mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-21 11:30:34 +00:00
Compare commits
@@ -0,0 +1,2 @@
|
|||||||
|
Periodic link aliveness CI detected a broken link. Please see the [periodic job
|
||||||
|
results](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic) for details.
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
---
|
||||||
|
name: Bug Report
|
||||||
|
about: Report a bug in Helm Charts
|
||||||
|
labels: bug
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- Please use this template while reporting a bug and provide as much info as
|
||||||
|
possible. Not doing so may result in your bug not being addressed in a timely
|
||||||
|
manner. Thanks!
|
||||||
|
|
||||||
|
If the matter is security related, please disclose it privately to the
|
||||||
|
Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
|
||||||
|
-->
|
||||||
|
|
||||||
|
|
||||||
|
**What happened**:
|
||||||
|
|
||||||
|
**What you expected to happen**:
|
||||||
|
|
||||||
|
**How to reproduce it (as minimally and precisely as possible)**:
|
||||||
|
|
||||||
|
**Anything else we need to know?**:
|
||||||
|
|
||||||
|
**Environment**:
|
||||||
|
- Submariner version (use `subctl version`):
|
||||||
|
- Kubernetes version (use `kubectl version`):
|
||||||
|
- Cloud provider or hardware configuration:
|
||||||
|
- OS (e.g: `cat /etc/os-release`):
|
||||||
|
- Kernel (e.g. `uname -a`):
|
||||||
|
- Install tools:
|
||||||
|
- Network plugin and version (if this is a network-related bug):
|
||||||
|
- Others:
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
name: Enhancement Request
|
||||||
|
about: Suggest an enhancement to the Helm Charts project
|
||||||
|
labels: enhancement
|
||||||
|
|
||||||
|
---
|
||||||
|
<!-- Please only use this template for submitting enhancement requests -->
|
||||||
|
|
||||||
|
**What would you like to be added**:
|
||||||
|
|
||||||
|
**Why is this needed**:
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
name: Support Request
|
||||||
|
about: Support request or question relating to Helm Charts
|
||||||
|
labels: support
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!--
|
||||||
|
GitHub may not the right place for support requests.
|
||||||
|
|
||||||
|
You can also post your question on the [Submariner
|
||||||
|
Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner
|
||||||
|
[users](https://bit.ly/submariner-users) or
|
||||||
|
[developers](https://bit.ly/submariner-dev) mailing lists.
|
||||||
|
|
||||||
|
If the matter is security related, please disclose it privately to the
|
||||||
|
Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
|
||||||
|
-->
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
---
|
||||||
|
# Configuration for probot-stale - https://github.com/probot/stale
|
||||||
|
|
||||||
|
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
|
||||||
|
daysUntilStale: 60
|
||||||
|
|
||||||
|
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
|
||||||
|
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
|
||||||
|
daysUntilClose: 7
|
||||||
|
|
||||||
|
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
|
||||||
|
onlyLabels: []
|
||||||
|
|
||||||
|
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
|
||||||
|
exemptLabels:
|
||||||
|
- security
|
||||||
|
- confirmed
|
||||||
|
|
||||||
|
# Set to true to ignore issues in a project (defaults to false)
|
||||||
|
exemptProjects: false
|
||||||
|
|
||||||
|
# Set to true to ignore issues in a milestone (defaults to false)
|
||||||
|
exemptMilestones: false
|
||||||
|
|
||||||
|
# Set to true to ignore issues with an assignee (defaults to false)
|
||||||
|
exemptAssignees: false
|
||||||
|
|
||||||
|
# Label to use when marking as stale
|
||||||
|
staleLabel: wontfix
|
||||||
|
|
||||||
|
# Comment to post when marking as stale. Set to `false` to disable
|
||||||
|
markComment: >
|
||||||
|
This issue has been automatically marked as stale because it has not had
|
||||||
|
activity for 60 days. It will be closed if no further activity occurs.
|
||||||
|
Please make a comment if this issue/pr is still valid. Thank you
|
||||||
|
for your contributions.
|
||||||
|
|
||||||
|
# Comment to post when removing the stale label.
|
||||||
|
# unmarkComment: >
|
||||||
|
# Your comment here.
|
||||||
|
|
||||||
|
# Comment to post when closing a stale Issue or Pull Request.
|
||||||
|
# closeComment: >
|
||||||
|
# Your comment here.
|
||||||
|
|
||||||
|
# Limit the number of actions per hour, from 1-30. Default is 30
|
||||||
|
limitPerRun: 30
|
||||||
|
|
||||||
|
# Limit to only `issues` or `pulls`
|
||||||
|
# only: issues
|
||||||
|
|
||||||
|
pulls:
|
||||||
|
daysUntilStale: 30
|
||||||
|
markComment: >
|
||||||
|
This pull request has been automatically marked as stale because it has not had
|
||||||
|
recent activity. It will be closed if no further activity occurs. Thank you
|
||||||
|
for your contributions.
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
name: Branch Checks
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
target_devel:
|
||||||
|
name: PR targets release-0.9
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Check that the PR targets release-0.9
|
||||||
|
if: ${{ github.base_ref != 'release-0.9' }}
|
||||||
|
run: exit 1
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
---
|
||||||
|
name: End to End Tests
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
e2e:
|
||||||
|
name: E2E
|
||||||
|
timeout-minutes: 30
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
cable_driver: ['libreswan', 'wireguard']
|
||||||
|
globalnet: ['', 'globalnet']
|
||||||
|
k8s_version: ['1.17.17']
|
||||||
|
lighthouse: ['', 'lighthouse']
|
||||||
|
include:
|
||||||
|
# Recentness of K8s versions are limited by kindest/node image releases
|
||||||
|
- k8s_version: 1.18.15
|
||||||
|
- k8s_version: 1.19.7
|
||||||
|
- k8s_version: 1.20.2
|
||||||
|
steps:
|
||||||
|
- name: Check out the repository
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- name: Run E2E deployment and tests
|
||||||
|
uses: submariner-io/shipyard/gh-actions/e2e@release-0.9
|
||||||
|
with:
|
||||||
|
k8s_version: ${{ matrix.k8s_version }}
|
||||||
|
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||||
|
|
||||||
|
- name: Post mortem
|
||||||
|
if: failure()
|
||||||
|
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.9
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
name: Flake Finder
|
||||||
|
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: "0 0 * * *"
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
e2e:
|
||||||
|
name: E2E
|
||||||
|
timeout-minutes: 30
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
cable_driver: ['libreswan', 'wireguard']
|
||||||
|
globalnet: ['', 'globalnet']
|
||||||
|
lighthouse: ['', 'lighthouse']
|
||||||
|
steps:
|
||||||
|
- name: Check out the repository
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- name: Run E2E deployment and tests
|
||||||
|
uses: submariner-io/shipyard/gh-actions/e2e@release-0.9
|
||||||
|
with:
|
||||||
|
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||||
|
|
||||||
|
- name: Post mortem
|
||||||
|
if: failure()
|
||||||
|
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.9
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
---
|
||||||
|
name: Linting
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
gitlint:
|
||||||
|
name: Commit Message(s)
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Check out the repository
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
- name: Run gitlint
|
||||||
|
run: make gitlint
|
||||||
|
|
||||||
|
markdown-link-check:
|
||||||
|
name: Markdown Links (modified files)
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Check out the repository
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- name: Run markdown-link-check
|
||||||
|
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||||
|
with:
|
||||||
|
config-file: ".markdownlinkcheck.json"
|
||||||
|
check-modified-files-only: "yes"
|
||||||
|
base-branch: ${{ github.base_ref }}
|
||||||
|
|
||||||
|
markdownlint:
|
||||||
|
name: Markdown
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Check out the repository
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
- name: Run markdownlint
|
||||||
|
run: make markdownlint
|
||||||
|
|
||||||
|
yaml-lint:
|
||||||
|
name: YAML
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Check out the repository
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
- name: Run yamllint
|
||||||
|
uses: ibiqlik/action-yamllint@v1
|
||||||
|
with:
|
||||||
|
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
|
||||||
|
config_file: .yamllint.yml
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
---
|
||||||
|
name: Periodic
|
||||||
|
|
||||||
|
on:
|
||||||
|
schedule:
|
||||||
|
- cron: "0 0 * * 0"
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
markdown-link-check-periodic:
|
||||||
|
name: Markdown Links (all files)
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Check out the repository
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
|
||||||
|
- name: Run markdown-link-check
|
||||||
|
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||||
|
with:
|
||||||
|
config-file: ".markdownlinkcheck.json"
|
||||||
|
|
||||||
|
- name: Raise an Issue to report broken links
|
||||||
|
if: ${{ failure() }}
|
||||||
|
uses: peter-evans/create-issue-from-file@v2.3.2
|
||||||
|
with:
|
||||||
|
title: Broken link detected by CI
|
||||||
|
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||||
|
labels: automated, broken link
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
---
|
||||||
|
name: Release Charts
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- release-0.9
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
release:
|
||||||
|
name: Release
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
|
||||||
|
- name: Configure Git
|
||||||
|
run: |
|
||||||
|
git config user.name "$GITHUB_ACTOR"
|
||||||
|
git config user.email "$GITHUB_ACTOR@users.noreply.github.com"
|
||||||
|
|
||||||
|
- name: Update the charts
|
||||||
|
run: |
|
||||||
|
make release
|
||||||
|
|
||||||
|
- name: Push the charts
|
||||||
|
run: |
|
||||||
|
git add charts/*
|
||||||
|
git commit -m "Chart update"
|
||||||
|
git push
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
.dapper
|
||||||
|
.idea
|
||||||
|
.shflags
|
||||||
|
*.tgz
|
||||||
|
Makefile.dapper
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
[general]
|
||||||
|
# body-is-missing: Allow commit messages with only a title
|
||||||
|
# body-min-length: Allow short body lines, like "Relates-to: #issue"
|
||||||
|
ignore=body-is-missing,body-min-length
|
||||||
|
|
||||||
|
[ignore-by-body]
|
||||||
|
# Dependabot doesn't follow our conventions, unfortunately
|
||||||
|
regex=^Signed-off-by: dependabot\[bot\](.*)
|
||||||
|
ignore=all
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
{
|
||||||
|
"ignorePatterns": [
|
||||||
|
{
|
||||||
|
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"pattern": "^http://localhost:"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
# Breaks reusing MD snippets extracted to files
|
||||||
|
first-line-heading: false
|
||||||
|
|
||||||
|
# Set maximum line Length to 140c to match Go linting
|
||||||
|
line-length:
|
||||||
|
line_length: 140
|
||||||
|
|
||||||
|
# Allow HTML span elements to set font sizes
|
||||||
|
no-inline-html:
|
||||||
|
allowed_elements:
|
||||||
|
- span
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
extends: default
|
||||||
|
rules:
|
||||||
|
comments: disable
|
||||||
|
comments-indentation: disable
|
||||||
|
line-length:
|
||||||
|
max: 150
|
||||||
|
braces:
|
||||||
|
min-spaces-inside: 0
|
||||||
|
max-spaces-inside: 0
|
||||||
|
brackets:
|
||||||
|
min-spaces-inside: 0
|
||||||
|
max-spaces-inside: 0
|
||||||
|
indentation:
|
||||||
|
indent-sequences: consistent
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# Code of Conduct
|
||||||
|
|
||||||
|
Please see the [Code of Conduct docs on Submariner's website](https://submariner.io/community/code-of-conduct/).
