summaryrefslogtreecommitdiff
path: root/roles
AgeCommit message (Collapse)Author
2017-07-19During provisioning, make unnecessary packages optional under a switch (#561)Tlacenka
* openshift-prep: bash-completion and vim-enhanced packages are now optional under install_debug_packages switch * openshift-prep: new line removal
2017-07-17Add a role to generate a static inventory (#540)Bogdan Dobrelya
* Add the static-inventory role that configures the inventory/hosts file by the given path, or creates it for you. Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-07-17Retry tasks in the subscription manager role (#552)Tlacenka
* subscription manager: added 10 retries after 1 second delay * subscription manager: added untils * sub manager: typo
2017-07-14Set up NetworkManager automatically (#542)Tomas Sedovic
* Set up NetworkManager automatically This removes the extra step of running the `openshift-ansible/playbooks/byo/openshift-node/network_manager.yml` before installing openshift. In addition, the playbook relies on a host group that the provisioning doesn't provide (oo_all_hosts). Instead, we set up NetworkManager on CentOS nodes automatically. And we restart it on RHEL (which is necessary for the nodes to pick up the new DNS we configured the subnet with). This makes the provisioning easier and more resilient. * Apply the node-network-manager role to every node It makes the code simpler and more consistent across distros.
2017-07-13Replace greaterthan and equalto in openstack-stackTomas Sedovic
These two Jinja filters were added in 2.8 which is notably not packaged in CentOS and RHEL. This removes them in favour of the `==` and `>` operators which are available in Jinja 2.7.
2017-07-12Add defaults values for some openstack vars (#539)Tomas Sedovic
* Add defaults values for some openstack vars Ansible shows errors when the `rhsm_register` and `openstack_flat_secgrp` values are not present in the inventory even though they have sensible default values. This makes them both default to false when they're not specified. * Comment out the flat security group option in inv It's no longer required to be there so let's comment it out.
2017-06-30Merge pull request #525 from bogdando/manage_packagesTomas Sedovic
Manage packages to install/update for openstack provider
2017-06-30Persist DNS configuration for nodes for openstack providerBogdan Dobrelya
* Firstly, provision a Heat stack with given public resolvers. * After the DNS node configured as an authoritative server, switch the Heat stack's Neutron subnet to that resolver (private_dns_server) the way it to become the first entry pushed into the hosts /etc/resolv.conf. It will be serving the cluster domain requests for OpenShift nodes and workloads. * Drop post-provision /etc/reslov.conf nameserver hacks as not needed anymore. * Fix dns floating IPs output and add the priv IPs output as well. * Update docs, clarify localhost vs servers requirements, add required Network Manager setup step. * Use post-provision task names instead of comments. Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-30Manage packages to install/update for openstack providerBogdan Dobrelya
Allow required packages and yum update all steps to be optionally disabled. Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-28Merge pull request #502 from bogdando/sec_groupsTomas Sedovic
Modify sec groups for provisioned openstack servers
2017-06-28Merge pull request #512 from bogdando/undo_infra_secgrpTomas Sedovic
Put back node/flat secgrp for infra nodes on openstack
2017-06-28Put back node/flat secgrp for infra nodes on openstackBogdan Dobrelya
Partially undo 2028883e936c8a1a0be031a19d531d0804a32b68 to unblock end-to-end deployments Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-26Merge pull request #491 from tzumainn/openstack-heat-stack-updateTomas Sedovic
Add node_removal_policies variable to openstack provisioning to allow for scaling down
2017-06-26Modify sec groups for provisioned openstack serversBogdan Dobrelya
Drop ingress DNS rules from the common secgrp. Add an ingress ICMP rule, restricted by the ssh ingress cidr, to the common secgrp. This allows to ping servers from the control node (ansible admin node). Add dns servers into the common secgrp as well. Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-23rename node_removal_policies, add some comments and defaultsTzu-Mainn Chen
2017-06-23Merge pull request #488 from bogdando/fix_flat_sgBogdan Dobrelya
Fix flat sec group and infra/dns sec rules
2017-06-23Fix flat sec group and infra/dns sec rulesBogdan Dobrelya
Make flat sec group to only merge node/master/etcd sec rules. Add basic dns/ssh sec group and assign it to all but dns node groups. Assign only dns sec group for dns nodes. Assign only infra (and basic) sec groups for ingra nodes. Add security notes for openstack provider. Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-21Add node_removal_policies variable to allow for scaling downTzu-Mainn Chen
2017-06-21Use cached facts, do not become for localhost (#484)Bogdan Dobrelya
Prohibit sudoing for localhost played tasks, like DNS setup. Re-use cached facts to speed up deployment. Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-16Fix yamllint errorsTomas Sedovic
2017-06-15Drop atomic-openshift-utils, update docs for originBogdan Dobrelya
TODO use with when: ansible_distribution == 'CentOS' Also update docs for origin Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-15Add a flat sec group for openstack providerBogdan Dobrelya
Add a openstack_flat_secgroup, defaults to False. When set, merges sec rules for master, node, etcd, infra nodes into a single group. Less secure, but might help to mitigate quota limitations. Update docs. Use timeout 30s to mitigate the error: Timeout (12s) waiting for privilege escalation prompt. Signed-off-by: Bogdan Dobrelya <bdobreli@redhat.com>
2017-06-15Always let the openshift nodes access the DNSTomas Sedovic
When `node_ingress_cidr` to limit the IP range for the DNS server, this can prevent the actual openshift nodes from accessing it as well. This commit makes the access from the `openstack_subnet_prefix` always pass through and uses `node_ingress_cidr` for additional access control.
2017-06-14Move pre_tasks from to the openstack provisionerTomas Sedovic
We should probably not pollute the role namespace with a name as common as "common". Moving the pre_task.yml to provisioners/openstack instead.
