diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 00000000..816593c4 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,27 @@ +--- +name: Bug report +about: Create a report to help us improve +title: '' +labels: 'bug' +assignees: '' + +--- + +**Describe the bug** +A clear and concise description of what the bug is. + +**To Reproduce** +Steps to reproduce the behavior: +1. Go to '...' +2. Click on '....' +3. Scroll down to '....' +4. See error + +**Expected behavior** +A clear and concise description of what you expected to happen. + +**Screenshots** +If applicable, add screenshots to help explain your problem. + +**Additional context** +Add any other context about the problem here. diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 00000000..36014cde --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,20 @@ +--- +name: Feature request +about: Suggest an idea for this project +title: '' +labels: 'enhancement' +assignees: '' + +--- + +**Is your feature request related to a problem? Please describe.** +A clear and concise description of what the problem is. Ex. I'm always frustrated when [...] + +**Describe the solution you'd like** +A clear and concise description of what you want to happen. + +**Describe alternatives you've considered** +A clear and concise description of any alternative solutions or features you've considered. + +**Additional context** +Add any other context or screenshots about the feature request here. diff --git a/.github/no-response.yml b/.github/no-response.yml new file mode 100644 index 00000000..47e7fb6f --- /dev/null +++ b/.github/no-response.yml @@ -0,0 +1 @@ +# See https://github.com/probot/no-response diff --git a/.github/stale.yml b/.github/stale.yml new file mode 100644 index 00000000..b81bf109 --- /dev/null +++ b/.github/stale.yml @@ -0,0 +1 @@ +# See https://github.com/probot/stale diff --git a/.gitignore b/.gitignore index 9385855f..468b8f5a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,3 @@ output .vscode +.DS_Store \ No newline at end of file diff --git a/charts/argo-cd/.helmignore b/charts/argo-cd/.helmignore new file mode 100644 index 00000000..f0c13194 --- /dev/null +++ b/charts/argo-cd/.helmignore @@ -0,0 +1,21 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj diff --git a/charts/argo-cd/Chart.yaml b/charts/argo-cd/Chart.yaml new file mode 100644 index 00000000..a39c17f7 --- /dev/null +++ b/charts/argo-cd/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v1 +appVersion: "0.12.1" +description: A Helm chart for Argo-CD +name: argo-cd +version: 0.2.1 diff --git a/charts/argo-cd/templates/NOTES.txt b/charts/argo-cd/templates/NOTES.txt new file mode 100644 index 00000000..ecd1f64b --- /dev/null +++ b/charts/argo-cd/templates/NOTES.txt @@ -0,0 +1,13 @@ +In order to access the server UI you have the following options: + +1. kubectl port-forward svc/argocd-server -n argocd 8080:443 + + and then open the browser on http://localhost:8080 and accept the certificate + +2. enable ingress and check the first option ssl passthrough: + https://github.com/argoproj/argo-cd/blob/master/docs/ingress.md#option-1-ssl-passthrough + +After reaching the UI the first time you can login with username: admin and the password will be the +name of the server pod. You can get the pod name by running: + +kubectl get pods -n argocd -l app.kubernetes.io/name={{ include "argo-cd.name" . }}-server -o name | cut -d'/' -f 2 diff --git a/charts/argo-cd/templates/_helpers.tpl b/charts/argo-cd/templates/_helpers.tpl new file mode 100644 index 00000000..bd65c45c --- /dev/null +++ b/charts/argo-cd/templates/_helpers.tpl @@ -0,0 +1,32 @@ +{{/* vim: set filetype=mustache: */}} +{{/* +Expand the name of the chart. +*/}} +{{- define "argo-cd.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "argo-cd.fullname" -}} +{{- if .Values.fullnameOverride -}} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- $name := default .Chart.Name .Values.nameOverride -}} +{{- if contains $name .Release.Name -}} +{{- .Release.Name | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} +{{- end -}} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "argo-cd.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}} +{{- end -}} diff --git a/charts/argo-cd/templates/argocd-application-controller-clusterrole.yaml b/charts/argo-cd/templates/argocd-application-controller-clusterrole.yaml new file mode 100644 index 00000000..83a31835 --- /dev/null +++ b/charts/argo-cd/templates/argocd-application-controller-clusterrole.yaml @@ -0,0 +1,24 @@ +{{- if .Values.clusterAdminAccess.enabled }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: argocd-application-controller + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller +rules: +- apiGroups: + - '*' + resources: + - '*' + verbs: + - '*' +- nonResourceURLs: + - '*' + verbs: + - '*' +{{- end }} \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-application-controller-clusterrolebinding.yaml b/charts/argo-cd/templates/argocd-application-controller-clusterrolebinding.yaml new file mode 100644 index 00000000..114b6572 --- /dev/null +++ b/charts/argo-cd/templates/argocd-application-controller-clusterrolebinding.yaml @@ -0,0 +1,21 @@ +{{- if .Values.clusterAdminAccess.enabled }} +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: argocd-application-controller + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: argocd-application-controller +subjects: +- kind: ServiceAccount + name: argocd-application-controller + namespace: {{ .Release.Namespace }} +{{- end -}} \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-application-controller-deployment.yaml b/charts/argo-cd/templates/argocd-application-controller-deployment.yaml new file mode 100755 index 00000000..31dd0a0b --- /dev/null +++ b/charts/argo-cd/templates/argocd-application-controller-deployment.yaml @@ -0,0 +1,43 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: argocd-application-controller + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller +spec: + selector: + matchLabels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + template: + metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller + spec: + containers: + - command: + - argocd-application-controller + - --status-processors + - "20" + - --operation-processors + - "10" + image: {{ .Values.applicationController.image.repository }}:{{ .Values.applicationController.image.tag }} + imagePullPolicy: {{ .Values.applicationController.image.pullPolicy }} + name: argocd-application-controller + ports: + - containerPort: {{ .Values.applicationController.containerPort }} + readinessProbe: + tcpSocket: + port: {{ .Values.applicationController.containerPort }} + initialDelaySeconds: 5 + periodSeconds: 10 + serviceAccountName: argocd-application-controller diff --git a/charts/argo-cd/templates/argocd-application-controller-role.yaml b/charts/argo-cd/templates/argocd-application-controller-role.yaml new file mode 100755 index 00000000..e6418a4f --- /dev/null +++ b/charts/argo-cd/templates/argocd-application-controller-role.yaml @@ -0,0 +1,42 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: argocd-application-controller + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller +rules: +- apiGroups: + - "" + resources: + - secrets + - configmaps + verbs: + - get + - list + - watch +- apiGroups: + - argoproj.io + resources: + - applications + - appprojects + verbs: + - create + - get + - list + - watch + - update + - patch + - delete +- apiGroups: + - "" + resources: + - events + verbs: + - create + - list + diff --git a/charts/argo-cd/templates/argocd-application-controller-rolebinding.yaml b/charts/argo-cd/templates/argocd-application-controller-rolebinding.yaml new file mode 100755 index 00000000..530475ec --- /dev/null +++ b/charts/argo-cd/templates/argocd-application-controller-rolebinding.yaml @@ -0,0 +1,18 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: argocd-application-controller + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: argocd-application-controller +subjects: +- kind: ServiceAccount + name: argocd-application-controller diff --git a/charts/argo-cd/templates/argocd-application-controller-sa.yaml b/charts/argo-cd/templates/argocd-application-controller-sa.yaml new file mode 100755 index 00000000..bd1890b7 --- /dev/null +++ b/charts/argo-cd/templates/argocd-application-controller-sa.yaml @@ -0,0 +1,11 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: argocd-application-controller + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller diff --git a/charts/argo-cd/templates/argocd-application-controller-service.yaml b/charts/argo-cd/templates/argocd-application-controller-service.yaml new file mode 100755 index 00000000..76b8b701 --- /dev/null +++ b/charts/argo-cd/templates/argocd-application-controller-service.yaml @@ -0,0 +1,17 @@ +apiVersion: v1 +kind: Service +metadata: + name: argocd-application-controller + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: application-controller +spec: + ports: + - port: {{ .Values.applicationController.servicePort }} + targetPort: {{ .Values.applicationController.containerPort }} + selector: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-application-controller diff --git a/charts/argo-cd/templates/argocd-cm.yaml b/charts/argo-cd/templates/argocd-cm.yaml new file mode 100755 index 00000000..ab7f1961 --- /dev/null +++ b/charts/argo-cd/templates/argocd-cm.yaml @@ -0,0 +1,30 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: argocd-cm + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }} + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} +data: +{{- if .Values.config.helmRepositories }} + helm.repositories: | +{{ toYaml .Values.config.helmRepositories | indent 4 }} +{{- end }} +{{- if .Values.config.repositories }} + repositories: | +{{ toYaml .Values.config.repositories | indent 4 }} +{{- end }} +{{- if .Values.config.dexConfig }} + dex.config: | +{{ toYaml .Values.config.dexConfig | indent 4 }} +{{- end }} +{{- if .Values.config.url }} + url: {{ .Values.config.url }} +{{- end }} +{{- if .Values.config.oidcConfig }} + oidc.config: | +{{ toYaml .Values.config.oidcConfig | indent 4 }} +{{- end }} diff --git a/charts/argo-cd/templates/argocd-dex-server-deployment.yaml b/charts/argo-cd/templates/argocd-dex-server-deployment.yaml new file mode 100644 index 00000000..8d7bc1c1 --- /dev/null +++ b/charts/argo-cd/templates/argocd-dex-server-deployment.yaml @@ -0,0 +1,48 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: argocd-dex-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: dex-server +spec: + selector: + matchLabels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server + template: + metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: dex-server + spec: + serviceAccountName: argocd-dex-server + initContainers: + - name: copyutil + image: {{ .Values.dexServer.initImage.repository }}:{{ .Values.dexServer.initImage.tag }} + imagePullPolicy: {{ .Values.dexServer.initImage.pullPolicy }} + command: [cp, /usr/local/bin/argocd-util, /shared] + volumeMounts: + - mountPath: /shared + name: static-files + containers: + - name: dex + image: {{ .Values.dexServer.image.repository }}:{{ .Values.dexServer.image.tag }} + imagePullPolicy: {{ .Values.dexServer.image.pullPolicy }} + command: [/shared/argocd-util, rundex] + ports: + - containerPort: {{ .Values.dexServer.containerPortHttp }} + - containerPort: {{ .Values.dexServer.containerPortGrpc }} + volumeMounts: + - mountPath: /shared + name: static-files + volumes: + - emptyDir: {} + name: static-files \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-dex-server-role.yaml b/charts/argo-cd/templates/argocd-dex-server-role.yaml new file mode 100644 index 00000000..16076248 --- /dev/null +++ b/charts/argo-cd/templates/argocd-dex-server-role.yaml @@ -0,0 +1,21 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: argocd-dex-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: dex-server +rules: +- apiGroups: + - "" + resources: + - secrets + - configmaps + verbs: + - get + - list + - watch \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-dex-server-rolebinding.yaml b/charts/argo-cd/templates/argocd-dex-server-rolebinding.yaml new file mode 100644 index 00000000..1db56ffe --- /dev/null +++ b/charts/argo-cd/templates/argocd-dex-server-rolebinding.yaml @@ -0,0 +1,18 