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
* @mangelajo @Oats87 @skitt @tpantelis
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# Contributing
|
||||||
|
|
||||||
|
Please see the [Development docs on Submariner's website](https://submariner.io/development/).
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
ARG BASE_BRANCH
|
||||||
|
FROM quay.io/submariner/shipyard-dapper-base:release-0.9
|
||||||
|
|
||||||
|
ARG DAPPER_HOST_ARCH
|
||||||
|
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
|
||||||
|
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
|
||||||
|
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
|
||||||
|
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
|
||||||
|
|
||||||
|
WORKDIR ${DAPPER_SOURCE}
|
||||||
|
|
||||||
|
# Override the Helm deployment scripts
|
||||||
|
COPY deploy_helm /opt/shipyard/scripts/lib/
|
||||||
|
|
||||||
|
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
|
||||||
|
CMD ["sh"]
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
BASE_BRANCH ?= release-0.9
|
||||||
|
export BASE_BRANCH
|
||||||
|
|
||||||
|
ifneq (,$(DAPPER_HOST_ARCH))
|
||||||
|
|
||||||
|
# Running in Dapper
|
||||||
|
|
||||||
|
PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent lighthouse-agent lighthouse-coredns
|
||||||
|
|
||||||
|
include $(SHIPYARD_DIR)/Makefile.inc
|
||||||
|
|
||||||
|
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
|
||||||
|
ifneq (,$(filter ovn,$(_using)))
|
||||||
|
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings.ovn
|
||||||
|
else
|
||||||
|
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
|
||||||
|
endif
|
||||||
|
|
||||||
|
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
|
||||||
|
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
|
||||||
|
export DEPLOY_ARGS
|
||||||
|
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||||
|
CHARTS_DIR=charts
|
||||||
|
CHARTS_VERSION=0.7.0
|
||||||
|
REPO_URL=$(shell git config remote.origin.url)
|
||||||
|
|
||||||
|
# Process extra flags from the `using=a,b,c` optional flag
|
||||||
|
|
||||||
|
ifneq (,$(filter lighthouse,$(_using)))
|
||||||
|
override DEPLOY_ARGS += --service_discovery
|
||||||
|
endif
|
||||||
|
|
||||||
|
ifneq (,$(filter globalnet,$(_using)))
|
||||||
|
override DEPLOY_ARGS += --globalnet
|
||||||
|
endif
|
||||||
|
|
||||||
|
# Targets to make
|
||||||
|
|
||||||
|
e2e: E2E_ARGS=cluster1 cluster2
|
||||||
|
|
||||||
|
%.tgz:
|
||||||
|
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
|
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
|
|
||||||
|
release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||||
|
git checkout gh-pages
|
||||||
|
mv *.tgz $(CHARTS_DIR)
|
||||||
|
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
||||||
|
helm repo index $(CHARTS_DIR) --url $(GH_URL) --merge $(CHARTS_DIR)/index.yaml; \
|
||||||
|
else \
|
||||||
|
helm repo index $(CHARTS_DIR) --url $(GH_URL); \
|
||||||
|
fi
|
||||||
|
|
||||||
|
.PHONY: release
|
||||||
|
|
||||||
|
else
|
||||||
|
|
||||||
|
# Not running in Dapper
|
||||||
|
|
||||||
|
Makefile.dapper:
|
||||||
|
@echo Downloading $@
|
||||||
|
@curl -sfLO https://raw.githubusercontent.com/submariner-io/shipyard/$(BASE_BRANCH)/$@
|
||||||
|
|
||||||
|
include Makefile.dapper
|
||||||
|
|
||||||
|
endif
|
||||||
|
|
||||||
|
# Disable rebuilding Makefile
|
||||||
|
Makefile Makefile.inc: ;
|
||||||
@@ -1,3 +1,56 @@
|
|||||||
# submariner-charts
|
# submariner-charts
|
||||||
|
|
||||||
Please see https://github.com/rancher/submariner for more information. This is only a supporting repository for Submariner
|
Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/).
|
||||||
|
|
||||||
|
## Development workflow
|
||||||
|
|
||||||
|
### Prerequisites
|
||||||
|
|
||||||
|
- [Helm] v3
|
||||||
|
- [Docker] or [Podman]
|
||||||
|
|
||||||
|
### Create a fork and checkout
|
||||||
|
|
||||||
|
[Create a fork] of the original repository, clone it locally and checkout a new branch from master.
|
||||||
|
|
||||||
|
Example:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
git clone https://github.com/myuser/submariner-charts.git
|
||||||
|
cd submariner-charts
|
||||||
|
git checkout -b new-feature
|
||||||
|
```
|
||||||
|
|
||||||
|
Now you can modify the Helm charts according to your needs.
|
||||||
|
|
||||||
|
### Use the modified charts
|
||||||
|
|
||||||
|
Locally-modified charts can be installed using `helm install`,
|
||||||
|
referring to the local path; for example:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm install submariner-k8s-broker ./submariner-k8s-broker ...
|
||||||
|
```
|
||||||
|
|
||||||
|
In the base directory of this repository, a local deployment using the
|
||||||
|
local charts can be obtained by running the following command:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
make deploy
|
||||||
|
```
|
||||||
|
|
||||||
|
This will start two kind clusters and deploy Submariner using the
|
||||||
|
Broker and Operator charts.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
make e2e
|
||||||
|
```
|
||||||
|
|
||||||
|
will run the end-to-end test suite used to validate that Submariner is
|
||||||
|
working correctly.
|
||||||
|
|
||||||
|
<!--links-->
|
||||||
|
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
|
||||||
|
[Docker]: https://docs.docker.com/install/
|
||||||
|
[Podman]: https://podman.io/getting-started/installation
|
||||||
|
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
. "${SCRIPTS_DIR}"/lib/source_only
|
||||||
|
|
||||||
|
# We need a minimal setup to verify the deployment works
|
||||||
|
clusters=('cluster1' 'cluster2')
|
||||||
|
cluster_nodes['cluster1']="control-plane worker"
|
||||||
|
cluster_nodes['cluster2']="control-plane worker"
|
||||||
|
|
||||||
|
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
|
||||||
|
|
||||||
|
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
. "${SCRIPTS_DIR}"/lib/source_only
|
||||||
|
|
||||||
|
# We need a minimal setup to verify the deployment works
|
||||||
|
clusters=('cluster1' 'cluster2')
|
||||||
|
cluster_nodes['cluster1']="control-plane worker worker"
|
||||||
|
cluster_nodes['cluster2']="control-plane worker worker"
|
||||||
|
|
||||||
|
cluster_cni=( ['cluster1']="ovn" ['cluster2']="ovn" )
|
||||||
|
|
||||||
|
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
|
||||||
+76
@@ -0,0 +1,76 @@
|
|||||||
|
# shellcheck shell=bash
|
||||||
|
# shellcheck source=scripts/shared/lib/source_only
|
||||||
|
. "${BASH_SOURCE%/*}"/source_only
|
||||||
|
|
||||||
|
### Constants ###
|
||||||
|
|
||||||
|
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
|
||||||
|
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
|
||||||
|
|
||||||
|
### Functions ###
|
||||||
|
|
||||||
|
function deploytool_prereqs() {
|
||||||
|
helm version
|
||||||
|
}
|
||||||
|
|
||||||
|
function setup_broker() {
|
||||||
|
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
|
||||||
|
echo "Submariner CRDs already exist, skipping broker creation..."
|
||||||
|
else
|
||||||
|
echo "Installing submariner broker..."
|
||||||
|
# shellcheck disable=SC2086 # Split on purpose
|
||||||
|
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
|
||||||
|
--create-namespace \
|
||||||
|
--kube-context "${cluster}" \
|
||||||
|
--namespace "${SUBMARINER_BROKER_NS}" \
|
||||||
|
${deploytool_broker_args}
|
||||||
|
fi
|
||||||
|
|
||||||
|
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
||||||
|
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
|
||||||
|
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
|
||||||
|
}
|
||||||
|
|
||||||
|
function helm_install_subm() {
|
||||||
|
local crd_create=false
|
||||||
|
[[ "${cluster}" = "${broker}" ]] || crd_create=true
|
||||||
|
|
||||||
|
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
|
||||||
|
echo "Submariner already installed, skipping installation..."
