mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-20 21:30:35 +00:00
Compare commits
252
Commits
v0.8.1
...
v0.20.0-rc1
@@ -1,8 +1,2 @@
|
||||
---
|
||||
name: Broken link detected by CI
|
||||
labels: bug
|
||||
---
|
||||
|
||||
<!-- Used by automation to raise an Issue when the periodic link aliveness tests detect a broken link. -->
|
||||
|
||||
Periodic link aliveness CI detected a broken link. Please see the job results for details.
|
||||
Periodic link aliveness CI detected a broken link. Please see the [periodic job
|
||||
results](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic) for details.
|
||||
|
||||
@@ -23,11 +23,9 @@ Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
|
||||
**Anything else we need to know?**:
|
||||
|
||||
**Environment**:
|
||||
- Submariner version (use `subctl version`):
|
||||
- Kubernetes version (use `kubectl version`):
|
||||
- Diagnose information (use `subctl diagnose all`):
|
||||
- Gather information (use `subctl gather`):
|
||||
- Cloud provider or hardware configuration:
|
||||
- OS (e.g: `cat /etc/os-release`):
|
||||
- Kernel (e.g. `uname -a`):
|
||||
- Install tools:
|
||||
- Network plugin and version (if this is a network-related bug):
|
||||
- Others:
|
||||
|
||||
@@ -6,7 +6,7 @@ labels: support
|
||||
---
|
||||
|
||||
<!--
|
||||
GitHub may not the right place for support requests.
|
||||
GitHub may not be the right place for support requests.
|
||||
|
||||
You can also post your question on the [Submariner
|
||||
Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
<!-- Thanks for sending a pull request! Here are some tips for you:
|
||||
|
||||
1. If this is your first time, please read our developer guide: https://submariner.io/development/
|
||||
2. Ensure you have added the appropriate tests for your PR: https://submariner.io/development/code-review/#test-new-functionality
|
||||
3. Read the code review guide to ease the review process: https://submariner.io/development/code-review/
|
||||
4. If the PR is unfinished, mark it as a draft: https://submariner.io/development/code-review/#mark-work-in-progress-prs-as-drafts
|
||||
5. If you are using CI to debug, use your private fork: https://submariner.io/development/code-review/#use-private-forks-for-debugging-prs-by-running-ci
|
||||
6. Add labels to the PR as appropriate.
|
||||
|
||||
This template is based on the K8s/K8s template:
|
||||
|
||||
https://github.com/kubernetes/kubernetes/blob/master/.github/PULL_REQUEST_TEMPLATE.md
|
||||
-->
|
||||
@@ -0,0 +1,47 @@
|
||||
---
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.15"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.16"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.17"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
- package-ecosystem: github-actions
|
||||
directory: '/'
|
||||
target-branch: "release-0.18"
|
||||
schedule:
|
||||
interval: monthly
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
@@ -1,57 +0,0 @@
|
||||
---
|
||||
# Configuration for probot-stale - https://github.com/probot/stale
|
||||
|
||||
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
|
||||
daysUntilStale: 60
|
||||
|
||||
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
|
||||
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
|
||||
daysUntilClose: 7
|
||||
|
||||
# Only issues or pull requests with all of these labels are check if stale. Defaults to `[]` (disabled)
|
||||
onlyLabels: []
|
||||
|
||||
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
|
||||
exemptLabels:
|
||||
- security
|
||||
- confirmed
|
||||
|
||||
# Set to true to ignore issues in a project (defaults to false)
|
||||
exemptProjects: false
|
||||
|
||||
# Set to true to ignore issues in a milestone (defaults to false)
|
||||
exemptMilestones: false
|
||||
|
||||
# Set to true to ignore issues with an assignee (defaults to false)
|
||||
exemptAssignees: false
|
||||
|
||||
# Label to use when marking as stale
|
||||
staleLabel: wontfix
|
||||
|
||||
# Comment to post when marking as stale. Set to `false` to disable
|
||||
markComment: >
|
||||
This issue has been automatically marked as stale because it has not had
|
||||
activity for 60 days. It will be closed if no further activity occurs.
|
||||
Please make a comment if this issue/pr is still valid. Thank you
|
||||
for your contributions.
|
||||
|
||||
# Comment to post when removing the stale label.
|
||||
# unmarkComment: >
|
||||
# Your comment here.
|
||||
|
||||
# Comment to post when closing a stale Issue or Pull Request.
|
||||
# closeComment: >
|
||||
# Your comment here.
|
||||
|
||||
# Limit the number of actions per hour, from 1-30. Default is 30
|
||||
limitPerRun: 30
|
||||
|
||||
# Limit to only `issues` or `pulls`
|
||||
# only: issues
|
||||
|
||||
pulls:
|
||||
daysUntilStale: 30
|
||||
markComment: >
|
||||
This pull request has been automatically marked as stale because it has not had
|
||||
recent activity. It will be closed if no further activity occurs. Thank you
|
||||
for your contributions.
|
||||
@@ -0,0 +1,16 @@
|
||||
---
|
||||
name: Branch Checks
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
target_branch:
|
||||
name: PR targets branch
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check that the PR targets release-0.20
|
||||
if: ${{ github.base_ref != 'release-0.20' }}
|
||||
run: exit 1
|
||||
@@ -0,0 +1,44 @@
|
||||
---
|
||||
name: PR Dependencies
|
||||
|
||||
on:
|
||||
issues:
|
||||
types:
|
||||
- opened
|
||||
- edited
|
||||
- closed
|
||||
- reopened
|
||||
- synchronize
|
||||
pull_request_target:
|
||||
types:
|
||||
- opened
|
||||
- edited
|
||||
- closed
|
||||
- reopened
|
||||
- synchronize
|
||||
schedule:
|
||||
- cron: '0 0/6 * * *' # every 6 hours
|
||||
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
statuses: write
|
||||
|
||||
jobs:
|
||||
check:
|
||||
name: Check Dependencies
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: z0al/dependent-issues@950226e7ca8fc43dc209a7febf67c655af3bdb43
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
with:
|
||||
# The label to use to mark dependent issues
|
||||
label: dependent
|
||||
|
||||
# Enable checking for dependencies in issues.
|
||||
check_issues: on
|
||||
|
||||
# A comma-separated list of keywords to mark dependency.
|
||||
keywords: depends on, Depends on
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
name: End to End Full
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [labeled, opened, synchronize, reopened]
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
if: contains(github.event.pull_request.labels.*.name, 'ready-to-test')
|
||||
timeout-minutes: 45
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
# Run most tests against the latest K8s version
|
||||
k8s_version: ['1.31']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
include:
|
||||
# Bottom of supported K8s version range
|
||||
- k8s_version: '1.28'
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.20
|
||||
with:
|
||||
k8s_version: ${{ matrix.k8s_version }}
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.20
|
||||
@@ -1,34 +1,23 @@
|
||||
---
|
||||
name: End to End Tests
|
||||
name: End to End Default
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
timeout-minutes: 30
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Reclaim free space
|
||||
run: |
|
||||
sudo swapoff -a
|
||||
sudo rm -f /swapfile
|
||||
df -h
|
||||
free -h
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
run: |
|
||||
make e2e
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.20
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
run: |
|
||||
df -h
|
||||
free -h
|
||||
make post-mortem
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.20
|
||||
|
||||
@@ -0,0 +1,33 @@
|
||||
---
|
||||
name: Flake Finder
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "0 0 * * *"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
timeout-minutes: 30
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.20
|
||||
with:
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.20
|
||||
@@ -4,54 +4,110 @@ name: Linting
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
dco:
|
||||
name: DCO in Commit Message(s)
|
||||
apply-suggestions-commits:
|
||||
name: 'No "Apply suggestions from code review" Commits'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Get PR commits
|
||||
id: 'get-pr-commits'
|
||||
uses: tim-actions/get-pr-commits@master
|
||||
uses: tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
- name: Run DCO check
|
||||
uses: tim-actions/dco@master
|
||||
|
||||
- name: 'Verify no "Apply suggestions from code review" commits'
|
||||
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
||||
with:
|
||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||
pattern: '^(?!.*(apply suggestions from code review))'
|
||||
flags: 'i'
|
||||
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
||||
|
||||
- name: 'Verify no "fixup!" commits'
|
||||
uses: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791
|
||||
with:
|
||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||
pattern: '^(?!fixup!)'
|
||||
flags: 'i'
|
||||
error: 'Fixup commits should be squashed into the commits under review'
|
||||
|
||||
chart-testing:
|
||||
name: Helm Chart Linting
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814
|
||||
with:
|
||||
version: v3.6.0
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38
|
||||
with:
|
||||
python-version: '3.x'
|
||||
|
||||
- name: Set up helm/chart-testing
|
||||
uses: helm/chart-testing-action@0d28d3144d3a25ea2cc349d6e59901c4ff469b3b
|
||||
|
||||
- name: Set up local helm repo
|
||||
run: make local-helm-repo
|
||||
|
||||
- name: Run helm/chart-testing (lint)
|
||||
run: ct lint --config ct.yaml
|
||||
|
||||
gitlint:
|
||||
name: Commit Message(s)
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Run gitlint
|
||||
run: make gitlint
|
||||
|
||||
helm-docs:
|
||||
name: Helm Docs Generation
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
- name: Run helm-docs and verify docs are up-to-date
|
||||
run: make helm-docs
|
||||
|
||||
markdown-link-check:
|
||||
name: Markdown Links (modified files)
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
check-modified-files-only: "yes"
|
||||
base-branch: ${{ github.base_ref }}
|
||||
|
||||
markdownlint:
|
||||
name: Markdown
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
- name: Run markdownlint
|
||||
uses: nosborn/github-action-markdown-cli@v1.1.1
|
||||
with:
|
||||
files: .
|
||||
config_file: ".markdownlint.yml"
|
||||
run: make markdownlint
|
||||
|
||||
yaml-lint:
|
||||
name: YAML
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
- name: Run yamllint
|
||||
uses: ibiqlik/action-yamllint@v1
|
||||
with:
|
||||
file_or_dir: submariner/Chart.yaml submariner/values.yaml submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
|
||||
config_file: .yamllint.yml
|
||||
run: make yamllint
|
||||
|
||||
@@ -5,23 +5,28 @@ on:
|
||||
schedule:
|
||||
- cron: "0 0 * * 0"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
markdown-link-check-periodic:
|
||||
name: Markdown Links (all files)
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
|
||||
- name: Raise an Issue to report broken links
|
||||
if: ${{ failure() }}
|
||||
uses: JasonEtco/create-an-issue@v2
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
uses: peter-evans/create-issue-from-file@e8ef132d6df98ed982188e460ebb3b5d4ef3a9cd
|
||||
with:
|
||||
filename: .github/ISSUE_TEMPLATE/broken-link.md
|
||||
title: Broken link detected by CI
|
||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||
labels: automated, broken link
|
||||
|
||||
@@ -4,15 +4,19 @@ name: Release Charts
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
- release-0.20
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Release
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
---
|
||||
name: Stale
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "0 0 * * *"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
name: Close Stale Issues and PRs
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
steps:
|
||||
- uses: actions/stale@ee7ef89499a3de6e4fe1fc1acb994e67c64e0a2a
|
||||
with:
|
||||
days-before-issue-stale: 120
|
||||
days-before-pr-stale: 14
|
||||
exempt-issue-labels: 'confirmed,security'
|
||||
exempt-pr-labels: 'confirmed,security'
|
||||
stale-issue-label: 'stale'
|
||||
stale-issue-message: |
|
||||
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||
activity occurs. Thank you for your contributions.
|
||||
stale-pr-label: 'stale'
|
||||
stale-pr-message: |
|
||||
This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further
|
||||
activity occurs. Thank you for your contributions.
|
||||
+12
-1
@@ -1,2 +1,13 @@
|
||||
.dapper
|
||||
.idea
|
||||
*.tgz
|
||||
.shflags
|
||||
*.tgz
|
||||
Makefile.dapper
|
||||
Makefile.shipyard
|
||||
Dockerfile.*
|
||||
helm_repo
|
||||
yamls
|
||||
submariner-k8s-broker/crds/crd.yaml
|
||||
submariner-k8s-broker/templates/_role.tpl
|
||||
submariner-operator/crds/crd.yaml
|
||||
submariner-operator/templates/*-rbac.yaml
|
||||
|
||||
@@ -1,10 +1,16 @@
|
||||
{
|
||||
"ignorePatterns": [
|
||||
{
|
||||
"pattern": "^https://docs.github.com"
|
||||
},
|
||||
{
|
||||
"pattern": "^https://github.com/\\S+/\\S+/(issues|pull)/[0-9]+"
|
||||
},
|
||||
{
|
||||
"pattern": "^http://localhost:"
|
||||
},
|
||||
{
|
||||
"pattern": "^https://submariner-io.github.io/submariner-charts/charts"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -10,3 +10,7 @@ line-length:
|
||||
no-inline-html:
|
||||
allowed_elements:
|
||||
- span
|
||||
|
||||
# Temporary while helm-docs has a bug where maintainer URLs are used raw in MD
|
||||
# Waiting on: https://github.com/norwoodj/helm-docs/pull/102
|
||||
no-bare-urls: false
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
---
|
||||
cni: ovn
|
||||
submariner: true
|
||||
nodes: control-plane
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
submariner: true
|
||||
nodes: control-plane
|
||||
clusters:
|
||||
cluster1:
|
||||
cluster2:
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
label-approved:
|
||||
approvals: 2
|
||||
label: ready-to-test
|
||||
+11
-11
@@ -1,15 +1,15 @@
|
||||
---
|
||||
extends: default
|
||||
|
||||
rules:
|
||||
comments: disable
|
||||
comments-indentation: disable
|
||||
line-length:
|
||||
max: 150
|
||||
braces:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 0
|
||||
brackets:
|
||||
min-spaces-inside: 0
|
||||
max-spaces-inside: 0
|
||||
indentation:
|
||||
indent-sequences: consistent
|
||||
max: 140
|
||||
# Allow standard GHA syntax for "on: *"
|
||||
truthy:
|
||||
ignore: '.github/workflows/*.yml'
|
||||
|
||||
ignore: |
|
||||
/submariner-k8s-broker/crds
|
||||
/submariner-operator/crds
|
||||
/submariner-k8s-broker/templates
|
||||
/submariner-operator/templates
|
||||
|
||||
+1
-1
@@ -1,3 +1,3 @@
|
||||
# Code of Conduct
|
||||
|
||||
Please see the [Code of Conduct docs on Submariner's website](https://submariner.io/contributing/code-of-conduct/).
|
||||
Please see the [Code of Conduct docs on Submariner's website](https://submariner.io/community/code-of-conduct/).
