{"version": 2, "width": 80, "height": 24, "timestamp": 1787607815, "env": {"SHELL": "/bin/bash", "TERM": null}, "title": "core playbook: apply dry run single node"}
[0.0, "o", "$ ./productive-k3s-core.sh apply --dry-run --mode single-node\r\n"]
[0.031, "o", "[INFO] Detected host platform: Ubuntu 24.04.4 LTS\r\n"]
[0.032, "o", "[INFO] Incremental apply: k3s + Rancher + Longhorn + Registry (Ubuntu 24.04.4 LTS)\r\n"]
[0.032, "o", "[INFO] Mode: single-node (dry-run single-node installation (core + default stack))\r\n"]
[0.032, "o", "[INFO] cluster distro: k3s\r\n"]
[0.032, "o", "[INFO] cluster installation engine: native\r\n"]
[0.032, "o", "[INFO] k3s installation engine: native\r\n"]
[0.032, "o", "  Run manifest: runs/apply-20260824-184335-2389-1987628315.json\r\n"]
[0.032, "o", "[WARN] Running in dry-run mode. No changes will be applied.\r\n"]
[0.067, "o", "[INFO] Detected environment\r\n"]
[0.067, "o", "  - k3s: missing\r\n"]
[0.067, "o", "  - helm: missing\r\n"]
[0.067, "o", "  - cert-manager: missing\r\n"]
[0.067, "o", "  - Longhorn: missing\r\n"]
[0.067, "o", "  - Rancher: missing\r\n"]
[0.067, "o", "  - Registry: missing\r\n"]
[0.067, "o", "  - NFS server: missing\r\n"]
[0.068, "o", "[INFO] Standalone kubectl was not detected. Managed workflow command: sudo k3s kubectl\r\n"]
[0.07, "o", "[INFO] Diagnosis\r\n"]
[0.07, "o", "  - k3s is missing.\r\n"]
[0.07, "o", "  - helm is missing.\r\n"]
[0.07, "o", "  - cert-manager is missing.\r\n"]
[0.07, "o", "  - Longhorn is missing.\r\n"]
[0.07, "o", "    Prepare and mount dedicated storage yourself if you want it; this script will not format disks.\r\n"]
[0.07, "o", "  - Rancher is missing.\r\n"]
[0.07, "o", "  - Internal registry is missing.\r\n"]
[0.07, "o", "  - NFS server is missing.\r\n"]
[0.082, "o", "k3s was not detected. Install it now? [required] [y] (y/n): "]
[0.082, "o", "Helm was not detected. Install it now? [required] [y] (y/n): "]
[0.085, "o", "Longhorn is missing. Install it now? [optional] [y] (y/n): "]
[0.087, "o", "Rancher is missing. Install it now? [optional] [y] (y/n): "]
[0.089, "o", "The in-cluster registry is missing. Install it now? [optional] [y] (y/n): "]
[0.091, "o", "cert-manager is missing. Install it now? [required for TLS-dependent installs] [y] (y/n): "]
[0.091, "o", "Do you want to ensure a local NFS server is available for host-to-cluster shared files? [optional] [y] (y/n): "]
[0.092, "o", "NFS export path on the host [/srv/nfs/k8s-share]: "]
[0.092, "o", "Allowed client network/CIDR for the NFS export [192.168.0.0/24]: "]
[0.093, "o", "Base domain (used to build hostnames) [example.local]: \r\n"]
[0.093, "o", "TLS options:\r\n"]
[0.093, "o", "  1) Let's Encrypt (requires public DNS + inbound 80/443)\r\n"]
[0.093, "o", "  2) Self-signed (works anywhere; you'll need to trust certs in browser/docker)\r\n"]
[0.093, "o", "Choose TLS mode (1/2) [2]: "]
[0.095, "o", "Longhorn data mount path [/data]: Longhorn default replica count (1 for single-node) [1]: Longhorn storage minimal available percentage (10 is recommended for single-node dev/lab) [10]: \r\n"]
[0.095, "o", "[INFO] Single-node Longhorn mode is enabled. The bootstrap will create a 'longhorn-single' StorageClass with numberOfReplicas=1.\r\n"]
[0.095, "o", "[WARN] Longhorn host preparation will install open-iscsi, enable iscsid, and ensure the data path exists on this host.\r\n"]
[0.095, "o", "Make Longhorn the default StorageClass? [y] (y/n): "]
[0.097, "o", "Rancher hostname (DNS name) [rancher.example.local]: Rancher bootstrap password [admin]: Update local /etc/hosts on this machine for the Rancher hostname? [y] (y/n): "]
