Add OpenEBS v4.6.1 with images repointed to ghcr.io/wrktalk-tech - Loki and Alloy disabled
This commit is contained in:
@@ -0,0 +1,9 @@
|
||||
The OpenEBS Dynamic LocalPV Provisioner has been installed.
|
||||
Check its status by running:
|
||||
$ kubectl get pods -n {{ .Release.Namespace }}
|
||||
|
||||
Get started with the Dynamic LocalPV Provisioner Quickstart guide at:
|
||||
https://github.com/openebs/dynamic-localpv-provisioner/blob/develop/docs/quickstart.md
|
||||
|
||||
For more information, visit our Slack at https://kubernetes.slack.com/messages/openebs or view
|
||||
the OpenEBS documentation online at https://openebs.io/docs
|
||||
@@ -0,0 +1,219 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "localpv.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified localpv provisioner name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
If release name contains chart name it will be used as a full name.
|
||||
*/}}
|
||||
{{- define "localpv.fullname" -}}
|
||||
{{- if .Values.fullnameOverride -}}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||
{{- if contains $name .Release.Name -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "localpv.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
|
||||
{{/*
|
||||
Meta labels
|
||||
*/}}
|
||||
{{- define "localpv.common.metaLabels" -}}
|
||||
chart: {{ template "localpv.chart" . }}
|
||||
heritage: {{ .Release.Service }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
*/}}
|
||||
{{- define "localpv.selectorLabels" -}}
|
||||
app: {{ template "localpv.name" . }}
|
||||
release: {{ .Release.Name }}
|
||||
component: {{ .Values.localpv.name | quote }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Component labels
|
||||
*/}}
|
||||
{{- define "localpv.componentLabels" -}}
|
||||
openebs.io/component-name: openebs-{{ .Values.localpv.name }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "localpv.labels" -}}
|
||||
{{ include "localpv.common.metaLabels" . }}
|
||||
{{ include "localpv.selectorLabels" . }}
|
||||
{{ include "localpv.componentLabels" . }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create the name of the service account to use
|
||||
*/}}
|
||||
{{- define "localpv.serviceAccountName" -}}
|
||||
{{- if .Values.serviceAccount.create -}}
|
||||
{{ default (include "localpv.fullname" .) .Values.serviceAccount.name }}
|
||||
{{- else -}}
|
||||
{{ default "default" .Values.serviceAccount.name }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Name of the ConfigMap used to record analytics install-event state for the
|
||||
current Helm release.
|
||||
|
||||
Usage:
|
||||
{{ include "localpv.analyticsStateCM.name" . }}
|
||||
*/}}
|
||||
{{- define "localpv.analyticsStateCM.name" -}}
|
||||
{{- printf "%s-analytics-state" (include "localpv.fullname" .) | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Name of the Lease used by the provisioner to elect a single analytics
|
||||
emitter in node-deployment mode.
|
||||
|
||||
Usage:
|
||||
{{ include "localpv.analyticsLease.name" . }}
|
||||
*/}}
|
||||
{{- define "localpv.analyticsLease.name" -}}
|
||||
{{- printf "%s-analytics" (include "localpv.fullname" .) | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Creates the tolerations based on the global tolerations, with early eviction
|
||||
Usage:
|
||||
{{ include "tolerations_with_early_eviction" . }}
|
||||
*/}}
|
||||
{{- define "tolerations_with_early_eviction" -}}
|
||||
{{- if .Values.earlyEvictionTolerations }}
|
||||
{{- toYaml .Values.earlyEvictionTolerations | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.tolerations }}
|
||||
{{- toYaml .Values.localpv.tolerations | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Creates the image URL ie registry/repository:tag
|
||||
|
||||
Registry resolution is tolerant of upgrades from chart versions that predate
|
||||
.global.imageRegistry (for example v4.1.4, which had no `global` block and left
|
||||
`registry` unset). Each registry source is normalised to a trimmed string
|
||||
(an unset/null value becomes "") before precedence is applied, so a stripped
|
||||
registry - e.g. under `helm upgrade --reuse-values` - no longer fails with
|
||||
"invalid value; expected string".
|
||||
|
||||
- override (globalImageRegistryOverride=true): .global.imageRegistry takes
|
||||
precedence over the image-local registry, falling back to the local one
|
||||
when the global registry is unset.
