{"version": 2, "width": 80, "height": 24, "timestamp": 1787593841, "env": {"SHELL": "/bin/bash", "TERM": null}, "title": "core playbook: stack install base"}
[0.0, "o", "$ ./productive-k3s-core.sh stack install base\r\n"]
[0.12, "o", "[INFO] Detected host platform: Ubuntu 24.04.4 LTS\r\n"]
[0.24, "o", "[INFO] Incremental apply: k3s + Rancher + Longhorn + Registry (Ubuntu 24.04.4 LTS)\r\n"]
[0.36, "o", "[INFO] Mode: stack (cluster stack installation)\r\n"]
[0.48, "o", "[INFO] cluster distro: k3s\r\n"]
[0.6, "o", "[INFO] cluster installation engine: native\r\n"]
[0.72, "o", "[INFO] k3s installation engine: native\r\n"]
[0.84, "o", "  Run manifest: runs/apply-20260824-145041-3471-303014120.json\r\n"]
[1.461, "o", "[INFO] Detected environment\r\n"]
[1.581, "o", "  - k3s: present\r\n"]
[1.701, "o", "  - helm: present\r\n"]
[1.821, "o", "  - cert-manager: missing\r\n"]
[1.941, "o", "  - Longhorn: missing\r\n"]
[2.061, "o", "  - Rancher: missing\r\n"]
[2.181, "o", "  - Registry: missing\r\n"]
[2.301, "o", "  - NFS server: missing\r\n"]
[2.421, "o", "[INFO] Standalone kubectl detected. Managed workflow command: sudo k3s kubectl\r\n"]
[2.541, "o", "[INFO] Diagnosis\r\n"]
[2.661, "o", "  - cert-manager is missing.\r\n"]
[2.781, "o", "  - Longhorn is missing.\r\n"]
[2.901, "o", "    Prepare and mount dedicated storage yourself if you want it; this script will not format disks.\r\n"]
[3.021, "o", "  - Rancher is missing.\r\n"]
[3.141, "o", "  - Internal registry is missing.\r\n"]
[3.261, "o", "  - NFS server is missing.\r\n"]
[4.165, "o", "Helm is already installed. Continue using it without changes? [required] [y] (y/n): "]
[4.285, "o", "Longhorn is missing. Install it now? [optional] [y] (y/n): "]
[4.405, "o", "Rancher is missing. Install it now? [optional] [y] (y/n): "]
[4.525, "o", "The in-cluster registry is missing. Install it now? [optional] [y] (y/n): "]
[4.645, "o", "cert-manager is missing. Install it now? [required for TLS-dependent installs] [y] (y/n): "]
[4.765, "o", "Base domain (used to build hostnames) [example.local]: "]
[4.885, "o", "TLS options:\r\n"]
[5.005, "o", "  1) Let's Encrypt (requires public DNS + inbound 80/443)\r\n"]
[5.125, "o", "  2) Self-signed (works anywhere; you'll need to trust certs in browser/docker)\r\n"]
[5.245, "o", "Choose TLS mode (1/2) [2]: "]
[5.365, "o", "Longhorn data mount path [/data]: "]
[5.485, "o", "Longhorn default replica count (1 for single-node) [1]: "]
[5.605, "o", "Longhorn storage minimal available percentage (10 is recommended for single-node dev/lab) [10]: \r\n"]
[5.725, "o", "[INFO] Single-node Longhorn mode is enabled. The bootstrap will create a 'longhorn-single' StorageClass with numberOfReplicas=1.\r\n"]
[5.845, "o", "[WARN] Longhorn host preparation will install open-iscsi, enable iscsid, and ensure the data path exists on this host.\r\n"]
[5.965, "o", "Make Longhorn the default StorageClass? [y] (y/n): "]
[6.085, "o", "Rancher hostname (DNS name) [rancher.home.arpa]: "]
[6.205, "o", "Rancher bootstrap password [admin]: "]
[6.325, "o", "Registry hostname (DNS name) [registry.home.arpa]: Registry PVC size [20Gi]: "]
[6.445, "o", "Registry StorageClass (blank uses cluster default) [longhorn-single]: "]
[6.565, "o", "Do you want to enable basic auth on the in-cluster registry? [n] (y/n): "]
[6.685, "o", "[INFO] Planned actions\r\n"]
[6.805, "o", "  Cluster:\r\n"]
[6.925, "o", "    - k3s: reuse\r\n"]
[7.045, "o", "    - helm: reuse\r\n"]
