube_vip_bgp_peeraddress": "192.168.30.1",
|
||||||
|
"kube_vip_bgp_peeras": "64512",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
if "name: bgp_as" not in output:
|
||||||
|
fail("single-peer bgp_as was not rendered")
|
||||||
|
if "name: bgp_peers" in output:
|
||||||
|
fail("bgp_peers present even though the peer list is empty")
|
||||||
|
|
||||||
|
print("kube-vip manifest regression test passed")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
Executable
+29
@@ -0,0 +1,29 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
repo_root="$(git rev-parse --show-toplevel)"
|
||||||
|
metallb_task="$repo_root/roles/k3s_server/tasks/metallb.yml"
|
||||||
|
|
||||||
|
# The speaker tag verification must read the rendered manifest on the managed
|
||||||
|
# host with slurp. A controller-side lookup('ansible.builtin.file', ...) would
|
||||||
|
# read from the Ansible control node, which does not have the file, and would
|
||||||
|
# fail on every MetalLB scenario.
|
||||||
|
grep -Fq -- 'ansible.builtin.slurp' "$metallb_task" || {
|
||||||
|
printf 'MetalLB speaker tag check does not use slurp on the managed host\n' >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
grep -Eq -- 'lookup\(.?ansible\.builtin\.file' "$metallb_task" && {
|
||||||
|
printf 'MetalLB speaker tag check uses a controller-side file lookup\n' >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# The check must reference the full image reference, not just a bare version
|
||||||
|
# string that could appear anywhere in the manifest.
|
||||||
|
grep -Fq -- 'quay.io/metallb/speaker:' "$metallb_task" || {
|
||||||
|
printf 'MetalLB speaker tag check does not match the full image reference\n' >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
printf 'MetalLB remote manifest read regression test passed\n'
|
||||||
+89
@@ -0,0 +1,89 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
repo_root="$(git rev-parse --show-toplevel)"
|
||||||
|
fixture="$(mktemp -d)"
|
||||||
|
trap 'rm -rf -- "$fixture"' EXIT
|
||||||
|
|
||||||
|
mock_bin="$fixture/bin"
|
||||||
|
mock_state="$fixture/state"
|
||||||
|
mock_home="$fixture/home"
|
||||||
|
mock_vagrant_home="$fixture/vagrant-home"
|
||||||
|
mock_box_dir="$mock_vagrant_home/boxes/bento-VAGRANTSLASH-ubuntu-26.04/202606.01.0/amd64/virtualbox"
|
||||||
|
mock_vbox_root="$mock_home/VirtualBox VMs"
|
||||||
|
mock_master_root="$mock_home/.cache/k3s-ci/vagrant-masters"
|
||||||
|
lock_file="$fixture/vagrant-boxes.lock"
|
||||||
|
mkdir -p -- "$mock_bin" "$mock_state" "$mock_box_dir" "$mock_vbox_root"
|
||||||
|
printf '%s\n' 'bento/ubuntu-26.04 202606.01.0 amd64' > "$lock_file"
|
||||||
|
ln -s "$repo_root/.github/scripts/test-fixtures/mock-vboxmanage" "$mock_bin/VBoxManage"
|
||||||
|
ln -s "$repo_root/.github/scripts/test-fixtures/mock-vagrant" "$mock_bin/vagrant"
|
||||||
|
ln -s "$repo_root/.github/scripts/test-fixtures/mock-flock" "$mock_bin/flock"
|
||||||
|
|
||||||
|
export PATH="$mock_bin:$PATH"
|
||||||
|
export HOME="$mock_home"
|
||||||
|
export VAGRANT_HOME="$mock_vagrant_home"
|
||||||
|
export VAGRANT_BOX_LOCK_FILE="$lock_file"
|
||||||
|
export K3S_CI_REPOSITORY_ROOT="$repo_root"
|
||||||
|
export K3S_CI_VAGRANT_MASTER_ROOT="$mock_master_root"
|
||||||
|
export K3S_CI_VIRTUALBOX_ROOT="$mock_vbox_root"
|
||||||
|
export MOCK_VBOX_STATE="$mock_state"
|
||||||
|
export MOCK_VBOX_ROOT="$mock_vbox_root"
|
||||||
|
export MOCK_BOX_DIR="$mock_box_dir"
|
||||||
|
export MOCK_VBOX_LOG="$fixture/vbox.log"
|
||||||
|
export MOCK_VAGRANT_LOG="$fixture/vagrant.log"
|
||||||
|
export MOCK_VAGRANTFILE_CAPTURE="$fixture/prewarm-Vagrantfile"
|
||||||
|
: > "$MOCK_VBOX_LOG"
|
||||||
|
: > "$MOCK_VAGRANT_LOG"
|
||||||
|
|
||||||
|
unowned_uuid='99999999-9999-4999-8999-999999999999'
|
||||||
|
printf '%s\n' "$unowned_uuid" > "$mock_box_dir/master_id"
|
||||||
|
|
||||||
|
script="$repo_root/.github/scripts/prepare-vagrant-box-masters.sh"
|
||||||
|
first_output="$fixture/first-output"
|
||||||
|
second_output="$fixture/second-output"
|
||||||
|
third_output="$fixture/third-output"
|
||||||
|
|
||||||
|
"$script" > "$first_output"
|
||||||
|
if grep -Fq 'config.ssh.insert_key' "$MOCK_VAGRANTFILE_CAPTURE"; then
|
||||||
|
printf 'prewarm Vagrantfile unexpectedly overrides Vagrant SSH key insertion\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
grep -Fq 'virtualbox.memory = 1024' "$MOCK_VAGRANTFILE_CAPTURE"
|
||||||
|
grep -Fq 'virtualbox.cpus = 2' "$MOCK_VAGRANTFILE_CAPTURE"
|
||||||
|
grep -Fq 'config.vm.boot_timeout = 600' "$MOCK_VAGRANTFILE_CAPTURE"
|
||||||
|
mapping_file="$mock_master_root/bento_ubuntu-26.04-202606.01.0-amd64.uuid"
|
||||||
|
test -s "$mapping_file"
|
||||||
|
cmp -s "$mapping_file" "$mock_box_dir/master_id"
|
||||||
|
grep -Fq 'Created and recorded owned master' "$first_output"
|
||||||
|
grep -Fq 'modifyvm' "$MOCK_VBOX_LOG"
|
||||||
|
grep -Fq 'setextradata' "$MOCK_VBOX_LOG"
|
||||||
|
if grep -Fq "$unowned_uuid" "$MOCK_VBOX_LOG"; then
|
||||||
|
printf 'unowned cached master UUID was unexpectedly inspected or modified\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if grep -Eq 'unregistervm|closemedium' "$MOCK_VBOX_LOG"; then
|
||||||
|
printf 'master preparation invoked a destructive VirtualBox command\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
: > "$MOCK_VAGRANT_LOG"
|
||||||
|
"$script" > "$second_output"
|
||||||
|
grep -Fq 'Reusing owned master' "$second_output"
|
||||||
|
if grep -Fq 'up ' "$MOCK_VAGRANT_LOG"; then
|
||||||
|
printf 'valid owned master was unexpectedly rebuilt\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
stale_uuid="$(tr -d '[:space:]' < "$mapping_file")"
|
||||||
|
rm -f -- "$mock_state/vm-$stale_uuid"
|
||||||
|
: > "$MOCK_VAGRANT_LOG"
|
||||||
|
"$script" > "$third_output"
|
||||||
|
grep -Fq 'rebuilding without deleting any VM or disk' "$third_output"
|
||||||
|
grep -Fq 'up ' "$MOCK_VAGRANT_LOG"
|
||||||
|
if grep -Eq 'unregistervm|closemedium' "$MOCK_VBOX_LOG"; then
|
||||||
|
printf 'stale master recovery invoked a destructive VirtualBox command\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf 'Vagrant box master preparation fixture test passed\n'
|
||||||
Executable
+24
@@ -0,0 +1,24 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
if (($# < 2)); then
|
||||||
|
printf 'Usage: vagrant-up-timed.sh WORKDIR MACHINE [MACHINE ...]\n' >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
|
||||||
|
workdir="$1"
|
||||||
|
shift
|
||||||
|
timing_log="${K3S_CI_CREATE_TIMING_LOG:-${RUNNER_TEMP:-/tmp}/k3s-ci-create-timing.log}"
|
||||||
|
mkdir -p -- "${timing_log%/*}"
|
||||||
|
|
||||||
|
printf '%s batch-start machines=%s\n' "$(date --iso-8601=ns)" "$*" | tee -a "$timing_log"
|
||||||
|
set +e
|
||||||
|
VAGRANT_CWD="$workdir" vagrant up "$@" --provider virtualbox --no-provision 2>&1 |
|
||||||
|
while IFS= read -r line; do
|
||||||
|
printf '%s %s\n' "$(date --iso-8601=ns)" "$line"
|
||||||
|
done | tee -a "$timing_log"
|
||||||
|
rc=${PIPESTATUS[0]}
|
||||||
|
set -e
|
||||||
|
printf '%s batch-end rc=%d machines=%s\n' "$(date --iso-8601=ns)" "$rc" "$*" | tee -a "$timing_log"
|
||||||
|
exit "$rc"
|
||||||
Executable
+98
@@ -0,0 +1,98 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
# The single-quoted expressions below are written into fake executables and
|
||||||
|
# intentionally expand only when those executables run.
|
||||||
|
# shellcheck disable=SC2016
|
||||||
|
|
||||||
|
set -Eeuo pipefail
|
||||||
|
|
||||||
|
repo_root=$(git rev-parse --show-toplevel)
|
||||||
|
test_root=$(mktemp -d)
|
||||||
|
fake_bin="$test_root/bin"
|
||||||
|
fake_log="$test_root/vagrant.log"
|
||||||
|
output="$test_root/output.txt"
|
||||||
|
mkdir -p "$fake_bin"
|
||||||
|
trap 'rm -rf "$test_root"' EXIT
|
||||||
|
|
||||||
|
printf '%s\n' \
|
||||||
|
'#!/usr/bin/env bash' \
|
||||||
|
'set -Eeuo pipefail' \
|
||||||
|
'printf "%s\n" bento/debian-13 bento/rockylinux-10.1 bento/ubuntu-26.04' \
|
||||||
|
>"$fake_bin/yq"
|
||||||
|
|
||||||
|
printf '%s\n' \
|
||||||
|
'#!/usr/bin/env bash' \
|
||||||
|
'set -Eeuo pipefail' \
|
||||||
|
'emit_box() {' \
|
||||||
|
' case "$1" in' \
|
||||||
|
' bento/debian-13) version=202510.26.0 ;;' \
|
||||||
|
' bento/rockylinux-10.1) version=202512.01.0 ;;' \
|
||||||
|
' bento/ubuntu-26.04) version=202606.01.0 ;;' \
|
||||||
|
' *) printf "Unexpected box: %s\n" "$1" >&2; exit 1 ;;' \
|
||||||
|
' esac' \
|
||||||
|
' printf "0,,box-name,%s\n" "$1"' \
|
||||||
|
' printf "0,,box-provider,virtualbox\n"' \
|
||||||
|
' printf "0,,box-version,%s\n" "$version"' \
|
||||||
|
' printf "0,,box-architecture,amd64\n"' \
|
||||||
|
'}' \
|
||||||
|
'if [[ "${1:-}" == box && "${2:-}" == list ]]; then' \
|
||||||
|
' emit_box bento/debian-13' \
|
||||||
|
' emit_box bento/rockylinux-10.1' \
|
||||||
|
' if [[ "${FAKE_PRESENT_MODE:-all}" == all ]]; then' \
|
||||||
|
' emit_box bento/ubuntu-26.04' \
|
||||||
|
' fi' \
|
||||||
|
'elif [[ "${1:-}" == box && "${2:-}" == add ]]; then' \
|
||||||
|
' printf "%s\n" "$*" >>"${FAKE_VAGRANT_LOG:?}"' \
|
||||||
|
'else' \
|
||||||
|
' printf "Unexpected vagrant arguments: %s\n" "$*" >&2' \
|
||||||
|
' exit 1' \
|
||||||
|
'fi' \
|
||||||
|
>"$fake_bin/vagrant"
|
||||||
|
chmod +x "$fake_bin/yq" "$fake_bin/vagrant"
|
||||||
|
|
||||||
|
PATH="$fake_bin:$PATH" \
|
||||||
|
FAKE_VAGRANT_LOG="$fake_log" \
|
||||||
|
"$repo_root/.github/download-boxes.sh" >"$output"
|
||||||
|
grep -Fq 'All pinned Vagrant boxes are already present.' "$output"
|
||||||
|
[[ ! -e "$fake_log" ]]
|
||||||
|
|
||||||
|
PATH="$fake_bin:$PATH" \
|
||||||
|
FAKE_PRESENT_MODE=partial \
|
||||||
|
FAKE_VAGRANT_LOG="$fake_log" \
|
||||||
|
"$repo_root/.github/download-boxes.sh" >"$output"
|
||||||
|
grep -Fxq \
|
||||||
|
'box add --provider virtualbox --box-version 202606.01.0 --architecture amd64 bento/ubuntu-26.04' \
|
||||||
|
"$fake_log"
|
||||||
|
|
||||||
|
incomplete_lock="$test_root/incomplete.lock"
|
||||||
|
printf '%s\n' \
|
||||||
|
'bento/debian-13 202510.26.0 amd64' \
|
||||||
|
'bento/rockylinux-10.1 202512.01.0 amd64' \
|
||||||
|
>"$incomplete_lock"
|
||||||
|
if PATH="$fake_bin:$PATH" \
|
||||||
|
VAGRANT_BOX_LOCK_FILE="$incomplete_lock" \
|
||||||
|
FAKE_VAGRANT_LOG="$fake_log" \
|
||||||
|
"$repo_root/.github/download-boxes.sh" >"$output" 2>&1; then
|
||||||
|
printf 'Download script accepted a lock missing a scenario box.\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
grep -Fq 'Scenario boxes missing from the lock file:' "$output"
|
||||||
|
grep -Fq 'bento/ubuntu-26.04' "$output"
|
||||||
|
|
||||||
|
duplicate_lock="$test_root/duplicate.lock"
|
||||||
|
printf '%s\n' \
|
||||||
|
'bento/debian-13 202510.26.0 amd64' \
|
||||||
|
'bento/debian-13 202508.10.0 amd64' \
|
||||||
|
'bento/rockylinux-10.1 202512.01.0 amd64' \
|
||||||
|
'bento/ubuntu-26.04 202606.01.0 amd64' \
|
||||||
|
>"$duplicate_lock"
|
||||||
|
if PATH="$fake_bin:$PATH" \
|
||||||
|
VAGRANT_BOX_LOCK_FILE="$duplicate_lock" \
|
||||||
|
FAKE_VAGRANT_LOG="$fake_log" \
|
||||||
|
"$repo_root/.github/download-boxes.sh" >"$output" 2>&1; then
|
||||||
|
printf 'Download script accepted duplicate box lock entries.\n' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
grep -Fq 'Duplicate Vagrant box lock entries:' "$output"
|
||||||
|
|
||||||
|
printf 'Vagrant box download tests passed.\n'
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
# box version architecture
|
||||||
|
bento/debian-13 202510.26.0 amd64
|
||||||
|
bento/rockylinux-10.1 202512.01.0 amd64
|
||||||
|
bento/ubuntu-26.04 202606.01.0 amd64
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
---
|
||||||
|
name: "Cache"
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
jobs:
|
||||||
|
molecule:
|
||||||
|
name: cache
|
||||||
|
runs-on: [self-hosted, linux, x64, k3s-ci, virtualbox, nested-virt]
|
||||||
|
env:
|
||||||
|
PYTHON_VERSION: "3.11"
|
||||||
|
VAGRANT_DEFAULT_PROVIDER: virtualbox
|
||||||
|
VAGRANT_HOME: ${{ github.workspace }}/.vagrant-home
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Check out the codebase
|
||||||
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 7.0.1
|
||||||
|
with:
|
||||||
|
ref: ${{ github.event.pull_request.head.sha || github.sha }}
|
||||||
|
|
||||||
|
- name: Check nested VirtualBox platform
|
||||||
|
run: |
|
||||||
|
set -Eeuo pipefail
|
||||||
|
grep -Eq 'vmx|svm' /proc/cpuinfo
|
||||||
|
test -c /dev/kvm
|
||||||
|
test -c /dev/vboxdrv
|
||||||
|
VBoxManage --version
|
||||||
|
vagrant --version
|
||||||
|
test -r /etc/vbox/networks.conf
|
||||||
|
test "$(stat -c '%u' /etc/vbox/networks.conf)" -eq 0
|
||||||
|
free -h
|
||||||
|
df -Pk "${RUNNER_TEMP}"
|
||||||
|
|
||||||
|
- name: Set up Python ${{ env.PYTHON_VERSION }}
|
||||||
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # 7.0.0
|
||||||
|
with:
|
||||||
|
python-version: ${{ env.PYTHON_VERSION }}
|
||||||
|
cache: 'pip' # caching pip dependencies
|
||||||
|
|
||||||
|
- name: Cache Vagrant boxes
|
||||||
|
id: cache-vagrant
|
||||||
|
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # 6.1.0
|
||||||
|
with:
|
||||||
|
# This producer only needs to know whether the immutable cache exists.
|
||||||
|
# Molecule jobs restore it after this job completes.
|
||||||
|
lookup-only: true
|
||||||
|
path: |
|
||||||
|
.vagrant-home/boxes
|
||||||
|
key: vagrant-boxes-${{ runner.name }}-${{ runner.os }}-${{ runner.arch }}-virtualbox-7.2-vagrant-2.4-${{ hashFiles('.github/vagrant-boxes.lock') }} # yamllint disable-line rule:line-length
|
||||||
|
|
||||||
|
- name: Download Vagrant boxes for all scenarios
|
||||||
|
# An exact hit skips both cache restoration and upstream downloads.
|
||||||
|
# A lock change builds and saves one clean, version-pinned cache.
|
||||||
|
if: steps.cache-vagrant.outputs.cache-hit != 'true'
|
||||||
|
run: |
|
||||||
|
./.github/download-boxes.sh
|
||||||
|
./.github/scripts/prepare-vagrant-box-masters.sh
|
||||||
|
vagrant box list
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
---
|
||||||
|
name: "CI"
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
types:
|
||||||
|
- opened
|
||||||
|
- synchronize
|
||||||
|
- reopened
|
||||||
|
- ready_for_review
|
||||||
|
paths-ignore:
|
||||||
|
- '**/.gitignore'
|
||||||
|
- '**/FUNDING.yml'
|
||||||
|
- '**/host.ini'
|
||||||
|
- '**/*.md'
|
||||||
|
- '**/.editorconfig'
|
||||||
|
- '**/ansible.example.cfg'
|
||||||
|
- '**/deploy.sh'
|
||||||
|
- '**/LICENSE'
|
||||||
|
- '**/reboot.sh'
|
||||||
|
- '**/reset.sh'
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ci-${{ github.event.pull_request.number || github.run_id }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
pre:
|
||||||
|
uses: ./.github/workflows/cache.yml
|
||||||
|
needs: [lint]
|
||||||
|
lint:
|
||||||
|
uses: ./.github/workflows/lint.yml
|
||||||
|
test:
|
||||||
|
uses: ./.github/workflows/test.yml
|
||||||
|
needs: [pre, lint]
|
||||||
+53
-19
@@ -1,24 +1,32 @@
|
|||||||
---
|
---
|
||||||
name: Linting
|
name: Linting
|
||||||
on:
|
on:
|
||||||
pull_request:
|
workflow_call:
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ansible-lint:
|
pre-commit-ci:
|
||||||
name: YAML Lint + Ansible Lint
|
name: Pre-Commit
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
env:
|
||||||
|
PYTHON_VERSION: "3.12"
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the codebase
|
- name: Check out the codebase
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # 3.0.2
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 7.0.1
|
||||||
|
|
||||||
- name: Set up Python 3.x
|
|
||||||
uses: actions/setup-python@b55428b1882923874294fa556849718a1d7f2ca5 #4.0.2
|
|
||||||
with:
|
with:
|
||||||
python-version: "3.x"
|
ref: ${{ github.event.pull_request.head.sha || github.sha }}
|
||||||
|
|
||||||
|
- name: Set up Python ${{ env.PYTHON_VERSION }}
|
||||||
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # 7.0.0
|
||||||
|
with:
|
||||||
|
python-version: ${{ env.PYTHON_VERSION }}
|
||||||
|
cache: 'pip' # caching pip dependencies
|
||||||
|
|
||||||
|
- name: Restore Ansible cache
|
||||||
|
id: cache-ansible
|
||||||
|
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # 6.1.0
|
||||||
|
with:
|
||||||
|
path: ~/.ansible/collections
|
||||||
|
key: ansible-${{ hashFiles('collections/requirements.yml') }}
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: |
|
run: |
|
||||||
@@ -30,12 +38,38 @@ jobs:
|
|||||||
python3 -m pip install -r requirements.txt
|
python3 -m pip install -r requirements.txt
|
||||||
echo "::endgroup::"
|
echo "::endgroup::"
|
||||||
|
|
||||||
echo "::group::Install Ansible role requirements from collections/requirements.yml"
|
- name: Install Ansible collections with retries
|
||||||
ansible-galaxy install -r collections/requirements.yml
|
if: steps.cache-ansible.outputs.cache-hit != 'true'
|
||||||
echo "::endgroup::"
|
run: |
|
||||||
|
set -Eeuo pipefail
|
||||||
|
for attempt in 1 2 3 4 5; do
|
||||||
|
if ansible-galaxy collection install -r collections/requirements.yml; then
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
echo "Ansible Galaxy attempt ${attempt} failed; retrying."
|
||||||
|
sleep $((attempt * 10))
|
||||||
|
done
|
||||||
|
exit 1
|
||||||
|
|
||||||
- name: Run yamllint
|
- name: Save Ansible collection cache
|
||||||
run: yamllint .
