mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-20 22:40:34 +00:00
Compare commits
226
Commits
release-0.11
...
devel
@@ -0,0 +1,74 @@
|
|||||||
|
---
|
||||||
|
version: 2
|
||||||
|
updates:
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.18"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.19"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.20"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.21"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.22"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.23"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.24"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
@@ -1,57 +0,0 @@
|
|||||||
---
|
|
||||||
# Configuration for probot-stale - https://github.com/probot/stale
|
|
||||||
|
|
||||||
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
|
|
||||||
daysUntilStale: 120
|
|
||||||
|
|
||||||
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
|
|
||||||
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
|
|
||||||
daysUntilClose: 7
|
|
||||||
|
|
||||||
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
|
|
||||||
onlyLabels: []
|
|
||||||
|
|
||||||
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
|
|
||||||
exemptLabels:
|
|
||||||
- security
|
|
||||||
- confirmed
|
|
||||||
|
|
||||||
# Set to true to ignore issues in a project (defaults to false)
|
|
||||||
exemptProjects: false
|
|
||||||
|
|
||||||
# Set to true to ignore issues in a milestone (defaults to false)
|
|
||||||
exemptMilestones: false
|
|
||||||
|
|
||||||
# Set to true to ignore issues with an assignee (defaults to false)
|
|
||||||
exemptAssignees: false
|
|
||||||
|
|
||||||
# Label to use when marking as stale
|
|
||||||
staleLabel: wontfix
|
|
||||||
|
|
||||||
# Comment to post when marking as stale. Set to `false` to disable
|
|
||||||
markComment: >
|
|
||||||
This issue has been automatically marked as stale because it has not had
|
|
||||||
activity for 60 days. It will be closed if no further activity occurs.
|
|
||||||
Please make a comment if this issue/pr is still valid. Thank you
|
|
||||||
for your contributions.
|
|
||||||
|
|
||||||
# Comment to post when removing the stale label.
|
|
||||||
# unmarkComment: >
|
|
||||||
# Your comment here.
|
|
||||||
|
|
||||||
# Comment to post when closing a stale Issue or Pull Request.
|
|
||||||
# closeComment: >
|
|
||||||
# Your comment here.
|
|
||||||
|
|
||||||
# Limit the number of actions per hour, from 1-30. Default is 30
|
|
||||||
limitPerRun: 30
|
|
||||||
|
|
||||||
# Limit to only `issues` or `pulls`
|
|
||||||
# only: issues
|
|
||||||
|
|
||||||
pulls:
|
|
||||||
daysUntilStale: 30
|
|
||||||
markComment: >
|
|
||||||
This pull request has been automatically marked as stale because it has not had
|
|
||||||
recent activity. It will be closed if no further activity occurs. Thank you
|
|
||||||
for your contributions.
|
|
||||||
@@ -4,9 +4,11 @@ name: Branch Checks
|
|||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
target_devel:
|
target_branch:
|
||||||
name: PR targets devel
|
name: PR targets branch
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check that the PR targets devel
|
- name: Check that the PR targets devel
|
||||||
|
|||||||
@@ -2,22 +2,15 @@
|
|||||||
name: PR Dependencies
|
name: PR Dependencies
|
||||||
|
|
||||||
on:
|
on:
|
||||||
issues:
|
|
||||||
types:
|
|
||||||
- opened
|
|
||||||
- edited
|
|
||||||
- closed
|
|
||||||
- reopened
|
|
||||||
- synchronize
|
|
||||||
pull_request_target:
|
pull_request_target:
|
||||||
types:
|
types:
|
||||||
- opened
|
- opened
|
||||||
- edited
|
- edited
|
||||||
- closed
|
|
||||||
- reopened
|
- reopened
|
||||||
- synchronize
|
- synchronize
|
||||||
schedule:
|
|
||||||
- cron: '0 0/6 * * *' # every 6 hours
|
permissions:
|
||||||
|
pull-requests: write
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
check:
|
check:
|
||||||
@@ -25,15 +18,7 @@ jobs:
|
|||||||
if: github.repository_owner == 'submariner-io'
|
if: github.repository_owner == 'submariner-io'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: z0al/dependent-issues@70a1b2d4ee1cdc743af33498bd0204123953a887
|
- uses: depends-on/depends-on-action@c7ac9a6932a7069e83aef80c202d9f60f91e43fd # v0.17.0
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
with:
|
with:
|
||||||
# The label to use to mark dependent issues
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
label: dependent
|
check-unmerged-pr: true
|
||||||
|
|
||||||
# Enable checking for dependencies in issues.
|
|
||||||
check_issues: on
|
|
||||||
|
|
||||||
# A comma-separated list of keywords to mark dependency.
|
|
||||||
keywords: depends on, Depends on
|
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ on:
|
|||||||
pull_request:
|
pull_request:
|
||||||
types: [labeled, opened, synchronize, reopened]
|
types: [labeled, opened, synchronize, reopened]
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
e2e:
|
e2e:
|
||||||
name: E2E
|
name: E2E
|
||||||
@@ -16,15 +18,15 @@ jobs:
|
|||||||
matrix:
|
matrix:
|
||||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||||
globalnet: ['', 'globalnet']
|
globalnet: ['', 'globalnet']
|
||||||
k8s_version: ['1.17']
|
# Run most tests against the latest K8s version
|
||||||
|
k8s_version: ['k8s-latest']
|
||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
include:
|
include:
|
||||||
- k8s_version: '1.18'
|
# Bottom of supported K8s version range
|
||||||
- k8s_version: '1.19'
|
- k8s_version: 'k8s-oldest-supported'
|
||||||
- k8s_version: '1.20'
|
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ name: End to End Default
|
|||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
e2e:
|
e2e:
|
||||||
name: E2E
|
name: E2E
|
||||||
@@ -11,7 +13,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ on:
|
|||||||
schedule:
|
schedule:
|
||||||
- cron: "0 0 * * *"
|
- cron: "0 0 * * *"
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
e2e:
|
e2e:
|
||||||
name: E2E
|
name: E2E
|
||||||
@@ -19,7 +21,7 @@ jobs:
|
|||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ name: Linting
|
|||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
apply-suggestions-commits:
|
apply-suggestions-commits:
|
||||||
name: 'No "Apply suggestions from code review" Commits'
|
name: 'No "Apply suggestions from code review" Commits'
|
||||||
@@ -11,37 +13,48 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Get PR commits
|
- name: Get PR commits
|
||||||
id: 'get-pr-commits'
|
id: 'get-pr-commits'
|
||||||
uses: tim-actions/get-pr-commits@55b867b9b28954e6f5c1a0fe2f729dc926c306d0
|
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d
|
||||||
with:
|
with:
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: 'Verify no "Apply suggestions from code review" commits'
|
- name: 'Verify no "Apply suggestions from code review" commits'
|
||||||
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
|
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
||||||
with:
|
with:
|
||||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||||
pattern: '^(?!.*(apply suggestions from code review))'
|
pattern: '^(?!.*(apply suggestions from code review))'
|
||||||
flags: 'i'
|
flags: 'i'
|
||||||
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
||||||
|
|
||||||
|
- name: 'Verify no "fixup!" commits'
|
||||||
|
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
||||||
|
with:
|
||||||
|
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||||
|
pattern: '^(?!fixup!)'
|
||||||
|
flags: 'i'
|
||||||
|
error: 'Fixup commits should be squashed into the commits under review'
|
||||||
|
|
||||||
chart-testing:
|
chart-testing:
|
||||||
name: Helm Chart Linting
|
name: Helm Chart Linting
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Set up Helm
|
- name: Set up Helm
|
||||||
uses: azure/setup-helm@18bc76811624f360dbd7f18c2d4ecb32c7b87bab
|
uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310
|
||||||
with:
|
with:
|
||||||
version: v3.6.0
|
version: v3.6.0
|
||||||
|
|
||||||
- name: Set up Python
|
- name: Set up Python
|
||||||
uses: actions/setup-python@dc73133d4da04e56a135ae2246682783cc7c7cb6
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.13.x'
|
||||||
|
|
||||||
- name: Set up helm/chart-testing
|
- name: Set up helm/chart-testing
|
||||||
uses: helm/chart-testing-action@5f16c27cf7a4fa9c776ff73734df3909b2b65127
|
uses: helm/chart-testing-action@6ec842c01de15ebb84c8627d2744a0c2f2755c9f
|
||||||
|
|
||||||
|
- name: Set up local helm repo
|
||||||
|
run: make local-helm-repo
|
||||||
|
|
||||||
- name: Run helm/chart-testing (lint)
|
- name: Run helm/chart-testing (lint)
|
||||||
run: ct lint --config ct.yaml
|
run: ct lint --config ct.yaml
|
||||||
@@ -51,7 +64,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- name: Run gitlint
|
- name: Run gitlint
|
||||||
@@ -62,7 +75,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run helm-docs and verify docs are up-to-date
|
- name: Run helm-docs and verify docs are up-to-date
|
||||||
run: make helm-docs
|
run: make helm-docs
|
||||||
@@ -72,10 +85,10 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
|
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
check-modified-files-only: "yes"
|
check-modified-files-only: "yes"
|
||||||
@@ -86,7 +99,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
- name: Run markdownlint
|
- name: Run markdownlint
|
||||||
run: make markdownlint
|
run: make markdownlint
|
||||||
|
|
||||||
@@ -95,10 +108,6 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
- name: Run yamllint
|
- name: Run yamllint
|
||||||
uses: ibiqlik/action-yamllint@ed2b6e911569708ed121c14b87d513860a7e36a7
|
run: make yamllint
|
||||||
with:
|
|
||||||
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
|
|
||||||
config_file: .yamllint.yml
|
|
||||||
strict: true
|
|
||||||
|
|||||||
@@ -5,23 +5,27 @@ on:
|
|||||||
schedule:
|
schedule:
|
||||||
- cron: "0 0 * * 0"
|
- cron: "0 0 * * 0"
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
markdown-link-check-periodic:
|
markdown-link-check-periodic:
|
||||||
name: Markdown Links (all files)
|
name: Markdown Links (all files)
|
||||||
if: github.repository_owner == 'submariner-io'
|
if: github.repository_owner == 'submariner-io'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
|
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
|
|
||||||
- name: Raise an Issue to report broken links
|
- name: Raise an Issue to report broken links
|
||||||
if: ${{ failure() }}
|
if: ${{ failure() }}
|
||||||
uses: peter-evans/create-issue-from-file@97e6f902a416aac38834e23fa52e166aad0437d2
|
uses: peter-evans/create-issue-from-file@fca9117c27cdc29c6c4db3b86c48e4115a786710
|
||||||
with:
|
with:
|
||||||
title: Broken link detected by CI
|
title: Broken link detected by CI
|
||||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||||
|
|||||||
@@ -6,6 +6,9 @@ on:
|
|||||||
branches:
|
branches:
|
||||||
- devel
|
- devel
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
release:
|
release:
|
||||||
name: Release
|
name: Release
|
||||||
@@ -13,7 +16,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,32 @@
|
|||||||
|
---
|
||||||
|
name: Stale
|
||||||
|
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: "0 0 * * *"
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
stale:
|
||||||
|
name: Close Stale Issues and PRs
|
||||||
|
if: github.repository_owner == 'submariner-io'
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
|
pull-requests: write
|
||||||
|
steps:
|
||||||
|
- uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93
|
||||||
|
with:
|
||||||
|
days-before-issue-stale: 120
|
||||||
|
days-before-pr-stale: 14
|
||||||
|
exempt-issue-labels: 'confirmed,security'
|
||||||
|
exempt-pr-labels: 'confirmed,security'
|
||||||
|
stale-issue-label: 'stale'
|
||||||
|
stale-issue-message: |
|
||||||
|
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||||
|
activity occurs. Thank you for your contributions.
