mirror of
https://github.com/techno-tim/k3s-ansible.git
synced 2026-08-08 23:13:19 +02:00
287d8b7a27
* feat(kube-vip): add endpoint override for the internal listening address Add a kube_vip_endpoint variable so the address kube-vip binds and listens on can differ from the announced apiserver_endpoint. This is useful for complex routing and site-to-site tunnels where the VIP kube-vip advertises over ARP differs from the address it listens on internally. - roles/k3s_server/templates/vip.yaml.j2: use kube_vip_endpoint (defaulting to apiserver_endpoint) for the `address` env and for deriving `vip_subnet` - roles/k3s_server/defaults/main.yml: add kube_vip_endpoint default (null) - roles/k3s_server/meta/main.yml: add kube_vip_endpoint argument_spec - inventory/sample/group_vars/all.yml: document the new sample variable - README.md: document the kube_vip_endpoint option - .github/scripts/test-kube-vip-manifest.py: extend regression test to cover the default (apiserver_endpoint) and the override case Closes #221 * chore(ci): extend molecule job timeout to 3 hours The default scenario occasionally takes longer than 150 minutes on the shared nested-virt runner (k3s agent notify-wait can exceed the limit under load), and a single timeout aborts the whole run before the other four scenarios execute. Raise timeout-minutes from 150 to 180 so a slow-but-progressing run completes instead of aborting. The default scenario remains first in the matrix so a failure surfaces fastest. * fix(kube-vip): fall back on null kube_vip_endpoint and cover it in the test - vip_subnet and address use default(apiserver_endpoint, true) so the null role default falls back to the apiserver endpoint instead of rendering an empty/invalid address and subnet - change the manifest regression test default case to pass kube_vip_endpoint as None so it pins the real runtime null condition and fails fast on this regression rather than timing out in CI
145 lines
4.1 KiB
YAML
145 lines
4.1 KiB
YAML
---
|
|
argument_specs:
|
|
main:
|
|
short_description: Setup k3s servers
|
|
options:
|
|
apiserver_endpoint:
|
|
description: Virtual ip-address configured on each master
|
|
required: true
|
|
|
|
cilium_bgp:
|
|
description:
|
|
- Enable cilium BGP control plane for LB services and pod cidrs.
|
|
- Disables the use of MetalLB.
|
|
type: bool
|
|
default: ~
|
|
|
|
cilium_iface:
|
|
description: The network interface used for when Cilium is enabled
|
|
default: ~
|
|
|
|
extra_server_args:
|
|
description: Extra arguments for server nodes
|
|
default: ""
|
|
|
|
group_name_master:
|
|
description: Name of the master group
|
|
default: master
|
|
|
|
k3s_create_kubectl_symlink:
|
|
description: Create the kubectl -> k3s symlink
|
|
default: false
|
|
type: bool
|
|
|
|
k3s_create_crictl_symlink:
|
|
description: Create the crictl -> k3s symlink
|
|
default: false
|
|
type: bool
|
|
|
|
kube_vip_arp:
|
|
description: Enables kube-vip ARP broadcasts
|
|
default: true
|
|
type: bool
|
|
|
|
kube_vip_bgp:
|
|
description: Enables kube-vip BGP peering
|
|
default: false
|
|
type: bool
|
|
|
|
kube_vip_bgp_routerid:
|
|
description: Defines the router ID for the kube-vip BGP server
|
|
default: "127.0.0.1"
|
|
|
|
kube_vip_bgp_as:
|
|
description: Defines the AS for the kube-vip BGP server
|
|
default: "64513"
|
|
|
|
kube_vip_bgp_peeraddress:
|
|
description: Defines the address for the kube-vip BGP peer
|
|
default: "192.168.30.1"
|
|
|
|
kube_vip_bgp_peeras:
|
|
description: Defines the AS for the kube-vip BGP peer
|
|
default: "64512"
|
|
|
|
kube_vip_bgp_peers:
|
|
description: List of BGP peer ASN & address pairs
|
|
default: []
|
|
|
|
kube_vip_bgp_peers_groups:
|
|
description: Inventory group in which to search for additional kube_vip_bgp_peers parameters to merge.
|
|
default: ['k3s_master']
|
|
|
|
kube_vip_iface:
|
|
description:
|
|
- Explicitly define an interface that ALL control nodes
|
|
- should use to propagate the VIP, define it here.
|
|
- Otherwise, kube-vip will determine the right interface
|
|
- automatically at runtime.
|
|
default: ~
|
|
|
|
kube_vip_endpoint:
|
|
description:
|
|
- Overrides the address kube-vip binds/listens on internally, which
|
|
- can differ from the announced apiserver_endpoint for complex
|
|
- routing and site-to-site tunnels.
|
|
- Defaults to apiserver_endpoint and is used to derive the kube-vip
|
|
- subnet.
|
|
default: ~
|
|
|
|
kube_vip_tag_version:
|
|
description: Image tag for kube-vip
|
|
default: v1.2.2
|
|
|
|
kube_vip_cloud_provider_tag_version:
|
|
description: Tag for kube-vip-cloud-provider manifest when enabled
|
|
default: v0.0.12
|
|
|
|
kube_vip_lb_ip_range:
|
|
description: IP range for kube-vip load balancer
|
|
default: ~
|
|
|
|
metal_lb_controller_tag_version:
|
|
description: Image tag for MetalLB
|
|
default: v0.16.0
|
|
|
|
metal_lb_speaker_tag_version:
|
|
description: Image tag for MetalLB
|
|
default: v0.16.0
|
|
|
|
metal_lb_type:
|
|
choices:
|
|
- frr
|
|
- native
|
|
default: native
|
|
description: Use FRR mode or native. Valid values are `frr` and `native`
|
|
|
|
proxy_env:
|
|
type: dict
|
|
description:
|
|
- Internet proxy configurations.
|
|
- See https://docs.k3s.io/advanced#configuring-an-http-proxy for details
|
|
default: ~
|
|
options:
|
|
HTTP_PROXY:
|
|
description: HTTP internet proxy
|
|
required: true
|
|
HTTPS_PROXY:
|
|
description: HTTPS internet proxy
|
|
required: true
|
|
NO_PROXY:
|
|
description: Addresses that will not use the proxies
|
|
required: true
|
|
|
|
retry_count:
|
|
description: Amount of retries when verifying that nodes joined
|
|
type: int
|
|
default: 20
|
|
|
|
server_init_args:
|
|
description: Arguments for server nodes
|
|
|
|
systemd_dir:
|
|
description: Path to systemd services
|
|
default: /etc/systemd/system
|