Initial commit - fresh start without history
This commit is contained in:
commit
f09410e17e
6
.gitignore
vendored
Normal file
6
.gitignore
vendored
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
# macOS
|
||||||
|
.DS_Store
|
||||||
|
**/.DS_Store
|
||||||
|
dockerconfig.json
|
||||||
|
tls.crt
|
||||||
|
tls.key
|
||||||
93
README.md
Normal file
93
README.md
Normal file
@ -0,0 +1,93 @@
|
|||||||
|
# cw-infra-apps
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
## Getting started
|
||||||
|
|
||||||
|
To make it easy for you to get started with GitLab, here's a list of recommended next steps.
|
||||||
|
|
||||||
|
Already a pro? Just edit this README.md and make it your own. Want to make it easy? [Use the template at the bottom](#editing-this-readme)!
|
||||||
|
|
||||||
|
## Add your files
|
||||||
|
|
||||||
|
- [ ] [Create](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#create-a-file) or [upload](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#upload-a-file) files
|
||||||
|
- [ ] [Add files using the command line](https://docs.gitlab.com/topics/git/add_files/#add-files-to-a-git-repository) or push an existing Git repository with the following command:
|
||||||
|
|
||||||
|
```
|
||||||
|
cd existing_repo
|
||||||
|
git remote add origin https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
git branch -M main
|
||||||
|
git push -uf origin main
|
||||||
|
```
|
||||||
|
|
||||||
|
## Integrate with your tools
|
||||||
|
|
||||||
|
- [ ] [Set up project integrations](https://git.co-work.ru/cw-devops/cw-infra-apps/-/settings/integrations)
|
||||||
|
|
||||||
|
## Collaborate with your team
|
||||||
|
|
||||||
|
- [ ] [Invite team members and collaborators](https://docs.gitlab.com/ee/user/project/members/)
|
||||||
|
- [ ] [Create a new merge request](https://docs.gitlab.com/ee/user/project/merge_requests/creating_merge_requests.html)
|
||||||
|
- [ ] [Automatically close issues from merge requests](https://docs.gitlab.com/ee/user/project/issues/managing_issues.html#closing-issues-automatically)
|
||||||
|
- [ ] [Enable merge request approvals](https://docs.gitlab.com/ee/user/project/merge_requests/approvals/)
|
||||||
|
- [ ] [Set auto-merge](https://docs.gitlab.com/user/project/merge_requests/auto_merge/)
|
||||||
|
|
||||||
|
## Test and Deploy
|
||||||
|
|
||||||
|
Use the built-in continuous integration in GitLab.
|
||||||
|
|
||||||
|
- [ ] [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
|
||||||
|
- [ ] [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
|
||||||
|
- [ ] [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
|
||||||
|
- [ ] [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
|
||||||
|
- [ ] [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
|
||||||
|
|
||||||
|
***
|
||||||
|
|
||||||
|
# Editing this README
|
||||||
|
|
||||||
|
When you're ready to make this README your own, just edit this file and use the handy template below (or feel free to structure it however you want - this is just a starting point!). Thanks to [makeareadme.com](https://www.makeareadme.com/) for this template.
|
||||||
|
|
||||||
|
## Suggestions for a good README
|
||||||
|
|
||||||
|
Every project is different, so consider which of these sections apply to yours. The sections used in the template are suggestions for most open source projects. Also keep in mind that while a README can be too long and detailed, too long is better than too short. If you think your README is too long, consider utilizing another form of documentation rather than cutting out information.
|
||||||
|
|
||||||
|
## Name
|
||||||
|
Choose a self-explaining name for your project.
|
||||||
|
|
||||||
|
## Description
|
||||||
|
Let people know what your project can do specifically. Provide context and add a link to any reference visitors might be unfamiliar with. A list of Features or a Background subsection can also be added here. If there are alternatives to your project, this is a good place to list differentiating factors.
|
||||||
|
|
||||||
|
## Badges
|
||||||
|
On some READMEs, you may see small images that convey metadata, such as whether or not all the tests are passing for the project. You can use Shields to add some to your README. Many services also have instructions for adding a badge.
|
||||||
|
|
||||||
|
## Visuals
|
||||||
|
Depending on what you are making, it can be a good idea to include screenshots or even a video (you'll frequently see GIFs rather than actual videos). Tools like ttygif can help, but check out Asciinema for a more sophisticated method.
|
||||||
|
|
||||||
|
## Installation
|
||||||
|
Within a particular ecosystem, there may be a common way of installing things, such as using Yarn, NuGet, or Homebrew. However, consider the possibility that whoever is reading your README is a novice and would like more guidance. Listing specific steps helps remove ambiguity and gets people to using your project as quickly as possible. If it only runs in a specific context like a particular programming language version or operating system or has dependencies that have to be installed manually, also add a Requirements subsection.
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
Use examples liberally, and show the expected output if you can. It's helpful to have inline the smallest example of usage that you can demonstrate, while providing links to more sophisticated examples if they are too long to reasonably include in the README.
|
||||||
|
|
||||||
|
## Support
|
||||||
|
Tell people where they can go to for help. It can be any combination of an issue tracker, a chat room, an email address, etc.
|
||||||
|
|
||||||
|
## Roadmap
|
||||||
|
If you have ideas for releases in the future, it is a good idea to list them in the README.
|
||||||
|
|
||||||
|
## Contributing
|
||||||
|
State if you are open to contributions and what your requirements are for accepting them.
|
||||||
|
|
||||||
|
For people who want to make changes to your project, it's helpful to have some documentation on how to get started. Perhaps there is a script that they should run or some environment variables that they need to set. Make these steps explicit. These instructions could also be useful to your future self.
|
||||||
|
|
||||||
|
You can also document commands to lint the code or run tests. These steps help to ensure high code quality and reduce the likelihood that the changes inadvertently break something. Having instructions for running tests is especially helpful if it requires external setup, such as starting a Selenium server for testing in a browser.
|
||||||
|
|
||||||
|
## Authors and acknowledgment
|
||||||
|
Show your appreciation to those who have contributed to the project.
|
||||||
|
|
||||||
|
## License
|
||||||
|
For open source projects, say how it is licensed.
|
||||||
|
|
||||||
|
## Project status
|
||||||
|
If you have run out of energy or time for your project, put a note at the top of the README saying that development has slowed down or stopped completely. Someone may choose to fork your project or volunteer to step in as a maintainer or owner, allowing your project to keep going. You can also make an explicit request for maintainers.
|
||||||
18
argo-infra-apps/backend-apps.yaml
Normal file
18
argo-infra-apps/backend-apps.yaml
Normal file
@ -0,0 +1,18 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: backend-app
|
||||||
|
namespace: argocd
|
||||||
|
spec:
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
path: charts/backend
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
namespace: client3
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
265
argo-infra-apps/cassandra.yaml
Normal file
265
argo-infra-apps/cassandra.yaml
Normal file
File diff suppressed because one or more lines are too long
258
argo-infra-apps/elasticsearch.yaml
Normal file
258
argo-infra-apps/elasticsearch.yaml
Normal file
@ -0,0 +1,258 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: "2025-04-22T07:01:17Z"
|
||||||
|
generation: 166
|
||||||
|
name: elasticsearch
|
||||||
|
namespace: argocd
|
||||||
|
resourceVersion: "9726027"
|
||||||
|
uid: 928fb09c-938a-4ed5-9f05-5f8702d14a5e
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
syncPolicy:
|
||||||
|
automated: {}
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
status:
|
||||||
|
controllerNamespace: argocd
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
history:
|
||||||
|
- deployStartedAt: "2025-04-22T09:21:48Z"
|
||||||
|
deployedAt: "2025-04-22T09:21:48Z"
|
||||||
|
id: 2
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 3bb4328927c2b211878533c8928b9aa50d3cb545
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:22:40Z"
|
||||||
|
deployedAt: "2025-04-22T09:22:41Z"
|
||||||
|
id: 3
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 3bb4328927c2b211878533c8928b9aa50d3cb545
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:23:22Z"
|
||||||
|
deployedAt: "2025-04-22T09:23:23Z"
|
||||||
|
id: 4
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 3bb4328927c2b211878533c8928b9aa50d3cb545
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:24:25Z"
|
||||||
|
deployedAt: "2025-04-22T09:24:28Z"
|
||||||
|
id: 5
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 70dfc9595b1a8138455d9225facc018518da5e8a
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:24:28Z"
|
||||||
|
deployedAt: "2025-04-22T09:24:29Z"
|
||||||
|
id: 6
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 3bb4328927c2b211878533c8928b9aa50d3cb545
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:26:23Z"
|
||||||
|
deployedAt: "2025-04-22T09:26:24Z"
|
||||||
|
id: 7
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 411b0b9894242dca75f4ee170a81ceef4e635b0a
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:26:25Z"
|
||||||
|
deployedAt: "2025-04-22T09:26:25Z"
|
||||||
|
id: 8
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 70dfc9595b1a8138455d9225facc018518da5e8a
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:27:24Z"
|
||||||
|
deployedAt: "2025-04-22T09:27:25Z"
|
||||||
|
id: 9
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 411b0b9894242dca75f4ee170a81ceef4e635b0a
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:27:25Z"
|
||||||
|
deployedAt: "2025-04-22T09:27:25Z"
|
||||||
|
id: 10
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 70dfc9595b1a8138455d9225facc018518da5e8a
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
- deployStartedAt: "2025-04-22T09:30:48Z"
|
||||||
|
deployedAt: "2025-04-22T09:30:48Z"
|
||||||
|
id: 11
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 411b0b9894242dca75f4ee170a81ceef4e635b0a
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
operationState:
|
||||||
|
finishedAt: "2025-04-22T09:30:48Z"
|
||||||
|
message: successfully synced (all tasks run)
|
||||||
|
operation:
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
retry:
|
||||||
|
limit: 5
|
||||||
|
sync:
|
||||||
|
revision: 411b0b9894242dca75f4ee170a81ceef4e635b0a
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
phase: Succeeded
|
||||||
|
startedAt: "2025-04-22T09:30:48Z"
|
||||||
|
syncResult:
|
||||||
|
resources:
|
||||||
|
- group: policy
|
||||||
|
hookPhase: Running
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
message: poddisruptionbudget.policy/elasticsearch-master-pdb configured
|
||||||
|
name: elasticsearch-master-pdb
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Secret
|
||||||
|
message: secret/elasticsearch-master-certs configured
|
||||||
|
name: elasticsearch-master-certs
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Secret
|
||||||
|
message: secret/elasticsearch-master-credentials configured
|
||||||
|
name: elasticsearch-master-credentials
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: service/elasticsearch-master-headless unchanged
|
||||||
|
name: elasticsearch-master-headless
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: service/elasticsearch-master configured
|
||||||
|
name: elasticsearch-master
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
hookPhase: Running
|
||||||
|
kind: StatefulSet
|
||||||
|
message: statefulset.apps/elasticsearch-master configured
|
||||||
|
name: elasticsearch-master
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
revision: 411b0b9894242dca75f4ee170a81ceef4e635b0a
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
reconciledAt: "2025-04-22T09:36:48Z"
|
||||||
|
resources:
|
||||||
|
- kind: Secret
|
||||||
|
name: elasticsearch-master-certs
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: Secret
|
||||||
|
name: elasticsearch-master-credentials
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: elasticsearch-master
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: elasticsearch-master-headless
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
message: statefulset rolling update complete 3 pods at revision elasticsearch-master-579789bbc...
|
||||||
|
status: Healthy
|
||||||
|
kind: StatefulSet
|
||||||
|
name: elasticsearch-master
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: policy
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
name: elasticsearch-master-pdb
|
||||||
|
namespace: elasticsearch
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
sourceType: Helm
|
||||||
|
summary:
|
||||||
|
images:
|
||||||
|
- docker.io/library/elasticsearch:8.5.1
|
||||||
|
sync:
|
||||||
|
comparedTo:
|
||||||
|
destination:
|
||||||
|
namespace: elasticsearch
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
source:
|
||||||
|
path: elasticsearch
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
revision: 411b0b9894242dca75f4ee170a81ceef4e635b0a
|
||||||
|
status: Synced
|
||||||
233
argo-infra-apps/grafana.yaml
Normal file
233
argo-infra-apps/grafana.yaml
Normal file
@ -0,0 +1,233 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: "2025-04-29T20:35:02Z"
|
||||||
|
generation: 18
|
||||||
|
name: grafana
|
||||||
|
namespace: argocd
|
||||||
|
resourceVersion: "12377177"
|
||||||
|
uid: 5f1ac9c2-48c5-4778-afc3-6a9a2c525a4f
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
path: grafana
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
syncPolicy:
|
||||||
|
automated: {}
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
status:
|
||||||
|
controllerNamespace: argocd
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
history:
|
||||||
|
- deployStartedAt: "2025-04-29T20:35:04Z"
|
||||||
|
deployedAt: "2025-04-29T20:35:06Z"
|
||||||
|
id: 0
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 0144665f14c7e31020dbfa8c9c2746a290caec74
|
||||||
|
source:
|
||||||
|
path: grafana
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
operationState:
|
||||||
|
finishedAt: "2025-04-29T20:35:07Z"
|
||||||
|
message: successfully synced (all tasks run)
|
||||||
|
operation:
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
retry:
|
||||||
|
limit: 5
|
||||||
|
sync:
|
||||||
|
revision: 0144665f14c7e31020dbfa8c9c2746a290caec74
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
phase: Succeeded
|
||||||
|
startedAt: "2025-04-29T20:35:04Z"
|
||||||
|
syncResult:
|
||||||
|
resources:
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Namespace
|
||||||
|
message: namespace/grafana created
|
||||||
|
name: grafana
|
||||||
|
namespace: ""
|
||||||
|
status: Synced
|
||||||
|
syncPhase: PreSync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ServiceAccount
|
||||||
|
message: serviceaccount/grafana-alloy-metrics created
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Secret
|
||||||
|
message: secret/metrics-grafana-k8s-monitoring created
|
||||||
|
name: metrics-grafana-k8s-monitoring
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ConfigMap
|
||||||
|
message: configmap/grafana-alloy-metrics created
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: "clusterrole.rbac.authorization.k8s.io/grafana-alloy-metrics reconciled.
|
||||||
|
reconciliation required create\n\tmissing rules added:\n\t\t{Verbs:[get
|
||||||
|
list watch] APIGroups:[ discovery.k8s.io networking.k8s.io] Resources:[endpoints
|
||||||
|
endpointslices ingresses nodes nodes/proxy nodes/metrics pods services]
|
||||||
|
ResourceNames:[] NonResourceURLs:[]}\n\t\t{Verbs:[get list watch] APIGroups:[]
|
||||||
|
Resources:[pods pods/log namespaces] ResourceNames:[] NonResourceURLs:[]}\n\t\t{Verbs:[get
|
||||||
|
list watch] APIGroups:[monitoring.grafana.com] Resources:[podlogs] ResourceNames:[]
|
||||||
|
NonResourceURLs:[]}\n\t\t{Verbs:[get list watch] APIGroups:[monitoring.coreos.com]
|
||||||
|
Resources:[prometheusrules] ResourceNames:[] NonResourceURLs:[]}\n\t\t{Verbs:[get]
|
||||||
|
APIGroups:[] Resources:[] ResourceNames:[] NonResourceURLs:[/metrics]}\n\t\t{Verbs:[get
|
||||||
|
list watch] APIGroups:[monitoring.coreos.com] Resources:[podmonitors servicemonitors
|
||||||
|
probes scrapeconfigs] ResourceNames:[] NonResourceURLs:[]}\n\t\t{Verbs:[get
|
||||||
|
list watch] APIGroups:[] Resources:[events] ResourceNames:[] NonResourceURLs:[]}\n\t\t{Verbs:[get
|
||||||
|
list watch] APIGroups:[] Resources:[configmaps secrets] ResourceNames:[]
|
||||||
|
NonResourceURLs:[]}\n\t\t{Verbs:[get list watch] APIGroups:[apps] Resources:[replicasets]
|
||||||
|
ResourceNames:[] NonResourceURLs:[]}\n\t\t{Verbs:[get list watch] APIGroups:[extensions]
|
||||||
|
Resources:[replicasets] ResourceNames:[] NonResourceURLs:[]}. clusterrole.rbac.authorization.k8s.io/grafana-alloy-metrics
|
||||||
|
configured. Warning: resource clusterroles/grafana-alloy-metrics is missing
|
||||||
|
the kubectl.kubernetes.io/last-applied-configuration annotation which is
|
||||||
|
required by apply. apply should only be used on resources created declaratively
|
||||||
|
by either create --save-config or apply. The missing annotation will be
|
||||||
|
patched automatically."
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
message: "clusterrolebinding.rbac.authorization.k8s.io/grafana-alloy-metrics
|
||||||
|
reconciled. reconciliation required create\n\tmissing subjects added:\n\t\t{Kind:ServiceAccount
|
||||||
|
APIGroup: Name:grafana-alloy-metrics Namespace:grafana}. clusterrolebinding.rbac.authorization.k8s.io/grafana-alloy-metrics
|
||||||
|
configured. Warning: resource clusterrolebindings/grafana-alloy-metrics
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically."
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: service/grafana-alloy-metrics-cluster created
|
||||||
|
name: grafana-alloy-metrics-cluster
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: service/grafana-alloy-metrics created
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
hookPhase: Running
|
||||||
|
kind: StatefulSet
|
||||||
|
message: statefulset.apps/grafana-alloy-metrics created
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
revision: 0144665f14c7e31020dbfa8c9c2746a290caec74
|
||||||
|
source:
|
||||||
|
path: grafana
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
reconciledAt: "2025-04-29T20:48:00Z"
|
||||||
|
resources:
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: Secret
|
||||||
|
name: metrics-grafana-k8s-monitoring
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: grafana-alloy-metrics-cluster
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
message: 'partitioned roll out complete: 1 new pods have been updated...'
|
||||||
|
status: Healthy
|
||||||
|
kind: StatefulSet
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
namespace: grafana
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
name: grafana-alloy-metrics
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
sourceType: Helm
|
||||||
|
summary:
|
||||||
|
images:
|
||||||
|
- docker.io/grafana/alloy:v1.8.2
|
||||||
|
- quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0
|
||||||
|
sync:
|
||||||
|
comparedTo:
|
||||||
|
destination:
|
||||||
|
namespace: grafana
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
source:
|
||||||
|
path: grafana
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
revision: 0144665f14c7e31020dbfa8c9c2746a290caec74
|
||||||
|
status: Synced
|
||||||
208
argo-infra-apps/ingress-nginx.yaml
Normal file
208
argo-infra-apps/ingress-nginx.yaml
Normal file
@ -0,0 +1,208 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: "2025-05-07T15:03:24Z"
|
||||||
|
generation: 779
|
||||||
|
name: ingress-nginx
|
||||||
|
namespace: argocd
|
||||||
|
resourceVersion: "15435627"
|
||||||
|
uid: ecb21cf9-d2a3-409b-87a7-cf1a44b0bbe1
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
syncPolicy:
|
||||||
|
automated: {}
|
||||||
|
status:
|
||||||
|
controllerNamespace: argocd
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
history:
|
||||||
|
- deployStartedAt: "2025-05-07T15:03:25Z"
|
||||||
|
deployedAt: "2025-05-07T15:03:50Z"
|
||||||
|
id: 0
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 91f02aa5bf6ced7986e99b89fca21ee4452f7d5c
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
- deployStartedAt: "2025-05-07T15:08:21Z"
|
||||||
|
deployedAt: "2025-05-07T15:08:35Z"
|
||||||
|
id: 1
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 1402201ea91b245cd137ca4e86763bfc5d995ff0
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
- deployStartedAt: "2025-05-07T15:08:35Z"
|
||||||
|
deployedAt: "2025-05-07T15:08:49Z"
|
||||||
|
id: 2
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 91f02aa5bf6ced7986e99b89fca21ee4452f7d5c
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
- deployStartedAt: "2025-05-08T10:46:45Z"
|
||||||
|
deployedAt: "2025-05-08T10:46:57Z"
|
||||||
|
id: 3
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 36e6d6dc59968e714b0b4ead488c5dc72682094a
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
- deployStartedAt: "2025-05-08T14:28:02Z"
|
||||||
|
deployedAt: "2025-05-08T14:28:14Z"
|
||||||
|
id: 4
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: c8b0c0149b5392e63bf832f558305d59d82ae9af
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
- deployStartedAt: "2025-05-08T14:41:29Z"
|
||||||
|
deployedAt: "2025-05-08T14:41:44Z"
|
||||||
|
id: 5
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: 6c1a12cdae7ccf40a6ba2282482187045749be6b
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
- deployStartedAt: "2025-05-08T14:53:12Z"
|
||||||
|
deployedAt: "2025-05-08T14:53:24Z"
|
||||||
|
id: 6
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: 6c1a12cdae7ccf40a6ba2282482187045749be6b
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
operationState:
|
||||||
|
finishedAt: "2025-05-08T14:57:22Z"
|
||||||
|
message: one or more objects failed to apply (dry run)
|
||||||
|
operation:
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
retry: {}
|
||||||
|
sync:
|
||||||
|
revision: 6c1a12cdae7ccf40a6ba2282482187045749be6b
|
||||||
|
syncOptions:
|
||||||
|
- Replace=true
|
||||||
|
syncStrategy:
|
||||||
|
hook:
|
||||||
|
force: true
|
||||||
|
phase: Failed
|
||||||
|
startedAt: "2025-05-08T14:57:16Z"
|
||||||
|
syncResult:
|
||||||
|
resources:
|
||||||
|
- group: batch
|
||||||
|
hookPhase: Failed
|
||||||
|
hookType: PreSync
|
||||||
|
kind: Job
|
||||||
|
message: 'error when deleting "/dev/shm/4286291675": jobs.batch "ingress-nginx-admission-create"
|
||||||
|
not found'
|
||||||
|
name: ingress-nginx-admission-create
|
||||||
|
namespace: default
|
||||||
|
status: SyncFailed
|
||||||
|
syncPhase: PreSync
|
||||||
|
version: v1
|
||||||
|
revision: 6c1a12cdae7ccf40a6ba2282482187045749be6b
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
reconciledAt: "2025-05-08T14:57:22Z"
|
||||||
|
resources:
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: ingress-nginx-controller
|
||||||
|
namespace: default
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: ingress-nginx-controller
|
||||||
|
namespace: default
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: ingress-nginx-controller-admission
|
||||||
|
namespace: default
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: ingress-nginx
|
||||||
|
namespace: default
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: admissionregistration.k8s.io
|
||||||
|
kind: ValidatingWebhookConfiguration
|
||||||
|
name: ingress-nginx-admission
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Deployment
|
||||||
|
name: ingress-nginx-controller
|
||||||
|
namespace: default
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: networking.k8s.io
|
||||||
|
kind: IngressClass
|
||||||
|
name: nginx
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: ingress-nginx
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
name: ingress-nginx
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: ingress-nginx
|
||||||
|
namespace: default
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: RoleBinding
|
||||||
|
name: ingress-nginx
|
||||||
|
namespace: default
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
sourceType: Helm
|
||||||
|
summary:
|
||||||
|
images:
|
||||||
|
- registry.k8s.io/ingress-nginx/controller:v1.12.2@sha256:03497ee984628e95eca9b2279e3f3a3c1685dd48635479e627d219f00c8eefa9
|
||||||
|
sync:
|
||||||
|
comparedTo:
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
source:
|
||||||
|
path: ingress-nginx
|
||||||
|
repoURL: https://git.co-work.ru/cw-devops/cw-infra-apps.git
|
||||||
|
targetRevision: main
|
||||||
|
revision: 6c1a12cdae7ccf40a6ba2282482187045749be6b
|
||||||
|
status: Synced
|
||||||
359
argo-infra-apps/kafka.yaml
Normal file
359
argo-infra-apps/kafka.yaml
Normal file
File diff suppressed because one or more lines are too long
122
argo-infra-apps/livekit-egress.yaml
Normal file
122
argo-infra-apps/livekit-egress.yaml
Normal file
@ -0,0 +1,122 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: "2025-05-08T14:26:30Z"
|
||||||
|
generation: 14
|
||||||
|
name: livekit-egress
|
||||||
|
namespace: argocd
|
||||||
|
resourceVersion: "15428767"
|
||||||
|
uid: e20642c8-3378-4c0c-8f8f-9c54440413ac
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-egress
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
syncPolicy:
|
||||||
|
automated: {}
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
ignoreDifferences:
|
||||||
|
- group: apps
|
||||||
|
kind: Deployment
|
||||||
|
name: livekit-egress
|
||||||
|
namespace: client3
|
||||||
|
jsonPointers:
|
||||||
|
- /spec/replicas
|
||||||
|
status:
|
||||||
|
controllerNamespace: argocd
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
history:
|
||||||
|
- deployStartedAt: "2025-05-08T14:26:31Z"
|
||||||
|
deployedAt: "2025-05-08T14:26:34Z"
|
||||||
|
id: 0
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: c8b0c0149b5392e63bf832f558305d59d82ae9af
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-egress
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
operationState:
|
||||||
|
finishedAt: "2025-05-08T14:26:34Z"
|
||||||
|
message: successfully synced (all tasks run)
|
||||||
|
operation:
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
retry:
|
||||||
|
limit: 5
|
||||||
|
sync:
|
||||||
|
revision: c8b0c0149b5392e63bf832f558305d59d82ae9af
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
phase: Succeeded
|
||||||
|
startedAt: "2025-05-08T14:26:31Z"
|
||||||
|
syncResult:
|
||||||
|
resources:
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Namespace
|
||||||
|
message: namespace/client3 created
|
||||||
|
name: livekit
|
||||||
|
namespace: ""
|
||||||
|
status: Synced
|
||||||
|
syncPhase: PreSync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ConfigMap
|
||||||
|
message: configmap/livekit-egress created
|
||||||
|
name: livekit-egress
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Deployment
|
||||||
|
message: deployment.apps/livekit-egress created
|
||||||
|
name: livekit-egress
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
revision: c8b0c0149b5392e63bf832f558305d59d82ae9af
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-egress
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
reconciledAt: "2025-05-08T14:35:27Z"
|
||||||
|
resources:
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: livekit-egress
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Deployment
|
||||||
|
name: livekit-egress
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
sourceType: Helm
|
||||||
|
summary:
|
||||||
|
images:
|
||||||
|
- livekit/egress:v1.9.0
|
||||||
|
sync:
|
||||||
|
comparedTo:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-egress
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
revision: c8b0c0149b5392e63bf832f558305d59d82ae9af
|
||||||
|
status: Synced
|
||||||
194
argo-infra-apps/livekit-server.yaml
Normal file
194
argo-infra-apps/livekit-server.yaml
Normal file
@ -0,0 +1,194 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: "2025-05-12T19:26:50Z"
|
||||||
|
generation: 54
|
||||||
|
name: livekit-server
|
||||||
|
namespace: argocd
|
||||||
|
resourceVersion: "16843936"
|
||||||
|
uid: 6fd2964a-59c7-442f-8029-d3c7095ee329
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-server
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
syncPolicy:
|
||||||
|
automated: {}
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
ignoreDifferences:
|
||||||
|
- group: apps
|
||||||
|
kind: Deployment
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
jsonPointers:
|
||||||
|
- /spec/replicas
|
||||||
|
|
||||||
|
status:
|
||||||
|
controllerNamespace: argocd
|
||||||
|
health:
|
||||||
|
status: Progressing
|
||||||
|
history:
|
||||||
|
- deployStartedAt: "2025-05-12T19:39:24Z"
|
||||||
|
deployedAt: "2025-05-12T19:39:25Z"
|
||||||
|
id: 0
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
revision: bd036c064dfb7ad6ff8537ffcbd411e433b899f1
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-server
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
operationState:
|
||||||
|
finishedAt: "2025-05-12T19:39:25Z"
|
||||||
|
message: successfully synced (all tasks run)
|
||||||
|
operation:
|
||||||
|
initiatedBy:
|
||||||
|
username: admin
|
||||||
|
retry: {}
|
||||||
|
sync:
|
||||||
|
revision: bd036c064dfb7ad6ff8537ffcbd411e433b899f1
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
- Replace=true
|
||||||
|
syncStrategy:
|
||||||
|
hook:
|
||||||
|
force: true
|
||||||
|
phase: Succeeded
|
||||||
|
startedAt: "2025-05-12T19:39:24Z"
|
||||||
|
syncResult:
|
||||||
|
resources:
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ConfigMap
|
||||||
|
message: |-
|
||||||
|
configmap "livekit-server" deleted
|
||||||
|
configmap/livekit-server replaced
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: |-
|
||||||
|
service "livekit-server" deleted
|
||||||
|
service/livekit-server replaced
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: |-
|
||||||
|
service "livekit-server-turn" deleted
|
||||||
|
service/livekit-server-turn replaced
|
||||||
|
name: livekit-server-turn
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Deployment
|
||||||
|
message: |-
|
||||||
|
deployment.apps "livekit-server" deleted
|
||||||
|
deployment.apps/livekit-server replaced
|
||||||
|
name: livekit-server
|
||||||
|
namespace: livekit
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: networking.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Ingress
|
||||||
|
message: ingress.networking.k8s.io/livekit-server-turn created
|
||||||
|
name: livekit-server-turn
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: networking.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Ingress
|
||||||
|
message: ingress.networking.k8s.io/livekit-server created
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
revision: bd036c064dfb7ad6ff8537ffcbd411e433b899f1
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-server
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
reconciledAt: "2025-05-12T20:05:28Z"
|
||||||
|
resources:
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: livekit-server-turn
|
||||||
|
namespace: livekit
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Deployment
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: networking.k8s.io
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Ingress
|
||||||
|
name: livekit-server
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: networking.k8s.io
|
||||||
|
health:
|
||||||
|
status: Progressing
|
||||||
|
kind: Ingress
|
||||||
|
name: livekit-server-turn
|
||||||
|
namespace: client3
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
sourceType: Helm
|
||||||
|
summary:
|
||||||
|
externalURLs:
|
||||||
|
- https://av-s001.co-work.ru/
|
||||||
|
- https://avt-s001.co-work.ru/
|
||||||
|
images:
|
||||||
|
- livekit/livekit-server:v1.8.3
|
||||||
|
sync:
|
||||||
|
comparedTo:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
source:
|
||||||
|
path: livekit/livekit-server
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
revision: bd036c064dfb7ad6ff8537ffcbd411e433b899f1
|
||||||
|
status: Synced
|
||||||
233
argo-infra-apps/nfs-subdir-external-provisioner.yaml
Normal file
233
argo-infra-apps/nfs-subdir-external-provisioner.yaml
Normal file
File diff suppressed because one or more lines are too long
20
argo-infra-apps/postgresql-ha.yaml
Normal file
20
argo-infra-apps/postgresql-ha.yaml
Normal file
@ -0,0 +1,20 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: postgresql-ha
|
||||||
|
namespace: argocd
|
||||||
|
spec:
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
path: postgresql-ha
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
namespace: client3
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
287
argo-infra-apps/redis.yaml
Normal file
287
argo-infra-apps/redis.yaml
Normal file
@ -0,0 +1,287 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: "2025-04-30T20:40:28Z"
|
||||||
|
generation: 16
|
||||||
|
name: redis
|
||||||
|
namespace: argocd
|
||||||
|
resourceVersion: "12737426"
|
||||||
|
uid: e79154a8-6a82-4993-8479-4260dd93deea
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
path: redis
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
|
status:
|
||||||
|
controllerNamespace: argocd
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
history:
|
||||||
|
- deployStartedAt: "2025-04-30T20:40:28Z"
|
||||||
|
deployedAt: "2025-04-30T20:40:29Z"
|
||||||
|
id: 0
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: d7952823366ef593ddd14f398cd8757fabc1b83a
|
||||||
|
source:
|
||||||
|
path: redis
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
operationState:
|
||||||
|
finishedAt: "2025-04-30T20:40:29Z"
|
||||||
|
message: successfully synced (all tasks run)
|
||||||
|
operation:
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
retry:
|
||||||
|
limit: 5
|
||||||
|
sync:
|
||||||
|
prune: true
|
||||||
|
revision: d7952823366ef593ddd14f398cd8757fabc1b83a
|
||||||
|
phase: Succeeded
|
||||||
|
startedAt: "2025-04-30T20:40:28Z"
|
||||||
|
syncResult:
|
||||||
|
resources:
|
||||||
|
- group: networking.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: NetworkPolicy
|
||||||
|
message: networkpolicy.networking.k8s.io/redis created
|
||||||
|
name: redis
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: policy
|
||||||
|
hookPhase: Running
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
message: poddisruptionbudget.policy/redis-master created
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: policy
|
||||||
|
hookPhase: Running
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
message: poddisruptionbudget.policy/redis-replicas created
|
||||||
|
name: redis-replicas
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ServiceAccount
|
||||||
|
message: serviceaccount/redis-master created
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ServiceAccount
|
||||||
|
message: serviceaccount/redis-replica created
|
||||||
|
name: redis-replica
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Secret
|
||||||
|
message: secret/redis created
|
||||||
|
name: redis
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ConfigMap
|
||||||
|
message: configmap/redis-scripts created
|
||||||
|
name: redis-scripts
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ConfigMap
|
||||||
|
message: configmap/redis-configuration created
|
||||||
|
name: redis-configuration
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ConfigMap
|
||||||
|
message: configmap/redis-health created
|
||||||
|
name: redis-health
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: service/redis-master created
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: service/redis-headless created
|
||||||
|
name: redis-headless
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: service/redis-replicas created
|
||||||
|
name: redis-replicas
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
hookPhase: Running
|
||||||
|
kind: StatefulSet
|
||||||
|
message: statefulset.apps/redis-master created
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
hookPhase: Running
|
||||||
|
kind: StatefulSet
|
||||||
|
message: statefulset.apps/redis-replicas created
|
||||||
|
name: redis-replicas
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
revision: d7952823366ef593ddd14f398cd8757fabc1b83a
|
||||||
|
source:
|
||||||
|
path: redis
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
reconciledAt: "2025-04-30T20:40:29Z"
|
||||||
|
resources:
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: redis-configuration
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: redis-health
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: redis-scripts
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: Secret
|
||||||
|
name: redis
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: redis-headless
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: redis-replicas
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: redis-replica
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
message: statefulset rolling update complete 1 pods at revision redis-master-7989dc744c...
|
||||||
|
status: Healthy
|
||||||
|
kind: StatefulSet
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
message: statefulset rolling update complete 3 pods at revision redis-replicas-58784fcb67...
|
||||||
|
status: Healthy
|
||||||
|
kind: StatefulSet
|
||||||
|
name: redis-replicas
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: networking.k8s.io
|
||||||
|
kind: NetworkPolicy
|
||||||
|
name: redis
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: policy
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
name: redis-master
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: policy
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
name: redis-replicas
|
||||||
|
namespace: redis
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
sourceType: Helm
|
||||||
|
summary:
|
||||||
|
images:
|
||||||
|
- docker.io/bitnami/redis:7.4.3-debian-12-r0
|
||||||
|
sync:
|
||||||
|
comparedTo:
|
||||||
|
destination:
|
||||||
|
namespace: redis
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
source:
|
||||||
|
path: redis
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
revision: d7952823366ef593ddd14f398cd8757fabc1b83a
|
||||||
|
status: Synced
|
||||||
908
argo-infra-apps/vault-secrets-operator.yaml
Normal file
908
argo-infra-apps/vault-secrets-operator.yaml
Normal file
@ -0,0 +1,908 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: "2025-03-31T11:53:35Z"
|
||||||
|
generation: 16
|
||||||
|
name: vault-secrets-operator
|
||||||
|
namespace: argocd
|
||||||
|
resourceVersion: "3238059"
|
||||||
|
uid: 0acb50cc-b736-4760-aa60-b1dffc497fdd
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: client3
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
path: vault-secrets-operator
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
status:
|
||||||
|
controllerNamespace: argocd
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
history:
|
||||||
|
- deployStartedAt: "2025-03-31T11:53:37Z"
|
||||||
|
deployedAt: "2025-03-31T11:53:47Z"
|
||||||
|
id: 0
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
revision: c44295c14ed484dd4417f4f0ac0a0408aa1d33df
|
||||||
|
source:
|
||||||
|
path: vault-secrets-operator
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
operationState:
|
||||||
|
finishedAt: "2025-03-31T11:53:47Z"
|
||||||
|
message: successfully synced (all tasks run)
|
||||||
|
operation:
|
||||||
|
initiatedBy:
|
||||||
|
automated: true
|
||||||
|
retry:
|
||||||
|
limit: 5
|
||||||
|
sync:
|
||||||
|
prune: true
|
||||||
|
revision: c44295c14ed484dd4417f4f0ac0a0408aa1d33df
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
phase: Succeeded
|
||||||
|
startedAt: "2025-03-31T11:53:37Z"
|
||||||
|
syncResult:
|
||||||
|
resources:
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Succeeded
|
||||||
|
hookType: PreSync
|
||||||
|
kind: ServiceAccount
|
||||||
|
message: vault-secrets-operator-upgrade-crds created
|
||||||
|
name: vault-secrets-operator-upgrade-crds
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
syncPhase: PreSync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Succeeded
|
||||||
|
hookType: PreSync
|
||||||
|
kind: ClusterRole
|
||||||
|
message: vault-secrets-operator-upgrade-crds created
|
||||||
|
name: vault-secrets-operator-upgrade-crds
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
syncPhase: PreSync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Succeeded
|
||||||
|
hookType: PreSync
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
message: vault-secrets-operator-upgrade-crds created
|
||||||
|
name: vault-secrets-operator-upgrade-crds
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
syncPhase: PreSync
|
||||||
|
version: v1
|
||||||
|
- group: batch
|
||||||
|
hookPhase: Succeeded
|
||||||
|
hookType: PreSync
|
||||||
|
kind: Job
|
||||||
|
message: Reached expected number of succeeded pods
|
||||||
|
name: upgrade-crds-vault-secrets-operator
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
syncPhase: PreSync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ServiceAccount
|
||||||
|
message: 'serviceaccount/vault-secrets-operator-controller-manager configured.
