Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ed9b03c281 | ||
|
|
6d6e25e9a0 | ||
|
|
77f4ce99b2 | ||
|
|
71b1291f8d | ||
|
|
aec148f8d4 | ||
|
|
ee8c472c50 | ||
|
|
e3e6bb4690 | ||
|
|
8dea9bdbde | ||
|
|
09bf89e432 | ||
|
|
4d7532e450 | ||
|
|
8ff445de6f | ||
|
|
7c609948ec | ||
|
|
4029bde2cd | ||
|
|
bed4aff4cc | ||
|
|
e0a8a88243 | ||
|
|
1c3c5d430d | ||
|
|
6e47dc62c2 | ||
|
|
2e9615aa1e | ||
|
|
e2aef8330e | ||
|
|
883baeb16b | ||
|
|
ba1bb878f1 | ||
|
|
45ce8185df | ||
|
|
a55829e5d5 | ||
|
|
54293a0efb | ||
|
|
e506466d08 | ||
|
|
e9750b489e | ||
|
|
0a89fc87a6 | ||
|
|
65a82f706c | ||
|
|
e8f0306ec2 | ||
|
|
f1660c8bd1 | ||
|
|
f967c7d341 | ||
|
|
54072d6a46 | ||
|
|
fb13011aad | ||
|
|
24cb6006f6 | ||
|
|
4c05137fb8 | ||
|
|
07540c29da | ||
|
|
5bb2b2ac87 | ||
|
|
039157d070 | ||
|
|
bb4f4c2eb4 | ||
|
|
97efcab2a2 | ||
|
|
c08c1027a1 | ||
|
|
3d1ecc19f4 | ||
|
|
5d0f91ec13 | ||
|
|
6ab32a42cf | ||
|
|
9718424483 | ||
|
|
d5683adaf8 | ||
|
|
1bc342258a | ||
|
|
79ab6f0b5e | ||
|
|
3822e32755 | ||
|
|
c30d4c174d | ||
|
|
8a5ec6e19c | ||
|
|
d4de2d3c44 | ||
|
|
848cf17d0b | ||
|
|
ae86cb3d13 | ||
|
|
70ec7a5304 | ||
|
|
532be386fc | ||
|
|
0367516203 | ||
|
|
8bad25cbc7 | ||
|
|
f50c029408 | ||
|
|
4f87143719 | ||
|
|
f0a518baf6 | ||
|
|
8224b0b354 | ||
|
|
d42737993f | ||
|
|
a95815561a | ||
|
|
2b0221bbc6 | ||
|
|
36cf9c23ea | ||
|
|
041270ffbe | ||
|
|
9f917231a0 | ||
|
|
cdab3dd538 | ||
|
|
0444ae31db | ||
|
|
e5a24b8918 | ||
|
|
f9792d486e | ||
|
|
dd37ebd440 | ||
|
|
4a1e3c1075 | ||
|
|
4b6eb8df05 | ||
|
|
9fc3738b53 | ||
|
|
e3c2720681 | ||
|
|
23a3266b4a | ||
|
|
e271515385 | ||
|
|
13abaab1b3 | ||
|
|
01bde2cebb | ||
|
|
c696eda50a | ||
|
|
a260ab6873 | ||
|
|
9fa46bea43 | ||
|
|
8ead140541 | ||
|
|
6820981dd5 | ||
|
|
56df3279a6 | ||
|
|
64fb262830 | ||
|
|
5d99553fa6 | ||
|
|
cecf812382 | ||
|
|
3f0fd7f965 | ||
|
|
f27d7b28b8 | ||
|
|
a8da7f9398 | ||
|
|
4720d29fda | ||
|
|
64e4279d96 | ||
|
|
cf61205f49 | ||
|
|
e98c913f86 | ||
|
|
b49d68ca92 | ||
|
|
9638a2b284 | ||
|
|
4fc20de72e | ||
|
|
6fff7cb485 | ||
|
|
6baf3a174d | ||
|
|
ed72dc12b2 | ||
|
|
3fa60853a2 | ||
|
|
f8bbe9f55a | ||
|
|
c7c7171110 | ||
|
|
b7370d0e48 | ||
|
|
0b37f76225 | ||
|
|
e6e1025206 | ||
|
|
a5d5028dae | ||
|
|
413b7003a2 | ||
|
|
7b02b5df04 | ||
|
|
a5211fe511 | ||
|
|
fcbf394272 | ||
|
|
7bf49c207a | ||
|
|
3c70598704 | ||
|
|
80a9e8c156 | ||
|
|
dc0e86b823 | ||
|
|
07b8120788 | ||
|
|
a6e7a1bec3 | ||
|
|
809491bce0 | ||
|
|
5e66b6aeb0 | ||
|
|
c6fe038fe4 | ||
|
|
49d7a566b2 | ||
|
|
3cf912c998 | ||
|
|
0dbf3ddff8 | ||
|
|
af16e9e73f | ||
|
|
154b801cfc | ||
|
|
a8acae4af5 | ||
|
|
6e31feaa20 | ||
|
|
a53a10ad33 | ||
|
|
d5a3cb7519 | ||
|
|
ed6ac1a11a | ||
|
|
b5d81b8e5d | ||
|
|
3abeec518a | ||
|
|
d2c4b9c8a4 | ||
|
|
2ad1d25120 | ||
|
|
26e72b4e1d | ||
|
|
3434cbef96 | ||
|
|
256d84a42a | ||
|
|
03cfe14c07 | ||
|
|
82c7dd2f44 | ||
|
|
818b3682fa | ||
|
|
ffba1b4712 | ||
|
|
dba934daa0 | ||
|
|
d0827ba426 | ||
|
|
16b2f2a34f | ||
|
|
607a7ca58c | ||
|
|
d11d66e81d | ||
|
|
7a937b0932 | ||
|
|
e1c0e33b4f | ||
|
|
cf905ca5d0 | ||
|
|
630a5ee1f3 | ||
|
|
3d78e90ab1 | ||
|
|
3981e6ba5e | ||
|
|
ac682a9c05 | ||
|
|
7bdf48ffc0 | ||
|
|
fc11db4ece | ||
|
|
148309325e | ||
|
|
82756ebfe7 | ||
|
|
a9cee5f4da | ||
|
|
5f3d9ed96f | ||
|
|
1eb8501430 | ||
|
|
ecbb16960f | ||
|
|
368f786244 | ||
|
|
e4fe1ee214 | ||
|
|
0d1fa239a5 | ||
|
|
8a51fe9285 | ||
|
|
33c64d5695 | ||
|
|
a534c856db | ||
|
|
acda72558f | ||
|
|
9e2eb16b67 | ||
|
|
6b02c2c53b | ||
|
|
0ca3f1a7c4 | ||
|
|
69474557eb | ||
|
|
48e3a96305 | ||
|
|
da7e227f71 | ||
|
|
98d5ac126d | ||
|
|
cb5db01406 | ||
|
|
494384c1d7 | ||
|
|
34c2e48e0a | ||
|
|
122995fda7 | ||
|
|
9761c78fe9 | ||
|
|
062c7153c6 | ||
|
|
6ef4aed024 | ||
|
|
3fe42ed4b9 | ||
|
|
2ff1d35b6d | ||
|
|
d3934d9e08 | ||
|
|
3c8ce3718a | ||
|
|
66f03c3c16 | ||
|
|
7e2c2bf92c | ||
|
|
7b95f03a30 | ||
|
|
b0cb1cc07d | ||
|
|
5be4c13016 | ||
|
|
07427be0b7 | ||
|
|
c23bc68900 | ||
|
|
582701d949 | ||
|
|
b6b3b6c0ab | ||
|
|
25a6c3c48a | ||
|
|
c67289d2cf | ||
|
|
d0c7f343b2 | ||
|
|
ef17865f12 | ||
|
|
d5fd5d3819 | ||
|
|
a61ed18147 | ||
|
|
e3e3da0e0e | ||
|
|
1470779b8f | ||
|
|
400df47678 | ||
|
|
0f0ff32bf6 | ||
|
|
a9245454a4 | ||
|
|
bba8b8e2b5 | ||
|
|
93c5e4a0c3 | ||
|
|
06c0dd96d0 | ||
|
|
e6b11084db | ||
|
|
669fe1d253 | ||
|
|
e4cfa2f809 | ||
|
|
7251961bcc | ||
|
|
3a5fbb0b06 | ||
|
|
a69ca7f8b5 | ||
|
|
0fb252b6e4 | ||
|
|
718e5cfcb9 | ||
|
|
a8153d5ffb | ||
|
|
7b0a68c2f4 | ||
|
|
1c89044be4 | ||
|
|
15ed13dd8d | ||
|
|
f2ad70678c | ||
|
|
2ec77f1e7e | ||
|
|
aa7d0b9918 | ||
|
|
38209f9720 | ||
|
|
0ba4feaf7a | ||
|
|
d4c1fda066 | ||
|
|
0d97183bbf | ||
|
|
293f0158e0 | ||
|
|
bb30b3b9fe | ||
|
|
39bebe64ba | ||
|
|
5bd84b3d3e | ||
|
|
76e315d191 | ||
|
|
dd022258b5 | ||
|
|
019fa3d356 | ||
|
|
4a968aa605 | ||
|
|
92639c1e89 | ||
|
|
a7cfbe23da | ||
|
|
16a2b590d6 | ||
|
|
8518e0d1c7 | ||
|
|
6bc101af3e | ||
|
|
31e1914db6 | ||
|
|
aee1b464ed | ||
|
|
61921d40ed | ||
|
|
b5f2c19470 | ||
|
|
8d91a67078 | ||
|
|
3df613346c | ||
|
|
b559e836e4 | ||
|
|
ea5fb823f9 | ||
|
|
4c5429190c | ||
|
|
22a05e8887 | ||
|
|
7012a6acfc | ||
|
|
1dc64b551c | ||
|
|
c949d6e58d | ||
|
|
0e0f413e82 | ||
|
|
7935873746 | ||
|
|
a57b9e0475 | ||
|
|
39eee1370b | ||
|
|
48dcb08c78 | ||
|
|
d60fddebca | ||
|
|
ffd1a4b2ab | ||
|
|
8391ed3501 | ||
|
|
3b2a218419 | ||
|
|
71362dd3d4 | ||
|
|
3188cd2889 | ||
|
|
bf3965eac7 | ||
|
|
7953d424f0 | ||
|
|
dc2599b0b9 | ||
|
|
93a7878ab7 | ||
|
|
3a1b763522 | ||
|
|
fcc25b1835 | ||
|
|
470c7c392b | ||
|
|
6e487ed29e | ||
|
|
7f4dfbc0a1 | ||
|
|
c9ab99385a | ||
|
|
ef7703563b | ||
|
|
7f6ed97fd5 | ||
|
|
45f7545f41 | ||
|
|
4b8f371095 | ||
|
|
822b3a439f | ||
|
|
cfb5048f85 | ||
|
|
43c1f396c3 | ||
|
|
cbdbeb790b | ||
|
|
d61a01321f | ||
|
|
3afe1df555 | ||
|
|
b18d59f118 | ||
|
|
1d72a97ac8 | ||
|
|
a8d2831b1c | ||
|
|
213c1bebc4 | ||
|
|
ca6666d271 | ||
|
|
56d1966397 | ||
|
|
fcc09673cc | ||
|
|
b1655479d2 | ||
|
|
a5e29aefec | ||
|
|
4d20079cfe | ||
|
|
645f3a7cf8 | ||
|
|
b65457a056 | ||
|
|
72bf56946f | ||
|
|
a62487b58b | ||
|
|
aa78813d73 | ||
|
|
a08c9104a9 | ||
|
|
5da4b697f1 | ||
|
|
f99a83c137 | ||
|
|
721d6814ca | ||
|
|
866acb3d9c | ||
|
|
94dc52d224 | ||
|
|
c0cd78899a | ||
|
|
3b54fa8675 | ||
|
|
4a869998d1 | ||
|
|
bc044431ab | ||
|
|
4fe482b77b | ||
|
|
194340688d | ||
|
|
b517b0a2a6 | ||
|
|
1dc56803e8 | ||
|
|
85da1aa1f3 | ||
|
|
6378836706 | ||
|
|
e829dafbd2 | ||
|
|
1023718b87 | ||
|
|
4a5141933c | ||
|
|
084841f549 | ||
|
|
76ab4a8342 | ||
|
|
2d6aa5815f | ||
|
|
d69b57c014 | ||
|
|
562a171de6 | ||
|
|
2118c6f49c | ||
|
|
9c759bfe88 | ||
|
|
d0205f4e5e | ||
|
|
d914edf3e0 | ||
|
|
be4fd1364c | ||
|
|
599b1e387d | ||
|
|
732ff9c02c | ||
|
|
d0e30a6878 | ||
|
|
a213b60008 | ||
|
|
768327ea3b | ||
|
|
4908ecfd5d | ||
|
|
e1e97a1bbf | ||
|
|
e54215863c | ||
|
|
0c2f45569c | ||
|
|
cde24806cf | ||
|
|
5a3b2179bc | ||
|
|
faf51c8b24 | ||
|
|
9bdbf4bacb | ||
|
|
d4015546db | ||
|
|
10df62ff7b | ||
|
|
a2a35d0a40 | ||
|
|
4589e2849d | ||
|
|
1456d24ff5 | ||
|
|
b5e630d0b5 | ||
|
|
4104e7d912 | ||
|
|
2f7297f5f5 | ||
|
|
073e6cff0a | ||
|
|
910f1eeb36 | ||
|
|
bba532e2e5 | ||
|
|
fee2289753 | ||
|
|
c5520d4c61 | ||
|
|
25e7f5a8f2 | ||
|
|
d4e12dff8f | ||
|
|
c4d9970111 | ||
|
|
34f48713a4 | ||
|
|
8d2d44dc6d | ||
|
|
2f59796caa | ||
|
|
4a6d1855dc | ||
|
|
cd3bfbef96 | ||
|
|
02328076e5 | ||
|
|
4bec3f7098 | ||
|
|
b7e6987aec | ||
|
|
7218e42771 | ||
|
|
25dfc97047 | ||
|
|
1106ef54ee | ||
|
|
6fd5ca918b | ||
|
|
942cce05e7 | ||
|
|
c2f0c214eb | ||
|
|
a0fdf653fb | ||
|
|
5894a4ad25 | ||
|
|
3c0ea07a55 | ||
|
|
84b766ac40 | ||
|
|
41e84be0d3 | ||
|
|
d40683cbb9 | ||
|
|
918e487422 | ||
|
|
6192cab653 | ||
|
|
c1bbd85ea9 | ||
|
|
d9f3a428d4 | ||
|
|
ebc040fe75 | ||
|
|
12e51ad9ad | ||
|
|
6477468729 | ||
|
|
19461fa86c | ||
|
|
2b3fd833a3 | ||
|
|
c76ad2cff1 | ||
|
|
aa673de25d | ||
|
|
f1512e9405 | ||
|
|
d853e050cd | ||
|
|
9f0c5c8ba9 | ||
|
|
1d34d86f32 | ||
|
|
7164c412f0 | ||
|
|
a8a05bb113 | ||
|
|
bf91f32f79 | ||
|
|
ef10b06be5 | ||
|
|
1e453aefd3 | ||
|
|
71b950c243 | ||
|
|
b00137cc3e | ||
|
|
2cc398d8d4 | ||
|
|
5c91bbd65e | ||
|
|
88b1a8c125 | ||
|
|
6fd969633e | ||
|
|
9c788ba3bd | ||
|
|
c2fd14e39a | ||
|
|
6513e93e7f | ||
|
|
d0f4898aaa | ||
|
|
3d849d9179 | ||
|
|
fe77f1deae | ||
|
|
9156909023 | ||
|
|
03e3b68eeb | ||
|
|
6cae8dfa32 | ||
|
|
b1ecc89759 | ||
|
|
bb85b31411 | ||
|
|
7e7c23e176 | ||
|
|
8442cc7ae8 | ||
|
|
3faf76d7c9 | ||
|
|
61ef5ef005 | ||
|
|
86043361c6 | ||
|
|
06194960e9 | ||
|
|
46da413585 | ||
|
|
b5f255cf00 | ||
|
|
f328b0adb6 | ||
|
|
1bfd3b2028 | ||
|
|
edf01f009e | ||
|
|
a3c28be98a | ||
|
|
49d1f00dbd | ||
|
|
81939cb521 | ||
|
|
6b10a8141c | ||
|
|
1ef1f00b3d | ||
|
|
ce48812921 | ||
|
|
336ea58a0a | ||
|
|
f042cb3d00 | ||
|
|
94d68bf382 | ||
|
|
b3a74362af | ||
|
|
ad531c8dce | ||
|
|
e589ceb661 | ||
|
|
234a10d185 | ||
|
|
e0fa1610ca | ||
|
|
5a856eeba8 | ||
|
|
d26a6bf641 | ||
|
|
8d6db0934f | ||
|
|
c1b2e73123 | ||
|
|
6ac8668ead | ||
|
|
d0516bcdc1 | ||
|
|
ac5a2538bc | ||
|
|
2bdc87d0a8 | ||
|
|
ab566c2530 | ||
|
|
6a7c3ca2de | ||
|
|
f6f58d5c6d | ||
|
|
b1a547d2a6 | ||
|
|
43f98eda77 | ||
|
|
007e47e35c | ||
|
|
21eb83b052 | ||
|
|
1f8414b8cb | ||
|
|
a199a8c104 | ||
|
|
fb1639a5d4 | ||
|
|
19c6c77c41 | ||
|
|
4ee523ed69 | ||
|
|
4c5bae69ef | ||
|
|
9bf896e37c | ||
|
|
cb50f4f3ac | ||
|
|
066e55e179 | ||
|
|
f35bd7cf83 | ||
|
|
95a1fc082b | ||
|
|
dbd1e59a55 | ||
|
|
61f45147f6 | ||
|
|
c20f9b4128 | ||
|
|
15568fe564 | ||
|
|
1baf417504 | ||
|
|
7fbf1c42aa | ||
|
|
a5e21b56ae | ||
|
|
1399504142 | ||
|
|
e5896d15ed | ||
|
|
6b01ff09ce | ||
|
|
c708cef4dc | ||
|
|
1cf466def2 | ||
|
|
0fc145b6aa | ||
|
|
e30d26cf7b | ||
|
|
7c4a731995 | ||
|
|
d2efea08e6 | ||
|
|
23e94f82c0 | ||
|
|
de2e58f222 | ||
|
|
1c7c89efb3 | ||
|
|
096fe100f7 | ||
|
|
58ee2f0c74 | ||
|
|
93f7484f38 | ||
|
|
225c47dbbc | ||
|
|
2daf8a1320 | ||
|
|
5772c706d3 | ||
|
|
ae0a74bea3 | ||
|
|
97cd7a9b7a | ||
|
|
0975663a52 | ||
|
|
efdbd61860 | ||
|
|
13b45cbb12 | ||
|
|
d3ca9c57c9 | ||
|
|
9b1b5e676d | ||
|
|
17eb9cf8e8 | ||
|
|
ed7e2b2a28 | ||
|
|
5b7589accd | ||
|
|
a1e289e189 | ||
|
|
0611f3efaa | ||
|
|
a94a6f045d | ||
|
|
1892b8f0ea | ||
|
|
57b5795aab | ||
|
|
e8096a5f33 | ||
|
|
271bce48bd | ||
|
|
d64c34f8a4 | ||
|
|
1bddb98476 | ||
|
|
5f183999d0 | ||
|
|
3769897131 | ||
|
|
7f86231009 | ||
|
|
f59dac829a | ||
|
|
edecf4d2fe | ||
|
|
4120b5e2b0 | ||
|
|
8dabca5418 | ||
|
|
1d341a21d0 | ||
|
|
f8719db954 | ||
|
|
89425826e8 | ||
|
|
5c572a9ba6 | ||
|
|
b7bbfd432d | ||
|
|
b17cd16fb7 | ||
|
|
dc6cbab501 | ||
|
|
a81be586db | ||
|
|
f2a9e967cc | ||
|
|
9f017d03e6 | ||
|
|
7d2d1b3c5e | ||
|
|
5d0ebd0121 | ||
|
|
f368a539a9 | ||
|
|
0aef4cc35f | ||
|
|
e3701dd3db | ||
|
|
cf98edc282 | ||
|
|
58a4778c89 | ||
|
|
8e50bdde9b | ||
|
|
60386bc928 | ||
|
|
f1df88dc53 | ||
|
|
8de6179ac7 | ||
|
|
8a3c8e727a | ||
|
|
c230016819 | ||
|
|
bea05c97ee | ||
|
|
ba3b6f5436 |
@@ -0,0 +1,23 @@
|
|||||||
|
version: 2
|
||||||
|
updates:
|
||||||
|
- package-ecosystem: "pip"
|
||||||
|
directory: "/docs"
|
||||||
|
groups:
|
||||||
|
dependencies:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
labels:
|
||||||
|
- "component:docs"
|
||||||
|
- "dependencies"
|
||||||
|
- package-ecosystem: "github-actions"
|
||||||
|
directory: "/"
|
||||||
|
groups:
|
||||||
|
dependencies:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
labels:
|
||||||
|
- "dependencies"
|
||||||
+33
-48
@@ -4,21 +4,24 @@ name: CI
|
|||||||
|
|
||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
branches: [devel]
|
|
||||||
|
|
||||||
push:
|
push:
|
||||||
branches: [devel]
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
molecule:
|
molecule:
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-latest
|
||||||
name: molecule
|
name: molecule
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
ansible_args:
|
||||||
|
- --skip-tags=replicas
|
||||||
|
- -t replicas
|
||||||
env:
|
env:
|
||||||
DOCKER_API_VERSION: "1.38"
|
DOCKER_API_VERSION: "1.41"
|
||||||
|
DEBUG_OUTPUT_DIR: /tmp/awx_operator_molecule_test
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- uses: actions/setup-python@v2
|
- uses: actions/setup-python@v5
|
||||||
with:
|
with:
|
||||||
python-version: "3.8"
|
python-version: "3.8"
|
||||||
|
|
||||||
@@ -35,50 +38,32 @@ jobs:
|
|||||||
MOLECULE_VERBOSITY: 3
|
MOLECULE_VERBOSITY: 3
|
||||||
PY_COLORS: '1'
|
PY_COLORS: '1'
|
||||||
ANSIBLE_FORCE_COLOR: '1'
|
ANSIBLE_FORCE_COLOR: '1'
|
||||||
|
STORE_DEBUG_OUTPUT: true
|
||||||
run: |
|
run: |
|
||||||
sudo rm -f $(which kustomize)
|
sudo rm -f $(which kustomize)
|
||||||
make kustomize
|
make kustomize
|
||||||
KUSTOMIZE_PATH=$(readlink -f bin/kustomize) molecule test -s kind
|
KUSTOMIZE_PATH=$(readlink -f bin/kustomize) molecule test -s kind -- ${{ matrix.ansible_args }}
|
||||||
helm:
|
|
||||||
runs-on: ubuntu-18.04
|
- name: Upload artifacts for failed tests if Run Molecule fails
|
||||||
name: helm
|
if: failure()
|
||||||
steps:
|
uses: actions/upload-artifact@v4
|
||||||
- uses: actions/checkout@v2
|
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
name: awx_operator_molecule_test
|
||||||
|
path: ${{ env.DEBUG_OUTPUT_DIR }}
|
||||||
|
no-log:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout sources
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Create k8s Kind Cluster
|
- name: Check no_log statements
|
||||||
uses: helm/[email protected]
|
|
||||||
|
|
||||||
- name: Build operator image and load into kind
|
|
||||||
run: |
|
run: |
|
||||||
IMG=awx-operator-ci make docker-build
|
set +e
|
||||||
kind load docker-image --name chart-testing awx-operator-ci
|
no_log=$(grep -nr ' no_log:' roles | grep -v '"{{ no_log }}"')
|
||||||
|
if [ -n "${no_log}" ]; then
|
||||||
- name: Patch pull policy for tests
|
echo 'Please update the following no_log statement(s) with the "{{ no_log }}" value'
|
||||||
run: |
|
echo "${no_log}"
|
||||||
kustomize edit add patch --path ../testing/pull_policy/Never.yaml
|
exit 1
|
||||||
working-directory: config/default
|
fi
|
||||||
|
nox-sessions:
|
||||||
- name: Build and lint helm chart
|
uses: ./.github/workflows/reusable-nox.yml
|
||||||
run: |
|
|
||||||
IMG=awx-operator-ci make helm-chart
|
|
||||||
helm lint ./charts/awx-operator
|
|
||||||
|
|
||||||
- name: Install kubeval
|
|
||||||
run: |
|
|
||||||
mkdir tmp && cd tmp
|
|
||||||
wget https://github.com/instrumenta/kubeval/releases/latest/download/kubeval-linux-amd64.tar.gz
|
|
||||||
tar xf kubeval-linux-amd64.tar.gz
|
|
||||||
sudo cp kubeval /usr/local/bin
|
|
||||||
working-directory: ./charts
|
|
||||||
|
|
||||||
- name: Run kubeval
|
|
||||||
run: |
|
|
||||||
helm template -n awx awx-operator > tmp/test.yaml
|
|
||||||
kubeval --strict --force-color --ignore-missing-schemas tmp/test.yaml
|
|
||||||
working-directory: ./charts
|
|
||||||
|
|
||||||
- name: Install helm chart
|
|
||||||
run: |
|
|
||||||
helm install --wait my-awx-operator --namespace awx --create-namespace ./charts/awx-operator
|
|
||||||
|
|||||||
@@ -0,0 +1,124 @@
|
|||||||
|
name: CI
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [ main ]
|
||||||
|
pull_request:
|
||||||
|
branches: [ main ]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
lint:
|
||||||
|
name: Lint scripts & YAML
|
||||||
|
runs-on: ${{ matrix.os }}
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
os: [ubuntu-22.04, ubuntu-20.04]
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Install linters
|
||||||
|
run: |
|
||||||
|
sudo apt-get update -y
|
||||||
|
sudo apt-get install -y shellcheck yamllint gettext-base curl ca-certificates
|
||||||
|
|
||||||
|
- name: Shellcheck - scan shell scripts
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
files=$(git ls-files 'awx-local-setup/*.sh' || true)
|
||||||
|
if [ -n "$files" ]; then
|
||||||
|
echo "Running shellcheck on: $files"
|
||||||
|
shellcheck -x $files
|
||||||
|
else
|
||||||
|
echo "No shell scripts found to lint"
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Shell syntax check
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
