diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..2c355b8 --- /dev/null +++ b/.gitignore @@ -0,0 +1,3 @@ +# macOS +.DS_Store +**/.DS_Store diff --git a/argo-infra-apps/backend-apps.yaml b/argo-infra-apps/backend-apps.yaml new file mode 100644 index 0000000..6b5632f --- /dev/null +++ b/argo-infra-apps/backend-apps.yaml @@ -0,0 +1,18 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: backend-app + namespace: argocd +spec: + project: default + source: + repoURL: https://gitlab.ii-p001.local/cw-devops/cw-infra-apps.git + targetRevision: main + path: charts/backend + destination: + server: https://kubernetes.default.svc + namespace: client1 + syncPolicy: + automated: + prune: true + selfHeal: true \ No newline at end of file diff --git a/argo-infra-apps/cassandra.yaml b/argo-infra-apps/cassandra.yaml index 50881df..0a8d541 100644 --- a/argo-infra-apps/cassandra.yaml +++ b/argo-infra-apps/cassandra.yaml @@ -14,7 +14,7 @@ metadata: uid: dcda9843-8c6e-4465-9f41-43be4d47e794 spec: destination: - namespace: cassandra + namespace: client1 server: https://kubernetes.default.svc project: default source: diff --git a/argo-infra-apps/elasticsearch.yaml b/argo-infra-apps/elasticsearch.yaml index 4490c66..8abbf16 100644 --- a/argo-infra-apps/elasticsearch.yaml +++ b/argo-infra-apps/elasticsearch.yaml @@ -9,7 +9,7 @@ metadata: uid: 928fb09c-938a-4ed5-9f05-5f8702d14a5e spec: destination: - namespace: elasticsearch + namespace: client1 server: https://kubernetes.default.svc project: default source: diff --git a/argo-infra-apps/grafana.yaml b/argo-infra-apps/grafana.yaml index 8754d7a..df95138 100644 --- a/argo-infra-apps/grafana.yaml +++ b/argo-infra-apps/grafana.yaml @@ -9,7 +9,7 @@ metadata: uid: 5f1ac9c2-48c5-4778-afc3-6a9a2c525a4f spec: destination: - namespace: grafana + namespace: client1 server: https://kubernetes.default.svc project: default source: diff --git a/argo-infra-apps/kafka.yaml b/argo-infra-apps/kafka.yaml index 434d7af..5443be8 100644 --- a/argo-infra-apps/kafka.yaml +++ b/argo-infra-apps/kafka.yaml @@ -14,7 +14,7 @@ metadata: uid: 742ebfdd-6dd9-4eea-bc4f-075e1f970bf4 spec: destination: - namespace: kafka + namespace: client1 server: https://kubernetes.default.svc project: default source: @@ -349,7 +349,7 @@ status: sync: comparedTo: destination: - namespace: kafka + namespace: client1 server: https://kubernetes.default.svc source: path: kafka diff --git a/argo-infra-apps/livekit-egress.yaml b/argo-infra-apps/livekit-egress.yaml index 327fee6..a1a9303 100644 --- a/argo-infra-apps/livekit-egress.yaml +++ b/argo-infra-apps/livekit-egress.yaml @@ -9,7 +9,7 @@ metadata: uid: e20642c8-3378-4c0c-8f8f-9c54440413ac spec: destination: - namespace: livekit + namespace: client1 server: https://kubernetes.default.svc project: default source: @@ -24,7 +24,7 @@ spec: - group: apps kind: Deployment name: livekit-egress - namespace: livekit + namespace: client1 jsonPointers: - /spec/replicas status: @@ -61,7 +61,7 @@ status: - group: "" hookPhase: Running kind: Namespace - message: namespace/livekit created + message: namespace/client1 created name: livekit namespace: "" status: Synced @@ -72,7 +72,7 @@ status: kind: ConfigMap message: configmap/livekit-egress created name: livekit-egress - namespace: livekit + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -81,7 +81,7 @@ status: kind: Deployment message: deployment.apps/livekit-egress created name: livekit-egress - namespace: livekit + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -94,7 +94,7 @@ status: resources: - kind: ConfigMap name: livekit-egress - namespace: livekit + namespace: client1 status: Synced version: v1 - group: apps @@ -102,7 +102,7 @@ status: status: Healthy kind: Deployment name: livekit-egress - namespace: livekit + namespace: client1 status: Synced version: v1 sourceType: Helm @@ -112,7 +112,7 @@ status: sync: comparedTo: destination: - namespace: livekit + namespace: client1 server: https://kubernetes.default.svc source: path: livekit/livekit-egress diff --git a/argo-infra-apps/livekit-server.yaml b/argo-infra-apps/livekit-server.yaml index 1deed39..599067e 100644 --- a/argo-infra-apps/livekit-server.yaml +++ b/argo-infra-apps/livekit-server.yaml @@ -9,7 +9,7 @@ metadata: uid: 6fd2964a-59c7-442f-8029-d3c7095ee329 spec: destination: - namespace: livekit + namespace: client1 server: https://kubernetes.default.svc project: default source: @@ -24,7 +24,7 @@ spec: - group: apps kind: Deployment name: livekit-server - namespace: livekit + namespace: client1 jsonPointers: - /spec/replicas @@ -69,7 +69,7 @@ status: configmap "livekit-server" deleted configmap/livekit-server replaced name: livekit-server - namespace: livekit + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -80,7 +80,7 @@ status: service "livekit-server" deleted service/livekit-server replaced name: livekit-server - namespace: livekit + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -91,7 +91,7 @@ status: service "livekit-server-turn" deleted service/livekit-server-turn replaced name: livekit-server-turn - namespace: livekit + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -111,7 +111,7 @@ status: kind: Ingress message: ingress.networking.k8s.io/livekit-server-turn created name: livekit-server-turn - namespace: livekit + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -120,7 +120,7 @@ status: kind: Ingress message: ingress.networking.k8s.io/livekit-server created name: livekit-server - namespace: livekit + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -133,14 +133,14 @@ status: resources: - kind: ConfigMap name: livekit-server - namespace: livekit + namespace: client1 status: Synced version: v1 - health: status: Healthy kind: Service name: livekit-server - namespace: livekit + namespace: client1 status: Synced version: v1 - health: @@ -155,7 +155,7 @@ status: status: Healthy kind: Deployment name: livekit-server - namespace: livekit + namespace: client1 status: Synced version: v1 - group: networking.k8s.io @@ -163,7 +163,7 @@ status: status: Healthy kind: Ingress name: livekit-server - namespace: livekit + namespace: client1 status: Synced version: v1 - group: networking.k8s.io @@ -171,7 +171,7 @@ status: status: Progressing kind: Ingress name: livekit-server-turn - namespace: livekit + namespace: client1 status: Synced version: v1 sourceType: Helm @@ -184,7 +184,7 @@ status: sync: comparedTo: destination: - namespace: livekit + namespace: client1 server: https://kubernetes.default.svc source: path: livekit/livekit-server diff --git a/argo-infra-apps/nfs-subdir-external-provisione.yaml b/argo-infra-apps/nfs-subdir-external-provisione.yaml index 9f0aa50..445cd3a 100644 --- a/argo-infra-apps/nfs-subdir-external-provisione.yaml +++ b/argo-infra-apps/nfs-subdir-external-provisione.yaml @@ -14,7 +14,7 @@ metadata: uid: 46da0f9d-0b3b-4b16-ab5d-ef5d65b15792 spec: destination: - namespace: nfs-subdir-external-provisioner + namespace: client1 server: https://kubernetes.default.svc project: default source: diff --git a/argo-infra-apps/postgresql-ha.yaml b/argo-infra-apps/postgresql-ha.yaml index c1547d3..d6fb9ca 100644 --- a/argo-infra-apps/postgresql-ha.yaml +++ b/argo-infra-apps/postgresql-ha.yaml @@ -11,7 +11,7 @@ spec: path: postgresql-ha destination: server: https://kubernetes.default.svc - namespace: postgresql-ha + namespace: client1 syncPolicy: automated: prune: true diff --git a/argo-infra-apps/redis.yaml b/argo-infra-apps/redis.yaml index ef2ec7b..90d3c8f 100644 --- a/argo-infra-apps/redis.yaml +++ b/argo-infra-apps/redis.yaml @@ -9,7 +9,7 @@ metadata: uid: e79154a8-6a82-4993-8479-4260dd93deea spec: destination: - namespace: redis + namespace: client1 server: https://kubernetes.default.svc project: default source: diff --git a/argo-infra-apps/vault-secrets-operator.yaml b/argo-infra-apps/vault-secrets-operator.yaml index 9942013..faead32 100644 --- a/argo-infra-apps/vault-secrets-operator.yaml +++ b/argo-infra-apps/vault-secrets-operator.yaml @@ -9,7 +9,7 @@ metadata: uid: 0acb50cc-b736-4760-aa60-b1dffc497fdd spec: destination: - namespace: vault-secrets-operator + namespace: client1 server: https://kubernetes.default.svc project: default source: diff --git a/argo-infra-apps/vault.yaml b/argo-infra-apps/vault.yaml index c8e7eaa..432985f 100644 --- a/argo-infra-apps/vault.yaml +++ b/argo-infra-apps/vault.yaml @@ -14,7 +14,7 @@ metadata: uid: 495b57f6-384a-4a4e-b976-514011af6c45 spec: destination: - namespace: vault + namespace: client1 server: https://kubernetes.default.svc ignoreDifferences: - group: admissionregistration.k8s.io @@ -120,7 +120,7 @@ status: poddisruptionbudget.policy "vault" deleted poddisruptionbudget.policy/vault replaced name: vault - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -131,7 +131,7 @@ status: serviceaccount "vault-agent-injector" deleted serviceaccount/vault-agent-injector replaced name: vault-agent-injector - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -142,7 +142,7 @@ status: serviceaccount "vault" deleted serviceaccount/vault replaced name: vault - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -153,7 +153,7 @@ status: configmap "vault-config" deleted configmap/vault-config replaced name: vault-config - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -164,7 +164,7 @@ status: clusterrole.rbac.authorization.k8s.io/vault-agent-injector-clusterrole reconciled. clusterrole.rbac.authorization.k8s.io "vault-agent-injector-clusterrole" deleted clusterrole.rbac.authorization.k8s.io/vault-agent-injector-clusterrole replaced name: vault-agent-injector-clusterrole - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -175,7 +175,7 @@ status: clusterrolebinding.rbac.authorization.k8s.io/vault-server-binding reconciled. clusterrolebinding.rbac.authorization.k8s.io "vault-server-binding" deleted clusterrolebinding.rbac.authorization.k8s.io/vault-server-binding replaced name: vault-server-binding - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -186,7 +186,7 @@ status: clusterrolebinding.rbac.authorization.k8s.io/vault-agent-injector-binding reconciled. clusterrolebinding.rbac.authorization.k8s.io "vault-agent-injector-binding" deleted clusterrolebinding.rbac.authorization.k8s.io/vault-agent-injector-binding replaced name: vault-agent-injector-binding - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -197,7 +197,7 @@ status: role.rbac.authorization.k8s.io/vault-discovery-role reconciled. role.rbac.authorization.k8s.io "vault-discovery-role" deleted role.rbac.authorization.k8s.io/vault-discovery-role replaced name: vault-discovery-role - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -208,7 +208,7 @@ status: rolebinding.rbac.authorization.k8s.io/vault-discovery-rolebinding reconciled. rolebinding.rbac.authorization.k8s.io "vault-discovery-rolebinding" deleted rolebinding.rbac.authorization.k8s.io/vault-discovery-rolebinding replaced name: vault-discovery-rolebinding - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -219,7 +219,7 @@ status: service "vault-internal" deleted service/vault-internal replaced name: vault-internal - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -230,7 +230,7 @@ status: service "vault-agent-injector-svc" deleted service/vault-agent-injector-svc replaced name: vault-agent-injector-svc - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -241,7 +241,7 @@ status: service "vault-standby" deleted service/vault-standby replaced name: vault-standby - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -252,7 +252,7 @@ status: service "vault" deleted service/vault replaced name: vault - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -263,7 +263,7 @@ status: service "vault-active" deleted service/vault-active replaced name: vault-active - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -274,7 +274,7 @@ status: deployment.apps "vault-agent-injector" deleted deployment.apps/vault-agent-injector replaced name: vault-agent-injector - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -285,7 +285,7 @@ status: statefulset.apps "vault" deleted statefulset.apps/vault replaced name: vault - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -296,7 +296,7 @@ status: mutatingwebhookconfiguration.admissionregistration.k8s.io "vault-agent-injector-cfg" deleted mutatingwebhookconfiguration.admissionregistration.k8s.io/vault-agent-injector-cfg replaced name: vault-agent-injector-cfg - namespace: vault + namespace: client1 status: Synced syncPhase: Sync version: v1 @@ -312,52 +312,52 @@ status: resources: - kind: ConfigMap name: vault-config - namespace: vault + namespace: client1 status: Synced version: v1 - health: status: Healthy kind: Service name: vault - namespace: vault + namespace: client1 status: Synced version: v1 - health: status: Healthy kind: Service name: vault-active - namespace: vault + namespace: client1 status: Synced version: v1 - health: status: Healthy kind: Service name: vault-agent-injector-svc - namespace: vault + namespace: client1 status: Synced version: v1 - health: status: Healthy kind: Service name: vault-internal - namespace: vault + namespace: client1 status: Synced version: v1 - health: status: Healthy kind: Service name: vault-standby - namespace: vault + namespace: client1 status: Synced version: v1 - kind: ServiceAccount name: vault - namespace: vault + namespace: client1 status: Synced version: v1 - kind: ServiceAccount name: vault-agent-injector - namespace: vault + namespace: client1 status: Synced version: v1 - group: admissionregistration.k8s.io @@ -370,7 +370,7 @@ status: status: Healthy kind: Deployment name: vault-agent-injector - namespace: vault + namespace: client1 status: Synced version: v1 - group: apps @@ -379,13 +379,13 @@ status: status: Healthy kind: StatefulSet name: vault - namespace: vault + namespace: client1 status: Synced version: v1 - group: policy kind: PodDisruptionBudget name: vault - namespace: vault + namespace: client1 status: Synced version: v1 - group: rbac.authorization.k8s.io @@ -406,13 +406,13 @@ status: - group: rbac.authorization.k8s.io kind: Role name: vault-discovery-role - namespace: vault + namespace: client1 status: Synced version: v1 - group: rbac.authorization.k8s.io kind: RoleBinding name: vault-discovery-rolebinding - namespace: vault + namespace: client1 status: Synced version: v1 sourceType: Helm @@ -423,7 +423,7 @@ status: sync: comparedTo: destination: - namespace: vault + namespace: client1 server: https://kubernetes.default.svc ignoreDifferences: - group: admissionregistration.k8s.io diff --git a/cassandra/templates/init_cm.yaml b/cassandra/templates/init_cm.yaml index ff477b3..947b71a 100644 --- a/cassandra/templates/init_cm.yaml +++ b/cassandra/templates/init_cm.yaml @@ -4,4 +4,4 @@ binaryData: kind: ConfigMap metadata: name: cassandra-init-script - namespace: cassandra + namespace: {{ .Release.Namespace }} diff --git a/cassandra/values.yaml b/cassandra/values.yaml index 742e438..96c4cd6 100644 --- a/cassandra/values.yaml +++ b/cassandra/values.yaml @@ -641,7 +641,7 @@ persistence: ## set, choosing the default provisioner. (gp2 on AWS, standard on ## GKE, AWS & OpenStack) ## - storageClass: "" + storageClass: "client1" ## @param persistence.commitStorageClass PVC Storage Class for Cassandra Commit Log volume ## Storage class to use with CASSANDRA_COMMITLOG_DIR to reduce the concurrence for writing data and commit logs ## ref: https://github.com/bitnami/containers/tree/main/bitnami/cassandra diff --git a/charts/backend/Chart.yaml b/charts/backend/Chart.yaml new file mode 100755 index 0000000..b082f89 --- /dev/null +++ b/charts/backend/Chart.yaml @@ -0,0 +1,125 @@ +apiVersion: v2 +name: backend +description: Umbrella chart for all backend k8s applications +type: application +version: "0.1.0" +appVersion: "1.0.0" + +dependencies: + - name: admin-app + version: "0.1.0" + repository: file://charts/admin-app-k8s + - name: android-app + version: "0.1.0" + repository: file://charts/android-app-k8s + - name: auth-app + version: "0.1.0" + repository: file://charts/auth-app-k8s + - name: auth-event-handler-app + version: "0.1.0" + repository: file://charts/auth-event-handler-app-k8s + - name: bff-admin-app + version: "0.1.0" + repository: file://charts/bff-admin-app-k8s + - name: bff-app + version: "0.1.0" + repository: file://charts/bff-app-k8s + - name: bff-vcs-app + version: "0.1.0" + repository: file://charts/bff-vcs-app-k8s + - name: big-chat-splitter-app + version: "0.1.0" + repository: file://charts/big-chat-splitter-app-k8s + - name: call-app + version: "0.1.0" + repository: file://charts/call-app-k8s + - name: call-event-handler-app + version: "0.1.0" + repository: file://charts/call-event-handler-app-k8s + - name: call-realtime-app + version: "0.1.0" + repository: file://charts/call-realtime-app-k8s + - name: chat-app + version: "0.1.0" + repository: file://charts/chat-app-k8s + - name: chat-event-handler-app + version: "0.1.0" + repository: file://charts/chat-event-handler-app-k8s + - name: deeplink-app + version: "0.1.0" + repository: file://charts/deeplink-app-k8s + - name: gem-call-app + version: "0.1.0" + repository: file://charts/gem-call-app-k8s + - name: gem-call-events-handler-app + version: "0.1.0" + repository: file://charts/gem-call-events-handler-app-k8s + - name: huawei-app + version: "0.1.0" + repository: file://charts/huawei-app-k8s + - name: ios-app + version: "0.1.0" + repository: file://charts/ios-app-k8s + - name: livekit-webhook-handler-app + version: "0.1.0" + repository: file://charts/livekit-webhook-handler-app-k8s + - name: message-app + version: "0.1.0" + repository: file://charts/message-app-k8s + - name: message-call-event-handler-app + version: "0.1.0" + repository: file://charts/message-call-event-handler-app-k8s + - name: message-chat-event-handler-app + version: "0.1.0" + repository: file://charts/message-chat-event-handler-app-k8s + - name: message-event-handler-app + version: "0.1.0" + repository: file://charts/message-event-handler-app-k8s + - name: message-link-preview-handler-app + version: "0.1.0" + repository: file://charts/message-link-preview-handler-app-k8s + - name: message-user-event-handler-app + version: "0.1.0" + repository: file://charts/message-user-event-handler-app-k8s + - name: notification-app + version: "0.1.0" + repository: file://charts/notification-app-k8s + - name: notification-event-handler-app + version: "0.1.0" + repository: file://charts/notification-event-handler-app-k8s + - name: realtime-app + version: "0.1.0" + repository: file://charts/realtime-app-k8s + - name: regular-chat-splitter-app + version: "0.1.0" + repository: file://charts/regular-chat-splitter-app-k8s + - name: search-app + version: "0.1.0" + repository: file://charts/search-app-k8s + - name: search-event-handler-app + version: "0.1.0" + repository: file://charts/search-event-handler-app-k8s + - name: sticker-app + version: "0.1.0" + repository: file://charts/sticker-app-k8s + - name: unregister-tokens-app + version: "0.1.0" + repository: file://charts/unregister-tokens-app-k8s + - name: upload-app + version: "0.1.0" + repository: file://charts/upload-app-k8s + - name: user-app + version: "0.1.0" + repository: file://charts/user-app-k8s + - name: voip-splitter-app + version: "0.1.0" + repository: file://charts/voip-splitter-app-k8s + - name: web-sender-app + version: "0.1.0" + repository: file://charts/web-sender-app-k8s + - name: workspace-app + version: "0.1.0" + repository: file://charts/workspace-app-k8s + - name: workspace-event-handler-app + version: "0.1.0" + repository: file://charts/workspace-event-handler-app-k8s \ No newline at end of file diff --git a/metallb/.helmignore b/charts/backend/charts/admin-app-k8s/.helmignore old mode 100644 new mode 100755 similarity index 100% rename from metallb/.helmignore rename to charts/backend/charts/admin-app-k8s/.helmignore diff --git a/charts/backend/charts/admin-app-k8s/Chart.yaml b/charts/backend/charts/admin-app-k8s/Chart.yaml new file mode 100755 index 0000000..d943528 --- /dev/null +++ b/charts/backend/charts/admin-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: admin-app +description: Helm chart for Admin app +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/admin-app-k8s/templates/_helpers.tpl b/charts/backend/charts/admin-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..6e6f4c1 --- /dev/null +++ b/charts/backend/charts/admin-app-k8s/templates/_helpers.tpl @@ -0,0 +1,24 @@ +{{/* Common labels */}} +{{- define "admin-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "admin-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Name */}} +{{- define "admin-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Fullname */}} +{{- define "admin-app.fullname" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Selector labels */}} +{{- define "admin-app.selectorLabels" -}} +app.kubernetes.io/name: {{ include "admin-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end }} diff --git a/charts/backend/charts/admin-app-k8s/templates/deployment.yaml b/charts/backend/charts/admin-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..8bfc32e --- /dev/null +++ b/charts/backend/charts/admin-app-k8s/templates/deployment.yaml @@ -0,0 +1,64 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "admin-app.fullname" . }} + labels: + {{- include "admin-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "admin-app.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "admin-app.selectorLabels" . | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: admin-app + ports: + - containerPort: 9090 + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + - name: WORKSPACE_HOST + value: "{{ .Values.env.workspace_host }}" + - name: WORKSPACE_PORT + value: "{{ .Values.env.workspace_port }}" + - name: USER_HOST + value: "{{ .Values.env.user_host }}" + - name: USER_PORT + value: "{{ .Values.env.user_port }}" + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/admin-app-k8s/templates/service.yaml b/charts/backend/charts/admin-app-k8s/templates/service.yaml new file mode 100755 index 0000000..a453710 --- /dev/null +++ b/charts/backend/charts/admin-app-k8s/templates/service.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "admin-app.fullname" . }} + labels: + {{- include "admin-app.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + selector: + {{- include "admin-app.selectorLabels" . | nindent 4 }} + ports: + - name: http + port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} + protocol: TCP diff --git a/charts/backend/charts/admin-app-k8s/values.yaml b/charts/backend/charts/admin-app-k8s/values.yaml new file mode 100755 index 0000000..7af34f6 --- /dev/null +++ b/charts/backend/charts/admin-app-k8s/values.yaml @@ -0,0 +1,16 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/admin-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + workspace_host: workspace-app + workspace_port: 9090 + user_host: user-app + user_port: 9090 +service: + type: ClusterIP + port: 9090 + targetPort: 9090 \ No newline at end of file diff --git a/metallb/charts/crds/.helmignore b/charts/backend/charts/android-app-k8s/.helmignore old mode 100644 new mode 100755 similarity index 100% rename from metallb/charts/crds/.helmignore rename to charts/backend/charts/android-app-k8s/.helmignore diff --git a/charts/backend/charts/android-app-k8s/Chart.yaml b/charts/backend/charts/android-app-k8s/Chart.yaml new file mode 100755 index 0000000..a47928d --- /dev/null +++ b/charts/backend/charts/android-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: android-app +description: Helm chart for Android Sender Application +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/android-app-k8s/templates/_helpers.tpl b/charts/backend/charts/android-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..0956742 --- /dev/null +++ b/charts/backend/charts/android-app-k8s/templates/_helpers.tpl @@ -0,0 +1,24 @@ +{{/* Common labels */}} +{{- define "android-sender-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "android-sender-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Name */}} +{{- define "android-sender-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Fullname */}} +{{- define "android-sender-app.fullname" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Selector labels */}} +{{- define "android-sender-app.selectorLabels" -}} +app.kubernetes.io/name: {{ include "android-sender-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end }} diff --git a/charts/backend/charts/android-app-k8s/templates/deployment.yaml b/charts/backend/charts/android-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..7c616bb --- /dev/null +++ b/charts/backend/charts/android-app-k8s/templates/deployment.yaml @@ -0,0 +1,64 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "android-sender-app.fullname" . }} + labels: + {{- include "android-sender-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "android-sender-app.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "android-sender-app.selectorLabels" . | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: android-sender + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: ANDROID_FIREBASE_CONFIG + value: {{ .Values.env.android_firebase_config }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/android-app-k8s/values.yaml b/charts/backend/charts/android-app-k8s/values.yaml new file mode 100755 index 0000000..f1344e8 --- /dev/null +++ b/charts/backend/charts/android-app-k8s/values.yaml @@ -0,0 +1,16 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/android-sender-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + kafkaServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redisHost: redis-master.redis.svc.cluster.local + redisPort: 6379 + android_firebase_config: "cowork-prod-firebase-adminsdk-l136z-648992e82d.json" + +secrets: + kafkaSecret: kafka-password + firebaseSecret: android-firebase-config \ No newline at end of file diff --git a/metallb/charts/frr-k8s/.helmignore b/charts/backend/charts/auth-app-k8s/.helmignore old mode 100644 new mode 100755 similarity index 100% rename from metallb/charts/frr-k8s/.helmignore rename to charts/backend/charts/auth-app-k8s/.helmignore diff --git a/charts/backend/charts/auth-app-k8s/Chart.yaml b/charts/backend/charts/auth-app-k8s/Chart.yaml new file mode 100755 index 0000000..ef6cebc --- /dev/null +++ b/charts/backend/charts/auth-app-k8s/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: auth-app +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/charts/backend/charts/auth-app-k8s/templates/_helpers.tpl b/charts/backend/charts/auth-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..9c13cc4 --- /dev/null +++ b/charts/backend/charts/auth-app-k8s/templates/_helpers.tpl @@ -0,0 +1,53 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "auth-app-k8s.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "auth-app-k8s.fullname" -}} +{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "auth-app-k8s.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "auth-app-k8s.labels" -}} +helm.sh/chart: {{ include "auth-app-k8s.chart" . }} +{{ include "auth-app-k8s.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "auth-app-k8s.selectorLabels" -}} +app.kubernetes.io/name: {{ include "auth-app-k8s.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "auth-app-k8s.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "auth-app-k8s.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/charts/backend/charts/auth-app-k8s/templates/deployment.yaml b/charts/backend/charts/auth-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..c398517 --- /dev/null +++ b/charts/backend/charts/auth-app-k8s/templates/deployment.yaml @@ -0,0 +1,103 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "auth-app-k8s.fullname" . }} + labels: + {{- include "auth-app-k8s.labels" . | nindent 4 }} + io.kompose.service: auth-app +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "auth-app-k8s.selectorLabels" . | nindent 6 }} + io.kompose.service: auth-app + template: + metadata: + annotations: + {{- toYaml .Values.podAnnotations | nindent 8 }} + labels: + {{- include "auth-app-k8s.selectorLabels" . | nindent 8 }} + {{- toYaml .Values.podLabels | nindent 8 }} + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: ca-cert + configMap: + name: {{ include "auth-app-k8s.fullname" . }}-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: auth-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: {{ .Values.service.targetPort }} + {{- if .Values.service.hostPort }} + hostPort: {{ .Values.service.hostPort }} + {{- end }} + protocol: TCP + env: + - name: ADMIN_CLIENT_ID + value: {{ .Values.env.adminClientId | quote }} + - name: ADMIN_PASSWORD + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.adminPassword.name }} + key: {{ .Values.secrets.adminPassword.key }} + - name: ADMIN_REALM + value: {{ .Values.env.adminRealm | quote }} + - name: ADMIN_URL + value: {{ .Values.env.adminUrl | quote }} + - name: ADMIN_USERNAME + value: {{ .Values.env.adminUsername | quote }} + - name: CLIENT_ID + value: {{ .Values.env.clientId | quote }} + - name: CLIENT_ISSUER_IRI + value: {{ .Values.env.clientIssuerIri | quote }} + - name: CLIENT_REALM + value: {{ .Values.env.clientRealm | quote }} + - name: CLIENT_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.clientSecret.name }} + key: {{ .Values.secrets.clientSecret.key }} + - name: REALM + value: {{ .Values.env.realm | quote }} + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + - name: SECURITY_ADMIN_REALM + value: {{ .Values.env.securityAdminRealm | quote }} + - name: SECURITY_OAUTH2_CLIENT_ISSUER_URI + value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + resources: + {{- toYaml .Values.resources | nindent 12 }} \ No newline at end of file diff --git a/charts/backend/charts/auth-app-k8s/templates/service.yaml b/charts/backend/charts/auth-app-k8s/templates/service.yaml new file mode 100755 index 0000000..d7fd4fc --- /dev/null +++ b/charts/backend/charts/auth-app-k8s/templates/service.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "auth-app-k8s.fullname" . }} + labels: + {{- include "auth-app-k8s.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + ports: + - port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} + protocol: TCP + selector: + {{- include "auth-app-k8s.selectorLabels" . | nindent 4 }} + io.kompose.service: auth-app \ No newline at end of file diff --git a/charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml b/charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml new file mode 100755 index 0000000..345e5ce --- /dev/null +++ b/charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Pod +metadata: + name: "{{ include "auth-app-k8s.fullname" . }}-test-connection" + labels: + {{- include "auth-app-k8s.labels" . | nindent 4 }} + annotations: + "helm.sh/hook": test +spec: + containers: + - name: wget + image: busybox + command: ['wget'] + args: ['{{ include "auth-app-k8s.fullname" . }}:{{ .Values.service.port }}'] + restartPolicy: Never diff --git a/charts/backend/charts/auth-app-k8s/values.yaml b/charts/backend/charts/auth-app-k8s/values.yaml new file mode 100755 index 0000000..3289564 --- /dev/null +++ b/charts/backend/charts/auth-app-k8s/values.yaml @@ -0,0 +1,58 @@ + +fullnameOverride: "auth-app" + +image: + repository: docker.ii-p001.local/auth-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +replicaCount: 1 + +service: + type: ClusterIP + port: 9090 + targetPort: 9090 + hostPort: null + +env: + cert_alias: co-work + adminClientId: "admin-cli" + adminRealm: "master" + adminUrl: "https://iam.stage.co-work.local/admin/realms/co-work" + adminUsername: "admin" + clientId: "gem-auth-client" + clientIssuerIri: "https://iam.stage.co-work.local/realms/co-work" + clientRealm: "co-work" + realm: "co-work" + securityAdminRealm: "master" + securityOauth2ClientIssuerUri: "https://iam.stage.co-work.local/realms" + + +secrets: + adminPassword: + name: auth-secrets + key: admin-password + clientSecret: + name: auth-secrets + key: client-secret + + +resources: + limits: + memory: 512Mi + requests: + cpu: 100m + memory: 256Mi + + +podAnnotations: + kompose.cmd: kompose convert -f app/auth-app.yml -o k8s/auth-app-k8s + kompose.version: 1.33.0 (HEAD) + +podLabels: + io.kompose.network/app-default: "true" + io.kompose.service: auth-app + + +autoscaling: + enabled: false \ No newline at end of file diff --git a/metallb/charts/frr-k8s/charts/crds/.helmignore b/charts/backend/charts/auth-event-handler-app-k8s/.helmignore old mode 100644 new mode 100755 similarity index 100% rename from metallb/charts/frr-k8s/charts/crds/.helmignore rename to charts/backend/charts/auth-event-handler-app-k8s/.helmignore diff --git a/charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..f45c1d5 --- /dev/null +++ b/charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: auth-event-handler-app +description: Authentication Event Handler +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..0ed8006 --- /dev/null +++ b/charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,19 @@ +{{/* Common Name Definitions */}} +{{- define "auth-event-handler-app-k8s.fullname" -}} +{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Standard labels */}} +{{- define "auth-event-handler-app-k8s.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/name: {{ .Chart.Name }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Selector labels */}} +{{- define "auth-event-handler-app-k8s.selectorLabels" -}} +app.kubernetes.io/name: {{ .Chart.Name }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end }} diff --git a/charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..eac50a8 --- /dev/null +++ b/charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,135 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "auth-event-handler-app-k8s.fullname" . }} + labels: + {{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }} +spec: + {{- if not .Values.autoscaling.enabled }} + replicas: {{ .Values.replicaCount }} + {{- end }} + selector: + matchLabels: + {{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 6 }} + template: + metadata: + {{- with .Values.podAnnotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + labels: + {{- include "auth-event-handler-app-k8s.labels" . | nindent 8 }} + {{- with .Values.podLabels }} + {{- toYaml . | nindent 8 }} + {{- end }} + spec: + {{- if .Values.serviceAccount.create }} + serviceAccountName: {{ .Values.serviceAccount.name | default (include "auth-event-handler-app-k8s.serviceAccountName" .) }} + {{- end }} + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + securityContext: + {{- toYaml .Values.podSecurityContext | nindent 8 }} + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + {{- with .Values.volumes }} + {{ toYaml . | nindent 8 }} + {{- end }} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: {{ .Chart.Name }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - name: http + containerPort: {{ .Values.service.port }} + protocol: TCP + env: + - name: ADMIN_CLIENT_ID + value: {{ .Values.env.adminClientId | quote }} + - name: ADMIN_REALM + value: {{ .Values.env.adminRealm | quote }} + - name: ADMIN_URL + value: {{ .Values.env.adminUrl | quote }} + - name: ADMIN_USERNAME + value: {{ .Values.env.adminUsername | quote }} + - name: CLIENT_ID + value: {{ .Values.env.clientId | quote }} + - name: CLIENT_ISSUER_IRI + value: {{ .Values.env.clientIssuerIri | quote }} + - name: CLIENT_REALM + value: {{ .Values.env.clientRealm | quote }} + - name: REALM + value: {{ .Values.env.realm | quote }} + - name: SECURITY_ADMIN_REALM + value: {{ .Values.env.securityAdminRealm | quote }} + - name: SECURITY_OAUTH2_CLIENT_ISSUER_URI + value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }} + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: ADMIN_PASSWORD + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.adminPassword.name }} + key: {{ .Values.secrets.adminPassword.key }} + - name: CLIENT_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.clientSecret.name }} + key: {{ .Values.secrets.clientSecret.key }} + livenessProbe: + {{- toYaml .Values.livenessProbe | nindent 12 }} + readinessProbe: + {{- toYaml .Values.readinessProbe | nindent 12 }} + resources: + {{- toYaml .Values.resources | nindent 12 }} + volumeMounts: + {{- with .Values.volumeMounts }} + {{- toYaml . | nindent 12 }} + {{- end }} + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} diff --git a/charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml b/charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml new file mode 100755 index 0000000..21e5053 --- /dev/null +++ b/charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "auth-event-handler-app-k8s.fullname" . }} + labels: + {{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }} +spec: + ports: + - port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} + selector: + {{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 4 }} \ No newline at end of file diff --git a/charts/backend/charts/auth-event-handler-app-k8s/values.yaml b/charts/backend/charts/auth-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..8f05c27 --- /dev/null +++ b/charts/backend/charts/auth-event-handler-app-k8s/values.yaml @@ -0,0 +1,60 @@ +fullnameOverride: "auth-event-handler-app" +image: + repository: docker.ii-p001.local/auth-event-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +replicaCount: 1 +service: + type: ClusterIP + port: 8094 + targetPort: 9090 +env: + adminClientId: "admin-cli" + adminRealm: "master" + adminUrl: "https://iam.stage.co-work.local/admin/realms/co-work" + adminUsername: "admin" + clientId: "gem-auth-client" + clientIssuerIri: "https://iam.stage.co-work.local/realms/co-work" + clientRealm: "co-work" + realm: "co-work" + securityAdminRealm: "master" + securityOauth2ClientIssuerUri: "https://iam.stage.co-work.local/realms" + kafkaBrokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" +secrets: + kafka: + name: kafka-password + passwordKey: client-passwords + username: admin + adminPassword: + name: auth-secrets + key: admin-password + clientSecret: + name: auth-secrets + key: client-secret + +resources: + limits: + memory: 512Mi + requests: + cpu: 100m + memory: 256Mi + +podAnnotations: + kompose.cmd: kompose convert -f app/auth-event-handler-app.yml -o k8s/auth-event-handler-app-k8s + kompose.version: 1.33.0 (HEAD) + +podLabels: + io.kompose.network/app-default: "true" + io.kompose.service: auth-event-handler-app + + +podSecurityContext: {} +securityContext: {} + +autoscaling: + enabled: false + +serviceAccount: + create: false + name: "" \ No newline at end of file diff --git a/charts/backend/charts/bff-admin-app-k8s/.helmignore b/charts/backend/charts/bff-admin-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/bff-admin-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/bff-admin-app-k8s/Chart.yaml b/charts/backend/charts/bff-admin-app-k8s/Chart.yaml new file mode 100755 index 0000000..97e78ff --- /dev/null +++ b/charts/backend/charts/bff-admin-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: bff-admin-app +description: Helm chart for bff-admin-app +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl b/charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..ee6b096 --- /dev/null +++ b/charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl @@ -0,0 +1,24 @@ +{{/* Common labels */}} +{{- define "bff-admin-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "bff-admin-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Name */}} +{{- define "bff-admin-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Fullname */}} +{{- define "bff-admin-app.fullname" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Selector labels */}} +{{- define "bff-admin-app.selectorLabels" -}} +app.kubernetes.io/name: {{ include "bff-admin-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end }} diff --git a/charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml b/charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..a463d63 --- /dev/null +++ b/charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml @@ -0,0 +1,39 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "bff-admin-app.fullname" . }} + labels: + {{- include "bff-admin-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "bff-admin-app.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "bff-admin-app.selectorLabels" . | nindent 8 }} + spec: + containers: + - name: bff-admin-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + - name: SWAGGER_HOST + value: "{{ .Values.env.swagger_host }}" + - name: SWAGGER_PORT + value: "{{ .Values.env.swagger_port }}" + - name: WORKSPACE_HOST + value: "{{ .Values.env.workspace_host }}" + - name: WORKSPACE_PORT + value: "{{ .Values.env.workspace_port }}" + - name: USER_HOST + value: "{{ .Values.env.user_host }}" + - name: USER_PORT + value: "{{ .Values.env.user_port }}" + - name: ADMIN_HOST + value: "{{ .Values.env.admin_host }}" + - name: ADMIN_PORT + value: "{{ .Values.env.admin_port }}" + - name: APP_NAME + value: "{{ .Values.env.app_name }}" diff --git a/charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml b/charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml new file mode 100755 index 0000000..5b5d502 --- /dev/null +++ b/charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml @@ -0,0 +1,38 @@ +{{- if .Values.ingress.enabled -}} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ .Values.ingress.name }} + namespace: {{ .Release.Namespace | default "default" }} + {{- with .Values.ingress.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + ingressClassName: {{ .Values.ingress.className }} + {{- if .Values.ingress.tls }} + tls: + {{- range .Values.ingress.tls }} + - hosts: + {{- range .hosts }} + - {{ . | quote }} + {{- end }} + secretName: {{ .secretName | quote }} + {{- end }} + {{- end }} + rules: + {{- range .Values.ingress.hosts }} + - host: {{ .host | quote }} + http: + paths: + {{- range .paths }} + - path: {{ .path }} + pathType: {{ .pathType }} + backend: + service: + name: {{ $.Values.env.app_name }} + port: + number: {{ $.Values.service.httpPort }} + {{- end }} + {{- end }} +{{- end }} \ No newline at end of file diff --git a/charts/backend/charts/bff-admin-app-k8s/templates/service.yaml b/charts/backend/charts/bff-admin-app-k8s/templates/service.yaml new file mode 100755 index 0000000..afaf6a0 --- /dev/null +++ b/charts/backend/charts/bff-admin-app-k8s/templates/service.yaml @@ -0,0 +1,17 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "bff-admin-app.fullname" . }} + labels: + {{- include "bff-admin-app.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + selector: + {{- include "bff-admin-app.selectorLabels" . | nindent 4 }} + ports: + {{- range .Values.service.ports }} + - name: {{ .name }} + port: {{ .port }} + targetPort: {{ .targetPort }} + protocol: TCP + {{- end }} diff --git a/charts/backend/charts/bff-admin-app-k8s/values.yaml b/charts/backend/charts/bff-admin-app-k8s/values.yaml new file mode 100755 index 0000000..db0ed36 --- /dev/null +++ b/charts/backend/charts/bff-admin-app-k8s/values.yaml @@ -0,0 +1,46 @@ +replicaCount: 1 +image: + repository: docker.ii-p001.local/bff-admin-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + swagger_host: "localhost" + swagger_port: 8080 + workspace_host: "workspace-app" + workspace_port: 9090 + user_host: "user-app" + user_port: 9090 + admin_host: "admin-app" + admin_port: 9090 + app_name: bff-admin-app + +service: + type: ClusterIP + httpPort: 8100 + grpcPort: 8101 + ports: + - name: http + port: 8100 + targetPort: 8080 + - name: grpc + port: 8101 + targetPort: 9090 + +ingress: + enabled: true + className: nginx + name: bff-admin-ingress + annotations: + nginx.ingress.kubernetes.io/ssl-redirect: "true" + nginx.ingress.kubernetes.io/force-ssl-redirect: "true" + nginx.ingress.kubernetes.io/backend-protocol: "HTTP" + hosts: + - host: adm-s001.co-work.ru + paths: + - path: / + pathType: Prefix + tls: + - hosts: + - adm-s001.co-work.ru + secretName: co-work-secret \ No newline at end of file diff --git a/charts/backend/charts/bff-app-k8s/.helmignore b/charts/backend/charts/bff-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/bff-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/bff-app-k8s/Chart.yaml b/charts/backend/charts/bff-app-k8s/Chart.yaml new file mode 100755 index 0000000..b75c1cf --- /dev/null +++ b/charts/backend/charts/bff-app-k8s/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: bff-app +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/charts/backend/charts/bff-app-k8s/templates/_helpers.tpl b/charts/backend/charts/bff-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..453c818 --- /dev/null +++ b/charts/backend/charts/bff-app-k8s/templates/_helpers.tpl @@ -0,0 +1,19 @@ +{{/* Common Name Definitions */}} +{{- define "bff-app-k8s.fullname" -}} +{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Standard labels */}} +{{- define "bff-app-k8s.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/name: {{ .Chart.Name }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Selector labels */}} +{{- define "bff-app-k8s.selectorLabels" -}} +app.kubernetes.io/name: {{ .Values.fullnameOverride }} +app.kubernetes.io/instance: {{ .Values.fullnameOverride }} +{{- end }} diff --git a/charts/backend/charts/bff-app-k8s/templates/deployment.yaml b/charts/backend/charts/bff-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..2e135ef --- /dev/null +++ b/charts/backend/charts/bff-app-k8s/templates/deployment.yaml @@ -0,0 +1,93 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "bff-app-k8s.fullname" . }} + labels: + {{- include "bff-app-k8s.selectorLabels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "bff-app-k8s.selectorLabels" . | nindent 6 }} + template: + metadata: + annotations: + {{- toYaml .Values.podAnnotations | nindent 8 }} + labels: + {{- include "bff-app-k8s.selectorLabels" . | nindent 8 }} + {{- toYaml .Values.podLabels | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} +# initContainers: +# - name: import-ca +# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" +# env: +# - name: CERT_ALIAS +# value: {{ .Values.global.cert_alias | quote }} +# volumeMounts: +# - name: ca-cert +# mountPath: /app/resources +# - name: cacerts-volume +# mountPath: /tmp/cacerts +# command: +# - sh +# - -c +# - | +# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && +# keytool -import -trustcacerts -storepass changeit -noprompt \ +# -alias gemcert \ +# -file /app/resources/RootCA_${CERT_ALIAS}.crt \ +# -keystore /tmp/cacerts/cacerts + containers: + - name: bff-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: {{ .Values.service.targetPort }} + {{- if .Values.service.hostPort }} + hostPort: {{ .Values.service.hostPort }} + {{- end }} + protocol: TCP + env: + - name: GRPC_CLIENT_AUTH_URL + value: {{ .Values.env.services.auth | quote }} + - name: GRPC_CLIENT_CHAT_URL + value: {{ .Values.env.services.chat | quote }} + - name: GRPC_CLIENT_CONFIG_URL + value: {{ .Values.env.services.user | quote }} + - name: GRPC_CLIENT_DEEPLINK_URL + value: {{ .Values.env.services.deeplink | quote }} + - name: GRPC_CLIENT_GEM_CALL_URL + value: {{ .Values.env.services.gemCall | quote }} + - name: GRPC_CLIENT_MESSAGE_URL + value: {{ .Values.env.services.message | quote }} + - name: GRPC_CLIENT_NOTIFICATIONS_URL + value: {{ .Values.env.services.notification | quote }} + - name: GRPC_CLIENT_REACTION_URL + value: {{ .Values.env.services.message | quote }} + - name: GRPC_CLIENT_REALTIME_URL + value: {{ .Values.env.services.realtime | quote }} + - name: GRPC_CLIENT_SEARCH_URL + value: {{ .Values.env.services.search | quote }} + - name: GRPC_CLIENT_STICKER_URL + value: {{ .Values.env.services.sticker | quote }} + - name: GRPC_CLIENT_UPLOAD_URL + value: {{ .Values.env.services.upload | quote }} + - name: GRPC_CLIENT_USER_URL + value: {{ .Values.env.services.user | quote }} + - name: GRPC_CLIENT_WORKSPACE_URL + value: {{ .Values.env.services.workspace | quote }} + resources: + {{- toYaml .Values.resources | nindent 12 }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/bff-app-k8s/templates/ingress.yaml b/charts/backend/charts/bff-app-k8s/templates/ingress.yaml new file mode 100755 index 0000000..04ac9bd --- /dev/null +++ b/charts/backend/charts/bff-app-k8s/templates/ingress.yaml @@ -0,0 +1,28 @@ +{{- if .Values.ingress.enabled -}} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ .Values.ingress.name }} + namespace: {{ .Release.Namespace | default "default" }} + {{- with .Values.ingress.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + ingressClassName: {{ .Values.ingress.className }} + tls: + - hosts: + - {{ .Values.ingress.host | quote }} + secretName: {{ .Values.ingress.tlsSecret | quote }} + rules: + - host: {{ .Values.ingress.host | quote }} + http: + paths: + - path: {{ .Values.ingress.path }} + pathType: {{ .Values.ingress.pathType }} + backend: + service: + name: {{ .Values.service.name }} + port: + number: {{ .Values.service.port }} +{{- end }} \ No newline at end of file diff --git a/charts/backend/charts/bff-app-k8s/templates/service.yaml b/charts/backend/charts/bff-app-k8s/templates/service.yaml new file mode 100755 index 0000000..6a9236b --- /dev/null +++ b/charts/backend/charts/bff-app-k8s/templates/service.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "bff-app-k8s.fullname" . }} + labels: + {{- include "bff-app-k8s.selectorLabels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + ports: + - port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} + protocol: TCP + selector: + {{- include "bff-app-k8s.selectorLabels" . | nindent 4 }} \ No newline at end of file diff --git a/charts/backend/charts/bff-app-k8s/values.yaml b/charts/backend/charts/bff-app-k8s/values.yaml new file mode 100755 index 0000000..b399569 --- /dev/null +++ b/charts/backend/charts/bff-app-k8s/values.yaml @@ -0,0 +1,58 @@ +image: + repository: docker.ii-p001.local/bff-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +replicaCount: 1 + +service: + type: ClusterIP + port: 8081 + targetPort: 8080 + nodePort: 31754 + name: bff-app # Added service name + +ingress: + enabled: true + className: nginx + name: bff-app-ingress + host: api-s001.co-work.ru + annotations: + nginx.ingress.kubernetes.io/ssl-redirect: "true" + nginx.ingress.kubernetes.io/force-ssl-redirect: "true" + nginx.ingress.kubernetes.io/backend-protocol: "HTTP" + path: / + pathType: Prefix + tlsSecret: co-work-secret + +env: + services: + auth: http://auth-app:9090 + chat: http://chat-app:9090 + user: http://user-app:9090 + deeplink: http://deeplink-app:9090 + gemCall: http://gem-call-app:9090 + message: http://message-app:9090 + notification: http://notification-app:9090 + realtime: http://realtime-app:9090 + search: http://search-app:9090 + sticker: http://sticker-app:9090 + upload: http://upload-app:9090 + workspace: http://workspace-app:9090 + +resources: + limits: + memory: 1Gi + requests: + cpu: 200m + memory: 512Mi + +podAnnotations: + kompose.cmd: kompose convert -f app/bff-app.yml -o k8s/bff-app-k8s + kompose.version: 1.33.0 (HEAD) + +podLabels: + io.kompose.network/app-default: "true" + io.kompose.service: bff-app + +fullnameOverride: "bff-app" \ No newline at end of file diff --git a/charts/backend/charts/bff-vcs-app-k8s/.helmignore b/charts/backend/charts/bff-vcs-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/bff-vcs-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/bff-vcs-app-k8s/Chart.yaml b/charts/backend/charts/bff-vcs-app-k8s/Chart.yaml new file mode 100755 index 0000000..4b2338f --- /dev/null +++ b/charts/backend/charts/bff-vcs-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: bff-vcs-app +description: Helm chart for bff-vcs-app +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/bff-vcs-app-k8s/templates/_helpers.tpl b/charts/backend/charts/bff-vcs-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..9b32ae2 --- /dev/null +++ b/charts/backend/charts/bff-vcs-app-k8s/templates/_helpers.tpl @@ -0,0 +1,24 @@ +{{/* Common labels */}} +{{- define "bff-vcs-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Name */}} +{{- define "bff-vcs-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Fullname */}} +{{- define "bff-vcs-app.fullname" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Selector labels */}} +{{- define "bff-vcs-app.selectorLabels" -}} +app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end }} diff --git a/charts/backend/charts/bff-vcs-app-k8s/templates/deployment.yaml b/charts/backend/charts/bff-vcs-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..8bb94d5 --- /dev/null +++ b/charts/backend/charts/bff-vcs-app-k8s/templates/deployment.yaml @@ -0,0 +1,58 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "bff-vcs-app.fullname" . }} + labels: + {{- include "bff-vcs-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "bff-vcs-app.selectorLabels" . | nindent 6 }} + template: + metadata: + labels: + {{- include "bff-vcs-app.selectorLabels" . | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} +# initContainers: +# - name: import-ca +# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" +# env: +# - name: CERT_ALIAS +# value: {{ .Values.global.cert_alias | quote }} +# volumeMounts: +# - name: ca-cert +# mountPath: /app/resources +# - name: cacerts-volume +# mountPath: /tmp/cacerts +# command: +# - sh +# - -c +# - | +# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && +# keytool -import -trustcacerts -storepass changeit -noprompt \ +# -alias gemcert \ +# -file /app/resources/RootCA_${CERT_ALIAS}.crt \ +# -keystore /tmp/cacerts/cacerts + containers: + - name: bff-vcs-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + - name: GRPC_CLIENT_CALL_URL + value: "{{ .Values.env.grpc_client_call_url }}" + - name: GRPC_CLIENT_CALL_REALTIME_URL + value: "{{ .Values.env.grpc_client_call_realtime_url }}" + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/bff-vcs-app-k8s/templates/ingress.yaml b/charts/backend/charts/bff-vcs-app-k8s/templates/ingress.yaml new file mode 100755 index 0000000..9d1467b --- /dev/null +++ b/charts/backend/charts/bff-vcs-app-k8s/templates/ingress.yaml @@ -0,0 +1,28 @@ +{{- if .Values.ingress.enabled }} +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: {{ include "bff-vcs-app.fullname" . }}-ingress + namespace: {{ .Release.Namespace }} + annotations: + {{- range $key, $value := .Values.ingress.annotations }} + {{ $key }}: {{ $value | quote }} + {{- end }} +spec: + ingressClassName: {{ .Values.ingress.ingressClassName }} + tls: + - hosts: + - {{ .Values.ingress.host }} + secretName: {{ .Values.ingress.tlsSecretName }} + rules: + - host: {{ .Values.ingress.host }} + http: + paths: + - path: / + pathType: Prefix + backend: + service: + name: {{ include "bff-vcs-app.fullname" . }} + port: + number: {{ .Values.service.port }} +{{- end }} diff --git a/charts/backend/charts/bff-vcs-app-k8s/templates/service.yaml b/charts/backend/charts/bff-vcs-app-k8s/templates/service.yaml new file mode 100755 index 0000000..e27a234 --- /dev/null +++ b/charts/backend/charts/bff-vcs-app-k8s/templates/service.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "bff-vcs-app.fullname" . }} + labels: + {{- include "bff-vcs-app.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + selector: + {{- include "bff-vcs-app.selectorLabels" . | nindent 4 }} + ports: + - name: http + port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} + protocol: TCP + diff --git a/charts/backend/charts/bff-vcs-app-k8s/values.yaml b/charts/backend/charts/bff-vcs-app-k8s/values.yaml new file mode 100755 index 0000000..8fb4ed9 --- /dev/null +++ b/charts/backend/charts/bff-vcs-app-k8s/values.yaml @@ -0,0 +1,25 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/bff-vcs-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + grpc_client_call_url: http://call-realtime-app:9090 + grpc_client_call_realtime_url: http://call-realtime-app:9090 + +service: + type: ClusterIP + port: 8079 + targetPort: 8080 + +ingress: + enabled: true + ingressClassName: nginx + host: vcs-s001.co-work.ru + tlsSecretName: co-work-secret + annotations: + nginx.ingress.kubernetes.io/ssl-redirect: "true" + nginx.ingress.kubernetes.io/force-ssl-redirect: "true" + nginx.ingress.kubernetes.io/backend-protocol: "HTTP" diff --git a/charts/backend/charts/big-chat-splitter-app-k8s/.helmignore b/charts/backend/charts/big-chat-splitter-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/big-chat-splitter-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/big-chat-splitter-app-k8s/Chart.yaml b/charts/backend/charts/big-chat-splitter-app-k8s/Chart.yaml new file mode 100755 index 0000000..033512c --- /dev/null +++ b/charts/backend/charts/big-chat-splitter-app-k8s/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: big-chat-splitter-app +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/charts/backend/charts/big-chat-splitter-app-k8s/templates/_helpers.tpl b/charts/backend/charts/big-chat-splitter-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..67db496 --- /dev/null +++ b/charts/backend/charts/big-chat-splitter-app-k8s/templates/_helpers.tpl @@ -0,0 +1,18 @@ +{{/* Common Name Definitions */}} +{{- define "big-chat-splitter-app-k8s.fullname" -}} +{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Standard labels */}} +{{- define "big-chat-splitter-app-k8s.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/name: {{ .Chart.Name }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Selector labels */}} +{{- define "big-chat-splitter-app-k8s.selectorLabels" -}} +io.kompose.service: big-chat-splitter-app +{{- end }} diff --git a/charts/backend/charts/big-chat-splitter-app-k8s/templates/deployment.yaml b/charts/backend/charts/big-chat-splitter-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..617d56d --- /dev/null +++ b/charts/backend/charts/big-chat-splitter-app-k8s/templates/deployment.yaml @@ -0,0 +1,65 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "big-chat-splitter-app-k8s.fullname" . }} + labels: + {{- include "big-chat-splitter-app-k8s.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 6 }} + template: + metadata: + annotations: + {{- toYaml .Values.podAnnotations | nindent 8 }} + labels: + {{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: big-chat-splitter-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: CHAT_SERVICE_HOST + value: {{ .Values.env.services.chat.host | quote }} + - name: CHAT_SERVICE_PORT + value: {{ .Values.env.services.chat.port | quote }} + - name: USER_SERVICE_HOST + value: {{ .Values.env.services.user.host | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/big-chat-splitter-app-k8s/values.yaml b/charts/backend/charts/big-chat-splitter-app-k8s/values.yaml new file mode 100755 index 0000000..0f894c4 --- /dev/null +++ b/charts/backend/charts/big-chat-splitter-app-k8s/values.yaml @@ -0,0 +1,54 @@ + +fullnameOverride: "big-chat-splitter-app" +image: + repository: docker.ii-p001.local/big-chat-splitter-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always +replicaCount: 1 +env: + cassandra: + dc: datacenter1 + host: "cassandra.cassandra.svc.cluster.local" + services: + chat: + host: chat-app + port: 9090 + user: + host: user-app + port: 9090 + redis: + host: redis-master.redis.svc.cluster.local + port: 6379 + kafka: + servers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + +secrets: + cassandra: + name: cassandra + passwordKey: cassandra-password + username: cassandra + + kafka: + name: kafka-password + passwordKey: client-passwords + username: admin + + +resources: + limits: + memory: 1Gi + requests: + cpu: 500m + memory: 512Mi + + +podAnnotations: + kompose.cmd: kompose convert -f app/big-chat-splitter-app.yml -o k8s/big-chat-splitter-app-k8s + kompose.version: 1.33.0 (HEAD) + +podLabels: + io.kompose.network/app-default: "true" + io.kompose.service: big-chat-splitter-app + + +fullnameOverride: "big-chat-splitter-app" \ No newline at end of file diff --git a/charts/backend/charts/call-app-k8s/.helmignore b/charts/backend/charts/call-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/call-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/call-app-k8s/Chart.yaml b/charts/backend/charts/call-app-k8s/Chart.yaml new file mode 100755 index 0000000..09ee51e --- /dev/null +++ b/charts/backend/charts/call-app-k8s/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: call-app +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/charts/backend/charts/call-app-k8s/templates/_helpers.tpl b/charts/backend/charts/call-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..92c7b59 --- /dev/null +++ b/charts/backend/charts/call-app-k8s/templates/_helpers.tpl @@ -0,0 +1,18 @@ +{{/* Common Name Definitions */}} +{{- define "call-app-k8s.fullname" -}} +{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Standard labels */}} +{{- define "call-app-k8s.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} +app.kubernetes.io/name: {{ .Chart.Name }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* Selector labels */}} +{{- define "call-app-k8s.selectorLabels" -}} +io.kompose.service: call-app +{{- end }} diff --git a/charts/backend/charts/call-app-k8s/templates/deployment.yaml b/charts/backend/charts/call-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..127eda7 --- /dev/null +++ b/charts/backend/charts/call-app-k8s/templates/deployment.yaml @@ -0,0 +1,97 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "call-app-k8s.fullname" . }} + labels: + {{- include "call-app-k8s.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "call-app-k8s.selectorLabels" . | nindent 6 }} + template: + metadata: + annotations: + {{- toYaml .Values.podAnnotations | nindent 8 }} + labels: + {{- include "call-app-k8s.selectorLabels" . | nindent 8 }} + {{- toYaml .Values.podLabels | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: call-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 5005 + protocol: TCP + - containerPort: 9090 + protocol: TCP + env: + - name: TENANT_ID + value: {{ .Values.env.TENANT_ID | quote }} + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloak.url | quote }} + - name: LIVEKIT_API_KEY + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.livekit.name }} + key: {{ .Values.secrets.livekit.apiKeyKey }} + - name: LIVEKIT_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.livekit.name }} + key: {{ .Values.secrets.livekit.secretKey }} + - name: RECORDING_ACCESS_KEY + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.recording.name }} + key: {{ .Values.secrets.recording.accessKeyKey }} + - name: RECORDING_API_HOST + value: {{ .Values.env.livekit.apiHost | quote }} + - name: RECORDING_BUCKET + value: {{ .Values.env.recording.bucket | quote }} + - name: RECORDING_ENDPOINT + value: {{ .Values.env.recording.endpoint | quote }} + - name: RECORDING_REGION + value: {{ .Values.env.recording.region | quote }} + - name: RECORDING_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.recording.name }} + key: {{ .Values.secrets.recording.secretKeyKey }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/call-app-k8s/templates/service.yaml b/charts/backend/charts/call-app-k8s/templates/service.yaml new file mode 100755 index 0000000..1aea5ec --- /dev/null +++ b/charts/backend/charts/call-app-k8s/templates/service.yaml @@ -0,0 +1,17 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "call-app-k8s.fullname" . }} + labels: + {{- include "call-app-k8s.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + ports: + {{- range .Values.service.ports }} + - name: {{ .name }} + port: {{ .port }} + targetPort: {{ .targetPort }} + protocol: TCP + {{- end }} + selector: + {{- include "call-app-k8s.selectorLabels" . | nindent 4 }} \ No newline at end of file diff --git a/charts/backend/charts/call-app-k8s/values.yaml b/charts/backend/charts/call-app-k8s/values.yaml new file mode 100755 index 0000000..66b9bac --- /dev/null +++ b/charts/backend/charts/call-app-k8s/values.yaml @@ -0,0 +1,66 @@ +image: + repository: docker.ii-p001.local/call-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +replicaCount: 1 + +service: + type: ClusterIP + ports: + - name: main + port: 5005 + targetPort: 5005 + - name: metrics + port: 9090 + targetPort: 9090 +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + kafka: + brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + port: 6379 + keycloak: + url: https://iam.stage.co-work.local/realms/co-work + livekit: + apiHost: https://av-s001.co-work.ru/ + recording: + endpoint: https://store.stage.co-work.local:9000 + region: us-east-2 + bucket: livekit + TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a" + +secrets: + cassandra: + name: cassandra + usernameKey: username + passwordKey: cassandra-password + kafka: + name: kafka-password + usernameKey: username + passwordKey: client-passwords + redis: + name: redis-kafka-user-passwords + passwordKey: client-passwords + livekit: + name: livekit-secret + apiKeyKey: api-key + secretKey: secret + recording: + name: recording-secret + accessKeyKey: access-key + secretKeyKey: secret + + +podAnnotations: + kompose.cmd: kompose convert -f app/call-app.yml -o k8s/call-app-k8s + kompose.version: 1.33.0 (HEAD) + +podLabels: + io.kompose.network/app-default: "true" + io.kompose.service: call-app + +fullnameOverride: "call-app" diff --git a/charts/backend/charts/call-event-handler-app-k8s/.helmignore b/charts/backend/charts/call-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/call-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/call-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/call-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..c2acbb2 --- /dev/null +++ b/charts/backend/charts/call-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: call-event-handler-app +description: Call Event Handler Application +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/call-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/call-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..41c0ef1 --- /dev/null +++ b/charts/backend/charts/call-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,46 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "call-event-handler-app.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +*/}} +{{- define "call-event-handler-app.fullname" -}} +{{- if .Values.fullnameOverride -}} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "call-event-handler-app.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Common labels +*/}} +{{- define "call-event-handler-app.labels" -}} +helm.sh/chart: {{ include "call-event-handler-app.chart" . }} +{{ include "call-event-handler-app.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end -}} + +{{/* +Selector labels +*/}} +{{- define "call-event-handler-app.selectorLabels" -}} +app.kubernetes.io/name: {{ include "call-event-handler-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end -}} \ No newline at end of file diff --git a/charts/backend/charts/call-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/call-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..994a585 --- /dev/null +++ b/charts/backend/charts/call-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,79 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "call-event-handler-app.fullname" . }} + labels: + {{- include "call-event-handler-app.labels" . | nindent 4 }} + annotations: + {{- toYaml .Values.podAnnotations | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "call-event-handler-app.selectorLabels" . | nindent 6 }} + template: + metadata: + annotations: + {{- toYaml .Values.podAnnotations | nindent 8 }} + labels: + {{- include "call-event-handler-app.selectorLabels" . | nindent 8 }} + {{- toYaml .Values.podLabels | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: {{ .Chart.Name }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 5005 + protocol: TCP + - containerPort: 9090 + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: LIVEKIT_API_KEY + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.livekit.name }} + key: {{ .Values.secrets.livekit.apiKeyKey }} + - name: LIVEKIT_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.livekit.name }} + key: {{ .Values.secrets.livekit.secretKey }} + - name: RECORDING_API_HOST + value: {{ .Values.env.recording.apiHost | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/call-event-handler-app-k8s/templates/service.yaml b/charts/backend/charts/call-event-handler-app-k8s/templates/service.yaml new file mode 100755 index 0000000..4b73d84 --- /dev/null +++ b/charts/backend/charts/call-event-handler-app-k8s/templates/service.yaml @@ -0,0 +1,17 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "call-event-handler-app.fullname" . }} + labels: + {{- include "call-event-handler-app.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + ports: + {{- range .Values.service.ports }} + - name: {{ .name }} + port: {{ .port }} + targetPort: {{ .targetPort }} + protocol: TCP + {{- end }} + selector: + {{- include "call-event-handler-app.selectorLabels" . | nindent 4 }} \ No newline at end of file diff --git a/charts/backend/charts/call-event-handler-app-k8s/values.yaml b/charts/backend/charts/call-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..f83bf5a --- /dev/null +++ b/charts/backend/charts/call-event-handler-app-k8s/values.yaml @@ -0,0 +1,57 @@ +image: + repository: docker.ii-p001.local/call-event-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +replicaCount: 1 + +service: + type: ClusterIP + ports: + - name: main + port: 5005 + targetPort: 5005 + - name: metrics + port: 9090 + targetPort: 9090 + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + kafka: + brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + port: "6379" + recording: + apiHost: https://store.stage.co-work.local:9000 + +secrets: + cassandra: + name: cassandra + usernameKey: username + passwordKey: cassandra-password + kafka: + name: kafka-password + usernameKey: username + passwordKey: client-passwords + redis: + name: redis-kafka-user-passwords + passwordKey: client-passwords + livekit: + name: livekit-secret + apiKeyKey: api-key + secretKey: secret + +podAnnotations: + kompose.cmd: kompose convert -f app/call-event-handler-app.yml -o k8s/call-event-handler-app-k8s + kompose.version: 1.33.0 (HEAD) + +podLabels: + io.kompose.network/app-default: "true" + io.kompose.service: call-event-handler-app + + +nameOverride: "" +fullnameOverride: "" \ No newline at end of file diff --git a/charts/backend/charts/call-realtime-app-k8s/.helmignore b/charts/backend/charts/call-realtime-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/call-realtime-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/call-realtime-app-k8s/Chart.yaml b/charts/backend/charts/call-realtime-app-k8s/Chart.yaml new file mode 100755 index 0000000..d2d0f02 --- /dev/null +++ b/charts/backend/charts/call-realtime-app-k8s/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: call-realtime-app +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/charts/backend/charts/call-realtime-app-k8s/templates/_helpers.tpl b/charts/backend/charts/call-realtime-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..487cb28 --- /dev/null +++ b/charts/backend/charts/call-realtime-app-k8s/templates/_helpers.tpl @@ -0,0 +1,39 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "call-realtime-app.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +*/}} +{{- define "call-realtime-app.fullname" -}} +{{- if .Values.fullnameOverride -}} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} + +{{/* +Common labels +*/}} +{{- define "call-realtime-app.labels" -}} +helm.sh/chart: {{ include "call-realtime-app.name" . }} +{{ include "call-realtime-app.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end -}} + +{{/* +Selector labels +*/}} +{{- define "call-realtime-app.selectorLabels" -}} +app.kubernetes.io/name: {{ include "call-realtime-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end -}} \ No newline at end of file diff --git a/charts/backend/charts/call-realtime-app-k8s/templates/deployment.yaml b/charts/backend/charts/call-realtime-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..1febce4 --- /dev/null +++ b/charts/backend/charts/call-realtime-app-k8s/templates/deployment.yaml @@ -0,0 +1,93 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "call-realtime-app.fullname" . }} + labels: + {{- include "call-realtime-app.labels" . | nindent 4 }} + annotations: + {{- toYaml .Values.podAnnotations | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "call-realtime-app.selectorLabels" . | nindent 6 }} + template: + metadata: + annotations: + {{- toYaml .Values.podAnnotations | nindent 8 }} + labels: + {{- include "call-realtime-app.selectorLabels" . | nindent 8 }} + {{- toYaml .Values.podLabels | nindent 8 }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: {{ .Chart.Name }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 5005 + protocol: TCP + - containerPort: 9090 + protocol: TCP + env: + - name: TENANT_ID + value: {{ .Values.env.TENANT_ID | quote }} + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: LIVEKIT_API_KEY + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.livekit.name }} + key: {{ .Values.secrets.livekit.apiKeyKey }} + - name: LIVEKIT_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.livekit.name }} + key: {{ .Values.secrets.livekit.secretKey }} + - name: RECORDING_ACCESS_KEY + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.recording.name }} + key: {{ .Values.secrets.recording.accessKeyKey }} + - name: RECORDING_API_HOST + value: {{ .Values.env.recording.apiHost | quote }} + - name: RECORDING_BUCKET + value: {{ .Values.env.recording.bucket | quote }} + - name: RECORDING_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.recording.name }} + key: {{ .Values.secrets.recording.secretKey }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/call-realtime-app-k8s/templates/service.yaml b/charts/backend/charts/call-realtime-app-k8s/templates/service.yaml new file mode 100755 index 0000000..c12d742 --- /dev/null +++ b/charts/backend/charts/call-realtime-app-k8s/templates/service.yaml @@ -0,0 +1,17 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "call-realtime-app.fullname" . }} + labels: + {{- include "call-realtime-app.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + ports: + {{- range .Values.service.ports }} + - name: {{ .name }} + port: {{ .port }} + targetPort: {{ .targetPort }} + protocol: TCP + {{- end }} + selector: + {{- include "call-realtime-app.selectorLabels" . | nindent 4 }} \ No newline at end of file diff --git a/charts/backend/charts/call-realtime-app-k8s/values.yaml b/charts/backend/charts/call-realtime-app-k8s/values.yaml new file mode 100755 index 0000000..4cd496c --- /dev/null +++ b/charts/backend/charts/call-realtime-app-k8s/values.yaml @@ -0,0 +1,66 @@ +# Image Configuration +image: + repository: docker.ii-p001.local/call-realtime-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +# Replica Configuration +replicaCount: 1 + +# Service Configuration +service: + type: ClusterIP + ports: + - name: main + port: 5096 + targetPort: 5005 + - name: metrics + port: 9090 + targetPort: 9090 + +# Environment Configuration +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + kafka: + brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + port: "6379" + recording: + apiHost: https://store.stage.co-work.local:9000 + bucket: livekit + TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a" + +# Secret References +secrets: + cassandra: + name: cassandra + usernameKey: username + passwordKey: cassandra-password + kafka: + name: kafka-password + usernameKey: username + passwordKey: client-passwords + livekit: + name: livekit-secret + apiKeyKey: api-key + secretKey: secret + recording: + name: recording-secret + accessKeyKey: access-key + secretKey: secret + +# Kompose Metadata +podAnnotations: + kompose.cmd: kompose convert -f app/call-realtime-app.yml -o k8s/call-realtime-app-k8s + kompose.version: 1.33.0 (HEAD) + +podLabels: + io.kompose.network/app-default: "true" + io.kompose.service: call-realtime-app + +# Chart Metadata +nameOverride: "" +fullnameOverride: call-realtime-app diff --git a/charts/backend/charts/chat-app-k8s/.helmignore b/charts/backend/charts/chat-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/chat-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/chat-app-k8s/Chart.yaml b/charts/backend/charts/chat-app-k8s/Chart.yaml new file mode 100755 index 0000000..2156ab6 --- /dev/null +++ b/charts/backend/charts/chat-app-k8s/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: chat-app +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/charts/backend/charts/chat-app-k8s/templates/_helpers.tpl b/charts/backend/charts/chat-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..ae0b849 --- /dev/null +++ b/charts/backend/charts/chat-app-k8s/templates/_helpers.tpl @@ -0,0 +1,27 @@ +{{/* +Return the name of the chart +*/}} +{{- define "chat-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* +Create a default fully qualified app name. +*/}} +{{- define "chat-app.fullname" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "chat-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "chat-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} +{{- define "chat-app.quote" -}} +{{- . | quote }} +{{- end }} diff --git a/charts/backend/charts/chat-app-k8s/templates/deployment.yaml b/charts/backend/charts/chat-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..23be3fa --- /dev/null +++ b/charts/backend/charts/chat-app-k8s/templates/deployment.yaml @@ -0,0 +1,105 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "chat-app.fullname" . }} + labels: + {{- include "chat-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "chat-app.name" . }} + template: + metadata: + labels: + app: {{ include "chat-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: {{ .Chart.Name }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + hostPort: 8085 + - containerPort: 5005 + hostPort: 5085 + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: DEEPLINK_HOST + value: {{ .Values.env.DEEPLINK_HOST }} + - name: DEEPLINK_PORT + value: {{ include "chat-app.quote" .Values.env.DEEPLINK_PORT }} + - name: GEM_CALL_HOST + value: {{ .Values.env.GEM_CALL_HOST }} + - name: GEM_CALL_PORT + value: {{ include "chat-app.quote" .Values.env.GEM_CALL_PORT }} + - name: MESSAGE_HOST + value: {{ .Values.env.MESSAGE_HOST }} + - name: MESSAGE_PORT + value: {{ .Values.env.MESSAGE_PORT | quote }} + - name: SEARCH_HOST + value: {{ .Values.env.SEARCH_HOST }} + - name: SEARCH_PORT + value: {{ include "chat-app.quote" .Values.env.SEARCH_PORT }} + - name: USER_HOST + value: {{ .Values.env.USER_HOST }} + - name: USER_PORT + value: {{ include "chat-app.quote" .Values.env.USER_PORT }} + - name: KEYCLOAK_URL + value: {{ .Values.env.KEYCLOAK_URL }} + - name: LIVEKIT_API_KEY + valueFrom: + secretKeyRef: + name: livekit-secret + key: api-key + - name: LIVEKIT_SECRET + valueFrom: + secretKeyRef: + name: livekit-secret + key: secret + - name: RECORDING_ACCESS_KEY + valueFrom: + secretKeyRef: + name: recording-secret + key: access-key + - name: RECORDING_SECRET + valueFrom: + secretKeyRef: + name: recording-secret + key: secret + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/chat-app-k8s/templates/service.yaml b/charts/backend/charts/chat-app-k8s/templates/service.yaml new file mode 100755 index 0000000..413533e --- /dev/null +++ b/charts/backend/charts/chat-app-k8s/templates/service.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "chat-app.fullname" . }} + labels: + {{- include "chat-app.labels" . | nindent 4 }} +spec: + selector: + app: {{ include "chat-app.name" . }} + ports: + - name: http + port: 9090 + targetPort: 9090 + - name: debug + port: 5085 + targetPort: 5005 diff --git a/charts/backend/charts/chat-app-k8s/values.yaml b/charts/backend/charts/chat-app-k8s/values.yaml new file mode 100755 index 0000000..3811d8e --- /dev/null +++ b/charts/backend/charts/chat-app-k8s/values.yaml @@ -0,0 +1,24 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/chat-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local + CASSANDRA_DATACENTER: datacenter1 + KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + REDIS_HOST: redis-master.redis.svc.cluster.local + REDIS_PORT: "6379" + DEEPLINK_HOST: deeplink-app + DEEPLINK_PORT: "9090" + GEM_CALL_HOST: gem-call-app + GEM_CALL_PORT: "9090" + MESSAGE_HOST: message-app + MESSAGE_PORT: "9090" + SEARCH_HOST: search-app + SEARCH_PORT: "9090" + USER_HOST: user-app + USER_PORT: "9090" + KEYCLOAK_URL: https://iam.stage.co-work.local/realms/co-work diff --git a/charts/backend/charts/chat-event-handler-app-k8s/.helmignore b/charts/backend/charts/chat-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/chat-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/chat-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/chat-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..9056195 --- /dev/null +++ b/charts/backend/charts/chat-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: chat-event-handler-app +description: A Helm chart for Kubernetes +type: application +version: 0.1.0 +appVersion: "1.16.0" diff --git a/charts/backend/charts/chat-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/chat-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..1d6775e --- /dev/null +++ b/charts/backend/charts/chat-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,27 @@ +{{/* +Return the name of the chart +*/}} +{{- define "chat-event-handler-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* +Create a default fully qualified app name. +*/}} +{{- define "chat-event-handler-app.fullname" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "chat-event-handler-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "chat-event-handler-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} +{{- define "chat-event-handler-app.quote" -}} +{{- . | quote }} +{{- end }} diff --git a/charts/backend/charts/chat-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/chat-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..eb013e5 --- /dev/null +++ b/charts/backend/charts/chat-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,83 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "chat-event-handler-app.fullname" . }} + labels: + {{- include "chat-event-handler-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "chat-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "chat-event-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: {{ .Chart.Name }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 5005 + hostPort: 5086 + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: DEEPLINK_HOST + value: {{ .Values.env.DEEPLINK_HOST }} + - name: DEEPLINK_PORT + value: {{ include "chat-event-handler-app.quote" .Values.env.DEEPLINK_PORT }} + - name: GEM_CALL_HOST + value: {{ .Values.env.GEM_CALL_HOST }} + - name: GEM_CALL_PORT + value: {{ include "chat-event-handler-app.quote" .Values.env.GEM_CALL_PORT }} + - name: MESSAGE_HOST + value: {{ .Values.env.MESSAGE_HOST }} + - name: MESSAGE_PORT + value: {{ .Values.env.MESSAGE_PORT | quote }} + - name: SEARCH_HOST + value: {{ .Values.env.SEARCH_HOST }} + - name: SEARCH_PORT + value: {{ include "chat-event-handler-app.quote" .Values.env.SEARCH_PORT }} + - name: USER_HOST + value: {{ .Values.env.USER_HOST }} + - name: USER_PORT + value: {{ include "chat-event-handler-app.quote" .Values.env.USER_PORT }} + - name: KEYCLOAK_URL + value: {{ .Values.env.KEYCLOAK_URL }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/chat-event-handler-app-k8s/templates/service.yaml b/charts/backend/charts/chat-event-handler-app-k8s/templates/service.yaml new file mode 100755 index 0000000..d6e58fa --- /dev/null +++ b/charts/backend/charts/chat-event-handler-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "chat-event-handler-app.fullname" . }} + labels: + {{- include "chat-event-handler-app.labels" . | nindent 4 }} +spec: + selector: + app: {{ include "chat-event-handler-app.name" . }} + ports: + - name: debug + port: 5086 + targetPort: 5005 diff --git a/charts/backend/charts/chat-event-handler-app-k8s/values.yaml b/charts/backend/charts/chat-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..3b04b6b --- /dev/null +++ b/charts/backend/charts/chat-event-handler-app-k8s/values.yaml @@ -0,0 +1,23 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/chat-event-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local + CASSANDRA_DATACENTER: datacenter1 + MESSAGE_HOST: message-app + MESSAGE_PORT: "9090" + USER_HOST: user-app + USER_PORT: "9090" + SEARCH_HOST: search-app + SEARCH_PORT: "9090" + GEM_CALL_HOST: gem-call-app + GEM_CALL_PORT: "9090" + DEEPLINK_HOST: deeplink-app + DEEPLINK_PORT: "9090" + REDIS_HOST: redis-master.redis.svc.cluster.local + REDIS_PORT: "6379" + KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" diff --git a/charts/backend/charts/deeplink-app-k8s/.helmignore b/charts/backend/charts/deeplink-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/deeplink-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/deeplink-app-k8s/Chart.yaml b/charts/backend/charts/deeplink-app-k8s/Chart.yaml new file mode 100755 index 0000000..f23c975 --- /dev/null +++ b/charts/backend/charts/deeplink-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: deeplink-app +description: A Helm chart for Kubernetes +type: application +version: 0.1.0 +appVersion: "1.16.0" diff --git a/charts/backend/charts/deeplink-app-k8s/templates/_helpers.tpl b/charts/backend/charts/deeplink-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..dee3dea --- /dev/null +++ b/charts/backend/charts/deeplink-app-k8s/templates/_helpers.tpl @@ -0,0 +1,17 @@ +{{/* Chart name */}} +{{- define "deeplink-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{- define "deeplink-app.fullname" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* Common labels */}} +{{- define "deeplink-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "deeplink-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} diff --git a/charts/backend/charts/deeplink-app-k8s/templates/deployment.yaml b/charts/backend/charts/deeplink-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..9e430ea --- /dev/null +++ b/charts/backend/charts/deeplink-app-k8s/templates/deployment.yaml @@ -0,0 +1,72 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "deeplink-app.fullname" . }} + labels: + {{- include "deeplink-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "deeplink-app.name" . }} + template: + metadata: + labels: + app: {{ include "deeplink-app.name" . }} + spec: + containers: + - name: {{ include "deeplink-app.name" . }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + ports: + - containerPort: {{ .Values.container.port }} + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: BRANCHIO_ACCESS + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: branchio-access + - name: BRANCHIO_APPID + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: branchio-appid + - name: BRANCHIO_DEFAULT_URL + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: branchio-default-url + - name: BRANCHIO_KEY + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: branchio-key + - name: BRANCHIO_SECRET + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: branchio-secret + - name: BRANCHIO_URL + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: branchio-url + - name: DEEPLINK_DOMAIN + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: deeplink-domain + - name: DEEPLINK_WEBDOMAIN + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.branchio }} + key: deeplink-webdomain + - name: DEEPLINK_TENANT + value: {{ .Values.deeplink.tenant | quote }} + + - name: KEYCLOAK_URL + value: {{ .Values.keycloak.url | quote }} + restartPolicy: Always diff --git a/charts/backend/charts/deeplink-app-k8s/templates/service.yaml b/charts/backend/charts/deeplink-app-k8s/templates/service.yaml new file mode 100755 index 0000000..b560b57 --- /dev/null +++ b/charts/backend/charts/deeplink-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "deeplink-app.fullname" . }} + labels: + {{- include "deeplink-app.labels" . | nindent 4 }} +spec: + selector: + app: {{ include "deeplink-app.name" . }} + ports: + - name: http + port: {{ .Values.service.port }} + targetPort: {{ .Values.container.port }} diff --git a/charts/backend/charts/deeplink-app-k8s/values.yaml b/charts/backend/charts/deeplink-app-k8s/values.yaml new file mode 100755 index 0000000..5234d90 --- /dev/null +++ b/charts/backend/charts/deeplink-app-k8s/values.yaml @@ -0,0 +1,23 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/deeplink-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +service: + port: 9090 + +container: + port: 9090 + +keycloak: + url: https://iam.stage.co-work.local/realms/co-work + +secrets: + branchio: deeplink-secret + +env: + CASSANDRA_PORT: "9042" +deeplink: + tenant: stage.co-work.local diff --git a/charts/backend/charts/gem-call-app-k8s/.helmignore b/charts/backend/charts/gem-call-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/gem-call-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/gem-call-app-k8s/Chart.yaml b/charts/backend/charts/gem-call-app-k8s/Chart.yaml new file mode 100755 index 0000000..6dc33e2 --- /dev/null +++ b/charts/backend/charts/gem-call-app-k8s/Chart.yaml @@ -0,0 +1,8 @@ +apiVersion: v2 +name: gem-call-app +description: A Helm chart for gem-call-app + +type: application + +version: 0.1.0 +appVersion: "1.0.0" \ No newline at end of file diff --git a/charts/backend/charts/gem-call-app-k8s/templates/_helpers.tpl b/charts/backend/charts/gem-call-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..c70647f --- /dev/null +++ b/charts/backend/charts/gem-call-app-k8s/templates/_helpers.tpl @@ -0,0 +1,15 @@ +{{- define "gem-call-app.name" -}} +{{- .Chart.Name | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{- define "gem-call-app.fullname" -}} +{{ .Chart.Name }} +{{- end }} + +{{- define "gem-call-app.labels" -}} +helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }} +app.kubernetes.io/name: {{ include "gem-call-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.AppVersion }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} diff --git a/charts/backend/charts/gem-call-app-k8s/templates/deployment.yaml b/charts/backend/charts/gem-call-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..745723f --- /dev/null +++ b/charts/backend/charts/gem-call-app-k8s/templates/deployment.yaml @@ -0,0 +1,51 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "gem-call-app.fullname" . }} + labels: + {{- include "gem-call-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "gem-call-app.name" . }} + template: + metadata: + labels: + app: {{ include "gem-call-app.name" . }} + spec: + containers: + - name: {{ include "gem-call-app.name" . }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + - containerPort: 5005 + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: CALL_HOST + value: {{ .Values.call.host | quote }} + - name: CALL_PORT + value: {{ .Values.call.port | quote }} + - name: CALL_REALTIME_HOST + value: {{ .Values.callRealtime.host | quote }} + - name: CALL_REALTIME_PORT + value: {{ .Values.callRealtime.port | quote }} + - name: CHAT_HOST + value: {{ .Values.chat.host | quote }} + - name: CHAT_PORT + value: {{ .Values.chat.port | quote }} + - name: DEEPLINK_HOST + value: {{ .Values.deeplink.host | quote }} + - name: DEEPLINK_PORT + value: {{ .Values.deeplink.port | quote }} + - name: KEYCLOAK_URL + value: {{ .Values.keycloak.url | quote }} + - name: USER_HOST + value: {{ .Values.user.host | quote }} + - name: USER_PORT + value: {{ .Values.user.port | quote }} + + restartPolicy: Always diff --git a/charts/backend/charts/gem-call-app-k8s/templates/service.yaml b/charts/backend/charts/gem-call-app-k8s/templates/service.yaml new file mode 100755 index 0000000..39730a0 --- /dev/null +++ b/charts/backend/charts/gem-call-app-k8s/templates/service.yaml @@ -0,0 +1,19 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "gem-call-app.fullname" . }} + labels: + app: {{ .Release.Name }} + chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} + release: {{ .Release.Name }} + heritage: {{ .Release.Service }} +spec: + ports: + - name: "9090" + port: 9090 + targetPort: 9090 + - name: "5089" + port: 5089 + targetPort: 5005 + selector: + app: gem-call-app \ No newline at end of file diff --git a/charts/backend/charts/gem-call-app-k8s/values.yaml b/charts/backend/charts/gem-call-app-k8s/values.yaml new file mode 100755 index 0000000..6b8338c --- /dev/null +++ b/charts/backend/charts/gem-call-app-k8s/values.yaml @@ -0,0 +1,41 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/gem-call-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +secrets: + kafka: kafka-password + redis: redis-kafka-user-passwords + +kafka: + bootstrapServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" +redis: + host: redis-master.redis.svc.cluster.local + port: "6379" + +keycloak: + url: https://iam.stage.co-work.local/realms/co-work +env: + cert_alias: nubes + +call: + host: call-app + port: "9090" + +callRealtime: + host: call-realtime-app + port: "9090" + +chat: + host: chat-app + port: "9090" + +deeplink: + host: deeplink-app + port: "9090" + +user: + host: user-app + port: "9090" diff --git a/charts/backend/charts/gem-call-events-handler-app-k8s/.helmignore b/charts/backend/charts/gem-call-events-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/gem-call-events-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/gem-call-events-handler-app-k8s/Chart.yaml b/charts/backend/charts/gem-call-events-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..1caeec0 --- /dev/null +++ b/charts/backend/charts/gem-call-events-handler-app-k8s/Chart.yaml @@ -0,0 +1,8 @@ +apiVersion: v2 +name: gem-call-events-handler-app +description: A Helm chart for gem-call-events-handler-app + +type: application + +version: 0.1.0 +appVersion: "1.0.0" diff --git a/charts/backend/charts/gem-call-events-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/gem-call-events-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..66a5277 --- /dev/null +++ b/charts/backend/charts/gem-call-events-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,15 @@ +{{- define "gem-call-events-handler-app.name" -}} +gem-call-events-handler-app +{{- end -}} + +{{- define "gem-call-events-handler-app.fullname" -}} +{{- .Chart.Name }} +{{- end -}} + +{{- define "gem-call-events-handler-app.labels" -}} +app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +app.kubernetes.io/version: {{ .Chart.Version }} +app.kubernetes.io/component: gem-call-events-handler-app +app.kubernetes.io/part-of: gem-call-events-handler-app +{{- end -}} diff --git a/charts/backend/charts/gem-call-events-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/gem-call-events-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..066e0af --- /dev/null +++ b/charts/backend/charts/gem-call-events-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,65 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "gem-call-events-handler-app.fullname" . }} + labels: + {{- include "gem-call-events-handler-app.