Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2853498a98 | ||
|
|
b6bd921ac1 | ||
|
|
5d97ea7762 | ||
|
|
fb60a14ecc | ||
|
|
38ec6528e3 | ||
|
|
7d7f532c46 | ||
|
|
14e829f6a4 | ||
|
|
703613a475 | ||
|
|
0bbb5c5f38 | ||
|
|
d8aa5b7374 | ||
|
|
f44983f02a | ||
|
|
9f0bb6d11f | ||
|
|
a8157e94a9 | ||
|
|
cd23fc6f63 | ||
|
|
40678800e6 | ||
|
|
6acb59f979 | ||
|
|
4bce904c96 | ||
|
|
54b67b5171 | ||
|
|
96b07bf9a8 | ||
|
|
b156625997 | ||
|
|
6cf15f6cec | ||
|
|
3f0e4f5e81 | ||
|
|
1358aa2a81 | ||
|
|
f0aaef203e | ||
|
|
77d24fc544 | ||
|
|
a083ba3de5 | ||
|
|
6a50eac9eb | ||
|
|
b954eedff7 | ||
|
|
0247627494 | ||
|
|
158c40a7af | ||
|
|
699011e18e | ||
|
|
e7dc87843a | ||
|
|
e67c3b7945 | ||
|
|
36ed2e44aa | ||
|
|
38779b9318 | ||
|
|
7058130c3b | ||
|
|
9644477d08 | ||
|
|
87cac28cad | ||
|
|
238cfd854b | ||
|
|
f7cc0ac32d | ||
|
|
d8108c6742 | ||
|
|
d5eafded1a | ||
|
|
48e8acedfb | ||
|
|
11a2fdbdab | ||
|
|
0aa1a12cdc | ||
|
|
f37c5ee102 | ||
|
|
59267e3a6b | ||
|
|
82c0fbaeda | ||
|
|
2d70c9d65f | ||
|
|
c43f6fe9c0 | ||
|
|
36f318186b | ||
|
|
fe7f1b07c9 | ||
|
|
352090d092 | ||
|
|
db2b0ad4a0 | ||
|
|
4b76ec9057 | ||
|
|
15857b02d9 | ||
|
|
9bdac9a334 | ||
|
|
2f8ad16639 | ||
|
|
687a84a2d6 | ||
|
|
2db9db0b38 | ||
|
|
2bf00025ed | ||
|
|
b8f746cb98 | ||
|
|
93869d3bc8 | ||
|
|
5d580e01aa | ||
|
|
1f41de9991 | ||
|
|
5cdecefc49 | ||
|
|
21bccdaecf | ||
|
|
cf55fbecea | ||
|
|
b80437b78c | ||
|
|
11baffc92c | ||
|
|
ce49eb3e18 | ||
|
|
bf19e2fae2 | ||
|
|
26f964886e | ||
|
|
cb3a765495 | ||
|
|
7203cbf846 | ||
|
|
0b9d4c6f5a | ||
|
|
c6beb29f5a | ||
|
|
13abb2e905 | ||
|
|
54db275dc2 | ||
|
|
0159802497 | ||
|
|
90d781ca2d | ||
|
|
1732d9f4b0 | ||
|
|
8de5a5b0f3 | ||
|
|
35276a503b | ||
|
|
c6c811ea76 | ||
|
|
f2baa17131 | ||
|
|
a34840b0a7 | ||
|
|
06b52e3631 | ||
|
|
19858521fd | ||
|
|
4c4b574d07 | ||
|
|
9b978cf2fd | ||
|
|
ef05e242e4 | ||
|
|
156c1ac2e6 | ||
|
|
ade2daa013 | ||
|
|
6a84cee1d8 | ||
|
|
b95e317a20 | ||
|
|
0cfe08df55 | ||
|
|
4e0643eed7 | ||
|
|
103c7d57e4 | ||
|
|
c6d01827b0 | ||
|
|
d8fe37e736 | ||
|
|
c126298db4 | ||
|
|
f7e9e71ee1 | ||
|
|
3e43c07e5a | ||
|
|
932be4eb38 | ||
|
|
8bfe2d0ed1 | ||
|
|
9cea0d2b32 | ||
|
|
5337dbfd0b | ||
|
|
08c662bc11 | ||
|
|
241983d2f7 | ||
|
|
63864a91f2 | ||
|
|
579d46cc1b | ||
|
|
dcecb10e6c | ||
|
|
6144c58a44 | ||
|
|
7e8d5dd7ef | ||
|
|
796c7a48e8 | ||
|
|
b0e4440328 | ||
|
|
b801c77432 | ||
|
|
82b2848eb7 | ||
|
|
0c1b03b862 | ||
|
|
0c8573467b | ||
|
|
12f8017d9b | ||
|
|
29b0cf24ac | ||
|
|
d4aba532f3 | ||
|
|
9b57f1f2e7 | ||
|
|
1fe13624f2 | ||
|
|
fdecc98775 | ||
|
|
10852c90a5 | ||
|
|
62f729727a | ||
|
|
95faf60959 | ||
|
|
17fbe42fcc | ||
|
|
f44174debc | ||
|
|
efeb6951dc | ||
|
|
b85ba9e419 | ||
|
|
d23ed572f9 | ||
|
|
e7d6381876 | ||
|
|
57b537f09e | ||
|
|
2e4825def0 | ||
|
|
3fabf64b3c | ||
|
|
2a40b4538c | ||
|
|
27132975c4 | ||
|
|
b099db38d7 | ||
|
|
88039cad63 | ||
|
|
267f7faf18 | ||
|
|
2223081c80 | ||
|
|
2eb2eba88c | ||
|
|
8a17d391c5 | ||
|
|
15e16fcc82 | ||
|
|
7137b39a14 | ||
|
|
fc97b7609b | ||
|
|
c6329ee3db | ||
|
|
7b21fbc199 | ||
|
|
703d757c29 | ||
|
|
c09319ceb3 | ||
|
|
3762ff80f2 | ||
|
|
b43b31884a | ||
|
|
56b49dcee8 | ||
|
|
657aee7cc2 | ||
|
|
44922bce6c | ||
|
|
3bcda55aa8 | ||
|
|
997493351a | ||
|
|
3d77077bc5 | ||
|
|
f955d1182a | ||
|
|
1cbc0ba9ff | ||
|
|
0936c6a2d7 | ||
|
|
f0ec328d24 | ||
|
|
2b1ac28300 | ||
|
|
0fb2096788 | ||
|
|
6e375629e7 | ||
|
|
1133386ce9 | ||
|
|
f99f10134c | ||
|
|
6c431e4d9b | ||
|
|
31c81e132e | ||
|
|
a5f3402dbc | ||
|
|
784bd82ec7 | ||
|
|
cd742a6d18 | ||
|
|
32530ac474 | ||
|
|
117c383fac | ||
|
|
3a1db58066 | ||
|
|
ce42dbc647 | ||
|
|
3840a90b54 | ||
|
|
77d4745242 | ||
|
|
715ef8267e | ||
|
|
b622f13ab6 | ||
|
|
2213ebc637 | ||
|
|
1f138d03fa | ||
|
|
a8e8cfb72d | ||
|
|
963081e096 | ||
|
|
a96b92f41f | ||
|
|
a93e9b4074 | ||
|
|
0de8923ea8 | ||
|
|
1cb18a78a6 | ||
|
|
4ebdb16623 | ||
|
|
3c0c96e98e | ||
|
|
e462f9ab71 | ||
|
|
d025022042 | ||
|
|
c4ed12d9c5 | ||
|
|
d3a615211f | ||
|
|
2b017f810a | ||
|
|
5c3c55d52f | ||
|
|
5db09a899a | ||
|
|
0edf2640b1 | ||
|
|
deb3523b59 | ||
|
|
0635a6a644 | ||
|
|
a9d55423ae | ||
|
|
496e4e3162 | ||
|
|
6667d7e383 | ||
|
|
922cb34243 | ||
|
|
fcf4fd2e63 | ||
|
|
69470a68d0 | ||
|
|
8df4fd0e7c | ||
|
|
275cfb55a6 | ||
|
|
3e25f474b0 | ||
|
|
d52c60216e | ||
|
|
16cbb87eab | ||
|
|
5fae765323 | ||
|
|
31f4f8c57e | ||
|
|
3ae1742953 | ||
|
|
d16de59e9f | ||
|
|
61d98152f1 | ||
|
|
300739c031 | ||
|
|
94eead8697 | ||
|
|
612206b033 | ||
|
|
985d94b5b8 | ||
|
|
4dde3c9520 | ||
|
|
9ccd2a4128 | ||
|
|
e9fd13b60c | ||
|
|
ee623d31b2 | ||
|
|
9612baecc0 | ||
|
|
691feaa84f | ||
|
|
6bf0c4124a | ||
|
|
9eb7acf061 | ||
|
|
e015d6d61f | ||
|
|
918214c0a9 | ||
|
|
526b5f0beb | ||
|
|
0aec9e139e | ||
|
|
8a3d8a4762 | ||
|
|
38d380924d | ||
|
|
1e0641d5f9 | ||
|
|
f11902e81b | ||
|
|
8db3d0065a | ||
|
|
92453908c6 | ||
|
|
28daccb3aa | ||
|
|
31639774b0 | ||
|
|
82d066b73a | ||
|
|
9c4fc4a306 | ||
|
|
68286fe44e | ||
|
|
d559628f29 | ||
|
|
4cbe6a7061 | ||
|
|
6d117ad43a | ||
|
|
70a0afd624 | ||
|
|
d2f201b721 | ||
|
|
3b2a86a8c9 | ||
|
|
9a07d7d96b | ||
|
|
31dfc3e4d3 | ||
|
|
66897cb9d0 | ||
|
|
57d3a80fc6 | ||
|
|
fa037166e1 | ||
|
|
32bd874ab6 | ||
|
|
b71a36dc1c | ||
|
|
261bf24974 | ||
|
|
6af53807aa | ||
|
|
f37e9e6f89 | ||
|
|
b9fa6ca20a | ||
|
|
c33842c94c | ||
|
|
9ff9a6e075 | ||
|
|
a64fcc3faf | ||
|
|
47cbbef06f | ||
|
|
dbd2153181 | ||
|
|
2bd005c387 | ||
|
|
3a9e5ab65d | ||
|
|
ee790b3e1e | ||
|
|
7eeb3ead66 | ||
|
|
827baea974 | ||
|
|
facd14de90 | ||
|
|
8d65b062f1 | ||
|
|
d933f0ba6c | ||
|
|
f2b790921b | ||
|
|
8fe62b755c | ||
|
|
b9513868ed | ||
|
|
0739aca920 | ||
|
|
18225db2bd | ||
|
|
8008a5420a | ||
|
|
3fa0f4bde3 | ||
|
|
a8a81ef5be | ||
|
|
1102999b4d | ||
|
|
da50c3759d | ||
|
|
e87c84ee2c | ||
|
|
d03395949b | ||
|
|
b19d18c8bc |
+3
-5
@@ -1,11 +1,9 @@
|
|||||||
ignore:
|
ignore:
|
||||||
- "charts"
|
- "charts"
|
||||||
- "demos"
|
- "test/"
|
||||||
- "Documentation"
|
|
||||||
- "examples"
|
|
||||||
- "test"
|
|
||||||
- "tools"
|
- "tools"
|
||||||
- "pkg/apis/genclient"
|
- "pkg/generated" # generated code
|
||||||
|
- "pkg/apis/*/*/zz_generated*" # generated code
|
||||||
coverage:
|
coverage:
|
||||||
status:
|
status:
|
||||||
project:
|
project:
|
||||||
|
|||||||
@@ -0,0 +1,36 @@
|
|||||||
|
version: 2
|
||||||
|
updates:
|
||||||
|
- package-ecosystem: github-actions
|
||||||
|
directory: /
|
||||||
|
schedule:
|
||||||
|
interval: weekly
|
||||||
|
open-pull-requests-limit: 5
|
||||||
|
groups:
|
||||||
|
github-actions:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
|
||||||
|
- package-ecosystem: docker
|
||||||
|
directories:
|
||||||
|
- /cmd/builder
|
||||||
|
- /cmd/fetcher
|
||||||
|
- /cmd/fission-bundle
|
||||||
|
- /cmd/preupgradechecks
|
||||||
|
- /cmd/reporter
|
||||||
|
schedule:
|
||||||
|
interval: weekly
|
||||||
|
open-pull-requests-limit: 5
|
||||||
|
groups:
|
||||||
|
docker-images:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
|
||||||
|
- package-ecosystem: gomod
|
||||||
|
directory: /
|
||||||
|
schedule:
|
||||||
|
interval: weekly
|
||||||
|
open-pull-requests-limit: 5
|
||||||
|
groups:
|
||||||
|
go-dependencies:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
@@ -4,39 +4,43 @@ on:
|
|||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- main
|
- main
|
||||||
paths:
|
- '!dependabot/**'
|
||||||
- '**.go'
|
|
||||||
- go.mod
|
|
||||||
- go.sum
|
|
||||||
pull_request:
|
pull_request:
|
||||||
branches:
|
branches:
|
||||||
- main
|
- main
|
||||||
paths:
|
|
||||||
- '**.go'
|
|
||||||
- go.mod
|
|
||||||
- go.sum
|
|
||||||
schedule:
|
schedule:
|
||||||
- cron: "0 0 * * 0"
|
- cron: "0 0 * * 0"
|
||||||
workflow_dispatch:
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
CodeQL-Build:
|
CodeQL-Build:
|
||||||
runs-on: ubuntu-latest
|
permissions:
|
||||||
|
actions: read # for github/codeql-action/init to get workflow details
|
||||||
|
contents: read # for actions/checkout to fetch code
|
||||||
|
security-events: write # for github/codeql-action/analyze to upload SARIF results
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
|
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||||
steps:
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
- name: Check out code
|
- name: Check out code
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
- name: setup go
|
- name: setup go
|
||||||
uses: actions/setup-go@v3
|
uses: actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: "go.mod"
|
go-version-file: "go.mod"
|
||||||
cache: true
|
cache: true
|
||||||
|
|
||||||
- name: Initialize CodeQL
|
- name: Initialize CodeQL
|
||||||
uses: github/codeql-action/init@v2
|
uses: github/codeql-action/init@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
|
|
||||||
- name: Perform CodeQL Analysis
|
- name: Perform CodeQL Analysis
|
||||||
uses: github/codeql-action/analyze@v2
|
uses: github/codeql-action/analyze@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
|
||||||
|
|||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# Dependency Review Action
|
||||||
|
#
|
||||||
|
# This Action will scan dependency manifest files that change as part of a Pull Request,
|
||||||
|
# surfacing known-vulnerable versions of the packages declared or updated in the PR.
|
||||||
|
# Once installed, if the workflow run is marked as required,
|
||||||
|
# PRs introducing known-vulnerable packages will be blocked from merging.
|
||||||
|
#
|
||||||
|
# Source repository: https://github.com/actions/dependency-review-action
|
||||||
|
name: 'Dependency Review'
|
||||||
|
on: [pull_request]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
dependency-review:
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
|
- name: 'Checkout Repository'
|
||||||
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
- name: 'Dependency Review'
|
||||||
|
uses: actions/dependency-review-action@3b139cfc5fae8b618d3eae3675e383bb1769c019 # v4.5.0
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
name: Greetings
|
|
||||||
|
|
||||||
on: [pull_request, issues]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
greeting:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
issues: write
|
|
||||||
pull-requests: write
|
|
||||||
steps:
|
|
||||||
- uses: actions/first-interaction@v1
|
|
||||||
if: env.month != 'Oct'
|
|
||||||
with:
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
issue-message: 'Thank you for your first issue! ✨😊'
|
|
||||||
pr-message: 'Thank you for contributing to this project! ✨😊'
|
|
||||||
- uses: actions/first-interaction@v1
|
|
||||||
if: env.month == 'Oct'
|
|
||||||
with:
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
issue-message: 'Thank you for your first issue! Happy Hacktoberfest!!! ✨🎃👕✨'
|
|
||||||
pr-message: 'Thank you for contributing to this project. Happy Hacktoberfest!!! ✨🎃👕'
|
|
||||||
@@ -11,20 +11,27 @@ on:
|
|||||||
- main
|
- main
|
||||||
paths:
|
paths:
|
||||||
- 'charts/fission-all/dashboards/**.json'
|
- 'charts/fission-all/dashboards/**.json'
|
||||||
workflow_dispatch:
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
lint-dashboards:
|
lint-dashboards:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-24.04
|
||||||
|
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||||
steps:
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
- name: Check out code
|
- name: Check out code
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@v3
|
uses: actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
|
||||||
with:
|
with:
|
||||||
go-version: 1.18.5
|
go-version-file: "go.mod"
|
||||||
|
|
||||||
- name: Install dashboard linter
|
- name: Install dashboard linter
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -15,22 +15,32 @@ on:
|
|||||||
- "**.go"
|
- "**.go"
|
||||||
- go.mod
|
- go.mod
|
||||||
- go.sum
|
- go.sum
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
env:
|
env:
|
||||||
GOLANGCI_LINT_VERSION: v1.49.0
|
GOLANGCI_LINT_VERSION: v1.63.4
|
||||||
GOLANGCI_LINT_TIMEOUT: 5m
|
GOLANGCI_LINT_TIMEOUT: 5m
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
lint:
|
lint:
|
||||||
runs-on: ubuntu-latest
|
permissions:
|
||||||
|
contents: read # for actions/checkout to fetch code
|
||||||
|
pull-requests: read # for golangci/golangci-lint-action to fetch pull requests
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
|
# if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||||
steps:
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
- name: Check out code
|
- name: Check out code
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
- name: Set up Go
|
- name: Set up Go
|
||||||
uses: actions/setup-go@v3
|
uses: actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: "go.mod"
|
go-version-file: "go.mod"
|
||||||
cache: true
|
cache: true
|
||||||
@@ -41,8 +51,9 @@ jobs:
|
|||||||
go mod download
|
go mod download
|
||||||
|
|
||||||
- name: Run golangci-lint
|
- name: Run golangci-lint
|
||||||
uses: golangci/golangci-lint-action@v3
|
uses: golangci/golangci-lint-action@ec5d18412c0aeab7936cb16880d708ba2a64e1ae # v6.2.0
|
||||||
with:
|
with:
|
||||||
|
skip-cache: true
|
||||||
version: ${{ env.GOLANGCI_LINT_VERSION }}
|
version: ${{ env.GOLANGCI_LINT_VERSION }}
|
||||||
args: --timeout=${{ env.GOLANGCI_LINT_TIMEOUT }}
|
args: --timeout=${{ env.GOLANGCI_LINT_TIMEOUT }}
|
||||||
|
|
||||||
@@ -61,8 +72,8 @@ jobs:
|
|||||||
run: ./hack/runtests.sh
|
run: ./hack/runtests.sh
|
||||||
|
|
||||||
- name: Upload Coverage report to CodeCov
|
- name: Upload Coverage report to CodeCov
|
||||||
uses: codecov/codecov-action@v2
|
uses: codecov/codecov-action@1e68e06f1dbfde0e4cefc87efeba9e4643565303 # v5.1.2
|
||||||
with:
|
with:
|
||||||
token: ${{secrets.CODECOV_TOKEN}}
|
token: ${{ secrets.CODECOV_TOKEN }}
|
||||||
flags: unittests
|
flags: unittests
|
||||||
file: ./coverage.txt
|
file: ./coverage.txt
|
||||||
|
|||||||
+209
-22
@@ -4,6 +4,7 @@ on:
|
|||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- main
|
- main
|
||||||
|
- '!dependabot/**'
|
||||||
paths:
|
paths:
|
||||||
- "**.go"
|
- "**.go"
|
||||||
- "charts/**"
|
- "charts/**"
|
||||||
@@ -19,54 +20,66 @@ on:
|
|||||||
- "test/**"
|
- "test/**"
|
||||||
- go.mod
|
- go.mod
|
||||||
- go.sum
|
- go.sum
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
env:
|
env:
|
||||||
HELM_VERSION: v3.9.0
|
HELM_VERSION: v3.16.4
|
||||||
KIND_VERSION: v0.14.0
|
KIND_VERSION: v0.26.0
|
||||||
|
KIND_CLUSTER_NAME: kind
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
# Job to run change detection
|
# Job to run change detection
|
||||||
integration-test:
|
integration-test:
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
|
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
kindversion: ["v1.19.16", "v1.20.15", "v1.21.12"]
|
kindversion: ["v1.28.15", "v1.30.8", "v1.32.0"]
|
||||||
os: [ubuntu-latest]
|
os: [ubuntu-24.04]
|
||||||
steps:
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
- name: setup go
|
- name: setup go
|
||||||
uses: actions/setup-go@v3
|
uses: actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: "go.mod"
|
go-version-file: "go.mod"
|
||||||
cache: true
|
cache: true
|
||||||
|
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
with:
|
with:
|
||||||
repository: fission/examples
|
repository: fission/examples
|
||||||
path: examples
|
path: examples
|
||||||
|
|
||||||
- name: Helm installation
|
- name: Helm installation
|
||||||
uses: Azure/setup-helm@v3
|
uses: Azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814 # v4.2.0
|
||||||
with:
|
with:
|
||||||
version: ${{ env.HELM_VERSION }}
|
version: ${{ env.HELM_VERSION }}
|
||||||
|
|
||||||
- name: Kind Clutser
|
- name: Kind Cluster
|
||||||
uses: engineerd/setup-kind@v0.5.0
|
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
|
||||||
with:
|
with:
|
||||||
image: kindest/node:${{ matrix.kindversion }}
|
node_image: kindest/node:${{ matrix.kindversion }}
|
||||||
version: ${{ env.KIND_VERSION }}
|
version: ${{ env.KIND_VERSION }}
|
||||||
|
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||||
config: kind.yaml
|
config: kind.yaml
|
||||||
|
|
||||||
- name: Configuring and testing the Installation
|
- name: Configuring and testing the Installation
|
||||||
run: |
|
run: |
|
||||||
kubectl cluster-info --context kind-kind
|
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||||
kubectl get nodes
|
kubectl get nodes
|
||||||
sudo apt-get install -y apache2-utils
|
sudo apt-get install -y apache2-utils
|
||||||
|
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||||
|
kubectl config view
|
||||||
|
|
||||||
- name: Helm chart lint
|
- name: Helm chart lint
|
||||||
run: |
|
run: |
|
||||||
@@ -74,21 +87,23 @@ jobs:
|
|||||||
|
|
||||||
- name: Install Skaffold
|
- name: Install Skaffold
|
||||||
run: |
|
run: |
|
||||||
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/latest/skaffold-linux-amd64
|
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/v2.13.2/skaffold-linux-amd64
|
||||||
sudo install skaffold /usr/local/bin/
|
sudo install skaffold /usr/local/bin/
|
||||||
skaffold version
|
skaffold version
|
||||||
|
|
||||||
- name: Install GoReleaser
|
- name: Install GoReleaser
|
||||||
uses: goreleaser/goreleaser-action@v2
|
uses: goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
|
||||||
with:
|
with:
|
||||||
install-only: true
|
install-only: true
|
||||||
|
version: "~> v2"
|
||||||
|
|
||||||
- name: Setup Prometheus Stack
|
- name: Setup Prometheus Stack
|
||||||
run: |
|
run: |
|
||||||
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
|
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
|
||||||
helm repo update
|
helm repo update
|
||||||
kubectl create ns monitoring
|
kubectl create ns monitoring
|
||||||
helm install monitoring prometheus-community/prometheus -n monitoring
|
helm install prometheus prometheus-community/kube-prometheus-stack -n monitoring \
|
||||||
|
--version 45.28.0 --set grafana.enabled=false --set alertmanager.enabled=false
|
||||||
|
|
||||||
- name: Build and Install Fission CLI
|
- name: Build and Install Fission CLI
|
||||||
run: |
|
run: |
|
||||||
@@ -98,6 +113,7 @@ jobs:
|
|||||||
sudo chmod +x /usr/local/bin/fission
|
sudo chmod +x /usr/local/bin/fission
|
||||||
|
|
||||||
- name: Build and Install Fission
|
- name: Build and Install Fission
|
||||||
|
timeout-minutes: 10
|
||||||
run: |
|
run: |
|
||||||
kubectl create ns fission
|
kubectl create ns fission
|
||||||
make create-crds
|
make create-crds
|
||||||
@@ -106,37 +122,208 @@ jobs:
|
|||||||
- name: Port-forward fission components
|
- name: Port-forward fission components
|
||||||
run: |
|
run: |
|
||||||
kubectl port-forward svc/router 8888:80 -nfission &
|
kubectl port-forward svc/router 8888:80 -nfission &
|
||||||
kubectl port-forward svc/controller 8889:80 -nfission &
|
|
||||||
|
|
||||||
- name: Get fission version
|
- name: Get fission version
|
||||||
|
timeout-minutes: 10
|
||||||
run: |
|
run: |
|
||||||
fission version
|
fission version
|
||||||
|
|
||||||
- name: Integration tests
|
- name: Integration tests
|
||||||
|
timeout-minutes: 90
|
||||||
run: ./test/kind_CI.sh
|
run: ./test/kind_CI.sh
|
||||||
|
|
||||||
- name: Collect Fission Dump
|
- name: Collect Fission Dump
|
||||||
|
timeout-minutes: 5
|
||||||
if: ${{ always() }}
|
if: ${{ always() }}
|
||||||
run: |
|
run: |
|
||||||
command -v fission && fission support dump
|
command -v fission && fission support dump
|
||||||
|
|
||||||
- name: Kind export logs
|
- name: Kind export logs
|
||||||
|
timeout-minutes: 10
|
||||||
if: ${{ always() }}
|
if: ${{ always() }}
|
||||||
run: |
|
run: |
|
||||||
kind export logs --name kind kind-logs
|
kind export logs --name ${{ env.KIND_CLUSTER_NAME }} kind-logs
|
||||||
|
|
||||||
|
- name: Backup prometheus data
|
||||||
|
timeout-minutes: 10
|
||||||
|
if: ${{ always() }}
|
||||||
|
run: |
|
||||||
|
TRACE=1 ./hack/backup-prometheus.sh
|
||||||
|
|
||||||
- name: Archive fission dump
|
- name: Archive fission dump
|
||||||
if: ${{ failure() }}
