Compare commits

...
43 Commits
Author SHA1 Message Date
Alexey RoytmanandGitHub d82c6ce442 Update the README file (#19)
* Update the README file

* update README file with shipyard changes
2020-04-16 09:40:21 -04:00
Miguel Angel Ajo PelayoandGitHub 77b41721a9 Merge pull request #24 from skitt/gateway-crd
Add Gateway CRD
2020-04-15 16:57:22 +02:00
Stephen Kitt 5888e837ce Add Gateway CRD
This will be used to store and report the cluster-local engine
status.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2020-04-14 10:54:14 +02:00
Miguel Angel Ajo PelayoandGitHub 8213fe55f0 Merge pull request #21 from sridhargaddam/route-agent-get-nodes
Add ClusterRole for route-agent to annotate a node
2020-04-13 16:36:50 +02:00
Miguel Angel Ajo PelayoandGitHub 8fa5ec5c03 Merge pull request #20 from sridhargaddam/gncontroller-nodes
Add role for globalnet controller to annotate a node
2020-04-13 16:36:02 +02:00
Sridhar Gaddam ae121cfdc4 Add ClusterRole for route-agent to annotate a node
As part of supporting connectivity from HostNetwork to remoteClusters, globalnet
controller requires the CNIInterfaceIP on each node. This PR adds the necessary
clusterRoles for the route-agent daemonSet which will annotate the node with the
CNIInterfaceIP on that respective node.

Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
2020-04-10 14:36:00 +05:30
Sridhar Gaddam 80bdf3eb07 Add role for globalnet controller to annotate a node
As part of supporting connectivity from HostNetwork to remoteClusters, globalnet
controller annotates a node with globalIP. This PR adds the necessary roles for
globalnetController.

Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
2020-04-09 22:58:57 +05:30
Miguel Angel Ajo PelayoandGitHub f3ff20e128 Update travis.yml to fail if deployment fails 2020-03-13 12:15:24 +01:00
Miguel Angel Ajo PelayoandGitHub 535256f640 Merge pull request #15 from sridhargaddam/leader-election
Make Gateway Leadership variables configurable
2020-03-11 18:23:21 +01:00
Miguel Angel Ajo PelayoandGitHub 232bb7478c Merge pull request #16 from mkolesnik/local-reg-globalnet
Support globalnet image specification
2020-03-11 15:28:37 +01:00
Mike Kolesnik 116615040a Support globalnet image specification
This is necessary to allow globalnet image to be stored in local
registry.
2020-03-11 10:30:34 +02:00
Sridhar Gaddam 9041855054 Make Gateway Leadership variables configurable
This PR provides a mechanism to configure the following
Submariner Gateway leader election values
1. leaseDuration
2. renewDeadline
3. retryPeriod

Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
2020-02-13 19:41:26 +05:30
Miguel Angel Ajo PelayoandGitHub f6301aea3a Merge pull request #14 from mangelajo/rename-daemonset-to-gateway
Rename submariner engine daemonset to submariner-gateyway
2020-01-29 13:37:26 +01:00
Miguel Angel Ajo bcd9f800bf Rename submariner engine daemonset to submariner-gateyway
In previous upstream discussions we talked about renaming submariner
engine "deployment" (now daemonset) to submariner-gateway to make
identification of the gateway easier to admins and avoid confusion.

Also see: https://github.com/submariner-io/submariner-operator/pull/145
2020-01-28 16:36:32 +01:00
Miguel Angel Ajo PelayoandGitHub fd672a570c Merge pull request #13 from sridhargaddam/update-sm-engine-as-ds
Update Submariner Engine to a DaemonSet
2020-01-28 16:21:14 +01:00
Sridhar Gaddam d4a0bc4d15 Update Submariner Engine to a DaemonSet
Currently, the Submariner Engine is a deployment with nodeSelector
(for submariner.io/gateway=true). It is seen that when the label
is removed from the node after SM engine is deployed, SM engine
continues to run on that node. This behavior is not in Sync with
the DaemonSet (used by GlobalnetController) behavior where the POD
is immediately terminated when the label is removed from the node.
This PR updates SM engine as DaemonSet so that we have consistent
behavior between the SM Engine POD and GlobalnetController POD.

Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
2020-01-28 19:23:32 +05:30
Miguel Angel Ajo PelayoandGitHub 7200264f5f Merge pull request #12 from mkolesnik/ipam-support
Add support for the Globalnet controller
2020-01-28 14:06:26 +01:00
Mike Kolesnik 04865e056b Added clusters to rbac 2020-01-28 08:27:25 +02:00
Mike Kolesnik fb754f5f2f Added the role & binding for globalnet
Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2020-01-23 14:36:26 +02:00
Mike Kolesnik 35417fa669 Add globalnet service account creation
Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2020-01-22 16:50:32 +02:00
Mike Kolesnik afac49e68e Remove GLOBALCIDR, empty yaml if disabled 2020-01-21 11:49:45 +02:00
Mike Kolesnik 409c875713 Add support for the Globalnet controller
Added a chart for the globalnet controller which uses the global CIDR.
Also added the global CIDR to the submariner engine pod env so it can
utilize it.
The controller will only be deployed if the CIDR is specified.
2020-01-13 10:22:23 +02:00
Dmitry GroismanandGitHub e1a313755c Merge pull request #10 from dimaunx/k8s-1.16.x
Add support for k8s version 1.16.x
2019-12-03 14:44:48 +02:00
Dmitry Groisman f8565a2e30 k8s 1.16.x support 2019-11-25 15:23:22 +02:00
Miguel Angel Ajo PelayoandGitHub ddf1538905 Merge pull request #9 from mangelajo/bump-submariner-to-0.0.2
Bump submariner image versions to 0.0.2
2019-11-05 15:29:50 +01:00
Miguel Angel Ajo 459b9c23bc Bump submariner image versions to 0.0.2 2019-11-04 14:01:36 +01:00
Dmitry GroismanandGitHub c563636ed0 Merge pull request #8 from dimaunx/dev-workflow
Dev workflow proposal
2019-09-27 15:19:10 +03:00
Miguel Angel Ajo PelayoandGitHub 97ebaecb96 Merge pull request #7 from dimaunx/ipsec-custom-port
Add custom ipsec ports support
2019-09-27 10:19:15 +02:00
Dmitry Groisman 129cb73a00 local dev workflow 2019-09-26 16:03:22 +03:00
Dmitry Groisman 8d2c48b8a1 adding custom ipsec ports support 2019-09-26 12:54:02 +03:00
Dmitry Groisman faf5f3e04b fixing sources location 2019-09-05 14:52:52 +03:00
Dmitry Groisman 2b92daa9f8 fixing yaml lint issues 2019-09-05 14:15:44 +03:00
Dmitry Groisman 47638e04f9 helm repo ci 2019-09-05 14:12:53 +03:00
Miguel Angel Ajo PelayoandGitHub 4629754c20 Merge pull request #3 from sridhargaddam/use-iptables-from-host
Fix iptables/nftables issue
2019-09-05 09:56:54 +02:00
Chris KimandGitHub 037bb91428 Merge pull request #1 from sridhargaddam/fix-submariner-broker-url
Update SUBMARINER_BROKER_URL to use https endpoint
2019-09-03 08:25:40 -07:00
Chris KimandGitHub c7433eaaf1 Merge pull request #4 from sridhargaddam/rbac-list-pods
Add RBAC policy for listing pods in sm-route-agent ds pod
2019-09-03 08:24:48 -07:00
Miguel Angel Ajo PelayoandGitHub a77d2ef36f Merge branch 'master' into use-iptables-from-host 2019-09-03 16:46:17 +02:00
Sridhar Gaddam c31d14f3c2 Add RBAC policy for listing pods in sm-route-agent ds pod
Submariner-route-agent daemonset pod needs to query the list of other sm-route-agent
pods in the cluster for their hostIP addresses. The ipaddress will be used as remote
VxLAN Vtep IPs. Currently, sm-route-agent pod does not have the necessary privileges
to list the pods in the submariner namespace of local cluster. This patch addresses
this issue by adding the necessary role.

