Add OpenEBS v4.6.1 with images repointed to ghcr.io/wrktalk-tech - Loki and Alloy disabled
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
apiVersion: v2
|
||||
appVersion: 4.6.0
|
||||
description: Helm chart for OpenEBS Dynamic Local PV. For instructions to install
|
||||
OpenEBS Dynamic Local PV using helm chart, refer to https://openebs.github.io/dynamic-localpv-provisioner/.
|
||||
home: https://openebs.io
|
||||
icon: https://raw.githubusercontent.com/cncf/artwork/master/projects/openebs/icon/color/openebs-icon-color.png
|
||||
keywords:
|
||||
- storage
|
||||
- local
|
||||
- dynamic-localpv
|
||||
name: localpv-provisioner
|
||||
sources:
|
||||
- https://github.com/openebs/dynamic-localpv-provisioner
|
||||
type: application
|
||||
version: 4.6.0
|
||||
@@ -0,0 +1,128 @@
|
||||
# OpenEBS LocalPV Provisioner
|
||||
|
||||
[](https://opensource.org/licenses/Apache-2.0)
|
||||

|
||||

|
||||
|
||||
A Helm chart for openebs dynamic localpv provisioner. This chart bootstraps OpenEBS Dynamic LocalPV provisioner deployment on a [Kubernetes](http://kubernetes.io) cluster using the [Helm](https://helm.sh) package manager.
|
||||
|
||||
|
||||
**Homepage:** <http://www.openebs.io/>
|
||||
|
||||
## Get Repo Info
|
||||
|
||||
```console
|
||||
helm repo add openebs-localpv https://openebs.github.io/dynamic-localpv-provisioner
|
||||
helm repo update
|
||||
```
|
||||
|
||||
_See [helm repo](https://helm.sh/docs/helm/helm_repo/) for command documentation._
|
||||
|
||||
## Install Chart
|
||||
|
||||
Please visit the [link](https://openebs.github.io/dynamic-localpv-provisioner/) for install instructions via helm3.
|
||||
|
||||
```console
|
||||
# Helm
|
||||
helm install [RELEASE_NAME] openebs-localpv/localpv-provisioner --namespace [NAMESPACE] --create-namespace
|
||||
```
|
||||
|
||||
_See [configuration](#configuration) below._
|
||||
|
||||
_See [helm install](https://helm.sh/docs/helm/helm_install/) for command documentation._
|
||||
|
||||
## Uninstall Chart
|
||||
|
||||
```console
|
||||
# Helm
|
||||
helm uninstall [RELEASE_NAME] --namespace [NAMESPACE]
|
||||
```
|
||||
|
||||
This removes all the Kubernetes components associated with the chart and deletes the release.
|
||||
|
||||
_See [helm uninstall](https://helm.sh/docs/helm/helm_uninstall/) for command documentation._
|
||||
|
||||
## Upgrading Chart
|
||||
|
||||
```console
|
||||
# Helm
|
||||
helm upgrade [RELEASE_NAME] [CHART] --install --namespace [NAMESPACE]
|
||||
```
|
||||
|
||||
|
||||
## Configuration
|
||||
|
||||
The following table lists the configurable parameters of the OpenEBS Dynamic LocalPV Provisioner chart and their default values.
|
||||
|
||||
You can modify different parameters by specifying the desired value in the `helm install` command by using the `--set` and/or the `--set-string` flag(s).
|
||||
|
||||
```console
|
||||
helm install openebs-localpv openebs-localpv/localpv-provisioner --namespace openebs --create-namespace
|
||||
```
|
||||
|
||||
Sample command to install the provisioner with nodeAffinityLabels "openebs.io/node-affinity-key-1" and "openebs.io/node-affinity-key-2" on the hostpath StorageClass:
|
||||
```console
|
||||
helm install openebs-localpv openebs-localpv/localpv-provisioner --namespace openebs --create-namespace \
|
||||
--set-string hostpathClass.nodeAffinityLabels="{openebs.io/node-affinity-key-1,openebs.io/node-affinity-key-2}"
|
||||
```
|
||||
|
||||
| Parameter | Description | Default |
|
||||
|--------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------|-------------------------------|
|
||||
| `globalImageRegistryOverride` | When set to true, the value of `global.imageRegistry` will override all image registry settings defined at local level | `"false"` |
|
||||
| `global.imagePullSecrets` | Global image pull secrets (merged with local imagePullSecrets and not overridden) | `[]` |
|
||||
| `global.imagePullPolicy` | Global override for image pull policy | `""` |
|
||||
| `global.analytics.enabled` | Global override for analytics | `null` |
|
||||
| `analytics.enabled` | Enable sending stats to Google Analytics | `true` |
|
||||
| `analytics.pingInterval` | Duration(hours) between sending ping stat | `24h` |
|
||||
| `extraLabels` | Additional labels to add to all chart resources | `{}` |
|
||||
| `global.imageRegistry` | Global override for container image registry (when `globalImageRegistryOverride` is set to true) | `"docker.io"` |
|
||||
| `helperPod.image.registry` | Registry for helper image | `""` |
|
||||
| `helperPod.image.repository` | Image for helper pod | `"openebs/linux-utils"` |
|
||||
| `helperPod.image.pullPolicy` | Pull policy for helper pod | `IfNotPresent` |
|
||||
| `helperPod.image.tag` | Image tag for helper image | `4.5.0` |
|
||||
| `helperPod.timeoutSecs` | The maximum number of seconds to wait for a helperPod (init, cleanup, quota) to complete | `120` |
|
||||
| `hostpathClass.allowedTopologies` | Restrict provisioning/scheduling of openebs-hostpath volumes to nodes matching these topology label selectors | `[]` |
|
||||
| `hostpathClass.basePath` | BasePath for openebs-hostpath StorageClass | `"/var/openebs/local"` |
|
||||
| `hostpathClass.enabled` | Enables creation of default Hostpath StorageClass | `true` |
|
||||
| `hostpathClass.isDefaultClass` | Make openebs-hostpath the default StorageClass | `"false"` |
|
||||
| `hostpathClass.nodeAffinityLabels` | Custom node label(or labels) key to uniquely identify nodes. `kubernetes.io/hostname` is the default label key for node selection. | `[]` |
|
||||
| `hostpathClass.xfsQuota.enabled` | Enable XFS Quota (requires XFS filesystem) | `false` |
|
||||
