Compare commits

..
23 Commits
Author SHA1 Message Date
Mike Kolesnik 929a180445 Bump to 0.11.2
Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2022-03-13 14:46:50 +02:00
Mike KolesnikandDaniel Farrell 8f30de30c0 Revert "Update K8s in E2E, EOL 1.19 and add 1.23"
0.11 never intended to support K8s 1.23

This reverts commit 3dd6eeb961.

Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2022-03-11 12:22:49 -05:00
Stephen KittandThomas Pantelis 5ab8347f4f Bump to 0.11.1
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2022-01-26 08:45:13 -05:00
Daniel FarrellandThomas Pantelis 3dd6eeb961 Update K8s in E2E, EOL 1.19 and add 1.23
Update the versions of Kubernetes tested in the E2E CI. Add 1.23 as the
new default for most tests, remove 1.19 as it is now EOL.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
(cherry picked from commit b6590df91b)
2022-01-26 08:44:26 -05:00
Sridhar GaddamandThomas Pantelis 85bc80cbe4 Configure RBAC for Globalnet pods on OCP deployments
Globalnet controller now uses internal services with external-ips
to support exported services. On OCP Clusters, we require an explicit
RBAC to create services with external-ips, this PR includes the
necessary RBAC for Globalnet pods.

Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>

(cherry picked from commit bf2c41115b)
2022-01-26 08:44:26 -05:00
NegashandThomas Pantelis cdc0e0e0c5 Fix coreDNSCustomConfig values
Signed-off-by: Negash <i@negash.ru>
(cherry picked from commit 9ba0123e72)
2022-01-26 08:44:26 -05:00
Sridhar GaddamandThomas Pantelis 6250b283fa Globalnet include ClusterRole for services
As part of Globalnet enhancement where kubeproxy dependency
is removed, the Globalnet Pod will now create internal
services for every exported service in the respective
namespace where the original service resides. This PR
adds the necessary clusterRole to allow Globalnet pod
to create/delete such internal services.

Related to: https://github.com/submariner-io/submariner/issues/1166
Signed-off-by: Sridhar Gaddam <sgaddam@redhat.com>
(cherry picked from commit b3a5e40a5a)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis ed33b07bd9 Add roles and privileges required for monitoring
This replicates the RBAC changes applied to the operator in
https://github.com/submariner-io/submariner-operator/pull/1416

Fixes: #191
Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 9358c86eb5)
2022-01-26 08:44:26 -05:00
Masaki KimuraandThomas Pantelis f1410811d7 Allow submariner-globalnet role to handle endpoints
Signed-off-by: Masaki Kimura <masaki.kimura@hitachivantara.com>
(cherry picked from commit 5da180d44f)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 648dbeacb3 Add dfarrell07 as *.md code owner
See <https://github.com/submariner-io/submariner/issues/1622>.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 7068abafc8)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 2a4213f768 Update all CRDs to v1 CRDs
... and drop the obsolete Lighthouse CRDs.

Fixes: #186
Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 2cfbd5c394)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 0f97bc9c11 Pass the broker.insecure flag to the CR
Fixes: #185
Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 42a2af008a)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 36945da91c Remove mangelajo from CODEOWNERS
... with his approval.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit 1fbd3da4ae)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis dfc0280658 Update K8s versions: drop 1.17/1.18, add 1.21/1.22
1.17 and 1.18 have reached EOL.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
(cherry picked from commit fc77796287)
2022-01-26 08:44:26 -05:00
Stephen KittandThomas Pantelis 12c3cbe928 Bump to 0.11.0
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-10-28 08:26:13 -04:00
Vishal ThaparandStephen Kitt 06ce316138 Fix connectionHealthCheck
connectionHealthCheck in submariner CR is a nested field
but is being added as a variable. This means it is ignored
and the field isn't set correctly in gateway pods.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-10-28 11:05:40 +02:00
Aswin SurayanarayananandThomas Pantelis 27eb25c8f6 Add RBAC permission endpointslices/restricted in broker roles
Fixes : github.com/submariner-io/lighthouse/issues#627

Signed-off-by: Aswin Surayanarayanan <asuryana@redhat.com>
2021-10-26 08:53:15 -04:00
5cc6ec47de Update submariner-operator/questions.yml
Co-authored-by: Sridhar Gaddam <sgaddam@redhat.com>
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 9fcea9930c Update Readme.md
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis c1ce210c89 Add ceIPSecForceUDPEncaps & coreDNSCustomConfig variables
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 7d8bf6a3ac Add enable/disable connectionHealthCheck
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 4cf74cfc3b Bump up to 0.10.1
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Automated Release 14e85ad476 Update base image to use stable branch 'release-0.11'
Signed-off-by: Automated Release <release@submariner.io>
2021-10-20 07:36:16 +00:00
40 changed files with 1681 additions and 1559 deletions
-47
View File
@@ -1,47 +0,0 @@
---
version: 2
updates:
- package-ecosystem: github-actions
directory: '/'
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.15"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.16"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.17"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.18"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
+57
View File
@@ -0,0 +1,57 @@
---
# Configuration for probot-stale - https://github.com/probot/stale
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
daysUntilStale: 120
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
daysUntilClose: 7
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
onlyLabels: []
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
exemptLabels:
- security
- confirmed
# Set to true to ignore issues in a project (defaults to false)
exemptProjects: false
# Set to true to ignore issues in a milestone (defaults to false)
exemptMilestones: false
# Set to true to ignore issues with an assignee (defaults to false)
exemptAssignees: false
# Label to use when marking as stale
staleLabel: wontfix
# Comment to post when marking as stale. Set to `false` to disable
markComment: >
This issue has been automatically marked as stale because it has not had
activity for 60 days. It will be closed if no further activity occurs.
Please make a comment if this issue/pr is still valid. Thank you
for your contributions.
# Comment to post when removing the stale label.
# unmarkComment: >
# Your comment here.
# Comment to post when closing a stale Issue or Pull Request.
# closeComment: >
# Your comment here.
# Limit the number of actions per hour, from 1-30. Default is 30
limitPerRun: 30
# Limit to only `issues` or `pulls`
# only: issues
pulls:
daysUntilStale: 30
markComment: >
This pull request has been automatically marked as stale because it has not had
recent activity. It will be closed if no further activity occurs. Thank you
for your contributions.
