Compare commits

..
21 Commits
Author SHA1 Message Date
Stephen KittandThomas Pantelis 5ab8347f4f Bump to 0.11.1
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2022-01-26 08:45:13 -05:00
Daniel FarrellandThomas Pantelis 3dd6eeb961 Update K8s in E2E, EOL 1.19 and add 1.23
Update the versions of Kubernetes tested in the E2E CI. Add 1.23 as the
new default for most tests, remove 1.19 as it is now EOL.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
(cherry picked from commit b6590df91b)
2022-01-26 08:44:26 -05:00
Sridhar GaddamandThomas Pantelis 85bc80cbe4 Configure RBAC for Globalnet pods on OCP deployments
Globalnet controller now uses internal services with external-ips
to support exported services. On OCP Clusters, we require an explicit
RBAC to create services with external-ips, this PR includes the
necessary RBAC for Globalnet pods.

Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>

(cherry picked from commit bf2c41115b)
2022-01-26 08:44:26 -05:00
NegashandThomas Pantelis cdc0e0e0c5 Fix coreDNSCustomConfig values
Signed-off-by: Negash <i@negash.ru>
(cherry picked from commit 9ba0123e72)
2022-01-26 08:44:26 -05:00
Sridhar GaddamandThomas Pantelis 6250b283fa Globalnet include ClusterRole for services
As part of Globalnet enhancement where kubeproxy dependency
is removed, the Globalnet Pod will now create internal
services for every exported service in the respective
namespace where the original service resides. This PR
adds the necessary clusterRole to allow Globalnet pod
to create/delete such internal services.

Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
(cherry picked from commit b3a5e40a5a)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis ed33b07bd9 Add roles and privileges required for monitoring
This replicates the RBAC changes applied to the operator in
https://github.com/submariner-io/submariner-operator/pull/1416

Fixes: #191
Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 9358c86eb5)
2022-01-26 08:44:26 -05:00
Masaki KimuraandThomas Pantelis f1410811d7 Allow submariner-globalnet role to handle endpoints
Signed-off-by: Masaki Kimura <masaki.kimura@hitachivantara.com>
(cherry picked from commit 5da180d44f)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 648dbeacb3 Add dfarrell07 as *.md code owner
See <https://github.com/submariner-io/submariner/issues/1622>.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 7068abafc8)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 2a4213f768 Update all CRDs to v1 CRDs
... and drop the obsolete Lighthouse CRDs.

Fixes: #186
Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 2cfbd5c394)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 0f97bc9c11 Pass the broker.insecure flag to the CR
Fixes: #185
Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 42a2af008a)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 36945da91c Remove mangelajo from CODEOWNERS
... with his approval.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 1fbd3da4ae)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis dfc0280658 Update K8s versions: drop 1.17/1.18, add 1.21/1.22
1.17 and 1.18 have reached EOL.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit fc77796287)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 12c3cbe928 Bump to 0.11.0
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-10-28 08:26:13 -04:00
Vishal ThaparandStephen Kitt 06ce316138 Fix connectionHealthCheck
connectionHealthCheck in submariner CR is a nested field
but is being added as a variable. This means it is ignored
and the field isn't set correctly in gateway pods.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-10-28 11:05:40 +02:00
Aswin SurayanarayananandThomas Pantelis 27eb25c8f6 Add RBAC permission endpointslices/restricted in broker roles
Fixes : github.com/submariner-io/lighthouse/issues#627

Signed-off-by: Aswin Surayanarayanan <asuryana@redhat.com>
2021-10-26 08:53:15 -04:00
5cc6ec47de Update submariner-operator/questions.yml
Co-authored-by: Sridhar Gaddam <sgaddam@redhat.com>