|
||||||
|
stale-pr-label: 'stale'
|
||||||
|
stale-pr-message: |
|
||||||
|
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||||
|
activity occurs. Thank you for your contributions.
|
||||||
+10
@@ -3,3 +3,13 @@
|
|||||||
.shflags
|
.shflags
|
||||||
*.tgz
|
*.tgz
|
||||||
Makefile.dapper
|
Makefile.dapper
|
||||||
|
Makefile.shipyard
|
||||||
|
Dockerfile.*
|
||||||
|
helm_repo
|
||||||
|
yamls/go.mod
|
||||||
|
yamls/go.sum
|
||||||
|
yamls/vendor
|
||||||
|
submariner-k8s-broker/crds/crd.yaml
|
||||||
|
submariner-k8s-broker/templates/_role.tpl
|
||||||
|
submariner-operator/crds/crd.yaml
|
||||||
|
submariner-operator/templates/*-rbac.yaml
|
||||||
|
|||||||
@@ -1,5 +1,8 @@
|
|||||||
{
|
{
|
||||||
"ignorePatterns": [
|
"ignorePatterns": [
|
||||||
|
{
|
||||||
|
"pattern": "^https://docs.github.com"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -2,6 +2,9 @@
|
|||||||
# Breaks reusing MD snippets extracted to files
|
# Breaks reusing MD snippets extracted to files
|
||||||
first-line-heading: false
|
first-line-heading: false
|
||||||
|
|
||||||
|
# Accept any consistent table column style
|
||||||
|
table-column-style: false
|
||||||
|
|
||||||
# Set maximum line Length to 140c to match Go linting
|
# Set maximum line Length to 140c to match Go linting
|
||||||
line-length:
|
line-length:
|
||||||
line_length: 140
|
line_length: 140
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
cni: ovn
|
||||||
|
submariner: true
|
||||||
|
nodes: control-plane
|
||||||
|
clusters:
|
||||||
|
cluster1:
|
||||||
|
cluster2:
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
submariner: true
|
||||||
|
nodes: control-plane
|
||||||
|
clusters:
|
||||||
|
cluster1:
|
||||||
|
cluster2:
|
||||||
@@ -1,3 +1,4 @@
|
|||||||
|
---
|
||||||
label-approved:
|
label-approved:
|
||||||
approvals: 2
|
approvals: 2
|
||||||
label: ready-to-test
|
label: ready-to-test
|
||||||
|
|||||||
+11
-11
@@ -1,15 +1,15 @@
|
|||||||
---
|
---
|
||||||
extends: default
|
extends: default
|
||||||
|
|
||||||
rules:
|
rules:
|
||||||
comments: disable
|
|
||||||
comments-indentation: disable
|
|
||||||
line-length:
|
line-length:
|
||||||
max: 150
|
max: 140
|
||||||
braces:
|
# Allow standard GHA syntax for "on: *"
|
||||||
min-spaces-inside: 0
|
truthy:
|
||||||
max-spaces-inside: 0
|
ignore: '.github/workflows/*.yml'
|
||||||
brackets:
|
|
||||||
min-spaces-inside: 0
|
ignore: |
|
||||||
max-spaces-inside: 0
|
/submariner-k8s-broker/crds
|
||||||
indentation:
|
/submariner-operator/crds
|
||||||
indent-sequences: consistent
|
/submariner-k8s-broker/templates
|
||||||
|
/submariner-operator/templates
|
||||||
|
|||||||
+4
-1
@@ -1 +1,4 @@
|
|||||||
* @mangelajo @Oats87 @skitt @sridhargaddam @tpantelis
|
# Auto-generated, do not edit; see CODEOWNERS.in
|
||||||
|
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||||
|
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||||
|
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
@aswinsuryan Makefile
|
||||||
|
@dfarrell07 *.md Makefile
|
||||||
|
@maayanf24 Makefile
|
||||||
|
@Oats87 *
|
||||||
|
@skitt *
|
||||||
|
@sridhargaddam *
|
||||||
|
@tpantelis *
|
||||||
|
@vthapar *
|
||||||
|
@yboaron Makefile
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
ARG BASE_BRANCH
|
|
||||||
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH}
|
|
||||||
|
|
||||||
ARG DAPPER_HOST_ARCH
|
|
||||||
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
|
|
||||||
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
|
|
||||||
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
|
|
||||||
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
|
|
||||||
|
|
||||||
WORKDIR ${DAPPER_SOURCE}
|
|
||||||
|
|
||||||
# Override the Helm deployment scripts
|
|
||||||
COPY deploy_helm /opt/shipyard/scripts/lib/
|
|
||||||
|
|
||||||
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
|
|
||||||
CMD ["sh"]
|
|
||||||
@@ -1,47 +1,45 @@
|
|||||||
BASE_BRANCH ?= devel
|
BASE_BRANCH ?= devel
|
||||||
export BASE_BRANCH
|
export BASE_BRANCH
|
||||||
|
export HELM_REPO_LOCATION=./helm_repo
|
||||||
|
|
||||||
ifneq (,$(DAPPER_HOST_ARCH))
|
ifneq (,$(DAPPER_HOST_ARCH))
|
||||||
|
|
||||||
# Running in Dapper
|
# Running in Dapper
|
||||||
|
|
||||||
PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent lighthouse-agent lighthouse-coredns
|
|
||||||
|
|
||||||
include $(SHIPYARD_DIR)/Makefile.inc
|
include $(SHIPYARD_DIR)/Makefile.inc
|
||||||
|
|
||||||
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
|
|
||||||
ifneq (,$(filter ovn,$(_using)))
|
ifneq (,$(filter ovn,$(_using)))
|
||||||
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings.ovn
|
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||||
else
|
else
|
||||||
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
|
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||||
endif
|
endif
|
||||||
|
|
||||||
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
|
export DEPLOYTOOL = helm
|
||||||
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
|
|
||||||
export DEPLOY_ARGS
|
|
||||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||||
CHARTS_DIR=charts
|
CHARTS_DIR=charts
|
||||||
CHARTS_VERSION=0.7.0
|
CHARTS_VERSION=0.25.0-m0
|
||||||
HELM_DOCS_VERSION=0.15.0
|
HELM_DOCS_VERSION=0.15.0
|
||||||
REPO_URL=$(shell git config remote.origin.url)
|
REPO_URL=$(shell git config remote.origin.url)
|
||||||
|
|
||||||
# Process extra flags from the `using=a,b,c` optional flag
|
|
||||||
|
|
||||||
ifneq (,$(filter lighthouse,$(_using)))
|
|
||||||
override DEPLOY_ARGS += --service_discovery
|
|
||||||
endif
|
|
||||||
|
|
||||||
ifneq (,$(filter globalnet,$(_using)))
|
|
||||||
override DEPLOY_ARGS += --globalnet
|
|
||||||
endif
|
|
||||||
|
|
||||||
# Targets to make
|
# Targets to make
|
||||||
|
|
||||||
e2e: E2E_ARGS=cluster1 cluster2
|
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||||
|
|
||||||
%.tgz:
|
local-helm-repo: $(CHART_PACKAGES)
|
||||||
|
mkdir -p $(HELM_REPO_LOCATION)
|
||||||
|
for archive in $^; do \
|
||||||
|
tar xzf $$archive -C $(HELM_REPO_LOCATION); \
|
||||||
|
done
|
||||||
|
|
||||||
|
e2e: local-helm-repo
|
||||||
|
$(SCRIPTS_DIR)/e2e.sh
|
||||||
|
|
||||||
|
generate-yamls:
|
||||||
|
./generate-yamls.sh $(BASE_BRANCH)
|
||||||
|
|
||||||
|
%.tgz: generate-yamls
|
||||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
|
|
||||||
helm-docs:
|
helm-docs:
|
||||||
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
||||||
@@ -57,7 +55,7 @@ helm-docs:
|
|||||||
exit 1; \
|
exit 1; \
|
||||||
fi
|
fi
|
||||||
|
|
||||||
release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
release: $(CHART_PACKAGES)
|
||||||
git checkout gh-pages
|
git checkout gh-pages
|
||||||
mv *.tgz $(CHARTS_DIR)
|
mv *.tgz $(CHARTS_DIR)
|
||||||
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
||||||
|
|||||||
@@ -60,4 +60,4 @@ working correctly.
|
|||||||
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
|
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
|
||||||
[Docker]: https://docs.docker.com/install/
|
[Docker]: https://docs.docker.com/install/
|
||||||
[Podman]: https://podman.io/getting-started/installation
|
[Podman]: https://podman.io/getting-started/installation
|
||||||
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
|
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo
|
||||||
|
|||||||
@@ -1,10 +0,0 @@
|
|||||||
. "${SCRIPTS_DIR}"/lib/source_only
|
|
||||||
|
|
||||||
# We need a minimal setup to verify the deployment works
|
|
||||||
clusters=('cluster1' 'cluster2')
|
|
||||||
cluster_nodes['cluster1']="control-plane worker"
|
|
||||||
cluster_nodes['cluster2']="control-plane worker"
|
|
||||||
|
|
||||||
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
|
|
||||||
|
|
||||||
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
. "${SCRIPTS_DIR}"/lib/source_only
|
|
||||||
|
|
||||||
# We need a minimal setup to verify the deployment works
|
|
||||||
clusters=('cluster1' 'cluster2')
|
|
||||||
cluster_nodes['cluster1']="control-plane worker worker"
|
|
||||||
cluster_nodes['cluster2']="control-plane worker worker"
|
|
||||||
|
|
||||||
cluster_cni=( ['cluster1']="ovn" ['cluster2']="ovn" )
|
|
||||||
|
|
||||||
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
|
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
|
---
|
||||||
charts:
|
charts:
|
||||||
- submariner-operator
|
- ./helm_repo/submariner-operator
|
||||||
- submariner-k8s-broker
|
- ./helm_repo/submariner-k8s-broker
|
||||||
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
||||||
# See: https://github.com/helm/chart-testing/issues/192
|
# See: https://github.com/helm/chart-testing/issues/192
|
||||||
validate-maintainers: false
|
validate-maintainers: false
|
||||||
|
|||||||
-76
@@ -1,76 +0,0 @@
|
|||||||
# shellcheck shell=bash
|
|
||||||
# shellcheck source=scripts/shared/lib/source_only
|
|
||||||
. "${BASH_SOURCE%/*}"/source_only
|
|
||||||
|
|
||||||
### Constants ###
|
|
||||||
|
|
||||||
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
|
|
||||||
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
|
|
||||||
|
|
||||||
### Functions ###
|
|
||||||
|
|
||||||
function deploytool_prereqs() {
|
|
||||||
helm version
|
|
||||||
}
|
|
||||||
|
|
||||||
function setup_broker() {
|
|
||||||
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
|
|
||||||
echo "Submariner CRDs already exist, skipping broker creation..."
|
|
||||||
else
|
|
||||||
echo "Installing submariner broker..."
|
|
||||||
# shellcheck disable=SC2086 # Split on purpose
|
|
||||||
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
|
|
||||||
--create-namespace \
|
|
||||||
--kube-context "${cluster}" \
|
|
||||||
--namespace "${SUBMARINER_BROKER_NS}" \
|
|
||||||
${deploytool_broker_args}
|
|
||||||
fi
|
|
||||||
|
|
||||||
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
|
||||||
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
|
|
||||||
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
|
|
||||||
}
|
|
||||||
|
|
||||||
function helm_install_subm() {
|
|
||||||
local crd_create=false
|
|
||||||
[[ "${cluster}" = "${broker}" ]] || crd_create=true
|
|
||||||
|
|
||||||
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
|
|
||||||
echo "Submariner already installed, skipping installation..."
