Compare commits

..
Author SHA1 Message Date
Sridhar Gaddam 277d91969b Exclude openshift-monitoring namespace in Globalnet
In an OCP Cluster, openshift-monitoring namespace has couple of
services and these are controlled by their respective operators.
When Globalnet is deployed on OCP, it was seen that globalip
annotation added to such services are periodically getting
deleted by the operators, so Globalnet tries to re-add the
annotation and this goes on forever. This will cause Globalnet
to consume CPU unnecessarily and could affect user-experience
with Submariner Globalnet. We have plans to enhance Globalnet
to improve its scalability, but until then we can exclude
annotating services in openshift-monitoring namespace.

Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>
2020-11-06 12:06:41 +05:30
Vishal ThaparandThomas Pantelis c128fb42c5 Install MCS SIG CRDs and roles
This installs the `multicluster.x-k8s.io` CRDs and roles for them

Fixes:submariner-io/lighthouse#336

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2020-11-02 08:29:12 -05:00
Daniel FarrellandThomas Pantelis f92523dbb1 Run YAML linting also via GHA
YAML linting currently runs on Travis. Convert to a GHA, to align with
other repos and prepare for future optimizations.

Only run against values.yaml and Chart.yaml files, as is currently the
case in the Travis-driven workflow.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2020-10-21 13:46:48 -04:00
Daniel FarrellandThomas Pantelis 4461924636 Fix Markdown linting errros in README
Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2020-10-21 11:06:52 -04:00
Daniel FarrellandThomas Pantelis 3ac4e14664 Add Markdown linting
Add linting for Markdown files, following norms from other repos.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2020-10-21 11:06:52 -04:00
Daniel FarrellandThomas Pantelis 8c49e84959 Refactor periodic GHA
Convert MD-lint Workflow into general periodic Workflow.

Minor tweaks from refactoring in other repos.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2020-10-21 09:18:50 -04:00
Daniel FarrellandThomas Pantelis 5d4d921dbf Refactor linting GHAs
Combine linting GitHub Actions into a single Workflow.

Minor updates to reflect refactoring in other repos.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2020-10-21 09:18:50 -04:00
Nir YechielandGitHub 0dde6f2123 Add stalebot to charts repo (#64)
Signed-off-by: nyechiel <n.yechiel@gmail.com>
2020-09-29 09:51:54 -04:00
Vishal ThaparandThomas Pantelis 1e3737abd9 Add deletecollection verb for endpointslices
Refer: https://github.com/submariner-io/submariner-operator/pull/636

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2020-09-03 10:10:19 -04:00
Stephen KittandMiguel Angel Ajo Pelayo c4760944f9 Bump to 0.6.0
This changes the defaults to 0.6.0, pulling the images from our Quay
repository.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2020-08-31 12:14:39 +02:00
Daniel FarrellandThomas Pantelis bb60a9e87b Bump MD link check linter 0.6->1.*
Adds support for check-modified-files-only config, which currently isn't
honored and throws a warning.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2020-08-26 09:00:50 -04:00
Sridhar GaddamandMiguel Angel Ajo Pelayo d38625a9fd Modify updateStrategy for Route-agent Pods
Currently, the updateStrategy for Route-agent pods is set to RollingUpdate
with maxUnavailable as 1. Because of this, when the route-agent DaemonSet
is updated, the Pods are updated one after the other. While the rolling
update strategy is good for user-facing services, for route-agent DaemonSet
its not the most suitable one as it takes time for all the route-agent pods
to be updated in a large cluster.