|
||||
- default (globalImageRegistryOverride=false): the image-local registry
|
||||
takes precedence, falling back to .global.imageRegistry when the local
|
||||
one is unset (retains v4.4.0 behaviour where the global was the default).
|
||||
|
||||
If neither registry resolves (both unset), the image defaults to the docker.io
|
||||
registry - matching the chart's default .global.imageRegistry - so upgrades that
|
||||
dropped the value still render a fully-qualified reference rather than an
|
||||
unprefixed one.
|
||||
*/}}
|
||||
{{- define "localpv.common.image" -}}
|
||||
{{- $global := .global | default dict -}}
|
||||
{{- $localRegistry := .imageRoot.registry | default "" | toString | trimSuffix "/" -}}
|
||||
{{- $globalRegistry := $global.imageRegistry | default "" | toString | trimSuffix "/" -}}
|
||||
{{- $registryName := "" -}}
|
||||
{{- if .override -}}
|
||||
{{- $registryName = $globalRegistry | default $localRegistry -}}
|
||||
{{- else -}}
|
||||
{{- $registryName = $localRegistry | default $globalRegistry -}}
|
||||
{{- end -}}
|
||||
{{- $registryName = $registryName | default "docker.io" -}}
|
||||
{{- $repositoryName := .imageRoot.repository -}}
|
||||
{{- $termination := .imageRoot.tag | toString -}}
|
||||
{{- printf "%s/%s:%s" $registryName $repositoryName $termination -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Concatenates imagepullsecrets, outputs in ENV format and handles different formats (example - secret or - name: secret)
|
||||
*/}}
|
||||
{{- define "localpv.helper.pullSecrets" -}}
|
||||
{{- $names := list -}}
|
||||
{{- with .Values.global.imagePullSecrets -}}
|
||||
{{- range . -}}
|
||||
{{- if kindIs "map" . }}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{ $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{ $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- with .Values.imagePullSecrets -}}
|
||||
{{- range . }}
|
||||
{{- if kindIs "map" . -}}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{- $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{- $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- if $names }}
|
||||
- name: OPENEBS_IO_IMAGE_PULL_SECRETS
|
||||
value: "{{ join "," ($names | uniq) }}"
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Concatenates imagepullsecrets and handles different formats (example - secret or - name: secret)
|
||||
*/}}
|
||||
{{- define "localpv.common.pullSecrets" -}}
|
||||
{{- $names := list -}}
|
||||
{{- with .Values.global.imagePullSecrets -}}
|
||||
{{- range . -}}
|
||||
{{- if kindIs "map" . }}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{ $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{ $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- with .Values.imagePullSecrets -}}
|
||||
{{- range . }}
|
||||
{{- if kindIs "map" . -}}
|
||||
{{- if and (hasKey . "name") (not (empty .name)) -}}
|
||||
{{- $names = append $names .name }}
|
||||
{{- end -}}
|
||||
{{- else if not (empty .) -}}
|
||||
{{- $names = append $names . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- $names = uniq $names -}}
|
||||
{{- if $names -}}
|
||||
{{- range $names }}
|
||||
- name: {{ . }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,27 @@
|
||||
{{/*
|
||||
Chart-managed Lease for analytics leader election (node-deployment mode only).
|
||||
|
||||
Elects a single analytics emitter across DaemonSet pods. Helm-managed so
|
||||
`helm uninstall` cleanly removes it; without this, the Lease would persist
|
||||
in the namespace with the previous holder's identity, and the next install
|
||||
would have to wait out LeaseDuration before acquiring leadership.
