Compare commits
642
Commits
1.7.0-rc.1
...
v1.20.0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9b57f1f2e7 | ||
|
|
1fe13624f2 | ||
|
|
fdecc98775 | ||
|
|
10852c90a5 | ||
|
|
62f729727a | ||
|
|
95faf60959 | ||
|
|
17fbe42fcc | ||
|
|
f44174debc | ||
|
|
efeb6951dc | ||
|
|
b85ba9e419 | ||
|
|
d23ed572f9 | ||
|
|
e7d6381876 | ||
|
|
57b537f09e | ||
|
|
2e4825def0 | ||
|
|
3fabf64b3c | ||
|
|
2a40b4538c | ||
|
|
27132975c4 | ||
|
|
b099db38d7 | ||
|
|
88039cad63 | ||
|
|
267f7faf18 | ||
|
|
2223081c80 | ||
|
|
2eb2eba88c | ||
|
|
8a17d391c5 | ||
|
|
15e16fcc82 | ||
|
|
7137b39a14 | ||
|
|
fc97b7609b | ||
|
|
c6329ee3db | ||
|
|
7b21fbc199 | ||
|
|
703d757c29 | ||
|
|
c09319ceb3 | ||
|
|
3762ff80f2 | ||
|
|
b43b31884a | ||
|
|
56b49dcee8 | ||
|
|
657aee7cc2 | ||
|
|
44922bce6c | ||
|
|
3bcda55aa8 | ||
|
|
997493351a | ||
|
|
3d77077bc5 | ||
|
|
f955d1182a | ||
|
|
1cbc0ba9ff | ||
|
|
0936c6a2d7 | ||
|
|
f0ec328d24 | ||
|
|
2b1ac28300 | ||
|
|
0fb2096788 | ||
|
|
6e375629e7 | ||
|
|
1133386ce9 | ||
|
|
f99f10134c | ||
|
|
6c431e4d9b | ||
|
|
31c81e132e | ||
|
|
a5f3402dbc | ||
|
|
784bd82ec7 | ||
|
|
cd742a6d18 | ||
|
|
32530ac474 | ||
|
|
117c383fac | ||
|
|
3a1db58066 | ||
|
|
ce42dbc647 | ||
|
|
3840a90b54 | ||
|
|
77d4745242 | ||
|
|
715ef8267e | ||
|
|
b622f13ab6 | ||
|
|
2213ebc637 | ||
|
|
1f138d03fa | ||
|
|
a8e8cfb72d | ||
|
|
963081e096 | ||
|
|
a96b92f41f | ||
|
|
a93e9b4074 | ||
|
|
0de8923ea8 | ||
|
|
1cb18a78a6 | ||
|
|
4ebdb16623 | ||
|
|
3c0c96e98e | ||
|
|
e462f9ab71 | ||
|
|
d025022042 | ||
|
|
c4ed12d9c5 | ||
|
|
d3a615211f | ||
|
|
2b017f810a | ||
|
|
5c3c55d52f | ||
|
|
5db09a899a | ||
|
|
0edf2640b1 | ||
|
|
deb3523b59 | ||
|
|
0635a6a644 | ||
|
|
a9d55423ae | ||
|
|
496e4e3162 | ||
|
|
6667d7e383 | ||
|
|
922cb34243 | ||
|
|
fcf4fd2e63 | ||
|
|
69470a68d0 | ||
|
|
8df4fd0e7c | ||
|
|
275cfb55a6 | ||
|
|
3e25f474b0 | ||
|
|
d52c60216e | ||
|
|
16cbb87eab | ||
|
|
5fae765323 | ||
|
|
31f4f8c57e | ||
|
|
3ae1742953 | ||
|
|
d16de59e9f | ||
|
|
61d98152f1 | ||
|
|
300739c031 | ||
|
|
94eead8697 | ||
|
|
612206b033 | ||
|
|
985d94b5b8 | ||
|
|
4dde3c9520 | ||
|
|
9ccd2a4128 | ||
|
|
e9fd13b60c | ||
|
|
ee623d31b2 | ||
|
|
9612baecc0 | ||
|
|
691feaa84f | ||
|
|
6bf0c4124a | ||
|
|
9eb7acf061 | ||
|
|
e015d6d61f | ||
|
|
918214c0a9 | ||
|
|
526b5f0beb | ||
|
|
0aec9e139e | ||
|
|
8a3d8a4762 | ||
|
|
38d380924d | ||
|
|
1e0641d5f9 | ||
|
|
f11902e81b | ||
|
|
8db3d0065a | ||
|
|
92453908c6 | ||
|
|
28daccb3aa | ||
|
|
31639774b0 | ||
|
|
82d066b73a | ||
|
|
9c4fc4a306 | ||
|
|
68286fe44e | ||
|
|
d559628f29 | ||
|
|
4cbe6a7061 | ||
|
|
6d117ad43a | ||
|
|
70a0afd624 | ||
|
|
d2f201b721 | ||
|
|
3b2a86a8c9 | ||
|
|
9a07d7d96b | ||
|
|
31dfc3e4d3 | ||
|
|
66897cb9d0 | ||
|
|
57d3a80fc6 | ||
|
|
fa037166e1 | ||
|
|
32bd874ab6 | ||
|
|
b71a36dc1c | ||
|
|
261bf24974 | ||
|
|
6af53807aa | ||
|
|
f37e9e6f89 | ||
|
|
b9fa6ca20a | ||
|
|
c33842c94c | ||
|
|
9ff9a6e075 | ||
|
|
a64fcc3faf | ||
|
|
47cbbef06f | ||
|
|
dbd2153181 | ||
|
|
2bd005c387 | ||
|
|
3a9e5ab65d | ||
|
|
ee790b3e1e | ||
|
|
7eeb3ead66 | ||
|
|
827baea974 | ||
|
|
facd14de90 | ||
|
|
8d65b062f1 | ||
|
|
d933f0ba6c | ||
|
|
f2b790921b | ||
|
|
8fe62b755c | ||
|
|
b9513868ed | ||
|
|
0739aca920 | ||
|
|
18225db2bd | ||
|
|
8008a5420a | ||
|
|
3fa0f4bde3 | ||
|
|
a8a81ef5be | ||
|
|
1102999b4d | ||
|
|
da50c3759d | ||
|
|
e87c84ee2c | ||
|
|
d03395949b | ||
|
|
b19d18c8bc | ||
|
|
b36e0516f4 | ||
|
|
121f962399 | ||
|
|
58f33d6f6c | ||
|
|
61f4d4f5ad | ||
|
|
dc4c6e20e3 | ||
|
|
12d323e32f | ||
|
|
2882e0d3e7 | ||
|
|
79b41ec070 | ||
|
|
05130949ad | ||
|
|
dea7b2be94 | ||
|
|
294ff5bb19 | ||
|
|
7dad7c8399 | ||
|
|
e0c09ce340 | ||
|
|
e4751d54cb | ||
|
|
ed6f4ea375 | ||
|
|
fef2d8f875 | ||
|
|
6971bcd287 | ||
|
|
b16010dfa3 | ||
|
|
9016b6d28c | ||
|
|
ce887f360a | ||
|
|
8238916340 | ||
|
|
b1f8ad8dca | ||
|
|
dca306d87f | ||
|
|
3b4211b581 | ||
|
|
5c4121ca1e | ||
|
|
a3fde534e2 | ||
|
|
63c1c25fda | ||
|
|
d32e09aaf9 | ||
|
|
1184864c14 | ||
|
|
9343eb9911 | ||
|
|
3ecf21a6f1 | ||
|
|
904413db6d | ||
|
|
3c8edab514 | ||
|
|
5c886e4cf4 | ||
|
|
dba9143f45 | ||
|
|
1abe4dadb7 | ||
|
|
9cedeb4fa6 | ||
|
|
899e6e96d6 | ||
|
|
7838debadf | ||
|
|
db13455a7b | ||
|
|
5838340594 | ||
|
|
655456ee03 | ||
|
|
770c19a27b | ||
|
|
613062549d | ||
|
|
f3a45b6549 | ||
|
|
c71867169b | ||
|
|
473acc4e2b | ||
|
|
21ea35b02a | ||
|
|
7f21b708e7 | ||
|
|
b80b41e1fd | ||
|
|
fe8f53375e | ||
|
|
a2b6f95656 | ||
|
|
fa3347077a | ||
|
|
5d010fe1fa | ||
|
|
979880ae2d | ||
|
|
7be3e4f410 | ||
|
|
709af6e432 | ||
|
|
ac3307bd91 | ||
|
|
063209dc9e | ||
|
|
83303471c5 | ||
|
|
8bcc9503d1 | ||
|
|
ed1e4a5cf0 | ||
|
|
3cf7dc89b9 | ||
|
|
69c1aab14a | ||
|
|
9547623a90 | ||
|
|
d524748b6d | ||
|
|
39dd65b224 | ||
|
|
925f817e42 | ||
|
|
ed4bd2573b | ||
|
|
e72641c0f3 | ||
|
|
f4892d7f10 | ||
|
|
90c479b23c | ||
|
|
b98538ba24 | ||
|
|
2a43213387 | ||
|
|
3bdbeb6c87 | ||
|
|
24b185db89 | ||
|
|
4bb7dcaf64 | ||
|
|
4a8c482a4d | ||
|
|
2d150e79fb | ||
|
|
8442e21621 | ||
|
|
b638a6d047 | ||
|
|
231de707dc | ||
|
|
8b9c2b4da1 | ||
|
|
4e91579ef2 | ||
|
|
8b3a3f29a8 | ||
|
|
24dee03e18 | ||
|
|
4e01aa1322 | ||
|
|
ba7fb86f5b | ||
|
|
6625b55f97 | ||
|
|
dd1995064e | ||
|
|
9024f6e695 | ||
|
|
26d0a89fd5 | ||
|
|
2f8fde0af0 | ||
|
|
21c76683ef | ||
|
|
ded13229c0 | ||
|
|
10f64a8d91 | ||
|
|
e1d86d8969 | ||
|
|
858aefee6b | ||
|
|
1d22b7596c | ||
|
|
fe5e5f592b | ||
|
|
f45d85f30a | ||
|
|
725479ded6 | ||
|
|
8110f9ac13 | ||
|
|
4f8a60b498 | ||
|
|
667629d265 | ||
|
|
b06ff625e0 | ||
|
|
8ee74161fc | ||
|
|
e1fb5a7411 | ||
|
|
e8ff79e448 | ||
|
|
5cb3ebf262 | ||
|
|
3ac188124e | ||
|
|
590eefaa52 | ||
|
|
4b307be939 | ||
|
|
260de05a63 | ||
|
|
e06aa25245 | ||
|
|
353453e9a7 | ||
|
|
85084249cf | ||
|
|
89aeddaf3a | ||
|
|
89f80c6f25 | ||
|
|
b27043518f | ||
|
|
f54bd6a703 | ||
|
|
327275d1a4 | ||
|
|
37609ad7ec | ||
|
|
bf8c01cff0 | ||
|
|
f635f6d16a | ||
|
|
223892f121 | ||
|
|
76f51e977d | ||
|
|
73784f39ac | ||
|
|
35a5397a05 | ||
|
|
fe0c1e3683 | ||
|
|
24737e8958 | ||
|
|
5349a59186 | ||
|
|
9f1cc0a290 | ||
|
|
f8fb41d6b8 | ||
|
|
b96f8ee9a5 | ||
|
|
31f8560a65 | ||
|
|
59e876062f | ||
|
|
d260f07acb | ||
|
|
81e247e1e8 | ||
|
|
65e842b1c8 | ||
|
|
547e1b0d83 | ||
|
|
2c1b459a5e | ||
|
|
adfc0fa6b8 | ||
|
|
0a7dc70339 | ||
|
|
3aaeb88bcd | ||
|
|
6f6710ede9 | ||
|
|
8b13c638b1 | ||
|
|
b08bb591be | ||
|
|
f09d399c17 | ||
|
|
0c8a0c43c1 | ||
|
|
12147d9cd2 | ||
|
|
a5fb5b9901 | ||
|
|
8fb311b739 | ||
|
|
02e16666ed | ||
|
|
2f4ec4b2b9 | ||
|
|
e641246866 | ||
|
|
772941e02e | ||
|
|
3efa3bbce9 | ||
|
|
178cdd42b7 | ||
|
|
3a7c139e18 | ||
|
|
e281c21662 | ||
|
|
9b26befcba | ||
|
|
1b3833205c | ||
|
|
40c9a78014 | ||
|
|
a5190dce5b | ||
|
|
0ad3bea276 | ||
|
|
ea3ea80ff4 | ||
|
|
c9da527d37 | ||
|
|
e930a2922c | ||
|
|
5055616101 | ||
|
|
e4d5565f8e | ||
|
|
0d319c07ae | ||
|
|
23f4643c6e | ||
|
|
6e00aa6cf5 | ||
|
|
9037d14d83 | ||
|
|
50b5c74c52 | ||
|
|
23d6266335 | ||
|
|
4f8727f9d4 | ||
|
|
119d674207 | ||
|
|
1347d73b04 | ||
|
|
b55dc1fd78 | ||
|
|
1a52f3dce8 | ||
|
|
4a0bd1aa21 | ||
|
|
33473a4528 | ||
|
|
453debb6e9 | ||
|
|
81ccf6359d | ||
|
|
681e6f02fe | ||
|
|
5e226433b5 | ||
|
|
f4c56f81f3 | ||
|
|
ce85b27803 | ||
|
|
eb31381094 | ||
|
|
a1cbce810e | ||
|
|
f195975bda | ||
|
|
3636bb35ff | ||
|
|
1d5a09699b | ||
|
|
1df59316e7 | ||
|
|
d6b47c1a4e | ||
|
|
49fe2cb61f | ||
|
|
5f17b4f3c5 | ||
|
|
1b9d21b5e3 | ||
|
|
c51c6b7f7e | ||
|
|
0c8d7c26c5 | ||
|
|
c4585c8394 | ||
|
|
dfcf961f75 | ||
|
|
0cc3ecc2e9 | ||
|
|
a24934f1a0 | ||
|
|
9d54f5daac | ||
|
|
0f8b5e51a4 | ||
|
|
47295309b3 | ||
|
|
ba7ee3ed95 | ||
|
|
9b5eb069d6 | ||
|
|
672bdbba6f | ||
|
|
8271dfae07 | ||
|
|
f4702fe066 | ||
|
|
fea8dbef1a | ||
|
|
6a527d36a8 | ||
|
|
2292f472c9 | ||
|
|
2aaaeee5a7 | ||
|
|
ca161690da | ||
|
|
8bd1a71065 | ||
|
|
eb72fdc717 | ||
|
|
a7f819a78e | ||
|
|
d4d58e166b | ||
|
|
1d41a198cb | ||
|
|
6ced9d03d3 | ||
|
|
19c7616a4b | ||
|
|
a82281ad1c | ||
|
|
f3e1f9df90 | ||
|
|
c85b9e8cbc | ||
|
|
ece0475808 | ||
|
|
2e0bb9304a | ||
|
|
74c0142968 | ||
|
|
7c71d90d17 | ||
|
|
f86fde81e6 | ||
|
|
43814450e5 | ||
|
|
d5077ee816 | ||
|
|
2cf2c6979e | ||
|
|
154fe0d447 | ||
|
|
a493f0117d | ||
|
|
cc0400bdd4 | ||
|
|
8b57a035ee | ||
|
|
dc57f83d19 | ||
|
|
611f556cf9 | ||
|
|
d06ad04341 | ||
|
|
72c89268ec | ||
|
|
3f99b483cb | ||
|
|
9bef235252 | ||
|
|
18935dcfdd | ||
|
|
db2fb81654 | ||
|
|
6fbd4878be | ||
|
|
023a9905f6 | ||
|
|
6facdac464 | ||
|
|
377600d0a3 | ||
|
|
b6cf078395 | ||
|
|
673ca25cf2 | ||
|
|
4038f0384b | ||
|
|
f5dc6ab994 | ||
|
|
aa45703a99 | ||
|
|
f01de5c802 | ||
|
|
827b64d633 | ||
|
|
7bf82c7ea9 | ||
|
|
3055a3ada0 | ||
|
|
5b1883802e | ||
|
|
bef677678b | ||
|
|
61c59b514f | ||
|
|
8f998e799d | ||
|
|
c2f455ec1b | ||
|
|
3a8af97eb9 | ||
|
|
e6c13057ce | ||
|
|
5f47a25711 | ||
|
|
4c9b67ead4 | ||
|
|
adef5e0e6a | ||
|
|
4e2632e100 | ||
|
|
4ff204a0c4 | ||
|
|
1e0baf5f6c | ||
|
|
a9c56e5bb2 | ||
|
|
4a1fc11b2d | ||
|
|
42c22a7bbb | ||
|
|
369537e515 | ||
|
|
3880279e89 | ||
|
|
524e7bcfd3 | ||
|
|
3bac1d2d9d | ||
|
|
d7ac0ee17a | ||
|
|
462b7d861d | ||
|
|
f523f8b2e3 | ||
|
|
279b009882 | ||
|
|
ee4feb17c4 | ||
|
|
2a014e56b0 | ||
|
|
040763ebb2 | ||
|
|
dfd8d340a0 | ||
|
|
ca6bc12cfc | ||
|
|
5b4bf5964e | ||
|
|
f72bfd8f3a | ||
|
|
0d93c109fb | ||
|
|
1cd8f4d4f7 | ||
|
|
25acd7fd16 | ||
|
|
3e6dae9616 | ||
|
|
1dce070245 | ||
|
|
cc552d9777 | ||
|
|
c7d448ca49 | ||
|
|
fe0bd3ff67 | ||
|
|
b5adc2bf93 | ||
|
|
6f9bad3d05 | ||
|
|
f28799cc4c | ||
|
|
e2376c27b4 | ||
|
|
e4a0aa3480 | ||
|
|
045a365a1b | ||
|
|
1059e9873a | ||
|
|
e0522cc20e | ||
|
|
ef83d4314e | ||
|
|
3b4ca09931 | ||
|
|
19adf0cd7e | ||
|
|
3fb1fdf16a | ||
|
|
695b0759e4 | ||
|
|
6dbdf4d88b | ||
|
|
e55430f61a | ||
|
|
a68f3edcd4 | ||
|
|
e438df87fa | ||
|
|
bb9f4136f5 | ||
|
|
aaf9f18d93 | ||
|
|
2f23120a64 | ||
|
|
7743583f4d | ||
|
|
fe5542845e | ||
|
|
e65bfcdacf | ||
|
|
9d199c86c5 | ||
|
|
fca0a60e5b | ||
|
|
6e3c42f238 | ||
|
|
ab94b68571 | ||
|
|
0662a44017 | ||
|
|
78e530f506 | ||
|
|
ab0b43d51c | ||
|
|
d975534bf7 | ||
|
|
ec22e22bbd | ||
|
|
0face3e966 | ||
|
|
823aacdeba | ||
|
|
c605d1d2c6 | ||
|
|
ef65602b79 | ||
|
|
778f047376 | ||
|
|
2b805fc7ca | ||
|
|
f3fe3123b3 | ||
|
|
c1ac7fcd38 | ||
|
|
7e7d9720be | ||
|
|
4fbaae4b12 | ||
|
|
07b294778a | ||
|
|
8c0a368969 | ||
|
|
99c2020795 | ||
|
|
54b384efec | ||
|
|
975286c2ac | ||
|
|
70b01eb9c8 | ||
|
|
1755d3a017 | ||
|
|
22f385b809 | ||
|
|
f751546913 | ||
|
|
587b166a4e | ||
|
|
b208528d3d | ||
|
|
882abff431 | ||
|
|
892da2478b | ||
|
|
28f5cd7852 | ||
|
|
8e0571c7c9 | ||
|
|
d6fc9f71d0 | ||
|
|
108ef50bd5 | ||
|
|
90b7680392 | ||
|
|
a8a9831c16 | ||
|
|
a1f39bb7d3 | ||
|
|
a50c9f76ec | ||
|
|
f6e679e70e | ||
|
|
17bb1ac39f | ||
|
|
33c23c1341 | ||
|
|
9dd084810f | ||
|
|
d4e1cd4f1e | ||
|
|
aa8c27fd5d | ||
|
|
806104626f | ||
|
|
2331dffe4c | ||
|
|
2d69542265 | ||
|
|
3e8cbe112f | ||
|
|
31ff3f0290 | ||
|
|
f606c3705f | ||
|
|
758ee32aa9 | ||
|
|
163b1d0731 | ||
|
|
e732cf59e0 | ||
|
|
a571c7b72c | ||
|
|
9340e62895 | ||
|
|
efd86e1b27 | ||
|
|
f1e243c145 | ||
|
|
e867b220a1 | ||
|
|
a04c40d016 | ||
|
|
4fb1a8fbe8 | ||
|
|
b959dd2e49 | ||
|
|
5c09099084 | ||
|
|
fc5711ce7c | ||
|
|
cc14044b6b | ||
|
|
e0dc7f2f81 | ||
|
|
03ce1e27c7 | ||
|
|
735f9abef7 | ||
|
|
f2ddaa7921 | ||
|
|
75321d306a | ||
|
|
d2e9364e5e | ||
|
|
b61f994746 | ||
|
|
633593e412 | ||
|
|
e7c0ff7d41 | ||
|
|
bda974a72c | ||
|
|
dbb2b49b55 | ||
|
|
e770c619e5 | ||
|
|
0d8d07d474 | ||
|
|
dd07c68201 | ||
|
|
e9804a5b76 | ||
|
|
85c384c64a | ||
|
|
fed5fd4c5e | ||
|
|
eec35b285e | ||
|
|
e2f1f778f3 | ||
|
|
7b87d7c52c | ||
|
|
c88fe59c71 | ||
|
|
9eac1512fb | ||
|
|
8f8afaf139 | ||
|
|
e651433727 | ||
|
|
8ac7db46e0 | ||
|
|
1e8148c051 | ||
|
|
520cc0e130 | ||
|
|
2338fbb06f | ||
|
|
3687602508 | ||
|
|
49ec161c5e | ||
|
|
4923708836 | ||
|
|
11f9ef1045 | ||
|
|
bb3e6d6907 | ||
|
|
574fb55fcf | ||
|
|
b96ca0735d | ||
|
|
c421e655c5 | ||
|
|
66d4669f36 | ||
|
|
953f63c7bd | ||
|
|
fca1123ee5 | ||
|
|
5eaf11b8aa | ||
|
|
0274ceb312 | ||
|
|
38f96c7e46 | ||
|
|
7b3cc8fdf0 | ||
|
|
c184e7be65 | ||
|
|
bfbb80efcf | ||
|
|
01bdc5bf89 | ||
|
|
711d7c2c41 | ||
|
|
2b4e53e926 | ||
|
|
9401c1ee85 | ||
|
|
5c704f053b | ||
|
|
eb1f971d52 | ||
|
|
83bc5508ee | ||
|
|
d6a8734aae | ||
|
|
3ee98cd13a | ||
|
|
275da18cf6 | ||
|
|
3f3b11ffbf | ||
|
|
7f8cb69326 | ||
|
|
003c304105 | ||
|
|
763ab475f2 | ||
|
|
4b3f48b537 | ||
|
|
6301a78814 | ||
|
|
506b427124 | ||
|
|
19ae7d5ac6 | ||
|
|
47aaa85108 | ||
|
|
3067ecdee3 | ||
|
|
d9a0ee1e33 | ||
|
|
5cfc8dee5e | ||
|
|
1ad7ac2dcf | ||
|
|
86446c8879 | ||
|
|
df857e3194 | ||
|
|
ad7a3951c5 | ||
|
|
7e8e968013 | ||
|
|
e38baeec36 | ||
|
|
ca28f962d4 | ||
|
|
dfb2c073d2 | ||
|
|
51b264e8ca | ||
|
|
6d2fe08973 | ||
|
|
ccc551112b | ||
|
|
1a5537f4ba | ||
|
|
5c2f0c5f4a | ||
|
|
a66de4c601 | ||
|
|
af73d0ce1a | ||
|
|
04654ca465 | ||
|
|
af10579be9 | ||
|
|
30d24a85b5 | ||
|
|
d8b386a812 |
+3
-4
@@ -1,10 +1,9 @@
|
||||
ignore:
|
||||
- "charts"
|
||||
- "demos"
|
||||
- "Documentation"
|
||||
- "examples"
|
||||
- "test"
|
||||
- "test/"
|
||||
- "tools"
|
||||
- "pkg/generated" # generated code
|
||||
- "pkg/apis/*/*/zz_generated*" # generated code
|
||||
coverage:
|
||||
status:
|
||||
project:
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
name: Blog
|
||||
about: Suggest a blog
|
||||
title: ''
|
||||
labels: ''
|
||||
assignees: ''
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,15 +9,15 @@ assignees: ''
|
||||
|
||||
<!-- Please answer these questions before submitting your issue. Thanks! -->
|
||||
|
||||
<!-- Documentation URL: https://docs.fission.io/ -->
|
||||
<!-- Troubleshooting guide: https://docs.fission.io/trouble-shooting/ -->
|
||||
<!-- Documentation URL: https://fission.io/docs -->
|
||||
<!-- Troubleshooting guide: https://fission.io/docs/trouble-shooting/ -->
|
||||
|
||||
**Fission/Kubernetes version**
|
||||
|
||||
<!-- If you tested with other services, for example Istio, please also provide the version of service as well. -->
|
||||
|
||||
<pre>
|
||||
$ fission --version
|
||||
$ fission version
|
||||
$ kubectl version
|
||||
</pre>
|
||||
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
name: Documentation
|
||||
about: Suggest changes/addition to documentation
|
||||
title: ''
|
||||
labels: ''
|
||||
assignees: ''
|
||||
|
||||
---
|
||||
|
||||
**Describe something that is unclear or not documented and needs a documentation update
|
||||
@@ -0,0 +1,20 @@
|
||||
---
|
||||
name: Feature request
|
||||
about: Suggest an idea for this project
|
||||
title: ''
|
||||
labels: ''
|
||||
assignees: ''
|
||||
|
||||
---
|
||||
|
||||
**Is your feature request related to a problem? Please describe.**
|
||||
A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]
|
||||
|
||||
**Describe the solution you'd like**
|
||||
A clear and concise description of what you want to happen.
|
||||
|
||||
**Describe alternatives you've considered**
|
||||
A clear and concise description of any alternative solutions or features you've considered.
|
||||
|
||||
**Additional context**
|
||||
Add any other context or screenshots about the feature request here.
|
||||
@@ -0,0 +1,23 @@
|
||||
<!-- Thanks for sending a pull request! We request you provide detailed description as much as possible. -->
|
||||
|
||||
## Description
|
||||
<!--- Describe your changes in detail. -->
|
||||
<!-- Typically try to give details of what, why and how of the PR changes. -->
|
||||
|
||||
## Which issue(s) this PR fixes:
|
||||
<!--
|
||||
*Automatically closes linked issue when PR is merged.
|
||||
Usage: `Fixes #<issue number>`, or `Fixes (paste link of issue)`.
|
||||
-->
|
||||
Fixes #
|
||||
|
||||
## Testing
|
||||
<!--- Please describe in detail how you tested your changes. -->
|
||||
|
||||
## Checklist:
|
||||
<!-- Please tick following checkboxes as per your understanding. -->
|
||||
- [ ] I ran tests as well as code linting locally to verify my changes.
|
||||
- [ ] I have done manual verification of my changes, changes working as expected.
|
||||
- [ ] I have added new tests to cover my changes.
|
||||
- [ ] My changes follow contributing guidelines of Fission.
|
||||
- [ ] I have signed all of my commits.
