fix: terraform & module
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
locals {
|
||||
sudo_prefix = var.ssh_user == "root" ? "" : "sudo "
|
||||
install_env = var.k3s_version != "" ? "INSTALL_K3S_VERSION=${var.k3s_version} " : ""
|
||||
install_env = "INSTALL_K3S_VERSION=${var.k3s_version} "
|
||||
disable_flags = join(" ", [for c in var.k3s_disable_components : "--disable=${c}"])
|
||||
kubeconfig_cmd = "${local.sudo_prefix}cat /etc/rancher/k3s/k3s.yaml"
|
||||
}
|
||||
@@ -22,10 +22,20 @@ resource "null_resource" "k3s_install" {
|
||||
|
||||
provisioner "remote-exec" {
|
||||
inline = [
|
||||
"${local.sudo_prefix}sh -c 'curl -sfL https://get.k3s.io | ${local.install_env}sh -s - server --write-kubeconfig-mode 644 ${local.disable_flags}'",
|
||||
"${local.sudo_prefix}sh -c 'curl -sfL https://get.k3s.io | ${local.install_env}sh -s - server ${local.disable_flags}'",
|
||||
"until ${local.sudo_prefix}test -f /etc/rancher/k3s/k3s.yaml; do sleep 2; done",
|
||||
]
|
||||
}
|
||||
|
||||
# Le kubeconfig est lu via sudo (fetch_kubeconfig), pas besoin de --write-kubeconfig-mode :
|
||||
# il reste 600/root par defaut, ce qui evite d'exposer les droits cluster-admin a tout utilisateur local.
|
||||
provisioner "remote-exec" {
|
||||
when = destroy
|
||||
on_failure = continue
|
||||
inline = [
|
||||
"${local.sudo_prefix}sh -c 'test -x /usr/local/bin/k3s-uninstall.sh && /usr/local/bin/k3s-uninstall.sh || true'",
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
resource "null_resource" "fetch_kubeconfig" {
|
||||
|
||||
Reference in New Issue
Block a user