|
37 | 37 | # @param puppetdb_discovery whether to use puppetdb for node discovery |
38 | 38 | # @param puppetdb_discovery_tag tag to use for puppetdb node discovery |
39 | 39 | # @param purge_manifests whether to purge manifests |
40 | | -# @param role role of the node |
| 40 | +# @param role the role of the node |
41 | 41 | # @param runc_version version of runc to install |
42 | 42 | # @param service_cluster_cidr CIDR for the service network |
43 | | -# @param sysconfig_path path to the sysconfig directory |
| 43 | +# @param sysconfig_path path to the sysconfig directory, per-OS values are configured in hiera |
44 | 44 | # @param tarball_url_template template for tarball packaging |
45 | 45 | # @param uid user id for kubernetes files and services |
46 | 46 | # @param user username for kubernetes files and services |
|
82 | 82 | String[1] $tarball_url_template = 'https://dl.k8s.io/release/v%{version}/kubernetes-%{component}-%{kernel}-%{arch}.tar.gz', |
83 | 83 | String[1] $package_template = 'kubernetes-%{component}', |
84 | 84 | String[1] $hyperkube_name = 'hyperkube', |
85 | | - Optional[Stdlib::Unixpath] $sysconfig_path = undef, |
| 85 | + Stdlib::Unixpath $sysconfig_path = '/etc/sysconfig', |
86 | 86 |
|
87 | 87 | K8s::Node_auth $node_auth = 'bootstrap', |
88 | 88 |
|
|
95 | 95 | Stdlib::Fqdn $cluster_domain = 'cluster.local', |
96 | 96 | String[1] $etcd_cluster_name = 'default', |
97 | 97 |
|
98 | | - Enum['node','server','none'] $role = 'none', |
| 98 | + Optional[K8s::Node_role] $role = undef, |
99 | 99 | Optional[K8s::Firewall] $firewall_type = undef, |
100 | 100 |
|
101 | 101 | String[1] $user = 'kube', |
102 | 102 | String[1] $group = 'kube', |
103 | 103 | Integer[0, 65535] $uid = 888, |
104 | 104 | Integer[0, 65535] $gid = 888, |
105 | 105 | ) { |
106 | | - if $manage_container_manager { |
107 | | - include k8s::install::container_runtime |
108 | | - } |
109 | | - |
110 | | - group { $group: |
111 | | - ensure => present, |
112 | | - system => true, |
113 | | - gid => $gid, |
114 | | - } |
115 | | - |
116 | | - user { $user: |
117 | | - ensure => present, |
118 | | - comment => 'Kubernetes user', |
119 | | - gid => $group, |
120 | | - home => '/srv/kubernetes', |
121 | | - managehome => false, |
122 | | - shell => (fact('os.family') ? { |
123 | | - 'Debian' => '/usr/sbin/nologin', |
124 | | - default => '/sbin/nologin', |
125 | | - }), |
126 | | - system => true, |
127 | | - uid => $uid, |
128 | | - } |
129 | | - |
130 | | - file { |
131 | | - default: |
132 | | - ensure => directory, |
133 | | - force => true, |
134 | | - purge => true, |
135 | | - recurse => true; |
136 | | - |
137 | | - '/opt/k8s': ; |
138 | | - '/opt/k8s/bin': ; |
139 | | - } |
140 | | - |
141 | | - file { '/var/run/kubernetes': |
142 | | - ensure => directory, |
143 | | - owner => $user, |
144 | | - group => $group, |
145 | | - } |
146 | | - |
147 | | - $_sysconfig_path = pick($sysconfig_path, '/etc/sysconfig') |
148 | | - file { "${_sysconfig_path}/kube-common": |
149 | | - ensure => file, |
150 | | - content => epp('k8s/sysconfig.epp', { |
151 | | - comment => 'General Kubernetes Configuration', |
152 | | - environment_variables => { |
153 | | - 'KUBE_LOG_LEVEL' => '', |
154 | | - }, |
155 | | - }), |
156 | | - } |
157 | | - |
158 | | - file { |
159 | | - default: |
160 | | - ensure => directory; |
161 | | - |
162 | | - '/etc/kubernetes': ; |
163 | | - '/etc/kubernetes/certs': ; |
164 | | - '/etc/kubernetes/manifests': |
165 | | - purge => $purge_manifests, |
166 | | - recurse => true; |
167 | | - '/root/.kube': ; |
168 | | - '/srv/kubernetes': |
169 | | - owner => $user, |
170 | | - group => $group; |
171 | | - '/usr/libexec/kubernetes': ; |
172 | | - '/var/lib/kubelet': ; |
173 | | - '/var/lib/kubelet/pki': ; |
174 | | - |
175 | | - '/usr/share/containers/': ; |
176 | | - '/usr/share/containers/oci/': ; |
177 | | - '/usr/share/containers/oci/hooks.d': ; |
178 | | - } |
179 | | - |
180 | | - if $manage_repo { |
181 | | - include k8s::repo |
182 | | - } |
183 | | - |
184 | | - if $manage_packages { |
185 | | - # Ensure conntrack is installed to properly handle networking cleanup |
186 | | - if fact('os.family') == 'Debian' { |
187 | | - $_conntrack = 'conntrack' |
188 | | - } else { |
189 | | - $_conntrack = 'conntrack-tools' |
190 | | - } |
191 | | - |
192 | | - ensure_packages([$_conntrack,]) |
193 | | - } |
194 | | - |
195 | | - include k8s::install::cni_plugins |
196 | | - |
197 | | - if $role == 'server' { |
198 | | - include k8s::server |
| 106 | + if $role == 'server' or $role == 'control-plane' { |
| 107 | + contain k8s::server |
199 | 108 | } elsif $role == 'node' { |
200 | | - include k8s::node |
| 109 | + contain k8s::node |
| 110 | + } elsif $role == 'etcd-replica' { |
| 111 | + contain k8s::server::etcd |
201 | 112 | } |
202 | 113 | } |
0 commit comments