Compare commits

...
3 Commits
2 changed files with 161 additions and 9 deletions
+132
View File
@@ -0,0 +1,132 @@
- name: Install Kubernetes
hosts: kubernetes
become: true
tasks:
- name: Disable swap
command: swapoff -a
- name: Comment out swap entries in /etc/fstab
replace:
path: /etc/fstab
regexp: '^([^#].*\sswap\s.*)$'
replace: '#\1'
- name: Remove conflicting packages
apt:
name:
- docker.io
- docker-compose
- docker-compose-v2
- docker-doc
- podman-docker
- containerd
- runc
state: absent
purge: true
autoremove: true
- name: Update and upgrade apt packages
apt:
update_cache: true
upgrade: dist
- name: Install prerequisites
apt:
name:
- ca-certificates
- curl
- apt-transport-https
- gpg
state: present
- name: Create /etc/apt/keyrings directory
file:
path: /etc/apt/keyrings
state: directory
mode: '0755'
- name: Download Docker GPG key
get_url:
url: https://download.docker.com/linux/ubuntu/gpg
dest: /etc/apt/keyrings/docker.asc
mode: '0644'
- name: Get Ubuntu codename
shell: ". /etc/os-release && echo \"${UBUNTU_CODENAME:-$VERSION_CODENAME}\""
register: ubuntu_codename
changed_when: false
- name: Add Docker apt repository
copy:
dest: /etc/apt/sources.list.d/docker.sources
content: |
Types: deb
URIs: https://download.docker.com/linux/ubuntu
Suites: {{ ubuntu_codename.stdout }}
Components: stable
Signed-By: /etc/apt/keyrings/docker.asc
- name: Download Kubernetes GPG key
shell: >
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.35/deb/Release.key |
gpg --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
args:
creates: /etc/apt/keyrings/kubernetes-apt-keyring.gpg
- name: Add Kubernetes apt repository
copy:
dest: /etc/apt/sources.list.d/kubernetes.list
content: "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.35/deb/ /\n"
- name: Update apt cache
apt:
update_cache: true
- name: Install Docker and Kubernetes packages
apt:
name:
- docker-ce
- docker-ce-cli
- containerd.io
- docker-buildx-plugin
- docker-compose-plugin
- kubelet
- kubeadm
- kubectl
state: present
- name: Hold kubelet, kubeadm, kubectl at current version
dpkg_selections:
name: "{{ item }}"
selection: hold
loop:
- kubelet
- kubeadm
- kubectl
- name: Generate default containerd config
shell: containerd config default > /etc/containerd/config.toml
args:
creates: /etc/containerd/config.toml
- name: Restart containerd
systemd:
name: containerd
state: restarted
- name: Enable and start Docker
systemd:
name: docker
enabled: true
state: started
- name: Enable and start kubelet
systemd:
name: kubelet
enabled: true
state: started
- name: Run hello-world Docker test
command: docker run hello-world
changed_when: false
+29 -9
View File
@@ -1,12 +1,11 @@
- name: Update checkmk on monitoring hosts - name: Gather latest checkmk version
hosts: sites hosts: all
become: true
tasks: tasks:
# cannot be done with git module. It has no method to query the tags of a repo # cannot be done with git module. It has no method to query the tags of a repo
- name: Get latest checkmk version # noqa: run-once[task] command-instead-of-module - name: Get latest checkmk version # noqa: run-once[task] command-instead-of-module
register: checkmk_version register: checkmk_version
run_once: true delegate_to: localhost
changed_when: false changed_when: false
ansible.builtin.shell: ansible.builtin.shell:
executable: /bin/bash executable: /bin/bash
@@ -23,6 +22,16 @@
ansible.builtin.debug: ansible.builtin.debug:
var: checkmk_version.stdout var: checkmk_version.stdout
- name: Set checkmk version fact # noqa: run-once[task]
run_once: true
ansible.builtin.set_fact:
checkmk_version: "{{ checkmk_version.stdout }}"
- name: Update checkmk on monitoring hosts
hosts: sites
become: true
tasks:
- name: Snapshot VM before update - name: Snapshot VM before update
become: false become: false
delegate_to: localhost delegate_to: localhost
@@ -33,16 +42,17 @@
api_token_secret: "{{ proxmox_api_token_secret }}" api_token_secret: "{{ proxmox_api_token_secret }}"
validate_certs: false validate_certs: false
hostname: "{{ inventory_hostname_short }}" hostname: "{{ inventory_hostname_short }}"
snapname: "checkmk_{{ checkmk_version.stdout | replace('.', '_') | replace('-', '_') }}" snapname: "checkmk_{{ checkmk_version | replace('.', '_') | replace('-', '_') }}"
description: "Pre-update snapshot before checkmk {{ checkmk_version.stdout }}" description: "Pre-update snapshot before checkmk {{ checkmk_version }}"
timeout: 120 timeout: 120
state: present state: present
- name: Install new checkmk version - name: Install new checkmk version
vars: vars:
filename: "check-mk-raw-{{ checkmk_version.stdout }}_0.{{ ansible_facts.lsb.codename }}_amd64.deb" checkmk_edition: community
filename: "check-mk-{{ checkmk_edition }}-{{ checkmk_version }}_0.{{ ansible_facts.lsb.codename }}_amd64.deb"
ansible.builtin.apt: ansible.builtin.apt:
deb: "https://download.checkmk.com/checkmk/{{ checkmk_version.stdout }}/{{ filename }}" deb: "https://download.checkmk.com/checkmk/{{ checkmk_version }}/{{ filename }}"
when: ansible_facts.lsb.id == 'Ubuntu' when: ansible_facts.lsb.id == 'Ubuntu'
- name: Stop omd sites - name: Stop omd sites
@@ -51,7 +61,7 @@
loop: "{{ checkmk_sites }}" loop: "{{ checkmk_sites }}"
ansible.builtin.command: "omd stop {{ item }}" ansible.builtin.command: "omd stop {{ item }}"
- name: Create backup of site (/tmp/backup-{ item }.tar.gz) - name: Create Site backups
changed_when: true changed_when: true
loop: "{{ checkmk_sites }}" loop: "{{ checkmk_sites }}"
ansible.builtin.command: "omd backup {{ item }} /tmp/backup-{{ item }}.tar.gz" ansible.builtin.command: "omd backup {{ item }} /tmp/backup-{{ item }}.tar.gz"
@@ -66,3 +76,13 @@
changed_when: start_cmd.rc == 0 changed_when: start_cmd.rc == 0
loop: "{{ checkmk_sites }}" loop: "{{ checkmk_sites }}"
ansible.builtin.command: "omd start {{ item }}" ansible.builtin.command: "omd start {{ item }}"
- name: Update checkmk agents on monitored hosts
hosts: agents
become: true
tasks:
- name: Install new checkmk agent
ansible.builtin.apt:
deb: "https://checkmk.stuyckv.com/local/check_mk/agents/check-mk-agent_{{ checkmk_version }}-1_all.deb"
when: ansible_facts.lsb.id == 'Ubuntu'