|
timeout-minutes: 10
|
||||||
uses: actions/upload-artifact@v2
|
if: ${{ failure() || cancelled() }}
|
||||||
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
with:
|
with:
|
||||||
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
path: fission-dump/*.zip
|
path: fission-dump/*.zip
|
||||||
retention-days: 5
|
retention-days: 5
|
||||||
|
|
||||||
- name: Archive kind logs
|
- name: Archive prometheus dump
|
||||||
|
timeout-minutes: 10
|
||||||
if: ${{ always() }}
|
if: ${{ always() }}
|
||||||
uses: actions/upload-artifact@v2
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
|
with:
|
||||||
|
name: prom-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
|
path: /tmp/prometheus/*
|
||||||
|
retention-days: 5
|
||||||
|
|
||||||
|
- name: Archive kind logs
|
||||||
|
timeout-minutes: 10
|
||||||
|
if: ${{ always() }}
|
||||||
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
with:
|
with:
|
||||||
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
path: kind-logs/*
|
path: kind-logs/*
|
||||||
retention-days: 5
|
retention-days: 5
|
||||||
|
|
||||||
|
# Job to ensure backward compatibility if function and builder pods are created
|
||||||
|
# inside functionNamespace and builderNamespace
|
||||||
|
integration-test-old:
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
if: ${{ contains(github.event.pull_request.labels.*.name, 'run-old-ci') }}
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
kindversion: ["v1.19.16"]
|
||||||
|
os: [ubuntu-24.04]
|
||||||
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
|
- name: setup go
|
||||||
|
uses: actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
|
||||||
|
with:
|
||||||
|
go-version-file: "go.mod"
|
||||||
|
cache: true
|
||||||
|
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
with:
|
||||||
|
repository: fission/examples
|
||||||
|
path: examples
|
||||||
|
|
||||||
|
- name: Helm installation
|
||||||
|
uses: Azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814 # v4.2.0
|
||||||
|
with:
|
||||||
|
version: ${{ env.HELM_VERSION }}
|
||||||
|
|
||||||
|
- name: Kind Cluster
|
||||||
|
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
|
||||||
|
with:
|
||||||
|
node_image: kindest/node:${{ matrix.kindversion }}
|
||||||
|
version: ${{ env.KIND_VERSION }}
|
||||||
|
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||||
|
config: kind.yaml
|
||||||
|
|
||||||
|
- name: Configuring and testing the Installation
|
||||||
|
run: |
|
||||||
|
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||||
|
kubectl get nodes
|
||||||
|
sudo apt-get install -y apache2-utils
|
||||||
|
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||||
|
kubectl config view
|
||||||
|
|
||||||
|
- name: Helm chart lint
|
||||||
|
run: |
|
||||||
|
helm lint charts/fission-all/
|
||||||
|
|
||||||
|
- name: Install Skaffold
|
||||||
|
run: |
|
||||||
|
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/v2.13.2/skaffold-linux-amd64
|
||||||
|
sudo install skaffold /usr/local/bin/
|
||||||
|
skaffold version
|
||||||
|
|
||||||
|
- name: Install GoReleaser
|
||||||
|
uses: goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
|
||||||
|
with:
|
||||||
|
install-only: true
|
||||||
|
version: "~> v2"
|
||||||
|
|
||||||
|
- name: Setup Prometheus Stack
|
||||||
|
run: |
|
||||||
|
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
|
||||||
|
helm repo update
|
||||||
|
kubectl create ns monitoring
|
||||||
|
helm install prometheus prometheus-community/kube-prometheus-stack -n monitoring \
|
||||||
|
--version 45.28.0 --set grafana.enabled=false --set alertmanager.enabled=false
|
||||||
|
|
||||||
|
- name: Build and Install Fission CLI
|
||||||
|
run: |
|
||||||
|
make debug-vars
|
||||||
|
make build-fission-cli
|
||||||
|
sudo make install-fission-cli
|
||||||
|
sudo chmod +x /usr/local/bin/fission
|
||||||
|
|
||||||
|
- name: Build and Install Fission
|
||||||
|
timeout-minutes: 10
|
||||||
|
run: |
|
||||||
|
kubectl create ns fission
|
||||||
|
make create-crds
|
||||||
|
SKAFFOLD_PROFILE=kind-ci-old make skaffold-deploy
|
||||||
|
|
||||||
|
- name: Port-forward fission components
|
||||||
|
run: |
|
||||||
|
kubectl port-forward svc/router 8888:80 -nfission &
|
||||||
|
|
||||||
|
- name: Get fission version
|
||||||
|
timeout-minutes: 10
|
||||||
|
run: |
|
||||||
|
fission version
|
||||||
|
|
||||||
|
- name: Integration tests
|
||||||
|
timeout-minutes: 90
|
||||||
|
run: |
|
||||||
|
export FUNCTION_NAMESPACE=fission-function
|
||||||
|
export BUILDER_NAMESPACE=fission-builder
|
||||||
|
./test/kind_CI.sh
|
||||||
|
|
||||||
|
- name: Collect Fission Dump
|
||||||
|
timeout-minutes: 5
|
||||||
|
if: ${{ always() }}
|
||||||
|
run: |
|
||||||
|
command -v fission && fission support dump
|
||||||
|
|
||||||
|
- name: Kind export logs
|
||||||
|
timeout-minutes: 10
|
||||||
|
if: ${{ always() }}
|
||||||
|
run: |
|
||||||
|
kind export logs --name kind kind-logs
|
||||||
|
|
||||||
|
- name: Backup prometheus data
|
||||||
|
timeout-minutes: 10
|
||||||
|
if: ${{ always() }}
|
||||||
|
run: |
|
||||||
|
TRACE=1 ./hack/backup-prometheus.sh
|
||||||
|
|
||||||
|
- name: Archive fission dump
|
||||||
|
timeout-minutes: 10
|
||||||
|
if: ${{ failure() || cancelled() }}
|
||||||
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
|
with:
|
||||||
|
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
|
path: fission-dump/*.zip
|
||||||
|
retention-days: 5
|
||||||
|
|
||||||
|
- name: Archive prometheus dump
|
||||||
|
timeout-minutes: 10
|
||||||
|
if: ${{ always() }}
|
||||||
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
|
with:
|
||||||
|
name: prom-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
|
path: /tmp/prometheus/*
|
||||||
|
retention-days: 5
|
||||||
|
|
||||||
|
- name: Archive kind logs
|
||||||
|
timeout-minutes: 10
|
||||||
|
if: ${{ always() }}
|
||||||
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
|
with:
|
||||||
|
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
|
path: kind-logs/*
|
||||||
|
retention-days: 5
|
||||||
+219
-26
@@ -6,61 +6,77 @@ on:
|
|||||||
- v2.**
|
- v2.**
|
||||||
|
|
||||||
env:
|
env:
|
||||||
KIND_VERSION: v0.14.0
|
KIND_VERSION: v0.26.0
|
||||||
KIND_NODE_IMAGE_TAG: v1.19.16
|
KIND_NODE_IMAGE_TAG: v1.28.15
|
||||||
|
KIND_CLUSTER_NAME: kind
|
||||||
|
COSIGN_VERSION: v2.4.1
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
create-draft-release:
|
create-draft-release:
|
||||||
runs-on: ubuntu-latest
|
name: Create Draft Release with Goreleaser
|
||||||
|
outputs:
|
||||||
|
hashes: ${{ steps.binary.outputs.hashes }}
|
||||||
|
ghcr_images: ${{ steps.image.outputs.ghcr_images }}
|
||||||
|
version: ${{ steps.get_version.outputs.VERSION }}
|
||||||
|
permissions:
|
||||||
|
contents: write # for goreleaser/goreleaser-action to create a GitHub release
|
||||||
|
packages: write # for goreleaser/goreleaser-action to upload artifacts to GitHub Packages
|
||||||
|
id-token: write # for cosign to sign the image and binary
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
steps:
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
- name: Check out code
|
- name: Check out code
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
- name: Setup go
|
- name: Setup go
|
||||||
uses: actions/setup-go@v3
|
uses: actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: "go.mod"
|
go-version-file: "go.mod"
|
||||||
cache: true
|
cache: true
|
||||||
|
|
||||||
- name: Get the version
|
- name: Get the version
|
||||||
id: get_version
|
id: get_version
|
||||||
run: echo ::set-output name=VERSION::${GITHUB_REF/refs\/tags\//}
|
run: echo "VERSION=${GITHUB_REF/refs\/tags\//}" >> $GITHUB_OUTPUT
|
||||||
|
|
||||||
- name: Install GoReleaser
|
- name: Install GoReleaser
|
||||||
uses: goreleaser/goreleaser-action@v3
|
uses: goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
|
||||||
with:
|
with:
|
||||||
install-only: true
|
install-only: true
|
||||||
|
version: "~> v2"
|
||||||
|
|
||||||
- name: Kind Clutser
|
- name: Kind Cluster
|
||||||
uses: engineerd/setup-kind@v0.5.0
|
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
|
||||||
with:
|
with:
|
||||||
image: kindest/node:${{ env.KIND_NODE_IMAGE_TAG }}
|
node_image: kindest/node:${{ env.KIND_NODE_IMAGE_TAG }}
|
||||||
version: ${{ env.KIND_VERSION }}
|
version: ${{ env.KIND_VERSION }}
|
||||||
config: kind.yaml
|
config: kind.yaml
|
||||||
|
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||||
|
|
||||||
- name: Set up QEMU
|
- name: Set up QEMU
|
||||||
uses: docker/setup-qemu-action@v2
|
uses: docker/setup-qemu-action@53851d14592bedcffcf25ea515637cff71ef929a # v3.3.0
|
||||||
|
|
||||||
- name: Docker Login
|
- name: Login to ghcr.io
|
||||||
uses: docker/login-action@v2
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
with:
|
with:
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
registry: ghcr.io
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
username: ${{ github.repository_owner }}
|
||||||
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: Install Cosign
|
- name: Install Cosign
|
||||||
uses: sigstore/cosign-installer@main
|
uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
|
||||||
with:
|
with:
|
||||||
cosign-release: 'v1.12.0'
|
cosign-release: ${{ env.COSIGN_VERSION }}
|
||||||
|
|
||||||
- name: Check cosign install!
|
- name: Check cosign install!
|
||||||
run: cosign version
|
run: cosign version
|
||||||
|
|
||||||
- name: Write cosign signing key to disk
|
- uses: anchore/sbom-action/download-syft@df80a981bc6edbc4e220a492d3cbe9f5547a6e75 #v0.17.9
|
||||||
run: 'echo "$KEY" > cosign.key'
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
|
||||||
|
|
||||||
- name: Generate yaml for manifest, Minikube and Openshift installation
|
- name: Generate yaml for manifest, Minikube and Openshift installation
|
||||||
run: ${GITHUB_WORKSPACE}/hack/build-yaml.sh $VERSION
|
run: ${GITHUB_WORKSPACE}/hack/build-yaml.sh $VERSION
|
||||||
@@ -69,14 +85,191 @@ jobs:
|
|||||||
shell: bash
|
shell: bash
|
||||||
|
|
||||||
- name: Run GoReleaser
|
- name: Run GoReleaser
|
||||||
uses: goreleaser/goreleaser-action@v3
|
id: goreleaser
|
||||||
|
uses: goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: "~> v2"
|
||||||
args: release
|
args: release
|
||||||
env:
|
env:
|
||||||
COSIGN_PWD: ${{ secrets.COSIGN_PWD }}
|
|
||||||
GORELEASER_CURRENT_TAG: ${{ steps.get_version.outputs.VERSION }}
|
GORELEASER_CURRENT_TAG: ${{ steps.get_version.outputs.VERSION }}
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
DOCKER_CLI_EXPERIMENTAL: "enabled"
|
DOCKER_CLI_EXPERIMENTAL: "enabled"
|
||||||
|
|
||||||
#ToDo - Verify and upload releases
|
- name: Generate binary hashes
|
||||||
|
id: binary
|
||||||
|
env:
|
||||||
|
ARTIFACTS: "${{ steps.goreleaser.outputs.artifacts }}"
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
checksum_file=$(echo "$ARTIFACTS" | jq -r '.[] | select (.type=="Checksum") | .path')
|
||||||
|
echo "hashes=$(cat $checksum_file | base64 -w0)" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
- name: Image digest
|
||||||
|
id: image
|
||||||
|
env:
|
||||||
|
ARTIFACTS: "${{ steps.goreleaser.outputs.artifacts }}"
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
image_and_digest=$(echo "$ARTIFACTS" | jq -r '.[] | select (.type=="Docker Manifest") | {name, "digest": (.extra.Digest // .extra.Checksum)} | select(.digest) | {name} + {digest} | join("@") | sub("^sha256:";"")' | grep -v latest)
|
||||||
|
ghcr_images=$(echo "${image_and_digest}" | grep ghcr.io | jq -R -s -c '
|
||||||
|
split("\n")
|
||||||
|
| map(select(. != ""))
|
||||||
|
| map(
|
||||||
|
split("@")
|
||||||
|
| {
|
||||||
|
"image": .[0] | split(":")[0],
|
||||||
|
"checksum": .[1]
|
||||||
|
}
|
||||||
|
)')
|
||||||
|
echo "ghcr_images=$ghcr_images" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
binary-provenance:
|
||||||
|
name: Create Binary Provenance
|
||||||
|
needs: [create-draft-release]
|
||||||
|
permissions:
|
||||||
|
actions: read # To read the workflow path.
|
||||||
|
id-token: write # To sign the provenance.
|
||||||
|
contents: write # To add assets to a release.
|
||||||
|
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0 # Do not use commit hash
|
||||||
|
with:
|
||||||
|
base64-subjects: "${{ needs.create-draft-release.outputs.hashes }}"
|
||||||
|
provenance-name: "fission_${{ needs.create-draft-release.outputs.version }}.intoto.jsonl"
|
||||||
|
upload-assets: true # upload to a new release
|
||||||
|
draft-release: true # create a draft release
|
||||||
|
|
||||||
|
image-provenance-ghcr:
|
||||||
|
name: Create Image Provenance
|
||||||
|
needs: [create-draft-release]
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
include: ${{ fromJson(needs.create-draft-release.outputs.ghcr_images) }}
|
||||||
|
permissions:
|
||||||
|
actions: read
|
||||||
|
id-token: write
|
||||||
|
packages: write
|
||||||
|
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.0.0 # Do not use commit hash
|
||||||
|
with:
|
||||||
|
image: ${{ fromJson(toJson(matrix)).image }}
|
||||||
|
digest: ${{ fromJson(toJson(matrix)).checksum }}
|
||||||
|
registry-username: ${{ github.actor }}
|
||||||
|
secrets:
|
||||||
|
registry-password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
|
image-sbom-ghcr:
|
||||||
|
name: Create SBOM for container images
|
||||||
|
# Goreleaser does not support generating SBOM for container images.
|
||||||
|
needs: [create-draft-release]
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
include: ${{ fromJson(needs.create-draft-release.outputs.ghcr_images) }}
|
||||||
|
permissions:
|
||||||
|
actions: write
|
||||||
|
id-token: write
|
||||||
|
packages: write
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
- name: Login to GitHub Container Registry
|
||||||
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
|
with:
|
||||||
|
registry: ghcr.io
|
||||||
|
username: ${{ github.actor }}
|
||||||
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
- name: Run Trivy in fs mode to generate SBOM
|
||||||
|
uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29.0
|
||||||
|
with:
|
||||||
|
scan-type: "fs"
|
||||||
|
format: "spdx-json"
|
||||||
|
output: "spdx.sbom.json"
|
||||||
|
- name: Install Cosign
|
||||||
|
uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
|
||||||
|
with:
|
||||||
|
cosign-release: ${{ env.COSIGN_VERSION }}
|
||||||
|
- name: Sign image and sbom
|
||||||
|
env:
|
||||||
|
IMAGE: ${{ fromJson(toJson(matrix)).image }}
|
||||||
|
DIGEST: ${{ fromJson(toJson(matrix)).checksum }}
|
||||||
|
run: |
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
cosign attach sbom --sbom spdx.sbom.json $IMAGE@$DIGEST
|
||||||
|
cosign sign -a git_sha=$GITHUB_SHA --attachment sbom $IMAGE@$DIGEST --yes
|
||||||
|
|
||||||
|
binary-provenance-verification-with-slsa-verifier:
|
||||||
|
name : Verify Binary Provenance
|
||||||
|
needs: [create-draft-release, binary-provenance]
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
|
permissions:
|
||||||
|
contents: write # To download the assets from draft release.
|
||||||
|
steps:
|
||||||
|
- name: Install the verifier
|
||||||
|
uses: slsa-framework/slsa-verifier/actions/installer@3714a2a4684014deb874a0e737dffa0ee02dd647 # v2.6.0
|
||||||
|
|
||||||
|
- name: Download assets
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
PROVENANCE: ${{ needs.binary-provenance.outputs.provenance-name }}
|
||||||
|
VERSION: ${{ needs.create-draft-release.outputs.version }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
echo "repo=$GITHUB_REPOSITORY"
|
||||||
|
echo "ref=$VERSION"
|
||||||
|
gh -R "$GITHUB_REPOSITORY" release download "$VERSION" -p "$PROVENANCE"
|
||||||
|
|
||||||
|
- name: Verify assets
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
CHECKSUMS: ${{ needs.create-draft-release.outputs.hashes }}
|
||||||
|
PROVENANCE: ${{ needs.binary-provenance.outputs.provenance-name }}
|
||||||
|
VERSION: ${{ needs.create-draft-release.outputs.version }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
echo "CHECKSUMS=$CHECKSUMS"
|
||||||
|
echo "PROVENANCE=$PROVENANCE"
|
||||||
|
checksums=$(echo "$CHECKSUMS" | base64 -d)
|
||||||
|
while read -r line; do
|
||||||
|
fn=$(echo $line | cut -d ' ' -f2)
|
||||||
|
echo "Verifying $fn"
|
||||||
|
gh -R "$GITHUB_REPOSITORY" release download "$VERSION" -p "$fn"
|
||||||
|
slsa-verifier verify-artifact --provenance-path "$PROVENANCE" \
|
||||||
|
--source-uri "github.com/$GITHUB_REPOSITORY" \
|
||||||
|
--source-tag "$VERSION" \
|
||||||
|
"$fn"
|
||||||
|
done <<<"$checksums"
|
||||||
|
|
||||||
|
image-provenance-verification-with-cosign:
|
||||||
|
name: Verify Image Provenance
|
||||||
|
needs: [create-draft-release, image-provenance-ghcr]
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
include: ${{ fromJson(needs.create-draft-release.outputs.ghcr_images) }}
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
|
permissions: read-all
|
||||||
|
steps:
|
||||||
|
- name: Login
|
||||||
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
|
with:
|
||||||
|
registry: ghcr.io
|
||||||
|
username: ${{ github.actor }}
|
||||||
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
|
- name: Install Cosign
|
||||||
|
uses: sigstore/cosign-installer@dc72c7d5c4d10cd6bcb8cf6e3fd625a9e5e537da # v3.7.0
|
||||||
|
with:
|
||||||
|
cosign-release: ${{ env.COSIGN_VERSION }}
|
||||||
|
|
||||||
|
- name: Verify image
|
||||||
|
env:
|
||||||
|
IMAGE: ${{ fromJson(toJson(matrix)).image }}
|
||||||
|
DIGEST: ${{ fromJson(toJson(matrix)).checksum }}
|
||||||
|
run: |
|
||||||
|
echo "Verifying $IMAGE@$DIGEST"
|
||||||
|
cosign verify-attestation \
|
||||||
|
--type slsaprovenance \
|
||||||
|
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
|
||||||
|
--certificate-identity-regexp '^https://github.com/slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@refs/tags/v[0-9]+.[0-9]+.[0-9]+$' \
|
||||||
|
$IMAGE@$DIGEST
|
||||||
@@ -0,0 +1,78 @@
|
|||||||
|
# This workflow uses actions that are not certified by GitHub. They are provided
|
||||||
|
# by a third-party and are governed by separate terms of service, privacy
|
||||||
|
# policy, and support documentation.
|
||||||
|
|
||||||
|
name: Scorecard supply-chain security
|
||||||
|
on:
|
||||||
|
# For Branch-Protection check. Only the default branch is supported. See
|
||||||
|
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
|
||||||
|
branch_protection_rule:
|
||||||
|
# To guarantee Maintained check is occasionally updated. See
|
||||||
|
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
|
||||||
|
schedule:
|
||||||
|
- cron: '41 18 * * 0'
|
||||||
|
push:
|
||||||
|
branches: [ "main" ]
|
||||||
|
|
||||||
|
# Declare default permissions as read only.
|
||||||
|
permissions: read-all
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
analysis:
|
||||||
|
name: Scorecard analysis
|
||||||
|
runs-on: ubuntu-24.04
|
||||||
|
permissions:
|
||||||
|
# Needed to upload the results to code-scanning dashboard.
|
||||||
|
security-events: write
|
||||||
|
# Needed to publish results and get a badge (see publish_results below).
|
||||||
|
id-token: write
|
||||||
|
# Uncomment the permissions below if installing in a private repository.
|
||||||
|
# contents: read
|
||||||
|
# actions: read
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
|
- name: "Checkout code"
|
||||||
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
|
- name: "Run analysis"
|
||||||
|
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
|
||||||
|
with:
|
||||||
|
results_file: results.sarif
|
||||||
|
results_format: sarif
|
||||||
|
# (Optional) "write" PAT token. Uncomment the `repo_token` line below if:
|
||||||
|
# - you want to enable the Branch-Protection check on a *public* repository, or
|
||||||
|
# - you are installing Scorecard on a *private* repository
|
||||||
|
# To create the PAT, follow the steps in https://github.com/ossf/scorecard-action?tab=readme-ov-file#authentication-with-fine-grained-pat-optional.
