Functions have access to secrets/configmaps specified by the user (#399)

This commit solves part of the issue #52 , functions are able to access secrets/configmaps specified by the user. For now, CLI only accept one secret/configmap. For advanced users, it will be able to use YAML to declare multiple secrets/configmaps in later changes.
This commit is contained in:
prithviramesh
2018-02-05 17:49:26 +08:00
committed by Ta-Ching Chen
parent 4cf195768e
commit 1eb0453ce4
14 changed files with 411 additions and 31 deletions
+45 -2
View File
@@ -69,6 +69,8 @@ type (
labelsForPool map[string]string
requestChannel chan *choosePodRequest
sharedMountPath string // used by generic pool when creating env deployment to specify the share volume path for fetcher & env
sharedSecretPath string
sharedCfgMapPath string
}
// serialize the choosing of pods so that choices don't conflict
@@ -134,6 +136,8 @@ func MakeGenericPool(
fetcherImage: fetcherImage,
useSvc: false, // defaults off -- svc takes a second or more to become routable, slowing cold start
sharedMountPath: "/userfunc", // change this may break v1 compatibility, since most of the v1 environments have hard-coded "/userfunc" in loading path
sharedSecretPath: "/secrets",
sharedCfgMapPath: "/configs",
}
gp.runtimeImagePullPolicy = getImagePullPolicy(runtimeImagePullPolicy)
@@ -360,7 +364,9 @@ func (gp *GenericPool) specializePod(pod *apiv1.Pod, metadata *metav1.ObjectMeta
Namespace: fn.Spec.Package.PackageRef.Namespace,
Name: fn.Spec.Package.PackageRef.Name,
},
Filename: targetFilename,
Filename: targetFilename,
Secrets: fn.Spec.Secrets,
ConfigMaps: fn.Spec.ConfigMaps,
})
if err != nil {
return err
@@ -449,6 +455,20 @@ func (gp *GenericPool) createPool() error {
EmptyDir: &apiv1.EmptyDirVolumeSource{},
},
},
{
Name: "secrets",
VolumeSource: apiv1.VolumeSource{
EmptyDir: &apiv1.EmptyDirVolumeSource{},
},
},
{
Name: "config",
VolumeSource: apiv1.VolumeSource{
EmptyDir: &apiv1.EmptyDirVolumeSource{},
},
},
},
Containers: []apiv1.Container{
{
@@ -461,6 +481,16 @@ func (gp *GenericPool) createPool() error {
Name: "userfunc",
MountPath: gp.sharedMountPath,
},
{
Name: "secrets",
MountPath: gp.sharedSecretPath,
},
{
Name: "config",
MountPath: gp.sharedCfgMapPath,
},
},
Resources: gp.env.Spec.Resources,
},
@@ -474,8 +504,21 @@ func (gp *GenericPool) createPool() error {
Name: "userfunc",
MountPath: gp.sharedMountPath,
},
{
Name: "secrets",
MountPath: gp.sharedSecretPath,
},
{
Name: "config",
MountPath: gp.sharedCfgMapPath,
},
},
Command: []string{"/fetcher", gp.sharedMountPath},
Command: []string{"/fetcher",
"-secret-dir", gp.sharedSecretPath,
"-cfgmap-dir", gp.sharedCfgMapPath,
gp.sharedMountPath},
},
},
ServiceAccountName: "fission-fetcher",