for f in awx-local-setup/*.sh; do
|
||||||
|
[ -f "$f" ] || continue
|
||||||
|
echo "Checking bash syntax: $f"
|
||||||
|
bash -n "$f"
|
||||||
|
done
|
||||||
|
|
||||||
|
- name: YAML lint
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
files=$(git ls-files '*.yml' '*.yaml' || true)
|
||||||
|
if [ -n "$files" ]; then
|
||||||
|
echo "$files" | xargs yamllint -d "extends: default"
|
||||||
|
else
|
||||||
|
echo "No YAML files found to lint"
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Dry-run setup script
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
chmod +x awx-local-setup/setup_awx_local.sh
|
||||||
|
./awx-local-setup/setup_awx_local.sh --dry-run --repo-root="$(pwd)"
|
||||||
|
|
||||||
|
kustomize-validate:
|
||||||
|
name: Validate kustomize builds (if any)
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Install kustomize and kubectl
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
if ! command -v kustomize >/dev/null 2>&1; then
|
||||||
|
curl -sSL "https://raw.githubusercontent.com/kubernetes-sigs/kustomize/master/hack/install_kustomize.sh" | bash -s 5.0.0
|
||||||
|
sudo mv kustomize /usr/local/bin/kustomize || true
|
||||||
|
fi
|
||||||
|
if ! command -v kubectl >/dev/null 2>&1; then
|
||||||
|
curl -sSL -o kubectl https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl
|
||||||
|
chmod +x kubectl
|
||||||
|
sudo mv kubectl /usr/local/bin/kubectl
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Run kustomize build for known directories
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
ok=true
|
||||||
|
for d in config config/*; do
|
||||||
|
if [ -d "$d" ] && ( [ -f "$d/kustomization.yaml" ] || [ -f "$d/kustomization.yml" ] ); then
|
||||||
|
echo "Building kustomize for $d"
|
||||||
|
kustomize build "$d" >/dev/null || { ok=false; echo "kustomize build failed for $d"; }
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
$ok || (echo "One or more kustomize builds failed" && exit 1)
|
||||||
|
|
||||||
|
- name: Kustomize -> kubectl --dry-run=client validation
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
any=false
|
||||||
|
for d in config config/*; do
|
||||||
|
if [ -d "$d" ] && ( [ -f "$d/kustomization.yaml" ] || [ -f "$d/kustomization.yml" ] ); then
|
||||||
|
echo "Validating manifests from $d with kubectl --dry-run=client"
|
||||||
|
kustomize build "$d" | kubectl apply --dry-run=client -f - || { echo "kubectl --dry-run failed for $d"; exit 1; }
|
||||||
|
any=true
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
if [ "$any" = false ]; then
|
||||||
|
echo "No kustomize directories found to validate with kubectl"
|
||||||
|
fi
|
||||||
|
|
||||||
|
release:
|
||||||
|
name: Create release artifact
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
needs: [lint, kustomize-validate]
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Create tarball
|
||||||
|
run: |
|
||||||
|
tar -czf awx-local-setup.tar.gz awx-local-setup
|
||||||
|
|
||||||
|
- name: Upload artifact
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: awx-local-setup
|
||||||
|
path: awx-local-setup.tar.gz
|
||||||
@@ -8,20 +8,41 @@ on:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
release:
|
release:
|
||||||
runs-on: ubuntu-18.04
|
runs-on: ubuntu-latest
|
||||||
name: Push devel image
|
name: Push devel image
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Build Image
|
- name: Fail if QUAY_REGISTRY not set
|
||||||
run: |
|
run: |
|
||||||
IMG=awx-operator:devel make docker-build
|
if [[ -z "${{ vars.QUAY_REGISTRY }}" ]]; then
|
||||||
|
echo "QUAY_REGISTRY not set. Please set QUAY_REGISTRY in variable GitHub Actions variables."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Push To Quay
|
- name: Log into registry ghcr.io
|
||||||
uses: redhat-actions/[email protected]
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
with:
|
with:
|
||||||
image: awx-operator
|
registry: ghcr.io
|
||||||
tags: devel
|
username: ${{ github.actor }}
|
||||||
registry: quay.io/ansible/
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
|
|
||||||
|
- name: Log into registry quay.io
|
||||||
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
|
with:
|
||||||
|
registry: ${{ vars.QUAY_REGISTRY }}
|
||||||
username: ${{ secrets.QUAY_USER }}
|
username: ${{ secrets.QUAY_USER }}
|
||||||
password: ${{ secrets.QUAY_TOKEN }}
|
password: ${{ secrets.QUAY_TOKEN }}
|
||||||
|
|
||||||
|
|
||||||
|
- name: Build and Store Image @ghcr
|
||||||
|
run: |
|
||||||
|
IMG=ghcr.io/${{ github.repository }}:${{ github.sha }} make docker-buildx
|
||||||
|
|
||||||
|
|
||||||
|
- name: Publish Image to quay.io
|
||||||
|
run: |
|
||||||
|
docker buildx imagetools create \
|
||||||
|
ghcr.io/${{ github.repository }}:${{ github.sha }} \
|
||||||
|
--tag ${{ vars.QUAY_REGISTRY }}/awx-operator:devel
|
||||||
|
|||||||
@@ -0,0 +1,56 @@
|
|||||||
|
---
|
||||||
|
|
||||||
|
name: Feature Branch Image Build and Push
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [feature_*]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
release:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Push devel image
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0 # needed so that git describe --tag works
|
||||||
|
|
||||||
|
- name: Set VERSION
|
||||||
|
run: |
|
||||||
|
echo "VERSION=$(git describe --tags)" >>${GITHUB_ENV}
|
||||||
|
|
||||||
|
- name: Set lower case owner name
|
||||||
|
run: |
|
||||||
|
echo "OWNER_LC=${OWNER,,}" >>${GITHUB_ENV}
|
||||||
|
env:
|
||||||
|
OWNER: '${{ github.repository_owner }}'
|
||||||
|
|
||||||
|
- name: Set IMAGE_TAG_BASE
|
||||||
|
run: |
|
||||||
|
echo "IMAGE_TAG_BASE=ghcr.io/${OWNER_LC}/awx-operator" >>${GITHUB_ENV}
|
||||||
|
|
||||||
|
- name: Log in to registry
|
||||||
|
run: |
|
||||||
|
echo "${{ secrets.GITHUB_TOKEN }}" | docker login ghcr.io -u ${{ github.actor }} --password-stdin
|
||||||
|
|
||||||
|
- name: Build and Push awx-operator Image
|
||||||
|
run: |
|
||||||
|
make docker-build docker-push
|
||||||
|
docker tag ${IMAGE_TAG_BASE}:${VERSION} ${IMAGE_TAG_BASE}:${GITHUB_REF##*/}
|
||||||
|
docker push ${IMAGE_TAG_BASE}:${GITHUB_REF##*/}
|
||||||
|
|
||||||
|
- name: Build bundle manifests
|
||||||
|
run: |
|
||||||
|
make bundle
|
||||||
|
|
||||||
|
- name: Build and Push awx-operator Bundle
|
||||||
|
run: |
|
||||||
|
make bundle-build bundle-push
|
||||||
|
docker tag ${IMAGE_TAG_BASE}-bundle:v${VERSION} ${IMAGE_TAG_BASE}-bundle:${GITHUB_REF##*/}
|
||||||
|
docker push ${IMAGE_TAG_BASE}-bundle:${GITHUB_REF##*/}
|
||||||
|
|
||||||
|
- name: Build and Push awx-operator Catalog
|
||||||
|
run: |
|
||||||
|
make catalog-build catalog-push
|
||||||
|
docker tag ${IMAGE_TAG_BASE}-catalog:v${VERSION} ${IMAGE_TAG_BASE}-catalog:${GITHUB_REF##*/}
|
||||||
|
docker push ${IMAGE_TAG_BASE}-catalog:${GITHUB_REF##*/}
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
---
|
||||||
|
name: Label Issues
|
||||||
|
|
||||||
|
on:
|
||||||
|
issues:
|
||||||
|
types:
|
||||||
|
- opened
|
||||||
|
- reopened
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
triage:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Label
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Label Issue - Needs Triage
|
||||||
|
uses: github/[email protected]
|
||||||
|
with:
|
||||||
|
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
||||||
|
not-before: 2021-12-07T07:00:00Z
|
||||||
|
configuration-path: .github/issue_labeler.yml
|
||||||
|
enable-versioned-regex: 0
|
||||||
|
if: github.event_name == 'issues'
|
||||||
|
|
||||||
|
community:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Label Issue - Community
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-python@v5
|
||||||
|
- name: Install python requests
|
||||||
|
run: pip install requests
|
||||||
|
- name: Check if user is a member of Ansible org
|
||||||
|
uses: jannekem/run-python-script-action@v1
|
||||||
|
id: check_user
|
||||||
|
with:
|
||||||
|
script: |
|
||||||
|
import requests
|
||||||
|
headers = {'Accept': 'application/vnd.github+json', 'Authorization': 'token ${{ secrets.GITHUB_TOKEN }}'}
|
||||||
|
response = requests.get('${{ fromJson(toJson(github.event.issue.user.url)) }}/orgs?per_page=100', headers=headers)
|
||||||
|
is_member = False
|
||||||
|
for org in response.json():
|
||||||
|
if org['login'] == 'ansible':
|
||||||
|
is_member = True
|
||||||
|
if is_member:
|
||||||
|
print("User is member")
|
||||||
|
else:
|
||||||
|
print("User is community")
|
||||||
|
- name: Add community label if not a member
|
||||||
|
if: contains(steps.check_user.outputs.stdout, 'community')
|
||||||
|
uses: andymckay/labeler@e6c4322d0397f3240f0e7e30a33b5c5df2d39e90
|
||||||
|
with:
|
||||||
|
add-labels: "community"
|
||||||
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
name: Label PR
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request_target:
|
||||||
|
types:
|
||||||
|
- opened
|
||||||
|
- reopened
|
||||||
|
- synchronize
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
community:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
name: Label PR - Community
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- uses: actions/setup-python@v5
|
||||||
|
|
||||||
|
- name: Create a virtual environment
|
||||||
|
run: python3 -m venv venv
|
||||||
|
|
||||||
|
- name: Activate virtual environment and install dependencies
|
||||||
|
run: |
|
||||||
|
source venv/bin/activate
|
||||||
|
pip3 install requests
|
||||||
|
|
||||||
|
- name: Check if user is a member of Ansible org
|
||||||
|
uses: jannekem/run-python-script-action@v1
|
||||||
|
id: check_user
|
||||||
|
with:
|
||||||
|
script: |
|
||||||
|
import requests
|
||||||
|
headers = {'Accept': 'application/vnd.github+json', 'Authorization': 'token ${{ secrets.GITHUB_TOKEN }}'}
|
||||||
|
response = requests.get('${{ fromJson(toJson(github.event.pull_request.user.url)) }}/orgs?per_page=100', headers=headers)
|
||||||
|
is_member = False
|
||||||
|
for org in response.json():
|
||||||
|
if org['login'] == 'ansible':
|
||||||
|
is_member = True
|
||||||
|
if is_member:
|
||||||
|
print("User is member")
|
||||||
|
else:
|
||||||
|
print("User is community")
|
||||||
|
|
||||||
|
- name: Add community label if not a member
|
||||||
|
if: contains(steps.check_user.outputs.stdout, 'community')
|
||||||
|
uses: andymckay/labeler@e6c4322d0397f3240f0e7e30a33b5c5df2d39e90
|
||||||
|
with:
|
||||||
|
add-labels: "community"
|
||||||
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
@@ -13,21 +13,13 @@ jobs:
|
|||||||
packages: write
|
packages: write
|
||||||
contents: read
|
contents: read
|
||||||
steps:
|
steps:
|
||||||
- name: Write PR body to a file
|
|
||||||
run: |
|
|
||||||
cat >> pr.body << __SOME_RANDOM_PR_EOF__
|
|
||||||
${{ github.event.pull_request.body }}
|
|
||||||
__SOME_RANDOM_PR_EOF__
|
|
||||||
|
|
||||||
- name: Display the received body for troubleshooting
|
|
||||||
run: cat pr.body
|
|
||||||
|
|
||||||
# We want to write these out individually just incase the options were joined on a single line
|
|
||||||
- name: Check for each of the lines
|
- name: Check for each of the lines
|
||||||
|
env:
|
||||||
|
PR_BODY: ${{ github.event.pull_request.body }}
|
||||||
run: |
|
run: |
|
||||||
grep "Bug, Docs Fix or other nominal change" pr.body > Z
|
echo "$PR_BODY" | grep "Bug, Docs Fix or other nominal change" > Z
|
||||||
grep "New or Enhanced Feature" pr.body > Y
|
echo "$PR_BODY" | grep "New or Enhanced Feature" > Y
|
||||||
grep "Breaking Change" pr.body > X
|
echo "$PR_BODY" | grep "Breaking Change" > X
|
||||||
exit 0
|
exit 0
|
||||||
# We exit 0 and set the shell to prevent the returns from the greps from failing this step
|
# We exit 0 and set the shell to prevent the returns from the greps from failing this step
|
||||||
# See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference
|
# See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference
|
||||||
|
|||||||
@@ -3,38 +3,70 @@ name: Promote AWX Operator image
|
|||||||
on:
|
on:
|
||||||
release:
|
release:
|
||||||
types: [published]
|
types: [published]
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
tag_name:
|
||||||
|
description: 'Name for the tag of the release.'
|
||||||
|
required: true
|
||||||
|
quay_registry:
|
||||||
|
description: 'Quay registry to push to.'
|
||||||
|
default: 'quay.io/ansible'
|
||||||
|
|
||||||
|
env:
|
||||||
|
QUAY_REGISTRY: ${{ vars.QUAY_REGISTRY }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
promote:
|
promote:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2
|
- name: Set GitHub Env vars for workflow_dispatch event
|
||||||
|
if: ${{ github.event_name == 'workflow_dispatch' }}
|
||||||
- name: Log in to GHCR
|
|
||||||
run: |
|
run: |
|
||||||
echo ${{ secrets.GITHUB_TOKEN }} | docker login ghcr.io -u ${{ github.actor }} --password-stdin
|
echo "TAG_NAME=${{ github.event.inputs.tag_name }}" >> $GITHUB_ENV
|
||||||
|
echo "QUAY_REGISTRY=${{ github.event.inputs.quay_registry }}" >> $GITHUB_ENV
|
||||||
|
|
||||||
- name: Log in to Quay
|
- name: Set GitHub Env vars if release event
|
||||||
|
if: ${{ github.event_name == 'release' }}
|
||||||
run: |
|
run: |
|
||||||
echo ${{ secrets.QUAY_TOKEN }} | docker login quay.io -u ${{ secrets.QUAY_USER }} --password-stdin
|
echo "TAG_NAME=${{ github.event.release.tag_name }}" >> $GITHUB_ENV
|
||||||
|
|
||||||
- name: Re-tag and promote awx-operator image
|
- name: Fail if QUAY_REGISTRY not set
|
||||||
run: |
|
run: |
|
||||||
docker pull ghcr.io/${{ github.repository }}:${{ github.event.release.tag_name }}
|
if [[ -z "${{ env.QUAY_REGISTRY }}" ]]; then
|
||||||
docker tag ghcr.io/${{ github.repository }}:${{ github.event.release.tag_name }} quay.io/${{ github.repository }}:${{ github.event.release.tag_name }}
|
echo "QUAY_REGISTRY not set. Please set QUAY_REGISTRY in variable GitHub Actions variables."
|
||||||
docker tag ghcr.io/${{ github.repository }}:${{ github.event.release.tag_name }} quay.io/${{ github.repository }}:latest
|
exit 1
|
||||||
docker push quay.io/${{ github.repository }}:${{ github.event.release.tag_name }}
|
fi
|
||||||
docker push quay.io/${{ github.repository }}:latest
|
|
||||||
|
|
||||||
- name: Configure git
|
- uses: actions/checkout@v4
|
||||||
run: |
|
with:
|
||||||
git config user.name "$GITHUB_ACTOR"
|
depth: 0
|
||||||
git config user.email "[email protected]"
|
|
||||||
|
|
||||||
- name: Release Helm chart
|
|
||||||
|
- name: Log into registry ghcr.io
|
||||||
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
|
with:
|
||||||
|
registry: ghcr.io
|
||||||
|
username: ${{ github.actor }}
|
||||||
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
|
|
||||||
|
- name: Log into registry quay.io
|
||||||
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
|
with:
|
||||||
|
registry: ${{ env.QUAY_REGISTRY }}
|
||||||
|
username: ${{ secrets.QUAY_USER }}
|
||||||
|
password: ${{ secrets.QUAY_TOKEN }}
|
||||||
|
|
||||||
|
|
||||||
|
- name: Pull Tagged Staged Image and Publish to quay.io
|
||||||
run: |
|
run: |
|
||||||
ansible-playbook ansible/helm-release.yml -v \
|
docker buildx imagetools create \
|
||||||
-e operator_image=quay.io/${{ github.repository }} \
|
ghcr.io/${{ github.repository }}:${{ env.TAG_NAME }} \
|
||||||
-e chart_owner=${{ github.repository_owner }} \
|
--tag ${{ env.QUAY_REGISTRY }}/awx-operator:${{ env.TAG_NAME }}
|
||||||
-e tag=${{ github.event.release.tag_name }} \
|
|
||||||
-e gh_token=${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
- name: Pull Staged Image and Publish to quay.io/${{ github.repository }}:latest
|
||||||
|
run: |
|
||||||
|
docker buildx imagetools create \
|
||||||
|
ghcr.io/${{ github.repository }}:${{ env.TAG_NAME }} \
|
||||||
|
--tag ${{ env.QUAY_REGISTRY }}/awx-operator:latest
|
||||||
|
|||||||
@@ -0,0 +1,86 @@
|
|||||||
|
name: Publish AWX Operator on operator-hub
|
||||||
|
on:
|
||||||
|
release:
|
||||||
|
types: [published]
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
tag_name:
|
||||||
|
description: 'Name for the tag of the release.'