|
||||||
|
Warning: resource serviceaccounts/vault-secrets-operator-controller-manager
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-controller-manager
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ConfigMap
|
||||||
|
message: 'configmap/vault-secrets-operator-manager-config configured. Warning:
|
||||||
|
resource configmaps/vault-secrets-operator-manager-config is missing the
|
||||||
|
kubectl.kubernetes.io/last-applied-configuration annotation which is required
|
||||||
|
by apply. apply should only be used on resources created declaratively
|
||||||
|
by either create --save-config or apply. The missing annotation will be
|
||||||
|
patched automatically.'
|
||||||
|
name: vault-secrets-operator-manager-config
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/vaultconnections.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/vaultconnections.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vaultconnections.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/vaultdynamicsecrets.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/vaultdynamicsecrets.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vaultdynamicsecrets.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/vaultauths.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/vaultauths.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vaultauths.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/hcpauths.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/hcpauths.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: hcpauths.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/hcpvaultsecretsapps.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/hcpvaultsecretsapps.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: hcpvaultsecretsapps.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/secrettransformations.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/secrettransformations.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: secrettransformations.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/vaultstaticsecrets.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/vaultstaticsecrets.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vaultstaticsecrets.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/vaultauthglobals.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/vaultauthglobals.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vaultauthglobals.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
message: 'customresourcedefinition.apiextensions.k8s.io/vaultpkisecrets.secrets.hashicorp.com
|
||||||
|
configured. Warning: resource customresourcedefinitions/vaultpkisecrets.secrets.hashicorp.com
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vaultpkisecrets.secrets.hashicorp.com
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpsecretsapp-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpsecretsapp-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-hcpsecretsapp-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-hcpsecretsapp-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultdynamicsecret-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultdynamicsecret-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultdynamicsecret-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultdynamicsecret-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultconnection-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultconnection-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultconnection-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultconnection-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-secrettransformation-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-secrettransformation-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-secrettransformation-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-secrettransformation-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-proxy-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-proxy-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-proxy-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-proxy-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultdynamicsecret-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultdynamicsecret-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultdynamicsecret-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultdynamicsecret-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultconnection-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultconnection-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultconnection-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultconnection-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-manager-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-manager-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-manager-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-manager-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpauth-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpauth-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-hcpauth-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-hcpauth-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultstaticsecret-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultstaticsecret-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultstaticsecret-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultstaticsecret-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-secrettransformation-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-secrettransformation-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-secrettransformation-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-secrettransformation-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultpki-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultpki-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultpki-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultpki-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpauth-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpauth-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-hcpauth-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-hcpauth-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpsecretsapp-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-hcpsecretsapp-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-hcpsecretsapp-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-hcpsecretsapp-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauthglobal-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauthglobal-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultauthglobal-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultauthglobal-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauthglobal-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauthglobal-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultauthglobal-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultauthglobal-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultpki-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultpki-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultpki-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultpki-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauth-viewer-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauth-viewer-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultauth-viewer-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultauth-viewer-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultstaticsecret-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultstaticsecret-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultstaticsecret-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultstaticsecret-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauth-editor-role
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-vaultauth-editor-role
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-vaultauth-editor-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-vaultauth-editor-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRole
|
||||||
|
message: 'clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-metrics-reader
|
||||||
|
reconciled. clusterrole.rbac.authorization.k8s.io/vault-secrets-operator-metrics-reader
|
||||||
|
configured. Warning: resource clusterroles/vault-secrets-operator-metrics-reader
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-metrics-reader
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
message: 'clusterrolebinding.rbac.authorization.k8s.io/vault-secrets-operator-proxy-rolebinding
|
||||||
|
reconciled. clusterrolebinding.rbac.authorization.k8s.io/vault-secrets-operator-proxy-rolebinding
|
||||||
|
configured. Warning: resource clusterrolebindings/vault-secrets-operator-proxy-rolebinding
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-proxy-rolebinding
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
message: 'clusterrolebinding.rbac.authorization.k8s.io/vault-secrets-operator-manager-rolebinding
|
||||||
|
reconciled. clusterrolebinding.rbac.authorization.k8s.io/vault-secrets-operator-manager-rolebinding
|
||||||
|
configured. Warning: resource clusterrolebindings/vault-secrets-operator-manager-rolebinding
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-manager-rolebinding
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Role
|
||||||
|
message: 'role.rbac.authorization.k8s.io/vault-secrets-operator-leader-election-role
|
||||||
|
reconciled. role.rbac.authorization.k8s.io/vault-secrets-operator-leader-election-role
|
||||||
|
configured. Warning: resource roles/vault-secrets-operator-leader-election-role
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-leader-election-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
hookPhase: Running
|
||||||
|
kind: RoleBinding
|
||||||
|
message: 'rolebinding.rbac.authorization.k8s.io/vault-secrets-operator-leader-election-rolebinding
|
||||||
|
reconciled. rolebinding.rbac.authorization.k8s.io/vault-secrets-operator-leader-election-rolebinding
|
||||||
|
configured. Warning: resource rolebindings/vault-secrets-operator-leader-election-rolebinding
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-leader-election-rolebinding
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: ""
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Service
|
||||||
|
message: 'service/vault-secrets-operator-metrics-service configured. Warning:
|
||||||
|
resource services/vault-secrets-operator-metrics-service is missing the
|
||||||
|
kubectl.kubernetes.io/last-applied-configuration annotation which is required
|
||||||
|
by apply. apply should only be used on resources created declaratively
|
||||||
|
by either create --save-config or apply. The missing annotation will be
|
||||||
|
patched automatically.'
|
||||||
|
name: vault-secrets-operator-metrics-service
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
hookPhase: Running
|
||||||
|
kind: Deployment
|
||||||
|
message: 'deployment.apps/vault-secrets-operator-controller-manager configured.
|
||||||
|
Warning: resource deployments/vault-secrets-operator-controller-manager
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-controller-manager
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1
|
||||||
|
- group: secrets.hashicorp.com
|
||||||
|
hookPhase: Running
|
||||||
|
kind: VaultConnection
|
||||||
|
message: 'vaultconnection.secrets.hashicorp.com/default configured. Warning:
|
||||||
|
resource vaultconnections/default is missing the kubectl.kubernetes.io/last-applied-configuration
|
||||||
|
annotation which is required by apply. apply should only be used on resources
|
||||||
|
created declaratively by either create --save-config or apply. The missing
|
||||||
|
annotation will be patched automatically.'
|
||||||
|
name: default
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1beta1
|
||||||
|
- group: secrets.hashicorp.com
|
||||||
|
hookPhase: Running
|
||||||
|
kind: VaultAuth
|
||||||
|
message: 'vaultauth.secrets.hashicorp.com/vault-secrets-operator-default-transit-auth
|
||||||
|
configured. Warning: resource vaultauths/vault-secrets-operator-default-transit-auth
|
||||||
|
is missing the kubectl.kubernetes.io/last-applied-configuration annotation
|
||||||
|
which is required by apply. apply should only be used on resources created
|
||||||
|
declaratively by either create --save-config or apply. The missing annotation
|
||||||
|
will be patched automatically.'
|
||||||
|
name: vault-secrets-operator-default-transit-auth
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
syncPhase: Sync
|
||||||
|
version: v1beta1
|
||||||
|
revision: c44295c14ed484dd4417f4f0ac0a0408aa1d33df
|
||||||
|
source:
|
||||||
|
path: vault-secrets-operator
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
reconciledAt: "2025-03-31T11:53:48Z"
|
||||||
|
resources:
|
||||||
|
- kind: ConfigMap
|
||||||
|
name: vault-secrets-operator-manager-config
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Service
|
||||||
|
name: vault-secrets-operator-metrics-service
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: vault-secrets-operator-controller-manager
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: hcpauths.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: hcpvaultsecretsapps.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: secrettransformations.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: vaultauthglobals.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: vaultauths.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: vaultconnections.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: vaultdynamicsecrets.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: vaultpkisecrets.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apiextensions.k8s.io
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
name: vaultstaticsecrets.secrets.hashicorp.com
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: apps
|
||||||
|
health:
|
||||||
|
status: Healthy
|
||||||
|
kind: Deployment
|
||||||
|
name: vault-secrets-operator-controller-manager
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-hcpauth-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-hcpauth-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-hcpsecretsapp-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-hcpsecretsapp-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-manager-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-metrics-reader
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-proxy-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-secrettransformation-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-secrettransformation-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultauth-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultauth-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultauthglobal-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultauthglobal-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultconnection-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultconnection-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultdynamicsecret-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultdynamicsecret-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultpki-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultpki-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultstaticsecret-editor-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: vault-secrets-operator-vaultstaticsecret-viewer-role
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
name: vault-secrets-operator-manager-rolebinding
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
name: vault-secrets-operator-proxy-rolebinding
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: vault-secrets-operator-leader-election-role
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: rbac.authorization.k8s.io
|
||||||
|
kind: RoleBinding
|
||||||
|
name: vault-secrets-operator-leader-election-rolebinding
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1
|
||||||
|
- group: secrets.hashicorp.com
|
||||||
|
kind: VaultAuth
|
||||||
|
name: vault-secrets-operator-default-transit-auth
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1beta1
|
||||||
|
- group: secrets.hashicorp.com
|
||||||
|
kind: VaultConnection
|
||||||
|
name: default
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
status: Synced
|
||||||
|
version: v1beta1
|
||||||
|
sourceType: Helm
|
||||||
|
summary:
|
||||||
|
images:
|
||||||
|
- hashicorp/vault-secrets-operator:0.10.0
|
||||||
|
- quay.io/brancz/kube-rbac-proxy:v0.18.1
|
||||||
|
sync:
|
||||||
|
comparedTo:
|
||||||
|
destination:
|
||||||
|
namespace: vault-secrets-operator
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
source:
|
||||||
|
path: vault-secrets-operator
|
||||||
|
repoURL: https://git.co-work.ru/devops/cw-infra-apps.git
|
||||||
|
targetRevision: client3
|
||||||
|
revision: c44295c14ed484dd4417f4f0ac0a0408aa1d33df
|
||||||
|
status: Synced
|
||||||
442
argo-infra-apps/vault.yaml
Normal file
442
argo-infra-apps/vault.yaml
Normal file
File diff suppressed because one or more lines are too long
25
cassandra/.helmignore
Normal file
25
cassandra/.helmignore
Normal file
@ -0,0 +1,25 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
# img folder
|
||||||
|
img/
|
||||||
|
# Changelog
|
||||||
|
CHANGELOG.md
|
||||||
6
cassandra/Chart.lock
Normal file
6
cassandra/Chart.lock
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
dependencies:
|
||||||
|
- name: common
|
||||||
|
repository: oci://registry-1.docker.io/bitnamicharts
|
||||||
|
version: 2.30.0
|
||||||
|
digest: sha256:46afdf79eae69065904d430f03f7e5b79a148afed20aa45ee83ba88adc036169
|
||||||
|
generated: "2025-03-05T09:18:46.745709854Z"
|
||||||
34
cassandra/Chart.yaml
Normal file
34
cassandra/Chart.yaml
Normal file
@ -0,0 +1,34 @@
|
|||||||
|
annotations:
|
||||||
|
category: Database
|
||||||
|
images: |
|
||||||
|
- name: cassandra
|
||||||
|
image: docker.io/bitnami/cassandra:5.0.3-debian-12-r6
|
||||||
|
- name: cassandra-exporter
|
||||||
|
image: docker.io/bitnami/cassandra-exporter:2.3.8-debian-12-r41
|
||||||
|
- name: os-shell
|
||||||
|
image: docker.io/bitnami/os-shell:12-debian-12-r39
|
||||||
|
licenses: Apache-2.0
|
||||||
|
apiVersion: v2
|
||||||
|
appVersion: 5.0.3
|
||||||
|
dependencies:
|
||||||
|
- name: common
|
||||||
|
repository: oci://registry-1.docker.io/bitnamicharts
|
||||||
|
tags:
|
||||||
|
- bitnami-common
|
||||||
|
version: 2.x.x
|
||||||
|
description: Apache Cassandra is an open source distributed database management system
|
||||||
|
designed to handle large amounts of data across many servers, providing high availability
|
||||||
|
with no single point of failure. And lets test it. Now.
|
||||||
|
home: https://bitnami.com
|
||||||
|
icon: https://dyltqmyl993wv.cloudfront.net/assets/stacks/cassandra/img/cassandra-stack-220x234.png
|
||||||
|
keywords:
|
||||||
|
- cassandra
|
||||||
|
- database
|
||||||
|
- nosql
|
||||||
|
maintainers:
|
||||||
|
- name: Broadcom, Inc. All Rights Reserved.
|
||||||
|
url: https://github.com/bitnami/charts
|
||||||
|
name: cassandra
|
||||||
|
sources:
|
||||||
|
- https://github.com/bitnami/charts/tree/main/bitnami/cassandra
|
||||||
|
version: 12.2.1
|
||||||
574
cassandra/README.md
Normal file
574
cassandra/README.md
Normal file
@ -0,0 +1,574 @@
|
|||||||
|
<!--- app-name: Apache Cassandra -->
|
||||||
|
|
||||||
|
console.sql has a big size and must be used as init script for our database. Due to a huge size it can't be placed inside configmap, and must be compresseed
|
||||||
|
|
||||||
|
gzip -c console.sql > init.cql.gz
|
||||||
|
after compression it must be placed in init_cm.yaml configmap as a binary data with
|
||||||
|
kubectl create configmap cassandra-init-script --from-file=init.cql.gz -n cassandra or in helm chart template
|
||||||
|
|
||||||
|
https://gemspacepro.atlassian.net/wiki/spaces/GEMB2B/pages/224657714 files are here;
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# Bitnami package for Apache Cassandra
|
||||||
|
|
||||||
|
Apache Cassandra is an open source distributed database management system designed to handle large amounts of data across many servers, providing high availability with no single point of failure.
|
||||||
|
|
||||||
|
[Overview of Apache Cassandra](http://cassandra.apache.org/)
|
||||||
|
|
||||||
|
Trademarks: This software listing is packaged by Bitnami. The respective trademarks mentioned in the offering are owned by the respective companies, and use of them does not imply any affiliation or endorsement.
|
||||||
|
|
||||||
|
## TL;DR
|
||||||
|
|
||||||
|
```console
|
||||||
|
helm install my-release oci://registry-1.docker.io/bitnamicharts/cassandra
|
||||||
|
```
|
||||||
|
|
||||||
|
Looking to use Apache Cassandra in production? Try [VMware Tanzu Application Catalog](https://bitnami.com/enterprise), the commercial edition of the Bitnami catalog.
|
||||||
|
|
||||||
|
## Introduction
|
||||||
|
|
||||||
|
This chart bootstraps an [Apache Cassandra](https://github.com/bitnami/containers/tree/main/bitnami/cassandra) deployment on a [Kubernetes](https://kubernetes.io) cluster using the [Helm](https://helm.sh) package manager.
|
||||||
|
|
||||||
|
Bitnami charts can be used with [Kubeapps](https://kubeapps.dev/) for deployment and management of Helm Charts in clusters.
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
- Kubernetes 1.23+
|
||||||
|
- Helm 3.8.0+
|
||||||
|
- PV provisioner support in the underlying infrastructure
|
||||||
|
|
||||||
|
## Installing the Chart
|
||||||
|
|
||||||
|
To install the chart with the release name `my-release`:
|
||||||
|
|
||||||
|
```console
|
||||||
|
helm install my-release oci://REGISTRY_NAME/REPOSITORY_NAME/cassandra
|
||||||
|
```
|
||||||
|
|
||||||
|
> Note: You need to substitute the placeholders `REGISTRY_NAME` and `REPOSITORY_NAME` with a reference to your Helm chart registry and repository. For example, in the case of Bitnami, you need to use `REGISTRY_NAME=registry-1.docker.io` and `REPOSITORY_NAME=bitnamicharts`.
|
||||||
|
|
||||||
|
These commands deploy one node with Apache Cassandra on the Kubernetes cluster in the default configuration. The [Parameters](#parameters) section lists the parameters that can be configured during installation.
|
||||||
|
|
||||||
|
> **Tip**: List all releases using `helm list`
|
||||||
|
|
||||||
|
## Configuration and installation details
|
||||||
|
|
||||||
|
### Resource requests and limits
|
||||||
|
|
||||||
|
Bitnami charts allow setting resource requests and limits for all containers inside the chart deployment. These are inside the `resources` value (check parameter table). Setting requests is essential for production workloads and these should be adapted to your specific use case.
|
||||||
|
|
||||||
|
To make this process easier, the chart contains the `resourcesPreset` values, which automatically sets the `resources` section according to different presets. Check these presets in [the bitnami/common chart](https://github.com/bitnami/charts/blob/main/bitnami/common/templates/_resources.tpl#L15). However, in production workloads using `resourcesPreset` is discouraged as it may not fully adapt to your specific needs. Find more information on container resource management in the [official Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/).
|
||||||
|
|
||||||
|
### Update credentials
|
||||||
|
|
||||||
|
Bitnami charts configure credentials at first boot. Any further change in the secrets or credentials require manual intervention. Follow these instructions:
|
||||||
|
|
||||||
|
- Update the user password following [the upstream documentation](https://docs.datastax.com/en/cql-oss/3.x/cql/cql_reference/cqlAlterUser.html)
|
||||||
|
- Update the password secret with the new values (replace the SECRET_NAME and PASSWORD placeholders)
|
||||||
|
|
||||||
|
```shell
|
||||||
|
kubectl create secret generic SECRET_NAME --from-literal=cassandra-password=PASSWORD --dry-run -o yaml | kubectl apply -f -
|
||||||
|
```
|
||||||
|
|
||||||
|
### [Rolling vs Immutable tags](https://techdocs.broadcom.com/us/en/vmware-tanzu/application-catalog/tanzu-application-catalog/services/tac-doc/apps-tutorials-understand-rolling-tags-containers-index.html)
|
||||||
|
|
||||||
|
It is strongly recommended to use immutable tags in a production environment. This ensures your deployment does not change automatically if the same tag is updated with a different image.
|
||||||
|
|
||||||
|
Bitnami will release a new chart updating its containers if a new version of the main container, significant changes, or critical vulnerabilities exist.
|
||||||
|
|
||||||
|
### Prometheus metrics
|
||||||
|
|
||||||
|
This chart can be integrated with Prometheus by setting `metrics.enabled` to `true`. This will deploy a sidecar container with [cassandra_exporter](https://github.com/criteo/cassandra_exporter) in all pods and will expose it via the Cassandra service. This service will have the necessary annotations to be automatically scraped by Prometheus.
|
||||||
|
|
||||||
|
#### Prometheus requirements
|
||||||
|
|
||||||
|
It is necessary to have a working installation of Prometheus or Prometheus Operator for the integration to work. Install the [Bitnami Prometheus helm chart](https://github.com/bitnami/charts/tree/main/bitnami/prometheus) or the [Bitnami Kube Prometheus helm chart](https://github.com/bitnami/charts/tree/main/bitnami/kube-prometheus) to easily have a working Prometheus in your cluster.
|
||||||
|
|
||||||
|
#### Integration with Prometheus Operator
|
||||||
|
|
||||||
|
The chart can deploy `ServiceMonitor` objects for integration with Prometheus Operator installations. To do so, set the value `metrics.serviceMonitor.enabled=true`. Ensure that the Prometheus Operator `CustomResourceDefinitions` are installed in the cluster or it will fail with the following error:
|
||||||
|
|
||||||
|
```text
|
||||||
|
no matches for kind "ServiceMonitor" in version "monitoring.coreos.com/v1"
|
||||||
|
```
|
||||||
|
|
||||||
|
Install the [Bitnami Kube Prometheus helm chart](https://github.com/bitnami/charts/tree/main/bitnami/kube-prometheus) for having the necessary CRDs and the Prometheus Operator.
|
||||||
|
|
||||||
|
### Enable TLS
|
||||||
|
|
||||||
|
This chart supports TLS between client and server and between nodes, as explained below:
|
||||||
|
|
||||||
|
- For internode cluster encryption, set the `tls.internodeEncryption` chart parameter to a value different from `none`. Available values are `all`, `dc` or `rack`.
|
||||||
|
- For client-server encryption, set the `tls.clientEncryption` chart parameter to `true`.
|
||||||
|
|
||||||
|
In both cases, it is also necessary to create a secret containing the keystore and truststore certificates and their corresponding protection passwords. This secret is to be passed to the chart via the `tls.existingSecret` parameter at deployment-time, as shown below:
|
||||||
|
|
||||||
|
```text
|
||||||
|
tls.internodeEncryption=all
|
||||||
|
tls.clientEncryption=true
|
||||||
|
tls.existingSecret=my-exisiting-stores
|
||||||
|
tls.passwordsSecret=my-stores-password
|
||||||
|
```
|
||||||
|
|
||||||
|
> TIP: The secret may be created in the standard way with the `--from-file=./keystore`, `--from-file=./truststore`, `--from-literal=keystore-password=KEYSTORE_PASSWORD` and `--from-literal=truststore-password=TRUSTSTORE_PASSWORD` options. This assumes that the stores are in the current working directory and the KEYSTORE_PASSWORD and TRUSTSTORE_PASSWORD placeholders are replaced with the correct keystore and truststore passwords respectively. Example:
|
||||||
|
|
||||||
|
```console
|
||||||
|
kubectl create secret generic my-exisiting-stores --from-file=./keystore --from-file=./truststore
|
||||||
|
kubectl create secret generic my-stores-password --from-literal=keystore-password=KEYSTORE_PASSWORD --from-literal=truststore-password=TRUSTSTORE_PASSWORD
|
||||||
|
```
|
||||||
|
|
||||||
|
Keystore and Truststore files can be dynamically created from the certificates files. In this case a secret with the tls.crt, tls.key and ca.crt in pem format is required. The following example shows how the secret can be created and assumes that all certificate files are in the working directory:
|
||||||
|
|
||||||
|
```console
|
||||||
|
kubectl create secret tls my-certs --cert ./tls.crt --key ./tls.key
|
||||||
|
kubectl patch secret my-certs -p="{\"data\":{\"ca.crt\": \"$(cat ./ca.crt | base64 )\"}}"
|
||||||
|
```
|
||||||
|
|
||||||
|
To enable this feature `tls.autoGenerated` must be set and the new secret should be set in `tls.certificateSecret`:
|
||||||
|
|
||||||
|
```text
|
||||||
|
tls.internodeEncryption=all
|
||||||
|
tls.clientEncryption=true
|
||||||
|
tls.autoGenerated=true
|
||||||
|
tls.certificatesSecret=my-certs
|
||||||
|
tls.passwordsSecret=my-stores-password
|
||||||
|
```
|
||||||
|
|
||||||
|
### Initialize the database
|
||||||
|
|
||||||
|
The [Apache Cassandra](https://github.com/bitnami/containers/tree/main/bitnami/cassandra) image supports the use of custom scripts to initialize a fresh instance. This may be done by creating a Kubernetes ConfigMap that includes the necessary `.sh` or `.cql` scripts and passing this ConfigMap to the chart via the `initDBConfigMap` parameter.
|
||||||
|
|
||||||
|
### Use a custom configuration file
|
||||||
|
|
||||||
|
This chart also supports mounting custom configuration file(s) for Apache Cassandra. This is achieved by setting the `existingConfiguration` parameter with the name of a ConfigMap that includes the custom configuration file(s). Here is an example of deploying the chart with a custom configuration file stored in a ConfigMap named `cassandra-configuration`:
|
||||||
|
|
||||||
|
```text
|
||||||
|
existingConfiguration=cassandra-configuration
|
||||||
|
```
|
||||||
|
|
||||||
|
> NOTE: This ConfigMap will override other Apache Cassandra configuration variables set in the chart.
|
||||||
|
|
||||||
|
### Backup and restore
|
||||||
|
|
||||||
|
Refer to our detailed tutorial on [backing up and restoring Bitnami Apache Cassandra deployments on Kubernetes](https://techdocs.broadcom.com/us/en/vmware-tanzu/application-catalog/tanzu-application-catalog/services/tac-doc/apps-tutorials-backup-restore-data-cassandra-kubernetes-index.html).
|
||||||
|
|
||||||
|
### Set pod affinity
|
||||||
|
|
||||||
|
This chart allows you to set custom pod affinity using the `XXX.affinity` parameter(s). Find more information about pod affinity in the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity).
|
||||||
|
|
||||||
|
As an alternative, you can use the preset configurations for pod affinity, pod anti-affinity, and node affinity available at the [bitnami/common](https://github.com/bitnami/charts/tree/main/bitnami/common#affinities) chart. To do so, set the `XXX.podAffinityPreset`, `XXX.podAntiAffinityPreset`, or `XXX.nodeAffinityPreset` parameters.
|
||||||
|
|
||||||
|
## Persistence
|
||||||
|
|
||||||
|
The [Bitnami Apache Cassandra](https://github.com/bitnami/containers/tree/main/bitnami/cassandra) image stores the Apache Cassandra data at the `/bitnami/cassandra` path of the container.
|
||||||
|
|
||||||
|
Persistent Volume Claims are used to keep the data across deployments. This is known to work in GCE, AWS, and minikube.
|
||||||
|
See the [Parameters](#parameters) section to configure the PVC or to disable persistence.
|
||||||
|
|
||||||
|
If you encounter errors when working with persistent volumes, refer to our [troubleshooting guide for persistent volumes](https://docs.bitnami.com/kubernetes/faq/troubleshooting/troubleshooting-persistence-volumes/).
|
||||||
|
|
||||||
|
### Adjust permissions of persistent volume mountpoint
|
||||||
|
|
||||||
|
As the image run as non-root by default, it is necessary to adjust the ownership of the persistent volume so that the container can write data into it. There are two approaches to achieve this:
|
||||||
|
|
||||||
|
- Use Kubernetes SecurityContexts by setting the `podSecurityContext.enabled` and `containerSecurityContext.enabled` to `true`. This option is enabled by default in the chart. However, this feature does not work in all Kubernetes distributions.
|
||||||
|
- Use an init container to change the ownership of the volume before mounting it in the final destination. Enable this container by setting the `volumePermissions.enabled` parameter to `true`.
|
||||||
|
|
||||||
|
## Parameters
|
||||||
|
|
||||||
|
### Global parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ----------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
|
||||||
|
| `global.imageRegistry` | Global Docker image registry | `""` |
|
||||||
|
| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` |
|
||||||
|
| `global.defaultStorageClass` | Global default StorageClass for Persistent Volume(s) | `""` |
|
||||||
|
| `global.security.allowInsecureImages` | Allows skipping image verification | `false` |
|
||||||
|
| `global.compatibility.openshift.adaptSecurityContext` | Adapt the securityContext sections of the deployment to make them compatible with Openshift restricted-v2 SCC: remove runAsUser, runAsGroup and fsGroup and let the platform use their allowed default IDs. Possible values: auto (apply if the detected running cluster is Openshift), force (perform the adaptation always), disabled (do not perform adaptation) | `auto` |
|
||||||
|
|
||||||
|
### Common parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ------------------------ | --------------------------------------------------------------------------------------- | --------------- |
|
||||||
|
| `nameOverride` | String to partially override common.names.fullname | `""` |
|
||||||
|
| `fullnameOverride` | String to fully override common.names.fullname | `""` |
|
||||||
|
| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `""` |
|
||||||
|
| `commonLabels` | Labels to add to all deployed objects (sub-charts are not considered) | `{}` |
|
||||||
|
| `commonAnnotations` | Annotations to add to all deployed objects | `{}` |
|
||||||
|
| `clusterDomain` | Kubernetes cluster domain name | `cluster.local` |
|
||||||
|
| `extraDeploy` | Array of extra objects to deploy with the release | `[]` |
|
||||||
|
| `usePasswordFiles` | Mount credentials as files instead of using environment variables | `true` |
|
||||||
|
| `diagnosticMode.enabled` | Enable diagnostic mode (all probes will be disabled and the command will be overridden) | `false` |
|
||||||
|
| `diagnosticMode.command` | Command to override all containers in the deployment | `["sleep"]` |
|
||||||
|
| `diagnosticMode.args` | Args to override all containers in the deployment | `["infinity"]` |
|
||||||
|
|
||||||
|
### Cassandra parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| -------------------------- | ---------------------------------------------------------------------------------------------------------------------- | --------------------------- |
|
||||||
|
| `image.registry` | Cassandra image registry | `REGISTRY_NAME` |
|
||||||
|
| `image.repository` | Cassandra image repository | `REPOSITORY_NAME/cassandra` |
|
||||||
|
| `image.digest` | Cassandra image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag | `""` |
|
||||||
|
| `image.pullPolicy` | image pull policy | `IfNotPresent` |
|
||||||
|
| `image.pullSecrets` | Cassandra image pull secrets | `[]` |
|
||||||
|
| `image.debug` | Enable image debug mode | `false` |
|
||||||
|
| `dbUser.user` | Cassandra admin user | `cassandra` |
|
||||||
|
| `dbUser.forcePassword` | Force the user to provide a non | `false` |
|
||||||
|
| `dbUser.password` | Password for `dbUser.user`. Randomly generated if empty | `""` |
|
||||||
|
| `dbUser.existingSecret` | Use an existing secret object for `dbUser.user` password (will ignore `dbUser.password`) | `""` |
|
||||||
|
| `initDB` | Object with cql scripts. Useful for creating a keyspace and pre-populating data | `{}` |
|
||||||
|
| `initDBConfigMap` | ConfigMap with cql scripts. Useful for creating a keyspace and pre-populating data | `""` |
|
||||||
|
| `initDBSecret` | Secret with cql script (with sensitive data). Useful for creating a keyspace and pre-populating data | `""` |
|
||||||
|
| `existingConfiguration` | ConfigMap with custom cassandra configuration files. This overrides any other Cassandra configuration set in the chart | `""` |
|
||||||
|
| `cluster.name` | Cassandra cluster name | `cassandra` |
|
||||||
|
| `cluster.seedCount` | Number of seed nodes | `1` |
|
||||||
|
| `cluster.numTokens` | Number of tokens for each node | `256` |
|
||||||
|
| `cluster.datacenter` | Datacenter name | `dc1` |
|
||||||
|
| `cluster.rack` | Rack name | `rack1` |
|
||||||
|
| `cluster.endpointSnitch` | Endpoint Snitch | `SimpleSnitch` |
|
||||||
|
| `cluster.clientEncryption` | Client Encryption | `false` |
|
||||||
|
| `cluster.extraSeeds` | For an external/second cassandra ring. | `[]` |
|
||||||
|
| `cluster.enableUDF` | Enable User defined functions | `false` |
|
||||||
|
| `jvm.extraOpts` | Set the value for Java Virtual Machine extra options | `""` |
|
||||||
|
| `jvm.maxHeapSize` | Set Java Virtual Machine maximum heap size (MAX_HEAP_SIZE). Calculated automatically if `nil` | `""` |
|
||||||
|
| `jvm.newHeapSize` | Set Java Virtual Machine new heap size (HEAP_NEWSIZE). Calculated automatically if `nil` | `""` |
|
||||||
|
| `command` | Command for running the container (set to default if not set). Use array form | `[]` |
|
||||||
|
| `args` | Args for running the container (set to default if not set). Use array form | `[]` |
|
||||||
|
| `extraEnvVars` | Extra environment variables to be set on cassandra container | `[]` |
|
||||||
|
| `extraEnvVarsCM` | Name of existing ConfigMap containing extra env vars | `""` |
|
||||||
|
| `extraEnvVarsSecret` | Name of existing Secret containing extra env vars | `""` |
|
||||||
|
|
||||||
|
### Statefulset parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------- |
|
||||||
|
| `replicaCount` | Number of Cassandra replicas | `1` |
|
||||||
|
| `updateStrategy.type` | updateStrategy for Cassandra statefulset | `RollingUpdate` |
|
||||||
|
| `automountServiceAccountToken` | Mount Service Account token in pod | `false` |
|
||||||
|
| `hostAliases` | Add deployment host aliases | `[]` |
|
||||||
|
| `podManagementPolicy` | StatefulSet pod management policy | `OrderedReady` |
|
||||||
|
| `priorityClassName` | Cassandra pods' priority. | `""` |
|
||||||
|
| `podAnnotations` | Additional pod annotations | `{}` |
|
||||||
|
| `podLabels` | Additional pod labels | `{}` |
|
||||||
|
| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
|
||||||
|
| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` |
|
||||||
|
| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` |
|
||||||
|
| `nodeAffinityPreset.key` | Node label key to match. Ignored if `affinity` is set | `""` |
|
||||||
|
| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set | `[]` |
|
||||||
|
| `affinity` | Affinity for pod assignment | `{}` |
|
||||||
|
| `nodeSelector` | Node labels for pod assignment | `{}` |
|
||||||
|
| `tolerations` | Tolerations for pod assignment | `[]` |
|
||||||
|
| `topologySpreadConstraints` | Topology Spread Constraints for pod assignment | `[]` |
|
||||||
|
| `podSecurityContext.enabled` | Enabled Cassandra pods' Security Context | `true` |
|
||||||
|
| `podSecurityContext.fsGroupChangePolicy` | Set filesystem group change policy | `Always` |
|
||||||
|
| `podSecurityContext.sysctls` | Set kernel settings using the sysctl interface | `[]` |
|
||||||
|
| `podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` |
|
||||||
|
| `podSecurityContext.fsGroup` | Set Cassandra pod's Security Context fsGroup | `1001` |
|
||||||
|
| `containerSecurityContext.enabled` | Enabled Cassandra containers' Security Context | `true` |
|
||||||
|
| `containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||||
|
| `containerSecurityContext.runAsUser` | Set Cassandra containers' Security Context runAsUser | `1001` |
|
||||||
|
| `containerSecurityContext.runAsGroup` | Set Cassandra containers' Security Context runAsGroup | `1001` |
|
||||||
|
| `containerSecurityContext.allowPrivilegeEscalation` | Set Cassandra containers' Security Context allowPrivilegeEscalation | `false` |
|
||||||
|
| `containerSecurityContext.capabilities.drop` | Set Cassandra containers' Security Context capabilities to be dropped | `["ALL"]` |
|
||||||
|
| `containerSecurityContext.readOnlyRootFilesystem` | Set Cassandra containers' Security Context readOnlyRootFilesystem | `true` |
|
||||||
|
| `containerSecurityContext.runAsNonRoot` | Set Cassandra containers' Security Context runAsNonRoot | `true` |
|
||||||
|
| `containerSecurityContext.privileged` | Set container's Security Context privileged | `false` |
|
||||||
|
| `containerSecurityContext.seccompProfile.type` | Set container's Security Context seccomp profile | `RuntimeDefault` |
|
||||||
|
| `resourcesPreset` | Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if resources is set (resources is recommended for production). | `large` |
|
||||||
|
| `resources` | Set container requests and limits for different resources like CPU or memory (essential for production workloads) | `{}` |
|
||||||
|
| `livenessProbe.enabled` | Enable livenessProbe | `true` |
|
||||||
|
| `livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `60` |
|
||||||
|
| `livenessProbe.periodSeconds` | Period seconds for livenessProbe | `30` |
|
||||||
|
| `livenessProbe.timeoutSeconds` | Timeout seconds for livenessProbe | `30` |
|
||||||
|
| `livenessProbe.failureThreshold` | Failure threshold for livenessProbe | `5` |
|
||||||
|
| `livenessProbe.successThreshold` | Success threshold for livenessProbe | `1` |
|
||||||
|
| `readinessProbe.enabled` | Enable readinessProbe | `true` |
|
||||||
|
| `readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `60` |
|
||||||
|
| `readinessProbe.periodSeconds` | Period seconds for readinessProbe | `10` |
|
||||||
|
| `readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `30` |
|
||||||
|
| `readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `5` |
|
||||||
|
| `readinessProbe.successThreshold` | Success threshold for readinessProbe | `1` |
|
||||||
|
| `startupProbe.enabled` | Enable startupProbe | `false` |
|
||||||
|
| `startupProbe.initialDelaySeconds` | Initial delay seconds for startupProbe | `0` |
|
||||||
|
| `startupProbe.periodSeconds` | Period seconds for startupProbe | `10` |
|
||||||
|
| `startupProbe.timeoutSeconds` | Timeout seconds for startupProbe | `5` |
|
||||||
|
| `startupProbe.failureThreshold` | Failure threshold for startupProbe | `60` |
|
||||||
|
| `startupProbe.successThreshold` | Success threshold for startupProbe | `1` |
|
||||||
|
| `customLivenessProbe` | Custom livenessProbe that overrides the default one | `{}` |
|
||||||
|
| `customReadinessProbe` | Custom readinessProbe that overrides the default one | `{}` |
|
||||||
|
| `customStartupProbe` | Override default startup probe | `{}` |
|
||||||
|
| `lifecycleHooks` | Override default etcd container hooks | `{}` |
|
||||||
|
| `schedulerName` | Alternative scheduler | `""` |
|
||||||
|
| `terminationGracePeriodSeconds` | In seconds, time the given to the Cassandra pod needs to terminate gracefully | `""` |
|
||||||
|
| `extraVolumes` | Optionally specify extra list of additional volumes for cassandra container | `[]` |
|
||||||
|
| `extraVolumeMounts` | Optionally specify extra list of additional volumeMounts for cassandra container | `[]` |
|
||||||
|
| `initContainers` | Add additional init containers to the cassandra pods | `[]` |
|
||||||
|
| `sidecars` | Add additional sidecar containers to the cassandra pods | `[]` |
|
||||||
|
| `pdb.create` | Enable/disable a Pod Disruption Budget creation | `true` |
|
||||||
|
| `pdb.minAvailable` | Mininimum number of pods that must still be available after the eviction | `""` |
|
||||||
|
| `pdb.maxUnavailable` | Max number of pods that can be unavailable after the eviction | `""` |
|
||||||
|
| `hostNetwork` | Enable HOST Network | `false` |
|
||||||
|
| `containerPorts.intra` | Intra Port on the Host and Container | `7000` |
|
||||||
|
| `containerPorts.tls` | TLS Port on the Host and Container | `7001` |
|
||||||
|
| `containerPorts.jmx` | JMX Port on the Host and Container | `7199` |
|
||||||
|
| `containerPorts.cql` | CQL Port on the Host and Container | `9042` |
|
||||||
|
| `hostPorts.intra` | Intra Port on the Host | `""` |
|
||||||
|
| `hostPorts.tls` | TLS Port on the Host | `""` |
|
||||||
|
| `hostPorts.jmx` | JMX Port on the Host | `""` |
|
||||||
|
| `hostPorts.cql` | CQL Port on the Host | `""` |
|
||||||
|
|
||||||
|
### RBAC parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------------------------------- | ---------------------------------------------------------- | ------- |
|
||||||
|
| `serviceAccount.create` | Enable the creation of a ServiceAccount for Cassandra pods | `true` |
|
||||||
|
| `serviceAccount.name` | The name of the ServiceAccount to use. | `""` |
|
||||||
|
| `serviceAccount.annotations` | Annotations for Cassandra Service Account | `{}` |
|
||||||
|
| `serviceAccount.automountServiceAccountToken` | Automount API credentials for a service account. | `false` |
|
||||||
|
|
||||||
|
### Traffic Exposure Parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------------------------- | ---------------------------------------------------------------------------------- | ----------- |
|
||||||
|
| `service.type` | Cassandra service type | `ClusterIP` |
|
||||||
|
| `service.ports.cql` | Cassandra service CQL Port | `9042` |
|
||||||
|
| `service.ports.metrics` | Cassandra service metrics port | `8080` |
|
||||||
|
| `service.nodePorts.cql` | Node port for CQL | `""` |
|
||||||
|
| `service.nodePorts.metrics` | Node port for metrics | `""` |
|
||||||
|
| `service.extraPorts` | Extra ports to expose in the service (normally used with the `sidecar` value) | `[]` |
|
||||||
|
| `service.loadBalancerIP` | LoadBalancerIP if service type is `LoadBalancer` | `""` |
|
||||||
|
| `service.loadBalancerSourceRanges` | Service Load Balancer sources | `[]` |
|
||||||
|
| `service.clusterIP` | Service Cluster IP | `""` |
|
||||||
|
| `service.externalTrafficPolicy` | Service external traffic policy | `Cluster` |
|
||||||
|
| `service.annotations` | Provide any additional annotations which may be required. | `{}` |
|
||||||
|
| `service.sessionAffinity` | Session Affinity for Kubernetes service, can be "None" or "ClientIP" | `None` |
|
||||||
|
| `service.sessionAffinityConfig` | Additional settings for the sessionAffinity | `{}` |
|
||||||
|
| `service.headless.annotations` | Annotations for the headless service. | `{}` |
|
||||||
|
| `networkPolicy.enabled` | Specifies whether a NetworkPolicy should be created | `true` |
|
||||||
|
| `networkPolicy.allowExternal` | Don't require server label for connections | `true` |
|
||||||
|
| `networkPolicy.allowExternalEgress` | Allow the pod to access any range of port and all destinations. | `true` |
|
||||||
|
| `networkPolicy.extraIngress` | Add extra ingress rules to the NetworkPolicy | `[]` |
|
||||||
|
| `networkPolicy.extraEgress` | Add extra ingress rules to the NetworkPolicy (ignored if allowExternalEgress=true) | `[]` |
|
||||||
|
| `networkPolicy.ingressNSMatchLabels` | Labels to match to allow traffic from other namespaces | `{}` |
|
||||||
|
| `networkPolicy.ingressNSPodMatchLabels` | Pod labels to match to allow traffic from other namespaces | `{}` |
|
||||||
|
|
||||||
|
### Persistence parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| -------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
|
||||||
|
| `persistence.enabled` | Enable Cassandra data persistence using PVC, use a Persistent Volume Claim, If false, use emptyDir | `true` |
|
||||||
|
| `persistence.existingClaim` | Name of an existing PVC to use | `""` |
|
||||||
|
| `persistence.storageClass` | PVC Storage Class for Cassandra data volume | `""` |
|
||||||
|
| `persistence.commitStorageClass` | PVC Storage Class for Cassandra Commit Log volume | `""` |
|
||||||
|
| `persistence.annotations` | Persistent Volume Claim annotations | `{}` |
|
||||||
|
| `persistence.accessModes` | Persistent Volume Access Mode | `["ReadWriteOnce"]` |
|
||||||
|
| `persistence.size` | PVC Storage Request for Cassandra data volume | `8Gi` |
|
||||||
|
| `persistence.commitLogsize` | PVC Storage Request for Cassandra commit log volume. Unset by default | `2Gi` |
|
||||||
|
| `persistence.mountPath` | The path the data volume will be mounted at | `/bitnami/cassandra` |
|
||||||
|
| `persistence.commitLogMountPath` | The path the commit log volume will be mounted at. Unset by default. Set it to '/bitnami/cassandra/commitlog' to enable a separate commit log volume | `""` |
|
||||||
|
|
||||||
|
### Volume Permissions parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| -------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- |
|
||||||
|
| `volumePermissions.enabled` | Enable init container that changes the owner and group of the persistent volume | `false` |
|
||||||
|
| `volumePermissions.image.registry` | Init container volume image registry | `REGISTRY_NAME` |
|
||||||
|
| `volumePermissions.image.repository` | Init container volume image repository | `REPOSITORY_NAME/os-shell` |
|
||||||
|
| `volumePermissions.image.digest` | Init container volume image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag | `""` |
|
||||||
|
| `volumePermissions.image.pullPolicy` | Init container volume pull policy | `IfNotPresent` |
|
||||||
|
| `volumePermissions.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` |
|
||||||
|
| `volumePermissions.resourcesPreset` | Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if volumePermissions.resources is set (volumePermissions.resources is recommended for production). | `nano` |
|
||||||
|
| `volumePermissions.resources` | Set container requests and limits for different resources like CPU or memory (essential for production workloads) | `{}` |
|
||||||
|
| `volumePermissions.securityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||||
|
| `volumePermissions.securityContext.runAsUser` | User ID for the init container | `0` |
|
||||||
|
|
||||||
|
### Metrics parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| -------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------ |
|
||||||
|
| `metrics.enabled` | Start a side-car prometheus exporter | `false` |
|
||||||
|
| `metrics.image.registry` | Cassandra exporter image registry | `REGISTRY_NAME` |
|
||||||
|
| `metrics.image.repository` | Cassandra exporter image name | `REPOSITORY_NAME/cassandra-exporter` |
|
||||||
|
| `metrics.image.digest` | Cassandra exporter image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag | `""` |
|
||||||
|
| `metrics.image.pullPolicy` | image pull policy | `IfNotPresent` |
|
||||||
|
| `metrics.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` |
|
||||||
|
| `metrics.resourcesPreset` | Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if metrics.resources is set (metrics.resources is recommended for production). | `nano` |
|
||||||
|
| `metrics.resources` | Set container requests and limits for different resources like CPU or memory (essential for production workloads) | `{}` |
|
||||||
|
| `metrics.readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `20` |
|
||||||
|
| `metrics.readinessProbe.periodSeconds` | Period seconds for readinessProbe | `10` |
|
||||||
|
| `metrics.readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `45` |
|
||||||
|
| `metrics.readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `3` |
|
||||||
|
| `metrics.readinessProbe.successThreshold` | Success threshold for readinessProbe | `1` |
|
||||||
|
| `metrics.extraVolumeMounts` | Optionally specify extra list of additional volumeMounts for cassandra-exporter container | `[]` |
|
||||||
|
| `metrics.podAnnotations` | Metrics exporter pod Annotation and Labels | `{}` |
|
||||||
|
| `metrics.serviceMonitor.enabled` | If `true`, creates a Prometheus Operator ServiceMonitor (also requires `metrics.enabled` to be `true`) | `false` |
|
||||||
|
| `metrics.serviceMonitor.namespace` | Namespace in which Prometheus is running | `monitoring` |
|
||||||
|
| `metrics.serviceMonitor.interval` | Interval at which metrics should be scraped. | `""` |
|
||||||
|
| `metrics.serviceMonitor.scrapeTimeout` | Timeout after which the scrape is ended | `""` |
|
||||||
|
| `metrics.serviceMonitor.selector` | Prometheus instance selector labels | `{}` |
|
||||||
|
| `metrics.serviceMonitor.metricRelabelings` | Specify Metric Relabelings to add to the scrape endpoint | `[]` |
|
||||||
|
| `metrics.serviceMonitor.relabelings` | RelabelConfigs to apply to samples before scraping | `[]` |
|
||||||
|
| `metrics.serviceMonitor.honorLabels` | Specify honorLabels parameter to add the scrape endpoint | `false` |
|
||||||
|
| `metrics.serviceMonitor.jobLabel` | The name of the label on the target service to use as the job name in prometheus. | `""` |
|
||||||
|
| `metrics.serviceMonitor.labels` | Used to pass Labels that are required by the installed Prometheus Operator | `{}` |
|
||||||
|
| `metrics.containerPorts.http` | HTTP Port on the Host and Container | `8080` |
|
||||||
|
| `metrics.containerPorts.jmx` | JMX Port on the Host and Container | `5555` |
|
||||||
|
| `metrics.hostPorts.http` | HTTP Port on the Host | `""` |
|
||||||
|
| `metrics.hostPorts.jmx` | JMX Port on the Host | `""` |
|
||||||
|
| `metrics.configuration` | Configure Cassandra-exporter with a custom config.yml file | `""` |
|
||||||
|
|
||||||
|
### TLS/SSL parameters
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
|
||||||
|
| `tls.internodeEncryption` | Set internode encryption | `none` |
|
||||||
|
| `tls.clientEncryption` | Set client-server encryption | `false` |
|
||||||
|
| `tls.autoGenerated` | Generate automatically self-signed TLS certificates. Currently only supports PEM certificates | `false` |
|
||||||
|
| `tls.existingSecret` | Existing secret that contains Cassandra Keystore and truststore | `""` |
|
||||||
|
| `tls.passwordsSecret` | Secret containing the Keystore and Truststore passwords if needed | `""` |
|
||||||
|
| `tls.keystorePassword` | Password for the keystore, if needed. | `""` |
|
||||||
|
| `tls.truststorePassword` | Password for the truststore, if needed. | `""` |
|
||||||
|
| `tls.resourcesPreset` | Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if tls.resources is set (tls.resources is recommended for production). | `nano` |
|
||||||
|
| `tls.resources` | Set container requests and limits for different resources like CPU or memory (essential for production workloads) | `{}` |
|
||||||
|
| `tls.certificatesSecret` | Secret with the TLS certificates. | `""` |
|
||||||
|
| `tls.tlsEncryptionSecretName` | Secret with the encryption of the TLS certificates | `""` |
|
||||||
|
|
||||||
|
The above parameters map to the env variables defined in [bitnami/cassandra](https://github.com/bitnami/containers/tree/main/bitnami/cassandra). For more information please refer to the [bitnami/cassandra](https://github.com/bitnami/containers/tree/main/bitnami/cassandra) image documentation.