Error seen:
Failed to list *v1.Pod: pods is forbidden: User
"system:serviceaccount:submariner:submariner-routeagent" cannot list resource "pods"
in API group "" in the namespace "submariner"
2019-08-30 21:32:50 +05:30
Thomas PantelisandGitHub 249e684959 Merge pull request #2 from sridhargaddam/update-route-agent-ds
Update route-agent-ds with Cluster/SVC CIDR values
2019-08-28 08:20:49 -04:00
Sridhar Gaddam 246e8c7f37 Fix iptables/nftables issue
Both iptables and nftables use netfilter framework in the kernel for
packet filtering. Many distributions are moving in the direction of
using nftables over iptables. Although, nftables uses a new command
line utility (named nft), starting from iptables >=1.8, it uses
nftables under the hood while continuing to support the same iptables
syntax from the user.

Quoting from Dan's comment [#]

"In iptables 1.8, the maintainers have "deprecated" the classic ip_tables:
the iptables tool now does userspace translation from the legacy UI/UX,
and uses nf_tables under the hood. So, the commands look and feel the
same, but they're now programming a different kernel subsystem.

The problem arises when you mix and match invocations of iptables 1.6
(the previous stable) and 1.8 on the same machine, because although they
look identical, they're programming different kernel subsystems.

Empirically, this causes weird and wonderful things to happen - things
like if you trace a packet coming from a pod, you see it flowing through
both ip_tables and nf_tables, but even if both accept the packet, it then
vanishes entirely and never gets forwarded"

So, as long as we are programming either nf_tables or iptables, we would
not have any issues. Currently, there is no easy way to identify what type
of rules are programmed on the host. This patch follows the same approach
(as described here [*]) that is taken in OpenShift where the host file
system is mounted inside the docker container and iptables utility on the
host is exec'ed for programming any firewall rules.

[#] https://github.com/kubernetes/kubernetes/issues/71305#issuecomment-448052889
[*] https://github.com/kubernetes/kubernetes/issues/71305#issuecomment-521978797
2019-08-27 16:33:55 +05:30
Sridhar GaddamandGitHub 77cc3ace93 Update route-agent-ds with Cluster/SVC CIDR values 2019-08-14 13:32:29 +05:30
Sridhar Gaddam 7b718471e5 Update SUBMARINER_BROKER_URL to use https endpoint
Normally in a vanilla kubernetes deployment, there is a single endpoint for kubernetes.
However, in some deployments (like OpenShift), there could be multiple endpoints.