+4 -6
View File
@@ -4,13 +4,11 @@ name: Branch Checks
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
target_branch: target_devel:
name: PR targets branch name: PR targets release-0.11
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check that the PR targets release-0.19 - name: Check that the PR targets release-0.11
if: ${{ github.base_ref != 'release-0.19' }} if: ${{ github.base_ref != 'release-0.11' }}
run: exit 1 run: exit 1
+1 -6
View File
@@ -19,18 +19,13 @@ on:
schedule: schedule:
- cron: '0 0/6 * * *' # every 6 hours - cron: '0 0/6 * * *' # every 6 hours
permissions:
issues: write
pull-requests: write
statuses: write
jobs: jobs:
check: check:
name: Check Dependencies name: Check Dependencies
if: github.repository_owner == 'submariner-io' if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43 - uses: z0al/dependent-issues@70a1b2d4ee1cdc743af33498bd0204123953a887
env: env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with: with:
+7 -9
View File
@@ -5,8 +5,6 @@ on:
pull_request: pull_request:
types: [labeled, opened, synchronize, reopened] types: [labeled, opened, synchronize, reopened]
permissions: {}
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
@@ -18,22 +16,22 @@ jobs:
matrix: matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan'] cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet'] globalnet: ['', 'globalnet']
# Run most tests against the latest K8s version k8s_version: ['1.19']
k8s_version: ['1.29']
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
include: include:
# Bottom of supported K8s version range - k8s_version: '1.20'
- k8s_version: '1.26' - k8s_version: '1.21'
- k8s_version: '1.22'
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19 uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
with: with:
k8s_version: ${{ matrix.k8s_version }} k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+3 -5
View File
@@ -4,8 +4,6 @@ name: End to End Default
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
@@ -13,11 +11,11 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19 uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+3 -5
View File
@@ -5,8 +5,6 @@ on:
schedule: schedule:
- cron: "0 0 * * *" - cron: "0 0 * * *"
permissions: {}
jobs: jobs:
e2e: e2e:
name: E2E name: E2E
@@ -21,13 +19,13 @@ jobs:
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19 uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
with: with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+17 -26
View File
@@ -4,8 +4,6 @@ name: Linting
on: on:
pull_request: pull_request:
permissions: {}
jobs: jobs:
apply-suggestions-commits: apply-suggestions-commits:
name: 'No "Apply suggestions from code review" Commits' name: 'No "Apply suggestions from code review" Commits'
@@ -13,48 +11,37 @@ jobs:
steps: steps:
- name: Get PR commits - name: Get PR commits
id: 'get-pr-commits' id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d uses: tim-actions/get-pr-commits@55b867b9b28954e6f5c1a0fe2f729dc926c306d0
with: with:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
- name: 'Verify no "Apply suggestions from code review" commits' - name: 'Verify no "Apply suggestions from code review" commits'
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791 uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
with: with:
commits: ${{ steps.get-pr-commits.outputs.commits }} commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!.*(apply suggestions from code review))' pattern: '^(?!.*(apply suggestions from code review))'
flags: 'i' flags: 'i'
error: 'Commits addressing code review feedback should typically be squashed into the commits under review' error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
- name: 'Verify no "fixup!" commits'
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!fixup!)'
flags: 'i'
error: 'Fixup commits should be squashed into the commits under review'
chart-testing: chart-testing:
name: Helm Chart Linting name: Helm Chart Linting
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Set up Helm - name: Set up Helm
uses: azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 uses: azure/setup-helm@18bc76811624f360dbd7f18c2d4ecb32c7b87bab
with: with:
version: v3.6.0 version: v3.6.0
- name: Set up Python - name: Set up Python
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 uses: actions/setup-python@dc73133d4da04e56a135ae2246682783cc7c7cb6
with: with:
python-version: '3.x' python-version: '3.x'
- name: Set up helm/chart-testing - name: Set up helm/chart-testing
uses: helm/chart-testing-action@0d28d3144d3a25ea2cc349d6e59901c4ff469b3b uses: helm/chart-testing-action@5f16c27cf7a4fa9c776ff73734df3909b2b65127
- name: Set up local helm repo
run: make local-helm-repo
- name: Run helm/chart-testing (lint) - name: Run helm/chart-testing (lint)
run: ct lint --config ct.yaml run: ct lint --config ct.yaml
@@ -64,7 +51,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Run gitlint - name: Run gitlint
@@ -75,7 +62,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run helm-docs and verify docs are up-to-date - name: Run helm-docs and verify docs are up-to-date
run: make helm-docs run: make helm-docs
@@ -85,10 +72,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes" check-modified-files-only: "yes"
@@ -99,7 +86,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdownlint - name: Run markdownlint
run: make markdownlint run: make markdownlint
@@ -108,6 +95,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run yamllint - name: Run yamllint
run: make yamllint uses: ibiqlik/action-yamllint@ed2b6e911569708ed121c14b87d513860a7e36a7
with:
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
config_file: .yamllint.yml
strict: true
+3 -7
View File
@@ -5,27 +5,23 @@ on:
schedule: schedule:
- cron: "0 0 * * 0" - cron: "0 0 * * 0"
permissions: {}
jobs: jobs:
markdown-link-check-periodic: markdown-link-check-periodic:
name: Markdown Links (all files) name: Markdown Links (all files)
if: github.repository_owner == 'submariner-io' if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
issues: write
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links - name: Raise an Issue to report broken links
if: ${{ failure() }} if: ${{ failure() }}
uses: peter-evans/create-issue-from-file@e8ef132d6df98ed982188e460ebb3b5d4ef3a9cd uses: peter-evans/create-issue-from-file@97e6f902a416aac38834e23fa52e166aad0437d2
with: with:
title: Broken link detected by CI title: Broken link detected by CI
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
+2 -5
View File
@@ -4,10 +4,7 @@ name: Release Charts
on: on:
push: push:
branches: branches:
- release-0.19 - release-0.11
permissions:
contents: write
jobs: jobs:
release: release:
@@ -16,7 +13,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
with: with:
fetch-depth: 0 fetch-depth: 0
-32
View File
@@ -1,32 +0,0 @@
---
name: Stale
on:
schedule:
- cron: "0 0 * * *"
permissions: {}
jobs:
stale:
name: Close Stale Issues and PRs
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
steps:
- uses: actions/stale@ee7ef89499a3de6e4fe1fc1acb994e67c64e0a2a
with:
days-before-issue-stale: 120
days-before-pr-stale: 14
exempt-issue-labels: 'confirmed,security'
exempt-pr-labels: 'confirmed,security'
stale-issue-label: 'stale'
stale-issue-message: |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
activity occurs. Thank you for your contributions.
stale-pr-label: 'stale'
stale-pr-message: |
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
activity occurs. Thank you for your contributions.
