Compare commits

..
1 Commits
Author SHA1 Message Date
Automated Release 33cb49c54e Update base image to use stable branch 'release-0.10'
Signed-off-by: Automated Release <release@submariner.io>
2021-08-09 16:29:36 +00:00
39 changed files with 1144 additions and 1630 deletions
-17
View File
@@ -1,17 +0,0 @@
---
version: 2
updates:
- package-ecosystem: github-actions
directory: '/'
schedule:
interval: weekly
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.12"
schedule:
interval: weekly
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.13"
schedule:
interval: weekly
+4 -6
View File
@@ -4,13 +4,11 @@ name: Branch Checks
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
target_branch: target_devel:
name: PR targets branch name: PR targets release-0.10
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check that the PR targets devel - name: Check that the PR targets release-0.10
if: ${{ github.base_ref != 'devel' }} if: ${{ github.base_ref != 'release-0.10' }}
run: exit 1 run: exit 1
+1 -7
View File
@@ -19,18 +19,12 @@ on:
schedule: schedule:
- cron: '0 0/6 * * *' # every 6 hours - cron: '0 0/6 * * *' # every 6 hours
permissions:
issues: write
pull-requests: write
statuses: write
jobs: jobs:
check: check:
name: Check Dependencies name: Check Dependencies
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: z0al/dependent-issues@0fae07162bc9e0d8e116a133bd03686eed6efa21 - uses: z0al/dependent-issues@70a1b2d4ee1cdc743af33498bd0204123953a887
env: env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with: with:
+7 -9
View File
@@ -5,8 +5,6 @@ on:
pull_request: pull_request:
types: [labeled, opened, synchronize, reopened] types: [labeled, opened, synchronize, reopened]
permissions: {}
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
@@ -18,22 +16,22 @@ jobs:
matrix: matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan'] cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet'] globalnet: ['', 'globalnet']
k8s_version: ['1.25'] k8s_version: ['1.17']
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
include: include:
- k8s_version: '1.22' - k8s_version: '1.18'
- k8s_version: '1.23' - k8s_version: '1.19'
- k8s_version: '1.24' - k8s_version: '1.20'
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel uses: submariner-io/shipyard/gh-actions/e2e@release-0.10
with: with:
k8s_version: ${{ matrix.k8s_version }} k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.10
+3 -5
View File
@@ -4,8 +4,6 @@ name: End to End Default
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
@@ -13,11 +11,11 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel uses: submariner-io/shipyard/gh-actions/e2e@release-0.10
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.10
+3 -5
View File
@@ -5,8 +5,6 @@ on:
schedule: schedule:
- cron: "0 0 * * *" - cron: "0 0 * * *"
permissions: {}
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
@@ -21,13 +19,13 @@ jobs:
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel uses: submariner-io/shipyard/gh-actions/e2e@release-0.10
with: with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.10
+16 -23
View File
@@ -4,8 +4,6 @@ name: Linting
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
apply-suggestions-commits: apply-suggestions-commits:
name: 'No "Apply suggestions from code review" Commits' name: 'No "Apply suggestions from code review" Commits'
@@ -13,45 +11,37 @@ jobs:
steps: steps:
- name: Get PR commits - name: Get PR commits
id: 'get-pr-commits' id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@c64db31d359214d244884dd68f971a110b29ab83 uses: tim-actions/get-pr-commits@v1.1.0
with: with:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
- name: 'Verify no "Apply suggestions from code review" commits' - name: 'Verify no "Apply suggestions from code review" commits'
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd uses: tim-actions/commit-message-checker-with-regex@v0.3.1
with: with:
commits: ${{ steps.get-pr-commits.outputs.commits }} commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!.*(apply suggestions from code review))' pattern: '^(?!.*(apply suggestions from code review))'
flags: 'i' flags: 'i'
error: 'Commits addressing code review feedback should typically be squashed into the commits under review' error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
- name: 'Verify no "fixup!" commits'
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!fixup!)'
flags: 'i'
error: 'Fixup commits should be squashed into the commits under review'
chart-testing: chart-testing:
name: Helm Chart Linting name: Helm Chart Linting
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Set up Helm - name: Set up Helm
uses: azure/setup-helm@b5b231a831f96336bbfeccc1329990f0005c5bb1 uses: azure/setup-helm@v1
with: with:
version: v3.6.0 version: v3.6.0
- name: Set up Python - name: Set up Python
uses: actions/setup-python@b55428b1882923874294fa556849718a1d7f2ca5 uses: actions/setup-python@v2
with: with:
python-version: '3.x' python-version: '3.x'
- name: Set up helm/chart-testing - name: Set up helm/chart-testing
uses: helm/chart-testing-action@afea100a513515fbd68b0e72a7bb0ae34cb62aec uses: helm/chart-testing-action@v2.1.0
- name: Run helm/chart-testing (lint) - name: Run helm/chart-testing (lint)
run: ct lint --config ct.yaml run: ct lint --config ct.yaml
@@ -61,7 +51,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Run gitlint - name: Run gitlint
@@ -72,7 +62,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run helm-docs and verify docs are up-to-date - name: Run helm-docs and verify docs are up-to-date
run: make helm-docs run: make helm-docs
@@ -82,10 +72,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f uses: gaurav-nelson/github-action-markdown-link-check@v1
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes" check-modified-files-only: "yes"
@@ -96,7 +86,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run markdownlint - name: Run markdownlint
run: make markdownlint run: make markdownlint
@@ -105,6 +95,9 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run yamllint - name: Run yamllint
run: make yamllint uses: ibiqlik/action-yamllint@v1
with:
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
config_file: .yamllint.yml
+3 -5
View File
@@ -5,8 +5,6 @@ on:
schedule: schedule:
- cron: "0 0 * * 0" - cron: "0 0 * * 0"
permissions: {}
jobs: jobs:
markdown-link-check-periodic: markdown-link-check-periodic:
name: Markdown Links (all files) name: Markdown Links (all files)
@@ -14,16 +12,16 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f uses: gaurav-nelson/github-action-markdown-link-check@v1
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links - name: Raise an Issue to report broken links
if: ${{ failure() }} if: ${{ failure() }}
uses: peter-evans/create-issue-from-file@99b87c35610e986ad2034a7b0518a9b3ebea541b uses: peter-evans/create-issue-from-file@v2.3.2
with: with:
title: Broken link detected by CI title: Broken link detected by CI
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
+2 -5
View File
@@ -4,10 +4,7 @@ name: Release Charts
on: on:
push: push:
branches: branches:
- devel - release-0.10
permissions:
contents: write
jobs: jobs:
release: release:
@@ -16,7 +13,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 uses: actions/checkout@v2
with: with:
fetch-depth: 0 fetch-depth: 0
-1
View File
@@ -3,4 +3,3 @@
.shflags .shflags
*.tgz *.tgz
Makefile.dapper Makefile.dapper
Dockerfile.*
-3
View File
@@ -1,8 +1,5 @@
{ {
"ignorePatterns": [ "ignorePatterns": [
{
"pattern": "^https://docs.github.com"
},
{ {
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+" "pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
}, },
-7
View File
@@ -1,7 +0,0 @@
---
cni: ovn
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-6
View File
@@ -1,6 +0,0 @@
---
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-1
View File
@@ -1,4 +1,3 @@
---
label-approved: label-approved:
approvals: 2 approvals: 2
label: ready-to-test label: ready-to-test
+11 -11
View File
@@ -1,15 +1,15 @@
--- ---
extends: default extends: default
rules: rules:
comments: disable
comments-indentation: disable
line-length: line-length:
max: 140 max: 150
# Allow standard GHA syntax for "on: *" braces:
truthy: min-spaces-inside: 0
ignore: '.github/workflows/*.yml' max-spaces-inside: 0
brackets:
ignore: | min-spaces-inside: 0
/submariner-k8s-broker/crds max-spaces-inside: 0
/submariner-operator/crds indentation:
/submariner-k8s-broker/templates indent-sequences: consistent
/submariner-operator/templates
+1 -3
View File
@@ -1,3 +1 @@
# Auto-generated, do not edit; see CODEOWNERS.in * @mangelajo @Oats87 @skitt @tpantelis
* @Oats87 @skitt @sridhargaddam @tpantelis
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
-5
View File
@@ -1,5 +0,0 @@
@dfarrell07 *.md
@Oats87 *
@skitt *
@sridhargaddam *
@tpantelis *
+16
View File
@@ -0,0 +1,16 @@
ARG BASE_BRANCH
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH}
ARG DAPPER_HOST_ARCH
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
WORKDIR ${DAPPER_SOURCE}
# Override the Helm deployment scripts
COPY deploy_helm /opt/shipyard/scripts/lib/
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
CMD ["sh"]
+20 -6
View File
@@ -1,26 +1,40 @@
BASE_BRANCH ?= devel BASE_BRANCH ?= release-0.10
export BASE_BRANCH export BASE_BRANCH
export HELM_REPO_LOCATION=.
ifneq (,$(DAPPER_HOST_ARCH)) ifneq (,$(DAPPER_HOST_ARCH))
# Running in Dapper # Running in Dapper
PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent lighthouse-agent lighthouse-coredns
include $(SHIPYARD_DIR)/Makefile.inc include $(SHIPYARD_DIR)/Makefile.inc
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
ifneq (,$(filter ovn,$(_using))) ifneq (,$(filter ovn,$(_using)))
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings.ovn
else else
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
endif endif
export DEPLOYTOOL = helm override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
export DEPLOY_ARGS
GH_URL=https://submariner-io.github.io/submariner-charts/charts GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts CHARTS_DIR=charts
CHARTS_VERSION=0.14.0-m1 CHARTS_VERSION=0.7.0
HELM_DOCS_VERSION=0.15.0 HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url) REPO_URL=$(shell git config remote.origin.url)
# Process extra flags from the `using=a,b,c` optional flag
ifneq (,$(filter lighthouse,$(_using)))
override DEPLOY_ARGS += --service_discovery
endif
ifneq (,$(filter globalnet,$(_using)))
override DEPLOY_ARGS += --globalnet
endif
# Targets to make # Targets to make
e2e: E2E_ARGS=cluster1 cluster2 e2e: E2E_ARGS=cluster1 cluster2
+1 -1
View File
@@ -60,4 +60,4 @@ working correctly.
[Helm]: https://helm.sh/docs/using_helm/#installing-helm [Helm]: https://helm.sh/docs/using_helm/#installing-helm
[Docker]: https://docs.docker.com/install/ [Docker]: https://docs.docker.com/install/
[Podman]: https://podman.io/getting-started/installation [Podman]: https://podman.io/getting-started/installation
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo [Create a fork]: https://help.github.com/en/articles/fork-a-repo
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker"
cluster_nodes['cluster2']="control-plane worker"
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker worker"
cluster_nodes['cluster2']="control-plane worker worker"
cluster_cni=( ['cluster1']="ovn" ['cluster2']="ovn" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
-1
View File
@@ -1,4 +1,3 @@
---
charts: charts:
- submariner-operator - submariner-operator
- submariner-k8s-broker - submariner-k8s-broker
+76
View File
@@ -0,0 +1,76 @@
# shellcheck shell=bash
# shellcheck source=scripts/shared/lib/source_only
. "${BASH_SOURCE%/*}"/source_only
### Constants ###
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
### Functions ###
function deploytool_prereqs() {
helm version
}
function setup_broker() {
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
echo "Submariner CRDs already exist, skipping broker creation..."
else
echo "Installing submariner broker..."
# shellcheck disable=SC2086 # Split on purpose
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
--create-namespace \
--kube-context "${cluster}" \
--namespace "${SUBMARINER_BROKER_NS}" \
${deploytool_broker_args}
fi
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
}
function helm_install_subm() {
local crd_create=false
[[ "${cluster}" = "${broker}" ]] || crd_create=true
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
echo "Submariner already installed, skipping installation..."
return
fi
echo "Installing Submariner..."
