mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-20 22:40:34 +00:00
Compare commits
42
Commits
v0.11.2
...
v0.13.0-rc2
@@ -0,0 +1,12 @@
|
||||
---
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
schedule:
|
||||
interval: daily
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.12"
|
||||
schedule:
|
||||
interval: daily
|
||||
@@ -5,10 +5,10 @@ on:
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
target_devel:
|
||||
name: PR targets devel
|
||||
target_branch:
|
||||
name: PR targets branch
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check that the PR targets devel
|
||||
if: ${{ github.base_ref != 'devel' }}
|
||||
- name: Check that the PR targets release-0.13
|
||||
if: ${{ github.base_ref != 'release-0.13' }}
|
||||
run: exit 1
|
||||
|
||||
@@ -17,7 +17,7 @@ on:
|
||||
- reopened
|
||||
- synchronize
|
||||
schedule:
|
||||
- cron: '0 0/6 * * *' # every 6 hours
|
||||
- cron: '0 0/6 * * *' # every 6 hours
|
||||
|
||||
jobs:
|
||||
check:
|
||||
@@ -25,7 +25,7 @@ jobs:
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: z0al/dependent-issues@70a1b2d4ee1cdc743af33498bd0204123953a887
|
||||
- uses: z0al/dependent-issues@0fae07162bc9e0d8e116a133bd03686eed6efa21
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
with:
|
||||
|
||||
@@ -16,22 +16,21 @@ jobs:
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
k8s_version: ['1.17']
|
||||
k8s_version: ['1.23']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
include:
|
||||
- k8s_version: '1.18'
|
||||
- k8s_version: '1.19'
|
||||
- k8s_version: '1.20'
|
||||
- k8s_version: '1.21'
|
||||
- k8s_version: '1.22'
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.13
|
||||
with:
|
||||
k8s_version: ${{ matrix.k8s_version }}
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.13
|
||||
|
||||
@@ -11,11 +11,11 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.13
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.13
|
||||
|
||||
@@ -19,13 +19,13 @@ jobs:
|
||||
lighthouse: ['', 'lighthouse']
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.13
|
||||
with:
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.13
|
||||
|
||||
@@ -11,7 +11,7 @@ jobs:
|
||||
steps:
|
||||
- name: Get PR commits
|
||||
id: 'get-pr-commits'
|
||||
uses: tim-actions/get-pr-commits@55b867b9b28954e6f5c1a0fe2f729dc926c306d0
|
||||
uses: tim-actions/get-pr-commits@c64db31d359214d244884dd68f971a110b29ab83
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
@@ -23,25 +23,33 @@ jobs:
|
||||
flags: 'i'
|
||||
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
||||
|
||||
- name: 'Verify no "fixup!" commits'
|
||||
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
|
||||
with:
|
||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||
pattern: '^(?!fixup!)'
|
||||
flags: 'i'
|
||||
error: 'Fixup commits should be squashed into the commits under review'
|
||||
|
||||
chart-testing:
|
||||
name: Helm Chart Linting
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@18bc76811624f360dbd7f18c2d4ecb32c7b87bab
|
||||
uses: azure/setup-helm@217bf70cbd2e930ba2e81ba7e1de2f7faecc42ba
|
||||
with:
|
||||
version: v3.6.0
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@dc73133d4da04e56a135ae2246682783cc7c7cb6
|
||||
uses: actions/setup-python@d09bd5e6005b175076f227b13d9730d56e9dcfcb
|
||||
with:
|
||||
python-version: '3.x'
|
||||
|
||||
- name: Set up helm/chart-testing
|
||||
uses: helm/chart-testing-action@5f16c27cf7a4fa9c776ff73734df3909b2b65127
|
||||
uses: helm/chart-testing-action@dae259e86a35ff09145c0805e2d7dd3f7207064a
|
||||
|
||||
- name: Run helm/chart-testing (lint)
|
||||
run: ct lint --config ct.yaml
|
||||
@@ -51,7 +59,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Run gitlint
|
||||
@@ -62,7 +70,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
- name: Run helm-docs and verify docs are up-to-date
|
||||
run: make helm-docs
|
||||
@@ -72,10 +80,10 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
check-modified-files-only: "yes"
|
||||
@@ -86,7 +94,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
- name: Run markdownlint
|
||||
run: make markdownlint
