Allow to set log level through environment variable (#1217)
This commit is contained in:
@@ -133,14 +133,16 @@ spec:
|
|||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--controllerPort", "8888", "--collectorEndpoint", "{{ .Values.traceCollectorEndpoint }}"]
|
args: ["--controllerPort", "8888", "--collectorEndpoint", "{{ .Values.traceCollectorEndpoint }}"]
|
||||||
env:
|
env:
|
||||||
- name: FISSION_FUNCTION_NAMESPACE
|
- name: FISSION_FUNCTION_NAMESPACE
|
||||||
value: "{{ .Values.functionNamespace }}"
|
value: "{{ .Values.functionNamespace }}"
|
||||||
- name: TRACING_SAMPLING_RATE
|
- name: TRACING_SAMPLING_RATE
|
||||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||||
- name: POD_NAMESPACE
|
- name: DEBUG_ENV
|
||||||
valueFrom:
|
value: {{ .Values.debugEnv | quote }}
|
||||||
fieldRef:
|
- name: POD_NAMESPACE
|
||||||
fieldPath: metadata.namespace
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.namespace
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
path: "/healthz"
|
path: "/healthz"
|
||||||
@@ -158,6 +160,9 @@ spec:
|
|||||||
- name: config-volume
|
- name: config-volume
|
||||||
mountPath: /etc/config/config.yaml
|
mountPath: /etc/config/config.yaml
|
||||||
subPath: config.yaml
|
subPath: config.yaml
|
||||||
|
ports:
|
||||||
|
- containerPort: 8888
|
||||||
|
name: http
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
volumes:
|
volumes:
|
||||||
- name: config-volume
|
- name: config-volume
|
||||||
@@ -192,32 +197,32 @@ spec:
|
|||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--routerPort", "8888", "--executorUrl", "http://executor.{{ .Release.Namespace }}", "--collectorEndpoint", "{{ .Values.traceCollectorEndpoint }}"]
|
args: ["--routerPort", "8888", "--executorUrl", "http://executor.{{ .Release.Namespace }}", "--collectorEndpoint", "{{ .Values.traceCollectorEndpoint }}"]
|
||||||
env:
|
env:
|
||||||
- name: POD_NAMESPACE
|
- name: POD_NAMESPACE
|
||||||
valueFrom:
|
valueFrom:
|
||||||
fieldRef:
|
fieldRef:
|
||||||
fieldPath: metadata.namespace
|
fieldPath: metadata.namespace
|
||||||
- name: ROUTER_ROUND_TRIP_TIMEOUT
|
- name: ROUTER_ROUND_TRIP_TIMEOUT
|
||||||
value: {{ .Values.routerRoundTripTimeout | default "50ms" | quote }}
|
value: {{ .Values.routerRoundTripTimeout | default "50ms" | quote }}
|
||||||
- name: ROUTER_ROUNDTRIP_TIMEOUT_EXPONENT
|
- name: ROUTER_ROUNDTRIP_TIMEOUT_EXPONENT
|
||||||
value: {{ .Values.routerRoundTripTimeoutExponent | default 2 | quote }}
|
value: {{ .Values.routerRoundTripTimeoutExponent | default 2 | quote }}
|
||||||
- name: ROUTER_ROUND_TRIP_KEEP_ALIVE_TIME
|
- name: ROUTER_ROUND_TRIP_KEEP_ALIVE_TIME
|
||||||
value: {{ .Values.routerRoundTripKeepAliveTime | default "30s" | quote }}
|
value: {{ .Values.routerRoundTripKeepAliveTime | default "30s" | quote }}
|
||||||
- name: ROUTER_ROUND_TRIP_MAX_RETRIES
|
- name: ROUTER_ROUND_TRIP_MAX_RETRIES
|
||||||
value: {{ .Values.routerRoundTripMaxRetries | default 10 | quote }}
|
value: {{ .Values.routerRoundTripMaxRetries | default 10 | quote }}
|
||||||
- name: ROUTER_ROUND_TRIP_SVC_ADDRESS_MAX_RETRIES
|
- name: ROUTER_ROUND_TRIP_SVC_ADDRESS_MAX_RETRIES
|
||||||
value: {{ .Values.routerRoundTripSvcAddressMaxRetries | default 5 | quote }}
|
value: {{ .Values.routerRoundTripSvcAddressMaxRetries | default 5 | quote }}
|
||||||
- name: ROUTER_ROUND_TRIP_SVC_ADDRESS_UPDATE_TIMEOUT
|
- name: ROUTER_ROUND_TRIP_SVC_ADDRESS_UPDATE_TIMEOUT
|
||||||
value: {{ .Values.routerRoundTripSvcAddressUpdateTimeout | default 30 | quote }}
|
value: {{ .Values.routerRoundTripSvcAddressUpdateTimeout | default 30 | quote }}
|
||||||
- name: DEBUG_ENV
|
- name: DEBUG_ENV
|
||||||
value: {{ .Values.debugEnv | quote }}
|
value: {{ .Values.debugEnv | quote }}
|
||||||
- name: TRACING_SAMPLING_RATE
|
- name: TRACING_SAMPLING_RATE
|
||||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||||
{{ if .Values.analytics }}
|
{{ if .Values.analytics }}
|
||||||
- name: ANALYTICS_URL
|
- name: ANALYTICS_URL
|
||||||
value: "https://g.fission.sh/metrics"
|
value: "https://g.fission.sh/metrics"
|
||||||
{{ else if .Values.analyticsNonHelmInstall }}
|
{{ else if .Values.analyticsNonHelmInstall }}
|
||||||
- name: ANALYTICS_URL
|
- name: ANALYTICS_URL
|
||||||
value: "https://g.fission.sh/metrics"
|
value: "https://g.fission.sh/metrics"
|
||||||
{{ end }}
|
{{ end }}
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
@@ -303,6 +308,8 @@ spec:
|
|||||||
value: {{ .Values.fetcherMaxMem | default "128Mi" | quote }}
|
value: {{ .Values.fetcherMaxMem | default "128Mi" | quote }}
|
||||||
- name: TRACING_SAMPLING_RATE
|
- name: TRACING_SAMPLING_RATE
|
||||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
path: "/healthz"
|
path: "/healthz"
|
||||||
@@ -367,6 +374,8 @@ spec:
|
|||||||
value: {{ .Values.fetcherMaxCpu | default "1000m" | quote }}
|
value: {{ .Values.fetcherMaxCpu | default "1000m" | quote }}
|
||||||
- name: FETCHER_MAXMEM
|
- name: FETCHER_MAXMEM
|
||||||
value: {{ .Values.fetcherMaxMem | default "128Mi" | quote }}
|
value: {{ .Values.fetcherMaxMem | default "128Mi" | quote }}
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -395,6 +404,8 @@ spec:
|
|||||||
env:
|
env:
|
||||||
- name: TRACING_SAMPLING_RATE
|
- name: TRACING_SAMPLING_RATE
|
||||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -435,18 +446,18 @@ spec:
|
|||||||
image: fission/influxdb
|
image: fission/influxdb
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
env:
|
env:
|
||||||
- name: PRE_CREATE_DB
|
- name: PRE_CREATE_DB
|
||||||
value: fissionFunctionLog
|
value: fissionFunctionLog
|
||||||
- name: ADMIN_USER
|
- name: ADMIN_USER
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: influxdb
|
name: influxdb
|
||||||
key: username
|
key: username
|
||||||
- name: INFLUXDB_INIT_PWD
|
- name: INFLUXDB_INIT_PWD
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: influxdb
|
name: influxdb
|
||||||
key: password
|
key: password
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -514,6 +525,9 @@ spec:
|
|||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--timer", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
args: ["--timer", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||||
|
env:
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -623,6 +637,8 @@ spec:
|
|||||||
value: nats://{{ .Values.nats.authToken }}@nats-streaming:4222
|
value: nats://{{ .Values.nats.authToken }}@nats-streaming:4222
|
||||||
- name: TRACING_SAMPLING_RATE
|
- name: TRACING_SAMPLING_RATE
|
||||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -660,6 +676,8 @@ spec:
|
|||||||
value: "{{.Values.kafka.version}}"
|
value: "{{.Values.kafka.version}}"
|
||||||
- name: TRACING_SAMPLING_RATE
|
- name: TRACING_SAMPLING_RATE
|
||||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -700,6 +718,8 @@ spec:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: azure-storage-account-key
|
name: azure-storage-account-key
|
||||||
key: key
|
key: key
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -731,6 +751,8 @@ spec:
|
|||||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||||
- name: PRUNE_INTERVAL
|
- name: PRUNE_INTERVAL
|
||||||
value: "{{.Values.pruneInterval}}"
|
value: "{{.Values.pruneInterval}}"
|
||||||
|
- name: DEBUG_ENV
|
||||||
|
value: {{ .Values.debugEnv | quote }}
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: fission-storage
|
- name: fission-storage
