Compare commits

...
42 Commits
Author SHA1 Message Date
Stephen KittandThomas Pantelis 12c3cbe928 Bump to 0.11.0
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-10-28 08:26:13 -04:00
Vishal ThaparandStephen Kitt 06ce316138 Fix connectionHealthCheck
connectionHealthCheck in submariner CR is a nested field
but is being added as a variable. This means it is ignored
and the field isn't set correctly in gateway pods.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-10-28 11:05:40 +02:00
Aswin SurayanarayananandThomas Pantelis 27eb25c8f6 Add RBAC permission endpointslices/restricted in broker roles
Fixes : github.com/submariner-io/lighthouse/issues#627

Signed-off-by: Aswin Surayanarayanan <asuryana@redhat.com>
2021-10-26 08:53:15 -04:00
5cc6ec47de Update submariner-operator/questions.yml
Co-authored-by: Sridhar Gaddam <sgaddam@redhat.com>
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 9fcea9930c Update Readme.md
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis c1ce210c89 Add ceIPSecForceUDPEncaps & coreDNSCustomConfig variables
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 7d8bf6a3ac Add enable/disable connectionHealthCheck
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Victor Godoy HernándezandThomas Pantelis 4cf74cfc3b Bump up to 0.10.1
Signed-off-by: Victor  Godoy Hernández <vigohe@gmail.com>
2021-10-26 08:34:24 -04:00
Automated Release 14e85ad476 Update base image to use stable branch 'release-0.11'
Signed-off-by: Automated Release <release@submariner.io>
2021-10-20 07:36:16 +00:00
Vishal ThaparandStephen Kitt 6b7fed425a Add endpontslices/restricted to lighthouse-agent
Fixes: submariner-io/lighthouse#627

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-10-19 16:22:31 +02:00
Stephen KittandThomas Pantelis ea1df8ed54 Add Sridhar Gaddam as code owner
... since he is now a project administrator, as voted on the mailing list.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-10-01 12:32:51 -04:00
Daniel FarrellandThomas Pantelis 2788692ffc Update create-issue-from-file GHA 2.3.2 to 3.0.0
Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-09-14 08:00:47 -04:00
Daniel FarrellandThomas Pantelis 87390b6e5d Enable strict YAML linting
Fail yamllint on warnings, as we do with other repos.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-09-10 08:32:45 -04:00
Daniel FarrellandThomas Pantelis 47a7aec05d Update ibiqlik/action-yamllint GHA 1.0.0 to 3.0.4
Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-09-09 17:26:16 -04:00
Daniel FarrellandThomas Pantelis eea398da4e Use SHAs for GHA versions
Per GitHub's security guidelines, GHAs should be pinned using full
length commit SHAs instead of tags.

The SHAs are of the commits currently resolved by the versions.

Even "trusted" GHAs from GitHub developers are pinned because it's
possible their repo rights could be compromised and a malicious GHA
published. These core repos are not frequently substantially updated.

Submariner-internal GHAs are left pinned at devel because we want
automatic updates from Shipyard's shared tooling.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-08-24 08:18:22 -04:00
Daniel FarrellandDaniel Farrell 50489802e2 Don't run periodic PR dependency checks on forks
As we do with the Flake Finder and other periodic jobs, skip the checks
for PR dependencies on forks.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-08-09 16:39:00 -04:00
Janki ChhatbarandGitHub cb78ab7aaa Remove duplicated information (#162)
Submariner, k8s, OS and kernel information
are collected as part of `subctl gather`. Don't
ask for them explicitly in bug report.

Signed-off-by: Janki Chhatbar <jchhatba@redhat.com>
2021-07-27 09:47:20 +00:00
Daniel FarrellandDaniel Farrell 2f9156cf34 Extract helm-docs generation/testing to Makefile
Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-07-27 05:00:56 -04:00
Stephen KittandThomas Pantelis 4b48a3d30c Remove project-specific gitlint configuration
We now use Shipyard's gitlint configuration everywhere.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-07-22 22:23:50 -04:00
Janki ChhatbarandDaniel Farrell 78294c1827 Enable PR dependency check jobs
This job marks a PR `dependent` whenever a dependent PR
is mentioned via `Depends on/ depends on` keyword.

The job fails until the dependent PR is not merged. This
helps in properly managing merging of dependent PRs.

