Ansible Role Create KVMs

This commit is contained in:
Siroco 2022-03-08 19:55:15 +01:00
commit 3fe42a618f
10 changed files with 327 additions and 0 deletions

kvm_provision.yaml Normal file
View File

@ -0,0 +1,25 @@
- name: Deploys VM based on cloud image
hosts: localhost
gather_facts: yes
#become: yes
pool_dir: "/home/user/kvm"
vm: vm_name
vcpus: 1
ram_mb: 512
cleanup: no
net: default
ssh_pub_key: "/home/user/.ssh/"
- name: KVM Provision role
name: kvm_provision
libvirt_pool_dir: "{{ pool_dir }}"
vm_name: "{{ vm }}"
vm_vcpus: "{{ vcpus }}"
vm_ram_mb: "{{ ram_mb }}"
vm_net: "{{ net }}"
cleanup_tmp: "{{ cleanup }}"
ssh_key: "{{ ssh_pub_key }}"

View File

@ -0,0 +1,50 @@
KVM Provision
Provision virtual machines to local libvirt
Related to:
* Pre install and configure libvirt
* Create your ssh key
* Check permissions/security apparmor on qemu:///system or qemu:///session
Example Playbook
- name: Deploys VM based on cloud image
hosts: localhost
gather_facts: yes
pool_dir: "/home/user/kvm"
vm: vm_name
vcpus: 1
ram_mb: 512
cleanup: no
net: default
ssh_pub_key: "/home/user/.ssh/"
- name: KVM Provision role
name: kvm_provision
libvirt_pool_dir: "{{ pool_dir }}"
vm_name: "{{ vm }}"
vm_vcpus: "{{ vcpus }}"
vm_ram_mb: "{{ ram_mb }}"
vm_net: "{{ net }}"
cleanup_tmp: "{{ cleanup }}"
ssh_key: "{{ ssh_pub_key }}"

View File

@ -0,0 +1,13 @@
# defaults file for kvm_provision
base_image_name: debian-11-nocloud-amd64.qcow2
base_image_url:{{ base_image_name }}
base_image_sha: 6180a18d3ed6ad2e24000024dc275c3956584873da2200113194e8db08dd316b8be1dd0421016c2e87ba0a445a1c0068bc86a4071e6e02cd8821d0f060e19544
libvirt_pool_dir: "/var/lib/libvirt/images"
vm_name: debian-dev
vm_vcpus: 2
vm_ram_mb: 2048
vm_net: default
vm_root_pass: debian
cleanup_tmp: no
ssh_key: /home/ocoris/.ssh/

View File

@ -0,0 +1,2 @@
# handlers file for kvm_provision

View File

@ -0,0 +1,52 @@
author: your name
description: your role description
company: your company (optional)
# If the issue tracker for your role is not on github, uncomment the
# next line and provide a value
# issue_tracker_url:
# Choose a valid license ID from - some suggested licenses:
# - BSD-3-Clause (default)
# - MIT
# - GPL-2.0-or-later
# - GPL-3.0-only
# - Apache-2.0
# - CC-BY-4.0
license: license (GPL-2.0-or-later, MIT, etc)
min_ansible_version: 2.1
# If this a Container Enabled role, provide the minimum Ansible Container version.
# min_ansible_container_version:
# Provide a list of supported platforms, and for each platform a list of versions.
# If you don't wish to enumerate all versions for a particular platform, use 'all'.
# To view available platforms and versions (or releases), visit:
# platforms:
# - name: Fedora
# versions:
# - all
# - 25
# - name: SomePlatform
# versions:
# - all
# - 1.0
# - 7
# - 99.99
galaxy_tags: []
# List tags for your role here, one per line. A tag is a keyword that describes
# and categorizes the role. Users find roles by searching for tags. Be sure to
# remove the '[]' above, if you add tags to this list.
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
# Maximum 20 tags per role.
dependencies: []
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
# if you add dependencies to this list.

