78 Commits

Author SHA1 Message Date
6220e2a9aa Add chart values to var_file;Add default null
Some checks failed
continuous-integration/drone/push Build is failing
2022-07-04 13:49:37 +02:00
e3e46bae7d Test injecting dictionaries into yaml file
Some checks failed
continuous-integration/drone/push Build is failing
2022-07-04 13:26:35 +02:00
6e6e7900da Update gitea chart values;Add registry mirror definitions
All checks were successful
continuous-integration/drone/push Build is passing
2022-07-04 12:39:53 +02:00
6c329a36e9 Move payload file
All checks were successful
continuous-integration/drone/push Build is passing
2022-07-03 22:32:17 +02:00
f33f2912f1 Fix linting error
All checks were successful
continuous-integration/drone/push Build is passing
2022-07-03 15:19:41 +02:00
9541942c23 Install gitea chart;Add tea cli binary
Some checks failed
continuous-integration/drone/push Build is failing
2022-07-03 15:08:57 +02:00
2f937aded7 Rename vapp property;Configure node for private registry 2022-07-03 14:52:01 +02:00
95dea97382 Fix skopeo copy syntax
All checks were successful
continuous-integration/drone/push Build is passing
2022-07-01 13:10:26 +02:00
a840306245 Change hypervisor cluster 2022-07-01 11:13:29 +02:00
bbd103d527 Fix scalar block syntax
All checks were successful
continuous-integration/drone/push Build is passing
2022-07-01 10:39:47 +02:00
b2ceee8720 Push images to registry
Some checks failed
continuous-integration/drone/push Build is failing
2022-07-01 10:32:58 +02:00
d5c886f02b Fix Harbor config;Add extra container images
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-30 16:21:19 +02:00
1d59cd4b3c Configure Harbor;Disable tarball deletion
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-30 11:20:39 +02:00
f2d9147291 Fix syntax error
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-30 08:03:13 +02:00
bc9f1c260f Reconfigure Longhorn/Harbor
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-29 17:06:23 +02:00
368f84769b Reenable image handling;Configure Longhorn/Harbor
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-29 13:07:34 +02:00
51366476cc Fix linting error
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-29 11:31:13 +02:00
dcbaf6b807 Create/mount logical volume;Add lvm2 dependency
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-29 11:29:22 +02:00
5dfc3a7813 Redirect crontab output 2022-06-29 09:58:10 +02:00
0989d0c586 Remove debugging;Add missing collection
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-29 09:27:03 +02:00
8a83f47572 Redirect error output;Add debugging;Housekeeping
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-29 09:06:13 +02:00
a3bbf88ce3 Rename file 2022-06-29 08:54:36 +02:00
5e0cebf733 Fix linting error 2022-06-29 08:00:02 +02:00
00e3266360 Test dynamic disk;Disable containerimages temporarily
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-29 07:59:17 +02:00
c6a8f9f7bd Fix linting errors
Some checks reported errors
continuous-integration/drone/push Build was killed
2022-06-28 17:11:11 +02:00
4f1231f973 Set longhorn defaults
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-28 17:10:24 +02:00
049bedbd8f Mount dynamic disk
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-28 16:37:54 +02:00
0e7cfa0934 Add dynamic disk;Add kubectl tab completion
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-28 15:46:55 +02:00
5435f73402 Disable local-path storageclass
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-28 12:02:12 +02:00
6917e0799a Add missing kubeconfig key
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-28 11:53:17 +02:00
4616b9b070 Fix typo
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-28 09:37:49 +02:00
8c741dc120 Fix parse logic
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-27 22:50:12 +02:00
8cbfcb016b Remove debugging; Cleanup redundant logic;Add vapp property
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 20:26:09 +02:00
4ba7b590ba Debugging & revert override logic
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 19:43:07 +02:00
52660e1414 Fix var reference
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 17:05:30 +02:00
0ab6aaeaa5 Fix foldername 2022-06-27 16:57:14 +02:00
02c26b2465 Scale down cpu/ram 2022-06-27 16:46:27 +02:00
1842a08a39 Add Gitea;Allow override of helm-chart basedir
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 16:32:25 +02:00
0c01f024e9 Increase disksize;Add container image import during firstboot
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-27 16:02:11 +02:00
40489ff373 Housekeeping #2 2022-06-27 15:34:15 +02:00
c491066384 Housekeeping 2022-06-27 15:33:49 +02:00
4c054cc434 Switch module
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-27 14:38:48 +02:00
dcbe6c397f Change tarball scope;Try zeroing disk
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 13:55:59 +02:00
cb84a02b6f Readd parse_logic
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-27 12:27:11 +02:00
8f432d3353 Remove debugging;Housekeeping;Rename dict 2022-06-27 10:55:17 +02:00
1cdbcaccaf Filter invalid results
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-27 10:28:27 +02:00
f1c6161bcb Revert debugging;Switch ansible module
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-27 09:56:48 +02:00
123518a787 Debugging versions
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 09:54:57 +02:00
2ec6a756b7 Quote whole cli string
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 09:27:33 +02:00
a1779be079 Change yq syntax
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 09:03:43 +02:00
8ed9b2f754 Fix firstboot logic;Refactor helm chart parsing;Housekeeping
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-27 08:44:16 +02:00
72202d9f21 Fix missing parenthesis;Attempt parsing argo-cd chart
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-26 22:30:10 +02:00
9eb5fbd0a3 Fix component name;Temporarily add ignore_errors
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-26 21:35:41 +02:00
c58ede04c4 Add missing galaxy collection;Fix logic to parse charts for container images;Add ArgoCD
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 21:20:16 +02:00
662e8984c3 Fix linting errors; Extend firstboot logic
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 21:01:27 +02:00
b7abf25907 Fix version number;Parse, Pull & Compress container images
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 20:56:45 +02:00
18fa7742fa Add short pause before first provisioner
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 18:48:06 +02:00
f6993c2052 Remove redundant quotes
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 18:32:05 +02:00
59d1730ca5 Update var reference #2
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 18:24:57 +02:00
b087203cfb Update var reference
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 18:06:15 +02:00
d39d594bf0 Reorganize vars dict;Parse & loop through dict key/values
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-26 17:54:19 +02:00
487239365e Remove debugging;Set loop_control label
All checks were successful
continuous-integration/drone/push Build is passing
2022-06-25 23:57:55 +02:00
6ea03d152c Debugging paths
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 23:43:20 +02:00
01991435ae Remove loop redundancy
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 23:32:29 +02:00
a64b5b2325 Fix missing quote
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 21:14:47 +02:00
38d7442025 Remove redundant tasks
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 21:03:42 +02:00
cf91519076 Add jinja filter
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 20:48:15 +02:00
bae044e145 Fix misaligned var references
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 20:23:27 +02:00
f39b4bbb62 Try dynamic logic for archived/compressed/flat static binaries
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 18:44:43 +02:00
9739c51100 Fix var reference
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 08:49:53 +02:00
0df98d4341 Quote special char string
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 08:33:12 +02:00
fc23dc068d Fix var reference;Install packages;Change DHCP identifier to MAC
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 08:28:44 +02:00
4d78d65ad8 Add missing role reference
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 01:13:37 +02:00
c1440d9dcd Add ansible galaxy collection requirements
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 01:08:11 +02:00
4a5f390ae1 Fix linting errors
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 00:54:36 +02:00
e0a5b5a5da Reorganize dependencies/components;Fix folder name
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-25 00:50:44 +02:00
081aaaaa19 Fix/Replace old references;Fix syntaxes
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-24 23:55:54 +02:00
2bd0f8df0a Initial build based on 22.04
Some checks failed
continuous-integration/drone/push Build is failing
2022-06-24 23:44:10 +02:00
27 changed files with 563 additions and 65 deletions

