diff options
Diffstat (limited to 'playbooks/aws')
| -rw-r--r-- | playbooks/aws/README.md | 235 | ||||
| -rwxr-xr-x | playbooks/aws/openshift-cluster/accept.yml | 19 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/build_ami.yml | 143 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/build_node_group.yml | 48 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/install.yml | 74 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/provision.yml | 165 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/provision_install.yml | 16 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/provision_nodes.yml | 64 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/provisioning_vars.example.yml | 26 | ||||
| -rw-r--r-- | playbooks/aws/openshift-cluster/vars.yml | 116 | 
10 files changed, 272 insertions, 634 deletions
| diff --git a/playbooks/aws/README.md b/playbooks/aws/README.md index 4b0f444ba..c2da4b632 100644 --- a/playbooks/aws/README.md +++ b/playbooks/aws/README.md @@ -32,127 +32,52 @@ Before any provisioning may occur, AWS account credentials must be present in th  ### Let's Provision!  The newly added playbooks are the following: -- build_ami.yml -- provision.yml -- provision_nodes.yml +- build_ami.yml - Builds a custom AMI.  This currently requires the user to supply a valid AMI with access to repositories that contain openshift repositories. +- provision.yml - Create a vpc, elbs, security groups, launch config, asg's, etc. +- install.yml - Calls the openshift-ansible installer on the newly created instances +- provision_nodes.yml - Creates the infra and compute node scale groups +- accept.yml - This is a playbook to accept infra and compute nodes into the cluster +- provision_install.yml - This is a combination of all 3 of the above playbooks. (provision, install, and provision_nodes as well as accept.yml) -The current expected work flow should be to provide the `vars.yml` file with the -desired settings for cluster instances.  These settings are AWS specific and should -be tailored to the consumer's AWS custom account settings. +The current expected work flow should be to provide an AMI with access to Openshift repositories.  There should be a repository specified in the `openshift_additional_repos` parameter of the inventory file. The next expectation is a minimal set of values in the `provisioning_vars.yml` file to configure the desired settings for cluster instances.  These settings are AWS specific and should be tailored to the consumer's AWS custom account settings.  ```yaml -clusterid: mycluster -region: us-east-1 - -provision: -  clusterid: "{{ clusterid }}" -  region: "{{ region }}" - -  build: -    ami_name: "openshift-gi-" -    base_image: ami-bdd5d6ab # base image for AMI to build from - -    # when creating an encrypted AMI please specify use_encryption -    use_encryption: False - -  # for s3 registry backend -  openshift_registry_s3: True - -  # whether to use custome ami for each node type -  use_custom_ami: False - -  # if using custom certificates these are required for the ELB -  iam_cert_ca: -    name: test_openshift -    cert_path: '/path/to/wildcard.<clusterid>.example.com.crt' -    key_path: '/path/to/wildcard.<clusterid>.example.com.key' -    chain_path: '/path/to/cert.ca.crt' - -  instance_users: -  - key_name: myuser_key -    username: myuser -    pub_key: | -           ssh-rsa aaa<place public ssh key here>aaaaa user@<clusterid> - -  node_group_config: -    tags: -      clusterid: "{{ clusterid }}" -      environment: stg -    ssh_key_name: myuser_key # name of the ssh key from above - -    # configure master settings here -    master: -      instance_type: m4.xlarge -      ami: ami-cdeec8b6 # if using an encrypted AMI this will be replaced -      volumes: -      - device_name: /dev/sdb -        volume_size: 100 -        device_type: gp2 -        delete_on_termination: False -      health_check: -        period: 60 -        type: EC2 -      # Set the following number to be the same for masters. -      min_size: 3 -      max_size: 3 -      desired_size: 3 -      tags: -        host-type: master -        sub-host-type: default -      wait_for_instances: True -... -  vpc: -    # name: mycluster  # If missing; will default to clusterid -    cidr: 172.31.0.0/16 -    subnets: -      us-east-1:  # These are us-east-1 region defaults. Ensure this matches your region -      - cidr: 172.31.48.0/20 -        az: "us-east-1c" -      - cidr: 172.31.32.0/20 -        az: "us-east-1e" -      - cidr: 172.31.16.0/20 -        az: "us-east-1a" +--- +openshift_node_bootstrap: True -``` +# specify a clusterid +# openshift_aws_clusterid: default -Repeat the following setup for the infra and compute node groups.  This most likely - will not need editing but if the install requires further customization then these parameters - can be updated. +# specify a region +# openshift_aws_region: us-east-1 -#### Step 1 +# must specify a base_ami when building an AMI +# openshift_aws_base_ami: # base image for AMI to build from +# specify when using a custom AMI +# openshift_aws_ami: -Once the vars.yml file has been updated with the correct settings for the desired AWS account then we are ready to build an AMI. +# when creating an encrypted AMI please specify use_encryption +# openshift_aws_ami_encrypt: False -``` -$ ansible-playbook build_ami.yml -``` +# custom certificates are required for the ELB +# openshift_aws_iam_cert_path: '/path/to/cert/wildcard.<clusterid>.