Signed-off-by: Janki Chhatbar <jchhatba@redhat.com>
2021-07-22 10:18:28 -04:00
Stephen KittandThomas Pantelis 29c87078b5 Increase days until stale to 120
This gives us a little over a full release to work on issues.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-07-16 15:04:52 -04:00
Vishal ThaparandThomas Pantelis f757a66958 Allow lighthouse-agent access to ingressips
`lighthouse-agent` `ClusterRole` requires access to `globalingressips`
for Globalnetv2 in Lighthouse.

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-07-07 10:04:32 -04:00
Vishal ThaparandMiguel Angel Ajo Pelayo ac4910d36b Fix globalnetv2 ClusterRole
Globalnetv2 requires `globalnet` `ClusterRole` for Egress/IngressIPs
but those were added as `globalnet` `Role` instead. This change
moves the permissions from `Role` to `ClusterRole`

Signed-off-by: Vishal Thapar <5137689+vthapar@users.noreply.github.com>
2021-07-07 13:33:54 +02:00
Daniel FarrellandGitHub 6869b47fc3 Add linter to check no "Apply suggestions" commits (#154)
Add a linting job to verify that no commit message in a PR contains the
case insensitive string "Apply suggestions from code review". Commits
with exactly this title are generated by GitHub automatically when a
batch of proposed changes from code review are accepted from the GitHub
UI. A number of such commits have made it into various Submariner/*
repos.

Commits addressing code review feedback should typically be squashed
into the commits under review, or made into well-commented discrete
commits.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-30 16:26:39 +00:00
Daniel FarrellandGitHub d3fcdc2c57 Add bot config for labeling when approved (#153)
Will configure the submariner-bot to add the /ready-to-test label when a
PR has two approvals, causing the full E2E workflow to run.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-30 13:39:53 +00:00
Daniel FarrellandDaniel Farrell 23968afbef Add helm-docs generation and linting
Generate docs for each chart and verify the committed docs match the
generated docs.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-29 12:14:34 -05:00
Daniel FarrellandDaniel Farrell 90db64f64d Add generated docs for both Helm charts
Add docs generated by helm-docs for each chart. The docs will be kept
up-to-date with CI and the contents of the docs can be improved in
future changes to inline commenting.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-29 12:14:34 -05:00
Daniel FarrellandDaniel Farrell 4f5b617ae7 Ignore raw URLs in MDlint pending helm-docs bugfix
The maintainers table generated by helm-docs includes a raw URL in
Markdown, which fails markdownlint. I sent a PR upstream to fix the root
of the issue, but for now we have to disable this linter rule.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-29 12:14:34 -05:00
Daniel FarrellandDaniel Farrell 06504b84d6 Ignore charts repo URL in MD link checking
Somehow the GitHub Pages URL we use to publish and install the charts
works to install the charts in CI but also fails with a 404 in CI.

The URL is successfully used by Shipyard here:

https://github.com/submariner-io/shipyard/blob/
33dc2ffdadf6e520a2101368f7f7456c031bace0/scripts/shared/lib/
deploy_helm#L14

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-29 12:14:34 -05:00
Sridhar GaddamandThomas Pantelis cff6e76f98 Add roles to access new Globalnet 2.0 objects
Signed-Off-by: Sridhar Gaddam <sgaddam@redhat.com>
2021-06-28 11:55:55 -04:00
Daniel FarrellandStephen Kitt 97782b4bb4 Split E2E into default and full
Following the pattern from other repos, split the E2E test job into a
default job that runs a single default-only test always on PRs and a
full job that runs the full matrix when the ready-to-test label is
added.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-22 15:10:19 +02:00
Daniel FarrellandDaniel Farrell 2938f26520 Add helm/chart-testing linting
Fixes: #68
Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-21 08:14:04 -05:00
Daniel FarrellandDaniel Farrell c8b09b5c31 Name RBAC fields to match K8s requirements
The colon in these field names isn't allowed by K8s, and fails ct
linting. Use the new names from submariner-operator, which have already
been renamed to fix this.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-21 08:14:04 -05:00
Daniel FarrellandDaniel Farrell df86353f4b Add required apiVersion field to Chart.yaml
This field is required by standard chart schemas. It should be v2 for
Charts that support Helm v3, as we do.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-21 08:14:04 -05:00
Daniel FarrellandDaniel Farrell b0cdd50077 Use CNCF-wording for maintainers
Use copyright notice wording required by CNCF for the maintainers field
for both Chart.yaml files.