View File

@@ -14,11 +14,11 @@ steps:
- name: Debugging information - name: Debugging information
image: bv11-cr01.bessems.eu/library/packer-extended image: bv11-cr01.bessems.eu/library/packer-extended
commands: commands:
- yamllint --version
- packer --version
- ansible --version - ansible --version
- ovftool --version - ovftool --version
- name: Ubuntu Server 22.04 - packer --version
- yamllint --version
- name: Kubernetes Bootstrap Appliance
image: bv11-cr01.bessems.eu/library/packer-extended image: bv11-cr01.bessems.eu/library/packer-extended
pull: always pull: always
commands: commands:
@@ -30,13 +30,16 @@ steps:
ansible \ ansible \
packer/preseed/UbuntuServer22.04/user-data \ packer/preseed/UbuntuServer22.04/user-data \
scripts scripts
- |
ansible-galaxy install \
-r ansible/requirements.yml
- | - |
packer init -upgrade \ packer init -upgrade \
./packer ./packer
- | - |
packer validate \ packer validate \
-var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \ -var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \
-var vm_guestos=ubuntuserver22.04 \ -var vm_guestos=k8sbootstrap \
-var repo_username=$${REPO_USERNAME} \ -var repo_username=$${REPO_USERNAME} \
-var repo_password=$${REPO_PASSWORD} \ -var repo_password=$${REPO_PASSWORD} \
-var vsphere_password=$${VSPHERE_PASSWORD} \ -var vsphere_password=$${VSPHERE_PASSWORD} \
@@ -46,7 +49,7 @@ steps:
packer build \ packer build \
-on-error=cleanup -timestamp-ui \ -on-error=cleanup -timestamp-ui \
-var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \ -var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \
-var vm_guestos=ubuntuserver22.04 \ -var vm_guestos=k8sbootstrap \
-var repo_username=$${REPO_USERNAME} \ -var repo_username=$${REPO_USERNAME} \
-var repo_password=$${REPO_PASSWORD} \ -var repo_password=$${REPO_PASSWORD} \
-var vsphere_password=$${VSPHERE_PASSWORD} \ -var vsphere_password=$${VSPHERE_PASSWORD} \