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 9fcea9930c Update Readme.md
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis c1ce210c89 Add ceIPSecForceUDPEncaps & coreDNSCustomConfig variables
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 7d8bf6a3ac Add enable/disable connectionHealthCheck
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 4cf74cfc3b Bump up to 0.10.1
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Automated Release 14e85ad476 Update base image to use stable branch 'release-0.11'
Signed-off-by: Automated Release <release@submariner.io>
2021-10-20 07:36:16 +00:00
34 changed files with 363 additions and 230 deletions
-17
View File
@@ -1,17 +0,0 @@
---
version: 2
updates:
- package-ecosystem: github-actions
directory: '/'
schedule:
interval: weekly
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.12"
schedule:
interval: weekly
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.13"
schedule:
interval: weekly
+4 -6
View File
@@ -4,13 +4,11 @@ name: Branch Checks
on:
pull_request:
permissions: {}
jobs:
target_branch:
name: PR targets branch
target_devel:
name: PR targets release-0.11
runs-on: ubuntu-latest
steps:
- name: Check that the PR targets release-0.14
if: ${{ github.base_ref != 'release-0.14' }}
- name: Check that the PR targets release-0.11
if: ${{ github.base_ref != 'release-0.11' }}
run: exit 1
+2 -7
View File
@@ -17,12 +17,7 @@ on:
- reopened
- synchronize
schedule:
- cron: '0 0/6 * * *' # every 6 hours
permissions:
issues: write
pull-requests: write
statuses: write
- cron: '0 0/6 * * *' # every 6 hours
jobs:
check:
@@ -30,7 +25,7 @@ jobs:
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
steps:
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43
- uses: z0al/dependent-issues@70a1b2d4ee1cdc743af33498bd0204123953a887
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
+6 -8
View File
@@ -5,8 +5,6 @@ on:
pull_request:
types: [labeled, opened, synchronize, reopened]
permissions: {}
jobs:
e2e:
name: E2E
@@ -18,22 +16,22 @@ jobs:
matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet']
k8s_version: ['1.25']
k8s_version: ['1.23']
lighthouse: ['', 'lighthouse']
include:
- k8s_version: '1.20'
- k8s_version: '1.21'
- k8s_version: '1.22'
- k8s_version: '1.23'
- k8s_version: '1.24'
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.14
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
with:
k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.14
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+3 -5
View File
@@ -4,8 +4,6 @@ name: End to End Default
on:
pull_request:
permissions: {}
jobs:
e2e:
name: E2E
@@ -13,11 +11,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.14
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.14
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+3 -5
View File
@@ -5,8 +5,6 @@ on:
schedule:
- cron: "0 0 * * *"
permissions: {}
jobs:
e2e:
name: E2E
@@ -21,13 +19,13 @@ jobs:
lighthouse: ['', 'lighthouse']
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.14
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.14
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+17 -23
View File
@@ -4,8 +4,6 @@ name: Linting
on:
pull_request:
permissions: {}
jobs:
apply-suggestions-commits:
name: 'No "Apply suggestions from code review" Commits'
@@ -13,45 +11,37 @@ jobs:
steps:
- name: Get PR commits
id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@8673d84c368f480628607dbe21c88545811ef23a
uses: tim-actions/get-pr-commits@55b867b9b28954e6f5c1a0fe2f729dc926c306d0
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: 'Verify no "Apply suggestions from code review" commits'
uses: tim-actions/commit-message-checker-with-regex@e16b08b1a7f5cafeb1f8167de05bf1d40239eb5d
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!.*(apply suggestions from code review))'
flags: 'i'
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
- name: 'Verify no "fixup!" commits'
uses: tim-actions/commit-message-checker-with-regex@e16b08b1a7f5cafeb1f8167de05bf1d40239eb5d
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!fixup!)'
