mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-20 22:40:34 +00:00
Compare commits
@@ -1,38 +0,0 @@
|
||||
---
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.14"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.15"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.16"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
@@ -0,0 +1,57 @@
|
||||
---
|
||||
# Configuration for probot-stale - https://github.com/probot/stale
|
||||
|
||||
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
|
||||
daysUntilStale: 120
|
||||
|
||||
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
|
||||
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
|
||||
daysUntilClose: 7
|
||||
|
||||
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
|
||||
onlyLabels: []
|
||||
|
||||
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
|
||||
exemptLabels:
|
||||
- security
|
||||
- confirmed
|
||||
|
||||
# Set to true to ignore issues in a project (defaults to false)
|
||||
exemptProjects: false
|
||||
|
||||
# Set to true to ignore issues in a milestone (defaults to false)
|
||||
exemptMilestones: false
|
||||
|
||||
# Set to true to ignore issues with an assignee (defaults to false)
|
||||
exemptAssignees: false
|
||||
|
||||
# Label to use when marking as stale
|
||||
staleLabel: wontfix
|
||||
|
||||
# Comment to post when marking as stale. Set to `false` to disable
|
||||
markComment: >
|
||||
This issue has been automatically marked as stale because it has not had
|
||||
activity for 60 days. It will be closed if no further activity occurs.
|
||||
Please make a comment if this issue/pr is still valid. Thank you
|
||||
for your contributions.
|
||||
|
||||
# Comment to post when removing the stale label.
|
||||
# unmarkComment: >
|
||||
# Your comment here.
|
||||
|
||||
# Comment to post when closing a stale Issue or Pull Request.
|
||||
# closeComment: >
|
||||
# Your comment here.
|
||||
|
||||
# Limit the number of actions per hour, from 1-30. Default is 30
|
||||
limitPerRun: 30
|
||||
|
||||
# Limit to only `issues` or `pulls`
|
||||
# only: issues
|
||||
|
||||
pulls:
|
||||
daysUntilStale: 30
|
||||
markComment: >
|
||||
This pull request has been automatically marked as stale because it has not had
|
||||
recent activity. It will be closed if no further activity occurs. Thank you
|
||||
for your contributions.
|
||||
@@ -4,13 +4,11 @@ name: Branch Checks
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
target_branch:
|
||||
name: PR targets branch
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check that the PR targets release-0.17
|
||||
if: ${{ github.base_ref != 'release-0.17' }}
|
||||
- name: Check that the PR targets release-0.12
|
||||
if: ${{ github.base_ref != 'release-0.12' }}
|
||||
run: exit 1
|
||||
|
||||
@@ -17,12 +17,7 @@ on:
|
||||
- reopened
|
||||
- synchronize
|
||||
schedule:
|
||||
- cron: '0 0/6 * * *' # every 6 hours
|
||||
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
statuses: write
|
||||
- cron: '0 0/6 * * *' # every 6 hours
|
||||
|
||||
jobs:
|
||||
check:
|
||||
@@ -30,7 +25,7 @@ jobs:
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43
|
||||
- uses: z0al/dependent-issues@0fae07162bc9e0d8e116a133bd03686eed6efa21
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
with:
|
||||
|
||||
@@ -5,8 +5,6 @@ on:
|
||||
pull_request:
|
||||
types: [labeled, opened, synchronize, reopened]
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
@@ -18,22 +16,22 @@ jobs:
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
# Run most tests against the latest K8s version
|
||||
k8s_version: ['1.29']
|
||||
k8s_version: ['1.23']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
include:
|
||||
# Bottom of supported K8s version range
|
||||
- k8s_version: '1.26'
|
||||
- k8s_version: '1.20'
|
||||
- k8s_version: '1.21'
|
||||
- k8s_version: '1.22'
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.17
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.12
|
||||
with:
|
||||
k8s_version: ${{ matrix.k8s_version }}
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.17
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.12
|
||||
|
||||
@@ -4,8 +4,6 @@ name: End to End Default
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
@@ -13,11 +11,11 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.17
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.12
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.17
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.12
|
||||
|
||||
@@ -5,8 +5,6 @@ on:
|
||||
schedule:
|
||||
- cron: "0 0 * * *"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
@@ -21,13 +19,13 @@ jobs:
|
||||
lighthouse: ['', 'lighthouse']
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.17
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.12
|
||||
with:
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.17
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.12
|
||||
|
||||
@@ -4,8 +4,6 @@ name: Linting
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
apply-suggestions-commits:
|
||||
name: 'No "Apply suggestions from code review" Commits'
|
||||
@@ -13,12 +11,12 @@ jobs:
|
||||
steps:
|
||||
- name: Get PR commits
|
||||
id: 'get-pr-commits'
|
||||
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d
|
||||
uses: tim-actions/get-pr-commits@c64db31d359214d244884dd68f971a110b29ab83
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: 'Verify no "Apply suggestions from code review" commits'
|
||||
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
||||
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
|
||||
with:
|
||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||
pattern: '^(?!.*(apply suggestions from code review))'
|
||||
@@ -26,7 +24,7 @@ jobs:
|
||||
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
||||
|
||||
- name: 'Verify no "fixup!" commits'
|
||||
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
||||
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
|
||||
with:
|
||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||
pattern: '^(?!fixup!)'