View File

@@ -1 +1 @@
# Packer.Images [![Build Status](https://ci.spamasaurus.com/api/badges/djpbessems/Packer.Images/status.svg?ref=refs/heads/UbuntuServer22.04)](https://ci.spamasaurus.com/djpbessems/Packer.Images) # Packer.Images [![Build Status](https://ci.spamasaurus.com/api/badges/djpbessems/Packer.Images/status.svg?ref=refs/heads/Kubernetes.Bootstrap.Appliance)](https://ci.spamasaurus.com/djpbessems/Packer.Images)

View File

@@ -1,7 +1,11 @@
--- ---
- hosts: all - hosts: all
gather_facts: false gather_facts: false
vars_files:
- metacluster.yml
become: true become: true
roles: roles:
- os - os
- firstboot - firstboot
- appliance
- metacluster

4
ansible/requirements.yml Normal file
View File

@@ -0,0 +1,4 @@
collections:
- ansible.utils
- community.general
- kubernetes.core

View File

@@ -0,0 +1,27 @@
---
- name: Initialize tempfolder
ansible.builtin.tempfile:
state: directory
register: archive
- name: Download & extract archived static binary
ansible.builtin.unarchive:
src: "{{ item.url }}"
dest: "{{ archive.path }}"
remote_src: yes
extra_opts: "{{ item.extra_opts | default(omit) }}"
- name: Install extracted binary
ansible.builtin.copy:
src: "{{ archive.path }}/{{ item.filename }}"
dest: /usr/local/bin/{{ item.filename }}
remote_src: yes
owner: root
group: root
mode: 0755
- name: Cleanup tempfolder
ansible.builtin.file:
path: "{{ archive.path }}"
state: absent
when: archive.path is defined

View File

@@ -0,0 +1,46 @@
# - name: Create folder structure(s)
# ansible.builtin.file:
# path: "{{ item }}"
# state: directory
# loop:
# - /foo
- name: Download & install static binaries
ansible.builtin.get_url:
url: "{{ item.url }}"
dest: /usr/local/bin/{{ item.filename }}
owner: root
group: root
mode: 0755
loop: "{{ dependencies.static_binaries | selectattr('archive', 'undefined') }}"
loop_control:
label: "{{ item.filename }}"
- name: Download, extract & install archived static binaries
include_tasks: dependencies.archive_compressed.yml
loop: "{{ dependencies.static_binaries | rejectattr('archive', 'undefined') | selectattr('archive', 'equalto', 'compressed') }}"
loop_control:
label: "{{ item.filename }}"
- name: Install ansible-galaxy collections
ansible.builtin.shell:
cmd: ansible-galaxy collection install {{ item }}
loop: "{{ dependencies.ansible_galaxy_collections }}"
- name: Install distro packages
ansible.builtin.apt:
pkg: "{{ dependencies.packages }}"
state: latest
update_cache: yes
install_recommends: no
- name: Upgrade all packages
ansible.builtin.apt:
name: '*'
state: latest
update_cache: yes
- name: Cleanup apt cache
ansible.builtin.apt:
autoremove: yes
purge: yes

View File

@@ -0,0 +1,2 @@
- name: Install & configure dependencies
import_tasks: dependencies.yml

View File

@@ -7,4 +7,6 @@
- vapp - vapp
- network - network
- users - users
- disks
- metacluster
- cleanup - cleanup

View File

@@ -0,0 +1,24 @@
- name: Create volume group
community.general.lvg:
vg: longhorn_vg
pvs:
- /dev/sdb
pvresize: yes
- name: Create logical volume
community.general.lvol:
vg: longhorn_vg
lv: longhorn_lv
size: 100%VG
- name: Create filesystem
community.general.filesystem:
dev: /dev/mapper/longhorn_vg-longhorn_lv
fstype: ext4
- name: Mount dynamic disk
ansible.posix.mount:
path: /mnt/blockstorage
src: /dev/mapper/longhorn_vg-longhorn_lv
fstype: ext4
state: mounted

