You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

58 lines
1.8 KiB

  1. ---
  2. - name: sync_kube_master_certs | Create list of needed kube admin certs
  3. set_fact:
  4. kube_master_cert_list: "{{ kube_master_cert_list|d([]) + ['admin-' + item + '.pem'] }}"
  5. with_items: "{{ groups['kube-master'] }}"
  6. - include: ../../../vault/tasks/shared/sync_file.yml
  7. vars:
  8. sync_file: "{{ item }}"
  9. sync_file_dir: "{{ kube_cert_dir }}"
  10. sync_file_group: "{{ kube_cert_group }}"
  11. sync_file_hosts: "{{ groups['kube-master'] }}"
  12. sync_file_is_cert: true
  13. sync_file_owner: kube
  14. with_items: "{{ kube_master_cert_list|d([]) }}"
  15. - name: sync_kube_master_certs | Set facts for kube admin sync_file results
  16. set_fact:
  17. kube_master_certs_needed: "{{ kube_master_certs_needed|default([]) + [item.path] }}"
  18. with_items: "{{ sync_file_results|d([]) }}"
  19. when: item.no_srcs|bool
  20. - name: sync_kube_master_certs | Unset sync_file_results after kube admin certs
  21. set_fact:
  22. sync_file_results: []
  23. - include: ../../../vault/tasks/shared/sync_file.yml
  24. vars:
  25. sync_file: "apiserver.pem"
  26. sync_file_dir: "{{ kube_cert_dir }}"
  27. sync_file_group: "{{ kube_cert_group }}"
  28. sync_file_hosts: "{{ groups['kube-master'] }}"
  29. sync_file_is_cert: true
  30. sync_file_owner: kube
  31. - name: sync_kube_master_certs | Set facts for apiserver sync_file results
  32. set_fact:
  33. kube_api_certs_needed: "{{ item.path }}"
  34. with_items: "{{ sync_file_results|d([]) }}"
  35. when: "{{ item.no_srcs }}"
  36. - name: sync_kube_master_certs | Unset sync_file_results after apiserver cert
  37. set_fact:
  38. sync_file_results: []
  39. - include: ../../../vault/tasks/shared/sync_file.yml
  40. vars:
  41. sync_file: ca.pem
  42. sync_file_dir: "{{ kube_cert_dir }}"
  43. sync_file_group: "{{ kube_cert_group }}"
  44. sync_file_hosts: "{{ groups['kube-master'] }}"
  45. sync_file_owner: kube
  46. - name: sync_kube_master_certs | Unset sync_file_results after ca.pem
  47. set_fact:
  48. sync_file_results: []