summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2017-10-10Force reconciliation of role for 3.6Simo Sorce
This is needed because in 3.6 we cannot reconcile non-cluster roles in the bootstrap reconciliation code. In 3.7 this is taken care of in code. Signed-off-by: Simo Sorce <simo@redhat.com>
2017-10-10GlusterFS: Fix registry storage documentationJose A. Rivera
Signed-off-by: Jose A. Rivera <jarrpa@redhat.com>
2017-10-10Remove etcd health checkScott Dodson
2017-10-10Merge pull request #5585 from nak3/bz#1496593OpenShift Merge Robot
Automatic merge from submit-queue. Add valid search when search does not exist on resolv.conf Current fix https://github.com/openshift/openshift-ansible/pull/5433 still misses to add `search cluster.local`. The logic needs to be: 1. When `search` does not exist, adds `search cluster.local`. 2. When `search.*.cluster.local` does not exist, adds(sed) `cluster.local`. in this order. cc @sdodson @caruccio
2017-10-10Merge pull request #5711 from ↵Scott Dodson
giuseppe/docker-crio-expect-openshiftrelease-with-v crio, docker: expect openshift_release to have 'v'
2017-10-10Merge pull request #5713 from mtnbikenc/fix-inventoryScott Dodson
Fix typo in inventory example
2017-10-10Fix typo in inventory exampleRussell Teague
2017-10-10Better credentials for GCP (#791)Peter Schiffer
* Updated GCE dynamic inventory script * Migrate from depreciated secrets.py to recommended yaml files * It's better to not use spaces in gce.ini
2017-10-10Separate tuned daemon setup into a role.Jiri Mencak
Currently, profiles for the tuned daemon are set only for OpenShift node(s). This excludes the OpenShift loadbalancer. As a result, ARP cache limits on loadbalancers are not raised. This causes problems with HA setups where loadbalancers serve 1k+ OpenShift nodes. This commit ensures the openshift-control-plane role is applied to loadbalancers, masters and OpenShift infra nodes. Regular OpenShift worker nodes get the openshift-node profile. Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1498213
2017-10-10crio, docker: expect openshift_release to have 'v'Giuseppe Scrivano
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-10Automatic commit of package [openshift-ansible] release [3.7.0-0.147.0].Jenkins CD Merge Bot
Created by command: /usr/bin/tito tag --debug --accept-auto-changelog --keep-version --debug
2017-10-09Added server_hostname as a parameter rhsm_hostname (#792)Chandler Wilkerson
2017-10-09Merge pull request #5695 from giuseppe/image_tag_default_to_releaseOpenShift Merge Robot
Automatic merge from submit-queue. docker, CRI-O: openshift_image_tag defaults to openshift_release Replace: commit c2c4ba7ec62d4dfd87d746d20991e10f2bd1bddf Author: Giuseppe Scrivano <gscrivan@redhat.com> Date: Tue Sep 26 09:01:59 2017 +0200 Require openshift_image_tag in the inventory with openshift-enterprise Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com> with using openshift_release for openshift_image_tag so we don't require users to include both in their inventory. Probably it is only a temporary solution until the openshift_image_tag vs openshift_release when using Docker/CRI-O is sorted out. Closes: https://bugzilla.redhat.com/show_bug.cgi?id=1493376
2017-10-09Merge pull request #5698 from abutcher/servinginfo-client-caOpenShift Merge Robot
Automatic merge from submit-queue. Bug 1493276: Setting servingInfo.clientCA to ca-bundle.crt can cause unwanted client cert popups in browser when hitting console https://bugzilla.redhat.com/show_bug.cgi?id=1493276
2017-10-09Merge pull request #5368 from jianlinliu/bz1490738Scott Dodson
Update registry_config.j2 to fix BZ#1490738
2017-10-09Merge pull request #5705 from mgugino-upstream-stage/docker-partof-iptablesScott Dodson
Add PartOf to docker systemd service unit.
2017-10-09Merge pull request #5699 from giuseppe/crio-use-systemdOpenShift Merge Robot
Automatic merge from submit-queue. crio: use systemd manager fix a regression introduced last week. Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-09Add PartOf to docker systemd service unit.Michael Gugino
Currently, if iptables service is restarted, existing iptables rules are removed. Docker adds iptables rules dyanmically upon startup and container creation. Restarting the iptables service results in a loss of these needed iptables rules. This commit ensures that if iptables service is restarted by anisble or the user, docker is also restarted. This ensures the proper dynamic iptables rules are in place for docker. Fixes: openshift/origin#16709
2017-10-09Automatic commit of package [openshift-ansible] release [3.7.0-0.146.0].Jenkins CD Merge Bot
Created by command: /usr/bin/tito tag --debug --accept-auto-changelog --keep-version --debug
2017-10-09Merge pull request #5650 from mgugino-upstream-stage/skopeo-auth-credsOpenShift Merge Robot
Automatic merge from submit-queue. Add authentication credentials to skopeo for image check Currently, docker_image_availability health_check does not support authenticated registries. This commit adds the '--creds=' option to skopeo if needed to support authentication credentials. Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1316341
2017-10-09crio: use systemd managerGiuseppe Scrivano
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-09Merge pull request #5682 from tbielawa/openshift_managementScott Dodson
Rename openshift_cfme role to openshift_management
2017-10-09Ensure servingInfo.clientCA is set as ca.crt rather than ca-bundle.crt.Andrew Butcher
2017-10-09Automatic commit of package [openshift-ansible] release [3.7.0-0.145.0].Jenkins CD Merge Bot
Created by command: /usr/bin/tito tag --debug --accept-auto-changelog --keep-version --debug
2017-10-09Merge pull request #5696 from ingvagabund/add-missing-handler-to-flannelJan Chaloupka
add missing restart node handler to flannel
2017-10-09add missing restart node handler to flannelJan Chaloupka
2017-10-09crio, docker: use openshift_release when openshift_image_tag is not usedGiuseppe Scrivano
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-09crio: fix typoGiuseppe Scrivano
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-09Add CentOS support to the docker-storage-setup roleTomas Sedovic
This let's us use the role on CentOS systems, as well as RHEL. In addition, it installs docker and makes sure it's restarted (as opposed to just "started" which has no effect when docker is already running).
