mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-21 18:30:34 +00:00
Compare commits
67
Commits
v0.13.2
...
v0.16.0-m0
+17
-2
@@ -4,9 +4,24 @@ updates:
|
|||||||
- package-ecosystem: github-actions
|
- package-ecosystem: github-actions
|
||||||
directory: '/'
|
directory: '/'
|
||||||
schedule:
|
schedule:
|
||||||
interval: daily
|
interval: monthly
|
||||||
- package-ecosystem: github-actions
|
- package-ecosystem: github-actions
|
||||||
directory: '/'
|
directory: '/'
|
||||||
target-branch: "release-0.12"
|
target-branch: "release-0.12"
|
||||||
schedule:
|
schedule:
|
||||||
interval: daily
|
interval: monthly
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.13"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.14"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.15"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ name: Branch Checks
|
|||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
target_branch:
|
target_branch:
|
||||||
name: PR targets branch
|
name: PR targets branch
|
||||||
|
|||||||
@@ -19,13 +19,18 @@ on:
|
|||||||
schedule:
|
schedule:
|
||||||
- cron: '0 0/6 * * *' # every 6 hours
|
- cron: '0 0/6 * * *' # every 6 hours
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
|
pull-requests: write
|
||||||
|
statuses: write
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
check:
|
check:
|
||||||
name: Check Dependencies
|
name: Check Dependencies
|
||||||
if: github.repository_owner == 'submariner-io'
|
if: github.repository_owner == 'submariner-io'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: z0al/dependent-issues@0fae07162bc9e0d8e116a133bd03686eed6efa21
|
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43
|
||||||
env:
|
env:
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ on:
|
|||||||
pull_request:
|
pull_request:
|
||||||
types: [labeled, opened, synchronize, reopened]
|
types: [labeled, opened, synchronize, reopened]
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
e2e:
|
e2e:
|
||||||
name: E2E
|
name: E2E
|
||||||
@@ -16,14 +18,15 @@ jobs:
|
|||||||
matrix:
|
matrix:
|
||||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||||
globalnet: ['', 'globalnet']
|
globalnet: ['', 'globalnet']
|
||||||
k8s_version: ['1.23']
|
k8s_version: ['1.25']
|
||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
include:
|
include:
|
||||||
- k8s_version: '1.21'
|
|
||||||
- k8s_version: '1.22'
|
- k8s_version: '1.22'
|
||||||
|
- k8s_version: '1.23'
|
||||||
|
- k8s_version: '1.24'
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ name: End to End Default
|
|||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
e2e:
|
e2e:
|
||||||
name: E2E
|
name: E2E
|
||||||
@@ -11,7 +13,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ on:
|
|||||||
schedule:
|
schedule:
|
||||||
- cron: "0 0 * * *"
|
- cron: "0 0 * * *"
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
e2e:
|
e2e:
|
||||||
name: E2E
|
name: E2E
|
||||||
@@ -19,7 +21,7 @@ jobs:
|
|||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ name: Linting
|
|||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
apply-suggestions-commits:
|
apply-suggestions-commits:
|
||||||
name: 'No "Apply suggestions from code review" Commits'
|
name: 'No "Apply suggestions from code review" Commits'
|
||||||
@@ -11,12 +13,12 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Get PR commits
|
- name: Get PR commits
|
||||||
id: 'get-pr-commits'
|
id: 'get-pr-commits'
|
||||||
uses: tim-actions/get-pr-commits@c64db31d359214d244884dd68f971a110b29ab83
|
uses: tim-actions/get-pr-commits@3efc1387ead42029a0d488ab98f24b7452dc3cde
|
||||||
with:
|
with:
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: 'Verify no "Apply suggestions from code review" commits'
|
- name: 'Verify no "Apply suggestions from code review" commits'
|
||||||
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
|
uses: tim-actions/commit-message-checker-with-regex@e16b08b1a7f5cafeb1f8167de05bf1d40239eb5d
|
||||||
with:
|
with:
|
||||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||||
pattern: '^(?!.*(apply suggestions from code review))'
|
pattern: '^(?!.*(apply suggestions from code review))'
|
||||||
@@ -24,7 +26,7 @@ jobs:
|
|||||||
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
||||||
|
|
||||||
- name: 'Verify no "fixup!" commits'
|
- name: 'Verify no "fixup!" commits'
|
||||||
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
|
uses: tim-actions/commit-message-checker-with-regex@e16b08b1a7f5cafeb1f8167de05bf1d40239eb5d
|
||||||
with:
|
with:
|
||||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||||
pattern: '^(?!fixup!)'
