Repository navigation
PVE Launch Node
Directions for creating a basic stand-alone PVE node named gismo.
This assumes a working and configured Ansible Control Node and that all prerequisites have been met.
Steps:
- Install PVE
- Update inventory
- Acquire Images
- Create SSH key
- Configure SSH access
- Install Ansible Collections
- Run playbook
- Configure APT repositories for No-Subscription and update PVE node.
- Configure
authorized_keysforrootto include (and remove) desired SSH public keys. - Upload Cloud-init image files to PVE nodes.
cloudcodger.proxmox_ve.aptcloudcodger.proxmox_ve.uploadcloudcodger.proxmox_openssh.datacenter
The links to Ansible Collections.
Regarding the cloudcodger.proxmox_ve.upload role variables. These have been configured to lookup the files that exist with the assumption that all Cloud-Init images end with .qcow2, all ISO images end in .iso and all LXC templates end with .zst. If you would like to change what gets uploaded, either edit the basic/group_vars/proxmox_hosts.yml file to set specific lists or update the contents of the files directory before running the playbook. Keep in mind that this does not remove any files on the PVE nodes and only uploads new or changed files.
First install the PVE software on the machine that will be your node. For experimentation purposes, this could be VM. Keep track of the root password that you set during the installation process as this will be needed when configuring SSH access.
This showcase uses the hostname of gismo for the PVE node.
Make sure the IP address in basic/pve.yml is correct for the PVE node.
Download any cloud-init images, ISO images and LXC container templates you want uploaded to the PVE node during the Run playbook step. These are listed in the upload_cloud_init_files, upload_iso_images and upload_lxc_templates variables respectively. To simplify things, these are set in the basic/group_vars/proxmox_hosts.yml file, where it looks up the existing files by the extention for each of the types.
The acquire.yml playbook will download the images and templates listed in the loop values for each task. Update the playbook with the desired items before running it.
This step can be skipped if the desired files already exist in the files directory. Make sure you have any files to be uploaded by the cloudcodger.proxmox_ve.upload role. This playbook runs on localhost, which does not require an inventory. However, this will produce the messages
[WARNING]: No inventory was parsed, only implicit localhost is available
[WARNING]: provided hosts list is empty, only localhost is available. Note that the implicit localhost does not match 'all'
Providing an inventory file with -i prevents these warning messages. The local_aliases.yml from any of the Inventory directories can be used for this command.
ansible-playbook -i basic/local_aliases.yml acquire.ymlansible-playbook -i lab/local_aliases.yml acquire.ymlIf an ed25519 type SSH key hasn't been created yet, create one. The file name needs to match the one in basic/group_vars/proxmox_hosts.yml. Otherwise the lookup will fail.
ssh-keygen -t ed25519 -N "" -f ~/.ssh/showcase_ed25519The -N sets an empty passphrase which is OK for a lab and using one is left up to the reader.
The known_hosts.yml playbook, with the specific inventory file basic/pve.yml, will scan each host and add the SSH hostkey to ~/.ssh/known_hosts file on the Ansible Control Node.
ansible-playbook -i basic/pve.yml known_hosts.yml -e host_list=proxmox_hostsSet up passwordless SSH access to the PVE nodes by configuring an SSH key pair for the root user. Use ssh-copy-id to copy up a public key. This will prompt for the password that was set during the install.
ssh-copy-id -i ~/.ssh/showcase_ed25519.pub root@192.168.6.230ssh-copy-id -i ~/.ssh/showcase_ed25519.pub root@gismoThe pve.yml playbook requires multiple collections and roles. If not done as part of creating the Ansible Control Node, install them using the requirements.yml file.
ansible-galaxy collection install -r requirements.ymlRun the pve_node.yml Ansible playbook with the specific inventory file basic/pve.yml. This must be able to validate certificates on the PVE node. The PVE Certificates page describes one method of configuring them.
ansible-playbook -i basic/pve.yml pve_node.ymlThis playbook demonstrates the showcased roles in two plays. Described here.
The first play runs on each PVE node in the proxmox_hosts group (set in basic/pve.yml) with settings in basic/group_vars/proxmox_hosts.yml.
Roles executed:
-
cloudcodger.proxmox_ve.aptto:- update the APT repositories
- run
apt dist-upgrade -
rebootthe PVE node if needed
-
cloudcodger.proxmox_ve.uploadto:- upload cloud-init images
- upload ISO images
- upload template images
The second play runs on local_pve_datacenter (an alias for localhost in basic/local_aliases.yml) with settings in basic/host_vars/local_pve_datacenter.yml.
Role executed:
- The
cloudcodger.proxmox_openssh.datacenterrole will:- Create a
.pve_secretsdirectory on the control node. - Update the
localstorage allowed content, soimagesis included. - Create
AdministratorandAuditorgroups, users, tokens, and permission ACLs. Storing token secrets in the.pve_secretsdirectory.
- Create a