Compare commits
2 Commits
bbd103d527
...
UbuntuServ
| Author | SHA1 | Date | |
|---|---|---|---|
| 73ec424030 | |||
| 154835d33e |
13
.drone.yml
13
.drone.yml
@@ -14,11 +14,11 @@ steps:
|
|||||||
- name: Debugging information
|
- name: Debugging information
|
||||||
image: bv11-cr01.bessems.eu/library/packer-extended
|
image: bv11-cr01.bessems.eu/library/packer-extended
|
||||||
commands:
|
commands:
|
||||||
|
- yamllint --version
|
||||||
|
- packer --version
|
||||||
- ansible --version
|
- ansible --version
|
||||||
- ovftool --version
|
- ovftool --version
|
||||||
- packer --version
|
- name: Ubuntu Server 22.04
|
||||||
- yamllint --version
|
|
||||||
- name: Kubernetes Bootstrap Appliance
|
|
||||||
image: bv11-cr01.bessems.eu/library/packer-extended
|
image: bv11-cr01.bessems.eu/library/packer-extended
|
||||||
pull: always
|
pull: always
|
||||||
commands:
|
commands:
|
||||||
@@ -30,16 +30,13 @@ steps:
|
|||||||
ansible \
|
ansible \
|
||||||
packer/preseed/UbuntuServer22.04/user-data \
|
packer/preseed/UbuntuServer22.04/user-data \
|
||||||
scripts
|
scripts
|
||||||
- |
|
|
||||||
ansible-galaxy install \
|
|
||||||
-r ansible/requirements.yml
|
|
||||||
- |
|
- |
|
||||||
packer init -upgrade \
|
packer init -upgrade \
|
||||||
./packer
|
./packer
|
||||||
- |
|
- |
|
||||||
packer validate \
|
packer validate \
|
||||||
-var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \
|
-var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \
|
||||||
-var vm_guestos=k8sbootstrap \
|
-var vm_guestos=ubuntuserver22.04 \
|
||||||
-var repo_username=$${REPO_USERNAME} \
|
-var repo_username=$${REPO_USERNAME} \
|
||||||
-var repo_password=$${REPO_PASSWORD} \
|
-var repo_password=$${REPO_PASSWORD} \
|
||||||
-var vsphere_password=$${VSPHERE_PASSWORD} \
|
-var vsphere_password=$${VSPHERE_PASSWORD} \
|
||||||
@@ -49,7 +46,7 @@ steps:
|
|||||||
packer build \
|
packer build \
|
||||||
-on-error=cleanup -timestamp-ui \
|
-on-error=cleanup -timestamp-ui \
|
||||||
-var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \
|
-var vm_name=$DRONE_BUILD_NUMBER-${DRONE_COMMIT_SHA:0:10} \
|
||||||
-var vm_guestos=k8sbootstrap \
|
-var vm_guestos=ubuntuserver22.04 \
|
||||||
-var repo_username=$${REPO_USERNAME} \
|
-var repo_username=$${REPO_USERNAME} \
|
||||||
-var repo_password=$${REPO_PASSWORD} \
|
-var repo_password=$${REPO_PASSWORD} \
|
||||||
-var vsphere_password=$${VSPHERE_PASSWORD} \
|
-var vsphere_password=$${VSPHERE_PASSWORD} \
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
# Packer.Images [](https://ci.spamasaurus.com/djpbessems/Packer.Images)
|
# Packer.Images [](https://ci.spamasaurus.com/djpbessems/Packer.Images)
|
||||||
|
|||||||
@@ -1,11 +1,7 @@
|
|||||||
---
|
---
|
||||||
- hosts: all
|
- hosts: all
|
||||||
gather_facts: false
|
gather_facts: false
|
||||||
vars_files:
|
|
||||||
- metacluster.yml
|
|
||||||
become: true
|
become: true
|
||||||
roles:
|
roles:
|
||||||
- os
|
- os
|
||||||
- firstboot
|
- firstboot
|
||||||
- appliance
|
|
||||||
- metacluster
|
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
collections:
|
|
||||||
- ansible.utils
|
|
||||||
- community.general
|
|
||||||
- kubernetes.core
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Initialize tempfolder
|
|
||||||
ansible.builtin.tempfile:
|
|
||||||
state: directory
|
|
||||||
register: archive
|
|
||||||
|
|
||||||
- name: Download & extract archived static binary
|
|
||||||
ansible.builtin.unarchive:
|
|
||||||
src: "{{ item.url }}"
|
|
||||||
dest: "{{ archive.path }}"
|
|
||||||
remote_src: yes
|
|
||||||
extra_opts: "{{ item.extra_opts | default(omit) }}"
|
|
||||||
|
|
||||||
- name: Install extracted binary
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: "{{ archive.path }}/{{ item.filename }}"
|
|
||||||
dest: /usr/local/bin/{{ item.filename }}
|
|
||||||
remote_src: yes
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0755
|
|
||||||
|
|
||||||
- name: Cleanup tempfolder
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ archive.path }}"