| `hostpathClass.ext4Quota.enabled` | Enable EXT4 Quota (requires EXT4 filesystem) | `false` |
|
||||
| `hostpathClass.reclaimPolicy` | ReclaimPolicy for Hostpath PVs | `"Delete"` |
|
||||
| `imagePullSecrets` | Provides image pull secret | `""` |
|
||||
| `localpv.controller.workers` | The no. of concurrent worker goroutines for processing PVC create/delete events | `4` |
|
||||
| `localpv.controller.client.qps` | Max queries/sec to the Kubernetes API server. Empty uses the client-go default (5) | `""` |
|
||||
| `localpv.controller.client.burst` | Max burst of queries above `client.qps` to the Kubernetes API server. Empty uses the client-go default (10) | `""` |
|
||||
| `localpv.enabled` | Enable LocalPV Provisioner | `true` |
|
||||
| `localpv.image.registry` | Registry for LocalPV Provisioner image | `""` |
|
||||
| `localpv.image.repository` | Image repository for LocalPV Provisioner | `openebs/provisioner-localpv` |
|
||||
| `localpv.image.pullPolicy` | Image pull policy for LocalPV Provisioner | `IfNotPresent` |
|
||||
| `localpv.image.tag` | Image tag for LocalPV Provisioner | `4.6.0` |
|
||||
| `localpv.updateStrategy.type` | Update strategy for LocalPV Provisioner | `RollingUpdate` |
|
||||
| `localpv.annotations` | Annotations for LocalPV Provisioner metadata | `""` |
|
||||
| `localpv.podAnnotations` | Annotations for LocalPV Provisioner pods metadata | `""` |
|
||||
| `localpv.privileged` | Run LocalPV Provisioner with extra privileges | `true` |
|
||||
| `localpv.resources` | Resource and request and limit for containers | `""` |
|
||||
| `localpv.podLabels` | Appends labels to the pods | `""` |
|
||||
| `localpv.nodeSelector` | Nodeselector for LocalPV Provisioner pods | `""` |
|
||||
| `localpv.nodeDeployment.enabled` | Enabled the NodeDeployment mode of installation | `""` |
|
||||
| `localpv.tolerations` | LocalPV Provisioner pod toleration values | `""` |
|
||||
| `localpv.securityContext` | Security context for container | `""` |
|
||||
| `localpv.healthCheck.liveness.enabled` | Keep/remove the liveness probe kubernetes health check | `true` |
|
||||
| `localpv.healthCheck.readiness.enabled` | Keep/remove the readiness probe kubernetes health check | `true` |
|
||||
| `localpv.healthCheck.port` | Set the port to which the health server binds (all interfaces) | `8081` |
|
||||
| `localpv.replicas` | No. of LocalPV Provisioner replica | `1` |
|
||||
| `localpv.allowInsecurePvcBasePathOverride` | Allow namespace tenants to set the BasePath PVC cas-config value | `false` |
|
||||
| `localpv.enableLeaderElection` | Enable leader election | `true` |
|
||||
| `localpv.affinity` | LocalPV Provisioner pod affinity | `{}` |
|
||||
| `localpv.priorityClassName` | Sets priorityClassName in pod | `""` |
|
||||
| `rbac.create` | Enable RBAC Resources | `true` |
|
||||
| `rbac.pspEnabled` | Create pod security policy resources | `false` |
|
||||
|
||||
A YAML file that specifies the values for the parameters can be provided while installing the chart. For example,
|
||||
|
||||
```bash
|
||||
helm install <release-name> -f values.yaml --namespace openebs openebs-localpv/localpv-provisioner
|
||||
```
|
||||
|
||||
> **Tip**: You can use the default [values.yaml](values.yaml)
|
||||
@@ -0,0 +1,9 @@
|
||||
The OpenEBS Dynamic LocalPV Provisioner has been installed.
|
||||
Check its status by running:
|
||||
$ kubectl get pods -n {{ .Release.Namespace }}
|
||||
|
||||
Get started with the Dynamic LocalPV Provisioner Quickstart guide at:
|
||||
https://github.com/openebs/dynamic-localpv-provisioner/blob/develop/docs/quickstart.md
|
||||
|
||||
For more information, visit our Slack at https://kubernetes.slack.com/messages/openebs or view
|
||||
the OpenEBS documentation online at https://openebs.io/docs
|
||||
@@ -0,0 +1,219 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "localpv.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified localpv provisioner name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
If release name contains chart name it will be used as a full name.
|
||||
*/}}
|
||||
{{- define "localpv.fullname" -}}
|
||||
{{- if .Values.fullnameOverride -}}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||
{{- if contains $name .Release.Name -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "localpv.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
|
||||
{{/*
|
||||
Meta labels
|
||||
*/}}
|
||||
{{- define "localpv.common.metaLabels" -}}
|
||||
chart: {{ template "localpv.chart" . }}
|
||||
heritage: {{ .Release.Service }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
*/}}
|
||||
{{- define "localpv.selectorLabels" -}}
|
||||
app: {{ template "localpv.name" . }}
|
||||
release: {{ .Release.Name }}
|
||||
component: {{ .Values.localpv.name | quote }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Component labels
|
||||
*/}}
|
||||
{{- define "localpv.componentLabels" -}}
|
||||
openebs.io/component-name: openebs-{{ .Values.localpv.name }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "localpv.labels" -}}
|
||||
{{ include "localpv.common.metaLabels" . }}
|
||||
{{ include "localpv.selectorLabels" . }}
|
||||
{{ include "localpv.componentLabels" . }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the service account to use
|
||||
*/}}
|
||||
{{- define "localpv.serviceAccountName" -}}
|
||||
{{- if .Values.serviceAccount.create -}}
|
||||
{{ default (include "localpv.fullname" .) .Values.serviceAccount.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccount.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Name of the ConfigMap used to record analytics install-event state for the
|
||||
current Helm release.
