Compare commits

..
1 Commits
Author SHA1 Message Date
Automated Release b19b7e6294 Update base image to use stable branch 'release-0.14'
Signed-off-by: Automated Release <release@submariner.io>
2022-10-26 10:24:20 +00:00
25 changed files with 1382 additions and 1393 deletions
+5 -35
View File
@@ -4,44 +4,14 @@ updates:
- package-ecosystem: github-actions - package-ecosystem: github-actions
directory: '/' directory: '/'
schedule: schedule:
interval: monthly interval: weekly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions - package-ecosystem: github-actions
directory: '/' directory: '/'
target-branch: "release-0.15" target-branch: "release-0.12"
schedule: schedule:
interval: monthly interval: weekly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions - package-ecosystem: github-actions
directory: '/' directory: '/'
target-branch: "release-0.16" target-branch: "release-0.13"
schedule: schedule:
interval: monthly interval: weekly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.17"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.18"
schedule:
interval: monthly
groups:
github-actions:
patterns:
- "*"
+57
View File
@@ -0,0 +1,57 @@
---
# Configuration for probot-stale - https://github.com/probot/stale
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
daysUntilStale: 120
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
daysUntilClose: 7
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
onlyLabels: []
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
exemptLabels:
- security
- confirmed
# Set to true to ignore issues in a project (defaults to false)
exemptProjects: false
# Set to true to ignore issues in a milestone (defaults to false)
exemptMilestones: false
# Set to true to ignore issues with an assignee (defaults to false)
exemptAssignees: false
# Label to use when marking as stale
staleLabel: wontfix
# Comment to post when marking as stale. Set to `false` to disable
markComment: >
This issue has been automatically marked as stale because it has not had
activity for 60 days. It will be closed if no further activity occurs.
Please make a comment if this issue/pr is still valid. Thank you
for your contributions.
# Comment to post when removing the stale label.
# unmarkComment: >
# Your comment here.
# Comment to post when closing a stale Issue or Pull Request.
# closeComment: >
# Your comment here.
# Limit the number of actions per hour, from 1-30. Default is 30
limitPerRun: 30
# Limit to only `issues` or `pulls`
# only: issues
pulls:
daysUntilStale: 30
markComment: >
This pull request has been automatically marked as stale because it has not had
recent activity. It will be closed if no further activity occurs. Thank you
for your contributions.
+2 -2
View File
@@ -11,6 +11,6 @@ jobs:
name: PR targets branch name: PR targets branch
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check that the PR targets release-0.19 - name: Check that the PR targets release-0.14
if: ${{ github.base_ref != 'release-0.19' }} if: ${{ github.base_ref != 'release-0.14' }}
run: exit 1 run: exit 1
+1 -1
View File
@@ -30,7 +30,7 @@ jobs:
if: github.repository_owner == 'submariner-io' if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43 - uses: z0al/dependent-issues@0fae07162bc9e0d8e116a133bd03686eed6efa21
env: env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with: with:
+7 -7
View File
@@ -18,22 +18,22 @@ jobs:
matrix: matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan'] cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet'] globalnet: ['', 'globalnet']
# Run most tests against the latest K8s version k8s_version: ['1.25']
k8s_version: ['1.29']
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
include: include:
# Bottom of supported K8s version range - k8s_version: '1.22'
- k8s_version: '1.26' - k8s_version: '1.23'
- k8s_version: '1.24'
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19 uses: submariner-io/shipyard/gh-actions/e2e@release-0.14
with: with:
k8s_version: ${{ matrix.k8s_version }} k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.14
+3 -3
View File
@@ -13,11 +13,11 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19 uses: submariner-io/shipyard/gh-actions/e2e@release-0.14
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.14
+3 -3
View File
@@ -21,13 +21,13 @@ jobs:
lighthouse: ['', 'lighthouse'] lighthouse: ['', 'lighthouse']
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run E2E deployment and tests - name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19 uses: submariner-io/shipyard/gh-actions/e2e@release-0.14
with: with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }} using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem - name: Post mortem
if: failure() if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19 uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.14
+13 -16
View File
@@ -13,12 +13,12 @@ jobs:
steps: steps:
- name: Get PR commits - name: Get PR commits
id: 'get-pr-commits' id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d uses: tim-actions/get-pr-commits@c64db31d359214d244884dd68f971a110b29ab83
with: with:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
- name: 'Verify no "Apply suggestions from code review" commits' - name: 'Verify no "Apply suggestions from code review" commits'
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791 uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
with: with:
commits: ${{ steps.get-pr-commits.outputs.commits }} commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!.*(apply suggestions from code review))' pattern: '^(?!.*(apply suggestions from code review))'
@@ -26,7 +26,7 @@ jobs:
error: 'Commits addressing code review feedback should typically be squashed into the commits under review' error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
- name: 'Verify no "fixup!" commits' - name: 'Verify no "fixup!" commits'
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791 uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
with: with:
commits: ${{ steps.get-pr-commits.outputs.commits }} commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!fixup!)' pattern: '^(?!fixup!)'