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + template: + metadata: + labels: + app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: gem-call-events-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYCLOAK_URL + value: {{ .Values.keycloak.url | quote }} + - name: CHAT_HOST + value: {{ .Values.chat.host | quote }} + - name: CHAT_PORT + value: {{ .Values.chat.port | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/gem-call-events-handler-app-k8s/templates/service.yaml b/charts/backend/charts/gem-call-events-handler-app-k8s/templates/service.yaml new file mode 100755 index 0000000..de057a7 --- /dev/null +++ b/charts/backend/charts/gem-call-events-handler-app-k8s/templates/service.yaml @@ -0,0 +1,19 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "gem-call-events-handler-app.fullname" . }} + labels: + app: {{ .Release.Name }} + chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} + release: {{ .Release.Name }} + heritage: {{ .Release.Service }} +spec: + ports: + - name: "8089" + port: 8089 + targetPort: 9090 + - name: "5089" + port: 5089 + targetPort: 5005 + selector: + io.kompose.service: gem-call-events-handler-app diff --git a/charts/backend/charts/gem-call-events-handler-app-k8s/values.yaml b/charts/backend/charts/gem-call-events-handler-app-k8s/values.yaml new file mode 100755 index 0000000..a5cf852 --- /dev/null +++ b/charts/backend/charts/gem-call-events-handler-app-k8s/values.yaml @@ -0,0 +1,32 @@ +replicaCount: 1 + +image: + repository: "docker.ii-p001.local/gem-call-events-handler-app" + tag: "1.0.0-SNAPSHOT" + pullPolicy: Always + +env: + cassandra: + contactPoint: "cassandra.cassandra.svc.cluster.local" + datacenter: "datacenter1" + kafka: + brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + +keycloak: + url: "https://iam.stage.co-work.local/realms/co-work" + +redis: + host: "redis-master.redis.svc.cluster.local" + port: "6379" + +secrets: + cassandra: cassandra + kafka: kafka-password +chat: + host: "chat-app" + port: "9090" + +additionalEnv: [] + +podAnnotations: {} +podLabels: {} \ No newline at end of file diff --git a/charts/backend/charts/huawei-app-k8s/.helmignore b/charts/backend/charts/huawei-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/huawei-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/huawei-app-k8s/Chart.yaml b/charts/backend/charts/huawei-app-k8s/Chart.yaml new file mode 100755 index 0000000..ca3f813 --- /dev/null +++ b/charts/backend/charts/huawei-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: huawei-app +description: A Helm chart for Kubernetes +type: application +version: 0.1.0 +appVersion: "1.16.0" diff --git a/charts/backend/charts/huawei-app-k8s/templates/_helpers.tpl b/charts/backend/charts/huawei-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..e7f7b42 --- /dev/null +++ b/charts/backend/charts/huawei-app-k8s/templates/_helpers.tpl @@ -0,0 +1,11 @@ +{{- define "huawei-sender-app.name" -}} +huawei-sender-app +{{- end }} + +{{- define "huawei-sender-app.fullname" -}} +huawei-sender-app +{{- end }} + +{{- define "huawei-sender-app.chart" -}} +{{ .Chart.Name }}-{{ .Chart.Version }} +{{- end }} diff --git a/charts/backend/charts/huawei-app-k8s/templates/deployment.yaml b/charts/backend/charts/huawei-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..ec9481d --- /dev/null +++ b/charts/backend/charts/huawei-app-k8s/templates/deployment.yaml @@ -0,0 +1,66 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "huawei-sender-app.fullname" . }} + labels: + app: {{ include "huawei-sender-app.name" . }} + chart: {{ include "huawei-sender-app.chart" . }} + release: {{ .Release.Name }} + heritage: {{ .Release.Service }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "huawei-sender-app.name" . }} + template: + metadata: + labels: + app: {{ include "huawei-sender-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: huawei-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/huawei-app-k8s/templates/service.yaml b/charts/backend/charts/huawei-app-k8s/templates/service.yaml new file mode 100755 index 0000000..3ebf666 --- /dev/null +++ b/charts/backend/charts/huawei-app-k8s/templates/service.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "huawei-sender-app.fullname" . }} + labels: + app: {{ include "huawei-sender-app.name" . }} +spec: + ports: + - port: 8080 + targetPort: 8080 + protocol: TCP + name: http + selector: + app: {{ include "huawei-sender-app.name" . }} diff --git a/charts/backend/charts/huawei-app-k8s/values.yaml b/charts/backend/charts/huawei-app-k8s/values.yaml new file mode 100755 index 0000000..7f583b0 --- /dev/null +++ b/charts/backend/charts/huawei-app-k8s/values.yaml @@ -0,0 +1,15 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/huawei-sender-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +kafka: + bootstrapServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" +redis: + host: "redis-master.redis.svc.cluster.local" + port: "6379" + +secrets: + kafka: kafka-password diff --git a/charts/backend/charts/ios-app-k8s/.helmignore b/charts/backend/charts/ios-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/ios-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/ios-app-k8s/Chart.yaml b/charts/backend/charts/ios-app-k8s/Chart.yaml new file mode 100755 index 0000000..c4b4dc9 --- /dev/null +++ b/charts/backend/charts/ios-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: ios-app +description: Helm chart for iOS sender app +type: application +version: 0.1.0 +appVersion: "1.0.0" \ No newline at end of file diff --git a/charts/backend/charts/ios-app-k8s/templates/_helpers.tpl b/charts/backend/charts/ios-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..1cbdb99 --- /dev/null +++ b/charts/backend/charts/ios-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "ios-app.name" -}} +ios-sender-app +{{- end }} + +{{- define "ios-app.fullname" -}} +{{ .Chart.Name }} +{{- end }} \ No newline at end of file diff --git a/charts/backend/charts/ios-app-k8s/templates/deployment.yaml b/charts/backend/charts/ios-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..bc8b7e6 --- /dev/null +++ b/charts/backend/charts/ios-app-k8s/templates/deployment.yaml @@ -0,0 +1,64 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "ios-app.fullname" . }} + labels: + app: {{ include "ios-app.name" . }} + chart: {{ .Chart.Name }}-{{ .Chart.Version }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "ios-app.name" . }} + template: + metadata: + labels: + app: {{ include "ios-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: ios-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/ios-app-k8s/values.yaml b/charts/backend/charts/ios-app-k8s/values.yaml new file mode 100755 index 0000000..734c952 --- /dev/null +++ b/charts/backend/charts/ios-app-k8s/values.yaml @@ -0,0 +1,13 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/ios-sender-app + tag: "1.0.0-SNAPSHOT" + pullPolicy: Always + +env: + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: "redis-master.redis.svc.cluster.local" + port: "6379" diff --git a/charts/backend/charts/livekit-webhook-handler-app-k8s/.helmignore b/charts/backend/charts/livekit-webhook-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/livekit-webhook-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/livekit-webhook-handler-app-k8s/Chart.yaml b/charts/backend/charts/livekit-webhook-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..3e25d07 --- /dev/null +++ b/charts/backend/charts/livekit-webhook-handler-app-k8s/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v2 +name: livekit-webhook-handler-app +description: A Helm chart for deploying livekit-webhook-handler-app +version: 0.1.0 +appVersion: "1.0.0" \ No newline at end of file diff --git a/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..901ee64 --- /dev/null +++ b/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,13 @@ +{{/* +Generate the name of the application +*/}} +{{- define "livekit-webhook-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{/* +Generate a fullname for the application +*/}} +{{- define "livekit-webhook-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..be78c01 --- /dev/null +++ b/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,78 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "livekit-webhook-handler-app.fullname" . }} + labels: + app: {{ include "livekit-webhook-handler-app.name" . }} + chart: {{ .Chart.Name }}-{{ .Chart.Version }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "livekit-webhook-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "livekit-webhook-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: livekit-webhook-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: {{ .Values.service.targetPort }} + hostPort: {{ .Values.service.port }} + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: LIVEKIT_API_KEY + valueFrom: + secretKeyRef: + name: livekit-secret + key: api-key + - name: LIVEKIT_SECRET + valueFrom: + secretKeyRef: + name: livekit-secret + key: secret + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/service.yaml b/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/service.yaml new file mode 100755 index 0000000..e50df5c --- /dev/null +++ b/charts/backend/charts/livekit-webhook-handler-app-k8s/templates/service.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "livekit-webhook-handler-app.fullname" . }} + labels: + app: {{ include "livekit-webhook-handler-app.name" . }} +spec: + type: {{ .Values.service.type }} + ports: + - name: "http" + port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} + nodePort: {{ .Values.service.nodePort }} + selector: + app: {{ include "livekit-webhook-handler-app.name" . }} + diff --git a/charts/backend/charts/livekit-webhook-handler-app-k8s/values.yaml b/charts/backend/charts/livekit-webhook-handler-app-k8s/values.yaml new file mode 100755 index 0000000..af948aa --- /dev/null +++ b/charts/backend/charts/livekit-webhook-handler-app-k8s/values.yaml @@ -0,0 +1,17 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/livekit-webhook-handler-app + tag: "1.0.0-SNAPSHOT" + pullPolicy: Always + +env: + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + username: "admin" + +service: + port: 5098 + targetPort: 8080 + type: NodePort + nodePort: 31646 diff --git a/charts/backend/charts/message-app-k8s/.helmignore b/charts/backend/charts/message-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/message-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/message-app-k8s/Chart.yaml b/charts/backend/charts/message-app-k8s/Chart.yaml new file mode 100755 index 0000000..94a5449 --- /dev/null +++ b/charts/backend/charts/message-app-k8s/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v2 +name: message-app +description: A Helm chart for deploying the message-app +version: 0.1.0 +appVersion: "1.0.0" \ No newline at end of file diff --git a/charts/backend/charts/message-app-k8s/templates/_helpers.tpl b/charts/backend/charts/message-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..1d98c5e --- /dev/null +++ b/charts/backend/charts/message-app-k8s/templates/_helpers.tpl @@ -0,0 +1,13 @@ +{{/* +Generate the name of the application +*/}} +{{- define "message-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{/* +Generate a fullname for the application +*/}} +{{- define "message-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/message-app-k8s/templates/deployment.yaml b/charts/backend/charts/message-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..21eef5b --- /dev/null +++ b/charts/backend/charts/message-app-k8s/templates/deployment.yaml @@ -0,0 +1,97 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "message-app.fullname" . }} + labels: + app: {{ include "message-app.name" . }} + chart: {{ .Chart.Name }}-{{ .Chart.Version }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "message-app.name" . }} + template: + metadata: + labels: + app: {{ include "message-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: message-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + ports: + - containerPort: {{ .Values.service.targetPort }} + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: TENANT_ID + value: {{ .Values.env.tenant_id | quote }} + - name: STICKER_BASE_URL + value: {{ .Values.env.sticker_base_url | quote }} + - name: CHAT_HOST + value: {{ .Values.env.chat.host | quote }} + - name: CHAT_PORT + value: {{ .Values.env.chat.port | quote }} + - name: DEEPLINK_HOST + value: {{ .Values.env.deeplink.host | quote }} + - name: DEEPLINK_PORT + value: {{ .Values.env.deeplink.port | quote }} + - name: LIVEKIT_API_KEY + value: {{ .Values.env.livekit.api_key | quote }} + - name: LIVEKIT_SECRET + value: {{ .Values.env.livekit.secret | quote }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloak.url | quote }} + - name: KEYSPACE + value: {{ .Values.env.keyspace | quote }} + - name: SEARCH_HOST + value: {{ .Values.env.search.host | quote }} + - name: SEARCH_PORT + value: {{ .Values.env.search.port | quote }} + - name: STICKER_HOST + value: {{ .Values.env.sticker.host | quote }} + - name: STICKER_PORT + value: {{ .Values.env.sticker.port | quote }} + - name: UPLOAD_HOST + value: {{ .Values.env.upload.host | quote }} + - name: UPLOAD_PORT + value: {{ .Values.env.upload.port | quote }} + - name: USER_HOST + value: {{ .Values.env.user.host | quote }} + - name: USER_PORT + value: {{ .Values.env.user.port | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/message-app-k8s/templates/service.yaml b/charts/backend/charts/message-app-k8s/templates/service.yaml new file mode 100755 index 0000000..d20ed84 --- /dev/null +++ b/charts/backend/charts/message-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "message-app.fullname" . }} + labels: + app: {{ include "message-app.name" . }} +spec: + ports: + - name: "http" + port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} + selector: + app: {{ include "message-app.name" . }} diff --git a/charts/backend/charts/message-app-k8s/values.yaml b/charts/backend/charts/message-app-k8s/values.yaml new file mode 100755 index 0000000..5f86cc9 --- /dev/null +++ b/charts/backend/charts/message-app-k8s/values.yaml @@ -0,0 +1,49 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/message-app + tag: "1.0.0-SNAPSHOT" + pullPolicy: Always + +env: + tenant_id: "412eb2e1-9660-4b74-a56a-6198f3b5338a" + sticker_base_url: https://store-s001.co-work.ru:9000 + cassandra: + contactPoint: "cassandra.cassandra.svc.cluster.local" + datacenter: "datacenter1" + CASSANDRA_PORT: "9042" + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + username: "admin" + redis: + host: "redis-master.redis.svc.cluster.local" + port: "6379" + keycloak: + url: "https://iam.stage.co-work.local/realms/co-work" + chat: + host: "chat-app" + port: "9090" + deeplink: + host: "deeplink-app" + port: "9090" + livekit: + api_key: "APIXj3LbDJJPLHv" + secret: "eWWetAn7vlfgFQnXXHyyox8QceBYTnZcIMhDe4I16UeE" + search: + host: "search-app" + port: "9090" + sticker: + host: "sticker-app" + port: "9090" + upload: + host: "upload-app" + port: "9090" + user: + host: "user-app" + port: "9090" + keyspace: "messages" + + +service: + port: 9090 + targetPort: 9090 diff --git a/charts/backend/charts/message-call-event-handler-app-k8s/.helmignore b/charts/backend/charts/message-call-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/message-call-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/message-call-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/message-call-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..5685548 --- /dev/null +++ b/charts/backend/charts/message-call-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v2 +name: message-call-event-handler-app +description: A Helm chart for deploying the message-call-event-handler-app +version: 0.1.0 +appVersion: "1.0.0" \ No newline at end of file diff --git a/charts/backend/charts/message-call-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/message-call-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..bff8b67 --- /dev/null +++ b/charts/backend/charts/message-call-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,13 @@ +{{/* +Generate the name of the application +*/}} +{{- define "message-call-event-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{/* +Generate a fullname for the application +*/}} +{{- define "message-call-event-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/message-call-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/message-call-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..8d2363c --- /dev/null +++ b/charts/backend/charts/message-call-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,89 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "message-call-event-handler-app.fullname" . }} + labels: + app: {{ include "message-call-event-handler-app.name" . }} + chart: {{ .Chart.Name }}-{{ .Chart.Version }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "message-call-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "message-call-event-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: message-call-event-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + ports: + - containerPort: 9090 + hostPort: 8086 + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: LIVEKIT_API_KEY + valueFrom: + secretKeyRef: + name: livekit-secret + key: api-key + - name: LIVEKIT_SECRET + valueFrom: + secretKeyRef: + name: livekit-secret + key: secret + - name: KEYCLOAK_URL + value: "https://iam.stage.co-work.local/realms/co-work" + - name: KEYSPACE + value: {{ .Values.env.keyspace | quote }} + - name: UPLOAD_HOST + value: {{ .Values.env.upload.host | quote }} + - name: UPLOAD_PORT + value: {{ .Values.env.upload.port | quote }} + - name: USER_HOST + value: {{ .Values.env.user.host | quote }} + - name: USER_PORT + value: {{ .Values.env.user.port | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/message-call-event-handler-app-k8s/values.yaml b/charts/backend/charts/message-call-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..2be2ad6 --- /dev/null +++ b/charts/backend/charts/message-call-event-handler-app-k8s/values.yaml @@ -0,0 +1,27 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/message-call-event-handler-app + tag: "1.0.0-SNAPSHOT" + pullPolicy: Always + +env: + cassandra: + contactPoint: "cassandra.cassandra.svc.cluster.local" + datacenter: "datacenter1" + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + username: "admin" + redis: + host: "redis-master.redis.svc.cluster.local" + port: "6379" + keyspace: "messages" + chat: + host: "chat-app" + port: "9090" + upload: + host: "upload-app" + port: "9090" + user: + host: "user-app" + port: "9090" diff --git a/charts/backend/charts/message-chat-event-handler-app-k8s/.helmignore b/charts/backend/charts/message-chat-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/message-chat-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/message-chat-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/message-chat-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..9d53019 --- /dev/null +++ b/charts/backend/charts/message-chat-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: message-chat-event-handler-app +description: A Helm chart for deploying message-chat-event-handler-app +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/message-chat-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/message-chat-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..5c86f8c --- /dev/null +++ b/charts/backend/charts/message-chat-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,53 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "message-chat-event-handler-app.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +Always use the chart name or fullnameOverride. +*/}} +{{- define "message-chat-event-handler-app.fullname" -}} +{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "message-chat-event-handler-app.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "message-chat-event-handler-app.labels" -}} +helm.sh/chart: {{ include "message-chat-event-handler-app.chart" . }} +{{ include "message-chat-event-handler-app.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "message-chat-event-handler-app.selectorLabels" -}} +app.kubernetes.io/name: {{ include "message-chat-event-handler-app.name" . }} +app.kubernetes.io/instance: {{ .Chart.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "message-chat-event-handler-app.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "message-chat-event-handler-app.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/charts/backend/charts/message-chat-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/message-chat-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..b05ca2b --- /dev/null +++ b/charts/backend/charts/message-chat-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,73 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "message-chat-event-handler-app.fullname" . }} + labels: + app: {{ include "message-chat-event-handler-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "message-chat-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "message-chat-event-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: message-chat-event-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + ports: + - containerPort: 9090 + hostPort: 8086 + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: USER_HOST + value: {{ .Values.env.user.host | quote }} + - name: USER_PORT + value: {{ .Values.env.user.port | quote }} + - name: CHAT_HOST + value: {{ .Values.env.chat.host | quote }} + - name: CHAT_PORT + value: {{ .Values.env.chat.port | quote }} + - name: UPLOAD_HOST + value: {{ .Values.env.upload.host | quote }} + - name: UPLOAD_PORT + value: {{ .Values.env.upload.port | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/message-chat-event-handler-app-k8s/values.yaml b/charts/backend/charts/message-chat-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..d9093af --- /dev/null +++ b/charts/backend/charts/message-chat-event-handler-app-k8s/values.yaml @@ -0,0 +1,27 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/message-chat-event-handler-app + tag: "1.0.0-SNAPSHOT" + pullPolicy: Always + +env: + cassandra: + contactPoint: "cassandra.cassandra.svc.cluster.local" + datacenter: "datacenter1" + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + username: "admin" + redis: + host: "redis-master.redis.svc.cluster.local" + port: "6379" + keyspace: "messages" + chat: + host: "chat-app" + port: "9090" + upload: + host: "upload-app" + port: "9090" + user: + host: "user-app" + port: "9090" \ No newline at end of file diff --git a/charts/backend/charts/message-event-handler-app-k8s/.helmignore b/charts/backend/charts/message-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/message-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/message-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/message-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..4c59d1f --- /dev/null +++ b/charts/backend/charts/message-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: message-event-handler-app +description: A Helm chart for the message-event-handler-app +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/message-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/message-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..7d670e2 --- /dev/null +++ b/charts/backend/charts/message-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "message-event-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "message-event-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/message-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/message-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..4a84063 --- /dev/null +++ b/charts/backend/charts/message-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,65 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "message-event-handler-app.fullname" . }} + labels: + app: {{ include "message-event-handler-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "message-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "message-event-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: message-event-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYSPACE + value: {{ .Values.env.cassandra.keyspace | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/message-event-handler-app-k8s/values.yaml b/charts/backend/charts/message-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..608d848 --- /dev/null +++ b/charts/backend/charts/message-event-handler-app-k8s/values.yaml @@ -0,0 +1,17 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/message-event-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + keyspace: messages + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + port: "6379" diff --git a/charts/backend/charts/message-link-preview-handler-app-k8s/.helmignore b/charts/backend/charts/message-link-preview-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/message-link-preview-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/message-link-preview-handler-app-k8s/Chart.yaml b/charts/backend/charts/message-link-preview-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..ccd0fba --- /dev/null +++ b/charts/backend/charts/message-link-preview-handler-app-k8s/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: message-link-preview-handler-app +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/charts/backend/charts/message-link-preview-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/message-link-preview-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..c8233d3 --- /dev/null +++ b/charts/backend/charts/message-link-preview-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "message-link-preview-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "message-link-preview-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/message-link-preview-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/message-link-preview-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..3c14ee8 --- /dev/null +++ b/charts/backend/charts/message-link-preview-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,69 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "message-link-preview-handler-app.fullname" . }} + labels: + app: {{ include "message-link-preview-handler-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "message-link-preview-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "message-link-preview-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: message-link-preview-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYSPACE + value: {{ .Values.env.cassandra.keyspace | quote }} + - name: UPLOAD_HOST + value: {{ .Values.env.upload.host | quote }} + - name: UPLOAD_PORT + value: {{ .Values.env.upload.port | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/message-link-preview-handler-app-k8s/values.yaml b/charts/backend/charts/message-link-preview-handler-app-k8s/values.yaml new file mode 100755 index 0000000..827bf4b --- /dev/null +++ b/charts/backend/charts/message-link-preview-handler-app-k8s/values.yaml @@ -0,0 +1,20 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/message-link-preview-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + keyspace: messages + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + port: "6379" + upload: + host: upload-app + port: "9090" diff --git a/charts/backend/charts/message-user-event-handler-app-k8s/.helmignore b/charts/backend/charts/message-user-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/message-user-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/message-user-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/message-user-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..b756528 --- /dev/null +++ b/charts/backend/charts/message-user-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: message-user-event-handler-app +description: A Helm chart for the message-event-handler-app +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/message-user-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/message-user-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..9423ea6 --- /dev/null +++ b/charts/backend/charts/message-user-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "message-user-event-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "message-user-event-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/message-user-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/message-user-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..746de0f --- /dev/null +++ b/charts/backend/charts/message-user-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,60 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "message-user-event-handler-app.fullname" . }} + labels: + app: {{ include "message-user-event-handler-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "message-user-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "message-user-event-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: message-user-event-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYSPACE + value: {{ .Values.env.cassandra.keyspace | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/message-user-event-handler-app-k8s/values.yaml b/charts/backend/charts/message-user-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..0f413af --- /dev/null +++ b/charts/backend/charts/message-user-event-handler-app-k8s/values.yaml @@ -0,0 +1,18 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/message-user-event-handler-app + pullPolicy: Always + tag: 1.0.0-SNAPSHOT + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + keyspace: messages + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + port: "6379" + kespace: messages diff --git a/charts/backend/charts/notification-app-k8s/.helmignore b/charts/backend/charts/notification-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/notification-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/notification-app-k8s/Chart.yaml b/charts/backend/charts/notification-app-k8s/Chart.yaml new file mode 100755 index 0000000..dda62a6 --- /dev/null +++ b/charts/backend/charts/notification-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: notification-app +description: Helm chart for notification-app +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/notification-app-k8s/templates/_helpers.tpl b/charts/backend/charts/notification-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..217963b --- /dev/null +++ b/charts/backend/charts/notification-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "notification-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "notification-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/notification-app-k8s/templates/deployment.yaml b/charts/backend/charts/notification-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..6f18ffc --- /dev/null +++ b/charts/backend/charts/notification-app-k8s/templates/deployment.yaml @@ -0,0 +1,63 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "notification-app.fullname" . }} + labels: + app: {{ include "notification-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "notification-app.name" . }} + template: + metadata: + labels: + app: {{ include "notification-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: notification-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: {{ .Values.service.targetPort }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloak.url | quote }} + - name: KEYSPACE + value: {{ .Values.env.cassandra.keyspace | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/notification-app-k8s/templates/service.yaml b/charts/backend/charts/notification-app-k8s/templates/service.yaml new file mode 100755 index 0000000..5f5c29f --- /dev/null +++ b/charts/backend/charts/notification-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "notification-app.fullname" . }} + labels: + app: {{ include "notification-app.name" . }} +spec: + selector: + app: {{ include "notification-app.name" . }} + ports: + - name: http + port: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} diff --git a/charts/backend/charts/notification-app-k8s/values.yaml b/charts/backend/charts/notification-app-k8s/values.yaml new file mode 100755 index 0000000..bc97597 --- /dev/null +++ b/charts/backend/charts/notification-app-k8s/values.yaml @@ -0,0 +1,26 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/notification-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + host: cassandra.cassandra.svc.cluster.local + port: "9042" + keyspace: notifications + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + realtimeHost: redis-master.redis.svc.cluster.local + port: "6379" + keycloak: + url: https://iam.stage.co-work.local/realms/co-work + +service: + port: 9090 + targetPort: 9090 diff --git a/charts/backend/charts/notification-event-handler-app-k8s/.helmignore b/charts/backend/charts/notification-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/notification-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/notification-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/notification-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..13c746c --- /dev/null +++ b/charts/backend/charts/notification-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: notification-event-handler-app +description: Helm chart for Notification Event Handler App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/notification-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/notification-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..07f06eb --- /dev/null +++ b/charts/backend/charts/notification-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "notification-event-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "notification-event-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/notification-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/notification-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..27a79b5 --- /dev/null +++ b/charts/backend/charts/notification-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,65 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "notification-event-handler-app.fullname" . }} + labels: + app: {{ include "notification-event-handler-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "notification-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "notification-event-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: notification-event-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: CHAT_SERVICE_HOST + value: {{ .Values.env.chat.host | quote }} + - name: CHAT_SERVICE_PORT + value: {{ .Values.env.chat.port | quote }} + - name: USER_SERVICE_HOST + value: {{ .Values.env.user.host | quote }} + - name: USER_SERVICE_PORT + value: {{ .Values.env.user.port | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts diff --git a/charts/backend/charts/notification-event-handler-app-k8s/values.yaml b/charts/backend/charts/notification-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..64cf658 --- /dev/null +++ b/charts/backend/charts/notification-event-handler-app-k8s/values.yaml @@ -0,0 +1,21 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/notification-event-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + host: cassandra.cassandra.svc.cluster.local + port: "9042" + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + chat: + host: chat-app + port: "9090" + user: + host: user-app + port: "9090" diff --git a/charts/backend/charts/realtime-app-k8s/.helmignore b/charts/backend/charts/realtime-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/realtime-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/realtime-app-k8s/Chart.yaml b/charts/backend/charts/realtime-app-k8s/Chart.yaml new file mode 100755 index 0000000..6609d57 --- /dev/null +++ b/charts/backend/charts/realtime-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: realtime-app +description: Helm chart for Realtime App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/realtime-app-k8s/templates/_helpers.tpl b/charts/backend/charts/realtime-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..a5470c9 --- /dev/null +++ b/charts/backend/charts/realtime-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "realtime-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "realtime-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/realtime-app-k8s/templates/deployment.yaml b/charts/backend/charts/realtime-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..41f3aac --- /dev/null +++ b/charts/backend/charts/realtime-app-k8s/templates/deployment.yaml @@ -0,0 +1,82 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "realtime-app.fullname" . }} + labels: + app: {{ include "realtime-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "realtime-app.name" . }} + template: + metadata: + labels: + app: {{ include "realtime-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: realtime-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloakUrl | quote }} + - name: CHAT_HOST + value: {{ .Values.env.services.chat.host | quote }} + - name: CHAT_PORT + value: {{ .Values.env.services.chat.port | quote }} + - name: GEM_CALL_HOST + value: {{ .Values.env.services.gemCall.host | quote }} + - name: GEM_CALL_PORT + value: {{ .Values.env.services.gemCall.port | quote }} + - name: MESSAGE_HOST + value: {{ .Values.env.services.message.host | quote }} + - name: MESSAGE_PORT + value: {{ .Values.env.services.message.port | quote }} + - name: USER_HOST + value: {{ .Values.env.services.user.host | quote }} + - name: USER_PORT + value: {{ .Values.env.services.user.port | quote }} + ports: + {{- range .Values.ports }} + - name: {{ .name }} + containerPort: {{ .containerPort }} + protocol: TCP + {{- end }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/realtime-app-k8s/templates/service.yaml b/charts/backend/charts/realtime-app-k8s/templates/service.yaml new file mode 100755 index 0000000..39da3e0 --- /dev/null +++ b/charts/backend/charts/realtime-app-k8s/templates/service.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "realtime-app.fullname" . }} + labels: + app: {{ include "realtime-app.name" . }} +spec: + selector: + app: {{ include "realtime-app.name" . }} + ports: + {{- range .Values.ports }} + - name: "{{ .servicePort }}" + port: {{ .servicePort }} + targetPort: {{ .containerPort }} + {{- end }} diff --git a/charts/backend/charts/realtime-app-k8s/values.yaml b/charts/backend/charts/realtime-app-k8s/values.yaml new file mode 100755 index 0000000..e39f565 --- /dev/null +++ b/charts/backend/charts/realtime-app-k8s/values.yaml @@ -0,0 +1,41 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/realtime-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + CASSANDRA_PORT: "9042" + redis: + host: redis-master.redis.svc.cluster.local + keycloakUrl: https://iam.stage.co-work.local/realms/co-work + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + services: + chat: + host: chat-app + port: "9090" + message: + host: message-app + port: "9090" + gemCall: + host: gem-call-app + port: "9090" + user: + host: user-app + port: "9090" + +ports: + - name: app + containerPort: 9090 + servicePort: 9090 + - name: debug + containerPort: 5005 + servicePort: 5091 + - name: metrics + containerPort: 9999 + servicePort: 9999 diff --git a/charts/backend/charts/regular-chat-splitter-app-k8s/.helmignore b/charts/backend/charts/regular-chat-splitter-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/regular-chat-splitter-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/regular-chat-splitter-app-k8s/Chart.yaml b/charts/backend/charts/regular-chat-splitter-app-k8s/Chart.yaml new file mode 100755 index 0000000..eee0ca9 --- /dev/null +++ b/charts/backend/charts/regular-chat-splitter-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: regular-chat-splitter-app +description: Helm chart for Regular Chat Splitter App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/regular-chat-splitter-app-k8s/templates/_helpers.tpl b/charts/backend/charts/regular-chat-splitter-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..3874a01 --- /dev/null +++ b/charts/backend/charts/regular-chat-splitter-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "regular-chat-splitter-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "regular-chat-splitter-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/regular-chat-splitter-app-k8s/templates/deployment.yaml b/charts/backend/charts/regular-chat-splitter-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..819fb96 --- /dev/null +++ b/charts/backend/charts/regular-chat-splitter-app-k8s/templates/deployment.yaml @@ -0,0 +1,66 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "regular-chat-splitter-app.fullname" . }} + labels: + app: {{ include "regular-chat-splitter-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "regular-chat-splitter-app.name" . }} + template: + metadata: + labels: + app: {{ include "regular-chat-splitter-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: regular-chat-splitter-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: CHAT_SERVICE_HOST + value: {{ .Values.env.chat.host | quote }} + - name: CHAT_SERVICE_PORT + value: {{ .Values.env.chat.port | quote }} + - name: USER_SERVICE_HOST + value: {{ .Values.env.user.host | quote }} + - name: USER_SERVICE_PORT + value: {{ .Values.env.user.port | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/regular-chat-splitter-app-k8s/values.yaml b/charts/backend/charts/regular-chat-splitter-app-k8s/values.yaml new file mode 100755 index 0000000..1f85e1d --- /dev/null +++ b/charts/backend/charts/regular-chat-splitter-app-k8s/values.yaml @@ -0,0 +1,22 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/regular-chat-splitter-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + host: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redis: + host: redis-master.redis.svc.cluster.local + port: "6379" + chat: + host: chat-app + port: "9090" + user: + host: user-app + port: "9090" diff --git a/charts/backend/charts/search-app-k8s/.helmignore b/charts/backend/charts/search-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/search-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/search-app-k8s/Chart.yaml b/charts/backend/charts/search-app-k8s/Chart.yaml new file mode 100755 index 0000000..6733dc0 --- /dev/null +++ b/charts/backend/charts/search-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: search-app +description: Helm chart for Search App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/search-app-k8s/templates/_helpers.tpl b/charts/backend/charts/search-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..7a098eb --- /dev/null +++ b/charts/backend/charts/search-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "search-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "search-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/search-app-k8s/templates/deployment.yaml b/charts/backend/charts/search-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..be83330 --- /dev/null +++ b/charts/backend/charts/search-app-k8s/templates/deployment.yaml @@ -0,0 +1,44 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "search-app.fullname" . }} + labels: + app: {{ include "search-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "search-app.name" . }} + template: + metadata: + labels: + app: {{ include "search-app.name" . }} + spec: + containers: + - name: search-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + hostPort: 8088 + protocol: TCP + env: + - name: CHAT_HOST + value: {{ .Values.env.chat.host | quote }} + - name: CHAT_PORT + value: {{ .Values.env.chat.port | quote }} + - name: CASSANDRA_PORT + value: {{ .Values.env.CASSANDRA_PORT | quote }} + - name: ELASTIC_HOST + value: {{ .Values.env.elastic.host | quote }} + - name: ELASTIC_PORT + value: {{ .Values.env.elastic.port | quote }} + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + {{- include "global.env.postgres" . | nindent 12 }} + - name: POSTGRES_URL + value: {{ .Values.env.postgres.url | quote }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloak.url | quote }} + restartPolicy: Always diff --git a/charts/backend/charts/search-app-k8s/templates/service.yaml b/charts/backend/charts/search-app-k8s/templates/service.yaml new file mode 100755 index 0000000..e85b387 --- /dev/null +++ b/charts/backend/charts/search-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "search-app.fullname" . }} + labels: + app: {{ include "search-app.name" . }} +spec: + selector: + app: {{ include "search-app.name" . }} + ports: + - name: http + port: 9090 + targetPort: 9090 diff --git a/charts/backend/charts/search-app-k8s/values.yaml b/charts/backend/charts/search-app-k8s/values.yaml new file mode 100755 index 0000000..65874cb --- /dev/null +++ b/charts/backend/charts/search-app-k8s/values.yaml @@ -0,0 +1,22 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/search-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + chat: + host: chat-app + port: "9090" + elastic: + host: elasticsearch-master + port: "9200" + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + keycloak: + url: https://iam.stage.co-work.local/realms/co-work + postgres: + url: jdbc:postgresql://postgresql-ha-pgpool:5432/search_db + username: postgres + CASSANDRA_PORT: "9042" \ No newline at end of file diff --git a/charts/backend/charts/search-event-handler-app-k8s/.helmignore b/charts/backend/charts/search-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/search-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/search-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/search-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..4267149 --- /dev/null +++ b/charts/backend/charts/search-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: search-event-handler-app +description: Helm chart for Search Event Handler App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" \ No newline at end of file diff --git a/charts/backend/charts/search-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/search-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..b430977 --- /dev/null +++ b/charts/backend/charts/search-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "search-event-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "search-event-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/search-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/search-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..b209877 --- /dev/null +++ b/charts/backend/charts/search-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,42 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "search-event-handler-app.fullname" . }} + labels: + app: {{ include "search-event-handler-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "search-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "search-event-handler-app.name" . }} + spec: + volumes: + + - name: cacerts-volume + emptyDir: {} + + + containers: + - name: search-event-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + - name: ELASTIC_HOST + value: {{ .Values.env.elastic.host | quote }} + - name: ELASTIC_PORT + value: {{ .Values.env.elastic.port | quote }} + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + {{- include "global.env.postgres" . | nindent 12 }} + - name: POSTGRES_URL + value: {{ .Values.env.postgres.url | quote }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloak.url | quote }} + + + restartPolicy: Always diff --git a/charts/backend/charts/search-event-handler-app-k8s/values.yaml b/charts/backend/charts/search-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..b41839d --- /dev/null +++ b/charts/backend/charts/search-event-handler-app-k8s/values.yaml @@ -0,0 +1,17 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/search-event-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + elastic: + host: elasticsearch-master.elasticsearch.svc.cluster.local + port: "9200" + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + keycloak: + url: https://iam.stage.co-work.local/realms/cowork + postgres: + url: jdbc:postgresql://postgresql-ha-pgpool:5432/search_db diff --git a/charts/backend/charts/sticker-app-k8s/.helmignore b/charts/backend/charts/sticker-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/sticker-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/sticker-app-k8s/Chart.yaml b/charts/backend/charts/sticker-app-k8s/Chart.yaml new file mode 100755 index 0000000..d4c926a --- /dev/null +++ b/charts/backend/charts/sticker-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: sticker-app +description: Helm chart for Sticker App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/sticker-app-k8s/templates/_helpers.tpl b/charts/backend/charts/sticker-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..cf165b4 --- /dev/null +++ b/charts/backend/charts/sticker-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "sticker-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "sticker-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/sticker-app-k8s/templates/deployment.yaml b/charts/backend/charts/sticker-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..c9ee922 --- /dev/null +++ b/charts/backend/charts/sticker-app-k8s/templates/deployment.yaml @@ -0,0 +1,70 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "sticker-app.fullname" . }} + labels: + app: {{ include "sticker-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "sticker-app.name" . }} + template: + metadata: + labels: + app: {{ include "sticker-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: sticker-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + hostPort: 8092 + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: TENANT_ID + value: {{ .Values.env.TENANT_ID | quote }} + - name: STICKER_BASE_URL + value: {{ .Values.env.STICKER_BASE_URL | quote }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloak.url | quote }} + - name: KEYSPACE + value: {{ .Values.env.keyspace | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/sticker-app-k8s/templates/service.yaml b/charts/backend/charts/sticker-app-k8s/templates/service.yaml new file mode 100755 index 0000000..13ede05 --- /dev/null +++ b/charts/backend/charts/sticker-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "sticker-app.fullname" . }} + labels: + app: {{ include "sticker-app.name" . }} +spec: + ports: + - name: "8092" + port: 9090 + targetPort: 9090 + selector: + app: {{ include "sticker-app.name" . }} diff --git a/charts/backend/charts/sticker-app-k8s/values.yaml b/charts/backend/charts/sticker-app-k8s/values.yaml new file mode 100755 index 0000000..c9acdeb --- /dev/null +++ b/charts/backend/charts/sticker-app-k8s/values.yaml @@ -0,0 +1,22 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/sticker-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + contactPoint: cassandra.cassandra.svc.cluster.local + port: "9042" + datacenter: datacenter1 + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + keycloak: + url: https://iam.stage.co-work.local/realms/co-work + redis: + host: redis-master.redis.svc.cluster.local + port: "6379" + keyspace: stickers + TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a" + STICKER_BASE_URL: https://store-s001.co-work.ru:9000 diff --git a/charts/backend/charts/unregister-tokens-app-k8s/.helmignore b/charts/backend/charts/unregister-tokens-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/unregister-tokens-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/unregister-tokens-app-k8s/Chart.yaml b/charts/backend/charts/unregister-tokens-app-k8s/Chart.yaml new file mode 100755 index 0000000..040cc3f --- /dev/null +++ b/charts/backend/charts/unregister-tokens-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: unregister-tokens-app +description: Helm chart for Unregister Tokens App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/unregister-tokens-app-k8s/templates/_helpers.tpl b/charts/backend/charts/unregister-tokens-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..3e80d26 --- /dev/null +++ b/charts/backend/charts/unregister-tokens-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "unregister-tokens-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "unregister-tokens-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/unregister-tokens-app-k8s/templates/deployment.yaml b/charts/backend/charts/unregister-tokens-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..006dd10 --- /dev/null +++ b/charts/backend/charts/unregister-tokens-app-k8s/templates/deployment.yaml @@ -0,0 +1,62 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "unregister-tokens-app.fullname" . }} + labels: + app: {{ include "unregister-tokens-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "unregister-tokens-app.name" . }} + template: + metadata: + labels: + app: {{ include "unregister-tokens-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: unregister-tokens-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: KEYSPACE + value: {{ .Values.env.cassandra.keyspace | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/unregister-tokens-app-k8s/values.yaml b/charts/backend/charts/unregister-tokens-app-k8s/values.yaml new file mode 100755 index 0000000..5faacfd --- /dev/null +++ b/charts/backend/charts/unregister-tokens-app-k8s/values.yaml @@ -0,0 +1,15 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/unregister-tokens-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandra: + host: cassandra.cassandra.svc.cluster.local + datacenter: datacenter1 + keyspace: notifications + kafka: + server: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + user: admin diff --git a/charts/backend/charts/upload-app-k8s/.helmignore b/charts/backend/charts/upload-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/upload-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/upload-app-k8s/Chart.yaml b/charts/backend/charts/upload-app-k8s/Chart.yaml new file mode 100755 index 0000000..c090d24 --- /dev/null +++ b/charts/backend/charts/upload-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: upload-app +description: Helm chart for the Upload App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/upload-app-k8s/templates/_helpers.tpl b/charts/backend/charts/upload-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..44077a9 --- /dev/null +++ b/charts/backend/charts/upload-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "upload-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "upload-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/upload-app-k8s/templates/deployment.yaml b/charts/backend/charts/upload-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..da3c708 --- /dev/null +++ b/charts/backend/charts/upload-app-k8s/templates/deployment.yaml @@ -0,0 +1,62 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "upload-app.fullname" . }} + labels: + app: {{ include "upload-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "upload-app.name" . }} + template: + metadata: + labels: + app: {{ include "upload-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: upload-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + env: + {{- include "global.env.s3_upload" . | nindent 12 }} + - name: TENANT_ID + value: {{ .Values.env.TENANT_ID | quote }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloakUrl | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/upload-app-k8s/templates/service.yaml b/charts/backend/charts/upload-app-k8s/templates/service.yaml new file mode 100755 index 0000000..9deb96d --- /dev/null +++ b/charts/backend/charts/upload-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "upload-app.fullname" . }} + labels: + app: {{ include "upload-app.name" . }} +spec: + ports: + - name: "http" + port: 9090 + targetPort: 9090 + selector: + app: {{ include "upload-app.name" . }} diff --git a/charts/backend/charts/upload-app-k8s/values.yaml b/charts/backend/charts/upload-app-k8s/values.yaml new file mode 100755 index 0000000..fccf63d --- /dev/null +++ b/charts/backend/charts/upload-app-k8s/values.yaml @@ -0,0 +1,10 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/upload-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + keycloakUrl: https://iam.stage.co-work.local/realms/co-work + TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a" diff --git a/charts/backend/charts/user-app-k8s/.helmignore b/charts/backend/charts/user-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/user-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/user-app-k8s/Chart.yaml b/charts/backend/charts/user-app-k8s/Chart.yaml new file mode 100755 index 0000000..a6fe370 --- /dev/null +++ b/charts/backend/charts/user-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: user-app +description: Helm chart for the User App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/user-app-k8s/templates/_helpers.tpl b/charts/backend/charts/user-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..321571e --- /dev/null +++ b/charts/backend/charts/user-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "user-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "user-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/user-app-k8s/templates/deployment.yaml b/charts/backend/charts/user-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..4a0e553 --- /dev/null +++ b/charts/backend/charts/user-app-k8s/templates/deployment.yaml @@ -0,0 +1,64 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "user-app.fullname" . }} + labels: + app: {{ include "user-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "user-app.name" . }} + template: + metadata: + labels: + app: {{ include "user-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: user-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + env: + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloakUrl | quote }} + - name: KEYSPACE + value: {{ .Values.env.keyspace | quote }} + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/user-app-k8s/templates/s3-secret.yaml b/charts/backend/charts/user-app-k8s/templates/s3-secret.yaml new file mode 100755 index 0000000..3ea4f51 --- /dev/null +++ b/charts/backend/charts/user-app-k8s/templates/s3-secret.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Secret +metadata: + name: {{ include "user-app.fullname" . }}-s3 +type: Opaque +stringData: + access-key: {{ .Values.s3.accessKey | quote }} + secret-key: {{ .Values.s3.secretKey | quote }} diff --git a/charts/backend/charts/user-app-k8s/templates/service.yaml b/charts/backend/charts/user-app-k8s/templates/service.yaml new file mode 100755 index 0000000..d85664d --- /dev/null +++ b/charts/backend/charts/user-app-k8s/templates/service.yaml @@ -0,0 +1,13 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "user-app.fullname" . }} + labels: + app: {{ include "user-app.name" . }} +spec: + ports: + - name: http + port: 9090 + targetPort: 9090 + selector: + app: {{ include "user-app.name" . }} diff --git a/charts/backend/charts/user-app-k8s/values.yaml b/charts/backend/charts/user-app-k8s/values.yaml new file mode 100755 index 0000000..4bce33e --- /dev/null +++ b/charts/backend/charts/user-app-k8s/values.yaml @@ -0,0 +1,19 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/user-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + keycloakUrl: https://iam.stage.co-work.local/realms/co-work + redisHost: redis-master.redis.svc.cluster.local + redisPort: "6379" + cassandraContactPoint: cassandra.cassandra.svc.cluster.local + cassandraDatacenter: datacenter1 + kafkaServer: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + keyspace: users + +s3: + accessKey: minio-admin + secretKey: X5hqry5cLVDMxzBHvtrE diff --git a/charts/backend/charts/voip-splitter-app-k8s/.helmignore b/charts/backend/charts/voip-splitter-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/voip-splitter-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/voip-splitter-app-k8s/Chart.yaml b/charts/backend/charts/voip-splitter-app-k8s/Chart.yaml new file mode 100755 index 0000000..33f7985 --- /dev/null +++ b/charts/backend/charts/voip-splitter-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: voip-splitter-app +description: Helm chart for the VoIP Splitter App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/voip-splitter-app-k8s/templates/_helpers.tpl b/charts/backend/charts/voip-splitter-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..2e178bf --- /dev/null +++ b/charts/backend/charts/voip-splitter-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "voip-splitter-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "voip-splitter-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/voip-splitter-app-k8s/templates/deployment.yaml b/charts/backend/charts/voip-splitter-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..96e12a4 --- /dev/null +++ b/charts/backend/charts/voip-splitter-app-k8s/templates/deployment.yaml @@ -0,0 +1,66 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "voip-splitter-app.fullname" . }} + labels: + app: {{ include "voip-splitter-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "voip-splitter-app.name" . }} + template: + metadata: + labels: + app: {{ include "voip-splitter-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: voip-splitter-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + - name: CHAT_SERVICE_HOST + value: {{ .Values.env.chatServiceHost | quote }} + - name: CHAT_SERVICE_PORT + value: {{ .Values.env.chatServicePort | quote }} + - name: USER_SERVICE_HOST + value: {{ .Values.env.userServiceHost | quote }} + - name: USER_SERVICE_PORT + value: {{ .Values.env.userServicePort | quote }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/voip-splitter-app-k8s/templates/s3-secret.yaml b/charts/backend/charts/voip-splitter-app-k8s/templates/s3-secret.yaml new file mode 100755 index 0000000..d6abc95 --- /dev/null +++ b/charts/backend/charts/voip-splitter-app-k8s/templates/s3-secret.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Secret +metadata: + name: {{ include "voip-splitter-app.fullname" . }}-s3 +type: Opaque +stringData: + access-key: {{ .Values.s3.accessKey | quote }} + secret-key: {{ .Values.s3.secretKey | quote }} diff --git a/charts/backend/charts/voip-splitter-app-k8s/values.yaml b/charts/backend/charts/voip-splitter-app-k8s/values.yaml new file mode 100755 index 0000000..9e3c5ed --- /dev/null +++ b/charts/backend/charts/voip-splitter-app-k8s/values.yaml @@ -0,0 +1,21 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/voip-splitter-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandraHost: cassandra.cassandra.svc.cluster.local + cassandraDatacenter: datacenter1 + chatServiceHost: chat-app + chatServicePort: "9090" + userServiceHost: user-app + userServicePort: "9090" + kafkaServer: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redisHost: redis-master.redis.svc.cluster.local + redisPort: "6379" + +s3: + accessKey: minio-admin + secretKey: X5hqry5cLVDMxzBHvtrE diff --git a/charts/backend/charts/web-sender-app-k8s/.helmignore b/charts/backend/charts/web-sender-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/web-sender-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/web-sender-app-k8s/Chart.yaml b/charts/backend/charts/web-sender-app-k8s/Chart.yaml new file mode 100755 index 0000000..fe79f87 --- /dev/null +++ b/charts/backend/charts/web-sender-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: web-sender-app +description: Helm chart for Web Sender App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/web-sender-app-k8s/templates/_helpers.tpl b/charts/backend/charts/web-sender-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..7ed2215 --- /dev/null +++ b/charts/backend/charts/web-sender-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "web-sender-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "web-sender-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/web-sender-app-k8s/templates/deployment.yaml b/charts/backend/charts/web-sender-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..113d872 --- /dev/null +++ b/charts/backend/charts/web-sender-app-k8s/templates/deployment.yaml @@ -0,0 +1,63 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "web-sender-app.fullname" . }} + labels: + app: {{ include "web-sender-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "web-sender-app.name" . }} + template: + metadata: + labels: + app: {{ include "web-sender-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: web-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + {{- include "global.env.redis" . | nindent 12 }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/web-sender-app-k8s/templates/s3-secret.yaml b/charts/backend/charts/web-sender-app-k8s/templates/s3-secret.yaml new file mode 100755 index 0000000..cf5ca44 --- /dev/null +++ b/charts/backend/charts/web-sender-app-k8s/templates/s3-secret.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Secret +metadata: + name: {{ include "web-sender-app.fullname" . }}-s3 +type: Opaque +stringData: + access-key: {{ .Values.s3.accessKey | quote }} + secret-key: {{ .Values.s3.secretKey | quote }} diff --git a/charts/backend/charts/web-sender-app-k8s/values.yaml b/charts/backend/charts/web-sender-app-k8s/values.yaml new file mode 100755 index 0000000..5a21aff --- /dev/null +++ b/charts/backend/charts/web-sender-app-k8s/values.yaml @@ -0,0 +1,15 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/web-sender-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + kafkaServer: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" + redisHost: redis-master.redis.svc.cluster.local + redisPort: "6379" + +s3: + accessKey: minio-admin + secretKey: X5hqry5cLVDMxzBHvtrE diff --git a/charts/backend/charts/workspace-app-k8s/.helmignore b/charts/backend/charts/workspace-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/workspace-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/workspace-app-k8s/Chart.yaml b/charts/backend/charts/workspace-app-k8s/Chart.yaml new file mode 100755 index 0000000..22f38a4 --- /dev/null +++ b/charts/backend/charts/workspace-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: workspace-app +description: Helm chart for Workspace App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/workspace-app-k8s/templates/_helpers.tpl b/charts/backend/charts/workspace-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..88af440 --- /dev/null +++ b/charts/backend/charts/workspace-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "workspace-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "workspace-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/workspace-app-k8s/templates/deployment.yaml b/charts/backend/charts/workspace-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..1dea7d9 --- /dev/null +++ b/charts/backend/charts/workspace-app-k8s/templates/deployment.yaml @@ -0,0 +1,61 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "workspace-app.fullname" . }} + labels: + app: {{ include "workspace-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "workspace-app.name" . }} + template: + metadata: + labels: + app: {{ include "workspace-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts && + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + containers: + - name: workspace-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + {{- include "global.env.cassandra" . | nindent 12 }} + - name: KEYCLOAK_URL + value: {{ .Values.env.keycloakUrl | quote }} + ports: + - containerPort: 9090 + protocol: TCP + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/workspace-app-k8s/templates/s3-secret.yaml b/charts/backend/charts/workspace-app-k8s/templates/s3-secret.yaml new file mode 100755 index 0000000..e49701b --- /dev/null +++ b/charts/backend/charts/workspace-app-k8s/templates/s3-secret.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Secret +metadata: + name: {{ include "workspace-app.fullname" . }}-s3 +type: Opaque +stringData: + access-key: {{ .Values.s3.accessKey | quote }} + secret-key: {{ .Values.s3.secretKey | quote }} diff --git a/charts/backend/charts/workspace-app-k8s/templates/service.yaml b/charts/backend/charts/workspace-app-k8s/templates/service.yaml new file mode 100755 index 0000000..8382d46 --- /dev/null +++ b/charts/backend/charts/workspace-app-k8s/templates/service.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "workspace-app.fullname" . }} + labels: + app: {{ include "workspace-app.name" . }} +spec: + selector: + app: {{ include "workspace-app.name" . }} + ports: + - name: http + port: 9090 + targetPort: 9090 + protocol: TCP diff --git a/charts/backend/charts/workspace-app-k8s/values.yaml b/charts/backend/charts/workspace-app-k8s/values.yaml new file mode 100755 index 0000000..5a7d9c5 --- /dev/null +++ b/charts/backend/charts/workspace-app-k8s/values.yaml @@ -0,0 +1,15 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/workspace-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandraContactPoint: cassandra.cassandra.svc.cluster.local + cassandraDatacenter: datacenter1 + keycloakUrl: https://iam.stage.co-work.local/realms/co-work + +s3: + accessKey: minio-admin + secretKey: X5hqry5cLVDMxzBHvtrE diff --git a/charts/backend/charts/workspace-event-handler-app-k8s/.helmignore b/charts/backend/charts/workspace-event-handler-app-k8s/.helmignore new file mode 100755 index 0000000..0e8a0eb --- /dev/null +++ b/charts/backend/charts/workspace-event-handler-app-k8s/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/backend/charts/workspace-event-handler-app-k8s/Chart.yaml b/charts/backend/charts/workspace-event-handler-app-k8s/Chart.yaml new file mode 100755 index 0000000..bcb3803 --- /dev/null +++ b/charts/backend/charts/workspace-event-handler-app-k8s/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: workspace-event-handler-app +description: Helm chart for Workspace Event Handler App +type: application +version: 0.1.0 +appVersion: "1.0.0-SNAPSHOT" diff --git a/charts/backend/charts/workspace-event-handler-app-k8s/templates/_helpers.tpl b/charts/backend/charts/workspace-event-handler-app-k8s/templates/_helpers.tpl new file mode 100755 index 0000000..1e3259a --- /dev/null +++ b/charts/backend/charts/workspace-event-handler-app-k8s/templates/_helpers.tpl @@ -0,0 +1,7 @@ +{{- define "workspace-event-handler-app.name" -}} +{{ .Chart.Name }} +{{- end -}} + +{{- define "workspace-event-handler-app.fullname" -}} +{{ .Chart.Name }} +{{- end -}} diff --git a/charts/backend/charts/workspace-event-handler-app-k8s/templates/deployment.yaml b/charts/backend/charts/workspace-event-handler-app-k8s/templates/deployment.yaml new file mode 100755 index 0000000..cadbd76 --- /dev/null +++ b/charts/backend/charts/workspace-event-handler-app-k8s/templates/deployment.yaml @@ -0,0 +1,65 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "workspace-event-handler-app.fullname" . }} + labels: + app: {{ include "workspace-event-handler-app.name" . }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: {{ include "workspace-event-handler-app.name" . }} + template: + metadata: + labels: + app: {{ include "workspace-event-handler-app.name" . }} + spec: + volumes: + - name: ca-cert + configMap: + name: auth-app-ca-cert + items: + - key: RootCA_{{ .Values.global.cert_alias }}.crt + path: RootCA_{{ .Values.global.cert_alias }}.crt + - name: cacerts-volume + emptyDir: {} + initContainers: + - name: import-ca + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + env: + - name: CERT_ALIAS + value: {{ .Values.global.cert_alias | quote }} + volumeMounts: + - name: ca-cert + mountPath: /app/resources + - name: cacerts-volume + mountPath: /tmp/cacerts + command: + - sh + - -c + - | + cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts + if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then + echo "Certificate with alias gemcert already exists, skipping import" + else + echo "Importing certificate with alias gemcert" + keytool -import -trustcacerts -storepass changeit -noprompt \ + -alias gemcert \ + -file /app/resources/RootCA_${CERT_ALIAS}.crt \ + -keystore /tmp/cacerts/cacerts + fi + containers: + - name: workspace-event-handler-app + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 9090 + protocol: TCP + env: + {{- include "global.env.cassandra" . | nindent 12 }} + {{- include "global.env.kafka" . | nindent 12 }} + volumeMounts: + - name: cacerts-volume + mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts + subPath: cacerts + restartPolicy: Always diff --git a/charts/backend/charts/workspace-event-handler-app-k8s/templates/s3-secret.yaml b/charts/backend/charts/workspace-event-handler-app-k8s/templates/s3-secret.yaml new file mode 100755 index 0000000..2726407 --- /dev/null +++ b/charts/backend/charts/workspace-event-handler-app-k8s/templates/s3-secret.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Secret +metadata: + name: {{ include "workspace-event-handler-app.fullname" . }}-s3 +type: Opaque +stringData: + access-key: {{ .Values.s3.accessKey | quote }} + secret-key: {{ .Values.s3.secretKey | quote }} diff --git a/charts/backend/charts/workspace-event-handler-app-k8s/templates/service.yaml b/charts/backend/charts/workspace-event-handler-app-k8s/templates/service.yaml new file mode 100755 index 0000000..6ab7149 --- /dev/null +++ b/charts/backend/charts/workspace-event-handler-app-k8s/templates/service.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "workspace-event-handler-app.fullname" . }} + labels: + app: {{ include "workspace-event-handler-app.name" . }} +spec: + selector: + app: {{ include "workspace-event-handler-app.name" . }} + ports: + - name: http + port: 8095 + targetPort: 9090 + protocol: TCP diff --git a/charts/backend/charts/workspace-event-handler-app-k8s/values.yaml b/charts/backend/charts/workspace-event-handler-app-k8s/values.yaml new file mode 100755 index 0000000..504d75c --- /dev/null +++ b/charts/backend/charts/workspace-event-handler-app-k8s/values.yaml @@ -0,0 +1,14 @@ +replicaCount: 1 + +image: + repository: docker.ii-p001.local/workspace-event-handler-app + tag: 1.0.0-SNAPSHOT + pullPolicy: Always + +env: + cassandraContactPoint: cassandra.cassandra.svc.cluster.local + cassandraDatacenter: datacenter1 + kafkaHost: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092" +s3: + accessKey: minio-access + secretKey: s3cr3t-minio diff --git a/charts/backend/templates/.helmignore b/charts/backend/templates/.helmignore new file mode 100755 index 0000000..e69de29 diff --git a/charts/backend/templates/templates/_globals.tpl b/charts/backend/templates/templates/_globals.tpl new file mode 100755 index 0000000..c12d48e --- /dev/null +++ b/charts/backend/templates/templates/_globals.tpl @@ -0,0 +1,36 @@ +{{/* Global Environment Templates */}} +{{- define "global.env.kafka" -}} + {{- if .Values.global.infrastructure.kafka.enabled -}} + {{- tpl (.Values.global.envTemplates.kafka | toYaml) . | nindent 0 -}} + {{- end -}} +{{- end -}} + +{{- define "global.env.redis" -}} + {{- if .Values.global.infrastructure.redis.enabled -}} + {{- tpl (.Values.global.envTemplates.redis | toYaml) . | nindent 0 -}} + {{- end -}} +{{- end -}} + +{{- define "global.env.cassandra" -}} + {{- if .Values.global.infrastructure.cassandra.enabled -}} + {{- tpl (.Values.global.envTemplates.cassandra | toYaml) . | nindent 0 -}} + {{- end -}} +{{- end -}} + +{{- define "global.env.postgres" -}} + {{- if .Values.global.infrastructure.postgres.enabled -}} + {{- tpl (.Values.global.envTemplates.postgres | toYaml) . | nindent 0 -}} + {{- end -}} +{{- end -}} + +{{- define "global.env.s3" -}} + {{- if .Values.global.infrastructure.s3.enabled -}} + {{- tpl (.Values.global.envTemplates.s3 | toYaml) . | nindent 0 -}} + {{- end -}} +{{- end -}} + +{{- define "global.env.s3_upload" -}} + {{- if .Values.global.infrastructure.s3_upload.enabled -}} + {{- tpl (.Values.global.envTemplates.s3_upload | toYaml) . | nindent 0 -}} + {{- end -}} +{{- end -}} \ No newline at end of file diff --git a/charts/backend/values.yaml b/charts/backend/values.yaml new file mode 100755 index 0000000..eb926fb --- /dev/null +++ b/charts/backend/values.yaml @@ -0,0 +1,174 @@ +global: + infrastructure: + tenant_id: 412eb2e1-9669-4b74-a56a-6198f3b5338a + sticker_base_url: store-s001.co-work.ru:9000 + kafka: + enabled: true + server: "kafka:9092,kafka:9092,kafka:9092" + port: 9092 + secret: "kafka-static-user-passwords" + username: "admin" + passwordKey: "client-passwords" + + redis: + enabled: true + host: "redis-master" + port: 6379 + + cassandra: + enabled: true + host: "cassandra" + contactPoint: "cassandra" + datacenter: "datacenter1" + secret: "cassandra-static-user-passwords" + usernameKey: "username" + passwordKey: "cassandra-password" + port: "9042" + + keycloak: + url: "https://iam.stage.co-work.local/realms/co-work" + + livekit: + secret: "livekit-secret" + apiKeyKey: "api-key" + secretKey: "secret" + + postgres: + enabled: true + host: "postgresql-ha-postgresql" + port: 5432 + secret: "pg-ha-creds" + username: "postgres" + passwordKey: "password" + + s3: + enabled: true + endpoint: https://store.stage.co-work.local:9000 + secret: "s3-static-secret" + accessKey: "access-key" + secretKey: "secret-key" + + s3_upload: + enabled: true + endpoint: https://store-s001.co-work.ru:9000 + secret: "s3-static-secret" + accessKey: "access-key" + secretKey: "secret-key" + + services: + chat: + host: "chat-app" + port: 9090 + user: + host: "user-app" + port: 9090 + message: + host: "message-app" + port: 9090 + deeplink: + host: "deeplink-app" + port: 9090 + + secrets: + branchio: + secret: "deeplink-secret" + keys: &branchio-keys + access: "branchio-access" + appid: "branchio-appid" + defaultUrl: "branchio-default-url" + key: "branchio-key" + secret: "branchio-secret" + url: "branchio-url" + + recording: + secret: "recording-secret" + keys: + access: "access-key" + secret: "secret" + + upload: + secret: "upload-app-s3" + keys: + access: "access-key" + secret: "secret-key" + + cert_alias: co-work + + + envTemplates: + kafka: &kafka-env + - name: KAFKA + value: "{{ .Values.global.infrastructure.kafka.server }}" + - name: KAFKA_SERVER + value: "{{ .Values.global.infrastructure.kafka.server }}" + - name: KAFKA_USERNAME + value: "{{ .Values.global.infrastructure.kafka.username }}" + - name: KAFKA_PASSWORD + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.kafka.secret }}" + key: "{{ .Values.global.infrastructure.kafka.passwordKey }}" + + redis: &redis-env + - name: REDIS_HOST + value: "{{ .Values.global.infrastructure.redis.host }}" + - name: REALTIME_REDIS_HOST + value: "{{ .Values.global.infrastructure.redis.host }}" + - name: REDIS_PORT + value: "{{ .Values.global.infrastructure.redis.port }}" + + cassandra: &cassandra-env + - name: CASSANDRA_CONTACTPOINT + value: "{{ .Values.global.infrastructure.cassandra.contactPoint }}" + - name: CASSANDRA_HOST + value: "{{ .Values.global.infrastructure.cassandra.host }}" + - name: CASSANDRA_DATACENTER + value: "{{ .Values.global.infrastructure.cassandra.datacenter }}" + - name: CASSANDRA_USERNAME + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.cassandra.secret }}" + key: "{{ .Values.global.infrastructure.cassandra.usernameKey }}" + - name: CASSANDRA_PASSWORD + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.cassandra.secret }}" + key: "{{ .Values.global.infrastructure.cassandra.passwordKey }}" + - name: CASSANDRA_PORT + value: "{{ .Values.global.infrastructure.cassandra.port }}" + + postgres: &postgres-env + - name: POSTGRES_USERNAME + value: "{{ .Values.global.infrastructure.postgres.username }}" + - name: POSTGRES_PASSWORD + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.postgres.secret }}" + key: "{{ .Values.global.infrastructure.postgres.passwordKey }}" + s3: &s3-env + - name: S3_ENDPOINT + value: "{{ .Values.global.infrastructure.s3.endpoint }}" + - name: S3_ACCESS_KEY + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.s3.secret }}" + key: "{{ .Values.global.infrastructure.s3.accessKey }}" + - name: S3_SECRET_KEY + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.s3.secret }}" + key: "{{ .Values.global.infrastructure.s3.secretKey }}" + + s3_upload: &s3_upload-env + - name: S3_ENDPOINT + value: "{{ .Values.global.infrastructure.s3_upload.endpoint }}" + - name: S3_ACCESS_KEY + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.s3_upload.secret }}" + key: "{{ .Values.global.infrastructure.s3_upload.accessKey }}" + - name: S3_SECRET_KEY + valueFrom: + secretKeyRef: + name: "{{ .Values.global.infrastructure.s3_upload.secret }}" + key: "{{ .Values.global.infrastructure.s3_upload.secretKey }}" \ No newline at end of file diff --git a/compose/ansible.cfg b/compose/ansible.cfg deleted file mode 100644 index cdc7912..0000000 --- a/compose/ansible.cfg +++ /dev/null @@ -1,28 +0,0 @@ -[defaults] -ansible_managed="Ansible managed" -host_key_checking=false -inventory=./inventory/hosts -timeout = 60 -roles_path = ./roles/ -retry_files_enabled = False -#log_path = ./logs/ansible.log -become = True -become_user = root -become_method = sudo -#vault_password_file = ~/.netdev_vault -forks = 100 -pipelining = True -#Gathered facts caching -#gathering = smart -#fact_caching = jsonfile -#fact_caching_connection = ./.cache -#Never expires -fact_caching_timeout = 0 -#Profiler -callbacks_enabled = timer, profile_tasks, profile_roles -[ssh_connection] -pipelining = True -#Hold ssh ssh_connection -#ssh_args = "-o ControlMaster=auto -o ControlPersist=15m" -#Speed up files transfer -transfer_method = piped \ No newline at end of file diff --git a/compose/custom_inventory/group_vars/all/all.yaml b/compose/custom_inventory/group_vars/all/all.yaml deleted file mode 100644 index a3bc616..0000000 --- a/compose/custom_inventory/group_vars/all/all.yaml +++ /dev/null @@ -1 +0,0 @@ -domain_name: "co-work.ru" \ No newline at end of file diff --git a/compose/custom_inventory/host_vars/cw-sya-reg-001/common.yml b/compose/custom_inventory/host_vars/cw-sya-reg-001/common.yml deleted file mode 100755 index 2b0d501..0000000 --- a/compose/custom_inventory/host_vars/cw-sya-reg-001/common.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -#host_name: "cw-sya-reg-001" -ansible_hostname: "docker.stage.co-work.local" -ansible_host: "10.130.0.42" diff --git a/compose/custom_inventory/host_vars/cw-sya-reg-001/files/ssl/docker.crt b/compose/custom_inventory/host_vars/cw-sya-reg-001/files/ssl/docker.crt deleted file mode 100644 index dc302b6..0000000 --- a/compose/custom_inventory/host_vars/cw-sya-reg-001/files/ssl/docker.crt +++ /dev/null @@ -1,78 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -39643962356131303761633334643262366464336364326535653733613031303462623037313636 -6466646332613364346437626465613039383132313335330a623837393332353363316536653661 -64373039653131386432643162646534386130373335326630343339353665353639383337336230 -3166656431363264620a333563346663323035643538646435323263636462386237356164383561 -32613835616630643938356461646663363033613663373139643865303430613137376563313133 -64313664393633386138363837653966303039363231616461336466623236643564353830353764 -34663938343938626264393165313732333864356335303239626234613766616266393930633339 -61326633333034626639346662323939373366363735353936306130343534376362396561653730 -34666632353539366165353637326237636437373135353062373733366238386233353430623163 -61346132373935653431373033623937376465323763313065396162643138333262326366396333 -33653462633532656263303366646663313735376333303964396534333134333532343865313564 -61613830323234663938373863666563306332613737346639356630333738633563333733373066 -31323937636631616533643963386437386335383265663539356238396133376464613362653233 -39346566393833383265316461633433343666613033663433616237636364373863653766333062 -36643535653365363862643761393264346365373531656130383838363665636534303736353535 -61653465396264386263373365613066333035393633643030383462613665346636386161303963 -37326665333937653866613164383835363062623332323939376162336462653830333135353937 -38336364653662373838643666353236363064353563626666363630363733323530393766333535 -66366335353737653435303861303462336366623765333635643135393163656663666138653731 -61346365346561623162333231666435323664653132386162626333343966333938653336373565 -61663964643737656232633363336535653861616266346130303164333766333432663462356635 -66623836326163666463336437336135373865343462313134376534383963383461626462396362 -30613234633038626539323434306465383036613334626433343932383132306433646161366230 -39666465313530646536356265653264366237383136636466393164646535663164396663306531 -30346336393263363630633835383266623736633866336635643531326366346366386630383132 -66303566306233393238626465346331383630306238353734323739383536633535303134636666 -64393235643034633030656432386162396236323965356637666162303666336239343766666261 -63363336653733366166383865366164353064333965663364623435613430643261393330646163 -61326333376532356237356264363335383465666362623965663035356132633534643230306334 -61333037396637353239323837636238633137613035653034376330383934356237656133326138 -61383136326431343337656564356464363434623330356464643762643930363139613865323461 -33393439323836333164656365343134313166646235373263666438333936613465386530306634 -32306364356564376661343061363462313539623238363562373535616565333239356365663338 -30323362626136393335643238383930316266383362633865323965643133376331346638373865 -32663434623364326339336437383366386539373930663365376437613461376366326133663634 -38303861656464383866633732306366363633323165363438623462383838653130376136656139 -31343263393561616663376331366534636239386638633032366563626634346664626432363735 -30623133383234666537623237653132386364313562373833633138336362366537663633383830 -34313837653866333838373063623032383037653163313536646162653731623538636664623038 -37326664393435316134393636303133393364323361633731316465373964373365643738656339 -33343330613432613362336633323362366134666636376564353033333033653339336362623838 -66366435393564376666356265343365653130626336313132343234663465383630636662376532 -31656431373263666339623434333263363135383038636232623338623562343036653635646632 -30653663353835343633653434383362663830643030363164616163613839383133656533343632 -33373132326362636165616134643065323364623430353565643136313239353336663438656532 -39343236306565336430656339633338623731616637303834323363643834363665656433363432 -36346331383134623732363864663537343265323033643330383763313862326235363462353533 -36646233343562356534333839323763613836316435323163346235323862386164613935336137 -37306536613930343938373130366235376264323766313932646361623965376563386632303536 -61626462633262343035336537353762663930386266653363313535313433306539306465663235 -38333237656334313637386235613230356233646533363332383536663164626433303561396466 -39653662373933316461386639633362316264373230613562303966353165366636383738373962 -36386634323236623165303339663936613936313761313730346233313632373563643439396565 -37663035626434343965316230383465303732386437333039323239643537373035613632383039 -34666334383062363232333331653161343431373534633739363665333634343134633964646137 -37363333653939633232623838383430633135643732363166366538313331343063363131356438 -36666165313835316135386337303566613934343335313937313339633838363039356665373631 -63636565613439633961363562613632636330666637383538303062653965373034306164333637 -30313131353038383735346335376231623463646234626266313633643462373761333931366637 -32663232346530383835333466643230306238656638336231636131323061623566376331626635 -34363264363133376266343864333435356631366465666239326666386233626263373231363963 -32656634383966666533656662396635373732303036666664306266313362333362633466613864 -64376361376562343864653364383731386465386361383433386531323835646535663031656636 -65626561333434646665346466393439333437386239346665646464393738383939336238383037 -64643263303238326431326537373932336630363363386435383063376664323431363836346538 -33366437306666643965633833663033653962353731313435303635666539646633366639313135 -62393266303836386461653965333435303764336637663737356666333632613834303865633937 -38663338363231336430376537616436316661333636326130336136613436343166666338653733 -38366539383132353939373665313935623566323539356336613466336661316138373535303463 -33323165366261613434663465653364343362306632333466356662383361626565303834396661 -63313137376266666530313739663766323864323561666139623063636539646431393862613335 -38633331323161333961346133623666353934343038623566326237663362323832303738396264 -36623333316632376533353265613031353039343362333234613964613738393162383735653565 -30663266633637636230346237336338383439306638626537363763373364633837363464313439 -61343062356432623932393138616261663861373661303636343239366337326230643739313962 -32656232353362383031616266623534626233316164383232363537343837313662323736646136 -6439 diff --git a/compose/custom_inventory/host_vars/cw-sya-reg-001/files/ssl/docker.key b/compose/custom_inventory/host_vars/cw-sya-reg-001/files/ssl/docker.key deleted file mode 100644 index 41df8e7..0000000 --- a/compose/custom_inventory/host_vars/cw-sya-reg-001/files/ssl/docker.key +++ /dev/null @@ -1,90 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -39663733323038363234363735323432656436633630376634333137363236373534633532373532 -6364623835383366363833386362656633373133613032650a313531306532306161333066396364 -30356364346362613932363732643335313361653137626462343663323938363962373939666230 -6466656531653464360a366135323161353466646461313762303535303266356238663866373835 -65623362383638326462343738646436363666396566346238313666326435623238636338363637 -66343766366139623238346135636437376436633531623666396132323236323361366661616166 -34386233613430323636313031323966306438626535366630346163343430663662633531373433 -62396536656635373634343332353038343136633330396332343365353631396434326266313332 -39626533393163313233366337633661623432653334666630363865306431623332393438316132 -66333130383166326336656565383266663835613137343537643265656263363031663333646265 -30376466356637613738666262313539363034653765346137316465613836613631303434353530 -37383761343162366430333539323130653664653134303739333033356464373837366433616265 -39333461313536386138346663313339306232353130386531303235633566376366343333333630 -33353238326439393531633437353966623337636538633735663038303837346134333864366332 -30653466376136366461663537393062646464373136356138623631663534383363366265373366 -36356362306239306331336337333864663631646232653164313936373362396232643730316236 -30333864316635323332323839373366623933386531643064626362303635373866653433616237 -65386237393036333934653066653237383934363165323535643265623833383830613365336465 -30626635656461356332393864646437363939633937353632646464393236373233306136623263 -38343261366664663561333638366165636330326162613661323562663239613435353966646562 -31306338653464373534356162376639396265633036633265643361626362333432636336373937 -62633664313639663939353632336666613332376263633933613537623131373966366139303731 -39623236313961663336303539626637623838646537306464333736306636636531353463636537 -63363865376631316337636236373563663636636564646665373566663534323339626237393133 -66396231393761303730366236313634336662613539636161623139636561373734306566336430 -32313938666434663231396165363733613464353930393939343536366631626465623035353033 -62646366623937643537383634616262316362316164653832396437356235623066356537623430 -32636462333330333464366634643736633937303837346238333635636430316363323230376537 -39333763626666643165613330303033343838616631353038636138336232303562643962303938 -62313762303861303539386333323031326338643665346630383938356362383738346163316563 -33353234653632383163383961363732393935396437623538623763353636643035396563343666 -30623631643731646337623062326562376665303764383135383361616365623132646138393664 -39636135366336653433393232373864356631663062366437663532666632353737366635346635 -63633363366565666132356366373461383339373036383532346636623837363831613338396333 -62626162393263313666616662623962356663666264373933663339363834653136633064333563 -33396432663830346563376561653364373637663539356564393462363432623731653533343637 -32376135356661363835663733636266393430383035613365656432393330326266353339383832 -37666162623738363538313132373034623234313733646532626162343931313066316436303036 -66363462333435393433666133643230316464646366633866356637396565643739643938633230 -33306264613738376361376630613932366234623739356564323137326566326233393230383532 -33613932323262616362616163383934313662343262646634626364353735643465343466366137 -34333162643965643361393031333836653334376236616634356665343534366230383263636638 -64333837333330316130356634613133636232396462393237313134656234616237666435656431 -61663938666533376433363531333663643266376164323163653537356532316462376330393434 -34333962323634643535383133353963323062303532623539613833366363323730646330343064 -37643136386164376434613531373438383331356661393637616630386161356339316130333861 -36343837636539636431303864646463666134663465363638323861316164653931323335343038 -63646264363132326234306566643336326564376134313739373938363835333264643539323834 -63363461323736306539663439626435353761643963346633396231336235316362343736383563 -63313938326561313264646536353232663635383164623733343962313733376539373830306366 -32363337303935623534386365353934353437356361366538353064663231356665306232386235 -65633837633438643431303935376535623439393931306566356538613363623333396161336531 -66653833616634623630656465363262326334666236393539303032646565353838643963646635 -64626533643432383137316165306662336562346537323066396638336266643033613836653034 -62373036373738626430343834633730326537656239343165386137623935363366373133393531 -33643565633038666438653235623039356665306130323635643230636133323536663635656630 -33333964633138666236623835633435313862326136343165353462363039663766633061663235 -32626539323264643536363666333238326362313333646235643064373863336334666432623361 -63316634313964633762613163313866373038623839383834643066313337386164636638323965 -36643661613965336366326663656536386436303038666235623836396333636265373837613036 -61333334656562323232656161316639393561333035383735393437346336393262663265343135 -38633330646265333733343337393833633964326139643966306130646663343432343638323035 -62383464333538633362316634643736643736393534373364323338623962636537383030336232 -37323637393735303531646165653563653365393665633337303762396136656166353836336436 -39643537633063626431363530616335393836653036363335333262616363623163396662383036 -36656533316164353530366639346132353731646332653938653636666463663661383864376464 -61316361373330633165363330643666313931326336303436323031386436646434613330366665 -66653731393638303139663230346536303937643461616366613738383862636634363435386133 -37663235663231343261336338373335616330626162363539313634346637373961613031306136 -33323866313634333131373864353862656362333536366465646435346565303636383362303634 -36356433623233363837316435636533363562663234336137333435363533626661666536376461 -32646464643130333930323537613063646635393534366462346539386131626139646562323134 -63613263333832366264343966383163393232636662646361643162323637653765643730613832 -31353665633262313065323064376536656433666563383834343139653939656639656339366362 -38666566323861666330636435363864346238363438343630306665666662663663393566366662 -65373763326432396334306265633936353234343265353936373837656362653963363065356264 -38343166346235333266353264633031343462373931616635306330636262646565653537316462 -66656563346633666464633461663533353831636238336232303161646336366134343066646337 -36663636626439383939336636383236663962393539633737396537353539666237646334616637 -36643335313239376138376634366232623037376138376161313737383562646366323632633866 -66333639313539653833316462653937386132323134346663346333383964336130333964633031 -39373663306161613339356636623630353336393366323139326538323539373630396531343435 -64313363663165643539323431383631343035656432663366643861343166616131613464613334 -30643638316431363865613862383339386431666164626264646533323136383734323730613433 -38626561363534333765333235343261616565383236363035663563316232363038386239303738 -35623165393566333837343862313961633238313938346632636166346430313631346130383134 -36353364393237333837393466653137356538613362613663326162666533393830613530666432 -37613835353739326162633737393538393965653266333637376536663631393838313561343235 -63323266653335643762373964366639343566383362393132643434336135333066 diff --git a/compose/custom_inventory/hosts b/compose/custom_inventory/hosts deleted file mode 100755 index a0f7217..0000000 --- a/compose/custom_inventory/hosts +++ /dev/null @@ -1,18 +0,0 @@ -[wireguard_servers] -gt-demo-vpn ansible_host=10.212.0.13 #34.18.24.128 -gt-demo-reg ansible_host=10.212.0.7 - -[gemteam_demo] -gt-demo-vpn ansible_host=10.212.0.13 #34.18.24.128 -gt-demo-dns ansible_host=10.212.0.4 -gt-demo-mon ansible_host=10.212.0.15 -gt-demo-ldap ansible_host=10.212.0.3 -gt-demo-iam ansible_host=10.212.0.5 -gt-demo-jfrog ansible_host=10.212.0.6 -gt-demo-reg ansible_host=10.212.0.7 -gt-demo-docker ansible_host=10.212.0.8 -gt-demo-jenkins-m ansible_host=10.212.0.9 -gt-demo-jenkins-w ansible_host=10.212.0.11 -gt-demo-store ansible_host=10.212.0.10 -gt-demo-livekit ansible_host=10.212.0.12 -gt-demo-front ansible_host=10.212.0.14 \ No newline at end of file diff --git a/compose/inventory/hosts b/compose/inventory/hosts deleted file mode 100644 index 17cabc9..0000000 --- a/compose/inventory/hosts +++ /dev/null @@ -1,8 +0,0 @@ -[co-work_stage] -cw-sya-ldap-001 ansible_host=10.130.0.16 -cw-sya-nfs-001 ansible_host=10.130.0.37 -cw-sya-store-001 ansible_host=10.130.0.12 -cw-sya-vpn-001 ansible_host=10.130.0.28 -cw-sya-iam-001 ansible_host=10.130.0.41 -cw-sya-reg-001 ansible_host=10.130.0.42 - diff --git a/compose/playbooks/ca_server/README.md b/compose/playbooks/ca_server/README.md deleted file mode 100644 index bf4e3d3..0000000 --- a/compose/playbooks/ca_server/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Playbook information -====================================================================== -Плейбук по установке и настройке Центра сертификации (OpenSSL) \ No newline at end of file diff --git a/compose/playbooks/ca_server/ansible.cfg b/compose/playbooks/ca_server/ansible.cfg deleted file mode 100644 index 20d7065..0000000 --- a/compose/playbooks/ca_server/ansible.cfg +++ /dev/null @@ -1,4 +0,0 @@ -[defaults] -ansible_managed="Ansible managed" -host_key_checking=False -inventory=inventory/hosts diff --git a/compose/playbooks/ca_server/defaults/main.yml b/compose/playbooks/ca_server/defaults/main.yml deleted file mode 100644 index 11163dc..0000000 --- a/compose/playbooks/ca_server/defaults/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# defaults vars -# ansible_python_interpreter: "/usr/libexec/platform-python" -ansible_ssh_pipelining: "true" -ansible_user: "gem-admin" -ansible_ssh_transfer_method: "piped" -ansible_ssh_common_args: "-o StrictHostKeyChecking=no" -ansible_port: 22 - diff --git a/compose/playbooks/ca_server/handlers/main.yml b/compose/playbooks/ca_server/handlers/main.yml deleted file mode 100644 index c09dec7..0000000 --- a/compose/playbooks/ca_server/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# handlers file - - - diff --git a/compose/playbooks/ca_server/inventory/hosts b/compose/playbooks/ca_server/inventory/hosts deleted file mode 100644 index 9318e56..0000000 --- a/compose/playbooks/ca_server/inventory/hosts +++ /dev/null @@ -1,3 +0,0 @@ - -[ca-host] -cw-sya-ldap-001 ansible_host=10.130.0.16 \ No newline at end of file diff --git a/compose/playbooks/ca_server/main.yml b/compose/playbooks/ca_server/main.yml deleted file mode 100644 index 742748d..0000000 --- a/compose/playbooks/ca_server/main.yml +++ /dev/null @@ -1,16 +0,0 @@ ---- -# Установка центра сертификации -- name: Install CA server - hosts: cw-sya-ldap-001 - gather_facts: true - become: true - vars_files: - - vars/base_conf.yml - - vars/secret.yml - - defaults/main.yml - pre_tasks: - - import_tasks: tasks/check_os_version.yml - roles: - - role: ca_install - when: ansible_distribution == "Ubuntu" - diff --git a/compose/playbooks/ca_server/roles/ca_install/README.md b/compose/playbooks/ca_server/roles/ca_install/README.md deleted file mode 100644 index 9b11033..0000000 --- a/compose/playbooks/ca_server/roles/ca_install/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка CA (Центра сертификации) \ No newline at end of file diff --git a/compose/playbooks/ca_server/roles/ca_install/handlers/main.yml b/compose/playbooks/ca_server/roles/ca_install/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/ca_server/roles/ca_install/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/ca_server/roles/ca_install/tasks/configure_ca.yml b/compose/playbooks/ca_server/roles/ca_install/tasks/configure_ca.yml deleted file mode 100644 index e7d2760..0000000 --- a/compose/playbooks/ca_server/roles/ca_install/tasks/configure_ca.yml +++ /dev/null @@ -1,51 +0,0 @@ ---- -# Настройка CA -- name: Configure CA - block: - - name: Creates base directory - ansible.builtin.file: - path: "/opt/{{ item }}" - state: directory - loop: - - CA - - CA/service - - - name: Check CA private key - stat: - path: /opt/CA/RootCA.key - register: ca_key_result - - - name: Create CA private key - expect: - command: /bin/bash -c 'openssl genpkey -algorithm RSA -out /opt/CA/RootCA.key -aes-128-cbc' - responses: - Enter PEM pass *: "{{ ca_password }}" - Verifying *: "{{ ca_password }}" - timeout: 300 - when: ca_key_result.stat.exists == false - - - name: Check CA certificate - stat: - path: /opt/CA/RootCA.crt - register: ca_crt_result - - - name: Create CA certificate - expect: - command: "/bin/bash -c 'openssl req -x509 -new -key /opt/CA/RootCA.key -sha256 -days {{ ca_lifeday }} -out /opt/CA/RootCA.crt'" - responses: - Enter pass *: "{{ ca_password }}" - Country *: "{{ ca_country }}" - State *: "{{ ca_state }}" - Locality *: "{{ ca_locality }}" - Organization *: "{{ ca_organization }}" - Organizational *: "{{ ca_organization }}" - Common *: "{{ ca_domain }}" - Email *: "admin@{{ ca_domain }}" - timeout: 300 - when: ca_crt_result.stat.exists == false - - - name: Create certificate template - template: - src: template.cnf.j2 - dest: /opt/CA/template.cnf - register: template_updated diff --git a/compose/playbooks/ca_server/roles/ca_install/tasks/create_cert.yml b/compose/playbooks/ca_server/roles/ca_install/tasks/create_cert.yml deleted file mode 100644 index 7410fd4..0000000 --- a/compose/playbooks/ca_server/roles/ca_install/tasks/create_cert.yml +++ /dev/null @@ -1,45 +0,0 @@ ---- -- name: Create wildcard service certificate - block: - - name: Check private KEY - stat: - path: /opt/CA/service/{{ crt_services }}.key - register: key_result - - - name: Create wildcard service KEY - shell: | - openssl genpkey -algorithm RSA -out /opt/CA/service/{{ crt_services }}.key - when: key_result.stat.exists == false - - - name: Check CSR - stat: - path: /opt/CA/service/{{ crt_services }}.csr - register: csr_result - - - name: Create wildcard service CSR - expect: - command: "/bin/bash -c 'openssl req -new -key /opt/CA/service/{{ crt_services }}.key -config /opt/CA/template.cnf -reqexts req_ext -out /opt/CA/service/{{ crt_services }}.csr'" - responses: - Country *: "{{ ca_country }}" - State *: "{{ ca_state }}" - Locality *: "{{ ca_locality }}" - Organization *: "{{ ca_organization }}" - Organizational *: "{{ ca_organization }}" - Common *: "{{ ca_domain }}" - Email *: "admin@{{ ca_domain }}" - timeout: 300 - when: csr_result.stat.exists == false - - - name: Check public CRT - stat: - path: /opt/CA/service/{{ crt_services }}.crt - register: crt_result - - - name: Create wildcard service CRT - expect: - command: "/bin/bash -c 'openssl x509 -req -days 730 -CA /opt/CA/RootCA.crt -CAkey /opt/CA/RootCA.key -extfile /opt/CA/template.cnf -extensions req_ext -in /opt/CA/service/{{ crt_services }}.csr -out /opt/CA/service/{{ crt_services }}.crt'" - responses: - Enter pass *: "{{ ca_password }}" - when: crt_result.stat.exists == false - - diff --git a/compose/playbooks/ca_server/roles/ca_install/tasks/main.yml b/compose/playbooks/ca_server/roles/ca_install/tasks/main.yml deleted file mode 100644 index 6dae5c5..0000000 --- a/compose/playbooks/ca_server/roles/ca_install/tasks/main.yml +++ /dev/null @@ -1,8 +0,0 @@ ---- - -# Настройка CA -- name: Configure CA - include_tasks: configure_ca.yml - -- name: Create service certificate - include_tasks: create_cert.yml diff --git a/compose/playbooks/ca_server/roles/ca_install/templates/template.cnf.j2 b/compose/playbooks/ca_server/roles/ca_install/templates/template.cnf.j2 deleted file mode 100644 index f403563..0000000 --- a/compose/playbooks/ca_server/roles/ca_install/templates/template.cnf.j2 +++ /dev/null @@ -1,22 +0,0 @@ -[ req ] -default_bits = 2048 -distinguished_name = req_distinguished_name -req_extensions = req_ext -[ req_distinguished_name ] -countryName = Country Name (2 letter code) -countryName_default = {{ ca_country }} -stateOrProvinceName = State or Province Name (full name) -stateOrProvinceName_default = {{ ca_state }} -localityName = Locality Name (eg, city) -localityName_default = {{ ca_locality }} -organizationName = Organization Name (eg, company) -organizationName_default = {{ ca_organization }} -commonName = Common Name (eg, YOUR name or FQDN) -commonName_max = 64 -commonName_default = *.