This patch updates the SUBMARINER_BROKER_URL to use the appropriate "https" endpoint.
2019-05-17 14:12:07 +05:30
Chris Kim dfcac09089 correct type for ca validation and update rancher catalog item images 2019-03-18 10:09:22 -07:00
17 changed files with 395 additions and 35 deletions
+2
View File
@@ -0,0 +1,2 @@
.idea
*.tgz
+46
View File
@@ -0,0 +1,46 @@
language: python
env:
global:
- HELM_URL=https://storage.googleapis.com/kubernetes-helm
- HELM_TGZ=helm-v2.14.3-linux-amd64.tar.gz
- TARGET_BR=gh-pages
- GH_URL=https://submariner-io.github.io/submariner-charts/charts
- CHARTS_DIR=charts
- YAMLLINT_VERSION=1.17.0
install:
- wget -q ${HELM_URL}/${HELM_TGZ}
- tar xzfv ${HELM_TGZ}
- PATH=`pwd`/linux-amd64/:$PATH
- helm init --client-only
- sudo pip install yamllint=="${YAMLLINT_VERSION}"
script:
- for dir in submariner submariner-k8s-broker; do helm lint $dir; done
- yamllint -c .yamllint.yml -s $(find . -type f -name "Chart.yaml")
- yamllint -c .yamllint.yml -s $(find . -type f -name "values.yaml")
after_success:
- >
if [ $TRAVIS_BRANCH = 'master' ] && [ $TRAVIS_PULL_REQUEST = 'false' ]; then
set -e
for dir in submariner submariner-k8s-broker; do
helm dep update $dir
helm package $dir
done
REPO_URL=`git config remote.origin.url`
git clone ${REPO_URL} out && cd out && git checkout gh-pages && mkdir -p ${CHARTS_DIR}
cp -f ../submariner-*.tgz ${CHARTS_DIR}/
if [ -f charts/index.yaml ]; then
helm repo index ${CHARTS_DIR} --url ${GH_URL} --merge index.yaml
else
helm repo index ${CHARTS_DIR} --url ${GH_URL}
fi
git config user.name "Travis CI"
git config user.email "travis@travis-ci.org"
git add -f ${CHARTS_DIR}/*
git commit -m "Travis build: $TRAVIS_BUILD_NUMBER"
git remote add origin-pages https://${GH_TOKEN}@github.com/submariner-io/submariner-charts.git > /dev/null 2>&1
git push --quiet -f -u origin-pages gh-pages
fi
+15
View File
@@ -0,0 +1,15 @@
---
extends: default
rules:
comments: disable
comments-indentation: disable
line-length:
max: 150
braces:
min-spaces-inside: 0
max-spaces-inside: 0
brackets:
min-spaces-inside: 0
max-spaces-inside: 0
indentation:
indent-sequences: consistent
+114 -1
View File
@@ -1,3 +1,116 @@
# submariner-charts
Please see https://github.com/rancher/submariner for more information. This is only a supporting repository for Submariner
Please see https://github.com/submariner-io/submariner for more information. This is only a supporting repository for Submariner
# Dev workflow.
### Prerequisites
- [helm]
- [docker] or [podman]
### Create a fork and checkout.
[Create a fork] of the original repository, clone it locally and checkout a new branch from master.
Example:
```bash
git clone https://github.com/myuser/submariner-charts.git
cd submariner-charts
git checkout -b new-feature
```
Now you can modify the helm charts according to your needs.
### Serve the modified charts
Before serving the modified charts, the charts must be packaged for local usage.
```bash
helm package ./submariner
helm package ./submariner-k8s-broker
```
Note: if you just installed helm, you have to init the helm, by running
```bash
helm init --client-only
```
Serve the packaged charts through a local helm repository:
```bash
docker run -d --rm --name helm-repo -p 8080:8080 -v $PWD:/charts -e DEBUG=true -e STORAGE=local -e STORAGE_LOCAL_ROOTDIR=/charts chartmuseum/chartmuseum
```
or
```bash
sudo podman run -d --rm --name helm-repo -p 8080:8080 -v $PWD:/charts -e DEBUG=true -e STORAGE=local -e STORAGE_LOCAL_ROOTDIR=/charts chartmuseum/chartmuseum
```
Get the container internal ip:
```bash
docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' helm-repo
```
The local container will serve the charts locally on port 8080.
Get logs for the container:
```bash
docker logs -f helm-repo
```
### Use the modified charts
Init helm
```bash
helm init --client-only
```
Add your local repository to helm
```bash
internal_ip=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' helm-repo)
