Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions ansible/install.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
---
- name: Ensure dependencies are installed
hosts: localhost
gather_facts: true
tags:
- kolla-ansible
- install
- bootstrap
vars:
kolla_ansible_install_epel: "{{ dnf_install_epel }}"
kolla_ansible_custom_requirements_search_paths_static:
- "{{ kayobe_config_path }}"
kolla_ansible_custom_requirements_search_paths: "{{ kolla_ansible_custom_requirements_search_paths_static + kayobe_env_search_paths | default([]) }}"
kolla_ansible_custom_requirements_paths: "{{ kolla_ansible_custom_requirements_search_paths | map('regex_replace', '$', '/kolla/requirements.yml') | list }}"
tasks:
- name: Install Kayobe dependencies
import_role:
name: bootstrap
tasks_from: install.yml

- name: Install kolla-ansible
import_role:
name: kolla-ansible
tasks_from: install.yml
5 changes: 0 additions & 5 deletions ansible/kolla-ansible.yml
Original file line number Diff line number Diff line change
Expand Up @@ -101,11 +101,6 @@
name: kolla-ansible
vars:
kolla_ansible_control_host_become: "{{ kayobe_control_host_become | bool }}"
kolla_ansible_install_epel: "{{ dnf_install_epel }}"
kolla_ansible_custom_requirements_search_paths_static:
- "{{ kayobe_config_path }}"
kolla_ansible_custom_requirements_search_paths: "{{ kolla_ansible_custom_requirements_search_paths_static + kayobe_env_search_paths | default([]) }}"
kolla_ansible_custom_requirements_paths: "{{ kolla_ansible_custom_requirements_search_paths | map('regex_replace', '$', '/kolla/requirements.yml') | list }}"
kolla_external_fqdn_cert: "{{ kolla_config_path }}/certificates/haproxy.pem"
kolla_internal_fqdn_cert: "{{ kolla_config_path }}/certificates/haproxy-internal.pem"
kolla_ansible_passwords_path: "{{ kayobe_env_config_path }}/kolla/passwords.yml"
Expand Down
10 changes: 4 additions & 6 deletions ansible/roles/arista-switch/templates/arista-config.j2
Original file line number Diff line number Diff line change
Expand Up @@ -4,14 +4,12 @@
{{ line }}
{% endfor %}

{% for interface, config in
arista_switch_interface_config.items() %}
interface {{ interface }}
{% for interface, config in arista_switch_interface_config.items() %}
interface {{ interface }}
{% if config.description is defined %}
description {{ config.description }}
description {{ config.description }}
{% endif %}
{% for line in config.config %}
{{ line }}
{{ line }}
{% endfor %}
exit
{% endfor %}
46 changes: 46 additions & 0 deletions ansible/roles/bootstrap/tasks/install.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
- block:
- name: Testing privilege escalation
raw: "true"
become: true
failed_when: false
changed_when: false
register: privilege_escalation_result

- name: Assert that we can escalate privileges
assert:
that:
- privilege_escalation_result is success
- '"password is required" not in privilege_escalation_result.stderr'
fail_msg: >-
Could not escalate privileges. You can either: set kayobe_control_host_become: true,
set ansible_become_password, or set up passwordless sudo.
when: kayobe_control_host_become | bool

- name: Include OS family-specific variables
include_vars: "{{ ansible_facts.os_family }}.yml"

- name: Gather the package facts
ansible.builtin.package_facts:
manager: auto

- block:
- name: Assert that all packages are installed if not using privilege escalation
assert:
that: missing_packages is falsy
fail_msg: >-
The following packages are missing from your system: {{ missing_packages | join(', ') }} and
privilege escalation is disabled. Please get your system administator to install these packages
or enable kayobe_control_host_become.
when: not kayobe_control_host_become | bool

