Compare commits

...
33 Commits
Author SHA1 Message Date
Automated ReleaseandSubmariner Bot 31c51fde17 Update Submariner dependencies to v0.19.1
Signed-off-by: Automated Release <release@submariner.io>
2024-11-28 13:49:17 +02:00
Automated ReleaseandSubmariner Bot 0c7a0d0ddb Update Submariner dependencies to v0.19.0
Signed-off-by: Automated Release <release@submariner.io>
2024-10-25 17:26:43 +03:00
Automated ReleaseandSubmariner Bot afe03c2134 Update Submariner dependencies to v0.19.0-rc3
Signed-off-by: Automated Release <release@submariner.io>
2024-10-18 18:28:40 +03:00
Automated ReleaseandSubmariner Bot 9a17c7a025 Update Submariner dependencies to v0.19.0-rc2
Signed-off-by: Automated Release <release@submariner.io>
2024-10-09 22:01:53 +03:00
Automated ReleaseandSubmariner Bot c113f9498c Update Submariner dependencies to v0.19.0-rc1
Signed-off-by: Automated Release <release@submariner.io>
2024-10-02 21:09:00 +03:00
Automated ReleaseandSubmariner Bot 29110cd64a Update Submariner dependencies to v0.19.0-rc0
Signed-off-by: Automated Release <release@submariner.io>
2024-10-01 15:48:25 +03:00
Automated Release d91605062a Update base image to use stable branch 'release-0.19'
Signed-off-by: Automated Release <release@submariner.io>
2024-10-01 07:32:45 +00:00
Tom Pantelis 5cf3f48cd8 Add clusterset IP CIDR configuration to the operator chart
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-09-11 07:54:32 -04:00
Automated ReleaseandSubmariner Bot cfebd2c93a Update Submariner dependencies to v0.19.0-m3
Signed-off-by: Automated Release <release@submariner.io>
2024-09-05 11:02:53 +03:00
dependabot[bot]andThomas Pantelis 167e6a8799 Bump actions/setup-python in the github-actions group
Bumps the github-actions group with 1 update: [actions/setup-python](https://github.com/actions/setup-python).


Updates `actions/setup-python` from 5.1.1 to 5.2.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/39cd14951b08e74b54015e9e001cdefcf80e669f...f677139bbe7f9c59b41e40162b753c062f5d49a3)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-02 06:37:55 -04:00
Tom Pantelis c458483968 Remove dependabot config for release 0.14
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-08-20 05:52:46 -04:00
Automated ReleaseandSubmariner Bot cdd86cf19f Update Submariner dependencies to v0.19.0-m2
Signed-off-by: Automated Release <release@submariner.io>
2024-08-16 19:03:54 +03:00
dependabot[bot]andStephen Kitt 64ca0deb62 Bump actions/setup-python in the github-actions group
Bumps the github-actions group with 1 update: [actions/setup-python](https://github.com/actions/setup-python).


Updates `actions/setup-python` from 5.1.0 to 5.1.1
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/82c7e631bb3cdc910f68e0081d67478d79c6982d...39cd14951b08e74b54015e9e001cdefcf80e669f)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-22 17:31:53 +02:00
Automated ReleaseandSubmariner Bot 9376b31107 Update Submariner dependencies to v0.19.0-m1
Signed-off-by: Automated Release <release@submariner.io>
2024-07-22 18:00:24 +03:00
Stephen KittandSubmariner Bot f406805d57 Remove extra space in YAML file
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2024-07-22 18:00:24 +03:00
dependabot[bot]andThomas Pantelis 525d5cc7af Bump actions/checkout from 4.1.6 to 4.1.7 in the github-actions group
Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout).


Updates `actions/checkout` from 4.1.6 to 4.1.7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/a5ac7e51b41094c92402da3b24376905380afc29...692973e3d937129bcbf40652eb9f2f61becf3332)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-06-20 08:19:59 -04:00
Tom Pantelis 561bf2d2b8 Add dependabot config for release-0.18
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-06-20 08:10:57 -04:00
Automated ReleaseandSubmariner Bot fd88fcff1d Update Submariner dependencies to v0.19.0-m0
Signed-off-by: Automated Release <release@submariner.io>
2024-06-13 11:36:51 +03:00
Tom Pantelis 6c093ebca2 Adjust globalnet RBAC permissions
Globalnet now annotates Gateways instead of nodes.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-06-03 15:03:23 -04:00
dependabot[bot]andThomas Pantelis d3bce36afe Bump actions/checkout from 4.1.4 to 4.1.6 in the github-actions group
Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout).