|
||||
|
||||
+4
-1
@@ -1 +1,4 @@
|
||||
* @mangelajo @Oats87 @skitt @tpantelis
|
||||
# Auto-generated, do not edit; see CODEOWNERS.in
|
||||
* @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||
*.md @dfarrell07 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar
|
||||
Makefile @aswinsuryan @dfarrell07 @maayanf24 @Oats87 @skitt @sridhargaddam @tpantelis @vthapar @yboaron
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
@aswinsuryan Makefile
|
||||
@dfarrell07 *.md Makefile
|
||||
@maayanf24 Makefile
|
||||
@Oats87 *
|
||||
@skitt *
|
||||
@sridhargaddam *
|
||||
@tpantelis *
|
||||
@vthapar *
|
||||
@yboaron Makefile
|
||||
+1
-1
@@ -1,3 +1,3 @@
|
||||
# Contributing
|
||||
|
||||
Please see the [Contributing docs on Submariner's website](https://submariner.io/for_developers/).
|
||||
Please see the [Development docs on Submariner's website](https://submariner.io/development/).
|
||||
|
||||
@@ -1,15 +0,0 @@
|
||||
FROM quay.io/submariner/shipyard-dapper-base:devel
|
||||
|
||||
ARG DAPPER_HOST_ARCH
|
||||
ENV HOST_ARCH=${DAPPER_HOST_ARCH} ARCH=${DAPPER_HOST_ARCH} \
|
||||
DAPPER_ENV="REPO TAG QUAY_USERNAME QUAY_PASSWORD GITHUB_SHA MAKEFLAGS CLUSTERS_ARGS DEPLOY_ARGS E2E_ARGS RELEASE_ARGS" \
|
||||
DAPPER_SOURCE=/go/src/github.com/submariner-io/submariner-charts DAPPER_DOCKER_SOCKET=true
|
||||
ENV DAPPER_OUTPUT=${DAPPER_SOURCE}/output PATH=${DAPPER_SOURCE}/bin/:${PATH}
|
||||
|
||||
WORKDIR ${DAPPER_SOURCE}
|
||||
|
||||
# Override the Helm deployment scripts
|
||||
COPY deploy_helm /opt/shipyard/scripts/lib/
|
||||
|
||||
ENTRYPOINT ["/opt/shipyard/scripts/entry"]
|
||||
CMD ["sh"]
|
||||
@@ -1,38 +1,61 @@
|
||||
BASE_BRANCH ?= release-0.20
|
||||
export BASE_BRANCH
|
||||
export HELM_REPO_LOCATION=./helm_repo
|
||||
|
||||
ifneq (,$(DAPPER_HOST_ARCH))
|
||||
|
||||
# Running in Dapper
|
||||
|
||||
include $(SHIPYARD_DIR)/Makefile.inc
|
||||
|
||||
CLUSTER_SETTINGS_FLAG = --cluster_settings $(DAPPER_SOURCE)/cluster_settings
|
||||
override CLUSTERS_ARGS += $(CLUSTER_SETTINGS_FLAG)
|
||||
override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm --deploytool_broker_args '--set submariner.serviceDiscovery=true'
|
||||
export DEPLOY_ARGS
|
||||
ifneq (,$(filter ovn,$(_using)))
|
||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.ovn.yml
|
||||
else
|
||||
export SETTINGS = $(DAPPER_SOURCE)/.shipyard.e2e.yml
|
||||
endif
|
||||
|
||||
export DEPLOYTOOL = helm
|
||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||
CHARTS_DIR=charts
|
||||
CHARTS_VERSION=0.7.0
|
||||
CHARTS_VERSION=0.20.0-rc1
|
||||
HELM_DOCS_VERSION=0.15.0
|
||||
REPO_URL=$(shell git config remote.origin.url)
|
||||
|
||||
# Targets to make
|
||||
|
||||
deploy: clusters preload-images
|
||||
CHART_PACKAGES := submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||
|
||||
e2e: E2E_ARGS=cluster1 cluster2
|
||||
|
||||
preload-images:
|
||||
source $(SCRIPTS_DIR)/lib/debug_functions; \
|
||||
source $(SCRIPTS_DIR)/lib/deploy_funcs; \
|
||||
source $(SCRIPTS_DIR)/lib/version; \
|
||||
set -e; \
|
||||
for image in submariner submariner-route-agent submariner-operator lighthouse-agent submariner-globalnet lighthouse-coredns; do \
|
||||
import_image quay.io/submariner/$${image}; \
|
||||
local-helm-repo: $(CHART_PACKAGES)
|
||||
mkdir -p $(HELM_REPO_LOCATION)
|
||||
for archive in $^; do \
|
||||
tar xzf $$archive -C $(HELM_REPO_LOCATION); \
|
||||
done
|
||||
|
||||
%.tgz:
|
||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
e2e: local-helm-repo
|
||||
$(SCRIPTS_DIR)/e2e.sh
|
||||
|
||||
release: submariner-$(CHARTS_VERSION).tgz submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||
generate-yamls:
|
||||
./generate-yamls.sh $(BASE_BRANCH)
|
||||
|
||||
%.tgz: generate-yamls
|
||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
helm package --version $(CHARTS_VERSION) --app-version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
|
||||
helm-docs:
|
||||
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
||||
cd /tmp && \
|
||||
curl -sL https://github.com/norwoodj/helm-docs/releases/download/v$(HELM_DOCS_VERSION)/helm-docs_$(HELM_DOCS_VERSION)_Linux_x86_64.tar.gz | tar zx && \
|
||||
cd -
|
||||
/tmp/helm-docs
|
||||
if [ ! -z $(git status --porcelain) ]; then \
|
||||
echo "Helm docs not up-to-date:"; \
|
||||
git status --porcelain; \
|
||||
git diff; \
|
||||
echo "Run make helm-docs locally to generate updated docs, commit the updates."; \
|
||||
exit 1; \
|
||||
fi
|
||||
|
||||
release: $(CHART_PACKAGES)
|
||||
git checkout gh-pages
|
||||
mv *.tgz $(CHARTS_DIR)
|
||||
if [ -f $(CHARTS_DIR)/index.yaml ]; then \
|
||||
@@ -41,15 +64,19 @@ release: submariner-$(CHARTS_VERSION).tgz submariner-k8s-broker-$(CHARTS_VERSION
|
||||
helm repo index $(CHARTS_DIR) --url $(GH_URL); \
|
||||
fi
|
||||
|
||||
.PHONY: preload-images release
|
||||
.PHONY: release helm-docs
|
||||
|
||||
else
|
||||
|
||||
# Not running in Dapper
|
||||
|
||||
Makefile.dapper:
|
||||
@echo Downloading $@
|
||||
@curl -sfLO https://raw.githubusercontent.com/submariner-io/shipyard/$(BASE_BRANCH)/$@
|
||||
|
||||
include Makefile.dapper
|
||||
|
||||
endif
|
||||
|
||||
# Disable rebuilding Makefile
|
||||
Makefile Makefile.dapper Makefile.inc: ;
|
||||
Makefile Makefile.inc: ;
|
||||
|
||||
@@ -1,26 +0,0 @@
|
||||
# This Makefile contains the rules required to set up our
|
||||
# Dapper-based build environment; it can be copied as-is to
|
||||
# other projects (and needs to be copied, it can't be shared
|
||||
# via the Dapper image since it's needed to retrieve the image)
|
||||
|
||||
.dapper:
|
||||
@echo Downloading dapper
|
||||
@curl -sL https://releases.rancher.com/dapper/latest/dapper-`uname -s`-`uname -m` > .dapper.tmp
|
||||
@@chmod +x .dapper.tmp
|
||||
@./.dapper.tmp -v
|
||||
@mv .dapper.tmp .dapper
|
||||
|
||||
invoke_dapper = +./.dapper -m bind make -- $1
|
||||
|
||||
%: .dapper
|
||||
@echo Invoking Dapper, MAKEFLAGS=$(MAKEFLAGS)
|
||||
$(call invoke_dapper,$@)
|
||||
|
||||
# Ensure that files in the current directory don't hide Dapper targets
|
||||
$(wildcard [^M]*): .dapper
|
||||
$(call invoke_dapper,$@)
|
||||
|
||||
shell: .dapper
|
||||
./.dapper -m bind -s
|
||||
|
||||
.PHONY: shell $(wildcard [^M]*)
|
||||
@@ -1,5 +1,12 @@
|
||||
# submariner-charts
|
||||
|
||||
<!-- markdownlint-disable line-length -->
|
||||
[](https://bestpractices.coreinfrastructure.org/projects/4865)
|
||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Release+Charts%22)
|
||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic)
|
||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Flake+Finder%22)
|
||||
<!-- markdownlint-enable line-length -->
|
||||
|
||||
Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/).
|
||||
|
||||
## Development workflow
|
||||
@@ -53,4 +60,4 @@ working correctly.
|
||||
[Helm]: https://helm.sh/docs/using_helm/#installing-helm
|
||||
[Docker]: https://docs.docker.com/install/
|
||||
[Podman]: https://podman.io/getting-started/installation
|
||||
[Create a fork]: https://help.github.com/en/articles/fork-a-repo
|
||||
[Create a fork]: https://docs.github.com/en/get-started/quickstart/fork-a-repo
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
. "${SCRIPTS_DIR}"/lib/source_only
|
||||
|
||||
# We need a minimal setup to verify the deployment works
|
||||
clusters=('cluster1' 'cluster2')
|
||||
cluster_nodes['cluster1']="control-plane worker"
|
||||
cluster_nodes['cluster2']="control-plane worker"
|
||||
|
||||
cluster_cni=( ['cluster1']="weave" ['cluster2']="weave" )
|
||||
|
||||
cluster_subm=( ['cluster1']="true" ['cluster2']="true" )
|
||||
@@ -0,0 +1,7 @@
|
||||
---
|
||||
charts:
|
||||
- ./helm_repo/submariner-operator
|
||||
- ./helm_repo/submariner-k8s-broker
|
||||
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
||||
# See: https://github.com/helm/chart-testing/issues/192
|
||||
validate-maintainers: false
|
||||
-72
@@ -1,72 +0,0 @@
|
||||
# shellcheck shell=bash
|
||||
# shellcheck source=scripts/shared/lib/source_only
|
||||
. "${BASH_SOURCE%/*}"/source_only
|
||||
|
||||
### Constants ###
|
||||
|
||||
readonly SUBMARINER_BROKER_NS=submariner-k8s-broker
|
||||
readonly SUBMARINER_PSK=$(LC_CTYPE=C tr -dc 'a-zA-Z0-9' < /dev/urandom | fold -w 64 | head -n 1)
|
||||
|
||||
### Functions ###
|
||||
|
||||
function deploytool_prereqs() {
|
||||
helm version
|
||||
}
|
||||
|
||||
function setup_broker() {
|
||||
if kubectl get crd clusters.submariner.io > /dev/null 2>&1; then
|
||||
echo "Submariner CRDs already exist, skipping broker creation..."
|
||||
else
|
||||
echo "Installing submariner broker..."
|
||||
# shellcheck disable=SC2086 # Split on purpose
|
||||
helm install "${SUBMARINER_BROKER_NS}" ./submariner-k8s-broker \
|
||||
--create-namespace \
|
||||
--kube-context "${cluster}" \
|
||||
--namespace "${SUBMARINER_BROKER_NS}" \
|
||||
${deploytool_broker_args}
|
||||
fi
|
||||
|
||||
submariner_broker_url=$(kubectl -n default get endpoints kubernetes -o jsonpath="{.subsets[0].addresses[0].ip}:{.subsets[0].ports[?(@.name=='https')].port}")
|
||||
submariner_broker_ca=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data['ca\.crt']}")
|
||||
submariner_broker_token=$(kubectl -n "${SUBMARINER_BROKER_NS}" get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='${SUBMARINER_BROKER_NS}-client')].data.token}"|base64 --decode)
|
||||
}
|
||||
|
||||
function helm_install_subm() {
|
||||
local crd_create=false
|
||||
[[ "${cluster}" = "${broker}" ]] || crd_create=true
|
||||
|
||||
if kubectl wait --for=condition=Ready pods -l app=submariner-operator -n "${SUBM_NS}" --timeout=60s > /dev/null 2>&1; then
|
||||
echo "Submariner already installed, skipping installation..."
|
||||
return
|
||||
fi
|
||||
|
||||
echo "Installing Submariner..."