|
|
||||||
state: absent
|
|
||||||
when: archive.path is defined
|
|
||||||
@@ -1,46 +0,0 @@
|
|||||||
# - name: Create folder structure(s)
|
|
||||||
# ansible.builtin.file:
|
|
||||||
# path: "{{ item }}"
|
|
||||||
# state: directory
|
|
||||||
# loop:
|
|
||||||
# - /foo
|
|
||||||
|
|
||||||
- name: Download & install static binaries
|
|
||||||
ansible.builtin.get_url:
|
|
||||||
url: "{{ item.url }}"
|
|
||||||
dest: /usr/local/bin/{{ item.filename }}
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0755
|
|
||||||
loop: "{{ dependencies.static_binaries | selectattr('archive', 'undefined') }}"
|
|
||||||
loop_control:
|
|
||||||
label: "{{ item.filename }}"
|
|
||||||
|
|
||||||
- name: Download, extract & install archived static binaries
|
|
||||||
include_tasks: dependencies.archive_compressed.yml
|
|
||||||
loop: "{{ dependencies.static_binaries | rejectattr('archive', 'undefined') | selectattr('archive', 'equalto', 'compressed') }}"
|
|
||||||
loop_control:
|
|
||||||
label: "{{ item.filename }}"
|
|
||||||
|
|
||||||
- name: Install ansible-galaxy collections
|
|
||||||
ansible.builtin.shell:
|
|
||||||
cmd: ansible-galaxy collection install {{ item }}
|
|
||||||
loop: "{{ dependencies.ansible_galaxy_collections }}"
|
|
||||||
|
|
||||||
- name: Install distro packages
|
|
||||||
ansible.builtin.apt:
|
|
||||||
pkg: "{{ dependencies.packages }}"
|
|
||||||
state: latest
|
|
||||||
update_cache: yes
|
|
||||||
install_recommends: no
|
|
||||||
|
|
||||||
- name: Upgrade all packages
|
|
||||||
ansible.builtin.apt:
|
|
||||||
name: '*'
|
|
||||||
state: latest
|
|
||||||
update_cache: yes
|
|
||||||
|
|
||||||
- name: Cleanup apt cache
|
|
||||||
ansible.builtin.apt:
|
|
||||||
autoremove: yes
|
|
||||||
purge: yes
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
- name: Install & configure dependencies
|
|
||||||
import_tasks: dependencies.yml
|
|
||||||
@@ -7,6 +7,4 @@
|
|||||||
- vapp
|
- vapp
|
||||||
- network
|
- network
|
||||||
- users
|
- users
|
||||||
- disks
|
|
||||||
- metacluster
|
|
||||||
- cleanup
|
- cleanup
|
||||||
|
|||||||
@@ -1,24 +0,0 @@
|
|||||||
- name: Create volume group
|
|
||||||
community.general.lvg:
|
|
||||||
vg: longhorn_vg
|
|
||||||
pvs:
|
|
||||||
- /dev/sdb
|
|
||||||
pvresize: yes
|
|
||||||
|
|
||||||
- name: Create logical volume
|
|
||||||
community.general.lvol:
|
|
||||||
vg: longhorn_vg
|
|
||||||
lv: longhorn_lv
|
|
||||||
size: 100%VG
|
|
||||||
|
|
||||||
- name: Create filesystem
|
|
||||||
community.general.filesystem:
|
|
||||||
dev: /dev/mapper/longhorn_vg-longhorn_lv
|
|
||||||
fstype: ext4
|
|
||||||
|
|
||||||
- name: Mount dynamic disk
|
|
||||||
ansible.posix.mount:
|
|
||||||
path: /mnt/blockstorage
|
|
||||||
src: /dev/mapper/longhorn_vg-longhorn_lv
|
|
||||||
fstype: ext4
|
|
||||||
state: mounted
|
|
||||||
@@ -1,126 +0,0 @@
|
|||||||
- name: Install K3s
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: ./install.sh
|
|
||||||
chdir: /opt/metacluster/k3s
|
|
||||||
environment:
|
|
||||||
INSTALL_K3S_SKIP_DOWNLOAD: 'true'
|
|
||||||
INSTALL_K3S_EXEC: 'server --cluster-init --disable local-storage'
|
|
||||||
|
|
||||||
- name: Install kubectl tab-completion
|
|
||||||
ansible.builtin.shell:
|
|
||||||
cmd: kubectl completion bash | tee /etc/bash_completion.d/kubectl
|
|
||||||
|
|
||||||
- name: Ensure API availability
|
|
||||||
ansible.utils.cli_parse:
|
|
||||||
command: curl -k https://{{ vapp['guestinfo.ipaddress'] }}:6443/livez?verbose
|
|
||||||
parser:
|
|
||||||
name: ansible.utils.json
|
|
||||||
set_fact: api_readycheck
|
|
||||||
ignore_errors: yes
|
|
||||||
until: api_readycheck.apiVersion is defined
|
|
||||||
retries: 3
|
|
||||||
delay: 30
|
|
||||||
|
|
||||||
- block:
|
|
||||||
|
|
||||||
- name: Initialize tempfile
|
|
||||||
ansible.builtin.tempfile:
|
|
||||||
state: file
|
|
||||||
register: kubeconfig
|
|
||||||
|
|
||||||
- name: Retrieve kubeconfig
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: kubectl config view --raw
|
|
||||||
