You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

134 lines
11 KiB

  1. # vSphere
  2. Kubespray can be deployed with vSphere as Cloud provider. This feature supports:
  3. - Volumes
  4. - Persistent Volumes
  5. - Storage Classes and provisioning of volumes
  6. - vSphere Storage Policy Based Management for Containers orchestrated by Kubernetes
  7. ## Out-of-tree vSphere cloud provider
  8. ### Prerequisites
  9. You need at first to configure your vSphere environment by following the [official documentation](https://github.com/kubernetes/cloud-provider-vsphere/blob/master/docs/book/tutorials/kubernetes-on-vsphere-with-kubeadm.md#prerequisites).
  10. After this step you should have:
  11. - vSphere upgraded to 6.7 U3 or later
  12. - VM hardware upgraded to version 15 or higher
  13. - UUID activated for each VM where Kubernetes will be deployed
  14. ### Kubespray configuration
  15. First in `inventory/sample/group_vars/all/all.yml` you must set the `cloud_provider` to `external` and `external_cloud_provider` to `vsphere`.
  16. ```yml
  17. cloud_provider: "external"
  18. external_cloud_provider: "vsphere"
  19. ```
  20. Then, `inventory/sample/group_vars/all/vsphere.yml`, you need to declare your vCenter credentials and enable the vSphere CSI following the description below.
  21. | Variable | Required | Type | Choices | Default | Comment |
  22. |----------------------------------------|----------|---------|----------------------------|---------------------------|---------------------------------------------------------------------------------------------------------------------|
  23. | external_vsphere_vcenter_ip | TRUE | string | | | IP/URL of the vCenter |
  24. | external_vsphere_vcenter_port | TRUE | string | | "443" | Port of the vCenter API |
  25. | external_vsphere_insecure | TRUE | string | "true", "false" | "true" | set to "true" if the host above uses a self-signed cert |
  26. | external_vsphere_user | TRUE | string | | | User name for vCenter with required privileges (Can also be specified with the `VSPHERE_USER` environment variable) |
  27. | external_vsphere_password | TRUE | string | | | Password for vCenter (Can also be specified with the `VSPHERE_PASSWORD` environment variable) |
  28. | external_vsphere_datacenter | TRUE | string | | | Datacenter name to use |
  29. | external_vsphere_kubernetes_cluster_id | TRUE | string | | "kubernetes-cluster-id" | Kubernetes cluster ID to use |
  30. | vsphere_csi_enabled | TRUE | boolean | | false | Enable vSphere CSI |
  31. Example configuration:
  32. ```yml
  33. external_vsphere_vcenter_ip: "myvcenter.domain.com"
  34. external_vsphere_vcenter_port: "443"
  35. external_vsphere_insecure: "true"
  36. external_vsphere_user: "administrator@vsphere.local"
  37. external_vsphere_password: "K8s_admin"
  38. external_vsphere_datacenter: "DATACENTER_name"
  39. external_vsphere_kubernetes_cluster_id: "kubernetes-cluster-id"
  40. vsphere_csi_enabled: true
  41. ```
  42. For a more fine-grained CSI setup, refer to the [vsphere-csi](/docs/vsphere-csi.md) documentation.
  43. ### Deployment
  44. Once the configuration is set, you can execute the playbook again to apply the new configuration:
  45. ```ShellSession
  46. cd kubespray
  47. ansible-playbook -i inventory/sample/hosts.ini -b -v cluster.yml
  48. ```
  49. You'll find some useful examples [here](https://github.com/kubernetes/cloud-provider-vsphere/blob/master/docs/book/tutorials/kubernetes-on-vsphere-with-kubeadm.md#sample-manifests-to-test-csi-driver-functionality) to test your configuration.
  50. ## In-tree vSphere cloud provider ([deprecated](https://cloud-provider-vsphere.sigs.k8s.io/concepts/in_tree_vs_out_of_tree.html))
  51. ### Prerequisites (deprecated)
  52. You need at first to configure your vSphere environment by following the [official documentation](https://kubernetes.io/docs/getting-started-guides/vsphere/#vsphere-cloud-provider).
