mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-23 05:30:34 +00:00
setup charts
This commit is contained in:
@@ -1,3 +1,3 @@
|
|||||||
# submariner-charts
|
# submariner-charts
|
||||||
|
|
||||||
Please see https://github.com/rancher/submariner for more information. This is only a supporting repository for Submariner
|
Please see https://github.com/submariner-io/submariner for more information.
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
.git
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
name: submariner-k8s-broker
|
|
||||||
version: 0.0.1
|
|
||||||
appVersion: v0.0.1
|
|
||||||
description: Submariner Kubernetes Broker
|
|
||||||
keywords:
|
|
||||||
home: https://submariner.io/
|
|
||||||
sources:
|
|
||||||
- https://github.com/rancher/submariner-charts
|
|
||||||
maintainers:
|
|
||||||
- name: Rancher Labs
|
|
||||||
email: charts@rancher.com
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
# Submariner Kubernetes Broker
|
|
||||||
|
|
||||||
[Submariner](https://submariner.io) is a cross-cluster networking tool.
|
|
||||||
|
|
||||||
This chart creates a service account and role/role binding for use by Submariner to share cluster/endpoint information between clusters.
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
questions:
|
|
||||||
- variable: submariner-k8s-broker.rbac.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Role Based Access Control"
|
|
||||||
description: "Create the role/rolebinding for the Submariner client"
|
|
||||||
label: "RBAC Creation Enabled"
|
|
||||||
- variable: submariner-k8s-broker.crd.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Submariner CRD"
|
|
||||||
description: "Create the submariner CRDs for the Submariner client"
|
|
||||||
label: "Submariner CRD Creation Enabled"
|
|
||||||
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Service Account"
|
|
||||||
description: "Create the service account for the Submariner client"
|
|
||||||
label: "Submariner Service Account Creation Enabled"
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
The Submariner Kubernetes Broker is now setup.
|
|
||||||
|
|
||||||
You can retrieve the server URL by running
|
|
||||||
|
|
||||||
$ SUBMARINER_BROKER_URL=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
|
||||||
|
|
||||||
The broker client token and CA can be retrieved by running
|
|
||||||
|
|
||||||
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
|
|
||||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner-k8s-broker.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
||||||
If release name contains chart name it will be used as a full name.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner-k8s-broker.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride -}}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
|
||||||
{{- if contains $name .Release.Name -}}
|
|
||||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner-k8s-broker.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-client service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.client.create -}}
|
|
||||||
{{ default (printf "%s-client" (include "submariner-k8s-broker.fullname" .)) .Values.serviceAccounts.client.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.client.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
{{- if .Values.crd.create -}}
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: clusters.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Cluster
|
|
||||||
plural: clusters
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: endpoints.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Endpoint
|
|
||||||
plural: endpoints
|
|
||||||
scope: Namespaced
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
{{- if .Values.rbac.create -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
|
||||||
app: {{ template "submariner-k8s-broker.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: ["submariner.io"]
|
|
||||||
resources: ["clusters", "endpoints"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
{{- if .Values.serviceAccounts.client.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
|
||||||
app: {{ template "submariner-k8s-broker.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
rbac:
|
|
||||||
create: true
|
|
||||||
crd:
|
|
||||||
create: true
|
|
||||||
serviceAccounts:
|
|
||||||
client:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
.git
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
name: submariner
|
|
||||||
version: 0.0.1
|
|
||||||
appVersion: v0.0.1
|
|
||||||
description: Submariner
|
|
||||||
keywords:
|
|
||||||
home: https://submariner.io/
|
|
||||||
sources:
|
|
||||||
- https://github.com/rancher/submariner-charts
|
|
||||||
maintainers:
|
|
||||||
- name: Rancher Labs
|
|
||||||
email: charts@rancher.com
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
# Submariner
|
|
||||||
|
|
||||||
[Submariner](https://submariner.io) is a cross-cluster networking tool.
|
|
||||||
|
|
||||||
This chart creates the required components in this cluster to enable cross cluster networking.
|
|
||||||
@@ -1,132 +0,0 @@
|
|||||||
questions:
|
|
||||||
- variable: defaultEngineImage
|
|
||||||
default: true
|
|
||||||
description: "Use default Submariner Engine image or specify a custom one"
|
|
||||||
label: Use default submariner engine image
|
|
||||||
type: boolean
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Container Images"
|
|
||||||
subquestions:
|
|
||||||
- variable: engine.image.repository
|
|
||||||
default: "rancher/submariner"
|
|
||||||
description: "Submariner Engine Image Repository"
|
|
||||||
type: string
|
|
||||||
label: Submariner Engine Image Repository
|
|
||||||
- variable: engine.image.tag
|
|
||||||
default: "v0.0.1"
|
|
||||||
description: "Submariner Engine Image Tag"
|
|
||||||
type: string
|
|
||||||
label: Submariner Engine Image Tag
|
|
||||||
- variable: defaultRouteAgentImage
|
|
||||||
default: true
|
|
||||||
description: "Use default Submariner Route Agent image or specify a custom one"
|
|
||||||
label: Use default submariner route agent image
|
|
||||||
type: boolean
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Container Images"
|
|
||||||
subquestions:
|
|
||||||
- variable: routeAgent.image.repository
|
|
||||||
default: "rancher/submariner-route-agent"
|
|
||||||
description: "Submariner Route Agent Image Repository"
|
|
||||||
type: string
|
|
||||||
label: Submariner Route Agent Image Repository
|
|
||||||
- variable: routeAgent.image.tag
|
|
||||||
default: "v0.0.1"
|
|
||||||
description: "Submariner Route Agent Image Tag"
|
|
||||||
type: string
|
|
||||||
label: Submariner Route Agent Image Tag
|
|
||||||
- variable: engine.nodeSelectorEnabled
|
|
||||||
default: true
|
|
||||||
description: "Restrict submariner to nodes labeled with submariner.io/gateway=true"
|
|
||||||
label: Restrict gateway deployments to specific nodes
|
|
||||||
type: boolean
|
|
||||||
group: "Gateway Configuration"
|
|
||||||
- variable: submariner.clusterId
|
|
||||||
default: ""
|
|
||||||
description: "Enter a unique cluster ID to identify this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Cluster ID"
|
|
||||||
group: "Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: ipsec.psk
|
|
||||||
default: ""
|
|
||||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
|
||||||
type: string
|
|
||||||
label: "IPsec Pre-Shared Key"
|
|
||||||
group: "Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: broker.type
|
|
||||||
type: enum
|
|
||||||
default: k8s
|
|
||||||
options:
|
|
||||||
- k8s
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Type"
|
|
||||||
description: "Type of Broker to use"
|
|
||||||
- variable: broker.server
|
|
||||||
type: string
|
|
||||||
default: ""
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Server"
|
|
||||||
description: "Broker server to use (without the https://)"
|
|
||||||
- variable: broker.insecure
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Insecure Broker"
|
|
||||||
description: "Connect to K8s broker without validating CA"
|
|
||||||
subquestions:
|
|
||||||
- variable: broker.ca
|
|
||||||
type: string
|
|
||||||
description: "Base64 encoded broker ca.crt"
|
|
||||||
label: "Broker CA encoded in base64"
|
|
||||||
default: ""
|
|
||||||
- variable: broker.token
|
|
||||||
type: string
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Token"
|
|
||||||
description: "Bearer token for broker"
|
|
||||||
- variable: broker.namespace
|
|
||||||
type: string
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Namespace"
|
|
||||||
description: "Enter namespace to use on central broker"
|
|
||||||
- variable: submariner.clusterCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Cluster CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: submariner.serviceCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Service CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: submariner.natEnabled
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
|
||||||
label: "NAT Enabled"
|
|
||||||
- variable: crd.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Create the Submariner CRDs, if deploying Submariner into the same cluster as the submariner-k8s-broker, you probably shouldn't create CRDs"
|
|
||||||
label: "CRD Creation Enabled"
|
|
||||||
- variable: submariner.debug
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable submariner debug mode"
|
|
||||||
label: "Submariner Debug Enabled"
|
|
||||||
- variable: ipsec.debug
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable Charon debug mode"
|
|
||||||
label: "Charon Enabled"
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
Submariner is now installed.
|
|
||||||
|
|
||||||
{{- if .Values.engine.nodeSelectorEnabled }}
|
|
||||||
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
||||||
If release name contains chart name it will be used as a full name.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride -}}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
|
||||||
{{- if contains $name .Release.Name -}}
|
|
||||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-engine service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.engineServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.engine.create -}}
|
|
||||||
{{ default (printf "%s-engine" (include "submariner.fullname" .)) .Values.serviceAccounts.engine.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.engine.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-route-agent service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.routeAgentServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
|
||||||
{{ default (printf "%s-routeagent" (include "submariner.fullname" .)) .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
{{- if .Values.crd.create -}}
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: clusters.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Cluster
|
|
||||||
plural: clusters
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: endpoints.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Endpoint
|
|
||||||
plural: endpoints
|
|
||||||
scope: Namespaced
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,123 +0,0 @@
|
|||||||
apiVersion: apps/v1beta2
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.fullname" . }}-engine
|
|
||||||
component: engine
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
spec:
|
|
||||||
progressDeadlineSeconds: 600
|
|
||||||
replicas: 1
|
|
||||||
revisionHistoryLimit: 5
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ template "submariner.fullname" . }}-engine
|
|
||||||
strategy:
|
|
||||||
rollingUpdate:
|
|
||||||
maxSurge: 1
|
|
||||||
maxUnavailable: 0
|
|
||||||
type: RollingUpdate
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
creationTimestamp: null
|
|
||||||
labels:
|
|
||||||
app: {{ template "submariner.fullname" . }}-engine
|
|
||||||
spec:
|
|
||||||
affinity:
|
|
||||||
podAntiAffinity:
|
|
||||||
requiredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
- labelSelector:
|
|
||||||
matchExpressions:
|
|
||||||
- key: app
|
|
||||||
operator: In
|
|
||||||
values:
|
|
||||||
- {{ template "submariner.fullname" . }}-engine
|
|
||||||
topologyKey: "kubernetes.io/hostname"
|
|
||||||
{{- with .Values.engine.affinity }}
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
nodeSelector:
|
|
||||||
{{- if .Values.engine.nodeSelectorEnabled }}
|
|
||||||
submariner.io/gateway: "true"
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.engine.nodeSelector }}
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.engine.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
containers:
|
|
||||||
- command:
|
|
||||||
- submariner.sh
|
|
||||||
env:
|
|
||||||
- name: SUBMARINER_NAMESPACE
|
|
||||||
value: "{{ .Release.Namespace }}"
|
|
||||||
- name: SUBMARINER_CLUSTERCIDR
|
|
||||||
value: "{{ .Values.submariner.clusterCidr }}"
|
|
||||||
- name: SUBMARINER_SERVICECIDR
|
|
||||||
value: "{{ .Values.submariner.serviceCidr }}"
|
|
||||||
- name: SUBMARINER_TOKEN
|
|
||||||
value: "{{ .Values.submariner.apiToken }}"
|
|
||||||
- name: SUBMARINER_CLUSTERID
