mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-21 23:10:35 +00:00
Compare commits
33
Commits
+27
-18
@@ -9,24 +9,6 @@ updates:
|
|||||||
github-actions:
|
github-actions:
|
||||||
patterns:
|
patterns:
|
||||||
- "*"
|
- "*"
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.15"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: '/'
|
|
||||||
target-branch: "release-0.16"
|
|
||||||
schedule:
|
|
||||||
interval: monthly
|
|
||||||
groups:
|
|
||||||
github-actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
- package-ecosystem: github-actions
|
- package-ecosystem: github-actions
|
||||||
directory: '/'
|
directory: '/'
|
||||||
target-branch: "release-0.17"
|
target-branch: "release-0.17"
|
||||||
@@ -45,3 +27,30 @@ updates:
|
|||||||
github-actions:
|
github-actions:
|
||||||
patterns:
|
patterns:
|
||||||
- "*"
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.19"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.20"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: '/'
|
||||||
|
target-branch: "release-0.21"
|
||||||
|
schedule:
|
||||||
|
interval: monthly
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
|||||||
@@ -11,6 +11,6 @@ jobs:
|
|||||||
name: PR targets branch
|
name: PR targets branch
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check that the PR targets release-0.19
|
- name: Check that the PR targets devel
|
||||||
if: ${{ github.base_ref != 'release-0.19' }}
|
if: ${{ github.base_ref != 'devel' }}
|
||||||
run: exit 1
|
run: exit 1
|
||||||
|
|||||||
@@ -19,21 +19,21 @@ jobs:
|
|||||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||||
globalnet: ['', 'globalnet']
|
globalnet: ['', 'globalnet']
|
||||||
# Run most tests against the latest K8s version
|
# Run most tests against the latest K8s version
|
||||||
k8s_version: ['1.29']
|
k8s_version: ['k8s-latest']
|
||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
include:
|
include:
|
||||||
# Bottom of supported K8s version range
|
# Bottom of supported K8s version range
|
||||||
- k8s_version: '1.26'
|
- k8s_version: 'k8s-oldest-supported'
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
with:
|
with:
|
||||||
k8s_version: ${{ matrix.k8s_version }}
|
k8s_version: ${{ matrix.k8s_version }}
|
||||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||||
|
|
||||||
- name: Post mortem
|
- name: Post mortem
|
||||||
if: failure()
|
if: failure()
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||||
|
|||||||
@@ -13,11 +13,11 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
|
|
||||||
- name: Post mortem
|
- name: Post mortem
|
||||||
if: failure()
|
if: failure()
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||||
|
|||||||
@@ -21,13 +21,13 @@ jobs:
|
|||||||
lighthouse: ['', 'lighthouse']
|
lighthouse: ['', 'lighthouse']
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
|
|
||||||
- name: Run E2E deployment and tests
|
- name: Run E2E deployment and tests
|
||||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.19
|
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||||
with:
|
with:
|
||||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||||
|
|
||||||
- name: Post mortem
|
- name: Post mortem
|
||||||
if: failure()
|
if: failure()
|
||||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.19
|
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||||
|
|||||||
@@ -38,15 +38,15 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
|
|
||||||
- name: Set up Helm
|
- name: Set up Helm
|
||||||
uses: azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112
|
uses: azure/setup-helm@1a275c3b69536ee54be43f2070a358922e12c8d4
|
||||||
with:
|
with:
|
||||||
version: v3.6.0
|
version: v3.6.0
|
||||||
|
|
||||||
- name: Set up Python
|
- name: Set up Python
|
||||||
uses: actions/setup-python@8d9ed9ac5c53483de85588cdf95a591a75ab9f55
|
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
|
|
||||||
@@ -64,7 +64,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
- name: Run gitlint
|
- name: Run gitlint
|
||||||
@@ -75,7 +75,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
|
|
||||||
- name: Run helm-docs and verify docs are up-to-date
|
- name: Run helm-docs and verify docs are up-to-date
|
||||||
run: make helm-docs
|
run: make helm-docs
|
||||||
@@ -85,7 +85,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||||
@@ -99,7 +99,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
- name: Run markdownlint
|
- name: Run markdownlint
|
||||||
run: make markdownlint
|
run: make markdownlint
|
||||||
|
|
||||||
@@ -108,6 +108,6 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
- name: Run yamllint
|
- name: Run yamllint
|
||||||
run: make yamllint
|
run: make yamllint
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ jobs:
|
|||||||
issues: write
|
issues: write
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the repository
|
- name: Check out the repository
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
|
|
||||||
- name: Run markdown-link-check
|
- name: Run markdown-link-check
|
||||||
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ name: Release Charts
|
|||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- release-0.19
|
- devel
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
@@ -16,7 +16,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ jobs:
|
|||||||
issues: write
|
issues: write
|
||||||
pull-requests: write
|
pull-requests: write
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@ba23c1cb02e5cb8f885b0994d870e6032be00186
|
- uses: actions/stale@8f717f0dfca33b78d3c933452e42558e4456c8e7
|
||||||
with:
|
with:
|
||||||
days-before-issue-stale: 120
|
days-before-issue-stale: 120
|
||||||
days-before-pr-stale: 14
|
days-before-pr-stale: 14
|
||||||
|
|||||||
@@ -6,3 +6,10 @@ Makefile.dapper
|
|||||||