Ideally, it would have been great if "Recreate" updateStrategy was supported
for DaemonSets, but unfortunately K8s does not support it. But an alternate
way to achieve something similar is to configure rollingUpdate.maxUnavailable
to 100% so that the DaemonSet controller can update all the route-agent Pods
in a single go.

https://kubernetes.io/docs/tasks/manage-daemon/update-daemon-set/#daemonset-update-strategy

Fixes issue: https://github.com/submariner-io/submariner/issues/734

Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>
2020-08-21 10:05:46 +02:00
Daniel FarrellandThomas Pantelis ae84a0b409 Add link aliveness tests
Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2020-08-20 14:36:53 -04:00
Stephen KittandMiguel Angel Ajo Pelayo 9d3a9b7f66 Rename "supercluster" to "clusterset"
The latter is the name chosen by the multi-cluster SIG.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2020-08-20 09:40:42 +02:00
Vishal ThaparandThomas Pantelis 8df47c6f85 Add roles for endpoints and endpointslices
* Add clusterrole to give lighthouse serviceaccount access to endpoints and
endpointslices
* Add role to give broker serviceaccont access to endpoint slices

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2020-08-07 07:54:15 -04:00
Vishal ThaparandThomas Pantelis fefd6b21ed Install gateway CRD on broker
If crd.create is set to false when installing submariner on same cluster
as broker, gateways CRD never gets installed because it is missing from
broker charts. This change is to install the CRD even on broker, as a
cleaner alternative to adding more flags.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2020-07-21 11:35:31 -04:00
Vishal ThaparandThomas Pantelis 1954770672 Allow lighthouse access to gateways.submariner.io
Adds following permissions to lighthouse clusterrole
for `gateways.submariner.io`
 - get
 - list
 - watch