|
if: steps.cache-ansible.outputs.cache-hit != 'true'
|
||||||
|
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # 6.1.0
|
||||||
|
with:
|
||||||
|
path: ~/.ansible/collections
|
||||||
|
key: ansible-${{ hashFiles('collections/requirements.yml') }}
|
||||||
|
|
||||||
- name: Run ansible-lint
|
- name: Run pre-commit
|
||||||
run: ansible-lint
|
uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # 3.0.1
|
||||||
|
|
||||||
|
ensure-pinned-actions:
|
||||||
|
name: Ensure SHA Pinned Actions
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 7.0.1
|
||||||
|
- name: Ensure SHA pinned actions
|
||||||
|
uses: zgosalvez/github-actions-ensure-sha-pinned-actions@3db98c0363e2fa5df3e1c4c471777a7c10b24cc9 # 5.0.5
|
||||||
|
with:
|
||||||
|
allowlist: |
|
||||||
|
aws-actions/
|
||||||
|
docker/login-action
|
||||||
|
|||||||
+81
-44
@@ -1,81 +1,118 @@
|
|||||||
---
|
---
|
||||||
name: Test
|
name: Test
|
||||||
on:
|
on:
|
||||||
pull_request:
|
workflow_call:
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
paths-ignore:
|
|
||||||
- '**/README.md'
|
|
||||||
jobs:
|
jobs:
|
||||||
molecule:
|
molecule:
|
||||||
name: Molecule
|
name: Molecule
|
||||||
runs-on: macos-12
|
runs-on: [self-hosted, linux, x64, k3s-ci, virtualbox, nested-virt]
|
||||||
|
|
||||||
strategy:
|
strategy:
|
||||||
matrix:
|
matrix:
|
||||||
scenario:
|
scenario:
|
||||||
- default
|
- default
|
||||||
- ipv6
|
|
||||||
- single_node
|
- single_node
|
||||||
fail-fast: false
|
- calico
|
||||||
|
- cilium
|
||||||
|
- kube-vip
|
||||||
|
# - ipv6
|
||||||
|
fail-fast: true
|
||||||
|
max-parallel: 1
|
||||||
env:
|
env:
|
||||||
PYTHON_VERSION: "3.10"
|
PYTHON_VERSION: "3.11"
|
||||||
|
VAGRANT_DEFAULT_PROVIDER: virtualbox
|
||||||
|
VAGRANT_HOME: ${{ github.workspace }}/.vagrant-home
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the codebase
|
- name: Check out the codebase
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b # 3.0.2
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 7.0.1
|
||||||
|
|
||||||
- name: Configure VirtualBox
|
|
||||||
run: |-
|
|
||||||
sudo mkdir -p /etc/vbox
|
|
||||||
cat <<EOF | sudo tee -a /etc/vbox/networks.conf > /dev/null
|
|
||||||
* 192.168.30.0/24
|
|
||||||
* fdad:bad:ba55::/64
|
|
||||||
EOF
|
|
||||||
|
|
||||||
- name: Cache Vagrant boxes
|
|
||||||
uses: actions/cache@fd5de65bc895cf536527842281bea11763fefd77 # 3.0.8
|
|
||||||
with:
|
with:
|
||||||
path: |
|
ref: ${{ github.event.pull_request.head.sha || github.sha }}
|
||||||
~/.vagrant.d/boxes
|
|
||||||
key: vagrant-boxes-${{ hashFiles('**/molecule.yml') }}
|
|
||||||
restore-keys: |
|
|
||||||
vagrant-boxes
|
|
||||||
|
|
||||||
- name: Download Vagrant boxes for all scenarios
|
- name: Clean repository-owned resources before testing
|
||||||
# To save some cache space, all scenarios share the same cache key.
|
run: ./.github/scripts/cleanup-runner-resources.sh --apply
|
||||||
# On the other hand, this means that the cache contents should be
|
|
||||||
# the same across all scenarios. This step ensures that.
|
- name: Record host-only network baseline
|
||||||
run: ./.github/download-boxes.sh
|
run: ./.github/scripts/cleanup-runner-resources.sh --snapshot
|
||||||
|
|
||||||
|
- name: Check nested VirtualBox platform
|
||||||
|
run: |
|
||||||
|
set -Eeuo pipefail
|
||||||
|
grep -Eq 'vmx|svm' /proc/cpuinfo
|
||||||
|
test -c /dev/kvm
|
||||||
|
test -c /dev/vboxdrv
|
||||||
|
VBoxManage --version
|
||||||
|
vagrant --version
|
||||||
|
test -r /etc/vbox/networks.conf
|
||||||
|
test "$(stat -c '%u' /etc/vbox/networks.conf)" -eq 0
|
||||||
|
free -h
|
||||||
|
df -Pk "${RUNNER_TEMP}"
|
||||||
|
|
||||||
- name: Set up Python ${{ env.PYTHON_VERSION }}
|
- name: Set up Python ${{ env.PYTHON_VERSION }}
|
||||||
uses: actions/setup-python@v2
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # 7.0.0
|
||||||
with:
|
with:
|
||||||
python-version: ${{ env.PYTHON_VERSION }}
|
python-version: ${{ env.PYTHON_VERSION }}
|
||||||
|
cache: 'pip' # caching pip dependencies
|
||||||
|
|
||||||
|
- name: Restore vagrant Boxes cache
|
||||||
|
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # 6.1.0
|
||||||
|
with:
|
||||||
|
path: .vagrant-home/boxes
|
||||||
|
key: vagrant-boxes-${{ runner.name }}-${{ runner.os }}-${{ runner.arch }}-virtualbox-7.2-vagrant-2.4-${{ hashFiles('.github/vagrant-boxes.lock') }} # yamllint disable-line rule:line-length
|
||||||
|
fail-on-cache-miss: true
|
||||||
|
|
||||||
|
- name: Prepare runner-owned Vagrant box masters
|
||||||
|
run: ./.github/scripts/prepare-vagrant-box-masters.sh
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: >-
|
run: |
|
||||||
python3 -m pip install --upgrade pip &&
|
echo "::group::Upgrade pip"
|
||||||
|
python3 -m pip install --upgrade pip
|
||||||
|
echo "::endgroup::"
|
||||||
|
|
||||||
|
echo "::group::Install Python requirements from requirements.txt"
|
||||||
python3 -m pip install -r requirements.txt
|
python3 -m pip install -r requirements.txt
|
||||||
|
echo "::endgroup::"
|
||||||
|
|
||||||
- name: Test with molecule
|
- name: Test with molecule
|
||||||
run: molecule test --scenario-name ${{ matrix.scenario }}
|
run: |
|
||||||
|
set -Eeuo pipefail
|
||||||
|
resource_dir="${RUNNER_TEMP}/logs/resources/${{ matrix.scenario }}"
|
||||||
|
timing_file="${RUNNER_TEMP}/logs/timing/${{ matrix.scenario }}.txt"
|
||||||
|
mkdir -p -- "${timing_file%/*}"
|
||||||
|
./.github/scripts/monitor-runner-resources.sh "$resource_dir" 10 &
|
||||||
|
monitor_pid=$!
|
||||||
|
stop_monitor() {
|
||||||
|
kill -TERM "$monitor_pid" 2>/dev/null || true
|
||||||
|
wait "$monitor_pid" 2>/dev/null || true
|
||||||
|
}
|
||||||
|
trap stop_monitor EXIT
|
||||||
|
/usr/bin/time -v -o "$timing_file" \
|
||||||
|
molecule test --scenario-name ${{ matrix.scenario }}
|
||||||
|
timeout-minutes: 150
|
||||||
env:
|
env:
|
||||||
ANSIBLE_K3S_LOG_DIR: ${{ runner.temp }}/logs/k3s-ansible/${{ matrix.scenario }}
|
ANSIBLE_K3S_LOG_DIR: ${{ runner.temp }}/logs/k3s-ansible/${{ matrix.scenario }}
|
||||||
ANSIBLE_SSH_RETRIES: 4
|
ANSIBLE_SSH_RETRIES: 4
|
||||||
ANSIBLE_TIMEOUT: 60
|
ANSIBLE_TIMEOUT: 120
|
||||||
PY_COLORS: 1
|
PY_COLORS: 1
|
||||||
ANSIBLE_FORCE_COLOR: 1
|
ANSIBLE_FORCE_COLOR: 1
|
||||||
|
K3S_CI_CREATE_TIMING_LOG: ${{ runner.temp }}/logs/timing/${{ matrix.scenario }}-create.log
|
||||||
|
|
||||||
|
- name: Collect runner diagnostics
|
||||||
|
if: always()
|
||||||
|
run: ./.github/scripts/collect-runner-diagnostics.sh "${RUNNER_TEMP}/logs/runner"
|
||||||
|
env:
|
||||||
|
K3S_CI_SCENARIO_NAME: ${{ matrix.scenario }}
|
||||||
|
|
||||||
|
- name: Clean repository-owned resources after testing
|
||||||
|
if: always()
|
||||||
|
run: ./.github/scripts/cleanup-runner-resources.sh --apply
|
||||||
|
|
||||||
- name: Upload log files
|
- name: Upload log files
|
||||||
if: always() # do this even if a step before has failed
|
if: always() # do this even if a step before has failed
|
||||||
uses: actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8 # 3.1.0
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # 7.0.1
|
||||||
with:
|
with:
|
||||||
name: logs
|
name: logs-${{ matrix.scenario }}-${{ github.run_id }}-${{ github.run_attempt }}
|
||||||
path: |
|
path: |
|
||||||
${{ runner.temp }}/logs
|
${{ runner.temp }}/logs
|
||||||
|
if-no-files-found: warn
|
||||||
- name: Delete old box versions
|
retention-days: 14
|
||||||
if: always() # do this even if a step before has failed
|
|
||||||
run: vagrant box prune --force
|
|
||||||
|
|||||||
@@ -1 +1,6 @@
|
|||||||
.env/
|
.env/
|
||||||
|
*.log
|
||||||
|
ansible.cfg
|
||||||
|
.ansible/
|
||||||
|
kubeconfig
|
||||||
|
zIgnore/
|
||||||
|
|||||||
@@ -0,0 +1,86 @@
|
|||||||
|
---
|
||||||
|
repos:
|
||||||
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||||
|
rev: v4.5.0
|
||||||
|
hooks:
|
||||||
|
- id: requirements-txt-fixer
|
||||||
|
- id: sort-simple-yaml
|
||||||
|
- id: detect-private-key
|
||||||
|
- id: check-merge-conflict
|
||||||
|
- id: end-of-file-fixer
|
||||||
|
- id: mixed-line-ending
|
||||||
|
- id: trailing-whitespace
|
||||||
|
args: [--markdown-linebreak-ext=md]
|
||||||
|
- repo: https://github.com/adrienverge/yamllint.git
|
||||||
|
rev: v1.33.0
|
||||||
|
hooks:
|
||||||
|
- id: yamllint
|
||||||
|
args: [-c=.yamllint]
|
||||||
|
- repo: https://github.com/ansible-community/ansible-lint.git
|
||||||
|
rev: v6.22.2
|
||||||
|
hooks:
|
||||||
|
- id: ansible-lint
|
||||||
|
additional_dependencies: [ansible-core==2.18.0]
|
||||||
|
language_version: python3.12
|
||||||
|
args: [--offline]
|
||||||
|
- repo: https://github.com/shellcheck-py/shellcheck-py
|
||||||
|
rev: v0.9.0.6
|
||||||
|
hooks:
|
||||||
|
- id: shellcheck
|
||||||
|
- repo: https://github.com/Lucas-C/pre-commit-hooks
|
||||||
|
rev: v1.5.4
|
||||||
|
hooks:
|
||||||
|
- id: remove-crlf
|
||||||
|
- id: remove-tabs
|
||||||
|
- repo: https://github.com/sirosen/texthooks
|
||||||
|
rev: 0.6.4
|
||||||
|
hooks:
|
||||||
|
- id: fix-smartquotes
|
||||||
|
- repo: local
|
||||||
|
hooks:
|
||||||
|
- id: cleanup-runner-resources-test
|
||||||
|
name: cleanup runner resources test
|
||||||
|
entry: .github/scripts/test-cleanup-runner-resources.sh
|
||||||
|
language: system
|
||||||
|
pass_filenames: false
|
||||||
|
files: ^\.github/scripts/(cleanup-runner-resources|test-cleanup-runner-resources)\.sh$
|
||||||
|
- id: download-vagrant-boxes-test
|
||||||
|
name: Vagrant box download test
|
||||||
|
entry: .github/test-download-boxes.sh
|
||||||
|
language: system
|
||||||
|
pass_filenames: false
|
||||||
|
files: ^\.github/(download-boxes|test-download-boxes)\.sh$|^\.github/vagrant-boxes\.lock$
|
||||||
|
- id: prepare-vagrant-box-masters-test
|
||||||
|
name: Vagrant box master preparation test
|
||||||
|
entry: .github/scripts/test-prepare-vagrant-box-masters.sh
|
||||||
|
language: system
|
||||||
|
pass_filenames: false
|
||||||
|
files: ^\.github/scripts/(prepare-vagrant-box-masters|test-prepare-vagrant-box-masters)\.sh$
|
||||||
|
- id: k3s-server-bootstrap-test
|
||||||
|
name: K3s transient bootstrap test
|
||||||
|
entry: .github/scripts/test-k3s-server-bootstrap.sh
|
||||||
|
language: system
|
||||||
|
pass_filenames: false
|
||||||
|
files: ^roles/k3s_server/tasks/(main|join_master)\.yml$|^\.github/scripts/test-k3s-server-bootstrap\.sh$
|
||||||
|
- id: cilium-bgp-manifest-test
|
||||||
|
name: Cilium BGP manifest test
|
||||||
|
entry: python3 .github/scripts/test-cilium-bgp-manifest.py
|
||||||
|
language: python
|
||||||
|
additional_dependencies:
|
||||||
|
- Jinja2>=3.1
|
||||||
|
pass_filenames: false
|
||||||
|
files: ^roles/k3s_server_post/templates/cilium\.crs\.j2$|^\.github/scripts/test-cilium-bgp-manifest\.py$
|
||||||
|
- id: kube-vip-manifest-test
|
||||||
|
name: kube-vip manifest test
|
||||||
|
entry: python3 .github/scripts/test-kube-vip-manifest.py
|
||||||
|
language: python
|
||||||
|
additional_dependencies:
|
||||||
|
- Jinja2>=3.1
|
||||||
|
pass_filenames: false
|
||||||
|
files: ^roles/k3s_server/templates/vip\.yaml\.j2$|^\.github/scripts/test-kube-vip-manifest\.py$
|
||||||
|
- id: metallb-remote-read-test
|
||||||
|
name: MetalLB remote read test
|
||||||
|
entry: .github/scripts/test-metallb-remote-read.sh
|
||||||
|
language: system
|
||||||
|
pass_filenames: false
|
||||||
|
files: ^roles/k3s_server/tasks/metallb\.yml$|^\.github/scripts/test-metallb-remote-read\.sh$
|
||||||
@@ -2,8 +2,19 @@
|
|||||||
extends: default
|
extends: default
|
||||||
|
|
||||||
rules:
|
rules:
|
||||||
|
comments:
|
||||||
|
min-spaces-from-content: 1
|
||||||
|
comments-indentation: false
|
||||||
|
braces:
|
||||||
|
max-spaces-inside: 1
|
||||||
|
octal-values:
|
||||||
|
forbid-implicit-octal: true
|
||||||
|
forbid-explicit-octal: true
|
||||||
line-length:
|
line-length:
|
||||||
max: 120
|
max: 120
|
||||||
level: warning
|
level: warning
|
||||||
truthy:
|
truthy:
|
||||||
allowed-values: ['true', 'false', 'yes', 'no']
|
allowed-values: ["true", "false"]
|
||||||
|
|
||||||
|
ignore:
|
||||||
|
- galaxy.yml
|
||||||
|
|||||||
@@ -4,21 +4,21 @@
|
|||||||
|
|
||||||
This playbook will build an HA Kubernetes cluster with `k3s`, `kube-vip` and MetalLB via `ansible`.
|
This playbook will build an HA Kubernetes cluster with `k3s`, `kube-vip` and MetalLB via `ansible`.
|
||||||
|
|
||||||
This is based on the work from [this fork](https://github.com/212850a/k3s-ansible) which is based on the work from [k3s-io/k3s-ansible](https://github.com/k3s-io/k3s-ansible). It uses [kube-vip](https://kube-vip.chipzoller.dev/) to create a load balancer for control plane, and [metal-lb](https://metallb.universe.tf/installation/) for its service `LoadBalancer`.
|
This is based on the work from [this fork](https://github.com/212850a/k3s-ansible) which is based on the work from [k3s-io/k3s-ansible](https://github.com/k3s-io/k3s-ansible). It uses [kube-vip](https://kube-vip.io/) to create a load balancer for control plane, and [metal-lb](https://metallb.universe.tf/installation/) for its service `LoadBalancer`.
|
||||||
|
|
||||||
If you want more context on how this works, see:
|
If you want more context on how this works, see:
|
||||||
|
|
||||||
📄 [Documentation](https://docs.technotim.live/posts/k3s-etcd-ansible/) (including example commands)
|
📄 [Documentation](https://technotim.com/posts/k3s-etcd-ansible/) (including example commands)
|
||||||
|
|
||||||
📺 [Video](https://www.youtube.com/watch?v=CbkEWcUZ7zM)
|
📺 [Watch the Video](https://www.youtube.com/watch?v=CbkEWcUZ7zM)
|
||||||
|
|
||||||
## 📖 k3s Ansible Playbook
|
## 📖 k3s Ansible Playbook
|
||||||
|
|
||||||
Build a Kubernetes cluster using Ansible with k3s. The goal is easily install a HA Kubernetes cluster on machines running:
|
Build a Kubernetes cluster using Ansible with k3s. The goal is easily install a HA Kubernetes cluster on machines running:
|
||||||
|
|
||||||
- [x] Debian (tested on version 11)
|
- [x] Debian (tested on version 13)
|
||||||
- [x] Ubuntu (tested on version 22.04)
|
- [x] Ubuntu (tested on version 26.04 LTS)
|
||||||
- [x] Rocky (tested on version 9)
|
- [x] Rocky (tested on version 10)
|
||||||
|
|
||||||
on processor architecture:
|
on processor architecture:
|
||||||
|
|
||||||
@@ -28,14 +28,14 @@ on processor architecture:
|
|||||||
|
|
||||||
## ✅ System requirements
|
## ✅ System requirements
|
||||||
|
|
||||||
- Deployment environment must have Ansible 2.4.0+. If you need a quick primer on Ansible [you can check out my docs and setting up Ansible](https://docs.technotim.live/posts/ansible-automation/).
|
- Control Node (the machine you are running `ansible` commands) must have Ansible 2.11+ If you need a quick primer on Ansible [you can check out my docs and setting up Ansible](https://technotim.com/posts/ansible-automation/).
|
||||||
|
|
||||||
|
- You will also need to install collections that this playbook uses by running `ansible-galaxy collection install -r ./collections/requirements.yml` (important❗)
|
||||||
|
|
||||||
- [`netaddr` package](https://pypi.org/project/netaddr/) must be available to Ansible. If you have installed Ansible via apt, this is already taken care of. If you have installed Ansible via `pip`, make sure to install `netaddr` into the respective virtual environment.
|
- [`netaddr` package](https://pypi.org/project/netaddr/) must be available to Ansible. If you have installed Ansible via apt, this is already taken care of. If you have installed Ansible via `pip`, make sure to install `netaddr` into the respective virtual environment.
|
||||||
|
|
||||||
- `server` and `agent` nodes should have passwordless SSH access, if not you can supply arguments to provide credentials `--ask-pass --ask-become-pass` to each command.
|
- `server` and `agent` nodes should have passwordless SSH access, if not you can supply arguments to provide credentials `--ask-pass --ask-become-pass` to each command.
|
||||||
|
|
||||||
- You will also need to install collections that this playbook uses by running `ansible-galaxy collection install -r ./collections/requirements.yml`
|
|
||||||
|
|
||||||
## 🚀 Getting Started
|
## 🚀 Getting Started
|
||||||
|
|
||||||
### 🍴 Preparation
|
### 🍴 Preparation
|
||||||
@@ -67,6 +67,8 @@ node
|
|||||||
|
|
||||||
If multiple hosts are in the master group, the playbook will automatically set up k3s in [HA mode with etcd](https://rancher.com/docs/k3s/latest/en/installation/ha-embedded/).
|
If multiple hosts are in the master group, the playbook will automatically set up k3s in [HA mode with etcd](https://rancher.com/docs/k3s/latest/en/installation/ha-embedded/).
|
||||||
|
|
||||||
|
Finally, copy `ansible.example.cfg` to `ansible.cfg` and adapt the inventory path to match the files that you just created.
|
||||||
|
|
||||||
This requires at least k3s version `1.19.1` however the version is configurable by using the `k3s_version` variable.
|
This requires at least k3s version `1.19.1` however the version is configurable by using the `k3s_version` variable.
|
||||||
|
|
||||||
If needed, you can also edit `inventory/my-cluster/group_vars/all.yml` to match your environment.
|
If needed, you can also edit `inventory/my-cluster/group_vars/all.yml` to match your environment.
|
||||||
@@ -89,21 +91,134 @@ ansible-playbook reset.yml -i inventory/my-cluster/hosts.ini
|
|||||||
|
|
||||||
>You should also reboot these nodes due to the VIP not being destroyed
|
>You should also reboot these nodes due to the VIP not being destroyed
|
||||||
|
|
||||||
|
## 🔁 Upgrading an existing cluster
|
||||||
|
|
||||||
|
These version variables select the components used for a **fresh** installation.
|
||||||
|
They are not a supported direct in-place upgrade path for an existing cluster.
|
||||||
|
K3s, Calico, and Cilium each require staged upgrades for long-lived clusters.
|
||||||
|
|
||||||
|
- **K3s**: do not jump an embedded-etcd cluster straight to Kubernetes 1.36.
|
||||||
|
Upgrade one Kubernetes minor version at a time. From the sample default
|
||||||
|
(`v1.30.2+k3s2`) the sequence is: the latest supported 1.30 patch, then 1.31,
|
||||||
|
1.32, a 1.33 patch that contains etcd 3.5.26 (for example `v1.33.7+k3s3`),
|
||||||
|
then 1.34, 1.35, and finally 1.36. Upgrade servers one at a time before
|
||||||
|
agents. Take backups and confirm cluster health at each step; this playbook
|
||||||
|
does not automate the upgrade, so those remain manual operational steps. See
|
||||||
|
[K3s manual upgrades](https://docs.k3s.io/upgrades/manual) and the
|
||||||
|
[v1.34 release notes](https://docs.k3s.io/release-notes/v1.34.X).
|
||||||
|
- **Cilium**: upstream supports only consecutive minor upgrades. Update to the
|
||||||
|
latest patch of the current minor, then upgrade 1.17, 1.18, 1.19, and 1.20 in
|
||||||
|
order, reading each version's upgrade notes and running preflight checks.
|
||||||
|
Do not attempt a direct upgrade from an old Cilium to 1.20.
|
||||||
|
- **Calico**: starting with 3.28 the v3 resource UID behavior changed. If you
|
||||||
|
have operators with OwnerReferences pointing to `projectcalico.org/v3`
|
||||||
|
resources, remove and recreate those references around an in-place upgrade.
|
||||||
|
- **MetalLB**: this project installs application tag `v0.16.0`. A newer
|
||||||
|
chart-only tag such as `metallb-chart-0.16.1` is not an application or image
|
||||||
|
release and must not be used as the controller or speaker image tag.
|
||||||
|
|
||||||
## ⚙️ Kube Config
|
## ⚙️ Kube Config
|
||||||
|
|
||||||
To copy your `kube config` locally so that you can access your **Kubernetes** cluster run:
|
To copy your `kube config` locally so that you can access your **Kubernetes** cluster run:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
scp debian@master_ip:~/.kube/config ~/.kube/config
|
scp debian@master_ip:/etc/rancher/k3s/k3s.yaml ~/.kube/config
|
||||||
```
|
```
|
||||||
|
If you get file Permission denied, go into the node and temporarly run:
|
||||||
|
```bash
|
||||||
|
sudo chmod 777 /etc/rancher/k3s/k3s.yaml
|
||||||
|
```
|
||||||
|
Then copy with the scp command and reset the permissions back to:
|
||||||
|
```bash
|
||||||
|
sudo chmod 600 /etc/rancher/k3s/k3s.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
You'll then want to modify the config to point to master IP by running:
|
||||||
|
```bash
|
||||||
|
sudo nano ~/.kube/config
|
||||||
|
```
|
||||||
|
Then change `server: https://127.0.0.1:6443` to match your master IP: `server: https://192.168.1.222:6443`
|
||||||
|
|
||||||
### 🔨 Testing your cluster
|
### 🔨 Testing your cluster
|
||||||
|
|
||||||
See the commands [here](https://docs.technotim.live/posts/k3s-etcd-ansible/#testing-your-cluster).
|
See the commands [here](https://technotim.com/posts/k3s-etcd-ansible/#testing-your-cluster).
