feat(infra): add cert-manager role and setup playbook
Introduce cert-manager role and a dedicated playbook for automated certificate management setup, complementing the newly restructured uyuni role for comprehensive infrastructure automation.
This commit is contained in:
parent
f30e4cf00d
commit
45a7ea0d93
9 changed files with 264 additions and 0 deletions
6
playbooks/setup_cert_manager.yml
Normal file
6
playbooks/setup_cert_manager.yml
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
---
|
||||||
|
- name: Deploy cert-manager
|
||||||
|
hosts: manager_nodes
|
||||||
|
become: true
|
||||||
|
roles:
|
||||||
|
- cert_manager
|
||||||
10
roles/cert_manager/defaults/main.yml
Normal file
10
roles/cert_manager/defaults/main.yml
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
---
|
||||||
|
cert_manager_namespace: cert-manager
|
||||||
|
cert_manager_kubeconfig: "/home/{{ ansible_user }}/.kube/config"
|
||||||
|
cert_manager_chart_version: "1.16.2"
|
||||||
|
|
||||||
|
cert_manager_crds_version: "v1.16.0"
|
||||||
|
|
||||||
|
cert_manager_use_helm: true
|
||||||
|
|
||||||
|
cert_manager_args: []
|
||||||
43
roles/cert_manager/tasks/helm.yml
Normal file
43
roles/cert_manager/tasks/helm.yml
Normal file
|
|
@ -0,0 +1,43 @@
|
||||||
|
---
|
||||||
|
- name: Helm | Add Jetstack chart repository
|
||||||
|
ansible.builtin.command: helm repo add jetstack https://charts.jetstack.io
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ cert_manager_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
register: _helm_repo_add
|
||||||
|
changed_when: "'already exists' not in _helm_repo_add.stdout"
|
||||||
|
failed_when: _helm_repo_add.rc != 0 and 'already exists' not in _helm_repo_add.stdout
|
||||||
|
|
||||||
|
- name: Helm | Update chart repositories
|
||||||
|
ansible.builtin.command: helm repo update
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ cert_manager_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Helm | Install or upgrade cert-manager CRDs
|
||||||
|
ansible.builtin.command: >
|
||||||
|
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/{{ cert_manager_crds_version }}/cert-manager.crds.yaml
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ cert_manager_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
register: _cert_manager_crds
|
||||||
|
changed_when: false
|
||||||
|
failed_when: _cert_manager_crds.rc != 0
|
||||||
|
|
||||||
|
- name: Helm | Install or upgrade cert-manager
|
||||||
|
ansible.builtin.command: >
|
||||||
|
helm upgrade --install cert-manager jetstack/cert-manager
|
||||||
|
--namespace {{ cert_manager_namespace }}
|
||||||
|
--create-namespace
|
||||||
|
--version {{ cert_manager_chart_version }}
|
||||||
|
{% if cert_manager_args is defined and cert_manager_args | length > 0 %}
|
||||||
|
--set args[0]={{ cert_manager_args[0] }}
|
||||||
|
{% endif %}
|
||||||
|
--timeout 10m0s
|
||||||
|
--wait
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ cert_manager_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
register: _helm_install
|
||||||
|
changed_when: "'STATUS: deployed' in _helm_install.stdout or 'has been upgraded' in _helm_install.stdout"
|
||||||
3
roles/cert_manager/tasks/main.yml
Normal file
3
roles/cert_manager/tasks/main.yml
Normal file
|
|
@ -0,0 +1,3 @@
|
||||||
|
---
|
||||||
|
- name: Deploy cert-manager via Helm
|
||||||
|
ansible.builtin.include_tasks: helm.yml
|
||||||
29
roles/uyuni/README.md
Normal file
29
roles/uyuni/README.md
Normal file
|
|
@ -0,0 +1,29 @@
|
||||||
|
# Uyuni Helm Installation Role
|
||||||
|
|
||||||
|
This role installs Uyuni using Helm charts.