[0.099, "o", "Registry hostname (DNS name) [registry.example.local]: Registry PVC size [20Gi]: "]
[0.099, "o", "Registry StorageClass (blank uses cluster default) [longhorn-single]: "]
[0.1, "o", "Do you want to enable basic auth on the in-cluster registry? [n] (y/n): Update local /etc/hosts on this machine for the registry hostname? [y] (y/n): Install local Docker trust for the registry certificate on this machine? [n] (y/n): "]
[0.106, "o", "[INFO] Planned actions\r\n"]
[0.106, "o", "  Cluster:\r\n"]
[0.106, "o", "    - k3s: install\r\n"]
[0.106, "o", "    - helm: install\r\n"]
[0.106, "o", "    - cert-manager: install\r\n"]
[0.106, "o", "    - Longhorn: install\r\n"]
[0.106, "o", "    - Rancher: install\r\n"]
[0.106, "o", "    - Registry: install\r\n"]
[0.106, "o", "  Host:\r\n"]
[0.106, "o", "    - NFS management: install\r\n"]
[0.106, "o", "  Add-on impact preview:\r\n"]
[0.128, "o", "    - cert-manager: cluster\r\n"]
[0.128, "o", "      \"Installs cert-manager and manages ClusterIssuer resources for TLS-enabled add-ons.\"\r\n"]
[0.146, "o", "    - longhorn: cluster  👁 host [package-install, service-enable, filesystem-path]\r\n"]
[0.146, "o", "      \"Installs Longhorn and prepares the host with iSCSI packages, service enablement, and the data path.\"\r\n"]
[0.161, "o", "    - rancher: cluster  👁 host [etc-hosts]\r\n"]
[0.161, "o", "      \"Installs Rancher and can optionally configure a local /etc/hosts entry for the selected hostname.\"\r\n"]
[0.176, "o", "    - registry: cluster  👁 host [etc-hosts, docker-registry-trust]\r\n"]
[0.176, "o", "      \"Installs an in-cluster registry and can optionally configure local /etc/hosts and Docker trust on the host.\"\r\n"]
[0.176, "o", "Proceed with this plan? [y] (y/n): "]
[0.186, "o", "[INFO] Required packages for k3s installation are already installed.\r\n"]
[0.186, "o", "[INFO] Installing k3s (v1.35.5+k3s1)...\r\n"]
[0.186, "o", "[INFO] [dry-run] Installing k3s (v1.35.5+k3s1)\r\n"]
[0.186, "o", "  curl -sfL https://get.k3s.io | INSTALL_K3S_VERSION=v1.35.5+k3s1 sh -\r\n"]
[0.194, "o", "[INFO] Required packages for Helm installation are already installed.\r\n"]
[0.194, "o", "[INFO] Installing Helm (v3.21.0)...\r\n"]
[0.194, "o", "[INFO] [dry-run] Installing Helm (v3.21.0)\r\n"]
[0.194, "o", "  curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | DESIRED_VERSION=v3.21.0 bash\r\n"]
[0.197, "o", "[WARN] k3s is not active yet. Cluster-level checks will be partial until it is installed for real.\r\n"]
[0.208, "o", "[INFO] Processing stack addon 'cert-manager' from stack 'base'\r\n"]
[0.211, "o", "[WARN] k3s is not active, so cert-manager preflight can only be partial.\r\n"]
[0.213, "o", "[INFO] [dry-run] Would install cert-manager from addon source...\r\n"]
[0.217, "o", "[INFO] Processing stack addon 'longhorn' from stack 'base'\r\n"]
[0.22, "o", "[WARN] k3s is not active, so Longhorn preflight can only be partial.\r\n"]
[0.221, "o", "[INFO] [dry-run] Would install Longhorn from addon source...\r\n"]
[0.225, "o", "[INFO] Processing stack addon 'rancher' from stack 'base'\r\n"]
[0.228, "o", "[WARN] k3s is not active, so Rancher preflight can only be partial.\r\n"]
[0.23, "o", "[INFO] [dry-run] Would install Rancher from addon source...\r\n"]
[0.234, "o", "[INFO] Processing stack addon 'registry' from stack 'base'\r\n"]
[0.237, "o", "[WARN] k3s is not active, so registry preflight can only be partial.\r\n"]
[0.238, "o", "[INFO] [dry-run] Would install Registry from addon source...\r\n"]
