mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-21 19:40:35 +00:00
Compare commits
66
Commits
v0.17.2
...
release-0.19
+18
-9
@@ -9,15 +9,6 @@ updates:
|
|||||||
github-actions:
|
github-actions:
|
||||||
patterns:
|
patterns:
|
||||||
- "*"
|
- "*"
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.14"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
- package-ecosystem: github-actions
|
||||||
directory: '/'
|
directory: '/'
|
||||||
target-branch: "release-0.15"
|
target-branch: "release-0.15"
|
||||||
@@ -36,3 +27,21 @@ updates:
|
|||||||
github-actions:
|
github-actions:
|
||||||
patterns:
|
patterns:
|
||||||
- "*"
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.17"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.18"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
|||||||
@@ -11,6 +11,6 @@ jobs:
|
|||||||
name: PR targets branch
|
name: PR targets branch
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check that the PR targets devel
|
- name: Check that the PR targets release-0.19
|
||||||
if: ${{ github.base_ref != 'devel' }}
|
if: ${{ github.base_ref != 'release-0.19' }}
|
||||||
run: exit 1
|
run: exit 1
|
||||||
|
|||||||
@@ -19,21 +19,21 @@ jobs:
|
|||||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||||
globalnet: ['', 'globalnet']
|
globalnet: ['', 'globalnet']
|
||||||
# Run most tests against the latest K8s version
|
# Run most tests against the latest K8s version
|
||||||
k8s_version: ['1.28']
|
k8s_version: ['k8s-latest']
|
||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
include:
|
include:
|
||||||
# Bottom of supported K8s version range
|
# Bottom of supported K8s version range
|
||||||
- k8s_version: '1.26'
|
- k8s_version: 'k8s-oldest-supported'
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
||||||
with:
|
with:
|
||||||
k8s_version: ${{ matrix.k8s_version }}
|
k8s_version: ${{ matrix.k8s_version }}
|
||||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||||
|
|
||||||
- name: Post mortem
|
- name: Post mortem
|
||||||
if: failure()
|
if: failure()
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
||||||
|
|||||||
@@ -13,11 +13,11 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
||||||
|
|
||||||
- name: Post mortem
|
- name: Post mortem
|
||||||
if: failure()
|
if: failure()
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
||||||
|
|||||||
@@ -21,13 +21,13 @@ jobs:
|
|||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
||||||
with:
|
with:
|
||||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||||
|
|
||||||
- name: Post mortem
|
- name: Post mortem
|
||||||
if: failure()
|
if: failure()
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Get PR commits
|
- name: Get PR commits
|
||||||
id: 'get-pr-commits'
|
id: 'get-pr-commits'
|
||||||
uses: tim-actions/get-pr-commits@3efc1387ead42029a0d488ab98f24b7452dc3cde
|
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d
|
||||||
with:
|
with:
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
@@ -38,20 +38,20 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Set up Helm
|
- name: Set up Helm
|
||||||
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78
|
uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310
|
||||||
with:
|
with:
|
||||||
version: v3.6.0
|
version: v3.6.0
|
||||||
|
|
||||||
- name: Set up Python
|
- name: Set up Python
|
||||||
uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.13.x'
|
||||||
|
|
||||||
- name: Set up helm/chart-testing
|
- name: Set up helm/chart-testing
|
||||||
uses: helm/chart-testing-action@e6669bcd63d7cb57cb4380c33043eebe5d111992
|
uses: helm/chart-testing-action@6ec842c01de15ebb84c8627d2744a0c2f2755c9f
|
||||||
|
|
||||||
- name: Set up local helm repo
|
- name: Set up local helm repo
|
||||||
run: make local-helm-repo
|
run: make local-helm-repo
|
||||||
@@ -64,7 +64,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- name: Run gitlint
|
- name: Run gitlint
|
||||||
@@ -75,7 +75,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run helm-docs and verify docs are up-to-date
|
- name: Run helm-docs and verify docs are up-to-date
|
||||||
run: make helm-docs
|
run: make helm-docs
|
||||||
@@ -85,10 +85,10 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
check-modified-files-only: "yes"
|
check-modified-files-only: "yes"
|
||||||
@@ -99,7 +99,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
- name: Run markdownlint
|
- name: Run markdownlint
|
||||||
run: make markdownlint
|
run: make markdownlint
|
||||||
|
|
||||||
@@ -108,6 +108,6 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
- name: Run yamllint
|
- name: Run yamllint
|
||||||
run: make yamllint
|
run: make yamllint
|
||||||
|
|||||||
@@ -16,16 +16,16 @@ jobs:
|
|||||||
issues: write
|
issues: write
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||||
with:
|
with:
|
||||||
config-file: ".markdownlinkcheck.json"
|
config-file: ".markdownlinkcheck.json"
|
||||||
|
|
||||||
- name: Raise an Issue to report broken links
|
- name: Raise an Issue to report broken links
|
||||||
if: ${{ failure() }}
|
if: ${{ failure() }}
|
||||||
uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f
|
uses: peter-evans/create-issue-from-file@fca9117c27cdc29c6c4db3b86c48e4115a786710