|
pattern: '^(?!fixup!)'
|
||||||
@@ -36,20 +38,23 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
|
|
||||||
- name: Set up Helm
|
- name: Set up Helm
|
||||||
uses: azure/setup-helm@217bf70cbd2e930ba2e81ba7e1de2f7faecc42ba
|
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78
|
||||||
with:
|
with:
|
||||||
version: v3.6.0
|
version: v3.6.0
|
||||||
|
|
||||||
- name: Set up Python
|
- name: Set up Python
|
||||||
uses: actions/setup-python@d09bd5e6005b175076f227b13d9730d56e9dcfcb
|
uses: actions/setup-python@bd6b4b6205c4dbad673328db7b31b7fab9e241c0
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
|
|
||||||
- name: Set up helm/chart-testing
|
- name: Set up helm/chart-testing
|
||||||
uses: helm/chart-testing-action@dae259e86a35ff09145c0805e2d7dd3f7207064a
|
uses: helm/chart-testing-action@e8788873172cb653a90ca2e819d79d65a66d4e76
|
||||||
|
|
||||||
|
- name: Set up local helm repo
|
||||||
|
run: make local-helm-repo
|
||||||
|
|
||||||
- name: Run helm/chart-testing (lint)
|
- name: Run helm/chart-testing (lint)
|
||||||
run: ct lint --config ct.yaml
|
run: ct lint --config ct.yaml
|
||||||
@@ -59,7 +64,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- name: Run gitlint
|
- name: Run gitlint
|
||||||
@@ -70,7 +75,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
|
|
||||||
- name: Run helm-docs and verify docs are up-to-date
|
- name: Run helm-docs and verify docs are up-to-date
|
||||||
run: make helm-docs
|
run: make helm-docs
|
||||||
@@ -80,10 +85,10 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f
|
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
check-modified-files-only: "yes"
|
check-modified-files-only: "yes"
|
||||||
@@ -94,7 +99,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
- name: Run markdownlint
|
- name: Run markdownlint
|
||||||
run: make markdownlint
|
run: make markdownlint
|
||||||
|
|
||||||
@@ -103,6 +108,6 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
- name: Run yamllint
|
- name: Run yamllint
|
||||||
run: make yamllint
|
run: make yamllint
|
||||||
|
|||||||
@@ -5,23 +5,27 @@ on:
|
|||||||
schedule:
|
schedule:
|
||||||
- cron: "0 0 * * 0"
|
- cron: "0 0 * * 0"
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
markdown-link-check-periodic:
|
markdown-link-check-periodic:
|
||||||
name: Markdown Links (all files)
|
name: Markdown Links (all files)
|
||||||
if: github.repository_owner == 'submariner-io'
|
if: github.repository_owner == 'submariner-io'
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f
|
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
|
|
||||||
- name: Raise an Issue to report broken links
|
- name: Raise an Issue to report broken links
|
||||||
if: ${{ failure() }}
|
if: ${{ failure() }}
|
||||||
uses: peter-evans/create-issue-from-file@99b87c35610e986ad2034a7b0518a9b3ebea541b
|
uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f
|
||||||
with:
|
with:
|
||||||
title: Broken link detected by CI
|
title: Broken link detected by CI
|
||||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||||
|
|||||||
@@ -6,6 +6,9 @@ on:
|
|||||||
branches:
|
branches:
|
||||||
- devel
|
- devel
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
release:
|
release:
|
||||||
name: Release
|
name: Release
|
||||||
@@ -13,7 +16,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
|
|||||||
@@ -3,3 +3,5 @@
|
|||||||
.shflags
|
.shflags
|
||||||
*.tgz
|
*.tgz
|
||||||
Makefile.dapper
|
Makefile.dapper
|
||||||
|
Dockerfile.*
|
||||||
|
helm_repo
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
cni: ovn
|
cni: ovn
|
||||||
submariner: true
|
submariner: true
|
||||||
nodes: control-plane worker worker
|
nodes: control-plane
|
||||||
clusters:
|
clusters:
|
||||||
cluster1:
|
cluster1:
|
||||||
cluster2:
|
cluster2:
|
||||||
|
|||||||
+1
-2
@@ -1,7 +1,6 @@
|
|||||||
---
|
---
|
||||||
cni: weave
|
|
||||||
submariner: true
|
submariner: true
|
||||||
nodes: control-plane worker
|
nodes: control-plane
|
||||||
clusters:
|
clusters:
|
||||||
cluster1:
|
cluster1:
|
||||||
cluster2:
|
cluster2:
|
||||||