View File

@@ -0,0 +1,153 @@
- name: Install K3s
ansible.builtin.command:
cmd: ./install.sh
chdir: /opt/metacluster/k3s
environment:
INSTALL_K3S_SKIP_DOWNLOAD: 'true'
INSTALL_K3S_EXEC: 'server --cluster-init --disable local-storage'
- name: Install kubectl tab-completion
ansible.builtin.shell:
cmd: kubectl completion bash | tee /etc/bash_completion.d/kubectl
- name: Ensure API availability
ansible.utils.cli_parse:
command: curl -k https://{{ vapp['guestinfo.ipaddress'] }}:6443/livez?verbose
parser:
name: ansible.utils.json
set_fact: api_readycheck
ignore_errors: yes
until: api_readycheck.apiVersion is defined
retries: 3
delay: 30
- block:
- name: Initialize tempfile
ansible.builtin.tempfile:
state: file
register: kubeconfig
- name: Retrieve kubeconfig
ansible.builtin.command:
cmd: kubectl config view --raw
register: kubectl_config
- name: Store kubeconfig in tempfile
ansible.builtin.copy:
dest: "{{ kubeconfig.path }}"
content: "{{ kubectl_config.stdout }}"
mode: 0600
no_log: true
- block:
- name: Extract container images
ansible.builtin.unarchive:
src: /opt/metacluster/container-images/image-tarballs.tgz
dest: /opt/metacluster/container-images
list_files: yes
register: imagetarballs
- name: Import container images
ansible.builtin.command:
cmd: k3s ctr image import {{ item }}
chdir: /opt/metacluster/container-images
loop: "{{ imagetarballs.files }}"
- name: Install longhorn chart
kubernetes.core.helm:
name: longhorn
chart_ref: /opt/metacluster/helm-charts/longhorn
release_namespace: longhorn-system
create_namespace: yes
wait: yes
kubeconfig: "{{ kubeconfig.path }}"
values:
defaultSettings:
defaultDataPath: /mnt/blockstorage
defaultReplicaCount: 1
ingress:
enabled: true
host: storage.{{ vapp['metacluster.fqdn'] }}
persistence:
defaultClassReplicaCount: 1
- name: Install harbor chart
kubernetes.core.helm:
name: harbor
chart_ref: /opt/metacluster/helm-charts/harbor
release_namespace: harbor
create_namespace: yes
wait: yes
kubeconfig: "{{ kubeconfig.path }}"
values:
expose:
ingress:
hosts:
core: registry.{{ vapp['metacluster.fqdn'] }}
externalURL: https://registry.{{ vapp['metacluster.fqdn'] }}
harborAdminPassword: "{{ vapp['guestinfo.rootpw'] }}"
notary:
enabled: false
- name: Push images to registry
ansible.builtin.shell:
cmd: >-
skopeo copy \
--dest-tls-verify=false \
--dest-creds admin:{{ vapp['guestinfo.rootpw'] }} \
docker-archive:./{{ item }} \
docker://registry.{{ vapp['metacluster.fqdn'] }}/library/$( \
k3s ctr run \
--rm \
--mount type=bind,src=$PWD,dst=/data,options=rbind:ro \
quay.io/skopeo/stable:v1.8.0 skopeo \
skopeo list-tags docker-archive:/data/{{ item }} | \
jq -r '.Tags[0]')
chdir: /opt/metacluster/container-images/
register: results
# ignore_errors: yes
loop: "{{ imagetarballs.files }}"
- ansible.builtin.debug:
var: results
- name: Delete container image tarballs/archives
ansible.builtin.file:
path: /opt/metacluster/container-images
state: absent
- name: Configure K3s node for private registry
ansible.builtin.template:
dest: /etc/rancher/k3s/registries.yaml
src: registries.j2
- name: Install gitea chart
kubernetes.core.helm:
name: gitea
chart_ref: /opt/metacluster/helm-charts/gitea
release_namespace: gitea
create_namespace: yes
wait: yes
kubeconfig: "{{ kubeconfig.path }}"
values:
gitea:
admin:
username: administrator
password: "{{ vapp['guestinfo.rootpw'] }}"
email: admin@{{ vapp['metacluster.fqdn'] }}
image:
pullPolicy: IfNotPresent
ingress:
hosts:
- host: git.{{ vapp['metacluster.fqdn'] }}
paths:
- path: /
pathType: Prefix
- name: Cleanup tempfile
ansible.builtin.file:
path: "{{ kubeconfig.path }}"
state: absent
when: kubeconfig.path is defined

View File

@@ -1,10 +1,12 @@
- name: Set hostname - name: Set hostname
ansible.builtin.hostname: ansible.builtin.hostname:
name: "{{ ovfproperties['guestinfo.hostname'] }}" name: "{{ vapp['guestinfo.hostname'] }}"
- name: Create netplan configuration file - name: Create netplan configuration file
ansible.builtin.template: ansible.builtin.template:
src: netplan.j2 src: netplan.j2
dest: /etc/netplan/00-installer-config.yaml dest: /etc/netplan/00-installer-config.yaml
- name: Apply netplan configuration - name: Apply netplan configuration
ansible.builtin.shell: ansible.builtin.shell:
cmd: /usr/sbin/netplan apply cmd: /usr/sbin/netplan apply

View File

@@ -3,8 +3,8 @@ network:
ethernets: ethernets:
ens192: ens192:
addresses: addresses:
- {{ ovfproperties['guestinfo.ipaddress'] }}/{{ ovfproperties['guestinfo.prefixlength'] }} - {{ vapp['guestinfo.ipaddress'] }}/{{ vapp['guestinfo.prefixlength'] }}
gateway4: {{ ovfproperties['guestinfo.gateway'] }} gateway4: {{ vapp['guestinfo.gateway'] }}
nameservers: nameservers:
addresses: addresses:
- {{ ovfproperties['guestinfo.dnsserver'] }} - {{ vapp['guestinfo.dnsserver'] }}

