You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

38 lines
1.2 KiB

  1. ---
  2. - name: sync_kube_node_certs | Create list of needed certs
  3. set_fact:
  4. kube_node_cert_list: "{{ kube_node_cert_list|default([]) + ['node-' + item + '.pem'] }}"
  5. with_items: "{{ groups['k8s-cluster'] }}"
  6. - include: ../../../vault/tasks/shared/sync_file.yml
  7. vars:
  8. sync_file: "{{ item }}"
  9. sync_file_dir: "{{ kube_cert_dir }}"
  10. sync_file_group: "{{ kuber_cert_group }}"
  11. sync_file_hosts: "{{ groups['k8s-cluster'] }}"
  12. sync_file_is_cert: true
  13. sync_file_owner: kube
  14. with_items: "{{ kube_node_cert_list|default([]) }}"
  15. - name: sync_kube_node_certs | Set facts for kube-master sync_file results
  16. set_fact:
  17. kube_node_certs_needed: "{{ kube_node_certs_needed|default([]) + [item.path] }}"
  18. with_items: "{{ sync_file_results|d([]) }}"
  19. when: item.no_srcs|bool
  20. - name: sync_kube_node_certs | Unset sync_file_results after kube node certs
  21. set_fact:
  22. sync_file_results: []
  23. - include: ../../../vault/tasks/shared/sync_file.yml
  24. vars:
  25. sync_file: ca.pem
  26. sync_file_dir: "{{ kube_cert_dir }}"
  27. sync_file_group: "{{ kuber_cert_group }}"
  28. sync_file_hosts: "{{ groups['k8s-cluster'] }}"
  29. sync_file_owner: kube
  30. - name: sync_kube_node_certs | Unset sync_file_results after ca.pem
  31. set_fact:
  32. sync_file_results: []