flags: 'i'
error: 'Fixup commits should be squashed into the commits under review'
chart-testing:
name: Helm Chart Linting
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Set up Helm
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78
uses: azure/setup-helm@18bc76811624f360dbd7f18c2d4ecb32c7b87bab
with:
version: v3.6.0
- name: Set up Python
uses: actions/setup-python@57ded4d7d5e986d7296eab16560982c6dd7c923b
uses: actions/setup-python@dc73133d4da04e56a135ae2246682783cc7c7cb6
with:
python-version: '3.x'
- name: Set up helm/chart-testing
uses: helm/chart-testing-action@e8788873172cb653a90ca2e819d79d65a66d4e76
uses: helm/chart-testing-action@5f16c27cf7a4fa9c776ff73734df3909b2b65127
- name: Run helm/chart-testing (lint)
run: ct lint --config ct.yaml
@@ -61,7 +51,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
with:
fetch-depth: 0
- name: Run gitlint
@@ -72,7 +62,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run helm-docs and verify docs are up-to-date
run: make helm-docs
@@ -82,10 +72,10 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
with:
config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes"
@@ -96,7 +86,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdownlint
run: make markdownlint
@@ -105,6 +95,10 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run yamllint
run: make yamllint
uses: ibiqlik/action-yamllint@ed2b6e911569708ed121c14b87d513860a7e36a7
with:
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
config_file: .yamllint.yml
strict: true
+3 -7
View File
@@ -5,27 +5,23 @@ on:
schedule:
- cron: "0 0 * * 0"
permissions: {}
jobs:
markdown-link-check-periodic:
name: Markdown Links (all files)
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
permissions:
issues: write
steps:
- name: Check out the repository
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
with:
config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links
if: ${{ failure() }}
uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f
uses: peter-evans/create-issue-from-file@97e6f902a416aac38834e23fa52e166aad0437d2
with:
title: Broken link detected by CI
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
+2 -5
View File
@@ -4,10 +4,7 @@ name: Release Charts
on:
push:
branches:
- release-0.14
permissions:
contents: write
- release-0.11
jobs:
release:
@@ -16,7 +13,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
with:
fetch-depth: 0
-1
View File
@@ -3,4 +3,3 @@
.shflags
*.tgz
Makefile.dapper
Dockerfile.*
-3
View File
@@ -1,8 +1,5 @@
{
"ignorePatterns": [
{
"pattern": "^https://docs.github.com"
},
{
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
},
-7
View File
@@ -1,7 +0,0 @@
---
cni: ovn
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-6
View File
@@ -1,6 +0,0 @@
---
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-1
View File
@@ -1,4 +1,3 @@
---
label-approved:
approvals: 2
label: ready-to-test
+11 -11
View File
@@ -1,15 +1,15 @@
---
extends: default
rules:
comments: disable
comments-indentation: disable
line-length:
max: 140
# Allow standard GHA syntax for "on: *"
truthy:
ignore: '.github/workflows/*.yml'
ignore: |
/submariner-k8s-broker/crds
/submariner-operator/crds
/submariner-k8s-broker/templates
/submariner-operator/templates
max: 150
braces:
min-spaces-inside: 0
max-spaces-inside: 0
brackets:
min-spaces-inside: 0
max-spaces-inside: 0
indentation:
indent-sequences: consistent
+16
View File
@@ -0,0 +1,16 @@
ARG BASE_BRANCH
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH}
ARG DAPPER_HOST_ARCH
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
WORKDIR ${DAPPER_SOURCE}
# Override the Helm deployment scripts
COPY deploy_helm /opt/shipyard/scripts/lib/
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
CMD ["sh"]
+20 -8
View File
@@ -1,27 +1,39 @@
BASE_BRANCH ?= release-0.14
BASE_BRANCH ?= release-0.11
export BASE_BRANCH
export HELM_REPO_LOCATION=.
ifneq (,$(DAPPER_HOST_ARCH))
# Running in Dapper
PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent lighthouse-agent lighthouse-coredns
include $(SHIPYARD_DIR)/Makefile.inc
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
ifneq (,$(filter ovn,$(_using)))
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings.ovn
else
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
endif
export DEPLOYTOOL = helm
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
export DEPLOY_ARGS
GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts
CHARTS_VERSION=0.14.0-m1
CHARTS_VERSION=0.11.1
HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url)
SUBCTL_VERSION=$(CHARTS_VERSION)
export SUBCTL_VERSION
# Process extra flags from the `using=a,b,c` optional flag
ifneq (,$(filter lighthouse,$(_using)))
override DEPLOY_ARGS += --service_discovery
endif
ifneq (,$(filter globalnet,$(_using)))
override DEPLOY_ARGS += --globalnet
endif
# Targets to make
+1 -1
View File
@@ -60,4 +60,4 @@ working correctly.