View File

@@ -1,14 +1,14 @@
- name: Set root password - name: Set root password
ansible.builtin.user: ansible.builtin.user:
name: root name: root
password: "{{ ovfproperties['guestinfo.rootpw'] | password_hash('sha512', 65534 | random(seed=ovfproperties['guestinfo.hostname']) | string) }}" password: "{{ vapp['guestinfo.rootpw'] | password_hash('sha512', 65534 | random(seed=vapp['guestinfo.hostname']) | string) }}"
generate_ssh_key: yes generate_ssh_key: yes
ssh_key_bits: 2048 ssh_key_bits: 2048
ssh_key_file: .ssh/id_rsa ssh_key_file: .ssh/id_rsa
- name: Save root SSH publickey - name: Save root SSH publickey
ansible.builtin.lineinfile: ansible.builtin.lineinfile:
path: /root/.ssh/authorized_keys path: /root/.ssh/authorized_keys
line: "{{ ovfproperties['guestinfo.rootsshkey'] }}" line: "{{ vapp['guestinfo.rootsshkey'] }}"
- name: Disable SSH password authentication - name: Disable SSH password authentication
ansible.builtin.lineinfile: ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config path: /etc/ssh/sshd_config

View File

@@ -2,6 +2,7 @@
ansible.builtin.shell: ansible.builtin.shell:
cmd: /usr/bin/vmtoolsd --cmd "info-get guestinfo.ovfEnv" cmd: /usr/bin/vmtoolsd --cmd "info-get guestinfo.ovfEnv"
register: ovfenv register: ovfenv
- name: Parse XML for vApp properties - name: Parse XML for vApp properties
community.general.xml: community.general.xml:
xmlstring: "{{ ovfenv.stdout }}" xmlstring: "{{ ovfenv.stdout }}"
@@ -10,10 +11,11 @@
xpath: /ns:Environment/ns:PropertySection/ns:Property xpath: /ns:Environment/ns:PropertySection/ns:Property
content: attribute content: attribute
register: ovfenv register: ovfenv
- name: Assign vApp properties to dictionary - name: Assign vApp properties to dictionary
ansible.builtin.set_fact: ansible.builtin.set_fact:
ovfproperties: >- vapp: >-
{{ ovfproperties | default({}) | {{ vapp | default({}) |
combine({((item.values() | list)[0].values() | list)[0]: combine({((item.values() | list)[0].values() | list)[0]:
((item.values() | list)[0].values() | list)[1]}) ((item.values() | list)[0].values() | list)[1]})
}} }}

View File

@@ -0,0 +1,16 @@
mirrors:
docker.io:
endpoint:
- "https://registry.{{ vapp['metacluster.fqdn'] }}
rewrite:
"(.*)": "library/docker.io/$1"
ghcr.io:
endpoint:
- "https://registry.{{ vapp['metacluster.fqdn'] }}
rewrite:
"(.*)": "library/ghcr.io/$1"
quay.io:
endpoint:
- "https://registry.{{ vapp['metacluster.fqdn'] }}
rewrite:
"(.*)": "library/quay.io/$1"

View File

@@ -0,0 +1,2 @@
components:

View File

@@ -2,6 +2,7 @@
ansible.builtin.file: ansible.builtin.file:
path: /opt/firstboot path: /opt/firstboot
state: directory state: directory
- name: Create firstboot script file - name: Create firstboot script file
ansible.builtin.template: ansible.builtin.template:
src: firstboot.j2 src: firstboot.j2
@@ -9,11 +10,13 @@
owner: root owner: root
group: root group: root
mode: o+x mode: o+x
- name: Create @reboot crontab job - name: Create @reboot crontab job
ansible.builtin.cron: ansible.builtin.cron:
name: firstboot name: firstboot
special_time: reboot special_time: reboot
job: "/opt/firstboot/firstboot.sh" job: "/opt/firstboot/firstboot.sh >/dev/tty1 2>&1"
- name: Copy payload folder - name: Copy payload folder
ansible.builtin.copy: ansible.builtin.copy:
src: ansible_payload/ src: ansible_payload/
@@ -21,6 +24,3 @@
owner: root owner: root
group: root group: root
mode: '0644' mode: '0644'
- name: Install ansible-galaxy collection
ansible.builtin.shell:
cmd: ansible-galaxy collection install community.general

View File

@@ -1,4 +1,4 @@
#!/bin/bash #!/bin/bash
# Apply firstboot configuration w/ ansible # Apply firstboot configuration w/ ansible
/usr/local/bin/ansible-playbook /opt/firstboot/ansible/playbook.yml | tee -a /var/log/firstboot.log > /dev/tty1 /usr/local/bin/ansible-playbook /opt/firstboot/ansible/playbook.yml | tee -a /var/log/firstboot.log > /dev/tty1 2>&1

View File

@@ -0,0 +1,4 @@
- name: Zero-out disk
ansible.builtin.shell:
cmd: dd bs=1M count=$(df -m . | awk '/[0-9]%/{print $(NF-2)}') if=/dev/zero of=./zero; sync; sync; rm -f ./zero
chdir: /opt/metacluster