-3
View File
@@ -3,6 +3,3 @@
.shflags .shflags
*.tgz *.tgz
Makefile.dapper Makefile.dapper
Makefile.shipyard
Dockerfile.*
helm_repo
-3
View File
@@ -1,8 +1,5 @@
{ {
"ignorePatterns": [ "ignorePatterns": [
{
"pattern": "^https://docs.github.com"
},
{ {
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+" "pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
}, },
-7
View File
@@ -1,7 +0,0 @@
---
cni: ovn
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-6
View File
@@ -1,6 +0,0 @@
---
submariner: true
nodes: control-plane
clusters:
cluster1:
cluster2:
-1
View File
@@ -1,4 +1,3 @@
---
label-approved: label-approved:
approvals: 2 approvals: 2
label: ready-to-test label: ready-to-test
+11 -11
View File
@@ -1,15 +1,15 @@
--- ---
extends: default extends: default
rules: rules:
comments: disable
comments-indentation: disable
line-length: line-length:
max: 140 max: 150
# Allow standard GHA syntax for "on: *" braces:
truthy: min-spaces-inside: 0
ignore: '.github/workflows/*.yml' max-spaces-inside: 0
brackets:
ignore: | min-spaces-inside: 0
/submariner-k8s-broker/crds max-spaces-inside: 0
/submariner-operator/crds indentation:
/submariner-k8s-broker/templates indent-sequences: consistent
/submariner-operator/templates
+2 -3
View File
@@ -1,4 +1,3 @@
# Auto-generated, do not edit; see CODEOWNERS.in # Auto-generated, do not edit; see CODEOWNERS.in
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar * @Oats87 @skitt @sridhargaddam @tpantelis
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar *.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
+1 -5
View File
@@ -1,9 +1,5 @@
@aswinsuryan Makefile @dfarrell07 *.md
@dfarrell07 *.md Makefile
@maayanf24 Makefile
@Oats87 * @Oats87 *
@skitt * @skitt *
@sridhargaddam * @sridhargaddam *
@tpantelis * @tpantelis *
@vthapar *
@yboaron Makefile
+16
View File
@@ -0,0 +1,16 @@
ARG BASE_BRANCH
FROM quay.io/submariner/shipyard-dapper-base:${BASE_BRANCH}
ARG DAPPER_HOST_ARCH
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
WORKDIR ${DAPPER_SOURCE}
# Override the Helm deployment scripts
COPY deploy_helm /opt/shipyard/scripts/lib/
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
CMD ["sh"]
+23 -18
View File
@@ -1,42 +1,47 @@
BASE_BRANCH ?= release-0.19 BASE_BRANCH ?= release-0.11
export BASE_BRANCH export BASE_BRANCH
export HELM_REPO_LOCATION=./helm_repo
ifneq (,$(DAPPER_HOST_ARCH)) ifneq (,$(DAPPER_HOST_ARCH))
# Running in Dapper # Running in Dapper
PRELOAD_IMAGES := submariner-gateway submariner-operator submariner-route-agent lighthouse-agent lighthouse-coredns
include $(SHIPYARD_DIR)/Makefile.inc include $(SHIPYARD_DIR)/Makefile.inc
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
ifneq (,$(filter ovn,$(_using))) ifneq (,$(filter ovn,$(_using)))
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings.ovn
else else
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
endif endif
export DEPLOYTOOL = helm override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
export DEPLOY_ARGS
GH_URL=https://submariner-io.github.io/submariner-charts/charts GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts CHARTS_DIR=charts
CHARTS_VERSION=0.19.3 CHARTS_VERSION=0.11.2
HELM_DOCS_VERSION=0.15.0 HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url) REPO_URL=$(shell git config remote.origin.url)
# Process extra flags from the `using=a,b,c` optional flag
ifneq (,$(filter lighthouse,$(_using)))
override DEPLOY_ARGS += --service_discovery
endif
ifneq (,$(filter globalnet,$(_using)))
override DEPLOY_ARGS += --globalnet
endif
# Targets to make # Targets to make
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz e2e: E2E_ARGS=cluster1 cluster2
local-helm-repo: $(CHART_PACKAGES)
mkdir -p $(HELM_REPO_LOCATION)
for archive in $^; do \
tar xzf $$archive -C $(HELM_REPO_LOCATION); \
done
e2e: local-helm-repo
$(SCRIPTS_DIR)/e2e.sh
%.tgz: %.tgz:
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm-docs: helm-docs:
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive # Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
@@ -52,7 +57,7 @@ helm-docs:
exit 1; \ exit 1; \
fi fi
release: $(CHART_PACKAGES) release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
git checkout gh-pages git checkout gh-pages
mv *.tgz $(CHARTS_DIR) mv *.tgz $(CHARTS_DIR)
if [ -f $(CHARTS_DIR)/index.yaml ]; then \ if [ -f $(CHARTS_DIR)/index.yaml ]; then \
+1 -1
View File
@@ -60,4 +60,4 @@ working correctly.
[Helm]: https://helm.sh/docs/using_helm/#installing-helm [Helm]: https://helm.sh/docs/using_helm/#installing-helm
[Docker]: https://docs.docker.com/install/ [Docker]: https://docs.docker.com/install/
[Podman]: https://podman.io/getting-started/installation [Podman]: https://podman.io/getting-started/installation
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo [Create a fork]: https://help.github.com/en/articles/fork-a-repo
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker"
cluster_nodes['cluster2']="control-plane worker"
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
+10
View File
@@ -0,0 +1,10 @@
. "${SCRIPTS_DIR}"/lib/source_only
# We need a minimal setup to verify the deployment works
clusters=('cluster1' 'cluster2')
cluster_nodes['cluster1']="control-plane worker worker"
cluster_nodes['cluster2']="control-plane worker worker"
cluster_cni=( ['cluster1']="ovn" ['cluster2']="ovn" )
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
+2 -3
View File
@@ -1,7 +1,6 @@
---
charts: charts:
- ./helm_repo/submariner-operator - submariner-operator
- ./helm_repo/submariner-k8s-broker - submariner-k8s-broker
# Tests that maintainer name is valid GitHub account, which isn't what we want # Tests that maintainer name is valid GitHub account, which isn't what we want
# See: https://github.com/helm/chart-testing/issues/192 # See: https://github.com/helm/chart-testing/issues/192
validate-maintainers: false validate-maintainers: false
+76
View File
@@ -0,0 +1,76 @@
# shellcheck shell=bash
# shellcheck source=scripts/shared/lib/source_only
. "${BASH_SOURCE%/*}"/source_only
### Constants ###
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
### Functions ###
function deploytool_prereqs() {
helm version
}
function setup_broker() {
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
echo "Submariner CRDs already exist, skipping broker creation..."
else
echo "Installing submariner broker..."
# shellcheck disable=SC2086 # Split on purpose
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
--create-namespace \
--kube-context "${cluster}" \
--namespace "${SUBMARINER_BROKER_NS}" \
${deploytool_broker_args}
fi
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
}
function helm_install_subm() {
local crd_create=false
[[ "${cluster}" = "${broker}" ]] || crd_create=true
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
echo "Submariner already installed, skipping installation..."
return
fi
echo "Installing Submariner..."
# shellcheck disable=SC2086 # Split on purpose
helm --kube-context "${cluster}" install submariner-operator \
./submariner-operator \
--create-namespace \
--namespace "${SUBM_NS}" \
--set ipsec.psk="${SUBMARINER_PSK}" \
--set broker.server="${submariner_broker_url}" \
--set broker.token="${submariner_broker_token}" \
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
--set broker.ca="${submariner_broker_ca}" \
--set broker.globalnet="${globalnet}" \
--set submariner.serviceDiscovery="${service_discovery}" \
--set submariner.cableDriver="${cable_driver}" \
--set submariner.clusterId="${cluster}" \
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
--set serviceAccounts.globalnet.create="${globalnet}" \
--set serviceAccounts.lighthouseAgent.create="${service_discovery}" \
--set serviceAccounts.lighthouseCoreDns.create="${service_discovery}" \
--set submariner.natEnabled="false" \
--set operator.image.repository="localhost:5000/submariner-operator" \
--set operator.image.tag="local" \
--set operator.image.pullPolicy="IfNotPresent" \
--set submariner.images.repository="localhost:5000" \
--set submariner.images.tag="local" \
--set brokercrds.create="${crd_create}" \
${deploytool_submariner_args}
}
function install_subm_all_clusters() {
run_subm_clusters helm_install_subm
}
+2 -1
View File
@@ -1,7 +1,8 @@
--- ---
name: submariner-k8s-broker name: submariner-k8s-broker
version: 0.0.0 version: 0.6.0
apiVersion: v2 apiVersion: v2
appVersion: 0.6.0
description: Submariner Kubernetes Broker description: Submariner Kubernetes Broker
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+2
View File
@@ -1,5 +1,7 @@
# submariner-k8s-broker # submariner-k8s-broker
![Version: 0.6.0](https://img.shields.io/badge/Version-0.6.0-informational?style=flat-square) ![AppVersion: 0.6.0](https://img.shields.io/badge/AppVersion-0.6.0-informational?style=flat-square)
Submariner Kubernetes Broker Submariner Kubernetes Broker
**Homepage:** <https://submariner-io.github.io/> **Homepage:** <https://submariner-io.github.io/>
+19
View File
@@ -0,0 +1,19 @@
questions:
- variable: submariner-k8s-broker.rbac.create
type: boolean
default: true
group: "Role Based Access Control"
description: "Create the role/rolebinding for the Submariner client"
label: "RBAC Creation Enabled"
- variable: submariner-k8s-broker.crd.create
type: boolean
default: true
group: "Submariner CRD"
description: "Create the submariner CRDs for the Submariner client"
label: "Submariner CRD Creation Enabled"
- variable: submariner-k8s-broker.serviceAccounts.client.create
type: boolean
default: true
group: "Service Account"
description: "Create the service account for the Submariner client"
label: "Submariner Service Account Creation Enabled"
+2 -2
View File
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
The broker client token and CA can be retrieved by running The broker client token and CA can be retrieved by running
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}") $ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode) $ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
@@ -8,12 +8,4 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner-k8s-broker.chart" . }} chart: {{ template "submariner-k8s-broker.chart" . }}
app: {{ template "submariner-k8s-broker.name" . }} app: {{ template "submariner-k8s-broker.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
+2 -1
View File
@@ -1,7 +1,8 @@
--- ---
name: submariner-operator name: submariner-operator
version: 0.0.0 version: 0.11.2
apiVersion: v2 apiVersion: v2
appVersion: 0.11.2
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+6 -4
View File
@@ -1,5 +1,7 @@
# submariner-operator # submariner-operator
![Version: 0.11.2](https://img.shields.io/badge/Version-0.11.2-informational?style=flat-square) ![AppVersion: 0.11.2](https://img.shields.io/badge/AppVersion-0.11.2-informational?style=flat-square)
Submariner enables direct networking between Pods and Services in different Kubernetes clusters Submariner enables direct networking between Pods and Services in different Kubernetes clusters
**Homepage:** <https://submariner-io.github.io/> **Homepage:** <https://submariner-io.github.io/>
@@ -24,6 +26,8 @@ Submariner enables direct networking between Pods and Services in different Kube
| broker.namespace | string | `"xyz"` | | | broker.namespace | string | `"xyz"` | |
| broker.server | string | `"example.k8s.apiserver"` | | | broker.server | string | `"example.k8s.apiserver"` | |
| broker.token | string | `"test"` | | | broker.token | string | `"test"` | |
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
| gateway.image.tag | string | `"0.11.2"` | |
| ipsec.debug | bool | `false` | | | ipsec.debug | bool | `false` | |
| ipsec.forceUDPEncaps | bool | `false` | | | ipsec.forceUDPEncaps | bool | `false` | |
| ipsec.ikePort | int | `500` | | | ipsec.ikePort | int | `500` | |
@@ -35,7 +39,7 @@ Submariner enables direct networking between Pods and Services in different Kube
| operator.affinity | object | `{}` | | | operator.affinity | object | `{}` | |
| operator.image.pullPolicy | string | `"IfNotPresent"` | | | operator.image.pullPolicy | string | `"IfNotPresent"` | |
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | | | operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
| operator.image.tag | string | `"0.14.0"` | | | operator.image.tag | string | `"0.11.2"` | |
| operator.resources | object | `{}` | | | operator.resources | object | `{}` | |
| operator.tolerations | list | `[]` | | | operator.tolerations | list | `[]` | |
| rbac.create | bool | `true` | | | rbac.create | bool | `true` | |
@@ -58,11 +62,9 @@ Submariner enables direct networking between Pods and Services in different Kube
| submariner.coreDNSCustomConfig | object | `{}` | | | submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | | | submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | | | submariner.globalCidr | string | `""` | |
| submariner.clustersetIpCidr | string | `""` | |
| submariner.clustersetIpEnabled | bool | `false` | |
| submariner.healthcheckEnabled | bool | `true` | | | submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | | | submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.14.0"` | | | submariner.images.tag | string | `"0.11.2"` | |
| submariner.natEnabled | bool | `false` | | | submariner.natEnabled | bool | `false` | |
| submariner.serviceCidr | string | `""` | | | submariner.serviceCidr | string | `""` | |
| submariner.serviceDiscovery | bool | `true` | | | submariner.serviceDiscovery | bool | `true` | |
+39 -225
View File
@@ -3,7 +3,8 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
annotations: annotations:
controller-gen.kubebuilder.io/version: v0.12.1 controller-gen.kubebuilder.io/version: v0.4.1
creationTimestamp: null
name: submariners.submariner.io name: submariners.submariner.io
spec: spec:
group: submariner.io group: submariner.io
@@ -17,7 +18,7 @@ spec:
- name: v1alpha1 - name: v1alpha1
schema: schema:
openAPIV3Schema: openAPIV3Schema:
description: Submariner is the Schema for the submariners API. description: Submariner is the Schema for the submariners API
properties: properties:
apiVersion: apiVersion:
description: 'APIVersion defines the versioned schema of this representation description: 'APIVersion defines the versioned schema of this representation
@@ -32,72 +33,43 @@ spec:
metadata: metadata:
type: object type: object
spec: spec:
description: SubmarinerSpec defines the desired state of Submariner. description: SubmarinerSpec defines the desired state of Submariner
properties: properties:
airGappedDeployment:
type: boolean
broker: broker:
description: Type of broker (must be "k8s").
type: string type: string
brokerK8sApiServer: brokerK8sApiServer:
description: The broker API URL.
type: string type: string
brokerK8sApiServerToken: brokerK8sApiServerToken:
description: The broker API Token.
type: string type: string
brokerK8sCA: brokerK8sCA:
description: The broker certificate authority.
type: string type: string
brokerK8sInsecure: brokerK8sInsecure:
type: boolean type: boolean
brokerK8sRemoteNamespace: brokerK8sRemoteNamespace:
description: The Broker namespace.
type: string
brokerK8sSecret:
type: string type: string
cableDriver: cableDriver:
description: Cable driver implementation - any of [libreswan, wireguard,
vxlan].
type: string type: string
ceIPSecDebug: ceIPSecDebug:
description: Enable logging IPsec debugging information.
type: boolean type: boolean
ceIPSecForceUDPEncaps: ceIPSecForceUDPEncaps:
description: Force UDP encapsulation for IPsec.
type: boolean type: boolean
ceIPSecIKEPort: ceIPSecIKEPort:
description: The IPsec IKE port (500 usually).
type: integer type: integer
ceIPSecNATTPort: ceIPSecNATTPort:
description: The IPsec NAT traversal port (4500 usually).
type: integer type: integer
ceIPSecPSK: ceIPSecPSK:
description: The IPsec Pre-Shared Key which must be identical in all
route agents across the cluster.
type: string
ceIPSecPSKSecret:
type: string type: string
ceIPSecPreferredServer: ceIPSecPreferredServer:
description: Enable this cluster as a preferred server for data-plane
connections.
type: boolean type: boolean
clusterCIDR: clusterCIDR:
description: The cluster CIDR.
type: string type: string
clusterID: clusterID:
description: The cluster ID used to identify the tunnels.
type: string
clustersetIPCIDR:
description: ClustersetIP CIDR for allocating ClustersetIPs to exported
services.
type: string type: string
colorCodes: colorCodes:
type: string type: string
connectionHealthCheck: connectionHealthCheck:
description: The gateway connection health check.
properties: properties:
enabled: enabled:
description: Enable the connection health check.
type: boolean type: boolean
intervalSeconds: intervalSeconds:
description: The interval at which health check pings are sent. description: The interval at which health check pings are sent.
