refactoring: Breakdown fission-all chart into components and removed fission-core (#2224)
* Sync a few files from fission-all to fission-core chart * Change values in fission-all chart We keep the following components by default disabled now, which were enabled by default earlier. 1. nats - Fission Nats integration 2. influxdb - Influxdb and logger component 3. prometheus - Prometheus disabled by default 4. canaryDeployment - Disabled by default This change reduces the need for a fission-core chart and we can configure values of fission-all so that it can provide the behaviour of fission-all as well as fission-core. * Remove fission-core chart * Add README in the fission-all chart * Rename clusterrolebinding fission-crd to fission-cr-admin * Add icon and sources in helm chart Signed-off-by: Sanket Sudake <sanketsudake@gmail.com>
This commit is contained in:
@@ -0,0 +1,194 @@
|
||||
{{- if .Values.influxdb.enabled }}
|
||||
# Fluentbit deployment for Fission
|
||||
#
|
||||
# Requires:
|
||||
# - service account: fission-svc
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-fluentbit
|
||||
data:
|
||||
{{- if .Files.Get "config/fluentbit.conf" }}
|
||||
fluentbit.conf: |
|
||||
{{ .Files.Get "config/fluentbit.conf" | indent 3 }}
|
||||
{{ else }}
|
||||
{{ fail "invalid chart" }}
|
||||
{{- end }}
|
||||
{{- if .Files.Get "config/parsers.conf" }}
|
||||
parsers.conf: |
|
||||
{{ .Files.Get "config/parsers.conf" | indent 3 }}
|
||||
{{ else }}
|
||||
{{ fail "invalid chart" }}
|
||||
{{- end }}
|
||||
{{- if .Values.logger.podSecurityPolicy.enabled }}
|
||||
---
|
||||
apiVersion: policy/v1beta1
|
||||
kind: PodSecurityPolicy
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-logger-privileged
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: logger
|
||||
spec:
|
||||
privileged: true
|
||||
seLinux:
|
||||
rule: RunAsAny
|
||||
supplementalGroups:
|
||||
rule: RunAsAny
|
||||
runAsUser:
|
||||
rule: RunAsAny
|
||||
fsGroup:
|
||||
rule: RunAsAny
|
||||
volumes:
|
||||
- '*'
|
||||
{{- if .Values.logger.podSecurityPolicy.additionalCapabilities }}
|
||||
allowedCapabilities:
|
||||
{{- range .Values.logger.podSecurityPolicy.additionalCapabilities }}
|
||||
- {{ . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: psp:{{ .Release.Name }}-fission-logger-privileged
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: logger
|
||||
rules:
|
||||
- apiGroups: ['policy']
|
||||
resources: ['podsecuritypolicies']
|
||||
verbs: ['use']
|
||||
resourceNames:
|
||||
- {{ .Release.Name }}-fission-logger-privileged
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: psp:{{ .Release.Name }}-fission-logger-privileged
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: logger
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: psp:{{ .Release.Name }}-fission-logger-privileged
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
metadata:
|
||||
name: logger
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: logger
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: logger
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: logger
|
||||
spec:
|
||||
initContainers:
|
||||
- name: init
|
||||
image: {{ .Values.busyboxImage | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ['mkdir', '-p', '/var/log/fission']
|
||||
volumeMounts:
|
||||
- name: container-log
|
||||
mountPath: /var/log/
|
||||
readOnly: false
|
||||
{{- if .Values.logger.enableSecurityContext }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: logger
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
env:
|
||||
- name: NODE_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
apiVersion: v1
|
||||
fieldPath: spec.nodeName
|
||||
- name: OPENTRACING_ENABLED
|
||||
value: {{ .Values.openTracing.enabled | default false | quote }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--logger"]
|
||||
volumeMounts:
|
||||
- name: container-log
|
||||
mountPath: /var/log/
|
||||
readOnly: false
|
||||
- name: docker-log
|
||||
mountPath: /var/lib/docker/containers
|
||||
readOnly: true
|
||||
{{- if .Values.logger.enableSecurityContext }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
- name: fluentbit
|
||||
{{- if .Values.repository }}
|
||||
image: "{{ .Values.logger.fluentdImageRepository }}/{{ .Values.logger.fluentdImage }}:{{ .Values.logger.fluentdImageTag }}"
|
||||
{{ else }}
|
||||
image: "{{ .Values.logger.fluentdImage }}:{{ .Values.logger.fluentdImageTag }}"
|
||||
{{- end }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
# CMD ["/fluent-bit/bin/fluent-bit", "-c", "/fluent-bit/etc/fluent-bit.conf"]
|
||||
command: ["/fluent-bit/bin/fluent-bit", "-c", "/fluent-bit/etc/fluentbit.conf"]
|
||||
env:
|
||||
- name: INFLUXDB_ADDRESS
|
||||
value: influxdb
|
||||
- name: INFLUXDB_PORT
|
||||
value: "8086"
|
||||
- name: INFLUXDB_DBNAME
|
||||
value: "fissionFunctionLog"
|
||||
- name: INFLUXDB_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: influxdb
|
||||
key: username
|
||||
- name: INFLUXDB_PASSWD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: influxdb
|
||||
key: password
|
||||
- name: LOG_PATH
|
||||
value: /var/log/fission/*.log
|
||||
- name: OPENTRACING_ENABLED
|
||||
value: {{ .Values.openTracing.enabled | default false | quote }}
|
||||
{{- if .Values.logger.enableSecurityContext }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: container-log
|
||||
mountPath: /var/log/
|
||||
readOnly: false
|
||||
- name: docker-log
|
||||
mountPath: /var/lib/docker/containers
|
||||
readOnly: true
|
||||
- name: fluentbit-config
|
||||
mountPath: /fluent-bit/etc/
|
||||
readOnly: true
|
||||
serviceAccountName: fission-svc
|
||||
volumes:
|
||||
- name: container-log
|
||||
hostPath:
|
||||
path: /var/log/
|
||||
- name: docker-log
|
||||
hostPath:
|
||||
path: /var/lib/docker/containers
|
||||
# Fluentbit config location: /fluent-bit/etc/*.conf
|
||||
- name: fluentbit-config
|
||||
configMap:
|
||||
name: {{ .Release.Name }}-fission-fluentbit
|
||||
updateStrategy:
|
||||
type: RollingUpdate
|
||||
{{- end }}
|
||||
Reference in New Issue
Block a user