Compare commits

..
Author SHA1 Message Date
Miguel Angel Ajo f8dc2dc5d1 Enable globalnet E2E matrix
Signed-off-by: Miguel Angel Ajo <majopela@redhat.com>
2021-02-24 14:39:49 +01:00
Miguel Angel Ajo d7b3ab6204 Add globalCidr mappings to the submariner template
also includes the questions.yaml which is UI.

Signed-off-by: Miguel Angel Ajo <majopela@redhat.com>
2021-02-24 14:29:16 +01:00
65 changed files with 3408 additions and 2082 deletions
+4 -2
View File
@@ -23,9 +23,11 @@ Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
**Anything else we need to know?**: **Anything else we need to know?**:
**Environment**: **Environment**:
- Diagnose information (use `subctl diagnose all`): - Submariner version (use `subctl version`):
- Gather information (use `subctl gather`): - Kubernetes version (use `kubectl version`):
- Cloud provider or hardware configuration: - Cloud provider or hardware configuration:
- OS (e.g: `cat /etc/os-release`):
- Kernel (e.g. `uname -a`):
- Install tools: - Install tools:
- Network plugin and version (if this is a network-related bug): - Network plugin and version (if this is a network-related bug):
- Others: - Others:
+1 -1
View File
@@ -6,7 +6,7 @@ labels: support
--- ---
<!-- <!--
GitHub may not be the right place for support requests. GitHub may not the right place for support requests.
You can also post your question on the [Submariner You can also post your question on the [Submariner
Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner
-13
View File
@@ -1,13 +0,0 @@
<!-- Thanks for sending a pull request! Here are some tips for you:
1. If this is your first time, please read our developer guide: https://submariner.io/development/
2. Ensure you have added the appropriate tests for your PR: https://submariner.io/development/code-review/#test-new-functionality
3. Read the code review guide to ease the review process: https://submariner.io/development/code-review/
4. If the PR is unfinished, mark it as a draft: https://submariner.io/development/code-review/#mark-work-in-progress-prs-as-drafts
5. If you are using CI to debug, use your private fork: https://submariner.io/development/code-review/#use-private-forks-for-debugging-prs-by-running-ci
6. Add labels to the PR as appropriate.
This template is based on the K8s/K8s template:
https://github.com/kubernetes/kubernetes/blob/master/.github/PULL_REQUEST_TEMPLATE.md
-->
-38
View File
@@ -1,38 +0,0 @@
---
version: 2
updates:
- package-ecosystem: github-actions
directory: '/'
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.14"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.15"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.16"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
+57
View File
@@ -0,0 +1,57 @@
---
# Configuration for probot-stale - https://github.com/probot/stale
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
daysUntilStale: 60
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
daysUntilClose: 7
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
onlyLabels: []
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
exemptLabels:
- security
- confirmed
# Set to true to ignore issues in a project (defaults to false)
exemptProjects: false
# Set to true to ignore issues in a milestone (defaults to false)
exemptMilestones: false
# Set to true to ignore issues with an assignee (defaults to false)
exemptAssignees: false
# Label to use when marking as stale
staleLabel: wontfix
# Comment to post when marking as stale. Set to `false` to disable
markComment: >
This issue has been automatically marked as stale because it has not had
activity for 60 days. It will be closed if no further activity occurs.
Please make a comment if this issue/pr is still valid. Thank you
for your contributions.
# Comment to post when removing the stale label.
# unmarkComment: >
# Your comment here.
# Comment to post when closing a stale Issue or Pull Request.
# closeComment: >
# Your comment here.
# Limit the number of actions per hour, from 1-30. Default is 30
limitPerRun: 30
# Limit to only `issues` or `pulls`
# only: issues
pulls:
daysUntilStale: 30
markComment: >
This pull request has been automatically marked as stale because it has not had
recent activity. It will be closed if no further activity occurs. Thank you
for your contributions.
-16
View File
@@ -1,16 +0,0 @@
---
name: Branch Checks
on:
pull_request:
permissions: {}
jobs:
target_branch:
name: PR targets branch
runs-on: ubuntu-latest
steps:
- name: Check that the PR targets release-0.17
if: ${{ github.base_ref != 'release-0.17' }}
run: exit 1
-44
View File
@@ -1,44 +0,0 @@
---
name: PR Dependencies
on:
issues:
types:
- opened
- edited
- closed
- reopened
- synchronize
pull_request_target:
types:
- opened
- edited
- closed
- reopened
- synchronize
schedule:
- cron: '0 0/6 * * *' # every 6 hours
permissions:
issues: write
pull-requests: write
statuses: write
jobs:
check:
name: Check Dependencies
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
steps:
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
# The label to use to mark dependent issues
label: dependent
# Enable checking for dependencies in issues.
check_issues: on
# A comma-separated list of keywords to mark dependency.
keywords: depends on, Depends on
-39
View File
@@ -1,39 +0,0 @@
---
name: End to End Full
on:
pull_request:
types: [labeled, opened, synchronize, reopened]
permissions: {}
jobs:
e2e:
name: E2E
if: contains(github.event.pull_request.labels.*.name, 'ready-to-test')
timeout-minutes: 45
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet']
# Run most tests against the latest K8s version
k8s_version: ['1.29']
lighthouse: ['', 'lighthouse']
include:
# Bottom of supported K8s version range
- k8s_version: '1.26'
steps:
- name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.17
with:
k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.17
+10 -6
View File
@@ -1,23 +1,27 @@
--- ---
name: End to End Default name: End to End Tests
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
timeout-minutes: 30 timeout-minutes: 30
runs-on: ubuntu-latest runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
globalnet: ['', 'globalnet']
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 uses: actions/checkout@v2
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.17 uses: submariner-io/shipyard/gh-actions/e2e@devel
with:
globalnet: ${{ matrix.globalnet }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.17 uses: submariner-io/shipyard/gh-actions/post-mortem@devel
-33
View File
@@ -1,33 +0,0 @@
---
name: Flake Finder
on:
schedule:
- cron: "0 0 * * *"
permissions: {}
jobs:
e2e:
name: E2E
if: github.repository_owner == 'submariner-io'
timeout-minutes: 30
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet']
lighthouse: ['', 'lighthouse']
steps:
- name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.17
with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.17
+14 -61
View File
@@ -4,91 +4,41 @@ name: Linting
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
apply-suggestions-commits: dco:
name: 'No "Apply suggestions from code review" Commits' name: DCO in Commit Message(s)
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Get PR commits - name: Get PR commits
id: 'get-pr-commits' id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d uses: tim-actions/get-pr-commits@master
with: with:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
- name: Run DCO check
- name: 'Verify no "Apply suggestions from code review" commits' uses: tim-actions/dco@master
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
with: with:
commits: ${{ steps.get-pr-commits.outputs.commits }} commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!.*(apply suggestions from code review))'
flags: 'i'
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
- name: 'Verify no "fixup!" commits'
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!fixup!)'
flags: 'i'
error: 'Fixup commits should be squashed into the commits under review'
chart-testing:
name: Helm Chart Linting
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Set up Helm
uses: azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814
with:
version: v3.6.0
- name: Set up Python
uses: actions/setup-python@82c7e631bb3cdc910f68e0081d67478d79c6982d
with:
python-version: '3.x'
- name: Set up helm/chart-testing
uses: helm/chart-testing-action@e6669bcd63d7cb57cb4380c33043eebe5d111992
- name: Set up local helm repo
run: make local-helm-repo
- name: Run helm/chart-testing (lint)
run: ct lint --config ct.yaml
gitlint: gitlint:
name: Commit Message(s) name: Commit Message(s)
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 uses: actions/checkout@v2
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Run gitlint - name: Run gitlint
run: make gitlint run: make gitlint
helm-docs:
name: Helm Docs Generation
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run helm-docs and verify docs are up-to-date
run: make helm-docs
markdown-link-check: markdown-link-check:
name: Markdown Links (modified files) name: Markdown Links (modified files)
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 uses: actions/checkout@v2
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec uses: gaurav-nelson/github-action-markdown-link-check@v1
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes" check-modified-files-only: "yes"
@@ -99,7 +49,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 uses: actions/checkout@v2
- name: Run markdownlint - name: Run markdownlint
run: make markdownlint run: make markdownlint
@@ -108,6 +58,9 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 uses: actions/checkout@v2
- name: Run yamllint - name: Run yamllint
run: make yamllint uses: ibiqlik/action-yamllint@v1
with:
file_or_dir: submariner/Chart.yaml submariner/values.yaml submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
config_file: .yamllint.yml
+3 -8
View File
@@ -5,27 +5,22 @@ on:
schedule: schedule:
- cron: "0 0 * * 0" - cron: "0 0 * * 0"
permissions: {}
jobs: jobs:
markdown-link-check-periodic: markdown-link-check-periodic:
name: Markdown Links (all files) name: Markdown Links (all files)
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
issues: write
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 uses: actions/checkout@v2
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec uses: gaurav-nelson/github-action-markdown-link-check@v1
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links - name: Raise an Issue to report broken links
if: ${{ failure() }} if: ${{ failure() }}
uses: peter-evans/create-issue-from-file@24452a72d85239eacf1468b0f1982a9f3fec4c94 uses: peter-evans/create-issue-from-file@v2.3.2
with: with:
title: Broken link detected by CI title: Broken link detected by CI
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
+2 -6
View File
@@ -4,19 +4,15 @@ name: Release Charts
on: on:
push: push:
branches: branches:
- release-0.17 - devel
permissions:
contents: write
jobs: jobs:
release: release:
name: Release name: Release
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 uses: actions/checkout@v2
with: with:
fetch-depth: 0 fetch-depth: 0
-32
View File
@@ -1,32 +0,0 @@
---
name: Stale
on:
schedule:
- cron: "0 0 * * *"
permissions: {}
jobs:
stale:
name: Close Stale Issues and PRs
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
steps:
- uses: actions/stale@3f3b0175e8c66fb49b9a6d5a0cd1f8436d4c3ab6
with:
days-before-issue-stale: 120
days-before-pr-stale: 14
exempt-issue-labels: 'confirmed,security'
exempt-pr-labels: 'confirmed,security'
stale-issue-label: 'stale'
stale-issue-message: |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
activity occurs. Thank you for your contributions.
stale-pr-label: 'stale'
stale-pr-message: |
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
activity occurs. Thank you for your contributions.