  53. After this step you should have:
  54. - UUID activated for each VM where Kubernetes will be deployed
  55. - A vSphere account with required privileges
  56. If you intend to leverage the [zone and region node labeling](https://kubernetes.io/docs/reference/kubernetes-api/labels-annotations-taints/#failure-domain-beta-kubernetes-io-region), create a tag category for both the zone and region in vCenter. The tags can then be applied at the host, cluster, datacenter, or folder level, and the cloud provider will walk the hierarchy to extract and apply the labels to the Kubernetes nodes.
  57. ### Kubespray configuration (deprecated)
  58. First you must define the cloud provider in `inventory/sample/group_vars/all.yml` and set it to `vsphere`.
  59. ```yml
  60. cloud_provider: vsphere
  61. ```
  62. Then, in the same file, you need to declare your vCenter credentials following the description below.
  63. | Variable | Required | Type | Choices | Default | Comment |
  64. |------------------------------|----------|---------|----------------------------|---------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  65. | vsphere_vcenter_ip | TRUE | string | | | IP/URL of the vCenter |
  66. | vsphere_vcenter_port | TRUE | integer | | | Port of the vCenter API. Commonly 443 |
  67. | vsphere_insecure | TRUE | integer | 1, 0 | | set to 1 if the host above uses a self-signed cert |
  68. | vsphere_user | TRUE | string | | | User name for vCenter with required privileges |
  69. | vsphere_password | TRUE | string | | | Password for vCenter |
  70. | vsphere_datacenter | TRUE | string | | | Datacenter name to use |
  71. | vsphere_datastore | TRUE | string | | | Datastore name to use |
  72. | vsphere_working_dir | TRUE | string | | | Working directory from the view "VMs and template" in the vCenter where VM are placed |
  73. | vsphere_scsi_controller_type | TRUE | string | buslogic, pvscsi, parallel | pvscsi | SCSI controller name. Commonly "pvscsi". |
  74. | vsphere_vm_uuid | FALSE | string | | | VM Instance UUID of virtual machine that host K8s master. Can be retrieved from instanceUuid property in VmConfigInfo, or as vc.uuid in VMX file or in `/sys/class/dmi/id/product_serial` (Optional, only used for Kubernetes <= 1.9.2) |
  75. | vsphere_public_network | FALSE | string | | Blank | Name of the network the VMs are joined to |
  76. | vsphere_resource_pool | FALSE | string | | Blank | Name of the Resource pool where the VMs are located (Optional, only used for Kubernetes >= 1.9.2) |
  77. | vsphere_zone_category | FALSE | string | | | Name of the tag category used to set the `failure-domain.beta.kubernetes.io/zone` label on nodes (Optional, only used for Kubernetes >= 1.12.0) |
  78. | vsphere_region_category | FALSE | string | | | Name of the tag category used to set the `failure-domain.beta.kubernetes.io/region` label on nodes (Optional, only used for Kubernetes >= 1.12.0) |
  79. Example configuration:
  80. ```yml
  81. vsphere_vcenter_ip: "myvcenter.domain.com"
  82. vsphere_vcenter_port: 443
  83. vsphere_insecure: 1
  84. vsphere_user: "k8s@vsphere.local"
  85. vsphere_password: "K8s_admin"
  86. vsphere_datacenter: "DATACENTER_name"
  87. vsphere_datastore: "DATASTORE_name"
  88. vsphere_working_dir: "Docker_hosts"
  89. vsphere_scsi_controller_type: "pvscsi"
  90. vsphere_resource_pool: "K8s-Pool"
  91. ```
  92. ### Deployment (deprecated)
  93. Once the configuration is set, you can execute the playbook again to apply the new configuration:
  94. ```ShellSession
  95. cd kubespray
  96. ansible-playbook -i inventory/sample/hosts.ini -b -v cluster.yml
  97. ```
  98. You'll find some useful examples [here](https://github.com/kubernetes/examples/tree/master/staging/volumes/vsphere) to test your configuration.