mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-21 22:00:35 +00:00
Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c422f45756 | ||
|
|
44c1ad34ab |
@@ -1,2 +1,8 @@
|
|||||||
Periodic link aliveness CI detected a broken link. Please see the [periodic job
|
---
|
||||||
results](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic) for details.
|
name: Broken link detected by CI
|
||||||
|
labels: bug
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- Used by automation to raise an Issue when the periodic link aliveness tests detect a broken link. -->
|
||||||
|
|
||||||
|
Periodic link aliveness CI detected a broken link. Please see the job results for details.
|
||||||
|
|||||||
@@ -1,31 +0,0 @@
|
|||||||
---
|
|
||||||
name: Bug Report
|
|
||||||
about: Report a bug in Helm Charts
|
|
||||||
labels: bug
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
<!-- Please use this template while reporting a bug and provide as much info as
|
|
||||||
possible. Not doing so may result in your bug not being addressed in a timely
|
|
||||||
manner. Thanks!
|
|
||||||
|
|
||||||
If the matter is security related, please disclose it privately to the
|
|
||||||
Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
|
|
||||||
-->
|
|
||||||
|
|
||||||
|
|
||||||
**What happened**:
|
|
||||||
|
|
||||||
**What you expected to happen**:
|
|
||||||
|
|
||||||
**How to reproduce it (as minimally and precisely as possible)**:
|
|
||||||
|
|
||||||
**Anything else we need to know?**:
|
|
||||||
|
|
||||||
**Environment**:
|
|
||||||
- Diagnose information (use `subctl diagnose all`):
|
|
||||||
- Gather information (use `subctl gather`):
|
|
||||||
- Cloud provider or hardware configuration:
|
|
||||||
- Install tools:
|
|
||||||
- Network plugin and version (if this is a network-related bug):
|
|
||||||
- Others:
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
---
|
|
||||||
name: Enhancement Request
|
|
||||||
about: Suggest an enhancement to the Helm Charts project
|
|
||||||
labels: enhancement
|
|
||||||
|
|
||||||
---
|
|
||||||
<!-- Please only use this template for submitting enhancement requests -->
|
|
||||||
|
|
||||||
**What would you like to be added**:
|
|
||||||
|
|
||||||
**Why is this needed**:
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
---
|
|
||||||
name: Support Request
|
|
||||||
about: Support request or question relating to Helm Charts
|
|
||||||
labels: support
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
<!--
|
|
||||||
GitHub may not be the right place for support requests.
|
|
||||||
|
|
||||||
You can also post your question on the [Submariner
|
|
||||||
Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner
|
|
||||||
[users](https://bit.ly/submariner-users) or
|
|
||||||
[developers](https://bit.ly/submariner-dev) mailing lists.
|
|
||||||
|
|
||||||
If the matter is security related, please disclose it privately to the
|
|
||||||
Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
|
|
||||||
-->
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
<!-- Thanks for sending a pull request! Here are some tips for you:
|
|
||||||
|
|
||||||
1. If this is your first time, please read our developer guide: https://submariner.io/development/
|
|
||||||
2. Ensure you have added the appropriate tests for your PR: https://submariner.io/development/code-review/#test-new-functionality
|
|
||||||
3. Read the code review guide to ease the review process: https://submariner.io/development/code-review/
|
|
||||||
4. If the PR is unfinished, mark it as a draft: https://submariner.io/development/code-review/#mark-work-in-progress-prs-as-drafts
|
|
||||||
5. If you are using CI to debug, use your private fork: https://submariner.io/development/code-review/#use-private-forks-for-debugging-prs-by-running-ci
|
|
||||||
6. Add labels to the PR as appropriate.
|
|
||||||
|
|
||||||
This template is based on the K8s/K8s template:
|
|
||||||
|
|
||||||
https://github.com/kubernetes/kubernetes/blob/master/.github/PULL_REQUEST_TEMPLATE.md
|
|
||||||
-->
|
|
||||||
@@ -1,74 +0,0 @@
|
|||||||
---
|
|
||||||
version: 2
|
|
||||||
updates:
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.18"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.19"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.20"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.21"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.22"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.23"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.24"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
---
|
||||||
|
# Configuration for probot-stale - https://github.com/probot/stale
|
||||||
|
|
||||||
|
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
|
||||||
|
daysUntilStale: 60
|
||||||
|
|
||||||
|
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
|
||||||
|
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
|
||||||
|
daysUntilClose: 7
|
||||||
|
|
||||||
|
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
|
||||||
|
onlyLabels: []
|
||||||
|
|
||||||
|
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
|
||||||
|
exemptLabels:
|
||||||
|
- security
|
||||||
|
- confirmed
|
||||||
|
|
||||||
|
# Set to true to ignore issues in a project (defaults to false)
|
||||||
|
exemptProjects: false
|
||||||
|
|
||||||
|
# Set to true to ignore issues in a milestone (defaults to false)
|
||||||
|
exemptMilestones: false
|
||||||
|
|
||||||
|
# Set to true to ignore issues with an assignee (defaults to false)
|
||||||
|
exemptAssignees: false
|
||||||
|
|
||||||
|
# Label to use when marking as stale
|
||||||
|
staleLabel: wontfix
|
||||||
|
|
||||||
|
# Comment to post when marking as stale. Set to `false` to disable
|
||||||
|
markComment: >
|
||||||
|
This issue has been automatically marked as stale because it has not had
|
||||||
|
activity for 60 days. It will be closed if no further activity occurs.
|
||||||
|
Please make a comment if this issue/pr is still valid. Thank you
|
||||||
|
for your contributions.
|
||||||
|
|
||||||
|
# Comment to post when removing the stale label.
|
||||||
|
# unmarkComment: >
|
||||||
|
# Your comment here.
|
||||||
|
|
||||||
|
# Comment to post when closing a stale Issue or Pull Request.
|
||||||
|
# closeComment: >
|
||||||
|
# Your comment here.
|
||||||
|
|
||||||
|
# Limit the number of actions per hour, from 1-30. Default is 30
|
||||||
|
limitPerRun: 30
|
||||||
|
|
||||||
|
# Limit to only `issues` or `pulls`
|
||||||
|
# only: issues
|
||||||
|
|
||||||
|
pulls:
|
||||||
|
daysUntilStale: 30
|
||||||
|
markComment: >
|
||||||
|
This pull request has been automatically marked as stale because it has not had
|
||||||
|
recent activity. It will be closed if no further activity occurs. Thank you
|
||||||
|
for your contributions.
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
---
|
|
||||||
name: Branch Checks
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
target_branch:
|
|
||||||
name: PR targets branch
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Check that the PR targets release-0.25
|
|
||||||
if: ${{ github.base_ref != 'release-0.25' }}
|
|
||||||
run: exit 1
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
---
|
|
||||||
name: PR Dependencies
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request_target:
|
|
||||||
types:
|
|
||||||
- opened
|
|
||||||
- edited
|
|
||||||
- reopened
|
|
||||||
- synchronize
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
pull-requests: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
check:
|
|
||||||
name: Check Dependencies
|
|
||||||
if: github.repository_owner == 'submariner-io'
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: depends-on/depends-on-action@c7ac9a6932a7069e83aef80c202d9f60f91e43fd # v0.17.0
|
|
||||||
with:
|
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
check-unmerged-pr: true
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
---
|
|
||||||
name: End to End Full
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
types: [labeled, opened, synchronize, reopened]
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
e2e:
|
|
||||||
name: E2E
|
|
||||||
if: contains(github.event.pull_request.labels.*.name, 'ready-to-test')
|
|
||||||
timeout-minutes: 45
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
|
||||||
globalnet: ['', 'globalnet']
|
|
||||||
# Run most tests against the latest K8s version
|
|
||||||
k8s_version: ['k8s-latest']
|
|
||||||
lighthouse: ['', 'lighthouse']
|
|
||||||
include:
|
|
||||||
# Bottom of supported K8s version range
|
|
||||||
- k8s_version: 'k8s-oldest-supported'
|
|
||||||
steps:
|
|
||||||
- name: Check out the repository
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.25
|
|
||||||
with:
|
|
||||||
k8s_version: ${{ matrix.k8s_version }}
|
|
||||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
|
||||||
|
|
||||||
- name: Post mortem
|
|
||||||
if: failure()
|
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.25
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
---
|
|
||||||
name: End to End Default
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
e2e:
|
|
||||||
name: E2E
|
|
||||||
timeout-minutes: 30
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Check out the repository
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.25
|
|
||||||
|
|
||||||
- name: Post mortem
|
|
||||||
if: failure()
|
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.25
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
---
|
|
||||||
name: Flake Finder
|
|
||||||
|
|
||||||
on:
|
|
||||||
schedule:
|
|
||||||
- cron: "0 0 * * *"
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
e2e:
|
|
||||||
name: E2E
|
|
||||||
if: github.repository_owner == 'submariner-io'
|
|
||||||
timeout-minutes: 30
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
|
||||||
globalnet: ['', 'globalnet']
|
|
||||||
lighthouse: ['', 'lighthouse']
|
|
||||||
steps:
|
|
||||||
- name: Check out the repository
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.25
|
|
||||||
with:
|
|
||||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
|
||||||
|
|
||||||
- name: Post mortem
|
|
||||||
if: failure()
|
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.25
|
|
||||||
@@ -4,110 +4,54 @@ name: Linting
|
|||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
apply-suggestions-commits:
|
dco:
|
||||||
name: 'No "Apply suggestions from code review" Commits'
|
name: DCO in Commit Message(s)
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Get PR commits
|
- name: Get PR commits
|
||||||
id: 'get-pr-commits'
|
id: 'get-pr-commits'
|
||||||
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d
|
uses: tim-actions/get-pr-commits@master
|
||||||
with:
|
with:
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
- name: Run DCO check
|
||||||
- name: 'Verify no "Apply suggestions from code review" commits'
|
uses: tim-actions/dco@master
|
||||||
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
|
||||||
with:
|
with:
|
||||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||||
pattern: '^(?!.*(apply suggestions from code review))'
|
|
||||||
flags: 'i'
|
|
||||||
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
|
||||||
|
|
||||||
- name: 'Verify no "fixup!" commits'
|
|
||||||
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
|
||||||
with:
|
|
||||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
|
||||||
pattern: '^(?!fixup!)'