|
||||||
|
# repo_token: ${{ secrets.SCORECARD_TOKEN }}
|
||||||
|
|
||||||
|
# Public repositories:
|
||||||
|
# - Publish results to OpenSSF REST API for easy access by consumers
|
||||||
|
# - Allows the repository to include the Scorecard badge.
|
||||||
|
# - See https://github.com/ossf/scorecard-action#publishing-results.
|
||||||
|
# For private repositories:
|
||||||
|
# - `publish_results` will always be set to `false`, regardless
|
||||||
|
# of the value entered here.
|
||||||
|
publish_results: true
|
||||||
|
|
||||||
|
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
|
||||||
|
# format to the repository Actions tab.
|
||||||
|
- name: "Upload artifact"
|
||||||
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v3.pre.node20
|
||||||
|
with:
|
||||||
|
name: SARIF file
|
||||||
|
path: results.sarif
|
||||||
|
retention-days: 5
|
||||||
|
|
||||||
|
# Upload the results to GitHub's code scanning dashboard (optional).
|
||||||
|
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
|
||||||
|
- name: "Upload to code-scanning"
|
||||||
|
uses: github/codeql-action/upload-sarif@b6a472f63d85b9c78a3ac5e89422239fc15e9b3c # v3.28.1
|
||||||
|
with:
|
||||||
|
sarif_file: results.sarif
|
||||||
@@ -4,6 +4,7 @@ on:
|
|||||||
push:
|
push:
|
||||||
branches:
|
branches:
|
||||||
- main
|
- main
|
||||||
|
- '!dependabot/**'
|
||||||
paths:
|
paths:
|
||||||
- "**.go"
|
- "**.go"
|
||||||
- "charts/**"
|
- "charts/**"
|
||||||
@@ -19,51 +20,65 @@ on:
|
|||||||
- "test/**"
|
- "test/**"
|
||||||
- go.mod
|
- go.mod
|
||||||
- go.sum
|
- go.sum
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
env:
|
env:
|
||||||
HELM_VERSION: v3.9.0
|
HELM_VERSION: v3.16.4
|
||||||
KIND_VERSION: v0.14.0
|
KIND_VERSION: v0.26.0
|
||||||
|
KIND_CLUSTER_NAME: kind
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
upgrade-test:
|
upgrade-test:
|
||||||
runs-on: ${{ matrix.os }}
|
runs-on: ${{ matrix.os }}
|
||||||
|
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
||||||
strategy:
|
strategy:
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
matrix:
|
matrix:
|
||||||
kindimage: ["kindest/node:v1.19.16"]
|
kindversion: ["v1.28.15"]
|
||||||
os: [ubuntu-latest]
|
os: [ubuntu-24.04]
|
||||||
steps:
|
steps:
|
||||||
|
- name: Harden Runner
|
||||||
|
uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
|
||||||
|
with:
|
||||||
|
egress-policy: audit
|
||||||
|
|
||||||
- name: Checkout action sources
|
- name: Checkout action sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
- name: Setup go
|
- name: Setup go
|
||||||
uses: actions/setup-go@v3
|
uses: actions/setup-go@3041bf56c941b39c61721a86cd11f3bb1338122a # v5.2.0
|
||||||
with:
|
with:
|
||||||
go-version-file: "go.mod"
|
go-version-file: "go.mod"
|
||||||
cache: true
|
cache: true
|
||||||
|
|
||||||
- name: Setup Helm
|
- name: Setup Helm
|
||||||
uses: Azure/setup-helm@v3
|
uses: Azure/setup-helm@fe7b79cd5ee1e45176fcad797de68ecaf3ca4814 # v4.2.0
|
||||||
with:
|
with:
|
||||||
version: ${{ env.HELM_VERSION }}
|
version: ${{ env.HELM_VERSION }}
|
||||||
|
|
||||||
- name: Setup Kind Clutser
|
- name: Setup Kind Cluster
|
||||||
uses: engineerd/setup-kind@v0.5.0
|
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
|
||||||
with:
|
with:
|
||||||
image: ${{ matrix.kindimage }}
|
node_image: kindest/node:${{ matrix.kindversion }}
|
||||||
version: ${{ env.KIND_VERSION }}
|
version: ${{ env.KIND_VERSION }}
|
||||||
|
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
||||||
|
|
||||||
- name: Install GoReleaser
|
- name: Install GoReleaser
|
||||||
uses: goreleaser/goreleaser-action@v2
|
uses: goreleaser/goreleaser-action@9ed2f89a662bf1735a48bc8557fd212fa902bebf # v6.1.0
|
||||||
with:
|
with:
|
||||||
install-only: true
|
install-only: true
|
||||||
|
version: "~> v2"
|
||||||
|
|
||||||
- name: Setup kubectl & fetch node information
|
- name: Setup kubectl & fetch node information
|
||||||
run: |
|
run: |
|
||||||
kubectl cluster-info --context kind-kind
|
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||||
kubectl get nodes
|
kubectl get nodes
|
||||||
kubectl get storageclasses.storage.k8s.io
|
kubectl get storageclasses.storage.k8s.io
|
||||||
|
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
||||||
|
kubectl config set-context --current --namespace=default
|
||||||
|
kubectl config view
|
||||||
|
|
||||||
- name: Dump system info
|
- name: Dump system info
|
||||||
run: |
|
run: |
|
||||||
@@ -83,6 +98,7 @@ jobs:
|
|||||||
&& install_fission_cli
|
&& install_fission_cli
|
||||||
|
|
||||||
- name: Test previously created fission objects with new release
|
- name: Test previously created fission objects with new release
|
||||||
|
timeout-minutes: 10
|
||||||
run: |
|
run: |
|
||||||
source ./test/upgrade_test/fission_objects.sh test_fission_objects
|
source ./test/upgrade_test/fission_objects.sh test_fission_objects
|
||||||
|
|
||||||
@@ -91,10 +107,23 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
command -v fission && fission support dump
|
command -v fission && fission support dump
|
||||||
|
|
||||||
|
- name: Kind export logs
|
||||||
|
if: ${{ always() }}
|
||||||
|
run: |
|
||||||
|
kind export logs --name ${{ env.KIND_CLUSTER_NAME }} kind-logs
|
||||||
|
|
||||||
- name: Archive fission dump
|
- name: Archive fission dump
|
||||||
if: ${{ failure() }}
|
if: ${{ failure() || cancelled() }}
|
||||||
uses: actions/upload-artifact@v2
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
with:
|
with:
|
||||||
name: fission-dump
|
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
path: fission-dump/*.zip
|
path: fission-dump/*.zip
|
||||||
retention-days: 5
|
retention-days: 5
|
||||||
|
|
||||||
|
- name: Archive kind logs
|
||||||
|
if: ${{ always() }}
|
||||||
|
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
|
||||||
|
with:
|
||||||
|
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
||||||
|
path: kind-logs/*
|
||||||
|
retention-days: 5
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ cmd/reporter/reporter
|
|||||||
|
|
||||||
# Logs
|
# Logs
|
||||||
test/logs/
|
test/logs/
|
||||||
|
test/e2e/cli/fission-dump/
|
||||||
|
|
||||||
# Pycharm IDE
|
# Pycharm IDE
|
||||||
.idea
|
.idea
|
||||||
@@ -37,3 +38,6 @@ manifest/
|
|||||||
coverage.txt
|
coverage.txt
|
||||||
|
|
||||||
cosign.key
|
cosign.key
|
||||||
|
|
||||||
|
# Dumps
|
||||||
|
.dumps/
|
||||||
|
|||||||
+2
-1
@@ -14,6 +14,7 @@ linters:
|
|||||||
- misspell
|
- misspell
|
||||||
- nakedret
|
- nakedret
|
||||||
- unconvert
|
- unconvert
|
||||||
|
- promlinter
|
||||||
# Enable in future
|
# Enable in future
|
||||||
# - bodyclose
|
# - bodyclose
|
||||||
# - dogsled
|
# - dogsled
|
||||||
@@ -31,4 +32,4 @@ linters-settings:
|
|||||||
goimports:
|
goimports:
|
||||||
# put imports beginning with prefix after 3rd-party packages;
|
# put imports beginning with prefix after 3rd-party packages;
|
||||||
# it's a comma-separated list of prefixes
|
# it's a comma-separated list of prefixes
|
||||||
local-prefixes: github.com/fission/fission
|
local: github.com/fission/fission
|
||||||
|
|||||||
+187
-143
@@ -1,9 +1,14 @@
|
|||||||
|
version: 2
|
||||||
|
|
||||||
|
env:
|
||||||
|
- GHCR_REPO=ghcr.io/fission
|
||||||
|
|
||||||
project_name: fission
|
project_name: fission
|
||||||
release:
|
release:
|
||||||
github:
|
github:
|
||||||
owner: fission
|
owner: fission
|
||||||
name: fission
|
name: fission
|
||||||
prerelease: true
|
prerelease: "true"
|
||||||
draft: true
|
draft: true
|
||||||
header: |
|
header: |
|
||||||
Release Highlights: https://fission.io/docs/releases/{{ .Tag }}/
|
Release Highlights: https://fission.io/docs/releases/{{ .Tag }}/
|
||||||
@@ -16,7 +21,7 @@ before:
|
|||||||
hooks:
|
hooks:
|
||||||
- go mod tidy
|
- go mod tidy
|
||||||
snapshot:
|
snapshot:
|
||||||
name_template: "{{ .Tag }}"
|
version_template: "{{ .Tag }}"
|
||||||
builds:
|
builds:
|
||||||
- &build-linux
|
- &build-linux
|
||||||
id: builder
|
id: builder
|
||||||
@@ -36,9 +41,6 @@ builds:
|
|||||||
goarch:
|
goarch:
|
||||||
- amd64
|
- amd64
|
||||||
- arm64
|
- arm64
|
||||||
- arm
|
|
||||||
goarm:
|
|
||||||
- 7
|
|
||||||
binary: builder
|
binary: builder
|
||||||
dir: ./cmd/builder
|
dir: ./cmd/builder
|
||||||
- <<: *build-linux
|
- <<: *build-linux
|
||||||
@@ -60,12 +62,6 @@ builds:
|
|||||||
ignore:
|
ignore:
|
||||||
- goos: windows
|
- goos: windows
|
||||||
goarch: arm64
|
goarch: arm64
|
||||||
- goos: darwin
|
|
||||||
goarch: arm
|
|
||||||
goarm: 7
|
|
||||||
- goos: windows
|
|
||||||
goarch: arm
|
|
||||||
goarm: 7
|
|
||||||
- <<: *build-linux
|
- <<: *build-linux
|
||||||
id: pre-upgrade-checks
|
id: pre-upgrade-checks
|
||||||
binary: pre-upgrade-checks
|
binary: pre-upgrade-checks
|
||||||
@@ -82,42 +78,87 @@ dockers:
|
|||||||
ids:
|
ids:
|
||||||
- builder
|
- builder
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/builder:latest-amd64"
|
- "{{ .Env.GHCR_REPO }}/builder:latest-amd64"
|
||||||
- "fission/builder:{{ .Tag }}-amd64"
|
- "{{ .Env.GHCR_REPO }}/builder:{{ .Tag }}-amd64"
|
||||||
dockerfile: cmd/builder/Dockerfile.fission-builder
|
dockerfile: cmd/builder/Dockerfile
|
||||||
build_flag_templates:
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=The builder assists in building the fission function source code for deployment."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
- "--platform=linux/amd64"
|
- "--platform=linux/amd64"
|
||||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
- <<: *docker-amd64
|
- <<: *docker-amd64
|
||||||
ids:
|
ids:
|
||||||
- fetcher
|
- fetcher
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/fetcher:latest-amd64"
|
- "{{ .Env.GHCR_REPO }}/fetcher:latest-amd64"
|
||||||
- "fission/fetcher:{{ .Tag }}-amd64"
|
- "{{ .Env.GHCR_REPO }}/fetcher:{{ .Tag }}-amd64"
|
||||||
dockerfile: cmd/fetcher/Dockerfile.fission-fetcher
|
dockerfile: cmd/fetcher/Dockerfile
|
||||||
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=Fetcher is a lightweight component used by environment and builder pods. Fetcher helps in fetch and upload of source/deployment packages and specializing environments."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/amd64"
|
||||||
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
- <<: *docker-amd64
|
- <<: *docker-amd64
|
||||||
ids:
|
ids:
|
||||||
- fission-bundle
|
- fission-bundle
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/fission-bundle:latest-amd64"
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:latest-amd64"
|
||||||
- "fission/fission-bundle:{{ .Tag }}-amd64"
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:{{ .Tag }}-amd64"
|
||||||
dockerfile: cmd/fission-bundle/Dockerfile.fission-bundle
|
dockerfile: cmd/fission-bundle/Dockerfile
|
||||||
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=fission-bundle is a component which is a single binary for all components. Most server side components running on server side are fission-bundle binary wrapped in container and used with different arguments."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/amd64"
|
||||||
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
- <<: *docker-amd64
|
- <<: *docker-amd64
|
||||||
ids:
|
ids:
|
||||||
- pre-upgrade-checks
|
- pre-upgrade-checks
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/pre-upgrade-checks:latest-amd64"
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:latest-amd64"
|
||||||
- "fission/pre-upgrade-checks:{{ .Tag }}-amd64"
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:{{ .Tag }}-amd64"
|
||||||
dockerfile: cmd/preupgradechecks/Dockerfile.fission-preupgradechecks
|
dockerfile: cmd/preupgradechecks/Dockerfile
|
||||||
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=Preupgradechecks ensures that Fission is ready for the targeted version upgrade by performing checks beforehand."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/amd64"
|
||||||
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
- <<: *docker-amd64
|
- <<: *docker-amd64
|
||||||
ids:
|
ids:
|
||||||
- reporter
|
- reporter
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/reporter:latest-amd64"
|
- "{{ .Env.GHCR_REPO }}/reporter:latest-amd64"
|
||||||
- "fission/reporter:{{ .Tag }}-amd64"
|
- "{{ .Env.GHCR_REPO }}/reporter:{{ .Tag }}-amd64"
|
||||||
dockerfile: cmd/reporter/Dockerfile.reporter
|
dockerfile: cmd/reporter/Dockerfile
|
||||||
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=The reporter gathers information that assists in improving fission."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/amd64"
|
||||||
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
- &docker-arm64
|
- &docker-arm64
|
||||||
use: buildx
|
use: buildx
|
||||||
goos: linux
|
goos: linux
|
||||||
@@ -125,139 +166,130 @@ dockers:
|
|||||||
ids:
|
ids:
|
||||||
- builder
|
- builder
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/builder:latest-arm64"
|
- "{{ .Env.GHCR_REPO }}/builder:latest-arm64"
|
||||||
- "fission/builder:{{ .Tag }}-arm64"
|
- "{{ .Env.GHCR_REPO }}/builder:{{ .Tag }}-arm64"
|
||||||
dockerfile: cmd/builder/Dockerfile.fission-builder
|
dockerfile: cmd/builder/Dockerfile
|
||||||
build_flag_templates:
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=The builder assists in building the fission function source code for deployment."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
- "--platform=linux/arm64"
|
- "--platform=linux/arm64"
|
||||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
- <<: *docker-arm64
|
- <<: *docker-arm64
|
||||||
ids:
|
ids:
|
||||||
- fetcher
|
- fetcher
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/fetcher:latest-arm64"
|
- "{{ .Env.GHCR_REPO }}/fetcher:latest-arm64"
|
||||||
- "fission/fetcher:{{ .Tag }}-arm64"
|
- "{{ .Env.GHCR_REPO }}/fetcher:{{ .Tag }}-arm64"
|
||||||
dockerfile: cmd/fetcher/Dockerfile.fission-fetcher
|
dockerfile: cmd/fetcher/Dockerfile
|
||||||
- <<: *docker-arm64
|
|
||||||
ids:
|
|
||||||
- fission-bundle
|
|
||||||
image_templates:
|
|
||||||
- "fission/fission-bundle:latest-arm64"
|
|
||||||
- "fission/fission-bundle:{{ .Tag }}-arm64"
|
|
||||||
dockerfile: cmd/fission-bundle/Dockerfile.fission-bundle
|
|
||||||
- <<: *docker-arm64
|
|
||||||
ids:
|
|
||||||
- pre-upgrade-checks
|
|
||||||
image_templates:
|
|
||||||
- "fission/pre-upgrade-checks:latest-arm64"
|
|
||||||
- "fission/pre-upgrade-checks:{{ .Tag }}-arm64"
|
|
||||||
dockerfile: cmd/preupgradechecks/Dockerfile.fission-preupgradechecks
|
|
||||||
- <<: *docker-arm64
|
|
||||||
ids:
|
|
||||||
- reporter
|
|
||||||
image_templates:
|
|
||||||
- "fission/reporter:latest-arm64"
|
|
||||||
- "fission/reporter:{{ .Tag }}-arm64"
|
|
||||||
dockerfile: cmd/reporter/Dockerfile.reporter
|
|
||||||
- &docker-armv7
|
|
||||||
use: buildx
|
|
||||||
goos: linux
|
|
||||||
goarch: arm
|
|
||||||
goarm: 7
|
|
||||||
ids:
|
|
||||||
- builder
|
|
||||||
image_templates:
|
|
||||||
- "fission/builder:latest-armv7"
|
|
||||||
- "fission/builder:{{ .Tag }}-armv7"
|
|
||||||
dockerfile: cmd/builder/Dockerfile.fission-builder
|
|
||||||
build_flag_templates:
|
build_flag_templates:
|
||||||
- "--platform=linux/arm/v7"
|
- "--label=org.opencontainers.image.description=Fetcher is a lightweight component used by environment and builder pods. Fetcher helps in fetch and upload of source/deployment packages and specializing environments."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/arm64"
|
||||||
- "--label=org.opencontainers.image.created={{.Date}}"
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
- "--label=org.opencontainers.image.version={{.Tag}}"
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
- <<: *docker-armv7
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
ids:
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
- fetcher
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
image_templates:
|
- <<: *docker-arm64
|
||||||
- "fission/fetcher:latest-armv7"
|
|
||||||
- "fission/fetcher:{{ .Tag }}-armv7"
|
|
||||||
dockerfile: cmd/fetcher/Dockerfile.fission-fetcher
|
|
||||||
- <<: *docker-armv7
|
|
||||||
ids:
|
ids:
|
||||||
- fission-bundle
|
- fission-bundle
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/fission-bundle:latest-armv7"
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:latest-arm64"
|
||||||
- "fission/fission-bundle:{{ .Tag }}-armv7"
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:{{ .Tag }}-arm64"
|
||||||
dockerfile: cmd/fission-bundle/Dockerfile.fission-bundle
|
dockerfile: cmd/fission-bundle/Dockerfile
|
||||||
- <<: *docker-armv7
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=fission-bundle is a component which is a single binary for all components. Most server side components running on server side are fission-bundle binary wrapped in container and used with different arguments."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/arm64"
|
||||||
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
|
- <<: *docker-arm64
|
||||||
ids:
|
ids:
|
||||||
- pre-upgrade-checks
|
- pre-upgrade-checks
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/pre-upgrade-checks:latest-armv7"
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:latest-arm64"
|
||||||
- "fission/pre-upgrade-checks:{{ .Tag }}-armv7"
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:{{ .Tag }}-arm64"
|
||||||
dockerfile: cmd/preupgradechecks/Dockerfile.fission-preupgradechecks
|
dockerfile: cmd/preupgradechecks/Dockerfile
|
||||||
- <<: *docker-armv7
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=Preupgradechecks ensures that Fission is ready for the targeted version upgrade by performing checks beforehand."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/arm64"
|
||||||
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
|
- <<: *docker-arm64
|
||||||
ids:
|
ids:
|
||||||
- reporter
|
- reporter
|
||||||
image_templates:
|
image_templates:
|
||||||
- "fission/reporter:latest-armv7"
|
- "{{ .Env.GHCR_REPO }}/reporter:latest-arm64"
|
||||||
- "fission/reporter:{{ .Tag }}-armv7"
|
- "{{ .Env.GHCR_REPO }}/reporter:{{ .Tag }}-arm64"
|
||||||
dockerfile: cmd/reporter/Dockerfile.reporter
|
dockerfile: cmd/reporter/Dockerfile
|
||||||
|
build_flag_templates:
|
||||||
|
- "--label=org.opencontainers.image.description=The reporter gathers information that assists in improving fission."