Makefile.shipyard
|
Makefile.shipyard
|
||||||
Dockerfile.*
|
Dockerfile.*
|
||||||
helm_repo
|
helm_repo
|
||||||
|
yamls/go.mod
|
||||||
|
yamls/go.sum
|
||||||
|
yamls/vendor
|
||||||
|
submariner-k8s-broker/crds/crd.yaml
|
||||||
|
submariner-k8s-broker/templates/_role.tpl
|
||||||
|
submariner-operator/crds/crd.yaml
|
||||||
|
submariner-operator/templates/*-rbac.yaml
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
BASE_BRANCH ?= release-0.19
|
BASE_BRANCH ?= devel
|
||||||
export BASE_BRANCH
|
export BASE_BRANCH
|
||||||
export HELM_REPO_LOCATION=./helm_repo
|
export HELM_REPO_LOCATION=./helm_repo
|
||||||
|
|
||||||
@@ -17,7 +17,7 @@ endif
|
|||||||
export DEPLOYTOOL = helm
|
export DEPLOYTOOL = helm
|
||||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||||
CHARTS_DIR=charts
|
CHARTS_DIR=charts
|
||||||
CHARTS_VERSION=0.19.4
|
CHARTS_VERSION=0.22.0-m2
|
||||||
HELM_DOCS_VERSION=0.15.0
|
HELM_DOCS_VERSION=0.15.0
|
||||||
REPO_URL=$(shell git config remote.origin.url)
|
REPO_URL=$(shell git config remote.origin.url)
|
||||||
|
|
||||||
@@ -34,7 +34,10 @@ local-helm-repo: $(CHART_PACKAGES)
|
|||||||
e2e: local-helm-repo
|
e2e: local-helm-repo
|
||||||
$(SCRIPTS_DIR)/e2e.sh
|
$(SCRIPTS_DIR)/e2e.sh
|
||||||
|
|
||||||
%.tgz:
|
generate-yamls:
|
||||||
|
./generate-yamls.sh $(BASE_BRANCH)
|
||||||
|
|
||||||
|
%.tgz: generate-yamls
|
||||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||||
|
|
||||||
|
|||||||
Executable
+103
@@ -0,0 +1,103 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
BROKER_ROLE_TPL=submariner-k8s-broker/templates/_role.tpl
|
||||||
|
OPERATOR_RBAC_YAML=submariner-operator/templates/operator-rbac.yaml
|
||||||
|
GATEWAY_RBAC_YAML=submariner-operator/templates/gateway-rbac.yaml
|
||||||
|
ROUTE_AGENT_RBAC_YAML=submariner-operator/templates/routeagent-rbac.yaml
|
||||||
|
GLOBALNET_RBAC_YAML=submariner-operator/templates/globalnet-rbac.yaml
|
||||||
|
SERVICE_DISC_RBAC_YAML=submariner-operator/templates/service-discovery-rbac.yaml
|
||||||
|
OPENSHIFT_MONITORING_YAML=submariner-operator/templates/openshift-monitoring-rbac.yaml
|
||||||
|
|
||||||
|
YAMLS_BASE=yamls/vendor
|
||||||
|
SUBM_CRDS=${YAMLS_BASE}/github.com/submariner-io/submariner/deploy/crds
|
||||||
|
OPERATOR_CRDS=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/deploy/crds
|
||||||
|
MCS_CRDS=${YAMLS_BASE}/sigs.k8s.io/mcs-api/config/crd
|
||||||
|
BROKER=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/broker/broker-client
|
||||||
|
RBAC_BASE=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/rbac
|
||||||
|
OPENSHIFT=${YAMLS_BASE}/github.com/submariner-io/submariner-operator/config/openshift
|
||||||
|
|
||||||
|
function add_service_acct_ns() {
|
||||||
|
sed -i '/- kind: ServiceAccount/a \ \ \ \ namespace: {{ .Release.Namespace }}' $1
|
||||||
|
}
|
||||||
|
|
||||||
|
cd yamls
|
||||||
|
rm go.mod || true
|
||||||
|
go mod init
|
||||||
|
go get github.com/submariner-io/submariner-operator@$1
|
||||||
|
go mod tidy
|
||||||
|
go mod vendor
|
||||||
|
cd ..
|
||||||
|
|
||||||
|
# Generate the CRDs for the broker chart
|
||||||
|
mkdir -p submariner-k8s-broker/crds
|
||||||
|
cat ${SUBM_CRDS}/submariner.io_endpoints.yaml \
|
||||||
|
${SUBM_CRDS}/submariner.io_clusters.yaml \
|
||||||
|
${SUBM_CRDS}/submariner.io_gateways.yaml > submariner-k8s-broker/crds/crd.yaml
|
||||||
|
echo '---' >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
cat ${MCS_CRDS}/multicluster.x-k8s.io_serviceexports.yaml >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
echo '---' >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
cat ${MCS_CRDS}/multicluster.x-k8s.io_serviceimports.yaml >> submariner-k8s-broker/crds/crd.yaml
|
||||||
|
|
||||||
|
# Generate the client role yaml for the broker chart
|
||||||
|
echo '{{- define "broker-role" -}}' > ${BROKER_ROLE_TPL}
|
||||||
|
cat ${BROKER}/role.yaml >> ${BROKER_ROLE_TPL}
|
||||||
|
echo '{{- end -}}' >> ${BROKER_ROLE_TPL}
|
||||||
|
sed -i -e 's/name:.*/name: {{ template "submariner-k8s-broker.fullname" \. }}-cluster/' ${BROKER_ROLE_TPL}
|
||||||
|
|
||||||
|
# Generate the CRDs for the operator chart
|
||||||
|
mkdir -p submariner-operator/crds
|
||||||
|
cat ${OPERATOR_CRDS}/submariner.io_submariners.yaml \
|
||||||
|
${OPERATOR_CRDS}/submariner.io_servicediscoveries.yaml \
|
||||||
|
${OPERATOR_CRDS}/submariner.io_brokers.yaml > submariner-operator/crds/crd.yaml
|
||||||
|
|
||||||
|
# Generate the operator RBAC yaml for the operator chart
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-operator/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-operator/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-operator/cluster_role_binding.yaml > ${OPERATOR_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the gateway RBAC yaml for the operator chart
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-gateway/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-gateway/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-gateway/cluster_role_binding.yaml > ${GATEWAY_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the routeagent RBAC yaml for the operator chart
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-route-agent/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-route-agent/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-route-agent/cluster_role_binding.yaml > ${ROUTE_AGENT_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the globalnet RBAC yaml for the operator chart
|
||||||
|
echo '{{- if .Values.broker.globalnet }}' > ${GLOBALNET_RBAC_YAML}
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/submariner-globalnet/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/submariner-globalnet/service_account.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/role_binding.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/submariner-globalnet/cluster_role_binding.yaml >> ${GLOBALNET_RBAC_YAML}
