51 Commits
Author SHA1 Message Date
Lukas SpinlerandThomas Pantelis c28d8eb1d4 feat(operator): added ceIPSecPSKSecret support
Signed-off-by: Lukas Spinler <lukas.spinler@gl-systemhaus.de>
2026-02-04 08:25:07 -05:00
Kyle PetryszakandThomas Pantelis 8e92d2c3e7 (feat): add conditional support for GitOps utilizing CRD spec.brokerK8sSecret
Signed-off-by: Kyle Petryszak <6314611+ProjectInitiative@users.noreply.github.com>
2026-01-17 10:48:40 -05:00
Tom Pantelis 028400610b Generate CRD and RBAC yaml templates from submariner-operator
The submariner-operator repo is the source of truth for the
CRD and RBAC resource yaml used by subctl and the ACM add-on so
we should use it for the helm charts as well. This will avoid
having to duplicate changes from the submariner-operator repo.
All the yaml is assembled in the pkg/embeddedyamls/yamls.go file
in submariner-operator so download and extract the yaml into
template files in the chart templates directories which can then
be included in other manifest files.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2025-01-21 22:59:29 -05:00
Tom Pantelis 967541e5ec Add submariner-operator RBAC create permission for events
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2025-01-08 12:57:59 -05:00
Tom Pantelis 0e2e31ae73 Enable leader election in the operator
The operator no longer runs leader-for-life election so enable
leader-with-lease via the CLI arg in the pod spec.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-12-13 01:08:54 -05:00
Tom Pantelis 5cf3f48cd8 Add clusterset IP CIDR configuration to the operator chart
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-09-11 07:54:32 -04:00
Tom Pantelis 6c093ebca2 Adjust globalnet RBAC permissions
Globalnet now annotates Gateways instead of nodes.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-06-03 15:03:23 -04:00
Tom Pantelis 301db56c91 Remove node update RBAC permission for route agent
Re: https://github.com/submariner-io/submariner/pull/3010

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-21 17:56:46 -04:00
Thomas PantelisandGitHub eb336236f3 Add RBAC access to finalizers for the operator role (#515)
On Openshift, the operator failed with error

"\"submariner-gateway\" is forbidden: cannot set blockOwnerDeletion
if an ownerReference refers to a resource you can't set finalizers on"

Openshift enables OwnerReferencesPermissionEnforcement, so
in order to set blockOwnerDeletion for an object, the user needs
update permission for the finalizers subresource of the referenced
owner. In this case the owner is the Submariner object.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-21 12:28:13 +03:00
Tom PantelisandStephen Kitt 1b251e84cf Reduce lighthouse-agent RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt f037f15dc0 Reduce lighthouse-coredns RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt b4720fad02 Reduce submariner-globalnet RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt 6f632767b3 Reduce submariner-routeagent RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt ab6d482b9e Reduce submariner-gateway RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt 01a4312a89 Reduce submariner-operator RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom Pantelis f80e71950e Add lease RBAC perm to submariner-globalnet role
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2023-11-06 12:54:03 -05:00
Automated ReleaseandThomas Pantelis fb1359b33f Update globalnet ClusterRole permissions
Signed-off-by: Automated Release <release@submariner.io>
2023-05-22 09:11:20 -04:00
Tom PantelisandStephen Kitt 5e0b4e62c0 Add LH coredns permission to access Submariner resource
Addresses
https://github.com/submariner-io/lighthouse/issues/936#issuecomment-1416197295

Also removed the permissions for the obsolete lighthouse.submariner.io
group.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2023-03-23 14:03:25 +01:00
Stephen KittandThomas Pantelis c0ce6ae239 Fix the case of configMapName
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2023-03-06 15:41:36 -05:00
NegashandStephen Kitt 0f76612b97 Add daemonsets to ClusterRole for check CNI
Signed-off-by: Negash <i@negash.ru>
2023-03-03 10:57:15 +01:00
Tom PantelisandDaniel Farrell d276eb2be8 Default submariner.images.tag to Chart.AppVersion
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2022-11-07 12:40:43 -05:00
Tom PantelisandDaniel Farrell d80c6ea26c Remove unused gateway template value
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2022-11-07 12:40:43 -05:00
Mike KolesnikandDaniel Farrell 045cc7f4f7 Add support for load balancer
Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2022-09-22 14:25:03 -04:00
Mike Kolesnik 5be04f2906 Adjust LH image overrides to use component names
Operator expects the component name, use it in the Submariner CR and not
the image name.

Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2022-09-06 14:25:30 +03:00
Mike KolesnikandThomas Pantelis 01599cbb65 Add support for image overrides
Add support to override specific images (already supported by
submariner) to the helm chart.

Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2022-08-22 08:07:25 -04:00
Thomas PantelisandGitHub d667fc2546 Add submariner-gateway role permissions for leases (#247)
This is needed for leader election resource locking in K8s 0.24.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2022-07-28 07:21:29 +03:00
Stephen KittandThomas Pantelis c605528741 Create secrets along with SAs
Starting with Kubernetes 1.24, secrets are no longer automatically
created for SAs. This adds secrets to the relevant templates; creating
secrets in this way is supported in all Kubernetes versions.

This also enables testing with 1.24 in CI, to make sure that the fix
actually works.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2022-07-07 11:54:23 -04:00
Sridhar GaddamandThomas Pantelis bf2c41115b Configure RBAC for Globalnet pods on OCP deployments
Globalnet controller now uses internal services with external-ips
to support exported services. On OCP Clusters, we require an explicit
RBAC to create services with external-ips, this PR includes the
necessary RBAC for Globalnet pods.

Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>
2022-01-13 12:35:40 -05:00
NegashandGitHub 9ba0123e72 Fix coreDNSCustomConfig values
Signed-off-by: Negash <i@negash.ru>
2022-01-05 12:47:35 +00:00
Sridhar GaddamandThomas Pantelis b3a5e40a5a Globalnet include ClusterRole for services
As part of Globalnet enhancement where kubeproxy dependency
is removed, the Globalnet Pod will now create internal
services for every exported service in the respective
namespace where the original service resides. This PR
adds the necessary clusterRole to allow Globalnet pod
to create/delete such internal services.

Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
2022-01-04 07:48:50 -05:00
Stephen KittandThomas Pantelis 9358c86eb5 Add roles and privileges required for monitoring
This replicates the RBAC changes applied to the operator in
https://github.com/submariner-io/submariner-operator/pull/1416

Fixes: #191
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-12-16 07:59:53 -05:00
Masaki KimuraandDaniel Farrell 5da180d44f Allow submariner-globalnet role to handle endpoints
Signed-off-by: Masaki Kimura <masaki.kimura@hitachivantara.com>
2021-12-14 21:44:22 -05:00
Stephen KittandThomas Pantelis 42a2af008a Pass the broker.insecure flag to the CR
Fixes: #185
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-12-06 11:07:45 -05:00
Vishal ThaparandDaniel Farrell 220ccc34f5 Fix connectionHealthCheck
connectionHealthCheck in submariner CR is a nested field
but is being added as a variable. This means it is ignored
and the field isn't set correctly in gateway pods.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-10-27 12:36:06 -04:00
Victor Godoy HernándezandThomas Pantelis 9ee272bec8 Update Readme.md
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-25 09:12:47 -04:00
Victor Godoy HernándezandThomas Pantelis 9347e8f345 Add ceIPSecForceUDPEncaps & coreDNSCustomConfig variables
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-25 09:12:47 -04:00
Victor Godoy HernándezandThomas Pantelis 916f255461 Add enable/disable connectionHealthCheck
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-25 09:12:47 -04:00
Vishal ThaparandStephen Kitt 6b7fed425a Add endpontslices/restricted to lighthouse-agent
Fixes: submariner-io/lighthouse#627

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-10-19 16:22:31 +02:00
Vishal ThaparandThomas Pantelis f757a66958 Allow lighthouse-agent access to ingressips
`lighthouse-agent` `ClusterRole` requires access to `globalingressips`
for Globalnetv2 in Lighthouse.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-07-07 10:04:32 -04:00
Vishal ThaparandMiguel Angel Ajo Pelayo ac4910d36b Fix globalnetv2 ClusterRole
Globalnetv2 requires `globalnet` `ClusterRole` for Egress/IngressIPs
but those were added as `globalnet` `Role` instead. This change
moves the permissions from `Role` to `ClusterRole`

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-07-07 13:33:54 +02:00
Sridhar GaddamandThomas Pantelis cff6e76f98 Add roles to access new Globalnet 2.0 objects
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>
2021-06-28 11:55:55 -04:00
Steve MattarandDaniel Farrell 12c8e9b3ff fix(rbac): add missing cluster roles to submariner-operator
Signed-off-by: Steve Mattar <smattar@redhat.com>
2021-05-24 14:40:13 -05:00
Steve MattarandSteve Mattar 64d7c11506 refactor: globalnet should be under the broker
Signed-off-by: Steve Mattar <smattar@redhat.com>
2021-03-10 16:41:48 +02:00
Steve MattarandSteve Mattar 86ba2b8857 feat: support cableDriver value default is libreswan
Closes #33

Signed-off-by: Steve Mattar <smattar@redhat.com>
2021-03-04 19:46:28 +02:00
Steve MattarandGitHub 4a59718a34 refactor: rename submariner-engine to submariner-gateway (#122)
Signed-off-by: Steve Mattar <smattar@redhat.com>
2021-03-02 08:57:52 -05:00
Miguel Angel AjoandThomas Pantelis f3787856f6 Add globalCidr mappings to the submariner template
also includes the questions.yaml which is UI.

Signed-off-by: Miguel Angel Ajo <majopela@redhat.com>
2021-02-24 08:36:47 -05:00
Steve MattarandGitHub 7f2d832e6f fix(rbac): sa and rbac definitions (#117)
Sync the SA and RBAC definitions with what we have in submariner-operator.

Signed-off-by: Steve Mattar <smattar@redhat.com>
2021-02-23 16:08:55 +01:00
Stephen KittandThomas Pantelis 8a670ad49d Set the serviceDiscoveryEnabled flag
This allows the e2e tests to complete successfully.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2020-12-17 08:21:41 -05:00
Stephen KittandMiguel Angel Ajo Pelayo 5906cfb3dc Switch to Helm v3
This allows us to deploy v1 CRDs such as the upstream MCS API CRDs.

Fixes: #47
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2020-11-13 12:31:30 +01:00
Stephen KittandMiguel Angel Ajo Pelayo 1ae567356b Fix the globalnet SAs
SA names can't include ':', revert to '-' as used in the old charts.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2020-11-12 12:04:20 +01:00