-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathinit.sls
100 lines (91 loc) · 2.7 KB
/
init.sls
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
{% from "k3s/defaults.jinja" import settings with context %}
{# modify kernel settings for server workload #}
{# use external containerd to gain more customization possibilities, eg. using zfs #}
include:
- kernel.server
- containerd
{% if grains['virtual']|lower in ['lxc', 'systemd-nspawn'] %}
{# lxc and nspawn do not have kmsg available, symlink to console #}
/etc/tmpfiles.d/kmsg.conf:
file.managed:
- contents: |
# add symlink for missing kmsg to console
L /dev/kmsg - - - - /dev/console
cmd.run:
- name: systemd-tmpfiles --create
- onchanges:
- file: /etc/tmpfiles.d/kmsg.conf
- require_in:
- service: k3s
{% endif %}
k3s.env:
file.managed:
- name: {{ settings.env_file }}
- mode: 600
- contents: |
{%- if salt['pillar.get']('http_proxy')|d(false) %}
http_proxy="{{ salt['pillar.get']('http_proxy') }}"
HTTP_PROXY="{{ salt['pillar.get']('http_proxy') }}"
{%- endif %}
{%- if salt['pillar.get']('https_proxy')|d(false) %}
https_proxy="{{ salt['pillar.get']('https_proxy') }}"
HTTPS_PROXY="{{ salt['pillar.get']('https_proxy') }}"
{%- endif %}
{%- if salt['pillar.get']('no_proxy')|d(false) %}
no_proxy="{{ salt['pillar.get']('no_proxy', default_no_proxy) }}"
NO_PROXY="{{ salt['pillar.get']('no_proxy', default_no_proxy) }}"
{%- endif %}
k3s.config:
file.serialize:
- name: {{ settings.k3s_config_file }}
- dataset: {{ settings.config }}
- formatter: yaml
- makedirs: true
k3s.tools:
pkg.installed:
- pkgs:
- kubetail
k3s.binary:
file.managed:
- name: {{ settings.external.k3s.target }}
- source: {{ settings.external.k3s.download }}
- source_hash: {{ settings.external.k3s.hash_url }}
- mode: "755"
- require:
- sls: kernel.server
- pkg: k3s.tools
k3s.service:
file.managed:
- name: /etc/systemd/system/k3s.service
- source: salt://k3s/k3s.service
- defaults:
settings: {{ settings }}
- template: jinja
cmd.run:
- name: systemctl daemon-reload
- onchanges:
- file: k3s.service
service.running:
- enable: true
- require:
- sls: containerd
- watch:
- file: k3s.env
- file: k3s.config
- file: k3s.binary
- file: k3s.service
{%- if settings.admin['copy-kubeconfig'] %}
{%- set admin_home= salt['user.info'](settings.admin.user)['home'] %}
admin.kube.config:
file.copy:
- source: {{ settings.config['write-kubeconfig'] }}
- name: {{ admin_home }}/.kube/config
- user: {{ settings.admin.user }}
- group: {{ settings.admin.user }}
- filemode: "0600"
- dirmode: "0700"
- makedirs: true
- force: true
- require:
- service: k3s.service
{%- endif %}