|
||||
*/}}
|
||||
{{- if .Values.localpv.enabled }}
|
||||
{{- $analyticsEnabled := .Values.analytics.enabled -}}
|
||||
{{- if kindIs "bool" .Values.global.analytics.enabled -}}
|
||||
{{- $analyticsEnabled = .Values.global.analytics.enabled -}}
|
||||
{{- end -}}
|
||||
{{- if and $analyticsEnabled .Values.localpv.nodeDeployment.enabled }}
|
||||
apiVersion: coordination.k8s.io/v1
|
||||
kind: Lease
|
||||
metadata:
|
||||
name: {{ include "localpv.analyticsLease.name" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec: {}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,217 @@
|
||||
{{- if .Values.localpv.enabled }}
|
||||
{{- if .Values.localpv.nodeDeployment.enabled }}
|
||||
{{- $healthPort := default 8081 .Values.localpv.healthCheck.port }}
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-node
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "localpv.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
{{- with .Values.localpv.podAnnotations }}
|
||||
annotations: {{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 8 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.localpv.podLabels }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.loggingLabels}}
|
||||
{{ toYaml . | nindent 8 -}}
|
||||
{{- end}}
|
||||
spec:
|
||||
{{- if .Values.localpv.priorityClassName }}
|
||||
priorityClassName: {{ tpl .Values.localpv.priorityClassName . }}
|
||||
{{- end }}
|
||||
{{- if or .Values.global.imagePullSecrets .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- include "localpv.common.pullSecrets" . | indent 6 }}
|
||||
{{- end }}
|
||||
serviceAccountName: {{ template "localpv.serviceAccountName" . }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||
containers:
|
||||
- name: {{ template "localpv.fullname" . }}
|
||||
image: "{{ include "localpv.common.image" (dict "imageRoot" .Values.localpv.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
imagePullPolicy: {{ default .Values.localpv.image.pullPolicy .Values.global.imagePullPolicy }}
|
||||
{{- if .Values.localpv.privileged }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
resources:
|
||||
{{ toYaml .Values.localpv.resources | indent 10 }}
|
||||
env:
|
||||
# OPENEBS_IO_K8S_MASTER enables openebs provisioner to connect to K8s
|
||||
# based on this address. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_K8S_MASTER
|
||||
# value: "http://10.128.0.12:8080"
|
||||
# OPENEBS_IO_KUBE_CONFIG enables openebs provisioner to connect to K8s
|
||||
# based on this config. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_KUBE_CONFIG
|
||||
# value: "/home/ubuntu/.kube/config"
|
||||
- name: OPENEBS_NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.nodeName
|
||||
# POD_NAME is consumed by the analytics leader-election code in
|
||||
# node-deployment mode so that each DaemonSet pod has a stable,
|
||||
# unique lease identity. Required for correct singleton behavior
|
||||
# of install/ping/heartbeat events.
|
||||
- name: POD_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.name
|
||||
# OPENEBS_SERVICE_ACCOUNT provides the service account of this pod as
|
||||
# environment variable
|
||||
- name: OPENEBS_SERVICE_ACCOUNT
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.serviceAccountName
|
||||
# OPENEBS_IO_BASE_PATH is the environment variable that provides the
|
||||
# default base path on the node where host-path PVs will be provisioned.
|
||||
{{- if kindIs "bool" .Values.global.analytics.enabled }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.global.analytics.enabled }}"
|
||||
{{- else }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.analytics.enabled }}"
