* Convert ClusterRoles to Roles for all components for multiple namespaces * Added templates for rules and role generator to dynamically generate roles for each component * Fix role-generator component templating * Enable namespaces variable for preupgradechecks Signed-off-by: Sanket Sudake <sanketsudake@gmail.com> Co-authored-by: shaunak_deshmukh <shaunak@infracloud.io> Co-authored-by: Sanket Sudake <sanketsudake@gmail.com>
49 lines
1.8 KiB
YAML
49 lines
1.8 KiB
YAML
{{- if .Values.preUpgradeChecks.enabled }}
|
|
apiVersion: batch/v1
|
|
kind: Job
|
|
metadata:
|
|
name: {{ template "fullname" . }}-{{ .Chart.Version }}-{{ randNumeric 3 }}
|
|
labels:
|
|
# The "release" convention makes it easy to tie a release to all of the
|
|
# Kubernetes resources that were created as part of that release.
|
|
release: "{{ .Release.Name }}"
|
|
# This makes it easy to audit chart usage.
|
|
chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
app: {{ template "name" . }}
|
|
annotations:
|
|
# This is what defines this resource as a hook. Without this line, the
|
|
# job is considered part of the release.
|
|
"helm.sh/hook": pre-upgrade
|
|
"helm.sh/hook-delete-policy": hook-succeeded
|
|
"helm.sh/hook-weight": "1"
|
|
spec:
|
|
backoffLimit: 0
|
|
template:
|
|
metadata:
|
|
name: {{ template "fullname" . }}
|
|
labels:
|
|
release: "{{ .Release.Name }}"
|
|
app: {{ template "name" . }}
|
|
spec:
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: pre-upgrade-job
|
|
{{- if .Values.preUpgradeChecks.imageTag }}
|
|
image: {{ .Values.preUpgradeChecks.image }}:{{ .Values.preUpgradeChecks.imageTag }}
|
|
{{- else }}
|
|
image: {{ .Values.preUpgradeChecks.image }}
|
|
{{- end }}
|
|
imagePullPolicy: {{ .Values.pullPolicy }}
|
|
command: [ "/pre-upgrade-checks" ]
|
|
args: ["--fn-pod-namespace", "{{ .Values.functionNamespace }}", "--envbuilder-namespace", "{{ .Values.builderNamespace }}"]
|
|
env:
|
|
{{- include "fission-resource-namespace.envs" . | indent 8 }}
|
|
{{- if .Values.terminationMessagePath }}
|
|
terminationMessagePath: {{ .Values.terminationMessagePath }}
|
|
{{- end }}
|
|
{{- if .Values.terminationMessagePolicy }}
|
|
terminationMessagePolicy: {{ .Values.terminationMessagePolicy }}
|
|
{{- end }}
|
|
serviceAccountName: fission-preupgrade
|
|
{{- end }}
|