mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-20 23:50:36 +00:00
Compare commits
12
Commits
v0.13.4
...
v0.14.0-m0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
883d93c0be | ||
|
|
414c72fc28 | ||
|
|
2f1cd8d728 | ||
|
|
d667fc2546 | ||
|
|
a1b5d7f20a | ||
|
|
85b746dd4c | ||
|
|
e6c1600270 | ||
|
|
9e5b80abda | ||
|
|
077c26b714 | ||
|
|
7f4648985e | ||
|
|
c605528741 | ||
|
|
d3a4507650 |
@@ -10,3 +10,8 @@ updates:
|
||||
target-branch: "release-0.12"
|
||||
schedule:
|
||||
interval: daily
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.13"
|
||||
schedule:
|
||||
interval: daily
|
||||
|
||||
@@ -16,11 +16,11 @@ jobs:
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
k8s_version: ['1.23']
|
||||
k8s_version: ['1.24']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
include:
|
||||
- k8s_version: '1.21'
|
||||
- k8s_version: '1.22'
|
||||
- k8s_version: '1.23'
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
|
||||
|
||||
@@ -44,12 +44,12 @@ jobs:
|
||||
version: v3.6.0
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@d09bd5e6005b175076f227b13d9730d56e9dcfcb
|
||||
uses: actions/setup-python@b55428b1882923874294fa556849718a1d7f2ca5
|
||||
with:
|
||||
python-version: '3.x'
|
||||
|
||||
- name: Set up helm/chart-testing
|
||||
uses: helm/chart-testing-action@dae259e86a35ff09145c0805e2d7dd3f7207064a
|
||||
uses: helm/chart-testing-action@09ed88797198755e5031f25be13da255e7e33aad
|
||||
|
||||
- name: Run helm/chart-testing (lint)
|
||||
run: ct lint --config ct.yaml
|
||||
|
||||
@@ -3,3 +3,4 @@
|
||||
.shflags
|
||||
*.tgz
|
||||
Makefile.dapper
|
||||
Dockerfile.*
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
---
|
||||
cni: ovn
|
||||
submariner: true
|
||||
nodes: control-plane worker worker
|
||||
nodes: control-plane
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
|
||||
+1
-1
@@ -1,7 +1,7 @@
|
||||
---
|
||||
cni: weave
|
||||
submariner: true
|
||||
nodes: control-plane worker
|
||||
nodes: control-plane
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
|
||||
@@ -1,18 +0,0 @@
|
||||
ARG BASE_BRANCH
|
||||
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH}
|
||||
|
||||
ARG DAPPER_HOST_ARCH
|
||||
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
|
||||
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
|
||||
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
|
||||
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
|
||||
|
||||
WORKDIR ${DAPPER_SOURCE}
|
||||
|
||||
RUN git config --global --add safe.directory ${DAPPER_SOURCE}
|
||||
|
||||
# Override the Helm deployment scripts
|
||||
COPY deploy_helm /opt/shipyard/scripts/lib/
|
||||
|
||||
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
|
||||
CMD ["sh"]
|
||||
@@ -1,5 +1,6 @@
|
||||
BASE_BRANCH ?= devel
|
||||
export BASE_BRANCH
|
||||
export HELM_REPO_LOCATION=.