|
||||
|
||||
@@ -95,10 +103,6 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
- name: Run yamllint
|
||||
uses: ibiqlik/action-yamllint@ed2b6e911569708ed121c14b87d513860a7e36a7
|
||||
with:
|
||||
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
|
||||
config_file: .yamllint.yml
|
||||
strict: true
|
||||
run: make yamllint
|
||||
|
||||
@@ -12,16 +12,16 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
|
||||
- name: Raise an Issue to report broken links
|
||||
if: ${{ failure() }}
|
||||
uses: peter-evans/create-issue-from-file@97e6f902a416aac38834e23fa52e166aad0437d2
|
||||
uses: peter-evans/create-issue-from-file@99b87c35610e986ad2034a7b0518a9b3ebea541b
|
||||
with:
|
||||
title: Broken link detected by CI
|
||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||
|
||||
@@ -4,7 +4,7 @@ name: Release Charts
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- devel
|
||||
- release-0.13
|
||||
|
||||
jobs:
|
||||
release:
|
||||
@@ -13,7 +13,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
|
||||
@@ -1,5 +1,8 @@
|
||||
{
|
||||
"ignorePatterns": [
|
||||
{
|
||||
"pattern": "^https://docs.github.com"
|
||||
},
|
||||
{
|
||||
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
||||
},
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
---
|
||||
cni: ovn
|
||||
submariner: true
|
||||
nodes: control-plane worker worker
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
@@ -0,0 +1,7 @@
|
||||
---
|
||||
cni: weave
|
||||
submariner: true
|
||||
nodes: control-plane worker
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
@@ -1,3 +1,4 @@
|
||||
---
|
||||
label-approved:
|
||||
approvals: 2
|
||||
label: ready-to-test
|
||||
|
||||
+11
-11
@@ -1,15 +1,15 @@
|
||||
---
|
||||
extends: default
|
||||
|
||||
rules:
|
||||
comments: disable
|
||||
comments-indentation: disable
|
||||
line-length:
|
||||
max: 150
|
||||
braces:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 0
|
||||
brackets:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 0
|
||||
indentation:
|
||||
indent-sequences: consistent
|
||||
max: 140
|
||||
# Allow standard GHA syntax for "on: *"
|
||||
truthy:
|
||||
ignore: '.github/workflows/*.yml'
|
||||
|
||||
ignore: |
|
||||
/submariner-k8s-broker/crds
|
||||
/submariner-operator/crds
|
||||
/submariner-k8s-broker/templates
|
||||
/submariner-operator/templates
|
||||
|
||||
+3
-1
@@ -1 +1,3 @@
|
||||
* @mangelajo @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
# Auto-generated, do not edit; see CODEOWNERS.in
|
||||
* @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
@dfarrell07 *.md
|
||||
@Oats87 *
|
||||
@skitt *
|
||||
@sridhargaddam *
|
||||
@tpantelis *
|
||||
@@ -9,6 +9,8 @@ ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
|
||||
|
||||
WORKDIR ${DAPPER_SOURCE}
|
||||
|
||||
RUN git config --global --add safe.directory ${DAPPER_SOURCE}
|
||||
|
||||
# Override the Helm deployment scripts
|
||||
COPY deploy_helm /opt/shipyard/scripts/lib/
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
BASE_BRANCH ?= devel
|
||||
BASE_BRANCH ?= release-0.13
|
||||
export BASE_BRANCH
|
||||
|
||||
ifneq (,$(DAPPER_HOST_ARCH))
|
||||
@@ -9,11 +9,10 @@ PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent
|
||||
|
||||
include $(SHIPYARD_DIR)/Makefile.inc
|
||||
|
||||
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
|
||||
ifneq (,$(filter ovn,$(_using)))
|
||||
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings.ovn
|
||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||
else
|
||||
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
|
||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||
endif
|
||||
|
||||
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
|
||||
@@ -21,7 +20,7 @@ override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
|
||||
export DEPLOY_ARGS
|
||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||
CHARTS_DIR=charts
|
||||
CHARTS_VERSION=0.7.0
|
||||
CHARTS_VERSION=0.10.1
|
||||
HELM_DOCS_VERSION=0.15.0
|
||||
REPO_URL=$(shell git config remote.origin.url)
|
||||
|
||||
|
||||
@@ -60,4 +60,4 @@ working correctly.
|
||||
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
|
||||
[Docker]: https://docs.docker.com/install/
|
||||
[Podman]: https://podman.io/getting-started/installation
|
||||
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
|
||||
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
. "${SCRIPTS_DIR}"/lib/source_only
|
||||
|
||||
# We need a minimal setup to verify the deployment works
|
||||
clusters=('cluster1' 'cluster2')
|
||||
cluster_nodes['cluster1']="control-plane worker"
|
||||
cluster_nodes['cluster2']="control-plane worker"
|
||||
|
||||
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
|
||||
|
||||
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
|
||||
@@ -1,10 +0,0 @@
|
||||
. "${SCRIPTS_DIR}"/lib/source_only
|
||||
|
||||
# We need a minimal setup to verify the deployment works
|
||||
clusters=('cluster1' 'cluster2')
|
||||
cluster_nodes['cluster1']="control-plane worker worker"
|
||||
cluster_nodes['cluster2']="control-plane worker worker"
|
||||
|
||||
cluster_cni=( ['cluster1']="ovn" ['cluster2']="ovn" )
|
||||
|
||||
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
|
||||
@@ -1,97 +1,333 @@
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: clusters.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Cluster
|
||||
listKind: ClusterList
|
||||
plural: clusters
|
||||
singular: cluster
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
properties:
|
||||
cluster_cidr:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
cluster_id:
|
||||
type: string
|
||||
color_codes:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
global_cidr:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
service_cidr:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
required:
|
||||
- cluster_cidr
|
||||
- cluster_id
|
||||
- color_codes
|
||||
- global_cidr
|
||||
- service_cidr
|
||||
type: object
|
||||
required:
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
status:
|
||||
acceptedNames:
|
||||
kind: ""
|
||||
plural: ""
|
||||
conditions: []
|
||||
storedVersions: []
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: endpoints.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Endpoint
|
||||
listKind: EndpointList
|
||||
plural: endpoints
|
||||
singular: endpoint
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
properties:
|
||||
backend:
|
||||
type: string
|
||||
backend_config:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
cable_name:
|
||||
type: string
|
||||
cluster_id:
|
||||
type: string
|
||||
healthCheckIP:
|
||||
type: string
|
||||
hostname:
|
||||
type: string
|
||||
nat_enabled:
|
||||
type: boolean
|
||||
private_ip:
|
||||
type: string
|
||||
public_ip:
|
||||
type: string
|
||||
subnets:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
required:
|
||||
- backend
|
||||
- cable_name
|
||||
- cluster_id
|
||||
- hostname
|
||||
- nat_enabled
|
||||
- private_ip
|
||||
- public_ip
|
||||
- subnets
|
||||
type: object
|
||||
required:
|
||||
- spec
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
status:
|
||||
acceptedNames:
|
||||
kind: ""
|
||||
plural: ""
|
||||
conditions: []
|
||||
storedVersions: []
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: gateways.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Gateway
|
||||
listKind: GatewayList
|
||||
plural: gateways
|
||||
singular: gateway
|
||||
scope: Namespaced
|
||||
additionalPrinterColumns:
|
||||
- name: ha-status
|
||||
versions:
|
||||
- additionalPrinterColumns:
|
||||
- description: High availability status of the Gateway
|
||||
jsonPath: .status.haStatus
|
||||
name: HA Status
|
||||
type: string
|
||||
description: High Availability Status of the Gateway
|
||||
JSONPath: .status.haStatus
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: multiclusterservices.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: MultiClusterService
|
||||
plural: multiclusterservices
|
||||
singular: multiclusterservice
|
||||
scope: Namespaced
|
||||
validation:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
spec:
|
||||
properties:
|
||||
clusterServiceInfo:
|
||||
properties:
|
||||
clusterID:
|
||||
type: "string"
|
||||
clusterDomain:
|
||||
type: "string"
|
||||
serviceIP:
|
||||
type: "string"
|
||||
port:
|
||||
type: "integer"
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceexports.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v2alpha1
|
||||
names:
|
||||
kind: ServiceExport
|
||||
plural: serviceexports
|
||||
singular: serviceexport
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceimports.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v2alpha1
|
||||
names:
|
||||
kind: ServiceImport
|
||||
plural: serviceimports
|
||||
singular: serviceimport
|
||||
scope: Namespaced
|
||||
name: v1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
status:
|
||||
properties:
|
||||
connections:
|
||||
items:
|
||||
properties:
|
||||
endpoint:
|
||||
properties:
|
||||
backend:
|
||||
type: string
|
||||
backend_config:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
cable_name:
|
||||
type: string
|
||||
cluster_id:
|
||||
type: string
|
||||
healthCheckIP:
|
||||
type: string
|
||||
hostname:
|
||||
type: string
|
||||
nat_enabled:
|
||||
type: boolean
|
||||
private_ip:
|
||||
type: string
|
||||
public_ip:
|
||||
type: string
|
||||
subnets:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
required:
|
||||
- backend
|
||||
- cable_name
|
||||
- cluster_id
|
||||
- hostname
|
||||
- nat_enabled
|
||||
- private_ip
|
||||
- public_ip
|
||||
- subnets
|
||||
type: object
|
||||
latency:
|
||||
description: LatencySpec describes the round trip time information
|
||||
in nanoseconds for a packet between the gateway pods of two
|
||||
clusters.
