Add OpenEBS v4.6.1 with images repointed to ghcr.io/wrktalk-tech - Loki and Alloy disabled

This commit is contained in:
2026-10-01 13:22:53 +05:30
commit a14a568465
912 changed files with 135387 additions and 0 deletions
@@ -0,0 +1,9 @@
The OpenEBS Dynamic LocalPV Provisioner has been installed.
Check its status by running:
$ kubectl get pods -n {{ .Release.Namespace }}
Get started with the Dynamic LocalPV Provisioner Quickstart guide at:
https://github.com/openebs/dynamic-localpv-provisioner/blob/develop/docs/quickstart.md
For more information, visit our Slack at https://kubernetes.slack.com/messages/openebs or view
the OpenEBS documentation online at https://openebs.io/docs
@@ -0,0 +1,219 @@
{{/* vim: set filetype=mustache: */}}
{{/*
Expand the name of the chart.
*/}}
{{- define "localpv.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Create a default fully qualified localpv provisioner name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "localpv.fullname" -}}
{{- if .Values.fullnameOverride -}}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default .Chart.Name .Values.nameOverride -}}
{{- if contains $name .Release.Name -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "localpv.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Meta labels
*/}}
{{- define "localpv.common.metaLabels" -}}
chart: {{ template "localpv.chart" . }}
heritage: {{ .Release.Service }}
{{- end -}}
{{/*
Selector labels
*/}}
{{- define "localpv.selectorLabels" -}}
app: {{ template "localpv.name" . }}
release: {{ .Release.Name }}
component: {{ .Values.localpv.name | quote }}
{{- end -}}
{{/*
Component labels
*/}}
{{- define "localpv.componentLabels" -}}
openebs.io/component-name: openebs-{{ .Values.localpv.name }}
{{- end -}}
{{/*
Common labels
*/}}
{{- define "localpv.labels" -}}
{{ include "localpv.common.metaLabels" . }}
{{ include "localpv.selectorLabels" . }}
{{ include "localpv.componentLabels" . }}
{{- end -}}
{{/*
Create the name of the service account to use
*/}}
{{- define "localpv.serviceAccountName" -}}
{{- if .Values.serviceAccount.create -}}
{{ default (include "localpv.fullname" .) .Values.serviceAccount.name }}
{{- else -}}
{{ default "default" .Values.serviceAccount.name }}
{{- end -}}
{{- end -}}
{{/*
Name of the ConfigMap used to record analytics install-event state for the
current Helm release.
Usage:
{{ include "localpv.analyticsStateCM.name" . }}
*/}}
{{- define "localpv.analyticsStateCM.name" -}}
{{- printf "%s-analytics-state" (include "localpv.fullname" .) | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Name of the Lease used by the provisioner to elect a single analytics
emitter in node-deployment mode.
Usage:
{{ include "localpv.analyticsLease.name" . }}
*/}}
{{- define "localpv.analyticsLease.name" -}}
{{- printf "%s-analytics" (include "localpv.fullname" .) | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Creates the tolerations based on the global tolerations, with early eviction
Usage:
{{ include "tolerations_with_early_eviction" . }}
*/}}
{{- define "tolerations_with_early_eviction" -}}
{{- if .Values.earlyEvictionTolerations }}
{{- toYaml .Values.earlyEvictionTolerations | nindent 8 }}
{{- end }}
{{- if .Values.localpv.tolerations }}
{{- toYaml .Values.localpv.tolerations | nindent 8 }}
{{- end }}
{{- end }}
{{/*
Creates the image URL ie registry/repository:tag
Registry resolution is tolerant of upgrades from chart versions that predate
.global.imageRegistry (for example v4.1.4, which had no `global` block and left
`registry` unset). Each registry source is normalised to a trimmed string
(an unset/null value becomes "") before precedence is applied, so a stripped
registry - e.g. under `helm upgrade --reuse-values` - no longer fails with
"invalid value; expected string".
- override (globalImageRegistryOverride=true): .global.imageRegistry takes
precedence over the image-local registry, falling back to the local one
when the global registry is unset.
- default (globalImageRegistryOverride=false): the image-local registry
takes precedence, falling back to .global.imageRegistry when the local
one is unset (retains v4.4.0 behaviour where the global was the default).