|
|
||||||
flags: 'i'
|
|
||||||
error: 'Fixup commits should be squashed into the commits under review'
|
|
||||||
|
|
||||||
chart-testing:
|
|
||||||
name: Helm Chart Linting
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Check out the repository
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
|
|
||||||
- name: Set up Helm
|
|
||||||
uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310
|
|
||||||
with:
|
|
||||||
version: v3.6.0
|
|
||||||
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97
|
|
||||||
with:
|
|
||||||
python-version: '3.13.x'
|
|
||||||
|
|
||||||
- name: Set up helm/chart-testing
|
|
||||||
uses: helm/chart-testing-action@6ec842c01de15ebb84c8627d2744a0c2f2755c9f
|
|
||||||
|
|
||||||
- name: Set up local helm repo
|
|
||||||
run: make local-helm-repo
|
|
||||||
|
|
||||||
- name: Run helm/chart-testing (lint)
|
|
||||||
run: ct lint --config ct.yaml
|
|
||||||
|
|
||||||
gitlint:
|
|
||||||
name: Commit Message(s)
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Check out the repository
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
- name: Run gitlint
|
|
||||||
run: make gitlint
|
|
||||||
|
|
||||||
helm-docs:
|
|
||||||
name: Helm Docs Generation
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Check out the repository
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
|
|
||||||
- name: Run helm-docs and verify docs are up-to-date
|
|
||||||
run: make helm-docs
|
|
||||||
|
|
||||||
markdown-link-check:
|
markdown-link-check:
|
||||||
name: Markdown Links (modified files)
|
name: Markdown Links (modified files)
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
check-modified-files-only: "yes"
|
check-modified-files-only: "yes"
|
||||||
base-branch: ${{ github.base_ref }}
|
|
||||||
|
|
||||||
markdownlint:
|
markdownlint:
|
||||||
name: Markdown
|
name: Markdown
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
uses: actions/checkout@v2
|
||||||
- name: Run markdownlint
|
- name: Run markdownlint
|
||||||
run: make markdownlint
|
uses: nosborn/github-action-markdown-cli@v1.1.1
|
||||||
|
with:
|
||||||
|
files: .
|
||||||
|
config_file: ".markdownlint.yml"
|
||||||
|
|
||||||
yaml-lint:
|
yaml-lint:
|
||||||
name: YAML
|
name: YAML
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
uses: actions/checkout@v2
|
||||||
- name: Run yamllint
|
- name: Run yamllint
|
||||||
run: make yamllint
|
uses: ibiqlik/action-yamllint@v1
|
||||||
|
with:
|
||||||
|
file_or_dir: submariner/values.yaml submariner-k8s-broker/values.yaml submariner/Chart.yaml submariner-k8s-broker/Chart.yaml
|
||||||
|
config_file: .yamllint.yml
|
||||||
|
|||||||
@@ -5,28 +5,23 @@ on:
|
|||||||
schedule:
|
schedule:
|
||||||
- cron: "0 0 * * 0"
|
- cron: "0 0 * * 0"
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
markdown-link-check-periodic:
|
markdown-link-check-periodic:
|
||||||
name: Markdown Links (all files)
|
name: Markdown Links (all files)
|
||||||
if: github.repository_owner == 'submariner-io'
|
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
permissions:
|
|
||||||
issues: write
|
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
|
|
||||||
- name: Raise an Issue to report broken links
|
- name: Raise an Issue to report broken links
|
||||||
if: ${{ failure() }}
|
if: ${{ failure() }}
|
||||||
uses: peter-evans/create-issue-from-file@fca9117c27cdc29c6c4db3b86c48e4115a786710
|
uses: JasonEtco/create-an-issue@v2
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
with:
|
with:
|
||||||
title: Broken link detected by CI
|
filename: .github/ISSUE_TEMPLATE/broken-link.md
|
||||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
|
||||||
labels: automated, broken link
|
|
||||||
|
|||||||
@@ -1,36 +0,0 @@
|
|||||||
---
|
|
||||||
name: Release Charts
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- release-0.25
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
release:
|
|
||||||
name: Release
|
|
||||||
if: github.repository_owner == 'submariner-io'
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Checkout
|
|
||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Configure Git
|
|
||||||
run: |
|
|
||||||
git config user.name "$GITHUB_ACTOR"
|
|
||||||
git config user.email "$GITHUB_ACTOR@users.noreply.github.com"
|
|
||||||
|
|
||||||
- name: Update the charts
|
|
||||||
run: |
|
|
||||||
make release
|
|
||||||
|
|
||||||
- name: Push the charts
|
|
||||||
run: |
|
|
||||||
git add charts/*
|
|
||||||
git commit -m "Chart update"
|
|
||||||
git push
|
|
||||||
@@ -1,32 +0,0 @@
|
|||||||
---
|
|
||||||
name: Stale
|
|
||||||
|
|
||||||
on:
|
|
||||||
schedule:
|
|
||||||
- cron: "0 0 * * *"
|
|
||||||
|
|
||||||
permissions: {}
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
stale:
|
|
||||||
name: Close Stale Issues and PRs
|
|
||||||
if: github.repository_owner == 'submariner-io'
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
issues: write
|
|
||||||
pull-requests: write
|
|
||||||
steps:
|
|
||||||
- uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93
|
|
||||||
with:
|
|
||||||
days-before-issue-stale: 120
|
|
||||||
days-before-pr-stale: 14
|
|
||||||
exempt-issue-labels: 'confirmed,security'
|
|
||||||
exempt-pr-labels: 'confirmed,security'
|
|
||||||
stale-issue-label: 'stale'
|
|
||||||
stale-issue-message: |
|
|
||||||
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
|
||||||
activity occurs. Thank you for your contributions.
|
|
||||||
stale-pr-label: 'stale'
|
|
||||||
stale-pr-message: |
|
|
||||||
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
|
||||||
activity occurs. Thank you for your contributions.
|
|
||||||
-13
@@ -1,15 +1,2 @@
|
|||||||
.dapper
|
|
||||||
.idea
|
.idea
|
||||||
.shflags
|
|
||||||
*.tgz
|
*.tgz
|
||||||
Makefile.dapper
|
|
||||||
Makefile.shipyard
|
|
||||||
Dockerfile.*
|
|
||||||
helm_repo
|
|
||||||
yamls/go.mod
|
|
||||||
yamls/go.sum
|
|
||||||
yamls/vendor
|
|
||||||
submariner-k8s-broker/crds/crd.yaml
|
|
||||||
submariner-k8s-broker/templates/_role.tpl
|
|
||||||
submariner-operator/crds/crd.yaml
|
|
||||||
submariner-operator/templates/*-rbac.yaml
|
|
||||||
|
|||||||
@@ -1,16 +1,10 @@
|
|||||||
{
|
{
|
||||||
"ignorePatterns": [
|
"ignorePatterns": [
|
||||||
{
|
|
||||||
"pattern": "^https://docs.github.com"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"pattern": "^http://localhost:"
|
"pattern": "^http://localhost:"
|
||||||
},
|
|
||||||
{
|
|
||||||
"pattern": "^https://submariner-io.github.io/submariner-charts/charts"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,9 +2,6 @@
|
|||||||
# Breaks reusing MD snippets extracted to files
|
# Breaks reusing MD snippets extracted to files
|
||||||
first-line-heading: false
|
first-line-heading: false
|
||||||
|
|
||||||
# Accept any consistent table column style
|
|
||||||
table-column-style: false
|
|
||||||
|
|
||||||
# Set maximum line Length to 140c to match Go linting
|
# Set maximum line Length to 140c to match Go linting
|
||||||
line-length:
|
line-length:
|
||||||
line_length: 140
|
line_length: 140
|
||||||
@@ -13,7 +10,3 @@ line-length:
|
|||||||
no-inline-html:
|
no-inline-html:
|
||||||
allowed_elements:
|
allowed_elements:
|
||||||
- span
|
- span
|
||||||
|
|
||||||
# Temporary while helm-docs has a bug where maintainer URLs are used raw in MD
|
|
||||||
# Waiting on: https://github.com/norwoodj/helm-docs/pull/102
|
|
||||||
no-bare-urls: false
|
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
---
|
|
||||||
cni: ovn
|
|
||||||
submariner: true
|
|
||||||
nodes: control-plane
|
|
||||||
clusters:
|
|
||||||
cluster1:
|
|
||||||
cluster2:
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
submariner: true
|
|
||||||
nodes: control-plane
|
|
||||||
clusters:
|
|
||||||
cluster1:
|
|
||||||
cluster2:
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
---
|
|
||||||
label-approved:
|
|
||||||
approvals: 2
|
|
||||||
label: ready-to-test
|
|
||||||
+47
@@ -0,0 +1,47 @@
|
|||||||
|
language: python
|
||||||
|
|
||||||
|
env:
|
||||||
|
global:
|
||||||
|
- HELM_URL=https://storage.googleapis.com/kubernetes-helm
|
||||||
|
- HELM_TGZ=helm-v2.14.3-linux-amd64.tar.gz
|
||||||
|
- TARGET_BR=gh-pages
|
||||||
|
- GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||||
|
- CHARTS_DIR=charts
|
||||||
|
- YAMLLINT_VERSION=1.17.0
|
||||||
|
- HELM_FLAGS='--set submariner.serviceDiscovery=true,serviceAccounts.globalnet.create=true,globalCidr="169.254.0.0/16"'
|
||||||
|
|
||||||
|
install:
|
||||||
|
- wget -q ${HELM_URL}/${HELM_TGZ}
|
||||||
|
- tar xzfv ${HELM_TGZ}
|
||||||
|
- PATH=`pwd`/linux-amd64/:$PATH
|
||||||
|
- helm init --client-only
|
||||||
|
- sudo pip install yamllint=="${YAMLLINT_VERSION}"
|
||||||
|
|
||||||
|
script:
|
||||||
|
- for dir in submariner submariner-k8s-broker; do helm lint $dir $HELM_FLAGS; done
|
||||||
|
- yamllint -c .yamllint.yml -s $(find . -type f -name "Chart.yaml")
|
||||||
|
- yamllint -c .yamllint.yml -s $(find . -type f -name "values.yaml")
|
||||||
|
|
||||||
|
after_success:
|
||||||
|
- >
|
||||||
|
if [ $TRAVIS_BRANCH = 'master' ] && [ $TRAVIS_PULL_REQUEST = 'false' ]; then
|
||||||
|
set -e
|
||||||
|
for dir in submariner submariner-k8s-broker; do
|
||||||
|
helm dep update $dir
|
||||||
|
helm package $dir
|
||||||
|
done
|
||||||
|
REPO_URL=`git config remote.origin.url`
|
||||||
|
git clone ${REPO_URL} out && cd out && git checkout gh-pages && mkdir -p ${CHARTS_DIR}
|
||||||
|
cp -f ../submariner-*.tgz ${CHARTS_DIR}/
|
||||||
|
if [ -f charts/index.yaml ]; then
|
||||||
|
helm repo index ${CHARTS_DIR} --url ${GH_URL} --merge index.yaml
|
||||||
|
else
|
||||||
|
helm repo index ${CHARTS_DIR} --url ${GH_URL}
|
||||||
|
fi
|
||||||
|
git config user.name "Travis CI"
|
||||||
|
git config user.email "travis@travis-ci.org"
|
||||||
|
git add -f ${CHARTS_DIR}/*
|
||||||
|
git commit -m "Travis build: $TRAVIS_BUILD_NUMBER"
|
||||||
|
git remote add origin-pages https://${GH_TOKEN}@github.com/submariner-io/submariner-charts.git > /dev/null 2>&1
|
||||||
|
git push --quiet -f -u origin-pages gh-pages
|
||||||
|
fi
|
||||||
+11
-11
@@ -1,15 +1,15 @@
|
|||||||
---
|
---
|
||||||
extends: default
|
extends: default
|
||||||
|
|
||||||
rules:
|
rules:
|
||||||
|
comments: disable
|
||||||
|
comments-indentation: disable
|
||||||
line-length:
|
line-length:
|
||||||
max: 140
|
max: 150
|
||||||
# Allow standard GHA syntax for "on: *"
|
braces:
|
||||||
truthy:
|
min-spaces-inside: 0
|
||||||
ignore: '.github/workflows/*.yml'
|
max-spaces-inside: 0
|
||||||
|
brackets:
|
||||||
ignore: |
|
min-spaces-inside: 0
|
||||||
/submariner-k8s-broker/crds
|
max-spaces-inside: 0
|
||||||
/submariner-operator/crds
|
indentation:
|
||||||
/submariner-k8s-broker/templates
|
indent-sequences: consistent
|
||||||
/submariner-operator/templates
|
|
||||||
+1
-1
@@ -1,3 +1,3 @@
|
|||||||
# Code of Conduct
|
# Code of Conduct
|
||||||
|
|
||||||
Please see the [Code of Conduct docs on Submariner's website](https://submariner.io/community/code-of-conduct/).