@@ -38,23 +38,20 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Set up Helm - name: Set up Helm
uses: azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 uses: azure/setup-helm@b5b231a831f96336bbfeccc1329990f0005c5bb1
with: with:
version: v3.6.0 version: v3.6.0
- name: Set up Python - name: Set up Python
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 uses: actions/setup-python@13ae5bb136fac2878aff31522b9efb785519f984
with: with:
python-version: '3.x' python-version: '3.x'
- name: Set up helm/chart-testing - name: Set up helm/chart-testing
uses: helm/chart-testing-action@0d28d3144d3a25ea2cc349d6e59901c4ff469b3b uses: helm/chart-testing-action@afea100a513515fbd68b0e72a7bb0ae34cb62aec
- name: Set up local helm repo
run: make local-helm-repo
- name: Run helm/chart-testing (lint) - name: Run helm/chart-testing (lint)
run: ct lint --config ct.yaml run: ct lint --config ct.yaml
@@ -64,7 +61,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Run gitlint - name: Run gitlint
@@ -75,7 +72,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run helm-docs and verify docs are up-to-date - name: Run helm-docs and verify docs are up-to-date
run: make helm-docs run: make helm-docs
@@ -85,10 +82,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes" check-modified-files-only: "yes"
@@ -99,7 +96,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run markdownlint - name: Run markdownlint
run: make markdownlint run: make markdownlint
@@ -108,6 +105,6 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run yamllint - name: Run yamllint
run: make yamllint run: make yamllint
+3 -3
View File
@@ -16,16 +16,16 @@ jobs:
issues: write issues: write
steps: steps:
- name: Check out the repository - name: Check out the repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
- name: Run markdown-link-check - name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc uses: gaurav-nelson/github-action-markdown-link-check@228fbf4ffb2a86a65314866e9b2322b519fd885f
with: with:
config-file: ".markdownlinkcheck.json" config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links - name: Raise an Issue to report broken links
if: ${{ failure() }} if: ${{ failure() }}
uses: peter-evans/create-issue-from-file@e8ef132d6df98ed982188e460ebb3b5d4ef3a9cd uses: peter-evans/create-issue-from-file@433e51abf769039ee20ba1293a088ca19d573b7f
with: with:
title: Broken link detected by CI title: Broken link detected by CI
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
+2 -2
View File
@@ -4,7 +4,7 @@ name: Release Charts
on: on:
push: push:
branches: branches:
- release-0.19 - release-0.14
permissions: permissions:
contents: write contents: write
@@ -16,7 +16,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8
with: with:
fetch-depth: 0 fetch-depth: 0
-32
View File
@@ -1,32 +0,0 @@
---
name: Stale
on:
schedule:
- cron: "0 0 * * *"
permissions: {}
jobs:
stale:
name: Close Stale Issues and PRs
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
steps:
- uses: actions/stale@ee7ef89499a3de6e4fe1fc1acb994e67c64e0a2a
with:
days-before-issue-stale: 120
days-before-pr-stale: 14
exempt-issue-labels: 'confirmed,security'
exempt-pr-labels: 'confirmed,security'
stale-issue-label: 'stale'
stale-issue-message: |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
activity occurs. Thank you for your contributions.
stale-pr-label: 'stale'
stale-pr-message: |
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
activity occurs. Thank you for your contributions.
