-
Notifications
You must be signed in to change notification settings - Fork 2
/
kubenode.tf
100 lines (89 loc) · 4.28 KB
/
kubenode.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
resource "template_file" "kubenode" {
count = "${var.nodecount}"
template = "${file("tpl.node.yaml")}"
vars {
tenantId = "${var.tenantId}"
subscriptionId = "${var.subscriptionId}"
resourceGroup = "${azurerm_resource_group.az_kube.name}"
servicePrincipalClientId = "${var.azureClientId}"
servicePrincipalClientSecret = "${var.azureClientSecret}"
caCertificate = "${base64encode(file("${var.secretPath}/ca.crt"))}"
apiserverCertificate = "${base64encode(file("${var.secretPath}/apiserver.crt"))}"
apiserverPrivateKey = "${base64encode(file("${var.secretPath}/apiserver.key"))}"
clientCertificate = "${base64encode(file("${var.secretPath}/client.crt"))}"
clientPrivateKey = "${base64encode(file("${var.secretPath}/client.key"))}"
sshAuthorizedKey = "${file(\"${var.secretPath}/${var.username}_rsa.pub\")}"
k8sVer = "${var.k8sVer}"
hyperkubeImage = "${var.hyperkubeImage}"
ETCDEndpoints = "${var.ETCDEndpoints}"
masterPrivateIp = "${var.masterPrivateIP}"
kubeServiceCidr = "${var.kubeServiceCidr}"
kubeClusterCidr = "${var.kubeClusterCidr}"
kubeDnsServiceIP = "${var.kubeDnsServiceIP}"
kubePodCidr = "${element(azurerm_subnet.node_bridge.*.address_prefix, count.index)}"
}
}
resource "azurerm_network_interface" "nodenic" {
count = "${var.nodecount}"
name = "${var.deployid}-nic-node-${count.index}"
location = "${var.location}"
resource_group_name = "${azurerm_resource_group.az_kube.name}"
enable_ip_forwarding = true
ip_configuration {
name = "nodenicip${count.index}"
subnet_id = "${azurerm_subnet.az_kube_vm.id}"
private_ip_address_allocation = "dynamic"
}
}
# Node VM cbr0 subnet
resource "azurerm_subnet" "node_bridge" {
count = "${var.nodecount}"
name = "node-subnet-${count.index}"
resource_group_name = "${azurerm_resource_group.az_kube.name}"
virtual_network_name = "${azurerm_virtual_network.az_kube.name}"
network_security_group_id = "${azurerm_network_security_group.az_kube.id}"
address_prefix = "${var.podIpPrefix}.${count.index + 10}.0/24"
route_table_id = "${azurerm_route_table.az_kube.id}"
}
resource "azurerm_route" "node_route" {
count = "${var.nodecount}"
name = "route-node-${count.index}"
resource_group_name = "${azurerm_resource_group.az_kube.name}"
route_table_name = "${azurerm_route_table.az_kube.name}"
address_prefix = "${element(azurerm_subnet.node_bridge.*.address_prefix, count.index)}"
next_hop_type = "VirtualAppliance"
next_hop_in_ip_address = "${element(azurerm_network_interface.nodenic.*.private_ip_address, count.index)}"
}
resource "azurerm_virtual_machine" "kubenode" {
count = "${var.nodecount}"
name = "${var.deployid}-node-${count.index}"
location = "${var.location}"
resource_group_name = "${azurerm_resource_group.az_kube.name}"
network_interface_ids = ["${element(azurerm_network_interface.nodenic.*.id, count.index)}"]
vm_size = "${var.nodesize}"
storage_image_reference {
publisher = "CoreOS"
offer = "CoreOS"
sku = "Stable"
version = "latest"
}
storage_os_disk {
name = "vm-node-disk"
vhd_uri = "${azurerm_storage_account.az_kube.primary_blob_endpoint}${azurerm_storage_container.az_kube.name}/vm-node-disk-${count.index}.vhd"
caching = "ReadWrite"
create_option = "FromImage"
}
os_profile_linux_config {
disable_password_authentication = true
ssh_keys {
path = "/home/${var.username}/.ssh/authorized_keys"
key_data = "${file(\"${var.secretPath}/${var.username}_rsa.pub\")}"
}
}
os_profile {
computer_name = "${var.deployid}-node-${count.index}"
admin_username = "${var.username}"
admin_password = "${file(\"${var.secretPath}/admin_password")}"
custom_data = "${base64encode(element(template_file.kubenode.*.rendered, count.index))}"
}
}