1
0
Fork 0

Add helm package

This commit is contained in:
Joao Gilberto Magalhaes 2022-08-27 14:34:55 -05:00
parent e8aa05512a
commit 899e6e8d23
9 changed files with 415 additions and 54 deletions

View file

@ -1,21 +1,27 @@
--- ---
apiVersion: v1 # Source: easyhaproxy-ingress/templates/serviceaccount.yaml
kind: Namespace
metadata:
name: easyhaproxy
---
apiVersion: v1 apiVersion: v1
kind: ServiceAccount kind: ServiceAccount
metadata: metadata:
name: easyhaproxy-ingress name: manual-easyhaproxy-ingress
namespace: easyhaproxy labels:
helm.sh/chart: easyhaproxy-ingress-0.1.0
app.kubernetes.io/name: easyhaproxy-ingress
app.kubernetes.io/instance: manual
app.kubernetes.io/version: "test"
app.kubernetes.io/managed-by: Helm
--- ---
# Source: easyhaproxy-ingress/templates/clusterrole.yaml
kind: ClusterRole kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
metadata: metadata:
name: easyhaproxy-ingress name: manual-easyhaproxy-ingress
labels:
helm.sh/chart: easyhaproxy-ingress-0.1.0
app.kubernetes.io/name: easyhaproxy-ingress
app.kubernetes.io/instance: manual
app.kubernetes.io/version: "test"
app.kubernetes.io/managed-by: Helm
rules: rules:
- apiGroups: - apiGroups:
- "" - ""
@ -69,36 +75,47 @@ rules:
# - get # - get
# - list # - list
# - watch # - watch
--- ---
# Source: easyhaproxy-ingress/templates/clusterrolebinding.yaml
kind: ClusterRoleBinding kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
metadata: metadata:
name: easyhaproxy-ingress name: manual-easyhaproxy-ingress
namespace: easyhaproxy labels:
helm.sh/chart: easyhaproxy-ingress-0.1.0
app.kubernetes.io/name: easyhaproxy-ingress
app.kubernetes.io/instance: manual
app.kubernetes.io/version: "test"
app.kubernetes.io/managed-by: Helm
roleRef: roleRef:
apiGroup: rbac.authorization.k8s.io apiGroup: rbac.authorization.k8s.io
kind: ClusterRole kind: ClusterRole
name: easyhaproxy-ingress name: manual-easyhaproxy-ingress
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: easyhaproxy-ingress name: manual-easyhaproxy-ingress
namespace: easyhaproxy
--- ---
# Source: easyhaproxy-ingress/templates/deployment.yaml
apiVersion: apps/v1 apiVersion: apps/v1
kind: DaemonSet kind: DaemonSet
metadata: metadata:
name: easyhaproxy-ingress name: manual-easyhaproxy-ingress
namespace: easyhaproxy labels:
helm.sh/chart: easyhaproxy-ingress-0.1.0
app.kubernetes.io/name: easyhaproxy-ingress
app.kubernetes.io/instance: manual
app.kubernetes.io/version: "test"
app.kubernetes.io/managed-by: Helm
spec: spec:
selector: selector:
matchLabels: matchLabels:
app: easyhaproxy-ingress app.kubernetes.io/name: easyhaproxy-ingress
app.kubernetes.io/instance: manual
template: template:
metadata: metadata:
labels: labels:
app: easyhaproxy-ingress app.kubernetes.io/name: easyhaproxy-ingress
app.kubernetes.io/instance: manual
spec: spec:
affinity: affinity:
nodeAffinity: nodeAffinity:
@ -108,37 +125,44 @@ spec:
- key: easyhaproxy/node - key: easyhaproxy/node
operator: In operator: In
values: values:
- master - master
serviceAccountName: easyhaproxy-ingress serviceAccountName: manual-easyhaproxy-ingress
securityContext:
{}
containers: containers:
- image: byjg/easy-haproxy:test - name: easyhaproxy-ingress
imagePullPolicy: Always securityContext:
name: easyhaproxy-ingress {}
ports: image: "byjg/easy-haproxy:test"
- name: http imagePullPolicy: Always
containerPort: 80 ports:
hostPort: 80 - name: http
- name: https containerPort: 80
containerPort: 443 hostPort: 80
hostPort: 443 - name: https
- name: stats containerPort: 443
containerPort: 1936 hostPort: 443
hostPort: 1936 - name: stats
resources: containerPort: 1936
requests: hostPort: 1936
cpu: "100m" resources:
memory: "128Mi" {}
env:
env: - name: EASYHAPROXY_DISCOVER
- name: EASYHAPROXY_DISCOVER value: kubernetes
value: kubernetes - name: HAPROXY_USERNAME
- name: HAPROXY_USERNAME value: admin
value: admin - name: HAPROXY_PASSWORD
- name: HAPROXY_PASSWORD value: password
value: password - name: EASYHAPROXY_REFRESH_CONF
- name: EASYHAPROXY_REFRESH_CONF value: "10"
value: "10" - name: HAPROXY_CUSTOMERRORS
- name: HAPROXY_CUSTOMERRORS value: "true"
value: "true" - name: EASYHAPROXY_SSL_MODE
- name: EASYHAPROXY_SSL_MODE value: loose
value: loose - name: EASYHAPROXY_LOG_LEVEL
value: DEBUG
- name: HAPROXY_LOG_LEVEL
value: DEBUG
- name: CERTBOT_LOG_LEVEL
value: DEBUG