register: kubectl_config
|
|
||||||
|
|
||||||
- name: Store kubeconfig in tempfile
|
|
||||||
ansible.builtin.copy:
|
|
||||||
dest: "{{ kubeconfig.path }}"
|
|
||||||
content: "{{ kubectl_config.stdout }}"
|
|
||||||
mode: 0600
|
|
||||||
no_log: true
|
|
||||||
|
|
||||||
- block:
|
|
||||||
|
|
||||||
- name: Extract container images
|
|
||||||
ansible.builtin.unarchive:
|
|
||||||
src: /opt/metacluster/container-images/image-tarballs.tgz
|
|
||||||
dest: /opt/metacluster/container-images
|
|
||||||
list_files: yes
|
|
||||||
register: imagetarballs
|
|
||||||
|
|
||||||
- name: Import container images
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: k3s ctr image import {{ item }}
|
|
||||||
chdir: /opt/metacluster/container-images
|
|
||||||
loop: "{{ imagetarballs.files }}"
|
|
||||||
|
|
||||||
- name: Install longhorn chart
|
|
||||||
kubernetes.core.helm:
|
|
||||||
name: longhorn
|
|
||||||
chart_ref: /opt/metacluster/helm-charts/longhorn
|
|
||||||
release_namespace: longhorn-system
|
|
||||||
create_namespace: yes
|
|
||||||
wait: yes
|
|
||||||
kubeconfig: "{{ kubeconfig.path }}"
|
|
||||||
values:
|
|
||||||
defaultSettings:
|
|
||||||
defaultDataPath: /mnt/blockstorage
|
|
||||||
defaultReplicaCount: 1
|
|
||||||
ingress:
|
|
||||||
enabled: true
|
|
||||||
host: storage.{{ vapp['guestinfo.fqdn'] }}
|
|
||||||
persistence:
|
|
||||||
defaultClassReplicaCount: 1
|
|
||||||
|
|
||||||
- name: Install harbor chart
|
|
||||||
kubernetes.core.helm:
|
|
||||||
name: harbor
|
|
||||||
chart_ref: /opt/metacluster/helm-charts/harbor
|
|
||||||
release_namespace: harbor
|
|
||||||
create_namespace: yes
|
|
||||||
wait: yes
|
|
||||||
kubeconfig: "{{ kubeconfig.path }}"
|
|
||||||
values:
|
|
||||||
expose:
|
|
||||||
ingress:
|
|
||||||
hosts:
|
|
||||||
core: registry.{{ vapp['guestinfo.fqdn'] }}
|
|
||||||
externalURL: https://registry.{{ vapp['guestinfo.fqdn'] }}
|
|
||||||
harborAdminPassword: "{{ vapp['guestinfo.rootpw'] }}"
|
|
||||||
notary:
|
|
||||||
enabled: false
|
|
||||||
|
|
||||||
- name: Push images to registry
|
|
||||||
ansible.builtin.shell:
|
|
||||||
cmd: >-
|
|
||||||
skopeo copy \
|
|
||||||
--dest-tls-verify=false \
|
|
||||||
--dest-creds admin:{{ vapp['guestinfo.rootpw'] }} \
|
|
||||||
docker-archive:./{{ item }} \
|
|
||||||
docker://registry.{{ vapp['guestinfo.fqdn'] }}/library/$( \
|
|
||||||
k3s ctr run \
|
|
||||||
--rm \
|
|
||||||
--mount type=bind,src=$PWD,dst=/data,options=rbind:ro \
|
|
||||||
quay.io/skopeo/stable:v1.8.0 \
|
|
||||||
skopeo-{{ lookup('community.general.random_string', length=5) }} \
|
|
||||||
skopeo list-tags /data/{{ item }} | \
|
|
||||||
jq -r '.Tags[0]')
|
|
||||||
chdir: /opt/metacluster/container-images/
|
|
||||||
register: results
|
|
||||||
ignore_errors: yes
|
|
||||||
loop: "{{ imagetarballs.files }}"
|
|
||||||
|
|
||||||
- ansible.builtin.debug:
|
|
||||||
var: results
|
|
||||||
|
|
||||||
#- name: Delete container image tarballs/archives
|
|
||||||
# ansible.builtin.file:
|
|
||||||
# path: /opt/metacluster/container-images
|
|
||||||
# state: absent
|
|
||||||
|
|
||||||
- name: Cleanup tempfile
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ kubeconfig.path }}"
|
|
||||||
state: absent
|
|
||||||
when: kubeconfig.path is defined
|
|
||||||
@@ -1,12 +1,10 @@
|
|||||||
- name: Set hostname
|
- name: Set hostname
|
||||||
ansible.builtin.hostname:
|
ansible.builtin.hostname:
|
||||||
name: "{{ vapp['guestinfo.hostname'] }}"
|
name: "{{ ovfproperties['guestinfo.hostname'] }}"
|
||||||
|
|
||||||
- name: Create netplan configuration file
|
- name: Create netplan configuration file
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
src: netplan.j2
|
src: netplan.j2
|
||||||
dest: /etc/netplan/00-installer-config.yaml
|
dest: /etc/netplan/00-installer-config.yaml
|
||||||
|
|
||||||
- name: Apply netplan configuration
|
- name: Apply netplan configuration
|
||||||
ansible.builtin.shell:
|
ansible.builtin.shell:
|
||||||
cmd: /usr/sbin/netplan apply
|
cmd: /usr/sbin/netplan apply