|
||||
# shellcheck disable=SC2086 # Split on purpose
|
||||
helm --kube-context "${cluster}" install submariner-operator \
|
||||
./submariner-operator \
|
||||
--create-namespace \
|
||||
--namespace "${SUBM_NS}" \
|
||||
--set ipsec.psk="${SUBMARINER_PSK}" \
|
||||
--set broker.server="${submariner_broker_url}" \
|
||||
--set broker.token="${submariner_broker_token}" \
|
||||
--set broker.namespace="${SUBMARINER_BROKER_NS}" \
|
||||
--set broker.ca="${submariner_broker_ca}" \
|
||||
--set submariner.cableDriver="${cable_driver}" \
|
||||
--set submariner.clusterId="${cluster}" \
|
||||
--set submariner.clusterCidr="${cluster_CIDRs[$cluster]}" \
|
||||
--set submariner.serviceCidr="${service_CIDRs[$cluster]}" \
|
||||
--set submariner.globalCidr="${global_CIDRs[$cluster]}" \
|
||||
--set serviceAccounts.globalnet.create="${globalnet}" \
|
||||
--set submariner.natEnabled="false" \
|
||||
--set operator.image.repository="localhost:5000/submariner-operator" \
|
||||
--set operator.image.tag="local" \
|
||||
--set operator.image.pullPolicy="IfNotPresent" \
|
||||
--set submariner.images.repository="localhost:5000" \
|
||||
--set submariner.images.tag="local" \
|
||||
--set brokercrds.create="${crd_create}" \
|
||||
${deploytool_submariner_args}
|
||||
}
|
||||
|
||||
function install_subm_all_clusters() {
|
||||
run_subm_clusters helm_install_subm
|
||||
}
|
||||
Executable
+21
@@ -0,0 +1,21 @@
|
||||
#!/usr/bin/awk -f
|
||||
|
||||
# Start of a file entry
|
||||
/= `/ {
|
||||
outfile = gensub("_yaml$", ".yaml", "1", $1)
|
||||
print "Writing " outfile
|
||||
firstline = substr($0, index($0, "`") + 1)
|
||||
if (firstline !~ "^---")
|
||||
firstline = "---\n"firstline
|
||||
print firstline > outfile
|
||||
next
|
||||
}
|
||||
|
||||
/^`$/ {
|
||||
outfile = ""
|
||||
next
|
||||
}
|
||||
|
||||
outfile != "" {
|
||||
print >> outfile
|
||||
}
|
||||
Executable
+90
@@ -0,0 +1,90 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
BROKER_ROLE_TPL=submariner-k8s-broker/templates/_role.tpl
|
||||
OPERATOR_RBAC_YAML=submariner-operator/templates/operator-rbac.yaml
|
||||
GATEWAY_RBAC_YAML=submariner-operator/templates/gateway-rbac.yaml
|
||||
ROUTE_AGENT_RBAC_YAML=submariner-operator/templates/routeagent-rbac.yaml
|
||||
GLOBALNET_RBAC_YAML=submariner-operator/templates/globalnet-rbac.yaml
|
||||
SERVICE_DISC_RBAC_YAML=submariner-operator/templates/service-discovery-rbac.yaml
|
||||
OPENSHIFT_MONITORING_YAML=submariner-operator/templates/openshift-monitoring-rbac.yaml
|
||||
|
||||
function add_service_acct_ns() {
|
||||
sed -i '/- kind: ServiceAccount/a \ \ \ \ namespace: {{ .Release.Namespace }}' $1
|
||||
}
|
||||
|
||||
mkdir -p yamls
|
||||
cd yamls
|
||||
curl -L https://raw.githubusercontent.com/submariner-io/submariner-operator/refs/heads/$1/pkg/embeddedyamls/yamls.go | ../extract-yamls
|
||||
cd -
|
||||
|
||||
# Generate the CRDs for the broker chart
|
||||
mkdir -p submariner-k8s-broker/crds
|
||||
cat yamls/Deploy_submariner_crds_submariner_io_endpoints.yaml \
|
||||
yamls/Deploy_submariner_crds_submariner_io_clusters.yaml \
|
||||
yamls/Deploy_submariner_crds_submariner_io_gateways.yaml \
|
||||
yamls/Deploy_mcsapi_crds_multicluster_x_k8s_io_serviceexports.yaml \
|
||||
yamls/Deploy_mcsapi_crds_multicluster_x_k8s_io_serviceimports.yaml > submariner-k8s-broker/crds/crd.yaml
|
||||
|
||||
# Generate the client role yaml for the broker chart
|
||||
echo '{{- define "broker-role" -}}' > ${BROKER_ROLE_TPL}
|
||||
cat yamls/Config_broker_broker_client_role.yaml >> ${BROKER_ROLE_TPL}
|
||||
echo '{{- end -}}' >> ${BROKER_ROLE_TPL}
|
||||
sed -i -e 's/name:.*/name: {{ template "submariner-k8s-broker.fullname" \. }}-cluster/' ${BROKER_ROLE_TPL}
|
||||
|
||||
# Generate the CRDs for the operator chart
|
||||
mkdir -p submariner-operator/crds
|
||||
cat yamls/Deploy_crds_submariner_io_submariners.yaml \
|
||||
yamls/Deploy_crds_submariner_io_servicediscoveries.yaml \
|
||||
yamls/Deploy_crds_submariner_io_brokers.yaml > submariner-operator/crds/crd.yaml
|
||||
|
||||
# Generate the operator RBAC yaml for the operator chart
|
||||
add_service_acct_ns yamls/Config_rbac_submariner_operator_cluster_role_binding.yaml
|
||||
cat yamls/Config_rbac_submariner_operator_service_account.yaml \
|
||||
yamls/Config_rbac_submariner_operator_role.yaml \
|
||||
yamls/Config_rbac_submariner_operator_role_binding.yaml \
|
||||
yamls/Config_rbac_submariner_operator_cluster_role.yaml \
|
||||
yamls/Config_rbac_submariner_operator_cluster_role_binding.yaml > ${OPERATOR_RBAC_YAML}
|
||||
|
||||
# Generate the gateway RBAC yaml for the operator chart
|
||||
add_service_acct_ns yamls/Config_rbac_submariner_gateway_cluster_role_binding.yaml
|
||||
cat yamls/Config_rbac_submariner_gateway_service_account.yaml \
|
||||
yamls/Config_rbac_submariner_gateway_role.yaml \
|
||||
yamls/Config_rbac_submariner_gateway_role_binding.yaml \
|
||||
yamls/Config_rbac_submariner_gateway_cluster_role.yaml \
|
||||
yamls/Config_rbac_submariner_gateway_cluster_role_binding.yaml > ${GATEWAY_RBAC_YAML}
|
||||
|
||||
# Generate the routeagent RBAC yaml for the operator chart
|
||||
add_service_acct_ns yamls/Config_rbac_submariner_route_agent_cluster_role_binding.yaml
|
||||
cat yamls/Config_rbac_submariner_route_agent_service_account.yaml \
|
||||
yamls/Config_rbac_submariner_route_agent_role.yaml \
|
||||
yamls/Config_rbac_submariner_route_agent_role_binding.yaml \
|
||||
yamls/Config_rbac_submariner_route_agent_cluster_role.yaml \
|
||||
yamls/Config_rbac_submariner_route_agent_cluster_role_binding.yaml > ${ROUTE_AGENT_RBAC_YAML}
|
||||
|
||||
# Generate the globalnet RBAC yaml for the operator chart
|
||||
echo '{{- if .Values.broker.globalnet }}' > ${GLOBALNET_RBAC_YAML}
|
||||
add_service_acct_ns yamls/Config_rbac_submariner_globalnet_cluster_role_binding.yaml
|
||||
cat yamls/Config_rbac_submariner_globalnet_service_account.yaml \
|
||||
yamls/Config_rbac_submariner_globalnet_role.yaml \
|
||||
yamls/Config_rbac_submariner_globalnet_role_binding.yaml \
|
||||
yamls/Config_rbac_submariner_globalnet_cluster_role.yaml \
|
||||
yamls/Config_rbac_submariner_globalnet_cluster_role_binding.yaml >> ${GLOBALNET_RBAC_YAML}
|
||||
echo '{{- end -}}' >> ${GLOBALNET_RBAC_YAML}
|
||||
|
||||
# Generate the service discovery RBAC yaml for the operator chart
|
||||
echo '{{- if .Values.submariner.serviceDiscovery }}' > ${SERVICE_DISC_RBAC_YAML}
|
||||
add_service_acct_ns yamls/Config_rbac_lighthouse_agent_cluster_role_binding.yaml
|
||||
add_service_acct_ns yamls/Config_rbac_lighthouse_coredns_cluster_role_binding.yaml
|
||||
cat yamls/Config_rbac_lighthouse_agent_service_account.yaml \
|
||||
yamls/Config_rbac_lighthouse_agent_cluster_role.yaml \
|
||||
yamls/Config_rbac_lighthouse_agent_cluster_role_binding.yaml \
|
||||
yamls/Config_rbac_lighthouse_coredns_service_account.yaml \
|
||||
yamls/Config_rbac_lighthouse_coredns_cluster_role.yaml \
|
||||
yamls/Config_rbac_lighthouse_coredns_cluster_role_binding.yaml >> ${SERVICE_DISC_RBAC_YAML}
|
||||
echo '{{- end -}}' >> ${SERVICE_DISC_RBAC_YAML}
|
||||
|
||||
# Generate the openshift monitoring rbac yaml for the operator chart
|
||||
cat yamls/Config_openshift_rbac_submariner_metrics_reader_role.yaml \
|
||||
yamls/Config_openshift_rbac_submariner_metrics_reader_role_binding.yaml > ${OPENSHIFT_MONITORING_YAML}
|
||||
@@ -1,12 +1,13 @@
|
||||
---
|
||||
name: submariner-k8s-broker
|
||||
version: 0.6.0
|
||||
appVersion: 0.6.0
|
||||
version: 0.0.0
|
||||
apiVersion: v2
|
||||
description: Submariner Kubernetes Broker
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
sources:
|
||||
- https://submariner-io.github.io/submariner-charts/charts
|
||||
- https://submariner-io.github.io/submariner-charts/charts
|
||||
maintainers:
|
||||
- name: Submariner Developers
|
||||
email: submariner-dev@googlegroups.com
|
||||
- name: Contributors to the Submariner project
|
||||
email: submariner-dev@googlegroups.com
|
||||
url: https://submariner.io/
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
# submariner-k8s-broker
|
||||
|
||||
Submariner Kubernetes Broker
|
||||
|
||||
**Homepage:** <https://submariner-io.github.io/>
|
||||
|
||||
## Maintainers
|
||||
|
||||
| Name | Email | Url |
|
||||
| ---- | ------ | --- |
|
||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
||||
|
||||
## Source Code
|
||||
|
||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
||||
@@ -1,324 +0,0 @@
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: clusters.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Cluster
|
||||
plural: clusters
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: endpoints.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Endpoint
|
||||
plural: endpoints
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: gateways.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Gateway
|
||||
plural: gateways
|
||||
scope: Namespaced
|
||||
additionalPrinterColumns:
|
||||
- name: ha-status
|
||||
type: string
|
||||
description: High Availability Status of the Gateway
|
||||
JSONPath: .status.haStatus
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: multiclusterservices.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: MultiClusterService
|
||||
plural: multiclusterservices
|
||||
singular: multiclusterservice
|
||||
scope: Namespaced
|
||||
validation:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
spec:
|
||||
properties:
|
||||
clusterServiceInfo:
|
||||
properties:
|
||||
clusterID:
|
||||
type: "string"
|
||||
clusterDomain:
|
||||
type: "string"
|
||||
serviceIP:
|
||||
type: "string"
|
||||
port:
|
||||
type: "integer"
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceexports.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v2alpha1
|
||||
names:
|
||||
kind: ServiceExport
|
||||
plural: serviceexports
|
||||
singular: serviceexport
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceimports.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v2alpha1
|
||||
names:
|
||||
kind: ServiceImport
|
||||
plural: serviceimports
|
||||
singular: serviceimport
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceexports.multicluster.x-k8s.io
|
||||
spec:
|
||||
group: multicluster.x-k8s.io
|
||||
scope: Namespaced
|
||||
names:
|
||||
plural: serviceexports
|
||||
singular: serviceexport
|
||||
kind: ServiceExport
|
||||
shortNames:
|
||||
- svcex
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
additionalPrinterColumns:
|
||||
- name: Age
|
||||
type: date
|
||||
jsonPath: .metadata.creationTimestamp
|
||||
"schema":
|
||||
"openAPIV3Schema":
|
||||
description: ServiceExport declares that the Service with the same name and
|
||||
namespace as this export should be consumable from other clusters.
|
||||
type: object
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
status:
|
||||
description: status describes the current state of an exported service.
|
||||
Service configuration comes from the Service that had the same name
|
||||
and namespace as this ServiceExport. Populated by the multi-cluster
|
||||
service implementation's controller.
|
||||
type: object
|
||||
properties:
|
||||
conditions:
|
||||
type: array
|
||||
items:
|
||||
description: "ServiceExportCondition contains details for the current
|
||||
condition of this service export. \n Once [KEP-1623](https://github.com/kubernetes/enhancements/tree/master/keps/sig-api-machinery/1623-standardize-conditions)
|
||||
is implemented, this will be replaced by metav1.Condition."
|
||||
type: object
|
||||
required:
|
||||
- status
|
||||
- type
|
||||
properties:
|
||||
lastTransitionTime:
|
||||
type: string
|
||||
format: date-time
|
||||
message:
|
||||
type: string
|
||||
reason:
|
||||
type: string
|
||||
status:
|
||||
description: Status is one of {"True", "False", "Unknown"}
|
||||
type: string
|
||||
enum:
|
||||
- "True"
|
||||
- "False"
|
||||
- Unknown
|
||||
type:
|
||||
description: ServiceExportConditionType identifies a specific
|
||||
condition.
|
||||
type: string
|
||||
x-kubernetes-list-map-keys:
|
||||
- type
|
||||
x-kubernetes-list-type: map
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceimports.multicluster.x-k8s.io
|
||||
spec:
|
||||
group: multicluster.x-k8s.io
|
||||
scope: Namespaced
|
||||
names:
|
||||
plural: serviceimports
|
||||
singular: serviceimport
|
||||
kind: ServiceImport
|
||||
shortNames:
|
||||
- svcim
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
additionalPrinterColumns:
|
||||
- name: Type
|
||||
type: string
|
||||
description: The type of this ServiceImport
|
||||
jsonPath: .spec.type
|
||||
- name: IP
|
||||
type: string
|
||||
description: The VIP for this ServiceImport
|
||||
jsonPath: .spec.ips
|
||||
- name: Age
|
||||
type: date
|
||||
jsonPath: .metadata.creationTimestamp
|
||||
"schema":
|
||||
"openAPIV3Schema":
|
||||
description: ServiceImport describes a service imported from clusters in a
|
||||
ClusterSet.
|
||||
type: object
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
description: spec defines the behavior of a ServiceImport.
|
||||
type: object
|
||||
required:
|
||||
- ports
|
||||
- type
|
||||
properties:
|
||||
ips:
|
||||
description: ip will be used as the VIP for this service when type
|
||||
is ClusterSetIP.
|
||||
type: array
|
||||
maxItems: 1
|
||||
items:
|
||||
type: string
|
||||
ports:
|
||||
type: array
|
||||
items:
|
||||
description: ServicePort represents the port on which the service
|
||||
is exposed
|
||||
type: object
|
||||
required:
|
||||
- port
|
||||
properties:
|
||||
appProtocol:
|
||||
description: The application protocol for this port. This field
|
||||
follows standard Kubernetes label syntax. Un-prefixed names
|
||||
are reserved for IANA standard service names (as per RFC-6335
|
||||
and http://www.iana.org/assignments/service-names). Non-standard
|
||||
protocols should use prefixed names such as mycompany.com/my-custom-protocol.
|
||||
Field can be enabled with ServiceAppProtocol feature gate.
|
||||
type: string
|
||||
name:
|
||||
description: The name of this port within the service. This
|
||||
must be a DNS_LABEL. All ports within a ServiceSpec must have
|
||||
unique names. When considering the endpoints for a Service,
|
||||
this must match the 'name' field in the EndpointPort. Optional
|
||||
if only one ServicePort is defined on this service.
|
||||
type: string
|
||||
port:
|
||||
description: The port that will be exposed by this service.
|
||||
type: integer
|
||||
format: int32
|
||||
protocol:
|
||||
description: The IP protocol for this port. Supports "TCP",
|
||||
"UDP", and "SCTP". Default is TCP.
|
||||
type: string
|
||||
x-kubernetes-list-type: atomic
|
||||
sessionAffinity:
|
||||
description: 'Supports "ClientIP" and "None". Used to maintain session
|
||||
affinity. Enable client IP based session affinity. Must be ClientIP
|
||||
or None. Defaults to None. Ignored when type is Headless More info:
|
||||
https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies'
|
||||
type: string
|
||||
sessionAffinityConfig:
|
||||
description: sessionAffinityConfig contains session affinity configuration.
|
||||
type: object
|
||||
properties:
|
||||
clientIP:
|
||||
description: clientIP contains the configurations of Client IP
|
||||
based session affinity.
|
||||
type: object
|
||||
properties:
|
||||
timeoutSeconds:
|
||||
description: timeoutSeconds specifies the seconds of ClientIP
|
||||
type session sticky time. The value must be >0 && <=86400(for
|
||||
1 day) if ServiceAffinity == "ClientIP". Default value is
|
||||
10800(for 3 hours).