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Installing Submariner..."
|
|
||||||
# shellcheck disable=SC2086 # Split on purpose
|
|
||||||
helm --kube-context "${cluster}" install submariner-operator \
|
|
||||||
./submariner-operator \
|
|
||||||
--create-namespace \
|
|
||||||
--namespace "${SUBM_NS}" \
|
|
||||||
--set ipsec.psk="${SUBMARINER_PSK}" \
|
|
||||||
--set broker.server="${submariner_broker_url}" \
|
|
||||||
--set broker.token="${submariner_broker_token}" \
|
|
||||||
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
|
|
||||||
--set broker.ca="${submariner_broker_ca}" \
|
|
||||||
--set broker.globalnet="${globalnet}" \
|
|
||||||
--set submariner.serviceDiscovery="${service_discovery}" \
|
|
||||||
--set submariner.cableDriver="${cable_driver}" \
|
|
||||||
--set submariner.clusterId="${cluster}" \
|
|
||||||
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
|
|
||||||
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
|
|
||||||
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
|
|
||||||
--set serviceAccounts.globalnet.create="${globalnet}" \
|
|
||||||
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
|
|
||||||
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
|
|
||||||
--set submariner.natEnabled="false" \
|
|
||||||
--set operator.image.repository="localhost:5000/submariner-operator" \
|
|
||||||
--set operator.image.tag="local" \
|
|
||||||
--set operator.image.pullPolicy="IfNotPresent" \
|
|
||||||
--set submariner.images.repository="localhost:5000" \
|
|
||||||
--set submariner.images.tag="local" \
|
|
||||||
--set brokercrds.create="${crd_create}" \
|
|
||||||
${deploytool_submariner_args}
|
|
||||||
}
|
|
||||||
|
|
||||||
function install_subm_all_clusters() {
|
|
||||||
run_subm_clusters helm_install_subm
|
|
||||||
}
|
|
||||||
Executable
+107
@@ -0,0 +1,107 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
BROKER_ROLE_TPL=submariner-k8s-broker/templates/_role.tpl
|
||||||
|
OPERATOR_RBAC_YAML=submariner-operator/templates/operator-rbac.yaml
|
||||||
|
GATEWAY_RBAC_YAML=submariner-operator/templates/gateway-rbac.yaml
|
||||||
|
ROUTE_AGENT_RBAC_YAML=submariner-operator/templates/routeagent-rbac.yaml
|
||||||
|
GLOBALNET_RBAC_YAML=submariner-operator/templates/globalnet-rbac.yaml
|
||||||
|
SERVICE_DISC_RBAC_YAML=submariner-operator/templates/service-discovery-rbac.yaml
|
||||||
|
OPENSHIFT_MONITORING_YAML=submariner-operator/templates/openshift-monitoring-rbac.yaml
|
||||||
|
|
||||||
|
YAMLS_BASE=yamls/vendor
|
||||||
|
SUBM_CRDS=${YAMLS_BASE}/github.com/submariner-io/submariner/deploy/crds
|
||||||
|
OPERATOR_CRDS=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/deploy/crds
|
||||||
|
MCS_CRDS=${YAMLS_BASE}/sigs.k8s.io/mcs-api/config/crd
|
||||||
|
BROKER=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/broker/broker-client
|
||||||
|
RBAC_BASE=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/rbac
|
||||||
|
OPENSHIFT=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/openshift
|
||||||
|
|
||||||
|
function add_service_acct_ns() {
|
||||||
|
sed -i '/- kind: ServiceAccount/a \ \ \ \ namespace: {{ .Release.Namespace }}' $1
|
||||||
|
}
|
||||||
|
|
||||||
|
cd yamls
|
||||||
|
rm go.mod || true
|
||||||
|
go mod init
|
||||||
|
go get github.com/submariner-io/submariner-operator@$1
|
||||||
|
go mod tidy
|
||||||
|
go mod vendor
|
||||||
|
cd ..
|
||||||
|
|
||||||
|
# Generate the CRDs for the broker chart
|
||||||
|
mkdir -p submariner-k8s-broker/crds
|
||||||
|
cat ${SUBM_CRDS}/submariner.io_endpoints.yaml \
|
||||||
|
${SUBM_CRDS}/submariner.io_clusters.yaml \
|
||||||
|
${SUBM_CRDS}/submariner.io_gateways.yaml > submariner-k8s-broker/crds/crd.yaml
|
||||||
|
echo '---' >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
cat ${MCS_CRDS}/multicluster.x-k8s.io_serviceexports.yaml >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
echo '---' >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
cat ${MCS_CRDS}/multicluster.x-k8s.io_serviceimports.yaml >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
|
||||||
|
# Generate the client role yaml for the broker chart
|
||||||
|
echo '{{- define "broker-role" -}}' > ${BROKER_ROLE_TPL}
|
||||||
|
cat ${BROKER}/role.yaml >> ${BROKER_ROLE_TPL}
|
||||||
|
echo '{{- end -}}' >> ${BROKER_ROLE_TPL}
|
||||||
|
sed -i -e 's/name:.*/name: {{ template "submariner-k8s-broker.fullname" \. }}-cluster/' ${BROKER_ROLE_TPL}
|
||||||
|
|
||||||
|
# Generate the CRDs for the operator chart
|
||||||
|
mkdir -p submariner-operator/crds
|
||||||
|
cat ${OPERATOR_CRDS}/submariner.io_submariners.yaml \
|
||||||
|
${OPERATOR_CRDS}/submariner.io_servicediscoveries.yaml \
|
||||||
|
${OPERATOR_CRDS}/submariner.io_brokers.yaml > submariner-operator/crds/crd.yaml
|
||||||
|
|
||||||
|
# Generate the operator RBAC yaml for the operator chart
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-operator/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-operator/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/cluster_role_binding.yaml > ${OPERATOR_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the gateway RBAC yaml for the operator chart
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-gateway/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-gateway/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/cluster_role_binding.yaml > ${GATEWAY_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the routeagent RBAC yaml for the operator chart
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-route-agent/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-route-agent/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/cluster_role_binding.yaml > ${ROUTE_AGENT_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the globalnet RBAC yaml for the operator chart
|
||||||
|
echo '{{- if .Values.broker.globalnet }}' > ${GLOBALNET_RBAC_YAML}
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-globalnet/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-globalnet/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/cluster_role_binding.yaml >> ${GLOBALNET_RBAC_YAML}
|
||||||
|
echo '{{- end -}}' >> ${GLOBALNET_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the service discovery RBAC yaml for the operator chart
|
||||||
|
echo '{{- if .Values.submariner.serviceDiscovery }}' > ${SERVICE_DISC_RBAC_YAML}
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/lighthouse-agent/cluster_role_binding.yaml
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/lighthouse-coredns/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/lighthouse-agent/service_account.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-agent/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-agent/cluster_role_binding.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-agent/role.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-agent/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/service_account.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/cluster_role_binding.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/role.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/role_binding.yaml >> ${SERVICE_DISC_RBAC_YAML}
|
||||||
|
echo '{{- end -}}' >> ${SERVICE_DISC_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the openshift monitoring rbac yaml for the operator chart
|
||||||
|
cat ${OPENSHIFT}/rbac/submariner-metrics-reader/role.yaml \
|
||||||
|
${OPENSHIFT}/rbac/submariner-metrics-reader/role_binding.yaml > ${OPENSHIFT_MONITORING_YAML}
|
||||||
@@ -1,8 +1,7 @@
|
|||||||
---
|
---
|
||||||
name: submariner-k8s-broker
|
name: submariner-k8s-broker
|
||||||
version: 0.6.0
|
version: 0.0.0
|
||||||
apiVersion: v2
|
apiVersion: v2
|
||||||
appVersion: 0.6.0
|
|
||||||
description: Submariner Kubernetes Broker
|
description: Submariner Kubernetes Broker
|
||||||
keywords:
|
keywords:
|
||||||
home: https://submariner-io.github.io/
|
home: https://submariner-io.github.io/
|
||||||
|
|||||||
@@ -1,26 +1,15 @@
|
|||||||
# submariner-k8s-broker
|
# submariner-k8s-broker
|
||||||
|
|
||||||
 
|
|
||||||
|
|
||||||
Submariner Kubernetes Broker
|
Submariner Kubernetes Broker
|
||||||
|
|
||||||
**Homepage:** <https://submariner-io.github.io/>
|
**Homepage:** <https://submariner-io.github.io/>
|
||||||
|
|
||||||
## Maintainers
|
## Maintainers
|
||||||
|
|
||||||
| Name | Email | Url |
|
| Name | Email | Url |
|
||||||
| ---- | ------ | --- |
|
| ---- | ------ | --- |
|
||||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
||||||
|
|
||||||
## Source Code
|
## Source Code
|
||||||
|
|
||||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
* <https://submariner-io.github.io/submariner-charts/charts>
|
||||||
|
|
||||||
## Values
|
|
||||||
|
|
||||||
| Key | Type | Default | Description |
|
|
||||||
|-----|------|---------|-------------|
|
|
||||||
| crd.create | bool | `true` | |
|
|
||||||
| rbac.create | bool | `true` | |
|
|
||||||
| serviceAccounts.client.create | bool | `true` | |
|
|
||||||
| serviceAccounts.client.name | string | `""` | |
|
|
||||||
|
|||||||
@@ -1,324 +0,0 @@
|
|||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: clusters.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Cluster
|
|
||||||
plural: clusters
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: endpoints.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Endpoint
|
|
||||||
plural: endpoints
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: gateways.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Gateway
|
|
||||||
plural: gateways
|
|
||||||
scope: Namespaced
|
|
||||||
additionalPrinterColumns:
|
|
||||||
- name: ha-status
|
|
||||||
type: string
|
|
||||||
description: High Availability Status of the Gateway
|
|
||||||
JSONPath: .status.haStatus
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: multiclusterservices.lighthouse.submariner.io
|
|
||||||
spec:
|
|
||||||
group: lighthouse.submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: MultiClusterService
|
|
||||||
plural: multiclusterservices
|
|
||||||
singular: multiclusterservice
|
|
||||||
scope: Namespaced
|
|
||||||
validation:
|
|
||||||
openAPIV3Schema:
|
|
||||||
properties:
|
|
||||||
spec:
|
|
||||||
properties:
|
|
||||||
clusterServiceInfo:
|
|
||||||
properties:
|
|
||||||
clusterID:
|
|
||||||
type: "string"
|
|
||||||
clusterDomain:
|
|
||||||
type: "string"
|
|
||||||
serviceIP:
|
|
||||||
type: "string"
|
|
||||||
port:
|
|
||||||
type: "integer"
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: serviceexports.lighthouse.submariner.io
|
|
||||||
spec:
|
|
||||||
group: lighthouse.submariner.io
|
|
||||||
version: v2alpha1
|
|
||||||
names:
|
|
||||||
kind: ServiceExport
|
|
||||||
plural: serviceexports
|
|
||||||
singular: serviceexport
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: serviceimports.lighthouse.submariner.io
|
|
||||||
spec:
|
|
||||||
group: lighthouse.submariner.io
|
|
||||||
version: v2alpha1
|
|
||||||
names:
|
|
||||||
kind: ServiceImport
|
|
||||||
plural: serviceimports
|
|
||||||
singular: serviceimport
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: serviceexports.multicluster.x-k8s.io
|
|
||||||
spec:
|
|
||||||
group: multicluster.x-k8s.io
|
|
||||||
scope: Namespaced
|
|
||||||
names:
|
|
||||||
plural: serviceexports
|
|
||||||
singular: serviceexport
|
|
||||||
kind: ServiceExport
|
|
||||||
shortNames:
|
|
||||||
- svcex
|
|
||||||
versions:
|
|
||||||
- name: v1alpha1
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
additionalPrinterColumns:
|
|
||||||
- name: Age
|
|
||||||
type: date
|
|
||||||
jsonPath: .metadata.creationTimestamp
|
|
||||||
"schema":
|
|
||||||
"openAPIV3Schema":
|
|
||||||
description: ServiceExport declares that the Service with the same name and
|
|
||||||
namespace as this export should be consumable from other clusters.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
description: status describes the current state of an exported service.