|
||||||
|
|
||||||
|
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
|
||||||
|
|
||||||
|
```console
|
||||||
|
helm install my-release \
|
||||||
|
--set dbUser.user=admin,dbUser.password=password \
|
||||||
|
oci://REGISTRY_NAME/REPOSITORY_NAME/cassandra
|
||||||
|
```
|
||||||
|
|
||||||
|
> Note: You need to substitute the placeholders `REGISTRY_NAME` and `REPOSITORY_NAME` with a reference to your Helm chart registry and repository. For example, in the case of Bitnami, you need to use `REGISTRY_NAME=registry-1.docker.io` and `REPOSITORY_NAME=bitnamicharts`.
|
||||||
|
|
||||||
|
Alternatively, a YAML file that specifies the values for the above parameters can be provided while installing the chart. For example,
|
||||||
|
|
||||||
|
```console
|
||||||
|
helm install my-release -f values.yaml oci://REGISTRY_NAME/REPOSITORY_NAME/cassandra
|
||||||
|
```
|
||||||
|
|
||||||
|
> Note: You need to substitute the placeholders `REGISTRY_NAME` and `REPOSITORY_NAME` with a reference to your Helm chart registry and repository. For example, in the case of Bitnami, you need to use `REGISTRY_NAME=registry-1.docker.io` and `REPOSITORY_NAME=bitnamicharts`.
|
||||||
|
> **Tip**: You can use the default [values.yaml](https://github.com/bitnami/charts/tree/main/bitnami/cassandra/values.yaml)
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
Find more information about how to deal with common errors related to Bitnami's Helm charts in [this troubleshooting guide](https://docs.bitnami.com/general/how-to/troubleshoot-helm-chart-issues).
|
||||||
|
|
||||||
|
## Upgrading
|
||||||
|
|
||||||
|
It's necessary to set the `dbUser.password` parameter when upgrading for readiness/liveness probes to work properly. When you install this chart for the first time, some notes will be displayed providing the credentials you must use. Please note down the password and run the command below to upgrade your chart:
|
||||||
|
|
||||||
|
```console
|
||||||
|
helm upgrade my-release oci://REGISTRY_NAME/REPOSITORY_NAME/cassandra --set dbUser.password=[PASSWORD]
|
||||||
|
```
|
||||||
|
|
||||||
|
> Note: You need to substitute the placeholders `REGISTRY_NAME` and `REPOSITORY_NAME` with a reference to your Helm chart registry and repository. For example, in the case of Bitnami, you need to use `REGISTRY_NAME=registry-1.docker.io` and `REPOSITORY_NAME=bitnamicharts`.
|
||||||
|
|
||||||
|
| Note: you need to substitute the placeholder *[PASSWORD]* with the value obtained in the installation notes.
|
||||||
|
|
||||||
|
### To 12.1.0
|
||||||
|
|
||||||
|
This version introduces image verification for security purposes. To disable it, set `global.security.allowInsecureImages` to `true`. More details at [GitHub issue](https://github.com/bitnami/charts/issues/30850).
|
||||||
|
|
||||||
|
### To 12.0.0
|
||||||
|
|
||||||
|
Cassandra's version was bumped to `5.0`, [the latest GA version](https://cassandra.apache.org/_/blog/Apache-Cassandra-5.0-Announcement.html). Users can upgrade from version 4 to 5.0 through an online upgrade, minimizing downtime for applications. Nevertheless, a backup creation prior to undergoing the upgrade process is recommended. Please, refer to the [official guide](https://cassandra.apache.org/doc/latest/operating/backups.html#snapshots) for further information.
|
||||||
|
|
||||||
|
### To 10.0.0
|
||||||
|
|
||||||
|
This major bump changes the following security defaults:
|
||||||
|
|
||||||
|
- `runAsGroup` is changed from `0` to `1001`
|
||||||
|
- `readOnlyRootFilesystem` is set to `true`
|
||||||
|
- `resourcesPreset` is changed from `none` to the minimum size working in our test suites (NOTE: `resourcesPreset` is not meant for production usage, but `resources` adapted to your use case).
|
||||||
|
- `global.compatibility.openshift.adaptSecurityContext` is changed from `disabled` to `auto`.
|
||||||
|
|
||||||
|
This could potentially break any customization or init scripts used in your deployment. If this is the case, change the default values to the previous ones.
|
||||||
|
|
||||||
|
### To 9.0.0
|
||||||
|
|
||||||
|
This major release renames several values in this chart and adds missing features, in order to be inline with the rest of assets in the Bitnami charts repository.
|
||||||
|
|
||||||
|
Affected values:
|
||||||
|
|
||||||
|
- `serviceMonitor.labels` renamed as `serviceMonitor.selector`.
|
||||||
|
- `service.port` renamed as `service.ports.cql`.
|
||||||
|
- `service.metricsPort` renamed as `service.ports.metrics`.
|
||||||
|
- `service.nodePort` renamed as `service.nodePorts.cql`.
|
||||||
|
- `updateStrategy` changed from String type (previously default to 'rollingUpdate') to Object type, allowing users to configure other updateStrategy parameters, similar to other charts.
|
||||||
|
- Removed value `rollingUpdatePartition`, now configured using `updateStrategy` setting `updateStrategy.rollingUpdate.partition`.
|
||||||
|
|
||||||
|
### To 8.0.0
|
||||||
|
|
||||||
|
Cassandra's version was bumped to `4.0`, [the new major](https://cassandra.apache.org/_/blog/Apache-Cassandra-4.0-is-Here.html) considered LTS. Among other features, this release removes support for [Thrift](https://issues.apache.org/jira/browse/CASSANDRA-11115), which means that the following properties of the chart will no longer be available:
|
||||||
|
|
||||||
|
- `cluster.enableRPC`
|
||||||
|
- `service.thriftPort`
|
||||||
|
- `service.nodePorts.thrift`
|
||||||
|
- `containerPorts.thrift`
|
||||||
|
|
||||||
|
For this version, there have been [intensive efforts](https://cwiki.apache.org/confluence/display/CASSANDRA/4.0+Quality%3A+Components+and+Test+Plans) from Apache to ensure that a safe cluster upgrade can be performed. Nevertheless, a backup creation prior to undergoing the upgrade process is recommended. Please, refer to the [official guide](https://cassandra.apache.org/doc/latest/operating/backups.html#snapshots) for further information.
|
||||||
|
|
||||||
|
### To 7.0.0
|
||||||
|
|
||||||
|
[On November 13, 2020, Helm v2 support was formally finished](https://github.com/helm/charts#status-of-the-project), this major version is the result of the required changes applied to the Helm Chart to be able to incorporate the different features added in Helm v3 and to be consistent with the Helm project itself regarding the Helm v2 EOL.
|
||||||
|
|
||||||
|
### To 6.0.0
|
||||||
|
|
||||||
|
- Several parameters were renamed or disappeared in favor of new ones on this major version:
|
||||||
|
- `securityContext.*` is deprecated in favor of `podSecurityContext` and `containerSecurityContext`.
|
||||||
|
- Parameters prefixed with `statefulset.` were renamed removing the prefix. E.g. `statefulset.rollingUpdatePartition` -> renamed to `rollingUpdatePartition`.
|
||||||
|
- `cluster.replicaCount` is renamed to `replicaCount`.
|
||||||
|
- `cluster.domain` is renamed to `clusterDomain`.
|
||||||
|
- Chart labels were adapted to follow the [Helm charts standard labels](https://helm.sh/docs/chart_best_practices/labels/#standard-labels).
|
||||||
|
- This version also introduces `bitnami/common`, a [library chart](https://helm.sh/docs/topics/library_charts/#helm) as a dependency. More documentation about this new utility could be found [here](https://github.com/bitnami/charts/tree/main/bitnami/common#bitnami-common-library-chart). Please, make sure that you have updated the chart dependencies before executing any upgrade.
|
||||||
|
|
||||||
|
Consequences:
|
||||||
|
|
||||||
|
- Backwards compatibility is not guaranteed. To upgrade to `6.0.0`, install a new release of the Cassandra chart, and migrate the data from your previous release. To do so, create an snapshot of the database, and restore it on the new database. Check [this guide](https://cassandra.apache.org/doc/latest/operating/backups.html#snapshots) for more information.
|
||||||
|
|
||||||
|
### To 5.4.0
|
||||||
|
|
||||||
|
The `minimumAvailable` option has been renamed to `minAvailable` for consistency with other charts. This is not a breaking change as `minimumAvailable` never worked before because of an error in chart templates.
|
||||||
|
|
||||||
|
### To 5.0.0
|
||||||
|
|
||||||
|
An issue in StatefulSet manifest of the 4.x chart series rendered chart upgrades to be broken. The 5.0.0 series fixes this issue. To upgrade to the 5.x series you need to manually delete the Cassandra StatefulSet before executing the `helm upgrade` command.
|
||||||
|
|
||||||
|
```console
|
||||||
|
kubectl delete sts -l release=<RELEASE_NAME>
|
||||||
|
helm upgrade <RELEASE_NAME> ...
|
||||||
|
```
|
||||||
|
|
||||||
|
### To 4.0.0
|
||||||
|
|
||||||
|
This release changes uses Bitnami Cassandra container `3.11.4-debian-9-r188`, based on Bash.
|
||||||
|
|
||||||
|
### To 2.0.0
|
||||||
|
|
||||||
|
This release make it possible to specify custom initialization scripts in both cql and sh files.
|
||||||
|
|
||||||
|
#### Breaking changes
|
||||||
|
|
||||||
|
- `startupCQL` has been removed. Instead, for initializing the database, see [this section](#initialize-the-database).
|
||||||
|
|
||||||
|
## License
|
||||||
|
|
||||||
|
Copyright © 2025 Broadcom. The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
<http://www.apache.org/licenses/LICENSE-2.0>
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
26
cassandra/charts/common/.helmignore
Normal file
26
cassandra/charts/common/.helmignore
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
|
# img folder
|
||||||
|
img/
|
||||||
|
# Changelog
|
||||||
|
CHANGELOG.md
|
||||||
23
cassandra/charts/common/Chart.yaml
Normal file
23
cassandra/charts/common/Chart.yaml
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
annotations:
|
||||||
|
category: Infrastructure
|
||||||
|
licenses: Apache-2.0
|
||||||
|
apiVersion: v2
|
||||||
|
appVersion: 2.30.0
|
||||||
|
description: A Library Helm Chart for grouping common logic between bitnami charts.
|
||||||
|
This chart is not deployable by itself.
|
||||||
|
home: https://bitnami.com
|
||||||
|
icon: https://dyltqmyl993wv.cloudfront.net/downloads/logos/bitnami-mark.png
|
||||||
|
keywords:
|
||||||
|
- common
|
||||||
|
- helper
|
||||||
|
- template
|
||||||
|
- function
|
||||||
|
- bitnami
|
||||||
|
maintainers:
|
||||||
|
- name: Broadcom, Inc. All Rights Reserved.
|
||||||
|
url: https://github.com/bitnami/charts
|
||||||
|
name: common
|
||||||
|
sources:
|
||||||
|
- https://github.com/bitnami/charts/tree/main/bitnami/common
|
||||||
|
type: library
|
||||||
|
version: 2.30.0
|
||||||
235
cassandra/charts/common/README.md
Normal file
235
cassandra/charts/common/README.md
Normal file
@ -0,0 +1,235 @@
|
|||||||
|
# Bitnami Common Library Chart
|
||||||
|
|
||||||
|
A [Helm Library Chart](https://helm.sh/docs/topics/library_charts/#helm) for grouping common logic between Bitnami charts.
|
||||||
|
|
||||||
|
## TL;DR
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
dependencies:
|
||||||
|
- name: common
|
||||||
|
version: 2.x.x
|
||||||
|
repository: oci://registry-1.docker.io/bitnamicharts
|
||||||
|
```
|
||||||
|
|
||||||
|
```console
|
||||||
|
helm dependency update
|
||||||
|
```
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
data:
|
||||||
|
myvalue: "Hello World"
|
||||||
|
```
|
||||||
|
|
||||||
|
Looking to use our applications in production? Try [VMware Tanzu Application Catalog](https://bitnami.com/enterprise), the commercial edition of the Bitnami catalog.
|
||||||
|
|
||||||
|
## Introduction
|
||||||
|
|
||||||
|
This chart provides a common template helpers which can be used to develop new charts using [Helm](https://helm.sh) package manager.
|
||||||
|
|
||||||
|
Bitnami charts can be used with [Kubeapps](https://kubeapps.dev/) for deployment and management of Helm Charts in clusters.
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
- Kubernetes 1.23+
|
||||||
|
- Helm 3.8.0+
|
||||||
|
|
||||||
|
## Parameters
|
||||||
|
|
||||||
|
## Special input schemas
|
||||||
|
|
||||||
|
### ImageRoot
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
registry:
|
||||||
|
type: string
|
||||||
|
description: Docker registry where the image is located
|
||||||
|
example: docker.io
|
||||||
|
|
||||||
|
repository:
|
||||||
|
type: string
|
||||||
|
description: Repository and image name
|
||||||
|
example: bitnami/nginx
|
||||||
|
|
||||||
|
tag:
|
||||||
|
type: string
|
||||||
|
description: image tag
|
||||||
|
example: 1.16.1-debian-10-r63
|
||||||
|
|
||||||
|
pullPolicy:
|
||||||
|
type: string
|
||||||
|
description: Specify a imagePullPolicy.'
|
||||||
|
|
||||||
|
pullSecrets:
|
||||||
|
type: array
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
description: Optionally specify an array of imagePullSecrets (evaluated as templates).
|
||||||
|
|
||||||
|
debug:
|
||||||
|
type: boolean
|
||||||
|
description: Set to true if you would like to see extra information on logs
|
||||||
|
example: false
|
||||||
|
|
||||||
|
## An instance would be:
|
||||||
|
# registry: docker.io
|
||||||
|
# repository: bitnami/nginx
|
||||||
|
# tag: 1.16.1-debian-10-r63
|
||||||
|
# pullPolicy: IfNotPresent
|
||||||
|
# debug: false
|
||||||
|
```
|
||||||
|
|
||||||
|
### Persistence
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
enabled:
|
||||||
|
type: boolean
|
||||||
|
description: Whether enable persistence.
|
||||||
|
example: true
|
||||||
|
|
||||||
|
storageClass:
|
||||||
|
type: string
|
||||||
|
description: Ghost data Persistent Volume Storage Class, If set to "-", storageClassName: "" which disables dynamic provisioning.
|
||||||
|
example: "-"
|
||||||
|
|
||||||
|
accessMode:
|
||||||
|
type: string
|
||||||
|
description: Access mode for the Persistent Volume Storage.
|
||||||
|
example: ReadWriteOnce
|
||||||
|
|
||||||
|
size:
|
||||||
|
type: string
|
||||||
|
description: Size the Persistent Volume Storage.
|
||||||
|
example: 8Gi
|
||||||
|
|
||||||
|
path:
|
||||||
|
type: string
|
||||||
|
description: Path to be persisted.
|
||||||
|
example: /bitnami
|
||||||
|
|
||||||
|
## An instance would be:
|
||||||
|
# enabled: true
|
||||||
|
# storageClass: "-"
|
||||||
|
# accessMode: ReadWriteOnce
|
||||||
|
# size: 8Gi
|
||||||
|
# path: /bitnami
|
||||||
|
```
|
||||||
|
|
||||||
|
### ExistingSecret
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
description: Name of the existing secret.
|
||||||
|
example: mySecret
|
||||||
|
keyMapping:
|
||||||
|
description: Mapping between the expected key name and the name of the key in the existing secret.
|
||||||
|
type: object
|
||||||
|
|
||||||
|
## An instance would be:
|
||||||
|
# name: mySecret
|
||||||
|
# keyMapping:
|
||||||
|
# password: myPasswordKey
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Example of use
|
||||||
|
|
||||||
|
When we store sensitive data for a deployment in a secret, some times we want to give to users the possibility of using theirs existing secrets.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# templates/secret.yaml
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "common.names.fullname" . }}
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
password: {{ .Values.password | b64enc | quote }}
|
||||||
|
|
||||||
|
# templates/dpl.yaml
|
||||||
|
---
|
||||||
|
...
|
||||||
|
env:
|
||||||
|
- name: PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ include "common.secrets.name" (dict "existingSecret" .Values.existingSecret "context" $) }}
|
||||||
|
key: {{ include "common.secrets.key" (dict "existingSecret" .Values.existingSecret "key" "password") }}
|
||||||
|
...
|
||||||
|
|
||||||
|
# values.yaml
|
||||||
|
---
|
||||||
|
name: mySecret
|
||||||
|
keyMapping:
|
||||||
|
password: myPasswordKey
|
||||||
|
```
|
||||||
|
|
||||||
|
### ValidateValue
|
||||||
|
|
||||||
|
#### NOTES.txt
|
||||||
|
|
||||||
|
```console
|
||||||
|
{{- $validateValueConf00 := (dict "valueKey" "path.to.value00" "secret" "secretName" "field" "password-00") -}}
|
||||||
|
{{- $validateValueConf01 := (dict "valueKey" "path.to.value01" "secret" "secretName" "field" "password-01") -}}
|
||||||
|
|
||||||
|
{{ include "common.validations.values.multiple.empty" (dict "required" (list $validateValueConf00 $validateValueConf01) "context" $) }}
|
||||||
|
```
|
||||||
|
|
||||||
|
If we force those values to be empty we will see some alerts
|
||||||
|
|
||||||
|
```console
|
||||||
|
helm install test mychart --set path.to.value00="",path.to.value01=""
|
||||||
|
'path.to.value00' must not be empty, please add '--set path.to.value00=$PASSWORD_00' to the command. To get the current value:
|
||||||
|
|
||||||
|
export PASSWORD_00=$(kubectl get secret --namespace default secretName -o jsonpath="{.data.password-00}" | base64 -d)
|
||||||
|
|
||||||
|
'path.to.value01' must not be empty, please add '--set path.to.value01=$PASSWORD_01' to the command. To get the current value:
|
||||||
|
|
||||||
|
export PASSWORD_01=$(kubectl get secret --namespace default secretName -o jsonpath="{.data.password-01}" | base64 -d)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Upgrading
|
||||||
|
|
||||||
|
### To 1.0.0
|
||||||
|
|
||||||
|
[On November 13, 2020, Helm v2 support was formally finished](https://github.com/helm/charts#status-of-the-project), this major version is the result of the required changes applied to the Helm Chart to be able to incorporate the different features added in Helm v3 and to be consistent with the Helm project itself regarding the Helm v2 EOL.
|
||||||
|
|
||||||
|
#### What changes were introduced in this major version?
|
||||||
|
|
||||||
|
- Previous versions of this Helm Chart use `apiVersion: v1` (installable by both Helm 2 and 3), this Helm Chart was updated to `apiVersion: v2` (installable by Helm 3 only). [Here](https://helm.sh/docs/topics/charts/#the-apiversion-field) you can find more information about the `apiVersion` field.
|
||||||
|
- Use `type: library`. [Here](https://v3.helm.sh/docs/faq/#library-chart-support) you can find more information.
|
||||||
|
- The different fields present in the *Chart.yaml* file has been ordered alphabetically in a homogeneous way for all the Bitnami Helm Charts
|
||||||
|
|
||||||
|
#### Considerations when upgrading to this version
|
||||||
|
|
||||||
|
- If you want to upgrade to this version from a previous one installed with Helm v3, you shouldn't face any issues
|
||||||
|
- If you want to upgrade to this version using Helm v2, this scenario is not supported as this version doesn't support Helm v2 anymore
|
||||||
|
- If you installed the previous version with Helm v2 and wants to upgrade to this version with Helm v3, please refer to the [official Helm documentation](https://helm.sh/docs/topics/v2_v3_migration/#migration-use-cases) about migrating from Helm v2 to v3
|
||||||
|
|
||||||
|
#### Useful links
|
||||||
|
|
||||||
|
- <https://techdocs.broadcom.com/us/en/vmware-tanzu/application-catalog/tanzu-application-catalog/services/tac-doc/apps-tutorials-resolve-helm2-helm3-post-migration-issues-index.html>
|
||||||
|
- <https://helm.sh/docs/topics/v2_v3_migration/>
|
||||||
|
- <https://helm.sh/blog/migrate-from-helm-v2-to-helm-v3/>
|
||||||
|
|
||||||
|
## License
|
||||||
|
|
||||||
|
Copyright © 2025 Broadcom. The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries.
|
||||||
|
|
||||||
|
Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
you may not use this file except in compliance with the License.
|
||||||
|
You may obtain a copy of the License at
|
||||||
|
|
||||||
|
<http://www.apache.org/licenses/LICENSE-2.0>
|
||||||
|
|
||||||
|
Unless required by applicable law or agreed to in writing, software
|
||||||
|
distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
See the License for the specific language governing permissions and
|
||||||
|
limitations under the License.
|
||||||
155
cassandra/charts/common/templates/_affinities.tpl
Normal file
155
cassandra/charts/common/templates/_affinities.tpl
Normal file
@ -0,0 +1,155 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a soft nodeAffinity definition
|
||||||
|
{{ include "common.affinities.nodes.soft" (dict "key" "FOO" "values" (list "BAR" "BAZ")) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.affinities.nodes.soft" -}}
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- preference:
|
||||||
|
matchExpressions:
|
||||||
|
- key: {{ .key }}
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
{{- range .values }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
weight: 1
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a hard nodeAffinity definition
|
||||||
|
{{ include "common.affinities.nodes.hard" (dict "key" "FOO" "values" (list "BAR" "BAZ")) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.affinities.nodes.hard" -}}
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
nodeSelectorTerms:
|
||||||
|
- matchExpressions:
|
||||||
|
- key: {{ .key }}
|
||||||
|
operator: In
|
||||||
|
values:
|
||||||
|
{{- range .values }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a nodeAffinity definition
|
||||||
|
{{ include "common.affinities.nodes" (dict "type" "soft" "key" "FOO" "values" (list "BAR" "BAZ")) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.affinities.nodes" -}}
|
||||||
|
{{- if eq .type "soft" }}
|
||||||
|
{{- include "common.affinities.nodes.soft" . -}}
|
||||||
|
{{- else if eq .type "hard" }}
|
||||||
|
{{- include "common.affinities.nodes.hard" . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a topologyKey definition
|
||||||
|
{{ include "common.affinities.topologyKey" (dict "topologyKey" "BAR") -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.affinities.topologyKey" -}}
|
||||||
|
{{ .topologyKey | default "kubernetes.io/hostname" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a soft podAffinity/podAntiAffinity definition
|
||||||
|
{{ include "common.affinities.pods.soft" (dict "component" "FOO" "customLabels" .Values.podLabels "extraMatchLabels" .Values.extraMatchLabels "topologyKey" "BAR" "extraPodAffinityTerms" .Values.extraPodAffinityTerms "extraNamespaces" (list "namespace1" "namespace2") "context" $) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.affinities.pods.soft" -}}
|
||||||
|
{{- $component := default "" .component -}}
|
||||||
|
{{- $customLabels := default (dict) .customLabels -}}
|
||||||
|
{{- $extraMatchLabels := default (dict) .extraMatchLabels -}}
|
||||||
|
{{- $extraPodAffinityTerms := default (list) .extraPodAffinityTerms -}}
|
||||||
|
{{- $extraNamespaces := default (list) .extraNamespaces -}}
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- podAffinityTerm:
|
||||||
|
labelSelector:
|
||||||
|
matchLabels: {{- (include "common.labels.matchLabels" ( dict "customLabels" $customLabels "context" .context )) | nindent 10 }}
|
||||||
|
{{- if not (empty $component) }}
|
||||||
|
{{ printf "app.kubernetes.io/component: %s" $component }}
|
||||||
|
{{- end }}
|
||||||
|
{{- range $key, $value := $extraMatchLabels }}
|
||||||
|
{{ $key }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if $extraNamespaces }}
|
||||||
|
namespaces:
|
||||||
|
- {{ .context.Release.Namespace }}
|
||||||
|
{{- with $extraNamespaces }}
|
||||||
|
{{ include "common.tplvalues.render" (dict "value" . "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
topologyKey: {{ include "common.affinities.topologyKey" (dict "topologyKey" .topologyKey) }}
|
||||||
|
weight: 1
|
||||||
|
{{- range $extraPodAffinityTerms }}
|
||||||
|
- podAffinityTerm:
|
||||||
|
labelSelector:
|
||||||
|
matchLabels: {{- (include "common.labels.matchLabels" ( dict "customLabels" $customLabels "context" $.context )) | nindent 10 }}
|
||||||
|
{{- if not (empty $component) }}
|
||||||
|
{{ printf "app.kubernetes.io/component: %s" $component }}
|
||||||
|
{{- end }}
|
||||||
|
{{- range $key, $value := .extraMatchLabels }}
|
||||||
|
{{ $key }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
topologyKey: {{ include "common.affinities.topologyKey" (dict "topologyKey" .topologyKey) }}
|
||||||
|
weight: {{ .weight | default 1 -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a hard podAffinity/podAntiAffinity definition
|
||||||
|
{{ include "common.affinities.pods.hard" (dict "component" "FOO" "customLabels" .Values.podLabels "extraMatchLabels" .Values.extraMatchLabels "topologyKey" "BAR" "extraPodAffinityTerms" .Values.extraPodAffinityTerms "extraNamespaces" (list "namespace1" "namespace2") "context" $) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.affinities.pods.hard" -}}
|
||||||
|
{{- $component := default "" .component -}}
|
||||||
|
{{- $customLabels := default (dict) .customLabels -}}
|
||||||
|
{{- $extraMatchLabels := default (dict) .extraMatchLabels -}}
|
||||||
|
{{- $extraPodAffinityTerms := default (list) .extraPodAffinityTerms -}}
|
||||||
|
{{- $extraNamespaces := default (list) .extraNamespaces -}}
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- labelSelector:
|
||||||
|
matchLabels: {{- (include "common.labels.matchLabels" ( dict "customLabels" $customLabels "context" .context )) | nindent 8 }}
|
||||||
|
{{- if not (empty $component) }}
|
||||||
|
{{ printf "app.kubernetes.io/component: %s" $component }}
|
||||||
|
{{- end }}
|
||||||
|
{{- range $key, $value := $extraMatchLabels }}
|
||||||
|
{{ $key }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if $extraNamespaces }}
|
||||||
|
namespaces:
|
||||||
|
- {{ .context.Release.Namespace }}
|
||||||
|
{{- with $extraNamespaces }}
|
||||||
|
{{ include "common.tplvalues.render" (dict "value" . "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
topologyKey: {{ include "common.affinities.topologyKey" (dict "topologyKey" .topologyKey) }}
|
||||||
|
{{- range $extraPodAffinityTerms }}
|
||||||
|
- labelSelector:
|
||||||
|
matchLabels: {{- (include "common.labels.matchLabels" ( dict "customLabels" $customLabels "context" $.context )) | nindent 8 }}
|
||||||
|
{{- if not (empty $component) }}
|
||||||
|
{{ printf "app.kubernetes.io/component: %s" $component }}
|
||||||
|
{{- end }}
|
||||||
|
{{- range $key, $value := .extraMatchLabels }}
|
||||||
|
{{ $key }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
topologyKey: {{ include "common.affinities.topologyKey" (dict "topologyKey" .topologyKey) }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a podAffinity/podAntiAffinity definition
|
||||||
|
{{ include "common.affinities.pods" (dict "type" "soft" "key" "FOO" "values" (list "BAR" "BAZ")) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.affinities.pods" -}}
|
||||||
|
{{- if eq .type "soft" }}
|
||||||
|
{{- include "common.affinities.pods.soft" . -}}
|
||||||
|
{{- else if eq .type "hard" }}
|
||||||
|
{{- include "common.affinities.pods.hard" . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
253
cassandra/charts/common/templates/_capabilities.tpl
Normal file
253
cassandra/charts/common/templates/_capabilities.tpl
Normal file
@ -0,0 +1,253 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the target Kubernetes version
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.kubeVersion" -}}
|
||||||
|
{{- default (default .Capabilities.KubeVersion.Version .Values.kubeVersion) ((.Values.global).kubeVersion) -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if the apiVersion is supported
|
||||||
|
Usage:
|
||||||
|
{{ include "common.capabilities.apiVersions.has" (dict "version" "batch/v1" "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.apiVersions.has" -}}
|
||||||
|
{{- $providedAPIVersions := default .context.Values.apiVersions ((.context.Values.global).apiVersions) -}}
|
||||||
|
{{- if and (empty $providedAPIVersions) (.context.Capabilities.APIVersions.Has .version) -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- else if has .version $providedAPIVersions -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for poddisruptionbudget.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.policy.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.21-0" $kubeVersion) -}}
|
||||||
|
{{- print "policy/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "policy/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for networkpolicy.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.networkPolicy.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.7-0" $kubeVersion) -}}
|
||||||
|
{{- print "extensions/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "networking.k8s.io/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for job.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.job.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.21-0" $kubeVersion) -}}
|
||||||
|
{{- print "batch/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "batch/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for cronjob.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.cronjob.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.21-0" $kubeVersion) -}}
|
||||||
|
{{- print "batch/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "batch/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for daemonset.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.daemonset.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.14-0" $kubeVersion) -}}
|
||||||
|
{{- print "extensions/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "apps/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for deployment.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.deployment.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.14-0" $kubeVersion) -}}
|
||||||
|
{{- print "extensions/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "apps/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for statefulset.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.statefulset.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.14-0" $kubeVersion) -}}
|
||||||
|
{{- print "apps/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "apps/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for ingress.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.ingress.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if (.Values.ingress).apiVersion -}}
|
||||||
|
{{- .Values.ingress.apiVersion -}}
|
||||||
|
{{- else if and (not (empty $kubeVersion)) (semverCompare "<1.14-0" $kubeVersion) -}}
|
||||||
|
{{- print "extensions/v1beta1" -}}
|
||||||
|
{{- else if and (not (empty $kubeVersion)) (semverCompare "<1.19-0" $kubeVersion) -}}
|
||||||
|
{{- print "networking.k8s.io/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "networking.k8s.io/v1" -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for RBAC resources.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.rbac.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.17-0" $kubeVersion) -}}
|
||||||
|
{{- print "rbac.authorization.k8s.io/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "rbac.authorization.k8s.io/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for CRDs.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.crd.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.19-0" $kubeVersion) -}}
|
||||||
|
{{- print "apiextensions.k8s.io/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "apiextensions.k8s.io/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for APIService.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.apiService.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.10-0" $kubeVersion) -}}
|
||||||
|
{{- print "apiregistration.k8s.io/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "apiregistration.k8s.io/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for Horizontal Pod Autoscaler.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.hpa.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" .context -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.23-0" $kubeVersion) -}}
|
||||||
|
{{- if .beta2 -}}
|
||||||
|
{{- print "autoscaling/v2beta2" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "autoscaling/v2beta1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "autoscaling/v2" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for Vertical Pod Autoscaler.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.vpa.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" .context -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.11-0" $kubeVersion) -}}
|
||||||
|
{{- print "autoscaling/v1beta1" -}}
|
||||||
|
{{- else if and (not (empty $kubeVersion)) (semverCompare "<1.25-0" $kubeVersion) -}}
|
||||||
|
{{- print "autoscaling/v1beta2" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "autoscaling/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Returns true if PodSecurityPolicy is supported
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.psp.supported" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if or (empty $kubeVersion) (semverCompare "<1.25-0" $kubeVersion) -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Returns true if AdmissionConfiguration is supported
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.admissionConfiguration.supported" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if or (empty $kubeVersion) (not (semverCompare "<1.23-0" $kubeVersion)) -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for AdmissionConfiguration.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.admissionConfiguration.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.23-0" $kubeVersion) -}}
|
||||||
|
{{- print "apiserver.config.k8s.io/v1alpha1" -}}
|
||||||
|
{{- else if and (not (empty $kubeVersion)) (semverCompare "<1.25-0" $kubeVersion) -}}
|
||||||
|
{{- print "apiserver.config.k8s.io/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "apiserver.config.k8s.io/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the appropriate apiVersion for PodSecurityConfiguration.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.podSecurityConfiguration.apiVersion" -}}
|
||||||
|
{{- $kubeVersion := include "common.capabilities.kubeVersion" . -}}
|
||||||
|
{{- if and (not (empty $kubeVersion)) (semverCompare "<1.23-0" $kubeVersion) -}}
|
||||||
|
{{- print "pod-security.admission.config.k8s.io/v1alpha1" -}}
|
||||||
|
{{- else if and (not (empty $kubeVersion)) (semverCompare "<1.25-0" $kubeVersion) -}}
|
||||||
|
{{- print "pod-security.admission.config.k8s.io/v1beta1" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "pod-security.admission.config.k8s.io/v1" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Returns true if the used Helm version is 3.3+.