|
||||
|
||||
Usage:
|
||||
{{ include "localpv.analyticsStateCM.name" . }}
|
||||
*/}}
|
||||
{{- define "localpv.analyticsStateCM.name" -}}
|
||||
{{- printf "%s-analytics-state" (include "localpv.fullname" .) | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Name of the Lease used by the provisioner to elect a single analytics
|
||||
emitter in node-deployment mode.
|
||||
|
||||
Usage:
|
||||
{{ include "localpv.analyticsLease.name" . }}
|
||||
*/}}
|
||||
{{- define "localpv.analyticsLease.name" -}}
|
||||
{{- printf "%s-analytics" (include "localpv.fullname" .) | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Creates the tolerations based on the global tolerations, with early eviction
|
||||
Usage:
|
||||
{{ include "tolerations_with_early_eviction" . }}
|
||||
*/}}
|
||||
{{- define "tolerations_with_early_eviction" -}}
|
||||
{{- if .Values.earlyEvictionTolerations }}
|
||||
{{- toYaml .Values.earlyEvictionTolerations | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.tolerations }}
|
||||
{{- toYaml .Values.localpv.tolerations | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Creates the image URL ie registry/repository:tag
|
||||
|
||||
Registry resolution is tolerant of upgrades from chart versions that predate
|
||||
.global.imageRegistry (for example v4.1.4, which had no `global` block and left
|
||||
`registry` unset). Each registry source is normalised to a trimmed string
|
||||
(an unset/null value becomes "") before precedence is applied, so a stripped
|
||||
registry - e.g. under `helm upgrade --reuse-values` - no longer fails with
|
||||
"invalid value; expected string".
|
||||
|
||||
- override (globalImageRegistryOverride=true): .global.imageRegistry takes
|
||||
precedence over the image-local registry, falling back to the local one
|
||||
when the global registry is unset.
|
||||
- default (globalImageRegistryOverride=false): the image-local registry
|
||||
takes precedence, falling back to .global.imageRegistry when the local
|
||||
one is unset (retains v4.4.0 behaviour where the global was the default).
|
||||
|
||||
If neither registry resolves (both unset), the image defaults to the docker.io
|
||||
registry - matching the chart's default .global.imageRegistry - so upgrades that
|
||||
dropped the value still render a fully-qualified reference rather than an
|
||||
unprefixed one.
|
||||
*/}}
|
||||
{{- define "localpv.common.image" -}}
|
||||
{{- $global := .global | default dict -}}
|
||||
{{- $localRegistry := .imageRoot.registry | default "" | toString | trimSuffix "/" -}}
|
||||
{{- $globalRegistry := $global.imageRegistry | default "" | toString | trimSuffix "/" -}}
|
||||
{{- $registryName := "" -}}
|
||||
{{- if .override -}}
|
||||
{{- $registryName = $globalRegistry | default $localRegistry -}}
|
||||
{{- else -}}
|
||||
{{- $registryName = $localRegistry | default $globalRegistry -}}
|
||||
{{- end -}}
|
||||
{{- $registryName = $registryName | default "docker.io" -}}
|
||||
{{- $repositoryName := .imageRoot.repository -}}
|
||||
{{- $termination := .imageRoot.tag | toString -}}
|
||||
{{- printf "%s/%s:%s" $registryName $repositoryName $termination -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Concatenates imagepullsecrets, outputs in ENV format and handles different formats (example - secret or - name: secret)
|
||||
*/}}
|
||||
{{- define "localpv.helper.pullSecrets" -}}
|
||||
{{- $names := list -}}
|
||||
{{- with .Values.global.imagePullSecrets -}}
|
||||
{{- range . -}}
|
||||
{{- if kindIs "map" . }}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{ $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{ $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- with .Values.imagePullSecrets -}}
|
||||
{{- range . }}
|
||||
{{- if kindIs "map" . -}}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{- $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{- $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- if $names }}
|
||||
- name: OPENEBS_IO_IMAGE_PULL_SECRETS
|
||||
value: "{{ join "," ($names | uniq) }}"
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Concatenates imagepullsecrets and handles different formats (example - secret or - name: secret)
|
||||
*/}}
|
||||
{{- define "localpv.common.pullSecrets" -}}
|
||||
{{- $names := list -}}
|
||||
{{- with .Values.global.imagePullSecrets -}}
|
||||
{{- range . -}}
|
||||
{{- if kindIs "map" . }}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{ $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{ $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- with .Values.imagePullSecrets -}}
|
||||
{{- range . }}
|
||||
{{- if kindIs "map" . -}}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{- $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{- $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- $names = uniq $names -}}
|
||||
{{- if $names -}}
|
||||
{{- range $names }}
|
||||
- name: {{ . }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,27 @@
|
||||
{{/*
|
||||
Chart-managed Lease for analytics leader election (node-deployment mode only).
|
||||
|
||||
Elects a single analytics emitter across DaemonSet pods. Helm-managed so
|
||||
`helm uninstall` cleanly removes it; without this, the Lease would persist
|
||||
in the namespace with the previous holder's identity, and the next install
|
||||
would have to wait out LeaseDuration before acquiring leadership.