- name: Ensure required packages are installed
package:
name: "{{ bootstrap_package_dependencies }}"
state: present
cache_valid_time: "{{ apt_cache_valid_time if ansible_facts.os_family == 'Debian' else omit }}"
update_cache: "{{ True if ansible_facts.os_family == 'Debian' else omit }}"
become: True
when: missing_packages is truthy
vars:
missing_packages: "{{ bootstrap_package_dependencies | difference(ansible_facts.packages.keys()) }}"
46 changes: 0 additions & 46 deletions ansible/roles/bootstrap/tasks/main.yml
Original file line number Diff line number Diff line change
@@ -1,50 +1,4 @@
---
- block:
- name: Testing privilege escalation
raw: "true"
become: true
failed_when: false
changed_when: false
register: privilege_escalation_result

- name: Assert that we can escalate privileges
assert:
that:
- privilege_escalation_result is success
- '"password is required" not in privilege_escalation_result.stderr'
fail_msg: >-
Could not escalate privileges. You can either: set kayobe_control_host_become: true,
set ansible_become_password, or set up passwordless sudo.
when: kayobe_control_host_become | bool

- name: Include OS family-specific variables
include_vars: "{{ ansible_facts.os_family }}.yml"

- name: Gather the package facts
ansible.builtin.package_facts:
manager: auto

- block:
- name: Assert that all packages are installed if not using privilege escalation
assert:
that: missing_packages is falsy
fail_msg: >-
The following packages are missing from your system: {{ missing_packages | join(', ') }} and
privilege escalation is disabled. Please get your system administator to install these packages
or enable kayobe_control_host_become.
when: not kayobe_control_host_become | bool

- name: Ensure required packages are installed
package:
name: "{{ bootstrap_package_dependencies }}"
state: present
cache_valid_time: "{{ apt_cache_valid_time if ansible_facts.os_family == 'Debian' else omit }}"
update_cache: "{{ True if ansible_facts.os_family == 'Debian' else omit }}"
become: True
when: missing_packages is truthy
vars:
missing_packages: "{{ bootstrap_package_dependencies | difference(ansible_facts.packages.keys()) }}"

- name: Check whether an SSH key exists
stat:
path: "{{ bootstrap_ssh_private_key_path }}"
Expand Down
2 changes: 1 addition & 1 deletion ansible/roles/kolla-ansible/tasks/install.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@
package:
name: "{{ packages }}"
state: present
cache_valid_time: "{{ apt_cache_valid_time if ansible_facts.os_family == 'Debian' else omit }}"
cache_valid_time: "{{ apt_cache_valid_time | default(3600) if ansible_facts.os_family == 'Debian' else omit }}"
update_cache: "{{ True if ansible_facts.os_family == 'Debian' else omit }}"
become: True
when: missing_packages is truthy
Expand Down
6 changes: 0 additions & 6 deletions ansible/roles/kolla-ansible/tasks/main.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,4 @@
---
# NOTE: Use import_tasks here, since tags are not applied to tasks included via
# include_tasks.
- import_tasks: install.yml
tags:
- install

- import_tasks: config.yml
tags:
- config
12 changes: 11 additions & 1 deletion ansible/roles/kolla-ansible/tests/test-defaults.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,17 @@
register: tempfile_result

- block:
- name: Install dependencies
include_role:
name: "{{ playbook_dir }}/.."
tasks_from: install.yml
vars:
kolla_ansible_source_path: "{{ temp_path }}/src"
kolla_ansible_ctl_install_type: "source"
kolla_ansible_source_url: "http://github.com/openstack/kolla-ansible"
kolla_ansible_source_version: "{{ openstack_branch }}"
kolla_ansible_venv: "{{ temp_path }}/venv"

- name: Test the kolla-ansible role with default values
include_role:
name: "{{ playbook_dir }}/.."
Expand Down Expand Up @@ -41,7 +52,6 @@
kolla_openstack_logging_debug: False
kolla_globals_paths_extra:
- "{{ tempfile_result.path ~ '/etc/kayobe/' }}"
apt_cache_valid_time: 3600

- name: Verify kolla-ansible installation
shell: ". {{ temp_path }}/venv/bin/activate && kolla-ansible -h"
Expand Down
12 changes: 11 additions & 1 deletion ansible/roles/kolla-ansible/tests/test-extras.yml
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,17 @@
bogus backend certificate

- block:
- name: Install dependencies
include_role:
name: "{{ playbook_dir }}/.."
tasks_from: install.yml
vars:
kolla_ansible_source_path: "{{ temp_path }}/src"
kolla_ansible_ctl_install_type: "source"
kolla_ansible_source_url: "http://github.com/openstack/kolla-ansible"
kolla_ansible_source_version: "{{ openstack_branch }}"
kolla_ansible_venv: "{{ temp_path }}/venv"

- name: Test the kolla-ansible role with default values
include_role:
name: ../../kolla-ansible
Expand Down Expand Up @@ -195,7 +206,6 @@
custom-password-1: "custom-password-1"
custom-password-2: "custom-password-2"
kolla_nova_compute_ironic_host: "controller1"
apt_cache_valid_time: 3600

- name: Verify kolla-ansible installation
shell: ". {{ temp_path }}/venv/bin/activate && kolla-ansible -h"
Expand Down
11 changes: 10 additions & 1 deletion ansible/roles/kolla-ansible/tests/test-globals-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,16 @@
register: tempfile_result

- block:
- name: Install dependencies
include_role:
name: "{{ playbook_dir }}/.."
tasks_from: install.yml
vars:
kolla_ansible_source_path: "{{ temp_path }}/src"
kolla_ansible_ctl_install_type: "source"
kolla_ansible_source_url: "http://github.com/openstack/kolla-ansible"
kolla_ansible_source_version: "{{ openstack_branch }}"
kolla_ansible_venv: "{{ temp_path }}/venv"

- name: Ensure directories exists
file:
Expand Down Expand Up @@ -74,7 +84,6 @@
- "{{ tempfile_result.path ~ '/etc/kayobe/' }}"
- "{{ tempfile_result.path ~ '/etc/kayobe/environments/level1/' }}"
- "{{ tempfile_result.path ~ '/etc/kayobe/environments/level2/' }}"
apt_cache_valid_time: 3600

- name: Verify kolla-ansible installation
shell: ". {{ temp_path }}/venv/bin/activate && kolla-ansible -h"
Expand Down
4 changes: 2 additions & 2 deletions ansible/roles/kolla-ansible/tests/test-requirements.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,8 @@
- block:
- name: Test the kolla-ansible role with extra Python requirements
include_role:
name: ../../kolla-ansible
name: "{{ playbook_dir }}/.."
tasks_from: install.yml
vars:
kolla_ansible_source_path: "{{ temp_path }}/src"
kolla_ansible_ctl_install_type: "source"
Expand Down Expand Up @@ -39,7 +40,6 @@
kolla_openstack_logging_debug: False
kolla_globals_paths_extra:
- "{{ tempfile_result.path ~ '/etc/kayobe/' }}"
apt_cache_valid_time: 3600

- name: List Python packages installed in virtualenv
command: "{{ temp_path }}/venv/bin/pip list"
Expand Down
24 changes: 24 additions & 0 deletions doc/source/deployment.rst
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,30 @@ To bootstrap the Ansible control host::

(kayobe) $ kayobe control host bootstrap

The bootstrap process now supports splitting dependency installation from
configuration. This is useful when building a container image for your
execution environment, where packages and Python dependencies are installed at
build time, and runtime-specific configuration is generated later.

To install dependencies only (without running later bootstrap steps)::

(kayobe) $ kayobe control host bootstrap --install-only

To skip installation and run only later bootstrap steps::

(kayobe) $ kayobe control host bootstrap --no-install

These modes are mutually exclusive.

Environment variables may be used to set defaults:

- ``KAYOBE_INSTALL_ONLY=true`` enables ``--install-only``
- ``KAYOBE_NO_INSTALL=true`` enables ``--no-install``

For example, a container image build may run ``--install-only``, then at
container runtime execute ``--no-install`` to complete control host bootstrap
once environment-specific configuration is available.

Since the Gazpacho 20.0.0 release it is possible to manage the Ansible control
host's configuration in the same way as other hosts. If using this feature, the
Ansible control host should be added to the Kayobe inventory in the
Expand Down
2 changes: 1 addition & 1 deletion doc/source/support-matrix.rst
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ therefore users need to build them by themselves.
.. note::

Rocky Linux 9 is no longer supported as a host OS. The 2025.1 Epoxy release
supports both CentOS Stream 9 and 10 to provide a route for migration.
supports both Rocky Linux 9 and 10 to provide a route for migration.

Supported container images
~~~~~~~~~~~~~~~~~~~~~~~~~~
Expand Down
46 changes: 41 additions & 5 deletions kayobe/cli/commands.py
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
import os
import re
import sys
import yaml

from cliff.command import Command
from cliff.hooks import CommandHook
Expand Down Expand Up @@ -301,13 +302,48 @@ def get_parser(self, prog_name):
group = parser.add_argument_group("Host Bootstrap")
group.add_argument("--add-known-hosts", action='store_true',
help="add SSH known hosts entries for each host")
install_group = group.add_mutually_exclusive_group()
install_group.add_argument(
"--no-install",
action='store_true',
default=yaml.safe_load(os.getenv("KAYOBE_NO_INSTALL", "false")),
help=("skip dependency installation and run later bootstrap "
"steps only (default from KAYOBE_NO_INSTALL env var)"),
)
install_group.add_argument(
"--install-only",
action='store_true',
default=yaml.safe_load(os.getenv("KAYOBE_INSTALL_ONLY", "false")),
help=("only install dependencies "
"(default from KAYOBE_INSTALL_ONLY env var)"),
)
return parser

def take_action(self, parsed_args):
self.app.LOG.debug("Bootstrapping Kayobe Ansible control host")
self.handle_kolla_tags_limits_deprecation(parsed_args)
ansible.install_galaxy_roles(parsed_args)
ansible.install_galaxy_collections(parsed_args)

if parsed_args.install_only and parsed_args.no_install:
self.app.LOG.error("--install-only and --no-install are "
"mutually exclusive")
sys.exit(1)

if parsed_args.no_install:
self.app.LOG.debug("Skipping dependency and Galaxy installation "
"due to --no-install")
else:
ansible.install_galaxy_roles(parsed_args)
ansible.install_galaxy_collections(parsed_args)

playbooks = _build_playbook_list("install")
self.run_kayobe_playbooks(parsed_args, playbooks,
ignore_limit=True)

if parsed_args.install_only:
self.app.LOG.debug("Skipping reset of bootstrap due to "
"--install-only")
return

playbooks = _build_playbook_list("bootstrap")
self.run_kayobe_playbooks(parsed_args, playbooks, ignore_limit=True)

Expand Down Expand Up @@ -455,11 +491,11 @@ def take_action(self, parsed_args):
# Use force to upgrade roles and collections.
ansible.install_galaxy_roles(parsed_args, force=True)
ansible.install_galaxy_collections(parsed_args, force=True)
playbooks = _build_playbook_list("install")
self.run_kayobe_playbooks(parsed_args, playbooks, ignore_limit=True)

playbooks = _build_playbook_list("bootstrap")
self.run_kayobe_playbooks(parsed_args, playbooks, ignore_limit=True)
playbooks = _build_playbook_list("kolla-ansible")
self.run_kayobe_playbooks(parsed_args, playbooks, tags="install",
ignore_limit=True, check=False)


class ControlHostServiceDeploy(KayobeAnsibleMixin, VaultMixin, Command):
Expand Down
Loading