You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

779 lines
18 KiB

8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
contiv network support (#1914) * Add Contiv support Contiv is a network plugin for Kubernetes and Docker. It supports vlan/vxlan/BGP/Cisco ACI technologies. It support firewall policies, multiple networks and bridging pods onto physical networks. * Update contiv version to 1.1.4 Update contiv version to 1.1.4 and added SVC_SUBNET in contiv-config. * Load openvswitch module to workaround on CentOS7.4 * Set contiv cni version to 0.1.0 Correct contiv CNI version to 0.1.0. * Use kube_apiserver_endpoint for K8S_API_SERVER Use kube_apiserver_endpoint as K8S_API_SERVER to make contiv talks to a available endpoint no matter if there's a loadbalancer or not. * Make contiv use its own etcd Before this commit, contiv is using a etcd proxy mode to k8s etcd, this work fine when the etcd hosts are co-located with contiv etcd proxy, however the k8s peering certs are only in etcd group, as a result the etcd-proxy is not able to peering with the k8s etcd on etcd group, plus the netplugin is always trying to find the etcd endpoint on localhost, this will cause problem for all netplugins not runnign on etcd group nodes. This commit make contiv uses its own etcd, separate from k8s one. on kube-master nodes (where net-master runs), it will run as leader mode and on all rest nodes it will run as proxy mode. * Use cp instead of rsync to copy cni binaries Since rsync has been removed from hyperkube, this commit changes it to use cp instead. * Make contiv-etcd able to run on master nodes * Add rbac_enabled flag for contiv pods * Add contiv into CNI network plugin lists * migrate contiv test to tests/files Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com> * Add required rules for contiv netplugin * Better handling json return of fwdMode * Make contiv etcd port configurable * Use default var instead of templating * roles/download/defaults/main.yml: use contiv 1.1.7 Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com>
7 years ago
contiv network support (#1914) * Add Contiv support Contiv is a network plugin for Kubernetes and Docker. It supports vlan/vxlan/BGP/Cisco ACI technologies. It support firewall policies, multiple networks and bridging pods onto physical networks. * Update contiv version to 1.1.4 Update contiv version to 1.1.4 and added SVC_SUBNET in contiv-config. * Load openvswitch module to workaround on CentOS7.4 * Set contiv cni version to 0.1.0 Correct contiv CNI version to 0.1.0. * Use kube_apiserver_endpoint for K8S_API_SERVER Use kube_apiserver_endpoint as K8S_API_SERVER to make contiv talks to a available endpoint no matter if there's a loadbalancer or not. * Make contiv use its own etcd Before this commit, contiv is using a etcd proxy mode to k8s etcd, this work fine when the etcd hosts are co-located with contiv etcd proxy, however the k8s peering certs are only in etcd group, as a result the etcd-proxy is not able to peering with the k8s etcd on etcd group, plus the netplugin is always trying to find the etcd endpoint on localhost, this will cause