Compare commits

..
4 Commits
Author SHA1 Message Date
Daniel FarrellandStephen Kitt fb66cc28b2 Name RBAC fields to match K8s requirements
The colon in these field names isn't allowed by K8s, and fails ct
linting. Use the new names from submariner-operator, which have already
been renamed to fix this.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
(cherry picked from commit c8b09b5c31)
2021-06-29 11:26:41 +02:00
Daniel FarrellandStephen Kitt e13cffdb4d Add required apiVersion field to Chart.yaml
This field is required by standard chart schemas. It should be v2 for
Charts that support Helm v3, as we do.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
(cherry picked from commit df86353f4b)
2021-06-29 11:26:41 +02:00
Steve MattarandStephen Kitt 6a0c5f2c29 fix(rbac): add missing cluster roles to submariner-operator
Signed-off-by: Steve Mattar <smattar@redhat.com>
(cherry picked from commit 12c8e9b3ff)
2021-06-29 11:26:41 +02:00
Automated Release 4126e0fb08 Update base image to use stable branch 'release-0.9'
Signed-off-by: Automated Release <release@submariner.io>
2021-04-30 09:49:39 +00:00
37 changed files with 887 additions and 1617 deletions
+4 -2
View File
@@ -23,9 +23,11 @@ Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
**Anything else we need to know?**: **Anything else we need to know?**:
**Environment**: **Environment**:
- Diagnose information (use `subctl diagnose all`): - Submariner version (use `subctl version`):
- Gather information (use `subctl gather`): - Kubernetes version (use `kubectl version`):
- Cloud provider or hardware configuration: - Cloud provider or hardware configuration:
- OS (e.g: `cat /etc/os-release`):
- Kernel (e.g. `uname -a`):
- Install tools: - Install tools:
- Network plugin and version (if this is a network-related bug): - Network plugin and version (if this is a network-related bug):
- Others: - Others:
+1 -1
View File
@@ -6,7 +6,7 @@ labels: support
--- ---
<!-- <!--
GitHub may not be the right place for support requests. GitHub may not the right place for support requests.
You can also post your question on the [Submariner You can also post your question on the [Submariner
Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner
-13
View File
@@ -1,13 +0,0 @@
<!-- Thanks for sending a pull request! Here are some tips for you:
1. If this is your first time, please read our developer guide: https://submariner.io/development/
2. Ensure you have added the appropriate tests for your PR: https://submariner.io/development/code-review/#test-new-functionality
3. Read the code review guide to ease the review process: https://submariner.io/development/code-review/
4. If the PR is unfinished, mark it as a draft: https://submariner.io/development/code-review/#mark-work-in-progress-prs-as-drafts
5. If you are using CI to debug, use your private fork: https://submariner.io/development/code-review/#use-private-forks-for-debugging-prs-by-running-ci
6. Add labels to the PR as appropriate.
This template is based on the K8s/K8s template:
https://github.com/kubernetes/kubernetes/blob/master/.github/PULL_REQUEST_TEMPLATE.md
-->
+1 -1
View File
@@ -2,7 +2,7 @@
# Configuration for probot-stale - https://github.com/probot/stale # Configuration for probot-stale - https://github.com/probot/stale
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later) # Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
daysUntilStale: 120 daysUntilStale: 60
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed. # Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale. # Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
+4 -4
View File
@@ -5,10 +5,10 @@ on:
pull_request: pull_request:
jobs: jobs:
target_branch: target_devel:
name: PR targets branch name: PR targets release-0.9
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check that the PR targets release-0.12 - name: Check that the PR targets release-0.9
if: ${{ github.base_ref != 'release-0.12' }} if: ${{ github.base_ref != 'release-0.9' }}
run: exit 1 run: exit 1
-39
View File
@@ -1,39 +0,0 @@
---
name: PR Dependencies
on:
issues:
types:
- opened
- edited
- closed
- reopened
- synchronize
pull_request_target:
types:
- opened
- edited
- closed
- reopened
- synchronize
schedule:
- cron: '0 0/6 * * *' # every 6 hours
jobs:
check:
name: Check Dependencies
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
steps:
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
# The label to use to mark dependent issues
label: dependent
# Enable checking for dependencies in issues.
check_issues: on
# A comma-separated list of keywords to mark dependency.
keywords: depends on, Depends on
-37
View File
@@ -1,37 +0,0 @@
---
name: End to End Full
on:
pull_request:
types: [labeled, opened, synchronize, reopened]
jobs:
e2e:
name: E2E
if: contains(github.event.pull_request.labels.*.name, 'ready-to-test')
timeout-minutes: 45
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet']
k8s_version: ['1.23']
lighthouse: ['', 'lighthouse']
include:
- k8s_version: '1.20'
- k8s_version: '1.21'
- k8s_version: '1.22'
steps:
- name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.12
with:
k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.12
+19 -4
View File
@@ -1,5 +1,5 @@
--- ---
name: End to End Default name: End to End Tests
on: on:
pull_request: pull_request:
@@ -9,13 +9,28 @@ jobs:
name: E2E name: E2E
timeout-minutes: 30 timeout-minutes: 30
runs-on: ubuntu-latest runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
cable_driver: ['libreswan', 'wireguard']
globalnet: ['', 'globalnet']
k8s_version: ['1.17.17']
lighthouse: ['', 'lighthouse']
include:
# Recentness of K8s versions are limited by kindest/node image releases
- k8s_version: 1.18.15
- k8s_version: 1.19.7
- k8s_version: 1.20.2
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.12 uses: submariner-io/shipyard/gh-actions/e2e@release-0.9
with:
k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.12 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.9
+4 -5
View File
@@ -8,24 +8,23 @@ on:
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
if: github.repository_owner == 'submariner-io'
timeout-minutes: 30 timeout-minutes: 30
runs-on: ubuntu-latest runs-on: ubuntu-latest
strategy: strategy:
fail-fast: false fail-fast: false
matrix: matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan'] cable_driver: ['libreswan', 'wireguard']
globalnet: ['', 'globalnet'] globalnet: ['', 'globalnet']
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.12 uses: submariner-io/shipyard/gh-actions/e2e@release-0.9
with: with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.12 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.9
+6 -66
View File
@@ -5,85 +5,26 @@ on:
pull_request: pull_request:
jobs: jobs:
apply-suggestions-commits:
name: 'No "Apply suggestions from code review" Commits'
runs-on: ubuntu-latest
steps:
- name: Get PR commits
id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@3efc1387ead42029a0d488ab98f24b7452dc3cde
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: 'Verify no "Apply suggestions from code review" commits'
uses: tim-actions/commit-message-checker-with-regex@e16b08b1a7f5cafeb1f8167de05bf1d40239eb5d
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!.*(apply suggestions from code review))'
flags: 'i'
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
- name: 'Verify no "fixup!" commits'
uses: tim-actions/commit-message-checker-with-regex@e16b08b1a7f5cafeb1f8167de05bf1d40239eb5d
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!fixup!)'
flags: 'i'
error: 'Fixup commits should be squashed into the commits under review'
chart-testing:
name: Helm Chart Linting
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9
- name: Set up Helm
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78
with:
version: v3.6.0
- name: Set up Python
uses: actions/setup-python@bd6b4b6205c4dbad673328db7b31b7fab9e241c0
with:
python-version: '3.x'
- name: Set up helm/chart-testing
uses: helm/chart-testing-action@e8788873172cb653a90ca2e819d79d65a66d4e76
- name: Run helm/chart-testing (lint)
run: ct lint --config ct.yaml
gitlint: gitlint:
name: Commit Message(s) name: Commit Message(s)
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Run gitlint - name: Run gitlint
run: make gitlint run: make gitlint
helm-docs:
name: Helm Docs Generation
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9
- name: Run helm-docs and verify docs are up-to-date
run: make helm-docs
markdown-link-check: markdown-link-check:
name: Markdown Links (modified files) name: Markdown Links (modified files)
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec uses: gaurav-nelson/github-action-markdown-link-check@v1
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes" check-modified-files-only: "yes"
@@ -94,7 +35,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
- name: Run markdownlint - name: Run markdownlint
run: make markdownlint run: make markdownlint
@@ -103,10 +44,9 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
- name: Run yamllint - name: Run yamllint
uses: ibiqlik/action-yamllint@2576378a8e339169678f9939646ee3ee325e845c uses: ibiqlik/action-yamllint@v1
with: with:
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
config_file: .yamllint.yml config_file: .yamllint.yml
strict: true
+3 -4
View File
@@ -8,20 +8,19 @@ on:
jobs: jobs:
markdown-link-check-periodic: markdown-link-check-periodic:
name: Markdown Links (all files) name: Markdown Links (all files)
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec uses: gaurav-nelson/github-action-markdown-link-check@v1
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links - name: Raise an Issue to report broken links
if: ${{ failure() }} if: ${{ failure() }}
uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f uses: peter-evans/create-issue-from-file@v2.3.2
with: with:
title: Broken link detected by CI title: Broken link detected by CI
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
+2 -3
View File
@@ -4,16 +4,15 @@ name: Release Charts
on: on:
push: push:
branches: branches:
- release-0.12 - release-0.9
jobs: jobs:
release: release:
name: Release name: Release
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 uses: actions/checkout@v2
with: with:
fetch-depth: 0 fetch-depth: 0
+9
View File
@@ -0,0 +1,9 @@
[general]
# body-is-missing: Allow commit messages with only a title
# body-min-length: Allow short body lines, like "Relates-to: #issue"
ignore=body-is-missing,body-min-length
[ignore-by-body]
# Dependabot doesn't follow our conventions, unfortunately
regex=^Signed-off-by: dependabot\[bot\](.*)
ignore=all
-3
View File
@@ -5,9 +5,6 @@
}, },
{ {
"pattern": "^http://localhost:" "pattern": "^http://localhost:"
},
{
"pattern": "^https://submariner-io.github.io/submariner-charts/charts"
} }
] ]
} }
-4
View File
@@ -10,7 +10,3 @@ line-length:
no-inline-html: no-inline-html:
allowed_elements: allowed_elements:
- span - span
# Temporary while helm-docs has a bug where maintainer URLs are used raw in MD
# Waiting on: https://github.com/norwoodj/helm-docs/pull/102
no-bare-urls: false
-7
View File
@@ -1,7 +0,0 @@
---
cni: ovn
submariner: true
nodes: control-plane worker worker
clusters:
cluster1:
cluster2:
-6
View File
@@ -1,6 +0,0 @@
---
submariner: true
nodes: control-plane worker
clusters:
cluster1:
cluster2:
-3
View File
@@ -1,3 +0,0 @@
label-approved:
approvals: 2
label: ready-to-test
+1 -3
View File
@@ -1,3 +1 @@
# Auto-generated, do not edit; see CODEOWNERS.in * @mangelajo @Oats87 @skitt @tpantelis
* @Oats87 @skitt @sridhargaddam @tpantelis
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
-5
View File
@@ -1,5 +0,0 @@
@dfarrell07 *.md
@Oats87 *
@skitt *
@sridhargaddam *
@tpantelis *
+1 -3
View File
@@ -1,5 +1,5 @@
ARG BASE_BRANCH ARG BASE_BRANCH
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH} FROM quay.io/submariner/shipyard-dapper-base:release-0.9
ARG DAPPER_HOST_ARCH ARG DAPPER_HOST_ARCH
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \ ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
@@ -9,8 +9,6 @@ ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
WORKDIR ${DAPPER_SOURCE} WORKDIR ${DAPPER_SOURCE}
RUN git config --global --add safe.directory ${DAPPER_SOURCE}
# Override the Helm deployment scripts # Override the Helm deployment scripts
COPY deploy_helm /opt/shipyard/scripts/lib/ COPY deploy_helm /opt/shipyard/scripts/lib/
+6 -20
View File
@@ -1,4 +1,4 @@
BASE_BRANCH ?= release-0.12 BASE_BRANCH ?= release-0.9
export BASE_BRANCH export BASE_BRANCH
ifneq (,$(DAPPER_HOST_ARCH)) ifneq (,$(DAPPER_HOST_ARCH))
@@ -9,10 +9,11 @@ PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent
include $(SHIPYARD_DIR)/Makefile.inc include $(SHIPYARD_DIR)/Makefile.inc
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
ifneq (,$(filter ovn,$(_using))) ifneq (,$(filter ovn,$(_using)))
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings.ovn
else else
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.yml CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
endif endif
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG) override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
@@ -20,8 +21,7 @@ override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
export DEPLOY_ARGS export DEPLOY_ARGS
GH_URL=https://submariner-io.github.io/submariner-charts/charts GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts CHARTS_DIR=charts
CHARTS_VERSION=0.12.2 CHARTS_VERSION=0.7.0
HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url) REPO_URL=$(shell git config remote.origin.url)
# Process extra flags from the `using=a,b,c` optional flag # Process extra flags from the `using=a,b,c` optional flag
@@ -42,20 +42,6 @@ e2e: E2E_ARGS=cluster1 cluster2
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm-docs:
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
cd /tmp && \
curl -sL https://github.com/norwoodj/helm-docs/releases/download/v$(HELM_DOCS_VERSION)/helm-docs_$(HELM_DOCS_VERSION)_Linux_x86_64.tar.gz | tar zx && \
cd -
/tmp/helm-docs
if [ ! -z $(git status --porcelain) ]; then \
echo "Helm docs not up-to-date:"; \
git status --porcelain; \
git diff; \
echo "Run make helm-docs locally to generate updated docs, commit the updates."; \
exit 1; \
fi
release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
git checkout gh-pages git checkout gh-pages
mv *.tgz $(CHARTS_DIR) mv *.tgz $(CHARTS_DIR)
@@ -65,7 +51,7 @@ release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHART
helm repo index $(CHARTS_DIR) --url $(GH_URL); \ helm repo index $(CHARTS_DIR) --url $(GH_URL); \
fi fi
.PHONY: release helm-docs .PHONY: release
else else
-7
View File
@@ -1,12 +1,5 @@
# submariner-charts # submariner-charts
<!-- markdownlint-disable line-length -->
[![CII Best Practices](https://bestpractices.coreinfrastructure.org/projects/4865/badge)](https://bestpractices.coreinfrastructure.org/projects/4865)
[![Release Charts](https://github.com/submariner-io/submariner-charts/workflows/Release%20Charts/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Release+Charts%22)
[![Periodic](https://github.com/submariner-io/submariner-charts/workflows/Periodic/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic)
[![Flake Finder](https://github.com/submariner-io/submariner-charts/workflows/Flake%20Finder/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Flake+Finder%22)
<!-- markdownlint-enable line-length -->
Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/). Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/).
## Development workflow ## Development workflow
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker"
cluster_nodes['cluster2']="control-plane worker"
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker worker"
cluster_nodes['cluster2']="control-plane worker worker"
cluster_cni=( ['cluster1']="ovn" ['cluster2']="ovn" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
-6
View File
@@ -1,6 +0,0 @@
charts:
- submariner-operator
- submariner-k8s-broker
# Tests that maintainer name is valid GitHub account, which isn't what we want
# See: https://github.com/helm/chart-testing/issues/192
validate-maintainers: false
+3 -4
View File
@@ -1,14 +1,13 @@
--- ---
name: submariner-k8s-broker name: submariner-k8s-broker
version: 0.12.2 version: 0.6.0
apiVersion: v2 apiVersion: v2
appVersion: 0.12.2 appVersion: 0.6.0
description: Submariner Kubernetes Broker description: Submariner Kubernetes Broker
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
sources: sources:
- https://submariner-io.github.io/submariner-charts/charts - https://submariner-io.github.io/submariner-charts/charts
maintainers: maintainers:
- name: Contributors to the Submariner project - name: Submariner Developers
email: submariner-dev@googlegroups.com email: submariner-dev@googlegroups.com
url: https://submariner.io/
-26
View File
@@ -1,26 +0,0 @@
# submariner-k8s-broker
![Version: 0.12.2](https://img.shields.io/badge/Version-0.12.2-informational?style=flat-square) ![AppVersion: 0.12.2](https://img.shields.io/badge/AppVersion-0.12.2-informational?style=flat-square)
Submariner Kubernetes Broker
**Homepage:** <https://submariner-io.github.io/>
## Maintainers
| Name | Email | Url |
| ---- | ------ | --- |
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
## Source Code
* <https://submariner-io.github.io/submariner-charts/charts>
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| crd.create | bool | `true` | |
| rbac.create | bool | `true` | |
| serviceAccounts.client.create | bool | `true` | |
| serviceAccounts.client.name | string | `""` | |
+61 -297
View File
@@ -1,333 +1,97 @@
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: clusters.submariner.io name: clusters.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Cluster kind: Cluster
listKind: ClusterList
plural: clusters plural: clusters
singular: cluster
scope: Namespaced scope: Namespaced
versions:
- name: v1
schema:
openAPIV3Schema:
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
properties:
cluster_cidr:
items:
type: string
type: array
cluster_id:
type: string
color_codes:
items:
type: string
type: array
global_cidr:
items:
type: string
type: array
service_cidr:
items:
type: string
type: array
required:
- cluster_cidr
- cluster_id
- color_codes
- global_cidr
- service_cidr
type: object
required:
- spec
type: object
served: true
storage: true
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: endpoints.submariner.io name: endpoints.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Endpoint kind: Endpoint
listKind: EndpointList
plural: endpoints plural: endpoints
singular: endpoint
scope: Namespaced scope: Namespaced
versions:
- name: v1
schema:
openAPIV3Schema:
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
properties:
backend:
type: string
backend_config:
additionalProperties:
type: string
type: object
cable_name:
type: string
cluster_id:
type: string
healthCheckIP:
type: string
hostname:
type: string
nat_enabled:
type: boolean
private_ip:
type: string
public_ip:
type: string
subnets:
items:
type: string
type: array
required:
- backend
- cable_name
- cluster_id
- hostname
- nat_enabled
- private_ip
- public_ip
- subnets
type: object
required:
- spec
type: object
served: true
storage: true
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: gateways.submariner.io name: gateways.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Gateway kind: Gateway
listKind: GatewayList
plural: gateways plural: gateways
singular: gateway
scope: Namespaced scope: Namespaced
versions: additionalPrinterColumns:
- additionalPrinterColumns: - name: ha-status
- description: High availability status of the Gateway
jsonPath: .status.haStatus
name: HA Status
type: string type: string
name: v1 description: High Availability Status of the Gateway
schema: JSONPath: .status.haStatus
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: multiclusterservices.lighthouse.submariner.io
spec:
group: lighthouse.submariner.io
version: v1
names:
kind: MultiClusterService
plural: multiclusterservices
singular: multiclusterservice
scope: Namespaced
validation:
openAPIV3Schema: openAPIV3Schema:
properties: properties:
apiVersion: spec:
description: 'APIVersion defines the versioned schema of this representation properties:
of an object. Servers should convert recognized schemas to the latest clusterServiceInfo:
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' properties:
type: string clusterID:
kind: type: "string"
description: 'Kind is a string value representing the REST resource this clusterDomain:
object represents. Servers may infer this from the endpoint the client type: "string"
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' serviceIP:
type: string type: "string"
port:
type: "integer"
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata: metadata:
type: object name: serviceexports.lighthouse.submariner.io
status: spec:
properties: group: lighthouse.submariner.io
connections: version: v2alpha1
items: names:
properties: kind: ServiceExport
endpoint: plural: serviceexports
properties: singular: serviceexport
backend: scope: Namespaced
type: string ---
backend_config: apiVersion: apiextensions.k8s.io/v1beta1
additionalProperties: kind: CustomResourceDefinition
type: string metadata:
type: object name: serviceimports.lighthouse.submariner.io
cable_name: spec:
type: string group: lighthouse.submariner.io
cluster_id: version: v2alpha1
type: string names:
healthCheckIP: kind: ServiceImport
type: string plural: serviceimports
hostname: singular: serviceimport
type: string scope: Namespaced
nat_enabled:
type: boolean
private_ip:
type: string
public_ip:
type: string
subnets:
items:
type: string
type: array
required:
- backend
- cable_name
- cluster_id
- hostname
- nat_enabled
- private_ip
- public_ip
- subnets
type: object
latency:
description: LatencySpec describes the round trip time information
in nanoseconds for a packet between the gateway pods of two
clusters.
properties:
averageRTT:
format: int64
type: integer
lastRTT:
description: TODO This shall be deleted once the operator
is using the latest. Using Optional to avoid validation
errors when this field is not used.
format: int64
type: integer
maxRTT:
format: int64
type: integer
minRTT:
format: int64
type: integer
stddevRTT:
format: int64
type: integer
type: object
latencyRTT:
description: LatencySpec describes the round trip time information
for a packet between the gateway pods of two clusters.
properties:
average:
type: string
last:
type: string
max:
type: string
min:
type: string
stdDev:
type: string
type: object
status:
type: string
statusMessage:
type: string
required:
- endpoint
- status
- statusMessage
type: object
type: array
haStatus:
type: string
localEndpoint:
properties:
backend:
type: string
backend_config:
additionalProperties:
type: string
type: object
cable_name:
type: string
cluster_id:
type: string
healthCheckIP:
type: string
hostname:
type: string
nat_enabled:
type: boolean
private_ip:
type: string
public_ip:
type: string
subnets:
items:
type: string
type: array
required:
- backend
- cable_name
- cluster_id
- hostname
- nat_enabled
- private_ip
- public_ip
- subnets
type: object
statusFailure:
type: string
version:
type: string
required:
- connections
- haStatus
- localEndpoint
- statusFailure
- version
type: object
required:
- status
type: object
served: true
storage: true
subresources: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
+1 -1
View File
@@ -16,7 +16,7 @@ rules:
resources: ["*"] resources: ["*"]
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"] verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
- apiGroups: ["discovery.k8s.io"] - apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices", "endpointslices/restricted"] resources: ["endpointslices"]
verbs: ["create", "get", "list", "watch","patch", "update", "delete"] verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
- apiGroups: ["multicluster.x-k8s.io"] - apiGroups: ["multicluster.x-k8s.io"]
resources: ["*"] resources: ["*"]
+3 -4
View File
@@ -1,14 +1,13 @@
--- ---
name: submariner-operator name: submariner-operator
version: 0.12.2 version: 0.7.0
apiVersion: v2 apiVersion: v2
appVersion: 0.12.2 appVersion: 0.7.0
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
sources: sources:
- https://submariner-io.github.io/submariner-charts/charts - https://submariner-io.github.io/submariner-charts/charts
maintainers: maintainers:
- name: Contributors to the Submariner project - name: Submariner Developers
email: submariner-dev@googlegroups.com email: submariner-dev@googlegroups.com
url: https://submariner.io/
-71
View File
@@ -1,71 +0,0 @@
# submariner-operator
![Version: 0.12.2](https://img.shields.io/badge/Version-0.12.2-informational?style=flat-square) ![AppVersion: 0.12.2](https://img.shields.io/badge/AppVersion-0.12.2-informational?style=flat-square)
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
**Homepage:** <https://submariner-io.github.io/>
## Maintainers
| Name | Email | Url |
| ---- | ------ | --- |
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
## Source Code
* <https://submariner-io.github.io/submariner-charts/charts>
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| broker.ca | string | `""` | |
| broker.globalnet | bool | `false` | |
| broker.insecure | bool | `false` | |
| broker.namespace | string | `"xyz"` | |
| broker.server | string | `"example.k8s.apiserver"` | |
| broker.token | string | `"test"` | |
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
| gateway.image.tag | string | `"0.12.2"` | |
| ipsec.debug | bool | `false` | |
| ipsec.forceUDPEncaps | bool | `false` | |
| ipsec.ikePort | int | `500` | |
| ipsec.natPort | int | `4500` | |
| ipsec.psk | string | `""` | |
| leadership.leaseDuration | int | `10` | |
| leadership.renewDeadline | int | `5` | |
| leadership.retryPeriod | int | `2` | |
| operator.affinity | object | `{}` | |
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
| operator.image.tag | string | `"0.12.2"` | |
| operator.resources | object | `{}` | |
| operator.tolerations | list | `[]` | |
| rbac.create | bool | `true` | |
| serviceAccounts.gateway.create | bool | `true` | |
| serviceAccounts.gateway.name | string | `""` | |
| serviceAccounts.globalnet.create | bool | `true` | |
| serviceAccounts.globalnet.name | string | `""` | |
| serviceAccounts.lighthouseAgent.create | bool | `true` | |
| serviceAccounts.lighthouseAgent.name | string | `""` | |
| serviceAccounts.lighthouseCoreDns.create | bool | `true` | |
| serviceAccounts.lighthouseCoreDns.name | string | `""` | |
| serviceAccounts.operator.create | bool | `true` | |
| serviceAccounts.operator.name | string | `""` | |
| serviceAccounts.routeAgent.create | bool | `true` | |
| serviceAccounts.routeAgent.name | string | `""` | |
| submariner.cableDriver | string | `"libreswan"` | |
| submariner.clusterCidr | string | `""` | |
| submariner.clusterId | string | `""` | |
| submariner.colorCodes | string | `"blue"` | |
| submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | |
| submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.12.2"` | |
| submariner.natEnabled | bool | `false` | |
| submariner.serviceCidr | string | `""` | |
| submariner.serviceDiscovery | bool | `true` | |
| submariner.token | string | `""` | |
+58 -185
View File
@@ -1,11 +1,10 @@
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.4.1
creationTimestamp: null
name: submariners.submariner.io name: submariners.submariner.io
annotations:
controller-gen.kubebuilder.io/version: v0.3.0
spec: spec:
group: submariner.io group: submariner.io
names: names:
@@ -14,9 +13,9 @@ spec:
plural: submariners plural: submariners
singular: submariner singular: submariner
scope: Namespaced scope: Namespaced
versions: subresources:
- name: v1alpha1 status: {}
schema: validation:
openAPIV3Schema: openAPIV3Schema:
description: Submariner is the Schema for the submariners API description: Submariner is the Schema for the submariners API
properties: properties:
@@ -43,51 +42,24 @@ spec:
type: string type: string
brokerK8sCA: brokerK8sCA:
type: string type: string
brokerK8sInsecure:
type: boolean
brokerK8sRemoteNamespace: brokerK8sRemoteNamespace:
type: string type: string
cableDriver: cableDriver:
type: string type: string
ceIPSecDebug: ceIPSecDebug:
type: boolean type: boolean
ceIPSecForceUDPEncaps:
type: boolean
ceIPSecIKEPort: ceIPSecIKEPort:
type: integer type: integer
ceIPSecNATTPort: ceIPSecNATTPort:
type: integer type: integer
ceIPSecPSK: ceIPSecPSK:
type: string type: string
ceIPSecPreferredServer:
type: boolean
clusterCIDR: clusterCIDR:
type: string type: string
clusterID: clusterID:
type: string type: string
colorCodes: colorCodes:
type: string type: string
connectionHealthCheck:
properties:
enabled:
type: boolean
intervalSeconds:
description: The interval at which health check pings are sent.
format: int64
type: integer
maxPacketLossCount:
description: The maximum number of packets lost at which the health
checker will mark the connection as down.