|
||||||
|
|||||||
@@ -3,8 +3,8 @@ network:
|
|||||||
ethernets:
|
ethernets:
|
||||||
ens192:
|
ens192:
|
||||||
addresses:
|
addresses:
|
||||||
- {{ vapp['guestinfo.ipaddress'] }}/{{ vapp['guestinfo.prefixlength'] }}
|
- {{ ovfproperties['guestinfo.ipaddress'] }}/{{ ovfproperties['guestinfo.prefixlength'] }}
|
||||||
gateway4: {{ vapp['guestinfo.gateway'] }}
|
gateway4: {{ ovfproperties['guestinfo.gateway'] }}
|
||||||
nameservers:
|
nameservers:
|
||||||
addresses:
|
addresses:
|
||||||
- {{ vapp['guestinfo.dnsserver'] }}
|
- {{ ovfproperties['guestinfo.dnsserver'] }}
|
||||||
|
|||||||
@@ -1,14 +1,14 @@
|
|||||||
- name: Set root password
|
- name: Set root password
|
||||||
ansible.builtin.user:
|
ansible.builtin.user:
|
||||||
name: root
|
name: root
|
||||||
password: "{{ vapp['guestinfo.rootpw'] | password_hash('sha512', 65534 | random(seed=vapp['guestinfo.hostname']) | string) }}"
|
password: "{{ ovfproperties['guestinfo.rootpw'] | password_hash('sha512', 65534 | random(seed=ovfproperties['guestinfo.hostname']) | string) }}"
|
||||||
generate_ssh_key: yes
|
generate_ssh_key: yes
|
||||||
ssh_key_bits: 2048
|
ssh_key_bits: 2048
|
||||||
ssh_key_file: .ssh/id_rsa
|
ssh_key_file: .ssh/id_rsa
|
||||||
- name: Save root SSH publickey
|
- name: Save root SSH publickey
|
||||||
ansible.builtin.lineinfile:
|
ansible.builtin.lineinfile:
|
||||||
path: /root/.ssh/authorized_keys
|
path: /root/.ssh/authorized_keys
|
||||||
line: "{{ vapp['guestinfo.rootsshkey'] }}"
|
line: "{{ ovfproperties['guestinfo.rootsshkey'] }}"
|
||||||
- name: Disable SSH password authentication
|
- name: Disable SSH password authentication
|
||||||
ansible.builtin.lineinfile:
|
ansible.builtin.lineinfile:
|
||||||
path: /etc/ssh/sshd_config
|
path: /etc/ssh/sshd_config
|
||||||
|
|||||||
@@ -2,7 +2,6 @@
|
|||||||
ansible.builtin.shell:
|
ansible.builtin.shell:
|
||||||
cmd: /usr/bin/vmtoolsd --cmd "info-get guestinfo.ovfEnv"
|
cmd: /usr/bin/vmtoolsd --cmd "info-get guestinfo.ovfEnv"
|
||||||
register: ovfenv
|
register: ovfenv
|
||||||
|
|
||||||
- name: Parse XML for vApp properties
|
- name: Parse XML for vApp properties
|
||||||
community.general.xml:
|
community.general.xml:
|
||||||
xmlstring: "{{ ovfenv.stdout }}"
|
xmlstring: "{{ ovfenv.stdout }}"
|
||||||
@@ -11,11 +10,10 @@
|
|||||||
xpath: /ns:Environment/ns:PropertySection/ns:Property
|
xpath: /ns:Environment/ns:PropertySection/ns:Property
|
||||||
content: attribute
|
content: attribute
|
||||||
register: ovfenv
|
register: ovfenv
|
||||||
|
|
||||||
- name: Assign vApp properties to dictionary
|
- name: Assign vApp properties to dictionary
|
||||||
ansible.builtin.set_fact:
|
ansible.builtin.set_fact:
|
||||||
vapp: >-
|
ovfproperties: >-
|
||||||
{{ vapp | default({}) |
|
{{ ovfproperties | default({}) |
|
||||||
combine({((item.values() | list)[0].values() | list)[0]:
|
combine({((item.values() | list)[0].values() | list)[0]:
|
||||||
((item.values() | list)[0].values() | list)[1]})
|
((item.values() | list)[0].values() | list)[1]})
|
||||||
}}
|
}}
|
||||||
|
|||||||
@@ -2,7 +2,6 @@
|
|||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: /opt/firstboot
|
path: /opt/firstboot
|
||||||
state: directory
|
state: directory
|
||||||
|
|
||||||
- name: Create firstboot script file
|
- name: Create firstboot script file
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
src: firstboot.j2
|
src: firstboot.j2
|
||||||
@@ -10,13 +9,11 @@
|
|||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: o+x
|
mode: o+x
|
||||||
|
|
||||||
- name: Create @reboot crontab job
|
- name: Create @reboot crontab job
|
||||||
ansible.builtin.cron:
|
ansible.builtin.cron:
|
||||||
name: firstboot
|
name: firstboot
|
||||||
special_time: reboot
|
special_time: reboot
|
||||||
job: "/opt/firstboot/firstboot.sh >/dev/tty1 2>&1"
|
job: "/opt/firstboot/firstboot.sh"
|
||||||
|
|
||||||
- name: Copy payload folder
|
- name: Copy payload folder
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: ansible_payload/
|
src: ansible_payload/