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Installing Submariner..."
|
||||||
|
# shellcheck disable=SC2086 # Split on purpose
|
||||||
|
helm --kube-context "${cluster}" install submariner-operator \
|
||||||
|
./submariner-operator \
|
||||||
|
--create-namespace \
|
||||||
|
--namespace "${SUBM_NS}" \
|
||||||
|
--set ipsec.psk="${SUBMARINER_PSK}" \
|
||||||
|
--set broker.server="${submariner_broker_url}" \
|
||||||
|
--set broker.token="${submariner_broker_token}" \
|
||||||
|
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
|
||||||
|
--set broker.ca="${submariner_broker_ca}" \
|
||||||
|
--set broker.globalnet="${globalnet}" \
|
||||||
|
--set submariner.serviceDiscovery="${service_discovery}" \
|
||||||
|
--set submariner.cableDriver="${cable_driver}" \
|
||||||
|
--set submariner.clusterId="${cluster}" \
|
||||||
|
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
|
||||||
|
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
|
||||||
|
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
|
||||||
|
--set serviceAccounts.globalnet.create="${globalnet}" \
|
||||||
|
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
|
||||||
|
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
|
||||||
|
--set submariner.natEnabled="false" \
|
||||||
|
--set operator.image.repository="localhost:5000/submariner-operator" \
|
||||||
|
--set operator.image.tag="local" \
|
||||||
|
--set operator.image.pullPolicy="IfNotPresent" \
|
||||||
|
--set submariner.images.repository="localhost:5000" \
|
||||||
|
--set submariner.images.tag="local" \
|
||||||
|
--set brokercrds.create="${crd_create}" \
|
||||||
|
${deploytool_submariner_args}
|
||||||
|
}
|
||||||
|
|
||||||
|
function install_subm_all_clusters() {
|
||||||
|
run_subm_clusters helm_install_subm
|
||||||
|
}
|
||||||
@@ -1,11 +1,13 @@
|
|||||||
|
---
|
||||||
name: submariner-k8s-broker
|
name: submariner-k8s-broker
|
||||||
version: 0.0.1
|
version: 0.6.0
|
||||||
appVersion: v0.0.1
|
apiVersion: v2
|
||||||
|
appVersion: 0.6.0
|
||||||
description: Submariner Kubernetes Broker
|
description: Submariner Kubernetes Broker
|
||||||
keywords:
|
keywords:
|
||||||
home: https://submariner.io/
|
home: https://submariner-io.github.io/
|
||||||
sources:
|
sources:
|
||||||
- https://github.com/rancher/submariner-charts
|
- https://submariner-io.github.io/submariner-charts/charts
|
||||||
maintainers:
|
maintainers:
|
||||||
- name: Rancher Labs
|
- name: Submariner Developers
|
||||||
email: charts@rancher.com
|
email: submariner-dev@googlegroups.com
|
||||||
|
|||||||
@@ -0,0 +1,324 @@
|
|||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: clusters.submariner.io
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Cluster
|
||||||
|
plural: clusters
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: endpoints.submariner.io
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Endpoint
|
||||||
|
plural: endpoints
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: gateways.submariner.io
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: Gateway
|
||||||
|
plural: gateways
|
||||||
|
scope: Namespaced
|
||||||
|
additionalPrinterColumns:
|
||||||
|
- name: ha-status
|
||||||
|
type: string
|
||||||
|
description: High Availability Status of the Gateway
|
||||||
|
JSONPath: .status.haStatus
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: multiclusterservices.lighthouse.submariner.io
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v1
|
||||||
|
names:
|
||||||
|
kind: MultiClusterService
|
||||||
|
plural: multiclusterservices
|
||||||
|
singular: multiclusterservice
|
||||||
|
scope: Namespaced
|
||||||
|
validation:
|
||||||
|
openAPIV3Schema:
|
||||||
|
properties:
|
||||||
|
spec:
|
||||||
|
properties:
|
||||||
|
clusterServiceInfo:
|
||||||
|
properties:
|
||||||
|
clusterID:
|
||||||
|
type: "string"
|
||||||
|
clusterDomain:
|
||||||
|
type: "string"
|
||||||
|
serviceIP:
|
||||||
|
type: "string"
|
||||||
|
port:
|
||||||
|
type: "integer"
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceexports.lighthouse.submariner.io
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v2alpha1
|
||||||
|
names:
|
||||||
|
kind: ServiceExport
|
||||||
|
plural: serviceexports
|
||||||
|
singular: serviceexport
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceimports.lighthouse.submariner.io
|
||||||
|
spec:
|
||||||
|
group: lighthouse.submariner.io
|
||||||
|
version: v2alpha1
|
||||||
|
names:
|
||||||
|
kind: ServiceImport
|
||||||
|
plural: serviceimports
|
||||||
|
singular: serviceimport
|
||||||
|
scope: Namespaced
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceexports.multicluster.x-k8s.io
|
||||||
|
spec:
|
||||||
|
group: multicluster.x-k8s.io
|
||||||
|
scope: Namespaced
|
||||||
|
names:
|
||||||
|
plural: serviceexports
|
||||||
|
singular: serviceexport
|
||||||
|
kind: ServiceExport
|
||||||
|
shortNames:
|
||||||
|
- svcex
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
additionalPrinterColumns:
|
||||||
|
- name: Age
|
||||||
|
type: date
|
||||||
|
jsonPath: .metadata.creationTimestamp
|
||||||
|
"schema":
|
||||||
|
"openAPIV3Schema":
|
||||||
|
description: ServiceExport declares that the Service with the same name and
|
||||||
|
namespace as this export should be consumable from other clusters.
|
||||||
|
type: object
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: status describes the current state of an exported service.
|
||||||
|
Service configuration comes from the Service that had the same name
|
||||||
|
and namespace as this ServiceExport. Populated by the multi-cluster
|
||||||
|
service implementation's controller.
|
||||||
|
type: object
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
type: array
|
||||||
|
items:
|
||||||
|
description: "ServiceExportCondition contains details for the current
|
||||||
|
condition of this service export. \n Once [KEP-1623](https://github.com/kubernetes/enhancements/tree/master/keps/sig-api-machinery/1623-standardize-conditions)
|
||||||
|
is implemented, this will be replaced by metav1.Condition."
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
type: string
|
||||||
|
format: date-time
|
||||||
|
message:
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: Status is one of {"True", "False", "Unknown"}
|
||||||
|
type: string
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type:
|
||||||
|
description: ServiceExportConditionType identifies a specific
|
||||||
|
condition.
|
||||||
|
type: string
|
||||||
|
x-kubernetes-list-map-keys:
|
||||||
|
- type
|
||||||
|
x-kubernetes-list-type: map
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: serviceimports.multicluster.x-k8s.io
|
||||||
|
spec:
|
||||||
|
group: multicluster.x-k8s.io
|
||||||
|
scope: Namespaced
|
||||||
|
names:
|
||||||
|
plural: serviceimports
|
||||||
|
singular: serviceimport
|
||||||
|
kind: ServiceImport
|
||||||
|
shortNames:
|
||||||
|
- svcim
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
additionalPrinterColumns:
|
||||||
|
- name: Type
|
||||||
|
type: string
|
||||||
|
description: The type of this ServiceImport
|
||||||
|
jsonPath: .spec.type
|
||||||
|
- name: IP
|
||||||
|
type: string
|
||||||
|
description: The VIP for this ServiceImport
|
||||||
|
jsonPath: .spec.ips
|
||||||
|
- name: Age
|
||||||
|
type: date
|
||||||
|
jsonPath: .metadata.creationTimestamp
|
||||||
|
"schema":
|
||||||
|
"openAPIV3Schema":
|
||||||
|
description: ServiceImport describes a service imported from clusters in a
|
||||||
|
ClusterSet.
|
||||||
|
type: object
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: spec defines the behavior of a ServiceImport.
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- ports
|
||||||
|
- type
|
||||||
|
properties:
|
||||||
|
ips:
|
||||||
|
description: ip will be used as the VIP for this service when type
|
||||||
|
is ClusterSetIP.
|
||||||
|
type: array
|
||||||
|
maxItems: 1
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
ports:
|
||||||
|
type: array
|
||||||
|
items:
|
||||||
|
description: ServicePort represents the port on which the service
|
||||||
|
is exposed
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- port
|
||||||
|
properties:
|
||||||
|
appProtocol:
|
||||||
|
description: The application protocol for this port. This field
|
||||||
|
follows standard Kubernetes label syntax. Un-prefixed names
|
||||||
|
are reserved for IANA standard service names (as per RFC-6335
|
||||||
|
and http://www.iana.org/assignments/service-names). Non-standard
|
||||||
|
protocols should use prefixed names such as mycompany.com/my-custom-protocol.
|
||||||
|
Field can be enabled with ServiceAppProtocol feature gate.
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of this port within the service. This
|
||||||
|
must be a DNS_LABEL. All ports within a ServiceSpec must have
|
||||||
|
unique names. When considering the endpoints for a Service,
|
||||||
|
this must match the 'name' field in the EndpointPort. Optional
|
||||||
|
if only one ServicePort is defined on this service.
|
||||||
|
type: string
|
||||||
|
port:
|
||||||
|
description: The port that will be exposed by this service.
|
||||||
|
type: integer
|
||||||
|
format: int32
|
||||||
|
protocol:
|
||||||
|
description: The IP protocol for this port. Supports "TCP",
|
||||||
|
"UDP", and "SCTP". Default is TCP.
|
||||||
|
type: string
|
||||||
|
x-kubernetes-list-type: atomic
|
||||||
|
sessionAffinity:
|
||||||
|
description: 'Supports "ClientIP" and "None". Used to maintain session
|
||||||
|
affinity. Enable client IP based session affinity. Must be ClientIP
|
||||||
|
or None. Defaults to None. Ignored when type is Headless More info:
|
||||||
|
https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies'
|
||||||
|
type: string
|
||||||
|
sessionAffinityConfig:
|
||||||
|
description: sessionAffinityConfig contains session affinity configuration.
|
||||||
|
type: object
|
||||||
|
properties:
|
||||||
|
clientIP:
|
||||||
|
description: clientIP contains the configurations of Client IP
|
||||||
|
based session affinity.
|
||||||
|
type: object
|
||||||
|
properties:
|
||||||
|
timeoutSeconds:
|
||||||
|
description: timeoutSeconds specifies the seconds of ClientIP
|
||||||
|
type session sticky time. The value must be >0 && <=86400(for
|
||||||
|
1 day) if ServiceAffinity == "ClientIP". Default value is
|
||||||
|
10800(for 3 hours).
|
||||||
|
type: integer
|
||||||
|
format: int32
|
||||||
|
type:
|
||||||
|
description: type defines the type of this service. Must be ClusterSetIP
|
||||||
|
or Headless.
|
||||||
|
type: string
|
||||||
|
enum:
|
||||||
|
- ClusterSetIP
|
||||||
|
- Headless
|
||||||
|
status:
|
||||||
|
description: status contains information about the exported services that
|
||||||
|
form the multi-cluster service referenced by this ServiceImport.
|
||||||
|
type: object
|
||||||
|
properties:
|
||||||
|
clusters:
|
||||||
|
description: clusters is the list of exporting clusters from which
|
||||||
|
this service was derived.
|
||||||
|
type: array
|
||||||
|
items:
|
||||||
|
description: ClusterStatus contains service configuration mapped
|
||||||
|
to a specific source cluster
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- cluster
|
||||||
|
properties:
|
||||||
|
cluster:
|
||||||
|
description: cluster is the name of the exporting cluster. Must
|
||||||
|
be a valid RFC-1123 DNS label.
|
||||||
|
type: string
|
||||||
|
x-kubernetes-list-map-keys:
|
||||||
|
- cluster
|
||||||
|
x-kubernetes-list-type: map
|
||||||
@@ -2,7 +2,7 @@ The Submariner Kubernetes Broker is now setup.