<domain>.com.crt' +# openshift_aws_iam_cert_key_path: '/path/to/key/wildcard.<clusterid>.<domain>.com.key' +# openshift_aws_iam_cert_chain_path: '/path/to/ca_cert_file/ca.crt' -1. This script will build a VPC. Default name will be clusterid if not specified. -2. Create an ssh key required for the instance. -3. Create a security group. -4. Create an instance. -5. Run some setup roles to ensure packages and services are correctly configured. -6. Create the AMI. -7. If encryption is desired -  - A KMS key is created with the name of $clusterid -  - An encrypted AMI will be produced with $clusterid KMS key -8. Terminate the instance used to configure the AMI. - -#### Step 2 +# This is required for any ec2 instances +# openshift_aws_ssh_key_name: myuser_key -Now that we have created an AMI for our Openshift installation, that AMI id needs to be placed in the `vars.yml` file.  To do so update the following fields (The AMI can be captured from the output of the previous step or found in the ec2 console under AMIs): - -``` -  # when creating an encrypted AMI please specify use_encryption -  use_encryption: False # defaults to false +# This will ensure these users are created +#openshift_aws_users: +#- key_name: myuser_key +#  username: myuser +#  pub_key: | +#         ssh-rsa AAAA  ``` -**Note**: If using encryption, specify with `use_encryption: True`.  This will ensure to take the recently created AMI and encrypt it to be used later.  If encryption is not desired then set the value to false. The AMI id will be fetched and used according to its most recent creation date. +If customization is required for the instances, scale groups, or any other configurable option please see the ['openshift_aws/defaults/main.yml'](../../roles/openshift_aws/defaults/main.yml) for variables and overrides. These overrides can be placed in the `provisioning_vars.yml`, `inventory`, or `group_vars`. -#### Step 3 - ->>>>>>> Fixing variables and allowing custom ami. -Create an openshift-ansible inventory file to use for a byo installation.  The exception here is that there will be no hosts specified by the inventory file.  Here is an example: +In order to create the bootstrap-able AMI we need to create an openshift-ansible inventory file.  This file enables us to create the AMI using the openshift-ansible node roles. The exception here is that there will be no hosts specified by the inventory file.  Here is an example:  ```ini  [OSEv3:children] @@ -169,6 +94,8 @@ etcd  ################################################################################  # Ensure these variables are set for bootstrap  ################################################################################ +# openshift_deployment_type is required for installation +openshift_deployment_type=origin  openshift_master_bootstrap_enabled=True  openshift_hosted_router_wait=False @@ -189,77 +116,94 @@ openshift_additional_repos=[{'name': 'openshift-repo', 'id': 'openshift-repo',  There are more examples of cluster inventory settings [`here`](../../inventory/byo/). -In order to create the bootstrapable AMI we need to create an openshift-ansible inventory file.  This file enables us to create the AMI using the openshift-ansible node roles. - - -#### Step 2 +#### Step 1 -Once the vars.yml file has been updated with the correct settings for the desired AWS account then we are ready to build an AMI. +Once the `inventory` and the `provisioning_vars.yml` file has been updated with the correct settings for the desired AWS account then we are ready to build an AMI.  ``` -$ ansible-playbook -i inventory.yml build_ami.yml +$ ansible-playbook -i inventory.yml build_ami.yml -e @provisioning_vars.yml  ```  1. This script will build a VPC. Default name will be clusterid if not specified.  2. Create an ssh key required for the instance. -3. Create an instance. -4. Run some setup roles to ensure packages and services are correctly configured. -5. Create the AMI. -6. If encryption is desired +3. Create a security group. +4. Create an instance using the key from step 2 or a specified key. +5. Run openshift-ansible setup roles to ensure packages and services are correctly configured. +6. Create the AMI. +7. If encryption is desired    - A KMS key is created with the name of $clusterid    - An encrypted AMI will be produced with $clusterid KMS key -7. Terminate the instance used to configure the AMI. +8. Terminate the instance used to configure the AMI. +More AMI specific options can be found in ['openshift_aws/defaults/main.yml'](../../roles/openshift_aws/defaults/main.yml).  When creating an encrypted AMI please specify use_encryption: +``` +# openshift_aws_ami_encrypt: True  # defaults to false +``` -#### Step 3 +**Note**:  This will ensure to take the recently created AMI and encrypt it to be used later.  If encryption is not desired then set the value to false (defaults to false). The AMI id will be fetched and used according to its most recent creation date. + +#### Step 2 -Now that we have created an AMI for our Openshift installation, that AMI id needs to be placed in the `vars.yml` file.  To do so update the following fields (The AMI can be captured from the output of the previous step or found in the ec2 console under AMIs): +Now that we have created an AMI for our Openshift installation, there are two ways to use the AMI. +1. In the default behavior, the AMI id will be found and used in the last created fashion. +2. The `openshift_aws_ami` option can be specified.  