|
16 | 16 | nodeNetwork: 172.18.0.0/16 |
17 | 17 | podNetwork: 10.244.0.0/24 |
18 | 18 | serviceNetwork: 10.96.0.0/16 |
| 19 | + tags: gardener |
19 | 20 |
|
20 | | - - name: Create garden namespace |
21 | | - k8s: |
22 | | - definition: |
23 | | - apiVersion: v1 |
24 | | - kind: Namespace |
25 | | - metadata: |
26 | | - name: garden |
27 | | - |
28 | | - # our current state in metal-roles/gardener does not support network policies from gardenlet <-> virtual garden |
29 | | - # this should be possible to resolve when we use the Gardener Operator |
30 | | - - name: Deploy allow all network policy |
31 | | - k8s: |
32 | | - definition: "{{ lookup('file', 'netpol-allow-all.yaml') }}" |
33 | | - namespace: garden |
34 | | - apply: yes |
35 | 21 | roles: |
36 | 22 | - name: ansible-common |
37 | 23 | tags: always |
38 | 24 | - name: minio |
| 25 | + tags: minio |
39 | 26 | - name: powerdns |
40 | 27 | tags: powerdns |
41 | | - - name: metal-roles/control-plane/roles/gardener |
| 28 | + - name: metal-roles/control-plane/roles/gardener-operator |
| 29 | + tags: gardener |
| 30 | + - name: metal-roles/control-plane/roles/gardener-extensions |
| 31 | + tags: gardener |
| 32 | + - name: metal-roles/control-plane/roles/gardener-virtual-garden-access |
| 33 | + tags: gardener |
| 34 | + - name: metal-roles/control-plane/roles/gardener-cloud-profile |
| 35 | + tags: gardener |
| 36 | + - name: metal-roles/control-plane/roles/gardener-gardenlet |
42 | 37 | tags: gardener |
43 | 38 | vars: |
44 | 39 | metal_control_plane_host_provider: metal |
45 | 40 |
|
46 | 41 | post_tasks: |
47 | | - # gardener exposes the istio ingress gateway through service type load balancer |
48 | | - # we can fake the exposal by patching the status field, which is also what's |
49 | | - # done in the gardener local environment |
50 | | - - name: Wait for istio ingress gateway service |
51 | | - kubernetes.core.k8s_info: |
52 | | - api_version: v1 |
53 | | - kind: Service |
54 | | - name: istio-ingressgateway |
55 | | - namespace: istio-ingress |
56 | | - register: result |
57 | | - until: result.resources |
58 | | - retries: 30 |
59 | | - delay: 10 |
| 42 | + - name: Get kubeconfig for virtual garden access |
| 43 | + virtual_garden_kubeconfig: |
| 44 | + garden_name: "{{ metal_control_plane_stage_name }}" |
| 45 | + tags: gardener |
| 46 | + |
| 47 | + - name: Wait for Gardenlet to be reconciled |
| 48 | + kubernetes.core.k8s_info: |
| 49 | + api_version: seedmanagement.gardener.cloud/v1alpha1 |
| 50 | + kind: Gardenlet |
| 51 | + name: "local" |
| 52 | + namespace: garden |
| 53 | + kubeconfig: "{{ virtual_garden_kubeconfig }}" |
| 54 | + wait: yes |
| 55 | + wait_condition: |
| 56 | + reason: Reconciled |
| 57 | + status: "True" |
| 58 | + type: GardenletReconciled |
| 59 | + wait_timeout: 900 |
| 60 | + tags: gardener |
| 61 | + |
| 62 | + - name: Wait for istio ingress gateway service |
| 63 | + kubernetes.core.k8s_info: |
| 64 | + api_version: v1 |
| 65 | + kind: Service |
| 66 | + name: istio-ingressgateway |
| 67 | + namespace: istio-ingress |
| 68 | + register: result |