|
||||||
|
A way to check the used Helm version was not introduced until version 3.3.0 with .Capabilities.HelmVersion, which contains an additional "{}}" structure.
|
||||||
|
This check is introduced as a regexMatch instead of {{ if .Capabilities.HelmVersion }} because checking for the key HelmVersion in <3.3 results in a "interface not found" error.
|
||||||
|
**To be removed when the catalog's minimun Helm version is 3.3**
|
||||||
|
*/}}
|
||||||
|
{{- define "common.capabilities.supportsHelmVersion" -}}
|
||||||
|
{{- if regexMatch "{(v[0-9])*[^}]*}}$" (.Capabilities | toString ) }}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
46
cassandra/charts/common/templates/_compatibility.tpl
Normal file
46
cassandra/charts/common/templates/_compatibility.tpl
Normal file
@ -0,0 +1,46 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if the detected platform is Openshift
|
||||||
|
Usage:
|
||||||
|
{{- include "common.compatibility.isOpenshift" . -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.compatibility.isOpenshift" -}}
|
||||||
|
{{- if .Capabilities.APIVersions.Has "security.openshift.io/v1" -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Render a compatible securityContext depending on the platform. By default it is maintained as it is. In other platforms like Openshift we remove default user/group values that do not work out of the box with the restricted-v1 SCC
|
||||||
|
Usage:
|
||||||
|
{{- include "common.compatibility.renderSecurityContext" (dict "secContext" .Values.containerSecurityContext "context" $) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.compatibility.renderSecurityContext" -}}
|
||||||
|
{{- $adaptedContext := .secContext -}}
|
||||||
|
|
||||||
|
{{- if (((.context.Values.global).compatibility).openshift) -}}
|
||||||
|
{{- if or (eq .context.Values.global.compatibility.openshift.adaptSecurityContext "force") (and (eq .context.Values.global.compatibility.openshift.adaptSecurityContext "auto") (include "common.compatibility.isOpenshift" .context)) -}}
|
||||||
|
{{/* Remove incompatible user/group values that do not work in Openshift out of the box */}}
|
||||||
|
{{- $adaptedContext = omit $adaptedContext "fsGroup" "runAsUser" "runAsGroup" -}}
|
||||||
|
{{- if not .secContext.seLinuxOptions -}}
|
||||||
|
{{/* If it is an empty object, we remove it from the resulting context because it causes validation issues */}}
|
||||||
|
{{- $adaptedContext = omit $adaptedContext "seLinuxOptions" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{/* Remove empty seLinuxOptions object if global.compatibility.omitEmptySeLinuxOptions is set to true */}}
|
||||||
|
{{- if and (((.context.Values.global).compatibility).omitEmptySeLinuxOptions) (not .secContext.seLinuxOptions) -}}
|
||||||
|
{{- $adaptedContext = omit $adaptedContext "seLinuxOptions" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{/* Remove fields that are disregarded when running the container in privileged mode */}}
|
||||||
|
{{- if $adaptedContext.privileged -}}
|
||||||
|
{{- $adaptedContext = omit $adaptedContext "capabilities" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- omit $adaptedContext "enabled" | toYaml -}}
|
||||||
|
{{- end -}}
|
||||||
85
cassandra/charts/common/templates/_errors.tpl
Normal file
85
cassandra/charts/common/templates/_errors.tpl
Normal file
@ -0,0 +1,85 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Throw error when upgrading using empty passwords values that must not be empty.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{- $validationError00 := include "common.validations.values.single.empty" (dict "valueKey" "path.to.password00" "secret" "secretName" "field" "password-00") -}}
|
||||||
|
{{- $validationError01 := include "common.validations.values.single.empty" (dict "valueKey" "path.to.password01" "secret" "secretName" "field" "password-01") -}}
|
||||||
|
{{ include "common.errors.upgrade.passwords.empty" (dict "validationErrors" (list $validationError00 $validationError01) "context" $) }}
|
||||||
|
|
||||||
|
Required password params:
|
||||||
|
- validationErrors - String - Required. List of validation strings to be return, if it is empty it won't throw error.
|
||||||
|
- context - Context - Required. Parent context.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.errors.upgrade.passwords.empty" -}}
|
||||||
|
{{- $validationErrors := join "" .validationErrors -}}
|
||||||
|
{{- if and $validationErrors .context.Release.IsUpgrade -}}
|
||||||
|
{{- $errorString := "\nPASSWORDS ERROR: You must provide your current passwords when upgrading the release." -}}
|
||||||
|
{{- $errorString = print $errorString "\n Note that even after reinstallation, old credentials may be needed as they may be kept in persistent volume claims." -}}
|
||||||
|
{{- $errorString = print $errorString "\n Further information can be obtained at https://docs.bitnami.com/general/how-to/troubleshoot-helm-chart-issues/#credential-errors-while-upgrading-chart-releases" -}}
|
||||||
|
{{- $errorString = print $errorString "\n%s" -}}
|
||||||
|
{{- printf $errorString $validationErrors | fail -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Throw error when original container images are replaced.
|
||||||
|
The error can be bypassed by setting the "global.security.allowInsecureImages" to true. In this case,
|
||||||
|
a warning message will be shown instead.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.errors.insecureImages" (dict "images" (list .Values.path.to.the.imageRoot) "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.errors.insecureImages" -}}
|
||||||
|
{{- $relocatedImages := list -}}
|
||||||
|
{{- $replacedImages := list -}}
|
||||||
|
{{- $retaggedImages := list -}}
|
||||||
|
{{- $globalRegistry := ((.context.Values.global).imageRegistry) -}}
|
||||||
|
{{- $originalImages := .context.Chart.Annotations.images -}}
|
||||||
|
{{- range .images -}}
|
||||||
|
{{- $registryName := default .registry $globalRegistry -}}
|
||||||
|
{{- $fullImageNameNoTag := printf "%s/%s" $registryName .repository -}}
|
||||||
|
{{- $fullImageName := printf "%s:%s" $fullImageNameNoTag .tag -}}
|
||||||
|
{{- if not (contains $fullImageNameNoTag $originalImages) -}}
|
||||||
|
{{- if not (contains $registryName $originalImages) -}}
|
||||||
|
{{- $relocatedImages = append $relocatedImages $fullImageName -}}
|
||||||
|
{{- else if not (contains .repository $originalImages) -}}
|
||||||
|
{{- $replacedImages = append $replacedImages $fullImageName -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if not (contains (printf "%s:%s" .repository .tag) $originalImages) -}}
|
||||||
|
{{- $retaggedImages = append $retaggedImages $fullImageName -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if and (or (gt (len $relocatedImages) 0) (gt (len $replacedImages) 0)) (((.context.Values.global).security).allowInsecureImages) -}}
|
||||||
|
{{- print "\n\n⚠ SECURITY WARNING: Verifying original container images was skipped. Please note this Helm chart was designed, tested, and validated on multiple platforms using a specific set of Bitnami and Tanzu Application Catalog containers. Substituting other containers is likely to cause degraded security and performance, broken chart features, and missing environment variables.\n" -}}
|
||||||
|
{{- else if (or (gt (len $relocatedImages) 0) (gt (len $replacedImages) 0)) -}}
|
||||||
|
{{- $errorString := "Original containers have been substituted for unrecognized ones. Deploying this chart with non-standard containers is likely to cause degraded security and performance, broken chart features, and missing environment variables." -}}
|
||||||
|
{{- $errorString = print $errorString "\n\nUnrecognized images:" -}}
|
||||||
|
{{- range (concat $relocatedImages $replacedImages) -}}
|
||||||
|
{{- $errorString = print $errorString "\n - " . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if or (contains "docker.io/bitnami/" $originalImages) (contains "docker.io/bitnamiprem/" $originalImages) -}}
|
||||||
|
{{- $errorString = print "\n\n⚠ ERROR: " $errorString -}}
|
||||||
|
{{- $errorString = print $errorString "\n\nIf you are sure you want to proceed with non-standard containers, you can skip container image verification by setting the global parameter 'global.security.allowInsecureImages' to true." -}}
|
||||||
|
{{- $errorString = print $errorString "\nFurther information can be obtained at https://github.com/bitnami/charts/issues/30850" -}}
|
||||||
|
{{- print $errorString | fail -}}
|
||||||
|
{{- else if gt (len $replacedImages) 0 -}}
|
||||||
|
{{- $errorString = print "\n\n⚠ WARNING: " $errorString -}}
|
||||||
|
{{- print $errorString -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- else if gt (len $retaggedImages) 0 -}}
|
||||||
|
{{- $warnString := "\n\n⚠ WARNING: Original containers have been retagged. Please note this Helm chart was tested, and validated on multiple platforms using a specific set of Tanzu Application Catalog containers. Substituting original image tags could cause unexpected behavior." -}}
|
||||||
|
{{- $warnString = print $warnString "\n\nRetagged images:" -}}
|
||||||
|
{{- range $retaggedImages -}}
|
||||||
|
{{- $warnString = print $warnString "\n - " . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- print $warnString -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
115
cassandra/charts/common/templates/_images.tpl
Normal file
115
cassandra/charts/common/templates/_images.tpl
Normal file
@ -0,0 +1,115 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Return the proper image name.
|
||||||
|
If image tag and digest are not defined, termination fallbacks to chart appVersion.
|
||||||
|
{{ include "common.images.image" ( dict "imageRoot" .Values.path.to.the.image "global" .Values.global "chart" .Chart ) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.images.image" -}}
|
||||||
|
{{- $registryName := default .imageRoot.registry ((.global).imageRegistry) -}}
|
||||||
|
{{- $repositoryName := .imageRoot.repository -}}
|
||||||
|
{{- $separator := ":" -}}
|
||||||
|
{{- $termination := .imageRoot.tag | toString -}}
|
||||||
|
|
||||||
|
{{- if not .imageRoot.tag }}
|
||||||
|
{{- if .chart }}
|
||||||
|
{{- $termination = .chart.AppVersion | toString -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if .imageRoot.digest }}
|
||||||
|
{{- $separator = "@" -}}
|
||||||
|
{{- $termination = .imageRoot.digest | toString -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if $registryName }}
|
||||||
|
{{- printf "%s/%s%s%s" $registryName $repositoryName $separator $termination -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s%s%s" $repositoryName $separator $termination -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper Docker Image Registry Secret Names (deprecated: use common.images.renderPullSecrets instead)
|
||||||
|
{{ include "common.images.pullSecrets" ( dict "images" (list .Values.path.to.the.image1, .Values.path.to.the.image2) "global" .Values.global) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.images.pullSecrets" -}}
|
||||||
|
{{- $pullSecrets := list }}
|
||||||
|
|
||||||
|
{{- range ((.global).imagePullSecrets) -}}
|
||||||
|
{{- if kindIs "map" . -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets .name -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets . -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- range .images -}}
|
||||||
|
{{- range .pullSecrets -}}
|
||||||
|
{{- if kindIs "map" . -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets .name -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if (not (empty $pullSecrets)) -}}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- range $pullSecrets | uniq }}
|
||||||
|
- name: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper Docker Image Registry Secret Names evaluating values as templates
|
||||||
|
{{ include "common.images.renderPullSecrets" ( dict "images" (list .Values.path.to.the.image1, .Values.path.to.the.image2) "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.images.renderPullSecrets" -}}
|
||||||
|
{{- $pullSecrets := list }}
|
||||||
|
{{- $context := .context }}
|
||||||
|
|
||||||
|
{{- range (($context.Values.global).imagePullSecrets) -}}
|
||||||
|
{{- if kindIs "map" . -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets (include "common.tplvalues.render" (dict "value" .name "context" $context)) -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets (include "common.tplvalues.render" (dict "value" . "context" $context)) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- range .images -}}
|
||||||
|
{{- range .pullSecrets -}}
|
||||||
|
{{- if kindIs "map" . -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets (include "common.tplvalues.render" (dict "value" .name "context" $context)) -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $pullSecrets = append $pullSecrets (include "common.tplvalues.render" (dict "value" . "context" $context)) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if (not (empty $pullSecrets)) -}}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- range $pullSecrets | uniq }}
|
||||||
|
- name: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper image version (ingores image revision/prerelease info & fallbacks to chart appVersion)
|
||||||
|
{{ include "common.images.version" ( dict "imageRoot" .Values.path.to.the.image "chart" .Chart ) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.images.version" -}}
|
||||||
|
{{- $imageTag := .imageRoot.tag | toString -}}
|
||||||
|
{{/* regexp from https://github.com/mainminds/semver/blob/23f51de38a0866c5ef0bfc42b3f735c73107b700/version.go#L41-L44 */}}
|
||||||
|
{{- if regexMatch `^([0-9]+)(\.[0-9]+)?(\.[0-9]+)?(-([0-9A-Za-z\-]+(\.[0-9A-Za-z\-]+)*))?(\+([0-9A-Za-z\-]+(\.[0-9A-Za-z\-]+)*))?$` $imageTag -}}
|
||||||
|
{{- $version := semver $imageTag -}}
|
||||||
|
{{- printf "%d.%d.%d" $version.Major $version.Minor $version.Patch -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print .chart.AppVersion -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
73
cassandra/charts/common/templates/_ingress.tpl
Normal file
73
cassandra/charts/common/templates/_ingress.tpl
Normal file
@ -0,0 +1,73 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Generate backend entry that is compatible with all Kubernetes API versions.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.ingress.backend" (dict "serviceName" "backendName" "servicePort" "backendPort" "context" $) }}
|
||||||
|
|
||||||
|
Params:
|
||||||
|
- serviceName - String. Name of an existing service backend
|
||||||
|
- servicePort - String/Int. Port name (or number) of the service. It will be translated to different yaml depending if it is a string or an integer.
|
||||||
|
- context - Dict - Required. The context for the template evaluation.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.ingress.backend" -}}
|
||||||
|
{{- $apiVersion := (include "common.capabilities.ingress.apiVersion" .context) -}}
|
||||||
|
{{- if or (eq $apiVersion "extensions/v1beta1") (eq $apiVersion "networking.k8s.io/v1beta1") -}}
|
||||||
|
serviceName: {{ .serviceName }}
|
||||||
|
servicePort: {{ .servicePort }}
|
||||||
|
{{- else -}}
|
||||||
|
service:
|
||||||
|
name: {{ .serviceName }}
|
||||||
|
port:
|
||||||
|
{{- if typeIs "string" .servicePort }}
|
||||||
|
name: {{ .servicePort }}
|
||||||
|
{{- else if or (typeIs "int" .servicePort) (typeIs "float64" .servicePort) }}
|
||||||
|
number: {{ .servicePort | int }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Print "true" if the API pathType field is supported
|
||||||
|
Usage:
|
||||||
|
{{ include "common.ingress.supportsPathType" . }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.ingress.supportsPathType" -}}
|
||||||
|
{{- if (semverCompare "<1.18-0" (include "common.capabilities.kubeVersion" .)) -}}
|
||||||
|
{{- print "false" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "true" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Returns true if the ingressClassname field is supported
|
||||||
|
Usage:
|
||||||
|
{{ include "common.ingress.supportsIngressClassname" . }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.ingress.supportsIngressClassname" -}}
|
||||||
|
{{- if semverCompare "<1.18-0" (include "common.capabilities.kubeVersion" .) -}}
|
||||||
|
{{- print "false" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- print "true" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if cert-manager required annotations for TLS signed
|
||||||
|
certificates are set in the Ingress annotations
|
||||||
|
Ref: https://cert-manager.io/docs/usage/ingress/#supported-annotations
|
||||||
|
Usage:
|
||||||
|
{{ include "common.ingress.certManagerRequest" ( dict "annotations" .Values.path.to.the.ingress.annotations ) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.ingress.certManagerRequest" -}}
|
||||||
|
{{ if or (hasKey .annotations "cert-manager.io/cluster-issuer") (hasKey .annotations "cert-manager.io/issuer") (hasKey .annotations "kubernetes.io/tls-acme") }}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
46
cassandra/charts/common/templates/_labels.tpl
Normal file
46
cassandra/charts/common/templates/_labels.tpl
Normal file
@ -0,0 +1,46 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Kubernetes standard labels
|
||||||
|
{{ include "common.labels.standard" (dict "customLabels" .Values.commonLabels "context" $) -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.labels.standard" -}}
|
||||||
|
{{- if and (hasKey . "customLabels") (hasKey . "context") -}}
|
||||||
|
{{- $default := dict "app.kubernetes.io/name" (include "common.names.name" .context) "helm.sh/chart" (include "common.names.chart" .context) "app.kubernetes.io/instance" .context.Release.Name "app.kubernetes.io/managed-by" .context.Release.Service -}}
|
||||||
|
{{- with .context.Chart.AppVersion -}}
|
||||||
|
{{- $_ := set $default "app.kubernetes.io/version" . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{ template "common.tplvalues.merge" (dict "values" (list .customLabels $default) "context" .context) }}
|
||||||
|
{{- else -}}
|
||||||
|
app.kubernetes.io/name: {{ include "common.names.name" . }}
|
||||||
|
helm.sh/chart: {{ include "common.names.chart" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- with .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ . | quote }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Labels used on immutable fields such as deploy.spec.selector.matchLabels or svc.spec.selector
|
||||||
|
{{ include "common.labels.matchLabels" (dict "customLabels" .Values.podLabels "context" $) -}}
|
||||||
|
|
||||||
|
We don't want to loop over custom labels appending them to the selector
|
||||||
|
since it's very likely that it will break deployments, services, etc.
|
||||||
|
However, it's important to overwrite the standard labels if the user
|
||||||
|
overwrote them on metadata.labels fields.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.labels.matchLabels" -}}
|
||||||
|
{{- if and (hasKey . "customLabels") (hasKey . "context") -}}
|
||||||
|
{{ merge (pick (include "common.tplvalues.render" (dict "value" .customLabels "context" .context) | fromYaml) "app.kubernetes.io/name" "app.kubernetes.io/instance") (dict "app.kubernetes.io/name" (include "common.names.name" .context) "app.kubernetes.io/instance" .context.Release.Name ) | toYaml }}
|
||||||
|
{{- else -}}
|
||||||
|
app.kubernetes.io/name: {{ include "common.names.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
71
cassandra/charts/common/templates/_names.tpl
Normal file
71
cassandra/charts/common/templates/_names.tpl
Normal file
@ -0,0 +1,71 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.names.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.names.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.names.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride -}}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||||
|
{{- if contains $name .Release.Name -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified dependency name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
Usage:
|
||||||
|
{{ include "common.names.dependency.fullname" (dict "chartName" "dependency-chart-name" "chartValues" .Values.dependency-chart "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.names.dependency.fullname" -}}
|
||||||
|
{{- if .chartValues.fullnameOverride -}}
|
||||||
|
{{- .chartValues.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .chartName .chartValues.nameOverride -}}
|
||||||
|
{{- if contains $name .context.Release.Name -}}
|
||||||
|
{{- .context.Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-%s" .context.Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Allow the release namespace to be overridden for multi-namespace deployments in combined charts.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.names.namespace" -}}
|
||||||
|
{{- default .Release.Namespace .Values.namespaceOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a fully qualified app name adding the installation's namespace.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.names.fullname.namespace" -}}
|
||||||
|
{{- printf "%s-%s" (include "common.names.fullname" .) (include "common.names.namespace" .) | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
50
cassandra/charts/common/templates/_resources.tpl
Normal file
50
cassandra/charts/common/templates/_resources.tpl
Normal file
@ -0,0 +1,50 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return a resource request/limit object based on a given preset.
|
||||||
|
These presets are for basic testing and not meant to be used in production
|
||||||
|
{{ include "common.resources.preset" (dict "type" "nano") -}}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.resources.preset" -}}
|
||||||
|
{{/* The limits are the requests increased by 50% (except ephemeral-storage and xlarge/2xlarge sizes)*/}}
|
||||||
|
{{- $presets := dict
|
||||||
|
"nano" (dict
|
||||||
|
"requests" (dict "cpu" "100m" "memory" "128Mi" "ephemeral-storage" "50Mi")
|
||||||
|
"limits" (dict "cpu" "150m" "memory" "192Mi" "ephemeral-storage" "2Gi")
|
||||||
|
)
|
||||||
|
"micro" (dict
|
||||||
|
"requests" (dict "cpu" "250m" "memory" "256Mi" "ephemeral-storage" "50Mi")
|
||||||
|
"limits" (dict "cpu" "375m" "memory" "384Mi" "ephemeral-storage" "2Gi")
|
||||||
|
)
|
||||||
|
"small" (dict
|
||||||
|
"requests" (dict "cpu" "500m" "memory" "512Mi" "ephemeral-storage" "50Mi")
|
||||||
|
"limits" (dict "cpu" "750m" "memory" "768Mi" "ephemeral-storage" "2Gi")
|
||||||
|
)
|
||||||
|
"medium" (dict
|
||||||
|
"requests" (dict "cpu" "500m" "memory" "1024Mi" "ephemeral-storage" "50Mi")
|
||||||
|
"limits" (dict "cpu" "750m" "memory" "1536Mi" "ephemeral-storage" "2Gi")
|
||||||
|
)
|
||||||
|
"large" (dict
|
||||||
|
"requests" (dict "cpu" "1.0" "memory" "2048Mi" "ephemeral-storage" "50Mi")
|
||||||
|
"limits" (dict "cpu" "1.5" "memory" "3072Mi" "ephemeral-storage" "2Gi")
|
||||||
|
)
|
||||||
|
"xlarge" (dict
|
||||||
|
"requests" (dict "cpu" "1.0" "memory" "3072Mi" "ephemeral-storage" "50Mi")
|
||||||
|
"limits" (dict "cpu" "3.0" "memory" "6144Mi" "ephemeral-storage" "2Gi")
|
||||||
|
)
|
||||||
|
"2xlarge" (dict
|
||||||
|
"requests" (dict "cpu" "1.0" "memory" "3072Mi" "ephemeral-storage" "50Mi")
|
||||||
|
"limits" (dict "cpu" "6.0" "memory" "12288Mi" "ephemeral-storage" "2Gi")
|
||||||
|
)
|
||||||
|
}}
|
||||||
|
{{- if hasKey $presets .type -}}
|
||||||
|
{{- index $presets .type | toYaml -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "ERROR: Preset key '%s' invalid. Allowed values are %s" .type (join "," (keys $presets)) | fail -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
192
cassandra/charts/common/templates/_secrets.tpl
Normal file
192
cassandra/charts/common/templates/_secrets.tpl
Normal file
@ -0,0 +1,192 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Generate secret name.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.secrets.name" (dict "existingSecret" .Values.path.to.the.existingSecret "defaultNameSuffix" "mySuffix" "context" $) }}
|
||||||
|
|
||||||
|
Params:
|
||||||
|
- existingSecret - ExistingSecret/String - Optional. The path to the existing secrets in the values.yaml given by the user
|
||||||
|
to be used instead of the default one. Allows for it to be of type String (just the secret name) for backwards compatibility.
|
||||||
|
+info: https://github.com/bitnami/charts/tree/main/bitnami/common#existingsecret
|
||||||
|
- defaultNameSuffix - String - Optional. It is used only if we have several secrets in the same deployment.
|
||||||
|
- context - Dict - Required. The context for the template evaluation.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.secrets.name" -}}
|
||||||
|
{{- $name := (include "common.names.fullname" .context) -}}
|
||||||
|
|
||||||
|
{{- if .defaultNameSuffix -}}
|
||||||
|
{{- $name = printf "%s-%s" $name .defaultNameSuffix | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- with .existingSecret -}}
|
||||||
|
{{- if not (typeIs "string" .) -}}
|
||||||
|
{{- with .name -}}
|
||||||
|
{{- $name = . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name = . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- printf "%s" $name -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Generate secret key.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.secrets.key" (dict "existingSecret" .Values.path.to.the.existingSecret "key" "keyName") }}
|
||||||
|
|
||||||
|
Params:
|
||||||
|
- existingSecret - ExistingSecret/String - Optional. The path to the existing secrets in the values.yaml given by the user
|
||||||
|
to be used instead of the default one. Allows for it to be of type String (just the secret name) for backwards compatibility.
|
||||||
|
+info: https://github.com/bitnami/charts/tree/main/bitnami/common#existingsecret
|
||||||
|
- key - String - Required. Name of the key in the secret.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.secrets.key" -}}
|
||||||
|
{{- $key := .key -}}
|
||||||
|
|
||||||
|
{{- if .existingSecret -}}
|
||||||
|
{{- if not (typeIs "string" .existingSecret) -}}
|
||||||
|
{{- if .existingSecret.keyMapping -}}
|
||||||
|
{{- $key = index .existingSecret.keyMapping $.key -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- printf "%s" $key -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Generate secret password or retrieve one if already created.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.secrets.passwords.manage" (dict "secret" "secret-name" "key" "keyName" "providedValues" (list "path.to.password1" "path.to.password2") "length" 10 "strong" false "chartName" "chartName" "honorProvidedValues" false "context" $) }}
|
||||||
|
|
||||||
|
Params:
|
||||||
|
- secret - String - Required - Name of the 'Secret' resource where the password is stored.
|
||||||
|
- key - String - Required - Name of the key in the secret.
|
||||||
|
- providedValues - List<String> - Required - The path to the validating value in the values.yaml, e.g: "mysql.password". Will pick first parameter with a defined value.
|
||||||
|
- length - int - Optional - Length of the generated random password.
|
||||||
|
- strong - Boolean - Optional - Whether to add symbols to the generated random password.
|
||||||
|
- chartName - String - Optional - Name of the chart used when said chart is deployed as a subchart.
|
||||||
|
- context - Context - Required - Parent context.
|
||||||
|
- failOnNew - Boolean - Optional - Default to true. If set to false, skip errors adding new keys to existing secrets.
|
||||||
|
- skipB64enc - Boolean - Optional - Default to false. If set to true, no the secret will not be base64 encrypted.
|
||||||
|
- skipQuote - Boolean - Optional - Default to false. If set to true, no quotes will be added around the secret.
|
||||||
|
- honorProvidedValues - Boolean - Optional - Default to false. If set to true, the values in providedValues have higher priority than an existing secret
|
||||||
|
The order in which this function returns a secret password:
|
||||||
|
1. Password provided via the values.yaml if honorProvidedValues = true
|
||||||
|
(If one of the keys passed to the 'providedValues' parameter to this function is a valid path to a key in the values.yaml and has a value, the value of the first key with a value will be returned)
|
||||||
|
2. Already existing 'Secret' resource
|
||||||
|
(If a 'Secret' resource is found under the name provided to the 'secret' parameter to this function and that 'Secret' resource contains a key with the name passed as the 'key' parameter to this function then the value of this existing secret password will be returned)
|
||||||
|
3. Password provided via the values.yaml if honorProvidedValues = false
|
||||||
|
(If one of the keys passed to the 'providedValues' parameter to this function is a valid path to a key in the values.yaml and has a value, the value of the first key with a value will be returned)
|
||||||
|
4. Randomly generated secret password
|
||||||
|
(A new random secret password with the length specified in the 'length' parameter will be generated and returned)
|
||||||
|
|
||||||
|
*/}}
|
||||||
|
{{- define "common.secrets.passwords.manage" -}}
|
||||||
|
|
||||||
|
{{- $password := "" }}
|
||||||
|
{{- $subchart := "" }}
|
||||||
|
{{- $chartName := default "" .chartName }}
|
||||||
|
{{- $passwordLength := default 10 .length }}
|
||||||
|
{{- $providedPasswordKey := include "common.utils.getKeyFromList" (dict "keys" .providedValues "context" $.context) }}
|
||||||
|
{{- $providedPasswordValue := include "common.utils.getValueFromKey" (dict "key" $providedPasswordKey "context" $.context) }}
|
||||||
|
{{- $secretData := (lookup "v1" "Secret" (include "common.names.namespace" .context) .secret).data }}
|
||||||
|
{{- if $secretData }}
|
||||||
|
{{- if hasKey $secretData .key }}
|
||||||
|
{{- $password = index $secretData .key | b64dec }}
|
||||||
|
{{- else if not (eq .failOnNew false) }}
|
||||||
|
{{- printf "\nPASSWORDS ERROR: The secret \"%s\" does not contain the key \"%s\"\n" .secret .key | fail -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- if and $providedPasswordValue .honorProvidedValues }}
|
||||||
|
{{- $password = $providedPasswordValue | toString }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- if not $password }}
|
||||||
|
{{- if $providedPasswordValue }}
|
||||||
|
{{- $password = $providedPasswordValue | toString }}
|
||||||
|
{{- else }}
|
||||||
|
{{- if .context.Values.enabled }}
|
||||||
|
{{- $subchart = $chartName }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if not (eq .failOnNew false) }}
|
||||||
|
{{- $requiredPassword := dict "valueKey" $providedPasswordKey "secret" .secret "field" .key "subchart" $subchart "context" $.context -}}
|
||||||
|
{{- $requiredPasswordError := include "common.validations.values.single.empty" $requiredPassword -}}
|
||||||
|
{{- $passwordValidationErrors := list $requiredPasswordError -}}
|
||||||
|
{{- include "common.errors.upgrade.passwords.empty" (dict "validationErrors" $passwordValidationErrors "context" $.context) -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- if .strong }}
|
||||||
|
{{- $subStr := list (lower (randAlpha 1)) (randNumeric 1) (upper (randAlpha 1)) | join "_" }}
|
||||||
|
{{- $password = randAscii $passwordLength }}
|
||||||
|
{{- $password = regexReplaceAllLiteral "\\W" $password "@" | substr 5 $passwordLength }}
|
||||||
|
{{- $password = printf "%s%s" $subStr $password | toString | shuffle }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $password = randAlphaNum $passwordLength }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if not .skipB64enc }}
|
||||||
|
{{- $password = $password | b64enc }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if .skipQuote -}}
|
||||||
|
{{- printf "%s" $password -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s" $password | quote -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Reuses the value from an existing secret, otherwise sets its value to a default value.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.secrets.lookup" (dict "secret" "secret-name" "key" "keyName" "defaultValue" .Values.myValue "context" $) }}
|
||||||
|
|
||||||
|
Params:
|
||||||
|
- secret - String - Required - Name of the 'Secret' resource where the password is stored.
|
||||||
|
- key - String - Required - Name of the key in the secret.
|
||||||
|
- defaultValue - String - Required - The path to the validating value in the values.yaml, e.g: "mysql.password". Will pick first parameter with a defined value.
|
||||||
|
- context - Context - Required - Parent context.
|
||||||
|
|
||||||
|
*/}}
|
||||||
|
{{- define "common.secrets.lookup" -}}
|
||||||
|
{{- $value := "" -}}
|
||||||
|
{{- $secretData := (lookup "v1" "Secret" (include "common.names.namespace" .context) .secret).data -}}
|
||||||
|
{{- if and $secretData (hasKey $secretData .key) -}}
|
||||||
|
{{- $value = index $secretData .key -}}
|
||||||
|
{{- else if .defaultValue -}}
|
||||||
|
{{- $value = .defaultValue | toString | b64enc -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if $value -}}
|
||||||
|
{{- printf "%s" $value -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Returns whether a previous generated secret already exists
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.secrets.exists" (dict "secret" "secret-name" "context" $) }}
|
||||||
|
|
||||||
|
Params:
|
||||||
|
- secret - String - Required - Name of the 'Secret' resource where the password is stored.
|
||||||
|
- context - Context - Required - Parent context.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.secrets.exists" -}}
|
||||||
|
{{- $secret := (lookup "v1" "Secret" (include "common.names.namespace" .context) .secret) }}
|
||||||
|
{{- if $secret }}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
21
cassandra/charts/common/templates/_storage.tpl
Normal file
21
cassandra/charts/common/templates/_storage.tpl
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper Storage Class
|
||||||
|
{{ include "common.storage.class" ( dict "persistence" .Values.path.to.the.persistence "global" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.storage.class" -}}
|
||||||
|
{{- $storageClass := (.global).storageClass | default .persistence.storageClass | default (.global).defaultStorageClass | default "" -}}
|
||||||
|
{{- if $storageClass -}}
|
||||||
|
{{- if (eq "-" $storageClass) -}}
|
||||||
|
{{- printf "storageClassName: \"\"" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "storageClassName: %s" $storageClass -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
52
cassandra/charts/common/templates/_tplvalues.tpl
Normal file
52
cassandra/charts/common/templates/_tplvalues.tpl
Normal file
@ -0,0 +1,52 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Renders a value that contains template perhaps with scope if the scope is present.