|
||||
@@ -0,0 +1,42 @@
|
||||
name: Code Scanning
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- '**.go'
|
||||
- go.mod
|
||||
- go.sum
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- '**.go'
|
||||
- go.mod
|
||||
- go.sum
|
||||
schedule:
|
||||
- cron: "0 0 * * 0"
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
CodeQL-Build:
|
||||
runs-on: ubuntu-latest
|
||||
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||
steps:
|
||||
- name: Check out code
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
|
||||
- name: setup go
|
||||
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
|
||||
with:
|
||||
go-version-file: "go.mod"
|
||||
cache: true
|
||||
|
||||
- name: Initialize CodeQL
|
||||
uses: github/codeql-action/init@66b90a5db151a8042fa97405c6cf843bbe433f7b # v2.22.7
|
||||
with:
|
||||
languages: go
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@66b90a5db151a8042fa97405c6cf843bbe433f7b # v2.22.7
|
||||
@@ -0,0 +1,35 @@
|
||||
name: Lint dashboards
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- 'charts/fission-all/dashboards/**.json'
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- 'charts/fission-all/dashboards/**.json'
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
lint-dashboards:
|
||||
runs-on: ubuntu-latest
|
||||
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||
steps:
|
||||
- name: Check out code
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
|
||||
with:
|
||||
go-version-file: "go.mod"
|
||||
|
||||
- name: Install dashboard linter
|
||||
run: |
|
||||
go get github.com/grafana/dashboard-linter
|
||||
go install github.com/grafana/dashboard-linter
|
||||
|
||||
- name: Run dashboard linter
|
||||
run: ./hack/lint-dashboards.sh
|
||||
@@ -0,0 +1,68 @@
|
||||
name: Lint and Unit tests
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- "**.go"
|
||||
- go.mod
|
||||
- go.sum
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- "**.go"
|
||||
- go.mod
|
||||
- go.sum
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
GOLANGCI_LINT_VERSION: v1.55.2
|
||||
GOLANGCI_LINT_TIMEOUT: 5m
|
||||
|
||||
jobs:
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
# if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||
steps:
|
||||
- name: Check out code
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
|
||||
with:
|
||||
go-version-file: "go.mod"
|
||||
cache: true
|
||||
|
||||
- name: Verify dependencies
|
||||
run: |
|
||||
go mod verify
|
||||
go mod download
|
||||
|
||||
- name: Run golangci-lint
|
||||
uses: golangci/golangci-lint-action@3a919529898de77ec3da873e3063ca4b10e7f5cc # v3.7.0
|
||||
with:
|
||||
version: ${{ env.GOLANGCI_LINT_VERSION }}
|
||||
args: --timeout=${{ env.GOLANGCI_LINT_TIMEOUT }}
|
||||
|
||||
- name: Detect git changes
|
||||
if: always()
|
||||
run: |
|
||||
if [[ $(git diff --stat) != '' ]]; then
|
||||
echo -e '❌ \033[0;31m. Fix lint changes.\033[0m'
|
||||
git diff --color
|
||||
exit 1
|
||||
else
|
||||
echo '✔ No issues detected. Have a nice day :-)'
|
||||
fi
|
||||
|
||||
- name: Run unit tests
|
||||
run: ./hack/runtests.sh
|
||||
|
||||
- name: Upload Coverage report to CodeCov
|
||||
uses: codecov/codecov-action@eaaf4bedf32dbdc6b720b63067d99c4d77d6047d # v3.1.4
|
||||
with:
|
||||
token: ${{secrets.CODECOV_TOKEN}}
|
||||
flags: unittests
|
||||
file: ./coverage.txt
|
||||
@@ -0,0 +1,314 @@
|
||||
name: Fission CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- "**.go"
|
||||
- "charts/**"
|
||||
- "test/**"
|
||||
- go.mod
|
||||
- go.sum
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- "**.go"
|
||||
- "charts/**"
|
||||
- "test/**"
|
||||
- go.mod
|
||||
- go.sum
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
HELM_VERSION: v3.13.0
|
||||
KIND_VERSION: v0.20.0
|
||||
KIND_CLUSTER_NAME: kind
|
||||
|
||||
jobs:
|
||||
# Job to run change detection
|
||||
integration-test:
|
||||
runs-on: ${{ matrix.os }}
|
||||
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
kindversion: ["v1.23.17", "v1.25.11", "v1.27.3"]
|
||||
os: [ubuntu-latest]
|
||||
steps:
|
||||
- name: Checkout sources
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
|
||||
- name: setup go
|
||||
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
|
||||
with:
|
||||
go-version-file: "go.mod"
|
||||
cache: true
|
||||
|
||||
- name: Checkout sources
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
with:
|
||||
repository: fission/examples
|
||||
path: examples
|
||||
|
||||
- name: Helm installation
|
||||
uses: Azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78 # v3.5
|
||||
with:
|
||||
version: ${{ env.HELM_VERSION }}
|
||||
|
||||
- name: Kind Cluster
|
||||
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
|
||||
with:
|
||||
node_image: kindest/node:${{ matrix.kindversion }}
|
||||
version: ${{ env.KIND_VERSION }}
|
||||
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||
config: kind.yaml
|
||||
|
||||
- name: Configuring and testing the Installation
|
||||
run: |
|
||||
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||
kubectl get nodes
|
||||
sudo apt-get install -y apache2-utils
|
||||
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||
kubectl config view
|
||||
|
||||
- name: Helm chart lint
|
||||
run: |
|
||||
helm lint charts/fission-all/
|
||||
|
||||
- name: Install Skaffold
|
||||
run: |
|
||||
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/v2.0.3/skaffold-linux-amd64
|
||||
sudo install skaffold /usr/local/bin/
|
||||
skaffold version
|
||||
|
||||
- name: Install GoReleaser
|
||||
uses: goreleaser/goreleaser-action@7ec5c2b0c6cdda6e8bbb49444bc797dd33d74dd8 # v5.0.0
|
||||
with:
|
||||
install-only: true
|
||||
|
||||
- name: Setup Prometheus Stack
|
||||
run: |
|
||||
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
|
||||
helm repo update
|
||||
kubectl create ns monitoring
|
||||
helm install prometheus prometheus-community/kube-prometheus-stack -n monitoring \
|
||||
--version 45.28.0 --set grafana.enabled=false --set alertmanager.enabled=false
|
||||
|
||||
- name: Build and Install Fission CLI
|
||||
run: |
|
||||
make debug-vars
|
||||
make build-fission-cli
|
||||
sudo make install-fission-cli
|
||||
sudo chmod +x /usr/local/bin/fission
|
||||
|
||||
- name: Build and Install Fission
|
||||
timeout-minutes: 10
|
||||
run: |
|
||||
kubectl create ns fission
|
||||
make create-crds
|
||||
SKAFFOLD_PROFILE=kind-ci make skaffold-deploy
|
||||
|
||||
- name: Port-forward fission components
|
||||
run: |
|
||||
kubectl port-forward svc/router 8888:80 -nfission &
|
||||
|
||||
- name: Get fission version
|
||||
timeout-minutes: 10
|
||||
run: |
|
||||
fission version
|
||||
|
||||
- name: Integration tests
|
||||
timeout-minutes: 90
|
||||
run: ./test/kind_CI.sh
|
||||
|
||||
- name: Collect Fission Dump
|
||||
timeout-minutes: 5
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
command -v fission && fission support dump
|
||||
|
||||
- name: Kind export logs
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
kind export logs --name ${{ env.KIND_CLUSTER_NAME }} kind-logs
|
||||
|
||||
- name: Backup prometheus data
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
TRACE=1 ./hack/backup-prometheus.sh
|
||||
|
||||
- name: Archive fission dump
|
||||
timeout-minutes: 10
|
||||
if: ${{ failure() || cancelled() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||
path: fission-dump/*.zip
|
||||
retention-days: 5
|
||||
|
||||
- name: Archive prometheus dump
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: prom-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||
path: /tmp/prometheus/*
|
||||
retention-days: 5
|
||||
|
||||
- name: Archive kind logs
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||
path: kind-logs/*
|
||||
retention-days: 5
|
||||
|
||||
# Job to ensure backward compatibility if function and builder pods are created
|
||||
# inside functionNamespace and builderNamespace
|
||||
integration-test-old:
|
||||
runs-on: ${{ matrix.os }}
|
||||
if: ${{ contains(github.event.pull_request.labels.*.name, 'run-old-ci') }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
kindversion: ["v1.19.16"]
|
||||
os: [ubuntu-latest]
|
||||
steps:
|
||||
- name: Checkout sources
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
|
||||
- name: setup go
|
||||
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
|
||||
with:
|
||||
go-version-file: "go.mod"
|
||||
cache: true
|
||||
|
||||
- name: Checkout sources
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
with:
|
||||
repository: fission/examples
|
||||
path: examples
|
||||
|
||||
- name: Helm installation
|
||||
uses: Azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78 # v3.5
|
||||
with:
|
||||
version: ${{ env.HELM_VERSION }}
|
||||
|
||||
- name: Kind Cluster
|
||||
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
|
||||
with:
|
||||
node_image: kindest/node:${{ matrix.kindversion }}
|
||||
version: ${{ env.KIND_VERSION }}
|
||||
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||
config: kind.yaml
|
||||
|
||||
- name: Configuring and testing the Installation
|
||||
run: |
|
||||
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||
kubectl get nodes
|
||||
sudo apt-get install -y apache2-utils
|
||||
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||
kubectl config view
|
||||
|
||||
- name: Helm chart lint
|
||||
run: |
|
||||
helm lint charts/fission-all/
|
||||
|
||||
- name: Install Skaffold
|
||||
run: |
|
||||
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/v2.0.3/skaffold-linux-amd64
|
||||
sudo install skaffold /usr/local/bin/
|
||||
skaffold version
|
||||
|
||||
- name: Install GoReleaser
|
||||
uses: goreleaser/goreleaser-action@7ec5c2b0c6cdda6e8bbb49444bc797dd33d74dd8 # v5.0.0
|
||||
with:
|
||||
install-only: true
|
||||
|
||||
- name: Setup Prometheus Stack
|
||||
run: |
|
||||
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
|
||||
helm repo update
|
||||
kubectl create ns monitoring
|
||||
helm install prometheus prometheus-community/kube-prometheus-stack -n monitoring \
|
||||
--version 45.28.0 --set grafana.enabled=false --set alertmanager.enabled=false
|
||||
|
||||
- name: Build and Install Fission CLI
|
||||
run: |
|
||||
make debug-vars
|
||||
make build-fission-cli
|
||||
sudo make install-fission-cli
|
||||
sudo chmod +x /usr/local/bin/fission
|
||||
|
||||
- name: Build and Install Fission
|
||||
timeout-minutes: 10
|
||||
run: |
|
||||
kubectl create ns fission
|
||||
make create-crds
|
||||
SKAFFOLD_PROFILE=kind-ci-old make skaffold-deploy
|
||||
|
||||
- name: Port-forward fission components
|
||||
run: |
|
||||
kubectl port-forward svc/router 8888:80 -nfission &
|
||||
|
||||
- name: Get fission version
|
||||
timeout-minutes: 10
|
||||
run: |
|
||||
fission version
|
||||
|
||||
- name: Integration tests
|
||||
timeout-minutes: 90
|
||||
run: |
|
||||
export FUNCTION_NAMESPACE=fission-function
|
||||
export BUILDER_NAMESPACE=fission-builder
|
||||
./test/kind_CI.sh
|
||||
|
||||
- name: Collect Fission Dump
|
||||
timeout-minutes: 5
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
command -v fission && fission support dump
|
||||
|
||||
- name: Kind export logs
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
kind export logs --name kind kind-logs
|
||||
|
||||
- name: Backup prometheus data
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
TRACE=1 ./hack/backup-prometheus.sh
|
||||
|
||||
- name: Archive fission dump
|
||||
timeout-minutes: 10
|
||||
if: ${{ failure() || cancelled() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: fission-dump-${{ github.run_id }}-${{ github.job_id }}-${{ matrix.kindversion }}
|
||||
path: fission-dump/*.zip
|
||||
retention-days: 5
|
||||
|
||||
- name: Archive prometheus dump
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: prom-dump-${{ github.run_id }}-${{ github.job_id }}-${{ matrix.kindversion }}
|
||||
path: /tmp/prometheus/*
|
||||
retention-days: 5
|
||||
|
||||
- name: Archive kind logs
|
||||
timeout-minutes: 10
|
||||
if: ${{ always() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: kind-logs-${{ github.run_id }}-${{ github.job_id }}-${{ matrix.kindversion }}
|
||||
path: kind-logs/*
|
||||
retention-days: 5
|
||||
@@ -0,0 +1,92 @@
|
||||
name: Create Draft release
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- v1.**
|
||||
- v2.**
|
||||
|
||||
env:
|
||||
KIND_VERSION: v0.20.0
|
||||
KIND_NODE_IMAGE_TAG: v1.23.17
|
||||
KIND_CLUSTER_NAME: kind
|
||||
|
||||
jobs:
|
||||
create-draft-release:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Check out code
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Setup go
|
||||
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
|
||||
with:
|
||||
go-version-file: "go.mod"
|
||||
cache: true
|
||||
|
||||
- name: Get the version
|
||||
id: get_version
|
||||
run: echo ::set-output name=VERSION::${GITHUB_REF/refs\/tags\//}
|
||||
|
||||
- name: Install GoReleaser
|
||||
uses: goreleaser/goreleaser-action@7ec5c2b0c6cdda6e8bbb49444bc797dd33d74dd8 # v5.0.0
|
||||
with:
|
||||
install-only: true
|
||||
|
||||
- name: Kind Clutser
|
||||
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
|
||||
with:
|
||||
node_image: kindest/node:${{ env.KIND_NODE_IMAGE_TAG }}
|
||||
version: ${{ env.KIND_VERSION }}
|
||||
config: kind.yaml
|
||||
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
|
||||
|
||||
- name: Login to ghcr.io
|
||||
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Login to docker.io
|
||||
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: Install Cosign
|
||||
uses: sigstore/cosign-installer@1fc5bd396d372bee37d608f955b336615edf79c8 # v3.2.0
|
||||
with:
|
||||
cosign-release: "v2.2.1"
|
||||
|
||||
- name: Check cosign install!
|
||||
run: cosign version
|
||||
|
||||
- name: Write cosign signing key to disk
|
||||
run: 'echo "$KEY" > cosign.key'
|
||||
shell: bash
|
||||
env:
|
||||
KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||
|
||||
- name: Generate yaml for manifest, Minikube and Openshift installation
|
||||
run: ${GITHUB_WORKSPACE}/hack/build-yaml.sh $VERSION
|
||||
env:
|
||||
VERSION: ${{ steps.get_version.outputs.VERSION }}
|
||||
shell: bash
|
||||
|
||||
- name: Run GoReleaser
|
||||
uses: goreleaser/goreleaser-action@7ec5c2b0c6cdda6e8bbb49444bc797dd33d74dd8 # v5.0.0
|
||||
with:
|
||||
version: latest
|
||||
args: release
|
||||
env:
|
||||
COSIGN_PWD: ${{ secrets.COSIGN_PWD }}
|
||||
GORELEASER_CURRENT_TAG: ${{ steps.get_version.outputs.VERSION }}
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
DOCKER_CLI_EXPERIMENTAL: "enabled"
|
||||
|
||||
#ToDo - Verify and upload releases
|
||||
@@ -0,0 +1,120 @@
|
||||
name: Fission CI upgrade
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- "**.go"
|
||||
- "charts/**"
|
||||
- "test/**"
|
||||
- go.mod
|
||||
- go.sum
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- "**.go"
|
||||
- "charts/**"
|
||||
- "test/**"
|
||||
- go.mod
|
||||
- go.sum
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
HELM_VERSION: v3.13.0
|
||||
KIND_VERSION: v0.20.0
|
||||
KIND_CLUSTER_NAME: kind
|
||||
|
||||
jobs:
|
||||
upgrade-test:
|
||||
runs-on: ${{ matrix.os }}
|
||||
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
kindimage: ["kindest/node:v1.23.17"]
|
||||
os: [ubuntu-latest]
|
||||
steps:
|
||||
- name: Checkout action sources
|
||||
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
|
||||
|
||||
- name: Setup go
|
||||
uses: actions/setup-go@93397bea11091df50f3d7e59dc26a7711a8bcfbe # v4.1.0
|
||||
with:
|
||||
go-version-file: "go.mod"
|
||||
cache: true
|
||||
|
||||
- name: Setup Helm
|
||||
uses: Azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78 # v3.5
|
||||
with:
|
||||
version: ${{ env.HELM_VERSION }}
|
||||
|
||||
- name: Setup Kind Clutser
|
||||
uses: helm/kind-action@dda0770415bac9fc20092cacbc54aa298604d140 # v1.8.0
|
||||
with:
|
||||
node_image: ${{ matrix.kindimage }}
|
||||
version: ${{ env.KIND_VERSION }}
|
||||
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||
|
||||
- name: Install GoReleaser
|
||||
uses: goreleaser/goreleaser-action@7ec5c2b0c6cdda6e8bbb49444bc797dd33d74dd8 # v5.0.0
|
||||
with:
|
||||
install-only: true
|
||||
|
||||
- name: Setup kubectl & fetch node information
|
||||
run: |
|
||||
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||
kubectl get nodes
|
||||
kubectl get storageclasses.storage.k8s.io
|
||||
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||
kubectl config set-context --current --namespace=default
|
||||
kubectl config view
|
||||
|
||||
- name: Dump system info
|
||||
run: |
|
||||
source ./test/upgrade_test/fission_objects.sh dump_system_info
|
||||
|
||||
- name: Install and configure previous stable fission
|
||||
run: |
|
||||
source ./test/upgrade_test/fission_objects.sh install_stable_release \
|
||||
&& create_fission_objects \
|
||||
&& test_fission_objects
|
||||
|
||||
- name: Upgrade fission to latest
|
||||
run: |
|
||||
source ./test/upgrade_test/fission_objects.sh build_docker_images \
|
||||
&& kind_image_load \
|
||||
&& install_current_release \
|
||||
&& install_fission_cli
|
||||
|
||||
- name: Test previously created fission objects with new release
|
||||
timeout-minutes: 10
|
||||
run: |
|
||||
source ./test/upgrade_test/fission_objects.sh test_fission_objects
|
||||
|
||||
- name: Collect Fission Dump
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
command -v fission && fission support dump
|
||||
|
||||
- name: Kind export logs
|
||||
if: ${{ always() }}
|
||||
run: |
|
||||
kind export logs --name ${{ env.KIND_CLUSTER_NAME }} kind-logs
|
||||
|
||||
- name: Archive fission dump
|
||||
if: ${{ failure() || cancelled() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||
path: fission-dump/*.zip
|
||||
retention-days: 5
|
||||
|
||||
- name: Archive kind logs
|
||||
if: ${{ always() }}
|
||||
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
|
||||
with:
|
||||
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||
path: kind-logs/*
|
||||
retention-days: 5
|
||||
+13
-4
@@ -5,9 +5,11 @@ cmd/fission-cli/fission-cli
|
||||
cmd/fetcher/fetcher
|
||||
cmd/builder/builder
|
||||
cmd/preupgradechecks/pre-upgrade-checks
|
||||
cmd/reporter/reporter
|
||||
|
||||
# Logs
|
||||
test/logs/
|
||||
test/e2e/cli/fission-dump/
|
||||
|
||||
# Pycharm IDE
|
||||
.idea
|
||||
@@ -28,7 +30,14 @@ environments/php7/vendor/
|
||||
.DS_Store
|
||||
vendor/
|
||||
local/
|
||||
environments/dotnet20/Builder/.vs/
|
||||
environments/dotnet20/.vs/
|
||||
environments/dotnet20/obj/
|
||||
environments/dotnet20/bin/
|
||||
|
||||
build/
|
||||
dist/
|
||||
manifest/
|
||||
.vscode/
|
||||
coverage.txt
|
||||
|
||||
cosign.key
|
||||
|
||||
# Dumps
|
||||
.dumps/
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
linters:
|
||||
enable:
|
||||
# Default linter
|
||||
- errcheck
|
||||
- gosimple
|
||||
- govet
|
||||
- ineffassign
|
||||
- staticcheck
|
||||
- typecheck
|
||||
- unused
|
||||
# Additional linters
|
||||
- gofmt
|
||||
- goimports
|
||||
- misspell
|
||||
- nakedret
|
||||
- unconvert
|
||||
- promlinter
|
||||
# Enable in future
|
||||
# - bodyclose
|
||||
# - dogsled
|
||||
# - dupl
|
||||
# - gosec
|
||||
# - nilerr
|
||||
# - prealloc
|
||||
# - revive
|
||||
# - unparam
|
||||
# - wrapcheck
|
||||
# - gocritic
|
||||
linters-settings:
|
||||
errcheck:
|
||||
ignore: go.uber.org/zap:Sync
|
||||
goimports:
|
||||
# put imports beginning with prefix after 3rd-party packages;
|
||||
# it's a comma-separated list of prefixes
|
||||
local: github.com/fission/fission
|
||||
+452
@@ -0,0 +1,452 @@
|
||||
project_name: fission
|
||||
release:
|
||||
github:
|
||||
owner: fission
|
||||
name: fission
|
||||
prerelease: true
|
||||
draft: true
|
||||
header: |
|
||||
Release Highlights: https://fission.io/docs/releases/{{ .Tag }}/
|
||||
Install Guide: https://fission.io/docs/installation/
|
||||
extra_files:
|
||||
- glob: ./manifest/charts/*
|
||||
- glob: ./manifest/yamls/*
|
||||
|
||||
before:
|
||||
hooks:
|
||||
- go mod tidy
|
||||
snapshot:
|
||||
name_template: "{{ .Tag }}"
|
||||
builds:
|
||||
- &build-linux
|
||||
id: builder
|
||||
ldflags:
|
||||
- -s -w
|
||||
- -X github.com/fission/fission/pkg/info.GitCommit={{.ShortCommit}}
|
||||
- -X github.com/fission/fission/pkg/info.BuildDate={{.Date}}
|
||||
- -X github.com/fission/fission/pkg/info.Version={{.Tag}}
|
||||
gcflags:
|
||||
- all=-trimpath={{ if index .Env "GITHUB_WORKSPACE"}}{{ .Env.GITHUB_WORKSPACE }}{{ else }}{{ .Env.PWD }}{{ end }}
|
||||
asmflags:
|
||||
- all=-trimpath={{ if index .Env "GITHUB_WORKSPACE"}}{{ .Env.GITHUB_WORKSPACE }}{{ else }}{{ .Env.PWD }}{{ end }}
|
||||
env:
|
||||
- CGO_ENABLED=0
|
||||
goos:
|
||||
- linux
|
||||
goarch:
|
||||
- amd64
|
||||
- arm64
|
||||
- arm
|
||||
goarm:
|
||||
- 7
|
||||
binary: builder
|
||||
dir: ./cmd/builder
|
||||
- <<: *build-linux
|
||||
id: fetcher
|
||||
binary: fetcher
|
||||
dir: ./cmd/fetcher
|
||||
- <<: *build-linux
|
||||
id: fission-bundle
|
||||
binary: fission-bundle
|
||||
dir: ./cmd/fission-bundle
|
||||
- <<: *build-linux
|
||||
id: fission-cli
|
||||
goos:
|
||||
- linux
|
||||
- windows
|
||||
- darwin
|
||||
binary: fission
|
||||
dir: ./cmd/fission-cli
|
||||
ignore:
|
||||
- goos: windows
|
||||
goarch: arm64
|
||||
- goos: darwin
|
||||
goarch: arm
|
||||
goarm: 7
|
||||
- goos: windows
|
||||
goarch: arm
|
||||
goarm: 7
|
||||
- <<: *build-linux
|
||||
id: pre-upgrade-checks
|
||||
binary: pre-upgrade-checks
|
||||
dir: ./cmd/preupgradechecks
|
||||
- <<: *build-linux
|
||||
id: reporter
|
||||
binary: reporter
|
||||
dir: ./cmd/reporter
|
||||
dockers:
|
||||
- &docker-amd64
|
||||
use: buildx
|
||||
goos: linux
|
||||
goarch: amd64
|
||||
ids:
|
||||
- builder
|
||||
image_templates:
|
||||
- "fission/builder:latest-amd64"
|
||||
- "fission/builder:{{ .Tag }}-amd64"
|
||||
- "ghcr.io/fission/builder:latest-amd64"
|
||||
- "ghcr.io/fission/builder:{{ .Tag }}-amd64"
|
||||
dockerfile: cmd/builder/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/amd64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-amd64
|
||||
ids:
|
||||
- fetcher
|
||||
image_templates:
|
||||
- "fission/fetcher:latest-amd64"
|
||||
- "fission/fetcher:{{ .Tag }}-amd64"
|
||||
- "ghcr.io/fission/fetcher:latest-amd64"
|
||||
- "ghcr.io/fission/fetcher:{{ .Tag }}-amd64"
|
||||
dockerfile: cmd/fetcher/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/amd64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-amd64
|
||||
ids:
|
||||
- fission-bundle
|
||||
image_templates:
|
||||
- "fission/fission-bundle:latest-amd64"
|
||||
- "fission/fission-bundle:{{ .Tag }}-amd64"
|
||||
- "ghcr.io/fission/fission-bundle:latest-amd64"
|
||||
- "ghcr.io/fission/fission-bundle:{{ .Tag }}-amd64"
|
||||
dockerfile: cmd/fission-bundle/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/amd64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-amd64
|
||||
ids:
|
||||
- pre-upgrade-checks
|
||||
image_templates:
|
||||
- "fission/pre-upgrade-checks:latest-amd64"
|
||||
- "fission/pre-upgrade-checks:{{ .Tag }}-amd64"
|
||||
- "ghcr.io/fission/pre-upgrade-checks:latest-amd64"
|
||||
- "ghcr.io/fission/pre-upgrade-checks:{{ .Tag }}-amd64"
|
||||
dockerfile: cmd/preupgradechecks/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/amd64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-amd64
|
||||
ids:
|
||||
- reporter
|
||||
image_templates:
|
||||
- "fission/reporter:latest-amd64"
|
||||
- "fission/reporter:{{ .Tag }}-amd64"
|
||||
- "ghcr.io/fission/reporter:latest-amd64"
|
||||
- "ghcr.io/fission/reporter:{{ .Tag }}-amd64"
|
||||
dockerfile: cmd/reporter/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/amd64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- &docker-arm64
|
||||
use: buildx
|
||||
goos: linux
|
||||
goarch: arm64
|
||||
ids:
|
||||
- builder
|
||||
image_templates:
|
||||
- "fission/builder:latest-arm64"
|
||||
- "fission/builder:{{ .Tag }}-arm64"
|
||||
- "ghcr.io/fission/builder:latest-arm64"
|
||||
- "ghcr.io/fission/builder:{{ .Tag }}-arm64"
|
||||
dockerfile: cmd/builder/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-arm64
|
||||
ids:
|
||||
- fetcher
|
||||
image_templates:
|
||||
- "fission/fetcher:latest-arm64"
|
||||
- "fission/fetcher:{{ .Tag }}-arm64"
|
||||
- "ghcr.io/fission/fetcher:latest-arm64"
|
||||
- "ghcr.io/fission/fetcher:{{ .Tag }}-arm64"
|
||||
dockerfile: cmd/fetcher/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-arm64
|
||||
ids:
|
||||
- fission-bundle
|
||||
image_templates:
|
||||
- "fission/fission-bundle:latest-arm64"
|
||||
- "fission/fission-bundle:{{ .Tag }}-arm64"
|
||||
- "ghcr.io/fission/fission-bundle:latest-arm64"
|
||||
- "ghcr.io/fission/fission-bundle:{{ .Tag }}-arm64"
|
||||
dockerfile: cmd/fission-bundle/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-arm64
|
||||
ids:
|
||||
- pre-upgrade-checks
|
||||
image_templates:
|
||||
- "fission/pre-upgrade-checks:latest-arm64"
|
||||
- "fission/pre-upgrade-checks:{{ .Tag }}-arm64"
|
||||
- "ghcr.io/fission/pre-upgrade-checks:latest-arm64"
|
||||
- "ghcr.io/fission/pre-upgrade-checks:{{ .Tag }}-arm64"
|
||||
dockerfile: cmd/preupgradechecks/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-arm64
|
||||
ids:
|
||||
- reporter
|
||||
image_templates:
|
||||
- "fission/reporter:latest-arm64"
|
||||
- "fission/reporter:{{ .Tag }}-arm64"
|
||||
- "ghcr.io/fission/reporter:latest-arm64"
|
||||
- "ghcr.io/fission/reporter:{{ .Tag }}-arm64"
|
||||
dockerfile: cmd/reporter/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm64"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- &docker-armv7
|
||||
use: buildx
|
||||
goos: linux
|
||||
goarch: arm
|
||||
goarm: 7
|
||||
ids:
|
||||
- builder
|
||||
image_templates:
|
||||
- "fission/builder:latest-armv7"
|
||||
- "fission/builder:{{ .Tag }}-armv7"
|
||||
- "ghcr.io/fission/builder:latest-armv7"
|
||||
- "ghcr.io/fission/builder:{{ .Tag }}-armv7"
|
||||
dockerfile: cmd/builder/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm/v7"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-armv7
|
||||
ids:
|
||||
- fetcher
|
||||
image_templates:
|
||||
- "fission/fetcher:latest-armv7"
|
||||
- "fission/fetcher:{{ .Tag }}-armv7"
|
||||
- "ghcr.io/fission/fetcher:latest-armv7"
|
||||
- "ghcr.io/fission/fetcher:{{ .Tag }}-armv7"
|
||||
dockerfile: cmd/fetcher/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm/v7"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-armv7
|
||||
ids:
|
||||
- fission-bundle
|
||||
image_templates:
|
||||
- "fission/fission-bundle:latest-armv7"
|
||||
- "fission/fission-bundle:{{ .Tag }}-armv7"
|
||||
- "ghcr.io/fission/fission-bundle:latest-armv7"
|
||||
- "ghcr.io/fission/fission-bundle:{{ .Tag }}-armv7"
|
||||
dockerfile: cmd/fission-bundle/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm/v7"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-armv7
|
||||
ids:
|
||||
- pre-upgrade-checks
|
||||
image_templates:
|
||||
- "fission/pre-upgrade-checks:latest-armv7"
|
||||
- "fission/pre-upgrade-checks:{{ .Tag }}-armv7"
|
||||
- "ghcr.io/fission/pre-upgrade-checks:latest-armv7"
|
||||
- "ghcr.io/fission/pre-upgrade-checks:{{ .Tag }}-armv7"
|
||||
dockerfile: cmd/preupgradechecks/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm/v7"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
- <<: *docker-armv7
|
||||
ids:
|
||||
- reporter
|
||||
image_templates:
|
||||
- "fission/reporter:latest-armv7"
|
||||
- "fission/reporter:{{ .Tag }}-armv7"
|
||||
- "ghcr.io/fission/reporter:latest-armv7"
|
||||
- "ghcr.io/fission/reporter:{{ .Tag }}-armv7"
|
||||
dockerfile: cmd/reporter/Dockerfile
|
||||
build_flag_templates:
|
||||
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||
- "--platform=linux/arm/v7"
|
||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||
docker_manifests:
|
||||
- name_template: ghcr.io/fission/builder:{{ .Tag }}
|
||||
image_templates:
|
||||
- ghcr.io/fission/builder:{{ .Tag }}-amd64
|
||||
- ghcr.io/fission/builder:{{ .Tag }}-arm64
|
||||
- ghcr.io/fission/builder:{{ .Tag }}-armv7
|
||||
- name_template: fission/builder:{{ .Tag }}
|
||||
image_templates:
|
||||
- fission/builder:{{ .Tag }}-amd64
|
||||
- fission/builder:{{ .Tag }}-arm64
|
||||
- fission/builder:{{ .Tag }}-armv7
|
||||
- name_template: ghcr.io/fission/fetcher:{{ .Tag }}
|
||||
image_templates:
|
||||
- ghcr.io/fission/fetcher:{{ .Tag }}-amd64
|
||||
- ghcr.io/fission/fetcher:{{ .Tag }}-arm64
|
||||
- ghcr.io/fission/fetcher:{{ .Tag }}-armv7
|
||||
- name_template: fission/fetcher:{{ .Tag }}
|
||||
image_templates:
|
||||
- fission/fetcher:{{ .Tag }}-amd64
|
||||
- fission/fetcher:{{ .Tag }}-arm64
|
||||
- fission/fetcher:{{ .Tag }}-armv7
|
||||
- name_template: ghcr.io/fission/fission-bundle:{{ .Tag }}
|
||||
image_templates:
|
||||
- ghcr.io/fission/fission-bundle:{{ .Tag }}-amd64
|
||||
- ghcr.io/fission/fission-bundle:{{ .Tag }}-arm64
|
||||
- ghcr.io/fission/fission-bundle:{{ .Tag }}-armv7
|
||||
- name_template: fission/fission-bundle:{{ .Tag }}
|
||||
image_templates:
|
||||
- fission/fission-bundle:{{ .Tag }}-amd64
|
||||
- fission/fission-bundle:{{ .Tag }}-arm64
|
||||
- fission/fission-bundle:{{ .Tag }}-armv7
|
||||
- name_template: ghcr.io/fission/pre-upgrade-checks:{{ .Tag }}
|
||||
image_templates:
|
||||
- ghcr.io/fission/pre-upgrade-checks:{{ .Tag }}-amd64
|
||||
- ghcr.io/fission/pre-upgrade-checks:{{ .Tag }}-arm64
|
||||
- ghcr.io/fission/pre-upgrade-checks:{{ .Tag }}-armv7
|
||||
- name_template: fission/pre-upgrade-checks:{{ .Tag }}
|
||||
image_templates:
|
||||
- fission/pre-upgrade-checks:{{ .Tag }}-amd64
|
||||
- fission/pre-upgrade-checks:{{ .Tag }}-arm64
|
||||
- fission/pre-upgrade-checks:{{ .Tag }}-armv7
|
||||
- name_template: ghcr.io/fission/reporter:{{ .Tag }}
|
||||
image_templates:
|
||||
- ghcr.io/fission/reporter:{{ .Tag }}-amd64
|
||||
- ghcr.io/fission/reporter:{{ .Tag }}-arm64
|
||||
- ghcr.io/fission/reporter:{{ .Tag }}-armv7
|
||||
- name_template: fission/reporter:{{ .Tag }}
|
||||
image_templates:
|
||||
- fission/reporter:{{ .Tag }}-amd64
|
||||
- fission/reporter:{{ .Tag }}-arm64
|
||||
- fission/reporter:{{ .Tag }}-armv7
|
||||
- name_template: ghcr.io/fission/builder:latest
|
||||
image_templates:
|
||||
- ghcr.io/fission/builder:latest-amd64
|
||||
- ghcr.io/fission/builder:latest-arm64
|
||||
- ghcr.io/fission/builder:latest-armv7
|
||||
- name_template: fission/builder:latest
|
||||
image_templates:
|
||||
- fission/builder:latest-amd64
|
||||
- fission/builder:latest-arm64
|
||||
- fission/builder:latest-armv7
|
||||
- name_template: ghcr.io/fission/fetcher:latest
|
||||
image_templates:
|
||||
- ghcr.io/fission/fetcher:latest-amd64
|
||||
- ghcr.io/fission/fetcher:latest-arm64
|
||||
- ghcr.io/fission/fetcher:latest-armv7
|
||||
- name_template: fission/fetcher:latest
|
||||
image_templates:
|
||||
- fission/fetcher:latest-amd64
|
||||
- fission/fetcher:latest-arm64
|
||||
- fission/fetcher:latest-armv7
|
||||
- name_template: ghcr.io/fission/fission-bundle:latest
|
||||
image_templates:
|
||||
- ghcr.io/fission/fission-bundle:latest-amd64
|
||||
- ghcr.io/fission/fission-bundle:latest-arm64
|
||||
- ghcr.io/fission/fission-bundle:latest-armv7
|
||||
- name_template: fission/fission-bundle:latest
|
||||
image_templates:
|
||||
- fission/fission-bundle:latest-amd64
|
||||
- fission/fission-bundle:latest-arm64
|
||||
- fission/fission-bundle:latest-armv7
|
||||
- name_template: ghcr.io/fission/pre-upgrade-checks:latest
|
||||
image_templates:
|
||||
- ghcr.io/fission/pre-upgrade-checks:latest-amd64
|
||||
- ghcr.io/fission/pre-upgrade-checks:latest-arm64
|
||||
- ghcr.io/fission/pre-upgrade-checks:latest-armv7
|
||||
- name_template: fission/pre-upgrade-checks:latest
|
||||
image_templates:
|
||||
- fission/pre-upgrade-checks:latest-amd64
|
||||
- fission/pre-upgrade-checks:latest-arm64
|
||||
- fission/pre-upgrade-checks:latest-armv7
|
||||
- name_template: ghcr.io/fission/reporter:latest
|
||||
image_templates:
|
||||
- ghcr.io/fission/reporter:latest-amd64
|
||||
- ghcr.io/fission/reporter:latest-arm64
|
||||
- ghcr.io/fission/reporter:latest-armv7
|
||||
- name_template: fission/reporter:latest
|
||||
image_templates:
|
||||
- fission/reporter:latest-amd64
|
||||
- fission/reporter:latest-arm64
|
||||
- fission/reporter:latest-armv7
|
||||
changelog:
|
||||
skip: false
|
||||
archives:
|
||||
- id: fission
|
||||
builds:
|
||||
- fission-cli
|
||||
name_template: "{{ .ProjectName }}-{{ .Tag }}-{{ .Os }}-{{ .Arch }}"
|
||||
format: binary
|
||||
checksum:
|
||||
name_template: "checksums.txt"
|
||||
algorithm: sha256
|
||||
|
||||
# signs the checksum file
|
||||
# https://goreleaser.com/customization/sign
|
||||
signs:
|
||||
- cmd: cosign
|
||||
artifacts: all
|
||||
stdin: '{{ .Env.COSIGN_PWD }}'
|
||||
output: true
|
||||
args:
|
||||
- sign-blob
|
||||
- '--key=cosign.key'
|
||||
- '--output-certificate=${certificate}'
|
||||
- '--output-signature=${signature}'
|
||||
- '${artifact}'
|
||||
- '--yes' # needed for cosign 2.0.0+
|
||||
|
||||
# signs our docker image
|
||||
# https://goreleaser.com/customization/docker_sign
|
||||
docker_signs:
|
||||
- cmd: cosign
|
||||
artifacts: all
|
||||
stdin: '{{ .Env.COSIGN_PWD }}'
|
||||
output: true
|
||||
args:
|
||||
- 'sign'
|
||||
- '--key=cosign.key'
|
||||
- '${artifact}'
|
||||
- '--yes' # needed for cosign 2.0.0+
|
||||
@@ -0,0 +1,17 @@
|
||||
pull_request_rules:
|
||||
- name: Automatic merge on approval
|
||||
conditions:
|
||||
- base=main
|
||||
- "#approved-reviews-by>=1"
|
||||
- label=ready-to-merge
|
||||
- label!=hold-off-merging
|
||||
- check-success=CodeQL-Build
|
||||
- check-success=CodeQL
|
||||
- check-success=lint
|
||||
- check-success=upgrade-test (kindest/node:v1.23.17, ubuntu-latest)
|
||||
- check-success=integration-test (v1.23.17, ubuntu-latest)
|
||||
- check-success=integration-test (v1.25.11, ubuntu-latest)
|
||||
- check-success=integration-test (v1.27.3, ubuntu-latest)
|
||||
actions:
|
||||
merge:
|
||||
method: squash
|
||||
-61
@@ -1,61 +0,0 @@
|
||||
sudo: required
|
||||
|
||||
dist: trusty
|
||||
|
||||
branches:
|
||||
only:
|
||||
- master
|
||||
|
||||
language: go
|
||||
|
||||
go:
|
||||
- 1.12.x
|
||||
|
||||
env:
|
||||
- KUBECONFIG=${HOME}/.kube/config PATH=$HOME/k8scli:$HOME/tool:$HOME/google-cloud-sdk/bin:${PATH} GO111MODULE=on DOCKER_CACHE_DIR=${HOME}/docker/
|
||||
|
||||
cache:
|
||||
directories:
|
||||
- $HOME/google-cloud-sdk/
|
||||
- $HOME/k8scli
|
||||
- $HOME/tool
|
||||
- $HOME/.cache/go-build
|
||||
- $HOME/gopath/pkg/mod
|
||||
|
||||
services:
|
||||
- docker
|
||||
|
||||
before_install:
|
||||
- sudo apt-get update
|
||||
# - sudo apt-get -y -o Dpkg::Options::="--force-confnew" install docker-ce
|
||||
- sudo apt-get -y install apache2-utils parallel realpath
|
||||
- sudo sysctl net.ipv6.conf.all.disable_ipv6=0
|
||||
|
||||
install:
|
||||
- hack/travis-kube-setup.sh
|
||||
|
||||
before_script:
|
||||
- cd ${TRAVIS_BUILD_DIR}
|
||||
- go mod download
|
||||
- hack/verify-staticcheck.sh
|
||||
- hack/verify-gofmt.sh
|
||||
- hack/verify-govet.sh
|
||||
- helm lint charts/fission-all/ charts/fission-core/
|
||||
- hack/runtests.sh
|
||||
- test/build.sh
|
||||
|
||||
script:
|
||||
- cd ${TRAVIS_BUILD_DIR}
|
||||
- test/test.sh
|
||||
- test/upgrade/fission_upgrade_test.sh
|
||||
|
||||
after_script:
|
||||
- bash <(curl -s https://codecov.io/bash)
|
||||
- kubectl --namespace default delete configmap -l travisID=${TRAVIS_BUILD_ID} # remove in-test configmap to indicate this CI build finished
|
||||
|
||||
notifications:
|
||||
slack:
|
||||
rooms:
|
||||
secure: YZ34vsfw1TtftJypg1MyP4+ihONI4gaxeS3FghBQli6+EezjzcxOXyj5VD+x0ucXfDeTaDrFfmVN0SAGObOoZUE+ea9KAoTo50tRLaD9kwOTACiekZalC4uuBguH0D1/A6vlbU8dchsr9mvIhbisG6mTncdPtqGYYHtyBQme6ngmmHbVAQFZcIBHmNuDb/HWhSr8KMEuyB6+mBXLYELHnXnf26cOhdGNaagqCOJTiemX85RGwIuOPxyBhKDFMLyHohDT7FJMH/qijveE6YgOYTQC5nYc2Np1KvC7hQkIu4nuyczyYlrNQl/TWv+SVI8PjIs0PYuCuD3gUqoVEi8d94HbrOPzFEpbwDS9P4qL39DGmco1Q56Vqxe6sRI0vDWPb5gCP1lSgs3PMECVn7Wor/pTvcL+C+U2jLwWJUl0vbyWCL7ngl/3iTssV7qBpUrI7Oclwp8LrQo9fPj0DL4gE9rNanpEWjQ6yPGaysIL1zLHtRghhm52A22NJGp71jkS2KEpLi6ZWFYjMeuXw5eOQFhqFlzyRJOmLYa3B607TLWuyo2L2CxAfMmq0FGfemvrkLZIWtlQKK4y9ImpsURwaGT2XCtThFtHl77wEss913nC+T2dX3O5Bl0UmxFd5S3mVM109I8c4lDosxnAjRfS9MheFlrG0gjSJSBCw57x7f0=
