mirror of
https://github.com/submariner-io/submariner-charts.git
synced 2026-09-20 22:40:34 +00:00
Compare commits
@@ -23,11 +23,9 @@ Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
|
||||
**Anything else we need to know?**:
|
||||
|
||||
**Environment**:
|
||||
- Submariner version (use `subctl version`):
|
||||
- Kubernetes version (use `kubectl version`):
|
||||
- Diagnose information (use `subctl diagnose all`):
|
||||
- Gather information (use `subctl gather`):
|
||||
- Cloud provider or hardware configuration:
|
||||
- OS (e.g: `cat /etc/os-release`):
|
||||
- Kernel (e.g. `uname -a`):
|
||||
- Install tools:
|
||||
- Network plugin and version (if this is a network-related bug):
|
||||
- Others:
|
||||
|
||||
@@ -6,7 +6,7 @@ labels: support
|
||||
---
|
||||
|
||||
<!--
|
||||
GitHub may not the right place for support requests.
|
||||
GitHub may not be the right place for support requests.
|
||||
|
||||
You can also post your question on the [Submariner
|
||||
Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
<!-- Thanks for sending a pull request! Here are some tips for you:
|
||||
|
||||
1. If this is your first time, please read our developer guide: https://submariner.io/development/
|
||||
2. Ensure you have added the appropriate tests for your PR: https://submariner.io/development/code-review/#test-new-functionality
|
||||
3. Read the code review guide to ease the review process: https://submariner.io/development/code-review/
|
||||
4. If the PR is unfinished, mark it as a draft: https://submariner.io/development/code-review/#mark-work-in-progress-prs-as-drafts
|
||||
5. If you are using CI to debug, use your private fork: https://submariner.io/development/code-review/#use-private-forks-for-debugging-prs-by-running-ci
|
||||
6. Add labels to the PR as appropriate.
|
||||
|
||||
This template is based on the K8s/K8s template:
|
||||
|
||||
https://github.com/kubernetes/kubernetes/blob/master/.github/PULL_REQUEST_TEMPLATE.md
|
||||
-->
|
||||
+1
-1
@@ -2,7 +2,7 @@
|
||||
# Configuration for probot-stale - https://github.com/probot/stale
|
||||
|
||||
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
|
||||
daysUntilStale: 60
|
||||
daysUntilStale: 120
|
||||
|
||||
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
|
||||
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
|
||||
|
||||
@@ -6,9 +6,9 @@ on:
|
||||
|
||||
jobs:
|
||||
target_devel:
|
||||
name: PR targets devel
|
||||
name: PR targets release-0.11
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check that the PR targets devel
|
||||
if: ${{ github.base_ref != 'devel' }}
|
||||
- name: Check that the PR targets release-0.11
|
||||
if: ${{ github.base_ref != 'release-0.11' }}
|
||||
run: exit 1
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
name: PR Dependencies
|
||||
|
||||
on:
|
||||
issues:
|
||||
types:
|
||||
- opened
|
||||
- edited
|
||||
- closed
|
||||
- reopened
|
||||
- synchronize
|
||||
pull_request_target:
|
||||
types:
|
||||
- opened
|
||||
- edited
|
||||
- closed
|
||||
- reopened
|
||||
- synchronize
|
||||
schedule:
|
||||
- cron: '0 0/6 * * *' # every 6 hours
|
||||
|
||||
jobs:
|
||||
check:
|
||||
name: Check Dependencies
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: z0al/dependent-issues@70a1b2d4ee1cdc743af33498bd0204123953a887
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
with:
|
||||
# The label to use to mark dependent issues
|
||||
label: dependent
|
||||
|
||||
# Enable checking for dependencies in issues.
|
||||
check_issues: on
|
||||
|
||||
# A comma-separated list of keywords to mark dependency.
|
||||
keywords: depends on, Depends on
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
name: End to End Full
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [labeled, opened, synchronize, reopened]
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
if: contains(github.event.pull_request.labels.*.name, 'ready-to-test')
|
||||
timeout-minutes: 45
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
k8s_version: ['1.17']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
include:
|
||||
- k8s_version: '1.18'
|
||||
- k8s_version: '1.19'
|
||||
- k8s_version: '1.20'
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
|
||||
with:
|
||||
k8s_version: ${{ matrix.k8s_version }}
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
|
||||
@@ -1,5 +1,5 @@
|
||||
---
|
||||
name: End to End Tests
|
||||
name: End to End Default
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
@@ -9,28 +9,13 @@ jobs:
|
||||
name: E2E
|
||||
timeout-minutes: 30
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard']
|
||||
globalnet: ['', 'globalnet']
|
||||
k8s_version: ['1.17.17']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
include:
|
||||
# Recentness of K8s versions are limited by kindest/node image releases
|
||||
- k8s_version: 1.18.15
|
||||
- k8s_version: 1.19.7
|
||||
- k8s_version: 1.20.2
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||
with:
|
||||
k8s_version: ${{ matrix.k8s_version }}
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
|
||||
|
||||
@@ -8,23 +8,24 @@ on:
|
||||
jobs:
|
||||
e2e:
|
||||
name: E2E
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
timeout-minutes: 30
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
cable_driver: ['libreswan', 'wireguard']
|
||||
cable_driver: ['libreswan', 'wireguard', 'vxlan']
|
||||
globalnet: ['', 'globalnet']
|
||||
lighthouse: ['', 'lighthouse']
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
|
||||
- name: Run E2E deployment and tests
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@devel
|
||||
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
|
||||
with:
|
||||
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
|
||||
|
||||
- name: Post mortem
|
||||
if: failure()
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
|
||||
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
|
||||
|
||||
@@ -5,26 +5,77 @@ on:
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
apply-suggestions-commits:
|
||||
name: 'No "Apply suggestions from code review" Commits'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Get PR commits
|
||||
id: 'get-pr-commits'
|
||||
uses: tim-actions/get-pr-commits@55b867b9b28954e6f5c1a0fe2f729dc926c306d0
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: 'Verify no "Apply suggestions from code review" commits'
|
||||
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
|
||||
with:
|
||||
commits: ${{ steps.get-pr-commits.outputs.commits }}
|
||||
pattern: '^(?!.*(apply suggestions from code review))'
|
||||
flags: 'i'
|
||||
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
|
||||
|
||||
chart-testing:
|
||||
name: Helm Chart Linting
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@18bc76811624f360dbd7f18c2d4ecb32c7b87bab
|
||||
with:
|
||||
version: v3.6.0
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@dc73133d4da04e56a135ae2246682783cc7c7cb6
|
||||
with:
|
||||
python-version: '3.x'
|
||||
|
||||
- name: Set up helm/chart-testing
|
||||
uses: helm/chart-testing-action@5f16c27cf7a4fa9c776ff73734df3909b2b65127
|
||||
|
||||
- name: Run helm/chart-testing (lint)
|
||||
run: ct lint --config ct.yaml
|
||||
|
||||
gitlint:
|
||||
name: Commit Message(s)
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Run gitlint
|
||||
run: make gitlint
|
||||
|
||||
helm-docs:
|
||||
name: Helm Docs Generation
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
|
||||
- name: Run helm-docs and verify docs are up-to-date
|
||||
run: make helm-docs
|
||||
|
||||
markdown-link-check:
|
||||
name: Markdown Links (modified files)
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
check-modified-files-only: "yes"
|
||||
@@ -35,7 +86,7 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
- name: Run markdownlint
|
||||
run: make markdownlint
|
||||
|
||||
@@ -44,9 +95,10 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
- name: Run yamllint
|
||||
uses: ibiqlik/action-yamllint@v1
|
||||