Also fix an indentation error in one Chart.yaml file.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-06-21 08:14:04 -05:00
Janki ChhatbarandThomas Pantelis 69ff334c72 Add vxlan cable driver to test matrix
Signed-Off-By: Janki Chhatbar <jchhatba@redhat.com>
2021-06-14 09:15:16 -04:00
Stephen KittandThomas Pantelis df9a462b9b Use short Kubernetes versions
Signed-off-by: Stephen Kitt <skitt@redhat.com>
2021-06-01 22:25:17 -04:00
Steve MattarandDaniel Farrell 12c8e9b3ff fix(rbac): add missing cluster roles to submariner-operator
Signed-off-by: Steve Mattar <smattar@redhat.com>
2021-05-24 14:40:13 -05:00
Daniel FarrellandThomas Pantelis 55b0610620 Add pull request template
Add a template for PRs with tips and pointers to docs.

This completes a recommendation of the CII Best Practices program:

> It is SUGGESTED that this policy on adding tests (see test_policy) be
documented in the instructions for change proposals.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-05-20 12:34:36 -04:00
Daniel FarrellandMiguel Angel Ajo Pelayo 4b52dc668e Add CII and merged-CI badges to README
Add Submariner's CII Best Practices badge to the README.

Add badges for workflows run against merged code.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2021-05-20 12:50:16 +02:00
Mike KolesnikandThomas Pantelis 6f94f29563 Don't run certain GHA jobs on forks
Don't run jobs that aren't triggered on pull request on forks.
Forks aren't likely to need these jobs, and theyre more likely to fail
there.

Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2021-05-12 07:35:11 -04:00
nyechielandThomas Pantelis f0a0ae93bf Fix a typo in support issue template
Signed-off-by: nyechiel <nyechiel@redhat.com>
2021-05-03 09:29:11 -04:00
29 changed files with 377 additions and 73 deletions
+2 -4
View File
@@ -23,11 +23,9 @@ Submariner Owners: https://github.com/orgs/submariner-io/teams/submariner-core
**Anything else we need to know?**:
**Environment**:
- Submariner version (use `subctl version`):
- Kubernetes version (use `kubectl version`):
- Diagnose information (use `subctl diagnose all`):
- Gather information (use `subctl gather`):
- Cloud provider or hardware configuration:
- OS (e.g: `cat /etc/os-release`):
- Kernel (e.g. `uname -a`):
- Install tools:
- Network plugin and version (if this is a network-related bug):
- Others:
+1 -1
View File
@@ -6,7 +6,7 @@ labels: support
---
<!--
GitHub may not the right place for support requests.
GitHub may not be the right place for support requests.
You can also post your question on the [Submariner
Slack](https://kubernetes.slack.com/archives/C010RJV694M) or the Submariner
+13
View File
@@ -0,0 +1,13 @@
<!-- Thanks for sending a pull request! Here are some tips for you:
1. If this is your first time, please read our developer guide: https://submariner.io/development/
2. Ensure you have added the appropriate tests for your PR: https://submariner.io/development/code-review/#test-new-functionality
3. Read the code review guide to ease the review process: https://submariner.io/development/code-review/
4. If the PR is unfinished, mark it as a draft: https://submariner.io/development/code-review/#mark-work-in-progress-prs-as-drafts
5. If you are using CI to debug, use your private fork: https://submariner.io/development/code-review/#use-private-forks-for-debugging-prs-by-running-ci
6. Add labels to the PR as appropriate.
This template is based on the K8s/K8s template:
https://github.com/kubernetes/kubernetes/blob/master/.github/PULL_REQUEST_TEMPLATE.md
-->
+1 -1
View File
@@ -2,7 +2,7 @@
# Configuration for probot-stale - https://github.com/probot/stale
# Number of days of inactivity before an Issue becomes stale (pull request is overridden later)
daysUntilStale: 60
daysUntilStale: 120
# Number of days of inactivity before an Issue or Pull Request with the stale label is closed.
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
+3 -3
View File
@@ -6,9 +6,9 @@ on:
jobs:
target_devel:
name: PR targets devel
name: PR targets release-0.11
runs-on: ubuntu-latest
steps:
- name: Check that the PR targets devel
if: ${{ github.base_ref != 'devel' }}
- name: Check that the PR targets release-0.11
if: ${{ github.base_ref != 'release-0.11' }}
run: exit 1
+39
View File
@@ -0,0 +1,39 @@
---
name: PR Dependencies
on:
issues:
types:
- opened
- edited
- closed
- reopened
- synchronize
pull_request_target:
types:
- opened
- edited
- closed
- reopened
- synchronize
schedule:
- cron: '0 0/6 * * *' # every 6 hours
jobs:
check:
name: Check Dependencies
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
steps:
- uses: z0al/dependent-issues@70a1b2d4ee1cdc743af33498bd0204123953a887
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
# The label to use to mark dependent issues
label: dependent
# Enable checking for dependencies in issues.
check_issues: on
# A comma-separated list of keywords to mark dependency.
keywords: depends on, Depends on
+37
View File
@@ -0,0 +1,37 @@
---
name: End to End Full
on:
pull_request:
types: [labeled, opened, synchronize, reopened]
jobs:
e2e:
name: E2E
if: contains(github.event.pull_request.labels.*.name, 'ready-to-test')
timeout-minutes: 45
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet']
k8s_version: ['1.17']
lighthouse: ['', 'lighthouse']
include:
- k8s_version: '1.18'
- k8s_version: '1.19'
- k8s_version: '1.20'
steps:
- name: Check out the repository
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
with:
k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+4 -19
View File
@@ -1,5 +1,5 @@
---
name: End to End Tests
name: End to End Default
on:
pull_request:
@@ -9,28 +9,13 @@ jobs:
name: E2E
timeout-minutes: 30
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
cable_driver: ['libreswan', 'wireguard']
globalnet: ['', 'globalnet']
k8s_version: ['1.17.17']
lighthouse: ['', 'lighthouse']
include:
# Recentness of K8s versions are limited by kindest/node image releases
- k8s_version: 1.18.15
- k8s_version: 1.19.7
- k8s_version: 1.20.2
steps:
- name: Check out the repository
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel
with:
k8s_version: ${{ matrix.k8s_version }}
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+5 -4
View File
@@ -8,23 +8,24 @@ on:
jobs:
e2e:
name: E2E
if: github.repository_owner == 'submariner-io'
timeout-minutes: 30
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
cable_driver: ['libreswan', 'wireguard']
cable_driver: ['libreswan', 'wireguard', 'vxlan']
globalnet: ['', 'globalnet']
lighthouse: ['', 'lighthouse']
steps:
- name: Check out the repository
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run E2E deployment and tests
uses: submariner-io/shipyard/gh-actions/e2e@devel
uses: submariner-io/shipyard/gh-actions/e2e@release-0.11
with:
using: ${{ matrix.cable_driver }} ${{ matrix.globalnet }} ${{ matrix.lighthouse }}
- name: Post mortem
if: failure()
uses: submariner-io/shipyard/gh-actions/post-mortem@devel
uses: submariner-io/shipyard/gh-actions/post-mortem@release-0.11
+58 -6
View File
@@ -5,26 +5,77 @@ on:
pull_request:
jobs:
apply-suggestions-commits:
name: 'No "Apply suggestions from code review" Commits'
runs-on: ubuntu-latest
steps:
- name: Get PR commits
id: 'get-pr-commits'
uses: tim-actions/get-pr-commits@55b867b9b28954e6f5c1a0fe2f729dc926c306d0
with:
token: ${{ secrets.GITHUB_TOKEN }}
- name: 'Verify no "Apply suggestions from code review" commits'
uses: tim-actions/commit-message-checker-with-regex@d6d9770051dd6460679d1cab1dcaa8cffc5c2bbd
with:
commits: ${{ steps.get-pr-commits.outputs.commits }}
pattern: '^(?!.*(apply suggestions from code review))'
flags: 'i'
error: 'Commits addressing code review feedback should typically be squashed into the commits under review'
chart-testing:
name: Helm Chart Linting
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Set up Helm
uses: azure/setup-helm@18bc76811624f360dbd7f18c2d4ecb32c7b87bab
with:
version: v3.6.0
- name: Set up Python
uses: actions/setup-python@dc73133d4da04e56a135ae2246682783cc7c7cb6
with:
python-version: '3.x'
- name: Set up helm/chart-testing
uses: helm/chart-testing-action@5f16c27cf7a4fa9c776ff73734df3909b2b65127
- name: Run helm/chart-testing (lint)
run: ct lint --config ct.yaml
gitlint:
name: Commit Message(s)
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
with:
fetch-depth: 0
- name: Run gitlint
run: make gitlint
helm-docs:
name: Helm Docs Generation
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run helm-docs and verify docs are up-to-date
run: make helm-docs
markdown-link-check:
name: Markdown Links (modified files)
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@v1
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
with:
config-file: ".markdownlinkcheck.json"
check-modified-files-only: "yes"
@@ -35,7 +86,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdownlint
run: make markdownlint
@@ -44,9 +95,10 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run yamllint
uses: ibiqlik/action-yamllint@v1
uses: ibiqlik/action-yamllint@ed2b6e911569708ed121c14b87d513860a7e36a7
with:
file_or_dir: submariner-k8s-broker/Chart.yaml submariner-k8s-broker/values.yaml submariner-operator/Chart.yaml submariner-operator/values.yaml
config_file: .yamllint.yml
strict: true
+4 -3
View File
@@ -8,19 +8,20 @@ on:
jobs:
markdown-link-check-periodic:
name: Markdown Links (all files)
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
steps:
- name: Check out the repository
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
- name: Run markdown-link-check
uses: gaurav-nelson/github-action-markdown-link-check@v1
uses: gaurav-nelson/github-action-markdown-link-check@9710f0fec812ce0a3b98bef4c9d842fc1f39d976
with:
config-file: ".markdownlinkcheck.json"
- name: Raise an Issue to report broken links
if: ${{ failure() }}
uses: peter-evans/create-issue-from-file@v2.3.2
uses: peter-evans/create-issue-from-file@97e6f902a416aac38834e23fa52e166aad0437d2
with:
title: Broken link detected by CI
content-filepath: .github/ISSUE_TEMPLATE/broken-link.md
+3 -2
View File
@@ -4,15 +4,16 @@ name: Release Charts
on:
push:
branches:
- devel
- release-0.11
jobs:
release:
name: Release
if: github.repository_owner == 'submariner-io'