|
||||||
|
|
||||||
|
### Variables
|
||||||
|
|
||||||
|
| Role(s) | Variable | Type | Default | Required | Description |
|
||||||
|
|---|---|---|---|---|---|
|
||||||
|
| `download` | `k3s_version` | string | ❌ | Required | K3s binaries version |
|
||||||
|
| `k3s_agent`, `k3s_server`, `k3s_server_post` | `apiserver_endpoint` | string | ❌ | Required | Virtual ip-address configured on each master |
|
||||||
|
| `k3s_agent` | `extra_agent_args` | string | `null` | Not required | Extra arguments for agents nodes |
|
||||||
|
| `k3s_agent`, `k3s_server` | `group_name_master` | string | `null` | Not required | Name othe master group |
|
||||||
|
| `k3s_agent` | `k3s_token` | string | `null` | Not required | Token used to communicate between masters |
|
||||||
|
| `k3s_agent`, `k3s_server` | `proxy_env` | dict | `null` | Not required | Internet proxy configurations |
|
||||||
|
| `k3s_agent`, `k3s_server` | `proxy_env.HTTP_PROXY` | string | ❌ | Required | HTTP internet proxy |
|
||||||
|
| `k3s_agent`, `k3s_server` | `proxy_env.HTTPS_PROXY` | string | ❌ | Required | HTTP internet proxy |
|
||||||
|
| `k3s_agent`, `k3s_server` | `proxy_env.NO_PROXY` | string | ❌ | Required | Addresses that will not use the proxies |
|
||||||
|
| `k3s_agent`, `k3s_server`, `reset` | `systemd_dir` | string | `/etc/systemd/system` | Not required | Path to systemd services |
|
||||||
|
| `k3s_custom_registries` | `custom_registries_yaml` | string | ❌ | Required | YAML block defining custom registries. The following is an example that pulls all images used in this playbook through your private registries. It also allows you to pull your own images from your private registry, without having to use imagePullSecrets in your deployments. If all you need is your own images and you don't care about caching the docker/quay/ghcr.io images, you can just remove those from the mirrors: section. |
|
||||||
|
| `k3s_server`, `k3s_server_post` | `cilium_bgp` | bool | `~` | Not required | Enable cilium BGP control plane for LB services and pod cidrs. Disables the use of MetalLB. |
|
||||||
|
| `k3s_server`, `k3s_server_post` | `cilium_iface` | string | ❌ | Not required | The network interface used for when Cilium is enabled |
|
||||||
|
| `k3s_server` | `extra_server_args` | string | `""` | Not required | Extra arguments for server nodes |
|
||||||
|
| `k3s_server` | `k3s_create_kubectl_symlink` | bool | `false` | Not required | Create the kubectl -> k3s symlink |
|
||||||
|
| `k3s_server` | `k3s_create_crictl_symlink` | bool | `true` | Not required | Create the crictl -> k3s symlink |
|
||||||
|
| `k3s_server` | `kube_vip_arp` | bool | `true` | Not required | Enables kube-vip ARP broadcasts |
|
||||||
|
| `k3s_server` | `kube_vip_bgp` | bool | `false` | Not required | Enables kube-vip BGP peering |
|
||||||
|
| `k3s_server` | `kube_vip_bgp_routerid` | string | `"127.0.0.1"` | Not required | Defines the router ID for the kube-vip BGP server |
|
||||||
|
| `k3s_server` | `kube_vip_bgp_as` | string | `"64513"` | Not required | Defines the AS for the kube-vip BGP server |
|
||||||
|
| `k3s_server` | `kube_vip_bgp_peeraddress` | string | `"192.168.30.1"` | Not required | Defines the address for the kube-vip BGP peer |
|
||||||
|
| `k3s_server` | `kube_vip_bgp_peeras` | string | `"64512"` | Not required | Defines the AS for the kube-vip BGP peer |
|
||||||
|
| `k3s_server` | `kube_vip_bgp_peers` | list | `[]` | Not required | List of BGP peer ASN & address pairs |
|
||||||
|
| `k3s_server` | `kube_vip_bgp_peers_groups` | list | `['k3s_master']` | Not required | Inventory group in which to search for additional `kube_vip_bgp_peers` parameters to merge. |
|
||||||
|
| `k3s_server` | `kube_vip_iface` | string | `~` | Not required | Explicitly define an interface that ALL control nodes should use to propagate the VIP, define it here. Otherwise, kube-vip will determine the right interface automatically at runtime. |
|
||||||
|
| `k3s_server` | `kube_vip_tag_version` | string | `v1.2.2` | Not required | Image tag for kube-vip |
|
||||||
|
| `k3s_server` | `kube_vip_cloud_provider_tag_version` | string | `v0.0.12` | Not required | Tag for kube-vip-cloud-provider manifest when enable |
|
||||||
|
| `k3s_server`, `k3_server_post` | `kube_vip_lb_ip_range` | string | `~` | Not required | IP range for kube-vip load balancer |
|
||||||
|
| `k3s_server`, `k3s_server_post` | `metal_lb_controller_tag_version` | string | `v0.16.0` | Not required | Image tag for MetalLB |
|
||||||
|
| `k3s_server` | `metal_lb_speaker_tag_version` | string | `v0.16.0` | Not required | Image tag for MetalLB |
|
||||||
|
| `k3s_server` | `metal_lb_type` | string | `native` | Not required | Use FRR mode or native. Valid values are `frr` and `native` |
|
||||||
|
| `k3s_server` | `retry_count` | int | `20` | Not required | Amount of retries when verifying that nodes joined |
|
||||||
|
| `k3s_server` | `server_init_args` | string | ❌ | Not required | Arguments for server nodes |
|
||||||
|
| `k3s_server_post` | `bpf_lb_algorithm` | string | `maglev` | Not required | BPF lb algorithm |
|
||||||
|
| `k3s_server_post` | `bpf_lb_mode` | string | `hybrid` | Not required | BPF lb mode |
|
||||||
|
| `k3s_server_post` | `calico_blocksize` | int | `26` | Not required | IP pool block size |
|
||||||
|
| `k3s_server_post` | `calico_ebpf` | bool | `false` | Not required | Use eBPF dataplane instead of iptables |
|
||||||
|
| `k3s_server_post` | `calico_encapsulation` | string | `VXLANCrossSubnet` | Not required | IP pool encapsulation |
|
||||||
|
| `k3s_server_post` | `calico_natOutgoing` | string | `Enabled` | Not required | IP pool NAT outgoing |
|
||||||
|
| `k3s_server_post` | `calico_nodeSelector` | string | `all()` | Not required | IP pool node selector |
|
||||||
|
| `k3s_server_post` | `calico_iface` | string | `~` | Not required | The network interface used for when Calico is enabled |
|
||||||
|
| `k3s_server_post` | `calico_tag` | string | `v3.32.1` | Not required | Calico version tag |
|
||||||
|
| `k3s_server_post` | `cilium_bgp_my_asn` | int | `64513` | Not required | Local ASN for BGP peer |
|
||||||
|
| `k3s_server_post` | `cilium_bgp_peer_asn` | int | `64512` | Not required | BGP peer ASN |
|
||||||
|
| `k3s_server_post` | `cilium_bgp_peer_address` | string | `~` | Not required | BGP peer address |
|
||||||
|
| `k3s_server_post` | `cilium_bgp_neighbors` | list | `[]` | Not required | List of BGP peer ASN & address pairs |
|
||||||
|
| `k3s_server_post` | `cilium_bgp_neighbors_groups` | list | `['k3s_all']` | Not required | Inventory group in which to search for additional `cilium_bgp_neighbors` parameters to merge. |
|
||||||
|
| `k3s_server_post` | `cilium_bgp_lb_cidr` | string | `192.168.31.0/24` | Not required | BGP load balancer IP range |
|
||||||
|
| `k3s_server_post` | `cilium_exportPodCIDR` | bool | `true` | Not required | Export pod CIDR |
|
||||||
|
| `k3s_server_post` | `cilium_hubble` | bool | `true` | Not required | Enable Cilium Hubble |
|
||||||
|
| `k3s_server_post` | `cilium_mode` | string | `native` | Not required | Inner-node communication mode (choices are `native` and `tunnel`; `routed` is a deprecated alias for `tunnel`) |
|
||||||
|
| `k3s_server_post` | `cilium_tag` | string | `v1.20.0` | Not required | Cilium version tag |
|
||||||
|
| `k3s_server_post` | `cilium_cli_tag` | string | `v0.19.7` | Not required | Cilium CLI version tag |
|
||||||
|
| `k3s_server_post` | `cluster_cidr` | string | `10.52.0.0/16` | Not required | Inner-cluster IP range |
|
||||||
|
| `k3s_server_post` | `enable_bpf_masquerade` | bool | `true` | Not required | Use IP masquerading |
|
||||||
|
| `k3s_server_post` | `kube_proxy_replacement` | bool | `true` | Not required | Replace the native kube-proxy with Cilium |
|
||||||
|
| `k3s_server_post` | `metal_lb_available_timeout` | string | `240s` | Not required | Wait for MetalLB resources |
|
||||||
|
| `k3s_server_post` | `metal_lb_ip_range` | string | `192.168.30.80-192.168.30.90` | Not required | MetalLB ip range for load balancer |
|
||||||
|
| `k3s_server_post` | `metal_lb_controller_tag_version` | string | `v0.16.0` | Not required | Image tag for MetalLB |
|
||||||
|
| `k3s_server_post` | `metal_lb_mode` | string | `layer2` | Not required | Metallb mode (choices are `bgp` and `layer2`) |
|
||||||
|
| `k3s_server_post` | `metal_lb_bgp_my_asn` | string | `~` | Not required | BGP ASN configurations |
|
||||||
|
| `k3s_server_post` | `metal_lb_bgp_peer_asn` | string | `~` | Not required | BGP peer ASN configurations |
|
||||||
|
| `k3s_server_post` | `metal_lb_bgp_peer_address` | string | `~` | Not required | BGP peer address |
|
||||||
|
| `lxc` | `custom_reboot_command` | string | `~` | Not required | Command to run on reboot |
|
||||||
|
| `prereq` | `system_timezone` | string | `null` | Not required | Timezone to be set on all nodes |
|
||||||
|
| `proxmox_lxc`, `reset_proxmox_lxc` | `proxmox_lxc_ct_ids` | list | ❌ | Required | Proxmox container ID list |
|
||||||
|
| `raspberrypi` | `state` | string | `present` | Not required | Indicates whether the k3s prerequisites for Raspberry Pi should be set up (possible values are `present` and `absent`) |
|
||||||
|
|
||||||
|
|
||||||
### Troubleshooting
|
### Troubleshooting
|
||||||
|
|
||||||
Be sure to see [this post](https://github.com/techno-tim/k3s-ansible/discussions/20) on how to troubleshoot common problems
|
Be sure to see [this post](https://github.com/timothystewart6/k3s-ansible/discussions/20) on how to troubleshoot common problems
|
||||||
|
|
||||||
### Testing the playbook using molecule
|
### Testing the playbook using molecule
|
||||||
|
|
||||||
@@ -112,9 +227,35 @@ It is run automatically in CI, but you can also run the tests locally.
|
|||||||
This might be helpful for quick feedback in a few cases.
|
This might be helpful for quick feedback in a few cases.
|
||||||
You can find more information about it [here](molecule/README.md).
|
You can find more information about it [here](molecule/README.md).
|
||||||
|
|
||||||
|
### Pre-commit Hooks
|
||||||
|
|
||||||
|
This repo uses `pre-commit` and `pre-commit-hooks` to lint and fix common style and syntax errors. Be sure to install python packages and then run `pre-commit install`. For more information, see [pre-commit](https://pre-commit.com/)
|
||||||
|
|
||||||
|
## 🌌 Ansible Galaxy
|
||||||
|
|
||||||
|
This collection can now be used in larger ansible projects.
|
||||||
|
|
||||||
|
Instructions:
|
||||||
|
|
||||||
|
- create or modify a file `collections/requirements.yml` in your project
|
||||||
|
|
||||||
|
```yml
|
||||||
|
collections:
|
||||||
|
- name: ansible.utils
|
||||||
|
- name: community.general
|
||||||
|
- name: ansible.posix
|
||||||
|
- name: kubernetes.core
|
||||||
|
- name: https://github.com/timothystewart6/k3s-ansible.git
|
||||||
|
type: git
|
||||||
|
version: master
|
||||||
|
```
|
||||||
|
|
||||||
|
- install via `ansible-galaxy collection install -r ./collections/requirements.yml`
|
||||||
|
- every role is now available via the prefix `techno_tim.k3s_ansible.` e.g. `techno_tim.k3s_ansible.lxc`
|
||||||
|
|
||||||
## Thanks 🤝
|
## Thanks 🤝
|
||||||
|
|
||||||
This repo is really standing on the shoulders of giants. Thank you to all those who have contributed and tanks to these repos for code and ideas:
|
This repo is really standing on the shoulders of giants. Thank you to all those who have contributed and thanks to these repos for code and ideas:
|
||||||
|
|
||||||
- [k3s-io/k3s-ansible](https://github.com/k3s-io/k3s-ansible)
|
- [k3s-io/k3s-ansible](https://github.com/k3s-io/k3s-ansible)
|
||||||
- [geerlingguy/turing-pi-cluster](https://github.com/geerlingguy/turing-pi-cluster)
|
- [geerlingguy/turing-pi-cluster](https://github.com/geerlingguy/turing-pi-cluster)
|
||||||
|
|||||||
-12
@@ -1,12 +0,0 @@
|
|||||||
[defaults]
|
|
||||||
nocows = True
|
|
||||||
roles_path = ./roles
|
|
||||||
inventory = ./hosts.ini
|
|
||||||
|
|
||||||
remote_tmp = $HOME/.ansible/tmp
|
|
||||||
local_tmp = $HOME/.ansible/tmp
|
|
||||||
pipelining = True
|
|
||||||
become = True
|
|
||||||
host_key_checking = False
|
|
||||||
deprecation_warnings = False
|
|
||||||
callback_whitelist = profile_tasks
|
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
[defaults]
|
||||||
|
inventory = inventory/my-cluster/hosts.ini ; Adapt this to the path to your inventory file
|
||||||
@@ -1,3 +1,3 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
ansible-playbook site.yml -i inventory/my-cluster/hosts.ini
|
ansible-playbook site.yml
|
||||||
|
|||||||
+81
@@ -0,0 +1,81 @@
|
|||||||
|
### REQUIRED
|
||||||
|
# The namespace of the collection. This can be a company/brand/organization or product namespace under which all
|
||||||
|
# content lives. May only contain alphanumeric lowercase characters and underscores. Namespaces cannot start with
|
||||||
|
# underscores or numbers and cannot contain consecutive underscores
|
||||||
|
namespace: techno_tim
|
||||||
|
|
||||||
|
# The name of the collection. Has the same character restrictions as 'namespace'
|
||||||
|
name: k3s_ansible
|
||||||
|
|
||||||
|
# The version of the collection. Must be compatible with semantic versioning
|
||||||
|
version: 1.0.0
|
||||||
|
|
||||||
|
# The path to the Markdown (.md) readme file. This path is relative to the root of the collection
|
||||||
|
readme: README.md
|
||||||
|
|
||||||
|
# A list of the collection's content authors. Can be just the name or in the format 'Full Name <email> (url)
|
||||||
|
# @nicks:irc/im.site#channel'
|
||||||
|
authors:
|
||||||
|
- your name <example@domain.com>
|
||||||
|
|
||||||
|
|
||||||
|
### OPTIONAL but strongly recommended
|
||||||
|
# A short summary description of the collection
|
||||||
|
description: >
|
||||||
|
The easiest way to bootstrap a self-hosted High Availability Kubernetes
|
||||||
|
cluster. A fully automated HA k3s etcd install with kube-vip, MetalLB,
|
||||||
|
and more.
|
||||||
|
|
||||||
|
# Either a single license or a list of licenses for content inside of a collection. Ansible Galaxy currently only
|
||||||
|
# accepts L(SPDX,https://spdx.org/licenses/) licenses. This key is mutually exclusive with 'license_file'
|
||||||
|
license:
|
||||||
|
- Apache-2.0
|
||||||
|
|
||||||
|
|
||||||
|
# A list of tags you want to associate with the collection for indexing/searching. A tag name has the same character
|
||||||
|
# requirements as 'namespace' and 'name'
|
||||||
|
tags:
|
||||||
|
- etcd
|
||||||
|
- high-availability
|
||||||
|
- k8s
|
||||||
|
- k3s
|
||||||
|
- k3s-cluster
|
||||||
|
- kube-vip
|
||||||
|
- kubernetes
|
||||||
|
- metallb
|
||||||
|
- rancher
|
||||||
|
|
||||||
|
# Collections that this collection requires to be installed for it to be usable. The key of the dict is the
|
||||||
|
# collection label 'namespace.name'. The value is a version range
|
||||||
|
# L(specifiers,https://python-semanticversion.readthedocs.io/en/latest/#requirement-specification). Multiple version
|
||||||
|
# range specifiers can be set and are separated by ','
|
||||||
|
dependencies:
|
||||||
|
ansible.utils: '*'
|
||||||
|
ansible.posix: '*'
|
||||||
|
community.general: '*'
|
||||||
|
kubernetes.core: '*'
|
||||||
|
|
||||||
|
# The URL of the originating SCM repository
|
||||||
|
repository: https://github.com/timothystewart6/k3s-ansible
|
||||||
|
|
||||||
|
# The URL to any online docs
|
||||||
|
documentation: https://github.com/timothystewart6/k3s-ansible
|
||||||
|
|
||||||
|
# The URL to the homepage of the collection/project
|
||||||
|
homepage: https://www.youtube.com/watch?v=CbkEWcUZ7zM
|
||||||
|
|
||||||
|
# The URL to the collection issue tracker
|
||||||
|
issues: https://github.com/timothystewart6/k3s-ansible/issues
|
||||||
|
|
||||||
|
# A list of file glob-like patterns used to filter any files or directories that should not be included in the build
|
||||||
|
# artifact. A pattern is matched from the relative path of the file or directory of the collection directory. This
|
||||||
|
# uses 'fnmatch' to match the files or directories. Some directories and files like 'galaxy.yml', '*.pyc', '*.retry',
|
||||||
|
# and '.git' are always filtered. Mutually exclusive with 'manifest'
|
||||||
|
build_ignore: []
|
||||||
|
|
||||||
|
# A dict controlling use of manifest directives used in building the collection artifact. The key 'directives' is a
|
||||||
|
# list of MANIFEST.in style
|
||||||
|
# L(directives,https://packaging.python.org/en/latest/guides/using-manifest-in/#manifest-in-commands). The key
|
||||||
|
# 'omit_default_directives' is a boolean that controls whether the default directives are used. Mutually exclusive
|
||||||
|
# with 'build_ignore'
|
||||||
|
# manifest: null
|
||||||
@@ -1,51 +1,184 @@
|
|||||||
---
|
---
|
||||||
k3s_version: v1.24.6+k3s1
|
k3s_version: v1.36.2+k3s1
|
||||||
# this is the user that has ssh access to these machines
|
# this is the user that has ssh access to these machines
|
||||||
ansible_user: ansibleuser
|
ansible_user: ansibleuser
|
||||||
systemd_dir: /etc/systemd/system
|
systemd_dir: /etc/systemd/system
|
||||||
|
|
||||||
# Set your timezone
|
# Set your timezone
|
||||||
system_timezone: "Your/Timezone"
|
system_timezone: Your/Timezone
|
||||||
|
|
||||||
# interface which will be used for flannel
|
# interface which will be used for flannel
|
||||||
flannel_iface: "eth0"
|
flannel_iface: eth0
|
||||||
|
|
||||||
|
# uncomment calico_iface to use tigera operator/calico cni instead of flannel https://docs.tigera.io/calico/latest/about
|
||||||
|
# calico_iface: "eth0"
|
||||||
|
calico_ebpf: false # use eBPF dataplane instead of iptables
|
||||||
|
calico_tag: v3.32.1 # calico version tag
|
||||||
|
|
||||||
|
# uncomment cilium_iface to use cilium cni instead of flannel or calico
|
||||||
|
# ensure v4.19.57, v5.1.16, v5.2.0 or more recent kernel
|
||||||
|
# cilium_iface: "eth0"
|
||||||
|
cilium_mode: native # native when nodes are on the same subnet or use BGP, otherwise set tunnel
|
||||||
|
cilium_tag: v1.20.0 # cilium version tag
|
||||||
|
cilium_cli_tag: v0.19.7 # cilium cli version tag
|
||||||
|
cilium_hubble: true # enable hubble observability relay and ui
|
||||||
|
|
||||||
|
# if using calico or cilium, you may specify the cluster pod cidr pool
|
||||||
|
cluster_cidr: 10.52.0.0/16
|
||||||
|
|
||||||
|
# enable cilium bgp control plane for lb services and pod cidrs. disables metallb.
|
||||||
|
cilium_bgp: false
|
||||||
|
|
||||||
|
# bgp parameters for cilium cni. only active when cilium_iface is defined and cilium_bgp is true.
|
||||||
|
cilium_bgp_my_asn: "64513"
|
||||||
|
cilium_bgp_peer_asn: "64512"
|
||||||
|
cilium_bgp_peer_address: 192.168.30.1
|
||||||
|
cilium_bgp_lb_cidr: 192.168.31.0/24 # cidr for cilium loadbalancer ipam
|
||||||
|
|
||||||
|
# enable kube-vip ARP broadcasts
|
||||||
|
kube_vip_arp: true
|
||||||
|
|
||||||
|
# enable kube-vip BGP peering
|
||||||
|
kube_vip_bgp: false
|
||||||
|
|
||||||
|
# bgp parameters for kube-vip
|
||||||
|
kube_vip_bgp_routerid: "127.0.0.1" # Defines the router ID for the BGP server
|
||||||
|
kube_vip_bgp_as: "64513" # Defines the AS for the BGP server
|
||||||
|
kube_vip_bgp_peeraddress: "192.168.30.1" # Defines the address for the BGP peer
|
||||||
|
kube_vip_bgp_peeras: "64512" # Defines the AS for the BGP peer
|
||||||
|
|
||||||
# apiserver_endpoint is virtual ip-address which will be configured on each master
|
# apiserver_endpoint is virtual ip-address which will be configured on each master
|
||||||
apiserver_endpoint: "192.168.30.222"
|
apiserver_endpoint: 192.168.30.222
|
||||||
|
|
||||||
# k3s_token is required masters can talk together securely
|
# k3s_token is required masters can talk together securely
|
||||||
# this token should be alpha numeric only
|
# this token should be alpha numeric only
|
||||||
k3s_token: "some-SUPER-DEDEUPER-secret-password"
|
k3s_token: some-SUPER-DEDEUPER-secret-password
|
||||||
|
|
||||||
# The IP on which the node is reachable in the cluster.
|
# The IP on which the node is reachable in the cluster.
|
||||||
# Here, a sensible default is provided, you can still override
|
# Here, a sensible default is provided, you can still override
|
||||||
# it for each of your hosts, though.
|
# it for each of your hosts, though.
|
||||||
k3s_node_ip: '{{ ansible_facts[flannel_iface]["ipv4"]["address"] }}'
|
k3s_node_ip: "{{ ansible_facts[(cilium_iface | default(calico_iface | default(flannel_iface)))]['ipv4']['address'] }}"
|
||||||
|
|
||||||
# Disable the taint manually by setting: k3s_master_taint = false
|
# Disable the taint manually by setting: k3s_master_taint = false
|
||||||
k3s_master_taint: "{{ true if groups['node'] | default([]) | length >= 1 else false }}"
|
k3s_master_taint: "{{ true if groups['node'] | default([]) | length >= 1 else false }}"
|
||||||
|
|
||||||
# these arguments are recommended for servers as well as agents:
|
# these arguments are recommended for servers as well as agents:
|
||||||
extra_args: >-
|
extra_args: >-
|
||||||
--flannel-iface={{ flannel_iface }}
|
{{ '--flannel-iface=' + flannel_iface if calico_iface is not defined and cilium_iface is not defined else '' }}
|
||||||
--node-ip={{ k3s_node_ip }}
|
--node-ip={{ k3s_node_ip }}
|
||||||
|
|
||||||
# change these to your liking, the only required are: --disable servicelb, --tls-san {{ apiserver_endpoint }}
|
# change these to your liking, the only required are: --disable servicelb, --tls-san {{ apiserver_endpoint }}
|
||||||
|
# the contents of the if block is also required if using calico or cilium
|
||||||
extra_server_args: >-
|
extra_server_args: >-
|
||||||
{{ extra_args }}
|
{{ extra_args }}
|
||||||
{{ '--node-taint node-role.kubernetes.io/master=true:NoSchedule' if k3s_master_taint else '' }}
|
{{ '--node-taint node-role.kubernetes.io/master=true:NoSchedule' if k3s_master_taint else '' }}
|
||||||
|
{% if calico_iface is defined or cilium_iface is defined %}
|
||||||
|
--flannel-backend=none
|
||||||
|
--disable-network-policy
|
||||||
|
--cluster-cidr={{ cluster_cidr | default('10.52.0.0/16') }}
|
||||||
|
{% endif %}
|
||||||
--tls-san {{ apiserver_endpoint }}
|
--tls-san {{ apiserver_endpoint }}
|
||||||
--disable servicelb
|
--disable servicelb
|
||||||
--disable traefik
|
--disable traefik
|
||||||
|
|
||||||
extra_agent_args: >-
|
extra_agent_args: >-
|
||||||
{{ extra_args }}
|
{{ extra_args }}
|
||||||
|
|
||||||
# image tag for kube-vip
|
# image tag for kube-vip
|
||||||
kube_vip_tag_version: "v0.5.5"
|
kube_vip_tag_version: v1.2.2
|
||||||
|
|
||||||
|
# tag for kube-vip-cloud-provider manifest
|
||||||
|
# kube_vip_cloud_provider_tag_version: "v0.0.12"
|
||||||
|
|
||||||
|
# kube-vip ip range for load balancer
|
||||||
|
# (uncomment to use kube-vip for services instead of MetalLB)
|
||||||
|
# kube_vip_lb_ip_range: "192.168.30.80-192.168.30.90"
|
||||||
|
|
||||||
|
# metallb type frr or native
|
||||||
|
metal_lb_type: native
|
||||||
|
|
||||||
|
# metallb mode layer2 or bgp
|
||||||
|
metal_lb_mode: layer2
|
||||||
|
|
||||||
|
# bgp options
|
||||||
|
# metal_lb_bgp_my_asn: "64513"
|
||||||
|
# metal_lb_bgp_peer_asn: "64512"
|
||||||
|
# metal_lb_bgp_peer_address: "192.168.30.1"
|
||||||
|
|
||||||
# image tag for metal lb
|
# image tag for metal lb
|
||||||
metal_lb_speaker_tag_version: "v0.13.6"
|
metal_lb_speaker_tag_version: v0.16.0
|
||||||
metal_lb_controller_tag_version: "v0.13.6"
|
metal_lb_controller_tag_version: v0.16.0
|
||||||
|
|
||||||
# metallb ip range for load balancer
|
# metallb ip range for load balancer
|
||||||
metal_lb_ip_range: "192.168.30.80-192.168.30.90"