|
|
||||||
Service configuration comes from the Service that had the same name
|
|
||||||
and namespace as this ServiceExport. Populated by the multi-cluster
|
|
||||||
service implementation's controller.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
conditions:
|
|
||||||
type: array
|
|
||||||
items:
|
|
||||||
description: "ServiceExportCondition contains details for the current
|
|
||||||
condition of this service export. \n Once [KEP-1623](https://github.com/kubernetes/enhancements/tree/master/keps/sig-api-machinery/1623-standardize-conditions)
|
|
||||||
is implemented, this will be replaced by metav1.Condition."
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- status
|
|
||||||
- type
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
type: string
|
|
||||||
format: date-time
|
|
||||||
message:
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
description: Status is one of {"True", "False", "Unknown"}
|
|
||||||
type: string
|
|
||||||
enum:
|
|
||||||
- "True"
|
|
||||||
- "False"
|
|
||||||
- Unknown
|
|
||||||
type:
|
|
||||||
description: ServiceExportConditionType identifies a specific
|
|
||||||
condition.
|
|
||||||
type: string
|
|
||||||
x-kubernetes-list-map-keys:
|
|
||||||
- type
|
|
||||||
x-kubernetes-list-type: map
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: serviceimports.multicluster.x-k8s.io
|
|
||||||
spec:
|
|
||||||
group: multicluster.x-k8s.io
|
|
||||||
scope: Namespaced
|
|
||||||
names:
|
|
||||||
plural: serviceimports
|
|
||||||
singular: serviceimport
|
|
||||||
kind: ServiceImport
|
|
||||||
shortNames:
|
|
||||||
- svcim
|
|
||||||
versions:
|
|
||||||
- name: v1alpha1
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
additionalPrinterColumns:
|
|
||||||
- name: Type
|
|
||||||
type: string
|
|
||||||
description: The type of this ServiceImport
|
|
||||||
jsonPath: .spec.type
|
|
||||||
- name: IP
|
|
||||||
type: string
|
|
||||||
description: The VIP for this ServiceImport
|
|
||||||
jsonPath: .spec.ips
|
|
||||||
- name: Age
|
|
||||||
type: date
|
|
||||||
jsonPath: .metadata.creationTimestamp
|
|
||||||
"schema":
|
|
||||||
"openAPIV3Schema":
|
|
||||||
description: ServiceImport describes a service imported from clusters in a
|
|
||||||
ClusterSet.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
spec:
|
|
||||||
description: spec defines the behavior of a ServiceImport.
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- ports
|
|
||||||
- type
|
|
||||||
properties:
|
|
||||||
ips:
|
|
||||||
description: ip will be used as the VIP for this service when type
|
|
||||||
is ClusterSetIP.
|
|
||||||
type: array
|
|
||||||
maxItems: 1
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
ports:
|
|
||||||
type: array
|
|
||||||
items:
|
|
||||||
description: ServicePort represents the port on which the service
|
|
||||||
is exposed
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- port
|
|
||||||
properties:
|
|
||||||
appProtocol:
|
|
||||||
description: The application protocol for this port. This field
|
|
||||||
follows standard Kubernetes label syntax. Un-prefixed names
|
|
||||||
are reserved for IANA standard service names (as per RFC-6335
|
|
||||||
and http://www.iana.org/assignments/service-names). Non-standard
|
|
||||||
protocols should use prefixed names such as mycompany.com/my-custom-protocol.
|
|
||||||
Field can be enabled with ServiceAppProtocol feature gate.
|
|
||||||
type: string
|
|
||||||
name:
|
|
||||||
description: The name of this port within the service. This
|
|
||||||
must be a DNS_LABEL. All ports within a ServiceSpec must have
|
|
||||||
unique names. When considering the endpoints for a Service,
|
|
||||||
this must match the 'name' field in the EndpointPort. Optional
|
|
||||||
if only one ServicePort is defined on this service.
|
|
||||||
type: string
|
|
||||||
port:
|
|
||||||
description: The port that will be exposed by this service.
|
|
||||||
type: integer
|
|
||||||
format: int32
|
|
||||||
protocol:
|
|
||||||
description: The IP protocol for this port. Supports "TCP",
|
|
||||||
"UDP", and "SCTP". Default is TCP.
|
|
||||||
type: string
|
|
||||||
x-kubernetes-list-type: atomic
|
|
||||||
sessionAffinity:
|
|
||||||
description: 'Supports "ClientIP" and "None". Used to maintain session
|
|
||||||
affinity. Enable client IP based session affinity. Must be ClientIP
|
|
||||||
or None. Defaults to None. Ignored when type is Headless More info:
|
|
||||||
https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies'
|
|
||||||
type: string
|
|
||||||
sessionAffinityConfig:
|
|
||||||
description: sessionAffinityConfig contains session affinity configuration.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
clientIP:
|
|
||||||
description: clientIP contains the configurations of Client IP
|
|
||||||
based session affinity.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
timeoutSeconds:
|
|
||||||
description: timeoutSeconds specifies the seconds of ClientIP
|
|
||||||
type session sticky time. The value must be >0 && <=86400(for
|
|
||||||
1 day) if ServiceAffinity == "ClientIP". Default value is
|
|
||||||
10800(for 3 hours).
|
|
||||||
type: integer
|
|
||||||
format: int32
|
|
||||||
type:
|
|
||||||
description: type defines the type of this service. Must be ClusterSetIP
|
|
||||||
or Headless.
|
|
||||||
type: string
|
|
||||||
enum:
|
|
||||||
- ClusterSetIP
|
|
||||||
- Headless
|
|
||||||
status:
|
|
||||||
description: status contains information about the exported services that
|
|
||||||
form the multi-cluster service referenced by this ServiceImport.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
clusters:
|
|
||||||
description: clusters is the list of exporting clusters from which
|
|
||||||
this service was derived.
|
|
||||||
type: array
|
|
||||||
items:
|
|
||||||
description: ClusterStatus contains service configuration mapped
|
|
||||||
to a specific source cluster
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- cluster
|
|
||||||
properties:
|
|
||||||
cluster:
|
|
||||||
description: cluster is the name of the exporting cluster. Must
|
|
||||||
be a valid RFC-1123 DNS label.
|
|
||||||
type: string
|
|
||||||
x-kubernetes-list-map-keys:
|
|
||||||
- cluster
|
|
||||||
x-kubernetes-list-type: map
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
questions:
|
|
||||||
- variable: submariner-k8s-broker.rbac.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Role Based Access Control"
|
|
||||||
description: "Create the role/rolebinding for the Submariner client"
|
|
||||||
label: "RBAC Creation Enabled"
|
|
||||||
- variable: submariner-k8s-broker.crd.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Submariner CRD"
|
|
||||||
description: "Create the submariner CRDs for the Submariner client"
|
|
||||||
label: "Submariner CRD Creation Enabled"
|
|
||||||
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Service Account"
|
|
||||||
description: "Create the service account for the Submariner client"
|
|
||||||
label: "Submariner Service Account Creation Enabled"
|
|
||||||
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
|
|||||||
|
|
||||||
The broker client token and CA can be retrieved by running
|
The broker client token and CA can be retrieved by running
|
||||||
|
|
||||||
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
|
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
|
||||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
|
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
|
||||||
|
|||||||
@@ -35,9 +35,5 @@ Create chart name and version as used by the chart label.
