mirror of
https://github.com/techno-tim/k3s-ansible.git
synced 2026-08-09 07:23:19 +02:00
c82f2e0415
* chore(deps): apply dependency updates in one combined change - Bump ansible-core to 2.19.11 and jmespath to 1.1.0 in requirements.in - Regenerate the Python 3.11 pip-compile lock in requirements.txt - Bump molecule-plugins to 23.6.0 while keeping molecule on the stable 6.x series (avoids the molecule-plugins 26 major jump that broke vagrant module resolution in CI) - Bump ruamel-yaml-clib to 0.2.15 - Bump the zgosalvez/github-actions-ensure-sha-pinned-actions action to 5.0.6 (SHA-pinned) in lint.yml * fix(server): make log_destination conditional boolean for ansible-core 2.19 - The always block's 'Save logs of k3s-init.service' task used when: log_destination where log_destination is a path string derived from an env var - ansible-core 2.19 rejects string-derived conditionals; evaluate the path as a real boolean (non-empty) check so the conditional is a true boolean - Required to keep the k3s_server role working with ansible-core 2.19.11 (the dependency bump in this change) * fix(verify): coerce regex_search assertions to bool for ansible-core 2.19 - ansible-core 2.19 requires assert conditionals to be boolean; regex_search returns a string, which is now rejected - Wrap all regex_search results used in assert.that with | bool so the calico, cilium, metallb, and kube-vip image-tag checks produce boolean results * fix(verify): use boolean is regex_search test instead of | bool - | bool on a regex_search result coerces a tag string like v0.16.0 to False in ansible-core 2.19, failing the image-tag assertions - Use the is regex_search test which returns a real boolean without string coercion for the calico, cilium, metallb, and kube-vip image assertions * fix(verify): use is not none for regex_search assertions - ansible-core 2.19 has no "is regex_search" test and rejects bool string coercion, so use the regex_search filter with an "is not none" comparison, which yields a real boolean for the image-tag assertions - Applies to calico, cilium, metallb, and kube-vip image checks * fix(metallb): retry transient apiserver resets in config tests - The Layer 2 and BGP final configuration checks ran a kubectl get per resource with no retry, so a transient connection refused from the kube API could abort converge - Mirror the download_retries/download_delay retry pattern used by the 'Wait for MetalLB resources' task so these checks survive api server resets on slow runners
143 lines
5.2 KiB
YAML
143 lines
5.2 KiB
YAML
---
|
|
- name: Create manifests directory for temp configuration
|
|
ansible.builtin.file:
|
|
path: /tmp/k3s
|
|
state: directory
|
|
owner: "{{ ansible_user_id }}"
|
|
mode: "0755"
|
|
with_items: "{{ groups[group_name_master | default('master')] }}"
|
|
run_once: true
|
|
|
|
- name: Delete outdated metallb replicas
|
|
ansible.builtin.shell: |-
|
|
set -o pipefail
|
|
|
|
REPLICAS=$({{ k3s_kubectl_binary | default('k3s kubectl') }} --namespace='metallb-system' get replicasets \
|
|
-l 'component=controller,app=metallb' \
|
|
-o jsonpath='{.items[0].spec.template.spec.containers[0].image}, {.items[0].metadata.name}' 2>/dev/null || true)
|
|
REPLICAS_SETS=$(echo ${REPLICAS} | grep -v '{{ metal_lb_controller_tag_version }}' | sed -e "s/^.*\s//g")
|
|
if [ -n "${REPLICAS_SETS}" ] ; then
|
|
for REPLICAS in "${REPLICAS_SETS}"
|
|
do
|
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} --namespace='metallb-system' \
|
|
delete rs "${REPLICAS}"
|
|
done
|
|
fi
|
|
args:
|
|
executable: /bin/bash
|
|
changed_when: false
|
|
run_once: true
|
|
with_items: "{{ groups[group_name_master | default('master')] }}"
|
|
|
|
- name: Copy metallb CRs manifest to first master
|
|
ansible.builtin.template:
|
|
src: metallb.crs.j2
|
|
dest: /tmp/k3s/metallb-crs.yaml
|
|
owner: "{{ ansible_user_id }}"
|
|
mode: "0755"
|
|
with_items: "{{ groups[group_name_master | default('master')] }}"
|
|
run_once: true
|
|
|
|
- name: Test metallb-system namespace
|
|
ansible.builtin.command: >-
|
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} -n metallb-system
|
|
changed_when: false
|
|
with_items: "{{ groups[group_name_master | default('master')] }}"
|
|
run_once: true
|
|
|
|
- name: Wait for MetalLB resources
|
|
ansible.builtin.command: >-
|
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} wait {{ item.resource }}
|
|
--namespace='metallb-system'
|
|
{% if item.name | default(False) -%}{{ item.name }}{%- endif %}
|
|
{% if item.selector | default(False) -%}--selector='{{ item.selector }}'{%- endif %}
|
|
{% if item.condition | default(False) -%}{{ item.condition }}{%- endif %}
|
|
--timeout='{{ metal_lb_available_timeout }}'