|
||||
type: integer
|
||||
format: int32
|
||||
type:
|
||||
description: type defines the type of this service. Must be ClusterSetIP
|
||||
or Headless.
|
||||
type: string
|
||||
enum:
|
||||
- ClusterSetIP
|
||||
- Headless
|
||||
status:
|
||||
description: status contains information about the exported services that
|
||||
form the multi-cluster service referenced by this ServiceImport.
|
||||
type: object
|
||||
properties:
|
||||
clusters:
|
||||
description: clusters is the list of exporting clusters from which
|
||||
this service was derived.
|
||||
type: array
|
||||
items:
|
||||
description: ClusterStatus contains service configuration mapped
|
||||
to a specific source cluster
|
||||
type: object
|
||||
required:
|
||||
- cluster
|
||||
properties:
|
||||
cluster:
|
||||
description: cluster is the name of the exporting cluster. Must
|
||||
be a valid RFC-1123 DNS label.
|
||||
type: string
|
||||
x-kubernetes-list-map-keys:
|
||||
- cluster
|
||||
x-kubernetes-list-type: map
|
||||
@@ -1,19 +0,0 @@
|
||||
questions:
|
||||
- variable: submariner-k8s-broker.rbac.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Role Based Access Control"
|
||||
description: "Create the role/rolebinding for the Submariner client"
|
||||
label: "RBAC Creation Enabled"
|
||||
- variable: submariner-k8s-broker.crd.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Submariner CRD"
|
||||
description: "Create the submariner CRDs for the Submariner client"
|
||||
label: "Submariner CRD Creation Enabled"
|
||||
- variable: submariner-k8s-broker.serviceAccounts.client.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Service Account"
|
||||
description: "Create the service account for the Submariner client"
|
||||
label: "Submariner Service Account Creation Enabled"
|
||||
@@ -6,5 +6,5 @@ You can retrieve the server URL by running
|
||||
|
||||
The broker client token and CA can be retrieved by running
|
||||
|
||||
$ SUBMARINER_BROKER_CA=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data['ca\.crt']}")
|
||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n {{ .Release.Namespace }} get secrets -o jsonpath="{.items[?(@.metadata.annotations['kubernetes\.io/service-account\.name']=='{{ template "submariner-k8s-broker.clientServiceAccountName" . }}')].data.token}"|base64 --decode)
|
||||
$ SUBMARINER_BROKER_CA=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data['ca\.crt']}")
|
||||
$ SUBMARINER_BROKER_TOKEN=$(kubectl -n "${BROKER_NS}" get secrets "${BROKER_NS}-client-token" -o jsonpath="{.data.token}"|base64 --decode)
|
||||
|
||||
@@ -35,9 +35,5 @@ Create chart name and version as used by the chart label.
|
||||
Create the name of the submariner-client service account to use
|
||||
*/}}
|
||||
{{- define "submariner-k8s-broker.clientServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.client.create -}}
|
||||
{{ default (printf "%s-client" (include "submariner-k8s-broker.fullname" .)) .Values.serviceAccounts.client.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.client.name }}
|
||||
{{- end -}}
|
||||
{{- printf "%s-client" (include "submariner-k8s-broker.fullname" .)}}
|
||||
{{- end -}}
|
||||
@@ -1,37 +1,14 @@
|
||||
{{- if .Values.rbac.create -}}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||
app: {{ template "submariner-k8s-broker.name" . }}
|
||||
rules:
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
- apiGroups: ["lighthouse.submariner.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
- apiGroups: ["discovery.k8s.io"]
|
||||
resources: ["endpointslices"]
|
||||
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
|
||||
- apiGroups: ["multicluster.x-k8s.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||
{{ include "broker-role" $ }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end -}}
|
||||
@@ -1,4 +1,3 @@
|
||||
{{- if .Values.serviceAccounts.client.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
@@ -8,4 +7,11 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner-k8s-broker.chart" . }}
|
||||
app: {{ template "submariner-k8s-broker.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}-token
|
||||
annotations:
|
||||
kubernetes.io/service-account.name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||
type: kubernetes.io/service-account-token
|
||||
|
||||
@@ -1,11 +1 @@
|
||||
---
|
||||
rbac:
|
||||
create: true
|
||||
crd:
|
||||
create: true
|
||||
serviceAccounts:
|
||||
client:
|
||||
create: true
|
||||
name: ""
|
||||
submariner:
|
||||
serviceDiscovery: false
|
||||
|
||||
@@ -1,12 +1,13 @@
|
||||
---
|
||||
name: submariner-operator
|
||||
version: 0.7.0
|
||||
appVersion: 0.7.0
|
||||
version: 0.0.0
|
||||
apiVersion: v2
|
||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
sources:
|
||||
- https://submariner-io.github.io/submariner-charts/charts
|
||||
maintainers:
|
||||
- name: Submariner Developers
|
||||
- name: Contributors to the Submariner project
|
||||
email: submariner-dev@googlegroups.com
|
||||
url: https://submariner.io/
|
||||
|
||||
@@ -0,0 +1,56 @@
|
||||
# submariner-operator
|
||||
|
||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
|
||||
**Homepage:** <https://submariner-io.github.io/>
|
||||
|
||||
## Maintainers
|
||||
|
||||
| Name | Email | Url |
|
||||
| ---- | ------ | --- |
|
||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
||||
|
||||
## Source Code
|
||||
|
||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
||||
|
||||
## Values
|
||||
|
||||
| Key | Type | Default | Description |
|
||||
|-----|------|---------|-------------|
|
||||
| broker.ca | string | `""` | |
|
||||
| broker.globalnet | bool | `false` | |
|
||||
| broker.insecure | bool | `false` | |
|
||||
| broker.namespace | string | `"xyz"` | |
|
||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
||||
| broker.token | string | `"test"` | |
|
||||
| ipsec.debug | bool | `false` | |
|
||||
| ipsec.forceUDPEncaps | bool | `false` | |
|
||||
| ipsec.ikePort | int | `500` | |
|
||||
| ipsec.natPort | int | `4500` | |
|
||||
| ipsec.psk | string | `""` | |
|
||||
| leadership.leaseDuration | int | `10` | |
|
||||
| leadership.renewDeadline | int | `5` | |
|
||||
| leadership.retryPeriod | int | `2` | |
|
||||
| operator.affinity | object | `{}` | |
|
||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
||||
| operator.image.tag | string | `"0.14.0"` | |
|
||||
| operator.resources | object | `{}` | |
|
||||
| operator.tolerations | list | `[]` | |
|
||||
| submariner.cableDriver | string | `"libreswan"` | |
|
||||
| submariner.clusterCidr | string | `""` | |
|
||||
| submariner.clusterId | string | `""` | |
|
||||
| submariner.colorCodes | string | `"blue"` | |
|
||||
| submariner.coreDNSCustomConfig | object | `{}` | |
|
||||
| submariner.debug | bool | `false` | |
|
||||
| submariner.globalCidr | string | `""` | |
|
||||
| submariner.clustersetIpCidr | string | `""` | |
|
||||
| submariner.clustersetIpEnabled | bool | `false` | |
|
||||
| submariner.healthcheckEnabled | bool | `true` | |
|
||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||
| submariner.images.tag | string | `"0.14.0"` | |
|
||||
| submariner.natEnabled | bool | `false` | |
|
||||
| submariner.serviceCidr | string | `""` | |
|
||||
| submariner.serviceDiscovery | bool | `true` | |
|
||||
| submariner.token | string | `""` | |
|
||||
@@ -1,722 +0,0 @@
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: submariners.submariner.io
|
||||
annotations:
|
||||
controller-gen.kubebuilder.io/version: v0.3.0
|
||||
spec:
|
||||
group: submariner.io
|
||||
names:
|
||||
kind: Submariner
|
||||
listKind: SubmarinerList
|
||||
plural: submariners
|
||||
singular: submariner
|
||||
scope: Namespaced
|
||||
subresources:
|
||||
status: {}
|
||||
validation:
|
||||
openAPIV3Schema:
|
||||
description: Submariner is the Schema for the submariners API
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
description: SubmarinerSpec defines the desired state of Submariner
|
||||
properties:
|
||||
broker:
|
||||
type: string
|
||||
brokerK8sApiServer:
|
||||
type: string
|
||||
brokerK8sApiServerToken:
|
||||
type: string
|
||||
brokerK8sCA:
|
||||
type: string
|
||||
brokerK8sRemoteNamespace:
|
||||
type: string
|
||||
cableDriver:
|
||||
type: string
|
||||
ceIPSecDebug:
|
||||
type: boolean
|
||||
ceIPSecIKEPort:
|
||||
type: integer
|
||||
ceIPSecNATTPort:
|
||||
type: integer
|
||||
ceIPSecPSK:
|
||||
type: string
|
||||
clusterCIDR:
|
||||
type: string
|
||||
clusterID:
|
||||
type: string
|
||||
colorCodes:
|
||||
type: string
|
||||
customDomains:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
x-kubernetes-list-type: set
|
||||
debug:
|
||||
type: boolean
|
||||
globalCIDR:
|
||||
type: string
|
||||
namespace:
|
||||
type: string
|
||||
natEnabled:
|
||||
type: boolean
|
||||
repository:
|
||||
type: string
|
||||
serviceCIDR:
|
||||
type: string
|
||||
serviceDiscoveryEnabled:
|
||||
type: boolean
|
||||
version:
|
||||
type: string
|
||||
required:
|
||||
- broker
|
||||
- brokerK8sApiServer
|
||||
- brokerK8sApiServerToken
|
||||
- brokerK8sCA
|
||||
- brokerK8sRemoteNamespace
|
||||
- ceIPSecDebug
|
||||
- ceIPSecPSK
|
||||
- clusterCIDR
|
||||
- clusterID
|
||||
- debug
|
||||
- namespace
|
||||
- natEnabled
|
||||
- serviceCIDR
|
||||
type: object
|
||||
status:
|
||||
description: SubmarinerStatus defines the observed state of Submariner
|
||||
properties:
|
||||
clusterCIDR:
|
||||
type: string
|
||||
clusterID:
|
||||
type: string
|
||||
colorCodes:
|
||||
type: string
|
||||
engineDaemonSetStatus:
|
||||
properties:
|
||||
lastResourceVersion:
|
||||
type: string
|
||||
mismatchedContainerImages:
|
||||
type: boolean
|
||||
nonReadyContainerStates:
|
||||
items:
|
||||
description: ContainerState holds a possible state of container.
|
||||
Only one of its members may be specified. If none of them is
|
||||
specified, the default one is ContainerStateWaiting.
|
||||
properties:
|
||||
running:
|
||||
description: Details about a running container
|
||||
properties:
|
||||
startedAt:
|
||||
description: Time at which the container was last (re-)started
|
||||
format: date-time
|
||||
type: string
|
||||
type: object
|
||||
terminated:
|
||||
description: Details about a terminated container
|
||||
properties:
|
||||
containerID:
|
||||
description: Container's ID in the format 'docker://<container_id>'
|
||||
type: string
|
||||
exitCode:
|
||||
description: Exit status from the last termination of
|
||||
the container
|
||||
format: int32
|
||||
type: integer
|
||||
finishedAt:
|
||||
description: Time at which the container last terminated
|
||||
format: date-time
|
||||
type: string
|
||||
message:
|
||||
description: Message regarding the last termination of
|
||||
the container
|
||||
type: string
|
||||
reason:
|
||||
description: (brief) reason from the last termination
|
||||
of the container
|
||||
type: string
|
||||
signal:
|
||||
description: Signal from the last termination of the container
|
||||
format: int32
|
||||
type: integer
|
||||
startedAt:
|
||||
description: Time at which previous execution of the container
|
||||
started
|
||||
format: date-time
|
||||
type: string
|
||||
required:
|
||||
- exitCode
|
||||
type: object
|
||||
waiting:
|
||||
description: Details about a waiting container
|
||||
properties:
|
||||
message:
|
||||
description: Message regarding why the container is not
|
||||
yet running.
|
||||
type: string
|
||||
reason:
|
||||
description: (brief) reason the container is not yet running.
|
||||
type: string
|
||||
type: object
|
||||
type: object
|
||||
type: array
|
||||
status:
|
||||
description: DaemonSetStatus represents the current status of a
|
||||
daemon set.
|
||||
properties:
|
||||
collisionCount:
|
||||
description: Count of hash collisions for the DaemonSet. The
|
||||
DaemonSet controller uses this field as a collision avoidance
|
||||
mechanism when it needs to create the name for the newest
|
||||
ControllerRevision.
|
||||
format: int32
|
||||
type: integer
|
||||
conditions:
|
||||
description: Represents the latest available observations of
|
||||
a DaemonSet's current state.
|
||||
items:
|
||||
description: DaemonSetCondition describes the state of a DaemonSet
|
||||
at a certain point.
|
||||
properties:
|
||||
lastTransitionTime:
|
||||
description: Last time the condition transitioned from
|
||||
one status to another.
|
||||
format: date-time
|
||||
type: string
|
||||
message:
|
||||
description: A human readable message indicating details
|
||||
about the transition.
|
||||
type: string
|
||||
reason:
|
||||
description: The reason for the condition's last transition.
|
||||
type: string
|
||||
status:
|
||||
description: Status of the condition, one of True, False,
|
||||
Unknown.
|
||||
type: string
|
||||
type:
|
||||
description: Type of DaemonSet condition.
|
||||
type: string
|
||||
required:
|
||||
- status
|
||||
- type
|
||||
type: object
|
||||
type: array
|
||||
currentNumberScheduled:
|
||||
description: 'The number of nodes that are running at least
|
||||
1 daemon pod and are supposed to run the daemon pod. More
|
||||
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
desiredNumberScheduled:
|
||||
description: 'The total number of nodes that should be running
|
||||
the daemon pod (including nodes correctly running the daemon
|
||||
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
numberAvailable:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and available (ready for at least spec.minReadySeconds)
|
||||
format: int32
|
||||
type: integer
|
||||
numberMisscheduled:
|
||||
description: 'The number of nodes that are running the daemon
|
||||
pod, but are not supposed to run the daemon pod. More info:
|
||||
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
numberReady:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and ready.
|
||||
format: int32
|
||||
type: integer
|
||||
numberUnavailable:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have none of the daemon pod running and available
|
||||
(ready for at least spec.minReadySeconds)
|
||||
format: int32
|
||||
type: integer
|
||||
observedGeneration:
|
||||
description: The most recent generation observed by the daemon
|
||||
set controller.
|
||||
format: int64
|
||||
type: integer
|
||||
updatedNumberScheduled:
|
||||
description: The total number of nodes that are running updated
|
||||
daemon pod
|
||||
format: int32
|
||||
type: integer
|
||||
required:
|
||||
- currentNumberScheduled
|
||||
- desiredNumberScheduled
|
||||
- numberMisscheduled
|
||||
- numberReady
|
||||
type: object
|
||||
required:
|
||||
- mismatchedContainerImages
|
||||
type: object
|
||||
gateways:
|
||||
items:
|
||||
properties:
|
||||
connections:
|
||||
items:
|
||||
properties:
|
||||
endpoint:
|
||||
properties:
|
||||
backend:
|
||||
type: string
|
||||
backend_config:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
cable_name:
|
||||
type: string
|
||||
cluster_id:
|
||||
type: string
|
||||
hostname:
|
||||
type: string
|
||||
nat_enabled:
|
||||
type: boolean
|
||||
private_ip:
|
||||
type: string
|
||||
public_ip:
|
||||
type: string
|
||||
subnets:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
required:
|
||||
- backend
|
||||
- cable_name
|
||||
- cluster_id
|
||||
- hostname
|
||||
- nat_enabled
|
||||
- private_ip
|
||||
- public_ip
|
||||
- subnets
|
||||
type: object
|
||||
status:
|
||||
type: string
|
||||
statusMessage:
|
||||
type: string
|
||||
required:
|
||||
- endpoint
|
||||
- status
|
||||
- statusMessage
|
||||
type: object
|
||||
type: array
|
||||
haStatus:
|
||||
type: string
|
||||
localEndpoint:
|
||||
properties:
|
||||
backend:
|
||||
type: string
|
||||
backend_config:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
cable_name:
|
||||
type: string
|
||||
cluster_id:
|
||||
type: string
|
||||
hostname:
|
||||
type: string
|
||||
nat_enabled:
|
||||
type: boolean
|
||||
private_ip:
|
||||
type: string
|
||||
public_ip:
|
||||
type: string
|
||||
subnets:
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
required:
|
||||
- backend
|
||||
- cable_name
|
||||
- cluster_id
|
||||
- hostname
|
||||
- nat_enabled
|
||||
- private_ip
|
||||
- public_ip
|
||||
- subnets
|
||||
type: object
|
||||
statusFailure:
|
||||
type: string
|
||||
version:
|
||||
type: string
|
||||
required:
|
||||
- connections
|
||||
- haStatus
|
||||
- localEndpoint
|
||||
- statusFailure
|
||||
- version
|
||||
type: object
|
||||
type: array
|
||||
globalCIDR:
|
||||
type: string
|
||||
globalnetDaemonSetStatus:
|
||||
properties:
|
||||
lastResourceVersion:
|
||||
type: string
|
||||
mismatchedContainerImages:
|
||||
type: boolean
|
||||
nonReadyContainerStates:
|
||||
items:
|
||||
description: ContainerState holds a possible state of container.
|
||||
Only one of its members may be specified. If none of them is
|
||||
specified, the default one is ContainerStateWaiting.
|
||||
properties:
|
||||
running:
|
||||
description: Details about a running container
|
||||
properties:
|
||||
startedAt:
|
||||
description: Time at which the container was last (re-)started
|
||||
format: date-time
|
||||
type: string
|
||||
type: object
|
||||
terminated:
|
||||
description: Details about a terminated container
|
||||
properties:
|
||||
containerID:
|
||||
description: Container's ID in the format 'docker://<container_id>'
|
||||
type: string
|
||||
exitCode:
|
||||
description: Exit status from the last termination of
|
||||
the container
|
||||
format: int32
|
||||
type: integer
|
||||
finishedAt:
|
||||
description: Time at which the container last terminated
|
||||
format: date-time
|
||||
type: string
|
||||
message:
|
||||
description: Message regarding the last termination of
|
||||
the container
|
||||
type: string
|
||||
reason:
|
||||
description: (brief) reason from the last termination
|
||||
of the container
|
||||
type: string
|
||||
signal:
|
||||
description: Signal from the last termination of the container
|
||||
format: int32
|
||||
type: integer
|
||||
startedAt:
|
||||
description: Time at which previous execution of the container
|
||||
started
|
||||
format: date-time
|
||||
type: string
|
||||
required:
|
||||
- exitCode
|
||||
type: object
|
||||
waiting:
|
||||
description: Details about a waiting container
|
||||
properties:
|
||||
message:
|
||||
description: Message regarding why the container is not
|
||||
yet running.
|
||||
type: string
|
||||
reason:
|
||||
description: (brief) reason the container is not yet running.
|
||||
type: string
|
||||
type: object
|
||||
type: object
|
||||
type: array
|
||||
status:
|
||||
description: DaemonSetStatus represents the current status of a
|
||||
daemon set.
|
||||
properties:
|
||||
collisionCount:
|
||||
description: Count of hash collisions for the DaemonSet. The
|
||||
DaemonSet controller uses this field as a collision avoidance
|
||||
mechanism when it needs to create the name for the newest
|
||||
ControllerRevision.
|
||||
format: int32
|
||||
type: integer
|
||||
conditions:
|
||||
description: Represents the latest available observations of
|
||||
a DaemonSet's current state.
|
||||
items:
|
||||
description: DaemonSetCondition describes the state of a DaemonSet
|
||||
at a certain point.
|
||||
properties:
|
||||
lastTransitionTime:
|
||||
description: Last time the condition transitioned from
|
||||
one status to another.
|
||||
format: date-time
|
||||
type: string
|
||||
message:
|
||||
description: A human readable message indicating details
|
||||
about the transition.
|
||||
type: string
|
||||
reason:
|
||||
description: The reason for the condition's last transition.
|
||||
type: string
|
||||
status:
|
||||
description: Status of the condition, one of True, False,
|
||||
Unknown.
|
||||
type: string
|
||||
type:
|
||||
description: Type of DaemonSet condition.
|
||||
type: string
|
||||
required:
|
||||
- status
|
||||
- type
|
||||
type: object
|
||||
type: array
|
||||
currentNumberScheduled:
|
||||
description: 'The number of nodes that are running at least
|
||||
1 daemon pod and are supposed to run the daemon pod. More
|
||||
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
desiredNumberScheduled:
|
||||
description: 'The total number of nodes that should be running
|
||||
the daemon pod (including nodes correctly running the daemon
|
||||
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
numberAvailable:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and available (ready for at least spec.minReadySeconds)
|
||||
format: int32
|
||||
type: integer
|
||||
numberMisscheduled:
|
||||
description: 'The number of nodes that are running the daemon
|
||||
pod, but are not supposed to run the daemon pod. More info:
|
||||
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
numberReady:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and ready.
|
||||
format: int32
|
||||
type: integer
|
||||
numberUnavailable:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have none of the daemon pod running and available
|
||||
(ready for at least spec.minReadySeconds)
|
||||
format: int32
|
||||
type: integer
|
||||
observedGeneration:
|
||||
description: The most recent generation observed by the daemon
|
||||
set controller.
|
||||
format: int64
|
||||
type: integer
|
||||
updatedNumberScheduled:
|
||||
description: The total number of nodes that are running updated
|
||||
daemon pod
|
||||
format: int32
|
||||
type: integer
|
||||
required:
|
||||
- currentNumberScheduled
|
||||
- desiredNumberScheduled
|
||||
- numberMisscheduled
|
||||
- numberReady
|
||||
type: object
|
||||
required:
|
||||
- mismatchedContainerImages
|
||||
type: object
|
||||
natEnabled:
|
||||
type: boolean
|
||||
routeAgentDaemonSetStatus:
|
||||
properties:
|
||||
lastResourceVersion:
|
||||
type: string
|
||||
mismatchedContainerImages:
|
||||
type: boolean
|
||||
nonReadyContainerStates:
|
||||
items:
|
||||
description: ContainerState holds a possible state of container.
|
||||
Only one of its members may be specified. If none of them is
|
||||
specified, the default one is ContainerStateWaiting.
|
||||
properties:
|
||||
running:
|
||||
description: Details about a running container
|
||||
properties:
|
||||
startedAt:
|
||||
description: Time at which the container was last (re-)started
|
||||
format: date-time
|
||||
type: string
|
||||
type: object
|
||||
terminated:
|
||||
description: Details about a terminated container
|
||||
properties:
|
||||
containerID:
|
||||
description: Container's ID in the format 'docker://<container_id>'
|
||||
type: string
|
||||
exitCode:
|
||||
description: Exit status from the last termination of
|
||||
the container
|
||||
format: int32
|
||||
type: integer
|
||||
finishedAt:
|
||||
description: Time at which the container last terminated
|
||||
format: date-time
|
||||
type: string
|
||||
message:
|
||||
description: Message regarding the last termination of
|
||||
the container
|
||||
type: string
|
||||
reason:
|
||||
description: (brief) reason from the last termination
|
||||
of the container
|
||||
type: string
|
||||
signal:
|
||||
description: Signal from the last termination of the container
|
||||
format: int32
|
||||
type: integer
|
||||
startedAt:
|
||||
description: Time at which previous execution of the container
|
||||
started
|
||||
format: date-time
|
||||
type: string
|
||||
required:
|
||||
- exitCode
|
||||
type: object
|
||||
waiting:
|
||||
description: Details about a waiting container
|
||||
properties:
|
||||
message:
|
||||
description: Message regarding why the container is not
|
||||
yet running.
|
||||
type: string
|
||||
reason:
|
||||
description: (brief) reason the container is not yet running.
|
||||
type: string
|
||||
type: object
|
||||
type: object
|
||||
type: array
|
||||
status:
|
||||
description: DaemonSetStatus represents the current status of a
|
||||
daemon set.
|
||||
properties:
|
||||
collisionCount:
|
||||
description: Count of hash collisions for the DaemonSet. The
|
||||
DaemonSet controller uses this field as a collision avoidance
|
||||
mechanism when it needs to create the name for the newest
|
||||
ControllerRevision.
|
||||
format: int32
|
||||
type: integer
|
||||
conditions:
|
||||
description: Represents the latest available observations of
|
||||
a DaemonSet's current state.
|
||||
items:
|
||||
description: DaemonSetCondition describes the state of a DaemonSet
|
||||
at a certain point.
|
||||
properties:
|
||||
lastTransitionTime:
|
||||
description: Last time the condition transitioned from
|
||||
one status to another.
|
||||
format: date-time
|
||||
type: string
|
||||
message:
|
||||
description: A human readable message indicating details
|
||||
about the transition.
|
||||
type: string
|
||||
reason:
|
||||
description: The reason for the condition's last transition.
|
||||
type: string
|
||||
status:
|
||||
description: Status of the condition, one of True, False,
|
||||
Unknown.
|
||||
type: string
|
||||
type:
|
||||
description: Type of DaemonSet condition.
|
||||
type: string
|
||||
required:
|
||||
- status
|
||||
- type
|
||||
type: object
|
||||
type: array
|
||||
currentNumberScheduled:
|
||||
description: 'The number of nodes that are running at least
|
||||
1 daemon pod and are supposed to run the daemon pod. More
|
||||
info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
desiredNumberScheduled:
|
||||
description: 'The total number of nodes that should be running
|
||||
the daemon pod (including nodes correctly running the daemon
|
||||
pod). More info: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
numberAvailable:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and available (ready for at least spec.minReadySeconds)
|
||||
format: int32
|
||||
type: integer
|
||||
numberMisscheduled:
|
||||
description: 'The number of nodes that are running the daemon
|
||||
pod, but are not supposed to run the daemon pod. More info:
|
||||
https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/'
|
||||
format: int32
|
||||
type: integer
|
||||
numberReady:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have one or more of the daemon pod running
|
||||
and ready.
|
||||
format: int32
|
||||
type: integer
|
||||
numberUnavailable:
|
||||
description: The number of nodes that should be running the
|
||||
daemon pod and have none of the daemon pod running and available
|
||||
(ready for at least spec.minReadySeconds)
|
||||
format: int32
|
||||
type: integer
|
||||
observedGeneration:
|
||||
description: The most recent generation observed by the daemon
|
||||
set controller.
|
||||
format: int64
|
||||
type: integer
|
||||
updatedNumberScheduled:
|
||||
description: The total number of nodes that are running updated
|
||||
daemon pod
|
||||
format: int32
|
||||
type: integer
|
||||
required:
|
||||
- currentNumberScheduled
|
||||
- desiredNumberScheduled
|
||||
- numberMisscheduled
|
||||
- numberReady
|
||||
type: object
|
||||
required:
|
||||
- mismatchedContainerImages
|
||||
type: object
|
||||
serviceCIDR:
|
||||
type: string
|
||||
required:
|
||||
- clusterID
|
||||
- natEnabled
|
||||
type: object
|
||||
type: object
|
||||
version: v1alpha1
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
served: true
|
||||
storage: true
|
||||
status:
|
||||
acceptedNames:
|
||||
kind: ""
|
||||
plural: ""
|
||||
conditions: []
|
||||
storedVersions: []
|
||||
@@ -1,118 +0,0 @@
|
||||
questions:
|
||||
- variable: defaultOperatorImage
|
||||
default: true
|
||||
description: "Use default Submariner operator image or specify a custom one"
|
||||
label: Use default Submariner operator image
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container Images"
|
||||
subquestions:
|
||||
- variable: operator.image.repository
|
||||
default: "quay.io/submariner/submariner-operator"
|
||||
description: "Submariner Operator Image Repository"
|
||||
type: string
|
||||
label: Submariner Operator Image Repository
|
||||
- variable: operator.image.tag
|
||||
default: "0.7.0"
|
||||
description: "Submariner Operator Image Tag"
|
||||
type: string
|
||||
label: Submariner Operator Image Tag
|
||||
- variable: defaultSubmarinerImages
|
||||
default: true
|
||||
description: "Use default Submariner images or specify custom ones"
|
||||
label: Use default Submariner images
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container images"
|
||||
subquestions:
|
||||
- variable: submariner.images.repository
|
||||
default: "quay.io/submariner"
|
||||
description: "Submariner Repository (base for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Repository
|
||||
- variable: submariner.images.tag
|
||||
default: "0.7.0"
|
||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Images Tag
|
||||
- variable: submariner.clusterId
|
||||
default: ""
|
||||
description: "Enter a unique cluster ID to identify this cluster"
|
||||
type: string
|
||||
label: "Cluster ID"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: ipsec.psk
|
||||
default: ""
|
||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
||||
type: string
|
||||
label: "IPsec Pre-Shared Key"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: broker.server
|
||||
type: string
|
||||
default: ""
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Server"
|
||||
description: "Broker server to use (without the https://)"
|
||||
- variable: broker.insecure
|
||||
type: boolean
|
||||
default: false
|
||||
show_subquestion_if: false
|
||||
group: "Broker Configuration"
|
||||
label: "Insecure Broker"
|
||||
description: "Connect to K8s broker without validating CA"
|
||||
subquestions:
|
||||
- variable: broker.ca
|
||||
type: string
|
||||
description: "Base64 encoded broker ca.crt"
|
||||
label: "Broker CA encoded in base64"
|
||||
default: ""
|
||||
- variable: broker.token
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Token"
|
||||
description: "Bearer token for broker"
|
||||
- variable: broker.namespace
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Namespace"
|
||||
description: "Enter namespace to use on central broker"
|
||||
- variable: submariner.clusterCidr
|
||||
default: ""
|
||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Cluster CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.serviceCidr
|
||||
default: ""
|
||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Service CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.natEnabled
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
||||
label: "NAT Enabled"
|
||||
- variable: submariner.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable submariner debug mode"
|
||||
label: "Submariner Debug Enabled"
|
||||
- variable: ipsec.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable Charon debug mode"
|
||||
label: "Charon Enabled"
|
||||
- variable: submariner.cableDriver
|
||||
type: string
|
||||
default: ""
|
||||
group: "Advanced Configuration"
|
||||
description: "Cable driver implementation"
|
||||
label: "Cable Driver"
|
||||
@@ -1,7 +1,3 @@
|
||||
Submariner is now installed.
|
||||
|
||||
{{- if .Values.engine.nodeSelectorEnabled }}
|
||||
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
||||
{{- end }}
|
||||
|
||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||
|
||||
@@ -1,11 +1,4 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "submariner.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
@@ -31,64 +24,3 @@ Create chart name and version as used by the chart label.