|
|||||||
@@ -1,18 +0,0 @@
|
|||||||
ARG BASE_BRANCH
|
|
||||||
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH}
|
|
||||||
|
|
||||||
ARG DAPPER_HOST_ARCH
|
|
||||||
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
|
|
||||||
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
|
|
||||||
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
|
|
||||||
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
|
|
||||||
|
|
||||||
WORKDIR ${DAPPER_SOURCE}
|
|
||||||
|
|
||||||
RUN git config --global --add safe.directory ${DAPPER_SOURCE}
|
|
||||||
|
|
||||||
# Override the Helm deployment scripts
|
|
||||||
COPY deploy_helm /opt/shipyard/scripts/lib/
|
|
||||||
|
|
||||||
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
|
|
||||||
CMD ["sh"]
|
|
||||||
@@ -1,46 +1,42 @@
|
|||||||
BASE_BRANCH ?= devel
|
BASE_BRANCH ?= devel
|
||||||
export BASE_BRANCH
|
export BASE_BRANCH
|
||||||
|
export HELM_REPO_LOCATION=./helm_repo
|
||||||
|
|
||||||
ifneq (,$(DAPPER_HOST_ARCH))
|
ifneq (,$(DAPPER_HOST_ARCH))
|
||||||
|
|
||||||
# Running in Dapper
|
# Running in Dapper
|
||||||
|
|
||||||
PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent lighthouse-agent lighthouse-coredns
|
|
||||||
|
|
||||||
include $(SHIPYARD_DIR)/Makefile.inc
|
include $(SHIPYARD_DIR)/Makefile.inc
|
||||||
|
|
||||||
ifneq (,$(filter ovn,$(_using)))
|
ifneq (,$(filter ovn,$(_using)))
|
||||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||||
else
|
else
|
||||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||||
endif
|
endif
|
||||||
|
|
||||||
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
|
export DEPLOYTOOL = helm
|
||||||
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
|
|
||||||
export DEPLOY_ARGS
|
|
||||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||||
CHARTS_DIR=charts
|
CHARTS_DIR=charts
|
||||||
CHARTS_VERSION=0.10.1
|
CHARTS_VERSION=0.16.0-m0
|
||||||
HELM_DOCS_VERSION=0.15.0
|
HELM_DOCS_VERSION=0.15.0
|
||||||
REPO_URL=$(shell git config remote.origin.url)
|
REPO_URL=$(shell git config remote.origin.url)
|
||||||
|
|
||||||
# Process extra flags from the `using=a,b,c` optional flag
|
|
||||||
|
|
||||||
ifneq (,$(filter lighthouse,$(_using)))
|
|
||||||
override DEPLOY_ARGS += --service_discovery
|
|
||||||
endif
|
|
||||||
|
|
||||||
ifneq (,$(filter globalnet,$(_using)))
|
|
||||||
override DEPLOY_ARGS += --globalnet
|
|
||||||
endif
|
|
||||||
|
|
||||||
# Targets to make
|
# Targets to make
|
||||||
|
|
||||||
e2e: E2E_ARGS=cluster1 cluster2
|
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||||
|
|
||||||
|
local-helm-repo: $(CHART_PACKAGES)
|
||||||
|
mkdir -p $(HELM_REPO_LOCATION)
|
||||||
|
for archive in $^; do \
|
||||||
|
tar xzf $$archive -C $(HELM_REPO_LOCATION); \
|
||||||
|
done
|
||||||
|
|
||||||
|
e2e: local-helm-repo
|
||||||
|
$(SCRIPTS_DIR)/e2e.sh
|
||||||
|
|
||||||
%.tgz:
|
%.tgz:
|
||||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
|
|
||||||
helm-docs:
|
helm-docs:
|
||||||
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
||||||
@@ -56,7 +52,7 @@ helm-docs:
|
|||||||
exit 1; \
|
exit 1; \
|
||||||
fi
|
fi
|
||||||
|
|
||||||
release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
release: $(CHART_PACKAGES)
|
||||||
git checkout gh-pages
|
git checkout gh-pages
|
||||||
mv *.tgz $(CHARTS_DIR)
|
mv *.tgz $(CHARTS_DIR)
|
||||||
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
charts:
|
charts:
|
||||||
- submariner-operator
|
- ./helm_repo/submariner-operator
|
||||||
- submariner-k8s-broker
|
- ./helm_repo/submariner-k8s-broker
|
||||||
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
||||||
# See: https://github.com/helm/chart-testing/issues/192
|
# See: https://github.com/helm/chart-testing/issues/192
|
||||||
validate-maintainers: false
|
validate-maintainers: false
|
||||||
|
|||||||
-76
@@ -1,76 +0,0 @@
|
|||||||
# shellcheck shell=bash
|
|
||||||
# shellcheck source=scripts/shared/lib/source_only
|
|
||||||
. "${BASH_SOURCE%/*}"/source_only
|
|
||||||
|
|
||||||
### Constants ###
|
|
||||||
|
|
||||||