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
[Docker]: https://docs.docker.com/install/
[Podman]: https://podman.io/getting-started/installation
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker"
cluster_nodes['cluster2']="control-plane worker"
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker worker"
cluster_nodes['cluster2']="control-plane worker worker"
cluster_cni=( ['cluster1']="ovn" ['cluster2']="ovn" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
-1
View File
@@ -1,4 +1,3 @@
---
charts:
- submariner-operator
- submariner-k8s-broker
+76
View File
@@ -0,0 +1,76 @@
# shellcheck shell=bash
# shellcheck source=scripts/shared/lib/source_only
. "${BASH_SOURCE%/*}"/source_only
### Constants ###
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
### Functions ###
function deploytool_prereqs() {
helm version
}
function setup_broker() {
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
echo "Submariner CRDs already exist, skipping broker creation..."
else
echo "Installing submariner broker..."
# shellcheck disable=SC2086 # Split on purpose
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
--create-namespace \
--kube-context "${cluster}" \
--namespace "${SUBMARINER_BROKER_NS}" \
${deploytool_broker_args}
fi
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
}
function helm_install_subm() {
local crd_create=false
[[ "${cluster}" = "${broker}" ]] || crd_create=true
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
echo "Submariner already installed, skipping installation..."
return
fi
echo "Installing Submariner..."
# shellcheck disable=SC2086 # Split on purpose
helm --kube-context "${cluster}" install submariner-operator \
./submariner-operator \
--create-namespace \
--namespace "${SUBM_NS}" \
--set ipsec.psk="${SUBMARINER_PSK}" \
--set broker.server="${submariner_broker_url}" \
--set broker.token="${submariner_broker_token}" \
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
--set broker.ca="${submariner_broker_ca}" \
--set broker.globalnet="${globalnet}" \
--set submariner.serviceDiscovery="${service_discovery}" \
--set submariner.cableDriver="${cable_driver}" \
--set submariner.clusterId="${cluster}" \
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
--set serviceAccounts.globalnet.create="${globalnet}" \
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
--set submariner.natEnabled="false" \
--set operator.image.repository="localhost:5000/submariner-operator" \
--set operator.image.tag="local" \
--set operator.image.pullPolicy="IfNotPresent" \
--set submariner.images.repository="localhost:5000" \
--set submariner.images.tag="local" \
--set brokercrds.create="${crd_create}" \
${deploytool_submariner_args}
}
function install_subm_all_clusters() {
run_subm_clusters helm_install_subm
}
+2 -2
View File
@@ -1,8 +1,8 @@
---
name: submariner-k8s-broker
version: 0.14.0-m1
version: 0.6.0
apiVersion: v2
appVersion: 0.14.0-m1
appVersion: 0.6.0
description: Submariner Kubernetes Broker
keywords:
home: https://submariner-io.github.io/
+2
View File
@@ -1,5 +1,7 @@
# submariner-k8s-broker
![Version: 0.6.0](https://img.shields.io/badge/Version-0.6.0-informational?style=flat-square) ![AppVersion: 0.6.0](https://img.shields.io/badge/AppVersion-0.6.0-informational?style=flat-square)
Submariner Kubernetes Broker
**Homepage:** <https://submariner-io.github.io/>
+19
View File
@@ -0,0 +1,19 @@
questions:
- variable: submariner-k8s-broker.rbac.create
type: boolean
default: true
group: "Role Based Access Control"
description: "Create the role/rolebinding for the Submariner client"
label: "RBAC Creation Enabled"
- variable: submariner-k8s-broker.crd.create
type: boolean
default: true
group: "Submariner CRD"
description: "Create the submariner CRDs for the Submariner client"
label: "Submariner CRD Creation Enabled"
- variable: submariner-k8s-broker.serviceAccounts.client.create
type: boolean
default: true
group: "Service Account"
description: "Create the service account for the Submariner client"
label: "Submariner Service Account Creation Enabled"
+2 -2
View File
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
The broker client token and CA can be retrieved by running
$ SUBMARINER_BROKER_CA=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
@@ -8,12 +8,4 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner-k8s-broker.chart" . }}
app: {{ template "submariner-k8s-broker.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }}
+2 -2
View File