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: argocd-dex-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: dex-server +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: argocd-dex-server +subjects: +- kind: ServiceAccount + name: argocd-dex-server \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-dex-server-sa.yaml b/charts/argo-cd/templates/argocd-dex-server-sa.yaml new file mode 100644 index 00000000..9fa6a3bd --- /dev/null +++ b/charts/argo-cd/templates/argocd-dex-server-sa.yaml @@ -0,0 +1,11 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: argocd-dex-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: dex-server \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-dex-server-service.yaml b/charts/argo-cd/templates/argocd-dex-server-service.yaml new file mode 100644 index 00000000..87402f40 --- /dev/null +++ b/charts/argo-cd/templates/argocd-dex-server-service.yaml @@ -0,0 +1,23 @@ +apiVersion: v1 +kind: Service +metadata: + name: argocd-dex-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: dex-server +spec: + ports: + - name: http + protocol: TCP + port: {{ .Values.dexServer.servicePortHttp }} + targetPort: {{ .Values.dexServer.containerPortHttp }} + - name: grpc + protocol: TCP + port: {{ .Values.dexServer.servicePortGrpc }} + targetPort: {{ .Values.dexServer.containerPortGrpc }} + selector: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-dex-server \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-metrics-service.yaml b/charts/argo-cd/templates/argocd-metrics-service.yaml new file mode 100755 index 00000000..f3a7b4f2 --- /dev/null +++ b/charts/argo-cd/templates/argocd-metrics-service.yaml @@ -0,0 +1,20 @@ +apiVersion: v1 +kind: Service +metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-metrics + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: server + name: argocd-metrics +spec: + ports: + - name: http + protocol: TCP + port: {{ .Values.server.serviceMetricsPort }} + targetPort: {{ .Values.server.containerMetricsPort }} + selector: + app: {{ include "argo-cd.name" . }}-server + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server diff --git a/charts/argo-cd/templates/argocd-rbac-cm.yaml b/charts/argo-cd/templates/argocd-rbac-cm.yaml new file mode 100755 index 00000000..fb688d03 --- /dev/null +++ b/charts/argo-cd/templates/argocd-rbac-cm.yaml @@ -0,0 +1,18 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: argocd-rbac-cm + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }} + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} +data: +{{- if .Values.rbac.policyDefault }} + policy.default: {{ .Values.rbac.policyDefault }} +{{- end }} +{{- if .Values.rbac.policyCsv }} + policy.csv: +{{- toYaml .Values.rbac.policyCsv | indent 4 }} +{{- end }} diff --git a/charts/argo-cd/templates/argocd-redis-deployment.yaml b/charts/argo-cd/templates/argocd-redis-deployment.yaml new file mode 100755 index 00000000..383520fe --- /dev/null +++ b/charts/argo-cd/templates/argocd-redis-deployment.yaml @@ -0,0 +1,38 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: argocd-redis + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-redis + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: redis +spec: + selector: + matchLabels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-redis + template: + metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-redis + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: redis + spec: + automountServiceAccountToken: false + containers: + - name: redis + args: + - --save + - "" + - --appendonly + - "no" + image: {{ .Values.redis.image.repository }}:{{ .Values.redis.image.tag }} + imagePullPolicy: {{ .Values.redis.image.pullPolicy}} + ports: + - containerPort: {{ .Values.redis.containerPort }} + diff --git a/charts/argo-cd/templates/argocd-redis-service.yaml b/charts/argo-cd/templates/argocd-redis-service.yaml new file mode 100755 index 00000000..01883d75 --- /dev/null +++ b/charts/argo-cd/templates/argocd-redis-service.yaml @@ -0,0 +1,17 @@ +apiVersion: v1 +kind: Service +metadata: + name: argocd-redis + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-redis + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: redis +spec: + ports: + - port: {{ .Values.redis.servicePort }} + targetPort: {{ .Values.redis.servicePort }} + selector: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-redis diff --git a/charts/argo-cd/templates/argocd-repo-server-deployment.yaml b/charts/argo-cd/templates/argocd-repo-server-deployment.yaml new file mode 100755 index 00000000..66229263 --- /dev/null +++ b/charts/argo-cd/templates/argocd-repo-server-deployment.yaml @@ -0,0 +1,38 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: argocd-repo-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-repo-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: repo-server +spec: + selector: + matchLabels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-repo-server + template: + metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-repo-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: repo-server + spec: + automountServiceAccountToken: false + containers: + - name: argocd-repo-server + image: {{ .Values.repoServer.image.repository }}:{{ .Values.repoServer.image.tag }} + imagePullPolicy: {{ .Values.repoServer.image.pullPolicy}} + command: [argocd-repo-server] + ports: + - containerPort: {{ .Values.repoServer.containerPort }} + readinessProbe: + tcpSocket: + port: {{ .Values.repoServer.containerPort }} + initialDelaySeconds: 5 + periodSeconds: 10 diff --git a/charts/argo-cd/templates/argocd-repo-server-service.yaml b/charts/argo-cd/templates/argocd-repo-server-service.yaml new file mode 100755 index 00000000..68b80200 --- /dev/null +++ b/charts/argo-cd/templates/argocd-repo-server-service.yaml @@ -0,0 +1,17 @@ +apiVersion: v1 +kind: Service +metadata: + name: argocd-repo-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-repo-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: repo-server +spec: + ports: + - port: {{ .Values.repoServer.servicePort }} + targetPort: {{ .Values.repoServer.servicePort }} + selector: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-repo-server