# K3s 集群安装 Playbook --- - name: Validate environment hosts: localhost gather_facts: false tasks: - name: Check TAILSCALE_AUTH_KEY ansible.builtin.fail: msg: "请设置: export TAILSCALE_AUTH_KEY='tskey-auth-xxx'" when: lookup('env', 'TAILSCALE_AUTH_KEY') | length == 0 - name: Check SSH credentials ansible.builtin.debug: msg: | {% if lookup('env', 'SSH_PASSWORD') | length > 0 %} ✓ 使用密码登录 (首次安装) {% else %} ✓ 使用密钥登录 {% endif %} # ============================================ # 阶段 1: SSH 安全加固 (可选,首次安装时使用) # ============================================ - name: SSH Security Hardening hosts: k3s_cluster gather_facts: false tags: [ssh, never] roles: - ssh # ============================================ # 阶段 2: 基础配置 # ============================================ - name: Common Setup hosts: k3s_cluster gather_facts: true tags: [common] roles: - common # ============================================ # 阶段 3: 安装 K3s (按顺序: init -> masters -> agents) # ============================================ - name: Install K3s on init node hosts: masters gather_facts: true serial: 1 tags: [k3s] roles: - role: k3s when: cluster_init | default(false) - name: Fetch K3S_TOKEN & K3S_SERVER_URL from init node hosts: localhost gather_facts: false tags: [k3s] tasks: - name: Find init node ansible.builtin.set_fact: init_node: "{{ item }}" loop: "{{ groups['masters'] }}" when: hostvars[item].cluster_init | default(false) - name: Read K3S_TOKEN from init node ansible.builtin.slurp: src: /var/lib/rancher/k3s/server/node-token register: k3s_token_content delegate_to: "{{ init_node }}" - name: Determine K3S_SERVER_URL ansible.builtin.set_fact: # 优先使用 HA_SERVER_URL 环境变量,否则使用 init 节点地址 k3s_server_url: "{{ ha_server_url if (ha_server_url | length > 0) else 'https://' + hostvars[init_node].ansible_host + ':6443' }}" - name: Set K3S_TOKEN and K3S_SERVER_URL for all hosts ansible.builtin.set_fact: k3s_token: "{{ k3s_token_content.content | b64decode | trim }}" k3s_server_url: "{{ k3s_server_url }}" delegate_to: "{{ item }}" delegate_facts: true loop: "{{ groups['k3s_cluster'] }}" - name: Install K3s on other masters hosts: masters gather_facts: true serial: 1 tags: [k3s] roles: - role: k3s when: not (cluster_init | default(false)) - name: Install K3s on agents hosts: agents gather_facts: true tags: [k3s] roles: - k3s # ============================================ # 阶段 4: 显示集群状态 # ============================================ - name: Show cluster status hosts: masters gather_facts: false tags: [status] run_once: true tasks: - name: Get nodes ansible.builtin.command: kubectl get nodes -o wide environment: KUBECONFIG: /etc/rancher/k3s/k3s.yaml register: nodes changed_when: false when: cluster_init | default(false) - name: Display nodes ansible.builtin.debug: msg: | ══════════════════════════════════════════════════════════════ K3s 集群节点: {{ nodes.stdout }} ══════════════════════════════════════════════════════════════ when: cluster_init | default(false)