{{ ca_domain }} -[ req_ext ] -basicConstraints = CA:FALSE -keyUsage = nonRepudiation, digitalSignature, keyEncipherment -subjectAltName = @alt_names -[alt_names] -DNS.1 = *.{{ ca_domain }} diff --git a/compose/playbooks/ca_server/roles/ca_install/vars/main.yml b/compose/playbooks/ca_server/roles/ca_install/vars/main.yml deleted file mode 100644 index fa2fb4c..0000000 --- a/compose/playbooks/ca_server/roles/ca_install/vars/main.yml +++ /dev/null @@ -1,2 +0,0 @@ ---- -# vars file diff --git a/compose/playbooks/ca_server/tasks/check_os_version.yml b/compose/playbooks/ca_server/tasks/check_os_version.yml deleted file mode 100644 index 2909c8b..0000000 --- a/compose/playbooks/ca_server/tasks/check_os_version.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -# Проверка версии ОС -- name: Check OS version - block: - # - name: DEBUG OS version - # debug: - # msg: - # - "OS: {{ ansible_distribution }}" - # - "Version: {{ ansible_distribution_version }}" - # - "Major version: {{ ansible_distribution_major_version }}" - - - name: OS version not supported - fail: - msg: "Operating system {{ ansible_distribution }} ver. {{ ansible_distribution_major_version }} not supported" - when: ansible_distribution not in ['Ubuntu'] \ No newline at end of file diff --git a/compose/playbooks/ca_server/vars/base_conf.yml b/compose/playbooks/ca_server/vars/base_conf.yml deleted file mode 100644 index add039b..0000000 --- a/compose/playbooks/ca_server/vars/base_conf.yml +++ /dev/null @@ -1,10 +0,0 @@ ---- -# Переменные конфигурации -ca_domain: "stage.co-work.local" # Имя доменна -ca_country: "RU" # Страна -ca_locality: "Moscow" -ca_state: "Moscow" -ca_organization: "co-work_stage" # Имя организации -ca_lifeday: "3650" # Срок жизни рутового сертификата -crt_services: "wc" # Имя wildcard сертификата - \ No newline at end of file diff --git a/compose/playbooks/ca_server/vars/secret.yml b/compose/playbooks/ca_server/vars/secret.yml deleted file mode 100644 index e896bc3..0000000 --- a/compose/playbooks/ca_server/vars/secret.yml +++ /dev/null @@ -1,10 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -32393233636236623437333934643231303835343237373436333735333939326635316636613433 -6137623638653763323232323831323537383561616361660a376136633637616165366362323065 -35336532623538336364636566633339316263653761383733643834633765313831333234663666 -6561343033383266660a363530616230396537623165326465326662353234383166356264306265 -61396233623233363933343932303733656630653633633938306230383933393433633266666133 -35313338326330636632346132336665636231313836393336346230303662356562363937303932 -31323466633735383738656264383066363231353561373635386461643865353235393661326435 -65353630383932613432376137376564623236623037623261663766356236363438383064663062 -3031 diff --git a/compose/playbooks/dns_server/README.md b/compose/playbooks/dns_server/README.md deleted file mode 100644 index 57b0732..0000000 --- a/compose/playbooks/dns_server/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Playbook information -====================================================================== -Плейбук по установке и настройке DNS сервера BIND \ No newline at end of file diff --git a/compose/playbooks/dns_server/ansible.cfg b/compose/playbooks/dns_server/ansible.cfg deleted file mode 100644 index 20d7065..0000000 --- a/compose/playbooks/dns_server/ansible.cfg +++ /dev/null @@ -1,4 +0,0 @@ -[defaults] -ansible_managed="Ansible managed" -host_key_checking=False -inventory=inventory/hosts diff --git a/compose/playbooks/dns_server/defaults/main.yml b/compose/playbooks/dns_server/defaults/main.yml deleted file mode 100644 index 11163dc..0000000 --- a/compose/playbooks/dns_server/defaults/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# defaults vars -# ansible_python_interpreter: "/usr/libexec/platform-python" -ansible_ssh_pipelining: "true" -ansible_user: "gem-admin" -ansible_ssh_transfer_method: "piped" -ansible_ssh_common_args: "-o StrictHostKeyChecking=no" -ansible_port: 22 - diff --git a/compose/playbooks/dns_server/handlers/main.yml b/compose/playbooks/dns_server/handlers/main.yml deleted file mode 100644 index c09dec7..0000000 --- a/compose/playbooks/dns_server/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# handlers file - - - diff --git a/compose/playbooks/dns_server/inventory/hosts b/compose/playbooks/dns_server/inventory/hosts deleted file mode 100644 index 35b252b..0000000 --- a/compose/playbooks/dns_server/inventory/hosts +++ /dev/null @@ -1,3 +0,0 @@ - -[dns-host] -cw-sya-ldap-001 ansible_host=10.130.0.16 \ No newline at end of file diff --git a/compose/playbooks/dns_server/main.yml b/compose/playbooks/dns_server/main.yml deleted file mode 100644 index e681e68..0000000 --- a/compose/playbooks/dns_server/main.yml +++ /dev/null @@ -1,16 +0,0 @@ ---- -# Установка DNS сервера Bind -- name: Install DNS server Bind - hosts: cw-sya-ldap-001 - gather_facts: true - become: true - vars_files: - - vars/base_conf.yml - - vars/dns_zone.yml - - defaults/main.yml - pre_tasks: - - import_tasks: tasks/check_os_version.yml - roles: - - role: bind_install - when: ansible_distribution == "Ubuntu" - diff --git a/compose/playbooks/dns_server/roles/bind_install/README.md b/compose/playbooks/dns_server/roles/bind_install/README.md deleted file mode 100644 index 10f7939..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка Bind \ No newline at end of file diff --git a/compose/playbooks/dns_server/roles/bind_install/handlers/main.yml b/compose/playbooks/dns_server/roles/bind_install/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/dns_server/roles/bind_install/tasks/configure_bind.yml b/compose/playbooks/dns_server/roles/bind_install/tasks/configure_bind.yml deleted file mode 100644 index 4b58cc3..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/tasks/configure_bind.yml +++ /dev/null @@ -1,124 +0,0 @@ ---- -# Настройка Bind -- name: Configure Bind - block: - - name: Change bind options config - template: - src: named.conf.options.j2 - dest: /etc/bind/named.conf.options - mode: 0644 - owner: root - group: bind - register: named_options_updated - - - name: Change bind local config - template: - src: named.conf.local.j2 - dest: /etc/bind/named.conf.local - mode: 0644 - owner: root - group: bind - register: named_local_updated - - - name: Creates master zone directory - ansible.builtin.file: - path: /var/cache/bind/master - state: directory - - - name: Create dns local zone config - template: - src: dns_zone_local.j2 - dest: "/var/cache/bind/master/{{ dns_zone }}" - mode: 0644 - owner: root - group: bind - register: named_zone_updated - - - name: Check and update zone config - shell: | - named-checkzone {{ dns_zone }} /var/cache/bind/master/{{ dns_zone }} - when: named_zone_updated['changed'] - - - name: Update DNS zone - shell: | - rndc reload - when: named_zone_updated['changed'] - - - name: Check Bind config - shell: "named-checkconf /etc/bind/named.conf" - when: named_options_updated['changed'] or named_local_updated['changed'] - - - name: Reload Bind service - service: - name: bind9 - state: reloaded - when: named_options_updated['changed'] or named_local_updated['changed'] or named_zone_updated['changed'] - -- name: Configure ufw - block: - - name: Install ufw packages - apt: - name: '{{ item }}' - state: present - update_cache: yes - loop: - - ufw - when: "'ufw' not in ansible_facts.packages" - - - name: Enable ufw service - systemd: - name: ufw.service - state: started - enabled: yes - - - name: Default allow outgoing traffic - community.general.ufw: - default: allow - direction: outgoing - - - name: Default deny incoming traffic - community.general.ufw: - default: deny - direction: incoming - - - name: Allow ssh traffic - community.general.ufw: - rule: allow - port: 22 - proto: tcp - - - name: Allow DNS traffic TCP - community.general.ufw: - rule: allow - port: 53 - proto: tcp - - - name: Allow DNS traffic UDP - community.general.ufw: - rule: allow - port: 53 - proto: udp - - - name: Enable UFW - community.general.ufw: - state: enabled - policy: deny - - # - name: Enable and start Docker service - # service: - # name: docker - # state: started - # enabled: yes - - # - name: Restart Docker service - # service: - # name: docker - # state: restarted - # when: docker_updated['changed'] - - # - name: Add users to a docker group - # ansible.builtin.user: - # name: "{{ item }}" - # groups: docker - # loop: "{{ docker_users_list }}" - # when: docker_users_list is defined \ No newline at end of file diff --git a/compose/playbooks/dns_server/roles/bind_install/tasks/install_bind.yml b/compose/playbooks/dns_server/roles/bind_install/tasks/install_bind.yml deleted file mode 100644 index c3c6fcd..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/tasks/install_bind.yml +++ /dev/null @@ -1,17 +0,0 @@ ---- -# Установка Bind -- name: "Check packages is installed" - package_facts: - manager: "auto" - -- name: "Install packages" - block: - - name: Install packages - apt: - name: '{{ item }}' - state: present - update_cache: yes - loop: - - bind9 - - dnsutils - when: "'bind9' not in ansible_facts.packages or 'dnsutils' not in ansible_facts.packages" \ No newline at end of file diff --git a/compose/playbooks/dns_server/roles/bind_install/tasks/main.yml b/compose/playbooks/dns_server/roles/bind_install/tasks/main.yml deleted file mode 100644 index 7e255c7..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/tasks/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- - -# Установка Bind -- name: Install Bind - include_tasks: install_bind.yml - -# Настройка Bind -- name: Configure Bind - include_tasks: configure_bind.yml diff --git a/compose/playbooks/dns_server/roles/bind_install/templates/dns_zone_local.j2 b/compose/playbooks/dns_server/roles/bind_install/templates/dns_zone_local.j2 deleted file mode 100644 index 7c33d19..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/templates/dns_zone_local.j2 +++ /dev/null @@ -1,17 +0,0 @@ -$TTL 14400 - -{{ dns_zone }}. IN SOA {{ ansible_hostname }}.{{ dns_zone }}. admin.{{ dns_zone }}. ( - 2017082401 ; Serial - 10800 ; Refresh - 3600 ; Retry - 604800 ; Expire - 604800 ; Negative Cache TTL -) - - IN NS {{ ansible_hostname }}.{{ dns_zone }}. - - -@ IN A {{ ansible_default_ipv4.address }} -localhost IN A 127.0.0.1 -{{ ansible_hostname }} IN A {{ ansible_default_ipv4.address }} -{{ dns_rec }} diff --git a/compose/playbooks/dns_server/roles/bind_install/templates/named.conf.local.j2 b/compose/playbooks/dns_server/roles/bind_install/templates/named.conf.local.j2 deleted file mode 100644 index eab046b..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/templates/named.conf.local.j2 +++ /dev/null @@ -1,6 +0,0 @@ -zone "{{ dns_zone }}" { - type master; - file "master/{{ dns_zone }}"; - allow-transfer { {{ ansible_default_ipv4.address }}; }; - allow-update { none; }; -}; \ No newline at end of file diff --git a/compose/playbooks/dns_server/roles/bind_install/templates/named.conf.options.j2 b/compose/playbooks/dns_server/roles/bind_install/templates/named.conf.options.j2 deleted file mode 100644 index e6ab096..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/templates/named.conf.options.j2 +++ /dev/null @@ -1,12 +0,0 @@ -options { - directory "/var/cache/bind"; - listen-on { - {{ ansible_default_ipv4.address }}; - }; - listen-on-v6 { none; }; - allow-query { any; }; - forwarders { - {{ ext_forward_dns1 }}; - {{ ext_forward_dns2 }}; - }; -}; \ No newline at end of file diff --git a/compose/playbooks/dns_server/roles/bind_install/vars/main.yml b/compose/playbooks/dns_server/roles/bind_install/vars/main.yml deleted file mode 100644 index fa2fb4c..0000000 --- a/compose/playbooks/dns_server/roles/bind_install/vars/main.yml +++ /dev/null @@ -1,2 +0,0 @@ ---- -# vars file diff --git a/compose/playbooks/dns_server/tasks/check_os_version.yml b/compose/playbooks/dns_server/tasks/check_os_version.yml deleted file mode 100644 index 2909c8b..0000000 --- a/compose/playbooks/dns_server/tasks/check_os_version.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -# Проверка версии ОС -- name: Check OS version - block: - # - name: DEBUG OS version - # debug: - # msg: - # - "OS: {{ ansible_distribution }}" - # - "Version: {{ ansible_distribution_version }}" - # - "Major version: {{ ansible_distribution_major_version }}" - - - name: OS version not supported - fail: - msg: "Operating system {{ ansible_distribution }} ver. {{ ansible_distribution_major_version }} not supported" - when: ansible_distribution not in ['Ubuntu'] \ No newline at end of file diff --git a/compose/playbooks/dns_server/vars/base_conf.yml b/compose/playbooks/dns_server/vars/base_conf.yml deleted file mode 100644 index 63530bf..0000000 --- a/compose/playbooks/dns_server/vars/base_conf.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# Переменные конфигурации -ext_forward_dns1: "10.130.0.2" # Внешний DNS сервер для перенаправления запросов -ext_forward_dns2: "77.88.8.8" # Внешний DNS сервер для перенаправления запросов -dns_zone: "stage.co-work.local" # DNS зона \ No newline at end of file diff --git a/compose/playbooks/dns_server/vars/dns_zone.yml b/compose/playbooks/dns_server/vars/dns_zone.yml deleted file mode 100644 index 9919ae3..0000000 --- a/compose/playbooks/dns_server/vars/dns_zone.yml +++ /dev/null @@ -1,16 +0,0 @@ -dns_rec: | - cw-sya-vpn-001 IN A 10.130.0.28 - cw-sya-iam-001 IN A 10.130.0.41 - cw-sya-ldap-001 IN A 10.130.0.16 - ldap IN A 10.130.0.16 - iam IN A 10.130.0.41 - cw-sya-reg-001 IN A 10.130.0.42 - docker IN A 10.130.0.42 - cw-sya-nfs-001 IN A 10.130.0.37 - cw-sya-store-001 IN A 10.130.0.12 - store IN A 10.130.0.12 - cw-sya-kubb-001 IN A 10.130.0.20 - cw-sya-kubb-002 IN A 10.130.0.13 - cw-sya-kubb-003 IN A 10.130.0.23 - argocd IN A 10.130.0.17 - cw-sya-mon-001 IN A 10.130.0.43 \ No newline at end of file diff --git a/compose/playbooks/infra-base_admin.yml b/compose/playbooks/infra-base_admin.yml deleted file mode 100644 index 6e1809d..0000000 --- a/compose/playbooks/infra-base_admin.yml +++ /dev/null @@ -1,50 +0,0 @@ ---- -# --------------------------- -# Добавление локальных администраторов -# --------------------------- -- hosts: all - become: yes - gather_facts: false - vars: - ansible_ssh_pipelining: "true" - ansible_user: "aantropov" - ansible_ssh_transfer_method: "piped" - ansible_ssh_common_args: "-o StrictHostKeyChecking=no" - ansible_port: 22 - users: - - { name: 'gem-admin', comment: 'Gem local administrator', exclusive: true, ssh_key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCGF42ADoauvpQeNW9I3dBvra4+/aK3zz0y8moBKngdwLbg/yu5dYlB7p4w2qp3QEFcHatyBHrjezKOEO5qM7HFx2Yp0dsR7j25ZhLc8Oy85eFJIKRu4DTJLahNgp+ybL+zjadRVGuc6xQtFemOtFTNzeMhwxvgLF312/pWnVlN3KIoIbOxOwnp0hr1yvKivDRTmDUI3bNvgCLSnap5fxcBZZklz+AzshIH9rY0W86VCewACRnPRcaE94O+4XjibqYi8vQPGUAu9NpRAPvuDbp1N5BgwhLcDx/XdQDcyhMdtLbHJ/I1WhaTLJjUDXVp3wcC4E7jpzXLBqkwPneplpVHT2Qk5AGp0R8Vb+q4TMLRbgm00036CcXY1Y/6VtAd1c3+QlXMSVMDEHBMBJ/NBM8cKkPhhBT8C1Tt660IFRErx8C48IqpGfHjHQZn8Xf0RWIyZ28c/x6mOhHJqqFAsPCsGsYcWVdAZBD53tWHGdjYcLGeI3UCYBFnnj4fEvQUUnBE3JB1NdkeVxYElbh7SktVTh3G3kNFAwWYgwn31Qh74jWpN11H8m5XM0I3R2TGzi7yuS8zKOKaEZwObSNVTfBbPHh6uVK3olIsiznAsI19jqrg+QQjStaNhHDcN/SZTxboy7q7Rnigl2cJOHM2rxm8NmuMuTHdPKlpbigvq7PFMQ== gem-admin" } - - { name: 'lsokurov', comment: 'Leonid Sokurov', exclusive: true, ssh_key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC99En90Q7+VECxJLvVJY4TjasnFxC77YHpEebNeJg8iWapjvFxQ5ROOQX43x0kRKIZrnj3aQmpSvs+RuvWAxszm3BE4jiSftL49ImSMdmyoiGV5l1WcV1HJrmwz7jq5Eq8P/iMw3hVkhWU6b860kWpAhFiaW/g58BHJHVYn4M+pLDWk2NRkvHD4Ez1rtH28hXqrrm+TD/KhxLUrqQdytvYi5trzWQbahtpOtev0Dyi8oBdj6Jph/pB3mzZnWFGP2r106x4bKlvzKlLgNn9yPgygknDIEmD9dIEf2sJ/WbxqurR0x+Id3rpAiyvZWnY0O4CNcP9DIOrM0onz2he+hJTH+Kr8tiJBfpqoboSnyIdPfh2dMGGpGxPYoghVBg6ylkQ6ZUB8xUTTjfzCxxNF7TgMI064iXi+RWwepknLxw2vcgiSRi/nnv9NFJta+QOskK+05YXecWcnJVvREmYkGSzKEkuzwxEWwYIc2/JAngQxeenGaBAl9mDKdFPyZcQUy0= leonisa@Leonids-MacBook-Pro.local"} - - { name: 'aantropov', comment: 'Aleksandr Antropov', exclusive: true, ssh_key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC9dzp4d6A9ZfVOXmHdiSW05qZbCGWBm8W0+KTlqEaRssliHHmrWSntiSvoeG2nQPJKBA5MAi476T/hmT2ym1oZxvRdyBODRw/UdXboHTXejXivtfhVT0ghcKOrllDbwzM/J9PT4k7rdefduIpv0wGHXzIVFqU1ZdjqDVqixuPq8dVSJJIOI5am6AJ6Of+U87FNC91GlGEezq8+Xo55BvUTKPjxnoHWUKVvvT6ci78i8I7Ux1Dx48lj90J61z9BIxvDZbWDDUY9gL2E0TSsYYDws5uX/+OSi3BIzJvMdzcn5LUTjIKX5FLYhdpagwqX2vaziI3S51RSpsqC6w76awKmcNbKfZzn8bXsvbK6pnwGKhFYBYZKui2piqq8rZ5MEHabHmEf1EdCtVW5Q0FNZzBKRFy6Sa5FwdzJPCmdoVOCtwXVZtKgUGHksxtWpMuuvO5QcXDoOqyCtTnk79S1fOYfQWbtTeKOpHiIONCgl6/CzZdoB8FXYRuyLtXmRTQy7rM= antropov.a.b-2023-09-25" } -# - { name: 'ffesenko', comment: 'Filipp Fesenko', exclusive: true, ssh_key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDP5mfMMJ8J/ZVC7QFYsbQ0lB9qc7zLNq41IgVCLi/f83GUcJ2OfXh7/SetGnujOnyIsM6qv3kaWmgrSKmaR/0AL7YcAXvKgFf/XThs6b/tOpKiaZIT2Yn3hW+yW7FcqO96tNSa3TMikSR/K72goC6jXvVFgbtREuwuMxnuDx4U5hJdsvx/fmMywCTPtiSWNXMJC1m08v9xaeaygycftVSPsJc8QeWThqt1Dvr39JcIZDqHbrdbqGzWzT2vJRbpmKkECoeW1d9wqr4DcsjamIKikS4/cw84pP8S0Sxu+JsK+H86v+gw9P6SfQYxVMwawjeQWukk2OK3MtKjpXiIF8f/5PJAq4QYo9aDgX3igoKvdFPni1qkn3NLhI+BexwkF1VCzalE4L9p75EkYpQzyhcAZ5HGF9FUVR1JNfdP+dgVCBjXgHcyKNGD9+MsUHx1BUeEFnon2P5XJ49FFXec3pZ+7Hrnf13EPGfz8ingoNvvV+2VNAUXpMpgB0/lba+vH68= f.fesenko" } -# - { name: 'mchudinov', comment: 'Maksim Chudinov', exclusive: true, ssh_key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJt7pOgOb7P6INJqnUhLj+gOJS/oH7JrZc13tfIC2lzi mchudinov" } - - tasks: - - name: Add local admin - user: - comment: "{{ item.comment }}" - createhome: true - name: "{{ item.name }}" - shell: /bin/bash - password_lock: true - force: true - loop: - "{{ users }}" - no_log: true - - name: Add SSH keys - authorized_key: - user: "{{ item.name }}" - key: "{{ item.ssh_key }}" - exclusive: "{{ item.exclusive }}" - loop: - "{{ users }}" - no_log: true - - - name: Sudo permissions - community.general.sudoers: - name: "{{ item.name | lower | replace('.','_') }}-access" - user: "{{ item.name }}" - commands: ALL - nopassword: true - state: present - loop: - "{{ users }}" \ No newline at end of file diff --git a/compose/playbooks/infra-docker-registry.yml b/compose/playbooks/infra-docker-registry.yml deleted file mode 100644 index 2d8b3f3..0000000 --- a/compose/playbooks/infra-docker-registry.yml +++ /dev/null @@ -1,8 +0,0 @@ ---- -- name: infra-common - hosts: cw-sya-reg-001 - become: true - gather_facts: true - roles: - - { role: infra-common, tags: ["common"] } - - { role: infra-container-registry, tags: ["registry"] } \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/README.md b/compose/playbooks/keycloak_server/README.md deleted file mode 100644 index 8cb64f7..0000000 --- a/compose/playbooks/keycloak_server/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Playbook information -====================================================================== -Плейбук по установке Keycloak в Docker \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/ansible.cfg b/compose/playbooks/keycloak_server/ansible.cfg deleted file mode 100644 index 20d7065..0000000 --- a/compose/playbooks/keycloak_server/ansible.cfg +++ /dev/null @@ -1,4 +0,0 @@ -[defaults] -ansible_managed="Ansible managed" -host_key_checking=False -inventory=inventory/hosts diff --git a/compose/playbooks/keycloak_server/defaults/main.yml b/compose/playbooks/keycloak_server/defaults/main.yml deleted file mode 100644 index 11163dc..0000000 --- a/compose/playbooks/keycloak_server/defaults/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# defaults vars -# ansible_python_interpreter: "/usr/libexec/platform-python" -ansible_ssh_pipelining: "true" -ansible_user: "gem-admin" -ansible_ssh_transfer_method: "piped" -ansible_ssh_common_args: "-o StrictHostKeyChecking=no" -ansible_port: 22 - diff --git a/compose/playbooks/keycloak_server/handlers/main.yml b/compose/playbooks/keycloak_server/handlers/main.yml deleted file mode 100644 index c09dec7..0000000 --- a/compose/playbooks/keycloak_server/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# handlers file - - - diff --git a/compose/playbooks/keycloak_server/inventory/hosts b/compose/playbooks/keycloak_server/inventory/hosts deleted file mode 100644 index 7b87a1b..0000000 --- a/compose/playbooks/keycloak_server/inventory/hosts +++ /dev/null @@ -1,4 +0,0 @@ - -[iam-host] -cw-sya-iam-001 ansible_host=10.130.0.41 - diff --git a/compose/playbooks/keycloak_server/main.yml b/compose/playbooks/keycloak_server/main.yml deleted file mode 100644 index dd26998..0000000 --- a/compose/playbooks/keycloak_server/main.yml +++ /dev/null @@ -1,18 +0,0 @@ ---- -# Установка Keycloak (Docker) -- name: Install Keycloak (Docker) - hosts: cw-sya-iam-001 - gather_facts: true - become: true - vars_files: - - vars/base_conf.yml - - vars/secret.yml - - defaults/main.yml - pre_tasks: - - import_tasks: tasks/check_os_version.yml - roles: - - role: docker_install - when: ansible_distribution == "Ubuntu" and docker_install == "yes" - - role: keycloak_install_docker - when: ansible_distribution == "Ubuntu" - diff --git a/compose/playbooks/keycloak_server/roles/docker_install/README.md b/compose/playbooks/keycloak_server/roles/docker_install/README.md deleted file mode 100644 index ae41738..0000000 --- a/compose/playbooks/keycloak_server/roles/docker_install/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка Docker-ce и Docker-compose \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/roles/docker_install/handlers/main.yml b/compose/playbooks/keycloak_server/roles/docker_install/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/keycloak_server/roles/docker_install/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/keycloak_server/roles/docker_install/tasks/configure_docker.yml b/compose/playbooks/keycloak_server/roles/docker_install/tasks/configure_docker.yml deleted file mode 100644 index 0aeb46c..0000000 --- a/compose/playbooks/keycloak_server/roles/docker_install/tasks/configure_docker.yml +++ /dev/null @@ -1,29 +0,0 @@ ---- -# Настройка Docker -- name: Configure Docker - block: - - name: Make docker config - template: - src: daemon.json.j2 - dest: /etc/docker/daemon.json - mode: 0644 - register: docker_updated - - - name: Enable and start Docker service - service: - name: docker - state: started - enabled: yes - - - name: Restart Docker service - service: - name: docker - state: restarted - when: docker_updated['changed'] - - - name: Add users to a docker group - ansible.builtin.user: - name: "{{ item }}" - groups: docker - loop: "{{ docker_users_list }}" - # when: docker_users_list is defined \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/roles/docker_install/tasks/install_docker.yml b/compose/playbooks/keycloak_server/roles/docker_install/tasks/install_docker.yml deleted file mode 100644 index 6cfefa7..0000000 --- a/compose/playbooks/keycloak_server/roles/docker_install/tasks/install_docker.yml +++ /dev/null @@ -1,35 +0,0 @@ ---- -# Установка Docker -- name: "Check packages is installed" - package_facts: - manager: "auto" - -- name: "Install Docker" - block: - - name: "Add GPG key" - shell: | - install -m 0755 -d /etc/apt/keyrings - curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc - chmod a+r /etc/apt/keyrings/docker.asc - - - name: "Add the repository to Apt sources" - shell: | - echo \ - "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \ - $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \ - sudo tee /etc/apt/sources.list.d/docker.list > /dev/null - apt-get update - - - name: Install docker packages - apt: - name: '{{ item }}' - state: present - update_cache: yes - loop: - - docker-ce - - docker-ce-cli - - containerd.io - - docker-buildx-plugin - - docker-compose-plugin - - docker-compose - when: "'docker-ce' not in ansible_facts.packages" \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/roles/docker_install/tasks/main.yml b/compose/playbooks/keycloak_server/roles/docker_install/tasks/main.yml deleted file mode 100644 index 08fc61c..0000000 --- a/compose/playbooks/keycloak_server/roles/docker_install/tasks/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- - -# Установка Docker -- name: Install Docker - include_tasks: install_docker.yml - -# Настройка Docker -- name: Configure Docker - include_tasks: configure_docker.yml diff --git a/compose/playbooks/keycloak_server/roles/docker_install/templates/daemon.json.j2 b/compose/playbooks/keycloak_server/roles/docker_install/templates/daemon.json.j2 deleted file mode 100644 index c8a6d5e..0000000 --- a/compose/playbooks/keycloak_server/roles/docker_install/templates/daemon.json.j2 +++ /dev/null @@ -1,7 +0,0 @@ -{ - "log-driver": "json-file", - "log-opts": { - "max-size": "{{ docker_log_size }}", - "max-file": "{{ docker_log_files }}" - } -} \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/roles/docker_install/vars/main.yml b/compose/playbooks/keycloak_server/roles/docker_install/vars/main.yml deleted file mode 100644 index 8831049..0000000 --- a/compose/playbooks/keycloak_server/roles/docker_install/vars/main.yml +++ /dev/null @@ -1,7 +0,0 @@ ---- -# vars file -docker_log_size: "100m" # Размер файла логов для Docker (в мегабайтах) -docker_log_files: "3" # Количество файлов логов для Docker -docker_users_list: # Пользователи которых необходлимо добавить в группу docker - - root - - gem-admin diff --git a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/README.md b/compose/playbooks/keycloak_server/roles/keycloak_install_docker/README.md deleted file mode 100644 index cbc8819..0000000 --- a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка Keycloak (Docker) \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/handlers/main.yml b/compose/playbooks/keycloak_server/roles/keycloak_install_docker/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/tasks/install_keycloak.yml b/compose/playbooks/keycloak_server/roles/keycloak_install_docker/tasks/install_keycloak.yml deleted file mode 100644 index a8ffcde..0000000 --- a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/tasks/install_keycloak.yml +++ /dev/null @@ -1,57 +0,0 @@ ---- -# Установка Keycloak (Docker) -- name: Install Keycloak - block: - - name: Creates base directory - ansible.builtin.file: - path: /opt/docker/{{ item }} - state: directory - loop: - - keycloak - - keycloak/ssl - - keycloak/db - - - name: Create compose config - template: - src: compose.yml.j2 - dest: /opt/docker/keycloak/compose.yml - register: compose_updated - - - name: Copy SSL PEM key - copy: - content: "{{ iam_ssl_pem }}" - dest: "/opt/docker/keycloak/ssl/iam.pem" - mode: 0644 - register: cert_updated - - - name: Pull docker images - shell: | - cd /opt/docker/keycloak/ - docker compose pull - when: compose_updated['changed'] - - - name: Run docker compose config - shell: | - cd /opt/docker/keycloak/ - docker compose stop - docker compose up -d - when: compose_updated['changed'] or cert_updated['changed'] - - - name: Allow ports - community.general.ufw: - rule: allow - port: "{{ item }}" - proto: tcp - loop: - - 80 - - 443 - - - name: Check service ports - wait_for: - port: "{{ item }}" - host: 127.0.0.1 - state: started - timeout: 5 - delay: 3 - loop: - - 443 diff --git a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/tasks/main.yml b/compose/playbooks/keycloak_server/roles/keycloak_install_docker/tasks/main.yml deleted file mode 100644 index f6e361c..0000000 --- a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/tasks/main.yml +++ /dev/null @@ -1,6 +0,0 @@ ---- - -# Установка Keycloak -- name: Install Keycloak - include_tasks: install_keycloak.yml - diff --git a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/templates/compose.yml.j2 b/compose/playbooks/keycloak_server/roles/keycloak_install_docker/templates/compose.yml.j2 deleted file mode 100644 index 52a0365..0000000 --- a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/templates/compose.yml.j2 +++ /dev/null @@ -1,44 +0,0 @@ -services: - keycloak_web: - # image: quay.io/keycloak/keycloak:25.0.1 - image: quay.io/keycloak/keycloak:latest - container_name: keycloak_web - restart: always - environment: - KC_DB: postgres - KC_DB_URL: jdbc:postgresql://keycloakdb:5432/keycloak - KC_DB_USERNAME: {{ db_username }} - KC_DB_PASSWORD: {{ db_pass }} - - KC_HOSTNAME: {{ fqdn_name }} - KC_HOSTNAME_PORT: 8443 - KEYCLOAK_HTTPS_PORT: 8443 - KEYCLOAK_PRODUCTION: 'true' - KEYCLOAK_ENABLE_HTTPS: 'true' - KEYCLOAK_HTTPS_USE_PEM: 'true' - KC_HTTPS_CERTIFICATE_FILE: /etc/x509/https/iam.pem - KC_HTTPS_CERTIFICATE_KEY_FILE: /etc/x509/https/iam.pem - KC_LOG_LEVEL: info - KC_METRICS_ENABLED: 'true' - KC_HEALTH_ENABLED: 'true' - KEYCLOAK_ADMIN: {{ admin_username }} - KEYCLOAK_ADMIN_PASSWORD: {{ admin_pass }} - command: - - start - depends_on: - - keycloakdb - ports: - - 443:8443 - volumes: - - "/opt/docker/keycloak/ssl/:/etc/x509/https" - - keycloakdb: - image: postgres:16 - container_name: keycloakdb - restart: always - volumes: - - /opt/docker/keycloak/db/:/var/lib/postgresql/data - environment: - POSTGRES_DB: keycloak - POSTGRES_USER: {{ db_username }} - POSTGRES_PASSWORD: {{ db_pass }} \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/vars/main.yml b/compose/playbooks/keycloak_server/roles/keycloak_install_docker/vars/main.yml deleted file mode 100644 index fa2fb4c..0000000 --- a/compose/playbooks/keycloak_server/roles/keycloak_install_docker/vars/main.yml +++ /dev/null @@ -1,2 +0,0 @@ ---- -# vars file diff --git a/compose/playbooks/keycloak_server/tasks/check_os_version.yml b/compose/playbooks/keycloak_server/tasks/check_os_version.yml deleted file mode 100644 index 2909c8b..0000000 --- a/compose/playbooks/keycloak_server/tasks/check_os_version.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -# Проверка версии ОС -- name: Check OS version - block: - # - name: DEBUG OS version - # debug: - # msg: - # - "OS: {{ ansible_distribution }}" - # - "Version: {{ ansible_distribution_version }}" - # - "Major version: {{ ansible_distribution_major_version }}" - - - name: OS version not supported - fail: - msg: "Operating system {{ ansible_distribution }} ver. {{ ansible_distribution_major_version }} not supported" - when: ansible_distribution not in ['Ubuntu'] \ No newline at end of file diff --git a/compose/playbooks/keycloak_server/vars/base_conf.yml b/compose/playbooks/keycloak_server/vars/base_conf.yml deleted file mode 100644 index 3cf8409..0000000 --- a/compose/playbooks/keycloak_server/vars/base_conf.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# Переменные конфигурации -docker_install: "yes" # Установка Docker - "yes" или "no" -fqdn_name: "iam.stage.co-work.local" # FQDN имя сервиса IAM - diff --git a/compose/playbooks/keycloak_server/vars/secret.yml b/compose/playbooks/keycloak_server/vars/secret.yml deleted file mode 100644 index 22ccfdb..0000000 --- a/compose/playbooks/keycloak_server/vars/secret.yml +++ /dev/null @@ -1,189 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -32333836633564653231393966383764633834663564316138626464666438656636636261633263 -3165303136353232623535326338363936306138336232340a613161356461353764326231613934 -30333933386631373238333865386437343935643666336366613233343931323434393831323230 -6264303839653264300a336335643533333364646433353335313733623031313137343862663136 -30386362373564366338306139613632656566623265333361666436376264303663313664323433 -30663734623763343564393962663831373838623033636636636163383637393330323132303834 -62306231393465366663643433623430336339656166323037383364343632633632626262643937 -64646134613136346134386333666362393465383234636363336365613936646336356634643333 -38663064366364333631316162353837346637646230323565316339386237653765613862663138 -66336338333266363634303039313930323234366339373538333734316336363632643761613734 -31636438613835343631636564656137613833383865393830316331383933653336326132353131 -30373466356134366631343236333963393332666262396262636561396638346135326333333264 -36316333643430396138373733396437376232643864613066386332663339626466393336393561 -34646138326365356636646438356464333331363839643832333163306465623131373237393138 -34643535343033316532653938326563323466636534643034326637363431313532313535383265 -33646230626566393763633533316265346130633464623933343335613233343965363535643237 -35373839663535396462306164623365366666663733366464613863333961376639346436643037 -39383731303833653138333962333530306661356234643566316336383061396431366564623766 -31303762373035353737323463346334396265343365616138636665333261363662636235343363 -31626565386265313764666633396162346162376232343139396530663038643831346337333238 -31313661393930393330656435363837396366373732363531323163383864346634356230333663 -64313161643037333735316332633831613533653164346464633261646361626166623163373038 -64393465363331373639366465666363303031333864303364643239623463656634346636633432 -37336261663539366462346663373633326332336632306637383732623035333633656262393032 -39616138663463353066616534366163363036393064643536336266613433303964613866613239 -35633938356365646539366165613333323661333338646235363131383236343163393562316532 -61623531666266313439343934626663363838623963383238393862653162323866353932336664 -39653431356334663236613037323234636135313063343335316164343834336133633735373434 -36656163616430333161643336343964313238323333363737313836386366656332646465376166 -30383233666466313261616236343566386134356130336132646133343566343566653734343038 -35646134613362666232313366313533396535643163616432333861346232613830316239613166 -32323866306236323565626162613763313034656463333236663562326133393261383936616538 -31626630613133363666636238343164323434646163363562303333383965653263383332643064 -63333833636330656331316538663237303432643031316465663331303561666565313565653164 -34613739386434656231303562386264613663313561666162303436313363373739626537353366 -64353866313934376161333765313662303865383035366666326666303939343761343936366530 -62373537353531643766346164623236353463343263363862306134393864613264316265626262 -39343133363263313732623837663266636265303661643265623938306235363933316566313434 -63313832353434323732643635646138386638373932663533636163373033623462306437663237 -65343638343933623665626634393238623437633065633064363333363465373761663939633730 -35383539646432316233636563316332383139346637383037393662653037313937393839623966 -61333635303436666532323063666365616261316535343063663730653637636132373561333834 -62653064333934613935343831633062616532386130616537616438366233373863613263333665 -36353037623532643730343361366266653165313231626134373733383538326436353366656330 -66346531613965383732316634396461633437656630393733393339393564396239663062626263 -62613761636531346266306261393166373732373939663162643261353630366235623362316435 -61643130636137666230373031383631323030393262343863666137623233333165643965326432 -61613264303065616565336465663164616332363335636631393563316137643636333263386237 -37383934636133633964386134616237623064653034353662383035653330323662373466663936 -66663030326233306339346165616636366432343139613965323131653037313835353136363466 -31633731336439323336393630356332626133643861336238393932323465643262633230636537 -32636336373465633364353764393762363965336364646263303136373931653661313339333631 -64623830336262663631316131333762333563656666343866656237363066643336356366613030 -66336339663166343230366333393436346337333833333132383630383037373530666661326539 -38643030653861633737636565663063663131343830373032616562666166346530333630656431 -36343264653138393038643338616364633431636534656263666339303631633838643562653534 -66373861303965643836313039623732393263616430306332386233643238626336316637393038 -30336535653963366433393534313933313266393062346461663133613461356233343738343333 -30643037343631326435303230343133326130373965616461613735303564663637333531666432 -61323039303633623663303264643932326362366263353232333333383266663531356530303430 -64653564386663326532373363653065376663643339653561376163326639613664646239336661 -31333532643737343037623036343263313039366137393063326330316266643836633164633032 -64376134653838313364316663363939663161626262373630373238373537363436363437656130 -33626635313730383734303536316130626432313337373631653636653239353430333161333263 -30653936373232613939363431396366646438393835626130626365303064333261333766646633 -62663763333665373230313163633037393662366432326537343866613936646534313263616134 -38363062356666343537666664303035616461626639306561393339303432656163393366613965 -62313135366466396466633061346333303165363237353466383835643335383966333066343866 -31316433646331356364346664643734373432313537383236646465656661383030363335343236 -64336236306561326334663035386338613463326239356133303233316139613633326336633262 -30623134616332656538386437353661373461663634306436383534666333623339353837383334 -36373233643864653433326134313431313331383936376432353734663833646639616565303631 -36343661303562346633383362326236613937343437393239326235383366623763636630313339 -66343462363232306430326263393838333238636439616461363731386234376333366638376530 -30626333333936613339643931626637323134363230313564633962653964316234323733333035 -39363936396561636330343836643163303732313934373836326261376330323834643966633436 -63373634353838663036343065366561616135376534313037613736653564623332386362646437 -34663139356636646133313164316538396435353638396336313738663162646234356333653162 -37336461666362383863366361333362303762383862646330613734366433666235316530633734 -37383663376561666233353536393534383235623665366332306466363936363634613634396631 -65663739636631643564636463613162303166633962333931633664333735363465623235313438 -66376563326431386661346163633534613232633536636137373731653234336262363133353964 -65313832376532626366303463626562323234353664626565346163353033396234363761313135 -33663366386463333732303362633534363338316363316334623333393534343633386237363561 -62613136663831393530366261623239343330653766623830333061616130333231656339633365 -63346231383533646663366536336633633763383163656135623234343265393337323461623764 -61343333383738613564653563356238623061633538346564643932663734313832343039653433 -32613931646165636266623065646562386332383663623339366435646332313438356463636164 -32656234393433343661383137346132396632616437323064343731316331353732303366303433 -34333337626466343664363635656434316533303863613861333662313530323131623937393739 -66333931316635393161656137613666343763643965346364323063386637306630313863386661 -62386561653961393936346337353861333435646363343638626264613537383537613637396632 -62373463383662346139633435626161353237323138353663316465613563363261396539353965 -38313031666333366230306436396535306566616265336236643734636361663164613066303466 -37643039386362613033323139373133363238306665616338653736633030343535326437373265 -36656339313233363931303766313263666237336230616262623865656634393333383334393332 -32323033373333356234396238336138373661643238306539336463626134363035333239306139 -36613938646633393237313962343166366563326438356136313235363231663830633861653433 -63396630393338356430373563613262653039313339343161336635666461323061613961383039 -62363766633333306233383035663731363362656535623734656430663465363336666565663332 -31623432643063303332326536393338666536663334366232383838613732633833333466643361 -39313537316331343733613436356234626634373639383263386162623337396365383439323032 -31303935613533306537393963373663313531306533313537373464656366646132656432633063 -39633232643134313334616430613639633739313332643633613362343139353736666230373332 -33633563343035303634363836326232636137656337346335396238313766643038623164656134 -32323566626235653738643062653439396537666563376230343364636439393464306538323630 -65616131373330643331636637343262346239333032643332343766623938643739393530666164 -39356236396561303033393033393663336532366661383162383433333665363961313132323664 -39366630316161663066363666333934376530343766663665623037366339666263306665383535 -64616132613561383836646333386439643962613064656537323730333034393661306662323733 -34636465613263613031333131633833333030663262313761333063383231373966313237623264 -65323631373434366337643463323264326237663539303338336465396532313032393765346239 -61663535363562663364323136353235666563343937666333376265373166653830393462643530 -31633531326135363238663763363562613337633137306137626334353661616333316635656538 -64373937626538363331383838643564646463316462363638653133363561643034333532303862 -34313636646636363964366662316435613231316137313534623035623730666635343732383966 -33353465376236363136353933353638363536353832386664653636663638343566643963666532 -31326535373365343332303865386461666465366632663535303466366261303335333134373133 -66363431396636383837653466643635323836346361346561653962336130353536363261313034 -64383936356436396238653666303831636330316333613461633631626162613630613363346637 -65306665353033646137363338363737613531313432353066316663636533386339313162356536 -35306262353664333533386366623364373635376363653031626334303137316263326363343861 -37366561343164623533323363386439616533663731396331636362623730343632393238663364 -34376236313738326439383633306532343532366237373263376664316437336261356639373065 -30346130616334633566343733663532356137313566646537353431613730613065633033393534 -65323530663036613035336335623337366464343537303737656534646366346331356666363532 -33313965633135346236346135643730353236376331626436613933386464623762393739366232 -32663864663064633563643931653339623262353036376634333531656564653038666531386161 -30646136326230663066316630383938393332663762383434623738386239633636333761643431 -61616364626335323563393037396563636632633639633762366363386662363130313137653434 -35356534343631363733633539393935653334663931396364303137376139313130333830663538 -64356266636431626430336662333730393133326635396233663365356666366430623232346438 -62313263303762636663373937343465383936666533623635386332306462643835653432306130 -37323765663634373865643138633632316633376136353035663733623939336462373038376261 -34663832333335353233616630306137636561323435656137333131336137303461656337666339 -35303238353831646663363066653165623933613064383735626432396437663839613637333732 -36653063643538613132336263616131366334626235366435666135343264353866313263316361 -65666436356337306332613066316133633463653762333839393130343533353238613364653133 -30383233666339313538663638303936303461663439643366373933343563376233626135316263 -37393930663937616334303364383332616637386162323336313938333530663638316661623730 -65636235323230323030636266396230303636323739626164633436353035643032386232336330 -37633761313663343637646439386336333436313866393664393761363035646331306164343962 -65383038636265333764666635386533336563323434383562343430613436343332643666353633 -32346233363065353139633564626138343938333131316336636539623539623435613031303663 -33613336343162616137323238343464636433356236653362376431323438653137363666366533 -31633565633762643163653830386235306162323663636363343033303261613263363832393866 -31366133343362323231613238376537643163316437333661353264363739303830386233373665 -33313634636464313564333534336335363236643835386564633464336462616335663636383631 -33373035613634663331313230613737366662613033383363623932653262333931393134656666 -64633933653536666637666265306439343834353361396665363637656433386236333861303562 -35613766313965653066313238656535333235353331326431353234366164643432623133666430 -61346637363836643765633737636536306337383131643564363463303965656638316236333665 -37643934333132393834663931616236313730316139653231376237343537336438376334323861 -64373131383931633336643461663830663964356365653934306430396238323939666464393464 -62396336353562353431396265326131646266323864396332616463613032333235343836366337 -65643531353636626539653436356437623738643438633036633237323531383662316166383466 -35663866396366626233333132356339356165366663313665313966613364336339376538633665 -65646665366335383066316630366336336163313232633931363839303639316535353338323037 -66633236623234363633653062393564373331346232633665626230326332313937353035343032 -64633538383638353563363939346166613961346162393766323632376436376632323239363536 -64333466313063383061623463346563343837316563623338643139633963633661336438396462 -33353730646138313866656133323335386136333738616437353031663832313165653236353630 -35353363383666633238343862373963373962656435363332656261313939623939613234316330 -34336432626334663330643339636132653666333235363163356132623834373761363265376161 -39643430376532303234346664396639663566383338633938393965653461326365656365303833 -32306330336537333038353037643830353766363333383864653937316438643438376531633639 -62623563323234343334306230633833303866646637623638363539613839656265633434633133 -38633461666663613662623239373134616566316437623535323039363831626663633261376132 -35396561376361303062656564663862353636343266313862393961353763623064643333356463 -35383762636231643430376662393136613064663931343334666135666535343935313936393634 -30396637333031333765373965333631646332663331396337376432653062656266313938393461 -37613933623463666131393863376438393437616632613637383734313938646232653065643634 -64633964633264626530666561343130383038376133373431393930353731616634623639356637 -39663931376139323839643762346536346461303166396235386536616430646237656632613162 -35333033383664393032343733626665653937316264343333386234323564616330343231363065 -66366332613439356665633166616365353835613536396134373333386365376664333263653364 -33623536656438356463333266626166653830386265326134363633626530306632373835373237 -31366430643030336138336164663630393738653432366530626466326335623431313137383064 -32373931333764353861666262616437363966393032643030656134393638326335393331386631 -66616532336330616263323637396133663362396430653334333666653164353532626335383738 -34643964356236656635396231383531643661313762643666363264363738373832653932303333 -61326531396131666433383461363130336562653863356164323734323963303331636265623563 -30356464613333663061343830653738633765393061393065623261343866663866623465346130 -38356265313336646630386439663561323938643538336130303430323235656539303561366133 -64623261646461353237373336343132386336343766666565393737613736666537383831616233 -66343631383764383363623064653439326365323161313633633635353332363834393332303930 -61373137626362623033323463633866623661613931323339643166336337623337383537653666 -64663834373836626361 diff --git a/compose/playbooks/openldap_server/README.md b/compose/playbooks/openldap_server/README.md deleted file mode 100644 index cb4b52f..0000000 --- a/compose/playbooks/openldap_server/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Playbook information -====================================================================== -Плейбук по установке OpenLDAP в Docker \ No newline at end of file diff --git a/compose/playbooks/openldap_server/ansible.cfg b/compose/playbooks/openldap_server/ansible.cfg deleted file mode 100644 index 20d7065..0000000 --- a/compose/playbooks/openldap_server/ansible.cfg +++ /dev/null @@ -1,4 +0,0 @@ -[defaults] -ansible_managed="Ansible managed" -host_key_checking=False -inventory=inventory/hosts diff --git a/compose/playbooks/openldap_server/defaults/main.yml b/compose/playbooks/openldap_server/defaults/main.yml deleted file mode 100644 index 11163dc..0000000 --- a/compose/playbooks/openldap_server/defaults/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# defaults vars -# ansible_python_interpreter: "/usr/libexec/platform-python" -ansible_ssh_pipelining: "true" -ansible_user: "gem-admin" -ansible_ssh_transfer_method: "piped" -ansible_ssh_common_args: "-o StrictHostKeyChecking=no" -ansible_port: 22 - diff --git a/compose/playbooks/openldap_server/handlers/main.yml b/compose/playbooks/openldap_server/handlers/main.yml deleted file mode 100644 index c09dec7..0000000 --- a/compose/playbooks/openldap_server/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# handlers file - - - diff --git a/compose/playbooks/openldap_server/inventory/hosts b/compose/playbooks/openldap_server/inventory/hosts deleted file mode 100644 index 86de6b1..0000000 --- a/compose/playbooks/openldap_server/inventory/hosts +++ /dev/null @@ -1,4 +0,0 @@ - -[ldap-host] -cw-sya-ldap-001 ansible_host=10.130.0.16 - diff --git a/compose/playbooks/openldap_server/main.yml b/compose/playbooks/openldap_server/main.yml deleted file mode 100644 index bb1d42d..0000000 --- a/compose/playbooks/openldap_server/main.yml +++ /dev/null @@ -1,18 +0,0 @@ ---- -# Установка OpenLDAP (Docker) -- name: Install OpenLDAP (Docker) - hosts: cw-sya-ldap-001 - gather_facts: true - become: true - vars_files: - - vars/base_conf.yml - - vars/secret.yml - - defaults/main.yml - pre_tasks: - - import_tasks: tasks/check_os_version.yml - roles: - - role: docker_install - when: ansible_distribution == "Ubuntu" and docker_install == "yes" - - role: openldap_install_docker - when: ansible_distribution == "Ubuntu" - diff --git a/compose/playbooks/openldap_server/roles/docker_install/README.md b/compose/playbooks/openldap_server/roles/docker_install/README.md deleted file mode 100644 index ae41738..0000000 --- a/compose/playbooks/openldap_server/roles/docker_install/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка Docker-ce и Docker-compose \ No newline at end of file diff --git a/compose/playbooks/openldap_server/roles/docker_install/handlers/main.yml b/compose/playbooks/openldap_server/roles/docker_install/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/openldap_server/roles/docker_install/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/openldap_server/roles/docker_install/tasks/configure_docker.yml b/compose/playbooks/openldap_server/roles/docker_install/tasks/configure_docker.yml deleted file mode 100644 index 0aeb46c..0000000 --- a/compose/playbooks/openldap_server/roles/docker_install/tasks/configure_docker.yml +++ /dev/null @@ -1,29 +0,0 @@ ---- -# Настройка Docker -- name: Configure Docker - block: - - name: Make docker config - template: - src: daemon.json.j2 - dest: /etc/docker/daemon.json - mode: 0644 - register: docker_updated - - - name: Enable and start Docker service - service: - name: docker - state: started - enabled: yes - - - name: Restart Docker service - service: - name: docker - state: restarted - when: docker_updated['changed'] - - - name: Add users to a docker group - ansible.builtin.user: - name: "{{ item }}" - groups: docker - loop: "{{ docker_users_list }}" - # when: docker_users_list is defined \ No newline at end of file diff --git a/compose/playbooks/openldap_server/roles/docker_install/tasks/install_docker.yml b/compose/playbooks/openldap_server/roles/docker_install/tasks/install_docker.yml deleted file mode 100644 index 6cfefa7..0000000 --- a/compose/playbooks/openldap_server/roles/docker_install/tasks/install_docker.yml +++ /dev/null @@ -1,35 +0,0 @@ ---- -# Установка Docker -- name: "Check packages is installed" - package_facts: - manager: "auto" - -- name: "Install Docker" - block: - - name: "Add GPG key" - shell: | - install -m 0755 -d /etc/apt/keyrings - curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc - chmod a+r /etc/apt/keyrings/docker.asc - - - name: "Add the repository to Apt sources" - shell: | - echo \ - "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \ - $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \ - sudo tee /etc/apt/sources.list.d/docker.list > /dev/null - apt-get update - - - name: Install docker packages - apt: - name: '{{ item }}' - state: present - update_cache: yes - loop: - - docker-ce - - docker-ce-cli - - containerd.io - - docker-buildx-plugin - - docker-compose-plugin - - docker-compose - when: "'docker-ce' not in ansible_facts.packages" \ No newline at end of file diff --git a/compose/playbooks/openldap_server/roles/docker_install/tasks/main.yml b/compose/playbooks/openldap_server/roles/docker_install/tasks/main.yml deleted file mode 100644 index 08fc61c..0000000 --- a/compose/playbooks/openldap_server/roles/docker_install/tasks/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- - -# Установка Docker -- name: Install Docker - include_tasks: install_docker.yml - -# Настройка Docker -- name: Configure Docker - include_tasks: configure_docker.yml diff --git a/compose/playbooks/openldap_server/roles/docker_install/templates/daemon.json.j2 b/compose/playbooks/openldap_server/roles/docker_install/templates/daemon.json.j2 deleted file mode 100644 index c8a6d5e..0000000 --- a/compose/playbooks/openldap_server/roles/docker_install/templates/daemon.json.j2 +++ /dev/null @@ -1,7 +0,0 @@ -{ - "log-driver": "json-file", - "log-opts": { - "max-size": "{{ docker_log_size }}", - "max-file": "{{ docker_log_files }}" - } -} \ No newline at end of file diff --git a/compose/playbooks/openldap_server/roles/docker_install/vars/main.yml b/compose/playbooks/openldap_server/roles/docker_install/vars/main.yml deleted file mode 100644 index 8831049..0000000 --- a/compose/playbooks/openldap_server/roles/docker_install/vars/main.yml +++ /dev/null @@ -1,7 +0,0 @@ ---- -# vars file -docker_log_size: "100m" # Размер файла логов для Docker (в мегабайтах) -docker_log_files: "3" # Количество файлов логов для Docker -docker_users_list: # Пользователи которых необходлимо добавить в группу docker - - root - - gem-admin diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/README.md b/compose/playbooks/openldap_server/roles/openldap_install_docker/README.md deleted file mode 100644 index e79e494..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка Openldap (Docker) \ No newline at end of file diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/files/cert/RootCA.crt b/compose/playbooks/openldap_server/roles/openldap_install_docker/files/cert/RootCA.crt deleted file mode 100644 index d61df84..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/files/cert/RootCA.crt +++ /dev/null @@ -1,22 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDkzCCAnugAwIBAgIUTTdDE08O+Sdo6Zxp5pfPzJ6XFdMwDQYJKoZIhvcNAQEL -BQAwWTELMAkGA1UEBhMCUlUxDzANBgNVBAgMBk1vc2NvdzEPMA0GA1UEBwwGTW9z -Y293MRAwDgYDVQQKDAdjby13b3JrMRYwFAYDVQQDDA1jby13b3JrLmxvY2FsMB4X -DTI1MDEyNDEzMTAyOVoXDTM1MDEyMjEzMTAyOVowWTELMAkGA1UEBhMCUlUxDzAN -BgNVBAgMBk1vc2NvdzEPMA0GA1UEBwwGTW9zY293MRAwDgYDVQQKDAdjby13b3Jr -MRYwFAYDVQQDDA1jby13b3JrLmxvY2FsMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A -MIIBCgKCAQEArHKBcveZBhMwhifgiPn+bBU9hw3sLRI/SHFFMX3hNvjYFwpjY3Kv -g52jdbFdQwcG14/uiXJCkF3NX8iIpCtZx8aPHY2JKpzr9Kvs4Ui1c9f33Z+CEWOx -KaYcbz5L9f8EgDyAJcZ7dDBGv7n1MY4E9gTDUO1CBcSNhzcNRj4h0y3av0Q5wNew -1aGg0GN+BoniclX2silaGYx+UfsvdnQM0ujIA8RbtYsRyg0z2/6u80AeE0y5dBkH -JxLao6xs/Ha7xBmK0dUzovbFj1khskIET16xnMhsCImIDSQtfjOEPO44Lt9RtS/c -pd1AleNxG8DAGGIJ87FfsRTIsCuP0ZV5LwIDAQABo1MwUTAdBgNVHQ4EFgQUw1pz -/FfPI4ZswcAaX1SlU3Vyy38wHwYDVR0jBBgwFoAUw1pz/FfPI4ZswcAaX1SlU3Vy -y38wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAmrv6hpGTJAMY -WjlvJRlGVuTCmnEgLwkuOyFl+V5WIr6JRE14Mr56OVmXBrRD7ZnFSYX3BdG7Lan9 -AlQwsqPQRmd1jRW3FtOYRKOX5Bxti0JJBIZ8GdisBCWXeb0ijppyOT8Hs6JzFdac -1WhgJNx4lPZ/NgTSRXOshDVGSNNnU02IM/bz/8aW+Xi0jk6TMoiFju/49nXt3vs/ -Nr4UCmL/1SBsPrz0H8qgSz0Cbo8RkAVMkHitkWEsSMfaIR9Q9xY8JOUvAGb0TH/t -pPLF4WyNTqWsccLm5RluJugtPmT5ZzTYsfmaPulnSa8NqIcxD4lJvCU3OpL+eop6 -BHFEdJ5o3w== ------END CERTIFICATE----- diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/handlers/main.yml b/compose/playbooks/openldap_server/roles/openldap_install_docker/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/tasks/install_openldap.yml b/compose/playbooks/openldap_server/roles/openldap_install_docker/tasks/install_openldap.yml deleted file mode 100644 index c2e19d7..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/tasks/install_openldap.yml +++ /dev/null @@ -1,78 +0,0 @@ ---- -# Установка OpenLDAP (Docker) -- name: Install OpenLDAP - block: - - name: Creates base directory - ansible.builtin.file: - path: /opt/docker/{{ item }} - state: directory - loop: - - openldap - - openldap/data - - openldap/data/certs - - openldap/data/ldap - - openldap/data/config - - openldap/haproxy - - openldap/haproxy/ssl - - openldap/haproxy/conf - - - name: Create compose config - template: - src: compose.yml.j2 - dest: /opt/docker/openldap/compose.yml - register: compose_updated - - - name: Create haproxy config - template: - src: haproxy.cfg.j2 - dest: /opt/docker/openldap/haproxy/conf/haproxy.cfg - register: haproxy_updated - - - name: Import CA certs - copy: - src: "cert/{{ item }}" - dest: "/opt/docker/openldap/data/certs/RootCA.crt" - loop: - - RootCA.crt - register: ca_cert_updated - - - name: Copy SSL private key - copy: - content: "{{ ldap_ssl_private_key }}" - dest: "/opt/docker/openldap/data/certs/ldap.key" - mode: 0600 - - - name: Copy SSL public key - copy: - content: "{{ ldap_ssl_public_key }}" - dest: "/opt/docker/openldap/data/certs/ldap.crt" - mode: 0600 - - - name: Copy PEM certificate for haproxy - shell: | - cat /opt/docker/openldap/data/certs/ldap.key /opt/docker/openldap/data/certs/ldap.crt > /opt/docker/openldap/haproxy/ssl/ldap.pem - - - name: Pull docker images - shell: | - cd /opt/docker/openldap/ - docker compose pull - when: compose_updated['changed'] - - - name: Run docker compose config - shell: | - cd /opt/docker/openldap/ - docker compose stop - docker compose up -d - when: compose_updated['changed'] or haproxy_updated['changed'] - - - name: Allow ports - community.general.ufw: - rule: allow - port: "{{ item }}" - proto: tcp - loop: - - 80 - - 443 - - 389 - - 636 - diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/tasks/main.yml b/compose/playbooks/openldap_server/roles/openldap_install_docker/tasks/main.yml deleted file mode 100644 index 9f76594..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/tasks/main.yml +++ /dev/null @@ -1,6 +0,0 @@ ---- - -# Установка OpenLDAP -- name: Install OpenLDAP - include_tasks: install_openldap.yml - diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/templates/compose.yml.j2 b/compose/playbooks/openldap_server/roles/openldap_install_docker/templates/compose.yml.j2 deleted file mode 100644 index ab918f6..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/templates/compose.yml.j2 +++ /dev/null @@ -1,61 +0,0 @@ -services: - openldap: - image: osixia/openldap:latest - container_name: openldap - hostname: openldap - restart: "always" - ports: - - "389:389" - - "636:636" - volumes: - - ./data/certs:/container/service/slapd/assets/certs - - ./data/ldap:/var/lib/ldap - - ./data/config:/etc/ldap/slapd.d - environment: - - LDAP_ORGANISATION={{ domain_lvl_2 }} - - LDAP_DOMAIN={{ domain_lvl_2 }}.{{ domain_lvl_1 }} - - LDAP_ADMIN_USERNAME= {{ admin_username }} - - LDAP_ADMIN_PASSWORD={{ admin_pass }} - - LDAP_CONFIG_PASSWORD={{ config_pass }} - - "LDAP_BASE_DN=dc={{ domain_lvl_2 }},dc={{ domain_lvl_1 }}" - - LDAP_TLS_CRT_FILENAME=ldap.crt - - LDAP_TLS_KEY_FILENAME=ldap.key - - LDAP_TLS_CA_CRT_FILENAME=RootCA.crt - - LDAP_READONLY_USER=true - - LDAP_READONLY_USER_USERNAME={{ ro_username }} - - LDAP_READONLY_USER_PASSWORD={{ ro_pass }} - networks: - - openldap - - phpldapadmin: - image: osixia/phpldapadmin:latest - container_name: phpldapadmin - hostname: phpldapadmin - restart: "always" - ports: - - "80:80" - environment: - - PHPLDAPADMIN_LDAP_HOSTS=openldap - - PHPLDAPADMIN_TRUST_PROXY_SSL=true - - PHPLDAPADMIN_HTTPS=false - depends_on: - - openldap - networks: - - openldap - - haproxy: - image: haproxy:2.3 - container_name: haproxy - ports: - - 443:443 - volumes: - - ./haproxy/conf/haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg:ro - - ./haproxy/ssl:/usr/local/etc/ssl:ro - networks: - - openldap - depends_on: - - phpldapadmin - -networks: - openldap: - driver: bridge \ No newline at end of file diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/templates/haproxy.cfg.j2 b/compose/playbooks/openldap_server/roles/openldap_install_docker/templates/haproxy.cfg.j2 deleted file mode 100644 index f5ceb53..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/templates/haproxy.cfg.j2 +++ /dev/null @@ -1,23 +0,0 @@ -defaults - mode http - timeout connect 5s - timeout client 5s - timeout server 5s - -frontend ldap - mode http -# bind :80 - bind :443 ssl crt /usr/local/etc/ssl/ldap.pem - http-response set-header Cache-Control no-cache - option http-keep-alive - redirect scheme https if !{ ssl_fc } - option forwardfor - default_backend ldap - -backend ldap - mode http - http-reuse safe - option http-keep-alive - option forwardfor - default-server inter 5s fall 3 rise 3 - server srv-phpldapadmin phpldapadmin:80 check diff --git a/compose/playbooks/openldap_server/roles/openldap_install_docker/vars/main.yml b/compose/playbooks/openldap_server/roles/openldap_install_docker/vars/main.yml deleted file mode 100644 index fa2fb4c..0000000 --- a/compose/playbooks/openldap_server/roles/openldap_install_docker/vars/main.yml +++ /dev/null @@ -1,2 +0,0 @@ ---- -# vars file diff --git a/compose/playbooks/openldap_server/tasks/check_os_version.yml b/compose/playbooks/openldap_server/tasks/check_os_version.yml deleted file mode 100644 index 2909c8b..0000000 --- a/compose/playbooks/openldap_server/tasks/check_os_version.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -# Проверка версии ОС -- name: Check OS version - block: - # - name: DEBUG OS version - # debug: - # msg: - # - "OS: {{ ansible_distribution }}" - # - "Version: {{ ansible_distribution_version }}" - # - "Major version: {{ ansible_distribution_major_version }}" - - - name: OS version not supported - fail: - msg: "Operating system {{ ansible_distribution }} ver. {{ ansible_distribution_major_version }} not supported" - when: ansible_distribution not in ['Ubuntu'] \ No newline at end of file diff --git a/compose/playbooks/openldap_server/vars/base_conf.yml b/compose/playbooks/openldap_server/vars/base_conf.yml deleted file mode 100644 index 1e9a83d..0000000 --- a/compose/playbooks/openldap_server/vars/base_conf.yml +++ /dev/null @@ -1,6 +0,0 @@ ---- -# Переменные конфигурации -docker_install: "yes" # Установка Docker - "yes" или "no" -domain_lvl_2: "co-work" # Имя домена на втором уровне -domain_lvl_1: "ru" # Имя домена на первом уровне - diff --git a/compose/playbooks/openldap_server/vars/secret.yml b/compose/playbooks/openldap_server/vars/secret.yml deleted file mode 100644 index 4d900d6..0000000 --- a/compose/playbooks/openldap_server/vars/secret.yml +++ /dev/null @@ -1,198 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -31333535313130303139323133653730663365333730363436306433633330363935306461663730 -3638396433336239363836643934313331393433626537320a353334336237323838346136363561 -35326532353766336535393464303239613336323264633333323032353738333231363034323638 -3530323466623230640a623736336461623634646164313831316231376234353239363730386131 -35306565306639326437393932656636363837323534386435613162656334663766636563616662 -33663239653931613266343136306337346639643765623833626235356638366538336566313233 -38653866386666623365356237616361366463656365333735623731376334326438373662653763 -34326337623563356130366630383763663639646238643834613964373965653031326361323366 -34663331343930373964316533633337633835363333343731623465643535303762336538386134 -35663065306662643734356364656237346637666663363333303066396330356637363931383138 -35666535636265343130386533323937393832646131303832376266333865616335306430616638 -30656161393363343165386263626365626239626138633162346466363530393435646163373132 -33613135633635373332626266363835356638386238313738366365333735643833323161303037 -63386664666437666132346665396333326633613564346636323630613461393334653261373335 -39303034643636633939343533656337656166333232333663633632373936346237313434663964 -61616634613366343834633863636361383365343137626237363439343038333131323665373236 -63633735376665656463383333633733623633666262326663663039366535363532303837646463 -37393661383035386430373238663737633565353531346137623438633431646363636636363730 -63386461373438613934363335306330386239303637613738353238396362643763623230643238 -64333231646530393138613331393466343137633131346432623336303066353162663134373962 -64663639323864336539333532346366373436633237333938353630373239643332353630633465 -38316538626430303637346566353731613062373334323465353539636431303431623463333966 -31303665363063323865623266613762383961336562646135353834356536666633323937333632 -32386638303237646164323837666464623766653537343932643335383461383435303339373364 -36383766316661366130633437616237333264616462366236396238383938663935336537313533 -30333463303263356565316263636566633433336130366366623633313334653462333162653762 -39346665383239376136396461373563616662346337366466656163363634303230396366326137 -34323731326230393237376232333463633439663730626261383330653862663132616163636636 -32333066346231373631626435616566366464613039656466613462653136373030376665663635 -63636335613535666638326130366135333638353033376138396630633364336565613931643130 -30313465353865623537373737336235393730303862386465336132373530373131313263613138 -33396235316265376336313430373064636461316530346166313466373036313337626439336336 -39646533393231626236323339373262636566343930616361616633626339623163313636623064 -31333266666664613337393331306336663331346363643734646432353631326464613266393531 -34666363653730383634643766663234393565383965653263666661336562656131386139346339 -36303663323164393230303835323333396437343334366565343863326566346566643239396164 -39623431393862613361663339363264306634386266376633663134653862643864643133366239 -62666535353866393239636230333266323031363466646662616635353566663433373830633831 -61393738643834376539323837396539323231313039386534333565386334303964633261313038 -65616161616539343732343964376634356236343730303165663237636232633837303634316434 -34336539393939626334396239336532376665386531393239636564323432323164616537333232 -32343132343137343264333235366563303261666130643439323038626238336236653334643164 -30626431383161323638326264326338653136393634333562376162623965336536373761306466 -62666432646137333031353032656330323734383131613730633830316632323262633533396236 -65303563376234346634623939333634653735373462383963336163613338316435396535376638 -33393934356561666266333233393931386137666561336363396265363239336637616661653663 -66306638636534343866653665626163376238323034336538386336333766313439356266326231 -38653863643534393861323636353666313337633063653639313839646661363937386361356164 -38663538633635306431383063353463636435633239663264366339386465663261353731326635 -62633532333931363236633666376563666630656431336166366333383562653036316233336535 -64353938333766393739303637336334626436326533663136643235636534373966333630346231 -37626666333230306137633538616563336633626663383966303139306361383233653738353932 -38353735336466363739373561383133623162376433656565383530616230663638646536386432 -64346264333438643838616666363065356233393839336538656238366637323366663039623533 -34316335616236393661633238633032306366653334396536346438633839323736343264333833 -32636361613764656561633666383730333435613332643235376461306334306335613138373931 -63623862316238383432623230643934656266323232303735333762653865306562653435303634 -38643332666639383633383561633534353335376332343239373338643466303938656339633430 -63346539373562346137616330396162353665353838326463653863366166316535643934356334 -35636538376433346464326133333262663663386137373931623362613737326333346431396561 -32393135646634343534366264626138626661633831366665333361333134356430353666316633 -38623830306134666466343735623763333431343337396165613861396162656531626231633961 -66623161363437613531396339363537353539303439353035633563663536313038366231366633 -34383262366336663361653839376464303336656131663064666666316363616463633439656431 -39643330363630376165343836326365306537306366323332346665353561616538346465666437 -39666337376132643261633566616436353365306662306163353235356630626132636361636661 -39323465376261343530636365613366656636613430353737366263626537306462393764633135 -36636434643565313139353933353261383463376438386264383733646535316635353866613835 -36393137353462323865343032666163383264326134346132353361373834633534353361653333 -66626437323135343633363465393635386661613737633236316330313963303439393833626530 -35643738646465313262343432396266646639303462333131306631373263373761623666613130 -38633362353734313438346565313135623732626639336437376435613538643365303934326439 -30323963323631326333613765363363626465663937386663653234363239326336626664373539 -31323865636534366564393537313531376263626137376433643233376239313433633562366131 -31643538666563646338326336653036366134363834643639356266653862333931373331643136 -32623830633364353064353632303738666533656466306264623165303738663763323464626634 -35656338353232626262323136353733663934333466346337373934313534373664663232643666 -34363731373535393666333530623030343039666532333237613937356430656238613064613431 -37316362326562303631666664633931313763646632323837663465393262633238333364353039 -66336535393133616630353861616334393033643831623532623766363462613461313364313837 -37363561663437626664303939346539626430316466633532366434393833353663303033383137 -38363439653933353738336136323566626363613163626333386366393430383063383464393861 -36386333323565653639323336326337366664643061343264353763666537383638656432303539 -39666433363038626363323634333763323339633831313165373765646537653735306630343938 -33326534366636373534333033643534636462316634383237653639303933316165626630366562 -61653165623336666264356432303137353633383834396561663565633439646461633865373163 -37666237613433326131346365336332386238626264326562383861653733383231656132383239 -38363931666466336631663762333632393933323831623530626130353565643265343732353530 -37346466636537616166616163346366646134393636613838316564333139363733363861303161 -32386330666633313038633762646164643364623034313464613964656633383030636439613530 -30613962326637656239346434623031333662623933366331336663666237376233356633383135 -34653438643131393166633139373966393631373935663234373930336563363530633166343139 -32393331363835326131343162663438633532663739373436383137666239303964643736626239 -64363336666164366163666264333864323639373233316361643965343037633335336566313461 -61373831643134383666303037393637346665326663306165623235383966396236383938303631 -63636336353766346435633632633463356630616538623966323331633966663433633636303435 -38383239373733343638363464633833613532353136376138633863633136363338633033363231 -32383535663530326331346330396138613264303631333137653264363166663730353365346230 -61323062633137656531613236623761313538336463306564396666393162653461356233383434 -64313635356430353430393665643563393131326632326466393064633639393932343865303862 -38653037353033353234343063333330613365313636373130303963326464666161333536666333 -61616636383135636566336434346539613338383461633064313134366564366665306631616565 -61353934333961653738633239666566356463363830333137313835326231636330633065373135 -38306366383565383063626230633366666561623030663163626635353261666564343635303939 -61313538353337353334613666616237346433343630666233316432373337326131363865346531 -34356132663037613965346336353964643230643636393837333131343134633639636238323335 -62383036336364623063666430316337323432653762333230396435373165343564633631376162 -61366438393932626230356363346361313536346162323434396630343564343163336230363839 -66353832663332396163383633333837346365633061636263663534353133643237643533393334 -62393932383563383432306264363762636530366466383833343534356234353165303464383063 -38666133393439653164366565383338373334306436303235373663636662326134363235306631 -36616138323165623237336465633161616139383663643033383335353766313532623238663961 -37323632343733613463386165643965643962643661373530383866393566396531316664653734 -36666565633063646161643265653839333233633666326266303035623466643963626132643366 -35373633653163323232623031363731336339616434386534336335383931306331623332653266 -65323636393835383862656561633237346366616633663362323235316431393336386462313131 -65363664663933323135653864643139663366376131323236306263333462643533663561616461 -32656531383430336663343637356130383764366361376263383035373132663438636332376538 -62393831363161653635653930366363343433666162396431633939656139316237303064636364 -63386661333338663737366261336134626261366137393831383136646438363065663237653535 -37623165626363353938613138346233373231626265323664373939613931306464363839616333 -65393036306134666566623965613265383562353436643034313666366239333663383661383339 -63383264363638373439306135356636613466333137643765613533613934613262396530323930 -34613137626131376439323035316164383931663063656137653363356162396266383034376362 -33326131396162373835346338656164623162316538376332613835343962313264623934626265 -63643962333263323965333438333638353964313965313539333661306531663337326562363464 -33373732336131363434376132316461396635373862326431353935663566336565306630343735 -34613639663231303133623862346338316665323363343536306434343538653363313834343534 -36346566386330356163346463623564643762303839623833656336333862376166346538323764 -34373439343666343937623132383461383232616664633633666664393664316665663166363836 -32383265636263343164396239356163333532353330313330393164643333336338373431636666 -31333731646262633061616361323339343330336665653864313434383132613631666637333661 -35333931323861323535356634353739383936633762643138333533353432373866343861633437 -37663132653261636437643134306461623061383434346363613361643130653066393234363432 -34653561376632383031626439343535363734353763623833336663643630623636623964356631 -34373866313431383563376664646539316363363162353364636366623433666433633837646437 -65306336366637313437383739306138396562613565326235623666646264666461623061313465 -61633261333361396464366434386437356133353933373964363233653036653935326363623034 -32303565633833346265616562333432663061613237353734353361666135633763626133333261 -31363336383637333334343664316266653939663366393961323963383632363432363666343733 -64306631336561383339353836306334313830633565623065323462643830366136333632663064 -64343034656137373335316336353934643561373765656665643864376361663061346462316636 -33323662376430356265376330633132353961363564666362303934383761343131653231653534 -64303065353235393963363663373862626331396334646162633237663562396232336436636632 -63623134303633363261363766376339666666373138343264323036626633616530306163303566 -32636233306234303164613334633739396632396161656635633431383632363832346362366663 -62376239626433613935643737313736623230356366616137653165633634313531613364356666 -35623662666539323135623536396534656364393333623161376539386132313664323838343766 -35376265323535343132363136653138333665353738656431616432343562386661316163323861 -37373665386432343039303231643835306634626437633535316439323633326364663333366661 -64646136396436353065383965396365346466373766343934323362316136333730373139343066 -66633232343466326266363462323936363330383037663266346337646366313264313635393863 -63373164323166346638623931366234346538626639366338356664326333636264393662656131 -30353836313533363164613435353338303665353536643763636139393164313339623533393261 -64363165313866343136323935393236633939316364313238663639303963326232323436666433 -37363262383936326266396365396438393438386166616366323037393530326666343466323131 -63393030643563643064386631656533396337393461363761333235313663636637616230646130 -31336435646262306333326637653234333766653831666664353530386234383632393435393363 -38646432366331303663623736623733313834363234326461323566303731373438663363303536 -39366337356235336130666562363238336331346162653462646633646435666533613864656339 -33363464373462323364336339363334376136646562656561643631656265623138383561613461 -31653563383766343331353937343536636463356361623531663039366166613630653438626462 -33313534623232613762313863316332383661386630633463303363346465646261663166653066 -65363236306261633831336566393733343333626337303535663864373232376339336565343766 -36373034396463313538666532376563626362656634326437666333323735393736353062313461 -35306634366439363561613239303135313630626465353837313761343438323362386234316361 -31306332353137633064376536643338316235393635363438306430383134353639376232383231 -64643136663462393139373530373733626634313430643161643332303062303864343039663433 -61383765386231323039666133666363383137373663316236396634313635346664656332646639 -36343364343961343833623038343237646138323636343836616265303262333231333536643161 -33643930666137613738653332326330366436633063313431646237626639306638373936636664 -64633733366338313261393633656363346365303532656135663837653731666664663439336165 -62626235333865323666383734336539653965313930363639623333663737353839393338623634 -33633561323433393937623162316436623665373863356431653365613662373931613537306465 -39616465646136633761653031326639393365646130346362613462353963636133376436326431 -64616365623438333035336536343162323734366139666462616530393061303932313035613634 -63383436636234396631383161656139346530316139396166323533636333616537386164333230 -63666435333262653835326236373564326162356234303263353839316563366634636136353761 -61326230366134396438653163396539666630376263393561633362636532356636386265333932 -31363434393831373362343235376163663265623235653632626566343431613231633634626432 -39303236643431353533323231623262396638656337363631363562363361346436303366616537 -64343561366632663338643731623265613737663164626336303662636437323132323539353264 -62363934383562633635343338326162363934663836336337306265626364363339393636386438 -62366638393331336132646232313434306238353739336362326262633334643865626433653639 -31643337373235323835316661383761373334343434383431643864366438323931343538326362 -62343831396264363636313165313034623864373565303664636137363363386535373633346133 -62353863623237363335323438313730316233313436366332323563613466316339643161646164 -36666330306561326430643662643262383563663765623464613539646633393464636136353238 -38653239343536373435386139346537373338643563313166326139646333636263306563393337 -35383836663335626262376531373363353637376433363335366237393366633237613165613836 -39626135636265326537666135353138363531353532633530376635306532643663343638373333 -65336332326161303939386161653566333838366335346165633839666434653164366433306464 -66333462373765373162323336643737656532363933383332323238646466373537386465303134 -61613465383138323662393934393963613230653831303864363333646139313138303534373231 -37393639613632346438363235646634633564306632393339346335383365623730393034313038 -33623334633330626663346464336361396239316235393035363031653466613765623634386639 -3063 diff --git a/compose/playbooks/prep_ubuntu/README.md b/compose/playbooks/prep_ubuntu/README.md deleted file mode 100644 index b2e8544..0000000 --- a/compose/playbooks/prep_ubuntu/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Playbook information -====================================================================== -Плейбук по базовой подготовке операционной системы Ubuntu \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/ansible.cfg b/compose/playbooks/prep_ubuntu/ansible.cfg deleted file mode 100644 index 20d7065..0000000 --- a/compose/playbooks/prep_ubuntu/ansible.cfg +++ /dev/null @@ -1,4 +0,0 @@ -[defaults] -ansible_managed="Ansible managed" -host_key_checking=False -inventory=inventory/hosts diff --git a/compose/playbooks/prep_ubuntu/defaults/main.yml b/compose/playbooks/prep_ubuntu/defaults/main.yml deleted file mode 100644 index 11163dc..0000000 --- a/compose/playbooks/prep_ubuntu/defaults/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# defaults vars -# ansible_python_interpreter: "/usr/libexec/platform-python" -ansible_ssh_pipelining: "true" -ansible_user: "gem-admin" -ansible_ssh_transfer_method: "piped" -ansible_ssh_common_args: "-o StrictHostKeyChecking=no" -ansible_port: 22 - diff --git a/compose/playbooks/prep_ubuntu/handlers/main.yml b/compose/playbooks/prep_ubuntu/handlers/main.yml deleted file mode 100644 index c09dec7..0000000 --- a/compose/playbooks/prep_ubuntu/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# handlers file - - - diff --git a/compose/playbooks/prep_ubuntu/inventory/hosts b/compose/playbooks/prep_ubuntu/inventory/hosts deleted file mode 100644 index 7dffa3e..0000000 --- a/compose/playbooks/prep_ubuntu/inventory/hosts +++ /dev/null @@ -1,6 +0,0 @@ - -[prep-host] -cw-sya-ldap-001 ansible_host=10.130.0.16 -cw-sya-store-001 ansible_host=10.130.0.12 -cw-sya-iam-001 ansible_host=10.130.0.41 -cw-sya-reg-001 ansible_host=10.130.0.42 diff --git a/compose/playbooks/prep_ubuntu/main.yml b/compose/playbooks/prep_ubuntu/main.yml deleted file mode 100644 index 6c5502a..0000000 --- a/compose/playbooks/prep_ubuntu/main.yml +++ /dev/null @@ -1,22 +0,0 @@ ---- -# Плей по базовой подготовке сервера Linux (Ubuntu) -- name: Base prepate Linux server -# hosts: gt-demo-ldap - hosts: all - - gather_facts: true - become: true - vars_files: - - vars/base_conf.yml - - vars/secret.yml - - defaults/main.yml - pre_tasks: - - import_tasks: tasks/check_os_version.yml - roles: - - role: ubuntu_base_conf - when: ansible_distribution == "Ubuntu" - - role: ubuntu_install_docker - when: ansible_distribution == "Ubuntu" and docker_install == "yes" - post_tasks: - - import_tasks: tasks/reboot.yml - when: reboot == "yes" diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/README.md b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/README.md deleted file mode 100644 index e9cd313..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Роль для базовой настройки Ubuntu (Gemspace) \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/handlers/main.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/handlers/main.yml deleted file mode 100644 index c09dec7..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# handlers file - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/add_admin_user.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/add_admin_user.yml deleted file mode 100644 index 3e336f9..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/add_admin_user.yml +++ /dev/null @@ -1,46 +0,0 @@ ---- -# Добавление локального администратора -- name: Create local admin - block: - - name: Add local admin - user: - comment: "{{ item.comment }}" - createhome: true - name: "{{ item.name }}" - shell: /bin/bash - password_lock: true - force: true - loop: - - { name: 'gem-admin', comment: 'Gem local administrator' } - - - name: Add SSH keys - authorized_key: - user: "{{ item.user }}" - key: "{{ item.ssh_keys | join('\n') }}" # Combine keys into a single string - exclusive: "{{ item.exclusive }}" - no_log: true - loop: - - user: gem-admin - ssh_keys: - - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCGF42ADoauvpQeNW9I3dBvra4+/aK3zz0y8moBKngdwLbg/yu5dYlB7p4w2qp3QEFcHatyBHrjezKOEO5qM7HFx2Yp0dsR7j25ZhLc8Oy85eFJIKRu4DTJLahNgp+ybL+zjadRVGuc6xQtFemOtFTNzeMhwxvgLF312/pWnVlN3KIoIbOxOwnp0hr1yvKivDRTmDUI3bNvgCLSnap5fxcBZZklz+AzshIH9rY0W86VCewACRnPRcaE94O+4XjibqYi8vQPGUAu9NpRAPvuDbp1N5BgwhLcDx/XdQDcyhMdtLbHJ/I1WhaTLJjUDXVp3wcC4E7jpzXLBqkwPneplpVHT2Qk5AGp0R8Vb+q4TMLRbgm00036CcXY1Y/6VtAd1c3+QlXMSVMDEHBMBJ/NBM8cKkPhhBT8C1Tt660IFRErx8C48IqpGfHjHQZn8Xf0RWIyZ28c/x6mOhHJqqFAsPCsGsYcWVdAZBD53tWHGdjYcLGeI3UCYBFnnj4fEvQUUnBE3JB1NdkeVxYElbh7SktVTh3G3kNFAwWYgwn31Qh74jWpN11H8m5XM0I3R2TGzi7yuS8zKOKaEZwObSNVTfBbPHh6uVK3olIsiznAsI19jqrg+QQjStaNhHDcN/SZTxboy7q7Rnigl2cJOHM2rxm8NmuMuTHdPKlpbigvq7PFMQ== gem-admin" - - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC99En90Q7+VECxJLvVJY4TjasnFxC77YHpEebNeJg8iWapjvFxQ5ROOQX43x0kRKIZrnj3aQmpSvs+RuvWAxszm3BE4jiSftL49ImSMdmyoiGV5l1WcV1HJrmwz7jq5Eq8P/iMw3hVkhWU6b860kWpAhFiaW/g58BHJHVYn4M+pLDWk2NRkvHD4Ez1rtH28hXqrrm+TD/KhxLUrqQdytvYi5trzWQbahtpOtev0Dyi8oBdj6Jph/pB3mzZnWFGP2r106x4bKlvzKlLgNn9yPgygknDIEmD9dIEf2sJ/WbxqurR0x+Id3rpAiyvZWnY0O4CNcP9DIOrM0onz2he+hJTH+Kr8tiJBfpqoboSnyIdPfh2dMGGpGxPYoghVBg6ylkQ6ZUB8xUTTjfzCxxNF7TgMI064iXi+RWwepknLxw2vcgiSRi/nnv9NFJta+QOskK+05YXecWcnJVvREmYkGSzKEkuzwxEWwYIc2/JAngQxeenGaBAl9mDKdFPyZcQUy0= leonisa@Leonids-MacBook-Pro.local" - - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC9dzp4d6A9ZfVOXmHdiSW05qZbCGWBm8W0+KTlqEaRssliHHmrWSntiSvoeG2nQPJKBA5MAi476T/hmT2ym1oZxvRdyBODRw/UdXboHTXejXivtfhVT0ghcKOrllDbwzM/J9PT4k7rdefduIpv0wGHXzIVFqU1ZdjqDVqixuPq8dVSJJIOI5am6AJ6Of+U87FNC91GlGEezq8+Xo55BvUTKPjxnoHWUKVvvT6ci78i8I7Ux1Dx48lj90J61z9BIxvDZbWDDUY9gL2E0TSsYYDws5uX/+OSi3BIzJvMdzcn5LUTjIKX5FLYhdpagwqX2vaziI3S51RSpsqC6w76awKmcNbKfZzn8bXsvbK6pnwGKhFYBYZKui2piqq8rZ5MEHabHmEf1EdCtVW5Q0FNZzBKRFy6Sa5FwdzJPCmdoVOCtwXVZtKgUGHksxtWpMuuvO5QcXDoOqyCtTnk79S1fOYfQWbtTeKOpHiIONCgl6/CzZdoB8FXYRuyLtXmRTQy7rM= antropov.a.b-2023-09-25" - exclusive: true - - user: leonid.sokurov - ssh_keys: - - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC99En90Q7+VECxJLvVJY4TjasnFxC77YHpEebNeJg8iWapjvFxQ5ROOQX43x0kRKIZrnj3aQmpSvs+RuvWAxszm3BE4jiSftL49ImSMdmyoiGV5l1WcV1HJrmwz7jq5Eq8P/iMw3hVkhWU6b860kWpAhFiaW/g58BHJHVYn4M+pLDWk2NRkvHD4Ez1rtH28hXqrrm+TD/KhxLUrqQdytvYi5trzWQbahtpOtev0Dyi8oBdj6Jph/pB3mzZnWFGP2r106x4bKlvzKlLgNn9yPgygknDIEmD9dIEf2sJ/WbxqurR0x+Id3rpAiyvZWnY0O4CNcP9DIOrM0onz2he+hJTH+Kr8tiJBfpqoboSnyIdPfh2dMGGpGxPYoghVBg6ylkQ6ZUB8xUTTjfzCxxNF7TgMI064iXi+RWwepknLxw2vcgiSRi/nnv9NFJta+QOskK+05YXecWcnJVvREmYkGSzKEkuzwxEWwYIc2/JAngQxeenGaBAl9mDKdFPyZcQUy0= leonisa@Leonids-MacBook-Pro.local" - exclusive: true - - user: a.antropov - ssh_keys: - - "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC9dzp4d6A9ZfVOXmHdiSW05qZbCGWBm8W0+KTlqEaRssliHHmrWSntiSvoeG2nQPJKBA5MAi476T/hmT2ym1oZxvRdyBODRw/UdXboHTXejXivtfhVT0ghcKOrllDbwzM/J9PT4k7rdefduIpv0wGHXzIVFqU1ZdjqDVqixuPq8dVSJJIOI5am6AJ6Of+U87FNC91GlGEezq8+Xo55BvUTKPjxnoHWUKVvvT6ci78i8I7Ux1Dx48lj90J61z9BIxvDZbWDDUY9gL2E0TSsYYDws5uX/+OSi3BIzJvMdzcn5LUTjIKX5FLYhdpagwqX2vaziI3S51RSpsqC6w76awKmcNbKfZzn8bXsvbK6pnwGKhFYBYZKui2piqq8rZ5MEHabHmEf1EdCtVW5Q0FNZzBKRFy6Sa5FwdzJPCmdoVOCtwXVZtKgUGHksxtWpMuuvO5QcXDoOqyCtTnk79S1fOYfQWbtTeKOpHiIONCgl6/CzZdoB8FXYRuyLtXmRTQy7rM= antropov.a.b-2023-09-25" - exclusive: true - - - name: Sudo permissions - community.general.sudoers: - name: "{{ item }}-access" - user: "{{ item }}" - commands: ALL - nopassword: true - state: present - loop: - - "gem-admin" \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/apt_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/apt_config.yml deleted file mode 100644 index 1f221ae..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/apt_config.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# Настройка apt -- name: Set apt config no check-valid-until - template: - src: "etc/apt/apt.conf.d/10-no-check-valid-until.j2" - dest: "/etc/apt/apt.conf.d/10-no-check-valid-until.conf" - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/cert_ca_import.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/cert_ca_import.yml deleted file mode 100644 index 3288519..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/cert_ca_import.yml +++ /dev/null @@ -1,14 +0,0 @@ ---- -# Установка корневых сертифифкатов УЦ -- name: Install CA certs - block: - - name: Import CA certs - copy: - content: "{{ rootca_public_key }}" - dest: "/usr/local/share/ca-certificates/rootca_local.crt" - register: cert_updated - - - name: Update CA certs - shell: | - update-ca-certificates - when: cert_updated['changed'] diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/dnsmasq_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/dnsmasq_config.yml deleted file mode 100644 index a771715..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/dnsmasq_config.yml +++ /dev/null @@ -1,75 +0,0 @@ ---- -# Конфигурирование сервиса локального кэширования dns запросов dnsmasq -- name: Gather the package facts - package_facts: - manager: auto - -- name: Configure dnsmasq - block: - - name: Stop and disable systemd-resolved service - service: - name: systemd-resolved - state: stopped - enabled: false - - - name: Copy dnsmasq config - template: - src: "etc/dnsmasq.d/local-cache.j2" - dest: "/etc/dnsmasq.d/local-cache.conf" - owner: root - group: root - mode: '0755' - register: dns_updated - - - name: Copy dhcpclient config - template: - src: "etc/dhcp/dhclient.conf.j2" - dest: "/etc/dhcp/dhclient.conf" - owner: root - group: root - mode: '0644' - register: dhcp_updated - - - name: Started Dnsmasq - service: - name: dnsmasq - state: started - enabled: yes - - - name: Pause for 5 seconds to start Dnsmasq - ansible.builtin.pause: - seconds: 5 - - - name: Remove /etc/resolv.conf - shell: | - rm -f /etc/resolv.conf - - - name: Add base /etc/resolv.conf - copy: - dest: /etc/resolv.conf - content: | - nameserver 127.0.0.1 - - - name: Restarted Dnsmasq - service: - name: dnsmasq - state: restarted - loop: - - dnsmasq - when: dns_updated['changed'] - - # - name: Restarted Networking - # service: - # # name: networking - # name: systemd-networkd - # state: restarted - # when: dhcp_updated['changed'] - - - name: Rebooting system... - ansible.builtin.reboot: - reboot_timeout: 180 - when: dhcp_updated['changed'] and reboot == "yes" - when: - - '"dnsmasq" in ansible_facts.packages' - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/enable_services.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/enable_services.yml deleted file mode 100644 index 38db340..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/enable_services.yml +++ /dev/null @@ -1,16 +0,0 @@ -- name: "Enable various systemd-services" - systemd: - enabled: yes - name: "{{ item }}" - with_items: - - rsyslog - - cron.service - -- name: "Start various systemd-services" - systemd: - enabled: yes - name: "{{ item }}" - state: started - with_items: - - rsyslog - - cron.service diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/fstrim-timer_enable.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/fstrim-timer_enable.yml deleted file mode 100644 index ce18ece..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/fstrim-timer_enable.yml +++ /dev/null @@ -1,8 +0,0 @@ ---- -# Включение сервиса fstrim timer -- name: Enable fstrim.timer - ansible.builtin.systemd: - name: fstrim.timer - state: started - enabled: yes - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/history_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/history_config.yml deleted file mode 100644 index a153a79..