|
||||
*/}}
|
||||
{{- if .Values.localpv.enabled }}
|
||||
{{- $analyticsEnabled := .Values.analytics.enabled -}}
|
||||
{{- if kindIs "bool" .Values.global.analytics.enabled -}}
|
||||
{{- $analyticsEnabled = .Values.global.analytics.enabled -}}
|
||||
{{- end -}}
|
||||
{{- if and $analyticsEnabled .Values.localpv.nodeDeployment.enabled }}
|
||||
apiVersion: coordination.k8s.io/v1
|
||||
kind: Lease
|
||||
metadata:
|
||||
name: {{ include "localpv.analyticsLease.name" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec: {}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,217 @@
|
||||
{{- if .Values.localpv.enabled }}
|
||||
{{- if .Values.localpv.nodeDeployment.enabled }}
|
||||
{{- $healthPort := default 8081 .Values.localpv.healthCheck.port }}
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-node
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "localpv.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
{{- with .Values.localpv.podAnnotations }}
|
||||
annotations: {{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 8 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.localpv.podLabels }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.loggingLabels}}
|
||||
{{ toYaml . | nindent 8 -}}
|
||||
{{- end}}
|
||||
spec:
|
||||
{{- if .Values.localpv.priorityClassName }}
|
||||
priorityClassName: {{ tpl .Values.localpv.priorityClassName . }}
|
||||
{{- end }}
|
||||
{{- if or .Values.global.imagePullSecrets .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- include "localpv.common.pullSecrets" . | indent 6 }}
|
||||
{{- end }}
|
||||
serviceAccountName: {{ template "localpv.serviceAccountName" . }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||
containers:
|
||||
- name: {{ template "localpv.fullname" . }}
|
||||
image: "{{ include "localpv.common.image" (dict "imageRoot" .Values.localpv.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
imagePullPolicy: {{ default .Values.localpv.image.pullPolicy .Values.global.imagePullPolicy }}
|
||||
{{- if .Values.localpv.privileged }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
resources:
|
||||
{{ toYaml .Values.localpv.resources | indent 10 }}
|
||||
env:
|
||||
# OPENEBS_IO_K8S_MASTER enables openebs provisioner to connect to K8s
|
||||
# based on this address. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_K8S_MASTER
|
||||
# value: "http://10.128.0.12:8080"
|
||||
# OPENEBS_IO_KUBE_CONFIG enables openebs provisioner to connect to K8s
|
||||
# based on this config. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_KUBE_CONFIG
|
||||
# value: "/home/ubuntu/.kube/config"
|
||||
- name: OPENEBS_NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.nodeName
|
||||
# POD_NAME is consumed by the analytics leader-election code in
|
||||
# node-deployment mode so that each DaemonSet pod has a stable,
|
||||
# unique lease identity. Required for correct singleton behavior
|
||||
# of install/ping/heartbeat events.
|
||||
- name: POD_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.name
|
||||
# OPENEBS_SERVICE_ACCOUNT provides the service account of this pod as
|
||||
# environment variable
|
||||
- name: OPENEBS_SERVICE_ACCOUNT
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.serviceAccountName
|
||||
# OPENEBS_IO_BASE_PATH is the environment variable that provides the
|
||||
# default base path on the node where host-path PVs will be provisioned.
|
||||
{{- if kindIs "bool" .Values.global.analytics.enabled }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.global.analytics.enabled }}"
|
||||
{{- else }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.analytics.enabled }}"
|
||||
{{- end }}
|
||||
# OPENEBS_IO_ANALYTICS_STATE_CM names the ConfigMap consulted to
|
||||
# decide whether to emit the install event for this Helm release
|
||||
# and to persist ping/heartbeat timestamps across pod restarts.
|
||||
# The provisioner creates and updates this ConfigMap itself; it
|
||||
# is not managed by Helm.
|
||||
- name: OPENEBS_IO_ANALYTICS_STATE_CM
|
||||
value: {{ include "localpv.analyticsStateCM.name" . | quote }}
|
||||
# OPENEBS_IO_ANALYTICS_LEASE names the Lease used to elect a single
|
||||
# analytics emitter across all DaemonSet pods. Release-scoped so
|
||||
# multiple releases in the same namespace do not collide. The
|
||||
# provisioner creates the Lease on-demand via client-go's
|
||||
# leader-election; it is not managed by Helm.
|
||||
- name: OPENEBS_IO_ANALYTICS_LEASE
|
||||
value: {{ include "localpv.analyticsLease.name" . | quote }}
|
||||
{{- if .Values.global.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.global.analytics.gaId | quote }}
|
||||
{{- else if .Values.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.analytics.gaId | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.global.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.global.analytics.gaKey | quote }}
|
||||
{{- else if .Values.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.analytics.gaKey | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_BASE_PATH
|
||||
value: "{{ .Values.localpv.basePath }}"
|
||||
- name: OPENEBS_IO_WORKER_THREADS
|
||||
value: {{ .Values.localpv.controller.workers | quote }}
|
||||
{{- if .Values.localpv.controller.client.qps }}
|
||||
- name: OPENEBS_IO_CLIENT_QPS
|
||||
value: {{ .Values.localpv.controller.client.qps | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.controller.client.burst }}
|
||||
- name: OPENEBS_IO_CLIENT_BURST
|
||||
value: {{ .Values.localpv.controller.client.burst | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_HELPER_IMAGE
|
||||
value: "{{ include "localpv.common.image" (dict "imageRoot" .Values.helperPod.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
- name: OPENEBS_IO_IMAGE_PULL_POLICY
|
||||
value: "{{ default .Values.helperPod.image.pullPolicy .Values.global.imagePullPolicy }}"
|
||||
- name: OPENEBS_IO_HELPER_POD_HOST_NETWORK
|
||||
value: "{{ .Values.helperPod.hostNetwork }}"
|
||||
- name: OPENEBS_IO_INSTALLER_TYPE
|
||||
value: "localpv-charts-helm-nodedeploy"
|
||||
- name: OPENEBS_IO_HELPER_POD_TIMEOUT_SECS
|
||||
value: {{ .Values.helperPod.timeoutSecs | quote }}
|
||||
# Disable leader election in node deployment mode.
|
||||
# Not related to anonymous usage analytics leader election.
|
||||
- name: LEADER_ELECTION_ENABLED
|
||||
value: "false"
|
||||
# Enable node deployment mode
|
||||
- name: NODE_DEPLOYMENT
|
||||
value: "true"