This will allow the user to override the behavior of the role and use a custom AMI specified in the `openshift_aws_ami` variable. + +We are now ready to provision and install the cluster.  This can be accomplished by calling all of the following steps at once or one-by-one.  The all in one can be called like this:  ``` -  # when creating an encrypted AMI please specify use_encryption -  use_encryption: False # defaults to false +$ ansible-playbook -i inventory.yml provision_install.yml -e @provisioning_vars.yml  ``` -**Note**: If using encryption, specify with `use_encryption: True`.  This will ensure to take the recently created AMI and encrypt it to be used later.  If encryption is not desired then set the value to false. The AMI id will be fetched and used according to its most recent creation date. - +If this is the first time running through this process, please attempt the following steps one-by-one and ensure the setup works correctly. -#### Step 4 +#### Step 3 -We are ready to create the master instances and install Openshift. +We are ready to create the master instances.  ``` -$ ansible-playbook -i <inventory from step 1> provision.yml +$ ansible-playbook provision.yml -e @provisioning_vars.yml  ```  This playbook runs through the following steps: -1. Ensures a VPC is created -2. Ensures a SSH key exists -3. Creates an s3 bucket for the registry named $clusterid -4. Create master security groups -5. Create a master launch config -6. Create the master auto scaling groups -7. If certificates are desired for ELB, they will be uploaded -8. Create internal and external master ELBs -9. Add newly created masters to the correct groups -10. Set a couple of important facts for the masters -11. Run the [`byo`](../../common/openshift-cluster/config.yml) +1. Ensures a VPC is created. +2. Ensures a SSH key exists. +3. Creates an s3 bucket for the registry named $clusterid-docker-registry +4. Create master security groups. +5. Create a master launch config. +6. Create the master auto scaling groups. +7. If certificates are desired for ELB, they will be uploaded. +8. Create internal and external master ELBs. +9. Add newly created masters to the correct groups. +10. Set a couple of important facts for the masters. + +At this point we have successfully created the infrastructure including the master nodes. + +#### Step 4 -At this point we have created a successful cluster with only the master nodes. +Now it is time to install Openshift using the openshift-ansible installer.  This can be achieved by running the following playbook: +``` +$ ansible-playbook -i inventory.yml install.yml @provisioning_vars.yml +``` +This playbook accomplishes the following: +1. Builds a dynamic inventory file by querying AWS. +2. Runs the [`byo`](../../common/openshift-cluster/config.yml) + +Once this playbook completes, the cluster masters should be installed and configured.  #### Step 5 -Now that we have a cluster deployed it might be more interesting to create some node types.  This can be done easily with the following playbook: +Now that we have a cluster deployed it will be more interesting to create some node types.  This can be done easily with the following playbook:  ``` -$ ansible-playbook provision_nodes.yml +$ ansible-playbook provision_nodes.yml -e @provisioning_vars.yml  ```  Once this playbook completes, it should create the compute and infra node scale groups.  These nodes will attempt to register themselves to the cluster.  These requests must be approved by an administrator.  #### Step 6 -The registration of our nodes can be automated by running the following script `accept.yml`.  This script can handle the registration in a few different ways. +To facilitate the node registration process, nodes may be registered by running the following script `accept.yml`.  This script can register in a few different ways.  - approve_all - **Note**: this option is for development and test environments.  Security is bypassed  - nodes - A list of node names that will be accepted into the cluster @@ -269,10 +213,11 @@ The registration of our nodes can be automated by running the following script `     nodes: < list of nodes here >     timeout: 0  ``` +  Once the desired accept method is chosen, run the following playbook `accept.yml`:  1. Run the following playbook.  ``` -$ ansible-playbook accept.yml +$ ansible-playbook accept.yml -e @provisioning_vars.yml  ```  Login to a master and run the following command: @@ -299,6 +244,6 @@ ip-172-31-49-148.ec2.internal   Ready                      1h       v1.6.1+5115d  At this point your cluster should be ready for workloads.  Proceed to deploy applications on your cluster. -### Still to compute +### Still to come  There are more enhancements that are arriving for provisioning.  These will include more playbooks that enhance the provisioning capabilities. diff --git a/playbooks/aws/openshift-cluster/accept.yml b/playbooks/aws/openshift-cluster/accept.yml index d43c84205..ffc367f9f 100755 --- a/playbooks/aws/openshift-cluster/accept.yml +++ b/playbooks/aws/openshift-cluster/accept.yml @@ -1,12 +1,17 @@ +#!