|
|||||||
|
|
||||||
You can retrieve the server URL by running
|
You can retrieve the server URL by running
|
||||||
|
|
||||||
$ SUBMARINER_BROKER_URL=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[0].port}")
|
$ SUBMARINER_BROKER_URL=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
||||||
|
|
||||||
The broker client token and CA can be retrieved by running
|
The broker client token and CA can be retrieved by running
|
||||||
|
|
||||||
|
|||||||
@@ -1,29 +0,0 @@
|
|||||||
{{- if .Values.crd.create -}}
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: clusters.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Cluster
|
|
||||||
plural: clusters
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: endpoints.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Endpoint
|
|
||||||
plural: endpoints
|
|
||||||
scope: Namespaced
|
|
||||||
{{- end -}}
|
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: Role
|
kind: Role
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||||
labels:
|
labels:
|
||||||
heritage: {{ .Release.Service | quote }}
|
heritage: {{ .Release.Service | quote }}
|
||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
@@ -12,17 +12,26 @@ rules:
|
|||||||
- apiGroups: ["submariner.io"]
|
- apiGroups: ["submariner.io"]
|
||||||
resources: ["clusters", "endpoints"]
|
resources: ["clusters", "endpoints"]
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||||
|
- apiGroups: ["lighthouse.submariner.io"]
|
||||||
|
resources: ["*"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||||
|
- apiGroups: ["discovery.k8s.io"]
|
||||||
|
resources: ["endpointslices"]
|
||||||
|
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
|
||||||
|
- apiGroups: ["multicluster.x-k8s.io"]
|
||||||
|
resources: ["*"]
|
||||||
|
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: Role
|
kind: Role
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
---
|
||||||
rbac:
|
rbac:
|
||||||
create: true
|
create: true
|
||||||
crd:
|
crd:
|
||||||
@@ -5,4 +6,4 @@ crd:
|
|||||||
serviceAccounts:
|
serviceAccounts:
|
||||||
client:
|
client:
|
||||||
create: true
|
create: true
|
||||||
name: ""
|
name: ""
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
name: submariner-operator
|
||||||
|
version: 0.7.0
|
||||||
|
apiVersion: v2
|
||||||
|
appVersion: 0.7.0
|
||||||
|
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||||
|
keywords:
|
||||||
|
home: https://submariner-io.github.io/
|
||||||
|
sources:
|
||||||
|
- https://submariner-io.github.io/submariner-charts/charts
|
||||||
|
maintainers:
|
||||||
|
- name: Submariner Developers
|
||||||
|
email: submariner-dev@googlegroups.com
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
# Submariner
|
||||||
|
|
||||||
|
[Submariner](https://submariner.io) is a cross-cluster networking tool.
|
||||||
|
|
||||||
|
This chart creates the required components in this cluster to deploy the Submariner operator.
|
||||||
@@ -0,0 +1,877 @@
|
|||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1beta1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: submariners.submariner.io
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.3.0
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
names:
|
||||||
|
kind: Submariner
|
||||||
|
listKind: SubmarinerList
|
||||||
|
plural: submariners
|
||||||
|
singular: submariner
|
||||||
|
scope: Namespaced
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
validation:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: Submariner is the Schema for the submariners API
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: SubmarinerSpec defines the desired state of Submariner
|
||||||
|
properties:
|
||||||
|
broker:
|
||||||
|
type: string
|
||||||
|
brokerK8sApiServer:
|
||||||
|
type: string
|
||||||
|
brokerK8sApiServerToken:
|
||||||
|
type: string
|
||||||
|
brokerK8sCA:
|
||||||
|
type: string
|
||||||
|
brokerK8sRemoteNamespace:
|
||||||
|
type: string
|
||||||
|
cableDriver:
|
||||||
|
type: string
|
||||||
|
ceIPSecDebug:
|
||||||
|
type: boolean
|
||||||
|
ceIPSecIKEPort:
|
||||||
|
type: integer
|
||||||
|
ceIPSecNATTPort:
|
||||||
|
type: integer
|
||||||
|
ceIPSecPSK:
|
||||||
|
type: string
|
||||||
|
clusterCIDR:
|
||||||
|
type: string
|
||||||
|
clusterID:
|
||||||
|
type: string
|
||||||
|
colorCodes:
|
||||||
|
type: string
|
||||||
|
customDomains:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
x-kubernetes-list-type: set
|
||||||
|
debug:
|
||||||
|
type: boolean
|
||||||
|
globalCIDR:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
natEnabled:
|
||||||
|
type: boolean
|
||||||
|
repository:
|
||||||
|
type: string
|
||||||
|
serviceCIDR:
|
||||||
|
type: string
|
||||||
|
serviceDiscoveryEnabled:
|
||||||
|
type: boolean
|
||||||
|
version:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- broker
|
||||||
|
- brokerK8sApiServer
|
||||||
|
- brokerK8sApiServerToken
|
||||||
|
- brokerK8sCA
|
||||||
|
- brokerK8sRemoteNamespace
|
||||||
|
- ceIPSecDebug
|
||||||
|
- ceIPSecPSK
|
||||||
|
- clusterCIDR
|
||||||
|
- clusterID
|
||||||
|
- debug
|
||||||
|
- namespace
|
||||||
|
- natEnabled
|
||||||
|
- serviceCIDR
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: SubmarinerStatus defines the observed state of Submariner
|
||||||
|
properties:
|
||||||
|
clusterCIDR:
|
||||||
|
type: string
|
||||||
|
clusterID:
|
||||||
|
type: string
|
||||||
|
colorCodes:
|
||||||
|
type: string
|
||||||
|
gatewayDaemonSetStatus:
|
||||||
|
properties:
|
||||||
|
lastResourceVersion:
|
||||||
|
type: string
|
||||||
|
mismatchedContainerImages:
|
||||||
|
type: boolean
|
||||||
|
nonReadyContainerStates:
|
||||||
|
items:
|
||||||
|
description: ContainerState holds a possible state of container.
|
||||||
|
Only one of its members may be specified. If none of them is
|
||||||
|
specified, the default one is ContainerStateWaiting.
|
||||||
|
properties:
|
||||||
|
running:
|
||||||
|
description: Details about a running container
|
||||||
|
properties:
|
||||||
|
startedAt:
|
||||||
|
description: Time at which the container was last (re-)started
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
terminated:
|
||||||
|
description: Details about a terminated container
|
||||||
|
properties:
|
||||||
|
containerID:
|
||||||
|
description: Container's ID in the format 'docker://<container_id>'
|
||||||
|
type: string
|
||||||
|
exitCode:
|
||||||
|
description: Exit status from the last termination of
|
||||||
|
the container
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
finishedAt:
|
||||||
|
description: Time at which the container last terminated
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: Message regarding the last termination of
|
||||||
|
the container
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: (brief) reason from the last termination
|
||||||
|
of the container
|
||||||
|
type: string
|
||||||
|
signal:
|
||||||
|
description: Signal from the last termination of the container
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
startedAt:
|
||||||
|
description: Time at which previous execution of the container
|
||||||
|
started
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- exitCode
|
||||||
|
type: object
|
||||||
|
waiting:
|
||||||
|
description: Details about a waiting container
|
||||||
|
properties:
|
||||||
|
message:
|
||||||
|
description: Message regarding why the container is not
|
||||||
|
yet running.
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: (brief) reason the container is not yet running.
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
status:
|
||||||
|
description: DaemonSetStatus represents the current status of a
|
||||||
|
daemon set.
|
||||||
|
properties:
|
||||||
|
collisionCount:
|
||||||
|
description: Count of hash collisions for the DaemonSet. The
|
||||||
|
DaemonSet controller uses this field as a collision avoidance
|
||||||
|
mechanism when it needs to create the name for the newest
|
||||||
|
ControllerRevision.
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
conditions:
|
||||||
|
description: Represents the latest available observations of
|
||||||
|
a DaemonSet's current state.
|
||||||
|
items:
|
||||||
|
description: DaemonSetCondition describes the state of a DaemonSet
|
||||||
|
at a certain point.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: Last time the condition transitioned from
|
||||||
|
one status to another.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: A human readable message indicating details
|
||||||
|
about the transition.
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: The reason for the condition's last transition.
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: Status of the condition, one of True, False,
|
||||||
|
Unknown.
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: Type of DaemonSet condition.
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
currentNumberScheduled:
|
||||||
|
description: 'The number of nodes that are running at least
|
||||||
|
1 daemon pod and are supposed to run the daemon pod. More
|
||||||
|
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
desiredNumberScheduled:
|
||||||
|
description: 'The total number of nodes that should be running
|
||||||
|
the daemon pod (including nodes correctly running the daemon
|
||||||
|
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberAvailable:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have one or more of the daemon pod running
|
||||||
|
and available (ready for at least spec.minReadySeconds)
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberMisscheduled:
|
||||||
|
description: 'The number of nodes that are running the daemon
|
||||||
|
pod, but are not supposed to run the daemon pod. More info:
|
||||||
|
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberReady:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have one or more of the daemon pod running
|
||||||
|
and ready.