If neither registry resolves (both unset), the image defaults to the docker.io
registry - matching the chart's default .global.imageRegistry - so upgrades that
dropped the value still render a fully-qualified reference rather than an
unprefixed one.
*/}}
{{- define "localpv.common.image" -}}
{{- $global := .global | default dict -}}
{{- $localRegistry := .imageRoot.registry | default "" | toString | trimSuffix "/" -}}
{{- $globalRegistry := $global.imageRegistry | default "" | toString | trimSuffix "/" -}}
{{- $registryName := "" -}}
{{- if .override -}}
{{- $registryName = $globalRegistry | default $localRegistry -}}
{{- else -}}
{{- $registryName = $localRegistry | default $globalRegistry -}}
{{- end -}}
{{- $registryName = $registryName | default "docker.io" -}}
{{- $repositoryName := .imageRoot.repository -}}
{{- $termination := .imageRoot.tag | toString -}}
{{- printf "%s/%s:%s" $registryName $repositoryName $termination -}}
{{- end -}}
{{/*
Concatenates imagepullsecrets, outputs in ENV format and handles different formats (example - secret or - name: secret)
*/}}
{{- define "localpv.helper.pullSecrets" -}}
{{- $names := list -}}
{{- with .Values.global.imagePullSecrets -}}
{{- range . -}}
{{- if kindIs "map" . }}
{{- if and (hasKey . "name") (not (empty .name)) -}}
{{ $names = append $names .name }}
{{- end -}}
{{- else if not (empty .) -}}
{{ $names = append $names . -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- with .Values.imagePullSecrets -}}
{{- range . }}
{{- if kindIs "map" . -}}
{{- if and (hasKey . "name") (not (empty .name)) -}}
{{- $names = append $names .name }}
{{- end -}}
{{- else if not (empty .) -}}
{{- $names = append $names . -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- if $names }}
- name: OPENEBS_IO_IMAGE_PULL_SECRETS
value: "{{ join "," ($names | uniq) }}"
{{- end -}}
{{- end -}}
{{/*
Concatenates imagepullsecrets and handles different formats (example - secret or - name: secret)
*/}}
{{- define "localpv.common.pullSecrets" -}}
{{- $names := list -}}
{{- with .Values.global.imagePullSecrets -}}
{{- range . -}}
{{- if kindIs "map" . }}
{{- if and (hasKey . "name") (not (empty .name)) -}}
{{ $names = append $names .name }}
{{- end -}}
{{- else if not (empty .) -}}
{{ $names = append $names . -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- with .Values.imagePullSecrets -}}
{{- range . }}
{{- if kindIs "map" . -}}
{{- if and (hasKey . "name") (not (empty .name)) -}}
{{- $names = append $names .name }}
{{- end -}}
{{- else if not (empty .) -}}
{{- $names = append $names . -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- $names = uniq $names -}}
{{- if $names -}}
{{- range $names }}
- name: {{ . }}
{{- end -}}
{{- end -}}
{{- end -}}
@@ -0,0 +1,27 @@
{{/*
Chart-managed Lease for analytics leader election (node-deployment mode only).
Elects a single analytics emitter across DaemonSet pods. Helm-managed so
`helm uninstall` cleanly removes it; without this, the Lease would persist
in the namespace with the previous holder's identity, and the next install
would have to wait out LeaseDuration before acquiring leadership.