|
||||||
|
Usage:
|
||||||
|
{{ include "common.tplvalues.render" ( dict "value" .Values.path.to.the.Value "context" $ ) }}
|
||||||
|
{{ include "common.tplvalues.render" ( dict "value" .Values.path.to.the.Value "context" $ "scope" $app ) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.tplvalues.render" -}}
|
||||||
|
{{- $value := typeIs "string" .value | ternary .value (.value | toYaml) }}
|
||||||
|
{{- if contains "{{" (toJson .value) }}
|
||||||
|
{{- if .scope }}
|
||||||
|
{{- tpl (cat "{{- with $.RelativeScope -}}" $value "{{- end }}") (merge (dict "RelativeScope" .scope) .context) }}
|
||||||
|
{{- else }}
|
||||||
|
{{- tpl $value .context }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Merge a list of values that contains template after rendering them.
|
||||||
|
Merge precedence is consistent with http://mainminds.github.io/sprig/dicts.html#merge-mustmerge
|
||||||
|
Usage:
|
||||||
|
{{ include "common.tplvalues.merge" ( dict "values" (list .Values.path.to.the.Value1 .Values.path.to.the.Value2) "context" $ ) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.tplvalues.merge" -}}
|
||||||
|
{{- $dst := dict -}}
|
||||||
|
{{- range .values -}}
|
||||||
|
{{- $dst = include "common.tplvalues.render" (dict "value" . "context" $.context "scope" $.scope) | fromYaml | merge $dst -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{ $dst | toYaml }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Merge a list of values that contains template after rendering them.
|
||||||
|
Merge precedence is consistent with https://mainminds.github.io/sprig/dicts.html#mergeoverwrite-mustmergeoverwrite
|
||||||
|
Usage:
|
||||||
|
{{ include "common.tplvalues.merge-overwrite" ( dict "values" (list .Values.path.to.the.Value1 .Values.path.to.the.Value2) "context" $ ) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.tplvalues.merge-overwrite" -}}
|
||||||
|
{{- $dst := dict -}}
|
||||||
|
{{- range .values -}}
|
||||||
|
{{- $dst = include "common.tplvalues.render" (dict "value" . "context" $.context "scope" $.scope) | fromYaml | mergeOverwrite $dst -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{ $dst | toYaml }}
|
||||||
|
{{- end -}}
|
||||||
77
cassandra/charts/common/templates/_utils.tpl
Normal file
77
cassandra/charts/common/templates/_utils.tpl
Normal file
@ -0,0 +1,77 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Print instructions to get a secret value.
|
||||||
|
Usage:
|
||||||
|
{{ include "common.utils.secret.getvalue" (dict "secret" "secret-name" "field" "secret-value-field" "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.utils.secret.getvalue" -}}
|
||||||
|
{{- $varname := include "common.utils.fieldToEnvVar" . -}}
|
||||||
|
export {{ $varname }}=$(kubectl get secret --namespace {{ include "common.names.namespace" .context | quote }} {{ .secret }} -o jsonpath="{.data.{{ .field }}}" | base64 -d)
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Build env var name given a field
|
||||||
|
Usage:
|
||||||
|
{{ include "common.utils.fieldToEnvVar" dict "field" "my-password" }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.utils.fieldToEnvVar" -}}
|
||||||
|
{{- $fieldNameSplit := splitList "-" .field -}}
|
||||||
|
{{- $upperCaseFieldNameSplit := list -}}
|
||||||
|
|
||||||
|
{{- range $fieldNameSplit -}}
|
||||||
|
{{- $upperCaseFieldNameSplit = append $upperCaseFieldNameSplit ( upper . ) -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{ join "_" $upperCaseFieldNameSplit }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Gets a value from .Values given
|
||||||
|
Usage:
|
||||||
|
{{ include "common.utils.getValueFromKey" (dict "key" "path.to.key" "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.utils.getValueFromKey" -}}
|
||||||
|
{{- $splitKey := splitList "." .key -}}
|
||||||
|
{{- $value := "" -}}
|
||||||
|
{{- $latestObj := $.context.Values -}}
|
||||||
|
{{- range $splitKey -}}
|
||||||
|
{{- if not $latestObj -}}
|
||||||
|
{{- printf "please review the entire path of '%s' exists in values" $.key | fail -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- $value = ( index $latestObj . ) -}}
|
||||||
|
{{- $latestObj = $value -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- printf "%v" (default "" $value) -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Returns first .Values key with a defined value or first of the list if all non-defined
|
||||||
|
Usage:
|
||||||
|
{{ include "common.utils.getKeyFromList" (dict "keys" (list "path.to.key1" "path.to.key2") "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.utils.getKeyFromList" -}}
|
||||||
|
{{- $key := first .keys -}}
|
||||||
|
{{- $reverseKeys := reverse .keys }}
|
||||||
|
{{- range $reverseKeys }}
|
||||||
|
{{- $value := include "common.utils.getValueFromKey" (dict "key" . "context" $.context ) }}
|
||||||
|
{{- if $value -}}
|
||||||
|
{{- $key = . }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- printf "%s" $key -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Checksum a template at "path" containing a *single* resource (ConfigMap,Secret) for use in pod annotations, excluding the metadata (see #18376).
|
||||||
|
Usage:
|
||||||
|
{{ include "common.utils.checksumTemplate" (dict "path" "/configmap.yaml" "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.utils.checksumTemplate" -}}
|
||||||
|
{{- $obj := include (print .context.Template.BasePath .path) .context | fromYaml -}}
|
||||||
|
{{ omit $obj "apiVersion" "kind" "metadata" | toYaml | sha256sum }}
|
||||||
|
{{- end -}}
|
||||||
109
cassandra/charts/common/templates/_warnings.tpl
Normal file
109
cassandra/charts/common/templates/_warnings.tpl
Normal file
@ -0,0 +1,109 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Warning about using rolling tag.
|
||||||
|
Usage:
|
||||||
|
{{ include "common.warnings.rollingTag" .Values.path.to.the.imageRoot }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.warnings.rollingTag" -}}
|
||||||
|
|
||||||
|
{{- if and (contains "bitnami/" .repository) (not (.tag | toString | regexFind "-r\\d+$|sha256:")) }}
|
||||||
|
WARNING: Rolling tag detected ({{ .repository }}:{{ .tag }}), please note that it is strongly recommended to avoid using rolling tags in a production environment.
|
||||||
|
+info https://techdocs.broadcom.com/us/en/vmware-tanzu/application-catalog/tanzu-application-catalog/services/tac-doc/apps-tutorials-understand-rolling-tags-containers-index.html
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Warning about replaced images from the original.
|
||||||
|
Usage:
|
||||||
|
{{ include "common.warnings.modifiedImages" (dict "images" (list .Values.path.to.the.imageRoot) "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.warnings.modifiedImages" -}}
|
||||||
|
{{- $affectedImages := list -}}
|
||||||
|
{{- $printMessage := false -}}
|
||||||
|
{{- $originalImages := .context.Chart.Annotations.images -}}
|
||||||
|
{{- range .images -}}
|
||||||
|
{{- $fullImageName := printf (printf "%s/%s:%s" .registry .repository .tag) -}}
|
||||||
|
{{- if not (contains $fullImageName $originalImages) }}
|
||||||
|
{{- $affectedImages = append $affectedImages (printf "%s/%s:%s" .registry .repository .tag) -}}
|
||||||
|
{{- $printMessage = true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if $printMessage }}
|
||||||
|
|
||||||
|
⚠ SECURITY WARNING: Original containers have been substituted. This Helm chart was designed, tested, and validated on multiple platforms using a specific set of Bitnami and Tanzu Application Catalog containers. Substituting other containers is likely to cause degraded security and performance, broken chart features, and missing environment variables.
|
||||||
|
|
||||||
|
Substituted images detected:
|
||||||
|
{{- range $affectedImages }}
|
||||||
|
- {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Warning about not setting the resource object in all deployments.
|
||||||
|
Usage:
|
||||||
|
{{ include "common.warnings.resources" (dict "sections" (list "path1" "path2") context $) }}
|
||||||
|
Example:
|
||||||
|
{{- include "common.warnings.resources" (dict "sections" (list "csiProvider.provider" "server" "volumePermissions" "") "context" $) }}
|
||||||
|
The list in the example assumes that the following values exist:
|
||||||
|
- csiProvider.provider.resources
|
||||||
|
- server.resources
|
||||||
|
- volumePermissions.resources
|
||||||
|
- resources
|
||||||
|
*/}}
|
||||||
|
{{- define "common.warnings.resources" -}}
|
||||||
|
{{- $values := .context.Values -}}
|
||||||
|
{{- $printMessage := false -}}
|
||||||
|
{{ $affectedSections := list -}}
|
||||||
|
{{- range .sections -}}
|
||||||
|
{{- if eq . "" -}}
|
||||||
|
{{/* Case where the resources section is at the root (one main deployment in the chart) */}}
|
||||||
|
{{- if not (index $values "resources") -}}
|
||||||
|
{{- $affectedSections = append $affectedSections "resources" -}}
|
||||||
|
{{- $printMessage = true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{/* Case where the are multiple resources sections (more than one main deployment in the chart) */}}
|
||||||
|
{{- $keys := split "." . -}}
|
||||||
|
{{/* We iterate through the different levels until arriving to the resource section. Example: a.b.c.resources */}}
|
||||||
|
{{- $section := $values -}}
|
||||||
|
{{- range $keys -}}
|
||||||
|
{{- $section = index $section . -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if not (index $section "resources") -}}
|
||||||
|
{{/* If the section has enabled=false or replicaCount=0, do not include it */}}
|
||||||
|
{{- if and (hasKey $section "enabled") -}}
|
||||||
|
{{- if index $section "enabled" -}}
|
||||||
|
{{/* enabled=true */}}
|
||||||
|
{{- $affectedSections = append $affectedSections (printf "%s.resources" .) -}}
|
||||||
|
{{- $printMessage = true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- else if and (hasKey $section "replicaCount") -}}
|
||||||
|
{{/* We need a casting to int because number 0 is not treated as an int by default */}}
|
||||||
|
{{- if (gt (index $section "replicaCount" | int) 0) -}}
|
||||||
|
{{/* replicaCount > 0 */}}
|
||||||
|
{{- $affectedSections = append $affectedSections (printf "%s.resources" .) -}}
|
||||||
|
{{- $printMessage = true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{/* Default case, add it to the affected sections */}}
|
||||||
|
{{- $affectedSections = append $affectedSections (printf "%s.resources" .) -}}
|
||||||
|
{{- $printMessage = true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if $printMessage }}
|
||||||
|
|
||||||
|
WARNING: There are "resources" sections in the chart not set. Using "resourcesPreset" is not recommended for production. For production installations, please set the following values according to your workload needs:
|
||||||
|
{{- range $affectedSections }}
|
||||||
|
- {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
+info https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
51
cassandra/charts/common/templates/validations/_cassandra.tpl
Normal file
51
cassandra/charts/common/templates/validations/_cassandra.tpl
Normal file
@ -0,0 +1,51 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for existingSecret.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.cassandra.values.existingSecret" (dict "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether Cassandra is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.cassandra.values.existingSecret" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- .context.Values.cassandra.dbUser.existingSecret | quote -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .context.Values.dbUser.existingSecret | quote -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for enabled cassandra.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.cassandra.values.enabled" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.cassandra.values.enabled" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- printf "%v" .context.Values.cassandra.enabled -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%v" (not .context.Values.enabled) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for the key dbUser
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.cassandra.values.key.dbUser" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether Cassandra is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.cassandra.values.key.dbUser" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
cassandra.dbUser
|
||||||
|
{{- else -}}
|
||||||
|
dbUser
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
108
cassandra/charts/common/templates/validations/_mariadb.tpl
Normal file
108
cassandra/charts/common/templates/validations/_mariadb.tpl
Normal file
@ -0,0 +1,108 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Validate MariaDB required passwords are not empty.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.validations.values.mariadb.passwords" (dict "secret" "secretName" "subchart" false "context" $) }}
|
||||||
|
Params:
|
||||||
|
- secret - String - Required. Name of the secret where MariaDB values are stored, e.g: "mysql-passwords-secret"
|
||||||
|
- subchart - Boolean - Optional. Whether MariaDB is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.validations.values.mariadb.passwords" -}}
|
||||||
|
{{- $existingSecret := include "common.mariadb.values.auth.existingSecret" . -}}
|
||||||
|
{{- $enabled := include "common.mariadb.values.enabled" . -}}
|
||||||
|
{{- $architecture := include "common.mariadb.values.architecture" . -}}
|
||||||
|
{{- $authPrefix := include "common.mariadb.values.key.auth" . -}}
|
||||||
|
{{- $valueKeyRootPassword := printf "%s.rootPassword" $authPrefix -}}
|
||||||
|
{{- $valueKeyUsername := printf "%s.username" $authPrefix -}}
|
||||||
|
{{- $valueKeyPassword := printf "%s.password" $authPrefix -}}
|
||||||
|
{{- $valueKeyReplicationPassword := printf "%s.replicationPassword" $authPrefix -}}
|
||||||
|
|
||||||
|
{{- if and (or (not $existingSecret) (eq $existingSecret "\"\"")) (eq $enabled "true") -}}
|
||||||
|
{{- $requiredPasswords := list -}}
|
||||||
|
|
||||||
|
{{- $requiredRootPassword := dict "valueKey" $valueKeyRootPassword "secret" .secret "field" "mariadb-root-password" -}}
|
||||||
|
{{- $requiredPasswords = append $requiredPasswords $requiredRootPassword -}}
|
||||||
|
|
||||||
|
{{- $valueUsername := include "common.utils.getValueFromKey" (dict "key" $valueKeyUsername "context" .context) }}
|
||||||
|
{{- if not (empty $valueUsername) -}}
|
||||||
|
{{- $requiredPassword := dict "valueKey" $valueKeyPassword "secret" .secret "field" "mariadb-password" -}}
|
||||||
|
{{- $requiredPasswords = append $requiredPasswords $requiredPassword -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if (eq $architecture "replication") -}}
|
||||||
|
{{- $requiredReplicationPassword := dict "valueKey" $valueKeyReplicationPassword "secret" .secret "field" "mariadb-replication-password" -}}
|
||||||
|
{{- $requiredPasswords = append $requiredPasswords $requiredReplicationPassword -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- include "common.validations.values.multiple.empty" (dict "required" $requiredPasswords "context" .context) -}}
|
||||||
|
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for existingSecret.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mariadb.values.auth.existingSecret" (dict "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MariaDB is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mariadb.values.auth.existingSecret" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- .context.Values.mariadb.auth.existingSecret | quote -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .context.Values.auth.existingSecret | quote -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for enabled mariadb.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mariadb.values.enabled" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mariadb.values.enabled" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- printf "%v" .context.Values.mariadb.enabled -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%v" (not .context.Values.enabled) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for architecture
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mariadb.values.architecture" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MariaDB is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mariadb.values.architecture" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- .context.Values.mariadb.architecture -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .context.Values.architecture -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for the key auth
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mariadb.values.key.auth" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MariaDB is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mariadb.values.key.auth" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
mariadb.auth
|
||||||
|
{{- else -}}
|
||||||
|
auth
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
67
cassandra/charts/common/templates/validations/_mongodb.tpl
Normal file
67
cassandra/charts/common/templates/validations/_mongodb.tpl
Normal file
@ -0,0 +1,67 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for existingSecret.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mongodb.values.auth.existingSecret" (dict "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MongoDb is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mongodb.values.auth.existingSecret" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- .context.Values.mongodb.auth.existingSecret | quote -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .context.Values.auth.existingSecret | quote -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for enabled mongodb.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mongodb.values.enabled" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mongodb.values.enabled" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- printf "%v" .context.Values.mongodb.enabled -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%v" (not .context.Values.enabled) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for the key auth
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mongodb.values.key.auth" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MongoDB® is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mongodb.values.key.auth" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
mongodb.auth
|
||||||
|
{{- else -}}
|
||||||
|
auth
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for architecture
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mongodb.values.architecture" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MongoDB® is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mongodb.values.architecture" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- .context.Values.mongodb.architecture -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .context.Values.architecture -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
67
cassandra/charts/common/templates/validations/_mysql.tpl
Normal file
67
cassandra/charts/common/templates/validations/_mysql.tpl
Normal file
@ -0,0 +1,67 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for existingSecret.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mysql.values.auth.existingSecret" (dict "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MySQL is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mysql.values.auth.existingSecret" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- .context.Values.mysql.auth.existingSecret | quote -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .context.Values.auth.existingSecret | quote -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for enabled mysql.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mysql.values.enabled" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mysql.values.enabled" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- printf "%v" .context.Values.mysql.enabled -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%v" (not .context.Values.enabled) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for architecture
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mysql.values.architecture" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MySQL is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mysql.values.architecture" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- .context.Values.mysql.architecture -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .context.Values.architecture -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for the key auth
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.mysql.values.key.auth" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether MySQL is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.mysql.values.key.auth" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
mysql.auth
|
||||||
|
{{- else -}}
|
||||||
|
auth
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
105
cassandra/charts/common/templates/validations/_postgresql.tpl
Normal file
105
cassandra/charts/common/templates/validations/_postgresql.tpl
Normal file
@ -0,0 +1,105 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to decide whether evaluate global values.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.postgresql.values.use.global" (dict "key" "key-of-global" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- key - String - Required. Field to be evaluated within global, e.g: "existingSecret"
|
||||||
|
*/}}
|
||||||
|
{{- define "common.postgresql.values.use.global" -}}
|
||||||
|
{{- if .context.Values.global -}}
|
||||||
|
{{- if .context.Values.global.postgresql -}}
|
||||||
|
{{- index .context.Values.global.postgresql .key | quote -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for existingSecret.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.postgresql.values.existingSecret" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.postgresql.values.existingSecret" -}}
|
||||||
|
{{- $globalValue := include "common.postgresql.values.use.global" (dict "key" "existingSecret" "context" .context) -}}
|
||||||
|
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- default (.context.Values.postgresql.existingSecret | quote) $globalValue -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- default (.context.Values.existingSecret | quote) $globalValue -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for enabled postgresql.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.postgresql.values.enabled" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.postgresql.values.enabled" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- printf "%v" .context.Values.postgresql.enabled -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%v" (not .context.Values.enabled) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for the key postgressPassword.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.postgresql.values.key.postgressPassword" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether postgresql is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.postgresql.values.key.postgressPassword" -}}
|
||||||
|
{{- $globalValue := include "common.postgresql.values.use.global" (dict "key" "postgresqlUsername" "context" .context) -}}
|
||||||
|
|
||||||
|
{{- if not $globalValue -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
postgresql.postgresqlPassword
|
||||||
|
{{- else -}}
|
||||||
|
postgresqlPassword
|
||||||
|
{{- end -}}
|
||||||
|
{{- else -}}
|
||||||
|
global.postgresql.postgresqlPassword
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for enabled.replication.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.postgresql.values.enabled.replication" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether postgresql is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.postgresql.values.enabled.replication" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- printf "%v" .context.Values.postgresql.replication.enabled -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%v" .context.Values.replication.enabled -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for the key replication.password.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.postgresql.values.key.replicationPassword" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether postgresql is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.postgresql.values.key.replicationPassword" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
postgresql.replication.password
|
||||||
|
{{- else -}}
|
||||||
|
replication.password
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
48
cassandra/charts/common/templates/validations/_redis.tpl
Normal file
48
cassandra/charts/common/templates/validations/_redis.tpl
Normal file
@ -0,0 +1,48 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right value for enabled redis.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.redis.values.enabled" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.redis.values.enabled" -}}
|
||||||
|
{{- if .subchart -}}
|
||||||
|
{{- printf "%v" .context.Values.redis.enabled -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%v" (not .context.Values.enabled) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Auxiliary function to get the right prefix path for the values
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.redis.values.key.prefix" (dict "subchart" "true" "context" $) }}
|
||||||
|
Params:
|
||||||
|
- subchart - Boolean - Optional. Whether redis is used as subchart or not. Default: false
|
||||||
|
*/}}
|
||||||
|
{{- define "common.redis.values.keys.prefix" -}}
|
||||||
|
{{- if .subchart -}}redis.{{- else -}}{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Checks whether the redis chart's includes the standarizations (version >= 14)
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.redis.values.standarized.version" (dict "context" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "common.redis.values.standarized.version" -}}
|
||||||
|
|
||||||
|
{{- $standarizedAuth := printf "%s%s" (include "common.redis.values.keys.prefix" .) "auth" -}}
|
||||||
|
{{- $standarizedAuthValues := include "common.utils.getValueFromKey" (dict "key" $standarizedAuth "context" .context) }}
|
||||||
|
|
||||||
|
{{- if $standarizedAuthValues -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
@ -0,0 +1,51 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Validate values must not be empty.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{- $validateValueConf00 := (dict "valueKey" "path.to.value" "secret" "secretName" "field" "password-00") -}}
|
||||||
|
{{- $validateValueConf01 := (dict "valueKey" "path.to.value" "secret" "secretName" "field" "password-01") -}}
|
||||||
|
{{ include "common.validations.values.empty" (dict "required" (list $validateValueConf00 $validateValueConf01) "context" $) }}
|
||||||
|
|
||||||
|
Validate value params:
|
||||||
|
- valueKey - String - Required. The path to the validating value in the values.yaml, e.g: "mysql.password"
|
||||||
|
- secret - String - Optional. Name of the secret where the validating value is generated/stored, e.g: "mysql-passwords-secret"
|
||||||
|
- field - String - Optional. Name of the field in the secret data, e.g: "mysql-password"
|
||||||
|
*/}}
|
||||||
|
{{- define "common.validations.values.multiple.empty" -}}
|
||||||
|
{{- range .required -}}
|
||||||
|
{{- include "common.validations.values.single.empty" (dict "valueKey" .valueKey "secret" .secret "field" .field "context" $.context) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Validate a value must not be empty.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
{{ include "common.validations.value.empty" (dict "valueKey" "mariadb.password" "secret" "secretName" "field" "my-password" "subchart" "subchart" "context" $) }}
|
||||||
|
|
||||||
|
Validate value params:
|
||||||
|
- valueKey - String - Required. The path to the validating value in the values.yaml, e.g: "mysql.password"
|
||||||
|
- secret - String - Optional. Name of the secret where the validating value is generated/stored, e.g: "mysql-passwords-secret"
|
||||||
|
- field - String - Optional. Name of the field in the secret data, e.g: "mysql-password"
|
||||||
|
- subchart - String - Optional - Name of the subchart that the validated password is part of.
|
||||||
|
*/}}
|
||||||
|
{{- define "common.validations.values.single.empty" -}}
|
||||||
|
{{- $value := include "common.utils.getValueFromKey" (dict "key" .valueKey "context" .context) }}
|
||||||
|
{{- $subchart := ternary "" (printf "%s." .subchart) (empty .subchart) }}
|
||||||
|
|
||||||
|
{{- if not $value -}}
|
||||||
|
{{- $varname := "my-value" -}}
|
||||||
|
{{- $getCurrentValue := "" -}}
|
||||||
|
{{- if and .secret .field -}}
|
||||||
|
{{- $varname = include "common.utils.fieldToEnvVar" . -}}
|
||||||
|
{{- $getCurrentValue = printf " To get the current value:\n\n %s\n" (include "common.utils.secret.getvalue" .) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- printf "\n '%s' must not be empty, please add '--set %s%s=$%s' to the command.%s" .valueKey $subchart .valueKey $varname $getCurrentValue -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
8
cassandra/charts/common/values.yaml
Normal file
8
cassandra/charts/common/values.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
# Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
# SPDX-License-Identifier: APACHE-2.0
|
||||||
|
|
||||||
|
## bitnami/common
|
||||||
|
## It is required by CI/CD tools and processes.
|
||||||
|
## @skip exampleValue
|
||||||
|
##
|
||||||
|
exampleValue: common-chart
|
||||||
96
cassandra/templates/NOTES.txt
Normal file
96
cassandra/templates/NOTES.txt
Normal file
@ -0,0 +1,96 @@
|
|||||||
|
CHART NAME: {{ .Chart.Name }}
|
||||||
|
CHART VERSION: {{ .Chart.Version }}
|
||||||
|
APP VERSION: {{ .Chart.AppVersion }}
|
||||||
|
|
||||||
|
Did you know there are enterprise versions of the Bitnami catalog? For enhanced secure software supply chain features, unlimited pulls from Docker, LTS support, or application customization, see Bitnami Premium or Tanzu Application Catalog. See https://www.arrow.com/globalecs/na/vendors/bitnami for more information.
|
||||||
|
|
||||||
|
{{- $cassandraPasswordKey := ( include "common.secrets.key" (dict "existingSecret" .Values.dbUser.existingSecret "key" "cassandra-password") ) -}}
|
||||||
|
{{- $cassandraSecretName := ( include "common.secrets.name" (dict "existingSecret" .Values.dbUser.existingSecret "context" $) ) -}}
|
||||||
|
|
||||||
|
** Please be patient while the chart is being deployed **
|
||||||
|
|
||||||
|
{{- if .Values.diagnosticMode.enabled }}
|
||||||
|
The chart has been deployed in diagnostic mode. All probes have been disabled and the command has been overwritten with:
|
||||||
|
|
||||||
|
command: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 4 }}
|
||||||
|
args: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 4 }}
|
||||||
|
|
||||||
|
Get the list of pods by executing:
|
||||||
|
|
||||||
|
kubectl get pods --namespace {{ include "common.names.namespace" . }} -l app.kubernetes.io/instance={{ .Release.Name }}
|
||||||
|
|
||||||
|
Access the pod you want to debug by executing
|
||||||
|
|
||||||
|
kubectl exec --namespace {{ include "common.names.namespace" . }} -ti <NAME OF THE POD> -- bash
|
||||||
|
|
||||||
|
In order to replicate the container startup scripts execute this command:
|
||||||
|
|
||||||
|
/opt/bitnami/scripts/cassandra/entrypoint.sh /opt/bitnami/scripts/cassandra/run.sh
|
||||||
|
|
||||||
|
{{- else }}
|
||||||
|
|
||||||
|
Cassandra can be accessed through the following URLs from within the cluster:
|
||||||
|
|
||||||
|
- CQL: {{ include "common.names.fullname" . }}.{{ include "common.names.namespace" . }}.svc.{{ .Values.clusterDomain }}:{{ .Values.service.ports.cql }}
|
||||||
|
|
||||||
|
To get your password run:
|
||||||
|
|
||||||
|
{{ include "common.utils.secret.getvalue" (dict "secret" $cassandraSecretName "field" $cassandraPasswordKey "context" $) }}
|
||||||
|
|
||||||
|
Check the cluster status by running:
|
||||||
|
|
||||||
|
kubectl exec -it --namespace {{ include "common.names.namespace" . }} $(kubectl get pods --namespace {{ include "common.names.namespace" . }} -l app.kubernetes.io/name={{ include "common.names.name" . }},app.kubernetes.io/instance={{ .Release.Name }} -o jsonpath='{.items[0].metadata.name}') nodetool status
|
||||||
|
|
||||||
|
To connect to your Cassandra cluster using CQL:
|
||||||
|
|
||||||
|
1. Run a Cassandra pod that you can use as a client:
|
||||||
|
|
||||||
|
kubectl run --namespace {{ include "common.names.namespace" . }} {{ include "common.names.fullname" . }}-client --rm --tty -i --restart='Never' \
|
||||||
|
--env CASSANDRA_PASSWORD=$CASSANDRA_PASSWORD \
|
||||||
|
{{ if and (.Values.networkPolicy.enabled) (not .Values.networkPolicy.allowExternal) }}--labels="{{ include "common.names.name" . }}-client=true"{{ end }} \
|
||||||
|
--image {{ include "cassandra.image" . }} -- bash
|
||||||
|
|
||||||
|
2. Connect using the cqlsh client:
|
||||||
|
|
||||||
|
cqlsh -u {{ .Values.dbUser.user }} -p $CASSANDRA_PASSWORD {{ include "common.names.fullname" . }}
|
||||||
|
|
||||||
|
{{ if and (.Values.networkPolicy.enabled) (not .Values.networkPolicy.allowExternal) }}
|
||||||
|
Note: Since NetworkPolicy is enabled, only pods with the label below will be able to connect to Cassandra:
|
||||||
|
|
||||||
|
"{{ include "common.names.fullname" . }}-client=true"
|
||||||
|
|
||||||
|
{{- else -}}
|
||||||
|
|
||||||
|
To connect to your database from outside the cluster execute the following commands:
|
||||||
|
|
||||||
|
{{- if contains "NodePort" .Values.service.type }}
|
||||||
|
|
||||||
|
export NODE_IP=$(kubectl get nodes --namespace {{ include "common.names.namespace" . }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
||||||
|
export NODE_PORT=$(kubectl get --namespace {{ include "common.names.namespace" . }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "common.names.fullname" . }})
|
||||||
|
|
||||||
|
cqlsh -u {{ .Values.dbUser.user }} -p $CASSANDRA_PASSWORD $NODE_IP $NODE_PORT
|
||||||
|
|
||||||
|
{{- else if contains "LoadBalancer" .Values.service.type }}
|
||||||
|
|
||||||
|
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
||||||
|
Watch the status with: 'kubectl get svc --namespace {{ include "common.names.namespace" . }} -w {{ include "common.names.fullname" . }}'
|
||||||
|
|
||||||
|
export SERVICE_IP=$(kubectl get svc --namespace {{ include "common.names.namespace" . }} {{ include "common.names.fullname" . }} --template "{{ "{{ range (index .status.loadBalancer.ingress 0) }}{{ . }}{{ end }}" }}")
|
||||||
|
cqlsh -u {{ .Values.dbUser.user }} -p $CASSANDRA_PASSWORD $SERVICE_IP
|
||||||
|
|
||||||
|
{{- else if contains "ClusterIP" .Values.service.type }}
|
||||||
|
|
||||||
|
kubectl port-forward --namespace {{ include "common.names.namespace" . }} svc/{{ include "common.names.fullname" . }} {{ .Values.service.ports.cql }}:{{ .Values.service.ports.cql }} &
|
||||||
|
cqlsh -u {{ .Values.dbUser.user }} -p $CASSANDRA_PASSWORD 127.0.0.1 {{ .Values.service.ports.cql }}
|
||||||
|
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- include "common.warnings.rollingTag" .Values.image }}
|
||||||
|
{{- include "common.warnings.rollingTag" .Values.metrics.image }}
|
||||||
|
{{- include "common.warnings.rollingTag" .Values.volumePermissions.image }}
|
||||||
|
{{- include "cassandra.validateValues" . }}
|
||||||
|
{{- include "common.warnings.resources" (dict "sections" (list "metrics" "" "tls" "volumePermissions") "context" $) }}
|
||||||
|
{{- include "cassandra.warnings.jvm" . }}{{- include "common.warnings.modifiedImages" (dict "images" (list .Values.image .Values.volumePermissions.image .Values.metrics.image) "context" $) }}
|
||||||
|
{{- include "common.errors.insecureImages" (dict "images" (list .Values.image .Values.volumePermissions.image .Values.metrics.image) "context" $) }}
|
||||||
282
cassandra/templates/_helpers.tpl
Normal file
282
cassandra/templates/_helpers.tpl
Normal file
@ -0,0 +1,282 @@
|
|||||||
|
{{/*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper Cassandra image name
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.image" -}}
|
||||||
|
{{ include "common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper metrics image name
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.metrics.image" -}}
|
||||||
|
{{ include "common.images.image" (dict "imageRoot" .Values.metrics.image "global" .Values.global) }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper image name (for the init container volume-permissions image)
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.volumePermissions.image" -}}
|
||||||
|
{{ include "common.images.image" (dict "imageRoot" .Values.volumePermissions.image "global" .Values.global) }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the proper Docker Image Registry Secret Names
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.imagePullSecrets" -}}
|
||||||
|
{{ include "common.images.pullSecrets" (dict "images" (list .Values.image .Values.metrics.image .Values.volumePermissions.image) "global" .Values.global) }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
{{ default (include "common.names.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else -}}
|
||||||
|
{{ default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the list of Cassandra seed nodes
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.seeds" -}}
|
||||||
|
{{- $seeds := list }}
|
||||||
|
{{- $fullname := include "common.names.fullname" . }}
|
||||||
|
{{- $releaseNamespace := include "common.names.namespace" . }}
|
||||||
|
{{- $clusterDomain := .Values.clusterDomain }}
|
||||||
|
{{- $seedCount := .Values.cluster.seedCount | int }}
|
||||||
|
{{- range $e, $i := until $seedCount }}
|
||||||
|
{{- $seeds = append $seeds (printf "%s-%d.%s-headless.%s.svc.%s" $fullname $i $fullname $releaseNamespace $clusterDomain) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- range .Values.cluster.extraSeeds }}
|
||||||
|
{{- $seeds = append $seeds . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- join "," $seeds }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Compile all warnings into a single message, and call fail.
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.validateValues" -}}
|
||||||
|
{{- $messages := list -}}
|
||||||
|
{{- $messages := append $messages (include "cassandra.validateValues.seedCount" .) -}}
|
||||||
|
{{- $messages := append $messages (include "cassandra.validateValues.tls" .) -}}
|
||||||
|
{{- $messages := without $messages "" -}}
|
||||||
|
{{- $message := join "\n" $messages -}}
|
||||||
|
|
||||||
|
{{- if $message -}}
|
||||||
|
{{- printf "\nVALUES VALIDATION:\n%s" $message | fail -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/* Validate values of Cassandra - Number of seed nodes */}}
|
||||||
|
{{- define "cassandra.validateValues.seedCount" -}}
|
||||||
|
{{- $replicaCount := int .Values.replicaCount }}
|
||||||
|
{{- $seedCount := int .Values.cluster.seedCount }}
|
||||||
|
{{- if or (lt $seedCount 1) (gt $seedCount $replicaCount) }}
|
||||||
|
cassandra: cluster.seedCount
|
||||||
|
|
||||||
|
Number of seed nodes must be greater or equal than 1 and less or
|
||||||
|
equal to `replicaCount`.
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/* Validate values of Cassandra - Tls enabled */}}
|
||||||
|
{{- define "cassandra.validateValues.tls" -}}
|
||||||
|
{{- if and (include "cassandra.tlsEncryption" .) (not .Values.tls.autoGenerated) (not .Values.tls.existingSecret) (not .Values.tls.certificatesSecret) }}
|
||||||
|
cassandra: tls.enabled
|
||||||
|
In order to enable TLS, you also need to provide
|
||||||
|
an existing secret containing the Keystore and Truststore or
|
||||||
|
enable auto-generated certificates.
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Return the proper Commit Storage Class
|
||||||
|
{{ include "cassandra.commitstorage.class" ( dict "persistence" .Values.path.to.the.persistence "global" $) }}
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.commitstorage.class" -}}
|
||||||
|
{{- $storageClass := default .persistence.commitStorageClass | default (.global).defaultStorageClass | default "" -}}
|
||||||
|
|
||||||
|
{{- if $storageClass -}}
|
||||||
|
{{- if (eq "-" $storageClass) -}}
|
||||||
|
{{- printf "storageClassName: \"\"" -}}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "storageClassName: %s" $storageClass -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if encryption via TLS for client connections should be configured
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.client.tlsEncryption" -}}
|
||||||
|
{{- if (or .Values.tls.clientEncryption .Values.cluster.clientEncryption) -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if encryption via TLS for internode communication connections should be configured
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.internode.tlsEncryption" -}}
|
||||||
|
{{- if (ne .Values.tls.internodeEncryption "none") -}}
|
||||||
|
{{- printf "%s" .Values.tls.internodeEncryption -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "none" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if encryption via TLS should be configured
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.tlsEncryption" -}}
|
||||||
|
{{- if or (include "cassandra.client.tlsEncryption" . ) ( ne "none" (include "cassandra.internode.tlsEncryption" . )) -}}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Convert memory to M
|
||||||
|
Usage:
|
||||||
|
{{ include "cassandra.memory.convertToM" (dict "value" "3Gi") }}
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.memory.convertToM" -}}
|
||||||
|
{{- $res := 0 -}}
|
||||||
|
{{- if regexMatch "G" .value -}}
|
||||||
|
{{- /* Multiply by 1000 if it is Gigabytes */ -}}
|
||||||
|
{{- $res = regexFind "[0-9.]+" .value | float64 | mulf 1000 | int -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- /* Assume M for the rest, so simply extract the number and convert to int */ -}}
|
||||||
|
{{- $res = regexFind "[0-9]+" .value | int -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- $res -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return memory limit if resources or resourcesPreset has been set (in M)
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.memory.getLimitInM" -}}
|
||||||
|
{{- $res := "" -}}
|
||||||
|
{{- if .Values.resources -}}
|
||||||
|
{{- /* We need to go step by step to avoid nil pointer exceptions */ -}}
|
||||||
|
{{- if .Values.resources.limits -}}
|
||||||
|
{{- if .Values.resources.limits.memory -}}
|
||||||
|
{{- $res = .Values.resources.limits.memory -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- else if (ne .Values.resourcesPreset "none") -}}
|
||||||
|
{{- $preset := include "common.resources.preset" (dict "type" .Values.resourcesPreset) | fromYaml -}}
|
||||||
|
{{- $res = $preset.limits.memory -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- if $res -}}
|
||||||
|
{{- /* Convert to M */ -}}
|
||||||
|
{{- include "cassandra.memory.convertToM" (dict "value" $res) -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Calculate Max Heap Size based on the given values
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.memory.calculateMaxHeapSize" -}}
|
||||||
|
{{- if .Values.jvm.maxHeapSize -}}
|
||||||
|
{{- /* Honor value explicitly set */ -}}
|
||||||
|
{{- print .Values.jvm.maxHeapSize -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- /* Calculate based on resources set */ -}}
|
||||||
|
{{- /* Reference: https://docs.oracle.com/javase/8/docs/technotes/guides/vm/gc-ergonomics.html */ -}}
|
||||||
|
{{- $res := include "cassandra.memory.getLimitInM" . -}}
|
||||||
|
{{- $res = div $res 4 | min 1000 -}}
|
||||||
|
{{- printf "%vM" $res -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Calculate New Heap Size based on the given values
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.memory.calculateNewHeapSize" -}}
|
||||||
|
{{- if .Values.jvm.newHeapSize -}}
|
||||||
|
{{- /* Honor value explicitly set */ -}}
|
||||||
|
{{- print .Values.jvm.newHeapSize -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- /* Calculate based on resources set */ -}}
|
||||||
|
{{- /* Reference: https://docs.oracle.com/javase/8/docs/technotes/guides/vm/gc-ergonomics.html */ -}}
|
||||||
|
{{- $res := include "cassandra.memory.getLimitInM" . -}}
|
||||||
|
{{- $res = div $res 64 | max 256 -}}
|
||||||
|
{{- printf "%vM" $res -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the Cassandra TLS credentials secret
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.tlsSecretName" -}}
|
||||||
|
{{- $secretName := coalesce .Values.tls.existingSecret .Values.tls.tlsEncryptionSecretName -}}
|
||||||
|
{{- if $secretName -}}
|
||||||
|
{{- printf "%s" (tpl $secretName $) -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-crt" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if a TLS credentials secret object should be created
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.createTlsSecret" -}}
|
||||||
|
{{- if and (include "cassandra.tlsEncryption" .) .Values.tls.autoGenerated (not .Values.tls.existingSecret) (not .Values.tls.tlsEncryptionSecretName) }}
|
||||||
|
{{- true -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return true if a TLS credentials secret object should be created
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.tlsPasswordsSecret" -}}
|
||||||
|
{{- $secretName := coalesce .Values.tls.passwordsSecret .Values.tls.tlsEncryptionSecretName -}}
|
||||||
|
{{- if $secretName -}}
|
||||||
|
{{- printf "%s" (tpl $secretName $) -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-tls-pass" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Get the password to use to access Cassandra
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.password" -}}
|
||||||
|
{{- if (and (empty .Values.dbUser.password) .Values.dbUser.forcePassword) }}
|
||||||
|
{{ required "A Cassandra Password is required!" .Values.dbUser.password }}
|
||||||
|
{{- else }}
|
||||||
|
{{- include "common.secrets.passwords.manage" (dict "secret" (include "common.names.fullname" .) "key" "cassandra-password" "providedValues" (list "dbUser.password") "context" $) -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Get the metrics config map name.