|
||||||
|
required: true
|
||||||
|
operator_hub_fork:
|
||||||
|
description: 'Fork of operator-hub where the PR will be created from. default: awx-auto'
|
||||||
|
required: true
|
||||||
|
default: 'awx-auto'
|
||||||
|
image_registry:
|
||||||
|
description: 'Image registry where the image is published to. default: quay.io'
|
||||||
|
required: true
|
||||||
|
default: 'quay.io'
|
||||||
|
image_registry_organization:
|
||||||
|
description: 'Image registry organization where the image is published to. default: ansible'
|
||||||
|
required: true
|
||||||
|
default: 'ansible'
|
||||||
|
community_operator_github_org:
|
||||||
|
description: 'Github organization for community-opeartor project. default: k8s-operatorhub'
|
||||||
|
required: true
|
||||||
|
default: 'k8s-operatorhub'
|
||||||
|
community_operator_prod_github_org:
|
||||||
|
description: 'GitHub organization for community-operator-prod project. default: redhat-openshift-ecosystem'
|
||||||
|
required: true
|
||||||
|
default: 'redhat-openshift-ecosystem'
|
||||||
|
jobs:
|
||||||
|
promote:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Set GITHUB_ENV from workflow_dispatch event
|
||||||
|
if: ${{ github.event_name == 'workflow_dispatch' }}
|
||||||
|
run: |
|
||||||
|
echo "VERSION=${{ github.event.inputs.tag_name }}" >> $GITHUB_ENV
|
||||||
|
echo "IMAGE_REGISTRY=${{ github.event.inputs.image_registry }}" >> $GITHUB_ENV
|
||||||
|
echo "IMAGE_REGISTRY_ORGANIZATION=${{ github.event.inputs.image_registry_organization }}" >> $GITHUB_ENV
|
||||||
|
echo "COMMUNITY_OPERATOR_GITHUB_ORG=${{ github.event.inputs.community_operator_github_org }}" >> $GITHUB_ENV
|
||||||
|
echo "COMMUNITY_OPERATOR_PROD_GITHUB_ORG=${{ github.event.inputs.community_operator_prod_github_org }}" >> $GITHUB_ENV
|
||||||
|
|
||||||
|
- name: Set GITHUB_ENV for release event
|
||||||
|
if: ${{ github.event_name == 'release' }}
|
||||||
|
run: |
|
||||||
|
echo "VERSION=${{ github.event.release.tag_name }}" >> $GITHUB_ENV
|
||||||
|
echo "IMAGE_REGISTRY=quay.io" >> $GITHUB_ENV
|
||||||
|
echo "IMAGE_REGISTRY_ORGANIZATION=ansible" >> $GITHUB_ENV
|
||||||
|
echo "COMMUNITY_OPERATOR_GITHUB_ORG=k8s-operatorhub" >> $GITHUB_ENV
|
||||||
|
echo "COMMUNITY_OPERATOR_PROD_GITHUB_ORG=redhat-openshift-ecosystem" >> $GITHUB_ENV
|
||||||
|
|
||||||
|
- name: Log in to image registry
|
||||||
|
run: |
|
||||||
|
echo ${{ secrets.QUAY_TOKEN }} | docker login ${{ env.IMAGE_REGISTRY }} -u ${{ secrets.QUAY_USER }} --password-stdin
|
||||||
|
|
||||||
|
- name: Checkout awx-operator at workflow branch
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
path: awx-operator
|
||||||
|
|
||||||
|
- name: Checkout awx-opearator at ${{ env.VERSION }}
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-tags: true
|
||||||
|
ref: ${{ env.VERSION }}
|
||||||
|
path: awx-operator-${{ env.VERSION }}
|
||||||
|
fetch-depth: 0 # fetch all history so that git describe works
|
||||||
|
|
||||||
|
- name: Copy scripts to awx-operator-${{ env.VERSION }}
|
||||||
|
run: |
|
||||||
|
cp -f \
|
||||||
|
awx-operator/hack/publish-to-operator-hub.sh \
|
||||||
|
awx-operator-${{ env.VERSION }}/hack/publish-to-operator-hub.sh
|
||||||
|
cp -f \
|
||||||
|
awx-operator/Makefile \
|
||||||
|
awx-operator-${{ env.VERSION }}/Makefile
|
||||||
|
|
||||||
|
- name: Build and publish bundle to operator-hub
|
||||||
|
working-directory: awx-operator-${{ env.VERSION }}
|
||||||
|
env:
|
||||||
|
IMG_REPOSITORY: ${{ env.IMAGE_REGISTRY }}/${{ env.IMAGE_REGISTRY_ORGANIZATION }}
|
||||||
|
GITHUB_TOKEN: ${{ secrets.AWX_AUTO_GITHUB_TOKEN }}
|
||||||
|
run: |
|
||||||
|
git config --global user.email "[email protected]"
|
||||||
|
git config --global user.name "AWX Automation"
|
||||||
|
./hack/publish-to-operator-hub.sh
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
---
|
||||||
|
name: nox
|
||||||
|
|
||||||
|
"on":
|
||||||
|
workflow_call:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
nox:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
include:
|
||||||
|
- session: build
|
||||||
|
python-versions: "3.11"
|
||||||
|
name: "Run nox ${{ matrix.session }} session"
|
||||||
|
steps:
|
||||||
|
- name: Check out repo
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- name: Setup nox
|
||||||
|
uses: wntrblm/[email protected]
|
||||||
|
with:
|
||||||
|
python-versions: "${{ matrix.python-versions }}"
|
||||||
|
- name: "Run nox -s ${{ matrix.session }}"
|
||||||
|
run: |
|
||||||
|
nox -s "${{ matrix.session }}"
|
||||||
+20
-21
@@ -37,14 +37,8 @@ jobs:
|
|||||||
|
|
||||||
exit 0
|
exit 0
|
||||||
|
|
||||||
- name: Checkout awx
|
|
||||||
uses: actions/checkout@v2
|
|
||||||
with:
|
|
||||||
repository: ${{ github.repository_owner }}/awx
|
|
||||||
path: awx
|
|
||||||
|
|
||||||
- name: Checkout awx-operator
|
- name: Checkout awx-operator
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
repository: ${{ github.repository_owner }}/awx-operator
|
repository: ${{ github.repository_owner }}/awx-operator
|
||||||
path: awx-operator
|
path: awx-operator
|
||||||
@@ -53,17 +47,20 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
python3 -m pip install docker
|
python3 -m pip install docker
|
||||||
|
|
||||||
- name: Log in to GHCR
|
- name: Log into registry ghcr.io
|
||||||
run: |
|
uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 # v3.3.0
|
||||||
echo ${{ secrets.GITHUB_TOKEN }} | docker login ghcr.io -u ${{ github.actor }} --password-stdin
|
with:
|
||||||
|
registry: ghcr.io
|
||||||
|
username: ${{ github.actor }}
|
||||||
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: Build and stage awx-operator
|
- name: Stage awx-operator
|
||||||
working-directory: awx-operator
|
working-directory: awx-operator
|
||||||
run: |
|
run: |
|
||||||
BUILD_ARGS="--build-arg DEFAULT_AWX_VERSION=${{ github.event.inputs.default_awx_version }} \
|
BUILD_ARGS="--build-arg DEFAULT_AWX_VERSION=${{ github.event.inputs.default_awx_version }} \
|
||||||
--build-arg OPERATOR_VERSION=${{ github.event.inputs.version }}" \
|
--build-arg OPERATOR_VERSION=${{ github.event.inputs.version }}" \
|
||||||
IMAGE_TAG_BASE=ghcr.io/${{ github.repository_owner }}/awx-operator \
|
IMG=ghcr.io/${{ github.repository }}:${{ github.event.inputs.version }} \
|
||||||
VERSION=${{ github.event.inputs.version }} make docker-build docker-push
|
make docker-buildx
|
||||||
|
|
||||||
- name: Run test deployment
|
- name: Run test deployment
|
||||||
working-directory: awx-operator
|
working-directory: awx-operator
|
||||||
@@ -76,10 +73,12 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
AWX_TEST_VERSION: ${{ github.event.inputs.default_awx_version }}
|
AWX_TEST_VERSION: ${{ github.event.inputs.default_awx_version }}
|
||||||
|
|
||||||
- name: Create draft release
|
- name: Create Draft Release
|
||||||
working-directory: awx
|
id: create_release
|
||||||
run: |
|
uses: actions/create-release@v1
|
||||||
ansible-playbook tools/ansible/stage.yml \
|
env:
|
||||||
-e version=${{ github.event.inputs.version }} \
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
-e repo=${{ github.repository_owner }}/awx-operator \
|
with:
|
||||||
-e github_token=${{ secrets.GITHUB_TOKEN }}
|
tag_name: ${{ github.event.inputs.version }}
|
||||||
|
release_name: Release ${{ github.event.inputs.version }}
|
||||||
|
draft: true
|
||||||
|
|||||||
@@ -1,22 +0,0 @@
|
|||||||
---
|
|
||||||
name: Triage
|
|
||||||
|
|
||||||
on:
|
|
||||||
issues:
|
|
||||||
types:
|
|
||||||
- opened
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
triage:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
name: Label
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: Label issues
|
|
||||||
uses: github/[email protected]
|
|
||||||
with:
|
|
||||||
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
|
||||||
not-before: 2021-12-07T07:00:00Z
|
|
||||||
configuration-path: .github/issue_labeler.yml
|
|
||||||
enable-versioned-regex: 0
|
|
||||||
if: github.event_name == 'issues'
|
|
||||||
@@ -1,4 +1,5 @@
|
|||||||
*~
|
*~
|
||||||
|
gh-pages/
|
||||||
.cache/
|
.cache/
|
||||||
/bin
|
/bin
|
||||||
/bundle
|
/bundle
|
||||||
@@ -7,3 +8,8 @@
|
|||||||
/charts
|
/charts
|
||||||
/.cr-release-packages
|
/.cr-release-packages
|
||||||
.vscode/
|
.vscode/
|
||||||
|
__pycache__
|
||||||
|
/site
|
||||||
|
venv/*
|
||||||
|
hacking/
|
||||||
|
token
|
||||||
|
|||||||
@@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v2
|
|
||||||
appVersion: 0.1.0
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
name: starter
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
@@ -1,56 +0,0 @@
|
|||||||
# AWX Operator Helm Chart
|
|
||||||
|
|
||||||
This chart installs the AWX Operator resources configured in [this](https://github.com/ansible/awx-operator) repository.
|
|
||||||
|
|
||||||
## Getting Started
|
|
||||||
To configure your AWX resource using this chart, create your own `yaml` values file. The name is up to personal preference since it will explicitly be passed into the helm chart. Helm will merge whatever values you specify in your file with the default `values.yaml`, overriding any settings you've changed while allowing you to fall back on defaults. Because of this functionality, `values.yaml` should not be edited directly.
|
|
||||||
|
|
||||||
In your values config, enable `AWX.enable` and add `AWX.spec` values based on the awx operator's [documentation](https://github.com/ansible/awx-operator/blob/devel/README.md). Consult the docs below for additional functionality.
|
|
||||||
|
|
||||||
### Installing
|
|
||||||
The operator's [helm install](https://github.com/ansible/awx-operator/blob/devel/README.md#helm-install-on-existing-cluster) guide provides key installation instructions.
|
|
||||||
|
|
||||||
Example:
|
|
||||||
```
|
|
||||||
helm install my-awx-operator awx-operator/awx-operator -n awx --create-namespace -f myvalues.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
Argument breakdown:
|
|
||||||
* `-f` passes in the file with your custom values
|
|
||||||
* `-n` sets the namespace to be installed in
|
|
||||||
* This value is accessed by `{{ $.Release.Namespace }}` in the templates
|
|
||||||
* Acts as the default namespace for all unspecified resources
|
|
||||||
* `--create-namespace` specifies that helm should create the namespace before installing
|
|
||||||
|
|
||||||
To update an existing installation, use `helm upgrade` instead of `install`. The rest of the syntax remains the same.
|
|
||||||
|
|
||||||
## Configuration
|
|
||||||
The goal of adding helm configurations is to abstract out and simplify the creation of multi-resource configs. The `AWX.spec` field maps directly to the spec configs of the `AWX` resource that the operator provides, which are detailed in the [main README](https://github.com/ansible/awx-operator/blob/devel/README.md). Other sub-config can be added with the goal of simplifying more involved setups that require additional resources to be specified.
|
|
||||||
|
|
||||||
These sub-headers aim to be a more intuitive entrypoint into customizing your deployment, and are easier to manage in the long-term. By design, the helm templates will defer to the manually defined specs to avoid configuration conflicts. For example, if `AWX.spec.postgres_configuration_secret` is being used, the `AWX.postgres` settings will not be applied, even if enabled.
|
|
||||||
|
|
||||||
### External Postgres
|
|
||||||
The `AWX.postgres` section simplifies the creation of the external postgres secret. If enabled, the configs provided will automatically be placed in a `postgres-config` secret and linked to the `AWX` resource. For proper secret management, the `AWX.postgres.password` value, and any other sensitive values, can be passed in at the command line rather than specified in code. Use the `--set` argument with `helm install`.
|
|
||||||
|
|
||||||
|
|
||||||
## Values Summary
|
|
||||||
|
|
||||||
### AWX
|
|
||||||
| Value | Description | Default |
|
|
||||||
|---|---|---|
|
|
||||||
| `AWX.enabled` | Enable this AWX resource configuration | `false` |
|
|
||||||
| `AWX.name` | The name of the AWX resource and default prefix for other resources | `"awx"` |
|
|
||||||
| `AWX.spec` | specs to directly configure the AWX resource | `{}` |
|
|
||||||
| `AWX.postgres` | configurations for the external postgres secret | - |
|
|
||||||
|
|
||||||
|
|
||||||
# Contributing
|
|
||||||
|
|
||||||
## Adding abstracted sections
|
|
||||||
Where possible, defer to `AWX.spec` configs before applying the abstracted configs to avoid collision. This can be facilitated by the `(hasKey .spec what_i_will_abstract)` check.
|
|
||||||
|
|
||||||
## Building and Testing
|
|
||||||
This chart is built using the Makefile in the [awx-operator repo](https://github.com/ansible/awx-operator). Clone the repo and run `make helm-chart`. This will create the awx-operator chart in the `charts/awx-operator` directory. In this process, the contents of the `.helm/starter` directory will be added to the chart.
|
|
||||||
|
|
||||||
## Future Goals
|
|
||||||
All values under the `AWX` header are focused on configurations that use the operator. Configurations that relate to the Operator itself could be placed under an `Operator` heading, but that may add a layer of complication over current development.
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
{{/*
|
|
||||||
Generate the name of the postgres secret, expects AWX context passed in
|
|
||||||
*/}}
|
|
||||||
{{- define "postgres.secretName" -}}
|
|
||||||
{{ default (printf "%s-postgres-configuration" .Values.AWX.name) .Values.AWX.postgres.secretName }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
{{- if $.Values.AWX.enabled }}
|
|
||||||
{{- with .Values.AWX }}
|
|
||||||
apiVersion: awx.ansible.com/v1beta1
|
|
||||||
kind: AWX
|
|
||||||
metadata:
|
|
||||||
name: {{ .name }}
|
|
||||||
namespace: {{ $.Release.Namespace }}
|
|
||||||
spec:
|
|
||||||
{{- /* Include raw map from the values file spec */}}
|
|
||||||
{{ .spec | toYaml | indent 2 }}
|
|
||||||
{{- /* Provide security context defaults */}}
|
|
||||||
{{- if not (hasKey .spec "security_context_settings") }}
|
|
||||||
security_context_settings:
|
|
||||||
runAsGroup: 0
|
|
||||||
runAsUser: 0
|
|
||||||
fsGroup: 0
|
|
||||||
fsGroupChangePolicy: OnRootMismatch
|
|
||||||
{{- end }}
|
|
||||||
{{- /* Postgres configs if enabled and not already present */}}
|
|
||||||
{{- if and .postgres.enabled (not (hasKey .spec "postgres_configuration_secret")) }}
|
|
||||||
postgres_configuration_secret: {{ include "postgres.secretName" $ }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
{{- if and $.Values.AWX.enabled $.Values.AWX.postgres.enabled }}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ include "postgres.secretName" . }}
|
|
||||||
namespace: {{ $.Release.Namespace }}
|
|
||||||
{{- with $.Values.AWX.postgres }}
|
|
||||||
stringData:
|
|
||||||
host: {{ .host }}
|
|
||||||
port: {{ .port | quote }}
|
|
||||||
database: {{ .dbName }}
|
|
||||||
username: {{ .username }}
|
|
||||||
password: {{ .password }}
|
|
||||||
sslmode: {{ .sslmode }}
|
|
||||||
type: {{ .type }}
|
|
||||||
type: Opaque
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
AWX:
|
|
||||||
# enable use of awx-deploy template
|
|
||||||
enabled: false
|
|
||||||
name: awx
|
|
||||||
spec:
|
|
||||||
admin_user: admin
|
|
||||||
|
|
||||||
# configurations for external postgres instance
|
|
||||||
postgres:
|
|
||||||
enabled: false
|
|
||||||
host: Unset
|
|
||||||
port: 5678
|
|
||||||
dbName: Unset
|
|
||||||
username: admin
|
|
||||||
# for secret management, pass in the password independently of this file
|
|
||||||
# at the command line, use --set AWX.postgres.password
|
|
||||||
password: Unset
|
|
||||||
sslmode: prefer
|
|
||||||
type: unmanaged
|
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Read the Docs configuration file
|
||||||
|
# See https://docs.readthedocs.io/en/stable/config-file/v2.html for details
|
||||||
|
|
||||||
|
# RTD API version
|
||||||
|
version: 2
|
||||||
|
|
||||||
|
build:
|
||||||
|
os: ubuntu-22.04
|
||||||
|
tools:
|
||||||
|
python: "3.11"
|
||||||
|
|
||||||
|
mkdocs:
|
||||||
|
configuration: mkdocs.yml
|
||||||
|
|
||||||
|
python:
|
||||||
|
install:
|
||||||
|
- requirements: ./docs/requirements.txt
|
||||||
@@ -6,9 +6,14 @@ ignore: |
|
|||||||
kustomization.yaml
|
kustomization.yaml
|
||||||
awx-operator.clusterserviceversion.yaml
|
awx-operator.clusterserviceversion.yaml
|
||||||
bundle
|
bundle
|
||||||
.helm/starter
|
hacking/
|
||||||
|
|
||||||
rules:
|
rules:
|
||||||
truthy: disable
|
truthy: disable
|
||||||
line-length:
|
line-length:
|
||||||
max: 170
|
max: 170
|
||||||
|
document-start: disable
|
||||||
|
comments-indentation: disable
|
||||||
|
indentation:
|
||||||
|
level: warning
|
||||||
|
indent-sequences: consistent
|
||||||
|
|||||||
+24
-17
@@ -6,13 +6,16 @@ Have questions about this document or anything not covered here? Please file a n
|
|||||||
|
|
||||||
## Table of contents
|
## Table of contents
|
||||||
|
|
||||||
* [Things to know prior to submitting code](#things-to-know-prior-to-submitting-code)
|
- [AWX-Operator Contributing Guidelines](#awx-operator-contributing-guidelines)
|
||||||
* [Submmiting your Work](#submitting-your-work)
|
- [Table of contents](#table-of-contents)
|
||||||
* [Testing](#testing)
|
- [Things to know prior to submitting code](#things-to-know-prior-to-submitting-code)
|
||||||
* [Testing in Docker](#testing-in-docker)
|
- [Submmiting your work](#submmiting-your-work)
|
||||||
* [Testing in Minikube](#testing-in-minikube)
|
- [Development](#development)
|
||||||
* [Generating a bundle](#generating-a-bundle)
|
- [Testing](#testing)
|
||||||
* [Reporting Issues](#reporting-issues)
|
- [Testing in Kind](#testing-in-kind)
|
||||||
|
- [Testing in Minikube](#testing-in-minikube)
|
||||||
|
- [Generating a bundle](#generating-a-bundle)
|
||||||
|
- [Reporting Issues](#reporting-issues)
|
||||||
|
|
||||||
|
|
||||||
## Things to know prior to submitting code
|
## Things to know prior to submitting code
|
||||||
@@ -25,13 +28,13 @@ Have questions about this document or anything not covered here? Please file a n
|
|||||||
|
|
||||||
|
|
||||||
## Submmiting your work
|
## Submmiting your work
|
||||||
1. From your fork `devel` branch, create a new brach to stage your changes.
|
1. From your fork `devel` branch, create a new branch to stage your changes.
|
||||||
```sh
|
```sh
|
||||||
#> git checkout -b <branch-name>
|
#> git checkout -b <branch-name>
|
||||||
```
|
```
|
||||||
2. Make your changes.
|
2. Make your changes.
|
||||||
3. Test your changes according described on the Testing section.
|
3. Test your changes according described on the Testing section.
|
||||||
4. If everylooks looks correct, commit your changes.
|
4. If everything looks correct, commit your changes.
|
||||||
```sh
|
```sh
|
||||||
#> git add <FILES>
|
#> git add <FILES>
|
||||||
#> git commit -m "My message here"
|
#> git commit -m "My message here"
|
||||||
@@ -40,30 +43,34 @@ Have questions about this document or anything not covered here? Please file a n
|
|||||||
|
|
||||||
**Note**: If you have multiple commits, make sure to `squash` your commits into a single commit which will facilitate our release process.
|
**Note**: If you have multiple commits, make sure to `squash` your commits into a single commit which will facilitate our release process.
|
||||||
|
|
||||||
|
## Development
|
||||||
|
The development environment consists of running an [`up.sh`](./up.sh) and a [`down.sh`](./down.sh) script, which applies or deletes yaml on the Openshift or K8s cluster you are connected to. See the [development.md](docs/development.md) for information on how to deploy and test changes from your branch.
|
||||||
|
|
||||||
## Testing
|
## Testing
|
||||||
|
|
||||||
This Operator includes a [Molecule](https://molecule.readthedocs.io/en/stable/)-based test environment, which can be executed standalone in Docker (e.g. in CI or in a single Docker container anywhere), or inside any kind of Kubernetes cluster (e.g. Minikube).
|
This Operator includes a [Molecule](https://ansible.readthedocs.io/projects/molecule/)-based test environment, which can be executed standalone in Docker (e.g. in CI or in a single Docker container anywhere), or inside any kind of Kubernetes cluster (e.g. Minikube).
|
||||||
|
|
||||||
You need to make sure you have Molecule installed before running the following commands. You can install Molecule with:
|
You need to make sure you have Molecule installed before running the following commands. You can install Molecule with:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
#> pip install 'molecule[docker]'
|
#> python -m pip install molecule-plugins[docker]
|
||||||
```
|
```
|
||||||
|
|
||||||
Running `molecule test` sets up a clean environment, builds the operator, runs all configured tests on an example operator instance, then tears down the environment (at least in the case of Docker).
|
Running `molecule test` sets up a clean environment, builds the operator, runs all configured tests on an example operator instance, then tears down the environment (at least in the case of Docker).
|
||||||
|
|
||||||
If you want to actively develop the operator, use `molecule converge`, which does everything but tear down the environment at the end.
|
If you want to actively develop the operator, use `molecule converge`, which does everything but tear down the environment at the end.
