Files
Tom PantelisandStephen Kitt 9d8c4f5dbd Add RBAC access to finalizers for the operator role
On Openshift, the operator failed with error

"\"submariner-gateway\" is forbidden: cannot set blockOwnerDeletion
if an ownerReference refers to a resource you can't set finalizers on"

Openshift enables OwnerReferencesPermissionEnforcement, so
in order to set blockOwnerDeletion for an object, the user needs
update permission for the finalizers subresource of the referenced
owner. In this case the owner is the Submariner object.

Signed-off-by: Tom Pantelis <tompantelis@gmail.com>
2024-05-21 16:51:16 +02:00
..
2021-12-08 15:37:07 -05:00
2020-11-06 07:56:55 +01:00
2020-11-06 07:56:55 +01:00
2022-11-07 12:40:43 -05:00

submariner-operator

Submariner enables direct networking between Pods and Services in different Kubernetes clusters

Homepage: https://submariner-io.github.io/

Maintainers

Name Email Url
Contributors to the Submariner project submariner-dev@googlegroups.com https://submariner.io/

Source Code

Values

Key Type Default Description
broker.ca string ""
broker.globalnet bool false
broker.insecure bool false
broker.namespace string "xyz"
broker.server string "example.k8s.apiserver"
broker.token string "test"
ipsec.debug bool false
ipsec.forceUDPEncaps bool false
ipsec.ikePort int 500
ipsec.natPort int 4500
ipsec.psk string ""
leadership.leaseDuration int 10
leadership.renewDeadline int 5
leadership.retryPeriod int 2
operator.affinity object {}
operator.image.pullPolicy string "IfNotPresent"
operator.image.repository string "quay.io/submariner/submariner-operator"
operator.image.tag string "0.14.0"
operator.resources object {}
operator.tolerations list []
rbac.create bool true
serviceAccounts.gateway.create bool true
serviceAccounts.gateway.name string ""
serviceAccounts.globalnet.create bool true
serviceAccounts.globalnet.name string ""
serviceAccounts.lighthouseAgent.create bool true
serviceAccounts.lighthouseAgent.name string ""
serviceAccounts.lighthouseCoreDns.create bool true
serviceAccounts.lighthouseCoreDns.name string ""
serviceAccounts.operator.create bool true
serviceAccounts.operator.name string ""
serviceAccounts.routeAgent.create bool true
serviceAccounts.routeAgent.name string ""
submariner.cableDriver string "libreswan"
submariner.clusterCidr string ""
submariner.clusterId string ""
submariner.colorCodes string "blue"
submariner.coreDNSCustomConfig object {}
submariner.debug bool false
submariner.globalCidr string ""
submariner.healthcheckEnabled bool true
submariner.images.repository string "quay.io/submariner"
submariner.images.tag string "0.14.0"
submariner.natEnabled bool false
submariner.serviceCidr string ""
submariner.serviceDiscovery bool true
submariner.token string ""