From c31c6745c4dc92f96f3a676e26f25a0328339824 Mon Sep 17 00:00:00 2001 From: David Anderson Date: Thu, 26 Jan 2023 10:38:24 -0800 Subject: [PATCH] WIP helm chart Signed-off-by: David Anderson --- cmd/k8s-operator/chart/.helmignore | 23 ++++ cmd/k8s-operator/chart/Chart.yaml | 24 ++++ cmd/k8s-operator/chart/templates/NOTES.txt | 22 +++ cmd/k8s-operator/chart/templates/_helpers.tpl | 62 +++++++++ .../chart/templates/deployment.yaml | 54 ++++++++ .../chart/templates/namespace.yaml | 4 + cmd/k8s-operator/chart/templates/rbac.yaml | 126 ++++++++++++++++++ cmd/k8s-operator/chart/templates/secret.yaml | 8 ++ .../chart/templates/serviceaccount.yaml | 15 +++ .../templates/tests/test-connection.yaml | 15 +++ cmd/k8s-operator/chart/values.yaml | 38 ++++++ 11 files changed, 391 insertions(+) create mode 100644 cmd/k8s-operator/chart/.helmignore create mode 100644 cmd/k8s-operator/chart/Chart.yaml create mode 100644 cmd/k8s-operator/chart/templates/NOTES.txt create mode 100644 cmd/k8s-operator/chart/templates/_helpers.tpl create mode 100644 cmd/k8s-operator/chart/templates/deployment.yaml create mode 100644 cmd/k8s-operator/chart/templates/namespace.yaml create mode 100644 cmd/k8s-operator/chart/templates/rbac.yaml create mode 100644 cmd/k8s-operator/chart/templates/secret.yaml create mode 100644 cmd/k8s-operator/chart/templates/serviceaccount.yaml create mode 100644 cmd/k8s-operator/chart/templates/tests/test-connection.yaml create mode 100644 cmd/k8s-operator/chart/values.yaml diff --git a/cmd/k8s-operator/chart/.helmignore b/cmd/k8s-operator/chart/.helmignore new file mode 100644 index 000000000..0e8a0eb36 --- /dev/null +++ b/cmd/k8s-operator/chart/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/cmd/k8s-operator/chart/Chart.yaml b/cmd/k8s-operator/chart/Chart.yaml new file mode 100644 index 000000000..df2d97f9b --- /dev/null +++ b/cmd/k8s-operator/chart/Chart.yaml @@ -0,0 +1,24 @@ +apiVersion: v2 +name: chart +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "1.16.0" diff --git a/cmd/k8s-operator/chart/templates/NOTES.txt b/cmd/k8s-operator/chart/templates/NOTES.txt new file mode 100644 index 000000000..319f01bda --- /dev/null +++ b/cmd/k8s-operator/chart/templates/NOTES.txt @@ -0,0 +1,22 @@ +1. Get the application URL by running these commands: +{{- if .Values.ingress.enabled }} +{{- range $host := .Values.ingress.hosts }} + {{- range .paths }} + http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} + {{- end }} +{{- end }} +{{- else if contains "NodePort" .Values.service.type }} + export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "chart.fullname" . }}) + export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") + echo http://$NODE_IP:$NODE_PORT +{{- else if contains "LoadBalancer" .Values.service.type }} + NOTE: It may take a few minutes for the LoadBalancer IP to be available. + You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "chart.fullname" . }}' + export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "chart.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") + echo http://$SERVICE_IP:{{ .Values.service.port }} +{{- else if contains "ClusterIP" .Values.service.type }} + export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "chart.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}") + export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}") + echo "Visit http://127.0.0.1:8080 to use your application" + kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT +{{- end }} diff --git a/cmd/k8s-operator/chart/templates/_helpers.tpl b/cmd/k8s-operator/chart/templates/_helpers.tpl new file mode 100644 index 000000000..7ba5edc27 --- /dev/null +++ b/cmd/k8s-operator/chart/templates/_helpers.tpl @@ -0,0 +1,62 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "chart.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "chart.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "chart.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "chart.labels" -}} +helm.sh/chart: {{ include "chart.chart" . }} +{{ include "chart.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "chart.selectorLabels" -}} +app.kubernetes.io/name: {{ include "chart.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "chart.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "chart.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/cmd/k8s-operator/chart/templates/deployment.yaml b/cmd/k8s-operator/chart/templates/deployment.yaml new file mode 100644 index 000000000..90412ab4b --- /dev/null +++ b/cmd/k8s-operator/chart/templates/deployment.yaml @@ -0,0 +1,54 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ include "chart.fullname" . }} + namespace: {{ .Values.namespace }} + labels: + {{- include "chart.labels" . | nindent 4 }} +spec: + replicas: 1 # Do not attempt to increase. It will not do what you want. + strategy: + type: Recreate + selector: + matchLabels: + {{- include "chart.selectorLabels" . | nindent 6 }} + template: + metadata: + {{- with .Values.podAnnotations }} + annotations: + {{- toYaml . | nindent 8 }} + {{- end }} + labels: + {{- include "chart.selectorLabels" . | nindent 8 }} + spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} + serviceAccountName: {{ include "chart.serviceAccountName" . }} + securityContext: + {{- toYaml .Values.podSecurityContext | nindent 8 }} + volumes: + - name: oauth + secret: + secretName: operator-oauth + containers: + - name: {{ .Chart.Name }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + resources: + {{- toYaml .Values.resources | nindent 12 }} + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} diff --git a/cmd/k8s-operator/chart/templates/namespace.yaml b/cmd/k8s-operator/chart/templates/namespace.yaml new file mode 100644 index 000000000..77db5f9f6 --- /dev/null +++ b/cmd/k8s-operator/chart/templates/namespace.