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
|
|
||||||
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
|
|
||||||
|
|
||||||
### Functions ###
|
|
||||||
|
|
||||||
function deploytool_prereqs() {
|
|
||||||
helm version
|
|
||||||
}
|
|
||||||
|
|
||||||
function setup_broker() {
|
|
||||||
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
|
|
||||||
echo "Submariner CRDs already exist, skipping broker creation..."
|
|
||||||
else
|
|
||||||
echo "Installing submariner broker..."
|
|
||||||
# shellcheck disable=SC2086 # Split on purpose
|
|
||||||
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
|
|
||||||
--create-namespace \
|
|
||||||
--kube-context "${cluster}" \
|
|
||||||
--namespace "${SUBMARINER_BROKER_NS}" \
|
|
||||||
${deploytool_broker_args}
|
|
||||||
fi
|
|
||||||
|
|
||||||
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
|
||||||
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
|
|
||||||
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
|
|
||||||
}
|
|
||||||
|
|
||||||
function helm_install_subm() {
|
|
||||||
local crd_create=false
|
|
||||||
[[ "${cluster}" = "${broker}" ]] || crd_create=true
|
|
||||||
|
|
||||||
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
|
|
||||||
echo "Submariner already installed, skipping installation..."
|
|
||||||
return
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "Installing Submariner..."
|
|
||||||
# shellcheck disable=SC2086 # Split on purpose
|
|
||||||
helm --kube-context "${cluster}" install submariner-operator \
|
|
||||||
./submariner-operator \
|
|
||||||
--create-namespace \
|
|
||||||
--namespace "${SUBM_NS}" \
|
|
||||||
--set ipsec.psk="${SUBMARINER_PSK}" \
|
|
||||||
--set broker.server="${submariner_broker_url}" \
|
|
||||||
--set broker.token="${submariner_broker_token}" \
|
|
||||||
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
|
|
||||||
--set broker.ca="${submariner_broker_ca}" \
|
|
||||||
--set broker.globalnet="${globalnet}" \
|
|
||||||
--set submariner.serviceDiscovery="${service_discovery}" \
|
|
||||||
--set submariner.cableDriver="${cable_driver}" \
|
|
||||||
--set submariner.clusterId="${cluster}" \
|
|
||||||
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
|
|
||||||
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
|
|
||||||
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
|
|
||||||
--set serviceAccounts.globalnet.create="${globalnet}" \
|
|
||||||
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
|
|
||||||
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
|
|
||||||
--set submariner.natEnabled="false" \
|
|
||||||
--set operator.image.repository="localhost:5000/submariner-operator" \
|
|
||||||
--set operator.image.tag="local" \
|
|
||||||
--set operator.image.pullPolicy="IfNotPresent" \
|
|
||||||
--set submariner.images.repository="localhost:5000" \
|
|
||||||
--set submariner.images.tag="local" \
|
|
||||||
--set brokercrds.create="${crd_create}" \
|
|
||||||
${deploytool_submariner_args}
|
|
||||||
}
|
|
||||||
|
|
||||||
function install_subm_all_clusters() {
|
|
||||||
run_subm_clusters helm_install_subm
|
|
||||||
}
|
|
||||||
@@ -1,8 +1,7 @@
|
|||||||
---
|
---
|
||||||
name: submariner-k8s-broker
|
name: submariner-k8s-broker
|
||||||
version: 0.6.0
|
version: 0.0.0
|
||||||
apiVersion: v2
|
apiVersion: v2
|
||||||
appVersion: 0.6.0
|
|
||||||
description: Submariner Kubernetes Broker
|
description: Submariner Kubernetes Broker
|
||||||
keywords:
|
keywords:
|
||||||
home: https://submariner-io.github.io/
|
home: https://submariner-io.github.io/
|
||||||
|
|||||||
@@ -1,7 +1,5 @@
|
|||||||
# submariner-k8s-broker
|
# submariner-k8s-broker
|
||||||
|
|
||||||
 
|
|
||||||
|
|
||||||
Submariner Kubernetes Broker
|
Submariner Kubernetes Broker
|
||||||
|
|
||||||
**Homepage:** <https://submariner-io.github.io/>
|
**Homepage:** <https://submariner-io.github.io/>
|
||||||
|
|||||||
@@ -1,20 +0,0 @@
|
|||||||
---
|
|
||||||
questions:
|
|
||||||
- variable: submariner-k8s-broker.rbac.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Role Based Access Control"