|
||||
on_success: change
|
||||
on_failure: always
|
||||
+793
-309
File diff suppressed because it is too large
Load Diff
+5
-40
@@ -1,45 +1,10 @@
|
||||
# Contributing to Fission
|
||||
|
||||
### Thank you!
|
||||
Thanks for helping make Fission better😍!
|
||||
|
||||
Thank you for taking the time and effort to contribute to Fission!
|
||||
There are many areas we can use contributions - ranging from code, documentation, feature proposals, issue triage, samples, and content creation.
|
||||
|
||||
First, please read the [code of conduct](CODE_OF_CONDUCT.md). By
|
||||
participating, you're expected to uphold this code.
|
||||
First, please read the [code of conduct](CODE_OF_CONDUCT.md). By participating, you're expected to uphold this code.
|
||||
|
||||
### Choose something to work on
|
||||
Please refer contributing docs for detailed guide.
|
||||
|
||||
The easiest way to start is to look at existing
|
||||
[issues](https://github.com/fission/fission/issues) and see if there's
|
||||
something there that you'd like to work on.
|
||||
|
||||
Also, if you're familiar with a language that we don't support today,
|
||||
adding an environment for a new language is a good task to take on.
|
||||
Take a look at the Python environment as an example.
|
||||
|
||||
If you're interested in working on something that doesn't have an
|
||||
existing issue, feel free to file a new one.
|
||||
|
||||
There's plenty of stuff to do. If you need help choosing something to
|
||||
work on, we'll be happy to suggest something depending on your
|
||||
interests.
|
||||
|
||||
### Talk to people
|
||||
|
||||
At any point, from thinking about contributing to merging your
|
||||
changes, please feel free to reach out to us! We're more than happy
|
||||
to talk.
|
||||
|
||||
If you choose a big chunk of work that involves design changes to
|
||||
Fission, please talk to us while planning the change; that way we can
|
||||
all be on the same page before you invest too much work into it.
|
||||
|
||||
* Drop by the [slack channel](http://slack.fission.io).
|
||||
* Say hi on [twitter](https://twitter.com/fissionio).
|
||||
|
||||
### Contribution Howto
|
||||
|
||||
* Fork this github repo
|
||||
* Make a branch in your fork
|
||||
* Commit your changes to that branch
|
||||
* Create a pull request
|
||||
[https://fission.io/docs/contributing/](https://fission.io/docs/contributing/)
|
||||
|
||||
@@ -1,200 +0,0 @@
|
||||
# A high-level view of the internals of Fission.
|
||||
|
||||
## How it works
|
||||
|
||||
Fission is a FaaS -- users create functions (source level), register
|
||||
them with Fission using a CLI, and associate functions with triggers.
|
||||
|
||||
Fission wraps those functions into a service and runs them on
|
||||
Kubernetes on demand.
|
||||
|
||||
Here's an overview of the services that make up Fission.
|
||||
|
||||
## Components
|
||||
|
||||
Core Components:
|
||||
* Controller
|
||||
* Executor
|
||||
* Environment Container (language-specific)
|
||||
* Router
|
||||
* Builder Manager
|
||||
* Storage Service
|
||||
|
||||
Optional Components:
|
||||
* Logger
|
||||
* Kubewatcher
|
||||
* Message Queue Trigger
|
||||
* Timer
|
||||
|
||||
Third-party components:
|
||||
* InfluxDB: To store function logs.
|
||||
* Prometheus: For metric collection and canary deployment.
|
||||
* NATS Streaming: For message queue trigger. (Kafka, Azure are not included in charts deployment.)
|
||||
|
||||
## Core Components
|
||||
|
||||
### Controller
|
||||
|
||||
The controller contains CRUD APIs for functions, triggers, environments,
|
||||
Kubernetes event watches, etc. This is the component that the client talks to.
|
||||
|
||||
All fission resources are stored in kubernetes CRDs. It needs to be able to
|
||||
talk to kubernetes API service.
|
||||
|
||||
### Executor
|
||||
|
||||
The executor has two simple APIs; the router calls both these endpoints.
|
||||
|
||||
* GetFunctionService takes function metadata and dispatches the corresponding executor
|
||||
type to get the address of a service/pod and returns it to the router.
|
||||
|
||||
* TapService lets executor know a service/pod is being used; if it's not
|
||||
called for a few minutes the pod(s) backing the service are killed.
|
||||
|
||||
It now supports two different executor types:
|
||||
|
||||
* PoolManager
|
||||
* NewDeploy
|
||||
|
||||
These two executor types have different strategies to launch, specialize, and manage pod(s).
|
||||
You should choose one of the executor types wisely based on the scenario.
|
||||
|
||||
#### PoolManager
|
||||
|
||||
PoolManager manages pools of generic containers and function containers.
|
||||
|
||||
PoolManager watches the environment CRD changes and eagerly creates generic pools
|
||||
for environments. It uses Kubernetes deployments to do that. The
|
||||
environment container runs in a pod with the 'fetcher' container.
|
||||
Fetcher is a straightforward utility that downloads a URL sent to it
|
||||
and saves it at a configured location (shared volume).
|
||||
|
||||
The implementation chooses a generic pod from the pool, relabels it to
|
||||
"orphan". The pod from the deployment invokes fetcher to copy the function
|
||||
into the pod and hits the specialize endpoint on the environment container.
|
||||
This causes the function to be loaded. The pod is now specific to that
|
||||
function. This function pod is cached; it's cleaned up if it's unused for a few minutes.
|
||||
|
||||
PoolManager selects a generic pod from the warm pool, specializes it,
|
||||
and recycles the pod if there are no further requests to the function after a few minutes.
|
||||
It makes PoolManager suitable for functions that are short-living
|
||||
and requires a short cold start time [1].
|
||||
|
||||
However, PoolManager only selects one pod per function, which is not
|
||||
suitable for serving massive traffic. In such cases, you should consider
|
||||
using NewDeploy as executor type of function.
|
||||
|
||||
[1] The cold start time depends on the package size of the function. If it's
|
||||
a snippet of code, the cold start time usually is less then 100ms.
|
||||
|
||||
#### NewDeploy
|
||||
|
||||
NewDeploy creates deployment, service, and HPA for functions in order to handle
|
||||
massive traffic.
|
||||
|
||||
NewDeploy watches the function CRD changes and creates a Kubernetes deployment,
|
||||
service, and HPA for a function. NewDeploy will scale the replicas of a function
|
||||
deployment to the minimum feasible scale setting, if the minimum scale setting of
|
||||
a function is greater than 0. The 'fetcher' inside the pod uses a URL in the
|
||||
JSON payload, which is attached as a parameter to start fetcher, to download the
|
||||
function package instead of waiting for calls from NewDeploy.
|
||||
|
||||
When a function experiences a traffic spike, the service helps to distribute the requests to
|
||||
pods belonging to the function for better workload distribution and lower latency. Also,
|
||||
the HPA scales the replicas of the deployment based on the conditions set by the user.
|
||||
|
||||
This approach though increases the cold time of a function, but also makes NewDeploy
|
||||
suitable for functions designed to serve massive traffic.
|
||||
|
||||
### Environment Container
|
||||
|
||||
Environment containers run user-defined functions and are language-specific.
|
||||
Each environment container must contain an HTTP server and a loader for functions.
|
||||
|
||||
The pool manager deploys the environment container into a pod with fetcher
|
||||
(fetcher is a simple utility that can fetch an HTTP URL to a file at a
|
||||
configured location). This pod forms a "generic pod" because it can
|
||||
be loaded with any function in that coding language.
|
||||
|
||||
When the pool manager needs to create a service for a function, it calls
|
||||
fetcher to fetch the function. Fetcher downloads the function into a
|
||||
volume shared between fetcher and this environment container. Poolmgr
|
||||
then requests the container to load the function.
|
||||
|
||||
### Router
|
||||
|
||||
The router forwards HTTP requests to function pods. If there's no
|
||||
running service for a function, it requests one from executor, while
|
||||
holding on to the request; the router will forward the request to
|
||||
the pod once the function service is ready.
|
||||
|
||||
The router is the only stateless component and can be scaled up if needed, according to
|
||||
load.
|
||||
|
||||
### Builder Manager
|
||||
|
||||
The builder manager watches the package & environments CRD changes and manages
|
||||
the builds of function source code. Once an environment that contains a builder
|
||||
image is created, the builder manager will then creates the Kubernetes service
|
||||
and deployment under the fission-builder namespace to start the environment
|
||||
builder. And once a package that contains a source archive is created, the
|
||||
builder manager talks to the environment builder to build the function's source
|
||||
archive into a deploy archive for function deployment.
|
||||
|
||||
After the build, the builder manager asks Builder to upload the deploy archive to the
|
||||
Storage Service once the build succeeded, and updates the package status attached with build logs.
|
||||
|
||||
### Storage Service
|
||||
|
||||
The storage service is the home for all archives of packages with sizes larger than 256KB.
|
||||
The Builder pulls the source archive from the storage service and uploads deploy archive to it.
|
||||
The fetcher inside the function pod also pulls the deploy archive for function specialization.
|
||||
|
||||
## Optional Components
|
||||
|
||||
### Logger
|
||||
|
||||
Logger is deployed as DaemonSet to help to forward function logs to a centralized
|
||||
database service for log persistence. Currently, only InfluxDB is supported to store logs.
|
||||
|
||||
Following is a diagram describe how log service works:
|
||||
1. Logger watches pod changes and creates a symlink to the container log if the pod runs on the same node.
|
||||
2. Fluentd reads logs from symlink and pipes them to InfluxDB
|
||||
3. `fission function logs ...` retrieve event logs from InfluxDB with optional log filter
|
||||
4. Logger removes the symlink if the pod no longer exists.
|
||||
|
||||
### Kubewatcher
|
||||
|
||||
Kubewatcher watches the Kubernetes API and invokes functions
|
||||
associated with watches, sending the watch event to the function.
|
||||
|
||||
The controller keeps track of the user's requested watches and associated
|
||||
functions. Kubewatcher watches the API based on these requests; when
|
||||
a watch event occurs, it serializes the object and calls the function
|
||||
via the router.
|
||||
|
||||
While a few simple retries are done, there isn't yet a reliable
|
||||
message bus between Kubewatcher and the function. Work for this is
|
||||
tracked in issue #64.
|
||||
|
||||
### Message Queue Trigger
|
||||
|
||||
A message queue trigger binds a message queue topic to a function:
|
||||
Events from that topic cause the function to be invoked with the
|
||||
message as the body of the request. The trigger may also contain a
|
||||
response topic: if specified, the function's output is sent to this
|
||||
response.
|
||||
|
||||
Here's a diagram of the components:
|
||||
|
||||

|
||||
|
||||
### Timer
|
||||
|
||||
The timer works like kubernetes CronJob but instead of creating a pod to do the task,
|
||||
it sends a request to router to invoke the function. It's suitable for the background tasks that
|
||||
need to executor periodically.
|
||||
|
||||
The timer works like a Kubernetes CronJob, but instead of creating a
|
||||
pod to do the task, it sends a request to the router to invoke the
|
||||
function. It is suitable for background tasks that need to execute periodically.
|
||||
@@ -1,4 +0,0 @@
|
||||
Fission Document
|
||||
=================
|
||||
|
||||
* Please visit [here](https://docs.fission.io/) for fission documentation.
|
||||
@@ -1,106 +0,0 @@
|
||||
# Fission Roadmap
|
||||
|
||||
## Function features ([area-func](https://github.com/fission/fission/labels/area-func))
|
||||
|
||||
- Secrets, configmaps, env vars
|
||||
- Volumes
|
||||
- Mem requests and limits
|
||||
- Function exec time deadline
|
||||
- Expose a regular K8s Service for a function
|
||||
|
||||
## Fission API ([area-api](https://github.com/fission/fission/labels/area-api))
|
||||
|
||||
- CRD-based controller
|
||||
- API authentication
|
||||
- Aggregated API server
|
||||
|
||||
## Development Workflows ([area-dev](https://github.com/fission/fission/labels/area-dev))
|
||||
|
||||
- Function Versioning
|
||||
- Versioning for a group of functions
|
||||
- Rolling upgrades
|
||||
- for one function
|
||||
- for multiple functions
|
||||
- for functions + other kubernetes deployments
|
||||
- Unit testing
|
||||
|
||||
## API Gateway / Ingress features ([area-ingress](https://github.com/fission/fission/labels/area-ingress))
|
||||
|
||||
- Function authn hooks
|
||||
- K8s Ingress flag
|
||||
- Bundle an ingress controller?
|
||||
|
||||
## Workflows and Function composition ([area-composition](https://github.com/fission/fission/labels/area-composition))
|
||||
|
||||
- Simple Composition - Sync
|
||||
- Simple Composition - Async
|
||||
- Hooks (pre, post, on-error)
|
||||
- Workflows
|
||||
- Testing in the presence of function composition
|
||||
|
||||
## Events ([area-events](https://github.com/fission/fission/labels/area-events))
|
||||
|
||||
- NATS
|
||||
- Kafka
|
||||
- AWS: SNS, SQS
|
||||
- Google PubSub
|
||||
- RabbitMQ
|
||||
- Other event sources
|
||||
|
||||
- Bundle an event queue (NATS streaming, most probably)
|
||||
|
||||
## Operability ([area-ops](https://github.com/fission/fission/labels/area-ops))
|
||||
|
||||
### Fission Install/Upgrade ([area-install](https://github.com/fission/fission/labels/area-install))
|
||||
|
||||
- Helm Installer for Fission
|
||||
- Helm installation for fission functions
|
||||
- CLI installer/upgrader? ("fission upgrade")
|
||||
- Upgrade checker/reminder (like minikube does)
|
||||
- CLI auto-upgrader
|
||||
|
||||
### Function observation ([area-observe](https://github.com/fission/fission/labels/area-observe))
|
||||
|
||||
- Function Logging
|
||||
- Tracing -- Opentracing
|
||||
- Metrics -- Prometheus
|
||||
- Function exception tracking
|
||||
- Logging function load errors
|
||||
- Tracing fission overheads for each function
|
||||
|
||||
## Function Security
|
||||
|
||||
- Function isolation (is authz hook sufficient or do we need something like mutual TLS?)
|
||||
- Function service accounts
|
||||
|
||||
## UX, especially for beginners ([area-ux](https://github.com/fission/fission/labels/area-ux))
|
||||
|
||||
- Fission CLI should include a tutorial
|
||||
- Fission CLI should have a way to drop you into the UI
|
||||
- Eliminate FISSION_URL, just use kube client to find fission url. Also useful to grab credentials.
|
||||
|
||||
## Documentation ([area-doc](https://github.com/fission/fission/labels/area-doc))
|
||||
|
||||
- Installation guide improvements
|
||||
- Troubleshooting guide for common problems
|
||||
- FAQ
|
||||
- Performance overview
|
||||
- Render docs nicely to fission.io
|
||||
|
||||
## Web UI (tracked separately in the fission-ui repo)
|
||||
|
||||
## Performance and Scalability ([area-perf](https://github.com/fission/fission/labels/area-perf))
|
||||
|
||||
- Autoscaling
|
||||
- Cold-start optimization -- optimistically choose from pool, save about ~20msec
|
||||
- Cold-start optimization -- preload funcs in fetcher
|
||||
- Cold-start optimization -- preload libraries in envs (v2) -- mem vs. speed tradeoff
|
||||
|
||||
## Function extensibility ([area-ext](https://github.com/fission/fission/labels/area-ext))
|
||||
|
||||
- Env v2: easy addition of dependencies etc.
|
||||
- Integration with Service Broker
|
||||
|
||||
## Multi-area stuff
|
||||
|
||||
- Execution strategies: cold-start pool vs create-pod-on-cold-start -- one size doesn't fit all, at least with current tech; abstract over execution strategies according to requirements
|
||||
@@ -1,66 +0,0 @@
|
||||
# Multi-tenancy in Fission
|
||||
|
||||
Multi-tenancy in Fission allows users to create Fission objects, i.e functions, packages, environments and triggers in different namespaces.
|
||||
It mandates that a function reference secrets, configmaps and its package (if explicity referenced during function creation/updation) to be present in the same namespace as the function.
|
||||
This allows user separation and prevents in-advertent access to sensitive data of other users sharing the same cluster.
|
||||
However, users are allowed and encouraged to share environments to ensure optimal utilization of cluster resources. To achieve this, users can create all the necessary environments in a ns, say ns1 and then go on to create functions in different namespaces and refer to env in ns1.
|
||||
Users that prefer complete isolation can create their env, functions in the same ns.
|
||||
|
||||
## Roles and privileges
|
||||
|
||||
1. Cluster-Admin Role : Fission's services need cluster-admin privileges to monitor, create, update and delete resources across namespaces.
|
||||
2. Package-getter Role : This role has privileges to do a get, watch and list on fission package objects.
|
||||
3. Secret-Configmap-getter Role : This role has privileges to do a get, watch and list on secrets and configmaps.
|
||||
|
||||
## Service Accounts
|
||||
|
||||
1. fission-fetcher
|
||||
|
||||
This SA is created in every namespace that a user creates runtime environments in.
|
||||
Also created in function namespaces where a user creates functions that use NewDeploy executor backend.
|
||||
|
||||
2. fission-builder
|
||||
|
||||
This SA is created in every namespace that a user creates builder environments in.
|
||||
|
||||
## Role-bindings
|
||||
|
||||
1. Package-getter-binding
|
||||
|
||||
Every time a user creates a package explicity in a namespace, this rolebinding is created in package's namespace (which is also function's namespace). This grants package-getter role to fission-fetcher SA present in the referenced environment's namespace.
|
||||
If the package is a source package, then, fission-builder SA present in the environment namespace is also added to this rolebinding.
|
||||
|
||||
Next when the user creates a function in the same namespace, if the function's executor type is newdeploy, then, the fission-fetcher SA present in function namespace is also added to the same rolebinding.
|
||||
|
||||
Note : For functions that have executor type poolmgr, the env pods are created in the namespace that env object is created. Whereas, for those functions that have executor type New deploy mgr, the function pods are created in the namespace that function object is created in.
|
||||
|
||||
This is because, poolmgr allows env sharing and optimal resource utilization. so generic env pools are created in a different namespace and all functions that prefer sharing this env pool can reference these pools.
|
||||
If users require strict isolation, they can either create functions with new deploy backend, or, create env's in different namespaces and not share them across functions.
|
||||
|
||||
2. Secret-Configmap-getter-binding
|
||||
|
||||
Every time a user creates a function in a namespace, Secret-Configmap-getter-binding is created in the same namespace, granting secret-configmap-getter role to fission-fetcher SA present in the referenced environment's namespace in case the executor type is poolmgr.
|
||||
If the executor type is newdeploymgr, then the same rolebinding is created in the same namespace as the function, granting the same secret-configmap-getter role to fission-fetcher SA present in the function namespace.
|
||||
|
||||
## Examples
|
||||
|
||||
1. create a generic python runtime env in ns 1 and function with poolmgr executor type in ns 2 that references it.
|
||||
|
||||
```bash
|
||||
$ fission env create --name python --image fission/python-env --envns ns1
|
||||
$ fission function create --name func1 --env python --code hello.py --fns ns2
|
||||
```
|
||||
|
||||
2. create a builder and runtime environment in ns3, a source pkg in ns3 and a function referring to this src pkg also in ns3. (for complete isolation, all objs are in ns3)
|
||||
|
||||
```bash
|
||||
$ fission env create --name python-builder-env --builder fission/python-builder --image fission/python-env --ns3
|
||||
$ fission package create --src src-pkg.zip --env python-builder-env --buildcmd "./build.sh" --pkgns ns3
|
||||
$ fission fn create --name func3 --fns ns3 --pkg $pkg --entrypoint "user.main"
|
||||
```
|
||||
|
||||
## Note
|
||||
|
||||
1. To maintain backward compatibility, fission objects that are created without the ns flags are created in default namespace. Also, the run time env pods in such a case will continue to live in fission-function ns and builder env pods in fission-builder ns
|
||||
2. Since all envs in a namespace have the same fission-fetcher SA mounted in them, even though multiple envs are created in a namespace and referenced by functions in different namespaces, the SA will have previleges to view those function's secrets if any.
|
||||
3. Similarly, if there are multiple functions in different namespaces but all sharing an env in one namespace, the fission-fetcher SA in that namespace will have previleges to see all of their secrets.
|
||||
@@ -1,24 +0,0 @@
|
||||
# Programming Model
|
||||
|
||||
This document describes the programming model for fission functions.
|
||||
|
||||
## Time Limits
|
||||
|
||||
By default, there is no time limit on fission functions.
|
||||
|
||||
Idle running instances may be killed at any time (usually after the
|
||||
default idle timeout of 10 minutes, but this is configurable).
|
||||
|
||||
|
||||
## HTTP Triggers
|
||||
|
||||
Functions triggered over HTTP receive the HTTP request object in the
|
||||
context. The request's query string, POST body, etc. can be retrieved
|
||||
from this object. The interface is language-specific: see [TODO] for
|
||||
documentation on the context object in each environment.
|
||||
|
||||
|
||||
## Kubernetes Watch Event Triggers
|
||||
|
||||
Kubernetes watches can be used to trigger functions. These functions
|
||||
receive the Kubernetes watch.Event object in JSON-serialized form.
|
||||
@@ -1,91 +0,0 @@
|
||||
# Annotations
|
||||
|
||||
Annotations are used by the core Kubernetes system and to even larger extent by projects such as Istio Ingress Controllers and Prometheus and such.
|
||||
|
||||
Users want to add annotations to some objects such as ingress (https://github.com/fission/fission/issues/989).
|
||||
|
||||
To enable the users to use annotations, here are some thoughts and ideas:
|
||||
|
||||
## Defining annotations
|
||||
|
||||
Annotations can be defined fairly easily in the spec file for any object as part of metadata.
|
||||
|
||||
``` yaml
|
||||
apiVersion: fission.io/v1
|
||||
kind: HTTPTrigger
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: spectest
|
||||
namespace: default
|
||||
annotations:
|
||||
test-anno: some-test-value
|
||||
spec:
|
||||
createingress: true
|
||||
```
|
||||
|
||||
These annotations can be merged to target object using a merging mechanism - so that additional annotations put by Fission can also be preserved.
|
||||
|
||||
## Considerations
|
||||
|
||||
- More often than not the annotations are needed by a Kubernetes objects created by one of the function CRDs/controllers. For example ingress created by route needs the annotation and not the route object itself.
|
||||
|
||||
### Implementation 1
|
||||
|
||||
- Most annotations use a convention which we can use to determine if an annotation is meant for an ingress object or to be applied on a pod.
|
||||
|
||||
For example. look at annotations:
|
||||
|
||||
|Annotation name| Description|
|
||||
|:-------------|:-------------|
|
||||
|`prometheus.io/scrape`| Prometheus - applied to pod|
|
||||
|`sidecar.istio.io/inject`|Istio - applied to pod|
|
||||
|`helm.sh/hook`| Used by helm to apply to pods/jobs|
|
||||
|`traefik.ingress.kubernetes.io/app-root`|Used by Trafeik ingress controller, applied to ingress|
|
||||
|`nginx.ingress.kubernetes.io/add-base-url`|Used by Nginx ingress controller, applied to ingress|
|
||||
|
||||
So we can write a simple logic - to check if a annotation is applicable for an ingress and based on that apply or not apply annotations to ingress.
|
||||
|
||||
|
||||
### Implementation 2
|
||||
|
||||
- One of side effects of this is that the annotations will still stay on the source CRD object - for example annotation will stay on the httptrigger as well as the ingress object. This can cause problems in certain cases where something like Prometheus uses annotations to scrape objects. So instead we wrap the annotations needed by an object into another annotation name. This also solves problem of having to guess which annotations to apply to which object.
|
||||
|
||||
```yaml
|
||||
apiVersion: fission.io/v1
|
||||
kind: HTTPTrigger
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: spectest
|
||||
namespace: default
|
||||
annotations:
|
||||
ingress-annotations: '{"nginx.ingress.kubernetes.io/add-base-url": "true", "nginx.ingress.kubernetes.io/app-root": "somevalue"}'
|
||||
```
|
||||
|
||||
|
||||
This is specifically important because for example newdeploy function will create a deployment, service and HPA and all three might have different set of annotations.
|
||||
|
||||
```yaml
|
||||
annotations:
|
||||
service-annotations: '{"service.annotation1": "somevalue"}'
|
||||
deployment-annotations: '{"deploy.annotation1": "somevalue"}'
|
||||
```
|
||||
|
||||
### Implementation 3
|
||||
|
||||
Based on discussion in the team there is a additional option of adding a explicit field in the spec to hold the annotations. For now this assumes that we are only considering HTTPTriggers for annotations and not other objects such as Functions.
|
||||
|
||||
```
|
||||
HTTPTriggerSpec struct {
|
||||
Host string `json:"host"`
|
||||
RelativeURL string `json:"relativeurl"`
|
||||
CreateIngress bool `json:"createingress"`
|
||||
Method string `json:"method"`
|
||||
FunctionReference FunctionReference `json:"functionref"`
|
||||
Annotations map[string]string `json:annotations`
|
||||
}
|
||||
```
|
||||
|
||||
## Final thoughts
|
||||
|
||||
- The implementation idea 2 & 3 look better than 1. The third option involves HTTPTrigger Spec change.
|
||||
- For both (2) & (3) - if in future we have to implement annotations for Functions etc. we will have to consider the fact that a function will in turn create 3 objects (Service, Pod & HPA) and annotations for all three would need to be accommodated.
|
||||
@@ -1,101 +0,0 @@
|
||||
# Continuous Integration and Delivery of Fission functions
|
||||
|
||||
This document outlines a simple CI/CD process for Fission functions which can be extended to any CI/CD tool. Before we start, some level setting for terminology used as the terms are used rather broadly in industry.
|
||||
|
||||
## Continuous Integration
|
||||
|
||||
CI is made up of a series of broad areas:
|
||||
|
||||
- The first step is to compile the source code and convert into artifact which is pushed to artifact repository. Traditionally this has been building a Py or wheel package (Python) or Jar file (Java) but as containers became mainstream the container image became the package. The traditional artifact repositories were replaced by the Docker registries.
|
||||
|
||||
- Execution and reporting of unit testing has been a crucial part of the CI cycle and is done after the source code can be compiled successfully.
|
||||
|
||||
- Running a static/dynamic code analyzer is the next step in continuous integration. The static code analysis is usually used to measure and report quality metrics and dynamic code scanning/analysis for security.
|
||||
|
||||
In the draft version of this proposal we will only consider the source to artifact conversion part and will not dive into unit testing or code scanning/analysis cycles of the CI.
|
||||
|
||||
## Continuous Delivery
|
||||
|
||||
CD is also composed of a few broad areas focusing on different aspects:
|
||||
|
||||
- After CI cycle completes successfully - deploying the artifact to a Dev/Staging environment so that it can be tested by developers and QA teams.
|
||||
|
||||
- Once the tests & teams have verified that a function works, the same function should be promoted from Dev/Stage to higher/production environment. The number of environment that a organization maintains varies but the idea of promotion from one environment to higher environment does exist. There are very few organizations who deploy the newer versions of functions directly in production with a A/B setup but that is as of this writing is an exception and not the norm.
|
||||
|
||||
- Another aspect of promoting from one environment to higher environment is the configuration for both environments will be different. For ex. the DB connection string will be different for each environment. Or the "maxscale" property for production environment could be higher than that for Dev. The ability to store all these environment specific configurations in some sort of system (Github for normal values and some sort of KMS for sensitive data) and being able to combine the logic and configurations for each environment when deploying is important.
|
||||
|
||||
Beyond these points there are integration/automation points such as being able to call a test suite after deployment is done etc. but we will skip for now for brevity.
|
||||
|
||||
## 1 Fission specs in a container
|
||||
|
||||
Let's start with a simple Fission function which uses specs. A typical directory structure looks like below:
|
||||
|
||||
```
|
||||
.
