2019-12-21 18:11:30 +01:00
|
|
|
---
|
|
|
|
|
2020-12-05 22:56:28 +01:00
|
|
|
- name: Check if newuidmap is available
|
2021-04-10 13:15:51 +02:00
|
|
|
ansible.builtin.command:
|
|
|
|
cmd: which newuidmap
|
2020-12-05 22:56:28 +01:00
|
|
|
failed_when: false
|
|
|
|
changed_when: false
|
|
|
|
register: k3s_check_newuidmap_installed
|
|
|
|
|
2019-12-21 18:11:30 +01:00
|
|
|
- name: Check if /proc/sys/kernel/unprivileged_userns_clone exists
|
2020-12-12 15:27:59 +01:00
|
|
|
ansible.builtin.stat:
|
2019-12-21 18:11:30 +01:00
|
|
|
path: /proc/sys/kernel/unprivileged_userns_clone
|
|
|
|
register: k3s_check_unprivileged_userns_exists
|
|
|
|
|
|
|
|
- name: Get the value of /proc/sys/kernel/unprivileged_userns_clone
|
2020-12-12 15:27:59 +01:00
|
|
|
ansible.builtin.slurp:
|
2019-12-21 18:11:30 +01:00
|
|
|
src: /proc/sys/kernel/unprivileged_userns_clone
|
|
|
|
register: k3s_get_unprivileged_userns_clone
|
|
|
|
when: k3s_check_unprivileged_userns_exists.stat.exists
|
|
|
|
|
|
|
|
- name: Set the value of k3s_get_unprivileged_userns_clone
|
2020-12-21 20:14:52 +01:00
|
|
|
ansible.builtin.set_fact:
|
2019-12-21 18:11:30 +01:00
|
|
|
k3s_get_unprivileged_userns_clone:
|
|
|
|
content: "MQo="
|
|
|
|
when: not k3s_check_unprivileged_userns_exists.stat.exists
|
|
|
|
|
|
|
|
- name: Get the value of /proc/sys/user/max_user_namespaces
|
2020-12-12 15:27:59 +01:00
|
|
|
ansible.builtin.slurp:
|
2019-12-21 18:11:30 +01:00
|
|
|
src: /proc/sys/user/max_user_namespaces
|
|
|
|
register: k3s_get_max_user_namespaces
|
|
|
|
|
|
|
|
- name: Get the contents of /etc/subuid
|
2020-12-12 15:27:59 +01:00
|
|
|
ansible.builtin.slurp:
|
2019-12-21 18:11:30 +01:00
|
|
|
src: /etc/subuid
|
|
|
|
register: k3s_get_subuid
|
|
|
|
|
|
|
|
- name: Get the contents of /etc/subgid
|
2020-12-12 15:27:59 +01:00
|
|
|
ansible.builtin.slurp:
|
2019-12-21 18:11:30 +01:00
|
|
|
src: /etc/subgid
|
|
|
|
register: k3s_get_subgid
|
|
|
|
|
|
|
|
- name: Get current user subuid and subgid values
|
2020-12-21 20:14:52 +01:00
|
|
|
ansible.builtin.set_fact:
|
2019-12-21 18:11:30 +01:00
|
|
|
k3s_current_user_subuid: "{{ (k3s_get_subuid['content'] | b64decode).split('\n')
|
|
|
|
| select('search', ansible_user_id) | first | default('UserNotFound:0:0') }}"
|
|
|
|
k3s_current_user_subgid: "{{ (k3s_get_subgid['content'] | b64decode).split('\n')
|
|
|
|
| select('search', ansible_user_id) | first | default('UserNotFound:0:0') }}"
|
|
|
|
|
|
|
|
- name: Check user namespaces kernel parameters are adequate
|
2020-12-12 15:27:59 +01:00
|
|
|
ansible.builtin.assert:
|
2019-12-21 18:11:30 +01:00
|
|
|
that:
|
|
|
|
- k3s_get_unprivileged_userns_clone['content'] | b64decode | int == 1
|
2021-12-20 22:14:23 +01:00
|
|
|
- ((k3s_get_max_user_namespaces['content'] | b64decode | int >= 28633) or (k3s_os_family != "redhat"))
|
2019-12-21 18:11:30 +01:00
|
|
|
- k3s_current_user_subuid != "UserNotFound:0:0"
|
|
|
|
- k3s_current_user_subgid != "UserNotFound:0:0"
|
|
|
|
- k3s_current_user_subuid.split(':')[2] | int >= 65536
|
|
|
|
- k3s_current_user_subgid.split(':')[2] | int >= 65536
|
|
|
|
- ansible_env['XDG_RUNTIME_DIR'] is defined
|
2020-12-05 22:56:28 +01:00
|
|
|
- k3s_check_newuidmap_installed.rc == 0
|
2019-12-21 18:11:30 +01:00
|
|
|
success_msg: All kernel parameters passed
|
2021-02-16 16:46:01 +01:00
|
|
|
fail_msg: >-
|
|
|
|
Kernel parameters are not set correctly, please check
|
|
|
|
https://github.com/rootless-containers/rootlesskit
|