|
||||||
@@ -24,3 +21,6 @@
|
|||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: '0644'
|
mode: '0644'
|
||||||
|
- name: Install ansible-galaxy collection
|
||||||
|
ansible.builtin.shell:
|
||||||
|
cmd: ansible-galaxy collection install community.general
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
# Apply firstboot configuration w/ ansible
|
# Apply firstboot configuration w/ ansible
|
||||||
/usr/local/bin/ansible-playbook /opt/firstboot/ansible/playbook.yml | tee -a /var/log/firstboot.log > /dev/tty1 2>&1
|
/usr/local/bin/ansible-playbook /opt/firstboot/ansible/playbook.yml | tee -a /var/log/firstboot.log > /dev/tty1
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
- name: Zero-out disk
|
|
||||||
ansible.builtin.shell:
|
|
||||||
cmd: dd bs=1M count=$(df -m . | awk '/[0-9]%/{print $(NF-2)}') if=/dev/zero of=./zero; sync; sync; rm -f ./zero
|
|
||||||
chdir: /opt/metacluster
|
|
||||||
@@ -1,46 +0,0 @@
|
|||||||
- name: Create folder structure(s)
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ item }}"
|
|
||||||
state: directory
|
|
||||||
loop:
|
|
||||||
- /opt/metacluster/helm-charts
|
|
||||||
- /opt/metacluster/container-images
|
|
||||||
|
|
||||||
#- name: Inject values (re: firstboot logic)
|
|
||||||
|
|
||||||
- name: Add helm repositories
|
|
||||||
kubernetes.core.helm_repository:
|
|
||||||
name: "{{ item.name }}"
|
|
||||||
repo_url: "{{ item.url }}"
|
|
||||||
state: present
|
|
||||||
loop: "{{ platform.helm_repositories }}"
|
|
||||||
|
|
||||||
- name: Fetch helm charts
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: helm fetch {{ item.value.helm.chart }} --untar --version {{ item.value.helm.version }}
|
|
||||||
chdir: /opt/metacluster/helm-charts
|
|
||||||
loop: "{{ lookup('ansible.builtin.dict', components) }}"
|
|
||||||
loop_control:
|
|
||||||
label: "{{ item.key }}"
|
|
||||||
|
|
||||||
- name: Parse helm charts for container images
|
|
||||||
ansible.builtin.shell:
|
|
||||||
cmd: "{{ item.value.helm.parse_logic }}"
|
|
||||||
chdir: /opt/metacluster/helm-charts/{{ item.key }}
|
|
||||||
register: containerimages
|
|
||||||
loop: "{{ lookup('ansible.builtin.dict', components) }}"
|
|
||||||
loop_control:
|
|
||||||
label: "{{ item.key }}"
|
|
||||||
|
|
||||||
- name: Pull and store containerimages
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: skopeo copy docker://{{ item }} docker-archive:./{{ ( item | regex_findall('[^/:]+'))[-2] }}.tar:{{ item }}
|
|
||||||
chdir: /opt/metacluster/container-images
|
|
||||||
loop: "{{ containerimages.results | map(attribute='stdout_lines') | flatten + dependencies.container_images}}"
|
|
||||||
|
|
||||||
- name: Compress tarballs
|
|
||||||
community.general.archive:
|
|
||||||
dest: /opt/metacluster/container-images/image-tarballs.tgz
|
|
||||||
path: /opt/metacluster/container-images/*
|
|
||||||
format: gz
|
|
||||||
remove: yes
|
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
- name: Create folder structure(s)
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ item }}"
|
|
||||||
state: directory
|
|
||||||
loop:
|
|
||||||
- /var/lib/rancher/k3s/agent/images
|
|
||||||
- /opt/metacluster/k3s
|
|
||||||
|
|
||||||
- name: Download & install K3s binary
|
|
||||||
ansible.builtin.get_url:
|
|
||||||
url: https://github.com/k3s-io/k3s/releases/download/{{ platform.k3s.version }}/k3s
|
|
||||||
dest: /usr/local/bin/k3s
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0755
|
|
||||||
|
|
||||||
- name: Download K3s images tarball
|
|
||||||
ansible.builtin.get_url:
|
|
||||||
url: https://github.com/k3s-io/k3s/releases/download/{{ platform.k3s.version }}/k3s-airgap-images-amd64.tar.gz
|
|
||||||
dest: /var/lib/rancher/k3s/agent/images
|
|
||||||
|
|
||||||
- name: Download K3s install script
|
|
||||||
ansible.builtin.get_url:
|
|
||||||
url: https://get.k3s.io
|
|
||||||
dest: /opt/metacluster/k3s/install.sh
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: 0755
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