uses: ibiqlik/action-yamllint@ed2b6e911569708ed121c14b87d513860a7e36a7
|
||||
with:
|
||||
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
|
||||
config_file: .yamllint.yml
|
||||
strict: true
|
||||
|
||||
@@ -8,19 +8,20 @@ on:
|
||||
jobs:
|
||||
markdown-link-check-periodic:
|
||||
name: Markdown Links (all files)
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out the repository
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
|
||||
- name: Run markdown-link-check
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@v1
|
||||
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
|
||||
with:
|
||||
config-file: ".markdownlinkcheck.json"
|
||||
|
||||
- name: Raise an Issue to report broken links
|
||||
if: ${{ failure() }}
|
||||
uses: peter-evans/create-issue-from-file@v2.3.2
|
||||
uses: peter-evans/create-issue-from-file@97e6f902a416aac38834e23fa52e166aad0437d2
|
||||
with:
|
||||
title: Broken link detected by CI
|
||||
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
|
||||
|
||||
@@ -4,15 +4,16 @@ name: Release Charts
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- devel
|
||||
- release-0.11
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Release
|
||||
if: github.repository_owner == 'submariner-io'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v2
|
||||
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
[general]
|
||||
# body-is-missing: Allow commit messages with only a title
|
||||
# body-min-length: Allow short body lines, like "Relates-to: #issue"
|
||||
ignore=body-is-missing,body-min-length
|
||||
|
||||
[ignore-by-body]
|
||||
# Dependabot doesn't follow our conventions, unfortunately
|
||||
regex=^Signed-off-by: dependabot\[bot\](.*)
|
||||
ignore=all
|
||||
@@ -5,6 +5,9 @@
|
||||
},
|
||||
{
|
||||
"pattern": "^http://localhost:"
|
||||
},
|
||||
{
|
||||
"pattern": "^https://submariner-io.github.io/submariner-charts/charts"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -10,3 +10,7 @@ line-length:
|
||||
no-inline-html:
|
||||
allowed_elements:
|
||||
- span
|
||||
|
||||
# Temporary while helm-docs has a bug where maintainer URLs are used raw in MD
|
||||
# Waiting on: https://github.com/norwoodj/helm-docs/pull/102
|
||||
no-bare-urls: false
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
label-approved:
|
||||
approvals: 2
|
||||
label: ready-to-test
|
||||
+1
-1
@@ -1 +1 @@
|
||||
* @mangelajo @Oats87 @skitt @tpantelis
|
||||
* @mangelajo @Oats87 @skitt @sridhargaddam @tpantelis
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
BASE_BRANCH ?= devel
|
||||
BASE_BRANCH ?= release-0.11
|
||||
export BASE_BRANCH
|
||||
|
||||
ifneq (,$(DAPPER_HOST_ARCH))
|
||||
@@ -21,7 +21,8 @@ override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
|
||||
export DEPLOY_ARGS
|
||||
GH_URL=https://submariner-io.github.io/submariner-charts/charts
|
||||
CHARTS_DIR=charts
|
||||
CHARTS_VERSION=0.7.0
|
||||
CHARTS_VERSION=0.11.0
|
||||
HELM_DOCS_VERSION=0.15.0
|
||||
REPO_URL=$(shell git config remote.origin.url)
|
||||
|
||||
# Process extra flags from the `using=a,b,c` optional flag
|
||||
@@ -42,6 +43,20 @@ e2e: E2E_ARGS=cluster1 cluster2
|
||||
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
|
||||
|
||||
helm-docs:
|
||||
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
|
||||
cd /tmp && \
|
||||
curl -sL https://github.com/norwoodj/helm-docs/releases/download/v$(HELM_DOCS_VERSION)/helm-docs_$(HELM_DOCS_VERSION)_Linux_x86_64.tar.gz | tar zx && \
|
||||
cd -
|
||||
/tmp/helm-docs
|
||||
if [ ! -z $(git status --porcelain) ]; then \
|
||||
echo "Helm docs not up-to-date:"; \
|
||||
git status --porcelain; \
|
||||
git diff; \
|
||||
echo "Run make helm-docs locally to generate updated docs, commit the updates."; \
|
||||
exit 1; \
|
||||
fi
|
||||
|
||||
release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
|
||||
git checkout gh-pages
|
||||
mv *.tgz $(CHARTS_DIR)
|
||||
@@ -51,7 +66,7 @@ release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHART
|
||||
helm repo index $(CHARTS_DIR) --url $(GH_URL); \
|
||||
fi
|
||||
|
||||
.PHONY: release
|
||||
.PHONY: release helm-docs
|
||||
|
||||
else
|
||||
|
||||
|
||||
@@ -1,5 +1,12 @@
|
||||
# submariner-charts
|
||||
|
||||
<!-- markdownlint-disable line-length -->
|
||||
[](https://bestpractices.coreinfrastructure.org/projects/4865)
|
||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Release+Charts%22)
|
||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic)
|
||||
[](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Flake+Finder%22)
|
||||
<!-- markdownlint-enable line-length -->
|
||||
|
||||
Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/).
