mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-22 20:10:34 +00:00
Compare commits
12
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
48e25395fa | ||
|
|
fc9f576a27 | ||
|
|
ece52e9f15 | ||
|
|
f5953f0440 | ||
|
|
3f84dc6055 | ||
|
|
2f47c2e263 | ||
|
|
3c297a818a | ||
|
|
64d3343e91 | ||
|
|
5c93ef310a | ||
|
|
2a6a7ecbe2 | ||
|
|
353261f2e7 | ||
|
|
a8d5a9da7b |
+10
-35
@@ -5,43 +5,18 @@ updates:
|
||||
directory: '/'
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.13"
|
||||
schedule:
|
||||
interval: monthly
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.14"
|
||||
schedule:
|
||||
interval: monthly
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.15"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.16"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.17"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.18"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
|
||||
@@ -0,0 +1,57 @@
|
||||
---
|
||||
# Configuration for probot-stale - https://github.com/probot/stale
|
||||
|
||||
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
|
||||
daysUntilStale: 120
|
||||
|
||||
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
|
||||
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
|
||||
daysUntilClose: 7
|
||||
|
||||
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
|
||||
onlyLabels: []
|
||||
|
||||
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
|
||||
exemptLabels:
|
||||
- security
|
||||
- confirmed
|
||||
|
||||
# Set to true to ignore issues in a project (defaults to false)
|
||||
exemptProjects: false
|
||||
|
||||
# Set to true to ignore issues in a milestone (defaults to false)
|
||||
exemptMilestones: false
|
||||
|
||||
# Set to true to ignore issues with an assignee (defaults to false)
|
||||
exemptAssignees: false
|
||||
|
||||
# Label to use when marking as stale
|
||||
staleLabel: wontfix
|
||||
|
||||
# Comment to post when marking as stale. Set to `false` to disable
|
||||
markComment: >
|
||||
This issue has been automatically marked as stale because it has not had
|
||||
activity for 60 days. It will be closed if no further activity occurs.
|
||||
Please make a comment if this issue/pr is still valid. Thank you
|
||||
for your contributions.
|
||||
|
||||
# Comment to post when removing the stale label.
|
||||
# unmarkComment: >
|
||||
# Your comment here.
|
||||
|
||||
# Comment to post when closing a stale Issue or Pull Request.
|
||||
# closeComment: >
|
||||
# Your comment here.
|
||||
|
||||
# Limit the number of actions per hour, from 1-30. Default is 30
|
||||
limitPerRun: 30
|
||||
|
||||
# Limit to only `issues` or `pulls`
|
||||
# only: issues
|
||||
|
||||
pulls:
|
||||
daysUntilStale: 30
|
||||
markComment: >
|
||||
This pull request has been automatically marked as stale because it has not had
|
||||
recent activity. It will be closed if no further activity occurs. Thank you
|
||||
for your contributions.
|
||||
@@ -11,6 +11,6 @@ jobs:
|
||||
name: PR targets branch
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check that the PR targets release-0.19
|
||||
if: ${{ github.base_ref != 'release-0.19' }}
|
||||
- name: Check that the PR targets release-0.16
|
||||
if: ${{ github.base_ref != 'release-0.16' }}
|
||||
run: exit 1
|
||||
|
||||
@@ -18,22 +18,22 @@ jobs:
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
# Run most tests against the latest K8s version
|
||||
k8s_version: ['k8s-latest']
|
||||
k8s_version: ['1.25']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
include:
|
||||
# Bottom of supported K8s version range
|
||||
- k8s_version: 'k8s-oldest-supported'
|
||||
- k8s_version: '1.22'
|
||||
- k8s_version: '1.23'
|
||||
- k8s_version: '1.24'
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.16
|
||||
with:
|
||||
k8s_version: ${{ matrix.k8s_version }}
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.16
|
||||
|
||||
@@ -13,11 +13,11 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.16
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.16
|
||||
|
||||
@@ -21,13 +21,13 @@ jobs:
|
||||
lighthouse: ['', 'lighthouse']
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.16
|
||||
with:
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.16
|
||||
|
||||
@@ -13,7 +13,7 @@ jobs:
|
||||
steps:
|
||||
- name: Get PR commits
|
||||
id: 'get-pr-commits'
|
||||
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d
|
||||
uses: tim-actions/get-pr-commits@3efc1387ead42029a0d488ab98f24b7452dc3cde
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
@@ -38,20 +38,20 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310
|
||||
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78
|
||||
with:
|
||||
version: v3.6.0
