Run canary config server separate from controller (#2617)

* add canary config server
* remove the canary config code from the controller
* remove port exposure for canary config
This commit is contained in:
neha_gupta
2022-11-15 13:08:42 +05:30
committed by GitHub
parent 9a07d7d96b
commit 3b2a86a8c9
14 changed files with 308 additions and 13 deletions
@@ -169,4 +169,17 @@ rules:
- update
- patch
- delete
{{- end }}
{{- define "canaryconfig-rules" }}
rules:
- apiGroups:
- fission.io
resources:
- canaryconfigs
- httptriggers
verbs:
- list
- watch
- get
- update
{{- end }}
@@ -41,6 +41,10 @@ metadata:
{{- if eq "timer" .component }}
{{- include "timer-rules" . }}
{{- end }}
{{- if eq "canaryconfig" .component }}
{{- include "canaryconfig-rules" . }}
{{- end }}
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
@@ -0,0 +1,43 @@
{{- if .Values.canaryDeployment.enabled }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ .Release.Name }}-canaryconfig
rules:
- apiGroups:
- ""
resources:
- services
verbs:
- list
- apiGroups:
- ""
resources:
- configmaps
- secrets
verbs:
- get
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- create
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
- apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- watch
{{- end }}
@@ -0,0 +1,14 @@
{{- if .Values.canaryDeployment.enabled }}
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: {{ .Release.Name }}-canaryconfig
subjects:
- kind: ServiceAccount
name: fission-canaryconfig
namespace: {{ .Release.Namespace }}
roleRef:
kind: ClusterRole
name: {{ .Release.Name }}-canaryconfig
apiGroup: rbac.authorization.k8s.io
{{- end -}}
@@ -0,0 +1,81 @@
{{- if .Values.canaryDeployment.enabled }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: canaryconfig
labels:
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
svc: canaryconfig
application: fission-canaryconfig
spec:
replicas: 1
selector:
matchLabels:
svc: canaryconfig
application: fission-canaryconfig
template:
metadata:
labels:
svc: canaryconfig
application: fission-canaryconfig
annotations:
prometheus.io/scrape: "true"
prometheus.io/path: "/metrics"
prometheus.io/port: "8080"
spec:
{{- if .Values.canaryDeployment.securityContext.enabled }}
securityContext: {{- omit .Values.canaryDeployment.securityContext "enabled" | toYaml | nindent 8 }}
{{- end }}
containers:
- name: canaryconfig
image: {{ include "fission-bundleImage" . | quote }}
imagePullPolicy: {{ .Values.pullPolicy }}
command: ["/fission-bundle"]
args: ["--canaryConfig"]
env:
- name: DEBUG_ENV
value: {{ .Values.debugEnv | quote }}
- name: PPROF_ENABLED
value: {{ .Values.pprof.enabled | quote }}
{{- include "fission-resource-namespace.envs" . | indent 8 }}
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
{{- include "opentelemtry.envs" . | indent 8 }}
resources:
{{- toYaml .Values.canaryDeployment.resources | nindent 10 }}
{{- if .Values.terminationMessagePath }}
terminationMessagePath: {{ .Values.terminationMessagePath }}
{{- end }}
{{- if .Values.terminationMessagePolicy }}
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
{{- end }}
volumeMounts:
- name: config-volume
mountPath: /etc/config/config.yaml
subPath: config.yaml
ports:
- containerPort: 8080
name: metrics
{{- if .Values.pprof.enabled }}
- containerPort: 6060
name: pprof
{{- end }}
serviceAccountName: fission-canaryconfig
volumes:
- name: config-volume
configMap:
name: feature-config
{{- if .Values.priorityClassName }}
priorityClassName: {{ .Values.priorityClassName }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if .Values.extraCoreComponentPodConfig }}
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
{{- end }}
{{- end -}}
@@ -0,0 +1,9 @@
{{- if .Values.canaryDeployment.enabled }}
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "canaryconfig") .) }}
{{- if not .Values.singleDefaultNamespace }}
{{- range $namespace := $.Values.additionalFissionNamespaces }}
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "canaryconfig") $) }}
{{- end }}
{{- end }}
{{- end -}}
@@ -0,0 +1,7 @@
{{- if .Values.canaryDeployment.enabled }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: fission-canaryconfig
namespace: {{ .Release.Namespace }}
{{- end -}}
@@ -0,0 +1,24 @@
{{- if .Values.canaryDeployment.enabled }}
{{- if .Values.serviceMonitor.enabled }}
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
name: canaryconfig-monitor
{{- if .Values.serviceMonitor.namespace }}
namespace: {{ .Values.serviceMonitor.namespace }}
{{- end }}
{{- with .Values.serviceMonitor.additionalServiceMonitorLabels }}
labels:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
namespaceSelector:
matchNames:
- {{ .Release.Namespace }}
selector:
matchLabels:
svc: canaryconfig
endpoints:
- targetPort: 8080
{{- end -}}
{{- end -}}
+26 -3
View File
@@ -359,7 +359,7 @@ controller:
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
runAsGroup: 10001
## webhook is the component that validates API calls.
## It contains validation and mutation for functions, triggers, environments, Kubernetes event watches, etc.
@@ -701,11 +701,34 @@ prometheus:
##
serviceEndpoint: ""
## set this flag to true if you need canary deployment feature
##
canaryDeployment:
## set this flag to true if you need canary deployment feature
enabled: false
## Pod resources as:
## resources:
## limits:
## cpu: <tbd>
## memory: <tbd>
## requests:
## cpu: <tbd>
## memory: <tbd>
##
resources: {}
## Security Context
## It holds pod-level and container level security configuration.
## This is an experimental section, please verify before enabling in production.
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
securityContext:
enabled: false
## Mark it false, if you want to stop the non root user validation
runAsNonRoot: true
fsGroup: 10001
runAsUser: 10001
runAsGroup: 10001
## Enable authentication for fission function invocation via Fission router
##
authentication: