diff --git a/charts/fission/README.md b/charts/README.md similarity index 53% rename from charts/fission/README.md rename to charts/README.md index 4ce23551..799d2083 100644 --- a/charts/fission/README.md +++ b/charts/README.md @@ -5,15 +5,24 @@ ## Prerequisites -- Kubernetes 1.4+ with Beta APIs enabled +- Kubernetes 1.6+ with Beta APIs enabled +## Helm charts + +The following table lists two helm charts for Fission. + +| Parameter | Description | +| ---------------| ---------------------------------------------------------------------------------------| +| `fission-core` | FaaS essentials, and triggers for HTTP, Timers and Kubernetes Watches | +| `fission-all` | Log aggregation with fluentd and InfluxDB; NATS for message queue triggers; Fission-UI | + ## Installing the chart To install the chart with the release name `my-release`, ```bash -$ helm install --name my-release ./fission +$ helm install --name my-release fission-all ``` ## Uninstalling the chart @@ -36,23 +45,36 @@ The following table lists the configurable parameters of the Fission chart and t | `controllerPort` | Fission Controller Service Port | `31313` | | `routerPort` | Fission Router Service Port | `31314` | | `functionNamespace` | Namespace for Fission functions | `fission-function` | +| `openshift` | RBAC for openshift | `false` | + + +* Extra configuration for `fission-all` + +| Parameter | Description | Default | +| ---------------------- | --------------------------- | -------------------------- | +| `logger.influxdbAdmin` | Log database admin username | `admin`. | +| `logger.fluentdImage` | Logger fluentd image | `fission/fluentd` | +| `fissionUiImage` | Fission ui image | `fission/fission-ui:0.1.0` | +| `nats.authToken` | Nats streaming auth token | `defaultFissionAuthToken` | +| `nats.clusterID` | Nats streaming clusterID | `fissionMQTrigger` | + Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example, ```bash -$ helm install --name my-release --set image=custom/fission-bundle,imageTag=v1 fission +$ helm install --name my-release --set image=custom/fission-bundle,imageTag=v1 fission-all ``` If you're using minikube, set serviceType to NodePort: ```bash -$ helm install --name my-release --set serviceType=NodePort fission +$ helm install --name my-release --set serviceType=NodePort fission-all ``` You can also set parameters with a yaml file (see values.yaml for what it should look like): ```bash -$ helm install --name my-release -f values.yaml fission +$ helm install --name my-release -f values.yaml fission-all ``` diff --git a/charts/fission/.helmignore b/charts/fission-all/.helmignore similarity index 100% rename from charts/fission/.helmignore rename to charts/fission-all/.helmignore diff --git a/charts/fission-all/Chart.yaml b/charts/fission-all/Chart.yaml new file mode 100644 index 00000000..3256ce5d --- /dev/null +++ b/charts/fission-all/Chart.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +name: fission-all +version: 0.1.0 +description: Fission is a fast serverless framework for Kubernetes. +keywords: +- fission +- serverless +home: http://fission.io/ +maintainers: + - name: Sanket Sudake + email: sanketsudake@gmail.com + - name: Soam Vasani + email: soamvasani@platform9.com + - name: Ta Ching Chen + email: contact@tachingchen.com +engine: gotpl diff --git a/charts/fission/LICENSE b/charts/fission-all/LICENSE similarity index 100% rename from charts/fission/LICENSE rename to charts/fission-all/LICENSE diff --git a/charts/fission/templates/NOTES.txt b/charts/fission-all/templates/NOTES.txt similarity index 72% rename from charts/fission/templates/NOTES.txt rename to charts/fission-all/templates/NOTES.txt index 6f65927b..06ac3610 100644 --- a/charts/fission/templates/NOTES.txt +++ b/charts/fission-all/templates/NOTES.txt @@ -1,10 +1,13 @@ 1. Install the client CLI. Mac: - $ curl http://fission.io/mac/fission > fission && chmod +x fission && sudo mv fission /usr/local/bin/ + $ curl -Lo fission https://github.com/fission/fission/releases/download/nightly20170705/fission-cli-osx && chmod +x fission && sudo mv fission /usr/local/bin/ Linux: - $ curl http://fission.io/linux/fission > fission && chmod +x fission && sudo mv fission /usr/local/bin/ + $ curl -Lo fission https://github.com/fission/fission/releases/download/nightly20170705/fission-cli-linux && chmod +x fission && sudo mv fission /usr/local/bin/ + +Windows: + For Windows, you can use the linux binary on WSL. Or you can download this windows executable: https://github.com/fission/fission/releases/download/nightly20170705/fission-cli-windows.exe 2. Set the FISSION_URL and FISSION_ROUTER environment variables. FISSION_URL is used by the fission CLI to find the server. diff --git a/charts/fission/templates/_helpers.tpl b/charts/fission-all/templates/_helpers.tpl similarity index 100% rename from charts/fission/templates/_helpers.tpl rename to charts/fission-all/templates/_helpers.tpl diff --git a/charts/fission-all/templates/deployment.yaml b/charts/fission-all/templates/deployment.yaml new file mode 100644 index 00000000..d96fa4f7 --- /dev/null +++ b/charts/fission-all/templates/deployment.yaml @@ -0,0 +1,470 @@ +{{ if .Values.openshift }} + +# For openshift + +--- +apiVersion: v1 +kind: ProjectRequest +metadata: + name: fission + labels: + name: fission + +--- +apiVersion: v1 +kind: ProjectRequest +metadata: + name: fission-function + labels: + name: fission-function + +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: fission-admin + namespace: fission + +--- +apiVersion: v1 +kind: ClusterRole +metadata: + name: fission:fission-admin +rules: +- apiGroups: + - extensions + attributeRestrictions: null + resources: + - deployments + verbs: + - create + - get + - list + - update + - watch +- apiGroups: + - "" + attributeRestrictions: null + resources: + - pods + verbs: + - get + - list + - update + +--- +apiVersion: v1 +groupNames: null +kind: RoleBinding +metadata: + name: fission:fission-admin + namespace: fission-function +roleRef: + name: fission:fission-admin +subjects: +- kind: ServiceAccount + name: fission-admin + namespace: fission +userNames: +- system:serviceaccount:fission:fission-admin + +{{ else }} + +# For all environments except openshift + +--- +apiVersion: v1 +kind: Namespace +metadata: + name: {{ .Values.functionNamespace }} + labels: + name: fission-function + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" + +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: fission-admin + namespace: fission + +--- +kind: RoleBinding +apiVersion: rbac.authorization.k8s.io/v1beta1 +metadata: + name: fission-admin + namespace: fission +subjects: + - kind: ServiceAccount + name: fission-admin + namespace: fission +roleRef: + kind: ClusterRole + name: admin + apiGroup: rbac.authorization.k8s.io + +--- +kind: RoleBinding +apiVersion: rbac.authorization.k8s.io/v1beta1 +metadata: + name: fission-function-admin + namespace: fission-function +subjects: + - kind: ServiceAccount + name: fission-admin + namespace: fission +roleRef: + kind: ClusterRole + name: admin + apiGroup: rbac.authorization.k8s.io + +{{ end }} + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: controller + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: controller + spec: + containers: + - name: controller + image: "{{ .Values.image }}:{{ .Values.imageTag }}" + command: ["/fission-bundle"] + args: ["--controllerPort", "8888", "--filepath", "/filestore"] + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: router + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: router + spec: + containers: + - name: router + image: "{{ .Values.image }}:{{ .Values.imageTag }}" + command: ["/fission-bundle"] + args: ["--routerPort", "8888"] + +--- +apiVersion: v1 +kind: Service +metadata: + name: poolmgr + labels: + svc: poolmgr + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + type: ClusterIP + ports: + - port: 80 + targetPort: 8888 + selector: + svc: poolmgr + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: poolmgr + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: poolmgr + spec: + containers: + - name: poolmgr + image: "{{ .Values.image }}:{{ .Values.imageTag }}" + command: ["/fission-bundle"] + args: ["--poolmgrPort", "8888", "--namespace", "{{ .Values.functionNamespace }}"] + serviceAccount: fission-admin + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: kubewatcher + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: kubewatcher + spec: + containers: + - name: kubewatcher + image: "{{ .Values.image }}:{{ .Values.imageTag }}" + command: ["/fission-bundle"] + args: ["--kubewatcher"] + serviceAccount: fission-admin + +--- +apiVersion: v1 +kind: Service +metadata: + name: etcd + labels: + svc: etcd + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + type: ClusterIP + ports: + - port: 2379 + targetPort: 2379 + selector: + svc: etcd + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: etcd + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: etcd + spec: + containers: + - name: etcd + image: quay.io/coreos/etcd + env: + - name: ETCD_LISTEN_CLIENT_URLS + value: http://0.0.0.0:2379 + - name: ETCD_ADVERTISE_CLIENT_URLS + value: http://etcd:2379 + +--- +apiVersion: v1 +kind: Service +metadata: + name: influxdb + labels: + svc: influxdb + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + type: ClusterIP + ports: + - port: 8086 + targetPort: 8086 + selector: + svc: influxdb + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: influxdb + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: influxdb + spec: + containers: + - name: influxdb + image: tutum/influxdb + env: + - name: PRE_CREATE_DB + value: fissionFunctionLog + - name: ADMIN_USER + valueFrom: + secretKeyRef: + name: influxdb + key: username + - name: INFLUXDB_INIT_PWD + valueFrom: + secretKeyRef: + name: influxdb + key: password + +--- +apiVersion: extensions/v1beta1 +kind: DaemonSet +metadata: + name: logger + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + template: + metadata: + labels: + svc: logger + spec: + containers: + - name: logger + image: "{{ .Values.image }}:{{ .Values.imageTag }}" + imagePullPolicy: IfNotPresent + command: ["/fission-bundle"] + args: ["--logger"] + volumeMounts: + - name: container-log + mountPath: /var/log/containers + readOnly: true + - name: docker-log + mountPath: /var/lib/docker/containers + readOnly: true + - name: fission-log + mountPath: /var/log/fission + readOnly: false + ports: + - containerPort: 1234 + hostPort: 1234 + protocol: TCP + - name: fluentd + image: {{ .Values.logger.fluentdImage }} + imagePullPolicy: IfNotPresent + env: + - name: INFLUXDB_ADDRESS + value: influxdb + - name: INFLUXDB_PORT + value: "8086" + - name: INFLUXDB_DBNAME + value: "fissionFunctionLog" + - name: INFLUXDB_USERNAME + valueFrom: + secretKeyRef: + name: influxdb + key: username + - name: INFLUXDB_PASSWD + valueFrom: + secretKeyRef: + name: influxdb + key: password + volumeMounts: + - name: container-log + mountPath: /var/log/containers + readOnly: true + - name: docker-log + mountPath: /var/lib/docker/containers + readOnly: true + - name: fission-log + mountPath: /var/log/fission + readOnly: false + serviceAccount: fission-admin + volumes: + - name: container-log + hostPath: + path: /var/log/containers + - name: docker-log + hostPath: + path: /var/lib/docker/containers + - name: fission-log + hostPath: + path: /var/log/fission + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: timer + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: timer + spec: + containers: + - name: timer + image: "{{ .Values.image }}:{{ .Values.imageTag }}" + command: ["/fission-bundle"] + args: ["--timer"] + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: fission-ui + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: fission-ui + spec: + containers: + - name: nginx + image: {{ .Values.fissionUiImage }} + - name: kubectl-proxy + image: lachlanevenson/k8s-kubectl + args: ["proxy", "--port", "8001", "--address", "127.0.0.1"] + serviceAccount: fission-admin + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + labels: + svc: nats-streaming + name: nats-streaming +spec: + replicas: 1 + template: + metadata: + labels: + svc: nats-streaming + spec: + containers: + - name: nats-streaming + image: nats-streaming + args: ["--cluster_id", "{{ .Values.nats.clusterID }}", "--auth", "{{ .Values.nats.authToken }}"] + ports: + - containerPort: 4222 + hostPort: 4222 + protocol: TCP + +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: mqtrigger + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + replicas: 1 + template: + metadata: + labels: + svc: mqtrigger + spec: + containers: + - name: mqtrigger + image: "{{ .Values.image }}:{{ .Values.imageTag }}" + command: ["/fission-bundle"] + args: ["--mqt"] + env: + - name: MESSAGE_QUEUE_TYPE + value: nats-streaming + - name: MESSAGE_QUEUE_URL + value: nats://{{ .Values.nats.authToken }}@nats-streaming:4222 \ No newline at end of file diff --git a/charts/fission-all/templates/secrets.yaml b/charts/fission-all/templates/secrets.yaml new file mode 100644 index 00000000..b6eb9480 --- /dev/null +++ b/charts/fission-all/templates/secrets.yaml @@ -0,0 +1,10 @@ +apiVersion: v1 +kind: Secret +metadata: + name: influxdb + labels: + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +type: Opaque +data: + username: {{ .Values.logger.influxdbAdmin | b64enc | quote }} + password: {{ randAlphaNum 20 | b64enc | quote }} \ No newline at end of file diff --git a/charts/fission-all/templates/svc.yaml b/charts/fission-all/templates/svc.yaml new file mode 100644 index 00000000..437b9f36 --- /dev/null +++ b/charts/fission-all/templates/svc.yaml @@ -0,0 +1,66 @@ +apiVersion: v1 +kind: Service +metadata: + name: router + labels: + svc: router + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + type: {{ .Values.serviceType }} + ports: + - port: 80 + targetPort: 8888 + nodePort: {{ .Values.routerPort }} + selector: + svc: router + +--- +apiVersion: v1 +kind: Service +metadata: + name: controller + labels: + svc: controller + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + type: {{ .Values.serviceType }} + ports: + - port: 80 + targetPort: 8888 + nodePort: {{ .Values.controllerPort }} + selector: + svc: controller + +--- +apiVersion: v1 +kind: Service +metadata: + name: fission-ui + labels: + svc: fission-ui + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + type: {{ .Values.serviceType }} + ports: + - port: 80 + targetPort: 80 + nodePort: 31319 + selector: + svc: fission-ui + +--- +apiVersion: v1 +kind: Service +metadata: + name: nats-streaming + labels: + svc: nats-streaming + chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +spec: + type: {{ .Values.serviceType }} + ports: + - port: 4222 + targetPort: 4222 + nodePort: 31316 + selector: + svc: nats-streaming \ No newline at end of file diff --git a/charts/fission-all/values.yaml b/charts/fission-all/values.yaml new file mode 100644 index 00000000..c93cf1df --- /dev/null +++ b/charts/fission-all/values.yaml @@ -0,0 +1,40 @@ +# +# Fission chart configuration +# + +## Kubernetes configuration +## For minikube, set this to NodePort, elsewhere use LoadBalancer. +serviceType: LoadBalancer + +## Fission image repostiroy +image: fission/fission-bundle + +## Fission image version +imageTag: nightly20170705 + +## Port at which Fission controller service should be exposed +controllerPort: 31313 + +## Port at which Fission router service should be exposed +routerPort: 31314 + +## Namespace in which to run fission functions (this is different from +## the release namespace) +functionNamespace: fission-function + +## Set up openshift RBAC rule +openshift: false + +## Logger config +logger: + influxdbAdmin: "admin" + fluentdImage: fission/fluentd + +## Fission ui config +fissionUiImage: fission/fission-ui:0.1.0 + +## Message queue trigger config +### NATS Streaming +nats: + authToken: "defaultFissionAuthToken" + clusterID: "fissionMQTrigger" \ No newline at end of file diff --git a/charts/fission-core/.helmignore b/charts/fission-core/.helmignore new file mode 100644 index 00000000..f0c13194 --- /dev/null +++ b/charts/fission-core/.helmignore @@ -0,0 +1,21 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj diff --git a/charts/fission-core/Chart.yaml b/charts/fission-core/Chart.yaml new file mode 100644 index 00000000..f66aa4c4 --- /dev/null +++ b/charts/fission-core/Chart.