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/history_config.yml +++ /dev/null @@ -1,4 +0,0 @@ -- name: Add date to history - lineinfile: - dest: /root/.bashrc - line: 'export HISTTIMEFORMAT="%F %T "' \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/hosts_file_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/hosts_file_config.yml deleted file mode 100644 index 760a291..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/hosts_file_config.yml +++ /dev/null @@ -1,14 +0,0 @@ ---- -# Базовый конфиг файла /etc/hosts -- name: Add base /etc/hosts config - copy: - dest: /etc/hosts - content: | - 127.0.0.1 localhost - {{ ansible_default_ipv4.address }} {{ ansible_hostname }}.{{ local_domain }} {{ ansible_hostname }} - - - - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/install-pkg.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/install-pkg.yml deleted file mode 100644 index 6fac107..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/install-pkg.yml +++ /dev/null @@ -1,34 +0,0 @@ ---- -# Установка дополнительных пакетов -- name: Update repo cache - command: apt update - -- name: Install additional packages - apt: - name: '{{ item }}' - state: present - update_cache: yes - loop: - - dstat - - sysstat - - tcpdump - - dnsutils - - vim - - wget - - curl - - chrony - - python3 - - python3-pip - - perl - - lsof - - net-tools - - traceroute - - python3-lxml - - rsyslog - - logrotate - - htop - - packagekit - # - python3-full - - dnsmasq - - unzip - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/journald_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/journald_config.yml deleted file mode 100644 index 0aa840b..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/journald_config.yml +++ /dev/null @@ -1,18 +0,0 @@ ---- -# Настройка конфигурации journald -- name: Configure journald - block: - - name: Add journald config - template: - src: "etc/systemd/journald.j2" - dest: "/etc/systemd/journald.conf" - register: journald_updated - - - name: Restart systemd-journald - systemd: - name: systemd-journald - state: restarted - when: journald_updated['changed'] - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/logrotate_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/logrotate_config.yml deleted file mode 100644 index fe76d36..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/logrotate_config.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# Настройка ротации логов logrotate -- name: Set logrotate config - template: - src: "etc/logrotate.j2" - dest: "/etc/logrotate.conf" - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/main.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/main.yml deleted file mode 100644 index e24f9bc..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/main.yml +++ /dev/null @@ -1,79 +0,0 @@ ---- -# Базовый конфиг файла /etc/hosts -- name: Add base /etc/hosts config - import_tasks: hosts_file_config.yml - -# Установка временной зоны -- name: Set timezone - import_tasks: timezone_config.yml - -# Настройка конфигурации ssh -- name: Configure ssh - import_tasks: ssh_conf.yml - -# # Добавление локального администратора -# - name: Create local admin -# import_tasks: add_admin_user.yml - -# Установка дополнительных пакетов -- name: Install additional packages - import_tasks: install-pkg.yml - -# Настройка синхронизации времени -- name: Time sync configure - import_tasks: time_sync_config.yml - -# Настройка dnsmasq -- name: Configure dnsmasq - import_tasks: dnsmasq_config.yml - -# Настройка swap -- name: Configure swap - import_tasks: swap_config.yml - -# Настройка конфигурации параметров ядра -- name: Configure kernel parameters - import_tasks: sysctl_config.yml - -# Включение сервиса fstrim timer -- name: Enable fstrim.timer service - import_tasks: fstrim-timer_enable.yml - -# Настройка apt -- name: Configure apt - import_tasks: apt_config.yml - -# Установка корневых сертифифкатов УЦ -- name: Install CA certs - import_tasks: cert_ca_import.yml - -# Настройка конфигурации journald -- name: Configure joutnald - import_tasks: journald_config.yml - -# Настройка конфигурации logrotate -- name: Configure logrotate - import_tasks: logrotate_config.yml - -# Настройка history -- name: History configure - import_tasks: history_config.yml - -# Включение сервисов -- name: Enable services - import_tasks: enable_services.yml - -# Установка пароля для root -- name: Set root password - import_tasks: set_root_pass.yml - -# Настройка ufw -- name: Configure ufw - import_tasks: ufw_conf.yml - when: configure_firewall == "yes" - -# Обновление пакетов -- name: Update packages - # ignore_errors: true - import_tasks: update_packages.yml - when: update_pkg == "yes" diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/profile_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/profile_config.yml deleted file mode 100644 index 99c861b..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/profile_config.yml +++ /dev/null @@ -1,19 +0,0 @@ ---- -# Настройка профиля пользователя -- name: Configure user profile - block: - - name: Change login.def - lineinfile: - path: "{{ item.path }}" - regexp: "{{ item.regexp }}" - line: "{{ item.line }}" - state: present - loop: - - { path: '/etc/login.defs', regexp: '^UID_MAX', line: 'UID_MAX 999999999' } - - { path: '/etc/login.defs', regexp: '^GID_MAX', line: 'GID_MAX 999999999' } - - - - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/set_root_pass.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/set_root_pass.yml deleted file mode 100644 index 2521630..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/set_root_pass.yml +++ /dev/null @@ -1,7 +0,0 @@ ---- -# Установка пароля для root -- name: Change password for root - ansible.builtin.user: - name: root - state: present - password: "{{ root_pass | password_hash('sha512') }}" \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/ssh_conf.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/ssh_conf.yml deleted file mode 100644 index 564ce5f..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/ssh_conf.yml +++ /dev/null @@ -1,22 +0,0 @@ ---- -# Настройка конфигурации ssh -- name: Configure ssh - block: - - name: Copy sshd_config (server config) - template: - src: "etc/ssh/sshd_config.j2" - dest: "/etc/ssh/sshd_config" - owner: root - group: root - mode: '0600' - register: sshd_updated - - - name: Restart sshd service - service: - name: ssh - state: restarted - when: sshd_updated['changed'] - - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/swap_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/swap_config.yml deleted file mode 100644 index 6aa9fe2..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/swap_config.yml +++ /dev/null @@ -1,26 +0,0 @@ ---- -# Настройка swap -- name: Check whether "/swapfile" exists - stat: - path: /swapfile - register: swap_check - -- name: Configure dnsmasq - block: - - name: Allocate the swap file - shell: fallocate -l {{ swap_size }} /swapfile - - - name: Change permission of the swap file - file: - path: /swapfile - mode: 600 - - - name: Create a swap area on the swap file - shell: mkswap /swapfile - - - name: Activate the swap file as a swap memory - shell: swapon /swapfile - - - name: Append configuration in /etc/fstab - shell: echo "\n/swapfile swap swap defaults 0 0\n" >> /etc/fstab - when: swap_check.stat.exists != true \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/sysctl_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/sysctl_config.yml deleted file mode 100644 index 52326b0..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/sysctl_config.yml +++ /dev/null @@ -1,19 +0,0 @@ ---- -# Настройка конфигурации параметров ядра -- name: Add sysctl parameters - ansible.posix.sysctl: - name: "{{ item.param }}" - value: "{{ item.value }}" - sysctl_set: true - reload: true - loop: - - { param: 'vm.swappiness', value: '10' } - - { param: 'net.ipv6.conf.all.disable_ipv6', value: '1' } - - { param: 'net.ipv6.conf.default.disable_ipv6', value: '1' } - - { param: 'net.ipv6.conf.lo.disable_ipv6', value: '1' } - - - - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/time_sync_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/time_sync_config.yml deleted file mode 100644 index 167e282..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/time_sync_config.yml +++ /dev/null @@ -1,24 +0,0 @@ ---- -# Настройка синхронизации времени -- name: Configure NTP - block: - - name: Install additional packages - apt: - name: chrony - state: present - update_cache: yes - - - name: Set chrony config - template: - src: "etc/chrony.j2" - dest: "/etc/chrony/chrony.conf" - register: ntp_updated - - - name: Enable and restart chronyd service - service: - name: chronyd - state: restarted - enabled: yes - when: ntp_updated['changed'] - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/timezone_config.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/timezone_config.yml deleted file mode 100644 index f6f3654..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/timezone_config.yml +++ /dev/null @@ -1,11 +0,0 @@ ---- -# Установка временной зоны -- name: Set timezone to Europe/Moscow - become: true - community.general.timezone: - name: Europe/Moscow - - - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/ufw_conf.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/ufw_conf.yml deleted file mode 100644 index b4ada10..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/ufw_conf.yml +++ /dev/null @@ -1,49 +0,0 @@ ---- -# Настройка ufw -- name: Configure ufw - block: - - name: Gather the package facts - package_facts: - manager: auto - - - name: Install additional packages - apt: - name: '{{ item }}' - state: present - update_cache: yes - loop: - - ufw - when: - - '"dnsmasq" in ansible_facts.packages' - - - name: Enable ufw service - systemd: - name: ufw.service - state: started - enabled: yes - - - name: Default allow outgoing traffic - community.general.ufw: - default: allow - direction: outgoing - - - name: Default deny incoming traffic - community.general.ufw: - default: deny - direction: incoming - - - name: Allow ssh traffic - community.general.ufw: - rule: allow - port: 22 - proto: tcp - - - name: Enable UFW - community.general.ufw: - state: enabled - policy: deny - - - - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/update_packages.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/update_packages.yml deleted file mode 100644 index 154e232..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/tasks/update_packages.yml +++ /dev/null @@ -1,20 +0,0 @@ ---- -# Обновление DEB пакетов - -- name: Update DEB Packeges - block: - - - name: Update repo cache - apt: - update_cache: yes - - - name: Upgrade OS - apt: - upgrade: dist - autoclean: yes - register: update_state - - - name: Clean old packages - apt: - autoclean: yes - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/apt/apt.conf.d/10-no-check-valid-until.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/apt/apt.conf.d/10-no-check-valid-until.j2 deleted file mode 100644 index 35996b0..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/apt/apt.conf.d/10-no-check-valid-until.j2 +++ /dev/null @@ -1 +0,0 @@ -Acquire::Check-Valid-Until false; \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/chrony.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/chrony.j2 deleted file mode 100644 index 89b8382..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/chrony.j2 +++ /dev/null @@ -1,39 +0,0 @@ -# Use public servers from the pool.ntp.org project. -# Please consider joining the pool (http://www.pool.ntp.org/join.html). -server ntp.msk-ix.ru iburst -server 0.ru.pool.ntp.org -server 1.ru.pool.ntp.org -server 2.ru.pool.ntp.org - -# Record the rate at which the system clock gains/losses time. -driftfile /var/lib/chrony/drift - -# Allow the system clock to be stepped in the first three updates -# if its offset is larger than 1 second. -makestep 1.0 3 - -# Enable kernel synchronization of the real-time clock (RTC). -rtcsync - -# Enable hardware timestamping on all interfaces that support it. -#hwtimestamp * - -# Increase the minimum number of selectable sources required to adjust -# the system clock. -#minsources 2 - -# Allow NTP client access from local network. -#allow 192.168.0.0/16 - -# Serve time even if not synchronized to a time source. -#local stratum 10 - -# Specify file containing keys for NTP authentication. -#keyfile /etc/chrony.keys - -# Specify directory for log files. -logdir /var/log/chrony - -# Select which information is logged. -#log measurements statistics tracking - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/dhcp/dhclient.conf.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/dhcp/dhclient.conf.j2 deleted file mode 100644 index 28ab41d..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/dhcp/dhclient.conf.j2 +++ /dev/null @@ -1,58 +0,0 @@ -# Configuration file for /sbin/dhclient. -# -# This is a sample configuration file for dhclient. See dhclient.conf's -# man page for more information about the syntax of this file -# and a more comprehensive list of the parameters understood by -# dhclient. -# -# Normally, if the DHCP server provides reasonable information and does -# not leave anything out (like the domain name, for example), then -# few changes must be made to this file, if any. -# - -option rfc3442-classless-static-routes code 121 = array of unsigned integer 8; - -send host-name = gethostname(); -request subnet-mask, broadcast-address, time-offset, routers, - domain-name, domain-name-servers, domain-search, host-name, - dhcp6.name-servers, dhcp6.domain-search, dhcp6.fqdn, dhcp6.sntp-servers, - netbios-name-servers, netbios-scope, interface-mtu, - rfc3442-classless-static-routes, ntp-servers; - -supersede domain-name "{{ local_domain }}"; -supersede domain-name-servers 127.0.0.1; -supersede domain-search "{{ local_domain }}"; -#send dhcp-client-identifier 1:0:a0:24:ab:fb:9c; -#send dhcp-lease-time 3600; -#supersede domain-name "fugue.com home.vix.com"; -#prepend domain-name-servers 127.0.0.1; -#require subnet-mask, domain-name-servers; -# "timeout" Value set by dhcp-all-interfaces -timeout 30; -#retry 60; -#reboot 10; -#select-timeout 5; -#initial-interval 2; -#script "/sbin/dhclient-script"; -#media "-link0 -link1 -link2", "link0 link1"; -#reject 192.33.137.209; - -#alias { -# interface "eth0"; -# fixed-address 192.5.5.213; -# option subnet-mask 255.255.255.255; -#} - -#lease { -# interface "eth0"; -# fixed-address 192.33.137.200; -# medium "link0 link1"; -# option host-name "andare.swiftmedia.com"; -# option subnet-mask 255.255.255.0; -# option broadcast-address 192.33.137.255; -# option routers 192.33.137.250; -# option domain-name-servers 127.0.0.1; -# renew 2 2000/1/12 00:00:01; -# rebind 2 2000/1/12 00:00:01; -# expire 2 2000/1/12 00:00:01; -#} \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/dnsmasq.d/local-cache.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/dnsmasq.d/local-cache.j2 deleted file mode 100644 index 0399bd6..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/dnsmasq.d/local-cache.j2 +++ /dev/null @@ -1,8 +0,0 @@ -bind-interfaces -listen-address=127.0.0.1 -cache-size=1000 -no-poll -clear-on-reload -no-resolv -server=/{{ local_domain }}/{{ dns_local_server }} -server={{ dns_cloud_server }} \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/logrotate.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/logrotate.j2 deleted file mode 100644 index 1a76b00..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/logrotate.j2 +++ /dev/null @@ -1,21 +0,0 @@ -# see "man logrotate" for details -# rotate log files daily -daily - -# keep 14 days worth of backlogs -rotate 14 - -# create new (empty) log files after rotating old ones -create - -# use date as a suffix of the rotated file -dateext - -# uncomment this if you want your log files compressed -compress - -# RPM packages drop log rotation information into this directory -include /etc/logrotate.d - -# system-specific logs may be also be configured here. - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/ssh/sshd_config.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/ssh/sshd_config.j2 deleted file mode 100644 index 06ced21..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/ssh/sshd_config.j2 +++ /dev/null @@ -1,140 +0,0 @@ -# SBT ssh config for SBEL - -# This sshd was compiled with PATH=/usr/local/bin:/usr/bin:/usr/local/sbin:/usr/sbin - -# The strategy used for options in the default sshd_config shipped with -# OpenSSH is to specify options with their default value where -# possible, but leave them commented. Uncommented options override the -# default value. - -# If you want to change the port on a SELinux system, you have to tell -# SELinux about this change. -# semanage port -a -t ssh_port_t -p tcp #PORTNUMBER -# -Protocol 2 -Port 22 -#AddressFamily any -#ListenAddress 0.0.0.0 -#ListenAddress :: - -HostKey /etc/ssh/ssh_host_rsa_key -HostKey /etc/ssh/ssh_host_ecdsa_key -HostKey /etc/ssh/ssh_host_ed25519_key - -# Ciphers and keying -#RekeyLimit default none -Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,chacha20-poly1305@openssh.com -KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256 -MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com - -# Logging -#SyslogFacility AUTH -SyslogFacility AUTHPRIV -#LogLevel INFO - -# Authentication: - -LoginGraceTime 3m -PermitRootLogin no -#StrictModes yes -MaxAuthTries 6 -#MaxSessions 10 - -PubkeyAuthentication yes - -# The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2 -# but this is overridden so installations will only check .ssh/authorized_keys -AuthorizedKeysFile .ssh/authorized_keys - -#AuthorizedPrincipalsFile none - -#AuthorizedKeysCommand none -#AuthorizedKeysCommandUser nobody - -# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts -HostbasedAuthentication no -# Change to yes if you don't trust ~/.ssh/known_hosts for -# HostbasedAuthentication -#IgnoreUserKnownHosts no -# Don't read the user's ~/.rhosts and ~/.shosts files -IgnoreRhosts yes - -# To disable tunneled clear text passwords, change to no here! -#PasswordAuthentication yes -PermitEmptyPasswords no -PasswordAuthentication no - -# Change to no to disable s/key passwords -#ChallengeResponseAuthentication yes -ChallengeResponseAuthentication no - -# Kerberos options -#KerberosAuthentication no -#KerberosOrLocalPasswd yes -#KerberosTicketCleanup yes -#KerberosGetAFSToken no -#KerberosUseKuserok yes - -# GSSAPI options -GSSAPIAuthentication yes -GSSAPICleanupCredentials no -#GSSAPIStrictAcceptorCheck yes -#GSSAPIKeyExchange no -#GSSAPIEnablek5users no - -# Set this to 'yes' to enable PAM authentication, account processing, -# and session processing. If this is enabled, PAM authentication will -# be allowed through the ChallengeResponseAuthentication and -# PasswordAuthentication. Depending on your PAM configuration, -# PAM authentication via ChallengeResponseAuthentication may bypass -# the setting of "PermitRootLogin without-password". -# If you just want the PAM account and session checks to run without -# PAM authentication, then enable this but set PasswordAuthentication -# and ChallengeResponseAuthentication to 'no'. -# WARNING: 'UsePAM no' is not supported in RHEL and may cause several -# problems. -UsePAM yes - -#AllowAgentForwarding yes -AllowTcpForwarding no -#GatewayPorts no -X11Forwarding yes -#X11DisplayOffset 10 -#X11UseLocalhost yes -#PermitTTY yes - -# It is recommended to use pam_motd in /etc/pam.d/sshd instead of PrintMotd, -# as it is more configurable and versatile than the built-in version. -PrintMotd no - -#PrintLastLog yes -#TCPKeepAlive yes -PermitUserEnvironment no -#Compression delayed -ClientAliveInterval 300 -ClientAliveCountMax 3 -#UseDNS no -#PidFile /var/run/sshd.pid -#MaxStartups 10:30:100 -#PermitTunnel no -#ChrootDirectory none -#VersionAddendum none - -# no default banner path -#Banner none - -# Accept locale-related environment variables -AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES -AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT -AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE -AcceptEnv XMODIFIERS - -# override default of no subsystems -Subsystem sftp /usr/libexec/openssh/sftp-server - -# Example of overriding settings on a per-user basis -#Match User anoncvs -# X11Forwarding no -# AllowTcpForwarding no -# PermitTTY no -# ForceCommand cvs server diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/systemd/journald.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/systemd/journald.j2 deleted file mode 100644 index 34ce79a..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_base_conf/templates/etc/systemd/journald.j2 +++ /dev/null @@ -1,29 +0,0 @@ -[Journal] -Storage=persistent -Compress=yes -#Seal=yes -#SplitMode=uid -#SyncIntervalSec=5m -#RateLimitIntervalSec=30s -#RateLimitBurst=10000 -SystemMaxUse=2G -#SystemKeepFree= -#SystemMaxFileSize= -#SystemMaxFiles=100 -#RuntimeMaxUse= -#RuntimeKeepFree= -#RuntimeMaxFileSize= -#RuntimeMaxFiles=100 -#MaxRetentionSec= -#MaxFileSec=1month -#ForwardToSyslog=no -#ForwardToKMsg=no -#ForwardToConsole=no -#ForwardToWall=yes -#TTYPath=/dev/console -#MaxLevelStore=debug -#MaxLevelSyslog=debug -#MaxLevelKMsg=notice -#MaxLevelConsole=info -#MaxLevelWall=emerg -#LineMax=48K diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/README.md b/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/README.md deleted file mode 100644 index ae41738..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка Docker-ce и Docker-compose \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/handlers/main.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/configure_docker.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/configure_docker.yml deleted file mode 100644 index 0aeb46c..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/configure_docker.yml +++ /dev/null @@ -1,29 +0,0 @@ ---- -# Настройка Docker -- name: Configure Docker - block: - - name: Make docker config - template: - src: daemon.json.j2 - dest: /etc/docker/daemon.json - mode: 0644 - register: docker_updated - - - name: Enable and start Docker service - service: - name: docker - state: started - enabled: yes - - - name: Restart Docker service - service: - name: docker - state: restarted - when: docker_updated['changed'] - - - name: Add users to a docker group - ansible.builtin.user: - name: "{{ item }}" - groups: docker - loop: "{{ docker_users_list }}" - # when: docker_users_list is defined \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/install_docker.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/install_docker.yml deleted file mode 100644 index 6cfefa7..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/install_docker.yml +++ /dev/null @@ -1,35 +0,0 @@ ---- -# Установка Docker -- name: "Check packages is installed" - package_facts: - manager: "auto" - -- name: "Install Docker" - block: - - name: "Add GPG key" - shell: | - install -m 0755 -d /etc/apt/keyrings - curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc - chmod a+r /etc/apt/keyrings/docker.asc - - - name: "Add the repository to Apt sources" - shell: | - echo \ - "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \ - $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \ - sudo tee /etc/apt/sources.list.d/docker.list > /dev/null - apt-get update - - - name: Install docker packages - apt: - name: '{{ item }}' - state: present - update_cache: yes - loop: - - docker-ce - - docker-ce-cli - - containerd.io - - docker-buildx-plugin - - docker-compose-plugin - - docker-compose - when: "'docker-ce' not in ansible_facts.packages" \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/main.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/main.yml deleted file mode 100644 index 08fc61c..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/tasks/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- - -# Установка Docker -- name: Install Docker - include_tasks: install_docker.yml - -# Настройка Docker -- name: Configure Docker - include_tasks: configure_docker.yml diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/templates/daemon.json.j2 b/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/templates/daemon.json.j2 deleted file mode 100644 index c8a6d5e..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/templates/daemon.json.j2 +++ /dev/null @@ -1,7 +0,0 @@ -{ - "log-driver": "json-file", - "log-opts": { - "max-size": "{{ docker_log_size }}", - "max-file": "{{ docker_log_files }}" - } -} \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/vars/main.yml b/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/vars/main.yml deleted file mode 100644 index 8831049..0000000 --- a/compose/playbooks/prep_ubuntu/roles/ubuntu_install_docker/vars/main.yml +++ /dev/null @@ -1,7 +0,0 @@ ---- -# vars file -docker_log_size: "100m" # Размер файла логов для Docker (в мегабайтах) -docker_log_files: "3" # Количество файлов логов для Docker -docker_users_list: # Пользователи которых необходлимо добавить в группу docker - - root - - gem-admin diff --git a/compose/playbooks/prep_ubuntu/tasks/check_os_version.yml b/compose/playbooks/prep_ubuntu/tasks/check_os_version.yml deleted file mode 100644 index 2909c8b..0000000 --- a/compose/playbooks/prep_ubuntu/tasks/check_os_version.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -# Проверка версии ОС -- name: Check OS version - block: - # - name: DEBUG OS version - # debug: - # msg: - # - "OS: {{ ansible_distribution }}" - # - "Version: {{ ansible_distribution_version }}" - # - "Major version: {{ ansible_distribution_major_version }}" - - - name: OS version not supported - fail: - msg: "Operating system {{ ansible_distribution }} ver. {{ ansible_distribution_major_version }} not supported" - when: ansible_distribution not in ['Ubuntu'] \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/tasks/reboot.yml b/compose/playbooks/prep_ubuntu/tasks/reboot.yml deleted file mode 100644 index 8700aef..0000000 --- a/compose/playbooks/prep_ubuntu/tasks/reboot.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# Перезагрузка системы -- name: Rebooting system... - ansible.builtin.reboot: - reboot_timeout: 360 - - - - diff --git a/compose/playbooks/prep_ubuntu/vars/base_conf.yml b/compose/playbooks/prep_ubuntu/vars/base_conf.yml deleted file mode 100644 index edbae76..0000000 --- a/compose/playbooks/prep_ubuntu/vars/base_conf.yml +++ /dev/null @@ -1,10 +0,0 @@ ---- -# Переменные конфигурации -swap_size: "2G" # Размер файла подкачки (по умолчанию 2G) -reboot: "yes" # Перезагрузка после подготовки - "yes" или "no" -update_pkg: "yes" # Обновление пакетов - "yes" или "no" -configure_firewall: "yes" # Настройка Firewall - "yes" или "no" -docker_install: "yes" # Установка Docker - "yes" или "no" -dns_local_server: "10.130.0.16" # DNS сервер в локальной инфраструктуре (Для внутренних запросов) -dns_cloud_server: "10.130.0.2" # DNS сервер облачного провайдера (Для внешних запросов) -local_domain: "stage.co-work.local" # Локальный домен в инстансе \ No newline at end of file diff --git a/compose/playbooks/prep_ubuntu/vars/secret.yml b/compose/playbooks/prep_ubuntu/vars/secret.yml deleted file mode 100644 index 5e0776d..0000000 --- a/compose/playbooks/prep_ubuntu/vars/secret.yml +++ /dev/null @@ -1,89 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -39396461316337366265626162636265633531613738633230653339346336323965643935363639 -3336363265366535316366373161626634626330623134330a373338313361633863346333306662 -31663962663630336139663866353065353162616332356163633436376562336261393237353065 -3838663034613834640a663363373838623935333733646139643633386133323634623537666164 -35356532656533663737613034636336636465373838333563633239366562376164383834336138 -37323066626166313432343137636563326533613132343133623134646264376131356462623965 -61306662356534623065386336646534373230333132336261626138356533316162363265353135 -34343263306166633161646531633338373132313939336162373965333163636263383230623762 -63313162633738623065326631666438386263393262623930313263306135326633363737373439 -65656534393637363661313132346166613666373462306430656137313262643231656362326532 -39303134633735396264363839643832373063666561613739613535396135353563396634376263 -31393936366337303237323661373061653434343064376438643066643962646264313832613664 -63303132373331646333633032383064663461616562663064393161666162306365653538666233 -39633361343034386639633335353261383433313432633332633665653462363836653332386565 -64316238623037393763643035366135353237343539633336663335393262666164356134373638 -33303263663231623836656539643539653835656533303430306264623436353737386135373534 -37616363386436633932353466626365373739343032653464636536663334613862313065653136 -35623863326634613566626265393565373531643939356433333230613135316130383930346261 -34303135383832353138623232653831346330633030346164646464366230343130336366616636 -39656534623061326464616639336139313963396631323632396437356438363564363036333331 -34343135623932326563393034643432663264656565623735666534346537646566393531393933 -61636362666237376161666333613333626438613766316635623765353333626639363262343532 -65303961616335316134353161663933623836333636303263623230373461653161653866333465 -30663935396534363164633739623130623736356266656163333838653262363935313961633730 -62363266353665383665643734313965333665313339366636313533336664613563366230333639 -35636233626237396130613263303664626136373562313663613337303765636433376434316532 -62386632376639353639386430663866356438383239663238633162306236363838626637633064 -61613232303465613166353066386462663063303133636363393938373736393939653636396666 -30343262623261616138313339646266363839313739323365346430653530333161313034623766 -35626465313037646363633366626166363330646338336563343537636132666365383336363132 -62373562656664666235643365353432333836386639333133613834313564356132326536663265 -30623865336666363162643435303530353731356137376536613366383062336637663634386434 -37353632366436383263653563646633353939623865343335653461373233316539663230373438 -32376431393463326362623134383330626364326136646234313639666261663437353262313336 -36636432386464316561333733643531663432396562633230313232333732656264353463343065 -64346634343462383765623939373438336630643534363163613438666232636635373461373335 -65663631643362316432666464646130636664643132393636643135373137323066343034663430 -30396334303966393461346537316664383839316635386261393032616234353435323933613631 -33303162306538656138356130646136373964346134643138363939663838653763396364333662 -61386639383633333135643239313136643065663434356365333231313436633634313062336462 -62303538626538646465373263316430376437386334653864363561623562363733636131356338 -35376164376530323131333632323335373861386639333135356266633433306334356631323166 -34333066323261613136616435336563363063353331663737626261336137333430323464623865 -38643435373764353864643134613361333130666363386366323362383432633630613334363439 -39303031376231303538633432353465653065303462666165623065643964613232303939393964 -39326165366237333337656335333165333837626665656361353138303531346366356466346366 -32656339333165663731346162653061366235373137316335613764333438366562386363376263 -63353030333539376561326537323236336337363862623464393039653465613064633165313363 -30636534376132653165383064636336653635396232663733333333316131383537326236386334 -37363865393534633739633961326133356638316131336433366636633334333231313066363961 -36616532643030326532373630333336313463363434326463636335303961373763313261633066 -38633631623437656162336661356131646232633337646437666533653965323266353030383232 -32373663353166306336383563333131623661306266646265316336316563306139613264663338 -30373436333838643331643631393265316330343133393139363730653536386161346430383930 -63383439656239393338313131363465303031623232616134636638306439336531363632633935 -64323137313136343730366639306637626136313366636238363264653035636462643130656236 -39363965346633646662623036626461373134643130333261646234663839646265663461623531 -62373933323636333936666434633739356664346139316664323765306461363334326635633135 -32626634303238333336396530613934663462383335356632363762623534633531396339363336 -65383732313562353632316161666639353932333234393163326232363639373731393261626132 -62646436306361373166306536363166346438336234383364373161366536613361386365666666 -38373837323638373434313633663966386138333531313433313033666564656433386530373062 -62383165626239373939643464633366336665616164626262383930663066363732333532623333 -32363735343461303038376339333037333535626364333563646163373130363739373330626264 -35383831323630316237346135393336636361313239393035353630313635333830396138313534 -37303635636332313834323335373538333237636262613966306432363536333135363938393864 -61663931343165383432333630366238653461373139653038383231366331653732356430623536 -33663065393732303166336435336361373533303264353464346130326234383664306662636532 -34393032373139396536396662646636396435396139623364386633336162656538336432353334 -36396439323639313936626636376431383837663036316661356537326466643539336562613032 -35373335326364313461326465333761356439663831363033613164333261386131346166356334 -36373038303033386238353833383562633166656132656665626165336566323164353864623930 -37326132343238353635396262653161386562363261373866303132383135353433373738366132 -61613631313866633161646463383938313562613038356431633665663365653134353938323061 -38653534636537616661396664393631326363313436373762393336326265666630303330653763 -33343361383961323064323232366262393039666663366639623330353061643134353837643232 -61373562383433373565626237386639333236616436373933396635383333373966393133373161 -65373237393437613735383838343062333631336530623337376637363534363135393433353033 -66343339626130343830306339623466653630656534336334323730333863653062363165393835 -31633739316639326637303137646466623864333238313766386331313934333461663937623633 -39376665343761336235313965623832663962383138613137393963366464396464373866613035 -62383238653030363333373439366239376338373838643062303634356131306463393632646133 -33613739393637353466636433376363636162373564616164643066633062666536303139623261 -30383534616161633365613130303438353430663339343430383135663161323363343533366636 -34313932613034633330396537346638326138643164306136643535663036306463306366376134 -35353631396564393136616437373530663730326134343332376663306663633963663330333839 -39666531613938306366323438316566396361623434353464643839326530626637303363346664 -34303862633664363435 diff --git a/compose/playbooks/s3_server/README.md b/compose/playbooks/s3_server/README.md deleted file mode 100644 index 83bcb5f..0000000 --- a/compose/playbooks/s3_server/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Playbook information -====================================================================== -Плейбук по устновке и настройке S3 хранилища Minio \ No newline at end of file diff --git a/compose/playbooks/s3_server/ansible.cfg b/compose/playbooks/s3_server/ansible.cfg deleted file mode 100644 index 20d7065..0000000 --- a/compose/playbooks/s3_server/ansible.cfg +++ /dev/null @@ -1,4 +0,0 @@ -[defaults] -ansible_managed="Ansible managed" -host_key_checking=False -inventory=inventory/hosts diff --git a/compose/playbooks/s3_server/defaults/main.yml b/compose/playbooks/s3_server/defaults/main.yml deleted file mode 100644 index 11163dc..0000000 --- a/compose/playbooks/s3_server/defaults/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -# defaults vars -# ansible_python_interpreter: "/usr/libexec/platform-python" -ansible_ssh_pipelining: "true" -ansible_user: "gem-admin" -ansible_ssh_transfer_method: "piped" -ansible_ssh_common_args: "-o StrictHostKeyChecking=no" -ansible_port: 22 - diff --git a/compose/playbooks/s3_server/handlers/main.yml b/compose/playbooks/s3_server/handlers/main.yml deleted file mode 100644 index c09dec7..0000000 --- a/compose/playbooks/s3_server/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -# handlers file - - - diff --git a/compose/playbooks/s3_server/inventory/hosts b/compose/playbooks/s3_server/inventory/hosts deleted file mode 100644 index 12f67c9..0000000 --- a/compose/playbooks/s3_server/inventory/hosts +++ /dev/null @@ -1,3 +0,0 @@ - -[s3-host] -cw-sya-store-001 ansible_host=10.130.0.12 \ No newline at end of file diff --git a/compose/playbooks/s3_server/main.yml b/compose/playbooks/s3_server/main.yml deleted file mode 100644 index a9dd889..0000000 --- a/compose/playbooks/s3_server/main.yml +++ /dev/null @@ -1,16 +0,0 @@ ---- -# Установка S3 хранилища Minio -- name: Install S3 Minio store - hosts: s3-host - gather_facts: true - become: true - vars_files: - - vars/base_conf.yml - - vars/secret.yml - - defaults/main.yml - pre_tasks: - - import_tasks: tasks/check_os_version.yml - roles: - - role: minio_install - when: ansible_distribution == "Ubuntu" - diff --git a/compose/playbooks/s3_server/roles/minio_install/README.md b/compose/playbooks/s3_server/roles/minio_install/README.md deleted file mode 100644 index eb9c2bd..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/README.md +++ /dev/null @@ -1,4 +0,0 @@ -====================================================================== -Role information -====================================================================== -Установка Minio \ No newline at end of file diff --git a/compose/playbooks/s3_server/roles/minio_install/handlers/main.yml b/compose/playbooks/s3_server/roles/minio_install/handlers/main.yml deleted file mode 100644 index 7479ceb..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/handlers/main.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -# handlers file - - diff --git a/compose/playbooks/s3_server/roles/minio_install/tasks/configure_minio.yml b/compose/playbooks/s3_server/roles/minio_install/tasks/configure_minio.yml deleted file mode 100644 index 2729aeb..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/tasks/configure_minio.yml +++ /dev/null @@ -1,191 +0,0 @@ ---- -# Настройка Minio -- name: "Check packages is installed" - package_facts: - manager: "auto" - -- name: Configure Minio - block: - - name: Add user minio-user - ansible.builtin.user: - name: minio-user - shell: /usr/sbin/nologin - password_lock: true - - - name: Creates store directory - ansible.builtin.file: - path: /s3/store - state: directory - owner: minio-user - group: minio-user - mode: '0775' - - - name: Directory permission - ansible.builtin.file: - path: /s3 - state: directory - mode: '0775' - - - name: Creates cert directory - ansible.builtin.file: - path: "{{ item }}" - state: directory - owner: minio-user - group: minio-user - loop: - - /opt/minio - - /opt/minio/certs - - /opt/minio/certs/CAs - - /opt/minio/certs/{{ minio_external_domain }} - - /opt/minio/certs/{{ minio_internal_domain }} - - /opt/minio/certs/{{ minio_external_domain }}/CAs - - /opt/minio/certs/{{ minio_internal_domain }}/CAs - - - name: Copy external RootCA certs - copy: - content: "{{ external_ssl_rootca }}" - dest: "/opt/minio/certs/{{ minio_external_domain }}/CAs/rootca.crt" - mode: 0644 - owner: minio-user - group: minio-user - register: ext_rootca_updated - - - name: Copy base external RootCA certs - copy: - content: "{{ external_ssl_rootca }}" - dest: "/opt/minio/certs/CAs/rootca.crt" - mode: 0644 - owner: minio-user - group: minio-user - register: ext_rootca_base_updated - - - name: Copy internal RootCA certs - copy: - content: "{{ internal_ssl_rootca }}" - dest: "/opt/minio/certs/{{ minio_internal_domain }}/CAs/rootca.crt" - mode: 0644 - owner: minio-user - group: minio-user - register: int_rootca_updated - - - name: Copy external cert - copy: - content: | - {{ external_ssl_crt }} - {{ external_ssl_rootca }} - dest: "/opt/minio/certs/{{ minio_external_domain }}/public.crt" - mode: 0644 - owner: minio-user - group: minio-user - register: ext_crt_updated - - - name: Copy external key - copy: - content: "{{ external_ssl_key }}" - dest: "/opt/minio/certs/{{ minio_external_domain }}/private.key" - mode: 0644 - owner: minio-user - group: minio-user - register: ext_key_updated - - - name: Copy base external cert - copy: - content: | - {{ external_ssl_crt }} - {{ external_ssl_rootca }} - dest: "/opt/minio/certs/public.crt" - mode: 0644 - owner: minio-user - group: minio-user - register: ext_crt_base_updated - - - name: Copy base external key - copy: - content: "{{ external_ssl_key }}" - dest: "/opt/minio/certs/private.key" - mode: 0644 - owner: minio-user - group: minio-user - register: ext_key_base_updated - - - name: Copy internal cert - copy: - content: | - {{ internal_ssl_crt }} - {{ internal_ssl_rootca }} - dest: "/opt/minio/certs/{{ minio_internal_domain }}/public.crt" - mode: 0644 - owner: minio-user - group: minio-user - register: int_crt_updated - - - name: Copy internal key - copy: - content: "{{ internal_ssl_key }}" - dest: "/opt/minio/certs/{{ minio_internal_domain }}/private.key" - mode: 0644 - owner: minio-user - group: minio-user - register: int_key_updated - - # - name: Set owner minio-user for /opt/minio/ - # shell: | - # chown -R minio-user:minio-user /opt/minio/ - - - name: Change minio config - template: - src: minio.j2 - dest: /etc/default/minio - mode: 0644 - owner: root - group: root - register: minio_updated - - - name: Enable and start Minio - service: - name: minio - state: started - enabled: yes - - - name: Restart Minio service - service: - name: minio - state: restarted - when: minio_updated['changed'] or - ext_rootca_updated['changed'] or - int_rootca_updated['changed'] or - ext_crt_updated['changed'] or - ext_key_updated['changed'] or - int_crt_updated['changed'] or - int_key_updated['changed'] or - ext_crt_base_updated['changed'] or - ext_key_base_updated['changed'] - -- name: Configure ufw - block: - - name: Allow minio TCP ports - community.general.ufw: - rule: allow - port: "{{ item }}" - proto: tcp - loop: - - "{{ minio_server_port }}" - - "{{ minio_console_port }}" - when: "'ufw' in ansible_facts.packages" - - -- name: Check server port - wait_for: - port: "{{ minio_server_port }}" - host: 127.0.0.1 - state: started - timeout: 5 - delay: 3 - -- name: Check console port - wait_for: - port: "{{ minio_console_port }}" - host: 127.0.0.1 - state: started - timeout: 5 - delay: 3 \ No newline at end of file diff --git a/compose/playbooks/s3_server/roles/minio_install/tasks/disk_layout.yml b/compose/playbooks/s3_server/roles/minio_install/tasks/disk_layout.yml deleted file mode 100644 index 2eaf29f..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/tasks/disk_layout.yml +++ /dev/null @@ -1,36 +0,0 @@ ---- -# Разметка диска -- name: Disk layout - block: - - name: Create directory - file: - path: "{{ disk_mountpoint }}" - state: directory - mode: 0775 - - - name: Create LVM volume group - community.general.lvg: - vg: "{{ disk_vg_name }}" - pvs: /dev/{{ disk_name }} - pvresize: true - state: present - register: vg_status - - - name: Create LVM logical volume - community.general.lvol: - vg: "{{ disk_vg_name }}" - lv: "{{ disk_lv_name }}" - size: 100%FREE - when: vg_status['changed'] - - - name: Create filesystem - community.general.filesystem: - fstype: "{{ disk_filesystem }}" - dev: /dev/mapper/data_vg-data - - - name: Mount up device - ansible.posix.mount: - path: "{{ disk_mountpoint }}" - src: "/dev/mapper/{{ disk_vg_name }}-{{ disk_lv_name }}" - fstype: "{{ disk_filesystem }}" - state: mounted diff --git a/compose/playbooks/s3_server/roles/minio_install/tasks/install_minio.yml b/compose/playbooks/s3_server/roles/minio_install/tasks/install_minio.yml deleted file mode 100644 index 24db5f1..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/tasks/install_minio.yml +++ /dev/null @@ -1,12 +0,0 @@ ---- -# Установка Minio -- name: "Check packages is installed" - package_facts: - manager: "auto" - -- name: Install packages - block: - - name: Install deb pkg - ansible.builtin.apt: - deb: "{{ minio_deb_url }}" - when: "'minio' not in ansible_facts.packages" \ No newline at end of file diff --git a/compose/playbooks/s3_server/roles/minio_install/tasks/main.yml b/compose/playbooks/s3_server/roles/minio_install/tasks/main.yml deleted file mode 100644 index d1619a2..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/tasks/main.yml +++ /dev/null @@ -1,13 +0,0 @@ ---- -# Разметка отдельного диска под s3 хранилище -- name: Disk layout for S3 store - include_tasks: disk_layout.yml - when: disk_layout == "yes" - -# Установка Minio -- name: Install Minio - include_tasks: install_minio.yml - -# Настройка Minio -- name: Configure Minio - include_tasks: configure_minio.yml diff --git a/compose/playbooks/s3_server/roles/minio_install/templates/minio.j2 b/compose/playbooks/s3_server/roles/minio_install/templates/minio.j2 deleted file mode 100644 index c3d5f15..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/templates/minio.j2 +++ /dev/null @@ -1,6 +0,0 @@ -MINIO_VOLUMES="{{ minio_path }}" -MINIO_OPTS="-C /etc/minio --address :{{ minio_server_port }} --console-address :{{ minio_console_port }} --certs-dir /opt/minio/certs/" -MINIO_ROOT_USER="{{ minio_root_user }}" -MINIO_ROOT_PASSWORD="{{ minio_root_pass }}" -#MINIO_DOMAIN="https://{{ minio_external_domain }}" -MINIO_SERVER_URL="https://{{ minio_external_domain }}:{{ minio_server_port }}" diff --git a/compose/playbooks/s3_server/roles/minio_install/vars/main.yml b/compose/playbooks/s3_server/roles/minio_install/vars/main.yml deleted file mode 100644 index fa2fb4c..0000000 --- a/compose/playbooks/s3_server/roles/minio_install/vars/main.yml +++ /dev/null @@ -1,2 +0,0 @@ ---- -# vars file diff --git a/compose/playbooks/s3_server/tasks/check_os_version.yml b/compose/playbooks/s3_server/tasks/check_os_version.yml deleted file mode 100644 index 2909c8b..0000000 --- a/compose/playbooks/s3_server/tasks/check_os_version.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -# Проверка версии ОС -- name: Check OS version - block: - # - name: DEBUG OS version - # debug: - # msg: - # - "OS: {{ ansible_distribution }}" - # - "Version: {{ ansible_distribution_version }}" - # - "Major version: {{ ansible_distribution_major_version }}" - - - name: OS version not supported - fail: - msg: "Operating system {{ ansible_distribution }} ver. {{ ansible_distribution_major_version }} not supported" - when: ansible_distribution not in ['Ubuntu'] \ No newline at end of file diff --git a/compose/playbooks/s3_server/vars/base_conf.yml b/compose/playbooks/s3_server/vars/base_conf.yml deleted file mode 100644 index b453532..0000000 --- a/compose/playbooks/s3_server/vars/base_conf.yml +++ /dev/null @@ -1,17 +0,0 @@ ---- -# Переменные конфигурации -# Разментка диска для хранилища S3 -disk_layout: "yes" # Разметка отдельного диска под хранилище S3 -disk_name: "vdb" # Имя дискового устройства для разметки -disk_filesystem: "ext4" # Файловая система -disk_mountpoint: "/s3" # Точка монтирования диска -disk_vg_name: "data_vg" # LVM Volume Group name -disk_lv_name: "data" # LVM Logical Volume name - -# Minio -minio_deb_url: "https://dl.min.io/server/minio/release/linux-amd64/minio.deb" # Ссылка на deb пакет minio (Проверить перед выполнением наличие пакета) -minio_path: "/s3/store" # Путь для размещения хранилища minio -minio_external_domain: "stage-store.co-work.ru" -minio_internal_domain: "store.stage.co-work.local" -minio_server_port: "9000" -minio_console_port: "8443" \ No newline at end of file diff --git a/compose/playbooks/s3_server/vars/secret.yml b/compose/playbooks/s3_server/vars/secret.yml deleted file mode 100644 index 4de70e8..0000000 --- a/compose/playbooks/s3_server/vars/secret.yml +++ /dev/null @@ -1,608 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -65343037653138646434613537663731323031343366663561323464663663383561313536643263 -3766373432313761636239383962356334353739313036340a653430326666393061646465656266 -65313332323261653132323739363430623936353831663665343861363439353939666533396633 -3632636233306565610a303963636466303135393537643830366138656664343630303563613838 -38626236643538653261373332353436393739363930613762663063613164346536633133663339 -33646330343466613762316139353561626564323063633666363932623464616337323234343764 -39663832373636656634346631316636316530663836363262613264663234323132353462616434 -61366433383430386165343232353030396433363836346138313734626264643132363034623236 -65663231643832663565653061343738343931316166396566356566336462316638383662336662 -39373162616136636532633261626664336161333033313666343532393638356532343531633637 -63643962316430326233633239616661316438323236623536626466616333306134383638623131 -62373264613131323135316661373931343862646239626636343965383566303334393137313363 -63353638366537333630616461663464343131343765633465643735326166376439316238653937 -35396531643739643835666632373339626264633331336135613161356333353663316437663138 -33623730393764333738626530376434353733663836383261636230363336303533366531313336 -32303564633030656466313838393733313064343532353632656138353863303938646234383834 -36623238623465323830613333666130366561623735626630643035633934333530366234393935 -30363762656362386239363636383334636437336134373238336436323139656232653736393236 -32616661623336333138363835623437323866336235656563613536656536363531353039643536 -36343137363135623533323733663961643537353161373666333063316430623031353364626131 -32633564303032363063373962623631666437363562343837633561346265333539333434346239 -62396265306664343562653063383633366130653738363764653539336562646639613937633633 -35656430313365373230353663633461646435346139393736333833343164646631663131663130 -38336332636434363437336139363361303063313333393038353766363833653263616162313139 -39633166356535396437393861343337316163613761626662316164303863386630346439323134 -61393963633834336532343236366537366431653038366639313536653937383264336161393039 -35376366633530383734346264623639396137323437333662633438623366303830306336396434 -63323935346231323533656132626166323039623334646365356664303738383538393038636639 -38373439656231323831353665666265363862393131343737393333383162303739396336336632 -32323232663633363032383039633831656537616635623637663536653832303365383333333131 -66396630316166386262383361643833366635643033313933303933656162633632373330363730 -31393165336434333133313931326362373139376235666666373935303264653534396264346239 -37303265663935353566616534643635306563663632613032643132653234333536653163623865 -38313232323165323731333432343432373933313062626163346265393864326662326632326363 -30356561323334393039323132313465633133306437656665633563303838663639316162313239 -66613438343332646262343335666635653836613232643464353234383462306131393764376164 -33393563663234636338313233643962383139626437303762613762616234303833653764633861 -62613365383231633637646539363066383536393737303638396238383134306664623230613961 -61653364666231616431333330646436383838636439323336366634326134396435653338643135 -65393635316139613838386532343762336230616366643137343834633638653539623736383432 -34643437643834363531313666373131373934346434643431653666363933656662373161383066 -35373965353031336266396135343065383632653466653231616164303339313332366164326136 -39313638363163653666326137366139653435383963386134616135356263336530383463336161 -31613564393637323736313263303162386434373235313165376633616332323230343664323437 -61373934623961653266623761373135623239393236363466656330323663383631323435666161 -33663632363962303436313761373230346538393766393561386662366161613366353235633037 -32363063633062396338633139616437323338623633366134323236633334613333376665386232 -64343466316561633162353036323536393938613238356431323435316566383861333161613763 -38663964373265353765396138646361336134613365313038383931626533383361333966333966 -36396633643339633936353363326464346432393138343264386365653236366332366664376430 -66636461313037353764316362666433616137353939633634343465666630613436306366313361 -66313263623566323436376361383466323233323030393062333764643362356339383432663665 -64353030643362626163363965333132623765393663306539363930353863313061306335326633 -35656564353562386634666261643036626632633162346165363463353235346635633736356539 -32393039646432613835303065656433343333396264316431653534613936613362306239646538 -37373738373931326531653439333364663033663631383631653738383666386631343031663162 -33633166653765383235636464346164333835366332343835373061373638663438623635343465 -66656261663566643962313832316335656237346566353565333239656230356538393632636238 -64333265663361326333666162373566326132393162643065363334626264393666303664326439 -31616239633566383762363339303530303239613562333161333665343038326365363735343233 -30306263306265343264643437373662363463626465336437636463393731623738643263303331 -66353333666462616537363962323932646430616133336134373564636262643337633565316430 -64396339633032663963633562646531623266623765643234373266313263306134323236643238 -32333231646639323833343436656536616233623161353433653339643639633933653432346365 -32336538333262636137666437653664633063333332356538333265323135333538633837316134 -65316537333062626535643966663366636437366263633330353365353762353563376465396266 -37396566363031623334613765646633643665323239613533373432303834666661333761353835 -62316132323861323563653961386664333536613364663031666135353331336663306665353336 -33613335633939656430663833363336626531326434393036353763653264373665623466333232 -37356566303230656430346637363731623434626561376438323038353137333566333338656436 -66386463386437626636373734323035353231346163613565366436633063633262613636333965 -34393131363633643738636633306563643566396435383261363331656135313638663739353662 -37623362633030653832303035326438356436353539633032353936613263306166636538656538 -34363832356136643330363232343430373765303135316261646564633439366636303337336466 -64336432363566306334373534353464386132313266396437613963383231626637623335333736 -39356431646362646362346132653839353238356464653730363961356464353939373637333839 -35336333643036353166613139646663303733323737643631646364326533313265316331646535 -33616566316234356463336365373962633835326363313966393666393463343861393832626239 -32323235346361633261623831343234396161666239346132636239633239613363376262613732 -30636131323636356234356366633330633033343461316633376562313233653034343630323964 -34646161306630353938396633393730366162393965356462306333636438633863616161303132 -66383064336363313636343431613063643437396131323064373666643466393539653135663666 -31373734333436323831386531333033366135383165306332326431336231306132653633306663 -35313631646438613962623737386663653434656338333739316132396534366434313465353230 -65663737323831613961636531653032386261313763383130663034633463663163383162353936 -34353638376562366563656138666664626265316433396466313331373565373836333266353463 -37323733653862613766363462376130303061383064656164306438653566336630353663616234 -33666531356538343661333438666432383361343264396462316431303163333761626433333035 -63396661343334323233353163323738353365373765646139366564633664633536626433306236 -66646363396463663565386633653366366230363561333137303032643630316561356338663032 -32333461643265663532346266636335666233343834633337323461396538313862353131366639 -37386331316463303034636265396661396435373031393033666466363833653363663862333463 -37363933626530386536626135343165356562303866366438303336393737353933636666643733 -61326262643433663063623735373330303037316262393035323834333464336239323731613763 -39306530366531633566376463643932633166383434396466633630373738333135323764373332 -61356239336439353266363162383732623162353066366439643166393432663138653261353137 -63623832383237646563636630373864393334386138623335666633653765323162383737326163 -65343235313061633137333634616431326635353232636463353061316465613539393939343435 -33393134663665346164386537376162313836396633646261396234373539643939623239333532 -36303633306139386161333931366232616535316338636266346365323935343064303931373833 -33396363303435663731323436653034353764316639333630643038336431313265363435356434 -63646365336530306138663038376535306237363330303132643833663439323934343266303765 -62666235613461383862323132383565346363396635396137313131653365666437326531303632 -39343133643238393463393530636266656439343764383438666536646237346261316662623064 -38646635386165386536613464656134306464663230393966663230376336383833656464666136 -66666537343963383162613166323139346232366535386636653533353963353639326530393538 -30626565633162623765373939373865303131386434343763643138396438363863346434616436 -63303134653930346463373038666438613764396561633333316639333431656631363531303665 -30323863636563363532343232386234626666356437336463363365333137353334366164383761 -66303634306165353239356132386236313563376465383233653234636639366134663534643832 -31613364376236363434623962613038393330336336613062636336383430396230613432333731 -66393030396261343863663739393661353334636266396131336461323738363161333532363665 -35623833353435653132313630316537646533616639303234633235613166353531376164663832 -38633864613765356166613930363762376339303430653339333335333230323330393165333635 -63643066616165633134396636613965653462393735383236383238653761643562343065376235 -66373831343536313639666237613761656539653266643034353936306634356134656638616633 -66363238353066346534396334343930333065393632333739653266616632333431656134613430 -33393763313933623738636439616435363935613534383537646330373166356363623262623631 -61343034343262343165633564383839306231313237656135656235306266336139383231393733 -37333331353661636265313430366334336137356631346339376164646232626332616162623432 -63633434656339303232336564613536643133393632646235306362363739363133346161323037 -64363134396339343239663139616362363265633235356238303639383261313336613763333338 -37633362643166636130633563613564303730616264306237356561666435666532616535363637 -35336162313831306261333034333863633937323130393936353237626664626261663262303861 -65663436633634376561623235353965333139393236643761326338356334393562373663373139 -36336566393962343830356139323763616434323565663462333061386465313136343664653161 -33663665633464663861616561353563363362623338623734346165646662633539663330373330 -34613835623835626633646434643561303131313966376631366162393962353137303537356666 -37613162316465346537656437373238306335323364333738396132366634633430643132663939 -63633164613064663730323934386661613937656338636166623036386230386332333536343833 -31663730623238643033356238653430663064373231313239643461336639333232353836336332 -32393965343831623362393261373334643334303165353661373062626230353362636537376136 -61333832646566373439643836316532653366636661613335646134363032633233313539303337 -38663233306463333135623738626365666466623630646132623962343966323939343532326139 -34306134613661333962323230393232623765356166656531633061353565373961643363326165 -33653338313561353562653133373632386461303361663338373939616262646337393665393238 -34653333366461623961373566616537356363396636653964396631353335383262653834373832 -62333035346330373534346635323437613536666161396161313437616637363765353666623661 -37366562653535366434376331383963343566386461653831666333326331363236346537626232 -65333964623064613734393162396237326464313062393331646463616661653436306465386562 -32303034633264636136323739343666646662363434623265663561303032303235616362326237 -39643633316531653261393931366630313835356638656132393934396365643139613639336235 -33633166633439336164353861633738383734636338343531663530663439333734656637356366 -64626439313437666665626166396131373161633932336139633938383934653431633833376532 -33666433363162303865356437626635613666646237333364623466666638653265383266303464 -31386530353466363138316261616132393261373364666236346366663932326464373932623831 -62623163313264303731326335313034393537336665663439303230383531336364383566383534 -38393262353663333762333861396662613136343333643431346465306466323433326561636636 -39343137323863616365383431353434613032396461626632386263636365663135626166646265 -37343936323364656133636137373035393136346361343965373364346462356436346330356266 -32343330346236376539396561396536346633396132373730333636633962656664393339646431 -32353634373632343339633836653363343535663564653432303935316664613563643033393461 -30656166663238646662643865336636623463393763613934636531383430663163323932313435 -38346261396161623836373262323136316433336263613733396331303864313430336339623131 -66613635323234373631323365663837323561313230633335643933366633653465653665306162 -66613034303937386565613164343937396261306431643064623161336335383731613465323730 -32613030303761373137636138343036623366333165336165363930656162323634313334333664 -66663361353936646135663738373931643032633866363134383631383833633935323139383235 -62666234333661343335623163333436333533313562383133626566366362393830333463663134 -38396134356335643837313238316138373634613436343338336635616562303662643932373034 -30666162353061323436633162666136316333656139343236393937663839643339356131376132 -65623538373930656339393365666139396633653061346537396265373961666632363866353332 -32376366663433616336613962333331313935323061333837303930616137326530623666643438 -66336539616434623161326630626361643938303635623838383639306261396339646432616132 -35323131663431343266383730313139633531363863653838343763383335313135386130626463 -63376565353330333332616538656135616162346232636330323161393465303832316334356139 -65623566663839633734623937393639386631356131623462346136643636643732323964623133 -30613465653136353036613238663134383338376366633365396565386438343030633435333337 -64656237326137353561323834303131623366393164353831303637663434356661623832346262 -32373664386265386363373136623934643131333230343131376538363765393732376232363134 -65353864653338396339666139346662366565313064343231663131393066393336316338343339 -39313333336566643762376233373963363666363865303861366533633230643266666436373962 -31303166323739613566386532343962663863356666646539346434353663393336326632313666 -37376133646661663865316233316335306439643637343438393966396236373066333563633761 -37386164393830353164636565343835613332366163343664376435653135313630386130343362 -34663339633933303635623734393233353537373035316564643165643430393531633739663266 -64343638363234376634616330386161313932376361653665373564343431386464383134383839 -61396636346633306335366232306165643533636364623130343933666633323031353135356266 -64666263306432353738336634643536633430366663626436636336653661623165383730623937 -38313530613231623465343636663434613831376637313064313439356664663565326136383363 -30653962316139373564633363623666363738666334623338363934363062653636636463366334 -65306232396262623166643463343733306633383034306564333762633332636264316632343537 -30366233643662303263396231636561356266656230633835373164353133633136376132386537 -65366638666166303437353730343136333230616531613938623433303865626437643930636466 -37393161353135333339346433373531633561373534376666343535366232363066613830646234 -39376432653930303231323766313937343066363535336165313862613334636665623938663962 -30373638376130653832653134373030646538376330643363666666333862656136663963363439 -63336631346239353139633334396666616463313331643835303762636661363035353563373765 -62383437633735306465346463643963343333653565623838366132636335393765366337663961 -34393564646636623036353933386462343939383537636337636365663161626130353732316538 -37316261636134623734666235333934613566623065393061303637633265633633653464336534 -61316630313961653731356535303531383634656439356338323234643937313530626365336364 -36643530326139316239636431323938636430303361326563336433326439663965666461656239 -63343031343262613562356432663930386231366139346461363363613936636163653533333539 -63363836373638633639313835666630646632323231633934636231323061663066633663616530 -38356437323763363632653831393331633731313732336237633438633734313663356535346665 -65616431353735343135393434646163313866653634623530363961613932303930306564323937 -63386134656636656232613562613839353966356236383032333433623430623434333536376664 -38646331303865656230373639626237393232653838613562313239613966666631613736376434 -39313761326638636236663931623431373363363639323535306137373732616233616436633965 -37653765646638316366623135356232333836346132376161383437333963383939633030336264 -66343933336238663061356138333839376630613861396638623237663063313635653766323631 -61336364383163363637323566343934656438623766393839336665316638353237396239373834 -36316634323634366362326232663438633230646563303464356336326534363361643035663061 -62353032376334396266343164356266643538666665326632336531616563653262316536336662 -31373533333138643964323632363964303532336536323035633465633466643262313035306135 -34323662303461356361313362376339363730643432306263346132616231363563666566373338 -36363836383730656363613237323764636532643539313465636430343263656136353862626637 -64656264633366306133396333313331363266303534393361383532653733663138306137313333 -34633535393364306639636430373035663832643762653738616464646365653032663331333766 -66343939323732363064386130303930633533386335303862386238646565633433383535653430 -31393463353162643063386464383630663764393037316266646431356363383466373761363736 -65383532306133613131633737393437373463353066323730666266616233303433643465653832 -38313865303766663931653365306261306137626264613936326539323361363237626630363064 -39613234333937333730376661373435623961363339613834383230653664333834633162396533 -66646664383537653366613431363236366232663764656534643264343763356461333063653636 -30666230363431636535343764633834376537386531616165353061653864303938663039636138 -32373961303639376262323962346337313134346264326233346533306630636631333431353431 -38646535303732356533383133336461303631313133323762386238393236663533303366343564 -31326265653531633630343832373561663164333565303735613765613137303932643535363531 -36326261643366663162663637613061393062336162303939373565323237336465313664333362 -65616233336439373764333463366235663834383766343038366666316131383764393066373738 -35343133373430653335633032353561386136323831616637386334313838323462343339663362 -35636438303935633231636439666438383561626330623366383262623131613166623534333364 -35313235666631306431353130663966613836366466393066303066376337623731646330313139 -64616132333735373631656532643231356232333962366366316631633562636361396139633765 -34336161383632323036303239383161653233323863323532313561373931633332396164393437 -39343664303961376663646239383936636566653463616131613364643035323433343334646562 -39316261633536323836643966366166363832383364316431353239616566396333653935343062 -36353363646165383062616463623235353030383163343236323565383665383238633466636566 -38353335663066376431616162333332303165616663623332353939613435623438613931393730 -34623161336166393230663231383864336161373234343666313765356536663937643239353363 -37643430313664323263636165396362616139393430643136393338653233393433383133616639 -31346463633634643462623736613431623334636134366432613862376433333031363836633436 -32616239616333653031653337383832336139626564643165393639393634643062623665346336 -31356636656134666335316139366664303536396136393631643330643536326539623736333633 -63316438633466393434393264316163626634323763353033613236386138363564386133393966 -33376531326337333865386633666361366437393139616433393566636632383039383362366239 -35326438633166353465366264643765336137656632356561363531363239303665333736366435 -31653239373864663465326230613032323530363836356363333565393637306664383337643938 -36623064363933383535366364386265643465386539323934613435346164626130333061653138 -31303265623766643739646565303564626333643363643764343433313439316638383335373232 -36316531353364303932323532653265613962663037353530386634373733363039326464393137 -63313561646364393133613464343135326537366639623332343232343066613864393465663362 -63393030336534393834643738336561636564636531393964663534643539333132646638613461 -62383865633266373762656538623365633631383965623365343037303639323631393138636462 -63326234666335333838656331383138393465323037366330356431623037356166366430393563 -36376465333061653164616161383836343333626239623537323564353262646333303637386531 -39643862666265663637666263323630623039313932306561326631336332666237653566636337 -32313238656336303132333938363062363238376565646531323161353631396238363434643866 -33633432303163343662323435356137616333646365636234303561393565326664623837353861 -66626461333163396233343837653432376431643730663931636335323336656162393030653631 -35623530313035666438326438323038373938323537316665383537333262633932353937373831 -63303336376661336338373333656566353232336239666664353237356362313233613366656565 -37303662306361346231306430353937376133633164363034613232663930313132303461383430 -61333963366433623164393836613637366136663033363734613130653761636232666332343230 -31363062316531396131303431636563303966613863333566616439366431613933363338613661 -62396665346534666465376635613866386231333235636630343366313561353635363862376361 -37643933336234313332313334333466633439306230636634643866303463303530326237636263 -38643864313533666564633832306663316465343730353064306536613232363466323235346137 -34663334326335633138316130376566653137363866313633386136383763303133363431643761 -36303739313064323036326561656466663738366236373132336661633134346534633631353561 -35366133343962343036326535346137636437353635323733343634653437636531373930653266 -66616163633231343430646437326438323038613939623132363137396462383862353365393136 -61613834313561653637343936323931363735356133366366396535363261343262316638663336 -39623036333033323861353961366631646361303837623032383635613531393834313036366631 -66633166613637646366303861613966656231616139316434613761626133666161393832326166 -37303663356530376137353834353933373264613330663231663261623865303065306233666664 -37313361393863313363626238313534633136366265666561393138316566356365303065303331 -38336135303334653061663837646231643332633535623062386139656562346537316661346161 -32376465353266316537613136636233363566313762396265656538373433653933313232663338 -66633130383836343930303865623262656338306361363234386137353038303536663763336139 -34333938643137656535666561656536393332386531323736313261376634316361393130313933 -38393666303563383238666666323061633139623065663661353738313564613065303838386137 -39353564653733666333616461353338303432353133333366363539666561656632643939646430 -38356664303164303862323861623362356362616231333761363238623764616463353539633439 -31386165316164636534626338396536653138346165613338623530393634623862333564353166 -31353531663265326531336165653536333730306666303465376136343966333565386235366365 -62333637333933316533623264363736306134643135343130663465343133653161346134336439 -61383262346663383332356537356165316661613964386666643835633566396231386538303465 -34646231303035653238303832353632656566353137643834346364643333346537613439353161 -38646332643733313139376238333230613865376231383762646237633733373763643766666261 -31396438333339323862333439326138373061363837623937356162363166323064613161386432 -33396663393230333537393138646262663065343865663463313333616235386338646165653765 -34316334353366613865663531616662663431303063316333326331313531666461613664363831 -66393164316365336165373639623938396338383565656531636332393266616230633465646534 -30623831353462396334616635626639303035346561613662326432303565636435373332396462 -64633830376534636533326633303462613637306339383832653065313235613937363266333932 -39633937333937326335356464383037366436396437646566343564633033633438666366306564 -65616236616331363030353366383136326434313434383163663565396135666334306130373438 -32663833383139353362663737383361386138656136623334363636326430666532326331353065 -31323832353066613866326237616339396332663633366263303037356138623635353134643063 -66303531633936353631373061626135653963336634643064316366313664313265316638373631 -30393136373436316535666136623732313830623563393232313166646538313734303962666566 -32313231376231633933373863313832386561623865646565316661373761666163303363333130 -34383861326364373838396137356239346133336662386631356565633737636363346664316437 -61663930643262646337303231393231626133636363356336313762356337623265366564303865 -33633231313566366332303732613235626465346133636538386164643237613661633963326539 -66366633393764393337323264343132316531373962326662303861333839653764656233613238 -62643231616564333665303364633430386265396664626264616236623166373162393538373763 -65653964383161326133323966303133666131323965316432616465666161653638653736366334 -61363839643066386166626561393438396466393233643432356463343163653830303532633262 -64646432653462653033656434656165643663656261336665643534363131616461376361616663 -32396261343835363863636661646632636536663032343434366538306537643862656361386661 -32653666376464383063626564353265363261663132326666326461336363666436383166313335 -62333963633163366238313061383231356161383463343935313565656662653233316434393230 -36613737656533323961316233366338663465313530656532383032666231376130623935656138 -38386261333763323733663134613030306532613234306265623230393839666137356135323764 -37366265653539303063363562633932303663343264393130613063313463386634626236626539 -31616163386538666661323638653861323365646165623832323736656535343133316664616237 -33363236303137323663346532386362343839636235363533333533393464363964386261383237 -31346662613133616137373966396533353962656237383733663364336663373831653165643530 -62643361663433666363663564316537663930323432333537363361666639373861343864323234 -36333162663066613230363735356432663865633536373165643339376464356532366664363737 -63383032643738363037636464623062383438636666626664366164633639653734323539626233 -36613335323036383738653734393634333238613463303161336663303835623936353561663463 -62343335613465393636323661323765313039376533663832373832396239666530366464323238 -66656133643839383662643865633061663034383233636435393464323139646630643933633438 -34333732393465636264646539343039643234393134343135393364663435373661633438396437 -35653463616333653236663066306661393336386262376235366436343630393033353536356365 -63663466386330633865626139383236646563373636373064653063393966626638626663383830 -36313933356333393165356565316335323533613863626235646631396663343138373739336265 -30633765623734303232363266306139343431646635373061663564373331663738646631313961 -65303866353730383934343531373364343738343934363761656334373966623435333631616333 -64336335303437326266623639396231376630663330663162366562663234366562326134353835 -34356638313862386635633038663535313930333834363164386331666136613562656234396231 -30643663646665313165393862393364313665646566306438393031306332626335643632306139 -36353962303736653563393561646136373166636233346536343037643665396538623764663164 -66363434306462353930646364663536363530356664383832396263646462636533313834363262 -32646538626138656164323934373736303738666534386562613861656361303433373938313065 -36356336316266636133393935383365623436663662643436663962373733623131353533376430 -65336535386331633162396139383238346466336332333334326663336563616333626462323865 -62393036316536666330613330663335353537646334613239373635353664396438376630363363 -38383536323238333431663761623063353839666331323439303935633066303839616534313962 -36616539363435626238626138643530333561373364613434353838356437633539303133396664 -32346534346466643031326664396662333236363137383335383138316461616461623339613066 -65613066613566303963316562356137643435306636353430336266343364376439346435303637 -34623431613039333161363030613937353931386532653065373637373762363233313666393166 -64326531303233373931343164326536343965656561646334623337326266316630646634386631 -39343331616262346335613839633239626431376462306266613762653737313535383364616339 -62333233353430313731333536356234646233666136613435343838613431616562303263396134 -30353133356337653934613539336534323135623938356130313933666236303236613366393635 -62343432353834313431343766663937306462613434333239663561636532343964313936306431 -30316335633733633265343030373866366366303964306530663764346235623962613764643662 -37386666643135363932393162663734316164306239313461653534653964366431316235653932 -35386433646230623663643931663330653632636639313235313035383863636162316465626133 -64306634623233373262326335383832643665666363643534653637343364313164636637363035 -63383730376333356438633432396438333366663962393762313130326265363462373832626434 -30363537323239353335343038363861643236656330623635323737313361333631666535656461 -38323433303461306463373238356664313230663131303464353463333433633738633066353864 -34613562316532646530383964396364323238623436366136313733663364306365656130393162 -61326631656334343062366634316235396433306139646333613437393961616234323666336663 -62343939343136396665323539306630643435313239626232386538633163393137633132643864 -63653265613665313666306438303636356664616130363131323166363134353764343461663961 -39353435306239636330653165306139336266353334633665653630363733393065633731613737 -34343137313131366461323532656664373936313737363932663439626534656266346631653536 -39396563656137623763633439623565623838313432316561613935373530323338316465386330 -65653338633631373466313436356331663131656231663932303366383536653166383434353835 -63396266616161323635666235343234333234373762393464376236386438623737356365336363 -31623033336265383466626363356162643163643339663035633439303266393537363164303630 -38396130376537333235633163396164643665623637653362373039373961343064323164633935 -38653435306266336562623737383561643439376266663836613634326438393930623065633033 -37313836383361613838633038343961316463386235376535666135353833346534323435643864 -62363166353165356461333731616162393536346434326137353537343039363166393133346637 -38363962643136383131336339363735663834626337366231346538316434376333303361386666 -34333237306166613832373163343561353537336637643662343232313635623734346466383061 -61386132613039306638356538333339353462643832376362643462383038326239363039323231 -66313362636333383034656631336536373237663231636636346366396666386238333762316531 -66396366303337383134313266336265646539646264636633353131663862353562393166383363 -64373238306161373765653037326236633538386465653064366437613235356132313061373264 -66343335646564353833303738666331376431663139616363653361383834376562353334383333 -31623837333139666236363064653661323166353031373930666232363535306635313431663763 -66343939636537376232353435626666643534393733303165333936636439653536303636383863 -31666439613937373639333935656138653163343134653139393837373664373638663036396361 -35386131346264363932386532313261646332623264343336346364306262623563643234383763 -65623830663132333264306466373932666432366564343866376439656366323939643235646639 -31356564313236633938356336663733666630383830336230313034313662333938626164313037 -32633461653761646238666232663662373464613064396133353064316665313264616335376663 -31353730623261643561653263623931643837373836633633636137393263363230306664333233 -64643832396466623535356638613538393063356133646535343463383131303830653261636161 -64616366306235333937383663363862373538343064656332323762616331326661376534393032 -62363934663235333833613237613237636663663937363564323864313563356133343432393038 -66633361326361373266666464373138353234333962306266643533356531623566616331316263 -33643462353337623332633532333762663237636264373233303235346330616437366432643364 -38393834653430306661353933636166653061303465626666363632616364616462373430316662 -65653966326334656565316630366663396164613938383666353936383039646262366230396131 -66303836336564323563396533656663306333323036323165373432633364356333323438666162 -65616431633230333535346162326362393265333361313239336438356435653462326164353763 -33326636633161656464303138636565373639363139343734656435653431626438356464623633 -63376261623930613165333732383061336132353665653036666464386135313337353866636530 -36663963313436353332613430313236643765353239343365306538663036306362333037653839 -38666539353439383639393966656636373234303866663536613363333139616138656266626333 -33313837373934366664303263613131353438613134386639353537353331636534353336396536 -66383031326531333332383435353261663439323937663433393763656435383737356434353631 -62306137373365356136396138646139636366393633616334316638653538653764363534623339 -61303033616238643633613064313330663961303737646333616533346364353362656238653264 -63333461313761656566653438666438393131663266623666326662396265316636653937393737 -38313936623031666561646663373431373366336330653635376530643034343265623962613530 -37353437656132653435323266383832313766666439376463653761343130313835633765373961 -61306431323631626631643832363161303131336439653965386331386165366534333762646335 -63383731663763356235663266376166326565363834323864313236333535393862323838646462 -30393635623839373839646166653062373432373533666137623763666239643032393063383561 -66663332666565386362306665303439373230356430366334346165663262613135613432633339 -38383562373432623362333039626164393863333963623133383734643931393033336663373463 -66323838393061646630646362366162313064656264636163373665666466333232353562386430 -35656236363532663431333964343130396432306231646434623164313965323431333238643934 -37623638356566393434313136343936353535343836333564643361313336306632663531333533 -34326636323234626136313839633763366438633330656232643563656232383731316330633666 -66306233343136383663396136616538393031386636653531656632383363633431373066356463 -32333638313963656661343736643537343665383137393430343237613130323566633339393931 -61336530366363376532613164303432343062396136623734303037633733656431346661623032 -34346363643037366265663264363833373337616664373661386561626336623736303831363265 -30393062666163386233656565376131613866666139636465343730623865323062646435626132 -61626336303463366630386363313031636230623132613830613265393037303831316464626338 -63643235666334613862303230373835373066303138363866333235646164343637636362346662 -37613731666330393931323732613139383065396266653936363233353832343431363736666433 -66303863633762643266356336633434663538306337383539636637306239623966663830636236 -32666461623531386562383731313533336234386165366634366361656563303932333739373761 -66626136626435626466373761323830343764333165393033353066333136373334313034373137 -39393066393165613231313561326639346435666434383537346230333234663162616131666366 -32333863626433383966663336373665326135353064643534623861356638346536613531373531 -38353438386262373461323363313766356635326261383036346261306361356537366563306237 -38653063613063323239386665623861303432396335643065623937396166336236623230396362 -36666137323132323265333165316464626333343832363033393831386563626233623638336531 -36626535653966343763313665623764363032613663303766633664643035653036363761323637 -31393662343237343161336361646330643630363834613632393834616436663263346538343864 -61636438626265653134343634323237323861336239613231636331653933323237633161643830 -62323062353266666638313163383965623665353962646335623266313237653862386539363230 -66323536343433653531366561636330346134303762393037313736643664623165393035653039 -36303331616438373631663032613238316362653333623061323330386364643737636565633632 -65303337363636386166333539656431393533303364663236393063653963313862303261656566 -31386339386263616336336630623863386639303765653039373963613533616334643566626339 -33666536306232393462396134336665306331383664333461363532366633613930333163313432 -64393938356535313735343239643665376665323634306134373162323366323435393164343162 -30623034613330616432356663666234383061326238636563653264626464343735313165333533 -35333230386361383137626465656536323833653464346335356439633334653964343063646332 -66316566383731313838643136313263343438313735613438616637303934396631306464396431 -39353661343339343361353838636636313531326162373335313835383934613838313139663862 -39323136366639643961373830386139323963666634646633613735626535396330613261636361 -36616234613339373133353165316366643164343264613433656461386465333031386638616166 -37623336326631343762623362666635326231636430626532383338656137353037653032303433 -35386230336633343064623764633332393061316436306433636262376233643638386131333466 -30653233353837303833616431336362666337373138653833666231306530636638323232656464 -33363939336263366239333334643439323939373832353830306661623633656239386338363536 -32373831396431333461663266393062663764363666306464393130306630303431306434616435 -38613762646662656339633436626463636264303932383161623837626264636438363636393136 -35313939303161343033353135373261343731666139303035646165653933383061303430656136 -34363665376161353063363237366130306461376230326231643466636130313436323533666264 -32363538633862343437646366653765376530373739386536336366653766383334323934333438 -63343561333133343336636438353031333535623031613037376236386438336433303234396563 -37326465643137306435353561343662626631616666626130323230306636303562306232373636 -61646163383137663135366563653030353264313437373531326665343935393061366333643731 -33383139623438666532613833396638303763663264373835323835636666303938323563643363 -32646237306139616462303962656363336165623365303638383762353731393235613661383565 -37396437363933376536356534636464353437326134616236653431356566323132333635653136 -30306333646137363633343938373062363764623533633966653762333930393435356635613766 -63393931303133336532363438373766656130316233363139336538353533366537653536613830 -36396435663962393933303564613064353561306362653537616266306566306661306130633730 -61346439663466616264386161323563326239656236613739323562366531313538613265633935 -33303565333063366235666130336537616563303631363331323236326531363138653762356338 -31396564323833356332633536386238383166333562353534306564646462323136633461383330 -63633364643766636266613833643162363132393634376236316233326464646161366630313537 -30333639356363373233646463386138653964326339346233656261373762656332646430316532 -30323336356662326537373030666264663238373039663666363363646430383937323133393235 -64656365396533306230666335343635333736636539313461306433343266633034303531666161 -32333239326662643939366639353563366434303763663061643233343436613739656564323364 -62306337633135623162326564306639363437653338326161643532353634306130643432363864 -34383763656233646136633832393937393033343137353539363235333938316362393436366236 -65316534306337303164373664393036663330383433623335376665653930316364643136303538 -39373337333037373862313165363762353466653733666436613733663035363633653737323036 -62623965356663373365633434663139363930663135613864666331386163656538633934303437 -31303039346439656538343439303137623939626466656430376531653764323137373130366539 -34343564353964623238386439313661613535663762306639656636316637626336383734613538 -65373464333564623762333562636130636133383766653634363736313432373239663661663166 -65333735613837396232303034656531656430333363666633333361303761356632323666313133 -38626134333466646566363139633031616130313530313535373032313362343037643139633531 -31633764346337353061663166353463386462373531333030633435326137336563383034616362 -38313533633563653734346632366162646431626234323161336533666231303764343034633464 -35623738326432316562306539666637636434306263363238616538333532626132386634326334 -63633262636238383462653035393830313963333337623661326335343231313136316331626666 -64613632643832643830316561383665343061643132306333653963653938303961383134306330 -61623834316337356265626630313233376234316466653964333637346136663361666638383130 -61373935313265656638643037386532636666393766663364616239613366343463656331613335 -61343064383532303937313538653566636135376137656534626334336630303534356335363234 -36373165353139383639303363323832393838666137396437333831306637656638623236353433 -37323834613336663064656531363532396564326537316263613239653430666638326435653939 -64303135356236316237633038336565343935316230376431353064383466626634396431643030 -65393737643966626333326563323431333832363133363461636433323931613736313633383137 -65356263363339386666323833346666663163613066303133373566616364656637323937666633 -36343631393166373539663937363765303261326236336530306566346561366434376666663432 -35653432666362393937346434303238363463386530356363353062626265656233636661646533 -61323433303366646530353763343536346132383232356234643466393635663038653765616664 -31373130373637646462373234313162633763313161383639393062326430356232353136653731 -62343734376131323730643266393137326661363938633763303435313334653562613764613230 -64353762616130643131663038336532356366653463363437343562356638363137313165613161 -31303363373965386134363133656161663632356536323366353839356234373937656430663637 -38313532636438333433346235623064623366303130373064316631363764646437316538393963 -65306661333039633034323462346164623737623666663162613734366437303661396236643137 -34356532303834343262653332653963313537663666646332316433643230303166346233313039 -65393763323262656436643865643361633735616365623931653761653363306161323739316434 -62393835326138383433376162363836613636313033353636623834336339333637366137666137 -62363963666265646636616530326138313433656339383433333662386666663362306430343764 -65363163336663363230656233666262663536313031666130323837653930626536623637353530 -30333433393763656635376466346465623961343562333431626362623965643066666362383534 -62393262613939366464343833326435663131366436313634376233373262396132313235396166 -39356564386131363735356536616338653937623333303564626331613238646262656562313664 -32646361656333636230313236643662623730643037333463343531663238313339353631323965 -37313135343130633361306333616663643836386666366238303032393331613930303064643839 -61303737353461346337393039383263643038383137353063323730653532343532313964353464 -64316466363131393662653830383139306339396534616637653536336639303162303766343962 -65333166376133643066643231353466333631656432386162643637666232633431366333353835 -37623734343931623538393961383334353539623439336132633865363364316230643962653632 -38666633303334336639653466316362363263636564633631356533373531326431353930666565 -63346165623463623739373165353231626430346161393239353063663065653565326434643363 -63396537316563636330323065356364396530313036653433303662393838646439333132396462 -38313531356163333032636133333964373436613136333035626439313032653239366437373962 -39363738303265616166623463353363313936616337336639666139663862343161633136366663 -36656230613938333334636665393937636238613236353436336263636163643632313464613836 -65663231353136626161653732363663326364393333666365623361623535633037316637383836 -32636534303932343263653936313966343035623965663133613261353466626434366138333766 -65303062333631313263373333616663373336626636333364363165353666356334643533343738 -32343766376533363838373461363732373139393434346461316630623564613238323636633532 -61323430636136383236326331336161623361313437353463633634353134353565373837653161 -33303638653336623636383431316362376262626361323737623132323933343233306533353536 -36616436643433326139393261613937333231663864333336363335313735376239313164613236 -35306338376565333434323936366439356363383039313362646634323161626662626532393432 -32636231316661336332313633313762623833346338383361353263343563353731346666346633 -30373065626139653335646131336233393437653465396164623531356330346636386465353636 -63323838336537316231336136656638363935346662383863343062306339333036306262383963 -35646166643430646666393166316561366338623264303164626462353862336362613934333533 -66303663353161373764353238343730333635396361343566303939613538306361613438656666 -39376162373336373835383230306261336232613363393638666531363331396332356238313533 -31663065636433353333623763646538303538316231333738396662396338616636336432323966 -31666432653162643736663063333261383034393230616631346662663662346332306562613966 -66653565356566353665366333373134663163623661303262376631633761353437663662326663 -34623535373561633066336162323739393533646138633734313933316264656434663137393130 -36366264663066323635663835643934306536643439326166323461303039633362653537346565 -33633732376235656638323230636437666131636431663932363662376139666532313532363837 -64633338663634666234373636383535346534323039326630383438633263663237653935653563 -33393565383938353939326265386636366532323565353339383032336561353662323161306161 -32313765396463646630616234653738613437326439343935373330316661636561356663613463 -35626537643534383532323931666136393466306239623965356137646231653131323335653032 -61373436313662613634393336366663636431313338636530323061383336313331333132373138 -33643464343837663161643337633837316261636533326662613939626137326161663537353632 -64653264363534333837613432336266353130653861323461363165633765353162306561356238 -64373533633763356434643761623664623164663864393539613432326262393566656262343039 -33666232376464303063623039346233303563356635643233373163326233633161616164323366 -65646532633365363033633163316533383365373733633661386431613261336636323730326662 -61383565316538616237343361373033626233656436646530303535303233623434646333626439 -39353765653666623731656230363062613839376134333034626139643661316266393437323432 -30643964393563323135643332633263306162643632326132373531333931343535353866613265 -32613138653037643664306438623038316535343263393766313166363439386631343031303339 -66303232656234643131306135336335353633616634656539333533343266643333363739303535 -34313362626566363138643565303466303631306431336665633862666137363166653761616335 -30656232393165366362336439383637373064306663366435643665383466396265336231363836 -39383164613630663130383131666334656632663161326261386461336239393037306261613434 -64323839663830313635343866613961333566313364373433393164663137323863356238613237 -63383162323561646334313133386530343163663261373435613064633230653862393066353630 -37343932333332636262376163323961396261313963356333623335613665323232306531363263 -38386532656535613639656462383733303135616562643663663330633063663831393366343962 -65316233636431653835393332383633653534646536623162663039663731633932313136323432 -39653566633965353330306533626236323234316331666462353532653864333034363830373531 -66663135316461393531666465613535336131366234386234663466303438616566626461376636 -35353066663634303930303732383363643761313732363365386137613832623935393961366331 -33393561653139346264366364373831316365366330636339663239303061626333653237373036 -31623762623064313133316363343963373062313435363331333437313037656462323938336566 -30616165353335396536343365313730663430616137626561363835386533353163383930626562 -39666264663537343733323232643661656462396330356334303733306334656366343538653665 -63613637333733663039616566363435663933316531663361626562613638323839353436353766 -35376338633863363937346438356438303031633564353439666265323333336332323631386332 -62303832633863323231646335613562393534656135333430343665336333393332626235326466 -35393037396232353762313134313830663534333661626630613334613064396534626461363038 -33343962343139303761323365333461663061636465323733333536373531613331386539613231 -33663766626238383663373366373934343033646363653431393732303566353461303438633739 -35646261323663626165353866346261663762393862356439623639613534616334393537356362 -61626339333430363965636237646236366134373538363234626632373937376231396333646231 -61616138663337396562663163646531363439666232333563653430393034666161313336663635 -62303866633261656330656264613335346663393236376664333638626161616536336436313339 -36353837613737383562616133356434366134663831386130623464383762353837623638343837 -35643736323330623535326335623330663530356236373230633166383938653538303238366665 -61376264353066643566636430386236383266653531633766613033333261366266666461383137 -30336363363066653662333561333239613231303134636665653533343137336431303037333134 -37313436653333613333366661623832363466333265303465333131366265656265383233303539 -35666234363462373565636239333833313236376330656161336533633038366431666136373934 -66663238313363356662613137333734336663623531623862656335366561303232343262303261 -30323164646439633134383762303065396235613364316534383339333930623561633330626562 -36363036396263653561643139663537626563346339653963396364383463656337386564346434 -63303032303532306432633239643861383333323435666131316664323965623632643032653630 -34386132383131363934613561366135343836666566633162643730643238323336633964366131 -65373264343033666433363037313533373834333363393132343836626335333630613663626536 -63313762306364323333643939393536333639616261303361666334646535636633666333363736 -66626365386533646366633464383139396161336238393761643461363563623035396663333534 -35626335326438353032643437363435633264363336333433386137663531303032623238313362 -65633666323161323064333161626234393639363531623030313738653066333539623866326531 -63386639313464653634653134363231313136373231303331653561336461653230613364333231 -65303230626364323131663930353439376531303239306561353139653738643030643936666264 -61333766326639633766656532363263393838366335643430313865313333333436373061303166 -61333435653834346631646630613130326534323563323537353236376561623935613937386634 -31373436663138643336666263326433326237353837613262646265643436336437653934333638 -37336463306336636335363639636232393863326530326565346261346566373534646262613461 -66383936656236653833336433336639323238623937663030613232666361646565656632343335 -62323237653937633931383936646461373835623961303734666462343563323838613933376538 -64353638383635373535616236623937656561306638633662343163326437346566316534356666 -61383166643136666261613831353136353930616331623665306466393561633161306162636532 -63623761616131356136316365313836393864343234623165616164633861613532646237316136 -62353639396438386532373762363665633065336136623233633266633333346566376666653839 -396237623662663837363564366362346166 diff --git a/compose/roles/infra-common/tasks/main.yml b/compose/roles/infra-common/tasks/main.yml deleted file mode 100755 index fdc43c8..0000000 --- a/compose/roles/infra-common/tasks/main.yml +++ /dev/null @@ -1,17 +0,0 @@ ---- -- name: Common for ubuntu - block: - - name: Update repos - become: true - apt: - update_cache: yes - - name: Install packages - become: true - ansible.builtin.apt: - pkg: - - mc -# - name: Set a hostname -# become: true -# ansible.builtin.hostname: -# name: "{{ host_name }}.{{ domain_name }}" -# \ No newline at end of file diff --git a/compose/roles/infra-container-registry/defaults/main.yml b/compose/roles/infra-container-registry/defaults/main.yml deleted file mode 100644 index dfc543d..0000000 --- a/compose/roles/infra-container-registry/defaults/main.yml +++ /dev/null @@ -1,5 +0,0 @@ -docker_compose_version: "latest" -registry_data_dir: "/opt/registry/data" -host_ssl_cert_dir: "/opt/registry/ssl" -container_ssl_cert_dir: /certs -docker_default_dir: "/opt/docker/registry" diff --git a/compose/roles/infra-container-registry/handlers/main.yml b/compose/roles/infra-container-registry/handlers/main.yml deleted file mode 100644 index 730d5b0..0000000 --- a/compose/roles/infra-container-registry/handlers/main.yml +++ /dev/null @@ -1,2 +0,0 @@ -- name: Restart registry - command: docker-compose -f /opt/registry/docker-compose.yml restart \ No newline at end of file diff --git a/compose/roles/infra-container-registry/tasks/configure.yml b/compose/roles/infra-container-registry/tasks/configure.yml deleted file mode 100644 index 9f66e19..0000000 --- a/compose/roles/infra-container-registry/tasks/configure.yml +++ /dev/null @@ -1,18 +0,0 @@ -# tasks/configure.yml -- name: Create necessary directories - file: - path: "{{ item }}" - state: directory - loop: - - "{{ registry_data_dir }}" - - "{{ host_ssl_cert_dir }}" - - "{{ docker_default_dir }}" - -- name: Copy SSL certificates - copy: - src: "{{ inventory_dir }}/host_vars/{{ inventory_hostname }}/files/ssl/{{ item }}" - dest: "{{ host_ssl_cert_dir }}/{{ item }}" - loop: - - docker.crt - - docker.key - ignore_errors: yes \ No newline at end of file diff --git a/compose/roles/infra-container-registry/tasks/deploy.yml b/compose/roles/infra-container-registry/tasks/deploy.yml deleted file mode 100644 index 04b0f57..0000000 --- a/compose/roles/infra-container-registry/tasks/deploy.yml +++ /dev/null @@ -1,8 +0,0 @@ -# tasks/deploy.yml -- name: Copy docker-compose template - template: - src: docker-compose.yml.j2 - dest: /opt/docker/registry/docker-compose.yml - -- name: Start registry using Docker Compose - command: docker-compose -f /opt/docker/registry/docker-compose.yml up -d diff --git a/compose/roles/infra-container-registry/tasks/install.yml b/compose/roles/infra-container-registry/tasks/install.yml deleted file mode 100644 index 0813f3c..0000000 --- a/compose/roles/infra-container-registry/tasks/install.yml +++ /dev/null @@ -1,5 +0,0 @@ -- name: Install required packages - apt: - name: - - docker-compose - state: present diff --git a/compose/roles/infra-container-registry/tasks/main.yml b/compose/roles/infra-container-registry/tasks/main.yml deleted file mode 100644 index 0ee31ec..0000000 --- a/compose/roles/infra-container-registry/tasks/main.yml +++ /dev/null @@ -1,9 +0,0 @@ -# tasks/main.yml -- name: Include install tasks - include_tasks: install.yml - -- name: Include configure tasks - include_tasks: configure.yml - -- name: Include deploy tasks - include_tasks: deploy.yml diff --git a/compose/roles/infra-container-registry/templates/docker-compose.yml.j2 b/compose/roles/infra-container-registry/templates/docker-compose.yml.j2 deleted file mode 100644 index 22dca66..0000000 --- a/compose/roles/infra-container-registry/templates/docker-compose.yml.j2 +++ /dev/null @@ -1,31 +0,0 @@ -version: '3' -services: - registry: - image: registry:2 - container_name: registry - restart: "always" - ports: - - "443:443" - environment: - REGISTRY_HTTP_ADDR: 0.0.0.0:443 - REGISTRY_HTTP_TLS_CERTIFICATE: {{ container_ssl_cert_dir }}/docker.crt - REGISTRY_HTTP_TLS_KEY: {{ container_ssl_cert_dir }}/docker.key - REGISTRY_STORAGE_DELETE_ENABLED: "true" - volumes: - - {{ registry_data_dir }}:/var/lib/registry - - {{ host_ssl_cert_dir }}:{{ container_ssl_cert_dir}} - ui: - image: joxit/docker-registry-ui:latest - container_name: registry-ui - restart: "always" - ports: - - "8080:8080" - environment: - - REGISTRY_TITLE=Private Docker Registry - - NGINX_PROXY_PASS_URL=https://registry - - NGINX_LISTEN_PORT=8080 - - SINGLE_REGISTRY=true - - DELETE_IMAGES=true - - SHOW_CONTENT_DIGEST=true - depends_on: - - registry \ No newline at end of file diff --git a/elasticsearch/values.yaml b/elasticsearch/values.yaml index f65c9cd..60f3bc0 100644 --- a/elasticsearch/values.yaml +++ b/elasticsearch/values.yaml @@ -125,6 +125,7 @@ initResources: {} networkHost: "0.0.0.0" volumeClaimTemplate: + storageClassName: "client1" accessModes: ["ReadWriteOnce"] resources: requests: @@ -158,7 +159,6 @@ podSecurityPolicy: persistence: enabled: true labels: - # Add default labels for the volumeClaimTemplate of the StatefulSet enabled: false annotations: {} diff --git a/grafana/values.yaml b/grafana/values.yaml index 5672adb..7d50b17 100644 --- a/grafana/values.yaml +++ b/grafana/values.yaml @@ -45,85 +45,66 @@ global: destinations: - name: Metrics type: prometheus - url: https://insert.metric.ngcloud.ru/insert/multitenant/prometheus/api/v1/write - extraLabels: - resourceRealm: "cowork.nubes.ru" + url: https://cw-sya-mon-001.stage.co-work.local:9011/api/v1/metrics/write tls: ca: | -----BEGIN CERTIFICATE----- - MIIGzTCCBLWgAwIBAgIUQje87V6XtMmXTm2Zik9aZRTVN6swDQYJKoZIhvcNAQEL - BQAwazELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9z - Y293MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxGjAYBgNVBAMMEW1l - dHJpYy5uZ2Nsb3VkLnJ1MB4XDTI1MDIxODIwMDQwNVoXDTM1MDIxNjIwMDQwNVow - azELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9zY293 - MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxGjAYBgNVBAMMEW1ldHJp - Yy5uZ2Nsb3VkLnJ1MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAzvqs - UfN5T6npdR2i0oOSngtmHfrBIy/6Cvc7ToQszvpA96PL8tyDYsnqpf44TPllHU5r - Y9jPM1RO4zBotTk7z8YLLn71uFUpbFDEJoXOmQzUL35KpD0CVMTzSc1WRwTICxi9 - IKYM9K4d5W7F+ayfZagFI6vLTLTpX7pRJlromxpDD6dUZZTIf0Brm1U0fMXKNUxT - PZ/hj+5Uk8ehA43f95VwB+IXjOnYOELL/U/dLfdiTdtKx9jIVMi84cxdKjsXNsZq - p6298/Ibh6UazntYSFZi4/IP16RsK1kW5HBTuU+XnUk2BsXh36DpY1gdiUBSUK1P - rCMPQcnTb6jnlWx0FBS24WoA07tYWPVuLZoEyIIGC+pBAqh7O9tn/eqDmZIJpTxr - p1FNEXog3if6VOnzGgm+nTpSnIUlwaY+8AFg8+/m5irWRR1gqINYUN+AaqneNjds - sF4jHKuyaRVqhhi3ci9/3dNKbvouqqHMyMRZtf9TfOfI7Va/a/Fy7HHeXnm1XCfh - UyMjnhcZCmlTFGWQIoAvQmghOkGV4aZhJCUVgcwVWn7hbKCQprXjt0r7F2S95AQm - 3IIZnWhqX69Zy4gT6iC3ekAkY4wbk3R8Px57bRy8Kl/fzs/TSzvDkLXNQp7fmCuf - uwIJlUw3777PptaxhhPBvn+qDXr75hztKRYYc5sCAwEAAaOCAWcwggFjMB0GA1Ud - DgQWBBT+NMAwR5MjzkqSINTOX8B+29W1cjCBqAYDVR0jBIGgMIGdgBT+NMAwR5Mj - zkqSINTOX8B+29W1cqFvpG0wazELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3Np - YTEPMA0GA1UEBwwGTW9zY293MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnVi - ZXMxGjAYBgNVBAMMEW1ldHJpYy5uZ2Nsb3VkLnJ1ghRCN7ztXpe0yZdObZmKT1pl - FNU3qzAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIC/DA9BgNVHREENjA0ghhzZWxl - Y3QubWV0cmljLm5nY2xvdWQucnWCGGluc2VydC5tZXRyaWMubmdjbG91ZC5ydTA9 - BgNVHRIENjA0ghhzZWxlY3QubWV0cmljLm5nY2xvdWQucnWCGGluc2VydC5tZXRy - aWMubmdjbG91ZC5ydTANBgkqhkiG9w0BAQsFAAOCAgEAYIoWyjVwBhIAVeqEZwgL - S0HiouN1SNhd8+TjNpmq5pk51/TejoA3pZ1NAo9wdAziyxbKkyCH9H35G7n/DWFO - S5E11UbNmlKrRuREV9TzTot8K1kEQrABiPPXaio8i6vtZD8gakYefPxDeWAWZazs - NCfGR2xLybTeXdJ5qm+2S4GGA9DnW+6e0RItVZD8cY252o/a3JNBsJjwfNmZWakz - raK+7eiCrBfwoJ5aLILGe4yul0XKVCYwWEu4EdavmYWTl5mtbZnkZMIvRQ4ZyqMR - JOAGlgK2QcfMWAvDGQc/GmXr4n+DPji0kSO1GZFWGBCjVSjTjVvL54RJhfF28OX9 - kFKAJJWaLR+wbaZMwTi6qD9zveqXvocQh9fmzJmkKlaQoDR6jeOCAOTQjkkKYQuX - DkTl9mytkWEdF8rqPSpzxbX3C7FMIC10oz7/vv8wNJL5jEUB/IuuiQmVbAjnn/hq - 7Sll7Z+0kl3XMytmb3x3sF6Ri7c0oZkRf5Zd+Jh8dr3VT4Yq+cVbkzocD1QaXYNF - zL2b6/91gjgcHbqcbEksfwfMbre4fflBMo2Vs6h3E99enQ0ZB5VBJQRv8X9ZOVnv - OWCME8Oi+X0lOryCz2bGW38q5UUyFv2hJn3enDA97oZtioDJ9rxCFmliMjacOpoy - hPGGjhjtmeQX3ApWW+gmXWw= + MIIECzCCAvOgAwIBAgIUXz45qUgBvqPnlkqm3TeWNKJ+J5QwDQYJKoZIhvcNAQEL + BQAwgZQxCzAJBgNVBAYTAlJVMQ8wDQYDVQQIDAZNb3Njb3cxDzANBgNVBAcMBk1v + c2NvdzEPMA0GA1UECgwGTW9zY293MRYwFAYDVQQLDA1jby13b3JrX3N0YWdlMRYw + FAYDVQQDDA1jby13b3JrX3N0YWdlMSIwIAYJKoZIhvcNAQkBFhNzdGFnZS5jby13 + b3JrLmxvY2FsMB4XDTI1MDMxNzE5MDkyMFoXDTM1MDMxNTE5MDkyMFowgZQxCzAJ + BgNVBAYTAlJVMQ8wDQYDVQQIDAZNb3Njb3cxDzANBgNVBAcMBk1vc2NvdzEPMA0G + A1UECgwGTW9zY293MRYwFAYDVQQLDA1jby13b3JrX3N0YWdlMRYwFAYDVQQDDA1j + by13b3JrX3N0YWdlMSIwIAYJKoZIhvcNAQkBFhNzdGFnZS5jby13b3JrLmxvY2Fs + MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwTGH/XcaGnUusf8DMYsW + /Pd97I4HnhYlInA9v3rLm9r5WSZ7bUx5nq56dcgSIiEAhS56/qFNAjiemF3x4Zg1 + NhfiAmuCCaWHFGayQrjBcgEjfTLlxArTiY8A+35TJ7fooXKJChfqZwJhMdI+XYLe + WjJRceK8BTBoMIdApx7YeUP9qKBrdKy5RgN7y9L0iA+sPCOQbIEJWE+qHJIswtHm + uoVHi6Lx8WgXknV9KCcKVydeVx9Dy0vN42eUgGyiM7p8QqYoHhtwY0QGyNqyaIrj + hb1miFBiUxt2sC9sLns9lSVFl8lwyF1iB6o70IfmoPb30DbyvhKP64KeEuDT+/hq + zwIDAQABo1MwUTAdBgNVHQ4EFgQURFp9aflCwMcR894WPpE9UoD5Q8swHwYDVR0j + BBgwFoAURFp9aflCwMcR894WPpE9UoD5Q8swDwYDVR0TAQH/BAUwAwEB/zANBgkq + hkiG9w0BAQsFAAOCAQEATmOdzIiusa6QZrcQm772cmMldYefM8lBxbtDjHBQw7L1 + u+/6B+eLE0ytza4BVfKaJ2gk4gk3dIFSYbGviPY+GOzR2bVZ+u8s42DspQt3pkKa + VsTZl4xl5dwoEpFLCY3JkcecRN5nBz3hiFrDGtLFbkx01QpUD7kSjaaLA2arQZHN + CkzLkRRDtozC2xKB1xW32SdXCjp5jpJZEXqkGvbTptUYXUkulLiGsmxwOk43G7QX + r0L5RCFLMw3g108yhVAm7PA9ta0iL3+XodGFfaRAs/o6QCt5qYhc6VXDN6zA0o91 + WPjlBBWu51/pmDhhQf9NawBhsG3GJ1VBo9InMZLHNA== -----END CERTIFICATE----- + extraLabels: + resourceRealm: "co-work.nubes.ru" - name: Logs type: loki - url: https://insert.log.ngcloud.ru/loki/api/v1/push - extraLabels: - resourceRealm: "cowork.nubes.ru" + url: https://cw-sya-mon-001.stage.co-work.local:3100/loki/api/v1/push tls: ca: | -----BEGIN CERTIFICATE----- - MIIEuDCCA6CgAwIBAgIUUADJQeKcpefXn/o6a8fba64bUscwDQYJKoZIhvcNAQEL - BQAwaDELMAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9z - Y293MQ4wDAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxFzAVBgNVBAMMDmxv - Zy5uZ2Nsb3VkLnJ1MB4XDTI1MDIxOTA5MjkzOFoXDTM1MDIxNzA5MjkzOFowaDEL - MAkGA1UEBhMCUlUxDzANBgNVBAgMBlJ1c3NpYTEPMA0GA1UEBwwGTW9zY293MQ4w - DAYDVQQKDAVudWJlczEOMAwGA1UECwwFbnViZXMxFzAVBgNVBAMMDmxvZy5uZ2Ns - b3VkLnJ1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvaVoQuQ8A1lO - 7mrriMQWVfUO2MT/fcBhiulYJcxkZTOwfS7iHssBFz5PigOSn0PqqCHPUJZ/SfKI - FdEagfpc4FuEJ5Mv7Fex7UBkXwAyOomU29cyaJjtlqDEKnNHie5PZQfnFV0YxPM1 - QtQsrOhhI2dMlQxR65I+440yPkrsv5hDXw5XBsHOvjxlnDnOfulmREgP8a+uwe8M - TokoE9XFCxIfYn0IbEhPEqWLlyHvBnXt2ddDOXDAp2XJndVrdj1rIy+rudAv5/Gx - Tna2JX+6h6f0JCwyOcbyYr3YznHmio5Gu0ZrAAFXueryYmuq9I9kUJJV9h5ilAFs - wRmt7EA9ywIDAQABo4IBWDCCAVQwHQYDVR0OBBYEFMjF50YBCR/hQMbeKCPYABSI - n789MIGlBgNVHSMEgZ0wgZqAFMjF50YBCR/hQMbeKCPYABSIn789oWykajBoMQsw - CQYDVQQGEwJSVTEPMA0GA1UECAwGUnVzc2lhMQ8wDQYDVQQHDAZNb3Njb3cxDjAM - BgNVBAoMBW51YmVzMQ4wDAYDVQQLDAVudWJlczEXMBUGA1UEAwwObG9nLm5nY2xv - dWQucnWCFFAAyUHinKXn15/6OmvH22uuG1LHMAwGA1UdEwQFMAMBAf8wCwYDVR0P - BAQDAgL8MDcGA1UdEQQwMC6CFXNlbGVjdC5sb2cubmdjbG91ZC5ydYIVaW5zZXJ0 - LmxvZy5uZ2Nsb3VkLnJ1MDcGA1UdEgQwMC6CFXNlbGVjdC5sb2cubmdjbG91ZC5y - dYIVaW5zZXJ0LmxvZy5uZ2Nsb3VkLnJ1MA0GCSqGSIb3DQEBCwUAA4IBAQCrQJbU - WSnURocaIbaaXLqa/cpniVyFQQXf1i4kQMVXydJuroGgNWlq2qXv4YYau96wZOxF - POr/HJMXBZapMLqAbup3k/8Cb42+qUxC7m/M2dHIHwAEegBwvb7TV50m2/Nd2907 - nhY/Jx22FaACpMdQPdiSdJLu2TTFHT3mpKJ0hse3El1Kw0WZBfwjaCESZvzH7K8h - 9xNEiSG/lOl6mjnVc1WPv2YIzYStUCbVleMKAz0DEtQYgRYY89sVvJlkTDHkUc8A - l37qH3wZrQ/5BU6psxe+586CB86gpt3F/266BCeUtunS9SywNWJsajgmKUENTfYW - E3yjqYhIOgCdntfV + MIIECzCCAvOgAwIBAgIUXz45qUgBvqPnlkqm3TeWNKJ+J5QwDQYJKoZIhvcNAQEL + BQAwgZQxCzAJBgNVBAYTAlJVMQ8wDQYDVQQIDAZNb3Njb3cxDzANBgNVBAcMBk1v + c2NvdzEPMA0GA1UECgwGTW9zY293MRYwFAYDVQQLDA1jby13b3JrX3N0YWdlMRYw + FAYDVQQDDA1jby13b3JrX3N0YWdlMSIwIAYJKoZIhvcNAQkBFhNzdGFnZS5jby13 + b3JrLmxvY2FsMB4XDTI1MDMxNzE5MDkyMFoXDTM1MDMxNTE5MDkyMFowgZQxCzAJ + BgNVBAYTAlJVMQ8wDQYDVQQIDAZNb3Njb3cxDzANBgNVBAcMBk1vc2NvdzEPMA0G + A1UECgwGTW9zY293MRYwFAYDVQQLDA1jby13b3JrX3N0YWdlMRYwFAYDVQQDDA1j + by13b3JrX3N0YWdlMSIwIAYJKoZIhvcNAQkBFhNzdGFnZS5jby13b3JrLmxvY2Fs + MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwTGH/XcaGnUusf8DMYsW + /Pd97I4HnhYlInA9v3rLm9r5WSZ7bUx5nq56dcgSIiEAhS56/qFNAjiemF3x4Zg1 + NhfiAmuCCaWHFGayQrjBcgEjfTLlxArTiY8A+35TJ7fooXKJChfqZwJhMdI+XYLe + WjJRceK8BTBoMIdApx7YeUP9qKBrdKy5RgN7y9L0iA+sPCOQbIEJWE+qHJIswtHm + uoVHi6Lx8WgXknV9KCcKVydeVx9Dy0vN42eUgGyiM7p8QqYoHhtwY0QGyNqyaIrj + hb1miFBiUxt2sC9sLns9lSVFl8lwyF1iB6o70IfmoPb30DbyvhKP64KeEuDT+/hq + zwIDAQABo1MwUTAdBgNVHQ4EFgQURFp9aflCwMcR894WPpE9UoD5Q8swHwYDVR0j + BBgwFoAURFp9aflCwMcR894WPpE9UoD5Q8swDwYDVR0TAQH/BAUwAwEB/zANBgkq + hkiG9w0BAQsFAAOCAQEATmOdzIiusa6QZrcQm772cmMldYefM8lBxbtDjHBQw7L1 + u+/6B+eLE0ytza4BVfKaJ2gk4gk3dIFSYbGviPY+GOzR2bVZ+u8s42DspQt3pkKa + VsTZl4xl5dwoEpFLCY3JkcecRN5nBz3hiFrDGtLFbkx01QpUD7kSjaaLA2arQZHN + CkzLkRRDtozC2xKB1xW32SdXCjp5jpJZEXqkGvbTptUYXUkulLiGsmxwOk43G7QX + r0L5RCFLMw3g108yhVAm7PA9ta0iL3+XodGFfaRAs/o6QCt5qYhc6VXDN6zA0o91 + WPjlBBWu51/pmDhhQf9NawBhsG3GJ1VBo9InMZLHNA== -----END CERTIFICATE----- + extraLabels: + resourceRealm: "co-work.nubes.ru" # # Features # @@ -498,7 +479,13 @@ alloy-singleton: # -- Extra Alloy configuration to be added to the configuration file. # @section -- Collectors - Alloy Singleton - extraConfig: "" + extraConfig: | + prometheus.scrape "livekit" { + targets = [ + {__address__ = "livekit-server:9092"}, + ] + forward_to = [prometheus.remote_write.metrics.receiver] + } # Remote configuration from a remote config server. remoteConfig: diff --git a/ingress-nginx/values.yaml b/ingress-nginx/values.yaml index 6e457e4..821b4bb 100644 --- a/ingress-nginx/values.yaml +++ b/ingress-nginx/values.yaml @@ -153,7 +153,7 @@ controller: enabled: true annotations: {} labels: {} - type: NodePort + type: LoadBalancer clusterIP: "" externalIPs: [] loadBalancerIP: "" diff --git a/kafka/templates/provisioning/job.yaml b/kafka/templates/provisioning/job.yaml index d144762..a7b4406 100644 --- a/kafka/templates/provisioning/job.yaml +++ b/kafka/templates/provisioning/job.yaml @@ -13,8 +13,9 @@ metadata: app.kubernetes.io/component: kafka-provisioning annotations: {{- if .Values.provisioning.useHelmHooks }} - helm.sh/hook: post-install,post-upgrade - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded + helm.sh/hook: pre-install,pre-upgrade + helm.sh/hook-weight: "0" + helm.sh/hook-delete-policy: hook-succeeded {{- end }} {{- if .Values.commonAnnotations }} {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} diff --git a/kafka/templates/vault-setup.yaml b/kafka/templates/vault-setup.yaml deleted file mode 100644 index 5063bb7..0000000 --- a/kafka/templates/vault-setup.yaml +++ /dev/null @@ -1,43 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - namespace: {{ .Release.Namespace }} - name: vault-secrets-operator-controller-manager ---- -apiVersion: secrets.hashicorp.com/v1beta1 -kind: VaultConnection -metadata: - name: vault-connection - namespace: {{ .Release.Namespace }} -spec: - address: http://vault.vault.svc.cluster.local:8200 - skipTLSVerify: true ---- -apiVersion: secrets.hashicorp.com/v1beta1 -kind: VaultAuth -metadata: - name: vault-auth - namespace: {{ .Release.Namespace }} -spec: - method: kubernetes - mount: kubernetes - kubernetes: - role: kafka-role - serviceAccount: vault-secrets-operator-controller-manager - audiences: - - vault ---- -apiVersion: secrets.hashicorp.com/v1beta1 -kind: VaultStaticSecret -metadata: - name: kafka-static-user-passwords - namespace: {{ .Release.Namespace }} -spec: - mount: kvv2 - type: kv-v2 - path: kafka/config - refreshAfter: 5m - destination: - create: true - name: kafka-static-user-passwords - vaultAuthRef: vault-auth \ No newline at end of file diff --git a/kafka/values.yaml b/kafka/values.yaml index 3336b2e..dcee0ea 100644 --- a/kafka/values.yaml +++ b/kafka/values.yaml @@ -20,7 +20,7 @@ global: ## imagePullSecrets: [] defaultStorageClass: "" - storageClass: "" + storageClass: "client1" ## Security parameters ## security: @@ -290,7 +290,7 @@ sasl: ## The client secrets are only required when using oauthbearer as sasl mechanism. ## Client, interbroker and controller passwords are only required if the sasl mechanism includes something other than oauthbearer. ## - existingSecret: "kafka-static-user-passwords" + existingSecret: kafka-static-user-passwords ## @section Kafka TLS parameters ## Kafka TLS settings, required if SSL or SASL_SSL listeners are configured ## @@ -628,7 +628,7 @@ controller: ## @param controller.resourcesPreset Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if controller.resources is set (controller.resources is recommended for production). ## More information: https://github.com/bitnami/charts/blob/main/bitnami/common/templates/_resources.tpl#L15 ## - resourcesPreset: "small" + resourcesPreset: "medium" ## @param controller.resources Set container requests and limits for different resources like CPU or memory (essential for production workloads) ## Example: ## resources: @@ -1086,7 +1086,7 @@ broker: ## @param broker.resourcesPreset Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if broker.resources is set (broker.resources is recommended for production). ## More information: https://github.com/bitnami/charts/blob/main/bitnami/common/templates/_resources.tpl#L15 ## - resourcesPreset: "small" + resourcesPreset: "medium" ## @param broker.resources Set container requests and limits for different resources like CPU or memory (essential for production workloads) ## Example: ## resources: @@ -1497,7 +1497,7 @@ service: ## labels: {} ## @param service.headless.ipFamilies IP families for the headless service - ## + ## ipFamilies: [] ## @param service.headless.ipFamilyPolicy IP family policy for the headless service ## @@ -2069,7 +2069,7 @@ metrics: prometheus.io/path: "/metrics" ## @param metrics.jmx.service.ipFamilies IP families for the jmx metrics service ## - ipFamilies: [] + ipFamilies: [] ## @param metrics.jmx.service.ipFamilyPolicy IP family policy for the jmx metrics service ## ipFamilyPolicy: "" @@ -2379,9 +2379,6 @@ provisioning: max.message.bytes: 128000 flush.messages: 10 - ## @param provisioning.nodeSelector Node labels for pod assignment - ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/ - ## nodeSelector: {} ## @param provisioning.tolerations Tolerations for pod assignment ## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ diff --git a/livekit/livekit-egress/values.yaml b/livekit/livekit-egress/values.yaml index 246e43f..54bc66a 100644 --- a/livekit/livekit-egress/values.yaml +++ b/livekit/livekit-egress/values.yaml @@ -2,18 +2,18 @@ image: repository: livekit/egress pullPolicy: IfNotPresent egress: - log_level: debug + log_level: info health_port: 8080 prometheus_port: 9090 redis: - address: redis-master.redis.svc.cluster.local:6379 + address: redis-master:6379 db: 0 username: "" password: "" use_tls: false api_key: APIXj3LbDJJPLHv api_secret: eWWetAn7vlfgFQnXXHyyox8QceBYTnZcIMhDe4I16UeE - ws_url: wss://av-p001.cw.ngcloud.ru + ws_url: wss://av-s001.co-work.ru terminationGracePeriodSeconds: 3600 nameOverride: "" fullnameOverride: "" diff --git a/livekit/livekit-server/templates/ingress_turn.yaml b/livekit/livekit-server/templates/ingress_turn.yaml index a449b96..f1ad3c8 100644 --- a/livekit/livekit-server/templates/ingress_turn.yaml +++ b/livekit/livekit-server/templates/ingress_turn.yaml @@ -2,11 +2,11 @@ apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: livekit-server-turn - namespace: livekit + namespace: {{ .Release.Namespace }} spec: ingressClassName: nginx rules: - - host: avt-p001.cw.ngcloud.ru + - host: avt-s001.co-work.ru http: paths: - backend: @@ -18,5 +18,5 @@ spec: pathType: Prefix tls: - hosts: - - avt-p001.cw.ngcloud.ru + - avt-s001.co-work.ru secretName: co-work-secret \ No newline at end of file diff --git a/livekit/livekit-server/templates/serivce-exporter.yaml b/livekit/livekit-server/templates/serivce-exporter.yaml new file mode 100644 index 0000000..9d4be14 --- /dev/null +++ b/livekit/livekit-server/templates/serivce-exporter.yaml @@ -0,0 +1,18 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "livekit-server.name" . }}-exporter + namespace: {{ .Release.namespace }} + labels: + app.kubernetes.io/instance: {{ include "livekit-server.name" . }} + app.kubernetes.io/name: {{ include "livekit-server.name" . }} + purpose: exporter +spec: + type: {{ .Values.serviceRtc.type }} + selector: + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/name: {{ include "livekit-server.name" . }} + ports: + - name: exporter + port: {{ .Values.livekit.prometheus.port }} + targetPort: {{ .Values.livekit.prometheus.port }} diff --git a/livekit/livekit-server/values.yaml b/livekit/livekit-server/values.yaml index dc46753..8038251 100644 --- a/livekit/livekit-server/values.yaml +++ b/livekit/livekit-server/values.yaml @@ -7,8 +7,9 @@ imagePullSecrets: [] terminationGracePeriodSeconds: 18000 livekit: +# prometheus_port: 9092 port: 7880 - log_level: info + log_level: debug rtc: tcp_port: 7881 port_range_start: 50000 @@ -16,7 +17,7 @@ livekit: use_external_ip: true enable_loopback_candidate: false redis: - address: redis-master.redis.svc.cluster.local:6379 + address: redis-master:6379 db: 0 username: "" password: "" @@ -30,16 +31,21 @@ livekit: keys: APIXj3LbDJJPLHv: "eWWetAn7vlfgFQnXXHyyox8QceBYTnZcIMhDe4I16UeE" turn: + servers: + - urls: + - "turn:avt-s001.co-work.ru:3478" + - "turns:avt-s001.co-work.ru:5349" enabled: true - domain: avt-p001.cw.ngcloud.ru + domain: avt-s001.co-work.ru tls_port: 5349 udp_port: 3478 external_tls: true - serviceType: ClusterIP + serviceType: NodePort + NodePort: 38888 webhook: api_key: 'APIXj3LbDJJPLHv' urls: - - 'http://livekit-webhook-handler-app.default.svc.cluster.local:5098/livekit/callback' + - 'http://livekit-webhook-handler-app:5098/livekit/callback' room: departure_timeout: 1 prometheus: @@ -71,7 +77,7 @@ loadBalancer: tls: - secretName: co-work-secret hosts: - - av-p001.cw.ngcloud.ru + - av-s001.co-work.ru turnLoadbalancer: enable: true @@ -92,10 +98,10 @@ nodeSelector: resources: requests: - cpu: 2000m + cpu: 1000m memory: 1Gi limits: - cpu: 3000m + cpu: 2000m memory: 2Gi # Due to port restrictions, you can run only one instance of LiveKit per physical # node. Because of that, we recommend giving it plenty of resources to work with @@ -181,4 +187,7 @@ serviceRtc: type: NodePort # or LoadBalancer if you prefer nodePort: 31881 externalTrafficPolicy: Cluster - annotations: {} \ No newline at end of file + annotations: {} + +serviceExporter: + type: ClusterIP # or LoadBalancer if you prefer diff --git a/metallb/Chart.lock b/metallb/Chart.lock deleted file mode 100644 index 7934558..0000000 --- a/metallb/Chart.lock +++ /dev/null @@ -1,9 +0,0 @@ -dependencies: -- name: crds - repository: "" - version: 0.14.9 -- name: frr-k8s - repository: https://metallb.github.io/frr-k8s - version: 0.0.16 -digest: sha256:20d9a53af12c82d35168e7524ae337341b2c7cb43e2169545185f750a718466e -generated: "2024-12-17T15:39:32.082324414+01:00" diff --git a/metallb/Chart.yaml b/metallb/Chart.yaml deleted file mode 100644 index 680ac9b..0000000 --- a/metallb/Chart.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: v2 -appVersion: v0.14.9 -dependencies: -- condition: crds.enabled - name: crds - repository: "" - version: 0.14.9 -- condition: frrk8s.enabled - name: frr-k8s - repository: https://metallb.github.io/frr-k8s - version: 0.0.16 -description: A network load-balancer implementation for Kubernetes using standard - routing protocols -home: https://metallb.universe.tf -icon: https://metallb.universe.tf/images/logo/metallb-white.png -kubeVersion: '>= 1.19.0-0' -name: metallb -sources: -- https://github.com/metallb/metallb -type: application -version: 0.14.9 diff --git a/metallb/README.md b/metallb/README.md deleted file mode 100644 index 43f51ef..0000000 --- a/metallb/README.md +++ /dev/null @@ -1,169 +0,0 @@ -# metallb - -![Version: 0.0.0](https://img.shields.io/badge/Version-0.0.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.0.0](https://img.shields.io/badge/AppVersion-v0.0.0-informational?style=flat-square) - -A network load-balancer implementation for Kubernetes using standard routing protocols - -**Homepage:** - -## Source Code - -* - -## Requirements - -Kubernetes: `>= 1.19.0-0` - -| Repository | Name | Version | -|------------|------|---------| -| | crds | 0.0.0 | -| https://metallb.github.io/frr-k8s | frr-k8s | 0.0.16 | - -## Values - -| Key | Type | Default | Description | -|-----|------|---------|-------------| -| controller.affinity | object | `{}` | | -| controller.enabled | bool | `true` | | -| controller.extraContainers | list | `[]` | | -| controller.image.pullPolicy | string | `nil` | | -| controller.image.repository | string | `"quay.io/metallb/controller"` | | -| controller.image.tag | string | `nil` | | -| controller.labels | object | `{}` | | -| controller.livenessProbe.enabled | bool | `true` | | -| controller.livenessProbe.failureThreshold | int | `3` | | -| controller.livenessProbe.initialDelaySeconds | int | `10` | | -| controller.livenessProbe.periodSeconds | int | `10` | | -| controller.livenessProbe.successThreshold | int | `1` | | -| controller.livenessProbe.timeoutSeconds | int | `1` | | -| controller.logLevel | string | `"info"` | Controller log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none` | -| controller.nodeSelector | object | `{}` | | -| controller.podAnnotations | object | `{}` | | -| controller.priorityClassName | string | `""` | | -| controller.readinessProbe.enabled | bool | `true` | | -| controller.readinessProbe.failureThreshold | int | `3` | | -| controller.readinessProbe.initialDelaySeconds | int | `10` | | -| controller.readinessProbe.periodSeconds | int | `10` | | -| controller.readinessProbe.successThreshold | int | `1` | | -| controller.readinessProbe.timeoutSeconds | int | `1` | | -| controller.resources | object | `{}` | | -| controller.runtimeClassName | string | `""` | | -| controller.securityContext.fsGroup | int | `65534` | | -| controller.securityContext.runAsNonRoot | bool | `true` | | -| controller.securityContext.runAsUser | int | `65534` | | -| controller.serviceAccount.annotations | object | `{}` | | -| controller.serviceAccount.create | bool | `true` | | -| controller.serviceAccount.name | string | `""` | | -| controller.strategy.type | string | `"RollingUpdate"` | | -| controller.tlsCipherSuites | string | `""` | | -| controller.tlsMinVersion | string | `"VersionTLS12"` | | -| controller.tolerations | list | `[]` | | -| crds.enabled | bool | `true` | | -| crds.validationFailurePolicy | string | `"Fail"` | | -| frrk8s.enabled | bool | `false` | | -| frrk8s.external | bool | `false` | | -| frrk8s.namespace | string | `""` | | -| fullnameOverride | string | `""` | | -| imagePullSecrets | list | `[]` | | -| loadBalancerClass | string | `""` | | -| nameOverride | string | `""` | | -| prometheus.controllerMetricsTLSSecret | string | `""` | | -| prometheus.metricsPort | int | `7472` | | -| prometheus.namespace | string | `""` | | -| prometheus.podMonitor.additionalLabels | object | `{}` | | -| prometheus.podMonitor.annotations | object | `{}` | | -| prometheus.podMonitor.enabled | bool | `false` | | -| prometheus.podMonitor.interval | string | `nil` | | -| prometheus.podMonitor.jobLabel | string | `"app.kubernetes.io/name"` | | -| prometheus.podMonitor.metricRelabelings | list | `[]` | | -| prometheus.podMonitor.relabelings | list | `[]` | | -| prometheus.prometheusRule.additionalLabels | object | `{}` | | -| prometheus.prometheusRule.addressPoolExhausted.enabled | bool | `true` | | -| prometheus.prometheusRule.addressPoolExhausted.labels.severity | string | `"critical"` | | -| prometheus.prometheusRule.addressPoolUsage.enabled | bool | `true` | | -| prometheus.prometheusRule.addressPoolUsage.thresholds[0].labels.severity | string | `"warning"` | | -| prometheus.prometheusRule.addressPoolUsage.thresholds[0].percent | int | `75` | | -| prometheus.prometheusRule.addressPoolUsage.thresholds[1].labels.severity | string | `"warning"` | | -| prometheus.prometheusRule.addressPoolUsage.thresholds[1].percent | int | `85` | | -| prometheus.prometheusRule.addressPoolUsage.thresholds[2].labels.severity | string | `"critical"` | | -| prometheus.prometheusRule.addressPoolUsage.thresholds[2].percent | int | `95` | | -| prometheus.prometheusRule.annotations | object | `{}` | | -| prometheus.prometheusRule.bgpSessionDown.enabled | bool | `true` | | -| prometheus.prometheusRule.bgpSessionDown.labels.severity | string | `"critical"` | | -| prometheus.prometheusRule.configNotLoaded.enabled | bool | `true` | | -| prometheus.prometheusRule.configNotLoaded.labels.severity | string | `"warning"` | | -| prometheus.prometheusRule.enabled | bool | `false` | | -| prometheus.prometheusRule.extraAlerts | list | `[]` | | -| prometheus.prometheusRule.staleConfig.enabled | bool | `true` | | -| prometheus.prometheusRule.staleConfig.labels.severity | string | `"warning"` | | -| prometheus.rbacPrometheus | bool | `true` | | -| prometheus.rbacProxy.pullPolicy | string | `nil` | | -| prometheus.rbacProxy.repository | string | `"gcr.io/kubebuilder/kube-rbac-proxy"` | | -| prometheus.rbacProxy.tag | string | `"v0.12.0"` | | -| prometheus.scrapeAnnotations | bool | `false` | | -| prometheus.serviceAccount | string | `""` | | -| prometheus.serviceMonitor.controller.additionalLabels | object | `{}` | | -| prometheus.serviceMonitor.controller.annotations | object | `{}` | | -| prometheus.serviceMonitor.controller.tlsConfig.insecureSkipVerify | bool | `true` | | -| prometheus.serviceMonitor.enabled | bool | `false` | | -| prometheus.serviceMonitor.interval | string | `nil` | | -| prometheus.serviceMonitor.jobLabel | string | `"app.kubernetes.io/name"` | | -| prometheus.serviceMonitor.metricRelabelings | list | `[]` | | -| prometheus.serviceMonitor.relabelings | list | `[]` | | -| prometheus.serviceMonitor.speaker.additionalLabels | object | `{}` | | -| prometheus.serviceMonitor.speaker.annotations | object | `{}` | | -| prometheus.serviceMonitor.speaker.tlsConfig.insecureSkipVerify | bool | `true` | | -| prometheus.speakerMetricsTLSSecret | string | `""` | | -| rbac.create | bool | `true` | | -| speaker.affinity | object | `{}` | | -| speaker.enabled | bool | `true` | | -| speaker.excludeInterfaces.enabled | bool | `true` | | -| speaker.extraContainers | list | `[]` | | -| speaker.frr.enabled | bool | `true` | | -| speaker.frr.image.pullPolicy | string | `nil` | | -| speaker.frr.image.repository | string | `"quay.io/frrouting/frr"` | | -| speaker.frr.image.tag | string | `"9.1.0"` | | -| speaker.frr.metricsPort | int | `7473` | | -| speaker.frr.resources | object | `{}` | | -| speaker.frrMetrics.resources | object | `{}` | | -| speaker.ignoreExcludeLB | bool | `false` | | -| speaker.image.pullPolicy | string | `nil` | | -| speaker.image.repository | string | `"quay.io/metallb/speaker"` | | -| speaker.image.tag | string | `nil` | | -| speaker.labels | object | `{}` | | -| speaker.livenessProbe.enabled | bool | `true` | | -| speaker.livenessProbe.failureThreshold | int | `3` | | -| speaker.livenessProbe.initialDelaySeconds | int | `10` | | -| speaker.livenessProbe.periodSeconds | int | `10` | | -| speaker.livenessProbe.successThreshold | int | `1` | | -| speaker.livenessProbe.timeoutSeconds | int | `1` | | -| speaker.logLevel | string | `"info"` | Speaker log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none` | -| speaker.memberlist.enabled | bool | `true` | | -| speaker.memberlist.mlBindAddrOverride | string | `""` | | -| speaker.memberlist.mlBindPort | int | `7946` | | -| speaker.memberlist.mlSecretKeyPath | string | `"/etc/ml_secret_key"` | | -| speaker.nodeSelector | object | `{}` | | -| speaker.podAnnotations | object | `{}` | | -| speaker.priorityClassName | string | `""` | | -| speaker.readinessProbe.enabled | bool | `true` | | -| speaker.readinessProbe.failureThreshold | int | `3` | | -| speaker.readinessProbe.initialDelaySeconds | int | `10` | | -| speaker.readinessProbe.periodSeconds | int | `10` | | -| speaker.readinessProbe.successThreshold | int | `1` | | -| speaker.readinessProbe.timeoutSeconds | int | `1` | | -| speaker.reloader.resources | object | `{}` | | -| speaker.resources | object | `{}` | | -| speaker.runtimeClassName | string | `""` | | -| speaker.securityContext | object | `{}` | | -| speaker.serviceAccount.annotations | object | `{}` | | -| speaker.serviceAccount.create | bool | `true` | | -| speaker.serviceAccount.name | string | `""` | | -| speaker.startupProbe.enabled | bool | `true` | | -| speaker.startupProbe.failureThreshold | int | `30` | | -| speaker.startupProbe.periodSeconds | int | `5` | | -| speaker.tolerateMaster | bool | `true` | | -| speaker.tolerations | list | `[]` | | -| speaker.updateStrategy.type | string | `"RollingUpdate"` | | - ----------------------------------------------- -Autogenerated from chart metadata using [helm-docs v1.10.0](https://github.com/norwoodj/helm-docs/releases/v1.10.0) diff --git a/metallb/charts/crds/Chart.yaml b/metallb/charts/crds/Chart.yaml deleted file mode 100644 index e9fec84..0000000 --- a/metallb/charts/crds/Chart.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: v2 -appVersion: v0.14.9 -description: MetalLB CRDs -home: https://metallb.universe.tf -icon: https://metallb.universe.tf/images/logo/metallb-white.png -name: crds -sources: -- https://github.com/metallb/metallb -type: application -version: 0.14.9 diff --git a/metallb/charts/crds/README.md b/metallb/charts/crds/README.md deleted file mode 100644 index 15bf8a7..0000000 --- a/metallb/charts/crds/README.md +++ /dev/null @@ -1,14 +0,0 @@ -# crds - -![Version: 0.0.0](https://img.shields.io/badge/Version-0.0.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.0.0](https://img.shields.io/badge/AppVersion-v0.0.0-informational?style=flat-square) - -MetalLB CRDs - -**Homepage:** - -## Source Code - -* - ----------------------------------------------- -Autogenerated from chart metadata using [helm-docs v1.10.0](https://github.com/norwoodj/helm-docs/releases/v1.10.0) diff --git a/metallb/charts/crds/templates/crds.yaml b/metallb/charts/crds/templates/crds.yaml deleted file mode 100644 index 8f24147..0000000 --- a/metallb/charts/crds/templates/crds.yaml +++ /dev/null @@ -1,1219 +0,0 @@ -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.3 - name: bfdprofiles.metallb.io -spec: - group: metallb.io - names: - kind: BFDProfile - listKind: BFDProfileList - plural: bfdprofiles - singular: bfdprofile - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.passiveMode - name: Passive Mode - type: boolean - - jsonPath: .spec.transmitInterval - name: Transmit Interval - type: integer - - jsonPath: .spec.receiveInterval - name: Receive Interval - type: integer - - jsonPath: .spec.detectMultiplier - name: Multiplier - type: integer - name: v1beta1 - schema: - openAPIV3Schema: - description: |- - BFDProfile represents the settings of the bfd session that can be - optionally associated with a BGP session. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: BFDProfileSpec defines the desired state of BFDProfile. - properties: - detectMultiplier: - description: |- - Configures the detection multiplier to determine - packet loss. The remote transmission interval will be multiplied - by this value to determine the connection loss detection timer. - format: int32 - maximum: 255 - minimum: 2 - type: integer - echoInterval: - description: |- - Configures the minimal echo receive transmission - interval that this system is capable of handling in milliseconds. - Defaults to 50ms - format: int32 - maximum: 60000 - minimum: 10 - type: integer - echoMode: - description: |- - Enables or disables the echo transmission mode. - This mode is disabled by default, and not supported on multi - hops setups. - type: boolean - minimumTtl: - description: |- - For multi hop sessions only: configure the minimum - expected TTL for an incoming BFD control packet. - format: int32 - maximum: 254 - minimum: 1 - type: integer - passiveMode: - description: |- - Mark session as passive: a passive session will not - attempt to start the connection and will wait for control packets - from peer before it begins replying. - type: boolean - receiveInterval: - description: |- - The minimum interval that this system is capable of - receiving control packets in milliseconds. - Defaults to 300ms. - format: int32 - maximum: 60000 - minimum: 10 - type: integer - transmitInterval: - description: |- - The minimum transmission interval (less jitter) - that this system wants to use to send BFD control packets in - milliseconds. Defaults to 300ms - format: int32 - maximum: 60000 - minimum: 10 - type: integer - type: object - status: - description: BFDProfileStatus defines the observed state of BFDProfile. - type: object - type: object - served: true - storage: true - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.3 - name: bgpadvertisements.metallb.io -spec: - group: metallb.io - names: - kind: BGPAdvertisement - listKind: BGPAdvertisementList - plural: bgpadvertisements - singular: bgpadvertisement - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.ipAddressPools - name: IPAddressPools - type: string - - jsonPath: .spec.ipAddressPoolSelectors - name: IPAddressPool Selectors - type: string - - jsonPath: .spec.peers - name: Peers - type: string - - jsonPath: .spec.nodeSelectors - name: Node Selectors - priority: 10 - type: string - name: v1beta1 - schema: - openAPIV3Schema: - description: |- - BGPAdvertisement allows to advertise the IPs coming - from the selected IPAddressPools via BGP, setting the parameters of the - BGP Advertisement. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: BGPAdvertisementSpec defines the desired state of BGPAdvertisement. - properties: - aggregationLength: - default: 32 - description: The aggregation-length advertisement option lets you “roll up” the /32s into a larger prefix. Defaults to 32. Works for IPv4 addresses. - format: int32 - minimum: 1 - type: integer - aggregationLengthV6: - default: 128 - description: The aggregation-length advertisement option lets you “roll up” the /128s into a larger prefix. Defaults to 128. Works for IPv6 addresses. - format: int32 - type: integer - communities: - description: |- - The BGP communities to be associated with the announcement. Each item can be a standard community of the - form 1234:1234, a large community of the form large:1234:1234:1234 or the name of an alias defined in the - Community CRD. - items: - type: string - type: array - ipAddressPoolSelectors: - description: |- - A selector for the IPAddressPools which would get advertised via this advertisement. - If no IPAddressPool is selected by this or by the list, the advertisement is applied to all the IPAddressPools. - items: - description: |- - A label selector is a label query over a set of resources. The result of matchLabels and - matchExpressions are ANDed. An empty label selector matches all objects. A null - label selector matches no objects. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - type: array - ipAddressPools: - description: The list of IPAddressPools to advertise via this advertisement, selected by name. - items: - type: string - type: array - localPref: - description: |- - The BGP LOCAL_PREF attribute which is used by BGP best path algorithm, - Path with higher localpref is preferred over one with lower localpref. - format: int32 - type: integer - nodeSelectors: - description: NodeSelectors allows to limit the nodes to announce as next hops for the LoadBalancer IP. When empty, all the nodes having are announced as next hops. - items: - description: |- - A label selector is a label query over a set of resources. The result of matchLabels and - matchExpressions are ANDed. An empty label selector matches all objects. A null - label selector matches no objects. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - type: array - peers: - description: |- - Peers limits the bgppeer to advertise the ips of the selected pools to. - When empty, the loadbalancer IP is announced to all the BGPPeers configured. - items: - type: string - type: array - type: object - status: - description: BGPAdvertisementStatus defines the observed state of BGPAdvertisement. - type: object - type: object - served: true - storage: true - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.3 - name: bgppeers.metallb.io -spec: - conversion: - strategy: Webhook - webhook: - clientConfig: - caBundle: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tDQpNSUlGWlRDQ0EwMmdBd0lCQWdJVU5GRW1XcTM3MVpKdGkrMmlSQzk1WmpBV1MxZ3dEUVlKS29aSWh2Y05BUUVMDQpCUUF3UWpFTE1Ba0dBMVVFQmhNQ1dGZ3hGVEFUQmdOVkJBY01ERVJsWm1GMWJIUWdRMmwwZVRFY01Cb0dBMVVFDQpDZ3dUUkdWbVlYVnNkQ0JEYjIxd1lXNTVJRXgwWkRBZUZ3MHlNakEzTVRrd09UTXlNek5hRncweU1qQTRNVGd3DQpPVE15TXpOYU1FSXhDekFKQmdOVkJBWVRBbGhZTVJVd0V3WURWUVFIREF4RVpXWmhkV3gwSUVOcGRIa3hIREFhDQpCZ05WQkFvTUUwUmxabUYxYkhRZ1EyOXRjR0Z1ZVNCTWRHUXdnZ0lpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElDDQpEd0F3Z2dJS0FvSUNBUUNxVFpxMWZRcC9vYkdlenhES0o3OVB3Ny94azJwellualNzMlkzb1ZYSm5sRmM4YjVlDQpma2ZZQnY2bndscW1keW5PL2phWFBaQmRQSS82aFdOUDBkdVhadEtWU0NCUUpyZzEyOGNXb3F0MGNTN3pLb1VpDQpvcU1tQ0QvRXVBeFFNZjhRZDF2c1gvVllkZ0poVTZBRXJLZEpIaXpFOUJtUkNkTDBGMW1OVW55Rk82UnRtWFZUDQpidkxsTDVYeTc2R0FaQVBLOFB4aVlDa0NtbDdxN0VnTWNiOXlLWldCYmlxQ3VkTXE5TGJLNmdKNzF6YkZnSXV4DQo1L1pXK2JraTB2RlplWk9ZODUxb1psckFUNzJvMDI4NHNTWW9uN0pHZVZkY3NoUnh5R1VpSFpSTzdkaXZVTDVTDQpmM2JmSDFYbWY1ZDQzT0NWTWRuUUV2NWVaOG8zeWVLa3ZrbkZQUGVJMU9BbjdGbDlFRVNNR2dhOGFaSG1URSttDQpsLzlMSmdDYjBnQmtPT0M0WnV4bWh2aERKV1EzWnJCS3pMQlNUZXN0NWlLNVlwcXRWVVk2THRyRW9FelVTK1lsDQpwWndXY2VQWHlHeHM5ZURsR3lNVmQraW15Y3NTU1UvVno2Mmx6MnZCS21NTXBkYldDQWhud0RsRTVqU2dyMjRRDQp0eGNXLys2N3d5KzhuQlI3UXdqVTFITndVRjBzeERWdEwrZ1NHVERnSEVZSlhZelYvT05zMy94TkpoVFNPSkxNDQpoeXNVdyttaGdackdhbUdXcHVIVU1DUitvTWJzMTc1UkcrQjJnUFFHVytPTjJnUTRyOXN2b0ZBNHBBQm8xd1dLDQpRYjRhY3pmeVVscElBOVFoSmFsZEY3S3dPSHVlV3gwRUNrNXg0T2tvVDBvWVp0dzFiR0JjRGtaSmF3SURBUUFCDQpvMU13VVRBZEJnTlZIUTRFRmdRVW90UlNIUm9IWTEyRFZ4R0NCdEhpb1g2ZmVFQXdId1lEVlIwakJCZ3dGb0FVDQpvdFJTSFJvSFkxMkRWeEdDQnRIaW9YNmZlRUF3RHdZRFZSMFRBUUgvQkFVd0F3RUIvekFOQmdrcWhraUc5dzBCDQpBUXNGQUFPQ0FnRUFSbkpsWWRjMTFHd0VxWnh6RDF2R3BDR2pDN2VWTlQ3aVY1d3IybXlybHdPYi9aUWFEa0xYDQpvVStaOVVXT1VlSXJTdzUydDdmQUpvVVAwSm5iYkMveVIrU1lqUGhvUXNiVHduOTc2ZldBWTduM3FMOXhCd1Y0DQphek41OXNjeUp0dlhMeUtOL2N5ak1ReDRLajBIMFg0bWJ6bzVZNUtzWWtYVU0vOEFPdWZMcEd0S1NGVGgrSEFDDQpab1Q5YnZHS25adnNHd0tYZFF0Wnh0akhaUjVqK3U3ZGtQOTJBT051RFNabS8rWVV4b2tBK09JbzdSR3BwSHNXDQo1ZTdNY0FTVXRtb1FORXd6dVFoVkJaRWQ1OGtKYjUrV0VWbGNzanlXNnRTbzErZ25tTWNqR1BsMWgxR2hVbjV4DQpFY0lWRnBIWXM5YWo1NmpBSjk1MVQvZjhMaWxmTlVnanBLQ0c1bnl0SUt3emxhOHNtdGlPdm1UNEpYbXBwSkI2DQo4bmdHRVluVjUrUTYwWFJ2OEhSSGp1VG9CRHVhaERrVDA2R1JGODU1d09FR2V4bkZpMXZYWUxLVllWb1V2MXRKDQo4dVdUR1pwNllDSVJldlBqbzg5ZytWTlJSaVFYUThJd0dybXE5c0RoVTlqTjA0SjdVL1RvRDFpNHE3VnlsRUc5DQorV1VGNkNLaEdBeTJIaEhwVncyTGFoOS9lUzdZMUZ1YURrWmhPZG1laG1BOCtqdHNZamJadnR5Mm1SWlF0UUZzDQpUU1VUUjREbUR2bVVPRVRmeStpRHdzK2RkWXVNTnJGeVVYV2dkMnpBQU4ydVl1UHFGY2pRcFNPODFzVTJTU3R3DQoxVzAyeUtYOGJEYmZFdjBzbUh3UzliQnFlSGo5NEM1Mjg0YXpsdTBmaUdpTm1OUEM4ckJLRmhBPQ0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQ== - service: - name: metallb-webhook-service - namespace: {{ .Release.Namespace }} - path: /convert - conversionReviewVersions: - - v1beta1 - - v1beta2 - group: metallb.io - names: - kind: BGPPeer - listKind: BGPPeerList - plural: bgppeers - singular: bgppeer - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.peerAddress - name: Address - type: string - - jsonPath: .spec.peerASN - name: ASN - type: string - - jsonPath: .spec.bfdProfile - name: BFD Profile - type: string - - jsonPath: .spec.ebgpMultiHop - name: Multi Hops - type: string - deprecated: true - deprecationWarning: v1beta1 is deprecated, please use v1beta2 - name: v1beta1 - schema: - openAPIV3Schema: - description: BGPPeer is the Schema for the peers API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: BGPPeerSpec defines the desired state of Peer. - properties: - bfdProfile: - type: string - ebgpMultiHop: - description: EBGP peer is multi-hops away - type: boolean - holdTime: - description: Requested BGP hold time, per RFC4271. - type: string - keepaliveTime: - description: Requested BGP keepalive time, per RFC4271. - type: string - myASN: - description: AS number to use for the local end of the session. - format: int32 - maximum: 4294967295 - minimum: 0 - type: integer - nodeSelectors: - description: |- - Only connect to this peer on nodes that match one of these - selectors. - items: - properties: - matchExpressions: - items: - properties: - key: - type: string - operator: - type: string - values: - items: - type: string - minItems: 1 - type: array - required: - - key - - operator - - values - type: object - type: array - matchLabels: - additionalProperties: - type: string - type: object - type: object - type: array - password: - description: Authentication password for routers enforcing TCP MD5 authenticated sessions - type: string - peerASN: - description: AS number to expect from the remote end of the session. - format: int32 - maximum: 4294967295 - minimum: 0 - type: integer - peerAddress: - description: Address to dial when establishing the session. - type: string - peerPort: - description: Port to dial when establishing the session. - maximum: 16384 - minimum: 0 - type: integer - routerID: - description: BGP router ID to advertise to the peer - type: string - sourceAddress: - description: Source address to use when establishing the session. - type: string - required: - - myASN - - peerASN - - peerAddress - type: object - status: - description: BGPPeerStatus defines the observed state of Peer. - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.peerAddress - name: Address - type: string - - jsonPath: .spec.peerASN - name: ASN - type: string - - jsonPath: .spec.bfdProfile - name: BFD Profile - type: string - - jsonPath: .spec.ebgpMultiHop - name: Multi Hops - type: string - name: v1beta2 - schema: - openAPIV3Schema: - description: BGPPeer is the Schema for the peers API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: BGPPeerSpec defines the desired state of Peer. - properties: - bfdProfile: - description: The name of the BFD Profile to be used for the BFD session associated to the BGP session. If not set, the BFD session won't be set up. - type: string - connectTime: - description: Requested BGP connect time, controls how long BGP waits between connection attempts to a neighbor. - type: string - x-kubernetes-validations: - - message: connect time should be between 1 seconds to 65535 - rule: duration(self).getSeconds() >= 1 && duration(self).getSeconds() <= 65535 - - message: connect time should contain a whole number of seconds - rule: duration(self).getMilliseconds() % 1000 == 0 - disableMP: - default: false - description: To set if we want to disable MP BGP that will separate IPv4 and IPv6 route exchanges into distinct BGP sessions. - type: boolean - dynamicASN: - description: |- - DynamicASN detects the AS number to use for the remote end of the session - without explicitly setting it via the ASN field. Limited to: - internal - if the neighbor's ASN is different than MyASN connection is denied. - external - if the neighbor's ASN is the same as MyASN the connection is denied. - ASN and DynamicASN are mutually exclusive and one of them must be specified. - enum: - - internal - - external - type: string - ebgpMultiHop: - description: To set if the BGPPeer is multi-hops away. Needed for FRR mode only. - type: boolean - enableGracefulRestart: - description: |- - EnableGracefulRestart allows BGP peer to continue to forward data packets - along known routes while the routing protocol information is being - restored. This field is immutable because it requires restart of the BGP - session. Supported for FRR mode only. - type: boolean - x-kubernetes-validations: - - message: EnableGracefulRestart cannot be changed after creation - rule: self == oldSelf - holdTime: - description: Requested BGP hold time, per RFC4271. - type: string - keepaliveTime: - description: Requested BGP keepalive time, per RFC4271. - type: string - myASN: - description: AS number to use for the local end of the session. - format: int32 - maximum: 4294967295 - minimum: 0 - type: integer - nodeSelectors: - description: |- - Only connect to this peer on nodes that match one of these - selectors. - items: - description: |- - A label selector is a label query over a set of resources. The result of matchLabels and - matchExpressions are ANDed. An empty label selector matches all objects. A null - label selector matches no objects. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - type: array - password: - description: Authentication password for routers enforcing TCP MD5 authenticated sessions - type: string - passwordSecret: - description: |- - passwordSecret is name of the authentication secret for BGP Peer. - the secret must be of type "kubernetes.io/basic-auth", and created in the - same namespace as the MetalLB deployment. The password is stored in the - secret as the key "password". - properties: - name: - description: name is unique within a namespace to reference a secret resource. - type: string - namespace: - description: namespace defines the space within which the secret name must be unique. - type: string - type: object - x-kubernetes-map-type: atomic - peerASN: - description: |- - AS number to expect from the remote end of the session. - ASN and DynamicASN are mutually exclusive and one of them must be specified. - format: int32 - maximum: 4294967295 - minimum: 0 - type: integer - peerAddress: - description: Address to dial when establishing the session. - type: string - peerPort: - default: 179 - description: Port to dial when establishing the session. - maximum: 16384 - minimum: 0 - type: integer - routerID: - description: BGP router ID to advertise to the peer - type: string - sourceAddress: - description: Source address to use when establishing the session. - type: string - vrf: - description: |- - To set if we want to peer with the BGPPeer using an interface belonging to - a host vrf - type: string - required: - - myASN - - peerAddress - type: object - status: - description: BGPPeerStatus defines the observed state of Peer. - type: object - type: object - served: true - storage: true - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.3 - name: communities.metallb.io -spec: - group: metallb.io - names: - kind: Community - listKind: CommunityList - plural: communities - singular: community - scope: Namespaced - versions: - - name: v1beta1 - schema: - openAPIV3Schema: - description: |- - Community is a collection of aliases for communities. - Users can define named aliases to be used in the BGPPeer CRD. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: CommunitySpec defines the desired state of Community. - properties: - communities: - items: - properties: - name: - description: The name of the alias for the community. - type: string - value: - description: |- - The BGP community value corresponding to the given name. Can be a standard community of the form 1234:1234 - or a large community of the form large:1234:1234:1234. - type: string - type: object - type: array - type: object - status: - description: CommunityStatus defines the observed state of Community. - type: object - type: object - served: true - storage: true - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.3 - name: ipaddresspools.metallb.io -spec: - group: metallb.io - names: - kind: IPAddressPool - listKind: IPAddressPoolList - plural: ipaddresspools - singular: ipaddresspool - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.autoAssign - name: Auto Assign - type: boolean - - jsonPath: .spec.avoidBuggyIPs - name: Avoid Buggy IPs - type: boolean - - jsonPath: .spec.addresses - name: Addresses - type: string - name: v1beta1 - schema: - openAPIV3Schema: - description: |- - IPAddressPool represents a pool of IP addresses that can be allocated - to LoadBalancer services. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: IPAddressPoolSpec defines the desired state of IPAddressPool. - properties: - addresses: - description: |- - A list of IP address ranges over which MetalLB has authority. - You can list multiple ranges in a single pool, they will all share the - same settings. Each range can be either a CIDR prefix, or an explicit - start-end range of IPs. - items: - type: string - type: array - autoAssign: - default: true - description: |- - AutoAssign flag used to prevent MetallB from automatic allocation - for a pool. - type: boolean - avoidBuggyIPs: - default: false - description: |- - AvoidBuggyIPs prevents addresses ending with .0 and .255 - to be used by a pool. - type: boolean - serviceAllocation: - description: |- - AllocateTo makes ip pool allocation to specific namespace and/or service. - The controller will use the pool with lowest value of priority in case of - multiple matches. A pool with no priority set will be used only if the - pools with priority can't be used. If multiple matching IPAddressPools are - available it will check for the availability of IPs sorting the matching - IPAddressPools by priority, starting from the highest to the lowest. If - multiple IPAddressPools have the same priority, choice will be random. - properties: - namespaceSelectors: - description: |- - NamespaceSelectors list of label selectors to select namespace(s) for ip pool, - an alternative to using namespace list. - items: - description: |- - A label selector is a label query over a set of resources. The result of matchLabels and - matchExpressions are ANDed. An empty label selector matches all objects. A null - label selector matches no objects. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - type: array - namespaces: - description: Namespaces list of namespace(s) on which ip pool can be attached. - items: - type: string - type: array - priority: - description: Priority priority given for ip pool while ip allocation on a service. - type: integer - serviceSelectors: - description: |- - ServiceSelectors list of label selector to select service(s) for which ip pool - can be used for ip allocation. - items: - description: |- - A label selector is a label query over a set of resources. The result of matchLabels and - matchExpressions are ANDed. An empty label selector matches all objects. A null - label selector matches no objects. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - type: array - type: object - required: - - addresses - type: object - status: - description: IPAddressPoolStatus defines the observed state of IPAddressPool. - type: object - required: - - spec - type: object - served: true - storage: true - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.3 - name: l2advertisements.metallb.io -spec: - group: metallb.io - names: - kind: L2Advertisement - listKind: L2AdvertisementList - plural: l2advertisements - singular: l2advertisement - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.ipAddressPools - name: IPAddressPools - type: string - - jsonPath: .spec.ipAddressPoolSelectors - name: IPAddressPool Selectors - type: string - - jsonPath: .spec.interfaces - name: Interfaces - type: string - - jsonPath: .spec.nodeSelectors - name: Node Selectors - priority: 10 - type: string - name: v1beta1 - schema: - openAPIV3Schema: - description: |- - L2Advertisement allows to advertise the LoadBalancer IPs provided - by the selected pools via L2. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: L2AdvertisementSpec defines the desired state of L2Advertisement. - properties: - interfaces: - description: |- - A list of interfaces to announce from. The LB IP will be announced only from these interfaces. - If the field is not set, we advertise from all the interfaces on the host. - items: - type: string - type: array - ipAddressPoolSelectors: - description: |- - A selector for the IPAddressPools which would get advertised via this advertisement. - If no IPAddressPool is selected by this or by the list, the advertisement is applied to all the IPAddressPools. - items: - description: |- - A label selector is a label query over a set of resources. The result of matchLabels and - matchExpressions are ANDed. An empty label selector matches all objects. A null - label selector matches no objects. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - type: array - ipAddressPools: - description: The list of IPAddressPools to advertise via this advertisement, selected by name. - items: - type: string - type: array - nodeSelectors: - description: NodeSelectors allows to limit the nodes to announce as next hops for the LoadBalancer IP. When empty, all the nodes having are announced as next hops. - items: - description: |- - A label selector is a label query over a set of resources. The result of matchLabels and - matchExpressions are ANDed. An empty label selector matches all objects. A null - label selector matches no objects. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - type: array - type: object - status: - description: L2AdvertisementStatus defines the observed state of L2Advertisement. - type: object - type: object - served: true - storage: true - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.3 - name: servicel2statuses.metallb.io -spec: - group: metallb.io - names: - kind: ServiceL2Status - listKind: ServiceL2StatusList - plural: servicel2statuses - singular: servicel2status - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .status.node - name: Allocated Node - type: string - - jsonPath: .status.serviceName - name: Service Name - type: string - - jsonPath: .status.serviceNamespace - name: Service Namespace - type: string - name: v1beta1 - schema: - openAPIV3Schema: - description: ServiceL2Status reveals the actual traffic status of loadbalancer services in layer2 mode. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: ServiceL2StatusSpec defines the desired state of ServiceL2Status. - type: object - status: - description: MetalLBServiceL2Status defines the observed state of ServiceL2Status. - properties: - interfaces: - description: Interfaces indicates the interfaces that receive the directed traffic - items: - description: InterfaceInfo defines interface info of layer2 announcement. - properties: - name: - description: Name the name of network interface card - type: string - type: object - type: array - node: - description: Node indicates the node that receives the directed traffic - type: string - x-kubernetes-validations: - - message: Value is immutable - rule: self == oldSelf - serviceName: - description: ServiceName indicates the service this status represents - type: string - x-kubernetes-validations: - - message: Value is immutable - rule: self == oldSelf - serviceNamespace: - description: ServiceNamespace indicates the namespace of the service - type: string - x-kubernetes-validations: - - message: Value is immutable - rule: self == oldSelf - type: object - type: object - served: true - storage: true - subresources: - status: {} diff --git a/metallb/charts/frr-k8s/Chart.lock b/metallb/charts/frr-k8s/Chart.lock deleted file mode 100644 index 913833f..0000000 --- a/metallb/charts/frr-k8s/Chart.lock +++ /dev/null @@ -1,6 +0,0 @@ -dependencies: -- name: crds - repository: "" - version: 0.0.16 -digest: sha256:b54ee64c5e61f1dd38e89efc87ebd1e36cdb7c4dd7c897d9985040dccd713dba -generated: "2024-11-22T11:40:47.152053909+01:00" diff --git a/metallb/charts/frr-k8s/Chart.yaml b/metallb/charts/frr-k8s/Chart.yaml deleted file mode 100644 index 385a95a..0000000 --- a/metallb/charts/frr-k8s/Chart.yaml +++ /dev/null @@ -1,16 +0,0 @@ -apiVersion: v2 -appVersion: v0.0.16 -dependencies: -- condition: crds.enabled - name: crds - repository: "" - version: 0.0.16 -description: A cloud native wrapper of FRR -home: https://metallb.universe.tf -icon: https://metallb.universe.tf/images/logo/metallb-white.png -kubeVersion: '>= 1.19.0-0' -name: frr-k8s -sources: -- https://github.com/metallb/frr-k8s -type: application -version: 0.0.16 diff --git a/metallb/charts/frr-k8s/README.md b/metallb/charts/frr-k8s/README.md deleted file mode 100644 index c90d353..0000000 --- a/metallb/charts/frr-k8s/README.md +++ /dev/null @@ -1,96 +0,0 @@ -# frr-k8s - -![Version: 0.0.16](https://img.shields.io/badge/Version-0.0.16-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.0.16](https://img.shields.io/badge/AppVersion-v0.0.16-informational?style=flat-square) - -A cloud native wrapper of FRR - -**Homepage:** - -## Source Code - -* - -## Requirements - -Kubernetes: `>= 1.19.0-0` - -| Repository | Name | Version | -|------------|------|---------| -| | crds | 0.0.16 | - -## Values - -| Key | Type | Default | Description | -|-----|------|---------|-------------| -| crds.enabled | bool | `true` | | -| crds.validationFailurePolicy | string | `"Fail"` | | -| frrk8s.affinity | object | `{}` | | -| frrk8s.alwaysBlock | string | `""` | | -| frrk8s.disableCertRotation | bool | `false` | | -| frrk8s.frr.acceptIncomingBGPConnections | bool | `false` | | -| frrk8s.frr.image.pullPolicy | string | `nil` | | -| frrk8s.frr.image.repository | string | `"quay.io/frrouting/frr"` | | -| frrk8s.frr.image.tag | string | `"9.1.0"` | | -| frrk8s.frr.metricsBindAddress | string | `"127.0.0.1"` | | -| frrk8s.frr.metricsPort | int | `7573` | | -| frrk8s.frr.resources | object | `{}` | | -| frrk8s.frr.secureMetricsPort | int | `9141` | | -| frrk8s.frrMetrics.resources | object | `{}` | | -| frrk8s.image.pullPolicy | string | `nil` | | -| frrk8s.image.repository | string | `"quay.io/metallb/frr-k8s"` | | -| frrk8s.image.tag | string | `nil` | | -| frrk8s.labels.app | string | `"frr-k8s"` | | -| frrk8s.livenessProbe.enabled | bool | `true` | | -| frrk8s.livenessProbe.failureThreshold | int | `3` | | -| frrk8s.livenessProbe.initialDelaySeconds | int | `10` | | -| frrk8s.livenessProbe.periodSeconds | int | `10` | | -| frrk8s.livenessProbe.successThreshold | int | `1` | | -| frrk8s.livenessProbe.timeoutSeconds | int | `1` | | -| frrk8s.logLevel | string | `"info"` | Controller log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none` | -| frrk8s.nodeSelector | object | `{}` | | -| frrk8s.podAnnotations | object | `{}` | | -| frrk8s.priorityClassName | string | `""` | | -| frrk8s.readinessProbe.enabled | bool | `true` | | -| frrk8s.readinessProbe.failureThreshold | int | `3` | | -| frrk8s.readinessProbe.initialDelaySeconds | int | `10` | | -| frrk8s.readinessProbe.periodSeconds | int | `10` | | -| frrk8s.readinessProbe.successThreshold | int | `1` | | -| frrk8s.readinessProbe.timeoutSeconds | int | `1` | | -| frrk8s.reloader.resources | object | `{}` | | -| frrk8s.resources | object | `{}` | | -| frrk8s.restartOnRotatorSecretRefresh | bool | `false` | | -| frrk8s.runtimeClassName | string | `""` | | -| frrk8s.serviceAccount.annotations | object | `{}` | | -| frrk8s.serviceAccount.create | bool | `true` | | -| frrk8s.serviceAccount.name | string | `""` | | -| frrk8s.startupProbe.enabled | bool | `true` | | -| frrk8s.startupProbe.failureThreshold | int | `30` | | -| frrk8s.startupProbe.periodSeconds | int | `5` | | -| frrk8s.tolerateMaster | bool | `true` | | -| frrk8s.tolerations | list | `[]` | | -| frrk8s.updateStrategy.type | string | `"RollingUpdate"` | | -| fullnameOverride | string | `""` | | -| nameOverride | string | `""` | | -| prometheus.metricsBindAddress | string | `"127.0.0.1"` | | -| prometheus.metricsPort | int | `7572` | | -| prometheus.metricsTLSSecret | string | `""` | | -| prometheus.namespace | string | `""` | | -| prometheus.rbacPrometheus | bool | `false` | | -| prometheus.rbacProxy.pullPolicy | string | `nil` | | -| prometheus.rbacProxy.repository | string | `"gcr.io/kubebuilder/kube-rbac-proxy"` | | -| prometheus.rbacProxy.tag | string | `"v0.12.0"` | | -| prometheus.scrapeAnnotations | bool | `false` | | -| prometheus.secureMetricsPort | int | `9140` | | -| prometheus.serviceAccount | string | `""` | | -| prometheus.serviceMonitor.additionalLabels | object | `{}` | | -| prometheus.serviceMonitor.annotations | object | `{}` | | -| prometheus.serviceMonitor.enabled | bool | `false` | | -| prometheus.serviceMonitor.interval | string | `nil` | | -| prometheus.serviceMonitor.jobLabel | string | `"app.kubernetes.io/name"` | | -| prometheus.serviceMonitor.metricRelabelings | list | `[]` | | -| prometheus.serviceMonitor.relabelings | list | `[]` | | -| prometheus.serviceMonitor.tlsConfig.insecureSkipVerify | bool | `true` | | -| rbac.create | bool | `true` | | - ----------------------------------------------- -Autogenerated from chart metadata using [helm-docs v1.10.0](https://github.com/norwoodj/helm-docs/releases/v1.10.0) diff --git a/metallb/charts/frr-k8s/charts/crds/Chart.yaml b/metallb/charts/frr-k8s/charts/crds/Chart.yaml deleted file mode 100644 index f5af05a..0000000 --- a/metallb/charts/frr-k8s/charts/crds/Chart.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: v2 -appVersion: v0.0.16 -description: FRR K8s CRDs -home: https://metallb.universe.tf -icon: https://metallb.universe.tf/images/logo/metallb-white.png -name: crds -sources: -- https://github.com/metallb/frr-k8s -type: application -version: 0.0.16 diff --git a/metallb/charts/frr-k8s/charts/crds/README.md b/metallb/charts/frr-k8s/charts/crds/README.md deleted file mode 100644 index 65e636c..0000000 --- a/metallb/charts/frr-k8s/charts/crds/README.md +++ /dev/null @@ -1,14 +0,0 @@ -# crds - -![Version: 0.0.0](https://img.shields.io/badge/Version-0.0.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: v0.0.0](https://img.shields.io/badge/AppVersion-v0.0.0-informational?style=flat-square) - -FRR-K8s CRDs - -**Homepage:** - -## Source Code - -* - ----------------------------------------------- -Autogenerated from chart metadata using [helm-docs v1.10.0](https://github.com/norwoodj/helm-docs/releases/v1.10.0) diff --git a/metallb/charts/frr-k8s/charts/crds/templates/frrk8s.metallb.io_frrconfigurations.yaml b/metallb/charts/frr-k8s/charts/crds/templates/frrk8s.metallb.io_frrconfigurations.yaml deleted file mode 100644 index 251143d..0000000 --- a/metallb/charts/frr-k8s/charts/crds/templates/frrk8s.metallb.io_frrconfigurations.yaml +++ /dev/null @@ -1,473 +0,0 @@ ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.14.0 - name: frrconfigurations.frrk8s.metallb.io -spec: - group: frrk8s.metallb.io - names: - kind: FRRConfiguration - listKind: FRRConfigurationList - plural: frrconfigurations - singular: frrconfiguration - scope: Namespaced - versions: - - name: v1beta1 - schema: - openAPIV3Schema: - description: FRRConfiguration is a piece of FRR configuration. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: FRRConfigurationSpec defines the desired state of FRRConfiguration. - properties: - bgp: - description: BGP is the configuration related to the BGP protocol. - properties: - bfdProfiles: - description: BFDProfiles is the list of bfd profiles to be used - when configuring the neighbors. - items: - description: |- - BFDProfile is the configuration related to the BFD protocol associated - to a BGP session. - properties: - detectMultiplier: - description: |- - Configures the detection multiplier to determine - packet loss. The remote transmission interval will be multiplied - by this value to determine the connection loss detection timer. - format: int32 - maximum: 255 - minimum: 2 - type: integer - echoInterval: - description: |- - Configures the minimal echo receive transmission - interval that this system is capable of handling in milliseconds. - Defaults to 50ms - format: int32 - maximum: 60000 - minimum: 10 - type: integer - echoMode: - description: |- - Enables or disables the echo transmission mode. - This mode is disabled by default, and not supported on multi - hops setups. - type: boolean - minimumTtl: - description: |- - For multi hop sessions only: configure the minimum - expected TTL for an incoming BFD control packet. - format: int32 - maximum: 254 - minimum: 1 - type: integer - name: - description: |- - The name of the BFD Profile to be referenced in other parts - of the configuration. - type: string - passiveMode: - description: |- - Mark session as passive: a passive session will not - attempt to start the connection and will wait for control packets - from peer before it begins replying. - type: boolean - receiveInterval: - description: |- - The minimum interval that this system is capable of - receiving control packets in milliseconds. - Defaults to 300ms. - format: int32 - maximum: 60000 - minimum: 10 - type: integer - transmitInterval: - description: |- - The minimum transmission interval (less jitter) - that this system wants to use to send BFD control packets in - milliseconds. Defaults to 300ms - format: int32 - maximum: 60000 - minimum: 10 - type: integer - required: - - name - type: object - type: array - routers: - description: Routers is the list of routers we want FRR to configure - (one per VRF). - items: - description: Router represent a neighbor router we want FRR - to connect to. - properties: - asn: - description: ASN is the AS number to use for the local end - of the session. - format: int32 - maximum: 4294967295 - minimum: 0 - type: integer - id: - description: ID is the BGP router ID - type: string - imports: - description: Imports is the list of imported VRFs we want - for this router / vrf. - items: - description: Import represents the possible imported VRFs - to a given router. - properties: - vrf: - description: Vrf is the vrf we want to import from - type: string - type: object - type: array - neighbors: - description: Neighbors is the list of neighbors we want - to establish BGP sessions with. - items: - description: Neighbor represents a BGP Neighbor we want - FRR to connect to. - properties: - address: - description: Address is the IP address to establish - the session with. - type: string - asn: - description: |- - ASN is the AS number to use for the local end of the session. - ASN and DynamicASN are mutually exclusive and one of them must be specified. - format: int32 - maximum: 4294967295 - minimum: 0 - type: integer - bfdProfile: - description: |- - BFDProfile is the name of the BFD Profile to be used for the BFD session associated - to the BGP session. If not set, the BFD session won't be set up. - type: string - connectTime: - description: Requested BGP connect time, controls - how long BGP waits between connection attempts to - a neighbor. - type: string - x-kubernetes-validations: - - message: connect time should be between 1 seconds - to 65535 - rule: duration(self).getSeconds() >= 1 && duration(self).getSeconds() - <= 65535 - - message: connect time should contain a whole number - of seconds - rule: duration(self).getMilliseconds() % 1000 == - 0 - disableMP: - default: false - description: To set if we want to disable MP BGP that - will separate IPv4 and IPv6 route exchanges into - distinct BGP sessions. - type: boolean - dynamicASN: - description: |- - DynamicASN detects the AS number to use for the local end of the session - without explicitly setting it via the ASN field. Limited to: - internal - if the neighbor's ASN is different than the router's the connection is denied. - external - if the neighbor's ASN is the same as the router's the connection is denied. - ASN and DynamicASN are mutually exclusive and one of them must be specified. - enum: - - internal - - external - type: string - ebgpMultiHop: - description: EBGPMultiHop indicates if the BGPPeer - is multi-hops away. - type: boolean - enableGracefulRestart: - description: |- - EnableGracefulRestart allows BGP peer to continue to forward data packets along - known routes while the routing protocol information is being restored. If - the session is already established, the configuration will have effect - after reconnecting to the peer - type: boolean - holdTime: - description: |- - HoldTime is the requested BGP hold time, per RFC4271. - Defaults to 180s. - type: string - keepaliveTime: - description: |- - KeepaliveTime is the requested BGP keepalive time, per RFC4271. - Defaults to 60s. - type: string - password: - description: |- - Password to be used for establishing the BGP session. - Password and PasswordSecret are mutually exclusive. - type: string - passwordSecret: - description: |- - PasswordSecret is name of the authentication secret for the neighbor. - the secret must be of type "kubernetes.io/basic-auth", and created in the - same namespace as the frr-k8s daemon. The password is stored in the - secret as the key "password". - Password and PasswordSecret are mutually exclusive. - properties: - name: - description: name is unique within a namespace - to reference a secret resource. - type: string - namespace: - description: namespace defines the space within - which the secret name must be unique. - type: string - type: object - x-kubernetes-map-type: atomic - port: - description: |- - Port is the port to dial when establishing the session. - Defaults to 179. - maximum: 16384 - minimum: 0 - type: integer - sourceaddress: - description: |- - SourceAddress is the IPv4 or IPv6 source address to use for the BGP - session to this neighbour, may be specified as either an IP address - directly or as an interface name - type: string - toAdvertise: - description: |- - ToAdvertise represents the list of prefixes to advertise to the given neighbor - and the associated properties. - properties: - allowed: - description: |- - Allowed is is the list of prefixes allowed to be propagated to - this neighbor. They must match the prefixes defined in the router. - properties: - mode: - default: filtered - description: |- - Mode is the mode to use when handling the prefixes. - When set to "filtered", only the prefixes in the given list will be allowed. - When set to "all", all the prefixes configured on the router will be allowed. - enum: - - all - - filtered - type: string - prefixes: - items: - type: string - type: array - type: object - withCommunity: - description: |- - PrefixesWithCommunity is a list of prefixes that are associated to a - bgp community when being advertised. The prefixes associated to a given local pref - must be in the prefixes allowed to be advertised. - items: - description: CommunityPrefixes is a list of - prefixes associated to a community. - properties: - community: - description: Community is the community - associated to the prefixes. - type: string - prefixes: - description: Prefixes is the list of prefixes - associated to the community. - format: cidr - items: - type: string - minItems: 1 - type: array - type: object - type: array - withLocalPref: - description: |- - PrefixesWithLocalPref is a list of prefixes that are associated to a local - preference when being advertised. The prefixes associated to a given local pref - must be in the prefixes allowed to be advertised. - items: - description: LocalPrefPrefixes is a list of - prefixes associated to a local preference. - properties: - localPref: - description: LocalPref is the local preference - associated to the prefixes. - format: int32 - type: integer - prefixes: - description: Prefixes is the list of prefixes - associated to the local preference. - format: cidr - items: - type: string - minItems: 1 - type: array - type: object - type: array - type: object - toReceive: - description: ToReceive represents the list of prefixes - to receive from the given neighbor. - properties: - allowed: - description: |- - Allowed is the list of prefixes allowed to be received from - this neighbor. - properties: - mode: - default: filtered - description: |- - Mode is the mode to use when handling the prefixes. - When set to "filtered", only the prefixes in the given list will be allowed. - When set to "all", all the prefixes configured on the router will be allowed. - enum: - - all - - filtered - type: string - prefixes: - items: - description: PrefixSelector is a filter - of prefixes to receive. - properties: - ge: - description: |- - The prefix length modifier. This selector accepts any matching prefix with length - greater or equal the given value. - format: int32 - maximum: 128 - minimum: 1 - type: integer - le: - description: |- - The prefix length modifier. This selector accepts any matching prefix with length - less or equal the given value. - format: int32 - maximum: 128 - minimum: 1 - type: integer - prefix: - format: cidr - type: string - type: object - type: array - type: object - type: object - required: - - address - type: object - type: array - prefixes: - description: Prefixes is the list of prefixes we want to - advertise from this router instance. - items: - type: string - type: array - vrf: - description: VRF is the host vrf used to establish sessions - from this router. - type: string - required: - - asn - type: object - type: array - type: object - nodeSelector: - description: |- - NodeSelector limits the nodes that will attempt to apply this config. - When specified, the configuration will be considered only on nodes - whose labels match the specified selectors. - When it is not specified all nodes will attempt to apply this config. - properties: - matchExpressions: - description: matchExpressions is a list of label selector requirements. - The requirements are ANDed. - items: - description: |- - A label selector requirement is a selector that contains values, a key, and an operator that - relates the key and values. - properties: - key: - description: key is the label key that the selector applies - to. - type: string - operator: - description: |- - operator represents a key's relationship to a set of values. - Valid operators are In, NotIn, Exists and DoesNotExist. - type: string - values: - description: |- - values is an array of string values. If the operator is In or NotIn, - the values array must be non-empty. If the operator is Exists or DoesNotExist, - the values array must be empty. This array is replaced during a strategic - merge patch. - items: - type: string - type: array - x-kubernetes-list-type: atomic - required: - - key - - operator - type: object - type: array - x-kubernetes-list-type: atomic - matchLabels: - additionalProperties: - type: string - description: |- - matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - x-kubernetes-map-type: atomic - raw: - description: |- - Raw is a snippet of raw frr configuration that gets appended to the - one rendered translating the type safe API. - properties: - priority: - description: |- - Priority is the order with this configuration is appended to the - bottom of the rendered configuration. A higher value means the - raw config is appended later in the configuration file. - type: integer - rawConfig: - description: |- - Config is a raw FRR configuration to be appended to the configuration - rendered via the k8s api. - type: string - type: object - type: object - status: - description: FRRConfigurationStatus defines the observed state of FRRConfiguration. - type: object - type: object - served: true - storage: true - subresources: - status: {} diff --git a/metallb/charts/frr-k8s/charts/crds/templates/frrk8s.metallb.io_frrnodestates.yaml b/metallb/charts/frr-k8s/charts/crds/templates/frrk8s.metallb.io_frrnodestates.yaml deleted file mode 100644 index e2bd77e..0000000 --- a/metallb/charts/frr-k8s/charts/crds/templates/frrk8s.metallb.io_frrnodestates.yaml +++ /dev/null @@ -1,65 +0,0 @@ ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.14.0 - name: frrnodestates.frrk8s.metallb.io -spec: - group: frrk8s.metallb.io - names: - kind: FRRNodeState - listKind: FRRNodeStateList - plural: frrnodestates - singular: frrnodestate - scope: Cluster - versions: - - name: v1beta1 - schema: - openAPIV3Schema: - description: FRRNodeState exposes the status of the FRR instance running on - each node. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: FRRNodeStateSpec defines the desired state of FRRNodeState. - type: object - status: - description: FRRNodeStateStatus defines the observed state of FRRNodeState. - properties: - lastConversionResult: - description: LastConversionResult is the status of the last translation - between the `FRRConfiguration`s resources and FRR's configuration, - contains "success" or an error. - type: string - lastReloadResult: - description: LastReloadResult represents the status of the last configuration - update operation by FRR, contains "success" or an error. - type: string - runningConfig: - description: RunningConfig represents the current FRR running config, - which is the configuration the FRR instance is currently running - with. - type: string - type: object - type: object - served: true - storage: true - subresources: - status: {} diff --git a/metallb/charts/frr-k8s/templates/NOTES.txt b/metallb/charts/frr-k8s/templates/NOTES.txt deleted file mode 100644 index 5b5b84a..0000000 --- a/metallb/charts/frr-k8s/templates/NOTES.txt +++ /dev/null @@ -1,4 +0,0 @@ -FRR-k8s is now running in the cluster. - -Now you can configure it via its CRs. Please refer to the frr-k8s official docs -on how to use the CRs. diff --git a/metallb/charts/frr-k8s/templates/_helpers.tpl b/metallb/charts/frr-k8s/templates/_helpers.tpl deleted file mode 100644 index 4e35f6f..0000000 --- a/metallb/charts/frr-k8s/templates/_helpers.tpl +++ /dev/null @@ -1,63 +0,0 @@ -{{/* vim: set filetype=mustache: */}} -{{/* -Expand the name of the chart. -*/}} -{{- define "frrk8s.name" -}} -{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{/* -Create a default fully qualified app name. -We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). -If release name contains chart name it will be used as a full name. -*/}} -{{- define "frrk8s.fullname" -}} -{{- if .Values.fullnameOverride }} -{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- $name := default .Chart.Name .Values.nameOverride }} -{{- if contains $name .Release.Name }} -{{- .Release.Name | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} -{{- end }} -{{- end }} -{{- end }} - -{{/* -Create chart name and version as used by the chart label. -*/}} -{{- define "frrk8s.chart" -}} -{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{/* -Common labels -*/}} -{{- define "frrk8s.labels" -}} -helm.sh/chart: {{ include "frrk8s.chart" . }} -{{ include "frrk8s.selectorLabels" . }} -{{- if .Chart.AppVersion }} -app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} -{{- end }} -app.kubernetes.io/managed-by: {{ .Release.Service }} -{{- end }} - -{{/* -Selector labels -*/}} -{{- define "frrk8s.selectorLabels" -}} -app.kubernetes.io/name: {{ include "frrk8s.name" . }} -app.kubernetes.io/instance: {{ .Release.Name }} -{{- end }} - -{{/* -Create the name of the frrk8s service account to use -*/}} -{{- define "frrk8s.serviceAccountName" -}} -{{- if .Values.frrk8s.serviceAccount.create }} -{{- default (printf "%s-controller" (include "frrk8s.fullname" .)) .Values.frrk8s.serviceAccount.name }} -{{- else }} -{{- default "default" .Values.frrk8s.serviceAccount.name }} -{{- end }} -{{- end }} diff --git a/metallb/charts/frr-k8s/templates/controller.yaml b/metallb/charts/frr-k8s/templates/controller.yaml deleted file mode 100644 index 1dedcf2..0000000 --- a/metallb/charts/frr-k8s/templates/controller.yaml +++ /dev/null @@ -1,430 +0,0 @@ -# FRR expects to have these files owned by frr:frr on startup. -# Having them in a ConfigMap allows us to modify behaviors: for example enabling more daemons on startup. -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ template "frrk8s.fullname" . }}-frr-startup - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "frrk8s.labels" . | nindent 4 }} - app.kubernetes.io/component: frr-k8s -data: - daemons: | - # This file tells the frr package which daemons to start. - # - # Sample configurations for these daemons can be found in - # /usr/share/doc/frr/examples/. - # - # ATTENTION: - # - # When activating a daemon for the first time, a config file, even if it is - # empty, has to be present *and* be owned by the user and group "frr", else - # the daemon will not be started by /etc/init.d/frr. The permissions should - # be u=rw,g=r,o=. - # When using "vtysh" such a config file is also needed. It should be owned by - # group "frrvty" and set to ug=rw,o= though. Check /etc/pam.d/frr, too. - # - # The watchfrr and zebra daemons are always started. - # - bgpd=yes - ospfd=no - ospf6d=no - ripd=no - ripngd=no - isisd=no - pimd=no - ldpd=no - nhrpd=no - eigrpd=no - babeld=no - sharpd=no - pbrd=no - bfdd=yes - fabricd=no - vrrpd=no - - # - # If this option is set the /etc/init.d/frr script automatically loads - # the config via "vtysh -b" when the servers are started. - # Check /etc/pam.d/frr if you intend to use "vtysh"! - # - vtysh_enable=yes - zebra_options=" -A 127.0.0.1 -s 90000000" - bgpd_options=" -A 127.0.0.1 {{ if not .Values.frrk8s.frr.acceptIncomingBGPConnections }} -p 0 {{- end }}" - ospfd_options=" -A 127.0.0.1" - ospf6d_options=" -A ::1" - ripd_options=" -A 127.0.0.1" - ripngd_options=" -A ::1" - isisd_options=" -A 127.0.0.1" - pimd_options=" -A 127.0.0.1" - ldpd_options=" -A 127.0.0.1" - nhrpd_options=" -A 127.0.0.1" - eigrpd_options=" -A 127.0.0.1" - babeld_options=" -A 127.0.0.1" - sharpd_options=" -A 127.0.0.1" - pbrd_options=" -A 127.0.0.1" - staticd_options="-A 127.0.0.1" - bfdd_options=" -A 127.0.0.1" - fabricd_options="-A 127.0.0.1" - vrrpd_options=" -A 127.0.0.1" - - # configuration profile - # - #frr_profile="traditional" - #frr_profile="datacenter" - - # - # This is the maximum number of FD's that will be available. - # Upon startup this is read by the control files and ulimit - # is called. Uncomment and use a reasonable value for your - # setup if you are expecting a large number of peers in - # say BGP. - #MAX_FDS=1024 - - # The list of daemons to watch is automatically generated by the init script. - #watchfrr_options="" - - # for debugging purposes, you can specify a "wrap" command to start instead - # of starting the daemon directly, e.g. to use valgrind on ospfd: - # ospfd_wrap="/usr/bin/valgrind" - # or you can use "all_wrap" for all daemons, e.g. to use perf record: - # all_wrap="/usr/bin/perf record --call-graph -" - # the normal daemon command is added to this at the end. - vtysh.conf: |+ - service integrated-vtysh-config - frr.conf: |+ - ! This file gets overriden the first time the speaker renders a config. - ! So anything configured here is only temporary. - frr version 8.0 - frr defaults traditional - hostname Router - line vty - log file /etc/frr/frr.log informational ---- -apiVersion: apps/v1 -kind: DaemonSet -metadata: - name: {{ template "frrk8s.fullname" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "frrk8s.labels" . | nindent 4 }} - app.kubernetes.io/component: frr-k8s - {{- range $key, $value := .Values.frrk8s.labels }} - {{ $key }}: {{ $value | quote }} - {{- end }} -spec: - {{- if .Values.frrk8s.updateStrategy }} - updateStrategy: {{- toYaml .Values.frrk8s.updateStrategy | nindent 4 }} - {{- end }} - selector: - matchLabels: - {{- include "frrk8s.selectorLabels" . | nindent 6 }} - app.kubernetes.io/component: frr-k8s - template: - metadata: - labels: - {{- include "frrk8s.selectorLabels" . | nindent 8 }} - app.kubernetes.io/component: frr-k8s - {{- range $key, $value := .Values.frrk8s.labels }} - {{ $key }}: {{ $value | quote }} - {{- end }} - spec: - {{- if .Values.frrk8s.runtimeClassName }} - runtimeClassName: {{ .Values.frrk8s.runtimeClassName }} - {{- end }} - {{- with .Values.imagePullSecrets }} - imagePullSecrets: - {{- toYaml . | nindent 8 }} - {{- end }} - serviceAccountName: {{ template "frrk8s.serviceAccountName" . }} - terminationGracePeriodSeconds: 0 - hostNetwork: true - volumes: - - name: frr-sockets - emptyDir: {} - - name: frr-startup - configMap: - name: {{ template "frrk8s.fullname" . }}-frr-startup - - name: frr-conf - emptyDir: {} - - name: reloader - emptyDir: {} - - name: metrics - emptyDir: {} - {{- if .Values.prometheus.metricsTLSSecret }} - - name: metrics-certs - secret: - secretName: {{ .Values.prometheus.metricsTLSSecret }} - {{- end }} - initContainers: - # Copies the initial config files with the right permissions to the shared volume. - - name: cp-frr-files - image: {{ .Values.frrk8s.frr.image.repository }}:{{ .Values.frrk8s.frr.image.tag | default .Chart.AppVersion }} - securityContext: - runAsUser: 100 - runAsGroup: 101 - command: ["/bin/sh", "-c", "cp -rLf /tmp/frr/* /etc/frr/"] - volumeMounts: - - name: frr-startup - mountPath: /tmp/frr - - name: frr-conf - mountPath: /etc/frr - # Copies the reloader to the shared volume between the speaker and reloader. - - name: cp-reloader - image: {{ .Values.frrk8s.image.repository }}:{{ .Values.frrk8s.image.tag | default .Chart.AppVersion }} - command: ["/bin/sh", "-c", "cp -f /frr-reloader.sh /etc/frr_reloader/"] - volumeMounts: - - name: reloader - mountPath: /etc/frr_reloader - # Copies the metrics exporter - - name: cp-metrics - image: {{ .Values.frrk8s.image.repository }}:{{ .Values.frrk8s.image.tag | default .Chart.AppVersion }} - command: ["/bin/sh", "-c", "cp -f /frr-metrics /etc/frr_metrics/"] - volumeMounts: - - name: metrics - mountPath: /etc/frr_metrics - shareProcessNamespace: true - containers: - - name: controller - image: {{ .Values.frrk8s.image.repository }}:{{ .Values.frrk8s.image.tag | default .Chart.AppVersion }} - {{- if .Values.frrk8s.image.pullPolicy }} - imagePullPolicy: {{ .Values.frrk8s.image.pullPolicy }} - {{- end }} - command: - - /frr-k8s - args: - - "--node-name=$(NODE_NAME)" - - "--namespace=$(NAMESPACE)" - - "--metrics-bind-address={{.Values.prometheus.metricsBindAddress}}:{{ .Values.prometheus.metricsPort }}" - {{- with .Values.frrk8s.logLevel }} - - --log-level={{ . }} - {{- end }} - {{- if .Values.frrk8s.alwaysBlock }} - - --always-block={{ .Values.frrk8s.alwaysBlock }} - {{- end }} - env: - - name: FRR_CONFIG_FILE - value: /etc/frr_reloader/frr.conf - - name: FRR_RELOADER_PID_FILE - value: /etc/frr_reloader/reloader.pid - - name: NODE_NAME - valueFrom: - fieldRef: - fieldPath: spec.nodeName - - name: NAMESPACE - valueFrom: - fieldRef: - fieldPath: metadata.namespace - ports: - - containerPort: {{ .Values.prometheus.metricsPort }} - name: monitoring - {{- if .Values.frrk8s.livenessProbe.enabled }} - livenessProbe: - httpGet: - path: /metrics - port: monitoring - host: {{ .Values.prometheus.metricsBindAddress }} - initialDelaySeconds: {{ .Values.frrk8s.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.frrk8s.livenessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.frrk8s.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.frrk8s.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.frrk8s.livenessProbe.failureThreshold }} - {{- end }} - {{- if .Values.frrk8s.readinessProbe.enabled }} - readinessProbe: - httpGet: - path: /metrics - port: monitoring - host: {{ .Values.prometheus.metricsBindAddress }} - initialDelaySeconds: {{ .Values.frrk8s.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.frrk8s.readinessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.frrk8s.readinessProbe.timeoutSeconds }} - successThreshold: {{ .Values.frrk8s.readinessProbe.successThreshold }} - failureThreshold: {{ .Values.frrk8s.readinessProbe.failureThreshold }} - {{- end }} - {{- with .Values.frrk8s.resources }} - resources: - {{- toYaml . | nindent 10 }} - {{- end }} - securityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: - - ALL - add: - - NET_RAW - volumeMounts: - - name: reloader - mountPath: /etc/frr_reloader - - name: frr - securityContext: - capabilities: - add: - - NET_ADMIN - - NET_RAW - - SYS_ADMIN - - NET_BIND_SERVICE - image: {{ .Values.frrk8s.frr.image.repository }}:{{ .Values.frrk8s.frr.image.tag | default .Chart.AppVersion }} - {{- if .Values.frrk8s.frr.image.pullPolicy }} - imagePullPolicy: {{ .Values.frrk8s.frr.image.pullPolicy }} - {{- end }} - env: - - name: TINI_SUBREAPER - value: "true" - volumeMounts: - - name: frr-sockets - mountPath: /var/run/frr - - name: frr-conf - mountPath: /etc/frr - # The command is FRR's default entrypoint & waiting for the log file to appear and tailing it. - # If the log file isn't created in 60 seconds the tail fails and the container is restarted. - # This workaround is needed to have the frr logs as part of kubectl logs -c frr < controller_pod_name >. - command: - - /bin/sh - - -c - - | - /sbin/tini -- /usr/lib/frr/docker-start & - attempts=0 - until [[ -f /etc/frr/frr.log || $attempts -eq 60 ]]; do - sleep 1 - attempts=$(( $attempts + 1 )) - done - tail -f /etc/frr/frr.log - {{- with .Values.frrk8s.frr.resources }} - resources: - {{- toYaml . | nindent 12 }} - {{- end }} - {{- if .Values.frrk8s.livenessProbe.enabled }} - livenessProbe: - httpGet: - path: /livez - port: {{ .Values.frrk8s.frr.metricsPort }} - host: {{ .Values.frrk8s.frr.metricsBindAddress }} - periodSeconds: {{ .Values.frrk8s.livenessProbe.periodSeconds }} - failureThreshold: {{ .Values.frrk8s.livenessProbe.failureThreshold }} - {{- end }} - {{- if .Values.frrk8s.startupProbe.enabled }} - startupProbe: - httpGet: - path: /livez - port: {{ .Values.frrk8s.frr.metricsPort }} - host: {{ .Values.frrk8s.frr.metricsBindAddress }} - failureThreshold: {{ .Values.frrk8s.startupProbe.failureThreshold }} - periodSeconds: {{ .Values.frrk8s.startupProbe.periodSeconds }} - {{- end }} - - name: reloader - image: {{ .Values.frrk8s.frr.image.repository }}:{{ .Values.frrk8s.frr.image.tag | default .Chart.AppVersion }} - {{- if .Values.frrk8s.frr.image.pullPolicy }} - imagePullPolicy: {{ .Values.frrk8s.frr.image.pullPolicy }} - {{- end }} - command: ["/etc/frr_reloader/frr-reloader.sh"] - volumeMounts: - - name: frr-sockets - mountPath: /var/run/frr - - name: frr-conf - mountPath: /etc/frr - - name: reloader - mountPath: /etc/frr_reloader - {{- with .Values.frrk8s.reloader.resources }} - resources: - {{- toYaml . | nindent 12 }} - {{- end }} - - name: frr-metrics - image: {{ .Values.frrk8s.frr.image.repository }}:{{ .Values.frrk8s.frr.image.tag | default .Chart.AppVersion }} - command: ["/etc/frr_metrics/frr-metrics"] - args: - - --metrics-port={{ .Values.frrk8s.frr.metricsPort }} - - --metrics-bind-address={{ .Values.frrk8s.frr.metricsBindAddress }} - ports: - - containerPort: {{ .Values.frrk8s.frr.metricsPort }} - name: monitoring - volumeMounts: - - name: frr-sockets - mountPath: /var/run/frr - - name: frr-conf - mountPath: /etc/frr - - name: metrics - mountPath: /etc/frr_metrics - {{- with .Values.frrk8s.frrMetrics.resources }} - resources: - {{- toYaml . | nindent 12 }} - {{- end }} - - name: kube-rbac-proxy - image: {{ .Values.prometheus.rbacProxy.repository }}:{{ .Values.prometheus.rbacProxy.tag }} - imagePullPolicy: {{ .Values.prometheus.rbacProxy.pullPolicy }} - args: - - --logtostderr - - --secure-listen-address=:{{ .Values.prometheus.secureMetricsPort }} - - --upstream=http://{{.Values.prometheus.metricsBindAddress}}:{{ .Values.prometheus.metricsPort }}/ - - --tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - {{- if .Values.prometheus.metricsTLSSecret }} - - --tls-private-key-file=/etc/metrics/tls.key - - --tls-cert-file=/etc/metrics/tls.crt - {{- end }} - ports: - - containerPort: {{ .Values.prometheus.secureMetricsPort }} - name: metricshttps - resources: - requests: - cpu: 10m - memory: 20Mi - terminationMessagePolicy: FallbackToLogsOnError - {{- if .Values.prometheus.metricsTLSSecret }} - volumeMounts: - - name: metrics-certs - mountPath: /etc/metrics - readOnly: true - {{- end }} - - name: kube-rbac-proxy-frr - image: {{ .Values.prometheus.rbacProxy.repository }}:{{ .Values.prometheus.rbacProxy.tag | default .Chart.AppVersion }} - imagePullPolicy: {{ .Values.prometheus.rbacProxy.pullPolicy }} - args: - - --logtostderr - - --secure-listen-address=:{{ .Values.frrk8s.frr.secureMetricsPort }} - - --tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - - --upstream=http://{{ .Values.frrk8s.frr.metricsBindAddress }}:{{ .Values.frrk8s.frr.metricsPort }}/ - {{- if .Values.prometheus.metricsTLSSecret }} - - --tls-private-key-file=/etc/metrics/tls.key - - --tls-cert-file=/etc/metrics/tls.crt - {{- end }} - ports: - - containerPort: {{ .Values.frrk8s.frr.secureMetricsPort }} - name: metricshttps - resources: - requests: - cpu: 10m - memory: 20Mi - terminationMessagePolicy: FallbackToLogsOnError - {{- if .Values.prometheus.metricsTLSSecret }} - volumeMounts: - - name: metrics-certs - mountPath: /etc/metrics - readOnly: true - {{- end }} - nodeSelector: - "kubernetes.io/os": linux - {{- with .Values.frrk8s.nodeSelector }} - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.frrk8s.affinity }} - affinity: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- if or .Values.frrk8s.tolerateMaster .Values.frrk8s.tolerations }} - tolerations: - {{- if .Values.frrk8s.tolerateMaster }} - - key: node-role.kubernetes.io/master - effect: NoSchedule - operator: Exists - - key: node-role.kubernetes.io/control-plane - effect: NoSchedule - operator: Exists - {{- end }} - {{- with .Values.frrk8s.tolerations }} - {{- toYaml . | nindent 6 }} - {{- end }} - {{- end }} - {{- with .Values.frrk8s.priorityClassName }} - priorityClassName: {{ . | quote }} - {{- end }} diff --git a/metallb/charts/frr-k8s/templates/rbac.yaml b/metallb/charts/frr-k8s/templates/rbac.yaml deleted file mode 100644 index e9beef8..0000000 --- a/metallb/charts/frr-k8s/templates/rbac.yaml +++ /dev/null @@ -1,73 +0,0 @@ -{{- if .Values.rbac.create -}} ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: {{ include "frrk8s.fullname" . }}-controller - labels: {{- include "frrk8s.labels" . | nindent 4 }} -rules: -- apiGroups: ["frrk8s.metallb.io"] - resources: ["frrconfigurations"] - verbs: ["get", "list", "watch"] -- apiGroups: ["frrk8s.metallb.io"] - resources: ["frrnodestates"] - verbs: ["get", "list", "watch", "create", "delete", "patch", "update"] -- apiGroups: ["frrk8s.metallb.io"] - resources: ["frrnodestates/status"] - verbs: ["get", "patch", "update"] -- apiGroups: [""] - resources: ["nodes"] - verbs: ["get", "list", "watch"] -- apiGroups: ["authentication.k8s.io"] - resources: ["tokenreviews"] - verbs: ["create"] -- apiGroups: ["authorization.k8s.io"] - resources: ["subjectaccessreviews"] - verbs: ["create"] -- apiGroups: ["admissionregistration.k8s.io"] - resources: ["validatingwebhookconfigurations"] - verbs: ["get", "list", "watch"] -- apiGroups: ["admissionregistration.k8s.io"] - resourceNames: ["frr-k8s-validating-webhook-configuration"] - resources: ["validatingwebhookconfigurations"] - verbs: ["update"] ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: {{ include "frrk8s.fullname" . }}-controller - labels: {{- include "frrk8s.labels" . | nindent 4 }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: {{ include "frrk8s.fullname" . }}-controller -subjects: -- kind: ServiceAccount - name: {{ include "frrk8s.serviceAccountName" . }} - namespace: {{ .Release.Namespace | quote }} ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: Role -metadata: - name: {{ include "frrk8s.fullname" . }}-controller - namespace: {{ .Release.Namespace | quote }} - labels: {{- include "frrk8s.labels" . | nindent 4 }} -rules: -- apiGroups: [""] - resources: ["secrets"] - verbs: ["get", "list", "watch","update"] ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding -metadata: - name: {{ include "frrk8s.fullname" . }}-controller - namespace: {{ .Release.Namespace | quote }} - labels: {{- include "frrk8s.labels" . | nindent 4 }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: {{ include "frrk8s.fullname" . }}-controller -subjects: -- kind: ServiceAccount - name: {{ include "frrk8s.serviceAccountName" . }} -{{ end -}} diff --git a/metallb/charts/frr-k8s/templates/service-accounts.yaml b/metallb/charts/frr-k8s/templates/service-accounts.yaml deleted file mode 100644 index 3c64c5c..0000000 --- a/metallb/charts/frr-k8s/templates/service-accounts.yaml +++ /dev/null @@ -1,16 +0,0 @@ -{{- if .Values.frrk8s.serviceAccount.create }} ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - name: {{ template "frrk8s.serviceAccountName" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "frrk8s.labels" . | nindent 4 }} - app.kubernetes.io/component: controller - {{- with .Values.frrk8s.serviceAccount.