Skip to content

Commit 0bfd434

Browse files
authored
Update etcd to 3.6 (#12634)
* [etcd] Update etcd 3.5.x to 3.6.5 - Add hashes for etcd 3.6.5 - Remove etcd v2 backup task for etcd 3.6 The etcd 3.6 removes 'etcdctl backup' command with ETCDCTL_API=2 - Downgrade etcd to 3.5 in netchecker The netchecker does not work with etcd 3.6 becaust it removes v2 API support (--enable-v2). And netchekcer does not support v3 API. * Fix: Change etcd config to clean up v2 store before upgrading etcd to 3.6 * Bump etcd to 3.6.8
1 parent 6a12431 commit 0bfd434

File tree

10 files changed

+97
-11
lines changed

10 files changed

+97
-11
lines changed

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,7 +112,7 @@ Note:
112112

113113
- Core
114114
- [kubernetes](https://github.com/kubernetes/kubernetes) 1.35.1
115-
- [etcd](https://github.com/etcd-io/etcd) 3.5.27
115+
- [etcd](https://github.com/etcd-io/etcd) 3.6.8
116116
- [docker](https://www.docker.com/) 28.3
117117
- [containerd](https://containerd.io/) 2.2.1
118118
- [cri-o](http://cri-o.io/) 1.35.0 (experimental: see [CRI-O Note](docs/CRI/cri-o.md). Only on fedora, ubuntu and centos based OS)

roles/etcd/handlers/backup.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@
3434
when:
3535
- etcd_data_dir_member.stat.exists
3636
- etcd_cluster_is_healthy.rc == 0
37+
- etcd_version is version('3.6.0', '<')
3738
command: >-
3839
{{ bin_dir }}/etcdctl backup
3940
--data-dir {{ etcd_data_dir }}
Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
---
2+
# When upgrading from etcd 3.5 to 3.6, need to clean up v2 store before upgrading.
3+
# Without this, etcd 3.6 will crash with following error:
4+
# "panic: detected disallowed v2 WAL for stage --v2-deprecation=write-only [recovered]"
5+
- name: Cleanup v2 store when upgrade etcd from <3.6 to >=3.6
6+
when:
7+
- etcd_cluster_setup
8+
- etcd_current_version != ''
9+
- etcd_current_version is version('3.6.0', '<')
10+
- etcd_version is version('3.6.0', '>=')
11+
block:
12+
- name: Ensure etcd version is >=3.5.26
13+
when:
14+
- etcd_current_version is version('3.5.26', '<')
15+
fail:
16+
msg: "You need to upgrade etcd to 3.5.26 or later before upgrade to 3.6. Current version is {{ etcd_current_version }}."
17+
18+
# Workarounds:
19+
# Disable --enable-v2 (recommended in 20289) and do workaround of 20231 (MAX_WALS=1 and SNAPSHOT_COUNT=1)
20+
# - https://github.com/etcd-io/etcd/issues/20809
21+
# - https://github.com/etcd-io/etcd/discussions/20231#discussioncomment-13958051
22+
- name: Change etcd configuration temporally to limit number of WALs and snapshots to clean up v2 store
23+
ansible.builtin.lineinfile:
24+
path: /etc/etcd.env
25+
regexp: "{{ item.regexp }}"
26+
line: "{{ item.line }}"
27+
loop:
28+
- { regexp: '^ETCD_SNAPSHOT_COUNT=', line: 'ETCD_SNAPSHOT_COUNT=1' }
29+
- { regexp: '^ETCD_MAX_WALS=', line: 'ETCD_MAX_WALS=1' }
30+
- { regexp: '^ETCD_MAX_SNAPSHOTS=', line: 'ETCD_MAX_SNAPSHOTS=1' }
31+
- { regexp: '^ETCD_ENABLE_V2=', line: 'ETCD_ENABLE_V2=false' }
32+
33+
# Restart etcd to apply temporal configuration and prevent some upgrade failures
34+
# See also: https://etcd.io/blog/2025/upgrade_from_3.5_to_3.6_issue_followup/
35+
- name: Stop etcd
36+
service:
37+
name: etcd
38+
state: stopped
39+
40+
- name: Start etcd
41+
service:
42+
name: etcd
43+
state: started

roles/etcd/tasks/install_docker.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,14 @@
2323
- etcd_events_cluster_setup
2424
- etcd_image_tag not in etcd_events_current_docker_image.stdout | default('')
2525

26+
- name: Get currently-deployed etcd version as x.y.z format
27+
set_fact:
28+
etcd_current_version: "{{ (etcd_current_docker_image.stdout | regex_search('.*:v([0-9]+\\.[0-9]+\\.[0-9]+)', '\\1'))[0] | default('') }}"
29+
when: etcd_cluster_setup
30+
31+
- name: Cleanup v2 store data
32+
import_tasks: clean_v2_store.yml
33+
2634
- name: Install etcd launch script
2735
template:
2836
src: etcd.j2

roles/etcd/tasks/install_host.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,14 @@
2121
- etcd_events_cluster_setup
2222
- etcd_version not in etcd_current_host_version.stdout | default('')
2323