|
||||
properties:
|
||||
averageRTT:
|
||||
format: int64
|
||||
type: integer
|
||||
lastRTT:
|
||||
description: TODO This shall be deleted once the operator
|
||||
is using the latest. Using Optional to avoid validation
|
||||
errors when this field is not used.
|
||||
format: int64
|
||||
type: integer
|
||||
maxRTT:
|
||||
format: int64
|
||||
type: integer
|
||||
minRTT:
|
||||
format: int64
|
||||
type: integer
|
||||
stddevRTT:
|
||||
format: int64
|
||||
type: integer
|
||||
type: object
|
||||
latencyRTT:
|
||||
description: LatencySpec describes the round trip time information
|
||||
for a packet between the gateway pods of two clusters.
|
||||
properties:
|
||||
average:
|
||||
type: string
|
||||
last:
|
||||
type: string
|
||||
max:
|
||||
type: string
|
||||
min:
|
||||
type: string
|
||||
stdDev:
|
||||
type: string
|
||||
type: object
|
||||
status:
|
||||
type: string
|
||||
statusMessage:
|
||||
type: string
|
||||
required:
|
||||
- endpoint
|
||||
- status
|
||||
- statusMessage
|
||||
type: object
|
||||
type: array
|
||||
haStatus:
|
||||
type: string
|
||||
localEndpoint:
|
||||
properties:
|
||||
backend:
|
||||
type: string
|
||||
backend_config:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
cable_name:
|
||||
type: string
|
||||
cluster_id:
|
||||
type: string
|
||||
healthCheckIP:
|
||||
type: string
|
||||
hostname:
|
||||
type: string
|
||||
nat_enabled:
|
||||
type: boolean
|
||||
private_ip:
|
||||
type: string
|
||||
public_ip:
|
||||
type: string
|
||||
subnets:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
required:
|
||||
- backend
|
||||
- cable_name
|
||||
- cluster_id
|
||||
- hostname
|
||||
- nat_enabled
|
||||
- private_ip
|
||||
- public_ip
|
||||
- subnets
|
||||
type: object
|
||||
statusFailure:
|
||||
type: string
|
||||
version:
|
||||
type: string
|
||||
required:
|
||||
- connections
|
||||
- haStatus
|
||||
- localEndpoint
|
||||
- statusFailure
|
||||
- version
|
||||
type: object
|
||||
required:
|
||||
- status
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources: {}
|
||||
status:
|
||||
acceptedNames:
|
||||
kind: ""
|
||||
plural: ""
|
||||
conditions: []
|
||||
storedVersions: []
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
|
||||
@@ -1,19 +1,20 @@
|
||||
---
|
||||
questions:
|
||||
- variable: submariner-k8s-broker.rbac.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Role Based Access Control"
|
||||
description: "Create the role/rolebinding for the Submariner client"
|
||||
label: "RBAC Creation Enabled"
|
||||
- variable: submariner-k8s-broker.crd.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Submariner CRD"
|
||||
description: "Create the submariner CRDs for the Submariner client"
|
||||
label: "Submariner CRD Creation Enabled"
|
||||
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Service Account"
|
||||
description: "Create the service account for the Submariner client"
|
||||
label: "Submariner Service Account Creation Enabled"
|
||||
- variable: submariner-k8s-broker.rbac.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Role Based Access Control"
|
||||
description: "Create the role/rolebinding for the Submariner client"
|
||||
label: "RBAC Creation Enabled"
|
||||
- variable: submariner-k8s-broker.crd.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Submariner CRD"
|
||||
description: "Create the submariner CRDs for the Submariner client"
|
||||
label: "Submariner CRD Creation Enabled"
|
||||
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Service Account"
|
||||
description: "Create the service account for the Submariner client"
|
||||
label: "Submariner Service Account Creation Enabled"
|
||||
|
||||
@@ -16,7 +16,7 @@ rules:
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
- apiGroups: ["discovery.k8s.io"]
|
||||
resources: ["endpointslices"]
|
||||
resources: ["endpointslices", "endpointslices/restricted"]
|
||||
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
|
||||
- apiGroups: ["multicluster.x-k8s.io"]
|
||||
resources: ["*"]
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
name: submariner-operator
|
||||
version: 0.7.0
|
||||
version: 0.10.1
|
||||
apiVersion: v2
|
||||
appVersion: 0.7.0
|
||||
appVersion: 0.10.1
|
||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# submariner-operator
|
||||
|
||||
 
|
||||
 
|
||||
|
||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
|
||||
@@ -27,8 +27,9 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
||||
| broker.token | string | `"test"` | |