View file

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View file

@ -0,0 +1,24 @@
apiVersion: v2
name: easyhaproxy-ingress
description: "EasyHAProxy - A service discovery backed on HAProxy"
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "test"

View file

@ -0,0 +1,62 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "easyhaproxy-ingress.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "easyhaproxy-ingress.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "easyhaproxy-ingress.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels
*/}}
{{- define "easyhaproxy-ingress.labels" -}}
helm.sh/chart: {{ include "easyhaproxy-ingress.chart" . }}
{{ include "easyhaproxy-ingress.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/*
Selector labels
*/}}
{{- define "easyhaproxy-ingress.selectorLabels" -}}
app.kubernetes.io/name: {{ include "easyhaproxy-ingress.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}
{{/*
Create the name of the service account to use
*/}}
{{- define "easyhaproxy-ingress.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "easyhaproxy-ingress.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}

View file

@ -0,0 +1,66 @@
{{- if .Values.serviceAccount.create -}}
---
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: {{ include "easyhaproxy-ingress.fullname" . }}
labels:
{{- include "easyhaproxy-ingress.labels" . | nindent 4 }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
rules:
- apiGroups:
- ""
resources:
# - configmaps
# - endpoints
# - nodes
- pods
- services
- namespaces
# - events
- serviceaccounts
verbs:
- get
- list
- watch
- apiGroups:
- "extensions"
- "networking.k8s.io"
resources:
- ingresses
# - ingresses/status
# - ingressclasses
verbs:
- get
- list
- watch
# - apiGroups:
# - "extensions"
# - "networking.k8s.io"
# resources:
# - ingresses/status
# verbs:
# - update
- apiGroups:
- ""
resources:
- secrets
verbs:
- get
- list
# - watch
# - create
# - patch
# - update
# - apiGroups:
# - "discovery.k8s.io"
# resources:
# - endpointslices
# verbs:
# - get
# - list
# - watch
{{- end }}

View file

@ -0,0 +1,20 @@
{{- if .Values.serviceAccount.create -}}
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: {{ include "easyhaproxy-ingress.fullname" . }}
labels:
{{- include "easyhaproxy-ingress.labels" . | nindent 4 }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ include "easyhaproxy-ingress.fullname" . }}
subjects:
- kind: ServiceAccount
name: {{ include "easyhaproxy-ingress.serviceAccountName" . }}
{{- end }}

View file

@ -0,0 +1,65 @@
---
apiVersion: apps/v1
kind: DaemonSet
metadata:
name: {{ include "easyhaproxy-ingress.fullname" . }}
labels:
{{- include "easyhaproxy-ingress.labels" . | nindent 4 }}
spec:
selector:
matchLabels:
{{- include "easyhaproxy-ingress.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "easyhaproxy-ingress.selectorLabels" . | nindent 8 }}
spec:
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: {{ .Values.masterNode.label }}
operator: In
values:
{{- toYaml .Values.masterNode.values | nindent 18 }}
serviceAccountName: {{ include "easyhaproxy-ingress.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
containers:
- name: {{ .Chart.Name }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- name: http
containerPort: 80
hostPort: 80
- name: https
containerPort: 443
hostPort: 443
- name: stats
containerPort: 1936
hostPort: 1936
resources:
{{- toYaml .Values.resources | nindent 12 }}
env:
- name: EASYHAPROXY_DISCOVER
value: kubernetes
- name: HAPROXY_USERNAME
value: {{ .Values.easyhaproxy.stats.username }}
- name: HAPROXY_PASSWORD
value: {{ .Values.easyhaproxy.stats.password }}
- name: EASYHAPROXY_REFRESH_CONF
value: {{ .Values.easyhaproxy.refresh | quote }}
- name: HAPROXY_CUSTOMERRORS
value: {{ .Values.easyhaproxy.customErrors | quote}}
- name: EASYHAPROXY_SSL_MODE
value: {{ .Values.easyhaproxy.sslMode }}
- name: EASYHAPROXY_LOG_LEVEL
value: {{ .Values.easyhaproxy.logLevel.easyhaproxy }}
- name: HAPROXY_LOG_LEVEL
value: {{ .Values.easyhaproxy.logLevel.haproxy }}
- name: CERTBOT_LOG_LEVEL
value: {{ .Values.easyhaproxy.logLevel.certbot }}

View file

@ -0,0 +1,12 @@
{{- if .Values.serviceAccount.create -}}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "easyhaproxy-ingress.serviceAccountName" . }}
labels:
{{- include "easyhaproxy-ingress.labels" . | nindent 4 }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}

View file

@ -0,0 +1,65 @@
# Default values for easyhaproxy-ingress.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: byjg/easy-haproxy
pullPolicy: Always # IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: ""
imagePullSecrets: []
nameOverride: ""
fullnameOverride: ""
serviceAccount:
create: true
annotations: {}
name: ""
podAnnotations: {}
podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
resources: {}
# requests:
# cpu: "100m"
# memory: "128Mi"
# limits:
# cpu: 100m
# memory: 128Mi
nodeSelector: {}
tolerations: []
affinity: {}
easyhaproxy:
stats:
username: admin
password: password
refresh: "10"
customErrors: "true"
sslMode: loose
logLevel:
certbot: DEBUG
easyhaproxy: DEBUG
haproxy: DEBUG
# Make sure to create this
masterNode:
label: easyhaproxy/node
values:
- master