|
||||
{{- end }}
|
||||
# OPENEBS_IO_ANALYTICS_STATE_CM names the ConfigMap consulted to
|
||||
# decide whether to emit the install event for this Helm release
|
||||
# and to persist ping/heartbeat timestamps across pod restarts.
|
||||
# The provisioner creates and updates this ConfigMap itself; it
|
||||
# is not managed by Helm.
|
||||
- name: OPENEBS_IO_ANALYTICS_STATE_CM
|
||||
value: {{ include "localpv.analyticsStateCM.name" . | quote }}
|
||||
# OPENEBS_IO_ANALYTICS_LEASE names the Lease used to elect a single
|
||||
# analytics emitter across all DaemonSet pods. Release-scoped so
|
||||
# multiple releases in the same namespace do not collide. The
|
||||
# provisioner creates the Lease on-demand via client-go's
|
||||
# leader-election; it is not managed by Helm.
|
||||
- name: OPENEBS_IO_ANALYTICS_LEASE
|
||||
value: {{ include "localpv.analyticsLease.name" . | quote }}
|
||||
{{- if .Values.global.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.global.analytics.gaId | quote }}
|
||||
{{- else if .Values.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.analytics.gaId | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.global.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.global.analytics.gaKey | quote }}
|
||||
{{- else if .Values.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.analytics.gaKey | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_BASE_PATH
|
||||
value: "{{ .Values.localpv.basePath }}"
|
||||
- name: OPENEBS_IO_WORKER_THREADS
|
||||
value: {{ .Values.localpv.controller.workers | quote }}
|
||||
{{- if .Values.localpv.controller.client.qps }}
|
||||
- name: OPENEBS_IO_CLIENT_QPS
|
||||
value: {{ .Values.localpv.controller.client.qps | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.controller.client.burst }}
|
||||
- name: OPENEBS_IO_CLIENT_BURST
|
||||
value: {{ .Values.localpv.controller.client.burst | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_HELPER_IMAGE
|
||||
value: "{{ include "localpv.common.image" (dict "imageRoot" .Values.helperPod.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
- name: OPENEBS_IO_IMAGE_PULL_POLICY
|
||||
value: "{{ default .Values.helperPod.image.pullPolicy .Values.global.imagePullPolicy }}"
|
||||
- name: OPENEBS_IO_HELPER_POD_HOST_NETWORK
|
||||
value: "{{ .Values.helperPod.hostNetwork }}"
|
||||
- name: OPENEBS_IO_INSTALLER_TYPE
|
||||
value: "localpv-charts-helm-nodedeploy"
|
||||
- name: OPENEBS_IO_HELPER_POD_TIMEOUT_SECS
|
||||
value: {{ .Values.helperPod.timeoutSecs | quote }}
|
||||
# Disable leader election in node deployment mode.
|
||||
# Not related to anonymous usage analytics leader election.
|
||||
- name: LEADER_ELECTION_ENABLED
|
||||
value: "false"
|
||||
# Enable node deployment mode
|
||||
- name: NODE_DEPLOYMENT
|
||||
value: "true"
|
||||
# OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS is the address the health-probe
|
||||
# HTTP server binds to. /healthz serves liveness, /readyz serves readiness.
|
||||
- name: OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS
|
||||
value: ":{{ $healthPort }}"
|
||||
{{- include "localpv.helper.pullSecrets" . | indent 8 }}
|
||||
args:
|
||||
- "--node-deployment=true"
|
||||
{{- if .Values.localpv.allowInsecurePvcBasePathOverride }}
|
||||
- "--allow-insecure-pvc-basepath-override"
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: healthz
|
||||
containerPort: {{ $healthPort }}
|
||||
protocol: TCP
|
||||
{{- if .Values.localpv.healthCheck.liveness.enabled }}
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.liveness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.liveness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.liveness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.liveness.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.healthCheck.readiness.enabled }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.readiness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.readiness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.readiness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.readiness.failureThreshold }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: host-root
|
||||
mountPath: /host
|
||||
mountPropagation: HostToContainer
|
||||
{{- if .Values.localpv.nodeDeployment.additionalVolumeMounts }}
|
||||
{{ toYaml .Values.localpv.nodeDeployment.additionalVolumeMounts | indent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: host-root
|
||||
hostPath:
|
||||
path: /
|
||||
type: Directory
|
||||
{{- if .Values.localpv.nodeDeployment.additionalVolumes }}
|
||||
{{ toYaml .Values.localpv.nodeDeployment.additionalVolumes | indent 6 }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{ toYaml .Values.localpv.nodeSelector | indent 8 }}
|
||||
{{- end }}
|
||||
{{- if $tolerations := include "tolerations_with_early_eviction" . }}
|
||||
tolerations: {{ $tolerations }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.affinity }}
|
||||
affinity:
|
||||
{{ toYaml .Values.localpv.affinity | indent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,198 @@
|
||||
{{- if .Values.localpv.enabled }}
|
||||
{{- if not .Values.localpv.nodeDeployment.enabled }}
|
||||
{{- $healthPort := default 8081 .Values.localpv.healthCheck.port }}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
replicas: {{ .Values.localpv.replicas }}
|
||||
strategy:
|
||||
type: "Recreate"
|
||||
rollingUpdate: null
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "localpv.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
{{- with .Values.localpv.podAnnotations }}
|
||||
annotations: {{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 8 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.localpv.podLabels }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.loggingLabels}}
|
||||
{{ toYaml . | nindent 8 -}}
|
||||
{{- end}}
|
||||
spec:
|
||||
{{- if .Values.localpv.priorityClassName }}
|
||||
priorityClassName: {{ tpl .Values.localpv.priorityClassName . }}
|
||||
{{- end }}
|
||||
{{- if or .Values.global.imagePullSecrets .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- include "localpv.common.pullSecrets" . | indent 6 }}
|
||||
{{- end }}
|
||||
serviceAccountName: {{ template "localpv.serviceAccountName" . }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||
containers:
|
||||
- name: {{ template "localpv.fullname" . }}
|
||||
image: "{{ include "localpv.common.image" (dict "imageRoot" .Values.localpv.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
imagePullPolicy: {{ default .Values.localpv.image.pullPolicy .Values.global.imagePullPolicy }}
|
||||
resources:
|
||||
{{ toYaml .Values.localpv.resources | indent 10 }}
|
||||
env:
|
||||
# OPENEBS_IO_K8S_MASTER enables openebs provisioner to connect to K8s
|
||||
# based on this address. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_K8S_MASTER
|
||||
# value: "http://10.128.0.12:8080"
|
||||
# OPENEBS_IO_KUBE_CONFIG enables openebs provisioner to connect to K8s
|
||||
# based on this config. This is ignored if empty.
|
||||
# This is supported for openebs provisioner version 0.5.2 onwards
|
||||
#- name: OPENEBS_IO_KUBE_CONFIG
|
||||
# value: "/home/ubuntu/.kube/config"
|
||||
- name: OPENEBS_NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.nodeName
|
||||
# OPENEBS_SERVICE_ACCOUNT provides the service account of this pod as
|
||||
# environment variable
|
||||
- name: OPENEBS_SERVICE_ACCOUNT
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: spec.serviceAccountName
|
||||
# OPENEBS_IO_BASE_PATH is the environment variable that provides the
|
||||
# default base path on the node where host-path PVs will be provisioned.
|
||||
{{- if kindIs "bool" .Values.global.analytics.enabled }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.global.analytics.enabled }}"
|
||||
{{- else }}
|
||||
- name: OPENEBS_IO_ENABLE_ANALYTICS
|
||||
value: "{{ .Values.analytics.enabled }}"
|
||||
{{- end }}
|
||||
# OPENEBS_IO_ANALYTICS_STATE_CM names the ConfigMap consulted to
|
||||
# decide whether to emit the install event for this Helm release
|
||||
# and to persist ping/heartbeat timestamps across pod restarts.
|
||||
# The provisioner creates and updates this ConfigMap itself; it
|
||||
# is not managed by Helm. helm uninstall does not remove it, so
|
||||
# reinstalls into the same namespace will not re-fire the install
|
||||
# event unless the ConfigMap is deleted manually.
|
||||
- name: OPENEBS_IO_ANALYTICS_STATE_CM
|
||||
value: {{ include "localpv.analyticsStateCM.name" . | quote }}
|
||||
{{- if .Values.global.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.global.analytics.gaId | quote }}
|
||||
{{- else if .Values.analytics.gaId }}
|
||||
- name: GA_ID
|
||||
value: {{ .Values.analytics.gaId | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.global.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.global.analytics.gaKey | quote }}
|
||||
{{- else if .Values.analytics.gaKey }}
|
||||
- name: GA_KEY
|
||||
value: {{ .Values.analytics.gaKey | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_BASE_PATH
|
||||
value: "{{ .Values.localpv.basePath }}"
|
||||
- name: OPENEBS_IO_WORKER_THREADS
|
||||
value: {{ .Values.localpv.controller.workers | quote }}
|
||||
{{- if .Values.localpv.controller.client.qps }}
|
||||
- name: OPENEBS_IO_CLIENT_QPS
|
||||
value: {{ .Values.localpv.controller.client.qps | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.controller.client.burst }}
|
||||
- name: OPENEBS_IO_CLIENT_BURST
|
||||
value: {{ .Values.localpv.controller.client.burst | quote }}
|
||||
{{- end }}
|
||||
- name: OPENEBS_IO_IMAGE_PULL_POLICY
|
||||
value: "{{ default .Values.helperPod.image.pullPolicy .Values.global.imagePullPolicy }}"
|
||||
- name: OPENEBS_IO_HELPER_IMAGE
|
||||
value: "{{ include "localpv.common.image" (dict "imageRoot" .Values.helperPod.image "global" .Values.global "override" .Values.globalImageRegistryOverride) }}"
|
||||
- name: OPENEBS_IO_HELPER_POD_HOST_NETWORK
|
||||
value: "{{ .Values.helperPod.hostNetwork }}"
|
||||
- name: OPENEBS_IO_INSTALLER_TYPE
|
||||
value: "localpv-charts-helm-helperpod"