|
||||
|
||||
## Development workflow
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
charts:
|
||||
- submariner-operator
|
||||
- submariner-k8s-broker
|
||||
# Tests that maintainer name is valid GitHub account, which isn't what we want
|
||||
# See: https://github.com/helm/chart-testing/issues/192
|
||||
validate-maintainers: false
|
||||
@@ -1,12 +1,14 @@
|
||||
---
|
||||
name: submariner-k8s-broker
|
||||
version: 0.6.0
|
||||
apiVersion: v2
|
||||
appVersion: 0.6.0
|
||||
description: Submariner Kubernetes Broker
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
sources:
|
||||
- https://submariner-io.github.io/submariner-charts/charts
|
||||
- https://submariner-io.github.io/submariner-charts/charts
|
||||
maintainers:
|
||||
- name: Submariner Developers
|
||||
email: submariner-dev@googlegroups.com
|
||||
- name: Contributors to the Submariner project
|
||||
email: submariner-dev@googlegroups.com
|
||||
url: https://submariner.io/
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
# submariner-k8s-broker
|
||||
|
||||
 
|
||||
|
||||
Submariner Kubernetes Broker
|
||||
|
||||
**Homepage:** <https://submariner-io.github.io/>
|
||||
|
||||
## Maintainers
|
||||
|
||||
| Name | Email | Url |
|
||||
| ---- | ------ | --- |
|
||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
||||
|
||||
## Source Code
|
||||
|
||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
||||
|
||||
## Values
|
||||
|
||||
| Key | Type | Default | Description |
|
||||
|-----|------|---------|-------------|
|
||||
| crd.create | bool | `true` | |
|
||||
| rbac.create | bool | `true` | |
|
||||
| serviceAccounts.client.create | bool | `true` | |
|
||||
| serviceAccounts.client.name | string | `""` | |
|
||||
@@ -2,7 +2,7 @@
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||
labels:
|
||||
heritage: {{ .Release.Service | quote }}
|
||||
release: {{ .Release.Name | quote }}
|
||||
@@ -16,7 +16,7 @@ rules:
|
||||
resources: ["*"]
|
||||
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
|
||||
- apiGroups: ["discovery.k8s.io"]
|
||||
resources: ["endpointslices"]
|
||||
resources: ["endpointslices", "endpointslices/restricted"]
|
||||
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
|
||||
- apiGroups: ["multicluster.x-k8s.io"]
|
||||
resources: ["*"]
|
||||
@@ -25,13 +25,13 @@ rules:
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}:client
|
||||
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
@@ -1,12 +1,14 @@
|
||||
---
|
||||
name: submariner-operator
|
||||
version: 0.7.0
|
||||
appVersion: 0.7.0
|
||||
version: 0.11.0
|
||||
apiVersion: v2
|
||||
appVersion: 0.11.0
|
||||
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
keywords:
|
||||
home: https://submariner-io.github.io/
|
||||
sources:
|
||||
- https://submariner-io.github.io/submariner-charts/charts
|
||||
maintainers:
|
||||
- name: Submariner Developers
|
||||
- name: Contributors to the Submariner project
|
||||
email: submariner-dev@googlegroups.com
|
||||
url: https://submariner.io/
|
||||
|
||||
@@ -0,0 +1,71 @@
|
||||
# submariner-operator
|
||||
|
||||
 
|
||||
|
||||
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
|
||||
|
||||
**Homepage:** <https://submariner-io.github.io/>
|
||||
|
||||
## Maintainers
|
||||
|
||||
| Name | Email | Url |
|
||||
| ---- | ------ | --- |
|
||||
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
|
||||
|
||||
## Source Code
|
||||
|
||||
* <https://submariner-io.github.io/submariner-charts/charts>
