prole/infrastructure/playbooks/iscsi_cleanup.yml
chrisfu cad49cc0a6 Summary of recent repairs and infrastructure updates
Repairs and improvements:
- iSCSI: Added cleanup tasks to remove stale mounts and fstab entries. Improved robustness of iSCSI target management and added 'iscsi_absent_mounts' support.
- K3s:
    - Updated service start logic to accept 'activating' state, preventing premature failure during slow startups.
    - Improved service stop logic to safely handle missing or not-found services.
    - Ensured 'prole-installer' ServiceAccount and ClusterRoleBinding exist for K8s administration.
    - Added leader election and etcd tuning arguments (forgiving leases) to config.yaml.j2.
    - Removed deprecated 'prole-port-forwards' systemd service.
- Installer & Scripts:
    - Updated legacy_tk.py to support K3s mode, secret resolution for passwords, and better environment management (including ~/.prole/env.sh for service mode).
    - Updated init_ansible.sh to support PROLE_VAULT_PASS_FILE and ANSIBLE_VAULT_PASSWORD_FILE.
    - Improved directory and kubeconfig path resolution in prole_cfg.sh to support fallback to ~/.prole.
    - Enhanced Grafana password resolution in init_monitoring.sh.
    - Added automatic application of iSCSI StorageClass and PersistentVolumes in init_openbao.sh.
- General: Switched conf/prole.cfg to k3s deployment mode and updated vault_k3s.yml token.

New Ansible Tasks and Playbooks:
- infrastructure/playbooks/iscsi_cleanup.yml: Automates logout and removal of stale iSCSI node records.
- infrastructure/playbooks/prole_logs_migrate.yml: Orchestrates /prole/logs migration to iSCSI storage.
- infrastructure/playbooks/tmp_bao_dir.yml: Ensures host-level storage directories for OpenBao.
- infrastructure/playbooks/tmp_mount.yml: Utility to verify and enforce host-level mounts.
- infrastructure/playbooks/k3s_sync.yml: Added tasks to start K3s after sync and update local kubeconfig on the controller.
- Added 'Unmount stale iSCSI mounts' and 'Remove stale iSCSI fstab entries' to the iscsi role.
- Added 'Ensure prole-installer service account exists' to the k3s role.
2026-02-15 17:51:57 -08:00

59 lines
1.9 KiB
YAML

---
- name: Cleanup stale iSCSI nodes and restart open-iscsi
hosts: myrddin.prole.org
become: true
tasks:
- name: List configured iSCSI nodes
ansible.builtin.command: iscsiadm -m node
register: iscsiadm_nodes
changed_when: false
failed_when: false
- name: Build desired iSCSI target list
ansible.builtin.set_fact:
desired_iqns: "{{ iscsi_targets | default([]) | map(attribute='iqn') | list }}"
- name: Build current iSCSI node list
ansible.builtin.set_fact:
iscsi_node_iqns: "{{ iscsiadm_nodes.stdout_lines | default([]) | map('split') | map('first') | list | unique }}"
- name: Determine stale iSCSI nodes
ansible.builtin.set_fact:
iscsi_stale_iqns: "{{ iscsi_node_iqns | difference(desired_iqns | default([])) }}"
- name: Logout stale iSCSI nodes
ansible.builtin.command: >
iscsiadm -m node -T {{ item }} -p {{ iscsi_portal }} --logout
loop: "{{ iscsi_stale_iqns | default([]) }}"
loop_control:
label: "{{ item }}"
failed_when: false
- name: Delete stale iSCSI node records
ansible.builtin.command: >
iscsiadm -m node -o delete -T {{ item }} -p {{ iscsi_portal }}
loop: "{{ iscsi_stale_iqns | default([]) }}"
loop_control:
label: "{{ item }}"
failed_when: false
- name: Reset open-iscsi failed state
ansible.builtin.command: systemctl reset-failed open-iscsi
changed_when: false
failed_when: false
- name: Restart open-iscsi
ansible.builtin.service:
name: open-iscsi
state: restarted
- name: Check open-iscsi status
ansible.builtin.command: systemctl is-failed open-iscsi
register: open_iscsi_state
changed_when: false
failed_when: false
- name: Report open-iscsi status
ansible.builtin.debug:
msg: "open-iscsi state: {{ open_iscsi_state.stdout | default('unknown') }}"