1
0
mirror of https://github.com/rancher/rke.git synced 2025-05-02 13:33:32 +00:00
rke/cmd/up.go

372 lines
12 KiB
Go
Raw Normal View History

package cmd
import (
"context"
"fmt"
"os"
2018-04-18 06:04:30 +00:00
"strings"
2018-07-10 19:21:27 +00:00
"time"
"github.com/rancher/rke/cluster"
2018-07-10 19:21:27 +00:00
"github.com/rancher/rke/dind"
"github.com/rancher/rke/hosts"
"github.com/rancher/rke/log"
"github.com/rancher/rke/pki"
2017-12-16 03:38:15 +00:00
"github.com/rancher/types/apis/management.cattle.io/v3"
"github.com/sirupsen/logrus"
"github.com/urfave/cli"
"k8s.io/client-go/util/cert"
)
2018-07-10 19:21:27 +00:00
const DINDWaitTime = 3
func UpCommand() cli.Command {
upFlags := []cli.Flag{
cli.StringFlag{
Name: "config",
Usage: "Specify an alternate cluster YAML file",
Value: pki.ClusterConfig,
EnvVar: "RKE_CONFIG",
},
cli.BoolFlag{
Name: "local",
Usage: "Deploy Kubernetes cluster locally",
},
2018-07-10 19:21:27 +00:00
cli.BoolFlag{
Name: "dind",
Usage: "Deploy Kubernetes cluster in docker containers (experimental)",
},
2018-09-10 23:17:45 +00:00
cli.StringFlag{
Name: "dind-storage-driver",
Usage: "Storage driver for the docker in docker containers (experimental)",
},
cli.BoolFlag{
Name: "update-only",
Usage: "Skip idempotent deployment of control and etcd plane",
},
cli.BoolFlag{
Name: "disable-port-check",
Usage: "Disable port check validation between nodes",
},
cli.BoolFlag{
Name: "init",
Usage: "Initiate RKE cluster",
},
}
2018-05-15 17:35:52 +00:00
upFlags = append(upFlags, commonFlags...)
return cli.Command{
Name: "up",
Usage: "Bring the cluster up",
Action: clusterUpFromCli,
Flags: upFlags,
}
}
func doUpgradeLegacyCluster(ctx context.Context, kubeCluster *cluster.Cluster, fullState *cluster.FullState) error {
if _, err := os.Stat(kubeCluster.LocalKubeConfigPath); os.IsNotExist(err) {
// there is no kubeconfig. This is a new cluster
logrus.Debug("[state] local kubeconfig not found, this is a new cluster")
return nil
}
if _, err := os.Stat(kubeCluster.StateFilePath); err == nil {
// this cluster has a previous state, I don't need to upgrade!
logrus.Debug("[state] previous state found, this is not a legacy cluster")
return nil
}
// We have a kubeconfig and no current state. This is a legacy cluster or a new cluster with old kubeconfig
// let's try to upgrade
log.Infof(ctx, "[state] Possible legacy cluster detected, trying to upgrade")
if err := cluster.RebuildKubeconfig(ctx, kubeCluster); err != nil {
return err
}
recoveredCluster, err := cluster.GetStateFromKubernetes(ctx, kubeCluster)
if err != nil {
return err
}
// if we found a recovered cluster, we will need override the current state
if recoveredCluster != nil {
recoveredCerts, err := cluster.GetClusterCertsFromKubernetes(ctx, kubeCluster)
if err != nil {
return err
}
fullState.CurrentState.RancherKubernetesEngineConfig = recoveredCluster.RancherKubernetesEngineConfig.DeepCopy()
fullState.CurrentState.CertificatesBundle = recoveredCerts
// we don't want to regenerate certificates
fullState.DesiredState.CertificatesBundle = recoveredCerts
return fullState.WriteStateFile(ctx, kubeCluster.StateFilePath)
}
return nil
}
func ClusterUp(ctx context.Context, dialersOptions hosts.DialersOptions, flags cluster.ExternalFlags) (string, string, string, string, map[string]pki.CertificatePKI, error) {
var APIURL, caCrt, clientCert, clientKey string
2018-11-02 05:53:29 +00:00
clusterState, err := cluster.ReadStateFile(ctx, cluster.GetStateFilePath(flags.ClusterFilePath, flags.ConfigDir))
2018-11-02 05:53:29 +00:00
if err != nil {
return APIURL, caCrt, clientCert, clientKey, nil, err
}
kubeCluster, err := cluster.InitClusterObject(ctx, clusterState.DesiredState.RancherKubernetesEngineConfig.DeepCopy(), flags)
2018-11-02 05:53:29 +00:00
if err != nil {
return APIURL, caCrt, clientCert, clientKey, nil, err
}
// check if rotate certificates is triggered
if kubeCluster.RancherKubernetesEngineConfig.RotateCertificates != nil {
return rebuildClusterWithRotatedCertificates(ctx, dialersOptions, flags)
}
log.Infof(ctx, "Building Kubernetes cluster")
err = kubeCluster.SetupDialers(ctx, dialersOptions)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
err = kubeCluster.TunnelHosts(ctx, flags)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