[7.165, "o", "    - cert-manager: install\r\n"]
[7.285, "o", "    - Longhorn: install\r\n"]
[7.405, "o", "    - Rancher: install\r\n"]
[7.525, "o", "    - Registry: install\r\n"]
[7.645, "o", "  Host:\r\n"]
[7.765, "o", "    - NFS management: skip\r\n"]
[7.885, "o", "  Add-on impact preview:\r\n"]
[8.005, "o", "    - cert-manager: cluster\r\n"]
[8.125, "o", "      \"Installs cert-manager and manages ClusterIssuer resources for TLS-enabled add-ons.\"\r\n"]
[8.245, "o", "    - longhorn: cluster  👁 host [package-install, service-enable, filesystem-path]\r\n"]
[8.365, "o", "      \"Installs Longhorn and prepares the host with iSCSI packages, service enablement, and the data path.\"\r\n"]
[8.485, "o", "    - rancher: cluster  👁 host [etc-hosts]\r\n"]
[8.605, "o", "      \"Installs Rancher and can optionally configure a local /etc/hosts entry for the selected hostname.\"\r\n"]
[8.725, "o", "    - registry: cluster  👁 host [etc-hosts, docker-registry-trust]\r\n"]
[8.845, "o", "      \"Installs an in-cluster registry and can optionally configure local /etc/hosts and Docker trust on the host.\"\r\n"]
[8.965, "o", "Proceed with this plan? [y] (y/n): "]
[9.085, "o", "[INFO] Waiting for k3s API and node readiness (timeout 180s)...\r\n"]
[9.909, "o", "[INFO] k3s API is reachable and at least one node is Ready.\r\n"]
[10.029, "o", "[INFO] Inspecting k3s node...\r\n"]
[10.149, "o", "NAME                                                STATUS   ROLES           AGE   VERSION        INTERNAL-IP    EXTERNAL-IP   OS-IMAGE             KERNEL-VERSION      CONTAINER-RUNTIME\r\n"]
[10.269, "o", "pk3s-cast-core-stack-install-base-20260824-144951   Ready    control-plane   8s    v1.35.5+k3s1   10.162.98.19   <none>        Ubuntu 24.04.4 LTS   6.8.0-137-generic   containerd://2.2.3-k3s1\r\n"]
[10.389, "o", "[INFO] Processing stack addon 'cert-manager' from stack 'base'\r\n"]
[10.509, "o", "[INFO] Preflight checks for cert-manager passed.\r\n"]
[10.629, "o", "[INFO] Installing cert-manager from addon source...\r\n"]
[11.594, "o", "Warning: resource namespaces/cert-manager is missing the kubectl.kubernetes.io/last-applied-configuration annotation which is required by kubectl apply. kubectl apply should only be used on resources created declaratively by either kubectl create --save-config or kubectl apply. The missing annotation will be patched automatically.\r\n"]
[11.714, "o", "namespace/cert-manager configured\r\n"]
[12.001, "o", "service/cert-manager-cainjector created\r\n"]
[12.121, "o", "service/cert-manager created"]
[12.241, "o", "service/cert-manager-webhook created\r\n"]
[12.361, "o", "deployment.apps/cert-manager-cainjector created\r\n"]
[12.481, "o", "deployment.apps/cert-manager created\r\n"]
[12.601, "o", "deployment.apps/cert-manager-webhook created\r\n"]
[12.721, "o", "mutatingwebhookconfiguration.admissionregistration.k8s.io/cert-manager-webhook created\r\n"]
[12.841, "o", "validatingwebhookconfiguration.admissionregistration.k8s.io/cert-manager-webhook created"]
[12.961, "o", "Waiting for deployment \"cert-manager\" rollout to finish: 0 of 1 updated replicas are available...\r\n"]
[20.961, "o", "deployment \"cert-manager\" successfully rolled out\r\n"]
[21.081, "o", "Waiting for deployment \"cert-manager-webhook\" rollout to finish: 0 of 1 updated replicas are available...\r\n"]
[26.984, "o", "deployment \"cert-manager-webhook\" successfully rolled out\r\n"]