-2
View File
@@ -3,6 +3,4 @@
.shflags .shflags
*.tgz *.tgz
Makefile.dapper Makefile.dapper
Makefile.shipyard
Dockerfile.* Dockerfile.*
helm_repo
+2 -3
View File
@@ -1,4 +1,3 @@
# Auto-generated, do not edit; see CODEOWNERS.in # Auto-generated, do not edit; see CODEOWNERS.in
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar * @Oats87 @skitt @sridhargaddam @tpantelis
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar *.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
+1 -5
View File
@@ -1,9 +1,5 @@
@aswinsuryan Makefile @dfarrell07 *.md
@dfarrell07 *.md Makefile
@maayanf24 Makefile
@Oats87 * @Oats87 *
@skitt * @skitt *
@sridhargaddam * @sridhargaddam *
@tpantelis * @tpantelis *
@vthapar *
@yboaron Makefile
+8 -15
View File
@@ -1,6 +1,6 @@
BASE_BRANCH ?= release-0.19 BASE_BRANCH ?= release-0.14
export BASE_BRANCH export BASE_BRANCH
export HELM_REPO_LOCATION=./helm_repo export HELM_REPO_LOCATION=.
ifneq (,$(DAPPER_HOST_ARCH)) ifneq (,$(DAPPER_HOST_ARCH))
@@ -17,26 +17,19 @@ endif
export DEPLOYTOOL = helm export DEPLOYTOOL = helm
GH_URL=https://submariner-io.github.io/submariner-charts/charts GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts CHARTS_DIR=charts
CHARTS_VERSION=0.19.3 CHARTS_VERSION=0.14.0-m1
HELM_DOCS_VERSION=0.15.0 HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url) REPO_URL=$(shell git config remote.origin.url)
SUBCTL_VERSION=$(CHARTS_VERSION)
export SUBCTL_VERSION
# Targets to make # Targets to make
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz e2e: E2E_ARGS=cluster1 cluster2
local-helm-repo: $(CHART_PACKAGES)
mkdir -p $(HELM_REPO_LOCATION)
for archive in $^; do \
tar xzf $$archive -C $(HELM_REPO_LOCATION); \
done
e2e: local-helm-repo
$(SCRIPTS_DIR)/e2e.sh
%.tgz: %.tgz:
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F))) helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm-docs: helm-docs:
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive # Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
@@ -52,7 +45,7 @@ helm-docs:
exit 1; \ exit 1; \
fi fi
release: $(CHART_PACKAGES) release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
git checkout gh-pages git checkout gh-pages
mv *.tgz $(CHARTS_DIR) mv *.tgz $(CHARTS_DIR)
if [ -f $(CHARTS_DIR)/index.yaml ]; then \ if [ -f $(CHARTS_DIR)/index.yaml ]; then \
+2 -2
View File
@@ -1,7 +1,7 @@
--- ---
charts: charts:
- ./helm_repo/submariner-operator - submariner-operator
- ./helm_repo/submariner-k8s-broker - submariner-k8s-broker
# Tests that maintainer name is valid GitHub account, which isn't what we want # Tests that maintainer name is valid GitHub account, which isn't what we want
# See: https://github.com/helm/chart-testing/issues/192 # See: https://github.com/helm/chart-testing/issues/192
validate-maintainers: false validate-maintainers: false
+2 -1
View File
@@ -1,7 +1,8 @@
--- ---
name: submariner-k8s-broker name: submariner-k8s-broker
version: 0.0.0 version: 0.14.0-m1
apiVersion: v2 apiVersion: v2
appVersion: 0.14.0-m1
description: Submariner Kubernetes Broker description: Submariner Kubernetes Broker
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+2 -2
View File
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
The broker client token and CA can be retrieved by running The broker client token and CA can be retrieved by running
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}") $ SUBMARINER_BROKER_CA=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode) $ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets "${SUBMARINER_BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
+2 -1
View File
@@ -1,7 +1,8 @@
--- ---
name: submariner-operator name: submariner-operator
version: 0.0.0 version: 0.14.0-m1
apiVersion: v2 apiVersion: v2
appVersion: 0.14.0-m1
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+2 -2
View File
@@ -24,6 +24,8 @@ Submariner enables direct networking between Pods and Services in different Kube
| broker.namespace | string | `"xyz"` | | | broker.namespace | string | `"xyz"` | |
| broker.server | string | `"example.k8s.apiserver"` | | | broker.server | string | `"example.k8s.apiserver"` | |
| broker.token | string | `"test"` | | | broker.token | string | `"test"` | |
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
| gateway.image.tag | string | `"0.14.0"` | |
| ipsec.debug | bool | `false` | | | ipsec.debug | bool | `false` | |
| ipsec.forceUDPEncaps | bool | `false` | | | ipsec.forceUDPEncaps | bool | `false` | |
| ipsec.ikePort | int | `500` | | | ipsec.ikePort | int | `500` | |
@@ -58,8 +60,6 @@ Submariner enables direct networking between Pods and Services in different Kube
| submariner.coreDNSCustomConfig | object | `{}` | | | submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | | | submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | | | submariner.globalCidr | string | `""` | |
| submariner.clustersetIpCidr | string | `""` | |
| submariner.clustersetIpEnabled | bool | `false` | |
| submariner.healthcheckEnabled | bool | `true` | | | submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | | | submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.14.0"` | | | submariner.images.tag | string | `"0.14.0"` | |
File diff suppressed because it is too large Load Diff
+5 -1
View File
@@ -1,3 +1,7 @@
Submariner is now installed. Submariner is now installed.