|
||||||
with:
|
with:
|
||||||
title: Broken link detected by CI
|
title: Broken link detected by CI
|
||||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ name: Release Charts
|
|||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- devel
|
- release-0.19
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
@@ -16,7 +16,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ jobs:
|
|||||||
issues: write
|
issues: write
|
||||||
pull-requests: write
|
pull-requests: write
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@3f3b0175e8c66fb49b9a6d5a0cd1f8436d4c3ab6
|
- uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93
|
||||||
with:
|
with:
|
||||||
days-before-issue-stale: 120
|
days-before-issue-stale: 120
|
||||||
days-before-pr-stale: 14
|
days-before-pr-stale: 14
|
||||||
|
|||||||
@@ -3,5 +3,6 @@
|
|||||||
.shflags
|
.shflags
|
||||||
*.tgz
|
*.tgz
|
||||||
Makefile.dapper
|
Makefile.dapper
|
||||||
|
Makefile.shipyard
|
||||||
Dockerfile.*
|
Dockerfile.*
|
||||||
helm_repo
|
helm_repo
|
||||||
|
|||||||
+3
-2
@@ -1,3 +1,4 @@
|
|||||||
# Auto-generated, do not edit; see CODEOWNERS.in
|
# Auto-generated, do not edit; see CODEOWNERS.in
|
||||||
* @Oats87 @skitt @sridhargaddam @tpantelis
|
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
|
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||||
|
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
|
||||||
|
|||||||
+5
-1
@@ -1,5 +1,9 @@
|
|||||||
@dfarrell07 *.md
|
@aswinsuryan Makefile
|
||||||
|
@dfarrell07 *.md Makefile
|
||||||
|
@maayanf24 Makefile
|
||||||
@Oats87 *
|
@Oats87 *
|
||||||
@skitt *
|
@skitt *
|
||||||
@sridhargaddam *
|
@sridhargaddam *
|
||||||
@tpantelis *
|
@tpantelis *
|
||||||
|
@vthapar *
|
||||||
|
@yboaron Makefile
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
BASE_BRANCH ?= devel
|
BASE_BRANCH ?= release-0.19
|
||||||
export BASE_BRANCH
|
export BASE_BRANCH
|
||||||
export HELM_REPO_LOCATION=./helm_repo
|
export HELM_REPO_LOCATION=./helm_repo
|
||||||
|
|
||||||
@@ -17,7 +17,7 @@ endif
|
|||||||
export DEPLOYTOOL = helm
|
export DEPLOYTOOL = helm
|
||||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||||
CHARTS_DIR=charts
|
CHARTS_DIR=charts
|
||||||
CHARTS_VERSION=0.17.0-m3
|
CHARTS_VERSION=0.19.4
|
||||||
HELM_DOCS_VERSION=0.15.0
|
HELM_DOCS_VERSION=0.15.0
|
||||||
REPO_URL=$(shell git config remote.origin.url)
|
REPO_URL=$(shell git config remote.origin.url)
|
||||||
|
|
||||||
|
|||||||
@@ -58,6 +58,8 @@ Submariner enables direct networking between Pods and Services in different Kube
|
|||||||
| submariner.coreDNSCustomConfig | object | `{}` | |
|
| submariner.coreDNSCustomConfig | object | `{}` | |
|
||||||
| submariner.debug | bool | `false` | |
|
| submariner.debug | bool | `false` | |
|
||||||
| submariner.globalCidr | string | `""` | |
|
| submariner.globalCidr | string | `""` | |
|
||||||
|
| submariner.clustersetIpCidr | string | `""` | |
|
||||||
|
| submariner.clustersetIpEnabled | bool | `false` | |
|
||||||
| submariner.healthcheckEnabled | bool | `true` | |
|
| submariner.healthcheckEnabled | bool | `true` | |
|
||||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||||
| submariner.images.tag | string | `"0.14.0"` | |
|
| submariner.images.tag | string | `"0.14.0"` | |
|
||||||
|
|||||||
@@ -3,8 +3,7 @@ apiVersion: apiextensions.k8s.io/v1
|
|||||||
kind: CustomResourceDefinition
|
kind: CustomResourceDefinition
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
controller-gen.kubebuilder.io/version: v0.4.1
|
controller-gen.kubebuilder.io/version: v0.12.1
|
||||||
creationTimestamp: null
|
|
||||||
name: submariners.submariner.io
|
name: submariners.submariner.io
|
||||||
spec:
|
spec:
|
||||||
group: submariner.io
|
group: submariner.io
|
||||||
@@ -18,7 +17,7 @@ spec:
|
|||||||
- name: v1alpha1
|
- name: v1alpha1
|
||||||
schema:
|
schema:
|
||||||
openAPIV3Schema:
|
openAPIV3Schema:
|
||||||
description: Submariner is the Schema for the submariners API
|
description: Submariner is the Schema for the submariners API.
|
||||||
properties:
|
properties:
|
||||||
apiVersion:
|
apiVersion:
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
@@ -33,43 +32,72 @@ spec:
|
|||||||
metadata:
|
metadata:
|
||||||
type: object
|
type: object
|
||||||
spec:
|
spec:
|
||||||
description: SubmarinerSpec defines the desired state of Submariner
|
description: SubmarinerSpec defines the desired state of Submariner.
|
||||||
properties:
|
properties:
|
||||||
|
airGappedDeployment:
|
||||||
|
type: boolean
|
||||||
broker:
|
broker:
|
||||||
|
description: Type of broker (must be "k8s").
|
||||||
type: string
|
type: string
|
||||||
brokerK8sApiServer:
|
brokerK8sApiServer:
|
||||||
|
description: The broker API URL.
|
||||||
type: string
|
type: string
|
||||||
brokerK8sApiServerToken:
|
brokerK8sApiServerToken:
|
||||||
|
description: The broker API Token.
|
||||||
type: string
|
type: string
|
||||||
brokerK8sCA:
|
brokerK8sCA:
|
||||||
|
description: The broker certificate authority.
|
||||||
type: string
|
type: string
|
||||||
brokerK8sInsecure:
|
brokerK8sInsecure:
|
||||||
type: boolean
|
type: boolean
|
||||||
brokerK8sRemoteNamespace:
|
brokerK8sRemoteNamespace:
|
||||||
|
description: The Broker namespace.