|
||||||
|
- "--label=org.opencontainers.image.source={{.GitURL}}"
|
||||||
|
- "--platform=linux/arm64"
|
||||||
|
- "--label=org.opencontainers.image.created={{.Date}}"
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Tag}}"
|
||||||
|
- "--label=org.opencontainers.image.authors=The Fission Authors https://fission.io/"
|
||||||
|
- "--label=org.opencontainers.image.vendor=Fission"
|
||||||
|
- "--label=org.opencontainers.image.url=https://fission.io/"
|
||||||
docker_manifests:
|
docker_manifests:
|
||||||
- name_template: fission/builder:{{ .Tag }}
|
- name_template: "{{ .Env.GHCR_REPO }}/builder:{{ .Tag }}"
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/builder:{{ .Tag }}-amd64
|
- "{{ .Env.GHCR_REPO }}/builder:{{ .Tag }}-amd64"
|
||||||
- fission/builder:{{ .Tag }}-arm64
|
- "{{ .Env.GHCR_REPO }}/builder:{{ .Tag }}-arm64"
|
||||||
- fission/builder:{{ .Tag }}-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/fetcher:{{ .Tag }}"
|
||||||
- name_template: fission/fetcher:{{ .Tag }}
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/fetcher:{{ .Tag }}-amd64
|
- "{{ .Env.GHCR_REPO }}/fetcher:{{ .Tag }}-amd64"
|
||||||
- fission/fetcher:{{ .Tag }}-arm64
|
- "{{ .Env.GHCR_REPO }}/fetcher:{{ .Tag }}-arm64"
|
||||||
- fission/fetcher:{{ .Tag }}-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/fission-bundle:{{ .Tag }}"
|
||||||
- name_template: fission/fission-bundle:{{ .Tag }}
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/fission-bundle:{{ .Tag }}-amd64
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:{{ .Tag }}-amd64"
|
||||||
- fission/fission-bundle:{{ .Tag }}-arm64
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:{{ .Tag }}-arm64"
|
||||||
- fission/fission-bundle:{{ .Tag }}-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:{{ .Tag }}"
|
||||||
- name_template: fission/pre-upgrade-checks:{{ .Tag }}
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/pre-upgrade-checks:{{ .Tag }}-amd64
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:{{ .Tag }}-amd64"
|
||||||
- fission/pre-upgrade-checks:{{ .Tag }}-arm64
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:{{ .Tag }}-arm64"
|
||||||
- fission/pre-upgrade-checks:{{ .Tag }}-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/reporter:{{ .Tag }}"
|
||||||
- name_template: fission/reporter:{{ .Tag }}
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/reporter:{{ .Tag }}-amd64
|
- "{{ .Env.GHCR_REPO }}/reporter:{{ .Tag }}-amd64"
|
||||||
- fission/reporter:{{ .Tag }}-arm64
|
- "{{ .Env.GHCR_REPO }}/reporter:{{ .Tag }}-arm64"
|
||||||
- fission/reporter:{{ .Tag }}-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/builder:latest"
|
||||||
- name_template: fission/builder:latest
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/builder:latest-amd64
|
- "{{ .Env.GHCR_REPO }}/builder:latest-amd64"
|
||||||
- fission/builder:latest-arm64
|
- "{{ .Env.GHCR_REPO }}/builder:latest-arm64"
|
||||||
- fission/builder:latest-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/fetcher:latest"
|
||||||
- name_template: fission/fetcher:latest
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/fetcher:latest-amd64
|
- "{{ .Env.GHCR_REPO }}/fetcher:latest-amd64"
|
||||||
- fission/fetcher:latest-arm64
|
- "{{ .Env.GHCR_REPO }}/fetcher:latest-arm64"
|
||||||
- fission/fetcher:latest-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/fission-bundle:latest"
|
||||||
- name_template: fission/fission-bundle:latest
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/fission-bundle:latest-amd64
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:latest-amd64"
|
||||||
- fission/fission-bundle:latest-arm64
|
- "{{ .Env.GHCR_REPO }}/fission-bundle:latest-arm64"
|
||||||
- fission/fission-bundle:latest-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:latest"
|
||||||
- name_template: fission/pre-upgrade-checks:latest
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/pre-upgrade-checks:latest-amd64
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:latest-amd64"
|
||||||
- fission/pre-upgrade-checks:latest-arm64
|
- "{{ .Env.GHCR_REPO }}/pre-upgrade-checks:latest-arm64"
|
||||||
- fission/pre-upgrade-checks:latest-armv7
|
- name_template: "{{ .Env.GHCR_REPO }}/reporter:latest"
|
||||||
- name_template: fission/reporter:latest
|
|
||||||
image_templates:
|
image_templates:
|
||||||
- fission/reporter:latest-amd64
|
- "{{ .Env.GHCR_REPO }}/reporter:latest-amd64"
|
||||||
- fission/reporter:latest-arm64
|
- "{{ .Env.GHCR_REPO }}/reporter:latest-arm64"
|
||||||
- fission/reporter:latest-armv7
|
|
||||||
changelog:
|
changelog:
|
||||||
skip: false
|
disable: true
|
||||||
archives:
|
archives:
|
||||||
- id: fission
|
- id: fission
|
||||||
builds:
|
builds:
|
||||||
@@ -271,25 +303,37 @@ checksum:
|
|||||||
# signs the checksum file
|
# signs the checksum file
|
||||||
# https://goreleaser.com/customization/sign
|
# https://goreleaser.com/customization/sign
|
||||||
signs:
|
signs:
|
||||||
- cmd: cosign
|
- id: cosign-binary
|
||||||
artifacts: all
|
env:
|
||||||
stdin: '{{ .Env.COSIGN_PWD }}'
|
- COSIGN_EXPERIMENTAL=1
|
||||||
output: true
|
certificate: "${artifact}.pem"
|
||||||
args:
|
cmd: cosign
|
||||||
- sign-blob
|
artifacts: binary
|
||||||
- '--key=cosign.key'
|
args:
|
||||||
- '--output-certificate=${certificate}'
|
- sign-blob
|
||||||
- '--output-signature=${signature}'
|
- "--output-signature=${signature}"
|
||||||
- '${artifact}'
|
- "--output-certificate=${certificate}"
|
||||||
|
- "${artifact}"
|
||||||
|
- "--yes" # needed for cosign 2.0.0+
|
||||||
|
|
||||||
# signs our docker image
|
# signs our docker image
|
||||||
# https://goreleaser.com/customization/docker_sign
|
# https://goreleaser.com/customization/docker_sign
|
||||||
docker_signs:
|
docker_signs:
|
||||||
- cmd: cosign
|
- cmd: cosign
|
||||||
artifacts: all
|
env:
|
||||||
stdin: '{{ .Env.COSIGN_PWD }}'
|
- COSIGN_EXPERIMENTAL=1
|
||||||
output: true
|
artifacts: all
|
||||||
args:
|
args:
|
||||||
- 'sign'
|
- sign
|
||||||
- '--key=cosign.key'
|
- "${artifact}"
|
||||||
- '${artifact}'
|
- "--yes" # needed for cosign 2.0.0+
|
||||||
|
|
||||||
|
sboms:
|
||||||
|
- artifacts: archive
|
||||||
|
id: archive
|
||||||
|
- artifacts: source
|
||||||
|
id: source
|
||||||
|
- artifacts: binary
|
||||||
|
id: binary
|
||||||
|
- artifacts: package
|
||||||
|
id: package
|
||||||
|
|||||||
+4
-4
@@ -8,10 +8,10 @@ pull_request_rules:
|
|||||||
- check-success=CodeQL-Build
|
- check-success=CodeQL-Build
|
||||||
- check-success=CodeQL
|
- check-success=CodeQL
|
||||||
- check-success=lint
|
- check-success=lint
|
||||||
- check-success=upgrade-test (kindest/node:v1.19.11, ubuntu-latest)
|
- check-success=upgrade-test (kindest/node:v1.23.17, ubuntu-latest)
|
||||||
- check-success=integration-test (v1.19.11, ubuntu-latest)
|
- check-success=integration-test (v1.23.17, ubuntu-latest)
|
||||||
- check-success=integration-test (v1.20.7, ubuntu-latest)
|
- check-success=integration-test (v1.25.11, ubuntu-latest)
|
||||||
- check-success=integration-test (v1.21.1, ubuntu-latest)
|
- check-success=integration-test (v1.27.3, ubuntu-latest)
|
||||||
actions:
|
actions:
|
||||||
merge:
|
merge:
|
||||||
method: squash
|
method: squash
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
repos:
|
||||||
|
- repo: https://github.com/gitleaks/gitleaks
|
||||||
|
rev: v8.16.3
|
||||||
|
hooks:
|
||||||
|
- id: gitleaks
|
||||||
|
- repo: https://github.com/golangci/golangci-lint
|
||||||
|
rev: v1.52.2
|
||||||
|
hooks:
|
||||||
|
- id: golangci-lint
|
||||||
|
- repo: https://github.com/jumanjihouse/pre-commit-hooks
|
||||||
|
rev: 3.0.0
|
||||||
|
hooks:
|
||||||
|
- id: shellcheck
|
||||||
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||||
|
rev: v4.4.0
|
||||||
|
hooks:
|
||||||
|
- id: end-of-file-fixer
|
||||||
|
- id: trailing-whitespace
|
||||||
@@ -23,6 +23,7 @@ COMMITSHA ?= $(shell git rev-parse HEAD)
|
|||||||
GOOS ?= $(shell go env GOOS)
|
GOOS ?= $(shell go env GOOS)
|
||||||
GOARCH ?= $(shell go env GOARCH)
|
GOARCH ?= $(shell go env GOARCH)
|
||||||
GOAMD64 ?= $(shell go env GOAMD64)
|
GOAMD64 ?= $(shell go env GOAMD64)
|
||||||
|
GOPATH ?= $(shell go env GOPATH)
|
||||||
|
|
||||||
FISSION-CLI-SUFFIX :=
|
FISSION-CLI-SUFFIX :=
|
||||||
ifeq ($(GOOS), windows)
|
ifeq ($(GOOS), windows)
|
||||||
@@ -51,7 +52,7 @@ test-run: code-checks
|
|||||||
|
|
||||||
### Binaries
|
### Binaries
|
||||||
build-fission-cli:
|
build-fission-cli:
|
||||||
@GOOS=$(GOOS) GOARCH=$(GOARCH) GOAMD64=$(GOAMD64) GORELEASER_CURRENT_TAG=$(VERSION) goreleaser build --snapshot --rm-dist --single-target --id fission-cli
|
@GOOS=$(GOOS) GOARCH=$(GOARCH) GOAMD64=$(GOAMD64) GORELEASER_CURRENT_TAG=$(VERSION) goreleaser build --snapshot --clean --single-target --id fission-cli
|
||||||
|
|
||||||
install-fission-cli:
|
install-fission-cli:
|
||||||
# TODO: Fix this hack, replace v1 with GOAMD64
|
# TODO: Fix this hack, replace v1 with GOAMD64
|
||||||
@@ -60,16 +61,21 @@ install-fission-cli:
|
|||||||
### Codegen
|
### Codegen
|
||||||
codegen:
|
codegen:
|
||||||
@./hack/update-codegen.sh
|
@./hack/update-codegen.sh
|
||||||
|
go run sigs.k8s.io/controller-tools/cmd/controller-gen object:headerFile="hack/boilerplate.txt" paths="./..."
|
||||||
|
|
||||||
### CRDs
|
### CRDs
|
||||||
controller-gen-install:
|
generate-crds:
|
||||||
go install sigs.k8s.io/controller-tools/cmd/controller-gen@v0.9.2
|
go run sigs.k8s.io/controller-tools/cmd/controller-gen crd \
|
||||||
|
|
||||||
generate-crds: controller-gen-install
|
|
||||||
controller-gen crd \
|
|
||||||
paths=./pkg/apis/core/v1 \
|
paths=./pkg/apis/core/v1 \
|
||||||
output:crd:artifacts:config=crds/v1
|
output:crd:artifacts:config=crds/v1
|
||||||
|
|
||||||
|
### Webhook generation: it generates webhook configs with help of kubebuilder:webhook tag
|
||||||
|
generate-webhooks:
|
||||||
|
go run sigs.k8s.io/controller-tools/cmd/controller-gen webhook \
|
||||||
|
paths=./pkg/webhook \
|
||||||
|
output:dir=charts/fission-all/templates/webhook-server
|
||||||
|
|
||||||
|
|
||||||
create-crds:
|
create-crds:
|
||||||
@kubectl create -k crds/v1
|
@kubectl create -k crds/v1
|
||||||
|
|
||||||
@@ -90,25 +96,22 @@ generate-swagger-doc:
|
|||||||
generate-cli-docs:
|
generate-cli-docs:
|
||||||
go run tools/cmd-docs/main.go -o "../fission.io/content/en/docs/reference/fission-cli"
|
go run tools/cmd-docs/main.go -o "../fission.io/content/en/docs/reference/fission-cli"
|
||||||
|
|
||||||
install-crd-ref-docs:
|
generate-crd-ref-docs:
|
||||||
go install github.com/elastic/crd-ref-docs@master
|
|
||||||
|
|
||||||
generate-crd-ref-docs: install-crd-ref-docs
|
|
||||||
# crd-ref-docs: https://github.com/elastic/crd-ref-docs
|
# crd-ref-docs: https://github.com/elastic/crd-ref-docs
|
||||||
crd-ref-docs --source-path=pkg/apis/core/v1 --config=tools/crd-ref-docs/config.yaml --renderer markdown
|
go run github.com/elastic/crd-ref-docs --source-path=pkg/apis/core/v1 --config=tools/crd-ref-docs/config.yaml --renderer markdown
|
||||||
cp tools/crd-ref-docs/header.md crd_docs.md
|
cp tools/crd-ref-docs/header.md crd_docs.md
|
||||||
cat out.md >> crd_docs.md && rm out.md
|
cat out.md >> crd_docs.md && rm out.md
|
||||||
mv crd_docs.md ../fission.io/content/en/docs/reference/crd-reference.md
|
mv crd_docs.md ../fission.io/content/en/docs/reference/crd-reference.md
|
||||||
|
|
||||||
all-generators: codegen generate-crds generate-swagger-doc
|
all-generators: codegen generate-crds generate-swagger-doc generate-cli-docs generate-crd-ref-docs
|
||||||
|
|
||||||
skaffold-prebuild:
|
skaffold-prebuild:
|
||||||
@GOOS=linux GOARCH=amd64 GORELEASER_CURRENT_TAG=$(VERSION) goreleaser build --snapshot --rm-dist --single-target
|
@GOOS=linux GOARCH=amd64 GORELEASER_CURRENT_TAG=$(VERSION) goreleaser build --snapshot --clean --single-target
|
||||||
@cp -v cmd/builder/Dockerfile.fission-builder dist/builder_linux_amd64_v1/Dockerfile
|
@cp -v cmd/builder/Dockerfile dist/builder_linux_amd64_v1/Dockerfile
|
||||||
@cp -v cmd/fetcher/Dockerfile.fission-fetcher dist/fetcher_linux_amd64_v1/Dockerfile
|
@cp -v cmd/fetcher/Dockerfile dist/fetcher_linux_amd64_v1/Dockerfile
|
||||||
@cp -v cmd/fission-bundle/Dockerfile.fission-bundle dist/fission-bundle_linux_amd64_v1/Dockerfile
|
@cp -v cmd/fission-bundle/Dockerfile dist/fission-bundle_linux_amd64_v1/Dockerfile
|
||||||
@cp -v cmd/reporter/Dockerfile.reporter dist/reporter_linux_amd64_v1/Dockerfile
|
@cp -v cmd/reporter/Dockerfile dist/reporter_linux_amd64_v1/Dockerfile
|
||||||
@cp -v cmd/preupgradechecks/Dockerfile.fission-preupgradechecks dist/pre-upgrade-checks_linux_amd64_v1/Dockerfile
|
@cp -v cmd/preupgradechecks/Dockerfile dist/pre-upgrade-checks_linux_amd64_v1/Dockerfile
|
||||||
|
|
||||||
skaffold-deploy: skaffold-prebuild
|
skaffold-deploy: skaffold-prebuild
|
||||||
skaffold run -p $(SKAFFOLD_PROFILE)
|
skaffold run -p $(SKAFFOLD_PROFILE)
|
||||||
@@ -119,3 +122,10 @@ release:
|
|||||||
@./hack/release.sh $(VERSION)
|
@./hack/release.sh $(VERSION)
|
||||||
@./hack/release-tag.sh $(VERSION)
|
@./hack/release-tag.sh $(VERSION)
|
||||||
@./hack/changelog.sh
|
@./hack/changelog.sh
|
||||||
|
|
||||||
|
## Envtest
|
||||||
|
install-envtest:
|
||||||
|
go install sigs.k8s.io/controller-runtime/tools/setup-envtest@latest
|
||||||
|
|
||||||
|
setup-envtest:
|
||||||
|
setup-envtest -p path use 1.30.x
|
||||||
|
|||||||
@@ -36,12 +36,16 @@
|
|||||||
<a href="https://github.com/fission/fission">
|
<a href="https://github.com/fission/fission">
|
||||||
<img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/fission/fission?style=social">
|
<img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/fission/fission?style=social">
|
||||||
</a>
|
</a>
|
||||||
|
<a href="https://scorecard.dev/viewer/?uri=github.com/fission/fission">
|
||||||
|
<image alt="OpenSSF Scorecard" src="https://api.scorecard.dev/projects/github.com/fission/fission/badge">
|
||||||
|
</a>
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
--------------
|
--------------
|
||||||
|
|
||||||
Fission is a fast serverless framework for Kubernetes with a focus on
|
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. With Fission, developers can easily create and deploy serverless functions that can be triggered by a variety of events, such as HTTP requests, messages from a message queue, or scheduled tasks.
|
||||||
developer productivity and high performance.
|
|
||||||
|
Fission provides a simple, easy-to-use interface for developers to create serverless functions in their language of choice, without having to worry about the underlying infrastructure. The framework also offers automatic scaling, so functions can scale up or down based on demand, without any additional configuration.
|
||||||
|
|
||||||
Fission operates on _just the code_: Docker and Kubernetes are
|
Fission operates on _just the code_: Docker and Kubernetes are
|
||||||
abstracted away under normal operation, though you can use both to
|
abstracted away under normal operation, though you can use both to
|
||||||
@@ -87,7 +91,7 @@ aggregation — also helps with ops on your Fission deployment.
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Add the stock NodeJS env to your Fission deployment
|
# Add the stock NodeJS env to your Fission deployment
|
||||||
$ fission env create --name nodejs --image fission/node-env
|
$ fission env create --name nodejs --image ghcr.io/fission/node-env
|
||||||
|
|
||||||
# Create a function with a javascript one-liner that prints "hello world"
|
# Create a function with a javascript one-liner that prints "hello world"
|
||||||
$ fission function create --name hello --env nodejs --code https://raw.githubusercontent.com/fission/examples/master/nodejs/hello.js
|
$ fission function create --name hello --env nodejs --code https://raw.githubusercontent.com/fission/examples/master/nodejs/hello.js
|
||||||
|
|||||||
+4
-4
@@ -6,12 +6,12 @@ Please refer using [latest stable release](https://github.com/fission/fission/re
|
|||||||
|
|
||||||
| Version | Supported |
|
| Version | Supported |
|
||||||
| ------- | ------------------ |
|
| ------- | ------------------ |
|
||||||
| >=1.14.x | :white_check_mark: |
|
| >=1.20.x | :white_check_mark: |
|
||||||
| < 1.14.0 | :x: |
|
| < 1.20.0 | :x: |
|
||||||
|
|
||||||
## Reporting a Vulnerability
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
Please send the details to both of us:
|
Please send the details to both of us:
|
||||||
|
|
||||||
- Sanket Sudake sanket@infracloud.io
|
- Sanket Sudake sanket[at]infracloud.io
|
||||||
- Vishal Biyani vishal@infracloud.io
|
- Vishal Biyani vishal[at]infracloud.io
|
||||||
|
|||||||
@@ -1,8 +1,9 @@
|
|||||||
apiVersion: v2
|
apiVersion: v2
|
||||||
name: fission-all
|
name: fission-all
|
||||||
version: v1.17.0
|
version: v1.21.0
|
||||||
appVersion: v1.17.0
|
appVersion: v1.21.0
|
||||||
description: Fission is a fast serverless framework for Kubernetes.
|
description: Fission is a fast serverless framework for Kubernetes.
|
||||||
|
kubeVersion: ">=1.27.0-0"
|
||||||
home: https://fission.io/
|
home: https://fission.io/
|
||||||
icon: https://fission.io/images/fission-logo-white.svg
|
icon: https://fission.io/images/fission-logo-white.svg
|
||||||
sources:
|
sources:
|
||||||
@@ -21,4 +22,8 @@ maintainers:
|
|||||||
- name: Sanket Sudake
|
- name: Sanket Sudake
|
||||||
email: sanket@infracloud.io
|
email: sanket@infracloud.io
|
||||||
engine: gotpl
|
engine: gotpl
|
||||||
type: application
|
type: application
|
||||||
|
annotations:
|
||||||
|
artifacthub.io/signKey: |
|
||||||
|
fingerprint: 2EAE29FDF8A387050C82CD5ABBDD4FD6A1FFCBF6
|
||||||
|
url: https://raw.githubusercontent.com/fission/fission-charts/main/public_key/pgp_keys.asc
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
|
|
||||||
## Prerequisites
|
## Prerequisites
|
||||||
|
|
||||||
- Kubernetes 1.19+
|
- Kubernetes 1.23+
|
||||||
- Helm 3+
|
- Helm 3+
|
||||||
|
|
||||||
## Get Repo Info
|
## Get Repo Info
|
||||||
@@ -93,6 +93,25 @@ _See [helm upgrade](https://helm.sh/docs/helm/helm_upgrade/) for command documen
|
|||||||
|
|
||||||
A major chart version change (like v1.2.3 -> v2.0.0) indicates that there is an incompatible breaking change needing manual actions.
|
A major chart version change (like v1.2.3 -> v2.0.0) indicates that there is an incompatible breaking change needing manual actions.
|
||||||
|
|
||||||
|
### Upgrade from 1.18.x to 1.20.x
|
||||||
|
|
||||||
|
We have removed controller service from fission-all chart.
|
||||||
|
|
||||||
|
### Upgrade from 1.17.x to 1.18.x
|
||||||
|
|
||||||
|
With 1.18.x, we have major change in the way we are deploying Fission.
|
||||||
|
We have added parameters `defaultNamespace`, `additionalFissionNamespaces`, `functionNamespace` and `builderNamespace` to manage the namespaces.
|
||||||
|
We watch and manage specific namespaces for Fission resources configured via `defaultNamespace` and `additionalFissionNamespaces` parameters.
|
||||||
|
You dont need to worry about `builderNamespace` and `functionNamespace` parameters, unless you want to consider legacy Fission resources.
|
||||||
|
|
||||||
|
Please refer to [core changes](https://fission.io/docs/releases/v1.18.0/#fission-core-changes) for more details.
|
||||||
|
|
||||||
|
### Upgrade from 1.16.x to 1.17.x
|
||||||
|
|
||||||
|
By default, Fission runs with the default security context. This means that it will be run as root. We have added settings in Helm chart for securityContext across all services in Fission. You can enable recommended securityContext settings during Fission installation.
|
||||||
|
|
||||||
|
Please refer to [security context settings](https://fission.io/docs/releases/v1.17.0/#security-context-setting-for-fission-installation) for more details.
|
||||||
|
|
||||||
### Upgrade from 1.15.x to 1.16.x
|
### Upgrade from 1.15.x to 1.16.x
|
||||||
|
|
||||||
If you have been using `prometheus.enabled=true` in your fission-all chart, you will need to deploy the prometheus using prometheus community supported chart.
|
If you have been using `prometheus.enabled=true` in your fission-all chart, you will need to deploy the prometheus using prometheus community supported chart.
|
||||||
|
|||||||
@@ -8,6 +8,4 @@ exclusions:
|
|||||||
target-instance-rule:
|
target-instance-rule:
|
||||||
reason: "Most panels dont need to be filtered by instance"
|
reason: "Most panels dont need to be filtered by instance"
|
||||||
panel-units-rule:
|
panel-units-rule:
|
||||||
reason: "Some panels are using the 'number' unit which throws a linting error."
|
reason: "Some panels are using the 'number' unit which throws a linting error."
|
||||||
target-counter-agg-rule:
|
|
||||||
reason: "disabled for fission_archives_total. This metric should be not have total due to naming conventions as its a gauge, not a counter"
|
|
||||||
@@ -879,7 +879,7 @@
|
|||||||
"uid": "${datasource}"
|
"uid": "${datasource}"
|
||||||
},
|
},
|
||||||
"editorMode": "code",
|
"editorMode": "code",
|
||||||
"expr": "fission_archives_total",
|
"expr": "fission_archives",
|
||||||
"legendFormat": "Namespace: {{namespace}} Pod: {{pod}}",
|
"legendFormat": "Namespace: {{namespace}} Pod: {{pod}}",
|
||||||
"range": true,
|
"range": true,
|
||||||
"refId": "A"
|
"refId": "A"
|
||||||
@@ -970,7 +970,7 @@
|
|||||||
"uid": "${datasource}"
|
"uid": "${datasource}"
|
||||||
},
|
},
|
||||||
"editorMode": "code",
|
"editorMode": "code",
|
||||||
"expr": "rate(fission_archives_total[$__rate_interval])",
|
"expr": "rate(fission_archives[$__rate_interval])",
|
||||||
"legendFormat": "Namespace: {{namespace}} Pod: {{pod}}",
|
"legendFormat": "Namespace: {{namespace}} Pod: {{pod}}",
|
||||||
"range": true,
|
"range": true,
|
||||||
"refId": "A"
|
"refId": "A"
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
{{ template "deprecationWarnings" . }}
|
||||||
|
|
||||||
1. Install the client CLI.
|
1. Install the client CLI.
|
||||||
|
|
||||||
Mac:
|
Mac:
|
||||||
@@ -11,14 +13,20 @@ Windows:
|
|||||||
|
|
||||||
2. You're ready to use Fission!
|
2. You're ready to use Fission!
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
You can create fission resources in the namespaces "{{ .Values.defaultNamespace }},{{ join "," .Values.additionalFissionNamespaces }}"
|
||||||
|
{{- else }}
|
||||||
|
You can create fission resources in the namespace "{{ .Values.defaultNamespace }}"
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
# Create an environment
|
# Create an environment
|
||||||
$ fission env create --name nodejs --image fission/node-env
|
$ fission env create --name nodejs --image ghcr.io/fission/node-env --namespace {{ .Values.defaultNamespace }}
|
||||||
|
|
||||||
# Get a hello world
|
# Get a hello world
|
||||||
$ curl https://raw.githubusercontent.com/fission/examples/master/nodejs/hello.js > hello.js
|
$ curl https://raw.githubusercontent.com/fission/examples/master/nodejs/hello.js > hello.js
|
||||||
|
|
||||||
# Register this function with Fission
|
# Register this function with Fission
|
||||||
$ fission function create --name hello --env nodejs --code hello.js
|
$ fission function create --name hello --env nodejs --code hello.js --namespace {{ .Values.defaultNamespace }}
|
||||||
|
|
||||||
{{- if .Values.authentication.enabled }}
|
{{- if .Values.authentication.enabled }}
|
||||||
|
|
||||||
@@ -29,6 +37,6 @@ Windows:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
# Run this function
|
# Run this function
|
||||||
$ fission function test --name hello
|
$ fission function test --name hello --namespace {{ .Values.defaultNamespace }}
|
||||||
Hello, world!
|
Hello, world!