# shellcheck disable=SC2086 # Split on purpose
helm --kube-context "${cluster}" install submariner-operator \
./submariner-operator \
--create-namespace \
--namespace "${SUBM_NS}" \
--set ipsec.psk="${SUBMARINER_PSK}" \
--set broker.server="${submariner_broker_url}" \
--set broker.token="${submariner_broker_token}" \
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
--set broker.ca="${submariner_broker_ca}" \
--set broker.globalnet="${globalnet}" \
--set submariner.serviceDiscovery="${service_discovery}" \
--set submariner.cableDriver="${cable_driver}" \
--set submariner.clusterId="${cluster}" \
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
--set serviceAccounts.globalnet.create="${globalnet}" \
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
--set submariner.natEnabled="false" \
--set operator.image.repository="localhost:5000/submariner-operator" \
--set operator.image.tag="local" \
--set operator.image.pullPolicy="IfNotPresent" \
--set submariner.images.repository="localhost:5000" \
--set submariner.images.tag="local" \
--set brokercrds.create="${crd_create}" \
${deploytool_submariner_args}
}
function install_subm_all_clusters() {
run_subm_clusters helm_install_subm
}
+2 -2
View File
@@ -1,8 +1,8 @@
--- ---
name: submariner-k8s-broker name: submariner-k8s-broker
version: 0.14.0-m1 version: 0.6.0
apiVersion: v2 apiVersion: v2
appVersion: 0.14.0-m1 appVersion: 0.6.0
description: Submariner Kubernetes Broker description: Submariner Kubernetes Broker
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+1 -1
View File
@@ -1,6 +1,6 @@
# submariner-k8s-broker # submariner-k8s-broker
![Version: 0.14.0](https://img.shields.io/badge/Version-0.14.0-informational?style=flat-square) ![AppVersion: 0.14.0](https://img.shields.io/badge/AppVersion-0.14.0-informational?style=flat-square) ![Version: 0.6.0](https://img.shields.io/badge/Version-0.6.0-informational?style=flat-square) ![AppVersion: 0.6.0](https://img.shields.io/badge/AppVersion-0.6.0-informational?style=flat-square)
Submariner Kubernetes Broker Submariner Kubernetes Broker
+60 -296
View File
@@ -1,333 +1,97 @@
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: clusters.submariner.io name: clusters.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Cluster kind: Cluster
listKind: ClusterList
plural: clusters plural: clusters
singular: cluster
scope: Namespaced scope: Namespaced
versions:
- name: v1
schema:
openAPIV3Schema:
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
properties:
cluster_cidr:
items:
type: string
type: array
cluster_id:
type: string
color_codes:
items:
type: string
type: array
global_cidr:
items:
type: string
type: array
service_cidr:
items:
type: string
type: array
required:
- cluster_cidr
- cluster_id
- color_codes
- global_cidr
- service_cidr
type: object
required:
- spec
type: object
served: true
storage: true
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: endpoints.submariner.io name: endpoints.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Endpoint kind: Endpoint
listKind: EndpointList
plural: endpoints plural: endpoints
singular: endpoint
scope: Namespaced scope: Namespaced
versions:
- name: v1
schema:
openAPIV3Schema:
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
properties:
backend:
type: string
backend_config:
additionalProperties:
type: string
type: object
cable_name:
type: string
cluster_id:
type: string
healthCheckIP:
type: string
hostname:
type: string
nat_enabled:
type: boolean
private_ip:
type: string
public_ip:
type: string
subnets:
items:
type: string
type: array
required:
- backend
- cable_name
- cluster_id
- hostname
- nat_enabled
- private_ip
- public_ip
- subnets
type: object
required:
- spec
type: object
served: true
storage: true
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: gateways.submariner.io name: gateways.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Gateway kind: Gateway
listKind: GatewayList
plural: gateways plural: gateways
singular: gateway
scope: Namespaced scope: Namespaced
versions: additionalPrinterColumns:
- additionalPrinterColumns: - name: ha-status
- description: High availability status of the Gateway
jsonPath: .status.haStatus
name: HA Status
type: string type: string
name: v1 description: High Availability Status of the Gateway
schema: JSONPath: .status.haStatus
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: multiclusterservices.lighthouse.submariner.io
spec:
group: lighthouse.submariner.io
version: v1
names:
kind: MultiClusterService
plural: multiclusterservices
singular: multiclusterservice
scope: Namespaced
validation:
openAPIV3Schema: openAPIV3Schema:
properties: properties:
apiVersion: spec:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
status:
properties: properties:
connections: clusterServiceInfo:
items:
properties: properties:
endpoint: clusterID:
properties: type: "string"
backend: clusterDomain:
type: string type: "string"
backend_config: serviceIP:
additionalProperties: type: "string"
type: string port:
type: object type: "integer"
cable_name: ---
type: string apiVersion: apiextensions.k8s.io/v1beta1
cluster_id: kind: CustomResourceDefinition
type: string metadata:
healthCheckIP: name: serviceexports.lighthouse.submariner.io
type: string spec:
hostname: group: lighthouse.submariner.io
type: string version: v2alpha1
nat_enabled: names:
type: boolean kind: ServiceExport
private_ip: plural: serviceexports
type: string singular: serviceexport
public_ip: scope: Namespaced
type: string ---
subnets: apiVersion: apiextensions.k8s.io/v1beta1
items: kind: CustomResourceDefinition
type: string metadata:
type: array name: serviceimports.lighthouse.submariner.io
required: spec:
- backend group: lighthouse.submariner.io
- cable_name version: v2alpha1
- cluster_id names:
- hostname kind: ServiceImport
- nat_enabled plural: serviceimports
- private_ip singular: serviceimport
- public_ip scope: Namespaced
- subnets
type: object
latency:
description: LatencySpec describes the round trip time information
in nanoseconds for a packet between the gateway pods of two
clusters.
properties:
averageRTT:
format: int64
type: integer
lastRTT:
description: TODO This shall be deleted once the operator
is using the latest. Using Optional to avoid validation
errors when this field is not used.
format: int64
type: integer
maxRTT:
format: int64
type: integer
minRTT:
format: int64
type: integer
stddevRTT:
format: int64
type: integer
type: object
latencyRTT:
description: LatencySpec describes the round trip time information
for a packet between the gateway pods of two clusters.