|
||||
@@ -38,23 +36,20 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814
|
||||
uses: azure/setup-helm@f382f75448129b3be48f8121b9857be18d815a82
|
||||
with:
|
||||
version: v3.6.0
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@82c7e631bb3cdc910f68e0081d67478d79c6982d
|
||||
uses: actions/setup-python@2c3dd9e7e29afd70cc0950079bde6c979d1f69f9
|
||||
with:
|
||||
python-version: '3.x'
|
||||
|
||||
- name: Set up helm/chart-testing
|
||||
uses: helm/chart-testing-action@e6669bcd63d7cb57cb4380c33043eebe5d111992
|
||||
|
||||
- name: Set up local helm repo
|
||||
run: make local-helm-repo
|
||||
uses: helm/chart-testing-action@afea100a513515fbd68b0e72a7bb0ae34cb62aec
|
||||
|
||||
- name: Run helm/chart-testing (lint)
|
||||
run: ct lint --config ct.yaml
|
||||
@@ -64,7 +59,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Run gitlint
|
||||
@@ -75,7 +70,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
|
||||
- name: Run helm-docs and verify docs are up-to-date
|
||||
run: make helm-docs
|
||||
@@ -85,10 +80,10 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@4d97ad89bbb0de4be573a9d7a2fc0ce900afc519
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
check-modified-files-only: "yes"
|
||||
@@ -99,7 +94,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
- name: Run markdownlint
|
||||
run: make markdownlint
|
||||
|
||||
@@ -108,6 +103,10 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
- name: Run yamllint
|
||||
run: make yamllint
|
||||
uses: ibiqlik/action-yamllint@2576378a8e339169678f9939646ee3ee325e845c
|
||||
with:
|
||||
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
|
||||
config_file: .yamllint.yml
|
||||
strict: true
|
||||
|
||||
@@ -5,27 +5,23 @@ on:
|
||||
schedule:
|
||||
- cron: "0 0 * * 0"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
markdown-link-check-periodic:
|
||||
name: Markdown Links (all files)
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@4d97ad89bbb0de4be573a9d7a2fc0ce900afc519
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
|
||||
- name: Raise an Issue to report broken links
|
||||
if: ${{ failure() }}
|
||||
uses: peter-evans/create-issue-from-file@24452a72d85239eacf1468b0f1982a9f3fec4c94
|
||||
uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f
|
||||
with:
|
||||
title: Broken link detected by CI
|
||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||
|
||||
@@ -4,10 +4,7 @@ name: Release Charts
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- release-0.17
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
- release-0.12
|
||||
|
||||
jobs:
|
||||
release:
|
||||
@@ -16,7 +13,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
|
||||
uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
|
||||
@@ -1,32 +0,0 @@
|
||||
---
|
||||
name: Stale
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "0 0 * * *"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
name: Close Stale Issues and PRs
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
steps:
|
||||
- uses: actions/stale@3f3b0175e8c66fb49b9a6d5a0cd1f8436d4c3ab6
|
||||
with:
|
||||
days-before-issue-stale: 120
|
||||
days-before-pr-stale: 14
|
||||
exempt-issue-labels: 'confirmed,security'
|
||||
exempt-pr-labels: 'confirmed,security'
|
||||
stale-issue-label: 'stale'
|
||||
stale-issue-message: |
|
||||
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||
activity occurs. Thank you for your contributions.