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} -{{- end }} - diff --git a/metallb/charts/frr-k8s/templates/service-monitor.yaml b/metallb/charts/frr-k8s/templates/service-monitor.yaml deleted file mode 100644 index c6f9130..0000000 --- a/metallb/charts/frr-k8s/templates/service-monitor.yaml +++ /dev/null @@ -1,128 +0,0 @@ -{{- if .Values.prometheus.serviceMonitor.enabled }} -apiVersion: monitoring.coreos.com/v1 -kind: ServiceMonitor -metadata: - name: {{ template "frrk8s.fullname" . }}-frr-k8s-monitor - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "frrk8s.labels" . | nindent 4 }} - app.kubernetes.io/component: frr-k8s - {{- if .Values.prometheus.serviceMonitor.additionalLabels }} -{{ toYaml .Values.prometheus.serviceMonitor.additionalLabels | indent 4 }} - {{- end }} - {{- if .Values.prometheus.serviceMonitor.annotations }} - annotations: -{{ toYaml .Values.prometheus.serviceMonitor.annotations | indent 4 }} - {{- end }} -spec: - endpoints: - - port: "metricshttps" - honorLabels: true - {{- if .Values.prometheus.serviceMonitor.metricRelabelings }} - metricRelabelings: - {{- toYaml .Values.prometheus.serviceMonitor.metricRelabelings | nindent 8 }} - {{- end -}} - {{- if .Values.prometheus.serviceMonitor.relabelings }} - relabelings: - {{- toYaml .Values.prometheus.serviceMonitor.relabelings | nindent 8 }} - {{- end }} - {{- if .Values.prometheus.serviceMonitor.interval }} - interval: {{ .Values.prometheus.serviceMonitor.interval }} - {{- end -}} -{{ if .Values.prometheus.secureMetricsPort }} - bearerTokenFile: "/var/run/secrets/kubernetes.io/serviceaccount/token" - scheme: "https" -{{- if .Values.prometheus.serviceMonitor.tlsConfig }} - tlsConfig: -{{ toYaml .Values.prometheus.serviceMonitor.tlsConfig | indent 8 }} -{{- end }} -{{ end }} -{{ if .Values.frrk8s.frr.secureMetricsPort }} - - port: "frrmetricshttps" - honorLabels: true - {{- if .Values.prometheus.serviceMonitor.metricRelabelings }} - metricRelabelings: - {{- toYaml .Values.prometheus.serviceMonitor.metricRelabelings | nindent 8 }} - {{- end -}} - {{- if .Values.prometheus.serviceMonitor.relabelings }} - relabelings: - {{- toYaml .Values.prometheus.serviceMonitor.relabelings | nindent 8 }} - {{- end }} - {{- if .Values.prometheus.serviceMonitor.interval }} - interval: {{ .Values.prometheus.serviceMonitor.interval }} - {{- end }} - bearerTokenFile: "/var/run/secrets/kubernetes.io/serviceaccount/token" - scheme: "https" -{{- if .Values.prometheus.serviceMonitor.tlsConfig }} - tlsConfig: -{{ toYaml .Values.prometheus.serviceMonitor.tlsConfig | indent 8 }} -{{- end }} -{{- end }} - jobLabel: {{ .Values.prometheus.serviceMonitor.jobLabel | quote }} - namespaceSelector: - matchNames: - - {{ .Release.Namespace }} - selector: - matchLabels: - name: {{ template "frrk8s.fullname" . }}-frr-k8s-monitor-service ---- -apiVersion: v1 -kind: Service -metadata: - annotations: - prometheus.io/scrape: "true" - {{- if .Values.prometheus.serviceMonitor.annotations }} -{{ toYaml .Values.prometheus.serviceMonitor.annotations | indent 4 }} - {{- end }} - labels: - name: {{ template "frrk8s.fullname" . }}-frr-k8s-monitor-service - name: {{ template "frrk8s.fullname" . }}-frr-k8s-monitor-service - namespace: {{ .Release.Namespace | quote }} -spec: - selector: - {{- include "frrk8s.selectorLabels" . | nindent 4 }} - app.kubernetes.io/component: frr-k8s - clusterIP: None - ports: - - name: "metricshttps" - port: {{ .Values.prometheus.secureMetricsPort }} - targetPort: {{ .Values.prometheus.secureMetricsPort }} - - name: frrmetricshttps - port: {{ .Values.frrk8s.frr.secureMetricsPort }} - targetPort: {{ .Values.frrk8s.frr.secureMetricsPort }} - sessionAffinity: None - type: ClusterIP ---- -{{- if .Values.prometheus.rbacPrometheus }} -apiVersion: rbac.authorization.k8s.io/v1 -kind: Role -metadata: - name: {{ template "frrk8s.fullname" . }}-prometheus - namespace: {{ .Release.Namespace | quote }} -rules: - - apiGroups: - - "" - resources: - - pods - - services - - endpoints - verbs: - - get - - list - - watch ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding -metadata: - name: {{ template "frrk8s.fullname" . }}-prometheus - namespace: {{ .Release.Namespace | quote }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: {{ template "frrk8s.fullname" . }}-prometheus -subjects: - - kind: ServiceAccount - name: {{ required ".Values.prometheus.serviceAccount must be defined when .Values.prometheus.serviceMonitor.enabled == true" .Values.prometheus.serviceAccount }} - namespace: {{ required ".Values.prometheus.namespace must be defined when .Values.prometheus.serviceMonitor.enabled == true" .Values.prometheus.namespace }} -{{- end }} -{{- end }} diff --git a/metallb/charts/frr-k8s/templates/webhooks.yaml b/metallb/charts/frr-k8s/templates/webhooks.yaml deleted file mode 100644 index 2549837..0000000 --- a/metallb/charts/frr-k8s/templates/webhooks.yaml +++ /dev/null @@ -1,162 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - name: {{ template "frrk8s.fullname" . }}-webhook-server - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "frrk8s.labels" . | nindent 4 }} - app.kubernetes.io/component: frr-k8s-webhook-server - {{- range $key, $value := .Values.frrk8s.labels }} - {{ $key }}: {{ $value | quote }} - {{- end }} -spec: - selector: - matchLabels: - app.kubernetes.io/component: frr-k8s-webhook-server - template: - metadata: - annotations: - kubectl.kubernetes.io/default-container: frr-k8s-webhook-server - labels: - app.kubernetes.io/component: frr-k8s-webhook-server - spec: - {{- if .Values.frrk8s.runtimeClassName }} - runtimeClassName: {{ .Values.frrk8s.runtimeClassName }} - {{- end }} - {{- with .Values.imagePullSecrets }} - imagePullSecrets: - {{- toYaml . | nindent 8 }} - {{- end }} - containers: - - command: - - /frr-k8s - args: - {{- with .Values.frrk8s.logLevel }} - - --log-level={{ . }} - {{- end }} - - "--webhook-mode=onlywebhook" - {{- if .Values.frrk8s.disableCertRotation }} - - "--disable-cert-rotation=true" - {{- end }} - {{- if .Values.frrk8s.restartOnRotatorSecretRefresh }} - - "--restart-on-rotator-secret-refresh=true" - {{- end }} - - "--namespace=$(NAMESPACE)" - - "--metrics-bind-address=:{{ .Values.prometheus.metricsPort }}" - env: - - name: NAMESPACE - valueFrom: - fieldRef: - fieldPath: metadata.namespace - image: {{ .Values.frrk8s.image.repository }}:{{ .Values.frrk8s.image.tag | default .Chart.AppVersion }} - {{- if .Values.frrk8s.image.pullPolicy }} - imagePullPolicy: {{ .Values.frrk8s.image.pullPolicy }} - {{- end }} - name: frr-k8s-webhook-server - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - readOnlyRootFilesystem: true - ports: - - containerPort: {{ .Values.prometheus.metricsPort }} - name: monitoring - {{- if .Values.frrk8s.livenessProbe.enabled }} - livenessProbe: - httpGet: - path: /metrics - port: monitoring - initialDelaySeconds: {{ .Values.frrk8s.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.frrk8s.livenessProbe.periodSeconds }} - failureThreshold: {{ .Values.frrk8s.livenessProbe.failureThreshold }} - {{- end }} - {{- if .Values.frrk8s.readinessProbe.enabled }} - readinessProbe: - httpGet: - path: /metrics - port: monitoring - initialDelaySeconds: {{ .Values.frrk8s.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.frrk8s.readinessProbe.periodSeconds }} - failureThreshold: {{ .Values.frrk8s.readinessProbe.failureThreshold }} - {{- end }} - {{- with .Values.frrk8s.resources }} - resources: - {{- toYaml . | nindent 10 }} - {{- end }} - volumeMounts: - - name: cert - mountPath: /tmp/k8s-webhook-server/serving-certs - readOnly: true - {{- with .Values.frrk8s.affinity }} - affinity: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- if or .Values.frrk8s.tolerateMaster .Values.frrk8s.tolerations }} - tolerations: - {{- if .Values.frrk8s.tolerateMaster }} - - key: node-role.kubernetes.io/master - effect: NoSchedule - operator: Exists - - key: node-role.kubernetes.io/control-plane - effect: NoSchedule - operator: Exists - {{- end }} - {{- with .Values.frrk8s.tolerations }} - {{- toYaml . | nindent 6 }} - {{- end }} - {{- end }} - {{- with .Values.frrk8s.priorityClassName }} - priorityClassName: {{ . | quote }} - {{- end }} - volumes: - - name: cert - secret: - defaultMode: 420 - secretName: frr-k8s-webhook-server-cert - serviceAccountName: {{ template "frrk8s.serviceAccountName" . }} - terminationGracePeriodSeconds: 10 ---- -apiVersion: v1 -kind: Secret -metadata: - name: frr-k8s-webhook-server-cert - namespace: {{ .Release.Namespace | quote }} ---- -apiVersion: v1 -kind: Service -metadata: - name: frr-k8s-webhook-service - namespace: {{ .Release.Namespace | quote }} -spec: - ports: - - port: 443 - targetPort: 9443 - selector: - app.kubernetes.io/component: frr-k8s-webhook-server ---- -apiVersion: admissionregistration.k8s.io/v1 -kind: ValidatingWebhookConfiguration -metadata: - name: frr-k8s-validating-webhook-configuration -webhooks: -- admissionReviewVersions: - - v1 - clientConfig: - service: - name: frr-k8s-webhook-service - namespace: {{ .Release.Namespace }} - path: /validate-frrk8s-metallb-io-v1beta1-frrconfiguration - failurePolicy: {{ .Values.crds.validationFailurePolicy }} - name: frrconfigurationsvalidationwebhook.metallb.io - rules: - - apiGroups: - - frrk8s.metallb.io - apiVersions: - - v1beta1 - operations: - - CREATE - - UPDATE - resources: - - frrconfigurations - sideEffects: None diff --git a/metallb/charts/frr-k8s/values.schema.json b/metallb/charts/frr-k8s/values.schema.json deleted file mode 100644 index cb7b914..0000000 --- a/metallb/charts/frr-k8s/values.schema.json +++ /dev/null @@ -1,387 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft-07/schema#", - "title": "Values", - "type": "object", - "definitions": { - "prometheusAlert": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "labels": { - "type": "object", - "additionalProperties": { - "type": "string" - } - } - }, - "required": [ - "enabled" - ] - }, - "probe": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "failureThreshold": { - "type": "integer" - }, - "initialDelaySeconds": { - "type": "integer" - }, - "periodSeconds": { - "type": "integer" - }, - "successThreshold": { - "type": "integer" - }, - "timeoutSeconds": { - "type": "integer" - } - }, - "required": [ - "failureThreshold", - "initialDelaySeconds", - "periodSeconds", - "successThreshold", - "timeoutSeconds" - ] - }, - "component": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "logLevel": { - "type": "string", - "enum": [ - "all", - "debug", - "info", - "warn", - "error", - "none" - ] - }, - "image": { - "type": "object", - "properties": { - "repository": { - "type": "string" - }, - "tag": { - "anyOf": [ - { - "type": "string" - }, - { - "type": "null" - } - ] - }, - "pullPolicy": { - "anyOf": [ - { - "type": "null" - }, - { - "type": "string", - "enum": [ - "Always", - "IfNotPresent", - "Never" - ] - } - ] - } - } - }, - "serviceAccount": { - "type": "object", - "properties": { - "create": { - "type": "boolean" - }, - "name": { - "type": "string" - }, - "annotations": { - "type": "object" - } - } - }, - "resources": { - "type": "object" - }, - "nodeSelector": { - "type": "object" - }, - "tolerations": { - "type": "array", - "items": { - "type": "object" - } - }, - "priorityClassName": { - "type": "string" - }, - "runtimeClassName": { - "type": "string" - }, - "affinity": { - "type": "object" - }, - "podAnnotations": { - "type": "object" - }, - "livenessProbe": { - "$ref": "#/definitions/probe" - }, - "readinessProbe": { - "$ref": "#/definitions/probe" - } - }, - "required": [ - "image", - "serviceAccount" - ] - } - }, - "properties": { - "imagePullSecrets": { - "description": "Secrets used for pulling images", - "type": "array", - "items": { - "type": "object", - "properties": { - "name": { - "type": "string" - } - }, - "required": [ - "name" - ], - "additionalProperties": false - } - }, - "nameOverride": { - "description": "Override chart name", - "type": "string" - }, - "fullNameOverride": { - "description": "Override fully qualified app name", - "type": "string" - }, - "rbac": { - "description": "RBAC configuration", - "type": "object", - "properties": { - "create": { - "description": "Enable RBAC", - "type": "boolean" - } - } - }, - "prometheus": { - "description": "Prometheus monitoring config", - "type": "object", - "properties": { - "scrapeAnnotations": { - "type": "boolean" - }, - "metricsPort": { - "type": "integer" - }, - "secureMetricsPort": { - "type": "integer" - }, - "rbacPrometheus": { - "type": "boolean" - }, - "serviceAccount": { - "type": "string" - }, - "namespace": { - "type": "string" - }, - "rbacProxy": { - "description": "kube-rbac-proxy configuration", - "type": "object", - "properties": { - "repository": { - "type": "string" - }, - "tag": { - "type": "string" - } - } - }, - "serviceMonitor": { - "description": "Prometheus Operator ServiceMonitors", - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "jobLabel": { - "type": "string" - }, - "interval": { - "anyOf": [ - { - "type": "integer" - }, - { - "type": "null" - } - ] - }, - "metricRelabelings": { - "type": "array", - "items": { - "type": "object" - } - }, - "relabelings": { - "type": "array", - "items": { - "type": "object" - } - } - } - } - }, - "frrk8s": { - "allOf": [ - { - "$ref": "#/definitions/component" - }, - { - "description": "FRR-K8s controller", - "type": "object", - "properties": { - "tolerateMaster": { - "type": "boolean" - }, - "updateStrategy": { - "type": "object", - "properties": { - "type": { - "type": "string" - } - }, - "required": [ - "type" - ] - }, - "runtimeClassName": { - "type": "string" - }, - "secretName": { - "type": "string" - }, - "frr": { - "description": "The FRR properties in the controller", - "type": "object", - "properties": { - "image": { - "$ref": "#/definitions/component/properties/image" - }, - "metricsPort": { - "type": "integer" - }, - "secureMetricsPort": { - "type": "integer" - }, - "resources:": { - "type": "object" - } - }, - "required": [ - "enabled" - ] - }, - "command": { - "type": "string" - }, - "reloader": { - "type": "object", - "properties": { - "resources": { - "type": "object" - } - } - }, - "frrMetrics": { - "type": "object", - "properties": { - "resources": { - "type": "object" - } - } - } - }, - "required": [ - "tolerateMaster" - ] - } - ] - }, - "crds": { - "description": "CRD configuration", - "type": "object", - "properties": { - "enabled": { - "description": "Enable CRDs", - "type": "boolean" - }, - "validationFailurePolicy": { - "description": "Failure policy to use with validating webhooks", - "type": "string", - "enum": [ - "Ignore", - "Fail" - ] - } - } - } - }, - "frrk8s": { - "allOf": [ - { - "$ref": "#/definitions/component" - }, - { - "description": "FRRk8s Controller", - "type": "object", - "properties": { - "strategy": { - "type": "object", - "properties": { - "type": { - "type": "string" - } - }, - "required": [ - "type" - ] - }, - "command": { - "type": "string" - }, - "webhookMode": { - "type": "string" - } - } - } - ] - } - }, - "required": [ - "frrk8s" - ] -} \ No newline at end of file diff --git a/metallb/charts/frr-k8s/values.yaml b/metallb/charts/frr-k8s/values.yaml deleted file mode 100644 index 9b5d4b1..0000000 --- a/metallb/charts/frr-k8s/values.yaml +++ /dev/null @@ -1,173 +0,0 @@ -# Default values for frr-k8s. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -nameOverride: "" -fullnameOverride: "" - -rbac: - # create specifies whether to install and use RBAC rules. - create: true - -prometheus: - # scrape annotations specifies whether to add Prometheus metric - # auto-collection annotations to pods. See - # https://github.com/prometheus/prometheus/blob/release-2.1/documentation/examples/prometheus-kubernetes.yml - # for a corresponding Prometheus configuration. Alternatively, you - # may want to use the Prometheus Operator - # (https://github.com/coreos/prometheus-operator) for more powerful - # monitoring configuration. If you use the Prometheus operator, this - # can be left at false. - scrapeAnnotations: false - - # bind addr frr-k8s will use for metrics - metricsBindAddress: 127.0.0.1 - - # port frr-k8s will listen on for metrics - metricsPort: 7572 - - # if set, enables rbac proxy on frr-k8s to expose - # the metrics via tls. - secureMetricsPort: 9140 - - # the name of the secret to be mounted in the frr-k8s pod - # to expose the metrics securely. If not present, a self signed - # certificate to be used. - metricsTLSSecret: "" - - # prometheus doens't have the permission to scrape all namespaces so we give it permission to scrape metallb's one - rbacPrometheus: false - - # the service account used by prometheus - # required when " .Values.prometheus.rbacPrometheus == true " and " prometheus.serviceMonitor.enabled=true " - serviceAccount: "" - - # the namespace where prometheus is deployed - # required when " .Values.prometheus.rbacPrometheus == true " and " prometheus.serviceMonitor.enabled=true " - namespace: "" - - # the image to be used for the kuberbacproxy container - rbacProxy: - repository: gcr.io/kubebuilder/kube-rbac-proxy - tag: v0.12.0 - pullPolicy: - - # Prometheus Operator ServiceMonitors. - serviceMonitor: - # enable support for Prometheus Operator - enabled: false - - additionalLabels: {} - # optional additional annotations for the controller serviceMonitor - annotations: {} - # optional tls configuration for the controller serviceMonitor, in case - # secure metrics are enabled. - tlsConfig: - insecureSkipVerify: true - - # Job label for scrape target - jobLabel: "app.kubernetes.io/name" - - # Scrape interval. If not set, the Prometheus default scrape interval is used. - interval: - - # metric relabel configs to apply to samples before ingestion. - metricRelabelings: [] - # - action: keep - # regex: 'kube_(daemonset|deployment|pod|namespace|node|statefulset).+' - # sourceLabels: [__name__] - - # relabel configs to apply to samples before ingestion. - relabelings: [] - # - sourceLabels: [__meta_kubernetes_pod_node_name] - # separator: ; - # regex: ^(.*)$ - # target_label: nodename - # replacement: $1 - # action: replace - -# controller contains configuration specific to the FRRK8s controller -# daemonset. -frrk8s: - # -- Controller log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none` - logLevel: info - tolerateMaster: true - image: - repository: quay.io/metallb/frr-k8s - tag: - pullPolicy: - ## @param controller.updateStrategy.type FRR-K8s controller daemonset strategy type - ## ref: https://kubernetes.io/docs/tasks/manage-daemon/update-daemon-set/ - ## - updateStrategy: - ## StrategyType - ## Can be set to RollingUpdate or OnDelete - ## - type: RollingUpdate - serviceAccount: - # Specifies whether a ServiceAccount should be created - create: true - # The name of the ServiceAccount to use. If not set and create is - # true, a name is generated using the fullname template - name: "" - annotations: {} - ## Defines a secret name for the controller to generate a memberlist encryption secret - ## By default secretName: {{ "metallb.fullname" }}-memberlist - ## - # secretName: - resources: {} - # limits: - # cpu: 100m - # memory: 100Mi - nodeSelector: {} - tolerations: [] - priorityClassName: "" - affinity: {} - ## Selects which runtime class will be used by the pod. - runtimeClassName: "" - podAnnotations: {} - labels: - app: frr-k8s - livenessProbe: - enabled: true - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - readinessProbe: - enabled: true - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - startupProbe: - enabled: true - failureThreshold: 30 - periodSeconds: 5 - ## A comma separated list of cidrs we want always to block for incoming routes - alwaysBlock: "" - ## Specifies whether the cert rotator works as part of the webhook. - disableCertRotation: false - ## Specifies whether the pod restarts when the rotator refreshes the cert secret. - ## Enabling this proved useful for the webhook's stability when it is redeployed multiple times in succession. - restartOnRotatorSecretRefresh: false - # frr contains configuration specific to the FRR container, - frr: - image: - repository: quay.io/frrouting/frr - tag: 9.1.0 - pullPolicy: - metricsBindAddress: 127.0.0.1 - metricsPort: 7573 - resources: {} - secureMetricsPort: 9141 - acceptIncomingBGPConnections: false - reloader: - resources: {} - frrMetrics: - resources: {} -crds: - enabled: true - validationFailurePolicy: Fail diff --git a/metallb/policy/controller.rego b/metallb/policy/controller.rego deleted file mode 100644 index b7a0ea1..0000000 --- a/metallb/policy/controller.rego +++ /dev/null @@ -1,16 +0,0 @@ -package main - -# validate serviceAccountName -deny[msg] { - input.kind == "Deployment" - serviceAccountName := input.spec.template.spec.serviceAccountName - not serviceAccountName == "release-name-metallb-controller" - msg = sprintf("controller serviceAccountName '%s' does not match expected value", [serviceAccountName]) -} - -# validate node selector includes builtin when custom ones are provided -deny[msg] { - input.kind == "Deployment" - not input.spec.template.spec.nodeSelector["kubernetes.io/os"] == "linux" - msg = "controller nodeSelector does not include '\"kubernetes.io/os\": linux'" -} diff --git a/metallb/policy/rbac.rego b/metallb/policy/rbac.rego deleted file mode 100644 index 047345e..0000000 --- a/metallb/policy/rbac.rego +++ /dev/null @@ -1,27 +0,0 @@ -package main - -# Validate PSP exists in ClusterRole :controller -deny[msg] { - input.kind == "ClusterRole" - input.metadata.name == "metallb:controller" - input.rules[3] == { - "apiGroups": ["policy"], - "resources": ["podsecuritypolicies"], - "resourceNames": ["metallb-controller"], - "verbs": ["use"] - } - msg = "ClusterRole metallb:controller does not include PSP rule" -} - -# Validate PSP exists in ClusterRole :speaker -deny[msg] { - input.kind == "ClusterRole" - input.metadata.name == "metallb:speaker" - input.rules[3] == { - "apiGroups": ["policy"], - "resources": ["podsecuritypolicies"], - "resourceNames": ["metallb-controller"], - "verbs": ["use"] - } - msg = "ClusterRole metallb:speaker does not include PSP rule" -} diff --git a/metallb/policy/speaker.rego b/metallb/policy/speaker.rego deleted file mode 100644 index 146a037..0000000 --- a/metallb/policy/speaker.rego +++ /dev/null @@ -1,30 +0,0 @@ -package main - -# validate serviceAccountName -deny[msg] { - input.kind == "DaemonSet" - serviceAccountName := input.spec.template.spec.serviceAccountName - not serviceAccountName == "release-name-metallb-speaker" - msg = sprintf("speaker serviceAccountName '%s' does not match expected value", [serviceAccountName]) -} - -# validate METALLB_ML_SECRET_KEY (memberlist) -deny[msg] { - input.kind == "DaemonSet" - not input.spec.template.spec.containers[0].env[5].name == "METALLB_ML_SECRET_KEY_PATH" - msg = "speaker env does not contain METALLB_ML_SECRET_KEY_PATH at env[5]" -} - -# validate node selector includes builtin when custom ones are provided -deny[msg] { - input.kind == "DaemonSet" - not input.spec.template.spec.nodeSelector["kubernetes.io/os"] == "linux" - msg = "controller nodeSelector does not include '\"kubernetes.io/os\": linux'" -} - -# validate tolerations include the builtins when custom ones are provided -deny[msg] { - input.kind == "DaemonSet" - not input.spec.template.spec.tolerations[0] == { "key": "node-role.kubernetes.io/master", "effect": "NoSchedule", "operator": "Exists" } - msg = "controller tolerations does not include node-role.kubernetes.io/master:NoSchedule" -} diff --git a/metallb/templates/NOTES.txt b/metallb/templates/NOTES.txt deleted file mode 100644 index 23d1d5b..0000000 --- a/metallb/templates/NOTES.txt +++ /dev/null @@ -1,4 +0,0 @@ -MetalLB is now running in the cluster. - -Now you can configure it via its CRs. Please refer to the metallb official docs -on how to use the CRs. diff --git a/metallb/templates/_helpers.tpl b/metallb/templates/_helpers.tpl deleted file mode 100644 index cd89381..0000000 --- a/metallb/templates/_helpers.tpl +++ /dev/null @@ -1,114 +0,0 @@ -{{/* vim: set filetype=mustache: */}} -{{/* -Expand the name of the chart. -*/}} -{{- define "metallb.name" -}} -{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{/* -Create a default fully qualified app name. -We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). -If release name contains chart name it will be used as a full name. -*/}} -{{- define "metallb.fullname" -}} -{{- if .Values.fullnameOverride }} -{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- $name := default .Chart.Name .Values.nameOverride }} -{{- if contains $name .Release.Name }} -{{- .Release.Name | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} -{{- end }} -{{- end }} -{{- end }} - -{{/* -Create chart name and version as used by the chart label. -*/}} -{{- define "metallb.chart" -}} -{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{/* -Common labels -*/}} -{{- define "metallb.labels" -}} -helm.sh/chart: {{ include "metallb.chart" . }} -{{ include "metallb.selectorLabels" . }} -{{- if .Chart.AppVersion }} -app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} -{{- end }} -app.kubernetes.io/managed-by: {{ .Release.Service }} -{{- end }} - -{{/* -Selector labels -*/}} -{{- define "metallb.selectorLabels" -}} -app.kubernetes.io/name: {{ include "metallb.name" . }} -app.kubernetes.io/instance: {{ .Release.Name }} -{{- end }} - -{{/* -Create the name of the controller service account to use -*/}} -{{- define "metallb.controller.serviceAccountName" -}} -{{- if .Values.controller.serviceAccount.create }} -{{- default (printf "%s-controller" (include "metallb.fullname" .)) .Values.controller.serviceAccount.name }} -{{- else }} -{{- default "default" .Values.controller.serviceAccount.name }} -{{- end }} -{{- end }} - -{{/* -Create the name of the speaker service account to use -*/}} -{{- define "metallb.speaker.serviceAccountName" -}} -{{- if .Values.speaker.serviceAccount.create }} -{{- default (printf "%s-speaker" (include "metallb.fullname" .)) .Values.speaker.serviceAccount.name }} -{{- else }} -{{- default "default" .Values.speaker.serviceAccount.name }} -{{- end }} -{{- end }} - -{{/* -Create the name of the settings Secret to use. -*/}} -{{- define "metallb.secretName" -}} - {{ default ( printf "%s-memberlist" (include "metallb.fullname" .)) .Values.speaker.secretName | trunc 63 | trimSuffix "-" }} -{{- end -}} - -{{- define "metrics.exposedportname" -}} -{{- if .Values.prometheus.secureMetricsPort -}} -"metricshttps" -{{- else -}} -"metrics" -{{- end -}} -{{- end -}} - -{{- define "metrics.exposedfrrportname" -}} -{{- if .Values.speaker.frr.secureMetricsPort -}} -"frrmetricshttps" -{{- else -}} -"frrmetrics" -{{- end }} -{{- end }} - -{{- define "metrics.exposedport" -}} -{{- if .Values.prometheus.secureMetricsPort -}} -{{ .Values.prometheus.secureMetricsPort }} -{{- else -}} -{{ .Values.prometheus.metricsPort }} -{{- end -}} -{{- end }} - -{{- define "metrics.exposedfrrport" -}} -{{- if .Values.speaker.frr.secureMetricsPort -}} -{{ .Values.speaker.frr.secureMetricsPort }} -{{- else -}} -{{ .Values.speaker.frr.metricsPort }} -{{- end }} -{{- end }} - diff --git a/metallb/templates/controller.yaml b/metallb/templates/controller.yaml deleted file mode 100644 index 8fd9c47..0000000 --- a/metallb/templates/controller.yaml +++ /dev/null @@ -1,194 +0,0 @@ -{{- if .Values.controller.enabled }} -apiVersion: apps/v1 -kind: Deployment -metadata: - name: {{ template "metallb.fullname" . }}-controller - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: controller - {{- range $key, $value := .Values.controller.labels }} - {{ $key }}: {{ $value | quote }} - {{- end }} -spec: - {{- if .Values.controller.strategy }} - strategy: {{- toYaml .Values.controller.strategy | nindent 4 }} - {{- end }} - selector: - matchLabels: - {{- include "metallb.selectorLabels" . | nindent 6 }} - app.kubernetes.io/component: controller - template: - metadata: - {{- if or .Values.prometheus.scrapeAnnotations .Values.controller.podAnnotations }} - annotations: - {{- if .Values.prometheus.scrapeAnnotations }} - prometheus.io/scrape: "true" - prometheus.io/port: "{{ .Values.prometheus.metricsPort }}" - {{- end }} - {{- with .Values.controller.podAnnotations }} - {{- toYaml . | nindent 8 }} - {{- end }} - {{- end }} - labels: - {{- include "metallb.selectorLabels" . | nindent 8 }} - app.kubernetes.io/component: controller - {{- range $key, $value := .Values.controller.labels }} - {{ $key }}: {{ $value | quote }} - {{- end }} - spec: - {{- with .Values.controller.runtimeClassName }} - runtimeClassName: {{ . | quote }} - {{- end }} - {{- with .Values.imagePullSecrets }} - imagePullSecrets: - {{- toYaml . | nindent 8 }} - {{- end }} - serviceAccountName: {{ template "metallb.controller.serviceAccountName" . }} - terminationGracePeriodSeconds: 0 -{{- if .Values.controller.securityContext }} - securityContext: -{{ toYaml .Values.controller.securityContext | indent 8 }} -{{- end }} - containers: - - name: controller - image: {{ .Values.controller.image.repository }}:{{ .Values.controller.image.tag | default .Chart.AppVersion }} - {{- if .Values.controller.image.pullPolicy }} - imagePullPolicy: {{ .Values.controller.image.pullPolicy }} - {{- end }} - {{- if .Values.controller.command }} - command: - - {{ .Values.controller.command }} - {{- end }} - args: - - --port={{ .Values.prometheus.metricsPort }} - {{- with .Values.controller.logLevel }} - - --log-level={{ . }} - {{- end }} - {{- if .Values.loadBalancerClass }} - - --lb-class={{ .Values.loadBalancerClass }} - {{- end }} - {{- if .Values.controller.webhookMode }} - - --webhook-mode={{ .Values.controller.webhookMode }} - {{- end }} - {{- if .Values.controller.tlsMinVersion }} - - --tls-min-version={{ .Values.controller.tlsMinVersion }} - {{- end }} - {{- if .Values.controller.tlsCipherSuites }} - - --tls-cipher-suites={{ .Values.controller.tlsCipherSuites }} - {{- end }} - env: - {{- if and .Values.speaker.enabled .Values.speaker.memberlist.enabled }} - - name: METALLB_ML_SECRET_NAME - value: {{ include "metallb.secretName" . }} - - name: METALLB_DEPLOYMENT - value: {{ template "metallb.fullname" . }}-controller - {{- end }} - {{- if and .Values.speaker.enabled .Values.speaker.frr.enabled }} - - name: METALLB_BGP_TYPE - value: frr - {{- end }} - {{- if or .Values.frrk8s.enabled .Values.frrk8s.external }} - - name: METALLB_BGP_TYPE - value: frr-k8s - {{- end }} - ports: - - name: monitoring - containerPort: {{ .Values.prometheus.metricsPort }} - - containerPort: 9443 - name: webhook-server - protocol: TCP - volumeMounts: - - mountPath: /tmp/k8s-webhook-server/serving-certs - name: cert - readOnly: true - {{- if .Values.controller.livenessProbe.enabled }} - livenessProbe: - httpGet: - path: /metrics - port: monitoring - initialDelaySeconds: {{ .Values.controller.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.controller.livenessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.controller.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.controller.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.controller.livenessProbe.failureThreshold }} - {{- end }} - {{- if .Values.controller.readinessProbe.enabled }} - readinessProbe: - httpGet: - path: /metrics - port: monitoring - initialDelaySeconds: {{ .Values.controller.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.controller.readinessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.controller.readinessProbe.timeoutSeconds }} - successThreshold: {{ .Values.controller.readinessProbe.successThreshold }} - failureThreshold: {{ .Values.controller.readinessProbe.failureThreshold }} - {{- end }} - {{- with .Values.controller.resources }} - resources: - {{- toYaml . | nindent 10 }} - {{- end }} - securityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: - - ALL - {{- if .Values.prometheus.secureMetricsPort }} - - name: kube-rbac-proxy - image: {{ .Values.prometheus.rbacProxy.repository }}:{{ .Values.prometheus.rbacProxy.tag }} - imagePullPolicy: {{ .Values.prometheus.rbacProxy.pullPolicy }} - args: - - --logtostderr - - --secure-listen-address=:{{ .Values.prometheus.secureMetricsPort }} - - --upstream=http://127.0.0.1:{{ .Values.prometheus.metricsPort }}/ - - --tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - {{- if .Values.prometheus.controllerMetricsTLSSecret }} - - --tls-private-key-file=/etc/metrics/tls.key - - --tls-cert-file=/etc/metrics/tls.crt - {{- end }} - ports: - - containerPort: {{ .Values.prometheus.secureMetricsPort }} - name: metricshttps - resources: - requests: - cpu: 10m - memory: 20Mi - terminationMessagePolicy: FallbackToLogsOnError - {{- if .Values.prometheus.controllerMetricsTLSSecret }} - volumeMounts: - - name: metrics-certs - mountPath: /etc/metrics - readOnly: true - {{- end }} - {{ end }} - {{- if .Values.controller.extraContainers }} - {{- toYaml .Values.controller.extraContainers | nindent 6 }} - {{- end }} - nodeSelector: - "kubernetes.io/os": linux - {{- with .Values.controller.nodeSelector }} - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.controller.affinity }} - affinity: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.controller.tolerations }} - tolerations: - {{- toYaml . | nindent 6 }} - {{- end }} - {{- with .Values.controller.priorityClassName }} - priorityClassName: {{ . | quote }} - {{- end }} - volumes: - - name: cert - secret: - defaultMode: 420 - secretName: metallb-webhook-cert - {{- if .Values.prometheus.controllerMetricsTLSSecret }} - - name: metrics-certs - secret: - secretName: {{ .Values.prometheus.controllerMetricsTLSSecret }} - {{- end }} -{{- end }} diff --git a/metallb/templates/deprecated_configInline.yaml b/metallb/templates/deprecated_configInline.yaml deleted file mode 100644 index 8a1a551..0000000 --- a/metallb/templates/deprecated_configInline.yaml +++ /dev/null @@ -1,3 +0,0 @@ -{{- if .Values.configInline }} -{{- fail "Starting from v0.13.0 configInline is no longer supported. Please see https://metallb.universe.tf/#backward-compatibility" }} -{{- end }} diff --git a/metallb/templates/exclude-l2-config.yaml b/metallb/templates/exclude-l2-config.yaml deleted file mode 100644 index 932c2d6..0000000 --- a/metallb/templates/exclude-l2-config.yaml +++ /dev/null @@ -1,25 +0,0 @@ -{{- if and .Values.speaker.enabled .Values.speaker.excludeInterfaces.enabled }} -apiVersion: v1 -kind: ConfigMap -metadata: - name: metallb-excludel2 - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} -data: - excludel2.yaml: | - announcedInterfacesToExclude: - - ^docker.* - - ^cbr.* - - ^dummy.* - - ^virbr.* - - ^lxcbr.* - - ^veth.* - - ^lo$ - - ^cali.* - - ^tunl.* - - ^flannel.* - - ^kube-ipvs.* - - ^cni.* - - ^nodelocaldns.* -{{- end }} \ No newline at end of file diff --git a/metallb/templates/metallb-config.yaml b/metallb/templates/metallb-config.yaml deleted file mode 100644 index 3fd46e5..0000000 --- a/metallb/templates/metallb-config.yaml +++ /dev/null @@ -1,17 +0,0 @@ -apiVersion: metallb.io/v1beta1 -kind: IPAddressPool -metadata: - name: default-pool - namespace: metallb-system -spec: - addresses: - - 192.168.2.240-192.168.2.250 ---- -apiVersion: metallb.io/v1beta1 -kind: L2Advertisement -metadata: - name: l2-advertisement - namespace: metallb-system -spec: - ipAddressPools: - - default-pool diff --git a/metallb/templates/podmonitor.yaml b/metallb/templates/podmonitor.yaml deleted file mode 100644 index 42de881..0000000 --- a/metallb/templates/podmonitor.yaml +++ /dev/null @@ -1,108 +0,0 @@ -{{- if .Values.prometheus.podMonitor.enabled }} -apiVersion: monitoring.coreos.com/v1 -kind: PodMonitor -metadata: - name: {{ template "metallb.fullname" . }}-controller - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: controller - {{- if .Values.prometheus.podMonitor.additionalLabels }} -{{ toYaml .Values.prometheus.podMonitor.additionalLabels | indent 4 }} - {{- end }} - {{- if .Values.prometheus.podMonitor.annotations }} - annotations: -{{ toYaml .Values.prometheus.podMonitor.annotations | indent 4 }} - {{- end }} -spec: - jobLabel: {{ .Values.prometheus.podMonitor.jobLabel | quote }} - selector: - matchLabels: - {{- include "metallb.selectorLabels" . | nindent 6 }} - app.kubernetes.io/component: controller - namespaceSelector: - matchNames: - - {{ .Release.Namespace }} - podMetricsEndpoints: - - port: monitoring - path: /metrics - {{- if .Values.prometheus.podMonitor.interval }} - interval: {{ .Values.prometheus.podMonitor.interval }} - {{- end }} -{{- if .Values.prometheus.podMonitor.metricRelabelings }} - metricRelabelings: -{{- toYaml .Values.prometheus.podMonitor.metricRelabelings | nindent 4 }} -{{- end }} -{{- if .Values.prometheus.podMonitor.relabelings }} - relabelings: -{{- toYaml .Values.prometheus.podMonitor.relabelings | nindent 4 }} -{{- end }} -{{- if .Values.speaker.enabled }} ---- -apiVersion: monitoring.coreos.com/v1 -kind: PodMonitor -metadata: - name: {{ template "metallb.fullname" . }}-speaker - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: speaker - {{- if .Values.prometheus.podMonitor.additionalLabels }} -{{ toYaml .Values.prometheus.podMonitor.additionalLabels | indent 4 }} - {{- end }} - {{- if .Values.prometheus.podMonitor.annotations }} - annotations: -{{ toYaml .Values.prometheus.podMonitor.annotations | indent 4 }} - {{- end }} -spec: - jobLabel: {{ .Values.prometheus.podMonitor.jobLabel | quote }} - selector: - matchLabels: - {{- include "metallb.selectorLabels" . | nindent 6 }} - app.kubernetes.io/component: speaker - namespaceSelector: - matchNames: - - {{ .Release.Namespace }} - podMetricsEndpoints: - - port: monitoring - path: /metrics - {{- if .Values.prometheus.podMonitor.interval }} - interval: {{ .Values.prometheus.podMonitor.interval }} - {{- end }} -{{- if .Values.prometheus.podMonitor.metricRelabelings }} - metricRelabelings: -{{- toYaml .Values.prometheus.podMonitor.metricRelabelings | nindent 4 }} -{{- end }} -{{- if .Values.prometheus.podMonitor.relabelings }} - relabelings: -{{- toYaml .Values.prometheus.podMonitor.relabelings | nindent 4 }} -{{- end }} -{{- end }} ---- -{{- if .Values.prometheus.rbacPrometheus }} -apiVersion: rbac.authorization.k8s.io/v1 -kind: Role -metadata: - name: {{ template "metallb.fullname" . }}-prometheus -rules: - - apiGroups: - - "" - resources: - - pods - verbs: - - get - - list - - watch ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding -metadata: - name: {{ template "metallb.fullname" . }}-prometheus -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: {{ template "metallb.fullname" . }}-prometheus -subjects: - - kind: ServiceAccount - name: {{ required ".Values.prometheus.serviceAccount must be defined when .Values.prometheus.podMonitor.enabled == true" .Values.prometheus.serviceAccount }} - namespace: {{ required ".Values.prometheus.namespace must be defined when .Values.prometheus.podMonitor.enabled == true" .Values.prometheus.namespace }} -{{- end }} -{{- end }} diff --git a/metallb/templates/prometheusrules.yaml b/metallb/templates/prometheusrules.yaml deleted file mode 100644 index 64e44c6..0000000 --- a/metallb/templates/prometheusrules.yaml +++ /dev/null @@ -1,84 +0,0 @@ -{{- if .Values.prometheus.prometheusRule.enabled }} -apiVersion: monitoring.coreos.com/v1 -kind: PrometheusRule -metadata: - name: {{ template "metallb.fullname" . }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - {{- if .Values.prometheus.prometheusRule.additionalLabels }} -{{ toYaml .Values.prometheus.prometheusRule.additionalLabels | indent 4 }} - {{- end }} - {{- if .Values.prometheus.prometheusRule.annotations }} - annotations: -{{ toYaml .Values.prometheus.prometheusRule.annotations | indent 4 }} - {{- end }} -spec: - groups: - - name: {{ template "metallb.fullname" . }}.rules - rules: - {{- if .Values.prometheus.prometheusRule.staleConfig.enabled }} - - alert: MetalLBStaleConfig - annotations: - summary: {{`'Stale config on {{ $labels.pod }}'`}} - description: {{`'{{ $labels.job }} - MetalLB {{ $labels.container }} on {{ $labels.pod }} has a stale config for > 1 minute'`}} - expr: metallb_k8s_client_config_stale_bool{job=~"{{ template "metallb.fullname" . }}.*"} == 1 - for: 1m - {{- with .Values.prometheus.prometheusRule.staleConfig.labels }} - labels: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- end }} - {{- if .Values.prometheus.prometheusRule.configNotLoaded.enabled }} - - alert: MetalLBConfigNotLoaded - annotations: - summary: {{`'Config on {{ $labels.pod }} has not been loaded'`}} - description: {{`'{{ $labels.job }} - MetalLB {{ $labels.container }} on {{ $labels.pod }} has not loaded for > 1 minute'`}} - expr: metallb_k8s_client_config_loaded_bool{job=~"{{ template "metallb.fullname" . }}.*"} == 0 - for: 1m - {{- with .Values.prometheus.prometheusRule.configNotLoaded.labels }} - labels: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- end }} - {{- if .Values.prometheus.prometheusRule.addressPoolExhausted.enabled }} - - alert: MetalLBAddressPoolExhausted - annotations: - summary: {{`'Exhausted address pool on {{ $labels.pod }}'`}} - description: {{`'{{ $labels.job }} - MetalLB {{ $labels.container }} on {{ $labels.pod }} has exhausted address pool {{ $labels.pool }} for > 1 minute'`}} - expr: metallb_allocator_addresses_in_use_total >= on(pool) metallb_allocator_addresses_total - for: 1m - {{- with .Values.prometheus.prometheusRule.addressPoolExhausted.labels }} - labels: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- end }} - - {{- if .Values.prometheus.prometheusRule.addressPoolUsage.enabled }} - {{- range .Values.prometheus.prometheusRule.addressPoolUsage.thresholds }} - - alert: MetalLBAddressPoolUsage{{ .percent }}Percent - annotations: - summary: {{`'Exhausted address pool on {{ $labels.pod }}'`}} - message: {{`'{{ $labels.job }} - MetalLB {{ $labels.container }} on {{ $labels.pod }} has address pool {{ $labels.pool }} past `}}{{ .percent }}{{`% usage for > 1 minute'`}} - expr: ( metallb_allocator_addresses_in_use_total / on(pool) metallb_allocator_addresses_total ) * 100 > {{ .percent }} - {{- with .labels }} - labels: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- end }} - {{- end }} - {{- if .Values.prometheus.prometheusRule.bgpSessionDown.enabled }} - - alert: MetalLBBGPSessionDown - annotations: - summary: {{`'BGP session down on {{ $labels.pod }}'`}} - message: {{`'{{ $labels.job }} - MetalLB {{ $labels.container }} on {{ $labels.pod }} has BGP session {{ $labels.peer }} down for > 1 minute'`}} - expr: metallb_bgp_session_up{job=~"{{ template "metallb.fullname" . }}.*"} == 0 - for: 1m - {{- with .Values.prometheus.prometheusRule.bgpSessionDown.labels }} - labels: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- end }} - {{- with .Values.prometheus.prometheusRule.extraAlerts }} - {{- toYaml . | nindent 4 }} - {{- end}} -{{- end }} diff --git a/metallb/templates/rbac.yaml b/metallb/templates/rbac.yaml deleted file mode 100644 index 10ffbd8..0000000 --- a/metallb/templates/rbac.yaml +++ /dev/null @@ -1,216 +0,0 @@ -{{- if .Values.rbac.create -}} -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: {{ template "metallb.fullname" . }}:controller - labels: - {{- include "metallb.labels" . | nindent 4 }} -rules: -- apiGroups: [""] - resources: ["services", "namespaces"] - verbs: ["get", "list", "watch"] -- apiGroups: [""] - resources: ["nodes"] - verbs: ["list"] -- apiGroups: [""] - resources: ["services/status"] - verbs: ["update"] -- apiGroups: [""] - resources: ["events"] - verbs: ["create", "patch"] -- apiGroups: ["admissionregistration.k8s.io"] - resources: ["validatingwebhookconfigurations"] - resourceNames: ["metallb-webhook-configuration"] - verbs: ["create", "delete", "get", "list", "patch", "update", "watch"] -- apiGroups: ["admissionregistration.k8s.io"] - resources: ["validatingwebhookconfigurations"] - verbs: ["list", "watch"] -- apiGroups: ["apiextensions.k8s.io"] - resources: ["customresourcedefinitions"] - resourceNames: ["bfdprofiles.metallb.io","bgpadvertisements.metallb.io", - "bgppeers.metallb.io","ipaddresspools.metallb.io","l2advertisements.metallb.io","communities.metallb.io"] - verbs: ["create", "delete", "get", "list", "patch", "update", "watch"] -- apiGroups: ["apiextensions.k8s.io"] - resources: ["customresourcedefinitions"] - verbs: ["list", "watch"] -{{- if .Values.prometheus.secureMetricsPort }} -- apiGroups: ["authentication.k8s.io"] - resources: ["tokenreviews"] - verbs: ["create"] -- apiGroups: ["authorization.k8s.io"] - resources: ["subjectaccessreviews"] - verbs: ["create"] -{{- end }} -{{- if .Values.speaker.enabled }} ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: {{ template "metallb.fullname" . }}:speaker - labels: - {{- include "metallb.labels" . | nindent 4 }} -rules: -- apiGroups: [""] - resources: ["services", "endpoints", "nodes", "namespaces"] - verbs: ["get", "list", "watch"] -- apiGroups: ["discovery.k8s.io"] - resources: ["endpointslices"] - verbs: ["get", "list", "watch"] -- apiGroups: [""] - resources: ["events"] - verbs: ["create", "patch"] -- apiGroups: ["metallb.io"] - resources: ["servicel2statuses","servicel2statuses/status"] - verbs: ["*"] -{{- if .Values.prometheus.secureMetricsPort }} -- apiGroups: ["authentication.k8s.io"] - resources: ["tokenreviews"] - verbs: ["create"] -- apiGroups: ["authorization.k8s.io"] - resources: ["subjectaccessreviews"] - verbs: ["create"] -{{- end }} -{{- if or .Values.frrk8s.enabled .Values.frrk8s.external }} -- apiGroups: ["frrk8s.metallb.io"] - resources: ["frrconfigurations"] - verbs: ["get", "list", "watch","create","update","delete"] -{{- end }} ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: Role -metadata: - name: {{ include "metallb.fullname" . }}-pod-lister - namespace: {{ .Release.Namespace | quote }} - labels: {{- include "metallb.labels" . | nindent 4 }} -rules: -- apiGroups: [""] - resources: ["pods"] - verbs: ["list", "get"] -- apiGroups: [""] - resources: ["secrets"] - verbs: ["get", "list", "watch"] -- apiGroups: [""] - resources: ["configmaps"] - verbs: ["get", "list", "watch"] -- apiGroups: ["metallb.io"] - resources: ["bfdprofiles"] - verbs: ["get", "list", "watch"] -- apiGroups: ["metallb.io"] - resources: ["bgppeers"] - verbs: ["get", "list", "watch"] -- apiGroups: ["metallb.io"] - resources: ["l2advertisements"] - verbs: ["get", "list", "watch"] -- apiGroups: ["metallb.io"] - resources: ["bgpadvertisements"] - verbs: ["get", "list", "watch"] -- apiGroups: ["metallb.io"] - resources: ["ipaddresspools"] - verbs: ["get", "list", "watch"] -- apiGroups: ["metallb.io"] - resources: ["communities"] - verbs: ["get", "list", "watch"] -{{- end }} ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: Role -metadata: - name: {{ include "metallb.fullname" . }}-controller - namespace: {{ .Release.Namespace | quote }} - labels: {{- include "metallb.labels" . | nindent 4 }} -rules: -{{- if and .Values.speaker.enabled .Values.speaker.memberlist.enabled }} -- apiGroups: [""] - resources: ["secrets"] - verbs: ["create", "get", "list", "watch"] -- apiGroups: [""] - resources: ["secrets"] - resourceNames: [{{ include "metallb.secretName" . | quote }}] - verbs: ["list"] -- apiGroups: ["apps"] - resources: ["deployments"] - resourceNames: ["{{ template "metallb.fullname" . }}-controller"] - verbs: ["get"] -{{- end }} -- apiGroups: [""] - resources: ["secrets"] - verbs: ["create", "delete", "get", "list", "patch", "update", "watch"] -- apiGroups: ["metallb.io"] - resources: ["ipaddresspools"] - verbs: ["get", "list", "watch"] -- apiGroups: ["metallb.io"] - resources: ["bgppeers"] - verbs: ["get", "list"] -- apiGroups: ["metallb.io"] - resources: ["bgpadvertisements"] - verbs: ["get", "list"] -- apiGroups: ["metallb.io"] - resources: ["l2advertisements"] - verbs: ["get", "list"] -- apiGroups: ["metallb.io"] - resources: ["communities"] - verbs: ["get", "list","watch"] -- apiGroups: ["metallb.io"] - resources: ["bfdprofiles"] - verbs: ["get", "list","watch"] ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: {{ template "metallb.fullname" . }}:controller - labels: - {{- include "metallb.labels" . | nindent 4 }} -subjects: -- kind: ServiceAccount - name: {{ template "metallb.controller.serviceAccountName" . }} - namespace: {{ .Release.Namespace }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: {{ template "metallb.fullname" . }}:controller -{{- if .Values.speaker.enabled }} ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: {{ template "metallb.fullname" . }}:speaker - labels: - {{- include "metallb.labels" . | nindent 4 }} -subjects: -- kind: ServiceAccount - name: {{ template "metallb.speaker.serviceAccountName" . }} - namespace: {{ .Release.Namespace }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: {{ template "metallb.fullname" . }}:speaker ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding -metadata: - name: {{ include "metallb.fullname" . }}-pod-lister - namespace: {{ .Release.Namespace | quote }} - labels: {{- include "metallb.labels" . | nindent 4 }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: {{ include "metallb.fullname" . }}-pod-lister -subjects: -- kind: ServiceAccount - name: {{ include "metallb.speaker.serviceAccountName" . }} -{{- end }} ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding -metadata: - name: {{ include "metallb.fullname" . }}-controller - namespace: {{ .Release.Namespace | quote }} - labels: {{- include "metallb.labels" . | nindent 4 }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: {{ include "metallb.fullname" . }}-controller -subjects: -- kind: ServiceAccount - name: {{ include "metallb.controller.serviceAccountName" . }} -{{- end -}} diff --git a/metallb/templates/service-accounts.yaml b/metallb/templates/service-accounts.yaml deleted file mode 100644 index 8d92a04..0000000 --- a/metallb/templates/service-accounts.yaml +++ /dev/null @@ -1,30 +0,0 @@ -{{- if .Values.controller.serviceAccount.create }} ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - name: {{ template "metallb.controller.serviceAccountName" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: controller - {{- with .Values.controller.serviceAccount.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} -{{- end }} -{{- if and .Values.speaker.enabled .Values.speaker.serviceAccount.create }} ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - name: {{ template "metallb.speaker.serviceAccountName" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: speaker - {{- with .Values.speaker.serviceAccount.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} -{{- end }} diff --git a/metallb/templates/servicemonitor.yaml b/metallb/templates/servicemonitor.yaml deleted file mode 100644 index 2a92e48..0000000 --- a/metallb/templates/servicemonitor.yaml +++ /dev/null @@ -1,199 +0,0 @@ -{{- if and .Values.prometheus.serviceMonitor.enabled .Values.prometheus.podMonitor.enabled }} -{{- fail "prometheus.serviceMonitor.enabled and prometheus.podMonitor.enabled cannot both be set" }} -{{- end }} - -{{- if .Values.prometheus.serviceMonitor.enabled }} -{{- if .Values.speaker.enabled }} -apiVersion: monitoring.coreos.com/v1 -kind: ServiceMonitor -metadata: - name: {{ template "metallb.fullname" . }}-speaker-monitor - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: speaker - {{- if .Values.prometheus.serviceMonitor.speaker.additionalLabels }} -{{ toYaml .Values.prometheus.serviceMonitor.speaker.additionalLabels | indent 4 }} - {{- end }} - {{- if .Values.prometheus.serviceMonitor.speaker.annotations }} - annotations: -{{ toYaml .Values.prometheus.serviceMonitor.speaker.annotations | indent 4 }} - {{- end }} -spec: - endpoints: - - port: {{ template "metrics.exposedportname" . }} - honorLabels: true - {{- if .Values.prometheus.serviceMonitor.metricRelabelings }} - metricRelabelings: - {{- toYaml .Values.prometheus.serviceMonitor.metricRelabelings | nindent 8 }} - {{- end -}} - {{- if .Values.prometheus.serviceMonitor.relabelings }} - relabelings: - {{- toYaml .Values.prometheus.serviceMonitor.relabelings | nindent 8 }} - {{- end }} - {{- if .Values.prometheus.serviceMonitor.interval }} - interval: {{ .Values.prometheus.serviceMonitor.interval }} - {{- end -}} -{{ if .Values.prometheus.secureMetricsPort }} - bearerTokenFile: "/var/run/secrets/kubernetes.io/serviceaccount/token" - scheme: "https" -{{- if .Values.prometheus.serviceMonitor.speaker.tlsConfig }} - tlsConfig: -{{ toYaml .Values.prometheus.serviceMonitor.speaker.tlsConfig | indent 8 }} -{{- end }} -{{ end }} -{{- if .Values.speaker.frr.enabled }} - - port: {{ template "metrics.exposedfrrportname" . }} - honorLabels: true -{{ if .Values.speaker.frr.secureMetricsPort }} - {{- if .Values.prometheus.serviceMonitor.interval }} - interval: {{ .Values.prometheus.serviceMonitor.interval }} - {{- end }} - bearerTokenFile: "/var/run/secrets/kubernetes.io/serviceaccount/token" - scheme: "https" -{{- if .Values.prometheus.serviceMonitor.speaker.tlsConfig }} - tlsConfig: -{{ toYaml .Values.prometheus.serviceMonitor.speaker.tlsConfig | indent 8 }} -{{- end }} -{{- end }} -{{- end }} - jobLabel: {{ .Values.prometheus.serviceMonitor.jobLabel | quote }} - namespaceSelector: - matchNames: - - {{ .Release.Namespace }} - selector: - matchLabels: - name: {{ template "metallb.fullname" . }}-speaker-monitor-service ---- -apiVersion: v1 -kind: Service -metadata: - annotations: - prometheus.io/scrape: "true" - {{- if .Values.prometheus.serviceMonitor.speaker.annotations }} -{{ toYaml .Values.prometheus.serviceMonitor.speaker.annotations | indent 4 }} - {{- end }} - labels: - name: {{ template "metallb.fullname" . }}-speaker-monitor-service - {{- include "metallb.labels" . | nindent 4 }} - name: {{ template "metallb.fullname" . }}-speaker-monitor-service - namespace: {{ .Release.Namespace | quote }} -spec: - selector: - {{- include "metallb.selectorLabels" . | nindent 4 }} - app.kubernetes.io/component: speaker - clusterIP: None - ports: - - name: {{ template "metrics.exposedportname" . }} - port: {{ template "metrics.exposedport" . }} - targetPort: {{ template "metrics.exposedport" . }} -{{- if .Values.speaker.frr.enabled }} - - name: {{ template "metrics.exposedfrrportname" . }} - port: {{ template "metrics.exposedfrrport" . }} - targetPort: {{ template "metrics.exposedfrrport" . }} -{{- end }} - sessionAffinity: None - type: ClusterIP -{{- end }} ---- -apiVersion: monitoring.coreos.com/v1 -kind: ServiceMonitor -metadata: - name: {{ template "metallb.fullname" . }}-controller-monitor - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - {{- if .Values.prometheus.serviceMonitor.controller.additionalLabels }} -{{ toYaml .Values.prometheus.serviceMonitor.controller.additionalLabels | indent 4 }} - {{- end }} - {{- if .Values.prometheus.serviceMonitor.controller.annotations }} - annotations: -{{ toYaml .Values.prometheus.serviceMonitor.controller.annotations | indent 4 }} - {{- end }} -spec: - endpoints: - - port: {{ template "metrics.exposedportname" . }} - {{- if .Values.prometheus.serviceMonitor.metricRelabelings }} - metricRelabelings: - {{- toYaml .Values.prometheus.serviceMonitor.metricRelabelings | nindent 8 }} - {{- end -}} - {{- if .Values.prometheus.serviceMonitor.relabelings }} - relabelings: - {{- toYaml .Values.prometheus.serviceMonitor.relabelings | nindent 8 }} - {{- end }} - {{- if .Values.prometheus.serviceMonitor.interval }} - interval: {{ .Values.prometheus.serviceMonitor.interval }} - {{- end }} - honorLabels: true -{{- if .Values.prometheus.secureMetricsPort }} - bearerTokenFile: "/var/run/secrets/kubernetes.io/serviceaccount/token" - scheme: "https" -{{- if .Values.prometheus.serviceMonitor.controller.tlsConfig }} - tlsConfig: -{{ toYaml .Values.prometheus.serviceMonitor.controller.tlsConfig | indent 8 }} -{{- end }} -{{- end }} - jobLabel: {{ .Values.prometheus.serviceMonitor.jobLabel | quote }} - namespaceSelector: - matchNames: - - {{ .Release.Namespace }} - selector: - matchLabels: - name: {{ template "metallb.fullname" . }}-controller-monitor-service ---- -apiVersion: v1 -kind: Service -metadata: - annotations: - prometheus.io/scrape: "true" - {{- if .Values.prometheus.serviceMonitor.controller.annotations }} -{{ toYaml .Values.prometheus.serviceMonitor.controller.annotations | indent 4 }} - {{- end }} - labels: - name: {{ template "metallb.fullname" . }}-controller-monitor-service - name: {{ template "metallb.fullname" . }}-controller-monitor-service -spec: - selector: - {{- include "metallb.selectorLabels" . | nindent 4 }} - app.kubernetes.io/component: controller - clusterIP: None - ports: - - name: {{ template "metrics.exposedportname" . }} - port: {{ template "metrics.exposedport" . }} - targetPort: {{ template "metrics.exposedport" . }} - sessionAffinity: None - type: ClusterIP ---- -{{- if .Values.prometheus.rbacPrometheus }} -apiVersion: rbac.authorization.k8s.io/v1 -kind: Role -metadata: - name: {{ template "metallb.fullname" . }}-prometheus - namespace: {{ .Release.Namespace | quote }} -rules: - - apiGroups: - - "" - resources: - - pods - - services - - endpoints - verbs: - - get - - list - - watch ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding -metadata: - name: {{ template "metallb.fullname" . }}-prometheus - namespace: {{ .Release.Namespace | quote }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: {{ template "metallb.fullname" . }}-prometheus -subjects: - - kind: ServiceAccount - name: {{ required ".Values.prometheus.serviceAccount must be defined when .Values.prometheus.serviceMonitor.enabled == true" .Values.prometheus.serviceAccount }} - namespace: {{ required ".Values.prometheus.namespace must be defined when .Values.prometheus.serviceMonitor.enabled == true" .Values.prometheus.namespace }} -{{- end }} -{{- end }} diff --git a/metallb/templates/speaker.yaml b/metallb/templates/speaker.yaml deleted file mode 100644 index e70743c..0000000 --- a/metallb/templates/speaker.yaml +++ /dev/null @@ -1,568 +0,0 @@ -{{- if .Values.speaker.frr.enabled }} -{{- if or .Values.frrk8s.enabled .Values.frrk8s.external }} -{{- fail "speaker.frr.enabled and frrk8s.enabled / external are mutually exclusive!" }} -{{- end }} -{{- end }} - -{{- if and .Values.frrk8s.enabled .Values.frrk8s.external }} -{{- fail "frrk8s.enabled frrk8s.external are mutually exclusive!" }} -{{- end }} - -{{- if .Values.speaker.frr.enabled }} - -# FRR expects to have these files owned by frr:frr on startup. -# Having them in a ConfigMap allows us to modify behaviors: for example enabling more daemons on startup. -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ template "metallb.fullname" . }}-frr-startup - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: speaker -data: - daemons: | - # This file tells the frr package which daemons to start. - # - # Sample configurations for these daemons can be found in - # /usr/share/doc/frr/examples/. - # - # ATTENTION: - # - # When activating a daemon for the first time, a config file, even if it is - # empty, has to be present *and* be owned by the user and group "frr", else - # the daemon will not be started by /etc/init.d/frr. The permissions should - # be u=rw,g=r,o=. - # When using "vtysh" such a config file is also needed. It should be owned by - # group "frrvty" and set to ug=rw,o= though. Check /etc/pam.d/frr, too. - # - # The watchfrr and zebra daemons are always started. - # - bgpd=yes - ospfd=no - ospf6d=no - ripd=no - ripngd=no - isisd=no - pimd=no - ldpd=no - nhrpd=no - eigrpd=no - babeld=no - sharpd=no - pbrd=no - bfdd=yes - fabricd=no - vrrpd=no - - # - # If this option is set the /etc/init.d/frr script automatically loads - # the config via "vtysh -b" when the servers are started. - # Check /etc/pam.d/frr if you intend to use "vtysh"! - # - vtysh_enable=yes - zebra_options=" -A 127.0.0.1 -s 90000000" - bgpd_options=" -A 127.0.0.1 -p 0" - ospfd_options=" -A 127.0.0.1" - ospf6d_options=" -A ::1" - ripd_options=" -A 127.0.0.1" - ripngd_options=" -A ::1" - isisd_options=" -A 127.0.0.1" - pimd_options=" -A 127.0.0.1" - ldpd_options=" -A 127.0.0.1" - nhrpd_options=" -A 127.0.0.1" - eigrpd_options=" -A 127.0.0.1" - babeld_options=" -A 127.0.0.1" - sharpd_options=" -A 127.0.0.1" - pbrd_options=" -A 127.0.0.1" - staticd_options="-A 127.0.0.1" - bfdd_options=" -A 127.0.0.1" - fabricd_options="-A 127.0.0.1" - vrrpd_options=" -A 127.0.0.1" - - # configuration profile - # - #frr_profile="traditional" - #frr_profile="datacenter" - - # - # This is the maximum number of FD's that will be available. - # Upon startup this is read by the control files and ulimit - # is called. Uncomment and use a reasonable value for your - # setup if you are expecting a large number of peers in - # say BGP. - #MAX_FDS=1024 - - # The list of daemons to watch is automatically generated by the init script. - #watchfrr_options="" - - # for debugging purposes, you can specify a "wrap" command to start instead - # of starting the daemon directly, e.g. to use valgrind on ospfd: - # ospfd_wrap="/usr/bin/valgrind" - # or you can use "all_wrap" for all daemons, e.g. to use perf record: - # all_wrap="/usr/bin/perf record --call-graph -" - # the normal daemon command is added to this at the end. - vtysh.conf: |+ - service integrated-vtysh-config - frr.conf: |+ - ! This file gets overriden the first time the speaker renders a config. - ! So anything configured here is only temporary. - frr version 8.0 - frr defaults traditional - hostname Router - line vty - log file /etc/frr/frr.log informational -{{- end }} ---- -{{- if .Values.speaker.enabled }} -apiVersion: apps/v1 -kind: DaemonSet -metadata: - name: {{ template "metallb.fullname" . }}-speaker - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} - app.kubernetes.io/component: speaker - {{- range $key, $value := .Values.speaker.labels }} - {{ $key }}: {{ $value | quote }} - {{- end }} -spec: - {{- if .Values.speaker.updateStrategy }} - updateStrategy: {{- toYaml .Values.speaker.updateStrategy | nindent 4 }} - {{- end }} - selector: - matchLabels: - {{- include "metallb.selectorLabels" . | nindent 6 }} - app.kubernetes.io/component: speaker - template: - metadata: - {{- if or .Values.prometheus.scrapeAnnotations .Values.speaker.podAnnotations }} - annotations: - {{- if .Values.prometheus.scrapeAnnotations }} - prometheus.io/scrape: "true" - {{- if not .Values.speaker.frr.enabled }} - prometheus.io/port: "{{ .Values.prometheus.metricsPort }}" - {{- end }} - {{- end }} - {{- with .Values.speaker.podAnnotations }} - {{- toYaml . | nindent 8 }} - {{- end }} - {{- end }} - labels: - {{- include "metallb.selectorLabels" . | nindent 8 }} - app.kubernetes.io/component: speaker - {{- range $key, $value := .Values.speaker.labels }} - {{ $key }}: {{ $value | quote }} - {{- end }} - spec: - {{- if .Values.speaker.runtimeClassName }} - runtimeClassName: {{ .Values.speaker.runtimeClassName }} - {{- end }} - {{- with .Values.imagePullSecrets }} - imagePullSecrets: - {{- toYaml . | nindent 8 }} - {{- end }} - serviceAccountName: {{ template "metallb.speaker.serviceAccountName" . }} - terminationGracePeriodSeconds: 0 - hostNetwork: true - {{- if .Values.speaker.securityContext }} - securityContext: - {{- toYaml .Values.speaker.securityContext | nindent 8 }} - {{- end }} - volumes: - {{- if .Values.prometheus.speakerMetricsTLSSecret }} - - name: metrics-certs - secret: - secretName: {{ .Values.prometheus.speakerMetricsTLSSecret }} - {{- end }} - {{- if .Values.speaker.memberlist.enabled }} - - name: memberlist - secret: - secretName: {{ include "metallb.secretName" . }} - defaultMode: 420 - {{- end }} - {{- if .Values.speaker.excludeInterfaces.enabled }} - - name: metallb-excludel2 - configMap: - defaultMode: 256 - name: metallb-excludel2 - {{- end }} - {{- if .Values.speaker.frr.enabled }} - - name: frr-sockets - emptyDir: {} - - name: frr-startup - configMap: - name: {{ template "metallb.fullname" . }}-frr-startup - - name: frr-conf - emptyDir: {} - - name: reloader - emptyDir: {} - - name: metrics - emptyDir: {} - initContainers: - # Copies the initial config files with the right permissions to the shared volume. - - name: cp-frr-files - image: {{ .Values.speaker.frr.image.repository }}:{{ .Values.speaker.frr.image.tag | default .Chart.AppVersion }} - securityContext: - runAsUser: 100 - runAsGroup: 101 - command: ["/bin/sh", "-c", "cp -rLf /tmp/frr/* /etc/frr/"] - volumeMounts: - - name: frr-startup - mountPath: /tmp/frr - - name: frr-conf - mountPath: /etc/frr - # Copies the reloader to the shared volume between the speaker and reloader. - - name: cp-reloader - image: {{ .Values.speaker.image.repository }}:{{ .Values.speaker.image.tag | default .Chart.AppVersion }} - command: ["/cp-tool","/frr-reloader.sh","/etc/frr_reloader/frr-reloader.sh"] - volumeMounts: - - name: reloader - mountPath: /etc/frr_reloader - # Copies the metrics exporter - - name: cp-metrics - image: {{ .Values.speaker.image.repository }}:{{ .Values.speaker.image.tag | default .Chart.AppVersion }} - command: ["/cp-tool","/frr-metrics","/etc/frr_metrics/frr-metrics"] - volumeMounts: - - name: metrics - mountPath: /etc/frr_metrics - shareProcessNamespace: true - {{- end }} - containers: - - name: speaker - image: {{ .Values.speaker.image.repository }}:{{ .Values.speaker.image.tag | default .Chart.AppVersion }} - {{- if .Values.speaker.image.pullPolicy }} - imagePullPolicy: {{ .Values.speaker.image.pullPolicy }} - {{- end }} - {{- if .Values.speaker.command }} - command: - - {{ .Values.speaker.command }} - {{- end }} - args: - - --port={{ .Values.prometheus.metricsPort }} - {{- with .Values.speaker.logLevel }} - - --log-level={{ . }} - {{- end }} - {{- if .Values.loadBalancerClass }} - - --lb-class={{ .Values.loadBalancerClass }} - {{- end }} - {{- if .Values.speaker.wanConfig }} - - --ml-wan-config - {{- end }} - {{- if .Values.speaker.ignoreExcludeLB}} - - --ignore-exclude-lb - {{- end }} - {{- if .Values.prometheus.secureMetricsPort }} - - --host=localhost - {{- end }} - {{- if .Values.frrk8s.external }} - - --frrk8s-namespace={{ required "namespace is required when frrk8s is external" .Values.frrk8s.namespace }} - {{- end }} - env: - - name: METALLB_NODE_NAME - valueFrom: - fieldRef: - fieldPath: spec.nodeName - - name: METALLB_HOST - valueFrom: - fieldRef: - fieldPath: status.hostIP - {{- if .Values.speaker.memberlist.enabled }} - {{- if .Values.speaker.memberlist.mlBindAddrOverride }} - - name: METALLB_ML_BIND_ADDR - value: "{{ .Values.speaker.memberlist.mlBindAddrOverride }}" - {{ else }} - - name: METALLB_ML_BIND_ADDR - valueFrom: - fieldRef: - fieldPath: status.podIP - {{ end }} - - name: METALLB_ML_LABELS - value: "app.kubernetes.io/name={{ include "metallb.name" . }},app.kubernetes.io/component=speaker" - - name: METALLB_ML_BIND_PORT - value: "{{ .Values.speaker.memberlist.mlBindPort }}" - - name: METALLB_ML_SECRET_KEY_PATH - value: "{{ .Values.speaker.memberlist.mlSecretKeyPath }}" - {{- end }} - {{- if .Values.speaker.frr.enabled }} - - name: FRR_CONFIG_FILE - value: /etc/frr_reloader/frr.conf - - name: FRR_RELOADER_PID_FILE - value: /etc/frr_reloader/reloader.pid - - name: METALLB_BGP_TYPE - value: frr - {{- end }} - {{- if or .Values.frrk8s.enabled .Values.frrk8s.external }} - - name: METALLB_BGP_TYPE - value: frr-k8s - {{- end }} - - name: METALLB_POD_NAME - valueFrom: - fieldRef: - fieldPath: metadata.name - ports: - - name: monitoring - containerPort: {{ .Values.prometheus.metricsPort }} - {{- if .Values.speaker.memberlist.enabled }} - - name: memberlist-tcp - containerPort: {{ .Values.speaker.memberlist.mlBindPort }} - protocol: TCP - - name: memberlist-udp - containerPort: {{ .Values.speaker.memberlist.mlBindPort }} - protocol: UDP - {{- end }} - {{- if .Values.speaker.livenessProbe.enabled }} - livenessProbe: - httpGet: - {{- if .Values.prometheus.secureMetricsPort }} - host: localhost - {{- end }} - path: /metrics - port: monitoring - initialDelaySeconds: {{ .Values.speaker.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.speaker.livenessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.speaker.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.speaker.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.speaker.livenessProbe.failureThreshold }} - {{- end }} - {{- if .Values.speaker.readinessProbe.enabled }} - readinessProbe: - httpGet: - {{- if .Values.prometheus.secureMetricsPort }} - host: localhost - {{- end }} - path: /metrics - port: monitoring - initialDelaySeconds: {{ .Values.speaker.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.speaker.readinessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.speaker.readinessProbe.timeoutSeconds }} - successThreshold: {{ .Values.speaker.readinessProbe.successThreshold }} - failureThreshold: {{ .Values.speaker.readinessProbe.failureThreshold }} - {{- end }} - {{- with .Values.speaker.resources }} - resources: - {{- toYaml . | nindent 10 }} - {{- end }} - securityContext: - allowPrivilegeEscalation: false - readOnlyRootFilesystem: true - capabilities: - drop: - - ALL - add: - - NET_RAW - {{- if or .Values.speaker.frr.enabled .Values.speaker.memberlist.enabled .Values.speaker.excludeInterfaces.enabled }} - volumeMounts: - {{- if .Values.speaker.memberlist.enabled }} - - name: memberlist - mountPath: {{ .Values.speaker.memberlist.mlSecretKeyPath }} - {{- end }} - {{- if .Values.speaker.frr.enabled }} - - name: reloader - mountPath: /etc/frr_reloader - {{- end }} - {{- if .Values.speaker.excludeInterfaces.enabled }} - - name: metallb-excludel2 - mountPath: /etc/metallb - {{- end }} - {{- end }} - {{- if .Values.speaker.frr.enabled }} - - name: frr - securityContext: - capabilities: - add: - - NET_ADMIN - - NET_RAW - - SYS_ADMIN - - NET_BIND_SERVICE - image: {{ .Values.speaker.frr.image.repository }}:{{ .Values.speaker.frr.image.tag | default .Chart.AppVersion }} - {{- if .Values.speaker.frr.image.pullPolicy }} - imagePullPolicy: {{ .Values.speaker.frr.image.pullPolicy }} - {{- end }} - env: - - name: TINI_SUBREAPER - value: "true" - volumeMounts: - - name: frr-sockets - mountPath: /var/run/frr - - name: frr-conf - mountPath: /etc/frr - # The command is FRR's default entrypoint & waiting for the log file to appear and tailing it. - # If the log file isn't created in 60 seconds the tail fails and the container is restarted. - # This workaround is needed to have the frr logs as part of kubectl logs -c frr < speaker_pod_name >. - command: - - /bin/sh - - -c - - | - /sbin/tini -- /usr/lib/frr/docker-start & - attempts=0 - until [[ -f /etc/frr/frr.log || $attempts -eq 60 ]]; do - sleep 1 - attempts=$(( $attempts + 1 )) - done - tail -f /etc/frr/frr.log - {{- with .Values.speaker.frr.resources }} - resources: - {{- toYaml . | nindent 12 }} - {{- end }} - {{- if .Values.speaker.livenessProbe.enabled }} - livenessProbe: - httpGet: - {{- if .Values.prometheus.secureMetricsPort }} - host: localhost - {{- end }} - path: livez - port: {{ .Values.speaker.frr.metricsPort }} - initialDelaySeconds: {{ .Values.speaker.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.speaker.livenessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.speaker.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.speaker.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.speaker.livenessProbe.failureThreshold }} - {{- end }} - {{- if .Values.speaker.startupProbe.enabled }} - startupProbe: - httpGet: - {{- if .Values.prometheus.secureMetricsPort }} - host: localhost - {{- end }} - path: /livez - port: {{ .Values.speaker.frr.metricsPort }} - failureThreshold: {{ .Values.speaker.startupProbe.failureThreshold }} - periodSeconds: {{ .Values.speaker.startupProbe.periodSeconds }} - {{- end }} - - name: reloader - image: {{ .Values.speaker.frr.image.repository }}:{{ .Values.speaker.frr.image.tag | default .Chart.AppVersion }} - {{- if .Values.speaker.frr.image.pullPolicy }} - imagePullPolicy: {{ .Values.speaker.frr.image.pullPolicy }} - {{- end }} - command: ["/etc/frr_reloader/frr-reloader.sh"] - volumeMounts: - - name: frr-sockets - mountPath: /var/run/frr - - name: frr-conf - mountPath: /etc/frr - - name: reloader - mountPath: /etc/frr_reloader - {{- with .Values.speaker.reloader.resources }} - resources: - {{- toYaml . | nindent 12 }} - {{- end }} - - name: frr-metrics - image: {{ .Values.speaker.frr.image.repository }}:{{ .Values.speaker.frr.image.tag | default .Chart.AppVersion }} - command: ["/etc/frr_metrics/frr-metrics"] - args: - - --metrics-port={{ .Values.speaker.frr.metricsPort }} - {{- if .Values.prometheus.secureMetricsPort }} - - --host=localhost - {{- end }} - env: - - name: VTYSH_HISTFILE - value: /dev/null - ports: - - containerPort: {{ .Values.speaker.frr.metricsPort }} - name: monitoring - volumeMounts: - - name: frr-sockets - mountPath: /var/run/frr - - name: frr-conf - mountPath: /etc/frr - - name: metrics - mountPath: /etc/frr_metrics - {{- with .Values.speaker.frrMetrics.resources }} - resources: - {{- toYaml . | nindent 12 }} - {{- end }} - {{- end }} - {{- if .Values.prometheus.secureMetricsPort }} - - name: kube-rbac-proxy - image: {{ .Values.prometheus.rbacProxy.repository }}:{{ .Values.prometheus.rbacProxy.tag }} - imagePullPolicy: {{ .Values.prometheus.rbacProxy.pullPolicy }} - args: - - --logtostderr - - --secure-listen-address=:{{ .Values.prometheus.secureMetricsPort }} - - --upstream=http://localhost:{{ .Values.prometheus.metricsPort }}/ - - --tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - {{- if .Values.prometheus.speakerMetricsTLSSecret }} - - --tls-private-key-file=/etc/metrics/tls.key - - --tls-cert-file=/etc/metrics/tls.crt - {{- end }} - ports: - - containerPort: {{ .Values.prometheus.secureMetricsPort }} - name: metricshttps - resources: - requests: - cpu: 10m - memory: 20Mi - terminationMessagePolicy: FallbackToLogsOnError - {{- if .Values.prometheus.speakerMetricsTLSSecret }} - volumeMounts: - - name: metrics-certs - mountPath: /etc/metrics - readOnly: true - {{- end }} - {{ end }} - {{- if .Values.speaker.frr.enabled }} - {{- if .Values.speaker.frr.secureMetricsPort }} - - name: kube-rbac-proxy-frr - image: {{ .Values.prometheus.rbacProxy.repository }}:{{ .Values.prometheus.rbacProxy.tag | default .Chart.AppVersion }} - imagePullPolicy: {{ .Values.prometheus.rbacProxy.pullPolicy }} - args: - - --logtostderr - - --secure-listen-address=:{{ .Values.speaker.frr.secureMetricsPort }} - - --tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 - - --upstream=http://localhost:{{ .Values.speaker.frr.metricsPort }}/ - {{- if .Values.prometheus.speakerMetricsTLSSecret }} - - --tls-private-key-file=/etc/metrics/tls.key - - --tls-cert-file=/etc/metrics/tls.crt - {{- end }} - ports: - - containerPort: {{ .Values.speaker.frr.secureMetricsPort }} - name: frrmetricshttps - env: - - name: METALLB_HOST - valueFrom: - fieldRef: - fieldPath: status.hostIP - resources: - requests: - cpu: 10m - memory: 20Mi - terminationMessagePolicy: FallbackToLogsOnError - {{- if .Values.prometheus.speakerMetricsTLSSecret }} - volumeMounts: - - name: metrics-certs - mountPath: /etc/metrics - readOnly: true - {{- end }} - {{ end }} - {{- end }} - {{- if .Values.speaker.extraContainers }} - {{- toYaml .Values.speaker.extraContainers | nindent 6 }} - {{- end }} - nodeSelector: - "kubernetes.io/os": linux - {{- with .Values.speaker.nodeSelector }} - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.speaker.affinity }} - affinity: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- if or .Values.speaker.tolerateMaster .Values.speaker.tolerations }} - tolerations: - {{- if .Values.speaker.tolerateMaster }} - - key: node-role.kubernetes.io/master - effect: NoSchedule - operator: Exists - - key: node-role.kubernetes.io/control-plane - effect: NoSchedule - operator: Exists - {{- end }} - {{- with .Values.speaker.tolerations }} - {{- toYaml . | nindent 6 }} - {{- end }} - {{- end }} - {{- with .Values.speaker.priorityClassName }} - priorityClassName: {{ . | quote }} - {{- end }} -{{- end }} diff --git a/metallb/templates/webhooks.yaml b/metallb/templates/webhooks.yaml deleted file mode 100644 index e708bee..0000000 --- a/metallb/templates/webhooks.yaml +++ /dev/null @@ -1,150 +0,0 @@ -apiVersion: admissionregistration.k8s.io/v1 -kind: ValidatingWebhookConfiguration -metadata: - name: metallb-webhook-configuration - labels: - {{- include "metallb.labels" . | nindent 4 }} -webhooks: -- admissionReviewVersions: - - v1 - clientConfig: - service: - name: metallb-webhook-service - namespace: {{ .Release.Namespace }} - path: /validate-metallb-io-v1beta2-bgppeer - failurePolicy: {{ .Values.crds.validationFailurePolicy }} - name: bgppeervalidationwebhook.metallb.io - rules: - - apiGroups: - - metallb.io - apiVersions: - - v1beta2 - operations: - - CREATE - - UPDATE - resources: - - bgppeers - sideEffects: None -- admissionReviewVersions: - - v1 - clientConfig: - service: - name: metallb-webhook-service - namespace: {{ .Release.Namespace }} - path: /validate-metallb-io-v1beta1-ipaddresspool - failurePolicy: {{ .Values.crds.validationFailurePolicy }} - name: ipaddresspoolvalidationwebhook.metallb.io - rules: - - apiGroups: - - metallb.io - apiVersions: - - v1beta1 - operations: - - CREATE - - UPDATE - resources: - - ipaddresspools - sideEffects: None -- admissionReviewVersions: - - v1 - clientConfig: - service: - name: metallb-webhook-service - namespace: {{ .Release.Namespace }} - path: /validate-metallb-io-v1beta1-bgpadvertisement - failurePolicy: {{ .Values.crds.validationFailurePolicy }} - name: bgpadvertisementvalidationwebhook.metallb.io - rules: - - apiGroups: - - metallb.io - apiVersions: - - v1beta1 - operations: - - CREATE - - UPDATE - resources: - - bgpadvertisements - sideEffects: None -- admissionReviewVersions: - - v1 - clientConfig: - service: - name: metallb-webhook-service - namespace: {{ .Release.Namespace }} - path: /validate-metallb-io-v1beta1-community - failurePolicy: {{ .Values.crds.validationFailurePolicy }} - name: communityvalidationwebhook.metallb.io - rules: - - apiGroups: - - metallb.io - apiVersions: - - v1beta1 - operations: - - CREATE - - UPDATE - resources: - - communities - sideEffects: None -- admissionReviewVersions: - - v1 - clientConfig: - service: - name: metallb-webhook-service - namespace: {{ .Release.Namespace }} - path: /validate-metallb-io-v1beta1-bfdprofile - failurePolicy: {{ .Values.crds.validationFailurePolicy }} - name: bfdprofilevalidationwebhook.metallb.io - rules: - - apiGroups: - - metallb.io - apiVersions: - - v1beta1 - operations: - - CREATE - - DELETE - resources: - - bfdprofiles - sideEffects: None -- admissionReviewVersions: - - v1 - clientConfig: - service: - name: metallb-webhook-service - namespace: {{ .Release.Namespace }} - path: /validate-metallb-io-v1beta1-l2advertisement - failurePolicy: {{ .Values.crds.validationFailurePolicy }} - name: l2advertisementvalidationwebhook.metallb.io - rules: - - apiGroups: - - metallb.io - apiVersions: - - v1beta1 - operations: - - CREATE - - UPDATE - resources: - - l2advertisements - sideEffects: None ---- -apiVersion: v1 -kind: Service -metadata: - name: metallb-webhook-service - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} -spec: - ports: - - port: 443 - targetPort: 9443 - selector: - {{- include "metallb.selectorLabels" . | nindent 4 }} - app.kubernetes.io/component: controller ---- -apiVersion: v1 -kind: Secret -metadata: - name: metallb-webhook-cert - namespace: {{ .Release.Namespace | quote }} - labels: - {{- include "metallb.labels" . | nindent 4 }} diff --git a/metallb/values.schema.json b/metallb/values.schema.json deleted file mode 100644 index bc0dd84..0000000 --- a/metallb/values.schema.json +++ /dev/null @@ -1,448 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft-07/schema#", - "title": "Values", - "type": "object", - "definitions": { - "prometheusAlert": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "labels": { - "type": "object", - "additionalProperties": { "type": "string" } - } - }, - "required": [ "enabled" ] - }, - "probe": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "failureThreshold": { - "type": "integer" - }, - "initialDelaySeconds": { - "type": "integer" - }, - "periodSeconds": { - "type": "integer" - }, - "successThreshold": { - "type": "integer" - }, - "timeoutSeconds": { - "type": "integer" - } - }, - "required": [ - "failureThreshold", - "initialDelaySeconds", - "periodSeconds", - "successThreshold", - "timeoutSeconds" - ] - }, - "component": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "logLevel": { - "type": "string", - "enum": [ "all", "debug", "info", "warn", "error", "none" ] - }, - "image": { - "type": "object", - "properties": { - "repository": { - "type": "string" - }, - "tag": { - "anyOf": [ - { "type": "string" }, - { "type": "null" } - ] - }, - "pullPolicy": { - "anyOf": [ - { - "type": "null" - }, - { - "type": "string", - "enum": [ "Always", "IfNotPresent", "Never" ] - } - ] - } - } - }, - "serviceAccount": { - "type": "object", - "properties": { - "create": { - "type": "boolean" - }, - "name": { - "type": "string" - }, - "annotations": { - "type": "object" - } - } - }, - "resources": { - "type": "object" - }, - "nodeSelector": { - "type": "object" - }, - "tolerations": { - "type": "array", - "items": { - "type": "object" - } - }, - "priorityClassName": { - "type":"string" - }, - "runtimeClassName": { - "type":"string" - }, - "affinity": { - "type": "object" - }, - "podAnnotations": { - "type": "object" - }, - "livenessProbe": { - "$ref": "#/definitions/probe" - }, - "readinessProbe": { - "$ref": "#/definitions/probe" - } - }, - "required": [ - "image", - "serviceAccount" - ] - } - }, - "properties": { - "imagePullSecrets": { - "description": "Secrets used for pulling images", - "type": "array", - "items": { - "type": "object", - "properties": { - "name": { - "type": "string" - } - }, - "required": [ "name" ], - "additionalProperties": false - } - }, - "nameOverride": { - "description": "Override chart name", - "type": "string" - }, - "fullNameOverride": { - "description": "Override fully qualified app name", - "type": "string" - }, - "configInLine": { - "description": "MetalLB configuration", - "type": "object" - }, - "loadBalancerClass": { - "type":"string" - }, - "rbac": { - "description": "RBAC configuration", - "type": "object", - "properties": { - "create": { - "description": "Enable RBAC", - "type": "boolean" - } - } - }, - "prometheus": { - "description": "Prometheus monitoring config", - "type": "object", - "properties": { - "scrapeAnnotations": { "type": "boolean" }, - "metricsPort": { "type": "integer" }, - "secureMetricsPort": { "type": "integer" }, - "rbacPrometheus": { "type": "boolean" }, - "serviceAccount": { "type": "string" }, - "namespace": { "type": "string" }, - "rbacProxy": { - "description": "kube-rbac-proxy configuration", - "type": "object", - "properties": { - "repository": { "type": "string" }, - "tag": { "type": "string" } - } - }, - "podMonitor": { - "description": "Prometheus Operator PodMonitors", - "type": "object", - "properties": { - "enabled": { "type": "boolean" }, - "additionalMonitors": { "type": "object" }, - "jobLabel": { "type": "string" }, - "interval": { - "anyOf": [ - { "type": "integer" }, - { "type": "null" } - ] - }, - "metricRelabelings": { - "type": "array", - "items": { - "type": "object" - } - }, - "relabelings": { - "type": "array", - "items": { - "type": "object" - } - } - } - }, - "serviceMonitor": { - "description": "Prometheus Operator ServiceMonitors", - "type": "object", - "properties": { - "enabled": { "type": "boolean" }, - "jobLabel": { "type": "string" }, - "interval": { - "anyOf": [ - { "type": "integer" }, - { "type": "null" } - ] - }, - "metricRelabelings": { - "type": "array", - "items": { - "type": "object" - } - }, - "relabelings": { - "type": "array", - "items": { - "type": "object" - } - } - } - }, - "prometheusRule": { - "description": "Prometheus Operator alertmanager alerts", - "type": "object", - "properties": { - "enabled": { "type": "boolean" }, - "additionalMonitors": { "type": "object" }, - "staleConfig": { "$ref": "#/definitions/prometheusAlert" }, - "configNotLoaded": { "$ref": "#/definitions/prometheusAlert" }, - "addressPoolExhausted": { "$ref": "#/definitions/prometheusAlert" }, - "addressPoolUsage": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "thresholds": { - "type": "array", - "items": { - "type": "object", - "properties": { - "percent": { - "type": "integer", - "minimum": 0, - "maximum": 100 - }, - "labels": { - "type": "object", - "additionalProperties": { "type": "string" } - } - }, - "required": [ "percent" ] - } - } - }, - "required": [ "enabled" ] - }, - "bgpSessionDown": { "$ref": "#/definitions/prometheusAlert" }, - "extraAlerts": { - "type": "array", - "items": { - "type": "object" - } - } - }, - "required": [ - "enabled", - "staleConfig", - "configNotLoaded", - "addressPoolExhausted", - "addressPoolUsage", - "bgpSessionDown" - ] - } - }, - "required": [ "podMonitor", "prometheusRule" ] - }, - "controller": { - "allOf": [ - { "$ref": "#/definitions/component" }, - { "description": "MetalLB Controller", - "type": "object", - "properties": { - "strategy": { - "type": "object", - "properties": { - "type": { - "type": "string" - } - }, - "required": [ "type" ] - }, - "command" : { - "type": "string" - }, - "webhookMode" : { - "type": "string" - }, - "extraContainers": { - "type": "array", - "items": { - "type": "object" - } - } - } - } - ] - }, - "speaker": { - "allOf": [ - { "$ref": "#/definitions/component" }, - { "description": "MetalLB Speaker", - "type": "object", - "properties": { - "tolerateMaster": { - "type": "boolean" - }, - "memberlist": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "mlBindPort": { - "type": "integer" - }, - "mlBindAddrOverride": { - "type": "string" - }, - "mlSecretKeyPath": { - "type": "string" - } - } - }, - "excludeInterfaces": { - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - } - } - }, - "ignoreExcludeLB": { - "type": "boolean" - }, - "updateStrategy": { - "type": "object", - "properties": { - "type": { - "type": "string" - } - }, - "required": [ "type" ] - }, - "runtimeClassName": { - "type": "string" - }, - "securityContext": { - "type": "object" - }, - "secretName": { - "type": "string" - }, - "frr": { - "description": "Install FRR container in speaker deployment", - "type": "object", - "properties": { - "enabled": { - "type": "boolean" - }, - "image": { "$ref": "#/definitions/component/properties/image" }, - "metricsPort": { "type": "integer" }, - "secureMetricsPort": { "type": "integer" }, - "resources:": { "type": "object" } - }, - "required": [ "enabled" ] - }, - "command" : { - "type": "string" - }, - "reloader": { - "type": "object", - "properties": { - "resources": { "type": "object" } - } - }, - "frrMetrics": { - "type": "object", - "properties": { - "resources": { "type": "object" } - } - }, - "extraContainers": { - "type": "array", - "items": { - "type": "object" - } - } - }, - "required": [ "tolerateMaster" ] - } - ] - }, - "crds": { - "description": "CRD configuration", - "type": "object", - "properties": { - "enabled": { - "description": "Enable CRDs", - "type": "boolean" - }, - "validationFailurePolicy": { - "description": "Failure policy to use with validating webhooks", - "type": "string", - "enum": [ "Ignore", "Fail" ] - } - } - } - }, - "required": [ - "controller", - "speaker" - ] -} diff --git a/metallb/values.yaml b/metallb/values.yaml deleted file mode 100644 index 50d26bc..0000000 --- a/metallb/values.yaml +++ /dev/null @@ -1,365 +0,0 @@ -# Default values for metallb. -# This is a YAML-formatted file. -# Declare variables to be passed into your templates. - -imagePullSecrets: [] -nameOverride: "" -fullnameOverride: "" -loadBalancerClass: "" - -# To configure MetalLB, you must specify ONE of the following two -# options. - -rbac: - # create specifies whether to install and use RBAC rules. - create: true - -prometheus: - # scrape annotations specifies whether to add Prometheus metric - # auto-collection annotations to pods. See - # https://github.com/prometheus/prometheus/blob/release-2.1/documentation/examples/prometheus-kubernetes.yml - # for a corresponding Prometheus configuration. Alternatively, you - # may want to use the Prometheus Operator - # (https://github.com/coreos/prometheus-operator) for more powerful - # monitoring configuration. If you use the Prometheus operator, this - # can be left at false. - scrapeAnnotations: false - - # port both controller and speaker will listen on for metrics - metricsPort: 7472 - - # if set, enables rbac proxy on the controller and speaker to expose - # the metrics via tls. - # secureMetricsPort: 9120 - - # the name of the secret to be mounted in the speaker pod - # to expose the metrics securely. If not present, a self signed - # certificate to be used. - speakerMetricsTLSSecret: "" - - # the name of the secret to be mounted in the controller pod - # to expose the metrics securely. If not present, a self signed - # certificate to be used. - controllerMetricsTLSSecret: "" - - # prometheus doesn't have the permission to scrape all namespaces so we give it permission to scrape metallb's one - rbacPrometheus: true - - # the service account used by prometheus - # required when " .Values.prometheus.rbacPrometheus == true " and " .Values.prometheus.podMonitor.enabled=true or prometheus.serviceMonitor.enabled=true " - serviceAccount: "" - - # the namespace where prometheus is deployed - # required when " .Values.prometheus.rbacPrometheus == true " and " .Values.prometheus.podMonitor.enabled=true or prometheus.serviceMonitor.enabled=true " - namespace: "" - - # the image to be used for the kuberbacproxy container - rbacProxy: - repository: gcr.io/kubebuilder/kube-rbac-proxy - tag: v0.12.0 - pullPolicy: - - # Prometheus Operator PodMonitors - podMonitor: - # enable support for Prometheus Operator - enabled: false - - # optional additional labels for podMonitors - additionalLabels: {} - - # optional annotations for podMonitors - annotations: {} - - # Job label for scrape target - jobLabel: "app.kubernetes.io/name" - - # Scrape interval. If not set, the Prometheus default scrape interval is used. - interval: - - # metric relabel configs to apply to samples before ingestion. - metricRelabelings: [] - # - action: keep - # regex: 'kube_(daemonset|deployment|pod|namespace|node|statefulset).+' - # sourceLabels: [__name__] - - # relabel configs to apply to samples before ingestion. - relabelings: [] - # - sourceLabels: [__meta_kubernetes_pod_node_name] - # separator: ; - # regex: ^(.*)$ - # target_label: nodename - # replacement: $1 - # action: replace - - # Prometheus Operator ServiceMonitors. To be used as an alternative - # to podMonitor, supports secure metrics. - serviceMonitor: - # enable support for Prometheus Operator - enabled: false - - speaker: - # optional additional labels for the speaker serviceMonitor - additionalLabels: {} - # optional additional annotations for the speaker serviceMonitor - annotations: {} - # optional tls configuration for the speaker serviceMonitor, in case - # secure metrics are enabled. - tlsConfig: - insecureSkipVerify: true - - controller: - # optional additional labels for the controller serviceMonitor - additionalLabels: {} - # optional additional annotations for the controller serviceMonitor - annotations: {} - # optional tls configuration for the controller serviceMonitor, in case - # secure metrics are enabled. - tlsConfig: - insecureSkipVerify: true - - # Job label for scrape target - jobLabel: "app.kubernetes.io/name" - - # Scrape interval. If not set, the Prometheus default scrape interval is used. - interval: - - # metric relabel configs to apply to samples before ingestion. - metricRelabelings: [] - # - action: keep - # regex: 'kube_(daemonset|deployment|pod|namespace|node|statefulset).+' - # sourceLabels: [__name__] - - # relabel configs to apply to samples before ingestion. - relabelings: [] - # - sourceLabels: [__meta_kubernetes_pod_node_name] - # separator: ; - # regex: ^(.