You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

764 lines
18 KiB

8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
contiv network support (#1914) * Add Contiv support Contiv is a network plugin for Kubernetes and Docker. It supports vlan/vxlan/BGP/Cisco ACI technologies. It support firewall policies, multiple networks and bridging pods onto physical networks. * Update contiv version to 1.1.4 Update contiv version to 1.1.4 and added SVC_SUBNET in contiv-config. * Load openvswitch module to workaround on CentOS7.4 * Set contiv cni version to 0.1.0 Correct contiv CNI version to 0.1.0. * Use kube_apiserver_endpoint for K8S_API_SERVER Use kube_apiserver_endpoint as K8S_API_SERVER to make contiv talks to a available endpoint no matter if there's a loadbalancer or not. * Make contiv use its own etcd Before this commit, contiv is using a etcd proxy mode to k8s etcd, this work fine when the etcd hosts are co-located with contiv etcd proxy, however the k8s peering certs are only in etcd group, as a result the etcd-proxy is not able to peering with the k8s etcd on etcd group, plus the netplugin is always trying to find the etcd endpoint on localhost, this will cause problem for all netplugins not runnign on etcd group nodes. This commit make contiv uses its own etcd, separate from k8s one. on kube-master nodes (where net-master runs), it will run as leader mode and on all rest nodes it will run as proxy mode. * Use cp instead of rsync to copy cni binaries Since rsync has been removed from hyperkube, this commit changes it to use cp instead. * Make contiv-etcd able to run on master nodes * Add rbac_enabled flag for contiv pods * Add contiv into CNI network plugin lists * migrate contiv test to tests/files Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com> * Add required rules for contiv netplugin * Better handling json return of fwdMode * Make contiv etcd port configurable * Use default var instead of templating * roles/download/defaults/main.yml: use contiv 1.1.7 Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com>
7 years ago
contiv network support (#1914) * Add Contiv support Contiv is a network plugin for Kubernetes and Docker. It supports vlan/vxlan/BGP/Cisco ACI technologies. It support firewall policies, multiple networks and bridging pods onto physical networks. * Update contiv version to 1.1.4 Update contiv version to 1.1.4 and added SVC_SUBNET in contiv-config. * Load openvswitch module to workaround on CentOS7.4 * Set contiv cni version to 0.1.0 Correct contiv CNI version to 0.1.0. * Use kube_apiserver_endpoint for K8S_API_SERVER Use kube_apiserver_endpoint as K8S_API_SERVER to make contiv talks to a available endpoint no matter if there's a loadbalancer or not. * Make contiv use its own etcd Before this commit, contiv is using a etcd proxy mode to k8s etcd, this work fine when the etcd hosts are co-located with contiv etcd proxy, however the k8s peering certs are only in etcd group, as a result the etcd-proxy is not able to peering with the k8s etcd on etcd group, plus the netplugin is always trying to find the etcd endpoint on localhost, this will cause problem for all netplugins not runnign on etcd group nodes. This commit make contiv uses its own etcd, separate from k8s one. on kube-master nodes (where net-master runs), it will run as leader mode and on all rest nodes it will run as proxy mode. * Use cp instead of rsync to copy cni binaries Since rsync has been removed from hyperkube, this commit changes it to use cp instead. * Make contiv-etcd able to run on master nodes * Add rbac_enabled flag for contiv pods * Add contiv into CNI network plugin lists * migrate contiv test to tests/files Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com> * Add required rules for contiv netplugin * Better handling json return of fwdMode * Make contiv etcd port configurable * Use default var instead of templating * roles/download/defaults/main.yml: use contiv 1.1.7 Signed-off-by: Cristian Staretu <cristian.staretu@gmail.com>