-4
View File
@@ -2,7 +2,3 @@
.idea .idea
.shflags .shflags
*.tgz *.tgz
Makefile.dapper
Makefile.shipyard
Dockerfile.*
helm_repo
+9
View File
@@ -0,0 +1,9 @@
[general]
# body-is-missing: Allow commit messages with only a title
# body-min-length: Allow short body lines, like "Relates-to: #issue"
ignore=body-is-missing,body-min-length
[ignore-by-body]
# Dependabot doesn't follow our conventions, unfortunately
regex=^Signed-off-by: dependabot\[bot\](.*)
ignore=all
-6
View File
@@ -1,16 +1,10 @@
{ {
"ignorePatterns": [ "ignorePatterns": [
{
"pattern": "^https://docs.github.com"
},
{ {
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+" "pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
}, },
{ {
"pattern": "^http://localhost:" "pattern": "^http://localhost:"
},
{
"pattern": "^https://submariner-io.github.io/submariner-charts/charts"
} }
] ]
} }
-4
View File
@@ -10,7 +10,3 @@ line-length:
no-inline-html: no-inline-html:
allowed_elements: allowed_elements:
- span - span
# Temporary while helm-docs has a bug where maintainer URLs are used raw in MD
# Waiting on: https://github.com/norwoodj/helm-docs/pull/102
no-bare-urls: false
-7
View File
@@ -1,7 +0,0 @@
---
cni: ovn
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-6
View File
@@ -1,6 +0,0 @@
---
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-4
View File
@@ -1,4 +0,0 @@
---
label-approved:
approvals: 2
label: ready-to-test
+11 -11
View File
@@ -1,15 +1,15 @@
--- ---
extends: default extends: default
rules: rules:
comments: disable
comments-indentation: disable
line-length: line-length:
max: 140 max: 150
# Allow standard GHA syntax for "on: *" braces:
truthy: min-spaces-inside: 0
ignore: '.github/workflows/*.yml' max-spaces-inside: 0
brackets:
ignore: | min-spaces-inside: 0
/submariner-k8s-broker/crds max-spaces-inside: 0
/submariner-operator/crds indentation:
/submariner-k8s-broker/templates indent-sequences: consistent
/submariner-operator/templates
+1 -4
View File
@@ -1,4 +1 @@
# Auto-generated, do not edit; see CODEOWNERS.in * @mangelajo @Oats87 @skitt @tpantelis
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
-9
View File
@@ -1,9 +0,0 @@
@aswinsuryan Makefile
@dfarrell07 *.md Makefile
@maayanf24 Makefile
@Oats87 *
@skitt *
@sridhargaddam *
@tpantelis *
@vthapar *
@yboaron Makefile
+15
View File
@@ -0,0 +1,15 @@
FROM quay.io/submariner/shipyard-dapper-base:devel
ARG DAPPER_HOST_ARCH
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
WORKDIR ${DAPPER_SOURCE}
# Override the Helm deployment scripts
COPY deploy_helm /opt/shipyard/scripts/lib/
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
CMD ["sh"]
+19 -43
View File
@@ -1,58 +1,38 @@
BASE_BRANCH ?= release-0.17
export BASE_BRANCH
export HELM_REPO_LOCATION=./helm_repo
ifneq (,$(DAPPER_HOST_ARCH)) ifneq (,$(DAPPER_HOST_ARCH))
# Running in Dapper # Running in Dapper
include $(SHIPYARD_DIR)/Makefile.inc include $(SHIPYARD_DIR)/Makefile.inc
ifneq (,$(filter ovn,$(_using))) CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
else override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm --deploytool_broker_args '--set submariner.serviceDiscovery=true'
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml export DEPLOY_ARGS
endif
export DEPLOYTOOL = helm
GH_URL=https://submariner-io.github.io/submariner-charts/charts GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts CHARTS_DIR=charts
CHARTS_VERSION=0.17.2 CHARTS_VERSION=0.7.0
HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url) REPO_URL=$(shell git config remote.origin.url)
# Targets to make # Targets to make
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz deploy: clusters preload-images
local-helm-repo: $(CHART_PACKAGES) e2e: E2E_ARGS=cluster1 cluster2
mkdir -p $(HELM_REPO_LOCATION)
for archive in $^; do \ preload-images:
tar xzf $$archive -C $(HELM_REPO_LOCATION); \ source $(SCRIPTS_DIR)/lib/debug_functions; \
source $(SCRIPTS_DIR)/lib/deploy_funcs; \
source $(SCRIPTS_DIR)/lib/version; \
set -e; \
for image in submariner submariner-route-agent submariner-operator lighthouse-agent submariner-globalnet lighthouse-coredns; do \
import_image quay.io/submariner/$${image}; \
done done
e2e: local-helm-repo
$(SCRIPTS_DIR)/e2e.sh
%.tgz: %.tgz:
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm-docs: release: submariner-$(CHARTS_VERSION).tgz submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
cd /tmp && \
curl -sL https://github.com/norwoodj/helm-docs/releases/download/v$(HELM_DOCS_VERSION)/helm-docs_$(HELM_DOCS_VERSION)_Linux_x86_64.tar.gz | tar zx && \
cd -
/tmp/helm-docs
if [ ! -z $(git status --porcelain) ]; then \
echo "Helm docs not up-to-date:"; \
git status --porcelain; \
git diff; \
echo "Run make helm-docs locally to generate updated docs, commit the updates."; \
exit 1; \
fi
release: $(CHART_PACKAGES)
git checkout gh-pages git checkout gh-pages
mv *.tgz $(CHARTS_DIR) mv *.tgz $(CHARTS_DIR)
if [ -f $(CHARTS_DIR)/index.yaml ]; then \ if [ -f $(CHARTS_DIR)/index.yaml ]; then \
@@ -61,19 +41,15 @@ release: $(CHART_PACKAGES)
helm repo index $(CHARTS_DIR) --url $(GH_URL); \ helm repo index $(CHARTS_DIR) --url $(GH_URL); \
fi fi
.PHONY: release helm-docs .PHONY: preload-images release
else else
# Not running in Dapper # Not running in Dapper
Makefile.dapper:
@echo Downloading $@
@curl -sfLO https://raw.githubusercontent.com/submariner-io/shipyard/$(BASE_BRANCH)/$@
include Makefile.dapper include Makefile.dapper
endif endif
# Disable rebuilding Makefile # Disable rebuilding Makefile
Makefile Makefile.inc: ; Makefile Makefile.dapper Makefile.inc: ;
+26
View File
@@ -0,0 +1,26 @@
# This Makefile contains the rules required to set up our
# Dapper-based build environment; it can be copied as-is to
# other projects (and needs to be copied, it can't be shared
# via the Dapper image since it's needed to retrieve the image)
.dapper:
@echo Downloading dapper
@curl -sL https://releases.rancher.com/dapper/latest/dapper-`uname -s`-`uname -m` > .dapper.tmp
@@chmod +x .dapper.tmp
@./.dapper.tmp -v
@mv .dapper.tmp .dapper
invoke_dapper = +./.dapper -m bind make -- $1
%: .dapper
@echo Invoking Dapper, MAKEFLAGS=$(MAKEFLAGS)
$(call invoke_dapper,$@)
# Ensure that files in the current directory don't hide Dapper targets
$(wildcard [^M]*): .dapper
$(call invoke_dapper,$@)
shell: .dapper
./.dapper -m bind -s
.PHONY: shell $(wildcard [^M]*)
+1 -8
View File
@@ -1,12 +1,5 @@
# submariner-charts # submariner-charts
<!-- markdownlint-disable line-length -->
[![CII Best Practices](https://bestpractices.coreinfrastructure.org/projects/4865/badge)](https://bestpractices.coreinfrastructure.org/projects/4865)
[![Release Charts](https://github.com/submariner-io/submariner-charts/workflows/Release%20Charts/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Release+Charts%22)
[![Periodic](https://github.com/submariner-io/submariner-charts/workflows/Periodic/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic)
[![Flake Finder](https://github.com/submariner-io/submariner-charts/workflows/Flake%20Finder/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Flake+Finder%22)
<!-- markdownlint-enable line-length -->
Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/). Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/).
## Development workflow ## Development workflow
@@ -60,4 +53,4 @@ working correctly.
[Helm]: https://helm.sh/docs/using_helm/#installing-helm [Helm]: https://helm.sh/docs/using_helm/#installing-helm
[Docker]: https://docs.docker.com/install/ [Docker]: https://docs.docker.com/install/
[Podman]: https://podman.io/getting-started/installation [Podman]: https://podman.io/getting-started/installation
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo [Create a fork]: https://help.github.com/en/articles/fork-a-repo
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker"
cluster_nodes['cluster2']="control-plane worker"
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
-7
View File
@@ -1,7 +0,0 @@
---
charts:
- ./helm_repo/submariner-operator
- ./helm_repo/submariner-k8s-broker
# Tests that maintainer name is valid GitHub account, which isn't what we want
# See: https://github.com/helm/chart-testing/issues/192
validate-maintainers: false
+72
View File
@@ -0,0 +1,72 @@
# shellcheck shell=bash
# shellcheck source=scripts/shared/lib/source_only
. "${BASH_SOURCE%/*}"/source_only
### Constants ###
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
### Functions ###
function deploytool_prereqs() {
helm version
}
function setup_broker() {
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
echo "Submariner CRDs already exist, skipping broker creation..."
else
echo "Installing submariner broker..."
# shellcheck disable=SC2086 # Split on purpose
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
--create-namespace \
--kube-context "${cluster}" \
--namespace "${SUBMARINER_BROKER_NS}" \
${deploytool_broker_args}
fi
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
}
function helm_install_subm() {
local crd_create=false
[[ "${cluster}" = "${broker}" ]] || crd_create=true
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
echo "Submariner already installed, skipping installation..."
return
fi
echo "Installing Submariner..."