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@5a4ac9002d0be2fb38bd78e4b4dbde5606d7042f
with:
fetch-depth: 0
-9
View File
@@ -1,9 +0,0 @@
[general]
# body-is-missing: Allow commit messages with only a title
# body-min-length: Allow short body lines, like "Relates-to: #issue"
ignore=body-is-missing,body-min-length
[ignore-by-body]
# Dependabot doesn't follow our conventions, unfortunately
regex=^Signed-off-by: dependabot\[bot\](.*)
ignore=all
+3
View File
@@ -5,6 +5,9 @@
},
{
"pattern": "^http://localhost:"
},
{
"pattern": "^https://submariner-io.github.io/submariner-charts/charts"
}
]
}
+4
View File
@@ -10,3 +10,7 @@ line-length:
no-inline-html:
allowed_elements:
- span
# Temporary while helm-docs has a bug where maintainer URLs are used raw in MD
# Waiting on: https://github.com/norwoodj/helm-docs/pull/102
no-bare-urls: false
+3
View File
@@ -0,0 +1,3 @@
label-approved:
approvals: 2
label: ready-to-test
+1 -1
View File
@@ -1 +1 @@
* @mangelajo @Oats87 @skitt @tpantelis
* @mangelajo @Oats87 @skitt @sridhargaddam @tpantelis
+18 -3
View File
@@ -1,4 +1,4 @@
BASE_BRANCH ?= devel
BASE_BRANCH ?= release-0.11
export BASE_BRANCH
ifneq (,$(DAPPER_HOST_ARCH))
@@ -21,7 +21,8 @@ override DEPLOY_ARGS += $(CLUSTER_SETTINGS_FLAG) --deploytool helm
export DEPLOY_ARGS
GH_URL=https://submariner-io.github.io/submariner-charts/charts
CHARTS_DIR=charts
CHARTS_VERSION=0.7.0
CHARTS_VERSION=0.11.0
HELM_DOCS_VERSION=0.15.0
REPO_URL=$(shell git config remote.origin.url)
# Process extra flags from the `using=a,b,c` optional flag
@@ -42,6 +43,20 @@ e2e: E2E_ARGS=cluster1 cluster2
helm dep update $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm package --version $(CHARTS_VERSION) $(subst -$(CHARTS_VERSION),,$(basename $(@F)))
helm-docs:
# Avoid polluting repo with helm-docs' README/LICENSE or other files in the release archive
cd /tmp && \
curl -sL https://github.com/norwoodj/helm-docs/releases/download/v$(HELM_DOCS_VERSION)/helm-docs_$(HELM_DOCS_VERSION)_Linux_x86_64.tar.gz | tar zx && \
cd -
/tmp/helm-docs
if [ ! -z $(git status --porcelain) ]; then \
echo "Helm docs not up-to-date:"; \
git status --porcelain; \
git diff; \
echo "Run make helm-docs locally to generate updated docs, commit the updates."; \
exit 1; \
fi
release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHARTS_VERSION).tgz
git checkout gh-pages
mv *.tgz $(CHARTS_DIR)
@@ -51,7 +66,7 @@ release: submariner-k8s-broker-$(CHARTS_VERSION).tgz submariner-operator-$(CHART
helm repo index $(CHARTS_DIR) --url $(GH_URL); \
fi
.PHONY: release
.PHONY: release helm-docs
else
+7
View File
@@ -1,5 +1,12 @@
# submariner-charts
<!-- markdownlint-disable line-length -->
[![CII Best Practices](https://bestpractices.coreinfrastructure.org/projects/4865/badge)](https://bestpractices.coreinfrastructure.org/projects/4865)
[![Release Charts](https://github.com/submariner-io/submariner-charts/workflows/Release%20Charts/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Release+Charts%22)
[![Periodic](https://github.com/submariner-io/submariner-charts/workflows/Periodic/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3APeriodic)
[![Flake Finder](https://github.com/submariner-io/submariner-charts/workflows/Flake%20Finder/badge.svg)](https://github.com/submariner-io/submariner-charts/actions?query=workflow%3A%22Flake+Finder%22)
<!-- markdownlint-enable line-length -->
Please see the [Helm docs on Submariner's website](https://submariner.io/operations/deployment/helm/).
## Development workflow
+6
View File
@@ -0,0 +1,6 @@
charts:
- submariner-operator
- submariner-k8s-broker
# Tests that maintainer name is valid GitHub account, which isn't what we want
# See: https://github.com/helm/chart-testing/issues/192
validate-maintainers: false
+5 -3
View File
@@ -1,12 +1,14 @@
---
name: submariner-k8s-broker
version: 0.6.0
apiVersion: v2
appVersion: 0.6.0
description: Submariner Kubernetes Broker
keywords:
home: https://submariner-io.github.io/
sources:
- https://submariner-io.github.io/submariner-charts/charts
- https://submariner-io.github.io/submariner-charts/charts
maintainers:
- name: Submariner Developers
email: submariner-dev@googlegroups.com
- name: Contributors to the Submariner project
email: submariner-dev@googlegroups.com
url: https://submariner.io/
+26
View File
@@ -0,0 +1,26 @@