|
||||
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
|
||||
| gateway.image.tag | string | `"0.7.0"` | |
|
||||
| gateway.image.tag | string | `"0.10.1"` | |
|
||||
| ipsec.debug | bool | `false` | |
|
||||
| ipsec.forceUDPEncaps | bool | `false` | |
|
||||
| ipsec.ikePort | int | `500` | |
|
||||
| ipsec.natPort | int | `4500` | |
|
||||
| ipsec.psk | string | `""` | |
|
||||
@@ -38,7 +39,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| operator.affinity | object | `{}` | |
|
||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
||||
| operator.image.tag | string | `"0.7.0"` | |
|
||||
| operator.image.tag | string | `"0.10.1"` | |
|
||||
| operator.resources | object | `{}` | |
|
||||
| operator.tolerations | list | `[]` | |
|
||||
| rbac.create | bool | `true` | |
|
||||
@@ -58,10 +59,12 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| submariner.clusterCidr | string | `""` | |
|
||||
| submariner.clusterId | string | `""` | |
|
||||
| submariner.colorCodes | string | `"blue"` | |
|
||||
| submariner.coreDNSCustomConfig | object | `{}` | |
|
||||
| submariner.debug | bool | `false` | |
|
||||
| submariner.globalCidr | string | `""` | |
|
||||
| submariner.healthcheckEnabled | bool | `true` | |
|
||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||
| submariner.images.tag | string | `"0.7.0"` | |
|
||||
| submariner.images.tag | string | `"0.10.1"` | |
|
||||
| submariner.natEnabled | bool | `false` | |
|
||||
| submariner.serviceCidr | string | `""` | |
|
||||
| submariner.serviceDiscovery | bool | `true` | |
|
||||
|
||||
+887
-760
File diff suppressed because it is too large
Load Diff
+141
-134
@@ -1,138 +1,145 @@
|
||||
---
|
||||
questions:
|
||||
- variable: defaultOperatorImage
|
||||
default: true
|
||||
description: "Use default Submariner operator image or specify a custom one"
|
||||
label: Use default Submariner operator image
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container Images"
|
||||
subquestions:
|
||||
- variable: operator.image.repository
|
||||
default: "quay.io/submariner/submariner-operator"
|
||||
description: "Submariner Operator Image Repository"
|
||||
type: string
|
||||
label: Submariner Operator Image Repository
|
||||
- variable: operator.image.tag
|
||||
default: "0.7.0"
|
||||
description: "Submariner Operator Image Tag"
|
||||
type: string
|
||||
label: Submariner Operator Image Tag
|
||||
- variable: defaultSubmarinerImages
|
||||
default: true
|
||||
description: "Use default Submariner images or specify custom ones"
|
||||
label: Use default Submariner images
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container images"
|
||||
subquestions:
|
||||
- variable: submariner.images.repository
|
||||
default: "quay.io/submariner"
|
||||
description: "Submariner Repository (base for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Repository
|
||||
- variable: submariner.images.tag
|
||||
default: "0.7.0"
|
||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Images Tag
|
||||
- variable: submariner.clusterId
|
||||
default: ""
|
||||
description: "Enter a unique cluster ID to identify this cluster"
|
||||
type: string
|
||||
label: "Cluster ID"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: ipsec.psk
|
||||
default: ""
|
||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
||||
type: string
|
||||
label: "IPsec Pre-Shared Key"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: broker.server
|
||||
type: string
|
||||
default: ""
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Server"
|
||||
description: "Broker server to use (without the https://)"
|
||||
- variable: broker.insecure
|
||||
type: boolean
|
||||
default: false
|
||||
show_subquestion_if: false
|
||||
group: "Broker Configuration"
|
||||
label: "Insecure Broker"
|
||||
description: "Connect to K8s broker without validating CA"
|
||||
subquestions:
|
||||
- variable: broker.ca
|
||||
type: string
|
||||
description: "Base64 encoded broker ca.crt"
|
||||
label: "Broker CA encoded in base64"
|
||||
- variable: defaultOperatorImage
|
||||
default: true
|
||||
description: "Use default Submariner operator image or specify a custom one"
|
||||
label: Use default Submariner operator image
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container Images"
|
||||
subquestions:
|
||||
- variable: operator.image.repository
|
||||
default: "quay.io/submariner/submariner-operator"
|
||||
description: "Submariner Operator Image Repository"
|
||||
type: string
|