|
|
||||||
value: "{{ .Values.submariner.clusterId }}"
|
|
||||||
- name: SUBMARINER_COLORCODES
|
|
||||||
value: "{{ .Values.submariner.colorCodes }}"
|
|
||||||
- name: SUBMARINER_DEBUG
|
|
||||||
value: "{{ .Values.submariner.debug }}"
|
|
||||||
- name: SUBMARINER_NATENABLED
|
|
||||||
value: "{{ .Values.submariner.natEnabled }}"
|
|
||||||
- name: SUBMARINER_BROKER
|
|
||||||
value: "{{ .Values.broker.type }}"
|
|
||||||
{{- if eq .Values.broker.type "phpapi" }}
|
|
||||||
- name: BROKER_PHPAPI_PROTO
|
|
||||||
value: "{{ .Values.broker.proto }}"
|
|
||||||
- name: BROKER_PHPAPI_SERVER
|
|
||||||
value: "{{ .Values.broker.server }}"
|
|
||||||
{{- end }}
|
|
||||||
{{- if eq .Values.broker.type "k8s" }}
|
|
||||||
- name: BROKER_K8S_APISERVER
|
|
||||||
value: "{{ .Values.broker.server }}"
|
|
||||||
- name: BROKER_K8S_APISERVERTOKEN
|
|
||||||
value: "{{ .Values.broker.token }}"
|
|
||||||
- name: BROKER_K8S_REMOTENAMESPACE
|
|
||||||
value: "{{ .Values.broker.namespace }}"
|
|
||||||
{{- if .Values.broker.insecure }}
|
|
||||||
- name: BROKER_K8S_INSECURE
|
|
||||||
value: "true"
|
|
||||||
{{- else }}
|
|
||||||
- name: BROKER_K8S_CA
|
|
||||||
value: "{{ .Values.broker.ca }}"
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
- name: CE_IPSEC_PSK
|
|
||||||
value: "{{ .Values.ipsec.psk }}"
|
|
||||||
- name: CE_IPSEC_DEBUG
|
|
||||||
value: "{{ .Values.ipsec.debug }}"
|
|
||||||
image: {{ .Values.engine.image.repository }}:{{ .Values.engine.image.tag }}
|
|
||||||
imagePullPolicy: {{ .Values.engine.image.pullPolicy }}
|
|
||||||
name: submariner
|
|
||||||
resources:
|
|
||||||
{{ toYaml .Values.engine.resources | indent 10 }}
|
|
||||||
securityContext:
|
|
||||||
allowPrivilegeEscalation: true
|
|
||||||
capabilities:
|
|
||||||
add:
|
|
||||||
- ALL
|
|
||||||
privileged: true
|
|
||||||
readOnlyRootFilesystem: false
|
|
||||||
runAsNonRoot: false
|
|
||||||
stdin: true
|
|
||||||
terminationMessagePath: /dev/termination-log
|
|
||||||
terminationMessagePolicy: File
|
|
||||||
tty: true
|
|
||||||
dnsPolicy: ClusterFirst
|
|
||||||
hostNetwork: true
|
|
||||||
restartPolicy: Always
|
|
||||||
schedulerName: default-scheduler
|
|
||||||
securityContext: {}
|
|
||||||
terminationGracePeriodSeconds: 0
|
|
||||||
serviceAccountName: {{ template "submariner.engineServiceAccountName" . }}
|
|
||||||
@@ -1,64 +0,0 @@
|
|||||||
{{- if .Values.rbac.create -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:engine
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["configmaps"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
|
||||||
- apiGroups: ["submariner.io"]
|
|
||||||
resources: ["clusters", "endpoints"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["events"]
|
|
||||||
verbs: ["create", "patch"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: ["submariner.io"]
|
|
||||||
resources: ["clusters", "endpoints"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["pods"]
|
|
||||||
verbs: ["get", "watch", "list"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:engine
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:engine
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.engineServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,74 +0,0 @@
|
|||||||
apiVersion: apps/v1beta2
|
|
||||||
kind: DaemonSet
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
component: routeagent
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