|
||||
stale-pr-label: 'stale'
|
||||
stale-pr-message: |
|
||||
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||
activity occurs. Thank you for your contributions.
|
||||
@@ -3,6 +3,3 @@
|
||||
.shflags
|
||||
*.tgz
|
||||
Makefile.dapper
|
||||
Makefile.shipyard
|
||||
Dockerfile.*
|
||||
helm_repo
|
||||
|
||||
@@ -1,8 +1,5 @@
|
||||
{
|
||||
"ignorePatterns": [
|
||||
{
|
||||
"pattern": "^https://docs.github.com"
|
||||
},
|
||||
{
|
||||
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
||||
},
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
---
|
||||
cni: ovn
|
||||
submariner: true
|
||||
nodes: control-plane
|
||||
nodes: control-plane worker worker
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
---
|
||||
submariner: true
|
||||
nodes: control-plane
|
||||
nodes: control-plane worker
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
label-approved:
|
||||
approvals: 2
|
||||
label: ready-to-test
|
||||
|
||||
+11
-11
@@ -1,15 +1,15 @@
|
||||
---
|
||||
extends: default
|
||||
|
||||
rules:
|
||||
comments: disable
|
||||
comments-indentation: disable
|
||||
line-length:
|
||||
max: 140
|
||||
# Allow standard GHA syntax for "on: *"
|
||||
truthy:
|
||||
ignore: '.github/workflows/*.yml'
|
||||
|
||||
ignore: |
|
||||
/submariner-k8s-broker/crds
|
||||
/submariner-operator/crds
|
||||
/submariner-k8s-broker/templates
|
||||
/submariner-operator/templates
|
||||
max: 150
|
||||
braces:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 0
|
||||
brackets:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 0
|
||||
indentation:
|
||||
indent-sequences: consistent
|
||||
+2
-3
@@ -1,4 +1,3 @@
|
||||
# Auto-generated, do not edit; see CODEOWNERS.in
|
||||
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
|
||||
* @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
|
||||
+1
-5
@@ -1,9 +1,5 @@
|
||||
@aswinsuryan Makefile
|
||||
@dfarrell07 *.md Makefile
|
||||
@maayanf24 Makefile
|
||||
@dfarrell07 *.md
|
||||
@Oats87 *
|
||||
@skitt *
|
||||
@sridhargaddam *
|
||||
@tpantelis *
|
||||
@vthapar *
|
||||
@yboaron Makefile
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
ARG BASE_BRANCH
|
||||
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH}
|
||||
|
||||
ARG DAPPER_HOST_ARCH
|
||||
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
|
||||
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
|
||||
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
|
||||
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
|
||||
|
||||
WORKDIR ${DAPPER_SOURCE}
|
||||
|
||||
RUN git config --global --add safe.directory ${DAPPER_SOURCE}
|
||||
|
||||
# Override the Helm deployment scripts
|
||||
COPY deploy_helm /opt/shipyard/scripts/lib/
|
||||
|
||||
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
|
||||
CMD ["sh"]
|
||||
@@ -1,42 +1,46 @@
|
||||
BASE_BRANCH ?= release-0.17
|
||||
BASE_BRANCH ?= release-0.12
|
||||
export BASE_BRANCH
|
||||
export HELM_REPO_LOCATION=./helm_repo
|
||||
|
||||
ifneq (,$(DAPPER_HOST_ARCH))
|
||||
|
||||
# Running in Dapper
|
||||
|
||||
PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent lighthouse-agent lighthouse-coredns
|
||||
|
||||
include $(SHIPYARD_DIR)/Makefile.inc
|
||||
|
||||
ifneq (,$(filter ovn,$(_using)))
|
||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||
else
|
||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||
CLUSTER_SETTINGS_FLAG = --settings $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||
endif
|
||||
|
||||
export DEPLOYTOOL = helm
|
||||
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
