Files
swaphb fc786ec63c
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Failing after 3m11s
Add Flatcar and Cilium kube-proxy-free architecture
2026-08-10 17:19:18 -04:00

93 lines
2.4 KiB
YAML

---
- name: Configure Flatcar host and install K3s
hosts: k3s_servers
become: true
gather_facts: true
vars:
k3s_version: "v1.30.6+k3s1"
k3s_install_url: "https://get.k3s.io"
k3s_api_server_port: 6443
pre_tasks:
- name: Require Flatcar Linux
ansible.builtin.assert:
that:
- ansible_distribution == "Flatcar"
fail_msg: "This playbook expects Flatcar Linux. Use the Ubuntu fallback playbook if needed."
tasks:
- name: Disable swap if a swap device is present
ansible.builtin.command: swapoff -a
changed_when: false
failed_when: false
- name: Set restrictive SSH authentication
ansible.builtin.copy:
dest: /etc/ssh/sshd_config.d/60-k8s-baseline.conf
owner: root
group: root
mode: '0644'
content: |
PasswordAuthentication no
PermitRootLogin no
notify: Restart sshd
- name: Create K3s configuration directory
ansible.builtin.file:
path: /etc/rancher/k3s
state: directory
owner: root
group: root
mode: '0750'
- name: Configure K3s for Cilium kube-proxy replacement
ansible.builtin.copy:
dest: /etc/rancher/k3s/config.yaml
owner: root
group: root
mode: '0600'
content: |
write-kubeconfig-mode: "0600"
flannel-backend: none
disable-network-policy: true
disable-kube-proxy: true
disable:
- traefik
https-listen-port: {{ k3s_api_server_port }}
- name: Download pinned K3s installer
ansible.builtin.get_url:
url: "{{ k3s_install_url }}"
dest: /var/lib/rancher/k3s-install.sh
owner: root
group: root
mode: '0700'
- name: Install pinned K3s server
ansible.builtin.command:
cmd: /var/lib/rancher/k3s-install.sh server
creates: /usr/local/bin/k3s
environment:
INSTALL_K3S_VERSION: "{{ k3s_version }}"
- name: Enable and start K3s
ansible.builtin.systemd:
name: k3s
state: started
enabled: true
daemon_reload: true
- name: Wait for K3s API port
ansible.builtin.wait_for:
host: 127.0.0.1
port: "{{ k3s_api_server_port }}"
timeout: 120
handlers:
- name: Restart sshd
ansible.builtin.systemd:
name: sshd
state: restarted