|
||||||
|
type: string
|
||||||
|
brokerK8sSecret:
|
||||||
type: string
|
type: string
|
||||||
cableDriver:
|
cableDriver:
|
||||||
|
description: Cable driver implementation - any of [libreswan, wireguard,
|
||||||
|
vxlan].
|
||||||
type: string
|
type: string
|
||||||
ceIPSecDebug:
|
ceIPSecDebug:
|
||||||
|
description: Enable logging IPsec debugging information.
|
||||||
type: boolean
|
type: boolean
|
||||||
ceIPSecForceUDPEncaps:
|
ceIPSecForceUDPEncaps:
|
||||||
|
description: Force UDP encapsulation for IPsec.
|
||||||
type: boolean
|
type: boolean
|
||||||
ceIPSecIKEPort:
|
ceIPSecIKEPort:
|
||||||
|
description: The IPsec IKE port (500 usually).
|
||||||
type: integer
|
type: integer
|
||||||
ceIPSecNATTPort:
|
ceIPSecNATTPort:
|
||||||
|
description: The IPsec NAT traversal port (4500 usually).
|
||||||
type: integer
|
type: integer
|
||||||
ceIPSecPSK:
|
ceIPSecPSK:
|
||||||
|
description: The IPsec Pre-Shared Key which must be identical in all
|
||||||
|
route agents across the cluster.
|
||||||
|
type: string
|
||||||
|
ceIPSecPSKSecret:
|
||||||
type: string
|
type: string
|
||||||
ceIPSecPreferredServer:
|
ceIPSecPreferredServer:
|
||||||
|
description: Enable this cluster as a preferred server for data-plane
|
||||||
|
connections.
|
||||||
type: boolean
|
type: boolean
|
||||||
clusterCIDR:
|
clusterCIDR:
|
||||||
|
description: The cluster CIDR.
|
||||||
type: string
|
type: string
|
||||||
clusterID:
|
clusterID:
|
||||||
|
description: The cluster ID used to identify the tunnels.
|
||||||
|
type: string
|
||||||
|
clustersetIPCIDR:
|
||||||
|
description: ClustersetIP CIDR for allocating ClustersetIPs to exported
|
||||||
|
services.
|
||||||
type: string
|
type: string
|
||||||
colorCodes:
|
colorCodes:
|
||||||
type: string
|
type: string
|
||||||
connectionHealthCheck:
|
connectionHealthCheck:
|
||||||
|
description: The gateway connection health check.
|
||||||
properties:
|
properties:
|
||||||
enabled:
|
enabled:
|
||||||
|
description: Enable the connection health check.
|
||||||
type: boolean
|
type: boolean
|
||||||
intervalSeconds:
|
intervalSeconds:
|
||||||
description: The interval at which health check pings are sent.
|
description: The interval at which health check pings are sent.
|
||||||
@@ -82,47 +110,111 @@ spec:
|
|||||||
type: integer
|
type: integer
|
||||||
type: object
|
type: object
|
||||||
coreDNSCustomConfig:
|
coreDNSCustomConfig:
|
||||||
|
description: Name of the custom CoreDNS configmap to configure forwarding
|
||||||
|
to Lighthouse. It should be in <namespace>/<name> format where <namespace>
|
||||||
|
is optional and defaults to kube-system.
|
||||||
properties:
|
properties:
|
||||||
configMapName:
|
configMapName:
|
||||||
|
description: Name of the custom CoreDNS configmap.
|
||||||
type: string
|
type: string
|
||||||
namespace:
|
namespace:
|
||||||
|
description: Namespace of the custom CoreDNS configmap.
|
||||||
type: string
|
type: string
|
||||||
type: object
|
type: object
|
||||||
customDomains:
|
customDomains:
|
||||||
|
description: List of domains to use for multi-cluster service discovery.
|
||||||
items:
|
items:
|
||||||
type: string
|
type: string
|
||||||
type: array
|
type: array
|
||||||
x-kubernetes-list-type: set
|
x-kubernetes-list-type: set
|
||||||
debug:
|
debug:
|
||||||
|
description: Enable operator debugging.
|
||||||
type: boolean
|
type: boolean
|
||||||
globalCIDR:
|
globalCIDR:
|
||||||
|
description: The Global CIDR super-net range for allocating GlobalCIDRs
|
||||||
|
to each cluster.
|
||||||
type: string
|
type: string
|
||||||
|
haltOnCertificateError:
|
||||||
|
description: Halt on certificate error (so the pod gets restarted).
|
||||||
|
type: boolean
|
||||||
imageOverrides:
|
imageOverrides:
|
||||||
additionalProperties:
|
additionalProperties:
|
||||||
type: string
|
type: string
|
||||||
|
description: Override component images.
|
||||||
type: object
|
type: object
|
||||||
loadBalancerEnabled:
|
loadBalancerEnabled:
|
||||||
|
description: Enable automatic Load Balancer in front of the gateways.
|
||||||
type: boolean
|
type: boolean
|
||||||
namespace:
|
namespace:
|
||||||
|
description: The namespace in which to deploy the submariner operator.
|
||||||
type: string
|
type: string
|
||||||
natEnabled:
|
natEnabled:
|
||||||
|
description: Enable NAT between clusters.
|
||||||
type: boolean
|
type: boolean
|
||||||
|
nodeSelector:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
repository:
|
repository:
|
||||||
|
description: The image repository.
|
||||||
type: string
|
type: string
|
||||||
serviceCIDR:
|
serviceCIDR:
|
||||||
|
description: The service CIDR.
|
||||||
type: string
|
type: string
|
||||||
serviceDiscoveryEnabled:
|
serviceDiscoveryEnabled:
|
||||||
|
description: Enable support for Service Discovery (Lighthouse).