properties:
average:
type: string
last:
type: string
max:
type: string
min:
type: string
stdDev:
type: string
type: object
status:
type: string
statusMessage:
type: string
required:
- endpoint
- status
- statusMessage
type: object
type: array
haStatus:
type: string
localEndpoint:
properties:
backend:
type: string
backend_config:
additionalProperties:
type: string
type: object
cable_name:
type: string
cluster_id:
type: string
healthCheckIP:
type: string
hostname:
type: string
nat_enabled:
type: boolean
private_ip:
type: string
public_ip:
type: string
subnets:
items:
type: string
type: array
required:
- backend
- cable_name
- cluster_id
- hostname
- nat_enabled
- private_ip
- public_ip
- subnets
type: object
statusFailure:
type: string
version:
type: string
required:
- connections
- haStatus
- localEndpoint
- statusFailure
- version
type: object
required:
- status
type: object
served: true
storage: true
subresources: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
+3 -4
View File
@@ -1,18 +1,17 @@
---
questions: questions:
- variable: submariner-k8s-broker.rbac.create - variable: submariner-k8s-broker.rbac.create
type: boolean type: boolean
default: true default: true
group: "Role Based Access Control" group: "Role Based Access Control"
description: "Create the role/rolebinding for the Submariner client" description: "Create the role/rolebinding for the Submariner client"
label: "RBAC Creation Enabled" label: "RBAC Creation Enabled"
- variable: submariner-k8s-broker.crd.create - variable: submariner-k8s-broker.crd.create
type: boolean type: boolean
default: true default: true
group: "Submariner CRD" group: "Submariner CRD"
description: "Create the submariner CRDs for the Submariner client" description: "Create the submariner CRDs for the Submariner client"
label: "Submariner CRD Creation Enabled" label: "Submariner CRD Creation Enabled"
- variable: submariner-k8s-broker.serviceAccounts.client.create - variable: submariner-k8s-broker.serviceAccounts.client.create
type: boolean type: boolean
default: true default: true
group: "Service Account" group: "Service Account"
+2 -2
View File
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
The broker client token and CA can be retrieved by running The broker client token and CA can be retrieved by running
$ SUBMARINER_BROKER_CA=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}") $ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode) $ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
+1 -1
View File
@@ -16,7 +16,7 @@ rules:
resources: ["*"] resources: ["*"]
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"] verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
- apiGroups: ["discovery.k8s.io"] - apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices", "endpointslices/restricted"] resources: ["endpointslices"]
verbs: ["create", "get", "list", "watch","patch", "update", "delete"] verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
- apiGroups: ["multicluster.x-k8s.io"] - apiGroups: ["multicluster.x-k8s.io"]
resources: ["*"] resources: ["*"]
@@ -8,12 +8,4 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner-k8s-broker.chart" . }} chart: {{ template "submariner-k8s-broker.chart" . }}
app: {{ template "submariner-k8s-broker.name" . }} app: {{ template "submariner-k8s-broker.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
+2 -2
View File
@@ -1,8 +1,8 @@
--- ---
name: submariner-operator name: submariner-operator
version: 0.14.0-m1 version: 0.7.0
apiVersion: v2 apiVersion: v2
appVersion: 0.14.0-m1 appVersion: 0.7.0
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+4 -7
View File
@@ -1,6 +1,6 @@
# submariner-operator # submariner-operator
![Version: 0.14.0](https://img.shields.io/badge/Version-0.14.0-informational?style=flat-square) ![AppVersion: 0.14.0](https://img.shields.io/badge/AppVersion-0.14.0-informational?style=flat-square) ![Version: 0.7.0](https://img.shields.io/badge/Version-0.7.0-informational?style=flat-square) ![AppVersion: 0.7.0](https://img.shields.io/badge/AppVersion-0.7.0-informational?style=flat-square)
Submariner enables direct networking between Pods and Services in different Kubernetes clusters Submariner enables direct networking between Pods and Services in different Kubernetes clusters
@@ -27,9 +27,8 @@ Submariner enables direct networking between Pods and Services in different Kube
| broker.server | string | `"example.k8s.apiserver"` | | | broker.server | string | `"example.k8s.apiserver"` | |
| broker.token | string | `"test"` | | | broker.token | string | `"test"` | |
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | | | gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
| gateway.image.tag | string | `"0.14.0-m1"` | | | gateway.image.tag | string | `"0.7.0"` | |
| ipsec.debug | bool | `false` | | | ipsec.debug | bool | `false` | |
| ipsec.forceUDPEncaps | bool | `false` | |
| ipsec.ikePort | int | `500` | | | ipsec.ikePort | int | `500` | |
| ipsec.natPort | int | `4500` | | | ipsec.natPort | int | `4500` | |
| ipsec.psk | string | `""` | | | ipsec.psk | string | `""` | |
@@ -39,7 +38,7 @@ Submariner enables direct networking between Pods and Services in different Kube
| operator.affinity | object | `{}` | | | operator.affinity | object | `{}` | |
| operator.image.pullPolicy | string | `"IfNotPresent"` | | | operator.image.pullPolicy | string | `"IfNotPresent"` | |
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | | | operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
| operator.image.tag | string | `"0.14.0-m1"` | | | operator.image.tag | string | `"0.7.0"` | |
| operator.resources | object | `{}` | | | operator.resources | object | `{}` | |
| operator.tolerations | list | `[]` | | | operator.tolerations | list | `[]` | |
| rbac.create | bool | `true` | | | rbac.create | bool | `true` | |
@@ -59,12 +58,10 @@ Submariner enables direct networking between Pods and Services in different Kube
| submariner.clusterCidr | string | `""` | | | submariner.clusterCidr | string | `""` | |
| submariner.clusterId | string | `""` | | | submariner.clusterId | string | `""` | |
| submariner.colorCodes | string | `"blue"` | | | submariner.colorCodes | string | `"blue"` | |
| submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | | | submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | | | submariner.globalCidr | string | `""` | |
| submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | | | submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.14.0-m1"` | | | submariner.images.tag | string | `"0.7.0"` | |
| submariner.natEnabled | bool | `false` | | | submariner.natEnabled | bool | `false` | |
| submariner.serviceCidr | string | `""` | | | submariner.serviceCidr | string | `""` | |
| submariner.serviceDiscovery | bool | `true` | | | submariner.serviceDiscovery | bool | `true` | |
+58 -185
View File
@@ -1,11 +1,10 @@
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.4.1
creationTimestamp: null
name: submariners.submariner.io name: submariners.submariner.io
annotations:
controller-gen.kubebuilder.io/version: v0.3.0
spec: spec:
group: submariner.io group: submariner.io
names: names:
@@ -14,9 +13,9 @@ spec:
plural: submariners plural: submariners
singular: submariner singular: submariner
scope: Namespaced scope: Namespaced
versions: subresources:
- name: v1alpha1 status: {}
schema: validation:
openAPIV3Schema: openAPIV3Schema:
description: Submariner is the Schema for the submariners API description: Submariner is the Schema for the submariners API
properties: properties:
@@ -43,51 +42,24 @@ spec:
type: string type: string
brokerK8sCA: brokerK8sCA:
type: string type: string
brokerK8sInsecure:
type: boolean
brokerK8sRemoteNamespace: brokerK8sRemoteNamespace:
type: string type: string
cableDriver: cableDriver:
type: string type: string
ceIPSecDebug: ceIPSecDebug:
type: boolean type: boolean
ceIPSecForceUDPEncaps:
type: boolean
ceIPSecIKEPort: ceIPSecIKEPort:
type: integer type: integer
ceIPSecNATTPort: ceIPSecNATTPort:
type: integer type: integer
ceIPSecPSK: ceIPSecPSK:
type: string type: string
ceIPSecPreferredServer:
type: boolean
clusterCIDR: clusterCIDR:
type: string type: string
clusterID: clusterID:
type: string type: string
colorCodes: colorCodes:
type: string type: string
connectionHealthCheck:
properties:
enabled:
type: boolean
intervalSeconds:
description: The interval at which health check pings are sent.