|
Please see the [Code of Conduct docs on Submariner's website](https://submariner.io/contributing/code-of-conduct/).
|
||||||
|
|||||||
+1
-4
@@ -1,4 +1 @@
|
|||||||
# Auto-generated, do not edit; see CODEOWNERS.in
|
* @mangelajo @tpantelis @Oats87
|
||||||
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
|
||||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
|
||||||
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
|
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
@aswinsuryan Makefile
|
|
||||||
@dfarrell07 *.md Makefile
|
|
||||||
@maayanf24 Makefile
|
|
||||||
@Oats87 *
|
|
||||||
@skitt *
|
|
||||||
@sridhargaddam *
|
|
||||||
@tpantelis *
|
|
||||||
@vthapar *
|
|
||||||
@yboaron Makefile
|
|
||||||
+1
-1
@@ -1,3 +1,3 @@
|
|||||||
# Contributing
|
# Contributing
|
||||||
|
|
||||||
Please see the [Development docs on Submariner's website](https://submariner.io/development/).
|
Please see the [Contributing docs on Submariner's website](https://submariner.io/contributing/).
|
||||||
|
|||||||
@@ -1,82 +0,0 @@
|
|||||||
BASE_BRANCH ?= release-0.25
|
|
||||||
export BASE_BRANCH
|
|
||||||
export HELM_REPO_LOCATION=./helm_repo
|
|
||||||
|
|
||||||
ifneq (,$(DAPPER_HOST_ARCH))
|
|
||||||
|
|
||||||
# Running in Dapper
|
|
||||||
|
|
||||||
include $(SHIPYARD_DIR)/Makefile.inc
|
|
||||||
|
|
||||||
ifneq (,$(filter ovn,$(_using)))
|
|
||||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
|
||||||
else
|
|
||||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
|
||||||
endif
|
|
||||||
|
|
||||||
export DEPLOYTOOL = helm
|
|
||||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
|
||||||
CHARTS_DIR=charts
|
|
||||||
CHARTS_VERSION=0.25.0-rc1
|
|
||||||
HELM_DOCS_VERSION=0.15.0
|
|
||||||
REPO_URL=$(shell git config remote.origin.url)
|
|
||||||
|
|
||||||
# Targets to make
|
|
||||||
|
|
||||||
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
|
||||||
|
|
||||||
local-helm-repo: $(CHART_PACKAGES)
|
|
||||||
mkdir -p $(HELM_REPO_LOCATION)
|
|
||||||
for archive in $^; do \
|
|
||||||
tar xzf $$archive -C $(HELM_REPO_LOCATION); \
|
|
||||||
done
|
|
||||||
|
|
||||||
e2e: local-helm-repo
|
|
||||||
$(SCRIPTS_DIR)/e2e.sh
|
|
||||||
|
|
||||||
generate-yamls:
|
|
||||||
./generate-yamls.sh $(BASE_BRANCH)
|
|
||||||
|
|
||||||
%.tgz: generate-yamls
|
|
||||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
|
||||||
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
|
||||||
|
|
||||||
helm-docs:
|
|
||||||
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
|
||||||
cd /tmp && \
|
|
||||||
curl -sL https://github.com/norwoodj/helm-docs/releases/download/v$(HELM_DOCS_VERSION)/helm-docs_$(HELM_DOCS_VERSION)_Linux_x86_64.tar.gz | tar zx && \
|
|
||||||
cd -
|
|
||||||
/tmp/helm-docs
|
|
||||||
if [ ! -z $(git status --porcelain) ]; then \
|
|
||||||
echo "Helm docs not up-to-date:"; \
|
|
||||||
git status --porcelain; \
|
|
||||||
git diff; \
|
|
||||||
echo "Run make helm-docs locally to generate updated docs, commit the updates."; \
|
|
||||||
exit 1; \
|
|
||||||
fi
|
|
||||||
|
|
||||||
release: $(CHART_PACKAGES)
|
|
||||||
git checkout gh-pages
|
|
||||||
mv *.tgz $(CHARTS_DIR)
|
|
||||||
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
|
||||||
helm repo index $(CHARTS_DIR) --url $(GH_URL) --merge $(CHARTS_DIR)/index.yaml; \
|
|
||||||
else \
|
|
||||||
helm repo index $(CHARTS_DIR) --url $(GH_URL); \
|
|
||||||
fi
|
|
||||||
|
|
||||||
.PHONY: release helm-docs
|
|
||||||
|
|
||||||
else
|
|
||||||
|
|
||||||
# Not running in Dapper
|
|
||||||
|
|
||||||
Makefile.dapper:
|
|
||||||
@echo Downloading $@
|
|
||||||
@curl -sfLO https://raw.githubusercontent.com/submariner-io/shipyard/$(BASE_BRANCH)/$@
|
|
||||||
|
|
||||||
include Makefile.dapper
|
|
||||||
|
|
||||||
endif
|
|
||||||
|
|
||||||
# Disable rebuilding Makefile
|
|
||||||
Makefile Makefile.inc: ;
|
|
||||||
@@ -1,20 +1,13 @@
|
|||||||
# submariner-charts
|
# submariner-charts
|
||||||
|
|
||||||
<!-- markdownlint-disable line-length -->
|
Please see the [Helm docs on Submariner's website](https://submariner.io/deployment/helm/).
|
||||||
[](https://bestpractices.coreinfrastructure.org/projects/4865)
|
|
||||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Release+Charts%22)
|
|
||||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic)
|
|
||||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Flake+Finder%22)
|
|
||||||
<!-- markdownlint-enable line-length -->
|
|
||||||
|
|
||||||
Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/).
|
## Dev workflow
|
||||||
|
|
||||||
## Development workflow
|
|
||||||
|
|
||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
- [Helm] v3
|
- [helm]
|
||||||
- [Docker] or [Podman]
|
- [docker] or [podman]
|
||||||
|
|
||||||
### Create a fork and checkout
|
### Create a fork and checkout
|
||||||
|
|
||||||
@@ -28,36 +21,96 @@ cd submariner-charts
|
|||||||
git checkout -b new-feature
|
git checkout -b new-feature
|
||||||
```
|
```
|
||||||
|
|
||||||
Now you can modify the Helm charts according to your needs.
|
Now you can modify the helm charts according to your needs.
|
||||||
|
|
||||||
|
### Serve the modified charts
|
||||||
|
|
||||||
|
Before serving the modified charts, the charts must be packaged for local usage.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm package ./submariner
|
||||||
|
helm package ./submariner-k8s-broker
|
||||||
|
```
|
||||||
|
|
||||||
|
Note: if you just installed helm, you have to init the helm, by running
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm init --client-only
|
||||||
|
```
|
||||||
|
|
||||||
|
Serve the packaged charts through a local helm repository:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker run -d --rm --name helm-repo -p 8080:8080 -v $PWD:/charts -e DEBUG=true -e STORAGE=local -e STORAGE_LOCAL_ROOTDIR=/charts chartmuseum/chartmuseum
|
||||||
|
```
|
||||||
|
|
||||||
|
or
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo podman run -d --rm --name helm-repo -p 8080:8080 -v $PWD:/charts -e DEBUG=true -e STORAGE=local -e STORAGE_LOCAL_ROOTDIR=/charts chartmuseum/chartmuseum
|
||||||
|
```
|
||||||
|
|
||||||
|
Get the container internal ip:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' helm-repo
|
||||||
|
```
|
||||||
|
|
||||||
|
The local container will serve the charts locally on port 8080.
|
||||||
|
|
||||||
|
Get logs for the container:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker logs -f helm-repo
|
||||||
|
```
|
||||||
|
|
||||||
### Use the modified charts
|
### Use the modified charts
|
||||||
|
|
||||||
Locally-modified charts can be installed using `helm install`,
|
Init helm
|
||||||
referring to the local path; for example:
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
helm install submariner-k8s-broker ./submariner-k8s-broker ...
|
helm init --client-only
|
||||||
```
|
```
|
||||||
|
|
||||||
In the base directory of this repository, a local deployment using the
|
Add your local repository to helm
|
||||||
local charts can be obtained by running the following command:
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
make deploy
|
internal_ip=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' helm-repo)
|
||||||
|
helm repo add test-repo http://$internal_ip:8080
|
||||||
```
|
```
|
||||||
|
|
||||||
This will start two kind clusters and deploy Submariner using the
|
List the repos:
|
||||||
Broker and Operator charts.