7 years ago
6 years ago
8 years ago
6 years ago
8 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
6 years ago
  1. stages:
  2. - unit-tests
  3. - moderator
  4. - deploy-part1
  5. - deploy-part2
  6. - deploy-special
  7. variables:
  8. FAILFASTCI_NAMESPACE: 'kargo-ci'
  9. GITLAB_REPOSITORY: 'kargo-ci/kubernetes-incubator__kubespray'
  10. # DOCKER_HOST: tcp://localhost:2375
  11. ANSIBLE_FORCE_COLOR: "true"
  12. MAGIC: "ci check this"
  13. TEST_ID: "$CI_PIPELINE_ID-$CI_BUILD_ID"
  14. CI_TEST_VARS: "./tests/files/${CI_JOB_NAME}.yml"
  15. GS_ACCESS_KEY_ID: $GS_KEY
  16. GS_SECRET_ACCESS_KEY: $GS_SECRET
  17. CONTAINER_ENGINE: docker
  18. SSH_USER: root
  19. GCE_PREEMPTIBLE: "false"
  20. ANSIBLE_KEEP_REMOTE_FILES: "1"
  21. ANSIBLE_CONFIG: ./tests/ansible.cfg
  22. ANSIBLE_INVENTORY: ./inventory/sample/${CI_JOB_NAME}-${BUILD_NUMBER}.ini
  23. IDEMPOT_CHECK: "false"
  24. RESET_CHECK: "false"
  25. UPGRADE_TEST: "false"
  26. KUBEADM_ENABLED: "false"
  27. LOG_LEVEL: "-vv"
  28. # asia-east1-a
  29. # asia-northeast1-a
  30. # europe-west1-b
  31. # us-central1-a
  32. # us-east1-b
  33. # us-west1-a
  34. before_script:
  35. - /usr/bin/python -m pip install -r tests/requirements.txt
  36. - mkdir -p /.ssh
  37. .job: &job
  38. tags:
  39. - kubernetes
  40. - docker
  41. image: quay.io/kubespray/kubespray:v2.7
  42. .docker_service: &docker_service
  43. services:
  44. - docker:dind
  45. .create_cluster: &create_cluster
  46. <<: *job
  47. <<: *docker_service
  48. .gce_variables: &gce_variables
  49. GCE_USER: travis
  50. SSH_USER: $GCE_USER
  51. CLOUD_MACHINE_TYPE: "g1-small"
  52. CI_PLATFORM: "gce"
  53. PRIVATE_KEY: $GCE_PRIVATE_KEY
  54. .do_variables: &do_variables
  55. PRIVATE_KEY: $DO_PRIVATE_KEY
  56. CI_PLATFORM: "do"
  57. SSH_USER: root
  58. .testcases: &testcases
  59. <<: *job
  60. <<: *docker_service
  61. cache:
  62. key: "$CI_BUILD_REF_NAME"
  63. paths:
  64. - downloads/
  65. - $HOME/.cache
  66. before_script:
  67. - docker info
  68. - /usr/bin/python -m pip install -r requirements.txt
  69. - /usr/bin/python -m pip install -r tests/requirements.txt
  70. - mkdir -p /.ssh
  71. - mkdir -p $HOME/.ssh
  72. - ansible-playbook --version
  73. - export PYPATH=$([[ ! "$CI_JOB_NAME" =~ "coreos" ]] && echo /usr/bin/python || echo /opt/bin/python)
  74. - echo "CI_JOB_NAME is $CI_JOB_NAME"
  75. - echo "PYPATH is $PYPATH"
  76. script:
  77. - pwd
  78. - ls
  79. - echo ${PWD}
  80. - echo "${STARTUP_SCRIPT}"
  81. - cd tests && make create-${CI_PLATFORM} -s ; cd -
  82. # Check out latest tag if testing upgrade
  83. # Uncomment when gitlab kubespray repo has tags
  84. #- test "${UPGRADE_TEST}" != "false" && git fetch --all && git checkout $(git describe --tags $(git rev-list --tags --max-count=1))
  85. - test "${UPGRADE_TEST}" != "false" && git checkout 53d87e53c5899d4ea2904ab7e3883708dd6363d3
  86. # Checkout the CI vars file so it is available
  87. - test "${UPGRADE_TEST}" != "false" && git checkout "${CI_BUILD_REF}" tests/files/${CI_JOB_NAME}.yml
  88. # Workaround https://github.com/kubernetes-incubator/kubespray/issues/2021
  89. - 'sh -c "echo ignore_assert_errors: true | tee -a tests/files/${CI_JOB_NAME}.yml"'
  90. # Create cluster
  91. - >
  92. ansible-playbook
  93. -i ${ANSIBLE_INVENTORY}
  94. -b --become-user=root
  95. --private-key=${HOME}/.ssh/id_rsa
  96. -u $SSH_USER
  97. ${SSH_ARGS}
  98. ${LOG_LEVEL}
  99. -e @${CI_TEST_VARS}
  100. -e ansible_ssh_user=${SSH_USER}
  101. -e local_release_dir=${PWD}/downloads