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberUnavailable:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have none of the daemon pod running and available
|
||||||
|
(ready for at least spec.minReadySeconds)
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
observedGeneration:
|
||||||
|
description: The most recent generation observed by the daemon
|
||||||
|
set controller.
|
||||||
|
format: int64
|
||||||
|
type: integer
|
||||||
|
updatedNumberScheduled:
|
||||||
|
description: The total number of nodes that are running updated
|
||||||
|
daemon pod
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
required:
|
||||||
|
- currentNumberScheduled
|
||||||
|
- desiredNumberScheduled
|
||||||
|
- numberMisscheduled
|
||||||
|
- numberReady
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- mismatchedContainerImages
|
||||||
|
type: object
|
||||||
|
gateways:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
connections:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
endpoint:
|
||||||
|
properties:
|
||||||
|
backend:
|
||||||
|
type: string
|
||||||
|
backend_config:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
cable_name:
|
||||||
|
type: string
|
||||||
|
cluster_id:
|
||||||
|
type: string
|
||||||
|
hostname:
|
||||||
|
type: string
|
||||||
|
nat_enabled:
|
||||||
|
type: boolean
|
||||||
|
private_ip:
|
||||||
|
type: string
|
||||||
|
public_ip:
|
||||||
|
type: string
|
||||||
|
subnets:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- backend
|
||||||
|
- cable_name
|
||||||
|
- cluster_id
|
||||||
|
- hostname
|
||||||
|
- nat_enabled
|
||||||
|
- private_ip
|
||||||
|
- public_ip
|
||||||
|
- subnets
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
type: string
|
||||||
|
statusMessage:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- endpoint
|
||||||
|
- status
|
||||||
|
- statusMessage
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
haStatus:
|
||||||
|
type: string
|
||||||
|
localEndpoint:
|
||||||
|
properties:
|
||||||
|
backend:
|
||||||
|
type: string
|
||||||
|
backend_config:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
cable_name:
|
||||||
|
type: string
|
||||||
|
cluster_id:
|
||||||
|
type: string
|
||||||
|
hostname:
|
||||||
|
type: string
|
||||||
|
nat_enabled:
|
||||||
|
type: boolean
|
||||||
|
private_ip:
|
||||||
|
type: string
|
||||||
|
public_ip:
|
||||||
|
type: string
|
||||||
|
subnets:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- backend
|
||||||
|
- cable_name
|
||||||
|
- cluster_id
|
||||||
|
- hostname
|
||||||
|
- nat_enabled
|
||||||
|
- private_ip
|
||||||
|
- public_ip
|
||||||
|
- subnets
|
||||||
|
type: object
|
||||||
|
statusFailure:
|
||||||
|
type: string
|
||||||
|
version:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- connections
|
||||||
|
- haStatus
|
||||||
|
- localEndpoint
|
||||||
|
- statusFailure
|
||||||
|
- version
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
globalCIDR:
|
||||||
|
type: string
|
||||||
|
globalnetDaemonSetStatus:
|
||||||
|
properties:
|
||||||
|
lastResourceVersion:
|
||||||
|
type: string
|
||||||
|
mismatchedContainerImages:
|
||||||
|
type: boolean
|
||||||
|
nonReadyContainerStates:
|
||||||
|
items:
|
||||||
|
description: ContainerState holds a possible state of container.
|
||||||
|
Only one of its members may be specified. If none of them is
|
||||||
|
specified, the default one is ContainerStateWaiting.
|
||||||
|
properties:
|
||||||
|
running:
|
||||||
|
description: Details about a running container
|
||||||
|
properties:
|
||||||
|
startedAt:
|
||||||
|
description: Time at which the container was last (re-)started
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
terminated:
|
||||||
|
description: Details about a terminated container
|
||||||
|
properties:
|
||||||
|
containerID:
|
||||||
|
description: Container's ID in the format 'docker://<container_id>'
|
||||||
|
type: string
|
||||||
|
exitCode:
|
||||||
|
description: Exit status from the last termination of
|
||||||
|
the container
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
finishedAt:
|
||||||
|
description: Time at which the container last terminated
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: Message regarding the last termination of
|
||||||
|
the container
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: (brief) reason from the last termination
|
||||||
|
of the container
|
||||||
|
type: string
|
||||||
|
signal:
|
||||||
|
description: Signal from the last termination of the container
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
startedAt:
|
||||||
|
description: Time at which previous execution of the container
|
||||||
|
started
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- exitCode
|
||||||
|
type: object
|
||||||
|
waiting:
|
||||||
|
description: Details about a waiting container
|
||||||
|
properties:
|
||||||
|
message:
|
||||||
|
description: Message regarding why the container is not
|
||||||
|
yet running.
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: (brief) reason the container is not yet running.
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
status:
|
||||||
|
description: DaemonSetStatus represents the current status of a
|
||||||
|
daemon set.
|
||||||
|
properties:
|
||||||
|
collisionCount:
|
||||||
|
description: Count of hash collisions for the DaemonSet. The
|
||||||
|
DaemonSet controller uses this field as a collision avoidance
|
||||||
|
mechanism when it needs to create the name for the newest
|
||||||
|
ControllerRevision.
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
conditions:
|
||||||
|
description: Represents the latest available observations of
|
||||||
|
a DaemonSet's current state.
|
||||||
|
items:
|
||||||
|
description: DaemonSetCondition describes the state of a DaemonSet
|
||||||
|
at a certain point.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: Last time the condition transitioned from
|
||||||
|
one status to another.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: A human readable message indicating details
|
||||||
|
about the transition.
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: The reason for the condition's last transition.
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: Status of the condition, one of True, False,
|
||||||
|
Unknown.
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: Type of DaemonSet condition.
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
currentNumberScheduled:
|
||||||
|
description: 'The number of nodes that are running at least
|
||||||
|
1 daemon pod and are supposed to run the daemon pod. More
|
||||||
|
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
desiredNumberScheduled:
|
||||||
|
description: 'The total number of nodes that should be running
|
||||||
|
the daemon pod (including nodes correctly running the daemon
|
||||||
|
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberAvailable:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have one or more of the daemon pod running
|
||||||
|
and available (ready for at least spec.minReadySeconds)
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberMisscheduled:
|
||||||
|
description: 'The number of nodes that are running the daemon
|
||||||
|
pod, but are not supposed to run the daemon pod. More info:
|
||||||
|
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberReady:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have one or more of the daemon pod running
|
||||||
|
and ready.
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberUnavailable:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have none of the daemon pod running and available
|
||||||
|
(ready for at least spec.minReadySeconds)
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
observedGeneration:
|
||||||
|
description: The most recent generation observed by the daemon
|
||||||
|
set controller.
|
||||||
|
format: int64
|
||||||
|
type: integer
|
||||||
|
updatedNumberScheduled:
|
||||||
|
description: The total number of nodes that are running updated
|
||||||
|
daemon pod
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
required:
|
||||||
|
- currentNumberScheduled
|
||||||
|
- desiredNumberScheduled
|
||||||
|
- numberMisscheduled
|
||||||
|
- numberReady
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- mismatchedContainerImages
|
||||||
|
type: object
|
||||||
|
natEnabled:
|
||||||
|
type: boolean
|
||||||
|
routeAgentDaemonSetStatus:
|
||||||
|
properties:
|
||||||
|
lastResourceVersion:
|
||||||
|
type: string
|
||||||
|
mismatchedContainerImages:
|
||||||
|
type: boolean
|
||||||
|
nonReadyContainerStates:
|
||||||
|
items:
|
||||||
|
description: ContainerState holds a possible state of container.
|
||||||
|
Only one of its members may be specified. If none of them is
|
||||||
|
specified, the default one is ContainerStateWaiting.
|
||||||
|
properties:
|
||||||
|
running:
|
||||||
|
description: Details about a running container
|
||||||
|
properties:
|
||||||
|
startedAt:
|
||||||
|
description: Time at which the container was last (re-)started
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
terminated:
|
||||||
|
description: Details about a terminated container
|
||||||
|
properties:
|
||||||
|
containerID:
|
||||||
|
description: Container's ID in the format 'docker://<container_id>'
|
||||||
|
type: string
|
||||||
|
exitCode:
|
||||||
|
description: Exit status from the last termination of
|
||||||
|
the container
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
finishedAt:
|
||||||
|
description: Time at which the container last terminated
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: Message regarding the last termination of
|
||||||
|
the container
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: (brief) reason from the last termination
|
||||||
|
of the container
|
||||||
|
type: string
|
||||||
|
signal:
|
||||||
|
description: Signal from the last termination of the container
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
startedAt:
|
||||||
|
description: Time at which previous execution of the container
|
||||||
|
started
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- exitCode
|
||||||
|
type: object
|
||||||
|
waiting:
|
||||||
|
description: Details about a waiting container
|
||||||
|
properties:
|
||||||
|
message:
|
||||||
|
description: Message regarding why the container is not
|
||||||
|
yet running.
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: (brief) reason the container is not yet running.
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
status:
|
||||||
|
description: DaemonSetStatus represents the current status of a
|
||||||
|
daemon set.
|
||||||
|
properties:
|
||||||
|
collisionCount:
|
||||||
|
description: Count of hash collisions for the DaemonSet. The
|
||||||
|
DaemonSet controller uses this field as a collision avoidance
|
||||||
|
mechanism when it needs to create the name for the newest
|
||||||
|
ControllerRevision.
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
conditions:
|
||||||
|
description: Represents the latest available observations of
|
||||||
|
a DaemonSet's current state.
|
||||||
|
items:
|
||||||
|
description: DaemonSetCondition describes the state of a DaemonSet
|
||||||
|
at a certain point.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: Last time the condition transitioned from
|
||||||
|
one status to another.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: A human readable message indicating details
|
||||||
|
about the transition.
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
description: The reason for the condition's last transition.
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: Status of the condition, one of True, False,
|
||||||
|
Unknown.
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: Type of DaemonSet condition.
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
currentNumberScheduled:
|
||||||
|
description: 'The number of nodes that are running at least
|
||||||
|
1 daemon pod and are supposed to run the daemon pod. More
|
||||||
|
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
desiredNumberScheduled:
|
||||||
|
description: 'The total number of nodes that should be running
|
||||||
|
the daemon pod (including nodes correctly running the daemon
|
||||||
|
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberAvailable:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have one or more of the daemon pod running
|
||||||
|
and available (ready for at least spec.minReadySeconds)
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberMisscheduled:
|
||||||
|
description: 'The number of nodes that are running the daemon
|
||||||
|
pod, but are not supposed to run the daemon pod. More info:
|
||||||
|
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberReady:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have one or more of the daemon pod running
|
||||||
|
and ready.