|
||||||
|
|
||||||
#### Testing in Docker
|
#### Testing in Kind
|
||||||
|
|
||||||
|
Testing with a kind cluster is the recommended way to test the awx-operator locally. First, you need to install kind if you haven't already. Please see these docs for setting that up:
|
||||||
|
* https://kind.sigs.k8s.io/docs/user/quick-start/
|
||||||
|
|
||||||
|
To run the tests, from the root of your checkout, run the following command:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
#> molecule test -s test-local
|
#> molecule test -s kind
|
||||||
```
|
```
|
||||||
|
|
||||||
This environment is meant for headless testing (e.g. in a CI environment, or when making smaller changes which don't need to be verified through a web interface). It is difficult to test things like AWX's web UI or to connect other applications on your local machine to the services running inside the cluster, since it is inside a Docker container with no static IP address.
|
|
||||||
|
|
||||||
#### Testing in Minikube
|
#### Testing in Minikube
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
@@ -137,4 +144,4 @@ Applying this template will do it. Once the CatalogSource is in a READY state, t
|
|||||||
|
|
||||||
## Reporting Issues
|
## Reporting Issues
|
||||||
|
|
||||||
We welcome your feedback, and encourage you to file an issue when you run into a problem.
|
We welcome your feedback, and encourage you to file an issue when you run into a problem.
|
||||||
|
|||||||
+12
-1
@@ -1,4 +1,10 @@
|
|||||||
FROM quay.io/operator-framework/ansible-operator:v1.12.0
|
FROM quay.io/operator-framework/ansible-operator:v1.36.1
|
||||||
|
|
||||||
|
USER root
|
||||||
|
RUN dnf update --security --bugfix -y && \
|
||||||
|
dnf install -y openssl
|
||||||
|
|
||||||
|
USER 1001
|
||||||
|
|
||||||
ARG DEFAULT_AWX_VERSION
|
ARG DEFAULT_AWX_VERSION
|
||||||
ARG OPERATOR_VERSION
|
ARG OPERATOR_VERSION
|
||||||
@@ -12,3 +18,8 @@ RUN ansible-galaxy collection install -r ${HOME}/requirements.yml \
|
|||||||
COPY watches.yaml ${HOME}/watches.yaml
|
COPY watches.yaml ${HOME}/watches.yaml
|
||||||
COPY roles/ ${HOME}/roles/
|
COPY roles/ ${HOME}/roles/
|
||||||
COPY playbooks/ ${HOME}/playbooks/
|
COPY playbooks/ ${HOME}/playbooks/
|
||||||
|
|
||||||
|
ENTRYPOINT ["/tini", "--", "/usr/local/bin/ansible-operator", "run", \
|
||||||
|
"--watches-file=./watches.yaml", \
|
||||||
|
"--reconcile-period=0s" \
|
||||||
|
]
|
||||||
|
|||||||
@@ -4,16 +4,10 @@
|
|||||||
# - use the VERSION as arg of the bundle target (e.g make bundle VERSION=0.0.2)
|
# - use the VERSION as arg of the bundle target (e.g make bundle VERSION=0.0.2)
|
||||||
# - use environment variables to overwrite this value (e.g export VERSION=0.0.2)
|
# - use environment variables to overwrite this value (e.g export VERSION=0.0.2)
|
||||||
VERSION ?= $(shell git describe --tags)
|
VERSION ?= $(shell git describe --tags)
|
||||||
|
PREV_VERSION ?= $(shell git describe --abbrev=0 --tags $(shell git rev-list --tags --skip=1 --max-count=1))
|
||||||
|
|
||||||
CONTAINER_CMD ?= docker
|
CONTAINER_CMD ?= docker
|
||||||
|
|
||||||
# GNU vs BSD in-place sed
|
|
||||||
ifeq ($(shell sed --version 2>/dev/null | grep -q GNU && echo gnu),gnu)
|
|
||||||
SED_I := sed -i
|
|
||||||
else
|
|
||||||
SED_I := sed -i ''
|
|
||||||
endif
|
|
||||||
|
|
||||||
# CHANNELS define the bundle channels used in the bundle.
|
# CHANNELS define the bundle channels used in the bundle.
|
||||||
# Add a new line here if you would like to change its default config. (E.g CHANNELS = "candidate,fast,stable")
|
# Add a new line here if you would like to change its default config. (E.g CHANNELS = "candidate,fast,stable")
|
||||||
# To re-generate a bundle for other specific channels without changing the standard setup, you can:
|
# To re-generate a bundle for other specific channels without changing the standard setup, you can:
|
||||||
@@ -44,18 +38,22 @@ IMAGE_TAG_BASE ?= quay.io/ansible/awx-operator
|
|||||||
# You can use it as an arg. (E.g make bundle-build BUNDLE_IMG=<some-registry>/<project-name-bundle>:<tag>)
|
# You can use it as an arg. (E.g make bundle-build BUNDLE_IMG=<some-registry>/<project-name-bundle>:<tag>)
|
||||||
BUNDLE_IMG ?= $(IMAGE_TAG_BASE)-bundle:v$(VERSION)
|
BUNDLE_IMG ?= $(IMAGE_TAG_BASE)-bundle:v$(VERSION)
|
||||||
|
|
||||||
|
# BUNDLE_GEN_FLAGS are the flags passed to the operator-sdk generate bundle command
|
||||||
|
BUNDLE_GEN_FLAGS ?= -q --overwrite --version $(VERSION) $(BUNDLE_METADATA_OPTS)
|
||||||
|
|
||||||
|
# USE_IMAGE_DIGESTS defines if images are resolved via tags or digests
|
||||||
|
# You can enable this value if you would like to use SHA Based Digests
|
||||||
|
# To enable set flag to true
|
||||||
|
USE_IMAGE_DIGESTS ?= false
|
||||||
|
ifeq ($(USE_IMAGE_DIGESTS), true)
|
||||||
|
BUNDLE_GEN_FLAGS += --use-image-digests
|
||||||
|
endif
|
||||||
|
|
||||||
# Image URL to use all building/pushing image targets
|
# Image URL to use all building/pushing image targets
|
||||||
IMG ?= $(IMAGE_TAG_BASE):$(VERSION)
|
IMG ?= $(IMAGE_TAG_BASE):$(VERSION)
|
||||||
NAMESPACE ?= awx
|
NAMESPACE ?= awx
|
||||||
|
|
||||||
# Helm variables
|
.PHONY: all
|
||||||
CHART_NAME ?= awx-operator
|
|
||||||
CHART_DESCRIPTION ?= A Helm chart for the AWX Operator
|
|
||||||
CHART_OWNER ?= $(GH_REPO_OWNER)
|
|
||||||
CHART_REPO ?= awx-operator
|
|
||||||
CHART_BRANCH ?= gh-pages
|
|
||||||
CHART_INDEX ?= index.yaml
|
|
||||||
|
|
||||||
all: docker-build
|
all: docker-build
|
||||||
|
|
||||||
##@ General
|
##@ General
|
||||||
@@ -71,38 +69,66 @@ all: docker-build
|
|||||||
# More info on the awk command:
|
# More info on the awk command:
|
||||||
# http://linuxcommand.org/lc3_adv_awk.php
|
# http://linuxcommand.org/lc3_adv_awk.php
|
||||||
|
|
||||||
|
.PHONY: help
|
||||||
help: ## Display this help.
|
help: ## Display this help.
|
||||||
@awk 'BEGIN {FS = ":.*##"; printf "\nUsage:\n make \033[36m<target>\033[0m\n"} /^[a-zA-Z_0-9-]+:.*?##/ { printf " \033[36m%-15s\033[0m %s\n", $$1, $$2 } /^##@/ { printf "\n\033[1m%s\033[0m\n", substr($$0, 5) } ' $(MAKEFILE_LIST)
|
@awk 'BEGIN {FS = ":.*##"; printf "\nUsage:\n make \033[36m<target>\033[0m\n"} /^[a-zA-Z_0-9-]+:.*?##/ { printf " \033[36m%-15s\033[0m %s\n", $$1, $$2 } /^##@/ { printf "\n\033[1m%s\033[0m\n", substr($$0, 5) } ' $(MAKEFILE_LIST)
|
||||||
|
|
||||||
|
.PHONY: print-%
|
||||||
|
print-%: ## Print any variable from the Makefile. Use as `make print-VARIABLE`
|
||||||
|
@echo $($*)
|
||||||
|
|
||||||
##@ Build
|
##@ Build
|
||||||
|
|
||||||
|
.PHONY: run
|
||||||
run: ansible-operator ## Run against the configured Kubernetes cluster in ~/.kube/config
|
run: ansible-operator ## Run against the configured Kubernetes cluster in ~/.kube/config
|
||||||
ANSIBLE_ROLES_PATH="$(ANSIBLE_ROLES_PATH):$(shell pwd)/roles" $(ANSIBLE_OPERATOR) run
|
ANSIBLE_ROLES_PATH="$(ANSIBLE_ROLES_PATH):$(shell pwd)/roles" $(ANSIBLE_OPERATOR) run
|
||||||
|
|
||||||
|
.PHONY: docker-build
|
||||||
docker-build: ## Build docker image with the manager.
|
docker-build: ## Build docker image with the manager.
|
||||||
${CONTAINER_CMD} build $(BUILD_ARGS) -t ${IMG} .
|
${CONTAINER_CMD} build $(BUILD_ARGS) -t ${IMG} .
|
||||||
|
|
||||||
|
.PHONY: docker-push
|
||||||
docker-push: ## Push docker image with the manager.
|
docker-push: ## Push docker image with the manager.
|
||||||
${CONTAINER_CMD} push ${IMG}
|
${CONTAINER_CMD} push ${IMG}
|
||||||
|
|
||||||
|
# PLATFORMS defines the target platforms for the manager image be build to provide support to multiple
|
||||||
|
# architectures. (i.e. make docker-buildx IMG=myregistry/mypoperator:0.0.1). To use this option you need to:
|
||||||
|
# - able to use docker buildx . More info: https://docs.docker.com/build/buildx/
|
||||||
|
# - have enable BuildKit, More info: https://docs.docker.com/develop/develop-images/build_enhancements/
|
||||||
|
# - be able to push the image for your registry (i.e. if you do not inform a valid value via IMG=<myregistry/image:<tag>> than the export will fail)
|
||||||
|
# To properly provided solutions that supports more than one platform you should use this option.
|
||||||
|
PLATFORMS ?= linux/arm64,linux/amd64,linux/s390x,linux/ppc64le
|
||||||
|
.PHONY: docker-buildx
|
||||||
|
docker-buildx: ## Build and push docker image for the manager for cross-platform support
|
||||||
|
- docker buildx create --name project-v3-builder
|
||||||
|
docker buildx use project-v3-builder
|
||||||
|
- docker buildx build --push $(BUILD_ARGS) --platform=$(PLATFORMS) --tag ${IMG} -f Dockerfile .
|
||||||
|
- docker buildx rm project-v3-builder
|
||||||
|
|
||||||
|
|
||||||
##@ Deployment
|
##@ Deployment
|
||||||
|
|
||||||
|
.PHONY: install
|
||||||
install: kustomize ## Install CRDs into the K8s cluster specified in ~/.kube/config.
|
install: kustomize ## Install CRDs into the K8s cluster specified in ~/.kube/config.
|
||||||
$(KUSTOMIZE) build config/crd | kubectl apply -f -
|
$(KUSTOMIZE) build config/crd | kubectl apply -f -
|
||||||
|
|
||||||
|
.PHONY: uninstall
|
||||||
uninstall: kustomize ## Uninstall CRDs from the K8s cluster specified in ~/.kube/config.
|
uninstall: kustomize ## Uninstall CRDs from the K8s cluster specified in ~/.kube/config.
|
||||||
$(KUSTOMIZE) build config/crd | kubectl delete -f -
|
$(KUSTOMIZE) build config/crd | kubectl delete -f -
|
||||||
|
|
||||||
|
.PHONY: gen-resources
|
||||||
gen-resources: kustomize ## Generate resources for controller and print to stdout
|
gen-resources: kustomize ## Generate resources for controller and print to stdout
|
||||||
@cd config/manager && $(KUSTOMIZE) edit set image controller=${IMG}
|
@cd config/manager && $(KUSTOMIZE) edit set image controller=${IMG}
|
||||||
@cd config/default && $(KUSTOMIZE) edit set namespace ${NAMESPACE}
|
@cd config/default && $(KUSTOMIZE) edit set namespace ${NAMESPACE}
|
||||||
@$(KUSTOMIZE) build config/default
|
@$(KUSTOMIZE) build config/default
|
||||||
|
|
||||||
|
.PHONY: deploy
|
||||||
deploy: kustomize ## Deploy controller to the K8s cluster specified in ~/.kube/config.
|
deploy: kustomize ## Deploy controller to the K8s cluster specified in ~/.kube/config.
|
||||||
@cd config/manager && $(KUSTOMIZE) edit set image controller=${IMG}
|
@cd config/manager && $(KUSTOMIZE) edit set image controller=${IMG}
|
||||||
@cd config/default && $(KUSTOMIZE) edit set namespace ${NAMESPACE}
|
@cd config/default && $(KUSTOMIZE) edit set namespace ${NAMESPACE}
|
||||||
@$(KUSTOMIZE) build config/default | kubectl apply -f -
|
@$(KUSTOMIZE) build config/default | kubectl apply -f -
|
||||||
|
|
||||||
|
.PHONY: undeploy
|
||||||
undeploy: ## Undeploy controller from the K8s cluster specified in ~/.kube/config.
|
undeploy: ## Undeploy controller from the K8s cluster specified in ~/.kube/config.
|
||||||
@cd config/default && $(KUSTOMIZE) edit set namespace ${NAMESPACE}
|
@cd config/default && $(KUSTOMIZE) edit set namespace ${NAMESPACE}
|
||||||
$(KUSTOMIZE) build config/default | kubectl delete -f -
|
$(KUSTOMIZE) build config/default | kubectl delete -f -
|
||||||
@@ -119,7 +145,7 @@ ifeq (,$(shell which kustomize 2>/dev/null))
|
|||||||
@{ \
|
@{ \
|
||||||
set -e ;\
|
set -e ;\
|
||||||
mkdir -p $(dir $(KUSTOMIZE)) ;\
|
mkdir -p $(dir $(KUSTOMIZE)) ;\
|
||||||
curl -sSLo - https://github.com/kubernetes-sigs/kustomize/releases/download/kustomize/v4.5.2/kustomize_v4.5.2_$(OS)_$(ARCHA).tar.gz | \
|
curl -sSLo - https://github.com/kubernetes-sigs/kustomize/releases/download/kustomize/v5.0.1/kustomize_v5.0.1_$(OS)_$(ARCHA).tar.gz | \
|
||||||
tar xzf - -C bin/ ;\
|
tar xzf - -C bin/ ;\
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
@@ -127,6 +153,22 @@ KUSTOMIZE = $(shell which kustomize)
|
|||||||
endif
|
endif
|
||||||
endif
|
endif
|
||||||
|
|
||||||
|
.PHONY: operator-sdk
|
||||||
|
OPERATOR_SDK = $(shell pwd)/bin/operator-sdk
|
||||||
|
operator-sdk: ## Download operator-sdk locally if necessary, preferring the $(pwd)/bin path over global if both exist.
|
||||||
|
ifeq (,$(wildcard $(OPERATOR_SDK)))
|
||||||
|
ifeq (,$(shell which operator-sdk 2>/dev/null))
|
||||||
|
@{ \
|
||||||
|
set -e ;\
|
||||||
|
mkdir -p $(dir $(OPERATOR_SDK)) ;\
|
||||||
|
curl -sSLo $(OPERATOR_SDK) https://github.com/operator-framework/operator-sdk/releases/download/v1.36.1/operator-sdk_$(OS)_$(ARCHA) ;\
|
||||||
|
chmod +x $(OPERATOR_SDK) ;\
|
||||||
|
}
|
||||||
|
else
|
||||||
|
OPERATOR_SDK = $(shell which operator-sdk)
|
||||||
|
endif
|
||||||
|
endif
|
||||||
|
|
||||||
.PHONY: ansible-operator
|
.PHONY: ansible-operator
|
||||||
ANSIBLE_OPERATOR = $(shell pwd)/bin/ansible-operator
|
ANSIBLE_OPERATOR = $(shell pwd)/bin/ansible-operator
|
||||||
ansible-operator: ## Download ansible-operator locally if necessary, preferring the $(pwd)/bin path over global if both exist.
|
ansible-operator: ## Download ansible-operator locally if necessary, preferring the $(pwd)/bin path over global if both exist.
|
||||||
@@ -135,7 +177,7 @@ ifeq (,$(shell which ansible-operator 2>/dev/null))
|
|||||||
@{ \
|
@{ \
|
||||||
set -e ;\
|
set -e ;\
|
||||||
mkdir -p $(dir $(ANSIBLE_OPERATOR)) ;\
|
mkdir -p $(dir $(ANSIBLE_OPERATOR)) ;\
|
||||||
curl -sSLo $(ANSIBLE_OPERATOR) https://github.com/operator-framework/operator-sdk/releases/download/v1.12.0/ansible-operator_$(OS)_$(ARCHA) ;\
|
curl -sSLo $(ANSIBLE_OPERATOR) https://github.com/operator-framework/ansible-operator-plugins/releases/download/v1.36.1/ansible-operator_$(OS)_$(ARCHA) ;\
|
||||||
chmod +x $(ANSIBLE_OPERATOR) ;\
|
chmod +x $(ANSIBLE_OPERATOR) ;\
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
@@ -144,11 +186,11 @@ endif
|
|||||||
endif
|
endif
|
||||||
|
|
||||||
.PHONY: bundle
|
.PHONY: bundle
|
||||||
bundle: kustomize ## Generate bundle manifests and metadata, then validate generated files.
|
bundle: kustomize operator-sdk ## Generate bundle manifests and metadata, then validate generated files.
|
||||||
operator-sdk generate kustomize manifests -q
|
$(OPERATOR_SDK) generate kustomize manifests -q
|
||||||
cd config/manager && $(KUSTOMIZE) edit set image controller=$(IMG)
|
cd config/manager && $(KUSTOMIZE) edit set image controller=$(IMG)
|
||||||
$(KUSTOMIZE) build config/manifests | operator-sdk generate bundle -q --overwrite --version $(VERSION) $(BUNDLE_METADATA_OPTS)
|
$(KUSTOMIZE) build config/manifests | $(OPERATOR_SDK) generate bundle -q --overwrite --version $(VERSION) $(BUNDLE_METADATA_OPTS)
|
||||||
operator-sdk bundle validate ./bundle
|
$(OPERATOR_SDK) bundle validate ./bundle
|
||||||
|
|
||||||
.PHONY: bundle-build
|
.PHONY: bundle-build
|
||||||
bundle-build: ## Build the bundle image.
|
bundle-build: ## Build the bundle image.
|
||||||
@@ -166,7 +208,7 @@ ifeq (,$(shell which opm 2>/dev/null))
|
|||||||
@{ \
|
@{ \
|
||||||
set -e ;\
|
set -e ;\
|
||||||
mkdir -p $(dir $(OPM)) ;\
|
mkdir -p $(dir $(OPM)) ;\
|
||||||
curl -sSLo $(OPM) https://github.com/operator-framework/operator-registry/releases/download/v1.15.1/$(OS)-$(ARCHA)-opm ;\
|
curl -sSLo $(OPM) https://github.com/operator-framework/operator-registry/releases/download/v1.26.0/$(OS)-$(ARCHA)-opm ;\
|
||||||
chmod +x $(OPM) ;\
|
chmod +x $(OPM) ;\
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
@@ -197,136 +239,3 @@ catalog-build: opm ## Build a catalog image.
|
|||||||
.PHONY: catalog-push
|
.PHONY: catalog-push
|
||||||
catalog-push: ## Push a catalog image.
|
catalog-push: ## Push a catalog image.
|
||||||
$(MAKE) docker-push IMG=$(CATALOG_IMG)
|
$(MAKE) docker-push IMG=$(CATALOG_IMG)
|
||||||
|
|
||||||
.PHONY: kubectl-slice
|
|
||||||
KUBECTL_SLICE = $(shell pwd)/bin/kubectl-slice
|
|
||||||
kubectl-slice: ## Download kubectl-slice locally if necessary.
|
|
||||||
ifeq (,$(wildcard $(KUBECTL_SLICE)))
|
|
||||||
ifeq (,$(shell which kubectl-slice 2>/dev/null))
|
|
||||||
@{ \
|
|
||||||
set -e ;\
|
|
||||||
mkdir -p $(dir $(KUBECTL_SLICE)) ;\
|
|
||||||
curl -sSLo - https://github.com/patrickdappollonio/kubectl-slice/releases/download/v1.1.0/kubectl-slice_1.1.0_$(OS)_$(ARCHX).tar.gz | \
|
|
||||||
tar xzf - -C bin/ kubectl-slice ;\
|
|
||||||
}
|
|
||||||
else
|
|
||||||
KUBECTL_SLICE = $(shell which kubectl-slice)
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
.PHONY: helm
|
|
||||||
HELM = $(shell pwd)/bin/helm
|
|
||||||
helm: ## Download helm locally if necessary.
|
|
||||||
ifeq (,$(wildcard $(HELM)))
|
|
||||||
ifeq (,$(shell which helm 2>/dev/null))
|
|
||||||
@{ \
|
|
||||||
set -e ;\
|
|
||||||
mkdir -p $(dir $(HELM)) ;\
|
|
||||||
curl -sSLo - https://get.helm.sh/helm-v3.8.0-$(OS)-$(ARCHA).tar.gz | \
|
|
||||||
tar xzf - -C bin/ $(OS)-$(ARCHA)/helm ;\
|
|
||||||
mv bin/$(OS)-$(ARCHA)/helm bin/helm ;\
|
|
||||||
rmdir bin/$(OS)-$(ARCHA) ;\
|
|
||||||
}
|
|
||||||
else
|
|
||||||
HELM = $(shell which helm)
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
.PHONY: yq
|
|
||||||
YQ = $(shell pwd)/bin/yq
|
|
||||||
yq: ## Download yq locally if necessary.
|
|
||||||
ifeq (,$(wildcard $(YQ)))
|
|
||||||
ifeq (,$(shell which yq 2>/dev/null))
|
|
||||||
@{ \
|
|
||||||
set -e ;\
|
|
||||||
mkdir -p $(dir $(HELM)) ;\
|
|
||||||
curl -sSLo - https://github.com/mikefarah/yq/releases/download/v4.20.2/yq_$(OS)_$(ARCHA).tar.gz | \
|
|
||||||
tar xzf - -C bin/ ;\
|
|
||||||
mv bin/yq_$(OS)_$(ARCHA) bin/yq ;\
|
|
||||||
}
|
|
||||||
else
|
|
||||||
YQ = $(shell which yq)
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
PHONY: cr
|
|
||||||
CR = $(shell pwd)/bin/cr
|
|
||||||
cr: ## Download cr locally if necessary.
