mirror of
https://github.com/puppetmaster/typhoon.git
synced 2025-01-15 01:09:34 +01:00
812a1adb49
* Kubelets can use a lower-privilege TLS client certificate with Org system:nodes and a binding to the system:node ClusterRole * Admin kubeconfig's continue to belong to Org system:masters to provide cluster-admin (available in assets/auth/kubeconfig or as a Terraform output kubeconfig-admin) * Remove bare-metal output variable kubeconfig
137 lines
3.8 KiB
HCL
137 lines
3.8 KiB
HCL
# Secure copy etcd TLS assets and kubeconfig to controllers. Activates kubelet.service
|
|
resource "null_resource" "copy-controller-secrets" {
|
|
count = "${length(var.controller_names)}"
|
|
|
|
# Without depends_on, remote-exec could start and wait for machines before
|
|
# matchbox groups are written, causing a deadlock.
|
|
depends_on = [
|
|
"matchbox_group.install",
|
|
"matchbox_group.controller",
|
|
"matchbox_group.worker",
|
|
]
|
|
|
|
connection {
|
|
type = "ssh"
|
|
host = "${element(var.controller_domains, count.index)}"
|
|
user = "fedora"
|
|
timeout = "60m"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.kubeconfig-kubelet}"
|
|
destination = "$HOME/kubeconfig"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_ca_cert}"
|
|
destination = "$HOME/etcd-client-ca.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_client_cert}"
|
|
destination = "$HOME/etcd-client.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_client_key}"
|
|
destination = "$HOME/etcd-client.key"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_server_cert}"
|
|
destination = "$HOME/etcd-server.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_server_key}"
|
|
destination = "$HOME/etcd-server.key"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_peer_cert}"
|
|
destination = "$HOME/etcd-peer.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_peer_key}"
|
|
destination = "$HOME/etcd-peer.key"
|
|
}
|
|
|
|
provisioner "remote-exec" {
|
|
inline = [
|
|
"sudo mkdir -p /etc/ssl/etcd/etcd",
|
|
"sudo mv etcd-client* /etc/ssl/etcd/",
|
|
"sudo cp /etc/ssl/etcd/etcd-client-ca.crt /etc/ssl/etcd/etcd/server-ca.crt",
|
|
"sudo mv etcd-server.crt /etc/ssl/etcd/etcd/server.crt",
|
|
"sudo mv etcd-server.key /etc/ssl/etcd/etcd/server.key",
|
|
"sudo cp /etc/ssl/etcd/etcd-client-ca.crt /etc/ssl/etcd/etcd/peer-ca.crt",
|
|
"sudo mv etcd-peer.crt /etc/ssl/etcd/etcd/peer.crt",
|
|
"sudo mv etcd-peer.key /etc/ssl/etcd/etcd/peer.key",
|
|
"sudo mv $HOME/kubeconfig /etc/kubernetes/kubeconfig",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Secure copy kubeconfig to all workers. Activates kubelet.service
|
|
resource "null_resource" "copy-worker-secrets" {
|
|
count = "${length(var.worker_names)}"
|
|
|
|
# Without depends_on, remote-exec could start and wait for machines before
|
|
# matchbox groups are written, causing a deadlock.
|
|
depends_on = [
|
|
"matchbox_group.install",
|
|
"matchbox_group.controller",
|
|
"matchbox_group.worker",
|
|
]
|
|
|
|
connection {
|
|
type = "ssh"
|
|
host = "${element(var.worker_domains, count.index)}"
|
|
user = "fedora"
|
|
timeout = "60m"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.kubeconfig-kubelet}"
|
|
destination = "$HOME/kubeconfig"
|
|
}
|
|
|
|
provisioner "remote-exec" {
|
|
inline = [
|
|
"sudo mv $HOME/kubeconfig /etc/kubernetes/kubeconfig",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Secure copy bootkube assets to ONE controller and start bootkube to perform
|
|
# one-time self-hosted cluster bootstrapping.
|
|
resource "null_resource" "bootkube-start" {
|
|
# Without depends_on, this remote-exec may start before the kubeconfig copy.
|
|
# Terraform only does one task at a time, so it would try to bootstrap
|
|
# while no Kubelets are running.
|
|
depends_on = [
|
|
"null_resource.copy-controller-secrets",
|
|
"null_resource.copy-worker-secrets",
|
|
]
|
|
|
|
connection {
|
|
type = "ssh"
|
|
host = "${element(var.controller_domains, 0)}"
|
|
user = "fedora"
|
|
timeout = "15m"
|
|
}
|
|
|
|
provisioner "file" {
|
|
source = "${var.asset_dir}"
|
|
destination = "$HOME/assets"
|
|
}
|
|
|
|
provisioner "remote-exec" {
|
|
inline = [
|
|
"while [ ! -f /var/lib/cloud/instance/boot-finished ]; do sleep 4; done",
|
|
"sudo mv $HOME/assets /var/lib/bootkube",
|
|
"sudo systemctl start bootkube",
|
|
]
|
|
}
|
|
}
|