/usr/bin/ansible-playbook  ---  - name: Setup the vpc and the master node group -  #hosts: oo_first_master    hosts: localhost    remote_user: root    gather_facts: no    tasks: -  - name: get provisioning vars -    include_vars: vars.yml +  - name: Alert user to variables needed - clusterid +    debug: +      msg: "openshift_aws_clusterid={{ openshift_aws_clusterid | default('default') }}" + +  - name: Alert user to variables needed - region +    debug: +      msg: "openshift_aws_region={{ openshift_aws_region | default('us-east-1') }}"    - name: bring lib_openshift into scope      include_role: @@ -14,9 +19,9 @@    - name: fetch masters      ec2_remote_facts: -      region: "{{ provision.region }}" +      region: "{{ openshift_aws_region | default('us-east-1') }}"        filters: -        "tag:clusterid": "{{ provision.clusterid }}" +        "tag:clusterid": "{{ openshift_aws_clusterid | default('default') }}"          "tag:host-type": master          instance-state-name: running      register: mastersout @@ -26,9 +31,9 @@    - name: fetch new node instances      ec2_remote_facts: -      region: "{{ provision.region }}" +      region: "{{ openshift_aws_region | default('us-east-1') }}"        filters: -        "tag:clusterid": "{{ provision.clusterid }}" +        "tag:clusterid": "{{ openshift_aws_clusterid | default('default') }}"          "tag:host-type": node          instance-state-name: running      register: instancesout diff --git a/playbooks/aws/openshift-cluster/build_ami.yml b/playbooks/aws/openshift-cluster/build_ami.yml index 998cf4340..d3c0057b5 100644 --- a/playbooks/aws/openshift-cluster/build_ami.yml +++ b/playbooks/aws/openshift-cluster/build_ami.yml @@ -3,75 +3,49 @@    connection: local    gather_facts: no    tasks: -  - name: get the necessary vars for ami building -    include_vars: vars.yml - -  - name: create a vpc with the name <clusterid> +  - name: Require openshift_aws_base_ami +    fail: +      msg: "A base AMI is required for AMI building.  Please ensure  `openshift_aws_base_ami` is defined." +    when: openshift_aws_base_ami is undefined + +  - name: "Alert user to variables needed and their values - {{ item.name }}" +    debug: +      msg: "{{ item.msg }}" +    with_items: +    - name: openshift_aws_clusterid +      msg: "openshift_aws_clusterid={{ openshift_aws_clusterid | default('default') }}" +    - name: openshift_aws_region +      msg: "openshift_aws_region={{ openshift_aws_region | default('us-east-1') }}" + +  - name: create an instance and prepare for ami      include_role: -      name: openshift_aws_vpc +      name: openshift_aws +      tasks_from: build_ami.yml      vars: -      r_openshift_aws_vpc_clusterid: "{{ provision.clusterid }}" -      r_openshift_aws_vpc_cidr: "{{ provision.vpc.cidr }}" -      r_openshift_aws_vpc_subnets: "{{ provision.vpc.subnets }}" -      r_openshift_aws_vpc_region: "{{ provision.region }}" -      r_openshift_aws_vpc_tags: "{{ provision.vpc.tags }}" -      r_openshift_aws_vpc_name: "{{ provision.vpc.name | default(provision.clusterid) }}" +      openshift_aws_node_group_type: compute -  - name: create aws ssh keypair -    include_role: -      name: openshift_aws_ssh_keys -    vars: -      r_openshift_aws_ssh_keys_users: "{{ provision.instance_users }}" -      r_openshift_aws_ssh_keys_region: "{{ provision.region }}" - -  - name: Create compute sgs -    include_role: -      name: openshift_aws_sg -    vars: -      r_openshift_aws_sg_clusterid: "{{ provision.clusterid }}" -      r_openshift_aws_sg_region: "{{ provision.region }}" -      r_openshift_aws_sg_type: compute - -  - name: fetch the default subnet id -    ec2_vpc_subnet_facts: -      region: "{{ provision.region }}" +  - name: fetch newly created instances +    ec2_remote_facts: +      region: "{{ openshift_aws_region | default('us-east-1') }}"        filters: -        "tag:Name": "{{ provision.vpc.subnets[provision.region][0].az }}" -    register: subnetout - -  - name: create instance for ami creation -    ec2: -      assign_public_ip: yes -      region: "{{ provision.region }}" -      key_name: "{{ provision.node_group_config.ssh_key_name }}" -      group: "{{ provision.clusterid }}" -      instance_type: m4.xlarge -      vpc_subnet_id: "{{ subnetout.subnets[0].id }}" -      image: "{{ provision.build.base_image }}" -      volumes: -      - device_name: /dev/sdb -        volume_type: gp2 -        volume_size: 100 -        delete_on_termination: true -      wait: yes -      exact_count: 1 -      count_tag: -        Name: ami_base -      instance_tags: -        Name: ami_base -    register: amibase +        "tag:Name": "{{ openshift_aws_base_ami_name | default('ami_base') }}" +        instance-state-name: running +    register: instancesout +    retries: 20 +    delay: 3 +    until: instancesout.instances|length > 0    - name: wait for ssh to become available      wait_for:        port: 22 -      host: "{{ amibase.tagged_instances.0.public_ip }}" +      host: "{{ instancesout.instances[0].public_ip_address }}"        timeout: 300        search_regex: OpenSSH    - name: add host to nodes      add_host:        groups: nodes -      name: "{{ amibase.tagged_instances.0.public_dns_name }}" +      name: "{{ instancesout.instances[0].public_dns_name }}"    - name: set the user to perform installation      set_fact: @@ -92,9 +66,6 @@  - hosts: nodes    remote_user: root    tasks: -  - name: get the necessary vars for ami building -    include_vars: vars.yml -    - set_fact:        openshift_node_bootstrap: True @@ -106,53 +77,9 @@    connection: local    become: no    tasks: -  - name: bundle ami -    ec2_ami: -      instance_id: "{{ amibase.tagged_instances.0.id }}" -      region: "{{ provision.region }}" -      state: present -      description: "This was provisioned {{ ansible_date_time.iso8601 }}" -      name: "{{ provision.build.ami_name }}{{ lookup('pipe', 'date +%Y%m%d%H%M')}}" -      tags: "{{ provision.build.openshift_ami_tags }}" -      wait: yes -    register: amioutput - -  - debug: var=amioutput - -  - when: provision.build.use_encryption | default(False) -    block: -    - name: setup kms key for encryption -      include_role: -        name: openshift_aws_iam_kms -      vars: -        r_openshift_aws_iam_kms_region: "{{ provision.region }}" -        r_openshift_aws_iam_kms_alias: "alias/{{ provision.clusterid }}_kms" - -    - name: augment the encrypted ami tags with source-ami -      set_fact: -        source_tag: -          source-ami: "{{ amioutput.image_id }}" - -    - name: copy the ami for encrypted disks -      include_role: -        name: openshift_aws_ami_copy -      vars: -        r_openshift_aws_ami_copy_region: "{{ provision.region }}" -        r_openshift_aws_ami_copy_name: "{{ provision.build.ami_name }}{{ lookup('pipe', 'date +%Y%m%d%H%M')}}-encrypted" -        r_openshift_aws_ami_copy_src_ami: "{{ amioutput.image_id }}" -        r_openshift_aws_ami_copy_kms_alias: "alias/{{ provision.clusterid }}_kms" -        r_openshift_aws_ami_copy_tags: "{{ source_tag | combine(provision.build.openshift_ami_tags) }}" -        r_openshift_aws_ami_copy_encrypt: "{{ provision.build.use_encryption }}" -        # this option currently fails due to boto waiters -        # when supported this need to be reapplied -        #r_openshift_aws_ami_copy_wait: True - -    - name: Display newly created encrypted ami id -      debug: -        msg: "{{ r_openshift_aws_ami_copy_retval_custom_ami }}" - -  - name: terminate temporary instance -    ec2: -      state: absent -      region: "{{ provision.region }}" -      instance_ids: "{{ amibase.tagged_instances.0.id }}" +  - name: seal the ami +    include_role: +      name: openshift_aws +      tasks_from: seal_ami.yml +    vars: +      openshift_aws_ami_name: "openshift-gi-{{ lookup('pipe', 'date +%Y%m%d%H%M')}}" diff --git a/playbooks/aws/openshift-cluster/build_node_group.yml b/playbooks/aws/openshift-cluster/build_node_group.yml deleted file mode 100644 index 5b0330e46..000000000 --- a/playbooks/aws/openshift-cluster/build_node_group.yml +++ /dev/null @@ -1,48 +0,0 @@ ---- -- name: fetch recently created AMI -  ec2_ami_find: -    region: "{{ openshift_region }}" -    sort: creationDate -    sort_order: descending -    name: "{{ openshift_ami_name }}*" -    ami_tags: "{{ openshift_ami_tags }}" -    #no_result_action: fail -  register: amiout -  when: not openshift_use_custom_ami - -- block: -  - name: "Create {{ openshift_build_node_type }} sgs" -    include_role: -      name: openshift_aws_sg -    vars: -      r_openshift_aws_sg_clusterid: "{{ openshift_clusterid }}" -      r_openshift_aws_sg_region: "{{ openshift_region }}" -      r_openshift_aws_sg_type: "{{ openshift_build_node_type }}" - -  - name: "generate a launch config name for {{ openshift_build_node_type }}" -    set_fact: -      launch_config_name: "{{ openshift_clusterid }}-{{ openshift_build_node_type }}-{{ ansible_date_time.epoch }}" - -  - name: create "{{ openshift_build_node_type }} launch config" -    include_role: -      name: openshift_aws_launch_config -    vars: -      r_openshift_aws_launch_config_name: "{{ launch_config_name }}" -      r_openshift_aws_launch_config_clusterid: "{{ openshift_clusterid }}" -      r_openshift_aws_launch_config_region: "{{ openshift_region }}" -      r_openshift_aws_launch_config: "{{ openshift_node_group_config }}" -      r_openshift_aws_launch_config_type: "{{ openshift_build_node_type }}" -      r_openshift_aws_launch_config_custom_image: "{{ '' if 'results' not in amiout and amiout.results|length > 0 else amiout.results[0].ami_id }}" -      r_openshift_aws_launch_config_bootstrap_token: "{{ (local_bootstrap['content'] |b64decode) if local_bootstrap is defined else '' }}" - -  - name: "create {{ openshift_build_node_type }} node groups" -    include_role: -      name: openshift_aws_node_group -    vars: -      r_openshift_aws_node_group_name: "{{ openshift_clusterid }} openshift {{ openshift_build_node_type }}" -      r_openshift_aws_node_group_lc_name: "{{ launch_config_name }}" -      r_openshift_aws_node_group_clusterid: "{{ openshift_clusterid }}" -      r_openshift_aws_node_group_region: "{{ openshift_region }}" -      r_openshift_aws_node_group_config: "{{ openshift_node_group_config }}" -      r_openshift_aws_node_group_type: "{{ openshift_build_node_type }}" -      r_openshift_aws_node_group_subnet_name: "{{ openshift_subnet_name }}" diff --git a/playbooks/aws/openshift-cluster/install.yml b/playbooks/aws/openshift-cluster/install.yml new file mode 100644 index 000000000..86d58a68e --- /dev/null +++ b/playbooks/aws/openshift-cluster/install.yml @@ -0,0 +1,74 @@ +--- +- name: Setup the vpc and the master node group +  hosts: localhost +  tasks: +  - name: Alert user to variables needed - clusterid +    debug: +      msg: "openshift_aws_clusterid={{ openshift_aws_clusterid | default('default') }}" + +  - name: Alert user to variables needed - region +    debug: +      msg: "openshift_aws_region={{ openshift_aws_region | default('us-east-1') }}" + +  - name: fetch newly created instances +    ec2_remote_facts: +      region: "{{ openshift_aws_region | default('us-east-1') }}" +      filters: +        "tag:clusterid": "{{ openshift_aws_clusterid | default('default') }}" +        "tag:host-type": master +        instance-state-name: running +    register: instancesout +    retries: 20 +    delay: 3 +    until: instancesout.instances|length > 0 + +  - name: add new master to masters group +    add_host: +      groups: "masters,etcd,nodes" +      name: "{{ item.public_ip_address }}" +      hostname: "{{ openshift_aws_clusterid | default('default') }}-master-{{ item.id[:-5] }}" +    with_items: "{{ instancesout.instances }}" + +  - name: wait for ssh to become available +    wait_for: +      port: 22 +      host: "{{ item.public_ip_address }}" +      timeout: 300 +      search_regex: OpenSSH +    with_items: "{{ instancesout.instances }}" + +- name: set the master facts for hostname to elb +  hosts: masters +  gather_facts: no +  remote_user: root +  tasks: +  - name: fetch elbs +    ec2_elb_facts: +      region: "{{ openshift_aws_region | default('us-east-1') }}" +      names: +      - "{{ item }}" +    with_items: +    - "{{ openshift_aws_clusterid | default('default') }}-master-external" +    - "{{ openshift_aws_clusterid | default('default') }}-master-internal" +    delegate_to: localhost +    register: elbs + +  - debug: var=elbs + +  - name: set fact +    set_fact: +      openshift_master_cluster_hostname: "{{ elbs.results[1].elbs[0].dns_name }}" +      osm_custom_cors_origins: +      - "{{ elbs.results[1].elbs[0].dns_name }}" +      - "console.{{ openshift_aws_clusterid | default('default') }}.openshift.com" +      - "api.{{ openshift_aws_clusterid | default('default') }}.openshift.com" +    with_items: "{{ groups['masters'] }}" + +- name: normalize groups +  include: ../../byo/openshift-cluster/initialize_groups.yml + +- name: run the std_include +  include: ../../common/openshift-cluster/std_include.yml + +- name: run the config +  include: ../../common/openshift-cluster/config.yml diff --git a/playbooks/aws/openshift-cluster/provision.yml b/playbooks/aws/openshift-cluster/provision.yml index 88ab0ecb1..db7afac6f 100644 --- a/playbooks/aws/openshift-cluster/provision.yml +++ b/playbooks/aws/openshift-cluster/provision.yml @@ -2,163 +2,16 @@  - name: Setup the vpc and the master node group    hosts: localhost    tasks: -  - name: get provisioning vars -    include_vars: vars.yml -  - name: create default vpc -    include_role: -      name: openshift_aws_vpc -    vars: -      r_openshift_aws_vpc_clusterid: "{{ provision.clusterid }}" -      r_openshift_aws_vpc_cidr: "{{ provision.vpc.cidr }}" -      r_openshift_aws_vpc_subnets: "{{ provision.vpc.subnets }}" -      r_openshift_aws_vpc_region: "{{ provision.region }}" -      r_openshift_aws_vpc_tags: "{{ provision.vpc.tags }}" -      r_openshift_aws_vpc_name: "{{ provision.vpc.name | default(provision.clusterid) }}" - -  - name: bring iam_cert23 into scope -    include_role: -      name: lib_utils - -  - name: upload certificates to AWS IAM -    iam_cert23: -      state: present -      name: "{{ provision.clusterid }}-master-external" -      cert: "{{ provision.iam_cert_ca.cert_path }}" -      key: "{{ provision.iam_cert_ca.key_path }}" -      cert_chain: "{{ provision.iam_cert_ca.chain_path | default(omit) }}" -    register: elb_cert_chain -    failed_when: -    - "'failed' in elb_cert_chain" -    - elb_cert_chain.failed -    - "'msg' in elb_cert_chain" -    - "'already exists' not in elb_cert_chain.msg" -    when: provision.iam_cert_ca is defined - -  - debug: var=elb_cert_chain +  - name: Alert user to variables needed - clusterid +    debug: +      msg: "openshift_aws_clusterid={{ openshift_aws_clusterid | default('default') }}" -  - name: create aws ssh keypair -    include_role: -      name: openshift_aws_ssh_keys -    vars: -      r_openshift_aws_ssh_keys_users: "{{ provision.instance_users }}" -      r_openshift_aws_ssh_keys_region: "{{ provision.region }}" - -  - when: provision.openshift_registry_s3 | default(false) -    name: create s3 bucket for registry -    include_role: -      name: openshift_aws_s3 -    vars: -      r_openshift_aws_s3_clusterid: "{{ provision.clusterid }}-docker-registry" -      r_openshift_aws_s3_region: "{{ provision.region }}" -      r_openshift_aws_s3_mode: create +  - name: Alert user to variables needed - region +    debug: +      msg: "openshift_aws_region={{ openshift_aws_region | default('us-east-1') }}" -  - name: include scale group creation for master -    include: build_node_group.yml -    vars: -      openshift_build_node_type: master -      openshift_clusterid: "{{ provision.clusterid }}" -      openshift_region: "{{ provision.region }}" -      openshift_use_custom_ami: "{{ provision.use_custom_ami }}" -      openshift_ami_name: "{{ provision.build.ami_name }}" -      openshift_ami_tags: "{{ provision.build.ami_tags }}" -      openshift_node_group_config: "{{ provision.node_group_config }}" -      openshift_subnet_name: "{{ provision.vpc.subnets[provision.region][0].az }}" - -  - name: fetch new master instances -    ec2_remote_facts: -      region: "{{ provision.region }}" -      filters: -        "tag:clusterid": "{{ provision.clusterid }}" -        "tag:host-type": master -        instance-state-name: running -    register: instancesout -    retries: 20 -    delay: 3 -    until: instancesout.instances|length > 0 - -  - name: create our master external and internal load balancers +  - name: create default vpc      include_role: -      name: openshift_aws_elb -    vars: -      r_openshift_aws_elb_clusterid: "{{ provision.clusterid }}" -      r_openshift_aws_elb_region: "{{ provision.region }}" -      r_openshift_aws_elb_instance_filter: -        "tag:clusterid": "{{ provision.clusterid }}" -        "tag:host-type": master -        instance-state-name: running -      r_openshift_aws_elb_type: master -      r_openshift_aws_elb_direction: "{{ elb_item }}" -      r_openshift_aws_elb_idle_timout: 400 -      r_openshift_aws_elb_scheme: internet-facing -      r_openshift_aws_elb_security_groups: -      - "{{ provision.clusterid }}" -      - "{{ provision.clusterid }}_master" -      r_openshift_aws_elb_subnet_name: "{{ provision.vpc.subnets[provision.region][0].az }}" -      r_openshift_aws_elb_name: "{{ provision.clusterid }}-master-{{ elb_item }}" -      r_openshift_aws_elb_cert_arn: "{{ elb_cert_chain.arn }}" -    with_items: -    - internal -    - external -    loop_control: -      loop_var: elb_item - -  - name: add new master to masters group -    add_host: -      groups: "masters,etcd,nodes" -      name: "{{ item.public_ip_address }}" -      hostname: "{{ provision.clusterid }}-master-{{ item.id[:-5] }}" -    with_items: "{{ instancesout.instances }}" - -  - name: set facts for group normalization -    set_fact: -      cluster_id: "{{ provision.clusterid }}" -      cluster_env: "{{ provision.node_group_config.tags.environment | default('dev') }}" - -  - name: wait for ssh to become available -    wait_for: -      port: 22 -      host: "{{ item.public_ip_address }}" -      timeout: 300 -      search_regex: OpenSSH -    with_items: "{{ instancesout.instances }}" - - -- name: set the master facts for hostname to elb -  hosts: masters -  gather_facts: no -  remote_user: root -  tasks: -  - name: include vars -    include_vars: vars.yml - -  - name: fetch elbs -    ec2_elb_facts: -      region: "{{ provision.region }}" -      names: -      - "{{ item }}" -    with_items: -    - "{{ provision.clusterid }}-master-external" -    - "{{ provision.clusterid }}-master-internal" -    delegate_to: localhost -    register: elbs - -  - debug: var=elbs - -  - name: set fact -    set_fact: -      openshift_master_cluster_hostname: "{{ elbs.results[1].elbs[0].dns_name }}" -      osm_custom_cors_origins: -      - "{{ elbs.results[1].elbs[0].dns_name }}" -      - "console.{{ provision.clusterid }}.openshift.com" -      - "api.{{ provision.clusterid }}.openshift.com" -    with_items: "{{ groups['masters'] }}" - -- name: normalize groups -  include: ../../byo/openshift-cluster/initialize_groups.yml - -- name: run the std_include -  include: ../../common/openshift-cluster/std_include.yml - -- name: run the config -  include: ../../common/openshift-cluster/config.yml +      name: openshift_aws +      tasks_from: provision.yml diff --git a/playbooks/aws/openshift-cluster/provision_install.yml b/playbooks/aws/openshift-cluster/provision_install.yml new file mode 100644 index 000000000..e787deced --- /dev/null +++ b/playbooks/aws/openshift-cluster/provision_install.yml @@ -0,0 +1,16 @@ +--- +# Once an AMI is built then this script is used for +# the one stop shop to provision and install a cluster +# this playbook is run with the following parameters: +# ansible-playbook -i openshift-ansible-inventory provision_install.yml +- name: Include the provision.yml playbook to create cluster +  include: provision.yml + +- name: Include the install.yml playbook to install cluster +  include: install.yml + +- name: Include the install.yml playbook to install cluster +  include: provision_nodes.yml + +- name: Include the accept.yml playbook to accept nodes into the cluster +  include: accept.yml diff --git a/playbooks/aws/openshift-cluster/provision_nodes.yml b/playbooks/aws/openshift-cluster/provision_nodes.yml index 87629e354..44c686e08 100644 --- a/playbooks/aws/openshift-cluster/provision_nodes.yml +++ b/playbooks/aws/openshift-cluster/provision_nodes.yml @@ -1,62 +1,18 @@  --- -# Get bootstrap config token -# bootstrap should be created on first master -# need to fetch it and shove it into cloud data  - name: create the node scale groups    hosts: localhost    connection: local    gather_facts: yes    tasks: -  - name: get provisioning vars -    include_vars: vars.yml +  - name: Alert user to variables needed - clusterid +    debug: +      msg: "openshift_aws_clusterid={{ openshift_aws_clusterid | default('default') }}" -  - name: fetch master instances -    ec2_remote_facts: -      region: "{{ provision.region }}" -      filters: -        "tag:clusterid": "{{ provision.clusterid }}" -        "tag:host-type": master -        instance-state-name: running -    register: instancesout -    retries: 20 -    delay: 3 -    until: instancesout.instances|length > 0 +  - name: Alert user to variables needed - region +    debug: +      msg: "openshift_aws_region={{ openshift_aws_region | default('us-east-1') }}" -  - name: slurp down the bootstrap.kubeconfig -    slurp: -      src: /etc/origin/master/bootstrap.kubeconfig -    delegate_to: "{{ instancesout.instances[0].public_ip_address }}" -    remote_user: root -    register: bootstrap - -  - name: set_fact on localhost for kubeconfig -    set_fact: -      local_bootstrap: "{{ bootstrap }}" -      launch_config_name: -        infra: "infra-{{ ansible_date_time.epoch }}" -        compute: "compute-{{ ansible_date_time.epoch }}" - -  - name: include build node group for infra -    include: build_node_group.yml -    vars: -      openshift_build_node_type: infra -      openshift_clusterid: "{{ provision.clusterid }}" -      openshift_region: "{{ provision.region }}" -      openshift_use_custom_ami: "{{ proviion.use_custom_ami }}" -      openshift_ami_name: "{{ provision.build.ami_name }}" -      openshift_ami_tags: "{{ provision.build.openshift_ami_tags }}" -      openshift_node_group_config: "{{ provision.node_group_config }}" -      openshift_subnet_name: "{{ provision.vpc.subnets[provision.region][0].az }}" - - -  - name: include build node group for compute -    include: build_node_group.yml -    vars: -      openshift_build_node_type: compute -      openshift_clusterid: "{{ provision.clusterid }}" -      openshift_region: "{{ provision.region }}" -      openshift_use_custom_ami: "{{ proviion.use_custom_ami }}" -      openshift_ami_name: "{{ provision.build.ami_name }}" -      openshift_ami_tags: "{{ provision.build.openshift_ami_tags }}" -      openshift_node_group_config: "{{ provision.node_group_config }}" -      openshift_subnet_name: "{{ provision.vpc.subnets[provision.region][0].az }}" +  - name: create the node groups +    include_role: +      name: openshift_aws +      tasks_from: provision_nodes.yml diff --git a/playbooks/aws/openshift-cluster/provisioning_vars.example.yml b/playbooks/aws/openshift-cluster/provisioning_vars.example.yml new file mode 100644 index 000000000..5a30ad3a5 --- /dev/null +++ b/playbooks/aws/openshift-cluster/provisioning_vars.example.yml @@ -0,0 +1,26 @@ +--- +openshift_node_bootstrap: True + +# specify a clusterid +#openshift_aws_clusterid: default + +# must specify a base_ami when building an AMI +#openshift_aws_base_ami: + +# when creating an encrypted AMI please specify use_encryption +#openshift_aws_ami_encrypt: False + +# custom certificates are required for the ELB +#openshift_aws_iam_cert_path: '/path/to/wildcard.<clusterid>.example.com.crt' +#openshift_aws_iam_key_path: '/path/to/wildcard.<clusterid>.example.com.key' +#openshift_aws_iam_cert_chain_path: '/path/to/cert.ca.crt' + +# This is required for any ec2 instances +#openshift_aws_ssh_key_name: myuser_key + +# This will ensure these users are created +#openshift_aws_users: +#- key_name: myuser_key +#  username: myuser +#  pub_key: | +#         ssh-rsa AAAA diff --git a/playbooks/aws/openshift-cluster/vars.yml b/playbooks/aws/openshift-cluster/vars.yml deleted file mode 100644 index 1d91593e2..000000000 --- a/playbooks/aws/openshift-cluster/vars.yml +++ /dev/null @@ -1,116 +0,0 @@ ---- - -clusterid: mycluster -region: us-east-1 - -provision: -  clusterid: "{{ clusterid }}" -  region: "{{ region }}" - -  build:  # build specific variables here -    ami_name: "openshift-gi-" -    base_image: ami-bdd5d6ab  # base image for AMI to build from - -    # when creating an encrypted AMI please specify use_encryption -    use_encryption: False - -    ami_tags: -      bootstrap: "true" -      openshift-created: "true" -      clusterid: "{{ clusterid }}" - -  # Use s3 backed registry storage -  openshift_registry_s3: True - -  # whether to use custome ami for each node type -  use_custom_ami: False - -  # if using custom certificates these are required for the ELB -  iam_cert_ca: -    name: "{{ clusterid }}_openshift" -    cert_path: '/path/to/wildcard.<clusterid>.example.com.crt' -    key_path: '/path/to/wildcard.<clusterid>.example.com.key' -    chain_path: '/path/to/cert.ca.crt' - -  instance_users: -  - key_name: myuser_key -    username: myuser -    pub_key: | -           ssh-rsa AAAA== myuser@system - -  node_group_config: -    tags: -      clusterid: "{{ clusterid }}" -      environment: stg - -    ssh_key_name: myuser_key - -    # master specific cluster node settings -    master: -      instance_type: m4.xlarge -      ami: ami-cdeec8b6  # if using an encrypted or custom AMI this will be replaced -      volumes: -      - device_name: /dev/sdb -        volume_size: 100 -        device_type: gp2 -        delete_on_termination: False -      health_check: -        period: 60 -        type: EC2 -      min_size: 3 -      max_size: 3 -      desired_size: 3 -      tags: -        host-type: master -        sub-host-type: default -      wait_for_instances: True - -    # compute specific cluster node settings -    compute: -      instance_type: m4.xlarge -      ami: ami-cdeec8b6  # if using an encrypted or custom AMI this will be replaced -      volumes: -      - device_name: /dev/sdb -        volume_size: 100 -        device_type: gp2 -        delete_on_termination: True -      health_check: -        period: 60 -        type: EC2 -      min_size: 3 -      max_size: 100 -      desired_size: 3 -      tags: -        host-type: node -        sub-host-type: compute - -    # infra specific cluster node settings -    infra: -      instance_type: m4.xlarge -      ami: ami-cdeec8b6  # if using an encrypted or custom AMI this will be replaced -      volumes: -      - device_name: /dev/sdb -        volume_size: 100 -        device_type: gp2 -        delete_on_termination: True -      health_check: -        period: 60 -        type: EC2 -      min_size: 2 -      max_size: 20 -      desired_size: 2 -      tags: -        host-type: node -        sub-host-type: infra - -  # vpc settings -  vpc: -    cidr: 172.31.0.0/16 -    subnets: -      us-east-1:  # These are us-east-1 region defaults. Ensure this matches your region -      - cidr: 172.31.48.0/20 -        az: "us-east-1c" -      - cidr: 172.31.32.0/20 -        az: "us-east-1e" -      - cidr: 172.31.16.0/20 -        az: "us-east-1a" | 
