prole/infrastructure/inventory/host_vars/myrddin.prole.org.yml
chrisfu cad49cc0a6 Summary of recent repairs and infrastructure updates
Repairs and improvements:
- iSCSI: Added cleanup tasks to remove stale mounts and fstab entries. Improved robustness of iSCSI target management and added 'iscsi_absent_mounts' support.
- K3s:
    - Updated service start logic to accept 'activating' state, preventing premature failure during slow startups.
    - Improved service stop logic to safely handle missing or not-found services.
    - Ensured 'prole-installer' ServiceAccount and ClusterRoleBinding exist for K8s administration.
    - Added leader election and etcd tuning arguments (forgiving leases) to config.yaml.j2.
    - Removed deprecated 'prole-port-forwards' systemd service.
- Installer & Scripts:
    - Updated legacy_tk.py to support K3s mode, secret resolution for passwords, and better environment management (including ~/.prole/env.sh for service mode).
    - Updated init_ansible.sh to support PROLE_VAULT_PASS_FILE and ANSIBLE_VAULT_PASSWORD_FILE.
    - Improved directory and kubeconfig path resolution in prole_cfg.sh to support fallback to ~/.prole.
    - Enhanced Grafana password resolution in init_monitoring.sh.
    - Added automatic application of iSCSI StorageClass and PersistentVolumes in init_openbao.sh.
- General: Switched conf/prole.cfg to k3s deployment mode and updated vault_k3s.yml token.

New Ansible Tasks and Playbooks:
- infrastructure/playbooks/iscsi_cleanup.yml: Automates logout and removal of stale iSCSI node records.
- infrastructure/playbooks/prole_logs_migrate.yml: Orchestrates /prole/logs migration to iSCSI storage.
- infrastructure/playbooks/tmp_bao_dir.yml: Ensures host-level storage directories for OpenBao.
- infrastructure/playbooks/tmp_mount.yml: Utility to verify and enforce host-level mounts.
- infrastructure/playbooks/k3s_sync.yml: Added tasks to start K3s after sync and update local kubeconfig on the controller.
- Added 'Unmount stale iSCSI mounts' and 'Remove stale iSCSI fstab entries' to the iscsi role.
- Added 'Ensure prole-installer service account exists' to the k3s role.
2026-02-15 17:51:57 -08:00

109 lines
2.8 KiB
YAML

iscsi_portal: 10.0.0.203
iscsi_targets:
# PROLE-DB-1
- iqn: "iqn.2000-01.com.synology:synology.Target-11.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- path: /prole/d001
fstype: xfs
opts: "_netdev,noatime"
src: "UUID=c07dc0f2-cf60-4da5-b68e-ea45e86d473e"
# PROLE-DB-2
- iqn: "iqn.2000-01.com.synology:synology.Target-12.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- path: /prole/d002
fstype: xfs
opts: "_netdev,noatime"
src: "UUID=fe087fb0-a321-4767-b838-b4385e81693e"
# PROLE-DB-3
- iqn: "iqn.2000-01.com.synology:synology.Target-13.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- path: /prole/d003
fstype: xfs
opts: "_netdev,noatime"
src: "UUID=757f1ee4-dc23-414b-b595-e3058c0744f0"
# PROLE-HOME
- iqn: "iqn.2000-01.com.synology:synology.Target-17.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- path: /prole/home
fstype: ext4
opts: "_netdev,noatime"
src: "UUID=607718c8-467a-474f-8e36-80ceafe1beb4"
# PROLE-LOGS
- iqn: "iqn.2000-01.com.synology:synology.Target-1.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- path: /prole/logs
fstype: ext4
opts: "_netdev,noatime"
src: "UUID=5335affd-b1ab-4134-a1c0-be88ab965309"
# PROLE-K3S
- iqn: "iqn.2000-01.com.synology:synology.Target-15.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- path: /var/lib/rancher
fstype: ext4
opts: "_netdev,noatime"
src: "UUID=c8320979-d3eb-4b40-93e0-ee452a4b9780"
iscsi_absent_mounts:
- /opt/prole/logs/chrisfu
ad_dc_enabled: true
k3s_enabled: true
k3s_cluster_init: true
k3s_role: server
k3s_token: "{{ vault_k3s_token }}" # store this in vault
k3s_tls_sans:
- myrddin.prole.org
k3s_node_labels:
- "storage=primary"
k3s_write_kubeconfig_mode: "0640"
k3s_kubeconfig_group: kubeadm
k3s_kubeconfig_users:
- pi
k3s_required_mounts:
- /prole/d001
- /prole/d002
- /prole/d003
k3s_kube_controller_manager_args:
- leader-elect=true
- leader-elect-lease-duration=10m
- leader-elect-renew-deadline=8m
- leader-elect-retry-period=30s
k3s_kube_scheduler_args:
- leader-elect=true
- leader-elect-lease-duration=10m
- leader-elect-renew-deadline=8m
- leader-elect-retry-period=30s
k3s_cloud_controller_manager_args:
- leader-elect=true
- leader-elect-lease-duration=10m
- leader-elect-renew-deadline=8m
- leader-elect-retry-period=30s
k3s_etcd_args:
- heartbeat-interval=500
- election-timeout=5000