|
||||
├── multifile
|
||||
│ ├── README.md
|
||||
│ ├── __init__.py
|
||||
│ ├── main.py
|
||||
│ ├── message.txt
|
||||
│ └── readfile.py
|
||||
└── specs
|
||||
├── README
|
||||
├── env-python.yaml
|
||||
├── fission-deployment-config.yaml
|
||||
└── function-pyz.yaml
|
||||
```
|
||||
|
||||
Irrespective of if source code that needs to be built or not, there is a simple command to fire to update the function, which will build (if applicable) and deploy the function:
|
||||
|
||||
```
|
||||
$ fission spec apply
|
||||
```
|
||||
|
||||
If we look at this from CI/CD perspective this process requires:
|
||||
1. Source code & specs
|
||||
2. A github push event when any one of the two change
|
||||
3. Fission CLI
|
||||
4. Kubernetes Config so that the apply command can be run
|
||||
|
||||
So if we build a container - which has the above requirements met as installed software (Ex. Fission & Kubectl CLI) or available as environment variable (Github pull token or Kubeconfig), the container can be used as part of CI workflow in any tool such as - Jenkins, Argo, Github Actions, Gitlab etc.
|
||||
|
||||
The idea is to build a generic container with Fission CLI, Kubernetes CLI and a way to read Github token and Kubeconfig from env variable/mounted files and being able to run `fission spec apply` command.
|
||||
|
||||
### 1.1
|
||||
|
||||
Instead of building a container in previous section - the same can be achieved by a function. The Github webhook can call a function endpoint which in turn can execute the process similar to inside the container.
|
||||
|
||||
## 2 Environment Configurations
|
||||
|
||||
There are use cases and reasons to have environment configuration different for each environment such as Dev/Staging etc. Let's assume that we want to vary the `maxscale` in functions and `DB_CONNECTION` in environment
|
||||
|
||||
```
|
||||
spec:
|
||||
InvokeStrategy:
|
||||
ExecutionStrategy:
|
||||
ExecutorType: newdeploy
|
||||
MaxScale: 2 // <-- Varies based on environment deployed in
|
||||
MinScale: 1
|
||||
```
|
||||
|
||||
```
|
||||
container:
|
||||
env:
|
||||
- name: DB_CONNECTION
|
||||
value: "http://database.url" // <-- Varies based on environment deployed in
|
||||
```
|
||||
|
||||
Without changing anything in Fission spec it is possible to change these things from environment to environment and some of strategies used by people are:
|
||||
|
||||
1. Generate and maintain specs for each environment. This is not a best practice as it leads to drift in code and configuration between environment over time.
|
||||
2. Use placeholder variables (i.e. $DB_CONNECTION_VALUE) and replace them for each environment before deploying. This is better in the sense that you are combining changes specific to each environment with spec code but is still a work around sort of.
|
||||
|
||||
For environment specific configurations, it is possible to use some sort of templating or overlay mechanism. One of interesting projects using overlays is [Kustomize](https://github.com/kubernetes-sigs/kustomize). In any case as of today the fission spec command does not have a way to use template or modify values using overlay and it is worth exploring this approach for fission spec.
|
||||
|
||||
## 3 Promotion from one environment to another
|
||||
|
||||
This necessarily does not fall in the area of Fission per se but it would be fairly easy to build a pipeline in the the tool used for CI/CD if we have container mentioned in (1) and even work around mentioned in (2).
|
||||
|
||||
## Action Items
|
||||
|
||||
As a first step it would be good to build a simple container mentioned in (1) and use it in various tools to understand the value it adds and any unknowns. The next steps would be to build a full end to end pipeline from source to production.
|
||||
@@ -1,128 +0,0 @@
|
||||
# Fission CLI Extensibility
|
||||
|
||||
### Approach
|
||||
To sum up the approach: git-style plugins.
|
||||
|
||||
Plugins are named with the fission prefix `fission-*`. When fission is invoked with an undefined/non-core subcommand
|
||||
is called (like `fission foo`). Fission will look in the PATH
|
||||
|
||||
**Installing Fission**
|
||||
```bash
|
||||
# The same as before
|
||||
$ curl -Lo fission https://github.com/fission/fission/releases/download/0.7.2/fission-cli-osx && chmod +x fission && sudo mv fission /usr/local/bin/
|
||||
```
|
||||
|
||||
**Installing Fission Workflows**
|
||||
```bash
|
||||
# The same process as Fission cli itself
|
||||
$ curl -Lo fission https://github.com/fission/fission-workflows/releases/download/0.4.0/fission-workflows-osx && chmod +x fission-workflows && sudo mv fission-workflows /usr/local/bin/
|
||||
```
|
||||
|
||||
**Invoking Fission Workflows**
|
||||
```bash
|
||||
$ fission workflows invocation get b1278e802a
|
||||
# Which is equivalent to:
|
||||
$ fission-workflows invocation get b1278e802a
|
||||
```
|
||||
General flow:
|
||||
1. fission does not recognize `workflows` subcommand
|
||||
2. fission checks the path for a binary called `fission-workflows`
|
||||
3. fission finds the binary.
|
||||
4. fission invokes the `fission-workflows`, passing the remainder of the arguments.
|
||||
|
||||
**Discoverability: fission --help**
|
||||
```bash
|
||||
$ fission --help
|
||||
USAGE:
|
||||
fission [global options] command [command options] [arguments...]
|
||||
|
||||
VERSION:
|
||||
0.6.0
|
||||
|
||||
COMMANDS:
|
||||
function, fn Create, update and manage functions
|
||||
httptrigger, ht, route Manage HTTP triggers (routes) for functions
|
||||
timetrigger, tt, timer Manage Time triggers (timers) for functions
|
||||
mqtrigger, mqt, messagequeue Manage message queue triggers for functions
|
||||
environment, env Manage environments
|
||||
watch, w Manage watches
|
||||
package, pkg Manage packages
|
||||
spec, specs Manage a declarative app specification
|
||||
upgrade Upgrade tool from fission v0.1
|
||||
tpr2crd Migrate tool for TPR to CRD
|
||||
help, h Shows a list of commands or help for one command
|
||||
|
||||
PLUGINS:
|
||||
workflows, wf Inspect and manage workflow executions
|
||||
ui Start the user interface
|
||||
|
||||
GLOBAL OPTIONS:
|
||||
--server value Fission server URL (default: "http://127.0.0.1:65356")
|
||||
--help, -h show help
|
||||
--version, -v print the version
|
||||
```
|
||||
Of course Fission needs to be able to find all plugins for this. There are several ways in which we can provide discoverability. The simplest one is for Fission to look in the path for all binaries starting with the `fission-*` prefix. Optionally, fission could invoke a specific command on the subcommand to get info about the plugin (such as version, help text, aliases...)
|
||||
|
||||
With Fission Workflows this info would look something like this:
|
||||
```bash
|
||||
$ fission-workflows --plugin
|
||||
name: workflows
|
||||
version: 0.4.0
|
||||
help: Inspect and manage workflow executions
|
||||
```
|
||||
The idea is that this plugin info is all completely optional.
|
||||
If it is not available, we simply degrade the results to user.
|
||||
This way users/we can easily prototype or add plugins without having to worry about adhering to some interface.
|
||||
|
||||
**List version**
|
||||
```bash
|
||||
$ fission --version
|
||||
client:
|
||||
fission: 0.8.0
|
||||
fission-workflows: 0.4.0
|
||||
server:
|
||||
fission: 0.8.1
|
||||
fission-workflows: 0.3.0
|
||||
```
|
||||
Again, versioning info for fission-workflows is taken from the plugin info of the commands.
|
||||
Note: a related issue is to have some more formalized plugin support/discoverability on the server-side,
|
||||
but that is out of the scope of this issue.
|
||||
|
||||
### Other (optional) extensions and notes
|
||||
- Like git we could setup a preferred binary path, where fission looks first when searching for the subcommand.
|
||||
This could optionally be defined with a `FISSION_EXEC_PATH`.
|
||||
- With the current approach we cannot have aliases for commands---fission will not be able to find fission-workflows
|
||||
when the user calls `fission wf`. This might be UX issue, with these long path names. One option is let the user fix
|
||||
it themselves by symlinking `fission-wf` to `fission-workflows`; using the plugin info Fission can recognize and
|
||||
merge aliases together.
|
||||
- To help detect versioning conflicts (old version of fission, too new version of fission workflows). We could add
|
||||
a `requires` field to the fission-workflows plugin info. Then we could throw a warning or error, when two out of sync
|
||||
versions are being used.
|
||||
- To avoid unhelpful errors to the user when they have not installed a plugin, we could add a heuristic to check
|
||||
`https://github.com/fission/SUBCOMMAND` to see if the subcommand might be an uninstalled plugin.
|
||||
OR, we could lookup a simple text file that contains common plugins `https://github.com/fission/fission/plugins.txt`
|
||||
and list them as suggestions to the user. OR we could of course just default to a bit help text that says something
|
||||
like `unknown subcommand 'foo'. If this is a plugin, ensure that it is present on your PATH`.
|
||||
|
||||
---
|
||||
|
||||
### Motivation
|
||||
|
||||
The proposed approach is to use the git-based plugin system for now. Reasons for this approach over a sophisticated,
|
||||
integrated plugin-based approach:
|
||||
- It is low effort to implement.
|
||||
- It is easy to extend with minimal to no required interface.
|
||||
- The binaries remain standalone, allowing users to separate them if needed and make independent development on the
|
||||
binaries easy.
|
||||
|
||||
Limitations of the proposed approach:
|
||||
- The user still has to do some work, adding binaries to the PATH; ensuring that permissions are correct; ensuring
|
||||
that the binary is executable; how to deal with duplicate binaries on the PATH. All this makes this approach assume
|
||||
basic/intermediate knowledge of the OS from the user.
|
||||
- I have to admit: I am not entirely sure if this approach requires any changes for Windows. Probably not.
|
||||
- Upgrading fission with many plugins could be cumbersome, as you would need to upgrade each binary one by one.
|
||||
Improving this is probably best left to future work.
|
||||
|
||||
|
||||
The more heavyweight solution solves some of these limitations to an extent, but these do not way up to the increased
|
||||
development and maintainance cost IMO. If needed we could explore this option (or some hybrid option) in the future.
|
||||
@@ -1,120 +0,0 @@
|
||||
# Environment V2 Fission-Environment API
|
||||
|
||||
Fission Environments are the language-specific component of fission.
|
||||
|
||||
They must satisfy the interface in this spec.
|
||||
|
||||
## Meta
|
||||
|
||||
This is version 2.0-alpha of the Fission-Environment API.
|
||||
|
||||
(It's unstable and may change without warning until 2.0-beta.)
|
||||
|
||||
## Overview
|
||||
|
||||
Fission V2 Environments consist of:
|
||||
|
||||
* Metadata
|
||||
* A runtime image
|
||||
* A builder image (optional)
|
||||
* Function Interface Specification
|
||||
* User Documentation
|
||||
* Examples
|
||||
|
||||
### Metadata
|
||||
|
||||
See EnvironmentSpec, Runtime, and Builder in types.go.
|
||||
|
||||
## Runtime Image
|
||||
|
||||
An environment runtime image is a docker container image. It must run
|
||||
a server that has two jobs:
|
||||
|
||||
(a) Loading a "function" from a file path on demand
|
||||
(b) Invoking that function on request
|
||||
|
||||
### Function Loading
|
||||
|
||||
The environment must expose a single HTTP endpoint (at the port and
|
||||
URL specified in the metadata) that loads a function. The function
|
||||
load request is a JSON-serialized `FunctionLoadRequest`.
|
||||
|
||||
The function load request contains a filepath to load the function
|
||||
from. Fission does not define in any way the contents of the path; it
|
||||
is completely environment-dependent. It may be a single file, or a
|
||||
directory (in case of deployment packages).
|
||||
|
||||
The load request may contain an EntryPoint. If it does, the loader
|
||||
must interpret this; usually it's the name of a function in a module
|
||||
or package containing multiple functions. If there is no entrypoint,
|
||||
the environment must use a default; again, the value of thsi default
|
||||
is environment-specific.
|
||||
|
||||
The load request may contain a URL. If it does, requests to that URL
|
||||
should be routed to the function. It defaults to "/".
|
||||
|
||||
### Function Invocation
|
||||
|
||||
Functions are invoked on HTTP request to the server. The port for the
|
||||
request on the runtime container is defined in the Runtime metadata,
|
||||
and the URL for the request is specified in the FunctionLoadRequest.
|
||||
|
||||
The interface of the function is environment specific; the environment
|
||||
must come with a spec for this interface.
|
||||
|
||||
## Builder
|
||||
|
||||
The builder is a container image that contains tools to build a
|
||||
function from source. The source may be a single file or a directory
|
||||
of files.
|
||||
|
||||
The builder container is invoked with the specified command, with the
|
||||
following params:
|
||||
|
||||
1. File path of the source
|
||||
2. File path where the output should go
|
||||
3. Other env or function-specific params passed by the user
|
||||
|
||||
The first two parameters are file paths, and all remaining params are
|
||||
environment-specific.
|
||||
|
||||
The output of the builder should be something that the runtime can
|
||||
load and run -- there should be no intermediate steps that need user
|
||||
intervention.
|
||||
|
||||
### Errors
|
||||
|
||||
## Function Interface Spec
|
||||
|
||||
The function interface spec is a document that specifies the interface
|
||||
of functions and their semantics. It must specify:
|
||||
|
||||
* How functions are invoked (sync, async)
|
||||
* How the request context is provided to the function (URL, headers, request type, request body)
|
||||
* Function logging
|
||||
* Semantics of function errors and exceptions
|
||||
|
||||
|
||||
## Documentation
|
||||
|
||||
The docs should contain everything necessary to use the environment:
|
||||
|
||||
* How to add it to a fission cluster
|
||||
* How to write and build functions for this environment (link to the interface spec)
|
||||
* How to modify and rebuild the environment itself
|
||||
|
||||
## Examples
|
||||
|
||||
Suggested examples to provide:
|
||||
|
||||
* A simple "Hello world"
|
||||
* A function that demonstrates use of the request context: url params,
|
||||
request headers, request body
|
||||
* A function that does logging
|
||||
* A multi-file function package
|
||||
* A function with dependencies
|
||||
* Functions with shared code
|
||||
|
||||
## Compatibility with v1
|
||||
|
||||
V1 environment images can be used as v2 environment runtime images.
|
||||
@@ -1,327 +0,0 @@
|
||||
# Fission Environments Redesign
|
||||
|
||||
As Fission supports more languages and reaches a wider set of use
|
||||
cases, it's time to ask how well the current Environments design is
|
||||
holding up.
|
||||
|
||||
|
||||
## Environments V1: What we learned
|
||||
|
||||
Environments V1 is very simple idea: an environments is one Docker
|
||||
image with an HTTP server + dynamic loader for that language; it's run
|
||||
in a pod with a language-agnostic sidecar (fetcher) that downloads and
|
||||
saves the function into a volume shared with the language-specific
|
||||
container.
|
||||
|
||||
### Pros:
|
||||
|
||||
* Abstracted away images.
|
||||
|
||||
* Very fast cold start
|
||||
|
||||
* No image registry to manage (neither for the user nor for fission
|
||||
implementation)
|
||||
|
||||
* Relatively small amount of language specific code. (python env is <
|
||||
100 lines)
|
||||
|
||||
### Cons:
|
||||
|
||||
* Doesn't work well for compiled languages
|
||||
|
||||
* Users have to rebuild the image to add dependencies
|
||||
|
||||
* Only one file supported
|
||||
|
||||
* Errors in loading are not surfaced properly. It is especially
|
||||
annoying to wait until runtime to see a syntax error that could have
|
||||
been caught on function upload.
|
||||
|
||||
* Starting a Pod without knowing the functions has its limitations: we
|
||||
can't set CPU/memory limits, we can't mount volumes (persistent
|
||||
volumes, secrets, configmaps). We also can't change the namespace
|
||||
the Pod is in.
|
||||
|
||||
* Not great for a large code base
|
||||
|
||||
* Some people want to operate at the image level but still get the
|
||||
on-demand execution semantics of FaaS. This is a cost-optimization
|
||||
use case.
|
||||
|
||||
|
||||
### Discussion
|
||||
|
||||
Early feedback shows that almost evey user ends up rebuilding images
|
||||
to add some dependecies. Some sort of automated dependecy resolution
|
||||
would be very nice to have and improve the development workflow. In
|
||||
other words, just attach a package.json(nodejs) or
|
||||
requirements.txt(python) with a function, and fission will do the
|
||||
rest. There's also the possiblity of supporting buildpacks (simple
|
||||
zipfiles), a la AWS Lambda.
|
||||
|
||||
Though we can support compiled languages by doing the compilation
|
||||
inside the cold-start, that's not a great solution because: (a)
|
||||
compile errors would be reported at runtime, and (b) because the
|
||||
overhead of compilation doesn't really need to be inside the
|
||||
cold-start latency.
|
||||
|
||||
Non-trivial functions will need multiple files. That also helps for
|
||||
common code across functions. So we need a way for the user to define
|
||||
a function as a collection of code with an entry point.
|
||||
|
||||
Finally, Docker images remain the most flexible way to package an app.
|
||||
Today, users can always rebuild an environment image to include
|
||||
anything they want. But those images must still run a server that
|
||||
implements fission-environment interface (i.e. the specialize
|
||||
endpoint). So perhaps there could be a way for users to say "don't
|
||||
use environments, I've already packaged up my function, here it is".
|
||||
|
||||
|
||||
## Environment V2 Requirements
|
||||
|
||||
Roughly in order of priority:
|
||||
|
||||
0. Retain the simplicity of the simple use cases. First user
|
||||
experience shoud remain trivial -- write a function, map a URL,
|
||||
done.
|
||||
|
||||
1. Support compiled languages. Support error reporting on function
|
||||
upload rather than cold start.
|
||||
|
||||
2. Support functions as a collection of files rather than just one
|
||||
file.
|
||||
|
||||
3. Support automated environment-specific dependecy resolution.
|
||||
|
||||
(#3 may end up having the same solution as #1. You could think of
|
||||
gathering deps as a "compilation" of package.json,
|
||||
requirements.txt, etc.)
|
||||
|
||||
4. Support functions as images.
|
||||
|
||||
|
||||
### User stories
|
||||
|
||||
#### Environment Creation
|
||||
|
||||
V1 Environments were just an image. V2 Environments will be a yaml
|
||||
file with the following properties:
|
||||
|
||||
* Run time image (required)
|
||||
* Version (required)
|
||||
* Builder image (optional)
|
||||
* Build invocation command (required if builder image specified)
|
||||
* File name extension(s) (optional)
|
||||
|
||||
The version will be used to distinguish V2 environments from V1.
|
||||
|
||||
```
|
||||
$ cat golang.yaml
|
||||
type: Environment
|
||||
metadata:
|
||||
name: go
|
||||
spec:
|
||||
runtimeImage: fission/go-runtime
|
||||
builderImage: fission/go-builder
|
||||
buildCommand:
|
||||
- "/build.sh"
|
||||
fileExtentions:
|
||||
- go
|
||||
|
||||
$ fission env create -f golang.yaml
|
||||
```
|
||||
|
||||
#### Function creation for compiled languages
|
||||
|
||||
User writes a function in a compiled language, for example Go.
|
||||
|
||||
```
|
||||
$ fission function create --code blah.go
|
||||
|
||||
<compilation errors>
|
||||
|
||||
<user edits file>
|
||||
$ $EDITOR blah.go
|
||||
<fixes errors>
|
||||
|
||||
$ fission function update --code blah.go
|
||||
<success>
|
||||
|
||||
$ fission route ... # routes work as usual
|
||||
```
|
||||
|
||||
This same user story applies to interpreted languages too, where the
|
||||
"compilation" step can be used to check for syntax errors.
|
||||
|
||||
#### Compiled language, without using fission builds
|
||||
|
||||
User compiles their function locally, resulting in a set of one or
|
||||
more binaries. The user packages these up as a zip file, creating a
|
||||
"deployment package".
|
||||
|
||||
```
|
||||
$ fission function create --deployment-package foo.zip
|
||||
|
||||
$ fission route ... # routes work as usual
|
||||
```
|
||||
|
||||
In this use case, fission is no longer operating at the source
|
||||
level. Builds are left to the user and fission only sees the
|
||||
deployment package package.
|
||||
|
||||
#### Collections of source files
|
||||
|
||||
The user can create a source package -- a set of source files in a
|
||||
zip.
|
||||
|
||||
```
|
||||
$ fission function create --source-package foo.zip
|
||||
|
||||
```
|
||||
|
||||
This workflow works similarly to providing a single source file.
|
||||
|
||||
In addition, fission CLI could support automatic creation of source packages, e.g.
|
||||
|
||||
```
|
||||
$ fission function create --source-files *.js
|
||||
```
|
||||
|
||||
This is purely client-side "syntactic sugar" -- the CLI creates the
|
||||
source package instead of the user having to do it manually. It
|
||||
doesn't change semantics; the source package is still handled as one
|
||||
object.
|
||||
|
||||
#### Handling Dependencies
|
||||
|
||||
The source package of a function can contain dependency specs.
|
||||
|
||||
Fission framework proper does not treat this spec in any special way;
|
||||
it's just another file in the source package. These will be
|
||||
interpreted by the environment builder.
|
||||
|
||||
```
|
||||
$ fission function create --source-files *.js --source-files package.json
|
||||
```
|
||||
|
||||
In this case, the CLI will create a source package containing the JS
|
||||
files and package.json. The NodeJS environment builder will create a
|
||||
deployment package out of these files. The runtime environment will
|
||||
load and run the deployment package.
|
||||
|
||||
#### V1 Compatibility
|
||||
|
||||
V1 Environments will continue to be supported. Existing commands will
|
||||
continue to work. V1 environments won't support newer features like
|
||||
builds, source and deployment packages, etc.
|
||||
|
||||
### Implementation
|
||||
|
||||
#### Environment Type
|
||||
|
||||
The environment type has a set of new properties: version, runtime
|
||||
image, builder image, build command, file extension(s).
|
||||
|
||||
#### Function Type
|
||||
|
||||
The function type has new properties: source package, deployment
|
||||
package. The literal code string continues to be supported, but it
|
||||
will have a specified size limit, say 512KB.
|
||||
|
||||
#### Source and Binary Packages
|
||||
|
||||
A package is just a zip file. It's contents are opaque to fission:
|
||||
the meaning of its contents is defined by the environment. Fission's
|
||||
job is to manage the storage and delivery of the package into build
|
||||
and runtime environments.
|
||||
|
||||
#### Storage Service
|
||||
|
||||
The storage service will have an HTTP API to upload and download
|
||||
files. It can store the packages on a persistent volume or as objects
|
||||
in cloud storage services such as S3.
|
||||
|
||||
Storage service has a garbage collection API endpoint. When invoked,
|
||||
it will remove all packages that are not referenced from any function.
|
||||
|
||||
#### Fetcher
|
||||
|
||||
Fetcher gets some new responsibilities:
|
||||
|
||||
1. It must now also handle zip/unzip of packages
|
||||
|
||||
2. It must know how to upload to the storage service (so it's not
|
||||
exactly "fetcher" any more, but...)
|
||||
|
||||
#### Runtime Environment Interface
|
||||
|
||||
The V2 runtime environment interface is very similar to V1
|
||||
environments. Environments must support a dynamic loader and have an
|
||||
HTTP server that forwards requests to the loaded module.
|
||||
|
||||
The differences:
|
||||
|
||||
* V2 runtimes must support loading a deployment package. Fetcher is
|
||||
responsible for unzipping a deployment package, but interpretation
|
||||
of the contents is up to the environment's code. For example, it
|
||||
may have to include the directory where the deployment package is
|
||||
unzipped in its module load path.
|
||||
|
||||
[TODO any other differences?]
|
||||
|
||||
#### Buildmgr
|
||||
|
||||
A new service that will manage builds. Its design is similar to
|
||||
poolmgr, except it is triggered on creation or update of a function,
|
||||
rather than HTTP requests.
|
||||
|
||||
Buildmgr creates a builder deployment+service for each environment.
|
||||
Pods in this deployment run the environment's build container, and
|
||||
fetcher, with a shared volume between the two containers.
|
||||
|
||||
When a function is created or updated with a source package, buildmgr
|
||||
notices this and triggers a build. First, it calls fetcher to
|
||||
download the source package into a shared volume with the build
|
||||
container. It then invokes the builder by running the build
|
||||
invocation command in the build container. Next, it calls fetcher to
|
||||
package up the output of the builder and store the built package into
|
||||
the the storage service.
|
||||
|
||||
Finally, it updates the function object in the controller API with a
|
||||
reference to the built package.
|
||||
|
||||
[We can collapse this workflow into one request into the builder
|
||||
service, which would make it easier to scale up the builder
|
||||
deployment; if we used multiple requests we'd need some sort of
|
||||
affinity rule, but k8s services only support IP based affinity.]
|
||||
|
||||
#### Poolmgr
|
||||
|
||||
Poolmgr remains relatively unchanged. Instead of contructing URLs for
|
||||
function metadata, it uses the deployment package URL in the function
|
||||
object.
|
||||
|
||||
#### CLI
|
||||
|
||||
Client libraries and CLI have to deal with the new properties in
|
||||
functions and environments.
|
||||
|
||||
The CLI will now talk to both storage service and controller. When a
|
||||
function is created, the user can specify the function in one of 3
|
||||
ways:
|
||||
|
||||
1. One source file, same as v1.
|
||||
|
||||
2. A source package (or a set of source files, which is turned into a
|
||||
source package by the CLI)
|
||||
|
||||
3. A deployment package
|
||||
|
||||
If the file is specified as a source file, fission CLI will use the
|
||||
code literal if it's under the size limit; otherwise it should use the
|
||||
storage service. This will allow users to use fission deployments
|
||||
with no storage service, but with a size limit on functions.
|
||||
|
||||
For the case of a source or deployment package, the CLI first does an
|
||||
upload to the storage service, then creates a function object with a
|
||||
reference to the uploaded package.
|
||||
@@ -1,47 +0,0 @@
|
||||
|
||||
# Fission Pool manager
|
||||
|
||||
Fission's currently uses a pool of running "environments" and specialized them for execution of a function. This design served the cold start use cases well but this is not the only strategy for creation and execution of functions. For example requirements for a new execution backend have been discussed in https://github.com/fission/fission/issues/193. This document aims to discuss the currently under development "newdeploy" backend and related thoughts
|
||||
|
||||
# Executor
|
||||
|
||||
A new layer - executor now sits between the router and actual backends are responsible for all of heavy lifting for execution of functions. Executor layer is responsible for accepting requests from router and checking with cache before calling on a backend for execution of a function.
|
||||
|
||||
# Backend
|
||||
|
||||
A backend is responsible for execution of a function - which can involve provisioning appropriate objects in Kubernetes. So with the new design Pool manager becomes one of backends. As of this writing there are two backends which are described as:
|
||||
|
||||
### Pool Manager Backend
|
||||
|
||||
Pool manager backend uses a pool of environment pods and specialized them when a function is invoked. The specialized pods are cleaned up if not in use after a few minutes. More details on Pool manager can be found here: https://github.com/fission/fission/blob/5c470735185b980c1f7987921db360e91c65573b/Documentation/Architecture.md
|
||||
|
||||
### New Deploy Backend
|
||||
|
||||
New Deploy backend create a Kubernetes deployment, a Kubernetes Service for a given function. It additionally creates a HorizontalPodAutoscaler if scale parameters are provided. The creation of deployment and service can be eager or lazy based on input.
|
||||
|
||||
### Execution Strategy
|
||||
|
||||
While this is still a WIP, parameters that affect execution behaviour of function are based on `InvokeStrategy`. A invoke strategy defines the `strategyType` and actual strategy parameters encapsulated in the strategy object.
|
||||
|
||||
```
|
||||
InvokeStrategy struct {
|
||||
ExecutionStrategy ExecutionStrategy
|
||||
StrategyType StrategyType
|
||||
}
|
||||
```
|
||||
For example in above case the strategy type is `ExecutionStrategy` and the corresponding parameters are listed below.
|
||||
|
||||
```
|
||||
ExecutionStrategy struct {
|
||||
Backend BackendType
|
||||
MinScale int
|
||||
MaxScale int
|
||||
EagerCreation bool
|
||||
}
|
||||
```
|
||||
|
||||
In future there could be more strategies for different use cases.
|
||||
|
||||
## Dispatch to backend
|
||||
|
||||
As of now one of the backends is chosen based on a simple flag in `ExecutionStrategy`. In future there might be a intelligent/hybrid ways of choosing a backend. For example initial requests of a function could be served from a pool manager while later scaling could be served by a NewDeploy backend
|
||||
@@ -1,67 +0,0 @@
|
||||
# Java Environment : Design & considerations
|
||||
|
||||
This document documents the design and thoughts that lead to design of Java environment. Before we dive deeper, some important points:
|
||||
|
||||
- When we say Java, we really mean JVM. That does not mean that all languages will work seamlessly, so support will be added gradually based on validation. Some of popular languages as of today are:
|
||||
- Scala
|
||||
- Groovy
|
||||
- Kotlin (Server side with Spring)
|
||||
|
||||
- In Java there are a few prominent frameworks which have a ecosystem of their own (See list below). How these framework fit in the environment will be detailed later, but it is important to understand their place in ecosystem and design for it.
|
||||
- A large percentage of entertprise developers use [Spring framework](https://spring.io/) as has been shown by multiple surveys
|
||||
- Reactive has taken up recently with data intensive operations [Reactive extensions for JVM](https://github.com/ReactiveX/RxJava)
|
||||
- [Spark](http://sparkjava.com/) is a micro web framework
|
||||
|
||||
A draft implementation of the Java environment design is in the branch [java_env_alpha](https://github.com/fission/fission/tree/java_env_alpha). Also a earlier implementation based on Vort.x framework [can be found here](https://github.com/tobias/fission-java-env/)
|
||||
|
||||
## Function interface
|
||||
|
||||
The goal is here is to minimize the lock in for the user into any framework as much as possible. Java 8 introduced an interface called ```Function``` which could be a great fit here. The user has to implement the ```Function<T, R>``` class and to meet the contract implement the apply method:
|
||||
|
||||
```
|
||||
public class HelloWorld implements Function<T, R> {
|
||||
|
||||
public R apply(T str) {
|
||||
|
||||
```
|
||||
|
||||
Now - the T & R could be different things and we discuss some options below:
|
||||
|
||||
### Body in request and response
|
||||
|
||||
From the early implementation in the branch mentioned above, the environment extracts the body and send it as a JSON string. The JSON then can be transformed into the appropriate object by the function.
|
||||
|
||||
This works well, but has one major limitation: the function does not get access to other things like headers etc. The same thing applies to the reponse: function can send the body but looses control over status code etc.
|
||||
|
||||
### HttpServletRequest and HttpServletResponse
|
||||
|
||||
It is possible to send the [HttpServeletRequest](https://docs.oracle.com/javaee/6/api/javax/servlet/http/HttpServletRequest.html) request object as it is to the function class but then the interface becomes a bit too low level. For example the function user has to retrieve the body of request using ```getInputStream``` which gives raw input stream and needs additional work.
|
||||
|
||||
Also most enterprise applications today use a framework of some sort for web applications instead of dealing with the raw HttpServlet
|
||||
|
||||
### Custom/Context Object
|
||||
|
||||
A custom object which encapsulates all needed fields etc. can be used to pass the data from environment to the function. But this means the user has to import a Fission object/library for this object in the application code.
|
||||
|
||||
This approach has been taken in the implementation done earlier for a Java environment in Fission and [object interface can be found here](https://github.com/tobias/fission-java-env/blob/master/src/main/java/io/fission/api/Context.java). Related discussion is in the [issue](https://github.com/fission/fission/issues/91)
|
||||
|
||||
AWS Lambda also uses a context object, but the purpose is very different, [details of context object here](https://docs.aws.amazon.com/lambda/latest/dg/java-context-object.html).
|
||||
|
||||
### Spring's HttpEntity
|
||||
|
||||
If we have to depend on a class/library, it is probably better to depend on a class which is part of ecosystem. So instead of using the low level interface of Servlet, we can use [HttpEntity's subclasses RequestEntity and ResponseEntity](https://docs.spring.io/spring/docs/5.0.5.RELEASE/javadoc-api/org/springframework/http/HttpEntity.html). This ensures that the function user is not locked in the Fission object contract, but also gets the full access to request/response object.
|
||||
|
||||
The Spring cloud function project also discusses the issue of not having access to other things in request and [related issues are here](https://github.com/spring-cloud/spring-cloud-function/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+header)
|
||||
|
||||
### Thoughts
|
||||
|
||||
- If we only intend to pass request/response object to function - then using HttpEntity might be a good choice
|
||||
|
||||
- If there is a need for additional exchange of information between the environment and function execution in future, then a custom/context object is a better option. We can wrap the HttpEntity's fields and additional fields in the custom context object
|
||||
|
||||
## Environment Design
|
||||
|
||||
JVM environment design is based on Spring boot and Spring MVC frameworks. The details can be found in branch, but here are some key points:
|
||||
|
||||
- All classes in the function and dependent classes are loaded into JVM. Which means the user should supply the uber/fat jar for execution.