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97
|
||||
uses: actions/setup-python@65d7f2d534ac1bc67fcd62888c5f4f3d2cb2b236
|
||||
with:
|
||||
python-version: '3.13.x'
|
||||
python-version: '3.x'
|
||||
|
||||
- name: Set up helm/chart-testing
|
||||
uses: helm/chart-testing-action@6ec842c01de15ebb84c8627d2744a0c2f2755c9f
|
||||
uses: helm/chart-testing-action@b43128a8b25298e1e7b043b78ea6613844e079b1
|
||||
|
||||
- name: Set up local helm repo
|
||||
run: make local-helm-repo
|
||||
@@ -64,7 +64,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Run gitlint
|
||||
@@ -75,7 +75,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
|
||||
- name: Run helm-docs and verify docs are up-to-date
|
||||
run: make helm-docs
|
||||
@@ -85,10 +85,10 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
check-modified-files-only: "yes"
|
||||
@@ -99,7 +99,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
- name: Run markdownlint
|
||||
run: make markdownlint
|
||||
|
||||
@@ -108,6 +108,6 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
- name: Run yamllint
|
||||
run: make yamllint
|
||||
|
||||
@@ -16,16 +16,16 @@ jobs:
|
||||
issues: write
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
|
||||
- name: Raise an Issue to report broken links
|
||||
if: ${{ failure() }}
|
||||
uses: peter-evans/create-issue-from-file@fca9117c27cdc29c6c4db3b86c48e4115a786710
|
||||
uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f
|
||||
with:
|
||||
title: Broken link detected by CI
|
||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||
|
||||
@@ -4,7 +4,7 @@ name: Release Charts
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- release-0.19
|
||||
- release-0.16
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
@@ -16,7 +16,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
|
||||
@@ -1,32 +0,0 @@
|
||||
---
|
||||
name: Stale
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "0 0 * * *"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
name: Close Stale Issues and PRs
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
steps:
|
||||
- uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93
|
||||
with:
|
||||
days-before-issue-stale: 120
|
||||
days-before-pr-stale: 14
|
||||
exempt-issue-labels: 'confirmed,security'
|
||||
exempt-pr-labels: 'confirmed,security'
|
||||
stale-issue-label: 'stale'
|
||||
stale-issue-message: |
|
||||
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||
activity occurs. Thank you for your contributions.
|
||||
stale-pr-label: 'stale'
|
||||
stale-pr-message: |
|
||||
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||
activity occurs. Thank you for your contributions.
|
||||
@@ -3,6 +3,5 @@
|
||||
.shflags
|
||||
*.tgz
|
||||
Makefile.dapper
|
||||
Makefile.shipyard
|
||||
Dockerfile.*
|
||||
helm_repo
|
||||
|
||||
+2
-3
@@ -1,4 +1,3 @@
|
||||
# Auto-generated, do not edit; see CODEOWNERS.in
|
||||
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
|
||||
* @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
|
||||
+1
-5
@@ -1,9 +1,5 @@
|
||||
@aswinsuryan Makefile
|
||||
@dfarrell07 *.md Makefile
|
||||
@maayanf24 Makefile
|
||||
@dfarrell07 *.md
|
||||
@Oats87 *
|
||||
@skitt *
|
||||
@sridhargaddam *
|
||||
@tpantelis *
|
||||
@vthapar *
|
||||
@yboaron Makefile
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
BASE_BRANCH ?= release-0.19
|
||||
BASE_BRANCH ?= release-0.16
|
||||
export BASE_BRANCH
|
||||
export HELM_REPO_LOCATION=./helm_repo
|
||||
|
||||
@@ -17,7 +17,7 @@ endif
|
||||
export DEPLOYTOOL = helm
|
||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||
CHARTS_DIR=charts
|
||||
CHARTS_VERSION=0.19.4
|
||||
CHARTS_VERSION=0.16.2
|
||||
HELM_DOCS_VERSION=0.15.0
|
||||
REPO_URL=$(shell git config remote.origin.url)
|
||||
|
||||
|
||||
@@ -58,8 +58,6 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| submariner.coreDNSCustomConfig | object | `{}` | |
|
||||
| submariner.debug | bool | `false` | |
|
||||
| submariner.globalCidr | string | `""` | |
|
||||
| submariner.clustersetIpCidr | string | `""` | |
|
||||
| submariner.clustersetIpEnabled | bool | `false` | |
|
||||
| submariner.healthcheckEnabled | bool | `true` | |
|
||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||
| submariner.images.tag | string | `"0.14.0"` | |
|
||||
|
||||
@@ -3,7 +3,8 @@ apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
annotations:
|
||||
controller-gen.kubebuilder.io/version: v0.12.1
|
||||
controller-gen.kubebuilder.io/version: v0.4.1
|
||||
creationTimestamp: null
|
||||
name: submariners.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
@@ -17,7 +18,7 @@ spec:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
description: Submariner is the Schema for the submariners API.