|
||||
- name: OPENEBS_IO_HELPER_POD_TIMEOUT_SECS
|
||||
value: {{ .Values.helperPod.timeoutSecs | quote }}
|
||||
# LEADER_ELECTION_ENABLED is used to enable/disable leader election. By default
|
||||
# leader election is enabled.
|
||||
- name: LEADER_ELECTION_ENABLED
|
||||
value: "{{ .Values.localpv.enableLeaderElection }}"
|
||||
# OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS is the address the health-probe
|
||||
# HTTP server binds to. /healthz serves liveness, /readyz serves readiness.
|
||||
- name: OPENEBS_IO_HEALTH_PROBE_BIND_ADDRESS
|
||||
value: ":{{ $healthPort }}"
|
||||
{{- include "localpv.helper.pullSecrets" . | indent 8 }}
|
||||
{{/* Add args below */}}
|
||||
{{/* All args are optional (so far, at least), so the 'args' PodTemplate key
|
||||
* is only included if there is at least one arg. And that's why we're doing
|
||||
* it this way.
|
||||
*/}}
|
||||
{{- $args := list }}
|
||||
{{- if .Values.localpv.allowInsecurePvcBasePathOverride }}
|
||||
{{- $args = append $args "--allow-insecure-pvc-basepath-override" }}
|
||||
{{- end }}
|
||||
|
||||
{{- if $args }}
|
||||
args:
|
||||
{{- range $args }}
|
||||
- {{ . | quote }} {{/* Add new args to the above $args list */}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: healthz
|
||||
containerPort: {{ $healthPort }}
|
||||
protocol: TCP
|
||||
{{- if .Values.localpv.healthCheck.liveness.enabled }}
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.liveness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.liveness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.liveness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.liveness.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.healthCheck.readiness.enabled }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: healthz
|
||||
initialDelaySeconds: {{ .Values.localpv.healthCheck.readiness.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.localpv.healthCheck.readiness.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.localpv.healthCheck.readiness.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.localpv.healthCheck.readiness.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{ toYaml .Values.localpv.nodeSelector | indent 8 }}
|
||||
{{- end }}
|
||||
{{- if $tolerations := include "tolerations_with_early_eviction" . }}
|
||||
tolerations: {{ $tolerations }}
|
||||
{{- end }}
|
||||
{{- if .Values.localpv.affinity }}
|
||||
affinity:
|
||||
{{ toYaml .Values.localpv.affinity | indent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,47 @@
|
||||
{{- if .Values.hostpathClass.enabled }}
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
name: {{ tpl (.Values.hostpathClass.name) .}}
|
||||
annotations:
|
||||
openebs.io/cas-type: local
|
||||
cas.openebs.io/config: |
|
||||
- name: StorageType
|
||||
value: "hostpath"
|
||||
{{- if or .Values.localpv.basePath .Values.hostpathClass.basePath }}
|
||||
- name: BasePath
|
||||
value: {{ tpl (.Values.hostpathClass.basePath | default .Values.localpv.basePath | quote) . }}
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.nodeAffinityLabels }}
|
||||
- name: NodeAffinityLabels
|
||||
list:
|
||||
{{ toYaml .Values.hostpathClass.nodeAffinityLabels | indent 10 }}
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.xfsQuota.enabled }}
|
||||
- name: XFSQuota
|
||||
enabled: "{{ .Values.hostpathClass.xfsQuota.enabled }}"
|
||||
data:
|
||||
softLimitGrace: "{{ .Values.hostpathClass.xfsQuota.softLimitGrace }}"
|
||||
hardLimitGrace: "{{ .Values.hostpathClass.xfsQuota.hardLimitGrace }}"
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.ext4Quota.enabled }}
|
||||
- name: EXT4Quota
|
||||
enabled: "{{ .Values.hostpathClass.ext4Quota.enabled }}"
|
||||
data:
|
||||
softLimitGrace: "{{ .Values.hostpathClass.ext4Quota.softLimitGrace }}"
|
||||