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
make e2e
|
helm repo list
|
||||||
```
|
```
|
||||||
|
|
||||||
will run the end-to-end test suite used to validate that Submariner is
|
You should be able to see test-repo in the list
|
||||||
working correctly.
|
|
||||||
|
Search the new repo for submariner charts:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm search -l test-repo
|
||||||
|
```
|
||||||
|
|
||||||
|
### Modify submariner e2e tests helm deployment script to use your local test-repo
|
||||||
|
|
||||||
|
You can test your helm-charts with e2e tests from the [shipyard](https://github.com/submariner-io/shipyard) repository.
|
||||||
|
In the file `scripts/shared/lib/deploy_helm` change the line from:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm repo add submariner-latest https://submariner-io.github.io/submariner-charts/charts
|
||||||
|
```
|
||||||
|
|
||||||
|
to
|
||||||
|
|
||||||
|
```bash
|
||||||
|
internal_ip=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' helm-repo)
|
||||||
|
helm repo add submariner-latest http://$internal_ip:8080
|
||||||
|
```
|
||||||
|
|
||||||
<!--links-->
|
<!--links-->
|
||||||
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
|
[helm]: https://helm.sh/docs/using_helm/#installing-helm
|
||||||
[Docker]: https://docs.docker.com/install/
|
[docker]: https://docs.docker.com/install/
|
||||||
[Podman]: https://podman.io/getting-started/installation
|
[podman]: https://podman.io/getting-started/installation
|
||||||
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo
|
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
---
|
|
||||||
charts:
|
|
||||||
- ./helm_repo/submariner-operator
|
|
||||||
- ./helm_repo/submariner-k8s-broker
|
|
||||||
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
|
||||||
# See: https://github.com/helm/chart-testing/issues/192
|
|
||||||
validate-maintainers: false
|
|
||||||
@@ -1,107 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
BROKER_ROLE_TPL=submariner-k8s-broker/templates/_role.tpl
|
|
||||||
OPERATOR_RBAC_YAML=submariner-operator/templates/operator-rbac.yaml
|
|
||||||
GATEWAY_RBAC_YAML=submariner-operator/templates/gateway-rbac.yaml
|
|
||||||
ROUTE_AGENT_RBAC_YAML=submariner-operator/templates/routeagent-rbac.yaml
|
|
||||||
GLOBALNET_RBAC_YAML=submariner-operator/templates/globalnet-rbac.yaml
|
|
||||||
SERVICE_DISC_RBAC_YAML=submariner-operator/templates/service-discovery-rbac.yaml
|
|
||||||
OPENSHIFT_MONITORING_YAML=submariner-operator/templates/openshift-monitoring-rbac.yaml
|
|
||||||
|
|
||||||
YAMLS_BASE=yamls/vendor
|
|
||||||
SUBM_CRDS=${YAMLS_BASE}/github.com/submariner-io/submariner/deploy/crds
|
|
||||||
OPERATOR_CRDS=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/deploy/crds
|
|
||||||
MCS_CRDS=${YAMLS_BASE}/sigs.k8s.io/mcs-api/config/crd
|
|
||||||
BROKER=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/broker/broker-client
|
|
||||||
RBAC_BASE=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/rbac
|
|
||||||
OPENSHIFT=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/openshift
|
|
||||||
|
|
||||||
function add_service_acct_ns() {
|
|
||||||
sed -i '/- kind: ServiceAccount/a \ \ \ \ namespace: {{ .Release.Namespace }}' $1
|
|
||||||
}
|
|
||||||
|
|
||||||
cd yamls
|
|
||||||
rm go.mod || true
|
|
||||||
go mod init
|
|
||||||
go get github.com/submariner-io/submariner-operator@$1
|
|
||||||
go mod tidy
|
|
||||||
go mod vendor
|
|
||||||
cd ..
|
|
||||||
|
|
||||||
# Generate the CRDs for the broker chart
|
|
||||||
mkdir -p submariner-k8s-broker/crds
|
|
||||||
cat ${SUBM_CRDS}/submariner.io_endpoints.yaml \
|
|
||||||
${SUBM_CRDS}/submariner.io_clusters.yaml \
|
|
||||||
${SUBM_CRDS}/submariner.io_gateways.yaml > submariner-k8s-broker/crds/crd.yaml
|
|
||||||
echo '---' >> submariner-k8s-broker/crds/crd.yaml
|
|
||||||
cat ${MCS_CRDS}/multicluster.x-k8s.io_serviceexports.yaml >> submariner-k8s-broker/crds/crd.yaml
|
|
||||||
echo '---' >> submariner-k8s-broker/crds/crd.yaml
|
|
||||||
cat ${MCS_CRDS}/multicluster.x-k8s.io_serviceimports.yaml >> submariner-k8s-broker/crds/crd.yaml
|
|
||||||
|
|
||||||
# Generate the client role yaml for the broker chart
|
|
||||||
echo '{{- define "broker-role" -}}' > ${BROKER_ROLE_TPL}
|
|
||||||
cat ${BROKER}/role.yaml >> ${BROKER_ROLE_TPL}
|
|
||||||
echo '{{- end -}}' >> ${BROKER_ROLE_TPL}
|
|
||||||
sed -i -e 's/name:.*/name: {{ template "submariner-k8s-broker.fullname" \. }}-cluster/' ${BROKER_ROLE_TPL}
|
|
||||||
|
|
||||||
# Generate the CRDs for the operator chart
|
|
||||||
mkdir -p submariner-operator/crds
|
|
||||||
cat ${OPERATOR_CRDS}/submariner.io_submariners.yaml \
|
|
||||||
${OPERATOR_CRDS}/submariner.io_servicediscoveries.yaml \
|
|
||||||
${OPERATOR_CRDS}/submariner.io_brokers.yaml > submariner-operator/crds/crd.yaml
|
|
||||||
|
|
||||||
# Generate the operator RBAC yaml for the operator chart
|
|
||||||
add_service_acct_ns ${RBAC_BASE}/submariner-operator/cluster_role_binding.yaml
|
|
||||||
cat ${RBAC_BASE}/submariner-operator/service_account.yaml \
|
|
||||||
${RBAC_BASE}/submariner-operator/role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-operator/role_binding.yaml \
|
|
||||||
${RBAC_BASE}/submariner-operator/cluster_role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-operator/cluster_role_binding.yaml > ${OPERATOR_RBAC_YAML}
|
|
||||||
|
|
||||||
# Generate the gateway RBAC yaml for the operator chart
|
|
||||||
add_service_acct_ns ${RBAC_BASE}/submariner-gateway/cluster_role_binding.yaml
|
|
||||||
cat ${RBAC_BASE}/submariner-gateway/service_account.yaml \
|
|
||||||
${RBAC_BASE}/submariner-gateway/role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-gateway/role_binding.yaml \
|
|
||||||
${RBAC_BASE}/submariner-gateway/cluster_role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-gateway/cluster_role_binding.yaml > ${GATEWAY_RBAC_YAML}
|
|
||||||
|
|
||||||
# Generate the routeagent RBAC yaml for the operator chart
|
|
||||||
add_service_acct_ns ${RBAC_BASE}/submariner-route-agent/cluster_role_binding.yaml
|
|
||||||
cat ${RBAC_BASE}/submariner-route-agent/service_account.yaml \
|
|
||||||
${RBAC_BASE}/submariner-route-agent/role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-route-agent/role_binding.yaml \
|
|
||||||
${RBAC_BASE}/submariner-route-agent/cluster_role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-route-agent/cluster_role_binding.yaml > ${ROUTE_AGENT_RBAC_YAML}
|
|
||||||
|
|
||||||
# Generate the globalnet RBAC yaml for the operator chart
|
|
||||||
echo '{{- if .Values.broker.globalnet }}' > ${GLOBALNET_RBAC_YAML}
|
|
||||||
add_service_acct_ns ${RBAC_BASE}/submariner-globalnet/cluster_role_binding.yaml
|
|
||||||
cat ${RBAC_BASE}/submariner-globalnet/service_account.yaml \
|
|
||||||
${RBAC_BASE}/submariner-globalnet/role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-globalnet/role_binding.yaml \
|
|
||||||
${RBAC_BASE}/submariner-globalnet/cluster_role.yaml \
|
|
||||||
${RBAC_BASE}/submariner-globalnet/cluster_role_binding.yaml >> ${GLOBALNET_RBAC_YAML}
|
|
||||||
echo '{{- end -}}' >> ${GLOBALNET_RBAC_YAML}
|
|
||||||
|
|
||||||
# Generate the service discovery RBAC yaml for the operator chart
|
|
||||||
echo '{{- if .Values.submariner.serviceDiscovery }}' > ${SERVICE_DISC_RBAC_YAML}
|
|
||||||
add_service_acct_ns ${RBAC_BASE}/lighthouse-agent/cluster_role_binding.yaml
|
|
||||||
add_service_acct_ns ${RBAC_BASE}/lighthouse-coredns/cluster_role_binding.yaml
|
|
||||||
cat ${RBAC_BASE}/lighthouse-agent/service_account.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-agent/cluster_role.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-agent/cluster_role_binding.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-agent/role.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-agent/role_binding.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-coredns/service_account.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-coredns/cluster_role.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-coredns/cluster_role_binding.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-coredns/role.yaml \
|
|
||||||
${RBAC_BASE}/lighthouse-coredns/role_binding.yaml >> ${SERVICE_DISC_RBAC_YAML}
|
|
||||||
echo '{{- end -}}' >> ${SERVICE_DISC_RBAC_YAML}
|
|
||||||
|
|
||||||
# Generate the openshift monitoring rbac yaml for the operator chart
|
|
||||||
cat ${OPENSHIFT}/rbac/submariner-metrics-reader/role.yaml \
|
|
||||||
${OPENSHIFT}/rbac/submariner-metrics-reader/role_binding.yaml > ${OPENSHIFT_MONITORING_YAML}
|
|
||||||
@@ -1,13 +1,12 @@
|
|||||||
---
|
---
|
||||||
name: submariner-k8s-broker
|
name: submariner-k8s-broker
|
||||||
version: 0.0.0
|
version: 0.6.0
|
||||||
apiVersion: v2
|
appVersion: 0.6.0
|
||||||
description: Submariner Kubernetes Broker
|
description: Submariner Kubernetes Broker
|
||||||
keywords:
|
keywords:
|
||||||
home: https://submariner-io.github.io/
|
home: https://submariner-io.github.io/
|
||||||
sources:
|
sources:
|
||||||
- https://submariner-io.github.io/submariner-charts/charts
|
- https://submariner-io.github.io/submariner-charts/charts
|
||||||
maintainers:
|
maintainers:
|
||||||
- name: Contributors to the Submariner project
|
- name: Submariner Developers
|
||||||
email: submariner-dev@googlegroups.com
|
email: submariner-dev@googlegroups.com
|
||||||
url: https://submariner.io/
|
|
||||||
|
|||||||
@@ -1,15 +0,0 @@
|
|||||||
# submariner-k8s-broker
|
|
||||||
|
|
||||||
Submariner Kubernetes Broker
|
|
||||||
|
|
||||||
**Homepage:** <https://submariner-io.github.io/>
|
|
||||||
|
|
||||||
## Maintainers
|
|
||||||
|
|
||||||
| Name | Email | Url |
|
|
||||||
| ---- | ------ | --- |
|
|
||||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
|
||||||
|
|
||||||
## Source Code
|
|
||||||
|
|
||||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
questions:
|
||||||
|
- variable: submariner-k8s-broker.rbac.create
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
group: "Role Based Access Control"
|
||||||
|
description: "Create the role/rolebinding for the Submariner client"
|
||||||
|
label: "RBAC Creation Enabled"
|
||||||
|
- variable: submariner-k8s-broker.crd.create
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
group: "Submariner CRD"
|
||||||
|
description: "Create the submariner CRDs for the Submariner client"
|
||||||
|
label: "Submariner CRD Creation Enabled"
|
||||||
|
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
group: "Service Account"
|
||||||
|
description: "Create the service account for the Submariner client"
|
||||||
|
label: "Submariner Service Account Creation Enabled"
|
||||||
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
|
|||||||
|
|
||||||
The broker client token and CA can be retrieved by running
|
The broker client token and CA can be retrieved by running
|
||||||
|
|
||||||
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
|
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
|
||||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
|
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
|
||||||
|
|||||||
@@ -35,5 +35,9 @@ Create chart name and version as used by the chart label.