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
numberUnavailable:
|
||||||
|
description: The number of nodes that should be running the
|
||||||
|
daemon pod and have none of the daemon pod running and available
|
||||||
|
(ready for at least spec.minReadySeconds)
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
observedGeneration:
|
||||||
|
description: The most recent generation observed by the daemon
|
||||||
|
set controller.
|
||||||
|
format: int64
|
||||||
|
type: integer
|
||||||
|
updatedNumberScheduled:
|
||||||
|
description: The total number of nodes that are running updated
|
||||||
|
daemon pod
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
required:
|
||||||
|
- currentNumberScheduled
|
||||||
|
- desiredNumberScheduled
|
||||||
|
- numberMisscheduled
|
||||||
|
- numberReady
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- mismatchedContainerImages
|
||||||
|
type: object
|
||||||
|
serviceCIDR:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- clusterID
|
||||||
|
- natEnabled
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
version: v1alpha1
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.3.0
|
||||||
|
creationTimestamp: null
|
||||||
|
name: servicediscoveries.submariner.io
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
names:
|
||||||
|
kind: ServiceDiscovery
|
||||||
|
listKind: ServiceDiscoveryList
|
||||||
|
plural: servicediscoveries
|
||||||
|
singular: servicediscovery
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: ServiceDiscovery is the Schema for the servicediscoveries API
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery
|
||||||
|
properties:
|
||||||
|
brokerK8sApiServer:
|
||||||
|
type: string
|
||||||
|
brokerK8sApiServerToken:
|
||||||
|
type: string
|
||||||
|
brokerK8sCA:
|
||||||
|
type: string
|
||||||
|
brokerK8sRemoteNamespace:
|
||||||
|
type: string
|
||||||
|
clusterID:
|
||||||
|
type: string
|
||||||
|
customDomains:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
x-kubernetes-list-type: set
|
||||||
|
debug:
|
||||||
|
type: boolean
|
||||||
|
globalnetEnabled:
|
||||||
|
type: boolean
|
||||||
|
imageOverrides:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
repository:
|
||||||
|
type: string
|
||||||
|
version:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- brokerK8sApiServer
|
||||||
|
- brokerK8sApiServerToken
|
||||||
|
- brokerK8sCA
|
||||||
|
- brokerK8sRemoteNamespace
|
||||||
|
- clusterID
|
||||||
|
- debug
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.3.0
|
||||||
|
creationTimestamp: null
|
||||||
|
name: brokers.submariner.io
|
||||||
|
spec:
|
||||||
|
group: submariner.io
|
||||||
|
names:
|
||||||
|
kind: Broker
|
||||||
|
listKind: BrokerList
|
||||||
|
plural: brokers
|
||||||
|
singular: broker
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: Broker is the Schema for the brokers API
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: BrokerSpec defines the desired state of Broker
|
||||||
|
properties:
|
||||||
|
components:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
defaultCustomDomains:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
defaultGlobalnetClusterSize:
|
||||||
|
type: integer
|
||||||
|
globalnetCIDRRange:
|
||||||
|
type: string
|
||||||
|
globalnetEnabled:
|
||||||
|
type: boolean
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: BrokerStatus defines the observed state of Broker
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
@@ -1,46 +1,40 @@
|
|||||||
questions:
|
questions:
|
||||||
- variable: defaultEngineImage
|
- variable: defaultOperatorImage
|
||||||
default: true
|
default: true
|
||||||
description: "Use default Submariner Engine image or specify a custom one"
|
description: "Use default Submariner operator image or specify a custom one"
|
||||||
label: Use default submariner engine image
|
label: Use default Submariner operator image
|
||||||
type: boolean
|
type: boolean
|
||||||
show_subquestion_if: false
|
show_subquestion_if: false
|
||||||
group: "Container Images"
|
group: "Container Images"
|
||||||
subquestions:
|
subquestions:
|
||||||
- variable: engine.image.repository
|
- variable: operator.image.repository
|
||||||
default: "oats87/submariner-engine"
|
default: "quay.io/submariner/submariner-operator"
|
||||||
description: "Submariner Engine Image Repository"
|
description: "Submariner Operator Image Repository"
|
||||||
type: string
|
type: string
|
||||||
label: Submariner Engine Image Repository
|
label: Submariner Operator Image Repository
|
||||||
- variable: engine.image.tag
|
- variable: operator.image.tag
|
||||||
default: "dev"
|
default: "0.7.0"
|
||||||
description: "Submariner Engine Image Tag"
|
description: "Submariner Operator Image Tag"
|
||||||
type: string
|
type: string
|
||||||
label: Submariner Engine Image Tag
|
label: Submariner Operator Image Tag
|
||||||
- variable: defaultRouteAgentImage
|
- variable: defaultSubmarinerImages
|
||||||
default: true
|
default: true
|
||||||
description: "Use default Submariner Route Agent image or specify a custom one"
|
description: "Use default Submariner images or specify custom ones"
|
||||||
label: Use default submariner route agent image
|
label: Use default Submariner images
|
||||||
type: boolean
|
type: boolean
|
||||||
show_subquestion_if: false
|
show_subquestion_if: false
|
||||||
group: "Container Images"
|
group: "Container images"
|
||||||
subquestions:
|
subquestions:
|
||||||
- variable: routeAgent.image.repository
|
- variable: submariner.images.repository
|
||||||
default: "oats87/submariner-route-agent"
|
default: "quay.io/submariner"
|
||||||
description: "Submariner Route Agent Image Repository"
|
description: "Submariner Repository (base for all non-operator images)"
|
||||||
type: string
|
type: string
|
||||||
label: Submariner Route Agent Image Repository
|
label: Submariner Repository
|
||||||
- variable: routeAgent.image.tag
|
- variable: submariner.images.tag
|
||||||
default: "dev"
|
default: "0.7.0"
|
||||||
description: "Submariner Route Agent Image Tag"
|
description: "Submariner Images Tag (shared for all non-operator images)"
|
||||||
type: string
|
type: string
|
||||||
label: Submariner Route Agent Image Tag
|
label: Submariner Images Tag
|
||||||
- variable: engine.nodeSelectorEnabled
|
|
||||||
default: true
|
|
||||||
description: "Restrict submariner to nodes labeled with submariner.io/gateway=true"
|
|
||||||
label: Restrict gateway deployments to specific nodes
|
|
||||||
type: boolean
|
|
||||||
group: "Gateway Configuration"
|
|
||||||
- variable: submariner.clusterId
|
- variable: submariner.clusterId
|
||||||
default: ""
|
default: ""
|
||||||
description: "Enter a unique cluster ID to identify this cluster"
|
description: "Enter a unique cluster ID to identify this cluster"
|
||||||
@@ -55,14 +49,6 @@ questions:
|
|||||||
label: "IPsec Pre-Shared Key"
|
label: "IPsec Pre-Shared Key"
|
||||||
group: "Configuration"
|
group: "Configuration"
|
||||||
required: true
|
required: true
|
||||||
- variable: broker.type
|
|
||||||
type: enum
|
|
||||||
default: k8s
|
|
||||||
options:
|
|
||||||
- k8s
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Type"
|
|
||||||
description: "Type of Broker to use"
|
|
||||||
- variable: broker.server
|
- variable: broker.server
|
||||||
type: string
|
type: string
|
||||||
default: ""
|
default: ""
|
||||||
@@ -70,7 +56,7 @@ questions:
|
|||||||
label: "Broker Server"
|
label: "Broker Server"
|
||||||
description: "Broker server to use (without the https://)"
|
description: "Broker server to use (without the https://)"
|
||||||
- variable: broker.insecure
|
- variable: broker.insecure
|
||||||
type: bool
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
show_subquestion_if: false
|
show_subquestion_if: false
|
||||||
group: "Broker Configuration"
|
group: "Broker Configuration"
|
||||||
@@ -106,18 +92,32 @@ questions:
|
|||||||
label: "Service CIDR"
|
label: "Service CIDR"
|
||||||
group: "CIDR Configuration"
|
group: "CIDR Configuration"
|
||||||
required: true
|
required: true
|
||||||
|
- variable: submariner.serviceDiscovery
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
group: "Advanced Configuration"
|
||||||
|
description: "Enable multicluster service discovery"
|
||||||
|
label: "Service Discovery Enabled"
|
||||||
|
- variable: broker.globalnet
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
group: "Broker Configuration"
|
||||||
|
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
|
||||||
|
label: "Globalnet Enabled"
|
||||||
|
subquestions:
|
||||||
|
- variable: submariner.globalCidr
|
||||||
|
default: ""
|
||||||
|
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
|
||||||
|
type: string
|
||||||
|
label: "Globalnet CIDR"
|
||||||
|
group: "CIDR Configuration"
|
||||||
|
required: false
|
||||||
- variable: submariner.natEnabled
|
- variable: submariner.natEnabled
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
group: "Advanced Configuration"
|
group: "Advanced Configuration"
|
||||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
||||||
label: "NAT Enabled"
|
label: "NAT Enabled"
|
||||||
- variable: crd.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Create the Submariner CRDs, if deploying Submariner into the same cluster as the submariner-k8s-broker, you probably shouldn't create CRDs"
|
|
||||||
label: "CRD Creation Enabled"
|
|
||||||
- variable: submariner.debug
|
- variable: submariner.debug
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
@@ -129,4 +129,10 @@ questions:
|
|||||||
default: false
|
default: false
|
||||||
group: "Advanced Configuration"
|
group: "Advanced Configuration"
|
||||||
description: "Enable Charon debug mode"
|
description: "Enable Charon debug mode"
|
||||||
label: "Charon Enabled"
|
label: "Charon Enabled"
|
||||||
|
- variable: submariner.cableDriver
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
group: "Advanced Configuration"
|
||||||
|
description: "Cable driver implementation"
|
||||||
|
label: "Cable Driver"
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
Submariner is now installed.
|
Submariner is now installed.