View File

@@ -0,0 +1,56 @@
- name: Create folder structure(s)
ansible.builtin.file:
path: "{{ item }}"
state: directory
loop:
- /opt/metacluster/helm-charts
- /opt/metacluster/container-images
#- name: Inject values (re: firstboot logic)
- name: Add helm repositories
kubernetes.core.helm_repository:
name: "{{ item.name }}"
repo_url: "{{ item.url }}"
state: present
loop: "{{ platform.helm_repositories }}"
- name: Fetch helm charts
ansible.builtin.command:
cmd: helm fetch {{ item.value.helm.chart }} --untar --version {{ item.value.helm.version }}
chdir: /opt/metacluster/helm-charts
loop: "{{ lookup('ansible.builtin.dict', components) }}"
loop_control:
label: "{{ item.key }}"
- name: Inject chart values into ansible var files
ansible.builtin.lineinfile:
path: /opt/firstboot/ansible/vars/metacluster.yml
block: |2
{{ item.key }}:
{{ item.value.chart_values | default('~') }}
loop: "{{ lookup('ansible.builtin.dict', components) }}"
loop_control:
label: "{{ item.key }}"
- name: Parse helm charts for container images
ansible.builtin.shell:
cmd: "{{ item.value.helm.parse_logic }}"
chdir: /opt/metacluster/helm-charts/{{ item.key }}
register: containerimages
loop: "{{ lookup('ansible.builtin.dict', components) }}"
loop_control:
label: "{{ item.key }}"
- name: Pull and store containerimages
ansible.builtin.command:
cmd: skopeo copy docker://{{ item }} docker-archive:./{{ ( item | regex_findall('[^/:]+'))[-2] }}.tar:{{ item }}
chdir: /opt/metacluster/container-images
loop: "{{ containerimages.results | map(attribute='stdout_lines') | flatten + dependencies.container_images }}"
- name: Compress tarballs
community.general.archive:
dest: /opt/metacluster/container-images/image-tarballs.tgz
path: /opt/metacluster/container-images/*
format: gz
remove: yes

View File

@@ -0,0 +1,28 @@
- name: Create folder structure(s)
ansible.builtin.file:
path: "{{ item }}"
state: directory
loop:
- /var/lib/rancher/k3s/agent/images
- /opt/metacluster/k3s
- name: Download & install K3s binary
ansible.builtin.get_url:
url: https://github.com/k3s-io/k3s/releases/download/{{ platform.k3s.version }}/k3s
dest: /usr/local/bin/k3s
owner: root
group: root
mode: 0755
- name: Download K3s images tarball
ansible.builtin.get_url:
url: https://github.com/k3s-io/k3s/releases/download/{{ platform.k3s.version }}/k3s-airgap-images-amd64.tar.gz
dest: /var/lib/rancher/k3s/agent/images
- name: Download K3s install script
ansible.builtin.get_url:
url: https://get.k3s.io
dest: /opt/metacluster/k3s/install.sh
owner: root
group: root
mode: 0755

View File

@@ -0,0 +1,6 @@
- name: Pre-stage K3s components
import_tasks: k3s.yml
- name: Pre-stage meta components
import_tasks: components.yml
- name: Cleanup
import_tasks: cleanup.yml

View File

@@ -1,24 +1,13 @@
- name: Configure 'needrestart' package
ansible.builtin.lineinfile:
path: /etc/needrestart/needrestart.conf
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
loop:
- regexp: "^#\\$nrconf\\{restart\\} = 'i';"
line: "$nrconf{restart} = 'a';"
- regexp: "^#\\$nrconf\\{kernelhints\\} = -1;"
line: "$nrconf{kernelhints} = -1;"
- name: Install additional packages - name: Install additional packages
ansible.builtin.apt: ansible.builtin.apt:
name: "{{ item }}" pkg: "{{ packages }}"
state: latest state: latest
update_cache: yes update_cache: yes
loop: "{{ packages }}" install_recommends: no
- name: Upgrade all packages - name: Upgrade all packages
ansible.builtin.apt: ansible.builtin.apt:
name: "*" name: '*'
state: latest state: latest
update_cache: yes update_cache: yes

View File

@@ -0,0 +1,97 @@
platform:
k3s:
version: v1.24.1+k3s1
helm_repositories:
- name: longhorn
url: https://charts.longhorn.io
- name: harbor
url: https://helm.goharbor.io
- name: gitea-charts
url: https://dl.gitea.io/charts/
- name: argo
url: https://argoproj.github.io/argo-helm
components:
longhorn:
helm:
version: 1.3.0
chart: longhorn/longhorn
parse_logic: cat values.yaml | yq eval '.. | select(has("repository")) | .repository + ":" + .tag'
chart_values:
defaultSettings:
defaultDataPath: /mnt/blockstorage
defaultReplicaCount: 1
ingress:
enabled: true
host: {% raw %}storage.{{ vapp['metacluster.fqdn'] }}{% endraw %}
persistence:
defaultClassReplicaCount: 1
harbor:
helm:
version: 1.9.1 # (= Harbor v2.5.1)
chart: harbor/harbor
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /'
chart_values:
expose:
ingress:
hosts:
core: registry.{{ vapp['metacluster.fqdn'] }}
externalURL: https://registry.{{ vapp['metacluster.fqdn'] }}
harborAdminPassword: "{{ vapp['guestinfo.rootpw'] }}"
notary:
enabled: false
gitea:
helm:
version: v5.0.9 # (= Gitea v1.16.8)
chart: gitea-charts/gitea
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | sed '/:/!s/$/:latest/'
chart_values:
gitea:
admin:
username: administrator
password: "{{ vapp['guestinfo.rootpw'] }}"
email: admin@{{ vapp['metacluster.fqdn'] }}
image:
pullPolicy: IfNotPresent
ingress:
hosts:
- host: git.{{ vapp['metacluster.fqdn'] }}
paths:
- path: /
pathType: Prefix
argo-cd:
helm:
version: 4.9.7 # (= ArgoCD v2.4.2)
chart: argo/argo-cd
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /'
dependencies:
ansible_galaxy_collections:
- ansible.posix
- ansible.utils
- community.general
- kubernetes.core
container_images:
- quay.io/skopeo/stable:v1.8.0
static_binaries:
- filename: tea
url: https://dl.gitea.io/tea/0.8.0/tea-0.8.0-linux-amd64
- filename: helm
url: https://get.helm.sh/helm-v3.9.0-linux-amd64.tar.gz
archive: compressed
extra_opts: --strip-components=1
- filename: yq
url: http://github.com/mikefarah/yq/releases/download/v4.25.3/yq_linux_amd64
packages:
- lvm2
- skopeo