hardLimitGrace: "{{ .Values.hostpathClass.ext4Quota.hardLimitGrace }}"
|
||||
{{- end }}
|
||||
{{- if .Values.hostpathClass.isDefaultClass }}
|
||||
storageclass.kubernetes.io/is-default-class: "true"
|
||||
{{- end }}
|
||||
{{- if .Values.extraLabels }}
|
||||
labels: {{- toYaml .Values.extraLabels | nindent 4 -}}
|
||||
{{- end }}
|
||||
provisioner: openebs.io/local
|
||||
volumeBindingMode: WaitForFirstConsumer
|
||||
reclaimPolicy: {{ .Values.hostpathClass.reclaimPolicy }}
|
||||
{{- if .Values.hostpathClass.allowedTopologies }}
|
||||
allowedTopologies:
|
||||
{{ toYaml .Values.hostpathClass.allowedTopologies }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,33 @@
|
||||
{{- if .Values.rbac.pspEnabled }}
|
||||
apiVersion: policy/v1beta1
|
||||
kind: PodSecurityPolicy
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
privileged: {{ .Values.localpv.privileged }}
|
||||
allowPrivilegeEscalation: true
|
||||
allowedCapabilities: ['*']
|
||||
volumes: ['*']
|
||||
hostNetwork: true
|
||||
hostPorts:
|
||||
- min: 0
|
||||
max: 65535
|
||||
hostIPC: true
|
||||
hostPID: true
|
||||
runAsUser:
|
||||
rule: 'RunAsAny'
|
||||
seLinux:
|
||||
rule: 'RunAsAny'
|
||||
supplementalGroups:
|
||||
rule: 'RunAsAny'
|
||||
fsGroup:
|
||||
rule: 'RunAsAny'
|
||||
{{- end }}
|
||||
@@ -0,0 +1,124 @@
|
||||
{{- if .Values.serviceAccount.create -}}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ include "localpv.serviceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with .Values.serviceAccount.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.rbac.create }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
- apiGroups: ["*"]
|
||||
resources: ["nodes"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["*"]
|
||||
resources: ["namespaces", "pods", "events", "endpoints"]
|
||||
verbs: ["*"]
|
||||
- apiGroups: ["*"]
|
||||
resources: ["resourcequotas", "limitranges"]
|
||||
verbs: ["list", "watch"]
|
||||
- apiGroups: ["*"]
|
||||
resources: ["storageclasses", "persistentvolumeclaims", "persistentvolumes"]
|
||||
verbs: ["*"]
|
||||
- apiGroups: ["apiextensions.k8s.io"]
|
||||
resources: ["customresourcedefinitions"]
|
||||
verbs: [ "get", "list", "create", "update", "delete", "patch"]
|
||||
- apiGroups: ["openebs.io"]
|
||||
resources: [ "*"]
|
||||
verbs: ["*" ]
|
||||
- apiGroups: ["coordination.k8s.io"]
|
||||
resources: ["leases"]
|
||||
verbs: ["get", "create", "update"]
|
||||
# Analytics state ConfigMap: the provisioner creates and updates this
|
||||
# ConfigMap itself to persist install/ping/heartbeat timestamps.
|
||||
- apiGroups: [""]
|
||||
resources: ["configmaps"]
|
||||
verbs: ["get", "create", "update", "patch"]
|
||||
- nonResourceURLs: ["/metrics"]
|
||||
verbs: ["get"]
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "localpv.fullname" . }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "localpv.serviceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- if .Values.rbac.pspEnabled }}
|
||||
---
|
||||
kind: ClusterRole
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
- apiGroups: ['policy']
|
||||
resources: ['podsecuritypolicies']
|
||||
verbs: ['use']
|
||||
resourceNames:
|
||||
- {{ template "localpv.fullname" . }}-psp
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
{{- with .Values.localpv.annotations }}
|
||||
annotations: {{ toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "localpv.labels" . | nindent 4 }}
|
||||
{{- if .Values.extraLabels -}}
|
||||
{{- toYaml .Values.extraLabels | nindent 4 }}
|
||||
{{- end }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: {{ template "localpv.fullname" . }}-psp
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "localpv.serviceAccountName" . }}
|
||||
namespace: {{ $.Release.Namespace }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
Reference in New Issue
Block a user