  102. --limit "all:!fake_hosts"
  103. cluster.yml
  104. # Repeat deployment if testing upgrade
  105. - >
  106. if [ "${UPGRADE_TEST}" != "false" ]; then
  107. test "${UPGRADE_TEST}" == "basic" && PLAYBOOK="cluster.yml";
  108. test "${UPGRADE_TEST}" == "graceful" && PLAYBOOK="upgrade-cluster.yml";
  109. git checkout "${CI_BUILD_REF}";
  110. ansible-playbook
  111. -i ${ANSIBLE_INVENTORY}
  112. -b --become-user=root
  113. --private-key=${HOME}/.ssh/id_rsa
  114. -u $SSH_USER
  115. ${SSH_ARGS}
  116. ${LOG_LEVEL}
  117. -e @${CI_TEST_VARS}
  118. -e ansible_ssh_user=${SSH_USER}
  119. -e local_release_dir=${PWD}/downloads
  120. --limit "all:!fake_hosts"
  121. $PLAYBOOK;
  122. fi
  123. # Tests Cases
  124. ## Test Master API
  125. - >
  126. ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/010_check-apiserver.yml $LOG_LEVEL
  127. -e "{kubeadm_enabled: ${KUBEADM_ENABLED}}"
  128. ## Ping the between 2 pod
  129. - ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/030_check-network.yml $LOG_LEVEL
  130. ## Advanced DNS checks
  131. - ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/040_check-network-adv.yml $LOG_LEVEL
  132. ## Idempotency checks 1/5 (repeat deployment)
  133. - >
  134. if [ "${IDEMPOT_CHECK}" = "true" ]; then
  135. ansible-playbook
  136. -i ${ANSIBLE_INVENTORY}
  137. -b --become-user=root
  138. --private-key=${HOME}/.ssh/id_rsa
  139. -u $SSH_USER
  140. ${SSH_ARGS}
  141. ${LOG_LEVEL}
  142. -e @${CI_TEST_VARS}
  143. -e ansible_python_interpreter=${PYPATH}
  144. -e local_release_dir=${PWD}/downloads
  145. --limit "all:!fake_hosts"
  146. cluster.yml;
  147. fi
  148. ## Idempotency checks 2/5 (Advanced DNS checks)
  149. - >
  150. if [ "${IDEMPOT_CHECK}" = "true" ]; then
  151. ansible-playbook
  152. -i ${ANSIBLE_INVENTORY}
  153. -b --become-user=root
  154. --private-key=${HOME}/.ssh/id_rsa
  155. -u $SSH_USER
  156. ${SSH_ARGS}
  157. ${LOG_LEVEL}
  158. -e @${CI_TEST_VARS}
  159. --limit "all:!fake_hosts"
  160. tests/testcases/040_check-network-adv.yml $LOG_LEVEL;
  161. fi
  162. ## Idempotency checks 3/5 (reset deployment)
  163. - >
  164. if [ "${IDEMPOT_CHECK}" = "true" -a "${RESET_CHECK}" = "true" ]; then
  165. ansible-playbook
  166. -i ${ANSIBLE_INVENTORY}
  167. -b --become-user=root
  168. --private-key=${HOME}/.ssh/id_rsa
  169. -u $SSH_USER
  170. ${SSH_ARGS}
  171. ${LOG_LEVEL}
  172. -e @${CI_TEST_VARS}
  173. -e ansible_python_interpreter=${PYPATH}
  174. -e reset_confirmation=yes
  175. --limit "all:!fake_hosts"
  176. reset.yml;
  177. fi
  178. ## Idempotency checks 4/5 (redeploy after reset)
  179. - >
  180. if [ "${IDEMPOT_CHECK}" = "true" -a "${RESET_CHECK}" = "true" ]; then
  181. ansible-playbook
  182. -i ${ANSIBLE_INVENTORY}
  183. -b --become-user=root
  184. --private-key=${HOME}/.ssh/id_rsa
  185. -u $SSH_USER
  186. ${SSH_ARGS}
  187. ${LOG_LEVEL}
  188. -e @${CI_TEST_VARS}
  189. -e ansible_python_interpreter=${PYPATH}
  190. -e local_release_dir=${PWD}/downloads
  191. --limit "all:!fake_hosts"
  192. cluster.yml;
  193. fi
  194. ## Idempotency checks 5/5 (Advanced DNS checks)
  195. - >
  196. if [ "${IDEMPOT_CHECK}" = "true" -a "${RESET_CHECK}" = "true" ]; then
  197. ansible-playbook -i ${ANSIBLE_INVENTORY} -e ansible_python_interpreter=${PYPATH}
  198. -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root
  199. --limit "all:!fake_hosts"
  200. tests/testcases/040_check-network-adv.yml $LOG_LEVEL;
  201. fi
  202. after_script:
  203. - cd tests && make delete-${CI_PLATFORM} -s ; cd -
  204. .gce: &gce
  205. <<: *testcases
  206. variables:
  207. <<: *gce_variables
  208. .do: &do
  209. variables:
  210. <<: *do_variables
  211. <<: *testcases
  212. # Test matrix. Leave the comments for markup scripts.