format: int64
type: integer
maxPacketLossCount:
description: The maximum number of packets lost at which the health
checker will mark the connection as down.
format: int64
type: integer
type: object
coreDNSCustomConfig:
properties:
configMapName:
type: string
namespace:
type: string
type: object
customDomains: customDomains:
items: items:
type: string type: string
@@ -97,12 +69,6 @@ spec:
type: boolean type: boolean
globalCIDR: globalCIDR:
type: string type: string
imageOverrides:
additionalProperties:
type: string
type: object
loadBalancerEnabled:
type: boolean
namespace: namespace:
type: string type: string
natEnabled: natEnabled:
@@ -139,17 +105,6 @@ spec:
type: string type: string
colorCodes: colorCodes:
type: string type: string
deploymentInfo:
properties:
cloudProvider:
type: string
kubernetesType:
type: string
kubernetesTypeVersion:
type: string
kubernetesVersion:
type: string
type: object
gatewayDaemonSetStatus: gatewayDaemonSetStatus:
properties: properties:
lastResourceVersion: lastResourceVersion:
@@ -159,8 +114,8 @@ spec:
nonReadyContainerStates: nonReadyContainerStates:
items: items:
description: ContainerState holds a possible state of container. description: ContainerState holds a possible state of container.
Only one of its members may be specified. If none of them Only one of its members may be specified. If none of them is
is specified, the default one is ContainerStateWaiting. specified, the default one is ContainerStateWaiting.
properties: properties:
running: running:
description: Details about a running container description: Details about a running container
@@ -186,21 +141,20 @@ spec:
format: date-time format: date-time
type: string type: string
message: message:
description: Message regarding the last termination description: Message regarding the last termination of
of the container the container
type: string type: string
reason: reason:
description: (brief) reason from the last termination description: (brief) reason from the last termination
of the container of the container
type: string type: string
signal: signal:
description: Signal from the last termination of the description: Signal from the last termination of the container
container
format: int32 format: int32
type: integer type: integer
startedAt: startedAt:
description: Time at which previous execution of the description: Time at which previous execution of the container
container started started
format: date-time format: date-time
type: string type: string
required: required:
@@ -210,19 +164,18 @@ spec:
description: Details about a waiting container description: Details about a waiting container
properties: properties:
message: message:
description: Message regarding why the container is description: Message regarding why the container is not
not yet running. yet running.
type: string type: string
reason: reason:
description: (brief) reason the container is not yet description: (brief) reason the container is not yet running.
running.
type: string type: string
type: object type: object
type: object type: object
type: array type: array
status: status:
description: DaemonSetStatus represents the current status of description: DaemonSetStatus represents the current status of a
a daemon set. daemon set.
properties: properties:
collisionCount: collisionCount:
description: Count of hash collisions for the DaemonSet. The description: Count of hash collisions for the DaemonSet. The
@@ -232,11 +185,11 @@ spec:
format: int32 format: int32
type: integer type: integer
conditions: conditions:
description: Represents the latest available observations description: Represents the latest available observations of
of a DaemonSet's current state. a DaemonSet's current state.
items: items:
description: DaemonSetCondition describes the state of a description: DaemonSetCondition describes the state of a DaemonSet
DaemonSet at a certain point. at a certain point.
properties: properties:
lastTransitionTime: lastTransitionTime:
description: Last time the condition transitioned from description: Last time the condition transitioned from
@@ -334,10 +287,6 @@ spec:
cable_name: cable_name:
type: string type: string
cluster_id: cluster_id:
maxLength: 63
minLength: 1
type: string
healthCheckIP:
type: string type: string
hostname: hostname:
type: string type: string
@@ -361,30 +310,10 @@ spec:
- public_ip - public_ip
- subnets - subnets
type: object type: object
latencyRTT:
description: LatencySpec describes the round trip time
information for a packet between the gateway pods of
two clusters.
properties:
average:
type: string
last:
type: string
max:
type: string
min:
type: string
stdDev:
type: string
type: object
status: status:
type: string type: string
statusMessage: statusMessage:
type: string type: string
usingIP:
type: string
usingNAT:
type: boolean
required: required:
- endpoint - endpoint
- status - status
@@ -404,10 +333,6 @@ spec:
cable_name: cable_name:
type: string type: string
cluster_id: cluster_id:
maxLength: 63
minLength: 1
type: string
healthCheckIP:
type: string type: string
hostname: hostname:
type: string type: string
@@ -454,8 +379,8 @@ spec:
nonReadyContainerStates: nonReadyContainerStates:
items: items:
description: ContainerState holds a possible state of container. description: ContainerState holds a possible state of container.