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,43 @@
|
|||||||
|
|
||||||
|
|
||||||
|
{{- define "fision.selfSignedCABundleCertPEM" -}}
|
||||||
|
{{- $caKeypair := .selfSignedCAKeypair | default (genCA "fission-ca" 1825) -}}
|
||||||
|
{{- $_ := set . "selfSignedCAKeypair" $caKeypair -}}
|
||||||
|
{{- $caKeypair.Cert -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "webhook.caBundleCertPEM" -}}
|
||||||
|
{{- if .Values.webhook.caBundlePEM -}}
|
||||||
|
{{- trim .Values.webhook.caBundlePEM -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $caKeypair := .selfSignedCAKeypair | default (genCA "fission-ca" 1825) -}}
|
||||||
|
{{- $_ := set . "selfSignedCAKeypair" $caKeypair -}}
|
||||||
|
{{- $caKeypair.Cert -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "webhook.certPEM" -}}
|
||||||
|
{{- if .Values.webhook.crtPEM -}}
|
||||||
|
{{- trim .Values.webhook.crtPEM -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $webhookName := printf "%s.%s.svc" (include "fission-webhook.svc" .) .Release.Namespace }}
|
||||||
|
{{- $fullWebhookName := printf "%s.%s.svc.cluster.local" (include "fission-webhook.svc" .) .Release.Namespace -}}
|
||||||
|
{{- $webhookCA := required "self-signed CA keypair is requried" .selfSignedCAKeypair -}}
|
||||||
|
{{- $webhookServerTLSKeypair := .webhookTLSKeypair | default (genSignedCert $webhookName nil (list $webhookName $fullWebhookName) 1825 $webhookCA) }}
|
||||||
|
{{- $_ := set . "webhookTLSKeypair" $webhookServerTLSKeypair -}}
|
||||||
|
{{- $webhookServerTLSKeypair.Cert -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "webhook.keyPEM" -}}
|
||||||
|
{{- if .Values.webhook.keyPEM -}}
|
||||||
|
{{ trim .Values.webhook.keyPEM }}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $webhookName := printf "%s.%s.svc" (include "fission-webhook.svc" .) .Release.Namespace -}}
|
||||||
|
{{- $fullWebhookName := printf "%s.%s.svc.cluster.local" (include "fission-webhook.svc" .) .Release.Namespace -}}
|
||||||
|
{{- $webhookCA := required "self-signed CA keypair is requried" .selfSignedCAKeypair -}}
|
||||||
|
{{- $webhookServerTLSKeypair := .webhookTLSKeypair | default (genSignedCert $webhookName nil (list $webhookName $fullWebhookName) 1825 $webhookCA) -}}
|
||||||
|
{{- $_ := set . "webhookTLSKeypair" $webhookServerTLSKeypair -}}
|
||||||
|
{{- $webhookServerTLSKeypair.Key -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
{{- define "deprecationWarnings" -}}
|
||||||
|
{{- $deprecations := list -}}
|
||||||
|
|
||||||
|
{{- if .Values.builderNamespace -}}
|
||||||
|
{{- $deprecations = append $deprecations "The 'builderNamespace' parameter is deprecated and will be removed in future release." -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if .Values.functionNamespace -}}
|
||||||
|
{{- $deprecations = append $deprecations "The 'functionNamespace' parameter is deprecated and will be removed in future release." -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if .Values.disableOwnerReference -}}
|
||||||
|
{{- $deprecations = append $deprecations "The 'disableOwnerReference' flag is temporary addition and will be removed in future release." -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- if $deprecations -}}
|
||||||
|
{{- range $deprecations }}
|
||||||
|
{{- printf "WARNING: %s" . | nindent 0 }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,163 @@
|
|||||||
|
{{- define "buildermgr-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
{{- define "executor-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
{{- define "kubewatcher-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- kuberneteswatchtriggers
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
{{- define "kafka-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- messagequeuetriggers
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
{{- define "keda-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- messagequeuetriggers
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
{{- define "preupgrade-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- canaryconfigs
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- httptriggers
|
||||||
|
- kuberneteswatchtriggers
|
||||||
|
- messagequeuetriggers
|
||||||
|
- packages
|
||||||
|
- timetriggers
|
||||||
|
verbs:
|
||||||
|
- list
|
||||||
|
{{- end }}
|
||||||
|
{{- define "router-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- httptriggers
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
{{- define "storagesvc-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
{{- end }}
|
||||||
|
{{- define "timer-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
- functions
|
||||||
|
- packages
|
||||||
|
- timetriggers
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
{{- define "canaryconfig-rules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- canaryconfigs
|
||||||
|
- httptriggers
|
||||||
|
verbs:
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- get
|
||||||
|
- update
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,384 @@
|
|||||||
|
{{- define "buildermgr-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
verbs:
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
{{- end }}
|
||||||
|
{{- define "canaryconfig-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- services
|
||||||
|
verbs:
|
||||||
|
- list
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
{{- end }}
|
||||||
|
{{- define "executor-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- replicationcontrollers
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- events
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
{{- if .Values.executor.serviceAccountCheck.enabled }}
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- serviceaccounts
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- authorization.k8s.io
|
||||||
|
resources:
|
||||||
|
- localsubjectaccessreviews
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- rbac.authorization.k8s.io
|
||||||
|
resources:
|
||||||
|
- rolebindings
|
||||||
|
- roles
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
{{- end }}
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- deployments/scale
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- autoscaling
|
||||||
|
resources:
|
||||||
|
- horizontalpodautoscalers
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- metrics.k8s.io
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
{{- end }}
|
||||||
|
{{- define "fluentbit-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
{{- end }}
|
||||||
|
{{- define "kubewatcher-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- pods
|
||||||
|
- secrets
|
||||||
|
- services
|
||||||
|
- replicationcontrollers
|
||||||
|
- events
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- batch
|
||||||
|
resources:
|
||||||
|
- jobs
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
{{- end }}
|
||||||
|
{{- define "kafka-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- pods
|
||||||
|
- secrets
|
||||||
|
- services
|
||||||
|
- replicationcontrollers
|
||||||
|
- events
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- deployments/scale
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
{{- end }}
|
||||||
|
{{- define "keda-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
- services
|
||||||
|
- replicationcontrollers
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- events
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
- deployments/scale
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- keda.sh
|
||||||
|
resources:
|
||||||
|
- scaledjobs
|
||||||
|
- scaledobjects
|
||||||
|
- scaledjobs/finalizers
|
||||||
|
- scaledjobs/status
|
||||||
|
- triggerauthentications
|
||||||
|
- triggerauthentications/status
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- if .Values.mqt_keda.enabled }}
|
||||||
|
- apiGroups:
|
||||||
|
- keda.k8s.io
|
||||||
|
resources:
|
||||||
|
- scaledjobs
|
||||||
|
- scaledobjects
|
||||||
|
- scaledjobs/finalizers
|
||||||
|
- scaledjobs/status
|
||||||
|
- triggerauthentications
|
||||||
|
- triggerauthentications/status
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
{{- end }}
|
||||||
|
- apiGroups:
|
||||||
|
- metrics.k8s.io
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
{{- end }}
|
||||||
|
{{- define "preupgrade-kuberules" }}
|
||||||
|
# TODO: Kept for future in case preupgrade needs any permissions in the future
|
||||||
|
rules: []
|
||||||
|
{{- end }}
|
||||||
|
# TODO: Currently, router needs ingress related permissions only.
|
||||||
|
# In future if router's permissions are modified then check the configured namespace.
|
||||||
|
{{- define "router-kuberules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- networking.k8s.io
|
||||||
|
resources:
|
||||||
|
- ingresses
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
{{- end }}
|
||||||
|
{{- define "timer-kuberules" }}
|
||||||
|
rules: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
{{- define "kubernetes-role-generator" }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
{{- if eq "preupgrade" .component }}
|
||||||
|
annotations:
|
||||||
|
helm.sh/hook: pre-upgrade
|
||||||
|
helm.sh/hook-delete-policy: before-hook-creation
|
||||||
|
helm.sh/hook-weight: "-2"
|
||||||
|
{{- end }}
|
||||||
|
name: "{{ .Release.Name }}-{{ .component }}"
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
{{- if eq "buildermgr" .component }}
|
||||||
|
{{- include "buildermgr-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "canaryconfig" .component }}
|
||||||
|
{{- include "canaryconfig-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "fluentbit" .component }}
|
||||||
|
{{- include "fluentbit-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "executor" .component }}
|
||||||
|
{{- include "executor-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "kubewatcher" .component }}
|
||||||
|
{{- include "kubewatcher-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "kafka" .component }}
|
||||||
|
{{- include "kafka-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "keda" .component }}
|
||||||
|
{{- include "keda-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "preupgrade" .component }}
|
||||||
|
{{- include "preupgrade-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "router" .component }}
|
||||||
|
{{- include "router-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "timer" .component }}
|
||||||
|
{{- include "timer-kuberules" . }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
---
|
||||||
|
kind: RoleBinding
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
metadata:
|
||||||
|
{{- if eq "preupgrade" .component }}
|
||||||
|
annotations:
|
||||||
|
helm.sh/hook: pre-upgrade
|
||||||
|
helm.sh/hook-delete-policy: before-hook-creation
|
||||||
|
{{- end }}
|
||||||
|
name: "{{ .Release.Name }}-{{ .component }}"
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: "fission-{{ .component }}"
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
roleRef:
|
||||||
|
kind: Role
|
||||||
|
name: "{{ .Release.Name }}-{{ .component }}"
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
{{- define "fission-role-generator" }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
{{- if eq "preupgrade" .component }}
|
||||||
|
annotations:
|
||||||
|
helm.sh/hook: pre-upgrade
|
||||||
|
helm.sh/hook-delete-policy: before-hook-creation
|
||||||
|
helm.sh/hook-weight: "-2"
|
||||||
|
{{- end }}
|
||||||
|
name: "{{ .Release.Name }}-{{ .component }}-fission-cr"
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
{{- if eq "buildermgr" .component }}
|
||||||
|
{{- include "buildermgr-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "executor" .component }}
|
||||||
|
{{- include "executor-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "kubewatcher" .component }}
|
||||||
|
{{- include "kubewatcher-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "kafka" .component }}
|
||||||
|
{{- include "kafka-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "keda" .component }}
|
||||||
|
{{- include "keda-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "preupgrade" .component }}
|
||||||
|
{{- include "preupgrade-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "router" .component }}
|
||||||
|
{{- include "router-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "storagesvc" .component }}
|
||||||
|
{{- include "storagesvc-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "timer" .component }}
|
||||||
|
{{- include "timer-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if eq "canaryconfig" .component }}
|
||||||
|
{{- include "canaryconfig-rules" . }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
---
|
||||||
|
kind: RoleBinding
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
metadata:
|
||||||
|
{{- if eq "preupgrade" .component }}
|
||||||
|
annotations:
|
||||||
|
helm.sh/hook: pre-upgrade
|
||||||
|
helm.sh/hook-delete-policy: before-hook-creation
|
||||||
|
{{- end }}
|
||||||
|
name: "{{ .Release.Name }}-{{ .component }}-fission-cr"
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: "fission-{{ .component }}"
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
roleRef:
|
||||||
|
kind: Role
|
||||||
|
name: "{{ .Release.Name }}-{{ .component }}-fission-cr"
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,123 @@
|
|||||||
|
{{- define "fissionFunction.roles" }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ .Release.Name }}-fission-fetcher
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ .Release.Name }}-fission-builder
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
resources:
|
||||||
|
- packages
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
name: {{ .Release.Name }}-fission-fetcher-websocket
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- "events"
|
||||||
|
verbs:
|
||||||
|
- "get"
|
||||||
|
- "list"
|
||||||
|
- "watch"
|
||||||
|
- "create"
|
||||||
|
- "update"
|
||||||
|
- "patch"
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "fissionFunction.rolebindings" }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ .Release.Name }}-fission-fetcher
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ .Release.Name }}-fission-fetcher
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: fission-fetcher
|
||||||
|
{{- if and (.Values.functionNamespace) (eq .namespace "default") }}
|
||||||
|
namespace: {{ .Values.functionNamespace }}
|
||||||
|
{{- else }}
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ .Release.Name }}-fission-builder
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ .Release.Name }}-fission-builder
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: fission-builder
|
||||||
|
{{- if and (.Values.builderNamespace) (eq .namespace "default") }}
|
||||||
|
namespace: {{ .Values.builderNamespace }}
|
||||||
|
{{- else }}
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ .Release.Name }}-fission-fetcher-websocket
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ .Release.Name }}-fission-fetcher-websocket
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: fission-fetcher
|
||||||
|
{{- if and (.Values.functionNamespace) (eq .namespace "default") }}
|
||||||
|
namespace: {{ .Values.functionNamespace }}
|
||||||
|
{{- else }}
|
||||||
|
namespace: {{ .namespace }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
@@ -37,22 +37,37 @@ auth:
|
|||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|
||||||
{{/*
|
{{/*
|
||||||
This template generates the image name for the deployment depending on the value of "repository" field in values.yaml file.
|
Helper template to construct image names with repository and tag
|
||||||
*/}}
|
*/}}
|
||||||
{{- define "fission-bundleImage" -}}
|
{{- define "imageWithTag" -}}
|
||||||
{{- if .Values.repository -}}
|
{{- $repository := index . 0 -}}
|
||||||
{{- if eq .Values.imageTag "" -}}
|
{{- $image := index . 1 -}}
|
||||||
{{ .Values.repository }}/{{ .Values.image }}
|
{{- $tag := index . 2 -}}
|
||||||
{{- else -}}
|
{{- if $repository -}}
|
||||||
{{ .Values.repository }}/{{ .Values.image }}:{{ .Values.imageTag }}
|
{{- printf "%s/%s%s" $repository $image (ne $tag "" | ternary (printf ":%s" $tag) "") -}}
|
||||||
{{- end }}
|
|
||||||
{{- else -}}
|
{{- else -}}
|
||||||
{{- if eq .Values.imageTag "" -}}
|
{{- printf "%s%s" $image (ne $tag "" | ternary (printf ":%s" $tag) "") -}}
|
||||||
{{ .Values.image }}
|
{{- end -}}
|
||||||
{{- else -}}
|
{{- end -}}
|
||||||
{{ .Values.image }}:{{ .Values.imageTag }}
|
|
||||||
{{- end }}
|
{{- define "fission-bundleImage" -}}
|
||||||
{{- end }}
|
{{- $args := list .Values.repository .Values.image .Values.imageTag -}}
|
||||||
|
{{- include "imageWithTag" $args -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "reporterImage" -}}
|
||||||
|
{{- $args := list .Values.repository .Values.postInstallReportImage .Values.imageTag -}}
|
||||||
|
{{- include "imageWithTag" $args -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "fetcherImage" -}}
|
||||||
|
{{- $args := list (.Values.fetcher.repository | default .Values.repository) .Values.fetcher.image .Values.fetcher.imageTag -}}
|
||||||
|
{{- include "imageWithTag" $args -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "preUpgradeChecksImage" -}}
|
||||||
|
{{- $args := list (.Values.preUpgradeChecks.repository | default .Values.repository) .Values.preUpgradeChecks.image .Values.preUpgradeChecks.imageTag -}}
|
||||||
|
{{- include "imageWithTag" $args -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|
||||||
{{- define "opentelemtry.envs" }}
|
{{- define "opentelemtry.envs" }}
|
||||||
@@ -71,3 +86,48 @@ This template generates the image name for the deployment depending on the value
|
|||||||
- name: OTEL_PROPAGATORS
|
- name: OTEL_PROPAGATORS
|
||||||
value: "{{ .Values.openTelemetry.propagators }}"
|
value: "{{ .Values.openTelemetry.propagators }}"
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "fission-resource-namespace.envs" }}
|
||||||
|
- name: FISSION_BUILDER_NAMESPACE
|
||||||
|
value: "{{ .Values.builderNamespace }}"
|
||||||
|
- name: FISSION_FUNCTION_NAMESPACE
|
||||||
|
value: "{{ .Values.functionNamespace }}"
|
||||||
|
- name: FISSION_DEFAULT_NAMESPACE
|
||||||
|
value: "{{ .Values.defaultNamespace }}"
|
||||||
|
- name: FISSION_RESOURCE_NAMESPACES
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
value: "{{ .Values.defaultNamespace }},{{ join "," .Values.additionalFissionNamespaces }}"
|
||||||
|
{{- else }}
|
||||||
|
value: {{ .Values.defaultNamespace }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "kube_client.envs" }}
|
||||||
|
- name: KUBE_CLIENT_QPS
|
||||||
|
value: "{{ .Values.kubernetesClientQPS }}"
|
||||||
|
- name: KUBE_CLIENT_BURST
|
||||||
|
value: "{{ .Values.kubernetesClientBurst }}"
|
||||||
|
{{- end}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Define the svc's name
|
||||||
|
*/}}
|
||||||
|
{{- define "fission-webhook.svc" -}}
|
||||||
|
{{- printf "webhook-service" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "fission-function-ns" -}}
|
||||||
|
{{- if .Values.functionNamespace -}}
|
||||||
|
{{- printf "%s" .Values.functionNamespace -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s" .Values.defaultNamespace -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "fission-builder-ns" -}}
|
||||||
|
{{- if .Values.builderNamespace -}}
|
||||||
|
{{- printf "%s" .Values.builderNamespace -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s" .Values.defaultNamespace -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|||||||
@@ -26,16 +26,15 @@ spec:
|
|||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
containers:
|
containers:
|
||||||
- name: post-install-job
|
- name: post-install-job
|
||||||
{{- if .Values.imageTag }}
|
image: {{ include "reporterImage" . | quote }}
|
||||||
image: {{ .Values.postInstallReportImage }}:{{ .Values.imageTag }}
|
|
||||||
{{- else }}
|
|
||||||
image: {{ .Values.postInstallReportImage }}
|
|
||||||
{{- end }}
|
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: [ "/reporter" ]
|
command: [ "/reporter" ]
|
||||||
args: ["event", "-c", "fission-use", "-a", "yaml-post-install", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
args: ["event", "-c", "fission-use", "-a", "yaml-post-install", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
||||||
env:
|
env:
|
||||||
- name: GA_TRACKING_ID
|
- name: GA_TRACKING_ID
|
||||||
value: "{{ .Values.gaTrackingID }}"
|
value: "{{ .Values.gaTrackingID }}"
|
||||||
serviceAccountName: fission-svc
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
apiVersion: batch/v1
|
apiVersion: batch/v1
|
||||||
kind: Job
|
kind: Job
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ template "fullname" . }}-{{ .Chart.Version }}
|
name: {{ template "fullname" . }}-{{ .Chart.Version }}-post-install
|
||||||
labels:
|
labels:
|
||||||
# The "release" convention makes it easy to tie a release to all of the
|
# The "release" convention makes it easy to tie a release to all of the
|
||||||
# Kubernetes resources that were created as part of that release.
|
# Kubernetes resources that were created as part of that release.
|
||||||
@@ -30,11 +30,7 @@ spec:
|
|||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
containers:
|
containers:
|
||||||
- name: post-install-job
|
- name: post-install-job
|
||||||
{{- if .Values.imageTag }}
|
image: {{ include "reporterImage" . | quote }}
|
||||||
image: {{ .Values.postInstallReportImage }}:{{ .Values.imageTag }}
|
|
||||||
{{- else }}
|
|
||||||
image: {{ .Values.postInstallReportImage }}
|
|
||||||
{{- end }}
|
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: [ "/reporter" ]
|
command: [ "/reporter" ]
|
||||||
args: ["event", "-c", "fission-use", "-a", "helm-post-install", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
args: ["event", "-c", "fission-use", "-a", "helm-post-install", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
||||||
@@ -47,5 +43,8 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
apiVersion: batch/v1
|
apiVersion: batch/v1
|
||||||
kind: Job
|
kind: Job
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ template "fullname" . }}-{{ .Chart.Version }}
|
name: {{ template "fullname" . }}-{{ .Chart.Version }}-post-upgrade
|
||||||
labels:
|
labels:
|
||||||
# The "release" convention makes it easy to tie a release to all of the
|
# The "release" convention makes it easy to tie a release to all of the
|
||||||
# Kubernetes resources that were created as part of that release.
|
# Kubernetes resources that were created as part of that release.
|
||||||
@@ -30,11 +30,7 @@ spec:
|
|||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
containers:
|
containers:
|
||||||
- name: post-upgrade-job
|
- name: post-upgrade-job
|
||||||
{{- if .Values.imageTag }}
|
image: {{ include "reporterImage" . | quote }}
|
||||||
image: {{ .Values.postInstallReportImage }}:{{ .Values.imageTag }}
|
|
||||||
{{- else }}
|
|
||||||
image: {{ .Values.postInstallReportImage }}
|
|
||||||
{{- end }}
|
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: [ "/reporter" ]
|
command: [ "/reporter" ]
|
||||||
args: ["event", "-c", "fission-use", "-a", "helm-post-upgrade", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
args: ["event", "-c", "fission-use", "-a", "helm-post-upgrade", "-l", "{{ .Chart.Name }}-{{ .Chart.Version }}"]
|
||||||
@@ -47,5 +43,8 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -4,6 +4,6 @@ kind: ConfigMap
|
|||||||
metadata:
|
metadata:
|
||||||
name: builder-podspec-patch
|
name: builder-podspec-patch
|
||||||
data:
|
data:
|
||||||
spec: |
|
builder-podspec-patch.yaml: |
|
||||||
{{- toYaml .Values.builderPodSpec.podSpec | nindent 4 }}
|
{{- toYaml .Values.builderPodSpec.podSpec | nindent 4 }}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
@@ -27,14 +27,10 @@ spec:
|
|||||||
image: {{ include "fission-bundleImage" . | quote }}
|
image: {{ include "fission-bundleImage" . | quote }}
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--builderMgr", "--storageSvcUrl", "http://storagesvc.{{ .Release.Namespace }}", "--envbuilder-namespace", "{{ .Values.builderNamespace }}"]
|
args: ["--builderMgr", "--storageSvcUrl", "http://storagesvc.{{ .Release.Namespace }}"]
|
||||||
env:
|
env:
|
||||||
- name: FETCHER_IMAGE
|
- name: FETCHER_IMAGE
|
||||||
{{- if eq .Values.fetcher.imageTag "" }}
|
value: {{ include "fetcherImage" . | quote }}
|
||||||
value: "{{ .Values.fetcher.image }}"
|
|
||||||
{{- else }}
|
|
||||||
value: "{{ .Values.fetcher.image }}:{{ .Values.fetcher.imageTag }}"
|
|
||||||
{{- end }}
|
|
||||||
- name: FETCHER_IMAGE_PULL_POLICY
|
- name: FETCHER_IMAGE_PULL_POLICY
|
||||||
value: "{{ .Values.pullPolicy }}"
|
value: "{{ .Values.pullPolicy }}"
|
||||||
- name: BUILDER_IMAGE_PULL_POLICY
|
- name: BUILDER_IMAGE_PULL_POLICY
|
||||||
@@ -51,11 +47,22 @@ spec:
|
|||||||
value: {{ .Values.fetcher.resource.mem.limits | quote }}
|
value: {{ .Values.fetcher.resource.mem.limits | quote }}
|
||||||
- name: DEBUG_ENV
|
- name: DEBUG_ENV
|
||||||
value: {{ .Values.debugEnv | quote }}
|
value: {{ .Values.debugEnv | quote }}
|
||||||
|
- name: DISABLE_OWNER_REFERENCES
|
||||||
|
value: {{ .Values.disableOwnerReference | quote }}
|
||||||
- name: PPROF_ENABLED
|
- name: PPROF_ENABLED
|
||||||
value: {{ .Values.pprof.enabled | quote }}
|
value: {{ .Values.pprof.enabled | quote }}
|
||||||
- name: HELM_RELEASE_NAME
|
- name: HELM_RELEASE_NAME
|
||||||
value: {{ .Release.Name | quote }}
|
value: {{ .Release.Name | quote }}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
|
{{- if .Values.builderPodSpec.enabled }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: builder-podspec-patch-volume
|
||||||
|
mountPath: /etc/fission/builder-podspec-patch.yaml
|
||||||
|
subPath: builder-podspec-patch.yaml
|
||||||
|
readOnly: true
|
||||||
|
{{- end }}
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
name: metrics
|
name: metrics
|
||||||
@@ -67,12 +74,18 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-buildermgr
|
||||||
|
{{- if .Values.builderPodSpec.enabled }}
|
||||||
|
volumes:
|
||||||
|
- name: builder-podspec-patch-volume
|
||||||
|
configMap:
|
||||||
|
name: builder-podspec-patch
|
||||||
|
{{- end }}
|
||||||
{{- if .Values.priorityClassName }}
|
{{- if .Values.priorityClassName }}
|
||||||
priorityClassName: {{ .Values.priorityClassName }}
|
priorityClassName: {{ .Values.priorityClassName }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- with .Values.imagePullSecrets }}
|
{{- with .Values.imagePullSecrets }}
|
||||||
imagePullSecrets:
|
imagePullSecrets:
|
||||||
{{- toYaml . | nindent 8 }}
|
{{- toYaml . | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if .Values.extraCoreComponentPodConfig }}
|
{{- if .Values.extraCoreComponentPodConfig }}
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "buildermgr") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "buildermgr") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.builderNamespace -}}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "buildermgr") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.functionNamespace -}}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "buildermgr") $) }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "buildermgr") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "buildermgr") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.builderNamespace -}}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "buildermgr") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.functionNamespace -}}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "buildermgr") $) }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-buildermgr
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
+18
-31
@@ -1,69 +1,57 @@
|
|||||||
|
{{- if .Values.canaryDeployment.enabled }}
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
name: controller
|
name: canaryconfig
|
||||||
labels:
|
labels:
|
||||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||||
svc: controller
|
svc: canaryconfig
|
||||||
application: fission-api
|
application: fission-canaryconfig
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
replicas: 1
|
||||||
selector:
|
selector:
|
||||||
matchLabels:
|
matchLabels:
|
||||||
svc: controller
|
svc: canaryconfig
|
||||||
application: fission-api
|
application: fission-canaryconfig
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
svc: controller
|
svc: canaryconfig
|
||||||
application: fission-api
|
application: fission-canaryconfig
|
||||||
annotations:
|
annotations:
|
||||||
prometheus.io/scrape: "true"
|
prometheus.io/scrape: "true"
|
||||||
prometheus.io/path: "/metrics"
|
prometheus.io/path: "/metrics"
|
||||||
prometheus.io/port: "8080"
|
prometheus.io/port: "8080"
|
||||||
spec:
|
spec:
|
||||||
{{- if .Values.controller.securityContext.enabled }}
|
{{- if .Values.canaryDeployment.securityContext.enabled }}
|
||||||
securityContext: {{- omit .Values.controller.securityContext "enabled" | toYaml | nindent 8 }}
|
securityContext: {{- omit .Values.canaryDeployment.securityContext "enabled" | toYaml | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
containers:
|
containers:
|
||||||
- name: controller
|
- name: canaryconfig
|
||||||
image: {{ include "fission-bundleImage" . | quote }}
|
image: {{ include "fission-bundleImage" . | quote }}
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--controllerPort", "8888"]
|
args: ["--canaryConfig"]
|
||||||
env:
|
env:
|
||||||
- name: FISSION_FUNCTION_NAMESPACE
|
|
||||||
value: "{{ .Values.functionNamespace }}"
|
|
||||||
- name: DEBUG_ENV
|
- name: DEBUG_ENV
|
||||||
value: {{ .Values.debugEnv | quote }}
|
value: {{ .Values.debugEnv | quote }}
|
||||||
- name: PPROF_ENABLED
|
- name: PPROF_ENABLED
|
||||||
value: {{ .Values.pprof.enabled | quote }}
|
value: {{ .Values.pprof.enabled | quote }}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
- name: POD_NAMESPACE
|
- name: POD_NAMESPACE
|
||||||
valueFrom:
|
valueFrom:
|
||||||
fieldRef:
|
fieldRef:
|
||||||
fieldPath: metadata.namespace
|
fieldPath: metadata.namespace
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.controller.resources | nindent 10 }}
|
{{- toYaml .Values.canaryDeployment.resources | nindent 10 }}
|
||||||
{{- if .Values.terminationMessagePath }}
|
{{- if .Values.terminationMessagePath }}
|
||||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: "/healthz"
|
|
||||||
port: 8888
|
|
||||||
initialDelaySeconds: 1
|
|
||||||
periodSeconds: 1
|
|
||||||
failureThreshold: 30
|
|
||||||
livenessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: "/healthz"
|
|
||||||
port: 8888
|
|
||||||
initialDelaySeconds: 35
|
|
||||||
periodSeconds: 5
|
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: config-volume
|
- name: config-volume
|
||||||
mountPath: /etc/config/config.yaml
|
mountPath: /etc/config/config.yaml
|
||||||
@@ -71,14 +59,12 @@ spec:
|
|||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
name: metrics
|
name: metrics
|
||||||
- containerPort: 8888
|
|
||||||
name: http
|
|
||||||
{{- if .Values.pprof.enabled }}
|
{{- if .Values.pprof.enabled }}
|
||||||
- containerPort: 6060
|
- containerPort: 6060
|
||||||
name: pprof
|
name: pprof
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-canaryconfig
|
||||||
volumes:
|
volumes:
|
||||||
- name: config-volume
|
- name: config-volume
|
||||||
configMap:
|
configMap:
|
||||||
@@ -92,4 +78,5 @@ spec:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if .Values.extraCoreComponentPodConfig }}
|
{{- if .Values.extraCoreComponentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{{- if .Values.canaryDeployment.enabled }}
|
||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "canaryconfig") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "canaryconfig") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{{- if .Values.canaryDeployment.enabled }}
|
||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "canaryconfig") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "canaryconfig") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- if .Values.canaryDeployment.enabled }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-canaryconfig
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
{{- if .Values.canaryDeployment.enabled }}
|
||||||
|
{{- if .Values.serviceMonitor.enabled }}
|
||||||
|
apiVersion: monitoring.coreos.com/v1
|
||||||
|
kind: ServiceMonitor
|
||||||
|
metadata:
|
||||||
|
name: canaryconfig-monitor
|
||||||
|
{{- if .Values.serviceMonitor.namespace }}
|
||||||
|
namespace: {{ .Values.serviceMonitor.namespace }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.serviceMonitor.additionalServiceMonitorLabels }}
|
||||||
|
labels:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
namespaceSelector:
|
||||||
|
matchNames:
|
||||||
|
- {{ .Release.Namespace }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
svc: canaryconfig
|
||||||
|
endpoints:
|
||||||
|
- targetPort: 8080
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
@@ -1,115 +0,0 @@
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ .Release.Name }}-fission-cr-admin
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
- pods
|
|
||||||
- secrets
|
|
||||||
- services
|
|
||||||
- serviceaccounts
|
|
||||||
- replicationcontrollers
|
|
||||||
- namespaces
|
|
||||||
- events
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- patch
|
|
||||||
- apiGroups:
|
|
||||||
- apps
|
|
||||||
resources:
|
|
||||||
- deployments
|
|
||||||
- deployments/scale
|
|
||||||
- replicasets
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- batch
|
|
||||||
resources:
|
|
||||||
- jobs
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- networking.k8s.io
|
|
||||||
resources:
|
|
||||||
- ingresses
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- apiextensions.k8s.io
|
|
||||||
resources:
|
|
||||||
- customresourcedefinitions
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- fission.io
|
|
||||||
resources:
|
|
||||||
- canaryconfigs
|
|
||||||
- environments
|
|
||||||
- functions
|
|
||||||
- httptriggers
|
|
||||||
- kuberneteswatchtriggers
|
|
||||||
- messagequeuetriggers
|
|
||||||
- packages
|
|
||||||
- timetriggers
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- autoscaling
|
|
||||||
resources:
|
|
||||||
- horizontalpodautoscalers
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- rbac.authorization.k8s.io
|
|
||||||
resources:
|
|
||||||
- rolebindings
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
- apiGroups:
|
|
||||||
- rbac.authorization.k8s.io
|
|
||||||
resources:
|
|
||||||
- clusterroles
|
|
||||||
verbs:
|
|
||||||
- bind
|
|
||||||
- apiGroups:
|
|
||||||
- keda.sh
|
|
||||||
resources:
|
|
||||||
- scaledjobs
|
|
||||||
- scaledobjects
|
|
||||||
- scaledjobs/finalizers
|
|
||||||
- scaledjobs/status
|
|
||||||
- triggerauthentications
|
|
||||||
- triggerauthentications/status
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
{{- if .Values.mqt_keda.enabled }}
|
|
||||||
- apiGroups:
|
|
||||||
- keda.k8s.io
|
|
||||||
resources:
|
|
||||||
- scaledjobs
|
|
||||||
- scaledobjects
|
|
||||||
- scaledjobs/finalizers
|
|
||||||
- scaledjobs/status
|
|
||||||
- triggerauthentications
|
|
||||||
- triggerauthentications/status
|
|
||||||
verbs:
|
|
||||||
- '*'
|
|
||||||
{{- end }}
|
|
||||||
- apiGroups:
|
|
||||||
- metrics.k8s.io
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: controller
|
|
||||||
labels:
|
|
||||||
svc: controller
|
|
||||||
application: fission-api
|
|
||||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.serviceType }}
|
|
||||||
ports:
|
|
||||||
- port: 80
|
|
||||||
targetPort: 8888
|
|
||||||
{{- if eq .Values.serviceType "NodePort" }}
|
|
||||||
nodePort: {{ .Values.controllerPort }}
|
|
||||||
{{- end }}
|
|
||||||
selector:
|
|
||||||
svc: controller
|
|
||||||
@@ -4,6 +4,6 @@ kind: ConfigMap
|
|||||||
metadata:
|
metadata:
|
||||||
name: runtime-podspec-patch
|
name: runtime-podspec-patch
|
||||||
data:
|
data:
|
||||||
spec: |
|
runtime-podspec-patch.yaml: |
|
||||||
{{- toYaml .Values.runtimePodSpec.podSpec | nindent 4 }}
|
{{- toYaml .Values.runtimePodSpec.podSpec | nindent 4 }}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
@@ -27,14 +27,10 @@ spec:
|
|||||||
image: {{ include "fission-bundleImage" . | quote }}
|
image: {{ include "fission-bundleImage" . | quote }}
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--executorPort", "8888", "--namespace", "{{ .Values.functionNamespace }}"]
|
args: ["--executorPort", "8888"]
|
||||||
env:
|
env:
|
||||||
- name: FETCHER_IMAGE
|
- name: FETCHER_IMAGE
|
||||||
{{- if eq .Values.fetcher.imageTag "" }}
|
value: {{ include "fetcherImage" . | quote }}
|
||||||
value: "{{ .Values.fetcher.image }}"
|
|
||||||
{{- else }}
|
|
||||||
value: "{{ .Values.fetcher.image }}:{{ .Values.fetcher.imageTag }}"
|
|
||||||
{{- end }}
|
|
||||||
- name: FETCHER_IMAGE_PULL_POLICY
|
- name: FETCHER_IMAGE_PULL_POLICY
|
||||||
value: "{{ .Values.pullPolicy }}"
|
value: "{{ .Values.pullPolicy }}"
|
||||||
- name: RUNTIME_IMAGE_PULL_POLICY
|
- name: RUNTIME_IMAGE_PULL_POLICY
|
||||||
@@ -57,6 +53,30 @@ spec:
|
|||||||
value: {{ .Values.debugEnv | quote }}
|
value: {{ .Values.debugEnv | quote }}
|
||||||
- name: PPROF_ENABLED
|
- name: PPROF_ENABLED
|
||||||
value: {{ .Values.pprof.enabled | quote }}
|
value: {{ .Values.pprof.enabled | quote }}
|
||||||
|
- name: OBJECT_REAPER_INTERVAL
|
||||||
|
value: {{ .Values.executor.objectReaperInterval | quote }}
|
||||||
|
{{- if .Values.executor.poolmgr.objectReaperInterval }}
|
||||||
|
- name: POOLMGR_OBJECT_REAPER_INTERVAL
|
||||||
|
value: {{ .Values.executor.poolmgr.objectReaperInterval | quote }}
|
||||||
|
{{- end}}
|
||||||
|
{{- if .Values.executor.newdeploy.objectReaperInterval }}
|
||||||
|
- name: NEWDEPLOY_OBJECT_REAPER_INTERVAL
|
||||||
|
value: {{ .Values.executor.newdeploy.objectReaperInterval | quote }}
|
||||||
|
{{- end}}
|
||||||
|
{{- if .Values.executor.container.objectReaperInterval }}
|
||||||
|
- name: CONTAINER_OBJECT_REAPER_INTERVAL
|
||||||
|
value: {{ .Values.executor.container.objectReaperInterval | quote }}
|
||||||
|
{{- end}}
|
||||||
|
{{- if .Values.executor.serviceAccountCheck.enabled }}
|
||||||
|
- name: SERVICEACCOUNT_CHECK_ENABLED
|
||||||
|
value: {{ .Values.executor.serviceAccountCheck.enabled | quote }}
|
||||||
|
- name: SERVICEACCOUNT_CHECK_INTERVAL
|
||||||
|
value: {{ .Values.executor.serviceAccountCheck.interval | quote }}
|
||||||
|
- name: DISABLE_OWNER_REFERENCES
|
||||||
|
value: {{ .Values.disableOwnerReference | quote }}
|
||||||
|
{{- end}}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
- name: HELM_RELEASE_NAME
|
- name: HELM_RELEASE_NAME
|
||||||
value: {{ .Release.Name | quote }}
|
value: {{ .Release.Name | quote }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
@@ -75,6 +95,13 @@ spec:
|
|||||||
port: 8888
|
port: 8888
|
||||||
initialDelaySeconds: 35
|
initialDelaySeconds: 35
|
||||||
periodSeconds: 5
|
periodSeconds: 5
|
||||||
|
{{- if .Values.runtimePodSpec.enabled }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: runtime-podspec-patch-volume
|
||||||
|
mountPath: /etc/fission/runtime-podspec-patch.yaml
|
||||||
|
subPath: runtime-podspec-patch.yaml
|
||||||
|
readOnly: true
|
||||||
|
{{- end }}
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
name: metrics
|
name: metrics
|
||||||
@@ -94,14 +121,20 @@ spec:
|
|||||||
{{- else if .Values.terminationMessagePolicy }}
|
{{- else if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-executor
|
||||||
|
{{- if .Values.runtimePodSpec.enabled }}
|
||||||
|
volumes:
|
||||||
|
- name: runtime-podspec-patch-volume
|
||||||
|
configMap:
|
||||||
|
name: runtime-podspec-patch
|
||||||
|
{{- end }}
|
||||||
{{- if .Values.executor.priorityClassName }}
|
{{- if .Values.executor.priorityClassName }}
|
||||||
priorityClassName: {{ .Values.executor.priorityClassName }}
|
priorityClassName: {{ .Values.executor.priorityClassName }}
|
||||||
{{- else if .Values.priorityClassName }}
|
{{- else if .Values.priorityClassName }}
|
||||||
priorityClassName: {{ .Values.priorityClassName }}
|
priorityClassName: {{ .Values.priorityClassName }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- with .Values.imagePullSecrets }}
|
{{- with .Values.imagePullSecrets }}
|
||||||
imagePullSecrets:
|
imagePullSecrets:
|
||||||
{{- toYaml . | nindent 8 }}
|
{{- toYaml . | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if .Values.extraCoreComponentPodConfig }}
|
{{- if .Values.extraCoreComponentPodConfig }}
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "executor") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "executor") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.builderNamespace -}}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "executor") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.functionNamespace -}}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "executor") $) }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "executor") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "executor") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.builderNamespace -}}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.builderNamespace "component" "executor") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.functionNamespace -}}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" .Values.functionNamespace "component" "executor") $) }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-executor
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -118,6 +118,7 @@ spec:
|
|||||||
fieldRef:
|
fieldRef:
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
fieldPath: spec.nodeName
|
fieldPath: spec.nodeName
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 12 }}
|
||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--logger"]
|
args: ["--logger"]
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
@@ -127,10 +128,8 @@ spec:
|
|||||||
- name: docker-log
|
- name: docker-log
|
||||||
mountPath: /var/lib/docker/containers
|
mountPath: /var/lib/docker/containers
|
||||||
readOnly: true
|
readOnly: true
|
||||||
{{- if .Values.logger.enableSecurityContext }}
|
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
{{- toYaml .Values.logger.securityContext | nindent 12 }}
|
||||||
{{- end }}
|
|
||||||
- name: fluentbit
|
- name: fluentbit
|
||||||
{{- if .Values.repository }}
|
{{- if .Values.repository }}
|
||||||
image: "{{ .Values.logger.fluentdImageRepository }}/{{ .Values.logger.fluentdImage }}:{{ .Values.logger.fluentdImageTag }}"
|
image: "{{ .Values.logger.fluentdImageRepository }}/{{ .Values.logger.fluentdImage }}:{{ .Values.logger.fluentdImageTag }}"
|
||||||
@@ -173,7 +172,7 @@ spec:
|
|||||||
- name: fluentbit-config
|
- name: fluentbit-config
|
||||||
mountPath: /fluent-bit/etc/
|
mountPath: /fluent-bit/etc/
|
||||||
readOnly: true
|
readOnly: true
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-fluentbit
|
||||||
volumes:
|
volumes:
|
||||||
- name: container-log
|
- name: container-log
|
||||||
hostPath:
|
hostPath:
|
||||||
@@ -185,6 +184,10 @@ spec:
|
|||||||
- name: fluentbit-config
|
- name: fluentbit-config
|
||||||
configMap:
|
configMap:
|
||||||
name: {{ .Release.Name }}-fission-fluentbit
|
name: {{ .Release.Name }}-fission-fluentbit
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
updateStrategy:
|
updateStrategy:
|
||||||
type: RollingUpdate
|
type: RollingUpdate
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "fluentbit") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "fluentbit") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-fluentbit
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -49,6 +49,10 @@ spec:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: influxdb
|
name: influxdb
|
||||||
key: password
|
key: password
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
{{- if .Values.extraCoreComponentPodConfig }}
|
{{- if .Values.extraCoreComponentPodConfig }}
|
||||||
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -29,6 +29,8 @@ spec:
|
|||||||
value: {{ .Values.debugEnv | quote }}
|
value: {{ .Values.debugEnv | quote }}
|
||||||
- name: PPROF_ENABLED
|
- name: PPROF_ENABLED
|
||||||
value: {{ .Values.pprof.enabled | quote }}
|
value: {{ .Values.pprof.enabled | quote }}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.kubewatcher.resources | nindent 10 }}
|
{{- toYaml .Values.kubewatcher.resources | nindent 10 }}
|
||||||
@@ -38,7 +40,7 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-kubewatcher
|
||||||
{{- if .Values.priorityClassName }}
|
{{- if .Values.priorityClassName }}
|
||||||
priorityClassName: {{ .Values.priorityClassName }}
|
priorityClassName: {{ .Values.priorityClassName }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "kubewatcher") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "kubewatcher") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "kubewatcher") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "kubewatcher") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-kubewatcher
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ .Release.Name }}-secret-configmap-getter
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- "*"
|
|
||||||
resources:
|
|
||||||
- secrets
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- watch
|
|
||||||
- list
|
|
||||||
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRole
|
|
||||||
metadata:
|
|
||||||
name: {{ .Release.Name }}-package-getter
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- "*"
|
|
||||||
resources:
|
|
||||||
- packages
|
|
||||||
verbs:
|
|
||||||
- "*"
|
|
||||||
- apiGroups:
|
|
||||||
- rbac.authorization.k8s.io
|
|
||||||
resources:
|
|
||||||
- rolebindings
|
|
||||||
verbs:
|
|
||||||
- "*"
|
|
||||||
@@ -1,24 +1,29 @@
|
|||||||
{{- if .Values.createNamespace }}
|
{{- if .Values.createNamespace }}
|
||||||
|
{{- if and (ne .Values.functionNamespace "default") (ne .Values.functionNamespace "") }}
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Namespace
|
kind: Namespace
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ .Values.functionNamespace }}
|
name: {{ template "fission-function-ns" . }}
|
||||||
labels:
|
labels:
|
||||||
name: fission-function
|
name: fission-function
|
||||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
{{- if .Values.enableIstio }}
|
{{- if .Values.enableIstio }}
|
||||||
istio-injection: enabled
|
istio-injection: enabled
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- end}}
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
{{- if and (ne .Values.builderNamespace "default") (ne .Values.builderNamespace "") }}
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Namespace
|
kind: Namespace
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ .Values.builderNamespace }}
|
name: {{ template "fission-builder-ns" . }}
|
||||||
labels:
|
labels:
|
||||||
name: fission-builder
|
name: fission-builder
|
||||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
{{- if .Values.enableIstio }}
|
{{- if .Values.enableIstio }}
|
||||||
istio-injection: enabled
|
istio-injection: enabled
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -1,70 +1,12 @@
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
{{/*
|
||||||
kind: Role
|
Passing namespace as an argument to the "fissionFunction.roles" template.
|
||||||
metadata:
|
Need to use merge function to pass in the current scope so that ".Release" values
|
||||||
name: {{ .Release.Name }}-fission-fetcher
|
can be used
|
||||||
namespace: {{ .Values.defaultNamespace }}
|
*/}}
|
||||||
rules:
|
{{ include "fissionFunction.roles" (merge (dict "namespace" .Values.defaultNamespace) .) }}
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
- secrets
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- events
|
|
||||||
verbs:
|
|
||||||
- "*"
|
|
||||||
- apiGroups:
|
|
||||||
- fission.io
|
|
||||||
resources:
|
|
||||||
- canaryconfigs
|
|
||||||
- environments
|
|
||||||
- functions
|
|
||||||
- httptriggers
|
|
||||||
- kuberneteswatchtriggers
|
|
||||||
- messagequeuetriggers
|
|
||||||
- packages
|
|
||||||
- timetriggers
|
|
||||||
verbs:
|
|
||||||
- "*"
|
|
||||||
|
|
||||||
---
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
kind: Role
|
{{ include "fissionFunction.roles" (merge (dict "namespace" $namespace) $) }}
|
||||||
metadata:
|
{{- end }}
|
||||||
name: {{ .Release.Name }}-fission-builder
|
{{- end }}
|
||||||
namespace: {{ .Values.defaultNamespace }}
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- fission.io
|
|
||||||
resources:
|
|
||||||
- canaryconfigs
|
|
||||||
- environments
|
|
||||||
- functions
|
|
||||||
- httptriggers
|
|
||||||
- kuberneteswatchtriggers
|
|
||||||
- messagequeuetriggers
|
|
||||||
- packages
|
|
||||||
- timetriggers
|
|
||||||
verbs:
|
|
||||||
- "*"
|
|
||||||
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
namespace: {{ .Values.functionNamespace }}
|
|
||||||
name: {{ .Release.Name }}-event-fetcher
|
|
||||||
rules:
|
|
||||||
- apiGroups: [""] # "" indicates the core API group
|
|
||||||
resources: ["pods"]
|
|
||||||
verbs: ["get", "watch", "list"]
|
|
||||||
- apiGroups: [""] # "" indicates the core API group
|
|
||||||
resources: ["events"]
|
|
||||||
verbs: ["*"]
|
|
||||||
|
|||||||
@@ -1,43 +1,12 @@
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
{{/*
|
||||||
kind: RoleBinding
|
Passing namespace as an argument to the "fissionFunction.rolebindings" template.