This allows lighthouse to track changes to gateway status and know which
clusters are connected.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2020-07-20 11:16:04 -04:00
18 changed files with 340 additions and 40 deletions
+8
View File
@@ -0,0 +1,8 @@
---
name: Broken link detected by CI
labels: bug
---
<!-- Used by automation to raise an Issue when the periodic link aliveness tests detect a broken link. -->
Periodic link aliveness CI detected a broken link. Please see the job results for details.
+57
View File
@@ -0,0 +1,57 @@
---
# Configuration for probot-stale - https://github.com/probot/stale
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
daysUntilStale: 60
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
daysUntilClose: 7
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
onlyLabels: []
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
exemptLabels:
- security
- confirmed
# Set to true to ignore issues in a project (defaults to false)
exemptProjects: false
# Set to true to ignore issues in a milestone (defaults to false)
exemptMilestones: false
# Set to true to ignore issues with an assignee (defaults to false)
exemptAssignees: false
# Label to use when marking as stale
staleLabel: wontfix
# Comment to post when marking as stale. Set to `false` to disable
markComment: >
This issue has been automatically marked as stale because it has not had
activity for 60 days. It will be closed if no further activity occurs.
Please make a comment if this issue/pr is still valid. Thank you
for your contributions.
# Comment to post when removing the stale label.
# unmarkComment: >
# Your comment here.
# Comment to post when closing a stale Issue or Pull Request.
# closeComment: >
# Your comment here.
# Limit the number of actions per hour, from 1-30. Default is 30
limitPerRun: 30
# Limit to only `issues` or `pulls`
# only: issues
pulls:
daysUntilStale: 30
markComment: >
This pull request has been automatically marked as stale because it has not had
recent activity. It will be closed if no further activity occurs. Thank you
for your contributions.
-17
View File
@@ -1,17 +0,0 @@
name: DCO Check
on: pull_request
jobs:
dco:
runs-on: ubuntu-latest
name: DCO Check
steps:
- name: Get PR Commits
id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@master
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: DCO Check
uses: tim-actions/dco@master
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
+57
View File
@@ -0,0 +1,57 @@
---
name: Linting
on:
pull_request:
jobs:
dco:
name: DCO in Commit Message(s)
runs-on: ubuntu-latest
steps:
- name: Get PR commits
id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@master
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: Run DCO check
uses: tim-actions/dco@master
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
markdown-link-check:
name: Markdown Links (modified files)
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
- name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@v1
with:
config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes"
markdownlint:
name: Markdown
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
- name: Run markdownlint
uses: nosborn/github-action-markdown-cli@v1.1.1
with:
files: .
config_file: ".markdownlint.yml"
yaml-lint:
name: YAML
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
- name: Run yamllint
uses: ibiqlik/action-yamllint@v1
with:
file_or_dir: submariner/values.yaml submariner-k8s-broker/values.yaml submariner/Chart.yaml submariner-k8s-broker/Chart.yaml
config_file: .yamllint.yml
+27
View File
@@ -0,0 +1,27 @@
---
name: Periodic
on:
schedule:
- cron: "0 0 * * 0"
jobs:
markdown-link-check-periodic:
name: Markdown Links (all files)
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
- name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@v1
with:
config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links
if: ${{ failure() }}
uses: JasonEtco/create-an-issue@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
filename: .github/ISSUE_TEMPLATE/broken-link.md
+10
View File
@@ -0,0 +1,10 @@
{
"ignorePatterns": [
{
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
},
{
"pattern": "^http://localhost:"
}
]
}
+12
View File
@@ -0,0 +1,12 @@
---
# Breaks reusing MD snippets extracted to files
first-line-heading: false
# Set maximum line Length to 140c to match Go linting
line-length:
line_length: 140
# Allow HTML span elements to set font sizes
no-inline-html:
allowed_elements:
- span
+6 -6
View File
@@ -1,15 +1,15 @@
# submariner-charts # submariner-charts
Please see https://github.com/submariner-io/submariner for more information. This is only a supporting repository for Submariner Please see the [Helm docs on Submariner's website](https://submariner.io/deployment/helm/).
# Dev workflow. ## Dev workflow
### Prerequisites ### Prerequisites
- [helm] - [helm]