@@ -110,111 +82,47 @@ spec:
type: integer type: integer
type: object type: object
coreDNSCustomConfig: coreDNSCustomConfig:
description: Name of the custom CoreDNS configmap to configure forwarding
to Lighthouse. It should be in <namespace>/<name> format where <namespace>
is optional and defaults to kube-system.
properties: properties:
configMapName: configMapName:
description: Name of the custom CoreDNS configmap.
type: string type: string
namespace: namespace:
description: Namespace of the custom CoreDNS configmap.
type: string type: string
type: object type: object
customDomains: customDomains:
description: List of domains to use for multi-cluster service discovery.
items: items:
type: string type: string
type: array type: array
x-kubernetes-list-type: set x-kubernetes-list-type: set
debug: debug:
description: Enable operator debugging.
type: boolean type: boolean
globalCIDR: globalCIDR:
description: The Global CIDR super-net range for allocating GlobalCIDRs
to each cluster.
type: string type: string
haltOnCertificateError:
description: Halt on certificate error (so the pod gets restarted).
type: boolean
imageOverrides: imageOverrides:
additionalProperties: additionalProperties:
type: string type: string
description: Override component images.
type: object type: object
loadBalancerEnabled: loadBalancerEnabled:
description: Enable automatic Load Balancer in front of the gateways.
type: boolean type: boolean
namespace: namespace:
description: The namespace in which to deploy the submariner operator.
type: string type: string
natEnabled: natEnabled:
description: Enable NAT between clusters.
type: boolean type: boolean
nodeSelector:
additionalProperties:
type: string
type: object
repository: repository:
description: The image repository.
type: string type: string
serviceCIDR: serviceCIDR:
description: The service CIDR.
type: string type: string
serviceDiscoveryEnabled: serviceDiscoveryEnabled:
description: Enable support for Service Discovery (Lighthouse).
type: boolean type: boolean
clustersetIPEnabled:
description: Enable ClustersetIP default for services exported on this
cluster.
type: boolean
tolerations:
items:
description: The pod this Toleration is attached to tolerates any
taint that matches the triple <key,value,effect> using the matching
operator <operator>.
properties:
effect:
description: Effect indicates the taint effect to match. Empty
means match all taint effects. When specified, allowed values
are NoSchedule, PreferNoSchedule and NoExecute.
type: string
key:
description: Key is the taint key that the toleration applies
to. Empty means match all taint keys. If the key is empty,
operator must be Exists; this combination means to match all
values and all keys.
type: string
operator:
description: Operator represents a key's relationship to the
value. Valid operators are Exists and Equal. Defaults to Equal.
Exists is equivalent to wildcard for value, so that a pod
can tolerate all taints of a particular category.
type: string
tolerationSeconds:
description: TolerationSeconds represents the period of time
the toleration (which must be of effect NoExecute, otherwise
this field is ignored) tolerates the taint. By default, it
is not set, which means tolerate the taint forever (do not
evict). Zero and negative values will be treated as 0 (evict
immediately) by the system.
format: int64
type: integer
value:
description: Value is the taint value the toleration matches
to. If the operator is Exists, the value should be empty,
otherwise just a regular string.
type: string
type: object
type: array
version: version:
description: The image tag.
type: string type: string
required: required:
- broker - broker
- brokerK8sApiServer - brokerK8sApiServer
- brokerK8sApiServerToken
- brokerK8sCA
- brokerK8sRemoteNamespace - brokerK8sRemoteNamespace
- ceIPSecDebug - ceIPSecDebug
- ceIPSecPSK
- clusterCIDR - clusterCIDR
- clusterID - clusterID
- debug - debug
@@ -223,23 +131,15 @@ spec:
- serviceCIDR - serviceCIDR
type: object type: object
status: status:
description: SubmarinerStatus defines the observed state of Submariner. description: SubmarinerStatus defines the observed state of Submariner
properties: properties:
airGappedDeployment:
type: boolean
clusterCIDR: clusterCIDR:
description: The current cluster CIDR.
type: string type: string
clusterID: clusterID:
description: The current cluster ID.
type: string
clustersetIPCIDR:
description: The current clustersetIP CIDR.
type: string type: string
colorCodes: colorCodes:
type: string type: string
deploymentInfo: deploymentInfo:
description: Information about the deployment.
properties: properties:
cloudProvider: cloudProvider:
type: string type: string
@@ -251,7 +151,6 @@ spec:
type: string type: string
type: object type: object
gatewayDaemonSetStatus: gatewayDaemonSetStatus:
description: The status of the gateway DaemonSet.
properties: properties:
lastResourceVersion: lastResourceVersion:
type: string type: string
@@ -275,7 +174,7 @@ spec:
description: Details about a terminated container description: Details about a terminated container
properties: properties:
containerID: containerID:
description: Container's ID in the format '<type>://<container_id>' description: Container's ID in the format 'docker://<container_id>'
type: string type: string
exitCode: exitCode:
description: Exit status from the last termination of description: Exit status from the last termination of
@@ -388,9 +287,9 @@ spec:
format: int32 format: int32
type: integer type: integer
numberReady: numberReady:
description: numberReady is the number of nodes that should description: The number of nodes that should be running the
be running the daemon pod and have one or more of the daemon daemon pod and have one or more of the daemon pod running
pod running with a Ready Condition. and ready.
format: int32 format: int32
type: integer type: integer
numberUnavailable: numberUnavailable:
@@ -419,7 +318,6 @@ spec:
- mismatchedContainerImages - mismatchedContainerImages
type: object type: object
gateways: gateways:
description: Status of the gateways in the cluster.
items: items:
properties: properties:
connections: connections:
@@ -546,10 +444,8 @@ spec:
type: object type: object
type: array type: array
globalCIDR: globalCIDR:
description: The current global CIDR.
type: string type: string
globalnetDaemonSetStatus: globalnetDaemonSetStatus:
description: The status of the Globalnet DaemonSet.
properties: properties:
lastResourceVersion: lastResourceVersion:
type: string type: string
@@ -573,7 +469,7 @@ spec:
description: Details about a terminated container description: Details about a terminated container
properties: properties:
containerID: containerID:
description: Container's ID in the format '<type>://<container_id>' description: Container's ID in the format 'docker://<container_id>'
type: string type: string
exitCode: exitCode:
description: Exit status from the last termination of description: Exit status from the last termination of
@@ -686,9 +582,9 @@ spec:
format: int32 format: int32
type: integer type: integer
numberReady: numberReady:
description: numberReady is the number of nodes that should description: The number of nodes that should be running the
be running the daemon pod and have one or more of the daemon daemon pod and have one or more of the daemon pod running
pod running with a Ready Condition. and ready.
format: int32 format: int32
type: integer type: integer
numberUnavailable: numberUnavailable:
@@ -717,7 +613,6 @@ spec:
- mismatchedContainerImages - mismatchedContainerImages
type: object type: object
loadBalancerStatus: loadBalancerStatus:
description: The status of the load balancer DaemonSet.
properties: properties:
status: status:
description: LoadBalancerStatus represents the status of a load-balancer. description: LoadBalancerStatus represents the status of a load-balancer.
@@ -739,53 +634,15 @@ spec:
description: IP is set for load-balancer ingress points description: IP is set for load-balancer ingress points
that are IP based (typically GCE or OpenStack load-balancers) that are IP based (typically GCE or OpenStack load-balancers)
type: string type: string
ports:
description: Ports is a list of records of service ports
If used, every port defined in the service should
have an entry in it
items:
properties:
error:
description: 'Error is to record the problem with
the service port The format of the error shall
comply with the following rules: - built-in
error values shall be specified in this file
and those shall use CamelCase names - cloud
provider specific error values must have names
that comply with the format foo.example.com/CamelCase.
--- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)'
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
port:
description: Port is the port number of the service
port of which status is recorded here
format: int32
type: integer
protocol:
default: TCP
description: 'Protocol is the protocol of the
service port of which status is recorded here
The supported values are: "TCP", "UDP", "SCTP"'
type: string
required:
- port
- protocol
type: object
type: array
x-kubernetes-list-type: atomic
type: object type: object
type: array type: array
type: object type: object
type: object type: object
natEnabled: natEnabled:
description: The current NAT status.
type: boolean type: boolean
networkPlugin: networkPlugin:
description: The current network plugin.
type: string type: string
routeAgentDaemonSetStatus: routeAgentDaemonSetStatus:
description: The status of the route agent DaemonSet.
properties: properties:
lastResourceVersion: lastResourceVersion:
type: string type: string
@@ -809,7 +666,7 @@ spec:
description: Details about a terminated container description: Details about a terminated container
properties: properties:
containerID: containerID:
description: Container's ID in the format '<type>://<container_id>' description: Container's ID in the format 'docker://<container_id>'
type: string type: string
exitCode: exitCode:
description: Exit status from the last termination of description: Exit status from the last termination of
@@ -922,9 +779,9 @@ spec:
format: int32 format: int32
type: integer type: integer
numberReady: numberReady:
description: numberReady is the number of nodes that should description: The number of nodes that should be running the
be running the daemon pod and have one or more of the daemon daemon pod and have one or more of the daemon pod running
pod running with a Ready Condition. and ready.
format: int32 format: int32
type: integer type: integer
numberUnavailable: numberUnavailable:
@@ -953,11 +810,6 @@ spec:
- mismatchedContainerImages - mismatchedContainerImages
type: object type: object
serviceCIDR: serviceCIDR:
description: The current service CIDR.
type: string
version:
description: The image version in use by the various Submariner DaemonSets
and Deployments.
type: string type: string
required: required:
- clusterID - clusterID
@@ -968,12 +820,19 @@ spec:
storage: true storage: true
subresources: subresources:
status: {} status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
metadata: metadata:
annotations: annotations:
controller-gen.kubebuilder.io/version: v0.12.1 controller-gen.kubebuilder.io/version: v0.4.1
creationTimestamp: null
name: servicediscoveries.submariner.io name: servicediscoveries.submariner.io
spec: spec:
group: submariner.io group: submariner.io
@@ -987,7 +846,7 @@ spec:
- name: v1alpha1 - name: v1alpha1
schema: schema:
openAPIV3Schema: openAPIV3Schema:
description: ServiceDiscovery is the Schema for the servicediscoveries API. description: ServiceDiscovery is the Schema for the servicediscoveries API
properties: properties:
apiVersion: apiVersion:
description: 'APIVersion defines the versioned schema of this representation description: 'APIVersion defines the versioned schema of this representation
@@ -1002,7 +861,7 @@ spec:
metadata: metadata:
type: object type: object
spec: spec:
description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery. description: ServiceDiscoverySpec defines the desired state of ServiceDiscovery
properties: properties:
brokerK8sApiServer: brokerK8sApiServer:
type: string type: string
@@ -1014,19 +873,13 @@ spec:
type: boolean type: boolean
brokerK8sRemoteNamespace: brokerK8sRemoteNamespace:
type: string type: string
brokerK8sSecret:
type: string
clusterID: clusterID:
type: string type: string
clustersetIPCIDR:
type: string
coreDNSCustomConfig: coreDNSCustomConfig:
properties: properties:
configMapName: configMapName:
description: Name of the custom CoreDNS configmap.
type: string type: string
namespace: namespace:
description: Namespace of the custom CoreDNS configmap.
type: string type: string
type: object type: object
customDomains: customDomains:
@@ -1038,72 +891,27 @@ spec:
type: boolean type: boolean
globalnetEnabled: globalnetEnabled:
type: boolean type: boolean
haltOnCertificateError:
type: boolean
clustersetIPEnabled:
type: boolean
imageOverrides: imageOverrides:
additionalProperties: additionalProperties:
type: string type: string
type: object type: object
namespace: namespace:
type: string type: string
nodeSelector:
additionalProperties:
type: string
type: object
repository: repository:
type: string type: string
tolerations:
items:
description: The pod this Toleration is attached to tolerates any
taint that matches the triple <key,value,effect> using the matching
operator <operator>.
properties:
effect:
description: Effect indicates the taint effect to match. Empty
means match all taint effects. When specified, allowed values
are NoSchedule, PreferNoSchedule and NoExecute.
type: string
key:
description: Key is the taint key that the toleration applies
to. Empty means match all taint keys. If the key is empty,
operator must be Exists; this combination means to match all
values and all keys.
type: string
operator:
description: Operator represents a key's relationship to the
value. Valid operators are Exists and Equal. Defaults to Equal.
Exists is equivalent to wildcard for value, so that a pod
can tolerate all taints of a particular category.
type: string
tolerationSeconds:
description: TolerationSeconds represents the period of time
the toleration (which must be of effect NoExecute, otherwise
this field is ignored) tolerates the taint. By default, it
is not set, which means tolerate the taint forever (do not
evict). Zero and negative values will be treated as 0 (evict
immediately) by the system.
format: int64
type: integer
value:
description: Value is the taint value the toleration matches
to. If the operator is Exists, the value should be empty,
otherwise just a regular string.