helm repo add test-repo http://$internal_ip:8080
```
List the repos:
```bash
helm repo list
```
You should be able to see test-repo in the list
Search the new repo for submariner charts:
```bash
helm search -l test-repo
```
### Modify submariner e2e tests helm deployment script to use your local test-repo.
You can test your helm-charts with e2e tests from the [shipyard](https://github.com/submariner-io/shipyard) repository.
In the file `scripts/shared/lib/deploy_helm` change the line from:
```bash
helm repo add submariner-latest https://submariner-io.github.io/submariner-charts/charts
```
to
```bash
internal_ip=$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' helm-repo)
helm repo add submariner-latest http://$internal_ip:8080
```
<!--links-->
[helm]: https://helm.sh/docs/using_helm/#installing-helm
[docker]: https://docs.docker.com/install/
[podman]: https://podman.io/getting-started/installation
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
+2 -1
View File
@@ -1,3 +1,4 @@
---
name: submariner-k8s-broker
version: 0.0.1
appVersion: v0.0.1
@@ -5,7 +6,7 @@ description: Submariner Kubernetes Broker
keywords:
home: https://submariner.io/
sources:
- https://github.com/rancher/submariner-charts
- https://submariner-io.github.io/submariner-charts/charts
maintainers:
- name: Rancher Labs
email: charts@rancher.com
+1 -1
View File
@@ -2,7 +2,7 @@ The Submariner Kubernetes Broker is now setup.
You can retrieve the server URL by running
$ SUBMARINER_BROKER_URL=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[0].port}")
$ SUBMARINER_BROKER_URL=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
The broker client token and CA can be retrieved by running
+2 -1
View File
@@ -1,3 +1,4 @@
---
rbac:
create: true
crd:
@@ -5,4 +6,4 @@ crd:
serviceAccounts:
client:
create: true
name: ""
name: ""
+7 -6
View File
@@ -1,11 +1,12 @@
---
name: submariner
version: 0.0.1
appVersion: v0.0.1
description: Submariner
version: 0.0.3
appVersion: v0.0.3
description: k8s 1.16.x support
keywords:
home: https://submariner.io/
sources:
- https://github.com/rancher/submariner-charts
- https://submariner-io.github.io/submariner-charts/charts
maintainers:
- name: Rancher Labs
email: charts@rancher.com
- name: Rancher Labs
email: charts@rancher.com
+6 -6
View File
@@ -8,12 +8,12 @@ questions:
group: "Container Images"
subquestions:
- variable: engine.image.repository
default: "oats87/submariner-engine"
default: "rancher/submariner"
description: "Submariner Engine Image Repository"
type: string
label: Submariner Engine Image Repository
- variable: engine.image.tag
default: "dev"
default: "v0.0.2"
description: "Submariner Engine Image Tag"
type: string
label: Submariner Engine Image Tag
@@ -26,12 +26,12 @@ questions:
group: "Container Images"
subquestions:
- variable: routeAgent.image.repository
default: "oats87/submariner-route-agent"
default: "rancher/submariner-route-agent"
description: "Submariner Route Agent Image Repository"
type: string
label: Submariner Route Agent Image Repository
- variable: routeAgent.image.tag
default: "dev"
default: "v0.0.2"
description: "Submariner Route Agent Image Tag"
type: string
label: Submariner Route Agent Image Tag
@@ -70,7 +70,7 @@ questions:
label: "Broker Server"
description: "Broker server to use (without the https://)"
- variable: broker.insecure
type: bool
type: boolean
default: false
show_subquestion_if: false
group: "Broker Configuration"
@@ -129,4 +129,4 @@ questions:
default: false
group: "Advanced Configuration"
description: "Enable Charon debug mode"
label: "Charon Enabled"
label: "Charon Enabled"
+12 -1
View File
@@ -51,4 +51,15 @@ Create the name of the submariner-route-agent service account to use
{{- else -}}
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
{{- end -}}
{{- end -}}
{{- end -}}
{{/*
Create the name of the submariner-globalnet service account to use
*/}}
{{- define "submariner.globalnetServiceAccountName" -}}
{{- if .Values.serviceAccounts.globalnet.create -}}
