mirror of
https://github.com/puppetmaster/typhoon.git
synced 2024-12-26 07:29:32 +01:00
ad2e4311d1
* Allow multi-controller clusters on Google Cloud * GCP regional network load balancers have a long open bug in which requests originating from a backend instance are routed to the instance itself, regardless of whether the health check passes or not. As a result, only the 0th controller node registers. We've recommended just using single master GCP clusters for a while * https://issuetracker.google.com/issues/67366622 * Workaround issue by switching to a GCP TCP Proxy load balancer. TCP proxy lb routes traffic to a backend service (global) of instance group backends. In our case, spread controllers across 3 zones (all regions have 3+ zones) and organize them in 3 zonal unmanaged instance groups that serve as backends. Allows multi-controller cluster creation * GCP network load balancers only allowed legacy HTTP health checks so kubelet 10255 was checked as an approximation of controller health. Replace with TCP apiserver health checks to detect unhealth or unresponsive apiservers. * Drawbacks: GCP provision time increases, tailed logs now timeout (similar tradeoff in AWS), controllers only span 3 zones instead of the exact number in the region * Workaround in Typhoon has been known and posted for 5 months, but there still appears to be no better alternative. Its probably time to support multi-master and accept the downsides
92 lines
2.4 KiB
HCL
92 lines
2.4 KiB
HCL
# Secure copy etcd TLS assets to controllers.
|
|
resource "null_resource" "copy-controller-secrets" {
|
|
count = "${var.controller_count}"
|
|
|
|
connection {
|
|
type = "ssh"
|
|
host = "${element(local.controllers_ipv4_public, count.index)}"
|
|
user = "core"
|
|
timeout = "15m"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_ca_cert}"
|
|
destination = "$HOME/etcd-client-ca.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_client_cert}"
|
|
destination = "$HOME/etcd-client.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_client_key}"
|
|
destination = "$HOME/etcd-client.key"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_server_cert}"
|
|
destination = "$HOME/etcd-server.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_server_key}"
|
|
destination = "$HOME/etcd-server.key"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_peer_cert}"
|
|
destination = "$HOME/etcd-peer.crt"
|
|
}
|
|
|
|
provisioner "file" {
|
|
content = "${module.bootkube.etcd_peer_key}"
|
|
destination = "$HOME/etcd-peer.key"
|
|
}
|
|
|
|
provisioner "remote-exec" {
|
|
inline = [
|
|
"sudo mkdir -p /etc/ssl/etcd/etcd",
|
|
"sudo mv etcd-client* /etc/ssl/etcd/",
|
|
"sudo cp /etc/ssl/etcd/etcd-client-ca.crt /etc/ssl/etcd/etcd/server-ca.crt",
|
|
"sudo mv etcd-server.crt /etc/ssl/etcd/etcd/server.crt",
|
|
"sudo mv etcd-server.key /etc/ssl/etcd/etcd/server.key",
|
|
"sudo cp /etc/ssl/etcd/etcd-client-ca.crt /etc/ssl/etcd/etcd/peer-ca.crt",
|
|
"sudo mv etcd-peer.crt /etc/ssl/etcd/etcd/peer.crt",
|
|
"sudo mv etcd-peer.key /etc/ssl/etcd/etcd/peer.key",
|
|
"sudo chown -R etcd:etcd /etc/ssl/etcd",
|
|
"sudo chmod -R 500 /etc/ssl/etcd",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Secure copy bootkube assets to ONE controller and start bootkube to perform
|
|
# one-time self-hosted cluster bootstrapping.
|
|
resource "null_resource" "bootkube-start" {
|
|
depends_on = [
|
|
"module.bootkube",
|
|
"module.workers",
|
|
"google_dns_record_set.apiserver",
|
|
"null_resource.copy-controller-secrets",
|
|
]
|
|
|
|
connection {
|
|
type = "ssh"
|
|
host = "${element(local.controllers_ipv4_public, 0)}"
|
|
user = "core"
|
|
timeout = "15m"
|
|
}
|
|
|
|
provisioner "file" {
|
|
source = "${var.asset_dir}"
|
|
destination = "$HOME/assets"
|
|
}
|
|
|
|
provisioner "remote-exec" {
|
|
inline = [
|
|
"sudo mv $HOME/assets /opt/bootkube",
|
|
"sudo systemctl start bootkube",
|
|
]
|
|
}
|
|
}
|