2017-06-14Merge redhat-cop/casl-ansible into openstack-providerTomas Sedovic
This imports the openstack provisioning bits of: https://github.com/redhat-cop/casl-ansible taking care to preserve the original history of those files.
2017-06-13Update CASL to use nsupdate for DNS records (#48)Øystein Bedin
* Updated to use nsupdate for DNS records * Updated formatting of dict * Updating descriptive text * Support for external DNS config * Upgrading jinja2 to work correctly with latest templates * Latest update for nsupdate * Updated to use nsupdate for DNS records * Updated formatting of dict * Updating descriptive text * Support for external DNS config * Latest update for nsupdate * Updated to support external public/private DNS server(s) * Updated DNS server handling * Updated DNS server handling * Updated DNS server handling * Eliminated the from the sample inventories * Updated sample inventory to point to 2 separate DNS servers for private/public * Playbook clean-up * Adding 'python-dns' * splitting subscription manager calls to allow for a clean pre-install playbook
2017-06-05Conditionally set the openshift_master_default_subdomain to avoid overriding ↵Øystein Bedin
it unecessary (#47)
2017-05-18More ansible migration and deploy OCP from local workstation (#376)Peter Schiffer
* Create registry bucket with deployment manager * Migrate ssh proxy to Ansible * Update gce dynamic inventory script, use instance name for ssh * Fix variable name in docker storage setup role * Deploy OCP from local workstation, and not from the bastion host
2017-05-16Removed hardcoded values from ansible rolesEduardo Minguez Perez
2017-04-27First attempt at a simple multi-master support (#39)Eric Sauer
* First attempt at a simple multi-master support * Removing unneeded inventory * adding default number of masters and lower number of nodes
2017-04-25Stack refactor (#38)Eric Sauer
* Refactored openstack-stack role to: - Convert static heat template files to ansible templates - Include native ansible groups via openstack metadata. This removes the need for a playbook to map host groups - Some code cleanup * Deleting commentd out code and irrelevant plays * Refactored openstack-stack role to: - Convert static heat template files to ansible templates - Include native ansible groups via openstack metadata. This removes the need for a playbook to map host groups - Some code cleanup * Deleting commentd out code and irrelevant plays * Replacing stack parameters with jinja expressions * Updating sample inventory to work with latest dynamic inventory changes * updating inventory with host group mapping. making sync keys optional * Missing cluster_hosts group * Updating to add infra_hosts * Updating inventory per comments from oybed and sabre1041
2017-02-20Ensure DNS configuration has wildcards set for infra nodes (#24)Øystein Bedin
* Ensure DNS configuration has wildcards set for infra nodes * Updated to include all cluster hosts for DNS entries
2017-02-06Fixing two significant bugs in the HEAT deployment (#13)Eric Sauer
2017-01-26update for yamllint errorsJason DeTiberus
2017-01-13Making providers common (#126)Ryan Cook
* Making providers common * moving directory locations * using links and removal of vars file callout * rename of file * went block crazy * cleanup * add to remove * missing Pyyaml package in README * let docker actually setup docker storage and start the service * name change * Fix for vmware. Will variablize in the future * catchup to test common providers against master * should only be schedulable nodes
2016-12-21Openstack heat (#2)Eric Sauer
* Adding a role to invoke openstack heat * Adding readme * Pulling parameters out to inventory file * start of end-to-end playbook * More enhancements and refactoring to make dynamic inventory the driver for an openshift install * Switching to variable substituted path to config.yaml playbook * Changes to allow defining of number of nodes/infranodes. * Added labels to inventory * Start of end-to-end functionality * Enhancements to support openstack heat provisioning * Updating inventory sample to remove some deprecation warnings * Working towards making the secure-registry role 'become' aware * Fixing node labels and removing secure-registry as it's no longer needed * No longer need insecure registry line, as installer will secure our registry * Adjusted dynamic inventory to filter by clusterid * Minor updates to dynamic inventory bug * Adding a refactored sample inventory directory * Refactoring playbooks for better directory structure, and to narrow down host groups * Adding volume mounts to heat template * Moving dns playbooks back to original location * Fixing incorrect file path * Cleaning up inventory samples * One more hostname to clean up * Changing var name * changed openshift-provision to openshift-prep * Adjusting current provision script to avoid breakage by new openstack-heat code
2016-11-15Fixing ansible impl to work with OSP9 and ansible 2.2Øystein Bedin
2016-08-21Updated env_id to be a sub-domain + make the logic a bit more flexibleØystein Bedin
2016-07-15Fixes Issue #163 if rhsm_password is not definedVinny Valdez
2016-06-21Merge pull request #157 from vvaldez/satellite-with-orgEric Sauer
Add org parameter to Satellite with user/pass
2016-06-17Cleande up hostname role to make it more genericØystein Bedin
2016-06-09Updated to run as root rather than cloud-user, for now...Øystein Bedin
2016-06-08Channging hard coded host groups to match openshift-ansible expected host ↵Eric Sauer
groups. Importing byo playbook now instead of nested ansible run. Need to refactor how we generate hostnames to make it fit this.
2016-06-03Subscription manager role should accomodate orgs with spacesEric Sauer
2016-06-03Reverting previous commit and making template adjustmentsEric Sauer
2016-06-03Changes to allow runs from inside a container. Also allows for running ↵Eric Sauer
upstream openshift-ansible installer
2016-05-13Changes by JayKayy for a full provision of OpenShift on OpenStackEric Sauer
2016-04-27Fix typo in task nameVinny Valdez
2016-04-23Add org parameter to Satellite with user/passVinny Valdez
2016-04-20Remove vars_prompt, add info to README to re-enable and for ansible-vaultVinny Valdez