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.metricsConfConfigMap" -}}
|
||||||
|
{{- printf "%s-metrics-conf" (include "common.names.fullname" . ) | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Print warning if jvm memory not set
|
||||||
|
*/}}
|
||||||
|
{{- define "cassandra.warnings.jvm" -}}
|
||||||
|
{{- if not .Values.jvm.maxHeapSize }}
|
||||||
|
WARNING: JVM Max Heap Size not set in value jvm.maxHeapSize. When not set, the chart will calculate the following size:
|
||||||
|
MIN(Memory Limit (if set) / 4, 1024M)
|
||||||
|
{{- end }}
|
||||||
|
{{- if not .Values.jvm.maxHeapSize }}
|
||||||
|
WARNING: JVM New Heap Size not set in value jvm.newHeapSize. When not set, the chart will calculate the following size:
|
||||||
|
MAX(Memory Limit (if set) / 64, 256M)
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
39
cassandra/templates/cassandra-secret.yaml
Normal file
39
cassandra/templates/cassandra-secret.yaml
Normal file
@ -0,0 +1,39 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- if (not .Values.dbUser.existingSecret) -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
cassandra-password: {{ include "cassandra.password" . }}
|
||||||
|
{{ end }}
|
||||||
|
{{- if and (or .Values.tls.keystorePassword .Values.tls.truststorePassword .Values.tls.autoGenerated) (not .Values.tls.passwordsSecret) (not .Values.tls.tlsEncryptionSecretName) }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ printf "%s-tls-pass" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
{{- if or .Values.tls.keystorePassword .Values.tls.autoGenerated }}
|
||||||
|
keystore-password: {{ include "common.secrets.passwords.manage" (dict "secret" (printf "%s-%s" (include "common.names.fullname" .) "tls-pass" | trunc 63 | trimSuffix "-") "key" "keystore-password" "providedValues" (list "tls.keystorePassword") "context" $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.tls.truststorePassword .Values.tls.autoGenerated }}
|
||||||
|
truststore-password: {{ include "common.secrets.passwords.manage" (dict "secret" (printf "%s-%s" (include "common.names.fullname" .) "tls-pass" | trunc 63 | trimSuffix "-") "key" "truststore-password" "providedValues" (list "tls.truststorePassword") "context" $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
9
cassandra/templates/extra-list.yaml
Normal file
9
cassandra/templates/extra-list.yaml
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- range .Values.extraDeploy }}
|
||||||
|
---
|
||||||
|
{{ include "common.tplvalues.render" (dict "value" . "context" $) }}
|
||||||
|
{{- end }}
|
||||||
33
cassandra/templates/headless-svc.yaml
Normal file
33
cassandra/templates/headless-svc.yaml
Normal file
@ -0,0 +1,33 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ printf "%s-headless" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if or .Values.service.headless.annotations .Values.commonAnnotations }}
|
||||||
|
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.service.headless.annotations .Values.commonAnnotations ) "context" . ) }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
clusterIP: None
|
||||||
|
publishNotReadyAddresses: true
|
||||||
|
ports:
|
||||||
|
- name: intra
|
||||||
|
port: 7000
|
||||||
|
targetPort: intra
|
||||||
|
- name: tls
|
||||||
|
port: 7001
|
||||||
|
targetPort: tls
|
||||||
|
- name: jmx
|
||||||
|
port: 7199
|
||||||
|
targetPort: jmx
|
||||||
|
- name: cql
|
||||||
|
port: {{ .Values.service.ports.cql }}
|
||||||
|
targetPort: cql
|
||||||
|
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
|
||||||
|
selector: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 4 }}
|
||||||
16
cassandra/templates/init_cm.yaml
Normal file
16
cassandra/templates/init_cm.yaml
Normal file
@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: cassandra-init-script
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
data:
|
||||||
|
init.cql: |
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS workspaces WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS users WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS stickers WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS notifications WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS messages WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS chats WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS calls WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS config WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
|
CREATE KEYSPACE IF NOT EXISTS dictionary WITH replication = {'class' : 'SimpleStrategy', 'replication_factor' : 3};
|
||||||
19
cassandra/templates/initdb-configmap.yaml
Normal file
19
cassandra/templates/initdb-configmap.yaml
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- if and .Values.initDB (not .Values.initDBConfigMap) }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ printf "%s-init-scripts" (include "common.names.fullname" .) }}
|
||||||
|
namespace: {{ .Release.Namespace | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
app.kubernetes.io/part-of: cassandra
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
data:
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.initDB "context" .) | nindent 2 }}
|
||||||
|
{{ end }}
|
||||||
19
cassandra/templates/metrics-configmap.yaml
Normal file
19
cassandra/templates/metrics-configmap.yaml
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ printf "%s-metrics-conf" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
app.kubernetes.io/part-of: cassandra
|
||||||
|
app.kubernetes.io/component: cassandra-exporter
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
data:
|
||||||
|
config.yml: |-
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.metrics.configuration "context" $) | nindent 4 }}
|
||||||
82
cassandra/templates/networkpolicy.yaml
Normal file
82
cassandra/templates/networkpolicy.yaml
Normal file
@ -0,0 +1,82 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- if .Values.networkPolicy.enabled }}
|
||||||
|
kind: NetworkPolicy
|
||||||
|
apiVersion: {{ include "common.capabilities.networkPolicy.apiVersion" . }}
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
|
||||||
|
podSelector:
|
||||||
|
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 6 }}
|
||||||
|
policyTypes:
|
||||||
|
- Ingress
|
||||||
|
- Egress
|
||||||
|
{{- if .Values.networkPolicy.allowExternalEgress }}
|
||||||
|
egress:
|
||||||
|
- {}
|
||||||
|
{{- else }}
|
||||||
|
egress:
|
||||||
|
# Allow dns resolution
|
||||||
|
- ports:
|
||||||
|
- port: 53
|
||||||
|
protocol: UDP
|
||||||
|
- port: 53
|
||||||
|
protocol: TCP
|
||||||
|
# Allow connection to other cluster pods
|
||||||
|
- ports:
|
||||||
|
- port: {{ .Values.containerPorts.cql }}
|
||||||
|
- port: {{ .Values.containerPorts.jmx }}
|
||||||
|
- port: {{ .Values.containerPorts.tls }}
|
||||||
|
- port: {{ .Values.containerPorts.intra }}
|
||||||
|
to:
|
||||||
|
- podSelector:
|
||||||
|
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 14 }}
|
||||||
|
{{- if .Values.networkPolicy.extraEgress }}
|
||||||
|
{{- include "common.tplvalues.render" ( dict "value" .Values.rts.networkPolicy.extraEgress "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
ingress:
|
||||||
|
- ports:
|
||||||
|
- port: {{ .Values.containerPorts.cql }}
|
||||||
|
- port: {{ .Values.containerPorts.jmx }}
|
||||||
|
- port: {{ .Values.containerPorts.tls }}
|
||||||
|
- port: {{ .Values.containerPorts.intra }}
|
||||||
|
{{- if .Values.metrics.enabled }}
|
||||||
|
- port: {{ .Values.metrics.containerPorts.http }}
|
||||||
|
- port: {{ .Values.metrics.containerPorts.jmx }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if not .Values.networkPolicy.allowExternal }}
|
||||||
|
from:
|
||||||
|
- podSelector:
|
||||||
|
matchLabels:
|
||||||
|
{{ template "common.names.fullname" . }}-client: "true"
|
||||||
|
- podSelector:
|
||||||
|
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 14 }}
|
||||||
|
{{- if .Values.networkPolicy.ingressNSMatchLabels }}
|
||||||
|
- namespaceSelector:
|
||||||
|
matchLabels:
|
||||||
|
{{- range $key, $value := .Values.networkPolicy.ingressNSMatchLabels }}
|
||||||
|
{{ $key | quote }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.networkPolicy.ingressNSPodMatchLabels }}
|
||||||
|
podSelector:
|
||||||
|
matchLabels:
|
||||||
|
{{- range $key, $value := .Values.networkPolicy.ingressNSPodMatchLabels }}
|
||||||
|
{{ $key | quote }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.networkPolicy.extraIngress }}
|
||||||
|
{{- include "common.tplvalues.render" ( dict "value" .Values.networkPolicy.extraIngress "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
26
cassandra/templates/pdb.yaml
Normal file
26
cassandra/templates/pdb.yaml
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- if .Values.pdb.create }}
|
||||||
|
apiVersion: {{ include "common.capabilities.policy.apiVersion" . }}
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.pdb.minAvailable }}
|
||||||
|
minAvailable: {{ .Values.pdb.minAvailable }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.pdb.maxUnavailable ( not .Values.pdb.minAvailable ) }}
|
||||||
|
maxUnavailable: {{ .Values.pdb.maxUnavailable | default 1 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
|
||||||
|
selector:
|
||||||
|
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 6 }}
|
||||||
|
{{- end }}
|
||||||
59
cassandra/templates/service.yaml
Normal file
59
cassandra/templates/service.yaml
Normal file
@ -0,0 +1,59 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if or .Values.service.annotations .Values.commonAnnotations }}
|
||||||
|
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.service.annotations .Values.commonAnnotations ) "context" . ) }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerIP)) }}
|
||||||
|
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerSourceRanges)) }}
|
||||||
|
loadBalancerSourceRanges: {{- toYaml .Values.service.loadBalancerSourceRanges | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if and .Values.service.clusterIP (eq .Values.service.type "ClusterIP") }}
|
||||||
|
clusterIP: {{ .Values.service.clusterIP }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.service.sessionAffinity }}
|
||||||
|
sessionAffinity: {{ .Values.service.sessionAffinity }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.service.sessionAffinityConfig }}
|
||||||
|
sessionAffinityConfig: {{- include "common.tplvalues.render" (dict "value" .Values.service.sessionAffinityConfig "context" $) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort") }}
|
||||||
|
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy | quote }}
|
||||||
|
{{- end }}
|
||||||
|
ports:
|
||||||
|
- name: cql
|
||||||
|
port: {{ .Values.service.ports.cql }}
|
||||||
|
targetPort: cql
|
||||||
|
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.cql)) }}
|
||||||
|
nodePort: {{ .Values.service.nodePorts.cql }}
|
||||||
|
{{- else if eq .Values.service.type "ClusterIP" }}
|
||||||
|
nodePort: null
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.enabled }}
|
||||||
|
- name: metrics
|
||||||
|
port: {{ .Values.service.ports.metrics }}
|
||||||
|
targetPort: metrics
|
||||||
|
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.metrics)) }}
|
||||||
|
nodePort: {{ .Values.service.nodePorts.metrics }}
|
||||||
|
{{- else if eq .Values.service.type "ClusterIP" }}
|
||||||
|
nodePort: null
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.service.extraPorts }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.service.extraPorts "context" $) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
|
||||||
|
selector: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 4 }}
|
||||||
18
cassandra/templates/serviceaccount.yaml
Normal file
18
cassandra/templates/serviceaccount.yaml
Normal file
@ -0,0 +1,18 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cassandra.serviceAccountName" . }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if or .Values.serviceAccount.annotations .Values.commonAnnotations }}
|
||||||
|
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.serviceAccount.annotations .Values.commonAnnotations ) "context" . ) }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
|
||||||
|
{{- end }}
|
||||||
46
cassandra/templates/servicemonitor.yaml
Normal file
46
cassandra/templates/servicemonitor.yaml
Normal file
@ -0,0 +1,46 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- if and .Values.metrics.enabled .Values.metrics.serviceMonitor.enabled }}
|
||||||
|
apiVersion: monitoring.coreos.com/v1
|
||||||
|
kind: ServiceMonitor
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
namespace: {{ default ( include "common.names.namespace" . ) .Values.metrics.serviceMonitor.namespace | quote }}
|
||||||
|
{{- $labels := include "common.tplvalues.merge" ( dict "values" ( list .Values.metrics.serviceMonitor.labels .Values.commonLabels ) "context" . ) }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" $labels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.metrics.serviceMonitor.jobLabel }}
|
||||||
|
jobLabel: {{ .Values.metrics.serviceMonitor.jobLabel }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 6 }}
|
||||||
|
{{- if .Values.metrics.serviceMonitor.selector }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.metrics.serviceMonitor.selector "context" $) | nindent 6 }}
|
||||||
|
{{- end }}
|
||||||
|
endpoints:
|
||||||
|
- port: metrics
|
||||||
|
{{- if .Values.metrics.serviceMonitor.interval }}
|
||||||
|
interval: {{ .Values.metrics.serviceMonitor.interval }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.serviceMonitor.scrapeTimeout }}
|
||||||
|
scrapeTimeout: {{ .Values.metrics.serviceMonitor.scrapeTimeout }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.serviceMonitor.honorLabels }}
|
||||||
|
honorLabels: {{ .Values.metrics.serviceMonitor.honorLabels }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.serviceMonitor.metricRelabelings }}
|
||||||
|
metricRelabelings: {{- toYaml .Values.metrics.serviceMonitor.metricRelabelings | nindent 6 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.serviceMonitor.relabelings }}
|
||||||
|
relabelings: {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.serviceMonitor.relabelings "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
namespaceSelector:
|
||||||
|
matchNames:
|
||||||
|
- {{ include "common.names.namespace" . }}
|
||||||
|
{{- end }}
|
||||||
690
cassandra/templates/statefulset.yaml
Normal file
690
cassandra/templates/statefulset.yaml
Normal file
@ -0,0 +1,690 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
apiVersion: {{ include "common.capabilities.statefulset.apiVersion" . }}
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
|
||||||
|
selector:
|
||||||
|
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 6 }}
|
||||||
|
serviceName: {{ printf "%s-headless" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" }}
|
||||||
|
podManagementPolicy: {{ .Values.podManagementPolicy }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
updateStrategy: {{- include "common.tplvalues.render" (dict "value" .Values.updateStrategy "context" $ ) | nindent 4 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" $podLabels "context" $ ) | nindent 8 }}
|
||||||
|
{{- if or .Values.podAnnotations (and .Values.metrics.enabled .Values.metrics.podAnnotations) }}
|
||||||
|
annotations:
|
||||||
|
{{- if .Values.podAnnotations }}
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.podAnnotations }}
|
||||||
|
{{- toYaml .Values.metrics.podAnnotations | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- include "cassandra.imagePullSecrets" . | nindent 6 }}
|
||||||
|
automountServiceAccountToken: {{ .Values.automountServiceAccountToken }}
|
||||||
|
{{- if .Values.hostAliases }}
|
||||||
|
hostAliases: {{- include "common.tplvalues.render" (dict "value" .Values.hostAliases "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ template "cassandra.serviceAccountName" . }}
|
||||||
|
{{- if .Values.affinity }}
|
||||||
|
affinity: {{- include "common.tplvalues.render" (dict "value" .Values.affinity "context" $) | nindent 8 }}
|
||||||
|
{{- else }}
|
||||||
|
affinity:
|
||||||
|
podAffinity: {{- include "common.affinities.pods" (dict "type" .Values.podAffinityPreset "customLabels" $podLabels "context" $) | nindent 10 }}
|
||||||
|
podAntiAffinity: {{- include "common.affinities.pods" (dict "type" .Values.podAntiAffinityPreset "customLabels" $podLabels "context" $) | nindent 10 }}
|
||||||
|
nodeAffinity: {{- include "common.affinities.nodes" (dict "type" .Values.nodeAffinityPreset.type "key" .Values.nodeAffinityPreset.key "values" .Values.nodeAffinityPreset.values) | nindent 10 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.nodeSelector }}
|
||||||
|
nodeSelector: {{- include "common.tplvalues.render" (dict "value" .Values.nodeSelector "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.tolerations }}
|
||||||
|
tolerations: {{- include "common.tplvalues.render" (dict "value" .Values.tolerations "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.schedulerName }}
|
||||||
|
schedulerName: {{ .Values.schedulerName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.priorityClassName }}
|
||||||
|
priorityClassName: {{ .Values.priorityClassName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.podSecurityContext.enabled }}
|
||||||
|
securityContext: {{- include "common.compatibility.renderSecurityContext" (dict "secContext" .Values.podSecurityContext "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.topologySpreadConstraints }}
|
||||||
|
topologySpreadConstraints: {{- include "common.tplvalues.render" (dict "value" .Values.topologySpreadConstraints "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.terminationGracePeriodSeconds }}
|
||||||
|
terminationGracePeriodSeconds: {{ .Values.terminationGracePeriodSeconds }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.initContainers (include "cassandra.tlsEncryption" . ) (and .Values.podSecurityContext.enabled .Values.volumePermissions.enabled .Values.persistence.enabled) }}
|
||||||
|
initContainers:
|
||||||
|
{{- if and .Values.podSecurityContext.enabled .Values.volumePermissions.enabled .Values.persistence.enabled }}
|
||||||
|
- name: volume-permissions
|
||||||
|
image: {{ include "cassandra.volumePermissions.image" . }}
|
||||||
|
imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }}
|
||||||
|
{{- if .Values.diagnosticMode.enabled }}
|
||||||
|
command: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 12 }}
|
||||||
|
{{- else }}
|
||||||
|
command:
|
||||||
|
- /bin/sh
|
||||||
|
- -cx
|
||||||
|
- |
|
||||||
|
{{- if .Values.persistence.enabled }}
|
||||||
|
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
|
||||||
|
chown `id -u`:`id -G | cut -d " " -f2` {{ .Values.persistence.mountPath }}
|
||||||
|
{{- else }}
|
||||||
|
chown {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} {{ .Values.persistence.mountPath }}
|
||||||
|
{{- end }}
|
||||||
|
mkdir -p {{ .Values.persistence.mountPath }}/data
|
||||||
|
chmod 700 {{ .Values.persistence.mountPath }}/data
|
||||||
|
find {{ .Values.persistence.mountPath }} -mindepth 1 -maxdepth 1 -not -name ".snapshot" -not -name "lost+found" | \
|
||||||
|
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
|
||||||
|
xargs chown -R `id -u`:`id -G | cut -d " " -f2`
|
||||||
|
{{- else }}
|
||||||
|
xargs chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.persistence.commitLogMountPath }}
|
||||||
|
- /bin/sh
|
||||||
|
- -cx
|
||||||
|
- |
|
||||||
|
{{- if .Values.persistence.enabled }}
|
||||||
|
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
|
||||||
|
chown `id -u`:`id -G | cut -d " " -f2` {{ .Values.persistence.mountPath }}
|
||||||
|
{{- else }}
|
||||||
|
chown {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} {{ .Values.persistence.mountPath }}
|
||||||
|
{{- end }}
|
||||||
|
mkdir -p {{ .Values.persistence.commitLogMountPath }}/commitlog
|
||||||
|
chmod 700 {{ .Values.persistence.commitLogMountPath }}/commitlog
|
||||||
|
find {{ .Values.persistence.mountPath }} -mindepth 1 -maxdepth 1 -not -name ".snapshot" -not -name "lost+found" | \
|
||||||
|
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
|
||||||
|
xargs -r chown -R `id -u`:`id -G | cut -d " " -f2`
|
||||||
|
{{- else }}
|
||||||
|
xargs -r chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }}
|
||||||
|
securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }}
|
||||||
|
{{- else }}
|
||||||
|
securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.volumePermissions.resources }}
|
||||||
|
resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }}
|
||||||
|
{{- else if ne .Values.volumePermissions.resourcesPreset "none" }}
|
||||||
|
resources: {{- include "common.resources.preset" (dict "type" .Values.volumePermissions.resourcesPreset) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: data
|
||||||
|
mountPath: {{ .Values.persistence.mountPath }}
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /tmp
|
||||||
|
subPath: tmp-dir
|
||||||
|
{{- if .Values.persistence.commitLogMountPath }}
|
||||||
|
- name: commitlog
|
||||||
|
mountPath: {{ .Values.persistence.commitLogMountPath }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if (include "cassandra.tlsEncryption" . ) }}
|
||||||
|
- name: init-certs
|
||||||
|
image: {{ include "cassandra.image" . }}
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy | quote }}
|
||||||
|
{{- if .Values.containerSecurityContext.enabled }}
|
||||||
|
securityContext: {{- include "common.compatibility.renderSecurityContext" (dict "secContext" .Values.containerSecurityContext "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
command:
|
||||||
|
- /bin/bash
|
||||||
|
- -ec
|
||||||
|
- |-
|
||||||
|
{{- if .Values.tls.autoGenerated }}
|
||||||
|
if [[ -f "/certs/tls.key" ]] && [[ -f "/certs/tls.crt" ]] && [[ -f "/certs/ca.crt" ]]; then
|
||||||
|
openssl pkcs12 -export -in "/certs/tls.crt" \
|
||||||
|
-passout pass:"${CASSANDRA_KEYSTORE_PASSWORD}" \
|
||||||
|
-inkey "/certs/tls.key" \
|
||||||
|
-out "/tmp/keystore.p12"
|
||||||
|
keytool -importkeystore -srckeystore "/tmp/keystore.p12" \
|
||||||
|
-srcstoretype PKCS12 \
|
||||||
|
-srcstorepass "${CASSANDRA_KEYSTORE_PASSWORD}" \
|
||||||
|
-deststorepass "${CASSANDRA_KEYSTORE_PASSWORD}" \
|
||||||
|
-destkeystore "/opt/bitnami/cassandra/certs/keystore" \
|
||||||
|
-noprompt
|
||||||
|
rm "/tmp/keystore.p12"
|
||||||
|
keytool -import -file "/certs/ca.crt" \
|
||||||
|
-keystore "/opt/bitnami/cassandra/certs/truststore" \
|
||||||
|
-storepass "${CASSANDRA_TRUSTSTORE_PASSWORD}" \
|
||||||
|
-noprompt
|
||||||
|
else
|
||||||
|
echo "Couldn't find the expected PEM certificates! They are mandatory when encryption via TLS is enabled."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
{{- else }}
|
||||||
|
if [[ -f "/certs/truststore" ]] && [[ -f "/certs/keystore" ]]; then
|
||||||
|
cp "/certs/truststore" "/opt/bitnami/cassandra/certs/truststore"
|
||||||
|
cp "/certs/keystore" "/opt/bitnami/cassandra/certs/keystore"
|
||||||
|
else
|
||||||
|
echo "Couldn't find the expected Java Key Stores (JKS) files! They are mandatory when encryption via TLS is enabled."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
{{- end }}
|
||||||
|
env:
|
||||||
|
- name: MY_POD_NAME
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
apiVersion: v1
|
||||||
|
fieldPath: metadata.name
|
||||||
|
{{- if or .Values.tls.passwordsSecret .Values.tls.tlsEncryptionSecretName .Values.tls.truststorePassword .Values.tls.autoGenerated }}
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: CASSANDRA_TRUSTSTORE_PASSWORD_FILE
|
||||||
|
value: "/opt/bitnami/cassandra/secrets/truststore-password"
|
||||||
|
{{- else }}
|
||||||
|
- name: CASSANDRA_TRUSTSTORE_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ include "cassandra.tlsPasswordsSecret" . }}
|
||||||
|
key: truststore-password
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.tls.passwordsSecret .Values.tls.tlsEncryptionSecretName .Values.tls.keystorePassword .Values.tls.autoGenerated }}
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: CASSANDRA_KEYSTORE_PASSWORD_FILE
|
||||||
|
value: "/opt/bitnami/cassandra/secrets/keystore-password"
|
||||||
|
{{- else }}
|
||||||
|
- name: CASSANDRA_KEYSTORE_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ include "cassandra.tlsPasswordsSecret" . }}
|
||||||
|
key: keystore-password
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.tls.resources }}
|
||||||
|
resources: {{- toYaml .Values.tls.resources | nindent 12 }}
|
||||||
|
{{- else if ne .Values.tls.resourcesPreset "none" }}
|
||||||
|
resources: {{- include "common.resources.preset" (dict "type" .Values.tls.resourcesPreset) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: script-volume
|
||||||
|
mountPath: /scripts
|
||||||
|
- name: certs
|
||||||
|
mountPath: /certs
|
||||||
|
- name: certs-shared
|
||||||
|
mountPath: /opt/bitnami/cassandra/certs
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /tmp
|
||||||
|
subPath: tmp-dir
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: cassandra-secrets
|
||||||
|
mountPath: /opt/bitnami/cassandra/secrets
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.initContainers }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.initContainers "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.hostNetwork }}
|
||||||
|
hostNetwork: true
|
||||||
|
dnsPolicy: ClusterFirstWithHostNet
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- name: cassandra
|
||||||
|
command:
|
||||||
|
{{- if .Values.command }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.command "context" $) | nindent 12 }}
|
||||||
|
{{- else }}
|
||||||
|
- bash
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
# Node 0 is the password seeder
|
||||||
|
if [[ $POD_NAME =~ (.*)-0$ ]]; then
|
||||||
|
echo "Setting node as password seeder"
|
||||||
|
export CASSANDRA_PASSWORD_SEEDER=yes
|
||||||
|
else
|
||||||
|
# Only node 0 will execute the startup initdb scripts
|
||||||
|
export CASSANDRA_IGNORE_INITDB_SCRIPTS=1
|
||||||
|
fi
|
||||||
|
/opt/bitnami/scripts/cassandra/entrypoint.sh /opt/bitnami/scripts/cassandra/run.sh
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.diagnosticMode.enabled }}
|
||||||
|
args: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 12 }}
|
||||||
|
{{- else if .Values.args }}
|
||||||
|
args: {{- include "common.tplvalues.render" (dict "value" .Values.args "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
image: {{ include "cassandra.image" . }}
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy | quote }}
|
||||||
|
{{- if .Values.containerSecurityContext.enabled }}
|
||||||
|
securityContext: {{- include "common.compatibility.renderSecurityContext" (dict "secContext" .Values.containerSecurityContext "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
env:
|
||||||
|
- name: BITNAMI_DEBUG
|
||||||
|
value: {{ ternary "true" "false" (or .Values.image.debug .Values.diagnosticMode.enabled) | quote }}
|
||||||
|
- name: CASSANDRA_CLUSTER_NAME
|
||||||
|
value: {{ .Values.cluster.name }}
|
||||||
|
- name: CASSANDRA_SEEDS
|
||||||
|
value: {{ (include "cassandra.seeds" .) | quote }}
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: CASSANDRA_PASSWORD_FILE
|
||||||
|
value: {{ printf "/opt/bitnami/cassandra/secrets/%s" (include "common.secrets.key" (dict "existingSecret" .Values.dbUser.existingSecret "key" "cassandra-password")) }}
|
||||||
|
{{- else }}
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ include "common.secrets.name" (dict "existingSecret" .Values.dbUser.existingSecret "context" $) }}
|
||||||
|
key: {{ include "common.secrets.key" (dict "existingSecret" .Values.dbUser.existingSecret "key" "cassandra-password") }}
|
||||||
|
{{- end }}
|
||||||
|
- name: POD_IP
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: status.podIP
|
||||||
|
- name: POD_NAME
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.name
|
||||||
|
- name: CASSANDRA_USER
|
||||||
|
value: {{ .Values.dbUser.user | quote }}
|
||||||
|
- name: CASSANDRA_NUM_TOKENS
|
||||||
|
value: {{ .Values.cluster.numTokens | quote }}
|
||||||
|
- name: CASSANDRA_DATACENTER
|
||||||
|
value: {{ .Values.cluster.datacenter }}
|
||||||
|
- name: CASSANDRA_ENDPOINT_SNITCH
|
||||||
|
value: {{ .Values.cluster.endpointSnitch }}
|
||||||
|
- name: CASSANDRA_KEYSTORE_LOCATION
|
||||||
|
value: "/opt/bitnami/cassandra/certs/keystore"
|
||||||
|
- name: CASSANDRA_TRUSTSTORE_LOCATION
|
||||||
|
value: "/opt/bitnami/cassandra/certs/truststore"
|
||||||
|
{{- if ne "none" (include "cassandra.internode.tlsEncryption" .) }}
|
||||||
|
- name: CASSANDRA_INTERNODE_ENCRYPTION
|
||||||
|
value: {{ (include "cassandra.internode.tlsEncryption" .) | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if (include "cassandra.client.tlsEncryption" .) }}
|
||||||
|
- name: CASSANDRA_CLIENT_ENCRYPTION
|
||||||
|
value: "true"
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.tls.passwordsSecret .Values.tls.tlsEncryptionSecretName .Values.tls.truststorePassword .Values.tls.autoGenerated }}
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: CASSANDRA_TRUSTSTORE_PASSWORD_FILE
|
||||||
|
value: "/opt/bitnami/cassandra/secrets/truststore-password"
|
||||||
|
{{- else }}
|
||||||
|
- name: CASSANDRA_TRUSTSTORE_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ include "cassandra.tlsPasswordsSecret" . }}
|
||||||
|
key: truststore-password
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.tls.passwordsSecret .Values.tls.tlsEncryptionSecretName .Values.tls.keystorePassword .Values.tls.autoGenerated }}
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: CASSANDRA_KEYSTORE_PASSWORD_FILE
|
||||||
|
value: "/opt/bitnami/cassandra/secrets/keystore-password"
|
||||||
|
{{- else }}
|
||||||
|
- name: CASSANDRA_KEYSTORE_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ include "cassandra.tlsPasswordsSecret" . }}
|
||||||
|
key: keystore-password
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
- name: CASSANDRA_RACK
|
||||||
|
value: {{ .Values.cluster.rack }}
|
||||||
|
{{- if or .Values.jvm.maxHeapSize (include "cassandra.memory.getLimitInM" .) }}
|
||||||
|
- name: MAX_HEAP_SIZE
|
||||||
|
value: {{ include "cassandra.memory.calculateMaxHeapSize" . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.jvm.newHeapSize (include "cassandra.memory.getLimitInM" .) }}
|
||||||
|
- name: HEAP_NEWSIZE
|
||||||
|
value: {{ include "cassandra.memory.calculateNewHeapSize" . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.jvm.extraOpts }}
|
||||||
|
- name: JVM_EXTRA_OPTS
|
||||||
|
value: {{ .Values.jvm.extraOpts | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.cluster.enableUDF }}
|
||||||
|
- name: CASSANDRA_ENABLE_USER_DEFINED_FUNCTIONS
|
||||||
|
value: {{ .Values.cluster.enableUDF | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.containerPorts.intra }}
|
||||||
|
- name: CASSANDRA_TRANSPORT_PORT_NUMBER
|
||||||
|
value: {{ .Values.containerPorts.intra | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.containerPorts.jmx }}
|
||||||
|
- name: CASSANDRA_JMX_PORT_NUMBER
|
||||||
|
value: {{ .Values.containerPorts.jmx | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.containerPorts.cql }}
|
||||||
|
- name: CASSANDRA_CQL_PORT_NUMBER
|
||||||
|
value: {{ .Values.containerPorts.cql | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.persistence.commitLogMountPath }}
|
||||||
|
- name: CASSANDRA_COMMITLOG_DIR
|
||||||
|
value: {{ .Values.persistence.commitLogMountPath | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.extraEnvVars }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
envFrom:
|
||||||
|
{{- if .Values.extraEnvVarsCM }}
|
||||||
|
- configMapRef:
|
||||||
|
name: {{ include "common.tplvalues.render" (dict "value" .Values.extraEnvVarsCM "context" $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.extraEnvVarsSecret }}
|
||||||
|
- secretRef:
|
||||||
|
name: {{ include "common.tplvalues.render" (dict "value" .Values.extraEnvVarsSecret "context" $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if not .Values.diagnosticMode.enabled }}
|
||||||
|
{{- if .Values.customLivenessProbe }}
|
||||||
|
livenessProbe: {{- include "common.tplvalues.render" (dict "value" .Values.customLivenessProbe "context" $) | nindent 12 }}
|
||||||
|
{{- else if .Values.livenessProbe.enabled }}
|
||||||
|
livenessProbe:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /bin/bash
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
nodetool info | grep "Native Transport active: true"
|
||||||
|
initialDelaySeconds: {{ .Values.livenessProbe.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.livenessProbe.periodSeconds }}
|
||||||
|
timeoutSeconds: {{ .Values.livenessProbe.timeoutSeconds }}
|
||||||
|
successThreshold: {{ .Values.livenessProbe.successThreshold }}
|
||||||
|
failureThreshold: {{ .Values.livenessProbe.failureThreshold }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.customReadinessProbe }}
|
||||||
|
readinessProbe: {{- include "common.tplvalues.render" (dict "value" .Values.customReadinessProbe "context" $) | nindent 12 }}
|
||||||
|
{{- else if .Values.readinessProbe.enabled }}
|
||||||
|
readinessProbe:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /bin/bash
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
nodetool status | grep -E "^UN\\s+${POD_IP}"
|
||||||
|
initialDelaySeconds: {{ .Values.readinessProbe.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.readinessProbe.periodSeconds }}
|
||||||
|
timeoutSeconds: {{ .Values.readinessProbe.timeoutSeconds }}
|
||||||
|
successThreshold: {{ .Values.readinessProbe.successThreshold }}
|
||||||
|
failureThreshold: {{ .Values.readinessProbe.failureThreshold }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.customStartupProbe }}
|
||||||
|
startupProbe: {{- include "common.tplvalues.render" (dict "value" .Values.customStartupProbe "context" $) | nindent 12 }}
|
||||||
|
{{- else if .Values.startupProbe.enabled }}
|
||||||
|
startupProbe:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /bin/bash
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
nodetool status | grep -E "^UN\\s+${POD_IP}"
|
||||||
|
initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.startupProbe.periodSeconds }}
|
||||||
|
timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}
|
||||||
|
successThreshold: {{ .Values.startupProbe.successThreshold }}
|
||||||
|
failureThreshold: {{ .Values.startupProbe.failureThreshold }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if not .Values.lifecycleHooks }}
|
||||||
|
lifecycle:
|
||||||
|
postStart:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /bin/bash
|
||||||
|
- -c
|
||||||
|
- set -euo pipefail
|
||||||
|
- mkdir -p /tmp/scripts
|
||||||
|
- cp /scripts/init.cql.gz /tmp/scripts/
|
||||||
|
- cd /tmp/scripts && gzip -d init.cql.gz
|
||||||
|
until cqlsh -u cassandra -p "$(cat /opt/bitnami/cassandra/secrets/cassandra-password)" -e "DESCRIBE KEYSPACES" | grep -q 'system_schema'; do
|
||||||
|
echo "Waiting for Cassandra to fully start..."