- name: Pre-stage K3s components
|
|
||||||
import_tasks: k3s.yml
|
|
||||||
- name: Pre-stage meta components
|
|
||||||
import_tasks: components.yml
|
|
||||||
- name: Cleanup
|
|
||||||
import_tasks: cleanup.yml
|
|
||||||
@@ -1,13 +1,24 @@
|
|||||||
|
- name: Configure 'needrestart' package
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: /etc/needrestart/needrestart.conf
|
||||||
|
regexp: "{{ item.regexp }}"
|
||||||
|
line: "{{ item.line }}"
|
||||||
|
loop:
|
||||||
|
- regexp: "^#\\$nrconf\\{restart\\} = 'i';"
|
||||||
|
line: "$nrconf{restart} = 'a';"
|
||||||
|
- regexp: "^#\\$nrconf\\{kernelhints\\} = -1;"
|
||||||
|
line: "$nrconf{kernelhints} = -1;"
|
||||||
|
|
||||||
- name: Install additional packages
|
- name: Install additional packages
|
||||||
ansible.builtin.apt:
|
ansible.builtin.apt:
|
||||||
pkg: "{{ packages }}"
|
name: "{{ item }}"
|
||||||
state: latest
|
state: latest
|
||||||
update_cache: yes
|
update_cache: yes
|
||||||
install_recommends: no
|
loop: "{{ packages }}"
|
||||||
|
|
||||||
- name: Upgrade all packages
|
- name: Upgrade all packages
|
||||||
ansible.builtin.apt:
|
ansible.builtin.apt:
|
||||||
name: '*'
|
name: "*"
|
||||||
state: latest
|
state: latest
|
||||||
update_cache: yes
|
update_cache: yes
|
||||||
|
|
||||||
|
|||||||
@@ -1,63 +0,0 @@
|
|||||||
platform:
|
|
||||||
|
|
||||||
k3s:
|
|
||||||
version: v1.24.1+k3s1
|
|
||||||
|
|
||||||
helm_repositories:
|
|
||||||
- name: longhorn
|
|
||||||
url: https://charts.longhorn.io
|
|
||||||
- name: harbor
|
|
||||||
url: https://helm.goharbor.io
|
|
||||||
- name: gitea-charts
|
|
||||||
url: https://dl.gitea.io/charts/
|
|
||||||
- name: argo
|
|
||||||
url: https://argoproj.github.io/argo-helm
|
|
||||||
|
|
||||||
components:
|
|
||||||
|
|
||||||
longhorn:
|
|
||||||
helm:
|
|
||||||
version: 1.3.0
|
|
||||||
chart: longhorn/longhorn
|
|
||||||
parse_logic: cat values.yaml | yq eval '.. | select(has("repository")) | .repository + ":" + .tag'
|
|
||||||
|
|
||||||
harbor:
|
|
||||||
helm:
|
|
||||||
version: 1.9.1 # (= Harbor v2.5.1)
|
|
||||||
chart: harbor/harbor
|
|
||||||
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /'
|
|
||||||
|
|
||||||
gitea:
|
|
||||||
helm:
|
|
||||||
version: v5.0.9 # (= Gitea v1.16.8)
|
|
||||||
chart: gitea-charts/gitea
|
|
||||||
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | sed '/:/!s/$/:latest/'
|
|
||||||
|
|
||||||
argo-cd:
|
|
||||||
helm:
|
|
||||||
version: 4.9.7 # (= ArgoCD v2.4.2)
|
|
||||||
chart: argo/argo-cd
|
|
||||||
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /'
|
|
||||||
|
|
||||||
dependencies:
|
|
||||||
|
|
||||||
ansible_galaxy_collections:
|
|
||||||
- ansible.posix
|
|
||||||
- ansible.utils
|
|
||||||
- community.general
|
|
||||||
- kubernetes.core
|
|
||||||
|
|
||||||
container_images:
|
|
||||||
- quay.io/skopeo/stable:v1.8.0
|
|
||||||
|
|
||||||
static_binaries:
|
|
||||||
- filename: helm
|
|
||||||
url: https://get.helm.sh/helm-v3.9.0-linux-amd64.tar.gz
|
|
||||||
archive: compressed
|
|
||||||
extra_opts: --strip-components=1
|
|
||||||
- filename: yq
|
|
||||||
url: http://github.com/mikefarah/yq/releases/download/v4.25.3/yq_linux_amd64
|
|
||||||
|
|
||||||
packages:
|
|
||||||
- lvm2
|
|
||||||
- skopeo
|
|
||||||
@@ -3,7 +3,7 @@ packer {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
source "vsphere-iso" "k8sbootstrap" {
|
source "vsphere-iso" "ubuntuserver" {
|
||||||
vcenter_server = var.vcenter_server
|
vcenter_server = var.vcenter_server
|
||||||
username = var.vsphere_username
|
username = var.vsphere_username
|
||||||
password = var.vsphere_password
|
password = var.vsphere_password
|
||||||
@@ -41,7 +41,7 @@ source "vsphere-iso" "k8sbootstrap" {
|
|||||||
network_card = "vmxnet3"
|
network_card = "vmxnet3"
|
||||||
}
|
}
|
||||||
storage {
|
storage {
|
||||||
disk_size = 51200
|
disk_size = 20480
|
||||||
disk_thin_provisioned = true
|
disk_thin_provisioned = true
|
||||||
}
|
}
|
||||||
disk_controller_type = ["pvscsi"]
|
disk_controller_type = ["pvscsi"]