|
||||
# OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS is the address the health-probe
|
||||
# HTTP server binds to. /healthz serves liveness, /readyz serves readiness.
|
||||
- name: OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS
|
||||
value: ":{{ $healthPort }}"
|
||||
{{- include "localpv.helper.pullSecrets" . | indent 8 }}
|
||||
args:
|
||||
- "--node-deployment=true"
|
||||
{{- if .Values.localpv.allowInsecurePvcBasePathOverride }}
|
||||
- "--allow-insecure-pvc-basepath-override"
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: healthz
|
||||
containerPort: {{ $healthPort }}
|
||||
protocol: TCP
|
||||
{{- if .Values.localpv.healthCheck.liveness.enabled }}
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.liveness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.liveness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.liveness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.liveness.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.healthCheck.readiness.enabled }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.readiness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.readiness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.readiness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.readiness.failureThreshold }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: host-root
|
||||
mountPath: /host
|
||||
mountPropagation: HostToContainer
|
||||
{{- if .Values.localpv.nodeDeployment.additionalVolumeMounts }}
|
||||
{{ toYaml .Values.localpv.nodeDeployment.additionalVolumeMounts | indent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: host-root
|
||||
hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
{{- if .Values.localpv.nodeDeployment.additionalVolumes }}
|
||||
{{ toYaml .Values.localpv.nodeDeployment.additionalVolumes | indent 6 }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{ toYaml .Values.localpv.nodeSelector | indent 8 }}
|
||||
{{- end }}
|
||||
{{- if $tolerations := include "tolerations_with_early_eviction" . }}
|
||||
tolerations: {{ $tolerations }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.affinity }}
|
||||
affinity:
|
||||
{{ toYaml .Values.localpv.affinity | indent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,198 @@
|
||||
{{- if .Values.localpv.enabled }}
|
||||
{{- if not .Values.localpv.nodeDeployment.enabled }}
|
||||
{{- $healthPort := default 8081 .Values.localpv.healthCheck.port }}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
replicas: {{ .Values.localpv.replicas }}
|
||||
strategy:
|
||||
type: "Recreate"
|
||||
rollingUpdate: null
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "localpv.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
{{- with .Values.localpv.podAnnotations }}
|
||||
annotations: {{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 8 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.localpv.podLabels }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.loggingLabels}}
|
||||
{{ toYaml . | nindent 8 -}}
|
||||
{{- end}}
|
||||
spec:
|
||||
{{- if .Values.localpv.priorityClassName }}
|
||||
priorityClassName: {{ tpl .Values.localpv.priorityClassName . }}
|
||||
{{- end }}
|
||||
{{- if or .Values.global.imagePullSecrets .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- include "localpv.common.pullSecrets" . | indent 6 }}
|
||||
{{- end }}
|
||||
serviceAccountName: {{ template "localpv.serviceAccountName" . }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||
containers:
|
||||
- name: {{ template "localpv.fullname" . }}
|
||||
image: "{{ include "localpv.common.image" (dict "imageRoot" .Values.localpv.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
imagePullPolicy: {{ default .Values.localpv.image.pullPolicy .Values.global.imagePullPolicy }}
|
||||
resources:
|
||||
{{ toYaml .Values.localpv.resources | indent 10 }}
|
||||
env:
|
||||
# OPENEBS_IO_K8S_MASTER enables openebs provisioner to connect to K8s
|
||||
# based on this address. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_K8S_MASTER
|
||||
# value: "http://10.128.0.12:8080"
|
||||
# OPENEBS_IO_KUBE_CONFIG enables openebs provisioner to connect to K8s
|
||||
# based on this config. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_KUBE_CONFIG
|
||||
# value: "/home/ubuntu/.kube/config"
|
||||
- name: OPENEBS_NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.nodeName
|
||||
# OPENEBS_SERVICE_ACCOUNT provides the service account of this pod as
|
||||
# environment variable
|
||||
- name: OPENEBS_SERVICE_ACCOUNT
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.serviceAccountName
|
||||
# OPENEBS_IO_BASE_PATH is the environment variable that provides the
|
||||
# default base path on the node where host-path PVs will be provisioned.
|
||||
{{- if kindIs "bool" .Values.global.analytics.enabled }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.global.analytics.enabled }}"
|
||||
{{- else }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.analytics.enabled }}"
|
||||
{{- end }}
|
||||
# OPENEBS_IO_ANALYTICS_STATE_CM names the ConfigMap consulted to
|
||||
# decide whether to emit the install event for this Helm release
|
||||
# and to persist ping/heartbeat timestamps across pod restarts.
|
||||
# The provisioner creates and updates this ConfigMap itself; it
|
||||
# is not managed by Helm. helm uninstall does not remove it, so
|
||||
# reinstalls into the same namespace will not re-fire the install
|
||||
# event unless the ConfigMap is deleted manually.
|
||||
- name: OPENEBS_IO_ANALYTICS_STATE_CM
|
||||
value: {{ include "localpv.analyticsStateCM.name" . | quote }}
|
||||
{{- if .Values.global.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.global.analytics.gaId | quote }}
|
||||
{{- else if .Values.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.analytics.gaId | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.global.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.global.analytics.gaKey | quote }}
|
||||
{{- else if .Values.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.analytics.gaKey | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_BASE_PATH
|
||||
value: "{{ .Values.localpv.basePath }}"
|
||||
- name: OPENEBS_IO_WORKER_THREADS
|
||||
value: {{ .Values.localpv.controller.workers | quote }}
|
||||
{{- if .Values.localpv.controller.client.qps }}
|
||||
- name: OPENEBS_IO_CLIENT_QPS
|
||||
value: {{ .Values.localpv.controller.client.qps | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.controller.client.burst }}
|
||||
- name: OPENEBS_IO_CLIENT_BURST
|
||||
value: {{ .Values.localpv.controller.client.burst | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_IMAGE_PULL_POLICY
|
||||
value: "{{ default .Values.helperPod.image.pullPolicy .Values.global.imagePullPolicy }}"
|
||||
- name: OPENEBS_IO_HELPER_IMAGE
|
||||
value: "{{ include "localpv.common.image" (dict "imageRoot" .Values.helperPod.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
- name: OPENEBS_IO_HELPER_POD_HOST_NETWORK
|
||||
value: "{{ .Values.helperPod.hostNetwork }}"
|
||||
- name: OPENEBS_IO_INSTALLER_TYPE
|
||||
value: "localpv-charts-helm-helperpod"