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool. {{- if .Values.gateway.nodeSelectorEnabled }}
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
{{- end }}
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
+386 -195
View File
@@ -9,84 +9,62 @@ metadata:
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
# For metrics - pods
- services - services
verbs: - services/finalizers
- get - endpoints
- create - persistentvolumeclaims
- update - events
- apiGroups: - configmaps
- "" - secrets
resources: verbs:
# Temporarily needed for network-plugin syncer removal - '*'
- serviceaccounts - apiGroups:
resourceNames: - apps
- submariner-networkplugin-syncer resources:
verbs: - deployments
- delete - daemonsets
- apiGroups: - replicasets
- apps - statefulsets
resources: verbs:
- deployments - '*'
- daemonsets - apiGroups:
verbs: - monitoring.coreos.com
- create resources:
- delete - servicemonitors
- get verbs:
- list - get
- patch - create
- update - apiGroups:
- watch - apps
- apiGroups: resourceNames:
- monitoring.coreos.com - {{ template "submariner.fullname" . }}
resources: resources:
# Needed for openshift monitoring - deployments/finalizers
- servicemonitors verbs:
verbs: - update
- get - apiGroups:
- create - ""
- apiGroups: resources:
- apps - pods
resourceNames: verbs:
- {{ template "submariner.fullname" . }} - get
resources: - apiGroups:
- deployments/finalizers - apps
verbs: resources:
- update - replicasets
- apiGroups: verbs:
- submariner.io - get
resources: - apiGroups:
- brokers - submariner.io
- brokers/status resources:
- submariners - '*'
- submariners/status - servicediscoveries
- servicediscoveries verbs:
- servicediscoveries/status - '*'
verbs:
- get
- list
- watch
- create
- update
- delete
- apiGroups:
- submariner.io
resources:
- gateways
verbs:
- get
- list
- watch
- apiGroups:
- submariner.io
resources:
- submariners/finalizers
- servicediscoveries/finalizers
verbs:
- update
--- ---
kind: RoleBinding kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
@@ -115,38 +93,86 @@ metadata:
chart: {{ template "submariner.chart" . }} chart: {{ template "submariner.chart" . }}
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods - pods
verbs: - services
- get - services/finalizers
- update - endpoints
- patch - persistentvolumeclaims
- apiGroups: - events
- submariner.io - configmaps
resources: - secrets
- clusters verbs:
- endpoints - '*'
- gateways - apiGroups:
verbs: - apps
- get resources:
- list - deployments
- watch - daemonsets
- create - replicasets
- update - statefulsets
- delete verbs:
- apiGroups: - '*'
- coordination.k8s.io - apiGroups:
resources: - monitoring.coreos.com
- leases resources:
verbs: - servicemonitors
- get verbs:
- list - get
- watch - create
- create - apiGroups:
- update - apps
- delete resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -177,25 +203,74 @@ metadata:
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- submariner.io - ""
resources: resources:
- pods
- services
- services/finalizers
- endpoints - endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs:
- get
- create
- apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- apiGroups:
- apps
resources:
- replicasets
verbs: verbs:
- get - get
- list
- watch
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gatewayroutes - '*'
- nongatewayroutes - servicediscoveries
verbs: verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create
- delete
- get - get
- list - list
- watch - patch
- create
- update - update
- delete - watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -227,25 +302,74 @@ metadata:
app: {{ template "submariner.name" . }} app: {{ template "submariner.name" . }}
rules: rules:
- apiGroups: - apiGroups:
- submariner.io - ""
resources: resources:
- gateways - pods
- services
- services/finalizers
- endpoints
- persistentvolumeclaims
- events
- configmaps
- secrets
verbs:
- '*'
- apiGroups:
- apps
resources:
- deployments
- daemonsets
- replicasets
- statefulsets
verbs:
- '*'
- apiGroups:
- monitoring.coreos.com
resources:
- servicemonitors
verbs: verbs:
- get - get
- list - create
- watch - apiGroups:
- apps
resourceNames:
- submariner-operator
resources:
- deployments/finalizers
verbs:
- update - update