problem for all netplugins not runnign on etcd group nodes. This commit make contiv uses its own etcd, separate from k8s one. on kube-master nodes (where net-master runs), it will run as leader mode and on all rest nodes it will run as proxy mode. * Use cp instead of rsync to copy cni binaries Since rsync has been removed from hyperkube, this commit changes it to use cp instead. * Make contiv-etcd able to run on master nodes * Add rbac_enabled flag for contiv pods * Add contiv into CNI network plugin lists * migrate contiv test to tests/files Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com> * Add required rules for contiv netplugin * Better handling json return of fwdMode * Make contiv etcd port configurable * Use default var instead of templating * roles/download/defaults/main.yml: use contiv 1.1.7 Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com>
7 years ago
6 years ago
8 years ago
6 years ago
8 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
  1. stages:
  2. - unit-tests
  3. - moderator
  4. - deploy-part1
  5. - deploy-part2
  6. - deploy-special
  7. variables:
  8. FAILFASTCI_NAMESPACE: 'kargo-ci'
  9. GITLAB_REPOSITORY: 'kargo-ci/kubernetes-incubator__kubespray'
  10. # DOCKER_HOST: tcp://localhost:2375
  11. ANSIBLE_FORCE_COLOR: "true"
  12. MAGIC: "ci check this"
  13. TEST_ID: "$CI_PIPELINE_ID-$CI_BUILD_ID"
  14. CI_TEST_VARS: "./tests/files/${CI_JOB_NAME}.yml"
  15. GS_ACCESS_KEY_ID: $GS_KEY
  16. GS_SECRET_ACCESS_KEY: $GS_SECRET
  17. CONTAINER_ENGINE: docker
  18. SSH_USER: root
  19. GCE_PREEMPTIBLE: "false"
  20. ANSIBLE_KEEP_REMOTE_FILES: "1"
  21. ANSIBLE_CONFIG: ./tests/ansible.cfg
  22. ANSIBLE_INVENTORY: ./inventory/sample/${CI_JOB_NAME}-${BUILD_NUMBER}.ini
  23. IDEMPOT_CHECK: "false"
  24. RESET_CHECK: "false"
  25. UPGRADE_TEST: "false"
  26. KUBEADM_ENABLED: "false"
  27. LOG_LEVEL: "-vv"
  28. # asia-east1-a
  29. # asia-northeast1-a
  30. # europe-west1-b
  31. # us-central1-a
  32. # us-east1-b
  33. # us-west1-a
  34. before_script:
  35. - /usr/bin/python -m pip install -r tests/requirements.txt
  36. - mkdir -p /.ssh
  37. .job: &job
  38. tags:
  39. - kubernetes
  40. - docker
  41. image: quay.io/kubespray/kubespray:v2.7
  42. .docker_service: &docker_service
  43. services:
  44. - docker:dind
  45. .create_cluster: &create_cluster
  46. <<: *job
  47. <<: *docker_service
  48. .gce_variables: &gce_variables
  49. GCE_USER: travis
  50. SSH_USER: $GCE_USER
  51. CLOUD_MACHINE_TYPE: "g1-small"
  52. CI_PLATFORM: "gce"
  53. PRIVATE_KEY: $GCE_PRIVATE_KEY
  54. .do_variables: &do_variables
  55. PRIVATE_KEY: $DO_PRIVATE_KEY
  56. CI_PLATFORM: "do"
  57. SSH_USER: root
  58. .testcases: &testcases
  59. <<: *job
  60. <<: *docker_service
  61. cache:
  62. key: "$CI_BUILD_REF_NAME"
  63. paths:
  64. - downloads/
  65. - $HOME/.cache
  66. before_script:
  67. - docker info
  68. - /usr/bin/python -m pip install -r requirements.txt
  69. - /usr/bin/python -m pip install -r tests/requirements.txt
  70. - mkdir -p /.ssh
  71. - mkdir -p $HOME/.ssh
  72. - ansible-playbook --version
  73. - export PYPATH=$([[ ! "$CI_JOB_NAME" =~ "coreos" ]] && echo /usr/bin/python || echo /opt/bin/python)