|
|
||||||
description: "Create the role/rolebinding for the Submariner client"
|
|
||||||
label: "RBAC Creation Enabled"
|
|
||||||
- variable: submariner-k8s-broker.crd.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Submariner CRD"
|
|
||||||
description: "Create the submariner CRDs for the Submariner client"
|
|
||||||
label: "Submariner CRD Creation Enabled"
|
|
||||||
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Service Account"
|
|
||||||
description: "Create the service account for the Submariner client"
|
|
||||||
label: "Submariner Service Account Creation Enabled"
|
|
||||||
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
|
|||||||
|
|
||||||
The broker client token and CA can be retrieved by running
|
The broker client token and CA can be retrieved by running
|
||||||
|
|
||||||
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
|
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
|
||||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
|
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
|
||||||
|
|||||||
@@ -8,4 +8,12 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||||
app: {{ template "submariner-k8s-broker.name" . }}
|
app: {{ template "submariner-k8s-broker.name" . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -1,8 +1,7 @@
|
|||||||
---
|
---
|
||||||
name: submariner-operator
|
name: submariner-operator
|
||||||
version: 0.10.1
|
version: 0.0.0
|
||||||
apiVersion: v2
|
apiVersion: v2
|
||||||
appVersion: 0.10.1
|
|
||||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||||
keywords:
|
keywords:
|
||||||
home: https://submariner-io.github.io/
|
home: https://submariner-io.github.io/
|
||||||
|
|||||||
@@ -1,7 +1,5 @@
|
|||||||
# submariner-operator
|
# submariner-operator
|
||||||
|
|
||||||
 
|
|
||||||
|
|
||||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||||
|
|
||||||
**Homepage:** <https://submariner-io.github.io/>
|
**Homepage:** <https://submariner-io.github.io/>
|
||||||
@@ -26,8 +24,6 @@ Submariner enables direct networking between Pods and Services in different Kube
|
|||||||
| broker.namespace | string | `"xyz"` | |
|
| broker.namespace | string | `"xyz"` | |
|
||||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
| broker.server | string | `"example.k8s.apiserver"` | |
|
||||||
| broker.token | string | `"test"` | |
|
| broker.token | string | `"test"` | |
|
||||||
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
|
|
||||||
| gateway.image.tag | string | `"0.10.1"` | |
|
|
||||||
| ipsec.debug | bool | `false` | |
|
| ipsec.debug | bool | `false` | |
|
||||||
| ipsec.forceUDPEncaps | bool | `false` | |
|
| ipsec.forceUDPEncaps | bool | `false` | |
|
||||||
| ipsec.ikePort | int | `500` | |
|
| ipsec.ikePort | int | `500` | |
|
||||||
@@ -39,7 +35,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
|||||||
| operator.affinity | object | `{}` | |
|
| operator.affinity | object | `{}` | |
|
||||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
||||||
| operator.image.tag | string | `"0.10.1"` | |
|
| operator.image.tag | string | `"0.14.0"` | |
|
||||||
| operator.resources | object | `{}` | |
|
| operator.resources | object | `{}` | |
|
||||||
| operator.tolerations | list | `[]` | |
|
| operator.tolerations | list | `[]` | |
|
||||||
| rbac.create | bool | `true` | |
|
| rbac.create | bool | `true` | |
|
||||||
@@ -64,7 +60,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
|||||||
| submariner.globalCidr | string | `""` | |
|
| submariner.globalCidr | string | `""` | |
|
||||||
| submariner.healthcheckEnabled | bool | `true` | |
|
| submariner.healthcheckEnabled | bool | `true` | |
|
||||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||||
| submariner.images.tag | string | `"0.10.1"` | |
|
| submariner.images.tag | string | `"0.14.0"` | |
|
||||||
| submariner.natEnabled | bool | `false` | |
|
| submariner.natEnabled | bool | `false` | |
|
||||||
| submariner.serviceCidr | string | `""` | |
|
| submariner.serviceCidr | string | `""` | |
|
||||||