currentCluster, err := kubeCluster.GetClusterState(ctx, clusterState)
2018-01-18 20:41:04 +00:00
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
2018-01-16 18:29:09 +00:00
}
if !flags.DisablePortCheck {
if err = kubeCluster.CheckClusterPorts(ctx, currentCluster); err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
}
err = cluster.SetUpAuthentication(ctx, kubeCluster, currentCluster, clusterState)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
if len(kubeCluster.ControlPlaneHosts) > 0 {
APIURL = fmt.Sprintf("https://" + kubeCluster.ControlPlaneHosts[0].Address + ":6443")
}
clientCert = string(cert.EncodeCertPEM(kubeCluster.Certificates[pki.KubeAdminCertName].Certificate))
clientKey = string(cert.EncodePrivateKeyPEM(kubeCluster.Certificates[pki.KubeAdminCertName].Key))
caCrt = string(cert.EncodeCertPEM(kubeCluster.Certificates[pki.CACertName].Certificate))
2018-11-02 05:53:29 +00:00
// moved deploying certs before reconcile to remove all unneeded certs generation from reconcile
err = kubeCluster.SetUpHosts(ctx, false)
if err != nil {
return APIURL, caCrt, clientCert, clientKey, nil, err
}
err = cluster.ReconcileCluster(ctx, kubeCluster, currentCluster, flags)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
// update APIURL after reconcile
if len(kubeCluster.ControlPlaneHosts) > 0 {
APIURL = fmt.Sprintf("https://" + kubeCluster.ControlPlaneHosts[0].Address + ":6443")
}
2018-11-02 05:53:29 +00:00
2018-02-01 21:43:09 +00:00
if err := kubeCluster.PrePullK8sImages(ctx); err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
2018-02-01 21:43:09 +00:00
}
err = kubeCluster.DeployControlPlane(ctx)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
2018-02-26 21:14:04 +00:00
// Apply Authz configuration after deploying controlplane
err = cluster.ApplyAuthzResources(ctx, kubeCluster.RancherKubernetesEngineConfig, flags, dialersOptions)
2018-02-26 21:14:04 +00:00
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
2018-02-26 21:14:04 +00:00
}
err = kubeCluster.UpdateClusterCurrentState(ctx, clusterState)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
err = cluster.SaveFullStateToKubernetes(ctx, kubeCluster, clusterState)
if err != nil {
return APIURL, caCrt, clientCert, clientKey, nil, err
}
err = kubeCluster.DeployWorkerPlane(ctx)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
if err = kubeCluster.CleanDeadLogs(ctx); err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
err = kubeCluster.SyncLabelsAndTaints(ctx, currentCluster)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
err = cluster.ConfigureCluster(ctx, kubeCluster.RancherKubernetesEngineConfig, kubeCluster.Certificates, flags, dialersOptions, false)
if err != nil {
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, nil, err
}
2018-04-18 06:04:30 +00:00
if err := checkAllIncluded(kubeCluster); err != nil {
return APIURL, caCrt, clientCert, clientKey, nil, err
}
log.Infof(ctx, "Finished building Kubernetes cluster successfully")
2018-04-02 11:02:00 +00:00
return APIURL, caCrt, clientCert, clientKey, kubeCluster.Certificates, nil
}
2018-04-18 06:04:30 +00:00
func checkAllIncluded(cluster *cluster.Cluster) error {
if len(cluster.InactiveHosts) == 0 {
return nil
}
var names []string
for _, host := range cluster.InactiveHosts {
names = append(names, host.Address)
}
return fmt.Errorf("Provisioning incomplete, host(s) [%s] skipped because they could not be contacted", strings.Join(names, ","))
}
func clusterUpFromCli(ctx *cli.Context) error {
2018-01-15 04:36:28 +00:00
if ctx.Bool("local") {
return clusterUpLocal(ctx)
}
2018-07-10 19:21:27 +00:00
if ctx.Bool("dind") {
return clusterUpDind(ctx)
}
2017-12-16 03:38:15 +00:00
clusterFile, filePath, err := resolveClusterFile(ctx)
if err != nil {
return fmt.Errorf("Failed to resolve cluster file: %v", err)
}
2017-12-16 03:38:15 +00:00
rkeConfig, err := cluster.ParseConfig(clusterFile)
if err != nil {
return fmt.Errorf("Failed to parse cluster file: %v", err)
}
rkeConfig, err = setOptionsFromCLI(ctx, rkeConfig)
if err != nil {
return err
}
updateOnly := ctx.Bool("update-only")
disablePortCheck := ctx.Bool("disable-port-check")
// setting up the flags
2018-11-12 23:24:59 +00:00
flags := cluster.GetExternalFlags(false, updateOnly, disablePortCheck, "", filePath)