|
||||
|
||||
ifneq (,$(DAPPER_HOST_ARCH))
|
||||
|
||||
@@ -10,30 +11,18 @@ PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent
|
||||
include $(SHIPYARD_DIR)/Makefile.inc
|
||||
|
||||
ifneq (,$(filter ovn,$(_using)))
|
||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||
else
|
||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||
endif
|
||||
|
||||
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
|
||||
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
|
||||
export DEPLOY_ARGS
|
||||
export DEPLOYTOOL = helm
|
||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||
CHARTS_DIR=charts
|
||||
CHARTS_VERSION=0.10.1
|
||||
CHARTS_VERSION=0.13.0-rc2
|
||||
HELM_DOCS_VERSION=0.15.0
|
||||
REPO_URL=$(shell git config remote.origin.url)
|
||||
|
||||
# Process extra flags from the `using=a,b,c` optional flag
|
||||
|
||||
ifneq (,$(filter lighthouse,$(_using)))
|
||||
override DEPLOY_ARGS += --service_discovery
|
||||
endif
|
||||
|
||||
ifneq (,$(filter globalnet,$(_using)))
|
||||
override DEPLOY_ARGS += --globalnet
|
||||
endif
|
||||
|
||||
# Targets to make
|
||||
|
||||
e2e: E2E_ARGS=cluster1 cluster2
|
||||
|
||||
-76
@@ -1,76 +0,0 @@
|
||||
# shellcheck shell=bash
|
||||
# shellcheck source=scripts/shared/lib/source_only
|
||||
. "${BASH_SOURCE%/*}"/source_only
|
||||
|
||||
### Constants ###
|
||||
|
||||
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
|
||||
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
|
||||
|
||||
### Functions ###
|
||||
|
||||
function deploytool_prereqs() {
|
||||
helm version
|
||||
}
|
||||
|
||||
function setup_broker() {
|
||||
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
|
||||
echo "Submariner CRDs already exist, skipping broker creation..."
|
||||
else
|
||||
echo "Installing submariner broker..."
|
||||
# shellcheck disable=SC2086 # Split on purpose
|
||||
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
|
||||
--create-namespace \
|
||||
--kube-context "${cluster}" \
|
||||
--namespace "${SUBMARINER_BROKER_NS}" \
|
||||
${deploytool_broker_args}
|
||||
fi
|
||||
|
||||
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
||||
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
|
||||
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
|
||||
}
|
||||
|
||||
function helm_install_subm() {
|
||||
local crd_create=false
|
||||
[[ "${cluster}" = "${broker}" ]] || crd_create=true
|
||||
|
||||
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
|
||||
echo "Submariner already installed, skipping installation..."
|
||||
return
|
||||
fi
|
||||
|
||||
echo "Installing Submariner..."
|
||||
# shellcheck disable=SC2086 # Split on purpose
|
||||
helm --kube-context "${cluster}" install submariner-operator \
|
||||
./submariner-operator \
|
||||
--create-namespace \
|
||||
--namespace "${SUBM_NS}" \
|
||||
--set ipsec.psk="${SUBMARINER_PSK}" \
|
||||
--set broker.server="${submariner_broker_url}" \
|
||||
--set broker.token="${submariner_broker_token}" \
|
||||
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
|
||||
--set broker.ca="${submariner_broker_ca}" \
|
||||
--set broker.globalnet="${globalnet}" \
|
||||
--set submariner.serviceDiscovery="${service_discovery}" \
|
||||
--set submariner.cableDriver="${cable_driver}" \
|
||||
--set submariner.clusterId="${cluster}" \
|
||||
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
|
||||
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
|
||||
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
|
||||
--set serviceAccounts.globalnet.create="${globalnet}" \
|
||||
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
|
||||
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
|
||||
--set submariner.natEnabled="false" \
|
||||
--set operator.image.repository="localhost:5000/submariner-operator" \
|
||||
--set operator.image.tag="local" \
|
||||
--set operator.image.pullPolicy="IfNotPresent" \
|
||||
--set submariner.images.repository="localhost:5000" \
|
||||
--set submariner.images.tag="local" \
|
||||
--set brokercrds.create="${crd_create}" \
|
||||
${deploytool_submariner_args}
|
||||
}
|
||||
|
||||
function install_subm_all_clusters() {
|
||||
run_subm_clusters helm_install_subm
|
||||
}
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
name: submariner-k8s-broker
|
||||
version: 0.6.0
|
||||
version: 0.13.0-rc2
|
||||
apiVersion: v2
|
||||
appVersion: 0.6.0
|