*/}}
{{- if .Values.localpv.enabled }}
{{- $analyticsEnabled := .Values.analytics.enabled -}}
{{- if kindIs "bool" .Values.global.analytics.enabled -}}
{{- $analyticsEnabled = .Values.global.analytics.enabled -}}
{{- end -}}
{{- if and $analyticsEnabled .Values.localpv.nodeDeployment.enabled }}
apiVersion: coordination.k8s.io/v1
kind: Lease
metadata:
name: {{ include "localpv.analyticsLease.name" . }}
namespace: {{ .Release.Namespace }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
spec: {}
{{- end }}
{{- end }}
@@ -0,0 +1,217 @@
{{- if .Values.localpv.enabled }}
{{- if .Values.localpv.nodeDeployment.enabled }}
{{- $healthPort := default 8081 .Values.localpv.healthCheck.port }}
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: {{ template "localpv.fullname" . }}-node
{{- with .Values.localpv.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
spec:
selector:
matchLabels:
{{- include "localpv.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.localpv.podAnnotations }}
annotations: {{ toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 8 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 8 }}
{{- end }}
{{- with .Values.localpv.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.loggingLabels}}
{{ toYaml . | nindent 8 -}}
{{- end}}
spec:
{{- if .Values.localpv.priorityClassName }}
priorityClassName: {{ tpl .Values.localpv.priorityClassName . }}
{{- end }}
{{- if or .Values.global.imagePullSecrets .Values.imagePullSecrets }}
imagePullSecrets:
{{- include "localpv.common.pullSecrets" . | indent 6 }}
{{- end }}
serviceAccountName: {{ template "localpv.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
containers:
- name: {{ template "localpv.fullname" . }}
image: "{{ include "localpv.common.image" (dict "imageRoot" .Values.localpv.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
imagePullPolicy: {{ default .Values.localpv.image.pullPolicy .Values.global.imagePullPolicy }}
{{- if .Values.localpv.privileged }}
securityContext:
privileged: true
{{- end }}
resources:
{{ toYaml .Values.localpv.resources | indent 10 }}
env:
# OPENEBS_IO_K8S_MASTER enables openebs provisioner to connect to K8s
# based on this address. This is ignored if empty.
# This is supported for openebs provisioner version 0.5.2 onwards
#- name: OPENEBS_IO_K8S_MASTER
# value: "http://10.128.0.12:8080"
# OPENEBS_IO_KUBE_CONFIG enables openebs provisioner to connect to K8s
# based on this config. This is ignored if empty.
# This is supported for openebs provisioner version 0.5.2 onwards
#- name: OPENEBS_IO_KUBE_CONFIG
# value: "/home/ubuntu/.kube/config"
- name: OPENEBS_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: NODE_NAME
valueFrom:
fieldRef:
fieldPath: spec.nodeName
# POD_NAME is consumed by the analytics leader-election code in
# node-deployment mode so that each DaemonSet pod has a stable,
# unique lease identity. Required for correct singleton behavior
# of install/ping/heartbeat events.
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
# OPENEBS_SERVICE_ACCOUNT provides the service account of this pod as
# environment variable
- name: OPENEBS_SERVICE_ACCOUNT
valueFrom:
fieldRef:
fieldPath: spec.serviceAccountName
# OPENEBS_IO_BASE_PATH is the environment variable that provides the
# default base path on the node where host-path PVs will be provisioned.
{{- if kindIs "bool" .Values.global.analytics.enabled }}
- name: OPENEBS_IO_ENABLE_ANALYTICS
value: "{{ .Values.global.analytics.enabled }}"
{{- else }}
- name: OPENEBS_IO_ENABLE_ANALYTICS
value: "{{ .Values.analytics.enabled }}"
