From e261a94712f2895acf75115a72c950fd44741274 Mon Sep 17 00:00:00 2001 From: Henry Mollman Date: Fri, 7 Jul 2017 13:49:48 -0700 Subject: [PATCH 1/2] Add dock subnet cidr to kubernetes load balancers for consul and vault --- ansible/dock.yml | 2 +- ansible/group_vars/all.yml | 1 + ansible/group_vars/alpha-consul-single.yml | 1 + ansible/group_vars/alpha-vault-single.yml | 1 + 4 files changed, 4 insertions(+), 1 deletion(-) diff --git a/ansible/dock.yml b/ansible/dock.yml index 39baf0cb..7b831cb0 100644 --- a/ansible/dock.yml +++ b/ansible/dock.yml @@ -9,7 +9,7 @@ name={{ dock }} groups=dock -- include: image-builder.yml git_branch="v4.6.0" +- include: image-builder.yml git_branch="v4.6.2" - hosts: "{{ dock }}" tasks: diff --git a/ansible/group_vars/all.yml b/ansible/group_vars/all.yml index b92be710..353c2466 100644 --- a/ansible/group_vars/all.yml +++ b/ansible/group_vars/all.yml @@ -18,6 +18,7 @@ jobs_path: "{{ opts_root }}/jobs" cron_jobs_path: "{{ opts_root }}/crons" volumes_path: "{{ opts_root }}/volumes" daemon_sets_path: "{{ opts_root }}/daemonSets" +dock_subnet_cidr: "{{ dock_subnet_cidr }}" container_tag: "{{ git_branch }}" # registry settings diff --git a/ansible/group_vars/alpha-consul-single.yml b/ansible/group_vars/alpha-consul-single.yml index aea6a9a3..fcd225ff 100644 --- a/ansible/group_vars/alpha-consul-single.yml +++ b/ansible/group_vars/alpha-consul-single.yml @@ -8,3 +8,4 @@ container_tag: v0.6.4 container_run_args: consul agent -server -client=0.0.0.0 -bootstrap-expect=1 -data-dir=/tmp/db -ui service_type: "LoadBalancer" +service_load_balancer_ranges: ["{{ dock_subnet_cidr }}"] diff --git a/ansible/group_vars/alpha-vault-single.yml b/ansible/group_vars/alpha-vault-single.yml index 961a57bb..afd7b9d1 100644 --- a/ansible/group_vars/alpha-vault-single.yml +++ b/ansible/group_vars/alpha-vault-single.yml @@ -18,6 +18,7 @@ add_capabilities: - IPC_LOCK service_type: "LoadBalancer" +service_load_balancer_ranges: ["{{ dock_subnet_cidr }}"] # Describes policy needed by Vault to create IAM users for orgs to get their org ids # Docks will not come up if policy is incorrect From f90cf5923a03356a361596e9025cdcb32025a2ee Mon Sep 17 00:00:00 2001 From: Henry Mollman Date: Fri, 7 Jul 2017 14:35:39 -0700 Subject: [PATCH 2/2] Add explicit subnet value to vars --- ansible/group_vars/all.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ansible/group_vars/all.yml b/ansible/group_vars/all.yml index 353c2466..21b56265 100644 --- a/ansible/group_vars/all.yml +++ b/ansible/group_vars/all.yml @@ -18,7 +18,7 @@ jobs_path: "{{ opts_root }}/jobs" cron_jobs_path: "{{ opts_root }}/crons" volumes_path: "{{ opts_root }}/volumes" daemon_sets_path: "{{ opts_root }}/daemonSets" -dock_subnet_cidr: "{{ dock_subnet_cidr }}" +dock_subnet_cidr: "10.10.2.0/24" container_tag: "{{ git_branch }}" # registry settings