|
||||||
mountPath: /fission
|
mountPath: /fission
|
||||||
@@ -747,6 +769,9 @@ spec:
|
|||||||
port: 8000
|
port: 8000
|
||||||
initialDelaySeconds: 35
|
initialDelaySeconds: 35
|
||||||
periodSeconds: 5
|
periodSeconds: 5
|
||||||
|
ports:
|
||||||
|
- containerPort: 8000
|
||||||
|
name: http
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
volumes:
|
volumes:
|
||||||
- name: fission-storage
|
- name: fission-storage
|
||||||
|
|||||||
@@ -144,7 +144,7 @@ preUpgradeChecksImage: fission/pre-upgrade-checks
|
|||||||
|
|
||||||
## if there are any pod specialization errors when a function is triggered and this flag is set to true, the error
|
## if there are any pod specialization errors when a function is triggered and this flag is set to true, the error
|
||||||
## summary is returned as part of http response
|
## summary is returned as part of http response
|
||||||
debugEnv: true
|
debugEnv: false
|
||||||
|
|
||||||
|
|
||||||
## set this flag to true if prometheus needs to be deployed along with fission
|
## set this flag to true if prometheus needs to be deployed along with fission
|
||||||
|
|||||||
@@ -159,6 +159,9 @@ spec:
|
|||||||
- name: config-volume
|
- name: config-volume
|
||||||
mountPath: /etc/config/config.yaml
|
mountPath: /etc/config/config.yaml
|
||||||
subPath: config.yaml
|
subPath: config.yaml
|
||||||
|
ports:
|
||||||
|
- containerPort: 8888
|
||||||
|
name: http
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
volumes:
|
volumes:
|
||||||
- name: config-volume
|
- name: config-volume
|
||||||
@@ -234,6 +237,11 @@ spec:
|
|||||||
port: 8888
|
port: 8888
|
||||||
initialDelaySeconds: 35
|
initialDelaySeconds: 35
|
||||||
periodSeconds: 5
|
periodSeconds: 5
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
name: metrics
|
||||||
|
- containerPort: 8888
|
||||||
|
name: http
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -311,6 +319,11 @@ spec:
|
|||||||
port: 8888
|
port: 8888
|
||||||
initialDelaySeconds: 35
|
initialDelaySeconds: 35
|
||||||
periodSeconds: 5
|
periodSeconds: 5
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
name: metrics
|
||||||
|
- containerPort: 8888
|
||||||
|
name: http
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
{{- if .Values.extraCoreComponmentPodConfig }}
|
{{- if .Values.extraCoreComponmentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponmentPodConfig | indent 6 -}}
|
||||||
@@ -447,6 +460,9 @@ spec:
|
|||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: fission-storage
|
- name: fission-storage
|
||||||
mountPath: /fission
|
mountPath: /fission
|
||||||
|
ports:
|
||||||
|
- containerPort: 8000
|
||||||
|
name: http
|
||||||
serviceAccount: fission-svc
|
serviceAccount: fission-svc
|
||||||
volumes:
|
volumes:
|
||||||
- name: fission-storage
|
- name: fission-storage
|
||||||
|
|||||||
@@ -103,7 +103,7 @@ preUpgradeChecksImage: fission/pre-upgrade-checks
|
|||||||
|
|
||||||
## if there are any pod specialization errors when a function is triggered and this flag is set to true, the error
|
## if there are any pod specialization errors when a function is triggered and this flag is set to true, the error
|
||||||
## summary is returned as part of http response
|
## summary is returned as part of http response
|
||||||
debugEnv: true
|
debugEnv: false
|
||||||
|
|
||||||
## set this flag to true if prometheus needs to be deployed along with fission
|
## set this flag to true if prometheus needs to be deployed along with fission
|
||||||
prometheusDeploy: false
|
prometheusDeploy: false
|
||||||
|
|||||||
@@ -208,7 +208,16 @@ Options:
|
|||||||
--builderMgr Start builder manager.
|
--builderMgr Start builder manager.