|
metal_lb_ip_range: 192.168.30.80-192.168.30.90
|
||||||
|
|
||||||
|
# Only enable if your nodes are proxmox LXC nodes, make sure to configure your proxmox nodes
|
||||||
|
# in your hosts.ini file.
|
||||||
|
# Please read https://gist.github.com/triangletodd/02f595cd4c0dc9aac5f7763ca2264185 before using this.
|
||||||
|
# Most notably, your containers must be privileged, and must not have nesting set to true.
|
||||||
|
# Please note this script disables most of the security of lxc containers, with the trade off being that lxc
|
||||||
|
# containers are significantly more resource efficient compared to full VMs.
|
||||||
|
# Mixing and matching VMs and lxc containers is not supported, ymmv if you want to do this.
|
||||||
|
# I would only really recommend using this if you have particularly low powered proxmox nodes where the overhead of
|
||||||
|
# VMs would use a significant portion of your available resources.
|
||||||
|
proxmox_lxc_configure: false
|
||||||
|
# the user that you would use to ssh into the host, for example if you run ssh some-user@my-proxmox-host,
|
||||||
|
# set this value to some-user
|
||||||
|
proxmox_lxc_ssh_user: root
|
||||||
|
# the unique proxmox ids for all of the containers in the cluster, both worker and master nodes
|
||||||
|
proxmox_lxc_ct_ids:
|
||||||
|
- 200
|
||||||
|
- 201
|
||||||
|
- 202
|
||||||
|
- 203
|
||||||
|
- 204
|
||||||
|
|
||||||
|
# Only enable this if you have set up your own container registry to act as a mirror / pull-through cache
|
||||||
|
# (harbor / nexus / docker's official registry / etc).
|
||||||
|
# Can be beneficial for larger dev/test environments (for example if you're getting rate limited by docker hub),
|
||||||
|
# or air-gapped environments where your nodes don't have internet access after the initial setup
|
||||||
|
# (which is still needed for downloading the k3s binary and such).
|
||||||
|
# k3s's documentation about private registries here: https://docs.k3s.io/installation/private-registry
|
||||||
|
custom_registries: false
|
||||||
|
# The registries can be authenticated or anonymous, depending on your registry server configuration.
|
||||||
|
# If they allow anonymous access, simply remove the following bit from custom_registries_yaml
|
||||||
|
# configs:
|
||||||
|
# "registry.domain.com":
|
||||||
|
# auth:
|
||||||
|
# username: yourusername
|
||||||
|
# password: yourpassword
|
||||||
|
# The following is an example that pulls all images used in this playbook through your private registries.
|
||||||
|
# It also allows you to pull your own images from your private registry, without having to use imagePullSecrets
|
||||||
|
# in your deployments.
|
||||||
|
# If all you need is your own images and you don't care about caching the docker/quay/ghcr.io images,
|
||||||
|
# you can just remove those from the mirrors: section.
|
||||||
|
custom_registries_yaml: |
|
||||||
|
mirrors:
|
||||||
|
docker.io:
|
||||||
|
endpoint:
|
||||||
|
- "https://registry.domain.com/v2/dockerhub"
|
||||||
|
quay.io:
|
||||||
|
endpoint:
|
||||||
|
- "https://registry.domain.com/v2/quayio"
|
||||||
|
ghcr.io:
|
||||||
|
endpoint:
|
||||||
|
- "https://registry.domain.com/v2/ghcrio"
|
||||||
|
registry.domain.com:
|
||||||
|
endpoint:
|
||||||
|
- "https://registry.domain.com"
|
||||||
|
|
||||||
|
configs:
|
||||||
|
"registry.domain.com":
|
||||||
|
auth:
|
||||||
|
username: yourusername
|
||||||
|
password: yourpassword
|
||||||
|
|
||||||
|
# On some distros like Diet Pi, there is no dbus installed. dbus required by the default reboot command.
|
||||||
|
# Uncomment if you need a custom reboot command
|
||||||
|
# custom_reboot_command: /usr/sbin/shutdown -r now
|
||||||
|
|
||||||
|
# Only enable and configure these if you access the internet through a proxy
|
||||||
|
# proxy_env:
|
||||||
|
# HTTP_PROXY: "http://proxy.domain.local:3128"
|
||||||
|
# HTTPS_PROXY: "http://proxy.domain.local:3128"
|
||||||
|
# NO_PROXY: "*.domain.local,127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16"
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
---
|
||||||
|
ansible_user: "{{ proxmox_lxc_ssh_user }}"
|
||||||
@@ -7,6 +7,11 @@
|
|||||||
192.168.30.41
|
192.168.30.41
|
||||||
192.168.30.42
|
192.168.30.42
|
||||||
|
|
||||||
|
# only required if proxmox_lxc_configure: true
|
||||||
|
# must contain all proxmox instances that have a master or worker node
|
||||||
|
# [proxmox]
|
||||||
|
# 192.168.30.43
|
||||||
|
|
||||||
[k3s_cluster:children]
|
[k3s_cluster:children]
|
||||||
master
|
master
|
||||||
node
|
node
|
||||||
|
|||||||
@@ -13,6 +13,12 @@ We have these scenarios:
|
|||||||
To save a bit of test time, this cluster is _not_ highly available, it consists of only one control and one worker node.
|
To save a bit of test time, this cluster is _not_ highly available, it consists of only one control and one worker node.
|
||||||
- **single_node**:
|
- **single_node**:
|
||||||
Very similar to the default scenario, but uses only a single node for all cluster functionality.
|
Very similar to the default scenario, but uses only a single node for all cluster functionality.
|
||||||
|
- **calico**:
|
||||||
|
The same as single node, but uses calico cni instead of flannel.
|
||||||
|
- **cilium**:
|
||||||
|
The same as single node, but uses cilium cni instead of flannel.
|
||||||
|
- **kube-vip**
|
||||||
|
The same as single node, but uses kube-vip as service loadbalancer instead of MetalLB
|
||||||
|
|
||||||
## How to execute
|
## How to execute
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,44 @@
|
|||||||
|
---
|
||||||
|
dependency:
|
||||||
|
name: galaxy
|
||||||
|
driver:
|
||||||
|
name: vagrant
|
||||||
|
platforms:
|
||||||
|
- name: control1
|
||||||
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 4096
|
||||||
|
cpus: 4
|
||||||
|
groups:
|
||||||
|
- k3s_cluster
|
||||||
|
- master
|
||||||
|
interfaces:
|
||||||
|
- network_name: private_network
|
||||||
|
ip: 192.168.30.62
|
||||||
|
provisioner:
|
||||||
|
name: ansible
|
||||||
|
env:
|
||||||
|
ANSIBLE_VERBOSITY: 1
|
||||||
|
playbooks:
|
||||||
|
converge: ../resources/converge.yml
|
||||||
|
side_effect: ../resources/reset.yml
|
||||||
|
verify: ../resources/verify.yml
|
||||||
|
inventory:
|
||||||
|
links:
|
||||||
|
group_vars: ../../inventory/sample/group_vars
|
||||||
|
scenario:
|
||||||
|
test_sequence:
|
||||||
|
- dependency
|
||||||
|
- cleanup
|
||||||
|
- destroy
|
||||||
|
- syntax
|
||||||
|
- create
|
||||||
|
- prepare
|
||||||
|
- converge
|
||||||
|
# idempotence is not possible with the playbook in its current form.
|
||||||
|
- verify
|
||||||
|
# We are repurposing side_effect here to test the reset playbook.
|
||||||
|
# This is why we do not run it before verify (which tests the cluster),
|
||||||
|
# but after the verify step.
|
||||||
|
- side_effect
|
||||||
|
- cleanup
|
||||||
|
- destroy
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
- name: Apply overrides
|
||||||
|
hosts: all
|
||||||
|
serial: 1
|
||||||
|
tasks:
|
||||||
|
- name: Override host variables
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
# See:
|
||||||
|
# https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant
|
||||||
|
calico_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
kube_vip_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
|
||||||
|
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
||||||
|
retry_count: 45
|
||||||
|
|
||||||
|
# Make sure that our IP ranges do not collide with those of the other scenarios
|
||||||
|
apiserver_endpoint: 192.168.30.224
|
||||||
|
metal_lb_ip_range: 192.168.30.100-192.168.30.109
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
# Durable verify inputs for the calico (Calico CNI + MetalLB) scenario.
|
||||||
|
verify_cni: calico
|
||||||
|
verify_lb: metallb
|
||||||
|
verify_lb_ip_range:
|
||||||
|
- 192.168.30.100-192.168.30.109
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
---
|
||||||
|
dependency:
|
||||||
|
name: galaxy
|
||||||
|
driver:
|
||||||
|
name: vagrant
|
||||||
|
platforms:
|
||||||
|
- name: control1
|
||||||
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 4096
|
||||||
|
cpus: 4
|
||||||
|
groups:
|
||||||
|
- k3s_cluster
|
||||||
|
- master
|
||||||
|
interfaces:
|
||||||
|
- network_name: private_network
|
||||||
|
ip: 192.168.30.63
|
||||||
|
provisioner:
|
||||||
|
name: ansible
|
||||||
|
env:
|
||||||
|
ANSIBLE_VERBOSITY: 1
|
||||||
|
playbooks:
|
||||||
|
converge: ../resources/converge.yml
|
||||||
|
side_effect: ../resources/reset.yml
|
||||||
|
verify: ../resources/verify.yml
|
||||||
|
inventory:
|
||||||
|
links:
|
||||||
|
group_vars: ../../inventory/sample/group_vars
|
||||||
|
scenario:
|
||||||
|
test_sequence:
|
||||||
|
- dependency
|
||||||
|
- cleanup
|
||||||
|
- destroy
|
||||||
|
- syntax
|
||||||
|
- create
|
||||||
|
- prepare
|
||||||
|
- converge
|
||||||
|
# idempotence is not possible with the playbook in its current form.
|
||||||
|
- verify
|
||||||
|
# We are repurposing side_effect here to test the reset playbook.
|
||||||
|
# This is why we do not run it before verify (which tests the cluster),
|
||||||
|
# but after the verify step.
|
||||||
|
- side_effect
|
||||||
|
- cleanup
|
||||||
|
- destroy
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
- name: Apply overrides
|
||||||
|
hosts: all
|
||||||
|
serial: 1
|
||||||
|
tasks:
|
||||||
|
- name: Override host variables
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
# See:
|
||||||
|
# https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant
|
||||||
|
cilium_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
kube_vip_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
|
||||||
|
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
||||||
|
retry_count: 45
|
||||||
|
|
||||||
|
# Make sure that our IP ranges do not collide with those of the other scenarios
|
||||||
|
apiserver_endpoint: 192.168.30.225
|
||||||
|
metal_lb_ip_range: 192.168.30.110-192.168.30.119
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
# Durable verify inputs for the cilium (Cilium CNI + MetalLB) scenario.
|
||||||
|
verify_cni: cilium
|
||||||
|
verify_lb: metallb
|
||||||
|
verify_lb_ip_range:
|
||||||
|
- 192.168.30.110-192.168.30.119
|
||||||
@@ -0,0 +1,80 @@
|
|||||||
|
---
|
||||||
|
- name: Create
|
||||||
|
hosts: localhost
|
||||||
|
connection: local
|
||||||
|
gather_facts: false
|
||||||
|
no_log: "{{ molecule_no_log }}"
|
||||||
|
vars:
|
||||||
|
create_batches:
|
||||||
|
- [control1, control2]
|
||||||
|
- [control3, node1]
|
||||||
|
- [node2]
|
||||||
|
tasks:
|
||||||
|
- name: Verify that bounded batches cover the configured platforms exactly once
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- create_batches | flatten | sort == molecule_yml.platforms | map(attribute='name') | sort
|
||||||
|
- create_batches | flatten | length == create_batches | flatten | unique | length
|
||||||
|
- create_batches | map('length') | max <= 2
|
||||||
|
fail_msg: Bounded create batches do not match the configured default platforms.
|
||||||
|
|
||||||
|
- name: Generate the complete Vagrant configuration # noqa fqcn[action]
|
||||||
|
vagrant:
|
||||||
|
instances: "{{ molecule_yml.platforms }}"
|
||||||
|
default_box: "{{ molecule_yml.driver.default_box | default('generic/alpine316') }}"
|
||||||
|
provider_name: "{{ molecule_yml.driver.provider.name | default(omit, true) }}"
|
||||||
|
provision: "{{ molecule_yml.driver.provision | default(omit) }}"
|
||||||
|
cachier: "{{ molecule_yml.driver.cachier | default(omit) }}"
|
||||||
|
parallel: false
|
||||||
|
state: halt
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Start clean Vagrant guests in bounded batches
|
||||||
|
ansible.builtin.command:
|
||||||
|
argv: >-
|
||||||
|
{{
|
||||||
|
[playbook_dir + '/../../.github/scripts/vagrant-up-timed.sh',
|
||||||
|
molecule_ephemeral_directory] + item
|
||||||
|
}}
|
||||||
|
loop: "{{ create_batches }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item | join(', ') }}"
|
||||||
|
changed_when: true
|
||||||
|
|
||||||
|
- name: Reconcile all instances and collect their connection configuration # noqa fqcn[action]
|
||||||
|
vagrant:
|
||||||
|
instances: "{{ molecule_yml.platforms }}"
|
||||||
|
default_box: "{{ molecule_yml.driver.default_box | default('generic/alpine316') }}"
|
||||||
|
provider_name: "{{ molecule_yml.driver.provider.name | default(omit, true) }}"
|
||||||
|
provision: "{{ molecule_yml.driver.provision | default(omit) }}"
|
||||||
|
cachier: "{{ molecule_yml.driver.cachier | default(omit) }}"
|
||||||
|
parallel: false
|
||||||
|
state: up
|
||||||
|
register: server
|
||||||
|
no_log: false
|
||||||
|
|
||||||
|
- name: Populate instance configuration dictionaries
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
instance_conf_dict:
|
||||||
|
instance: "{{ item.Host }}"
|
||||||
|
address: "{{ item.HostName }}"
|
||||||
|
user: "{{ item.User }}"
|
||||||
|
port: "{{ item.Port }}"
|
||||||
|
identity_file: "{{ item.IdentityFile }}"
|
||||||
|
loop: "{{ server.results }}"
|
||||||
|
register: instance_config_dict
|
||||||
|
|
||||||
|
- name: Convert instance configuration dictionaries to a list
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
instance_conf: >-
|
||||||
|
{{
|
||||||
|
instance_config_dict.results
|
||||||
|
| map(attribute='ansible_facts.instance_conf_dict')
|
||||||
|
| list
|
||||||
|
}}
|
||||||
|
|
||||||
|
- name: Write Molecule instance configuration
|
||||||
|
ansible.builtin.copy:
|
||||||
|
content: "{{ instance_conf | to_json | from_json | to_yaml }}"
|
||||||
|
dest: "{{ molecule_instance_config }}"
|
||||||
|
mode: "0600"
|
||||||
@@ -3,59 +3,83 @@ dependency:
|
|||||||
name: galaxy
|
name: galaxy
|
||||||
driver:
|
driver:
|
||||||
name: vagrant
|
name: vagrant
|
||||||
.platform_presets:
|
# The Vagrant driver warns that parallel VirtualBox creation can cause
|
||||||
- &control
|
# platform issues. Keep this five-node, mixed-distribution scenario serial.
|
||||||
memory: 2048
|
parallel: false
|
||||||
|
platforms:
|
||||||
|
- name: control1
|
||||||
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 1024
|
||||||
cpus: 2
|
cpus: 2
|
||||||
groups:
|
groups:
|
||||||
- k3s_cluster
|
- k3s_cluster
|
||||||
- master
|
- master
|
||||||
- &node
|
# Keep adapter 2 stable across linked-clone rebuilds so stale host-only
|
||||||
memory: 2048
|
# neighbor state still identifies the current scenario guest.
|
||||||
|
provider_raw_config_args:
|
||||||
|
- "customize ['modifyvm', :id, '--mac-address2', '080027A13038']"
|
||||||
|
interfaces:
|
||||||
|
- network_name: private_network
|
||||||
|
ip: 192.168.30.38
|
||||||
|
|
||||||
|
- name: control2
|
||||||
|
box: bento/debian-13
|
||||||
|
memory: 1024
|
||||||
|
cpus: 2
|
||||||
|
groups:
|
||||||
|
- k3s_cluster
|
||||||
|
- master
|
||||||
|
provider_raw_config_args:
|
||||||
|
- "customize ['modifyvm', :id, '--mac-address2', '080027A13039']"
|
||||||
|
interfaces:
|
||||||
|
- network_name: private_network
|
||||||
|
ip: 192.168.30.39
|
||||||
|
|
||||||
|
- name: control3
|
||||||
|
box: bento/rockylinux-10.1
|
||||||
|
memory: 1024
|
||||||
|
cpus: 2
|
||||||
|
groups:
|
||||||
|
- k3s_cluster
|
||||||
|
- master
|
||||||
|
provider_raw_config_args:
|
||||||
|
- "customize ['modifyvm', :id, '--mac-address2', '080027A13040']"
|
||||||
|
interfaces:
|
||||||
|
- network_name: private_network
|
||||||
|
ip: 192.168.30.40
|
||||||
|
|
||||||
|
- name: node1
|
||||||
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 1024
|
||||||
cpus: 2
|
cpus: 2
|
||||||
groups:
|
groups:
|
||||||
- k3s_cluster
|
- k3s_cluster
|
||||||
- node
|
- node
|
||||||
- &debian
|
provider_raw_config_args:
|
||||||
box: generic/debian11
|
- "customize ['modifyvm', :id, '--mac-address2', '080027A13041']"
|
||||||
- &rocky
|
|
||||||
box: generic/rocky9
|
|
||||||
- &ubuntu
|
|
||||||
box: generic/ubuntu2204
|
|
||||||
config_options:
|
|
||||||
# We currently can not use public-key based authentication on Ubuntu 22.04,
|
|
||||||
# see: https://github.com/chef/bento/issues/1405
|
|
||||||
ssh.username: "vagrant"
|
|
||||||
ssh.password: "vagrant"
|
|
||||||
platforms:
|
|
||||||
- <<: [*control, *ubuntu]
|
|
||||||
name: control1
|
|
||||||
interfaces:
|
|
||||||
- network_name: private_network
|
|
||||||
ip: 192.168.30.38
|
|
||||||
- <<: [*control, *debian]
|
|
||||||
name: control2
|
|
||||||
interfaces:
|
|
||||||
- network_name: private_network
|
|
||||||
ip: 192.168.30.39
|
|
||||||
- <<: [*control, *rocky]
|
|
||||||
name: control3
|
|
||||||
interfaces:
|
|
||||||
- network_name: private_network
|
|
||||||
ip: 192.168.30.40
|
|
||||||
- <<: [*node, *ubuntu]
|
|
||||||
name: node1
|
|
||||||
interfaces:
|
interfaces:
|
||||||
- network_name: private_network
|
- network_name: private_network
|
||||||
ip: 192.168.30.41
|
ip: 192.168.30.41
|
||||||
- <<: [*node, *rocky]
|
|
||||||
name: node2
|
- name: node2
|
||||||
|
box: bento/rockylinux-10.1
|
||||||
|
memory: 1024
|
||||||
|
cpus: 2
|
||||||
|
groups:
|
||||||
|
- k3s_cluster
|
||||||
|
- node
|
||||||
|
provider_raw_config_args:
|
||||||
|
- "customize ['modifyvm', :id, '--mac-address2', '080027A13042']"
|
||||||
interfaces:
|
interfaces:
|
||||||
- network_name: private_network
|
- network_name: private_network
|
||||||
ip: 192.168.30.42
|
ip: 192.168.30.42
|
||||||
|
|
||||||
provisioner:
|
provisioner:
|
||||||
name: ansible
|
name: ansible
|
||||||
|
env:
|
||||||
|
ANSIBLE_VERBOSITY: 1
|
||||||
playbooks:
|
playbooks:
|
||||||
|
create: create.yml
|
||||||
converge: ../resources/converge.yml
|
converge: ../resources/converge.yml
|
||||||
side_effect: ../resources/reset.yml
|
side_effect: ../resources/reset.yml
|
||||||
verify: ../resources/verify.yml
|
verify: ../resources/verify.yml
|
||||||
@@ -65,7 +89,6 @@ provisioner:
|
|||||||
scenario:
|
scenario:
|
||||||
test_sequence:
|
test_sequence:
|
||||||
- dependency
|
- dependency
|
||||||
- lint
|
|
||||||
- cleanup
|
- cleanup
|
||||||
- destroy
|
- destroy
|
||||||
- syntax
|
- syntax
|
||||||
|
|||||||
@@ -1,11 +1,16 @@
|
|||||||
---
|
---
|
||||||
- name: Apply overrides
|
- name: Apply overrides
|
||||||
hosts: all
|
hosts: all
|
||||||
|
serial: 1
|
||||||
tasks:
|
tasks:
|
||||||
- name: Override host variables
|
- name: Override host variables
|
||||||
ansible.builtin.set_fact:
|
ansible.builtin.set_fact:
|
||||||
# See: https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant # noqa yaml[line-length]
|
# See:
|
||||||
flannel_iface: eth1
|
# https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant
|
||||||
|
flannel_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
# kube-vip cannot infer the cluster interface in these multi-NIC
|
||||||
|
# Vagrant guests because the default route is on eth0.
|
||||||
|
kube_vip_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
|
||||||
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
||||||
retry_count: 45
|
retry_count: 45
|
||||||
|
|||||||
@@ -5,18 +5,137 @@
|
|||||||
|
|
||||||
- name: Network setup
|
- name: Network setup
|
||||||
hosts: all
|
hosts: all
|
||||||
|
vars:
|
||||||
|
primary_master: "{{ groups[group_name_master | default('master')][0] }}"
|
||||||
|
primary_cluster_ip: >-
|
||||||
|
{{ hostvars[primary_master].k3s_node_ip | split(',') | first }}
|
||||||
|
cluster_interface: >-
|
||||||
|
{{ cilium_iface | default(calico_iface | default(flannel_iface)) }}
|
||||||
|
primary_cluster_interface: >-
|
||||||
|
{{ hostvars[primary_master].cilium_iface
|
||||||
|
| default(hostvars[primary_master].calico_iface
|
||||||
|
| default(hostvars[primary_master].flannel_iface)) }}
|
||||||
|
primary_cluster_mac: >-
|
||||||
|
{{ hostvars[primary_master].ansible_facts[primary_cluster_interface].macaddress }}
|
||||||
tasks:
|
tasks:
|
||||||
- name: Disable firewalld
|
- name: Gather service facts
|
||||||
when: ansible_distribution == "Rocky"
|
ansible.builtin.service_facts:
|
||||||
# Rocky Linux comes with firewalld enabled. It blocks some of the network
|
|
||||||
# connections needed for our k3s cluster. For our test setup, we just disable
|
- name: Disable guest firewall services
|
||||||
# it since the VM host's firewall is still active for connections to and from
|
# The disposable test guests use an isolated VirtualBox network. A distro
|
||||||
# the Internet.
|
# firewall can allow ICMP while silently blocking the inter-node Kubernetes
|
||||||
|
# API connection, so disable the known guest firewalls consistently.
|
||||||
# When building your own cluster, please DO NOT blindly copy this. Instead,
|
# When building your own cluster, please DO NOT blindly copy this. Instead,
|
||||||
# please create a custom firewall configuration that fits your network design
|
# please create a custom firewall configuration that fits your network design
|
||||||
# and security needs.
|
# and security needs.
|
||||||
ansible.builtin.systemd:
|
ansible.builtin.systemd:
|
||||||
name: firewalld
|
name: "{{ item }}"
|
||||||
enabled: no
|
enabled: false
|
||||||
state: stopped
|
state: stopped
|
||||||
become: true
|
become: true
|
||||||
|
loop:
|
||||||
|
- firewalld.service
|
||||||
|
- nftables.service
|
||||||
|
- ufw.service
|
||||||
|
when: item in ansible_facts.services
|
||||||
|
|
||||||
|
- name: Verify the private cluster interface
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- flannel_iface in ansible_facts
|
||||||
|
- ansible_facts[flannel_iface].ipv4 is defined
|
||||||
|
- ansible_facts[flannel_iface].ipv4.address is defined
|
||||||
|
fail_msg: >-
|
||||||
|
The Vagrant private interface {{ flannel_iface }} does not have an
|
||||||
|
IPv4 address on {{ inventory_hostname }}.