{{ default (printf "%s-globalnet" (include "submariner.fullname" .)) .Values.serviceAccounts.globalnet.name }}
{{- else -}}
{{ default "default" .Values.serviceAccounts.globalnet.name }}
{{- end -}}
{{- end -}}
+14
View File
@@ -26,4 +26,18 @@ spec:
kind: Endpoint
plural: endpoints
scope: Namespaced
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: gateways.submariner.io
annotations:
"helm.sh/hook": crd-install
spec:
group: submariner.io
version: v1
names:
kind: Gateway
plural: gateways
scope: Namespaced
{{- end -}}
+17 -8
View File
@@ -1,5 +1,5 @@
apiVersion: apps/v1beta2
kind: Deployment
apiVersion: apps/v1
kind: DaemonSet
metadata:
labels:
heritage: {{ .Release.Service | quote }}
@@ -7,18 +7,15 @@ metadata:
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }}-engine
component: engine
name: {{ template "submariner.fullname" . }}
name: {{ template "submariner.fullname" . }}-gateway
spec:
progressDeadlineSeconds: 600
replicas: 1
revisionHistoryLimit: 5
selector:
matchLabels:
app: {{ template "submariner.fullname" . }}-engine
strategy:
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
@@ -60,6 +57,8 @@ spec:
value: "{{ .Values.submariner.clusterCidr }}"
- name: SUBMARINER_SERVICECIDR
value: "{{ .Values.submariner.serviceCidr }}"
- name: SUBMARINER_GLOBALCIDR
value: "{{ .Values.submariner.globalCidr }}"
- name: SUBMARINER_TOKEN
value: "{{ .Values.submariner.apiToken }}"
- name: SUBMARINER_CLUSTERID
@@ -97,6 +96,16 @@ spec:
value: "{{ .Values.ipsec.psk }}"
- name: CE_IPSEC_DEBUG
value: "{{ .Values.ipsec.debug }}"
- name: CE_IPSEC_IKEPORT
value: "{{ .Values.ipsec.ikePort }}"
- name: CE_IPSEC_NATTPORT
value: "{{ .Values.ipsec.natPort }}"
- name: LEADERSHIP_LEASEDURATION
value: "{{ .Values.leadership.leaseDuration }}"
- name: LEADERSHIP_RENEWDEADLINE
value: "{{ .Values.leadership.renewDeadline }}"
- name: LEADERSHIP_RETRYPERIOD
value: "{{ .Values.leadership.retryPeriod }}"
image: {{ .Values.engine.image.repository }}:{{ .Values.engine.image.tag }}
imagePullPolicy: {{ .Values.engine.image.pullPolicy }}
name: submariner
@@ -120,4 +129,4 @@ spec:
schedulerName: default-scheduler
securityContext: {}
terminationGracePeriodSeconds: 0
serviceAccountName: {{ template "submariner.engineServiceAccountName" . }}
serviceAccountName: {{ template "submariner.engineServiceAccountName" . }}
+54
View File
@@ -0,0 +1,54 @@
{{- if ne .Values.submariner.globalCidr "" }}
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: {{ template "submariner.fullname" . }}-globalnet
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }}-globalnet
component: globalnet
spec:
selector:
matchLabels:
app: {{ template "submariner.fullname" . }}-globalnet
template:
metadata:
labels:
app: {{ template "submariner.fullname" . }}-globalnet
spec:
hostNetwork: true
serviceAccountName: submariner-globalnet
serviceAccount: submariner-globalnet
nodeSelector:
submariner.io/gateway: 'true'
containers:
- name: {{ template "submariner.fullname" . }}-globalnet
image: {{ .Values.globalnet.image.repository }}:{{ .Values.globalnet.image.tag }}
imagePullPolicy: {{ .Values.globalnet.image.pullPolicy }}
env:
- name: SUBMARINER_CLUSTERID
value: '{{ .Values.submariner.clusterId }}'
- name: SUBMARINER_EXCLUDENS
value: 'submariner,kube-system,operators'
- name: SUBMARINER_NAMESPACE
value: '{{ .Release.Namespace }}'
securityContext:
allowPrivilegeEscalation: true
capabilities:
add:
- ALL
privileged: true
readOnlyRootFilesystem: false
runAsNonRoot: false
volumeMounts:
# Because we don't actually run iptables locally, but chroot in to the host
- mountPath: /host
name: host-slash
readOnly: true
volumes:
- name: host-slash
hostPath:
path: /
{{- end }}
+54 -2
View File
@@ -13,7 +13,7 @@ rules:
resources: ["configmaps"]
verbs: ["create", "get", "list", "watch", "patch", "update"]
- apiGroups: ["submariner.io"]
resources: ["clusters", "endpoints"]
resources: ["clusters", "endpoints", "gateways"]