||||
label: Submariner Operator Image Repository
|
||||
- variable: operator.image.tag
|
||||
default: "0.10.1"
|
||||
description: "Submariner Operator Image Tag"
|
||||
type: string
|
||||
label: Submariner Operator Image Tag
|
||||
- variable: defaultSubmarinerImages
|
||||
default: true
|
||||
description: "Use default Submariner images or specify custom ones"
|
||||
label: Use default Submariner images
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container images"
|
||||
subquestions:
|
||||
- variable: submariner.images.repository
|
||||
default: "quay.io/submariner"
|
||||
description: "Submariner Repository (base for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Repository
|
||||
- variable: submariner.images.tag
|
||||
default: "0.10.1"
|
||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Images Tag
|
||||
- variable: submariner.clusterId
|
||||
default: ""
|
||||
- variable: broker.token
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Token"
|
||||
description: "Bearer token for broker"
|
||||
- variable: broker.namespace
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Namespace"
|
||||
description: "Enter namespace to use on central broker"
|
||||
- variable: submariner.clusterCidr
|
||||
default: ""
|
||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Cluster CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.serviceCidr
|
||||
default: ""
|
||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Service CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.serviceDiscovery
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable multicluster service discovery"
|
||||
label: "Service Discovery Enabled"
|
||||
- variable: broker.globalnet
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Broker Configuration"
|
||||
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
|
||||
label: "Globalnet Enabled"
|
||||
subquestions:
|
||||
- variable: submariner.globalCidr
|
||||
default: ""
|
||||
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
|
||||
description: "Enter a unique cluster ID to identify this cluster"
|
||||
type: string
|
||||
label: "Globalnet CIDR"
|
||||
label: "Cluster ID"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: ipsec.psk
|
||||
default: ""
|
||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
||||
type: string
|
||||
label: "IPsec Pre-Shared Key"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: broker.server
|
||||
type: string
|
||||
default: ""
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Server"
|
||||
description: "Broker server to use (without the https://)"
|
||||
- variable: broker.insecure
|
||||
type: boolean
|
||||
default: false
|
||||
show_subquestion_if: false
|
||||
group: "Broker Configuration"
|
||||
label: "Insecure Broker"
|
||||
description: "Connect to K8s broker without validating CA"
|
||||
subquestions:
|
||||
- variable: broker.ca
|
||||
type: string
|
||||
description: "Base64 encoded broker ca.crt"
|
||||
label: "Broker CA encoded in base64"
|
||||
default: ""
|
||||
- variable: broker.token
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Token"
|
||||
description: "Bearer token for broker"
|
||||
- variable: broker.namespace
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Namespace"
|
||||
description: "Enter namespace to use on central broker"
|
||||
- variable: submariner.clusterCidr
|
||||
default: ""
|
||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Cluster CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: false
|
||||
- variable: submariner.natEnabled
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
||||
label: "NAT Enabled"
|
||||
- variable: submariner.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable submariner debug mode"
|
||||
label: "Submariner Debug Enabled"
|
||||
- variable: ipsec.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable Charon debug mode"
|
||||
label: "Charon Enabled"
|
||||
- variable: submariner.cableDriver
|
||||
type: string
|
||||
default: ""
|
||||
group: "Advanced Configuration"
|
||||
description: "Cable driver implementation"
|
||||
label: "Cable Driver"
|
||||
required: true
|
||||
- variable: submariner.serviceCidr
|
||||
default: ""
|
||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Service CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.serviceDiscovery
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable multicluster service discovery"
|
||||
label: "Service Discovery Enabled"
|
||||
- variable: broker.globalnet