|
||||||
|
|
||||||
|
- name: Pin disposable cluster peer neighbor entries
|
||||||
|
ansible.builtin.command:
|
||||||
|
argv:
|
||||||
|
- ip
|
||||||
|
- neigh
|
||||||
|
- replace
|
||||||
|
- "{{ peer_cluster_ip }}"
|
||||||
|
- lladdr
|
||||||
|
- "{{ peer_cluster_mac }}"
|
||||||
|
- nud
|
||||||
|
- permanent
|
||||||
|
- dev
|
||||||
|
- "{{ cluster_interface }}"
|
||||||
|
become: true
|
||||||
|
changed_when: false
|
||||||
|
loop: "{{ groups['k3s_cluster'] }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ inventory_hostname }} -> {{ item }}"
|
||||||
|
vars:
|
||||||
|
peer_cluster_interface: >-
|
||||||
|
{{ hostvars[item].cilium_iface
|
||||||
|
| default(hostvars[item].calico_iface
|
||||||
|
| default(hostvars[item].flannel_iface)) }}
|
||||||
|
peer_cluster_ip: >-
|
||||||
|
{{ hostvars[item].k3s_node_ip | split(',') | first }}
|
||||||
|
peer_cluster_mac: >-
|
||||||
|
{{ hostvars[item].ansible_facts[peer_cluster_interface].macaddress }}
|
||||||
|
when: item != inventory_hostname
|
||||||
|
|
||||||
|
- name: Verify guest-to-guest cluster network reachability
|
||||||
|
ansible.builtin.command:
|
||||||
|
argv:
|
||||||
|
- ping
|
||||||
|
- -c
|
||||||
|
- "1"
|
||||||
|
- -W
|
||||||
|
- "1"
|
||||||
|
- "{{ primary_cluster_ip }}"
|
||||||
|
register: primary_cluster_ping
|
||||||
|
until: primary_cluster_ping.rc == 0
|
||||||
|
retries: 6
|
||||||
|
delay: 2
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Read the primary neighbor entry
|
||||||
|
ansible.builtin.command:
|
||||||
|
argv:
|
||||||
|
- ip
|
||||||
|
- neigh
|
||||||
|
- show
|
||||||
|
- to
|
||||||
|
- "{{ primary_cluster_ip }}"
|
||||||
|
- dev
|
||||||
|
- "{{ cluster_interface }}"
|
||||||
|
register: primary_cluster_neighbor
|
||||||
|
changed_when: false
|
||||||
|
when: inventory_hostname != primary_master
|
||||||
|
|
||||||
|
- name: Verify the primary neighbor identity
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- (primary_cluster_mac | lower) in (primary_cluster_neighbor.stdout | lower)
|
||||||
|
fail_msg: >-
|
||||||
|
{{ inventory_hostname }} resolved primary {{ primary_cluster_ip }} to
|
||||||
|
an unexpected MAC on {{ cluster_interface }}. Expected
|
||||||
|
{{ primary_cluster_mac }}, got: {{ primary_cluster_neighbor.stdout }}
|
||||||
|
when: inventory_hostname != primary_master
|
||||||
|
|
||||||
|
- name: Verify GitHub release host DNS
|
||||||
|
ansible.builtin.getent:
|
||||||
|
database: hosts
|
||||||
|
key: github.com
|
||||||
|
register: github_dns
|
||||||
|
retries: 6
|
||||||
|
delay: 5
|
||||||
|
until: github_dns is succeeded
|
||||||
|
|
||||||
|
- name: Verify k3s checksum URL is reachable
|
||||||
|
ansible.builtin.uri:
|
||||||
|
url: >-
|
||||||
|
https://github.com/k3s-io/k3s/releases/download/{{ k3s_version
|
||||||
|
}}/sha256sum-amd64.txt
|
||||||
|
method: HEAD
|
||||||
|
follow_redirects: safe
|
||||||
|
status_code: [200, 302]
|
||||||
|
timeout: 15
|
||||||
|
register: k3s_checksum_request
|
||||||
|
retries: 3
|
||||||
|
delay: 5
|
||||||
|
until: k3s_checksum_request.status in [200, 302]
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
# Durable verify inputs for the default (flannel + MetalLB) scenario.
|
||||||
|
# These are plain inventory vars linked into the shared Molecule inventory so
|
||||||
|
# the verify play can see them even though the converge play's set_fact values
|
||||||
|
# are not persisted between the two Ansible processes.
|
||||||
|
verify_cni: flannel
|
||||||
|
verify_lb: metallb
|
||||||
|
verify_lb_ip_range:
|
||||||
|
- 192.168.30.80-192.168.30.90
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
---
|
||||||
|
node_ipv4: 192.168.123.12
|
||||||
|
node_ipv6: fdad:bad:ba55::de:12
|
||||||
+24
-21
@@ -3,39 +3,43 @@ dependency:
|
|||||||
name: galaxy
|
name: galaxy
|
||||||
driver:
|
driver:
|
||||||
name: vagrant
|
name: vagrant
|
||||||
.platform_presets:
|
platforms:
|
||||||
- &control
|
- name: control1
|
||||||
memory: 2048
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 1024
|
||||||
cpus: 2
|
cpus: 2
|
||||||
groups:
|
groups:
|
||||||
- k3s_cluster
|
- k3s_cluster
|
||||||
- master
|
- master
|
||||||
- &node
|
interfaces:
|
||||||
memory: 2048
|
- network_name: private_network
|
||||||
|
ip: fdad:bad:ba55::de:11
|
||||||
|
|
||||||
|
- name: control2
|
||||||
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 1024
|
||||||
|
cpus: 2
|
||||||
|
groups:
|
||||||
|
- k3s_cluster
|
||||||
|
- master
|
||||||
|
interfaces:
|
||||||
|
- network_name: private_network
|
||||||
|
ip: fdad:bad:ba55::de:12
|
||||||
|
|
||||||
|
- name: node1
|
||||||
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 1024
|
||||||
cpus: 2
|
cpus: 2
|
||||||
groups:
|
groups:
|
||||||
- k3s_cluster
|
- k3s_cluster
|
||||||
- node
|
- node
|
||||||
- &ubuntu
|
|
||||||
box: generic/ubuntu2204
|
|
||||||
config_options:
|
|
||||||
# We currently can not use public-key based authentication on Ubuntu 22.04,
|
|
||||||
# see: https://github.com/chef/bento/issues/1405
|
|
||||||
ssh.username: "vagrant"
|
|
||||||
ssh.password: "vagrant"
|
|
||||||
platforms:
|
|
||||||
- <<: [*control, *ubuntu]
|
|
||||||
name: control1
|
|
||||||
interfaces:
|
|
||||||
- network_name: private_network
|
|
||||||
ip: fdad:bad:ba55::de:11
|
|
||||||
- <<: [*node, *ubuntu]
|
|
||||||
name: node1
|
|
||||||
interfaces:
|
interfaces:
|
||||||
- network_name: private_network
|
- network_name: private_network
|
||||||
ip: fdad:bad:ba55::de:21
|
ip: fdad:bad:ba55::de:21
|
||||||
provisioner:
|
provisioner:
|
||||||
name: ansible
|
name: ansible
|
||||||
|
env:
|
||||||
|
ANSIBLE_VERBOSITY: 1
|
||||||
playbooks:
|
playbooks:
|
||||||
converge: ../resources/converge.yml
|
converge: ../resources/converge.yml
|
||||||
side_effect: ../resources/reset.yml
|
side_effect: ../resources/reset.yml
|
||||||
@@ -46,7 +50,6 @@ provisioner:
|
|||||||
scenario:
|
scenario:
|
||||||
test_sequence:
|
test_sequence:
|
||||||
- dependency
|
- dependency
|
||||||
- lint
|
|
||||||
- cleanup
|
- cleanup
|
||||||
- destroy
|
- destroy
|
||||||
- syntax
|
- syntax
|
||||||
|
|||||||
@@ -1,11 +1,18 @@
|
|||||||
---
|
---
|
||||||
- name: Apply overrides
|
- name: Apply overrides
|
||||||
hosts: all
|
hosts: all
|
||||||
|
serial: 1
|
||||||
tasks:
|
tasks:
|
||||||
- name: Override host variables (1/2)
|
- name: Override host variables (1/2)
|
||||||
ansible.builtin.set_fact:
|
ansible.builtin.set_fact:
|
||||||
# See: https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant # noqa yaml[line-length]
|
# See:
|
||||||
flannel_iface: eth1
|
# https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant
|
||||||
|
flannel_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
|
||||||
|
# In this scenario, we have multiple interfaces that the VIP could be
|
||||||
|
# broadcasted on. Since we have assigned a dedicated private network
|
||||||
|
# here, let's make sure that it is used.
|
||||||
|
kube_vip_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
|
||||||
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
||||||
retry_count: 45
|
retry_count: 45
|
||||||
|
|||||||
@@ -38,7 +38,7 @@
|
|||||||
dest: /etc/netplan/55-flannel-ipv4.yaml
|
dest: /etc/netplan/55-flannel-ipv4.yaml
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: 0644
|
mode: "0644"
|
||||||
register: netplan_template
|
register: netplan_template
|
||||||
|
|
||||||
- name: Apply netplan configuration
|
- name: Apply netplan configuration
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
# Durable verify inputs for the ipv6 (flannel CNI + MetalLB) scenario.
|
||||||
|
verify_cni: flannel
|
||||||
|
verify_lb: metallb
|
||||||
|
verify_lb_ip_range:
|
||||||
|
- fdad:bad:ba55::1b:0/112
|
||||||
|
- 192.168.123.80-192.168.123.90
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
---
|
||||||
|
dependency:
|
||||||
|
name: galaxy
|
||||||
|
driver:
|
||||||
|
name: vagrant
|
||||||
|
platforms:
|
||||||
|
- name: control1
|
||||||
|
box: bento/ubuntu-26.04
|
||||||
|
memory: 4096
|
||||||
|
cpus: 4
|
||||||
|
groups:
|
||||||
|
- k3s_cluster
|
||||||
|
- master
|
||||||
|
interfaces:
|
||||||
|
- network_name: private_network
|
||||||
|
ip: 192.168.30.62
|
||||||
|
provisioner:
|
||||||
|
name: ansible
|
||||||
|
env:
|
||||||
|
ANSIBLE_VERBOSITY: 1
|
||||||
|
playbooks:
|
||||||
|
converge: ../resources/converge.yml
|
||||||
|
side_effect: ../resources/reset.yml
|
||||||
|
verify: ../resources/verify.yml
|
||||||
|
inventory:
|
||||||
|
links:
|
||||||
|
group_vars: ../../inventory/sample/group_vars
|
||||||
|
scenario:
|
||||||
|
test_sequence:
|
||||||
|
- dependency
|
||||||
|
- cleanup
|
||||||
|
- destroy
|
||||||
|
- syntax
|
||||||
|
- create
|
||||||
|
- prepare
|
||||||
|
- converge
|
||||||
|
# idempotence is not possible with the playbook in its current form.
|
||||||
|
- verify
|
||||||
|
# We are repurposing side_effect here to test the reset playbook.
|
||||||
|
# This is why we do not run it before verify (which tests the cluster),
|
||||||
|
# but after the verify step.
|
||||||
|
- side_effect
|
||||||
|
- cleanup
|
||||||
|
- destroy
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
- name: Apply overrides
|
||||||
|
hosts: all
|
||||||
|
serial: 1
|
||||||
|
tasks:
|
||||||
|
- name: Override host variables
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
# See:
|
||||||
|
# https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant
|
||||||
|
flannel_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
kube_vip_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
|
||||||
|
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
||||||
|
retry_count: 45
|
||||||
|
|
||||||
|
# Make sure that our IP ranges do not collide with those of the other scenarios
|
||||||
|
apiserver_endpoint: 192.168.30.225
|
||||||
|
# Use kube-vip instead of MetalLB
|
||||||
|
kube_vip_lb_ip_range: 192.168.30.110-192.168.30.119
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
# Durable verify inputs for the kube-vip (flannel CNI + kube-vip LB) scenario.
|
||||||
|
verify_cni: flannel
|
||||||
|
verify_lb: kube-vip
|
||||||
|
# The kube-vip cloud provider tag is not defined in the linked sample group
|
||||||
|
# vars (its sample entry is commented out), so it is supplied here.
|
||||||
|
verify_kube_vip_cloud_provider_tag: v0.0.12
|
||||||
|
verify_lb_ip_range:
|
||||||
|
- 192.168.30.110-192.168.30.119
|
||||||
@@ -1,5 +1,8 @@
|
|||||||
---
|
---
|
||||||
- name: Verify
|
- name: Verify
|
||||||
hosts: all
|
hosts: all
|
||||||
|
vars_files:
|
||||||
|
- >-
|
||||||
|
{{ lookup("ansible.builtin.env", "MOLECULE_SCENARIO_DIRECTORY") }}/verify-vars.yml
|
||||||
roles:
|
roles:
|
||||||
- verify/from_outside
|
- verify_from_outside
|
||||||
|
|||||||
@@ -1,58 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Deploy example
|
|
||||||
block:
|
|
||||||
- name: "Create namespace: {{ testing_namespace }}"
|
|
||||||
kubernetes.core.k8s:
|
|
||||||
api_version: v1
|
|
||||||
kind: Namespace
|
|
||||||
name: "{{ testing_namespace }}"
|
|
||||||
state: present
|
|
||||||
wait: true
|
|
||||||
kubeconfig: "{{ kubecfg_path }}"
|
|
||||||
|
|
||||||
- name: Apply example manifests
|
|
||||||
kubernetes.core.k8s:
|
|
||||||
src: "{{ example_manifests_path }}/{{ item }}"
|
|
||||||
namespace: "{{ testing_namespace }}"
|
|
||||||
state: present
|
|
||||||
wait: true
|
|
||||||
kubeconfig: "{{ kubecfg_path }}"
|
|
||||||
with_items:
|
|
||||||
- deployment.yml
|
|
||||||
- service.yml
|
|
||||||
|
|
||||||
- name: Get info about nginx service
|
|
||||||
kubernetes.core.k8s_info:
|
|
||||||
kind: service
|
|
||||||
name: nginx
|
|
||||||
namespace: "{{ testing_namespace }}"
|
|
||||||
kubeconfig: "{{ kubecfg_path }}"
|
|
||||||
vars: &load_balancer_metadata
|
|
||||||
metallb_ip: status.loadBalancer.ingress[0].ip
|
|
||||||
metallb_port: spec.ports[0].port
|
|
||||||
register: nginx_services
|
|
||||||
|
|
||||||
- name: Assert that the nginx welcome page is available
|
|
||||||
ansible.builtin.uri:
|
|
||||||
url: http://{{ ip | ansible.utils.ipwrap }}:{{ port }}/
|
|
||||||
return_content: yes
|
|
||||||
register: result
|
|
||||||
failed_when: "'Welcome to nginx!' not in result.content"
|
|
||||||
vars:
|
|
||||||
ip: >-
|
|
||||||
{{ nginx_services.resources[0].status.loadBalancer.ingress[0].ip }}
|
|
||||||
port: >-
|
|
||||||
{{ nginx_services.resources[0].spec.ports[0].port }}
|
|
||||||
# Deactivated linter rules:
|
|
||||||
# - jinja[invalid]: As of version 6.6.0, ansible-lint complains that the input to ipwrap
|
|
||||||
# would be undefined. This will not be the case during playbook execution.
|
|
||||||
# noqa jinja[invalid]
|
|
||||||
|
|
||||||
always:
|
|
||||||
- name: "Remove namespace: {{ testing_namespace }}"
|
|
||||||
kubernetes.core.k8s:
|
|
||||||
api_version: v1
|
|
||||||
kind: Namespace
|
|
||||||
name: "{{ testing_namespace }}"
|
|
||||||
state: absent
|
|
||||||
kubeconfig: "{{ kubecfg_path }}"
|
|
||||||
+1
-1
@@ -6,4 +6,4 @@ outside_host: localhost
|
|||||||
testing_namespace: molecule-verify-from-outside
|
testing_namespace: molecule-verify-from-outside
|
||||||
|
|
||||||
# The directory in which the example manifests reside
|
# The directory in which the example manifests reside
|
||||||
example_manifests_path: ../../../../example
|
example_manifests_path: ../../../example
|
||||||
+2
@@ -7,6 +7,8 @@
|
|||||||
ansible.builtin.import_tasks: kubecfg-fetch.yml
|
ansible.builtin.import_tasks: kubecfg-fetch.yml
|
||||||
- name: "TEST CASE: Get nodes"
|
- name: "TEST CASE: Get nodes"
|
||||||
ansible.builtin.include_tasks: test/get-nodes.yml
|
ansible.builtin.include_tasks: test/get-nodes.yml
|
||||||
|
- name: "TEST CASE: Verify components"
|
||||||
|
ansible.builtin.include_tasks: test/verify-components.yml
|
||||||
- name: "TEST CASE: Deploy example"
|
- name: "TEST CASE: Deploy example"
|
||||||
ansible.builtin.include_tasks: test/deploy-example.yml
|
ansible.builtin.include_tasks: test/deploy-example.yml
|
||||||
always:
|
always:
|
||||||
@@ -0,0 +1,127 @@
|
|||||||
|
---
|
||||||
|
- name: Deploy example
|
||||||
|
block:
|
||||||
|
- name: "Create namespace: {{ testing_namespace }}"
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
api_version: v1
|
||||||
|
kind: Namespace
|
||||||
|
name: "{{ testing_namespace }}"
|
||||||
|
state: present
|
||||||
|
wait: true
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
|
||||||
|
- name: Apply example manifests
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
src: "{{ example_manifests_path }}/{{ item }}"
|
||||||
|
namespace: "{{ testing_namespace }}"
|
||||||
|
state: present
|
||||||
|
wait: true
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
with_items:
|
||||||
|
- deployment.yml
|
||||||
|
- service.yml
|
||||||
|
|
||||||
|
- name: Get info about nginx service
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: service
|
||||||
|
name: nginx
|
||||||
|
namespace: "{{ testing_namespace }}"
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
vars:
|
||||||
|
metallb_ip: status.loadBalancer.ingress[0].ip
|
||||||
|
metallb_port: spec.ports[0].port
|
||||||
|
register: nginx_services
|
||||||
|
|
||||||
|
- name: Wait for the load balancer address to be assigned
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
nginx_lb_ip: >-
|
||||||
|
{{
|
||||||
|
nginx_services.resources[0].status.loadBalancer.ingress[0].ip
|
||||||
|
if (nginx_services.resources | length > 0) and
|
||||||
|
(nginx_services.resources[0].status.loadBalancer.ingress is defined) and
|
||||||
|
(nginx_services.resources[0].status.loadBalancer.ingress | length > 0)
|
||||||
|
else ''
|
||||||
|
}}
|
||||||
|
|
||||||
|
- name: Retry until the load balancer service has an external IP
|
||||||
|
block:
|
||||||
|
- name: Refresh nginx service until it has an assigned address
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: service
|
||||||
|
name: nginx
|
||||||
|
namespace: "{{ testing_namespace }}"
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: nginx_lb_wait
|
||||||
|
until: >-
|
||||||
|
(nginx_lb_wait.resources | length > 0) and
|
||||||
|
(nginx_lb_wait.resources[0].status.loadBalancer.ingress is defined) and
|
||||||
|
(nginx_lb_wait.resources[0].status.loadBalancer.ingress | length > 0)
|
||||||
|
retries: 30
|
||||||
|
delay: 5
|
||||||
|
|
||||||
|
- name: Record the assigned load balancer address
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
nginx_lb_ip: >-
|
||||||
|
{{ nginx_lb_wait.resources[0].status.loadBalancer.ingress[0].ip }}
|
||||||
|
|
||||||
|
- name: Assert that the nginx welcome page is available
|
||||||
|
ansible.builtin.uri:
|
||||||
|
url: http://{{ nginx_lb_ip | ansible.utils.ipwrap }}:{{ port_ }}/
|
||||||
|
return_content: true
|
||||||
|
register: result
|
||||||
|
failed_when: "'Welcome to nginx!' not in result.content"
|
||||||
|
vars:
|
||||||
|
port_: >-
|
||||||
|
{{ nginx_services.resources[0].spec.ports[0].port }}
|
||||||
|
|
||||||
|
- name: Initialize load balancer address range check
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
lb_addr_in_range: false
|
||||||
|
lb_ip_value: "{{ nginx_lb_ip }}"
|
||||||
|
|
||||||
|
- name: Check load balancer address against start-end pools
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
lb_addr_in_range: true
|
||||||
|
loop: "{{ verify_lb_ip_range }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item }}"
|
||||||
|
when:
|
||||||
|
- "'-' in item"
|
||||||
|
- "'/' not in item"
|
||||||
|
- >-
|
||||||
|
(lb_ip_value | ansible.utils.ipaddr('int') | int) >=
|
||||||
|
(item.split('-')[0] | ansible.utils.ipaddr('int') | int)
|
||||||
|
- >-
|
||||||
|
(lb_ip_value | ansible.utils.ipaddr('int') | int) <=
|
||||||
|
(item.split('-')[1] | ansible.utils.ipaddr('int') | int)
|
||||||
|
|
||||||
|
- name: Check load balancer address against CIDR pools
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
lb_addr_in_range: true
|
||||||
|
loop: "{{ verify_lb_ip_range }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item }}"
|
||||||
|
when:
|
||||||
|
- "'/' in item"
|
||||||
|
- (lb_ip_value | ansible.utils.ipaddr(item)) is string
|
||||||
|
|
||||||
|
- name: Assert that the load balancer address is within a configured pool
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: lb_addr_in_range
|
||||||
|
success_msg: "LoadBalancer address {{ lb_ip_value }} is in a configured range"