|
||||||
type: boolean
|
type: boolean
|
||||||
|
clustersetIPEnabled:
|
||||||
|
description: Enable ClustersetIP default for services exported on this
|
||||||
|
cluster.
|
||||||
|
type: boolean
|
||||||
|
tolerations:
|
||||||
|
items:
|
||||||
|
description: The pod this Toleration is attached to tolerates any
|
||||||
|
taint that matches the triple <key,value,effect> using the matching
|
||||||
|
operator <operator>.
|
||||||
|
properties:
|
||||||
|
effect:
|
||||||
|
description: Effect indicates the taint effect to match. Empty
|
||||||
|
means match all taint effects. When specified, allowed values
|
||||||
|
are NoSchedule, PreferNoSchedule and NoExecute.
|
||||||
|
type: string
|
||||||
|
key:
|
||||||
|
description: Key is the taint key that the toleration applies
|
||||||
|
to. Empty means match all taint keys. If the key is empty,
|
||||||
|
operator must be Exists; this combination means to match all
|
||||||
|
values and all keys.
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
description: Operator represents a key's relationship to the
|
||||||
|
value. Valid operators are Exists and Equal. Defaults to Equal.
|
||||||
|
Exists is equivalent to wildcard for value, so that a pod
|
||||||
|
can tolerate all taints of a particular category.
|
||||||
|
type: string
|
||||||
|
tolerationSeconds:
|
||||||
|
description: TolerationSeconds represents the period of time
|
||||||
|
the toleration (which must be of effect NoExecute, otherwise
|
||||||
|
this field is ignored) tolerates the taint. By default, it
|
||||||
|
is not set, which means tolerate the taint forever (do not
|
||||||
|
evict). Zero and negative values will be treated as 0 (evict
|
||||||
|
immediately) by the system.
|
||||||
|
format: int64
|
||||||
|
type: integer
|
||||||
|
value:
|
||||||
|
description: Value is the taint value the toleration matches
|
||||||
|
to. If the operator is Exists, the value should be empty,
|
||||||
|
otherwise just a regular string.
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
version:
|
version:
|
||||||
|
description: The image tag.
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- broker
|
- broker
|
||||||
- brokerK8sApiServer
|
- brokerK8sApiServer
|
||||||
- brokerK8sApiServerToken
|
|
||||||
- brokerK8sCA
|
|
||||||
- brokerK8sRemoteNamespace
|
- brokerK8sRemoteNamespace
|
||||||
- ceIPSecDebug
|
- ceIPSecDebug
|
||||||
- ceIPSecPSK
|
|
||||||
- clusterCIDR
|
- clusterCIDR
|
||||||
- clusterID
|
- clusterID
|
||||||
- debug
|
- debug
|
||||||
@@ -131,15 +223,23 @@ spec:
|
|||||||
- serviceCIDR
|
- serviceCIDR
|
||||||
type: object
|
type: object
|
||||||
status:
|
status:
|
||||||
description: SubmarinerStatus defines the observed state of Submariner
|
description: SubmarinerStatus defines the observed state of Submariner.
|
||||||
properties:
|
properties:
|
||||||
|
airGappedDeployment:
|
||||||
|
type: boolean
|
||||||
clusterCIDR:
|
clusterCIDR:
|
||||||
|
description: The current cluster CIDR.
|
||||||
type: string
|
type: string
|
||||||
clusterID:
|
clusterID:
|
||||||
|
description: The current cluster ID.
|
||||||
|
type: string
|
||||||
|
clustersetIPCIDR:
|
||||||
|
description: The current clustersetIP CIDR.
|
||||||
type: string
|
type: string
|
||||||
colorCodes:
|
colorCodes:
|
||||||
type: string
|
type: string
|
||||||
deploymentInfo:
|
deploymentInfo:
|
||||||
|
description: Information about the deployment.
|
||||||
properties:
|
properties:
|
||||||
cloudProvider:
|
cloudProvider:
|
||||||
type: string
|
type: string
|
||||||
@@ -151,6 +251,7 @@ spec:
|
|||||||
type: string
|
type: string
|
||||||
type: object
|
type: object
|
||||||
gatewayDaemonSetStatus:
|
gatewayDaemonSetStatus:
|
||||||
|
description: The status of the gateway DaemonSet.
|
||||||
properties:
|
properties:
|
||||||
lastResourceVersion:
|
lastResourceVersion:
|
||||||
type: string
|
type: string
|
||||||
@@ -174,7 +275,7 @@ spec:
|
|||||||
description: Details about a terminated container
|
description: Details about a terminated container
|
||||||
properties:
|
properties:
|
||||||
containerID:
|
containerID:
|
||||||
description: Container's ID in the format 'docker://<container_id>'
|
description: Container's ID in the format '<type>://<container_id>'
|
||||||
type: string
|
type: string
|
||||||
exitCode:
|
exitCode:
|
||||||
description: Exit status from the last termination of
|
description: Exit status from the last termination of
|
||||||
@@ -287,9 +388,9 @@ spec:
|
|||||||
format: int32
|
format: int32
|
||||||
type: integer
|
type: integer
|
||||||
numberReady:
|
numberReady:
|
||||||
description: The number of nodes that should be running the
|
description: numberReady is the number of nodes that should
|
||||||
daemon pod and have one or more of the daemon pod running
|
be running the daemon pod and have one or more of the daemon
|
||||||
and ready.
|
pod running with a Ready Condition.
|
||||||
format: int32
|
format: int32
|
||||||
type: integer
|
type: integer
|
||||||
numberUnavailable:
|
numberUnavailable:
|
||||||
@@ -318,6 +419,7 @@ spec:
|
|||||||
- mismatchedContainerImages
|
- mismatchedContainerImages
|
||||||
type: object
|
type: object
|
||||||
gateways:
|
gateways:
|
||||||
|
description: Status of the gateways in the cluster.
|
||||||
items:
|
items:
|
||||||
properties:
|
properties:
|
||||||
connections:
|
connections:
|
||||||
@@ -444,8 +546,10 @@ spec:
|
|||||||
type: object
|
type: object
|
||||||
type: array
|
type: array
|
||||||
globalCIDR:
|
globalCIDR:
|
||||||
|
description: The current global CIDR.
|
||||||
type: string
|
type: string
|
||||||
globalnetDaemonSetStatus:
|
globalnetDaemonSetStatus:
|
||||||
|
description: The status of the Globalnet DaemonSet.
|
||||||
properties:
|
properties:
|
||||||
lastResourceVersion:
|
lastResourceVersion:
|
||||||
type: string
|
type: string
|
||||||
@@ -469,7 +573,7 @@ spec:
|
|||||||
description: Details about a terminated container
|
description: Details about a terminated container
|
||||||
properties:
|
properties:
|
||||||
containerID:
|
containerID:
|
||||||
description: Container's ID in the format 'docker://<container_id>'
|
description: Container's ID in the format '<type>://<container_id>'
|
||||||
type: string
|
type: string
|
||||||
exitCode:
|
exitCode:
|
||||||
description: Exit status from the last termination of
|
description: Exit status from the last termination of
|
||||||
@@ -582,9 +686,9 @@ spec:
|
|||||||
format: int32
|
format: int32
|
||||||
type: integer
|
type: integer
|
||||||
numberReady:
|
numberReady:
|
||||||
description: The number of nodes that should be running the
|
description: numberReady is the number of nodes that should
|
||||||
daemon pod and have one or more of the daemon pod running
|
be running the daemon pod and have one or more of the daemon
|
||||||
and ready.
|
pod running with a Ready Condition.
|
||||||
format: int32
|
format: int32
|
||||||
type: integer
|
type: integer
|
||||||
numberUnavailable:
|
numberUnavailable:
|
||||||
@@ -613,6 +717,7 @@ spec:
|
|||||||
- mismatchedContainerImages
|
- mismatchedContainerImages
|
||||||
type: object
|
type: object
|
||||||
loadBalancerStatus:
|
loadBalancerStatus:
|
||||||
|
description: The status of the load balancer DaemonSet.
|
||||||
properties:
|
properties:
|
||||||
status:
|
status:
|
||||||
description: LoadBalancerStatus represents the status of a load-balancer.
|
description: LoadBalancerStatus represents the status of a load-balancer.
|
||||||
@@ -634,15 +739,53 @@ spec:
|
|||||||
description: IP is set for load-balancer ingress points
|
description: IP is set for load-balancer ingress points
|
||||||
that are IP based (typically GCE or OpenStack load-balancers)
|
that are IP based (typically GCE or OpenStack load-balancers)
|
||||||
type: string
|
type: string
|
||||||
|
ports:
|
||||||
|
description: Ports is a list of records of service ports
|
||||||
|
If used, every port defined in the service should
|
||||||
|
have an entry in it
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
error:
|
||||||
|
description: 'Error is to record the problem with
|
||||||
|
the service port The format of the error shall
|
||||||
|
comply with the following rules: - built-in
|
||||||
|
error values shall be specified in this file
|
||||||
|
and those shall use CamelCase names - cloud
|
||||||
|
provider specific error values must have names
|
||||||
|
that comply with the format foo.example.com/CamelCase.
|
||||||
|
--- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)'
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
port:
|
||||||
|
description: Port is the port number of the service
|
||||||
|
port of which status is recorded here
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
protocol:
|
||||||
|
default: TCP
|
||||||
|
description: 'Protocol is the protocol of the
|
||||||
|
service port of which status is recorded here
|
||||||
|
The supported values are: "TCP", "UDP", "SCTP"'
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- port
|
||||||
|
- protocol
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
x-kubernetes-list-type: atomic
|
||||||
type: object
|
type: object
|
||||||
type: array
|
type: array
|
||||||
type: object
|
type: object
|
||||||
type: object
|
type: object
|
||||||
natEnabled:
|
natEnabled:
|
||||||
|
description: The current NAT status.
|
||||||
type: boolean
|
type: boolean
|
||||||
networkPlugin:
|
networkPlugin:
|
||||||
|
description: The current network plugin.
|
||||||
type: string
|
type: string
|
||||||
routeAgentDaemonSetStatus:
|
routeAgentDaemonSetStatus:
|
||||||
|
description: The status of the route agent DaemonSet.
|
||||||
properties:
|
properties:
|
||||||
lastResourceVersion:
|
lastResourceVersion:
|
||||||
type: string
|
type: string
|
||||||
@@ -666,7 +809,7 @@ spec:
|
|||||||
description: Details about a terminated container
|
description: Details about a terminated container
|
||||||
properties:
|
properties:
|
||||||
containerID:
|
containerID:
|
||||||
description: Container's ID in the format 'docker://<container_id>'
|
description: Container's ID in the format '<type>://<container_id>'
|
||||||
type: string
|
type: string
|
||||||
exitCode:
|
exitCode:
|
||||||
description: Exit status from the last termination of
|
description: Exit status from the last termination of
|
||||||
@@ -779,9 +922,9 @@ spec:
|
|||||||
format: int32
|
format: int32
|
||||||
type: integer
|
type: integer
|
||||||
numberReady:
|
numberReady:
|
||||||
description: The number of nodes that should be running the
|
description: numberReady is the number of nodes that should
|
||||||
daemon pod and have one or more of the daemon pod running
|
be running the daemon pod and have one or more of the daemon
|
||||||
and ready.
|
pod running with a Ready Condition.
|
||||||
format: int32
|
format: int32
|
||||||
type: integer
|
type: integer
|
||||||
numberUnavailable:
|
numberUnavailable:
|
||||||
@@ -810,6 +953,11 @@ spec:
|
|||||||
- mismatchedContainerImages
|
- mismatchedContainerImages
|
||||||
type: object
|
type: object
|
||||||
serviceCIDR:
|
serviceCIDR:
|
||||||
|
description: The current service CIDR.
|
||||||
|
type: string
|
||||||
|
version:
|
||||||
|
description: The image version in use by the various Submariner DaemonSets
|
||||||
|
and Deployments.