|
|
||||||
ifeq (,$(wildcard $(CR)))
|
|
||||||
ifeq (,$(shell which cr 2>/dev/null))
|
|
||||||
@{ \
|
|
||||||
set -e ;\
|
|
||||||
mkdir -p $(dir $(CR)) ;\
|
|
||||||
curl -sSLo - https://github.com/helm/chart-releaser/releases/download/v1.3.0/chart-releaser_1.3.0_$(OS)_$(ARCHA).tar.gz | \
|
|
||||||
tar xzf - -C bin/ cr ;\
|
|
||||||
}
|
|
||||||
else
|
|
||||||
CR = $(shell which cr)
|
|
||||||
endif
|
|
||||||
endif
|
|
||||||
|
|
||||||
charts:
|
|
||||||
mkdir -p $@
|
|
||||||
|
|
||||||
.PHONY: helm-chart
|
|
||||||
helm-chart: helm-chart-generate helm-chart-slice
|
|
||||||
|
|
||||||
.PHONY: helm-chart-generate
|
|
||||||
helm-chart-generate: kustomize helm kubectl-slice yq charts
|
|
||||||
@echo "== KUSTOMIZE (image and namespace) =="
|
|
||||||
cd config/manager && $(KUSTOMIZE) edit set image controller=${IMG}
|
|
||||||
|
|
||||||
@echo "== HELM =="
|
|
||||||
cd charts && \
|
|
||||||
$(HELM) create awx-operator --starter $(shell pwd)/.helm/starter ;\
|
|
||||||
$(YQ) -i '.version = "$(VERSION)"' $(CHART_NAME)/Chart.yaml ;\
|
|
||||||
$(YQ) -i '.appVersion = "$(VERSION)" | .appVersion style="double"' $(CHART_NAME)/Chart.yaml ;\
|
|
||||||
$(YQ) -i '.description = "$(CHART_DESCRIPTION)"' $(CHART_NAME)/Chart.yaml ;\
|
|
||||||
|
|
||||||
@cat charts/$(CHART_NAME)/Chart.yaml
|
|
||||||
|
|
||||||
@echo "== KUSTOMIZE (annotation) =="
|
|
||||||
cd config/manager && $(KUSTOMIZE) edit set annotation helm.sh/chart:$(CHART_NAME)-$(VERSION)
|
|
||||||
cd config/default && $(KUSTOMIZE) edit set annotation helm.sh/chart:$(CHART_NAME)-$(VERSION)
|
|
||||||
|
|
||||||
@echo "== SLICE =="
|
|
||||||
$(KUSTOMIZE) build --load-restrictor LoadRestrictionsNone config/default | \
|
|
||||||
$(KUBECTL_SLICE) --input-file=- \
|
|
||||||
--output-dir=charts/$(CHART_NAME)/templates \
|
|
||||||
--sort-by-kind
|
|
||||||
@echo "AWX Operator installed with Helm Chart version $(VERSION)" > charts/$(CHART_NAME)/templates/NOTES.txt
|
|
||||||
mkdir charts/$(CHART_NAME)/crds
|
|
||||||
mv charts/$(CHART_NAME)/templates/customresourcedefinition* charts/$(CHART_NAME)/crds
|
|
||||||
|
|
||||||
.PHONY: helm-chart-edit
|
|
||||||
helm-chart-slice:
|
|
||||||
@echo "== EDIT =="
|
|
||||||
$(foreach file, $(wildcard charts/$(CHART_NAME)/templates/*),$(YQ) -i 'del(.. | select(has("namespace")).namespace)' $(file);)
|
|
||||||
$(foreach file, $(wildcard charts/$(CHART_NAME)/templates/*rolebinding*),$(YQ) -i '.subjects[0].namespace = "{{ .Release.Namespace }}"' $(file);)
|
|
||||||
rm -f charts/$(CHART_NAME)/templates/namespace*.yaml
|
|
||||||
|
|
||||||
|
|
||||||
.PHONY: helm-package
|
|
||||||
helm-package: cr helm-chart
|
|
||||||
@echo "== CHART RELEASER (package) =="
|
|
||||||
$(CR) package ./charts/awx-operator
|
|
||||||
|
|
||||||
# The actual release happens in ansible/helm-release.yml
|
|
||||||
# until https://github.com/helm/chart-releaser/issues/122 happens
|
|
||||||
.PHONY: helm-index
|
|
||||||
helm-index: cr helm-chart
|
|
||||||
@echo "== CHART RELEASER (httpsorigin) =="
|
|
||||||
git remote add httpsorigin "https://github.com/$(CHART_OWNER)/$(CHART_REPO).git"
|
|
||||||
git fetch httpsorigin
|
|
||||||
|
|
||||||
@echo "== CHART RELEASER (index) =="
|
|
||||||
$(CR) index \
|
|
||||||
--owner "$(CHART_OWNER)" \
|
|
||||||
--git-repo "$(CHART_REPO)" \
|
|
||||||
--token "$(CR_TOKEN)" \
|
|
||||||
--pages-branch "$(CHART_BRANCH)" \
|
|
||||||
--index-path "./charts/$(CHART_INDEX)" \
|
|
||||||
--charts-repo "https://$(CHART_OWNER).github.io/$(CHART_REPO)/$(CHART_INDEX)" \
|
|
||||||
--remote httpsorigin \
|
|
||||||
--release-name-template="{{ .Version }}" \
|
|
||||||
--push
|
|
||||||
|
|||||||
@@ -1,3 +1,7 @@
|
|||||||
|
# Code generated by tool. DO NOT EDIT.
|
||||||
|
# This file is used to track the info used to scaffold your project
|
||||||
|
# and allow the plugins properly work.
|
||||||
|
# More info: https://book.kubebuilder.io/reference/project-config.html
|
||||||
domain: ansible.com
|
domain: ansible.com
|
||||||
layout:
|
layout:
|
||||||
- ansible.sdk.operatorframework.io/v1
|
- ansible.sdk.operatorframework.io/v1
|
||||||
@@ -13,4 +17,25 @@ resources:
|
|||||||
group: awx
|
group: awx
|
||||||
kind: AWX
|
kind: AWX
|
||||||
version: v1beta1
|
version: v1beta1
|
||||||
|
- api:
|
||||||
|
crdVersion: v1
|
||||||
|
namespaced: true
|
||||||
|
domain: ansible.com
|
||||||
|
group: awx
|
||||||
|
kind: AWXBackup
|
||||||
|
version: v1beta1
|
||||||
|
- api:
|
||||||
|
crdVersion: v1
|
||||||
|
namespaced: true
|
||||||
|
domain: ansible.com
|
||||||
|
group: awx
|
||||||
|
kind: AWXRestore
|
||||||
|
version: v1beta1
|
||||||
|
- api:
|
||||||
|
crdVersion: v1
|
||||||
|
namespaced: true
|
||||||
|
domain: ansible.com
|
||||||
|
group: awx
|
||||||
|
kind: AWXMeshIngress
|
||||||
|
version: v1alpha1
|
||||||
version: "3"
|
version: "3"
|
||||||
|
|||||||
@@ -1,47 +0,0 @@
|
|||||||
---
|
|
||||||
- hosts: localhost
|
|
||||||
vars:
|
|
||||||
chart_repo: awx-operator
|
|
||||||
tasks:
|
|
||||||
- name: Look up release
|
|
||||||
uri:
|
|
||||||
url: "https://api.github.com/repos/{{ chart_owner }}/{{ chart_repo }}/releases/tags/{{ tag }}"
|
|
||||||
register: release
|
|
||||||
ignore_errors: yes
|
|
||||||
|
|
||||||
- fail:
|
|
||||||
msg: |
|
|
||||||
Release must exist before running this playbook
|
|
||||||
when: release is not success
|
|
||||||
|
|
||||||
- name: Build and package helm chart
|
|
||||||
command: |
|
|
||||||
make helm-chart helm-package
|
|
||||||
environment:
|
|
||||||
VERSION: "{{ tag }}"
|
|
||||||
IMAGE_TAG_BASE: "{{ operator_image }}"
|
|
||||||
args:
|
|
||||||
chdir: "{{ playbook_dir }}/../"
|
|
||||||
|
|
||||||
# Move to chart releaser after https://github.com/helm/chart-releaser/issues/122 exists
|
|
||||||
- name: Upload helm chart
|
|
||||||
uri:
|
|
||||||
url: "https://uploads.github.com/repos/{{ chart_owner }}/{{ chart_repo }}/releases/{{ release.json.id }}/assets?name=awx-operator-{{ tag }}.tgz"
|
|
||||||
src: "{{ playbook_dir }}/../.cr-release-packages/awx-operator-{{ tag }}.tgz"
|
|
||||||
headers:
|
|
||||||
Authorization: "token {{ gh_token }}"
|
|
||||||
Content-Type: "application/octet-stream"
|
|
||||||
status_code:
|
|
||||||
- 200
|
|
||||||
- 201
|
|
||||||
register: asset_upload
|
|
||||||
changed_when: asset_upload.json.state == "uploaded"
|
|
||||||
|
|
||||||
- name: Publish helm index
|
|
||||||
command: |
|
|
||||||
make helm-index
|
|
||||||
environment:
|
|
||||||
CHART_OWNER: "{{ chart_owner }}"
|
|
||||||
CR_TOKEN: "{{ gh_token }}"
|
|
||||||
args:
|
|
||||||
chdir: "{{ playbook_dir }}/../"
|
|
||||||
@@ -26,6 +26,7 @@
|
|||||||
image_version: "{{ image_version | default(omit) }}"
|
image_version: "{{ image_version | default(omit) }}"
|
||||||
development_mode: "{{ development_mode | default(omit) | bool }}"
|
development_mode: "{{ development_mode | default(omit) | bool }}"
|
||||||
image_pull_policy: "{{ image_pull_policy | default(omit) }}"
|
image_pull_policy: "{{ image_pull_policy | default(omit) }}"
|
||||||
|
nodeport_port: "{{ nodeport_port | default(omit) }}"
|
||||||
# ee_images:
|
# ee_images:
|
||||||
# - name: test-ee
|
# - name: test-ee
|
||||||
# image: quay.io/<user>/awx-ee
|
# image: quay.io/<user>/awx-ee
|
||||||
|
|||||||
Submodule
+1
Submodule awx-local-setup added at 434e91144b
@@ -0,0 +1,17 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=AWX Network Bridge - Permanent access to AWX on 192.168.1.144:8082
|
||||||
|
After=minikube.service
|
||||||
|
Requires=minikube.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
User=alex
|
||||||
|
ExecStartPre=/bin/bash -c 'until minikube status | grep -q "Running"; do sleep 5; done'
|
||||||
|
ExecStartPre=/bin/bash -c 'until kubectl get pods -n awx | grep awx-web | grep -q Running; do sleep 5; done'
|
||||||
|
ExecStart=/usr/bin/socat TCP-LISTEN:8082,bind=192.168.1.144,fork,reuseaddr TCP:192.168.49.2:31080
|
||||||
|
Restart=always
|
||||||
|
RestartSec=10
|
||||||
|
Environment=HOME=/home/alex
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: awx-web-nodeport
|
||||||
|
namespace: awx
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/component: awx
|
||||||
|
app.kubernetes.io/name: awx-web
|
||||||
|
ports:
|
||||||
|
- protocol: TCP
|
||||||
|
port: 8082
|
||||||
|
targetPort: 8052
|
||||||
|
type: LoadBalancer
|
||||||
|
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx
|
||||||
|
namespace: awx
|
||||||
|
spec:
|
||||||
|
service_type: NodePort
|
||||||
|
ingress_type: none
|
||||||
|
hostname: awx.local
|
||||||
|
nodePort: 8081 # Change to an available port, like 8081 or 8082
|
||||||
|
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1alpha1
|
||||||
|
kind: AWXMeshIngress
|
||||||
|
metadata:
|
||||||
|
name: awx-mesh-ingress-demo
|
||||||
|
spec:
|
||||||
|
deployment_name: awx-demo
|
||||||
@@ -0,0 +1,147 @@
|
|||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: awxbackups.awx.ansible.com
|
||||||
|
spec:
|
||||||
|
group: awx.ansible.com
|
||||||
|
names:
|
||||||
|
kind: AWXBackup
|
||||||
|
listKind: AWXBackupList
|
||||||
|
plural: awxbackups
|
||||||
|
singular: awxbackup
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1beta1
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
type: object
|
||||||
|
description: Schema validation for the AWXBackup CRD
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
type: object
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
required:
|
||||||
|
- deployment_name
|
||||||
|
properties:
|
||||||
|
deployment_name:
|
||||||
|
description: Name of the deployment to be backed up
|
||||||
|
type: string
|
||||||
|
backup_pvc:
|
||||||
|
description: Name of the backup PVC
|
||||||
|
type: string
|
||||||
|
backup_pvc_namespace:
|
||||||
|
description: (Deprecated) Namespace the PVC is in
|
||||||
|
type: string
|
||||||
|
backup_storage_requirements:
|
||||||
|
description: Storage requirements for backup PVC (may be similar to existing postgres PVC backing up from)
|
||||||
|
type: string
|
||||||
|
backup_resource_requirements:
|
||||||
|
description: Resource requirements for the management pod used to create a backup
|
||||||
|
properties:
|
||||||
|
requests:
|
||||||
|
properties:
|
||||||
|
cpu:
|
||||||
|
type: string
|
||||||
|
memory:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
limits:
|
||||||
|
properties:
|
||||||
|
cpu:
|
||||||
|
type: string
|
||||||
|
memory:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
backup_storage_class:
|
||||||
|
description: Storage class to use when creating PVC for backup
|
||||||
|
type: string
|
||||||
|
clean_backup_on_delete:
|
||||||
|
description: Flag to indicate if backup should be deleted on PVC if AWXBackup object is deleted
|
||||||
|
type: boolean
|
||||||
|
pg_dump_suffix:
|
||||||
|
description: Additional parameters for the pg_dump command
|
||||||
|
type: string
|
||||||
|
postgres_label_selector:
|
||||||
|
description: Label selector used to identify postgres pod for backing up data
|
||||||
|
type: string
|
||||||
|
postgres_image:
|
||||||
|
description: Registry path to the PostgreSQL container to use
|
||||||
|
type: string
|
||||||
|
postgres_image_version:
|
||||||
|
description: PostgreSQL container image version to use
|
||||||
|
type: string
|
||||||
|
precreate_partition_hours:
|
||||||
|
description: Number of hours worth of events table partitions to precreate before backup to avoid pg_dump locks.
|
||||||
|
type: integer
|
||||||
|
format: int32
|
||||||
|
image_pull_policy:
|
||||||
|
description: The image pull policy
|
||||||
|
type: string
|
||||||
|
default: IfNotPresent
|
||||||
|
enum:
|
||||||
|
- Always
|
||||||
|
- always
|
||||||
|
- Never
|
||||||
|
- never
|
||||||
|
- IfNotPresent
|
||||||
|
- ifnotpresent
|
||||||
|
db_management_pod_node_selector:
|
||||||
|
description: nodeSelector for the Postgres pods to backup
|
||||||
|
type: string
|
||||||
|
no_log:
|
||||||
|
description: Configure no_log for no_log tasks
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
additional_labels:
|
||||||
|
description: Additional labels defined on the resource, which should be propagated to child resources
|
||||||
|
type: array
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
set_self_labels:
|
||||||
|
description: Maintain some of the recommended `app.kubernetes.io/*` labels on the resource (self)
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
status:
|
||||||
|
type: object
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
description: The resulting conditions when a Service Telemetry is instantiated
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
backupDirectory:
|
||||||
|
description: Backup directory name on the specified pvc
|
||||||
|
type: string
|
||||||
|
backupClaim:
|
||||||
|
description: Backup persistent volume claim
|
||||||
|
type: string
|
||||||
@@ -0,0 +1,464 @@
|
|||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: awxmeshingresses.awx.ansible.com
|
||||||
|
spec:
|
||||||
|
group: awx.ansible.com
|
||||||
|
names:
|
||||||
|
kind: AWXMeshIngress
|
||||||
|
listKind: AWXMeshIngressList
|
||||||
|
plural: awxmeshingresses
|
||||||
|
singular: awxmeshingress
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: AWXMeshIngress is the Schema for the awxmeshingresses API
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: Spec defines the desired state of AWXMeshIngress
|
||||||
|
type: object
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
required:
|
||||||
|
- deployment_name
|
||||||
|
properties:
|
||||||
|
deployment_name:
|
||||||
|
description: Name of the AWX deployment to create the Mesh Ingress for.
|
||||||
|
type: string
|
||||||
|
image_pull_secrets:
|
||||||
|
description: Image pull secrets for Mesh Ingress containers.
|
||||||
|
type: array
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
external_hostname:
|
||||||
|
description: External hostname to use for the Mesh Ingress.
|
||||||
|
type: string
|
||||||
|
external_ipaddress:
|
||||||
|
description: External IP address to use for the Mesh Ingress.
|
||||||
|
type: string
|
||||||
|
ingress_type:
|
||||||
|
description: The ingress type to use to reach the deployed instance
|
||||||
|
type: string
|
||||||
|
enum:
|
||||||
|
- none
|
||||||
|
- Ingress
|
||||||
|
- ingress
|
||||||
|
- IngressRouteTCP
|
||||||
|
- ingressroutetcp
|
||||||
|
- Route
|
||||||
|
- route
|
||||||
|
ingress_api_version:
|
||||||
|
description: The Ingress API version to use
|
||||||
|
type: string
|
||||||
|
ingress_annotations:
|
||||||
|
description: Annotations to add to the Ingress Controller
|
||||||
|
type: string
|
||||||
|
route_annotations:
|
||||||
|
description: Annotations to add to the OpenShift Route
|
||||||
|
type: string
|
||||||
|
ingress_class_name:
|
||||||
|
description: The name of ingress class to use instead of the cluster default.
|
||||||
|
type: string
|
||||||
|
ingress_controller:
|
||||||
|
description: Special configuration for specific Ingress Controllers
|
||||||
|
type: string
|
||||||
|
node_selector:
|
||||||
|
description: Assign the Mesh Ingress Pod to the specified node.
|
||||||
|
type: string
|
||||||
|
tolerations:
|
||||||
|
description: Scheduling tolerations for the Mesh Ingress instance.
|
||||||
|
type: string
|
||||||
|
topology_spread_constraints:
|
||||||
|
description: Topology spread constraints for the Mesh Ingress instance.
|
||||||
|
type: string
|
||||||
|
affinity:
|
||||||
|
description: Scheduling constraints to apply to the Pod definition
|
||||||
|
properties:
|
||||||
|
nodeAffinity:
|
||||||
|
properties:
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
preference:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchFields:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
weight:
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
required:
|
||||||
|
- preference
|
||||||
|
- weight
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
properties:
|
||||||
|
nodeSelectorTerms:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchFields:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- nodeSelectorTerms
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
type: object
|
||||||
|
podAffinity:
|
||||||
|
properties:
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
podAffinityTerm:
|
||||||
|
properties:
|
||||||
|
labelSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaceSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaces:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
topologyKey:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- topologyKey
|
||||||
|
type: object
|
||||||
|
weight:
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
required:
|
||||||
|
- podAffinityTerm
|
||||||
|
- weight
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
labelSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaceSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaces:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
topologyKey:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- topologyKey
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
type: object
|
||||||
|
podAntiAffinity:
|
||||||
|
properties:
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
podAffinityTerm:
|
||||||
|
properties:
|
||||||
|
labelSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaceSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaces:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
topologyKey:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- topologyKey
|
||||||
|
type: object
|
||||||
|
weight:
|
||||||
|
format: int32
|
||||||
|
type: integer
|
||||||
|
required:
|
||||||
|
- podAffinityTerm
|
||||||
|
- weight
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
labelSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaceSelector:
|
||||||
|
properties:
|
||||||
|
matchExpressions:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
type: string
|
||||||
|
operator:
|
||||||
|
type: string
|
||||||
|
values:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- operator
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
matchLabels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
x-kubernetes-map-type: atomic
|
||||||
|
namespaces:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
topologyKey:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- topologyKey
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: Status defines the observed state of AWXMeshIngress
|
||||||
|
type: object
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
@@ -0,0 +1,153 @@
|
|||||||
|
---
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: awxrestores.awx.ansible.com
|
||||||
|
spec:
|
||||||
|
group: awx.ansible.com
|
||||||
|
names:
|
||||||
|
kind: AWXRestore
|
||||||
|
listKind: AWXRestoreList
|
||||||
|
plural: awxrestores
|
||||||
|
singular: awxrestore
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1beta1
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
type: object
|
||||||
|
description: Schema validation for the AWXRestore CRD
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: 'APIVersion defines the versioned schema of this representation
|
||||||
|
of an object. Servers should convert recognized schemas to the latest
|
||||||
|
internal value, and may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: 'Kind is a string value representing the REST resource this
|
||||||
|
object represents. Servers may infer this from the endpoint the client
|
||||||
|
submits requests to. Cannot be updated. In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
type: object
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
required:
|
||||||
|
- deployment_name
|
||||||
|
properties:
|
||||||
|
backup_source:
|
||||||
|
description: Backup source
|
||||||
|
type: string
|
||||||
|
enum:
|
||||||
|
- Backup CR
|
||||||
|
- PVC
|
||||||
|
deployment_name:
|
||||||
|
description: Name of the restored deployment. This should be different from the original deployment name
|
||||||
|
if the original deployment still exists.
