You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

57 lines
2.0 KiB

  1. ---
  2. - name: sync_kube_master_certs | Create list of needed kube admin certs
  3. set_fact:
  4. kube_admin_cert_list: "{{ kube_admin_cert_list|d([]) + ['admin-' + inventory_hostname + '.pem'] }}"
  5. - include_tasks: ../../../vault/tasks/shared/sync_file.yml
  6. vars:
  7. sync_file: "{{ item }}"
  8. sync_file_dir: "{{ kube_cert_dir }}"
  9. sync_file_group: "{{ kube_cert_group }}"
  10. sync_file_hosts: [ "{{ inventory_hostname }}" ]
  11. sync_file_is_cert: true
  12. sync_file_owner: kube
  13. with_items: "{{ kube_admin_cert_list|d([]) }}"
  14. - name: sync_kube_master_certs | Set facts for kube admin sync_file results
  15. set_fact:
  16. kube_admin_certs_needed: "{{ kube_admin_certs_needed|default([]) + [item.path] }}"
  17. with_items: "{{ sync_file_results|d([]) }}"
  18. when: item.no_srcs|bool
  19. - name: sync_kube_master_certs | Unset sync_file_results after kube admin certs
  20. set_fact:
  21. sync_file_results: []
  22. - include_tasks: ../../../vault/tasks/shared/sync_file.yml
  23. vars:
  24. sync_file: "{{ item }}"
  25. sync_file_dir: "{{ kube_cert_dir }}"
  26. sync_file_group: "{{ kube_cert_group }}"
  27. sync_file_hosts: "{{ groups['kube-master'] }}"
  28. sync_file_is_cert: true
  29. sync_file_owner: kube
  30. with_items: ["apiserver.pem", "kube-scheduler.pem", "kube-controller-manager.pem"]
  31. - name: sync_kube_master_certs | Set facts for kube master components sync_file results
  32. set_fact:
  33. kube_master_components_certs_needed: "{{ kube_master_components_certs_needed|d([]) + [item.path] }}"
  34. with_items: "{{ sync_file_results|d([]) }}"
  35. when: item.no_srcs|bool
  36. - name: sync_kube_master_certs | Unset sync_file_results after kube master components cert
  37. set_fact:
  38. sync_file_results: []
  39. - include_tasks: ../../../vault/tasks/shared/sync_file.yml
  40. vars:
  41. sync_file: ca.pem
  42. sync_file_dir: "{{ kube_cert_dir }}"
  43. sync_file_group: "{{ kube_cert_group }}"
  44. sync_file_hosts: "{{ groups['kube-master'] }}"
  45. sync_file_owner: kube
  46. - name: sync_kube_master_certs | Unset sync_file_results after ca.pem
  47. set_fact:
  48. sync_file_results: []