type: string
type: object
type: array
version: version:
type: string type: string
required: required:
- brokerK8sApiServer - brokerK8sApiServer
- brokerK8sApiServerToken
- brokerK8sCA
- brokerK8sRemoteNamespace - brokerK8sRemoteNamespace
- clusterID - clusterID
- debug - debug
- namespace - namespace
type: object type: object
status: status:
description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery. description: ServiceDiscoveryStatus defines the observed state of ServiceDiscovery
properties: properties:
deploymentInfo: deploymentInfo:
properties: properties:
@@ -1122,6 +930,12 @@ spec:
storage: true storage: true
subresources: subresources:
status: {} status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
--- ---
apiVersion: apiextensions.k8s.io/v1 apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition kind: CustomResourceDefinition
+144
View File
@@ -0,0 +1,144 @@
questions:
- variable: defaultOperatorImage
default: true
description: "Use default Submariner operator image or specify a custom one"
label: Use default Submariner operator image
type: boolean
show_subquestion_if: false
group: "Container Images"
subquestions:
- variable: operator.image.repository
default: "quay.io/submariner/submariner-operator"
description: "Submariner Operator Image Repository"
type: string
label: Submariner Operator Image Repository
- variable: operator.image.tag
default: "0.11.2"
description: "Submariner Operator Image Tag"
type: string
label: Submariner Operator Image Tag
- variable: defaultSubmarinerImages
default: true
description: "Use default Submariner images or specify custom ones"
label: Use default Submariner images
type: boolean
show_subquestion_if: false
group: "Container images"
subquestions:
- variable: submariner.images.repository
default: "quay.io/submariner"
description: "Submariner Repository (base for all non-operator images)"
type: string
label: Submariner Repository
- variable: submariner.images.tag
default: "0.11.2"
description: "Submariner Images Tag (shared for all non-operator images)"
type: string
label: Submariner Images Tag
- variable: submariner.clusterId
default: ""
description: "Enter a unique cluster ID to identify this cluster"
type: string
label: "Cluster ID"
group: "Configuration"
required: true
- variable: ipsec.psk
default: ""
description: "Enter the pre-shared key for the IPsec Cable Engine"
type: string
label: "IPsec Pre-Shared Key"
group: "Configuration"
required: true
- variable: broker.server
type: string
default: ""
group: "Broker Configuration"
label: "Broker Server"
description: "Broker server to use (without the https://)"
- variable: broker.insecure
type: boolean
default: false
show_subquestion_if: false
group: "Broker Configuration"
label: "Insecure Broker"
description: "Connect to K8s broker without validating CA"
subquestions:
- variable: broker.ca
type: string
description: "Base64 encoded broker ca.crt"
label: "Broker CA encoded in base64"
default: ""
- variable: broker.token
type: string
group: "Broker Configuration"
label: "Broker Token"
description: "Bearer token for broker"
- variable: broker.namespace
type: string
group: "Broker Configuration"
label: "Broker Namespace"
description: "Enter namespace to use on central broker"
- variable: submariner.clusterCidr
default: ""
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
type: string
label: "Cluster CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.serviceCidr
default: ""
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
type: string
label: "Service CIDR"
group: "CIDR Configuration"
required: true
- variable: submariner.serviceDiscovery
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable multicluster service discovery"
label: "Service Discovery Enabled"
- variable: broker.globalnet
type: boolean
default: false
group: "Broker Configuration"
description: "Enable support for overlapping Cluster/Service CIDRs in connecting clusters"
label: "Globalnet Enabled"
subquestions:
- variable: submariner.globalCidr
default: ""
description: "Enter the globalnet CIDR (i.e. 169.254.1.0/24) for this cluster if using globalnet"
type: string
label: "Globalnet CIDR"
group: "CIDR Configuration"
required: false
- variable: submariner.natEnabled
type: boolean
default: false
group: "Advanced Configuration"
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
label: "NAT Enabled"
- variable: submariner.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable submariner debug mode"
label: "Submariner Debug Enabled"
- variable: ipsec.debug
type: boolean
default: false
group: "Advanced Configuration"
description: "Enable Charon debug mode"
label: "Charon Enabled"
- variable: submariner.cableDriver
type: string
default: ""
group: "Advanced Configuration"
description: "Cable driver implementation"
label: "Cable Driver"
- variable: submariner.healthcheckEnabled
type: boolean
default: true
group: "Advanced Configuration"
description: "Disable Healthcheck"
label: "Healthcheck Disabled"
+4
View File
@@ -1,3 +1,7 @@
Submariner is now installed. Submariner is now installed.
{{- if .Values.gateway.nodeSelectorEnabled }}
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
{{- end }}
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool. By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
+327 -147
View File
@@ -12,38 +12,28 @@ rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
# For metrics - pods
- services - services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs: verbs:
- get - '*'
- create
- update
- apiGroups:
- ""
resources:
# Temporarily needed for network-plugin syncer removal
- serviceaccounts
resourceNames:
- submariner-networkplugin-syncer
verbs:
- delete
- apiGroups: - apiGroups:
- apps - apps
resources: resources:
- deployments - deployments
- daemonsets - daemonsets
- replicasets
- statefulsets
verbs: verbs:
- create - '*'
- delete
- get
- list
- patch
- update
- watch
- apiGroups: - apiGroups:
- monitoring.coreos.com - monitoring.coreos.com
resources: resources:
# Needed for openshift monitoring
- servicemonitors - servicemonitors
verbs: verbs:
- get - get
@@ -56,37 +46,25 @@ rules:
- deployments/finalizers - deployments/finalizers
verbs: verbs:
- update - update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- brokers - '*'
- brokers/status
- submariners
- submariners/status
- servicediscoveries - servicediscoveries
- servicediscoveries/status
verbs: verbs:
- get - '*'
- list
- watch
- create
- update
- delete
- apiGroups:
- submariner.io
resources:
- gateways
verbs:
- get
- list
- watch
- apiGroups:
- submariner.io
resources:
- submariners/finalizers
- servicediscoveries/finalizers
verbs:
- update
--- ---
kind: RoleBinding kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -119,34 +97,71 @@ rules:
- "" - ""
resources: resources:
- pods - pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs: verbs:
- get - get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update - update
- patch - apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- clusters - '*'
- endpoints - servicediscoveries
- gateways
verbs: verbs:
- get - '*'
- list
- watch
- create
- update
- delete
- apiGroups: - apiGroups:
- coordination.k8s.io - lighthouse.submariner.io
resources: resources:
- leases - '*'
- serviceexports
verbs: verbs:
- create
- delete
- get - get
- list - list
- watch - patch
- create
- update - update
- delete - watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -177,25 +192,74 @@ metadata:
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- submariner.io - ""
resources: resources:
- pods
- services
- services/finalizers
- endpoints - endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs: verbs:
- get - get
- list
- watch
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gatewayroutes - '*'
- nongatewayroutes - servicediscoveries
verbs: verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get - get
- list - list
- watch - patch
- create
- update - update
- delete - watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -227,25 +291,74 @@ metadata:
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- submariner.io - ""
resources: resources:
- gateways - pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs: verbs:
- get - get
- list - create
- watch - apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update - update
- apiGroups: - apiGroups:
- coordination.k8s.io - ""
resources: resources:
- leases - pods
verbs: verbs:
- get - get
- list - apiGroups:
- watch - apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create - create
- update
- delete - delete
- get
- list
- patch
- update
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -300,10 +413,9 @@ rules:
- update - update
- delete - delete
- watch - watch
- apiGroups: - apiGroups: # pods, services and nodes are looked up to figure out network settings
- "" - ""
resources: resources:
# Needed for network settings discovery
- pods - pods
- services - services
- nodes - nodes
@@ -317,42 +429,31 @@ rules:
- dnses - dnses
verbs: verbs:
- get - get
- list
- watch
- update - update
- apiGroups: - apiGroups:
- config.openshift.io - config.openshift.io
resources: resources:
# Needed for network settings discovery
- networks - networks
resourceNames:
- cluster
verbs: verbs:
- get - get
- list
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
- watch