  74. - echo "CI_JOB_NAME is $CI_JOB_NAME"
  75. - echo "PYPATH is $PYPATH"
  76. script:
  77. - pwd
  78. - ls
  79. - echo ${PWD}
  80. - echo "${STARTUP_SCRIPT}"
  81. - cd tests && make create-${CI_PLATFORM} -s ; cd -
  82. # Check out latest tag if testing upgrade
  83. # Uncomment when gitlab kubespray repo has tags
  84. #- test "${UPGRADE_TEST}" != "false" && git fetch --all && git checkout $(git describe --tags $(git rev-list --tags --max-count=1))
  85. - test "${UPGRADE_TEST}" != "false" && git checkout 53d87e53c5899d4ea2904ab7e3883708dd6363d3
  86. # Checkout the CI vars file so it is available
  87. - test "${UPGRADE_TEST}" != "false" && git checkout "${CI_BUILD_REF}" tests/files/${CI_JOB_NAME}.yml
  88. # Workaround https://github.com/kubernetes-incubator/kubespray/issues/2021
  89. - 'sh -c "echo ignore_assert_errors: true | tee -a tests/files/${CI_JOB_NAME}.yml"'
  90. # Create cluster
  91. - >
  92. ansible-playbook
  93. -i ${ANSIBLE_INVENTORY}
  94. -b --become-user=root
  95. --private-key=${HOME}/.ssh/id_rsa
  96. -u $SSH_USER
  97. ${SSH_ARGS}
  98. ${LOG_LEVEL}
  99. -e @${CI_TEST_VARS}
  100. -e ansible_ssh_user=${SSH_USER}
  101. -e local_release_dir=${PWD}/downloads
  102. --limit "all:!fake_hosts"
  103. cluster.yml
  104. # Repeat deployment if testing upgrade
  105. - >
  106. if [ "${UPGRADE_TEST}" != "false" ]; then
  107. test "${UPGRADE_TEST}" == "basic" && PLAYBOOK="cluster.yml";
  108. test "${UPGRADE_TEST}" == "graceful" && PLAYBOOK="upgrade-cluster.yml";
  109. git checkout "${CI_BUILD_REF}";
  110. ansible-playbook
  111. -i ${ANSIBLE_INVENTORY}
  112. -b --become-user=root
  113. --private-key=${HOME}/.ssh/id_rsa
  114. -u $SSH_USER
  115. ${SSH_ARGS}
  116. ${LOG_LEVEL}
  117. -e @${CI_TEST_VARS}
  118. -e ansible_ssh_user=${SSH_USER}
  119. -e local_release_dir=${PWD}/downloads
  120. --limit "all:!fake_hosts"
  121. $PLAYBOOK;
  122. fi
  123. # Tests Cases
  124. ## Test Master API
  125. - >
  126. ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/010_check-apiserver.yml $LOG_LEVEL
  127. -e "{kubeadm_enabled: ${KUBEADM_ENABLED}}"
  128. ## Ping the between 2 pod
  129. - ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/030_check-network.yml $LOG_LEVEL
  130. ## Advanced DNS checks
  131. - ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/040_check-network-adv.yml $LOG_LEVEL
  132. ## Idempotency checks 1/5 (repeat deployment)
  133. - >
  134. if [ "${IDEMPOT_CHECK}" = "true" ]; then
  135. ansible-playbook
  136. -i ${ANSIBLE_INVENTORY}
  137. -b --become-user=root
  138. --private-key=${HOME}/.ssh/id_rsa
  139. -u $SSH_USER
  140. ${SSH_ARGS}
  141. ${LOG_LEVEL}
  142. -e @${CI_TEST_VARS}
  143. -e ansible_python_interpreter=${PYPATH}
  144. -e local_release_dir=${PWD}/downloads
  145. --limit "all:!fake_hosts"
  146. cluster.yml;
  147. fi
  148. ## Idempotency checks 2/5 (Advanced DNS checks)
  149. - >
  150. if [ "${IDEMPOT_CHECK}" = "true" ]; then
  151. ansible-playbook
  152. -i ${ANSIBLE_INVENTORY}
  153. -b --become-user=root
  154. --private-key=${HOME}/.ssh/id_rsa
  155. -u $SSH_USER
  156. ${SSH_ARGS}
  157. ${LOG_LEVEL}
  158. -e @${CI_TEST_VARS}
  159. --limit "all:!fake_hosts"
  160. tests/testcases/040_check-network-adv.yml $LOG_LEVEL;
  161. fi
  162. ## Idempotency checks 3/5 (reset deployment)
  163. - >
  164. if [ "${IDEMPOT_CHECK}" = "true" -a "${RESET_CHECK}" = "true" ]; then
  165. ansible-playbook
  166. -i ${ANSIBLE_INVENTORY}
  167. -b --become-user=root
  168. --private-key=${HOME}/.ssh/id_rsa
  169. -u $SSH_USER
  170. ${SSH_ARGS}
  171. ${LOG_LEVEL}
  172. -e @${CI_TEST_VARS}
  173. -e ansible_python_interpreter=${PYPATH}
  174. -e reset_confirmation=yes
  175. --limit "all:!fake_hosts"
  176. reset.yml;
  177. fi
  178. ## Idempotency checks 4/5 (redeploy after reset)
  179. - >
  180. if [ "${IDEMPOT_CHECK}" = "true" -a "${RESET_CHECK}" = "true" ]; then
  181. ansible-playbook
  182. -i ${ANSIBLE_INVENTORY}
  183. -b --become-user=root
  184. --private-key=${HOME}/.ssh/id_rsa
  185. -u $SSH_USER
  186. ${SSH_ARGS}
  187. ${LOG_LEVEL}
  188. -e @${CI_TEST_VARS}
  189. -e ansible_python_interpreter=${PYPATH}
  190. -e local_release_dir=${PWD}/downloads
  191. --limit "all:!fake_hosts"
  192. cluster.yml;
  193. fi
  194. ## Idempotency checks 5/5 (Advanced DNS checks)
  195. - >
  196. if [ "${IDEMPOT_CHECK}" = "true" -a "${RESET_CHECK}" = "true" ]; then
  197. ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH}
  198. -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root
  199. --limit "all:!fake_hosts"
  200. tests/testcases/040_check-network-adv.yml $LOG_LEVEL;
  201. fi
  202. after_script:
  203. - cd tests && make delete-${CI_PLATFORM} -s ; cd -
  204. .gce: &gce
  205. <<: *testcases
  206. variables:
  207. <<: *gce_variables
  208. .do: &do
  209. variables:
  210. <<: *do_variables
  211. <<: *testcases
  212. # Test matrix. Leave the comments for markup scripts.
  213. .coreos_calico_aio_variables: &coreos_calico_aio_variables
  214. # stage: deploy-part1
  215. MOVED_TO_GROUP_VARS: "true"
  216. .ubuntu18_flannel_aio_variables: &ubuntu18_flannel_aio_variables
  217. # stage: deploy-part1
  218. MOVED_TO_GROUP_VARS: "true"
  219. .ubuntu_canal_ha_variables: &ubuntu_canal_ha_variables
  220. # stage: deploy-part1
  221. UPGRADE_TEST: "graceful"
  222. .centos_weave_kubeadm_variables: &centos_weave_kubeadm_variables
  223. # stage: deploy-part1
  224. UPGRADE_TEST: "graceful"
  225. .ubuntu_canal_kubeadm_variables: &ubuntu_canal_kubeadm_variables
  226. # stage: deploy-part1
  227. MOVED_TO_GROUP_VARS: "true"
  228. .ubuntu_contiv_sep_variables: &ubuntu_contiv_sep_variables
  229. # stage: deploy-special
  230. MOVED_TO_GROUP_VARS: "true"
  231. .coreos_cilium_variables: &coreos_cilium_variables
  232. # stage: deploy-special
  233. MOVED_TO_GROUP_VARS: "true"
  234. .ubuntu_cilium_sep_variables: &ubuntu_cilium_sep_variables
  235. # stage: deploy-special
  236. MOVED_TO_GROUP_VARS: "true"
  237. .rhel7_weave_variables: &rhel7_weave_variables
  238. # stage: deploy-part1
  239. MOVED_TO_GROUP_VARS: "true"
  240. .centos7_flannel_addons_variables: &centos7_flannel_addons_variables
  241. # stage: deploy-part2