|
||||||
|
|
||||||
{{- if .Values.engine.nodeSelectorEnabled }}
|
{{- if .Values.gateway.nodeSelectorEnabled }}
|
||||||
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
@@ -0,0 +1,105 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride -}}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||||
|
{{- if contains $name .Release.Name -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-operator service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.operatorServiceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccounts.operator.create -}}
|
||||||
|
{{ default (printf "%s" (include "submariner.fullname" .)) .Values.serviceAccounts.operator.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.operator.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-gateway service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.gatewayServiceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccounts.gateway.create -}}
|
||||||
|
{{ default "submariner-gateway" .Values.serviceAccounts.gateway.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.gateway.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-route-agent service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.routeAgentServiceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
||||||
|
{{ default "submariner-routeagent" .Values.serviceAccounts.routeAgent.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-globalnet service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.globalnetServiceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccounts.globalnet.create -}}
|
||||||
|
{{ default "submariner-globalnet" .Values.serviceAccounts.globalnet.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.globalnet.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-lighthouse-agent service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.lighthouseAgentServiceAccountName" -}}
|
||||||
|
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseAgent.create) -}}
|
||||||
|
{{ default "submariner-lighthouse-agent" .Values.serviceAccounts.lighthouseAgent.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.lighthouseAgent.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-lighthouse-coredns service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.lighthouseCoreDnsServiceAccountName" -}}
|
||||||
|
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseCoreDns.create) -}}
|
||||||
|
{{ default "submariner-lighthouse-coredns" .Values.serviceAccounts.lighthouseCoreDns.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccounts.lighthouseCoreDns.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the submariner-lighthouse-coredns service name to use
|
||||||
|
*/}}
|
||||||
|
{{- define "submariner.lighthouseDnsName" -}}
|
||||||
|
{{- default (printf "%s-lighthouse-coredns" (include "submariner.fullname" .)) .Values.lighthouseCoredns.name }}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.fullname" . }}
|
||||||
|
component: gateway
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
spec:
|
||||||
|
progressDeadlineSeconds: 600
|
||||||
|
replicas: 1
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
strategy:
|
||||||
|
rollingUpdate:
|
||||||
|
maxSurge: 25%
|
||||||
|
maxUnavailable: 25%
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: null
|
||||||
|
labels:
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- command:
|
||||||
|
- submariner-operator
|
||||||
|
env:
|
||||||
|
- name: WATCH_NAMESPACE
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
apiVersion: v1
|
||||||
|
fieldPath: metadata.namespace
|
||||||
|
- name: POD_NAME
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
apiVersion: v1
|
||||||
|
fieldPath: metadata.name
|
||||||
|
- name: OPERATOR_NAME
|
||||||
|
value: submariner-operator
|
||||||
|
image: {{ .Values.operator.image.repository }}:{{ default .Chart.AppVersion .Values.operator.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.operator.image.pullPolicy }}
|
||||||
|
name: submariner-operator
|
||||||
|
resources: {}
|
||||||
|
terminationMessagePath: /dev/termination-log
|
||||||
|
terminationMessagePolicy: File
|
||||||
|
dnsPolicy: ClusterFirst
|
||||||
|
restartPolicy: Always
|
||||||
|
schedulerName: default-scheduler
|
||||||
|
securityContext: {}
|
||||||
|
serviceAccount: {{ template "submariner.fullname" . }}
|
||||||
|
serviceAccountName: {{ template "submariner.fullname" . }}
|
||||||
|
terminationGracePeriodSeconds: 30
|
||||||
@@ -0,0 +1,832 @@
|
|||||||
|
{{- if .Values.rbac.create -}}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- services/finalizers
|
||||||
|
- endpoints
|
||||||
|
- persistentvolumeclaims
|
||||||
|
- events
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- daemonsets
|
||||||
|
- replicasets
|
||||||
|
- statefulsets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- monitoring.coreos.com
|
||||||
|
resources:
|
||||||
|
- servicemonitors
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resourceNames:
|
||||||
|
- {{ template "submariner.fullname" . }}
|
||||||
|
resources:
|
||||||
|
- deployments/finalizers
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
- servicediscoveries
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
---
|
||||||
|
kind: RoleBinding
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||||
|
roleRef:
|
||||||
|
kind: Role
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:gateway
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- services/finalizers
|
||||||
|
- endpoints
|
||||||
|
- persistentvolumeclaims
|
||||||
|
- events
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- daemonsets
|
||||||
|
- replicasets
|
||||||
|
- statefulsets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- monitoring.coreos.com
|
||||||
|
resources:
|
||||||
|
- servicemonitors
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resourceNames:
|
||||||
|
- submariner-operator
|
||||||
|
resources:
|
||||||
|
- deployments/finalizers
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
- servicediscoveries
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- lighthouse.submariner.io
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
- serviceexports
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:gateway
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ template "submariner.fullname" . }}:gateway
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- services/finalizers
|
||||||
|
- endpoints
|
||||||
|
- persistentvolumeclaims
|
||||||
|
- events
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- daemonsets
|
||||||
|
- replicasets
|
||||||
|
- statefulsets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- monitoring.coreos.com
|
||||||
|
resources:
|
||||||
|
- servicemonitors
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resourceNames:
|
||||||
|
- submariner-operator
|
||||||
|
resources:
|
||||||
|
- deployments/finalizers
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
- servicediscoveries
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- lighthouse.submariner.io
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
- serviceexports
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
{{- if .Values.broker.globalnet }}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- services/finalizers
|
||||||
|
- endpoints
|
||||||
|
- persistentvolumeclaims
|
||||||
|
- events
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- daemonsets
|
||||||
|
- replicasets
|
||||||
|
- statefulsets
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- monitoring.coreos.com
|
||||||
|
resources:
|
||||||
|
- servicemonitors
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resourceNames:
|
||||||
|
- submariner-operator
|
||||||
|
resources:
|
||||||
|
- deployments/finalizers
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
- servicediscoveries
|
||||||
|
verbs:
|
||||||
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- lighthouse.submariner.io
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
- serviceexports
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
{{- end -}}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
# submariner-operator updates the config map of core-dns to forward requests to
|
||||||
|
# clusterset.local to Lighthouse DNS, also looks at existing configmaps
|
||||||
|
# to figure out network settings
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
- watch
|
||||||
|
- apiGroups: # pods, services and nodes are looked up to figure out network settings
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- nodes
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- operator.openshift.io
|
||||||
|
resources:
|
||||||
|
- dnses
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- config.openshift.io
|
||||||
|
resources:
|
||||||
|
- networks
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:gateway
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
- apiGroups: # pods and services are looked up to figure out network settings
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- nodes
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- operator.openshift.io
|
||||||
|
resources:
|
||||||
|
- dnses
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- config.openshift.io
|
||||||
|
resources:
|
||||||
|
- networks
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- endpoints
|
||||||
|
- gateways
|
||||||
|
- clusters
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:gateway
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:gateway
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
- apiGroups: # pods and services are looked up to figure out network settings
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- operator.openshift.io
|
||||||
|
resources:
|
||||||
|
- dnses
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- config.openshift.io
|
||||||
|
resources:
|
||||||
|
- networks
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
resources:
|
||||||
|
- nodes
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:routeagent
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
{{- if .Values.broker.globalnet }}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- namespaces
|
||||||
|
- nodes
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- endpoints
|
||||||
|
- clusters
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- multicluster.x-k8s.io
|
||||||
|
resources:
|
||||||
|
- "serviceexports"
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
---
|
||||||
|
{{- end -}}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:globalnet
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
{{- if .Values.submariner.serviceDiscovery }}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- services
|
||||||
|
- namespaces
|
||||||
|
- endpoints
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- discovery.k8s.io
|
||||||
|
resources:
|
||||||
|
- endpointslices
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
- deletecollection
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- "gateways"
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- multicluster.x-k8s.io
|
||||||
|
resources:
|
||||||
|
- "*"
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- services
|
||||||
|
- namespaces
|
||||||
|
- endpoints
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- discovery.k8s.io
|
||||||
|
resources:
|
||||||
|
- endpointslices
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
- deletecollection
|
||||||
|
- apiGroups:
|
||||||
|
- lighthouse.submariner.io
|
||||||
|
resources:
|
||||||
|
- "*"
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- "gateways"
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- multicluster.x-k8s.io
|
||||||
|
resources:
|
||||||
|
- "*"
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
apiVersion: submariner.io/v1alpha1
|
||||||
|
kind: Submariner
|
||||||
|
metadata:
|
||||||
|
name: submariner
|
||||||
|
namespace: submariner-operator
|
||||||
|
spec:
|
||||||
|
broker: k8s
|
||||||
|
brokerK8sApiServer: {{ .Values.broker.server }}
|
||||||
|
brokerK8sApiServerToken: {{ .Values.broker.token }}
|
||||||
|
brokerK8sCA: {{ .Values.broker.ca }}
|
||||||
|
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
|
||||||
|
ceIPSecDebug: {{ .Values.ipsec.debug }}
|
||||||
|
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
|
||||||
|
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
|
||||||
|
ceIPSecPSK: {{ .Values.ipsec.psk }}
|
||||||
|
clusterCIDR: "{{ .Values.submariner.clusterCidr }}"
|
||||||
|
clusterID: {{ .Values.submariner.clusterId }}
|
||||||
|
colorCodes: {{ .Values.submariner.colorCodes }}
|
||||||
|
debug: {{ .Values.submariner.debug }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
natEnabled: {{ .Values.submariner.natEnabled }}
|
||||||
|
repository: {{ .Values.submariner.images.repository }}
|
||||||
|
version: {{ .Values.submariner.images.tag }}
|
||||||
|
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
||||||
|
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||||
|
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||||
|
cableDriver: {{ .Values.submariner.cableDriver }}
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
{{- if .Values.serviceAccounts.operator.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.gateway.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.routeAgent.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.globalnet.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
heritage: {{ .Release.Service | quote }}
|
||||||
|
release: {{ .Release.Name | quote }}
|
||||||
|
chart: {{ template "submariner.chart" . }}
|
||||||
|
app: {{ template "submariner.name" . }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
---
|
||||||
|
submariner:
|
||||||
|
clusterId: ""
|
||||||
|
token: ""
|
||||||
|
clusterCidr: ""
|
||||||
|
serviceCidr: ""
|
||||||
|
globalCidr: ""
|
||||||
|
natEnabled: false
|
||||||
|
colorCodes: blue
|
||||||
|
debug: false
|
||||||
|
serviceDiscovery: true
|
||||||
|
cableDriver: "libreswan"
|
||||||
|
images:
|
||||||
|
repository: quay.io/submariner
|
||||||
|
tag: "0.7.0"
|
||||||
|
broker:
|
||||||
|
server: example.k8s.apiserver
|
||||||
|
token: test
|
||||||
|
namespace: xyz
|
||||||
|
insecure: false
|
||||||
|
ca: ""
|
||||||
|
globalnet: false
|
||||||
|
rbac:
|
||||||
|
create: true
|
||||||
|
ipsec:
|
||||||
|
psk: ""
|
||||||
|
debug: false
|
||||||
|
ikePort: 500
|
||||||
|
natPort: 4500
|
||||||
|
leadership:
|
||||||
|
leaseDuration: 10
|
||||||
|
renewDeadline: 5
|
||||||
|
retryPeriod: 2
|
||||||
|
operator:
|
||||||
|
image:
|
||||||
|
repository: quay.io/submariner/submariner-operator
|
||||||
|
tag: "0.7.0"
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
resources: {}
|
||||||
|
tolerations: []
|
||||||
|
affinity: {}
|
||||||
|
gateway:
|
||||||
|
image:
|
||||||
|
repository: quay.io/submariner/submariner-gateway
|
||||||
|
tag: "0.7.0"
|
||||||
|
serviceAccounts:
|
||||||
|
operator:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
gateway:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
routeAgent:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
globalnet:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
lighthouseAgent:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
lighthouseCoreDns:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
name: submariner
|
|
||||||
version: 0.0.1
|
|
||||||
appVersion: v0.0.1
|
|
||||||
description: Submariner
|
|
||||||
keywords:
|
|
||||||
home: https://submariner.io/
|
|
||||||
sources:
|
|
||||||
- https://github.com/rancher/submariner-charts
|
|
||||||
maintainers:
|
|
||||||
- name: Rancher Labs
|
|
||||||
email: charts@rancher.com
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
# Submariner
|
|
||||||
|
|
||||||
[Submariner](https://submariner.io) is a cross-cluster networking tool.
|
|
||||||
|
|
||||||
This chart creates the required components in this cluster to enable cross cluster networking.