diff --git a/charts/argo-cd/templates/argocd-secret.yaml b/charts/argo-cd/templates/argocd-secret.yaml new file mode 100755 index 00000000..c693d079 --- /dev/null +++ b/charts/argo-cd/templates/argocd-secret.yaml @@ -0,0 +1,21 @@ +apiVersion: v1 +kind: Secret +metadata: + name: argocd-secret + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }} + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} +type: Opaque +data: +{{- if .Values.config.webhook.githubSecret }} + github.webhook.secret: {{ .Values.config.webhook.githubSecret }} +{{- end }} +{{- if .Values.config.webhook.gitlabSecret }} + gitlab.webhook.secret: {{ .Values.config.webhook.gitlabSecret }} +{{- end }} +{{- if .Values.config.webhook.bitbucketSecret }} + bitbucket.webhook.uuid: {{ .Values.config.webhook.bitbucketSecret }} +{{- end }} \ No newline at end of file diff --git a/charts/argo-cd/templates/argocd-server-deployment.yaml b/charts/argo-cd/templates/argocd-server-deployment.yaml new file mode 100755 index 00000000..928a3c15 --- /dev/null +++ b/charts/argo-cd/templates/argocd-server-deployment.yaml @@ -0,0 +1,59 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: argocd-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: server +spec: + selector: + matchLabels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + template: + metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: server + spec: + serviceAccountName: argocd-server + initContainers: + - name: ui + image: {{ .Values.server.uiInitImage.repository }}:{{ .Values.server.uiInitImage.tag }} + imagePullPolicy: {{ .Values.server.uiInitImage.pullPolicy }} + command: [cp, -r, /app, /shared] + volumeMounts: + - mountPath: /shared + name: static-files + containers: + - name: argocd-server + image: {{ .Values.server.image.repository }}:{{ .Values.server.image.tag }} + imagePullPolicy: {{ .Values.server.image.pullPolicy }} + command: + - argocd-server + - --staticassets + - /shared/app + {{- range .Values.server.extraArgs }} + - {{. | quote }} + {{- end }} + volumeMounts: + - mountPath: /shared + name: static-files + ports: + - containerPort: {{ .Values.server.containerPort }} + readinessProbe: + httpGet: + path: /healthz + port: {{ .Values.server.containerPort }} + initialDelaySeconds: 3 + periodSeconds: 30 + volumes: + - emptyDir: {} + name: static-files diff --git a/charts/argo-cd/templates/argocd-server-ingress.yaml b/charts/argo-cd/templates/argocd-server-ingress.yaml new file mode 100644 index 00000000..d8b11266 --- /dev/null +++ b/charts/argo-cd/templates/argocd-server-ingress.yaml @@ -0,0 +1,29 @@ +{{- if .Values.ingress.enabled -}} +{{- $ingressPath := .Values.ingress.path -}} +{{- $servicePortHttps := .Values.server.servicePortHttps -}} +apiVersion: extensions/v1beta1 +kind: Ingress +metadata: + name: argocd-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }} + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} +{{- with .Values.ingress.annotations }} + annotations: +{{ toYaml . | indent 4 }} +{{- end }} +spec: + rules: + {{- range .Values.ingress.hosts }} + - host: {{ . | quote }} + http: + paths: + - path: {{ $ingressPath }} + backend: + serviceName: argocd-server + servicePort: {{ $servicePortHttps }} + {{- end }} +{{- end }} diff --git a/charts/argo-cd/templates/argocd-server-role.yaml b/charts/argo-cd/templates/argocd-server-role.yaml new file mode 100755 index 00000000..832ca5c4 --- /dev/null +++ b/charts/argo-cd/templates/argocd-server-role.yaml @@ -0,0 +1,45 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: argocd-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: server +rules: +- apiGroups: + - "" + resources: + - secrets + - configmaps + verbs: + - create + - get + - list + - watch + - update + - patch + - delete +- apiGroups: + - argoproj.io + resources: + - applications + - appprojects + verbs: + - create + - get + - list + - watch + - update + - delete + - patch +- apiGroups: + - "" + resources: + - events + verbs: + - create + - list diff --git a/charts/argo-cd/templates/argocd-server-rolebinding.yaml b/charts/argo-cd/templates/argocd-server-rolebinding.yaml new file mode 100755 index 00000000..4c53b979 --- /dev/null +++ b/charts/argo-cd/templates/argocd-server-rolebinding.yaml @@ -0,0 +1,19 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: argocd-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: server + +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: argocd-server +subjects: +- kind: ServiceAccount + name: argocd-server diff --git a/charts/argo-cd/templates/argocd-server-sa.yaml b/charts/argo-cd/templates/argocd-server-sa.yaml new file mode 100755 index 00000000..d764c65f --- /dev/null +++ b/charts/argo-cd/templates/argocd-server-sa.yaml @@ -0,0 +1,11 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: argocd-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: server diff --git a/charts/argo-cd/templates/argocd-server-service.yaml b/charts/argo-cd/templates/argocd-server-service.yaml new file mode 100755 index 00000000..2f8decca --- /dev/null +++ b/charts/argo-cd/templates/argocd-server-service.yaml @@ -0,0 +1,26 @@ +apiVersion: v1 +kind: Service +metadata: + name: argocd-server + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + helm.sh/chart: {{ include "argo-cd.chart" . }} + app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + app.kubernetes.io/component: server + annotations: +{{ toYaml .Values.server.serviceAnnotations | indent 4}}{{- end }} +spec: + ports: + - name: http + protocol: TCP + port: {{ .Values.server.servicePortHttp }} + targetPort: {{ .Values.server.containerPort }} + - name: https + protocol: TCP + port: {{ .Values.server.servicePortHttps }} + targetPort: {{ .Values.server.containerPort }} + selector: + app.kubernetes.io/name: {{ include "argo-cd.name" . }}-server + diff --git a/charts/argo-cd/templates/crds/application-crd.yaml b/charts/argo-cd/templates/crds/application-crd.yaml new file mode 100644 index 00000000..5c2b8b60 --- /dev/null +++ b/charts/argo-cd/templates/crds/application-crd.yaml @@ -0,0 +1,23 @@ +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }} + helm.sh/chart: {{ include "argo-cd.chart" . }} +# Don't apply label