|
|||||||
Create the name of the submariner-client service account to use
|
Create the name of the submariner-client service account to use
|
||||||
*/}}
|
*/}}
|
||||||
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
||||||
{{- if .Values.serviceAccounts.client.create -}}
|
{{- printf "%s-client" (include "submariner-k8s-broker.fullname" .)}}
|
||||||
{{ default (printf "%s-client" (include "submariner-k8s-broker.fullname" .)) .Values.serviceAccounts.client.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.client.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
@@ -1,26 +1,4 @@
|
|||||||
{{- if .Values.rbac.create -}}
|
{{ include "broker-role" $ }}
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
|
||||||
app: {{ template "submariner-k8s-broker.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: ["submariner.io"]
|
|
||||||
resources: ["clusters", "endpoints"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
|
||||||
- apiGroups: ["lighthouse.submariner.io"]
|
|
||||||
resources: ["*"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
|
||||||
- apiGroups: ["discovery.k8s.io"]
|
|
||||||
resources: ["endpointslices"]
|
|
||||||
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
|
|
||||||
- apiGroups: ["multicluster.x-k8s.io"]
|
|
||||||
resources: ["*"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
@@ -34,4 +12,3 @@ subjects:
|
|||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
{{- end -}}
|
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
{{- if .Values.serviceAccounts.client.create }}
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
@@ -8,4 +7,11 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||||
app: {{ template "submariner-k8s-broker.name" . }}
|
app: {{ template "submariner-k8s-broker.name" . }}
|
||||||
{{- end }}
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
|
|||||||
@@ -1,9 +1 @@
|
|||||||
---
|
---
|
||||||
rbac:
|
|
||||||
create: true
|
|
||||||
crd:
|
|
||||||
create: true
|
|
||||||
serviceAccounts:
|
|
||||||
client:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
|
|||||||
@@ -1,8 +1,7 @@
|
|||||||
---
|
---
|
||||||
name: submariner-operator
|
name: submariner-operator
|
||||||
version: 0.7.0
|
version: 0.0.0
|
||||||
apiVersion: v2
|
apiVersion: v2
|
||||||
appVersion: 0.7.0
|
|
||||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||||
keywords:
|
keywords:
|
||||||
home: https://submariner-io.github.io/
|
home: https://submariner-io.github.io/
|
||||||
|
|||||||
@@ -1,16 +1,14 @@
|
|||||||
# submariner-operator
|
# submariner-operator
|
||||||
|
|
||||||
 
|
|
||||||
|
|
||||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||||
|
|
||||||
**Homepage:** <https://submariner-io.github.io/>
|
**Homepage:** <https://submariner-io.github.io/>
|
||||||
|
|
||||||
## Maintainers
|
## Maintainers
|
||||||
|
|
||||||
| Name | Email | Url |
|
| Name | Email | Url |
|
||||||
| ---- | ------ | --- |
|
| ---- | ------ | --- |
|
||||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
||||||
|
|
||||||
## Source Code
|
## Source Code
|
||||||
|
|
||||||
@@ -18,51 +16,43 @@ Submariner enables direct networking between Pods and Services in different Kube
|
|||||||
|
|
||||||
## Values
|
## Values
|
||||||
|
|
||||||
| Key | Type | Default | Description |
|
| Key | Type | Default | Description |
|
||||||
|-----|------|---------|-------------|
|
| ----- | ------ | --------- | ------------- |
|
||||||
| broker.ca | string | `""` | |
|
| broker.ca | string | `""` | |
|
||||||
| broker.globalnet | bool | `false` | |
|
| broker.globalnet | bool | `false` | |
|
||||||
| broker.insecure | bool | `false` | |
|
| broker.insecure | bool | `false` | |
|
||||||
| broker.namespace | string | `"xyz"` | |
|
| broker.namespace | string | `"xyz"` | |
|
||||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
| broker.server | string | `"example.k8s.apiserver"` | |
|
||||||
| broker.token | string | `"test"` | |
|
| broker.token | string | `"test"` | |
|
||||||
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
|
| ipsec.debug | bool | `false` | |
|
||||||
| gateway.image.tag | string | `"0.7.0"` | |
|
| ipsec.forceUDPEncaps | bool | `false` | |
|
||||||
| ipsec.debug | bool | `false` | |
|
| ipsec.ikePort | int | `500` | |
|
||||||
| ipsec.ikePort | int | `500` | |
|
| ipsec.natPort | int | `4500` | |
|
||||||
| ipsec.natPort | int | `4500` | |
|
| ipsec.pskSecret | string | `""` | Name of the Kubernetes Secret containing the IPsec PSK as field psk |
|
||||||
| ipsec.psk | string | `""` | |
|
| ipsec.psk | string | `""` | |
|
||||||
| leadership.leaseDuration | int | `10` | |
|
| leadership.leaseDuration | int | `10` | |
|
||||||
| leadership.renewDeadline | int | `5` | |
|
| leadership.renewDeadline | int | `5` | |
|
||||||
| leadership.retryPeriod | int | `2` | |
|
| leadership.retryPeriod | int | `2` | |
|
||||||
| operator.affinity | object | `{}` | |
|
| operator.affinity | object | `{}` | |
|
||||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
||||||
| operator.image.tag | string | `"0.7.0"` | |
|
| operator.image.tag | string | `"0.14.0"` | |
|
||||||
| operator.resources | object | `{}` | |
|
| operator.resources | object | `{}` | |
|
||||||
| operator.tolerations | list | `[]` | |
|
| operator.tolerations | list | `[]` | |
|
||||||
| rbac.create | bool | `true` | |
|
| submariner.cableDriver | string | `"libreswan"` | |
|
||||||
| serviceAccounts.gateway.create | bool | `true` | |
|
| submariner.clusterCidr | string | `""` | |
|
||||||
| serviceAccounts.gateway.name | string | `""` | |
|
| submariner.clusterId | string | `""` | |
|
||||||
| serviceAccounts.globalnet.create | bool | `true` | |
|
| submariner.colorCodes | string | `"blue"` | |
|
||||||
| serviceAccounts.globalnet.name | string | `""` | |
|
| submariner.coreDNSCustomConfig | object | `{}` | |
|
||||||
| serviceAccounts.lighthouseAgent.create | bool | `true` | |
|
| submariner.debug | bool | `false` | |
|
||||||
| serviceAccounts.lighthouseAgent.name | string | `""` | |
|
| submariner.globalCidr | string | `""` | |
|
||||||
| serviceAccounts.lighthouseCoreDns.create | bool | `true` | |
|
| submariner.clustersetIpCidr | string | `""` | |
|
||||||
| serviceAccounts.lighthouseCoreDns.name | string | `""` | |
|
| submariner.clustersetIpEnabled | bool | `false` | |
|
||||||
| serviceAccounts.operator.create | bool | `true` | |
|
| submariner.healthcheckEnabled | bool | `true` | |
|
||||||
| serviceAccounts.operator.name | string | `""` | |
|
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||||
| serviceAccounts.routeAgent.create | bool | `true` | |
|
| submariner.images.tag | string | `"0.14.0"` | |
|
||||||
| serviceAccounts.routeAgent.name | string | `""` | |
|
| submariner.natEnabled | bool | `false` | |
|
||||||
| submariner.cableDriver | string | `"libreswan"` | |
|
| submariner.serviceCidr | string | `""` | |
|
||||||
| submariner.clusterCidr | string | `""` | |
|
| submariner.brokerK8sSecret | string | `""` | Name of the Kubernetes Secret containing broker credentials (ca.crt, token). |
|
||||||
| submariner.clusterId | string | `""` | |
|
| submariner.serviceDiscovery | bool | `true` | |
|
||||||
| submariner.colorCodes | string | `"blue"` | |
|
| submariner.token | string | `""` | |
|
||||||
| submariner.debug | bool | `false` | |
|
|
||||||
| submariner.globalCidr | string | `""` | |
|
|
||||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
|
||||||
| submariner.images.tag | string | `"0.7.0"` | |
|
|
||||||
| submariner.natEnabled | bool | `false` | |
|
|
||||||
| submariner.serviceCidr | string | `""` | |
|
|
||||||
| submariner.serviceDiscovery | bool | `true` | |
|
|
||||||
| submariner.token | string | `""` | |
|
|
||||||
|
|||||||
@@ -1,877 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: submariners.submariner.io
|
|
||||||
annotations:
|
|
||||||
controller-gen.kubebuilder.io/version: v0.3.0
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
names:
|
|
||||||
kind: Submariner
|
|
||||||
listKind: SubmarinerList
|
|
||||||
plural: submariners
|
|
||||||
singular: submariner
|
|
||||||
scope: Namespaced
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
validation:
|
|
||||||
openAPIV3Schema:
|
|
||||||
description: Submariner is the Schema for the submariners API
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
spec:
|
|
||||||
description: SubmarinerSpec defines the desired state of Submariner
|
|
||||||
properties:
|
|
||||||
broker:
|
|
||||||
type: string
|
|
||||||
brokerK8sApiServer:
|
|
||||||
type: string
|
|
||||||
brokerK8sApiServerToken:
|
|
||||||
type: string
|
|
||||||
brokerK8sCA:
|
|
||||||
type: string
|
|
||||||
brokerK8sRemoteNamespace:
|
|
||||||
type: string
|
|
||||||
cableDriver:
|
|
||||||
type: string
|
|
||||||
ceIPSecDebug:
|
|
||||||
type: boolean
|
|
||||||
ceIPSecIKEPort:
|
|
||||||
type: integer
|
|
||||||
ceIPSecNATTPort:
|
|
||||||
type: integer
|
|
||||||
ceIPSecPSK:
|
|
||||||
type: string
|
|
||||||
clusterCIDR:
|
|
||||||
type: string
|
|
||||||
clusterID:
|
|
||||||
type: string
|
|
||||||
colorCodes:
|
|
||||||
type: string
|
|
||||||
customDomains:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
x-kubernetes-list-type: set
|
|
||||||
debug:
|
|
||||||
type: boolean
|
|
||||||
globalCIDR:
|
|
||||||
type: string
|
|
||||||
namespace:
|
|
||||||
type: string
|
|
||||||
natEnabled:
|
|
||||||
type: boolean
|
|
||||||
repository:
|
|
||||||
type: string
|
|
||||||
serviceCIDR:
|
|
||||||
type: string
|
|
||||||
serviceDiscoveryEnabled:
|
|
||||||
type: boolean
|
|
||||||
version:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- broker
|
|
||||||
- brokerK8sApiServer
|
|
||||||
- brokerK8sApiServerToken
|
|
||||||
- brokerK8sCA
|
|
||||||
- brokerK8sRemoteNamespace
|
|
||||||
- ceIPSecDebug
|
|
||||||
- ceIPSecPSK
|
|
||||||
- clusterCIDR
|
|
||||||
- clusterID
|
|
||||||
- debug
|
|
||||||
- namespace
|
|
||||||
- natEnabled
|
|
||||||
- serviceCIDR
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
description: SubmarinerStatus defines the observed state of Submariner
|
|
||||||
properties:
|
|
||||||
clusterCIDR:
|
|
||||||
type: string
|
|
||||||
clusterID:
|
|
||||||
type: string
|
|
||||||
colorCodes:
|
|
||||||
type: string
|
|
||||||
gatewayDaemonSetStatus:
|
|
||||||
properties:
|
|
||||||
lastResourceVersion:
|
|
||||||
type: string
|
|
||||||
mismatchedContainerImages:
|
|
||||||
type: boolean
|
|
||||||
nonReadyContainerStates:
|
|
||||||
items:
|
|
||||||
description: ContainerState holds a possible state of container.
|
|
||||||
Only one of its members may be specified. If none of them is
|
|
||||||
specified, the default one is ContainerStateWaiting.
|
|
||||||
properties:
|
|
||||||
running:
|
|
||||||
description: Details about a running container
|
|
||||||
properties:
|
|
||||||
startedAt:
|
|
||||||
description: Time at which the container was last (re-)started
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
terminated:
|
|
||||||
description: Details about a terminated container
|
|
||||||
properties:
|
|
||||||
containerID:
|
|
||||||
description: Container's ID in the format 'docker://<container_id>'
|
|
||||||
type: string
|
|
||||||
exitCode:
|
|
||||||
description: Exit status from the last termination of
|
|
||||||
the container
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
finishedAt:
|
|
||||||
description: Time at which the container last terminated
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
message:
|
|
||||||
description: Message regarding the last termination of
|
|
||||||
the container
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: (brief) reason from the last termination
|
|
||||||
of the container
|
|
||||||
type: string
|
|
||||||
signal:
|
|
||||||
description: Signal from the last termination of the container
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
startedAt:
|
|
||||||
description: Time at which previous execution of the container
|
|
||||||
started
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- exitCode
|
|
||||||
type: object
|
|
||||||
waiting:
|
|
||||||
description: Details about a waiting container
|
|
||||||
properties:
|
|
||||||
message:
|
|
||||||
description: Message regarding why the container is not
|
|
||||||
yet running.
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: (brief) reason the container is not yet running.
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
status:
|
|
||||||
description: DaemonSetStatus represents the current status of a
|
|
||||||
daemon set.
|
|
||||||
properties:
|
|
||||||
collisionCount:
|
|
||||||
description: Count of hash collisions for the DaemonSet. The
|
|
||||||
DaemonSet controller uses this field as a collision avoidance
|
|
||||||
mechanism when it needs to create the name for the newest
|
|
||||||
ControllerRevision.