|
||||||
--version Print version information
|
--version Print version information
|
||||||
`
|
`
|
||||||
logger, err := zap.NewProduction()
|
|
||||||
|
var logger *zap.Logger
|
||||||
|
var err error
|
||||||
|
|
||||||
|
isDebugEnv, _ := strconv.ParseBool(os.Getenv("DEBUG_ENV"))
|
||||||
|
if isDebugEnv {
|
||||||
|
logger, err = zap.NewDevelopment()
|
||||||
|
} else {
|
||||||
|
logger, err = zap.NewProduction()
|
||||||
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Fatalf("can't initialize zap logger: %v", err)
|
log.Fatalf("can't initialize zap logger: %v", err)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -138,7 +138,7 @@ func AddSaToRoleBindingWithRetries(logger *zap.Logger, k8sClient *kubernetes.Cli
|
|||||||
rbObj := makeRoleBindingObj(roleBinding, roleBindingNs, role, roleKind, sa, saNamespace)
|
rbObj := makeRoleBindingObj(roleBinding, roleBindingNs, role, roleKind, sa, saNamespace)
|
||||||
rbObj, err = k8sClient.RbacV1beta1().RoleBindings(roleBindingNs).Create(rbObj)
|
rbObj, err = k8sClient.RbacV1beta1().RoleBindings(roleBindingNs).Create(rbObj)
|
||||||
if err == nil {
|
if err == nil {
|
||||||
logger.Info("created rolebinding",
|
logger.Debug("created rolebinding",
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
zap.String("role_binding_namespace", roleBindingNs))
|
zap.String("role_binding_namespace", roleBindingNs))
|
||||||
return err
|
return err
|
||||||
@@ -181,7 +181,7 @@ func RemoveSAFromRoleBindingWithRetries(logger *zap.Logger, k8sClient *kubernete
|
|||||||
roleBinding, metav1.GetOptions{})
|
roleBinding, metav1.GetOptions{})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// silently ignoring the error. there's no need for us to remove sa anymore.
|
// silently ignoring the error. there's no need for us to remove sa anymore.
|
||||||
logger.Info("rolebinding not found, but ignoring the error since we're cleaning up",
|
logger.Debug("rolebinding not found, but ignoring the error since we're cleaning up",
|
||||||
zap.Error(err),
|
zap.Error(err),
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
zap.String("role_binding_namespace", roleBindingNs))
|
zap.String("role_binding_namespace", roleBindingNs))
|
||||||
@@ -213,13 +213,13 @@ func RemoveSAFromRoleBindingWithRetries(logger *zap.Logger, k8sClient *kubernete
|
|||||||
_, err = k8sClient.RbacV1beta1().RoleBindings(rbObj.Namespace).Update(rbObj)
|
_, err = k8sClient.RbacV1beta1().RoleBindings(rbObj.Namespace).Update(rbObj)
|
||||||
switch {
|
switch {
|
||||||
case err == nil:
|
case err == nil:
|
||||||
logger.Info("removed service accounts from rolebinding",
|
logger.Debug("removed service accounts from rolebinding",
|
||||||
zap.Any("service_accounts", saToRemove),
|
zap.Any("service_accounts", saToRemove),
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
zap.String("role_binding_namespace", roleBindingNs))
|
zap.String("role_binding_namespace", roleBindingNs))
|
||||||
return nil
|
return nil
|
||||||
case k8serrors.IsConflict(err):
|
case k8serrors.IsConflict(err):
|
||||||
logger.Info("conflict in update of rolebinding - retrying",
|
logger.Error("conflict in update of rolebinding - retrying",
|
||||||
zap.Error(err),
|
zap.Error(err),
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
zap.String("role_binding_namespace", roleBindingNs))
|
zap.String("role_binding_namespace", roleBindingNs))
|
||||||
@@ -241,14 +241,14 @@ func SetupRoleBinding(logger *zap.Logger, k8sClient *kubernetes.Clientset, roleB
|
|||||||
|
|
||||||
if err == nil {
|
if err == nil {
|
||||||
if !isSAInRoleBinding(rbObj, sa, saNamespace) {
|
if !isSAInRoleBinding(rbObj, sa, saNamespace) {
|
||||||
logger.Info("service account is not present in the rolebinding - will add",
|
logger.Debug("service account is not present in the rolebinding - will add",
|
||||||
zap.String("service_account_name", sa),
|
zap.String("service_account_name", sa),
|
||||||
zap.String("service_account_namespace", saNamespace),
|
zap.String("service_account_namespace", saNamespace),
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
zap.String("role_binding_namespace", roleBindingNs))
|
zap.String("role_binding_namespace", roleBindingNs))
|
||||||
return AddSaToRoleBindingWithRetries(logger, k8sClient, roleBinding, roleBindingNs, sa, saNamespace, role, roleKind)
|
return AddSaToRoleBindingWithRetries(logger, k8sClient, roleBinding, roleBindingNs, sa, saNamespace, role, roleKind)
|
||||||
}
|
}
|
||||||
logger.Info("service account already present in rolebinding so nothing to add",
|
logger.Debug("service account already present in rolebinding so nothing to add",
|
||||||
zap.String("service_account_name", sa),
|
zap.String("service_account_name", sa),
|
||||||
zap.String("service_account_namespace", saNamespace),
|
zap.String("service_account_namespace", saNamespace),
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
@@ -258,14 +258,14 @@ func SetupRoleBinding(logger *zap.Logger, k8sClient *kubernetes.Clientset, roleB
|
|||||||
|
|
||||||
// if role binding is missing, create it. also add this sa to the binding.
