5 Commits

Author SHA1 Message Date
5740faeb9d feat: Add cli binary
All checks were successful
Container & Helm chart / Linting (push) Successful in 7s
Container & Helm chart / Semantic Release (Dry-run) (push) Successful in 1m9s
Container & Helm chart / Kubernetes Bootstrap Appliance (push) Successful in 34m49s
2024-06-15 19:48:17 +10:00
e057f313ea chore: Ensure api availability 2024-06-15 19:47:44 +10:00
ac38731dcf chore: Configure argo workflows permissions
All checks were successful
Container & Helm chart / Linting (push) Successful in 1m35s
Container & Helm chart / Semantic Release (Dry-run) (push) Successful in 2m15s
Container & Helm chart / Kubernetes Bootstrap Appliance (push) Successful in 32m49s
2024-06-14 12:32:06 +10:00
9cbb84a0f3 chore: Remove redundant node template injection task
All checks were successful
Container & Helm chart / Linting (push) Successful in 6s
Container & Helm chart / Semantic Release (Dry-run) (push) Successful in 1m12s
Container & Helm chart / Kubernetes Bootstrap Appliance (push) Successful in 31m55s
2024-06-12 22:10:38 +10:00
066ec9a967 chore: Remove redundant kustomize patch 2024-06-12 22:10:16 +10:00
8 changed files with 105 additions and 39 deletions

View File

@ -29,4 +29,3 @@
- import_tasks: manifests.yml - import_tasks: manifests.yml
- import_tasks: kubeadm.yml - import_tasks: kubeadm.yml
- import_tasks: containerimages.yml - import_tasks: containerimages.yml
- import_tasks: nodetemplates.yml

View File

@ -1,4 +0,0 @@
- name: Download node-template image
ansible.builtin.uri:
url: "{{ components.clusterapi.workload.node_template.url }}"
dest: /opt/workloadcluster/node-templates/{{ components.clusterapi.workload.node_template.url | basename}}

View File

@ -10,6 +10,23 @@
# - argo-workflows # - argo-workflows
- firstboot - firstboot
- name: Create ClusterRoleBinding for default serviceaccount
kubernetes.core.k8s:
state: present
kubeconfig: "{{ kubeconfig.path }}"
definition: |
kind: ClusterRoleBinding
metadata:
name: argo-workflows-firstboot-clusteradmin
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: default
namespace: firstboot
- name: Install argo-workflows chart - name: Install argo-workflows chart
kubernetes.core.helm: kubernetes.core.helm:
name: argo-workflows name: argo-workflows
@ -20,8 +37,15 @@
kubeconfig: "{{ kubeconfig.path }}" kubeconfig: "{{ kubeconfig.path }}"
values: "{{ components['argo-workflows'].chart_values }}" values: "{{ components['argo-workflows'].chart_values }}"
# - name: Trigger handlers - name: Ensure argo workflows API availability
# ansible.builtin.meta: flush_handlers ansible.builtin.uri:
url: https://workflow.{{ vapp['metacluster.fqdn'] }}/api/v1/version
method: GET
register: api_readycheck
until:
- api_readycheck.json.version is defined
retries: "{{ playbook.retries }}"
delay: "{{ (storage_benchmark | int) * (playbook.delay.long | int) }}"
module_defaults: module_defaults:
ansible.builtin.uri: ansible.builtin.uri:

View File

@ -172,7 +172,7 @@
- name: Generate nodepool kustomization manifest - name: Generate nodepool kustomization manifest
ansible.builtin.template: ansible.builtin.template:
src: kustomization.nodepool.j2 src: kustomization.longhorn-storage.j2
dest: "{{ capi_clustermanifest.path }}/kustomization.yaml" dest: "{{ capi_clustermanifest.path }}/kustomization.yaml"
vars: vars:
_template: _template:

View File

@ -4,34 +4,6 @@ resources:
- cluster-template.yaml - cluster-template.yaml
patches: patches:
- patch: |-
apiVersion: v1
kind: Secret
metadata:
name: csi-vsphere-config
namespace: '${NAMESPACE}'
stringData:
data: |
apiVersion: v1
kind: Secret
metadata:
name: csi-vsphere-config
namespace: kube-system
stringData:
csi-vsphere.conf: |+
[Global]
insecure-flag = true
thumbprint = "${VSPHERE_TLS_THUMBPRINT}"
cluster-id = "${NAMESPACE}/${CLUSTER_NAME}"
[VirtualCenter "${VSPHERE_SERVER}"]
user = "${VSPHERE_USERNAME}"
password = "${VSPHERE_PASSWORD}"
datacenters = "${VSPHERE_DATACENTER}"
[Network]
public-network = "${VSPHERE_NETWORK}"
type: Opaque
- patch: |- - patch: |-
apiVersion: controlplane.cluster.x-k8s.io/v1beta1 apiVersion: controlplane.cluster.x-k8s.io/v1beta1
kind: KubeadmControlPlane kind: KubeadmControlPlane
@ -95,6 +67,7 @@ patches:
spec: spec:
template: template:
spec: spec:
diskGiB: 60
network: network:
devices: devices:
- dhcp4: false - dhcp4: false
@ -114,6 +87,7 @@ patches:
spec: spec:
template: template:
spec: spec:
diskGiB: 60
network: network:
devices: devices:
- dhcp4: false - dhcp4: false
@ -125,6 +99,25 @@ patches:
- {{ _template.network.dnsserver }} - {{ _template.network.dnsserver }}
networkName: '${VSPHERE_NETWORK}' networkName: '${VSPHERE_NETWORK}'
- target:
group: addons.cluster.x-k8s.io
version: v1beta1
kind: ClusterResourceSet
name: \${CLUSTER_NAME}-crs-0
patch: |-
- op: replace
path: /spec/resources
value:
- kind: Secret
name: cloud-controller-manager
- kind: Secret
name: cloud-provider-vsphere-credentials
- kind: ConfigMap
name: cpi-manifests
- op: add
path: /spec/strategy
value: Reconcile
- target: - target:
group: controlplane.cluster.x-k8s.io group: controlplane.cluster.x-k8s.io
version: v1beta1 version: v1beta1
@ -198,6 +191,8 @@ patches:
- op: replace - op: replace
path: /metadata/name path: /metadata/name
value: ${CLUSTER_NAME}-master value: ${CLUSTER_NAME}-master
- op: remove
path: /spec/template/spec/thumbprint
- target: - target:
group: controlplane.cluster.x-k8s.io group: controlplane.cluster.x-k8s.io
version: v1beta1 version: v1beta1
@ -237,6 +232,8 @@ patches:
- op: replace - op: replace
path: /spec/template/spec/memoryMiB path: /spec/template/spec/memoryMiB
value: {{ _template.nodesize.memory }} value: {{ _template.nodesize.memory }}
- op: remove
path: /spec/template/spec/thumbprint
- target: - target:
group: cluster.x-k8s.io group: cluster.x-k8s.io
version: v1beta1 version: v1beta1
@ -258,3 +255,12 @@ patches:
- op: replace - op: replace
path: /metadata/name path: /metadata/name
value: ${CLUSTER_NAME}-worker value: ${CLUSTER_NAME}-worker
- target:
group: infrastructure.cluster.x-k8s.io
version: v1beta1
kind: VSphereCluster
name: .*
patch: |-
- op: remove
path: /spec/thumbprint