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-operator service account to use
|
||||
*/}}
|
||||
{{- define "submariner.operatorServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.operator.create -}}
|
||||
{{ default (printf "%s" (include "submariner.fullname" .)) .Values.serviceAccounts.operator.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.operator.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-engine service account to use
|
||||
*/}}
|
||||
{{- define "submariner.engineServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.engine.create -}}
|
||||
{{ default (printf "%s-engine" (include "submariner.fullname" .)) .Values.serviceAccounts.engine.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.engine.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-route-agent service account to use
|
||||
*/}}
|
||||
{{- define "submariner.routeAgentServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
||||
{{ default (printf "%s-routeagent" (include "submariner.fullname" .)) .Values.serviceAccounts.routeAgent.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-globalnet service account to use
|
||||
*/}}
|
||||
{{- define "submariner.globalnetServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.globalnet.create -}}
|
||||
{{ default (printf "%s-globalnet" (include "submariner.fullname" .)) .Values.serviceAccounts.globalnet.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.globalnet.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-lighthouse service account to use
|
||||
*/}}
|
||||
{{- define "submariner.lighthouseServiceAccountName" -}}
|
||||
{{- if .Values.submariner.serviceDiscovery -}}
|
||||
{{ default (printf "%s-lighthouse" (include "submariner.fullname" .)) .Values.serviceAccounts.lighthouse.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.lighthouse.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-lighthouse-coredns service name to use
|
||||
*/}}
|
||||
{{- define "submariner.lighthouseDnsName" -}}
|
||||
{{- default (printf "%s-lighthouse-coredns" (include "submariner.fullname" .)) .Values.lighthouseCoredns.name }}
|
||||
{{- end -}}
|
||||
|
||||
@@ -6,7 +6,6 @@ metadata:
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.fullname" . }}
|
||||
component: engine
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
spec:
|
||||
progressDeadlineSeconds: 600
|
||||
@@ -27,8 +26,8 @@ spec:
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- submariner-operator
|
||||
- args:
|
||||
- --leader-elect
|
||||
env:
|
||||
- name: WATCH_NAMESPACE
|
||||
valueFrom:
|
||||
@@ -52,6 +51,5 @@ spec:
|
||||
restartPolicy: Always
|
||||
schedulerName: default-scheduler
|
||||
securityContext: {}
|
||||
serviceAccount: {{ template "submariner.fullname" . }}
|
||||
serviceAccountName: {{ template "submariner.fullname" . }}
|
||||
serviceAccountName: submariner-operator
|
||||
terminationGracePeriodSeconds: 30
|
||||
|
||||
@@ -1,318 +0,0 @@
|
||||
{{- if .Values.rbac.create -}}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- services/finalizers
|
||||
- endpoints
|
||||
- persistentvolumeclaims
|
||||
- events
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- daemonsets
|
||||
- replicasets
|
||||
- statefulsets
|
||||
verbs:
|
||||
- '*'
|
||||
- apiGroups:
|
||||
- monitoring.coreos.com
|
||||
resources:
|
||||
- servicemonitors
|
||||
verbs:
|
||||
- get
|
||||
- create
|
||||
- apiGroups:
|
||||
- apps
|
||||
resourceNames:
|
||||
- {{ template "submariner.fullname" . }}
|
||||
resources:
|
||||
- deployments/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- replicasets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- '*'
|
||||
- servicediscoveries
|
||||
verbs:
|
||||
- '*'
|
||||
---
|
||||
kind: RoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:engine
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["configmaps"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints", "gateways"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
- apiGroups: [""]
|
||||
resources: ["events"]
|
||||
verbs: ["create", "patch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:engine
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ template "submariner.fullname" . }}:engine
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints", "gateways"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs: ["get", "watch", "list"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
# submariner-operator updates the config map of core-dns to forward requests to
|
||||
# clusterset.local to Lighthouse DNS, also looks at existing configmaps
|
||||
# to figure out network settings
|
||||
- apiGroups: [""]
|
||||
resources: ["configmaps"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
- apiGroups: ["apiextensions.k8s.io"]
|
||||
resources: ["customresourcedefinitions"]
|
||||
verbs: ["get", "list", "create", "update", "delete"]
|
||||
- apiGroups: [""] # pods and services are looked up to figure out network settings
|
||||
resources: ["pods", "services"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["operator.openshift.io"]
|
||||
resources: ["dnses"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
- apiGroups: ["config.openshift.io"]
|
||||
resources: ["networks"]
|
||||
verbs: ["get", "list"]
|
||||
- apiGroups: ["multicluster.x-k8s.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["nodes"]
|
||||
verbs: ["get", "update"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:globalnet
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["services", "namespaces", "pods", "nodes"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints", "gateways"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:globalnet
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}:globalnet
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["services", "namespaces", "configmaps", "endpoints"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
- apiGroups: ["discovery.k8s.io"]
|
||||
resources: ["endpointslices"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||
- apiGroups: ["lighthouse.submariner.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["gateways"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -9,7 +9,9 @@ spec:
|
||||
brokerK8sApiServerToken: {{ .Values.broker.token }}
|
||||
brokerK8sCA: {{ .Values.broker.ca }}
|
||||
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
|
||||
brokerK8sInsecure: {{ .Values.broker.insecure }}
|
||||
ceIPSecDebug: {{ .Values.ipsec.debug }}
|
||||
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
|
||||
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
|
||||
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
|
||||
ceIPSecPSK: {{ .Values.ipsec.psk }}
|
||||
@@ -17,8 +19,49 @@ spec:
|
||||
clusterID: {{ .Values.submariner.clusterId }}
|
||||
colorCodes: {{ .Values.submariner.colorCodes }}
|
||||
debug: {{ .Values.submariner.debug }}
|
||||
loadBalancerEnabled: {{ .Values.submariner.loadBalancerEnabled }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
natEnabled: {{ .Values.submariner.natEnabled }}
|
||||
repository: {{ .Values.submariner.images.repository }}
|
||||
version: {{ .Values.submariner.images.tag }}
|
||||
version: {{ default .Chart.AppVersion .Values.submariner.images.tag }}
|
||||
{{- with .Values.images }}
|
||||
{{- if . }}
|
||||
imageOverrides:
|
||||
{{- if index . "submariner-operator" }}
|
||||
submariner-operator: {{ index . "submariner-operator" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-gateway" }}
|
||||
submariner-gateway: {{ index . "submariner-gateway" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-route-agent" }}
|
||||
submariner-routeagent: {{ index . "submariner-route-agent" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-globalnet" }}
|
||||
submariner-globalnet: {{ index . "submariner-globalnet" }}
|
||||
{{- end }}
|
||||
{{- if index . "submariner-networkplugin-syncer" }}
|
||||
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
|
||||
{{- end }}
|
||||
{{- if index . "lighthouse-agent" }}
|
||||
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
|
||||
{{- end }}
|
||||
{{- if index . "lighthouse-coredns" }}
|
||||
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
|
||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||
clustersetIPCIDR: "{{ .Values.submariner.clustersetIpCidr }}"
|
||||
clustersetIPEnabled: {{ .Values.submariner.clustersetIpEnabled }}
|
||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||
cableDriver: {{ .Values.submariner.cableDriver }}
|
||||
connectionHealthCheck:
|
||||
enabled: {{ .Values.submariner.healthcheckEnabled }}
|
||||
intervalSeconds: 1
|
||||
maxPacketLossCount: 5
|
||||
{{- with .Values.submariner.coreDNSCustomConfig }}
|
||||
coreDNSCustomConfig:
|
||||
configMapName: {{ .configMapName }}
|
||||
namespace: {{ .namespace }}
|
||||
{{- end }}
|
||||
|
||||
@@ -1,59 +0,0 @@
|
||||
{{- if .Values.serviceAccounts.operator.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.operatorServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.engine.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.engineServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.globalnet.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.lighthouse.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
@@ -5,24 +5,31 @@ submariner:
|
||||
clusterCidr: ""
|
||||
serviceCidr: ""
|
||||
globalCidr: ""
|
||||
clustersetIpCidr: ""
|
||||
clustersetIpEnabled: false
|
||||
loadBalancerEnabled: false
|
||||
natEnabled: false
|
||||
colorCodes: blue
|
||||
debug: false
|
||||
serviceDiscovery: true
|
||||
cableDriver: "libreswan"
|
||||
healthcheckEnabled: true
|
||||
coreDNSCustomConfig: {}
|
||||
images:
|
||||
repository: quay.io/submariner
|
||||
tag: "0.7.0"
|
||||
tag: ""
|
||||
broker:
|
||||
server: example.k8s.apiserver
|
||||
token: test
|
||||
namespace: xyz
|
||||
insecure: false
|
||||
ca: ""
|
||||
rbac:
|
||||
create: true
|
||||
globalnet: false
|
||||
images: {}
|
||||
ipsec:
|
||||
psk: ""
|
||||
debug: false
|
||||
forceUDPEncaps: false
|
||||
ikePort: 500
|
||||
natPort: 4500
|
||||
leadership:
|
||||
@@ -32,28 +39,8 @@ leadership:
|
||||
operator:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-operator
|
||||
tag: "0.7.0"
|
||||
tag: ""
|
||||
pullPolicy: IfNotPresent
|
||||
resources: {}
|
||||
tolerations: []
|
||||
affinity: {}
|
||||
engine:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner
|
||||
tag: "0.7.0"
|
||||
serviceAccounts:
|
||||
operator:
|
||||
create: true
|
||||
name: ""
|
||||
engine:
|
||||
create: true
|
||||
name: ""
|
||||
routeAgent:
|
||||
create: true
|
||||
name: ""
|
||||
globalnet:
|
||||
create: true
|
||||
name: ""
|
||||
lighthouse:
|
||||
create: false
|
||||
name: ""
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
.git
|
||||
@@ -1,12 +0,0 @@
|
||||
---
|
||||
name: submariner
|
||||
version: 0.6.0
|
||||
appVersion: 0.6.0
|
||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
sources:
|
||||
- https://submariner-io.github.io/submariner-charts/charts
|
||||
maintainers:
|
||||
- name: Submariner Developers
|
||||
email: submariner-dev@googlegroups.com
|
||||
@@ -1,5 +0,0 @@
|
||||
# Submariner
|
||||
|
||||
[Submariner](https://submariner.io) is a cross-cluster networking tool.
|
||||
|
||||
This chart creates the required components in this cluster to enable cross cluster networking.
|
||||
@@ -1,324 +0,0 @@
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: clusters.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Cluster
|
||||
plural: clusters
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: endpoints.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Endpoint
|
||||
plural: endpoints
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: gateways.submariner.io
|
||||
spec:
|
||||
group: submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: Gateway
|
||||
plural: gateways
|
||||
scope: Namespaced
|
||||
additionalPrinterColumns:
|
||||
- name: ha-status
|
||||
type: string
|
||||
description: High Availability Status of the Gateway
|
||||
JSONPath: .status.haStatus
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: multiclusterservices.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v1
|
||||
names:
|
||||
kind: MultiClusterService
|
||||
plural: multiclusterservices
|
||||
singular: multiclusterservice
|
||||
scope: Namespaced
|
||||
validation:
|
||||
openAPIV3Schema:
|
||||
properties:
|
||||
spec:
|
||||
properties:
|
||||
clusterServiceInfo:
|
||||
properties:
|
||||
clusterID:
|
||||
type: "string"
|
||||
clusterDomain:
|
||||
type: "string"
|
||||
serviceIP:
|
||||
type: "string"
|
||||
port:
|
||||
type: "integer"
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceexports.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v2alpha1
|
||||
names:
|
||||
kind: ServiceExport
|
||||
plural: serviceexports
|
||||
singular: serviceexport
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1beta1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceimports.lighthouse.submariner.io
|
||||
spec:
|
||||
group: lighthouse.submariner.io
|
||||
version: v2alpha1
|
||||
names:
|
||||
kind: ServiceImport
|
||||
plural: serviceimports
|
||||
singular: serviceimport
|
||||
scope: Namespaced
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceexports.multicluster.x-k8s.io
|
||||
spec:
|
||||
group: multicluster.x-k8s.io
|
||||
scope: Namespaced
|
||||
names:
|
||||
plural: serviceexports
|
||||
singular: serviceexport
|
||||
kind: ServiceExport
|
||||
shortNames:
|
||||
- svcex
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
additionalPrinterColumns:
|
||||
- name: Age
|
||||
type: date
|
||||
jsonPath: .metadata.creationTimestamp
|
||||
"schema":
|
||||
"openAPIV3Schema":
|
||||
description: ServiceExport declares that the Service with the same name and
|
||||
namespace as this export should be consumable from other clusters.
|
||||
type: object
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
status:
|
||||
description: status describes the current state of an exported service.
|
||||
Service configuration comes from the Service that had the same name
|
||||
and namespace as this ServiceExport. Populated by the multi-cluster
|
||||
service implementation's controller.
|
||||
type: object
|
||||
properties:
|
||||
conditions:
|
||||
type: array
|
||||
items:
|
||||
description: "ServiceExportCondition contains details for the current
|
||||
condition of this service export. \n Once [KEP-1623](https://github.com/kubernetes/enhancements/tree/master/keps/sig-api-machinery/1623-standardize-conditions)
|
||||
is implemented, this will be replaced by metav1.Condition."
|
||||
type: object
|
||||
required:
|
||||
- status
|
||||
- type
|
||||
properties:
|
||||
lastTransitionTime:
|
||||
type: string
|
||||
format: date-time
|
||||
message:
|
||||
type: string
|
||||
reason:
|
||||
type: string
|
||||
status:
|
||||
description: Status is one of {"True", "False", "Unknown"}
|
||||
type: string
|
||||
enum:
|
||||
- "True"
|
||||
- "False"
|
||||
- Unknown
|
||||
type:
|
||||
description: ServiceExportConditionType identifies a specific
|
||||
condition.