|
||||
description: Submariner is the Schema for the submariners API
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
@@ -32,72 +33,43 @@ spec:
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
description: SubmarinerSpec defines the desired state of Submariner.
|
||||
description: SubmarinerSpec defines the desired state of Submariner
|
||||
properties:
|
||||
airGappedDeployment:
|
||||
type: boolean
|
||||
broker:
|
||||
description: Type of broker (must be "k8s").
|
||||
type: string
|
||||
brokerK8sApiServer:
|
||||
description: The broker API URL.
|
||||
type: string
|
||||
brokerK8sApiServerToken:
|
||||
description: The broker API Token.
|
||||
type: string
|
||||
brokerK8sCA:
|
||||
description: The broker certificate authority.
|
||||
type: string
|
||||
brokerK8sInsecure:
|
||||
type: boolean
|
||||
brokerK8sRemoteNamespace:
|
||||
description: The Broker namespace.
|
||||
type: string
|
||||
brokerK8sSecret:
|
||||
type: string
|
||||
cableDriver:
|
||||
description: Cable driver implementation - any of [libreswan, wireguard,
|
||||
vxlan].
|
||||
type: string
|
||||
ceIPSecDebug:
|
||||
description: Enable logging IPsec debugging information.
|
||||
type: boolean
|
||||
ceIPSecForceUDPEncaps:
|
||||
description: Force UDP encapsulation for IPsec.
|
||||
type: boolean
|
||||
ceIPSecIKEPort:
|
||||
description: The IPsec IKE port (500 usually).
|
||||
type: integer
|
||||
ceIPSecNATTPort:
|
||||
description: The IPsec NAT traversal port (4500 usually).
|
||||
type: integer
|
||||
ceIPSecPSK:
|
||||
description: The IPsec Pre-Shared Key which must be identical in all
|
||||
route agents across the cluster.
|
||||
type: string
|
||||
ceIPSecPSKSecret:
|
||||
type: string
|
||||
ceIPSecPreferredServer:
|
||||
description: Enable this cluster as a preferred server for data-plane
|
||||
connections.
|
||||
type: boolean
|
||||
clusterCIDR:
|
||||
description: The cluster CIDR.
|
||||
type: string
|
||||
clusterID:
|
||||
description: The cluster ID used to identify the tunnels.
|
||||
type: string
|
||||
clustersetIPCIDR:
|
||||
description: ClustersetIP CIDR for allocating ClustersetIPs to exported
|
||||
services.
|
||||
type: string
|
||||
colorCodes:
|
||||
type: string
|
||||
connectionHealthCheck:
|
||||
description: The gateway connection health check.
|
||||
properties:
|
||||
enabled:
|
||||
description: Enable the connection health check.
|
||||
type: boolean
|
||||
intervalSeconds:
|
||||
description: The interval at which health check pings are sent.
|
||||
@@ -110,111 +82,47 @@ spec:
|
||||
type: integer
|
||||
type: object
|
||||
coreDNSCustomConfig:
|
||||
description: Name of the custom CoreDNS configmap to configure forwarding
|
||||
to Lighthouse. It should be in <namespace>/<name> format where <namespace>
|
||||
is optional and defaults to kube-system.
|
||||
properties:
|
||||
configMapName:
|
||||
description: Name of the custom CoreDNS configmap.
|
||||
type: string
|
||||
namespace:
|
||||
description: Namespace of the custom CoreDNS configmap.
|
||||
type: string
|
||||
type: object
|
||||
customDomains:
|
||||
description: List of domains to use for multi-cluster service discovery.