|
||||||
|
echo '{{- end -}}' >> ${GLOBALNET_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the service discovery RBAC yaml for the operator chart
|
||||||
|
echo '{{- if .Values.submariner.serviceDiscovery }}' > ${SERVICE_DISC_RBAC_YAML}
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/lighthouse-agent/cluster_role_binding.yaml
|
||||||
|
add_service_acct_ns ${RBAC_BASE}/lighthouse-coredns/cluster_role_binding.yaml
|
||||||
|
cat ${RBAC_BASE}/lighthouse-agent/service_account.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-agent/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-agent/cluster_role_binding.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/service_account.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/cluster_role.yaml \
|
||||||
|
${RBAC_BASE}/lighthouse-coredns/cluster_role_binding.yaml >> ${SERVICE_DISC_RBAC_YAML}
|
||||||
|
echo '{{- end -}}' >> ${SERVICE_DISC_RBAC_YAML}
|
||||||
|
|
||||||
|
# Generate the openshift monitoring rbac yaml for the operator chart
|
||||||
|
cat ${OPENSHIFT}/rbac/submariner-metrics-reader/role.yaml \
|
||||||
|
${OPENSHIFT}/rbac/submariner-metrics-reader/role_binding.yaml > ${OPENSHIFT_MONITORING_YAML}
|
||||||
@@ -13,12 +13,3 @@ Submariner Kubernetes Broker
|
|||||||
## Source Code
|
## Source Code
|
||||||
|
|
||||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
* <https://submariner-io.github.io/submariner-charts/charts>
|
||||||
|
|
||||||
## Values
|
|
||||||
|
|
||||||
| Key | Type | Default | Description |
|
|
||||||
|-----|------|---------|-------------|
|
|
||||||
| crd.create | bool | `true` | |
|
|
||||||
| rbac.create | bool | `true` | |
|
|
||||||
| serviceAccounts.client.create | bool | `true` | |
|
|
||||||
| serviceAccounts.client.name | string | `""` | |
|
|
||||||
|
|||||||
@@ -1,560 +0,0 @@
|
|||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: clusters.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
names:
|
|
||||||
kind: Cluster
|
|
||||||
listKind: ClusterList
|
|
||||||
plural: clusters
|
|
||||||
singular: cluster
|
|
||||||
scope: Namespaced
|
|
||||||
versions:
|
|
||||||
- name: v1
|
|
||||||
schema:
|
|
||||||
openAPIV3Schema:
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
spec:
|
|
||||||
properties:
|
|
||||||
cluster_cidr:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
cluster_id:
|
|
||||||
type: string
|
|
||||||
color_codes:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
global_cidr:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
service_cidr:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
required:
|
|
||||||
- cluster_cidr
|
|
||||||
- cluster_id
|
|
||||||
- color_codes
|
|
||||||
- global_cidr
|
|
||||||
- service_cidr
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- spec
|
|
||||||
type: object
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: endpoints.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
names:
|
|
||||||
kind: Endpoint
|
|
||||||
listKind: EndpointList
|
|
||||||
plural: endpoints
|
|
||||||
singular: endpoint
|
|
||||||
scope: Namespaced
|
|
||||||
versions:
|
|
||||||
- name: v1
|
|
||||||
schema:
|
|
||||||
openAPIV3Schema:
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
spec:
|
|
||||||
properties:
|
|
||||||
backend:
|
|
||||||
type: string
|
|
||||||
backend_config:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
cable_name:
|
|
||||||
type: string
|
|
||||||
cluster_id:
|
|
||||||
type: string
|
|
||||||
healthCheckIP:
|
|
||||||
type: string
|
|
||||||
hostname:
|
|
||||||
type: string
|
|
||||||
nat_enabled:
|
|
||||||
type: boolean
|
|
||||||
private_ip:
|
|
||||||
type: string
|
|
||||||
public_ip:
|
|
||||||
type: string
|
|
||||||
subnets:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
required:
|
|
||||||
- backend
|
|
||||||
- cable_name
|
|
||||||
- cluster_id
|
|
||||||
- hostname
|
|
||||||
- nat_enabled
|
|
||||||
- private_ip
|
|
||||||
- public_ip
|
|
||||||
- subnets
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- spec
|
|
||||||
type: object
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: gateways.submariner.io
|
|
||||||
spec:
|
|
||||||
group: submariner.io
|
|
||||||
names:
|
|
||||||
kind: Gateway
|
|
||||||
listKind: GatewayList
|
|
||||||
plural: gateways
|
|
||||||
singular: gateway
|
|
||||||
scope: Namespaced
|
|
||||||
versions:
|
|
||||||
- additionalPrinterColumns:
|
|
||||||
- description: High availability status of the Gateway
|
|
||||||
jsonPath: .status.haStatus
|
|
||||||
name: HA Status
|
|
||||||
type: string
|
|
||||||
name: v1
|
|
||||||
schema:
|
|
||||||
openAPIV3Schema:
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
properties:
|
|
||||||
connections:
|
|
||||||
items:
|
|
||||||
properties:
|
|
||||||
endpoint:
|
|
||||||
properties:
|
|
||||||
backend:
|
|
||||||
type: string
|
|
||||||
backend_config:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
cable_name:
|
|
||||||
type: string
|
|
||||||
cluster_id:
|
|
||||||
type: string
|
|
||||||
healthCheckIP:
|
|
||||||
type: string
|
|
||||||
hostname:
|
|
||||||
type: string
|
|
||||||
nat_enabled:
|
|
||||||
type: boolean
|
|
||||||
private_ip:
|
|
||||||
type: string
|
|
||||||
public_ip:
|
|
||||||
type: string
|
|
||||||
subnets:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
required:
|
|
||||||
- backend
|
|
||||||
- cable_name
|
|
||||||
- cluster_id
|
|
||||||
- hostname
|
|
||||||
- nat_enabled
|
|
||||||
- private_ip
|
|
||||||
- public_ip
|
|
||||||
- subnets
|
|
||||||
type: object
|
|
||||||
latency:
|
|
||||||
description: LatencySpec describes the round trip time information
|
|
||||||
in nanoseconds for a packet between the gateway pods of two
|
|
||||||
clusters.