|
|||||||
Create the name of the submariner-client service account to use
|
Create the name of the submariner-client service account to use
|
||||||
*/}}
|
*/}}
|
||||||
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
||||||
{{- printf "%s-client" (include "submariner-k8s-broker.fullname" .)}}
|
{{- if .Values.serviceAccounts.client.create -}}
|
||||||
|
{{ default (printf "%s-client" (include "submariner-k8s-broker.fullname" .)) .Values.serviceAccounts.client.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.client.name }}
|
||||||
|
{{- end -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
@@ -0,0 +1,110 @@
|
|||||||
|
{{- if .Values.crd.create -}}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: clusters.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Cluster
|
||||||
|
plural: clusters
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: endpoints.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Endpoint
|
||||||
|
plural: endpoints
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: gateways.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Gateway
|
||||||
|
plural: gateways
|
||||||
|
scope: Namespaced
|
||||||
|
additionalPrinterColumns:
|
||||||
|
- name: ha-status
|
||||||
|
type: string
|
||||||
|
description: High Availability Status of the Gateway
|
||||||
|
JSONPath: .status.haStatus
|
||||||
|
---
|
||||||
|
{{- if .Values.submariner.serviceDiscovery }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: multiclusterservices.lighthouse.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: MultiClusterService
|
||||||
|
plural: multiclusterservices
|
||||||
|
singular: multiclusterservice
|
||||||
|
scope: Namespaced
|
||||||
|
validation:
|
||||||
|
openAPIV3Schema:
|
||||||
|
properties:
|
||||||
|
spec:
|
||||||
|
properties:
|
||||||
|
clusterServiceInfo:
|
||||||
|
properties:
|
||||||
|
clusterID:
|
||||||
|
type: "string"
|
||||||
|
clusterDomain:
|
||||||
|
type: "string"
|
||||||
|
serviceIP:
|
||||||
|
type: "string"
|
||||||
|
port:
|
||||||
|
type: "integer"
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceexports.lighthouse.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v2alpha1
|
||||||
|
names:
|
||||||
|
kind: ServiceExport
|
||||||
|
plural: serviceexports
|
||||||
|
singular: serviceexport
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceimports.lighthouse.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v2alpha1
|
||||||
|
names:
|
||||||
|
kind: ServiceImport
|
||||||
|
plural: serviceimports
|
||||||
|
singular: serviceimport
|
||||||
|
scope: Namespaced
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
@@ -1,14 +1,34 @@
|
|||||||
{{ include "broker-role" $ }}
|
{{- if .Values.rbac.create -}}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||||
|
app: {{ template "submariner-k8s-broker.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups: ["submariner.io"]
|
||||||
|
resources: ["clusters", "endpoints"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||||
|
- apiGroups: ["lighthouse.submariner.io"]
|
||||||
|
resources: ["*"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||||
|
- apiGroups: ["discovery.k8s.io"]
|
||||||
|
resources: ["endpointslices"]
|
||||||
|
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: Role
|
kind: Role
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
|
{{- end -}}
|
||||||
@@ -1,3 +1,4 @@
|
|||||||
|
{{- if .Values.serviceAccounts.client.create }}
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
@@ -7,11 +8,4 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||||
app: {{ template "submariner-k8s-broker.name" . }}
|
app: {{ template "submariner-k8s-broker.name" . }}
|
||||||
---
|
{{- end }}
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
|
|
||||||
annotations:
|
|
||||||
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
|
||||||
type: kubernetes.io/service-account-token
|
|
||||||
@@ -1 +1,11 @@
|
|||||||
---
|
---
|
||||||
|
rbac:
|
||||||
|
create: true
|
||||||
|
crd:
|
||||||
|
create: true
|
||||||
|
serviceAccounts:
|
||||||
|
client:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
submariner:
|
||||||
|
serviceDiscovery: false
|
||||||
|
|||||||
@@ -1,58 +0,0 @@
|
|||||||
# submariner-operator
|
|
||||||
|
|
||||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
|
||||||
|
|
||||||
**Homepage:** <https://submariner-io.github.io/>
|
|
||||||
|
|
||||||
## Maintainers
|
|
||||||
|
|
||||||
| Name | Email | Url |
|
|
||||||
| ---- | ------ | --- |
|
|
||||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
|
||||||
|
|
||||||
## Source Code
|
|
||||||
|
|
||||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
|
||||||
|
|
||||||
## Values
|
|
||||||
|
|
||||||
| Key | Type | Default | Description |
|
|
||||||
| ----- | ------ | --------- | ------------- |
|
|
||||||
| broker.ca | string | `""` | |
|
|
||||||
| broker.globalnet | bool | `false` | |
|
|
||||||
| broker.insecure | bool | `false` | |
|
|
||||||
| broker.namespace | string | `"xyz"` | |
|
|
||||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
|
||||||
| broker.token | string | `"test"` | |
|
|
||||||
| ipsec.debug | bool | `false` | |
|
|
||||||
| ipsec.forceUDPEncaps | bool | `false` | |
|
|
||||||
| ipsec.ikePort | int | `500` | |
|
|
||||||
| ipsec.natPort | int | `4500` | |
|
|
||||||
| ipsec.pskSecret | string | `""` | Name of the Kubernetes Secret containing the IPsec PSK as field psk |
|
|
||||||
| ipsec.psk | string | `""` | |
|
|
||||||
| leadership.leaseDuration | int | `10` | |
|
|
||||||
| leadership.renewDeadline | int | `5` | |
|
|
||||||
| leadership.retryPeriod | int | `2` | |
|
|
||||||
| operator.affinity | object | `{}` | |
|
|
||||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
|
||||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
|
||||||
| operator.image.tag | string | `"0.14.0"` | |
|
|
||||||
| operator.resources | object | `{}` | |
|
|
||||||
| operator.tolerations | list | `[]` | |
|
|
||||||
| submariner.cableDriver | string | `"libreswan"` | |
|
|
||||||
| submariner.clusterCidr | string | `""` | |
|
|
||||||
| submariner.clusterId | string | `""` | |
|
|
||||||
| submariner.colorCodes | string | `"blue"` | |
|
|
||||||
| submariner.coreDNSCustomConfig | object | `{}` | |
|
|
||||||
| submariner.debug | bool | `false` | |
|
|
||||||
| submariner.globalCidr | string | `""` | |
|
|
||||||
| submariner.clustersetIpCidr | string | `""` | |
|
|
||||||
| submariner.clustersetIpEnabled | bool | `false` | |
|
|
||||||
| submariner.healthcheckEnabled | bool | `true` | |
|
|
||||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
|
||||||
| submariner.images.tag | string | `"0.14.0"` | |
|
|
||||||
| submariner.natEnabled | bool | `false` | |
|
|
||||||
| submariner.serviceCidr | string | `""` | |
|
|
||||||
| submariner.brokerK8sSecret | string | `""` | Name of the Kubernetes Secret containing broker credentials (ca.crt, token). |
|
|
||||||
| submariner.serviceDiscovery | bool | `true` | |
|
|
||||||
| submariner.token | string | `""` | |
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
# Submariner
|
|
||||||
|
|
||||||
[Submariner](https://submariner.io) is a cross-cluster networking tool.
|
|
||||||
|
|
||||||
This chart creates the required components in this cluster to deploy the Submariner operator.
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
||||||
If release name contains chart name it will be used as a full name.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride -}}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
|
||||||
{{- if contains $name .Release.Name -}}
|
|
||||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.fullname" . }}
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
spec:
|
|
||||||
progressDeadlineSeconds: 600
|
|
||||||
replicas: 1
|
|
||||||
revisionHistoryLimit: 10
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
strategy:
|
|
||||||
rollingUpdate:
|
|
||||||
maxSurge: 25%
|
|
||||||
maxUnavailable: 25%
|
|
||||||
type: RollingUpdate
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
creationTimestamp: null
|
|
||||||
labels:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- args:
|
|
||||||
- --leader-elect
|
|
||||||
env:
|
|
||||||
- name: WATCH_NAMESPACE
|
|
||||||
valueFrom:
|
|
||||||
fieldRef:
|
|
||||||
apiVersion: v1
|
|
||||||
fieldPath: metadata.namespace
|
|
||||||
- name: POD_NAME
|
|
||||||
valueFrom:
|
|
||||||
fieldRef:
|
|
||||||
apiVersion: v1
|
|
||||||
fieldPath: metadata.name
|
|
||||||
- name: OPERATOR_NAME
|
|
||||||
value: submariner-operator
|
|
||||||
image: {{ .Values.operator.image.repository }}:{{ default .Chart.AppVersion .Values.operator.image.tag }}
|
|
||||||
imagePullPolicy: {{ .Values.operator.image.pullPolicy }}
|
|
||||||
name: submariner-operator
|
|
||||||
resources: {}
|
|
||||||
terminationMessagePath: /dev/termination-log
|
|
||||||
terminationMessagePolicy: File
|
|
||||||
dnsPolicy: ClusterFirst
|
|
||||||
restartPolicy: Always
|
|
||||||
schedulerName: default-scheduler
|
|
||||||
securityContext: {}
|
|
||||||
serviceAccountName: submariner-operator
|
|
||||||
terminationGracePeriodSeconds: 30
|
|
||||||
@@ -1,75 +0,0 @@
|
|||||||
apiVersion: submariner.io/v1alpha1
|
|
||||||
kind: Submariner
|
|
||||||
metadata:
|
|
||||||
name: submariner
|
|
||||||
namespace: submariner-operator
|
|
||||||
spec:
|
|
||||||
broker: k8s
|
|
||||||
brokerK8sApiServer: {{ .Values.broker.server }}
|
|
||||||
{{- if .Values.submariner.brokerK8sSecret }}
|
|
||||||
brokerK8sSecret: {{ .Values.submariner.brokerK8sSecret }}
|
|
||||||
{{- else }}
|
|
||||||
brokerK8sApiServerToken: {{ .Values.broker.token }}
|
|
||||||
brokerK8sCA: {{ .Values.broker.ca }}
|
|
||||||
{{- end }}
|
|
||||||
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
|
|
||||||
brokerK8sInsecure: {{ .Values.broker.insecure }}
|
|
||||||
ceIPSecDebug: {{ .Values.ipsec.debug }}
|
|
||||||
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
|
|
||||||
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
|
|
||||||
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
|
|
||||||
{{- if .Values.ipsec.pskSecret }}
|
|
||||||
ceIPSecPSKSecret: {{ .Values.ipsec.pskSecret }}
|
|
||||||
{{- else }}
|
|
||||||
ceIPSecPSK: {{ .Values.ipsec.psk }}
|
|
||||||
{{- end }}
|
|
||||||
clusterCIDR: "{{ .Values.submariner.clusterCidr }}"
|
|
||||||
clusterID: {{ .Values.submariner.clusterId }}
|
|
||||||
colorCodes: {{ .Values.submariner.colorCodes }}
|
|
||||||
debug: {{ .Values.submariner.debug }}
|
|
||||||
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
natEnabled: {{ .Values.submariner.natEnabled }}
|
|
||||||
repository: {{ .Values.submariner.images.repository }}
|
|
||||||
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }}
|
|
||||||
{{- with .Values.images }}
|
|
||||||
{{- if . }}
|
|
||||||
imageOverrides:
|
|
||||||
{{- if index . "submariner-operator" }}
|
|
||||||
submariner-operator: {{ index . "submariner-operator" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if index . "submariner-gateway" }}
|
|
||||||
submariner-gateway: {{ index . "submariner-gateway" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if index . "submariner-route-agent" }}
|
|
||||||
submariner-routeagent: {{ index . "submariner-route-agent" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if index . "submariner-globalnet" }}
|
|
||||||
submariner-globalnet: {{ index . "submariner-globalnet" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if index . "submariner-networkplugin-syncer" }}
|
|
||||||
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if index . "lighthouse-agent" }}
|
|
||||||
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if index . "lighthouse-coredns" }}
|
|
||||||
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
|
||||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
|
||||||
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
|
|
||||||
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
|
|
||||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
|
||||||
cableDriver: {{ .Values.submariner.cableDriver }}
|
|
||||||
connectionHealthCheck:
|
|
||||||
enabled: {{ .Values.submariner.healthcheckEnabled }}
|
|
||||||
intervalSeconds: 1
|
|
||||||
maxPacketLossCount: 5
|
|
||||||
{{- with .Values.submariner.coreDNSCustomConfig }}
|
|
||||||
coreDNSCustomConfig:
|
|
||||||
configMapName: {{ .configMapName }}
|
|
||||||
namespace: {{ .namespace }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,48 +0,0 @@
|
|||||||
---
|
|
||||||
submariner:
|
|
||||||
clusterId: ""
|
|
||||||
token: ""
|
|
||||||
clusterCidr: ""
|
|
||||||
serviceCidr: ""
|
|
||||||
globalCidr: ""
|
|
||||||
clustersetIpCidr: ""
|
|
||||||
clustersetIpEnabled: false
|
|
||||||
brokerK8sSecret: ""
|
|
||||||
loadBalancerEnabled: false
|
|
||||||
natEnabled: false
|
|
||||||
colorCodes: blue
|
|
||||||
debug: false
|
|
||||||
serviceDiscovery: true
|
|
||||||
cableDriver: "libreswan"
|
|
||||||
healthcheckEnabled: true
|
|
||||||
coreDNSCustomConfig: {}
|
|
||||||
images:
|
|
||||||
repository: quay.io/submariner
|
|
||||||
tag: ""
|
|
||||||
broker:
|
|
||||||
server: example.k8s.apiserver
|
|
||||||
token: test
|
|
||||||
namespace: xyz
|
|
||||||
insecure: false
|
|
||||||
ca: ""
|
|
||||||
globalnet: false
|
|
||||||
images: {}
|
|
||||||
ipsec:
|
|
||||||
psk: ""
|
|
||||||
pskSecret: ""
|
|
||||||
debug: false
|
|
||||||
forceUDPEncaps: false
|
|
||||||
ikePort: 500
|
|
||||||
natPort: 4500
|
|
||||||
leadership:
|
|
||||||
leaseDuration: 10
|
|
||||||
renewDeadline: 5
|
|
||||||
retryPeriod: 2
|
|
||||||
operator:
|
|
||||||
image:
|
|
||||||
repository: quay.io/submariner/submariner-operator
|
|
||||||
tag: ""
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
resources: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
@@ -1,13 +1,12 @@
|
|||||||
---
|
---
|
||||||
name: submariner-operator
|
name: submariner
|
||||||
version: 0.0.0
|
version: 0.6.0
|
||||||
apiVersion: v2
|
appVersion: 0.6.0
|
||||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||||
keywords:
|
keywords:
|
||||||
home: https://submariner-io.github.io/
|
home: https://submariner-io.github.io/
|
||||||
sources:
|
sources:
|
||||||
- https://submariner-io.github.io/submariner-charts/charts
|
- https://submariner-io.github.io/submariner-charts/charts
|
||||||
maintainers:
|
maintainers:
|
||||||
- name: Contributors to the Submariner project
|
- name: Submariner Developers
|
||||||
email: submariner-dev@googlegroups.com
|
email: submariner-dev@googlegroups.com
|
||||||
url: https://submariner.io/
|
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
# Submariner
|
||||||
|
|
||||||
|
[Submariner](https://submariner.io) is a cross-cluster networking tool.
|
||||||
|
|
||||||
|
This chart creates the required components in this cluster to enable cross cluster networking.
|
||||||
@@ -0,0 +1,138 @@
|
|||||||
|
questions:
|
||||||
|
- variable: defaultEngineImage
|
||||||
|
default: true
|
||||||
|
description: "Use default Submariner Engine image or specify a custom one"
|
||||||
|
label: Use default submariner engine image
|
||||||
|
type: boolean
|
||||||
|
show_subquestion_if: false
|
||||||
|
group: "Container Images"
|
||||||
|
subquestions:
|
||||||
|
- variable: engine.image.repository
|
||||||
|
default: "quay.io/submariner/submariner"
|
||||||
|
description: "Submariner Engine Image Repository"
|
||||||
|
type: string
|
||||||
|
label: Submariner Engine Image Repository
|
||||||
|
- variable: engine.image.tag
|
||||||
|
default: "0.6.0"
|
||||||
|
description: "Submariner Engine Image Tag"
|
||||||
|
type: string
|
||||||
|
label: Submariner Engine Image Tag
|
||||||
|
- variable: defaultRouteAgentImage
|
||||||
|
default: true
|
||||||
|
description: "Use default Submariner Route Agent image or specify a custom one"
|
||||||
|
label: Use default submariner route agent image
|
||||||
|
type: boolean
|
||||||
|
show_subquestion_if: false
|
||||||
|
group: "Container Images"
|
||||||
|
subquestions:
|
||||||
|
- variable: routeAgent.image.repository
|
||||||
|
default: "quay.io/submariner/submariner-route-agent"
|
||||||
|
description: "Submariner Route Agent Image Repository"
|
||||||
|
type: string
|
||||||
|
label: Submariner Route Agent Image Repository
|
||||||
|
- variable: routeAgent.image.tag
|
||||||
|
default: "0.6.0"
|
||||||
|
description: "Submariner Route Agent Image Tag"
|
||||||
|
type: string
|
||||||
|
label: Submariner Route Agent Image Tag
|
||||||
|
- variable: engine.nodeSelectorEnabled
|
||||||
|
default: true
|
||||||
|
description: "Restrict submariner to nodes labeled with submariner.io/gateway=true"
|
||||||
|
label: Restrict gateway deployments to specific nodes
|
||||||
|
type: boolean
|
||||||
|
group: "Gateway Configuration"
|
||||||
|
- variable: submariner.clusterId
|
||||||
|
default: ""
|
||||||
|
description: "Enter a unique cluster ID to identify this cluster"
|
||||||
|
type: string
|
||||||
|
label: "Cluster ID"
|
||||||
|
group: "Configuration"
|
||||||
|
required: true
|
||||||
|
- variable: ipsec.psk
|
||||||
|
default: ""
|
||||||
|
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
||||||
|
type: string
|
||||||
|
label: "IPsec Pre-Shared Key"
|
||||||
|
group: "Configuration"
|
||||||
|
required: true
|
||||||
|
- variable: broker.type
|
||||||
|
type: enum
|
||||||
|
default: k8s
|
||||||
|
options:
|
||||||
|
- k8s
|
||||||
|
group: "Broker Configuration"
|
||||||
|
label: "Broker Type"
|
||||||
|
description: "Type of Broker to use"
|
||||||
|
- variable: broker.server
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
group: "Broker Configuration"
|
||||||
|
label: "Broker Server"
|
||||||
|
description: "Broker server to use (without the https://)"
|
||||||
|
- variable: broker.insecure
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
show_subquestion_if: false
|
||||||
|
group: "Broker Configuration"
|
||||||
|
label: "Insecure Broker"
|
||||||
|
description: "Connect to K8s broker without validating CA"
|
||||||
|
subquestions:
|
||||||
|
- variable: broker.ca
|
||||||
|
type: string
|
||||||
|
description: "Base64 encoded broker ca.crt"
|
||||||
|
label: "Broker CA encoded in base64"
|
||||||
|
default: ""
|
||||||
|
- variable: broker.token
|
||||||
|
type: string
|
||||||
|
group: "Broker Configuration"
|
||||||
|
label: "Broker Token"
|
||||||
|
description: "Bearer token for broker"
|
||||||
|
- variable: broker.namespace
|
||||||
|
type: string
|
||||||
|
group: "Broker Configuration"
|
||||||
|
label: "Broker Namespace"
|
||||||
|
description: "Enter namespace to use on central broker"
|
||||||
|
- variable: submariner.clusterCidr
|
||||||
|
default: ""
|
||||||
|
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
||||||
|
type: string
|
||||||
|
label: "Cluster CIDR"
|
||||||
|
group: "CIDR Configuration"
|
||||||
|
required: true
|
||||||
|
- variable: submariner.serviceCidr
|
||||||
|
default: ""
|
||||||
|
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
||||||
|
type: string
|
||||||
|
label: "Service CIDR"
|
||||||
|
group: "CIDR Configuration"
|
||||||
|
required: true
|
||||||
|
- variable: submariner.natEnabled
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
group: "Advanced Configuration"
|
||||||
|
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
||||||
|
label: "NAT Enabled"
|
||||||
|
- variable: crd.create
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
group: "Advanced Configuration"
|
||||||
|
description: "Create the Submariner CRDs, if deploying Submariner into the same cluster as the submariner-k8s-broker, you probably shouldn't create CRDs"
|
||||||
|
label: "CRD Creation Enabled"
|
||||||
|
- variable: submariner.debug
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
group: "Advanced Configuration"
|
||||||
|
description: "Enable submariner debug mode"
|
||||||
|
label: "Submariner Debug Enabled"
|
||||||
|
- variable: ipsec.debug
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
group: "Advanced Configuration"
|
||||||
|
description: "Enable Charon debug mode"
|
||||||
|
label: "Charon Enabled"
|
||||||
|
- variable: submariner.cableDriver
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
group: "Advanced Configuration"
|
||||||
|
description: "Cable driver implementation"
|
||||||
|
label: "Cable Driver"
|
||||||
@@ -1,3 +1,7 @@
|
|||||||
Submariner is now installed.
|
Submariner is now installed.