- apiGroups: - apiGroups:
- monitoring.coreos.com - monitoring.coreos.com
resources: resources:
# Needed for openshift monitoring
- servicemonitors - servicemonitors
verbs: verbs:
- get - get
- create - create
- apiGroups:
- apps
resources:
# Needed for Flannel CNI discovery
- daemonsets
verbs:
- list
- apiGroups:
- rbac.authorization.k8s.io
resources:
# Temporarily needed for network-plugin syncer removal
- clusterroles
- clusterrolebindings
resourceNames:
- ocp-submariner-networkplugin-syncer
- submariner-networkplugin-syncer
verbs:
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -411,7 +512,21 @@ rules:
- configmaps - configmaps
verbs: verbs:
- get - get
- list
- watch
- create
- update
- apiGroups: - apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- "" - ""
resources: resources:
- pods - pods
@@ -421,6 +536,32 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- submariner.io
resources:
- endpoints
- gateways
- clusters
verbs:
- get
- list
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -453,40 +594,56 @@ rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods
- services
- secrets
- configmaps - configmaps
- endpoints
verbs: verbs:
- get - get
- list - list
- watch
- update
- apiGroups: - apiGroups:
- config.openshift.io - apiextensions.k8s.io
resources: resources:
- networks - customresourcedefinitions
resourceNames:
- cluster
verbs: verbs:
- get - get
- apiGroups: - list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- "" - ""
resources: resources:
- nodes - pods
- services
verbs: verbs:
- get - get
- list - list
- watch - watch
- apiGroups: - apiGroups:
- projectcalico.org - operator.openshift.io
resources: resources:
- ippools - dnses
verbs: verbs:
- get - get
- create - list
- delete - watch
- update - update
- deletecollection - apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- ""
verbs:
- get
- list
- watch
- update
resources:
- nodes
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -521,15 +678,18 @@ rules:
- "" - ""
resources: resources:
- pods - pods
- namespaces
- nodes
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- update
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- services - services
- endpoints
verbs: verbs:
- create - create
- get - get
@@ -540,8 +700,8 @@ rules:
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- clusters
- endpoints - endpoints
- clusters
verbs: verbs:
- get - get
- list - list
@@ -550,11 +710,17 @@ rules:
- submariner.io - submariner.io
resources: resources:
- clusterglobalegressips - clusterglobalegressips
- clusterglobalegressips/status
- globalegressips - globalegressips
- globalegressips/status verbs:
- create
- get
- list
- watch
- update
- apiGroups:
- submariner.io
resources:
- globalingressips - globalingressips
- globalingressips/status
verbs: verbs:
- create - create
- get - get
@@ -566,7 +732,7 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceexports - "serviceexports"
verbs: verbs:
- get - get
- list - list
@@ -621,6 +787,7 @@ rules:
- get - get
- list - list
- watch - watch
- update
- apiGroups: - apiGroups:
- discovery.k8s.io - discovery.k8s.io
resources: resources:
@@ -637,8 +804,8 @@ rules:
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gateways - "gateways"
- globalingressips - "globalingressips"
verbs: verbs:
- get - get
- list - list
@@ -646,8 +813,7 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceimports - "*"
- serviceimports/status
verbs: verbs:
- create - create
- get - get
@@ -655,20 +821,6 @@ rules:
- watch - watch
- update - update
- delete - delete
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports
verbs:
- get
- list
- watch
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports/status
verbs:
- update
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -694,18 +846,43 @@ metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-coredns name: {{ template "submariner.fullname" . }}:lighthouse-coredns
rules: rules:
- apiGroups: - apiGroups:
- discovery.k8s.io - ""
resources: resources:
- endpointslices - services
- namespaces
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- update
- apiGroups:
- discovery.k8s.io
resources:
- endpointslices
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups:
- lighthouse.submariner.io
resources:
- "*"
verbs:
- create
- get
- list
- watch
- update
- delete
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gateways - "gateways"
- submariners
verbs: verbs:
- get - get
- list - list
@@ -713,11 +890,14 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceimports - "*"
verbs: verbs:
- create
- get - get
- list - list
- watch - watch
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
+2 -31
View File
@@ -19,41 +19,12 @@ spec:
clusterID: {{ .Values.submariner.clusterId }} clusterID: {{ .Values.submariner.clusterId }}
colorCodes: {{ .Values.submariner.colorCodes }} colorCodes: {{ .Values.submariner.colorCodes }}
debug: {{ .Values.submariner.debug }} debug: {{ .Values.submariner.debug }}
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
natEnabled: {{ .Values.submariner.natEnabled }} natEnabled: {{ .Values.submariner.natEnabled }}
repository: {{ .Values.submariner.images.repository }} repository: {{ .Values.submariner.images.repository }}
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }} version: {{ .Values.submariner.images.tag }}
{{- with .Values.images }}
{{- if . }}
imageOverrides:
{{- if index . "submariner-operator" }}
submariner-operator: {{ index . "submariner-operator" }}
{{- end }}
{{- if index . "submariner-gateway" }}
submariner-gateway: {{ index . "submariner-gateway" }}
{{- end }}
{{- if index . "submariner-route-agent" }}
submariner-routeagent: {{ index . "submariner-route-agent" }}
{{- end }}
{{- if index . "submariner-globalnet" }}
submariner-globalnet: {{ index . "submariner-globalnet" }}
{{- end }}
{{- if index . "submariner-networkplugin-syncer" }}
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
{{- end }}
{{- if index . "lighthouse-agent" }}
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
{{- end }}
{{- if index . "lighthouse-coredns" }}
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
{{- end }}
{{- end }}
{{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}" serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}" globalCIDR: "{{ .Values.submariner.globalCidr }}"
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }} serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }} cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck: connectionHealthCheck:
@@ -62,6 +33,6 @@ spec:
maxPacketLossCount: 5 maxPacketLossCount: 5
{{- with .Values.submariner.coreDNSCustomConfig }} {{- with .Values.submariner.coreDNSCustomConfig }}
coreDNSCustomConfig: coreDNSCustomConfig:
configMapName: {{ .configMapName }} configmapName: {{ .configmapName }}
namespace: {{ .namespace }} namespace: {{ .namespace }}
{{- end }} {{- end }}
@@ -8,14 +8,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.operatorServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.gateway.create }} {{- if .Values.serviceAccounts.gateway.create }}
@@ -28,14 +20,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.routeAgent.create }} {{- if .Values.serviceAccounts.routeAgent.create }}
@@ -48,14 +32,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.globalnet.create }} {{- if .Values.serviceAccounts.globalnet.create }}
@@ -68,14 +44,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.lighthouseAgent.create }} {{- if .Values.serviceAccounts.lighthouseAgent.create }}
@@ -88,14 +56,6 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
--- ---
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }} {{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
@@ -108,12 +68,4 @@ metadata:
release: {{ .Release.Name | quote }} release: {{ .Release.Name | quote }}
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
---
apiVersion: v1
kind: Secret
metadata:
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
annotations:
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
type: kubernetes.io/service-account-token
{{- end }} {{- end }}
+6 -6
View File
@@ -5,9 +5,6 @@ submariner:
clusterCidr: "" clusterCidr: ""
serviceCidr: "" serviceCidr: ""
globalCidr: "" globalCidr: ""
clustersetIpCidr: ""
clustersetIpEnabled: false
loadBalancerEnabled: false
natEnabled: false natEnabled: false
colorCodes: blue colorCodes: blue
debug: false debug: false
@@ -17,7 +14,7 @@ submariner:
coreDNSCustomConfig: {} coreDNSCustomConfig: {}
images: images:
repository: quay.io/submariner repository: quay.io/submariner
tag: "" tag: "0.11.2"
broker: broker:
server: example.k8s.apiserver server: example.k8s.apiserver
token: test token: test
@@ -27,7 +24,6 @@ broker:
globalnet: false globalnet: false
rbac: rbac:
create: true create: true
images: {}
ipsec: ipsec:
psk: "" psk: ""
debug: false debug: false
@@ -41,11 +37,15 @@ leadership:
operator: operator:
image: image:
repository: quay.io/submariner/submariner-operator repository: quay.io/submariner/submariner-operator
tag: "" tag: "0.11.2"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
resources: {} resources: {}
tolerations: [] tolerations: []
affinity: {} affinity: {}
gateway:
image:
repository: quay.io/submariner/submariner-gateway
tag: "0.11.2"
serviceAccounts: serviceAccounts:
operator: operator:
create: true create: true