|
|
||||||
properties:
|
|
||||||
averageRTT:
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
lastRTT:
|
|
||||||
description: TODO This shall be deleted once the operator
|
|
||||||
is using the latest. Using Optional to avoid validation
|
|
||||||
errors when this field is not used.
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
maxRTT:
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
minRTT:
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
stddevRTT:
|
|
||||||
format: int64
|
|
||||||
type: integer
|
|
||||||
type: object
|
|
||||||
latencyRTT:
|
|
||||||
description: LatencySpec describes the round trip time information
|
|
||||||
for a packet between the gateway pods of two clusters.
|
|
||||||
properties:
|
|
||||||
average:
|
|
||||||
type: string
|
|
||||||
last:
|
|
||||||
type: string
|
|
||||||
max:
|
|
||||||
type: string
|
|
||||||
min:
|
|
||||||
type: string
|
|
||||||
stdDev:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
type: string
|
|
||||||
statusMessage:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- endpoint
|
|
||||||
- status
|
|
||||||
- statusMessage
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
haStatus:
|
|
||||||
type: string
|
|
||||||
localEndpoint:
|
|
||||||
properties:
|
|
||||||
backend:
|
|
||||||
type: string
|
|
||||||
backend_config:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
cable_name:
|
|
||||||
type: string
|
|
||||||
cluster_id:
|
|
||||||
type: string
|
|
||||||
healthCheckIP:
|
|
||||||
type: string
|
|
||||||
hostname:
|
|
||||||
type: string
|
|
||||||
nat_enabled:
|
|
||||||
type: boolean
|
|
||||||
private_ip:
|
|
||||||
type: string
|
|
||||||
public_ip:
|
|
||||||
type: string
|
|
||||||
subnets:
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
type: array
|
|
||||||
required:
|
|
||||||
- backend
|
|
||||||
- cable_name
|
|
||||||
- cluster_id
|
|
||||||
- hostname
|
|
||||||
- nat_enabled
|
|
||||||
- private_ip
|
|
||||||
- public_ip
|
|
||||||
- subnets
|
|
||||||
type: object
|
|
||||||
statusFailure:
|
|
||||||
type: string
|
|
||||||
version:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- connections
|
|
||||||
- haStatus
|
|
||||||
- localEndpoint
|
|
||||||
- statusFailure
|
|
||||||
- version
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- status
|
|
||||||
type: object
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources: {}
|
|
||||||
status:
|
|
||||||
acceptedNames:
|
|
||||||
kind: ""
|
|
||||||
plural: ""
|
|
||||||
conditions: []
|
|
||||||
storedVersions: []
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: serviceexports.multicluster.x-k8s.io
|
|
||||||
spec:
|
|
||||||
group: multicluster.x-k8s.io
|
|
||||||
scope: Namespaced
|
|
||||||
names:
|
|
||||||
plural: serviceexports
|
|
||||||
singular: serviceexport
|
|
||||||
kind: ServiceExport
|
|
||||||
shortNames:
|
|
||||||
- svcex
|
|
||||||
versions:
|
|
||||||
- name: v1alpha1
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
additionalPrinterColumns:
|
|
||||||
- name: Age
|
|
||||||
type: date
|
|
||||||
jsonPath: .metadata.creationTimestamp
|
|
||||||
"schema":
|
|
||||||
"openAPIV3Schema":
|
|
||||||
description: ServiceExport declares that the Service with the same name and
|
|
||||||
namespace as this export should be consumable from other clusters.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
description: status describes the current state of an exported service.
|
|
||||||
Service configuration comes from the Service that had the same name
|
|
||||||
and namespace as this ServiceExport. Populated by the multi-cluster
|
|
||||||
service implementation's controller.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
conditions:
|
|
||||||
type: array
|
|
||||||
items:
|
|
||||||
description: "ServiceExportCondition contains details for the current
|
|
||||||
condition of this service export. \n Once [KEP-1623](https://github.com/kubernetes/enhancements/tree/master/keps/sig-api-machinery/1623-standardize-conditions)
|
|
||||||
is implemented, this will be replaced by metav1.Condition."
