Add clusterset IP CIDR configuration to the operator chart

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
This commit is contained in:
Tom Pantelis
2024-09-11 07:54:32 -04:00
committed by Thomas Pantelis
parent cfebd2c93a
commit 5cf3f48cd8
4 changed files with 1040 additions and 848 deletions
+2
View File
@@ -58,6 +58,8 @@ Submariner enables direct networking between Pods and Services in different Kube
| submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | |
| submariner.clustersetIpCidr | string | `""` | |
| submariner.clustersetIpEnabled | bool | `false` | |
| submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.14.0"` | |
+225 -39
View File
@@ -3,8 +3,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.4.1
creationTimestamp: null
controller-gen.kubebuilder.io/version: v0.12.1
name: submariners.submariner.io
spec:
group: submariner.io
@@ -18,7 +17,7 @@ spec:
- name: v1alpha1
schema:
openAPIV3Schema:
description: Submariner is the Schema for the submariners API
description: Submariner is the Schema for the submariners API.
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
@@ -33,43 +32,72 @@ spec:
metadata:
type: object
spec:
description: SubmarinerSpec defines the desired state of Submariner
description: SubmarinerSpec defines the desired state of Submariner.
properties:
airGappedDeployment:
type: boolean
broker:
description: Type of broker (must be "k8s").
type: string
brokerK8sApiServer:
description: The broker API URL.
type: string
brokerK8sApiServerToken:
description: The broker API Token.
type: string
brokerK8sCA:
description: The broker certificate authority.
type: string
brokerK8sInsecure:
type: boolean
brokerK8sRemoteNamespace:
description: The Broker namespace.
type: string
brokerK8sSecret:
type: string
cableDriver:
description: Cable driver implementation - any of [libreswan, wireguard,
vxlan].
type: string
ceIPSecDebug:
description: Enable logging IPsec debugging information.
type: boolean
ceIPSecForceUDPEncaps:
description: Force UDP encapsulation for IPsec.
type: boolean
ceIPSecIKEPort:
description: The IPsec IKE port (500 usually).
type: integer
ceIPSecNATTPort:
description: The IPsec NAT traversal port (4500 usually).
type: integer
ceIPSecPSK:
description: The IPsec Pre-Shared Key which must be identical in all
route agents across the cluster.
type: string
ceIPSecPSKSecret:
type: string
ceIPSecPreferredServer:
description: Enable this cluster as a preferred server for data-plane
connections.
type: boolean
clusterCIDR:
description: The cluster CIDR.
type: string
clusterID:
description: The cluster ID used to identify the tunnels.
type: string
clustersetIPCIDR:
description: ClustersetIP CIDR for allocating ClustersetIPs to exported
services.
type: string
colorCodes:
type: string
connectionHealthCheck:
description: The gateway connection health check.
properties:
enabled:
description: Enable the connection health check.
type: boolean
intervalSeconds:
description: The interval at which health check pings are sent.
@@ -82,47 +110,111 @@ spec:
type: integer
type: object
coreDNSCustomConfig:
description: Name of the custom CoreDNS configmap to configure forwarding
to Lighthouse. It should be in <namespace>/<name> format where <namespace>
is optional and defaults to kube-system.
properties:
configMapName:
description: Name of the custom CoreDNS configmap.
type: string
namespace:
description: Namespace of the custom CoreDNS configmap.
type: string
type: object
customDomains:
description: List of domains to use for multi-cluster service discovery.
items:
type: string
type: array
x-kubernetes-list-type: set
debug:
description: Enable operator debugging.
type: boolean
globalCIDR:
description: The Global CIDR super-net range for allocating GlobalCIDRs
to each cluster.
type: string
haltOnCertificateError:
description: Halt on certificate error (so the pod gets restarted).
type: boolean
imageOverrides:
additionalProperties:
type: string
description: Override component images.
type: object
loadBalancerEnabled:
description: Enable automatic Load Balancer in front of the gateways.
type: boolean
namespace:
description: The namespace in which to deploy the submariner operator.
type: string
natEnabled:
description: Enable NAT between clusters.
type: boolean
nodeSelector:
additionalProperties:
type: string
type: object
repository:
description: The image repository.
type: string
serviceCIDR:
description: The service CIDR.
type: string
serviceDiscoveryEnabled:
description: Enable support for Service Discovery (Lighthouse).
type: boolean
clustersetIPEnabled:
description: Enable ClustersetIP default for services exported on this
cluster.
type: boolean
tolerations:
items:
description: The pod this Toleration is attached to tolerates any
taint that matches the triple <key,value,effect> using the matching
operator <operator>.
properties:
effect:
description: Effect indicates the taint effect to match. Empty
means match all taint effects. When specified, allowed values
are NoSchedule, PreferNoSchedule and NoExecute.
type: string
key:
description: Key is the taint key that the toleration applies
to. Empty means match all taint keys. If the key is empty,
operator must be Exists; this combination means to match all
values and all keys.
type: string
operator:
description: Operator represents a key's relationship to the
value. Valid operators are Exists and Equal. Defaults to Equal.