24+
- name: Get currently-deployed etcd version as x.y.z format
25+
set_fact:
26+
etcd_current_version: "{{ (etcd_current_host_version.stdout | regex_search('etcd Version: ([0-9]+\\.[0-9]+\\.[0-9]+)', '\\1'))[0] | default('') }}"
27+
when: etcd_cluster_setup
28+
29+
- name: Cleanup v2 store data
30+
import_tasks: clean_v2_store.yml
31+
2432
- name: Install | Copy etcd binary from download dir
2533
copy:
2634
src: "{{ local_release_dir }}/etcd-v{{ etcd_version }}-linux-{{ host_architecture }}/{{ item }}"

roles/etcd/tasks/main.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,12 @@
5353
- control-plane
5454
- network
5555

56+
- name: Install etcd
57+
include_tasks: "install_{{ etcd_deployment_type }}.yml"
58+
when: ('etcd' in group_names)
59+
tags:
60+
- upgrade
61+
5662
- name: Install etcdctl and etcdutl binary
5763
import_role:
5864
name: etcdctl_etcdutl
@@ -64,12 +70,6 @@
6470
- ('etcd' in group_names)
6571
- etcd_cluster_setup
6672

67-
- name: Install etcd
68-
include_tasks: "install_{{ etcd_deployment_type }}.yml"
69-
when: ('etcd' in group_names)
70-
tags:
71-
- upgrade
72-
7373
- name: Configure etcd
7474
include_tasks: configure.yml
7575
when: ('etcd' in group_names)

roles/etcd/templates/etcd.env.j2

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,8 +25,6 @@ ETCD_MAX_REQUEST_BYTES={{ etcd_max_request_bytes }}
2525
ETCD_LOG_LEVEL={{ etcd_log_level }}
2626
ETCD_MAX_SNAPSHOTS={{ etcd_max_snapshots }}
2727
ETCD_MAX_WALS={{ etcd_max_wals }}
28-
# Flannel need etcd v2 API
29-
ETCD_ENABLE_V2=true
3028

3129
# TLS settings
3230
ETCD_TRUSTED_CA_FILE={{ etcd_cert_dir }}/ca.pem

roles/kubespray_defaults/defaults/main/download.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -237,7 +237,8 @@ netcheck_agent_image_repo: "{{ docker_image_repo }}/mirantis/k8s-netchecker-agen
237237
netcheck_agent_image_tag: "v{{ netcheck_version }}"
238238
netcheck_server_image_repo: "{{ docker_image_repo }}/mirantis/k8s-netchecker-server"
239239
netcheck_server_image_tag: "v{{ netcheck_version }}"
240-
netcheck_etcd_image_tag: "{{ etcd_image_tag }}"
240+
# netchecker doesn't work with etcd>=3.6 because etcd v2 API is removed
241+
netcheck_etcd_image_tag: "v{{ (etcd_binary_checksums['amd64'].keys() | select('version', '3.6', '<'))[0] }}"
241242
cilium_image_repo: "{{ quay_image_repo }}/cilium/cilium"
242243
cilium_image_tag: "v{{ cilium_version }}"
243244
cilium_operator_image_repo: "{{ quay_image_repo }}/cilium/operator"

