diff --git a/charts/kubernetes-operator/Chart.yaml b/charts/kubernetes-operator/Chart.yaml index fc0085e..8facf76 100644 --- a/charts/kubernetes-operator/Chart.yaml +++ b/charts/kubernetes-operator/Chart.yaml @@ -2,5 +2,5 @@ apiVersion: v2 name: kubernetes-operator description: NetBird Kubernetes Operator type: application -version: 0.3.0-rc.2 -appVersion: "0.3.0-rc.2" +version: "0.3.1" +appVersion: "0.3.1" diff --git a/charts/kubernetes-operator/crds/netbird.io_groups.yaml b/charts/kubernetes-operator/crds/netbird.io_groups.yaml new file mode 100644 index 0000000..95bb602 --- /dev/null +++ b/charts/kubernetes-operator/crds/netbird.io_groups.yaml @@ -0,0 +1,135 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.20.1 + name: groups.netbird.io +spec: + group: netbird.io + names: + kind: Group + listKind: GroupList + plural: groups + singular: group + scope: Namespaced + versions: + - additionalPrinterColumns: + - jsonPath: .status.conditions[?(@.type=="Ready")].status + name: Ready + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1alpha1 + schema: + openAPIV3Schema: + description: Group is the Schema for the groups API. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: GroupSpec defines the desired state of Group. + properties: + name: + description: Name of the group. + minLength: 1 + type: string + required: + - name + type: object + status: + default: + observedGeneration: -1 + description: GroupStatus defines the observed state of Group. + properties: + conditions: + description: Conditions holds the conditions for the Group. + items: + description: Condition contains details for one aspect of the current + state of this API Resource. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + description: |- + message is a human readable message indicating details about the transition. + This may be an empty string. + maxLength: 32768 + type: string + observedGeneration: + description: |- + observedGeneration represents the .metadata.generation that the condition was set based upon. + For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date + with respect to the current state of the instance. + format: int64 + minimum: 0 + type: integer + reason: + description: |- + reason contains a programmatic identifier indicating the reason for the condition's last transition. + Producers of specific condition types may define expected values and meanings for this field, + and whether the values are considered a guaranteed API. + The value should be a CamelCase string. + This field may not be empty. + maxLength: 1024 + minLength: 1 + pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - message + - reason + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + groupID: + description: GroupID is the id of the created group. + type: string + observedGeneration: + description: ObservedGeneration is the last reconciled generation. + format: int64 + type: integer + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/charts/kubernetes-operator/crds/netbird.io_nbgroups.yaml b/charts/kubernetes-operator/crds/netbird.io_nbgroups.yaml index 71b8673..6236988 100644 --- a/charts/kubernetes-operator/crds/netbird.io_nbgroups.yaml +++ b/charts/kubernetes-operator/crds/netbird.io_nbgroups.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.17.1 + controller-gen.kubebuilder.io/version: v0.20.1 name: nbgroups.netbird.io spec: group: netbird.io diff --git a/charts/kubernetes-operator/crds/netbird.io_nbpolicies.yaml b/charts/kubernetes-operator/crds/netbird.io_nbpolicies.yaml index bffff40..c1fa576 100644 --- a/charts/kubernetes-operator/crds/netbird.io_nbpolicies.yaml +++ b/charts/kubernetes-operator/crds/netbird.io_nbpolicies.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.17.1 + controller-gen.kubebuilder.io/version: v0.20.1 name: nbpolicies.netbird.io spec: group: netbird.io diff --git a/charts/kubernetes-operator/crds/netbird.io_nbresources.yaml b/charts/kubernetes-operator/crds/netbird.io_nbresources.yaml index b8ce582..cbf5ca4 100644 --- a/charts/kubernetes-operator/crds/netbird.io_nbresources.yaml +++ b/charts/kubernetes-operator/crds/netbird.io_nbresources.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.17.1 + controller-gen.kubebuilder.io/version: v0.20.1 name: nbresources.netbird.io spec: group: netbird.io diff --git a/charts/kubernetes-operator/crds/netbird.io_nbroutingpeers.yaml b/charts/kubernetes-operator/crds/netbird.io_nbroutingpeers.yaml index 4004d4d..866d40a 100644 --- a/charts/kubernetes-operator/crds/netbird.io_nbroutingpeers.yaml +++ b/charts/kubernetes-operator/crds/netbird.io_nbroutingpeers.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.17.1 + controller-gen.kubebuilder.io/version: v0.20.1 name: nbroutingpeers.netbird.io spec: group: netbird.io diff --git a/charts/kubernetes-operator/crds/netbird.io_nbsetupkeys.yaml b/charts/kubernetes-operator/crds/netbird.io_nbsetupkeys.yaml index 46b33a3..60aa6df 100644 --- a/charts/kubernetes-operator/crds/netbird.io_nbsetupkeys.yaml +++ b/charts/kubernetes-operator/crds/netbird.io_nbsetupkeys.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.17.1 + controller-gen.kubebuilder.io/version: v0.20.1 name: nbsetupkeys.netbird.io spec: group: netbird.io diff --git a/charts/kubernetes-operator/crds/netbird.io_networkresources.yaml b/charts/kubernetes-operator/crds/netbird.io_networkresources.yaml new file mode 100644 index 0000000..4ed250a --- /dev/null +++ b/charts/kubernetes-operator/crds/netbird.io_networkresources.yaml @@ -0,0 +1,206 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.20.1 + name: networkresources.netbird.io +spec: + group: netbird.io + names: + kind: NetworkResource + listKind: NetworkResourceList + plural: networkresources + singular: networkresource + scope: Namespaced + versions: + - additionalPrinterColumns: + - jsonPath: .status.conditions[?