due to https://github.com/argoproj/argo-cd/issues/1425 +# app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + name: applications.argoproj.io + annotations: + "helm.sh/hook": crd-install +spec: + group: argoproj.io + names: + kind: Application + plural: applications + shortNames: + - app + - apps + scope: Namespaced + version: v1alpha1 diff --git a/charts/argo-cd/templates/crds/appproject-crd.yaml b/charts/argo-cd/templates/crds/appproject-crd.yaml new file mode 100644 index 00000000..afd1a38e --- /dev/null +++ b/charts/argo-cd/templates/crds/appproject-crd.yaml @@ -0,0 +1,23 @@ +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + labels: + app.kubernetes.io/name: {{ include "argo-cd.name" . }} + helm.sh/chart: {{ include "argo-cd.chart" . }} +# Don't apply label due to https://github.com/argoproj/argo-cd/issues/1425 +# app.kubernetes.io/instance: {{ .Release.Name }} + app.kubernetes.io/managed-by: {{ .Release.Service }} + app.kubernetes.io/part-of: {{ include "argo-cd.name" . }} + name: appprojects.argoproj.io + annotations: + "helm.sh/hook": crd-install +spec: + group: argoproj.io + names: + kind: AppProject + plural: appprojects + shortNames: + - appproj + - appprojs + scope: Namespaced + version: v1alpha1 diff --git a/charts/argo-cd/values.yaml b/charts/argo-cd/values.yaml new file mode 100644 index 00000000..f3b40b19 --- /dev/null +++ b/charts/argo-cd/values.yaml @@ -0,0 +1,144 @@ +applicationController: + containerPort: 8082 + servicePort: 8082 + image: + repository: argoproj/argocd + tag: v0.12.1 + pullPolicy: Always + +server: + containerPort: 8080 + servicePortHttp: 80 + servicePortHttps: 443 + containerMetricsPort: 8082 + serviceMetricsPort: 8082 + serviceAnnotations: {} + image: + repository: argoproj/argocd + tag: v0.12.1 + pullPolicy: Always + uiInitImage: + repository: argoproj/argocd-ui + tag: v0.12.1 + pullPolicy: Always + extraArgs: [] + +repoServer: + containerPort: 8081 + servicePort: 8081 + image: + repository: argoproj/argocd + tag: v0.12.1 + pullPolicy: Always + +dexServer: + containerPortHttp: 5556 + containerPortGrpc: 5557 + servicePortHttp: 5556 + servicePortGrpc: 5557 + image: + repository: quay.io/dexidp/dex + tag: v2.12.0 + pullPolicy: Always + initImage: + repository: argoproj/argocd + tag: v0.12.1 + pullPolicy: Always + +# terminate tls at ArgoCD level +ingress: + enabled: false + annotations: {} + # kubernetes.io/ingress.class: nginx + # nginx.ingress.kubernetes.io/force-ssl-redirect: "true" + # nginx.ingress.kubernetes.io/ssl-passthrough: "true" + path: / + hosts: + - argocd.example.com + +# Standard Argo CD installation with cluster-admin access. +# Set this true if you plan to use Argo CD to deploy applications in the same cluster that +# Argo CD runs in (i.e. kubernetes.svc.default). +# Will still be able to deploy to external clusters with inputted credentials. + +clusterAdminAccess: + enabled: true + +config: + helmRepositories: + # - name: privateRepo + # url: http://chartmuseum.privatecloud.com + # usernameSecret: + # name: private-chartmuseum + # key: username + # passwordSecret: + # name: private-chartmuseum + # key: password + # - name: incubator + # url: https://kubernetes-charts-incubator.storage.googleapis.com/ + repositories: + # - url: git@gitlab.com:usersprivategroup/users-gitops-config.git + # sshPrivateKeySecret: + # key: privateKey + # name: argocd-dev-key + # - url: git@gitlab.com:accountingprivategroup/accounting-gitops-config.git + # sshPrivateKeySecret: + # key: privateKey + # name: argocd-dev-key + dexConfig: + # # Argo CD's externally facing base URL. Required for configuring SSO + # # url: https://argo-cd-demo.argoproj.io + # + # # A dex connector configuration. See documentation on how to configure SSO: + # # https://github.com/argoproj/argo-cd/blob/master/docs/sso.md#2-configure-argocd-for-sso + # connectors: + # # GitHub example + # - type: github + # id: github + # name: GitHub + # config: + # clientID: aabbccddeeff00112233 + # clientSecret: $dex.github.clientSecret + # orgs: + # - name: your-github-org + # teams: + url: # https://argocd.example.com/ + oidcConfig: + # name: Okta + # issuer: https://dev-123456.oktapreview.com + # clientID: aaaabbbbccccddddeee + # clientSecret: $oidc.okta.clientSecret + # The following keys hold the shared secret for authenticating GitHub/GitLab/BitBucket webhook + # events. To enable webhooks, configure one or more of the following keys with the shared git + # provider webhook secret. The payload URL configured in the git provider should use the + # /api/webhook endpoint of your Argo CD instance (e.g. https://argocd.example.com/api/webhook) + webhook: + githubSecret: + gitlabSecret: + bitbucketSecret: +rbac: +# # An RBAC policy .csv file containing additional policy and role definitions. +# # See https://github.com/argoproj/argo-cd/blob/master/docs/rbac.md on how to write RBAC policies. +# policy.csv: | +# # Give all members of "my-org:team-alpha" the ability to sync apps in "my-project" +# p, my-org:team-alpha, applications, sync, my-project/*, allow +# # Make all members of "my-org:team-beta" admins +# g, my-org:team-beta, role:admin + policyCsv: #| + # p, role:org-admin, applications, *, */*, allow + # p, role:org-admin, clusters, get, *, allow + # p, role:org-admin, repositories, get, *, allow + # p, role:org-admin, repositories, create, *, allow + # p, role:org-admin, repositories, update, *, allow + # p, role:org-admin, repositories, delete, *, allow + # g, your-github-org:your-team, role:org-admin + # The default role Argo CD will fall back to, when authorizing API requests + policyDefault: #role:readonly + +redis: + image: + repository: redis + tag: 5.0.3 + pullPolicy: Always + containerPort: 6379 + servicePort: 6379 diff --git a/charts/argo-events/Chart.yaml b/charts/argo-events/Chart.yaml index d32cb2be..f6469311 100644 --- a/charts/argo-events/Chart.yaml +++ b/charts/argo-events/Chart.yaml @@ -1,15 +1,14 @@ apiVersion: v1 description: A Helm chart to install Argo-Events in k8s Cluster name: argo-events -version: 0.2.0 +version: 0.4.0 keywords: - argo-events - sensor-controller +- gateway-controller sources: - https://github.com/argoproj/argo-events