View File

@@ -3,7 +3,7 @@ packer {
} }
} }
source "vsphere-iso" "ubuntuserver" { source "vsphere-iso" "k8sbootstrap" {
vcenter_server = var.vcenter_server vcenter_server = var.vcenter_server
username = var.vsphere_username username = var.vsphere_username
password = var.vsphere_password password = var.vsphere_password
@@ -41,7 +41,7 @@ source "vsphere-iso" "ubuntuserver" {
network_card = "vmxnet3" network_card = "vmxnet3"
} }
storage { storage {
disk_size = 20480 disk_size = 51200
disk_thin_provisioned = true disk_thin_provisioned = true
} }
disk_controller_type = ["pvscsi"] disk_controller_type = ["pvscsi"]
@@ -60,18 +60,18 @@ source "vsphere-iso" "ubuntuserver" {
export { export {
images = false images = false
output_directory = "/scratch/ubuntuserver" output_directory = "/scratch/k8sbootstrap"
} }
remove_cdrom = true remove_cdrom = true
} }
build { build {
sources = [ sources = [
"source.vsphere-iso.ubuntuserver" "source.vsphere-iso.k8sbootstrap"
] ]
provisioner "ansible" { provisioner "ansible" {
only = ["vsphere-iso.ubuntuserver"] pause_before = "2m30s"
playbook_file = "ansible/playbook.yml" playbook_file = "ansible/playbook.yml"
user = "ubuntu" user = "ubuntu"
@@ -85,16 +85,15 @@ build {
} }
post-processor "shell-local" { post-processor "shell-local" {
only = ["vsphere-iso.ubuntuserver"]
inline = [ inline = [
"pwsh -command \"& scripts/Update-OvfConfiguration.ps1 \\", "pwsh -command \"& scripts/Update-OvfConfiguration.ps1 \\",
" -OVFFile '/scratch/ubuntuserver/${var.vm_guestos}-${var.vm_name}.ovf' \\", " -OVFFile '/scratch/k8sbootstrap/${var.vm_guestos}-${var.vm_name}.ovf' \\",
" -Parameter @{'appliance.name'='${var.vm_guestos}';'appliance.version'='${var.vm_name}'}\"", " -Parameter @{'appliance.name'='${var.vm_guestos}';'appliance.version'='${var.vm_name}'}\"",
"pwsh -file scripts/Update-Manifest.ps1 \\", "pwsh -file scripts/Update-Manifest.ps1 \\",
" -ManifestFileName '/scratch/ubuntuserver/${var.vm_guestos}-${var.vm_name}.mf'", " -ManifestFileName '/scratch/k8sbootstrap/${var.vm_guestos}-${var.vm_name}.mf'",
"ovftool --acceptAllEulas --allowExtraConfig --overwrite \\", "ovftool --acceptAllEulas --allowExtraConfig --overwrite \\",
" '/scratch/ubuntuserver/${var.vm_guestos}-${var.vm_name}.ovf' \\", " '/scratch/k8sbootstrap/${var.vm_guestos}-${var.vm_name}.ovf' \\",
" /output/Ubuntu-Server-22.04.ova" " /output/Kubernetes.Bootstrap.Appliance.ova"
] ]
} }
} }

View File

@@ -1,9 +1,9 @@
vcenter_server = "bv11-vc.bessems.lan" vcenter_server = "bv11-vc.bessems.lan"
vsphere_username = "administrator@vsphere.local" vsphere_username = "administrator@vsphere.local"
vsphere_datacenter = "DeSchakel" vsphere_datacenter = "DeSchakel"
vsphere_cluster = "Cluster.Legacy" vsphere_cluster = "Cluster.01"
vsphere_host = "bv11-esx.bessems.lan" vsphere_host = "bv11-esx02.bessems.lan"
vsphere_datastore = "ESX00.SSD01" vsphere_datastore = "NAS01.RAID5"
vsphere_folder = "/Packer" vsphere_folder = "/Packer"
vsphere_templatefolder = "/Templates" vsphere_templatefolder = "/Templates"
vsphere_network = "LAN" vsphere_network = "LAN"