|
// if role binding is missing, create it. also add this sa to the binding.
|
||||||
if k8serrors.IsNotFound(err) {
|
if k8serrors.IsNotFound(err) {
|
||||||
logger.Info("rolebinding does NOT exist in namespace - creating it",
|
logger.Debug("rolebinding does NOT exist in namespace - creating it",
|
||||||
zap.Error(err),
|
zap.Error(err),
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
zap.String("role_binding_namespace", roleBindingNs))
|
zap.String("role_binding_namespace", roleBindingNs))
|
||||||
rbObj = makeRoleBindingObj(roleBinding, roleBindingNs, role, roleKind, sa, saNamespace)
|
rbObj = makeRoleBindingObj(roleBinding, roleBindingNs, role, roleKind, sa, saNamespace)
|
||||||
rbObj, err = k8sClient.RbacV1beta1().RoleBindings(roleBindingNs).Create(rbObj)
|
rbObj, err = k8sClient.RbacV1beta1().RoleBindings(roleBindingNs).Create(rbObj)
|
||||||
if k8serrors.IsAlreadyExists(err) {
|
if k8serrors.IsAlreadyExists(err) {
|
||||||
logger.Info("rolebinding already exists in namespace - adding service account to rolebinding",
|
logger.Debug("rolebinding already exists in namespace - adding service account to rolebinding",
|
||||||
zap.String("service_account_name", sa),
|
zap.String("service_account_name", sa),
|
||||||
zap.String("service_account_namespace", saNamespace),
|
zap.String("service_account_namespace", saNamespace),
|
||||||
zap.String("role_binding", roleBinding),
|
zap.String("role_binding", roleBinding),
|
||||||
|
|||||||
+1
-1
@@ -177,7 +177,7 @@ helm_install_fission() {
|
|||||||
ns=f-$id
|
ns=f-$id
|
||||||
fns=f-func-$id
|
fns=f-func-$id
|
||||||
|
|
||||||
helmVars=repository=$repo,image=$image,imageTag=$imageTag,fetcherImage=$fetcherImage,fetcherImageTag=$fetcherImageTag,functionNamespace=$fns,controllerPort=$controllerNodeport,routerPort=$routerNodeport,pullPolicy=Always,analytics=false,pruneInterval=$pruneInterval,routerServiceType=$routerServiceType,serviceType=$serviceType,preUpgradeChecksImage=$preUpgradeCheckImage,prometheus.server.persistentVolume.enabled=false,prometheus.alertmanager.enabled=false,prometheus.kubeStateMetrics.enabled=false,prometheus.nodeExporter.enabled=false
|
helmVars=repository=$repo,image=$image,imageTag=$imageTag,fetcherImage=$fetcherImage,fetcherImageTag=$fetcherImageTag,functionNamespace=$fns,controllerPort=$controllerNodeport,routerPort=$routerNodeport,pullPolicy=Always,analytics=false,debugEnv=true,pruneInterval=$pruneInterval,routerServiceType=$routerServiceType,serviceType=$serviceType,preUpgradeChecksImage=$preUpgradeCheckImage,prometheus.server.persistentVolume.enabled=false,prometheus.alertmanager.enabled=false,prometheus.kubeStateMetrics.enabled=false,prometheus.nodeExporter.enabled=false
|
||||||
|
|
||||||
timeout 30 bash -c "helm_setup"
|
timeout 30 bash -c "helm_setup"
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user