mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-20 20:20:35 +00:00
Add Lighthouse charts
This adds the deployment for lighthouse-agent, service account and RBAC.
This commit is contained in:
committed by
Miguel Angel Ajo Pelayo
parent
2914c74e38
commit
5e425b9079
@@ -26,4 +26,36 @@ spec:
|
||||
kind: Endpoint
|
||||
plural: endpoints
|
||||
scope: Namespaced
|
||||
---
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: multiclusterservices.lighthouse.submariner.io
|
||||
annotations:
|
||||
"helm.sh/hook": crd-install
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: MultiClusterService
|
||||
plural: multiclusterservices
|
||||
singular: multiclusterservice
|
||||
scope: Namespaced
|
||||
validation:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
spec:
|
||||
properties:
|
||||
clusterServiceInfo:
|
||||
properties:
|
||||
clusterID:
|
||||
type: "string"
|
||||
clusterDomain:
|
||||
type: "string"
|
||||
serviceIP:
|
||||
type: "string"
|
||||
port:
|
||||
type: "integer"
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -12,6 +12,9 @@ rules:
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
- apiGroups: ["lighthouse.submariner.io"]
|
||||
resources: ["multiclusterservices"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
|
||||
@@ -7,3 +7,5 @@ serviceAccounts:
|
||||
client:
|
||||
create: true
|
||||
name: ""
|
||||
submariner:
|
||||
serviceDiscovery: false
|
||||
|
||||
@@ -63,3 +63,14 @@ Create the name of the submariner-globalnet service account to use
|
||||
{{ default "default" .Values.serviceAccounts.globalnet.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-lighthouse service account to use
|
||||
*/}}
|
||||
{{- define "submariner.lighthouseServiceAccountName" -}}
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
{{ default (printf "%s-lighthouse" (include "submariner.fullname" .)) .Values.serviceAccounts.lighthouse.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.lighthouse.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
@@ -40,4 +40,36 @@ spec:
|
||||
kind: Gateway
|
||||
plural: gateways
|
||||
scope: Namespaced
|
||||
---
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: multiclusterservices.lighthouse.submariner.io
|
||||
annotations:
|
||||
"helm.sh/hook": crd-install
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: MultiClusterService
|
||||
plural: multiclusterservices
|
||||
singular: multiclusterservice
|
||||
scope: Namespaced
|
||||
validation:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
spec:
|
||||
properties:
|
||||
clusterServiceInfo:
|
||||
properties:
|
||||
clusterID:
|
||||
type: "string"
|
||||
clusterDomain:
|
||||
type: "string"
|
||||
serviceIP:
|
||||
type: "string"
|
||||
port:
|
||||
type: "integer"
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
component: lighthouse
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
spec:
|
||||
serviceAccountName: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
containers:
|
||||
- command:
|
||||
- lighthouse-agent.sh
|
||||
env:
|
||||
- name: SUBMARINER_NAMESPACE
|
||||
value: "{{ .Release.Namespace }}"
|
||||
- name: SUBMARINER_CLUSTERID
|
||||
value: "{{ .Values.submariner.clusterId }}"
|
||||
- name: SUBMARINER_DEBUG
|
||||
value: "{{ .Values.submariner.debug }}"
|
||||
- name: BROKER_K8S_APISERVER
|
||||
value: "{{ .Values.broker.server }}"
|
||||
- name: BROKER_K8S_APISERVERTOKEN
|
||||
value: "{{ .Values.broker.token }}"
|
||||
- name: BROKER_K8S_REMOTENAMESPACE
|
||||
value: "{{ .Values.broker.namespace }}"
|
||||
{{- if .Values.broker.insecure }}
|
||||
- name: BROKER_K8S_INSECURE
|
||||
value: "true"
|
||||
{{- else }}
|
||||
- name: BROKER_K8S_CA
|
||||
value: "{{ .Values.broker.ca }}"
|
||||
{{- end }}
|
||||
name: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
image: {{ .Values.lighthouse.image.repository }}:{{ .Values.lighthouse.image.tag }}
|
||||
imagePullPolicy: {{ .Values.lighthouse.image.pullPolicy }}
|
||||
restartPolicy: Always
|
||||
terminationGracePeriodSeconds: 0
|
||||
{{- end }}
|
||||
@@ -109,5 +109,32 @@ subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
{{- end -}}
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["services", "namespaces"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
- apiGroups: ["lighthouse.submariner.io"]
|
||||
resources: ["multiclusterservices"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
@@ -33,3 +33,15 @@ metadata:
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.lighthouse.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
|
||||
@@ -8,6 +8,7 @@ submariner:
|
||||
natEnabled: false
|
||||
colorCodes: blue
|
||||
debug: false
|
||||
serviceDiscovery: false
|
||||
crd:
|
||||
create: true
|
||||
broker:
|
||||
@@ -58,6 +59,11 @@ globalnet:
|
||||
repository: submariner-globalnet
|
||||
tag: local
|
||||
pullPolicy: IfNotPresent
|
||||
lighthouse:
|
||||
image:
|
||||
repository: lighthouse-agent
|
||||
tag: local
|
||||
pullPolicy: IfNotPresent
|
||||
serviceAccounts:
|
||||
engine:
|
||||
create: true
|
||||
@@ -68,3 +74,6 @@ serviceAccounts:
|
||||
globalnet:
|
||||
create: false
|
||||
name: ""
|
||||
lighthouse:
|
||||
create: false
|
||||
name: ""
|
||||
|
||||
Reference in New Issue
Block a user