The submainer-engine now access the node object as part
of golbalnet-healthcheck support and the required roles are
added
Signed-off-by: Aswin Surayanarayanan <asuryana@redhat.com>
In the new event framework we use node listeners to support certain use-cases.
Currently in helm, routeagent does not have that role, so e2e tests are failing.
This PR enables it.
Related to: https://github.com/submariner-io/submariner/issues/858
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>
This installs the `multicluster.x-k8s.io` CRDs and roles for them
Fixes:submariner-io/lighthouse#336
Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
* Add clusterrole to give lighthouse serviceaccount access to endpoints and
endpointslices
* Add role to give broker serviceaccont access to endpoint slices
Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
Adds following permissions to lighthouse clusterrole
for `gateways.submariner.io`
- get
- list
- watch
This allows lighthouse to track changes to gateway status and know which
clusters are connected.
Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
As part of supporting connectivity from HostNetwork to remoteClusters, globalnet
controller requires the CNIInterfaceIP on each node. This PR adds the necessary
clusterRoles for the route-agent daemonSet which will annotate the node with the
CNIInterfaceIP on that respective node.
Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
As part of supporting connectivity from HostNetwork to remoteClusters, globalnet
controller annotates a node with globalIP. This PR adds the necessary roles for
globalnetController.
Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
Submariner-route-agent daemonset pod needs to query the list of other sm-route-agent
pods in the cluster for their hostIP addresses. The ipaddress will be used as remote
VxLAN Vtep IPs. Currently, sm-route-agent pod does not have the necessary privileges
to list the pods in the submariner namespace of local cluster. This patch addresses
this issue by adding the necessary role.
Error seen:
Failed to list *v1.Pod: pods is forbidden: User
"system:serviceaccount:submariner:submariner-routeagent" cannot list resource "pods"
in API group "" in the namespace "submariner"