|
||||||
|
|
||||||
|
{{- if .Values.engine.nodeSelectorEnabled }}
|
||||||
|
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride -}}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||||
|
{{- if contains $name .Release.Name -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-engine service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.engineServiceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccounts.engine.create -}}
|
||||||
|
{{ default (printf "%s-engine" (include "submariner.fullname" .)) .Values.serviceAccounts.engine.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.engine.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-route-agent service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.routeAgentServiceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
||||||
|
{{ default (printf "%s-routeagent" (include "submariner.fullname" .)) .Values.serviceAccounts.routeAgent.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-globalnet service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.globalnetServiceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccounts.globalnet.create -}}
|
||||||
|
{{ default (printf "%s-globalnet" (include "submariner.fullname" .)) .Values.serviceAccounts.globalnet.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.globalnet.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-lighthouse service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.lighthouseServiceAccountName" -}}
|
||||||
|
{{- if .Values.submariner.serviceDiscovery -}}
|
||||||
|
{{ default (printf "%s-lighthouse" (include "submariner.fullname" .)) .Values.serviceAccounts.lighthouse.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.lighthouse.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-lighthouse-coredns service name to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.lighthouseDnsName" -}}
|
||||||
|
{{- default (printf "%s-lighthouse-coredns" (include "submariner.fullname" .)) .Values.lighthouseCoredns.name }}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,110 @@
|
|||||||
|
{{- if .Values.crd.create -}}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: clusters.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Cluster
|
||||||
|
plural: clusters
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: endpoints.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Endpoint
|
||||||
|
plural: endpoints
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: gateways.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Gateway
|
||||||
|
plural: gateways
|
||||||
|
scope: Namespaced
|
||||||
|
additionalPrinterColumns:
|
||||||
|
- name: ha-status
|
||||||
|
type: string
|
||||||
|
description: High Availability Status of the Gateway
|
||||||
|
JSONPath: .status.haStatus
|
||||||
|
---
|
||||||
|
{{- if .Values.submariner.serviceDiscovery }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: multiclusterservices.lighthouse.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: MultiClusterService
|
||||||
|
plural: multiclusterservices
|
||||||
|
singular: multiclusterservice
|
||||||
|
scope: Namespaced
|
||||||
|
validation:
|
||||||
|
openAPIV3Schema:
|
||||||
|
properties:
|
||||||
|
spec:
|
||||||
|
properties:
|
||||||
|
clusterServiceInfo:
|
||||||
|
properties:
|
||||||
|
clusterID:
|
||||||
|
type: "string"
|
||||||
|
clusterDomain:
|
||||||
|
type: "string"
|
||||||
|
serviceIP:
|
||||||
|
type: "string"
|
||||||
|
port:
|
||||||
|
type: "integer"
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceexports.lighthouse.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v2alpha1
|
||||||
|
names:
|
||||||
|
kind: ServiceExport
|
||||||
|
plural: serviceexports
|
||||||
|
singular: serviceexport
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceimports.lighthouse.submariner.io
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": crd-install
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v2alpha1
|
||||||
|
names:
|
||||||
|
kind: ServiceImport
|
||||||
|
plural: serviceimports
|
||||||
|
singular: serviceimport
|
||||||
|
scope: Namespaced
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,134 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.fullname" . }}-engine
|
||||||
|
component: engine
|
||||||
|
name: {{ template "submariner.fullname" . }}-gateway
|
||||||
|
spec:
|
||||||
|
revisionHistoryLimit: 5
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ template "submariner.fullname" . }}-engine
|
||||||
|
updateStrategy:
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 1
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: null
|
||||||
|
labels:
|
||||||
|
app: {{ template "submariner.fullname" . }}-engine
|
||||||
|
spec:
|
||||||
|
affinity:
|
||||||
|
podAntiAffinity:
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- labelSelector:
|
||||||
|
matchExpressions:
|
||||||
|
- key: app
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
- {{ template "submariner.fullname" . }}-engine
|
||||||
|
topologyKey: "kubernetes.io/hostname"
|
||||||
|
{{- with .Values.engine.affinity }}
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- if .Values.engine.nodeSelectorEnabled }}
|
||||||
|
submariner.io/gateway: "true"
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.engine.nodeSelector }}
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.engine.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- command:
|
||||||
|
- submariner.sh
|
||||||
|
env:
|
||||||
|
- name: SUBMARINER_NAMESPACE
|
||||||
|
value: "{{ .Release.Namespace }}"
|
||||||
|
- name: SUBMARINER_CLUSTERCIDR
|
||||||
|
value: "{{ .Values.submariner.clusterCidr }}"
|
||||||
|
- name: SUBMARINER_SERVICECIDR
|
||||||
|
value: "{{ .Values.submariner.serviceCidr }}"
|
||||||
|
- name: SUBMARINER_GLOBALCIDR
|
||||||
|
value: "{{ .Values.submariner.globalCidr }}"
|
||||||
|
- name: SUBMARINER_TOKEN
|
||||||
|
value: "{{ .Values.submariner.apiToken }}"
|
||||||
|
- name: SUBMARINER_CLUSTERID
|
||||||
|
value: "{{ .Values.submariner.clusterId }}"
|
||||||
|
- name: SUBMARINER_COLORCODES
|
||||||
|
value: "{{ .Values.submariner.colorCodes }}"
|
||||||
|
- name: SUBMARINER_DEBUG
|
||||||
|
value: "{{ .Values.submariner.debug }}"
|
||||||
|
- name: SUBMARINER_NATENABLED
|
||||||
|
value: "{{ .Values.submariner.natEnabled }}"
|
||||||
|
- name: SUBMARINER_BROKER
|
||||||
|
value: "{{ .Values.broker.type }}"
|
||||||
|
- name: SUBMARINER_CABLEDRIVER
|
||||||
|
value: "{{ .Values.submariner.cableDriver }}"
|
||||||
|
{{- if eq .Values.broker.type "phpapi" }}
|
||||||
|
- name: BROKER_PHPAPI_PROTO
|
||||||
|
value: "{{ .Values.broker.proto }}"
|
||||||
|
- name: BROKER_PHPAPI_SERVER
|
||||||
|
value: "{{ .Values.broker.server }}"
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq .Values.broker.type "k8s" }}
|
||||||
|
- name: BROKER_K8S_APISERVER
|
||||||
|
value: "{{ .Values.broker.server }}"
|
||||||
|
- name: BROKER_K8S_APISERVERTOKEN
|
||||||
|
value: "{{ .Values.broker.token }}"
|
||||||
|
- name: BROKER_K8S_REMOTENAMESPACE
|
||||||
|
value: "{{ .Values.broker.namespace }}"
|
||||||
|
{{- if .Values.broker.insecure }}
|
||||||
|
- name: BROKER_K8S_INSECURE
|
||||||
|
value: "true"
|
||||||
|
{{- else }}
|
||||||
|
- name: BROKER_K8S_CA
|
||||||
|
value: "{{ .Values.broker.ca }}"
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
- name: CE_IPSEC_PSK
|
||||||
|
value: "{{ .Values.ipsec.psk }}"
|
||||||
|
- name: CE_IPSEC_DEBUG
|
||||||
|
value: "{{ .Values.ipsec.debug }}"
|
||||||
|
- name: CE_IPSEC_IKEPORT
|
||||||
|
value: "{{ .Values.ipsec.ikePort }}"
|
||||||
|
- name: CE_IPSEC_NATTPORT
|
||||||
|
value: "{{ .Values.ipsec.natPort }}"
|
||||||
|
- name: LEADERSHIP_LEASEDURATION
|
||||||
|
value: "{{ .Values.leadership.leaseDuration }}"
|
||||||
|
- name: LEADERSHIP_RENEWDEADLINE
|
||||||
|
value: "{{ .Values.leadership.renewDeadline }}"
|
||||||
|
- name: LEADERSHIP_RETRYPERIOD
|
||||||
|
value: "{{ .Values.leadership.retryPeriod }}"
|
||||||
|
image: {{ .Values.engine.image.repository }}:{{ default .Chart.AppVersion .Values.engine.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.engine.image.pullPolicy }}
|
||||||
|
name: submariner
|
||||||
|
resources:
|
||||||
|
{{ toYaml .Values.engine.resources | indent 10 }}
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: true
|
||||||
|
capabilities:
|
||||||
|
add:
|
||||||
|
- ALL
|
||||||
|
privileged: true
|
||||||
|
readOnlyRootFilesystem: false
|
||||||
|
runAsNonRoot: false
|
||||||
|
stdin: true
|
||||||
|
terminationMessagePath: /dev/termination-log
|
||||||
|
terminationMessagePolicy: File
|
||||||
|
tty: true
|
||||||
|
dnsPolicy: ClusterFirst
|
||||||
|
hostNetwork: true
|
||||||
|
restartPolicy: Always
|
||||||
|
schedulerName: default-scheduler
|
||||||
|
securityContext: {}
|
||||||
|
terminationGracePeriodSeconds: 1
|
||||||
|
serviceAccountName: {{ template "submariner.engineServiceAccountName" . }}
|
||||||
@@ -0,0 +1,59 @@
|
|||||||
|
{{- if ne .Values.submariner.globalCidr "" }}
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}-globalnet
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.fullname" . }}-globalnet
|
||||||
|
component: globalnet
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ template "submariner.fullname" . }}-globalnet
|
||||||
|
updateStrategy:
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 1
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ template "submariner.fullname" . }}-globalnet
|
||||||
|
spec:
|
||||||
|
hostNetwork: true
|
||||||
|
serviceAccountName: submariner-globalnet
|
||||||
|
serviceAccount: submariner-globalnet
|
||||||
|
terminationGracePeriodSeconds: 2
|
||||||
|
nodeSelector:
|
||||||
|
submariner.io/gateway: 'true'
|
||||||
|
containers:
|
||||||
|
- name: {{ template "submariner.fullname" . }}-globalnet
|
||||||
|
image: {{ .Values.globalnet.image.repository }}:{{ default .Chart.AppVersion .Values.globalnet.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.globalnet.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: SUBMARINER_CLUSTERID
|
||||||
|
value: '{{ .Values.submariner.clusterId }}'
|
||||||
|
- name: SUBMARINER_EXCLUDENS
|
||||||
|
value: 'submariner-operator,kube-system,operators'
|
||||||
|
- name: SUBMARINER_NAMESPACE
|
||||||
|
value: '{{ .Release.Namespace }}'
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: true
|
||||||
|
capabilities:
|
||||||
|
add:
|
||||||
|
- ALL
|
||||||
|
privileged: true
|
||||||
|
readOnlyRootFilesystem: false
|
||||||
|
runAsNonRoot: false
|
||||||
|
volumeMounts:
|
||||||
|
# Because we don't actually run iptables locally, but chroot in to the host
|
||||||
|
- mountPath: /host
|
||||||
|
name: host-slash
|
||||||
|
readOnly: true
|
||||||
|
volumes:
|
||||||
|
- name: host-slash
|
||||||
|
hostPath:
|
||||||
|
path: /
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
{{- if .Values.submariner.serviceDiscovery }}
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
component: lighthouse-coredns
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
replicas: 2
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- args:
|
||||||
|
- -conf
|
||||||
|
- /etc/coredns/Corefile
|
||||||
|