View File

@@ -1,28 +1,51 @@
DeploymentConfigurations: DeploymentConfigurations:
- Id: small - Id: small
Label: 'Ubuntu Server 20.04 [SMALL: 1 vCPU/2GB RAM]' Label: 'Ubuntu Server 22.04 [SMALL: 1 vCPU/2GB RAM]'
Description: Ubuntu Server 20.04.x Description: Ubuntu Server 22.04.x
Size: Size:
CPU: 1 CPU: 1
Memory: 2048 Memory: 2048
- Id: large
Label: 'Ubuntu Server 20.04 [LARGE: 4 vCPU/8GB RAM]' - Id: medium
Description: Ubuntu Server 20.04.x Label: 'Ubuntu Server 22.04 [MEDIUM: 2 vCPU/4GB RAM]'
Description: Ubuntu Server 22.04.x
Size: Size:
CPU: 4 CPU: 2
Memory: 8192 Memory: 4096
DynamicDisks: []
DynamicDisks:
- Description: Longhorn persistent storage
UnitSize: GB
Constraints:
Minium: 100
Maximum: ''
PropertyCategories: PropertyCategories:
# - Name: 0) Deployment information # - Name: 0) Deployment information
# ProductProperties: # ProductProperties:
# - Key: deployment.type # - Key: deployment.type
# Type: string # Type: string
# Value: # Value:
# - small # - small
# - large # - medium
# UserConfigurable: false # UserConfigurable: false
- Name: 1) Operating System
- Name: 1) Kubernetes
ProductProperties: ProductProperties:
- Key: metacluster.fqdn
Type: string(1..)
Label: Appliance FQDN*
Description: 'Respective subdomains will be available for each component (e.g. storage.example.org); this address should already be configured as a wildcard record within your DNS zone.'
DefaultValue: 'example.org'
Configurations: '*'
UserConfigurable: true
- Name: 2) Operating System
ProductProperties:
- Key: guestinfo.hostname - Key: guestinfo.hostname
Type: string(1..15) Type: string(1..15)
Label: Hostname* Label: Hostname*
@@ -30,6 +53,7 @@ PropertyCategories:
DefaultValue: '' DefaultValue: ''
Configurations: '*' Configurations: '*'
UserConfigurable: true UserConfigurable: true
- Key: guestinfo.rootpw - Key: guestinfo.rootpw
Type: password(7..) Type: password(7..)
Label: Local root password* Label: Local root password*
@@ -37,6 +61,7 @@ PropertyCategories:
DefaultValue: '' DefaultValue: ''
Configurations: '*' Configurations: '*'
UserConfigurable: true UserConfigurable: true
- Key: guestinfo.rootsshkey - Key: guestinfo.rootsshkey
Type: password(1..) Type: password(1..)
Label: Local root SSH public key* Label: Local root SSH public key*
@@ -44,15 +69,10 @@ PropertyCategories:
DefaultValue: '' DefaultValue: ''
Configurations: '*' Configurations: '*'
UserConfigurable: true UserConfigurable: true
- Key: guestinfo.ntpserver
Type: string(1..) - Name: 3) Networking
Label: Time server*
Description: A comma-separated list of timeservers
DefaultValue: 0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org
Configurations: '*'
UserConfigurable: true
- Name: 2) Networking
ProductProperties: ProductProperties:
- Key: guestinfo.ipaddress - Key: guestinfo.ipaddress
Type: ip Type: ip
Label: IP Address* Label: IP Address*
@@ -60,6 +80,7 @@ PropertyCategories:
DefaultValue: '' DefaultValue: ''
Configurations: '*' Configurations: '*'
UserConfigurable: true UserConfigurable: true
- Key: guestinfo.prefixlength - Key: guestinfo.prefixlength
Type: int(8..32) Type: int(8..32)
Label: Subnet prefix length* Label: Subnet prefix length*
@@ -67,6 +88,7 @@ PropertyCategories:
DefaultValue: '24' DefaultValue: '24'
Configurations: '*' Configurations: '*'
UserConfigurable: true UserConfigurable: true
- Key: guestinfo.dnsserver - Key: guestinfo.dnsserver
Type: ip Type: ip
Label: DNS server* Label: DNS server*
@@ -74,6 +96,7 @@ PropertyCategories:
DefaultValue: '' DefaultValue: ''
Configurations: '*' Configurations: '*'
UserConfigurable: true UserConfigurable: true
- Key: guestinfo.gateway - Key: guestinfo.gateway
Type: ip Type: ip
Label: Gateway* Label: Gateway*
@@ -81,6 +104,15 @@ PropertyCategories:
DefaultValue: '' DefaultValue: ''
Configurations: '*' Configurations: '*'
UserConfigurable: true UserConfigurable: true
- Key: guestinfo.ntpserver
Type: string(1..)
Label: Time server*
Description: A comma-separated list of timeservers
DefaultValue: 0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org
Configurations: '*'
UserConfigurable: true
AdvancedOptions: AdvancedOptions:
- Key: appliance.name - Key: appliance.name
Value: "{{ appliance.name }}" Value: "{{ appliance.name }}"