Compare commits

...

11 Commits

18 changed files with 187 additions and 4 deletions
+1
View File
@@ -2,6 +2,7 @@
.*
terraform.tfstate
terraform.tfstate.backup
ansible/lookup_plugins
!.gitignore
!.editorconfig
+7
View File
@@ -1,6 +1,8 @@
#!/usr/bin/env just
opentofu_dir := "infra/"
ansible_proton_pass_plugin_ref := "4bd0741c347646060ec59c73f8adf7ed8e706cf3"
ansible_proton_pass_plugin_url := "https://raw.githubusercontent.com/protonpass/proton-pass-ansible-integration/" + ansible_proton_pass_plugin_ref + "/lookup_plugins/proton_pass.py"
up: tofu-apply ansible-run-playbook
down: tofu-destroy
@@ -15,6 +17,7 @@ tofu-destroy: tofu-init
tofu -chdir={{ opentofu_dir }} apply -auto-approve -destroy
ansible-run-playbook:
ansible-playbook -i ansible/inventories/incus/incus.yaml -c community.general.incus ansible/playbooks/provision.yaml -e ansible_user=root
ansible-playbook -i ansible/inventories/incus/incus.yaml -c community.general.incus ansible/site.yaml
get-admin-conf:
@@ -22,3 +25,7 @@ get-admin-conf:
clean: tofu-destroy
git clean -fdx
fetch-plugins:
mkdir -p ansible/lookup_plugins
curl -fsSL -o ansible/lookup_plugins/proton_pass.py {{ ansible_proton_pass_plugin_url }}
+16
View File
@@ -1 +1,17 @@
# Home Infrastructure
## Setup
```shell
just fetch-plugins
```
## Bare-metal provisioning
When creating a set of fresh machines, you must run the provisioning step to create the "Kolibri" automation user.
The Kolibri automation user is used for all other playbooks and has permissions to execute passwordless sudo.
```shell
ansible-playbook -i ansible/inventories/bare_metal/hosts.yaml ansible/playbooks/provision.yaml -K -e ansible_user=<your_interactive_user>
```
+2
View File
@@ -0,0 +1,2 @@
[defaults]
lookup_plugins = ansible/lookup_plugins
View File
-1
View File
@@ -1 +0,0 @@
ansible_python_interpreter: /usr/bin/python3
@@ -0,0 +1,5 @@
ansible_python_interpreter: /usr/bin/python3
ansible_become_exe: sudo.ws
ansible_user: kolibri
vip_interface: eno1
vip_address: 10.0.0.200
@@ -0,0 +1,8 @@
masters:
hosts:
vineta:
ansible_host: 10.0.0.201
rotfront:
ansible_host: 10.0.0.202
leng:
ansible_host: 10.0.0.203
@@ -0,0 +1,4 @@
ansible_python_interpreter: /usr/bin/python3
ansible_user: kolibri
vip_interface: enp5s0
vip_address: 10.150.0.100
+24
View File
@@ -0,0 +1,24 @@
- name: Provision kolibri automation user
hosts: all
become: true
tasks:
- name: Ensure Kolibri user exists
ansible.builtin.user:
name: kolibri
comment: Hummingbird
create_home: true
groups:
- sudo
shell: /bin/bash
- name: Ensure authorised keys for Kolibri
ansible.posix.authorized_key:
user: kolibri
key: "{{ lookup('proton_pass', vault_name='Home Lab', item_title='Kolibri Automation', field='Public key') }}"
- name: Allow passwordless sudo for Kolibri
ansible.builtin.copy:
content: "kolibri ALL=(ALL) NOPASSWD: ALL\n"
dest: /etc/sudoers.d/kolibri
mode: "0440"
validate: visudo -cf %s
+1 -1
View File
@@ -14,6 +14,6 @@
ansible.builtin.copy:
src: ssh.service
dest: /etc/avahi/services/ssh.service
mode: "644"
mode: "0644"
notify:
- Restart Avahi Daemon
@@ -0,0 +1,4 @@
- name: Restart keepalived
ansible.builtin.service:
name: keepalived
state: restarted
+12
View File
@@ -0,0 +1,12 @@
- name: Install keepalived
ansible.builtin.apt:
pkg:
- keepalived
state: present
- name: Install keepalived config
ansible.builtin.template:
src: keepalived.conf.j2
dest: /etc/keepalived/keepalived.conf
mode: "0644"
notify: Restart keepalived
@@ -0,0 +1,19 @@
vrrp_instance VI_1 {
state MASTER
interface enp5s0
virtual_router_id 51
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
10.150.0.100
10.150.0.101
10.150.0.102
}
# Allow packets addressed to the VIPs above to be received
accept
}
@@ -0,0 +1,5 @@
- name: Ensure kube-vip static pod
ansible.builtin.template:
src: kube-vip.yaml.j2
dest: /etc/kubernetes/manifests/kube-vip.yaml
mode: "0644"
@@ -1,10 +1,13 @@
- name: Install kube-vip
ansible.builtin.import_tasks: kube-vip.yaml
- name: Initialise Kubernetes cluster
ansible.builtin.command:
argv:
- kubeadm
- init
- --pod-network-cidr=172.16.0.0/16
- --control-plane-endpoint={{ ansible_facts['default_ipv4']['address'] }}:6443
- --control-plane-endpoint={{ vip_address }}:6443
- --upload-certs
args:
creates: /etc/kubernetes/admin.conf
@@ -0,0 +1,72 @@
apiVersion: v1
kind: Pod
metadata:
name: kube-vip
namespace: kube-system
spec:
containers:
- args:
- manager
env:
- name: vip_arp
value: "true"
- name: port
value: "6443"
- name: vip_nodename
valueFrom:
fieldRef:
fieldPath: spec.nodeName
- name: vip_interface
value: {{ vip_interface }}
- name: vip_subnet
value: "32"
- name: dns_mode
value: first
- name: dhcp_mode
value: ipv4
- name: cp_enable
value: "true"
- name: cp_namespace
value: kube-system
- name: svc_enable
value: "true"
- name: svc_leasename
value: plndr-svcs-lock
- name: vip_leaderelection
value: "true"
- name: vip_leasename
value: plndr-cp-lock
- name: vip_leaseduration
value: "15"
- name: vip_renewdeadline
value: "10"
- name: vip_retryperiod
value: "2"
- name: address
value: {{ vip_address }}
- name: prometheus_server
value: :2112
image: ghcr.io/kube-vip/kube-vip:v1.2.1
imagePullPolicy: IfNotPresent
name: kube-vip
resources: {}
securityContext:
capabilities:
add:
- NET_ADMIN
- NET_RAW
drop:
- ALL
volumeMounts:
- mountPath: /etc/kubernetes/admin.conf
name: kubeconfig
hostAliases:
- hostnames:
- kubernetes
ip: 127.0.0.1
hostNetwork: true
volumes:
- hostPath:
path: /etc/kubernetes/admin.conf
name: kubeconfig
status: {}
+3 -1
View File
@@ -1,5 +1,6 @@
- name: Common setup
- name: Baseline configuration
hosts: all
become: true
roles:
- common
- kubernetes_common
@@ -10,6 +11,7 @@
- name: Initialise Kubernetes Cluster
hosts: masters
become: true
roles:
- kubernetes_control_plane