@@ -1,8 +1,8 @@
---
name: submariner-operator
version: 0.14.0-m1
version: 0.11.1
apiVersion: v2
appVersion: 0.14.0-m1
appVersion: 0.11.1
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords:
home: https://submariner-io.github.io/
+5 -3
View File
@@ -1,5 +1,7 @@
# submariner-operator
![Version: 0.11.1](https://img.shields.io/badge/Version-0.11.1-informational?style=flat-square) ![AppVersion: 0.11.1](https://img.shields.io/badge/AppVersion-0.11.1-informational?style=flat-square)
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
**Homepage:** <https://submariner-io.github.io/>
@@ -25,7 +27,7 @@ Submariner enables direct networking between Pods and Services in different Kube
| broker.server | string | `"example.k8s.apiserver"` | |
| broker.token | string | `"test"` | |
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
| gateway.image.tag | string | `"0.14.0"` | |
| gateway.image.tag | string | `"0.11.1"` | |
| ipsec.debug | bool | `false` | |
| ipsec.forceUDPEncaps | bool | `false` | |
| ipsec.ikePort | int | `500` | |
@@ -37,7 +39,7 @@ Submariner enables direct networking between Pods and Services in different Kube
| operator.affinity | object | `{}` | |
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
| operator.image.tag | string | `"0.14.0"` | |
| operator.image.tag | string | `"0.11.1"` | |
| operator.resources | object | `{}` | |
| operator.tolerations | list | `[]` | |
| rbac.create | bool | `true` | |
@@ -62,7 +64,7 @@ Submariner enables direct networking between Pods and Services in different Kube
| submariner.globalCidr | string | `""` | |
| submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.14.0"` | |
| submariner.images.tag | string | `"0.11.1"` | |
| submariner.natEnabled | bool | `false` | |
| submariner.serviceCidr | string | `""` | |
| submariner.serviceDiscovery | bool | `true` | |
+144
View File
@@ -0,0 +1,144 @@
questions:
- variable: defaultOperatorImage
default: true
description: "Use default Submariner operator image or specify a custom one"
label: Use default Submariner operator image
type: boolean
show_subquestion_if: false
group: "Container Images"
subquestions:
- variable: operator.image.repository
default: "quay.io/submariner/submariner-operator"
description: "Submariner Operator Image Repository"
type: string
label: Submariner Operator Image Repository
- variable: operator.image.tag
default: "0.11.1"
description: "Submariner Operator Image Tag"
type: string
label: Submariner Operator Image Tag
- variable: defaultSubmarinerImages
default: true
description: "Use default Submariner images or specify custom ones"
label: Use default Submariner images
type: boolean
show_subquestion_if: false
group: "Container images"
subquestions:
- variable: submariner.images.repository
default: "quay.io/submariner"
description: "Submariner Repository (base for all non-operator images)"
type: string
label: Submariner Repository
- variable: submariner.images.tag
default: "0.11.1"
description: "Submariner Images Tag (shared for all non-operator images)"
type: string
label: Submariner Images Tag
- variable: submariner.clusterId
default: ""
description: "Enter a unique cluster ID to identify this cluster"
type: string
label: "Cluster ID"
group: "Configuration"
required: true
- variable: ipsec.psk
default: ""
description: "Enter the pre-shared key for the IPsec Cable Engine"
type: string
label: "IPsec Pre-Shared Key"
group: "Configuration"
required: true
- variable: broker.server
type: string
default: ""
group: "Broker Configuration"
label: "Broker Server"
description: "Broker server to use (without the https://)"
- variable: broker.insecure
type: boolean
default: false
show_subquestion_if: false
group: "Broker Configuration"
label: "Insecure Broker"
description: "Connect to K8s broker without validating CA"
subquestions:
- variable: broker.ca
type: string
description: "Base64 encoded broker ca.crt"
label: "Broker CA encoded in base64"
default: ""
- variable: broker.token
type: string
group: "Broker Configuration"
label: "Broker Token"
description: "Bearer token for broker"
- variable: broker.namespace
type: string
group: "Broker Configuration"
label: "Broker Namespace"
description: "Enter namespace to use on central broker"
- variable: submariner.clusterCidr
default: ""
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
type: string
label: "Cluster CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.serviceCidr
default: ""
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