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
x-kubernetes-list-type: set
|
||||
debug:
|
||||
description: Enable operator debugging.
|
||||
type: boolean
|
||||
globalCIDR:
|
||||
description: The Global CIDR super-net range for allocating GlobalCIDRs
|
||||
to each cluster.
|
||||
type: string
|
||||
haltOnCertificateError:
|
||||
description: Halt on certificate error (so the pod gets restarted).
|
||||
type: boolean
|
||||
imageOverrides:
|
||||
additionalProperties:
|
||||
type: string
|
||||
description: Override component images.
|
||||
type: object
|
||||
loadBalancerEnabled:
|
||||
description: Enable automatic Load Balancer in front of the gateways.
|
||||
type: boolean
|
||||
namespace:
|
||||
description: The namespace in which to deploy the submariner operator.
|
||||
type: string
|
||||
natEnabled:
|
||||
description: Enable NAT between clusters.
|
||||
type: boolean
|
||||
nodeSelector:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
repository:
|
||||
description: The image repository.
|
||||
type: string
|
||||
serviceCIDR:
|
||||
description: The service CIDR.
|
||||
type: string
|
||||
serviceDiscoveryEnabled:
|
||||
description: Enable support for Service Discovery (Lighthouse).
|
||||
type: boolean
|
||||
clustersetIPEnabled:
|
||||
description: Enable ClustersetIP default for services exported on this
|
||||
cluster.
|
||||
type: boolean
|
||||
tolerations:
|
||||
items:
|
||||
description: The pod this Toleration is attached to tolerates any
|
||||
taint that matches the triple <key,value,effect> using the matching
|
||||
operator <operator>.
|
||||
properties:
|
||||
effect:
|
||||
description: Effect indicates the taint effect to match. Empty
|
||||
means match all taint effects. When specified, allowed values
|
||||
are NoSchedule, PreferNoSchedule and NoExecute.
|
||||
type: string
|
||||
key:
|
||||
description: Key is the taint key that the toleration applies
|
||||
to. Empty means match all taint keys. If the key is empty,
|
||||
operator must be Exists; this combination means to match all
|
||||
values and all keys.
|
||||
type: string
|
||||
operator:
|
||||
description: Operator represents a key's relationship to the
|
||||
value. Valid operators are Exists and Equal. Defaults to Equal.
|
||||
Exists is equivalent to wildcard for value, so that a pod
|
||||
can tolerate all taints of a particular category.
|
||||
type: string
|
||||
tolerationSeconds:
|
||||
description: TolerationSeconds represents the period of time
|
||||
the toleration (which must be of effect NoExecute, otherwise
|
||||
this field is ignored) tolerates the taint. By default, it
|
||||
is not set, which means tolerate the taint forever (do not
|
||||
evict). Zero and negative values will be treated as 0 (evict
|
||||
immediately) by the system.
|
||||
format: int64
|
||||
type: integer
|
||||
value:
|
||||
description: Value is the taint value the toleration matches
|
||||
to. If the operator is Exists, the value should be empty,
|
||||
otherwise just a regular string.
|
||||
type: string
|
||||
type: object
|
||||
type: array
|
||||
version:
|
||||
description: The image tag.
|
||||
type: string
|
||||
required:
|
||||
- broker
|
||||
- brokerK8sApiServer
|
||||
- brokerK8sApiServerToken
|
||||
- brokerK8sCA
|
||||
- brokerK8sRemoteNamespace
|
||||
- ceIPSecDebug
|
||||
- ceIPSecPSK
|
||||
- clusterCIDR
|
||||
- clusterID
|
||||
- debug
|
||||
@@ -223,23 +131,15 @@ spec:
|
||||
- serviceCIDR
|
||||
type: object
|
||||
status:
|
||||
description: SubmarinerStatus defines the observed state of Submariner.