|
||||||
metadata:
|
Need to use merge function to pass in the current scope so that ".Release" values
|
||||||
name: {{ .Release.Name }}-fission-fetcher
|
can be used
|
||||||
namespace: {{ .Values.defaultNamespace }}
|
*/}}
|
||||||
roleRef:
|
{{ include "fissionFunction.rolebindings" (merge (dict "namespace" .Values.defaultNamespace) .) }}
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ .Release.Name }}-fission-fetcher
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: fission-fetcher
|
|
||||||
namespace: {{ .Values.functionNamespace }}
|
|
||||||
|
|
||||||
---
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
kind: RoleBinding
|
{{ include "fissionFunction.rolebindings" (merge (dict "namespace" $namespace) $) }}
|
||||||
metadata:
|
{{- end }}
|
||||||
name: {{ .Release.Name }}-fission-builder
|
{{- end }}
|
||||||
namespace: {{ .Values.defaultNamespace }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ .Release.Name }}-fission-builder
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: fission-builder
|
|
||||||
namespace: {{ .Values.builderNamespace }}
|
|
||||||
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: {{ .Release.Name }}-fission-fetcher-pod-reader
|
|
||||||
namespace: {{ .Values.functionNamespace }}
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: {{ .Release.Name }}-event-fetcher
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: fission-fetcher
|
|
||||||
namespace: {{ .Values.functionNamespace }}
|
|
||||||
|
|||||||
@@ -2,11 +2,11 @@ apiVersion: v1
|
|||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
name: fission-fetcher
|
name: fission-fetcher
|
||||||
namespace: {{ .Values.functionNamespace }}
|
namespace: {{ template "fission-function-ns" . }}
|
||||||
|
|
||||||
---
|
---
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
name: fission-builder
|
name: fission-builder
|
||||||
namespace: {{ .Values.builderNamespace }}
|
namespace: {{ template "fission-builder-ns" . }}
|
||||||
|
|||||||
@@ -25,11 +25,7 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: mqtrigger
|
- name: mqtrigger
|
||||||
{{- if eq .Values.imageTag "" }}
|
image: {{ include "fission-bundleImage" . | quote }}
|
||||||
image: "{{ .Values.image }}"
|
|
||||||
{{- else }}
|
|
||||||
image: "{{ .Values.image }}:{{ .Values.imageTag }}"
|
|
||||||
{{- end }}
|
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: ["/fission-bundle"]
|
command: ["/fission-bundle"]
|
||||||
args: ["--mqt", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
args: ["--mqt", "--routerUrl", "http://router.{{ .Release.Namespace }}"]
|
||||||
@@ -47,6 +43,7 @@ spec:
|
|||||||
value: {{ .Values.debugEnv | quote }}
|
value: {{ .Values.debugEnv | quote }}
|
||||||
- name: PPROF_ENABLED
|
- name: PPROF_ENABLED
|
||||||
value: {{ .Values.pprof.enabled | quote }}
|
value: {{ .Values.pprof.enabled | quote }}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
# TLS authentication is TLS with authentication (2 way)
|
# TLS authentication is TLS with authentication (2 way)
|
||||||
# More info: https://docs.confluent.io/current/kafka/authentication_ssl.html#ssl-overview
|
# More info: https://docs.confluent.io/current/kafka/authentication_ssl.html#ssl-overview
|
||||||
@@ -67,7 +64,7 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-kafka
|
||||||
{{- if .Values.kafka.authentication.tls.enabled }}
|
{{- if .Values.kafka.authentication.tls.enabled }}
|
||||||
volumes:
|
volumes:
|
||||||
- name: kafka-secrets
|
- name: kafka-secrets
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "kafka") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "kafka") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "kafka") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "kafka") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-kafka
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -46,6 +46,8 @@ spec:
|
|||||||
value: "{{ .Values.mqt_keda.connector_images.gcp_pubsub.image }}:{{ .Values.mqt_keda.connector_images.gcp_pubsub.tag }}"
|
value: "{{ .Values.mqt_keda.connector_images.gcp_pubsub.image }}:{{ .Values.mqt_keda.connector_images.gcp_pubsub.tag }}"
|
||||||
- name: REDIS_IMAGE
|
- name: REDIS_IMAGE
|
||||||
value: "{{ .Values.mqt_keda.connector_images.redis.image }}:{{ .Values.mqt_keda.connector_images.redis.tag }}"
|
value: "{{ .Values.mqt_keda.connector_images.redis.image }}:{{ .Values.mqt_keda.connector_images.redis.tag }}"
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.mqt_keda.resources | nindent 10 }}
|
{{- toYaml .Values.mqt_keda.resources | nindent 10 }}
|
||||||
@@ -55,7 +57,7 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-keda
|
||||||
{{- if .Values.priorityClassName }}
|
{{- if .Values.priorityClassName }}
|
||||||
priorityClassName: {{ .Values.priorityClassName }}
|
priorityClassName: {{ .Values.priorityClassName }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "keda") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "keda") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "keda") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "keda") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
+1
-1
@@ -1,5 +1,5 @@
|
|||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
name: fission-svc
|
name: fission-keda
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ .Release.Name }}-preupgrade
|
||||||
|
annotations:
|
||||||
|
helm.sh/hook: pre-upgrade
|
||||||
|
helm.sh/hook-delete-policy: before-hook-creation
|
||||||
|
helm.sh/hook-weight: "-2"
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- apiextensions.k8s.io
|
||||||
|
resources:
|
||||||
|
- customresourcedefinitions
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
+6
-3
@@ -1,12 +1,15 @@
|
|||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ .Release.Name }}-fission-cr-admin
|
name: {{ .Release.Name }}-preupgrade
|
||||||
|
annotations:
|
||||||
|
helm.sh/hook: pre-upgrade
|
||||||
|
helm.sh/hook-delete-policy: before-hook-creation
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: fission-svc
|
name: fission-preupgrade
|
||||||
namespace: {{ .Release.Namespace }}
|
namespace: {{ .Release.Namespace }}
|
||||||
roleRef:
|
roleRef:
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: {{ .Release.Name }}-fission-cr-admin
|
name: {{ .Release.Name }}-preupgrade
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
@@ -15,6 +15,7 @@ metadata:
|
|||||||
# job is considered part of the release.
|
# job is considered part of the release.
|
||||||
"helm.sh/hook": pre-upgrade
|
"helm.sh/hook": pre-upgrade
|
||||||
"helm.sh/hook-delete-policy": hook-succeeded
|
"helm.sh/hook-delete-policy": hook-succeeded
|
||||||
|
"helm.sh/hook-weight": "1"
|
||||||
spec:
|
spec:
|
||||||
backoffLimit: 0
|
backoffLimit: 0
|
||||||
template:
|
template:
|
||||||
@@ -27,19 +28,21 @@ spec:
|
|||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
containers:
|
containers:
|
||||||
- name: pre-upgrade-job
|
- name: pre-upgrade-job
|
||||||
{{- if .Values.preUpgradeChecks.imageTag }}
|
image: {{ include "preUpgradeChecksImage" . | quote }}
|
||||||
image: {{ .Values.preUpgradeChecks.image }}:{{ .Values.preUpgradeChecks.imageTag }}
|
|
||||||
{{- else }}
|
|
||||||
image: {{ .Values.preUpgradeChecks.image }}
|
|
||||||
{{- end }}
|
|
||||||
imagePullPolicy: {{ .Values.pullPolicy }}
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
command: [ "/pre-upgrade-checks" ]
|
command: [ "/pre-upgrade-checks" ]
|
||||||
args: ["--fn-pod-namespace", "{{ .Values.functionNamespace }}", "--envbuilder-namespace", "{{ .Values.builderNamespace }}"]
|
env:
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
{{- if .Values.terminationMessagePath }}
|
{{- if .Values.terminationMessagePath }}
|
||||||
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-preupgrade
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "preupgrade") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "preupgrade") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-preupgrade
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
annotations:
|
||||||
|
helm.sh/hook: pre-upgrade
|
||||||
|
helm.sh/hook-delete-policy: before-hook-creation
|
||||||
|
helm.sh/hook-weight: "-1"
|
||||||
@@ -12,7 +12,7 @@ metadata:
|
|||||||
application: fission-router
|
application: fission-router
|
||||||
spec:
|
spec:
|
||||||
{{- if not .Values.router.deployAsDaemonSet }}
|
{{- if not .Values.router.deployAsDaemonSet }}
|
||||||
replicas: 1
|
replicas: {{ .Values.router.replicas | default 1 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
selector:
|
selector:
|
||||||
matchLabels:
|
matchLabels:
|
||||||
@@ -83,6 +83,8 @@ spec:
|
|||||||
value: {{ .Values.pprof.enabled | quote }}
|
value: {{ .Values.pprof.enabled | quote }}
|
||||||
- name: DISPLAY_ACCESS_LOG
|
- name: DISPLAY_ACCESS_LOG
|
||||||
value: {{ .Values.router.displayAccessLog | default false | quote }}
|
value: {{ .Values.router.displayAccessLog | default false | quote }}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.router.resources | nindent 10 }}
|
{{- toYaml .Values.router.resources | nindent 10 }}
|
||||||
@@ -122,7 +124,7 @@ spec:
|
|||||||
{{- else if .Values.terminationMessagePolicy }}
|
{{- else if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-router
|
||||||
volumes:
|
volumes:
|
||||||
- name: config-volume
|
- name: config-volume
|
||||||
configMap:
|
configMap:
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "router") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "router") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Release.Namespace "component" "router") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "router") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -6,9 +6,9 @@ metadata:
|
|||||||
labels:
|
labels:
|
||||||
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||||
annotations:
|
annotations:
|
||||||
"helm.sh/hook": pre-install
|
"helm.sh/hook": pre-install,pre-upgrade
|
||||||
data:
|
data:
|
||||||
username: {{ .Values.authentication.authUsername | b64enc | quote }}
|
username: {{ .Values.authentication.authUsername | b64enc | quote }}
|
||||||
password: {{ randAlphaNum 20 | b64enc | quote }}
|
password: {{ randAlphaNum 20 | b64enc | quote }}
|
||||||
jwtSigningKey: {{ .Values.authentication.jwtSigningKey | b64enc | quote }}
|
jwtSigningKey: {{ default (randAlphaNum 20) .Values.authentication.jwtSigningKey | b64enc | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-router
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -60,6 +60,8 @@ spec:
|
|||||||
- name: STORAGE_S3_REGION
|
- name: STORAGE_S3_REGION
|
||||||
value: {{ .Values.persistence.s3.region }}
|
value: {{ .Values.persistence.s3.region }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.storagesvc.resources | nindent 10 }}
|
{{- toYaml .Values.storagesvc.resources | nindent 10 }}
|
||||||
@@ -96,7 +98,7 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-storagesvc
|
||||||
{{- if and (.Values.persistence.enabled) (ne (.Values.persistence.storageType | default "local") "s3") }}
|
{{- if and (.Values.persistence.enabled) (ne (.Values.persistence.storageType | default "local") "s3") }}
|
||||||
volumes:
|
volumes:
|
||||||
- name: fission-storage
|
- name: fission-storage
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "storagesvc") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "storagesvc") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-storagesvc
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -29,6 +29,8 @@ spec:
|
|||||||
value: {{ .Values.debugEnv | quote }}
|
value: {{ .Values.debugEnv | quote }}
|
||||||
- name: PPROF_ENABLED
|
- name: PPROF_ENABLED
|
||||||
value: {{ .Values.pprof.enabled | quote }}
|
value: {{ .Values.pprof.enabled | quote }}
|
||||||
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
||||||
|
{{- include "kube_client.envs" . | indent 8 }}
|
||||||
{{- include "opentelemtry.envs" . | indent 8 }}
|
{{- include "opentelemtry.envs" . | indent 8 }}
|
||||||
resources:
|
resources:
|
||||||
{{- toYaml .Values.timer.resources | nindent 10 }}
|
{{- toYaml .Values.timer.resources | nindent 10 }}
|
||||||
@@ -38,7 +40,7 @@ spec:
|
|||||||
{{- if .Values.terminationMessagePolicy }}
|
{{- if .Values.terminationMessagePolicy }}
|
||||||
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
serviceAccountName: fission-svc
|
serviceAccountName: fission-timer
|
||||||
{{- if .Values.priorityClassName }}
|
{{- if .Values.priorityClassName }}
|
||||||
priorityClassName: {{ .Values.priorityClassName }}
|
priorityClassName: {{ .Values.priorityClassName }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "fission-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "timer") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "fission-role-generator" (merge (dict "namespace" $namespace "component" "timer") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{{- include "kubernetes-role-generator" (merge (dict "namespace" .Values.defaultNamespace "component" "timer") .) }}
|
||||||
|
|
||||||
|
{{- if gt (len .Values.additionalFissionNamespaces) 0 }}
|
||||||
|
{{- range $namespace := $.Values.additionalFissionNamespaces }}
|
||||||
|
{{ include "kubernetes-role-generator" (merge (dict "namespace" $namespace "component" "timer") $) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-timer
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
{{- $certManagerEnabled := .Values.webhook.certManager.enabled }}
|
||||||
|
|
||||||
|
{{- if not $certManagerEnabled }}
|
||||||
|
kind: Secret
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
name: fission-webhook-certs
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: webhook-secret
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
ca.crt: {{ b64enc (include "webhook.caBundleCertPEM" .) }}
|
||||||
|
tls.crt: {{ b64enc (include "webhook.certPEM" .) }}
|
||||||
|
tls.key: {{ b64enc (include "webhook.keyPEM" .) }}
|
||||||
|
|
||||||
|
{{- else }}
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Issuer
|
||||||
|
metadata:
|
||||||
|
name: fission-selfsigned-issuer
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
spec:
|
||||||
|
selfSigned: {}
|
||||||
|
---
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: fission-webhook-cert
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
spec:
|
||||||
|
secretName: fission-webhook-certs
|
||||||
|
dnsNames:
|
||||||
|
- "webhook-service.{{ .Release.Namespace }}.svc"
|
||||||
|
- "webhook-service.{{ .Release.Namespace }}.svc.cluster.local "
|
||||||
|
issuerRef:
|
||||||
|
name: fission-selfsigned-issuer
|
||||||
|
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: webhook
|
||||||
|
labels:
|
||||||
|
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||||
|
svc: webhook-service
|
||||||
|
application: fission-webhook
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
svc: webhook-service
|
||||||
|
application: fission-webhook
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
svc: webhook-service
|
||||||
|
application: fission-webhook
|
||||||
|
annotations:
|
||||||
|
prometheus.io/scrape: "true"
|
||||||
|
prometheus.io/path: "/metrics"
|
||||||
|
prometheus.io/port: "8080"
|
||||||
|
spec:
|
||||||
|
{{- if .Values.webhook.securityContext.enabled }}
|
||||||
|
securityContext: {{- omit .Values.webhook.securityContext "enabled" | toYaml | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- name: webhook
|
||||||
|
image: {{ include "fission-bundleImage" . | quote }}
|
||||||
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
||||||
|
command: ["/fission-bundle"]
|
||||||
|
args: ["--webhookPort", "9443"]
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /tmp/k8s-webhook-server/serving-certs
|
||||||
|
name: serving-certs
|
||||||
|
readOnly: true
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
name: metrics
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.webhook.resources | nindent 10 }}
|
||||||
|
volumes:
|
||||||
|
- name: serving-certs
|
||||||
|
secret:
|
||||||
|
secretName: fission-webhook-certs
|
||||||
|
serviceAccountName: fission-webhook
|
||||||
|
{{- if .Values.priorityClassName }}
|
||||||
|
priorityClassName: {{ .Values.priorityClassName }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.extraCoreComponentPodConfig }}
|
||||||
|
{{ toYaml .Values.extraCoreComponentPodConfig | indent 6 -}}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: fission-webhook
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
+2
-2
@@ -2,7 +2,7 @@
|
|||||||
apiVersion: monitoring.coreos.com/v1
|
apiVersion: monitoring.coreos.com/v1
|
||||||
kind: ServiceMonitor
|
kind: ServiceMonitor
|
||||||
metadata:
|
metadata:
|
||||||
name: controller-monitor
|
name: webhook-monitor
|
||||||
{{- if .Values.serviceMonitor.namespace }}
|
{{- if .Values.serviceMonitor.namespace }}
|
||||||
namespace: {{ .Values.serviceMonitor.namespace }}
|
namespace: {{ .Values.serviceMonitor.namespace }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -16,7 +16,7 @@ spec:
|
|||||||
- {{ .Release.Namespace }}
|
- {{ .Release.Namespace }}
|
||||||
selector:
|
selector:
|
||||||
matchLabels:
|
matchLabels:
|
||||||
svc: controller
|
svc: webhook-service
|
||||||
endpoints:
|
endpoints:
|
||||||
- targetPort: 8080
|
- targetPort: 8080
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: webhook-service
|
||||||
|
labels:
|
||||||
|
svc: webhook-service
|
||||||
|
application: fission-webhook
|
||||||
|
chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.serviceType }}
|
||||||
|
ports:
|
||||||
|
- port: 443
|
||||||
|
targetPort: 9443
|
||||||
|
selector:
|
||||||
|
svc: webhook-service
|
||||||
@@ -0,0 +1,203 @@
|
|||||||
|
---
|
||||||
|
{{- $caCert := include "webhook.caBundleCertPEM" . -}}
|
||||||
|
{{- $crtPEM := include "webhook.certPEM" . -}}
|
||||||
|
{{- $keyPEM := include "webhook.keyPEM" . -}}
|
||||||
|
|
||||||
|
{{- $certManagerEnabled := $.Values.webhook.certManager.enabled }}
|
||||||
|
{{- $caBundleValue := "" -}}
|
||||||
|
{{- if $certManagerEnabled }}
|
||||||
|
{{- $caBundleValue = "Cg==" -}}
|
||||||
|
{{- else }}
|
||||||
|
{{- $caBundleValue = ternary (b64enc $caCert) (b64enc (trim $crtPEM)) (empty $crtPEM) -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
---
|
||||||
|
apiVersion: admissionregistration.k8s.io/v1
|
||||||
|
kind: MutatingWebhookConfiguration
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: null
|
||||||
|
name: fission-mutating-webhooks
|
||||||
|
{{- if $certManagerEnabled }}
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/inject-ca-from: "{{ .Release.Namespace }}/fission-webhook-cert"
|
||||||
|
{{- end }}
|
||||||
|
webhooks:
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /mutate-fission-io-v1-package
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: mpackage.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
- UPDATE
|
||||||
|
resources:
|
||||||
|
- packages
|
||||||
|
sideEffects: None
|
||||||
|
---
|
||||||
|
|
||||||
|
apiVersion: admissionregistration.k8s.io/v1
|
||||||
|
kind: ValidatingWebhookConfiguration
|
||||||
|
metadata:
|
||||||
|
creationTimestamp: null
|
||||||
|
name: fission-validating-webhooks
|
||||||
|
{{- if $certManagerEnabled }}
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/inject-ca-from: "{{ .Release.Namespace }}/fission-webhook-cert"
|
||||||
|
{{- end }}
|
||||||
|
webhooks:
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /validate-fission-io-v1-environment
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: venvironment.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
resources:
|
||||||
|
- environments
|
||||||
|
sideEffects: None
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /validate-fission-io-v1-function
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: vfunction.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
- UPDATE
|
||||||
|
resources:
|
||||||
|
- functions
|
||||||
|
sideEffects: None
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /validate-fission-io-v1-httptrigger
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: vhttptrigger.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
- UPDATE
|
||||||
|
resources:
|
||||||
|
- httptriggers
|
||||||
|
sideEffects: None
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /validate-fission-io-v1-kuberneteswatchtrigger
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: vkuberneteswatchtrigger.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
- UPDATE
|
||||||
|
resources:
|
||||||
|
- kuberneteswatchtriggers
|
||||||
|
sideEffects: None
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /validate-fission-io-v1-messagequeuetrigger
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: vmessagequeuetrigger.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
- UPDATE
|
||||||
|
resources:
|
||||||
|
- messagequeuetriggers
|
||||||
|
sideEffects: None
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /validate-fission-io-v1-package
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: vpackage.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
- UPDATE
|
||||||
|
resources:
|
||||||
|
- packages
|
||||||
|
sideEffects: None
|
||||||
|
- admissionReviewVersions:
|
||||||
|
- v1
|
||||||
|
clientConfig:
|
||||||
|
caBundle: {{ $caBundleValue }}
|
||||||
|
service:
|
||||||
|
name: webhook-service
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
path: /validate-fission-io-v1-timetrigger
|
||||||
|
failurePolicy: Fail
|
||||||
|
name: vtimetrigger.fission.io
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- fission.io
|
||||||
|
apiVersions:
|
||||||
|
- v1
|
||||||
|
operations:
|
||||||
|
- CREATE
|
||||||
|
- UPDATE
|
||||||
|
resources:
|
||||||
|
- timetriggers
|
||||||
|
sideEffects: None
|
||||||
+169
-57
@@ -1,7 +1,7 @@
|
|||||||
## Fission chart configuration
|
## Fission chart configuration
|
||||||
##
|
##
|
||||||
|
|
||||||
## serviceType to consider while creating Fission Controller service.
|
## serviceType to consider while creating Fission webhook service.
|
||||||
## For minikube/kind, set this to NodePort, elsewhere use LoadBalancer or ClusterIP.
|
## For minikube/kind, set this to NodePort, elsewhere use LoadBalancer or ClusterIP.
|
||||||
##
|
##
|
||||||
serviceType: ClusterIP
|
serviceType: ClusterIP
|
||||||
@@ -14,7 +14,7 @@ routerServiceType: LoadBalancer
|
|||||||
## repository represents base repository for images used in the chart.
|
## repository represents base repository for images used in the chart.
|
||||||
## Keep it empty for using existing local image
|
## Keep it empty for using existing local image
|
||||||
##
|
##
|
||||||
repository: index.docker.io
|
repository: ghcr.io
|
||||||
|
|
||||||
## image represents the base image fission-bundle used by multiple Fission components.
|
## image represents the base image fission-bundle used by multiple Fission components.
|
||||||
## We alter arguments to the image to run a particular component.
|
## We alter arguments to the image to run a particular component.
|
||||||
@@ -25,7 +25,7 @@ image: fission/fission-bundle
|
|||||||
## It is also used by the chart to identify version of the few more images apart from fission-bundle.
|
## It is also used by the chart to identify version of the few more images apart from fission-bundle.
|
||||||
## Keep it empty for using latest tag.
|
## Keep it empty for using latest tag.
|
||||||
##
|
##
|
||||||
imageTag: v1.17.0
|
imageTag: v1.21.0
|
||||||
|
|
||||||
## pullPolicy represents the pull policy to use for images in the chart.
|
## pullPolicy represents the pull policy to use for images in the chart.
|
||||||
##
|
##
|
||||||
@@ -53,46 +53,78 @@ terminationMessagePath: /dev/termination-log
|
|||||||
##
|
##
|
||||||
terminationMessagePolicy: File
|
terminationMessagePolicy: File
|
||||||
|
|
||||||
## controllerPort represents the port at which the Fission controller service should be exposed.
|
|
||||||
##
|
|
||||||
controllerPort: 31313
|
|
||||||
|
|
||||||
## routerPort represents the port at which the Fission Router service should be exposed.
|
## routerPort represents the port at which the Fission Router service should be exposed.
|
||||||
##
|
##
|
||||||
routerPort: 31314
|
routerPort: 31314
|
||||||
|
|
||||||
## functionNamespace represents the namespace in which Fission Function resources will be created.
|
## defaultNamespace represents the namespace in which Fission custom resources will be created by the Fission user.
|
||||||
## This is different from the release namespace.
|
## This is different from the release namespace.
|
||||||
##
|
## Please consider setting `additionalFissionNamespaces` if you want more than one namespace to be used for Fission custom resources.
|
||||||
functionNamespace: fission-function
|
|
||||||
|
|
||||||
## builderNamespace represents the namespace in which Fission Builder resources will be created.
|
|
||||||
## This is different from the release namespace.
|
|
||||||
##
|
|
||||||
builderNamespace: fission-builder
|
|
||||||
|
|
||||||
## defaultNamespace represents the default namespace in Kubernetes.
|
|
||||||
##
|
##
|
||||||
defaultNamespace: default
|
defaultNamespace: default
|
||||||
|
|
||||||
|
## builderNamespace represents the namespace in which Fission Builder resources will be created.
|
||||||
|
## if builderNamespace is set to empty then builder resources will be created in the same namespace as the Fission resources.
|
||||||
|
## This is different from the release namespace.
|
||||||
|
##
|
||||||
|
## Note: This parameter is deprecated and will be removed in future fission releases.
|
||||||
|
##
|
||||||
|
builderNamespace: ""
|
||||||
|
|
||||||
|
## functionNamespace represents the namespace in which Fission Function resources will be created.
|
||||||
|
## if functionNamespace is set to empty then function resources will be created in the same namespace as the Fission resources.
|
||||||
|
## This is different from the release namespace.
|
||||||
|
##
|
||||||
|
## Note: This parameter is deprecated and will be removed in future fission releases.
|
||||||
|
##
|
||||||
|
functionNamespace: ""
|
||||||
|
|
||||||
|
## Fission will watch the following namespaces along with the `defaultNamespace` for fission custom resources.
|
||||||
|
## additionalFissionNamespaces:
|
||||||
|
## - namespace1
|
||||||
|
## - namespace2
|
||||||
|
## - namespace3
|
||||||
|
additionalFissionNamespaces: []
|
||||||
|
|
||||||
## createNamespace decides to create namespaces by the chart.
|
## createNamespace decides to create namespaces by the chart.
|
||||||
## If set to true, functionNamespace and builderNamespace namespaces mentioned above will be created by the chart.
|
## If set to true, functionNamespace and builderNamespace namespaces mentioned above will be created by the chart.
|
||||||
## Set to false if you want to create the namespaces manually.
|
## Set to false if you want to create the namespaces manually.
|
||||||
##
|
##
|
||||||
createNamespace: true
|
createNamespace: true
|
||||||
|
|
||||||
|
## disableOwnerReference decides to set OwnerReference to K8s resources like deployment, services, hpa etc. created by Fission.
|
||||||
|
## If set to true, the K8s resources created by Fission will not have OwnerReference set.
|
||||||
|
## Set to false if you want to add OwnerReference to K8s resources created by Fission.
|
||||||
|
##
|
||||||
|
## Set to true if you are using cross namespace meaning `builderNamespace` and `functionNamespace` are set.
|
||||||
|
##
|
||||||
|
## Note: This flag is temporary addition and would be removed in future fission releases.
|
||||||
|
##
|
||||||
|
disableOwnerReference: false
|
||||||
|
|
||||||
## enableIstio indicates whether to enable istio integration.
|
## enableIstio indicates whether to enable istio integration.
|
||||||
##
|
##
|
||||||
enableIstio: false
|
enableIstio: false
|
||||||
|
|
||||||
|
## Kubernetes client QPS and Burst settings
|
||||||
|
##
|
||||||
|
## kubernetesClientQPS represents the maximum queries per second to the kubernetes api server from client instances of fission components.
|
||||||
|
kubernetesClientQPS: 200
|
||||||
|
## kubernetesClientBurst represents the maximum burst queries to the kubernetes api server from client instances of fission components.
|
||||||
|
kubernetesClientBurst: 500
|
||||||
|
|
||||||
## fetcher is a light weight component that helps in running functions.
|
## fetcher is a light weight component that helps in running functions.
|
||||||
## fetcher helps in fetching function source code/build and uploading it when function is invoked.
|
## fetcher helps in fetching function source code/build and uploading it when function is invoked.
|
||||||
##
|
##
|
||||||
fetcher:
|
fetcher:
|
||||||
|
## repository represents the repository of the fetcher component.
|
||||||
|
##
|
||||||
|
## By default, it is empty, which means global repository will be used.
|
||||||
|
repository: ""
|
||||||
## image represents the image of the fetcher component.
|
## image represents the image of the fetcher component.
|
||||||
image: fission/fetcher
|
image: fission/fetcher
|
||||||
## imageTag represents the tag of the image of the fetcher component.
|
## imageTag represents the tag of the image of the fetcher component.
|
||||||
imageTag: v1.17.0
|
imageTag: v1.21.0
|
||||||
|
|
||||||
## Fetcher is only for to downloading or uploading archive.
|
## Fetcher is only for to downloading or uploading archive.
|
||||||
## Normally, you don't need to change the value here, unless necessary.
|
## Normally, you don't need to change the value here, unless necessary.
|
||||||
@@ -148,13 +180,41 @@ executor:
|
|||||||
## This is an experimental section, please verify before enabling in production.
|
## This is an experimental section, please verify before enabling in production.
|
||||||
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
securityContext:
|
securityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
## Mark it false, if you want to stop the non root user validation
|
## Mark it false, if you want to stop the non root user validation
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
fsGroup: 10001
|
fsGroup: 10001
|
||||||
runAsUser: 10001
|
runAsUser: 10001
|
||||||
runAsGroup: 10001
|
runAsGroup: 10001
|
||||||
|
|
||||||
|
## Object Reaper
|
||||||
|
## objectReaperInterval (seconds) represents GLOBAL interval to run process that reaps objects after certain idle time.
|
||||||
|
## Also you can set different objectReaperInterval for specific executor type. See poolmgs/newdeploy/container section
|
||||||
|
## Default: 5 (in seconds)
|
||||||
|
##
|
||||||
|
objectReaperInterval: 5
|
||||||
|
|
||||||
|
poolmgr: {}
|
||||||
|
## objectReaperInterval specific to poolmgr executor type
|
||||||
|
##
|
||||||
|
## objectReaperInterval: 5
|
||||||
|
newdeploy: {}
|
||||||
|
## objectReaperInterval specific to newdeploy executor type
|
||||||
|
##
|
||||||
|
## objectReaperInterval: 5
|
||||||
|
container: {}
|
||||||
|
## objectReaperInterval specific to container executor type
|
||||||
|
##
|
||||||
|
## objectReaperInterval: 5
|
||||||
|
|
||||||
|
serviceAccountCheck:
|
||||||
|
## enables fission to create service account, roles and rolebinding for missing permission for builder and fetcher.
|
||||||
|
enabled: true
|
||||||
|
## indicates the time interval in minutes, after that fission will create service account, roles and rolebinding for builder and fetcher.
|
||||||
|
## interval will be applicable only if enable value is set to true.
|
||||||
|
## default timing will be 0 minutes. That means check will run only once.
|
||||||
|
## if you want to run check every 30 minutes then set interval to 30.
|
||||||
|
interval: 0
|
||||||
## router is responsible for routing function calls to the appropriate function.
|
## router is responsible for routing function calls to the appropriate function.
|
||||||
##
|
##
|
||||||
router:
|
router:
|
||||||
@@ -172,6 +232,9 @@ router:
|
|||||||
## deployAsDaemonSet decides whether to deploy router as a DaemonSet or a Deployment.
|
## deployAsDaemonSet decides whether to deploy router as a DaemonSet or a Deployment.
|
||||||
##
|
##
|
||||||
deployAsDaemonSet: false
|
deployAsDaemonSet: false
|
||||||
|
## replicas decides how many router pods to deploy. Only used when deployAsDaemonSet is false.
|
||||||
|
##
|
||||||
|
replicas: 1
|
||||||
## svcAddressMaxRetries is the max times for router to retry with a specific function service address
|
## svcAddressMaxRetries is the max times for router to retry with a specific function service address
|
||||||
##
|
##
|
||||||
svcAddressMaxRetries: 5
|
svcAddressMaxRetries: 5
|
||||||
@@ -231,7 +294,7 @@ router:
|
|||||||
maxRetries: 10
|
maxRetries: 10
|
||||||
|
|
||||||
## Extend the container specs for the core fission pods.
|
## Extend the container specs for the core fission pods.
|
||||||
## Can be used to add things like affinty/tolerations/nodeSelectors/etc.
|
## Can be used to add things like affinity/tolerations/nodeSelectors/etc.
|
||||||
## For example:
|
## For example:
|
||||||
## extraCoreComponentPodConfig:
|
## extraCoreComponentPodConfig:
|
||||||
## affinity:
|
## affinity:
|
||||||
@@ -265,7 +328,7 @@ router:
|
|||||||
## This is an experimental section, please verify before enabling in production.
|
## This is an experimental section, please verify before enabling in production.
|
||||||
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
securityContext:
|
securityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
## Mark it false, if you want to stop the non root user validation
|
## Mark it false, if you want to stop the non root user validation
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
fsGroup: 10001
|
fsGroup: 10001
|
||||||
@@ -291,17 +354,17 @@ buildermgr:
|
|||||||
## This is an experimental section, please verify before enabling in production.
|
## This is an experimental section, please verify before enabling in production.
|
||||||
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
securityContext:
|
securityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
## Mark it false, if you want to stop the non root user validation
|
## Mark it false, if you want to stop the non root user validation
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
fsGroup: 10001
|
fsGroup: 10001
|
||||||
runAsUser: 10001
|
runAsUser: 10001
|
||||||
runAsGroup: 10001
|
runAsGroup: 10001
|
||||||
|
|
||||||
## controller is the component that the client talks to.
|
## webhook is the component that validates API calls.
|
||||||
## It contains CRUD APIs for functions, triggers, environments, Kubernetes event watches, etc. and proxy APIs to internal 3rd-party services.
|
## It contains validation and mutation for functions, triggers, environments, Kubernetes event watches, etc.
|
||||||
##
|
##
|
||||||
controller:
|
webhook:
|
||||||
## Pod resources as:
|
## Pod resources as:
|
||||||
## resources:
|
## resources:
|
||||||
## limits:
|
## limits:
|
||||||
@@ -313,18 +376,29 @@ controller:
|
|||||||
##
|
##
|
||||||
resources: {}
|
resources: {}
|
||||||
|
|
||||||
|
certManager:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
caBundlePEM: |
|
||||||
|
|
||||||
|
crtPEM: |
|
||||||
|
|
||||||
|
keyPEM: |
|
||||||
|
|
||||||
|
|
||||||
## Security Context
|
## Security Context
|
||||||
## It holds pod-level and container level security configuration.
|
## It holds pod-level and container level security configuration.
|
||||||
## This is an experimental section, please verify before enabling in production.
|
## This is an experimental section, please verify before enabling in production.
|
||||||
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
securityContext:
|
securityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
## Mark it false, if you want to stop the non root user validation
|
## Mark it false, if you want to stop the non root user validation
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
fsGroup: 10001
|
fsGroup: 10001
|
||||||
runAsUser: 10001
|
runAsUser: 10001
|
||||||
runAsGroup: 10001
|
runAsGroup: 10001
|
||||||
|
|
||||||
|
|
||||||
## kubewatcher watches the Kubernetes API and invokes functions associated with watches, sending the watch event to the function.
|
## kubewatcher watches the Kubernetes API and invokes functions associated with watches, sending the watch event to the function.
|
||||||
##
|
##
|
||||||
kubewatcher:
|
kubewatcher:
|
||||||
@@ -344,7 +418,7 @@ kubewatcher:
|
|||||||
## This is an experimental section, please verify before enabling in production.
|
## This is an experimental section, please verify before enabling in production.
|
||||||
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
securityContext:
|
securityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
## Mark it false, if you want to stop the non root user validation
|
## Mark it false, if you want to stop the non root user validation
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
fsGroup: 10001
|
fsGroup: 10001
|
||||||
@@ -376,7 +450,7 @@ storagesvc:
|
|||||||
## This is an experimental section, please verify before enabling in production.
|
## This is an experimental section, please verify before enabling in production.
|
||||||
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
securityContext:
|
securityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
## Mark it false, if you want to stop the non root user validation
|
## Mark it false, if you want to stop the non root user validation
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
fsGroup: 10001
|
fsGroup: 10001
|
||||||
@@ -403,7 +477,7 @@ timer:
|
|||||||
## This is an experimental section, please verify before enabling in production.
|
## This is an experimental section, please verify before enabling in production.
|
||||||
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
securityContext:
|
securityContext:
|
||||||
enabled: false
|
enabled: true
|
||||||
## Mark it false, if you want to stop the non root user validation
|
## Mark it false, if you want to stop the non root user validation
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
fsGroup: 10001
|
fsGroup: 10001
|
||||||
@@ -453,14 +527,14 @@ kafka:
|
|||||||
# version: "0.11.2.0"
|
# version: "0.11.2.0"
|
||||||
|
|
||||||
# The following components expose Prometheus metrics and have servicemonitors in this chart (disabled by default)
|
# The following components expose Prometheus metrics and have servicemonitors in this chart (disabled by default)
|
||||||
# Controller, router, executor, storage svc
|
# router, executor, storage svc
|
||||||
serviceMonitor:
|
serviceMonitor:
|
||||||
enabled: false
|
enabled: false
|
||||||
##namespace in which you want to deploy servicemonitor
|
##namespace in which you want to deploy servicemonitor
|
||||||
##
|
##
|
||||||
namespace: ""
|
namespace: ""
|
||||||
## Map of additional lables to add to the ServiceMonitor resources
|
## Map of additional labels to add to the ServiceMonitor resources
|
||||||
# to allow selecting sepcific ServiceMonitors
|
# to allow selecting specific ServiceMonitors
|
||||||
# in case of multiple prometheus deployments
|
# in case of multiple prometheus deployments
|
||||||
additionalServiceMonitorLabels: {}
|
additionalServiceMonitorLabels: {}
|
||||||
# release: "monitoring"
|
# release: "monitoring"
|
||||||
@@ -473,8 +547,8 @@ podMonitor:
|
|||||||
##namespace in which you want to deploy podmonitor
|
##namespace in which you want to deploy podmonitor
|
||||||
##
|
##
|
||||||
namespace: ""
|
namespace: ""
|
||||||
## Map of additional lables to add to the PodMonitor resources
|
## Map of additional labels to add to the PodMonitor resources
|
||||||
# to allow selecting sepcific PodMonitor
|
# to allow selecting specific PodMonitor
|
||||||
# in case of multiple prometheus deployments
|
# in case of multiple prometheus deployments
|
||||||
additionalPodMonitorLabels: {}
|
additionalPodMonitorLabels: {}
|
||||||
# release: "monitoring"
|
# release: "monitoring"
|
||||||
@@ -522,7 +596,7 @@ persistence:
|
|||||||
size: 8Gi
|
size: 8Gi
|
||||||
|
|
||||||
## Extend the container specs for the core fission pods.
|
## Extend the container specs for the core fission pods.
|
||||||
## Can be used to add things like affinty/tolerations/nodeSelectors/etc.
|
## Can be used to add things like affinity/tolerations/nodeSelectors/etc.
|
||||||
## For example:
|
## For example:
|
||||||
## extraCoreComponentPodConfig:
|
## extraCoreComponentPodConfig:
|
||||||
## affinity:
|
## affinity:
|
||||||
@@ -564,11 +638,22 @@ logger:
|
|||||||
|
|
||||||
## Fluent-bit writes/reads it’s own sqlite database to record a history of tracked
|
## Fluent-bit writes/reads it’s own sqlite database to record a history of tracked
|
||||||
## files and a state of offsets, this is very useful to resume a state if the ser-
|
## files and a state of offsets, this is very useful to resume a state if the ser-
|
||||||
## vice is restarted. For Kubernetes environment with constraints like OpenShift,
|
## vice is restarted.
|
||||||
|
##
|
||||||
|
## For Kubernetes environment with constraints like OpenShift,
|
||||||
## the containers are limited to write hostPath volume. Hence, we have to enable
|
## the containers are limited to write hostPath volume. Hence, we have to enable
|
||||||
## security context and set privileged to true.
|
## security context and set privileged to true.
|
||||||
##
|
##
|
||||||
enableSecurityContext: false
|
## The user ID in runAsUser should have access to the `/var/log` and
|
||||||
|
## `/var/lib/docker/containers` directories on your host.
|
||||||
|
## On many hosts, this user might be root ,i.e., `runAsUser: 0`.
|
||||||
|
## Although it is recommended not to use root user for security reasons.
|
||||||
|
##
|
||||||
|
## The `/var/log` and `/var/lib/docker/containers` directories on host are mounted
|
||||||
|
## to logger container with volumeType `HostPath`.
|
||||||
|
securityContext: {}
|
||||||
|
# privileged: true
|
||||||
|
# runAsUser: 0
|
||||||
|
|
||||||
## Enable PodSecurityPolicies to allow privileged container
|
## Enable PodSecurityPolicies to allow privileged container
|
||||||
## Only required in some clusters and when enableSecurityContext is true
|
## Only required in some clusters and when enableSecurityContext is true
|
||||||
@@ -602,12 +687,16 @@ preUpgradeChecks:
|
|||||||
## Run pre-install/pre-upgrade checks if true
|
## Run pre-install/pre-upgrade checks if true
|
||||||
##
|
##
|
||||||
enabled: true
|
enabled: true
|
||||||
|
## Repository for pre-install/pre-upgrade checks image
|
||||||
|
## By default it uses the global repository
|
||||||
|
##
|
||||||
|
repository: ""
|
||||||
## pre-install/pre-upgrade checks live in this image
|
## pre-install/pre-upgrade checks live in this image
|
||||||
##
|
##
|
||||||
image: fission/pre-upgrade-checks
|
image: fission/pre-upgrade-checks
|
||||||
## pre-install/pre-upgrade checks image version
|
## pre-install/pre-upgrade checks image version
|
||||||
##
|
##
|
||||||
imageTag: v1.17.0
|
imageTag: v1.21.0
|
||||||
|
|
||||||
## Fission post-install/post-upgrade reporting live in this image
|
## Fission post-install/post-upgrade reporting live in this image
|
||||||
##
|
##
|
||||||
@@ -627,11 +716,34 @@ prometheus:
|
|||||||
##
|
##
|
||||||
serviceEndpoint: ""
|
serviceEndpoint: ""
|
||||||
|
|
||||||
## set this flag to true if you need canary deployment feature
|
|
||||||
##
|
|
||||||
canaryDeployment:
|
canaryDeployment:
|
||||||
|
## set this flag to true if you need canary deployment feature
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|
||||||
|
## Pod resources as:
|
||||||
|
## resources:
|
||||||
|
## limits:
|
||||||
|
## cpu: <tbd>
|
||||||
|
## memory: <tbd>
|
||||||
|
## requests:
|
||||||
|
## cpu: <tbd>
|
||||||
|
## memory: <tbd>
|
||||||
|
##
|
||||||
|
resources: {}
|
||||||
|
|
||||||
|
## Security Context
|
||||||
|
## It holds pod-level and container level security configuration.
|
||||||
|
## This is an experimental section, please verify before enabling in production.
|
||||||
|
## Ref: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1
|
||||||
|
securityContext:
|
||||||
|
enabled: true
|
||||||
|
## Mark it false, if you want to stop the non root user validation
|
||||||
|
runAsNonRoot: true
|
||||||
|
fsGroup: 10001
|
||||||
|
runAsUser: 10001
|
||||||
|
runAsGroup: 10001
|
||||||
|
|
||||||
## Enable authentication for fission function invocation via Fission router
|
## Enable authentication for fission function invocation via Fission router
|
||||||
##
|
##
|
||||||
authentication:
|
authentication:
|
||||||
@@ -652,7 +764,7 @@ authentication:
|
|||||||
## jwtSigningKey is the signing key used for
|
## jwtSigningKey is the signing key used for
|
||||||
## signing the JWT token
|
## signing the JWT token
|
||||||
##
|
##
|
||||||
jwtSigningKey: serverless
|
jwtSigningKey:
|
||||||
## jwtExpiryTime is the JWT expiry time
|
## jwtExpiryTime is the JWT expiry time
|
||||||
## in seconds
|
## in seconds
|
||||||
## default '120'
|
## default '120'
|
||||||
@@ -715,29 +827,29 @@ mqt_keda:
|
|||||||
enabled: true
|
enabled: true
|
||||||
connector_images:
|
connector_images:
|
||||||
kafka:
|
kafka:
|
||||||
image: fission/keda-kafka-http-connector
|
image: ghcr.io/fission/keda-kafka-http-connector
|
||||||
tag: v0.11
|
tag: v0.17
|
||||||
rabbitmq:
|
rabbitmq:
|
||||||
image: fission/keda-rabbitmq-http-connector
|
image: ghcr.io/fission/keda-rabbitmq-http-connector
|
||||||
tag: v0.10
|
tag: v0.15
|
||||||
awskinesis:
|
awskinesis:
|
||||||
image: fission/keda-aws-kinesis-http-connector
|
image: ghcr.io/fission/keda-aws-kinesis-http-connector
|
||||||
tag: v0.10
|
tag: v0.15
|
||||||
aws_sqs:
|
aws_sqs:
|
||||||
image: fission/keda-aws-sqs-http-connector
|
image: ghcr.io/fission/keda-aws-sqs-http-connector
|
||||||
tag: v0.10
|
tag: v0.16
|
||||||
nats_steaming:
|
nats_steaming:
|
||||||
image: fission/keda-nats-streaming-http-connector
|
image: ghcr.io/fission/keda-nats-streaming-http-connector
|
||||||
tag: v0.12
|
tag: v0.18
|
||||||
nats_jetstream:
|
nats_jetstream:
|
||||||
image: fission/keda-nats-jetstream-http-connector
|
image: ghcr.io/fission/keda-nats-jetstream-http-connector
|
||||||
tag: v0.2
|
tag: v0.9
|
||||||
gcp_pubsub:
|
gcp_pubsub:
|
||||||
image: fission/keda-gcp-pubsub-http-connector
|
image: ghcr.io/fission/keda-gcp-pubsub-http-connector
|
||||||
tag: v0.5
|
tag: v0.11
|
||||||
redis:
|
redis:
|
||||||
image: fission/keda-redis-http-connector
|
image: ghcr.io/fission/keda-redis-http-connector
|
||||||
tag: v0.3
|
tag: v0.8
|
||||||
|
|
||||||
## Pod resources as:
|
## Pod resources as:
|
||||||
## resources:
|
## resources:
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
FROM cgr.dev/chainguard/static:latest@sha256:5497b01f36ef14a5198c0165e50ae6a0006d0c7457d4566f1110257e1c0812ed
|
||||||
|
COPY builder /builder
|
||||||
|
ENTRYPOINT ["/builder"]
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
FROM alpine:3.16
|
|
||||||
RUN apk add --update ca-certificates
|
|
||||||
COPY builder /builder
|
|
||||||
ENTRYPOINT ["/builder"]
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user