[27.55, "o", "deployment \"cert-manager-cainjector\" successfully rolled out\r\n"]
[27.681, "o", "[INFO] Creating ClusterIssuer selfsigned via cert-manager addon\r\n"]
[27.801, "o", "clusterissuer.cert-manager.io/selfsigned created\r\n"]
[27.921, "o", "[INFO] Processing stack addon 'longhorn' from stack 'base'\r\n"]
[28.238, "o", "[WARN] The cluster already has 1 default StorageClass(es).\r\n"]
[28.358, "o", "[INFO] Installing Longhorn from addon source...\r\n"]
[28.478, "o", "[INFO] Required packages for Longhorn are already installed.\r\n"]
[28.598, "o", "Synchronizing state of iscsid.service with SysV service script with /usr/lib/systemd/systemd-sysv-install.\r\n"]
[28.718, "o", "Executing: /usr/lib/systemd/systemd-sysv-install enable iscsid\r\n"]
[29.005, "o", "Created symlink /etc/systemd/system/sysinit.target.wants/iscsid.service → /usr/lib/systemd/system/iscsid.service.\r\n"]
[29.22, "o", "[WARN] Longhorn storage path '/data' will be created if missing.\r\n"]
[29.34, "o", "[WARN] This add-on will not format or mount disks. Prepare dedicated mounted storage yourself if you need it.\r\n"]
[30.731, "o", "Release \"longhorn\" does not exist. Installing it now.\r\n"]
[31.924, "o", "I0824 14:51:10.694367    6581 warnings.go:107] \"Warning: unrecognized format \\\"int64\\\"\"\r\n"]
[32.117, "o", "NAME: longhorn\r\n"]
[32.237, "o", "LAST DEPLOYED: Mon Aug 24 14:51:10 2026\r\n"]
[32.357, "o", "NAMESPACE: longhorn-system\r\n"]
[32.477, "o", "STATUS: deployed\r\n"]
[32.597, "o", "REVISION: 1\r\n"]
[32.717, "o", "TEST SUITE: None\r\n"]
[32.837, "o", "NOTES:\r\n"]
[32.957, "o", "Longhorn is now installed on the cluster!\r\n"]
[33.077, "o", "Please wait a few minutes for other Longhorn components such as CSI deployments, Engine Images, and Instance Managers to be initialized.\r\n"]
[33.197, "o", "Visit our documentation at https://longhorn.io/docs/\r\n"]
[33.821, "o", "Waiting for deployment \"longhorn-driver-deployer\" rollout to finish: 0 of 1 updated replicas are available...\r\n"]
[41.821, "o", "deployment \"longhorn-driver-deployer\" successfully rolled out\r\n"]
[41.941, "o", "storageclass.storage.k8s.io/longhorn-single created"]
[42.061, "o", "setting.longhorn.io/storage-minimal-available-percentage patched\r\n"]
[42.679, "o", "[INFO] Processing stack addon 'rancher' from stack 'base'\r\n"]
[42.871, "o", "[INFO] Preflight checks for Rancher passed.\r\n"]
[42.991, "o", "[INFO] Installing Rancher from addon source...\r\n"]
[45.79, "o", "Warning: spec.privateKey.rotationPolicy: In cert-manager >= v1.18.0, the default value changed from `Never` to `Always`.\r\n"]
[45.91, "o", "certificate.cert-manager.io/rancher-tls created\r\n"]
[46.328, "o", "Release \"rancher\" does not exist. Installing it now.\r\n"]
[47.381, "o", "NAME: rancher\r\n"]
[47.501, "o", "LAST DEPLOYED: Mon Aug 24 14:52:00 2026\r\n"]
[47.621, "o", "NAMESPACE: cattle-system\r\n"]
[47.741, "o", "STATUS: deployed\r\n"]
[47.861, "o", "REVISION: 1\r\n"]
[47.981, "o", "TEST SUITE: None\r\n"]
[48.101, "o", "NOTES:\r\n"]
[48.221, "o", "Rancher Server has been installed. Rancher may take several minutes to fully initialize.\r\n"]
[48.341, "o", "Please standby while Certificates are being issued, Containers are started and the Ingress rule comes up.\r\n"]
[48.461, "o", "Check out our docs at https://rancher.com/docs/\r\n"]
[48.581, "o", "## First Time Login\r\n"]
[48.701, "o", "If you provided your own bootstrap password during installation, browse to https://rancher.home.arpa to get started.\r\n"]