|
||||
- name: OPENEBS_IO_HELPER_POD_TIMEOUT_SECS
|
||||
value: {{ .Values.helperPod.timeoutSecs | quote }}
|
||||
# LEADER_ELECTION_ENABLED is used to enable/disable leader election. By default
|
||||
# leader election is enabled.
|
||||
- name: LEADER_ELECTION_ENABLED
|
||||
value: "{{ .Values.localpv.enableLeaderElection }}"
|
||||
# OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS is the address the health-probe
|
||||
# HTTP server binds to. /healthz serves liveness, /readyz serves readiness.
|
||||
- name: OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS
|
||||
value: ":{{ $healthPort }}"
|
||||
{{- include "localpv.helper.pullSecrets" . | indent 8 }}
|
||||
{{/* Add args below */}}
|
||||
{{/* All args are optional (so far, at least), so the 'args' PodTemplate key
|
||||
* is only included if there is at least one arg. And that's why we're doing
|
||||
* it this way.
|
||||
*/}}
|
||||
{{- $args := list }}
|
||||
{{- if .Values.localpv.allowInsecurePvcBasePathOverride }}
|
||||
{{- $args = append $args "--allow-insecure-pvc-basepath-override" }}
|
||||
{{- end }}
|
||||
|
||||
{{- if $args }}
|
||||
args:
|
||||
{{- range $args }}
|
||||
- {{ . | quote }} {{/* Add new args to the above $args list */}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: healthz
|
||||
containerPort: {{ $healthPort }}
|
||||
protocol: TCP
|
||||
{{- if .Values.localpv.healthCheck.liveness.enabled }}
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.liveness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.liveness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.liveness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.liveness.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.healthCheck.readiness.enabled }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.readiness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.readiness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.readiness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.readiness.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{ toYaml .Values.localpv.nodeSelector | indent 8 }}
|
||||
{{- end }}
|
||||
{{- if $tolerations := include "tolerations_with_early_eviction" . }}
|
||||
tolerations: {{ $tolerations }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.affinity }}
|
||||
affinity:
|
||||
{{ toYaml .Values.localpv.affinity | indent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,47 @@
|
||||
{{- if .Values.hostpathClass.enabled }}
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
name: {{ tpl (.Values.hostpathClass.name) .}}
|
||||
annotations:
|
||||
openebs.io/cas-type: local
|
||||
cas.openebs.io/config: |
|
||||
- name: StorageType
|
||||
value: "hostpath"
|
||||
{{- if or .Values.localpv.basePath .Values.hostpathClass.basePath }}
|
||||
- name: BasePath
|
||||
value: {{ tpl (.Values.hostpathClass.basePath | default .Values.localpv.basePath | quote) . }}
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.nodeAffinityLabels }}
|
||||
- name: NodeAffinityLabels
|
||||
list:
|
||||
{{ toYaml .Values.hostpathClass.nodeAffinityLabels | indent 10 }}
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.xfsQuota.enabled }}
|
||||
- name: XFSQuota
|
||||
enabled: "{{ .Values.hostpathClass.xfsQuota.enabled }}"
|
||||
data:
|
||||
softLimitGrace: "{{ .Values.hostpathClass.xfsQuota.softLimitGrace }}"
|
||||
hardLimitGrace: "{{ .Values.hostpathClass.xfsQuota.hardLimitGrace }}"
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.ext4Quota.enabled }}
|
||||
- name: EXT4Quota
|
||||
enabled: "{{ .Values.hostpathClass.ext4Quota.enabled }}"
|
||||
data:
|
||||
softLimitGrace: "{{ .Values.hostpathClass.ext4Quota.softLimitGrace }}"
|
||||
hardLimitGrace: "{{ .Values.hostpathClass.ext4Quota.hardLimitGrace }}"
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.isDefaultClass }}
|
||||
storageclass.kubernetes.io/is-default-class: "true"
|
||||
{{- end }}
|
||||
{{- if .Values.extraLabels }}
|
||||
labels: {{- toYaml .Values.extraLabels | nindent 4 -}}
|
||||
{{- end }}
|
||||
provisioner: openebs.io/local
|
||||
volumeBindingMode: WaitForFirstConsumer
|
||||
reclaimPolicy: {{ .Values.hostpathClass.reclaimPolicy }}
|
||||
{{- if .Values.hostpathClass.allowedTopologies }}
|
||||
allowedTopologies:
|
||||
{{ toYaml .Values.hostpathClass.allowedTopologies }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,33 @@
|
||||
{{- if .Values.rbac.pspEnabled }}
|
||||
apiVersion: policy/v1beta1
|
||||
kind: PodSecurityPolicy
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
privileged: {{ .Values.localpv.privileged }}
|
||||
allowPrivilegeEscalation: true
|
||||
allowedCapabilities: ['*']
|
||||
volumes: ['*']
|
||||
hostNetwork: true
|
||||
hostPorts:
|
||||
- min: 0
|
||||
max: 65535
|
||||
hostIPC: true
|
||||
hostPID: true
|
||||
runAsUser:
|
||||
rule: 'RunAsAny'
|
||||
seLinux:
|
||||
rule: 'RunAsAny'
|
||||
supplementalGroups:
|
||||
rule: 'RunAsAny'
|
||||
fsGroup:
|
||||
rule: 'RunAsAny'
|
||||
{{- end }}
|
||||
@@ -0,0 +1,124 @@
|
||||
{{- if .Values.serviceAccount.create -}}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ include "localpv.serviceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with .Values.serviceAccount.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.rbac.create }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
- apiGroups: ["*"]
|
||||
resources: ["nodes"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["*"]
|
||||
resources: ["namespaces", "pods", "events", "endpoints"]
|
||||
verbs: ["*"]
|
||||
- apiGroups: ["*"]
|
||||
resources: ["resourcequotas", "limitranges"]
|
||||
verbs: ["list", "watch"]
|
||||
- apiGroups: ["*"]
|
||||
resources: ["storageclasses", "persistentvolumeclaims", "persistentvolumes"]
|
||||
verbs: ["*"]
|
||||
- apiGroups: ["apiextensions.k8s.io"]
|
||||
resources: ["customresourcedefinitions"]
|
||||
verbs: [ "get", "list", "create", "update", "delete", "patch"]
|
||||
- apiGroups: ["openebs.io"]
|
||||
resources: [ "*"]
|
||||
verbs: ["*" ]
|
||||
- apiGroups: ["coordination.k8s.io"]
|
||||
resources: ["leases"]
|
||||
verbs: ["get", "create", "update"]