Only one of its members may be specified. If none of them Only one of its members may be specified. If none of them is
is specified, the default one is ContainerStateWaiting. specified, the default one is ContainerStateWaiting.
properties: properties:
running: running:
description: Details about a running container description: Details about a running container
@@ -481,21 +406,20 @@ spec:
format: date-time format: date-time
type: string type: string
message: message:
description: Message regarding the last termination description: Message regarding the last termination of
of the container the container
type: string type: string
reason: reason:
description: (brief) reason from the last termination description: (brief) reason from the last termination
of the container of the container
type: string type: string
signal: signal:
description: Signal from the last termination of the description: Signal from the last termination of the container
container
format: int32 format: int32
type: integer type: integer
startedAt: startedAt:
description: Time at which previous execution of the description: Time at which previous execution of the container
container started started
format: date-time format: date-time
type: string type: string
required: required:
@@ -505,19 +429,18 @@ spec:
description: Details about a waiting container description: Details about a waiting container
properties: properties:
message: message:
description: Message regarding why the container is description: Message regarding why the container is not
not yet running. yet running.
type: string type: string
reason: reason:
description: (brief) reason the container is not yet description: (brief) reason the container is not yet running.
running.
type: string type: string
type: object type: object
type: object type: object
type: array type: array
status: status:
description: DaemonSetStatus represents the current status of description: DaemonSetStatus represents the current status of a
a daemon set. daemon set.
properties: properties:
collisionCount: collisionCount:
description: Count of hash collisions for the DaemonSet. The description: Count of hash collisions for the DaemonSet. The
@@ -527,11 +450,11 @@ spec:
format: int32 format: int32
type: integer type: integer
conditions: conditions:
description: Represents the latest available observations description: Represents the latest available observations of
of a DaemonSet's current state. a DaemonSet's current state.
items: items:
description: DaemonSetCondition describes the state of a description: DaemonSetCondition describes the state of a DaemonSet
DaemonSet at a certain point. at a certain point.
properties: properties:
lastTransitionTime: lastTransitionTime:
description: Last time the condition transitioned from description: Last time the condition transitioned from
@@ -612,36 +535,8 @@ spec:
required: required:
- mismatchedContainerImages - mismatchedContainerImages
type: object type: object
loadBalancerStatus:
properties:
status:
description: LoadBalancerStatus represents the status of a load-balancer.
properties:
ingress:
description: Ingress is a list containing ingress points for
the load-balancer. Traffic intended for the service should
be sent to these ingress points.
items:
description: 'LoadBalancerIngress represents the status
of a load-balancer ingress point: traffic intended for
the service should be sent to an ingress point.'
properties:
hostname:
description: Hostname is set for load-balancer ingress
points that are DNS based (typically AWS load-balancers)
type: string
ip:
description: IP is set for load-balancer ingress points
that are IP based (typically GCE or OpenStack load-balancers)
type: string
type: object
type: array
type: object
type: object
natEnabled: natEnabled:
type: boolean type: boolean
networkPlugin:
type: string
routeAgentDaemonSetStatus: routeAgentDaemonSetStatus:
properties: properties:
lastResourceVersion: lastResourceVersion:
@@ -651,8 +546,8 @@ spec:
nonReadyContainerStates: nonReadyContainerStates:
items: items:
description: ContainerState holds a possible state of container. description: ContainerState holds a possible state of container.
Only one of its members may be specified. If none of them Only one of its members may be specified. If none of them is
is specified, the default one is ContainerStateWaiting. specified, the default one is ContainerStateWaiting.
properties: properties:
running: running:
description: Details about a running container description: Details about a running container
@@ -678,21 +573,20 @@ spec:
format: date-time format: date-time
type: string type: string
message: message:
description: Message regarding the last termination description: Message regarding the last termination of
of the container the container
type: string type: string
reason: reason:
description: (brief) reason from the last termination description: (brief) reason from the last termination
of the container of the container
type: string type: string
signal: signal:
description: Signal from the last termination of the description: Signal from the last termination of the container
container
format: int32 format: int32
type: integer type: integer
startedAt: startedAt:
description: Time at which previous execution of the description: Time at which previous execution of the container
container started started
format: date-time format: date-time
type: string type: string
required: required:
@@ -702,19 +596,18 @@ spec:
description: Details about a waiting container description: Details about a waiting container
properties: properties:
message: message:
description: Message regarding why the container is description: Message regarding why the container is not
not yet running. yet running.
type: string type: string
reason: reason:
description: (brief) reason the container is not yet description: (brief) reason the container is not yet running.
running.
type: string type: string
type: object type: object
type: object type: object
type: array type: array
status: status:
description: DaemonSetStatus represents the current status of description: DaemonSetStatus represents the current status of a
a daemon set. daemon set.
properties: properties:
collisionCount: collisionCount:
description: Count of hash collisions for the DaemonSet. The description: Count of hash collisions for the DaemonSet. The
@@ -724,11 +617,11 @@ spec:
format: int32 format: int32
type: integer type: integer
conditions: conditions:
description: Represents the latest available observations description: Represents the latest available observations of
of a DaemonSet's current state. a DaemonSet's current state.
items: items:
description: DaemonSetCondition describes the state of a description: DaemonSetCondition describes the state of a DaemonSet
DaemonSet at a certain point. at a certain point.