- apiGroups: - apiGroups:
- coordination.k8s.io - ""
resources: resources:
- leases - pods
verbs: verbs:
- get - get
- list - apiGroups:
- watch - apps
resources:
- replicasets
verbs:
- get
- apiGroups:
- submariner.io
resources:
- '*'
- servicediscoveries
verbs:
- '*'
- apiGroups:
- lighthouse.submariner.io
resources:
- '*'
- serviceexports
verbs:
- create - create
- update
- delete - delete
- get
- list
- patch
- update
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
@@ -300,10 +424,9 @@ rules:
- update - update
- delete - delete
- watch - watch
- apiGroups: - apiGroups: # pods, services and nodes are looked up to figure out network settings
- "" - ""
resources: resources:
# Needed for network settings discovery
- pods - pods
- services - services
- nodes - nodes
@@ -317,42 +440,31 @@ rules:
- dnses - dnses
verbs: verbs:
- get - get
- list
- watch
- update - update
- apiGroups: - apiGroups:
- config.openshift.io - config.openshift.io
resources: resources:
# Needed for network settings discovery
- networks - networks
resourceNames:
- cluster
verbs: verbs:
- get - get
- list
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
- watch
- apiGroups: - apiGroups:
- monitoring.coreos.com - monitoring.coreos.com
resources: resources:
# Needed for openshift monitoring
- servicemonitors - servicemonitors
verbs: verbs:
- get - get
- create - create
- apiGroups:
- apps
resources:
# Needed for Flannel CNI discovery
- daemonsets
verbs:
- list
- apiGroups:
- rbac.authorization.k8s.io
resources:
# Temporarily needed for network-plugin syncer removal
- clusterroles
- clusterrolebindings
resourceNames:
- ocp-submariner-networkplugin-syncer
- submariner-networkplugin-syncer
verbs:
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -411,7 +523,21 @@ rules:
- configmaps - configmaps
verbs: verbs:
- get - get
- list
- watch
- create
- update
- apiGroups: - apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- "" - ""
resources: resources:
- pods - pods
@@ -421,6 +547,32 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- operator.openshift.io
resources:
- dnses
verbs:
- get
- list
- watch
- update
- apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- submariner.io
resources:
- endpoints
- gateways
- clusters
verbs:
- get
- list
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -453,40 +605,56 @@ rules:
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- pods
- services
- secrets
- configmaps - configmaps
- endpoints
verbs: verbs:
- get - get
- list - list
- watch
- update
- apiGroups: - apiGroups:
- config.openshift.io - apiextensions.k8s.io
resources: resources:
- networks - customresourcedefinitions
resourceNames:
- cluster
verbs: verbs:
- get - get
- apiGroups: - list
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- "" - ""
resources: resources:
- nodes - pods
- services
verbs: verbs:
- get - get
- list - list
- watch - watch
- apiGroups: - apiGroups:
- projectcalico.org - operator.openshift.io
resources: resources:
- ippools - dnses
verbs: verbs:
- get - get
- create - list
- delete - watch
- update - update
- deletecollection - apiGroups:
- config.openshift.io
resources:
- networks
verbs:
- get
- list
- apiGroups:
- ""
verbs:
- get
- list
- watch
- update
resources:
- nodes
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -521,15 +689,18 @@ rules:
- "" - ""
resources: resources:
- pods - pods
- namespaces
- nodes
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- update
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
- services - services
- endpoints
verbs: verbs:
- create - create
- get - get
@@ -540,8 +711,8 @@ rules:
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- clusters
- endpoints - endpoints
- clusters
verbs: verbs:
- get - get
- list - list
@@ -550,11 +721,17 @@ rules:
- submariner.io - submariner.io
resources: resources:
- clusterglobalegressips - clusterglobalegressips
- clusterglobalegressips/status
- globalegressips - globalegressips
- globalegressips/status verbs:
- create
- get
- list
- watch
- update
- apiGroups:
- submariner.io
resources:
- globalingressips - globalingressips
- globalingressips/status
verbs: verbs:
- create - create
- get - get
@@ -566,7 +743,7 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceexports - "serviceexports"