|
||||
# Analytics state ConfigMap: the provisioner creates and updates this
|
||||
# ConfigMap itself to persist install/ping/heartbeat timestamps.
|
||||
- apiGroups: [""]
|
||||
resources: ["configmaps"]
|
||||
verbs: ["get", "create", "update", "patch"]
|
||||
- nonResourceURLs: ["/metrics"]
|
||||
verbs: ["get"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "localpv.serviceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- if .Values.rbac.pspEnabled }}
|
||||
---
|
||||
kind: ClusterRole
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
- apiGroups: ['policy']
|
||||
resources: ['podsecuritypolicies']
|
||||
verbs: ['use']
|
||||
resourceNames:
|
||||
- {{ template "localpv.fullname" . }}-psp
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "localpv.serviceAccountName" . }}
|
||||
namespace: {{ $.Release.Namespace }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -0,0 +1,233 @@
|
||||
# Default values for localpv.
|
||||
# This is a YAML-formatted file.
|
||||
# Declare variables to be passed into your templates.
|
||||
|
||||
# NOTE: This option is required so that .global.imageRegistry works as an override
|
||||
# for the local image registry values. By default, this option is set to false
|
||||
# and that's to retain backwards compatibility with v4.4.0 where .global.imageRegistry
|
||||
# was introduced as the default and the local options were overrides for the global default.
|
||||
# The other .global options do not work this way, and they are all overrides for their
|
||||
# respective options. If you're not upgrading from v4.4.0, you'll want to enable
|
||||
# this option (set to 'true').
|
||||
globalImageRegistryOverride: false
|
||||
|
||||
global:
|
||||
# Global override for container image registry (when `globalImageRegistryOverride` is set to true)
|
||||
imageRegistry: "docker.io"
|
||||
# Global image pull secrets (merged with local imagePullSecrets and not overridden)
|
||||
# - secret
|
||||
imagePullSecrets: []
|
||||
# Global override for image pull policy
|
||||
imagePullPolicy: ""
|
||||
analytics:
|
||||
# Global override for analytics
|
||||
enabled:
|
||||
|
||||
rbac:
|
||||
# rbac.create: `true` if rbac resources should be created
|
||||
create: true
|
||||
# rbac.pspEnabled: `true` if PodSecurityPolicy resources should be created
|
||||
pspEnabled: false
|
||||
|
||||
earlyEvictionTolerations:
|
||||
- effect: NoExecute
|
||||
key: node.kubernetes.io/unreachable
|
||||
operator: Exists
|
||||
tolerationSeconds: 5
|
||||
- effect: NoExecute
|
||||
key: node.kubernetes.io/not-ready
|
||||
operator: Exists
|
||||
tolerationSeconds: 5
|
||||
|
||||
localpv:
|
||||
name: localpv-provisioner
|
||||
enabled: true
|
||||
controller:
|
||||
# The number of concurrent worker goroutines for processing PVC create and delete events.
|
||||
# Higher values increase provisioning throughput when many PVC events are received simultaneously.
|
||||
workers: 4
|
||||
# Client-side rate limits for requests to the Kubernetes API server.
|
||||
client:
|
||||
# Maximum queries per second (QPS) the provisioner sends to the Kubernetes API server.
|
||||
# Leave empty to use the client-go default (5). Raise it alongside `workers` to avoid
|
||||
# client-side throttling when provisioning many volumes concurrently.
|
||||
qps: ""
|
||||
# Maximum burst of queries above `client.qps` the provisioner allows to the Kubernetes
|
||||
# API server. Leave empty to use the client-go default (10). Setting `client.qps`
|
||||
# without `client.burst` leaves burst at the client-go default of 10, which may
|
||||
# throttle bursts well below the configured QPS; prefer setting both together.
|
||||
burst: ""
|
||||
image:
|
||||
registry: "docker.io/"
|
||||
repository: openebs/provisioner-localpv
|
||||
tag: 4.6.0
|
||||
pullPolicy: IfNotPresent
|
||||
updateStrategy:
|
||||
type: RollingUpdate
|
||||
# If set to false, containers created by the localpv provisioner will run without extra privileges.
|
||||
privileged: true
|
||||
annotations: {}
|
||||
podAnnotations: {}
|
||||
## Labels to be added to localpv provisioner deployment pods
|
||||
podLabels:
|
||||
name: openebs-localpv-provisioner
|
||||
healthCheck:
|
||||
# Container port the provisioner serves its HTTP health endpoints on:
|
||||
# /healthz (liveness) and /readyz (readiness).
|
||||
port: 8081
|
||||
liveness:
|
||||
# Enable the liveness probe (httpGet /healthz).
|
||||
enabled: true
|
||||
# No. of failures the liveness probe will tolerate.
|
||||
failureThreshold: 3
|
||||
# No. of seconds of delay before checking the liveness status.
|
||||
initialDelaySeconds: 1
|
||||
# No. of seconds between liveness probe checks.
|
||||
periodSeconds: 30
|
||||
# No. of seconds of timeout tolerance.
|
||||
timeoutSeconds: 5
|
||||
readiness:
|
||||
# Enable the readiness probe (httpGet /readyz).
|
||||
enabled: true
|
||||
# No. of failures the readiness probe will tolerate.
|
||||
failureThreshold: 3
|
||||
# No. of seconds of delay before checking the readiness status.
|
||||
initialDelaySeconds: 1
|
||||
# No. of seconds between readiness probe checks.
|
||||
periodSeconds: 20
|
||||
# No. of seconds of timeout tolerance.
|
||||
timeoutSeconds: 5
|
||||
replicas: 1
|
||||
enableLeaderElection: true
|
||||
basePath: "/var/openebs/local"
|
||||
# Node deployment configuration for distributed provisioning mode
|
||||
nodeDeployment:
|
||||
# Enable the NodeDeployment mode. This deploys the provisioner as a DaemonSet on
|
||||
# cluster nodes. NodeDeployment avoids the need to spin up a HelperPod at volume
|
||||
# creation/deletion time, and instead performs volume operations via the DaemonSet
|
||||
# container.
|
||||
# NOTE: This mode mounts the host '/' path on to container, as it does not use a
|
||||
# HelperPod and must be able to cater to different BasePath paths.
|
||||
enabled: false
|
||||
# Additional volume mounts for the provisioner container
|
||||
additionalVolumeMounts: []
|
||||
# Additional volumes for the provisioner pod
|
||||
additionalVolumes: []
|
||||
# Enabling (setting to 'true') this option enables namespaced PVC tenants to be able
|
||||
# to set the BasePath cas-config value of their hostpath volume via PVC annotations.
|
||||
# It's reasonable to want to not allow the namespace tenant to decide this for
|
||||
# themselves, and to only allow setting BasePath via the StorageClass/default env
|
||||
# (at a cluster admin level). The default value 'false' does not allow namespace tenants
|
||||
# to set BasePath via PVC cas-config annotations.
|
||||
allowInsecurePvcBasePathOverride: false
|
||||
resources:
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
# choice for the user. This also increases chances charts run on environments with little
|
||||
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||
# limits:
|
||||
# cpu: 100m
|
||||
# memory: 128Mi
|
||||
# requests:
|
||||
# cpu: 100m
|
||||
# memory: 128Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
affinity: {}
|
||||
securityContext: {}
|
||||
## Sets priorityClassName in pod
|
||||
priorityClassName: ""
|
||||
|
||||
imagePullSecrets:
|
||||
# - name: img-pull-secret
|
||||
podSecurityContext: {}
|
||||
# fsGroup: 2000
|
||||
|
||||
nameOverride: ""
|
||||
fullnameOverride: ""
|
||||
|
||||
serviceAccount:
|
||||
# Specifies whether a service account should be created
|
||||
create: true
|
||||
# Annotations to add to the service account
|
||||
annotations: {}
|
||||
# The name of the service account to use.
|
||||
# If not set and create is true, a name is generated using the fullname template
|
||||
name:
|
||||
|
||||
hostpathClass:
|
||||
# Name of the default hostpath StorageClass
|
||||
name: openebs-hostpath
|
||||
# If true, enables creation of the openebs-hostpath StorageClass
|
||||
enabled: true
|
||||
# Available reclaim policies: Delete/Retain, defaults: Delete.
|
||||
reclaimPolicy: Delete
|
||||
# If true, sets the openebs-hostpath StorageClass as the default StorageClass
|
||||
isDefaultClass: false
|
||||
# Path on the host where local volumes of this storage class are mounted under.
|
||||
# NOTE: If not specified, this defaults to the value of localpv.basePath.
|
||||
basePath: ""
|
||||
# Custom node affinity label(s) for example "openebs.io/node-affinity-value"
|
||||
# that will be used instead of hostnames
|
||||
# This helps in cases where the hostname changes when the node is removed and
|
||||
# added back with the disks still intact.
|
||||
# Example:
|
||||
# nodeAffinityLabels:
|
||||
# - "openebs.io/node-affinity-key-1"
|
||||
# - "openebs.io/node-affinity-key-2"
|
||||
nodeAffinityLabels: []
|
||||
# Custom allowedTopologies for the openebs-hostpath StorageClass. Restricts the
|
||||
# set of nodes where volumes of this StorageClass may be provisioned/scheduled,
|
||||
# by matching node labels. See:
|
||||
# https://kubernetes.io/docs/concepts/storage/storage-classes/#allowed-topologies
|
||||
# Example:
|
||||
# allowedTopologies:
|
||||
# - matchLabelExpressions:
|
||||
# - key: kubernetes.io/hostname
|
||||
# values:
|
||||
# - worker-2
|
||||
# - worker-3
|
||||
allowedTopologies: []
|
||||
# Prerequisite: XFS Quota requires an XFS filesystem mounted with
|
||||
# the 'pquota' or 'prjquota' mount option.
|
||||
xfsQuota:
|
||||
# If true, enables XFS project quota
|
||||
enabled: false
|
||||
# Detailed configuration options for XFS project quota.
|
||||
# If XFS Quota is enabled with the default values, the usage limit
|
||||
# is set at the storage capacity specified in the PVC.
|
||||
softLimitGrace: "0%"
|
||||
hardLimitGrace: "0%"
|
||||
# Prerequisite: EXT4 Quota requires an EXT4 filesystem mounted with
|
||||
# the 'prjquota' mount option.
|
||||
ext4Quota:
|
||||
# If true, enables EXT4 project quota
|
||||
enabled: false
|
||||
# Detailed configuration options for EXT4 project quota.
|
||||
# If EXT4 Quota is enabled with the default values, the usage limit
|
||||
# is set at the storage capacity specified in the PVC.
|
||||
softLimitGrace: "0%"
|
||||
hardLimitGrace: "0%"
|
||||
|
||||
helperPod:
|
||||
image:
|
||||
registry: ""
|
||||
repository: openebs/linux-utils
|
||||
pullPolicy: IfNotPresent
|
||||
# Overrides the image tag whose default is the chart appVersion.
|
||||
tag: 4.6.0
|
||||
hostNetwork: false
|
||||
# The maximum number of seconds to wait for a helperPod (init, cleanup, quota) to complete before timing out.
|
||||
timeoutSecs: 120
|
||||
|
||||
# Additional labels to add to all chart resources
|
||||
extraLabels: {}
|
||||
|
||||
loggingLabels:
|
||||
openebs.io/logging: "true"
|
||||
|
||||
analytics:
|
||||
# Enable sending stats to Google Analytics
|
||||
enabled: true
|
||||
# Specify in hours the duration after which a ping event needs to be sent.
|
||||
pingInterval: "24h"
|
||||
Reference in New Issue
Block a user