|
||||||
|
sleep 5
|
||||||
|
done
|
||||||
|
- cqlsh -u cassandra -p "$(cat /opt/bitnami/cassandra/secrets/cassandra-password)" -f /tmp/scripts/init.cql
|
||||||
|
preStop:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- bash
|
||||||
|
- -ec
|
||||||
|
{{- if not .Values.persistence.enabled }}
|
||||||
|
- nodetool decommission
|
||||||
|
{{- else }}
|
||||||
|
- nodetool drain
|
||||||
|
{{- end }}
|
||||||
|
{{- else if .Values.lifecycleHooks }}
|
||||||
|
lifecycle: {{- include "common.tplvalues.render" (dict "value" .Values.lifecycleHooks "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
ports:
|
||||||
|
- name: intra
|
||||||
|
containerPort: {{ .Values.containerPorts.intra | default "7000" }}
|
||||||
|
{{- if .Values.hostNetwork }}
|
||||||
|
hostPort: {{ .Values.containerPorts.intra }}
|
||||||
|
{{- else if .Values.hostPorts.intra }}
|
||||||
|
hostPort: {{ .Values.hostPorts.intra }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if (ne (include "cassandra.internode.tlsEncryption" .) "none") }}
|
||||||
|
- name: tls
|
||||||
|
containerPort: {{ .Values.containerPorts.tls | default "7001" }}
|
||||||
|
{{- if .Values.hostNetwork }}
|
||||||
|
hostPort: {{ .Values.containerPorts.tls }}
|
||||||
|
{{- else if .Values.hostPorts.tls }}
|
||||||
|
hostPort: {{ .Values.hostPorts.tls }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
- name: jmx
|
||||||
|
containerPort: {{ .Values.containerPorts.jmx | default "7199" }}
|
||||||
|
{{- if .Values.hostNetwork }}
|
||||||
|
hostPort: {{ .Values.containerPorts.jmx }}
|
||||||
|
{{- else if .Values.hostPorts.jmx }}
|
||||||
|
hostPort: {{ .Values.hostPorts.jmx }}
|
||||||
|
{{- end }}
|
||||||
|
- name: cql
|
||||||
|
containerPort: {{ .Values.containerPorts.cql | default "9042" }}
|
||||||
|
{{- if .Values.hostNetwork }}
|
||||||
|
hostPort: {{ .Values.containerPorts.cql }}
|
||||||
|
{{- else if .Values.hostPorts.cql }}
|
||||||
|
hostPort: {{ .Values.hostPorts.cql }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.resources }}
|
||||||
|
resources: {{ toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- else if ne .Values.resourcesPreset "none" }}
|
||||||
|
resources: {{- include "common.resources.preset" (dict "type" .Values.resourcesPreset) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: script-volume
|
||||||
|
mountPath: /scripts
|
||||||
|
- name: data
|
||||||
|
mountPath: {{ .Values.persistence.mountPath }}
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: cassandra-secrets
|
||||||
|
mountPath: /opt/bitnami/cassandra/secrets
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.persistence.commitLogMountPath }}
|
||||||
|
- name: commitlog
|
||||||
|
mountPath: {{ .Values.persistence.commitLogMountPath }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if (include "cassandra.tlsEncryption" . ) }}
|
||||||
|
- name: certs-shared
|
||||||
|
mountPath: /opt/bitnami/cassandra/certs
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.initDBConfigMap .Values.initDB }}
|
||||||
|
- name: init-db-cm
|
||||||
|
mountPath: /docker-entrypoint-initdb.d/configmap
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.initDBSecret }}
|
||||||
|
- name: init-db-secret
|
||||||
|
mountPath: /docker-entrypoint-initdb.d/secret
|
||||||
|
{{- end }}
|
||||||
|
{{ if .Values.existingConfiguration }}
|
||||||
|
- name: configurations
|
||||||
|
mountPath: {{ .Values.persistence.mountPath }}/conf
|
||||||
|
{{- end }}
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /tmp
|
||||||
|
subPath: tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/cassandra/conf
|
||||||
|
subPath: app-conf-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/cassandra/tmp
|
||||||
|
subPath: app-tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/cassandra/logs
|
||||||
|
subPath: app-logs-dir
|
||||||
|
{{- if .Values.extraVolumeMounts }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.extraVolumeMounts "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.enabled }}
|
||||||
|
- name: metrics
|
||||||
|
image: {{ include "cassandra.metrics.image" . }}
|
||||||
|
imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }}
|
||||||
|
{{- if .Values.diagnosticMode.enabled }}
|
||||||
|
command: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 12 }}
|
||||||
|
args: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
ports:
|
||||||
|
- name: metrics
|
||||||
|
containerPort: {{ .Values.metrics.containerPorts.http | default "8080" }}
|
||||||
|
{{- if .Values.hostNetwork }}
|
||||||
|
hostPort: {{ .Values.metrics.containerPorts.http }}
|
||||||
|
{{- else if .Values.metrics.hostPorts.http }}
|
||||||
|
hostPort: {{ .Values.metrics.hostPorts.http }}
|
||||||
|
{{- end }}
|
||||||
|
protocol: TCP
|
||||||
|
- name: jmx
|
||||||
|
containerPort: {{ .Values.metrics.containerPorts.jmx | default "5555" }}
|
||||||
|
{{- if .Values.hostNetwork }}
|
||||||
|
hostPort: {{ .Values.metrics.containerPorts.jmx }}
|
||||||
|
{{- else if .Values.metrics.hostPorts.jmx }}
|
||||||
|
hostPort: {{ .Values.metrics.hostPorts.jmx }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.metrics.resources }}
|
||||||
|
resources: {{- toYaml .Values.metrics.resources | nindent 12 }}
|
||||||
|
{{- else if ne .Values.metrics.resourcesPreset "none" }}
|
||||||
|
resources: {{- include "common.resources.preset" (dict "type" .Values.metrics.resourcesPreset) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if not .Values.diagnosticMode.enabled }}
|
||||||
|
livenessProbe:
|
||||||
|
tcpSocket:
|
||||||
|
port: metrics
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /metrics
|
||||||
|
port: metrics
|
||||||
|
initialDelaySeconds: {{ .Values.metrics.readinessProbe.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.metrics.readinessProbe.periodSeconds }}
|
||||||
|
timeoutSeconds: {{ .Values.metrics.readinessProbe.timeoutSeconds }}
|
||||||
|
failureThreshold: {{ .Values.metrics.readinessProbe.failureThreshold }}
|
||||||
|
successThreshold: {{ .Values.metrics.readinessProbe.successThreshold }}
|
||||||
|
{{- end }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: metrics-conf
|
||||||
|
mountPath: /opt/bitnami/cassandra-exporter/config.yml
|
||||||
|
subPath: config.yml
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /tmp
|
||||||
|
subPath: tmp-dir
|
||||||
|
{{- if .Values.metrics.extraVolumeMounts }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.metrics.extraVolumeMounts "context" $) | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.sidecars }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.sidecars "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: script-volume
|
||||||
|
configMap:
|
||||||
|
name: cassandra-init-script
|
||||||
|
- name: metrics-conf
|
||||||
|
configMap:
|
||||||
|
name: {{ include "cassandra.metricsConfConfigMap" . }}
|
||||||
|
{{- if .Values.usePasswordFiles }}
|
||||||
|
- name: cassandra-secrets
|
||||||
|
projected:
|
||||||
|
sources:
|
||||||
|
- secret:
|
||||||
|
name: {{ include "common.secrets.name" (dict "existingSecret" .Values.dbUser.existingSecret "context" $) }}
|
||||||
|
{{- if or .Values.tls.passwordsSecret .Values.tls.tlsEncryptionSecretName .Values.tls.keystorePassword .Values.tls.truststorePassword .Values.tls.autoGenerated }}
|
||||||
|
- secret:
|
||||||
|
name: {{ include "cassandra.tlsPasswordsSecret" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if (include "cassandra.tlsEncryption" . ) }}
|
||||||
|
- name: certs
|
||||||
|
secret:
|
||||||
|
secretName: {{ include "cassandra.tlsSecretName" . }}
|
||||||
|
defaultMode: 256
|
||||||
|
- name: certs-shared
|
||||||
|
emptyDir:
|
||||||
|
sizeLimit: 500Mi
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.existingConfiguration }}
|
||||||
|
- name: configurations
|
||||||
|
configMap:
|
||||||
|
name: {{ tpl .Values.existingConfiguration $ }}
|
||||||
|
{{- end }}
|
||||||
|
- name: empty-dir
|
||||||
|
emptyDir: {}
|
||||||
|
{{- if or .Values.initDB .Values.initDBConfigMap }}
|
||||||
|
- name: init-db-cm
|
||||||
|
configMap:
|
||||||
|
name: {{ ternary (printf "%s-init-scripts" (include "common.names.fullname" .)) (tpl .Values.initDBConfigMap $) (empty .Values.initDBConfigMap) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.initDBSecret }}
|
||||||
|
- name: init-db-secret
|
||||||
|
secret:
|
||||||
|
secretName: {{ tpl .Values.initDBSecret $ }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.extraVolumes }}
|
||||||
|
{{- include "common.tplvalues.render" (dict "value" .Values.extraVolumes "context" $) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if and .Values.persistence.enabled .Values.persistence.existingClaim }}
|
||||||
|
- name: data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: {{ tpl .Values.persistence.existingClaim $ }}
|
||||||
|
{{- else if not .Values.persistence.enabled }}
|
||||||
|
- name: data
|
||||||
|
emptyDir: {}
|
||||||
|
{{- else }}
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: data
|
||||||
|
labels: {{- include "common.labels.matchLabels" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 10 }}
|
||||||
|
{{- if .Values.persistence.annotations }}
|
||||||
|
annotations: {{- toYaml .Values.persistence.annotations | nindent 10 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
{{- range .Values.persistence.accessModes }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.persistence.size | quote }}
|
||||||
|
{{- include "common.storage.class" (dict "persistence" .Values.persistence "global" .Values.global) | nindent 8 }}
|
||||||
|
{{- if .Values.persistence.commitLogMountPath }}
|
||||||
|
- metadata:
|
||||||
|
name: commitlog
|
||||||
|
labels: {{- include "common.labels.matchLabels" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 10 }}
|
||||||
|
{{- if .Values.persistence.annotations }}
|
||||||
|
annotations: {{- toYaml .Values.persistence.annotations | nindent 10 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
{{- range .Values.persistence.accessModes }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.persistence.commitLogsize | quote }}
|
||||||
|
{{- include "cassandra.commitstorage.class" (dict "persistence" .Values.persistence "global" .Values.global) | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
30
cassandra/templates/tls-secret.yaml
Normal file
30
cassandra/templates/tls-secret.yaml
Normal file
@ -0,0 +1,30 @@
|
|||||||
|
{{- /*
|
||||||
|
Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
SPDX-License-Identifier: APACHE-2.0
|
||||||
|
*/}}
|
||||||
|
|
||||||
|
{{- if (include "cassandra.createTlsSecret" . ) }}
|
||||||
|
{{- $secretName := printf "%s-crt" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- $ca := genCA "cassandra-ca" 365 }}
|
||||||
|
{{- $fullname := include "common.names.fullname" . }}
|
||||||
|
{{- $releaseNamespace := include "common.names.namespace" . }}
|
||||||
|
{{- $clusterDomain := .Values.clusterDomain }}
|
||||||
|
{{- $serviceName := include "common.names.fullname" . }}
|
||||||
|
{{- $headlessServiceName := printf "%s-headless" (include "common.names.fullname" .) | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- $altNames := list (printf "*.%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "*.%s.%s.svc.%s" $headlessServiceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $headlessServiceName $releaseNamespace $clusterDomain) "localhost" "127.0.0.1" $fullname }}
|
||||||
|
{{- $cert := genSignedCert $fullname nil $altNames 365 $ca }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ $secretName }}
|
||||||
|
namespace: {{ include "common.names.namespace" . | quote }}
|
||||||
|
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
|
||||||
|
{{- if .Values.commonAnnotations }}
|
||||||
|
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
type: kubernetes.io/tls
|
||||||
|
data:
|
||||||
|
tls.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.crt" "defaultValue" $cert.Cert "context" $) }}
|
||||||
|
tls.key: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.key" "defaultValue" $cert.Key "context" $) }}
|
||||||
|
ca.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "ca.crt" "defaultValue" $ca.Cert "context" $) }}
|
||||||
|
{{- end }}
|
||||||
983
cassandra/values.yaml
Normal file
983
cassandra/values.yaml
Normal file
@ -0,0 +1,983 @@
|
|||||||
|
# Copyright Broadcom, Inc. All Rights Reserved.
|
||||||
|
# SPDX-License-Identifier: APACHE-2.0
|
||||||
|
|
||||||
|
## @section Global parameters
|
||||||
|
## Global Docker image parameters
|
||||||
|
## Please, note that this will override the image parameters, including dependencies, configured to use the global value
|
||||||
|
## Current available global Docker image parameters: imageRegistry, imagePullSecrets and storageClass
|
||||||
|
##
|
||||||
|
|
||||||
|
## @param global.imageRegistry Global Docker image registry
|
||||||
|
## @param global.imagePullSecrets Global Docker registry secret names as an array
|
||||||
|
## @param global.defaultStorageClass Global default StorageClass for Persistent Volume(s)
|
||||||
|
##
|
||||||
|
global:
|
||||||
|
imageRegistry: "registry.co-work.ru"
|
||||||
|
## E.g.
|
||||||
|
## imagePullSecrets:
|
||||||
|
## - myRegistryKeySecretName
|
||||||
|
##
|
||||||
|
imagePullSecrets: [docker-registry-secret]
|
||||||
|
defaultStorageClass: ""
|
||||||
|
## Security parameters
|
||||||
|
##
|
||||||
|
security:
|
||||||
|
## @param global.security.allowInsecureImages Allows skipping image verification
|
||||||
|
allowInsecureImages: true
|
||||||
|
## Compatibility adaptations for Kubernetes platforms
|
||||||
|
##
|
||||||
|
compatibility:
|
||||||
|
## Compatibility adaptations for Openshift
|
||||||
|
##
|
||||||
|
openshift:
|
||||||
|
## @param global.compatibility.openshift.adaptSecurityContext Adapt the securityContext sections of the deployment to make them compatible with Openshift restricted-v2 SCC: remove runAsUser, runAsGroup and fsGroup and let the platform use their allowed default IDs. Possible values: auto (apply if the detected running cluster is Openshift), force (perform the adaptation always), disabled (do not perform adaptation)
|
||||||
|
##
|
||||||
|
adaptSecurityContext: auto
|
||||||
|
## @section Common parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## @param nameOverride String to partially override common.names.fullname
|
||||||
|
##
|
||||||
|
nameOverride: ""
|
||||||
|
## @param fullnameOverride String to fully override common.names.fullname
|
||||||
|
##
|
||||||
|
fullnameOverride: ""
|
||||||
|
## @param kubeVersion Force target Kubernetes version (using Helm capabilities if not set)
|
||||||
|
##
|
||||||
|
kubeVersion: ""
|
||||||
|
## @param commonLabels Labels to add to all deployed objects (sub-charts are not considered)
|
||||||
|
##
|
||||||
|
commonLabels: {}
|
||||||
|
## @param commonAnnotations Annotations to add to all deployed objects
|
||||||
|
##
|
||||||
|
commonAnnotations: {}
|
||||||
|
## @param clusterDomain Kubernetes cluster domain name
|
||||||
|
##
|
||||||
|
clusterDomain: cluster.local
|
||||||
|
## @param extraDeploy Array of extra objects to deploy with the release
|
||||||
|
##
|
||||||
|
extraDeploy: []
|
||||||
|
## @param usePasswordFiles Mount credentials as files instead of using environment variables
|
||||||
|
##
|
||||||
|
usePasswordFiles: true
|
||||||
|
## Enable diagnostic mode in the deployment
|
||||||
|
##
|
||||||
|
diagnosticMode:
|
||||||
|
## @param diagnosticMode.enabled Enable diagnostic mode (all probes will be disabled and the command will be overridden)
|
||||||
|
##
|
||||||
|
enabled: false
|
||||||
|
## @param diagnosticMode.command Command to override all containers in the deployment
|
||||||
|
##
|
||||||
|
command:
|
||||||
|
- sleep
|
||||||
|
## @param diagnosticMode.args Args to override all containers in the deployment
|
||||||
|
##
|
||||||
|
args:
|
||||||
|
- infinity
|
||||||
|
## @section Cassandra parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## Bitnami Cassandra image
|
||||||
|
## ref: https://hub.docker.com/r/bitnami/cassandra/tags/
|
||||||
|
## @param image.registry [default: REGISTRY_NAME] Cassandra image registry
|
||||||
|
## @param image.repository [default: REPOSITORY_NAME/cassandra] Cassandra image repository
|
||||||
|
## @skip image.tag Cassandra image tag (immutable tags are recommended)
|
||||||
|
## @param image.digest Cassandra image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag
|
||||||
|
## @param image.pullPolicy image pull policy
|
||||||
|
## @param image.pullSecrets Cassandra image pull secrets
|
||||||
|
## @param image.debug Enable image debug mode
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: docker.io
|
||||||
|
repository: bitnami/cassandra
|
||||||
|
tag: 5.0.3-debian-12-r6
|
||||||
|
digest: ""
|
||||||
|
## Specify a imagePullPolicy
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/containers/images/#pre-pulled-images
|
||||||
|
##
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
## Optionally specify an array of imagePullSecrets.
|
||||||
|
## Secrets must be manually created in the namespace.
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||||
|
## e.g:
|
||||||
|
## pullSecrets:
|
||||||
|
## - myRegistryKeySecretName
|
||||||
|
##
|
||||||
|
pullSecrets: []
|
||||||
|
## Enable debug mode
|
||||||
|
##
|
||||||
|
debug: false
|
||||||
|
## Secret with keystore, keystore password, truststore, truststore password
|
||||||
|
## DEPRECATED. Use tls.existingSecret instead
|
||||||
|
# tlsEncryptionSecretName:
|
||||||
|
|
||||||
|
## Database credentials
|
||||||
|
## @param dbUser.user Cassandra admin user
|
||||||
|
## @param dbUser.forcePassword Force the user to provide a non
|
||||||
|
## @param dbUser.password Password for `dbUser.user`. Randomly generated if empty
|
||||||
|
## @param dbUser.existingSecret Use an existing secret object for `dbUser.user` password (will ignore `dbUser.password`)
|
||||||
|
##
|
||||||
|
dbUser:
|
||||||
|
user: cassandra
|
||||||
|
forcePassword: false
|
||||||
|
password: ""
|
||||||
|
## Use an existing secrets which already stores your password data.
|
||||||
|
## for backwards compatibility, existingSecret can be a simple string,
|
||||||
|
## referencing the secret by name.
|
||||||
|
## existingSecret:
|
||||||
|
## ## Name of the existing secret
|
||||||
|
## ##
|
||||||
|
## name: mySecret
|
||||||
|
## ## Key mapping where <key> is the value which the deployment is expecting and
|
||||||
|
## ## <value> is the name of the key in the existing secret.
|
||||||
|
## ##
|
||||||
|
## keyMapping:
|
||||||
|
## cassandra-password: myCassandraPasswordKey
|
||||||
|
##
|
||||||
|
existingSecret: "cassandra-static-user-passwords"
|
||||||
|
existingSecretPasswordKey: ""
|
||||||
|
## @param initDB Object with cql scripts. Useful for creating a keyspace and pre-populating data
|
||||||
|
##
|
||||||
|
initDB: {}
|
||||||
|
## @param initDBConfigMap ConfigMap with cql scripts. Useful for creating a keyspace and pre-populating data
|
||||||
|
##
|
||||||
|
initDBConfigMap: "cassandra-init-script"
|
||||||
|
|
||||||
|
## @param initDBSecret Secret with cql script (with sensitive data). Useful for creating a keyspace and pre-populating data
|
||||||
|
##
|
||||||
|
initDBSecret: ""
|
||||||
|
## @param existingConfiguration ConfigMap with custom cassandra configuration files. This overrides any other Cassandra configuration set in the chart
|
||||||
|
##
|
||||||
|
existingConfiguration: ""
|
||||||
|
## Cluster parameters
|
||||||
|
## @param cluster.name Cassandra cluster name
|
||||||
|
## @param cluster.seedCount Number of seed nodes
|
||||||
|
## @param cluster.numTokens Number of tokens for each node
|
||||||
|
## @param cluster.datacenter Datacenter name
|
||||||
|
## @param cluster.rack Rack name
|
||||||
|
## @param cluster.endpointSnitch Endpoint Snitch
|
||||||
|
## @param cluster.clientEncryption Client Encryption
|
||||||
|
## @param cluster.extraSeeds For an external/second cassandra ring.
|
||||||
|
## @param cluster.enableUDF Enable User defined functions
|
||||||
|
##
|
||||||
|
cluster:
|
||||||
|
name: cassandra
|
||||||
|
seedCount: 1
|
||||||
|
numTokens: 256
|
||||||
|
datacenter: datacenter1
|
||||||
|
rack: rack1
|
||||||
|
endpointSnitch: SimpleSnitch
|
||||||
|
clientEncryption: false
|
||||||
|
## eg:
|
||||||
|
## extraSeeds:
|
||||||
|
## - hostname/IP
|
||||||
|
## - hostname/IP
|
||||||
|
##
|
||||||
|
extraSeeds: []
|
||||||
|
enableUDF: false
|
||||||
|
## JVM Settings
|
||||||
|
## @param jvm.extraOpts Set the value for Java Virtual Machine extra options
|
||||||
|
## @param jvm.maxHeapSize Set Java Virtual Machine maximum heap size (MAX_HEAP_SIZE). Calculated automatically if `nil`
|
||||||
|
## @param jvm.newHeapSize Set Java Virtual Machine new heap size (HEAP_NEWSIZE). Calculated automatically if `nil`
|
||||||
|
##
|
||||||
|
jvm:
|
||||||
|
extraOpts: ""
|
||||||
|
## Memory settings: These are calculated automatically unless specified otherwise
|
||||||
|
## To run on environments with little resources (<= 8GB), tune your heap settings:
|
||||||
|
## - calculate 1/2 ram and cap to 1024MB
|
||||||
|
## - calculate 1/4 ram and cap to 8192MB
|
||||||
|
## - pick the max
|
||||||
|
##
|
||||||
|
maxHeapSize: ""
|
||||||
|
## newHeapSize:
|
||||||
|
## A good guideline is 100 MB per CPU core.
|
||||||
|
## - min(100 * num_cores, 1/4 * heap size)
|
||||||
|
## ref: https://docs.datastax.com/en/archived/cassandra/2.0/cassandra/operations/ops_tune_jvm_c.html
|
||||||
|
##
|
||||||
|
newHeapSize: ""
|
||||||
|
## @param command Command for running the container (set to default if not set). Use array form
|
||||||
|
##
|
||||||
|
command: []
|
||||||
|
## @param args Args for running the container (set to default if not set). Use array form
|
||||||
|
##
|
||||||
|
args: []
|
||||||
|
## @param extraEnvVars Extra environment variables to be set on cassandra container
|
||||||
|
## For example:
|
||||||
|
## - name: FOO
|
||||||
|
## value: BAR
|
||||||
|
##
|
||||||
|
extraEnvVars:
|
||||||
|
- name: CASSANDRA_CFG_YAML_SASI_INDEXES_ENABLED
|
||||||
|
value: "true"
|
||||||
|
## @param extraEnvVarsCM Name of existing ConfigMap containing extra env vars
|
||||||
|
##
|
||||||
|
extraEnvVarsCM: ""
|
||||||
|
## @param extraEnvVarsSecret Name of existing Secret containing extra env vars
|
||||||
|
##
|
||||||
|
extraEnvVarsSecret: ""
|
||||||
|
## @section Statefulset parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## @param replicaCount Number of Cassandra replicas
|
||||||
|
##
|
||||||
|
replicaCount: 3
|
||||||
|
## @param updateStrategy.type updateStrategy for Cassandra statefulset
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies
|
||||||
|
##
|
||||||
|
updateStrategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
## @param automountServiceAccountToken Mount Service Account token in pod
|
||||||
|
##
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
## @param hostAliases Add deployment host aliases
|
||||||
|
## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/
|
||||||
|
##
|
||||||
|
hostAliases: []
|
||||||
|
## @param podManagementPolicy StatefulSet pod management policy
|
||||||
|
##
|
||||||
|
podManagementPolicy: OrderedReady
|
||||||
|
## @param priorityClassName Cassandra pods' priority.
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/
|
||||||
|
##
|
||||||
|
priorityClassName: ""
|
||||||
|
## @param podAnnotations Additional pod annotations
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
|
||||||
|
##
|
||||||
|
podAnnotations: {}
|
||||||
|
## @param podLabels Additional pod labels
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
|
||||||
|
##
|
||||||
|
podLabels: {}
|
||||||
|
## @param podAffinityPreset Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
|
||||||
|
##
|
||||||
|
podAffinityPreset: ""
|
||||||
|
## @param podAntiAffinityPreset Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
|
||||||
|
##
|
||||||
|
podAntiAffinityPreset: soft
|
||||||
|
## Node affinity preset
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity
|
||||||
|
##
|
||||||
|
nodeAffinityPreset:
|
||||||
|
## @param nodeAffinityPreset.type Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
|
||||||
|
##
|
||||||
|
type: ""
|
||||||
|
## @param nodeAffinityPreset.key Node label key to match. Ignored if `affinity` is set
|
||||||
|
##
|
||||||
|
key: ""
|
||||||
|
## @param nodeAffinityPreset.values Node label values to match. Ignored if `affinity` is set
|
||||||
|
## E.g.
|
||||||
|
## values:
|
||||||
|
## - e2e-az1
|
||||||
|
## - e2e-az2
|
||||||
|
##
|
||||||
|
values: []
|
||||||
|
## @param affinity Affinity for pod assignment
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
|
||||||
|
## NOTE: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set
|
||||||
|
##
|
||||||
|
affinity:
|
||||||
|
podAntiAffinity:
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: cassandra
|
||||||
|
topologyKey: "kubernetes.io/hostname"
|
||||||
|
## @param nodeSelector Node labels for pod assignment
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/
|
||||||
|
##
|
||||||
|
nodeSelector: {}
|
||||||
|
## @param tolerations Tolerations for pod assignment
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
|
||||||
|
##
|
||||||
|
tolerations:
|
||||||
|
- key: "node-role.kubernetes.io/control-plane"
|
||||||
|
operator: "Exists"
|
||||||
|
effect: "NoSchedule"
|
||||||
|
## @param topologySpreadConstraints Topology Spread Constraints for pod assignment
|
||||||
|
## https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
|
||||||
|
## The value is evaluated as a template
|
||||||
|
##
|
||||||
|
topologySpreadConstraints: []
|
||||||
|
## Pod security context
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod
|
||||||
|
## @param podSecurityContext.enabled Enabled Cassandra pods' Security Context
|
||||||
|
## @param podSecurityContext.fsGroupChangePolicy Set filesystem group change policy
|
||||||
|
## @param podSecurityContext.sysctls Set kernel settings using the sysctl interface
|
||||||
|
## @param podSecurityContext.supplementalGroups Set filesystem extra groups
|
||||||
|
## @param podSecurityContext.fsGroup Set Cassandra pod's Security Context fsGroup
|
||||||
|
##
|
||||||
|
podSecurityContext:
|
||||||
|
enabled: true
|
||||||
|
fsGroupChangePolicy: Always
|
||||||
|
sysctls: []
|
||||||
|
supplementalGroups: []
|
||||||
|
fsGroup: 1001
|
||||||
|
## Configure Container Security Context (only main container)
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||||
|
## @param containerSecurityContext.enabled Enabled Cassandra containers' Security Context
|
||||||
|
## @param containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container
|
||||||
|
## @param containerSecurityContext.runAsUser Set Cassandra containers' Security Context runAsUser
|
||||||
|
## @param containerSecurityContext.runAsGroup Set Cassandra containers' Security Context runAsGroup
|
||||||
|
## @param containerSecurityContext.allowPrivilegeEscalation Set Cassandra containers' Security Context allowPrivilegeEscalation
|
||||||
|
## @param containerSecurityContext.capabilities.drop Set Cassandra containers' Security Context capabilities to be dropped
|
||||||
|
## @param containerSecurityContext.readOnlyRootFilesystem Set Cassandra containers' Security Context readOnlyRootFilesystem
|
||||||
|
## @param containerSecurityContext.runAsNonRoot Set Cassandra containers' Security Context runAsNonRoot
|
||||||
|
## @param containerSecurityContext.privileged Set container's Security Context privileged
|
||||||
|
## @param containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
|
||||||
|
##
|
||||||
|
containerSecurityContext:
|
||||||
|
enabled: true
|
||||||
|
seLinuxOptions: {}
|
||||||
|
runAsUser: 1001
|
||||||
|
runAsGroup: 1001
|
||||||
|
runAsNonRoot: true
|
||||||
|
privileged: false
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop: ["ALL"]
|
||||||
|
seccompProfile:
|
||||||
|
type: "RuntimeDefault"
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
## Cassandra pods' resource requests and limits
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
|
||||||
|
## Minimum memory for development is 4GB and 2 CPU cores
|
||||||
|
## Minimum memory for production is 8GB and 4 CPU cores
|
||||||
|
## ref: http://docs.datastax.com/en/archived/cassandra/2.0/cassandra/architecture/architecturePlanningHardware_c.html
|
||||||
|
##
|
||||||
|
## We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
## choice for the user. This also increases chances charts run on environments with little
|
||||||
|
## resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
## lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
## @param resourcesPreset Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if resources is set (resources is recommended for production).
|
||||||
|
## More information: https://github.com/bitnami/charts/blob/main/bitnami/common/templates/_resources.tpl#L15
|
||||||
|
##
|
||||||
|
resourcesPreset: "large"
|
||||||
|
## @param resources Set container requests and limits for different resources like CPU or memory (essential for production workloads)
|
||||||
|
## Example:
|
||||||
|
## resources:
|
||||||
|
## requests:
|
||||||
|
## cpu: 2
|
||||||
|
## memory: 512Mi
|
||||||
|
## limits:
|
||||||
|
## cpu: 3
|
||||||
|
## memory: 1024Mi
|
||||||
|
##
|
||||||
|
resources: {}
|
||||||
|
## Configure extra options for Cassandra containers' liveness and readiness probes
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes
|
||||||
|
## @param livenessProbe.enabled Enable livenessProbe
|
||||||
|
## @param livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe
|
||||||
|
## @param livenessProbe.periodSeconds Period seconds for livenessProbe
|
||||||
|
## @param livenessProbe.timeoutSeconds Timeout seconds for livenessProbe
|
||||||
|
## @param livenessProbe.failureThreshold Failure threshold for livenessProbe
|
||||||
|
## @param livenessProbe.successThreshold Success threshold for livenessProbe
|
||||||
|
##
|
||||||
|
livenessProbe:
|
||||||
|
enabled: true
|
||||||
|
initialDelaySeconds: 60
|
||||||
|
periodSeconds: 30
|
||||||
|
timeoutSeconds: 30
|
||||||
|
successThreshold: 1
|
||||||
|
failureThreshold: 5
|
||||||
|
## @param readinessProbe.enabled Enable readinessProbe
|
||||||
|
## @param readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
|
||||||
|
## @param readinessProbe.periodSeconds Period seconds for readinessProbe
|
||||||
|
## @param readinessProbe.timeoutSeconds Timeout seconds for readinessProbe
|
||||||
|
## @param readinessProbe.failureThreshold Failure threshold for readinessProbe
|
||||||
|
## @param readinessProbe.successThreshold Success threshold for readinessProbe
|
||||||
|
##
|
||||||
|
readinessProbe:
|
||||||
|
enabled: true
|
||||||
|
initialDelaySeconds: 60
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 30
|
||||||
|
successThreshold: 1
|
||||||
|
failureThreshold: 5
|
||||||
|
## Configure extra options for startup probe
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#configure-probes
|
||||||
|
## @param startupProbe.enabled Enable startupProbe
|
||||||
|
## @param startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
|
||||||
|
## @param startupProbe.periodSeconds Period seconds for startupProbe
|
||||||
|
## @param startupProbe.timeoutSeconds Timeout seconds for startupProbe
|
||||||
|
## @param startupProbe.failureThreshold Failure threshold for startupProbe
|
||||||
|
## @param startupProbe.successThreshold Success threshold for startupProbe
|
||||||
|
##
|
||||||
|
startupProbe:
|
||||||
|
enabled: false
|
||||||
|
initialDelaySeconds: 0
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 5
|
||||||
|
successThreshold: 1
|
||||||
|
failureThreshold: 60
|
||||||
|
## @param customLivenessProbe Custom livenessProbe that overrides the default one
|
||||||
|
##
|
||||||
|
customLivenessProbe: {}
|
||||||
|
## @param customReadinessProbe Custom readinessProbe that overrides the default one
|
||||||
|
##
|
||||||
|
customReadinessProbe: {}
|
||||||
|
## @param customStartupProbe [object] Override default startup probe
|
||||||
|
##
|
||||||
|
customStartupProbe: {}
|
||||||
|
## @param lifecycleHooks [object] Override default etcd container hooks
|
||||||
|
##
|
||||||
|
lifecycleHooks: {}
|
||||||
|
## @param schedulerName Alternative scheduler
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/
|
||||||
|
##
|
||||||
|
schedulerName: ""
|
||||||
|
## @param terminationGracePeriodSeconds In seconds, time the given to the Cassandra pod needs to terminate gracefully
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod/#termination-of-pods
|
||||||
|
##
|
||||||
|
terminationGracePeriodSeconds: ""
|
||||||
|
## @param extraVolumes Optionally specify extra list of additional volumes for cassandra container
|
||||||
|
##
|
||||||
|
extraVolumes: []
|
||||||
|
## @param extraVolumeMounts Optionally specify extra list of additional volumeMounts for cassandra container
|
||||||
|
##
|
||||||
|
extraVolumeMounts: []
|
||||||
|
## @param initContainers Add additional init containers to the cassandra pods
|
||||||
|
##
|
||||||
|
initContainers: []
|
||||||
|
## @param sidecars Add additional sidecar containers to the cassandra pods
|
||||||
|
##
|
||||||
|
sidecars: []
|
||||||
|
## Cassandra Pod Disruption Budget configuration
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
|
||||||
|
##
|
||||||
|
pdb:
|
||||||
|
## @param pdb.create Enable/disable a Pod Disruption Budget creation
|
||||||
|
##
|
||||||
|
create: true
|
||||||
|
## @param pdb.minAvailable Mininimum number of pods that must still be available after the eviction
|
||||||
|
##
|
||||||
|
minAvailable: ""
|
||||||
|
## @param pdb.maxUnavailable Max number of pods that can be unavailable after the eviction
|
||||||
|
##
|
||||||
|
maxUnavailable: ""
|
||||||
|
## @param hostNetwork Enable HOST Network
|
||||||
|
## If hostNetwork true -> dnsPolicy is set to ClusterFirstWithHostNet
|
||||||
|
##
|
||||||
|
hostNetwork: false
|
||||||
|
## Cassandra container ports to open
|
||||||
|
## If hostNetwork true: the hostPort is set identical to the containerPort
|
||||||
|
## @param containerPorts.intra Intra Port on the Host and Container
|
||||||
|
## @param containerPorts.tls TLS Port on the Host and Container
|
||||||
|
## @param containerPorts.jmx JMX Port on the Host and Container
|
||||||
|
## @param containerPorts.cql CQL Port on the Host and Container
|
||||||
|
##
|
||||||
|
containerPorts:
|
||||||
|
intra: 7000
|
||||||
|
tls: 7001
|
||||||
|
jmx: 7199
|
||||||
|
cql: 9042
|
||||||
|
## Cassandra ports to be exposed as hostPort
|
||||||
|
## If hostNetwork is false, only the ports specified here will be exposed (or not if set to an empty string)
|
||||||
|
## @param hostPorts.intra Intra Port on the Host
|
||||||
|
## @param hostPorts.tls TLS Port on the Host
|
||||||
|
## @param hostPorts.jmx JMX Port on the Host
|
||||||
|
## @param hostPorts.cql CQL Port on the Host
|
||||||
|
##
|
||||||
|
hostPorts:
|
||||||
|
intra: ""
|
||||||
|
tls: ""
|
||||||
|
jmx: ""
|
||||||
|
cql: ""
|
||||||
|
## @section RBAC parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## Cassandra pods ServiceAccount
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
|
||||||
|
##
|
||||||
|
serviceAccount:
|
||||||
|
## @param serviceAccount.create Enable the creation of a ServiceAccount for Cassandra pods
|
||||||
|
##
|
||||||
|
create: true
|
||||||
|
## @param serviceAccount.name The name of the ServiceAccount to use.
|
||||||
|
## If not set and create is true, a name is generated using the cassandra.fullname template
|
||||||
|
##
|
||||||
|
name: ""
|
||||||
|
## @param serviceAccount.annotations Annotations for Cassandra Service Account
|
||||||
|
##
|
||||||
|
annotations: {}
|
||||||
|
## @param serviceAccount.automountServiceAccountToken Automount API credentials for a service account.
|
||||||
|
##
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
## @section Traffic Exposure Parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## Cassandra service parameters
|
||||||
|
##
|
||||||
|
service:
|
||||||
|
## @param service.type Cassandra service type
|
||||||
|
##
|
||||||
|
type: ClusterIP
|
||||||
|
## @param service.ports.cql Cassandra service CQL Port
|
||||||
|
## @param service.ports.metrics Cassandra service metrics port
|
||||||
|
##
|
||||||
|
ports:
|
||||||
|
cql: 9042
|
||||||
|
metrics: 8080
|
||||||
|
## Node ports to expose
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
|
||||||
|
## @param service.nodePorts.cql Node port for CQL
|
||||||
|
## @param service.nodePorts.metrics Node port for metrics
|
||||||
|
##
|
||||||
|
nodePorts:
|
||||||
|
cql: ""
|
||||||
|
metrics: ""
|
||||||
|
## @param service.extraPorts Extra ports to expose in the service (normally used with the `sidecar` value)
|
||||||
|
##
|
||||||
|
extraPorts: []
|
||||||
|
## @param service.loadBalancerIP LoadBalancerIP if service type is `LoadBalancer`
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer
|
||||||
|
##
|
||||||
|
loadBalancerIP: ""
|
||||||
|
## @param service.loadBalancerSourceRanges Service Load Balancer sources
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service
|
||||||
|
## e.g:
|
||||||
|
## loadBalancerSourceRanges:
|
||||||
|
## - 10.10.10.0/24
|
||||||
|
##
|
||||||
|
loadBalancerSourceRanges: []
|
||||||
|
## @param service.clusterIP Service Cluster IP
|
||||||
|
## e.g.:
|
||||||
|
## clusterIP: None
|
||||||
|
##
|
||||||
|
clusterIP: ""