|
||||||
|
fail_msg: >-
|
||||||
|
LoadBalancer address {{ lb_ip_value }} is not in a configured
|
||||||
|
range {{ verify_lb_ip_range }}
|
||||||
|
# Deactivated linter rules:
|
||||||
|
# - jinja[invalid]: As of version 6.6.0, ansible-lint complains that the input to ipwrap
|
||||||
|
# would be undefined. This will not be the case during playbook execution.
|
||||||
|
# noqa jinja[invalid]
|
||||||
|
|
||||||
|
always:
|
||||||
|
- name: "Remove namespace: {{ testing_namespace }}"
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
api_version: v1
|
||||||
|
kind: Namespace
|
||||||
|
name: "{{ testing_namespace }}"
|
||||||
|
state: absent
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
+1
-1
@@ -9,7 +9,7 @@
|
|||||||
ansible.builtin.assert:
|
ansible.builtin.assert:
|
||||||
that: found_nodes == expected_nodes
|
that: found_nodes == expected_nodes
|
||||||
success_msg: "Found nodes as expected: {{ found_nodes }}"
|
success_msg: "Found nodes as expected: {{ found_nodes }}"
|
||||||
fail_msg: "Expected nodes {{ expected_nodes }}, but found nodes {{ found_nodes }}"
|
fail_msg: Expected nodes {{ expected_nodes }}, but found nodes {{ found_nodes }}
|
||||||
vars:
|
vars:
|
||||||
found_nodes: >-
|
found_nodes: >-
|
||||||
{{ cluster_nodes | json_query('resources[*].metadata.name') | unique | sort }}
|
{{ cluster_nodes | json_query('resources[*].metadata.name') | unique | sort }}
|
||||||
@@ -0,0 +1,313 @@
|
|||||||
|
---
|
||||||
|
# Scenario-aware verification of cluster components and their live image tags.
|
||||||
|
# Scenario identity (verify_cni / verify_lb) and expected address range come
|
||||||
|
# from each scenario's verify-vars.yml, which is plain inventory data available
|
||||||
|
# to the verify play. Converge-time set_fact values are not persisted between
|
||||||
|
# the two Ansible processes, so they are never used here.
|
||||||
|
- name: Verify cluster components report expected versions
|
||||||
|
block:
|
||||||
|
- name: Get all nodes with their kubelet versions
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: node
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: verify_nodes
|
||||||
|
|
||||||
|
- name: Assert each node reports the expected Kubernetes version
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: item.status.nodeInfo.kubeletVersion == k3s_version
|
||||||
|
success_msg: "{{ item.metadata.name }} reports {{ k3s_version }}"
|
||||||
|
fail_msg: >-
|
||||||
|
{{ item.metadata.name }} reports
|
||||||
|
{{ item.status.nodeInfo.kubeletVersion }},
|
||||||
|
expected {{ k3s_version }}
|
||||||
|
loop: "{{ verify_nodes.resources }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.metadata.name }}"
|
||||||
|
|
||||||
|
- name: Verify Flannel is the active CNI
|
||||||
|
when: verify_cni == 'flannel'
|
||||||
|
block:
|
||||||
|
- name: Assert every node reports Ready
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: item.status.conditions
|
||||||
|
| selectattr('type', 'equalto', 'Ready')
|
||||||
|
| map(attribute='status') | first | default('') == 'True'
|
||||||
|
success_msg: "{{ item.metadata.name }} is Ready"
|
||||||
|
fail_msg: "{{ item.metadata.name }} is not Ready"
|
||||||
|
loop: "{{ verify_nodes.resources }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.metadata.name }} ready"
|
||||||
|
|
||||||
|
- name: Get any Calico namespaces with Flannel enabled
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: Namespace
|
||||||
|
name: calico-system
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: flannel_calico_absent
|
||||||
|
|
||||||
|
- name: Assert there is no Calico system namespace
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: flannel_calico_absent.resources | length == 0
|
||||||
|
success_msg: "No Calico present with Flannel"
|
||||||
|
fail_msg: "A Calico namespace exists alongside Flannel"
|
||||||
|
|
||||||
|
- name: Get the Cilium namespace with Flannel enabled
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: Namespace
|
||||||
|
name: cilium
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: flannel_cilium
|
||||||
|
|
||||||
|
- name: Assert the Cilium namespace is absent
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: flannel_cilium.resources | length == 0
|
||||||
|
success_msg: "No Cilium present with Flannel"
|
||||||
|
fail_msg: "A Cilium namespace exists alongside Flannel"
|
||||||
|
|
||||||
|
- name: Verify Calico is the active CNI
|
||||||
|
when: verify_cni == 'calico'
|
||||||
|
block:
|
||||||
|
- name: Get the Calico node DaemonSet image
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: DaemonSet
|
||||||
|
name: calico-node
|
||||||
|
namespace: calico-system
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: calico_node_ds
|
||||||
|
|
||||||
|
- name: Assert the Calico node image uses the expected tag
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- calico_node_ds.resources | length == 1
|
||||||
|
- calico_node_image | regex_search(':' ~ calico_tag)
|
||||||
|
success_msg: "Calico node image uses tag {{ calico_tag }}"
|
||||||
|
fail_msg: >-
|
||||||
|
Calico node image {{ calico_node_image }},
|
||||||
|
expected {{ calico_tag }}
|
||||||
|
vars:
|
||||||
|
calico_node_image: "{{ calico_node_ds.resources[0].spec.template.spec.containers[0].image }}"
|
||||||
|
|
||||||
|
- name: Get Calico TigeraStatus for calico and apiserver
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
api_version: operator.tigera.io/v1
|
||||||
|
kind: TigeraStatus
|
||||||
|
name: "{{ item }}"
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: calico_tigerastatus
|
||||||
|
loop:
|
||||||
|
- calico
|
||||||
|
- apiserver
|
||||||
|
loop_control:
|
||||||
|
label: "Tigerastatus/{{ item }}"
|
||||||
|
|
||||||
|
- name: Assert Calico TigeraStatus reports Available
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: >-
|
||||||
|
item.resources | length == 1 and
|
||||||
|
(item.resources[0].status.conditions
|
||||||
|
| selectattr('type', 'equalto', 'Available')
|
||||||
|
| map(attribute='status') | first | default('')) == 'True'
|
||||||
|
success_msg: "Tigerastatus {{ item.resources[0].metadata.name }} is Available"
|
||||||
|
fail_msg: "Tigerastatus is not Available"
|
||||||
|
loop: "{{ calico_tigerastatus.results }}"
|
||||||
|
loop_control:
|
||||||
|
label: "Tigerastatus Available"
|
||||||
|
|
||||||
|
- name: Get any Flannel DaemonSets with Calico enabled
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: DaemonSet
|
||||||
|
namespace: kube-flannel
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: no_flannel_ds
|
||||||
|
|
||||||
|
- name: Assert there are no Flannel DaemonSets
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: no_flannel_ds.resources | length == 0
|
||||||
|
success_msg: "No Flannel DaemonSet present with Calico"
|
||||||
|
fail_msg: "A Flannel DaemonSet exists alongside Calico"
|
||||||
|
|
||||||
|
- name: Verify Cilium is the active CNI
|
||||||
|
when: verify_cni == 'cilium'
|
||||||
|
block:
|
||||||
|
- name: Get the Cilium agent and operator images
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: "{{ item.kind }}"
|
||||||
|
name: "{{ item.name }}"
|
||||||
|
namespace: kube-system
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: cilium_info
|
||||||
|
loop:
|
||||||
|
- { kind: DaemonSet, name: cilium }
|
||||||
|
- { kind: Deployment, name: cilium-operator }
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.kind }}/{{ item.name }}"
|
||||||
|
|
||||||
|
- name: Assert Cilium agent and operator use the expected image tag
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- cilium_agent_image | regex_search(':' ~ cilium_tag)
|
||||||
|
- cilium_operator_image | regex_search(':' ~ cilium_tag)
|
||||||
|
success_msg: "Cilium agent and operator use {{ cilium_tag }}"
|
||||||
|
fail_msg: >-
|
||||||
|
Cilium agent {{ cilium_agent_image }},
|
||||||
|
operator {{ cilium_operator_image }},
|
||||||
|
expected {{ cilium_tag }}
|
||||||
|
vars:
|
||||||
|
cilium_agent_image: >-
|
||||||
|
{{ (cilium_info.results
|
||||||
|
| selectattr('resources', 'defined')
|
||||||
|
| map(attribute='resources')
|
||||||
|
| list
|
||||||
|
| map(attribute='0')
|
||||||
|
| selectattr('kind', 'equalto', 'DaemonSet')
|
||||||
|
| list)[0].spec.template.spec.containers[0].image }}
|
||||||
|
cilium_operator_image: >-
|
||||||
|
{{ (cilium_info.results
|
||||||
|
| selectattr('resources', 'defined')
|
||||||
|
| map(attribute='resources')
|
||||||
|
| list
|
||||||
|
| map(attribute='0')
|
||||||
|
| selectattr('kind', 'equalto', 'Deployment')
|
||||||
|
| list)[0].spec.template.spec.containers[0].image }}
|
||||||
|
|
||||||
|
- name: Get Hubble relay and UI deployments when enabled
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: Deployment
|
||||||
|
name: "{{ item }}"
|
||||||
|
namespace: kube-system
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: hubble_info
|
||||||
|
loop:
|
||||||
|
- hubble-relay
|
||||||
|
- hubble-ui
|
||||||
|
loop_control:
|
||||||
|
label: "Deployment/{{ item }}"
|
||||||
|
when: cilium_hubble | bool
|
||||||
|
|
||||||
|
- name: Assert Hubble components are Ready when enabled
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- item.resources | length == 1
|
||||||
|
- item.resources[0].status.readyReplicas | default(0) >= 1
|
||||||
|
success_msg: "Hubble deployment {{ item.resources[0].metadata.name }} is Ready"
|
||||||
|
fail_msg: "Hubble deployment is not Ready"
|
||||||
|
loop: "{{ hubble_info.results }}"
|
||||||
|
loop_control:
|
||||||
|
label: "Hubble deployment"
|
||||||
|
when: cilium_hubble | bool
|
||||||
|
|
||||||
|
- name: Get any Flannel DaemonSets with Cilium enabled
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: DaemonSet
|
||||||
|
namespace: kube-flannel
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: no_flannel_ds_cilium
|
||||||
|
|
||||||
|
- name: Assert there are no Flannel DaemonSets
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: no_flannel_ds_cilium.resources | length == 0
|
||||||
|
success_msg: "No Flannel DaemonSet present with Cilium"
|
||||||
|
fail_msg: "A Flannel DaemonSet exists alongside Cilium"
|
||||||
|
|
||||||
|
- name: Verify MetalLB is the active load balancer
|
||||||
|
when: verify_lb == 'metallb'
|
||||||
|
block:
|
||||||
|
- name: Get the MetalLB controller and speaker images
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: "{{ item.kind }}"
|
||||||
|
name: "{{ item.name }}"
|
||||||
|
namespace: metallb-system
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: metallb_info
|
||||||
|
loop:
|
||||||
|
- { kind: Deployment, name: controller }
|
||||||
|
- { kind: DaemonSet, name: speaker }
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.kind }}/{{ item.name }}"
|
||||||
|
|
||||||
|
- name: Assert MetalLB controller and speaker use the expected image tags
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- controller_image | regex_search(metal_lb_controller_tag_version)
|
||||||
|
- speaker_image | regex_search(metal_lb_speaker_tag_version)
|
||||||
|
success_msg: >-
|
||||||
|
MetalLB controller {{ metal_lb_controller_tag_version }},
|
||||||
|
speaker {{ metal_lb_speaker_tag_version }}
|
||||||
|
fail_msg: >-
|
||||||
|
MetalLB controller {{ controller_image }},
|
||||||
|
speaker {{ speaker_image }}
|
||||||
|
vars:
|
||||||
|
controller_image: >-
|
||||||
|
{{ (metallb_info.results
|
||||||
|
| selectattr('resources', 'defined')
|
||||||
|
| map(attribute='resources')
|
||||||
|
| list
|
||||||
|
| map(attribute='0')
|
||||||
|
| selectattr('kind', 'equalto', 'Deployment')
|
||||||
|
| list)[0].spec.template.spec.containers[0].image }}
|
||||||
|
speaker_image: >-
|
||||||
|
{{ (metallb_info.results
|
||||||
|
| selectattr('resources', 'defined')
|
||||||
|
| map(attribute='resources')
|
||||||
|
| list
|
||||||
|
| map(attribute='0')
|
||||||
|
| selectattr('kind', 'equalto', 'DaemonSet')
|
||||||
|
| list)[0].spec.template.spec.containers[0].image }}
|
||||||
|
|
||||||
|
- name: Verify kube-vip is the active load balancer
|
||||||
|
when: verify_lb == 'kube-vip'
|
||||||
|
block:
|
||||||
|
- name: Get the kube-vip and cloud provider images
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: "{{ item.kind }}"
|
||||||
|
name: "{{ item.name }}"
|
||||||
|
namespace: kube-system
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: kubevip_info
|
||||||
|
loop:
|
||||||
|
- { kind: DaemonSet, name: kube-vip-ds }
|
||||||
|
- { kind: Deployment, name: kube-vip-cloud-provider }
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.kind }}/{{ item.name }}"
|
||||||
|
|
||||||
|
- name: Assert the kube-vip and cloud provider image tags
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that:
|
||||||
|
- kubevip_image | regex_search(':' ~ kube_vip_tag_version)
|
||||||
|
- cloud_provider_image | regex_search(verify_kube_vip_cloud_provider_tag)
|
||||||
|
success_msg: >-
|
||||||
|
kube-vip {{ kube_vip_tag_version }},
|
||||||
|
cloud provider {{ verify_kube_vip_cloud_provider_tag }}
|
||||||
|
fail_msg: >-
|
||||||
|
kube-vip {{ kubevip_image }},
|
||||||
|
cloud provider {{ cloud_provider_image }}
|
||||||
|
vars:
|
||||||
|
kubevip_image: >-
|
||||||
|
{{ (kubevip_info.results
|
||||||
|
| selectattr('resources', 'defined')
|
||||||
|
| map(attribute='resources')
|
||||||
|
| list
|
||||||
|
| map(attribute='0')
|
||||||
|
| selectattr('kind', 'equalto', 'DaemonSet')
|
||||||
|
| list)[0].spec.template.spec.containers[0].image }}
|
||||||
|
cloud_provider_image: >-
|
||||||
|
{{ (kubevip_info.results
|
||||||
|
| selectattr('resources', 'defined')
|
||||||
|
| map(attribute='resources')
|
||||||
|
| list
|
||||||
|
| map(attribute='0')
|
||||||
|
| selectattr('kind', 'equalto', 'Deployment')
|
||||||
|
| list)[0].spec.template.spec.containers[0].image }}
|
||||||
|
|
||||||
|
- name: Get the MetalLB namespace with kube-vip enabled
|
||||||
|
kubernetes.core.k8s_info:
|
||||||
|
kind: Namespace
|
||||||
|
name: metallb-system
|
||||||
|
kubeconfig: "{{ kubecfg_path }}"
|
||||||
|
register: metallb_absent
|
||||||
|
|
||||||
|
- name: Assert the MetalLB namespace does not exist
|
||||||
|
ansible.builtin.assert:
|
||||||
|
that: metallb_absent.resources | length == 0
|
||||||
|
success_msg: "MetalLB is not installed with kube-vip"
|
||||||
|
fail_msg: "MetalLB namespace exists alongside kube-vip"
|
||||||
@@ -5,14 +5,9 @@ driver:
|
|||||||
name: vagrant
|
name: vagrant
|
||||||
platforms:
|
platforms:
|
||||||
- name: control1
|
- name: control1
|
||||||
box: generic/ubuntu2204
|
box: bento/ubuntu-26.04
|
||||||
memory: 4096
|
memory: 4096
|
||||||
cpus: 4
|
cpus: 4
|
||||||
config_options:
|
|
||||||
# We currently can not use public-key based authentication on Ubuntu 22.04,
|
|
||||||
# see: https://github.com/chef/bento/issues/1405
|
|
||||||
ssh.username: "vagrant"
|
|
||||||
ssh.password: "vagrant"
|
|
||||||
groups:
|
groups:
|
||||||
- k3s_cluster
|
- k3s_cluster
|
||||||
- master
|
- master
|
||||||
@@ -21,6 +16,8 @@ platforms:
|
|||||||
ip: 192.168.30.50
|
ip: 192.168.30.50
|
||||||
provisioner:
|
provisioner:
|
||||||
name: ansible
|
name: ansible
|
||||||
|
env:
|
||||||
|
ANSIBLE_VERBOSITY: 1
|
||||||
playbooks:
|
playbooks:
|
||||||
converge: ../resources/converge.yml
|
converge: ../resources/converge.yml
|
||||||
side_effect: ../resources/reset.yml
|
side_effect: ../resources/reset.yml
|
||||||
@@ -31,7 +28,6 @@ provisioner:
|
|||||||
scenario:
|
scenario:
|
||||||
test_sequence:
|
test_sequence:
|
||||||
- dependency
|
- dependency
|
||||||
- lint
|
|
||||||
- cleanup
|
- cleanup
|
||||||
- destroy
|
- destroy
|
||||||
- syntax
|
- syntax
|
||||||
|
|||||||
@@ -1,15 +1,18 @@
|
|||||||
---
|
---
|
||||||
- name: Apply overrides
|
- name: Apply overrides
|
||||||
hosts: all
|
hosts: all
|
||||||
|
serial: 1
|
||||||
tasks:
|
tasks:
|
||||||
- name: Override host variables
|
- name: Override host variables
|
||||||
ansible.builtin.set_fact:
|
ansible.builtin.set_fact:
|
||||||
# See: https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant # noqa yaml[line-length]
|
# See:
|
||||||
flannel_iface: eth1
|
# https://github.com/flannel-io/flannel/blob/67d603aaf45ef80f5dd39f43714fc5e6f8a637eb/Documentation/troubleshooting.md#Vagrant
|
||||||
|
flannel_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
kube_vip_iface: "{{ 'eth1' if 'eth1' in ansible_facts.interfaces else 'enp0s8' }}"
|
||||||
|
|
||||||
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
# The test VMs might be a bit slow, so we give them more time to join the cluster:
|
||||||
retry_count: 45
|
retry_count: 45
|
||||||
|
|
||||||
# Make sure that our IP ranges do not collide with those of the default scenario
|
# Make sure that our IP ranges do not collide with those of the default scenario
|
||||||
apiserver_endpoint: "192.168.30.223"
|
apiserver_endpoint: 192.168.30.223
|
||||||
metal_lb_ip_range: "192.168.30.91-192.168.30.99"