maintainers: -- name: Matt Magaldi - email: mmagaldi@blackrock.com - name: Vaibhav Page - email: vpage@blackrock.com -appVersion: 0.1.0 +- name: Matt Magaldi +appVersion: 0.8.1 diff --git a/charts/argo-events/README.md b/charts/argo-events/README.md index e08cf4ba..d09f9e8a 100644 --- a/charts/argo-events/README.md +++ b/charts/argo-events/README.md @@ -1,13 +1,11 @@ # Argo-Events Helm Chart This helm chart installs the [argo-events](https://github.com/argoproj/argo-events) application. This application comes packaged with: - Sensor Custom Resource Definition +- Gateway Custom Resource Definition - Sensor Controller Deployment - Sensor Controller ConfigMap -- Sensor Controller Service Account -- Sensor Controller Cluster Roles -- Sensor Controller Cluster Role Bindings - - -Note: the associated `argo-events` cluster role and cluster role bindings can be found in the [roles](https://blade-git.blackrock.com/cloud-native/roles) repository. The purpose that these aren't included in this Helm chart is that we do not have the required permissions to create these resources in the Kubernetes clusters. Reach out to `+Group Kubernetes Support` for help in setting up these roles. - -## Chart Values +- Gateway Controller Deployment +- Gateway Controller ConfigMap +- Service Account +- Cluster Roles +- Cluster Role Bindings diff --git a/charts/argo-events/templates/_helpers.tpl b/charts/argo-events/templates/_helpers.tpl index 55c1142c..f0d83d2e 100644 --- a/charts/argo-events/templates/_helpers.tpl +++ b/charts/argo-events/templates/_helpers.tpl @@ -14,24 +14,3 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this {{- $name := default .Chart.Name .Values.nameOverride -}} {{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} {{- end -}} - -{{- define "sensor-crd-json" }} -{ - "apiVersion": "apiextensions.k8s.io/v1beta1", - "kind": "CustomResourceDefinition", - "metadata": { - "name": "sensors.argoproj.io" - }, - "spec": { - "group": "argoproj.io", - "names": { - "kind": "Sensor", - "listKind": "SensorList", - "plural": "sensors", - "singular": "sensor" - }, - "scope": "Namespaced", - "version": "v1alpha1" - } -} -{{- end}} diff --git a/charts/argo-events/templates/_sensor-crd.tpl b/charts/argo-events/templates/_sensor-crd.tpl deleted file mode 100644 index 48fb2ab5..00000000 --- a/charts/argo-events/templates/_sensor-crd.tpl +++ /dev/null @@ -1,20 +0,0 @@ -{{- define "sensor-crd-json" }} -{ - "apiVersion": "apiextensions.k8s.io/{{ .Values.crd.version }}", - "kind": "CustomResourceDefinition", - "metadata": { - "name": "sensors.argoproj.io" - }, - "spec": { - "group": "argoproj.io", - "names": { - "kind": "Sensor", - "listKind": "SensorList", - "plural": "sensors", - "singular": "sensor" - }, - "scope": "Namespaced", - "version": "v1alpha1" - } -} -{{- end}} diff --git a/charts/argo-events/templates/apply-sensor-crd-job.yaml b/charts/argo-events/templates/apply-sensor-crd-job.yaml deleted file mode 100644 index 8360d0fd..00000000 --- a/charts/argo-events/templates/apply-sensor-crd-job.yaml +++ /dev/null @@ -1,19 +0,0 @@ -apiVersion: batch/v1 -kind: Job -metadata: - name: {{ .Release.Name }}-apply-sensor-crd - annotations: - helm.sh/hook: pre-install - helm.sh/hook-delete-policy: hook-succeeded -spec: - backoffLimit: 5 - activeDeadlineSeconds: 100 - template: - spec: - serviceAccountName: {{ .Values.crd.jobServiceAccount }} - containers: - - name: kubectl-apply - image: lachlanevenson/k8s-kubectl - command: ["/bin/sh"] - args: ["-c", 'echo ''{{- include "sensor-crd-json" .}}'' | kubectl apply -f -'] - restartPolicy: Never diff --git a/charts/argo-events/templates/argo-events-cluster-roles.yaml b/charts/argo-events/templates/argo-events-cluster-roles.yaml new file mode 100644 index 00000000..402076ab --- /dev/null +++ b/charts/argo-events/templates/argo-events-cluster-roles.yaml @@ -0,0 +1,94 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: argo-events-binding +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: argo-events-role +subjects: + - kind: ServiceAccount + name: argo-events-sa + namespace: {{ .Release.Namespace }} +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: argo-events-role +rules: + - apiGroups: + - apiextensions.k8s.io + - apiextensions.k8s.io/v1beta1 + verbs: + - create + - delete + - deletecollection + - get + - list + - patch + - update + - watch + resources: + - customresourcedefinitions + - apiGroups: + - argoproj.io + verbs: + - create + - delete + - deletecollection + - get + - list + - patch + - update + - watch + resources: + - workflows + - workflows/finalizers + - gateways + - gateways/finalizers + - sensors + - sensors/finalizers + - apiGroups: + - "" + resources: + - pods + - pods/exec + - configmaps + - secrets + - services + - events + - persistentvolumeclaims + verbs: + - create + - get + - list + - watch + - update + - patch + - delete + - apiGroups: + - "batch" + resources: + - jobs + verbs: + - create + - get + - list + - watch + - update + - patch + - delete + - apiGroups: + - "apps/v1" + - "apps/v1beta2" + - "apps/v1beta1" + resources: + - deployments + verbs: + - create + - get + - list + - watch + - update + - patch + - delete diff --git a/charts/argo-events/templates/argo-events-sa.yaml b/charts/argo-events/templates/argo-events-sa.yaml new file mode 100644 index 00000000..69525269 --- /dev/null +++ b/charts/argo-events/templates/argo-events-sa.yaml @@ -0,0 +1,7 @@ +# All argo-events services are bound to the "argo-events" service account. +# In RBAC enabled setups, this SA is bound to specific roles. +apiVersion: v1 +kind: ServiceAccount +metadata: + name: argo-events-sa + namespace: {{ .Release.Namespace }} diff --git a/charts/argo-events/templates/gateway-controller-configmap.yaml b/charts/argo-events/templates/gateway-controller-configmap.yaml new file mode 100644 index 00000000..5e01b9b8 --- /dev/null +++ b/charts/argo-events/templates/gateway-controller-configmap.