*)$ - # target_label: nodename - # replacement: $1 - # action: replace - - # Prometheus Operator alertmanager alerts - prometheusRule: - # enable alertmanager alerts - enabled: false - - # optional additional labels for prometheusRules - additionalLabels: {} - - # optional annotations for prometheusRules - annotations: {} - - # MetalLBStaleConfig - staleConfig: - enabled: true - labels: - severity: warning - - # MetalLBConfigNotLoaded - configNotLoaded: - enabled: true - labels: - severity: warning - - # MetalLBAddressPoolExhausted - addressPoolExhausted: - enabled: true - labels: - severity: critical - - addressPoolUsage: - enabled: true - thresholds: - - percent: 75 - labels: - severity: warning - - percent: 85 - labels: - severity: warning - - percent: 95 - labels: - severity: critical - - # MetalLBBGPSessionDown - bgpSessionDown: - enabled: true - labels: - severity: critical - - extraAlerts: [] - -# controller contains configuration specific to the MetalLB cluster -# controller. -controller: - enabled: true - # -- Controller log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none` - logLevel: info - # command: /controller - # webhookMode: enabled - image: - repository: quay.io/metallb/controller - tag: - pullPolicy: - ## @param controller.updateStrategy.type Metallb controller deployment strategy type. - ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy - ## e.g: - ## strategy: - ## type: RollingUpdate - ## rollingUpdate: - ## maxSurge: 25% - ## maxUnavailable: 25% - ## - strategy: - type: RollingUpdate - serviceAccount: - # Specifies whether a ServiceAccount should be created - create: true - # The name of the ServiceAccount to use. If not set and create is - # true, a name is generated using the fullname template - name: "" - annotations: {} - securityContext: - runAsNonRoot: true - # nobody - runAsUser: 65534 - fsGroup: 65534 - resources: {} - # limits: - # cpu: 100m - # memory: 100Mi - nodeSelector: {} - tolerations: [] - priorityClassName: "" - runtimeClassName: "" - affinity: {} - podAnnotations: {} - labels: {} - livenessProbe: - enabled: true - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - readinessProbe: - enabled: true - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - tlsMinVersion: "VersionTLS12" - tlsCipherSuites: "" - - extraContainers: [] - -# speaker contains configuration specific to the MetalLB speaker -# daemonset. -speaker: - enabled: true - # command: /speaker - # -- Speaker log level. Must be one of: `all`, `debug`, `info`, `warn`, `error` or `none` - logLevel: info - tolerateMaster: true - memberlist: - enabled: true - mlBindPort: 7946 - mlBindAddrOverride: "" - mlSecretKeyPath: "/etc/ml_secret_key" - excludeInterfaces: - enabled: true - # ignore the exclude-from-external-loadbalancer label - ignoreExcludeLB: false - - image: - repository: quay.io/metallb/speaker - tag: - pullPolicy: - ## @param speaker.updateStrategy.type Speaker daemonset strategy type - ## ref: https://kubernetes.io/docs/tasks/manage-daemon/update-daemon-set/ - ## - updateStrategy: - ## StrategyType - ## Can be set to RollingUpdate or OnDelete - ## - type: RollingUpdate - serviceAccount: - # Specifies whether a ServiceAccount should be created - create: true - # The name of the ServiceAccount to use. If not set and create is - # true, a name is generated using the fullname template - name: "" - annotations: {} - securityContext: {} - ## Defines a secret name for the controller to generate a memberlist encryption secret - ## By default secretName: {{ "metallb.fullname" }}-memberlist - ## - # secretName: - resources: {} - # limits: - # cpu: 100m - # memory: 100Mi - nodeSelector: {} - tolerations: [] - priorityClassName: "" - affinity: {} - ## Selects which runtime class will be used by the pod. - runtimeClassName: "" - podAnnotations: {} - labels: {} - livenessProbe: - enabled: true - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - readinessProbe: - enabled: true - failureThreshold: 3 - initialDelaySeconds: 10 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - startupProbe: - enabled: true - failureThreshold: 30 - periodSeconds: 5 - # frr contains configuration specific to the MetalLB FRR container, - # for speaker running alongside FRR. - frr: - enabled: true - image: - repository: quay.io/frrouting/frr - tag: 9.1.0 - pullPolicy: - metricsPort: 7473 - resources: {} - - # if set, enables a rbac proxy sidecar container on the speaker to - # expose the frr metrics via tls. - # secureMetricsPort: 9121 - - - reloader: - resources: {} - - frrMetrics: - resources: {} - - extraContainers: [] - -crds: - enabled: true - validationFailurePolicy: Fail - -# frrk8s contains the configuration related to using an frrk8s instance -# (github.com/metallb/frr-k8s) as the backend for the BGP implementation. -# This allows configuring additional frr parameters in combination to those -# applied by MetalLB. -frrk8s: - # if set, enables frrk8s as a backend. This is mutually exclusive to frr - # mode. - enabled: false - external: false - namespace: "" diff --git a/nfs-subdir-external-provisioner/values.yaml b/nfs-subdir-external-provisioner/values.yaml index 58c6d91..7801f87 100644 --- a/nfs-subdir-external-provisioner/values.yaml +++ b/nfs-subdir-external-provisioner/values.yaml @@ -8,43 +8,88 @@ image: imagePullSecrets: [] nfs: - server: 192.168.2.6 + server: 192.168.2.14 path: /nfs/kube mountOptions: volumeName: nfs-subdir-external-provisioner-root + # Reclaim policy for the main nfs volume reclaimPolicy: Retain +# For creating the StorageClass automatically: storageClass: create: true - defaultClass: true - name: nfs-client + + # Set a provisioner name. If unset, a name will be generated. + provisionerName: client2 + + # Set StorageClass as the default StorageClass + # Ignored if storageClass.create is false + defaultClass: false + + # Set a StorageClass name + # Ignored if storageClass.create is false + name: client2 + + # Allow volume to be expanded dynamically allowVolumeExpansion: true + + # Method used to reclaim an obsoleted volume reclaimPolicy: Delete + + # When set to false your PVs will not be archived by the provisioner upon deletion of the PVC. archiveOnDelete: true + + # If it exists and has 'delete' value, delete the directory. If it exists and has 'retain' value, save the directory. + # Overrides archiveOnDelete. + # Ignored if value not set. onDelete: + + # Specifies a template for creating a directory path via PVC metadata's such as labels, annotations, name or namespace. + # Ignored if value not set. pathPattern: - accessModes: ReadWriteMany + + # Set access mode - ReadWriteOnce, ReadOnlyMany or ReadWriteMany + accessModes: ReadWriteOnce + + # Set volume bindinng mode - Immediate or WaitForFirstConsumer volumeBindingMode: Immediate + + # Storage class annotations annotations: {} leaderElection: + # When set to false leader election will be disabled enabled: true +## For RBAC support: rbac: + # Specifies whether RBAC resources should be created create: true +# If true, create & use Pod Security Policy resources +# https://kubernetes.io/docs/concepts/policy/pod-security-policy/ podSecurityPolicy: enabled: false +# Deployment pod annotations podAnnotations: {} +## Set pod priorityClassName +# priorityClassName: "" + podSecurityContext: {} securityContext: {} serviceAccount: + # Specifies whether a ServiceAccount should be created create: true + + # Annotations to add to the service account annotations: {} + + # The name of the ServiceAccount to use. + # If not set and create is true, a name is generated using the fullname template name: resources: {} diff --git a/postgresql-ha/templates/vault-setup.yaml b/postgresql-ha/templates/vault-setup.yaml deleted file mode 100644 index a7c46f1..0000000 --- a/postgresql-ha/templates/vault-setup.yaml +++ /dev/null @@ -1,43 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - namespace: {{ .Release.Namespace }} - name: vault-secrets-operator-controller-manager ---- -apiVersion: secrets.hashicorp.com/v1beta1 -kind: VaultConnection -metadata: - name: vault-connection - namespace: {{ .Release.Namespace }} -spec: - address: http://vault.vault.svc.cluster.local:8200 - skipTLSVerify: true ---- -apiVersion: secrets.hashicorp.com/v1beta1 -kind: VaultAuth -metadata: - name: vault-auth - namespace: {{ .Release.Namespace }} -spec: - method: kubernetes - mount: kubernetes - kubernetes: - role: postgresql-ha-role - serviceAccount: vault-secrets-operator-controller-manager - audiences: - - vault ---- -apiVersion: secrets.hashicorp.com/v1beta1 -kind: VaultStaticSecret -metadata: - name: pg-ha-creds - namespace: {{ .Release.Namespace }} -spec: - mount: kvv2 - type: kv-v2 - path: postgresql-ha/config - refreshAfter: 1m - destination: - create: true - name: pg-ha-creds - vaultAuthRef: vault-auth diff --git a/postgresql-ha/values.yaml b/postgresql-ha/values.yaml index 10e1689..81cd48e 100644 --- a/postgresql-ha/values.yaml +++ b/postgresql-ha/values.yaml @@ -29,7 +29,7 @@ global: ## - myRegistryKeySecretName ## imagePullSecrets: [] - storageClass: "" + storageClass: "client1" postgresql: username: "" password: "" @@ -2062,7 +2062,7 @@ persistence: ## If undefined (the default) or set to null, no storageClassName spec is ## set, choosing the default provisioner. ## - storageClass: "" + storageClass: "client1" ## @param persistence.mountPath The path the volume will be mounted at, useful when using different PostgreSQL images. ## mountPath: /bitnami/postgresql @@ -2258,7 +2258,7 @@ backup: ## If undefined (the default) or set to null, no storageClassName spec is ## set, choosing the default provisioner. ## - storageClass: "" + storageClass: "client1" ## @param backup.cronjob.storage.accessModes PV Access Mode ## accessModes: diff --git a/redis/values.yaml b/redis/values.yaml index 1fc352a..70c5107 100644 --- a/redis/values.yaml +++ b/redis/values.yaml @@ -21,7 +21,7 @@ global: ## imagePullSecrets: [] defaultStorageClass: "" - storageClass: "" + storageClass: "client1" ## Security parameters ## security: @@ -528,7 +528,7 @@ master: ## If set to "-", storageClassName: "", which disables dynamic provisioning ## If undefined (the default) or set to null, no storageClassName spec is set, choosing the default provisioner ## - storageClass: "" + storageClass: "client1" ## @param master.persistence.accessModes Persistent Volume access modes ## accessModes: @@ -1013,7 +1013,7 @@ replica: ## If set to "-", storageClassName: "", which disables dynamic provisioning ## If undefined (the default) or set to null, no storageClassName spec is set, choosing the default provisioner ## - storageClass: "" + storageClass: "client1" ## @param replica.persistence.accessModes Persistent Volume access modes ## accessModes: @@ -1338,7 +1338,7 @@ sentinel: ## If set to "-", storageClassName: "", which disables dynamic provisioning ## If undefined (the default) or set to null, no storageClassName spec is set, choosing the default provisioner ## - storageClass: "" + storageClass: "client1" ## @param sentinel.persistence.accessModes Persistent Volume access modes ## accessModes: diff --git a/vault-secrets-operator/values.yaml b/vault-secrets-operator/values.yaml index f93590d..3cf9aef 100644 --- a/vault-secrets-operator/values.yaml +++ b/vault-secrets-operator/values.yaml @@ -323,7 +323,7 @@ controller: # This is a required field and must be setup in Vault prior to deploying the helm chart # if `defaultAuthMethod.enabled=true` # @type: string - role: auth-role-operator + role: auth-role-operator" # Kubernetes ServiceAccount associated with the Transit Vault Auth Role # Defaults to using the Operator's service-account. diff --git a/vault/templates/vault-setup.yml b/vault/templates/vault-setup.yml new file mode 100644 index 0000000..d7d32b2 --- /dev/null +++ b/vault/templates/vault-setup.yml @@ -0,0 +1,129 @@ +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultConnection +metadata: + name: vault-connection-infra + namespace: {{ .Release.Namespace }} +spec: + address: http://vault:8200 + skipTLSVerify: true +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultAuth +metadata: + name: vault-auth-infra + namespace: {{ .Release.Namespace }} +spec: + vaultConnectionRef: vault-connection-infra + method: kubernetes + mount: kubernetes + kubernetes: + role: shared-role + serviceAccount: vault-secrets-operator-controller-manager + audiences: + - vault +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: kafka-static-user-passwords + namespace: {{ .Release.Namespace }} +spec: + mount: kvv2 + type: kv-v2 + path: kafka/config + refreshAfter: 5m + destination: + create: true + name: kafka-static-user-passwords + vaultAuthRef: vault-auth-infra +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: cassandra-static-user-passwords + namespace: {{ .Release.Namespace }} +spec: + mount: kvv2 + type: kv-v2 + path: cassandra/config + refreshAfter: 5m + destination: + create: true + name: cassandra-static-user-passwords + vaultAuthRef: vault-auth-infra +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: pg-ha-creds + namespace: {{ .Release.Namespace }} +spec: + mount: kvv2 + type: kv-v2 + path: postgresql-ha/config + refreshAfter: 5m + destination: + create: true + name: pg-ha-creds + vaultAuthRef: vault-auth-infra +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: deeplink-secret + namespace: {{ .Release.Namespace }} +spec: + mount: kvv2 + type: kv-v2 + path: deeplink/config + refreshAfter: 5m + destination: + create: true + name: deeplink-secret + vaultAuthRef: vault-auth-infra +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: co-work-secret + namespace: {{ .Release.Namespace }} +spec: + mount: kvv2 + type: kv-v2 + path: tls-secret/config + refreshAfter: 5m + destination: + create: true + name: co-work-secret + type: kubernetes.io/tls + vaultAuthRef: vault-auth-infra +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: livekit-secret + namespace: {{ .Release.Namespace }} +spec: + mount: kvv2 + type: kv-v2 + path: livekit/config + refreshAfter: 5m + destination: + create: true + name: livekit-secret + vaultAuthRef: vault-auth-infra +--- +apiVersion: secrets.hashicorp.com/v1beta1 +kind: VaultStaticSecret +metadata: + name: s3-static-secret + namespace: {{ .Release.Namespace }} +spec: + mount: kvv2 + type: kv-v2 + path: s3/config + refreshAfter: 5m + destination: + create: true + name: s3-static-secret + vaultAuthRef: vault-auth-infra \ No newline at end of file diff --git a/vault/values.yaml b/vault/values.yaml index cc79a8d..fa399f1 100644 --- a/vault/values.yaml +++ b/vault/values.yaml @@ -9,7 +9,7 @@ global: enabled: true # The namespace to deploy to. Defaults to the `helm` installation namespace. - namespace: "vault" + namespace: "client1" # Image pull secret to use for registry authentication. # Alternatively, the value may be specified as an array of strings. @@ -770,7 +770,7 @@ server: mountPath: "/vault/data" # Name of the storage class to use. If null it will use the # configured default Storage Class. - storageClass: null + storageClass: client1 # Access Mode of the storage device being used for the PVC accessMode: ReadWriteOnce # Annotations to apply to the PVC @@ -799,7 +799,7 @@ server: mountPath: "/vault/audit" # Name of the storage class to use. If null it will use the # configured default Storage Class. - storageClass: null + storageClass: client1 # Access Mode of the storage device being used for the PVC accessMode: ReadWriteOnce # Annotations to apply to the PVC @@ -913,11 +913,18 @@ server: # unauthenticated_metrics_access = "true" #} } - storage "raft" { path = "/vault/data" + retry_join { + leader_api_addr = "http://vault-0.vault-internal:8200" + } + retry_join { + leader_api_addr = "http://vault-1.vault-internal:8200" + } + retry_join { + leader_api_addr = "http://vault-2.vault-internal:8200" + } } - service_registration "kubernetes" {} # config is a raw string of default configuration when using a Stateful @@ -928,20 +935,6 @@ server: # such as passwords should be either mounted through extraSecretEnvironmentVars # or through a Kube secret. For more information see: # https://developer.hashicorp.com/vault/docs/platform/k8s/helm/run#protecting-sensitive-vault-configurations - config: | - ui = true - - listener "tcp" { - tls_disable = 1 - address = "[::]:8200" - cluster_address = "[::]:8201" - } - storage "consul" { - path = "vault" - address = "HOST_IP:8500" - } - - service_registration "kubernetes" {} # Example configuration for using auto-unseal, using Google Cloud KMS. The # GKMS keys must already exist, and the cluster must have a service account diff --git a/velero/.helmignore b/velero/.helmignore new file mode 100644 index 0000000..f0c1319 --- /dev/null +++ b/velero/.helmignore @@ -0,0 +1,21 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj diff --git a/velero/Chart.yaml b/velero/Chart.yaml new file mode 100644 index 0000000..2ef7a3b --- /dev/null +++ b/velero/Chart.yaml @@ -0,0 +1,17 @@ +apiVersion: v2 +appVersion: 1.16.1 +kubeVersion: ">=1.16.0-0" +description: A Helm chart for velero +name: velero +version: 10.0.7 +home: https://github.com/vmware-tanzu/velero +icon: https://cdn-images-1.medium.com/max/1600/1*-9mb3AKnKdcL_QD3CMnthQ.png +sources: + - https://github.com/vmware-tanzu/velero +maintainers: + - name: jenting + email: hsiaoairplane@gmail.com + - name: reasonerjt + email: jiangd@vmware.com + - name: ywk253100 + email: yinw@vmware.com diff --git a/velero/OWNERS b/velero/OWNERS new file mode 100644 index 0000000..97bd924 --- /dev/null +++ b/velero/OWNERS @@ -0,0 +1,8 @@ +approvers: +- jenting +- reasonerjt +- ywk253100 +reviewers: +- jenting +- reasonerjt +- ywk253100 diff --git a/velero/README.md b/velero/README.md new file mode 100644 index 0000000..61d584a --- /dev/null +++ b/velero/README.md @@ -0,0 +1,181 @@ +# Velero + +Velero is an open source tool to safely backup and restore, perform disaster recovery, and migrate Kubernetes cluster resources and persistent volumes. + +Velero has two main components: a CLI, and a server-side Kubernetes deployment. + +## Installing the Velero CLI + +See the different options for installing the [Velero CLI](https://velero.io/docs/v1.13/basic-install/#install-the-cli). + +## Installing the Velero server + +### Installation Requirements + +Kubernetes v1.16+, because this helm chart uses CustomResourceDefinition `apiextensions.k8s.io/v1`. This API version was introduced in Kubernetes v1.16. + +### Velero version + +This helm chart installs Velero version v1.16 https://velero.io/docs/v1.16/. See the [#Upgrading](#upgrading) section for information on how to upgrade from other versions. + +### Provider credentials + +When installing using the Helm chart, the provider's credential information will need to be appended into your values. The easiest way to do this is with the `--set-file` argument, available in Helm 2.10 and higher. See your cloud provider's documentation for the contents and creation of the `credentials-velero` file. + +### Azure resources + +When using the Azure plug-in, requests and limits must be set. See https://github.com/vmware-tanzu/velero/issues/3234 and https://github.com/vmware-tanzu/helm-charts/issues/469 for details. + +### Installing + +The default configuration values for this chart are listed in values.yaml. + +See Velero's full [official documentation](https://velero.io/docs/v1.13/basic-install/). More specifically, find your provider in the Velero list of [supported providers](https://velero.io/docs/v1.13/supported-providers/) for specific configuration information and examples. + +#### Set up Helm + +See the main [README.md](https://github.com/vmware-tanzu/helm-charts#kubernetes-helm-charts-for-vmware-tanzu). + +#### Using Helm 3 + +##### Option 1) CLI commands + +Note: You may add the flag `--set cleanUpCRDs=true` if you want to delete the Velero CRDs after deleting a release. +Please note that cleaning up CRDs will also delete any CRD instance, such as BackupStorageLocation and VolumeSnapshotLocation, which would have to be reconfigured when reinstalling Velero. The backup data in object storage will not be deleted, even though the backup instances in the cluster will. + +Specify the necessary values using the --set key=value[,key=value] argument to helm install. For example, + +```bash +helm install velero vmware-tanzu/velero \ +--namespace \ +--create-namespace \ +--set-file credentials.secretContents.cloud= \ +--set configuration.backupStorageLocation[0].name= \ +--set configuration.backupStorageLocation[0].provider= \ +--set configuration.backupStorageLocation[0].bucket= \ +--set configuration.backupStorageLocation[0].config.region= \ +--set configuration.volumeSnapshotLocation[0].name= \ +--set configuration.volumeSnapshotLocation[0].provider= \ +--set configuration.volumeSnapshotLocation[0].config.region= \ +--set initContainers[0].name=velero-plugin-for- \ +--set initContainers[0].image=velero/velero-plugin-for-: \ +--set initContainers[0].volumeMounts[0].mountPath=/target \ +--set initContainers[0].volumeMounts[0].name=plugins +``` + +Users of zsh might need to put quotes around key/value pairs. + +##### Option 2) YAML file + +Add/update the necessary values by changing the values.yaml from this repository, then run: + +```bash +helm install vmware-tanzu/velero --namespace -f values.yaml --generate-name +``` +##### Upgrade the configuration + +If a value needs to be added or changed, you may do so with the `upgrade` command. An example: + +```bash +helm upgrade vmware-tanzu/velero --namespace --reuse-values --set configuration.backupStorageLocation[0].provider= +``` + +#### Using Helm 2 + +We're no longer supporting Helm v2 since it was deprecated in November 2020. + +##### Upgrade the configuration + +If a value needs to be added or changed, you may do so with the `upgrade` command. An example: + +```bash +helm upgrade vmware-tanzu/velero --reuse-values --set configuration.backupStorageLocation[0].provider= +``` +## Upgrading Chart + +### Upgrading to 7.0.0 + +Delete the CSI plugin. Because the Velero CSI plugin is already merged into the Velero, need to remove the existing CSI plugin InitContainer. Otherwise, the Velero server plugin would fail to start due to same plugin registered twice. +CSI plugin has been merged into velero repo in v1.14 release. It will be installed by default as an internal plugin. + +### Upgrading to 6.0.0 + +This version removes the `nodeAgent.privileged` field, you should use `nodeAgent.containerSecurityContext.privileged` instead + +## Upgrading Velero + +### Upgrading to v1.16 + +The [instructions found here](https://velero.io/docs/v1.16/upgrade-to-1.16/) will assist you in upgrading from version v1.15.x to v1.16. + +### Upgrading to v1.15 + +The [instructions found here](https://velero.io/docs/v1.15/upgrade-to-1.15/) will assist you in upgrading from version v1.14.x to v1.15. + +### Upgrading to v1.14 + +The [instructions found here](https://velero.io/docs/v1.14/upgrade-to-1.14/) will assist you in upgrading from version v1.13.x to v1.14. + +### Upgrading to v1.13 + +The [instructions found here](https://velero.io/docs/v1.13/upgrade-to-1.13/) will assist you in upgrading from version v1.12.x to v1.13. + +### Upgrading to v1.12 + +The [instructions found here](https://velero.io/docs/v1.12/upgrade-to-1.12/) will assist you in upgrading from version v1.11.x to v1.12. + +### Upgrading to v1.11 + +The [instructions found here](https://velero.io/docs/v1.11/upgrade-to-1.11/) will assist you in upgrading from version v1.10.x to v1.11. + +### Upgrading to v1.10 + +The [instructions found here](https://velero.io/docs/v1.10/upgrade-to-1.10/) will assist you in upgrading from version v1.9.x to v1.10. + +### Upgrading to v1.9 + +The [instructions found here](https://velero.io/docs/v1.9/upgrade-to-1.9/) will assist you in upgrading from version v1.8.x to v1.9. + +### Upgrading to v1.8 + +The [instructions found here](https://velero.io/docs/v1.8/upgrade-to-1.8/) will assist you in upgrading from version v1.7.x to v1.8. + +### Upgrading to v1.7 + +The [instructions found here](https://velero.io/docs/v1.7/upgrade-to-1.7/) will assist you in upgrading from version v1.6.x to v1.7. + +### Upgrading to v1.6 + +The [instructions found here](https://velero.io/docs/v1.6/upgrade-to-1.6/) will assist you in upgrading from version v1.5.x to v1.6. + +### Upgrading to v1.5 + +The [instructions found here](https://velero.io/docs/v1.5/upgrade-to-1.5/) will assist you in upgrading from version v1.4.x to v1.5. + +### Upgrading to v1.4 + +The [instructions found here](https://velero.io/docs/v1.4/upgrade-to-1.4/) will assist you in upgrading from version v1.3.x to v1.4. + +### Upgrading to v1.3.1 + +The [instructions found here](https://velero.io/docs/v1.3.1/upgrade-to-1.3/) will assist you in upgrading from version v1.2.0 or v1.3.0 to v1.3.1. + +### Upgrading to v1.2.0 + +The [instructions found here](https://velero.io/docs/v1.2.0/upgrade-to-1.2/) will assist you in upgrading from version v1.0.0 or v1.1.0 to v1.2.0. + +### Upgrading to v1.1.0 + +The [instructions found here](https://velero.io/docs/v1.1.0/upgrade-to-1.1/) will assist you in upgrading from version v1.0.0 to v1.1.0. + +## Uninstall Velero + +Note: when you uninstall the Velero server, all backups remain untouched. + +### Using Helm 3 + +```bash +helm uninstall -n +``` +### Note +Since from velero v1.10.0, it has supported both Restic and Kopia to do file-system level backup and restore, some configuration that contains the keyword Restic is not suitable anymore, which means from chart version 3.0.0 is not backward compatible, and we've done a configure filed name validation. diff --git a/velero/ci/test-values.yaml b/velero/ci/test-values.yaml new file mode 100644 index 0000000..80d1fbf --- /dev/null +++ b/velero/ci/test-values.yaml @@ -0,0 +1,119 @@ +# Set provider name and backup storage location bucket name +configuration: + backupStorageLocation: + - name: default + bucket: velero-backups + default: true + provider: aws + credential: + name: test-credential + key: test-key + config: + region: us-east-1 + profile: us-east-1-profile + - name: backups-secondary + bucket: velero-backups + provider: aws + config: + region: us-west-1 + profile: us-west-1-profile + volumeSnapshotLocation: + - name: ebs-us-east-1 + provider: aws + config: + region: us-east-1 + - name: portworx-cloud + provider: portworx + config: + type: cloud + +schedules: + mybackup: + labels: + myenv: foo + schedule: "0 0 * * *" + template: + ttl: "240h" + includedNamespaces: + - foo + +# Set a service account so that the CRD clean up job has proper permissions to delete CRDs +serviceAccount: + server: + name: velero + +# The Velero server +# Annotations to Velero deployment +annotations: + annotation: velero + foo: bar + +# Labels to Velero deployment +labels: + label: velero + foo: bar + +# Annotations to Velero deployment's template +podAnnotations: + pod-annotation: velero + foo: bar + +# Labels to Velero deployment's template +podLabels: + pod-label: velero + foo: bar + +# Resources to Velero deployment +resources: + requests: + cpu: 100m + memory: 128Mi + limits: + cpu: 100m + memory: 128Mi + +# The node-agent daemonset +deployNodeAgent: true + +nodeAgent: + # Annotations to node-agent daemonset + annotations: + annotation: node-agent + foo: bar + # Labels to node-agent daemonset + labels: + label: node-agent + foo: bar + # Resources to node-agent daemonset + resources: + requests: + cpu: 100m + memory: 128Mi + limits: + cpu: 100m + memory: 128Mi + +# The kubectl upgrade/cleanup job +kubectl: + # Annotations to kubectl job + annotations: + annotation: kubectl + foo: bar + # Labels to kubectl job + labels: + label: kubectl + foo: bar + # Resources to kubectl job + resources: + requests: + cpu: 100m + memory: 128Mi + limits: + cpu: 100m + memory: 128Mi + +# Whether or not to clean up CustomResourceDefintions when deleting a release. +# Cleaning up CRDs will delete the BackupStorageLocation and VolumeSnapshotLocation instances, which would have to be reconfigured. +# Backup data in object storage will _not_ be deleted, however Backup instances in the Kubernetes API will. +# Always clean up CRDs in CI. +cleanUpCRDs: true diff --git a/velero/crds/backuprepositories.yaml b/velero/crds/backuprepositories.yaml new file mode 100644 index 0000000..73da6ea --- /dev/null +++ b/velero/crds/backuprepositories.yaml @@ -0,0 +1,141 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: backuprepositories.velero.io +spec: + group: velero.io + names: + kind: BackupRepository + listKind: BackupRepositoryList + plural: backuprepositories + singular: backuprepository + scope: Namespaced + versions: + - additionalPrinterColumns: + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + - jsonPath: .spec.repositoryType + name: Repository Type + type: string + name: v1 + schema: + openAPIV3Schema: + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackupRepositorySpec is the specification for a BackupRepository. + properties: + backupStorageLocation: + description: |- + BackupStorageLocation is the name of the BackupStorageLocation + that should contain this repository. + type: string + maintenanceFrequency: + description: MaintenanceFrequency is how often maintenance should + be run. + type: string + repositoryConfig: + additionalProperties: + type: string + description: RepositoryConfig is for repository-specific configuration + fields. + nullable: true + type: object + repositoryType: + description: RepositoryType indicates the type of the backend repository + enum: + - kopia + - restic + - "" + type: string + resticIdentifier: + description: |- + ResticIdentifier is the full restic-compatible string for identifying + this repository. + type: string + volumeNamespace: + description: |- + VolumeNamespace is the namespace this backup repository contains + pod volume backups for. + type: string + required: + - backupStorageLocation + - maintenanceFrequency + - resticIdentifier + - volumeNamespace + type: object + status: + description: BackupRepositoryStatus is the current status of a BackupRepository. + properties: + lastMaintenanceTime: + description: LastMaintenanceTime is the last time repo maintenance + succeeded. + format: date-time + nullable: true + type: string + message: + description: Message is a message about the current status of the + BackupRepository. + type: string + phase: + description: Phase is the current state of the BackupRepository. + enum: + - New + - Ready + - NotReady + type: string + recentMaintenance: + description: RecentMaintenance is status of the recent repo maintenance. + items: + properties: + completeTimestamp: + description: CompleteTimestamp is the completion time of the + repo maintenance. + format: date-time + nullable: true + type: string + message: + description: Message is a message about the current status + of the repo maintenance. + type: string + result: + description: Result is the result of the repo maintenance. + enum: + - Succeeded + - Failed + type: string + startTimestamp: + description: StartTimestamp is the start time of the repo + maintenance. + format: date-time + nullable: true + type: string + type: object + type: array + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/backups.yaml b/velero/crds/backups.yaml new file mode 100644 index 0000000..f36d7b4 --- /dev/null +++ b/velero/crds/backups.yaml @@ -0,0 +1,670 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: backups.velero.io +spec: + group: velero.io + names: + kind: Backup + listKind: BackupList + plural: backups + singular: backup + scope: Namespaced + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Backup is a Velero resource that represents the capture of Kubernetes + cluster state at a point in time (API objects and associated volume state). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackupSpec defines the specification for a Velero backup. + properties: + csiSnapshotTimeout: + description: |- + CSISnapshotTimeout specifies the time used to wait for CSI VolumeSnapshot status turns to + ReadyToUse during creation, before returning error as timeout. + The default value is 10 minute. + type: string + datamover: + description: |- + DataMover specifies the data mover to be used by the backup. + If DataMover is "" or "velero", the built-in data mover will be used. + type: string + defaultVolumesToFsBackup: + description: |- + DefaultVolumesToFsBackup specifies whether pod volume file system backup should be used + for all volumes by default. + nullable: true + type: boolean + defaultVolumesToRestic: + description: |- + DefaultVolumesToRestic specifies whether restic should be used to take a + backup of all pod volumes by default. + + Deprecated: this field is no longer used and will be removed entirely in future. Use DefaultVolumesToFsBackup instead. + nullable: true + type: boolean + excludedClusterScopedResources: + description: |- + ExcludedClusterScopedResources is a slice of cluster-scoped + resource type names to exclude from the backup. + If set to "*", all cluster-scoped resource types are excluded. + The default value is empty. + items: + type: string + nullable: true + type: array + excludedNamespaceScopedResources: + description: |- + ExcludedNamespaceScopedResources is a slice of namespace-scoped + resource type names to exclude from the backup. + If set to "*", all namespace-scoped resource types are excluded. + The default value is empty. + items: + type: string + nullable: true + type: array + excludedNamespaces: + description: |- + ExcludedNamespaces contains a list of namespaces that are not + included in the backup. + items: + type: string + nullable: true + type: array + excludedResources: + description: |- + ExcludedResources is a slice of resource names that are not + included in the backup. + items: + type: string + nullable: true + type: array + hooks: + description: Hooks represent custom behaviors that should be executed + at different phases of the backup. + properties: + resources: + description: Resources are hooks that should be executed when + backing up individual instances of a resource. + items: + description: |- + BackupResourceHookSpec defines one or more BackupResourceHooks that should be executed based on + the rules defined for namespaces, resources, and label selector. + properties: + excludedNamespaces: + description: ExcludedNamespaces specifies the namespaces + to which this hook spec does not apply. + items: + type: string + nullable: true + type: array + excludedResources: + description: ExcludedResources specifies the resources + to which this hook spec does not apply. + items: + type: string + nullable: true + type: array + includedNamespaces: + description: |- + IncludedNamespaces specifies the namespaces to which this hook spec applies. If empty, it applies + to all namespaces. + items: + type: string + nullable: true + type: array + includedResources: + description: |- + IncludedResources specifies the resources to which this hook spec applies. If empty, it applies + to all resources. + items: + type: string + nullable: true + type: array + labelSelector: + description: LabelSelector, if specified, filters the + resources to which this hook spec applies. + nullable: true + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + name: + description: Name is the name of this hook. + type: string + post: + description: |- + PostHooks is a list of BackupResourceHooks to execute after storing the item in the backup. + These are executed after all "additional items" from item actions are processed. + items: + description: BackupResourceHook defines a hook for a + resource. + properties: + exec: + description: Exec defines an exec hook. + properties: + command: + description: Command is the command and arguments + to execute. + items: + type: string + minItems: 1 + type: array + container: + description: |- + Container is the container in the pod where the command should be executed. If not specified, + the pod's first container is used. + type: string + onError: + description: OnError specifies how Velero should + behave if it encounters an error executing + this hook. + enum: + - Continue + - Fail + type: string + timeout: + description: |- + Timeout defines the maximum amount of time Velero should wait for the hook to complete before + considering the execution a failure. + type: string + required: + - command + type: object + required: + - exec + type: object + type: array + pre: + description: |- + PreHooks is a list of BackupResourceHooks to execute prior to storing the item in the backup. + These are executed before any "additional items" from item actions are processed. + items: + description: BackupResourceHook defines a hook for a + resource. + properties: + exec: + description: Exec defines an exec hook. + properties: + command: + description: Command is the command and arguments + to execute. + items: + type: string + minItems: 1 + type: array + container: + description: |- + Container is the container in the pod where the command should be executed. If not specified, + the pod's first container is used. + type: string + onError: + description: OnError specifies how Velero should + behave if it encounters an error executing + this hook. + enum: + - Continue + - Fail + type: string + timeout: + description: |- + Timeout defines the maximum amount of time Velero should wait for the hook to complete before + considering the execution a failure. + type: string + required: + - command + type: object + required: + - exec + type: object + type: array + required: + - name + type: object + nullable: true + type: array + type: object + includeClusterResources: + description: |- + IncludeClusterResources specifies whether cluster-scoped resources + should be included for consideration in the backup. + nullable: true + type: boolean + includedClusterScopedResources: + description: |- + IncludedClusterScopedResources is a slice of cluster-scoped + resource type names to include in the backup. + If set to "*", all cluster-scoped resource types are included. + The default value is empty, which means only related + cluster-scoped resources are included. + items: + type: string + nullable: true + type: array + includedNamespaceScopedResources: + description: |- + IncludedNamespaceScopedResources is a slice of namespace-scoped + resource type names to include in the backup. + The default value is "*". + items: + type: string + nullable: true + type: array + includedNamespaces: + description: |- + IncludedNamespaces is a slice of namespace names to include objects + from. If empty, all namespaces are included. + items: + type: string + nullable: true + type: array + includedResources: + description: |- + IncludedResources is a slice of resource names to include + in the backup. If empty, all resources are included. + items: + type: string + nullable: true + type: array + itemOperationTimeout: + description: |- + ItemOperationTimeout specifies the time used to wait for asynchronous BackupItemAction operations + The default value is 4 hour. + type: string + labelSelector: + description: |- + LabelSelector is a metav1.LabelSelector to filter with + when adding individual objects to the backup. If empty + or nil, all objects are included. Optional. + nullable: true + properties: + matchExpressions: + description: matchExpressions is a list of label selector requirements. + The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + metadata: + properties: + labels: + additionalProperties: + type: string + type: object + type: object + orLabelSelectors: + description: |- + OrLabelSelectors is list of metav1.LabelSelector to filter with + when adding individual objects to the backup. If multiple provided + they will be joined by the OR operator. LabelSelector as well as + OrLabelSelectors cannot co-exist in backup request, only one of them + can be used. + items: + description: |- + A label selector is a label query over a set of resources. The result of matchLabels and + matchExpressions are ANDed. An empty label selector matches all objects. A null + label selector matches no objects. + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + nullable: true + type: array + orderedResources: + additionalProperties: + type: string + description: |- + OrderedResources specifies the backup order of resources of specific Kind. + The map key is the resource name and value is a list of object names separated by commas. + Each resource name has format "namespace/objectname". For cluster resources, simply use "objectname". + nullable: true + type: object + resourcePolicy: + description: ResourcePolicy specifies the referenced resource policies + that backup should follow + properties: + apiGroup: + description: |- + APIGroup is the group for the resource being referenced. + If APIGroup is not specified, the specified Kind must be in the core API group. + For any other third-party types, APIGroup is required. + type: string + kind: + description: Kind is the type of resource being referenced + type: string + name: + description: Name is the name of resource being referenced + type: string + required: + - kind + - name + type: object + x-kubernetes-map-type: atomic + snapshotMoveData: + description: SnapshotMoveData specifies whether snapshot data should + be moved + nullable: true + type: boolean + snapshotVolumes: + description: |- + SnapshotVolumes specifies whether to take snapshots + of any PV's referenced in the set of objects included + in the Backup. + nullable: true + type: boolean + storageLocation: + description: StorageLocation is a string containing the name of + a BackupStorageLocation where the backup should be stored. + type: string + ttl: + description: |- + TTL is a time.Duration-parseable string describing how long + the Backup should be retained for. + type: string + uploaderConfig: + description: UploaderConfig specifies the configuration for the + uploader. + nullable: true + properties: + parallelFilesUpload: + description: ParallelFilesUpload is the number of files parallel + uploads to perform when using the uploader. + type: integer + type: object + volumeSnapshotLocations: + description: VolumeSnapshotLocations is a list containing names + of VolumeSnapshotLocations associated with this backup. + items: + type: string + type: array + type: object + status: + description: BackupStatus captures the current status of a Velero backup. + properties: + backupItemOperationsAttempted: + description: |- + BackupItemOperationsAttempted is the total number of attempted + async BackupItemAction operations for this backup. + type: integer + backupItemOperationsCompleted: + description: |- + BackupItemOperationsCompleted is the total number of successfully completed + async BackupItemAction operations for this backup. + type: integer + backupItemOperationsFailed: + description: |- + BackupItemOperationsFailed is the total number of async + BackupItemAction operations for this backup which ended with an error. + type: integer + completionTimestamp: + description: |- + CompletionTimestamp records the time a backup was completed. + Completion time is recorded even on failed backups. + Completion time is recorded before uploading the backup object. + The server's time is used for CompletionTimestamps + format: date-time + nullable: true + type: string + csiVolumeSnapshotsAttempted: + description: |- + CSIVolumeSnapshotsAttempted is the total number of attempted + CSI VolumeSnapshots for this backup. + type: integer + csiVolumeSnapshotsCompleted: + description: |- + CSIVolumeSnapshotsCompleted is the total number of successfully + completed CSI VolumeSnapshots for this backup. + type: integer + errors: + description: |- + Errors is a count of all error messages that were generated during + execution of the backup. The actual errors are in the backup's log + file in object storage. + type: integer + expiration: + description: Expiration is when this Backup is eligible for garbage-collection. + format: date-time + nullable: true + type: string + failureReason: + description: FailureReason is an error that caused the entire backup + to fail. + type: string + formatVersion: + description: FormatVersion is the backup format version, including + major, minor, and patch version. + type: string + hookStatus: + description: HookStatus contains information about the status of + the hooks. + nullable: true + properties: + hooksAttempted: + description: |- + HooksAttempted is the total number of attempted hooks + Specifically, HooksAttempted represents the number of hooks that failed to execute + and the number of hooks that executed successfully. + type: integer + hooksFailed: + description: HooksFailed is the total number of hooks which + ended with an error + type: integer + type: object + phase: + description: Phase is the current state of the Backup. + enum: + - New + - FailedValidation + - InProgress + - WaitingForPluginOperations + - WaitingForPluginOperationsPartiallyFailed + - Finalizing + - FinalizingPartiallyFailed + - Completed + - PartiallyFailed + - Failed + - Deleting + type: string + progress: + description: |- + Progress contains information about the backup's execution progress. Note + that this information is best-effort only -- if Velero fails to update it + during a backup for any reason, it may be inaccurate/stale. + nullable: true + properties: + itemsBackedUp: + description: |- + ItemsBackedUp is the number of items that have actually been written to the + backup tarball so far. + type: integer + totalItems: + description: |- + TotalItems is the total number of items to be backed up. This number may change + throughout the execution of the backup due to plugins that return additional related + items to back up, the velero.io/exclude-from-backup label, and various other + filters that happen as items are processed. + type: integer + type: object + startTimestamp: + description: |- + StartTimestamp records the time a backup was started. + Separate from CreationTimestamp, since that value changes + on restores. + The server's time is used for StartTimestamps + format: date-time + nullable: true + type: string + validationErrors: + description: |- + ValidationErrors is a slice of all validation errors (if + applicable). + items: + type: string + nullable: true + type: array + version: + description: |- + Version is the backup format major version. + Deprecated: Please see FormatVersion + type: integer + volumeSnapshotsAttempted: + description: |- + VolumeSnapshotsAttempted is the total number of attempted + volume snapshots for this backup. + type: integer + volumeSnapshotsCompleted: + description: |- + VolumeSnapshotsCompleted is the total number of successfully + completed volume snapshots for this backup. + type: integer + warnings: + description: |- + Warnings is a count of all warning messages that were generated during + execution of the backup. The actual warnings are in the backup's log + file in object storage. + type: integer + type: object + type: object + served: true + storage: true diff --git a/velero/crds/backupstoragelocations.yaml b/velero/crds/backupstoragelocations.yaml new file mode 100644 index 0000000..5b59a07 --- /dev/null +++ b/velero/crds/backupstoragelocations.yaml @@ -0,0 +1,191 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: backupstoragelocations.velero.io +spec: + group: velero.io + names: + kind: BackupStorageLocation + listKind: BackupStorageLocationList + plural: backupstoragelocations + shortNames: + - bsl + singular: backupstoragelocation + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: Backup Storage Location status such as Available/Unavailable + jsonPath: .status.phase + name: Phase + type: string + - description: LastValidationTime is the last time the backup store location + was validated + jsonPath: .status.lastValidationTime + name: Last Validated + type: date + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + - description: Default backup storage location + jsonPath: .spec.default + name: Default + type: boolean + name: v1 + schema: + openAPIV3Schema: + description: BackupStorageLocation is a location where Velero stores backup + objects + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: BackupStorageLocationSpec defines the desired state of + a Velero BackupStorageLocation + properties: + accessMode: + description: AccessMode defines the permissions for the backup storage + location. + enum: + - ReadOnly + - ReadWrite + type: string + backupSyncPeriod: + description: BackupSyncPeriod defines how frequently to sync backup + API objects from object storage. A value of 0 disables sync. + nullable: true + type: string + config: + additionalProperties: + type: string + description: Config is for provider-specific configuration fields. + type: object + credential: + description: Credential contains the credential information intended + to be used with this location + properties: + key: + description: The key of the secret to select from. Must be + a valid secret key. + type: string + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + optional: + description: Specify whether the Secret or its key must be defined + type: boolean + required: + - key + type: object + x-kubernetes-map-type: atomic + default: + description: Default indicates this location is the default backup + storage location. + type: boolean + objectStorage: + description: ObjectStorageLocation specifies the settings necessary + to connect to a provider's object storage. + properties: + bucket: + description: Bucket is the bucket to use for object storage. + type: string + caCert: + description: CACert defines a CA bundle to use when verifying + TLS connections to the provider. + format: byte + type: string + prefix: + description: Prefix is the path inside a bucket to use for Velero + storage. Optional. + type: string + required: + - bucket + type: object + provider: + description: Provider is the provider of the backup storage. + type: string + validationFrequency: + description: ValidationFrequency defines how frequently to validate + the corresponding object storage. A value of 0 disables validation. + nullable: true + type: string + required: + - objectStorage + - provider + type: object + status: + description: BackupStorageLocationStatus defines the observed state + of BackupStorageLocation + properties: + accessMode: + description: |- + AccessMode is an unused field. + + Deprecated: there is now an AccessMode field on the Spec and this field + will be removed entirely as of v2.0. + enum: + - ReadOnly + - ReadWrite + type: string + lastSyncedRevision: + description: |- + LastSyncedRevision is the value of the `metadata/revision` file in the backup + storage location the last time the BSL's contents were synced into the cluster. + + Deprecated: this field is no longer updated or used for detecting changes to + the location's contents and will be removed entirely in v2.0. + type: string + lastSyncedTime: + description: |- + LastSyncedTime is the last time the contents of the location were synced into + the cluster. + format: date-time + nullable: true + type: string + lastValidationTime: + description: |- + LastValidationTime is the last time the backup store location was validated + the cluster. + format: date-time + nullable: true + type: string + message: + description: Message is a message about the backup storage location's + status. + type: string + phase: + description: Phase is the current state of the BackupStorageLocation. + enum: + - Available + - Unavailable + type: string + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/datadownloads.yaml b/velero/crds/datadownloads.yaml new file mode 100644 index 0000000..8000389 --- /dev/null +++ b/velero/crds/datadownloads.yaml @@ -0,0 +1,211 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: datadownloads.velero.io +spec: + group: velero.io + names: + kind: DataDownload + listKind: DataDownloadList + plural: datadownloads + singular: datadownload + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: DataDownload status such as New/InProgress + jsonPath: .status.phase + name: Status + type: string + - description: Time duration since this DataDownload was started + jsonPath: .status.startTimestamp + name: Started + type: date + - description: Completed bytes + format: int64 + jsonPath: .status.progress.bytesDone + name: Bytes Done + type: integer + - description: Total bytes + format: int64 + jsonPath: .status.progress.totalBytes + name: Total Bytes + type: integer + - description: Name of the Backup Storage Location where the backup data is + stored + jsonPath: .spec.backupStorageLocation + name: Storage Location + type: string + - description: Time duration since this DataDownload was created + jsonPath: .metadata.creationTimestamp + name: Age + type: date + - description: Name of the node where the DataDownload is processed + jsonPath: .status.node + name: Node + type: string + name: v2alpha1 + schema: + openAPIV3Schema: + description: DataDownload acts as the protocol between data mover plugins + and data mover controller for the datamover restore operation + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: DataDownloadSpec is the specification for a DataDownload. + properties: + backupStorageLocation: + description: |- + BackupStorageLocation is the name of the backup storage location + where the backup repository is stored. + type: string + cancel: + description: |- + Cancel indicates request to cancel the ongoing DataDownload. It can be set + when the DataDownload is in InProgress phase + type: boolean + dataMoverConfig: + additionalProperties: + type: string + description: DataMoverConfig is for data-mover-specific configuration + fields. + type: object + datamover: + description: |- + DataMover specifies the data mover to be used by the backup. + If DataMover is "" or "velero", the built-in data mover will be used. + type: string + nodeOS: + description: NodeOS is OS of the node where the DataDownload is + processed. + enum: + - auto + - linux + - windows + type: string + operationTimeout: + description: |- + OperationTimeout specifies the time used to wait internal operations, + before returning error as timeout. + type: string + snapshotID: + description: SnapshotID is the ID of the Velero backup snapshot + to be restored from. + type: string + sourceNamespace: + description: |- + SourceNamespace is the original namespace where the volume is backed up from. + It may be different from SourcePVC's namespace if namespace is remapped during restore. + type: string + targetVolume: + description: TargetVolume is the information of the target PVC and + PV. + properties: + namespace: + description: Namespace is the target namespace + type: string + pv: + description: PV is the name of the target PV that is created + by Velero restore + type: string + pvc: + description: PVC is the name of the target PVC that is created + by Velero restore + type: string + required: + - namespace + - pv + - pvc + type: object + required: + - backupStorageLocation + - operationTimeout + - snapshotID + - sourceNamespace + - targetVolume + type: object + status: + description: DataDownloadStatus is the current status of a DataDownload. + properties: + acceptedByNode: + description: Node is name of the node where the DataUpload is prepared. + type: string + acceptedTimestamp: + description: |- + AcceptedTimestamp records the time the DataUpload is to be prepared. + The server's time is used for AcceptedTimestamp + format: date-time + nullable: true + type: string + completionTimestamp: + description: |- + CompletionTimestamp records the time a restore was completed. + Completion time is recorded even on failed restores. + The server's time is used for CompletionTimestamps + format: date-time + nullable: true + type: string + message: + description: Message is a message about the DataDownload's status. + type: string + node: + description: Node is name of the node where the DataDownload is + processed. + type: string + phase: + description: Phase is the current state of the DataDownload. + enum: + - New + - Accepted + - Prepared + - InProgress + - Canceling + - Canceled + - Completed + - Failed + type: string + progress: + description: |- + Progress holds the total number of bytes of the snapshot and the current + number of restored bytes. This can be used to display progress information + about the restore operation. + properties: + bytesDone: + format: int64 + type: integer + totalBytes: + format: int64 + type: integer + type: object + startTimestamp: + description: |- + StartTimestamp records the time a restore was started. + The server's time is used for StartTimestamps + format: date-time + nullable: true + type: string + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/datauploads.yaml b/velero/crds/datauploads.yaml new file mode 100644 index 0000000..d17bd13 --- /dev/null +++ b/velero/crds/datauploads.yaml @@ -0,0 +1,234 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: datauploads.velero.io +spec: + group: velero.io + names: + kind: DataUpload + listKind: DataUploadList + plural: datauploads + singular: dataupload + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: DataUpload status such as New/InProgress + jsonPath: .status.phase + name: Status + type: string + - description: Time duration since this DataUpload was started + jsonPath: .status.startTimestamp + name: Started + type: date + - description: Completed bytes + format: int64 + jsonPath: .status.progress.bytesDone + name: Bytes Done + type: integer + - description: Total bytes + format: int64 + jsonPath: .status.progress.totalBytes + name: Total Bytes + type: integer + - description: Name of the Backup Storage Location where this backup should + be stored + jsonPath: .spec.backupStorageLocation + name: Storage Location + type: string + - description: Time duration since this DataUpload was created + jsonPath: .metadata.creationTimestamp + name: Age + type: date + - description: Name of the node where the DataUpload is processed + jsonPath: .status.node + name: Node + type: string + name: v2alpha1 + schema: + openAPIV3Schema: + description: DataUpload acts as the protocol between data mover plugins + and data mover controller for the datamover backup operation + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: DataUploadSpec is the specification for a DataUpload. + properties: + backupStorageLocation: + description: |- + BackupStorageLocation is the name of the backup storage location + where the backup repository is stored. + type: string + cancel: + description: |- + Cancel indicates request to cancel the ongoing DataUpload. It can be set + when the DataUpload is in InProgress phase + type: boolean + csiSnapshot: + description: If SnapshotType is CSI, CSISnapshot provides the information + of the CSI snapshot. + nullable: true + properties: + snapshotClass: + description: SnapshotClass is the name of the snapshot class + that the volume snapshot is created with + type: string + storageClass: + description: StorageClass is the name of the storage class of + the PVC that the volume snapshot is created from + type: string + volumeSnapshot: + description: VolumeSnapshot is the name of the volume snapshot + to be backed up + type: string + required: + - storageClass + - volumeSnapshot + type: object + dataMoverConfig: + additionalProperties: + type: string + description: DataMoverConfig is for data-mover-specific configuration + fields. + nullable: true + type: object + datamover: + description: |- + DataMover specifies the data mover to be used by the backup. + If DataMover is "" or "velero", the built-in data mover will be used. + type: string + operationTimeout: + description: |- + OperationTimeout specifies the time used to wait internal operations, + before returning error as timeout. + type: string + snapshotType: + description: SnapshotType is the type of the snapshot to be backed + up. + type: string + sourceNamespace: + description: |- + SourceNamespace is the original namespace where the volume is backed up from. + It is the same namespace for SourcePVC and CSI namespaced objects. + type: string + sourcePVC: + description: SourcePVC is the name of the PVC which the snapshot + is taken for. + type: string + required: + - backupStorageLocation + - operationTimeout + - snapshotType + - sourceNamespace + - sourcePVC + type: object + status: + description: DataUploadStatus is the current status of a DataUpload. + properties: + acceptedByNode: + description: AcceptedByNode is name of the node where the DataUpload + is prepared. + type: string + acceptedTimestamp: + description: |- + AcceptedTimestamp records the time the DataUpload is to be prepared. + The server's time is used for AcceptedTimestamp + format: date-time + nullable: true + type: string + completionTimestamp: + description: |- + CompletionTimestamp records the time a backup was completed. + Completion time is recorded even on failed backups. + Completion time is recorded before uploading the backup object. + The server's time is used for CompletionTimestamps + format: date-time + nullable: true + type: string + dataMoverResult: + additionalProperties: + type: string + description: DataMoverResult stores data-mover-specific information + as a result of the DataUpload. + nullable: true + type: object + message: + description: Message is a message about the DataUpload's status. + type: string + node: + description: Node is name of the node where the DataUpload is processed. + type: string + nodeOS: + description: NodeOS is OS of the node where the DataUpload is processed. + enum: + - auto + - linux + - windows + type: string + path: + description: Path is the full path of the snapshot volume being + backed up. + type: string + phase: + description: Phase is the current state of the DataUpload. + enum: + - New + - Accepted + - Prepared + - InProgress + - Canceling + - Canceled + - Completed + - Failed + type: string + progress: + description: |- + Progress holds the total number of bytes of the volume and the current + number of backed up bytes. This can be used to display progress information + about the backup operation. + properties: + bytesDone: + format: int64 + type: integer + totalBytes: + format: int64 + type: integer + type: object + snapshotID: + description: SnapshotID is the identifier for the snapshot in the + backup repository. + type: string + startTimestamp: + description: |- + StartTimestamp records the time a backup was started. + Separate from CreationTimestamp, since that value changes + on restores. + The server's time is used for StartTimestamps + format: date-time + nullable: true + type: string + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/deletebackuprequests.yaml b/velero/crds/deletebackuprequests.yaml new file mode 100644 index 0000000..11c6a9d --- /dev/null +++ b/velero/crds/deletebackuprequests.yaml @@ -0,0 +1,80 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: deletebackuprequests.velero.io +spec: + group: velero.io + names: + kind: DeleteBackupRequest + listKind: DeleteBackupRequestList + plural: deletebackuprequests + singular: deletebackuprequest + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: The name of the backup to be deleted + jsonPath: .spec.backupName + name: BackupName + type: string + - description: The status of the deletion request + jsonPath: .status.phase + name: Status + type: string + name: v1 + schema: + openAPIV3Schema: + description: DeleteBackupRequest is a request to delete one or more backups. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: DeleteBackupRequestSpec is the specification for which + backups to delete. + properties: + backupName: + type: string + required: + - backupName + type: object + status: + description: DeleteBackupRequestStatus is the current status of a DeleteBackupRequest. + properties: + errors: + description: Errors contains any errors that were encountered during + the deletion process. + items: + type: string + nullable: true + type: array + phase: + description: Phase is the current state of the DeleteBackupRequest. + enum: + - New + - InProgress + - Processed + type: string + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/downloadrequests.yaml b/velero/crds/downloadrequests.yaml new file mode 100644 index 0000000..37489af --- /dev/null +++ b/velero/crds/downloadrequests.yaml @@ -0,0 +1,101 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: downloadrequests.velero.io +spec: + group: velero.io + names: + kind: DownloadRequest + listKind: DownloadRequestList + plural: downloadrequests + singular: downloadrequest + scope: Namespaced + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + DownloadRequest is a request to download an artifact from backup object storage, such as a backup + log file. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: DownloadRequestSpec is the specification for a download + request. + properties: + target: + description: Target is what to download (e.g. logs for a backup). + properties: + kind: + description: Kind is the type of file to download. + enum: + - BackupLog + - BackupContents + - BackupVolumeSnapshots + - BackupItemOperations + - BackupResourceList + - BackupResults + - RestoreLog + - RestoreResults + - RestoreResourceList + - RestoreItemOperations + - CSIBackupVolumeSnapshots + - CSIBackupVolumeSnapshotContents + - BackupVolumeInfos + - RestoreVolumeInfo + type: string + name: + description: Name is the name of the Kubernetes resource with + which the file is associated. + type: string + required: + - kind + - name + type: object + required: + - target + type: object + status: + description: DownloadRequestStatus is the current status of a DownloadRequest. + properties: + downloadURL: + description: DownloadURL contains the pre-signed URL for the target + file. + type: string + expiration: + description: Expiration is when this DownloadRequest expires and + can be deleted by the system. + format: date-time + nullable: true + type: string + phase: + description: Phase is the current state of the DownloadRequest. + enum: + - New + - Processed + type: string + type: object + type: object + served: true + storage: true diff --git a/velero/crds/podvolumebackups.yaml b/velero/crds/podvolumebackups.yaml new file mode 100644 index 0000000..f83ff45 --- /dev/null +++ b/velero/crds/podvolumebackups.yaml @@ -0,0 +1,225 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: podvolumebackups.velero.io +spec: + group: velero.io + names: + kind: PodVolumeBackup + listKind: PodVolumeBackupList + plural: podvolumebackups + singular: podvolumebackup + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: Pod Volume Backup status such as New/InProgress + jsonPath: .status.phase + name: Status + type: string + - description: Time when this backup was started + jsonPath: .status.startTimestamp + name: Created + type: date + - description: Namespace of the pod containing the volume to be backed up + jsonPath: .spec.pod.namespace + name: Namespace + type: string + - description: Name of the pod containing the volume to be backed up + jsonPath: .spec.pod.name + name: Pod + type: string + - description: Name of the volume to be backed up + jsonPath: .spec.volume + name: Volume + type: string + - description: The type of the uploader to handle data transfer + jsonPath: .spec.uploaderType + name: Uploader Type + type: string + - description: Name of the Backup Storage Location where this backup should + be stored + jsonPath: .spec.backupStorageLocation + name: Storage Location + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: PodVolumeBackupSpec is the specification for a PodVolumeBackup. + properties: + backupStorageLocation: + description: |- + BackupStorageLocation is the name of the backup storage location + where the backup repository is stored. + type: string + node: + description: Node is the name of the node that the Pod is running + on. + type: string + pod: + description: Pod is a reference to the pod containing the volume + to be backed up. + properties: + apiVersion: + description: API version of the referent. + type: string + fieldPath: + description: |- + If referring to a piece of an object instead of an entire object, this string + should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2]. + For example, if the object reference is to a container within a pod, this would take on a value like: + "spec.containers{name}" (where "name" refers to the name of the container that triggered + the event) or if no container name is specified "spec.containers[2]" (container with + index 2 in this pod). This syntax is chosen only to have some well-defined way of + referencing a part of an object. + type: string + kind: + description: |- + Kind of the referent. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + name: + description: |- + Name of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + namespace: + description: |- + Namespace of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/ + type: string + resourceVersion: + description: |- + Specific resourceVersion to which this reference is made, if any. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency + type: string + uid: + description: |- + UID of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids + type: string + type: object + x-kubernetes-map-type: atomic + repoIdentifier: + description: RepoIdentifier is the backup repository identifier. + type: string + tags: + additionalProperties: + type: string + description: |- + Tags are a map of key-value pairs that should be applied to the + volume backup as tags. + type: object + uploaderSettings: + additionalProperties: + type: string + description: |- + UploaderSettings are a map of key-value pairs that should be applied to the + uploader configuration. + nullable: true + type: object + uploaderType: + description: UploaderType is the type of the uploader to handle + the data transfer. + enum: + - kopia + - restic + - "" + type: string + volume: + description: |- + Volume is the name of the volume within the Pod to be backed + up. + type: string + required: + - backupStorageLocation + - node + - pod + - repoIdentifier + - volume + type: object + status: + description: PodVolumeBackupStatus is the current status of a PodVolumeBackup. + properties: + completionTimestamp: + description: |- + CompletionTimestamp records the time a backup was completed. + Completion time is recorded even on failed backups. + Completion time is recorded before uploading the backup object. + The server's time is used for CompletionTimestamps + format: date-time + nullable: true + type: string + message: + description: Message is a message about the pod volume backup's + status. + type: string + path: + description: Path is the full path within the controller pod being + backed up. + type: string + phase: + description: Phase is the current state of the PodVolumeBackup. + enum: + - New + - InProgress + - Completed + - Failed + type: string + progress: + description: |- + Progress holds the total number of bytes of the volume and the current + number of backed up bytes. This can be used to display progress information + about the backup operation. + properties: + bytesDone: + format: int64 + type: integer + totalBytes: + format: int64 + type: integer + type: object + snapshotID: + description: SnapshotID is the identifier for the snapshot of the + pod volume. + type: string + startTimestamp: + description: |- + StartTimestamp records the time a backup was started. + Separate from CreationTimestamp, since that value changes + on restores. + The server's time is used for StartTimestamps + format: date-time + nullable: true + type: string + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/podvolumerestores.yaml b/velero/crds/podvolumerestores.yaml new file mode 100644 index 0000000..7bc5eda --- /dev/null +++ b/velero/crds/podvolumerestores.yaml @@ -0,0 +1,211 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: podvolumerestores.velero.io +spec: + group: velero.io + names: + kind: PodVolumeRestore + listKind: PodVolumeRestoreList + plural: podvolumerestores + singular: podvolumerestore + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: Namespace of the pod containing the volume to be restored + jsonPath: .spec.pod.namespace + name: Namespace + type: string + - description: Name of the pod containing the volume to be restored + jsonPath: .spec.pod.name + name: Pod + type: string + - description: The type of the uploader to handle data transfer + jsonPath: .spec.uploaderType + name: Uploader Type + type: string + - description: Name of the volume to be restored + jsonPath: .spec.volume + name: Volume + type: string + - description: Pod Volume Restore status such as New/InProgress + jsonPath: .status.phase + name: Status + type: string + - description: Pod Volume Restore status such as New/InProgress + format: int64 + jsonPath: .status.progress.totalBytes + name: TotalBytes + type: integer + - description: Pod Volume Restore status such as New/InProgress + format: int64 + jsonPath: .status.progress.bytesDone + name: BytesDone + type: integer + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1 + schema: + openAPIV3Schema: + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: PodVolumeRestoreSpec is the specification for a PodVolumeRestore. + properties: + backupStorageLocation: + description: |- + BackupStorageLocation is the name of the backup storage location + where the backup repository is stored. + type: string + pod: + description: Pod is a reference to the pod containing the volume + to be restored. + properties: + apiVersion: + description: API version of the referent. + type: string + fieldPath: + description: |- + If referring to a piece of an object instead of an entire object, this string + should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2]. + For example, if the object reference is to a container within a pod, this would take on a value like: + "spec.containers{name}" (where "name" refers to the name of the container that triggered + the event) or if no container name is specified "spec.containers[2]" (container with + index 2 in this pod). This syntax is chosen only to have some well-defined way of + referencing a part of an object. + type: string + kind: + description: |- + Kind of the referent. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + name: + description: |- + Name of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + namespace: + description: |- + Namespace of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/ + type: string + resourceVersion: + description: |- + Specific resourceVersion to which this reference is made, if any. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency + type: string + uid: + description: |- + UID of the referent. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids + type: string + type: object + x-kubernetes-map-type: atomic + repoIdentifier: + description: RepoIdentifier is the backup repository identifier. + type: string + snapshotID: + description: SnapshotID is the ID of the volume snapshot to be restored. + type: string + sourceNamespace: + description: SourceNamespace is the original namespace for namaspace + mapping. + type: string + uploaderSettings: + additionalProperties: + type: string + description: |- + UploaderSettings are a map of key-value pairs that should be applied to the + uploader configuration. + nullable: true + type: object + uploaderType: + description: UploaderType is the type of the uploader to handle + the data transfer. + enum: + - kopia + - restic + - "" + type: string + volume: + description: Volume is the name of the volume within the Pod to + be restored. + type: string + required: + - backupStorageLocation + - pod + - repoIdentifier + - snapshotID + - sourceNamespace + - volume + type: object + status: + description: PodVolumeRestoreStatus is the current status of a PodVolumeRestore. + properties: + completionTimestamp: + description: |- + CompletionTimestamp records the time a restore was completed. + Completion time is recorded even on failed restores. + The server's time is used for CompletionTimestamps + format: date-time + nullable: true + type: string + message: + description: Message is a message about the pod volume restore's + status. + type: string + phase: + description: Phase is the current state of the PodVolumeRestore. + enum: + - New + - InProgress + - Completed + - Failed + type: string + progress: + description: |- + Progress holds the total number of bytes of the snapshot and the current + number of restored bytes. This can be used to display progress information + about the restore operation. + properties: + bytesDone: + format: int64 + type: integer + totalBytes: + format: int64 + type: integer + type: object + startTimestamp: + description: |- + StartTimestamp records the time a restore was started. + The server's time is used for StartTimestamps + format: date-time + nullable: true + type: string + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/restores.yaml b/velero/crds/restores.yaml new file mode 100644 index 0000000..df1c161 --- /dev/null +++ b/velero/crds/restores.yaml @@ -0,0 +1,566 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: restores.velero.io +spec: + group: velero.io + names: + kind: Restore + listKind: RestoreList + plural: restores + singular: restore + scope: Namespaced + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Restore is a Velero resource that represents the application of + resources from a Velero backup to a target Kubernetes cluster. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: RestoreSpec defines the specification for a Velero restore. + properties: + backupName: + description: |- + BackupName is the unique name of the Velero backup to restore + from. + type: string + excludedNamespaces: + description: |- + ExcludedNamespaces contains a list of namespaces that are not + included in the restore. + items: + type: string + nullable: true + type: array + excludedResources: + description: |- + ExcludedResources is a slice of resource names that are not + included in the restore. + items: + type: string + nullable: true + type: array + existingResourcePolicy: + description: ExistingResourcePolicy specifies the restore behavior + for the Kubernetes resource to be restored + nullable: true + type: string + hooks: + description: Hooks represent custom behaviors that should be executed + during or post restore. + properties: + resources: + items: + description: |- + RestoreResourceHookSpec defines one or more RestoreResrouceHooks that should be executed based on + the rules defined for namespaces, resources, and label selector. + properties: + excludedNamespaces: + description: ExcludedNamespaces specifies the namespaces + to which this hook spec does not apply. + items: + type: string + nullable: true + type: array + excludedResources: + description: ExcludedResources specifies the resources + to which this hook spec does not apply. + items: + type: string + nullable: true + type: array + includedNamespaces: + description: |- + IncludedNamespaces specifies the namespaces to which this hook spec applies. If empty, it applies + to all namespaces. + items: + type: string + nullable: true + type: array + includedResources: + description: |- + IncludedResources specifies the resources to which this hook spec applies. If empty, it applies + to all resources. + items: + type: string + nullable: true + type: array + labelSelector: + description: LabelSelector, if specified, filters the + resources to which this hook spec applies. + nullable: true + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + name: + description: Name is the name of this hook. + type: string + postHooks: + description: PostHooks is a list of RestoreResourceHooks + to execute during and after restoring a resource. + items: + description: RestoreResourceHook defines a restore hook + for a resource. + properties: + exec: + description: Exec defines an exec restore hook. + properties: + command: + description: Command is the command and arguments + to execute from within a container after a + pod has been restored. + items: + type: string + minItems: 1 + type: array + container: + description: |- + Container is the container in the pod where the command should be executed. If not specified, + the pod's first container is used. + type: string + execTimeout: + description: |- + ExecTimeout defines the maximum amount of time Velero should wait for the hook to complete before + considering the execution a failure. + type: string + onError: + description: OnError specifies how Velero should + behave if it encounters an error executing + this hook. + enum: + - Continue + - Fail + type: string + waitForReady: + description: WaitForReady ensures command will + be launched when container is Ready instead + of Running. + nullable: true + type: boolean + waitTimeout: + description: |- + WaitTimeout defines the maximum amount of time Velero should wait for the container to be Ready + before attempting to run the command. + type: string + required: + - command + type: object + init: + description: Init defines an init restore hook. + properties: + initContainers: + description: InitContainers is list of init + containers to be added to a pod during its + restore. + items: + type: object + x-kubernetes-preserve-unknown-fields: true + type: array + x-kubernetes-preserve-unknown-fields: true + timeout: + description: Timeout defines the maximum amount + of time Velero should wait for the initContainers + to complete. + type: string + type: object + type: object + type: array + required: + - name + type: object + type: array + type: object + includeClusterResources: + description: |- + IncludeClusterResources specifies whether cluster-scoped resources + should be included for consideration in the restore. If null, defaults + to true. + nullable: true + type: boolean + includedNamespaces: + description: |- + IncludedNamespaces is a slice of namespace names to include objects + from. If empty, all namespaces are included. + items: + type: string + nullable: true + type: array + includedResources: + description: |- + IncludedResources is a slice of resource names to include + in the restore. If empty, all resources in the backup are included. + items: + type: string + nullable: true + type: array + itemOperationTimeout: + description: |- + ItemOperationTimeout specifies the time used to wait for RestoreItemAction operations + The default value is 4 hour. + type: string + labelSelector: + description: |- + LabelSelector is a metav1.LabelSelector to filter with + when restoring individual objects from the backup. If empty + or nil, all objects are included. Optional. + nullable: true + properties: + matchExpressions: + description: matchExpressions is a list of label selector requirements. + The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + namespaceMapping: + additionalProperties: + type: string + description: |- + NamespaceMapping is a map of source namespace names + to target namespace names to restore into. Any source + namespaces not included in the map will be restored into + namespaces of the same name. + type: object + orLabelSelectors: + description: |- + OrLabelSelectors is list of metav1.LabelSelector to filter with + when restoring individual objects from the backup. If multiple provided + they will be joined by the OR operator. LabelSelector as well as + OrLabelSelectors cannot co-exist in restore request, only one of them + can be used + items: + description: |- + A label selector is a label query over a set of resources. The result of matchLabels and + matchExpressions are ANDed. An empty label selector matches all objects. A null + label selector matches no objects. + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + nullable: true + type: array + preserveNodePorts: + description: PreserveNodePorts specifies whether to restore old + nodePorts from backup. + nullable: true + type: boolean + resourceModifier: + description: ResourceModifier specifies the reference to JSON resource + patches that should be applied to resources before restoration. + nullable: true + properties: + apiGroup: + description: |- + APIGroup is the group for the resource being referenced. + If APIGroup is not specified, the specified Kind must be in the core API group. + For any other third-party types, APIGroup is required. + type: string + kind: + description: Kind is the type of resource being referenced + type: string + name: + description: Name is the name of resource being referenced + type: string + required: + - kind + - name + type: object + x-kubernetes-map-type: atomic + restorePVs: + description: |- + RestorePVs specifies whether to restore all included + PVs from snapshot + nullable: true + type: boolean + restoreStatus: + description: |- + RestoreStatus specifies which resources we should restore the status + field. If nil, no objects are included. Optional. + nullable: true + properties: + excludedResources: + description: ExcludedResources specifies the resources to which + will not restore the status. + items: + type: string + nullable: true + type: array + includedResources: + description: |- + IncludedResources specifies the resources to which will restore the status. + If empty, it applies to all resources. + items: + type: string + nullable: true + type: array + type: object + scheduleName: + description: |- + ScheduleName is the unique name of the Velero schedule to restore + from. If specified, and BackupName is empty, Velero will restore + from the most recent successful backup created from this schedule. + type: string + uploaderConfig: + description: UploaderConfig specifies the configuration for the + restore. + nullable: true + properties: + parallelFilesDownload: + description: ParallelFilesDownload is the concurrency number + setting for restore. + type: integer + writeSparseFiles: + description: WriteSparseFiles is a flag to indicate whether + write files sparsely or not. + nullable: true + type: boolean + type: object + type: object + status: + description: RestoreStatus captures the current status of a Velero restore + properties: + completionTimestamp: + description: |- + CompletionTimestamp records the time the restore operation was completed. + Completion time is recorded even on failed restore. + The server's time is used for StartTimestamps + format: date-time + nullable: true + type: string + errors: + description: |- + Errors is a count of all error messages that were generated during + execution of the restore. The actual errors are stored in object storage. + type: integer + failureReason: + description: FailureReason is an error that caused the entire restore + to fail. + type: string + hookStatus: + description: HookStatus contains information about the status of + the hooks. + nullable: true + properties: + hooksAttempted: + description: |- + HooksAttempted is the total number of attempted hooks + Specifically, HooksAttempted represents the number of hooks that failed to execute + and the number of hooks that executed successfully. + type: integer + hooksFailed: + description: HooksFailed is the total number of hooks which + ended with an error + type: integer + type: object + phase: + description: Phase is the current state of the Restore + enum: + - New + - FailedValidation + - InProgress + - WaitingForPluginOperations + - WaitingForPluginOperationsPartiallyFailed + - Completed + - PartiallyFailed + - Failed + - Finalizing + - FinalizingPartiallyFailed + type: string + progress: + description: |- + Progress contains information about the restore's execution progress. Note + that this information is best-effort only -- if Velero fails to update it + during a restore for any reason, it may be inaccurate/stale. + nullable: true + properties: + itemsRestored: + description: ItemsRestored is the number of items that have + actually been restored so far + type: integer + totalItems: + description: |- + TotalItems is the total number of items to be restored. This number may change + throughout the execution of the restore due to plugins that return additional related + items to restore + type: integer + type: object + restoreItemOperationsAttempted: + description: |- + RestoreItemOperationsAttempted is the total number of attempted + async RestoreItemAction operations for this restore. + type: integer + restoreItemOperationsCompleted: + description: |- + RestoreItemOperationsCompleted is the total number of successfully completed + async RestoreItemAction operations for this restore. + type: integer + restoreItemOperationsFailed: + description: |- + RestoreItemOperationsFailed is the total number of async + RestoreItemAction operations for this restore which ended with an error. + type: integer + startTimestamp: + description: |- + StartTimestamp records the time the restore operation was started. + The server's time is used for StartTimestamps + format: date-time + nullable: true + type: string + validationErrors: + description: |- + ValidationErrors is a slice of all validation errors (if + applicable) + items: + type: string + nullable: true + type: array + warnings: + description: |- + Warnings is a count of all warning messages that were generated during + execution of the restore. The actual warnings are stored in object storage. + type: integer + type: object + type: object + served: true + storage: true diff --git a/velero/crds/schedules.yaml b/velero/crds/schedules.yaml new file mode 100644 index 0000000..f09bdb1 --- /dev/null +++ b/velero/crds/schedules.yaml @@ -0,0 +1,606 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: schedules.velero.io +spec: + group: velero.io + names: + kind: Schedule + listKind: ScheduleList + plural: schedules + singular: schedule + scope: Namespaced + versions: + - additionalPrinterColumns: + - description: Status of the schedule + jsonPath: .status.phase + name: Status + type: string + - description: A Cron expression defining when to run the Backup + jsonPath: .spec.schedule + name: Schedule + type: string + - description: The last time a Backup was run for this schedule + jsonPath: .status.lastBackup + name: LastBackup + type: date + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + - jsonPath: .spec.paused + name: Paused + type: boolean + name: v1 + schema: + openAPIV3Schema: + description: |- + Schedule is a Velero resource that represents a pre-scheduled or + periodic Backup that should be run. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ScheduleSpec defines the specification for a Velero schedule + properties: + paused: + description: Paused specifies whether the schedule is paused or + not + type: boolean + schedule: + description: |- + Schedule is a Cron expression defining when to run + the Backup. + type: string + skipImmediately: + description: |- + SkipImmediately specifies whether to skip backup if schedule is due immediately from `schedule.status.lastBackup` timestamp when schedule is unpaused or if schedule is new. + If true, backup will be skipped immediately when schedule is unpaused if it is due based on .Status.LastBackupTimestamp or schedule is new, and will run at next schedule time. + If false, backup will not be skipped immediately when schedule is unpaused, but will run at next schedule time. + If empty, will follow server configuration (default: false). + type: boolean + template: + description: |- + Template is the definition of the Backup to be run + on the provided schedule + properties: + csiSnapshotTimeout: + description: |- + CSISnapshotTimeout specifies the time used to wait for CSI VolumeSnapshot status turns to + ReadyToUse during creation, before returning error as timeout. + The default value is 10 minute. + type: string + datamover: + description: |- + DataMover specifies the data mover to be used by the backup. + If DataMover is "" or "velero", the built-in data mover will be used. + type: string + defaultVolumesToFsBackup: + description: |- + DefaultVolumesToFsBackup specifies whether pod volume file system backup should be used + for all volumes by default. + nullable: true + type: boolean + defaultVolumesToRestic: + description: |- + DefaultVolumesToRestic specifies whether restic should be used to take a + backup of all pod volumes by default. + + Deprecated: this field is no longer used and will be removed entirely in future. Use DefaultVolumesToFsBackup instead. + nullable: true + type: boolean + excludedClusterScopedResources: + description: |- + ExcludedClusterScopedResources is a slice of cluster-scoped + resource type names to exclude from the backup. + If set to "*", all cluster-scoped resource types are excluded. + The default value is empty. + items: + type: string + nullable: true + type: array + excludedNamespaceScopedResources: + description: |- + ExcludedNamespaceScopedResources is a slice of namespace-scoped + resource type names to exclude from the backup. + If set to "*", all namespace-scoped resource types are excluded. + The default value is empty. + items: + type: string + nullable: true + type: array + excludedNamespaces: + description: |- + ExcludedNamespaces contains a list of namespaces that are not + included in the backup. + items: + type: string + nullable: true + type: array + excludedResources: + description: |- + ExcludedResources is a slice of resource names that are not + included in the backup. + items: + type: string + nullable: true + type: array + hooks: + description: Hooks represent custom behaviors that should be + executed at different phases of the backup. + properties: + resources: + description: Resources are hooks that should be executed + when backing up individual instances of a resource. + items: + description: |- + BackupResourceHookSpec defines one or more BackupResourceHooks that should be executed based on + the rules defined for namespaces, resources, and label selector. + properties: + excludedNamespaces: + description: ExcludedNamespaces specifies the namespaces + to which this hook spec does not apply. + items: + type: string + nullable: true + type: array + excludedResources: + description: ExcludedResources specifies the resources + to which this hook spec does not apply. + items: + type: string + nullable: true + type: array + includedNamespaces: + description: |- + IncludedNamespaces specifies the namespaces to which this hook spec applies. If empty, it applies + to all namespaces. + items: + type: string + nullable: true + type: array + includedResources: + description: |- + IncludedResources specifies the resources to which this hook spec applies. If empty, it applies + to all resources. + items: + type: string + nullable: true + type: array + labelSelector: + description: LabelSelector, if specified, filters + the resources to which this hook spec applies. + nullable: true + properties: + matchExpressions: + description: matchExpressions is a list of label + selector requirements. The requirements are + ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the + selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + name: + description: Name is the name of this hook. + type: string + post: + description: |- + PostHooks is a list of BackupResourceHooks to execute after storing the item in the backup. + These are executed after all "additional items" from item actions are processed. + items: + description: BackupResourceHook defines a hook for + a resource. + properties: + exec: + description: Exec defines an exec hook. + properties: + command: + description: Command is the command and + arguments to execute. + items: + type: string + minItems: 1 + type: array + container: + description: |- + Container is the container in the pod where the command should be executed. If not specified, + the pod's first container is used. + type: string + onError: + description: OnError specifies how Velero + should behave if it encounters an error + executing this hook. + enum: + - Continue + - Fail + type: string + timeout: + description: |- + Timeout defines the maximum amount of time Velero should wait for the hook to complete before + considering the execution a failure. + type: string + required: + - command + type: object + required: + - exec + type: object + type: array + pre: + description: |- + PreHooks is a list of BackupResourceHooks to execute prior to storing the item in the backup. + These are executed before any "additional items" from item actions are processed. + items: + description: BackupResourceHook defines a hook for + a resource. + properties: + exec: + description: Exec defines an exec hook. + properties: + command: + description: Command is the command and + arguments to execute. + items: + type: string + minItems: 1 + type: array + container: + description: |- + Container is the container in the pod where the command should be executed. If not specified, + the pod's first container is used. + type: string + onError: + description: OnError specifies how Velero + should behave if it encounters an error + executing this hook. + enum: + - Continue + - Fail + type: string + timeout: + description: |- + Timeout defines the maximum amount of time Velero should wait for the hook to complete before + considering the execution a failure. + type: string + required: + - command + type: object + required: + - exec + type: object + type: array + required: + - name + type: object + nullable: true + type: array + type: object + includeClusterResources: + description: |- + IncludeClusterResources specifies whether cluster-scoped resources + should be included for consideration in the backup. + nullable: true + type: boolean + includedClusterScopedResources: + description: |- + IncludedClusterScopedResources is a slice of cluster-scoped + resource type names to include in the backup. + If set to "*", all cluster-scoped resource types are included. + The default value is empty, which means only related + cluster-scoped resources are included. + items: + type: string + nullable: true + type: array + includedNamespaceScopedResources: + description: |- + IncludedNamespaceScopedResources is a slice of namespace-scoped + resource type names to include in the backup. + The default value is "*". + items: + type: string + nullable: true + type: array + includedNamespaces: + description: |- + IncludedNamespaces is a slice of namespace names to include objects + from. If empty, all namespaces are included. + items: + type: string + nullable: true + type: array + includedResources: + description: |- + IncludedResources is a slice of resource names to include + in the backup. If empty, all resources are included. + items: + type: string + nullable: true + type: array + itemOperationTimeout: + description: |- + ItemOperationTimeout specifies the time used to wait for asynchronous BackupItemAction operations + The default value is 4 hour. + type: string + labelSelector: + description: |- + LabelSelector is a metav1.LabelSelector to filter with + when adding individual objects to the backup. If empty + or nil, all objects are included. Optional. + nullable: true + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + metadata: + properties: + labels: + additionalProperties: + type: string + type: object + type: object + orLabelSelectors: + description: |- + OrLabelSelectors is list of metav1.LabelSelector to filter with + when adding individual objects to the backup. If multiple provided + they will be joined by the OR operator. LabelSelector as well as + OrLabelSelectors cannot co-exist in backup request, only one of them + can be used. + items: + description: |- + A label selector is a label query over a set of resources. The result of matchLabels and + matchExpressions are ANDed. An empty label selector matches all objects. A null + label selector matches no objects. + properties: + matchExpressions: + description: matchExpressions is a list of label selector + requirements. The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector + applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + nullable: true + type: array + orderedResources: + additionalProperties: + type: string + description: |- + OrderedResources specifies the backup order of resources of specific Kind. + The map key is the resource name and value is a list of object names separated by commas. + Each resource name has format "namespace/objectname". For cluster resources, simply use "objectname". + nullable: true + type: object + resourcePolicy: + description: ResourcePolicy specifies the referenced resource + policies that backup should follow + properties: + apiGroup: + description: |- + APIGroup is the group for the resource being referenced. + If APIGroup is not specified, the specified Kind must be in the core API group. + For any other third-party types, APIGroup is required. + type: string + kind: + description: Kind is the type of resource being referenced + type: string + name: + description: Name is the name of resource being referenced + type: string + required: + - kind + - name + type: object + x-kubernetes-map-type: atomic + snapshotMoveData: + description: SnapshotMoveData specifies whether snapshot data + should be moved + nullable: true + type: boolean + snapshotVolumes: + description: |- + SnapshotVolumes specifies whether to take snapshots + of any PV's referenced in the set of objects included + in the Backup. + nullable: true + type: boolean + storageLocation: + description: StorageLocation is a string containing the name + of a BackupStorageLocation where the backup should be stored. + type: string + ttl: + description: |- + TTL is a time.Duration-parseable string describing how long + the Backup should be retained for. + type: string + uploaderConfig: + description: UploaderConfig specifies the configuration for + the uploader. + nullable: true + properties: + parallelFilesUpload: + description: ParallelFilesUpload is the number of files + parallel uploads to perform when using the uploader. + type: integer + type: object + volumeSnapshotLocations: + description: VolumeSnapshotLocations is a list containing names + of VolumeSnapshotLocations associated with this backup. + items: + type: string + type: array + type: object + useOwnerReferencesInBackup: + description: |- + UseOwnerReferencesBackup specifies whether to use + OwnerReferences on backups created by this Schedule. + nullable: true + type: boolean + required: + - schedule + - template + type: object + status: + description: ScheduleStatus captures the current state of a Velero schedule + properties: + lastBackup: + description: |- + LastBackup is the last time a Backup was run for this + Schedule schedule + format: date-time + nullable: true + type: string + lastSkipped: + description: LastSkipped is the last time a Schedule was skipped + format: date-time + nullable: true + type: string + phase: + description: Phase is the current phase of the Schedule + enum: + - New + - Enabled + - FailedValidation + type: string + validationErrors: + description: |- + ValidationErrors is a slice of all validation errors (if + applicable) + items: + type: string + type: array + type: object + type: object + served: true + storage: true + subresources: {} diff --git a/velero/crds/serverstatusrequests.yaml b/velero/crds/serverstatusrequests.yaml new file mode 100644 index 0000000..979d5b9 --- /dev/null +++ b/velero/crds/serverstatusrequests.yaml @@ -0,0 +1,86 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: serverstatusrequests.velero.io +spec: + group: velero.io + names: + kind: ServerStatusRequest + listKind: ServerStatusRequestList + plural: serverstatusrequests + shortNames: + - ssr + singular: serverstatusrequest + scope: Namespaced + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + ServerStatusRequest is a request to access current status information about + the Velero server. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ServerStatusRequestSpec is the specification for a ServerStatusRequest. + type: object + status: + description: ServerStatusRequestStatus is the current status of a ServerStatusRequest. + properties: + phase: + description: Phase is the current lifecycle phase of the ServerStatusRequest. + enum: + - New + - Processed + type: string + plugins: + description: Plugins list information about the plugins running + on the Velero server + items: + description: PluginInfo contains attributes of a Velero plugin + properties: + kind: + type: string + name: + type: string + required: + - kind + - name + type: object + nullable: true + type: array + processedTimestamp: + description: |- + ProcessedTimestamp is when the ServerStatusRequest was processed + by the ServerStatusRequestController. + format: date-time + nullable: true + type: string + serverVersion: + description: ServerVersion is the Velero server version. + type: string + type: object + type: object + served: true + storage: true diff --git a/velero/crds/volumesnapshotlocations.yaml b/velero/crds/volumesnapshotlocations.yaml new file mode 100644 index 0000000..2735e3d --- /dev/null +++ b/velero/crds/volumesnapshotlocations.yaml @@ -0,0 +1,97 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.16.5 + labels: + component: velero + name: volumesnapshotlocations.velero.io +spec: + group: velero.io + names: + kind: VolumeSnapshotLocation + listKind: VolumeSnapshotLocationList + plural: volumesnapshotlocations + shortNames: + - vsl + singular: volumesnapshotlocation + scope: Namespaced + versions: + - name: v1 + schema: + openAPIV3Schema: + description: VolumeSnapshotLocation is a location where Velero stores volume + snapshots. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: VolumeSnapshotLocationSpec defines the specification for + a Velero VolumeSnapshotLocation. + properties: + config: + additionalProperties: + type: string + description: Config is for provider-specific configuration fields. + type: object + credential: + description: Credential contains the credential information intended + to be used with this location + properties: + key: + description: The key of the secret to select from. Must be + a valid secret key. + type: string + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + optional: + description: Specify whether the Secret or its key must be defined + type: boolean + required: + - key + type: object + x-kubernetes-map-type: atomic + provider: + description: Provider is the provider of the volume storage. + type: string + required: + - provider + type: object + status: + description: VolumeSnapshotLocationStatus describes the current status + of a Velero VolumeSnapshotLocation. + properties: + phase: + description: VolumeSnapshotLocationPhase is the lifecycle phase + of a Velero VolumeSnapshotLocation. + enum: + - Available + - Unavailable + type: string + type: object + type: object + served: true + storage: true diff --git a/velero/templates/NOTES.txt b/velero/templates/NOTES.txt new file mode 100644 index 0000000..d2f0fb7 --- /dev/null +++ b/velero/templates/NOTES.txt @@ -0,0 +1,80 @@ +Check that the velero is up and running: + + kubectl get deployment/{{ include "velero.fullname" . }} -n {{ .Release.Namespace }} + +Check that the secret has been created: + + kubectl get secret/{{ include "velero.fullname" . }} -n {{ .Release.Namespace }} + +Once velero server is up and running you need the client before you can use it +1. wget https://github.com/vmware-tanzu/velero/releases/download/{{ .Values.image.tag }}/velero-{{ .Values.image.tag }}-darwin-amd64.tar.gz +2. tar -xvf velero-{{ .Values.image.tag }}-darwin-amd64.tar.gz -C velero-client + +More info on the official site: https://velero.io/docs + +{{- /* + Breaking changes. +*/}} + +{{- $breaking := "" }} +{{- $breaking_title := "\n" }} +{{- $breaking_title = print $breaking_title "\n#################################################################################" }} +{{- $breaking_title = print $breaking_title "\n###### BREAKING: The config values passed contained no longer accepted #####" }} +{{- $breaking_title = print $breaking_title "\n###### options. See the messages below for more details. #####" }} +{{- $breaking_title = print $breaking_title "\n###### #####" }} +{{- $breaking_title = print $breaking_title "\n###### To verify your updated config is accepted, you can use #####" }} +{{- $breaking_title = print $breaking_title "\n###### the `helm template` command. #####" }} +{{- $breaking_title = print $breaking_title "\n#################################################################################" }} + +{{- if typeIs "map[string]interface {}" .Values.configuration.backupStorageLocation }} +{{- $breaking = print $breaking "\n\nERROR: Please make .configuration.backupStorageLocation from map to slice" }} +{{- end }} + +{{- if typeIs "map[string]interface {}" .Values.configuration.volumeSnapshotLocation }} +{{- $breaking = print $breaking "\n\nERROR: Please make .configuration.volumeSnapshotLocation from map to slice" }} +{{- end }} + +{{- if hasKey .Values.configuration "provider" }} +{{- $breaking = print $breaking "\n\nREMOVED: .configuration.provider has been removed, instead each backupStorageLocation and volumeSnapshotLocation has a provider configured" }} +{{- end }} + +{{- if hasKey .Values "resticTimeout" }} +{{- $breaking = print $breaking "\n\nREMOVED: resticTimeout has been removed, and it is named fsBackupTimeout" }} +{{- end }} + +{{- if hasKey .Values "defaultVolumesToRestic" }} +{{- $breaking = print $breaking "\n\nREMOVED: defaultVolumesToRestic has been removed, and it is named defaultVolumesToFsBackup" }} +{{- end }} + +{{- if hasKey .Values "defaultResticPruneFrequency" }} +{{- $breaking = print $breaking "\n\nREMOVED: defaultResticPruneFrequency has been removed, and it is named defaultRepoMaintainFrequency" }} +{{- end }} + +{{- if hasKey .Values "deployRestic" }} +{{- $breaking = print $breaking "\n\nREMOVED: deployRestic has been removed, and it is named deployNodeAgent" }} +{{- end }} + +{{- if hasKey .Values "restic" }} +{{- $breaking = print $breaking "\n\nREMOVED: restic has been removed, and it is named nodeAgent" }} +{{- end }} + +{{- if hasKey .Values.configMaps "restic-restore-action-config" }} +{{- $breaking = print $breaking "\n\nREMOVED: restic-restore-action-config has been removed, and it is named fs-restore-action-config" }} +{{- end }} + +{{- range $key, $value := .Values.configMaps }} +{{- if eq $key "fs-restore-action-config" }} +{{- if hasKey $value.labels "velero.io/restic" }} +{{- $breaking = print $breaking "\n\nREMOVED: velero.io/restic has been removed, and it is named velero.io/pod-volume-restore" }} +{{- end }} +{{- if and $value.data.image }} +{{- if contains "velero-restic-restore-helper" $value.data.image }} +{{- $breaking = print $breaking "\n\nREMOVED: restore helper image velero-restic-restore-helper has been changed to velero-restore-helper" }} +{{- end }} +{{- end }} +{{- end }} +{{- end }} + +{{- if $breaking }} +{{- fail (print $breaking_title $breaking) }} +{{- end }} diff --git a/velero/templates/_helpers.tpl b/velero/templates/_helpers.tpl new file mode 100644 index 0000000..e47cb1c --- /dev/null +++ b/velero/templates/_helpers.tpl @@ -0,0 +1,118 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "velero.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "velero.fullname" -}} +{{- if .Values.fullnameOverride -}} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- if contains $name .Release.Name -}} +{{- .Release.Name | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "velero.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create the name of the service account to use for creating or deleting the velero server +*/}} +{{- define "velero.serverServiceAccount" -}} +{{- if .Values.serviceAccount.server.create -}} + {{ default (printf "%s-%s" (include "velero.fullname" .) "server") .Values.serviceAccount.server.name }} +{{- else -}} + {{ default "default" .Values.serviceAccount.server.name }} +{{- end -}} +{{- end -}} + +{{/* +Create the name for the credentials secret. +*/}} +{{- define "velero.secretName" -}} +{{- if .Values.credentials.existingSecret -}} + {{- .Values.credentials.existingSecret -}} +{{- else -}} + {{ default (include "velero.fullname" .) .Values.credentials.name }} +{{- end -}} +{{- end -}} + +{{/* +Create the Velero priority class name. +*/}} +{{- define "velero.priorityClassName" -}} +{{- if .Values.priorityClassName -}} + {{- .Values.priorityClassName -}} +{{- else -}} + {{- include "velero.fullname" . -}} +{{- end -}} +{{- end -}} + +{{/* +Create the Velero runtime class name. +*/}} +{{- define "velero.runtimeClassName" -}} +{{- if .Values.runtimeClassName -}} + {{- .Values.runtimeClassName -}} +{{- else -}} + {{- include "velero.fullname" . -}} +{{- end -}} +{{- end -}} + +{{/* +Create the node-Agent priority class name. +*/}} +{{- define "velero.nodeAgent.priorityClassName" -}} +{{- if .Values.nodeAgent.priorityClassName -}} + {{- .Values.nodeAgent.priorityClassName -}} +{{- else -}} + {{- include "velero.fullname" . -}} +{{- end -}} +{{- end -}} + +{{/* +Create the node-Agent runtime class name. +*/}} +{{- define "velero.nodeAgent.runtimeClassName" -}} +{{- if .Values.nodeAgent.runtimeClassName -}} + {{- .Values.nodeAgent.runtimeClassName -}} +{{- else -}} + {{- include "velero.fullname" . -}} +{{- end -}} +{{- end -}} + +{{/* +Kubernetes version +Built-in object .Capabilities.KubeVersion.Minor can provide non-number output +For examples: +- on GKE it returns "18+" instead of "18" +- on EKS it returns "20+" instead of "20" +*/}} +{{- define "chart.KubernetesVersion" -}} +{{- $minorVersion := .Capabilities.KubeVersion.Minor | regexFind "[0-9]+" -}} +{{- printf "%s.%s" .Capabilities.KubeVersion.Major $minorVersion -}} +{{- end -}} + + +{{/* +Calculate the checksum of the credentials secret. +*/}} +{{- define "chart.config-checksum" -}} +{{- tpl (print .Values.credentials.secretContents .Values.credentials.extraEnvVars ) $ | sha256sum -}} +{{- end -}} diff --git a/velero/templates/backupstoragelocation.yaml b/velero/templates/backupstoragelocation.yaml new file mode 100644 index 0000000..b86cf19 --- /dev/null +++ b/velero/templates/backupstoragelocation.yaml @@ -0,0 +1,56 @@ +{{- if .Values.backupsEnabled }} + +{{- if typeIs "[]interface {}" .Values.configuration.backupStorageLocation }} +{{- range .Values.configuration.backupStorageLocation }} +--- +apiVersion: velero.io/v1 +kind: BackupStorageLocation +metadata: + name: {{ .name | default "default" }} + namespace: {{ $.Release.Namespace }} + {{- with .annotations }} + annotations: + {{- range $key, $value := . }} + {{- $key | nindent 4 }}: {{ $value | quote }} + {{- end }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" $ }} + app.kubernetes.io/instance: {{ $.Release.Name }} + app.kubernetes.io/managed-by: {{ $.Release.Service }} + helm.sh/chart: {{ include "velero.chart" $ }} +spec: + {{- if not (empty .credential) }} + credential: + {{- with .credential.name }} + name: {{ . }} + {{- end }} + {{- with .credential.key }} + key: {{ . }} + {{- end }} + {{- end }} + provider: {{ .provider }} + accessMode: {{ .accessMode | default "ReadWrite" }} + {{- with .default }} + default: {{ . }} + {{- end }} + {{- with .validationFrequency }} + validationFrequency: {{ . }} + {{- end }} + objectStorage: + bucket: {{ .bucket | quote }} + {{- with .prefix }} + prefix: {{ . | quote }} + {{- end }} + {{- with .caCert }} + caCert: {{ . }} + {{- end }} +{{- with .config }} + config: +{{- range $key, $value := . }} +{{- $key | nindent 4 }}: {{ $value | quote }} +{{- end }} +{{- end }} +{{- end }} +{{- end }} +{{- end }} diff --git a/velero/templates/cleanup-crds.yaml b/velero/templates/cleanup-crds.yaml new file mode 100644 index 0000000..4e86320 --- /dev/null +++ b/velero/templates/cleanup-crds.yaml @@ -0,0 +1,85 @@ +{{- if .Values.cleanUpCRDs }} +# This job is meant primarily for cleaning up on CI systems. +# Using this on production systems, especially those that have multiple releases of Velero, will be destructive. +{{/* 'securityContext' got renamed to 'podSecurityContext', merge both dicts into one for backward compatibility */}} +{{- $podSecurityContext := merge (.Values.podSecurityContext | default dict) (.Values.securityContext | default dict) -}} +apiVersion: batch/v1 +kind: Job +metadata: + name: {{ template "velero.fullname" . }}-cleanup-crds + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": pre-delete + "helm.sh/hook-delete-policy": hook-succeeded + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +spec: + backoffLimit: 3 + template: + metadata: + name: velero-cleanup-crds + {{- with .Values.kubectl.labels }} + labels: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.kubectl.annotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + spec: + {{- if .Values.image.imagePullSecrets }} + imagePullSecrets: + {{- range .Values.image.imagePullSecrets }} + - name: {{ . }} + {{- end }} + {{- end }} + serviceAccountName: {{ include "velero.serverServiceAccount" . }} + containers: + - name: kubectl + {{- if .Values.kubectl.image.digest }} + image: "{{ .Values.kubectl.image.repository }}@{{ .Values.kubectl.image.digest }}" + {{- else if .Values.kubectl.image.tag }} + image: "{{ .Values.kubectl.image.repository }}:{{ .Values.kubectl.image.tag }}" + {{- else }} + image: "{{ .Values.kubectl.image.repository }}:{{ template "chart.KubernetesVersion" . }}" + {{- end }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - /bin/sh + - -c + - > + kubectl delete restore --all; + kubectl delete backup --all; + kubectl delete backupstoragelocation --all; + kubectl delete volumesnapshotlocation --all; + kubectl delete podvolumerestore --all; + kubectl delete crd -l component=velero; + {{- with .Values.kubectl.containerSecurityContext }} + securityContext: + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.kubectl.resources }} + resources: + {{- toYaml . | nindent 12 }} + {{- end }} + restartPolicy: OnFailure + {{- with $podSecurityContext }} + securityContext: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} +{{- end }} diff --git a/velero/templates/clusterrolebinding.yaml b/velero/templates/clusterrolebinding.yaml new file mode 100644 index 0000000..669289c --- /dev/null +++ b/velero/templates/clusterrolebinding.yaml @@ -0,0 +1,20 @@ +{{- if and .Values.rbac.create .Values.rbac.clusterAdministrator }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ include "velero.fullname" . }}-server + labels: + app.kubernetes.io/component: server + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +subjects: + - kind: ServiceAccount + namespace: {{ .Release.Namespace }} + name: {{ include "velero.serverServiceAccount" . }} +roleRef: + kind: ClusterRole + name: {{ .Values.rbac.clusterAdministratorName }} + apiGroup: rbac.authorization.k8s.io +{{- end }} diff --git a/velero/templates/configmaps.yaml b/velero/templates/configmaps.yaml new file mode 100644 index 0000000..5840681 --- /dev/null +++ b/velero/templates/configmaps.yaml @@ -0,0 +1,18 @@ +{{- range $configMapName, $configMap := .Values.configMaps }} +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ include "velero.fullname" $ }}-{{ $configMapName }} + namespace: {{ $.Release.Namespace }} + labels: + app.kubernetes.io/name: {{ include "velero.name" $ }} + app.kubernetes.io/instance: {{ $.Release.Name }} + app.kubernetes.io/managed-by: {{ $.Release.Service }} + helm.sh/chart: {{ include "velero.chart" $ }} + {{- with $configMap.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +data: + {{- toYaml $configMap.data | nindent 2 }} +--- +{{- end }} diff --git a/velero/templates/deployment.yaml b/velero/templates/deployment.yaml new file mode 100644 index 0000000..b331876 --- /dev/null +++ b/velero/templates/deployment.yaml @@ -0,0 +1,328 @@ +{{/* 'securityContext' got renamed to 'podSecurityContext', merge both dicts into one for backward compatibility */}} +{{- $podSecurityContext := merge (.Values.podSecurityContext | default dict) (.Values.securityContext | default dict) -}} +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "velero.fullname" . }} + namespace: {{ .Release.Namespace }} + {{- with .Values.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/version: {{ .Chart.AppVersion }} + helm.sh/chart: {{ include "velero.chart" . }} + component: velero + {{- with .Values.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + replicas: 1 + {{- if .Values.revisionHistoryLimit }} + revisionHistoryLimit: {{ .Values.revisionHistoryLimit }} + {{- end }} + strategy: + type: Recreate + selector: + matchLabels: + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/name: {{ include "velero.name" . }} + template: + metadata: + labels: + name: velero + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/version: {{ .Chart.AppVersion }} + helm.sh/chart: {{ include "velero.chart" . }} + {{- if .Values.podLabels }} + {{- toYaml .Values.podLabels | nindent 8 }} + {{- end }} + {{- if or .Values.podAnnotations .Values.metrics.enabled (and .Values.credentials.useSecret (not .Values.credentials.existingSecret)) }} + annotations: + {{- with .Values.podAnnotations }} + {{- toYaml . | nindent 8 }} + {{- end }} + {{- if and (.Values.metrics.enabled) (not .Values.metrics.serviceMonitor.enabled) }} + {{- with .Values.metrics.podAnnotations }} + {{- toYaml . | nindent 8 }} + {{- end }} + {{- end }} + {{- if and .Values.credentials.useSecret (not .Values.credentials.existingSecret) }} + checksum/secret: {{ template "chart.config-checksum" . }} + {{- end }} + {{- end }} + spec: + {{- with .Values.hostAliases }} + hostAliases: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- if .Values.image.imagePullSecrets }} + imagePullSecrets: + {{- range .Values.image.imagePullSecrets }} + - name: {{ . }} + {{- end }} + {{- end }} + restartPolicy: Always + serviceAccountName: {{ include "velero.serverServiceAccount" . }} + automountServiceAccountToken: {{ .Values.serviceAccount.server.automountServiceAccountToken }} + {{- if .Values.priorityClassName }} + priorityClassName: {{ include "velero.priorityClassName" . }} + {{- end }} + {{- if .Values.runtimeClassName }} + runtimeClassName: {{ include "velero.runtimeClassName" . }} + {{- end }} + terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }} + containers: + - name: velero + {{- if .Values.image.digest }} + image: "{{ .Values.image.repository }}@{{ .Values.image.digest }}" + {{- else }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + {{- end }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + {{- if .Values.metrics.enabled }} + ports: + - name: http-monitoring + containerPort: 8085 + {{- end }} + command: + - /velero + args: + - server + ### Flags + {{- with .Values.configuration }} + - --uploader-type={{ default "kopia" .uploaderType }} + {{- with .backupSyncPeriod }} + - --backup-sync-period={{ . }} + {{- end }} + {{- with .fsBackupTimeout }} + - --fs-backup-timeout={{ . }} + {{- end }} + {{- with .clientBurst }} + - --client-burst={{ . }} + {{- end }} + {{- with .clientPageSize }} + - --client-page-size={{ . }} + {{- end }} + {{- with .clientQPS }} + - --client-qps={{ . }} + {{- end }} + {{- with .defaultBackupStorageLocation }} + - --default-backup-storage-location={{ . }} + {{- end }} + {{- with .defaultBackupTTL }} + - --default-backup-ttl={{ . }} + {{- end }} + {{- with .defaultItemOperationTimeout }} + - --default-item-operation-timeout={{ . }} + {{- end }} + {{- with .defaultVolumeSnapshotLocations }} + - --default-volume-snapshot-locations={{ . }} + {{- end }} + {{- if .defaultVolumesToFsBackup }} + - --default-volumes-to-fs-backup + {{- end }} + {{- with .defaultRepoMaintainFrequency }} + - --default-repo-maintain-frequency={{ . }} + {{- end }} + {{- with .disableControllers }} + - --disable-controllers={{ . }} + {{- end }} + {{- with .disableInformerCache }} + - --disable-informer-cache={{ . }} + {{- end }} + {{- with .garbageCollectionFrequency }} + - --garbage-collection-frequency={{ . }} + {{- end }} + {{- with .itemBlockWorkerCount }} + - --item-block-worker-count={{ . }} + {{- end }} + {{- with .logFormat }} + - --log-format={{ . }} + {{- end }} + {{- with .logLevel }} + - --log-level={{ . }} + {{- end }} + {{- with .metricsAddress }} + - --metrics-address={{ . }} + {{- end }} + {{- with .pluginDir }} + - --plugin-dir={{ . }} + {{- end }} + {{- with .profilerAddress }} + - --profiler-address={{ . }} + {{- end }} + {{- if .restoreOnlyMode }} + - --restore-only + {{- end }} + {{- with .restoreResourcePriorities }} + - --restore-resource-priorities={{ . }} + {{- end }} + {{- with .storeValidationFrequency }} + - --store-validation-frequency={{ . }} + {{- end }} + {{- with .terminatingResourceTimeout }} + - --terminating-resource-timeout={{ . }} + {{- end }} + {{- with .defaultSnapshotMoveData }} + - --default-snapshot-move-data={{ . }} + {{- end }} + ### Global Flags + {{- with .features }} + - --features={{ . }} + {{- end }} + {{- with .namespace }} + - --namespace={{ . }} + {{- end }} + {{- with .repositoryMaintenanceJob }} + {{- with .requests }} + {{- with .cpu }} + - --maintenance-job-cpu-request={{ . }} + {{- end }} + {{- with .memory }} + - --maintenance-job-mem-request={{ . }} + {{- end }} + {{- end }} + {{- with .limits }} + {{- with .cpu }} + - --maintenance-job-cpu-limit={{ . }} + {{- end }} + {{- with .memory }} + - --maintenance-job-mem-limit={{ . }} + {{- end }} + {{- end }} + {{- with .latestJobsCount }} + - --keep-latest-maintenance-jobs={{ . }} + {{- end }} + {{- end }} + {{- with .extraArgs }} + ### User-supplied overwrite flags + {{- toYaml . | nindent 12 }} + {{- end }} + {{- end }} + {{- with .Values.resources }} + resources: + {{- toYaml . | nindent 12 }} + {{- end }} + {{- if .Values.metrics.enabled }} + {{- with .Values.livenessProbe }} + livenessProbe: {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.readinessProbe }} + readinessProbe: {{- toYaml . | nindent 12 }} + {{- end }} + {{- end }} + {{- with .Values.containerSecurityContext }} + securityContext: + {{- toYaml . | nindent 12 }} + {{- end }} + volumeMounts: + - name: plugins + mountPath: /plugins + {{- if .Values.credentials.useSecret }} + - name: cloud-credentials + mountPath: /credentials + {{- end }} + - name: scratch + mountPath: /scratch + {{- if .Values.containerSecurityContext.readOnlyRootFilesystem }} + - name: tmpdir + mountPath: /tmp + {{- end }} + {{- if .Values.extraVolumeMounts }} + {{- toYaml .Values.extraVolumeMounts | nindent 12 }} + {{- end }} + {{- if .Values.credentials.extraSecretRef }} + envFrom: + - secretRef: + name: {{ .Values.credentials.extraSecretRef }} + {{- end }} + env: + - name: VELERO_SCRATCH_DIR + value: /scratch + - name: VELERO_NAMESPACE + valueFrom: + fieldRef: + apiVersion: v1 + fieldPath: metadata.namespace + - name: LD_LIBRARY_PATH + value: /plugins + {{- if .Values.credentials.useSecret }} + - name: AWS_SHARED_CREDENTIALS_FILE + value: /credentials/cloud + - name: GOOGLE_APPLICATION_CREDENTIALS + value: /credentials/cloud + - name: AZURE_CREDENTIALS_FILE + value: /credentials/cloud + - name: ALIBABA_CLOUD_CREDENTIALS_FILE + value: /credentials/cloud + {{- end }} + {{- with .Values.configuration.extraEnvVars }} + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.credentials.extraEnvVars }} + {{- range $key, $value := . }} + - name: {{ default "none" $key }} + valueFrom: + secretKeyRef: + name: {{ include "velero.secretName" $ }} + key: {{ default "none" $key }} + {{- end }} + {{- end }} + {{- if .Values.lifecycle }} + lifecycle: {{ toYaml .Values.lifecycle | nindent 12 }} + {{- end }} + {{- if .Values.extraContainers }} + {{ toYaml .Values.extraContainers | nindent 8 }} + {{- end }} + dnsPolicy: {{ .Values.dnsPolicy }} +{{- if .Values.initContainers }} + initContainers: + {{- if eq (typeOf .Values.initContainers) "string" }} + {{- tpl .Values.initContainers . | nindent 8 }} + {{- else }} + {{- toYaml .Values.initContainers | nindent 8 }} + {{- end }} +{{- end }} + volumes: + {{- if .Values.credentials.useSecret }} + - name: cloud-credentials + secret: + secretName: {{ include "velero.secretName" . }} + {{- end }} + - name: plugins + emptyDir: {} + - name: scratch + emptyDir: {} + {{- if .Values.containerSecurityContext.readOnlyRootFilesystem }} + - name: tmpdir + emptyDir: {} + {{- end }} + {{- if .Values.extraVolumes }} + {{- toYaml .Values.extraVolumes | nindent 8 }} + {{- end }} + {{- with $podSecurityContext }} + securityContext: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.dnsConfig }} + dnsConfig: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} diff --git a/velero/templates/etcd-backup.yaml b/velero/templates/etcd-backup.yaml new file mode 100644 index 0000000..45ad9cf --- /dev/null +++ b/velero/templates/etcd-backup.yaml @@ -0,0 +1,37 @@ +apiVersion: velero.io/v1 +kind: Backup +metadata: + name: etcd-backup +spec: + includedNamespaces: + - velero + includedResources: [] + hooks: + resources: + - name: velero + includedNamespaces: + - velero + pre: + - exec: + container: etcdctl + command: + - /bin/sh + - -c + - | + set -e + echo "Starting etcd backup at $(date)" + BACKUP_DIR="/var/lib/velero/etcd-backup" + TIMESTAMP=$(date +"%Y%m%d-%H%M%S") + mkdir -p "$BACKUP_DIR" + echo "Backup directory created: $BACKUP_DIR" + ETCDCTL_API=3 etcdctl snapshot save "$BACKUP_DIR/etcd-snapshot-$TIMESTAMP.db" \ + --endpoints=https://10.130.0.20:2379 \ + --cacert=/etc/kubernetes/pki/etcd/ca.pem \ + --cert=/etc/kubernetes/pki/etcd/cert.pem \ + --key=/etc/kubernetes/pki/etcd/key.pem + echo "etcd snapshot saved" + tar czf "$BACKUP_DIR/k8s-pki-$TIMESTAMP.tar.gz" -C /etc/kubernetes pki + echo "PKI files archived" + echo "Backup completed at $BACKUP_DIR" + storageLocation: default + ttl: 72h \ No newline at end of file diff --git a/velero/templates/extra-manifests.yaml b/velero/templates/extra-manifests.yaml new file mode 100644 index 0000000..a9bb3b6 --- /dev/null +++ b/velero/templates/extra-manifests.yaml @@ -0,0 +1,4 @@ +{{ range .Values.extraObjects }} +--- +{{ tpl (toYaml .) $ }} +{{ end }} diff --git a/velero/templates/label-namespace/labelnamespace.yaml b/velero/templates/label-namespace/labelnamespace.yaml new file mode 100644 index 0000000..de64ce6 --- /dev/null +++ b/velero/templates/label-namespace/labelnamespace.yaml @@ -0,0 +1,48 @@ +{{- if .Values.namespace }} +{{- if gt (len .Values.namespace.labels) 0 }} +apiVersion: batch/v1 +kind: Job +metadata: + name: {{ template "velero.fullname" . }}-label-namespace + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": post-install,post-upgrade,post-rollback + "helm.sh/hook-delete-policy": hook-succeeded + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +spec: + template: + spec: + serviceAccountName: {{ include "velero.serverServiceAccount" . }} + automountServiceAccountToken: {{ .Values.serviceAccount.server.automountServiceAccountToken }} + containers: + - name: label-namespace + {{- if .Values.kubectl.image.digest }} + image: "{{ .Values.kubectl.image.repository }}@{{ .Values.kubectl.image.digest }}" + {{- else if .Values.kubectl.image.tag }} + image: "{{ .Values.kubectl.image.repository }}:{{ .Values.kubectl.image.tag }}" + {{- else }} + image: "{{ .Values.kubectl.image.repository }}:{{ template "chart.KubernetesVersion" . }}" + {{- end }} + command: + - /bin/sh + - -c + - | + {{- range .Values.namespace.labels }} + kubectl label namespace {{ $.Release.Namespace }} {{ .key }}={{ .value }} + {{- end }} + {{- if .Values.kubectl.extraVolumeMounts }} + volumeMounts: + {{- toYaml .Values.kubectl.extraVolumeMounts | nindent 8 }} + {{- end }} + restartPolicy: Never + {{- if .Values.kubectl.extraVolumes }} + volumes: + {{- toYaml .Values.kubectl.extraVolumes | nindent 6 }} + {{- end }} + backoffLimit: 3 +{{- end }} +{{- end }} \ No newline at end of file diff --git a/velero/templates/node-agent-daemonset.yaml b/velero/templates/node-agent-daemonset.yaml new file mode 100644 index 0000000..962e67a --- /dev/null +++ b/velero/templates/node-agent-daemonset.yaml @@ -0,0 +1,220 @@ +{{- if .Values.deployNodeAgent }} +{{/* 'nodeAgent.securityContext' got renamed to 'nodeAgent.containerSecurityContext', merge both dicts into one for backward compatibility */}} +{{- $containerSecurityContext := merge (.Values.nodeAgent.containerSecurityContext | default dict) (.Values.nodeAgent.securityContext | default dict) -}} +apiVersion: apps/v1 +kind: DaemonSet +metadata: + name: node-agent + namespace: {{ .Release.Namespace }} + {{- with .Values.nodeAgent.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} + {{- with .Values.nodeAgent.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: + name: node-agent + template: + metadata: + labels: + name: node-agent + role: node-agent + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} + {{- if .Values.nodeAgent.podLabels }} + {{- toYaml .Values.nodeAgent.podLabels | nindent 8 }} + {{- end }} + {{- if or .Values.podAnnotations .Values.metrics.enabled (and .Values.credentials.useSecret (not .Values.credentials.existingSecret)) }} + annotations: + {{- with .Values.podAnnotations }} + {{- toYaml . | nindent 8 }} + {{- end }} + {{- if and (.Values.metrics.enabled) (not .Values.metrics.nodeAgentPodMonitor.enabled) }} + {{- with .Values.metrics.podAnnotations }} + {{- toYaml . | nindent 8 }} + {{- end }} + {{- end }} + {{- if and .Values.credentials.useSecret (not .Values.credentials.existingSecret) }} + checksum/secret: {{ template "chart.config-checksum" . }} + {{- end }} + {{- end }} + spec: + {{- with .Values.nodeAgent.hostAliases }} + hostAliases: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- if .Values.image.imagePullSecrets }} + imagePullSecrets: + {{- range .Values.image.imagePullSecrets }} + - name: {{ . }} + {{- end }} + {{- end }} + serviceAccountName: {{ include "velero.serverServiceAccount" . }} + automountServiceAccountToken: {{ .Values.serviceAccount.server.automountServiceAccountToken }} + {{- with .Values.nodeAgent.podSecurityContext }} + securityContext: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- if .Values.nodeAgent.priorityClassName }} + priorityClassName: {{ include "velero.nodeAgent.priorityClassName" . }} + {{- end }} + {{- if .Values.runtimeClassName }} + runtimeClassName: {{ include "velero.nodeAgent.runtimeClassName" . }} + {{- end }} + terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }} + volumes: + {{- if .Values.credentials.useSecret }} + - name: cloud-credentials + secret: + secretName: {{ include "velero.secretName" . }} + {{- end }} + - name: host-pods + hostPath: + path: {{ .Values.nodeAgent.podVolumePath }} + - name: host-plugins + hostPath: + path: {{ .Values.nodeAgent.pluginVolumePath | default "/var/lib/kubelet/plugins" }} + {{- if .Values.nodeAgent.useScratchEmptyDir }} + - name: scratch + emptyDir: {} + {{- end }} + {{- if .Values.nodeAgent.extraVolumes }} + {{- toYaml .Values.nodeAgent.extraVolumes | nindent 8 }} + {{- end }} + dnsPolicy: {{ .Values.nodeAgent.dnsPolicy }} + containers: + - name: node-agent + {{- if .Values.image.digest }} + image: "{{ .Values.image.repository }}@{{ .Values.image.digest }}" + {{- else }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + {{- end }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + {{- if .Values.metrics.enabled }} + ports: + - name: http-monitoring + containerPort: 8085 + {{- end }} + command: + - /velero + args: + - node-agent + - server + {{- with .Values.configuration }} + {{- with .features }} + - --features={{ . }} + {{- end }} + {{- with .dataMoverPrepareTimeout }} + - --data-mover-prepare-timeout={{ . }} + {{- end }} + {{- with .logLevel }} + - --log-level={{ . }} + {{- end }} + {{- with .logFormat }} + - --log-format={{ . }} + {{- end }} + {{- end }} + {{- with .Values.nodeAgent.extraArgs }} + {{- toYaml . | nindent 12 }} + {{- end }} + volumeMounts: + {{- if .Values.credentials.useSecret }} + - name: cloud-credentials + mountPath: /credentials + {{- end }} + - name: host-pods + mountPath: /host_pods + mountPropagation: HostToContainer + - name: host-plugins + mountPath: /host_plugins + mountPropagation: HostToContainer + {{- if .Values.nodeAgent.useScratchEmptyDir }} + - name: scratch + mountPath: /scratch + {{- end }} + {{- if .Values.nodeAgent.extraVolumeMounts }} + {{- toYaml .Values.nodeAgent.extraVolumeMounts | nindent 12 }} + {{- end }} + {{- if .Values.credentials.extraSecretRef }} + envFrom: + - secretRef: + name: {{ .Values.credentials.extraSecretRef }} + {{- end }} + env: + - name: VELERO_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: NODE_NAME + valueFrom: + fieldRef: + fieldPath: spec.nodeName + - name: VELERO_SCRATCH_DIR + value: /scratch + {{- if .Values.credentials.useSecret }} + - name: AWS_SHARED_CREDENTIALS_FILE + value: /credentials/cloud + - name: GOOGLE_APPLICATION_CREDENTIALS + value: /credentials/cloud + - name: AZURE_CREDENTIALS_FILE + value: /credentials/cloud + - name: ALIBABA_CLOUD_CREDENTIALS_FILE + value: /credentials/cloud + {{- end }} + {{- with .Values.configuration.extraEnvVars }} + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.credentials.extraEnvVars }} + {{- range $key, $value := . }} + - name: {{ default "none" $key }} + valueFrom: + secretKeyRef: + name: {{ include "velero.secretName" $ }} + key: {{ default "none" $key }} + {{- end }} + {{- end }} + {{- with .Values.nodeAgent.extraEnvVars }} + {{- toYaml . | nindent 12 }} + {{- end }} + {{- if .Values.lifecycle }} + lifecycle: {{ toYaml .Values.nodeAgent.lifecycle | nindent 12 }} + {{- end }} + securityContext: + {{- with $containerSecurityContext }} + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.nodeAgent.resources }} + resources: + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.nodeAgent.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.nodeAgent.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.nodeAgent.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.nodeAgent.dnsConfig }} + dnsConfig: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.nodeAgent.updateStrategy }} + updateStrategy: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} diff --git a/velero/templates/podmonitor.yaml b/velero/templates/podmonitor.yaml new file mode 100644 index 0000000..4e4e304 --- /dev/null +++ b/velero/templates/podmonitor.yaml @@ -0,0 +1,44 @@ +{{ if and (and .Values.metrics.enabled .Values.metrics.nodeAgentPodMonitor.enabled) (or (not .Values.metrics.nodeAgentPodMonitor.autodetect) (.Capabilities.APIVersions.Has "monitoring.coreos.com/v1")) }} +apiVersion: monitoring.coreos.com/v1 +kind: PodMonitor +metadata: + name: node-agent + {{- if .Values.metrics.nodeAgentPodMonitor.namespace }} + namespace: {{ .Values.metrics.nodeAgentPodMonitor.namespace }} + {{- end }} + {{- with .Values.metrics.nodeAgentPodMonitor.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} + {{- with .Values.metrics.nodeAgentPodMonitor.additionalLabels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + namespaceSelector: + matchNames: + - {{ .Release.Namespace }} + selector: + matchLabels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + name: node-agent + {{- with .Values.nodeAgent.podLabels }} + {{- toYaml . | nindent 6 }} + {{- end }} + podMetricsEndpoints: + - port: http-monitoring + interval: {{ .Values.metrics.scrapeInterval }} + scrapeTimeout: {{ .Values.metrics.scrapeTimeout }} + {{- if .Values.metrics.nodeAgentPodMonitor.scheme }} + scheme: {{ .Values.metrics.nodeAgentPodMonitor.scheme }} + {{- end }} + {{- if .Values.metrics.nodeAgentPodMonitor.tlsConfig }} + tlsConfig: + {{- toYaml .Values.metrics.nodeAgentPodMonitor.tlsConfig | nindent 6 }} + {{- end }} +{{- end }} diff --git a/velero/templates/prometheusrule.yaml b/velero/templates/prometheusrule.yaml new file mode 100644 index 0000000..60bcfc3 --- /dev/null +++ b/velero/templates/prometheusrule.yaml @@ -0,0 +1,21 @@ +{{- if and (and .Values.metrics.enabled .Values.metrics.prometheusRule.enabled) (or (not .Values.metrics.prometheusRule.autodetect) (.Capabilities.APIVersions.Has "monitoring.coreos.com/v1")) (.Values.metrics.prometheusRule.spec) }} +apiVersion: monitoring.coreos.com/v1 +kind: PrometheusRule +metadata: + name: {{ include "velero.fullname" . }} + {{- if .Values.metrics.prometheusRule.namespace }} + namespace: {{ .Values.metrics.prometheusRule.namespace }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + {{- if .Values.metrics.prometheusRule.additionalLabels }} + {{- toYaml .Values.metrics.prometheusRule.additionalLabels | nindent 4 }} + {{- end }} +spec: + groups: + - name: {{ include "velero.name" . }} + rules: + {{- toYaml .Values.metrics.prometheusRule.spec | nindent 4 }} +{{- end }} diff --git a/velero/templates/role.yaml b/velero/templates/role.yaml new file mode 100644 index 0000000..f6bc87c --- /dev/null +++ b/velero/templates/role.yaml @@ -0,0 +1,21 @@ +{{- if .Values.rbac.create }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: {{ include "velero.fullname" . }}-server + namespace: {{ .Release.Namespace }} + labels: + app.kubernetes.io/component: server + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +rules: +- apiGroups: + - "*" + resources: + - "*" + verbs: + - "*" + +{{- end }} diff --git a/velero/templates/rolebinding.yaml b/velero/templates/rolebinding.yaml new file mode 100644 index 0000000..d77bea4 --- /dev/null +++ b/velero/templates/rolebinding.yaml @@ -0,0 +1,21 @@ +{{- if .Values.rbac.create }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: {{ include "velero.fullname" . }}-server + namespace: {{ .Release.Namespace }} + labels: + app.kubernetes.io/component: server + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +subjects: + - kind: ServiceAccount + namespace: {{ .Release.Namespace }} + name: {{ include "velero.serverServiceAccount" . }} +roleRef: + kind: Role + name: {{ include "velero.fullname" . }}-server + apiGroup: rbac.authorization.k8s.io +{{- end }} diff --git a/velero/templates/schedule.yaml b/velero/templates/schedule.yaml new file mode 100644 index 0000000..3236658 --- /dev/null +++ b/velero/templates/schedule.yaml @@ -0,0 +1,37 @@ +{{- range $scheduleName, $schedule := .Values.schedules }} +{{- if (not $schedule.disabled) }} +apiVersion: velero.io/v1 +kind: Schedule +metadata: + name: {{ include "velero.fullname" $ }}-{{ $scheduleName }} + namespace: {{ $.Release.Namespace }} + {{- if $schedule.annotations }} + annotations: + {{- toYaml $schedule.annotations | nindent 4 }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" $ }} + app.kubernetes.io/instance: {{ $.Release.Name }} + app.kubernetes.io/managed-by: {{ $.Release.Service }} + helm.sh/chart: {{ include "velero.chart" $ }} + {{- if $schedule.labels }} + {{- toYaml $schedule.labels | nindent 4 }} + {{- end }} +spec: +{{- if $schedule.paused }} + paused: {{ $schedule.paused }} +{{- end }} +{{- if $schedule.useOwnerReferencesInBackup }} + useOwnerReferencesInBackup: {{ $schedule.useOwnerReferencesInBackup }} +{{- end }} +{{- if $schedule.skipImmediately }} + skipImmediately: {{ $schedule.skipImmediately }} +{{- end }} + schedule: {{ $schedule.schedule | quote }} +{{- with $schedule.template }} + template: + {{- toYaml . | nindent 4 }} +{{- end }} +--- +{{- end }} +{{- end }} diff --git a/velero/templates/secret.yaml b/velero/templates/secret.yaml new file mode 100644 index 0000000..0cd9d57 --- /dev/null +++ b/velero/templates/secret.yaml @@ -0,0 +1,24 @@ +{{- if and .Values.credentials.useSecret (not .Values.credentials.existingSecret) -}} +apiVersion: v1 +kind: Secret +metadata: + name: {{ include "velero.secretName" . }} + namespace: {{ .Release.Namespace }} + {{- with .Values.secretAnnotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +type: Opaque +data: +{{- range $key, $value := .Values.credentials.secretContents }} + {{ $key }}: {{ tpl $value $ | b64enc | quote }} +{{- end }} +{{- range $key, $value := .Values.credentials.extraEnvVars }} + {{ $key }}: {{ tpl $value $ | b64enc | quote }} +{{- end }} +{{- end -}} diff --git a/velero/templates/service.yaml b/velero/templates/service.yaml new file mode 100644 index 0000000..7cccbc5 --- /dev/null +++ b/velero/templates/service.yaml @@ -0,0 +1,38 @@ +{{- if .Values.metrics.enabled }} +apiVersion: v1 +kind: Service +metadata: + name: {{ include "velero.fullname" . }} + namespace: {{ .Release.Namespace }} + {{- with .Values.metrics.service.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} + {{- with .Values.metrics.service.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + {{- if .Values.metrics.service.externalTrafficPolicy }} + externalTrafficPolicy: {{ .Values.metrics.service.externalTrafficPolicy }} + {{- end }} + {{- if .Values.metrics.service.internalTrafficPolicy }} + internalTrafficPolicy: {{ .Values.metrics.service.internalTrafficPolicy }} + {{- end }} + type: {{ .Values.metrics.service.type }} + ports: + - name: http-monitoring + port: 8085 + {{- if ( and (eq .Values.metrics.service.type "NodePort" ) (not (empty .Values.metrics.service.nodePort)) ) }} + nodePort: {{ .Values.metrics.service.nodePort }} + {{- end }} + targetPort: http-monitoring + selector: + name: velero + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} diff --git a/velero/templates/serviceaccount-server.yaml b/velero/templates/serviceaccount-server.yaml new file mode 100644 index 0000000..2e6e281 --- /dev/null +++ b/velero/templates/serviceaccount-server.yaml @@ -0,0 +1,26 @@ +{{- if .Values.serviceAccount.server.create }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "velero.serverServiceAccount" . }} + namespace: {{ .Release.Namespace }} +{{- if .Values.serviceAccount.server.annotations }} + annotations: +{{- toYaml .Values.serviceAccount.server.annotations | nindent 4 }} +{{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +{{- with .Values.serviceAccount.server.labels }} + {{- toYaml . | nindent 4 }} +{{- end }} +{{- if .Values.serviceAccount.server.imagePullSecrets }} +imagePullSecrets: +{{- range .Values.serviceAccount.server.imagePullSecrets }} + - name: {{ . }} +{{- end }} +{{- end }} +automountServiceAccountToken: {{ .Values.serviceAccount.server.automountServiceAccountToken }} +{{- end }} diff --git a/velero/templates/servicemonitor.yaml b/velero/templates/servicemonitor.yaml new file mode 100644 index 0000000..777ff9f --- /dev/null +++ b/velero/templates/servicemonitor.yaml @@ -0,0 +1,46 @@ +{{ if and (and .Values.metrics.enabled .Values.metrics.serviceMonitor.enabled) (or (not .Values.metrics.serviceMonitor.autodetect) (.Capabilities.APIVersions.Has "monitoring.coreos.com/v1")) }} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: {{ include "velero.fullname" . }} + {{- if .Values.metrics.serviceMonitor.namespace }} + namespace: {{ .Values.metrics.serviceMonitor.namespace }} + {{- end }} + {{- with .Values.metrics.serviceMonitor.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} + {{- with .Values.metrics.serviceMonitor.additionalLabels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + namespaceSelector: + matchNames: + - {{ .Release.Namespace }} + selector: + matchLabels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + endpoints: + - port: http-monitoring + interval: {{ .Values.metrics.scrapeInterval }} + scrapeTimeout: {{ .Values.metrics.scrapeTimeout }} + {{- if .Values.metrics.serviceMonitor.scheme }} + scheme: {{ .Values.metrics.serviceMonitor.scheme }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.metricRelabelings }} + metricRelabelings: {{- toYaml .Values.metrics.serviceMonitor.metricRelabelings | nindent 6 }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.relabelings }} + relabelings: {{ toYaml .Values.metrics.serviceMonitor.relabelings | nindent 6 }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.tlsConfig }} + tlsConfig: + {{- toYaml .Values.metrics.serviceMonitor.tlsConfig | nindent 6 }} + {{- end }} +{{- end }} diff --git a/velero/templates/upgrade-crds/clusterrole-upgrade.yaml b/velero/templates/upgrade-crds/clusterrole-upgrade.yaml new file mode 100644 index 0000000..426d1cb --- /dev/null +++ b/velero/templates/upgrade-crds/clusterrole-upgrade.yaml @@ -0,0 +1,27 @@ +{{- if .Values.upgradeCRDs }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: {{ include "velero.fullname" . }}-upgrade-crds + annotations: + "helm.sh/hook": pre-install,pre-upgrade,pre-rollback + "helm.sh/hook-weight": "-5" + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded + labels: + app.kubernetes.io/component: upgrade-crds + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +rules: +- apiGroups: + - "apiextensions.k8s.io" + resources: + - "customresourcedefinitions" + verbs: + - create + - patch + - update + - get + - list +{{- end }} diff --git a/velero/templates/upgrade-crds/clusterrolebinding-upgrade.yaml b/velero/templates/upgrade-crds/clusterrolebinding-upgrade.yaml new file mode 100644 index 0000000..07d802c --- /dev/null +++ b/velero/templates/upgrade-crds/clusterrolebinding-upgrade.yaml @@ -0,0 +1,25 @@ +{{- if .Values.upgradeCRDs }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ include "velero.fullname" . }}-upgrade-crds + labels: + app.kubernetes.io/component: upgrade-crds + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} + annotations: + "helm.sh/hook": pre-install,pre-upgrade,pre-rollback + "helm.sh/hook-weight": "-3" + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded +subjects: + - kind: ServiceAccount + namespace: {{ .Release.Namespace }} + name: {{ include "velero.serverServiceAccount" . }}-upgrade-crds +roleRef: + kind: ClusterRole + name: {{ include "velero.fullname" . }}-upgrade-crds + apiGroup: rbac.authorization.k8s.io +{{- end }} + diff --git a/velero/templates/upgrade-crds/serviceaccount-upgrade.yaml b/velero/templates/upgrade-crds/serviceaccount-upgrade.yaml new file mode 100644 index 0000000..c41eb5d --- /dev/null +++ b/velero/templates/upgrade-crds/serviceaccount-upgrade.yaml @@ -0,0 +1,29 @@ +{{- if .Values.upgradeCRDs }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "velero.serverServiceAccount" . }}-upgrade-crds + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": pre-install,pre-upgrade,pre-rollback + "helm.sh/hook-weight": "-4" + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded +{{- if .Values.serviceAccount.server.annotations }} +{{- toYaml .Values.serviceAccount.server.annotations | nindent 4 }} +{{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} +{{- with .Values.serviceAccount.server.labels }} + {{- toYaml . | nindent 4 }} +{{- end }} +{{- if .Values.serviceAccount.server.imagePullSecrets }} +imagePullSecrets: +{{- range .Values.serviceAccount.server.imagePullSecrets }} + - name: {{ . }} +{{- end }} +{{- end }} +automountServiceAccountToken: {{ .Values.upgradeCRDsJob.automountServiceAccountToken }} +{{- end }} diff --git a/velero/templates/upgrade-crds/upgrade-crds.yaml b/velero/templates/upgrade-crds/upgrade-crds.yaml new file mode 100644 index 0000000..f9cf034 --- /dev/null +++ b/velero/templates/upgrade-crds/upgrade-crds.yaml @@ -0,0 +1,125 @@ +{{- if .Values.upgradeCRDs }} +{{/* 'securityContext' got renamed to 'podSecurityContext', merge both dicts into one for backward compatibility */}} +{{- $podSecurityContext := merge (.Values.podSecurityContext | default dict) (.Values.securityContext | default dict) -}} +apiVersion: batch/v1 +kind: Job +metadata: + name: {{ template "velero.fullname" . }}-upgrade-crds + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": pre-install,pre-upgrade,pre-rollback + "helm.sh/hook-weight": "5" + "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded + labels: + app.kubernetes.io/name: {{ include "velero.name" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + helm.sh/chart: {{ include "velero.chart" . }} + {{- with .Values.kubectl.labels }} + {{- toYaml . | nindent 4 }} + {{- end }} +spec: + backoffLimit: 3 + template: + metadata: + name: velero-upgrade-crds + {{- with .Values.kubectl.labels }} + labels: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.kubectl.annotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + spec: + {{- if .Values.image.imagePullSecrets }} + imagePullSecrets: + {{- range .Values.image.imagePullSecrets }} + - name: {{ . }} + {{- end }} + {{- end }} + serviceAccountName: {{ include "velero.serverServiceAccount" . }}-upgrade-crds + automountServiceAccountToken: {{ .Values.upgradeCRDsJob.automountServiceAccountToken }} + initContainers: + - name: kubectl + {{- if .Values.kubectl.image.digest }} + image: "{{ .Values.kubectl.image.repository }}@{{ .Values.kubectl.image.digest }}" + {{- else if .Values.kubectl.image.tag }} + image: "{{ .Values.kubectl.image.repository }}:{{ .Values.kubectl.image.tag }}" + {{- else }} + image: "{{ .Values.kubectl.image.repository }}:{{ template "chart.KubernetesVersion" . }}" + {{- end }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - /bin/sh + args: + - -c + - cp `which sh` /tmp && cp `which kubectl` /tmp + {{- with .Values.kubectl.resources }} + resources: + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.kubectl.containerSecurityContext }} + securityContext: + {{- toYaml . | nindent 12 }} + {{- end }} + volumeMounts: + - mountPath: /tmp + name: crds + containers: + - name: velero + {{- if .Values.image.digest }} + image: "{{ .Values.image.repository }}@{{ .Values.image.digest }}" + {{- else }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + {{- end }} + imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - {{ .Values.upgradeCRDsJob.shellCmd | default "/tmp/sh" }} + args: + - -c + - {{ .Values.upgradeCRDsJob.updateCmd | default "/velero install --crds-only --dry-run -o yaml | /tmp/kubectl apply -f -" }} + {{- with .Values.upgradeJobResources }} + resources: + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.containerSecurityContext }} + securityContext: + {{- toYaml . | nindent 12 }} + {{- end }} + volumeMounts: + - mountPath: /tmp + name: crds + {{- if (.Values.upgradeCRDsJob).extraVolumeMounts }} + {{- toYaml .Values.upgradeCRDsJob.extraVolumeMounts | nindent 12 }} + {{- end }} + {{- if (.Values.upgradeCRDsJob).extraEnvVars }} + env: + {{- with .Values.upgradeCRDsJob.extraEnvVars }} + {{- toYaml . | nindent 12 }} + {{- end }} + {{- end }} + volumes: + - name: crds + emptyDir: {} + {{- if (.Values.upgradeCRDsJob).extraVolumes }} + {{- toYaml .Values.upgradeCRDsJob.extraVolumes | nindent 8 }} + {{- end }} + restartPolicy: OnFailure + {{- with $podSecurityContext }} + securityContext: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} +{{- end }} diff --git a/cassandra/templates/vault-setup.yaml b/velero/templates/vault-setup.yml similarity index 73% rename from cassandra/templates/vault-setup.yaml rename to velero/templates/vault-setup.yml index 0a93dd1..4784ffc 100644 --- a/cassandra/templates/vault-setup.yaml +++ b/velero/templates/vault-setup.yml @@ -1,28 +1,29 @@ apiVersion: v1 kind: ServiceAccount metadata: - namespace: {{ .Release.Namespace }} name: vault-secrets-operator-controller-manager + namespace: {{ .Release.Namespace }} --- apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultConnection metadata: - name: vault-connection + name: vault-connection-infra namespace: {{ .Release.Namespace }} spec: - address: http://vault.vault.svc.cluster.local:8200 + address: http://vault:8200 skipTLSVerify: true --- apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultAuth metadata: - name: vault-auth + name: vault-auth-infra namespace: {{ .Release.Namespace }} spec: + vaultConnectionRef: vault-connection-infra method: kubernetes mount: kubernetes kubernetes: - role: cassandra-role + role: velero-role serviceAccount: vault-secrets-operator-controller-manager audiences: - vault @@ -30,14 +31,14 @@ spec: apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultStaticSecret metadata: - name: cassandra-static-user-passwords + name: velero-static-s3-secret namespace: {{ .Release.Namespace }} spec: mount: kvv2 type: kv-v2 - path: cassandra/config + path: velero/config refreshAfter: 5m destination: create: true - name: cassandra-static-user-passwords - vaultAuthRef: vault-auth + name: velero-static-s3-secret + vaultAuthRef: vault-auth-infra diff --git a/velero/templates/velero-db-backup-pvc.yaml b/velero/templates/velero-db-backup-pvc.yaml new file mode 100644 index 0000000..4c9b72c --- /dev/null +++ b/velero/templates/velero-db-backup-pvc.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: velero-db-backup-pvc + namespace: velero + annotations: + backup.velero.io/backup-volumes: "db-backup-pvc" +spec: + accessModes: + - ReadWriteMany + resources: + requests: + storage: 20Gi + storageClassName: client1 diff --git a/velero/templates/velero-etcd-backup-pvc.yaml b/velero/templates/velero-etcd-backup-pvc.yaml new file mode 100644 index 0000000..05c509e --- /dev/null +++ b/velero/templates/velero-etcd-backup-pvc.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: velero-etcd-backup-pvc + namespace: velero + annotations: + backup.velero.io/backup-volumes: "etcd-backup-pvc" +spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 10Gi + storageClassName: client1 diff --git a/velero/templates/velero-etcd-backup-script.yaml b/velero/templates/velero-etcd-backup-script.yaml new file mode 100644 index 0000000..0f4e7d6 --- /dev/null +++ b/velero/templates/velero-etcd-backup-script.yaml @@ -0,0 +1,25 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: velero-etcd-backup-script + namespace: velero +data: + backup-etcd.sh: | + #!/bin/bash + set -e + + BACKUP_DIR="/var/lib/velero/etcd-backup" + TIMESTAMP=$(date +"%Y%m%d-%H%M%S") + + mkdir -p "$BACKUP_DIR" + + # etcd snapshot + ETCDCTL_API=3 etcdctl snapshot save "$BACKUP_DIR/etcd-snapshot-$TIMESTAMP.db" \ + --endpoints=https://10.130.0.20:2379 \ + --cacert=/etc/kubernetes/pki/etcd/ca.pem \ + --cert=/etc/kubernetes/pki/etcd/cert.pem \ + --key=/etc/kubernetes/pki/etcd/key.pem + + tar czf "$BACKUP_DIR/k8s-pki-$TIMESTAMP.tar.gz" -C /etc/kubernetes pki + + echo "Backup completed at $BACKUP_DIR" diff --git a/velero/templates/volumesnapshotlocation.yaml b/velero/templates/volumesnapshotlocation.yaml new file mode 100644 index 0000000..8319968 --- /dev/null +++ b/velero/templates/volumesnapshotlocation.yaml @@ -0,0 +1,41 @@ +{{- if .Values.snapshotsEnabled }} + +{{- if typeIs "[]interface {}" .Values.configuration.volumeSnapshotLocation }} +{{- range .Values.configuration.volumeSnapshotLocation }} +--- +apiVersion: velero.io/v1 +kind: VolumeSnapshotLocation +metadata: + name: {{ .name | default "default" }} + namespace: {{ $.Release.Namespace }} + {{- with .annotations }} + annotations: + {{- range $key, $value := . }} + {{- $key | nindent 4 }}: {{ $value | quote }} + {{- end }} + {{- end }} + labels: + app.kubernetes.io/name: {{ include "velero.name" $ }} + app.kubernetes.io/instance: {{ $.Release.Name }} + app.kubernetes.io/managed-by: {{ $.Release.Service }} + helm.sh/chart: {{ include "velero.chart" $ }} +spec: + {{- if not (empty .credential) }} + credential: + {{- with .credential.name }} + name: {{ . }} + {{- end }} + {{- with .credential.key }} + key: {{ . }} + {{- end }} + {{- end }} + provider: {{ .provider }} +{{- with .config }} + config: +{{- range $key, $value := . }} +{{- $key | nindent 4 }}: {{ $value | quote }} +{{- end }} +{{- end -}} +{{- end }} +{{- end }} +{{- end }} diff --git a/velero/values.schema.json b/velero/values.schema.json new file mode 100644 index 0000000..08e95f7 --- /dev/null +++ b/velero/values.schema.json @@ -0,0 +1,731 @@ +{ + "$schema": "http://json-schema.org/draft-07/schema#", + "title": "Schema for Velero helm chart", + "type": "object", + "properties": { + "namespace": { + "type": "object", + "properties": { + "labels": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [] + }, + "image": { + "type": "object", + "properties": { + "repository": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "pullPolicy": { + "type": "string" + }, + "imagePullSecrets": { + "type": "array", + "items": {} + } + }, + "required": [ + "repository", + "tag", + "pullPolicy" + ] + }, + "nameOverride": { + "type": "string" + }, + "fullnameOverride": { + "type": "string" + }, + "annotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "secretAnnotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "labels": { + "type": "object", + "properties": {}, + "required": [] + }, + "podAnnotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "podLabels": { + "type": "object", + "properties": {}, + "required": [] + }, + "resources": { + "type": "object", + "properties": {}, + "required": [] + }, + "upgradeJobResources": { + "type": "object", + "properties": {}, + "required": [] + }, + "upgradeCRDsJob": { + "type": "object", + "properties": { + "extraVolumes": { + "type": "array", + "items": {} + }, + "extraVolumeMounts": { + "type": "array", + "items": {} + }, + "extraEnvVars": { + "type": "array", + "items": {} + }, + "automountServiceAccountToken": { + "type": "boolean" + } + }, + "required": [ + "automountServiceAccountToken" + ] + }, + "dnsPolicy": { + "type": "string" + }, + "initContainers": { + "type": ["array", "null"], + "items": {} + }, + "podSecurityContext": { + "type": "object", + "properties": {}, + "required": [] + }, + "containerSecurityContext": { + "type": "object", + "properties": {}, + "required": [] + }, + "lifecycle": { + "type": "object", + "properties": {}, + "required": [] + }, + "priorityClassName": { + "type": "string" + }, + "runtimeClassName": { + "type": "string" + }, + "terminationGracePeriodSeconds": { + "type": "number" + }, + "livenessProbe": { + "type": "object", + "properties": {}, + "required": [] + }, + "readinessProbe": { + "type": "object", + "properties": {}, + "required": [] + }, + "tolerations": { + "type": "array", + "items": {} + }, + "affinity": { + "type": "object", + "properties": {}, + "required": [] + }, + "nodeSelector": { + "type": "object", + "properties": {}, + "required": [] + }, + "dnsConfig": { + "type": "object", + "properties": {}, + "required": [] + }, + "extraVolumes": { + "type": "array", + "items": {} + }, + "extraVolumeMounts": { + "type": "array", + "items": {} + }, + "extraObjects": { + "type": "array", + "items": {} + }, + "metrics": { + "type": "object", + "properties": { + "enabled": { + "type": "boolean" + }, + "scrapeInterval": { + "type": "string" + }, + "scrapeTimeout": { + "type": "string" + }, + "service": { + "type": "object", + "properties": { + "annotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "labels": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [] + }, + "podAnnotations": { + "type": "object", + "properties": { + "prometheus.io/scrape": { + "type": "string" + }, + "prometheus.io/port": { + "type": "string" + }, + "prometheus.io/path": { + "type": "string" + } + }, + "required": [] + }, + "serviceMonitor": { + "type": "object", + "properties": { + "autodetect": { + "type": "boolean" + }, + "enabled": { + "type": "boolean" + }, + "annotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "additionalLabels": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [ + "autodetect", + "enabled" + ] + }, + "nodeAgentPodMonitor": { + "type": "object", + "properties": { + "autodetect": { + "type": "boolean" + }, + "enabled": { + "type": "boolean" + }, + "annotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "additionalLabels": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [ + "autodetect", + "enabled" + ] + }, + "prometheusRule": { + "type": "object", + "properties": { + "autodetect": { + "type": "boolean" + }, + "enabled": { + "type": "boolean" + }, + "additionalLabels": { + "type": "object", + "properties": {}, + "required": [] + }, + "spec": { + "type": "array", + "items": {} + } + }, + "required": [ + "autodetect", + "enabled" + ] + } + }, + "required": [ + "enabled", + "scrapeInterval", + "scrapeTimeout", + "service", + "podAnnotations", + "serviceMonitor", + "nodeAgentPodMonitor", + "prometheusRule" + ] + }, + "kubectl": { + "type": "object", + "properties": { + "image": { + "type": "object", + "properties": { + "repository": { + "type": "string" + } + }, + "required": [ + "repository" + ] + }, + "containerSecurityContext": { + "type": "object", + "properties": {}, + "required": [] + }, + "resources": { + "type": "object", + "properties": {}, + "required": [] + }, + "annotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "labels": { + "type": "object", + "properties": {}, + "required": [] + }, + "extraVolumes": { + "type": "array", + "items": {} + }, + "extraVolumeMounts": { + "type": "array", + "items": {} + } + }, + "required": [ + "image" + ] + }, + "upgradeCRDs": { + "type": "boolean" + }, + "cleanUpCRDs": { + "type": "boolean" + }, + "configuration": { + "type": "object", + "properties": { + "backupStorageLocation": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": ["string", "null"] + }, + "provider": { + "type": ["string"] + }, + "bucket": { + "type": ["string"] + }, + "caCert": { + "type": ["string", "null"] + }, + "prefix": { + "type": ["string", "null"] + }, + "default": { + "type": ["boolean", "null"] + }, + "validationFrequency": { + "type": ["string", "null"] + }, + "accessMode": { + "type": ["string", "null"] + }, + "credential": { + "type": "object", + "properties": {}, + "required": [] + }, + "config": { + "type": "object", + "properties": {}, + "required": [] + }, + "annotations": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [ + "provider", + "bucket" + ] + } + }, + "volumeSnapshotLocation": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": ["string", "null"] + }, + "provider": { + "type": ["string"] + }, + "credential": { + "type": "object", + "properties": {}, + "required": [] + }, + "config": { + "type": "object", + "properties": {}, + "required": [] + }, + "annotations": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [ + "provider" + ] + } + }, + "repositoryMaintenanceJob": { + "type": "object", + "properties": { + "requests": { + "type": ["object", "null"], + "properties": { + "cpu": { + "type": "string" + }, + "memory": { + "type": "string" + } + }, + "required": [] + }, + "limits": { + "type": ["object", "null"], + "properties": { + "cpu": { + "type": "string" + }, + "memory": { + "type": "string" + } + }, + "required": [] + }, + "latestJobsCount": { + "type": "number" + } + }, + "required": [] + }, + "namespace": { + "type": ["string", "null"] + }, + "extraArgs": { + "type": "array", + "items": {} + }, + "extraEnvVars": { + "type": "array", + "items": {} + } + }, + "required": [] + }, + "rbac": { + "type": "object", + "properties": { + "create": { + "type": "boolean" + }, + "clusterAdministrator": { + "type": "boolean" + }, + "clusterAdministratorName": { + "type": "string" + } + }, + "required": [ + "create", + "clusterAdministrator", + "clusterAdministratorName" + ] + }, + "serviceAccount": { + "type": "object", + "properties": { + "server": { + "type": "object", + "properties": { + "create": { + "type": "boolean" + }, + "name": { + "type": ["string", "null"] + }, + "annotations": { + "type": ["object", "null"], + "properties": {}, + "required": [] + }, + "labels": { + "type": ["object", "null"], + "properties": {}, + "required": [] + }, + "imagePullSecrets": { + "type": "array", + "items": { + "type": "string" + } + }, + "automountServiceAccountToken": { + "type": "boolean" + } + }, + "required": [ + "create", + "automountServiceAccountToken" + ] + } + }, + "required": [ + "server" + ] + }, + "credentials": { + "type": "object", + "properties": { + "useSecret": { + "type": "boolean" + }, + "name": { + "type": ["string", "null"] + }, + "existingSecret": { + "type": ["string", "null"] + }, + "secretContents": { + "type": "object", + "properties": {}, + "required": [] + }, + "extraEnvVars": { + "type": "object", + "properties": {}, + "required": [] + }, + "extraSecretRef": { + "type": "string" + } + }, + "required": [] + }, + "backupsEnabled": { + "type": "boolean" + }, + "snapshotsEnabled": { + "type": "boolean" + }, + "deployNodeAgent": { + "type": "boolean" + }, + "nodeAgent": { + "type": "object", + "properties": { + "podVolumePath": { + "type": "string" + }, + "pluginVolumePath": { + "type": "string" + }, + "priorityClassName": { + "type": "string" + }, + "runtimeClassName": { + "type": "string" + }, + "resources": { + "type": "object", + "properties": {}, + "required": [] + }, + "tolerations": { + "type": "array", + "items": {} + }, + "annotations": { + "type": "object", + "properties": {}, + "required": [] + }, + "labels": { + "type": "object", + "properties": {}, + "required": [] + }, + "podLabels": { + "type": "object", + "properties": {}, + "required": [] + }, + "useScratchEmptyDir": { + "type": "boolean" + }, + "extraVolumes": { + "type": "array", + "items": {} + }, + "extraVolumeMounts": { + "type": "array", + "items": {} + }, + "extraEnvVars": { + "type": "array", + "items": {} + }, + "extraArgs": { + "type": "array", + "items": {} + }, + "dnsPolicy": { + "type": "string" + }, + "podSecurityContext": { + "type": "object", + "properties": {}, + "required": [] + }, + "containerSecurityContext": { + "type": "object", + "properties": {}, + "required": [] + }, + "lifecycle": { + "type": "object", + "properties": {}, + "required": [] + }, + "nodeSelector": { + "type": "object", + "properties": {}, + "required": [] + }, + "affinity": { + "type": "object", + "properties": {}, + "required": [] + }, + "dnsConfig": { + "type": "object", + "properties": {}, + "required": [] + }, + "updateStrategy": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [ + "podVolumePath", + "dnsPolicy" + ] + }, + "schedules": { + "type": "object", + "properties": {}, + "required": [] + }, + "configMaps": { + "type": "object", + "properties": {}, + "required": [] + } + }, + "required": [ + "image", + "upgradeCRDsJob", + "dnsPolicy", + "metrics", + "kubectl", + "configuration", + "rbac", + "serviceAccount", + "credentials", + "configMaps" + ], + "dependencies": { + "deployNodeAgent": { + "oneOf": [ + { + "properties": { + "deployNodeAgent": { "const": false } + } + }, + { + "properties": { + "deployNodeAgent": { "const": true } + }, + "required": ["nodeAgent"] + } + ] + } + } +} \ No newline at end of file diff --git a/velero/values.yaml b/velero/values.yaml new file mode 100644 index 0000000..b1663df --- /dev/null +++ b/velero/values.yaml @@ -0,0 +1,747 @@ +## +## Configuration settings related to Velero installation namespace +## + +# Labels settings in namespace +namespace: + labels: {} +# Enforce Pod Security Standards with Namespace Labels +# https://kubernetes.io/docs/tasks/configure-pod-container/enforce-standards-namespace-labels/ +# - key: pod-security.kubernetes.io/enforce +# value: privileged +# - key: pod-security.kubernetes.io/enforce-version +# value: latest +# - key: pod-security.kubernetes.io/audit +# value: privileged +# - key: pod-security.kubernetes.io/audit-version +# value: latest +# - key: pod-security.kubernetes.io/warn +# value: privileged +# - key: pod-security.kubernetes.io/warn-version +# value: latest + +## +## End of namespace-related settings. +## + + +## +## Configuration settings that directly affect the Velero deployment YAML. +## + +# Details of the container image to use in the Velero deployment & daemonset (if +# enabling node-agent). Required. +image: + repository: velero/velero + tag: v1.16.1 + # Digest value example: sha256:d238835e151cec91c6a811fe3a89a66d3231d9f64d09e5f3c49552672d271f38. + # If used, it will take precedence over the image.tag. + # digest: + pullPolicy: IfNotPresent + # One or more secrets to be used when pulling images + imagePullSecrets: [] + # - registrySecretName + +nameOverride: "" +fullnameOverride: "" + +# Annotations to add to the Velero deployment's. Optional. +# +# If you are using reloader use the following annotation with your VELERO_SECRET_NAME +annotations: {} +# secret.reloader.stakater.com/reload: "" + +# Annotations to add to secret +secretAnnotations: {} + +# Labels to add to the Velero deployment's. Optional. +labels: {} + +# Annotations to add to the Velero deployment's pod template. Optional. +# +# If using kube2iam or kiam, use the following annotation with your AWS_ACCOUNT_ID +# and VELERO_ROLE_NAME filled in: +podAnnotations: + backup.velero.io/backup-volumes: "etcd-backup-pvc" + # iam.amazonaws.com/role: "arn:aws:iam:::role/" + +# Additional pod labels for Velero deployment's template. Optional +# ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ +podLabels: {} + +# Number of old history to retain to allow rollback (If not set, default Kubernetes value is set to 10) +# revisionHistoryLimit: 1 + +# Resource requests/limits to specify for the Velero deployment. +# https://velero.io/docs/v1.6/customize-installation/#customize-resource-requests-and-limits +resources: {} + # requests: + # cpu: 500m + # memory: 128Mi + # limits: + # cpu: 1000m + # memory: 512Mi + +# Configure hostAliases for Velero deployment. Optional +# For more information, check: https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/ +hostAliases: [] + # - ip: "127.0.0.1" + # hostnames: + # - "foo.local" + # - "bar.local" + +# Resource requests/limits to specify for the upgradeCRDs job pod. Need to be adjusted by user accordingly. +upgradeJobResources: {} +# requests: +# cpu: 50m +# memory: 128Mi +# limits: +# cpu: 100m +# memory: 256Mi +upgradeCRDsJob: + # Extra volumes for the Upgrade CRDs Job. Optional. + extraVolumes: [] + # Extra volumeMounts for the Upgrade CRDs Job. Optional. + extraVolumeMounts: [] + # Additional values to be used as environment variables. Optional. + extraEnvVars: [] + # Simple value + # - name: SIMPLE_VAR + # value: "simple-value" + + # FieldRef example + # - name: MY_POD_LABEL + # valueFrom: + # fieldRef: + # fieldPath: metadata.labels['my_label'] + + # Configure if API credential for Service Account is automounted. + automountServiceAccountToken: true + # Configure the shell cmd in case you are using custom image + # shellCmd: /tmp/sh + # updateCmd: /velero install --crds-only --dry-run -o yaml | /tmp/kubectl apply -f - + +# Configure the dnsPolicy of the Velero deployment +# See: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy +dnsPolicy: ClusterFirst + +# Init containers to add to the Velero deployment's pod spec. At least one plugin provider image is required. +# If the value is a string then it is evaluated as a template. +initContainers: + # - name: velero-plugin-for-aws + # image: velero/velero-plugin-for-aws:v1.12.1 + # imagePullPolicy: IfNotPresent + # volumeMounts: + # - mountPath: /target + # name: plugins + - name: velero-plugin-for-aws + image: velero/velero-plugin-for-aws:v1.12.1 + imagePullPolicy: IfNotPresent + volumeMounts: + - mountPath: /target + name: plugins +# SecurityContext to use for the Velero deployment. Optional. +# Set fsGroup for `AWS IAM Roles for Service Accounts` +# see more informations at: https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html +podSecurityContext: {} + # fsGroup: 1337 + +# Container Level Security Context for the 'velero' container of the Velero deployment. Optional. +# See: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container +containerSecurityContext: {} + # allowPrivilegeEscalation: false + # capabilities: + # drop: ["ALL"] + # add: [] + # readOnlyRootFilesystem: true + +# Container Lifecycle Hooks to use for the Velero deployment. Optional. +lifecycle: {} + +# Pod priority class name to use for the Velero deployment. Optional. +priorityClassName: "" + +# Pod runtime class name to use for the Velero deployment. Optional. +runtimeClassName: "" + +# The number of seconds to allow for graceful termination of the pod. Optional. +terminationGracePeriodSeconds: 3600 + +# Liveness probe of the pod +livenessProbe: + httpGet: + path: /metrics + port: http-monitoring + scheme: HTTP + initialDelaySeconds: 10 + periodSeconds: 30 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 5 + +# Readiness probe of the pod +readinessProbe: + httpGet: + path: /metrics + port: http-monitoring + scheme: HTTP + initialDelaySeconds: 10 + periodSeconds: 30 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 5 + +# Tolerations to use for the Velero deployment. Optional. +tolerations: [] + +# Affinity to use for the Velero deployment. Optional. +affinity: {} + +# Node selector to use for the Velero deployment. Optional. +nodeSelector: {} + +# DNS configuration to use for the Velero deployment. Optional. +dnsConfig: {} + +# Extra volumes for the Velero deployment. Optional. +extraVolumes: + - name: etcd-backup-script + configMap: + name: velero-etcd-backup-script + + - name: etcd-tls + secret: + secretName: etcd-tls + + - name: etcd-backup-pvc + persistentVolumeClaim: + claimName: velero-etcd-backup-pvc + +# Extra volumeMounts for the Velero deployment. Optional. +extraVolumeMounts: + - name: etcd-backup-script + mountPath: /scripts + readOnly: true + + - name: etcd-tls + mountPath: /etc/kubernetes/pki/etcd + readOnly: true + + - name: etcd-backup-pvc + mountPath: /var/lib/velero/etcd-backup + +extraContainers: + - name: etcdctl + image: bitnami/etcd:3.5 + command: ["/bin/sh", "-c", "sleep infinity"] + volumeMounts: + - name: etcd-backup-script + mountPath: /scripts + - name: etcd-tls + mountPath: /etc/kubernetes/pki/etcd + - name: etcd-backup-pvc + mountPath: /var/lib/velero/etcd-backup + +# Extra K8s manifests to deploy +extraObjects: [] + # - apiVersion: secrets-store.csi.x-k8s.io/v1 + # kind: SecretProviderClass + # metadata: + # name: velero-secrets-store + # spec: + # provider: aws + # parameters: + # objects: | + # - objectName: "velero" + # objectType: "secretsmanager" + # jmesPath: + # - path: "access_key" + # objectAlias: "access_key" + # - path: "secret_key" + # objectAlias: "secret_key" + # secretObjects: + # - data: + # - key: access_key + # objectName: client-id + # - key: client-secret + # objectName: client-secret + # secretName: velero-secrets-store + # type: Opaque + +# Settings for Velero's prometheus metrics. Enabled by default. +metrics: + enabled: true + scrapeInterval: 30s + scrapeTimeout: 10s + + # service metdata if metrics are enabled + service: + annotations: {} + type: ClusterIP + labels: {} + nodePort: null + + # External/Internal traffic policy setting (Cluster, Local) + # https://kubernetes.io/docs/reference/networking/virtual-ips/#traffic-policies + externalTrafficPolicy: "" + internalTrafficPolicy: "" + + # Pod annotations for Prometheus + podAnnotations: + prometheus.io/scrape: "true" + prometheus.io/port: "8085" + prometheus.io/path: "/metrics" + + serviceMonitor: + autodetect: true + enabled: false + annotations: {} + additionalLabels: {} + + # metrics.serviceMonitor.metricRelabelings Specify Metric Relabelings to add to the scrape endpoint + # ref: https://github.com/coreos/prometheus-operator/blob/master/Documentation/api.md#relabelconfig + # metricRelabelings: [] + # metrics.serviceMonitor.relabelings [array] Prometheus relabeling rules + # relabelings: [] + # ServiceMonitor namespace. Default to Velero namespace. + # namespace: + # ServiceMonitor connection scheme. Defaults to HTTP. + # scheme: "" + # ServiceMonitor connection tlsConfig. Defaults to {}. + # tlsConfig: {} + nodeAgentPodMonitor: + autodetect: true + enabled: false + annotations: {} + additionalLabels: {} + # ServiceMonitor namespace. Default to Velero namespace. + # namespace: + # ServiceMonitor connection scheme. Defaults to HTTP. + # scheme: "" + # ServiceMonitor connection tlsConfig. Defaults to {}. + # tlsConfig: {} + + prometheusRule: + autodetect: true + enabled: false + # Additional labels to add to deployed PrometheusRule + additionalLabels: {} + # PrometheusRule namespace. Defaults to Velero namespace. + # namespace: "" + # Rules to be deployed + spec: [] + # - alert: VeleroBackupPartialFailures + # annotations: + # message: Velero backup {{ $labels.schedule }} has {{ $value | humanizePercentage }} partialy failed backups. + # expr: |- + # velero_backup_partial_failure_total{schedule!=""} / velero_backup_attempt_total{schedule!=""} > 0.25 + # for: 15m + # labels: + # severity: warning + # - alert: VeleroBackupFailures + # annotations: + # message: Velero backup {{ $labels.schedule }} has {{ $value | humanizePercentage }} failed backups. + # expr: |- + # velero_backup_failure_total{schedule!=""} / velero_backup_attempt_total{schedule!=""} > 0.25 + # for: 15m + # labels: + # severity: warning + +kubectl: + image: + repository: docker.io/bitnami/kubectl + # Digest value example: sha256:d238835e151cec91c6a811fe3a89a66d3231d9f64d09e5f3c49552672d271f38. + # If used, it will take precedence over the kubectl.image.tag. + # digest: + # kubectl image tag. If used, it will take precedence over the cluster Kubernetes version. + # tag: 1.16.15 + # Container Level Security Context for the 'kubectl' container of the crd jobs. Optional. + # See: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container + containerSecurityContext: {} + # Resource requests/limits to specify for the upgrade/cleanup job. Optional + resources: {} + # Annotations to set for the upgrade/cleanup job. Optional. + annotations: {} + # Labels to set for the upgrade/cleanup job. Optional. + labels: {} + # Extra volumes for the upgrade/cleanup job. Optional. + extraVolumes: [] + # Extra volumeMounts for the upgrade/cleanup job.. Optional. + extraVolumeMounts: [] + +# This job upgrades the CRDs. +upgradeCRDs: true + +# This job is meant primarily for cleaning up CRDs on CI systems. +# Using this on production systems, especially those that have multiple releases of Velero, will be destructive. +cleanUpCRDs: false + +## +## End of deployment-related settings. +## + + +## +## Parameters for the `default` BackupStorageLocation and VolumeSnapshotLocation, +## and additional server settings. +## +configuration: + backupStorageLocation: + - name: default + provider: aws + bucket: velero-backups + config: + region: us-east-1 + s3Url: https://store.stage.co-work.local:9000 + insecureSkipTLSVerify: true + s3ForcePathStyle: "true" + default: true + caCert: "" + prefix: "" + validationFrequency: "" + accessMode: ReadWrite + credential: + name: velero-static-s3-secret + key: cloud + annotations: {} + + # Parameters for the VolumeSnapshotLocation(s). Configure multiple by adding other element(s) to the volumeSnapshotLocation slice. + # See https://velero.io/docs/v1.6/api-types/volumesnapshotlocation/ + volumeSnapshotLocation: + # name is the name of the volume snapshot location where snapshots are being taken. If a name is not provided, + # a volume snapshot location will be created with the name "default". Optional. + - name: default + # provider is the name for the volume snapshot provider. + provider: aws + credential: + # name of the secret used by this volumeSnapshotLocation. + name: velero-static-s3-secret + # name of key that contains the secret data to be used. + key: cloud + # Additional provider-specific configuration. See link above + # for details of required/optional fields for your provider. + config: + region: us-east-1 + # region: + # apiTimeout: + # resourceGroup: + # The ID of the subscription where volume snapshots should be stored, if different from the cluster’s subscription. If specified, also requires `configuration.volumeSnapshotLocation.config.resourceGroup`to be set. (Azure only) + # subscriptionId: + # incremental: + # snapshotLocation: + # project: + + # annotations allows adding arbitrary annotations to this VolumeSnapshotLocation resource. Optional. + annotations: {} + + # These are server-level settings passed as CLI flags to the `velero server` command. Velero + # uses default values if they're not passed in, so they only need to be explicitly specified + # here if using a non-default value. The `velero server` default values are shown in the + # comments below. + # -------------------- + # `velero server` default: kopia + uploaderType: + # `velero server` default: 1m + backupSyncPeriod: + # `velero server` default: 4h + fsBackupTimeout: + # `velero server` default: 30 + clientBurst: + # `velero server` default: 500 + clientPageSize: + # `velero server` default: 20.0 + clientQPS: + # Name of the default backup storage location. Default: default + defaultBackupStorageLocation: + # The default duration any single item operation can take before timing out, especially important for large volume schedules. Default 4h + defaultItemOperationTimeout: + # How long to wait by default before backups can be garbage collected. Default: 72h + defaultBackupTTL: + # Name of the default volume snapshot location. + defaultVolumeSnapshotLocations: + # `velero server` default: empty + disableControllers: + # `velero server` default: false + disableInformerCache: false + # `velero server` default: 1h + garbageCollectionFrequency: + # `velero server` default: 1 + itemBlockWorkerCount: + # Set log-format for Velero pod. Default: text. Other option: json. + logFormat: + # Set log-level for Velero pod. Default: info. Other options: debug, warning, error, fatal, panic. + logLevel: + # The address to expose prometheus metrics. Default: :8085 + metricsAddress: + # Directory containing Velero plugins. Default: /plugins + pluginDir: + # The address to expose the pprof profiler. Default: localhost:6060 + profilerAddress: + # `velero server` default: false + restoreOnlyMode: + # `velero server` default: customresourcedefinitions,namespaces,storageclasses,volumesnapshotclass.snapshot.storage.k8s.io,volumesnapshotcontents.snapshot.storage.k8s.io,volumesnapshots.snapshot.storage.k8s.io,persistentvolumes,persistentvolumeclaims,secrets,configmaps,serviceaccounts,limitranges,pods,replicasets.apps,clusterclasses.cluster.x-k8s.io,clusters.cluster.x-k8s.io,clusterresourcesets.addons.cluster.x-k8s.io + restoreResourcePriorities: + # `velero server` default: 1m + storeValidationFrequency: + # How long to wait on persistent volumes and namespaces to terminate during a restore before timing out. Default: 10m + terminatingResourceTimeout: + # Bool flag to configure Velero server to move data by default for all snapshots supporting data movement. Default: false + defaultSnapshotMoveData: + # Comma separated list of velero feature flags. default: empty + # features: EnableCSI + features: + # Configures the timeout for provisioning the volume created from the CSI snapshot. Default: 30m + dataMoverPrepareTimeout: + # Resource requests/limits to specify for the repository-maintenance job. Optional. + # https://velero.io/docs/v1.14/repository-maintenance/#resource-limitation + repositoryMaintenanceJob: + requests: + # cpu: 500m + # memory: 512Mi + limits: + # cpu: 1000m + # memory: 1024Mi + # Number of latest maintenance jobs to keep for each repository + latestJobsCount: 3 + # `velero server` default: velero + namespace: + # additional command-line arguments that will be passed to the `velero server` + # e.g.: extraArgs: ["--foo=bar"] + extraArgs: [] + + # Additional values to be used as environment variables. Optional. + extraEnvVars: [] + # Simple value + # - name: SIMPLE_VAR + # value: "simple-value" + + # FieldRef example + # - name: MY_POD_LABEL + # valueFrom: + # fieldRef: + # fieldPath: metadata.labels['my_label'] + + # Set true for backup all pod volumes without having to apply annotation on the pod when used file system backup Default: false. + defaultVolumesToFsBackup: + + # How often repository maintain is run for repositories by default. + defaultRepoMaintainFrequency: + +## +## End of backup/snapshot location settings. +## + + +## +## Settings for additional Velero resources. +## + +rbac: + # Whether to create the Velero role and role binding to give all permissions to the namespace to Velero. + create: true + # Whether to create the cluster role binding to give administrator permissions to Velero + clusterAdministrator: true + # Name of the ClusterRole. + clusterAdministratorName: cluster-admin + +# Information about the Kubernetes service account Velero uses. +serviceAccount: + server: + create: true + name: velero + annotations: + labels: + imagePullSecrets: [] + # - registrySecretName + # Configure if API credential for Service Account is automounted. + automountServiceAccountToken: true + +# Info about the secret to be used by the Velero deployment, which +# should contain credentials for the cloud provider IAM account you've +# set up for Velero. +credentials: + # Whether a secret should be used. Set to false if, for examples: + # - using kube2iam or kiam to provide AWS IAM credentials instead of providing the key file. (AWS only) + # - using workload identity instead of providing the key file. (Azure/GCP only) + useSecret: true + # Name of the secret to create if `useSecret` is true and `existingSecret` is empty + name: "" + # Name of a pre-existing secret (if any) in the Velero namespace + # that should be used to get IAM account credentials. Optional. + existingSecret: velero-static-s3-secret + # Data to be stored in the Velero secret, if `useSecret` is true and `existingSecret` is empty. + # As of the current Velero release, Velero only uses one secret key/value at a time. + # The key must be named `cloud`, and the value corresponds to the entire content of your IAM credentials file. + # Note that the format will be different for different providers, please check their documentation. + # Here is a list of documentation for plugins maintained by the Velero team: + # [AWS] https://github.com/vmware-tanzu/velero-plugin-for-aws/blob/main/README.md + # [GCP] https://github.com/vmware-tanzu/velero-plugin-for-gcp/blob/main/README.md + # [Azure] https://github.com/vmware-tanzu/velero-plugin-for-microsoft-azure/blob/main/README.md + secretContents: {} + # cloud: | + # [default] + # aws_access_key_id= + # aws_secret_access_key= + # additional key/value pairs to be used as environment variables such as "DIGITALOCEAN_TOKEN: ". Values will be stored in the secret. + extraEnvVars: {} + # Name of a pre-existing secret (if any) in the Velero namespace + # that will be used to load environment variables into velero and node-agent. + # Secret should be in format - https://kubernetes.io/docs/concepts/configuration/secret/#use-case-as-container-environment-variables + extraSecretRef: "" + +# Whether to create backupstoragelocation crd, if false => do not create a default backup location +backupsEnabled: true +# Whether to create volumesnapshotlocation crd, if false => disable snapshot feature +snapshotsEnabled: true + +# Whether to deploy the node-agent daemonset. +deployNodeAgent: true + +nodeAgent: + podVolumePath: /var/lib/kubelet/pods + pluginVolumePath: /var/lib/kubelet/plugins + # Pod priority class name to use for the node-agent daemonset. Optional. + priorityClassName: "" + # Pod runtime class name to use for the node-agent daemonset. Optional. + runtimeClassName: "" + # Resource requests/limits to specify for the node-agent daemonset deployment. Optional. + # https://velero.io/docs/v1.6/customize-installation/#customize-resource-requests-and-limits + resources: + requests: + cpu: 250m + memory: 512Mi + limits: + cpu: 500m + memory: 1024Mi + + # Tolerations to use for the node-agent daemonset. Optional. + tolerations: [] + + # Annotations to set for the node-agent daemonset. Optional. + annotations: {} + + # labels to set for the node-agent daemonset. Optional. + labels: {} + + # Additional pod labels for the node-agent daemonset. Optional + # ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ + podLabels: {} + + # will map /scratch to emptyDir. Set to false and specify your own volume + # via extraVolumes and extraVolumeMounts that maps to /scratch + # if you don't want to use emptyDir. + useScratchEmptyDir: true + + # Extra volumes for the node-agent daemonset. Optional. + extraVolumes: [] + + # Extra volumeMounts for the node-agent daemonset. Optional. + extraVolumeMounts: [] + + # Additional values to be used as environment variables for node-agent daemonset. Optional. + extraEnvVars: [] + # Simple key/value + # - name: SIMPLE_VAR + # value: "simple-value" + + # FieldRef example + # - name: MY_POD_LABEL + # valueFrom: + # fieldRef: + # fieldPath: metadata.labels['my_label'] + + # Additional command-line arguments that will be passed to the node-agent. Optional. + # e.g.: extraArgs: ["--foo=bar"] + extraArgs: [] + + # Configure the dnsPolicy of the node-agent daemonset + # See: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy + dnsPolicy: ClusterFirst + + # Configure hostAliases for node-agent daemonset. Optional + # For more information, check: https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/ + hostAliases: [] + # - ip: "127.0.0.1" + # hostnames: + # - "foo.local" + # - "bar.local" + + # SecurityContext to use for the Velero deployment. Optional. + # Set fsGroup for `AWS IAM Roles for Service Accounts` + # see more informations at: https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html + podSecurityContext: + runAsUser: 0 + # fsGroup: 1337 + + # Container Level Security Context for the 'node-agent' container of the node-agent daemonset. Optional. + # See: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container + containerSecurityContext: {} + + # Container Lifecycle Hooks to use for the node-agent daemonset. Optional. + lifecycle: {} + + # Node selector to use for the node-agent daemonset. Optional. + nodeSelector: {} + + # Affinity to use with node-agent daemonset. Optional. + affinity: {} + + # DNS configuration to use for the node-agent daemonset. Optional. + dnsConfig: {} + + # Update strategy to use for the node-agent daemonset. Optional. + updateStrategy: {} + +# Backup schedules to create. +# Eg: +# schedules: +# mybackup: +# disabled: false +# labels: +# myenv: foo +# annotations: +# myenv: foo +# schedule: "0 0 * * *" +# useOwnerReferencesInBackup: false +# paused: false +# skipImmediately: false +# template: +# ttl: "240h" +# storageLocation: default +# includedNamespaces: +# - foo +# # See: https://velero.io/docs/v1.14/resource-filtering/#excludes +# excludedNamespaceScopedResources: +# - persistentVolumeClaims +# excludedClusterScopedResources: +# - persistentVolumes +schedules: {} + +# Velero ConfigMaps. +# Eg: +# configMaps: + # See: https://velero.io/docs/v1.11/file-system-backup/ +# fs-restore-action-config: +# labels: +# velero.io/plugin-config: "" +# velero.io/pod-volume-restore: RestoreItemAction +# data: +# image: velero/velero-restore-helper:v1.10.2 +# cpuRequest: 200m +# memRequest: 128Mi +# cpuLimit: 200m +# memLimit: 128Mi +# secCtx: | +# capabilities: +# drop: +# - ALL +# add: [] +# allowPrivilegeEscalation: false +# readOnlyRootFilesystem: true +# runAsUser: 1001 +# runAsGroup: 999 +configMaps: {} + +## +## End of additional Velero resource settings. +##