|
metal_lb_ip_range: 192.168.30.91-192.168.30.99
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
# Durable verify inputs for the single_node (flannel + MetalLB) scenario.
|
||||||
|
verify_cni: flannel
|
||||||
|
verify_lb: metallb
|
||||||
|
verify_lb_ip_range:
|
||||||
|
- 192.168.30.91-192.168.30.99
|
||||||
+10
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
- name: Reboot k3s_cluster
|
||||||
|
hosts: k3s_cluster
|
||||||
|
gather_facts: true
|
||||||
|
tasks:
|
||||||
|
- name: Reboot the nodes (and Wait upto 5 mins max)
|
||||||
|
become: true
|
||||||
|
ansible.builtin.reboot:
|
||||||
|
reboot_command: "{{ custom_reboot_command | default(omit) }}"
|
||||||
|
reboot_timeout: 300
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
ansible-core>=2.16.2
|
||||||
|
jmespath>=1.0.1
|
||||||
|
jsonpatch>=1.33
|
||||||
|
kubernetes>=29.0.0
|
||||||
|
molecule-plugins[vagrant]
|
||||||
|
molecule>=6.0.3
|
||||||
|
netaddr>=0.10.1
|
||||||
|
pre-commit>=3.6.0
|
||||||
|
pre-commit-hooks>=4.5.0
|
||||||
|
pyyaml>=6.0.1
|
||||||
+161
-63
@@ -1,71 +1,169 @@
|
|||||||
ansible-compat==2.2.1
|
#
|
||||||
ansible-core==2.13.5
|
# This file is autogenerated by pip-compile with Python 3.11
|
||||||
ansible-lint==6.8.2
|
# by the following command:
|
||||||
arrow==1.2.3
|
#
|
||||||
attrs==22.1.0
|
# pip-compile requirements.in
|
||||||
binaryornot==0.4.4
|
#
|
||||||
black==22.10.0
|
ansible-compat==4.1.11
|
||||||
bracex==2.3.post1
|
# via molecule
|
||||||
cachetools==5.2.0
|
ansible-core==2.18.0
|
||||||
Cerberus==1.3.2
|
# via
|
||||||
certifi==2022.9.24
|
# -r requirements.in
|
||||||
cffi==1.15.1
|
# ansible-compat
|
||||||
chardet==5.0.0
|
# molecule
|
||||||
charset-normalizer==2.1.1
|
attrs==23.2.0
|
||||||
click==8.1.3
|
# via
|
||||||
click-help-colors==0.9.1
|
# jsonschema
|
||||||
commonmark==0.9.1
|
# referencing
|
||||||
cookiecutter==2.1.1
|
bracex==2.4
|
||||||
cryptography==38.0.1
|
# via wcmatch
|
||||||
distro==1.8.0
|
cachetools==5.3.2
|
||||||
|
# via google-auth
|
||||||
|
certifi==2023.11.17
|
||||||
|
# via
|
||||||
|
# kubernetes
|
||||||
|
# requests
|
||||||
|
cffi==1.16.0
|
||||||
|
# via cryptography
|
||||||
|
cfgv==3.4.0
|
||||||
|
# via pre-commit
|
||||||
|
charset-normalizer==3.3.2
|
||||||
|
# via requests
|
||||||
|
click==8.1.7
|
||||||
|
# via
|
||||||
|
# click-help-colors
|
||||||
|
# molecule
|
||||||
|
click-help-colors==0.9.4
|
||||||
|
# via molecule
|
||||||
|
cryptography==41.0.7
|
||||||
|
# via ansible-core
|
||||||
|
distlib==0.3.8
|
||||||
|
# via virtualenv
|
||||||
enrich==1.2.7
|
enrich==1.2.7
|
||||||
filelock==3.8.0
|
# via molecule
|
||||||
google-auth==2.12.0
|
filelock==3.13.1
|
||||||
idna==3.4
|
# via virtualenv
|
||||||
importlib-resources==5.10.0
|
google-auth==2.26.2
|
||||||
Jinja2==3.1.2
|
# via kubernetes
|
||||||
jinja2-time==0.2.0
|
identify==2.5.33
|
||||||
|
# via pre-commit
|
||||||
|
idna==3.6
|
||||||
|
# via requests
|
||||||
|
jinja2==3.1.3
|
||||||
|
# via
|
||||||
|
# ansible-core
|
||||||
|
# molecule
|
||||||
jmespath==1.0.1
|
jmespath==1.0.1
|
||||||
jsonpatch==1.32
|
# via -r requirements.in
|
||||||
jsonpointer==2.3
|
jsonpatch==1.33
|
||||||
jsonschema==4.16.0
|
# via -r requirements.in
|
||||||
kubernetes==24.2.0
|
jsonpointer==2.4
|
||||||
MarkupSafe==2.1.1
|
# via jsonpatch
|
||||||
molecule==4.0.1
|
jsonschema==4.21.1
|
||||||
molecule-vagrant==1.0.0
|
# via
|
||||||
mypy-extensions==0.4.3
|
# ansible-compat
|
||||||
netaddr==0.8.0
|
# molecule
|
||||||
oauthlib==3.2.1
|
jsonschema-specifications==2023.12.1
|
||||||
packaging==21.3
|
# via jsonschema
|
||||||
pathspec==0.10.1
|
kubernetes==29.0.0
|
||||||
pkgutil-resolve-name==1.3.10
|
# via -r requirements.in
|
||||||
platformdirs==2.5.2
|
markdown-it-py==3.0.0
|
||||||
pluggy==1.0.0
|
# via rich
|
||||||
pyasn1==0.4.8
|
markupsafe==2.1.4
|
||||||
pyasn1-modules==0.2.8
|
# via jinja2
|
||||||
|
mdurl==0.1.2
|
||||||
|
# via markdown-it-py
|
||||||
|
molecule==6.0.3
|
||||||
|
# via
|
||||||
|
# -r requirements.in
|
||||||
|
# molecule-plugins
|
||||||
|
molecule-plugins[vagrant]==23.5.3
|
||||||
|
# via -r requirements.in
|
||||||
|
netaddr==0.10.1
|
||||||
|
# via -r requirements.in
|
||||||
|
nodeenv==1.8.0
|
||||||
|
# via pre-commit
|
||||||
|
oauthlib==3.2.2
|
||||||
|
# via
|
||||||
|
# kubernetes
|
||||||
|
# requests-oauthlib
|
||||||
|
packaging==23.2
|
||||||
|
# via
|
||||||
|
# ansible-compat
|
||||||
|
# ansible-core
|
||||||
|
# molecule
|
||||||
|
platformdirs==4.1.0
|
||||||
|
# via virtualenv
|
||||||
|
pluggy==1.3.0
|
||||||
|
# via molecule
|
||||||
|
pre-commit==3.8.0
|
||||||
|
# via -r requirements.in
|
||||||
|
pre-commit-hooks==4.6.0
|
||||||
|
# via -r requirements.in
|
||||||
|
pyasn1==0.5.1
|
||||||
|
# via
|
||||||
|
# pyasn1-modules
|
||||||
|
# rsa
|
||||||
|
pyasn1-modules==0.3.0
|
||||||
|
# via google-auth
|
||||||
pycparser==2.21
|
pycparser==2.21
|
||||||
Pygments==2.13.0
|
# via cffi
|
||||||
pyparsing==3.0.9
|
pygments==2.17.2
|
||||||
pyrsistent==0.18.1
|
# via rich
|
||||||
python-dateutil==2.8.2
|
python-dateutil==2.8.2
|
||||||
python-slugify==6.1.2
|
# via kubernetes
|
||||||
python-vagrant==1.0.0
|
python-vagrant==1.0.0
|
||||||
PyYAML==6.0
|
# via molecule-plugins
|
||||||
requests==2.28.1
|
pyyaml==6.0.2
|
||||||
|
# via
|
||||||
|
# -r requirements.in
|
||||||
|
# ansible-compat
|
||||||
|
# ansible-core
|
||||||
|
# kubernetes
|
||||||
|
# molecule
|
||||||
|
# pre-commit
|
||||||
|
referencing==0.32.1
|
||||||
|
# via
|
||||||
|
# jsonschema
|
||||||
|
# jsonschema-specifications
|
||||||
|
requests==2.31.0
|
||||||
|
# via
|
||||||
|
# kubernetes
|
||||||
|
# requests-oauthlib
|
||||||
requests-oauthlib==1.3.1
|
requests-oauthlib==1.3.1
|
||||||
resolvelib==0.8.1
|
# via kubernetes
|
||||||
rich==12.6.0
|
resolvelib==1.0.1
|
||||||
|
# via ansible-core
|
||||||
|
rich==13.7.0
|
||||||
|
# via
|
||||||
|
# enrich
|
||||||
|
# molecule
|
||||||
|
rpds-py==0.17.1
|
||||||
|
# via
|
||||||
|
# jsonschema
|
||||||
|
# referencing
|
||||||
rsa==4.9
|
rsa==4.9
|
||||||
ruamel.yaml==0.17.21
|
# via google-auth
|
||||||
ruamel.yaml.clib==0.2.6
|
ruamel-yaml==0.18.5
|
||||||
selinux==0.2.1
|
# via pre-commit-hooks
|
||||||
|
ruamel-yaml-clib==0.2.8
|
||||||
|
# via ruamel-yaml
|
||||||
six==1.16.0
|
six==1.16.0
|
||||||
subprocess-tee==0.3.5
|
# via
|
||||||
text-unidecode==1.3
|
# kubernetes
|
||||||
tomli==2.0.1
|
# python-dateutil
|
||||||
typing-extensions==4.4.0
|
subprocess-tee==0.4.1
|
||||||
urllib3==1.26.12
|
# via ansible-compat
|
||||||
wcmatch==8.4.1
|
urllib3==2.1.0
|
||||||
websocket-client==1.4.1
|
# via
|
||||||
yamllint==1.28.0
|
# kubernetes
|
||||||
zipp==3.9.0
|
# requests
|
||||||
|
virtualenv==20.25.0
|
||||||
|
# via pre-commit
|
||||||
|
wcmatch==8.5
|
||||||
|
# via molecule
|
||||||
|
websocket-client==1.7.0
|
||||||
|
# via kubernetes
|
||||||
|
|
||||||
|
# The following packages are considered to be unsafe in a requirements file:
|
||||||
|
# setuptools
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
ansible-playbook reset.yml -i inventory/my-cluster/hosts.ini
|
ansible-playbook reset.yml
|
||||||
|
|||||||
@@ -1,13 +1,25 @@
|
|||||||
---
|
---
|
||||||
|
- name: Reset k3s cluster
|
||||||
- hosts: k3s_cluster
|
hosts: k3s_cluster
|
||||||
gather_facts: yes
|
gather_facts: true
|
||||||
become: yes
|
|
||||||
roles:
|
roles:
|
||||||
- role: reset
|
- role: reset
|
||||||
|
become: true
|
||||||
- role: raspberrypi
|
- role: raspberrypi
|
||||||
vars: {state: absent}
|
become: true
|
||||||
|
vars: { state: absent }
|
||||||
post_tasks:
|
post_tasks:
|
||||||
- name: Reboot and wait for node to come back up
|
- name: Reboot and wait for node to come back up
|
||||||
reboot:
|
become: true
|
||||||
|
ansible.builtin.reboot:
|
||||||
|
reboot_command: "{{ custom_reboot_command | default(omit) }}"
|
||||||
reboot_timeout: 3600
|
reboot_timeout: 3600
|
||||||
|
|
||||||
|
- name: Revert changes to Proxmox cluster
|
||||||
|
hosts: proxmox
|
||||||
|
gather_facts: true
|
||||||
|
become: true
|
||||||
|
remote_user: "{{ proxmox_lxc_ssh_user }}"
|
||||||
|
roles:
|
||||||
|
- role: reset_proxmox_lxc
|
||||||
|
when: proxmox_lxc_configure
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
argument_specs:
|
||||||
|
main:
|
||||||
|
short_description: Manage the downloading of K3S binaries
|
||||||
|
options:
|
||||||
|
k3s_version:
|
||||||
|
description: The desired version of K3S
|
||||||
|
required: true
|
||||||
@@ -1,36 +1,46 @@
|
|||||||
---
|
---
|
||||||
|
|
||||||
- name: Download k3s binary x64
|
- name: Download k3s binary x64
|
||||||
get_url:
|
ansible.builtin.get_url:
|
||||||
url: https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/k3s
|
url: https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/k3s
|
||||||
checksum: sha256:https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/sha256sum-amd64.txt
|
checksum: sha256:https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/sha256sum-amd64.txt
|
||||||
dest: /usr/local/bin/k3s
|
dest: /usr/local/bin/k3s
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: 0755
|
mode: "0755"
|
||||||
|
register: k3s_download_x64
|
||||||
|
retries: 5
|
||||||
|
delay: 10
|
||||||
|
until: k3s_download_x64 is succeeded
|
||||||
when: ansible_facts.architecture == "x86_64"
|
when: ansible_facts.architecture == "x86_64"
|
||||||
|
|
||||||
- name: Download k3s binary arm64
|
- name: Download k3s binary arm64
|
||||||
get_url:
|
ansible.builtin.get_url:
|
||||||
url: https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/k3s-arm64
|
url: https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/k3s-arm64
|
||||||
checksum: sha256:https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/sha256sum-arm64.txt
|
checksum: sha256:https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/sha256sum-arm64.txt
|
||||||
dest: /usr/local/bin/k3s
|
dest: /usr/local/bin/k3s
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: 0755
|
mode: "0755"
|
||||||
|
register: k3s_download_arm64
|
||||||
|
retries: 5
|
||||||
|
delay: 10
|
||||||
|
until: k3s_download_arm64 is succeeded
|
||||||
when:
|
when:
|
||||||
- ( ansible_facts.architecture is search("arm") and
|
- ( ansible_facts.architecture is search("arm") and ansible_facts.userspace_bits == "64" )
|
||||||
ansible_facts.userspace_bits == "64" ) or
|
or ansible_facts.architecture is search("aarch64")
|
||||||
ansible_facts.architecture is search("aarch64")
|
|
||||||
|
|
||||||
- name: Download k3s binary armhf
|
- name: Download k3s binary armhf
|
||||||
get_url:
|
ansible.builtin.get_url:
|
||||||
url: https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/k3s-armhf
|
url: https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/k3s-armhf
|
||||||
checksum: sha256:https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/sha256sum-arm.txt
|
checksum: sha256:https://github.com/k3s-io/k3s/releases/download/{{ k3s_version }}/sha256sum-arm.txt
|
||||||
dest: /usr/local/bin/k3s
|
dest: /usr/local/bin/k3s
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: 0755
|
mode: "0755"
|
||||||
|
register: k3s_download_armhf
|
||||||
|
retries: 5
|
||||||
|
delay: 10
|
||||||
|
until: k3s_download_armhf is succeeded
|
||||||
when:
|
when:
|
||||||
- ansible_facts.architecture is search("arm")
|
- ansible_facts.architecture is search("arm")
|
||||||
- ansible_facts.userspace_bits == "32"
|
- ansible_facts.userspace_bits == "32"
|
||||||
|
|||||||
@@ -1,12 +0,0 @@
|
|||||||
---
|
|
||||||
ansible_user: root
|
|
||||||
server_init_args: >-
|
|
||||||
{% if groups['master'] | length > 1 %}
|
|
||||||
{% if ansible_hostname == hostvars[groups['master'][0]]['ansible_hostname'] %}
|
|
||||||
--cluster-init
|
|
||||||
{% else %}
|
|
||||||
--server https://{{ hostvars[groups['master'][0]].k3s_node_ip }}:6443
|
|
||||||
{% endif %}
|
|
||||||
--token {{ k3s_token }}
|
|
||||||
{% endif %}
|
|
||||||
{{ extra_server_args | default('') }}
|
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
---
|
|
||||||
# Download logs of k3s-init.service from the nodes to localhost.
|
|
||||||
# Note that log_destination must be set.
|
|
||||||
|
|
||||||
- name: Fetch k3s-init.service logs
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: journalctl --all --unit=k3s-init.service
|
|
||||||
changed_when: false
|
|
||||||
register: k3s_init_log
|
|
||||||
|
|
||||||
- name: Create {{ log_destination }}
|
|
||||||
delegate_to: localhost
|
|
||||||
run_once: true
|
|
||||||
become: false
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ log_destination }}"
|
|
||||||
state: directory
|
|
||||||
mode: "0755"
|
|
||||||
|
|
||||||
- name: Store logs to {{ log_destination }}
|
|
||||||
delegate_to: localhost
|
|
||||||
become: false
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: content.j2
|
|
||||||
dest: "{{ log_destination }}/k3s-init@{{ ansible_hostname }}.log"
|
|
||||||
mode: 0644
|
|
||||||
vars:
|
|
||||||
content: "{{ k3s_init_log.stdout }}"
|
|
||||||
@@ -1,201 +0,0 @@
|
|||||||
---
|
|
||||||
|
|
||||||
- name: Clean previous runs of k3s-init
|
|
||||||
systemd:
|
|
||||||
name: k3s-init
|
|
||||||
state: stopped
|
|
||||||
failed_when: false
|
|
||||||
|
|
||||||
- name: Clean previous runs of k3s-init
|
|
||||||
command: systemctl reset-failed k3s-init
|
|
||||||
failed_when: false
|
|
||||||
changed_when: false
|
|
||||||
args:
|
|
||||||
warn: false # The ansible systemd module does not support reset-failed
|
|
||||||
|
|
||||||
- name: Create manifests directory on first master
|
|
||||||
file:
|
|
||||||
path: /var/lib/rancher/k3s/server/manifests
|
|
||||||
state: directory
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0644
|
|
||||||
when: ansible_hostname == hostvars[groups['master'][0]]['ansible_hostname']
|
|
||||||
|
|
||||||
- name: Copy vip rbac manifest to first master
|
|
||||||
template:
|
|
||||||
src: "vip.rbac.yaml.j2"
|
|
||||||
dest: "/var/lib/rancher/k3s/server/manifests/vip-rbac.yaml"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0644
|
|
||||||
when: ansible_hostname == hostvars[groups['master'][0]]['ansible_hostname']
|
|
||||||
|
|
||||||
- name: Copy vip manifest to first master
|
|
||||||
template:
|
|
||||||
src: "vip.yaml.j2"
|
|
||||||
dest: "/var/lib/rancher/k3s/server/manifests/vip.yaml"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0644
|
|
||||||
when: ansible_hostname == hostvars[groups['master'][0]]['ansible_hostname']
|
|
||||||
|
|
||||||
# these will be copied and installed now, then tested later and apply config
|
|
||||||
- name: Copy metallb namespace to first master
|
|
||||||
template:
|
|
||||||
src: "metallb.namespace.j2"
|
|
||||||
dest: "/var/lib/rancher/k3s/server/manifests/metallb-namespace.yaml"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0644
|
|
||||||
when: ansible_hostname == hostvars[groups['master'][0]]['ansible_hostname']
|
|
||||||
|
|
||||||
- name: Copy metallb namespace to first master
|
|
||||||
template:
|
|
||||||
src: "metallb.crds.j2"
|
|
||||||
dest: "/var/lib/rancher/k3s/server/manifests/metallb-crds.yaml"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0644
|
|
||||||
when: ansible_hostname == hostvars[groups['master'][0]]['ansible_hostname']
|
|
||||||
|
|
||||||
- name: Init cluster inside the transient k3s-init service
|
|
||||||
command:
|
|
||||||
cmd: "systemd-run -p RestartSec=2 \
|
|
||||||
-p Restart=on-failure \
|
|
||||||
--unit=k3s-init \
|
|
||||||
k3s server {{ server_init_args }}"
|
|
||||||
creates: "{{ systemd_dir }}/k3s.service"
|
|
||||||
args:
|
|
||||||
warn: false # The ansible systemd module does not support transient units
|
|
||||||
|
|
||||||
- name: Verification
|
|
||||||
block:
|
|
||||||
- name: Verify that all nodes actually joined (check k3s-init.service if this fails)
|
|
||||||
command:
|
|
||||||
cmd: k3s kubectl get nodes -l "node-role.kubernetes.io/master=true" -o=jsonpath="{.items[*].metadata.name}"
|
|
||||||
register: nodes
|
|
||||||
until: nodes.rc == 0 and (nodes.stdout.split() | length) == (groups['master'] | length)
|
|
||||||
retries: "{{ retry_count | default(20) }}"
|
|
||||||
delay: 10
|
|
||||||
changed_when: false
|
|
||||||
always:
|
|
||||||
- name: Save logs of k3s-init.service
|
|
||||||
include_tasks: fetch_k3s_init_logs.yml
|
|
||||||
when: log_destination
|
|
||||||
vars:
|
|
||||||
log_destination: >-
|
|
||||||
{{ lookup('ansible.builtin.env', 'ANSIBLE_K3S_LOG_DIR', default=False) }}
|
|
||||||
- name: Kill the temporary service used for initialization
|
|
||||||
systemd:
|
|
||||||
name: k3s-init
|
|
||||||
state: stopped
|
|
||||||
failed_when: false
|
|
||||||
when: not ansible_check_mode
|
|
||||||
|
|
||||||
- name: Copy K3s service file
|
|
||||||
register: k3s_service
|
|
||||||
template:
|
|
||||||
src: "k3s.service.j2"
|
|
||||||
dest: "{{ systemd_dir }}/k3s.service"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0644
|
|
||||||
|
|
||||||
- name: Enable and check K3s service
|
|
||||||
systemd:
|
|
||||||
name: k3s
|
|
||||||
daemon_reload: yes
|
|
||||||
state: restarted
|
|
||||||
enabled: yes
|
|
||||||
|
|
||||||
- name: Wait for node-token
|
|
||||||
wait_for:
|
|
||||||
path: /var/lib/rancher/k3s/server/node-token
|
|
||||||
|
|
||||||
- name: Register node-token file access mode
|
|
||||||
stat:
|
|
||||||
path: /var/lib/rancher/k3s/server
|
|
||||||
register: p
|
|
||||||
|
|
||||||
- name: Change file access node-token
|
|
||||||
file:
|
|
||||||
path: /var/lib/rancher/k3s/server
|
|
||||||
mode: "g+rx,o+rx"
|
|
||||||
|
|
||||||
- name: Read node-token from master
|
|
||||||
slurp:
|
|
||||||
src: /var/lib/rancher/k3s/server/node-token
|
|
||||||
register: node_token
|
|
||||||
|
|
||||||
- name: Store Master node-token
|
|
||||||
set_fact:
|
|
||||||
token: "{{ node_token.content | b64decode | regex_replace('\n', '') }}"
|
|
||||||
|
|
||||||
- name: Restore node-token file access
|
|
||||||
file:
|
|
||||||
path: /var/lib/rancher/k3s/server
|
|
||||||
mode: "{{ p.stat.mode }}"
|
|
||||||
|
|
||||||
- name: Create directory .kube
|
|
||||||
file:
|
|
||||||
path: ~{{ ansible_user }}/.kube
|
|
||||||
state: directory
|
|
||||||
owner: "{{ ansible_user }}"
|
|
||||||
mode: "u=rwx,g=rx,o="
|
|
||||||
|
|
||||||
- name: Copy config file to user home directory
|
|
||||||
copy:
|
|
||||||
src: /etc/rancher/k3s/k3s.yaml
|
|
||||||
dest: ~{{ ansible_user }}/.kube/config
|
|
||||||
remote_src: yes
|
|
||||||
owner: "{{ ansible_user }}"
|
|
||||||
mode: "u=rw,g=,o="
|
|
||||||
|
|
||||||
- name: Configure kubectl cluster to {{ endpoint_url }}
|
|
||||||
command: >-
|
|
||||||
k3s kubectl config set-cluster default
|
|
||||||
--server={{ endpoint_url }}
|
|
||||||
--kubeconfig ~{{ ansible_user }}/.kube/config
|
|
||||||
changed_when: true
|
|
||||||
vars:
|
|
||||||
endpoint_url: >-
|
|
||||||
https://{{ apiserver_endpoint | ansible.utils.ipwrap }}:6443
|
|
||||||
# Deactivated linter rules:
|
|
||||||
# - jinja[invalid]: As of version 6.6.0, ansible-lint complains that the input to ipwrap
|
|
||||||
# would be undefined. This will not be the case during playbook execution.
|
|
||||||
# noqa jinja[invalid]
|
|
||||||
|
|
||||||
- name: Create kubectl symlink
|
|
||||||
file:
|
|
||||||
src: /usr/local/bin/k3s
|
|
||||||
dest: /usr/local/bin/kubectl
|
|
||||||
state: link
|
|
||||||
|
|
||||||
- name: Create crictl symlink
|
|
||||||
file:
|
|
||||||
src: /usr/local/bin/k3s
|
|
||||||
dest: /usr/local/bin/crictl
|
|
||||||
state: link
|
|
||||||
|
|
||||||
- name: Get contents of manifests folder
|
|
||||||
find:
|
|
||||||
paths: /var/lib/rancher/k3s/server/manifests
|
|
||||||
file_type: file
|
|
||||||
register: k3s_server_manifests
|
|
||||||
|
|
||||||
- name: Get sub dirs of manifests folder
|
|
||||||
find:
|
|
||||||
paths: /var/lib/rancher/k3s/server/manifests
|
|
||||||
file_type: directory
|
|
||||||
register: k3s_server_manifests_directories
|
|
||||||
|
|
||||||
- name: Remove manifests and folders that are only needed for bootstrapping cluster so k3s doesn't auto apply on start
|
|
||||||
file:
|
|
||||||
path: "{{ item.path }}"
|
|
||||||
state: absent
|
|
||||||
with_items:
|
|
||||||
- "{{ k3s_server_manifests.files }}"
|
|
||||||
- "{{ k3s_server_manifests_directories.files }}"
|
|
||||||
loop_control:
|
|
||||||
label: "{{ item.path }}"
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,6 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: metallb-system
|
|
||||||
labels:
|
|
||||||
app: metallb
|
|
||||||
@@ -1,32 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: kube-vip
|
|
||||||
namespace: kube-system
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
rbac.authorization.kubernetes.io/autoupdate: "true"
|
|
||||||
name: system:kube-vip-role
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["services", "services/status", "nodes", "endpoints"]
|
|
||||||
verbs: ["list","get","watch", "update"]
|
|
||||||
- apiGroups: ["coordination.k8s.io"]
|
|
||||||
resources: ["leases"]
|
|
||||||
verbs: ["list", "get", "watch", "update", "create"]
|
|
||||||
---
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
metadata:
|
|
||||||
name: system:kube-vip-binding
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: system:kube-vip-role
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: kube-vip
|
|
||||||
namespace: kube-system
|
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
---
|
||||||
|
# Name of the master group
|
||||||
|
group_name_master: master
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
---
|
|
||||||
|
|
||||||
- name: Copy K3s service file
|
|
||||||
template:
|
|
||||||
src: "k3s.service.j2"
|
|
||||||
dest: "{{ systemd_dir }}/k3s-node.service"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0755
|
|
||||||
|
|
||||||
- name: Enable and check K3s service
|
|
||||||
systemd:
|
|
||||||
name: k3s-node
|
|
||||||
daemon_reload: yes
|
|
||||||
state: restarted
|
|
||||||
enabled: yes
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
# Timeout to wait for MetalLB services to come up
|
|
||||||
metal_lb_available_timeout: 120s
|
|
||||||
@@ -1,94 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Create manifests directory for temp configuration
|
|
||||||
file:
|
|
||||||
path: /tmp/k3s
|
|
||||||
state: directory
|
|
||||||
owner: "{{ ansible_user }}"
|
|
||||||
mode: 0755
|
|
||||||
with_items: "{{ groups['master'] }}"
|
|
||||||
run_once: true
|
|
||||||
|
|
||||||
- name: Copy metallb CRs manifest to first master
|
|
||||||
template:
|
|
||||||
src: "metallb.crs.j2"
|
|
||||||
dest: "/tmp/k3s/metallb-crs.yaml"
|
|
||||||
owner: "{{ ansible_user }}"
|
|
||||||
mode: 0755
|
|
||||||
with_items: "{{ groups['master'] }}"
|
|
||||||
run_once: true
|
|
||||||
|
|
||||||
- name: Test metallb-system namespace
|
|
||||||
command: >-
|
|
||||||
k3s kubectl -n metallb-system
|
|
||||||
changed_when: false
|
|
||||||
with_items: "{{ groups['master'] }}"
|
|
||||||
run_once: true
|
|
||||||
|
|
||||||
- name: Wait for MetalLB resources
|
|
||||||
command: >-
|
|
||||||
k3s kubectl wait {{ item.resource }}
|
|
||||||
--namespace='metallb-system'
|
|
||||||
{% if item.name | default(False) -%}{{ item.name }}{%- endif %}
|
|
||||||
{% if item.selector | default(False) -%}--selector='{{ item.selector }}'{%- endif %}
|
|
||||||
{% if item.condition | default(False) -%}{{ item.condition }}{%- endif %}
|
|
||||||
--timeout='{{ metal_lb_available_timeout }}'
|
|
||||||
changed_when: false
|
|
||||||
run_once: true
|
|
||||||
with_items:
|
|
||||||
- description: controller
|
|
||||||
resource: deployment
|
|
||||||
name: controller
|
|
||||||
condition: --for condition=Available=True
|
|
||||||
- description: webhook service
|
|
||||||
resource: pod
|
|
||||||
selector: component=controller
|
|
||||||
condition: --for=jsonpath='{.status.phase}'=Running
|
|
||||||
- description: pods in replica sets
|
|
||||||
resource: pod
|
|
||||||
selector: component=controller,app=metallb
|
|
||||||
condition: --for condition=Ready
|
|
||||||
- description: ready replicas of controller
|
|
||||||
resource: replicaset
|
|
||||||
selector: component=controller,app=metallb
|
|
||||||
condition: --for=jsonpath='{.status.readyReplicas}'=1
|
|
||||||
- description: fully labeled replicas of controller
|
|
||||||
resource: replicaset
|
|
||||||
selector: component=controller,app=metallb
|
|
||||||
condition: --for=jsonpath='{.status.fullyLabeledReplicas}'=1
|
|
||||||
- description: available replicas of controller
|
|
||||||
resource: replicaset
|
|
||||||
selector: component=controller,app=metallb
|
|
||||||
condition: --for=jsonpath='{.status.availableReplicas}'=1
|
|
||||||
loop_control:
|
|
||||||
label: "{{ item.description }}"
|
|
||||||
|
|
||||||
- name: Test metallb-system webhook-service endpoint
|
|
||||||
command: >-
|
|
||||||
k3s kubectl -n metallb-system get endpoints webhook-service
|
|
||||||
changed_when: false
|
|
||||||
with_items: "{{ groups['master'] }}"
|
|
||||||
run_once: true
|
|
||||||
|
|
||||||
- name: Apply metallb CRs
|
|
||||||
command: >-
|
|
||||||
k3s kubectl apply -f /tmp/k3s/metallb-crs.yaml
|
|
||||||
--timeout='{{ metal_lb_available_timeout }}'
|
|
||||||
register: this
|
|
||||||
changed_when: false
|
|
||||||
run_once: true
|
|
||||||
until: this.rc == 0
|
|
||||||
retries: 5
|
|
||||||
|
|
||||||
- name: Test metallb-system resources
|
|
||||||
command: >-
|
|
||||||
k3s kubectl -n metallb-system get {{ item }}
|
|
||||||
changed_when: false
|
|
||||||
run_once: true
|
|
||||||
with_items:
|
|
||||||
- IPAddressPool
|
|
||||||
- L2Advertisement
|
|
||||||
|
|
||||||
- name: Remove tmp directory used for manifests
|
|
||||||
file:
|
|
||||||
path: /tmp/k3s
|
|
||||||
state: absent
|
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
extra_agent_args: ""
|
||||||
|
group_name_master: master
|
||||||
|
systemd_dir: /etc/systemd/system
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
---
|
||||||
|
argument_specs:
|
||||||
|
main:
|
||||||
|
short_description: Setup k3s agents
|
||||||
|
options:
|
||||||
|
apiserver_endpoint:
|
||||||
|
description: Virtual ip-address configured on each master
|
||||||
|
required: true
|
||||||
|
|
||||||
|
extra_agent_args:
|
||||||
|
description: Extra arguments for agents nodes
|
||||||
|
|
||||||
|
group_name_master:
|
||||||
|
description: Name of the master group
|
||||||
|
default: master
|
||||||
|
|
||||||
|
k3s_token:
|
||||||
|
description: Token used to communicate between masters
|
||||||
|
|
||||||
|
proxy_env:
|
||||||
|
type: dict
|
||||||
|
description:
|
||||||
|
- Internet proxy configurations.