|
||||
- The entrypoint class is specified by the user as ```entrypoint``` flag on the class. The method is by convention (```apply``` as per the Function interface contract)
|
||||
@@ -1,62 +0,0 @@
|
||||
# Fission Support Tool
|
||||
Fission now has rich functionality supported by multiple services, however, it brings the complexity of troubleshooting.
|
||||
This proposal tends to give a picture of fission support tool that can help both user and developer to locate the problem in short time.
|
||||
To achieve this, the support tool will dump related kubernetes objects, fission resources and pod logs from the given cluster.
|
||||
|
||||
# Functionality
|
||||
|
||||
## Environment Information Collection
|
||||
|
||||
Before troubleshooting, some of the basic information is needed to give others an overview of kubernetes/fission user test with so that we can locate the problem in short time.
|
||||
|
||||
* Fission version
|
||||
* Client/Server version
|
||||
|
||||
* Kubernetes cluster version
|
||||
* Cluster version (i.e v1.9.7-gke.0)
|
||||
* Running environment (i.e GKE, AKS and minikube)
|
||||
* Nodes version and other information
|
||||
|
||||
## Service Logs Collection
|
||||
|
||||
The component logs and the logs of interaction between components are important for people to understand what really happened in cluster. Following are components need to collect logs from.
|
||||
|
||||
* All fission component pods
|
||||
* Function pods
|
||||
* Builder pods
|
||||
* Environment pods
|
||||
|
||||
## Object dumping
|
||||
|
||||
Fission is deeply coupled with Kubernetes, most of the objects are created and maintained by it. There is two major type of objects need to be dumped from kubernetes:
|
||||
|
||||
* K8S objects
|
||||
* CRD resources
|
||||
|
||||
All objects should be dumped into a readable file format. It will be great if people can reproduce similar environment with these files.
|
||||
|
||||
## Information upload
|
||||
|
||||
Upload dump files to the specific backend server for support channel to analysis
|
||||
|
||||
# CLI Interface
|
||||
|
||||
```
|
||||
$ fission support collect
|
||||
NAME:
|
||||
fission support collect - Collect pod logs, fission resources and related kubernetes objects for troubleshooting
|
||||
|
||||
USAGE:
|
||||
fission support collect [command options] [arguments...]
|
||||
|
||||
OPTIONS:
|
||||
--dumpdir value Directory to save dump kubernetes objects and fission resources (default: "fission-dump")
|
||||
--fissionns value Namespace of fission installation (default: "fission")
|
||||
--builderns value Namespace of fission package builder (default: "fission-builder")
|
||||
--funcns value Namespace of fission function pod (default: "fission-function")
|
||||
```
|
||||
|
||||
# Thoughts?
|
||||
|
||||
1. What to do with sensitive objects like secrets and configmap? Ignore the dump for such objects?
|
||||
2. The functionality is necessary but not listed above?
|
||||
@@ -1,209 +0,0 @@
|
||||
# Testing Proposal
|
||||
|
||||
This proposal was initially started as a upgrade testing proposal but soon problems that were posed resulted in a bigger proposal.
|
||||
### Kinds of testing
|
||||
|
||||
Most of current integration tests are CLI driven. Fission CLI is used to test execute various test cases. In future we would have to also focus on API level testing as a UI is built for Fission.
|
||||
## Needs & patterns
|
||||
|
||||
This section only explains the problems/best practices without going into tooling and language used for implementation.
|
||||
### Separating the test & data
|
||||
|
||||
Seperating the tests from test data has two aspects - one is separation of concerns and second is scaling the tests without touching the test logic. The test data is a simple data structure which holds all information and test can take data and execute the logic.
|
||||
|
||||
As an example today we test "Hello world" for nodejs environment with a simple hello.js like this:
|
||||
|
||||
```
|
||||
fission env create --name nodejs --image fission/node-env
|
||||
fission fn create --name $fn --env nodejs --code $ROOT/examples/nodejs/hello.js
|
||||
fission route create --function $fn --url /$fn --method GET
|
||||
response=$(curl http://$FISSION_ROUTER/$fn)
|
||||
```
|
||||
The variables here are environment image, function code & route URL.
|
||||
|
||||
If tomorrow if we had to scale this test for all environments, we will have to repeat ourselves. (Violate DRY principle). Instead of that if we encapsulate the test setup & test in a simple function:
|
||||
|
||||
```
|
||||
test_hello_env(envImage, codePath, routeURL){
|
||||
|
||||
}
|
||||
```
|
||||
|
||||
And feed it with a dictionary which has all possible combination of tests:
|
||||
|
||||
```
|
||||
{
|
||||
node: {"fission/node-env", "test/hello.js", "/hellonode"},
|
||||
python: {"fission/python-env", "test/hello.py", "/hellopy"},
|
||||
golang: {"fission/go-env", "test/hello.go", "/hellogo"},
|
||||
binray: {"fission/binary-env", "test/hello.sh", "/hellobinary"},
|
||||
}
|
||||
|
||||
```
|
||||
This would achieve a few things:
|
||||
|
||||
- Separate the test execution logic from the data it needs clearly.
|
||||
- For adding new kind of environments, you just need to add one more entry into data structure.
|
||||
|
||||
Testing all environments may not be most apt example for this, but there can be potential use cases like this.
|
||||
### Separating the test & setup/teardown
|
||||
|
||||
When we run a test there are typically three distinct phases:
|
||||
|
||||
- Setup (Create env, fn, route)
|
||||
- Test (Curl the function)
|
||||
- Cleanup (Delete fn, route & env)
|
||||
|
||||
It should be possible to separate the before test and after test parts from actual tests at two levels:
|
||||
- Each test
|
||||
- A whole test suite
|
||||
|
||||
The ability to have clean and separate before and after blocks, apart from separation of concerns, enables:
|
||||
|
||||
- Running a suite of tests for same setup (See tagging for suite of tests)
|
||||
### Tagging tests & running a selection
|
||||
|
||||
Over a period of time as tests grow, there will be unit, smkoe, integration, performance, soak tests and so on. Ability to run a perticular test suite only or a combination of them makes it easy to run for specific purpose.
|
||||
### Measuring test times
|
||||
|
||||
[Good to have, not a must] Measuring time for tests and reporting somewhere helps over time to monitor trends. Although this job is better done by performance/benchmark tests so it is not a strict requirement
|
||||
|
||||
### Cleaner Logging
|
||||
It would be good to have cleaner/relevant logging as part of build & test. For example something that Ginkgo framework does is it shows error logs only for failed tests.
|
||||
### Tests in Parallel
|
||||
|
||||
It would be good to be able to run tests in parallel.
|
||||
|
||||
## Evalutaing the tools/alternatives
|
||||
### BATS
|
||||
|
||||
Bash Automated Testing System is like a enhanced version of bash with support for @test tags and before and after steps & ability to skip tests etc. While it enhances the bash to certain extent, the overall improvement is only marginal.
|
||||
|
||||
```
|
||||
#!/usr/bin/env bats
|
||||
|
||||
@test "addition using bc" {
|
||||
result="$(echo 2+2 | bc)"
|
||||
[ "$result" -eq 4 ]
|
||||
}
|
||||
|
||||
$ bats addition.bats
|
||||
✓ addition using bc
|
||||
✓ addition using dc
|
||||
|
||||
2 tests, 0 failures
|
||||
|
||||
```
|
||||
#### Links
|
||||
- Bats repo: https://github.com/sstephenson/bats
|
||||
- Runc uses Bats https://github.com/opencontainers/runc/tree/master/tests/integration
|
||||
### Go Test
|
||||
|
||||
The testing package of Go also is quite feature rich for most of the use cases we need. Go 1.7 onwards there is support for setup & teardown parts and parallelism etc.
|
||||
#### Go - Testing package
|
||||
|
||||
- Support for setup and teardown based on https://golang.org/pkg/testing/#hdr-Main
|
||||
- Go testing already supports and has examples of table driven tests (Separating test & data), measuring test times and parallel tests
|
||||
#### Shell execution: Go's Exec Library
|
||||
GO provides a built in Exec library for working with CLI commands. The package seems good enough for us to work, though a few working examples will help decide better
|
||||
|
||||
https://golang.org/pkg/os/exec
|
||||
|
||||
### Using CLI package
|
||||
|
||||
Currently we build a CLI and then execute the tests. The tests basically call one of functions from CLI package. If we decide to use a go lang based framework, then we can import the CLI package and then call those functions by providing them context. This is as good as calling the Fission from CLI, with added benefit of programmibility of Go langugage.
|
||||
|
||||
```
|
||||
func TestSomething(t *testing.T) {
|
||||
// Build the Cli context with flags etc.
|
||||
ctx := cli.Context{}
|
||||
|
||||
// Pass the ctx to create function
|
||||
fnCreate(ctx)
|
||||
}
|
||||
```
|
||||
|
||||
Some of benefits of using above pattern are:
|
||||
- We can build a small framework around above core where we can pass various flag combinations etc. and exercise all flags in great detail
|
||||
- We can use rest of Go testing library and other libraries to build matchers, looping, parallelism etc.
|
||||
- It allows us to exercise the logic in CLI as well as validate the API at the same time.
|
||||
|
||||
### Ginkgo & Gomega
|
||||
|
||||
Ginkgo is a BDD framework which works with Gomega matcher library. I will state relevant portions of these two frameworks which can be utilized:
|
||||
|
||||
From Ginkgo:
|
||||
|
||||
- Global `BeforeSuite` and after `AfterSuite` can be used to have global setup and tear down phases
|
||||
- For tests `BeforeEach` and `AfterEach` and more such varients to do before and after test tasks.
|
||||
|
||||
From Gomega:
|
||||
|
||||
Gomega is a matcher library but the `gexec` library makes it really easy to interact with OS execution environment. Some working examples:
|
||||
|
||||
- Build and cleanup the Fission CLI before & after the tests
|
||||
```
|
||||
var fissionCli string
|
||||
|
||||
BeforeSuite(func() {
|
||||
var err error
|
||||
fissionCli, err = gexec.Build("github.com/fission/fission")
|
||||
Ω(err).ShouldNot(HaveOccurred())
|
||||
})
|
||||
|
||||
AfterSuite(func() {
|
||||
gexec.CleanupBuildArtifacts()
|
||||
})
|
||||
```
|
||||
|
||||
- Following will run Fission commands with Fission CLI and print error if there is one (verbosity is configurable)
|
||||
|
||||
```
|
||||
command := exec.Command(fissionCli, "fission env create --name nodejs --image fission/node-env")
|
||||
session, err := gexec.Start(command, GinkgoWriter, GinkgoWriter)
|
||||
Ω(err).ShouldNot(HaveOccurred())
|
||||
```
|
||||
|
||||
- Use Fission CLI's output to validate test results
|
||||
|
||||
```
|
||||
Eventually(session.Out).Should(gbytes.Say("hello [A-Za-z], world"))
|
||||
```
|
||||
#### Gomega Matchers
|
||||
|
||||
- Gomega provides quite a few built in matchers - so you don't have to code those small usual checks, for example:
|
||||
```
|
||||
Ω(ACTUAL).Should(BeTrue()) // The output should be true
|
||||
|
||||
Ω(ACTUAL).Should(BeAnExistingFile()) // The file should already exist
|
||||
|
||||
```
|
||||
There are many more matchers which cane be found here: http://onsi.github.io/gomega/#provided-matchers
|
||||
|
||||
- We can build custom mathers in Go language for reusable logic.
|
||||
|
||||
#### Links
|
||||
Ginkgo: http://onsi.github.io/ginkgo/
|
||||
Gomega: http://onsi.github.io/gomega/
|
||||
## Thoughts & Next actions
|
||||
|
||||
Based on the discussion with team, here are current thoughts and next action items:
|
||||
|
||||
### Thoughts
|
||||
- As far as possible we should stick to Go's built in testing package
|
||||
- Ginkgo's cleaner logging feature (Onlu log if there are errors) - is very useful. We can decide to incorporate this in future.
|
||||
- Gomega's (gexec)[http://onsi.github.io/gomega/#gexec-testing-external-processes] is really neat and some matchers can be used if necessary
|
||||
|
||||
### Action items
|
||||
- How will upgrade test for Fission fit in the framework?
|
||||
- How will migration of tests happen over time:
|
||||
- Aim is to keep existing tests around so that enough validation is in place
|
||||
- May be migrate one test at a time
|
||||
- How much of current setup etc. will move into framework? For example it is clear that helm commands should be part of test framework as part of setup/teardown. But other sections may or may not be. A RCA needs to be done to analyze and come up with clear demarkation.
|
||||
|
||||
## References
|
||||
|
||||
- EngineYard uses BATS: https://www.engineyard.com/blog/bats-test-command-line-tools
|
||||
- AWS CLI Tests, written in Python (CLI itself is also in Python): https://github.com/aws/aws-cli/tree/develop/tests
|
||||
- Kubernetes uses Ginkgo and Gomega extensively: https://github.com/kubernetes/kubernetes/search?l=Go&q=onsi&type=
|
||||
- Hashicorp's Mitchell's talk on Advanced testing with go talks about some good patterns to use: https://www.youtube.com/watch?v=8hQG7QlcLBk
|
||||
@@ -14,35 +14,123 @@
|
||||
|
||||
.DEFAULT_GOAL := check
|
||||
|
||||
check: test-run build clean
|
||||
SKAFFOLD_PROFILE ?= kind
|
||||
|
||||
VERSION ?= v0.0.0
|
||||
TIMESTAMP ?= $(shell date -u +'%Y-%m-%dT%H:%M:%SZ')
|
||||
COMMITSHA ?= $(shell git rev-parse HEAD)
|
||||
|
||||
GOOS ?= $(shell go env GOOS)
|
||||
GOARCH ?= $(shell go env GOARCH)
|
||||
GOAMD64 ?= $(shell go env GOAMD64)
|
||||
|
||||
FISSION-CLI-SUFFIX :=
|
||||
ifeq ($(GOOS), windows)
|
||||
FISSION-CLI-SUFFIX := .exe
|
||||
endif
|
||||
|
||||
# Show this help.
|
||||
help:
|
||||
@awk '/^#/{c=substr($$0,3);next}c&&/^[[:alpha:]][[:alnum:]_-]+:/{print substr($$1,1,index($$1,":")),c}1{c=0}' $(MAKEFILE_LIST) | column -s: -t
|
||||
|
||||
print-%:
|
||||
@echo '$*=$($*)'
|
||||
|
||||
debug-vars: print-GOOS print-GOARCH print-GOAMD64 print-VERSION print-TIMESTAMP print-COMMITSHA print-FISSION-CLI-SUFFIX print-SKAFFOLD_PROFILE
|
||||
|
||||
### Static checks
|
||||
check: test-run build-fission-cli clean
|
||||
|
||||
code-checks:
|
||||
golangci-lint run
|
||||
|
||||
# run basic check scripts
|
||||
test-run:
|
||||
hack/verify-gofmt.sh
|
||||
hack/verify-govet.sh
|
||||
hack/verify-staticcheck.sh
|
||||
test-run: code-checks
|
||||
hack/runtests.sh
|
||||
@rm -f coverage.txt
|
||||
|
||||
# ensure the changes are buildable
|
||||
build:
|
||||
go build -o cmd/fission-bundle/fission-bundle ./cmd/fission-bundle/
|
||||
go build -o cmd/fission-cli/fission ./cmd/fission-cli/
|
||||
go build -o cmd/fetcher/fetcher ./cmd/fetcher/
|
||||
go build -o cmd/fetcher/builder ./cmd/builder/
|
||||
### Binaries
|
||||
build-fission-cli:
|
||||
@GOOS=$(GOOS) GOARCH=$(GOARCH) GOAMD64=$(GOAMD64) GORELEASER_CURRENT_TAG=$(VERSION) goreleaser build --snapshot --clean --single-target --id fission-cli
|
||||
|
||||
# install CLI binary to $PATH
|
||||
install: build
|
||||
mv cmd/fission-cli/fission $(GOPATH)/bin
|
||||
install-fission-cli:
|
||||
# TODO: Fix this hack, replace v1 with GOAMD64
|
||||
mv dist/fission-cli_$(GOOS)_$(GOARCH)_v1/fission$(FISSION-CLI-SUFFIX) /usr/local/bin/fission
|
||||
|
||||
# build images (environment images are not included)
|
||||
image:
|
||||
docker build -t fission-bundle -f cmd/fission-bundle/Dockerfile.fission-bundle .
|
||||
docker build -t fetcher -f cmd/fetcher/Dockerfile.fission-fetcher .
|
||||
docker build -t builder -f cmd/builder/Dockerfile.fission-builder .
|
||||
### Codegen
|
||||
codegen: controller-gen-install
|
||||
@controller-gen object:headerFile="hack/boilerplate.txt" paths="./..."
|
||||
@./hack/update-codegen.sh
|
||||
|
||||
### CRDs
|
||||
controller-gen-install:
|
||||
go install sigs.k8s.io/controller-tools/cmd/controller-gen@v0.13.0
|
||||
|
||||
generate-crds: controller-gen-install
|
||||
controller-gen crd \
|
||||
paths=./pkg/apis/core/v1 \
|
||||
output:crd:artifacts:config=crds/v1
|
||||
|
||||
### Webhook generation: it generates webhook configs with help of kubebuilder:webhook tag
|
||||
generate-webhooks: controller-gen-install
|
||||
controller-gen webhook \
|
||||
paths=./pkg/apis/core/v1 \
|
||||
output:dir=charts/fission-all/templates/webhook-server
|
||||
|
||||
|
||||
create-crds:
|
||||
@kubectl create -k crds/v1
|
||||
|
||||
update-crds:
|
||||
@kubectl replace -k crds/v1
|
||||
|
||||
delete-crds:
|
||||
@kubectl delete -k crds/v1
|
||||
|
||||
### Cleanup
|
||||
clean:
|
||||
@rm -f cmd/fission-bundle/fission-bundle
|
||||
@rm -f cmd/fission-cli/fission
|
||||
@rm -f cmd/fetcher/fetcher
|
||||
@rm -f cmd/fetcher/builder
|
||||
@rm -f dist/
|
||||
|
||||
### Misc
|
||||
generate-swagger-doc:
|
||||
@./hack/update-swagger-docs.sh
|
||||
|
||||
generate-cli-docs:
|
||||
go run tools/cmd-docs/main.go -o "../fission.io/content/en/docs/reference/fission-cli"
|
||||
|
||||
install-crd-ref-docs:
|
||||
go install github.com/elastic/crd-ref-docs@v0.0.10
|
||||
|
||||
generate-crd-ref-docs: install-crd-ref-docs
|
||||
# crd-ref-docs: https://github.com/elastic/crd-ref-docs
|
||||
crd-ref-docs --source-path=pkg/apis/core/v1 --config=tools/crd-ref-docs/config.yaml --renderer markdown
|
||||
cp tools/crd-ref-docs/header.md crd_docs.md
|
||||
cat out.md >> crd_docs.md && rm out.md
|
||||
mv crd_docs.md ../fission.io/content/en/docs/reference/crd-reference.md
|
||||
|
||||
all-generators: codegen generate-crds generate-swagger-doc generate-cli-docs generate-crd-ref-docs
|
||||
|
||||
skaffold-prebuild:
|
||||
@GOOS=linux GOARCH=amd64 GORELEASER_CURRENT_TAG=$(VERSION) goreleaser build --snapshot --clean --single-target
|
||||
@cp -v cmd/builder/Dockerfile dist/builder_linux_amd64_v1/Dockerfile
|
||||
@cp -v cmd/fetcher/Dockerfile dist/fetcher_linux_amd64_v1/Dockerfile
|
||||
@cp -v cmd/fission-bundle/Dockerfile dist/fission-bundle_linux_amd64_v1/Dockerfile
|
||||
@cp -v cmd/reporter/Dockerfile dist/reporter_linux_amd64_v1/Dockerfile
|
||||
@cp -v cmd/preupgradechecks/Dockerfile dist/pre-upgrade-checks_linux_amd64_v1/Dockerfile
|
||||
|
||||
skaffold-deploy: skaffold-prebuild
|
||||
skaffold run -p $(SKAFFOLD_PROFILE)
|
||||
|
||||
### Release
|
||||
release:
|
||||
@./hack/generate-helm-manifest.sh $(VERSION)
|
||||
@./hack/release.sh $(VERSION)
|
||||
@./hack/release-tag.sh $(VERSION)
|
||||
@./hack/changelog.sh
|
||||
|
||||
## Envtest
|
||||
install-envtest:
|
||||
go install sigs.k8s.io/controller-runtime/tools/setup-envtest@latest
|
||||
|
||||
setup-envtest:
|
||||
setup-envtest -p path use 1.23.x
|
||||
|
||||
@@ -1,10 +1,44 @@
|
||||
# Fission: Serverless Functions for Kubernetes
|
||||
<p align="center">
|
||||
<img src="https://fission.io/images/logo-gh.svg" width="300" />
|
||||
<br>
|
||||
<h1 align="center">Fission: Serverless Functions for Kubernetes</h1>
|
||||
</p>
|
||||
|
||||
[](https://travis-ci.org/fission/fission)
|
||||
[](https://goreportcard.com/report/github.com/fission/fission)
|
||||
[](http://slack.fission.io)
|
||||
<p align="center">
|
||||
<a href="https://github.com/fission/fission/blob/main/LICENSE">
|
||||
<img alt="Fission Licence" src="https://img.shields.io/github/license/fission/fission">
|
||||
</a>
|
||||
<a href="https://github.com/fission/fission/releases">
|
||||
<img alt="Fission Releases" src="https://img.shields.io/github/release-pre/fission/fission.svg">
|
||||
</a>
|
||||
<a href="https://pkg.go.dev/github.com/fission/fission">
|
||||
<img alt="go.dev reference" src="https://img.shields.io/badge/go.dev-reference-007d9c?logo=go&logoColor=white">
|
||||
</a>
|
||||
<a href="https://goreportcard.com/report/github.com/fission/fission">
|
||||
<img src="https://goreportcard.com/badge/github.com/fission/fission" alt="Go Report Card" />
|
||||
</a>
|
||||
<a href="https://github.com/fission/fission/graphs/contributors">
|
||||
<img alt="Fission contributors" src="https://img.shields.io/github/contributors/fission/fission">
|
||||
</a>
|
||||
<a href="https://github.com/fission/fission/commits/main">
|
||||
<img alt="Commit Activity" src="https://img.shields.io/github/commit-activity/m/fission/fission">
|
||||
</a>
|
||||
<br>
|
||||
<a href="https://fission.io/">
|
||||
<img alt="Fission website" src="https://img.shields.io/badge/website-fission.io-blue">
|
||||
</a>
|
||||
<a href="https://fission.io/slack">
|
||||
<img alt="Fission slack" src="https://badgen.net/badge/slack/Fission?icon=slack">
|
||||
</a>
|
||||
<a href="https://twitter.com/fissionio">
|
||||
<img alt="Fission twitter" src="https://img.shields.io/twitter/follow/fissionio?style=social">
|
||||
</a>
|
||||
<a href="https://github.com/fission/fission">
|
||||
<img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/fission/fission?style=social">
|
||||
</a>
|
||||
</p>
|
||||
|
||||
[fission.io](http://fission.io) [@fissionio](http://twitter.com/fissionio)
|
||||
--------------
|
||||
|
||||
Fission is a fast serverless framework for Kubernetes with a focus on
|
||||
developer productivity and high performance.
|
||||
@@ -18,7 +52,19 @@ language-specific parts are isolated in something called
|
||||
_environments_ (more below). Fission currently supports NodeJS, Python, Ruby, Go,
|
||||
PHP, Bash, and any Linux executable, with more languages coming soon.
|
||||
|
||||
# Performance: 100msec cold start
|
||||
Table of Contents
|
||||
=================
|
||||
- [Table of Contents](#table-of-contents)
|
||||
- [Performance: 100msec cold start](#performance-100msec-cold-start)
|
||||
- [Kubernetes is the right place for Serverless](#kubernetes-is-the-right-place-for-serverless)
|
||||
- [Getting Started](#getting-started)
|
||||
- [Learn More](#learn-more)
|
||||
- [Contributing](#contributing)
|
||||
- [Who is using Fission?](#who-is-using-fission)
|
||||
- [Sponsors](#sponsors)
|
||||
- [License](#license)
|
||||
|
||||
## Performance: 100msec cold start
|
||||
|
||||
Fission maintains a pool of "warm" containers that each contain a
|
||||
small dynamic loader. When a function is first called,
|
||||
@@ -26,7 +72,7 @@ i.e. "cold-started", a running container is chosen and the function is
|
||||
loaded. This pool is what makes Fission fast: cold-start latencies
|
||||
are typically about 100msec.
|
||||
|
||||
# Kubernetes is the right place for Serverless
|
||||
## Kubernetes is the right place for Serverless
|
||||
|
||||
We're built on Kubernetes because we think any non-trivial app will
|
||||
use a combination of serverless functions and more conventional
|
||||
@@ -37,60 +83,59 @@ Building on Kubernetes also means that anything you do for operations
|
||||
on your Kubernetes cluster — such as monitoring or log
|
||||
aggregation — also helps with ops on your Fission deployment.
|
||||
|
||||
# Getting started and documentation
|
||||
|
||||
## Fission Concepts
|
||||
|
||||
Visit [concepts](https://docs.fission.io/docs/concepts/) for more details.
|
||||
|
||||
## Documentations
|
||||
|
||||
You can learn more about Fission and get started from [Fission Docs](https://docs.fission.io/docs).
|
||||
* See the [installation guide](https://docs.fission.io/docs/installation/) for installing and running Fission.
|
||||
* See the [troubleshooting guide](https://docs.fission.io/docs/trouble-shooting/) for debugging your functions and Fission installation.
|
||||
|
||||
## Usage
|
||||
## Getting Started
|
||||
|
||||
```bash
|
||||
# Add the stock NodeJS env to your Fission deployment
|
||||
$ fission env create --name nodejs --image fission/node-env
|
||||
|
||||
# A javascript one-liner that prints "hello world"
|
||||
$ curl https://raw.githubusercontent.com/fission/fission/master/examples/nodejs/hello.js > hello.js
|
||||
|
||||
# Upload your function code to fission
|
||||
$ fission function create --name hello --env nodejs --code hello.js
|
||||
|
||||
# Map GET /hello to your new function
|
||||
$ fission route create --method GET --url /hello --function hello
|
||||
# Create a function with a javascript one-liner that prints "hello world"
|
||||
$ fission function create --name hello --env nodejs --code https://raw.githubusercontent.com/fission/examples/master/nodejs/hello.js
|
||||
|
||||
# Run the function. This takes about 100msec the first time.
|
||||
$ fission function test --name hello
|
||||
Hello, world!
|
||||
```
|
||||
|
||||
# Contributing
|
||||
## Learn More
|
||||
|
||||
## Building Fission
|
||||
See the [compilation guide](https://docs.fission.io/docs/contributing/).
|
||||
- Understand [Fission Concepts](https://fission.io/docs/concepts/).
|
||||
- See the [installation guide](https://fission.io/docs/installation/) for installing and running Fission.
|
||||
- You can learn more about Fission and get started from [Fission Docs](https://fission.io/docs).
|
||||
- To see Fission in action, check out the [Fission Examples Repo](https://github.com/fission/examples).
|
||||
- See the [troubleshooting guide](https://fission.io/docs/trouble-shooting/) for debugging your functions and Fission installation.
|
||||
|
||||
## Contact
|
||||
Reach us on [slack](http://slack.fission.io) or [twitter](https://twitter.com/fissionio).
|
||||
## Contributing
|
||||
|
||||
Fission is a project by [many contributors](https://github.com/fission/fission/graphs/contributors).
|
||||
Check out the [contributing guide](CONTRIBUTING.md).
|
||||
|
||||
## Community meeting
|
||||
## Who is using Fission?
|
||||
- [Fareye](https://www.getfareye.com)
|
||||
- Apple
|
||||
- [iQuanti](https://www.iquanti.com)
|
||||
- A large telecom CSP
|
||||
- [Gadget](https://gadget.dev)
|
||||
- [CinnamonAI](https://cinnamon.is/en)
|
||||
- [Armo](https://www.armosec.io/)
|
||||
- [The Social Audience](https://thesocialaudience.com/)
|
||||
- [KubeML](https://github.com/DiegoStock12/kubeml)
|
||||
- Unilever
|
||||
- [BD](https://www.bd.com/en-in)
|
||||
- [Biofourmis](https://biofourmis.com/)
|
||||
- [Babylon](https://www.babylonhealth.com/en-gb)
|
||||
|
||||
A regular community meeting takes place every other Thursday at 08:30 AM PT (Pacific Time). [Convert to your local timezone](http://www.thetimezoneconverter.com/?t=08:30&tz=PT%20%28Pacific%20Time%29).
|
||||
## Sponsors
|
||||
|
||||
# Official Releases
|
||||
The following companies, organizations, and individuals support Fission's ongoing maintenance and development. If you are using/contributing to Fission, we would be happy to list you here, please raise a Pull request.
|
||||
|
||||
Official releases of Fission can be found on [the releases page](https://github.com/fission/fission/releases).
|
||||
Please note that it is strongly recommended that you use official releases of Fission, as unreleased versions from
|
||||
the master branch are subject to changes and incompatibilities that will not be supported in the official releases.
|
||||
Builds from the master branch can have functionality changed and even removed at any time without compatibility support
|
||||
and without prior notice.
|
||||
<p>
|
||||
<a href="https://infracloud.io/"><img src="https://fission.io/sponsors/infracloud.png" alt="InfraCloud" height="70"></a>
|
||||
<a href="https://srcmesh.com/"><img src="https://fission.io/sponsors/srcmesh.png" alt="Srcmesh" height="70"></a>
|
||||
<a href="https://www.digitalocean.com/?utm_medium=opensource&utm_source=fissionio">
|
||||
<img src="https://opensource.nyc3.cdn.digitaloceanspaces.com/attribution/assets/PoweredByDO/DO_Powered_by_Badge_blue.svg" width="201px">
|
||||
</a>
|
||||
</p>
|
||||
|
||||
# Licensing
|
||||
# License
|
||||
|
||||
Fission is under the Apache 2.0 license.
|
||||
Fission is licensed under the Apache License 2.0 - see the [LICENSE](./LICENSE) file for details
|
||||
|
||||
+17
@@ -0,0 +1,17 @@
|
||||
# Security Policy
|
||||
|
||||
## Supported Versions
|
||||
|
||||
Please refer using [latest stable release](https://github.com/fission/fission/releases/latest) of Fission.
|
||||
|
||||
| Version | Supported |
|
||||
| ------- | ------------------ |
|
||||
| >=1.14.x | :white_check_mark: |
|
||||
| < 1.14.0 | :x: |
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
Please send the details to both of us:
|
||||
|
||||
- Sanket Sudake sanket@infracloud.io
|
||||
- Vishal Biyani vishal@infracloud.io
|
||||
@@ -1,121 +0,0 @@
|
||||
# Fission
|
||||
|
||||
[Fission](http://fission.io/) is a framework for serverless functions on Kubernetes.
|
||||
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Kubernetes 1.9 or later
|
||||
|
||||
|
||||
## Helm charts
|
||||
|
||||
The following table lists two helm charts for Fission.
|
||||
|
||||
| Parameter | Description |
|
||||
| ---------------| ---------------------------------------------------------------------------------------|
|
||||
| `fission-core` | FaaS essentials, and triggers for HTTP, Timers and Kubernetes Watches |
|
||||
| `fission-all` | Log aggregation with fluentd and InfluxDB; NATS for message queue triggers; Fission-UI |
|
||||
|
||||
## Installing the chart
|
||||
|
||||
To install the chart with the release name `my-release`,
|
||||
|
||||
```bash
|
||||
$ helm install --name my-release fission-all
|
||||
```
|
||||
|
||||
## Uninstalling the chart
|
||||
|
||||
To uninstall/delete chart,
|
||||
|
||||
```bash
|
||||
$ helm delete my-release
|
||||
```
|
||||
|
||||
## Configuration
|
||||
|
||||
The following table lists the configurable parameters of the Fission chart and their default values.