  213. .coreos_calico_aio_variables: &coreos_calico_aio_variables
  214. # stage: deploy-part1
  215. MOVED_TO_GROUP_VARS: "true"
  216. .ubuntu18_flannel_aio_variables: &ubuntu18_flannel_aio_variables
  217. # stage: deploy-part1
  218. MOVED_TO_GROUP_VARS: "true"
  219. .ubuntu_canal_ha_variables: &ubuntu_canal_ha_variables
  220. # stage: deploy-part1
  221. UPGRADE_TEST: "graceful"
  222. .centos_weave_kubeadm_variables: &centos_weave_kubeadm_variables
  223. # stage: deploy-part1
  224. UPGRADE_TEST: "graceful"
  225. .ubuntu_canal_kubeadm_variables: &ubuntu_canal_kubeadm_variables
  226. # stage: deploy-part1
  227. MOVED_TO_GROUP_VARS: "true"
  228. .ubuntu_contiv_sep_variables: &ubuntu_contiv_sep_variables
  229. # stage: deploy-special
  230. MOVED_TO_GROUP_VARS: "true"
  231. .coreos_cilium_variables: &coreos_cilium_variables
  232. # stage: deploy-special
  233. MOVED_TO_GROUP_VARS: "true"
  234. .ubuntu_cilium_sep_variables: &ubuntu_cilium_sep_variables
  235. # stage: deploy-special
  236. MOVED_TO_GROUP_VARS: "true"
  237. .rhel7_weave_variables: &rhel7_weave_variables
  238. # stage: deploy-part1
  239. MOVED_TO_GROUP_VARS: "true"
  240. .centos7_flannel_addons_variables: &centos7_flannel_addons_variables
  241. # stage: deploy-part2
  242. MOVED_TO_GROUP_VARS: "true"
  243. .debian8_calico_variables: &debian8_calico_variables
  244. # stage: deploy-part2
  245. MOVED_TO_GROUP_VARS: "true"
  246. .coreos_canal_variables: &coreos_canal_variables
  247. # stage: deploy-part2
  248. MOVED_TO_GROUP_VARS: "true"
  249. .rhel7_canal_sep_variables: &rhel7_canal_sep_variables
  250. # stage: deploy-special
  251. MOVED_TO_GROUP_VARS: "true"
  252. .ubuntu_weave_sep_variables: &ubuntu_weave_sep_variables
  253. # stage: deploy-special
  254. MOVED_TO_GROUP_VARS: "true"
  255. .centos7_calico_ha_variables: &centos7_calico_ha_variables
  256. # stage: deploy-special
  257. MOVED_TO_GROUP_VARS: "true"
  258. .centos7_kube_router_variables: &centos7_kube_router_variables
  259. # stage: deploy-special
  260. MOVED_TO_GROUP_VARS: "true"
  261. .coreos_alpha_weave_ha_variables: &coreos_alpha_weave_ha_variables
  262. # stage: deploy-special
  263. MOVED_TO_GROUP_VARS: "true"
  264. .coreos_kube_router_variables: &coreos_kube_router_variables
  265. # stage: deploy-special
  266. MOVED_TO_GROUP_VARS: "true"
  267. .ubuntu_rkt_sep_variables: &ubuntu_rkt_sep_variables
  268. # stage: deploy-part1
  269. MOVED_TO_GROUP_VARS: "true"
  270. .ubuntu_vault_sep_variables: &ubuntu_vault_sep_variables
  271. # stage: deploy-part1
  272. MOVED_TO_GROUP_VARS: "true"
  273. .coreos_vault_upgrade_variables: &coreos_vault_upgrade_variables
  274. # stage: deploy-part1
  275. UPGRADE_TEST: "basic"
  276. .ubuntu_flannel_variables: &ubuntu_flannel_variables
  277. # stage: deploy-special
  278. MOVED_TO_GROUP_VARS: "true"
  279. .ubuntu_kube_router_variables: &ubuntu_kube_router_variables
  280. # stage: deploy-special
  281. MOVED_TO_GROUP_VARS: "true"
  282. .opensuse_canal_variables: &opensuse_canal_variables
  283. # stage: deploy-part2
  284. MOVED_TO_GROUP_VARS: "true"
  285. # Builds for PRs only (premoderated by unit-tests step) and triggers (auto)
  286. ### PR JOBS PART1
  287. gce_ubuntu18-flannel-aio:
  288. stage: deploy-part1
  289. <<: *job
  290. <<: *gce
  291. variables:
  292. <<: *ubuntu18_flannel_aio_variables