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- status
|
|
||||||
- type
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
type: string
|
|
||||||
format: date-time
|
|
||||||
message:
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
description: Status is one of {"True", "False", "Unknown"}
|
|
||||||
type: string
|
|
||||||
enum:
|
|
||||||
- "True"
|
|
||||||
- "False"
|
|
||||||
- Unknown
|
|
||||||
type:
|
|
||||||
description: ServiceExportConditionType identifies a specific
|
|
||||||
condition.
|
|
||||||
type: string
|
|
||||||
x-kubernetes-list-map-keys:
|
|
||||||
- type
|
|
||||||
x-kubernetes-list-type: map
|
|
||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: serviceimports.multicluster.x-k8s.io
|
|
||||||
spec:
|
|
||||||
group: multicluster.x-k8s.io
|
|
||||||
scope: Namespaced
|
|
||||||
names:
|
|
||||||
plural: serviceimports
|
|
||||||
singular: serviceimport
|
|
||||||
kind: ServiceImport
|
|
||||||
shortNames:
|
|
||||||
- svcim
|
|
||||||
versions:
|
|
||||||
- name: v1alpha1
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
additionalPrinterColumns:
|
|
||||||
- name: Type
|
|
||||||
type: string
|
|
||||||
description: The type of this ServiceImport
|
|
||||||
jsonPath: .spec.type
|
|
||||||
- name: IP
|
|
||||||
type: string
|
|
||||||
description: The VIP for this ServiceImport
|
|
||||||
jsonPath: .spec.ips
|
|
||||||
- name: Age
|
|
||||||
type: date
|
|
||||||
jsonPath: .metadata.creationTimestamp
|
|
||||||
"schema":
|
|
||||||
"openAPIV3Schema":
|
|
||||||
description: ServiceImport describes a service imported from clusters in a
|
|
||||||
ClusterSet.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
apiVersion:
|
|
||||||
description: 'APIVersion defines the versioned schema of this representation
|
|
||||||
of an object. Servers should convert recognized schemas to the latest
|
|
||||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
||||||
type: string
|
|
||||||
kind:
|
|
||||||
description: 'Kind is a string value representing the REST resource this
|
|
||||||
object represents. Servers may infer this from the endpoint the client
|
|
||||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
||||||
type: string
|
|
||||||
metadata:
|
|
||||||
type: object
|
|
||||||
spec:
|
|
||||||
description: spec defines the behavior of a ServiceImport.
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- ports
|
|
||||||
- type
|
|
||||||
properties:
|
|
||||||
ips:
|
|
||||||
description: ip will be used as the VIP for this service when type
|
|
||||||
is ClusterSetIP.
|
|
||||||
type: array
|
|
||||||
maxItems: 1
|
|
||||||
items:
|
|
||||||
type: string
|
|
||||||
ports:
|
|
||||||
type: array
|
|
||||||
items:
|
|
||||||
description: ServicePort represents the port on which the service
|
|
||||||
is exposed
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- port
|
|
||||||
properties:
|
|
||||||
appProtocol:
|
|
||||||
description: The application protocol for this port. This field
|
|
||||||
follows standard Kubernetes label syntax. Un-prefixed names
|
|
||||||
are reserved for IANA standard service names (as per RFC-6335
|
|
||||||
and http://www.iana.org/assignments/service-names). Non-standard
|
|
||||||
protocols should use prefixed names such as mycompany.com/my-custom-protocol.
|
|
||||||
Field can be enabled with ServiceAppProtocol feature gate.
|
|
||||||
type: string
|
|
||||||
name:
|
|
||||||
description: The name of this port within the service. This
|
|
||||||
must be a DNS_LABEL. All ports within a ServiceSpec must have
|
|
||||||
unique names. When considering the endpoints for a Service,
|
|
||||||
this must match the 'name' field in the EndpointPort. Optional
|
|
||||||
if only one ServicePort is defined on this service.
|
|
||||||
type: string
|
|
||||||
port:
|
|
||||||
description: The port that will be exposed by this service.
|
|
||||||
type: integer
|
|
||||||
format: int32
|
|
||||||
protocol:
|
|
||||||
description: The IP protocol for this port. Supports "TCP",
|
|
||||||
"UDP", and "SCTP". Default is TCP.
|
|
||||||
type: string
|
|
||||||
x-kubernetes-list-type: atomic
|
|
||||||
sessionAffinity:
|
|
||||||
description: 'Supports "ClientIP" and "None". Used to maintain session
|
|
||||||
affinity. Enable client IP based session affinity. Must be ClientIP
|
|
||||||
or None. Defaults to None. Ignored when type is Headless More info:
|
|
||||||
https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies'
|
|
||||||
type: string
|
|
||||||
sessionAffinityConfig:
|
|
||||||
description: sessionAffinityConfig contains session affinity configuration.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
clientIP:
|
|
||||||
description: clientIP contains the configurations of Client IP
|
|
||||||
based session affinity.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
timeoutSeconds:
|
|
||||||
description: timeoutSeconds specifies the seconds of ClientIP
|
|
||||||
type session sticky time. The value must be >0 && <=86400(for
|
|
||||||
1 day) if ServiceAffinity == "ClientIP". Default value is
|
|
||||||
10800(for 3 hours).
|
|
||||||
type: integer
|
|
||||||
format: int32
|
|
||||||
type:
|
|
||||||
description: type defines the type of this service. Must be ClusterSetIP
|
|
||||||
or Headless.
|
|
||||||
type: string
|
|
||||||
enum:
|
|
||||||
- ClusterSetIP
|
|
||||||
- Headless
|
|
||||||
status:
|
|
||||||
description: status contains information about the exported services that
|
|
||||||
form the multi-cluster service referenced by this ServiceImport.