# submariner-k8s-broker
![Version: 0.6.0](https://img.shields.io/badge/Version-0.6.0-informational?style=flat-square) ![AppVersion: 0.6.0](https://img.shields.io/badge/AppVersion-0.6.0-informational?style=flat-square)
Submariner Kubernetes Broker
**Homepage:** <https://submariner-io.github.io/>
## Maintainers
| Name | Email | Url |
| ---- | ------ | --- |
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
## Source Code
* <https://submariner-io.github.io/submariner-charts/charts>
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| crd.create | bool | `true` | |
| rbac.create | bool | `true` | |
| serviceAccounts.client.create | bool | `true` | |
| serviceAccounts.client.name | string | `""` | |
+5 -5
View File
@@ -2,7 +2,7 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: {{ template "submariner-k8s-broker.fullname" . }}:client
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
labels:
heritage: {{ .Release.Service | quote }}
release: {{ .Release.Name | quote }}
@@ -16,7 +16,7 @@ rules:
resources: ["*"]
verbs: ["create", "get", "list", "watch", "patch", "update", "delete"]
- apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices"]
resources: ["endpointslices", "endpointslices/restricted"]
verbs: ["create", "get", "list", "watch","patch", "update", "delete"]
- apiGroups: ["multicluster.x-k8s.io"]
resources: ["*"]
@@ -25,13 +25,13 @@ rules:
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: {{ template "submariner-k8s-broker.fullname" . }}:client
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ template "submariner-k8s-broker.fullname" . }}:client
name: {{ template "submariner-k8s-broker.fullname" . }}-cluster
subjects:
- kind: ServiceAccount
name: {{ template "submariner-k8s-broker.clientServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
{{- end -}}
{{- end -}}
+5 -3
View File
@@ -1,12 +1,14 @@
---
name: submariner-operator
version: 0.7.0
appVersion: 0.7.0
version: 0.11.0
apiVersion: v2
appVersion: 0.11.0
description: Submariner enables direct networking between Pods and Services in different Kubernetes clusters
keywords:
home: https://submariner-io.github.io/
sources:
- https://submariner-io.github.io/submariner-charts/charts
maintainers:
- name: Submariner Developers
- name: Contributors to the Submariner project
email: submariner-dev@googlegroups.com
url: https://submariner.io/
+71
View File
@@ -0,0 +1,71 @@
# submariner-operator
![Version: 0.11.0](https://img.shields.io/badge/Version-0.11.0-informational?style=flat-square) ![AppVersion: 0.11.0](https://img.shields.io/badge/AppVersion-0.11.0-informational?style=flat-square)
Submariner enables direct networking between Pods and Services in different Kubernetes clusters
**Homepage:** <https://submariner-io.github.io/>
## Maintainers
| Name | Email | Url |
| ---- | ------ | --- |
| Contributors to the Submariner project | submariner-dev@googlegroups.com | https://submariner.io/ |
## Source Code
* <https://submariner-io.github.io/submariner-charts/charts>
## Values
| Key | Type | Default | Description |
|-----|------|---------|-------------|
| broker.ca | string | `""` | |
| broker.globalnet | bool | `false` | |
| broker.insecure | bool | `false` | |
| broker.namespace | string | `"xyz"` | |
| broker.server | string | `"example.k8s.apiserver"` | |
| broker.token | string | `"test"` | |
| gateway.image.repository | string | `"quay.io/submariner/submariner-gateway"` | |
| gateway.image.tag | string | `"0.11.0"` | |
| ipsec.debug | bool | `false` | |
| ipsec.forceUDPEncaps | bool | `false` | |
| ipsec.ikePort | int | `500` | |
| ipsec.natPort | int | `4500` | |
| ipsec.psk | string | `""` | |
| leadership.leaseDuration | int | `10` | |
| leadership.renewDeadline | int | `5` | |
| leadership.retryPeriod | int | `2` | |
| operator.affinity | object | `{}` | |
| operator.image.pullPolicy | string | `"IfNotPresent"` | |
| operator.image.repository | string | `"quay.io/submariner/submariner-operator"` | |
| operator.image.tag | string | `"0.11.0"` | |
| operator.resources | object | `{}` | |
| operator.tolerations | list | `[]` | |
| rbac.create | bool | `true` | |
| serviceAccounts.gateway.create | bool | `true` | |
| serviceAccounts.gateway.name | string | `""` | |
| serviceAccounts.globalnet.create | bool | `true` | |
| serviceAccounts.globalnet.name | string | `""` | |
| serviceAccounts.lighthouseAgent.create | bool | `true` | |