|
||||
|
||||
## Values
|
||||
|
||||
| Key | Type | Default | Description |
|
||||
|-----|------|---------|-------------|
|
||||
| broker.ca | string | `""` | |
|
||||
| broker.globalnet | bool | `false` | |
|
||||
| broker.insecure | bool | `false` | |
|
||||
| broker.namespace | string | `"xyz"` | |
|
||||
| broker.server | string | `"example.k8s.apiserver"` | |
|
||||
| broker.token | string | `"test"` | |
|
||||
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
|
||||
| gateway.image.tag | string | `"0.11.0"` | |
|
||||
| ipsec.debug | bool | `false` | |
|
||||
| ipsec.forceUDPEncaps | bool | `false` | |
|
||||
| ipsec.ikePort | int | `500` | |
|
||||
| ipsec.natPort | int | `4500` | |
|
||||
| ipsec.psk | string | `""` | |
|
||||
| leadership.leaseDuration | int | `10` | |
|
||||
| leadership.renewDeadline | int | `5` | |
|
||||
| leadership.retryPeriod | int | `2` | |
|
||||
| operator.affinity | object | `{}` | |
|
||||
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
|
||||
| operator.image.tag | string | `"0.11.0"` | |
|
||||
| operator.resources | object | `{}` | |
|
||||
| operator.tolerations | list | `[]` | |
|
||||
| rbac.create | bool | `true` | |
|
||||
| serviceAccounts.gateway.create | bool | `true` | |
|
||||
| serviceAccounts.gateway.name | string | `""` | |
|
||||
| serviceAccounts.globalnet.create | bool | `true` | |
|
||||
| serviceAccounts.globalnet.name | string | `""` | |
|
||||
| serviceAccounts.lighthouseAgent.create | bool | `true` | |
|
||||
| serviceAccounts.lighthouseAgent.name | string | `""` | |
|
||||
| serviceAccounts.lighthouseCoreDns.create | bool | `true` | |
|
||||
| serviceAccounts.lighthouseCoreDns.name | string | `""` | |
|
||||
| serviceAccounts.operator.create | bool | `true` | |
|
||||
| serviceAccounts.operator.name | string | `""` | |
|
||||
| serviceAccounts.routeAgent.create | bool | `true` | |
|
||||
| serviceAccounts.routeAgent.name | string | `""` | |
|
||||
| submariner.cableDriver | string | `"libreswan"` | |
|
||||
| submariner.clusterCidr | string | `""` | |
|
||||
| submariner.clusterId | string | `""` | |
|
||||
| submariner.colorCodes | string | `"blue"` | |
|
||||
| submariner.coreDNSCustomConfig | object | `{}` | |
|
||||
| submariner.debug | bool | `false` | |
|
||||
| submariner.globalCidr | string | `""` | |
|
||||
| submariner.healthcheckEnabled | bool | `true` | |
|
||||
| submariner.images.repository | string | `"quay.io/submariner"` | |
|
||||
| submariner.images.tag | string | `"0.11.0"` | |
|
||||
| submariner.natEnabled | bool | `false` | |
|
||||
| submariner.serviceCidr | string | `""` | |
|
||||
| submariner.serviceDiscovery | bool | `true` | |
|
||||
| submariner.token | string | `""` | |
|
||||
@@ -13,7 +13,7 @@ questions:
|
||||
type: string
|
||||
label: Submariner Operator Image Repository
|
||||
- variable: operator.image.tag
|
||||
default: "0.7.0"
|
||||
default: "0.11.0"
|
||||
description: "Submariner Operator Image Tag"
|
||||
type: string
|
||||
label: Submariner Operator Image Tag
|
||||
@@ -31,7 +31,7 @@ questions:
|
||||
type: string
|
||||
label: Submariner Repository
|
||||
- variable: submariner.images.tag
|
||||
default: "0.7.0"
|
||||
default: "0.11.0"
|
||||
description: "Submariner Images Tag (shared for all non-operator images)"
|
||||
type: string
|
||||
label: Submariner Images Tag
|
||||
@@ -136,3 +136,9 @@ questions:
|
||||
group: "Advanced Configuration"
|
||||
description: "Cable driver implementation"
|
||||
