--- - fail: msg: "Only set one of kubernetes_context or openshift_host" when: openshift_host is defined and kubernetes_context is defined - include_tasks: "{{ tasks }}" with_items: - openshift_auth.yml - openshift.yml loop_control: loop_var: tasks when: openshift_host is defined - include_tasks: "{{ tasks }}" with_items: - kubernetes_auth.yml - kubernetes.yml loop_control: loop_var: tasks when: kubernetes_context is defined - name: Use kubectl or oc set_fact: kubectl_or_oc: "{{ openshift_oc_bin if openshift_oc_bin is defined else 'kubectl' }}" - set_fact: deployment_object: "sts" - name: Record deployment size shell: | {{ kubectl_or_oc }} get {{ deployment_object }} \ {{ kubernetes_deployment_name }} \ -n {{ kubernetes_namespace }} -o=jsonpath='{.status.replicas}' register: deployment_details ignore_errors: yes - name: Set expected post-deployment Replicas value set_fact: kubernetes_deployment_replica_size: "{{ deployment_details.stdout | int }}" when: deployment_details.rc == 0 - name: Delete existing Deployment shell: | {{ kubectl_or_oc }} delete {{ deployment_object }} \ {{ kubernetes_deployment_name }} -n {{ kubernetes_namespace }} when: deployment_details.rc == 0 - name: Get Postgres Service Detail shell: "{{ kubectl_or_oc }} describe svc {{ postgresql_service_name }} -n {{ kubernetes_namespace }}" register: postgres_svc_details ignore_errors: yes when: "pg_hostname is not defined or pg_hostname == ''" - name: Deploy PostgreSQL (OpenShift) block: - name: Template PostgreSQL Deployment (OpenShift) template: src: postgresql-persistent.yml.j2 dest: "{{ kubernetes_base_path }}/postgresql-persistent.yml" mode: '0600' - name: Deploy and Activate Postgres (OpenShift) shell: | {{ openshift_oc_bin }} new-app --file={{ kubernetes_base_path }}/postgresql-persistent.yml \ -e MEMORY_LIMIT={{ pg_memory_limit|default('512') }}Mi \ -e DATABASE_SERVICE_NAME=postgresql \ -e POSTGRESQL_MAX_CONNECTIONS={{ pg_max_connections|default(1024) }} \ -e POSTGRESQL_USER={{ pg_username }} \ -e POSTGRESQL_PASSWORD={{ pg_password | quote }} \ -e POSTGRESQL_ADMIN_PASSWORD={{ pg_admin_password | quote }} \ -e POSTGRESQL_DATABASE={{ pg_database }} \ -e POSTGRESQL_VERSION=10 \ -n {{ kubernetes_namespace }} register: openshift_pg_activate no_log: yes when: - pg_hostname is not defined or pg_hostname == '' - postgres_svc_details is defined and postgres_svc_details.rc != 0 - openshift_host is defined - name: Deploy PostgreSQL (Kubernetes) block: - name: Template PostgreSQL Deployment (Kubernetes) set_fact: pg_values: "{{ lookup('template', 'postgresql-values.yml.j2') }}" no_log: yes - name: Deploy and Activate Postgres (Kubernetes) shell: | helm repo update --tiller-namespace={{ tiller_namespace | default('kube-system') }} echo {{ pg_values | quote }} | helm upgrade {{ postgresql_service_name }} --install \ --namespace {{ kubernetes_namespace }} \ --version="6.2.1" \ --tiller-namespace={{ tiller_namespace | default('kube-system') }} \ --values - \ stable/postgresql register: kubernetes_pg_activate no_log: yes when: - pg_hostname is not defined or pg_hostname == '' - postgres_svc_details is defined and postgres_svc_details.rc != 0 - kubernetes_context is defined - name: Set postgresql hostname to helm package service (Kubernetes) set_fact: pg_hostname: "{{ postgresql_service_name }}" when: - pg_hostname is not defined or pg_hostname == '' - kubernetes_context is defined - name: Wait for Postgres to activate pause: seconds: "{{ postgress_activate_wait }}" when: openshift_pg_activate.changed or kubernetes_pg_activate.changed - name: Check postgres version and upgrade Postgres if necessary block: - name: Check if Postgres 9.6 is being used shell: | POD=$({{ kubectl_or_oc }} -n {{ kubernetes_namespace }} \ get pods -l=name=postgresql --field-selector status.phase=Running -o jsonpath="{.items[0].metadata.name}") oc exec $POD -n {{ kubernetes_namespace }} -- bash -c "psql -tAc 'select version()'" register: pg_version - name: Upgrade postgres if necessary block: - name: Set new pg image shell: | IMAGE=registry.access.redhat.com/rhscl/postgresql-10-rhel7 {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} set image dc/postgresql postgresql=$IMAGE - name: Wait for change to take affect pause: seconds: 5 - name: Set env var for pg upgrade shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} set env dc/postgresql POSTGRESQL_UPGRADE=copy - name: Wait for change to take affect pause: seconds: 5 - name: Set env var for new pg version shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} set env dc/postgresql POSTGRESQL_VERSION=10 - name: Wait for Postgres to redeploy pause: seconds: "{{ postgress_activate_wait }}" - name: Wait for Postgres to finish upgrading shell: | POD=$({{ kubectl_or_oc }} -n {{ kubernetes_namespace }} \ get pods -l=name=postgresql -o jsonpath="{.items[0].metadata.name}") {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} logs $POD | grep 'Upgrade DONE' register: pg_upgrade_logs retries: 360 delay: 10 until: pg_upgrade_logs is success - name: Unset upgrade env var shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} set env dc/postgresql POSTGRESQL_UPGRADE- - name: Wait for Postgres to redeploy pause: seconds: "{{ postgress_activate_wait }}" when: "pg_version is success and '9.6' in pg_version.stdout" when: - pg_hostname is not defined or pg_hostname == '' - name: Set image names if using custom registry block: - name: Set task image name set_fact: kubernetes_task_image: "{{ docker_registry }}/{{ docker_registry_repository }}/{{ task_image }}" when: kubernetes_task_image is not defined - name: Set web image name set_fact: kubernetes_web_image: "{{ docker_registry }}/{{ docker_registry_repository }}/{{ web_image }}" when: kubernetes_web_image is not defined when: docker_registry is defined - name: Generate SSL certificates for RabbitMQ, if needed include_tasks: ssl_cert_gen.yml when: "rabbitmq_use_ssl|default(False)|bool" - name: Get Kubernetes API version command: | {{ kubectl_or_oc }} version -o json register: kube_version - name: Extract server version from command output set_fact: kube_api_version: "{{ (kube_version.stdout | from_json).serverVersion.gitVersion[1:] }}" - name: Determine StatefulSet api version set_fact: kubernetes_statefulset_api_version: "{{ 'apps/v1' if kube_api_version is version('1.9', '>=') else 'apps/v1beta1' }}" - name: Render deployment templates set_fact: "{{ item }}": "{{ lookup('template', item + '.yml.j2') }}" with_items: - 'configmap' - 'deployment' - 'secret' no_log: yes - name: Apply Deployment shell: | echo {{ item | quote }} | {{ kubectl_or_oc }} apply -f - with_items: - "{{ configmap }}" - "{{ deployment }}" - "{{ secret }}" no_log: yes - name: Delete any existing management pod shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} \ delete pod ansible-tower-management --grace-period=0 --ignore-not-found - name: Template management pod set_fact: management_pod: "{{ lookup('template', 'management-pod.yml.j2') }}" - name: Create management pod shell: | echo {{ management_pod | quote }} | {{ kubectl_or_oc }} apply -f - - name: Wait for management pod to start shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} \ get pod ansible-tower-management -o jsonpath="{.status.phase}" register: result until: result.stdout == "Running" retries: 60 delay: 10 - name: Migrate database shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} exec ansible-tower-management -- \ bash -c "awx-manage migrate --noinput" - name: Check for Tower Super users shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} exec ansible-tower-management -- \ bash -c "echo 'from django.contrib.auth.models import User; nsu = User.objects.filter(is_superuser=True).count(); exit(0 if nsu > 0 else 1)' | awx-manage shell" register: super_check ignore_errors: yes changed_when: super_check.rc > 0 - name: create django super user if it does not exist shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} exec ansible-tower-management -- \ bash -c "echo \"from django.contrib.auth.models import User; User.objects.create_superuser('{{ admin_user }}', '{{ admin_email }}', '{{ admin_password }}')\" | awx-manage shell" no_log: yes when: super_check.rc > 0 - name: update django super user password shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} exec ansible-tower-management -- \ bash -c "awx-manage update_password --username='{{ admin_user }}' --password='{{ admin_password }}'" no_log: yes register: result changed_when: "'Password updated' in result.stdout" - name: Create the default organization if it is needed. shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} exec ansible-tower-management -- \ bash -c "awx-manage create_preload_data" register: cdo changed_when: "'added' in cdo.stdout" when: create_preload_data | bool - name: Delete management pod shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} \ delete pod ansible-tower-management --grace-period=0 --ignore-not-found - name: Scale up deployment shell: | {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} \ scale {{ deployment_object }} {{ kubernetes_deployment_name }} --replicas=0 {{ kubectl_or_oc }} -n {{ kubernetes_namespace }} \ scale {{ deployment_object }} {{ kubernetes_deployment_name }} --replicas={{ kubernetes_deployment_replica_size }}