View File

@ -0,0 +1,70 @@
- name: Requirements
- guestfs-tools
- python3-libvirt
- qemu-system
- libvirt-clients
- libvirt-daemon-system
state: present
become: yes
- name: Get VMs
command: list_vms
uri: "qemu:///system"
register: existing_vms
changed_when: no
- name: Create VM if not exists
- name: Download base image
url: "{{ base_image_url }}"
dest: "/tmp/{{ base_image_name }}"
checksum: "sha512:{{ base_image_sha }}"
mode: '0660'
- name: Copy base image to libvirt
dest: "{{ libvirt_pool_dir }}/{{ vm_name }}.qcow2"
src: "/tmp/{{ base_image_name }}"
force: no
remote_src: yes
mode: 0660
register: copy_results
- name: Custom kvm
virt-customize -a {{ libvirt_pool_dir }}/{{ vm_name }}.qcow2 \
--hostname {{ vm_name }} \
--root-password password:{{ vm_root_pass }} \
--ssh-inject 'root:file:{{ ssh_key }}'
when: copy_results is changed
- name: Define vm
uri: "qemu:///system"
command: define
xml: "{{ lookup('template','vm-template.xml.j2') }}"
when: "vm_name not in existing_vms.list_vms"
- name: Ensure VM is started
name: "{{ vm_name }}"
uri: "qemu:///system"
state: running
register: vm_start_results
until: "vm_start_results is success"
retries: 15
delay: 2
- name: Ensure temporary file is deleted
path: "/tmp/{{ base_image_name }}"
state: absent
when: cleanup_tmp | bool

View File

@ -0,0 +1,106 @@
<domain type='kvm' id='4'>
<name>{{ vm_name}}</name>
<memory unit='MiB'>{{ vm_ram_mb }}</memory>
<vcpu placement='static'>{{ vm_vcpus }}</vcpu>
<type arch='x86_64' machine='pc-i440fx-2.8'>hvm</type>
<boot dev='hd'/>
<vmport state='off'/>
<cpu mode='custom' match='exact' check='full'>
<model fallback='forbid'>Skylake-Client-IBRS</model>
<feature policy='disable' name='rtm'/>
<feature policy='disable' name='hle'/>
<feature policy='require' name='md-clear'/>
<feature policy='require' name='ssbd'/>
<feature policy='require' name='spec-ctrl'/>
<feature policy='require' name='hypervisor'/>
<clock offset='utc'>
<timer name='rtc' tickpolicy='catchup'/>
<timer name='pit' tickpolicy='delay'/>
<timer name='hpet' present='no'/>
<suspend-to-mem enabled='no'/>
<suspend-to-disk enabled='no'/>
<disk type='file' device='disk'>
<driver name='qemu' type='qcow2'/>
<source file='{{ libvirt_pool_dir }}/{{ vm_name }}.qcow2'/>
<target dev='vda' bus='virtio'/>
<address type='pci' domain='0x0000' bus='0x00' slot='0x05' function='0x0'/>
<interface type='network'>
<source network='{{ vm_net }}'/>
<model type='virtio'/>
<address type='pci' domain='0x0000' bus='0x01' slot='0x01' function='0x0'/>
<serial type='pty'>
<source path='/dev/pts/15'/>
<target type='isa-serial' port='0'>
<model name='isa-serial'/>
<alias name='serial0'/>
<console type='pty' tty='/dev/pts/15'>
<source path='/dev/pts/15'/>
<target type='serial' port='0'/>
<alias name='serial0'/>
<channel type='unix'>
<source mode='bind' path='/var/lib/libvirt/qemu/channel/target/domain-4-nova/org.qemu.guest_agent.0'/>
<target type='virtio' name='org.qemu.guest_agent.0' state='disconnected'/>
<alias name='channel0'/>
<address type='virtio-serial' controller='0' bus='0' port='1'/>
<channel type='spicevmc'>
<target type='virtio' name='com.redhat.spice.0' state='disconnected'/>
<alias name='channel1'/>
<address type='virtio-serial' controller='0' bus='0' port='2'/>
<input type='tablet' bus='usb'>
<alias name='input0'/>
<address type='usb' bus='0' port='1'/>
<input type='mouse' bus='ps2'>
<alias name='input1'/>
<input type='keyboard' bus='ps2'>
<alias name='input2'/>
<graphics type='spice' port='5901' autoport='yes' listen=''>
<listen type='address' address=''/>
<model type='qxl' ram='65536' vram='65536' vgamem='16384' heads='1' primary='yes'/>
<address type='pci' domain='0x0000' bus='0x00' slot='0x02' function='0x0'/>
<memballoon model='virtio'>
<alias name='balloon0'/>
<address type='pci' domain='0x0000' bus='0x00' slot='0x08' function='0x0'/>
<rng model='virtio'>
<backend model='random'>/dev/urandom</backend>
<alias name='rng0'/>
<address type='pci' domain='0x0000' bus='0x00' slot='0x09' function='0x0'/>
<seclabel type='dynamic' model='apparmor' relabel='yes'>
<seclabel type='dynamic' model='dac' relabel='yes'>

View File

@ -0,0 +1,2 @@

View File

@ -0,0 +1,5 @@
- hosts: localhost
remote_user: root
- kvm_provision

View File

@ -0,0 +1,2 @@
# vars file for kvm_provision