if ctx.Bool("init") {
return ClusterInit(context.Background(), rkeConfig, hosts.DialersOptions{}, flags)
}
if err := ClusterInit(context.Background(), rkeConfig, hosts.DialersOptions{}, flags); err != nil {
2018-11-02 05:53:29 +00:00
return err
}
_, _, _, _, _, err = ClusterUp(context.Background(), hosts.DialersOptions{}, flags)
2018-01-15 04:36:28 +00:00
return err
}
func clusterUpLocal(ctx *cli.Context) error {
var rkeConfig *v3.RancherKubernetesEngineConfig
clusterFile, filePath, err := resolveClusterFile(ctx)
if err != nil {
log.Infof(context.Background(), "Failed to resolve cluster file, using default cluster instead")
rkeConfig = cluster.GetLocalRKEConfig()
} else {
rkeConfig, err = cluster.ParseConfig(clusterFile)
if err != nil {
return fmt.Errorf("Failed to parse cluster file: %v", err)
}
rkeConfig.Nodes = []v3.RKEConfigNode{*cluster.GetLocalRKENodeConfig()}
}
2018-05-15 17:35:52 +00:00
rkeConfig.IgnoreDockerVersion = ctx.Bool("ignore-docker-version")
// setting up the dialers
dialers := hosts.GetDialerOptions(nil, hosts.LocalHealthcheckFactory, nil)
// setting up the flags
2018-11-12 23:24:59 +00:00
flags := cluster.GetExternalFlags(true, false, false, "", filePath)
if ctx.Bool("init") {
return ClusterInit(context.Background(), rkeConfig, dialers, flags)
}
if err := ClusterInit(context.Background(), rkeConfig, dialers, flags); err != nil {
return err
}
_, _, _, _, _, err = ClusterUp(context.Background(), dialers, flags)
return err
}
2018-07-10 19:21:27 +00:00
func clusterUpDind(ctx *cli.Context) error {
// get dind config
rkeConfig, disablePortCheck, dindStorageDriver, filePath, err := getDindConfig(ctx)
2018-07-10 19:21:27 +00:00
if err != nil {
return err
}
// setup dind environment
2018-09-10 23:17:45 +00:00
if err = createDINDEnv(context.Background(), rkeConfig, dindStorageDriver); err != nil {
2018-07-10 19:21:27 +00:00
return err
}
// setting up the dialers
dialers := hosts.GetDialerOptions(hosts.DindConnFactory, hosts.DindHealthcheckConnFactory, nil)
// setting up flags
2018-11-12 23:24:59 +00:00
flags := cluster.GetExternalFlags(false, false, disablePortCheck, "", filePath)
flags.DinD = true
if ctx.Bool("init") {
return ClusterInit(context.Background(), rkeConfig, dialers, flags)
}
if err := ClusterInit(context.Background(), rkeConfig, dialers, flags); err != nil {
return err
}
2018-07-10 19:21:27 +00:00
// start cluster
_, _, _, _, _, err = ClusterUp(context.Background(), dialers, flags)
2018-07-10 19:21:27 +00:00
return err
}
func getDindConfig(ctx *cli.Context) (*v3.RancherKubernetesEngineConfig, bool, string, string, error) {
2018-07-10 19:21:27 +00:00
disablePortCheck := ctx.Bool("disable-port-check")
2018-09-10 23:17:45 +00:00
dindStorageDriver := ctx.String("dind-storage-driver")
2018-07-10 19:21:27 +00:00
clusterFile, filePath, err := resolveClusterFile(ctx)
if err != nil {
return nil, disablePortCheck, "", "", fmt.Errorf("Failed to resolve cluster file: %v", err)
2018-07-10 19:21:27 +00:00
}
rkeConfig, err := cluster.ParseConfig(clusterFile)
if err != nil {
return nil, disablePortCheck, "", "", fmt.Errorf("Failed to parse cluster file: %v", err)
2018-07-10 19:21:27 +00:00
}
rkeConfig, err = setOptionsFromCLI(ctx, rkeConfig)
if err != nil {
return nil, disablePortCheck, "", "", err
2018-07-10 19:21:27 +00:00
}
// Setting conntrack max for kubeproxy to 0
if rkeConfig.Services.Kubeproxy.ExtraArgs == nil {
rkeConfig.Services.Kubeproxy.ExtraArgs = make(map[string]string)
}
rkeConfig.Services.Kubeproxy.ExtraArgs["conntrack-max-per-core"] = "0"
return rkeConfig, disablePortCheck, dindStorageDriver, filePath, nil
2018-07-10 19:21:27 +00:00
}
2018-09-10 23:17:45 +00:00
func createDINDEnv(ctx context.Context, rkeConfig *v3.RancherKubernetesEngineConfig, dindStorageDriver string) error {
for i := range rkeConfig.Nodes {
2018-09-10 23:17:45 +00:00
address, err := dind.StartUpDindContainer(ctx, rkeConfig.Nodes[i].Address, dind.DINDNetwork, dindStorageDriver)
if err != nil {
2018-07-10 19:21:27 +00:00
return err
}
if rkeConfig.Nodes[i].HostnameOverride == "" {
rkeConfig.Nodes[i].HostnameOverride = rkeConfig.Nodes[i].Address
}
rkeConfig.Nodes[i].Address = address
2018-07-10 19:21:27 +00:00
}
time.Sleep(DINDWaitTime * time.Second)
return nil
}