|
||||
type: string
|
||||
x-kubernetes-list-map-keys:
|
||||
- type
|
||||
x-kubernetes-list-type: map
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
name: serviceimports.multicluster.x-k8s.io
|
||||
spec:
|
||||
group: multicluster.x-k8s.io
|
||||
scope: Namespaced
|
||||
names:
|
||||
plural: serviceimports
|
||||
singular: serviceimport
|
||||
kind: ServiceImport
|
||||
shortNames:
|
||||
- svcim
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
additionalPrinterColumns:
|
||||
- name: Type
|
||||
type: string
|
||||
description: The type of this ServiceImport
|
||||
jsonPath: .spec.type
|
||||
- name: IP
|
||||
type: string
|
||||
description: The VIP for this ServiceImport
|
||||
jsonPath: .spec.ips
|
||||
- name: Age
|
||||
type: date
|
||||
jsonPath: .metadata.creationTimestamp
|
||||
"schema":
|
||||
"openAPIV3Schema":
|
||||
description: ServiceImport describes a service imported from clusters in a
|
||||
ClusterSet.
|
||||
type: object
|
||||
properties:
|
||||
apiVersion:
|
||||
description: 'APIVersion defines the versioned schema of this representation
|
||||
of an object. Servers should convert recognized schemas to the latest
|
||||
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||
type: string
|
||||
kind:
|
||||
description: 'Kind is a string value representing the REST resource this
|
||||
object represents. Servers may infer this from the endpoint the client
|
||||
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
description: spec defines the behavior of a ServiceImport.
|
||||
type: object
|
||||
required:
|
||||
- ports
|
||||
- type
|
||||
properties:
|
||||
ips:
|
||||
description: ip will be used as the VIP for this service when type
|
||||
is ClusterSetIP.
|
||||
type: array
|
||||
maxItems: 1
|
||||
items:
|
||||
type: string
|
||||
ports:
|
||||
type: array
|
||||
items:
|
||||
description: ServicePort represents the port on which the service
|
||||
is exposed
|
||||
type: object
|
||||
required:
|
||||
- port
|
||||
properties:
|
||||
appProtocol:
|
||||
description: The application protocol for this port. This field
|
||||
follows standard Kubernetes label syntax. Un-prefixed names
|
||||
are reserved for IANA standard service names (as per RFC-6335
|
||||
and http://www.iana.org/assignments/service-names). Non-standard
|
||||
protocols should use prefixed names such as mycompany.com/my-custom-protocol.
|
||||
Field can be enabled with ServiceAppProtocol feature gate.
|
||||
type: string
|
||||
name:
|
||||
description: The name of this port within the service. This
|
||||
must be a DNS_LABEL. All ports within a ServiceSpec must have
|
||||
unique names. When considering the endpoints for a Service,
|
||||
this must match the 'name' field in the EndpointPort. Optional
|
||||
if only one ServicePort is defined on this service.
|
||||
type: string
|
||||
port:
|
||||
description: The port that will be exposed by this service.
|
||||
type: integer
|
||||
format: int32
|
||||
protocol:
|
||||
description: The IP protocol for this port. Supports "TCP",
|
||||
"UDP", and "SCTP". Default is TCP.
|
||||
type: string
|
||||
x-kubernetes-list-type: atomic
|
||||
sessionAffinity:
|
||||
description: 'Supports "ClientIP" and "None". Used to maintain session
|
||||
affinity. Enable client IP based session affinity. Must be ClientIP
|
||||
or None. Defaults to None. Ignored when type is Headless More info:
|
||||
https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies'
|
||||
type: string
|
||||
sessionAffinityConfig:
|
||||
description: sessionAffinityConfig contains session affinity configuration.
|
||||
type: object
|
||||
properties:
|
||||
clientIP:
|
||||
description: clientIP contains the configurations of Client IP
|
||||
based session affinity.
|
||||
type: object
|
||||
properties:
|
||||
timeoutSeconds:
|
||||
description: timeoutSeconds specifies the seconds of ClientIP
|
||||
type session sticky time. The value must be >0 && <=86400(for
|
||||
1 day) if ServiceAffinity == "ClientIP". Default value is
|
||||
10800(for 3 hours).
|
||||
type: integer
|
||||
format: int32
|
||||
type:
|
||||
description: type defines the type of this service. Must be ClusterSetIP
|
||||
or Headless.
|
||||
type: string
|
||||
enum:
|
||||
- ClusterSetIP
|
||||
- Headless
|
||||
status:
|
||||
description: status contains information about the exported services that
|
||||
form the multi-cluster service referenced by this ServiceImport.
|
||||
type: object
|
||||
properties:
|
||||
clusters:
|
||||
description: clusters is the list of exporting clusters from which
|
||||
this service was derived.
|
||||
type: array
|
||||
items:
|
||||
description: ClusterStatus contains service configuration mapped
|
||||
to a specific source cluster
|
||||
type: object
|
||||
required:
|
||||
- cluster
|
||||
properties:
|
||||
cluster:
|
||||
description: cluster is the name of the exporting cluster. Must
|
||||
be a valid RFC-1123 DNS label.
|
||||
type: string
|
||||
x-kubernetes-list-map-keys:
|
||||
- cluster
|
||||
x-kubernetes-list-type: map
|
||||
@@ -1,138 +0,0 @@
|
||||
questions:
|
||||
- variable: defaultEngineImage
|
||||
default: true
|
||||
description: "Use default Submariner Engine image or specify a custom one"
|
||||
label: Use default submariner engine image
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container Images"
|
||||
subquestions:
|
||||
- variable: engine.image.repository
|
||||
default: "quay.io/submariner/submariner"
|
||||
description: "Submariner Engine Image Repository"
|
||||
type: string
|
||||
label: Submariner Engine Image Repository
|
||||
- variable: engine.image.tag
|
||||
default: "0.6.0"
|
||||
description: "Submariner Engine Image Tag"
|
||||
type: string
|
||||
label: Submariner Engine Image Tag
|
||||
- variable: defaultRouteAgentImage
|
||||
default: true
|
||||
description: "Use default Submariner Route Agent image or specify a custom one"
|
||||
label: Use default submariner route agent image
|
||||
type: boolean
|
||||
show_subquestion_if: false
|
||||
group: "Container Images"
|
||||
subquestions:
|
||||
- variable: routeAgent.image.repository
|
||||
default: "quay.io/submariner/submariner-route-agent"
|
||||
description: "Submariner Route Agent Image Repository"
|
||||
type: string
|
||||
label: Submariner Route Agent Image Repository
|
||||
- variable: routeAgent.image.tag
|
||||
default: "0.6.0"
|
||||
description: "Submariner Route Agent Image Tag"
|
||||
type: string
|
||||
label: Submariner Route Agent Image Tag
|
||||
- variable: engine.nodeSelectorEnabled
|
||||
default: true
|
||||
description: "Restrict submariner to nodes labeled with submariner.io/gateway=true"
|
||||
label: Restrict gateway deployments to specific nodes
|
||||
type: boolean
|
||||
group: "Gateway Configuration"
|
||||
- variable: submariner.clusterId
|
||||
default: ""
|
||||
description: "Enter a unique cluster ID to identify this cluster"
|
||||
type: string
|
||||
label: "Cluster ID"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: ipsec.psk
|
||||
default: ""
|
||||
description: "Enter the pre-shared key for the IPsec Cable Engine"
|
||||
type: string
|
||||
label: "IPsec Pre-Shared Key"
|
||||
group: "Configuration"
|
||||
required: true
|
||||
- variable: broker.type
|
||||
type: enum
|
||||
default: k8s
|
||||
options:
|
||||
- k8s
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Type"
|
||||
description: "Type of Broker to use"
|
||||
- variable: broker.server
|
||||
type: string
|
||||
default: ""
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Server"
|
||||
description: "Broker server to use (without the https://)"
|
||||
- variable: broker.insecure
|
||||
type: boolean
|
||||
default: false
|
||||
show_subquestion_if: false
|
||||
group: "Broker Configuration"
|
||||
label: "Insecure Broker"
|
||||
description: "Connect to K8s broker without validating CA"
|
||||
subquestions:
|
||||
- variable: broker.ca
|
||||
type: string
|
||||
description: "Base64 encoded broker ca.crt"
|
||||
label: "Broker CA encoded in base64"
|
||||
default: ""
|
||||
- variable: broker.token
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Token"
|
||||
description: "Bearer token for broker"
|
||||
- variable: broker.namespace
|
||||
type: string
|
||||
group: "Broker Configuration"
|
||||
label: "Broker Namespace"
|
||||
description: "Enter namespace to use on central broker"
|
||||
- variable: submariner.clusterCidr
|
||||
default: ""
|
||||
description: "Enter the cluster CIDR (i.e. 10.42.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Cluster CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.serviceCidr
|
||||
default: ""
|
||||
description: "Enter the service CIDR (i.e. 10.43.0.0/16) for this cluster"
|
||||
type: string
|
||||
label: "Service CIDR"
|
||||
group: "CIDR Configuration"
|
||||
required: true
|
||||
- variable: submariner.natEnabled
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "If the gateway nodes for this cluster are behind 1:1 NAT, you should enable NAT"
|
||||
label: "NAT Enabled"
|
||||
- variable: crd.create
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Advanced Configuration"
|
||||
description: "Create the Submariner CRDs, if deploying Submariner into the same cluster as the submariner-k8s-broker, you probably shouldn't create CRDs"
|
||||
label: "CRD Creation Enabled"
|
||||
- variable: submariner.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable submariner debug mode"
|
||||
label: "Submariner Debug Enabled"
|
||||
- variable: ipsec.debug
|
||||
type: boolean
|
||||
default: false
|
||||
group: "Advanced Configuration"
|
||||
description: "Enable Charon debug mode"
|
||||
label: "Charon Enabled"
|
||||
- variable: submariner.cableDriver
|
||||
type: string
|
||||
default: ""
|
||||
group: "Advanced Configuration"
|
||||
description: "Cable driver implementation"
|
||||
label: "Cable Driver"
|
||||
@@ -1,7 +0,0 @@
|
||||
Submariner is now installed.
|
||||
|
||||
{{- if .Values.engine.nodeSelectorEnabled }}
|
||||
If you haven't done so yet, please label a node as `submariner.io/gateway=true` to elect it for running Submariner.
|
||||
{{- end }}
|
||||
|
||||
By default, Submariner runs with 1 replica. If you have more than one Gateway host, you can scale Submariner to N replicas, and the other Submariner pods will simply join the leader election pool.
|
||||
@@ -1,83 +0,0 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "submariner.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
If release name contains chart name it will be used as a full name.