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
conditions:
|
|
||||||
description: Represents the latest available observations of
|
|
||||||
a DaemonSet's current state.
|
|
||||||
items:
|
|
||||||
description: DaemonSetCondition describes the state of a DaemonSet
|
|
||||||
at a certain point.
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
description: Last time the condition transitioned from
|
|
||||||
one status to another.
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
message:
|
|
||||||
description: A human readable message indicating details
|
|
||||||
about the transition.
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: The reason for the condition's last transition.
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
description: Status of the condition, one of True, False,
|
|
||||||
Unknown.
|
|
||||||
type: string
|
|
||||||
type:
|
|
||||||
description: Type of DaemonSet condition.
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- status
|
|
||||||
- type
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
currentNumberScheduled:
|
|
||||||
description: 'The number of nodes that are running at least
|
|
||||||
1 daemon pod and are supposed to run the daemon pod. More
|
|
||||||
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
desiredNumberScheduled:
|
|
||||||
description: 'The total number of nodes that should be running
|
|
||||||
the daemon pod (including nodes correctly running the daemon
|
|
||||||
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberAvailable:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have one or more of the daemon pod running
|
|
||||||
and available (ready for at least spec.minReadySeconds)
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberMisscheduled:
|
|
||||||
description: 'The number of nodes that are running the daemon
|
|
||||||
pod, but are not supposed to run the daemon pod. More info:
|
|
||||||
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberReady:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have one or more of the daemon pod running
|
|
||||||
and ready.
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberUnavailable:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have none of the daemon pod running and available
|
|
||||||
(ready for at least spec.minReadySeconds)
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
observedGeneration:
|
|
||||||
description: The most recent generation observed by the daemon
|
|
||||||
set controller.
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
updatedNumberScheduled:
|
|
||||||
description: The total number of nodes that are running updated
|
|
||||||
daemon pod
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
required:
|
|
||||||
- currentNumberScheduled
|
|
||||||
- desiredNumberScheduled
|
|
||||||
- numberMisscheduled
|
|
||||||
- numberReady
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- mismatchedContainerImages
|
|
||||||
type: object
|
|
||||||
gateways:
|
|
||||||
items:
|
|
||||||
properties:
|
|
||||||
connections:
|
|
||||||
items:
|
|
||||||
properties:
|
|
||||||
endpoint:
|
|
||||||
properties:
|
|
||||||
backend:
|
|
||||||
type: string
|
|
||||||
backend_config:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
cable_name:
|
|
||||||
type: string
|
|
||||||
cluster_id:
|
|
||||||
type: string
|
|
||||||
hostname:
|
|
||||||
type: string
|
|
||||||
nat_enabled:
|
|
||||||
type: boolean
|
|
||||||
private_ip:
|
|
||||||
type: string
|
|
||||||
public_ip:
|
|
||||||
type: string
|
|
||||||
subnets:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
required:
|
|
||||||
- backend
|
|
||||||
- cable_name
|
|
||||||
- cluster_id
|
|
||||||
- hostname
|
|
||||||
- nat_enabled
|
|
||||||
- private_ip
|
|
||||||
- public_ip
|
|
||||||
- subnets
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
type: string
|
|
||||||
statusMessage:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- endpoint
|
|
||||||
- status
|
|
||||||
- statusMessage
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
haStatus:
|
|
||||||
type: string
|
|
||||||
localEndpoint:
|
|
||||||
properties:
|
|
||||||
backend:
|
|
||||||
type: string
|
|
||||||
backend_config:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
cable_name:
|
|
||||||
type: string
|
|
||||||
cluster_id:
|
|
||||||
type: string
|
|
||||||
hostname:
|
|
||||||
type: string
|
|
||||||
nat_enabled:
|
|
||||||
type: boolean
|
|
||||||
private_ip:
|
|
||||||
type: string
|
|
||||||
public_ip:
|
|
||||||
type: string
|
|
||||||
subnets:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
required:
|
|
||||||
- backend
|
|
||||||
- cable_name
|
|
||||||
- cluster_id
|
|
||||||
- hostname
|
|
||||||
- nat_enabled
|
|
||||||
- private_ip
|
|
||||||
- public_ip
|
|
||||||
- subnets
|
|
||||||
type: object
|
|
||||||
statusFailure:
|
|
||||||
type: string
|
|
||||||
version:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- connections
|
|
||||||
- haStatus
|
|
||||||
- localEndpoint
|
|
||||||
- statusFailure
|
|
||||||
- version
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
globalCIDR:
|
|
||||||
type: string
|
|
||||||
globalnetDaemonSetStatus:
|
|
||||||
properties:
|
|
||||||
lastResourceVersion:
|
|
||||||
type: string
|
|
||||||
mismatchedContainerImages:
|
|
||||||
type: boolean
|
|
||||||
nonReadyContainerStates:
|
|
||||||
items:
|
|
||||||
description: ContainerState holds a possible state of container.
|
|
||||||
Only one of its members may be specified. If none of them is
|
|
||||||
specified, the default one is ContainerStateWaiting.
|
|
||||||
properties:
|
|
||||||
running:
|
|
||||||
description: Details about a running container
|
|
||||||
properties:
|
|
||||||
startedAt:
|
|
||||||
description: Time at which the container was last (re-)started
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
terminated:
|
|
||||||
description: Details about a terminated container
|
|
||||||
properties:
|
|
||||||
containerID:
|
|
||||||
description: Container's ID in the format 'docker://<container_id>'
|
|
||||||
type: string
|
|
||||||
exitCode:
|
|
||||||
description: Exit status from the last termination of
|
|
||||||
the container
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
finishedAt:
|
|
||||||
description: Time at which the container last terminated
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
message:
|
|
||||||
description: Message regarding the last termination of
|
|
||||||
the container
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: (brief) reason from the last termination
|
|
||||||
of the container
|
|
||||||
type: string
|
|
||||||
signal:
|
|
||||||
description: Signal from the last termination of the container
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
startedAt:
|
|
||||||
description: Time at which previous execution of the container
|
|
||||||
started
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- exitCode
|
|
||||||
type: object
|
|
||||||
waiting:
|
|
||||||
description: Details about a waiting container
|
|
||||||
properties:
|
|
||||||
message:
|
|
||||||
description: Message regarding why the container is not
|
|
||||||
yet running.
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: (brief) reason the container is not yet running.
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
status:
|
|
||||||
description: DaemonSetStatus represents the current status of a
|
|
||||||
daemon set.
|
|
||||||
properties:
|
|
||||||
collisionCount:
|
|
||||||
description: Count of hash collisions for the DaemonSet. The
|
|
||||||
DaemonSet controller uses this field as a collision avoidance
|
|
||||||
mechanism when it needs to create the name for the newest
|
|
||||||
ControllerRevision.
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
conditions:
|
|
||||||
description: Represents the latest available observations of
|
|
||||||
a DaemonSet's current state.
|
|
||||||
items:
|
|
||||||
description: DaemonSetCondition describes the state of a DaemonSet
|
|
||||||
at a certain point.
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
description: Last time the condition transitioned from
|
|
||||||
one status to another.
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
message:
|
|
||||||
description: A human readable message indicating details
|
|
||||||
about the transition.
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: The reason for the condition's last transition.
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
description: Status of the condition, one of True, False,
|
|
||||||
Unknown.
|
|
||||||
type: string
|
|
||||||
type:
|
|
||||||
description: Type of DaemonSet condition.
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- status
|
|
||||||
- type
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
currentNumberScheduled:
|
|
||||||
description: 'The number of nodes that are running at least
|
|
||||||
1 daemon pod and are supposed to run the daemon pod. More
|
|
||||||
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
desiredNumberScheduled:
|
|
||||||
description: 'The total number of nodes that should be running
|
|
||||||
the daemon pod (including nodes correctly running the daemon
|
|
||||||
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberAvailable:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have one or more of the daemon pod running
|
|
||||||
and available (ready for at least spec.minReadySeconds)
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberMisscheduled:
|
|
||||||
description: 'The number of nodes that are running the daemon
|
|
||||||
pod, but are not supposed to run the daemon pod. More info:
|
|
||||||
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberReady:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have one or more of the daemon pod running
|
|
||||||
and ready.
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberUnavailable:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have none of the daemon pod running and available
|
|
||||||
(ready for at least spec.minReadySeconds)
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
observedGeneration:
|
|
||||||
description: The most recent generation observed by the daemon
|
|
||||||
set controller.
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
updatedNumberScheduled:
|
|
||||||
description: The total number of nodes that are running updated
|
|
||||||
daemon pod
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
required:
|
|
||||||
- currentNumberScheduled
|
|
||||||
- desiredNumberScheduled
|
|
||||||
- numberMisscheduled
|
|
||||||
- numberReady
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- mismatchedContainerImages
|
|
||||||
type: object
|
|
||||||
natEnabled:
|
|
||||||
type: boolean
|
|
||||||
routeAgentDaemonSetStatus:
|
|
||||||
properties:
|
|
||||||
lastResourceVersion:
|
|
||||||
type: string
|
|
||||||
mismatchedContainerImages:
|
|
||||||
type: boolean
|
|
||||||
nonReadyContainerStates:
|
|
||||||
items:
|
|
||||||
description: ContainerState holds a possible state of container.
|
|
||||||
Only one of its members may be specified. If none of them is
|
|
||||||
specified, the default one is ContainerStateWaiting.
|
|
||||||
properties:
|
|
||||||
running:
|
|
||||||
description: Details about a running container
|
|
||||||
properties:
|
|
||||||
startedAt:
|
|
||||||
description: Time at which the container was last (re-)started
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
terminated:
|
|
||||||
description: Details about a terminated container
|
|
||||||
properties:
|
|
||||||
containerID:
|
|
||||||
description: Container's ID in the format 'docker://<container_id>'
|
|
||||||
type: string
|
|
||||||
exitCode:
|
|
||||||
description: Exit status from the last termination of
|
|
||||||
the container
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
finishedAt:
|
|
||||||
description: Time at which the container last terminated
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
message:
|
|
||||||
description: Message regarding the last termination of
|
|
||||||
the container
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: (brief) reason from the last termination
|
|
||||||
of the container
|
|
||||||
type: string
|
|
||||||
signal:
|
|
||||||
description: Signal from the last termination of the container
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
startedAt:
|
|
||||||
description: Time at which previous execution of the container
|
|
||||||
started
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- exitCode
|
|
||||||
type: object
|
|
||||||
waiting:
|
|
||||||
description: Details about a waiting container
|
|
||||||
properties:
|
|
||||||
message:
|
|
||||||
description: Message regarding why the container is not
|
|
||||||
yet running.
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: (brief) reason the container is not yet running.
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
status:
|
|
||||||
description: DaemonSetStatus represents the current status of a
|
|
||||||
daemon set.
|
|
||||||
properties:
|
|
||||||
collisionCount:
|
|
||||||
description: Count of hash collisions for the DaemonSet. The
|
|
||||||
DaemonSet controller uses this field as a collision avoidance
|
|
||||||
mechanism when it needs to create the name for the newest
|
|
||||||
ControllerRevision.
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
conditions:
|
|
||||||
description: Represents the latest available observations of
|
|
||||||
a DaemonSet's current state.
|
|
||||||
items:
|
|
||||||
description: DaemonSetCondition describes the state of a DaemonSet
|
|
||||||
at a certain point.
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
description: Last time the condition transitioned from
|
|
||||||
one status to another.