{{- end }}
# OPENEBS_IO_ANALYTICS_STATE_CM names the ConfigMap consulted to
# decide whether to emit the install event for this Helm release
# and to persist ping/heartbeat timestamps across pod restarts.
# The provisioner creates and updates this ConfigMap itself; it
# is not managed by Helm.
- name: OPENEBS_IO_ANALYTICS_STATE_CM
value: {{ include "localpv.analyticsStateCM.name" . | quote }}
# OPENEBS_IO_ANALYTICS_LEASE names the Lease used to elect a single
# analytics emitter across all DaemonSet pods. Release-scoped so
# multiple releases in the same namespace do not collide. The
# provisioner creates the Lease on-demand via client-go's
# leader-election; it is not managed by Helm.
- name: OPENEBS_IO_ANALYTICS_LEASE
value: {{ include "localpv.analyticsLease.name" . | quote }}
{{- if .Values.global.analytics.gaId }}
- name: GA_ID
value: {{ .Values.global.analytics.gaId | quote }}
{{- else if .Values.analytics.gaId }}
- name: GA_ID
value: {{ .Values.analytics.gaId | quote }}
{{- end }}
{{- if .Values.global.analytics.gaKey }}
- name: GA_KEY
value: {{ .Values.global.analytics.gaKey | quote }}
{{- else if .Values.analytics.gaKey }}
- name: GA_KEY
value: {{ .Values.analytics.gaKey | quote }}
{{- end }}
- name: OPENEBS_IO_BASE_PATH
value: "{{ .Values.localpv.basePath }}"
- name: OPENEBS_IO_WORKER_THREADS
value: {{ .Values.localpv.controller.workers | quote }}
{{- if .Values.localpv.controller.client.qps }}
- name: OPENEBS_IO_CLIENT_QPS
value: {{ .Values.localpv.controller.client.qps | quote }}
{{- end }}
{{- if .Values.localpv.controller.client.burst }}
- name: OPENEBS_IO_CLIENT_BURST
value: {{ .Values.localpv.controller.client.burst | quote }}
{{- end }}
- name: OPENEBS_IO_HELPER_IMAGE
value: "{{ include "localpv.common.image" (dict "imageRoot" .Values.helperPod.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
- name: OPENEBS_IO_IMAGE_PULL_POLICY
value: "{{ default .Values.helperPod.image.pullPolicy .Values.global.imagePullPolicy }}"
- name: OPENEBS_IO_HELPER_POD_HOST_NETWORK
value: "{{ .Values.helperPod.hostNetwork }}"
- name: OPENEBS_IO_INSTALLER_TYPE
value: "localpv-charts-helm-nodedeploy"
- name: OPENEBS_IO_HELPER_POD_TIMEOUT_SECS
value: {{ .Values.helperPod.timeoutSecs | quote }}
# Disable leader election in node deployment mode.
# Not related to anonymous usage analytics leader election.
- name: LEADER_ELECTION_ENABLED
value: "false"
# Enable node deployment mode
- name: NODE_DEPLOYMENT
value: "true"
# OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS is the address the health-probe
# HTTP server binds to. /healthz serves liveness, /readyz serves readiness.
- name: OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS
value: ":{{ $healthPort }}"
{{- include "localpv.helper.pullSecrets" . | indent 8 }}
args:
- "--node-deployment=true"
{{- if .Values.localpv.allowInsecurePvcBasePathOverride }}
- "--allow-insecure-pvc-basepath-override"
{{- end }}
ports:
- name: healthz
containerPort: {{ $healthPort }}
protocol: TCP
{{- if .Values.localpv.healthCheck.liveness.enabled }}
livenessProbe:
httpGet:
path: /healthz
port: healthz
initialDelaySeconds: {{ .Values.localpv.healthCheck.liveness.initialDelaySeconds }}
periodSeconds: {{ .Values.localpv.healthCheck.liveness.periodSeconds }}
timeoutSeconds: {{ .Values.localpv.healthCheck.liveness.timeoutSeconds }}
failureThreshold: {{ .Values.localpv.healthCheck.liveness.failureThreshold }}
{{- end }}
{{- if .Values.localpv.healthCheck.readiness.enabled }}
readinessProbe:
httpGet:
path: /readyz
port: healthz
initialDelaySeconds: {{ .Values.localpv.healthCheck.readiness.initialDelaySeconds }}
periodSeconds: {{ .Values.localpv.healthCheck.readiness.periodSeconds }}
timeoutSeconds: {{ .Values.localpv.healthCheck.readiness.timeoutSeconds }}
failureThreshold: {{ .Values.localpv.healthCheck.readiness.failureThreshold }}
{{- end }}
volumeMounts:
- name: host-root
mountPath: /host
mountPropagation: HostToContainer
{{- if .Values.localpv.nodeDeployment.additionalVolumeMounts }}
{{ toYaml .Values.localpv.nodeDeployment.additionalVolumeMounts | indent 8 }}
{{- end }}
volumes:
- name: host-root
hostPath:
path: /
type: Directory
{{- if .Values.localpv.nodeDeployment.additionalVolumes }}
{{ toYaml .Values.localpv.nodeDeployment.additionalVolumes | indent 6 }}
{{- end }}
{{- if .Values.localpv.nodeSelector }}
nodeSelector:
{{ toYaml .Values.localpv.nodeSelector | indent 8 }}
{{- end }}
{{- if $tolerations := include "tolerations_with_early_eviction" . }}
tolerations: {{ $tolerations }}
{{- end }}
{{- if .Values.localpv.affinity }}
affinity:
{{ toYaml .Values.localpv.affinity | indent 8 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,198 @@
{{- if .Values.localpv.enabled }}
{{- if not .Values.localpv.nodeDeployment.enabled }}
{{- $healthPort := default 8081 .Values.localpv.healthCheck.port }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ template "localpv.fullname" . }}
namespace: {{ .Release.Namespace }}
{{- with .Values.localpv.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
spec:
replicas: {{ .Values.localpv.replicas }}
strategy:
type: "Recreate"
rollingUpdate: null
selector:
matchLabels:
{{- include "localpv.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.localpv.podAnnotations }}
annotations: {{ toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 8 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 8 }}
{{- end }}
{{- with .Values.localpv.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.loggingLabels}}
{{ toYaml . | nindent 8 -}}
{{- end}}
spec:
{{- if .Values.localpv.priorityClassName }}
priorityClassName: {{ tpl .Values.localpv.priorityClassName . }}
{{- end }}
{{- if or .Values.global.imagePullSecrets .Values.imagePullSecrets }}
imagePullSecrets:
{{- include "localpv.common.pullSecrets" . | indent 6 }}
{{- end }}
serviceAccountName: {{ template "localpv.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
containers:
- name: {{ template "localpv.fullname" . }}
image: "{{ include "localpv.common.image" (dict "imageRoot" .Values.localpv.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
imagePullPolicy: {{ default .Values.localpv.image.pullPolicy .Values.global.imagePullPolicy }}
resources:
{{ toYaml .Values.localpv.resources | indent 10 }}
env:
# OPENEBS_IO_K8S_MASTER enables openebs provisioner to connect to K8s
# based on this address. This is ignored if empty.
# This is supported for openebs provisioner version 0.5.2 onwards
#- name: OPENEBS_IO_K8S_MASTER
# value: "http://10.128.0.12:8080"
# OPENEBS_IO_KUBE_CONFIG enables openebs provisioner to connect to K8s
# based on this config. This is ignored if empty.
# This is supported for openebs provisioner version 0.5.2 onwards
#- name: OPENEBS_IO_KUBE_CONFIG
# value: "/home/ubuntu/.kube/config"
- name: OPENEBS_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: NODE_NAME
valueFrom:
fieldRef:
fieldPath: spec.nodeName
# OPENEBS_SERVICE_ACCOUNT provides the service account of this pod as
# environment variable
- name: OPENEBS_SERVICE_ACCOUNT
valueFrom:
fieldRef:
fieldPath: spec.serviceAccountName
# OPENEBS_IO_BASE_PATH is the environment variable that provides the
# default base path on the node where host-path PVs will be provisioned.
{{- if kindIs "bool" .Values.global.analytics.enabled }}
- name: OPENEBS_IO_ENABLE_ANALYTICS
value: "{{ .Values.global.analytics.enabled }}"
{{- else }}
- name: OPENEBS_IO_ENABLE_ANALYTICS
value: "{{ .Values.analytics.enabled }}"
{{- end }}
# OPENEBS_IO_ANALYTICS_STATE_CM names the ConfigMap consulted to
# decide whether to emit the install event for this Helm release
# and to persist ping/heartbeat timestamps across pod restarts.
# The provisioner creates and updates this ConfigMap itself; it
# is not managed by Helm. helm uninstall does not remove it, so
# reinstalls into the same namespace will not re-fire the install
# event unless the ConfigMap is deleted manually.
- name: OPENEBS_IO_ANALYTICS_STATE_CM
value: {{ include "localpv.analyticsStateCM.name" . | quote }}
{{- if .Values.global.analytics.gaId }}
- name: GA_ID
value: {{ .Values.global.analytics.gaId | quote }}
{{- else if .Values.analytics.gaId }}
- name: GA_ID
value: {{ .Values.analytics.gaId | quote }}
{{- end }}
{{- if .Values.global.analytics.gaKey }}
- name: GA_KEY
value: {{ .Values.global.analytics.gaKey | quote }}
{{- else if .Values.analytics.gaKey }}
- name: GA_KEY
value: {{ .Values.analytics.gaKey | quote }}
{{- end }}
- name: OPENEBS_IO_BASE_PATH
value: "{{ .Values.localpv.basePath }}"
- name: OPENEBS_IO_WORKER_THREADS
value: {{ .Values.localpv.controller.workers | quote }}
{{- if .Values.localpv.controller.client.qps }}
- name: OPENEBS_IO_CLIENT_QPS
value: {{ .Values.localpv.controller.client.qps | quote }}
{{- end }}
{{- if .Values.localpv.controller.client.burst }}
- name: OPENEBS_IO_CLIENT_BURST
value: {{ .Values.localpv.controller.client.burst | quote }}
{{- end }}
- name: OPENEBS_IO_IMAGE_PULL_POLICY
value: "{{ default .Values.helperPod.image.pullPolicy .Values.global.imagePullPolicy }}"
- name: OPENEBS_IO_HELPER_IMAGE
value: "{{ include "localpv.common.image" (dict "imageRoot" .Values.helperPod.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
- name: OPENEBS_IO_HELPER_POD_HOST_NETWORK
value: "{{ .Values.helperPod.hostNetwork }}"
- name: OPENEBS_IO_INSTALLER_TYPE
value: "localpv-charts-helm-helperpod"