properties: properties:
lastTransitionTime: lastTransitionTime:
description: Last time the condition transitioned from description: Last time the condition transitioned from
@@ -816,10 +709,11 @@ spec:
- natEnabled - natEnabled
type: object type: object
type: object type: object
version: v1alpha1
versions:
- name: v1alpha1
served: true served: true
storage: true storage: true
subresources:
status: {}
status: status:
acceptedNames: acceptedNames:
kind: "" kind: ""
@@ -831,7 +725,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
annotations: annotations:
controller-gen.kubebuilder.io/version: v0.4.1 controller-gen.kubebuilder.io/version: v0.3.0
creationTimestamp: null creationTimestamp: null
name: servicediscoveries.submariner.io name: servicediscoveries.submariner.io
spec: spec:
@@ -869,19 +763,10 @@ spec:
type: string type: string
brokerK8sCA: brokerK8sCA:
type: string type: string
brokerK8sInsecure:
type: boolean
brokerK8sRemoteNamespace: brokerK8sRemoteNamespace:
type: string type: string
clusterID: clusterID:
type: string type: string
coreDNSCustomConfig:
properties:
configMapName:
type: string
namespace:
type: string
type: object
customDomains: customDomains:
items: items:
type: string type: string
@@ -912,18 +797,6 @@ spec:
type: object type: object
status: status:
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
properties:
deploymentInfo:
properties:
cloudProvider:
type: string
kubernetesType:
type: string
kubernetesTypeVersion:
type: string
kubernetesVersion:
type: string
type: object
type: object type: object
type: object type: object
served: true served: true
+18 -25
View File
@@ -1,6 +1,5 @@
---
questions: questions:
- variable: defaultOperatorImage - variable: defaultOperatorImage
default: true default: true
description: "Use default Submariner operator image or specify a custom one" description: "Use default Submariner operator image or specify a custom one"
label: Use default Submariner operator image label: Use default Submariner operator image
@@ -14,11 +13,11 @@ questions:
type: string type: string
label: Submariner Operator Image Repository label: Submariner Operator Image Repository
- variable: operator.image.tag - variable: operator.image.tag
default: "0.14.0-m1" default: "0.7.0"
description: "Submariner Operator Image Tag" description: "Submariner Operator Image Tag"
type: string type: string
label: Submariner Operator Image Tag label: Submariner Operator Image Tag
- variable: defaultSubmarinerImages - variable: defaultSubmarinerImages
default: true default: true
description: "Use default Submariner images or specify custom ones" description: "Use default Submariner images or specify custom ones"
label: Use default Submariner images label: Use default Submariner images
@@ -32,31 +31,31 @@ questions:
type: string type: string
label: Submariner Repository label: Submariner Repository
- variable: submariner.images.tag - variable: submariner.images.tag
default: "0.14.0-m1" default: "0.7.0"
description: "Submariner Images Tag (shared for all non-operator images)" description: "Submariner Images Tag (shared for all non-operator images)"
type: string type: string
label: Submariner Images Tag label: Submariner Images Tag
- variable: submariner.clusterId - variable: submariner.clusterId
default: "" default: ""
description: "Enter a unique cluster ID to identify this cluster" description: "Enter a unique cluster ID to identify this cluster"
type: string type: string
label: "Cluster ID" label: "Cluster ID"
group: "Configuration" group: "Configuration"
required: true required: true
- variable: ipsec.psk - variable: ipsec.psk
default: "" default: ""
description: "Enter the pre-shared key for the IPsec Cable Engine" description: "Enter the pre-shared key for the IPsec Cable Engine"
type: string type: string
label: "IPsec Pre-Shared Key" label: "IPsec Pre-Shared Key"
group: "Configuration" group: "Configuration"
required: true required: true
- variable: broker.server - variable: broker.server
type: string type: string
default: "" default: ""
group: "Broker Configuration" group: "Broker Configuration"
label: "Broker Server" label: "Broker Server"
description: "Broker server to use (without the https://)" description: "Broker server to use (without the https://)"
- variable: broker.insecure - variable: broker.insecure
type: boolean type: boolean
default: false default: false
show_subquestion_if: false show_subquestion_if: false
@@ -69,37 +68,37 @@ questions:
description: "Base64 encoded broker ca.crt" description: "Base64 encoded broker ca.crt"
label: "Broker CA encoded in base64" label: "Broker CA encoded in base64"
default: "" default: ""
- variable: broker.token - variable: broker.token
type: string type: string
group: "Broker Configuration" group: "Broker Configuration"
label: "Broker Token" label: "Broker Token"
description: "Bearer token for broker" description: "Bearer token for broker"
- variable: broker.namespace - variable: broker.namespace
type: string type: string
group: "Broker Configuration" group: "Broker Configuration"
label: "Broker Namespace" label: "Broker Namespace"
description: "Enter namespace to use on central broker" description: "Enter namespace to use on central broker"
- variable: submariner.clusterCidr - variable: submariner.clusterCidr
default: "" default: ""
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster" description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
type: string type: string
label: "Cluster CIDR" label: "Cluster CIDR"
group: "CIDR Configuration" group: "CIDR Configuration"
required: true required: true
- variable: submariner.serviceCidr - variable: submariner.serviceCidr
default: "" default: ""
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster" description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
type: string type: string
label: "Service CIDR" label: "Service CIDR"
group: "CIDR Configuration" group: "CIDR Configuration"
required: true required: true
- variable: submariner.serviceDiscovery - variable: submariner.serviceDiscovery
type: boolean type: boolean
default: false default: false
group: "Advanced Configuration" group: "Advanced Configuration"
description: "Enable multicluster service discovery" description: "Enable multicluster service discovery"
label: "Service Discovery Enabled" label: "Service Discovery Enabled"
- variable: broker.globalnet - variable: broker.globalnet
type: boolean type: boolean
default: false default: false
group: "Broker Configuration" group: "Broker Configuration"
@@ -113,33 +112,27 @@ questions:
label: "Globalnet CIDR" label: "Globalnet CIDR"
group: "CIDR Configuration" group: "CIDR Configuration"
required: false required: false
- variable: submariner.natEnabled - variable: submariner.natEnabled
type: boolean type: boolean
default: false default: false
group: "Advanced Configuration" group: "Advanced Configuration"
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT" description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
label: "NAT Enabled" label: "NAT Enabled"
- variable: submariner.debug - variable: submariner.debug
type: boolean type: boolean
default: false default: false
group: "Advanced Configuration" group: "Advanced Configuration"
description: "Enable submariner debug mode" description: "Enable submariner debug mode"
label: "Submariner Debug Enabled" label: "Submariner Debug Enabled"
- variable: ipsec.debug - variable: ipsec.debug
type: boolean type: boolean
default: false default: false
group: "Advanced Configuration" group: "Advanced Configuration"