component: routeagent
|
|
||||||
spec:
|
|
||||||
serviceAccountName: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
terminationGracePeriodSeconds: 0
|
|
||||||
hostNetwork: true
|
|
||||||
containers:
|
|
||||||
- name: routeagent
|
|
||||||
command:
|
|
||||||
- submariner-route-agent.sh
|
|
||||||
image: {{ .Values.routeAgent.image.repository }}:{{ .Values.routeAgent.image.tag }}
|
|
||||||
imagePullPolicy: {{ .Values.routeAgent.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
- name: SUBMARINER_NAMESPACE
|
|
||||||
value: "{{ .Release.Namespace }}"
|
|
||||||
- name: SUBMARINER_CLUSTERID
|
|
||||||
value: "{{ .Values.submariner.clusterId }}"
|
|
||||||
- name: SUBMARINER_DEBUG
|
|
||||||
value: "{{ .Values.submariner.debug }}"
|
|
||||||
- name: SUBMARINER_CLUSTERCIDR
|
|
||||||
value: "{{ .Values.submariner.clusterCidr }}"
|
|
||||||
- name: SUBMARINER_SERVICECIDR
|
|
||||||
value: "{{ .Values.submariner.serviceCidr }}"
|
|
||||||
resources:
|
|
||||||
{{ toYaml .Values.routeAgent.resources | indent 10 }}
|
|
||||||
securityContext:
|
|
||||||
allowPrivilegeEscalation: true
|
|
||||||
capabilities:
|
|
||||||
add:
|
|
||||||
- ALL
|
|
||||||
privileged: true
|
|
||||||
readOnlyRootFilesystem: false
|
|
||||||
runAsNonRoot: false
|
|
||||||
volumeMounts:
|
|
||||||
# Because we don't actually run iptables locally, but chroot in to the host
|
|
||||||
- mountPath: /host
|
|
||||||
name: host-slash
|
|
||||||
readOnly: true
|
|
||||||
{{- with .Values.routeAgent.nodeSelector }}
|
|
||||||
nodeSelector:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.routeAgent.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.routeAgent.affinity }}
|
|
||||||
affinity:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
volumes:
|
|
||||||
- name: host-slash
|
|
||||||
hostPath:
|
|
||||||
path: /
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
{{- if .Values.serviceAccounts.engine.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.engineServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
submariner:
|
|
||||||
clusterId: ""
|
|
||||||
token: ""
|
|
||||||
clusterCidr: "10.42.0.0/16"
|
|
||||||
serviceCidr: "10.43.0.0/16"
|
|
||||||
natEnabled: false
|
|
||||||
colorCodes: blue
|
|
||||||
debug: false
|
|
||||||
crd:
|
|
||||||
create: true
|
|
||||||
broker:
|
|
||||||
type: k8s
|
|
||||||
server: example.k8s.apiserver
|
|
||||||
token: test
|
|
||||||
namespace: xyz
|
|
||||||
insecure: false
|
|
||||||
ca: ""
|
|
||||||
rbac:
|
|
||||||
create: true
|
|
||||||
ipsec:
|
|
||||||
psk: ""
|
|
||||||
debug: false
|
|
||||||
engine:
|
|
||||||
image:
|
|
||||||
repository: rancher/submariner
|
|
||||||
tag: v0.0.1
|
|
||||||
pullPolicy: Always
|
|
||||||
resources: {}
|
|
||||||
# limits:
|
|
||||||
# cpu: 100m
|
|
||||||
# memory: 100Mi
|
|
||||||
nodeSelectorEnabled: true
|
|
||||||
nodeSelector: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
routeAgent:
|
|
||||||
image:
|
|
||||||
repository: rancher/submariner-route-agent
|
|
||||||
tag: v0.0.1
|
|
||||||
pullPolicy: Always
|
|
||||||
resources: {}
|
|
||||||
# limits:
|
|
||||||
# cpu: 100m
|
|
||||||
# memory: 100Mi
|
|
||||||
nodeSelector: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
serviceAccounts:
|
|
||||||
engine:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
routeAgent:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
Reference in New Issue
Block a user