| 69 | + until: result.resources |
| 70 | + retries: 30 |
| 71 | + delay: 10 |
| 72 | + tags: gardener |
| 73 | + |
| 74 | + - name: Patch istio ingress gateway service status |
| 75 | + patch_service_status_k8s: |
| 76 | + name: istio-ingressgateway |
| 77 | + namespace: istio-ingress |
| 78 | + body: |
| 79 | + status: |
| 80 | + loadBalancer: |
| 81 | + ingress: |
| 82 | + - ip: "172.17.0.1" |
| 83 | + tags: gardener |
| 84 | + |
| 85 | + - name: Expose istio gateway through ingress-nginx (for local environments) |
| 86 | + k8s: |
| 87 | + definition: |
| 88 | + apiVersion: networking.k8s.io/v1 |
| 89 | + kind: Ingress |
| 90 | + metadata: |
| 91 | + annotations: |
| 92 | + nginx.ingress.kubernetes.io/ssl-passthrough: "true" |
| 93 | + name: apiserver-ingress |
| 94 | + namespace: istio-ingress |
| 95 | + spec: |
| 96 | + ingressClassName: nginx |
| 97 | + rules: |
| 98 | + - host: "{{ metal_control_plane_stage_name }}.{{ gardener_gardenlet_default_dns_domain }}" |
| 99 | + http: |
| 100 | + paths: |
| 101 | + - path: / |
| 102 | + pathType: Prefix |
| 103 | + backend: |
| 104 | + service: |
| 105 | + name: istio-ingressgateway |
| 106 | + port: |
| 107 | + number: 443 |
| 108 | + tls: |
| 109 | + - hosts: |
| 110 | + - "{{ metal_control_plane_stage_name }}.{{ gardener_gardenlet_default_dns_domain }}" |
| 111 | + tags: gardener |
60 | 112 |
|
61 | | - - name: Patch ingress status of istio ingress gateway to allow seed to get ready |
62 | | - patch_service_status_k8s: |
63 | | - name: istio-ingressgateway |
64 | | - namespace: istio-ingress |
65 | | - body: |
66 | | - status: |
67 | | - loadBalancer: |
68 | | - ingress: |
69 | | - - ip: "172.17.0.1" |
| 113 | + - name: Wait until Garden is ready |
| 114 | + kubernetes.core.k8s_info: |
| 115 | + api_version: "operator.gardener.cloud/v1alpha1" |
| 116 | + kind: Garden |
| 117 | + name: "{{ metal_control_plane_stage_name }}" |
| 118 | + wait: yes |
| 119 | + wait_condition: |
| 120 | + status: "True" |
| 121 | + type: "{{ item }}" |
| 122 | + wait_timeout: 300 |
| 123 | + loop: |
| 124 | + - VirtualComponentsHealthy |
| 125 | + - RuntimeComponentsHealthy |
| 126 | + tags: gardener |
70 | 127 |
|
71 | | - - name: Wait until seed is ready |
72 | | - kubernetes.core.k8s_info: |
73 | | - api_version: "core.gardener.cloud/v1beta1" |
74 | | - kind: Seed |
75 | | - name: "{{ metal_control_plane_stage_name }}" |
76 | | - kubeconfig: "{{ gardener_kube_apiserver_kubeconfig_path }}" |
77 | | - wait: yes |
78 | | - wait_condition: |
79 | | - reason: GardenletReady |
80 | | - status: "True" |
81 | | - type: GardenletReady |
82 | | - wait_timeout: 300 |
| 128 | + - name: Wait until seed is ready |
| 129 | + kubernetes.core.k8s_info: |
| 130 | + api_version: "core.gardener.cloud/v1beta1" |
| 131 | + kind: Seed |
| 132 | + name: "{{ metal_control_plane_stage_name }}" |
| 133 | + kubeconfig: "{{ virtual_garden_kubeconfig }}" |
| 134 | + wait: yes |
| 135 | + wait_condition: |
| 136 | + reason: GardenletReady |
| 137 | + status: "True" |
| 138 | + type: GardenletReady |
| 139 | + wait_timeout: 300 |
| 140 | + tags: gardener |
0 commit comments