format: int64
type: integer
type: object
coreDNSCustomConfig:
properties:
configMapName:
type: string
namespace:
type: string
type: object
customDomains: customDomains:
items: items:
type: string type: string
@@ -97,12 +69,6 @@ spec:
type: boolean type: boolean
globalCIDR: globalCIDR:
type: string type: string
imageOverrides:
additionalProperties:
type: string
type: object
loadBalancerEnabled:
type: boolean
namespace: namespace:
type: string type: string
natEnabled: natEnabled:
@@ -139,17 +105,6 @@ spec:
type: string type: string
colorCodes: colorCodes:
type: string type: string
deploymentInfo:
properties:
cloudProvider:
type: string
kubernetesType:
type: string
kubernetesTypeVersion:
type: string
kubernetesVersion:
type: string
type: object
gatewayDaemonSetStatus: gatewayDaemonSetStatus:
properties: properties:
lastResourceVersion: lastResourceVersion:
@@ -159,8 +114,8 @@ spec:
nonReadyContainerStates: nonReadyContainerStates:
items: items:
description: ContainerState holds a possible state of container. description: ContainerState holds a possible state of container.
Only one of its members may be specified. If none of them Only one of its members may be specified. If none of them is
is specified, the default one is ContainerStateWaiting. specified, the default one is ContainerStateWaiting.
properties: properties:
running: running:
description: Details about a running container description: Details about a running container
@@ -186,21 +141,20 @@ spec:
format: date-time format: date-time
type: string type: string
message: message:
description: Message regarding the last termination description: Message regarding the last termination of
of the container the container
type: string type: string
reason: reason:
description: (brief) reason from the last termination description: (brief) reason from the last termination
of the container of the container
type: string type: string
signal: signal:
description: Signal from the last termination of the description: Signal from the last termination of the container
container
format: int32 format: int32
type: integer type: integer
startedAt: startedAt:
description: Time at which previous execution of the description: Time at which previous execution of the container
container started started
format: date-time format: date-time
type: string type: string
required: required:
@@ -210,19 +164,18 @@ spec:
description: Details about a waiting container description: Details about a waiting container
properties: properties:
message: message:
description: Message regarding why the container is description: Message regarding why the container is not
not yet running. yet running.
type: string type: string
reason: reason:
description: (brief) reason the container is not yet description: (brief) reason the container is not yet running.
running.
type: string type: string
type: object type: object
type: object type: object
type: array type: array
status: status:
description: DaemonSetStatus represents the current status of description: DaemonSetStatus represents the current status of a
a daemon set. daemon set.
properties: properties:
collisionCount: collisionCount:
description: Count of hash collisions for the DaemonSet. The description: Count of hash collisions for the DaemonSet. The
@@ -232,11 +185,11 @@ spec:
format: int32 format: int32
type: integer type: integer
conditions: conditions:
description: Represents the latest available observations description: Represents the latest available observations of
of a DaemonSet's current state. a DaemonSet's current state.
items: items:
description: DaemonSetCondition describes the state of a description: DaemonSetCondition describes the state of a DaemonSet
DaemonSet at a certain point. at a certain point.
properties: properties:
lastTransitionTime: lastTransitionTime:
description: Last time the condition transitioned from description: Last time the condition transitioned from
@@ -334,10 +287,6 @@ spec:
cable_name: cable_name:
type: string type: string
cluster_id: cluster_id:
maxLength: 63
minLength: 1
type: string
healthCheckIP:
type: string type: string
hostname: hostname:
type: string type: string
@@ -361,30 +310,10 @@ spec:
- public_ip - public_ip
- subnets - subnets
type: object type: object
latencyRTT:
description: LatencySpec describes the round trip time
information for a packet between the gateway pods of
two clusters.
properties:
average:
type: string
last:
type: string
max:
type: string
min:
type: string
stdDev:
type: string
type: object
status: status:
type: string type: string
statusMessage: statusMessage:
type: string type: string
usingIP:
type: string
usingNAT:
type: boolean
required: required:
- endpoint - endpoint
- status - status
@@ -404,10 +333,6 @@ spec:
cable_name: cable_name:
type: string type: string
cluster_id: cluster_id:
maxLength: 63
minLength: 1
type: string
healthCheckIP:
type: string type: string
hostname: hostname:
type: string type: string
@@ -454,8 +379,8 @@ spec:
nonReadyContainerStates: nonReadyContainerStates:
items: items:
description: ContainerState holds a possible state of container. description: ContainerState holds a possible state of container.
Only one of its members may be specified. If none of them Only one of its members may be specified. If none of them is
is specified, the default one is ContainerStateWaiting. specified, the default one is ContainerStateWaiting.
properties: properties:
running: running:
description: Details about a running container description: Details about a running container
@@ -481,21 +406,20 @@ spec:
format: date-time format: date-time
type: string type: string
message: message:
description: Message regarding the last termination description: Message regarding the last termination of
of the container the container
type: string type: string
reason: reason:
description: (brief) reason from the last termination description: (brief) reason from the last termination
of the container of the container
type: string type: string
signal: signal:
description: Signal from the last termination of the description: Signal from the last termination of the container
container
format: int32 format: int32
type: integer type: integer
startedAt: startedAt:
description: Time at which previous execution of the description: Time at which previous execution of the container
container started started
format: date-time format: date-time
type: string type: string
required: required:
@@ -505,19 +429,18 @@ spec:
description: Details about a waiting container description: Details about a waiting container
properties: properties:
message: message:
description: Message regarding why the container is description: Message regarding why the container is not
not yet running. yet running.
type: string type: string
reason: reason:
description: (brief) reason the container is not yet description: (brief) reason the container is not yet running.
running.
type: string type: string
type: object type: object
type: object type: object
type: array type: array
status: status:
description: DaemonSetStatus represents the current status of description: DaemonSetStatus represents the current status of a
a daemon set. daemon set.