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
clusters:
|
|
||||||
description: clusters is the list of exporting clusters from which
|
|
||||||
this service was derived.
|
|
||||||
type: array
|
|
||||||
items:
|
|
||||||
description: ClusterStatus contains service configuration mapped
|
|
||||||
to a specific source cluster
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- cluster
|
|
||||||
properties:
|
|
||||||
cluster:
|
|
||||||
description: cluster is the name of the exporting cluster. Must
|
|
||||||
be a valid RFC-1123 DNS label.
|
|
||||||
type: string
|
|
||||||
x-kubernetes-list-map-keys:
|
|
||||||
- cluster
|
|
||||||
x-kubernetes-list-type: map
|
|
||||||
@@ -35,9 +35,5 @@ Create chart name and version as used by the chart label.
|
|||||||
Create the name of the submariner-client service account to use
|
Create the name of the submariner-client service account to use
|
||||||
*/}}
|
*/}}
|
||||||
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
||||||
{{- if .Values.serviceAccounts.client.create -}}
|
{{- printf "%s-client" (include "submariner-k8s-broker.fullname" .)}}
|
||||||
{{ default (printf "%s-client" (include "submariner-k8s-broker.fullname" .)) .Values.serviceAccounts.client.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.client.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
@@ -1,26 +1,4 @@
|
|||||||
{{- if .Values.rbac.create -}}
|
{{ include "broker-role" $ }}
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
|
||||||
app: {{ template "submariner-k8s-broker.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: ["submariner.io"]
|
|
||||||
resources: ["clusters", "endpoints"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
|
||||||
- apiGroups: ["lighthouse.submariner.io"]
|
|
||||||
resources: ["*"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
|
||||||
- apiGroups: ["discovery.k8s.io"]
|
|
||||||
resources: ["endpointslices", "endpointslices/restricted"]
|
|
||||||
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
|
|
||||||
- apiGroups: ["multicluster.x-k8s.io"]
|
|
||||||
resources: ["*"]
|
|
||||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
@@ -34,4 +12,3 @@ subjects:
|
|||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
{{- end -}}
|
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
{{- if .Values.serviceAccounts.client.create }}
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
@@ -16,4 +15,3 @@ metadata:
|
|||||||
annotations:
|
annotations:
|
||||||
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||||
type: kubernetes.io/service-account-token
|
type: kubernetes.io/service-account-token
|
||||||
{{- end }}
|
|
||||||
@@ -1,9 +1 @@
|
|||||||
---
|
---
|
||||||
rbac:
|
|
||||||
create: true
|
|
||||||
crd:
|
|
||||||
create: true
|
|
||||||
serviceAccounts:
|
|
||||||
client:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
|
|||||||
@@ -38,19 +38,6 @@ Submariner enables direct networking between Pods and Services in different Kube
|
|||||||
| operator.image.tag | string | `"0.14.0"` | |
|
| operator.image.tag | string | `"0.14.0"` | |
|
||||||
| operator.resources | object | `{}` | |
|
| operator.resources | object | `{}` | |
|
||||||
| operator.tolerations | list | `[]` | |
|
| operator.tolerations | list | `[]` | |
|
||||||
| rbac.create | bool | `true` | |
|
|
||||||
| serviceAccounts.gateway.create | bool | `true` | |
|
|
||||||
| serviceAccounts.gateway.name | string | `""` | |
|
|
||||||
| serviceAccounts.globalnet.create | bool | `true` | |
|
|
||||||
| serviceAccounts.globalnet.name | string | `""` | |
|
|
||||||
| serviceAccounts.lighthouseAgent.create | bool | `true` | |
|
|
||||||
| serviceAccounts.lighthouseAgent.name | string | `""` | |
|
|
||||||
| serviceAccounts.lighthouseCoreDns.create | bool | `true` | |
|
|
||||||
| serviceAccounts.lighthouseCoreDns.name | string | `""` | |
|
|
||||||
| serviceAccounts.operator.create | bool | `true` | |
|
|
||||||
| serviceAccounts.operator.name | string | `""` | |
|
|
||||||
| serviceAccounts.routeAgent.create | bool | `true` | |
|
|
||||||
| serviceAccounts.routeAgent.name | string | `""` | |
|
|
||||||
| submariner.cableDriver | string | `"libreswan"` | |
|
| submariner.cableDriver | string | `"libreswan"` | |
|
||||||
| submariner.clusterCidr | string | `""` | |
|
| submariner.clusterCidr | string | `""` | |
|
||||||
| submariner.clusterId | string | `""` | |
|
| submariner.clusterId | string | `""` | |
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -1,11 +1,4 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
{{/* vim: set filetype=mustache: */}}
|
||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
{{/*
|
||||||
Create a default fully qualified app name.
|
Create a default fully qualified app name.
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
@@ -31,75 +24,3 @@ Create chart name and version as used by the chart label.