|
||||
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
|
||||
export DEPLOY_ARGS
|
||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||
CHARTS_DIR=charts
|
||||
CHARTS_VERSION=0.17.2
|
||||
CHARTS_VERSION=0.12.2
|
||||
HELM_DOCS_VERSION=0.15.0
|
||||
REPO_URL=$(shell git config remote.origin.url)
|
||||
|
||||
# Process extra flags from the `using=a,b,c` optional flag
|
||||
|
||||
ifneq (,$(filter lighthouse,$(_using)))
|
||||
override DEPLOY_ARGS += --service_discovery
|
||||
endif
|
||||
|
||||
ifneq (,$(filter globalnet,$(_using)))
|
||||
override DEPLOY_ARGS += --globalnet
|
||||
endif
|
||||
|
||||
# Targets to make
|
||||
|
||||
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||
|
||||
local-helm-repo: $(CHART_PACKAGES)
|
||||
mkdir -p $(HELM_REPO_LOCATION)
|
||||
for archive in $^; do \
|
||||
tar xzf $$archive -C $(HELM_REPO_LOCATION); \
|
||||
done
|
||||
|
||||
e2e: local-helm-repo
|
||||
$(SCRIPTS_DIR)/e2e.sh
|
||||
e2e: E2E_ARGS=cluster1 cluster2
|
||||
|
||||
%.tgz:
|
||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
|
||||
helm-docs:
|
||||
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
||||
@@ -52,7 +56,7 @@ helm-docs:
|
||||
exit 1; \
|
||||
fi
|
||||
|
||||
release: $(CHART_PACKAGES)
|
||||
release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||
git checkout gh-pages
|
||||
mv *.tgz $(CHARTS_DIR)
|
||||
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
||||
|
||||
@@ -60,4 +60,4 @@ working correctly.
|
||||
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
|
||||
[Docker]: https://docs.docker.com/install/
|
||||
[Podman]: https://podman.io/getting-started/installation
|
||||
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo
|
||||
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
---
|
||||
charts:
|
||||
- ./helm_repo/submariner-operator
|
||||
- ./helm_repo/submariner-k8s-broker
|
||||
- submariner-operator
|
||||
- submariner-k8s-broker
|
||||
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
||||
# See: https://github.com/helm/chart-testing/issues/192
|
||||
validate-maintainers: false
|
||||
|
||||
+76
@@ -0,0 +1,76 @@
|
||||
# shellcheck shell=bash
|
||||
# shellcheck source=scripts/shared/lib/source_only
|
||||
. "${BASH_SOURCE%/*}"/source_only
|
||||
|
||||
### Constants ###
|
||||
|
||||
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
|
||||
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
|
||||
|
||||
### Functions ###
|
||||
|
||||
function deploytool_prereqs() {
|
||||
helm version
|
||||
}
|
||||
|
||||
function setup_broker() {
|
||||
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
|
||||
echo "Submariner CRDs already exist, skipping broker creation..."
|
||||
else
|
||||
echo "Installing submariner broker..."
|
||||
# shellcheck disable=SC2086 # Split on purpose
|
||||
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
|
||||
--create-namespace \
|
||||
--kube-context "${cluster}" \
|
||||
--namespace "${SUBMARINER_BROKER_NS}" \
|
||||
${deploytool_broker_args}
|
||||
fi
|
||||
|
||||
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
||||
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
|
||||
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
|
||||
}
|
||||
|
||||
function helm_install_subm() {
|
||||
local crd_create=false
|
||||
[[ "${cluster}" = "${broker}" ]] || crd_create=true
|
||||
|
||||
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
|
||||
echo "Submariner already installed, skipping installation..."
|
||||
return
|
||||
fi
|
||||
|
||||
echo "Installing Submariner..."
|
||||
# shellcheck disable=SC2086 # Split on purpose
|
||||
helm --kube-context "${cluster}" install submariner-operator \
|
||||
./submariner-operator \
|
||||
--create-namespace \
|
||||
--namespace "${SUBM_NS}" \
|
||||
--set ipsec.psk="${SUBMARINER_PSK}" \
|
||||
--set broker.server="${submariner_broker_url}" \
|
||||
--set broker.token="${submariner_broker_token}" \
|
||||
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
|
||||
--set broker.ca="${submariner_broker_ca}" \
|
||||
--set broker.globalnet="${globalnet}" \
|
||||
--set submariner.serviceDiscovery="${service_discovery}" \
|
||||
--set submariner.cableDriver="${cable_driver}" \
|
||||
--set submariner.clusterId="${cluster}" \
|
||||
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
|
||||
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
|
||||
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
|
||||
--set serviceAccounts.globalnet.create="${globalnet}" \
|
||||
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
|
||||
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
|
||||
--set submariner.natEnabled="false" \
|
||||
--set operator.image.repository="localhost:5000/submariner-operator" \
|
||||
--set operator.image.tag="local" \
|
||||
--set operator.image.pullPolicy="IfNotPresent" \
|
||||
--set submariner.images.repository="localhost:5000" \
|
||||
--set submariner.images.tag="local" \
|
||||
--set brokercrds.create="${crd_create}" \
|
||||
${deploytool_submariner_args}
|
||||
}
|
||||
|
||||
function install_subm_all_clusters() {
|
||||
run_subm_clusters helm_install_subm
|
||||
}
|
||||
@@ -1,7 +1,8 @@
|
||||
---
|
||||
name: submariner-k8s-broker
|
||||
version: 0.0.0
|
||||
version: 0.12.2
|
||||
apiVersion: v2
|
||||
appVersion: 0.12.2
|
||||
description: Submariner Kubernetes Broker
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# submariner-k8s-broker
|
||||
|
||||
 
|
||||
|
||||
Submariner Kubernetes Broker
|
||||
|
||||
**Homepage:** <https://submariner-io.github.io/>
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
questions:
|
||||
- variable: submariner-k8s-broker.rbac.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Role Based Access Control"
|
||||
description: "Create the role/rolebinding for the Submariner client"
|
||||
label: "RBAC Creation Enabled"
|
||||
- variable: submariner-k8s-broker.crd.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Submariner CRD"
|
||||
description: "Create the submariner CRDs for the Submariner client"
|
||||
label: "Submariner CRD Creation Enabled"
|
||||
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Service Account"
|
||||
description: "Create the service account for the Submariner client"
|
||||
label: "Submariner Service Account Creation Enabled"
|
||||
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
|
||||
|
||||
The broker client token and CA can be retrieved by running
|
||||
|
||||
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
|
||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
|
||||
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
|
||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
|
||||
|
||||
@@ -8,12 +8,4 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||
app: {{ template "submariner-k8s-broker.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
@@ -1,7 +1,8 @@
|
||||
---
|
||||
name: submariner-operator
|
||||
version: 0.0.0
|
||||
version: 0.12.2
|
||||
apiVersion: v2
|
||||
appVersion: 0.12.2
|
||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# submariner-operator
|
||||
|
||||
 
|
||||
|
||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
|
||||
**Homepage:** <https://submariner-io.github.io/>
|
||||
@@ -24,6 +26,8 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| broker.namespace | string | `"xyz"` | |
|
||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
||||
| broker.token | string | `"test"` | |
|
||||
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
|
||||
| gateway.image.tag | string | `"0.12.2"` | |
|
||||
| ipsec.debug | bool | `false` | |
|
||||
| ipsec.forceUDPEncaps | bool | `false` | |
|
||||
| ipsec.ikePort | int | `500` | |
|
||||
@@ -35,7 +39,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| operator.affinity | object | `{}` | |
|
||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
||||
| operator.image.tag | string | `"0.14.0"` | |
|
||||
| operator.image.tag | string | `"0.12.2"` | |
|
||||
| operator.resources | object | `{}` | |
|
||||
| operator.tolerations | list | `[]` | |
|
||||
| rbac.create | bool | `true` | |
|
||||
@@ -60,7 +64,7 @@ Submariner enables direct networking between Pods and Services in different Kube
|
||||
| submariner.globalCidr | string | `""` | |
|
||||
| submariner.healthcheckEnabled | bool | `true` | |
|
||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||
| submariner.images.tag | string | `"0.14.0"` | |
|
||||
| submariner.images.tag | string | `"0.12.2"` | |
|
||||
| submariner.natEnabled | bool | `false` | |
|
||||
| submariner.serviceCidr | string | `""` | |
|
||||
| submariner.serviceDiscovery | bool | `true` | |
|
||||
|
||||
@@ -0,0 +1,144 @@
|
||||
questions:
|
||||
- variable: defaultOperatorImage
|
||||
default: true
|
||||
description: "Use default Submariner operator image or specify a custom one"
|
||||
label: Use default Submariner operator image
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container Images"
|
||||
subquestions:
|
||||
- variable: operator.image.repository
|
||||
default: "quay.io/submariner/submariner-operator"
|
||||
description: "Submariner Operator Image Repository"
|
||||
type: string
|
||||
label: Submariner Operator Image Repository
|
||||
- variable: operator.image.tag
|
||||
default: "0.12.2"
|
||||
description: "Submariner Operator Image Tag"
|
||||
type: string
|
||||
label: Submariner Operator Image Tag
|
||||
- variable: defaultSubmarinerImages
|
||||
default: true
|
||||
description: "Use default Submariner images or specify custom ones"
|
||||
label: Use default Submariner images
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container images"
|
||||
subquestions:
|
||||
- variable: submariner.images.repository
|
||||
default: "quay.io/submariner"
|
||||
description: "Submariner Repository (base for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Repository
|
||||
- variable: submariner.images.tag
|
||||
default: "0.12.2"
|
||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Images Tag
|
||||
- variable: submariner.clusterId
|
||||
default: ""
|
||||
description: "Enter a unique cluster ID to identify this cluster"
|
||||
type: string
|
||||
label: "Cluster ID"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: ipsec.psk
|
||||
default: ""
|
||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
||||
type: string
|
||||
label: "IPsec Pre-Shared Key"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: broker.server
|
||||
type: string
|
||||
default: ""
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Server"
|
||||
description: "Broker server to use (without the https://)"
|
||||
- variable: broker.insecure
|
||||
type: boolean
|
||||
default: false
|
||||
show_subquestion_if: false
|
||||
group: "Broker Configuration"
|
||||
label: "Insecure Broker"
|
||||
description: "Connect to K8s broker without validating CA"
|
||||
subquestions:
|
||||
- variable: broker.ca
|
||||
type: string
|
||||
description: "Base64 encoded broker ca.crt"
|
||||
label: "Broker CA encoded in base64"
|
||||
default: ""
|
||||
- variable: broker.token
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Token"
|
||||
description: "Bearer token for broker"
|
||||
- variable: broker.namespace
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Namespace"
|
||||
description: "Enter namespace to use on central broker"
|
||||
- variable: submariner.clusterCidr
|
||||
default: ""
|
||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Cluster CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.serviceCidr
|
||||
default: ""
|
||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Service CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.serviceDiscovery
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable multicluster service discovery"
|
||||
label: "Service Discovery Enabled"
|
||||
- variable: broker.globalnet
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Broker Configuration"
|
||||
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
|
||||
label: "Globalnet Enabled"
|
||||
subquestions:
|
||||
- variable: submariner.globalCidr
|
||||
default: ""
|
||||
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
|
||||
type: string
|
||||
label: "Globalnet CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: false
|
||||
- variable: submariner.natEnabled
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
||||
label: "NAT Enabled"
|
||||
- variable: submariner.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable submariner debug mode"
|
||||
label: "Submariner Debug Enabled"
|
||||
- variable: ipsec.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable Charon debug mode"
|
||||
label: "Charon Enabled"
|
||||
- variable: submariner.cableDriver
|
||||
type: string
|
||||
default: ""
|
||||
group: "Advanced Configuration"
|
||||
description: "Cable driver implementation"
|
||||
label: "Cable Driver"
|
||||
- variable: submariner.healthcheckEnabled
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Advanced Configuration"
|
||||
description: "Disable Healthcheck"
|
||||
label: "Healthcheck Disabled"
|
||||
@@ -1,3 +1,7 @@
|
||||
Submariner is now installed.
|
||||
|
||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||
{{- if .Values.gateway.nodeSelectorEnabled }}
|
||||
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
||||
{{- end }}
|
||||
|
||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||
@@ -9,94 +9,62 @@ metadata:
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
# For metrics
|
||||
- services
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
# For syncing Secrets from the broker
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
# Temporarily needed for network-plugin syncer removal
|
||||
- serviceaccounts
|
||||
resourceNames:
|
||||
- submariner-networkplugin-syncer
|
||||
verbs:
|
||||
- delete
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
# Needed for openshift monitoring
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- {{ template "submariner.fullname" . }}
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- brokers
|
||||
- brokers/status
|
||||
- submariners
|
||||
- submariners/status
|
||||
- servicediscoveries
|
||||
- servicediscoveries/status
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gateways
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- submariners/finalizers
|
||||
- servicediscoveries/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- {{ template "submariner.fullname" . }}
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
---
|
||||
kind: RoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
@@ -125,38 +93,75 @@ metadata:
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- update
|
||||
- patch
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- clusters
|
||||
- endpoints
|
||||
- gateways
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- submariner-operator
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- lighthouse.submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- serviceexports
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
@@ -187,25 +192,74 @@ metadata:
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- submariner-operator
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gatewayroutes
|
||||
- nongatewayroutes
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- lighthouse.submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- serviceexports
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- delete
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
@@ -237,16 +291,74 @@ metadata:
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
- ""
|
||||
resources:
|
||||
- leases
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- submariner-operator
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- lighthouse.submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- serviceexports
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
@@ -301,10 +413,9 @@ rules:
|
||||
- update
|
||||
- delete
|
||||
- watch
|
||||
- apiGroups:
|
||||
- apiGroups: # pods, services and nodes are looked up to figure out network settings
|
||||
- ""
|
||||
resources:
|
||||
# Needed for network settings discovery
|
||||
- pods
|
||||
- services
|
||||
- nodes
|
||||
@@ -318,42 +429,31 @@ rules:
|
||||
- dnses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
resources:
|
||||
# Needed for network settings discovery
|
||||
- networks
|
||||
resourceNames:
|
||||
- cluster
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- namespaces
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
# Needed for openshift monitoring
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
# Needed for Flannel CNI discovery
|
||||
- daemonsets
|
||||
verbs:
|
||||
- list
|
||||
- apiGroups:
|
||||
- rbac.authorization.k8s.io
|
||||
resources:
|
||||
# Temporarily needed for network-plugin syncer removal
|
||||
- clusterroles
|
||||
- clusterrolebindings
|
||||
resourceNames:
|
||||
- ocp-submariner-networkplugin-syncer
|
||||
- submariner-networkplugin-syncer
|
||||
verbs:
|
||||
- delete
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -412,7 +512,21 @@ rules:
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- create
|
||||
- update
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups: # pods and services are looked up to figure out network settings
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
@@ -422,6 +536,32 @@ rules:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- operator.openshift.io
|
||||
resources:
|
||||
- dnses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
resources:
|
||||
- networks
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- endpoints
|
||||
- gateways
|
||||
- clusters
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -454,41 +594,56 @@ rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- secrets
|
||||
- configmaps
|
||||
- endpoints
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
resources:
|
||||
- networks
|
||||
resourceNames:
|
||||
- cluster
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- projectcalico.org
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- ippools
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- create
|
||||
- delete
|
||||
- update
|
||||
- deletecollection
|
||||
- delete
|
||||
- apiGroups: # pods and services are looked up to figure out network settings
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- operator.openshift.io
|
||||
resources:
|
||||
- dnses
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- config.openshift.io
|
||||
resources:
|
||||
- networks
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
resources:
|
||||
- nodes
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -522,25 +677,19 @@ rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- namespaces
|
||||
- nodes
|
||||
- endpoints
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- services
|
||||
- endpoints
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
@@ -551,8 +700,8 @@ rules:
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- clusters
|
||||
- endpoints
|
||||
- clusters
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -561,11 +710,17 @@ rules:
|
||||
- submariner.io
|
||||
resources:
|
||||
- clusterglobalegressips
|
||||
- clusterglobalegressips/status
|
||||
- globalegressips
|
||||
- globalegressips/status
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- globalingressips
|
||||
- globalingressips/status
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
@@ -577,7 +732,7 @@ rules:
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceexports
|
||||
- "serviceexports"
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -632,6 +787,7 @@ rules:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- discovery.k8s.io
|
||||
resources:
|
||||
@@ -648,8 +804,8 @@ rules:
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gateways
|
||||
- globalingressips
|
||||
- "gateways"
|
||||
- "globalingressips"
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -657,8 +813,7 @@ rules:
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceimports
|
||||
- serviceimports/status
|
||||
- "*"
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
@@ -666,20 +821,6 @@ rules:
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceexports
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceexports/status
|
||||
verbs:
|
||||
- update
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
@@ -705,18 +846,43 @@ metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
||||
rules:
|
||||
- apiGroups:
|
||||
- discovery.k8s.io
|
||||
- ""
|
||||
resources:
|
||||
- endpointslices
|
||||
- services
|
||||
- namespaces
|
||||
- endpoints
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- discovery.k8s.io
|
||||
resources:
|
||||
- endpointslices
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- deletecollection
|
||||
- apiGroups:
|
||||
- lighthouse.submariner.io
|
||||
resources:
|
||||
- "*"
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- gateways
|
||||
- submariners
|
||||
- "gateways"
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -724,11 +890,14 @@ rules:
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
- serviceimports
|
||||
- "*"
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
|
||||
@@ -19,37 +19,10 @@ spec:
|
||||
clusterID: {{ .Values.submariner.clusterId }}
|
||||
colorCodes: {{ .Values.submariner.colorCodes }}
|
||||
debug: {{ .Values.submariner.debug }}
|
||||
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
natEnabled: {{ .Values.submariner.natEnabled }}
|
||||
repository: {{ .Values.submariner.images.repository }}
|
||||
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }}
|
||||
{{- with .Values.images }}
|
||||
{{- if . }}
|
||||
imageOverrides:
|
||||
{{- if index . "submariner-operator" }}
|
||||
submariner-operator: {{ index . "submariner-operator" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-gateway" }}
|
||||
submariner-gateway: {{ index . "submariner-gateway" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-route-agent" }}
|
||||
submariner-routeagent: {{ index . "submariner-route-agent" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-globalnet" }}
|
||||
submariner-globalnet: {{ index . "submariner-globalnet" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-networkplugin-syncer" }}
|
||||
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
|
||||
{{- end }}
|
||||
{{- if index . "lighthouse-agent" }}
|
||||
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
|
||||
{{- end }}
|
||||
{{- if index . "lighthouse-coredns" }}
|
||||
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
version: {{ .Values.submariner.images.tag }}
|
||||
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||
@@ -60,6 +33,6 @@ spec:
|
||||
maxPacketLossCount: 5
|
||||
{{- with .Values.submariner.coreDNSCustomConfig }}
|
||||
coreDNSCustomConfig:
|
||||
configMapName: {{ .configMapName }}
|
||||
configmapName: {{ .configmapName }}
|
||||
namespace: {{ .namespace }}
|
||||
{{- end }}
|
||||
|
||||
@@ -8,14 +8,6 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.gateway.create }}
|
||||
@@ -28,14 +20,6 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
||||
@@ -48,14 +32,6 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.globalnet.create }}
|
||||
@@ -68,14 +44,6 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
|
||||
@@ -88,14 +56,6 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
|
||||
@@ -108,12 +68,4 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
{{- end }}
|
||||
|
||||
@@ -5,7 +5,6 @@ submariner:
|
||||
clusterCidr: ""
|
||||
serviceCidr: ""
|
||||
globalCidr: ""
|
||||
loadBalancerEnabled: false
|
||||
natEnabled: false
|
||||
colorCodes: blue
|
||||
debug: false
|
||||
@@ -15,7 +14,7 @@ submariner:
|
||||
coreDNSCustomConfig: {}
|
||||
images:
|
||||
repository: quay.io/submariner
|
||||
tag: ""
|
||||
tag: "0.12.2"
|
||||
broker:
|
||||
server: example.k8s.apiserver
|
||||
token: test
|
||||
@@ -25,7 +24,6 @@ broker:
|
||||
globalnet: false
|
||||
rbac:
|
||||
create: true
|
||||
images: {}
|
||||
ipsec:
|
||||
psk: ""
|
||||
debug: false
|
||||
@@ -39,11 +37,15 @@ leadership:
|
||||
operator:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-operator
|
||||
tag: ""
|
||||
tag: "0.12.2"
|
||||
pullPolicy: IfNotPresent
|
||||
resources: {}
|
||||
tolerations: []
|
||||
affinity: {}
|
||||
gateway:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-gateway
|
||||
tag: "0.12.2"
|
||||
serviceAccounts:
|
||||
operator:
|
||||
create: true
|
||||
|
||||
Reference in New Issue
Block a user