type: string
label: "Service CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.serviceDiscovery
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable multicluster service discovery"
label: "Service Discovery Enabled"
- variable: broker.globalnet
type: boolean
default: false
group: "Broker Configuration"
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
label: "Globalnet Enabled"
subquestions:
- variable: submariner.globalCidr
default: ""
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
type: string
label: "Globalnet CIDR"
group: "CIDR Configuration"
required: false
- variable: submariner.natEnabled
type: boolean
default: false
group: "Advanced Configuration"
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
label: "NAT Enabled"
- variable: submariner.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable submariner debug mode"
label: "Submariner Debug Enabled"
- variable: ipsec.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable Charon debug mode"
label: "Charon Enabled"
- variable: submariner.cableDriver
type: string
default: ""
group: "Advanced Configuration"
description: "Cable driver implementation"
label: "Cable Driver"
- variable: submariner.healthcheckEnabled
type: boolean
default: true
group: "Advanced Configuration"
description: "Disable Healthcheck"
label: "Healthcheck Disabled"
-11
View File
@@ -162,17 +162,6 @@ rules:
- patch
- update
- watch
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- delete
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
@@ -19,37 +19,10 @@ spec:
clusterID: {{ .Values.submariner.clusterId }}
colorCodes: {{ .Values.submariner.colorCodes }}
debug: {{ .Values.submariner.debug }}
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
namespace: {{ .Release.Namespace }}
natEnabled: {{ .Values.submariner.natEnabled }}
repository: {{ .Values.submariner.images.repository }}
version: {{ .Values.submariner.images.tag }}
{{- with .Values.images }}
{{- if . }}
imageOverrides:
{{- if index . "submariner-operator" }}
submariner-operator: {{ index . "submariner-operator" }}
{{- end }}
{{- if index . "submariner-gateway" }}
submariner-gateway: {{ index . "submariner-gateway" }}
{{- end }}
{{- if index . "submariner-route-agent" }}
submariner-routeagent: {{ index . "submariner-route-agent" }}
{{- end }}
{{- if index . "submariner-globalnet" }}
submariner-globalnet: {{ index . "submariner-globalnet" }}
{{- end }}
{{- if index . "submariner-networkplugin-syncer" }}
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
{{- end }}
{{- if index . "lighthouse-agent" }}
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
{{- end }}
{{- if index . "lighthouse-coredns" }}
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
{{- end }}
{{- end }}
{{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}"
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
@@ -8,14 +8,6 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.operatorServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }}
---
{{- if .Values.serviceAccounts.gateway.create }}
@@ -28,14 +20,6 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }}
---
{{- if .Values.serviceAccounts.routeAgent.create }}
@@ -48,14 +32,6 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }}
---
{{- if .Values.serviceAccounts.globalnet.create }}
@@ -68,14 +44,6 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }}
---
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
@@ -88,14 +56,6 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }}
---
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
@@ -108,12 +68,4 @@ metadata:
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }}
+3 -5
View File
@@ -5,7 +5,6 @@ submariner:
clusterCidr: ""
serviceCidr: ""
globalCidr: ""
loadBalancerEnabled: false
natEnabled: false
colorCodes: blue
debug: false
@@ -15,7 +14,7 @@ submariner:
coreDNSCustomConfig: {}
images:
repository: quay.io/submariner
tag: "0.14.0-m1"
tag: "0.11.1"
broker:
server: example.k8s.apiserver
token: test
@@ -25,7 +24,6 @@ broker:
globalnet: false
rbac:
create: true
images: {}
ipsec:
psk: ""
debug: false
@@ -39,7 +37,7 @@ leadership:
operator:
image:
repository: quay.io/submariner/submariner-operator
tag: "0.14.0-m1"
tag: "0.11.1"
pullPolicy: IfNotPresent
resources: {}
tolerations: []
@@ -47,7 +45,7 @@ operator:
gateway:
image:
repository: quay.io/submariner/submariner-gateway
tag: "0.14.0-m1"
tag: "0.11.1"
serviceAccounts:
operator:
create: true