|
||||
|
||||
Parameter | Description | Default
|
||||
--------- | ----------- | -------
|
||||
`serviceType` | Type of Fission Controller service to use. For minikube, set this to NodePort, elsewhere use LoadBalancer or ClusterIP. | `ClusterIP`
|
||||
`routerServiceType` | Type of Fission Router service to use. For minikube, set this to NodePort, elsewhere use LoadBalancer or ClusterIP. | `LoadBalancer`
|
||||
`repository` | Image base repository | `index.docker.io`
|
||||
`image` | Fission image repository | `fission/fission-bundle`
|
||||
`imageTag` | Fission image tag | `1.7.0-rc.1`
|
||||
`pullPolicy` | Image pull policy | `IfNotPresent`
|
||||
`fetcherImage` | Fission fetcher repository | `fission/fetcher`
|
||||
`fetcherImageTag` | Fission fetcher image tag | `1.7.0-rc.1`
|
||||
`controllerPort` | Fission Controller service port | `31313`
|
||||
`routerPort` | Fission Router service port | ` 31314`
|
||||
`functionNamespace` | Namespace in which to run fission functions (this is different from the release namespace) | `fission-function`
|
||||
`builderNamespace` | Namespace in which to run fission builders (this is different from the release namespace) | `fission-builder`
|
||||
`enableIstio` | Enable istio integration | `false`
|
||||
`persistence.enabled` | If true, persist data to a persistent volume | `true`
|
||||
`persistence.existingClaim` | Provide an existing PersistentVolumeClaim instead of creating a new one | `nil`
|
||||
`persistence.storageClass` | PersistentVolumeClaim storage class | `nil`
|
||||
`persistence.accessMode` | PersistentVolumeClaim access mode | `ReadWriteOnce`
|
||||
`persistence.size` | PersistentVolumeClaim size | `8Gi`
|
||||
`analytics` | Analytics let us count how many people installed fission. Set to false to disable analytics | `true`
|
||||
`analyticsNonHelmInstall` | Internally used for generating an analytics job for non-helm installs | `false`
|
||||
`pruneInterval` | The frequency of archive pruner (in minutes) | `60`
|
||||
`preUpgradeChecksImage` | Fission pre-install/pre-upgrade checks live in this image | `fission/pre-upgrade-checks`
|
||||
`debugEnv` | If there are any pod specialization errors when a function is triggered and this flag is set to true, the error summary is returned as part of http response | `true`
|
||||
`prometheus.enabled` | Set to true if prometheus needs to be deployed along with fission | `true` in `fission-all`, `false` in `fission-core`
|
||||
`prometheus.serviceEndpoint` | If prometheus.enabled is false, please assign the prometheus service URL that is accessible by components. | `nil`
|
||||
`canaryDeployment.enabled` | Set to true if you need canary deployment feature | `true` in `fission-all`, `false` in `fission-core`
|
||||
`extraCoreComponentPodConfig` | Extend the container specs for the core fission pods. Can be used to add things like affinty/tolerations/nodeSelectors/etc. | None
|
||||
`router.deployAsDaemonSet` | Deploy router as DaemonSet instead of Deployment | `false`
|
||||
`router.svcAddressMaxRetries` | Max retries times for router to retry on a certain service URL returns from cache/executor | `5`
|
||||
`router.svcAddressUpdateTimeout` | The length of update lock expiry time for router to get a service URL returns from executor | `30`
|
||||
`router.svcAnnotations` | Annotations for router service | None
|
||||
`router.useEncodedPath` | For router to match encoded path. If true, "/foo%2Fbar" will match the path "/{var}"; Otherwise, it will match the path "/foo/bar". | `false`
|
||||
`router.traceSamplingRate` | Uniformly sample traces with the given probabilistic sampling rate | `0.5`
|
||||
`router.roundTrip.disableKeepAlive` | Disable transport keep-alive for fast switching function version | `true`
|
||||
`router.roundTrip.keepAliveTime` | The keep-alive period for an active network connection to function pod | `30s`
|
||||
`router.roundTrip.timeout` | HTTP transport request timeout | `50ms`
|
||||
`router.roundTrip.timeoutExponent` | The length of request timeout will multiply with timeoutExponent after each retry | `2`
|
||||
`router.roundTrip.maxRetries` | Max retries times of a failed request | `10`
|
||||
|
||||
### Extra configuration for `fission-all`
|
||||
|
||||
Parameter | Description | Default
|
||||
--------- | ----------- | -------
|
||||
`createNamespace` | If true, create `fission-function` and `fission-builder` namespaces | ` true`
|
||||
`logger.influxdbAdmin` | Log database admin username | `admin`
|
||||
`logger.fluentdImageRepository` | Logger fluentbit image repository | `index.docker.io`
|
||||
`logger.fluentdImage` | Logger fluentbit image | `fluent/fluent-bit`
|
||||
`logger.fluentdImageTag` | Logger fluentbit image tag | `1.0.4`
|
||||
`nats.enabled` | Nats streaming enabled | `true`
|
||||
`nats.authToken` | Nats streaming auth token | `defaultFissionAuthToken`
|
||||
`nats.clusterID` | Nats streaming clusterID | `fissionMQTrigger`
|
||||
`natsStreamingPort` | Nats streaming service port | `31316`
|
||||
`azureStorageQueue.enabled` | Azure storage account name | `false`
|
||||
`azureStorageQueue.key` | Azure storage account name | `""`
|
||||
`azureStorageQueue.accountName` | Azure storage access key | `""`
|
||||
`kafka.enabled` | Kafka trigger enabled | `false`
|
||||
`kafka.brokers` | Kafka brokers uri | `broker.kafka:9092`
|
||||
`kafka.version` | Kafka broker version | `nil`
|
||||
`heapster` | Enable Heapster (only enable this in clusters where heapster does not exist already) | `false`
|
||||
|
||||
Please note that deploying of Azure Storage Queue or Kafka is not done by Fission chart and you will have to explicitly deploy them.
|
||||
|
||||
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example,
|
||||
|
||||
```bash
|
||||
$ helm install --name my-release --set image=custom/fission-bundle,imageTag=v1 fission-all
|
||||
```
|
||||
|
||||
If you're using minikube, set serviceType and routerServiceType to NodePort:
|
||||
|
||||
```bash
|
||||
$ helm install --name my-release --set serviceType=NodePort,routerServiceType=NodePort fission-all
|
||||
```
|
||||
|
||||
You can also set parameters with a yaml file (see [values.yaml](fission-all/values.yaml) for
|
||||
what it should look like):
|
||||
|
||||
```bash
|
||||
$ helm install --name my-release -f values.yaml fission-all
|
||||
```
|
||||
@@ -1,15 +1,24 @@
|
||||
apiVersion: v1
|
||||
apiVersion: v2
|
||||
name: fission-all
|
||||
version: 1.7.0-rc.1
|
||||
version: v1.20.0
|
||||
appVersion: v1.20.0
|
||||
description: Fission is a fast serverless framework for Kubernetes.
|
||||
home: https://fission.io/
|
||||
icon: https://fission.io/images/fission-logo-white.svg
|
||||
sources:
|
||||
- https://github.com/fission/fission
|
||||
- https://github.com/fission/keda-connectors
|
||||
keywords:
|
||||
- fission
|
||||
- serverless
|
||||
home: http://fission.io/
|
||||
- fission
|
||||
- serverless
|
||||
- platform
|
||||
- faas
|
||||
- functions
|
||||
- Integration & Delivery
|
||||
maintainers:
|
||||
- name: Soam Vasani
|
||||
email: soamvasani+1@gmail.com
|
||||
- name: Ta Ching Chen
|
||||
email: hello@tachingchen.com
|
||||
- name: Vishal Biyani
|
||||
email: vishal@infracloud.io
|
||||
- name: Sanket Sudake
|
||||
email: sanket@infracloud.io
|
||||
engine: gotpl
|
||||
appVersion: 1.7.0-rc.1
|
||||
type: application
|
||||
@@ -0,0 +1,157 @@
|
||||
# fission-all
|
||||
|
||||
[Fission](https://fission.io/) is a framework for serverless functions on Kubernetes.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Kubernetes 1.23+
|
||||
- Helm 3+
|
||||
|
||||
## Get Repo Info
|
||||
|
||||
```console
|
||||
helm repo add fission-charts https://fission.github.io/fission-charts
|
||||
helm repo update
|
||||
```
|
||||
|
||||
_See [helm repo](https://helm.sh/docs/helm/helm_repo/) for command documentation._
|
||||
|
||||
## Install Chart
|
||||
|
||||
Replace `{{version}}` with [the latest Fission version](https://github.com/fission/fission/releases/latest).
|
||||

|
||||
|
||||
```console
|
||||
# Helm
|
||||
$ export FISSION_NAMESPACE="fission"
|
||||
$ kubectl create namespace $FISSION_NAMESPACE
|
||||
$ kubectl create -k "github.com/fission/fission/crds/v1?ref={{version}}"
|
||||
$ helm install [RELEASE_NAME] fission-charts/fission-all --namespace fission
|
||||
```
|
||||
|
||||
_See [configuration](#configuration) below._
|
||||
|
||||
_See [helm install](https://helm.sh/docs/helm/helm_install/) for command documentation._
|
||||
|
||||
## Dependencies
|
||||
|
||||
By default, this chart installs additional, dependent charts:
|
||||
|
||||
- [prometheus-community/prometheus](https://github.com/prometheus-community/helm-charts/tree/main/charts/prometheus)
|
||||
|
||||
To disable dependencies during installation, see [multiple releases](#multiple-releases) below.
|
||||
|
||||
_See [helm dependency](https://helm.sh/docs/helm/helm_dependency/) for command documentation._
|
||||
|
||||
## Uninstall Chart
|
||||
|
||||
```console
|
||||
# Helm
|
||||
$ helm uninstall [RELEASE_NAME]
|
||||
```
|
||||
|
||||
This removes all the Kubernetes components associated with the chart and deletes the release.
|
||||
|
||||
_See [helm uninstall](https://helm.sh/docs/helm/helm_uninstall/) for command documentation._
|
||||
|
||||
CRDs are not removed by this chart and should be manually cleaned up:
|
||||
|
||||
`{{version}}` references the version you used during the installation of chart.
|
||||
|
||||
```console
|
||||
kubectl delete -k "github.com/fission/fission/crds/v1?ref={{version}}"
|
||||
```
|
||||
|
||||
OR
|
||||
|
||||
You can list all Fission CRDs and clean them up with `kubectl delete crd` command.
|
||||
|
||||
```console
|
||||
kubectl get crds| grep ".fission.io"
|
||||
```
|
||||
|
||||
## Upgrading Chart
|
||||
|
||||
CRDs created by this chart are not updated by default and should be manually updated.
|
||||
|
||||
`{{version}}` references the version you are upgrading to 
|
||||
|
||||
```console
|
||||
kubectl replace -k "github.com/fission/fission/crds/v1?ref={{version}}"
|
||||
```
|
||||
|
||||
```console
|
||||
# Helm
|
||||
$ helm upgrade [RELEASE_NAME] fission-charts/fission-all
|
||||
```
|
||||
|
||||
_See [configuration](#configuration) below._
|
||||
|
||||
_See [helm upgrade](https://helm.sh/docs/helm/helm_upgrade/) for command documentation._
|
||||
|
||||
### Upgrading an existing Release to a new major version
|
||||
|
||||
A major chart version change (like v1.2.3 -> v2.0.0) indicates that there is an incompatible breaking change needing manual actions.
|
||||
|
||||
### Upgrade from 1.18.x to 1.20.x
|
||||
|
||||
We have removed controller service from fission-all chart.
|
||||
|
||||
### Upgrade from 1.17.x to 1.18.x
|
||||
|
||||
With 1.18.x, we have major change in the way we are deploying Fission.
|
||||
We have added parameters `defaultNamespace`, `additionalFissionNamespaces`, `functionNamespace` and `builderNamespace` to manage the namespaces.
|
||||
We watch and manage specific namespaces for Fission resources configured via `defaultNamespace` and `additionalFissionNamespaces` parameters.
|
||||
You dont need to worry about `builderNamespace` and `functionNamespace` parameters, unless you want to consider legacy Fission resources.
|
||||
|
||||
Please refer to [core changes](https://fission.io/docs/releases/v1.18.0/#fission-core-changes) for more details.
|
||||
|
||||
### Upgrade from 1.16.x to 1.17.x
|
||||
|
||||
By default, Fission runs with the default security context. This means that it will be run as root. We have added settings in Helm chart for securityContext across all services in Fission. You can enable recommended securityContext settings during Fission installation.
|
||||
|
||||
Please refer to [security context settings](https://fission.io/docs/releases/v1.17.0/#security-context-setting-for-fission-installation) for more details.
|
||||
|
||||
### Upgrade from 1.15.x to 1.16.x
|
||||
|
||||
If you have been using `prometheus.enabled=true` in your fission-all chart, you will need to deploy the prometheus using prometheus community supported chart.
|
||||
We have removed prometheus dependency from fission-all chart.
|
||||
We would recommend [prometheus-community/prometheus](https://artifacthub.io/packages/helm/prometheus-community/prometheus) or [prometheus-community/kube-prometheus-stack](https://artifacthub.io/packages/helm/prometheus-community/kube-prometheus-stack) chart.
|
||||
|
||||
### Upgrade from 1.14.x to 1.15.x
|
||||
|
||||
With 1.15.x release, following changes are made:
|
||||
|
||||
- `fission-core` chart is removed
|
||||
- `fission-all` chart is made similar `fission-core` chart
|
||||
- In the `fission-all` chart, the following components are disabled which were enabled by default earlier. If you want to enable them, please use `--set` flag.
|
||||
|
||||
- nats - Set `nats.enabled=true` to enable Fission Nats integration
|
||||
- influxdb - Set `influxdb.enabled=true` to enable Fission InfluxDB and logger component
|
||||
- prometheus - Set `prometheus.enabled=true` to install Prometheus with Fission
|
||||
- canaryDeployment - Set `canaryDeployment.enabled=true` to enable Canary Deployment
|
||||
|
||||
## Migrating from fission-core chart
|
||||
|
||||
With the release of Fission v1.15.x, the fission-core chart was removed.
|
||||
Fission-all is now exactly similar to fission-core and can be used to migrate from fission-core.
|
||||
|
||||
If you are upgrading from the fission-core chart, you can use the following command to migrate with required changes.
|
||||
|
||||
```console
|
||||
helm upgrade [RELEASE_NAME] fission-charts/fission-all --namespace fission
|
||||
```
|
||||
|
||||
## Configuration
|
||||
|
||||
See [Customizing the Chart Before Installing](https://helm.sh/docs/intro/using_helm/#customizing-the-chart-before-installing). To see all configurable options with detailed comments:
|
||||
|
||||
```console
|
||||
helm show values fission-charts/fission-all
|
||||
```
|
||||
|
||||
You may also `helm show values` on this chart's [dependencies](#dependencies) for additional options.
|
||||
|
||||
### Multiple releases
|
||||
|
||||
The same chart can be used to run multiple Fission instances in the same cluster if required.
|
||||
@@ -16,7 +16,8 @@
|
||||
|
||||
[FILTER]
|
||||
Name kubernetes
|
||||
Match log.*
|
||||
Match *
|
||||
Kube_Tag_Prefix log.var.log.fission.
|
||||
Kube_URL https://kubernetes.default.svc.cluster.local:443
|
||||
|
||||
#
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
exclusions:
|
||||
template-job-rule:
|
||||
reason: "Most panels dont need to be filtered by job"
|
||||
template-instance-rule:
|
||||
reason: "Most panels dont need to be filtered by instance"
|
||||
target-job-rule:
|
||||
reason: "Most panels dont need to be filtered by job"
|
||||
target-instance-rule:
|
||||
reason: "Most panels dont need to be filtered by instance"
|
||||
panel-units-rule:
|
||||
reason: "Some panels are using the 'number' unit which throws a linting error."
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,648 @@
|
||||
{
|
||||
"annotations": {
|
||||
"list": [
|
||||
{
|
||||
"builtIn": 1,
|
||||
"datasource": {
|
||||
"type": "grafana",
|
||||
"uid": "-- Grafana --"
|
||||
},
|
||||
"enable": true,
|
||||
"hide": true,
|
||||
"iconColor": "rgba(0, 211, 255, 1)",
|
||||
"name": "Annotations & Alerts",
|
||||
"target": {
|
||||
"limit": 100,
|
||||
"matchAny": false,
|
||||
"tags": [],
|
||||
"type": "dashboard"
|
||||
},
|
||||
"type": "dashboard"
|
||||
}
|
||||
]
|
||||
},
|
||||
"editable": true,
|
||||
"fiscalYearStartMonth": 0,
|
||||
"graphTooltip": 0,
|
||||
"links": [],
|
||||
"liveNow": false,
|
||||
"panels": [
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"description": "Shows function calls, namespaces and their response codes.",
|
||||
"fieldConfig": {
|
||||
"defaults": {
|
||||
"color": {
|
||||
"mode": "palette-classic"
|
||||
},
|
||||
"custom": {
|
||||
"axisLabel": "",
|
||||
"axisPlacement": "auto",
|
||||
"barAlignment": 0,
|
||||
"drawStyle": "line",
|
||||
"fillOpacity": 0,
|
||||
"gradientMode": "none",
|
||||
"hideFrom": {
|
||||
"legend": false,
|
||||
"tooltip": false,
|
||||
"viz": false
|
||||
},
|
||||
"lineInterpolation": "linear",
|
||||
"lineWidth": 1,
|
||||
"pointSize": 5,
|
||||
"scaleDistribution": {
|
||||
"type": "linear"
|
||||
},
|
||||
"showPoints": "auto",
|
||||
"spanNulls": false,
|
||||
"stacking": {
|
||||
"group": "A",
|
||||
"mode": "none"
|
||||
},
|
||||
"thresholdsStyle": {
|
||||
"mode": "off"
|
||||
}
|
||||
},
|
||||
"mappings": [],
|
||||
"thresholds": {
|
||||
"mode": "absolute",
|
||||
"steps": [
|
||||
{
|
||||
"color": "green",
|
||||
"value": null
|
||||
},
|
||||
{
|
||||
"color": "red",
|
||||
"value": 80
|
||||
}
|
||||
]
|
||||
},
|
||||
"unit": "reqps"
|
||||
},
|
||||
"overrides": []
|
||||
},
|
||||
"gridPos": {
|
||||
"h": 8,
|
||||
"w": 12,
|
||||
"x": 0,
|
||||
"y": 0
|
||||
},
|
||||
"id": 2,
|
||||
"options": {
|
||||
"legend": {
|
||||
"calcs": [],
|
||||
"displayMode": "list",
|
||||
"placement": "bottom"
|
||||
},
|
||||
"tooltip": {
|
||||
"mode": "single",
|
||||
"sort": "none"
|
||||
}
|
||||
},
|
||||
"targets": [
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"editorMode": "code",
|
||||
"expr": "increase(fission_function_calls_total{function_name=~\"$Function_Name\",function_namespace=~\"$Function_Namespace\"}[1m])",
|
||||
"interval": "",
|
||||
"legendFormat": "Namespace:{{function_namespace}} Func:{{function_name}} {{method}} Response: {{code}} ",
|
||||
"range": true,
|
||||
"refId": "A"
|
||||
}
|
||||
],
|
||||
"title": "Function calls",
|
||||
"type": "timeseries"
|
||||
},
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"description": "Shows any functions that return 400 or 500 errors.",
|
||||
"fieldConfig": {
|
||||
"defaults": {
|
||||
"color": {
|
||||
"mode": "palette-classic"
|
||||
},
|
||||
"custom": {
|
||||
"axisLabel": "",
|
||||
"axisPlacement": "auto",
|
||||
"barAlignment": 0,
|
||||
"drawStyle": "line",
|
||||
"fillOpacity": 0,
|
||||
"gradientMode": "none",
|
||||
"hideFrom": {
|
||||
"legend": false,
|
||||
"tooltip": false,
|
||||
"viz": false
|
||||
},
|
||||
"lineInterpolation": "linear",
|
||||
"lineWidth": 1,
|
||||
"pointSize": 5,
|
||||
"scaleDistribution": {
|
||||
"type": "linear"
|
||||
},
|
||||
"showPoints": "auto",
|
||||
"spanNulls": false,
|
||||
"stacking": {
|
||||
"group": "A",
|
||||
"mode": "none"
|
||||
},
|
||||
"thresholdsStyle": {
|
||||
"mode": "off"
|
||||
}
|
||||
},
|
||||
"mappings": [],
|
||||
"thresholds": {
|
||||
"mode": "absolute",
|
||||
"steps": [
|
||||
{
|
||||
"color": "green",
|
||||
"value": null
|
||||
},
|
||||
{
|
||||
"color": "red",
|
||||
"value": 80
|
||||
}
|
||||
]
|
||||
},
|
||||
"unit": "reqps"
|
||||
},
|
||||
"overrides": []
|
||||
},
|
||||
"gridPos": {
|
||||
"h": 8,
|
||||
"w": 12,
|
||||
"x": 12,
|
||||
"y": 0
|
||||
},
|
||||
"id": 6,
|
||||
"options": {
|
||||
"legend": {
|
||||
"calcs": [],
|
||||
"displayMode": "list",
|
||||
"placement": "bottom"
|
||||
},
|
||||
"tooltip": {
|
||||
"mode": "single",
|
||||
"sort": "none"
|
||||
}
|
||||
},
|
||||
"targets": [
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"editorMode": "code",
|
||||
"expr": "increase(fission_function_errors_total{function_name=~\"$Function_Name\",function_namespace=~\"$Function_Namespace\"}[1m])",
|
||||
"legendFormat": "Namespace:{{function_namespace}} Function:{{function_name}} Response:{{code}} ",
|
||||
"range": true,
|
||||
"refId": "A"
|
||||
}
|
||||
],
|
||||
"title": "Function Errors",
|
||||
"type": "timeseries"
|
||||
},
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"description": "Tracks cold starts of all functions.",
|
||||
"fieldConfig": {
|
||||
"defaults": {
|
||||
"color": {
|
||||
"mode": "palette-classic"
|
||||
},
|
||||
"custom": {
|
||||
"axisLabel": "",
|
||||
"axisPlacement": "auto",
|
||||
"barAlignment": 0,
|
||||
"drawStyle": "line",
|
||||
"fillOpacity": 0,
|
||||
"gradientMode": "none",
|
||||
"hideFrom": {
|
||||
"legend": false,
|
||||
"tooltip": false,
|
||||
"viz": false
|
||||
},
|
||||
"lineInterpolation": "linear",
|
||||
"lineWidth": 1,
|
||||
"pointSize": 5,
|
||||
"scaleDistribution": {
|
||||
"type": "linear"
|
||||
},
|
||||
"showPoints": "auto",
|
||||
"spanNulls": false,
|
||||
"stacking": {
|
||||
"group": "A",
|
||||
"mode": "none"
|
||||
},
|
||||
"thresholdsStyle": {
|
||||
"mode": "off"
|
||||
}
|
||||
},
|
||||
"mappings": [],
|
||||
"thresholds": {
|
||||
"mode": "absolute",
|
||||
"steps": [
|
||||
{
|
||||
"color": "green",
|
||||
"value": null
|
||||
},
|
||||
{
|
||||
"color": "red",
|
||||
"value": 80
|
||||
}
|
||||
]
|
||||
},
|
||||
"unit": "none"
|
||||
},
|
||||
"overrides": []
|
||||
},
|
||||
"gridPos": {
|
||||
"h": 8,
|
||||
"w": 12,
|
||||
"x": 0,
|
||||
"y": 8
|
||||
},
|
||||
"id": 4,
|
||||
"options": {
|
||||
"legend": {
|
||||
"calcs": [],
|
||||
"displayMode": "list",
|
||||
"placement": "bottom"
|
||||
},
|
||||
"tooltip": {
|
||||
"mode": "single",
|
||||
"sort": "none"
|
||||
}
|
||||
},
|
||||
"targets": [
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"editorMode": "code",
|
||||
"expr": "increase(fission_function_cold_starts_total{function_name=~\"$Function_Name\",function_namespace=~\"$Function_Namespace\"}[1m])",
|
||||
"legendFormat": "{{function_name}}",
|
||||
"range": true,
|
||||
"refId": "A"
|
||||
}
|
||||
],
|
||||
"title": "Function cold starts",
|
||||
"type": "timeseries"
|
||||
},
|
||||
{
|
||||
"collapsed": false,
|
||||
"gridPos": {
|
||||
"h": 1,
|
||||
"w": 24,
|
||||
"x": 0,
|
||||
"y": 16
|
||||
},
|
||||
"id": 12,
|
||||
"panels": [],
|
||||
"title": "Http Requests",
|
||||
"type": "row"
|
||||
},
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"description": "Shows the number of requests currently in flight per function path",
|
||||
"fieldConfig": {
|
||||
"defaults": {
|
||||
"color": {
|
||||
"mode": "palette-classic"
|
||||
},
|
||||
"custom": {
|
||||
"axisLabel": "",
|
||||
"axisPlacement": "auto",
|
||||
"barAlignment": 0,
|
||||
"drawStyle": "line",
|
||||
"fillOpacity": 0,
|
||||
"gradientMode": "none",
|
||||
"hideFrom": {
|
||||
"legend": false,
|
||||
"tooltip": false,
|
||||
"viz": false
|
||||
},
|
||||
"lineInterpolation": "linear",
|
||||
"lineWidth": 1,
|
||||
"pointSize": 5,
|
||||
"scaleDistribution": {
|
||||
"type": "linear"
|
||||
},
|
||||
"showPoints": "auto",
|
||||
"spanNulls": false,
|
||||
"stacking": {
|
||||
"group": "A",
|
||||
"mode": "none"
|
||||
},
|
||||
"thresholdsStyle": {
|
||||
"mode": "off"
|
||||
}
|
||||
},
|
||||
"mappings": [],
|
||||
"thresholds": {
|
||||
"mode": "absolute",
|
||||
"steps": [
|
||||
{
|
||||
"color": "green",
|
||||
"value": null
|
||||
},
|
||||
{
|
||||
"color": "red",
|
||||
"value": 80
|
||||
}
|
||||
]
|
||||
},
|
||||
"unit": "none"
|
||||
},
|
||||
"overrides": []
|
||||
},
|
||||
"gridPos": {
|
||||
"h": 8,
|
||||
"w": 12,
|
||||
"x": 0,
|
||||
"y": 17
|
||||
},
|
||||
"id": 8,
|
||||
"options": {
|
||||
"legend": {
|
||||
"calcs": [],
|
||||
"displayMode": "list",
|
||||
"placement": "bottom"
|
||||
},
|
||||
"tooltip": {
|
||||
"mode": "single",
|
||||
"sort": "none"
|
||||
}
|
||||
},
|
||||
"targets": [
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"editorMode": "code",
|
||||
"expr": "http_requests_in_flight{path=~\"$Path\"}",
|
||||
"legendFormat": "{{path}}",
|
||||
"range": true,
|
||||
"refId": "A"
|
||||
}
|
||||
],
|
||||
"title": "Http Requests in Flight (function)",
|
||||
"type": "timeseries"
|
||||
},
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"description": "Shows the average latency for each path.",
|
||||
"fieldConfig": {
|
||||
"defaults": {
|
||||
"color": {
|
||||
"mode": "palette-classic"
|
||||
},
|
||||
"custom": {
|
||||
"axisLabel": "",
|
||||
"axisPlacement": "auto",
|
||||
"barAlignment": 0,
|
||||
"drawStyle": "line",
|
||||
"fillOpacity": 0,
|
||||
"gradientMode": "none",
|
||||
"hideFrom": {
|
||||
"legend": false,
|
||||
"tooltip": false,
|
||||
"viz": false
|
||||
},
|
||||
"lineInterpolation": "linear",
|
||||
"lineWidth": 1,
|
||||
"pointSize": 5,
|
||||
"scaleDistribution": {
|
||||
"type": "linear"
|
||||
},
|
||||
"showPoints": "auto",
|
||||
"spanNulls": false,
|
||||
"stacking": {
|
||||
"group": "A",
|
||||
"mode": "none"
|
||||
},
|
||||
"thresholdsStyle": {
|
||||
"mode": "off"
|
||||
}
|
||||
},
|
||||
"mappings": [],
|
||||
"thresholds": {
|
||||
"mode": "absolute",
|
||||
"steps": [
|
||||
{
|
||||
"color": "green",
|
||||
"value": null
|
||||
},
|
||||
{
|
||||
"color": "red",
|
||||
"value": 80
|
||||
}
|
||||
]
|
||||
},
|
||||
"unit": "s"
|
||||
},
|
||||
"overrides": []
|
||||
},
|
||||
"gridPos": {
|
||||
"h": 8,
|
||||
"w": 12,
|
||||
"x": 12,
|
||||
"y": 17
|
||||
},
|
||||
"id": 10,
|
||||
"options": {
|
||||
"legend": {
|
||||
"calcs": [],
|
||||
"displayMode": "list",
|
||||
"placement": "bottom"
|
||||
},
|
||||
"tooltip": {
|
||||
"mode": "single",
|
||||
"sort": "none"
|
||||
}
|
||||
},
|
||||
"targets": [
|
||||
{
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"editorMode": "code",
|
||||
"expr": "http_requests_duration_seconds_sum{path!=\"/healthz\",path!~\"/v2/.*\",path!~\"/router.*\",path=~\"$Path\"}/http_requests_duration_seconds_count{path=~\"$Path\"}",
|
||||
"legendFormat": "{{path}}",
|
||||
"range": true,
|
||||
"refId": "A"
|
||||
}
|
||||
],
|
||||
"title": "Request latency",
|
||||
"type": "timeseries"
|
||||
}
|
||||
],
|
||||
"schemaVersion": 36,
|
||||
"style": "dark",
|
||||
"tags": [],
|
||||
"templating": {
|
||||
"list": [
|
||||
{
|
||||
"current": {
|
||||
"selected": false,
|
||||
"text": "Prometheus",
|
||||
"value": "Prometheus"
|
||||
},
|
||||
"hide": 0,
|
||||
"includeAll": false,
|
||||
"label": "Data Source",
|
||||
"multi": false,
|
||||
"name": "datasource",
|
||||
"options": [],
|
||||
"query": "prometheus",
|
||||
"queryValue": "",
|
||||
"refresh": 1,
|
||||
"regex": "",
|
||||
"skipUrlSync": false,
|
||||
"type": "datasource"
|
||||
},
|
||||
{
|
||||
"allValue": ".*",
|
||||
"current": {
|
||||
"selected": false,
|
||||
"text": "All",
|
||||
"value": "$__all"
|
||||
},
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"definition": "label_values(fission_function_calls_total, function_name)",
|
||||
"hide": 0,
|
||||
"includeAll": true,
|
||||
"multi": false,
|
||||
"name": "Function_Name",
|
||||
"options": [],
|
||||
"query": {
|
||||
"query": "label_values(fission_function_calls_total, function_name)",
|
||||
"refId": "StandardVariableQuery"
|
||||
},
|
||||
"refresh": 1,
|
||||
"regex": "",
|
||||
"skipUrlSync": false,
|
||||
"sort": 0,
|
||||
"type": "query"
|
||||
},
|
||||
{
|
||||
"allValue": ".*",
|
||||
"current": {
|
||||
"selected": true,
|
||||
"text": [
|
||||
"All"
|
||||
],
|
||||
"value": [
|
||||
"$__all"
|
||||
]
|
||||
},
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"definition": "label_values(http_requests_total, path)",
|
||||
"hide": 0,
|
||||
"includeAll": true,
|
||||
"multi": true,
|
||||
"name": "Path",
|
||||
"options": [],
|
||||
"query": {
|
||||
"query": "label_values(http_requests_total, path)",
|
||||
"refId": "StandardVariableQuery"
|
||||
},
|
||||
"refresh": 1,
|
||||
"regex": "",
|
||||
"skipUrlSync": false,
|
||||
"sort": 0,
|
||||
"type": "query"
|
||||
},
|
||||
{
|
||||
"allValue": ".*",
|
||||
"current": {
|
||||
"selected": false,
|
||||
"text": "All",
|
||||
"value": "$__all"
|
||||
},
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"definition": "label_values(kube_namespace_labels, namespace)",
|
||||
"description": "",
|
||||
"hide": 0,
|
||||
"includeAll": true,
|
||||
"multi": false,
|
||||
"name": "Function_Namespace",
|
||||
"options": [],
|
||||
"query": {
|
||||
"query": "label_values(kube_namespace_labels, namespace)",
|
||||
"refId": "StandardVariableQuery"
|
||||
},
|
||||
"refresh": 1,
|
||||
"regex": "",
|
||||
"skipUrlSync": false,
|
||||
"sort": 0,
|
||||
"type": "query"
|
||||
},
|
||||
{
|
||||
"current": {
|
||||
"selected": false,
|
||||
"text": "fission",
|
||||
"value": "fission"
|
||||
},
|
||||
"datasource": {
|
||||
"type": "prometheus",
|
||||
"uid": "${datasource}"
|
||||
},
|
||||
"definition": "label_values(fission_function_calls_total, namespace)",
|
||||
"hide": 0,
|
||||
"includeAll": false,
|
||||
"multi": false,
|
||||
"name": "Fission_Namespace",
|
||||
"options": [],
|
||||
"query": {
|
||||
"query": "label_values(fission_function_calls_total, namespace)",
|
||||
"refId": "StandardVariableQuery"
|
||||
},
|
||||
"refresh": 1,
|
||||
"regex": "",
|
||||
"skipUrlSync": false,
|
||||
"sort": 0,
|
||||
"type": "query"
|
||||
}
|
||||
]
|
||||
},
|
||||
"time": {
|
||||
"from": "now-5m",
|
||||
"to": "now"
|
||||
},
|
||||
"timepicker": {},
|
||||
"timezone": "",
|
||||
"title": "Fission User Dashboard",
|
||||
"uid": "he2w3Xq7z",
|
||||
"version": 3,
|
||||
"weekStart": ""
|
||||
}
|
||||
@@ -1,6 +0,0 @@
|
||||
dependencies:
|
||||
- name: prometheus
|
||||
repository: https://kubernetes-charts.storage.googleapis.com
|
||||
version: 9.3.1
|
||||
digest: sha256:33395db6ac17f57dab0e60a47a3e029c59aa4a58fb1695c73b8ea6f0754eaf0c
|
||||
generated: 2019-11-09T02:56:08.384381+08:00
|
||||
@@ -1,5 +0,0 @@
|
||||
dependencies:
|
||||
- name: prometheus
|
||||
version: 9.3.1
|
||||
repository: https://kubernetes-charts.storage.googleapis.com
|
||||
condition: prometheus.enabled
|
||||
@@ -1,25 +1,40 @@
|
||||
1. Install the client CLI.
|
||||
|
||||
Mac:
|
||||
$ curl -Lo fission https://github.com/fission/fission/releases/download/{{ .Chart.Version }}/fission-cli-osx && chmod +x fission && sudo mv fission /usr/local/bin/
|
||||
$ curl -Lo fission https://github.com/fission/fission/releases/download/{{ .Chart.Version }}/fission-{{ .Chart.Version }}-darwin-amd64 && chmod +x fission && sudo mv fission /usr/local/bin/
|
||||
|
||||
Linux:
|
||||
$ curl -Lo fission https://github.com/fission/fission/releases/download/{{ .Chart.Version }}/fission-cli-linux && chmod +x fission && sudo mv fission /usr/local/bin/
|
||||
$ curl -Lo fission https://github.com/fission/fission/releases/download/{{ .Chart.Version }}/fission-{{ .Chart.Version }}-linux-amd64 && chmod +x fission && sudo mv fission /usr/local/bin/
|
||||
|
||||
Windows:
|
||||
For Windows, you can use the linux binary on WSL. Or you can download this windows executable: https://github.com/fission/fission/releases/download/{{ .Chart.Version }}/fission-cli-windows.exe
|
||||
For Windows, you can use the linux binary on WSL. Or you can download this windows executable: https://github.com/fission/fission/releases/download/{{ .Chart.Version }}/fission-{{ .Chart.Version }}-windows-amd64.exe
|
||||
|
||||
2. You're ready to use Fission!
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
You can create fission resources in the namespaces "{{ .Values.defaultNamespace }},{{ join "," .Values.additionalFissionNamespaces }}"
|
||||
{{- else }}
|
||||
You can create fission resources in the namespace "{{ .Values.defaultNamespace }}"
|
||||
{{- end }}
|
||||
|
||||
# Create an environment
|
||||
$ fission env create --name nodejs --image fission/node-env
|
||||
$ fission env create --name nodejs --image fission/node-env --namespace {{ .Values.defaultNamespace }}
|
||||
|
||||
# Get a hello world
|
||||
$ curl https://raw.githubusercontent.com/fission/fission/master/examples/nodejs/hello.js > hello.js
|
||||
$ curl https://raw.githubusercontent.com/fission/examples/master/nodejs/hello.js > hello.js
|
||||
|
||||
# Register this function with Fission
|
||||
$ fission function create --name hello --env nodejs --code hello.js
|
||||
$ fission function create --name hello --env nodejs --code hello.js --namespace {{ .Values.defaultNamespace }}
|
||||
|
||||
{{- if .Values.authentication.enabled }}
|
||||
|
||||
# Create token
|
||||
$ FISSION_USERNAME=$(kubectl get secrets/router --template={{`{{.data.username}}`}} -n fission | base64 -d)
|
||||
$ FISSION_PASSWORD=$(kubectl get secrets/router --template={{`{{.data.password}}`}} -n fission | base64 -d)
|
||||
$ export FISSION_AUTH_TOKEN=$(fission token create --username $FISSION_USERNAME --password $FISSION_PASSWORD)
|
||||
{{- end }}
|
||||
|
||||
# Run this function
|
||||
$ fission function test --name hello
|
||||
$ fission function test --name hello --namespace {{ .Values.defaultNamespace }}
|
||||
Hello, world!