|
||||||
|
type: string
|
||||||
|
cluster_name:
|
||||||
|
description: Cluster name
|
||||||
|
type: string
|
||||||
|
backup_name:
|
||||||
|
description: AWXBackup object name
|
||||||
|
type: string
|
||||||
|
backup_pvc:
|
||||||
|
description: Name of the PVC to be restored from, set as a status found on the awxbackup object (backupClaim)
|
||||||
|
type: string
|
||||||
|
backup_pvc_namespace:
|
||||||
|
description: (Deprecated) Namespace the PVC is in
|
||||||
|
type: string
|
||||||
|
backup_dir:
|
||||||
|
description: Backup directory name, set as a status found on the awxbackup object (backupDirectory)
|
||||||
|
type: string
|
||||||
|
restore_resource_requirements:
|
||||||
|
description: Resource requirements for the management pod that restores AWX from a backup
|
||||||
|
properties:
|
||||||
|
requests:
|
||||||
|
properties:
|
||||||
|
cpu:
|
||||||
|
type: string
|
||||||
|
memory:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
limits:
|
||||||
|
properties:
|
||||||
|
cpu:
|
||||||
|
type: string
|
||||||
|
memory:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
postgres_label_selector:
|
||||||
|
description: Label selector used to identify postgres pod for backing up data
|
||||||
|
type: string
|
||||||
|
postgres_image:
|
||||||
|
description: Registry path to the PostgreSQL container to use
|
||||||
|
type: string
|
||||||
|
postgres_image_version:
|
||||||
|
description: PostgreSQL container image version to use
|
||||||
|
type: string
|
||||||
|
spec_overrides:
|
||||||
|
description: Overrides for the AWX spec
|
||||||
|
# type: string
|
||||||
|
type: object
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
image_pull_policy:
|
||||||
|
description: The image pull policy
|
||||||
|
type: string
|
||||||
|
default: IfNotPresent
|
||||||
|
enum:
|
||||||
|
- Always
|
||||||
|
- always
|
||||||
|
- Never
|
||||||
|
- never
|
||||||
|
- IfNotPresent
|
||||||
|
- ifnotpresent
|
||||||
|
db_management_pod_node_selector:
|
||||||
|
description: nodeSelector for the Postgres pods to backup
|
||||||
|
type: string
|
||||||
|
no_log:
|
||||||
|
description: Configure no_log for no_log tasks
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
additional_labels:
|
||||||
|
description: Additional labels defined on the resource, which should be propagated to child resources
|
||||||
|
type: array
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
set_self_labels:
|
||||||
|
description: Maintain some of the recommended `app.kubernetes.io/*` labels on the resource (self)
|
||||||
|
type: boolean
|
||||||
|
default: true
|
||||||
|
force_drop_db:
|
||||||
|
description: Force drop the database before restoring. USE WITH CAUTION!
|
||||||
|
type: boolean
|
||||||
|
default: false
|
||||||
|
status:
|
||||||
|
type: object
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
description: The resulting conditions when a Service Telemetry is instantiated
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
type: string
|
||||||
|
reason:
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
restoreComplete:
|
||||||
|
description: Restore process complete
|
||||||
|
type: boolean
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,87 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: awxbackups.awx.ansible.com
|
|
||||||
spec:
|
|
||||||
group: awx.ansible.com
|
|
||||||
names:
|
|
||||||
kind: AWXBackup
|
|
||||||
listKind: AWXBackupList
|
|
||||||
plural: awxbackups
|
|
||||||
singular: awxbackup
|
|
||||||
scope: Namespaced
|
|
||||||
versions:
|
|
||||||
- name: v1beta1
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
schema:
|
|
||||||
openAPIV3Schema:
|
|
||||||
type: object
|
|
||||||
x-kubernetes-preserve-unknown-fields: true
|
|
||||||
description: Schema validation for the AWXBackup CRD
|
|
||||||
properties:
|
|
||||||
spec:
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- deployment_name
|
|
||||||
properties:
|
|
||||||
deployment_name:
|
|
||||||
description: Name of the deployment to be backed up
|
|
||||||
type: string
|
|
||||||
backup_pvc:
|
|
||||||
description: Name of the backup PVC
|
|
||||||
type: string
|
|
||||||
backup_pvc_namespace:
|
|
||||||
description: (Deprecated) Namespace the PVC is in
|
|
||||||
type: string
|
|
||||||
backup_storage_requirements:
|
|
||||||
description: Storage requirements for backup PVC (may be similar to existing postgres PVC backing up from)
|
|
||||||
type: string
|
|
||||||
backup_storage_class:
|
|
||||||
description: Storage class to use when creating PVC for backup
|
|
||||||
type: string
|
|
||||||
clean_backup_on_delete:
|
|
||||||
description: Flag to indicate if backup should be deleted on PVC if AWXBackup object is deleted
|
|
||||||
type: boolean
|
|
||||||
postgres_label_selector:
|
|
||||||
description: Label selector used to identify postgres pod for backing up data
|
|
||||||
type: string
|
|
||||||
postgres_image:
|
|
||||||
description: Registry path to the PostgreSQL container to use
|
|
||||||
type: string
|
|
||||||
postgres_image_version:
|
|
||||||
description: PostgreSQL container image version to use
|
|
||||||
type: string
|
|
||||||
no_log:
|
|
||||||
description: Configure no_log for no_log tasks
|
|
||||||
type: string
|
|
||||||
set_self_labels:
|
|
||||||
description: Maintain some of the recommended `app.kubernetes.io/*` labels on the resource (self)
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
status:
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
conditions:
|
|
||||||
description: The resulting conditions when a Service Telemetry is instantiated
|
|
||||||
items:
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
type: string
|
|
||||||
type:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
backupDirectory:
|
|
||||||
description: Backup directory name on the specified pvc
|
|
||||||
type: string
|
|
||||||
backupClaim:
|
|
||||||
description: Backup persistent volume claim
|
|
||||||
type: string
|
|
||||||
@@ -1,86 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
|
||||||
kind: CustomResourceDefinition
|
|
||||||
metadata:
|
|
||||||
name: awxrestores.awx.ansible.com
|
|
||||||
spec:
|
|
||||||
group: awx.ansible.com
|
|
||||||
names:
|
|
||||||
kind: AWXRestore
|
|
||||||
listKind: AWXRestoreList
|
|
||||||
plural: awxrestores
|
|
||||||
singular: awxrestore
|
|
||||||
scope: Namespaced
|
|
||||||
versions:
|
|
||||||
- name: v1beta1
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
schema:
|
|
||||||
openAPIV3Schema:
|
|
||||||
type: object
|
|
||||||
x-kubernetes-preserve-unknown-fields: true
|
|
||||||
description: Schema validation for the AWXRestore CRD
|
|
||||||
properties:
|
|
||||||
spec:
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
backup_source:
|
|
||||||
description: Backup source
|
|
||||||
type: string
|
|
||||||
enum:
|
|
||||||
- CR
|
|
||||||
- PVC
|
|
||||||
deployment_name:
|
|
||||||
description: Name of the restored deployment. This should be different from the original deployment name
|
|
||||||
if the original deployment still exists.
|
|
||||||
type: string
|
|
||||||
backup_name:
|
|
||||||
description: AWXBackup object name
|
|
||||||
type: string
|
|
||||||
backup_pvc:
|
|
||||||
description: Name of the PVC to be restored from, set as a status found on the awxbackup object (backupClaim)
|
|
||||||
type: string
|
|
||||||
backup_pvc_namespace:
|
|
||||||
description: (Deprecated) Namespace the PVC is in
|
|
||||||
type: string
|
|
||||||
backup_dir:
|
|
||||||
description: Backup directory name, set as a status found on the awxbackup object (backupDirectory)
|
|
||||||
type: string
|
|
||||||
postgres_label_selector:
|
|
||||||
description: Label selector used to identify postgres pod for backing up data
|
|
||||||
type: string
|
|
||||||
postgres_image:
|
|
||||||
description: Registry path to the PostgreSQL container to use
|
|
||||||
type: string
|
|
||||||
postgres_image_version:
|
|
||||||
description: PostgreSQL container image version to use
|
|
||||||
type: string
|
|
||||||
no_log:
|
|
||||||
description: Configure no_log for no_log tasks
|
|
||||||
type: string
|
|
||||||
set_self_labels:
|
|
||||||
description: Maintain some of the recommended `app.kubernetes.io/*` labels on the resource (self)
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
status:
|
|
||||||
type: object
|
|
||||||
properties:
|
|
||||||
conditions:
|
|
||||||
description: The resulting conditions when a Service Telemetry is instantiated
|
|
||||||
items:
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
type: string
|
|
||||||
reason:
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
type: string
|
|
||||||
type:
|
|
||||||
type: string
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
restoreComplete:
|
|
||||||
description: Restore process complete
|
|
||||||
type: boolean
|
|
||||||
@@ -1,9 +1,9 @@
|
|||||||
---
|
|
||||||
# This kustomization.yaml is not intended to be run by itself,
|
# This kustomization.yaml is not intended to be run by itself,
|
||||||
# since it depends on service name and namespace that are out of this kustomize package.
|
# since it depends on service name and namespace that are out of this kustomize package.
|
||||||
# It should be run by config/default
|
# It should be run by config/default
|
||||||
resources:
|
resources:
|
||||||
- bases/awx.ansible.com_awxs.yaml
|
- bases/awx.ansible.com_awxs.yaml
|
||||||
- bases/awxbackup.ansible.com_awxbackups.yaml
|
- bases/awx.ansible.com_awxbackups.yaml
|
||||||
- bases/awxrestore.ansible.com_awxrestores.yaml
|
- bases/awx.ansible.com_awxrestores.yaml
|
||||||
# +kubebuilder:scaffold:crdkustomizeresource
|
- bases/awx.ansible.com_awxmeshingresses.yaml
|
||||||
|
#+kubebuilder:scaffold:crdkustomizeresource
|
||||||
|
|||||||
@@ -1,24 +1,30 @@
|
|||||||
# Adds namespace to all resources.
|
# Adds namespace to all resources.
|
||||||
namespace: awx
|
namespace: awx
|
||||||
|
|
||||||
# Value of this field is prepended to the
|
# Value of this field is prepended to the
|
||||||
# names of all resources, e.g. a deployment named
|
# names of all resources, e.g. a deployment named
|
||||||
# "wordpress" becomes "alices-wordpress".
|
# "wordpress" becomes "alices-wordpress".
|
||||||
# Note that it should also match with the prefix (text before '-') of the namespace
|
# Note that it should also match with the prefix (text before '-') of the namespace
|
||||||
# field above.
|
# field above.
|
||||||
namePrefix: awx-operator-
|
namePrefix: awx-operator-
|
||||||
|
|
||||||
# Labels to add to all resources and selectors.
|
# Labels to add to all resources and selectors.
|
||||||
# commonLabels:
|
#labels:
|
||||||
# someName: someValue
|
#- includeSelectors: true
|
||||||
# [PROMETHEUS] To enable prometheus monitor, uncomment all sections with 'PROMETHEUS'.
|
# pairs:
|
||||||
# - ../prometheus
|
# someName: someValue
|
||||||
# Protect the /metrics endpoint by putting it behind auth.
|
|
||||||
# If you want your controller-manager to expose the /metrics
|
|
||||||
# endpoint w/o any authn/z, please comment the following line.
|
|
||||||
patchesStrategicMerge:
|
|
||||||
- manager_auth_proxy_patch.yaml
|
|
||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
resources:
|
resources:
|
||||||
- ../crd
|
- ../crd
|
||||||
- ../rbac
|
- ../rbac
|
||||||
- ../manager
|
- ../manager
|
||||||
|
# [PROMETHEUS] To enable prometheus monitor, uncomment all sections with 'PROMETHEUS'.
|
||||||
|
#- ../prometheus
|
||||||
|
|
||||||
|
# Protect the /metrics endpoint by putting it behind auth.
|
||||||
|
# If you want your controller-manager to expose the /metrics
|
||||||
|
# endpoint w/o any authn/z, please comment the following line.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
patches:
|
||||||
|
- path: manager_auth_proxy_patch.yaml
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
# This patch inject a sidecar container which is a HTTP proxy for the
|
# This patch inject a sidecar container which is a HTTP proxy for the
|
||||||
# controller manager, it performs RBAC authorization against the Kubernetes API using SubjectAccessReviews.
|
# controller manager, it performs RBAC authorization against the Kubernetes API using SubjectAccessReviews.
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
@@ -10,20 +9,32 @@ spec:
|
|||||||
template:
|
template:
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: kube-rbac-proxy
|
- name: kube-rbac-proxy
|
||||||
image: gcr.io/kubebuilder/kube-rbac-proxy:v0.8.0
|
securityContext:
|
||||||
args:
|
allowPrivilegeEscalation: false
|
||||||
- "--secure-listen-address=0.0.0.0:8443"
|
capabilities:
|
||||||
- "--upstream=http://127.0.0.1:8080/"
|
drop:
|
||||||
- "--logtostderr=true"
|
- "ALL"
|
||||||
- "--v=10"
|
image: gcr.io/kubebuilder/kube-rbac-proxy:v0.15.0
|
||||||
ports:
|
args:
|
||||||
- containerPort: 8443
|
- "--secure-listen-address=0.0.0.0:8443"
|
||||||
protocol: TCP
|
- "--upstream=http://127.0.0.1:8080/"
|
||||||
name: https
|
- "--logtostderr=true"
|
||||||
- name: awx-manager
|
- "--v=0"
|
||||||
args:
|
ports:
|
||||||
- "--health-probe-bind-address=:6789"
|
- containerPort: 8443
|
||||||
- "--metrics-bind-address=127.0.0.1:8080"
|
protocol: TCP
|
||||||
- "--leader-elect"
|
name: https
|
||||||
- "--leader-election-id=awx-operator"
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 128Mi
|
||||||
|
requests:
|
||||||
|
cpu: 5m
|
||||||
|
memory: 64Mi
|
||||||
|
- name: awx-manager
|
||||||
|
args:
|
||||||
|
- "--health-probe-bind-address=:6789"
|
||||||
|
- "--metrics-bind-address=127.0.0.1:8080"
|
||||||
|
- "--leader-elect"
|
||||||
|
- "--leader-election-id=awx-operator"
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
@@ -8,14 +7,14 @@ spec:
|
|||||||
template:
|
template:
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: awx-manager
|
- name: awx-manager
|
||||||
args:
|
args:
|
||||||
- "--config=controller_manager_config.yaml"
|
- "--config=controller_manager_config.yaml"
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: awx-manager-config
|
|
||||||
mountPath: /controller_manager_config.yaml
|
|
||||||
subPath: controller_manager_config.yaml
|
|
||||||
volumes:
|
|
||||||
- name: awx-manager-config
|
- name: awx-manager-config
|
||||||
configMap:
|
mountPath: /controller_manager_config.yaml
|
||||||
name: awx-manager-config
|
subPath: controller_manager_config.yaml
|
||||||
|
volumes:
|
||||||
|
- name: awx-manager-config
|
||||||
|
configMap:
|
||||||
|
name: awx-manager-config
|
||||||
|
|||||||
@@ -1,10 +1,20 @@
|
|||||||
---
|
apiVersion: controller-runtime.sigs.k8s.io/v1alpha1
|
||||||
apiVersion: controller-runtime.sigs.k8s.io/v1beta1
|
|
||||||
kind: ControllerManagerConfig
|
kind: ControllerManagerConfig
|
||||||
health:
|
health:
|
||||||
healthProbeBindAddress: :6789
|
healthProbeBindAddress: :6789
|
||||||
metrics:
|
metrics:
|
||||||
bindAddress: 127.0.0.1:8080
|
bindAddress: 127.0.0.1:8080
|
||||||
|
|
||||||
leaderElection:
|
leaderElection:
|
||||||
leaderElect: true
|
leaderElect: true
|
||||||
resourceName: 811c9dc5.ansible.com
|
resourceName: 811c9dc5.ansible.com
|
||||||
|
# leaderElectionReleaseOnCancel defines if the leader should step down volume
|
||||||
|
# when the Manager ends. This requires the binary to immediately end when the
|
||||||
|
# Manager is stopped, otherwise, this setting is unsafe. Setting this significantly
|
||||||
|
# speeds up voluntary leader transitions as the new leader don't have to wait
|
||||||
|
# LeaseDuration time first.
|
||||||
|
# In the default scaffold provided, the program ends immediately after
|
||||||
|
# the manager stops, so would be fine to enable this option. However,
|
||||||
|
# if you are doing or is intended to do any operation such as perform cleanups
|
||||||
|
# after the manager stops then its usage might be unsafe.
|
||||||
|
# leaderElectionReleaseOnCancel: true
|
||||||
|
|||||||
@@ -1,11 +1,14 @@
|
|||||||
resources:
|
resources:
|
||||||
- manager.yaml
|
- manager.yaml
|
||||||
|
|
||||||
generatorOptions:
|
generatorOptions:
|
||||||
disableNameSuffixHash: true
|
disableNameSuffixHash: true
|
||||||
|
|
||||||
configMapGenerator:
|
configMapGenerator:
|
||||||
- files:
|
- files:
|
||||||
- controller_manager_config.yaml
|
- controller_manager_config.yaml
|
||||||
name: awx-manager-config
|
name: awx-manager-config
|
||||||
|
|
||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
images:
|
images:
|
||||||
|
|||||||
+50
-36
@@ -20,48 +20,62 @@ spec:
|
|||||||
replicas: 1
|
replicas: 1
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
|
annotations:
|
||||||
|
kubectl.kubernetes.io/default-container: awx-manager
|
||||||
labels:
|
labels:
|
||||||
control-plane: controller-manager
|
control-plane: controller-manager
|
||||||
spec:
|
spec:
|
||||||
securityContext:
|
securityContext:
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
|
# For common cases that do not require escalating privileges
|
||||||
|
# it is recommended to ensure that all your Pods/Containers are restrictive.
|
||||||
|
# More info: https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
|
||||||
|
# Please uncomment the following code if your project does NOT have to work on old Kubernetes
|
||||||
|
# versions < 1.19 or on vendors versions which do NOT support this field by default (i.e. Openshift < 4.11 ).
|
||||||
|
# seccompProfile:
|
||||||
|
# type: RuntimeDefault
|
||||||
containers:
|
containers:
|
||||||
- args:
|
- args:
|
||||||
- --leader-elect
|
- --leader-elect
|
||||||
- --leader-election-id=awx-operator
|
- --leader-election-id=awx-operator
|
||||||
image: controller:latest
|
image: controller:latest
|
||||||
name: awx-manager
|
imagePullPolicy: IfNotPresent
|
||||||
env:
|
name: awx-manager
|
||||||
- name: ANSIBLE_GATHERING
|
env:
|
||||||
value: explicit
|
- name: ANSIBLE_GATHERING
|
||||||
- name: ANSIBLE_DEBUG_LOGS
|
value: explicit
|
||||||
value: 'false'
|
- name: ANSIBLE_DEBUG_LOGS
|
||||||
- name: WATCH_NAMESPACE
|
value: 'false'
|
||||||
valueFrom:
|
- name: WATCH_NAMESPACE
|
||||||
fieldRef:
|
valueFrom:
|
||||||
fieldPath: metadata.namespace
|
fieldRef:
|
||||||
securityContext:
|
fieldPath: metadata.namespace
|
||||||
allowPrivilegeEscalation: false
|
securityContext:
|
||||||
livenessProbe:
|
allowPrivilegeEscalation: false
|
||||||
httpGet:
|
capabilities:
|
||||||
path: /healthz
|
drop:
|
||||||
port: 6789
|
- "ALL"
|
||||||
initialDelaySeconds: 15
|
livenessProbe:
|
||||||
periodSeconds: 20
|
httpGet:
|
||||||
readinessProbe:
|
path: /healthz
|
||||||
httpGet:
|
port: 6789
|
||||||
path: /readyz
|
initialDelaySeconds: 15
|
||||||
port: 6789
|
periodSeconds: 20
|
||||||
initialDelaySeconds: 5
|
readinessProbe:
|
||||||
periodSeconds: 10
|
httpGet:
|
||||||
resources:
|
path: /readyz
|
||||||
requests:
|
port: 6789
|
||||||
memory: "32Mi"
|
initialDelaySeconds: 5
|
||||||
cpu: "50m"
|
periodSeconds: 10
|
||||||
limits:
|
# More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
|
||||||
memory: "4096Mi"
|
resources:
|
||||||
cpu: "2000m"
|
requests:
|
||||||
|
memory: "32Mi"
|
||||||
|
cpu: "50m"
|
||||||
|
limits:
|
||||||
|
memory: "4000Mi"
|
||||||
|
cpu: "2000m"
|
||||||
serviceAccountName: controller-manager
|
serviceAccountName: controller-manager
|
||||||
imagePullSecrets:
|
imagePullSecrets:
|
||||||
- name: redhat-operators-pull-secret
|
- name: redhat-operators-pull-secret
|
||||||
terminationGracePeriodSeconds: 10
|
terminationGracePeriodSeconds: 10
|
||||||
|
|||||||
File diff suppressed because one or more lines are too long
@@ -1,8 +1,7 @@
|
|||||||
---
|
|
||||||
# These resources constitute the fully configured set of manifests
|
# These resources constitute the fully configured set of manifests
|
||||||
# used to generate the 'manifests/' directory in a bundle.
|
# used to generate the 'manifests/' directory in a bundle.
|
||||||
resources:
|
resources:
|
||||||
- bases/awx-operator.clusterserviceversion.yaml
|
- bases/awx-operator.clusterserviceversion.yaml
|
||||||
- ../default
|
- ../default
|
||||||
- ../samples
|
- ../samples
|
||||||
- ../scorecard
|
- ../scorecard
|
||||||
|
|||||||
@@ -1,3 +1,2 @@
|
|||||||
---
|
|
||||||
resources:
|
resources:
|
||||||
- monitor.yaml
|
- monitor.yaml
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
# Prometheus Monitor Service (Metrics)
|
# Prometheus Monitor Service (Metrics)
|
||||||
apiVersion: monitoring.coreos.com/v1
|
apiVersion: monitoring.coreos.com/v1
|
||||||
kind: ServiceMonitor
|
kind: ServiceMonitor
|
||||||
|
|||||||
@@ -1,10 +1,9 @@
|
|||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: metrics-reader
|
name: metrics-reader
|
||||||
rules:
|
rules:
|
||||||
- nonResourceURLs:
|
- nonResourceURLs:
|
||||||
- "/metrics"
|
- "/metrics"
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
|
|||||||
@@ -1,18 +1,17 @@
|
|||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: proxy-role
|
name: proxy-role
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- authentication.k8s.io
|
- authentication.k8s.io
|
||||||
resources:
|
resources:
|
||||||
- tokenreviews
|
- tokenreviews
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- authorization.k8s.io
|
- authorization.k8s.io
|
||||||
resources:
|
resources:
|
||||||
- subjectaccessreviews
|
- subjectaccessreviews
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
@@ -8,6 +7,6 @@ roleRef:
|
|||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: proxy-role
|
name: proxy-role
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: controller-manager
|
name: controller-manager
|
||||||
namespace: system
|
namespace: system
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
@@ -8,9 +7,9 @@ metadata:
|
|||||||
namespace: system
|
namespace: system
|
||||||
spec:
|
spec:
|
||||||
ports:
|
ports:
|
||||||
- name: https
|
- name: https
|
||||||
port: 8443
|
port: 8443
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
targetPort: https
|
targetPort: https
|
||||||
selector:
|
selector:
|
||||||
control-plane: controller-manager
|
control-plane: controller-manager
|
||||||
|
|||||||
@@ -1,25 +1,24 @@
|
|||||||
---
|
|
||||||
# permissions for end users to edit awxs.
|
# permissions for end users to edit awxs.
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: awx-editor-role
|
name: awx-editor-role
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- awx.ansible.com
|
- awx.ansible.com
|
||||||
resources:
|
resources:
|
||||||
- awxs
|
- awxs
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
- delete
|
- delete
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- patch
|
- patch
|
||||||
- update
|
- update
|
||||||
- watch
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- awx.ansible.com
|
- awx.ansible.com
|
||||||
resources:
|
resources:
|
||||||
- awxs/status
|
- awxs/status
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
|
|||||||
@@ -1,21 +1,20 @@
|
|||||||
---
|
|
||||||
# permissions for end users to view awxs.
|
# permissions for end users to view awxs.
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: awx-viewer-role
|
name: awx-viewer-role
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- awx.ansible.com
|
- awx.ansible.com
|
||||||
resources:
|
resources:
|
||||||
- awxs
|
- awxs
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- awx.ansible.com
|
- awx.ansible.com
|
||||||
resources:
|
resources:
|
||||||
- awxs/status
|
- awxs/status
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
# permissions for end users to edit awxbackups.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: awxbackup-editor-role
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxbackups
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxbackups/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
# permissions for end users to view awxbackups.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: awxbackup-viewer-role
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxbackups
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxbackups/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
# permissions for end users to edit awxmeshingresses.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: clusterrole
|
||||||
|
app.kubernetes.io/instance: awxmeshingress-editor-role
|
||||||
|
app.kubernetes.io/component: rbac
|
||||||
|
app.kubernetes.io/created-by: awx-operator
|
||||||
|
app.kubernetes.io/part-of: awx-operator
|
||||||
|
app.kubernetes.io/managed-by: kustomize
|
||||||
|
name: awxmeshingress-editor-role
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxmeshingresses
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxmeshingresses/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# permissions for end users to view awxmeshingresses.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: clusterrole
|
||||||
|
app.kubernetes.io/instance: awxmeshingress-viewer-role
|
||||||
|
app.kubernetes.io/component: rbac
|
||||||
|
app.kubernetes.io/created-by: awx-operator
|
||||||
|
app.kubernetes.io/part-of: awx-operator
|
||||||
|
app.kubernetes.io/managed-by: kustomize
|
||||||
|
name: awxmeshingress-viewer-role
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxmeshingresses
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxmeshingresses/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
# permissions for end users to edit awxrestores.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: awxrestore-editor-role
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxrestores
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxrestores/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
# permissions for end users to view awxrestores.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: awxrestore-viewer-role
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxrestores
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- awx.ansible.com
|
||||||
|
resources:
|
||||||
|
- awxrestores/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
@@ -1,19 +1,18 @@
|
|||||||
---
|
|
||||||
resources:
|
resources:
|
||||||
# All RBAC will be applied under this service account in
|
# All RBAC will be applied under this service account in
|
||||||
# the deployment namespace. You may comment out this resource
|
# the deployment namespace. You may comment out this resource
|
||||||
# if your manager will use a service account that exists at
|
# if your manager will use a service account that exists at
|
||||||
# runtime. Be sure to update RoleBinding and ClusterRoleBinding
|
# runtime. Be sure to update RoleBinding and ClusterRoleBinding
|
||||||
# subjects if changing service account names.
|
# subjects if changing service account names.
|
||||||
- service_account.yaml
|
- service_account.yaml
|
||||||
- role.yaml
|
- role.yaml
|
||||||
- role_binding.yaml
|
- role_binding.yaml
|
||||||
- leader_election_role.yaml
|
- leader_election_role.yaml
|
||||||
- leader_election_role_binding.yaml
|
- leader_election_role_binding.yaml
|
||||||
# Comment the following 4 lines if you want to disable
|
# Comment the following 4 lines if you want to disable
|
||||||
# the auth proxy (https://github.com/brancz/kube-rbac-proxy)
|
# the auth proxy (https://github.com/brancz/kube-rbac-proxy)
|
||||||
# which protects your /metrics endpoint.
|
# which protects your /metrics endpoint.
|
||||||
- auth_proxy_service.yaml
|
- auth_proxy_service.yaml
|
||||||
- auth_proxy_role.yaml
|
- auth_proxy_role.yaml
|
||||||
- auth_proxy_role_binding.yaml
|
- auth_proxy_role_binding.yaml
|
||||||
- auth_proxy_client_clusterrole.yaml
|
- auth_proxy_client_clusterrole.yaml
|
||||||
|
|||||||
@@ -1,38 +1,37 @@
|
|||||||
---
|
|
||||||
# permissions to do leader election.
|
# permissions to do leader election.
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: Role
|
kind: Role
|
||||||
metadata:
|
metadata:
|
||||||
name: leader-election-role
|
name: leader-election-role
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
- configmaps
|
- configmaps
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- create
|
- create
|
||||||
- update
|
- update
|
||||||
- patch
|
- patch
|
||||||
- delete
|
- delete
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- coordination.k8s.io
|
- coordination.k8s.io
|
||||||
resources:
|
resources:
|
||||||
- leases
|
- leases
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
- watch
|
- watch
|
||||||
- create
|
- create
|
||||||
- update
|
- update
|
||||||
- patch
|
- patch
|
||||||
- delete
|
- delete
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
resources:
|
resources:
|
||||||
- events
|
- events
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
- patch
|
- patch
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
@@ -8,6 +7,6 @@ roleRef:
|
|||||||
kind: Role
|
kind: Role
|
||||||
name: leader-election-role
|
name: leader-election-role
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: controller-manager
|
name: controller-manager
|
||||||
namespace: system
|
namespace: system
|
||||||
|
|||||||
+47
-2
@@ -20,7 +20,6 @@ rules:
|
|||||||
- watch
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- ""
|
- ""
|
||||||
- "rbac.authorization.k8s.io"
|
|
||||||
resources:
|
resources:
|
||||||
- pods
|
- pods
|
||||||
- services
|
- services
|
||||||
@@ -31,6 +30,17 @@ rules:
|
|||||||
- events
|
- events
|
||||||
- configmaps
|
- configmaps
|
||||||
- secrets
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- "rbac.authorization.k8s.io"
|
||||||
|
resources:
|
||||||
- roles
|
- roles
|
||||||
- rolebindings
|
- rolebindings
|
||||||
verbs:
|
verbs:
|
||||||
@@ -43,12 +53,22 @@ rules:
|
|||||||
- watch
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- apps
|
- apps
|
||||||
- networking.k8s.io
|
|
||||||
resources:
|
resources:
|
||||||
- deployments
|
- deployments
|
||||||
- daemonsets
|
- daemonsets
|
||||||
- replicasets
|
- replicasets
|
||||||
- statefulsets
|
- statefulsets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- networking.k8s.io
|
||||||
|
resources:
|
||||||
- ingresses
|
- ingresses
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
@@ -58,6 +78,18 @@ rules:
|
|||||||
- patch
|
- patch
|
||||||
- update
|
- update
|
||||||
- watch
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- batch
|
||||||
|
resources:
|
||||||
|
- cronjobs
|
||||||
|
- jobs
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- monitoring.coreos.com
|
- monitoring.coreos.com
|
||||||
resources:
|
resources:
|
||||||
@@ -104,3 +136,16 @@ rules:
|
|||||||
- awxrestores
|
- awxrestores
|
||||||
verbs:
|
verbs:
|
||||||
- '*'
|
- '*'
|
||||||
|
- apiGroups:
|
||||||
|
- traefik.containo.us
|
||||||
|
- traefik.io
|
||||||
|
resources:
|
||||||
|
- ingressroutetcps
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
metadata:
|
metadata:
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
# Placeholder to pass CI and allow bundle generation
|
||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1alpha1
|
||||||
|
kind: AWXMeshIngress
|
||||||
|
metadata:
|
||||||
|
name: example-awx-mesh-ingress
|
||||||
|
spec:
|
||||||
|
deployment_name: example-awx
|
||||||
@@ -0,0 +1,48 @@
|
|||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx-with-limits
|
||||||
|
spec:
|
||||||
|
task_resource_requirements:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 2000m
|
||||||
|
memory: 4Gi
|
||||||
|
web_resource_requirements:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 1000m
|
||||||
|
memory: 4Gi
|
||||||
|
ee_resource_requirements:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 64Mi
|
||||||
|
limits:
|
||||||
|
cpu: 1000m
|
||||||
|
memory: 4Gi
|
||||||
|
redis_resource_requirements:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 64Mi
|
||||||
|
limits:
|
||||||
|
cpu: 1000m
|
||||||
|
memory: 4Gi
|
||||||
|
rsyslog_resource_requirements:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 1000m
|
||||||
|
memory: 2Gi
|
||||||
|
init_container_resource_requirements:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 1000m
|
||||||
|
memory: 2Gi
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWXBackup
|
||||||
|
metadata:
|
||||||
|
name: example-awx-backup
|
||||||
|
spec:
|
||||||
|
deployment_name: example-awx
|
||||||
|
backup_resource_requirements:
|
||||||
|
limits:
|
||||||
|
cpu: "1000m"
|
||||||
|
memory: "4096Mi"
|
||||||
|
requests:
|
||||||
|
cpu: "25m"
|
||||||
|
memory: "32Mi"
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWXRestore
|
||||||
|
metadata:
|
||||||
|
name: awxrestore-sample
|
||||||
|
spec:
|
||||||
|
deployment_name: example-awx-2
|
||||||
|
backup_name: example-awx-backup
|
||||||
|
restore_resource_requirements:
|
||||||
|
limits:
|
||||||
|
cpu: "1000m"
|
||||||
|
memory: "4096Mi"
|
||||||
|
requests:
|
||||||
|
cpu: "25m"
|
||||||
|
memory: "32Mi"
|
||||||
@@ -1,5 +1,7 @@
|
|||||||
---
|
|
||||||
## Append samples you want in your CSV to this file as resources ##
|
## Append samples you want in your CSV to this file as resources ##
|
||||||
resources:
|
resources:
|
||||||
- awx_v1beta1_awx.yaml
|
- awx_v1beta1_awx.yaml
|
||||||
# +kubebuilder:scaffold:manifestskustomizesamples
|
- awx_v1beta1_awxbackup.yaml
|
||||||
|
- awx_v1beta1_awxrestore.yaml
|
||||||
|
- awx_v1alpha1_awxmeshingress.yaml
|
||||||
|
#+kubebuilder:scaffold:manifestskustomizesamples
|
||||||
|
|||||||
@@ -1,8 +1,7 @@
|
|||||||
---
|
|
||||||
apiVersion: scorecard.operatorframework.io/v1alpha3
|
apiVersion: scorecard.operatorframework.io/v1alpha3
|
||||||
kind: Configuration
|
kind: Configuration
|
||||||
metadata:
|
metadata:
|
||||||
name: config
|
name: config
|
||||||
stages:
|
stages:
|
||||||
- parallel: true
|
- parallel: true
|
||||||
tests: []
|
tests: []
|
||||||
|
|||||||
@@ -1,17 +1,16 @@
|
|||||||
---
|
|
||||||
resources:
|
resources:
|
||||||
- bases/config.yaml
|
- bases/config.yaml
|
||||||
patchesJson6902:
|
patchesJson6902:
|
||||||
- path: patches/basic.config.yaml
|
- path: patches/basic.config.yaml
|
||||||
target:
|
target:
|
||||||
group: scorecard.operatorframework.io
|
group: scorecard.operatorframework.io
|
||||||
version: v1alpha3
|
version: v1alpha3
|
||||||
kind: Configuration
|
kind: Configuration
|
||||||
name: config
|
name: config
|
||||||
- path: patches/olm.config.yaml
|
- path: patches/olm.config.yaml
|
||||||
target:
|
target:
|
||||||
group: scorecard.operatorframework.io
|
group: scorecard.operatorframework.io
|
||||||
version: v1alpha3
|
version: v1alpha3
|
||||||
kind: Configuration
|
kind: Configuration
|
||||||
name: config
|
name: config
|
||||||
# +kubebuilder:scaffold:patchesJson6902
|
#+kubebuilder:scaffold:patchesJson6902
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
---
|
|
||||||
- op: add
|
- op: add
|
||||||
path: /stages/0/tests/-
|
path: /stages/0/tests/-
|
||||||
value:
|
value:
|
||||||
entrypoint:
|
entrypoint:
|
||||||
- scorecard-test
|
- scorecard-test
|
||||||
- basic-check-spec
|
- basic-check-spec
|
||||||
image: quay.io/operator-framework/scorecard-test:v1.12.0
|
image: quay.io/operator-framework/scorecard-test:v1.26.0
|
||||||
labels:
|
labels:
|
||||||
suite: basic
|
suite: basic
|
||||||
test: basic-check-spec-test
|
test: basic-check-spec-test
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
---
|
|
||||||
- op: add
|
- op: add
|
||||||
path: /stages/0/tests/-
|
path: /stages/0/tests/-
|
||||||
value:
|
value:
|
||||||
entrypoint:
|
entrypoint:
|
||||||
- scorecard-test
|
- scorecard-test
|
||||||
- olm-bundle-validation
|
- olm-bundle-validation
|
||||||
image: quay.io/operator-framework/scorecard-test:v1.12.0
|
image: quay.io/operator-framework/scorecard-test:v1.26.0
|
||||||
labels:
|
labels:
|
||||||
suite: olm
|
suite: olm
|
||||||
test: olm-bundle-validation-test
|
test: olm-bundle-validation-test
|
||||||
@@ -13,9 +12,9 @@
|
|||||||
path: /stages/0/tests/-
|
path: /stages/0/tests/-
|
||||||
value:
|
value:
|
||||||
entrypoint:
|
entrypoint:
|
||||||
- scorecard-test
|
- scorecard-test
|
||||||
- olm-crds-have-validation
|
- olm-crds-have-validation
|
||||||
image: quay.io/operator-framework/scorecard-test:v1.12.0
|
image: quay.io/operator-framework/scorecard-test:v1.26.0
|
||||||
labels:
|
labels:
|
||||||
suite: olm
|
suite: olm
|
||||||
test: olm-crds-have-validation-test
|
test: olm-crds-have-validation-test
|
||||||
@@ -23,9 +22,9 @@
|
|||||||
path: /stages/0/tests/-
|
path: /stages/0/tests/-
|
||||||
value:
|
value:
|
||||||
entrypoint:
|
entrypoint:
|
||||||
- scorecard-test
|
- scorecard-test
|
||||||
- olm-crds-have-resources
|
- olm-crds-have-resources
|
||||||
image: quay.io/operator-framework/scorecard-test:v1.12.0
|
image: quay.io/operator-framework/scorecard-test:v1.26.0
|
||||||
labels:
|
labels:
|
||||||
suite: olm
|
suite: olm
|
||||||
test: olm-crds-have-resources-test
|
test: olm-crds-have-resources-test
|
||||||
@@ -33,9 +32,9 @@
|
|||||||
path: /stages/0/tests/-
|
path: /stages/0/tests/-
|
||||||
value:
|
value:
|
||||||
entrypoint:
|
entrypoint:
|
||||||
- scorecard-test
|
- scorecard-test
|
||||||
- olm-spec-descriptors
|
- olm-spec-descriptors
|
||||||
image: quay.io/operator-framework/scorecard-test:v1.12.0
|
image: quay.io/operator-framework/scorecard-test:v1.26.0
|
||||||
labels:
|
labels:
|
||||||
suite: olm
|
suite: olm
|
||||||
test: olm-spec-descriptors-test
|
test: olm-spec-descriptors-test
|
||||||
@@ -43,9 +42,9 @@
|
|||||||
path: /stages/0/tests/-
|
path: /stages/0/tests/-
|
||||||
value:
|
value:
|
||||||
entrypoint:
|
entrypoint:
|
||||||
- scorecard-test
|
- scorecard-test
|
||||||
- olm-status-descriptors
|
- olm-status-descriptors
|
||||||
image: quay.io/operator-framework/scorecard-test:v1.12.0
|
image: quay.io/operator-framework/scorecard-test:v1.26.0
|
||||||
labels:
|
labels:
|
||||||
suite: olm
|
suite: olm
|
||||||
test: olm-status-descriptors-test
|
test: olm-status-descriptors-test
|
||||||
|
|||||||
@@ -1,13 +1,13 @@
|
|||||||
# Adds namespace to all resources.
|
# Adds namespace to all resources.
|
||||||
namespace: osdk-test
|
namespace: osdk-test
|
||||||
|
|
||||||
namePrefix: osdk-
|
namePrefix: osdk-
|
||||||
|
|
||||||
# Labels to add to all resources and selectors.
|
# Labels to add to all resources and selectors.
|
||||||
# commonLabels:
|
#commonLabels:
|
||||||
# someName: someValue
|
# someName: someValue
|
||||||
patchesStrategicMerge:
|
|
||||||
- manager_image.yaml
|
|
||||||
- debug_logs_patch.yaml
|
|
||||||
- ../default/manager_auth_proxy_patch.yaml
|
|
||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
@@ -18,4 +18,6 @@ images:
|
|||||||
- name: testing
|
- name: testing
|
||||||
newName: testing-operator
|
newName: testing-operator
|
||||||
patches:
|
patches:
|
||||||
- path: pull_policy/Never.yaml
|
- path: manager_image.yaml
|
||||||
|
- path: debug_logs_patch.yaml
|
||||||
|
- path: ../default/manager_auth_proxy_patch.yaml
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx
|
||||||
|
spec:
|
||||||
|
service_type: clusterip
|
||||||
|
ingress_type: route
|
||||||
|
no_log: false
|
||||||
|
|
||||||
|
# Secrets
|
||||||
|
admin_password_secret: custom-admin-password
|
||||||
|
postgres_configuration_secret: custom-pg-configuration
|
||||||
|
secret_key_secret: custom-secret-key
|
||||||
|
|
||||||
|
# Resource Requirements
|
||||||
|
postgres_storage_requirements:
|
||||||
|
requests:
|
||||||
|
storage: 10Gi
|
||||||
|
|
||||||
|
# Extra Settings
|
||||||
|
extra_settings:
|
||||||
|
- setting: MAX_PAGE_SIZE
|
||||||
|
value: "500"
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx
|
||||||
|
spec:
|
||||||
|
service_type: clusterip
|
||||||
|
ingress_type: Route
|
||||||
|
|
||||||
|
postgres_extra_settings:
|
||||||
|
- setting: max_connections
|
||||||
|
value: "999"
|
||||||
|
- setting: ssl_ciphers
|
||||||
|
value: "HIGH:!aNULL:!MD5"
|
||||||
|
|
||||||
|
# requires custom-postgres-configuration secret to be pre-created
|
||||||
|
# postgres_configuration_secret: custom-postgres-configuration
|
||||||
|
|
||||||
|
postgres_resource_requirements:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 256Mi
|
||||||
|
limits:
|
||||||
|
cpu: 800m
|
||||||
|
memory: 1Gi
|
||||||
|
postgres_storage_requirements:
|
||||||
|
requests:
|
||||||
|
storage: 20Gi
|
||||||
|
limits:
|
||||||
|
storage: 100Gi
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx
|
||||||
|
spec:
|
||||||
|
service_type: nodeport
|
||||||
|
ingress_type: ingress
|
||||||
|
|
||||||
|
# Secrets
|
||||||
|
admin_password_secret: custom-admin-password
|
||||||
|
postgres_configuration_secret: custom-pg-configuration
|
||||||
|
secret_key_secret: custom-secret-key
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx
|
||||||
|
spec:
|
||||||
|
service_type: clusterip
|
||||||
|
ingress_type: Route
|
||||||
|
|
||||||
|
# # Secrets
|
||||||
|
# admin_password_secret: custom-admin-password
|
||||||
|
# postgres_configuration_secret: custom-pg-configuration
|
||||||
|
# secret_key_secret: custom-secret-key
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: custom-admin-password
|
||||||
|
stringData:
|
||||||
|
password: 'password'
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: custom-secret-key
|
||||||
|
stringData:
|
||||||
|
secret_key: 'awxsecret'
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: external-pg-secret
|
||||||
|
stringData:
|
||||||
|
database: 'awx'
|
||||||
|
host: 'awx-postgres'
|
||||||
|
password: 'test'
|
||||||
|
port: '5432'
|
||||||
|
type: 'managed'
|
||||||
|
username: 'awx'
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
# Building the Ansible AWX Operator Docs
|
||||||
|
|
||||||
|
To build the AWX Operator docs locally:
|
||||||
|
|
||||||
|
1. Clone the AWX operator repository.
|
||||||
|
1. Preferrably, create a virtual environment for installing the dependencies.
|
||||||
|
a. `python3 -m venv venv`
|
||||||
|
b. `source venv/bin/activate`
|
||||||
|
1. From the root directory:
|
||||||
|
a. `pip install -r docs/requirements.txt`
|
||||||
|
b. `mkdocs build`
|
||||||
|
1. View the docs in your browser:
|
||||||
|
a. `mkdocs serve`
|
||||||
|
b. Open your browser and navigate to `http://127.0.0.1:8000/`
|
||||||
|
|
||||||
|
This will create a new directory called `site/` in the root of your clone containing the index.html and static files.
|
||||||
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 825 KiB |
@@ -0,0 +1,3 @@
|
|||||||
|
# Author
|
||||||
|
|
||||||
|
This operator was originally built in 2019 by [Jeff Geerling](https://www.jeffgeerling.com) and is now maintained by the Ansible Team
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# Code of Conduct
|
||||||
|
|
||||||
|
We ask all of our community members and contributors to adhere to the [Ansible code of conduct](http://docs.ansible.com/ansible/latest/community/code_of_conduct.html). If you have questions or need assistance, please reach out to our community team at [[email protected]](mailto:[email protected])
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
# Contributing
|
||||||
|
|
||||||
|
Please visit [our contributing guidelines](https://github.com/ansible/awx-operator/blob/devel/CONTRIBUTING.md).
|
||||||
|
|
||||||
|
For docs changes, create PRs on the appropriate files in the `/docs` folder.