- name: OPENEBS_IO_HELPER_POD_TIMEOUT_SECS
value: {{ .Values.helperPod.timeoutSecs | quote }}
# LEADER_ELECTION_ENABLED is used to enable/disable leader election. By default
# leader election is enabled.
- name: LEADER_ELECTION_ENABLED
value: "{{ .Values.localpv.enableLeaderElection }}"
# OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS is the address the health-probe
# HTTP server binds to. /healthz serves liveness, /readyz serves readiness.
- name: OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS
value: ":{{ $healthPort }}"
{{- include "localpv.helper.pullSecrets" . | indent 8 }}
{{/* Add args below */}}
{{/* All args are optional (so far, at least), so the 'args' PodTemplate key
* is only included if there is at least one arg. And that's why we're doing
* it this way.
*/}}
{{- $args := list }}
{{- if .Values.localpv.allowInsecurePvcBasePathOverride }}
{{- $args = append $args "--allow-insecure-pvc-basepath-override" }}
{{- end }}
{{- if $args }}
args:
{{- range $args }}
- {{ . | quote }} {{/* Add new args to the above $args list */}}
{{- end }}
{{- end }}
ports:
- name: healthz
containerPort: {{ $healthPort }}
protocol: TCP
{{- if .Values.localpv.healthCheck.liveness.enabled }}
livenessProbe:
httpGet:
path: /healthz
port: healthz
initialDelaySeconds: {{ .Values.localpv.healthCheck.liveness.initialDelaySeconds }}
periodSeconds: {{ .Values.localpv.healthCheck.liveness.periodSeconds }}
timeoutSeconds: {{ .Values.localpv.healthCheck.liveness.timeoutSeconds }}
failureThreshold: {{ .Values.localpv.healthCheck.liveness.failureThreshold }}
{{- end }}
{{- if .Values.localpv.healthCheck.readiness.enabled }}
readinessProbe:
httpGet:
path: /readyz
port: healthz
initialDelaySeconds: {{ .Values.localpv.healthCheck.readiness.initialDelaySeconds }}
periodSeconds: {{ .Values.localpv.healthCheck.readiness.periodSeconds }}
timeoutSeconds: {{ .Values.localpv.healthCheck.readiness.timeoutSeconds }}
failureThreshold: {{ .Values.localpv.healthCheck.readiness.failureThreshold }}
{{- end }}
{{- if .Values.localpv.nodeSelector }}
nodeSelector:
{{ toYaml .Values.localpv.nodeSelector | indent 8 }}
{{- end }}
{{- if $tolerations := include "tolerations_with_early_eviction" . }}
tolerations: {{ $tolerations }}
{{- end }}
{{- if .Values.localpv.affinity }}
affinity:
{{ toYaml .Values.localpv.affinity | indent 8 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,47 @@
{{- if .Values.hostpathClass.enabled }}
apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
name: {{ tpl (.Values.hostpathClass.name) .}}
annotations:
openebs.io/cas-type: local
cas.openebs.io/config: |
- name: StorageType
value: "hostpath"
{{- if or .Values.localpv.basePath .Values.hostpathClass.basePath }}
- name: BasePath
value: {{ tpl (.Values.hostpathClass.basePath | default .Values.localpv.basePath | quote) . }}
{{- end }}
{{- if .Values.hostpathClass.nodeAffinityLabels }}
- name: NodeAffinityLabels
list:
{{ toYaml .Values.hostpathClass.nodeAffinityLabels | indent 10 }}
{{- end }}
{{- if .Values.hostpathClass.xfsQuota.enabled }}
- name: XFSQuota
enabled: "{{ .Values.hostpathClass.xfsQuota.enabled }}"
data:
softLimitGrace: "{{ .Values.hostpathClass.xfsQuota.softLimitGrace }}"
hardLimitGrace: "{{ .Values.hostpathClass.xfsQuota.hardLimitGrace }}"
{{- end }}
{{- if .Values.hostpathClass.ext4Quota.enabled }}
- name: EXT4Quota
enabled: "{{ .Values.hostpathClass.ext4Quota.enabled }}"
data:
softLimitGrace: "{{ .Values.hostpathClass.ext4Quota.softLimitGrace }}"
hardLimitGrace: "{{ .Values.hostpathClass.ext4Quota.hardLimitGrace }}"
{{- end }}