verbs: verbs:
- get - get
- list - list
@@ -621,6 +798,7 @@ rules:
- get - get
- list - list
- watch - watch
- update
- apiGroups: - apiGroups:
- discovery.k8s.io - discovery.k8s.io
resources: resources:
@@ -637,8 +815,8 @@ rules:
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gateways - "gateways"
- globalingressips - "globalingressips"
verbs: verbs:
- get - get
- list - list
@@ -646,8 +824,7 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceimports - "*"
- serviceimports/status
verbs: verbs:
- create - create
- get - get
@@ -655,20 +832,6 @@ rules:
- watch - watch
- update - update
- delete - delete
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports
verbs:
- get
- list
- watch
- apiGroups:
- multicluster.x-k8s.io
resources:
- serviceexports/status
verbs:
- update
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -694,18 +857,43 @@ metadata:
name: {{ template "submariner.fullname" . }}:lighthouse-coredns name: {{ template "submariner.fullname" . }}:lighthouse-coredns
rules: rules:
- apiGroups: - apiGroups:
- discovery.k8s.io - ""
resources: resources:
- endpointslices - services
- namespaces
- endpoints
verbs: verbs:
- get - get
- list - list
- watch - watch
- update
- apiGroups:
- discovery.k8s.io
resources:
- endpointslices
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups:
- lighthouse.submariner.io
resources:
- "*"
verbs:
- create
- get
- list
- watch
- update
- delete
- apiGroups: - apiGroups:
- submariner.io - submariner.io
resources: resources:
- gateways - "gateways"
- submariners
verbs: verbs:
- get - get
- list - list
@@ -713,11 +901,14 @@ rules:
- apiGroups: - apiGroups:
- multicluster.x-k8s.io - multicluster.x-k8s.io
resources: resources:
- serviceimports - "*"
verbs: verbs:
- create
- get - get
- list - list
- watch - watch
- update
- delete
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -23,7 +23,7 @@ spec:
namespace: {{ .Release.Namespace }} namespace: {{ .Release.Namespace }}
natEnabled: {{ .Values.submariner.natEnabled }} natEnabled: {{ .Values.submariner.natEnabled }}
repository: {{ .Values.submariner.images.repository }} repository: {{ .Values.submariner.images.repository }}
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }} version: {{ .Values.submariner.images.tag }}
{{- with .Values.images }} {{- with .Values.images }}
{{- if . }} {{- if . }}
imageOverrides: imageOverrides:
@@ -52,8 +52,6 @@ spec:
{{- end }} {{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}" serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}" globalCIDR: "{{ .Values.submariner.globalCidr }}"
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }} serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }} cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck: connectionHealthCheck:
@@ -62,6 +60,6 @@ spec:
maxPacketLossCount: 5 maxPacketLossCount: 5
{{- with .Values.submariner.coreDNSCustomConfig }} {{- with .Values.submariner.coreDNSCustomConfig }}
coreDNSCustomConfig: coreDNSCustomConfig:
configMapName: {{ .configMapName }} configmapName: {{ .configmapName }}
namespace: {{ .namespace }} namespace: {{ .namespace }}
{{- end }} {{- end }}
+6 -4
View File
@@ -5,8 +5,6 @@ submariner:
clusterCidr: "" clusterCidr: ""
serviceCidr: "" serviceCidr: ""
globalCidr: "" globalCidr: ""
clustersetIpCidr: ""
clustersetIpEnabled: false
loadBalancerEnabled: false loadBalancerEnabled: false
natEnabled: false natEnabled: false
colorCodes: blue colorCodes: blue
@@ -17,7 +15,7 @@ submariner:
coreDNSCustomConfig: {} coreDNSCustomConfig: {}
images: images:
repository: quay.io/submariner repository: quay.io/submariner
tag: "" tag: "0.14.0-m1"
broker: broker:
server: example.k8s.apiserver server: example.k8s.apiserver
token: test token: test
@@ -41,11 +39,15 @@ leadership:
operator: operator:
image: image:
repository: quay.io/submariner/submariner-operator repository: quay.io/submariner/submariner-operator
tag: "" tag: "0.14.0-m1"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
resources: {} resources: {}
tolerations: [] tolerations: []
affinity: {} affinity: {}
gateway:
image:
repository: quay.io/submariner/submariner-gateway
tag: "0.14.0-m1"
serviceAccounts: serviceAccounts:
operator: operator:
create: true create: true