Updates `actions/checkout` from 4.1.4 to 4.1.6
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/0ad4b8fadaa221de15dcec353f45205ec38ea70b...a5ac7e51b41094c92402da3b24376905380afc29)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-06-03 07:15:07 -04:00
Tom Pantelis 301db56c91 Remove node update RBAC permission for route agent
Re: https://github.com/submariner-io/submariner/pull/3010

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-21 17:56:46 -04:00
Thomas PantelisandGitHub eb336236f3 Add RBAC access to finalizers for the operator role (#515)
On Openshift, the operator failed with error

"\"submariner-gateway\" is forbidden: cannot set blockOwnerDeletion
if an ownerReference refers to a resource you can't set finalizers on"

Openshift enables OwnerReferencesPermissionEnforcement, so
in order to set blockOwnerDeletion for an object, the user needs
update permission for the finalizers subresource of the referenced
owner. In this case the owner is the Submariner object.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-21 12:28:13 +03:00
Tom PantelisandStephen Kitt 1b251e84cf Reduce lighthouse-agent RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt f037f15dc0 Reduce lighthouse-coredns RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt b4720fad02 Reduce submariner-globalnet RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt 6f632767b3 Reduce submariner-routeagent RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt ab6d482b9e Reduce submariner-gateway RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt 01a4312a89 Reduce submariner-operator RBAC permissions
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
Tom PantelisandStephen Kitt ae72e4bb5d Add Makefile.shipyard to .gitignore
Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-06 17:46:32 +02:00
dependabot[bot]andThomas Pantelis a6f99ab9cc Bump the github-actions group with 2 updates
Bumps the github-actions group with 2 updates: [actions/checkout](https://github.com/actions/checkout) and [azure/setup-helm](https://github.com/azure/setup-helm).


Updates `actions/checkout` from 4.1.2 to 4.1.4
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/9bb56186c3b09b4f86b1c65136769dd318469633...0ad4b8fadaa221de15dcec353f45205ec38ea70b)

Updates `azure/setup-helm` from 3.5 to 4
- [Release notes](https://github.com/azure/setup-helm/releases)
- [Changelog](https://github.com/Azure/setup-helm/blob/main/CHANGELOG.md)
- [Commits](https://github.com/azure/setup-helm/compare/5119fcb9089d432beecbf79bb2c7915207344b78...fe7b79cd5ee1e45176fcad797de68ecaf3ca4814)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: azure/setup-helm
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-05-01 07:59:15 -04:00
Automated ReleaseandSubmariner Bot d1805991eb Update Submariner dependencies to v0.18.0-m3
Signed-off-by: Automated Release <release@submariner.io>
2024-04-30 18:40:47 +03:00
dependabot[bot]andThomas Pantelis a3ed300574 Bump the github-actions group with 2 updates
Bumps the github-actions group with 2 updates: [actions/checkout](https://github.com/actions/checkout) and [actions/setup-python](https://github.com/actions/setup-python).


Updates `actions/checkout` from 4.1.1 to 4.1.2
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/b4ffde65f46336ab88eb53be808477a3936bae11...9bb56186c3b09b4f86b1c65136769dd318469633)

Updates `actions/setup-python` from 5.0.0 to 5.1.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/0a5c61591373683505ea898e09a3ea4f39ef2b9c...82c7e631bb3cdc910f68e0081d67478d79c6982d)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-04-02 11:32:46 -04:00
Automated ReleaseandSubmariner Bot c83ec2d623 Update Submariner dependencies to v0.18.0-m2
Signed-off-by: Automated Release <release@submariner.io>
2024-04-02 16:57:42 +03:00
15 changed files with 1251 additions and 1252 deletions
+9 -9
View File
@@ -9,15 +9,6 @@ updates:
github-actions: github-actions:
patterns: patterns:
- "*" - "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.14"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions - package-ecosystem: github-actions
directory: '/' directory: '/'
target-branch: "release-0.15" target-branch: "release-0.15"
@@ -45,3 +36,12 @@ updates:
github-actions: github-actions:
patterns: patterns:
- "*" - "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.18"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
+2 -2
View File
@@ -11,6 +11,6 @@ jobs:
name: PR targets branch name: PR targets branch
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check that the PR targets devel - name: Check that the PR targets release-0.19
if: ${{ github.base_ref != 'devel' }} if: ${{ github.base_ref != 'release-0.19' }}
run: exit 1 run: exit 1
+3 -3
View File
@@ -26,14 +26,14 @@ jobs:
- k8s_version: '1.26' - k8s_version: '1.26'
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
with: with:
k8s_version: ${{ matrix.k8s_version }} k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
+3 -3
View File
@@ -13,11 +13,11 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
+3 -3
View File
@@ -21,13 +21,13 @@ jobs:
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
with: with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
+8 -8
View File
@@ -38,15 +38,15 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Set up Helm - name: Set up Helm
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78 uses: azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814
with: with:
version: v3.6.0 version: v3.6.0
- name: Set up Python - name: Set up Python
uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c uses: actions/setup-python@f677139bbe7f9c59b41e40162b753c062f5d49a3
with: with:
python-version: '3.x' python-version: '3.x'
@@ -64,7 +64,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Run gitlint - name: Run gitlint
@@ -75,7 +75,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run helm-docs and verify docs are up-to-date - name: Run helm-docs and verify docs are up-to-date
run: make helm-docs run: make helm-docs
@@ -85,7 +85,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
@@ -99,7 +99,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run markdownlint - name: Run markdownlint
run: make markdownlint run: make markdownlint
@@ -108,6 +108,6 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run yamllint - name: Run yamllint
run: make yamllint run: make yamllint
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
issues: write issues: write
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec
+2 -2
View File
@@ -4,7 +4,7 @@ name: Release Charts
on: on:
push: push:
branches: branches:
- devel - release-0.19
permissions: permissions:
contents: write contents: write
@@ -16,7 +16,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332
with: with:
fetch-depth: 0 fetch-depth: 0
+1
View File
@@ -3,5 +3,6 @@
.shflags .shflags
*.tgz *.tgz
Makefile.dapper Makefile.dapper
Makefile.shipyard
Dockerfile.* Dockerfile.*
helm_repo helm_repo
+2 -2
View File
@@ -1,4 +1,4 @@
BASE_BRANCH ?= devel BASE_BRANCH ?= release-0.19
export BASE_BRANCH export BASE_BRANCH
export HELM_REPO_LOCATION=./helm_repo export HELM_REPO_LOCATION=./helm_repo
@@ -17,7 +17,7 @@ endif
export DEPLOYTOOL = helm export DEPLOYTOOL = helm
GH_URL=https://submariner-io.github.io/submariner-charts/charts GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts CHARTS_DIR=charts
CHARTS_VERSION=0.18.0-m1 CHARTS_VERSION=0.19.1
HELM_DOCS_VERSION=0.15.0 HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url) REPO_URL=$(shell git config remote.origin.url)
+2
View File
@@ -58,6 +58,8 @@ Submariner enables direct networking between Pods and Services in different Kube
| submariner.coreDNSCustomConfig | object | `{}` | | | submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | | | submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | | | submariner.globalCidr | string | `""` | |
| submariner.clustersetIpCidr | string | `""` | |
| submariner.clustersetIpEnabled | bool | `false` | |
| submariner.healthcheckEnabled | bool | `true` | | | submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | | | submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.14.0"` | | | submariner.images.tag | string | `"0.14.0"` | |
File diff suppressed because it is too large Load Diff
+177 -371
View File
@@ -9,62 +9,84 @@ metadata:
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods # For metrics
- services - services
- services/finalizers verbs:
- endpoints - get
- persistentvolumeclaims - create
- events - update
- configmaps - apiGroups:
- secrets - ""
verbs: resources:
- '*' # Temporarily needed for network-plugin syncer removal
- apiGroups: - serviceaccounts
- apps resourceNames:
resources: - submariner-networkplugin-syncer
- deployments verbs:
- daemonsets - delete
- replicasets - apiGroups:
- statefulsets - apps
verbs: resources:
- '*' - deployments
- apiGroups: - daemonsets
- monitoring.coreos.com verbs:
resources: - create
- servicemonitors - delete
verbs: - get
- get - list
- create - patch
- apiGroups: - update
- apps - watch
resourceNames: - apiGroups:
- {{ template "submariner.fullname" . }} - monitoring.coreos.com
resources: resources:
- deployments/finalizers # Needed for openshift monitoring
verbs: - servicemonitors
- update verbs:
- apiGroups: - get
- "" - create
resources: - apiGroups:
- pods - apps
verbs: resourceNames:
- get - {{ template "submariner.fullname" . }}
- apiGroups: resources:
- apps - deployments/finalizers
resources: verbs:
- replicasets - update
verbs: - apiGroups:
- get - submariner.io
- apiGroups: resources:
- submariner.io - brokers
resources: - brokers/status
- '*' - submariners
- servicediscoveries - submariners/status
verbs: - servicediscoveries
- '*' - servicediscoveries/status
verbs:
- get
- list
- watch
- create
- update
- delete
- apiGroups:
- submariner.io
resources:
- gateways
verbs:
- get
- list
- watch
- apiGroups:
- submariner.io
resources:
- submariners/finalizers
- servicediscoveries/finalizers
verbs:
- update
--- ---
kind: RoleBinding kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -93,86 +115,38 @@ metadata:
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods - pods
- services verbs:
- services/finalizers - get
- endpoints - update
- persistentvolumeclaims - patch
- events - apiGroups:
- configmaps - submariner.io
- secrets resources:
verbs: - clusters
- '*' - endpoints
- apiGroups: - gateways
- apps verbs:
resources: - get
- deployments - list
- daemonsets - watch
- replicasets - create
- statefulsets - update
verbs: - delete
- '*' - apiGroups:
- apiGroups: - coordination.k8s.io
- monitoring.coreos.com resources:
resources: - leases
- servicemonitors verbs:
verbs: - get
- get - list
- create - watch
- apiGroups: - create
- apps - update
resourceNames: - delete
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -203,74 +177,25 @@ metadata:
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- "" - submariner.io
resources: resources:
- pods
- services
- services/finalizers
- endpoints - endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs: verbs:
- get - get
- list
- watch
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- '*' - gatewayroutes
- servicediscoveries - nongatewayroutes
verbs: verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get - get
- list - list
- patch
- update
- watch - watch
- create
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -301,75 +226,15 @@ metadata:
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups:
- ""
resources:
- pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- '*' - gateways
- servicediscoveries
verbs: verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get - get
- list - list
- patch
- update
- watch - watch
- update
- apiGroups: - apiGroups:
- coordination.k8s.io - coordination.k8s.io
resources: resources:
@@ -435,9 +300,10 @@ rules:
- update - update
- delete - delete
- watch - watch
- apiGroups: # pods, services and nodes are looked up to figure out network settings - apiGroups:
- "" - ""
resources: resources:
# Needed for network settings discovery
- pods - pods
- services - services
- nodes - nodes
@@ -451,27 +317,20 @@ rules:
- dnses - dnses
verbs: verbs:
- get - get
- list
- watch
- update - update
- apiGroups: - apiGroups:
- config.openshift.io - config.openshift.io
resources: resources:
# Needed for network settings discovery
- networks - networks
resourceNames:
- cluster
verbs: verbs:
- get - get
- list
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
- watch
- apiGroups: - apiGroups:
- monitoring.coreos.com - monitoring.coreos.com
resources: resources:
# Needed for openshift monitoring
- servicemonitors - servicemonitors
verbs: verbs:
- get - get
@@ -479,11 +338,21 @@ rules:
- apiGroups: - apiGroups:
- apps - apps
resources: resources:
# Needed for Flannel CNI discovery
- daemonsets - daemonsets
verbs: verbs:
- get
- list - list
- watch - apiGroups:
- rbac.authorization.k8s.io
resources:
# Temporarily needed for network-plugin syncer removal
- clusterroles
- clusterrolebindings
resourceNames:
- ocp-submariner-networkplugin-syncer
- submariner-networkplugin-syncer
verbs:
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -542,21 +411,7 @@ rules:
- configmaps - configmaps
verbs: verbs:
- get - get
- list
- watch
- create
- update
- apiGroups: - apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- "" - ""
resources: resources:
- pods - pods
@@ -566,32 +421,6 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- submariner.io
resources:
- endpoints
- gateways
- clusters
verbs:
- get
- list
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -623,57 +452,41 @@ metadata:
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
resources:
- configmaps
verbs:
- get
- list
- watch
- update
- apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- ""
resources: resources:
- pods - pods
- services - services
- secrets
- configmaps
- endpoints
verbs: verbs:
- get - get
- list - list
- watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups: - apiGroups:
- config.openshift.io - config.openshift.io
resources: resources:
- networks - networks
resourceNames:
- cluster
verbs: verbs:
- get - get
- list
- apiGroups: - apiGroups:
- "" - ""
resources:
- nodes
verbs: verbs:
- get - get
- list - list
- watch - watch
- update - apiGroups:
- projectcalico.org
resources: resources:
- nodes - ippools
verbs:
- get
- create
- delete
- update
- deletecollection
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -708,13 +521,10 @@ rules:
- "" - ""
resources: resources:
- pods - pods
- namespaces
- nodes
verbs: verbs:
- get - get
- list - list
- watch - watch
- update
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
@@ -730,8 +540,8 @@ rules:
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- endpoints
- clusters - clusters
- endpoints
verbs: verbs:
- get - get
- list - list
@@ -756,7 +566,7 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- "serviceexports" - serviceexports
verbs: verbs:
- get - get
- list - list
@@ -811,7 +621,6 @@ rules:
- get - get
- list - list
- watch - watch
- update
- apiGroups: - apiGroups:
- discovery.k8s.io - discovery.k8s.io
resources: resources:
@@ -828,8 +637,8 @@ rules:
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- "gateways" - gateways
- "globalingressips" - globalingressips
verbs: verbs:
- get - get
- list - list
@@ -837,7 +646,8 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- "*" - serviceimports
- serviceimports/status
verbs: verbs:
- create - create
- get - get
@@ -845,6 +655,20 @@ rules:
- watch - watch
- update - update
- delete - delete
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports
verbs:
- get
- list
- watch
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports/status
verbs:
- update
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -869,34 +693,19 @@ kind: ClusterRole
metadata: metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-coredns name: {{ template "submariner.fullname" . }}:lighthouse-coredns
rules: rules:
- apiGroups:
- ""
resources:
- services
- namespaces
- endpoints
verbs:
- get
- list
- watch
- update
- apiGroups: - apiGroups:
- discovery.k8s.io - discovery.k8s.io
resources: resources:
- endpointslices - endpointslices
verbs: verbs:
- create
- get - get
- list - list
- watch - watch
- update
- delete
- deletecollection
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- "gateways" - gateways
- "submariners" - submariners
verbs: verbs:
- get - get
- list - list
@@ -904,14 +713,11 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- "*" - serviceimports
verbs: verbs:
- create
- get - get
- list - list
- watch - watch
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -52,6 +52,8 @@ spec:
{{- end }} {{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}" serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}" globalCIDR: "{{ .Values.submariner.globalCidr }}"
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }} serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }} cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck: connectionHealthCheck:
+2
View File
@@ -5,6 +5,8 @@ submariner:
clusterCidr: "" clusterCidr: ""
serviceCidr: "" serviceCidr: ""
globalCidr: "" globalCidr: ""
clustersetIpCidr: ""
clustersetIpEnabled: false
loadBalancerEnabled: false loadBalancerEnabled: false
natEnabled: false natEnabled: false
colorCodes: blue colorCodes: blue