label: "Cable Driver"
|
||||
- variable: submariner.healthcheckEnabled
|
||||
type: boolean
|
||||
default: true
|
||||
group: "Advanced Configuration"
|
||||
description: "Disable Healthcheck"
|
||||
label: "Healthcheck Disabled"
|
||||
|
||||
@@ -397,6 +397,7 @@ rules:
|
||||
resources:
|
||||
- configmaps
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
@@ -411,11 +412,13 @@ rules:
|
||||
- create
|
||||
- update
|
||||
- delete
|
||||
- apiGroups: # pods and services are looked up to figure out network settings
|
||||
- watch
|
||||
- apiGroups: # pods, services and nodes are looked up to figure out network settings
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- nodes
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
@@ -654,6 +657,29 @@ rules:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- clusterglobalegressips
|
||||
- globalegressips
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- apiGroups:
|
||||
- submariner.io
|
||||
resources:
|
||||
- globalingressips
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- delete
|
||||
- deletecollection
|
||||
- apiGroups:
|
||||
- multicluster.x-k8s.io
|
||||
resources:
|
||||
@@ -708,6 +734,7 @@ rules:
|
||||
- discovery.k8s.io
|
||||
resources:
|
||||
- endpointslices
|
||||
- endpointslices/restricted
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
@@ -720,6 +747,7 @@ rules:
|
||||
- submariner.io
|
||||
resources:
|
||||
- "gateways"
|
||||
- "globalingressips"
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
|
||||
@@ -10,6 +10,7 @@ spec:
|
||||
brokerK8sCA: {{ .Values.broker.ca }}
|
||||
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
|
||||
ceIPSecDebug: {{ .Values.ipsec.debug }}
|
||||
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
|
||||
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
|
||||
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
|
||||
ceIPSecPSK: {{ .Values.ipsec.psk }}
|
||||
@@ -25,3 +26,12 @@ spec:
|
||||
globalCIDR: "{{ .Values.submariner.globalCidr }}"
|
||||
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
|
||||
cableDriver: {{ .Values.submariner.cableDriver }}
|
||||
connectionHealthCheck:
|
||||
enabled: {{ .Values.submariner.healthcheckEnabled }}
|
||||
intervalSeconds: 1
|
||||
maxPacketLossCount: 5
|
||||
{{- with .Values.submariner.coreDNSCustomConfig }}
|
||||
coreDNSCustomConfig:
|
||||
configmapName: .configmapName
|
||||
namespace: .namespace
|
||||
{{- end }}
|
||||
|
||||
@@ -10,9 +10,11 @@ submariner:
|
||||
debug: false
|
||||
serviceDiscovery: true
|
||||
cableDriver: "libreswan"
|
||||
healthcheckEnabled: true
|
||||
coreDNSCustomConfig: {}
|
||||
images:
|
||||
repository: quay.io/submariner
|
||||
tag: "0.7.0"
|
||||
tag: "0.11.0"
|
||||
broker:
|
||||
server: example.k8s.apiserver
|
||||
token: test
|
||||
@@ -25,6 +27,7 @@ rbac:
|
||||
ipsec:
|
||||
psk: ""
|
||||
debug: false
|
||||
forceUDPEncaps: false
|
||||
ikePort: 500
|
||||
natPort: 4500
|
||||
leadership:
|
||||
@@ -34,7 +37,7 @@ leadership:
|
||||
operator:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-operator
|
||||
tag: "0.7.0"
|
||||
tag: "0.11.0"
|
||||
pullPolicy: IfNotPresent
|
||||
resources: {}
|
||||
tolerations: []
|
||||
@@ -42,7 +45,7 @@ operator:
|
||||
gateway:
|
||||
image:
|
||||
repository: quay.io/submariner/submariner-gateway
|
||||
tag: "0.7.0"
|
||||
tag: "0.11.0"
|
||||
serviceAccounts:
|
||||
operator:
|
||||
create: true
|
||||
|
||||
Reference in New Issue
Block a user