  293. <<: *gce_variables
  294. when: on_success
  295. except: ['triggers']
  296. only: [/^pr-.*$/]
  297. ### PR JOBS PART2
  298. gce_coreos-calico-aio:
  299. stage: deploy-part2
  300. <<: *job
  301. <<: *gce
  302. variables:
  303. <<: *coreos_calico_aio_variables
  304. <<: *gce_variables
  305. when: on_success
  306. except: ['triggers']
  307. only: [/^pr-.*$/]
  308. gce_centos7-flannel-addons:
  309. stage: deploy-part2
  310. <<: *job
  311. <<: *gce
  312. variables:
  313. <<: *gce_variables
  314. <<: *centos7_flannel_addons_variables
  315. when: on_success
  316. except: ['triggers']
  317. only: [/^pr-.*$/]
  318. gce_centos-weave-kubeadm-sep:
  319. stage: deploy-part2
  320. <<: *job
  321. <<: *gce
  322. variables:
  323. <<: *gce_variables
  324. <<: *centos_weave_kubeadm_variables
  325. when: on_success
  326. except: ['triggers']
  327. only: [/^pr-.*$/]
  328. ### MANUAL JOBS
  329. gce_ubuntu-weave-sep:
  330. stage: deploy-part2
  331. <<: *job
  332. <<: *gce
  333. variables:
  334. <<: *gce_variables
  335. <<: *ubuntu_weave_sep_variables
  336. when: manual
  337. except: ['triggers']
  338. only: [/^pr-.*$/]
  339. gce_coreos-calico-sep-triggers:
  340. stage: deploy-part2
  341. <<: *job
  342. <<: *gce
  343. variables:
  344. <<: *gce_variables
  345. <<: *coreos_calico_aio_variables
  346. when: on_success
  347. only: ['triggers']
  348. gce_ubuntu-canal-ha-triggers:
  349. stage: deploy-part2
  350. <<: *job
  351. <<: *gce
  352. variables:
  353. <<: *gce_variables
  354. <<: *ubuntu_canal_ha_variables
  355. when: on_success
  356. only: ['triggers']
  357. gce_centos7-flannel-addons-triggers:
  358. stage: deploy-part2
  359. <<: *job
  360. <<: *gce
  361. variables:
  362. <<: *gce_variables
  363. <<: *centos7_flannel_addons_variables
  364. when: on_success
  365. only: ['triggers']
  366. gce_ubuntu-weave-sep-triggers:
  367. stage: deploy-part2
  368. <<: *job
  369. <<: *gce
  370. variables:
  371. <<: *gce_variables
  372. <<: *ubuntu_weave_sep_variables
  373. when: on_success
  374. only: ['triggers']
  375. # More builds for PRs/merges (manual) and triggers (auto)
  376. do_ubuntu-canal-ha:
  377. stage: deploy-part2
  378. <<: *job
  379. <<: *do
  380. variables:
  381. <<: *do_variables
  382. when: manual
  383. except: ['triggers']
  384. only: ['master', /^pr-.*$/]
  385. gce_ubuntu-canal-ha:
  386. stage: deploy-part2
  387. <<: *job
  388. <<: *gce
  389. variables:
  390. <<: *gce_variables
  391. <<: *ubuntu_canal_ha_variables
  392. when: manual
  393. except: ['triggers']
  394. only: ['master', /^pr-.*$/]
  395. gce_ubuntu-canal-kubeadm:
  396. stage: deploy-part2
  397. <<: *job
  398. <<: *gce
  399. variables:
  400. <<: *gce_variables
  401. <<: *ubuntu_canal_kubeadm_variables
  402. when: manual
  403. except: ['triggers']
  404. only: ['master', /^pr-.*$/]
  405. gce_ubuntu-canal-kubeadm-triggers:
  406. stage: deploy-part2
  407. <<: *job
  408. <<: *gce
  409. variables:
  410. <<: *gce_variables
  411. <<: *ubuntu_canal_kubeadm_variables
  412. when: on_success
  413. only: ['triggers']
  414. gce_centos-weave-kubeadm-triggers:
  415. stage: deploy-part2
  416. <<: *job
  417. <<: *gce
  418. variables:
  419. <<: *gce_variables
  420. <<: *centos_weave_kubeadm_variables
  421. when: on_success
