feat: moderate the k8s install
- only install a base config - wait for 3 masters before deploying helm charts - remove nginx and rancher-ingres configurations
This commit is contained in:
parent
a9c959d924
commit
5123147aa0
@ -1 +1 @@
|
||||
rke2::node_token: ENC[PKCS7,MIIB2gYJKoZIhvcNAQcDoIIByzCCAccCAQAxggEhMIIBHQIBADAFMAACAQEwDQYJKoZIhvcNAQEBBQAEggEAPRBcsDJv/SDR4pOi4fBWzU2ayCXW8BaATzpg3h8mHsVPcHwhfL9w9d4BIshM5yzSZwfmj8EBMk6sa4vEcBRN5r5vWDETnjwsvtLULvyiPm5WVYAYe+Z/fzoCUqswWvXrU/yzoMd/oUYFOrtCB0wT4bZX2leg64CQ7DZIf4wZod0Z9EH7YwUpL4mmbLWY29w0Z3F702O8v0hp9J7IWX5A5ob8OLaTy9SmApZEtm35UDz+OAaJ1OZ9yc2pWTkVZ0dSgMvouynJWToZ/k0ZwoW5I32WLeZ6mkYODwXF1ULqVTX3eX/c9HlVilHJar9TlcY46+8ypV3Uoju8j6c86DaRtjCBnAYJKoZIhvcNAQcBMB0GCWCGSAFlAwQBKgQQe3h1bWn1G2HYEwupc7n3EoBwzcA4ICV4efMd1n4d1CW+wlBAoa5T8lXSluf09vajUQmaFhl3pl99v3uc5M38ePPd5QkzoZPfb4kLcmuufGNfwbIXpaQQ+nwQATOX1UG5SOEovshvWnW0iF5JrgIa+MLed9WF48NMbvZZLbwyBe7hrQ==]
|
||||
rke2::node_token: ENC[PKCS7,MIIB2gYJKoZIhvcNAQcDoIIByzCCAccCAQAxggEhMIIBHQIBADAFMAACAQEwDQYJKoZIhvcNAQEBBQAEggEAEn4S30har6RkJrG2gjwkqQd2GtVF/2r7+0xay3hQJahcInzum5guLDRAdyQrxUzqqzYQ4gzIg09JIW5dbyQVR+t+T5dmw3HybY2q8rIOE/osHVhkFONsm+uqot09WT4fB1x0zk2nIHqpnN/QiLQsQCJoUldxY3rdq/Av3VGMrpZfPAH6yGe6sieBqsJGfSWeDwsxD9m0mE1sQykiigsOUdKXWW8qw4eOxLwQ5qNqpflKJ0CV2aOj/61k2nXnjtAqYB4cHjqsDKQbjXxn/L3cqSesheT7HJrsDQf4msMxtDntzP/eQUZDGMTgEP6RwA37lphrJgA+oTY1clpF9HUK1DCBnAYJKoZIhvcNAQcBMB0GCWCGSAFlAwQBKgQQCn5FYZUy3Cv87mk6nDAPt4BwZVeSmOtkXPs7XurdJiIYJiZrYPZwPZBQXQD0wAF9gOM9i1YpylQx5M4r/dTBoRsck5bgCBtgcJk97ROQxbRQsXB/Zt2dWkvLwNtOZvU62+qxsrTsySCZFX8gTh3DLGtKrtLWwh45ChnNgqzP0OXkQQ==]
|
||||
|
||||
@ -28,7 +28,7 @@ rke2::csi_ceph_templates:
|
||||
- ceph-csi-secret
|
||||
rke2::extra_config_files:
|
||||
- rke2-canal-config
|
||||
- service-loadbalancer-nginx
|
||||
# - service-loadbalancer-nginx
|
||||
rke2::config_hash:
|
||||
advertise-address: "%{hiera('networking_loopback0_ip')}"
|
||||
cluster-domain: "svc.k8s.unkin.net"
|
||||
|
||||
39
modules/rke2/lib/facter/k8s_masters.rb
Normal file
39
modules/rke2/lib/facter/k8s_masters.rb
Normal file
@ -0,0 +1,39 @@
|
||||
# frozen_string_literal: true
|
||||
|
||||
require 'json'
|
||||
require 'open3'
|
||||
|
||||
Facter.add(:k8s_masters) do
|
||||
confine do
|
||||
File.exist?('/etc/rancher/rke2/rke2.yaml') &&
|
||||
File.executable?('/usr/bin/kubectl')
|
||||
end
|
||||
|
||||
setcode do
|
||||
env = { 'KUBECONFIG' => '/etc/rancher/rke2/rke2.yaml' }
|
||||
cmd = ['/usr/bin/kubectl', 'get', 'nodes', '-o', 'json']
|
||||
|
||||
stdout, stderr, status = Open3.capture3(env, *cmd)
|
||||
|
||||
if status.success?
|
||||
json = JSON.parse(stdout)
|
||||
|
||||
master_count = json['items'].count do |item|
|
||||
roles = item.dig('metadata', 'labels') || {}
|
||||
|
||||
# Look for well-known labels assigned to control-plane nodes
|
||||
roles.any? do |key, _|
|
||||
key =~ %r{node-role\.kubernetes\.io/(control-plane|master|etcd)}
|
||||
end
|
||||
end
|
||||
|
||||
master_count
|
||||
else
|
||||
Facter.debug("kubectl error: #{stderr}")
|
||||
0
|
||||
end
|
||||
rescue StandardError => e
|
||||
Facter.debug("Exception in k8s_masters fact: #{e.message}")
|
||||
0
|
||||
end
|
||||
end
|
||||
@ -24,9 +24,7 @@ class rke2::config (
|
||||
token => $node_token,
|
||||
} )
|
||||
}else{
|
||||
$config = merge($config_hash, {
|
||||
token => $node_token,
|
||||
} )
|
||||
$config = merge($config_hash, {})
|
||||
}
|
||||
} elsif $node_type == 'agent' {
|
||||
$config = merge($config_hash, {
|
||||
@ -75,7 +73,7 @@ class rke2::config (
|
||||
}
|
||||
|
||||
# on the controller nodes only
|
||||
if $node_type == 'server' {
|
||||
if $node_type == 'server' and $facts['k8s_masters'] and $facts['k8s_masters'] > 2 {
|
||||
|
||||
# wait for purelb helm to setup namespace
|
||||
if 'purelb' in $facts['k8s_namespaces'] {
|
||||
@ -89,17 +87,17 @@ class rke2::config (
|
||||
}
|
||||
}
|
||||
|
||||
# wait for rancher helm to setup namespace
|
||||
if 'cattle-system' in $facts['k8s_namespaces'] {
|
||||
file {'/var/lib/rancher/rke2/server/manifests/ingress-route-rancher.yaml':
|
||||
ensure => file,
|
||||
owner => 'root',
|
||||
group => 'root',
|
||||
mode => '0644',
|
||||
source => 'puppet:///modules/rke2/ingress-route-rancher.yaml',
|
||||
require => Service['rke2-server'],
|
||||
}
|
||||
}
|
||||
## wait for rancher helm to setup namespace
|
||||
#if 'cattle-system' in $facts['k8s_namespaces'] {
|
||||
# file {'/var/lib/rancher/rke2/server/manifests/ingress-route-rancher.yaml':
|
||||
# ensure => file,
|
||||
# owner => 'root',
|
||||
# group => 'root',
|
||||
# mode => '0644',
|
||||
# source => 'puppet:///modules/rke2/ingress-route-rancher.yaml',
|
||||
# require => Service['rke2-server'],
|
||||
# }
|
||||
#}
|
||||
|
||||
# manage extra config config (these are not dependent on helm)
|
||||
$extra_config_files.each |$file| {
|
||||
|
||||
@ -20,8 +20,8 @@ class rke2::helm (
|
||||
mode => '0755',
|
||||
}
|
||||
|
||||
# on the controller nodes only
|
||||
if $node_type == 'server' {
|
||||
# on the controller nodes only, and after 3 master nodes exist
|
||||
if $node_type == 'server' and $facts['k8s_masters'] and $facts['k8s_masters'] > 2 {
|
||||
|
||||
# check if the repo already exists
|
||||
$helm_repos.each | String $repo, Stdlib::HTTPSUrl $url | {
|
||||
|
||||
Loading…
Reference in New Issue
Block a user