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
message:
|
|
||||||
description: A human readable message indicating details
|
|
||||||
about the transition.
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
description: The reason for the condition's last transition.
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
description: Status of the condition, one of True, False,
|
|
||||||
Unknown.
|
|
||||||
type: string
|
|
||||||
type:
|
|
||||||
description: Type of DaemonSet condition.
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- status
|
|
||||||
- type
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
currentNumberScheduled:
|
|
||||||
description: 'The number of nodes that are running at least
|
|
||||||
1 daemon pod and are supposed to run the daemon pod. More
|
|
||||||
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
desiredNumberScheduled:
|
|
||||||
description: 'The total number of nodes that should be running
|
|
||||||
the daemon pod (including nodes correctly running the daemon
|
|
||||||
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberAvailable:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have one or more of the daemon pod running
|
|
||||||
and available (ready for at least spec.minReadySeconds)
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberMisscheduled:
|
|
||||||
description: 'The number of nodes that are running the daemon
|
|
||||||
pod, but are not supposed to run the daemon pod. More info:
|
|
||||||
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberReady:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have one or more of the daemon pod running
|
|
||||||
and ready.
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
numberUnavailable:
|
|
||||||
description: The number of nodes that should be running the
|
|
||||||
daemon pod and have none of the daemon pod running and available
|
|
||||||
(ready for at least spec.minReadySeconds)
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
observedGeneration:
|
|
||||||
description: The most recent generation observed by the daemon
|
|
||||||
set controller.
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
updatedNumberScheduled:
|
|
||||||
description: The total number of nodes that are running updated
|
|
||||||
daemon pod
|
|
||||||
format: int32
|
|
||||||
type: integer
|
|
||||||
required:
|
|
||||||
- currentNumberScheduled
|
|
||||||
- desiredNumberScheduled
|
|
||||||
- numberMisscheduled
|
|
||||||
- numberReady
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- mismatchedContainerImages
|
|
||||||
type: object
|
|
||||||
serviceCIDR:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- clusterID
|
|
||||||
- natEnabled
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
version: v1alpha1
|
|
||||||
versions:
|
|
||||||
- name: v1alpha1
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
controller-gen.kubebuilder.io/version: v0.3.0
|
|
||||||
creationTimestamp: null
|
|
||||||
name: servicediscoveries.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
names:
|
|
||||||
kind: ServiceDiscovery
|
|
||||||
listKind: ServiceDiscoveryList
|
|
||||||
plural: servicediscoveries
|
|
||||||
singular: servicediscovery
|
|
||||||
scope: Namespaced
|
|
||||||
versions:
|
|
||||||
- name: v1alpha1
|
|
||||||
schema:
|
|
||||||
openAPIV3Schema:
|
|
||||||
description: ServiceDiscovery is the Schema for the servicediscoveries API
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
spec:
|
|
||||||
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery
|
|
||||||
properties:
|
|
||||||
brokerK8sApiServer:
|
|
||||||
type: string
|
|
||||||
brokerK8sApiServerToken:
|
|
||||||
type: string
|
|
||||||
brokerK8sCA:
|
|
||||||
type: string
|
|
||||||
brokerK8sRemoteNamespace:
|
|
||||||
type: string
|
|
||||||
clusterID:
|
|
||||||
type: string
|
|
||||||
customDomains:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
x-kubernetes-list-type: set
|
|
||||||
debug:
|
|
||||||
type: boolean
|
|
||||||
globalnetEnabled:
|
|
||||||
type: boolean
|
|
||||||
imageOverrides:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
namespace:
|
|
||||||
type: string
|
|
||||||
repository:
|
|
||||||
type: string
|
|
||||||
version:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- brokerK8sApiServer
|
|
||||||
- brokerK8sApiServerToken
|
|
||||||
- brokerK8sCA
|
|
||||||
- brokerK8sRemoteNamespace
|
|
||||||
- clusterID
|
|
||||||
- debug
|
|
||||||
- namespace
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
controller-gen.kubebuilder.io/version: v0.3.0
|
|
||||||
creationTimestamp: null
|
|
||||||
name: brokers.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
names:
|
|
||||||
kind: Broker
|
|
||||||
listKind: BrokerList
|
|
||||||
plural: brokers
|
|
||||||
singular: broker
|
|
||||||
scope: Namespaced
|
|
||||||
versions:
|
|
||||||
- name: v1alpha1
|
|
||||||
schema:
|
|
||||||
openAPIV3Schema:
|
|
||||||
description: Broker is the Schema for the brokers API
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
spec:
|
|
||||||
description: BrokerSpec defines the desired state of Broker
|
|
||||||
properties:
|
|
||||||
components:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
defaultCustomDomains:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
defaultGlobalnetClusterSize:
|
|
||||||
type: integer
|
|
||||||
globalnetCIDRRange:
|
|
||||||
type: string
|
|
||||||
globalnetEnabled:
|
|
||||||
type: boolean
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
description: BrokerStatus defines the observed state of Broker
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
@@ -1,138 +0,0 @@
|
|||||||
questions:
|
|
||||||
- variable: defaultOperatorImage
|
|
||||||
default: true
|
|
||||||
description: "Use default Submariner operator image or specify a custom one"
|
|
||||||
label: Use default Submariner operator image
|
|
||||||
type: boolean
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Container Images"
|
|
||||||
subquestions:
|
|
||||||
- variable: operator.image.repository
|
|
||||||
default: "quay.io/submariner/submariner-operator"
|
|
||||||
description: "Submariner Operator Image Repository"
|
|
||||||
type: string
|
|
||||||
label: Submariner Operator Image Repository
|
|
||||||
- variable: operator.image.tag
|
|
||||||
default: "0.7.0"
|
|
||||||
description: "Submariner Operator Image Tag"
|
|
||||||
type: string
|
|
||||||
label: Submariner Operator Image Tag
|
|
||||||
- variable: defaultSubmarinerImages
|
|
||||||
default: true
|
|
||||||
description: "Use default Submariner images or specify custom ones"
|
|
||||||
label: Use default Submariner images
|
|
||||||
type: boolean
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Container images"
|
|
||||||
subquestions:
|
|
||||||
- variable: submariner.images.repository
|
|
||||||
default: "quay.io/submariner"
|
|
||||||
description: "Submariner Repository (base for all non-operator images)"
|
|
||||||
type: string
|
|
||||||
label: Submariner Repository
|
|
||||||
- variable: submariner.images.tag
|
|
||||||
default: "0.7.0"
|
|
||||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
|
||||||
type: string
|
|
||||||
label: Submariner Images Tag
|
|
||||||
- variable: submariner.clusterId
|
|
||||||
default: ""
|
|
||||||
description: "Enter a unique cluster ID to identify this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Cluster ID"
|
|
||||||
group: "Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: ipsec.psk
|
|
||||||
default: ""
|
|
||||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
|
||||||
type: string
|
|
||||||
label: "IPsec Pre-Shared Key"
|
|
||||||
group: "Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: broker.server
|
|
||||||
type: string
|
|
||||||
default: ""
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Server"
|
|
||||||
description: "Broker server to use (without the https://)"
|
|
||||||
- variable: broker.insecure
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Insecure Broker"
|
|
||||||
description: "Connect to K8s broker without validating CA"
|
|
||||||
subquestions:
|
|
||||||
- variable: broker.ca
|
|
||||||
type: string
|
|
||||||
description: "Base64 encoded broker ca.crt"
|
|
||||||
label: "Broker CA encoded in base64"
|
|
||||||
default: ""
|
|
||||||
- variable: broker.token
|
|
||||||
type: string
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Token"
|
|
||||||
description: "Bearer token for broker"
|
|
||||||
- variable: broker.namespace
|
|
||||||
type: string
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Namespace"
|
|
||||||
description: "Enter namespace to use on central broker"
|
|
||||||
- variable: submariner.clusterCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Cluster CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: submariner.serviceCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Service CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: submariner.serviceDiscovery
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable multicluster service discovery"
|
|
||||||
label: "Service Discovery Enabled"
|
|
||||||
- variable: broker.globalnet
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Broker Configuration"
|
|
||||||
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
|
|
||||||
label: "Globalnet Enabled"
|
|
||||||
subquestions:
|
|
||||||
- variable: submariner.globalCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
|
|
||||||
type: string
|
|
||||||
label: "Globalnet CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: false
|
|
||||||
- variable: submariner.natEnabled
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
|
||||||
label: "NAT Enabled"
|
|
||||||
- variable: submariner.debug
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable submariner debug mode"
|
|
||||||
label: "Submariner Debug Enabled"
|
|
||||||
- variable: ipsec.debug
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable Charon debug mode"
|
|
||||||
label: "Charon Enabled"
|
|
||||||
- variable: submariner.cableDriver
|
|
||||||
type: string
|
|
||||||
default: ""
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Cable driver implementation"
|
|
||||||
label: "Cable Driver"
|
|
||||||
@@ -1,7 +1,3 @@
|
|||||||
Submariner is now installed.
|
Submariner is now installed.
|
||||||
|
|
||||||
{{- if .Values.gateway.nodeSelectorEnabled }}
|
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||||
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
|
||||||
|
|||||||
@@ -1,11 +1,4 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
{{/* vim: set filetype=mustache: */}}
|
||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
{{/*
|
||||||
Create a default fully qualified app name.
|
Create a default fully qualified app name.
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
@@ -31,75 +24,3 @@ Create chart name and version as used by the chart label.