# shellcheck disable=SC2086 # Split on purpose
helm --kube-context "${cluster}" install submariner-operator \
./submariner-operator \
--create-namespace \
--namespace "${SUBM_NS}" \
--set ipsec.psk="${SUBMARINER_PSK}" \
--set broker.server="${submariner_broker_url}" \
--set broker.token="${submariner_broker_token}" \
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
--set broker.ca="${submariner_broker_ca}" \
--set submariner.cableDriver="${cable_driver}" \
--set submariner.clusterId="${cluster}" \
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
--set serviceAccounts.globalnet.create="${globalnet}" \
--set submariner.natEnabled="false" \
--set operator.image.repository="localhost:5000/submariner-operator" \
--set operator.image.tag="local" \
--set operator.image.pullPolicy="IfNotPresent" \
--set submariner.images.repository="localhost:5000" \
--set submariner.images.tag="local" \
--set brokercrds.create="${crd_create}" \
${deploytool_submariner_args}
}
function install_subm_all_clusters() {
run_subm_clusters helm_install_subm
}
+5 -6
View File
@@ -1,13 +1,12 @@
--- ---
name: submariner-k8s-broker name: submariner-k8s-broker
version: 0.0.0 version: 0.6.0
apiVersion: v2 appVersion: 0.6.0
description: Submariner Kubernetes Broker description: Submariner Kubernetes Broker
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
sources: sources:
- https://submariner-io.github.io/submariner-charts/charts - https://submariner-io.github.io/submariner-charts/charts
maintainers: maintainers:
- name: Contributors to the Submariner project - name: Submariner Developers
email: submariner-dev@googlegroups.com email: submariner-dev@googlegroups.com
url: https://submariner.io/
-24
View File
@@ -1,24 +0,0 @@
# submariner-k8s-broker
Submariner Kubernetes Broker
**Homepage:** <https://submariner-io.github.io/>
## Maintainers
| Name | Email | Url |
| ---- | ------ | --- |
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
## Source Code
* <https://submariner-io.github.io/submariner-charts/charts>
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| crd.create | bool | `true` | |
| rbac.create | bool | `true` | |
| serviceAccounts.client.create | bool | `true` | |
| serviceAccounts.client.name | string | `""` | |
+64 -300
View File
@@ -1,333 +1,97 @@
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: clusters.submariner.io name: clusters.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Cluster kind: Cluster
listKind: ClusterList
plural: clusters plural: clusters
singular: cluster
scope: Namespaced scope: Namespaced
versions:
- name: v1
schema:
openAPIV3Schema:
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
properties:
cluster_cidr:
items:
type: string
type: array
cluster_id:
type: string
color_codes:
items:
type: string
type: array
global_cidr:
items:
type: string
type: array
service_cidr:
items:
type: string
type: array
required:
- cluster_cidr
- cluster_id
- color_codes
- global_cidr
- service_cidr
type: object
required:
- spec
type: object
served: true
storage: true
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: endpoints.submariner.io name: endpoints.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Endpoint kind: Endpoint
listKind: EndpointList
plural: endpoints plural: endpoints
singular: endpoint
scope: Namespaced scope: Namespaced
versions:
- name: v1
schema:
openAPIV3Schema:
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
properties:
backend:
type: string
backend_config:
additionalProperties:
type: string
type: object
cable_name:
type: string
cluster_id:
type: string
healthCheckIP:
type: string
hostname:
type: string
nat_enabled:
type: boolean
private_ip:
type: string
public_ip:
type: string
subnets:
items:
type: string
type: array
required:
- backend
- cable_name
- cluster_id
- hostname
- nat_enabled
- private_ip
- public_ip
- subnets
type: object
required:
- spec
type: object
served: true
storage: true
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
name: gateways.submariner.io name: gateways.submariner.io
spec: spec:
group: submariner.io group: submariner.io
version: v1
names: names:
kind: Gateway kind: Gateway
listKind: GatewayList
plural: gateways plural: gateways
singular: gateway
scope: Namespaced scope: Namespaced
versions: additionalPrinterColumns:
- additionalPrinterColumns: - name: ha-status
- description: High availability status of the Gateway
jsonPath: .status.haStatus
name: HA Status
type: string type: string
name: v1 description: High Availability Status of the Gateway
schema: JSONPath: .status.haStatus
openAPIV3Schema: ---
properties: apiVersion: apiextensions.k8s.io/v1beta1
apiVersion: kind: CustomResourceDefinition
description: 'APIVersion defines the versioned schema of this representation metadata:
of an object. Servers should convert recognized schemas to the latest name: multiclusterservices.lighthouse.submariner.io
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources' spec:
type: string group: lighthouse.submariner.io
kind: version: v1
description: 'Kind is a string value representing the REST resource this names:
object represents. Servers may infer this from the endpoint the client kind: MultiClusterService
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds' plural: multiclusterservices
type: string singular: multiclusterservice
metadata: scope: Namespaced
type: object validation:
status: openAPIV3Schema:
properties: properties:
connections: spec:
items: properties:
properties: clusterServiceInfo:
endpoint: properties:
properties: clusterID:
backend: type: "string"
type: string clusterDomain:
backend_config: type: "string"
additionalProperties: serviceIP:
type: string type: "string"
type: object port:
cable_name: type: "integer"
type: string ---
cluster_id: apiVersion: apiextensions.k8s.io/v1beta1
type: string kind: CustomResourceDefinition
healthCheckIP: metadata:
type: string name: serviceexports.lighthouse.submariner.io
hostname: spec:
type: string group: lighthouse.submariner.io
nat_enabled: version: v2alpha1
type: boolean names:
private_ip: kind: ServiceExport
type: string plural: serviceexports
public_ip: singular: serviceexport
type: string scope: Namespaced
subnets: ---
items: apiVersion: apiextensions.k8s.io/v1beta1
type: string kind: CustomResourceDefinition
type: array metadata:
required: name: serviceimports.lighthouse.submariner.io
- backend spec:
- cable_name group: lighthouse.submariner.io
- cluster_id version: v2alpha1
- hostname names:
- nat_enabled kind: ServiceImport
- private_ip plural: serviceimports
- public_ip singular: serviceimport
- subnets scope: Namespaced
type: object
latency:
description: LatencySpec describes the round trip time information
in nanoseconds for a packet between the gateway pods of two
clusters.
properties:
averageRTT:
format: int64
type: integer
lastRTT:
description: TODO This shall be deleted once the operator
is using the latest. Using Optional to avoid validation
errors when this field is not used.
format: int64
type: integer
maxRTT:
format: int64
type: integer
minRTT:
format: int64
type: integer
stddevRTT:
format: int64
type: integer
type: object
latencyRTT:
description: LatencySpec describes the round trip time information
for a packet between the gateway pods of two clusters.
properties:
average:
type: string
last:
type: string
max:
type: string
min:
type: string
stdDev:
type: string
type: object
status:
type: string
statusMessage:
type: string
required:
- endpoint
- status
- statusMessage
type: object
type: array
haStatus:
type: string
localEndpoint:
properties:
backend:
type: string
backend_config:
additionalProperties:
type: string
type: object
cable_name:
type: string
cluster_id:
type: string
healthCheckIP:
type: string
hostname:
type: string
nat_enabled:
type: boolean
private_ip:
type: string
public_ip:
type: string
subnets:
items:
type: string
type: array
required:
- backend
- cable_name
- cluster_id
- hostname
- nat_enabled
- private_ip
- public_ip
- subnets
type: object
statusFailure:
type: string
version:
type: string
required:
- connections
- haStatus
- localEndpoint
- statusFailure
- version
type: object
required:
- status
type: object
served: true
storage: true
subresources: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
+19
View File
@@ -0,0 +1,19 @@
questions:
- variable: submariner-k8s-broker.rbac.create
type: boolean
default: true
group: "Role Based Access Control"
description: "Create the role/rolebinding for the Submariner client"
label: "RBAC Creation Enabled"
- variable: submariner-k8s-broker.crd.create
type: boolean
default: true
group: "Submariner CRD"
description: "Create the submariner CRDs for the Submariner client"
label: "Submariner CRD Creation Enabled"
- variable: submariner-k8s-broker.serviceAccounts.client.create
type: boolean
default: true
group: "Service Account"
description: "Create the service account for the Submariner client"
label: "Submariner Service Account Creation Enabled"
+2 -2
View File
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
The broker client token and CA can be retrieved by running The broker client token and CA can be retrieved by running
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}") $ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode) $ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
+5 -5
View File
@@ -2,7 +2,7 @@
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: Role kind: Role
metadata: metadata:
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster name: {{ template "submariner-k8s-broker.fullname" . }}:client
labels: labels:
heritage: {{ .Release.Service | quote }} heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
@@ -16,7 +16,7 @@ rules:
resources: ["*"] resources: ["*"]
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"] verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
- apiGroups: ["discovery.k8s.io"] - apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices", "endpointslices/restricted"] resources: ["endpointslices"]
verbs: ["create", "get", "list", "watch","patch", "update", "delete"] verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
- apiGroups: ["multicluster.x-k8s.io"] - apiGroups: ["multicluster.x-k8s.io"]
resources: ["*"] resources: ["*"]
@@ -25,13 +25,13 @@ rules:
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
metadata: metadata:
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster name: {{ template "submariner-k8s-broker.fullname" . }}:client
roleRef: roleRef:
apiGroup: rbac.authorization.k8s.io apiGroup: rbac.authorization.k8s.io
kind: Role kind: Role
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster name: {{ template "submariner-k8s-broker.fullname" . }}:client
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }} name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
{{- end -}} {{- end -}}
@@ -8,12 +8,4 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner-k8s-broker.chart" . }} chart: {{ template "submariner-k8s-broker.chart" . }}
app: {{ template "submariner-k8s-broker.name" . }} app: {{ template "submariner-k8s-broker.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
+2
View File
@@ -7,3 +7,5 @@ serviceAccounts:
client: client:
create: true create: true
name: "" name: ""
submariner:
serviceDiscovery: false
+3 -4
View File
@@ -1,13 +1,12 @@
--- ---
name: submariner-operator name: submariner-operator
version: 0.0.0 version: 0.7.0
apiVersion: v2 appVersion: 0.7.0
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
sources: sources:
- https://submariner-io.github.io/submariner-charts/charts - https://submariner-io.github.io/submariner-charts/charts
maintainers: maintainers:
- name: Contributors to the Submariner project - name: Submariner Developers
email: submariner-dev@googlegroups.com email: submariner-dev@googlegroups.com
url: https://submariner.io/
-67
View File
@@ -1,67 +0,0 @@
# submariner-operator
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
**Homepage:** <https://submariner-io.github.io/>
## Maintainers
| Name | Email | Url |
| ---- | ------ | --- |
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
## Source Code
* <https://submariner-io.github.io/submariner-charts/charts>
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| broker.ca | string | `""` | |
| broker.globalnet | bool | `false` | |
| broker.insecure | bool | `false` | |
| broker.namespace | string | `"xyz"` | |
| broker.server | string | `"example.k8s.apiserver"` | |