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ .Release.Name }}-{{ .Values.gatewayController.name }}-configmap + labels: + chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} + release: {{ .Release.Name }} + heritage: {{ .Release.Service }} +data: + config: | + instanceID: {{ .Values.instanceID }} +{{- if .Values.singleNamespace }} + namespace: {{ .Values.namespace }} +{{- end }} diff --git a/charts/argo-events/templates/gateway-controller-deployment.yaml b/charts/argo-events/templates/gateway-controller-deployment.yaml new file mode 100644 index 00000000..7c699639 --- /dev/null +++ b/charts/argo-events/templates/gateway-controller-deployment.yaml @@ -0,0 +1,33 @@ +apiVersion: apps/v1beta1 +kind: Deployment +metadata: + name: {{ .Release.Name }}-{{ .Values.gatewayController.name }} + labels: + app: {{ .Release.Name }}-{{ .Values.gatewayController.name }} + chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} + release: {{ .Release.Name }} + heritage: {{ .Release.Service }} +spec: + replicas: {{ .Values.gatewayController.replicaCount }} + selector: + matchLabels: + app: {{ .Release.Name }}-{{ .Values.gatewayController.name }} + release: {{ .Release.Name }} + template: + metadata: + labels: + app: {{ .Release.Name }}-{{ .Values.gatewayController.name }} + release: {{ .Release.Name }} + spec: + serviceAccountName: {{ .Values.serviceAccount }} + containers: + - name: {{ .Values.gatewayController.name }} + image: "{{ .Values.registry }}/{{ .Values.gatewayController.image }}:{{ .Values.gatewayController.tag }}" + imagePullPolicy: {{ .Values.imagePullPolicy }} + env: + - name: GATEWAY_NAMESPACE + valueFrom: + fieldRef: + fieldPath: metadata.namespace + - name: GATEWAY_CONTROLLER_CONFIG_MAP + value: {{ .Release.Name }}-{{ .Values.gatewayController.name }}-configmap diff --git a/charts/argo-events/templates/gateway-crd.yaml b/charts/argo-events/templates/gateway-crd.yaml new file mode 100644 index 00000000..6cab34ba --- /dev/null +++ b/charts/argo-events/templates/gateway-crd.yaml @@ -0,0 +1,14 @@ +# Define a "gateway" custom resource definition +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + name: gateways.argoproj.io +spec: + group: argoproj.io + names: + kind: Gateway + listKind: GatewayList + plural: gateways + singular: gateway + scope: Namespaced + version: v1alpha1 diff --git a/charts/argo-events/templates/sensor-controller-clusterrole.yaml b/charts/argo-events/templates/sensor-controller-clusterrole.yaml deleted file mode 100644 index a1d53e8d..00000000 --- a/charts/argo-events/templates/sensor-controller-clusterrole.yaml +++ /dev/null @@ -1,15 +0,0 @@ -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: {{ .Release.name }}-{{ .Values.controller.name}}-cluster-role -rules: -- apiGroups: ["argoproj.io"] - resources: ["sensors"] - verbs: ["get", "list", "watch", "update", "patch"] -# The following rules define what the triggers can do -- apiGroups: ["argoproj.io"] - resources: ["workflows"] - verbs: ["create", "delete"] -- apiGroups: [""] - resources: ["configmaps", "secrets", "pods"] - verbs: ["get", "watch", "list", "patch"] diff --git a/charts/argo-events/templates/sensor-controller-configmap.yaml b/charts/argo-events/templates/sensor-controller-configmap.yaml index c3dc4661..17735823 100644 --- a/charts/argo-events/templates/sensor-controller-configmap.yaml +++ b/charts/argo-events/templates/sensor-controller-configmap.yaml @@ -1,16 +1,14 @@ apiVersion: v1 kind: ConfigMap metadata: - name: {{ .Release.Name }}-{{ .Values.controller.name }}-configmap + name: {{ .Release.Name }}-{{ .Values.sensorController.name }}-configmap labels: chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} release: {{ .Release.Name }} heritage: {{ .Release.Service }} data: config: | - namespace: {{ .Release.Namespace }} - {{- if .Values.useReleaseAsInstanceID }} - instanceID: {{ .Release.Name }} - {{- else }} instanceID: {{ .Values.instanceID }} - {{- end }} +{{- if .Values.singleNamespace }} + namespace: {{ .Values.namespace }} +{{- end }} diff --git a/charts/argo-events/templates/sensor-controller-crb.yaml b/charts/argo-events/templates/sensor-controller-crb.yaml deleted file mode 100644 index b7d54544..00000000 --- a/charts/argo-events/templates/sensor-controller-crb.yaml +++ /dev/null @@ -1,12 +0,0 @@ -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: {{ .Release.name }}-{{ .Values.controller.name}}-binding -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: {{ .Release.name }}-{{ .Values.controller.name}}-cluster-role -subjects: -- kind: ServiceAccount - name: {{ .Values.controller.serviceAccount }} - namespace: {{ .Release.Namespace }} diff --git a/charts/argo-events/templates/sensor-controller-deployment.yaml b/charts/argo-events/templates/sensor-controller-deployment.yaml index a53780f5..48ae0f56 100644 --- a/charts/argo-events/templates/sensor-controller-deployment.yaml +++ b/charts/argo-events/templates/sensor-controller-deployment.yaml @@ -1,28 +1,28 @@ apiVersion: apps/v1beta1 kind: Deployment metadata: - name: {{ .Release.Name }}-{{ .Values.controller.name }} + name: {{ .Release.Name }}-{{ .Values.sensorController.name }} labels: - app: {{ .Release.Name }}-{{ .Values.controller.name }} + app: {{ .Release.Name }}-{{ .Values.sensorController.name }} chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }} release: {{ .Release.Name }} heritage: {{ .Release.Service }} spec: - replicas: {{ .Values.controller.replicaCount }} + replicas: {{ .Values.sensorController.replicaCount }} selector: matchLabels: - app: {{ .Release.Name }}-{{ .Values.controller.name }} + app: {{ .Release.Name }}-{{ .Values.sensorController.name }} release: {{ .Release.Name }} template: metadata: labels: - app: {{ .Release.Name }}-{{ .Values.controller.name }} + app: {{ .Release.Name }}-{{ .Values.sensorController.name }} release: {{ .Release.Name }} spec: - serviceAccountName: {{ .Values.controller.serviceAccount }} + serviceAccountName: {{ .Values.serviceAccount }} containers: - - name: {{ .Values.controller.name }} - image: "{{ .Values.registry }}/{{ .Values.controller.image }}:{{ .Values.controller.tag }}" + - name: {{ .Values.sensorController.name }} + image: "{{ .Values.registry }}/{{ .Values.sensorController.image }}:{{ .Values.sensorController.tag }}" imagePullPolicy: {{ .Values.imagePullPolicy }} env: - name: SENSOR_NAMESPACE @@ -30,4 +30,4 @@ spec: fieldRef: fieldPath: metadata.namespace - name: SENSOR_CONFIG_MAP - value: {{ .Release.Name }}-{{ .Values.controller.name }}-configmap + value: {{ .Release.Name }}-{{ .Values.sensorController.name }}-configmap diff --git a/charts/argo-events/templates/sensor-controller-sa.yaml b/charts/argo-events/templates/sensor-controller-sa.yaml deleted file mode 100644 index af3ef519..00000000 --- a/charts/argo-events/templates/sensor-controller-sa.yaml +++ /dev/null @@ -1,4 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: {{ .Values.controller.serviceAccount }} diff --git a/charts/argo-events/templates/sensor-crd.yaml b/charts/argo-events/templates/sensor-crd.yaml new file mode 100644 index 00000000..5b50b240 --- /dev/null +++ b/charts/argo-events/templates/sensor-crd.yaml @@ -0,0 +1,14 @@ +# Define a "sensor" custom resource definition +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + name: sensors.argoproj.io +spec: + group: argoproj.io + names: + kind: Sensor + listKind: SensorList + plural: sensors + singular: sensor + scope: Namespaced + version: v1alpha1 diff --git a/charts/argo-events/templates/signals-clusterrole.yaml b/charts/argo-events/templates/signals-clusterrole.yaml deleted file mode 100644 index dfec0e27..00000000 --- a/charts/argo-events/templates/signals-clusterrole.yaml +++ /dev/null @@ -1,11 +0,0 @@ -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - name: {{ .Release.name }}-signals-cluster-role -rules: -- apiGroups: [""] - resources: ["pods"] - verbs: ["watch", "list", "patch"] -- apiGroups: {{ .Values.signals.listenRoles.apiGroups }} - resources: {{ .Values.signals.listenRoles.resources }} - verbs: ["get", "list", "watch"] \ No newline at end of file diff --git a/charts/argo-events/templates/signals-crb.yaml b/charts/argo-events/templates/signals-crb.yaml deleted file mode 100644 index 3a265e5b..00000000 --- a/charts/argo-events/templates/signals-crb.yaml +++ /dev/null @@ -1,12 +0,0 @@ -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - name: {{ .Release.name }}-signals-binding -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: {{ .Release.name }}-signals-cluster-role -subjects: -- kind: ServiceAccount - name: {{ .Values.signals.serviceAccount }} - namespace: {{ .Release.Namespace }} diff --git a/charts/argo-events/templates/signals-sa.yaml b/charts/argo-events/templates/signals-sa.yaml deleted file mode 100644 index 9baaa73b..00000000 --- a/charts/argo-events/templates/signals-sa.yaml +++ /dev/null @@ -1,4 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: {{ .Values.signals.serviceAccount }} diff --git a/charts/argo-events/values.yaml b/charts/argo-events/values.yaml index c68ca7cc..107c9b1a 100644 --- a/charts/argo-events/values.yaml +++ b/charts/argo-events/values.yaml @@ -1,27 +1,31 @@ +# docker registry registry: argoproj + +# The image pull policy imagePullPolicy: Always -# Version of the Sensor CRD -crd: - version: v1beta1 - jobServiceAccount: default +# ServiceAccount to use for running controller. +serviceAccount: argo-events-sa -# If set to true then chart set controller instance id to release name -useReleaseAsInstanceID: true -instanceID: 1 +instanceID: argo-events -# controller -controller: + + +# set `singleNamespace` to false to have the controllers +# listen on all namespaces. Otherwise the controllers will listen +# on the namespace provided +namespace: argo-events +singleNamespace: true + +# sensor controller +sensorController: name: sensor-controller image: sensor-controller - tag: latest + tag: v0.8.1 replicaCount: 1 - serviceAccount: argo-events -# signal microservices -signals: - serviceAccount: argo-signals - # this controls what the resource signal pod can listen to - listenRoles: - apiGroups: ["argoproj.io", ""] - resources: ["sensors", "workflows", "pods"] +gatewayController: + name: gateway-controller + image: gateway-controller + tag: v0.8.1 + replicaCount: 1 diff --git a/charts/argo/templates/ui-service.yaml b/charts/argo/templates/ui-service.yaml index 78d3fb12..3a63613d 100644 --- a/charts/argo/templates/ui-service.yaml +++ b/charts/argo/templates/ui-service.yaml @@ -19,4 +19,7 @@ spec: app: {{ .Release.Name }}-{{ .Values.ui.name }} sessionAffinity: None type: {{ .Values.ui.serviceType }} + {{- if and (eq .Values.ui.serviceType "LoadBalancer") .Values.ui.loadBalancerSourceRanges }} + loadBalancerSourceRanges: +{{ toYaml .Values.ui.loadBalancerSourceRanges | indent 4 }}{{- end }} {{- end -}} diff --git a/charts/argo/templates/workflow-controller-config-map.yaml b/charts/argo/templates/workflow-controller-config-map.yaml index 4c97cfc6..f77637a0 100644 --- a/charts/argo/templates/workflow-controller-config-map.yaml +++ b/charts/argo/templates/workflow-controller-config-map.yaml @@ -30,3 +30,6 @@ data: endpoint: {{ .Values.artifactRepository.s3.endpoint | default (printf "%s-%s" .Release.Name "minio:9000") }} insecure: {{ .Values.artifactRepository.s3.insecure }} {{- end}} + {{- if .Values.controller.metricsConfig.enabled }} + metricsConfig: +{{ toYaml .Values.controller.metricsConfig | indent 6}}{{- end }} diff --git a/charts/argo/templates/workflow-crd.yaml b/charts/argo/templates/workflow-crd.yaml index f65e5d14..64a77d7f 100644 --- a/charts/argo/templates/workflow-crd.yaml +++ b/charts/argo/templates/workflow-crd.yaml @@ -4,6 +4,7 @@ metadata: name: workflows.argoproj.io annotations: helm.sh/hook: crd-install + helm.sh/hook-delete-policy: before-hook-creation spec: group: argoproj.io version: v1alpha1 diff --git a/charts/argo/values.yaml b/charts/argo/values.yaml index c5374b37..09faee2f 100644 --- a/charts/argo/values.yaml +++ b/charts/argo/values.yaml @@ -15,6 +15,10 @@ init: controller: # podAnnotations is an optional map of annotations to be applied to the controller Pods podAnnotations: {} + metricsConfig: + enabled: false + path: /metrics + port: 8080 serviceAccount: argo name: workflow-controller workflowNamespaces: @@ -41,7 +45,10 @@ ui: serviceAccount: argo-ui # Annotations to be applied to the UI Service serviceAnnotations: {} - + # Source ranges to allow access to service from. Only applies to + # service type `LoadBalancer` + loadBalancerSourceRanges: [] + ## Ingress configuration. ## ref: https://kubernetes.io/docs/user-guide/ingress/ ##