|
||||||
|
- See https://docs.k3s.io/advanced#configuring-an-http-proxy for details
|
||||||
|
default: ~
|
||||||
|
options:
|
||||||
|
HTTP_PROXY:
|
||||||
|
description: HTTP internet proxy
|
||||||
|
required: true
|
||||||
|
HTTPS_PROXY:
|
||||||
|
description: HTTPS internet proxy
|
||||||
|
required: true
|
||||||
|
NO_PROXY:
|
||||||
|
description: Addresses that will not use the proxies
|
||||||
|
required: true
|
||||||
|
|
||||||
|
systemd_dir:
|
||||||
|
description: Path to systemd services
|
||||||
|
default: /etc/systemd/system
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
- name: Create k3s-node.service.d directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ systemd_dir }}/k3s-node.service.d"
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0755"
|
||||||
|
when: proxy_env is defined
|
||||||
|
|
||||||
|
- name: Copy K3s http_proxy conf file
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: http_proxy.conf.j2
|
||||||
|
dest: "{{ systemd_dir }}/k3s-node.service.d/http_proxy.conf"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0755"
|
||||||
|
when: proxy_env is defined
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
---
|
||||||
|
- name: Check for PXE-booted system
|
||||||
|
block:
|
||||||
|
- name: Check if system is PXE-booted
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: cat /proc/cmdline
|
||||||
|
register: boot_cmdline
|
||||||
|
changed_when: false
|
||||||
|
check_mode: false
|
||||||
|
|
||||||
|
- name: Set fact for PXE-booted system
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
is_pxe_booted: "{{ 'root=/dev/nfs' in boot_cmdline.stdout }}"
|
||||||
|
when: boot_cmdline.stdout is defined
|
||||||
|
|
||||||
|
- name: Include http_proxy configuration tasks
|
||||||
|
ansible.builtin.include_tasks: http_proxy.yml
|
||||||
|
|
||||||
|
- name: Deploy K3s http_proxy conf
|
||||||
|
ansible.builtin.include_tasks: http_proxy.yml
|
||||||
|
when: proxy_env is defined
|
||||||
|
|
||||||
|
- name: Configure the k3s service
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: k3s.service.j2
|
||||||
|
dest: "{{ systemd_dir }}/k3s-node.service"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0755"
|
||||||
|
|
||||||
|
- name: Manage k3s service
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: k3s-node
|
||||||
|
daemon_reload: true
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
[Service]
|
||||||
|
Environment=HTTP_PROXY={{ proxy_env.HTTP_PROXY }}
|
||||||
|
Environment=HTTPS_PROXY={{ proxy_env.HTTPS_PROXY }}
|
||||||
|
Environment=NO_PROXY={{ proxy_env.NO_PROXY }}
|
||||||
@@ -7,11 +7,14 @@ After=network-online.target
|
|||||||
Type=notify
|
Type=notify
|
||||||
ExecStartPre=-/sbin/modprobe br_netfilter
|
ExecStartPre=-/sbin/modprobe br_netfilter
|
||||||
ExecStartPre=-/sbin/modprobe overlay
|
ExecStartPre=-/sbin/modprobe overlay
|
||||||
ExecStart=/usr/local/bin/k3s agent --server https://{{ apiserver_endpoint | ansible.utils.ipwrap }}:6443 --token {{ hostvars[groups['master'][0]]['token'] | default(k3s_token) }} {{ extra_agent_args | default("") }}
|
# Conditional snapshotter based on PXE boot status
|
||||||
|
ExecStart=/usr/local/bin/k3s agent \
|
||||||
|
--server https://{{ apiserver_endpoint | ansible.utils.ipwrap }}:6443 \
|
||||||
|
{% if is_pxe_booted | default(false) %}--snapshotter native \
|
||||||
|
{% endif %}--token {{ hostvars[groups[group_name_master | default('master')][0]]['token'] | default(k3s_token) }} \
|
||||||
|
{{ extra_agent_args }}
|
||||||
KillMode=process
|
KillMode=process
|
||||||
Delegate=yes
|
Delegate=yes
|
||||||
# Having non-zero Limit*s causes performance problems due to accounting overhead
|
|
||||||
# in the kernel. We recommend using cgroups to do container-local accounting.
|
|
||||||
LimitNOFILE=1048576
|
LimitNOFILE=1048576
|
||||||
LimitNPROC=infinity
|
LimitNPROC=infinity
|
||||||
LimitCORE=infinity
|
LimitCORE=infinity
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
---
|
||||||
|
argument_specs:
|
||||||
|
main:
|
||||||
|
short_description: Configure the use of a custom container registry
|
||||||
|
options:
|
||||||
|
custom_registries_yaml:
|
||||||
|
description:
|
||||||
|
- YAML block defining custom registries.
|
||||||
|
- >
|
||||||
|
The following is an example that pulls all images used in
|
||||||
|
this playbook through your private registries.
|
||||||
|
- >
|
||||||
|
It also allows you to pull your own images from your private
|
||||||
|
registry, without having to use imagePullSecrets in your
|
||||||
|
deployments.
|
||||||
|
- >
|
||||||
|
If all you need is your own images and you don't care about
|
||||||
|
caching the docker/quay/ghcr.io images, you can just remove
|
||||||
|
those from the mirrors: section.
|
||||||
|
required: true
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
- name: Create directory /etc/rancher/k3s
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /etc/{{ item }}
|
||||||
|
state: directory
|
||||||
|
mode: "0755"
|
||||||
|
loop:
|
||||||
|
- rancher
|
||||||
|
- rancher/k3s
|
||||||
|
|
||||||
|
- name: Insert registries into /etc/rancher/k3s/registries.yaml
|
||||||
|
ansible.builtin.blockinfile:
|
||||||
|
path: /etc/rancher/k3s/registries.yaml
|
||||||
|
block: "{{ custom_registries_yaml }}"
|
||||||
|
mode: "0600"
|
||||||
|
create: true
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
---
|
||||||
|
extra_server_args: ""
|
||||||
|
|
||||||
|
k3s_kubectl_binary: k3s kubectl
|
||||||
|
|
||||||
|
group_name_master: master
|
||||||
|
|
||||||
|
kube_vip_arp: true
|
||||||
|
kube_vip_iface:
|
||||||
|
kube_vip_cloud_provider_tag_version: v0.0.12
|
||||||
|
kube_vip_tag_version: v1.2.2
|
||||||
|
|
||||||
|
kube_vip_bgp: false
|
||||||
|
kube_vip_bgp_routerid: 127.0.0.1
|
||||||
|
kube_vip_bgp_as: "64513"
|
||||||
|
kube_vip_bgp_peeraddress: 192.168.30.1
|
||||||
|
kube_vip_bgp_peeras: "64512"
|
||||||
|
|
||||||
|
kube_vip_bgp_peers: []
|
||||||
|
kube_vip_bgp_peers_groups: ['k3s_master']
|
||||||
|
|
||||||
|
metal_lb_controller_tag_version: v0.16.0
|
||||||
|
metal_lb_speaker_tag_version: v0.16.0
|
||||||
|
metal_lb_type: native
|
||||||
|
|
||||||
|
retry_count: 20
|
||||||
|
|
||||||
|
# yamllint disable rule:line-length
|
||||||
|
server_init_args: >-
|
||||||
|
{% if groups[group_name_master | default('master')] | length > 1 %}
|
||||||
|
{% if ansible_hostname == hostvars[groups[group_name_master | default('master')][0]]['ansible_hostname'] %}
|
||||||
|
--cluster-init
|
||||||
|
{% else %}
|
||||||
|
--server https://{{ hostvars[groups[group_name_master | default('master')][0]].k3s_node_ip | split(",") | first | ansible.utils.ipwrap }}:6443
|
||||||
|
{% endif %}
|
||||||
|
--token {{ k3s_token }}
|
||||||
|
{% endif %}
|
||||||
|
{{ extra_server_args }}
|
||||||
|
|
||||||
|
systemd_dir: /etc/systemd/system
|
||||||
@@ -0,0 +1,135 @@
|
|||||||
|
---
|
||||||
|
argument_specs:
|
||||||
|
main:
|
||||||
|
short_description: Setup k3s servers
|
||||||
|
options:
|
||||||
|
apiserver_endpoint:
|
||||||
|
description: Virtual ip-address configured on each master
|
||||||
|
required: true
|
||||||
|
|
||||||
|
cilium_bgp:
|
||||||
|
description:
|
||||||
|
- Enable cilium BGP control plane for LB services and pod cidrs.
|
||||||
|
- Disables the use of MetalLB.
|
||||||
|
type: bool
|
||||||
|
default: ~
|
||||||
|
|
||||||
|
cilium_iface:
|
||||||
|
description: The network interface used for when Cilium is enabled
|
||||||
|
default: ~
|
||||||
|
|
||||||
|
extra_server_args:
|
||||||
|
description: Extra arguments for server nodes
|
||||||
|
default: ""
|
||||||
|
|
||||||
|
group_name_master:
|
||||||
|
description: Name of the master group
|
||||||
|
default: master
|
||||||
|
|
||||||
|
k3s_create_kubectl_symlink:
|
||||||
|
description: Create the kubectl -> k3s symlink
|
||||||
|
default: false
|
||||||
|
type: bool
|
||||||
|
|
||||||
|
k3s_create_crictl_symlink:
|
||||||
|
description: Create the crictl -> k3s symlink
|
||||||
|
default: false
|
||||||
|
type: bool
|
||||||
|
|
||||||
|
kube_vip_arp:
|
||||||
|
description: Enables kube-vip ARP broadcasts
|
||||||
|
default: true
|
||||||
|
type: bool
|
||||||
|
|
||||||
|
kube_vip_bgp:
|
||||||
|
description: Enables kube-vip BGP peering
|
||||||
|
default: false
|
||||||
|
type: bool
|
||||||
|
|
||||||
|
kube_vip_bgp_routerid:
|
||||||
|
description: Defines the router ID for the kube-vip BGP server
|
||||||
|
default: "127.0.0.1"
|
||||||
|
|
||||||
|
kube_vip_bgp_as:
|
||||||
|
description: Defines the AS for the kube-vip BGP server
|
||||||
|
default: "64513"
|
||||||
|
|
||||||
|
kube_vip_bgp_peeraddress:
|
||||||
|
description: Defines the address for the kube-vip BGP peer
|
||||||
|
default: "192.168.30.1"
|
||||||
|
|
||||||
|
kube_vip_bgp_peeras:
|
||||||
|
description: Defines the AS for the kube-vip BGP peer
|
||||||
|
default: "64512"
|
||||||
|
|
||||||
|
kube_vip_bgp_peers:
|
||||||
|
description: List of BGP peer ASN & address pairs
|
||||||
|
default: []
|
||||||
|
|
||||||
|
kube_vip_bgp_peers_groups:
|
||||||
|
description: Inventory group in which to search for additional kube_vip_bgp_peers parameters to merge.
|
||||||
|
default: ['k3s_master']
|
||||||
|
|
||||||
|
kube_vip_iface:
|
||||||
|
description:
|
||||||
|
- Explicitly define an interface that ALL control nodes
|
||||||
|
- should use to propagate the VIP, define it here.
|
||||||
|
- Otherwise, kube-vip will determine the right interface
|
||||||
|
- automatically at runtime.
|
||||||
|
default: ~
|
||||||
|
|
||||||
|
kube_vip_tag_version:
|
||||||
|
description: Image tag for kube-vip
|
||||||
|
default: v1.2.2
|
||||||
|
|
||||||
|
kube_vip_cloud_provider_tag_version:
|
||||||
|
description: Tag for kube-vip-cloud-provider manifest when enabled
|
||||||
|
default: v0.0.12
|
||||||
|
|
||||||
|
kube_vip_lb_ip_range:
|
||||||
|
description: IP range for kube-vip load balancer
|
||||||
|
default: ~
|
||||||
|
|
||||||
|
metal_lb_controller_tag_version:
|
||||||
|
description: Image tag for MetalLB
|
||||||
|
default: v0.16.0
|
||||||
|
|
||||||
|
metal_lb_speaker_tag_version:
|
||||||
|
description: Image tag for MetalLB
|
||||||
|
default: v0.16.0
|
||||||
|
|
||||||
|
metal_lb_type:
|
||||||
|
choices:
|
||||||
|
- frr
|
||||||
|
- native
|
||||||
|
default: native
|
||||||
|
description: Use FRR mode or native. Valid values are `frr` and `native`
|
||||||
|
|
||||||
|
proxy_env:
|
||||||
|
type: dict
|
||||||
|
description:
|
||||||
|
- Internet proxy configurations.
|
||||||
|
- See https://docs.k3s.io/advanced#configuring-an-http-proxy for details
|
||||||
|
default: ~
|
||||||
|
options:
|
||||||
|
HTTP_PROXY:
|
||||||
|
description: HTTP internet proxy
|
||||||
|
required: true
|
||||||
|
HTTPS_PROXY:
|
||||||
|
description: HTTPS internet proxy
|
||||||
|
required: true
|
||||||
|
NO_PROXY:
|
||||||
|
description: Addresses that will not use the proxies
|
||||||
|
required: true
|
||||||
|
|
||||||
|
retry_count:
|
||||||
|
description: Amount of retries when verifying that nodes joined
|
||||||
|
type: int
|
||||||
|
default: 20
|
||||||
|
|
||||||
|
server_init_args:
|
||||||
|
description: Arguments for server nodes
|
||||||
|
|
||||||
|
systemd_dir:
|
||||||
|
description: Path to systemd services
|
||||||
|
default: /etc/systemd/system
|
||||||
@@ -0,0 +1,180 @@
|
|||||||
|
---
|
||||||
|
# Download logs of k3s-init.service from the nodes to localhost.
|
||||||
|
# Note that log_destination must be set.
|
||||||
|
|
||||||
|
- name: Fetch k3s-init.service logs
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: >-
|
||||||
|
timeout --signal=TERM --kill-after=5s 30s journalctl --no-pager
|
||||||
|
--unit=k3s-init.service --since=-30min --lines=5000
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_init_log
|
||||||
|
|
||||||
|
- name: Fetch k3s-init.service status
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: >-
|
||||||
|
timeout --signal=TERM --kill-after=5s 15s systemctl status
|
||||||
|
k3s-init.service --no-pager --full
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_init_status
|
||||||
|
|
||||||
|
- name: Fetch IP address state
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: ip -br address
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_ip_address_state
|
||||||
|
|
||||||
|
- name: Fetch IP link state
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: ip -br link
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_ip_link_state
|
||||||
|
|
||||||
|
- name: Fetch IP route state
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: ip route show
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_ip_route_state
|
||||||
|
|
||||||
|
- name: Fetch IP neighbor state
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: ip neigh show
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_ip_neighbor_state
|
||||||
|
|
||||||
|
- name: Fetch IP rule state
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: ip rule show
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_ip_rule_state
|
||||||
|
|
||||||
|
- name: Fetch listening TCP sockets
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: ss -ltn
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_tcp_listener_state
|
||||||
|
|
||||||
|
- name: Fetch guest firewall service state
|
||||||
|
ansible.builtin.service_facts:
|
||||||
|
no_log: true
|
||||||
|
register: k3s_service_facts
|
||||||
|
|
||||||
|
- name: Fetch input firewall rules
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: iptables -S INPUT
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_input_firewall_rules
|
||||||
|
|
||||||
|
- name: Ping the primary Kubernetes API address from {{ ansible_hostname }}
|
||||||
|
ansible.builtin.command:
|
||||||
|
argv:
|
||||||
|
- ping
|
||||||
|
- -c
|
||||||
|
- "1"
|
||||||
|
- -W
|
||||||
|
- "1"
|
||||||
|
- "{{ hostvars[groups[group_name_master | default('master')][0]].k3s_node_ip | split(',') | first }}"
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_primary_api_ping
|
||||||
|
|
||||||
|
- name: Probe primary Kubernetes API from {{ ansible_hostname }}
|
||||||
|
ansible.builtin.wait_for:
|
||||||
|
host: "{{ hostvars[groups[group_name_master | default('master')][0]].k3s_node_ip | split(',') | first }}"
|
||||||
|
port: 6443
|
||||||
|
connect_timeout: 1
|
||||||
|
timeout: 2
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
no_log: true
|
||||||
|
register: k3s_primary_api_probe
|
||||||
|
|
||||||
|
- name: Create {{ log_destination }}
|
||||||
|
delegate_to: localhost
|
||||||
|
run_once: true
|
||||||
|
become: false
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ log_destination }}"
|
||||||
|
state: directory
|
||||||
|
mode: "0755"
|
||||||
|
|
||||||
|
- name: Store logs to {{ log_destination }}
|
||||||
|
delegate_to: localhost
|
||||||
|
become: false
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: content.j2
|
||||||
|
dest: "{{ log_destination }}/k3s-init@{{ ansible_hostname }}.log"
|
||||||
|
mode: "0644"
|
||||||
|
vars:
|
||||||
|
content: |
|
||||||
|
=== k3s-init.service status ===
|
||||||
|
{{ k3s_init_status.stdout | regex_replace('--token(?:=| +)[^ ]+', '--token ***') }}
|
||||||
|
|
||||||
|
=== k3s-init.service journal ===
|
||||||
|
{{ k3s_init_log.stdout | regex_replace('--token(?:=| +)[^ ]+', '--token ***') }}
|
||||||
|
|
||||||
|
- name: Store network diagnostics to {{ log_destination }}
|
||||||
|
delegate_to: localhost
|
||||||
|
become: false
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: content.j2
|
||||||
|
dest: "{{ log_destination }}/network@{{ ansible_hostname }}.log"
|
||||||
|
mode: "0644"
|
||||||
|
vars:
|
||||||
|
content: |
|
||||||
|
=== ip -br address ===
|
||||||
|
{{ k3s_ip_address_state.stdout }}
|
||||||
|
|
||||||
|
=== ip -br link ===
|
||||||
|
{{ k3s_ip_link_state.stdout }}
|
||||||
|
|
||||||
|
=== ip route show ===
|
||||||
|
{{ k3s_ip_route_state.stdout }}
|
||||||
|
|
||||||
|
=== ip neigh show ===
|
||||||
|
{{ k3s_ip_neighbor_state.stdout }}
|
||||||
|
|
||||||
|
=== ip rule show ===
|
||||||
|
{{ k3s_ip_rule_state.stdout }}
|
||||||
|
|
||||||
|
=== ss -ltn ===
|
||||||
|
{{ k3s_tcp_listener_state.stdout }}
|
||||||
|
|
||||||
|
=== guest firewall services ===
|
||||||
|
firewalld={{ k3s_service_facts.ansible_facts.services.get('firewalld.service', {}).get('state', 'not-found') }}
|
||||||
|
nftables={{ k3s_service_facts.ansible_facts.services.get('nftables.service', {}).get('state', 'not-found') }}
|
||||||
|
ufw={{ k3s_service_facts.ansible_facts.services.get('ufw.service', {}).get('state', 'not-found') }}
|
||||||
|
|
||||||
|
=== iptables -S INPUT ===
|
||||||
|
rc={{ k3s_input_firewall_rules.rc }}
|
||||||
|
{{ k3s_input_firewall_rules.stdout }}
|
||||||
|
{{ k3s_input_firewall_rules.stderr }}
|
||||||
|
|
||||||
|
=== primary API ping ===
|
||||||
|
rc={{ k3s_primary_api_ping.rc }}
|
||||||
|
{{ k3s_primary_api_ping.stdout }}
|
||||||
|
{{ k3s_primary_api_ping.stderr }}
|
||||||
|
|
||||||
|
=== primary API probe ===
|
||||||
|
failed={{ k3s_primary_api_probe.failed | default(false) }}
|
||||||
|
elapsed={{ k3s_primary_api_probe.elapsed | default('unknown') }}
|
||||||
|
msg={{ k3s_primary_api_probe.msg | default('connected') }}
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
- name: Create k3s.service.d directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ systemd_dir }}/k3s.service.d"
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0755"
|
||||||
|
|
||||||
|
- name: Copy K3s http_proxy conf file
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: http_proxy.conf.j2
|
||||||
|
dest: "{{ systemd_dir }}/k3s.service.d/http_proxy.conf"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0755"
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
---
|
||||||
|
- name: Verify primary Kubernetes API reachability from {{ joining_master }}
|
||||||
|
ansible.builtin.wait_for:
|
||||||
|
host: >-
|
||||||
|
{{ hostvars[groups[group_name_master | default('master')][0]].k3s_node_ip
|
||||||
|
| split(',') | first }}
|
||||||
|
port: 6443
|
||||||
|
connect_timeout: 2
|
||||||
|
timeout: 30
|
||||||
|
delegate_to: "{{ joining_master }}"
|
||||||
|
|
||||||
|
- name: Join transient k3s-init service for {{ joining_master }}
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: >-
|
||||||
|
systemd-run -p RestartSec=2 -p Restart=on-failure
|
||||||
|
-p Delegate=yes -p TasksMax=infinity -p KillMode=process
|
||||||
|
-p LimitNOFILE=1048576 -p LimitNPROC=infinity -p LimitCORE=infinity
|
||||||
|
--unit=k3s-init
|
||||||
|
k3s server {{ hostvars[joining_master].k3s_server_init_args }}
|
||||||
|
creates: "{{ systemd_dir }}/k3s-init.service"
|
||||||
|
delegate_to: "{{ joining_master }}"
|
||||||
|
no_log: true
|
||||||
|
|
||||||
|
- name: Wait for primary registration of {{ joining_master }}
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: >-
|
||||||
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} get node
|
||||||
|
{{ hostvars[joining_master].ansible_hostname }}
|
||||||
|
delegate_to: "{{ groups[group_name_master | default('master')][0] }}"
|
||||||
|
register: joined_master
|
||||||
|
until: joined_master.rc == 0
|
||||||
|
retries: "{{ retry_count | default(20) }}"
|
||||||
|
delay: 2
|
||||||
|
changed_when: false
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user