|
|||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-operator service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.operatorServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.operator.create -}}
|
|
||||||
{{ default (printf "%s" (include "submariner.fullname" .)) .Values.serviceAccounts.operator.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.operator.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-gateway service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.gatewayServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.gateway.create -}}
|
|
||||||
{{ default "submariner-gateway" .Values.serviceAccounts.gateway.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.gateway.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-route-agent service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.routeAgentServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
|
||||||
{{ default "submariner-routeagent" .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-globalnet service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.globalnetServiceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccounts.globalnet.create -}}
|
|
||||||
{{ default "submariner-globalnet" .Values.serviceAccounts.globalnet.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.globalnet.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-lighthouse-agent service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.lighthouseAgentServiceAccountName" -}}
|
|
||||||
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseAgent.create) -}}
|
|
||||||
{{ default "submariner-lighthouse-agent" .Values.serviceAccounts.lighthouseAgent.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.lighthouseAgent.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-lighthouse-coredns service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.lighthouseCoreDnsServiceAccountName" -}}
|
|
||||||
{{- if and (.Values.submariner.serviceDiscovery ) (.Values.serviceAccounts.lighthouseCoreDns.create) -}}
|
|
||||||
{{ default "submariner-lighthouse-coredns" .Values.serviceAccounts.lighthouseCoreDns.name }}
|
|
||||||
{{- else -}}
|
|
||||||
{{ default "default" .Values.serviceAccounts.lighthouseCoreDns.name }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the submariner-lighthouse-coredns service name to use
|
|
||||||
*/}}
|
|
||||||
{{- define "submariner.lighthouseDnsName" -}}
|
|
||||||
{{- default (printf "%s-lighthouse-coredns" (include "submariner.fullname" .)) .Values.lighthouseCoredns.name }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|||||||
@@ -6,7 +6,6 @@ metadata:
|
|||||||
release: {{ .Release.Name | quote }}
|
release: {{ .Release.Name | quote }}
|
||||||
chart: {{ template "submariner.chart" . }}
|
chart: {{ template "submariner.chart" . }}
|
||||||
app: {{ template "submariner.fullname" . }}
|
app: {{ template "submariner.fullname" . }}
|
||||||
component: gateway
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
name: {{ template "submariner.fullname" . }}
|
||||||
spec:
|
spec:
|
||||||
progressDeadlineSeconds: 600
|
progressDeadlineSeconds: 600
|
||||||
@@ -27,8 +26,8 @@ spec:
|
|||||||
name: {{ template "submariner.fullname" . }}
|
name: {{ template "submariner.fullname" . }}
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- command:
|
- args:
|
||||||
- submariner-operator
|
- --leader-elect
|
||||||
env:
|
env:
|
||||||
- name: WATCH_NAMESPACE
|
- name: WATCH_NAMESPACE
|
||||||
valueFrom:
|
valueFrom:
|
||||||
@@ -52,6 +51,5 @@ spec:
|
|||||||
restartPolicy: Always
|
restartPolicy: Always
|
||||||
schedulerName: default-scheduler
|
schedulerName: default-scheduler
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
serviceAccount: {{ template "submariner.fullname" . }}
|
serviceAccountName: submariner-operator
|
||||||
serviceAccountName: {{ template "submariner.fullname" . }}
|
|
||||||
terminationGracePeriodSeconds: 30
|
terminationGracePeriodSeconds: 30
|
||||||
|
|||||||
@@ -1,735 +0,0 @@
|
|||||||
{{- if .Values.rbac.create -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
# For metrics
|
|
||||||
- services
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
# Temporarily needed for network-plugin syncer removal
|
|
||||||
- serviceaccounts
|
|
||||||
resourceNames:
|
|
||||||
- submariner-networkplugin-syncer
|
|
||||||
verbs:
|
|
||||||
- delete
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- daemonsets
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
# Needed for openshift monitoring
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resourceNames:
|
|
||||||
- {{ template "submariner.fullname" . }}
|
|
||||||
resources:
|
|
||||||
- deployments/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- brokers
|
|
||||||
- brokers/status
|
|
||||||
- submariners
|
|
||||||
- submariners/status
|
|
||||||
- servicediscoveries
|
|
||||||
- servicediscoveries/status
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- gateways
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- submariners/finalizers
|
|
||||||
- servicediscoveries/finalizers
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
---
|
|
||||||
kind: RoleBinding
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
|
||||||
roleRef:
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- update
|
|
||||||
- patch
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- clusters
|
|
||||||
- endpoints
|
|
||||||
- gateways
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups:
|
|
||||||
- coordination.k8s.io
|
|
||||||
resources:
|
|
||||||
- leases
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- gatewayroutes
|
|
||||||
- nongatewayroutes
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- if .Values.broker.globalnet }}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- gateways
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- coordination.k8s.io
|
|
||||||
resources:
|
|
||||||
- leases
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- end -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
# submariner-operator updates the config map of core-dns to forward requests to
|
|
||||||
# clusterset.local to Lighthouse DNS, also looks at existing configmaps
|
|
||||||
# to figure out network settings
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- apiextensions.k8s.io
|
|
||||||
resources:
|
|
||||||
- customresourcedefinitions
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- create
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
# Needed for network settings discovery
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- nodes
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- operator.openshift.io
|
|
||||||
resources:
|
|
||||||
- dnses
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- config.openshift.io
|
|
||||||
resources:
|
|
||||||
# Needed for network settings discovery
|
|
||||||
- networks
|
|
||||||
resourceNames:
|
|
||||||
- cluster
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- monitoring.coreos.com
|
|
||||||
resources:
|
|
||||||
# Needed for openshift monitoring
|
|
||||||
- servicemonitors
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
# Needed for Flannel CNI discovery
|
|
||||||
- daemonsets
|
|
||||||
verbs:
|
|
||||||
- list
|
|
||||||
- apiGroups:
|
|
||||||
- rbac.authorization.k8s.io
|
|
||||||
resources:
|
|
||||||
# Temporarily needed for network-plugin syncer removal
|
|
||||||
- clusterroles
|
|
||||||
- clusterrolebindings
|
|
||||||
resourceNames:
|
|
||||||
- ocp-submariner-networkplugin-syncer
|
|
||||||
- submariner-networkplugin-syncer
|
|
||||||
verbs:
|
|
||||||
- delete
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: submariner-metrics-reader
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["pods", "services", "endpoints"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: read-submariner-metrics