Exists is equivalent to wildcard for value, so that a pod
can tolerate all taints of a particular category.
type: string
tolerationSeconds:
description: TolerationSeconds represents the period of time
the toleration (which must be of effect NoExecute, otherwise
this field is ignored) tolerates the taint. By default, it
is not set, which means tolerate the taint forever (do not
evict). Zero and negative values will be treated as 0 (evict
immediately) by the system.
format: int64
type: integer
value:
description: Value is the taint value the toleration matches
to. If the operator is Exists, the value should be empty,
otherwise just a regular string.
type: string
type: object
type: array
version:
description: The image tag.
type: string
required:
- broker
- brokerK8sApiServer
- brokerK8sApiServerToken
- brokerK8sCA
- brokerK8sRemoteNamespace
- ceIPSecDebug
- ceIPSecPSK
- clusterCIDR
- clusterID
- debug
@@ -131,15 +223,23 @@ spec:
- serviceCIDR
type: object
status:
description: SubmarinerStatus defines the observed state of Submariner
description: SubmarinerStatus defines the observed state of Submariner.
properties:
airGappedDeployment:
type: boolean
clusterCIDR:
description: The current cluster CIDR.
type: string
clusterID:
description: The current cluster ID.
type: string
clustersetIPCIDR:
description: The current clustersetIP CIDR.
type: string
colorCodes:
type: string
deploymentInfo:
description: Information about the deployment.
properties:
cloudProvider:
type: string
@@ -151,6 +251,7 @@ spec:
type: string
type: object
gatewayDaemonSetStatus:
description: The status of the gateway DaemonSet.
properties:
lastResourceVersion:
type: string
@@ -174,7 +275,7 @@ spec:
description: Details about a terminated container
properties:
containerID:
description: Container's ID in the format 'docker://<container_id>'
description: Container's ID in the format '<type>://<container_id>'
type: string
exitCode:
description: Exit status from the last termination of
@@ -287,9 +388,9 @@ spec:
format: int32
type: integer
numberReady:
description: The number of nodes that should be running the
daemon pod and have one or more of the daemon pod running
and ready.
description: numberReady is the number of nodes that should
be running the daemon pod and have one or more of the daemon
pod running with a Ready Condition.
format: int32
type: integer
numberUnavailable:
@@ -318,6 +419,7 @@ spec:
- mismatchedContainerImages
type: object
gateways:
description: Status of the gateways in the cluster.
items:
properties:
connections:
@@ -444,8 +546,10 @@ spec:
type: object
type: array
globalCIDR:
description: The current global CIDR.
type: string
globalnetDaemonSetStatus:
description: The status of the Globalnet DaemonSet.
properties:
lastResourceVersion:
type: string
@@ -469,7 +573,7 @@ spec:
description: Details about a terminated container
properties:
containerID:
description: Container's ID in the format 'docker://<container_id>'
description: Container's ID in the format '<type>://<container_id>'
type: string
exitCode:
description: Exit status from the last termination of
@@ -582,9 +686,9 @@ spec:
format: int32
type: integer
numberReady:
description: The number of nodes that should be running the
daemon pod and have one or more of the daemon pod running
and ready.
description: numberReady is the number of nodes that should
be running the daemon pod and have one or more of the daemon
pod running with a Ready Condition.
format: int32
type: integer
numberUnavailable:
@@ -613,6 +717,7 @@ spec:
- mismatchedContainerImages
type: object
loadBalancerStatus:
description: The status of the load balancer DaemonSet.
properties:
status:
description: LoadBalancerStatus represents the status of a load-balancer.
@@ -634,15 +739,53 @@ spec:
description: IP is set for load-balancer ingress points
that are IP based (typically GCE or OpenStack load-balancers)
type: string
ports:
description: Ports is a list of records of service ports
If used, every port defined in the service should
have an entry in it
items:
properties:
error:
description: 'Error is to record the problem with
the service port The format of the error shall
comply with the following rules: - built-in
error values shall be specified in this file
and those shall use CamelCase names - cloud
provider specific error values must have names
that comply with the format foo.example.com/CamelCase.
--- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)'
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
port:
description: Port is the port number of the service
port of which status is recorded here
format: int32
type: integer
protocol:
default: TCP
description: 'Protocol is the protocol of the
service port of which status is recorded here
The supported values are: "TCP", "UDP", "SCTP"'
type: string
required:
- port
- protocol
type: object
type: array
x-kubernetes-list-type: atomic
type: object
type: array
type: object
type: object
natEnabled:
description: The current NAT status.
type: boolean
networkPlugin:
description: The current network plugin.
type: string
routeAgentDaemonSetStatus:
description: The status of the route agent DaemonSet.
properties:
lastResourceVersion:
type: string
@@ -666,7 +809,7 @@ spec:
description: Details about a terminated container
properties:
containerID:
description: Container's ID in the format 'docker://<container_id>'
description: Container's ID in the format '<type>://<container_id>'
type: string
exitCode:
description: Exit status from the last termination of
@@ -779,9 +922,9 @@ spec:
format: int32
type: integer
numberReady:
description: The number of nodes that should be running the
daemon pod and have one or more of the daemon pod running
and ready.
description: numberReady is the number of nodes that should
be running the daemon pod and have one or more of the daemon
pod running with a Ready Condition.
format: int32
type: integer
numberUnavailable:
@@ -810,6 +953,11 @@ spec:
- mismatchedContainerImages
type: object
serviceCIDR:
description: The current service CIDR.
type: string
version:
description: The image version in use by the various Submariner DaemonSets
and Deployments.
type: string
required:
- clusterID
@@ -820,19 +968,12 @@ spec:
storage: true
subresources:
status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.4.1
creationTimestamp: null
controller-gen.kubebuilder.io/version: v0.12.1
name: servicediscoveries.submariner.io
spec:
group: submariner.io
@@ -846,7 +987,7 @@ spec:
- name: v1alpha1
schema:
openAPIV3Schema:
description: ServiceDiscovery is the Schema for the servicediscoveries API
description: ServiceDiscovery is the Schema for the servicediscoveries API.
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
@@ -861,7 +1002,7 @@ spec:
metadata:
type: object
spec:
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery.
properties:
brokerK8sApiServer:
type: string
@@ -873,13 +1014,19 @@ spec:
type: boolean
brokerK8sRemoteNamespace:
type: string
brokerK8sSecret:
type: string
clusterID:
type: string
clustersetIPCIDR:
type: string
coreDNSCustomConfig:
properties:
configMapName:
description: Name of the custom CoreDNS configmap.
type: string
namespace:
description: Namespace of the custom CoreDNS configmap.
type: string
type: object
customDomains:
@@ -891,27 +1038,72 @@ spec:
type: boolean
globalnetEnabled:
type: boolean
haltOnCertificateError:
type: boolean
clustersetIPEnabled:
type: boolean
imageOverrides:
additionalProperties:
type: string
type: object
namespace:
type: string
nodeSelector:
additionalProperties:
type: string
type: object
repository:
type: string
tolerations:
items:
description: The pod this Toleration is attached to tolerates any
taint that matches the triple <key,value,effect> using the matching
operator <operator>.
properties:
effect:
description: Effect indicates the taint effect to match. Empty
means match all taint effects. When specified, allowed values
are NoSchedule, PreferNoSchedule and NoExecute.
type: string
key:
description: Key is the taint key that the toleration applies
to. Empty means match all taint keys. If the key is empty,
operator must be Exists; this combination means to match all
values and all keys.
type: string
operator:
description: Operator represents a key's relationship to the
value. Valid operators are Exists and Equal. Defaults to Equal.
Exists is equivalent to wildcard for value, so that a pod
can tolerate all taints of a particular category.
type: string
tolerationSeconds:
description: TolerationSeconds represents the period of time
the toleration (which must be of effect NoExecute, otherwise
this field is ignored) tolerates the taint. By default, it
is not set, which means tolerate the taint forever (do not
evict). Zero and negative values will be treated as 0 (evict
immediately) by the system.
format: int64
type: integer
value:
description: Value is the taint value the toleration matches
to. If the operator is Exists, the value should be empty,
otherwise just a regular string.
type: string
type: object
type: array
version:
type: string
required:
- brokerK8sApiServer
- brokerK8sApiServerToken
- brokerK8sCA
- brokerK8sRemoteNamespace
- clusterID
- debug
- namespace
type: object
status:
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery.
properties:
deploymentInfo:
properties:
@@ -930,12 +1122,6 @@ spec:
storage: true
subresources:
status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
@@ -52,6 +52,8 @@ spec:
{{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}"
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck:
+2
View File
@@ -5,6 +5,8 @@ submariner:
clusterCidr: ""
serviceCidr: ""
globalCidr: ""
clustersetIpCidr: ""
clustersetIpEnabled: false
loadBalancerEnabled: false
natEnabled: false
colorCodes: blue