Lukas Spinler and Thomas Pantelis
c28d8eb1d4
feat(operator): added ceIPSecPSKSecret support
...
Signed-off-by: Lukas Spinler <lukas.spinler@gl-systemhaus.de >
2026-02-04 08:25:07 -05:00
Kyle Petryszak and Thomas Pantelis
8e92d2c3e7
(feat): add conditional support for GitOps utilizing CRD spec.brokerK8sSecret
...
Signed-off-by: Kyle Petryszak <6314611+ProjectInitiative@users.noreply.github.com >
2026-01-17 10:48:40 -05:00
Tom Pantelis
028400610b
Generate CRD and RBAC yaml templates from submariner-operator
...
The submariner-operator repo is the source of truth for the
CRD and RBAC resource yaml used by subctl and the ACM add-on so
we should use it for the helm charts as well. This will avoid
having to duplicate changes from the submariner-operator repo.
All the yaml is assembled in the pkg/embeddedyamls/yamls.go file
in submariner-operator so download and extract the yaml into
template files in the chart templates directories which can then
be included in other manifest files.
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2025-01-21 22:59:29 -05:00
Tom Pantelis
967541e5ec
Add submariner-operator RBAC create permission for events
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2025-01-08 12:57:59 -05:00
Tom Pantelis
0e2e31ae73
Enable leader election in the operator
...
The operator no longer runs leader-for-life election so enable
leader-with-lease via the CLI arg in the pod spec.
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-12-13 01:08:54 -05:00
Tom Pantelis
5cf3f48cd8
Add clusterset IP CIDR configuration to the operator chart
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-09-11 07:54:32 -04:00
Tom Pantelis
6c093ebca2
Adjust globalnet RBAC permissions
...
Globalnet now annotates Gateways instead of nodes.
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-06-03 15:03:23 -04:00
Tom Pantelis
301db56c91
Remove node update RBAC permission for route agent
...
Re: https://github.com/submariner-io/submariner/pull/3010
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-21 17:56:46 -04:00
Thomas Pantelis and GitHub
eb336236f3
Add RBAC access to finalizers for the operator role ( #515 )
...
On Openshift, the operator failed with error
"\"submariner-gateway\" is forbidden: cannot set blockOwnerDeletion
if an ownerReference refers to a resource you can't set finalizers on"
Openshift enables OwnerReferencesPermissionEnforcement, so
in order to set blockOwnerDeletion for an object, the user needs
update permission for the finalizers subresource of the referenced
owner. In this case the owner is the Submariner object.
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-21 12:28:13 +03:00
Tom Pantelis and Stephen Kitt
1b251e84cf
Reduce lighthouse-agent RBAC permissions
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-06 17:46:32 +02:00
Tom Pantelis and Stephen Kitt
f037f15dc0
Reduce lighthouse-coredns RBAC permissions
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-06 17:46:32 +02:00
Tom Pantelis and Stephen Kitt
b4720fad02
Reduce submariner-globalnet RBAC permissions
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-06 17:46:32 +02:00
Tom Pantelis and Stephen Kitt
6f632767b3
Reduce submariner-routeagent RBAC permissions
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-06 17:46:32 +02:00
Tom Pantelis and Stephen Kitt
ab6d482b9e
Reduce submariner-gateway RBAC permissions
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-06 17:46:32 +02:00
Tom Pantelis and Stephen Kitt
01a4312a89
Reduce submariner-operator RBAC permissions
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2024-05-06 17:46:32 +02:00
Tom Pantelis
f80e71950e
Add lease RBAC perm to submariner-globalnet role
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2023-11-06 12:54:03 -05:00
Automated Release and Thomas Pantelis
fb1359b33f
Update globalnet ClusterRole permissions
...
Signed-off-by: Automated Release <release@submariner.io >
2023-05-22 09:11:20 -04:00
Tom Pantelis and Stephen Kitt
5e0b4e62c0
Add LH coredns permission to access Submariner resource
...
Addresses
https://github.com/submariner-io/lighthouse/issues/936#issuecomment-1416197295
Also removed the permissions for the obsolete lighthouse.submariner.io
group.
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2023-03-23 14:03:25 +01:00
Stephen Kitt and Thomas Pantelis
c0ce6ae239
Fix the case of configMapName
...