[0.242, "o", "[INFO] Preflight checks for NFS passed.\r\n"]
[0.246, "o", "[WARN] Missing OS packages for NFS server: nfs-kernel-server\r\n"]
[0.246, "o", "Install the missing packages for NFS server? [y] (y/n): "]
[0.246, "o", "[INFO] Installing packages for NFS server...\r\n"]
[0.246, "o", "[INFO] [dry-run] Updating apt indexes for NFS server\r\n"]
[0.246, "o", "  sudo apt-get update -y \r\n"]
[0.246, "o", "[INFO] [dry-run] Installing packages for NFS server\r\n"]
[0.246, "o", "  sudo apt-get install -y nfs-kernel-server \r\n"]
[0.246, "o", "[INFO] [dry-run] Enabling and starting nfs-kernel-server\r\n"]
[0.246, "o", "  sudo systemctl enable --now nfs-kernel-server \r\n"]
[0.246, "o", "[INFO] [dry-run] Creating NFS export directory /srv/nfs/k8s-share\r\n"]
[0.246, "o", "sudo mkdir -p /srv/nfs/k8s-share \r\n"]
[0.247, "o", "[INFO] [dry-run] Adding NFS export to /etc/exports\r\n"]
[0.247, "o", "  /srv/nfs/k8s-share 192.168.0.0/24(rw,sync,no_subtree_check)\r\n"]
[0.247, "o", "[INFO] [dry-run] Reloading NFS exports\r\n"]
[0.247, "o", "  sudo exportfs -ra \r\n"]
[0.248, "o", "[INFO] DONE. Quick checks:\r\n"]
[0.248, "o", "  cluster nodes:        sudo k3s kubectl get nodes\r\n"]
[0.248, "o", "  cert-manager pods:    sudo k3s kubectl get pods -n cert-manager\r\n"]
[0.249, "o", "  longhorn pods:        sudo k3s kubectl get pods -n longhorn-system\r\n"]
[0.249, "o", "  rancher pods:         sudo k3s kubectl get pods -n cattle-system\r\n"]
[0.249, "o", "  registry pods:        sudo k3s kubectl get pods -n registry\r\n"]
[0.249, "o", "  nfs exports:          sudo exportfs -v\r\n"]
[0.249, "o", "[WARN] DNS/Hosts:\r\n"]
[0.249, "o", "  Ensure these resolve to your VM IP:\r\n"]
[0.249, "o", "    rancher.example.local\r\n"]
[0.249, "o", "    registry.example.local\r\n"]
[0.249, "o", "  Local /etc/hosts entries would be updated on this machine by the selected add-ons:\r\n"]
[0.249, "o", "    10.162.98.241 rancher.example.local\r\n"]
[0.249, "o", "    10.162.98.241 registry.example.local\r\n"]
[0.249, "o", "[WARN] Self-signed TLS:\r\n"]
[0.249, "o", "  - Your browser and Docker clients may not trust the cert by default.\r\n"]
[0.249, "o", "  - To use the registry with docker push/pull from a machine, you typically need to trust the CA/cert.\r\n"]
[0.249, "o", "  Rancher URL:  https://rancher.example.local\r\n"]
[0.249, "o", "  Registry URL: https://registry.example.local\r\n"]
[0.251, "o", "  NFS export:    10.162.98.241:/srv/nfs/k8s-share\r\n"]
[0.251, "o", "  NFS clients:   192.168.0.0/24\r\n"]
[0.251, "o", "  Run manifest:  runs/apply-20260824-184335-2389-1987628315.json\r\n"]
[0.251, "o", "[INFO] Dry-run summary\r\n"]
[0.251, "o", "  Reuse existing:\r\n"]
[0.251, "o", "    - none\r\n"]
[0.251, "o", "  Would install/configure:\r\n"]
[0.251, "o", "    - k3s\r\n"]
[0.251, "o", "    - helm\r\n"]
[0.251, "o", "    - cert-manager\r\n"]
[0.251, "o", "    - clusterissuer/selfsigned\r\n"]
[0.251, "o", "    - Longhorn\r\n"]
[0.251, "o", "    - Rancher\r\n"]
[0.251, "o", "    - Registry\r\n"]
[0.251, "o", "    - NFS server\r\n"]
[0.251, "o", "    - NFS export /srv/nfs/k8s-share (192.168.0.0/24)\r\n"]
[0.251, "o", "  Skipped by choice/preflight:\r\n"]
[0.251, "o", "    - none\r\n"]
[0.251, "o", "  Warnings:\r\n"]
[0.251, "o", "    - cert-manager: k3s is not active, preflight is partial\r\n"]
[0.251, "o", "    - Longhorn: k3s is not active, preflight is partial\r\n"]
[0.251, "o", "    - Rancher: k3s is not active, preflight is partial\r\n"]
[0.251, "o", "    - Registry: k3s is not active, preflight is partial\r\n$ "]