|
|
changed_when: false
|
|
# The kube API can briefly return ServiceUnavailable while MetalLB converges,
|
|
# which would otherwise abort the whole converge play on a transient error.
|
|
register: metallb_wait_result
|
|
until: metallb_wait_result.rc == 0
|
|
retries: "{{ download_retries }}"
|
|
delay: "{{ download_delay }}"
|
|
run_once: true
|
|
with_items:
|
|
- description: controller
|
|
resource: deployment
|
|
name: controller
|
|
condition: --for condition=Available=True
|
|
- description: webhook service
|
|
resource: pod
|
|
selector: component=controller
|
|
condition: --for=jsonpath='{.status.phase}'=Running
|
|
- description: pods in replica sets
|
|
resource: pod
|
|
selector: component=controller,app=metallb
|
|
condition: --for condition=Ready
|
|
- description: ready replicas of controller
|
|
resource: replicaset
|
|
selector: component=controller,app=metallb
|
|
condition: --for=jsonpath='{.status.readyReplicas}'=1
|
|
- description: fully labeled replicas of controller
|
|
resource: replicaset
|
|
selector: component=controller,app=metallb
|
|
condition: --for=jsonpath='{.status.fullyLabeledReplicas}'=1
|
|
- description: available replicas of controller
|
|
resource: replicaset
|
|
selector: component=controller,app=metallb
|
|
condition: --for=jsonpath='{.status.availableReplicas}'=1
|
|
loop_control:
|
|
label: "{{ item.description }}"
|
|
|
|
- name: Set metallb webhook service name
|
|
ansible.builtin.set_fact:
|
|
# Inspected the v0.16.0 manifest: the newer webhook Service name is used
|
|
# by every supported MetalLB release, so the old pre-0.14.4 branch is gone.
|
|
metallb_webhook_service_name: metallb-webhook-service
|
|
|
|
- name: Test metallb-system webhook-service endpoint
|
|
ansible.builtin.command: >-
|
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} -n metallb-system get endpoints {{ metallb_webhook_service_name }}
|
|
changed_when: false
|
|
with_items: "{{ groups[group_name_master | default('master')] }}"
|
|
run_once: true
|
|
|
|
- name: Apply metallb CRs
|
|
ansible.builtin.command: >-
|
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} apply -f /tmp/k3s/metallb-crs.yaml
|
|
--timeout='{{ metal_lb_available_timeout }}'
|
|
register: this
|
|
changed_when: false
|
|
run_once: true
|
|
until: this.rc == 0
|
|
retries: 5
|
|
|
|
- name: Test metallb-system resources for Layer 2 configuration
|
|
ansible.builtin.command: >-
|
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} -n metallb-system get {{ item }}
|
|
changed_when: false
|
|
run_once: true
|
|
when: metal_lb_mode == "layer2"
|
|
register: metallb_l2_test_result
|
|
until: metallb_l2_test_result.rc == 0
|
|
retries: "{{ download_retries }}"
|
|
delay: "{{ download_delay }}"
|
|
with_items:
|
|
- IPAddressPool
|
|
- L2Advertisement
|
|
|
|
- name: Test metallb-system resources for BGP configuration
|
|
ansible.builtin.command: >-
|
|
{{ k3s_kubectl_binary | default('k3s kubectl') }} -n metallb-system get {{ item }}
|
|
changed_when: false
|
|
run_once: true
|
|
when: metal_lb_mode == "bgp"
|
|
register: metallb_bgp_test_result
|
|
until: metallb_bgp_test_result.rc == 0
|
|
retries: "{{ download_retries }}"
|
|
delay: "{{ download_delay }}"
|
|
with_items:
|
|
- IPAddressPool
|
|
- BGPPeer
|
|
- BGPAdvertisement
|