description: "Enable Charon debug mode" description: "Enable Charon debug mode"
label: "Charon Enabled" label: "Charon Enabled"
- variable: submariner.cableDriver - variable: submariner.cableDriver
type: string type: string
default: "" default: ""
group: "Advanced Configuration" group: "Advanced Configuration"
description: "Cable driver implementation" description: "Cable driver implementation"
label: "Cable Driver" label: "Cable Driver"
- variable: submariner.healthcheckEnabled
type: boolean
default: true
group: "Advanced Configuration"
description: "Disable Healthcheck"
label: "Healthcheck Disabled"
+1 -71
View File
@@ -162,17 +162,6 @@ rules:
- patch - patch
- update - update
- watch - watch
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -450,21 +439,6 @@ rules:
verbs: verbs:
- get - get
- list - list
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
- watch
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -485,29 +459,6 @@ roleRef:
name: {{ template "submariner.fullname" . }} name: {{ template "submariner.fullname" . }}
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: submariner-metrics-reader
namespace: {{ .Release.Namespace }}
rules:
- apiGroups: [""]
resources: ["pods", "services", "endpoints"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-submariner-metrics
subjects:
- kind: ServiceAccount
name: prometheus-k8s
namespace: openshift-monitoring
roleRef:
kind: Role
name: submariner-metrics-reader
apiGroup: rbac.authorization.k8s.io
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole kind: ClusterRole
metadata: metadata:
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:gateway
@@ -689,25 +640,14 @@ rules:
- "" - ""
resources: resources:
- pods - pods
- services
- namespaces - namespaces
- nodes - nodes
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- update - update
- apiGroups:
- ""
resources:
- services
verbs:
- create
- get
- list
- watch
- update
- delete
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
@@ -748,15 +688,6 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- network.openshift.io
resources:
- service/externalips
verbs:
- create
- get
- list
- delete
--- ---
{{- end -}} {{- end -}}
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -803,7 +734,6 @@ rules:
- discovery.k8s.io - discovery.k8s.io
resources: resources:
- endpointslices - endpointslices
- endpointslices/restricted
verbs: verbs:
- create - create
- get - get
@@ -9,9 +9,7 @@ spec:
brokerK8sApiServerToken: {{ .Values.broker.token }} brokerK8sApiServerToken: {{ .Values.broker.token }}
brokerK8sCA: {{ .Values.broker.ca }} brokerK8sCA: {{ .Values.broker.ca }}
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }} brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
brokerK8sInsecure: {{ .Values.broker.insecure }}
ceIPSecDebug: {{ .Values.ipsec.debug }} ceIPSecDebug: {{ .Values.ipsec.debug }}
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }} ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
ceIPSecNATTPort: {{ .Values.ipsec.natPort }} ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
ceIPSecPSK: {{ .Values.ipsec.psk }} ceIPSecPSK: {{ .Values.ipsec.psk }}
@@ -19,47 +17,11 @@ spec:
clusterID: {{ .Values.submariner.clusterId }} clusterID: {{ .Values.submariner.clusterId }}
colorCodes: {{ .Values.submariner.colorCodes }} colorCodes: {{ .Values.submariner.colorCodes }}
debug: {{ .Values.submariner.debug }} debug: {{ .Values.submariner.debug }}
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
natEnabled: {{ .Values.submariner.natEnabled }} natEnabled: {{ .Values.submariner.natEnabled }}
repository: {{ .Values.submariner.images.repository }} repository: {{ .Values.submariner.images.repository }}
version: {{ .Values.submariner.images.tag }} version: {{ .Values.submariner.images.tag }}
{{- with .Values.images }}
{{- if . }}
imageOverrides:
{{- if index . "submariner-operator" }}
submariner-operator: {{ index . "submariner-operator" }}
{{- end }}
{{- if index . "submariner-gateway" }}
submariner-gateway: {{ index . "submariner-gateway" }}
{{- end }}
{{- if index . "submariner-route-agent" }}
submariner-routeagent: {{ index . "submariner-route-agent" }}
{{- end }}
{{- if index . "submariner-globalnet" }}
submariner-globalnet: {{ index . "submariner-globalnet" }}
{{- end }}
{{- if index . "submariner-networkplugin-syncer" }}
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
{{- end }}
{{- if index . "lighthouse-agent" }}
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
{{- end }}
{{- if index . "lighthouse-coredns" }}
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
{{- end }}
{{- end }}
{{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}" serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}" globalCIDR: "{{ .Values.submariner.globalCidr }}"
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }} serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }} cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck:
enabled: {{ .Values.submariner.healthcheckEnabled }}
intervalSeconds: 1
maxPacketLossCount: 5
{{- with .Values.submariner.coreDNSCustomConfig }}
coreDNSCustomConfig:
configmapName: {{ .configmapName }}
namespace: {{ .namespace }}
{{- end }}
@@ -8,14 +8,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.operatorServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.gateway.create }} {{- if .Values.serviceAccounts.gateway.create }}
@@ -28,14 +20,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.routeAgent.create }} {{- if .Values.serviceAccounts.routeAgent.create }}
@@ -48,14 +32,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.globalnet.create }} {{- if .Values.serviceAccounts.globalnet.create }}
@@ -68,14 +44,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.lighthouseAgent.create }} {{- if .Values.serviceAccounts.lighthouseAgent.create }}
@@ -88,14 +56,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }} {{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
@@ -108,12 +68,4 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
+3 -8
View File
@@ -5,17 +5,14 @@ submariner:
clusterCidr: "" clusterCidr: ""
serviceCidr: "" serviceCidr: ""
globalCidr: "" globalCidr: ""
loadBalancerEnabled: false
natEnabled: false natEnabled: false
colorCodes: blue colorCodes: blue
debug: false debug: false
serviceDiscovery: true serviceDiscovery: true
cableDriver: "libreswan" cableDriver: "libreswan"
healthcheckEnabled: true
coreDNSCustomConfig: {}
images: images:
repository: quay.io/submariner repository: quay.io/submariner
tag: "0.14.0-m1" tag: "0.7.0"
broker: broker:
server: example.k8s.apiserver server: example.k8s.apiserver
token: test token: test
@@ -25,11 +22,9 @@ broker:
globalnet: false globalnet: false
rbac: rbac:
create: true create: true
images: {}
ipsec: ipsec:
psk: "" psk: ""
debug: false debug: false
forceUDPEncaps: false
ikePort: 500 ikePort: 500
natPort: 4500 natPort: 4500
leadership: leadership:
@@ -39,7 +34,7 @@ leadership:
operator: operator:
image: image:
repository: quay.io/submariner/submariner-operator repository: quay.io/submariner/submariner-operator
tag: "0.14.0-m1" tag: "0.7.0"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
resources: {} resources: {}
tolerations: [] tolerations: []
@@ -47,7 +42,7 @@ operator:
gateway: gateway:
image: image:
repository: quay.io/submariner/submariner-gateway repository: quay.io/submariner/submariner-gateway
tag: "0.14.0-m1" tag: "0.7.0"
serviceAccounts: serviceAccounts:
operator: operator:
create: true create: true