|
||||||
|
## @param service.externalTrafficPolicy Service external traffic policy
|
||||||
|
## ref https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
|
||||||
|
##
|
||||||
|
externalTrafficPolicy: Cluster
|
||||||
|
## @param service.annotations Provide any additional annotations which may be required.
|
||||||
|
## This can be used to set the LoadBalancer service type to internal only.
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer
|
||||||
|
##
|
||||||
|
annotations: {}
|
||||||
|
## @param service.sessionAffinity Session Affinity for Kubernetes service, can be "None" or "ClientIP"
|
||||||
|
## If "ClientIP", consecutive client requests will be directed to the same Pod
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
|
||||||
|
##
|
||||||
|
sessionAffinity: None
|
||||||
|
## @param service.sessionAffinityConfig Additional settings for the sessionAffinity
|
||||||
|
## sessionAffinityConfig:
|
||||||
|
## clientIP:
|
||||||
|
## timeoutSeconds: 300
|
||||||
|
##
|
||||||
|
sessionAffinityConfig: {}
|
||||||
|
## Headless service properties
|
||||||
|
##
|
||||||
|
headless:
|
||||||
|
## @param service.headless.annotations Annotations for the headless service.
|
||||||
|
##
|
||||||
|
annotations: {}
|
||||||
|
## Network Policies
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/services-networking/network-policies/
|
||||||
|
##
|
||||||
|
networkPolicy:
|
||||||
|
## @param networkPolicy.enabled Specifies whether a NetworkPolicy should be created
|
||||||
|
##
|
||||||
|
enabled: true
|
||||||
|
## @param networkPolicy.allowExternal Don't require server label for connections
|
||||||
|
## The Policy model to apply. When set to false, only pods with the correct
|
||||||
|
## server label will have network access to the ports server is listening
|
||||||
|
## on. When true, server will accept connections from any source
|
||||||
|
## (with the correct destination port).
|
||||||
|
##
|
||||||
|
allowExternal: true
|
||||||
|
## @param networkPolicy.allowExternalEgress Allow the pod to access any range of port and all destinations.
|
||||||
|
##
|
||||||
|
allowExternalEgress: true
|
||||||
|
## @param networkPolicy.extraIngress [array] Add extra ingress rules to the NetworkPolicy
|
||||||
|
## e.g:
|
||||||
|
## extraIngress:
|
||||||
|
## - ports:
|
||||||
|
## - port: 1234
|
||||||
|
## from:
|
||||||
|
## - podSelector:
|
||||||
|
## - matchLabels:
|
||||||
|
## - role: frontend
|
||||||
|
## - podSelector:
|
||||||
|
## - matchExpressions:
|
||||||
|
## - key: role
|
||||||
|
## operator: In
|
||||||
|
## values:
|
||||||
|
## - frontend
|
||||||
|
extraIngress: []
|
||||||
|
## @param networkPolicy.extraEgress [array] Add extra ingress rules to the NetworkPolicy (ignored if allowExternalEgress=true)
|
||||||
|
## e.g:
|
||||||
|
## extraEgress:
|
||||||
|
## - ports:
|
||||||
|
## - port: 1234
|
||||||
|
## to:
|
||||||
|
## - podSelector:
|
||||||
|
## - matchLabels:
|
||||||
|
## - role: frontend
|
||||||
|
## - podSelector:
|
||||||
|
## - matchExpressions:
|
||||||
|
## - key: role
|
||||||
|
## operator: In
|
||||||
|
## values:
|
||||||
|
## - frontend
|
||||||
|
##
|
||||||
|
extraEgress: []
|
||||||
|
## @param networkPolicy.ingressNSMatchLabels [object] Labels to match to allow traffic from other namespaces
|
||||||
|
## @param networkPolicy.ingressNSPodMatchLabels [object] Pod labels to match to allow traffic from other namespaces
|
||||||
|
##
|
||||||
|
ingressNSMatchLabels: {}
|
||||||
|
ingressNSPodMatchLabels: {}
|
||||||
|
## @section Persistence parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## Enable persistence using Persistent Volume Claims
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/storage/persistent-volumes/
|
||||||
|
##
|
||||||
|
persistence:
|
||||||
|
## @param persistence.enabled Enable Cassandra data persistence using PVC, use a Persistent Volume Claim, If false, use emptyDir
|
||||||
|
##
|
||||||
|
enabled: true
|
||||||
|
## @param persistence.existingClaim Name of an existing PVC to use
|
||||||
|
##
|
||||||
|
existingClaim: ""
|
||||||
|
## @param persistence.storageClass PVC Storage Class for Cassandra data volume
|
||||||
|
## If defined, storageClassName: <storageClass>
|
||||||
|
## If set to "-", storageClassName: "", which disables dynamic provisioning
|
||||||
|
## If undefined (the default) or set to null, no storageClassName spec is
|
||||||
|
## set, choosing the default provisioner. (gp2 on AWS, standard on
|
||||||
|
## GKE, AWS & OpenStack)
|
||||||
|
##
|
||||||
|
storageClass: "client3"
|
||||||
|
## @param persistence.commitStorageClass PVC Storage Class for Cassandra Commit Log volume
|
||||||
|
## Storage class to use with CASSANDRA_COMMITLOG_DIR to reduce the concurrence for writing data and commit logs
|
||||||
|
## ref: https://github.com/bitnami/containers/tree/main/bitnami/cassandra
|
||||||
|
## If set to "-", commitStorageClass: "", which disables dynamic provisioning
|
||||||
|
## If undefined (the default) or set to null, no storageClassName spec is
|
||||||
|
## set, choosing the default provisioner. (gp2 on AWS, standard on
|
||||||
|
## GKE, AWS & OpenStack)
|
||||||
|
##
|
||||||
|
commitStorageClass: ""
|
||||||
|
## @param persistence.annotations Persistent Volume Claim annotations
|
||||||
|
##
|
||||||
|
annotations: {}
|
||||||
|
## @param persistence.accessModes Persistent Volume Access Mode
|
||||||
|
##
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
## @param persistence.size PVC Storage Request for Cassandra data volume
|
||||||
|
##
|
||||||
|
size: 8Gi
|
||||||
|
## @param persistence.commitLogsize PVC Storage Request for Cassandra commit log volume. Unset by default
|
||||||
|
##
|
||||||
|
commitLogsize: 2Gi
|
||||||
|
## @param persistence.mountPath The path the data volume will be mounted at
|
||||||
|
##
|
||||||
|
mountPath: /bitnami/cassandra
|
||||||
|
## @param persistence.commitLogMountPath The path the commit log volume will be mounted at. Unset by default. Set it to '/bitnami/cassandra/commitlog' to enable a separate commit log volume
|
||||||
|
##
|
||||||
|
# commitLogMountPath: /bitnami/cassandra/commitlog
|
||||||
|
commitLogMountPath: ""
|
||||||
|
## @section Volume Permissions parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## Init containers parameters:
|
||||||
|
## volumePermissions: Change the owner and group of the persistent volume mountpoint to runAsUser:fsGroup values from the securityContext section.
|
||||||
|
##
|
||||||
|
volumePermissions:
|
||||||
|
## @param volumePermissions.enabled Enable init container that changes the owner and group of the persistent volume
|
||||||
|
##
|
||||||
|
enabled: false
|
||||||
|
## @param volumePermissions.image.registry [default: REGISTRY_NAME] Init container volume image registry
|
||||||
|
## @param volumePermissions.image.repository [default: REPOSITORY_NAME/os-shell] Init container volume image repository
|
||||||
|
## @skip volumePermissions.image.tag Init container volume image tag (immutable tags are recommended)
|
||||||
|
## @param volumePermissions.image.digest Init container volume image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag
|
||||||
|
## @param volumePermissions.image.pullPolicy Init container volume pull policy
|
||||||
|
## @param volumePermissions.image.pullSecrets Specify docker-registry secret names as an array
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: docker.io
|
||||||
|
repository: bitnami/os-shell
|
||||||
|
tag: 12-debian-12-r39
|
||||||
|
digest: ""
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
## Optionally specify an array of imagePullSecrets.
|
||||||
|
## Secrets must be manually created in the namespace.
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||||
|
## e.g:
|
||||||
|
## pullSecrets:
|
||||||
|
## - myRegistryKeySecretName
|
||||||
|
##
|
||||||
|
pullSecrets: []
|
||||||
|
## Init container' resource requests and limits
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
|
||||||
|
## We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
## choice for the user. This also increases chances charts run on environments with little
|
||||||
|
## resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
## lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
## @param volumePermissions.resourcesPreset Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if volumePermissions.resources is set (volumePermissions.resources is recommended for production).
|
||||||
|
## More information: https://github.com/bitnami/charts/blob/main/bitnami/common/templates/_resources.tpl#L15
|
||||||
|
##
|
||||||
|
resourcesPreset: "nano"
|
||||||
|
## @param volumePermissions.resources Set container requests and limits for different resources like CPU or memory (essential for production workloads)
|
||||||
|
## Example:
|
||||||
|
## resources:
|
||||||
|
## requests:
|
||||||
|
## cpu: 2
|
||||||
|
## memory: 512Mi
|
||||||
|
## limits:
|
||||||
|
## cpu: 3
|
||||||
|
## memory: 1024Mi
|
||||||
|
##
|
||||||
|
resources: {}
|
||||||
|
## Init container Security Context
|
||||||
|
## Note: the chown of the data folder is done to securityContext.runAsUser
|
||||||
|
## and not the below volumePermissions.securityContext.runAsUser
|
||||||
|
## @param volumePermissions.securityContext.seLinuxOptions [object,nullable] Set SELinux options in container
|
||||||
|
## @param volumePermissions.securityContext.runAsUser User ID for the init container
|
||||||
|
##
|
||||||
|
## When runAsUser is set to special value "auto", init container will try to chwon the
|
||||||
|
## data folder to autodetermined user&group, using commands: `id -u`:`id -G | cut -d" " -f2`
|
||||||
|
## "auto" is especially useful for OpenShift which has scc with dynamic userids (and 0 is not allowed).
|
||||||
|
## You may want to use this volumePermissions.securityContext.runAsUser="auto" in combination with
|
||||||
|
## pod securityContext.enabled=false and shmVolume.chmod.enabled=false
|
||||||
|
##
|
||||||
|
securityContext:
|
||||||
|
seLinuxOptions: {}
|
||||||
|
runAsUser: 0
|
||||||
|
## @section Metrics parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## Cassandra Prometheus exporter configuration
|
||||||
|
##
|
||||||
|
metrics:
|
||||||
|
## @param metrics.enabled Start a side-car prometheus exporter
|
||||||
|
##
|
||||||
|
enabled: false
|
||||||
|
## Bitnami Cassandra Exporter image
|
||||||
|
## ref: https://hub.docker.com/r/bitnami/cassandra-exporter/tags/
|
||||||
|
## @param metrics.image.registry [default: REGISTRY_NAME] Cassandra exporter image registry
|
||||||
|
## @param metrics.image.repository [default: REPOSITORY_NAME/cassandra-exporter] Cassandra exporter image name
|
||||||
|
## @skip metrics.image.tag Cassandra exporter image tag
|
||||||
|
## @param metrics.image.digest Cassandra exporter image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag
|
||||||
|
## @param metrics.image.pullPolicy image pull policy
|
||||||
|
## @param metrics.image.pullSecrets Specify docker-registry secret names as an array
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
registry: docker.io
|
||||||
|
repository: bitnami/cassandra-exporter
|
||||||
|
tag: 2.3.8-debian-12-r41
|
||||||
|
digest: ""
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
## Optionally specify an array of imagePullSecrets.
|
||||||
|
## Secrets must be manually created in the namespace.
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||||
|
## e.g:
|
||||||
|
## pullSecrets:
|
||||||
|
## - myRegistryKeySecretName
|
||||||
|
##
|
||||||
|
pullSecrets: []
|
||||||
|
## Cassandra Prometheus exporter resource requests and limits
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
|
||||||
|
## We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
## choice for the user. This also increases chances charts run on environments with little
|
||||||
|
## resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
## lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
## @param metrics.resourcesPreset Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if metrics.resources is set (metrics.resources is recommended for production).
|
||||||
|
## More information: https://github.com/bitnami/charts/blob/main/bitnami/common/templates/_resources.tpl#L15
|
||||||
|
##
|
||||||
|
resourcesPreset: "nano"
|
||||||
|
## @param metrics.resources Set container requests and limits for different resources like CPU or memory (essential for production workloads)
|
||||||
|
## Example:
|
||||||
|
## resources:
|
||||||
|
## requests:
|
||||||
|
## cpu: 2
|
||||||
|
## memory: 512Mi
|
||||||
|
## limits:
|
||||||
|
## cpu: 3
|
||||||
|
## memory: 1024Mi
|
||||||
|
##
|
||||||
|
resources: {}
|
||||||
|
## @param metrics.readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
|
||||||
|
## @param metrics.readinessProbe.periodSeconds Period seconds for readinessProbe
|
||||||
|
## @param metrics.readinessProbe.timeoutSeconds Timeout seconds for readinessProbe
|
||||||
|
## @param metrics.readinessProbe.failureThreshold Failure threshold for readinessProbe
|
||||||
|
## @param metrics.readinessProbe.successThreshold Success threshold for readinessProbe
|
||||||
|
##
|
||||||
|
readinessProbe:
|
||||||
|
initialDelaySeconds: 20
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 45
|
||||||
|
failureThreshold: 3
|
||||||
|
successThreshold: 1
|
||||||
|
## @param metrics.extraVolumeMounts Optionally specify extra list of additional volumeMounts for cassandra-exporter container
|
||||||
|
##
|
||||||
|
extraVolumeMounts: []
|
||||||
|
## @param metrics.podAnnotations [object] Metrics exporter pod Annotation and Labels
|
||||||
|
## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
|
||||||
|
##
|
||||||
|
podAnnotations:
|
||||||
|
prometheus.io/scrape: "true"
|
||||||
|
prometheus.io/port: "8080"
|
||||||
|
## Prometheus Operator ServiceMonitor configuration
|
||||||
|
##
|
||||||
|
serviceMonitor:
|
||||||
|
## @param metrics.serviceMonitor.enabled If `true`, creates a Prometheus Operator ServiceMonitor (also requires `metrics.enabled` to be `true`)
|
||||||
|
##
|
||||||
|
enabled: false
|
||||||
|
## @param metrics.serviceMonitor.namespace Namespace in which Prometheus is running
|
||||||
|
##
|
||||||
|
namespace: monitoring
|
||||||
|
## @param metrics.serviceMonitor.interval Interval at which metrics should be scraped.
|
||||||
|
## ref: https://github.com/coreos/prometheus-operator/blob/main/Documentation/api.md#endpoint
|
||||||
|
## e.g:
|
||||||
|
## interval: 10s
|
||||||
|
##
|
||||||
|
interval: ""
|
||||||
|
## @param metrics.serviceMonitor.scrapeTimeout Timeout after which the scrape is ended
|
||||||
|
## ref: https://github.com/coreos/prometheus-operator/blob/main/Documentation/api.md#endpoint
|
||||||
|
## e.g:
|
||||||
|
## scrapeTimeout: 10s
|
||||||
|
##
|
||||||
|
scrapeTimeout: ""
|
||||||
|
## @param metrics.serviceMonitor.selector Prometheus instance selector labels
|
||||||
|
## ref: https://github.com/bitnami/charts/tree/main/bitnami/prometheus-operator#prometheus-configuration
|
||||||
|
## e.g:
|
||||||
|
## selector:
|
||||||
|
## prometheus: my-prometheus
|
||||||
|
##
|
||||||
|
selector: {}
|
||||||
|
## @param metrics.serviceMonitor.metricRelabelings Specify Metric Relabelings to add to the scrape endpoint
|
||||||
|
## ref: https://github.com/coreos/prometheus-operator/blob/main/Documentation/api.md#relabelconfig
|
||||||
|
##
|
||||||
|
metricRelabelings: []
|
||||||
|
## @param metrics.serviceMonitor.relabelings RelabelConfigs to apply to samples before scraping
|
||||||
|
## ref: https://github.com/coreos/prometheus-operator/blob/main/Documentation/api.md#relabelconfig
|
||||||
|
##
|
||||||
|
relabelings: []
|
||||||
|
## @param metrics.serviceMonitor.honorLabels Specify honorLabels parameter to add the scrape endpoint
|
||||||
|
##
|
||||||
|
honorLabels: false
|
||||||
|
## @param metrics.serviceMonitor.jobLabel The name of the label on the target service to use as the job name in prometheus.
|
||||||
|
##
|
||||||
|
jobLabel: ""
|
||||||
|
## @param metrics.serviceMonitor.labels Used to pass Labels that are required by the installed Prometheus Operator
|
||||||
|
## ref: https://github.com/coreos/prometheus-operator/blob/main/Documentation/api.md#prometheusspec
|
||||||
|
##
|
||||||
|
labels: {}
|
||||||
|
## Metrics container ports to open
|
||||||
|
## If hostNetwork true: the hostPort is set identical to the containerPort
|
||||||
|
## @param metrics.containerPorts.http HTTP Port on the Host and Container
|
||||||
|
## @param metrics.containerPorts.jmx JMX Port on the Host and Container
|
||||||
|
##
|
||||||
|
containerPorts:
|
||||||
|
http: 8080
|
||||||
|
jmx: 5555
|
||||||
|
## Metrics ports to be exposed as hostPort
|
||||||
|
## If hostNetwork is false, only the ports specified here will be exposed (or not if set to an empty string)
|
||||||
|
## @param metrics.hostPorts.http HTTP Port on the Host
|
||||||
|
## @param metrics.hostPorts.jmx JMX Port on the Host
|
||||||
|
##
|
||||||
|
hostPorts:
|
||||||
|
http: ""
|
||||||
|
jmx: ""
|
||||||
|
## @param metrics.configuration [string] Configure Cassandra-exporter with a custom config.yml file
|
||||||
|
## ref: https://github.com/criteo/cassandra_exporter/blob/main/config.yml
|
||||||
|
##
|
||||||
|
configuration: |
|
||||||
|
host: localhost:{{ .Values.containerPorts.jmx }}
|
||||||
|
ssl: False
|
||||||
|
user:
|
||||||
|
password:
|
||||||
|
listenPort: {{ .Values.metrics.containerPorts.http }}
|
||||||
|
blacklist:
|
||||||
|
# To profile the duration of jmx call you can start the program with the following options
|
||||||
|
# > java -Dorg.slf4j.simpleLogger.defaultLogLevel=trace -jar cassandra_exporter.jar config.yml --oneshot
|
||||||
|
#
|
||||||
|
# To get intuition of what is done by cassandra when something is called you can look in cassandra
|
||||||
|
# https://github.com/apache/cassandra/tree/trunk/src/java/org/apache/cassandra/metrics
|
||||||
|
# Please avoid to scrape frequently those calls that are iterating over all sstables
|
||||||
|
|
||||||
|
# Unaccessible metrics (not enough privilege)
|
||||||
|
- java:lang:memorypool:.*usagethreshold.*
|
||||||
|
|
||||||
|
# Leaf attributes not interesting for us but that are presents in many path
|
||||||
|
- .*:999thpercentile
|
||||||
|
- .*:95thpercentile
|
||||||
|
- .*:fifteenminuterate
|
||||||
|
- .*:fiveminuterate
|
||||||
|
- .*:durationunit
|
||||||
|
- .*:rateunit
|
||||||
|
- .*:stddev
|
||||||
|
- .*:meanrate
|
||||||
|
- .*:mean
|
||||||
|
- .*:min
|
||||||
|
|
||||||
|
# Path present in many metrics but uninterresting
|
||||||
|
- .*:viewlockacquiretime:.*
|
||||||
|
- .*:viewreadtime:.*
|
||||||
|
- .*:cas[a-z]+latency:.*
|
||||||
|
- .*:colupdatetimedeltahistogram:.*
|
||||||
|
|
||||||
|
# Mostly for RPC, do not scrap them
|
||||||
|
- org:apache:cassandra:db:.*
|
||||||
|
|
||||||
|
# columnfamily is an alias for Table metrics
|
||||||
|
# https://github.com/apache/cassandra/blob/8b3a60b9a7dbefeecc06bace617279612ec7092d/src/java/org/apache/cassandra/metrics/TableMetrics.java#L162
|
||||||
|
- org:apache:cassandra:metrics:columnfamily:.*
|
||||||
|
|
||||||
|
# Should we export metrics for system keyspaces/tables ?
|
||||||
|
- org:apache:cassandra:metrics:[^:]+:system[^:]*:.*
|
||||||
|
|
||||||
|
# Don't scrap us
|
||||||
|
- com:criteo:nosql:cassandra:exporter:.*
|
||||||
|
|
||||||
|
maxScrapFrequencyInSec:
|
||||||
|
50:
|
||||||
|
- .*
|
||||||
|
|
||||||
|
# Refresh those metrics only every hour as it is costly for cassandra to retrieve them
|
||||||
|
3600:
|
||||||
|
- .*:snapshotssize:.*
|
||||||
|
- .*:estimated.*
|
||||||
|
- .*:totaldiskspaceused:.*
|
||||||
|
## @section TLS/SSL parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## TLS/SSL parameters
|
||||||
|
## @param tls.internodeEncryption Set internode encryption
|
||||||
|
## @param tls.clientEncryption Set client-server encryption
|
||||||
|
## @param tls.autoGenerated Generate automatically self-signed TLS certificates. Currently only supports PEM certificates
|
||||||
|
## @param tls.existingSecret Existing secret that contains Cassandra Keystore and truststore
|
||||||
|
## @param tls.passwordsSecret Secret containing the Keystore and Truststore passwords if needed
|
||||||
|
## @param tls.keystorePassword Password for the keystore, if needed.
|
||||||
|
## @param tls.truststorePassword Password for the truststore, if needed.
|
||||||
|
## @param tls.resourcesPreset Set container resources according to one common preset (allowed values: none, nano, micro, small, medium, large, xlarge, 2xlarge). This is ignored if tls.resources is set (tls.resources is recommended for production).
|
||||||
|
## More information: https://github.com/bitnami/charts/blob/main/bitnami/common/templates/_resources.tpl#L15
|
||||||
|
## @param tls.resources Set container requests and limits for different resources like CPU or memory (essential for production workloads)
|
||||||
|
## @param tls.certificatesSecret Secret with the TLS certificates.
|
||||||
|
## @param tls.tlsEncryptionSecretName Secret with the encryption of the TLS certificates
|
||||||
|
##
|
||||||
|
tls:
|
||||||
|
internodeEncryption: none
|
||||||
|
clientEncryption: false
|
||||||
|
autoGenerated: false
|
||||||
|
existingSecret: ""
|
||||||
|
passwordsSecret: ""
|
||||||
|
keystorePassword: ""
|
||||||
|
truststorePassword: ""
|
||||||
|
certificatesSecret: ""
|
||||||
|
tlsEncryptionSecretName: ""
|
||||||
|
resourcesPreset: "nano"
|
||||||
|
## We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
## choice for the user. This also increases chances charts run on environments with little
|
||||||
|
## resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
## lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
## Example:
|
||||||
|
## resources:
|
||||||
|
## requests:
|
||||||
|
## cpu: 2
|
||||||
|
## memory: 512Mi
|
||||||
|
## limits:
|
||||||
|
## cpu: 3
|
||||||
|
## memory: 1024Mi
|
||||||
|
resources: {}
|
||||||
131
charts/backend/Chart.yaml
Executable file
131
charts/backend/Chart.yaml
Executable file
@ -0,0 +1,131 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: backend
|
||||||
|
description: Umbrella chart for all backend k8s applications
|
||||||
|
type: application
|
||||||
|
version: "0.1.0"
|
||||||
|
appVersion: "1.0.0"
|
||||||
|
|
||||||
|
dependencies:
|
||||||
|
- name: admin-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/admin-app-k8s
|
||||||
|
- name: android-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/android-app-k8s
|
||||||
|
- name: auth-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/auth-app-k8s
|
||||||
|
- name: auth-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/auth-event-handler-app-k8s
|
||||||
|
- name: bff-admin-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/bff-admin-app-k8s
|
||||||
|
- name: bff-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/bff-app-k8s
|
||||||
|
- name: bff-vcs-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/bff-vcs-app-k8s
|
||||||
|
- name: big-chat-splitter-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/big-chat-splitter-app-k8s
|
||||||
|
- name: call-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/call-app-k8s
|
||||||
|
- name: call-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/call-event-handler-app-k8s
|
||||||
|
- name: call-realtime-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/call-realtime-app-k8s
|
||||||
|
- name: chat-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/chat-app-k8s
|
||||||
|
- name: chat-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/chat-event-handler-app-k8s
|
||||||
|
- name: deeplink-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/deeplink-app-k8s
|
||||||
|
- name: gem-call-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/gem-call-app-k8s
|
||||||
|
- name: gem-call-events-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/gem-call-events-handler-app-k8s
|
||||||
|
- name: huawei-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/huawei-app-k8s
|
||||||
|
- name: ios-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/ios-app-k8s
|
||||||
|
- name: livekit-webhook-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/livekit-webhook-handler-app-k8s
|
||||||
|
- name: message-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/message-app-k8s
|
||||||
|
- name: message-call-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/message-call-event-handler-app-k8s
|
||||||
|
- name: message-chat-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/message-chat-event-handler-app-k8s
|
||||||
|
- name: message-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/message-event-handler-app-k8s
|
||||||
|
- name: message-link-preview-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/message-link-preview-handler-app-k8s
|
||||||
|
- name: message-user-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/message-user-event-handler-app-k8s
|
||||||
|
- name: notification-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/notification-app-k8s
|
||||||
|
- name: notification-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/notification-event-handler-app-k8s
|
||||||
|
- name: realtime-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/realtime-app-k8s
|
||||||
|
- name: regular-chat-splitter-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/regular-chat-splitter-app-k8s
|
||||||
|
- name: search-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/search-app-k8s
|
||||||
|
- name: search-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/search-event-handler-app-k8s
|
||||||
|
- name: sticker-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/sticker-app-k8s
|
||||||
|
- name: unregister-tokens-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/unregister-tokens-app-k8s
|
||||||
|
- name: upload-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/upload-app-k8s
|
||||||
|
- name: user-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/user-app-k8s
|
||||||
|
- name: voip-splitter-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/voip-splitter-app-k8s
|
||||||
|
- name: web-sender-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/web-sender-app-k8s
|
||||||
|
- name: workspace-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/workspace-app-k8s
|
||||||
|
- name: workspace-event-handler-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/workspace-event-handler-app-k8s
|
||||||
|
- name: devices-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/devices-app-k8s
|
||||||
|
- name: license-app
|
||||||
|
version: "0.1.0"
|
||||||
|
repository: file://charts/license-app-k8s
|
||||||
23
charts/backend/charts/admin-app-k8s/.helmignore
Executable file
23
charts/backend/charts/admin-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/admin-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/admin-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: admin-app
|
||||||
|
description: Helm chart for Admin app
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/admin-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/admin-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "admin-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "admin-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "admin-app.fullname" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "admin-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
{{- end }}
|
||||||
62
charts/backend/charts/admin-app-k8s/templates/deployment.yaml
Executable file
62
charts/backend/charts/admin-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,62 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "admin-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "admin-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.global.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
||||||
|
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
||||||
|
echo "Certificate with alias gemcert already exists, skipping import"
|
||||||
|
else
|
||||||
|
echo "Importing certificate with alias gemcert"
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
fi
|
||||||
|
containers:
|
||||||
|
- name: admin-app
|
||||||
|
ports:
|
||||||
|
- containerPort: 9090
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
{{- include "global.env.general" . | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
15
charts/backend/charts/admin-app-k8s/templates/service.yaml
Executable file
15
charts/backend/charts/admin-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "admin-app.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
protocol: TCP
|
||||||
10
charts/backend/charts/admin-app-k8s/values.yaml
Executable file
10
charts/backend/charts/admin-app-k8s/values.yaml
Executable file
@ -0,0 +1,10 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
23
charts/backend/charts/admin-ui-app-k8s/.helmignore
Executable file
23
charts/backend/charts/admin-ui-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/admin-ui-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/admin-ui-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: admin-ui-app
|
||||||
|
description: Helm chart for Admin ui app
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/admin-ui-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/admin-ui-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "admin-ui-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "admin-ui-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "admin-ui-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "admin-ui-app.fullname" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "admin-ui-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "admin-ui-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
{{- end }}
|
||||||
22
charts/backend/charts/admin-ui-app-k8s/templates/deployment.yaml
Executable file
22
charts/backend/charts/admin-ui-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,22 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "admin-ui-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "admin-ui-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "admin-ui-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "admin-ui-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: admin-ui-app
|
||||||
|
ports:
|
||||||
|
- containerPort: 9090
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}admin-panel-cowork:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
15
charts/backend/charts/admin-ui-app-k8s/templates/service.yaml
Executable file
15
charts/backend/charts/admin-ui-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "admin-ui-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "admin-ui-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "admin-ui-app.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
protocol: TCP
|
||||||
11
charts/backend/charts/admin-ui-app-k8s/values.yaml
Executable file
11
charts/backend/charts/admin-ui-app-k8s/values.yaml
Executable file
@ -0,0 +1,11 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
tag: preprod
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
service:
|
||||||
|
name: admin-ui-app
|
||||||
|
type: ClusterIP
|
||||||
|
port: 9090
|
||||||
|
targetPort: 80
|
||||||
23
charts/backend/charts/android-app-k8s/.helmignore
Executable file
23
charts/backend/charts/android-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/android-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/android-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: android-app
|
||||||
|
description: Helm chart for Android Sender Application
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/android-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/android-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "android-sender-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "android-sender-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "android-sender-app.fullname" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "android-sender-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
{{- end }}
|
||||||
64
charts/backend/charts/android-app-k8s/templates/deployment.yaml
Executable file
64
charts/backend/charts/android-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,64 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "android-sender-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "android-sender-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "android-sender-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "android-sender-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}android-sender-app:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.global.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
||||||
|
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
||||||
|
echo "Certificate with alias gemcert already exists, skipping import"
|
||||||
|
else
|
||||||
|
echo "Importing certificate with alias gemcert"
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
fi
|
||||||
|
containers:
|
||||||
|
- name: android-sender
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}android-sender-app:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
{{- include "global.env.cassandra" . | nindent 12 }}
|
||||||
|
{{- include "global.env.kafka" . | nindent 12 }}
|
||||||
|
{{- include "global.env.redis" . | nindent 12 }}
|
||||||
|
- name: ANDROID_FIREBASE_CONFIG
|
||||||
|
value: {{ .Values.env.android_firebase_config }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
9
charts/backend/charts/android-app-k8s/values.yaml
Executable file
9
charts/backend/charts/android-app-k8s/values.yaml
Executable file
@ -0,0 +1,9 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
env:
|
||||||
|
android_firebase_config: "cowork-prod-firebase-adminsdk-l136z-648992e82d.json"
|
||||||
|
secrets:
|
||||||
|
firebaseSecret: android-firebase-config
|
||||||
23
charts/backend/charts/auth-app-k8s/.helmignore
Executable file
23
charts/backend/charts/auth-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/auth-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/auth-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: auth-app
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
53
charts/backend/charts/auth-app-k8s/templates/_helpers.tpl
Executable file
53
charts/backend/charts/auth-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,53 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.fullname" -}}
|
||||||
|
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "auth-app-k8s.chart" . }}
|
||||||
|
{{ include "auth-app-k8s.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "auth-app-k8s.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "auth-app-k8s.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
88
charts/backend/charts/auth-app-k8s/templates/deployment.yaml
Executable file
88
charts/backend/charts/auth-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,88 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||||
|
io.kompose.service: auth-app
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "auth-app-k8s.selectorLabels" . | nindent 6 }}
|
||||||
|
io.kompose.service: auth-app
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.selectorLabels" . | nindent 8 }}
|
||||||
|
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: {{ include "auth-app-k8s.fullname" . }}-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.global.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
||||||
|
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
||||||
|
echo "Certificate with alias gemcert already exists, skipping import"
|
||||||
|
else
|
||||||
|
echo "Importing certificate with alias gemcert"
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
fi
|
||||||
|
containers:
|
||||||
|
- name: auth-app
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- containerPort: {{ .Values.service.targetPort }}
|
||||||
|
{{- if .Values.service.hostPort }}
|
||||||
|
hostPort: {{ .Values.service.hostPort }}
|
||||||
|
{{- end }}
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
{{- include "global.env.general" . | nindent 12 }}
|
||||||
|
{{- include "global.env.auth" . | nindent 12 }}
|
||||||
|
- name: ADMIN_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.adminPassword.name }}
|
||||||
|
key: {{ .Values.secrets.adminPassword.key }}
|
||||||
|
- name: CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.clientSecret.name }}
|
||||||
|
key: {{ .Values.secrets.clientSecret.key }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
15
charts/backend/charts/auth-app-k8s/templates/service.yaml
Executable file
15
charts/backend/charts/auth-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
selector:
|
||||||
|
{{- include "auth-app-k8s.selectorLabels" . | nindent 4 }}
|
||||||
|
io.kompose.service: auth-app
|
||||||
15
charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml
Executable file
15
charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "auth-app-k8s.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "auth-app-k8s.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
||||||
40
charts/backend/charts/auth-app-k8s/values.yaml
Executable file
40
charts/backend/charts/auth-app-k8s/values.yaml
Executable file
@ -0,0 +1,40 @@
|
|||||||
|
|
||||||
|
fullnameOverride: "auth-app"
|
||||||
|
|
||||||
|
image:
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
hostPort: null
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
adminPassword:
|
||||||
|
name: auth-secrets
|
||||||
|
key: admin-password
|
||||||
|
clientSecret:
|
||||||
|
name: auth-secrets
|
||||||
|
key: client-secret
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 512Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 256Mi
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/auth-app.yml -o k8s/auth-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: auth-app
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
23
charts/backend/charts/auth-event-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/auth-event-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: auth-event-handler-app
|
||||||
|
description: Authentication Event Handler
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
19
charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl
Executable file
19
charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,19 @@
|
|||||||
|
{{/* Common Name Definitions */}}
|
||||||
|
{{- define "auth-event-handler-app-k8s.fullname" -}}
|
||||||
|
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Standard labels */}}
|
||||||
|
{{- define "auth-event-handler-app-k8s.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "auth-event-handler-app-k8s.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
{{- end }}
|
||||||
122
charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml
Executable file
122
charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,122 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.labels" . | nindent 8 }}
|
||||||
|
{{- with .Values.podLabels }}
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
serviceAccountName: {{ .Values.serviceAccount.name | default (include "auth-event-handler-app-k8s.serviceAccountName" .) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
{{- with .Values.volumes }}
|
||||||
|
{{ toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.global.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
||||||
|
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
||||||
|
echo "Certificate with alias gemcert already exists, skipping import"
|
||||||
|
else
|
||||||
|
echo "Importing certificate with alias gemcert"
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
fi
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
{{- include "global.env.general" . | nindent 12 }}
|
||||||
|
{{- include "global.env.cassandra" . | nindent 12 }}
|
||||||
|
{{- include "global.env.kafka" . | nindent 12 }}
|
||||||
|
{{- include "global.env.redis" . | nindent 12 }}
|
||||||
|
{{- include "global.env.auth" . | nindent 12 }}
|
||||||
|
- name: ADMIN_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.adminPassword.name }}
|
||||||
|
key: {{ .Values.secrets.adminPassword.key }}
|
||||||
|
- name: CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.clientSecret.name }}
|
||||||
|
key: {{ .Values.secrets.clientSecret.key }}
|
||||||
|
livenessProbe:
|
||||||
|
{{- toYaml .Values.livenessProbe | nindent 12 }}
|
||||||
|
readinessProbe:
|
||||||
|
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
{{- with .Values.volumeMounts }}
|
||||||
|
{{- toYaml . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
12
charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml
Executable file
12
charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,12 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
selector:
|
||||||
|
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 4 }}
|
||||||
48
charts/backend/charts/auth-event-handler-app-k8s/values.yaml
Executable file
48
charts/backend/charts/auth-event-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,48 @@
|
|||||||
|
fullnameOverride: "auth-event-handler-app"
|
||||||
|
image:
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 8094
|
||||||
|
targetPort: 9090
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
kafka:
|
||||||
|
name: kafka-password
|
||||||
|
passwordKey: client-passwords
|
||||||
|
username: admin
|
||||||
|
adminPassword:
|
||||||
|
name: auth-secrets
|
||||||
|
key: admin-password
|
||||||
|
clientSecret:
|
||||||
|
name: auth-secrets
|
||||||
|
key: client-secret
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 512Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 256Mi
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/auth-event-handler-app.yml -o k8s/auth-event-handler-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: auth-event-handler-app
|
||||||
|
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
securityContext: {}
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
create: false
|
||||||
|
name: ""
|
||||||
23
charts/backend/charts/bff-admin-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-admin-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/bff-admin-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/bff-admin-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: bff-admin-app
|
||||||
|
description: Helm chart for bff-admin-app
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "bff-admin-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "bff-admin-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "bff-admin-app.fullname" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "bff-admin-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Chart.Name }}
|
||||||
|
{{- end }}
|
||||||
60
charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml
Executable file
60
charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,60 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "bff-admin-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "bff-admin-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.global.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
||||||
|
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
||||||
|
echo "Certificate with alias gemcert already exists, skipping import"
|
||||||
|
else
|
||||||
|
echo "Importing certificate with alias gemcert"
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
fi
|
||||||
|
containers:
|
||||||
|
- name: bff-admin-app
|
||||||
|
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
{{- include "global.env.general" . | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
38
charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml
Executable file
38
charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml
Executable file
@ -0,0 +1,38 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ .Values.ingress.name }}
|
||||||
|
namespace: {{ .Release.Namespace | default "default" }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
ingressClassName: {{ .Values.ingress.className }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
{{- range .paths }}
|
||||||
|
- path: {{ .path }}
|
||||||
|
pathType: {{ .pathType }}
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $.Values.env.app_name }}
|
||||||
|
port:
|
||||||
|
number: {{ $.Values.service.httpPort }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
17
charts/backend/charts/bff-admin-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/bff-admin-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "bff-admin-app.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
{{- range .Values.service.ports }}
|
||||||
|
- name: {{ .name }}
|
||||||
|
port: {{ .port }}
|
||||||
|
targetPort: {{ .targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
37
charts/backend/charts/bff-admin-app-k8s/values.yaml
Executable file
37
charts/backend/charts/bff-admin-app-k8s/values.yaml
Executable file
@ -0,0 +1,37 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
image:
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
env:
|
||||||
|
app_name: bff-admin-app
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
httpPort: 8100
|
||||||
|
grpcPort: 8101
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 8100
|
||||||
|
targetPort: 8080
|
||||||
|
- name: grpc
|
||||||
|
port: 8101
|
||||||
|
targetPort: 9090
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
className: nginx
|
||||||
|
name: bff-admin-ingress
|
||||||
|
annotations:
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
||||||
|
hosts:
|
||||||
|
- host: adm-p003.cw.ngcloud.ru
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- adm-p003.cw.ngcloud.ru
|
||||||
|
secretName: co-work-secret
|
||||||
23
charts/backend/charts/bff-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/bff-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/bff-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: bff-app
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user