  422. only: ['triggers']
  423. gce_ubuntu-contiv-sep:
  424. stage: deploy-special
  425. <<: *job
  426. <<: *gce
  427. variables:
  428. <<: *gce_variables
  429. <<: *ubuntu_contiv_sep_variables
  430. when: manual
  431. except: ['triggers']
  432. only: ['master', /^pr-.*$/]
  433. gce_coreos-cilium:
  434. stage: deploy-special
  435. <<: *job
  436. <<: *gce
  437. variables:
  438. <<: *gce_variables
  439. <<: *coreos_cilium_variables
  440. when: manual
  441. except: ['triggers']
  442. only: ['master', /^pr-.*$/]
  443. gce_ubuntu-cilium-sep:
  444. stage: deploy-special
  445. <<: *job
  446. <<: *gce
  447. variables:
  448. <<: *gce_variables
  449. <<: *ubuntu_cilium_sep_variables
  450. when: manual
  451. except: ['triggers']
  452. only: ['master', /^pr-.*$/]
  453. gce_rhel7-weave:
  454. stage: deploy-part2
  455. <<: *job
  456. <<: *gce
  457. variables:
  458. <<: *gce_variables
  459. <<: *rhel7_weave_variables
  460. when: manual
  461. except: ['triggers']
  462. only: ['master', /^pr-.*$/]
  463. gce_rhel7-weave-triggers:
  464. stage: deploy-part2
  465. <<: *job
  466. <<: *gce
  467. variables:
  468. <<: *gce_variables
  469. <<: *rhel7_weave_variables
  470. when: on_success
  471. only: ['triggers']
  472. gce_debian8-calico-upgrade:
  473. stage: deploy-part2
  474. <<: *job
  475. <<: *gce
  476. variables:
  477. <<: *gce_variables
  478. <<: *debian8_calico_variables
  479. when: manual
  480. except: ['triggers']
  481. only: ['master', /^pr-.*$/]
  482. gce_debian8-calico-triggers:
  483. stage: deploy-part2
  484. <<: *job
  485. <<: *gce
  486. variables:
  487. <<: *gce_variables
  488. <<: *debian8_calico_variables
  489. when: on_success
  490. only: ['triggers']
  491. gce_coreos-canal:
  492. stage: deploy-part2
  493. <<: *job
  494. <<: *gce
  495. variables:
  496. <<: *gce_variables
  497. <<: *coreos_canal_variables
  498. when: manual
  499. except: ['triggers']
  500. only: ['master', /^pr-.*$/]
  501. gce_coreos-canal-triggers:
  502. stage: deploy-part2
  503. <<: *job
  504. <<: *gce
  505. variables:
  506. <<: *gce_variables
  507. <<: *coreos_canal_variables
  508. when: on_success
  509. only: ['triggers']
  510. gce_rhel7-canal-sep:
  511. stage: deploy-special
  512. <<: *job
  513. <<: *gce
  514. variables:
  515. <<: *gce_variables
  516. <<: *rhel7_canal_sep_variables
  517. when: manual
  518. except: ['triggers']
  519. only: ['master', /^pr-.*$/]
  520. gce_rhel7-canal-sep-triggers:
  521. stage: deploy-part2
  522. <<: *job
  523. <<: *gce
  524. variables:
  525. <<: *gce_variables
  526. <<: *rhel7_canal_sep_variables
  527. when: on_success
  528. only: ['triggers']
  529. gce_centos7-calico-ha:
  530. stage: deploy-special
  531. <<: *job
  532. <<: *gce
  533. variables:
  534. <<: *gce_variables
  535. <<: *centos7_calico_ha_variables
  536. when: manual
  537. except: ['triggers']
  538. only: ['master', /^pr-.*$/]
  539. gce_centos7-calico-ha-triggers:
  540. stage: deploy-part2
  541. <<: *job
  542. <<: *gce
  543. variables:
  544. <<: *gce_variables
  545. <<: *centos7_calico_ha_variables
  546. when: on_success
  547. only: ['triggers']
  548. gce_centos7-kube-router:
  549. stage: deploy-special
  550. <<: *job
  551. <<: *gce
  552. variables:
  553. <<: *gce_variables
  554. <<: *centos7_kube_router_variables
  555. when: manual
  556. except: ['triggers']
  557. only: ['master', /^pr-.*$/]
  558. gce_opensuse-canal:
  559. stage: deploy-part2
  560. <<: *job
  561. <<: *gce
  562. variables:
  563. <<: *gce_variables
  564. <<: *opensuse_canal_variables
  565. when: manual
  566. except: ['triggers']
  567. only: ['master', /^pr-.*$/]
  568. # no triggers yet https://github.com/kubernetes-incubator/kargo/issues/613
  569. gce_coreos-alpha-weave-ha:
  570. stage: deploy-special
  571. <<: *job
  572. <<: *gce
  573. variables:
  574. <<: *gce_variables
  575. <<: *coreos_alpha_weave_ha_variables
  576. when: manual
  577. except: ['triggers']
  578. only: ['master', /^pr-.*$/]
  579. gce_coreos-kube-router:
  580. stage: deploy-special
  581. <<: *job
  582. <<: *gce
  583. variables:
  584. <<: *gce_variables
  585. <<: *coreos_kube_router_variables
  586. when: manual
  587. except: ['triggers']
  588. only: ['master', /^pr-.*$/]
  589. gce_ubuntu-rkt-sep:
  590. stage: deploy-part2
  591. <<: *job
  592. <<: *gce
  593. variables:
  594. <<: *gce_variables
  595. <<: *ubuntu_rkt_sep_variables
  596. when: manual
  597. except: ['triggers']
  598. only: ['master', /^pr-.*$/]
  599. gce_ubuntu-vault-sep:
  600. stage: deploy-part2
  601. <<: *job
  602. <<: *gce
  603. variables:
  604. <<: *gce_variables
  605. <<: *ubuntu_vault_sep_variables
  606. when: manual
  607. except: ['triggers']
  608. only: ['master', /^pr-.*$/]
  609. gce_coreos-vault-upgrade:
  610. stage: deploy-part2
  611. <<: *job
  612. <<: *gce
  613. variables:
  614. <<: *gce_variables
  615. <<: *coreos_vault_upgrade_variables
  616. when: manual
  617. except: ['triggers']
  618. only: ['master', /^pr-.*$/]
  619. gce_ubuntu-flannel-sep:
  620. stage: deploy-special
  621. <<: *job
  622. <<: *gce
  623. variables:
  624. <<: *gce_variables
  625. <<: *ubuntu_flannel_variables
  626. when: manual
  627. except: ['triggers']
  628. only: ['master', /^pr-.*$/]
  629. gce_ubuntu-kube-router-sep:
  630. stage: deploy-special
  631. <<: *job
  632. <<: *gce
  633. variables:
  634. <<: *gce_variables
  635. <<: *ubuntu_kube_router_variables
  636. when: manual
  637. except: ['triggers']
  638. only: ['master', /^pr-.*$/]
  639. # Premoderated with manual actions
  640. ci-authorized:
  641. <<: *job
  642. stage: moderator
  643. before_script:
  644. - apt-get -y install jq
  645. script:
  646. - /bin/sh scripts/premoderator.sh
  647. except: ['triggers', 'master']
  648. syntax-check:
  649. <<: *job
  650. stage: unit-tests
  651. script:
  652. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root cluster.yml -vvv --syntax-check
  653. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root upgrade-cluster.yml -vvv --syntax-check
  654. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root reset.yml -vvv --syntax-check
  655. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root extra_playbooks/upgrade-only-k8s.yml -vvv --syntax-check
  656. except: ['triggers', 'master']
  657. yamllint:
  658. <<: *job
  659. stage: unit-tests
  660. script:
  661. - yamllint roles
  662. except: ['triggers', 'master']
  663. tox-inventory-builder:
  664. stage: unit-tests
  665. <<: *job
  666. script:
  667. - pip install tox
  668. - cd contrib/inventory_builder && tox
  669. when: manual
  670. except: ['triggers', 'master']