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: prometheus-k8s
|
|
||||||
namespace: openshift-monitoring
|
|
||||||
roleRef:
|
|
||||||
kind: Role
|
|
||||||
name: submariner-metrics-reader
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- nodes
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:gateway
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- services
|
|
||||||
- secrets
|
|
||||||
- configmaps
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- apiGroups:
|
|
||||||
- config.openshift.io
|
|
||||||
resources:
|
|
||||||
- networks
|
|
||||||
resourceNames:
|
|
||||||
- cluster
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- nodes
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- projectcalico.org
|
|
||||||
resources:
|
|
||||||
- ippools
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- update
|
|
||||||
- deletecollection
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:routeagent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- if .Values.broker.globalnet }}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- services
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- clusters
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- clusterglobalegressips
|
|
||||||
- clusterglobalegressips/status
|
|
||||||
- globalegressips
|
|
||||||
- globalegressips/status
|
|
||||||
- globalingressips
|
|
||||||
- globalingressips/status
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- deletecollection
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- network.openshift.io
|
|
||||||
resources:
|
|
||||||
- service/externalips
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- delete
|
|
||||||
---
|
|
||||||
{{- end -}}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:globalnet
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
{{- if .Values.submariner.serviceDiscovery }}
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- services
|
|
||||||
- namespaces
|
|
||||||
- endpoints
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- discovery.k8s.io
|
|
||||||
resources:
|
|
||||||
- endpointslices
|
|
||||||
- endpointslices/restricted
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- deletecollection
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- gateways
|
|
||||||
- globalingressips
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- serviceimports
|
|
||||||
- serviceimports/status
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- update
|
|
||||||
- delete
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- serviceexports
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- serviceexports/status
|
|
||||||
verbs:
|
|
||||||
- update
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-agent
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- discovery.k8s.io
|
|
||||||
resources:
|
|
||||||
- endpointslices
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- submariner.io
|
|
||||||
resources:
|
|
||||||
- gateways
|
|
||||||
- submariners
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- multicluster.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- serviceimports
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: {{ template "submariner.fullname" . }}:lighthouse-coredns
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,119 +0,0 @@
|
|||||||
{{- if .Values.serviceAccounts.operator.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.operatorServiceAccountName" . }}-token
|
|
||||||
annotations:
|
|
||||||
kubernetes.io/service-account.name: {{ template "submariner.operatorServiceAccountName" . }}
|
|
||||||
type: kubernetes.io/service-account-token
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.gateway.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.gatewayServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.gatewayServiceAccountName" . }}-token
|
|
||||||
annotations:
|
|
||||||
kubernetes.io/service-account.name: {{ template "submariner.gatewayServiceAccountName" . }}
|
|
||||||
type: kubernetes.io/service-account-token
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}-token
|
|
||||||
annotations:
|
|
||||||
kubernetes.io/service-account.name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
|
||||||
type: kubernetes.io/service-account-token
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.globalnet.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.globalnetServiceAccountName" . }}-token
|
|
||||||
annotations:
|
|
||||||
kubernetes.io/service-account.name: {{ template "submariner.globalnetServiceAccountName" . }}
|
|
||||||
type: kubernetes.io/service-account-token
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.lighthouseAgent.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}-token
|
|
||||||
annotations:
|
|
||||||
kubernetes.io/service-account.name: {{ template "submariner.lighthouseAgentServiceAccountName" . }}
|
|
||||||
type: kubernetes.io/service-account-token
|
|
||||||
{{- end }}
|
|
||||||
---
|
|
||||||
{{- if .Values.serviceAccounts.lighthouseCoreDns.create }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
heritage: {{ .Release.Service | quote }}
|
|
||||||
release: {{ .Release.Name | quote }}
|
|
||||||
chart: {{ template "submariner.chart" . }}
|
|
||||||
app: {{ template "submariner.name" . }}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}-token
|
|
||||||
annotations:
|
|
||||||
kubernetes.io/service-account.name: {{ template "submariner.lighthouseCoreDnsServiceAccountName" . }}
|
|
||||||
type: kubernetes.io/service-account-token
|
|
||||||
{{- end }}
|
|
||||||
@@ -25,8 +25,6 @@ broker:
|
|||||||
insecure: false
|
insecure: false
|
||||||
ca: ""
|
ca: ""
|
||||||
globalnet: false
|
globalnet: false
|
||||||
rbac:
|
|
||||||
create: true
|
|
||||||
images: {}
|
images: {}
|
||||||
ipsec:
|
ipsec:
|
||||||
psk: ""
|
psk: ""
|
||||||
@@ -46,22 +44,3 @@ operator:
|
|||||||
resources: {}
|
resources: {}
|
||||||
tolerations: []
|
tolerations: []
|
||||||
affinity: {}
|
affinity: {}
|
||||||
serviceAccounts:
|
|
||||||
operator:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
gateway:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
routeAgent:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
globalnet:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
lighthouseAgent:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
lighthouseCoreDns:
|
|
||||||
create: true
|
|
||||||
name: ""
|
|
||||||
|
|||||||
@@ -0,0 +1,38 @@
|
|||||||
|
//go:build yamls
|
||||||
|
|
||||||
|
/*
|
||||||
|
SPDX-License-Identifier: Apache-2.0
|
||||||
|
|
||||||
|
Copyright Contributors to the Submariner project.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
|
*/
|
||||||
|
|
||||||
|
// Place any runtime dependencies as imports in this file.
|
||||||
|
// Go modules will be forced to download and install them.
|
||||||
|
|
||||||
|
package yamls
|
||||||
|
|
||||||
|
import (
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/broker/broker-client"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/openshift/rbac/submariner-metrics-reader"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-gateway"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-globalnet"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-operator"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/submariner-route-agent"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/lighthouse-agent"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/config/rbac/lighthouse-coredns"
|
||||||
|
_ "github.com/submariner-io/submariner-operator/deploy/crds"
|
||||||
|
_ "github.com/submariner-io/submariner/deploy/crds"
|
||||||
|
_ "sigs.k8s.io/mcs-api/config/crd"
|
||||||
|
)
|
||||||
Reference in New Issue
Block a user