2026-03-02 20:28:51 +00:00
|
|
|
---
|
2026-03-02 21:39:47 +00:00
|
|
|
- name: Determine if Tailscale operator is enabled
|
|
|
|
|
set_fact:
|
|
|
|
|
tailscale_operator_enabled: "{{ (tailscale_oauth_client_id | default('') | length) > 0 and (tailscale_oauth_client_secret | default('') | length) > 0 }}"
|
|
|
|
|
changed_when: false
|
|
|
|
|
|
|
|
|
|
- name: Skip Tailscale operator when OAuth credentials are missing
|
|
|
|
|
debug:
|
|
|
|
|
msg: "Skipping Tailscale Kubernetes Operator: set TAILSCALE_OAUTH_CLIENT_ID and TAILSCALE_OAUTH_CLIENT_SECRET to enable it."
|
|
|
|
|
when: not tailscale_operator_enabled
|
|
|
|
|
|
|
|
|
|
- name: End Tailscale operator role when disabled
|
|
|
|
|
meta: end_host
|
|
|
|
|
when: not tailscale_operator_enabled
|
|
|
|
|
|
2026-03-02 20:28:51 +00:00
|
|
|
- name: Check if Helm is installed
|
|
|
|
|
command: helm version --short
|
|
|
|
|
register: helm_check
|
|
|
|
|
changed_when: false
|
|
|
|
|
failed_when: false
|
|
|
|
|
|
|
|
|
|
- name: Install Helm
|
|
|
|
|
shell: curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
|
|
|
|
when: helm_check.rc != 0
|
|
|
|
|
changed_when: true
|
|
|
|
|
|
|
|
|
|
- name: Create Tailscale operator namespace
|
|
|
|
|
command: kubectl create namespace {{ tailscale_operator_namespace }}
|
|
|
|
|
register: create_ns
|
|
|
|
|
failed_when: create_ns.rc != 0 and "AlreadyExists" not in create_ns.stderr
|
|
|
|
|
changed_when: create_ns.rc == 0
|
|
|
|
|
|
|
|
|
|
- name: Add Tailscale Helm repo
|
|
|
|
|
command: helm repo add tailscale https://pkgs.tailscale.com/unstable/helmcharts
|
|
|
|
|
register: add_repo
|
|
|
|
|
failed_when: add_repo.rc != 0 and "already exists" not in add_repo.stderr
|
|
|
|
|
changed_when: add_repo.rc == 0
|
|
|
|
|
|
|
|
|
|
- name: Update Helm repos
|
|
|
|
|
command: helm repo update
|
|
|
|
|
changed_when: false
|
|
|
|
|
|
|
|
|
|
- name: Write Tailscale operator values
|
|
|
|
|
template:
|
|
|
|
|
src: operator-values.yaml.j2
|
|
|
|
|
dest: /tmp/tailscale-operator-values.yaml
|
|
|
|
|
mode: "0644"
|
|
|
|
|
|
2026-03-02 21:39:47 +00:00
|
|
|
- name: Create or update Tailscale operator OAuth secret
|
|
|
|
|
shell: >-
|
|
|
|
|
kubectl -n {{ tailscale_operator_namespace }} create secret generic operator-oauth
|
|
|
|
|
--from-literal=client_id='{{ tailscale_oauth_client_id }}'
|
|
|
|
|
--from-literal=client_secret='{{ tailscale_oauth_client_secret }}'
|
|
|
|
|
--dry-run=client -o yaml | kubectl apply -f -
|
|
|
|
|
register: oauth_secret_result
|
|
|
|
|
changed_when: "'created' in oauth_secret_result.stdout or 'configured' in oauth_secret_result.stdout"
|
|
|
|
|
|
2026-03-02 20:28:51 +00:00
|
|
|
- name: Install Tailscale Kubernetes Operator
|
|
|
|
|
command: >-
|
2026-03-02 21:15:37 +00:00
|
|
|
helm upgrade --install tailscale-operator tailscale/tailscale-operator
|
2026-03-02 20:28:51 +00:00
|
|
|
--namespace {{ tailscale_operator_namespace }}
|
|
|
|
|
--version {{ tailscale_operator_version }}
|
|
|
|
|
--values /tmp/tailscale-operator-values.yaml
|
|
|
|
|
--wait
|
2026-03-02 21:39:47 +00:00
|
|
|
--timeout 10m
|
|
|
|
|
register: tailscale_install
|
|
|
|
|
failed_when: false
|
2026-03-02 20:28:51 +00:00
|
|
|
changed_when: true
|
|
|
|
|
|
2026-03-02 21:39:47 +00:00
|
|
|
- name: Show Tailscale operator pods on install failure
|
|
|
|
|
command: kubectl -n {{ tailscale_operator_namespace }} get pods -o wide
|
|
|
|
|
register: tailscale_pods
|
|
|
|
|
changed_when: false
|
|
|
|
|
failed_when: false
|
|
|
|
|
when: tailscale_install.rc != 0
|
|
|
|
|
|
|
|
|
|
- name: Show Tailscale operator events on install failure
|
|
|
|
|
command: kubectl -n {{ tailscale_operator_namespace }} get events --sort-by=.lastTimestamp
|
|
|
|
|
register: tailscale_events
|
|
|
|
|
changed_when: false
|
|
|
|
|
failed_when: false
|
|
|
|
|
when: tailscale_install.rc != 0
|
|
|
|
|
|
|
|
|
|
- name: Fail with Tailscale operator diagnostics
|
|
|
|
|
fail:
|
|
|
|
|
msg: |
|
|
|
|
|
Tailscale operator install failed.
|
|
|
|
|
Helm stderr:
|
|
|
|
|
{{ tailscale_install.stderr | default('') }}
|
|
|
|
|
|
|
|
|
|
Pods:
|
|
|
|
|
{{ tailscale_pods.stdout | default('n/a') }}
|
|
|
|
|
|
|
|
|
|
Events:
|
|
|
|
|
{{ tailscale_events.stdout | default('n/a') }}
|
|
|
|
|
when: tailscale_install.rc != 0
|
|
|
|
|
|
2026-03-02 20:28:51 +00:00
|
|
|
- name: Wait for Tailscale operator to be ready
|
2026-03-02 21:39:47 +00:00
|
|
|
command: kubectl -n {{ tailscale_operator_namespace }} rollout status deployment/operator --timeout=5m
|
2026-03-02 20:28:51 +00:00
|
|
|
changed_when: false
|