|
||||
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
|
||||
|
||||
{{- define "fision.selfSignedCABundleCertPEM" -}}
|
||||
{{- $caKeypair := .selfSignedCAKeypair | default (genCA "fission-ca" 1825) -}}
|
||||
{{- $_ := set . "selfSignedCAKeypair" $caKeypair -}}
|
||||
{{- $caKeypair.Cert -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "webhook.caBundleCertPEM" -}}
|
||||
{{- if .Values.webhook.caBundlePEM -}}
|
||||
{{- trim .Values.webhook.caBundlePEM -}}
|
||||
{{- else -}}
|
||||
{{- $caKeypair := .selfSignedCAKeypair | default (genCA "fission-ca" 1825) -}}
|
||||
{{- $_ := set . "selfSignedCAKeypair" $caKeypair -}}
|
||||
{{- $caKeypair.Cert -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "webhook.certPEM" -}}
|
||||
{{- if .Values.webhook.crtPEM -}}
|
||||
{{- trim .Values.webhook.crtPEM -}}
|
||||
{{- else -}}
|
||||
{{- $webhookName := printf "%s.%s.svc" (include "fission-webhook.svc" .) .Release.Namespace }}
|
||||
{{- $fullWebhookName := printf "%s.%s.svc.cluster.local" (include "fission-webhook.svc" .) .Release.Namespace -}}
|
||||
{{- $webhookCA := required "self-signed CA keypair is requried" .selfSignedCAKeypair -}}
|
||||
{{- $webhookServerTLSKeypair := .webhookTLSKeypair | default (genSignedCert $webhookName nil (list $webhookName $fullWebhookName) 1825 $webhookCA) }}
|
||||
{{- $_ := set . "webhookTLSKeypair" $webhookServerTLSKeypair -}}
|
||||
{{- $webhookServerTLSKeypair.Cert -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "webhook.keyPEM" -}}
|
||||
{{- if .Values.webhook.keyPEM -}}
|
||||
{{ trim .Values.webhook.keyPEM }}
|
||||
{{- else -}}
|
||||
{{- $webhookName := printf "%s.%s.svc" (include "fission-webhook.svc" .) .Release.Namespace -}}
|
||||
{{- $fullWebhookName := printf "%s.%s.svc.cluster.local" (include "fission-webhook.svc" .) .Release.Namespace -}}
|
||||
{{- $webhookCA := required "self-signed CA keypair is requried" .selfSignedCAKeypair -}}
|
||||
{{- $webhookServerTLSKeypair := .webhookTLSKeypair | default (genSignedCert $webhookName nil (list $webhookName $fullWebhookName) 1825 $webhookCA) -}}
|
||||
{{- $_ := set . "webhookTLSKeypair" $webhookServerTLSKeypair -}}
|
||||
{{- $webhookServerTLSKeypair.Key -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,145 @@
|
||||
{{- define "buildermgr-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- environments
|
||||
- functions
|
||||
- packages
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- end }}
|
||||
{{- define "executor-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- environments
|
||||
- functions
|
||||
- packages
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- end }}
|
||||
{{- define "kubewatcher-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- environments
|
||||
- functions
|
||||
- kuberneteswatchtriggers
|
||||
- packages
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- end }}
|
||||
{{- define "keda-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- environments
|
||||
- functions
|
||||
- messagequeuetriggers
|
||||
- packages
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- end }}
|
||||
{{- define "preupgrade-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- canaryconfigs
|
||||
- environments
|
||||
- functions
|
||||
- httptriggers
|
||||
- kuberneteswatchtriggers
|
||||
- messagequeuetriggers
|
||||
- packages
|
||||
- timetriggers
|
||||
verbs:
|
||||
- list
|
||||
{{- end }}
|
||||
{{- define "router-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- environments
|
||||
- functions
|
||||
- httptriggers
|
||||
- packages
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- end }}
|
||||
{{- define "storagesvc-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- packages
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
{{- end }}
|
||||
{{- define "timer-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- environments
|
||||
- functions
|
||||
- packages
|
||||
- timetriggers
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- end }}
|
||||
{{- define "canaryconfig-rules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- canaryconfigs
|
||||
- httptriggers
|
||||
verbs:
|
||||
- list
|
||||
- watch
|
||||
- get
|
||||
- update
|
||||
{{- end }}
|
||||
@@ -0,0 +1,334 @@
|
||||
{{- define "buildermgr-kuberules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
verbs:
|
||||
- list
|
||||
- create
|
||||
- delete
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
{{- end }}
|
||||
{{- define "canaryconfig-kuberules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- services
|
||||
verbs:
|
||||
- list
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
{{- end }}
|
||||
{{- define "executor-kuberules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- replicationcontrollers
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
{{- if .Values.executor.serviceAccountCheck.enabled }}
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- serviceaccounts
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- apiGroups:
|
||||
- authorization.k8s.io
|
||||
resources:
|
||||
- localsubjectaccessreviews
|
||||
verbs:
|
||||
- create
|
||||
- apiGroups:
|
||||
- rbac.authorization.k8s.io
|
||||
resources:
|
||||
- rolebindings
|
||||
- roles
|
||||
verbs:
|
||||
- create
|
||||
{{- end }}
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- deployments/scale
|
||||
- replicasets
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- autoscaling
|
||||
resources:
|
||||
- horizontalpodautoscalers
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- metrics.k8s.io
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
{{- end }}
|
||||
{{- define "fluentbit-kuberules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
{{- end }}
|
||||
{{- define "kubewatcher-kuberules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
- pods
|
||||
- secrets
|
||||
- services
|
||||
- replicationcontrollers
|
||||
- events
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- batch
|
||||
resources:
|
||||
- jobs
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
{{- end }}
|
||||
{{- define "keda-kuberules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
- services
|
||||
- replicationcontrollers
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- patch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- apps
|
||||
resources:
|
||||
- deployments
|
||||
- deployments/scale
|
||||
- replicasets
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- keda.sh
|
||||
resources:
|
||||
- scaledjobs
|
||||
- scaledobjects
|
||||
- scaledjobs/finalizers
|
||||
- scaledjobs/status
|
||||
- triggerauthentications
|
||||
- triggerauthentications/status
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- if .Values.mqt_keda.enabled }}
|
||||
- apiGroups:
|
||||
- keda.k8s.io
|
||||
resources:
|
||||
- scaledjobs
|
||||
- scaledobjects
|
||||
- scaledjobs/finalizers
|
||||
- scaledjobs/status
|
||||
- triggerauthentications
|
||||
- triggerauthentications/status
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
{{- end }}
|
||||
- apiGroups:
|
||||
- metrics.k8s.io
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
{{- end }}
|
||||
{{- define "preupgrade-kuberules" }}
|
||||
# TODO: Kept for future in case preupgrade needs any permissions in the future
|
||||
rules: []
|
||||
{{- end }}
|
||||
{{- define "router-kuberules" }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- networking.k8s.io
|
||||
resources:
|
||||
- ingresses
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- update
|
||||
- patch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
{{- end }}
|
||||
{{- define "timer-kuberules" }}
|
||||
rules: []
|
||||
{{- end }}
|
||||
@@ -0,0 +1,61 @@
|
||||
{{- define "kubernetes-role-generator" }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
{{- if eq "preupgrade" .component }}
|
||||
annotations:
|
||||
helm.sh/hook: pre-upgrade
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
helm.sh/hook-weight: "-2"
|
||||
{{- end }}
|
||||
name: "{{ .Release.Name }}-{{ .component }}"
|
||||
namespace: {{ .namespace }}
|
||||
{{- if eq "buildermgr" .component }}
|
||||
{{- include "buildermgr-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "canaryconfig" .component }}
|
||||
{{- include "canaryconfig-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "fluentbit" .component }}
|
||||
{{- include "fluentbit-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "executor" .component }}
|
||||
{{- include "executor-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "kubewatcher" .component }}
|
||||
{{- include "kubewatcher-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "keda" .component }}
|
||||
{{- include "keda-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "preupgrade" .component }}
|
||||
{{- include "preupgrade-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "router" .component }}
|
||||
{{- include "router-kuberules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "timer" .component }}
|
||||
{{- include "timer-kuberules" . }}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
kind: RoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
{{- if eq "preupgrade" .component }}
|
||||
annotations:
|
||||
helm.sh/hook: pre-upgrade
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
{{- end }}
|
||||
name: "{{ .Release.Name }}-{{ .component }}"
|
||||
namespace: {{ .namespace }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: "fission-{{ .component }}"
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: "{{ .Release.Name }}-{{ .component }}"
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
{{- end }}
|
||||
@@ -0,0 +1,61 @@
|
||||
{{- define "fission-role-generator" }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
{{- if eq "preupgrade" .component }}
|
||||
annotations:
|
||||
helm.sh/hook: pre-upgrade
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
helm.sh/hook-weight: "-2"
|
||||
{{- end }}
|
||||
name: "{{ .Release.Name }}-{{ .component }}-fission-cr"
|
||||
namespace: {{ .namespace }}
|
||||
{{- if eq "buildermgr" .component }}
|
||||
{{- include "buildermgr-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "executor" .component }}
|
||||
{{- include "executor-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "kubewatcher" .component }}
|
||||
{{- include "kubewatcher-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "keda" .component }}
|
||||
{{- include "keda-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "preupgrade" .component }}
|
||||
{{- include "preupgrade-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "router" .component }}
|
||||
{{- include "router-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "storagesvc" .component }}
|
||||
{{- include "storagesvc-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "timer" .component }}
|
||||
{{- include "timer-rules" . }}
|
||||
{{- end }}
|
||||
{{- if eq "canaryconfig" .component }}
|
||||
{{- include "canaryconfig-rules" . }}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
kind: RoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
{{- if eq "preupgrade" .component }}
|
||||
annotations:
|
||||
helm.sh/hook: pre-upgrade
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
{{- end }}
|
||||
name: "{{ .Release.Name }}-{{ .component }}-fission-cr"
|
||||
namespace: {{ .namespace }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: "fission-{{ .component }}"
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: "{{ .Release.Name }}-{{ .component }}-fission-cr"
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
{{- end }}
|
||||
@@ -0,0 +1,123 @@
|
||||
{{- define "fissionFunction.roles" }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-fetcher
|
||||
namespace: {{ .namespace }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- packages
|
||||
verbs:
|
||||
- get
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-builder
|
||||
namespace: {{ .namespace }}
|
||||
rules:
|
||||
- apiGroups:
|
||||
- fission.io
|
||||
resources:
|
||||
- packages
|
||||
verbs:
|
||||
- get
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- configmaps
|
||||
- secrets
|
||||
verbs:
|
||||
- get
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
namespace: {{ .namespace }}
|
||||
name: {{ .Release.Name }}-fission-fetcher-websocket
|
||||
rules:
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- "events"
|
||||
verbs:
|
||||
- "get"
|
||||
- "list"
|
||||
- "watch"
|
||||
- "create"
|
||||
- "update"
|
||||
- "patch"
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
{{- end -}}
|
||||
|
||||
{{- define "fissionFunction.rolebindings" }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-fetcher
|
||||
namespace: {{ .namespace }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ .Release.Name }}-fission-fetcher
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: fission-fetcher
|
||||
{{- if and (.Values.functionNamespace) (eq .namespace "default") }}
|
||||
namespace: {{ .Values.functionNamespace }}
|
||||
{{- else }}
|
||||
namespace: {{ .namespace }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-builder
|
||||
namespace: {{ .namespace }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ .Release.Name }}-fission-builder
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: fission-builder
|
||||
{{- if and (.Values.builderNamespace) (eq .namespace "default") }}
|
||||
namespace: {{ .Values.builderNamespace }}
|
||||
{{- else }}
|
||||
namespace: {{ .namespace }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-fetcher-websocket
|
||||
namespace: {{ .namespace }}
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: {{ .Release.Name }}-fission-fetcher-websocket
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: fission-fetcher
|
||||
{{- if and (.Values.functionNamespace) (eq .namespace "default") }}
|
||||
namespace: {{ .Values.functionNamespace }}
|
||||
{{- else }}
|
||||
namespace: {{ .namespace }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
@@ -25,12 +25,15 @@ controller/config.go
|
||||
{{- define "config" -}}
|
||||
canary:
|
||||
enabled: {{ .Values.canaryDeployment.enabled }}
|
||||
{{- if .Values.prometheus.enabled }}
|
||||
prometheusSvc: "http://{{ .Release.Name }}-prometheus-server.{{ .Release.Namespace }}"
|
||||
{{- else }}
|
||||
prometheusSvc: {{ .Values.prometheus.serviceEndpoint | default "" | quote }}
|
||||
{{- end }}
|
||||
{{- printf "\n" -}}
|
||||
auth:
|
||||
enabled: {{ .Values.authentication.enabled | default false }}
|
||||
{{- if .Values.authentication.enabled }}
|
||||
authUriPath: {{ .Values.authentication.authUriPath | default "/auth/login" | quote}}
|
||||
jwtExpiryTime: {{ .Values.authentication.jwtExpiryTime | default 120 }}
|
||||
jwtIssuer: {{ .Values.authentication.jwtIssuer | default "fission" | quote }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
@@ -38,8 +41,87 @@ This template generates the image name for the deployment depending on the value
|
||||
*/}}
|
||||
{{- define "fission-bundleImage" -}}
|
||||
{{- if .Values.repository -}}
|
||||
{{- if eq .Values.imageTag "" -}}
|
||||
{{ .Values.repository }}/{{ .Values.image }}
|
||||
{{- else -}}
|
||||
{{ .Values.repository }}/{{ .Values.image }}:{{ .Values.imageTag }}
|
||||
{{- end }}
|
||||
{{- else -}}
|
||||
{{ .Values.image }}:{{ .Values.imageTag }}
|
||||
{{- if eq .Values.imageTag "" -}}
|
||||
{{ .Values.image }}
|
||||
{{- else -}}
|
||||
{{ .Values.image }}:{{ .Values.imageTag }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "reporterImage" -}}
|
||||
{{- if .Values.repository -}}
|
||||
{{- if eq .Values.imageTag "" -}}
|
||||
{{ .Values.repository }}/{{ .Values.postInstallReportImage }}
|
||||
{{- else -}}
|
||||
{{ .Values.repository }}/{{ .Values.postInstallReportImage }}:{{ .Values.imageTag }}
|
||||
{{- end }}
|
||||
{{- else -}}
|
||||
{{- if eq .Values.imageTag "" -}}
|
||||
{{ .Values.postInstallReportImage }}
|
||||
{{- else -}}
|
||||
{{ .Values.postInstallReportImage }}:{{ .Values.imageTag }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "opentelemtry.envs" }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.openTelemetry.otlpCollectorEndpoint }}"
|
||||
- name: OTEL_EXPORTER_OTLP_INSECURE
|
||||
value: "{{ .Values.openTelemetry.otlpInsecure }}"
|
||||
{{- if .Values.openTelemetry.otlpHeaders }}
|
||||
- name: OTEL_EXPORTER_OTLP_HEADERS
|
||||
value: "{{ .Values.openTelemetry.otlpHeaders }}"
|
||||
{{- end }}
|
||||
- name: OTEL_TRACES_SAMPLER
|
||||
value: "{{ .Values.openTelemetry.tracesSampler }}"
|
||||
- name: OTEL_TRACES_SAMPLER_ARG
|
||||
value: "{{ .Values.openTelemetry.tracesSamplingRate }}"
|
||||
- name: OTEL_PROPAGATORS
|
||||
value: "{{ .Values.openTelemetry.propagators }}"
|
||||
{{- end }}
|
||||
|
||||
{{- define "fission-resource-namespace.envs" }}
|
||||
- name: FISSION_BUILDER_NAMESPACE
|
||||
value: "{{ .Values.builderNamespace }}"
|
||||
- name: FISSION_FUNCTION_NAMESPACE
|
||||
value: "{{ .Values.functionNamespace }}"
|
||||
- name: FISSION_DEFAULT_NAMESPACE
|
||||
value: "{{ .Values.defaultNamespace }}"
|
||||
- name: FISSION_RESOURCE_NAMESPACES
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
value: "{{ .Values.defaultNamespace }},{{ join "," .Values.additionalFissionNamespaces }}"
|
||||
{{- else }}
|
||||
value: {{ .Values.defaultNamespace }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Define the svc's name
|
||||
*/}}
|
||||
{{- define "fission-webhook.svc" -}}
|
||||
{{- printf "webhook-service" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "fission-function-ns" -}}
|
||||
{{- if .Values.functionNamespace -}}
|
||||
{{- printf "%s" .Values.functionNamespace -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s" .Values.defaultNamespace -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "fission-builder-ns" -}}
|
||||
{{- if .Values.builderNamespace -}}
|
||||
{{- printf "%s" .Values.builderNamespace -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s" .Values.defaultNamespace -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
+10
-2
@@ -26,7 +26,15 @@ spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: post-install-job
|
||||
image: "fission/alpinecurl"
|
||||
image: {{ include "reporterImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["sh", "-c", "/usr/bin/curl -m 5 -H \"Content-Type: application/json\" -X POST -d '{\"type\": \"yaml-post-install\", \"chartName\": \"{{ .Chart.Name }}\", \"chartVersion\": \"{{ .Chart.Version }}\"}' https://g.fission.sh/analytics || true"]
|
||||
command: [ "/reporter" ]
|
||||
args: ["event", "-c", "fission-use", "-a", "yaml-post-install", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
||||
env:
|
||||
- name: GA_TRACKING_ID
|
||||
value: "{{ .Values.gaTrackingID }}"
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
+16
-2
@@ -30,7 +30,21 @@ spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: post-install-job
|
||||
image: "fission/alpinecurl"
|
||||
image: {{ include "reporterImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["sh", "-c", "/usr/bin/curl -m 5 -H \"Content-Type: application/json\" -X POST -d '{\"type\": \"helm-post-install\", \"chartName\": \"{{ .Chart.Name }}\", \"chartVersion\": \"{{ .Chart.Version }}\"}' https://g.fission.sh/analytics || true"]
|
||||
command: [ "/reporter" ]
|
||||
args: ["event", "-c", "fission-use", "-a", "helm-post-install", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
||||
env:
|
||||
- name: GA_TRACKING_ID
|
||||
value: "{{ .Values.gaTrackingID }}"
|
||||
{{- if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
+16
-2
@@ -30,7 +30,21 @@ spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: post-upgrade-job
|
||||
image: "fission/alpinecurl"
|
||||
image: {{ include "reporterImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["sh", "-c", "/usr/bin/curl -m 5 -H \"Content-Type: application/json\" -X POST -d '{\"type\": \"helm-post-upgrade\", \"chartName\": \"{{ .Chart.Name }}\", \"chartVersion\": \"{{ .Chart.Version }}\"}' https://g.fission.sh/analytics || true"]
|
||||
command: [ "/reporter" ]
|
||||
args: ["event", "-c", "fission-use", "-a", "helm-post-upgrade", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
||||
env:
|
||||
- name: GA_TRACKING_ID
|
||||
value: "{{ .Values.gaTrackingID }}"
|
||||
{{- if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,9 @@
|
||||
{{- if .Values.builderPodSpec.enabled }}
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: builder-podspec-patch
|
||||
data:
|
||||
builder-podspec-patch.yaml: |
|
||||
{{- toYaml .Values.builderPodSpec.podSpec | nindent 4 }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,94 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: buildermgr
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: buildermgr
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: buildermgr
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: buildermgr
|
||||
annotations:
|
||||
prometheus.io/scrape: "true"
|
||||
prometheus.io/path: "/metrics"
|
||||
prometheus.io/port: "8080"
|
||||
spec:
|
||||
{{- if .Values.buildermgr.securityContext.enabled }}
|
||||
securityContext: {{- omit .Values.buildermgr.securityContext "enabled" | toYaml | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: buildermgr
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--builderMgr", "--storageSvcUrl", "http://storagesvc.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: FETCHER_IMAGE
|
||||
{{- if eq .Values.fetcher.imageTag "" }}
|
||||
value: "{{ .Values.fetcher.image }}"
|
||||
{{- else }}
|
||||
value: "{{ .Values.fetcher.image }}:{{ .Values.fetcher.imageTag }}"
|
||||
{{- end }}
|
||||
- name: FETCHER_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: BUILDER_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: ENABLE_ISTIO
|
||||
value: "{{ .Values.enableIstio }}"
|
||||
- name: FETCHER_MINCPU
|
||||
value: {{ .Values.fetcher.resource.cpu.requests | quote }}
|
||||
- name: FETCHER_MINMEM
|
||||
value: {{ .Values.fetcher.resource.mem.requests | quote }}
|
||||
- name: FETCHER_MAXCPU
|
||||
value: {{ .Values.fetcher.resource.cpu.limits | quote }}
|
||||
- name: FETCHER_MAXMEM
|
||||
value: {{ .Values.fetcher.resource.mem.limits | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
- name: PPROF_ENABLED
|
||||
value: {{ .Values.pprof.enabled | quote }}
|
||||
- name: HELM_RELEASE_NAME
|
||||
value: {{ .Release.Name | quote }}
|
||||
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||
{{- if .Values.builderPodSpec.enabled }}
|
||||
volumeMounts:
|
||||
- name: builder-podspec-patch-volume
|
||||
mountPath: /etc/fission/builder-podspec-patch.yaml
|
||||
subPath: builder-podspec-patch.yaml
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: metrics
|
||||
resources:
|
||||
{{- toYaml .Values.buildermgr.resources | nindent 10 }}
|
||||
{{- if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
serviceAccountName: fission-buildermgr
|
||||
{{- if .Values.builderPodSpec.enabled }}
|
||||
volumes:
|
||||
- name: builder-podspec-patch-volume
|
||||
configMap:
|
||||
name: builder-podspec-patch
|
||||
{{- end }}
|
||||
{{- if .Values.priorityClassName }}
|
||||
priorityClassName: {{ .Values.priorityClassName }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,23 @@
|
||||
{{- if .Values.podMonitor.enabled }}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PodMonitor
|
||||
metadata:
|
||||
name: buildermgr-monitor
|
||||
{{- if .Values.podMonitor.namespace }}
|
||||
namespace: {{ .Values.podMonitor.namespace }}
|
||||
{{- end }}
|
||||
{{- with .Values.podMonitor.additionalPodMonitorLabels }}
|
||||
labels:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
namespaceSelector:
|
||||
matchNames:
|
||||
- {{ .Release.Namespace }}
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: buildermgr
|
||||
podMetricsEndpoints:
|
||||
- port: "metrics"
|
||||
path: "/metrics"
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,13 @@
|
||||
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "buildermgr") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "buildermgr") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.builderNamespace -}}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "buildermgr") $) }}
|
||||
{{- end }}
|
||||
{{- if .Values.functionNamespace -}}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "buildermgr") $) }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,13 @@
|
||||
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "buildermgr") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "buildermgr") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.builderNamespace -}}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "buildermgr") $) }}
|
||||
{{- end }}
|
||||
{{- if .Values.functionNamespace -}}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "buildermgr") $) }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,5 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-buildermgr
|
||||
namespace: {{ .Release.Namespace }}
|
||||
@@ -0,0 +1,81 @@
|
||||
{{- if .Values.canaryDeployment.enabled }}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: canaryconfig
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: canaryconfig
|
||||
application: fission-canaryconfig
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: canaryconfig
|
||||
application: fission-canaryconfig
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: canaryconfig
|
||||
application: fission-canaryconfig
|
||||
annotations:
|
||||
prometheus.io/scrape: "true"
|
||||
prometheus.io/path: "/metrics"
|
||||
prometheus.io/port: "8080"
|
||||
spec:
|
||||
{{- if .Values.canaryDeployment.securityContext.enabled }}
|
||||
securityContext: {{- omit .Values.canaryDeployment.securityContext "enabled" | toYaml | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: canaryconfig
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--canaryConfig"]
|
||||
env:
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
- name: PPROF_ENABLED
|
||||
value: {{ .Values.pprof.enabled | quote }}
|
||||
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||
- name: POD_NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||
resources:
|
||||
{{- toYaml .Values.canaryDeployment.resources | nindent 10 }}
|
||||
{{- if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: config-volume
|
||||
mountPath: /etc/config/config.yaml
|
||||
subPath: config.yaml
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: metrics
|
||||
{{- if .Values.pprof.enabled }}
|
||||
- containerPort: 6060
|
||||
name: pprof
|
||||
{{- end }}
|
||||
|
||||
serviceAccountName: fission-canaryconfig
|
||||
volumes:
|
||||
- name: config-volume
|
||||
configMap:
|
||||
name: feature-config
|
||||
{{- if .Values.priorityClassName }}
|
||||
priorityClassName: {{ .Values.priorityClassName }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,9 @@
|
||||
{{- if .Values.canaryDeployment.enabled }}
|
||||
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "canaryconfig") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "canaryconfig") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,9 @@
|
||||
{{- if .Values.canaryDeployment.enabled }}
|
||||
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "canaryconfig") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "canaryconfig") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,7 @@
|
||||
{{- if .Values.canaryDeployment.enabled }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-canaryconfig
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,24 @@
|
||||
{{- if .Values.canaryDeployment.enabled }}
|
||||
{{- if .Values.serviceMonitor.enabled }}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: canaryconfig-monitor
|
||||
{{- if .Values.serviceMonitor.namespace }}
|
||||
namespace: {{ .Values.serviceMonitor.namespace }}
|
||||
{{- end }}
|
||||
{{- with .Values.serviceMonitor.additionalServiceMonitorLabels }}
|
||||
labels:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
namespaceSelector:
|
||||
matchNames:
|
||||
- {{ .Release.Namespace }}
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: canaryconfig
|
||||
endpoints:
|
||||
- targetPort: 8080
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,17 @@
|
||||
{{- if .Values.grafana.dashboards.enable }}
|
||||
{{- $files := .Files }}
|
||||
{{- range $path, $bytes := .Files.Glob "dashboards/*.json" }}
|
||||
{{- $filename := trimSuffix (ext $path) (base $path) }}
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ printf "%s-%s" $.Chart.Name $filename | trunc 63 | trimSuffix "-" }}
|
||||
namespace: {{ $.Values.grafana.namespace }}
|
||||
labels:
|
||||
grafana_dashboard: "1"
|
||||
created_by: "{{ $.Chart.Name }}"
|
||||
data:
|
||||
{{ base $path }}: '{{ $files.Get $path }}'
|
||||
---
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -1,807 +0,0 @@
|
||||
{{- if .Values.createNamespace }}
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: {{ .Values.functionNamespace }}
|
||||
labels:
|
||||
name: fission-function
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
{{- if .Values.enableIstio }}
|
||||
istio-injection: enabled
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: {{ .Values.builderNamespace }}
|
||||
labels:
|
||||
name: fission-builder
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
{{- if .Values.enableIstio }}
|
||||
istio-injection: enabled
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: secret-configmap-getter
|
||||
rules:
|
||||
- apiGroups:
|
||||
- '*'
|
||||
resources:
|
||||
- secrets
|
||||
- configmaps
|
||||
verbs:
|
||||
- get
|
||||
- watch
|
||||
- list
|
||||
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: package-getter
|
||||
rules:
|
||||
- apiGroups:
|
||||
- '*'
|
||||
resources:
|
||||
- packages
|
||||
verbs:
|
||||
- get
|
||||
- watch
|
||||
- list
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-svc
|
||||
namespace: {{ .Release.Namespace }}
|
||||
|
||||
---
|
||||
kind: RoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: fission-admin
|
||||
namespace: {{ .Release.Namespace }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: fission-svc
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: ClusterRole
|
||||
name: admin
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
|
||||
---
|
||||
kind: ClusterRoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: fission-crd
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: fission-svc
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: ClusterRole
|
||||
name: cluster-admin
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-fetcher
|
||||
namespace: {{ .Values.functionNamespace }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-builder
|
||||
namespace: {{ .Values.builderNamespace }}
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: feature-config
|
||||
namespace: {{ .Release.Namespace }}
|
||||
data:
|
||||
"config.yaml": {{ include "config" . | b64enc }}
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: controller
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: controller
|
||||
application: fission-api
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: controller
|
||||
application: fission-api
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: controller
|
||||
application: fission-api
|
||||
spec:
|
||||
containers:
|
||||
- name: controller
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--controllerPort", "8888"]
|
||||
env:
|
||||
- name: FISSION_FUNCTION_NAMESPACE
|
||||
value: "{{ .Values.functionNamespace }}"
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
- name: POD_NAMESPACE
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.namespace
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8888
|
||||
initialDelaySeconds: 1
|
||||
periodSeconds: 1
|
||||
failureThreshold: 30
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8888
|
||||
initialDelaySeconds: 35
|
||||
periodSeconds: 5
|
||||
volumeMounts:
|
||||
- name: config-volume
|
||||
mountPath: /etc/config/config.yaml
|
||||
subPath: config.yaml
|
||||
ports:
|
||||
- containerPort: 8888
|
||||
name: http
|
||||
serviceAccountName: fission-svc
|
||||
volumes:
|
||||
- name: config-volume
|
||||
configMap:
|
||||
name: feature-config
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: executor
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: executor
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: executor
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: executor
|
||||
annotations:
|
||||
prometheus.io/scrape: "true"
|
||||
prometheus.io/path: "/metrics"
|
||||
prometheus.io/port: "8080"
|
||||
spec:
|
||||
containers:
|
||||
- name: executor
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--executorPort", "8888", "--namespace", "{{ .Values.functionNamespace }}"]
|
||||
env:
|
||||
- name: FETCHER_IMAGE
|
||||
value: "{{ .Values.fetcherImage }}:{{ .Values.fetcherImageTag }}"
|
||||
- name: FETCHER_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: RUNTIME_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: ENABLE_ISTIO
|
||||
value: "{{ .Values.enableIstio }}"
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: FETCHER_MINCPU
|
||||
value: {{ .Values.fetcherMinCpu | default "10m" | quote }}
|
||||
- name: FETCHER_MINMEM
|
||||
value: {{ .Values.fetcherMinMem | default "16Mi" | quote }}
|
||||
- name: FETCHER_MAXCPU
|
||||
value: {{ .Values.fetcherMaxCpu | default "1000m" | quote }}
|
||||
- name: FETCHER_MAXMEM
|
||||
value: {{ .Values.fetcherMaxMem | default "128Mi" | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8888
|
||||
initialDelaySeconds: 1
|
||||
periodSeconds: 1
|
||||
failureThreshold: 30
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8888
|
||||
initialDelaySeconds: 35
|
||||
periodSeconds: 5
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: metrics
|
||||
- containerPort: 8888
|
||||
name: http
|
||||
serviceAccountName: fission-svc
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: buildermgr
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: buildermgr
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: buildermgr
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: buildermgr
|
||||
spec:
|
||||
containers:
|
||||
- name: buildermgr
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--builderMgr", "--storageSvcUrl", "http://storagesvc.{{ .Release.Namespace }}", "--envbuilder-namespace", "{{ .Values.builderNamespace }}"]
|
||||
env:
|
||||
- name: FETCHER_IMAGE
|
||||
value: "{{ .Values.fetcherImage }}:{{ .Values.fetcherImageTag }}"
|
||||
- name: FETCHER_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: BUILDER_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: ENABLE_ISTIO
|
||||
value: "{{ .Values.enableIstio }}"
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: FETCHER_MINCPU
|
||||
value: {{ .Values.fetcherMinCpu | default "10m" | quote }}
|
||||
- name: FETCHER_MINMEM
|
||||
value: {{ .Values.fetcherMinMem | default "16Mi" | quote }}
|
||||
- name: FETCHER_MAXCPU
|
||||
value: {{ .Values.fetcherMaxCpu | default "1000m" | quote }}
|
||||
- name: FETCHER_MAXMEM
|
||||
value: {{ .Values.fetcherMaxMem | default "128Mi" | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
serviceAccountName: fission-svc
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: kubewatcher
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: kubewatcher
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: kubewatcher
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: kubewatcher
|
||||
spec:
|
||||
containers:
|
||||
- name: kubewatcher
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--kubewatcher", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
serviceAccountName: fission-svc
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: influxdb
|
||||
labels:
|
||||
svc: influxdb
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- port: 8086
|
||||
targetPort: 8086
|
||||
selector:
|
||||
svc: influxdb
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: influxdb
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: influxdb
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: influxdb
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: influxdb
|
||||
spec:
|
||||
containers:
|
||||
- name: influxdb
|
||||
image: fission/influxdb
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
env:
|
||||
- name: PRE_CREATE_DB
|
||||
value: fissionFunctionLog
|
||||
- name: ADMIN_USER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: influxdb
|
||||
key: username
|
||||
- name: INFLUXDB_INIT_PWD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: influxdb
|
||||
key: password
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.heapster }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: heapster
|
||||
namespace: kube-system
|
||||
labels:
|
||||
svc: heapster
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
kubernetes.io/cluster-service: 'true'
|
||||
kubernetes.io/name: heapster
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 8082
|
||||
selector:
|
||||
svc: heapster
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: heapster
|
||||
namespace: kube-system
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: heapster
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: heapster
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: heapster
|
||||
spec:
|
||||
containers:
|
||||
- name: heapster
|
||||
image: gcr.io/google_containers/heapster-amd64:v1.5.0
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command:
|
||||
- /heapster
|
||||
- --source=kubernetes:https://kubernetes.default
|
||||
serviceAccountName: {{ .Release.Namespace }}/fission-svc
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: timer
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: timer
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: timer
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: timer
|
||||
spec:
|
||||
containers:
|
||||
- name: timer
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--timer", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