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- clusterID
|
- clusterID
|
||||||
@@ -820,19 +968,12 @@ spec:
|
|||||||
storage: true
|
storage: true
|
||||||
subresources:
|
subresources:
|
||||||
status: {}
|
status: {}
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
---
|
---
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
kind: CustomResourceDefinition
|
kind: CustomResourceDefinition
|
||||||
metadata:
|
metadata:
|
||||||
annotations:
|
annotations:
|
||||||
controller-gen.kubebuilder.io/version: v0.4.1
|
controller-gen.kubebuilder.io/version: v0.12.1
|
||||||
creationTimestamp: null
|
|
||||||
name: servicediscoveries.submariner.io
|
name: servicediscoveries.submariner.io
|
||||||
spec:
|
spec:
|
||||||
group: submariner.io
|
group: submariner.io
|
||||||
@@ -846,7 +987,7 @@ spec:
|
|||||||
- name: v1alpha1
|
- name: v1alpha1
|
||||||
schema:
|
schema:
|
||||||
openAPIV3Schema:
|
openAPIV3Schema:
|
||||||
description: ServiceDiscovery is the Schema for the servicediscoveries API
|
description: ServiceDiscovery is the Schema for the servicediscoveries API.
|
||||||
properties:
|
properties:
|
||||||
apiVersion:
|
apiVersion:
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
@@ -861,7 +1002,7 @@ spec:
|
|||||||
metadata:
|
metadata:
|
||||||
type: object
|
type: object
|
||||||
spec:
|
spec:
|
||||||
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery
|
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery.
|
||||||
properties:
|
properties:
|
||||||
brokerK8sApiServer:
|
brokerK8sApiServer:
|
||||||
type: string
|
type: string
|
||||||
@@ -873,13 +1014,19 @@ spec:
|
|||||||
type: boolean
|
type: boolean
|
||||||
brokerK8sRemoteNamespace:
|
brokerK8sRemoteNamespace:
|
||||||
type: string
|
type: string
|
||||||
|
brokerK8sSecret:
|
||||||
|
type: string
|
||||||
clusterID:
|
clusterID:
|
||||||
type: string
|
type: string
|
||||||
|
clustersetIPCIDR:
|
||||||
|
type: string
|
||||||
coreDNSCustomConfig:
|
coreDNSCustomConfig:
|
||||||
properties:
|
properties:
|
||||||
configMapName:
|
configMapName:
|
||||||
|
description: Name of the custom CoreDNS configmap.
|
||||||
type: string
|
type: string
|
||||||
namespace:
|
namespace:
|
||||||
|
description: Namespace of the custom CoreDNS configmap.
|
||||||
type: string
|
type: string
|
||||||
type: object
|
type: object
|
||||||
customDomains:
|
customDomains:
|
||||||
@@ -891,27 +1038,72 @@ spec:
|
|||||||
type: boolean
|
type: boolean
|
||||||
globalnetEnabled:
|
globalnetEnabled:
|
||||||
type: boolean
|
type: boolean
|
||||||
|
haltOnCertificateError:
|
||||||
|
type: boolean
|
||||||
|
clustersetIPEnabled:
|
||||||
|
type: boolean
|
||||||
imageOverrides:
|
imageOverrides:
|
||||||
additionalProperties:
|
additionalProperties:
|
||||||
type: string
|
type: string
|
||||||
type: object
|
type: object
|
||||||
namespace:
|
namespace:
|
||||||
type: string
|
type: string
|
||||||
|
nodeSelector:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
repository:
|
repository:
|
||||||
type: string
|
type: string
|
||||||
|
tolerations:
|
||||||
|
items:
|
||||||
|
description: The pod this Toleration is attached to tolerates any
|
||||||
|
taint that matches the triple <key,value,effect> using the matching
|
||||||
|
operator <operator>.
|
||||||
|
properties:
|
||||||
|
effect:
|
||||||
|
description: Effect indicates the taint effect to match. Empty
|
||||||
|
means match all taint effects. When specified, allowed values
|
||||||
|
are NoSchedule, PreferNoSchedule and NoExecute.
|
||||||
|
type: string
|
||||||
|
key:
|
||||||
|
description: Key is the taint key that the toleration applies
|
||||||
|
to. Empty means match all taint keys. If the key is empty,
|
||||||
|
operator must be Exists; this combination means to match all
|
||||||
|
values and all keys.
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
description: Operator represents a key's relationship to the
|
||||||
|
value. Valid operators are Exists and Equal. Defaults to Equal.
|
||||||
|
Exists is equivalent to wildcard for value, so that a pod
|
||||||
|
can tolerate all taints of a particular category.
|
||||||
|
type: string
|
||||||
|
tolerationSeconds:
|
||||||
|
description: TolerationSeconds represents the period of time
|
||||||
|
the toleration (which must be of effect NoExecute, otherwise
|
||||||
|
this field is ignored) tolerates the taint. By default, it
|
||||||
|
is not set, which means tolerate the taint forever (do not
|
||||||
|
evict). Zero and negative values will be treated as 0 (evict
|
||||||
|
immediately) by the system.
|
||||||
|
format: int64
|
||||||
|
type: integer
|
||||||
|
value:
|
||||||
|
description: Value is the taint value the toleration matches
|
||||||
|
to. If the operator is Exists, the value should be empty,
|
||||||
|
otherwise just a regular string.