- [docker] or [podman] - [docker] or [podman]
### Create a fork and checkout. ### Create a fork and checkout
[Create a fork] of the original repository, clone it locally and checkout a new branch from master. [Create a fork] of the original repository, clone it locally and checkout a new branch from master.
@@ -31,13 +31,13 @@ Before serving the modified charts, the charts must be packaged for local usage.
helm package ./submariner helm package ./submariner
helm package ./submariner-k8s-broker helm package ./submariner-k8s-broker
``` ```
Note: if you just installed helm, you have to init the helm, by running Note: if you just installed helm, you have to init the helm, by running
```bash ```bash
helm init --client-only helm init --client-only
``` ```
Serve the packaged charts through a local helm repository: Serve the packaged charts through a local helm repository:
```bash ```bash
@@ -93,7 +93,7 @@ Search the new repo for submariner charts:
helm search -l test-repo helm search -l test-repo
``` ```
### Modify submariner e2e tests helm deployment script to use your local test-repo. ### Modify submariner e2e tests helm deployment script to use your local test-repo
You can test your helm-charts with e2e tests from the [shipyard](https://github.com/submariner-io/shipyard) repository. You can test your helm-charts with e2e tests from the [shipyard](https://github.com/submariner-io/shipyard) repository.
In the file `scripts/shared/lib/deploy_helm` change the line from: In the file `scripts/shared/lib/deploy_helm` change the line from:
+2 -2
View File
@@ -1,7 +1,7 @@
--- ---
name: submariner-k8s-broker name: submariner-k8s-broker
version: 0.4.1 version: 0.6.0
appVersion: 0.4.1 appVersion: 0.6.0
description: Submariner Kubernetes Broker description: Submariner Kubernetes Broker
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+75
View File
@@ -27,6 +27,25 @@ spec:
plural: endpoints plural: endpoints
scope: Namespaced scope: Namespaced
--- ---
apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition
metadata:
name: gateways.submariner.io
annotations:
"helm.sh/hook": crd-install
spec:
group: submariner.io
version: v1
names:
kind: Gateway
plural: gateways
scope: Namespaced
additionalPrinterColumns:
- name: ha-status
type: string
description: High Availability Status of the Gateway
JSONPath: .status.haStatus
---
{{- if .Values.submariner.serviceDiscovery }} {{- if .Values.submariner.serviceDiscovery }}
apiVersion: apiextensions.k8s.io/v1beta1 apiVersion: apiextensions.k8s.io/v1beta1
kind: CustomResourceDefinition kind: CustomResourceDefinition
@@ -87,5 +106,61 @@ spec:
plural: serviceimports plural: serviceimports
singular: serviceimport singular: serviceimport
scope: Namespaced scope: Namespaced
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: serviceexports.multicluster.x-k8s.io
annotations:
"helm.sh/hook": crd-install
spec:
group: multicluster.x-k8s.io
scope: Namespaced
names:
plural: serviceexports
singular: serviceexport
kind: ServiceExport
shortNames:
- svcex
versions:
- name: v1alpha1
served: true
storage: true
additionalPrinterColumns:
- name: Age
type: date
jsonPath: .metadata.creationTimestamp
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: serviceimports.multicluster.x-k8s.io
annotations:
"helm.sh/hook": crd-install
spec:
group: multicluster.x-k8s.io
scope: Namespaced
names:
plural: serviceimports
singular: serviceimport
kind: ServiceImport
shortNames:
- svcim
versions:
- name: v1alpha1
served: true
storage: true
additionalPrinterColumns:
- name: Type
type: string
description: The type of this ServiceImport
jsonPath: .spec.type
- name: IP
type: string
description: The VIP for this ServiceImport
jsonPath: .spec.ips
- name: Age
type: date
jsonPath: .metadata.creationTimestamp
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}
@@ -15,6 +15,12 @@ rules:
- apiGroups: ["lighthouse.submariner.io"] - apiGroups: ["lighthouse.submariner.io"]
resources: ["*"] resources: ["*"]
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"] verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
- apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices"]
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
- apiGroups: ["multicluster.x-k8s.io"]
resources: ["*"]
verbs: ["create", "get", "list", "watch", "update", "delete"]
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding kind: RoleBinding
+2 -2
View File
@@ -1,7 +1,7 @@
--- ---
name: submariner name: submariner
version: 0.4.0 version: 0.6.0
appVersion: 0.4.0 appVersion: 0.6.0
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords: keywords:
home: https://submariner-io.github.io/ home: https://submariner-io.github.io/
+4 -4
View File
@@ -8,12 +8,12 @@ questions:
group: "Container Images" group: "Container Images"
subquestions: subquestions:
- variable: engine.image.repository - variable: engine.image.repository