  242. MOVED_TO_GROUP_VARS: "true"
  243. .debian8_calico_variables: &debian8_calico_variables
  244. # stage: deploy-part2
  245. MOVED_TO_GROUP_VARS: "true"
  246. .coreos_canal_variables: &coreos_canal_variables
  247. # stage: deploy-part2
  248. MOVED_TO_GROUP_VARS: "true"
  249. .rhel7_canal_sep_variables: &rhel7_canal_sep_variables
  250. # stage: deploy-special
  251. MOVED_TO_GROUP_VARS: "true"
  252. .ubuntu_weave_sep_variables: &ubuntu_weave_sep_variables
  253. # stage: deploy-special
  254. MOVED_TO_GROUP_VARS: "true"
  255. .centos7_calico_ha_variables: &centos7_calico_ha_variables
  256. # stage: deploy-special
  257. MOVED_TO_GROUP_VARS: "true"
  258. .centos7_kube_router_variables: &centos7_kube_router_variables
  259. # stage: deploy-special
  260. MOVED_TO_GROUP_VARS: "true"
  261. .centos7_multus_calico_variables: &centos7_multus_calico_variables
  262. # stage: deploy-part2
  263. MOVED_TO_GROUP_VARS: "true"
  264. .coreos_alpha_weave_ha_variables: &coreos_alpha_weave_ha_variables
  265. # stage: deploy-special
  266. MOVED_TO_GROUP_VARS: "true"
  267. .coreos_kube_router_variables: &coreos_kube_router_variables
  268. # stage: deploy-special
  269. MOVED_TO_GROUP_VARS: "true"
  270. .ubuntu_rkt_sep_variables: &ubuntu_rkt_sep_variables
  271. # stage: deploy-part1
  272. MOVED_TO_GROUP_VARS: "true"
  273. .ubuntu_vault_sep_variables: &ubuntu_vault_sep_variables
  274. # stage: deploy-part1
  275. MOVED_TO_GROUP_VARS: "true"
  276. .coreos_vault_upgrade_variables: &coreos_vault_upgrade_variables
  277. # stage: deploy-part1
  278. UPGRADE_TEST: "basic"
  279. .ubuntu_flannel_variables: &ubuntu_flannel_variables
  280. # stage: deploy-special
  281. MOVED_TO_GROUP_VARS: "true"
  282. .ubuntu_kube_router_variables: &ubuntu_kube_router_variables
  283. # stage: deploy-special
  284. MOVED_TO_GROUP_VARS: "true"
  285. .opensuse_canal_variables: &opensuse_canal_variables
  286. # stage: deploy-part2
  287. MOVED_TO_GROUP_VARS: "true"
  288. # Builds for PRs only (premoderated by unit-tests step) and triggers (auto)
  289. ### PR JOBS PART1
  290. gce_ubuntu18-flannel-aio:
  291. stage: deploy-part1
  292. <<: *job
  293. <<: *gce
  294. variables:
  295. <<: *ubuntu18_flannel_aio_variables
  296. <<: *gce_variables
  297. when: on_success
  298. except: ['triggers']
  299. only: [/^pr-.*$/]
  300. ### PR JOBS PART2
  301. gce_coreos-calico-aio:
  302. stage: deploy-part2
  303. <<: *job
  304. <<: *gce
  305. variables:
  306. <<: *coreos_calico_aio_variables
  307. <<: *gce_variables
  308. when: on_success
  309. except: ['triggers']
  310. only: [/^pr-.*$/]
  311. gce_centos7-flannel-addons:
  312. stage: deploy-part2
  313. <<: *job
  314. <<: *gce
  315. variables:
  316. <<: *gce_variables
  317. <<: *centos7_flannel_addons_variables
  318. when: on_success
  319. except: ['triggers']
  320. only: [/^pr-.*$/]
  321. gce_centos-weave-kubeadm-sep:
  322. stage: deploy-part2
  323. <<: *job
  324. <<: *gce
  325. variables:
  326. <<: *gce_variables
  327. <<: *centos_weave_kubeadm_variables
  328. when: on_success
  329. except: ['triggers']
  330. only: [/^pr-.*$/]
  331. ### MANUAL JOBS
  332. gce_ubuntu-weave-sep:
  333. stage: deploy-part2
  334. <<: *job
  335. <<: *gce
  336. variables:
  337. <<: *gce_variables
  338. <<: *ubuntu_weave_sep_variables
  339. when: manual
  340. except: ['triggers']
  341. only: [/^pr-.*$/]
  342. gce_coreos-calico-sep-triggers:
  343. stage: deploy-part2
  344. <<: *job
  345. <<: *gce
  346. variables:
  347. <<: *gce_variables
  348. <<: *coreos_calico_aio_variables
  349. when: on_success
  350. only: ['triggers']
  351. gce_ubuntu-canal-ha-triggers:
  352. stage: deploy-part2
  353. <<: *job
  354. <<: *gce
  355. variables:
  356. <<: *gce_variables
  357. <<: *ubuntu_canal_ha_variables
  358. when: on_success
  359. only: ['triggers']
  360. gce_centos7-flannel-addons-triggers:
  361. stage: deploy-part2
  362. <<: *job
  363. <<: *gce
  364. variables:
  365. <<: *gce_variables
  366. <<: *centos7_flannel_addons_variables
  367. when: on_success
  368. only: ['triggers']
  369. gce_ubuntu-weave-sep-triggers:
  370. stage: deploy-part2
  371. <<: *job
  372. <<: *gce
  373. variables:
  374. <<: *gce_variables
  375. <<: *ubuntu_weave_sep_variables
  376. when: on_success
  377. only: ['triggers']
  378. # More builds for PRs/merges (manual) and triggers (auto)
  379. do_ubuntu-canal-ha:
  380. stage: deploy-part2
  381. <<: *job
  382. <<: *do
  383. variables:
  384. <<: *do_variables
  385. when: manual
  386. except: ['triggers']
  387. only: ['master', /^pr-.*$/]
  388. gce_ubuntu-canal-ha:
  389. stage: deploy-part2
  390. <<: *job
  391. <<: *gce
  392. variables:
  393. <<: *gce_variables
  394. <<: *ubuntu_canal_ha_variables
  395. when: manual
  396. except: ['triggers']
  397. only: ['master', /^pr-.*$/]
  398. gce_ubuntu-canal-kubeadm:
  399. stage: deploy-part2
  400. <<: *job
  401. <<: *gce
  402. variables:
  403. <<: *gce_variables
  404. <<: *ubuntu_canal_kubeadm_variables
  405. when: manual
  406. except: ['triggers']
  407. only: ['master', /^pr-.*$/]
  408. gce_ubuntu-canal-kubeadm-triggers:
  409. stage: deploy-part2
  410. <<: *job
  411. <<: *gce
  412. variables:
  413. <<: *gce_variables
  414. <<: *ubuntu_canal_kubeadm_variables
  415. when: on_success
  416. only: ['triggers']
  417. gce_centos-weave-kubeadm-triggers:
  418. stage: deploy-part2
  419. <<: *job
  420. <<: *gce
  421. variables:
  422. <<: *gce_variables
  423. <<: *centos_weave_kubeadm_variables
  424. when: on_success
  425. only: ['triggers']
  426. gce_ubuntu-contiv-sep:
  427. stage: deploy-special
  428. <<: *job
  429. <<: *gce
  430. variables:
  431. <<: *gce_variables
  432. <<: *ubuntu_contiv_sep_variables
  433. when: manual
  434. except: ['triggers']
  435. only: ['master', /^pr-.*$/]
  436. gce_coreos-cilium:
  437. stage: deploy-special
  438. <<: *job
  439. <<: *gce
  440. variables:
  441. <<: *gce_variables
  442. <<: *coreos_cilium_variables
  443. when: manual
  444. except: ['triggers']
  445. only: ['master', /^pr-.*$/]
  446. gce_ubuntu-cilium-sep:
  447. stage: deploy-special
  448. <<: *job
  449. <<: *gce
  450. variables:
  451. <<: *gce_variables
  452. <<: *ubuntu_cilium_sep_variables
  453. when: manual
  454. except: ['triggers']
  455. only: ['master', /^pr-.*$/]
  456. gce_rhel7-weave:
  457. stage: deploy-part2
  458. <<: *job
  459. <<: *gce
  460. variables:
  461. <<: *gce_variables
  462. <<: *rhel7_weave_variables
  463. when: manual
  464. except: ['triggers']
  465. only: ['master', /^pr-.*$/]
  466. gce_rhel7-weave-triggers:
  467. stage: deploy-part2
  468. <<: *job
  469. <<: *gce
  470. variables:
  471. <<: *gce_variables
  472. <<: *rhel7_weave_variables
  473. when: on_success
  474. only: ['triggers']
  475. gce_debian8-calico-upgrade:
  476. stage: deploy-part2
  477. <<: *job
  478. <<: *gce
  479. variables:
  480. <<: *gce_variables
  481. <<: *debian8_calico_variables
  482. when: manual
  483. except: ['triggers']
  484. only: ['master', /^pr-.*$/]
  485. gce_debian8-calico-triggers:
  486. stage: deploy-part2
  487. <<: *job
  488. <<: *gce
  489. variables:
  490. <<: *gce_variables
  491. <<: *debian8_calico_variables
  492. when: on_success
  493. only: ['triggers']
  494. gce_coreos-canal:
  495. stage: deploy-part2
  496. <<: *job
  497. <<: *gce
  498. variables:
  499. <<: *gce_variables
  500. <<: *coreos_canal_variables
  501. when: manual
  502. except: ['triggers']
  503. only: ['master', /^pr-.*$/]
  504. gce_coreos-canal-triggers:
  505. stage: deploy-part2
  506. <<: *job
  507. <<: *gce
  508. variables:
  509. <<: *gce_variables
  510. <<: *coreos_canal_variables
  511. when: on_success
  512. only: ['triggers']
  513. gce_rhel7-canal-sep:
  514. stage: deploy-special
  515. <<: *job
  516. <<: *gce
  517. variables:
  518. <<: *gce_variables
  519. <<: *rhel7_canal_sep_variables
  520. when: manual
  521. except: ['triggers']
  522. only: ['master', /^pr-.*$/]
  523. gce_rhel7-canal-sep-triggers:
  524. stage: deploy-part2
  525. <<: *job
  526. <<: *gce
  527. variables:
  528. <<: *gce_variables
  529. <<: *rhel7_canal_sep_variables
  530. when: on_success
  531. only: ['triggers']
  532. gce_centos7-calico-ha:
  533. stage: deploy-special
  534. <<: *job
  535. <<: *gce
  536. variables:
  537. <<: *gce_variables
  538. <<: *centos7_calico_ha_variables
  539. when: manual
  540. except: ['triggers']
  541. only: ['master', /^pr-.*$/]
  542. gce_centos7-calico-ha-triggers:
  543. stage: deploy-part2
  544. <<: *job
  545. <<: *gce
  546. variables:
  547. <<: *gce_variables
  548. <<: *centos7_calico_ha_variables
  549. when: on_success
  550. only: ['triggers']
  551. gce_centos7-kube-router:
  552. stage: deploy-special
  553. <<: *job
  554. <<: *gce
  555. variables:
  556. <<: *gce_variables
  557. <<: *centos7_kube_router_variables
  558. when: manual
  559. except: ['triggers']
  560. only: ['master', /^pr-.*$/]
  561. gce_centos7-multus-calico:
  562. stage: deploy-part2
  563. <<: *job
  564. <<: *gce
  565. variables:
  566. <<: *gce_variables
  567. <<: *centos7_multus_calico_variables
  568. when: manual
  569. except: ['triggers']
  570. only: ['master', /^pr-.*$/]
  571. gce_opensuse-canal:
  572. stage: deploy-part2
  573. <<: *job
  574. <<: *gce
  575. variables:
  576. <<: *gce_variables