|
||||
*/}}
|
||||
{{- define "submariner.fullname" -}}
|
||||
{{- if .Values.fullnameOverride -}}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||
{{- if contains $name .Release.Name -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "submariner.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-engine service account to use
|
||||
*/}}
|
||||
{{- define "submariner.engineServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.engine.create -}}
|
||||
{{ default (printf "%s-engine" (include "submariner.fullname" .)) .Values.serviceAccounts.engine.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.engine.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-route-agent service account to use
|
||||
*/}}
|
||||
{{- define "submariner.routeAgentServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.routeAgent.create -}}
|
||||
{{ default (printf "%s-routeagent" (include "submariner.fullname" .)) .Values.serviceAccounts.routeAgent.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.routeAgent.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-globalnet service account to use
|
||||
*/}}
|
||||
{{- define "submariner.globalnetServiceAccountName" -}}
|
||||
{{- if .Values.serviceAccounts.globalnet.create -}}
|
||||
{{ default (printf "%s-globalnet" (include "submariner.fullname" .)) .Values.serviceAccounts.globalnet.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.globalnet.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-lighthouse service account to use
|
||||
*/}}
|
||||
{{- define "submariner.lighthouseServiceAccountName" -}}
|
||||
{{- if .Values.submariner.serviceDiscovery -}}
|
||||
{{ default (printf "%s-lighthouse" (include "submariner.fullname" .)) .Values.serviceAccounts.lighthouse.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccounts.lighthouse.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the submariner-lighthouse-coredns service name to use
|
||||
*/}}
|
||||
{{- define "submariner.lighthouseDnsName" -}}
|
||||
{{- default (printf "%s-lighthouse-coredns" (include "submariner.fullname" .)) .Values.lighthouseCoredns.name }}
|
||||
{{- end -}}
|
||||
@@ -1,134 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.fullname" . }}-engine
|
||||
component: engine
|
||||
name: {{ template "submariner.fullname" . }}-gateway
|
||||
spec:
|
||||
revisionHistoryLimit: 5
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ template "submariner.fullname" . }}-engine
|
||||
updateStrategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
labels:
|
||||
app: {{ template "submariner.fullname" . }}-engine
|
||||
spec:
|
||||
affinity:
|
||||
podAntiAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
- labelSelector:
|
||||
matchExpressions:
|
||||
- key: app
|
||||
operator: In
|
||||
values:
|
||||
- {{ template "submariner.fullname" . }}-engine
|
||||
topologyKey: "kubernetes.io/hostname"
|
||||
{{- with .Values.engine.affinity }}
|
||||
{{ toYaml . | indent 8 }}
|
||||
{{- end }}
|
||||
nodeSelector:
|
||||
{{- if .Values.engine.nodeSelectorEnabled }}
|
||||
submariner.io/gateway: "true"
|
||||
{{- end }}
|
||||
{{- with .Values.engine.nodeSelector }}
|
||||
{{ toYaml . | indent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.engine.tolerations }}
|
||||
tolerations:
|
||||
{{ toYaml . | indent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- command:
|
||||
- submariner.sh
|
||||
env:
|
||||
- name: SUBMARINER_NAMESPACE
|
||||
value: "{{ .Release.Namespace }}"
|
||||
- name: SUBMARINER_CLUSTERCIDR
|
||||
value: "{{ .Values.submariner.clusterCidr }}"
|
||||
- name: SUBMARINER_SERVICECIDR
|
||||
value: "{{ .Values.submariner.serviceCidr }}"
|
||||
- name: SUBMARINER_GLOBALCIDR
|
||||
value: "{{ .Values.submariner.globalCidr }}"
|
||||
- name: SUBMARINER_TOKEN
|
||||
value: "{{ .Values.submariner.apiToken }}"
|
||||
- name: SUBMARINER_CLUSTERID
|
||||
value: "{{ .Values.submariner.clusterId }}"
|
||||
- name: SUBMARINER_COLORCODES
|
||||
value: "{{ .Values.submariner.colorCodes }}"
|
||||
- name: SUBMARINER_DEBUG
|
||||
value: "{{ .Values.submariner.debug }}"
|
||||
- name: SUBMARINER_NATENABLED
|
||||
value: "{{ .Values.submariner.natEnabled }}"
|
||||
- name: SUBMARINER_BROKER
|
||||
value: "{{ .Values.broker.type }}"
|
||||
- name: SUBMARINER_CABLEDRIVER
|
||||
value: "{{ .Values.submariner.cableDriver }}"
|
||||
{{- if eq .Values.broker.type "phpapi" }}
|
||||
- name: BROKER_PHPAPI_PROTO
|
||||
value: "{{ .Values.broker.proto }}"
|
||||
- name: BROKER_PHPAPI_SERVER
|
||||
value: "{{ .Values.broker.server }}"
|
||||
{{- end }}
|
||||
{{- if eq .Values.broker.type "k8s" }}
|
||||
- name: BROKER_K8S_APISERVER
|
||||
value: "{{ .Values.broker.server }}"
|
||||
- name: BROKER_K8S_APISERVERTOKEN
|
||||
value: "{{ .Values.broker.token }}"
|
||||
- name: BROKER_K8S_REMOTENAMESPACE
|
||||
value: "{{ .Values.broker.namespace }}"
|
||||
{{- if .Values.broker.insecure }}
|
||||
- name: BROKER_K8S_INSECURE
|
||||
value: "true"
|
||||
{{- else }}
|
||||
- name: BROKER_K8S_CA
|
||||
value: "{{ .Values.broker.ca }}"
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
- name: CE_IPSEC_PSK
|
||||
value: "{{ .Values.ipsec.psk }}"
|
||||
- name: CE_IPSEC_DEBUG
|
||||
value: "{{ .Values.ipsec.debug }}"
|
||||
- name: CE_IPSEC_IKEPORT
|
||||
value: "{{ .Values.ipsec.ikePort }}"
|
||||
- name: CE_IPSEC_NATTPORT
|
||||
value: "{{ .Values.ipsec.natPort }}"
|
||||
- name: LEADERSHIP_LEASEDURATION
|
||||
value: "{{ .Values.leadership.leaseDuration }}"
|
||||
- name: LEADERSHIP_RENEWDEADLINE
|
||||
value: "{{ .Values.leadership.renewDeadline }}"
|
||||
- name: LEADERSHIP_RETRYPERIOD
|
||||
value: "{{ .Values.leadership.retryPeriod }}"
|
||||
image: {{ .Values.engine.image.repository }}:{{ default .Chart.AppVersion .Values.engine.image.tag }}
|
||||
imagePullPolicy: {{ .Values.engine.image.pullPolicy }}
|
||||
name: submariner
|
||||
resources:
|
||||
{{ toYaml .Values.engine.resources | indent 10 }}
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: true
|
||||
capabilities:
|
||||
add:
|
||||
- ALL
|
||||
privileged: true
|
||||
readOnlyRootFilesystem: false
|
||||
runAsNonRoot: false
|
||||
stdin: true
|
||||
terminationMessagePath: /dev/termination-log
|
||||
terminationMessagePolicy: File
|
||||
tty: true
|
||||
dnsPolicy: ClusterFirst
|
||||
hostNetwork: true
|
||||
restartPolicy: Always
|
||||
schedulerName: default-scheduler
|
||||
securityContext: {}
|
||||
terminationGracePeriodSeconds: 1
|
||||
serviceAccountName: {{ template "submariner.engineServiceAccountName" . }}
|
||||
@@ -1,59 +0,0 @@
|
||||
{{- if ne .Values.submariner.globalCidr "" }}
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}-globalnet
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.fullname" . }}-globalnet
|
||||
component: globalnet
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ template "submariner.fullname" . }}-globalnet
|
||||
updateStrategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ template "submariner.fullname" . }}-globalnet
|
||||
spec:
|
||||
hostNetwork: true
|
||||
serviceAccountName: submariner-globalnet
|
||||
serviceAccount: submariner-globalnet
|
||||
terminationGracePeriodSeconds: 2
|
||||
nodeSelector:
|
||||
submariner.io/gateway: 'true'
|
||||
containers:
|
||||
- name: {{ template "submariner.fullname" . }}-globalnet
|
||||
image: {{ .Values.globalnet.image.repository }}:{{ default .Chart.AppVersion .Values.globalnet.image.tag }}
|
||||
imagePullPolicy: {{ .Values.globalnet.image.pullPolicy }}
|
||||
env:
|
||||
- name: SUBMARINER_CLUSTERID
|
||||
value: '{{ .Values.submariner.clusterId }}'
|
||||
- name: SUBMARINER_EXCLUDENS
|
||||
value: 'submariner-operator,kube-system,operators,openshift-monitoring,openshift-dns'
|
||||
- name: SUBMARINER_NAMESPACE
|
||||
value: '{{ .Release.Namespace }}'
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: true
|
||||
capabilities:
|
||||
add:
|
||||
- ALL
|
||||
privileged: true
|
||||
readOnlyRootFilesystem: false
|
||||
runAsNonRoot: false
|
||||
volumeMounts:
|
||||
# Because we don't actually run iptables locally, but chroot in to the host
|
||||
- mountPath: /host
|
||||
name: host-slash
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: host-slash
|
||||
hostPath:
|
||||
path: /
|
||||
{{- end }}
|
||||
@@ -1,74 +0,0 @@
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||
component: lighthouse-coredns
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||
replicas: 2
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||
spec:
|
||||
containers:
|
||||
- args:
|
||||
- -conf
|
||||
- /etc/coredns/Corefile
|
||||
image: {{ .Values.lighthouseCoredns.image.repository }}:{{ default .Chart.AppVersion .Values.lighthouseCoredns.image.tag }}
|
||||
imagePullPolicy: {{ .Values.lighthouseCoredns.image.pullPolicy }}
|
||||
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||
volumeMounts:
|
||||
- mountPath: /etc/coredns
|
||||
name: config-volume
|
||||
readOnly: true
|
||||
serviceAccountName: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
volumes:
|
||||
- configMap:
|
||||
defaultMode: 420
|
||||
items:
|
||||
- key: Corefile
|
||||
path: Corefile
|
||||
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||
name: config-volume
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||
labels:
|
||||
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||
spec:
|
||||
ports:
|
||||
- name: udp
|
||||
port: 53
|
||||
protocol: UDP
|
||||
targetPort: 53
|
||||
selector:
|
||||
app: {{ template "submariner.lighthouseDnsName" . }}
|
||||
type: ClusterIP
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseDnsName" . }}
|
||||
data:
|
||||
Corefile: |
|
||||
clusterset.local:53 {
|
||||
{{- if .Values.submariner.debug }}
|
||||
log
|
||||
{{- end }}
|
||||
lighthouse
|
||||
errors
|
||||
health
|
||||
ready
|
||||
}
|
||||
{{- end }}
|
||||
@@ -1,55 +0,0 @@
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
component: lighthouse
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
spec:
|
||||
serviceAccountName: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
containers:
|
||||
- command:
|
||||
- lighthouse-agent.sh
|
||||
env:
|
||||
- name: SUBMARINER_NAMESPACE
|
||||
value: "{{ .Release.Namespace }}"
|
||||
- name: SUBMARINER_CLUSTERID
|
||||
value: "{{ .Values.submariner.clusterId }}"
|
||||
- name: SUBMARINER_DEBUG
|
||||
value: "{{ .Values.submariner.debug }}"
|
||||
{{- if ne .Values.submariner.globalCidr "" }}
|
||||
- name: SUBMARINER_GLOBALNET_ENABLED
|
||||
value: "true"
|
||||
{{- end }}
|
||||
- name: BROKER_K8S_APISERVER
|
||||
value: "{{ .Values.broker.server }}"
|
||||
- name: BROKER_K8S_APISERVERTOKEN
|
||||
value: "{{ .Values.broker.token }}"
|
||||
- name: BROKER_K8S_REMOTENAMESPACE
|
||||
value: "{{ .Values.broker.namespace }}"
|
||||
{{- if .Values.broker.insecure }}
|
||||
- name: BROKER_K8S_INSECURE
|
||||
value: "true"
|
||||
{{- else }}
|
||||
- name: BROKER_K8S_CA
|
||||
value: "{{ .Values.broker.ca }}"
|
||||
{{- end }}
|
||||
name: {{ template "submariner.fullname" . }}-lighthouse-agent
|
||||
image: {{ .Values.lighthouse.image.repository }}:{{ default .Chart.AppVersion .Values.lighthouse.image.tag }}
|
||||
imagePullPolicy: {{ .Values.lighthouse.image.pullPolicy }}
|
||||
restartPolicy: Always
|
||||
terminationGracePeriodSeconds: 0
|
||||
{{- end }}
|
||||
@@ -1,149 +0,0 @@
|
||||
{{- if .Values.rbac.create -}}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:engine
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["configmaps"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints", "gateways"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
- apiGroups: [""]
|
||||
resources: ["events"]
|
||||
verbs: ["create", "patch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
rules:
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints", "gateways"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update"]
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs: ["get", "watch", "list"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:engine
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ template "submariner.fullname" . }}:engine
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.engineServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["nodes"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}:routeagent
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
{{- if ne .Values.submariner.globalCidr "" }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:globalnet
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["services", "namespaces", "pods", "nodes"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["clusters", "endpoints", "gateways"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:globalnet
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}:globalnet
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
---
|
||||
{{- end -}}
|
||||
{{- if .Values.submariner.serviceDiscovery }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["services", "namespaces", "configmaps", "endpoints"]
|
||||
verbs: ["get", "list", "watch", "update"]
|
||||
- apiGroups: ["discovery.k8s.io"]
|
||||
resources: ["endpointslices"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete", "deletecollection"]
|
||||
- apiGroups: ["lighthouse.submariner.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||
- apiGroups: ["submariner.io"]
|
||||
resources: ["gateways"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["multicluster.x-k8s.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "delete"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "submariner.fullname" . }}:lighthouse
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -1,82 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
name: {{ template "submariner.fullname" . }}-routeagent
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.fullname" . }}-routeagent
|
||||
component: routeagent
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ template "submariner.fullname" . }}-routeagent
|
||||
updateStrategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: "100%"
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.fullname" . }}-routeagent
|
||||
component: routeagent
|
||||
spec:
|
||||
serviceAccountName: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||
terminationGracePeriodSeconds: 1
|
||||
hostNetwork: true
|
||||
containers:
|
||||
- name: routeagent
|
||||
command:
|
||||
- submariner-route-agent.sh
|
||||
image: {{ .Values.routeAgent.image.repository }}:{{ default .Chart.AppVersion .Values.routeAgent.image.tag }}
|
||||
imagePullPolicy: {{ .Values.routeAgent.image.pullPolicy }}
|
||||
env:
|
||||
- name: SUBMARINER_NAMESPACE
|
||||
value: "{{ .Release.Namespace }}"
|
||||
- name: SUBMARINER_CLUSTERID
|
||||
value: "{{ .Values.submariner.clusterId }}"
|
||||
- name: SUBMARINER_DEBUG
|
||||
value: "{{ .Values.submariner.debug }}"
|
||||
- name: SUBMARINER_CLUSTERCIDR
|
||||
value: "{{ .Values.submariner.clusterCidr }}"
|
||||
- name: SUBMARINER_SERVICECIDR
|
||||
value: "{{ .Values.submariner.serviceCidr }}"
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: "spec.nodeName"
|
||||
resources:
|
||||
{{ toYaml .Values.routeAgent.resources | indent 10 }}
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: true
|
||||
capabilities:
|
||||
add:
|
||||
- ALL
|
||||
privileged: true
|
||||
readOnlyRootFilesystem: false
|
||||
runAsNonRoot: false
|
||||
volumeMounts:
|
||||
# Because we don't actually run iptables locally, but chroot in to the host
|
||||
- mountPath: /host
|
||||
name: host-slash
|
||||
readOnly: true
|
||||
{{- with .Values.routeAgent.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{ toYaml . | indent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.routeAgent.tolerations }}
|
||||
tolerations:
|
||||
{{ toYaml . | indent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.routeAgent.affinity }}
|
||||
affinity:
|
||||
{{ toYaml . | indent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: host-slash
|
||||
hostPath:
|
||||
path: /
|
||||
@@ -1,47 +0,0 @@
|
||||
{{- if .Values.serviceAccounts.engine.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.engineServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.routeAgent.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.routeAgentServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.globalnet.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.globalnetServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
---
|
||||
{{- if .Values.serviceAccounts.lighthouse.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "submariner.lighthouseServiceAccountName" . }}
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
chart: {{ template "submariner.chart" . }}
|
||||
app: {{ template "submariner.name" . }}
|
||||
{{- end }}
|
||||
@@ -1,79 +0,0 @@
|
||||
---
|
||||
submariner:
|
||||
clusterId: ""
|
||||
token: ""
|
||||
clusterCidr: "10.42.0.0/16"
|
||||
serviceCidr: "10.43.0.0/16"
|
||||
globalCidr: ""
|
||||
natEnabled: false
|
||||
colorCodes: blue
|
||||
debug: false
|
||||
serviceDiscovery: false
|
||||
crd:
|
||||
create: true
|
||||
broker:
|
||||
type: k8s
|
||||
server: example.k8s.apiserver
|
||||
token: test
|
||||
namespace: xyz
|
||||
insecure: false
|
||||
ca: ""
|
||||
rbac:
|
||||
create: true
|
||||
ipsec:
|
||||
psk: ""
|
||||
debug: false
|
||||
ikePort: 500
|
||||
natPort: 4500
|
||||
leadership:
|
||||
leaseDuration: 10
|
||||
renewDeadline: 5
|
||||
retryPeriod: 2
|
||||
engine:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner
|
||||
tag: ""
|
||||
pullPolicy: IfNotPresent
|
||||
resources: {}
|
||||
nodeSelectorEnabled: true
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
affinity: {}
|
||||
routeAgent:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-route-agent
|
||||
tag: ""
|
||||
pullPolicy: IfNotPresent
|
||||
resources: {}
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
affinity: {}
|
||||
globalnet:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-globalnet
|
||||
tag: ""
|
||||
pullPolicy: IfNotPresent
|
||||
lighthouse:
|
||||
image:
|
||||
repository: quay.io/submariner/lighthouse-agent
|
||||
tag: ""
|
||||
pullPolicy: IfNotPresent
|
||||
lighthouseCoredns:
|
||||
name: ""
|
||||
image:
|
||||
repository: quay.io/submariner/lighthouse-coredns
|
||||
tag: ""
|
||||
pullPolicy: IfNotPresent
|
||||
serviceAccounts:
|
||||
engine:
|
||||
create: true
|
||||
name: ""
|
||||
routeAgent:
|
||||
create: true
|
||||
name: ""
|
||||
globalnet:
|
||||
create: false
|
||||
name: ""
|
||||
lighthouse:
|
||||
create: false
|
||||
name: ""
|
||||
Reference in New Issue
Block a user