image: {{ .Values.lighthouseCoredns.image.repository }}:{{ default .Chart.AppVersion .Values.lighthouseCoredns.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.lighthouseCoredns.image.pullPolicy }}
|
||||||
|
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/coredns
|
||||||
|
name: config-volume
|
||||||
|
readOnly: true
|
||||||
|
serviceAccountName: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||||
|
volumes:
|
||||||
|
- configMap:
|
||||||
|
defaultMode: 420
|
||||||
|
items:
|
||||||
|
- key: Corefile
|
||||||
|
path: Corefile
|
||||||
|
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
name: config-volume
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
labels:
|
||||||
|
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: udp
|
||||||
|
port: 53
|
||||||
|
protocol: UDP
|
||||||
|
targetPort: 53
|
||||||
|
selector:
|
||||||
|
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
type: ClusterIP
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||||
|
data:
|
||||||
|
Corefile: |
|
||||||
|
clusterset.local:53 {
|
||||||
|
{{- if .Values.submariner.debug }}
|
||||||
|
log
|
||||||
|
{{- end }}
|
||||||
|
lighthouse
|
||||||
|
errors
|
||||||
|
health
|
||||||
|
ready
|
||||||
|
}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
{{- if .Values.submariner.serviceDiscovery }}
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||||
|
component: lighthouse
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||||
|
spec:
|
||||||
|
serviceAccountName: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||||
|
containers:
|
||||||
|
- command:
|
||||||
|
- lighthouse-agent.sh
|
||||||
|
env:
|
||||||
|
- name: SUBMARINER_NAMESPACE
|
||||||
|
value: "{{ .Release.Namespace }}"
|
||||||
|
- name: SUBMARINER_CLUSTERID
|
||||||
|
value: "{{ .Values.submariner.clusterId }}"
|
||||||
|
- name: SUBMARINER_DEBUG
|
||||||
|
value: "{{ .Values.submariner.debug }}"
|
||||||
|
{{- if ne .Values.submariner.globalCidr "" }}
|
||||||
|
- name: SUBMARINER_GLOBALNET_ENABLED
|
||||||
|
value: "true"
|
||||||
|
{{- end }}
|
||||||
|
- name: BROKER_K8S_APISERVER
|
||||||
|
value: "{{ .Values.broker.server }}"
|
||||||
|
- name: BROKER_K8S_APISERVERTOKEN
|
||||||
|
value: "{{ .Values.broker.token }}"
|
||||||
|
- name: BROKER_K8S_REMOTENAMESPACE
|
||||||
|
value: "{{ .Values.broker.namespace }}"
|
||||||
|
{{- if .Values.broker.insecure }}
|
||||||
|
- name: BROKER_K8S_INSECURE
|
||||||
|
value: "true"
|
||||||
|
{{- else }}
|
||||||
|
- name: BROKER_K8S_CA
|
||||||
|
value: "{{ .Values.broker.ca }}"
|
||||||
|
{{- end }}
|
||||||
|
name: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||||
|
image: {{ .Values.lighthouse.image.repository }}:{{ default .Chart.AppVersion .Values.lighthouse.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.lighthouse.image.pullPolicy }}
|
||||||
|
restartPolicy: Always
|
||||||
|
terminationGracePeriodSeconds: 0
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,146 @@
|
|||||||
|
{{- if .Values.rbac.create -}}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:engine
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["configmaps"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
||||||
|
- apiGroups: ["submariner.io"]
|
||||||
|
resources: ["clusters", "endpoints", "gateways"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["events"]
|
||||||
|
verbs: ["create", "patch"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups: ["submariner.io"]
|
||||||
|
resources: ["clusters", "endpoints", "gateways"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["pods"]
|
||||||
|
verbs: ["get", "watch", "list"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:engine
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ template "submariner.fullname" . }}:engine
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.engineServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
rules:
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["nodes"]
|
||||||
|
verbs: ["get", "update"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
{{- if ne .Values.submariner.globalCidr "" }}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
rules:
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["services", "namespaces", "pods", "nodes"]
|
||||||
|
verbs: ["get", "list", "watch", "update"]
|
||||||
|
- apiGroups: ["submariner.io"]
|
||||||
|
resources: ["clusters", "endpoints", "gateways"]
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
{{- end -}}
|
||||||
|
{{- if .Values.submariner.serviceDiscovery }}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||||
|
rules:
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["services", "namespaces", "configmaps", "endpoints"]
|
||||||
|
verbs: ["get", "list", "watch", "update"]
|
||||||
|
- apiGroups: ["discovery.k8s.io"]
|
||||||
|
resources: ["endpointslices"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "update", "delete", "deletecollection"]
|
||||||
|
- apiGroups: ["lighthouse.submariner.io"]
|
||||||
|
resources: ["*"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||||
|
- apiGroups: ["submariner.io"]
|
||||||
|
resources: ["gateways"]
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,78 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}-routeagent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.fullname" . }}-routeagent
|
||||||
|
component: routeagent
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ template "submariner.fullname" . }}-routeagent
|
||||||
|
updateStrategy:
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: "100%"
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.fullname" . }}-routeagent
|
||||||
|
component: routeagent
|
||||||
|
spec:
|
||||||
|
serviceAccountName: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
terminationGracePeriodSeconds: 1
|
||||||
|
hostNetwork: true
|
||||||
|
containers:
|
||||||
|
- name: routeagent
|
||||||
|
command:
|
||||||
|
- submariner-route-agent.sh
|
||||||
|
image: {{ .Values.routeAgent.image.repository }}:{{ default .Chart.AppVersion .Values.routeAgent.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.routeAgent.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: SUBMARINER_NAMESPACE
|
||||||
|
value: "{{ .Release.Namespace }}"
|
||||||
|
- name: SUBMARINER_CLUSTERID
|
||||||
|
value: "{{ .Values.submariner.clusterId }}"
|
||||||
|
- name: SUBMARINER_DEBUG
|
||||||
|
value: "{{ .Values.submariner.debug }}"
|
||||||
|
- name: SUBMARINER_CLUSTERCIDR
|
||||||
|
value: "{{ .Values.submariner.clusterCidr }}"
|
||||||
|
- name: SUBMARINER_SERVICECIDR
|
||||||
|
value: "{{ .Values.submariner.serviceCidr }}"
|
||||||
|
resources:
|
||||||
|
{{ toYaml .Values.routeAgent.resources | indent 10 }}
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: true
|
||||||
|
capabilities:
|
||||||
|
add:
|
||||||
|
- ALL
|
||||||
|
privileged: true
|
||||||
|
readOnlyRootFilesystem: false
|
||||||
|
runAsNonRoot: false
|
||||||
|
volumeMounts:
|
||||||
|
# Because we don't actually run iptables locally, but chroot in to the host
|
||||||
|
- mountPath: /host
|
||||||
|
name: host-slash
|
||||||
|
readOnly: true
|
||||||
|
{{- with .Values.routeAgent.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.routeAgent.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.routeAgent.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: host-slash
|
||||||
|
hostPath:
|
||||||
|
path: /
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
{{- if .Values.serviceAccounts.engine.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.engineServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.routeAgent.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.globalnet.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.lighthouse.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
---
|
||||||
|
submariner:
|
||||||
|
clusterId: ""
|
||||||
|
token: ""
|
||||||
|
clusterCidr: "10.42.0.0/16"
|
||||||
|
serviceCidr: "10.43.0.0/16"
|
||||||
|
globalCidr: ""
|
||||||
|
natEnabled: false
|
||||||
|
colorCodes: blue
|
||||||
|
debug: false
|
||||||
|
serviceDiscovery: false
|
||||||
|
crd:
|
||||||
|
create: true
|
||||||
|
broker:
|
||||||
|
type: k8s
|
||||||
|
server: example.k8s.apiserver
|
||||||
|
token: test
|
||||||
|
namespace: xyz
|
||||||
|
insecure: false
|
||||||
|
ca: ""
|
||||||
|
rbac:
|
||||||
|
create: true
|
||||||
|
ipsec:
|
||||||
|
psk: ""
|
||||||
|
debug: false
|
||||||
|
ikePort: 500
|
||||||
|
natPort: 4500
|
||||||
|
leadership:
|
||||||
|
leaseDuration: 10
|
||||||
|
renewDeadline: 5
|
||||||
|
retryPeriod: 2
|
||||||
|
engine:
|
||||||
|
image:
|
||||||
|
repository: quay.io/submariner/submariner
|
||||||
|
tag: ""
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
resources: {}
|
||||||
|
nodeSelectorEnabled: true
|
||||||
|
nodeSelector: {}
|
||||||
|
tolerations: []
|
||||||
|
affinity: {}
|
||||||
|
routeAgent:
|
||||||
|
image:
|
||||||
|
repository: quay.io/submariner/submariner-route-agent
|
||||||
|
tag: ""
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
resources: {}
|
||||||
|
nodeSelector: {}
|
||||||
|
tolerations: []
|
||||||
|
affinity: {}
|
||||||
|
globalnet:
|
||||||
|
image:
|
||||||
|
repository: quay.io/submariner/submariner-globalnet
|
||||||
|
tag: ""
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
lighthouse:
|
||||||
|
image:
|
||||||
|
repository: quay.io/submariner/lighthouse-agent
|
||||||
|
tag: ""
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
lighthouseCoredns:
|
||||||
|
name: ""
|
||||||
|
image:
|
||||||
|
repository: quay.io/submariner/lighthouse-coredns
|
||||||
|
tag: ""
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
serviceAccounts:
|
||||||
|
engine:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
routeAgent:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
globalnet:
|
||||||
|
create: false
|
||||||
|
name: ""
|
||||||
|
lighthouse:
|
||||||
|
create: false
|
||||||
|
name: ""
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
//go:build yamls
|
|
||||||
|
|
||||||
/*
|
|
||||||
SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
Copyright Contributors to the Submariner project.
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
*/
|
|
||||||
|
|
||||||
// Place any runtime dependencies as imports in this file.
|
|
||||||
// Go modules will be forced to download and install them.
|
|
||||||
|
|
||||||
package yamls
|
|
||||||
|
|
||||||
import (
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/broker/broker-client"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/openshift/rbac/submariner-metrics-reader"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-gateway"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-globalnet"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-operator"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-route-agent"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/rbac/lighthouse-agent"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/config/rbac/lighthouse-coredns"
|
|
||||||
_ "github.com/submariner-io/submariner-operator/deploy/crds"
|
|
||||||
_ "github.com/submariner-io/submariner/deploy/crds"
|
|
||||||
_ "sigs.k8s.io/mcs-api/config/crd"
|
|
||||||
)
|
|
||||||
Reference in New Issue
Block a user