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +name: fission-core +version: 0.1.0 +description: Fission is a fast serverless framework for Kubernetes. +keywords: +- fission +- serverless +home: http://fission.io/ +maintainers: + - name: Sanket Sudake + email: sanketsudake@gmail.com + - name: Soam Vasani + email: soamvasani@platform9.com + - name: Ta Ching Chen + email: contact@tachingchen.com +engine: gotpl diff --git a/charts/fission-core/LICENSE b/charts/fission-core/LICENSE new file mode 100644 index 00000000..d6456956 --- /dev/null +++ b/charts/fission-core/LICENSE @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/charts/fission-core/templates/NOTES.txt b/charts/fission-core/templates/NOTES.txt new file mode 100644 index 00000000..06ac3610 --- /dev/null +++ b/charts/fission-core/templates/NOTES.txt @@ -0,0 +1,40 @@ +1. Install the client CLI. + +Mac: + $ curl -Lo fission https://github.com/fission/fission/releases/download/nightly20170705/fission-cli-osx && chmod +x fission && sudo mv fission /usr/local/bin/ + +Linux: + $ curl -Lo fission https://github.com/fission/fission/releases/download/nightly20170705/fission-cli-linux && chmod +x fission && sudo mv fission /usr/local/bin/ + +Windows: + For Windows, you can use the linux binary on WSL. Or you can download this windows executable: https://github.com/fission/fission/releases/download/nightly20170705/fission-cli-windows.exe + +2. Set the FISSION_URL and FISSION_ROUTER environment variables. +FISSION_URL is used by the fission CLI to find the server. +FISSION_URL should be prefixed with a http://. (FISSION_ROUTER is only needed for the examples below to work.) + +{{- if contains "NodePort" .Values.serviceType }} + $ export FISSION_URL=http://$(minikube ip):{{ .Values.controllerPort }} + $ export FISSION_ROUTER=$(minikube ip):{{ .Values.routerPort }} + +{{- else if contains "LoadBalancer" .Values.serviceType }} + NOTE: It may take a few minutes for the LoadBalancer IP to be available. + You can watch the status of by running 'kubectl --namespace fission get -w svc' and 'kubectl --namespace fission get svc -w router' + + $ export FISSION_URL=http://$(kubectl --namespace fission get svc controller -o=jsonpath='{..ip}') + $ export FISSION_ROUTER=$(kubectl --namespace fission get svc router -o=jsonpath='{..ip}') + +{{- end }} + +3. Finally, you're ready to use Fission! + + $ fission env create --name nodejs --image fission/node-env + + $ curl https://raw.githubusercontent.com/fission/fission/master/examples/nodejs/hello.js > hello.js + + $ fission function create --name hello --env nodejs --code hello.js + + $ fission route create --method GET --url /hello --function hello + + $ curl http://$FISSION_ROUTER/hello + Hello, world! diff --git a/charts/fission-core/templates/_helpers.tpl b/charts/fission-core/templates/_helpers.tpl new file mode 100644 index 00000000..f7877c32 --- /dev/null +++ b/charts/fission-core/templates/_helpers.tpl @@ -0,0 +1,16 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 24 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 24 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +*/}} +{{- define "fullname" -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- printf "%s-%s" .Release.Name $name | trunc 24 | trimSuffix "-" -}} +{{- end -}} diff --git a/charts/fission/templates/deployment.yaml b/charts/fission-core/templates/deployment.yaml similarity index 60% rename from charts/fission/templates/deployment.yaml rename to charts/fission-core/templates/deployment.yaml index bc21ba04..740934e8 100644 --- a/charts/fission/templates/deployment.yaml +++ b/charts/fission-core/templates/deployment.yaml @@ -1,3 +1,77 @@ +{{ if .Values.openshift }} + +# For openshift + +--- +apiVersion: v1 +kind: ProjectRequest +metadata: + name: fission + labels: + name: fission + +--- +apiVersion: v1 +kind: ProjectRequest +metadata: + name: fission-function + labels: + name: fission-function + +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: fission-admin + namespace: fission + +--- +apiVersion: v1 +kind: ClusterRole +metadata: + name: fission:fission-admin +rules: +- apiGroups: + - extensions + attributeRestrictions: null + resources: + - deployments + verbs: + - create + - get + - list + - update + - watch +- apiGroups: + - "" + attributeRestrictions: null + resources: + - pods + verbs: + - get + - list + - update + +--- +apiVersion: v1 +groupNames: null +kind: RoleBinding +metadata: + name: fission:fission-admin + namespace: fission-function +roleRef: + name: fission:fission-admin +subjects: +- kind: ServiceAccount + name: fission-admin + namespace: fission +userNames: +- system:serviceaccount:fission:fission-admin + +{{ else }} + +# For all environments except openshift + --- apiVersion: v1 kind: Namespace @@ -7,6 +81,45 @@ metadata: name: fission-function chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: fission-admin + namespace: fission + +--- +kind: RoleBinding +apiVersion: rbac.authorization.k8s.io/v1beta1 +metadata: + name: fission-admin + namespace: fission +subjects: + - kind: ServiceAccount + name: fission-admin + namespace: fission +roleRef: + kind: ClusterRole + name: admin + apiGroup: rbac.authorization.k8s.io + +--- +kind: RoleBinding +apiVersion: rbac.authorization.k8s.io/v1beta1 +metadata: + name: fission-function-admin + namespace: fission-function +subjects: + - kind: ServiceAccount + name: fission-admin + namespace: fission +roleRef: + kind: ClusterRole + name: admin + apiGroup: rbac.authorization.k8s.io + +{{ end }} + --- apiVersion: extensions/v1beta1 kind: Deployment @@ -56,6 +169,7 @@ metadata: svc: poolmgr chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" spec: + type: ClusterIP ports: - port: 80 targetPort: 8888 @@ -81,6 +195,7 @@ spec: image: "{{ .Values.image }}:{{ .Values.imageTag }}" command: ["/fission-bundle"] args: ["--poolmgrPort", "8888", "--namespace", "{{ .Values.functionNamespace }}"] + serviceAccount: fission-admin --- apiVersion: extensions/v1beta1 @@ -101,6 +216,7 @@ spec: image: "{{ .Values.image }}:{{ .Values.imageTag }}" command: ["/fission-bundle"] args: ["--kubewatcher"] + serviceAccount: fission-admin --- apiVersion: v1 @@ -111,6 +227,7 @@ metadata: svc: etcd chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" spec: + type: ClusterIP ports: - port: 2379 targetPort: 2379 diff --git a/charts/fission/templates/svc.yaml b/charts/fission-core/templates/svc.yaml similarity index 96% rename from charts/fission/templates/svc.yaml rename to charts/fission-core/templates/svc.yaml index a6a6cb58..70f16f0c 100644 --- a/charts/fission/templates/svc.yaml +++ b/charts/fission-core/templates/svc.yaml @@ -29,4 +29,4 @@ spec: targetPort: 8888 nodePort: {{ .Values.controllerPort }} selector: - svc: controller + svc: controller \ No newline at end of file diff --git a/charts/fission/values.yaml b/charts/fission-core/values.yaml similarity index 92% rename from charts/fission/values.yaml rename to charts/fission-core/values.yaml index b645cdf0..ab8d8948 100644 --- a/charts/fission/values.yaml +++ b/charts/fission-core/values.yaml @@ -21,3 +21,6 @@ routerPort: 31314 ## Namespace in which to run fission functions (this is different from ## the release namespace) functionNamespace: fission-function + +## Set up openshift RBAC rule +openshift: false \ No newline at end of file diff --git a/charts/fission/Chart.yaml b/charts/fission/Chart.yaml deleted file mode 100644 index 7522a6ab..00000000 --- a/charts/fission/Chart.yaml +++ /dev/null @@ -1,12 +0,0 @@ -apiVersion: v1 -name: fission -version: 0.1.0 -description: A Helm chart for Fission. Fission is a fast serverless framework for Kubernetes. -keywords: -- fission -- serverless -home: http://fission.io/ -maintainers: - - name: Sanket Sudake - email: sanketsudake@gmail.com -engine: gotpl