||||
appVersion: 0.13.0-rc2
|
||||
description: Submariner Kubernetes Broker
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# submariner-k8s-broker
|
||||
|
||||
 
|
||||
 
|
||||
|
||||
Submariner Kubernetes Broker
|
||||
|
||||
|
||||
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
|
||||
|
||||
The broker client token and CA can be retrieved by running
|
||||
|
||||
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
|
||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
|
||||
$ SUBMARINER_BROKER_CA=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
|
||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
|
||||
|
||||
@@ -8,4 +8,12 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||
app: {{ template "submariner-k8s-broker.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
name: submariner-operator
|
||||
version: 0.10.1
|
||||
version: 0.13.0-rc2
|
||||
apiVersion: v2
|
||||
appVersion: 0.10.1
|
||||
appVersion: 0.13.0-rc2
|
||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# submariner-operator
|
||||
|
||||
 
|
||||
 
|
||||
|
||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
|
||||
@@ -27,7 +27,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
||||
| broker.token | string | `"test"` | |
|
||||
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
|
||||
| gateway.image.tag | string | `"0.10.1"` | |
|
||||
| gateway.image.tag | string | `"0.13.0-rc2"` | |
|
||||
| ipsec.debug | bool | `false` | |
|
||||
| ipsec.forceUDPEncaps | bool | `false` | |
|
||||
| ipsec.ikePort | int | `500` | |
|
||||
@@ -39,7 +39,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| operator.affinity | object | `{}` | |
|
||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
||||
| operator.image.tag | string | `"0.10.1"` | |
|
||||
| operator.image.tag | string | `"0.13.0-rc2"` | |
|
||||
| operator.resources | object | `{}` | |
|
||||
| operator.tolerations | list | `[]` | |
|
||||
| rbac.create | bool | `true` | |
|
||||
@@ -64,7 +64,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| submariner.globalCidr | string | `""` | |
|
||||
| submariner.healthcheckEnabled | bool | `true` | |
|
||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||
| submariner.images.tag | string | `"0.10.1"` | |
|
||||
| submariner.images.tag | string | `"0.13.0-rc2"` | |
|
||||
| submariner.natEnabled | bool | `false` | |
|
||||
| submariner.serviceCidr | string | `""` | |
|
||||
| submariner.serviceDiscovery | bool | `true` | |
|
||||
|
||||
@@ -14,7 +14,7 @@ questions:
|
||||
type: string
|
||||
label: Submariner Operator Image Repository
|
||||
- variable: operator.image.tag
|
||||
default: "0.10.1"
|
||||
default: "0.13.0-rc2"
|
||||
description: "Submariner Operator Image Tag"
|
||||
type: string
|
||||
label: Submariner Operator Image Tag
|
||||
@@ -32,7 +32,7 @@ questions:
|
||||
type: string
|
||||
label: Submariner Repository
|
||||
- variable: submariner.images.tag
|
||||
default: "0.10.1"
|
||||
default: "0.13.0-rc2"
|
||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Images Tag
|
||||
|
||||
@@ -162,6 +162,17 @@ rules:
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
|
||||
@@ -8,6 +8,14 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.gateway.create }}
|
||||
@@ -20,6 +28,14 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
||||
@@ -32,6 +48,14 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.globalnet.create }}
|
||||
@@ -44,6 +68,14 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
|
||||
@@ -56,6 +88,14 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
|
||||
@@ -68,4 +108,12 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
|
||||
@@ -14,7 +14,7 @@ submariner:
|
||||
coreDNSCustomConfig: {}
|
||||
images:
|
||||
repository: quay.io/submariner
|
||||
tag: "0.10.1"
|
||||
tag: "0.13.0-rc2"
|
||||
broker:
|
||||
server: example.k8s.apiserver
|
||||
token: test
|
||||
@@ -37,7 +37,7 @@ leadership:
|
||||
operator:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-operator
|
||||
tag: "0.10.1"
|
||||
tag: "0.13.0-rc2"
|
||||
pullPolicy: IfNotPresent
|
||||
resources: {}
|
||||
tolerations: []
|
||||
@@ -45,7 +45,7 @@ operator:
|
||||
gateway:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-gateway
|
||||
tag: "0.10.1"
|
||||
tag: "0.13.0-rc2"
|
||||
serviceAccounts:
|
||||
operator:
|
||||
create: true
|
||||
|
||||
Reference in New Issue
Block a user