serviceAccountName: fission-svc
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
|
||||
#
|
||||
# This is commented out until fission-ui allows configuring the
|
||||
# namespace. Right now it just crashes if Release.Namespace !=
|
||||
# "fission".
|
||||
#
|
||||
#---
|
||||
#apiVersion: apps/v1
|
||||
#kind: Deployment
|
||||
#metadata:
|
||||
# name: fission-ui
|
||||
# labels:
|
||||
# chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
#spec:
|
||||
# replicas: 1
|
||||
# template:
|
||||
# metadata:
|
||||
# labels:
|
||||
# svc: fission-ui
|
||||
# spec:
|
||||
# containers:
|
||||
# - name: nginx
|
||||
# image: {{ .Values.repository }}/{{ .Values.fissionUiImage }}
|
||||
# imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
# - name: kubectl-proxy
|
||||
# image: {{ .Values.repository }}/lachlanevenson/k8s-kubectl
|
||||
# args: ["proxy", "--port", "8001", "--address", "127.0.0.1"]
|
||||
# serviceAccountName: fission-svc
|
||||
|
||||
{{- if .Values.nats.enabled }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
labels:
|
||||
svc: nats-streaming
|
||||
name: nats-streaming
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: nats-streaming
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: nats-streaming
|
||||
spec:
|
||||
containers:
|
||||
- name: nats-streaming
|
||||
image: nats-streaming
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
args: [
|
||||
"--cluster_id", "{{ .Values.nats.clusterID }}",
|
||||
"--auth", "{{ .Values.nats.authToken }}",
|
||||
"--max_channels", "0",
|
||||
"--http_port", "4223"
|
||||
]
|
||||
ports:
|
||||
- containerPort: 4222
|
||||
hostPort: 4222
|
||||
protocol: TCP
|
||||
- containerPort: 4223
|
||||
hostPort: 4223
|
||||
protocol: TCP
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: "/streaming/serverz"
|
||||
port: 4223
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 1
|
||||
failureThreshold: 30
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: "/streaming/serverz"
|
||||
port: 4223
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 5
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: mqtrigger-nats-streaming
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: mqtrigger
|
||||
messagequeue: nats-streaming
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: mqtrigger
|
||||
messagequeue: nats-streaming
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: mqtrigger
|
||||
messagequeue: nats-streaming
|
||||
spec:
|
||||
containers:
|
||||
- name: mqtrigger
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--mqt", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: MESSAGE_QUEUE_TYPE
|
||||
value: nats-streaming
|
||||
- name: MESSAGE_QUEUE_URL
|
||||
value: nats://{{ .Values.nats.authToken }}@nats-streaming:4222
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
serviceAccountName: fission-svc
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.kafka.enabled }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: mqtrigger-kafka
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: mqtrigger
|
||||
messagequeue: kafka
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: mqtrigger
|
||||
messagequeue: kafka
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: mqtrigger
|
||||
messagequeue: kafka
|
||||
spec:
|
||||
containers:
|
||||
- name: mqtrigger
|
||||
image: "{{ .Values.image }}:{{ .Values.imageTag }}"
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--mqt", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: MESSAGE_QUEUE_TYPE
|
||||
value: kafka
|
||||
- name: MESSAGE_QUEUE_URL
|
||||
value: "{{.Values.kafka.brokers}}"
|
||||
- name: MESSAGE_QUEUE_KAFKA_VERSION
|
||||
value: "{{.Values.kafka.version}}"
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
# TLS authentication is TLS with authentication (2 way)
|
||||
# More info: https://docs.confluent.io/current/kafka/authentication_ssl.html#ssl-overview
|
||||
{{- if .Values.kafka.authentication.tls.enabled }}
|
||||
- name: TLS_ENABLED
|
||||
value: "true"
|
||||
- name: MESSAGE_QUEUE_SECRETS
|
||||
value: /etc/fission/secrets
|
||||
volumeMounts:
|
||||
- name: kafka-secrets
|
||||
mountPath: /etc/fission/secrets
|
||||
{{- end }}
|
||||
serviceAccountName: fission-svc
|
||||
{{- if .Values.kafka.authentication.tls.enabled }}
|
||||
volumes:
|
||||
- name: kafka-secrets
|
||||
secret:
|
||||
secretName: mqtrigger-kafka-secrets
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
{{- if .Values.kafka.authentication.tls.enabled }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: mqtrigger-kafka-secrets
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
data:
|
||||
{{- if .Files.Get (printf "%s" .Values.kafka.authentication.tls.caCert) }}
|
||||
caCert: {{ .Files.Get (printf "%s" .Values.kafka.authentication.tls.caCert) | b64enc }}
|
||||
{{- else }}
|
||||
{{ fail "Invalid chart. CA Certificate not found." }}
|
||||
{{- end }}
|
||||
{{- if .Files.Get (printf "%s" .Values.kafka.authentication.tls.userCert) }}
|
||||
userCert: {{ .Files.Get (printf "%s" .Values.kafka.authentication.tls.userCert) | b64enc }}
|
||||
{{- else }}
|
||||
{{ fail "Invalid chart. User Certificate not found." }}
|
||||
{{- end }}
|
||||
{{- if .Files.Get (printf "%s" .Values.kafka.authentication.tls.userKey) }}
|
||||
userKey: {{ .Files.Get (printf "%s" .Values.kafka.authentication.tls.userKey) | b64enc }}
|
||||
{{- else }}
|
||||
{{ fail "Invalid chart. User Key not found." }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.azureStorageQueue.enabled }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: mqtrigger-azure-storage-queue
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: mqtrigger
|
||||
messagequeue: azure-storage-queue
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: mqtrigger
|
||||
messagequeue: azure-storage-queue
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: mqtrigger
|
||||
messagequeue: azure-storage-queue
|
||||
spec:
|
||||
containers:
|
||||
- name: mqtrigger
|
||||
image: "{{ .Values.image }}:{{ .Values.imageTag }}"
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--mqt", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: MESSAGE_QUEUE_TYPE
|
||||
value: azure-storage-queue
|
||||
- name: AZURE_STORAGE_ACCOUNT_NAME
|
||||
value: {{ required "An Azure storage account name is required." .Values.azureStorageQueue.accountName }}
|
||||
- name: AZURE_STORAGE_ACCOUNT_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: azure-storage-account-key
|
||||
key: key
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
serviceAccountName: fission-svc
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: storagesvc
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: storagesvc
|
||||
application: fission-storage
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: storagesvc
|
||||
application: fission-storage
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: storagesvc
|
||||
application: fission-storage
|
||||
spec:
|
||||
containers:
|
||||
- name: storagesvc
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--storageServicePort", "8000", "--filePath", "/fission"]
|
||||
env:
|
||||
- name: TRACE_JAEGER_COLLECTOR_ENDPOINT
|
||||
value: "{{ .Values.traceCollectorEndpoint }}"
|
||||
- name: TRACING_SAMPLING_RATE
|
||||
value: {{ .Values.traceSamplingRate | default "0.5" | quote }}
|
||||
- name: PRUNE_INTERVAL
|
||||
value: "{{.Values.pruneInterval}}"
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
volumeMounts:
|
||||
- name: fission-storage
|
||||
mountPath: /fission
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8000
|
||||
initialDelaySeconds: 1
|
||||
periodSeconds: 1
|
||||
failureThreshold: 30
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8000
|
||||
initialDelaySeconds: 35
|
||||
periodSeconds: 5
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
name: http
|
||||
serviceAccountName: fission-svc
|
||||
volumes:
|
||||
- name: fission-storage
|
||||
{{- if .Values.persistence.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ .Values.persistence.existingClaim | default "fission-storage-pvc" }}
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,9 @@
|
||||
{{- if .Values.runtimePodSpec.enabled }}
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: runtime-podspec-patch
|
||||
data:
|
||||
runtime-podspec-patch.yaml: |
|
||||
{{- toYaml .Values.runtimePodSpec.podSpec | nindent 4 }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,143 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: executor
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: executor
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: executor
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: executor
|
||||
annotations:
|
||||
prometheus.io/scrape: "true"
|
||||
prometheus.io/path: "/metrics"
|
||||
prometheus.io/port: "8080"
|
||||
spec:
|
||||
{{- if .Values.executor.securityContext.enabled }}
|
||||
securityContext: {{- omit .Values.executor.securityContext "enabled" | toYaml | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: executor
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--executorPort", "8888"]
|
||||
env:
|
||||
- name: FETCHER_IMAGE
|
||||
{{- if eq .Values.fetcher.imageTag "" }}
|
||||
value: "{{ .Values.fetcher.image }}"
|
||||
{{- else }}
|
||||
value: "{{ .Values.fetcher.image }}:{{ .Values.fetcher.imageTag }}"
|
||||
{{- end }}
|
||||
- name: FETCHER_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: RUNTIME_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: ADOPT_EXISTING_RESOURCES
|
||||
value: {{ .Values.executor.adoptExistingResources | default false | quote }}
|
||||
- name: POD_READY_TIMEOUT
|
||||
value: {{ .Values.executor.podReadyTimeout | default false | quote }}
|
||||
- name: ENABLE_ISTIO
|
||||
value: "{{ .Values.enableIstio }}"
|
||||
- name: FETCHER_MINCPU
|
||||
value: {{ .Values.fetcher.resource.cpu.requests | quote }}
|
||||
- name: FETCHER_MINMEM
|
||||
value: {{ .Values.fetcher.resource.mem.requests | quote }}
|
||||
- name: FETCHER_MAXCPU
|
||||
value: {{ .Values.fetcher.resource.cpu.limits | quote }}
|
||||
- name: FETCHER_MAXMEM
|
||||
value: {{ .Values.fetcher.resource.mem.limits | quote }}
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
- name: PPROF_ENABLED
|
||||
value: {{ .Values.pprof.enabled | quote }}
|
||||
- name: OBJECT_REAPER_INTERVAL
|
||||
value: {{ .Values.executor.objectReaperInterval | quote }}
|
||||
{{- if .Values.executor.poolmgr.objectReaperInterval }}
|
||||
- name: POOLMGR_OBJECT_REAPER_INTERVAL
|
||||
value: {{ .Values.executor.poolmgr.objectReaperInterval | quote }}
|
||||
{{- end}}
|
||||
{{- if .Values.executor.newdeploy.objectReaperInterval }}
|
||||
- name: NEWDEPLOY_OBJECT_REAPER_INTERVAL
|
||||
value: {{ .Values.executor.newdeploy.objectReaperInterval | quote }}
|
||||
{{- end}}
|
||||
{{- if .Values.executor.container.objectReaperInterval }}
|
||||
- name: CONTAINER_OBJECT_REAPER_INTERVAL
|
||||
value: {{ .Values.executor.container.objectReaperInterval | quote }}
|
||||
{{- end}}
|
||||
{{- if .Values.executor.serviceAccountCheck.enabled }}
|
||||
- name: SERVICEACCOUNT_CHECK_ENABLED
|
||||
value: {{ .Values.executor.serviceAccountCheck.enabled | quote }}
|
||||
- name: SERVICEACCOUNT_CHECK_INTERVAL
|
||||
value: {{ .Values.executor.serviceAccountCheck.interval | quote }}
|
||||
{{- end}}
|
||||
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||
- name: HELM_RELEASE_NAME
|
||||
value: {{ .Release.Name | quote }}
|
||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||
resources:
|
||||
{{- toYaml .Values.executor.resources | nindent 10 }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8888
|
||||
initialDelaySeconds: 1
|
||||
periodSeconds: 1
|
||||
failureThreshold: 30
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: "/healthz"
|
||||
port: 8888
|
||||
initialDelaySeconds: 35
|
||||
periodSeconds: 5
|
||||
{{- if .Values.runtimePodSpec.enabled }}
|
||||
volumeMounts:
|
||||
- name: runtime-podspec-patch-volume
|
||||
mountPath: /etc/fission/runtime-podspec-patch.yaml
|
||||
subPath: runtime-podspec-patch.yaml
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: metrics
|
||||
- containerPort: 8888
|
||||
name: http
|
||||
{{- if .Values.pprof.enabled }}
|
||||
- containerPort: 6060
|
||||
name: pprof
|
||||
{{- end }}
|
||||
{{- if .Values.executor.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.executor.terminationMessagePath }}
|
||||
{{- else if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.executor.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.executor.terminationMessagePolicy }}
|
||||
{{- else if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
serviceAccountName: fission-executor
|
||||
{{- if .Values.runtimePodSpec.enabled }}
|
||||
volumes:
|
||||
- name: runtime-podspec-patch-volume
|
||||
configMap:
|
||||
name: runtime-podspec-patch
|
||||
{{- end }}
|
||||
{{- if .Values.executor.priorityClassName }}
|
||||
priorityClassName: {{ .Values.executor.priorityClassName }}
|
||||
{{- else if .Values.priorityClassName }}
|
||||
priorityClassName: {{ .Values.priorityClassName }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,13 @@
|
||||
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "executor") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "executor") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.builderNamespace -}}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "executor") $) }}
|
||||
{{- end }}
|
||||
{{- if .Values.functionNamespace -}}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "executor") $) }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,13 @@
|
||||
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "executor") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "executor") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.builderNamespace -}}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "executor") $) }}
|
||||
{{- end }}
|
||||
{{- if .Values.functionNamespace -}}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "executor") $) }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,5 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-executor
|
||||
namespace: {{ .Release.Namespace }}
|
||||
@@ -0,0 +1,22 @@
|
||||
{{- if .Values.serviceMonitor.enabled }}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: executor-monitor
|
||||
{{- if .Values.serviceMonitor.namespace }}
|
||||
namespace: {{ .Values.serviceMonitor.namespace }}
|
||||
{{- end }}
|
||||
{{- with .Values.serviceMonitor.additionalServiceMonitorLabels }}
|
||||
labels:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
namespaceSelector:
|
||||
matchNames:
|
||||
- {{ .Release.Namespace }}
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: executor
|
||||
endpoints:
|
||||
- targetPort: 8080
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: executor
|
||||
labels:
|
||||
svc: executor
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 8888
|
||||
selector:
|
||||
svc: executor
|
||||
+79
-7
@@ -1,3 +1,4 @@
|
||||
{{- if .Values.influxdb.enabled }}
|
||||
# Fluentbit deployment for Fission
|
||||
#
|
||||
# Requires:
|
||||
@@ -19,6 +20,64 @@ data:
|
||||
{{ else }}
|
||||
{{ fail "invalid chart" }}
|
||||
{{- end }}
|
||||
{{- if .Values.logger.podSecurityPolicy.enabled }}
|
||||
---
|
||||
apiVersion: policy/v1beta1
|
||||
kind: PodSecurityPolicy
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-fission-logger-privileged
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: logger
|
||||
spec:
|
||||
privileged: true
|
||||
seLinux:
|
||||
rule: RunAsAny
|
||||
supplementalGroups:
|
||||
rule: RunAsAny
|
||||
runAsUser:
|
||||
rule: RunAsAny
|
||||
fsGroup:
|
||||
rule: RunAsAny
|
||||
volumes:
|
||||
- '*'
|
||||
{{- if .Values.logger.podSecurityPolicy.additionalCapabilities }}
|
||||
allowedCapabilities:
|
||||
{{- range .Values.logger.podSecurityPolicy.additionalCapabilities }}
|
||||
- {{ . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: psp:{{ .Release.Name }}-fission-logger-privileged
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: logger
|
||||
rules:
|
||||
- apiGroups: ['policy']
|
||||
resources: ['podsecuritypolicies']
|
||||
verbs: ['use']
|
||||
resourceNames:
|
||||
- {{ .Release.Name }}-fission-logger-privileged
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: psp:{{ .Release.Name }}-fission-logger-privileged
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: logger
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: psp:{{ .Release.Name }}-fission-logger-privileged
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
namespace: {{ .Release.Namespace }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: DaemonSet
|
||||
@@ -38,20 +97,20 @@ spec:
|
||||
spec:
|
||||
initContainers:
|
||||
- name: init
|
||||
image: busybox
|
||||
image: {{ .Values.busyboxImage | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ['mkdir', '-p', '/var/log/fission']
|
||||
volumeMounts:
|
||||
- name: container-log
|
||||
mountPath: /var/log/
|
||||
readOnly: false
|
||||
{{- if .Values.logger.enableSecurityContext }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: logger
|
||||
{{ if .Values.repository }}
|
||||
image: "{{ .Values.repository }}/{{ .Values.image }}:{{ .Values.imageTag }}"
|
||||
{{ else }}
|
||||
image: "{{ .Values.image }}:{{ .Values.imageTag }}"
|
||||
{{ end }}
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
env:
|
||||
- name: NODE_NAME
|
||||
@@ -68,6 +127,10 @@ spec:
|
||||
- name: docker-log
|
||||
mountPath: /var/lib/docker/containers
|
||||
readOnly: true
|
||||
{{- if .Values.logger.enableSecurityContext }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
- name: fluentbit
|
||||
{{- if .Values.repository }}
|
||||
image: "{{ .Values.logger.fluentdImageRepository }}/{{ .Values.logger.fluentdImage }}:{{ .Values.logger.fluentdImageTag }}"
|
||||
@@ -96,6 +159,10 @@ spec:
|
||||
key: password
|
||||
- name: LOG_PATH
|
||||
value: /var/log/fission/*.log
|
||||
{{- if .Values.logger.enableSecurityContext }}
|
||||
securityContext:
|
||||
privileged: true
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: container-log
|
||||
mountPath: /var/log/
|
||||
@@ -106,7 +173,7 @@ spec:
|
||||
- name: fluentbit-config
|
||||
mountPath: /fluent-bit/etc/
|
||||
readOnly: true
|
||||
serviceAccountName: fission-svc
|
||||
serviceAccountName: fission-fluentbit
|
||||
volumes:
|
||||
- name: container-log
|
||||
hostPath:
|
||||
@@ -118,5 +185,10 @@ spec:
|
||||
- name: fluentbit-config
|
||||
configMap:
|
||||
name: {{ .Release.Name }}-fission-fluentbit
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
updateStrategy:
|
||||
type: RollingUpdate
|
||||
{{- end }}
|
||||
@@ -0,0 +1,7 @@
|
||||
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "fluentbit") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "fluentbit") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,5 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-fluentbit
|
||||
namespace: {{ .Release.Namespace }}
|
||||
@@ -0,0 +1,59 @@
|
||||
{{- if .Values.influxdb.enabled }}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: influxdb
|
||||
labels:
|
||||
svc: influxdb
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- port: 8086
|
||||
targetPort: 8086
|
||||
selector:
|
||||
svc: influxdb
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: influxdb
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: influxdb
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: influxdb
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: influxdb
|
||||
spec:
|
||||
containers:
|
||||
- name: influxdb
|
||||
image: {{ .Values.influxdb.image | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
env:
|
||||
- name: INFLUXDB_DB
|
||||
value: fissionFunctionLog
|
||||
- name: INFLUXDB_ADMIN_USER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: influxdb
|
||||
key: username
|
||||
- name: INFLUXDB_ADMIN_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: influxdb
|
||||
key: password
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,12 @@
|
||||
{{- if .Values.influxdb.enabled }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: influxdb
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
type: Opaque
|
||||
data:
|
||||
username: {{ .Values.logger.influxdbAdmin | b64enc | quote }}
|
||||
password: {{ randAlphaNum 20 | b64enc | quote }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,52 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: kubewatcher
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: kubewatcher
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: kubewatcher
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: kubewatcher
|
||||
spec:
|
||||
{{- if .Values.kubewatcher.securityContext.enabled }}
|
||||
securityContext: {{- omit .Values.kubewatcher.securityContext "enabled" | toYaml | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: kubewatcher
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--kubewatcher", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
- name: PPROF_ENABLED
|
||||
value: {{ .Values.pprof.enabled | quote }}
|
||||
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||
resources:
|
||||
{{- toYaml .Values.kubewatcher.resources | nindent 10 }}
|
||||
{{- if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
serviceAccountName: fission-kubewatcher
|
||||
{{- if .Values.priorityClassName }}
|
||||
priorityClassName: {{ .Values.priorityClassName }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,7 @@
|
||||
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "kubewatcher") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "kubewatcher") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,7 @@
|
||||
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "kubewatcher") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "kubewatcher") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,5 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-kubewatcher
|
||||
namespace: {{ .Release.Namespace }}
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: feature-config
|
||||
namespace: {{ .Release.Namespace }}
|
||||
data:
|
||||
"config.yaml": {{ include "config" . | b64enc }}
|
||||
@@ -0,0 +1,29 @@
|
||||
{{- if .Values.createNamespace }}
|
||||
{{- if and (ne .Values.functionNamespace "default") (ne .Values.functionNamespace "") }}
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: {{ template "fission-function-ns" . }}
|
||||
labels:
|
||||
name: fission-function
|
||||
chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
{{- if .Values.enableIstio }}
|
||||
istio-injection: enabled
|
||||
{{- end }}
|
||||
{{- end}}
|
||||
|
||||
---
|
||||
|
||||
{{- if and (ne .Values.builderNamespace "default") (ne .Values.builderNamespace "") }}
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: {{ template "fission-builder-ns" . }}
|
||||
labels:
|
||||
name: fission-builder
|
||||
chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
{{- if .Values.enableIstio }}
|
||||
istio-injection: enabled
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,12 @@
|
||||
{{/*
|
||||
Passing namespace as an argument to the "fissionFunction.roles" template.
|
||||
Need to use merge function to pass in the current scope so that ".Release" values
|
||||
can be used
|
||||
*/}}
|
||||
{{ include "fissionFunction.roles" (merge (dict "namespace" .Values.defaultNamespace) .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fissionFunction.roles" (merge (dict "namespace" $namespace) $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,12 @@
|
||||
{{/*
|
||||
Passing namespace as an argument to the "fissionFunction.rolebindings" template.
|
||||
Need to use merge function to pass in the current scope so that ".Release" values
|
||||
can be used
|
||||
*/}}
|
||||
{{ include "fissionFunction.rolebindings" (merge (dict "namespace" .Values.defaultNamespace) .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fissionFunction.rolebindings" (merge (dict "namespace" $namespace) $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-fetcher
|
||||
namespace: {{ template "fission-function-ns" . }}
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-builder
|
||||
namespace: {{ template "fission-builder-ns" . }}
|
||||
@@ -0,0 +1,70 @@
|
||||
{{- if .Values.mqt_keda.enabled }}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: mqtrigger-keda
|
||||
labels:
|
||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||
svc: mqtrigger-keda
|
||||
messagequeue: keda
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
svc: mqtrigger-keda
|
||||
messagequeue: keda
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
svc: mqtrigger-keda
|
||||
messagequeue: keda
|
||||
spec:
|
||||
containers:
|
||||
- name: mqtrigger-keda
|
||||
image: {{ include "fission-bundleImage" . | quote }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: ["/fission-bundle"]
|
||||
args: ["--mqt_keda", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||
env:
|
||||
- name: DEBUG_ENV
|
||||
value: {{ .Values.debugEnv | quote }}
|
||||
- name: CONNECTOR_IMAGE_PULL_POLICY
|
||||
value: "{{ .Values.pullPolicy }}"
|
||||
- name: KAFKA_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.kafka.image }}:{{ .Values.mqt_keda.connector_images.kafka.tag }}"
|
||||
- name: RABBITMQ_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.rabbitmq.image }}:{{ .Values.mqt_keda.connector_images.rabbitmq.tag }}"
|
||||
- name: AWS-KINESIS-STREAM_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.awskinesis.image }}:{{ .Values.mqt_keda.connector_images.awskinesis.tag }}"
|
||||
- name: AWS-SQS-QUEUE_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.aws_sqs.image }}:{{ .Values.mqt_keda.connector_images.aws_sqs.tag }}"
|
||||
- name: STAN_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.nats_steaming.image }}:{{ .Values.mqt_keda.connector_images.nats_steaming.tag }}"
|
||||
- name: NATS-JETSTREAM_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.nats_jetstream.image }}:{{ .Values.mqt_keda.connector_images.nats_jetstream.tag }}"
|
||||
- name: GCP-PUBSUB_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.gcp_pubsub.image }}:{{ .Values.mqt_keda.connector_images.gcp_pubsub.tag }}"
|
||||
- name: REDIS_IMAGE
|
||||
value: "{{ .Values.mqt_keda.connector_images.redis.image }}:{{ .Values.mqt_keda.connector_images.redis.tag }}"
|
||||
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||
resources:
|
||||
{{- toYaml .Values.mqt_keda.resources | nindent 10 }}
|
||||
{{- if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
serviceAccountName: fission-keda
|
||||
{{- if .Values.priorityClassName }}
|
||||
priorityClassName: {{ .Values.priorityClassName }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraCoreComponentPodConfig }}
|
||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,7 @@
|
||||
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "keda") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "keda") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,7 @@
|
||||
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "keda") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "keda") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,5 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-keda
|
||||
namespace: {{ .Release.Namespace }}
|
||||
@@ -0,0 +1,17 @@
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-preupgrade
|
||||
annotations:
|
||||
helm.sh/hook: pre-upgrade
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
helm.sh/hook-weight: "-2"
|
||||
rules:
|
||||
- apiGroups:
|
||||
- apiextensions.k8s.io
|
||||
resources:
|
||||
- customresourcedefinitions
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
@@ -0,0 +1,15 @@
|
||||
kind: ClusterRoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: {{ .Release.Name }}-preupgrade
|
||||
annotations:
|
||||
helm.sh/hook: pre-upgrade
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: fission-preupgrade
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: ClusterRole
|
||||
name: {{ .Release.Name }}-preupgrade
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
+21
-3
@@ -1,3 +1,4 @@
|
||||
{{- if .Values.preUpgradeChecks.enabled }}
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
@@ -14,6 +15,7 @@ metadata:
|
||||
# job is considered part of the release.
|
||||
"helm.sh/hook": pre-upgrade
|
||||
"helm.sh/hook-delete-policy": hook-succeeded
|
||||
"helm.sh/hook-weight": "1"
|
||||
spec:
|
||||
backoffLimit: 0
|
||||
template:
|
||||
@@ -26,8 +28,24 @@ spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: pre-upgrade-job
|
||||
image: {{ .Values.preUpgradeChecksImage }}:{{ .Values.imageTag }}
|
||||
{{- if .Values.preUpgradeChecks.imageTag }}
|
||||
image: {{ .Values.preUpgradeChecks.image }}:{{ .Values.preUpgradeChecks.imageTag }}
|
||||
{{- else }}
|
||||
image: {{ .Values.preUpgradeChecks.image }}
|
||||
{{- end }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: [ "/pre-upgrade-checks" ]
|
||||
args: ["--fn-pod-namespace", "{{ .Values.functionNamespace }}", "--envbuilder-namespace", "{{ .Values.builderNamespace }}"]
|
||||
serviceAccountName: fission-svc
|
||||
env:
|
||||
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||
{{- if .Values.terminationMessagePath }}
|
||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||
{{- end }}
|
||||
{{- if .Values.terminationMessagePolicy }}
|
||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||
{{- end }}
|
||||
serviceAccountName: fission-preupgrade
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,7 @@
|
||||
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "preupgrade") .) }}
|
||||
|
||||
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "preupgrade") $) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,9 @@
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: fission-preupgrade
|
||||
namespace: {{ .Release.Namespace }}
|
||||
annotations:
|
||||
helm.sh/hook: pre-upgrade
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
helm.sh/hook-weight: "-1"
|
||||
@@ -1,33 +0,0 @@
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: {{ template "fullname" . }}-{{ .Chart.Version }}-{{ randNumeric 3 }}
|
||||
labels:
|
||||
# The "release" convention makes it easy to tie a release to all of the
|
||||
# Kubernetes resources that were created as part of that release.
|
||||
release: "{{ .Release.Name }}"
|
||||
# This makes it easy to audit chart usage.
|
||||
chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app: {{ template "name" . }}
|
||||
annotations:
|
||||
# This is what defines this resource as a hook. Without this line, the
|
||||
# job is considered part of the release.
|
||||
"helm.sh/hook": pre-upgrade
|
||||
"helm.sh/hook-delete-policy": hook-succeeded
|
||||
spec:
|
||||
backoffLimit: 0
|
||||
template:
|
||||
metadata:
|
||||
name: {{ template "fullname" . }}
|
||||
labels:
|
||||
release: "{{ .Release.Name }}"
|
||||
app: {{ template "name" . }}
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: pre-upgrade-job
|
||||
image: {{ .Values.preUpgradeChecksImage }}:{{ .Values.imageTag }}
|
||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||
command: [ "/pre-upgrade-checks" ]
|
||||
args: ["--fn-pod-namespace", "{{ .Values.functionNamespace }}", "--envbuilder-namespace", "{{ .Values.builderNamespace }}"]
|
||||
serviceAccountName: fission-svc
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user