| submariner.serviceDiscovery | bool | `true` | |
|
| submariner.serviceDiscovery | bool | `true` | |
|
||||||
|
|||||||
@@ -1,145 +0,0 @@
|
|||||||
---
|
|
||||||
questions:
|
|
||||||
- variable: defaultOperatorImage
|
|
||||||
default: true
|
|
||||||
description: "Use default Submariner operator image or specify a custom one"
|
|
||||||
label: Use default Submariner operator image
|
|
||||||
type: boolean
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Container Images"
|
|
||||||
subquestions:
|
|
||||||
- variable: operator.image.repository
|
|
||||||
default: "quay.io/submariner/submariner-operator"
|
|
||||||
description: "Submariner Operator Image Repository"
|
|
||||||
type: string
|
|
||||||
label: Submariner Operator Image Repository
|
|
||||||
- variable: operator.image.tag
|
|
||||||
default: "0.10.1"
|
|
||||||
description: "Submariner Operator Image Tag"
|
|
||||||
type: string
|
|
||||||
label: Submariner Operator Image Tag
|
|
||||||
- variable: defaultSubmarinerImages
|
|
||||||
default: true
|
|
||||||
description: "Use default Submariner images or specify custom ones"
|
|
||||||
label: Use default Submariner images
|
|
||||||
type: boolean
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Container images"
|
|
||||||
subquestions:
|
|
||||||
- variable: submariner.images.repository
|
|
||||||
default: "quay.io/submariner"
|
|
||||||
description: "Submariner Repository (base for all non-operator images)"
|
|
||||||
type: string
|
|
||||||
label: Submariner Repository
|
|
||||||
- variable: submariner.images.tag
|
|
||||||
default: "0.10.1"
|
|
||||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
|
||||||
type: string
|
|
||||||
label: Submariner Images Tag
|
|
||||||
- variable: submariner.clusterId
|
|
||||||
default: ""
|
|
||||||
description: "Enter a unique cluster ID to identify this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Cluster ID"
|
|
||||||
group: "Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: ipsec.psk
|
|
||||||
default: ""
|
|
||||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
|
||||||
type: string
|
|
||||||
label: "IPsec Pre-Shared Key"
|
|
||||||
group: "Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: broker.server
|
|
||||||
type: string
|
|
||||||
default: ""
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Server"
|
|
||||||
description: "Broker server to use (without the https://)"
|
|
||||||
- variable: broker.insecure
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
show_subquestion_if: false
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Insecure Broker"
|
|
||||||
description: "Connect to K8s broker without validating CA"
|
|
||||||
subquestions:
|
|
||||||
- variable: broker.ca
|
|
||||||
type: string
|
|
||||||
description: "Base64 encoded broker ca.crt"
|
|
||||||
label: "Broker CA encoded in base64"
|
|
||||||
default: ""
|
|
||||||
- variable: broker.token
|
|
||||||
type: string
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Token"
|
|
||||||
description: "Bearer token for broker"
|
|
||||||
- variable: broker.namespace
|
|
||||||
type: string
|
|
||||||
group: "Broker Configuration"
|
|
||||||
label: "Broker Namespace"
|
|
||||||
description: "Enter namespace to use on central broker"
|
|
||||||
- variable: submariner.clusterCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Cluster CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: submariner.serviceCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
|
||||||
type: string
|
|
||||||
label: "Service CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: true
|
|
||||||
- variable: submariner.serviceDiscovery
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable multicluster service discovery"
|
|
||||||
label: "Service Discovery Enabled"
|
|
||||||
- variable: broker.globalnet
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Broker Configuration"
|
|
||||||
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
|
|
||||||
label: "Globalnet Enabled"
|
|
||||||
subquestions:
|
|
||||||
- variable: submariner.globalCidr
|
|
||||||
