2014-07-14 17:50:04 +00:00
|
|
|
#!/bin/bash
|
|
|
|
|
2015-05-01 16:19:44 +00:00
|
|
|
# Copyright 2014 The Kubernetes Authors All rights reserved.
|
2014-07-14 17:50:04 +00:00
|
|
|
#
|
|
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
# you may not use this file except in compliance with the License.
|
|
|
|
# You may obtain a copy of the License at
|
|
|
|
#
|
|
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
#
|
|
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
# See the License for the specific language governing permissions and
|
|
|
|
# limitations under the License.
|
|
|
|
|
|
|
|
# exit on any error
|
|
|
|
set -e
|
|
|
|
|
2015-06-10 06:02:27 +00:00
|
|
|
#setup kubelet config
|
|
|
|
mkdir -p "/var/lib/kubelet"
|
|
|
|
(umask 077;
|
|
|
|
cat > "/var/lib/kubelet/kubeconfig" << EOF
|
|
|
|
apiVersion: v1
|
|
|
|
kind: Config
|
|
|
|
users:
|
|
|
|
- name: kubelet
|
|
|
|
user:
|
|
|
|
token: ${KUBELET_TOKEN}
|
|
|
|
clusters:
|
|
|
|
- name: local
|
|
|
|
cluster:
|
|
|
|
insecure-skip-tls-verify: true
|
|
|
|
contexts:
|
|
|
|
- context:
|
|
|
|
cluster: local
|
|
|
|
user: kubelet
|
|
|
|
name: service-account-context
|
|
|
|
current-context: service-account-context
|
|
|
|
EOF
|
|
|
|
)
|
|
|
|
|
|
|
|
#setup proxy config
|
|
|
|
mkdir -p "/var/lib/kube-proxy/"
|
|
|
|
# Make a kubeconfig file with the token.
|
|
|
|
# TODO(etune): put apiserver certs into secret too, and reference from authfile,
|
|
|
|
# so that "Insecure" is not needed.
|
|
|
|
(umask 077;
|
|
|
|
cat > "/var/lib/kube-proxy/kubeconfig" << EOF
|
|
|
|
apiVersion: v1
|
|
|
|
kind: Config
|
|
|
|
users:
|
|
|
|
- name: kube-proxy
|
|
|
|
user:
|
|
|
|
token: ${KUBE_PROXY_TOKEN}
|
|
|
|
clusters:
|
|
|
|
- name: local
|
|
|
|
cluster:
|
|
|
|
insecure-skip-tls-verify: true
|
|
|
|
contexts:
|
|
|
|
- context:
|
|
|
|
cluster: local
|
|
|
|
user: kube-proxy
|
|
|
|
name: service-account-context
|
|
|
|
current-context: service-account-context
|
|
|
|
EOF
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-06-02 01:19:38 +00:00
|
|
|
# Set the host name explicitly
|
|
|
|
# See: https://github.com/mitchellh/vagrant/issues/2430
|
|
|
|
hostnamectl set-hostname ${MINION_NAME}
|
|
|
|
|
2015-07-01 18:16:20 +00:00
|
|
|
if [[ "$(grep 'VERSION_ID' /etc/os-release)" =~ ^VERSION_ID=21 ]]; then
|
|
|
|
# Workaround to vagrant inability to guess interface naming sequence
|
|
|
|
# Tell system to abandon the new naming scheme and use eth* instead
|
|
|
|
rm -f /etc/sysconfig/network-scripts/ifcfg-enp0s3
|
2015-06-02 01:19:38 +00:00
|
|
|
|
2015-07-01 18:16:20 +00:00
|
|
|
# Disable network interface being managed by Network Manager (needed for Fedora 21+)
|
|
|
|
NETWORK_CONF_PATH=/etc/sysconfig/network-scripts/
|
2015-07-17 21:28:54 +00:00
|
|
|
if_to_edit=$( find ${NETWORK_CONF_PATH}ifcfg-* | xargs grep -l VAGRANT-BEGIN )
|
|
|
|
for if_conf in ${if_to_edit}; do
|
|
|
|
grep -q ^NM_CONTROLLED= ${if_conf} || echo 'NM_CONTROLLED=no' >> ${if_conf}
|
|
|
|
sed -i 's/#^NM_CONTROLLED=.*/NM_CONTROLLED=no/' ${if_conf}
|
|
|
|
done;
|
2015-07-01 18:16:20 +00:00
|
|
|
systemctl restart network
|
|
|
|
fi
|
2015-06-02 01:19:38 +00:00
|
|
|
|
2015-07-17 21:28:54 +00:00
|
|
|
NETWORK_IF_NAME=`echo ${if_to_edit} | awk -F- '{ print $3 }'`
|
|
|
|
|
2014-09-05 16:33:52 +00:00
|
|
|
# Setup hosts file to support ping by hostname to master
|
2014-08-12 19:43:35 +00:00
|
|
|
if [ ! "$(cat /etc/hosts | grep $MASTER_NAME)" ]; then
|
2014-09-05 16:33:52 +00:00
|
|
|
echo "Adding $MASTER_NAME to hosts file"
|
2014-08-12 19:43:35 +00:00
|
|
|
echo "$MASTER_IP $MASTER_NAME" >> /etc/hosts
|
|
|
|
fi
|
2015-06-02 01:19:38 +00:00
|
|
|
echo "$MINION_IP $MINION_NAME" >> /etc/hosts
|
2014-07-14 17:50:04 +00:00
|
|
|
|
2014-09-05 16:33:52 +00:00
|
|
|
# Setup hosts file to support ping by hostname to each minion in the cluster
|
|
|
|
for (( i=0; i<${#MINION_NAMES[@]}; i++)); do
|
|
|
|
minion=${MINION_NAMES[$i]}
|
2014-12-12 19:08:22 +00:00
|
|
|
ip=${MINION_IPS[$i]}
|
2014-09-05 16:33:52 +00:00
|
|
|
if [ ! "$(cat /etc/hosts | grep $minion)" ]; then
|
|
|
|
echo "Adding $minion to hosts file"