|
||||
description: SubmarinerStatus defines the observed state of Submariner
|
||||
properties:
|
||||
airGappedDeployment:
|
||||
type: boolean
|
||||
clusterCIDR:
|
||||
description: The current cluster CIDR.
|
||||
type: string
|
||||
clusterID:
|
||||
description: The current cluster ID.
|
||||
type: string
|
||||
clustersetIPCIDR:
|
||||
description: The current clustersetIP CIDR.
|
||||
type: string
|
||||
colorCodes:
|
||||
type: string
|
||||
deploymentInfo:
|
||||
description: Information about the deployment.
|
||||
properties:
|
||||
cloudProvider:
|
||||
type: string
|
||||
@@ -251,7 +151,6 @@ spec:
|
||||
type: string
|
||||
type: object
|
||||
gatewayDaemonSetStatus:
|
||||
description: The status of the gateway DaemonSet.
|
||||
properties:
|
||||
lastResourceVersion:
|
||||
type: string
|
||||
@@ -275,7 +174,7 @@ spec:
|
||||
description: Details about a terminated container
|
||||
properties:
|
||||
containerID:
|
||||
description: Container's ID in the format '<type>://<container_id>'
|
||||
description: Container's ID in the format 'docker://<container_id>'
|
||||
type: string
|
||||
exitCode:
|
||||
description: Exit status from the last termination of
|
||||
@@ -388,9 +287,9 @@ spec:
|
||||
format: int32
|
||||
type: integer
|
||||
numberReady:
|
||||
description: numberReady is the number of nodes that should
|
||||
be running the daemon pod and have one or more of the daemon
|
||||
pod running with a Ready Condition.
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and ready.
|
||||
format: int32
|
||||
type: integer
|
||||
numberUnavailable:
|
||||
@@ -419,7 +318,6 @@ spec:
|
||||
- mismatchedContainerImages
|
||||
type: object
|
||||
gateways:
|
||||
description: Status of the gateways in the cluster.
|
||||
items:
|
||||
properties:
|
||||
connections:
|
||||
@@ -546,10 +444,8 @@ spec:
|
||||
type: object
|
||||
type: array
|
||||
globalCIDR:
|
||||
description: The current global CIDR.
|
||||
type: string
|
||||
globalnetDaemonSetStatus:
|
||||
description: The status of the Globalnet DaemonSet.
|
||||
properties:
|
||||
lastResourceVersion:
|
||||
type: string
|
||||
@@ -573,7 +469,7 @@ spec:
|
||||
description: Details about a terminated container
|
||||
properties:
|
||||
containerID:
|
||||
description: Container's ID in the format '<type>://<container_id>'
|
||||
description: Container's ID in the format 'docker://<container_id>'
|
||||
type: string
|
||||
exitCode:
|
||||
description: Exit status from the last termination of
|
||||
@@ -686,9 +582,9 @@ spec:
|
||||
format: int32
|
||||
type: integer
|
||||
numberReady:
|
||||
description: numberReady is the number of nodes that should
|
||||
be running the daemon pod and have one or more of the daemon
|
||||
pod running with a Ready Condition.
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and ready.
|
||||
format: int32
|
||||
type: integer
|
||||
numberUnavailable:
|
||||
@@ -717,7 +613,6 @@ spec:
|
||||
- mismatchedContainerImages
|
||||
type: object
|
||||
loadBalancerStatus:
|
||||
description: The status of the load balancer DaemonSet.
|
||||
properties:
|
||||
status:
|
||||
description: LoadBalancerStatus represents the status of a load-balancer.
|
||||
@@ -739,53 +634,15 @@ spec:
|
||||
description: IP is set for load-balancer ingress points
|
||||
that are IP based (typically GCE or OpenStack load-balancers)
|
||||
type: string
|
||||
ports:
|
||||
description: Ports is a list of records of service ports
|
||||
If used, every port defined in the service should
|
||||
have an entry in it
|
||||
items:
|
||||
properties:
|
||||
error:
|
||||
description: 'Error is to record the problem with
|
||||
the service port The format of the error shall
|
||||
comply with the following rules: - built-in
|
||||
error values shall be specified in this file
|
||||
and those shall use CamelCase names - cloud
|
||||
provider specific error values must have names
|
||||
that comply with the format foo.example.com/CamelCase.
|
||||
--- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)'
|
||||
maxLength: 316
|
||||
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||
type: string
|
||||
port:
|
||||
description: Port is the port number of the service
|
||||
port of which status is recorded here
|
||||
format: int32
|
||||
type: integer
|
||||
protocol:
|
||||
default: TCP
|
||||
description: 'Protocol is the protocol of the
|
||||
service port of which status is recorded here
|
||||
The supported values are: "TCP", "UDP", "SCTP"'
|
||||
type: string
|
||||
required:
|
||||
- port
|
||||
- protocol
|
||||
type: object
|
||||
type: array
|
||||
x-kubernetes-list-type: atomic
|
||||
type: object
|
||||
type: array
|
||||
type: object
|
||||
type: object
|
||||
natEnabled:
|
||||
description: The current NAT status.
|
||||
type: boolean
|
||||
networkPlugin:
|
||||
description: The current network plugin.
|
||||
type: string
|
||||
routeAgentDaemonSetStatus:
|
||||
description: The status of the route agent DaemonSet.
|
||||
properties:
|
||||
lastResourceVersion:
|
||||
type: string
|
||||
@@ -809,7 +666,7 @@ spec:
|
||||
description: Details about a terminated container
|
||||
properties:
|
||||
containerID:
|
||||
description: Container's ID in the format '<type>://<container_id>'
|
||||
description: Container's ID in the format 'docker://<container_id>'
|
||||
type: string
|
||||
exitCode:
|
||||
description: Exit status from the last termination of
|
||||
@@ -922,9 +779,9 @@ spec:
|
||||
format: int32
|
||||
type: integer
|
||||
numberReady:
|
||||
description: numberReady is the number of nodes that should
|
||||
be running the daemon pod and have one or more of the daemon
|
||||
pod running with a Ready Condition.
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and ready.
|
||||
format: int32
|
||||
type: integer
|
||||
numberUnavailable:
|
||||
@@ -953,11 +810,6 @@ spec:
|
||||
- mismatchedContainerImages
|
||||
type: object
|
||||
serviceCIDR:
|
||||
description: The current service CIDR.
|
||||
type: string
|
||||
version:
|
||||
description: The image version in use by the various Submariner DaemonSets
|
||||
and Deployments.
|
||||
type: string
|
||||
required:
|
||||
- clusterID
|
||||
@@ -968,12 +820,19 @@ spec:
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
status:
|
||||
acceptedNames:
|
||||
kind: ""
|
||||
plural: ""
|
||||
conditions: []
|
||||
storedVersions: []
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
annotations:
|
||||
controller-gen.kubebuilder.io/version: v0.12.1
|
||||
controller-gen.kubebuilder.io/version: v0.4.1
|
||||
creationTimestamp: null
|
||||
name: servicediscoveries.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
@@ -987,7 +846,7 @@ spec:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
description: ServiceDiscovery is the Schema for the servicediscoveries API.
|
||||
description: ServiceDiscovery is the Schema for the servicediscoveries API
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
@@ -1002,7 +861,7 @@ spec:
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery.
|
||||
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery
|
||||
properties:
|
||||
brokerK8sApiServer:
|
||||
type: string
|
||||
@@ -1014,19 +873,13 @@ spec:
|
||||
type: boolean
|
||||
brokerK8sRemoteNamespace:
|
||||
type: string
|
||||
brokerK8sSecret:
|
||||
type: string
|
||||
clusterID:
|
||||
type: string
|
||||
clustersetIPCIDR:
|
||||
type: string
|
||||
coreDNSCustomConfig:
|
||||
properties:
|
||||
configMapName:
|
||||
description: Name of the custom CoreDNS configmap.
|
||||
type: string
|
||||
namespace:
|
||||
description: Namespace of the custom CoreDNS configmap.
|
||||
type: string
|
||||
type: object
|
||||
customDomains:
|
||||
@@ -1038,72 +891,27 @@ spec:
|
||||
type: boolean
|
||||
globalnetEnabled:
|
||||
type: boolean
|
||||
haltOnCertificateError:
|
||||
type: boolean
|
||||
clustersetIPEnabled:
|
||||
type: boolean
|
||||
imageOverrides:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
namespace:
|
||||
type: string
|
||||
nodeSelector:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
repository:
|
||||
type: string
|
||||
tolerations:
|
||||
items:
|
||||
description: The pod this Toleration is attached to tolerates any
|
||||
taint that matches the triple <key,value,effect> using the matching
|
||||
operator <operator>.
|
||||
properties:
|
||||
effect:
|
||||
description: Effect indicates the taint effect to match. Empty
|
||||
means match all taint effects. When specified, allowed values
|
||||
are NoSchedule, PreferNoSchedule and NoExecute.
|
||||
type: string
|
||||
key:
|
||||
description: Key is the taint key that the toleration applies
|
||||
to. Empty means match all taint keys. If the key is empty,
|
||||
operator must be Exists; this combination means to match all
|
||||
values and all keys.
|
||||
type: string
|
||||
operator:
|
||||
description: Operator represents a key's relationship to the
|
||||
value. Valid operators are Exists and Equal. Defaults to Equal.
|
||||
Exists is equivalent to wildcard for value, so that a pod
|
||||
can tolerate all taints of a particular category.
|
||||
type: string
|
||||
tolerationSeconds:
|
||||
description: TolerationSeconds represents the period of time
|
||||
the toleration (which must be of effect NoExecute, otherwise
|
||||
this field is ignored) tolerates the taint. By default, it
|
||||
is not set, which means tolerate the taint forever (do not
|
||||
evict). Zero and negative values will be treated as 0 (evict
|
||||
immediately) by the system.
|
||||
format: int64
|
||||
type: integer
|
||||
value:
|
||||
description: Value is the taint value the toleration matches
|
||||
to. If the operator is Exists, the value should be empty,
|
||||
otherwise just a regular string.
|
||||
type: string
|
||||
type: object
|
||||
type: array
|
||||
version:
|
||||
type: string
|
||||
required:
|
||||
- brokerK8sApiServer
|
||||
- brokerK8sApiServerToken
|
||||
- brokerK8sCA
|
||||
- brokerK8sRemoteNamespace
|
||||
- clusterID
|
||||
- debug
|
||||
- namespace
|
||||
type: object
|
||||
status:
|
||||
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery.
|
||||
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
|
||||
properties:
|
||||
deploymentInfo:
|
||||
properties:
|
||||
@@ -1122,6 +930,12 @@ spec:
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
status:
|
||||
acceptedNames:
|
||||
kind: ""
|
||||
plural: ""
|
||||
conditions: []
|
||||
storedVersions: []
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
|
||||
@@ -12,38 +12,28 @@ rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
# For metrics
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
# Temporarily needed for network-plugin syncer removal
|
||||
- serviceaccounts
|
||||
resourceNames:
|
||||
- submariner-networkplugin-syncer
|
||||
verbs:
|
||||
- delete
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
# Needed for openshift monitoring
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
@@ -56,37 +46,25 @@ rules:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- brokers
|
||||
- brokers/status
|
||||
- submariners
|
||||
- submariners/status
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
- servicediscoveries/status
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gateways
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- submariners/finalizers
|
||||
- servicediscoveries/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- '*'
|
||||
---
|
||||
kind: RoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
@@ -119,23 +97,71 @@ rules:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- submariner-operator
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- clusters
|
||||
- endpoints
|
||||
- gateways
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- lighthouse.submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- serviceexports
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- delete
|
||||
- watch
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
@@ -177,25 +203,74 @@ metadata:
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- submariner-operator
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gatewayroutes
|
||||
- nongatewayroutes
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- lighthouse.submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- serviceexports
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- delete
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
@@ -227,14 +302,74 @@ metadata:
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
- ""
|
||||
resources:
|
||||
- gateways
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- submariner-operator
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- lighthouse.submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- serviceexports
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
@@ -300,10 +435,9 @@ rules:
|
||||
- update
|
||||
- delete
|
||||
- watch
|
||||
- apiGroups:
|
||||