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- Helm must be installed on the target system
|
||||||
|
- Kubernetes cluster access configured via kubeconfig
|
||||||
|
|
||||||
|
## Role Variables
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
uyuni_namespace: uyuni
|
||||||
|
uyuni_chart_version: 0.1.0
|
||||||
|
uyuni_kubeconfig: /path/to/kubeconfig
|
||||||
|
uyuni_helm_values: {}
|
||||||
|
```
|
||||||
|
|
||||||
|
## Example Playbook
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- hosts: servers
|
||||||
|
roles:
|
||||||
|
- uyuni
|
||||||
|
```
|
||||||
|
|
||||||
|
## License
|
||||||
|
|
||||||
|
MIT
|
||||||
13
roles/uyuni/defaults/main.yml
Normal file
13
roles/uyuni/defaults/main.yml
Normal file
|
|
@ -0,0 +1,13 @@
|
||||||
|
---
|
||||||
|
# role defaults
|
||||||
|
uyuni_namespace: uyuni-server
|
||||||
|
uyuni_chart_version: 2026.6.0
|
||||||
|
uyuni_kubeconfig: /root/.kube/config
|
||||||
|
uyuni_helm_values:
|
||||||
|
global.fqdn: null
|
||||||
|
uyuni_tls_cert: null
|
||||||
|
uyuni_tls_key: null
|
||||||
|
db_tls_cert: null
|
||||||
|
db_tls_key: null
|
||||||
|
uyuni_ca_cert: null
|
||||||
|
db_ca_cert: null
|
||||||
32
roles/uyuni/files/uyuni/server-helm/README.md
Normal file
32
roles/uyuni/files/uyuni/server-helm/README.md
Normal file
|
|
@ -0,0 +1,32 @@
|
||||||
|
# Uyuni Helm Chart Configuration
|
||||||
|
|
||||||
|
This directory contains the Uyuni Helm chart and configuration files.
|
||||||
|
|
||||||
|
## Chart Location
|
||||||
|
|
||||||
|
The Uyuni Helm chart is located at: `uyuni/uyuni-server`
|
||||||
|
|
||||||
|
## Custom Values
|
||||||
|
|
||||||
|
You can customize the installation by modifying the values in your Ansible playbook:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
uyuni_helm_values:
|
||||||
|
server:
|
||||||
|
hostname: uyuni.example.com
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "4Gi"
|
||||||
|
cpu: "2"
|
||||||
|
limits:
|
||||||
|
memory: "8Gi"
|
||||||
|
cpu: "4"
|
||||||
|
database:
|
||||||
|
type: internal
|
||||||
|
proxy:
|
||||||
|
enabled: false
|
||||||
|
```
|
||||||
|
|
||||||
|
## Documentation
|
||||||
|
|
||||||
|
For detailed configuration options, see the [Uyuni Helm Chart documentation](https://github.com/uyuni-project/uyuni-helm).
|
||||||
64
roles/uyuni/tasks/helm.yml
Normal file
64
roles/uyuni/tasks/helm.yml
Normal file
|
|
@ -0,0 +1,64 @@
|
||||||
|
---
|
||||||
|
- name: Helm | Install or upgrade Uyuni from OCI registry
|
||||||
|
ansible.builtin.command: >
|
||||||
|
helm upgrade --install uyuni-server oci://registry.opensuse.org/uyuni/server-helm
|
||||||
|
--namespace {{ uyuni_namespace }}
|
||||||
|
--create-namespace
|
||||||
|
--version {{ uyuni_chart_version }}
|
||||||
|
--set {{ item.key }}={{ item.value }}
|
||||||
|
--timeout 20m0s
|
||||||
|
--wait
|
||||||
|
loop: "{{ uyuni_helm_values | dict2items }}"
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ uyuni_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
register: _helm_install
|
||||||
|
changed_when: "'STATUS: deployed' in _helm_install.stdout or 'has been upgraded' in _helm_install.stdout"
|
||||||
|
when: uyuni_helm_values is defined
|
||||||
|
|
||||||
|
- name: Helm | Install or upgrade Uyuni from OCI registry (no values)
|
||||||
|
ansible.builtin.command: >
|
||||||
|
helm upgrade --install uyuni-server oci://registry.opensuse.org/uyuni/server-helm
|
||||||
|
--namespace {{ uyuni_namespace }}
|
||||||
|
--create-namespace
|
||||||
|
--version {{ uyuni_chart_version }}
|
||||||
|
--timeout 20m0s
|
||||||
|
--wait
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ uyuni_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
register: _helm_install_simple
|
||||||
|