Signed-off-by: Stephen Kitt <skitt@redhat.com >
2023-03-06 15:41:36 -05:00
Negash and Stephen Kitt
0f76612b97
Add daemonsets to ClusterRole for check CNI
...
Signed-off-by: Negash <i@negash.ru >
2023-03-03 10:57:15 +01:00
Tom Pantelis and Daniel Farrell
d276eb2be8
Default submariner.images.tag to Chart.AppVersion
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2022-11-07 12:40:43 -05:00
Tom Pantelis and Daniel Farrell
d80c6ea26c
Remove unused gateway template value
...
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2022-11-07 12:40:43 -05:00
Mike Kolesnik and Daniel Farrell
045cc7f4f7
Add support for load balancer
...
Signed-off-by: Mike Kolesnik <mkolesni@redhat.com >
2022-09-22 14:25:03 -04:00
Mike Kolesnik
5be04f2906
Adjust LH image overrides to use component names
...
Operator expects the component name, use it in the Submariner CR and not
the image name.
Signed-off-by: Mike Kolesnik <mkolesni@redhat.com >
2022-09-06 14:25:30 +03:00
Mike Kolesnik and Thomas Pantelis
01599cbb65
Add support for image overrides
...
Add support to override specific images (already supported by
submariner) to the helm chart.
Signed-off-by: Mike Kolesnik <mkolesni@redhat.com >
2022-08-22 08:07:25 -04:00
Thomas Pantelis and GitHub
d667fc2546
Add submariner-gateway role permissions for leases ( #247 )
...
This is needed for leader election resource locking in K8s 0.24.
Signed-off-by: Tom Pantelis <tompantelis@gmail.com >
2022-07-28 07:21:29 +03:00
Stephen Kitt and Thomas Pantelis
c605528741
Create secrets along with SAs
...
Starting with Kubernetes 1.24, secrets are no longer automatically
created for SAs. This adds secrets to the relevant templates; creating
secrets in this way is supported in all Kubernetes versions.
This also enables testing with 1.24 in CI, to make sure that the fix
actually works.
Signed-off-by: Stephen Kitt <skitt@redhat.com >
2022-07-07 11:54:23 -04:00
Sridhar Gaddam and Thomas Pantelis
bf2c41115b
Configure RBAC for Globalnet pods on OCP deployments
...
Globalnet controller now uses internal services with external-ips
to support exported services. On OCP Clusters, we require an explicit
RBAC to create services with external-ips, this PR includes the
necessary RBAC for Globalnet pods.
Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com >
2022-01-13 12:35:40 -05:00
Negash and GitHub
9ba0123e72
Fix coreDNSCustomConfig values
...
Signed-off-by: Negash <i@negash.ru >
2022-01-05 12:47:35 +00:00
Sridhar Gaddam and Thomas Pantelis
b3a5e40a5a
Globalnet include ClusterRole for services
...
As part of Globalnet enhancement where kubeproxy dependency
is removed, the Globalnet Pod will now create internal
services for every exported service in the respective
namespace where the original service resides. This PR
adds the necessary clusterRole to allow Globalnet pod
to create/delete such internal services.
Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com >
2022-01-04 07:48:50 -05:00
Stephen Kitt and Thomas Pantelis
9358c86eb5
Add roles and privileges required for monitoring
...
This replicates the RBAC changes applied to the operator in
https://github.com/submariner-io/submariner-operator/pull/1416
Fixes : #191
Signed-off-by: Stephen Kitt <skitt@redhat.com >
2021-12-16 07:59:53 -05:00
Masaki Kimura and Daniel Farrell
5da180d44f
Allow submariner-globalnet role to handle endpoints
...
Signed-off-by: Masaki Kimura <masaki.kimura@hitachivantara.com >
2021-12-14 21:44:22 -05:00
Stephen Kitt and Thomas Pantelis
42a2af008a
Pass the broker.insecure flag to the CR
...
Fixes : #185
Signed-off-by: Stephen Kitt <skitt@redhat.com >
2021-12-06 11:07:45 -05:00
Vishal Thapar and Daniel Farrell
220ccc34f5
Fix connectionHealthCheck
...
connectionHealthCheck in submariner CR is a nested field
but is being added as a variable. This means it is ignored
and the field isn't set correctly in gateway pods.
Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com >
2021-10-27 12:36:06 -04:00
Victor Godoy Hernández and Thomas Pantelis
9ee272bec8
Update Readme.md
...
Signed-off-by: Victor Godoy Hernández <vigohe@gmail.com >
2021-10-25 09:12:47 -04:00
Victor Godoy Hernández and Thomas Pantelis
9347e8f345
Add ceIPSecForceUDPEncaps & coreDNSCustomConfig variables
...
Signed-off-by: Victor Godoy Hernández <vigohe@gmail.com >
2021-10-25 09:12:47 -04:00
Victor Godoy Hernández and Thomas Pantelis
916f255461
Add enable/disable connectionHealthCheck
...
Signed-off-by: Victor Godoy Hernández <vigohe@gmail.com >
2021-10-25 09:12:47 -04:00
Vishal Thapar and Stephen Kitt
6b7fed425a
Add endpontslices/restricted to lighthouse-agent
...
Fixes : submariner-io/lighthouse#627
Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com >
2021-10-19 16:22:31 +02:00
Vishal Thapar and Thomas Pantelis
f757a66958
Allow lighthouse-agent access to ingressips
...
`lighthouse-agent` `ClusterRole` requires access to `globalingressips`
for Globalnetv2 in Lighthouse.
Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com >
2021-07-07 10:04:32 -04:00
Vishal Thapar and Miguel Angel Ajo Pelayo
ac4910d36b
Fix globalnetv2 ClusterRole
...
Globalnetv2 requires `globalnet` `ClusterRole` for Egress/IngressIPs
but those were added as `globalnet` `Role` instead. This change
moves the permissions from `Role` to `ClusterRole`
Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com >
2021-07-07 13:33:54 +02:00
Sridhar Gaddam and Thomas Pantelis
cff6e76f98
Add roles to access new Globalnet 2.0 objects
...
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com >
2021-06-28 11:55:55 -04:00
Steve Mattar and Daniel Farrell
12c8e9b3ff
fix(rbac): add missing cluster roles to submariner-operator
...
Signed-off-by: Steve Mattar <smattar@redhat.com >
2021-05-24 14:40:13 -05:00
Steve Mattar and Steve Mattar
64d7c11506
refactor: globalnet should be under the broker
...
Signed-off-by: Steve Mattar <smattar@redhat.com >
2021-03-10 16:41:48 +02:00
Steve Mattar and Steve Mattar
86ba2b8857
feat: support cableDriver value default is libreswan
...
Closes #33
Signed-off-by: Steve Mattar <smattar@redhat.com >
2021-03-04 19:46:28 +02:00
Steve Mattar and GitHub
4a59718a34
refactor: rename submariner-engine to submariner-gateway ( #122 )
...
Signed-off-by: Steve Mattar <smattar@redhat.com >
2021-03-02 08:57:52 -05:00
Miguel Angel Ajo and Thomas Pantelis
f3787856f6
Add globalCidr mappings to the submariner template
...
also includes the questions.yaml which is UI.
Signed-off-by: Miguel Angel Ajo <majopela@redhat.com >
2021-02-24 08:36:47 -05:00
Steve Mattar and GitHub
7f2d832e6f
fix(rbac): sa and rbac definitions ( #117 )
...
Sync the SA and RBAC definitions with what we have in submariner-operator.
Signed-off-by: Steve Mattar <smattar@redhat.com >
2021-02-23 16:08:55 +01:00
Stephen Kitt and Thomas Pantelis
8a670ad49d
Set the serviceDiscoveryEnabled flag
...
This allows the e2e tests to complete successfully.
Signed-off-by: Stephen Kitt <skitt@redhat.com >
2020-12-17 08:21:41 -05:00
Stephen Kitt and Miguel Angel Ajo Pelayo
5906cfb3dc
Switch to Helm v3
...
This allows us to deploy v1 CRDs such as the upstream MCS API CRDs.
Fixes : #47
Signed-off-by: Stephen Kitt <skitt@redhat.com >
2020-11-13 12:31:30 +01:00
Stephen Kitt and Miguel Angel Ajo Pelayo
1ae567356b
Fix the globalnet SAs
...
SA names can't include ':', revert to '-' as used in the old charts.
Signed-off-by: Stephen Kitt <skitt@redhat.com >
2020-11-12 12:04:20 +01:00