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: {{ .Values.namespace }} diff --git a/cmd/k8s-operator/chart/templates/rbac.yaml b/cmd/k8s-operator/chart/templates/rbac.yaml new file mode 100644 index 000000000..5447f943f --- /dev/null +++ b/cmd/k8s-operator/chart/templates/rbac.yaml @@ -0,0 +1,126 @@ + +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: proxies + namespace: {{ .Values.namespace }} +rules: +- apiGroups: [""] + resources: ["secrets"] + verbs: ["*"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: proxies + namespace: {{ .Values.namespace }} +subjects: +- kind: ServiceAccount + name: proxies + namespace: {{ .Values.namespace }} +roleRef: + kind: Role + name: proxies + apiGroup: rbac.authorization.k8s.io +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: {{ include "chart.fullname" . }}-operator +rules: +- apiGroups: [""] + resources: ["services", "services/status"] + verbs: ["*"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: {{ include "chart.fullname" . }}-operator +subjects: +- kind: ServiceAccount + name: operator + namespace: {{ .Values.namespace }} +roleRef: + kind: ClusterRole + name: {{ include "chart.fullname" . }}-operator + apiGroup: rbac.authorization.k8s.io +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: operator + namespace: {{ .Values.namespace }} +rules: +- apiGroups: [""] + resources: ["secrets"] + verbs: ["*"] +- apiGroups: ["apps"] + resources: ["statefulsets"] + verbs: ["*"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: {{ include "chart.fullname" . }}-operator + namespace: {{ .Values.namespace }} +subjects: +- kind: ServiceAccount + name: {{ include "chart.fullname" . }}-operator + namespace: {{ .Values.namespace }} +roleRef: + kind: Role + name: {{ include "chart.fullname" . }}-operator + apiGroup: rbac.authorization.k8s.io +--- +apiVersion: apps/v1 +kind: Deployment +metadata: + name: operator + namespace: tailscale +spec: + replicas: 1 + strategy: + type: Recreate + selector: + matchLabels: + app: operator + template: + metadata: + labels: + app: operator + spec: + serviceAccountName: operator + volumes: + - name: oauth + secret: + secretName: operator-oauth + containers: + - name: operator + image: tailscale/k8s-operator:latest + resources: + requests: + cpu: 500m + memory: 100Mi + env: + - name: OPERATOR_HOSTNAME + value: tailscale-operator + - name: OPERATOR_SECRET + value: operator + - name: OPERATOR_LOGGING + value: info + - name: OPERATOR_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: CLIENT_ID_FILE + value: /oauth/client_id + - name: CLIENT_SECRET_FILE + value: /oauth/client_secret + - name: PROXY_IMAGE + value: tailscale/tailscale:latest + - name: PROXY_TAGS + value: tag:k8s + volumeMounts: + - name: oauth + mountPath: /oauth + readOnly: true diff --git a/cmd/k8s-operator/chart/templates/secret.yaml b/cmd/k8s-operator/chart/templates/secret.yaml new file mode 100644 index 000000000..8882bc6a7 --- /dev/null +++ b/cmd/k8s-operator/chart/templates/secret.yaml @@ -0,0 +1,8 @@ +apiVersion: v1 +kind: Secret +metadata: + name: operator-oauth + namespace: {{ .Values.namespace }} +stringData: + client_id: # SET CLIENT ID HERE + client_secret: # SET CLIENT SECRET HERE diff --git a/cmd/k8s-operator/chart/templates/serviceaccount.yaml b/cmd/k8s-operator/chart/templates/serviceaccount.yaml new file mode 100644 index 000000000..b08305316 --- /dev/null +++ b/cmd/k8s-operator/chart/templates/serviceaccount.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: proxies + namespace: {{ .Values.namespace }} + labels: + {{- include "chart.labels" . | nindent 4 }} +-- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: operator + namespace: {{ .Values.namespace }} + labels: + {{- include "chart.labels" . | nindent 4 }} diff --git a/cmd/k8s-operator/chart/templates/tests/test-connection.yaml b/cmd/k8s-operator/chart/templates/tests/test-connection.yaml new file mode 100644 index 000000000..8dfed872d --- /dev/null +++ b/cmd/k8s-operator/chart/templates/tests/test-connection.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Pod +metadata: + name: "{{ include "chart.fullname" . }}-test-connection" + labels: + {{- include "chart.labels" . | nindent 4 }} + annotations: + "helm.sh/hook": test +spec: + containers: + - name: wget + image: busybox + command: ['wget'] + args: ['{{ include "chart.fullname" . }}:{{ .Values.service.port }}'] + restartPolicy: Never diff --git a/cmd/k8s-operator/chart/values.yaml b/cmd/k8s-operator/chart/values.yaml new file mode 100644 index 000000000..8eae60336 --- /dev/null +++ b/cmd/k8s-operator/chart/values.yaml @@ -0,0 +1,38 @@ +# Default values for chart. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. + +image: + repository: tailscale/k8s-operator + pullPolicy: IfNotPresent + tag: "v1.36.0" + +imagePullSecrets: [] +nameOverride: "" +fullnameOverride: "" + +namespace: "tailscale" + +tailscaleCredential: + clientID: "" # YOUR CLIENT ID MUST GO HERE + clientSecret: "" # YOUR CLIENT SECRET MUST GO HERE + +podAnnotations: {} + +podSecurityContext: {} + +securityContext: {} + +resources: + requests: + cpu: 500m + memory: 100Mi + # limits: + # cpu: 100m + # memory: 128Mi + +nodeSelector: {} + +tolerations: [] + +affinity: {}