changed_when: "'STATUS: deployed' in _helm_install_simple.stdout or 'has been upgraded' in _helm_install_simple.stdout"
|
||||||
|
when: uyuni_helm_values is not defined
|
||||||
|
|
||||||
|
- name: Helm | Install or upgrade Uyuni
|
||||||
|
ansible.builtin.command: >
|
||||||
|
helm upgrade --install uyuni-server uyuni/uyuni-server
|
||||||
|
--namespace {{ uyuni_namespace }}
|
||||||
|
--create-namespace
|
||||||
|
--version {{ uyuni_chart_version }}
|
||||||
|
--set {{ item.key }}={{ item.value }}
|
||||||
|
--timeout 20m0s
|
||||||
|
--wait
|
||||||
|
loop: "{{ uyuni_helm_values | dict2items }}"
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ uyuni_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
register: _helm_install
|
||||||
|
changed_when: "'STATUS: deployed' in _helm_install.stdout or 'has been upgraded' in _helm_install.stdout"
|
||||||
|
when: uyuni_helm_values is defined
|
||||||
|
|
||||||
|
- name: Helm | Install or upgrade Uyuni (no values)
|
||||||
|
ansible.builtin.command: >
|
||||||
|
helm upgrade --install uyuni-server uyuni/uyuni-server
|
||||||
|
--namespace {{ uyuni_namespace }}
|
||||||
|
--create-namespace
|
||||||
|
--version {{ uyuni_chart_version }}
|
||||||
|
--timeout 20m0s
|
||||||
|
--wait
|
||||||
|
environment:
|
||||||
|
KUBECONFIG: "{{ uyuni_kubeconfig }}"
|
||||||
|
PATH: "/usr/local/bin:/usr/bin:/bin"
|
||||||
|
register: _helm_install_simple
|
||||||
|
changed_when: "'STATUS: deployed' in _helm_install_simple.stdout or 'has been upgraded' in _helm_install_simple.stdout"
|
||||||
|
when: uyuni_helm_values is not defined
|
||||||
64
roles/uyuni/tasks/main.yml
Normal file
64
roles/uyuni/tasks/main.yml
Normal file
|
|
@ -0,0 +1,64 @@
|
||||||
|
---
|
||||||
|
- name: Create namespace
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
api_version: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: "{{ uyuni_namespace }}"
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Create uyuni TLS certificate secret
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
api_version: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: uyuni-cert
|
||||||
|
namespace: "{{ uyuni_namespace }}"
|
||||||
|
type: kubernetes.io/tls
|
||||||
|
data:
|
||||||
|
tls.crt: "{{ uyuni_tls_cert | b64encode }}"
|
||||||
|
tls.key: "{{ uyuni_tls_key | b64encode }}"
|
||||||
|
state: present
|
||||||
|
when: uyuni_tls_cert is defined and uyuni_tls_key is defined
|
||||||
|
|
||||||
|
- name: Create database TLS certificate secret
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
api_version: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: db-cert
|
||||||
|
namespace: "{{ uyuni_namespace }}"
|
||||||
|
type: kubernetes.io/tls
|
||||||
|
data:
|
||||||
|
tls.crt: "{{ db_tls_cert | b64encode }}"
|
||||||
|
tls.key: "{{ db_tls_key | b64encode }}"
|
||||||
|
state: present
|
||||||
|
when: db_tls_cert is defined and db_tls_key is defined
|
||||||
|
|
||||||
|
- name: Create uyuni CA ConfigMap
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
api_version: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: uyuni-ca
|
||||||
|
namespace: "{{ uyuni_namespace }}"
|
||||||
|
data:
|
||||||
|
ca.crt: "{{ uyuni_ca_cert | string }}"
|
||||||
|
state: present
|
||||||
|
when: uyuni_ca_cert is defined
|
||||||
|
|
||||||
|
- name: Create database CA ConfigMap
|
||||||
|
kubernetes.core.k8s:
|
||||||
|
api_version: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: db-ca
|
||||||
|
namespace: "{{ uyuni_namespace }}"
|
||||||
|
data:
|
||||||
|
ca.crt: "{{ db_ca_cert | string }}"
|
||||||
|
state: present
|
||||||
|
when: db_ca_cert is defined
|
||||||
|
|
||||||
|
- name: Include Helm installation
|
||||||
|
ansible.builtin.include_tasks: helm.yml
|
||||||
|
run_once: true
|
||||||
Loading…
Reference in a new issue