View File

@ -58,6 +58,7 @@ components:
argo-cd: argo-cd:
helm: helm:
# Must match the version referenced at `dependencies.static_binaries[.filename==argo].url`
version: 6.7.7 # (=Argo CD v2.10.5) version: 6.7.7 # (=Argo CD v2.10.5)
chart: argo/argo-cd chart: argo/argo-cd
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /' parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /'
@ -85,11 +86,19 @@ components:
chart: argo/argo-workflows chart: argo/argo-workflows
parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /' parse_logic: helm template . | yq --no-doc eval '.. | .image? | select(.)' | sort -u | awk '!/ /'
chart_values: !unsafe | chart_values: !unsafe |
# workflow:
# serviceAccount:
# create: true
# name: "argo-workflows"
# rbac:
# create: true
controller: controller:
workflowNamespaces: workflowNamespaces:
- default - default
- firstboot - firstboot
server: server:
authModes:
- server
ingress: ingress:
enabled: true enabled: true
hosts: hosts:
@ -122,8 +131,8 @@ components:
calico: v3.27.3 calico: v3.27.3
k8s: v1.30.1 k8s: v1.30.1
node_template: node_template:
# url: https://{{ repo_username }}:{{ repo_password }}@sn.itch.fyi/Repository/rel/ubuntu-2204-kube-v1.27.1.ova # Not used anymore; should be uploaded to hypervisor manually!
url: https://github.com/kubernetes-sigs/cluster-api-provider-vsphere/releases/download/templates%2Fv1.30.0/ubuntu-2204-kube-v1.30.0.ova # https://github.com/kubernetes-sigs/cluster-api-provider-vsphere/releases/download/templates%2Fv1.30.0/
dex: dex:
helm: helm:
@ -355,6 +364,8 @@ dependencies:
- registry.k8s.io/sig-storage/livenessprobe:v2.10.0 - registry.k8s.io/sig-storage/livenessprobe:v2.10.0
static_binaries: static_binaries:
- filename: argo
url: https://github.com/argoproj/argo-workflows/releases/download/v3.5.7/argo-linux-amd64.gz
- filename: clusterctl - filename: clusterctl
url: https://github.com/kubernetes-sigs/cluster-api/releases/download/v1.6.3/clusterctl-linux-amd64 url: https://github.com/kubernetes-sigs/cluster-api/releases/download/v1.6.3/clusterctl-linux-amd64
- filename: govc - filename: govc

View File

@ -5,12 +5,42 @@
- vars/pb.secrets.yaml - vars/pb.secrets.yaml
tasks: tasks:
- name: Retrieve target folder details
community.vmware.vmware_vm_info:
hostname: "{{ hv.hostname }}"
username: "{{ hv.username }}"
password: "{{ secrets.hv.password }}"
folder: "{{ hv.folder }}"
validate_certs: false
register: vm_info
- name: User prompt
ansible.builtin.pause:
prompt: Virtual machine '{{ appliance.id }}' already exists. Delete to continue [yes] or abort [no]?"
register: prompt
until:
- prompt.user_input in ['yes', 'no']
delay: 0
when: (vm_info | selectattr('guest_name', 'equalto', appliance.id) | length) > 0
- name: Destroy existing VM
community.vmware.vmware_guest:
hostname: "{{ hv.hostname }}"
username: "{{ hv.username }}"
password: "{{ secrets.hv.password }}"
folder: "{{ hv.folder }}"
name: appliance.id
state: absent
when:
- (vm_info | selectattr('guest_name', 'equalto', appliance.id) | length) > 0
- (prompt.user_input | bool) == true
- name: Deploy VM from OVA-template - name: Deploy VM from OVA-template
community.vmware.vmware_deploy_ovf: community.vmware.vmware_deploy_ovf:
hostname: "{{ hv.hostname }}" hostname: "{{ hv.hostname }}"
username: "{{ hv.username }}" username: "{{ hv.username }}"
password: "{{ secrets.hv.password }}" password: "{{ secrets.hv.password }}"
validate_certs: no validate_certs: false
datacenter: "{{ hv.datacenter }}" datacenter: "{{ hv.datacenter }}"
folder: "{{ hv.folder }}" folder: "{{ hv.folder }}"
cluster: "{{ hv.cluster }}" cluster: "{{ hv.cluster }}"