properties: properties:
collisionCount: collisionCount:
description: Count of hash collisions for the DaemonSet. The description: Count of hash collisions for the DaemonSet. The
@@ -527,11 +450,11 @@ spec:
format: int32 format: int32
type: integer type: integer
conditions: conditions:
description: Represents the latest available observations description: Represents the latest available observations of
of a DaemonSet's current state. a DaemonSet's current state.
items: items:
description: DaemonSetCondition describes the state of a description: DaemonSetCondition describes the state of a DaemonSet
DaemonSet at a certain point. at a certain point.
properties: properties:
lastTransitionTime: lastTransitionTime:
description: Last time the condition transitioned from description: Last time the condition transitioned from
@@ -612,36 +535,8 @@ spec:
required: required:
- mismatchedContainerImages - mismatchedContainerImages
type: object type: object
loadBalancerStatus:
properties:
status:
description: LoadBalancerStatus represents the status of a load-balancer.
properties:
ingress:
description: Ingress is a list containing ingress points for
the load-balancer. Traffic intended for the service should
be sent to these ingress points.
items:
description: 'LoadBalancerIngress represents the status
of a load-balancer ingress point: traffic intended for
the service should be sent to an ingress point.'
properties:
hostname:
description: Hostname is set for load-balancer ingress
points that are DNS based (typically AWS load-balancers)
type: string
ip:
description: IP is set for load-balancer ingress points
that are IP based (typically GCE or OpenStack load-balancers)
type: string
type: object
type: array
type: object
type: object
natEnabled: natEnabled:
type: boolean type: boolean
networkPlugin:
type: string
routeAgentDaemonSetStatus: routeAgentDaemonSetStatus:
properties: properties:
lastResourceVersion: lastResourceVersion:
@@ -651,8 +546,8 @@ spec:
nonReadyContainerStates: nonReadyContainerStates:
items: items:
description: ContainerState holds a possible state of container. description: ContainerState holds a possible state of container.
Only one of its members may be specified. If none of them Only one of its members may be specified. If none of them is
is specified, the default one is ContainerStateWaiting. specified, the default one is ContainerStateWaiting.
properties: properties:
running: running:
description: Details about a running container description: Details about a running container
@@ -678,21 +573,20 @@ spec:
format: date-time format: date-time
type: string type: string
message: message:
description: Message regarding the last termination description: Message regarding the last termination of
of the container the container
type: string type: string
reason: reason:
description: (brief) reason from the last termination description: (brief) reason from the last termination
of the container of the container
type: string type: string
signal: signal:
description: Signal from the last termination of the description: Signal from the last termination of the container
container
format: int32 format: int32
type: integer type: integer
startedAt: startedAt:
description: Time at which previous execution of the description: Time at which previous execution of the container
container started started
format: date-time format: date-time
type: string type: string
required: required:
@@ -702,19 +596,18 @@ spec:
description: Details about a waiting container description: Details about a waiting container
properties: properties:
message: message:
description: Message regarding why the container is description: Message regarding why the container is not
not yet running. yet running.
type: string type: string
reason: reason:
description: (brief) reason the container is not yet description: (brief) reason the container is not yet running.
running.
type: string type: string
type: object type: object
type: object type: object
type: array type: array
status: status:
description: DaemonSetStatus represents the current status of description: DaemonSetStatus represents the current status of a
a daemon set. daemon set.
properties: properties:
collisionCount: collisionCount:
description: Count of hash collisions for the DaemonSet. The description: Count of hash collisions for the DaemonSet. The
@@ -724,11 +617,11 @@ spec:
format: int32 format: int32
type: integer type: integer
conditions: conditions:
description: Represents the latest available observations description: Represents the latest available observations of
of a DaemonSet's current state. a DaemonSet's current state.
items: items:
description: DaemonSetCondition describes the state of a description: DaemonSetCondition describes the state of a DaemonSet
DaemonSet at a certain point. at a certain point.
properties: properties:
lastTransitionTime: lastTransitionTime:
description: Last time the condition transitioned from description: Last time the condition transitioned from
@@ -816,10 +709,11 @@ spec:
- natEnabled - natEnabled
type: object type: object
type: object type: object
version: v1alpha1
versions:
- name: v1alpha1
served: true served: true
storage: true storage: true
subresources:
status: {}
status: status:
acceptedNames: acceptedNames:
kind: "" kind: ""
@@ -831,7 +725,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
annotations: annotations:
controller-gen.kubebuilder.io/version: v0.4.1 controller-gen.kubebuilder.io/version: v0.3.0
creationTimestamp: null creationTimestamp: null
name: servicediscoveries.submariner.io name: servicediscoveries.submariner.io
spec: spec:
@@ -869,19 +763,10 @@ spec:
type: string type: string
brokerK8sCA: brokerK8sCA:
type: string type: string
brokerK8sInsecure:
type: boolean
brokerK8sRemoteNamespace: brokerK8sRemoteNamespace:
type: string type: string
clusterID: clusterID:
type: string type: string
coreDNSCustomConfig:
properties:
configMapName:
type: string
namespace:
type: string
type: object
customDomains: customDomains:
items: items:
type: string type: string
@@ -912,18 +797,6 @@ spec:
type: object type: object
status: status:
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