default: ""
|
|
||||||
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
|
|
||||||
type: string
|
|
||||||
label: "Globalnet CIDR"
|
|
||||||
group: "CIDR Configuration"
|
|
||||||
required: false
|
|
||||||
- variable: submariner.natEnabled
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
|
||||||
label: "NAT Enabled"
|
|
||||||
- variable: submariner.debug
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable submariner debug mode"
|
|
||||||
label: "Submariner Debug Enabled"
|
|
||||||
- variable: ipsec.debug
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Enable Charon debug mode"
|
|
||||||
label: "Charon Enabled"
|
|
||||||
- variable: submariner.cableDriver
|
|
||||||
type: string
|
|
||||||
default: ""
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Cable driver implementation"
|
|
||||||
label: "Cable Driver"
|
|
||||||
- variable: submariner.healthcheckEnabled
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
group: "Advanced Configuration"
|
|
||||||
description: "Disable Healthcheck"
|
|
||||||
label: "Healthcheck Disabled"
|
|
||||||
@@ -1,7 +1,3 @@
|
|||||||
Submariner is now installed.
|
Submariner is now installed.
|
||||||
|
|
||||||
{{- if .Values.gateway.nodeSelectorEnabled }}
|
|
||||||
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||||
@@ -162,6 +162,17 @@ rules:
|
|||||||
- patch
|
- patch
|
||||||
- update
|
- update
|
||||||
- watch
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- coordination.k8s.io
|
||||||
|
resources:
|
||||||
|
- leases
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
@@ -454,6 +465,14 @@ rules:
|
|||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- create
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- daemonsets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
@@ -680,7 +699,6 @@ rules:
|
|||||||
- pods
|
- pods
|
||||||
- namespaces
|
- namespaces
|
||||||
- nodes
|
- nodes
|
||||||
- endpoints
|
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
@@ -690,6 +708,7 @@ rules:
|
|||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
- services
|
- services
|
||||||
|
- endpoints
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
- get
|
- get
|
||||||
@@ -710,17 +729,11 @@ rules:
|
|||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- clusterglobalegressips
|
- clusterglobalegressips
|
||||||
|
- clusterglobalegressips/status
|
||||||
- globalegressips
|
- globalegressips
|
||||||
verbs:
|
- globalegressips/status
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- globalingressips
|
- globalingressips
|
||||||
|
- globalingressips/status
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
- get
|
- get
|
||||||
@@ -868,21 +881,11 @@ rules:
|
|||||||
- update
|
- update
|
||||||
- delete
|
- delete
|
||||||
- deletecollection
|
- deletecollection
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- "*"
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- "gateways"
|
- "gateways"
|
||||||
|
- "submariners"
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
|
|||||||
@@ -19,10 +19,37 @@ spec:
|
|||||||
clusterID: {{ .Values.submariner.clusterId }}
|
clusterID: {{ .Values.submariner.clusterId }}
|
||||||
colorCodes: {{ .Values.submariner.colorCodes }}
|
colorCodes: {{ .Values.submariner.colorCodes }}
|
||||||
debug: {{ .Values.submariner.debug }}
|
debug: {{ .Values.submariner.debug }}
|
||||||
|
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
natEnabled: {{ .Values.submariner.natEnabled }}
|
natEnabled: {{ .Values.submariner.natEnabled }}
|
||||||
repository: {{ .Values.submariner.images.repository }}
|
repository: {{ .Values.submariner.images.repository }}
|
||||||
version: {{ .Values.submariner.images.tag }}
|
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }}
|
||||||
|
{{- with .Values.images }}
|
||||||
|
{{- if . }}
|
||||||
|
imageOverrides:
|
||||||
|
{{- if index . "submariner-operator" }}
|
||||||
|
submariner-operator: {{ index . "submariner-operator" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-gateway" }}
|
||||||
|