|
|
|
|
echo "$ip $minion" >> /etc/hosts
|
2014-10-03 21:58:49 +00:00
|
|
|
fi
|
2014-09-05 16:33:52 +00:00
|
|
|
done
|
|
|
|
|
2015-06-02 01:19:38 +00:00
|
|
|
# Configure network
|
|
|
|
provision-network
|
|
|
|
|
|
|
|
# Placeholder for any other manifests that may be per-node.
|
|
|
|
mkdir -p /etc/kubernetes/manifests
|
|
|
|
|
2014-08-12 19:43:35 +00:00
|
|
|
# Let the minion know who its master is
|
2015-02-21 18:31:50 +00:00
|
|
|
# Recover the salt-minion if the salt-master network changes
|
|
|
|
## auth_timeout - how long we want to wait for a time out
|
|
|
|
## auth_tries - how many times we will retry before restarting salt-minion
|
|
|
|
## auth_safemode - if our cert is rejected, we will restart salt minion
|
|
|
|
## ping_interval - restart the minion if we cannot ping the master after 1 minute
|
|
|
|
## random_reauth_delay - wait 0-3 seconds when reauthenticating
|
|
|
|
## recon_default - how long to wait before reconnecting
|
|
|
|
## recon_max - how long you will wait upper bound
|
|
|
|
## state_aggregrate - try to do a single yum command to install all referenced packages where possible at once, should improve startup times
|
|
|
|
##
|
2014-08-12 19:43:35 +00:00
|
|
|
mkdir -p /etc/salt/minion.d
|
2014-12-16 23:16:59 +00:00
|
|
|
cat <<EOF >/etc/salt/minion.d/master.conf
|
|
|
|
master: '$(echo "$MASTER_NAME" | sed -e "s/'/''/g")'
|
2015-02-21 18:31:50 +00:00
|
|
|
auth_timeout: 10
|
|
|
|
auth_tries: 2
|
|
|
|
auth_safemode: True
|
|
|
|
ping_interval: 1
|
|
|
|
random_reauth_delay: 3
|
|
|
|
state_aggregrate:
|
|
|
|
- pkg
|
2014-12-16 23:16:59 +00:00
|
|
|
EOF
|
2014-07-14 17:50:04 +00:00
|
|
|
|
2014-12-12 19:08:22 +00:00
|
|
|
cat <<EOF >/etc/salt/minion.d/log-level-debug.conf
|
|
|
|
log_level: debug
|
|
|
|
log_level_logfile: debug
|
|
|
|
EOF
|
|
|
|
|
2014-08-12 19:43:35 +00:00
|
|
|
# Our minions will have a pool role to distinguish them from the master.
|
|
|
|
cat <<EOF >/etc/salt/minion.d/grains.conf
|
2014-07-14 17:50:04 +00:00
|
|
|
grains:
|
2015-03-10 20:47:26 +00:00
|
|
|
cloud: vagrant
|
2014-09-08 17:15:40 +00:00
|
|
|
network_mode: openvswitch
|
2014-12-16 23:16:59 +00:00
|
|
|
node_ip: '$(echo "$MINION_IP" | sed -e "s/'/''/g")'
|
|
|
|
api_servers: '$(echo "$MASTER_IP" | sed -e "s/'/''/g")'
|
2015-07-17 21:28:54 +00:00
|
|
|
networkInterfaceName: '$(echo "$NETWORK_IF_NAME" | sed -e "s/'/''/g")'
|
2014-07-14 17:50:04 +00:00
|
|
|
roles:
|
|
|
|
- kubernetes-pool
|
2014-12-12 19:08:22 +00:00
|
|
|
cbr-cidr: '$(echo "$CONTAINER_SUBNET" | sed -e "s/'/''/g")'
|
2015-04-21 13:23:37 +00:00
|
|
|
hostname_override: '$(echo "$MINION_IP" | sed -e "s/'/''/g")'
|
2015-06-02 01:19:38 +00:00
|
|
|
docker_opts: '$(echo "$DOCKER_OPTS" | sed -e "s/'/''/g")'
|
2014-07-14 17:50:04 +00:00
|
|
|
EOF
|
|
|
|
|
2015-09-02 21:02:23 +00:00
|
|
|
# QoS support requires that swap memory is disabled on each of the minions
|
|
|
|
echo "Disable swap memory to ensure proper QoS"
|
|
|
|
swapoff -a
|
|
|
|
|
2014-08-12 19:43:35 +00:00
|
|
|
# we will run provision to update code each time we test, so we do not want to do salt install each time
|
2014-08-28 05:08:35 +00:00
|
|
|
if ! which salt-minion >/dev/null 2>&1; then
|
2014-07-14 17:50:04 +00:00
|
|
|
# Install Salt
|
2014-08-28 15:05:20 +00:00
|
|
|
curl -sS -L --connect-timeout 20 --retry 6 --retry-delay 10 https://bootstrap.saltstack.com | sh -s
|
2014-12-12 19:08:22 +00:00
|
|
|
else
|
|
|
|
# Sometimes the minion gets wedged when it comes up along with the master.
|
|
|
|
# Restarting it here un-wedges it.
|
|
|
|
systemctl restart salt-minion.service
|
2014-07-14 17:50:04 +00:00
|
|
|
fi
|