| broker.token | string | `"test"` | |
| ipsec.debug | bool | `false` | |
| ipsec.forceUDPEncaps | bool | `false` | |
| ipsec.ikePort | int | `500` | |
| ipsec.natPort | int | `4500` | |
| ipsec.psk | string | `""` | |
| leadership.leaseDuration | int | `10` | |
| leadership.renewDeadline | int | `5` | |
| leadership.retryPeriod | int | `2` | |
| operator.affinity | object | `{}` | |
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
| operator.image.tag | string | `"0.14.0"` | |
| operator.resources | object | `{}` | |
| operator.tolerations | list | `[]` | |
| rbac.create | bool | `true` | |
| serviceAccounts.gateway.create | bool | `true` | |
| serviceAccounts.gateway.name | string | `""` | |
| serviceAccounts.globalnet.create | bool | `true` | |
| serviceAccounts.globalnet.name | string | `""` | |
| serviceAccounts.lighthouseAgent.create | bool | `true` | |
| serviceAccounts.lighthouseAgent.name | string | `""` | |
| serviceAccounts.lighthouseCoreDns.create | bool | `true` | |
| serviceAccounts.lighthouseCoreDns.name | string | `""` | |
| serviceAccounts.operator.create | bool | `true` | |
| serviceAccounts.operator.name | string | `""` | |
| serviceAccounts.routeAgent.create | bool | `true` | |
| serviceAccounts.routeAgent.name | string | `""` | |
| submariner.cableDriver | string | `"libreswan"` | |
| submariner.clusterCidr | string | `""` | |
| submariner.clusterId | string | `""` | |
| submariner.colorCodes | string | `"blue"` | |
| submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | |
| submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.14.0"` | |
| submariner.natEnabled | bool | `false` | |
| submariner.serviceCidr | string | `""` | |
| submariner.serviceDiscovery | bool | `true` | |
| submariner.token | string | `""` | |
File diff suppressed because it is too large Load Diff
+125
View File
@@ -0,0 +1,125 @@
questions:
- variable: defaultOperatorImage
default: true
description: "Use default Submariner operator image or specify a custom one"
label: Use default Submariner operator image
type: boolean
show_subquestion_if: false
group: "Container Images"
subquestions:
- variable: operator.image.repository
default: "quay.io/submariner/submariner-operator"
description: "Submariner Operator Image Repository"
type: string
label: Submariner Operator Image Repository
- variable: operator.image.tag
default: "0.7.0"
description: "Submariner Operator Image Tag"
type: string
label: Submariner Operator Image Tag
- variable: defaultSubmarinerImages
default: true
description: "Use default Submariner images or specify custom ones"
label: Use default Submariner images
type: boolean
show_subquestion_if: false
group: "Container images"
subquestions:
- variable: submariner.images.repository
default: "quay.io/submariner"
description: "Submariner Repository (base for all non-operator images)"
type: string
label: Submariner Repository
- variable: submariner.images.tag
default: "0.7.0"
description: "Submariner Images Tag (shared for all non-operator images)"
type: string
label: Submariner Images Tag
- variable: submariner.clusterId
default: ""
description: "Enter a unique cluster ID to identify this cluster"
type: string
label: "Cluster ID"
group: "Configuration"
required: true
- variable: ipsec.psk
default: ""
description: "Enter the pre-shared key for the IPsec Cable Engine"
type: string
label: "IPsec Pre-Shared Key"
group: "Configuration"
required: true
- variable: broker.server
type: string
default: ""
group: "Broker Configuration"
label: "Broker Server"
description: "Broker server to use (without the https://)"
- variable: broker.insecure
type: boolean
default: false
show_subquestion_if: false
group: "Broker Configuration"
label: "Insecure Broker"
description: "Connect to K8s broker without validating CA"
subquestions:
- variable: broker.ca
type: string
description: "Base64 encoded broker ca.crt"
label: "Broker CA encoded in base64"
default: ""
- variable: broker.token
type: string
group: "Broker Configuration"
label: "Broker Token"
description: "Bearer token for broker"
- variable: broker.namespace
type: string
group: "Broker Configuration"
label: "Broker Namespace"
description: "Enter namespace to use on central broker"
- variable: submariner.clusterCidr
default: ""
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
type: string
label: "Cluster CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.serviceCidr
default: ""
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
type: string
label: "Service CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.globalCidr
default: ""
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
type: string
label: "Globalnet CIDR"
group: "CIDR Configuration"
required: false
- variable: submariner.natEnabled
type: boolean
default: false
group: "Advanced Configuration"
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
label: "NAT Enabled"
- variable: submariner.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable submariner debug mode"
label: "Submariner Debug Enabled"
- variable: ipsec.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable Charon debug mode"
label: "Charon Enabled"
- variable: submariner.cableDriver
type: string
default: ""
group: "Advanced Configuration"
description: "Cable driver implementation"
label: "Cable Driver"
+5 -1
View File
@@ -1,3 +1,7 @@
Submariner is now installed. Submariner is now installed.
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool. {{- if .Values.engine.nodeSelectorEnabled }}
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
{{- end }}
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
+5 -5
View File
@@ -43,13 +43,13 @@ Create the name of the submariner-operator service account to use
{{- end -}} {{- end -}}
{{/* {{/*
Create the name of the submariner-gateway service account to use Create the name of the submariner-engine service account to use
*/}} */}}
{{- define "submariner.gatewayServiceAccountName" -}} {{- define "submariner.engineServiceAccountName" -}}
{{- if .Values.serviceAccounts.gateway.create -}} {{- if .Values.serviceAccounts.engine.create -}}
{{ default "submariner-gateway" .Values.serviceAccounts.gateway.name }} {{ default "submariner-engine" .Values.serviceAccounts.engine.name }}
{{- else -}} {{- else -}}
{{ default "default" .Values.serviceAccounts.gateway.name }} {{ default "default" .Values.serviceAccounts.engine.name }}
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}
@@ -6,7 +6,7 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }} app: {{ template "submariner.fullname" . }}
component: gateway component: engine
name: {{ template "submariner.fullname" . }} name: {{ template "submariner.fullname" . }}
spec: spec:
progressDeadlineSeconds: 600 progressDeadlineSeconds: 600
+376 -293
View File
@@ -9,94 +9,62 @@ metadata:
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
# For metrics - pods
- services - services
verbs: - services/finalizers
- get - endpoints
- create - persistentvolumeclaims
- update - events
- apiGroups: - configmaps
- "" - secrets
resources: verbs:
# For syncing Secrets from the broker - '*'
- secrets - apiGroups:
verbs: - apps
- get resources:
- create - deployments
- update - daemonsets
- delete - replicasets
- apiGroups: - statefulsets
- "" verbs:
resources: - '*'
# Temporarily needed for network-plugin syncer removal - apiGroups:
- serviceaccounts - monitoring.coreos.com
resourceNames: resources:
- submariner-networkplugin-syncer - servicemonitors
verbs: verbs:
- delete - get
- apiGroups: - create
- apps - apiGroups:
resources: - apps
- deployments resourceNames:
- daemonsets - {{ template "submariner.fullname" . }}
verbs: resources:
- create - deployments/finalizers
- delete verbs:
- get - update
- list - apiGroups:
- patch - ""
- update resources:
- watch - pods
- apiGroups: verbs:
- monitoring.coreos.com - get
resources: - apiGroups:
# Needed for openshift monitoring - apps
- servicemonitors resources:
verbs: - replicasets
- get verbs:
- create - get
- apiGroups: - apiGroups:
- apps - submariner.io
resourceNames: resources:
- {{ template "submariner.fullname" . }} - '*'
resources: - servicediscoveries
- deployments/finalizers verbs:
verbs: - '*'
- update
- apiGroups:
- submariner.io
resources:
- brokers
- brokers/status
- submariners
- submariners/status
- servicediscoveries
- servicediscoveries/status
verbs:
- get
- list
- watch
- create
- update
- delete
- apiGroups:
- submariner.io
resources:
- gateways
verbs:
- get
- list
- watch
- apiGroups:
- submariner.io
resources:
- submariners/finalizers
- servicediscoveries/finalizers
verbs:
- update
--- ---
kind: RoleBinding kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -118,50 +86,87 @@ roleRef:
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: Role kind: Role
metadata: metadata:
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:engine
labels: labels:
heritage: {{ .Release.Service | quote }} heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods - pods
verbs: - services
- get - services/finalizers
- update - endpoints
- patch - persistentvolumeclaims
- apiGroups: - events
- submariner.io - configmaps
resources: - secrets
- clusters verbs:
- endpoints - '*'
- gateways - apiGroups:
verbs: - apps
- get resources:
- list - deployments
- watch - daemonsets
- create - replicasets
- update - statefulsets
- delete verbs:
- apiGroups: - '*'
- coordination.k8s.io - apiGroups:
resources: - monitoring.coreos.com
- leases resources:
verbs: - servicemonitors
- get verbs:
- list - get
- watch - create
- create - apiGroups:
- update - apps
- delete resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
metadata: metadata:
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:engine
labels: labels:
heritage: {{ .Release.Service | quote }} heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
@@ -170,10 +175,10 @@ metadata:
roleRef: roleRef:
apiGroup: rbac.authorization.k8s.io apiGroup: rbac.authorization.k8s.io
kind: Role kind: Role
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:engine
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: {{ template "submariner.gatewayServiceAccountName" . }} name: {{ template "submariner.engineServiceAccountName" . }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -187,25 +192,74 @@ metadata:
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- submariner.io - ""
resources: resources:
- pods
- services
- services/finalizers
- endpoints - endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs: verbs:
- get - get
- list
- watch
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gatewayroutes - '*'
- nongatewayroutes - servicediscoveries
verbs: verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get - get
- list - list
- watch - patch
- create
- update - update
- delete - watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -225,7 +279,7 @@ subjects:
name: {{ template "submariner.routeAgentServiceAccountName" . }} name: {{ template "submariner.routeAgentServiceAccountName" . }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
--- ---
{{- if .Values.broker.globalnet }} {{- if ne .Values.submariner.globalCidr "" }}
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: Role kind: Role
metadata: metadata:
@@ -237,16 +291,74 @@ metadata:
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- coordination.k8s.io - ""
resources: resources:
- leases - pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs: verbs:
- get - get
- list
- watch
- create - create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update - update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete - delete
- get
- list
- patch
- update
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -285,7 +397,6 @@ rules:
resources: resources:
- configmaps - configmaps
verbs: verbs:
- create
- get - get
- list - list
- watch - watch
@@ -300,14 +411,11 @@ rules:
- create - create
- update - update
- delete - delete
- watch - apiGroups: # pods and services are looked up to figure out network settings
- apiGroups:
- "" - ""
resources: resources:
# Needed for network settings discovery
- pods - pods
- services - services
- nodes
verbs: verbs:
- get - get
- list - list
@@ -318,42 +426,16 @@ rules:
- dnses - dnses
verbs: verbs:
- get - get
- list
- watch
- update - update
- apiGroups: - apiGroups:
- config.openshift.io - config.openshift.io
resources: resources:
# Needed for network settings discovery
- networks - networks
resourceNames:
- cluster
verbs: verbs:
- get - get
- apiGroups:
- monitoring.coreos.com
resources:
# Needed for openshift monitoring
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resources:
# Needed for Flannel CNI discovery
- daemonsets
verbs:
- list - list
- apiGroups:
- rbac.authorization.k8s.io
resources:
# Temporarily needed for network-plugin syncer removal
- clusterroles
- clusterrolebindings
resourceNames:
- ocp-submariner-networkplugin-syncer
- submariner-networkplugin-syncer
verbs:
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -374,32 +456,9 @@ roleRef:
name: {{ template "submariner.fullname" . }} name: {{ template "submariner.fullname" . }}
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: submariner-metrics-reader
namespace: {{ .Release.Namespace }}
rules:
- apiGroups: [""]
resources: ["pods", "services", "endpoints"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-submariner-metrics
subjects:
- kind: ServiceAccount
name: prometheus-k8s
namespace: openshift-monitoring
roleRef:
kind: Role
name: submariner-metrics-reader
apiGroup: rbac.authorization.k8s.io
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole kind: ClusterRole
metadata: metadata:
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:engine
labels: labels:
heritage: {{ .Release.Service | quote }} heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
@@ -412,7 +471,21 @@ rules:
- configmaps - configmaps
verbs: verbs:
- get - get
- list
- watch
- create
- update
- apiGroups: - apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- "" - ""
resources: resources:
- pods - pods
@@ -422,11 +495,37 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- submariner.io
resources:
- endpoints
- gateways
- clusters
verbs:
- get
- list
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
metadata: metadata:
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:engine
labels: labels:
heritage: {{ .Release.Service | quote }} heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
@@ -435,10 +534,10 @@ metadata:
roleRef: roleRef:
apiGroup: rbac.authorization.k8s.io apiGroup: rbac.authorization.k8s.io
kind: ClusterRole kind: ClusterRole
name: {{ template "submariner.fullname" . }}:gateway name: {{ template "submariner.fullname" . }}:engine
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: {{ template "submariner.gatewayServiceAccountName" . }} name: {{ template "submariner.engineServiceAccountName" . }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -454,41 +553,56 @@ rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods
- services
- secrets
- configmaps - configmaps
- endpoints
verbs:
- get
- list
- apiGroups:
- config.openshift.io
resources:
- networks
resourceNames:
- cluster
verbs:
- get
- apiGroups:
- ""
resources:
- nodes
verbs: verbs:
- get - get
- list - list
- watch - watch
- update - update
- apiGroups: - apiGroups:
- projectcalico.org - apiextensions.k8s.io
resources: resources:
- ippools - customresourcedefinitions
verbs: verbs:
- get - get
- list
- create - create
- delete
- update - update
- deletecollection - delete
- apiGroups: # pods and services are looked up to figure out network settings
- ""
resources:
- pods
- services
verbs:
- get
- list
- watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- ""
verbs:
- get
- list
- watch
- update
resources:
- nodes
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -508,7 +622,7 @@ subjects:
name: {{ template "submariner.routeAgentServiceAccountName" . }} name: {{ template "submariner.routeAgentServiceAccountName" . }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
--- ---
{{- if .Values.broker.globalnet }} {{- if ne .Values.submariner.globalCidr "" }}
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole kind: ClusterRole
metadata: metadata:
@@ -522,75 +636,32 @@ rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods
- services
- namespaces
- nodes - nodes
verbs: verbs:
- get - get
- list - list
- watch - watch
- update - update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- services
- endpoints
verbs:
- create
- get
- list
- watch
- update
- delete
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- endpoints
- clusters - clusters
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- apiGroups:
- submariner.io
resources:
- clusterglobalegressips
- clusterglobalegressips/status
- globalegressips
- globalegressips/status
- globalingressips
- globalingressips/status
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceexports - "serviceexports"
verbs: verbs:
- get - get
- list - list
- watch - watch
- apiGroups:
- network.openshift.io
resources:
- service/externalips
verbs:
- create
- get
- list
- delete
--- ---
{{- end -}} {{- end -}}
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -632,11 +703,11 @@ rules:
- get - get
- list - list
- watch - watch
- update
- apiGroups: - apiGroups:
- discovery.k8s.io - discovery.k8s.io
resources: resources:
- endpointslices - endpointslices
- endpointslices/restricted
verbs: verbs:
- create - create
- get - get
@@ -648,8 +719,7 @@ rules:
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gateways - "gateways"
- globalingressips
verbs: verbs:
- get - get
- list - list
@@ -657,8 +727,7 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceimports - "*"
- serviceimports/status
verbs: verbs:
- create - create
- get - get
@@ -666,20 +735,6 @@ rules:
- watch - watch
- update - update
- delete - delete
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports
verbs:
- get
- list
- watch
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports/status
verbs:
- update
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -705,18 +760,43 @@ metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-coredns name: {{ template "submariner.fullname" . }}:lighthouse-coredns
rules: rules:
- apiGroups: - apiGroups:
- discovery.k8s.io - ""
resources: resources:
- endpointslices - services
- namespaces
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- update
- apiGroups:
- discovery.k8s.io
resources:
- endpointslices
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups:
- lighthouse.submariner.io
resources:
- "*"
verbs:
- create
- get
- list
- watch
- update
- delete
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gateways - "gateways"
- submariners
verbs: verbs:
- get - get
- list - list
@@ -724,11 +804,14 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceimports - "*"
verbs: verbs:
- create
- get - get
- list - list
- watch - watch
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
+1 -40
View File
@@ -9,9 +9,7 @@ spec:
brokerK8sApiServerToken: {{ .Values.broker.token }} brokerK8sApiServerToken: {{ .Values.broker.token }}
brokerK8sCA: {{ .Values.broker.ca }} brokerK8sCA: {{ .Values.broker.ca }}
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }} brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
brokerK8sInsecure: {{ .Values.broker.insecure }}
ceIPSecDebug: {{ .Values.ipsec.debug }} ceIPSecDebug: {{ .Values.ipsec.debug }}
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }} ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
ceIPSecNATTPort: {{ .Values.ipsec.natPort }} ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
ceIPSecPSK: {{ .Values.ipsec.psk }} ceIPSecPSK: {{ .Values.ipsec.psk }}
@@ -19,47 +17,10 @@ spec:
clusterID: {{ .Values.submariner.clusterId }} clusterID: {{ .Values.submariner.clusterId }}
colorCodes: {{ .Values.submariner.colorCodes }} colorCodes: {{ .Values.submariner.colorCodes }}
debug: {{ .Values.submariner.debug }} debug: {{ .Values.submariner.debug }}
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
natEnabled: {{ .Values.submariner.natEnabled }} natEnabled: {{ .Values.submariner.natEnabled }}
repository: {{ .Values.submariner.images.repository }} repository: {{ .Values.submariner.images.repository }}
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }} version: {{ .Values.submariner.images.tag }}
{{- with .Values.images }}
{{- if . }}
imageOverrides:
{{- if index . "submariner-operator" }}
submariner-operator: {{ index . "submariner-operator" }}
{{- end }}
{{- if index . "submariner-gateway" }}
submariner-gateway: {{ index . "submariner-gateway" }}
{{- end }}
{{- if index . "submariner-route-agent" }}
submariner-routeagent: {{ index . "submariner-route-agent" }}
{{- end }}
{{- if index . "submariner-globalnet" }}
submariner-globalnet: {{ index . "submariner-globalnet" }}
{{- end }}
{{- if index . "submariner-networkplugin-syncer" }}
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
{{- end }}
{{- if index . "lighthouse-agent" }}
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
{{- end }}
{{- if index . "lighthouse-coredns" }}
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
{{- end }}
{{- end }}
{{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}" serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}" globalCIDR: "{{ .Values.submariner.globalCidr }}"
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }} serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck:
enabled: {{ .Values.submariner.healthcheckEnabled }}
intervalSeconds: 1
maxPacketLossCount: 5
{{- with .Values.submariner.coreDNSCustomConfig }}
coreDNSCustomConfig:
configMapName: {{ .configMapName }}
namespace: {{ .namespace }}
{{- end }}
+2 -50
View File
@@ -8,34 +8,18 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.operatorServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.gateway.create }} {{- if .Values.serviceAccounts.engine.create }}
apiVersion: v1 apiVersion: v1
kind: ServiceAccount kind: ServiceAccount
metadata: metadata:
name: {{ template "submariner.gatewayServiceAccountName" . }} name: {{ template "submariner.engineServiceAccountName" . }}
labels: labels:
heritage: {{ .Release.Service | quote }} heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.routeAgent.create }} {{- if .Values.serviceAccounts.routeAgent.create }}
@@ -48,14 +32,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.globalnet.create }} {{- if .Values.serviceAccounts.globalnet.create }}
@@ -68,14 +44,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.lighthouseAgent.create }} {{- if .Values.serviceAccounts.lighthouseAgent.create }}
@@ -88,14 +56,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }} {{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
@@ -108,12 +68,4 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
+7 -10
View File
@@ -5,31 +5,24 @@ submariner:
clusterCidr: "" clusterCidr: ""
serviceCidr: "" serviceCidr: ""
globalCidr: "" globalCidr: ""
loadBalancerEnabled: false
natEnabled: false natEnabled: false
colorCodes: blue colorCodes: blue
debug: false debug: false
serviceDiscovery: true serviceDiscovery: true
cableDriver: "libreswan"
healthcheckEnabled: true
coreDNSCustomConfig: {}
images: images:
repository: quay.io/submariner repository: quay.io/submariner
tag: "" tag: "0.7.0"
broker: broker:
server: example.k8s.apiserver server: example.k8s.apiserver
token: test token: test
namespace: xyz namespace: xyz
insecure: false insecure: false
ca: "" ca: ""
globalnet: false
rbac: rbac:
create: true create: true
images: {}
ipsec: ipsec:
psk: "" psk: ""
debug: false debug: false
forceUDPEncaps: false
ikePort: 500 ikePort: 500
natPort: 4500 natPort: 4500
leadership: leadership:
@@ -39,16 +32,20 @@ leadership:
operator: operator:
image: image:
repository: quay.io/submariner/submariner-operator repository: quay.io/submariner/submariner-operator
tag: "" tag: "0.7.0"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
resources: {} resources: {}
tolerations: [] tolerations: []
affinity: {} affinity: {}
engine:
image:
repository: quay.io/submariner/submariner
tag: "0.7.0"
serviceAccounts: serviceAccounts:
operator: operator:
create: true create: true
name: "" name: ""
gateway: engine:
create: true create: true
name: "" name: ""
routeAgent: routeAgent:
+1
View File
@@ -0,0 +1 @@
.git
+12
View File
@@ -0,0 +1,12 @@
---
name: submariner
version: 0.6.0
appVersion: 0.6.0
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords:
home: https://submariner-io.github.io/
sources:
- https://submariner-io.github.io/submariner-charts/charts
maintainers:
- name: Submariner Developers
email: submariner-dev@googlegroups.com
+5
View File
@@ -0,0 +1,5 @@
# Submariner
[Submariner](https://submariner.io) is a cross-cluster networking tool.
This chart creates the required components in this cluster to enable cross cluster networking.
+324
View File
@@ -0,0 +1,324 @@
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: clusters.submariner.io
spec:
group: submariner.io
version: v1
names:
kind: Cluster
plural: clusters
scope: Namespaced
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: endpoints.submariner.io
spec:
group: submariner.io
version: v1
names:
kind: Endpoint
plural: endpoints
scope: Namespaced
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: gateways.submariner.io
spec:
group: submariner.io
version: v1
names:
kind: Gateway
plural: gateways
scope: Namespaced
additionalPrinterColumns:
- name: ha-status
type: string
description: High Availability Status of the Gateway
JSONPath: .status.haStatus
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: multiclusterservices.lighthouse.submariner.io
spec:
group: lighthouse.submariner.io
version: v1
names:
kind: MultiClusterService
plural: multiclusterservices
singular: multiclusterservice
scope: Namespaced
validation:
openAPIV3Schema:
properties:
spec:
properties:
clusterServiceInfo:
properties:
clusterID:
type: "string"
clusterDomain:
type: "string"
serviceIP:
type: "string"
port:
type: "integer"
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: serviceexports.lighthouse.submariner.io
spec:
group: lighthouse.submariner.io
version: v2alpha1
names:
kind: ServiceExport
plural: serviceexports
singular: serviceexport
scope: Namespaced
---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: serviceimports.lighthouse.submariner.io
spec:
group: lighthouse.submariner.io
version: v2alpha1
names:
kind: ServiceImport
plural: serviceimports
singular: serviceimport
scope: Namespaced
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: serviceexports.multicluster.x-k8s.io
spec:
group: multicluster.x-k8s.io
scope: Namespaced
names:
plural: serviceexports
singular: serviceexport
kind: ServiceExport
shortNames:
- svcex
versions:
- name: v1alpha1
served: true
storage: true
subresources:
status: {}
additionalPrinterColumns:
- name: Age
type: date
jsonPath: .metadata.creationTimestamp
"schema":
"openAPIV3Schema":
description: ServiceExport declares that the Service with the same name and
namespace as this export should be consumable from other clusters.
type: object
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
status:
description: status describes the current state of an exported service.
Service configuration comes from the Service that had the same name
and namespace as this ServiceExport. Populated by the multi-cluster
service implementation's controller.
type: object
properties:
conditions:
type: array
items:
description: "ServiceExportCondition contains details for the current
condition of this service export. \n Once [KEP-1623](https://github.com/kubernetes/enhancements/tree/master/keps/sig-api-machinery/1623-standardize-conditions)
is implemented, this will be replaced by metav1.Condition."
type: object
required:
- status
- type
properties:
lastTransitionTime:
type: string
format: date-time
message:
type: string
reason:
type: string
status:
description: Status is one of {"True", "False", "Unknown"}
type: string
enum:
- "True"
- "False"
- Unknown
type:
description: ServiceExportConditionType identifies a specific
condition.
type: string
x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: serviceimports.multicluster.x-k8s.io
spec:
group: multicluster.x-k8s.io
scope: Namespaced
names:
plural: serviceimports
singular: serviceimport
kind: ServiceImport
shortNames:
- svcim
versions:
- name: v1alpha1
served: true
storage: true
subresources:
status: {}
additionalPrinterColumns:
- name: Type
type: string
description: The type of this ServiceImport
jsonPath: .spec.type
- name: IP
type: string
description: The VIP for this ServiceImport
jsonPath: .spec.ips
- name: Age
type: date
jsonPath: .metadata.creationTimestamp
"schema":
"openAPIV3Schema":
description: ServiceImport describes a service imported from clusters in a
ClusterSet.
type: object
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
description: spec defines the behavior of a ServiceImport.
type: object
required:
- ports
- type
properties:
ips:
description: ip will be used as the VIP for this service when type
is ClusterSetIP.
type: array
maxItems: 1
items:
type: string
ports:
type: array
items:
description: ServicePort represents the port on which the service
is exposed
type: object
required:
- port
properties:
appProtocol:
description: The application protocol for this port. This field
follows standard Kubernetes label syntax. Un-prefixed names
are reserved for IANA standard service names (as per RFC-6335
and http://www.iana.org/assignments/service-names). Non-standard
protocols should use prefixed names such as mycompany.com/my-custom-protocol.
Field can be enabled with ServiceAppProtocol feature gate.
type: string
name:
description: The name of this port within the service. This
must be a DNS_LABEL. All ports within a ServiceSpec must have
unique names. When considering the endpoints for a Service,
this must match the 'name' field in the EndpointPort. Optional
if only one ServicePort is defined on this service.
type: string
port:
description: The port that will be exposed by this service.
type: integer
format: int32
protocol:
description: The IP protocol for this port. Supports "TCP",
"UDP", and "SCTP". Default is TCP.
type: string
x-kubernetes-list-type: atomic
sessionAffinity:
description: 'Supports "ClientIP" and "None". Used to maintain session
affinity. Enable client IP based session affinity. Must be ClientIP
or None. Defaults to None. Ignored when type is Headless More info:
https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies'
type: string
sessionAffinityConfig:
description: sessionAffinityConfig contains session affinity configuration.
type: object
properties:
clientIP:
description: clientIP contains the configurations of Client IP
based session affinity.
type: object
properties:
timeoutSeconds:
description: timeoutSeconds specifies the seconds of ClientIP
type session sticky time. The value must be >0 && <=86400(for
1 day) if ServiceAffinity == "ClientIP". Default value is
10800(for 3 hours).
type: integer
format: int32
type:
description: type defines the type of this service. Must be ClusterSetIP
or Headless.
type: string
enum:
- ClusterSetIP
- Headless
status:
description: status contains information about the exported services that
form the multi-cluster service referenced by this ServiceImport.
type: object
properties:
clusters:
description: clusters is the list of exporting clusters from which
this service was derived.
type: array
items:
description: ClusterStatus contains service configuration mapped
to a specific source cluster
type: object
required:
- cluster
properties:
cluster:
description: cluster is the name of the exporting cluster. Must
be a valid RFC-1123 DNS label.
type: string
x-kubernetes-list-map-keys:
- cluster
x-kubernetes-list-type: map
+138
View File
@@ -0,0 +1,138 @@
questions:
- variable: defaultEngineImage
default: true
description: "Use default Submariner Engine image or specify a custom one"
label: Use default submariner engine image
type: boolean
show_subquestion_if: false
group: "Container Images"
subquestions:
- variable: engine.image.repository
default: "quay.io/submariner/submariner"
description: "Submariner Engine Image Repository"
type: string
label: Submariner Engine Image Repository
- variable: engine.image.tag
default: "0.6.0"
description: "Submariner Engine Image Tag"
type: string
label: Submariner Engine Image Tag
- variable: defaultRouteAgentImage
default: true
description: "Use default Submariner Route Agent image or specify a custom one"
label: Use default submariner route agent image
type: boolean
show_subquestion_if: false
group: "Container Images"
subquestions:
- variable: routeAgent.image.repository
default: "quay.io/submariner/submariner-route-agent"
description: "Submariner Route Agent Image Repository"
type: string
label: Submariner Route Agent Image Repository
- variable: routeAgent.image.tag
default: "0.6.0"
description: "Submariner Route Agent Image Tag"
type: string
label: Submariner Route Agent Image Tag
- variable: engine.nodeSelectorEnabled
default: true
description: "Restrict submariner to nodes labeled with submariner.io/gateway=true"
label: Restrict gateway deployments to specific nodes
type: boolean
group: "Gateway Configuration"
- variable: submariner.clusterId
default: ""
description: "Enter a unique cluster ID to identify this cluster"
type: string
label: "Cluster ID"
group: "Configuration"
required: true
- variable: ipsec.psk
default: ""
description: "Enter the pre-shared key for the IPsec Cable Engine"
type: string
label: "IPsec Pre-Shared Key"
group: "Configuration"
required: true
- variable: broker.type
type: enum
default: k8s
options:
- k8s
group: "Broker Configuration"
label: "Broker Type"
description: "Type of Broker to use"
- variable: broker.server
type: string
default: ""
group: "Broker Configuration"
label: "Broker Server"
description: "Broker server to use (without the https://)"
- variable: broker.insecure
type: boolean
default: false
show_subquestion_if: false
group: "Broker Configuration"
label: "Insecure Broker"
description: "Connect to K8s broker without validating CA"
subquestions:
- variable: broker.ca
type: string
description: "Base64 encoded broker ca.crt"
label: "Broker CA encoded in base64"
default: ""
- variable: broker.token
type: string
group: "Broker Configuration"
label: "Broker Token"
description: "Bearer token for broker"
- variable: broker.namespace
type: string
group: "Broker Configuration"
label: "Broker Namespace"
description: "Enter namespace to use on central broker"
- variable: submariner.clusterCidr
default: ""
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
type: string
label: "Cluster CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.serviceCidr
default: ""
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
type: string
label: "Service CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.natEnabled
type: boolean
default: false
group: "Advanced Configuration"
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
label: "NAT Enabled"
- variable: crd.create
type: boolean
default: true
group: "Advanced Configuration"
description: "Create the Submariner CRDs, if deploying Submariner into the same cluster as the submariner-k8s-broker, you probably shouldn't create CRDs"
label: "CRD Creation Enabled"
- variable: submariner.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable submariner debug mode"
label: "Submariner Debug Enabled"
- variable: ipsec.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable Charon debug mode"
label: "Charon Enabled"
- variable: submariner.cableDriver
type: string
default: ""
group: "Advanced Configuration"
description: "Cable driver implementation"
label: "Cable Driver"
+7
View File
@@ -0,0 +1,7 @@
Submariner is now installed.
{{- if .Values.engine.nodeSelectorEnabled }}
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
{{- end }}
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
+94
View File
@@ -0,0 +1,94 @@
{{/* vim: set filetype=mustache: */}}
{{/*
Expand the name of the chart.
*/}}
{{- define "submariner.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "submariner.fullname" -}}
{{- if .Values.fullnameOverride -}}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default .Chart.Name .Values.nameOverride -}}
{{- if contains $name .Release.Name -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "submariner.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Create the name of the submariner-engine service account to use
*/}}
{{- define "submariner.engineServiceAccountName" -}}
{{- if .Values.serviceAccounts.engine.create -}}
{{ default "submariner-engine" .Values.serviceAccounts.engine.name }}
{{- else -}}
{{ default "default" .Values.serviceAccounts.engine.name }}
{{- end -}}
{{- end -}}
{{/*
Create the name of the submariner-route-agent service account to use
*/}}
{{- define "submariner.routeAgentServiceAccountName" -}}
{{- if .Values.serviceAccounts.routeAgent.create -}}
{{ default "submariner-routeagent" .Values.serviceAccounts.routeAgent.name }}
{{- else -}}
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
{{- end -}}
{{- end -}}
{{/*
Create the name of the submariner-globalnet service account to use
*/}}
{{- define "submariner.globalnetServiceAccountName" -}}
{{- if .Values.serviceAccounts.globalnet.create -}}
{{ default "submariner-globalnet" .Values.serviceAccounts.globalnet.name }}
{{- else -}}
{{ default "default" .Values.serviceAccounts.globalnet.name }}
{{- end -}}
{{- end -}}
{{/*
Create the name of the submariner-lighthouse-agent service account to use
*/}}
{{- define "submariner.lighthouseAgentServiceAccountName" -}}
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseAgent.create) -}}
{{ default "submariner-lighthouse-agent" .Values.serviceAccounts.lighthouseAgent.name }}
{{- else -}}
{{ default "default" .Values.serviceAccounts.lighthouseAgent.name }}
{{- end -}}
{{- end -}}
{{/*
Create the name of the submariner-lighthouse-coredns service account to use
*/}}
{{- define "submariner.lighthouseCoreDnsServiceAccountName" -}}
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseCoreDns.create) -}}
{{ default "submariner-lighthouse-coredns" .Values.serviceAccounts.lighthouseCoreDns.name }}
{{- else -}}
{{ default "default" .Values.serviceAccounts.lighthouseCoreDns.name }}
{{- end -}}
{{- end -}}
{{/*
Create the name of the submariner-lighthouse-coredns service name to use
*/}}
{{- define "submariner.lighthouseDnsName" -}}
{{- default (printf "%s-lighthouse-coredns" (include "submariner.fullname" .)) .Values.lighthouseCoredns.name }}
{{- end -}}
+138
View File
@@ -0,0 +1,138 @@
apiVersion: apps/v1
kind: DaemonSet
metadata:
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }}-engine
component: engine
name: {{ template "submariner.fullname" . }}-gateway
spec:
revisionHistoryLimit: 5
selector:
matchLabels:
app: {{ template "submariner.fullname" . }}-engine
updateStrategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
creationTimestamp: null
labels:
app: {{ template "submariner.fullname" . }}-engine
spec:
affinity:
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
matchExpressions:
- key: app
operator: In
values:
- {{ template "submariner.fullname" . }}-engine
topologyKey: "kubernetes.io/hostname"
{{- with .Values.engine.affinity }}
{{ toYaml . | indent 8 }}
{{- end }}
nodeSelector:
{{- if .Values.engine.nodeSelectorEnabled }}
submariner.io/gateway: "true"
{{- end }}
{{- with .Values.engine.nodeSelector }}
{{ toYaml . | indent 8 }}
{{- end }}
{{- with .Values.engine.tolerations }}
tolerations:
{{ toYaml . | indent 8 }}
{{- end }}
containers:
- command:
- submariner.sh
env:
- name: SUBMARINER_NAMESPACE
value: "{{ .Release.Namespace }}"
- name: SUBMARINER_CLUSTERCIDR
value: "{{ .Values.submariner.clusterCidr }}"
- name: SUBMARINER_SERVICECIDR
value: "{{ .Values.submariner.serviceCidr }}"
- name: SUBMARINER_GLOBALCIDR
value: "{{ .Values.submariner.globalCidr }}"
- name: SUBMARINER_TOKEN
value: "{{ .Values.submariner.apiToken }}"
- name: SUBMARINER_CLUSTERID
value: "{{ .Values.submariner.clusterId }}"
- name: SUBMARINER_COLORCODES
value: "{{ .Values.submariner.colorCodes }}"
- name: SUBMARINER_DEBUG
value: "{{ .Values.submariner.debug }}"
- name: SUBMARINER_NATENABLED
value: "{{ .Values.submariner.natEnabled }}"
- name: SUBMARINER_BROKER
value: "{{ .Values.broker.type }}"
- name: SUBMARINER_CABLEDRIVER
value: "{{ .Values.submariner.cableDriver }}"
{{- if eq .Values.broker.type "phpapi" }}
- name: BROKER_PHPAPI_PROTO
value: "{{ .Values.broker.proto }}"
- name: BROKER_PHPAPI_SERVER
value: "{{ .Values.broker.server }}"
{{- end }}
{{- if eq .Values.broker.type "k8s" }}
- name: BROKER_K8S_APISERVER
value: "{{ .Values.broker.server }}"
- name: BROKER_K8S_APISERVERTOKEN
value: "{{ .Values.broker.token }}"
- name: BROKER_K8S_REMOTENAMESPACE
value: "{{ .Values.broker.namespace }}"
{{- if .Values.broker.insecure }}
- name: BROKER_K8S_INSECURE
value: "true"
{{- else }}
- name: BROKER_K8S_CA
value: "{{ .Values.broker.ca }}"
{{- end }}
{{- end }}
- name: CE_IPSEC_PSK
value: "{{ .Values.ipsec.psk }}"
- name: CE_IPSEC_DEBUG
value: "{{ .Values.ipsec.debug }}"
- name: CE_IPSEC_IKEPORT
value: "{{ .Values.ipsec.ikePort }}"
- name: CE_IPSEC_NATTPORT
value: "{{ .Values.ipsec.natPort }}"
- name: LEADERSHIP_LEASEDURATION
value: "{{ .Values.leadership.leaseDuration }}"
- name: LEADERSHIP_RENEWDEADLINE
value: "{{ .Values.leadership.renewDeadline }}"
- name: LEADERSHIP_RETRYPERIOD
value: "{{ .Values.leadership.retryPeriod }}"
- name: NODE_NAME
valueFrom:
fieldRef:
fieldPath: "spec.nodeName"
image: {{ .Values.engine.image.repository }}:{{ default .Chart.AppVersion .Values.engine.image.tag }}
imagePullPolicy: {{ .Values.engine.image.pullPolicy }}
name: submariner
resources:
{{ toYaml .Values.engine.resources | indent 10 }}
securityContext:
allowPrivilegeEscalation: true
capabilities:
add:
- ALL
privileged: true
readOnlyRootFilesystem: false
runAsNonRoot: false
stdin: true
terminationMessagePath: /dev/termination-log
terminationMessagePolicy: File
tty: true
dnsPolicy: ClusterFirst
hostNetwork: true
restartPolicy: Always
schedulerName: default-scheduler
securityContext: {}
terminationGracePeriodSeconds: 1
serviceAccountName: {{ template "submariner.engineServiceAccountName" . }}
+63
View File
@@ -0,0 +1,63 @@
{{- if ne .Values.submariner.globalCidr "" }}
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: {{ template "submariner.fullname" . }}-globalnet
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }}-globalnet
component: globalnet
spec:
selector:
matchLabels:
app: {{ template "submariner.fullname" . }}-globalnet
updateStrategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
labels:
app: {{ template "submariner.fullname" . }}-globalnet
spec:
hostNetwork: true
serviceAccountName: submariner-globalnet
serviceAccount: submariner-globalnet
terminationGracePeriodSeconds: 2
nodeSelector:
submariner.io/gateway: 'true'
containers:
- name: {{ template "submariner.fullname" . }}-globalnet
image: {{ .Values.globalnet.image.repository }}:{{ default .Chart.AppVersion .Values.globalnet.image.tag }}
imagePullPolicy: {{ .Values.globalnet.image.pullPolicy }}
env:
- name: SUBMARINER_CLUSTERID
value: '{{ .Values.submariner.clusterId }}'
- name: SUBMARINER_EXCLUDENS
value: 'submariner-operator,kube-system,operators,openshift-monitoring,openshift-dns'
- name: SUBMARINER_NAMESPACE
value: '{{ .Release.Namespace }}'
- name: NODE_NAME
valueFrom:
fieldRef:
fieldPath: "spec.nodeName"
securityContext:
allowPrivilegeEscalation: true
capabilities:
add:
- ALL
privileged: true
readOnlyRootFilesystem: false
runAsNonRoot: false
volumeMounts:
# Because we don't actually run iptables locally, but chroot in to the host
- mountPath: /host
name: host-slash
readOnly: true
volumes:
- name: host-slash
hostPath:
path: /
{{- end }}
@@ -0,0 +1,74 @@
{{- if .Values.submariner.serviceDiscovery }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ template "submariner.lighthouseDnsName" . }}
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.lighthouseDnsName" . }}
component: lighthouse-coredns
spec:
selector:
matchLabels:
app: {{ template "submariner.lighthouseDnsName" . }}
replicas: 2
template:
metadata:
labels:
app: {{ template "submariner.lighthouseDnsName" . }}
spec:
containers:
- args:
- -conf
- /etc/coredns/Corefile
image: {{ .Values.lighthouseCoredns.image.repository }}:{{ default .Chart.AppVersion .Values.lighthouseCoredns.image.tag }}
imagePullPolicy: {{ .Values.lighthouseCoredns.image.pullPolicy }}
name: {{ template "submariner.lighthouseDnsName" . }}
volumeMounts:
- mountPath: /etc/coredns
name: config-volume
readOnly: true
serviceAccountName: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
volumes:
- configMap:
defaultMode: 420
items:
- key: Corefile
path: Corefile
name: {{ template "submariner.lighthouseDnsName" . }}
name: config-volume
---
apiVersion: v1
kind: Service
metadata:
name: {{ template "submariner.lighthouseDnsName" . }}
labels:
app: {{ template "submariner.lighthouseDnsName" . }}
spec:
ports:
- name: udp
port: 53
protocol: UDP
targetPort: 53
selector:
app: {{ template "submariner.lighthouseDnsName" . }}
type: ClusterIP
---
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ template "submariner.lighthouseDnsName" . }}
data:
Corefile: |
clusterset.local:53 {
{{- if .Values.submariner.debug }}
log
{{- end }}
lighthouse
errors
health
ready
}
{{- end }}
+55
View File
@@ -0,0 +1,55 @@
{{- if .Values.submariner.serviceDiscovery }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ template "submariner.fullname" . }}-lighthouse-agent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }}-lighthouse-agent
component: lighthouse
spec:
replicas: 1
selector:
matchLabels:
app: {{ template "submariner.fullname" . }}-lighthouse-agent
template:
metadata:
labels:
app: {{ template "submariner.fullname" . }}-lighthouse-agent
spec:
serviceAccountName: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
containers:
- command:
- lighthouse-agent.sh
env:
- name: SUBMARINER_NAMESPACE
value: "{{ .Release.Namespace }}"
- name: SUBMARINER_CLUSTERID
value: "{{ .Values.submariner.clusterId }}"
- name: SUBMARINER_DEBUG
value: "{{ .Values.submariner.debug }}"
{{- if ne .Values.submariner.globalCidr "" }}
- name: SUBMARINER_GLOBALNET_ENABLED
value: "true"
{{- end }}
- name: BROKER_K8S_APISERVER
value: "{{ .Values.broker.server }}"
- name: BROKER_K8S_APISERVERTOKEN
value: "{{ .Values.broker.token }}"
- name: BROKER_K8S_REMOTENAMESPACE
value: "{{ .Values.broker.namespace }}"
{{- if .Values.broker.insecure }}
- name: BROKER_K8S_INSECURE
value: "true"
{{- else }}
- name: BROKER_K8S_CA
value: "{{ .Values.broker.ca }}"
{{- end }}
name: {{ template "submariner.fullname" . }}-lighthouse-agent
image: {{ .Values.lighthouse.image.repository }}:{{ default .Chart.AppVersion .Values.lighthouse.image.tag }}
imagePullPolicy: {{ .Values.lighthouse.image.pullPolicy }}
restartPolicy: Always
terminationGracePeriodSeconds: 0
{{- end }}
+670
View File
@@ -0,0 +1,670 @@
{{- if .Values.rbac.create -}}
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: {{ template "submariner.fullname" . }}:engine
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
rules:
- apiGroups:
- ""
resources:
- pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:engine
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ template "submariner.fullname" . }}:engine
subjects:
- kind: ServiceAccount
name: {{ template "submariner.engineServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: {{ template "submariner.fullname" . }}:routeagent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
rules:
- apiGroups:
- ""
resources:
- pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:routeagent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ template "submariner.fullname" . }}:routeagent
subjects:
- kind: ServiceAccount
name: {{ template "submariner.routeAgentServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
{{- if ne .Values.submariner.globalCidr "" }}
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: {{ template "submariner.fullname" . }}:globalnet
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
rules:
- apiGroups:
- ""
resources:
- pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:globalnet
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ template "submariner.fullname" . }}:globalnet
subjects:
- kind: ServiceAccount
name: {{ template "submariner.globalnetServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
{{- end -}}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "submariner.fullname" . }}:engine
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
rules:
- apiGroups:
- ""
resources:
- configmaps
verbs:
- get
- list
- watch
- create
- update
- apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- ""
resources:
- pods
- services
- nodes
verbs:
- get
- list
- watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- submariner.io
resources:
- endpoints
- gateways
- clusters
verbs:
- get
- list
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:engine
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "submariner.fullname" . }}:engine
subjects:
- kind: ServiceAccount
name: {{ template "submariner.engineServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "submariner.fullname" . }}:routeagent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
rules:
- apiGroups:
- ""
resources:
- configmaps
verbs:
- get
- list
- watch
- update
- apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- ""
resources:
- pods
- services
verbs:
- get
- list
- watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- ""
verbs:
- get
- list
- watch
- update
resources:
- nodes
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:routeagent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "submariner.fullname" . }}:routeagent
subjects:
- kind: ServiceAccount
name: {{ template "submariner.routeAgentServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
{{- if ne .Values.submariner.globalCidr "" }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "submariner.fullname" . }}:globalnet
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
rules:
- apiGroups:
- ""
resources:
- pods
- services
- namespaces
- nodes
verbs:
- get
- list
- watch
- update
- apiGroups:
- submariner.io
resources:
- endpoints
- clusters
verbs:
- get
- list
- watch
- apiGroups:
- multicluster.x-k8s.io
resources:
- "serviceexports"
verbs:
- get
- list
- watch
---
{{- end -}}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:globalnet
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "submariner.fullname" . }}:globalnet
subjects:
- kind: ServiceAccount
name: {{ template "submariner.globalnetServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
{{- if .Values.submariner.serviceDiscovery }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-agent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
rules:
- apiGroups:
- ""
resources:
- services
- namespaces
- endpoints
verbs:
- get
- list
- watch
- update
- apiGroups:
- discovery.k8s.io
resources:
- endpointslices
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups:
- submariner.io
resources:
- "gateways"
verbs:
- get
- list
- watch
- apiGroups:
- multicluster.x-k8s.io
resources:
- "*"
verbs:
- create
- get
- list
- watch
- update
- delete
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-agent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "submariner.fullname" . }}:lighthouse-agent
subjects:
- kind: ServiceAccount
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
rules:
- apiGroups:
- ""
resources:
- services
- namespaces
- endpoints
verbs:
- get
- list
- watch
- update
- apiGroups:
- discovery.k8s.io
resources:
- endpointslices
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups:
- lighthouse.submariner.io
resources:
- "*"
verbs:
- create
- get
- list
- watch
- update
- delete
- apiGroups:
- submariner.io
resources:
- "gateways"
verbs:
- get
- list
- watch
- apiGroups:
- multicluster.x-k8s.io
resources:
- "*"
verbs:
- create
- get
- list
- watch
- update
- delete
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
subjects:
- kind: ServiceAccount
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
{{- end -}}
{{- end -}}
+82
View File
@@ -0,0 +1,82 @@
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: {{ template "submariner.fullname" . }}-routeagent
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }}-routeagent
component: routeagent
spec:
selector:
matchLabels:
app: {{ template "submariner.fullname" . }}-routeagent
updateStrategy:
rollingUpdate:
maxUnavailable: "100%"
type: RollingUpdate
template:
metadata:
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.fullname" . }}-routeagent
component: routeagent
spec:
serviceAccountName: {{ template "submariner.routeAgentServiceAccountName" . }}
terminationGracePeriodSeconds: 1
hostNetwork: true
containers:
- name: routeagent
command:
- submariner-route-agent.sh
image: {{ .Values.routeAgent.image.repository }}:{{ default .Chart.AppVersion .Values.routeAgent.image.tag }}
imagePullPolicy: {{ .Values.routeAgent.image.pullPolicy }}
env:
- name: SUBMARINER_NAMESPACE
value: "{{ .Release.Namespace }}"
- name: SUBMARINER_CLUSTERID
value: "{{ .Values.submariner.clusterId }}"
- name: SUBMARINER_DEBUG
value: "{{ .Values.submariner.debug }}"
- name: SUBMARINER_CLUSTERCIDR
value: "{{ .Values.submariner.clusterCidr }}"
- name: SUBMARINER_SERVICECIDR
value: "{{ .Values.submariner.serviceCidr }}"
- name: NODE_NAME
valueFrom:
fieldRef:
fieldPath: "spec.nodeName"
resources:
{{ toYaml .Values.routeAgent.resources | indent 10 }}
securityContext:
allowPrivilegeEscalation: true
capabilities:
add:
- ALL
privileged: true
readOnlyRootFilesystem: false
runAsNonRoot: false
volumeMounts:
# Because we don't actually run iptables locally, but chroot in to the host
- mountPath: /host
name: host-slash
readOnly: true
{{- with .Values.routeAgent.nodeSelector }}
nodeSelector:
{{ toYaml . | indent 8 }}
{{- end }}
{{- with .Values.routeAgent.tolerations }}
tolerations:
{{ toYaml . | indent 8 }}
{{- end }}
{{- with .Values.routeAgent.affinity }}
affinity:
{{ toYaml . | indent 8 }}
{{- end }}
volumes:
- name: host-slash
hostPath:
path: /
+59
View File
@@ -0,0 +1,59 @@
{{- if .Values.serviceAccounts.engine.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ template "submariner.engineServiceAccountName" . }}
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
{{- end }}
---
{{- if .Values.serviceAccounts.routeAgent.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ template "submariner.routeAgentServiceAccountName" . }}
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
{{- end }}
---
{{- if .Values.serviceAccounts.globalnet.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ template "submariner.globalnetServiceAccountName" . }}
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
{{- end }}
---
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
{{- end }}
---
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }}
{{- end }}
+82
View File
@@ -0,0 +1,82 @@
---
submariner:
clusterId: ""
token: ""
clusterCidr: "10.42.0.0/16"
serviceCidr: "10.43.0.0/16"
globalCidr: ""
natEnabled: false
colorCodes: blue
debug: false
serviceDiscovery: false
crd:
create: true
broker:
type: k8s
server: example.k8s.apiserver
token: test
namespace: xyz
insecure: false
ca: ""
rbac:
create: true
ipsec:
psk: ""
debug: false
ikePort: 500
natPort: 4500
leadership:
leaseDuration: 10
renewDeadline: 5
retryPeriod: 2
engine:
image:
repository: quay.io/submariner/submariner
tag: ""
pullPolicy: IfNotPresent
resources: {}
nodeSelectorEnabled: true
nodeSelector: {}
tolerations: []
affinity: {}
routeAgent:
image:
repository: quay.io/submariner/submariner-route-agent
tag: ""
pullPolicy: IfNotPresent
resources: {}
nodeSelector: {}
tolerations: []
affinity: {}
globalnet:
image:
repository: quay.io/submariner/submariner-globalnet
tag: ""
pullPolicy: IfNotPresent
lighthouse:
image:
repository: quay.io/submariner/lighthouse-agent
tag: ""
pullPolicy: IfNotPresent
lighthouseCoredns:
name: ""
image:
repository: quay.io/submariner/lighthouse-coredns
tag: ""
pullPolicy: IfNotPresent
serviceAccounts:
engine:
create: true
name: ""
routeAgent:
create: true
name: ""
globalnet:
create: true
name: ""
lighthouseAgent:
create: true
name: ""
lighthouseCoreDns:
create: true
name: ""