| serviceAccounts.lighthouseAgent.name | string | `""` | |
| serviceAccounts.lighthouseCoreDns.create | bool | `true` | |
| serviceAccounts.lighthouseCoreDns.name | string | `""` | |
| serviceAccounts.operator.create | bool | `true` | |
| serviceAccounts.operator.name | string | `""` | |
| serviceAccounts.routeAgent.create | bool | `true` | |
| serviceAccounts.routeAgent.name | string | `""` | |
| submariner.cableDriver | string | `"libreswan"` | |
| submariner.clusterCidr | string | `""` | |
| submariner.clusterId | string | `""` | |
| submariner.colorCodes | string | `"blue"` | |
| submariner.coreDNSCustomConfig | object | `{}` | |
| submariner.debug | bool | `false` | |
| submariner.globalCidr | string | `""` | |
| submariner.healthcheckEnabled | bool | `true` | |
| submariner.images.repository | string | `"quay.io/submariner"` | |
| submariner.images.tag | string | `"0.11.0"` | |
| submariner.natEnabled | bool | `false` | |
| submariner.serviceCidr | string | `""` | |
| submariner.serviceDiscovery | bool | `true` | |
| submariner.token | string | `""` | |
+8 -2
View File
@@ -13,7 +13,7 @@ questions:
type: string
label: Submariner Operator Image Repository
- variable: operator.image.tag
default: "0.7.0"
default: "0.11.0"
description: "Submariner Operator Image Tag"
type: string
label: Submariner Operator Image Tag
@@ -31,7 +31,7 @@ questions:
type: string
label: Submariner Repository
- variable: submariner.images.tag
default: "0.7.0"
default: "0.11.0"
description: "Submariner Images Tag (shared for all non-operator images)"
type: string
label: Submariner Images Tag
@@ -136,3 +136,9 @@ questions:
group: "Advanced Configuration"
description: "Cable driver implementation"
label: "Cable Driver"
- variable: submariner.healthcheckEnabled
type: boolean
default: true
group: "Advanced Configuration"
description: "Disable Healthcheck"
label: "Healthcheck Disabled"
+29 -1
View File
@@ -397,6 +397,7 @@ rules:
resources:
- configmaps
verbs:
- create
- get
- list
- watch
@@ -411,11 +412,13 @@ rules:
- create
- update
- delete
- apiGroups: # pods and services are looked up to figure out network settings
- watch
- apiGroups: # pods, services and nodes are looked up to figure out network settings
- ""
resources:
- pods
- services
- nodes
verbs:
- get
- list
@@ -654,6 +657,29 @@ rules:
- get
- list
- watch
- apiGroups:
- submariner.io
resources:
- clusterglobalegressips
- globalegressips
verbs:
- create
- get
- list
- watch
- update
- apiGroups:
- submariner.io
resources:
- globalingressips
verbs:
- create
- get
- list
- watch
- update
- delete
- deletecollection
- apiGroups:
- multicluster.x-k8s.io
resources:
@@ -708,6 +734,7 @@ rules:
- discovery.k8s.io
resources:
- endpointslices
- endpointslices/restricted
verbs:
- create
- get
@@ -720,6 +747,7 @@ rules:
- submariner.io
resources:
- "gateways"
- "globalingressips"
verbs:
- get
- list
@@ -10,6 +10,7 @@ spec:
brokerK8sCA: {{ .Values.broker.ca }}
brokerK8sRemoteNamespace: {{ .Values.broker.namespace }}
ceIPSecDebug: {{ .Values.ipsec.debug }}
ceIPSecForceUDPEncaps: {{ .Values.ipsec.forceUDPEncaps }}
ceIPSecIKEPort: {{ .Values.ipsec.ikePort }}
ceIPSecNATTPort: {{ .Values.ipsec.natPort }}
ceIPSecPSK: {{ .Values.ipsec.psk }}
@@ -25,3 +26,12 @@ spec:
globalCIDR: "{{ .Values.submariner.globalCidr }}"
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
cableDriver: {{ .Values.submariner.cableDriver }}
connectionHealthCheck:
enabled: {{ .Values.submariner.healthcheckEnabled }}
intervalSeconds: 1
maxPacketLossCount: 5
{{- with .Values.submariner.coreDNSCustomConfig }}
coreDNSCustomConfig:
configmapName: .configmapName
namespace: .namespace
{{- end }}
+6 -3
View File
@@ -10,9 +10,11 @@ submariner:
debug: false
serviceDiscovery: true
cableDriver: "libreswan"
healthcheckEnabled: true
coreDNSCustomConfig: {}
images:
repository: quay.io/submariner
tag: "0.7.0"
tag: "0.11.0"
broker:
server: example.k8s.apiserver
token: test
@@ -25,6 +27,7 @@ rbac:
ipsec:
psk: ""
debug: false
forceUDPEncaps: false
ikePort: 500
natPort: 4500
leadership:
@@ -34,7 +37,7 @@ leadership:
operator:
image:
repository: quay.io/submariner/submariner-operator
tag: "0.7.0"
tag: "0.11.0"
pullPolicy: IfNotPresent
resources: {}
tolerations: []
@@ -42,7 +45,7 @@ operator:
gateway:
image:
repository: quay.io/submariner/submariner-gateway
tag: "0.7.0"
tag: "0.11.0"
serviceAccounts:
operator:
create: true