2017-10-07Merge pull request #5684 from enj/enj/i/configmap_lockOpenShift Merge Robot
Automatic merge from submit-queue. Switch to configmap leader election on 3.7 upgrade This change sets the controllerConfig.election.lockName to openshift-master-controllers on a 3.7 upgrade. This is the default in a new 3.7 cluster. Important excerpt from the docs inside the origin codebase (slightly modified): There are two modes for lease operation - a legacy mode that directly connects to etcd, and the preferred mode which coordinates on a configmap or endpoint in the kube-system namespace. Because legacy mode and the new mode do not coordinate on the same key, an upgrade must stop all controllers before changing the configuration and starting controllers with the new config. Signed-off-by: Monis Khan <mkhan@redhat.com> /assign @smarterclayton @jupierce /kind bug
2017-10-07Merge pull request #5661 from giuseppe/crio-use-overlay-instead-of-overlay2OpenShift Merge Robot
Automatic merge from submit-queue. cri-o: use overlay instead of overlay2 overlay2 and overlay are the same driver. Upstream CRI-O is going to drop any reference to overlay2 and use only overlay. Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-07Merge pull request #787 from glennswest/masterGlenn S West
add a proper $GITURL to bastion.sh and rework add_node.sh to use it
2017-10-06docker_image_availability: credentials to skopeoMichael Gugino
Currently, docker_image_availability health_check does not support authenticated registries. This commit adds the '--creds=' option to skopeo if needed to support authentication credentials. Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1316341 Some other fixes to handle docker config better: Should now account properly for blocked registries, insecure registries, multiple additional registries, and oreg_url registry with or without credentials. Output on failure should be clearer about what was tried. Fixed a bug in the action_plugin_test exposed by these changes.
2017-10-06Merge pull request #776 from tomassedovic/dynamic-inventorytzumainn
Add dynamic inventory
2017-10-06Merge pull request #5680 from ↵OpenShift Merge Robot
mgugino-upstream-stage/ensure-docker-restarts-with-iptables Automatic merge from submit-queue. Ensure docker is restarted when iptables is restarted Currently, os_firewall role may run after docker role, and iptables.service may be restarted. When restarted, this negatively impacts docker's iptables rules. This commit ensures that if iptables is restarted, docker is restarted as well (by systemd) Fixes: https://github.com/openshift/origin/issues/16709
2017-10-06Rename openshift_cfme role to openshift_managementTim Bielawa
2017-10-06Switch to configmap leader election on 3.7 upgradeMonis Khan
This change sets the controllerConfig.election.lockName to openshift-master-controllers on a 3.7 upgrade. This is the default in a new 3.7 cluster. Important excerpt from the docs inside the origin codebase (slightly modified): There are two modes for lease operation - a legacy mode that directly connects to etcd, and the preferred mode which coordinates on a configmap or endpoint in the kube-system namespace. Because legacy mode and the new mode do not coordinate on the same key, an upgrade must stop all controllers before changing the configuration and starting controllers with the new config. Signed-off-by: Monis Khan <mkhan@redhat.com>
2017-10-06Adjusting logic on rhsm_user (#784)Chandler Wilkerson
2017-10-06Merge pull request #786 from openshift/test-openstack-latest-openshift-ansibletzumainn
Switch to the latest openshift-ansible for Openstack CI
2017-10-06crio.conf.j2: sync from upstreamGiuseppe Scrivano
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-06cri-o: use overlay instead of overlay2Giuseppe Scrivano
overlay2 and overlay are the same driver. Upstream CRI-O is going to drop any reference to overlay2 and use only overlay. Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2017-10-06migrate embedded etcd to external etcdJan Chaloupka
2017-10-06change public_hosted_zone to dns_zoneDavis Phillips
2017-10-06Ensure docker is restarted when iptables is restartedMichael Gugino
Currently, os_firewall role may run after docker role, and iptables.service may be restarted. When restarted, this negatively impacts docker's iptables rules. This commit ensures that if iptables is restarted, docker is restarted as well (by systemd) Fixes: https://github.com/openshift/origin/issues/16709
2017-10-06Merge pull request #5660 from sdodson/one-exampleScott Dodson
Stop including origin and ose hosts example file
2017-10-06Stop including origin and ose hosts example fileScott Dodson
It's a pain keeping these two in sync so just mention the differences as necessary.
2017-10-06rebase on masterAdam Miller
Signed-off-by: Adam Miller <maxamillion@fedoraproject.org>
2017-10-06Add fedora compatibilityAdam Miller
- don't check pkg versions on Fedora, it won't work; they move faster than RHEL and it's not realistic to maintain that package list. - handle differences between yum and dnf pkgspec for excluder - work-around for a bug in dnf https://bugzilla.redhat.com/show_bug.cgi?id=1199432 - make requirement verify one play, don't run unnecessary checks on Fedora
2017-10-06Merge branch 'master' of https://github.com/openshift/openshift-ansible-contribglennswest
Merge upstream commits
2017-10-06Revert to production repoglennswest