From 8de07752828613f6317181cd4e34d7db8e305543 Mon Sep 17 00:00:00 2001 From: cyberops7 <18562612+cyberops7@users.noreply.github.com> Date: Thu, 2 Jul 2026 00:34:00 -0600 Subject: [PATCH] Fix RKE2 MetalLB L2Advertisement to honor custom lb_pool_name (#135) (#168) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * Fix RKE2 MetalLB L2Advertisement to honor custom lb_pool_name (#135) The apply-manifests role rendered the IPAddressPool from a template using lb_pool_name, but applied the L2Advertisement from a hardcoded remote file where the pool name was baked in as 'first-pool'. Setting lb_pool_name to anything else left the L2Advertisement pointing at a non-existent pool, so MetalLB assigned LoadBalancer IPs but never advertised them (services got an external IP but were unreachable). Template the L2Advertisement locally from lb_pool_name, mirroring the IPAddressPool pattern, so both manifests always reference the same pool. * Add explicit become: true to apply-manifests kubectl tasks These tasks set become_user without a task-level become, tripping ansible-lint's partial-become rule. become is already enabled globally via ansible_become in group_vars/all.yaml, so the tasks already escalate to the ansible user — but that is invisible to the linter (and to anyone reading the task in isolation). Make it explicit with become: true alongside become_user. Behavior-neutral: verified with ansible-playbook -vvv that the escalation target is unchanged (sudo -u ansible; chown ansible on the temp files), so kubectl still runs as the ansible user that owns ~/.kube/config. --- .../RKE2/roles/apply-manifests/tasks/main.yaml | 18 +++++++++++++++++- .../templates/metallb-l2advertisement.j2 | 8 ++++++++ 2 files changed, 25 insertions(+), 1 deletion(-) create mode 100644 Ansible/Playbooks/RKE2/roles/apply-manifests/templates/metallb-l2advertisement.j2 diff --git a/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml b/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml index bf5ea47..4a3bd28 100644 --- a/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml +++ b/Ansible/Playbooks/RKE2/roles/apply-manifests/tasks/main.yaml @@ -6,6 +6,7 @@ retries: 120 delay: 10 changed_when: true + become: true become_user: "{{ ansible_user }}" when: inventory_hostname == groups['servers'][0] @@ -13,6 +14,7 @@ - name: Apply metallb namespace ansible.builtin.command: cmd: kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.12.1/manifests/namespace.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0] @@ -21,6 +23,7 @@ - name: Apply metallb manifest ansible.builtin.command: cmd: kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/{{ metallb_version }}/config/manifests/metallb-native.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0] @@ -30,13 +33,25 @@ ansible.builtin.command: cmd: "kubectl wait --namespace metallb-system --for=condition=ready pod --selector=component=controller --timeout=1800s" changed_when: true + become: true become_user: "{{ ansible_user }}" when: inventory_hostname == groups['servers'][0] +# Deploy L2 Advertisement to Server 1 (templated so it matches lb_pool_name) +- name: Copy metallb L2 Advertisement to server 1 + ansible.builtin.template: + src: templates/metallb-l2advertisement.j2 + dest: /home/{{ ansible_user }}/l2advertisement.yaml + owner: "{{ ansible_user }}" + group: "{{ ansible_user }}" + mode: '0755' + when: inventory_hostname == groups['servers'][0] + # Apply L2 Advertisement for metallb - name: Apply metallb L2 Advertisement ansible.builtin.command: - cmd: kubectl apply -f https://raw.githubusercontent.com/JamesTurland/JimsGarage/main/Kubernetes/RKE2/l2Advertisement.yaml + cmd: kubectl apply -f /home/{{ ansible_user }}/l2advertisement.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0] @@ -55,6 +70,7 @@ - name: Apply metallb ipppool ansible.builtin.command: cmd: kubectl apply -f /home/{{ ansible_user }}/ippool.yaml + become: true become_user: "{{ ansible_user }}" changed_when: true when: inventory_hostname == groups['servers'][0] diff --git a/Ansible/Playbooks/RKE2/roles/apply-manifests/templates/metallb-l2advertisement.j2 b/Ansible/Playbooks/RKE2/roles/apply-manifests/templates/metallb-l2advertisement.j2 new file mode 100644 index 0000000..25458f0 --- /dev/null +++ b/Ansible/Playbooks/RKE2/roles/apply-manifests/templates/metallb-l2advertisement.j2 @@ -0,0 +1,8 @@ +apiVersion: metallb.io/v1beta1 +kind: L2Advertisement +metadata: + name: example + namespace: metallb-system +spec: + ipAddressPools: + - {{ lb_pool_name }}