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
||||||
If release name contains chart name it will be used as a full name.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride -}}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
|
||||||
{{- if contains $name .Release.Name -}}
|
|
||||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-engine service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.engineServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.engine.create -}}
|
|
||||||
{{ default (printf "%s-engine" (include "submariner.fullname" .)) .Values.serviceAccounts.engine.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.engine.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-route-agent service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.routeAgentServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
|
||||||
{{ default (printf "%s-routeagent" (include "submariner.fullname" .)) .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
{{- if .Values.crd.create -}}
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: clusters.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Cluster
|
|
||||||
plural: clusters
|
|
||||||
scope: Namespaced
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1beta1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: endpoints.submariner.io
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": crd-install
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
version: v1
|
|
||||||
names:
|
|
||||||
kind: Endpoint
|
|
||||||
plural: endpoints
|
|
||||||
scope: Namespaced
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,123 +0,0 @@
|
|||||||
apiVersion: apps/v1beta2
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.fullname" . }}-engine
|
|
||||||
component: engine
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
spec:
|
|
||||||
progressDeadlineSeconds: 600
|
|
||||||
replicas: 1
|
|
||||||
revisionHistoryLimit: 5
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ template "submariner.fullname" . }}-engine
|
|
||||||
strategy:
|
|
||||||
rollingUpdate:
|
|
||||||
maxSurge: 1
|
|
||||||
maxUnavailable: 0
|
|
||||||
type: RollingUpdate
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
creationTimestamp: null
|
|
||||||
labels:
|
|
||||||
app: {{ template "submariner.fullname" . }}-engine
|
|
||||||
spec:
|
|
||||||
affinity:
|
|
||||||
podAntiAffinity:
|
|
||||||
requiredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
- labelSelector:
|
|
||||||
matchExpressions:
|
|
||||||
- key: app
|
|
||||||
operator: In
|
|
||||||
values:
|
|
||||||
- {{ template "submariner.fullname" . }}-engine
|
|
||||||
topologyKey: "kubernetes.io/hostname"
|
|
||||||
{{- with .Values.engine.affinity }}
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
nodeSelector:
|
|
||||||
{{- if .Values.engine.nodeSelectorEnabled }}
|
|
||||||
submariner.io/gateway: "true"
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.engine.nodeSelector }}
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.engine.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
containers:
|
|
||||||
- command:
|
|
||||||
- submariner.sh
|
|
||||||
env:
|
|
||||||
- name: SUBMARINER_NAMESPACE
|
|
||||||
value: "{{ .Release.Namespace }}"
|
|
||||||
- name: SUBMARINER_CLUSTERCIDR
|
|
||||||
value: "{{ .Values.submariner.clusterCidr }}"
|
|
||||||
- name: SUBMARINER_SERVICECIDR
|
|
||||||
value: "{{ .Values.submariner.serviceCidr }}"
|
|
||||||
- name: SUBMARINER_TOKEN
|
|
||||||
value: "{{ .Values.submariner.apiToken }}"
|
|
||||||
- name: SUBMARINER_CLUSTERID
|
|
||||||
value: "{{ .Values.submariner.clusterId }}"
|
|
||||||
- name: SUBMARINER_COLORCODES
|
|
||||||
value: "{{ .Values.submariner.colorCodes }}"
|
|
||||||
- name: SUBMARINER_DEBUG
|
|
||||||
value: "{{ .Values.submariner.debug }}"
|
|
||||||
- name: SUBMARINER_NATENABLED
|
|
||||||
value: "{{ .Values.submariner.natEnabled }}"
|
|
||||||
- name: SUBMARINER_BROKER
|
|
||||||
value: "{{ .Values.broker.type }}"
|
|
||||||
{{- if eq .Values.broker.type "phpapi" }}
|
|
||||||
- name: BROKER_PHPAPI_PROTO
|
|
||||||
value: "{{ .Values.broker.proto }}"
|
|
||||||
- name: BROKER_PHPAPI_SERVER
|
|
||||||
value: "{{ .Values.broker.server }}"
|
|
||||||
{{- end }}
|
|
||||||
{{- if eq .Values.broker.type "k8s" }}
|
|
||||||
- name: BROKER_K8S_APISERVER
|
|
||||||
value: "{{ .Values.broker.server }}"
|
|
||||||
- name: BROKER_K8S_APISERVERTOKEN
|
|
||||||
value: "{{ .Values.broker.token }}"
|
|
||||||
- name: BROKER_K8S_REMOTENAMESPACE
|
|
||||||
value: "{{ .Values.broker.namespace }}"
|
|
||||||
{{- if .Values.broker.insecure }}
|
|
||||||
- name: BROKER_K8S_INSECURE
|
|
||||||
value: "true"
|
|
||||||
{{- else }}
|
|
||||||
- name: BROKER_K8S_CA
|
|
||||||
value: "{{ .Values.broker.ca }}"
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
- name: CE_IPSEC_PSK
|
|
||||||
value: "{{ .Values.ipsec.psk }}"
|
|
||||||
- name: CE_IPSEC_DEBUG
|
|
||||||
value: "{{ .Values.ipsec.debug }}"
|
|
||||||
image: {{ .Values.engine.image.repository }}:{{ .Values.engine.image.tag }}
|
|
||||||
imagePullPolicy: {{ .Values.engine.image.pullPolicy }}
|
|
||||||
name: submariner
|
|
||||||
resources:
|
|
||||||
{{ toYaml .Values.engine.resources | indent 10 }}
|
|
||||||
securityContext:
|
|
||||||
allowPrivilegeEscalation: true
|
|
||||||
capabilities:
|
|
||||||
add:
|
|
||||||
- ALL
|
|
||||||
privileged: true
|
|
||||||
readOnlyRootFilesystem: false
|
|
||||||
runAsNonRoot: false
|
|
||||||
stdin: true
|
|
||||||
terminationMessagePath: /dev/termination-log
|
|
||||||
terminationMessagePolicy: File
|
|
||||||
tty: true
|
|
||||||
dnsPolicy: ClusterFirst
|
|
||||||
hostNetwork: true
|
|
||||||
restartPolicy: Always
|
|
||||||
schedulerName: default-scheduler
|
|
||||||
securityContext: {}
|
|
||||||
terminationGracePeriodSeconds: 0
|
|
||||||
serviceAccountName: {{ template "submariner.engineServiceAccountName" . }}
|
|
||||||
@@ -1,61 +0,0 @@
|
|||||||
{{- if .Values.rbac.create -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:engine
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["configmaps"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
|
||||||
- apiGroups: ["submariner.io"]
|
|
||||||
resources: ["clusters", "endpoints"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["events"]
|
|
||||||
verbs: ["create", "patch"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: ["submariner.io"]
|
|
||||||
resources: ["clusters", "endpoints"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:engine
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:engine
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.engineServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,61 +0,0 @@
|
|||||||
apiVersion: apps/v1beta2
|
|
||||||
kind: DaemonSet
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
component: routeagent
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.fullname" . }}-routeagent
|
|
||||||
component: routeagent
|
|
||||||
spec:
|
|
||||||
serviceAccountName: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
terminationGracePeriodSeconds: 0
|
|
||||||
hostNetwork: true
|
|
||||||
containers:
|
|
||||||
- name: routeagent
|
|
||||||
command:
|
|
||||||
- submariner-route-agent.sh
|
|
||||||
image: {{ .Values.routeAgent.image.repository }}:{{ .Values.routeAgent.image.tag }}
|
|
||||||
imagePullPolicy: {{ .Values.routeAgent.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
- name: SUBMARINER_NAMESPACE
|
|
||||||
value: "{{ .Release.Namespace }}"
|
|
||||||
- name: SUBMARINER_CLUSTERID
|
|
||||||
value: "{{ .Values.submariner.clusterId }}"
|
|
||||||
- name: SUBMARINER_DEBUG
|
|
||||||
value: "{{ .Values.submariner.debug }}"
|
|
||||||
resources:
|
|
||||||
{{ toYaml .Values.routeAgent.resources | indent 10 }}
|
|
||||||
securityContext:
|
|
||||||
allowPrivilegeEscalation: true
|
|
||||||
capabilities:
|
|
||||||
add:
|
|
||||||
- ALL
|
|
||||||
privileged: true
|
|
||||||
readOnlyRootFilesystem: false
|
|
||||||
runAsNonRoot: false
|
|
||||||
{{- with .Values.routeAgent.nodeSelector }}
|
|
||||||
nodeSelector:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.routeAgent.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.routeAgent.affinity }}
|
|
||||||
affinity:
|
|
||||||
{{ toYaml . | indent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
{{- if .Values.serviceAccounts.engine.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.engineServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
submariner:
|
|
||||||
clusterId: ""
|
|
||||||
token: ""
|
|
||||||
clusterCidr: "10.42.0.0/16"
|
|
||||||
serviceCidr: "10.43.0.0/16"
|
|
||||||
natEnabled: false
|
|
||||||
colorCodes: blue
|
|
||||||
debug: false
|
|
||||||
crd:
|
|
||||||
create: true
|
|
||||||
broker:
|
|
||||||
type: k8s
|
|
||||||
server: example.k8s.apiserver
|
|
||||||
token: test
|
|
||||||
namespace: xyz
|
|
||||||
insecure: false
|
|
||||||
ca: ""
|
|
||||||
rbac:
|
|
||||||
create: true
|
|
||||||
ipsec:
|
|
||||||
psk: ""
|
|
||||||
debug: false
|
|
||||||
engine:
|
|
||||||
image:
|
|
||||||
repository: rancher/submariner
|
|
||||||
tag: v0.0.1
|
|
||||||
pullPolicy: Always
|
|
||||||
resources: {}
|
|
||||||
# limits:
|
|
||||||
# cpu: 100m
|
|
||||||
# memory: 100Mi
|
|
||||||
nodeSelectorEnabled: true
|
|
||||||
nodeSelector: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
routeAgent:
|
|
||||||
image:
|
|
||||||
repository: rancher/submariner-route-agent
|
|
||||||
tag: v0.0.1
|
|
||||||
pullPolicy: Always
|
|
||||||
resources: {}
|
|
||||||
# limits:
|
|
||||||
# cpu: 100m
|
|
||||||
# memory: 100Mi
|
|
||||||
nodeSelector: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
serviceAccounts:
|
|
||||||
engine:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
routeAgent:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
Reference in New Issue
Block a user