[48.821, "o", "If this is the first time you installed Rancher, get started by running this command and clicking the URL it generates:\r\n"]
[48.941, "o", "```\r\n"]
[49.061, "o", "echo https://rancher.home.arpa/dashboard/?setup=$(kubectl get secret --namespace cattle-system bootstrap-secret -o go-template='{{.data.bootstrapPassword|base64decode}}')\r\n"]
[49.181, "o", "```\r\n"]
[49.301, "o", "To get just the bootstrap password on its own, run:\r\n"]
[49.421, "o", "```\r\n"]
[49.541, "o", "kubectl get secret --namespace cattle-system bootstrap-secret -o go-template='{{.data.bootstrapPassword|base64decode}}{{ \"\\n\" }}'\r\n"]
[49.661, "o", "```\r\n"]
[49.781, "o", "Happy Containering!\r\n"]
[50.389, "o", "Waiting for deployment \"rancher\" rollout to finish: 0 out of 3 new replicas have been updated...\r\n"]
[50.509, "o", "Waiting for deployment \"rancher\" rollout to finish: 0 of 3 updated replicas are available...\r\n"]
[51.509, "o", "Waiting for deployment spec update to be observed...\r\n"]
[51.674, "o", "Waiting for deployment \"rancher\" rollout to finish: 0 of 3 updated replicas are available...\r\n"]
[56.11, "o", "deployment \"rancher\" successfully rolled out\r\n"]
[56.23, "o", "[INFO] Processing stack addon 'registry' from stack 'base'\r\n"]
[56.801, "o", "[INFO] Preflight checks for Registry passed.\r\n"]
[56.921, "o", "[INFO] Installing Registry from addon source...\r\n"]
[57.101, "o", "namespace/registry created\r\n"]
[57.54, "o", "Warning: spec.privateKey.rotationPolicy: In cert-manager >= v1.18.0, the default value changed from `Never` to `Always`.\r\n"]
[57.66, "o", "certificate.cert-manager.io/registry-tls created\r\n"]
[63.242, "o", "deployment.apps/registry created\r\n"]
[63.362, "o", "service/registry created\r\n"]
[63.482, "o", "persistentvolumeclaim/registry-data created\r\n"]
[63.602, "o", "ingress.networking.k8s.io/registry created\r\n"]
[63.788, "o", "Waiting for deployment \"registry\" rollout to finish: 0 of 1 updated replicas are available...\r\n"]
[71.788, "o", "deployment \"registry\" successfully rolled out\r\n"]
[71.908, "o", "[INFO] DONE. Quick checks:\r\n"]
[72.028, "o", "  cluster nodes:        sudo k3s kubectl get nodes\r\n"]
[72.148, "o", "  cert-manager pods:    sudo k3s kubectl get pods -n cert-manager\r\n"]
[72.268, "o", "  longhorn pods:        sudo k3s kubectl get pods -n longhorn-system\r\n"]
[72.388, "o", "  rancher pods:         sudo k3s kubectl get pods -n cattle-system\r\n"]
[72.508, "o", "  registry pods:        sudo k3s kubectl get pods -n registry\r\n"]
[72.628, "o", "[WARN] DNS/Hosts:\r\n"]
[72.748, "o", "  Ensure these resolve to your VM IP:\r\n"]
[72.868, "o", "    rancher.home.arpa\r\n"]
[72.988, "o", "    registry.home.arpa\r\n"]
[73.108, "o", "  For local testing on the VM itself, you can add to /etc/hosts:\r\n"]
[73.228, "o", "    <VM-IP> rancher.home.arpa\r\n"]
[73.348, "o", "    <VM-IP> registry.home.arpa\r\n"]
[73.468, "o", "[WARN] Self-signed TLS:\r\n"]
[73.588, "o", "  - Your browser and Docker clients may not trust the cert by default.\r\n"]
[73.708, "o", "  - To use the registry with docker push/pull from a machine, you typically need to trust the CA/cert.\r\n"]
[73.828, "o", "  Rancher URL:  https://rancher.home.arpa\r\n"]
[73.948, "o", "  Registry URL: https://registry.home.arpa\r\n"]
[74.068, "o", "  Run manifest:  runs/apply-20260824-145041-3471-303014120.json\r\n$ "]