properties:
deploymentInfo:
properties:
cloudProvider:
type: string
kubernetesType:
type: string
kubernetesTypeVersion:
type: string
kubernetesVersion:
type: string
type: object
type: object type: object
type: object type: object
served: true served: true
+2 -8
View File
@@ -13,7 +13,7 @@ questions:
type: string type: string
label: Submariner Operator Image Repository label: Submariner Operator Image Repository
- variable: operator.image.tag - variable: operator.image.tag
default: "0.12.2" default: "0.7.0"
description: "Submariner Operator Image Tag" description: "Submariner Operator Image Tag"
type: string type: string
label: Submariner Operator Image Tag label: Submariner Operator Image Tag
@@ -31,7 +31,7 @@ questions:
type: string type: string
label: Submariner Repository label: Submariner Repository
- variable: submariner.images.tag - variable: submariner.images.tag
default: "0.12.2" default: "0.7.0"
description: "Submariner Images Tag (shared for all non-operator images)" description: "Submariner Images Tag (shared for all non-operator images)"
type: string type: string
label: Submariner Images Tag label: Submariner Images Tag
@@ -136,9 +136,3 @@ questions:
group: "Advanced Configuration" group: "Advanced Configuration"
description: "Cable driver implementation" description: "Cable driver implementation"
label: "Cable Driver" label: "Cable Driver"
- variable: submariner.healthcheckEnabled
type: boolean
default: true
group: "Advanced Configuration"
description: "Disable Healthcheck"
label: "Healthcheck Disabled"
+1 -84
View File
@@ -439,21 +439,6 @@ rules:
verbs: verbs:
- get - get
- list - list
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
- watch
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -474,29 +459,6 @@ roleRef:
name: {{ template "submariner.fullname" . }} name: {{ template "submariner.fullname" . }}
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: submariner-metrics-reader
namespace: {{ .Release.Namespace }}
rules:
- apiGroups: [""]
resources: ["pods", "services", "endpoints"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-submariner-metrics
subjects:
- kind: ServiceAccount
name: prometheus-k8s
namespace: openshift-monitoring
roleRef:
kind: Role
name: submariner-metrics-reader
apiGroup: rbac.authorization.k8s.io
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole kind: ClusterRole
metadata: metadata:
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:gateway
@@ -678,25 +640,14 @@ rules:
- "" - ""
resources: resources:
- pods - pods
- services
- namespaces - namespaces
- nodes - nodes
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- update - update
- apiGroups:
- ""
resources:
- services
verbs:
- create
- get
- list
- watch
- update
- delete
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
@@ -706,29 +657,6 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- submariner.io
resources:
- clusterglobalegressips
- globalegressips
verbs:
- create
- get
- list
- watch
- update
- apiGroups:
- submariner.io
resources:
- globalingressips
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
@@ -737,15 +665,6 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- network.openshift.io
resources:
- service/externalips
verbs:
- create
- get
- list
- delete
--- ---
{{- end -}} {{- end -}}
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -792,7 +711,6 @@ rules:
- discovery.k8s.io - discovery.k8s.io
resources: resources:
- endpointslices - endpointslices
- endpointslices/restricted
verbs: verbs:
- create - create
- get - get
@@ -805,7 +723,6 @@ rules:
- submariner.io - submariner.io
resources: resources:
- "gateways" - "gateways"
- "globalingressips"
verbs: verbs:
- get - get
- list - list
@@ -9,9 +9,7 @@ spec:
brokerK8sApiServerToken: {{ .Values.broker.token }} brokerK8sApiServerToken: {{ .Values.broker.token }}
brokerK8sCA: {{ .Values.broker.ca }} brokerK8sCA: {{ .Values.broker.ca }}
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }} brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
brokerK8sInsecure: {{ .Values.broker.insecure }}
ceIPSecDebug: {{ .Values.ipsec.debug }} ceIPSecDebug: {{ .Values.ipsec.debug }}
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }} ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
ceIPSecNATTPort: {{ .Values.ipsec.natPort }} ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
ceIPSecPSK: {{ .Values.ipsec.psk }} ceIPSecPSK: {{ .Values.ipsec.psk }}
@@ -27,12 +25,3 @@ spec:
globalCIDR: "{{ .Values.submariner.globalCidr }}" globalCIDR: "{{ .Values.submariner.globalCidr }}"
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }} serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }} cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck:
enabled: {{ .Values.submariner.healthcheckEnabled }}
intervalSeconds: 1
maxPacketLossCount: 5
{{- with .Values.submariner.coreDNSCustomConfig }}
coreDNSCustomConfig:
configmapName: {{ .configmapName }}
namespace: {{ .namespace }}
{{- end }}
+3 -6
View File
@@ -10,11 +10,9 @@ submariner:
debug: false debug: false
serviceDiscovery: true serviceDiscovery: true
cableDriver: "libreswan" cableDriver: "libreswan"
healthcheckEnabled: true
coreDNSCustomConfig: {}
images: images:
repository: quay.io/submariner repository: quay.io/submariner
tag: "0.12.2" tag: "0.7.0"
broker: broker:
server: example.k8s.apiserver server: example.k8s.apiserver
token: test token: test
@@ -27,7 +25,6 @@ rbac:
ipsec: ipsec:
psk: "" psk: ""
debug: false debug: false
forceUDPEncaps: false
ikePort: 500 ikePort: 500
natPort: 4500 natPort: 4500
leadership: leadership:
@@ -37,7 +34,7 @@ leadership:
operator: operator:
image: image:
repository: quay.io/submariner/submariner-operator repository: quay.io/submariner/submariner-operator
tag: "0.12.2" tag: "0.7.0"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
resources: {} resources: {}
tolerations: [] tolerations: []
@@ -45,7 +42,7 @@ operator:
gateway: gateway:
image: image:
repository: quay.io/submariner/submariner-gateway repository: quay.io/submariner/submariner-gateway
tag: "0.12.2" tag: "0.7.0"
serviceAccounts: serviceAccounts:
operator: operator:
create: true create: true