mirror of
https://github.com/techno-tim/k3s-ansible.git
synced 2026-08-09 07:23:19 +02:00
249238c7a4
- Correct the Deploy metallb manifest/pool when condition so MetalLB is installed whenever kube-vip does not own the VIP range and Cilium BGP is disabled - The previous guard (cilium_bgp is not defined or cilium_iface is not defined) skipped MetalLB whenever cilium_iface was set, breaking the cilium + MetalLB scenario - Use cilium_bgp | default(false) | bool to stay safe when Cilium vars are not in scope (#644) while still deploying MetalLB for non-BGP Cilium - Retry the converge-side MetalLB resource wait so a transient kube API ServiceUnavailable does not abort the converge play - Add a regression test that evaluates both when conditions across flannel, calico, non-BGP cilium, BGP cilium, and kube-vip scenarios ci: skip CI for Dependabot pull requests - Add an actor guard to the CI workflow jobs so automatic Dependabot PRs do not consume the shared self-hosted runner - Dependabot CI runs need maintainer approval instead of auto-running
25 lines
863 B
YAML
25 lines
863 B
YAML
---
|
|
- name: Deploy calico
|
|
ansible.builtin.include_tasks: calico.yml
|
|
tags: calico
|
|
when: calico_iface is defined and cilium_iface is not defined
|
|
|
|
- name: Deploy cilium
|
|
ansible.builtin.include_tasks: cilium.yml
|
|
tags: cilium
|
|
when: cilium_iface is defined
|
|
|
|
- name: Deploy metallb pool
|
|
ansible.builtin.include_tasks: metallb.yml
|
|
tags: metallb
|
|
# Deploy MetalLB unless kube-vip owns the load balancer IP range, or Cilium
|
|
# BGP is enabled (Cilium then provides its own load balancing). The cilium_bgp
|
|
# default keeps this safe when Cilium variables are not in scope at all (#644)
|
|
# while still deploying MetalLB when a non-BGP Cilium CNI is in use.
|
|
when: kube_vip_lb_ip_range is not defined and not (cilium_bgp | default(false) | bool)
|
|
|
|
- name: Remove tmp directory used for manifests
|
|
ansible.builtin.file:
|
|
path: /tmp/k3s
|
|
state: absent
|