{{- if .Values.hostpathClass.isDefaultClass }}
storageclass.kubernetes.io/is-default-class: "true"
{{- end }}
{{- if .Values.extraLabels }}
labels: {{- toYaml .Values.extraLabels | nindent 4 -}}
{{- end }}
provisioner: openebs.io/local
volumeBindingMode: WaitForFirstConsumer
reclaimPolicy: {{ .Values.hostpathClass.reclaimPolicy }}
{{- if .Values.hostpathClass.allowedTopologies }}
allowedTopologies:
{{ toYaml .Values.hostpathClass.allowedTopologies }}
{{- end }}
{{- end }}
@@ -0,0 +1,33 @@
{{- if .Values.rbac.pspEnabled }}
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: {{ template "localpv.fullname" . }}-psp
{{- with .Values.localpv.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
spec:
privileged: {{ .Values.localpv.privileged }}
allowPrivilegeEscalation: true
allowedCapabilities: ['*']
volumes: ['*']
hostNetwork: true
hostPorts:
- min: 0
max: 65535
hostIPC: true
hostPID: true
runAsUser:
rule: 'RunAsAny'
seLinux:
rule: 'RunAsAny'
supplementalGroups:
rule: 'RunAsAny'
fsGroup:
rule: 'RunAsAny'
{{- end }}
@@ -0,0 +1,124 @@
{{- if .Values.serviceAccount.create -}}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "localpv.serviceAccountName" . }}
namespace: {{ .Release.Namespace }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}
{{- if .Values.rbac.create }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ template "localpv.fullname" . }}
{{- with .Values.localpv.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
rules:
- apiGroups: ["*"]
resources: ["nodes"]
verbs: ["get", "list", "watch"]
- apiGroups: ["*"]
resources: ["namespaces", "pods", "events", "endpoints"]
verbs: ["*"]
- apiGroups: ["*"]
resources: ["resourcequotas", "limitranges"]
verbs: ["list", "watch"]
- apiGroups: ["*"]
resources: ["storageclasses", "persistentvolumeclaims", "persistentvolumes"]
verbs: ["*"]
- apiGroups: ["apiextensions.k8s.io"]
resources: ["customresourcedefinitions"]
verbs: [ "get", "list", "create", "update", "delete", "patch"]
- apiGroups: ["openebs.io"]
resources: [ "*"]
verbs: ["*" ]
- apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs: ["get", "create", "update"]
# Analytics state ConfigMap: the provisioner creates and updates this
# ConfigMap itself to persist install/ping/heartbeat timestamps.
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "create", "update", "patch"]
- nonResourceURLs: ["/metrics"]
verbs: ["get"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "localpv.fullname" . }}
{{- with .Values.localpv.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "localpv.fullname" . }}
subjects:
- kind: ServiceAccount
name: {{ template "localpv.serviceAccountName" . }}
namespace: {{ .Release.Namespace }}
{{- if .Values.rbac.pspEnabled }}
---
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: {{ template "localpv.fullname" . }}-psp
{{- with .Values.localpv.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
rules:
- apiGroups: ['policy']
resources: ['podsecuritypolicies']
verbs: ['use']
resourceNames:
- {{ template "localpv.fullname" . }}-psp
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ template "localpv.fullname" . }}-psp
{{- with .Values.localpv.annotations }}
annotations: {{ toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "localpv.labels" . | nindent 4 }}
{{- if .Values.extraLabels -}}
{{- toYaml .Values.extraLabels | nindent 4 }}
{{- end }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ template "localpv.fullname" . }}-psp
subjects:
- kind: ServiceAccount
name: {{ template "localpv.serviceAccountName" . }}
namespace: {{ $.Release.Namespace }}
{{- end }}
{{- end }}