|
||||||
@@ -60,18 +60,18 @@ source "vsphere-iso" "k8sbootstrap" {
|
|||||||
|
|
||||||
export {
|
export {
|
||||||
images = false
|
images = false
|
||||||
output_directory = "/scratch/k8sbootstrap"
|
output_directory = "/scratch/ubuntuserver"
|
||||||
}
|
}
|
||||||
remove_cdrom = true
|
remove_cdrom = true
|
||||||
}
|
}
|
||||||
|
|
||||||
build {
|
build {
|
||||||
sources = [
|
sources = [
|
||||||
"source.vsphere-iso.k8sbootstrap"
|
"source.vsphere-iso.ubuntuserver"
|
||||||
]
|
]
|
||||||
|
|
||||||
provisioner "ansible" {
|
provisioner "ansible" {
|
||||||
pause_before = "2m30s"
|
only = ["vsphere-iso.ubuntuserver"]
|
||||||
|
|
||||||
playbook_file = "ansible/playbook.yml"
|
playbook_file = "ansible/playbook.yml"
|
||||||
user = "ubuntu"
|
user = "ubuntu"
|
||||||
@@ -85,15 +85,16 @@ build {
|
|||||||
}
|
}
|
||||||
|
|
||||||
post-processor "shell-local" {
|
post-processor "shell-local" {
|
||||||
|
only = ["vsphere-iso.ubuntuserver"]
|
||||||
inline = [
|
inline = [
|
||||||
"pwsh -command \"& scripts/Update-OvfConfiguration.ps1 \\",
|
"pwsh -command \"& scripts/Update-OvfConfiguration.ps1 \\",
|
||||||
" -OVFFile '/scratch/k8sbootstrap/${var.vm_guestos}-${var.vm_name}.ovf' \\",
|
" -OVFFile '/scratch/ubuntuserver/${var.vm_guestos}-${var.vm_name}.ovf' \\",
|
||||||
" -Parameter @{'appliance.name'='${var.vm_guestos}';'appliance.version'='${var.vm_name}'}\"",
|
" -Parameter @{'appliance.name'='${var.vm_guestos}';'appliance.version'='${var.vm_name}'}\"",
|
||||||
"pwsh -file scripts/Update-Manifest.ps1 \\",
|
"pwsh -file scripts/Update-Manifest.ps1 \\",
|
||||||
" -ManifestFileName '/scratch/k8sbootstrap/${var.vm_guestos}-${var.vm_name}.mf'",
|
" -ManifestFileName '/scratch/ubuntuserver/${var.vm_guestos}-${var.vm_name}.mf'",
|
||||||
"ovftool --acceptAllEulas --allowExtraConfig --overwrite \\",
|
"ovftool --acceptAllEulas --allowExtraConfig --overwrite \\",
|
||||||
" '/scratch/k8sbootstrap/${var.vm_guestos}-${var.vm_name}.ovf' \\",
|
" '/scratch/ubuntuserver/${var.vm_guestos}-${var.vm_name}.ovf' \\",
|
||||||
" /output/Kubernetes.Bootstrap.Appliance.ova"
|
" /output/Ubuntu-Server-22.04.ova"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -1,51 +1,28 @@
|
|||||||
DeploymentConfigurations:
|
DeploymentConfigurations:
|
||||||
|
|
||||||
- Id: small
|
- Id: small
|
||||||
Label: 'Ubuntu Server 22.04 [SMALL: 1 vCPU/2GB RAM]'
|
Label: 'Ubuntu Server 20.04 [SMALL: 1 vCPU/2GB RAM]'
|
||||||
Description: Ubuntu Server 22.04.x
|
Description: Ubuntu Server 20.04.x
|
||||||
Size:
|
Size:
|
||||||
CPU: 1
|
CPU: 1
|
||||||
Memory: 2048
|
Memory: 2048
|
||||||
|
- Id: large
|
||||||
- Id: medium
|
Label: 'Ubuntu Server 20.04 [LARGE: 4 vCPU/8GB RAM]'
|
||||||
Label: 'Ubuntu Server 22.04 [MEDIUM: 2 vCPU/4GB RAM]'
|
Description: Ubuntu Server 20.04.x
|
||||||
Description: Ubuntu Server 22.04.x
|
|
||||||
Size:
|
Size:
|
||||||
CPU: 2
|
CPU: 4
|
||||||
Memory: 4096
|
Memory: 8192
|
||||||
|
DynamicDisks: []
|
||||||
DynamicDisks:
|
|
||||||
|
|
||||||
- Description: Longhorn persistent storage
|
|
||||||
UnitSize: GB
|
|
||||||
Constraints:
|
|
||||||
Minium: 100
|
|
||||||
Maximum: ''
|
|
||||||
|
|
||||||
PropertyCategories:
|
PropertyCategories:
|
||||||
|
|
||||||
# - Name: 0) Deployment information
|
# - Name: 0) Deployment information
|
||||||
# ProductProperties:
|
# ProductProperties:
|
||||||
# - Key: deployment.type
|
# - Key: deployment.type
|
||||||
# Type: string
|
# Type: string
|
||||||
# Value:
|
# Value:
|
||||||
# - small
|
# - small
|
||||||
# - medium
|
# - large
|
||||||
# UserConfigurable: false
|
# UserConfigurable: false
|
||||||
|
- Name: 1) Operating System
|
||||||
- Name: 1) Kubernetes
|
|
||||||
ProductProperties:
|
ProductProperties:
|
||||||
- Key: guestinfo.fqdn
|
|
||||||
Type: string(1..)
|
|
||||||
Label: Appliance FQDN*
|
|
||||||
Description: 'Respective subdomains will be available for each component (e.g. storage.example.org); this address should already be configured as a wildcard record within your DNS zone.'
|
|
||||||
DefaultValue: 'example.org'
|
|
||||||
Configurations: '*'
|
|
||||||
UserConfigurable: true
|
|
||||||
|
|
||||||
- Name: 2) Operating System
|
|
||||||
ProductProperties:
|
|
||||||
|
|
||||||
- Key: guestinfo.hostname
|
- Key: guestinfo.hostname
|
||||||
Type: string(1..15)
|
Type: string(1..15)
|
||||||
Label: Hostname*
|
Label: Hostname*
|
||||||
@@ -53,7 +30,6 @@ PropertyCategories:
|
|||||||
DefaultValue: ''
|
DefaultValue: ''
|
||||||
Configurations: '*'
|
Configurations: '*'
|
||||||
UserConfigurable: true
|
UserConfigurable: true
|
||||||
|
|
||||||
- Key: guestinfo.rootpw
|
- Key: guestinfo.rootpw
|
||||||
Type: password(7..)
|
Type: password(7..)
|
||||||
Label: Local root password*
|
Label: Local root password*
|
||||||
@@ -61,7 +37,6 @@ PropertyCategories:
|
|||||||
DefaultValue: ''
|
DefaultValue: ''
|
||||||
Configurations: '*'
|
Configurations: '*'
|
||||||
UserConfigurable: true
|
UserConfigurable: true
|
||||||
|
|
||||||
- Key: guestinfo.rootsshkey
|
- Key: guestinfo.rootsshkey
|
||||||
Type: password(1..)
|
Type: password(1..)
|
||||||
Label: Local root SSH public key*
|
Label: Local root SSH public key*
|
||||||
@@ -69,42 +44,6 @@ PropertyCategories:
|
|||||||
DefaultValue: ''
|
DefaultValue: ''
|
||||||
Configurations: '*'
|
Configurations: '*'
|
||||||
UserConfigurable: true
|
UserConfigurable: true
|
||||||
|
|
||||||
- Name: 3) Networking
|
|
||||||
ProductProperties:
|
|
||||||
|
|
||||||
- Key: guestinfo.ipaddress
|
|
||||||
Type: ip
|
|
||||||
Label: IP Address*
|
|
||||||
Description: ''
|
|
||||||
DefaultValue: ''
|
|
||||||
Configurations: '*'
|
|
||||||
UserConfigurable: true
|
|
||||||
|
|
||||||
- Key: guestinfo.prefixlength
|
|
||||||
Type: int(8..32)
|
|
||||||
Label: Subnet prefix length*
|
|
||||||
Description: ''
|
|
||||||
DefaultValue: '24'
|
|
||||||
Configurations: '*'
|
|
||||||
UserConfigurable: true
|
|
||||||
|
|
||||||
- Key: guestinfo.dnsserver
|
|
||||||
Type: ip
|
|
||||||
Label: DNS server*
|
|
||||||
Description: ''
|
|
||||||
DefaultValue: ''
|
|
||||||
Configurations: '*'
|
|
||||||
UserConfigurable: true
|
|
||||||
|
|
||||||
- Key: guestinfo.gateway
|
|
||||||
Type: ip
|
|
||||||
Label: Gateway*
|
|
||||||
Description: ''
|
|
||||||
DefaultValue: ''
|
|
||||||
Configurations: '*'
|
|
||||||
UserConfigurable: true
|
|
||||||
|
|
||||||
- Key: guestinfo.ntpserver
|
- Key: guestinfo.ntpserver
|
||||||
Type: string(1..)
|
Type: string(1..)
|
||||||
Label: Time server*
|
Label: Time server*
|
||||||
@@ -112,7 +51,36 @@ PropertyCategories:
|
|||||||
DefaultValue: 0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org
|
DefaultValue: 0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org
|
||||||
Configurations: '*'
|
Configurations: '*'
|
||||||
UserConfigurable: true
|
UserConfigurable: true
|
||||||
|
- Name: 2) Networking
|
||||||
|
ProductProperties:
|
||||||
|
- Key: guestinfo.ipaddress
|
||||||
|
Type: ip
|
||||||
|
Label: IP Address*
|
||||||
|
Description: ''
|
||||||
|
DefaultValue: ''
|
||||||
|
Configurations: '*'
|
||||||
|
UserConfigurable: true
|
||||||
|
- Key: guestinfo.prefixlength
|
||||||
|
Type: int(8..32)
|
||||||
|
Label: Subnet prefix length*
|
||||||
|
Description: ''
|
||||||
|
DefaultValue: '24'
|
||||||
|
Configurations: '*'
|
||||||
|
UserConfigurable: true
|
||||||
|
- Key: guestinfo.dnsserver
|
||||||
|
Type: ip
|
||||||
|
Label: DNS server*
|
||||||
|
Description: ''
|
||||||
|
DefaultValue: ''
|
||||||
|
Configurations: '*'
|
||||||
|
UserConfigurable: true
|
||||||
|
- Key: guestinfo.gateway
|
||||||
|
Type: ip
|
||||||
|
Label: Gateway*
|
||||||
|
Description: ''
|
||||||
|
DefaultValue: ''
|
||||||
|
Configurations: '*'
|
||||||
|
UserConfigurable: true
|
||||||
AdvancedOptions:
|
AdvancedOptions:
|
||||||
- Key: appliance.name
|
- Key: appliance.name
|
||||||
Value: "{{ appliance.name }}"
|
Value: "{{ appliance.name }}"
|
||||||
|
|||||||
Reference in New Issue
Block a user