default: "rancher/submariner" default: "quay.io/submariner/submariner"
description: "Submariner Engine Image Repository" description: "Submariner Engine Image Repository"
type: string type: string
label: Submariner Engine Image Repository label: Submariner Engine Image Repository
- variable: engine.image.tag - variable: engine.image.tag
default: "v0.0.2" default: "0.6.0"
description: "Submariner Engine Image Tag" description: "Submariner Engine Image Tag"
type: string type: string
label: Submariner Engine Image Tag label: Submariner Engine Image Tag
@@ -26,12 +26,12 @@ questions:
group: "Container Images" group: "Container Images"
subquestions: subquestions:
- variable: routeAgent.image.repository - variable: routeAgent.image.repository
default: "rancher/submariner-route-agent" default: "quay.io/submariner/submariner-route-agent"
description: "Submariner Route Agent Image Repository" description: "Submariner Route Agent Image Repository"
type: string type: string
label: Submariner Route Agent Image Repository label: Submariner Route Agent Image Repository
- variable: routeAgent.image.tag - variable: routeAgent.image.tag
default: "v0.0.2" default: "0.6.0"
description: "Submariner Route Agent Image Tag" description: "Submariner Route Agent Image Tag"
type: string type: string
label: Submariner Route Agent Image Tag label: Submariner Route Agent Image Tag
+56
View File
@@ -106,5 +106,61 @@ spec:
plural: serviceimports plural: serviceimports
singular: serviceimport singular: serviceimport
scope: Namespaced scope: Namespaced
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: serviceexports.multicluster.x-k8s.io
annotations:
"helm.sh/hook": crd-install
spec:
group: multicluster.x-k8s.io
scope: Namespaced
names:
plural: serviceexports
singular: serviceexport
kind: ServiceExport
shortNames:
- svcex
versions:
- name: v1alpha1
served: true
storage: true
additionalPrinterColumns:
- name: Age
type: date
jsonPath: .metadata.creationTimestamp
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: serviceimports.multicluster.x-k8s.io
annotations:
"helm.sh/hook": crd-install
spec:
group: multicluster.x-k8s.io
scope: Namespaced
names:
plural: serviceimports
singular: serviceimport
kind: ServiceImport
shortNames:
- svcim
versions:
- name: v1alpha1
served: true
storage: true
additionalPrinterColumns:
- name: Type
type: string
description: The type of this ServiceImport
jsonPath: .spec.type
- name: IP
type: string
description: The VIP for this ServiceImport
jsonPath: .spec.ips
- name: Age
type: date
jsonPath: .metadata.creationTimestamp
{{- end }} {{- end }}
{{- end -}} {{- end -}}
+1 -1
View File
@@ -36,7 +36,7 @@ spec:
- name: SUBMARINER_CLUSTERID - name: SUBMARINER_CLUSTERID
value: '{{ .Values.submariner.clusterId }}' value: '{{ .Values.submariner.clusterId }}'
- name: SUBMARINER_EXCLUDENS - name: SUBMARINER_EXCLUDENS
value: 'submariner-operator,kube-system,operators' value: 'submariner-operator,kube-system,operators,openshift-monitoring'
- name: SUBMARINER_NAMESPACE - name: SUBMARINER_NAMESPACE
value: '{{ .Release.Namespace }}' value: '{{ .Release.Namespace }}'
securityContext: securityContext:
+1 -1
View File
@@ -62,7 +62,7 @@ metadata:
name: {{ template "submariner.lighthouseDnsName" . }} name: {{ template "submariner.lighthouseDnsName" . }}
data: data:
Corefile: | Corefile: |
supercluster.local:53 { clusterset.local:53 {
{{- if .Values.submariner.debug }} {{- if .Values.submariner.debug }}
log log
{{- end }} {{- end }}
+10 -1
View File
@@ -118,11 +118,20 @@ metadata:
name: {{ template "submariner.fullname" . }}:lighthouse name: {{ template "submariner.fullname" . }}:lighthouse
rules: rules:
- apiGroups: [""] - apiGroups: [""]
resources: ["services", "namespaces", "configmaps"] resources: ["services", "namespaces", "configmaps", "endpoints"]
verbs: ["get", "list", "watch", "update"] verbs: ["get", "list", "watch", "update"]
- apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices"]
verbs: ["create", "get", "list", "watch", "update", "delete", "deletecollection"]
- apiGroups: ["lighthouse.submariner.io"] - apiGroups: ["lighthouse.submariner.io"]
resources: ["*"] resources: ["*"]
verbs: ["create", "get", "list", "watch", "update", "delete"] verbs: ["create", "get", "list", "watch", "update", "delete"]
- apiGroups: ["submariner.io"]
resources: ["gateways"]
verbs: ["get", "list", "watch"]
- apiGroups: ["multicluster.x-k8s.io"]
resources: ["*"]
verbs: ["create", "get", "list", "watch", "update", "delete"]
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
+1 -1
View File
@@ -14,7 +14,7 @@ spec:
app: {{ template "submariner.fullname" . }}-routeagent app: {{ template "submariner.fullname" . }}-routeagent
updateStrategy: updateStrategy:
rollingUpdate: rollingUpdate:
maxUnavailable: 1 maxUnavailable: "100%"
type: RollingUpdate type: RollingUpdate
template: template:
metadata: metadata: