---
# Copyright kubeinit contributors
# All Rights Reserved.
#
# Licensed under the Apache License, Version 2.0 (the "License"); you may
# not use this file except in compliance with the License. You may obtain
# a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
- name: Install buildah if required
ansible.builtin.package:
state: present
name: "buildah"
- name: Create a new working container image
ansible.builtin.command: buildah from --name {{ kubeinit_cluster_name }}-registry quay.io/kubeinit/registry:2
register: _result
changed_when: "_result.rc == 0"
- name: Update the container
ansible.builtin.command: buildah run {{ kubeinit_cluster_name }}-registry -- apk upgrade
register: _result
changed_when: "_result.rc == 0"
- name: Set kubeinit-cluster-name label
ansible.builtin.command: buildah config --label kubeinit-cluster-name={{ kubeinit_cluster_name }} {{ kubeinit_cluster_name }}-registry
register: _result
changed_when: "_result.rc == 0"
- name: Commit the container image
ansible.builtin.command: buildah commit {{ kubeinit_cluster_name }}-registry kubeinit/{{ kubeinit_cluster_name }}-registry:latest
register: _result
changed_when: "_result.rc == 0"
- name: Remove the buildah container
ansible.builtin.command: buildah rm {{ kubeinit_cluster_name }}-registry
register: _result
changed_when: "_result.rc == 0"
- name: Create a podman container to serve the registry
containers.podman.podman_container:
name: "{{ kubeinit_registry_service_name }}"
image: kubeinit/{{ kubeinit_cluster_name }}-registry:latest
pod: "{{ kubeinit_deployment_pod_name }}"
init: true
state: stopped
volumes:
- "{{ kubeinit_services_data_volume }}:/var/kubeinit"
env:
REGISTRY_AUTH: htpasswd
REGISTRY_AUTH_HTPASSWD_REALM: Registry
REGISTRY_HTTP_SECRET: ALongRandomSecretForRegistry
REGISTRY_AUTH_HTPASSWD_PATH: auth/htpasswd
REGISTRY_HTTP_TLS_CERTIFICATE: certs/domain.crt
REGISTRY_HTTP_TLS_KEY: certs/domain.key
REGISTRY_COMPATIBILITY_SCHEMA1_ENABLED: true
register: _result_container_info
retries: 5
delay: 10
until: not _result_container_info.failed
- name: Copy kubeinit registry secrets into registry container
ansible.builtin.shell: |
set -eo pipefail
podman --remote --connection {{ hostvars[kubeinit_registry_service_node].target }} cp {{ kubeinit_registry_service_name }}:{{ kubeinit_registry_directory_auth }} - | \
podman --remote --connection {{ hostvars[kubeinit_registry_service_node].target }} cp - "{{ kubeinit_registry_service_name }}:/"
podman --remote --connection {{ hostvars[kubeinit_registry_service_node].target }} cp {{ kubeinit_registry_service_name }}:{{ kubeinit_registry_directory_cert }} - | \
podman --remote --connection {{ hostvars[kubeinit_registry_service_node].target }} cp - "{{ kubeinit_registry_service_name }}:/"
args:
executable: /bin/bash
register: _result
changed_when: "_result.rc == 0"
delegate_to: localhost
- name: Create systemd service for podman container
ansible.builtin.include_role:
name: kubeinit.kubeinit.kubeinit_services
tasks_from: create_managed_service.yml
public: true
vars:
_param_service_user_dir: "{{ kubeinit_service_user_dir }}"
_param_service_user: "{{ kubeinit_service_user }}"
_param_systemd_service_name: "{{ kubeinit_registry_service_name }}"
_param_podman_container_name: "{{ _result_container_info.container.Name }}"
_param_podman_container_pidfile: "{{ _result_container_info.container.ConmonPidFile }}"
- name: Clear temp facts
ansible.builtin.set_fact:
_result_container_info: null