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
version:
|
version:
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- brokerK8sApiServer
|
- brokerK8sApiServer
|
||||||
- brokerK8sApiServerToken
|
|
||||||
- brokerK8sCA
|
|
||||||
- brokerK8sRemoteNamespace
|
- brokerK8sRemoteNamespace
|
||||||
- clusterID
|
- clusterID
|
||||||
- debug
|
- debug
|
||||||
- namespace
|
- namespace
|
||||||
type: object
|
type: object
|
||||||
status:
|
status:
|
||||||
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
|
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery.
|
||||||
properties:
|
properties:
|
||||||
deploymentInfo:
|
deploymentInfo:
|
||||||
properties:
|
properties:
|
||||||
@@ -930,12 +1122,6 @@ spec:
|
|||||||
storage: true
|
storage: true
|
||||||
subresources:
|
subresources:
|
||||||
status: {}
|
status: {}
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
---
|
---
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
kind: CustomResourceDefinition
|
kind: CustomResourceDefinition
|
||||||
|
|||||||
@@ -12,28 +12,38 @@ rules:
|
|||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
- pods
|
# For metrics
|
||||||
- services
|
- services
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
verbs:
|
||||||
- '*'
|
- get
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
# Temporarily needed for network-plugin syncer removal
|
||||||
|
- serviceaccounts
|
||||||
|
resourceNames:
|
||||||
|
- submariner-networkplugin-syncer
|
||||||
|
verbs:
|
||||||
|
- delete
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- apps
|
- apps
|
||||||
resources:
|
resources:
|
||||||
- deployments
|
- deployments
|
||||||
- daemonsets
|
- daemonsets
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
verbs:
|
||||||
- '*'
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- monitoring.coreos.com
|
- monitoring.coreos.com
|
||||||
resources:
|
resources:
|
||||||
|
# Needed for openshift monitoring
|
||||||
- servicemonitors
|
- servicemonitors
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
@@ -47,24 +57,36 @@ rules:
|
|||||||
verbs:
|
verbs:
|
||||||
- update
|
- update
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- pods
|
- brokers
|
||||||
verbs:
|
- brokers/status
|
||||||
- get
|
- submariners
|
||||||
- apiGroups:
|
- submariners/status
|
||||||
- apps
|
- servicediscoveries
|
||||||
resources:
|
- servicediscoveries/status
|
||||||
- replicasets
|
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- '*'
|
- gateways
|
||||||
- servicediscoveries
|
|
||||||
verbs:
|
verbs:
|
||||||
- '*'
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- submariner.io
|
||||||
|
resources:
|
||||||
|
- submariners/finalizers
|
||||||
|
- servicediscoveries/finalizers
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
---
|
---
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
@@ -97,71 +119,23 @@ rules:
|
|||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
- pods
|
- pods
|
||||||
- services
|
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- submariner-operator
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
- update
|
||||||
- apiGroups:
|
- patch
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- '*'
|
- clusters
|
||||||
- servicediscoveries
|
- endpoints
|
||||||
|
- gateways
|
||||||
verbs:
|
verbs:
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- watch
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- coordination.k8s.io
|
- coordination.k8s.io
|
||||||
resources:
|
resources:
|
||||||
@@ -203,74 +177,25 @@ metadata:
|
|||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
- endpoints
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- submariner-operator
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- '*'
|
- gatewayroutes
|
||||||
- servicediscoveries
|
- nongatewayroutes
|
||||||
verbs:
|
verbs:
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- watch
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- delete
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
@@ -301,75 +226,15 @@ metadata:
|
|||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.name" . }}
|
app: {{ template "submariner.name" . }}
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- services/finalizers
|
|
||||||
- endpoints
|
|
||||||
- persistentvolumeclaims
|
|
||||||
- events
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
- replicasets
|
|
||||||
- statefulsets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- submariner-operator
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- '*'
|
- gateways
|
||||||
- servicediscoveries
|
|
||||||
verbs:
|
verbs:
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- lighthouse.submariner.io
|
|
||||||
resources:
|
|
||||||
- '*'
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- watch
|
- watch
|
||||||
|
- update
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- coordination.k8s.io
|
- coordination.k8s.io
|
||||||
resources:
|
resources:
|
||||||
@@ -435,9 +300,10 @@ rules:
|
|||||||
- update
|
- update
|
||||||
- delete
|
- delete
|
||||||
- watch
|
- watch
|
||||||
- apiGroups: # pods, services and nodes are looked up to figure out network settings
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
|
# Needed for network settings discovery
|
||||||
- pods
|
- pods
|
||||||
- services
|
- services
|
||||||
- nodes
|
- nodes
|
||||||
@@ -451,27 +317,20 @@ rules:
|
|||||||
- dnses
|
- dnses
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
- update
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- config.openshift.io
|
- config.openshift.io
|
||||||
resources:
|
resources:
|
||||||
|
# Needed for network settings discovery
|
||||||
- networks
|
- networks
|
||||||
|
resourceNames:
|
||||||
|
- cluster
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- namespaces
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- monitoring.coreos.com
|
- monitoring.coreos.com
|
||||||
resources:
|
resources:
|
||||||
|
# Needed for openshift monitoring
|
||||||
- servicemonitors
|
- servicemonitors
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
@@ -479,11 +338,21 @@ rules:
|
|||||||
- apiGroups:
|
- apiGroups:
|
||||||
- apps
|
- apps
|
||||||
resources:
|
resources:
|
||||||
|
# Needed for Flannel CNI discovery
|
||||||
- daemonsets
|
- daemonsets
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
|
||||||
- list
|
- list
|
||||||
- watch
|
- apiGroups:
|
||||||
|
- rbac.authorization.k8s.io
|
||||||
|
resources:
|
||||||
|
# Temporarily needed for network-plugin syncer removal
|
||||||
|
- clusterroles
|
||||||
|
- clusterrolebindings
|
||||||
|
resourceNames:
|
||||||
|
- ocp-submariner-networkplugin-syncer
|
||||||
|
- submariner-networkplugin-syncer
|
||||||
|
verbs:
|
||||||
|
- delete
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
@@ -542,21 +411,7 @@ rules:
|
|||||||
- configmaps
|
- configmaps
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- apiextensions.k8s.io
|
|
||||||
resources:
|
|
||||||
- customresourcedefinitions
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups: # pods and services are looked up to figure out network settings
|
|
||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
- pods
|
- pods
|
||||||
@@ -566,32 +421,6 @@ rules:
|
|||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- apiGroups:
|
|
||||||
- operator.openshift.io
|
|
||||||
resources:
|
|
||||||
- dnses
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- config.openshift.io
|
|
||||||
resources:
|
|
||||||
- networks
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- endpoints
|
|
||||||
- gateways
|
|
||||||
- clusters
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
@@ -623,57 +452,41 @@ metadata:
|
|||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- apiextensions.k8s.io
|
|
||||||
resources:
|
|
||||||
- customresourcedefinitions
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups: # pods and services are looked up to figure out network settings
|
|
||||||
- ""
|
|
||||||
resources:
|
resources:
|
||||||
- pods
|
- pods
|
||||||
- services
|
- services
|
||||||
|
- secrets
|
||||||
|
- configmaps
|
||||||
|
- endpoints
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- operator.openshift.io
|
|
||||||
resources:
|
|
||||||
- dnses
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- config.openshift.io
|
- config.openshift.io
|
||||||
resources:
|
resources:
|
||||||
- networks
|
- networks
|
||||||
|
resourceNames:
|
||||||
|
- cluster
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
|
resources:
|
||||||
|
- nodes
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- update
|
- apiGroups:
|
||||||
|
- projectcalico.org
|
||||||
resources:
|
resources:
|
||||||
- nodes
|
- ippools
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- update
|
||||||
|
- deletecollection
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
@@ -708,13 +521,10 @@ rules:
|
|||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
- pods
|
- pods
|
||||||
- namespaces
|
|
||||||
- nodes
|
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- update
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
@@ -730,8 +540,8 @@ rules:
|
|||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- endpoints
|
|
||||||
- clusters
|
- clusters
|
||||||
|
- endpoints
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
@@ -756,7 +566,7 @@ rules:
|
|||||||
- apiGroups:
|
- apiGroups:
|
||||||
- multicluster.x-k8s.io
|
- multicluster.x-k8s.io
|
||||||
resources:
|
resources:
|
||||||
- "serviceexports"
|
- serviceexports
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
@@ -811,7 +621,6 @@ rules:
|
|||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- update
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- discovery.k8s.io
|
- discovery.k8s.io
|
||||||
resources:
|
resources:
|
||||||
@@ -828,8 +637,8 @@ rules:
|
|||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- "gateways"
|
- gateways
|
||||||
- "globalingressips"
|
- globalingressips
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
@@ -837,7 +646,8 @@ rules:
|
|||||||
- apiGroups:
|
- apiGroups:
|
||||||
- multicluster.x-k8s.io
|
- multicluster.x-k8s.io
|
||||||
resources:
|
resources:
|
||||||
- "*"
|
- serviceimports
|
||||||
|
- serviceimports/status
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
- get
|
- get
|
||||||
@@ -845,6 +655,20 @@ rules:
|
|||||||
- watch
|
- watch
|
||||||
- update
|
- update
|
||||||
- delete
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- multicluster.x-k8s.io
|
||||||
|
resources:
|
||||||
|
- serviceexports
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- multicluster.x-k8s.io
|
||||||
|
resources:
|
||||||
|
- serviceexports/status
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
@@ -869,34 +693,19 @@ kind: ClusterRole
|
|||||||
metadata:
|
metadata:
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- services
|
|
||||||
- namespaces
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- discovery.k8s.io
|
- discovery.k8s.io
|
||||||
resources:
|
resources:
|
||||||
- endpointslices
|
- endpointslices
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- deletecollection
|
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- submariner.io
|
- submariner.io
|
||||||
resources:
|
resources:
|
||||||
- "gateways"
|
- gateways
|
||||||
- "submariners"
|
- submariners
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
@@ -904,14 +713,11 @@ rules:
|
|||||||
- apiGroups:
|
- apiGroups:
|
||||||
- multicluster.x-k8s.io
|
- multicluster.x-k8s.io
|
||||||
resources:
|
resources:
|
||||||
- "*"
|
- serviceimports
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
|
|||||||
@@ -52,6 +52,8 @@ spec:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
||||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||||
|
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
|
||||||
|
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
|
||||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||||
cableDriver: {{ .Values.submariner.cableDriver }}
|
cableDriver: {{ .Values.submariner.cableDriver }}
|
||||||
connectionHealthCheck:
|
connectionHealthCheck:
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ submariner:
|
|||||||
clusterCidr: ""
|
clusterCidr: ""
|
||||||
serviceCidr: ""
|
serviceCidr: ""
|
||||||
globalCidr: ""
|
globalCidr: ""
|
||||||
|
clustersetIpCidr: ""
|
||||||
|
clustersetIpEnabled: false
|
||||||
loadBalancerEnabled: false
|
loadBalancerEnabled: false
|
||||||
natEnabled: false
|
natEnabled: false
|
||||||
colorCodes: blue
|
colorCodes: blue
|
||||||
|
|||||||
Reference in New Issue
Block a user