submariner-gateway: {{ index . "submariner-gateway" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-route-agent" }}
|
||||||
|
submariner-routeagent: {{ index . "submariner-route-agent" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-globalnet" }}
|
||||||
|
submariner-globalnet: {{ index . "submariner-globalnet" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "submariner-networkplugin-syncer" }}
|
||||||
|
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "lighthouse-agent" }}
|
||||||
|
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if index . "lighthouse-coredns" }}
|
||||||
|
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
||||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||||
@@ -33,6 +60,6 @@ spec:
|
|||||||
maxPacketLossCount: 5
|
maxPacketLossCount: 5
|
||||||
{{- with .Values.submariner.coreDNSCustomConfig }}
|
{{- with .Values.submariner.coreDNSCustomConfig }}
|
||||||
coreDNSCustomConfig:
|
coreDNSCustomConfig:
|
||||||
configmapName: {{ .configmapName }}
|
configMapName: {{ .configMapName }}
|
||||||
namespace: {{ .namespace }}
|
namespace: {{ .namespace }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -8,6 +8,14 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.operatorServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
{{- end }}
|
||||||
---
|
---
|
||||||
{{- if .Values.serviceAccounts.gateway.create }}
|
{{- if .Values.serviceAccounts.gateway.create }}
|
||||||
@@ -20,6 +28,14 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
{{- end }}
|
||||||
---
|
---
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
{{- if .Values.serviceAccounts.routeAgent.create }}
|
||||||
@@ -32,6 +48,14 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
{{- end }}
|
||||||
---
|
---
|
||||||
{{- if .Values.serviceAccounts.globalnet.create }}
|
{{- if .Values.serviceAccounts.globalnet.create }}
|
||||||
@@ -44,6 +68,14 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
{{- end }}
|
||||||
---
|
---
|
||||||
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
|
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
|
||||||
@@ -56,6 +88,14 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
{{- end }}
|
||||||
---
|
---
|
||||||
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
|
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
|
||||||
@@ -68,4 +108,12 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
||||||
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ submariner:
|
|||||||
clusterCidr: ""
|
clusterCidr: ""
|
||||||
serviceCidr: ""
|
serviceCidr: ""
|
||||||
globalCidr: ""
|
globalCidr: ""
|
||||||
|
loadBalancerEnabled: false
|
||||||
natEnabled: false
|
natEnabled: false
|
||||||
colorCodes: blue
|
colorCodes: blue
|
||||||
debug: false
|
debug: false
|
||||||
@@ -14,7 +15,7 @@ submariner:
|
|||||||
coreDNSCustomConfig: {}
|
coreDNSCustomConfig: {}
|
||||||
images:
|
images:
|
||||||
repository: quay.io/submariner
|
repository: quay.io/submariner
|
||||||
tag: "0.10.1"
|
tag: ""
|
||||||
broker:
|
broker:
|
||||||
server: example.k8s.apiserver
|
server: example.k8s.apiserver
|
||||||
token: test
|
token: test
|
||||||
@@ -24,6 +25,7 @@ broker:
|
|||||||
globalnet: false
|
globalnet: false
|
||||||
rbac:
|
rbac:
|
||||||
create: true
|
create: true
|
||||||
|
images: {}
|
||||||
ipsec:
|
ipsec:
|
||||||
psk: ""
|
psk: ""
|
||||||
debug: false
|
debug: false
|
||||||
@@ -37,15 +39,11 @@ leadership:
|
|||||||
operator:
|
operator:
|
||||||
image:
|
image:
|
||||||
repository: quay.io/submariner/submariner-operator
|
repository: quay.io/submariner/submariner-operator
|
||||||
tag: "0.10.1"
|
tag: ""
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
resources: {}
|
resources: {}
|
||||||
tolerations: []
|
tolerations: []
|
||||||
affinity: {}
|
affinity: {}
|
||||||
gateway:
|
|
||||||
image:
|
|
||||||
repository: quay.io/submariner/submariner-gateway
|
|
||||||
tag: "0.10.1"
|
|
||||||
serviceAccounts:
|
serviceAccounts:
|
||||||
operator:
|
operator:
|
||||||
create: true
|
create: true
|
||||||
|
|||||||
Reference in New Issue
Block a user