  577. <<: *opensuse_canal_variables
  578. when: manual
  579. except: ['triggers']
  580. only: ['master', /^pr-.*$/]
  581. # no triggers yet https://github.com/kubernetes-incubator/kargo/issues/613
  582. gce_coreos-alpha-weave-ha:
  583. stage: deploy-special
  584. <<: *job
  585. <<: *gce
  586. variables:
  587. <<: *gce_variables
  588. <<: *coreos_alpha_weave_ha_variables
  589. when: manual
  590. except: ['triggers']
  591. only: ['master', /^pr-.*$/]
  592. gce_coreos-kube-router:
  593. stage: deploy-special
  594. <<: *job
  595. <<: *gce
  596. variables:
  597. <<: *gce_variables
  598. <<: *coreos_kube_router_variables
  599. when: manual
  600. except: ['triggers']
  601. only: ['master', /^pr-.*$/]
  602. gce_ubuntu-rkt-sep:
  603. stage: deploy-part2
  604. <<: *job
  605. <<: *gce
  606. variables:
  607. <<: *gce_variables
  608. <<: *ubuntu_rkt_sep_variables
  609. when: manual
  610. except: ['triggers']
  611. only: ['master', /^pr-.*$/]
  612. gce_ubuntu-vault-sep:
  613. stage: deploy-part2
  614. <<: *job
  615. <<: *gce
  616. variables:
  617. <<: *gce_variables
  618. <<: *ubuntu_vault_sep_variables
  619. when: manual
  620. except: ['triggers']
  621. only: ['master', /^pr-.*$/]
  622. gce_coreos-vault-upgrade:
  623. stage: deploy-part2
  624. <<: *job
  625. <<: *gce
  626. variables:
  627. <<: *gce_variables
  628. <<: *coreos_vault_upgrade_variables
  629. when: manual
  630. except: ['triggers']
  631. only: ['master', /^pr-.*$/]
  632. gce_ubuntu-flannel-sep:
  633. stage: deploy-special
  634. <<: *job
  635. <<: *gce
  636. variables:
  637. <<: *gce_variables
  638. <<: *ubuntu_flannel_variables
  639. when: manual
  640. except: ['triggers']
  641. only: ['master', /^pr-.*$/]
  642. gce_ubuntu-kube-router-sep:
  643. stage: deploy-special
  644. <<: *job
  645. <<: *gce
  646. variables:
  647. <<: *gce_variables
  648. <<: *ubuntu_kube_router_variables
  649. when: manual
  650. except: ['triggers']
  651. only: ['master', /^pr-.*$/]
  652. # Premoderated with manual actions
  653. ci-authorized:
  654. <<: *job
  655. stage: moderator
  656. before_script:
  657. - apt-get -y install jq
  658. script:
  659. - /bin/sh scripts/premoderator.sh
  660. except: ['triggers', 'master']
  661. syntax-check:
  662. <<: *job
  663. stage: unit-tests
  664. script:
  665. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root cluster.yml -vvv --syntax-check
  666. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root upgrade-cluster.yml -vvv --syntax-check
  667. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root reset.yml -vvv --syntax-check
  668. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root extra_playbooks/upgrade-only-k8s.yml -vvv --syntax-check
  669. except: ['triggers', 'master']
  670. yamllint:
  671. <<: *job
  672. stage: unit-tests
  673. script:
  674. - yamllint roles
  675. except: ['triggers', 'master']
  676. tox-inventory-builder:
  677. stage: unit-tests
  678. <<: *job
  679. script:
  680. - pip install tox
  681. - cd contrib/inventory_builder && tox
  682. when: manual
  683. except: ['triggers', 'master']