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Broker Configuration"
|
||||
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
|
||||
label: "Globalnet Enabled"
|
||||
subquestions:
|
||||
- variable: submariner.globalCidr
|
||||
default: ""
|
||||
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
|
||||
type: string
|
||||
label: "Globalnet CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: false
|
||||
- variable: submariner.natEnabled
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
||||
label: "NAT Enabled"
|
||||
- variable: submariner.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable submariner debug mode"
|
||||
label: "Submariner Debug Enabled"
|
||||
- variable: ipsec.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable Charon debug mode"
|
||||
label: "Charon Enabled"
|
||||
- variable: submariner.cableDriver
|
||||
type: string
|
||||
default: ""
|
||||
group: "Advanced Configuration"
|
||||
description: "Cable driver implementation"
|
||||
label: "Cable Driver"
|
||||
- variable: submariner.healthcheckEnabled
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Advanced Configuration"
|
||||
description: "Disable Healthcheck"
|
||||
label: "Healthcheck Disabled"
|
||||
|
||||
@@ -439,6 +439,21 @@ rules:
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- namespaces
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -459,6 +474,29 @@ roleRef:
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: submariner-metrics-reader
|
||||
namespace: {{ .Release.Namespace }}
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["pods", "services", "endpoints"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: read-submariner-metrics
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: prometheus-k8s
|
||||
namespace: openshift-monitoring
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: submariner-metrics-reader
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:gateway
|
||||
@@ -640,14 +678,25 @@ rules:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- namespaces
|
||||
- nodes
|
||||
- endpoints
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- services
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
@@ -688,6 +737,15 @@ rules:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- network.openshift.io
|
||||
resources:
|
||||
- service/externalips
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- delete
|
||||
---
|
||||
{{- end -}}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
|
||||
@@ -9,7 +9,9 @@ spec:
|
||||
brokerK8sApiServerToken: {{ .Values.broker.token }}
|
||||
brokerK8sCA: {{ .Values.broker.ca }}
|
||||
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
|
||||
brokerK8sInsecure: {{ .Values.broker.insecure }}
|
||||
ceIPSecDebug: {{ .Values.ipsec.debug }}
|
||||
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
|
||||
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
|
||||
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
|
||||
ceIPSecPSK: {{ .Values.ipsec.psk }}
|
||||
@@ -25,3 +27,12 @@ spec:
|
||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||
cableDriver: {{ .Values.submariner.cableDriver }}
|
||||
connectionHealthCheck:
|
||||
enabled: {{ .Values.submariner.healthcheckEnabled }}
|
||||
intervalSeconds: 1
|
||||
maxPacketLossCount: 5
|
||||
{{- with .Values.submariner.coreDNSCustomConfig }}
|
||||
coreDNSCustomConfig:
|
||||
configmapName: {{ .configmapName }}
|
||||
namespace: {{ .namespace }}
|
||||
{{- end }}
|
||||
|
||||
@@ -10,9 +10,11 @@ submariner:
|
||||
debug: false
|
||||
serviceDiscovery: true
|
||||
cableDriver: "libreswan"
|
||||
healthcheckEnabled: true
|
||||
coreDNSCustomConfig: {}
|
||||
images:
|
||||
repository: quay.io/submariner
|
||||
tag: "0.7.0"
|
||||
tag: "0.10.1"
|
||||
broker:
|
||||
server: example.k8s.apiserver
|
||||
token: test
|
||||
@@ -25,6 +27,7 @@ rbac:
|
||||
ipsec:
|
||||
psk: ""
|
||||
debug: false
|
||||
forceUDPEncaps: false
|
||||
ikePort: 500
|
||||
natPort: 4500
|
||||
leadership:
|
||||
@@ -34,7 +37,7 @@ leadership:
|
||||
operator:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-operator
|
||||
tag: "0.7.0"
|
||||
tag: "0.10.1"
|
||||
pullPolicy: IfNotPresent
|
||||
resources: {}
|
||||
tolerations: []
|
||||
@@ -42,7 +45,7 @@ operator:
|
||||
gateway:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-gateway
|
||||
tag: "0.7.0"
|
||||
tag: "0.10.1"
|
||||
serviceAccounts:
|
||||
operator:
|
||||
create: true
|
||||
|
||||
Reference in New Issue
Block a user