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
# Get Involved
|
||||||
|
|
||||||
|
We welcome your feedback, questions and ideas. Here's how to reach the community.
|
||||||
|
|
||||||
|
## Forum
|
||||||
|
|
||||||
|
Join the [Ansible Forum](https://forum.ansible.com) as a single starting point and our default communication platform for questions and help, development discussions, events, and much more. [Register](https://forum.ansible.com/signup?) to join the community. Search by categories and tags to find interesting topics or start a new one; subscribe only to topics you need!
|
||||||
|
|
||||||
|
* [Get Help](https://forum.ansible.com/c/help/6): get help or help others. Please add appropriate tags if you start new discussions, for example `awx-operator` and `documentation`.
|
||||||
|
* [Posts tagged with 'awx-operator'](https://forum.ansible.com/tag/awx-operator): subscribe to participate in project-related conversations.
|
||||||
|
* [Bullhorn newsletter](https://docs.ansible.com/ansible/devel/community/communication.html#the-bullhorn) used to announce releases and important changes.
|
||||||
|
* [Social Spaces](https://forum.ansible.com/c/chat/4): gather and interact with fellow enthusiasts.
|
||||||
|
* [News & Announcements](https://forum.ansible.com/c/news/5): track project-wide announcements including social events.
|
||||||
|
|
||||||
|
For more information on the forum navigation, see [Navigating the Ansible forum](https://forum.ansible.com/t/navigating-the-ansible-forum-tags-categories-and-concepts/39) post.
|
||||||
|
|
||||||
|
## Matrix
|
||||||
|
|
||||||
|
For real-time interactions, conversations in the community happen over the Matrix protocol in the following channels:
|
||||||
|
|
||||||
|
* [#awx:ansible.com](https://matrix.to/#/#awx:ansible.com): AWX and AWX-Operator project-related discussions.
|
||||||
|
* [#docs:ansible.im](https://matrix.to/#/#docs:ansible.im): Ansible, AWX and AWX-Operator documentation-related discussions.
|
||||||
|
|
||||||
|
For more information, see the community-hosted [Matrix FAQ](https://hackmd.io/@ansible-community/community-matrix-faq).
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# Release Process
|
||||||
|
|
||||||
|
The first step is to create a draft release. Typically this will happen in the [Stage Release](https://github.com/ansible/awx/blob/devel/.github/workflows/stage.yml) workflow for AWX and you don't need to do it as a separate step.
|
||||||
|
|
||||||
|
If you need to do an independent release of the operator, you can run the [Stage Release](https://github.com/ansible/awx-operator/blob/devel/.github/workflows/stage.yml) in the awx-operator repo. Both of these workflows will run smoke tests, so there is no need to do this manually.
|
||||||
|
|
||||||
|
After the draft release is created, publish it and the [Promote AWX Operator image](https://github.com/ansible/awx-operator/blob/devel/.github/workflows/promote.yaml) will run, which will:
|
||||||
|
|
||||||
|
- Publish image to Quay
|
||||||
|
- Release Helm chart
|
||||||
|
|
||||||
|
After the GHA is complete, the final step is to run the [publish-to-operator-hub.sh](https://github.com/ansible/awx-operator/blob/devel/hack/publish-to-operator-hub.sh) script, which will create a PR in the following repos to add the new awx-operator bundle version to OperatorHub:
|
||||||
|
|
||||||
|
- <https://github.com/k8s-operatorhub/community-operators> (community operator index)
|
||||||
|
- <https://github.com/redhat-openshift-ecosystem/community-operators-prod> (operator index shipped with Openshift)
|
||||||
|
|
||||||
|
!!! note
|
||||||
|
The usage is documented in the script itself, but here is an example of how you would use the script to publish the 2.5.3 awx-opeator bundle to OperatorHub.
|
||||||
|
Note that you need to specify the version being released, as well as the previous version. This is because the bundle has a pointer to the previous version that is it being upgrade from. This is used by OLM to create a dependency graph.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
VERSION=2.5.3 PREV_VERSION=2.5.2 ./hack/publish-to-operator-hub.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
There are some quirks with running this on OS X that still need to be fixed, but the script runs smoothly on linux.
|
||||||
|
|
||||||
|
As soon as CI completes successfully, the PR's will be auto-merged. Please remember to monitor those PR's to make sure that CI passes, sometimes it needs a retry.
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
# Iterating on the installer without deploying the operator
|
|
||||||
|
|
||||||
Go through the [normal basic install](https://github.com/ansible/awx-operator/blob/devel/README.md#basic-install) steps.
|
|
||||||
|
|
||||||
Install some dependencies:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ ansible-galaxy collection install -r molecule/requirements.yml
|
|
||||||
$ pip install -r molecule/requirements.txt
|
|
||||||
```
|
|
||||||
|
|
||||||
To prevent the changes we're about to make from being overwritten, scale down any running instance of the operator:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ kubectl scale deployment awx-operator-controller-manager --replicas=0
|
|
||||||
```
|
|
||||||
|
|
||||||
Create a playbook that invokes the installer role (the operator uses ansible-runner's role execution feature):
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
# run.yml
|
|
||||||
---
|
|
||||||
- hosts: localhost
|
|
||||||
roles:
|
|
||||||
- installer
|
|
||||||
```
|
|
||||||
|
|
||||||
Create a vars file:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
# vars.yml
|
|
||||||
---
|
|
||||||
ansible_operator_meta:
|
|
||||||
name: awx
|
|
||||||
namespace: awx
|
|
||||||
service_type: nodeport
|
|
||||||
```
|
|
||||||
|
|
||||||
Run the installer:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ ansible-playbook run.yml -e @vars.yml -v
|
|
||||||
```
|
|
||||||
|
|
||||||
Grab the URL and admin password:
|
|
||||||
|
|
||||||
```
|
|
||||||
$ minikube service awx-service --url -n awx
|
|
||||||
$ minikube kubectl get secret awx-admin-password -- -o jsonpath="{.data.password}" | base64 --decode
|
|
||||||
LU6lTfvnkjUvDwL240kXKy1sNhjakZmT
|
|
||||||
```
|
|
||||||
@@ -0,0 +1,104 @@
|
|||||||
|
# Development Guide
|
||||||
|
|
||||||
|
There are development scripts and yaml exaples in the [`dev/`](../dev) directory that, along with the up.sh and down.sh scripts in the root of the repo, can be used to build, deploy and test changes made to the awx-operator.
|
||||||
|
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
You will need to have the following tools installed:
|
||||||
|
|
||||||
|
* [git](https://git-scm.com/book/en/v2/Getting-Started-Installing-Git)
|
||||||
|
* [podman](https://podman.io/docs/installation) or [docker](https://docs.docker.com/get-docker/)
|
||||||
|
* [kubectl](https://kubernetes.io/docs/tasks/tools/install-kubectl/)
|
||||||
|
* [oc](https://docs.openshift.com/container-platform/4.11/cli_reference/openshift_cli/getting-started-cli.html) (if using Openshift)
|
||||||
|
|
||||||
|
You will also need to have a container registry account. This guide uses quay.io, but any container registry will work. You will need to create a robot account and login at the CLI with `podman login` or `docker login`.
|
||||||
|
|
||||||
|
## Quay.io Setup for Development
|
||||||
|
|
||||||
|
Before using the development scripts, you'll need to set up a Quay.io repository and pull secret:
|
||||||
|
|
||||||
|
### 1. Create a Private Quay.io Repository
|
||||||
|
- Go to [quay.io](https://quay.io) and create a private repository named `awx-operator` under your username
|
||||||
|
- The repository URL should be `quay.io/username/awx-operator`
|
||||||
|
|
||||||
|
### 2. Create a Bot Account
|
||||||
|
- In your Quay.io repository, go to Settings → Robot Accounts
|
||||||
|
- Create a new robot account with write permissions to your repository
|
||||||
|
- Click on the robot account name to view its credentials
|
||||||
|
|
||||||
|
### 3. Generate Kubernetes Pull Secret
|
||||||
|
- In the robot account details, click "Kubernetes Secret"
|
||||||
|
- Copy the generated YAML content from the pop-up
|
||||||
|
|
||||||
|
### 4. Create Local Pull Secret File
|
||||||
|
- Create a file at `hacking/pull-secret.yml` in your awx-operator checkout
|
||||||
|
- Paste the Kubernetes secret YAML content into this file
|
||||||
|
- **Important**: Change the `name` field in the secret from the default to `redhat-operators-pull-secret`
|
||||||
|
- The `hacking/` directory is in `.gitignore`, so this file won't be committed to git
|
||||||
|
|
||||||
|
Example `hacking/pull-secret.yml`:
|
||||||
|
```yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: redhat-operators-pull-secret # Change this name
|
||||||
|
namespace: awx
|
||||||
|
type: kubernetes.io/dockerconfigjson
|
||||||
|
data:
|
||||||
|
.dockerconfigjson: <base64-encoded-credentials>
|
||||||
|
```
|
||||||
|
|
||||||
|
## Build and Deploy
|
||||||
|
|
||||||
|
|
||||||
|
If you clone the repo, and make sure you are logged in at the CLI with oc and your cluster, you can run:
|
||||||
|
|
||||||
|
```
|
||||||
|
export QUAY_USER=username
|
||||||
|
export NAMESPACE=awx
|
||||||
|
export TAG=test
|
||||||
|
./up.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
You can add those variables to your .bashrc file so that you can just run `./up.sh` in the future.
|
||||||
|
|
||||||
|
> Note: the first time you run this, it will create quay.io repos on your fork. If you followed the Quay.io setup steps above and created the `hacking/pull-secret.yml` file, the script will automatically handle the pull secret. Otherwise, you will need to either make those repos public, or create a global pull secret on your cluster.
|
||||||
|
|
||||||
|
To get the URL, if on **Openshift**, run:
|
||||||
|
|
||||||
|
```
|
||||||
|
$ oc get route
|
||||||
|
```
|
||||||
|
|
||||||
|
On **k8s with ingress**, run:
|
||||||
|
|
||||||
|
```
|
||||||
|
$ kubectl get ing
|
||||||
|
```
|
||||||
|
|
||||||
|
On **k8s with nodeport**, run:
|
||||||
|
|
||||||
|
```
|
||||||
|
$ kubectl get svc
|
||||||
|
```
|
||||||
|
|
||||||
|
The URL is then `http://<Node-IP>:<NodePort>`
|
||||||
|
|
||||||
|
> Note: NodePort will only work if you expose that port on your underlying k8s node, or are accessing it from localhost.
|
||||||
|
|
||||||
|
By default, the usename and password will be admin and password if using the `up.sh` script because it pre-creates a custom admin password k8s secret and specifies it on the AWX custom resource spec. Without that, a password would have been generated and stored in a k8s secret named <deployment-name>-admin-password.
|
||||||
|
|
||||||
|
## Clean up
|
||||||
|
|
||||||
|
|
||||||
|
Same thing for cleanup, just run ./down.sh and it will clean up your namespace on that cluster
|
||||||
|
|
||||||
|
|
||||||
|
```
|
||||||
|
./down.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
## Running CI tests locally
|
||||||
|
|
||||||
|
More tests coming soon...
|
||||||
Symlink
+1
@@ -0,0 +1 @@
|
|||||||
|
../README.md
|
||||||
@@ -0,0 +1,177 @@
|
|||||||
|
# Basic Install
|
||||||
|
|
||||||
|
After cloning this repository, you must choose the tag to run:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
git clone git@github.com:ansible/awx-operator.git
|
||||||
|
cd awx-operator
|
||||||
|
git tag
|
||||||
|
git checkout tags/<tag>
|
||||||
|
|
||||||
|
# For instance:
|
||||||
|
git checkout tags/2.7.2
|
||||||
|
```
|
||||||
|
|
||||||
|
If you work from a fork and made modifications since the tag was issued, you must provide the VERSION number to deploy. Otherwise the operator will get stuck in "ImagePullBackOff" state:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
export VERSION=<tag>
|
||||||
|
|
||||||
|
# For instance:
|
||||||
|
export VERSION=2.7.2
|
||||||
|
```
|
||||||
|
|
||||||
|
Once you have a running Kubernetes cluster, you can deploy AWX Operator into your cluster using [Kustomize](https://kubectl.docs.kubernetes.io/guides/introduction/kustomize/). Since kubectl version 1.14 kustomize functionality is built-in (otherwise, follow the instructions here to install the latest version of Kustomize: <https://kubectl.docs.kubernetes.io/installation/kustomize/>)
|
||||||
|
|
||||||
|
!!! tip
|
||||||
|
If you don't have a Kubernetes cluster, you can use [Minikube](https://minikube.sigs.k8s.io/docs/) for testing purposes. See the [Minikube install docs](./creating-a-minikube-cluster-for-testing.md) for more details.
|
||||||
|
|
||||||
|
!!! note
|
||||||
|
Some things may need to be configured slightly differently for different Kubernetes flavors for the networking aspects. When installing on Kind, see the [kind install docs](./kind-install.md) for more details.
|
||||||
|
|
||||||
|
There is a make target you can run:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
make deploy
|
||||||
|
```
|
||||||
|
|
||||||
|
If you have a custom operator image you have built, you can specify it with:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
IMG=quay.io/$YOURNAMESPACE/awx-operator:$YOURTAG make deploy
|
||||||
|
```
|
||||||
|
|
||||||
|
Otherwise, you can manually create a file called `kustomization.yaml` with the following content:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
# Find the latest tag here: https://github.com/ansible/awx-operator/releases
|
||||||
|
- github.com/ansible/awx-operator/config/default?ref=<tag>
|
||||||
|
|
||||||
|
# Set the image tags to match the git version from above
|
||||||
|
images:
|
||||||
|
- name: quay.io/ansible/awx-operator
|
||||||
|
newTag: <tag>
|
||||||
|
|
||||||
|
# Specify a custom namespace in which to install AWX
|
||||||
|
namespace: awx
|
||||||
|
```
|
||||||
|
|
||||||
|
!!! tip
|
||||||
|
If you need to change any of the default settings for the operator (such as resources.limits), you can add [patches](https://kubectl.docs.kubernetes.io/references/kustomize/kustomization/patches/) at the bottom of your kustomization.yaml file.
|
||||||
|
|
||||||
|
Install the manifests by running this:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
$ kubectl apply -k .
|
||||||
|
namespace/awx created
|
||||||
|
customresourcedefinition.apiextensions.k8s.io/awxbackups.awx.ansible.com created
|
||||||
|
customresourcedefinition.apiextensions.k8s.io/awxrestores.awx.ansible.com created
|
||||||
|
customresourcedefinition.apiextensions.k8s.io/awxs.awx.ansible.com created
|
||||||
|
serviceaccount/awx-operator-controller-manager created
|
||||||
|
role.rbac.authorization.k8s.io/awx-operator-awx-manager-role created
|
||||||
|
role.rbac.authorization.k8s.io/awx-operator-leader-election-role created
|
||||||
|
clusterrole.rbac.authorization.k8s.io/awx-operator-metrics-reader created
|
||||||
|
clusterrole.rbac.authorization.k8s.io/awx-operator-proxy-role created
|
||||||
|
rolebinding.rbac.authorization.k8s.io/awx-operator-awx-manager-rolebinding created
|
||||||
|
rolebinding.rbac.authorization.k8s.io/awx-operator-leader-election-rolebinding created
|
||||||
|
clusterrolebinding.rbac.authorization.k8s.io/awx-operator-proxy-rolebinding created
|
||||||
|
configmap/awx-operator-awx-manager-config created
|
||||||
|
service/awx-operator-controller-manager-metrics-service created
|
||||||
|
deployment.apps/awx-operator-controller-manager created
|
||||||
|
```
|
||||||
|
|
||||||
|
Wait a bit and you should have the `awx-operator` running:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
$ kubectl get pods -n awx
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
awx-operator-controller-manager-66ccd8f997-rhd4z 2/2 Running 0 11s
|
||||||
|
```
|
||||||
|
|
||||||
|
So we don't have to keep repeating `-n awx`, let's set the current namespace for `kubectl`:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
kubectl config set-context --current --namespace=awx
|
||||||
|
```
|
||||||
|
|
||||||
|
Next, create a file named `awx-demo.yml` in the same folder with the suggested content below. The `metadata.name` you provide will be the name of the resulting AWX deployment.
|
||||||
|
|
||||||
|
!!! note
|
||||||
|
If you deploy more than one AWX instance to the same namespace, be sure to use unique names.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx-demo
|
||||||
|
spec:
|
||||||
|
service_type: nodeport
|
||||||
|
```
|
||||||
|
|
||||||
|
!!! tip
|
||||||
|
It may make sense to create and specify your own secret key for your deployment so that if the k8s secret gets deleted, it can be re-created if needed. If it is not provided, one will be auto-generated, but cannot be recovered if lost. Read more [here](../user-guide/admin-user-account-configuration.md#secret-key-configuration).
|
||||||
|
|
||||||
|
If you are on Openshift, you can take advantage of Routes by specifying the following your spec. This will automatically create a Route for you with a custom hostname. This can be found on the Route section of the Openshift Console.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
---
|
||||||
|
apiVersion: awx.ansible.com/v1beta1
|
||||||
|
kind: AWX
|
||||||
|
metadata:
|
||||||
|
name: awx-demo
|
||||||
|
spec:
|
||||||
|
service_type: clusterip
|
||||||
|
ingress_type: Route
|
||||||
|
```
|
||||||
|
|
||||||
|
Make sure to add this new file to the list of `resources` in your `kustomization.yaml` file:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
...
|
||||||
|
resources:
|
||||||
|
- github.com/ansible/awx-operator/config/default?ref=<tag>
|
||||||
|
# Add this extra line:
|
||||||
|
- awx-demo.yml
|
||||||
|
...
|
||||||
|
```
|
||||||
|
|
||||||
|
Finally, apply the changes to create the AWX instance in your cluster:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
kubectl apply -k .
|
||||||
|
```
|
||||||
|
|
||||||
|
After a few seconds, you should see the operator begin to create new resources:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
$ kubectl get pods -l "app.kubernetes.io/managed-by=awx-operator"
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
awx-demo-77d96f88d5-pnhr8 4/4 Running 0 3m24s
|
||||||
|
awx-demo-postgres-0 1/1 Running 0 3m34s
|
||||||
|
|
||||||
|
$ kubectl get svc -l "app.kubernetes.io/managed-by=awx-operator"
|
||||||
|
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||||
|
awx-demo-postgres ClusterIP None <none> 5432/TCP 4m4s
|
||||||
|
awx-demo-service NodePort 10.109.40.38 <none> 80:31006/TCP 3m56s
|
||||||
|
```
|
||||||
|
|
||||||
|
After a few minutes, the new AWX instance will be deployed. You can look at the operator pod logs in order to know where the installation process is at:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
kubectl logs -f deployments/awx-operator-controller-manager -c awx-manager
|
||||||
|
```
|
||||||
|
|
||||||
|
Once deployed, your AWX instance should now be reachable at `http://localhost:<assigned-nodeport>/` (in this case, `http://localhost:31006/`).
|
||||||
|
|
||||||
|
By default, the admin user is `admin` and the password is available in the `<resourcename>-admin-password` secret. To retrieve the admin password, run:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
$ kubectl get secret awx-demo-admin-password -o jsonpath="{.data.password}" | base64 --decode ; echo
|
||||||
|
yDL2Cx5Za94g9MvBP6B73nzVLlmfgPjR
|
||||||
|
```
|
||||||
|
|
||||||
|
You just completed the most basic install of an AWX instance via this operator. Congratulations!!!
|
||||||
@@ -0,0 +1,61 @@
|
|||||||
|
# Creating a minikube cluster for testing
|
||||||
|
|
||||||
|
If you do not have an existing cluster, the `awx-operator` can be deployed on a [Minikube](https://minikube.sigs.k8s.io/docs/) cluster for testing purposes. Due to different OS and hardware environments, please refer to the official Minikube documentation for further information.
|
||||||
|
|
||||||
|
```sh
|
||||||
|
$ minikube start --cpus=4 --memory=6g --addons=ingress
|
||||||
|
😄 minikube v1.23.2 on Fedora 34
|
||||||
|
✨ Using the docker driver based on existing profile
|
||||||
|
👍 Starting control plane node minikube in cluster minikube
|
||||||
|
🚜 Pulling base image ...
|
||||||
|
🏃 Updating the running docker "minikube" container ...
|
||||||
|
🐳 Preparing Kubernetes v1.22.2 on Docker 20.10.8 ...
|
||||||
|
🔎 Verifying Kubernetes components...
|
||||||
|
▪ Using image gcr.io/k8s-minikube/storage-provisioner:v5
|
||||||
|
▪ Using image k8s.gcr.io/ingress-nginx/controller:v1.0.0-beta.3
|
||||||
|
▪ Using image k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v1.0
|
||||||
|
▪ Using image k8s.gcr.io/ingress-nginx/kube-webhook-certgen:v1.0
|
||||||
|
🔎 Verifying ingress addon...
|
||||||
|
🌟 Enabled addons: storage-provisioner, default-storageclass, ingress
|
||||||
|
🏄 Done! kubectl is now configured to use "minikube" cluster and "default" namespace by default
|
||||||
|
```
|
||||||
|
|
||||||
|
Once Minikube is deployed, check if the node(s) and `kube-apiserver` communication is working as expected.
|
||||||
|
|
||||||
|
```sh
|
||||||
|
$ minikube kubectl -- get nodes
|
||||||
|
NAME STATUS ROLES AGE VERSION
|
||||||
|
minikube Ready control-plane,master 113s v1.22.2
|
||||||
|
|
||||||
|
$ minikube kubectl -- get pods -A
|
||||||
|
NAMESPACE NAME READY STATUS RESTARTS AGE
|
||||||
|
ingress-nginx ingress-nginx-admission-create--1-kk67h 0/1 Completed 0 2m1s
|
||||||
|
ingress-nginx ingress-nginx-admission-patch--1-7mp2r 0/1 Completed 1 2m1s
|
||||||
|
ingress-nginx ingress-nginx-controller-69bdbc4d57-bmwg8 1/1 Running 0 2m
|
||||||
|
kube-system coredns-78fcd69978-q7nmx 1/1 Running 0 2m
|
||||||
|
kube-system etcd-minikube 1/1 Running 0 2m12s
|
||||||
|
kube-system kube-apiserver-minikube 1/1 Running 0 2m16s
|
||||||
|
kube-system kube-controller-manager-minikube 1/1 Running 0 2m12s
|
||||||
|
kube-system kube-proxy-5mmnw 1/1 Running 0 2m1s
|
||||||
|
kube-system kube-scheduler-minikube 1/1 Running 0 2m15s
|
||||||
|
kube-system storage-provisioner 1/1 Running 0 2m11s
|
||||||
|
```
|
||||||
|
|
||||||
|
It is not required for `kubectl` to be separately installed since it comes already wrapped inside minikube. As demonstrated above, simply prefix `minikube kubectl --` before kubectl command, i.e. `kubectl get nodes` would become `minikube kubectl -- get nodes`
|
||||||
|
|
||||||
|
Let's create an alias for easier usage:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
alias kubectl="minikube kubectl --"
|
||||||
|
```
|
||||||
|
|
||||||
|
Now, you can proceed with the installation of the AWX Operator and AWX. Please refer to the [Basic Install](basic-install.md) for further instructions.
|
||||||
|
|
||||||
|
!!! tip
|
||||||
|
Once your AWX has been deployed, the AWX instance will be accessible by running:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
minikube service -n awx awx-demo-service --url
|
||||||
|
```
|
||||||
|
|
||||||
|
For an example using the Nginx Ingress Controller in Minikube, don't miss our [demo video](https://asciinema.org/a/416946).
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user