roles/kubespray_defaults/vars/main/checksums.yml

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -284,6 +284,15 @@ kubeadm_checksums:
284284
1.33.0: sha256:26cb7ac57d522a59c84c4784b176097d23c7b4e61874fab84ae719d0e43ac0bc
285285
etcd_binary_checksums:
286286
arm64:
287+
3.6.8: sha256:438f56a700d17ce761510a3e63e6fa5c1d587b2dd4d7a22c179c09a649366760
288+
3.6.7: sha256:ef5fc443cf7cc5b82738f3c28363704896551900af90a6d622cae740b5644270
289+
3.6.6: sha256:8a15f5427c111ff4692753682374970fb68878401d946c2c28bdad6857db652f
290+
3.6.5: sha256:7010161787077b07de29b15b76825ceacbbcedcb77fe2e6832f509be102cab6b
291+
3.6.4: sha256:323421fa279f4f3d7da4c7f2dfa17d9e49529cb2b4cdf40899a7416bccdde42d
292+
3.6.3: sha256:4b39989093699da7502d1cdd649c412055a2bddd26b3d80ed87d0db31957075c
293+
3.6.2: sha256:79d0a2488967aa07ecfde79158b1dab458158522f834810c2827eecac4695a31
294+
3.6.1: sha256:5f8ed6e314df44128c218decbf0d146cf882583d05c6f6d9023ce905d232aaec
295+
3.6.0: sha256:81477b120ef66ff338fe7de63d894e5feec17e6e1f1d98507676832e089d9b58
287296
3.5.27: sha256:1277309f540c5a0329c428f95455c9f76d24f768c8d28fd2753e891c379053fa
288297
3.5.26: sha256:93ac1667df0e178ea6d152476ce4088df4075604fe4bc7f85f4719e863cd030b
289298
3.5.25: sha256:419dce0b679df31cc45201ef2449b7a6a48e9d241af01741957c9ac86a35badc
@@ -307,6 +316,15 @@ etcd_binary_checksums:
307316
3.5.7: sha256:1a35314900da7db006b198dd917e923459b462128101736c63a3cda57ecdbf51
308317
3.5.6: sha256:888e25c9c94702ac1254c7655709b44bb3711ebaabd3cb05439f3dd1f2b51a87
309318
amd64:
319+
3.6.8: sha256:cf9cfe91a4856cb90eed9c99e6aee4b708db2c7888b88a6f116281f04b0ea693
320+
3.6.7: sha256:cf8af880c5a01ee5363cefa14a3e0cb7e5308dcf4ed17a6973099c9a7aee5a9a
321+
3.6.6: sha256:887afaa4a99f22d802ccdfbe65730a5e79aa5c9ce2c8799c67e9d804c50ecedb
322+
3.6.5: sha256:66bad39ed920f6fc15fd74adcb8bfd38ba9a6412f8c7852d09eb11670e88cac3
323+
3.6.4: sha256:4d5f3101daa534e45ccaf3eec8d21c19b7222db377bcfd5e5a9144155238c105
324+
3.6.3: sha256:3f3b4aa9785d86322c50b296eebdc7a0a57b27065190154b5858bf6a7512ac10
325+
3.6.2: sha256:4b5d55d61e2218fab7c1cc1c00b341c469159ecde8cedd575fa858683f67e9f4
326+
3.6.1: sha256:1324664bfe56d178d1362a57462ca5a7b26a6d2cbe9e1c94b6820e32cb82d673
327+
3.6.0: sha256:42305b0dcbba7b6fdff0382d0c7b99c42026c88c44847a619ab58cde216725d9
310328
3.5.27: sha256:0aad9a9e4e0817a021e933f9806a2b2960a62f949ad5a3d6436d8886945cb1bc
311329
3.5.26: sha256:0a682a91201dc8351d507210bc30b021a11e254eab806f03224b51e8fad29abb
312330
3.5.25: sha256:168af82b59772e1811a9af7b358d42f5c6df44e0d9767afb006ecf12c4bbd607
@@ -330,6 +348,15 @@ etcd_binary_checksums:
330348
3.5.7: sha256:a43119af79c592a874e8f59c4f23832297849d0c479338f9df36e196b86bc396
331349
3.5.6: sha256:4db32e3bc06dd0999e2171f76a87c1cffed8369475ec7aa7abee9023635670fb
332350
ppc64le:
351+
3.6.8: sha256:3b9bb486b0eb8d79b30410749ec26e174db075956c9ecb533b313b9263e7ba78
352+
3.6.7: sha256:de3b1ed50fc8868cdd56b12b0cd81d6740bf53edbca570400a78e530e4829b7b
353+
3.6.6: sha256:e4f528b63a731e9b96f5d10f55ce096223fb4e1bc1778aa2535a3d47e9a129e5
354+
3.6.5: sha256:3cf99879c7c5b8678a0ec2edf9102b268ea934584db2850f049d89ed8e36b61c
355+
3.6.4: sha256:2910fc73e42e1eeb9cc7da8080b821c7649558465e0e6122e49afce832e4b9da
356+
3.6.3: sha256:de8ee412ee2669483fd9c730e915c5bd4fe113ba33be4a70305d13ff35e1f919
357+
3.6.2: sha256:bf79b9d4c7e9f86e611e73de9fe54a195bc0ad54aeb17200b1c8bda3c4119705
358+
3.6.1: sha256:bb87fcd0ea4b9fabf502703512c416ca1d9f4082679cb7f6dbc34bed3dfc13f6
359+
3.6.0: sha256:1180d06e3a3787ab65078d9a488f778a4712c59cc82d614abde80c5d06efe38f
333360
3.5.27: sha256:b41d488dcd579e780f49f5bd747e9386e17e1376ffb77bfff061f7944818a678
334361
3.5.26: sha256:9678ddaced9fcd4878b76b0b76c9c2a3638a70bdc362c9f4cb25ecc48de2c6d3
335362
3.5.25: sha256:0dee64e99a43a06dd9541a40a18b52c7309eb1682a2a32740d4bdf358296c007

roles/kubespray_defaults/vars/main/main.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ pod_infra_supported_versions:
1212
'1.33': '3.10'
1313

1414
etcd_supported_versions:
15-
'1.35': "{{ (etcd_binary_checksums['amd64'].keys() | select('version', '3.6', '<'))[0] }}"
15+
'1.35': "{{ (etcd_binary_checksums['amd64'].keys() | select('version', '3.7', '<'))[0] }}"
1616
'1.34': "{{ (etcd_binary_checksums['amd64'].keys() | select('version', '3.6', '<'))[0] }}"
1717
'1.33': "{{ (etcd_binary_checksums['amd64'].keys() | select('version', '3.6', '<'))[0] }}"
1818
# Kubespray constants

0 commit comments

Comments
 (0)