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
- apiGroups: [""]
resources: ["events"]
@@ -30,8 +30,11 @@ metadata:
app: {{ template "submariner.name" . }}
rules:
- apiGroups: ["submariner.io"]
resources: ["clusters", "endpoints"]
resources: ["clusters", "endpoints", "gateways"]
verbs: ["create", "get", "list", "watch", "patch", "update"]
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "watch", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
@@ -58,4 +61,53 @@ subjects:
- kind: ServiceAccount
name: {{ template "submariner.routeAgentServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "submariner.fullname" . }}:routeagent
rules:
- apiGroups: [""]
resources: ["nodes"]
verbs: ["get", "update"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:routeagent
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "submariner.fullname" . }}:routeagent
subjects:
- kind: ServiceAccount
name: {{ template "submariner.routeAgentServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
{{- if ne .Values.submariner.globalCidr "" }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "submariner.fullname" . }}:globalnet
rules:
- apiGroups: [""]
resources: ["services", "namespaces", "pods", "nodes"]
verbs: ["get", "list", "watch", "update"]
- apiGroups: ["submariner.io"]
resources: ["clusters", "endpoints", "gateways"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:globalnet
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "submariner.fullname" . }}:globalnet
subjects:
- kind: ServiceAccount
name: {{ template "submariner.globalnetServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
{{- end -}}
{{- end -}}
+15 -2
View File
@@ -1,4 +1,4 @@
apiVersion: apps/v1beta2
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: {{ template "submariner.fullname" . }}-routeagent
@@ -37,6 +37,10 @@ spec:
value: "{{ .Values.submariner.clusterId }}"
- name: SUBMARINER_DEBUG
value: "{{ .Values.submariner.debug }}"
- name: SUBMARINER_CLUSTERCIDR
value: "{{ .Values.submariner.clusterCidr }}"
- name: SUBMARINER_SERVICECIDR
value: "{{ .Values.submariner.serviceCidr }}"
resources:
{{ toYaml .Values.routeAgent.resources | indent 10 }}
securityContext:
@@ -47,6 +51,11 @@ spec:
privileged: true
readOnlyRootFilesystem: false
runAsNonRoot: false
volumeMounts:
# Because we don't actually run iptables locally, but chroot in to the host
- mountPath: /host
name: host-slash
readOnly: true
{{- with .Values.routeAgent.nodeSelector }}
nodeSelector:
{{ toYaml . | indent 8 }}
@@ -58,4 +67,8 @@ spec:
{{- with .Values.routeAgent.affinity }}
affinity:
{{ toYaml . | indent 8 }}
{{- end }}
{{- end }}
volumes:
- name: host-slash
hostPath:
path: /
+13 -1
View File
@@ -20,4 +20,16 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
{{- end }}
{{- end }}
---
{{- if .Values.serviceAccounts.globalnet.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ template "submariner.globalnetServiceAccountName" . }}
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
{{- end }}
+21 -5
View File
@@ -1,8 +1,10 @@
---
submariner:
clusterId: ""
token: ""
clusterCidr: "10.42.0.0/16"
serviceCidr: "10.43.0.0/16"
globalCidr: ""
natEnabled: false
colorCodes: blue
debug: false
@@ -20,14 +22,20 @@ rbac:
ipsec:
psk: ""
debug: false
ikePort: 500
natPort: 4500
leadership:
leaseDuration: 5
renewDeadline: 3
retryPeriod: 2
engine:
image:
repository: rancher/submariner
tag: v0.0.1
tag: v0.0.2
pullPolicy: Always
resources: {}
# limits:
# cpu: 100m
# cpu: 100m
# memory: 100Mi
nodeSelectorEnabled: true
nodeSelector: {}
@@ -36,19 +44,27 @@ engine:
routeAgent:
image:
repository: rancher/submariner-route-agent
tag: v0.0.1
tag: v0.0.2
pullPolicy: Always
resources: {}
# limits:
# limits:
# cpu: 100m
# memory: 100Mi
nodeSelector: {}
tolerations: []
affinity: {}
globalnet:
image:
repository: submariner-globalnet
tag: local
pullPolicy: IfNotPresent
serviceAccounts:
engine:
create: true
name: ""
routeAgent:
create: true
name: ""
name: ""
globalnet:
create: false
name: ""