|
|||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-operator service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.operatorServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.operator.create -}}
|
|
||||||
{{ default (printf "%s" (include "submariner.fullname" .)) .Values.serviceAccounts.operator.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.operator.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-gateway service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.gatewayServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.gateway.create -}}
|
|
||||||
{{ default "submariner-gateway" .Values.serviceAccounts.gateway.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.gateway.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-route-agent service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.routeAgentServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
|
||||||
{{ default "submariner-routeagent" .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-globalnet service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.globalnetServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.globalnet.create -}}
|
|
||||||
{{ default "submariner-globalnet" .Values.serviceAccounts.globalnet.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.globalnet.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-lighthouse-agent service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.lighthouseAgentServiceAccountName" -}}
|
|
||||||
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseAgent.create) -}}
|
|
||||||
{{ default "submariner-lighthouse-agent" .Values.serviceAccounts.lighthouseAgent.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.lighthouseAgent.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-lighthouse-coredns service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.lighthouseCoreDnsServiceAccountName" -}}
|
|
||||||
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseCoreDns.create) -}}
|
|
||||||
{{ default "submariner-lighthouse-coredns" .Values.serviceAccounts.lighthouseCoreDns.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.lighthouseCoreDns.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-lighthouse-coredns service name to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.lighthouseDnsName" -}}
|
|
||||||
{{- default (printf "%s-lighthouse-coredns" (include "submariner.fullname" .)) .Values.lighthouseCoredns.name }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|||||||
@@ -6,7 +6,6 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.fullname" . }}
|
app: {{ template "submariner.fullname" . }}
|
||||||
component: gateway
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
name: {{ template "submariner.fullname" . }}
|
||||||
spec:
|
spec:
|
||||||
progressDeadlineSeconds: 600
|
progressDeadlineSeconds: 600
|
||||||
@@ -27,8 +26,8 @@ spec:
|
|||||||
name: {{ template "submariner.fullname" . }}
|
name: {{ template "submariner.fullname" . }}
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- command:
|
- args:
|
||||||
- submariner-operator
|
- --leader-elect
|
||||||
env:
|
env:
|
||||||
- name: WATCH_NAMESPACE
|
- name: WATCH_NAMESPACE
|
||||||
valueFrom:
|
valueFrom:
|
||||||
@@ -52,6 +51,5 @@ spec:
|
|||||||
restartPolicy: Always
|
restartPolicy: Always
|
||||||
schedulerName: default-scheduler
|
schedulerName: default-scheduler
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
serviceAccount: {{ template "submariner.fullname" . }}
|
serviceAccountName: submariner-operator
|
||||||
serviceAccountName: {{ template "submariner.fullname" . }}
|
|
||||||
terminationGracePeriodSeconds: 30
|
terminationGracePeriodSeconds: 30
|
||||||
|
|||||||
@@ -1,857 +0,0 @@
|
|||||||
{{- if .Values.rbac.create -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- {{ template "submariner.fullname" . }}
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- servicediscoveries
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
---
|
|
||||||
kind: RoleBinding
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
|
||||||
roleRef:
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- submariner-operator
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- servicediscoveries
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- watch
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- submariner-operator
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- servicediscoveries
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- watch
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- if .Values.broker.globalnet }}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- submariner-operator
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- servicediscoveries
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- watch
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- end -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
# submariner-operator updates the config map of core-dns to forward requests to
|
|
||||||
# clusterset.local to Lighthouse DNS, also looks at existing configmaps
|
|
||||||
# to figure out network settings
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- apiextensions.k8s.io
|
|
||||||
resources:
|
|
||||||
- customresourcedefinitions
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- watch
|
|
||||||
- apiGroups: # pods, services and nodes are looked up to figure out network settings
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- nodes
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- operator.openshift.io
|
|
||||||
resources:
|
|
||||||
- dnses
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- config.openshift.io
|
|
||||||
resources:
|
|
||||||
- networks
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- apiextensions.k8s.io
|
|
||||||
resources:
|
|
||||||
- customresourcedefinitions
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups: # pods and services are looked up to figure out network settings
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- nodes
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- operator.openshift.io
|
|
||||||
resources:
|
|
||||||
- dnses
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- config.openshift.io
|
|
||||||
resources:
|
|
||||||
- networks
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- endpoints
|
|
||||||
- gateways
|
|
||||||
- clusters
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- apiextensions.k8s.io
|
|
||||||
resources:
|
|
||||||
- customresourcedefinitions
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups: # pods and services are looked up to figure out network settings
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- operator.openshift.io
|
|
||||||
resources:
|
|
||||||
- dnses
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- config.openshift.io
|
|
||||||
resources:
|
|
||||||
- networks
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
resources:
|
|
||||||
- nodes
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- if .Values.broker.globalnet }}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- namespaces
|
|
||||||
- nodes
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- endpoints
|
|
||||||
- clusters
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- clusterglobalegressips
|
|
||||||
- globalegressips
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- globalingressips
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- deletecollection
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- "serviceexports"
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
---
|
|
||||||
{{- end -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- if .Values.submariner.serviceDiscovery }}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- services
|
|
||||||
- namespaces
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- discovery.k8s.io
|
|
||||||
resources:
|
|
||||||
- endpointslices
|
|
||||||
- endpointslices/restricted
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- deletecollection
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- "gateways"
|
|
||||||
- "globalingressips"
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- "*"
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- services
|
|
||||||
- namespaces
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- discovery.k8s.io
|
|
||||||
resources:
|
|
||||||
- endpointslices
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- deletecollection
|
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- "*"
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- "gateways"
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- "*"
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -6,22 +6,70 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
broker: k8s
|
broker: k8s
|
||||||
brokerK8sApiServer: {{ .Values.broker.server }}
|
brokerK8sApiServer: {{ .Values.broker.server }}
|
||||||
|
{{- if .Values.submariner.brokerK8sSecret }}
|
||||||
|
brokerK8sSecret: {{ .Values.submariner.brokerK8sSecret }}
|
||||||
|
{{- else }}
|
||||||
brokerK8sApiServerToken: {{ .Values.broker.token }}
|
brokerK8sApiServerToken: {{ .Values.broker.token }}
|
||||||
brokerK8sCA: {{ .Values.broker.ca }}
|
brokerK8sCA: {{ .Values.broker.ca }}
|
||||||
|
{{- end }}
|
||||||
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
|
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
|
||||||
|
brokerK8sInsecure: {{ .Values.broker.insecure }}
|
||||||
ceIPSecDebug: {{ .Values.ipsec.debug }}
|
ceIPSecDebug: {{ .Values.ipsec.debug }}
|
||||||
|
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
|
||||||
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
|
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
|
||||||
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
|
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
|
||||||
|
{{- if .Values.ipsec.pskSecret }}
|
||||||
|
ceIPSecPSKSecret: {{ .Values.ipsec.pskSecret }}
|
||||||
|
{{- else }}
|
||||||
ceIPSecPSK: {{ .Values.ipsec.psk }}
|
ceIPSecPSK: {{ .Values.ipsec.psk }}
|
||||||
|
{{- end }}
|
||||||
clusterCIDR: "{{ .Values.submariner.clusterCidr }}"
|
clusterCIDR: "{{ .Values.submariner.clusterCidr }}"
|
||||||
clusterID: {{ .Values.submariner.clusterId }}
|
clusterID: {{ .Values.submariner.clusterId }}
|
||||||
colorCodes: {{ .Values.submariner.colorCodes }}
|
colorCodes: {{ .Values.submariner.colorCodes }}
|
||||||
debug: {{ .Values.submariner.debug }}
|
debug: {{ .Values.submariner.debug }}
|
||||||
|
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
natEnabled: {{ .Values.submariner.natEnabled }}
|
natEnabled: {{ .Values.submariner.natEnabled }}
|
||||||
repository: {{ .Values.submariner.images.repository }}
|
repository: {{ .Values.submariner.images.repository }}
|
||||||
version: {{ .Values.submariner.images.tag }}
|
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }}
|
||||||
|
{{- with .Values.images }}
|
||||||
|
{{- if . }}
|
||||||
|
imageOverrides:
|
||||||
|
{{- if index . "submariner-operator" }}
|
||||||
|
submariner-operator: {{ index . "submariner-operator" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-gateway" }}
|
||||||
|
submariner-gateway: {{ index . "submariner-gateway" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-route-agent" }}
|
||||||
|
submariner-routeagent: {{ index . "submariner-route-agent" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-globalnet" }}
|
||||||
|
submariner-globalnet: {{ index . "submariner-globalnet" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-networkplugin-syncer" }}
|
||||||
|
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "lighthouse-agent" }}
|
||||||
|
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "lighthouse-coredns" }}
|
||||||
|
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
||||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||||
|
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
|
||||||
|
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
|
||||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||||
cableDriver: {{ .Values.submariner.cableDriver }}
|
cableDriver: {{ .Values.submariner.cableDriver }}
|
||||||
|
connectionHealthCheck:
|
||||||
|
enabled: {{ .Values.submariner.healthcheckEnabled }}
|
||||||
|
intervalSeconds: 1
|
||||||
|
maxPacketLossCount: 5
|
||||||
|
{{- with .Values.submariner.coreDNSCustomConfig }}
|
||||||
|
coreDNSCustomConfig:
|
||||||
|
configMapName: {{ .configMapName }}
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
{{- end }}
|
||||||
|
|||||||
@@ -1,71 +0,0 @@
|
|||||||
{{- if .Values.serviceAccounts.operator.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.gateway.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.globalnet.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -5,14 +5,20 @@ submariner:
|
|||||||
clusterCidr: ""
|
clusterCidr: ""
|
||||||
serviceCidr: ""
|
serviceCidr: ""
|
||||||
globalCidr: ""
|
globalCidr: ""
|
||||||
|
clustersetIpCidr: ""
|
||||||
|
clustersetIpEnabled: false
|
||||||
|
brokerK8sSecret: ""
|
||||||
|
loadBalancerEnabled: false
|
||||||
natEnabled: false
|
natEnabled: false
|
||||||
colorCodes: blue
|
colorCodes: blue
|
||||||
debug: false
|
debug: false
|
||||||
serviceDiscovery: true
|
serviceDiscovery: true
|
||||||
cableDriver: "libreswan"
|
cableDriver: "libreswan"
|
||||||
|
healthcheckEnabled: true
|
||||||
|
coreDNSCustomConfig: {}
|
||||||
images:
|
images:
|
||||||
repository: quay.io/submariner
|
repository: quay.io/submariner
|
||||||
tag: "0.7.0"
|
tag: ""
|
||||||
broker:
|
broker:
|
||||||
server: example.k8s.apiserver
|
server: example.k8s.apiserver
|
||||||
token: test
|
token: test
|
||||||
@@ -20,11 +26,12 @@ broker:
|
|||||||
insecure: false
|
insecure: false
|
||||||
ca: ""
|
ca: ""
|
||||||
globalnet: false
|
globalnet: false
|
||||||
rbac:
|
images: {}
|
||||||
create: true
|
|
||||||
ipsec:
|
ipsec:
|
||||||
psk: ""
|
psk: ""
|
||||||
|
pskSecret: ""
|
||||||
debug: false
|
debug: false
|
||||||
|
forceUDPEncaps: false
|
||||||
ikePort: 500
|
ikePort: 500
|
||||||
natPort: 4500
|
natPort: 4500
|
||||||
leadership:
|
leadership:
|
||||||
@@ -34,31 +41,8 @@ leadership:
|
|||||||
operator:
|
operator:
|
||||||
image:
|
image:
|
||||||
repository: quay.io/submariner/submariner-operator
|
repository: quay.io/submariner/submariner-operator
|
||||||
tag: "0.7.0"
|
tag: ""
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
resources: {}
|
resources: {}
|
||||||
tolerations: []
|
tolerations: []
|
||||||
affinity: {}
|
affinity: {}
|
||||||
gateway:
|
|
||||||
image:
|
|
||||||
repository: quay.io/submariner/submariner-gateway
|
|
||||||
tag: "0.7.0"
|
|
||||||
serviceAccounts:
|
|
||||||
operator:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
gateway:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
routeAgent:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
globalnet:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
lighthouseAgent:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
lighthouseCoreDns:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
|
|||||||
@@ -0,0 +1,38 @@
|
|||||||
|
//go:build yamls
|
||||||
|
|
||||||
|
/*
|
||||||
|
SPDX-License-Identifier: Apache-2.0
|
||||||
|
|
||||||
|
Copyright Contributors to the Submariner project.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// Place any runtime dependencies as imports in this file.
|
||||||
|
// Go modules will be forced to download and install them.
|
||||||
|
|
||||||
|
package yamls
|
||||||
|
|
||||||
|
import (
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/broker/broker-client"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/openshift/rbac/submariner-metrics-reader"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-gateway"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-globalnet"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-operator"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-route-agent"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/lighthouse-agent"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/lighthouse-coredns"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/deploy/crds"
|
||||||
|
_ "github.com/submariner-io/submariner/deploy/crds"
|
||||||
|
_ "sigs.k8s.io/mcs-api/config/crd"
|
||||||
|
)
|
||||||
Reference in New Issue
Block a user