- apiGroups: # pods, services and nodes are looked up to figure out network settings
|
||||
- ""
|
||||
resources:
|
||||
# Needed for network settings discovery
|
||||
- pods
|
||||
- services
|
||||
- nodes
|
||||
@@ -317,20 +451,27 @@ rules:
|
||||
- dnses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
resources:
|
||||
# Needed for network settings discovery
|
||||
- networks
|
||||
resourceNames:
|
||||
- cluster
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- namespaces
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
# Needed for openshift monitoring
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
@@ -338,21 +479,11 @@ rules:
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
# Needed for Flannel CNI discovery
|
||||
- daemonsets
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- rbac.authorization.k8s.io
|
||||
resources:
|
||||
# Temporarily needed for network-plugin syncer removal
|
||||
- clusterroles
|
||||
- clusterrolebindings
|
||||
resourceNames:
|
||||
- ocp-submariner-networkplugin-syncer
|
||||
- submariner-networkplugin-syncer
|
||||
verbs:
|
||||
- delete
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -411,7 +542,21 @@ rules:
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups: # pods and services are looked up to figure out network settings
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
@@ -421,6 +566,32 @@ rules:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- operator.openshift.io
|
||||
resources:
|
||||
- dnses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
resources:
|
||||
- networks
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- endpoints
|
||||
- gateways
|
||||
- clusters
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -453,40 +624,56 @@ rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- secrets
|
||||
- configmaps
|
||||
- endpoints
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- networks
|
||||
resourceNames:
|
||||
- cluster
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- list
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups: # pods and services are looked up to figure out network settings
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
- pods
|
||||
- services
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- projectcalico.org
|
||||
- operator.openshift.io
|
||||
resources:
|
||||
- ippools
|
||||
- dnses
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- delete
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- deletecollection
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
resources:
|
||||
- networks
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
resources:
|
||||
- nodes
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -521,10 +708,13 @@ rules:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- namespaces
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
@@ -540,8 +730,8 @@ rules:
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- clusters
|
||||
- endpoints
|
||||
- clusters
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -566,7 +756,7 @@ rules:
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceexports
|
||||
- "serviceexports"
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -621,6 +811,7 @@ rules:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- discovery.k8s.io
|
||||
resources:
|
||||
@@ -637,8 +828,8 @@ rules:
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gateways
|
||||
- globalingressips
|
||||
- "gateways"
|
||||
- "globalingressips"
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -646,8 +837,7 @@ rules:
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceimports
|
||||
- serviceimports/status
|
||||
- "*"
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
@@ -655,20 +845,6 @@ rules:
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceexports
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceexports/status
|
||||
verbs:
|
||||
- update
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -694,18 +870,33 @@ metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
||||
rules:
|
||||
- apiGroups:
|
||||
- discovery.k8s.io
|
||||
- ""
|
||||
resources:
|
||||
- endpointslices
|
||||
- services
|
||||
- namespaces
|
||||
- endpoints
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- discovery.k8s.io
|
||||
resources:
|
||||
- endpointslices
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- deletecollection
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gateways
|
||||
- submariners
|
||||
- "gateways"
|
||||
- "submariners"
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -713,11 +904,14 @@ rules:
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceimports
|
||||
- "*"
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
|
||||
@@ -52,8 +52,6 @@ spec:
|
||||
{{- end }}
|
||||
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
|
||||
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
|
||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||
cableDriver: {{ .Values.submariner.cableDriver }}
|
||||
connectionHealthCheck:
|
||||
|
||||
@@ -5,8 +5,6 @@ submariner:
|
||||
clusterCidr: ""
|
||||
serviceCidr: ""
|
||||
globalCidr: ""
|
||||
clustersetIpCidr: ""
|
||||
clustersetIpEnabled: false
|
||||
loadBalancerEnabled: false
|
||||
natEnabled: false
|
||||
colorCodes: blue
|
||||
|
||||
Reference in New Issue
Block a user