(@.type=="Ready")].status + name: Ready + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1alpha1 + schema: + openAPIV3Schema: + description: NetworkResource is the Schema for the networkresources API. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: NetworkResourceSpec defines the desired state of NetworkResource. + properties: + groups: + description: Groups are references to groups that the resource will + be a part of. + items: + properties: + id: + description: ID is the id of the group. + type: string + localRef: + description: LocalReference is a reference to a group in the + same namespace. + properties: + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + type: object + x-kubernetes-map-type: atomic + name: + description: Name is the name of the group. + type: string + type: object + x-kubernetes-validations: + - message: Exactly one of id, name, or localRef must be set + rule: (has(self.id)?1:0)+(has(self.name)?1:0)+(has(self.localRef)?1:0)==1 + type: array + networkRouterRef: + description: NetworkRouterRef is a reference to the network and router + where the resource will be created. + properties: + name: + description: Name of the referent. + type: string + namespace: + description: Namespace of the referent. + type: string + required: + - name + - namespace + type: object + x-kubernetes-validations: + - message: Value is immutable + rule: self == oldSelf + serviceRef: + description: ServiceRef is a reference to the service to expose in + the Network. + properties: + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + type: object + x-kubernetes-map-type: atomic + required: + - networkRouterRef + - serviceRef + type: object + status: + default: + observedGeneration: -1 + description: NetworkResourceStatus defines the observed state of NetworkResource. + properties: + conditions: + description: Conditions holds the conditions for the NetworkResource. + items: + description: Condition contains details for one aspect of the current + state of this API Resource. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + description: |- + message is a human readable message indicating details about the transition. + This may be an empty string. + maxLength: 32768 + type: string + observedGeneration: + description: |- + observedGeneration represents the .metadata.generation that the condition was set based upon. + For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date + with respect to the current state of the instance. + format: int64 + minimum: 0 + type: integer + reason: + description: |- + reason contains a programmatic identifier indicating the reason for the condition's last transition. + Producers of specific condition types may define expected values and meanings for this field, + and whether the values are considered a guaranteed API. + The value should be a CamelCase string. + This field may not be empty. + maxLength: 1024 + minLength: 1 + pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - message + - reason + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + dnsRecordID: + description: DNSRecordID is the id of the created DNS record. + type: string + dnsZoneID: + description: DNSZoneID is the id of the zone the DNS record is created + in. + type: string + networkID: + description: NetworkID is the id of the network the resource is created + in. + type: string + observedGeneration: + description: ObservedGeneration is the last reconciled generation. + format: int64 + type: integer + resourceID: + description: ResourceID is the id of the created resource. + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/charts/kubernetes-operator/crds/netbird.io_networkrouters.yaml b/charts/kubernetes-operator/crds/netbird.io_networkrouters.yaml new file mode 100644 index 0000000..6644007 --- /dev/null +++ b/charts/kubernetes-operator/crds/netbird.io_networkrouters.yaml @@ -0,0 +1,168 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.20.1 + name: networkrouters.netbird.io +spec: + group: netbird.io + names: + kind: NetworkRouter + listKind: NetworkRouterList + plural: networkrouters + singular: networkrouter + scope: Namespaced + versions: + - additionalPrinterColumns: + - jsonPath: .status.conditions[?(@.type=="Ready")].status + name: Ready + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1alpha1 + schema: + openAPIV3Schema: + description: NetworkRouter is the Schema for the networkrouters API. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: NetworkRouterSpec defines the desired state of NetworkRouter. + properties: + dnsZoneRef: + description: DNSZoneRef is a reference to the DNS zone used to create + records for resources. + properties: + name: + description: Name is the domain name of an existing Netbird DNS + zone, e.g. "example.com". + type: string + required: + - name + type: object + workloadOverride: + description: WorkloadOverride contains configuration that will override + the default workload. + properties: + annotations: + additionalProperties: + type: string + description: Annotations that will be added. + type: object + labels: + additionalProperties: + type: string + description: Labels that will be added. + type: object + podTemplate: + description: PodTemplate overrides the pod template. + x-kubernetes-preserve-unknown-fields: true + replicas: + description: Replicas sets the amount of client replicas. + format: int32 + type: integer + type: object + required: + - dnsZoneRef + type: object + status: + default: + observedGeneration: -1 + description: NetworkRouterStatus defines the observed state of NetworkRouter. + properties: + conditions: + description: Conditions holds the conditions for the NetworkRouter. + items: + description: Condition contains details for one aspect of the current + state of this API Resource. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + description: |- + message is a human readable message indicating details about the transition. + This may be an empty string. + maxLength: 32768 + type: string + observedGeneration: + description: |- + observedGeneration represents the .metadata.generation that the condition was set based upon. + For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date + with respect to the current state of the instance. + format: int64 + minimum: 0 + type: integer + reason: + description: |- + reason contains a programmatic identifier indicating the reason for the condition's last transition. + Producers of specific condition types may define expected values and meanings for this field, + and whether the values are considered a guaranteed API. + The value should be a CamelCase string. + This field may not be empty. + maxLength: 1024 + minLength: 1 + pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - message + - reason + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + networkID: + description: NetworkID is the id of the network the routing peer was + created in. + type: string + observedGeneration: + description: ObservedGeneration is the last reconciled generation. + format: int64 + type: integer + routingPeerID: + description: RoutingPeerID is the id of the created routing peer. + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/charts/kubernetes-operator/crds/netbird.io_setupkeys.yaml b/charts/kubernetes-operator/crds/netbird.io_setupkeys.yaml new file mode 100644 index 0000000..0b1cad4 --- /dev/null +++ b/charts/kubernetes-operator/crds/netbird.io_setupkeys.yaml @@ -0,0 +1,181 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.20.1 + name: setupkeys.netbird.io +spec: + group: netbird.io + names: + kind: SetupKey + listKind: SetupKeyList + plural: setupkeys + singular: setupkey + scope: Namespaced + versions: + - additionalPrinterColumns: + - jsonPath: .status.conditions[?(@.type=="Ready")].status + name: Ready + type: string + - jsonPath: .metadata.creationTimestamp + name: Age + type: date + name: v1alpha1 + schema: + openAPIV3Schema: + description: SetupKey is the Schema for the setupkeys API. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: SetupKeySpec defines the desired state of SetupKey. + properties: + autoGroups: + description: AutoGroups are groups that will be automatically assigned + to peers using setup key. + items: + properties: + id: + description: ID is the id of the group. + type: string + localRef: + description: LocalReference is a reference to a group in the + same namespace. + properties: + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + type: object + x-kubernetes-map-type: atomic + name: + description: Name is the name of the group. + type: string + type: object + x-kubernetes-validations: + - message: Exactly one of id, name, or localRef must be set + rule: (has(self.id)?1:0)+(has(self.name)?1:0)+(has(self.localRef)?1:0)==1 + type: array + duration: + description: Duration sets how long the setup key is valid for. + pattern: ^([0-9]+(\.[0-9]+)?(m|h))+$ + type: string + x-kubernetes-validations: + - message: duration is immutable + rule: self == oldSelf + ephemeral: + description: Ephemeral decides if peers added with the key are ephemeral + or not. + type: boolean + x-kubernetes-validations: + - message: ephemeral is immutable + rule: self == oldSelf + name: + description: Name of the setup key. + minLength: 1 + type: string + required: + - ephemeral + - name + type: object + status: + default: + observedGeneration: -1 + description: SetupKeyStatus defines the observed state of SetupKey. + properties: + conditions: + description: Conditions holds the conditions for the SetupKey. + items: + description: Condition contains details for one aspect of the current + state of this API Resource. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + description: |- + message is a human readable message indicating details about the transition. + This may be an empty string. + maxLength: 32768 + type: string + observedGeneration: + description: |- + observedGeneration represents the .metadata.generation that the condition was set based upon. + For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date + with respect to the current state of the instance. + format: int64 + minimum: 0 + type: integer + reason: + description: |- + reason contains a programmatic identifier indicating the reason for the condition's last transition. + Producers of specific condition types may define expected values and meanings for this field, + and whether the values are considered a guaranteed API. + The value should be a CamelCase string. + This field may not be empty. + maxLength: 1024 + minLength: 1 + pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - message + - reason + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + observedGeneration: + description: ObservedGeneration is the last reconciled generation. + format: int64 + type: integer + setupKeyID: + description: SetupKeyID is the id of the created setup key. + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/charts/kubernetes-operator/crds/netbird.io_sidecarprofiles.yaml b/charts/kubernetes-operator/crds/netbird.io_sidecarprofiles.yaml new file mode 100644 index 0000000..d08db01 --- /dev/null +++ b/charts/kubernetes-operator/crds/netbird.io_sidecarprofiles.yaml @@ -0,0 +1,551 @@ +--- +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + controller-gen.kubebuilder.io/version: v0.20.1 + name: sidecarprofiles.netbird.io +spec: + group: netbird.io + names: + kind: SidecarProfile + listKind: SidecarProfileList + plural: sidecarprofiles + singular: sidecarprofile + scope: Namespaced + versions: + - name: v1alpha1 + schema: + openAPIV3Schema: + description: SidecarProfile is the Schema for the sidecarprofiles API. + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: SidecarProfileSpec defines the desired state of SidecarProfile. + properties: + containerOverride: + properties: + env: + items: + description: EnvVar represents an environment variable present + in a Container. + properties: + name: + description: |- + Name of the environment variable. + May consist of any printable ASCII characters except '='. + type: string + value: + description: |- + Variable references $(VAR_NAME) are expanded + using the previously defined environment variables in the container and + any service environment variables. If a variable cannot be resolved, + the reference in the input string will be unchanged. Double $$ are reduced + to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e. + "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". + Escaped references will never be expanded, regardless of whether the variable + exists or not. + Defaults to "". + type: string + valueFrom: + description: Source for the environment variable's value. + Cannot be used if value is not empty. + properties: + configMapKeyRef: + description: Selects a key of a ConfigMap. + properties: + key: + description: The key to select. + type: string + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + optional: + description: Specify whether the ConfigMap or its + key must be defined + type: boolean + required: + - key + type: object + x-kubernetes-map-type: atomic + fieldRef: + description: |- + Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['']`, `metadata.annotations['']`, + spec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs. + properties: + apiVersion: + description: Version of the schema the FieldPath + is written in terms of, defaults to "v1". + type: string + fieldPath: + description: Path of the field to select in the + specified API version. + type: string + required: + - fieldPath + type: object + x-kubernetes-map-type: atomic + fileKeyRef: + description: |- + FileKeyRef selects a key of the env file. + Requires the EnvFiles feature gate to be enabled. + properties: + key: + description: |- + The key within the env file. An invalid key will prevent the pod from starting. + The keys defined within a source may consist of any printable ASCII characters except '='. + During Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters. + type: string + optional: + default: false + description: |- + Specify whether the file or its key must be defined. If the file or key + does not exist, then the env var is not published. + If optional is set to true and the specified key does not exist, + the environment variable will not be set in the Pod's containers. + + If optional is set to false and the specified key does not exist, + an error will be returned during Pod creation. + type: boolean + path: + description: |- + The path within the volume from which to select the file. + Must be relative and may not contain the '..' path or start with '..'. + type: string + volumeName: + description: The name of the volume mount containing + the env file. + type: string + required: + - key + - path + - volumeName + type: object + x-kubernetes-map-type: atomic + resourceFieldRef: + description: |- + Selects a resource of the container: only resources limits and requests + (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported. + properties: + containerName: + description: 'Container name: required for volumes, + optional for env vars' + type: string + divisor: + anyOf: + - type: integer + - type: string + description: Specifies the output format of the + exposed resources, defaults to "1" + pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$ + x-kubernetes-int-or-string: true + resource: + description: 'Required: resource to select' + type: string + required: + - resource + type: object + x-kubernetes-map-type: atomic + secretKeyRef: + description: Selects a key of a secret in the pod's + namespace + properties: + key: + description: The key of the secret to select from. Must + be a valid secret key. + type: string + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + optional: + description: Specify whether the Secret or its key + must be defined + type: boolean + required: + - key + type: object + x-kubernetes-map-type: atomic + type: object + required: + - name + type: object + type: array + image: + description: Image overrides the image used by the client. + type: string + securityContext: + description: |- + SecurityContext holds security configuration that will be applied to a container. + Some fields are present in both SecurityContext and PodSecurityContext. When both + are set, the values in SecurityContext take precedence. + properties: + allowPrivilegeEscalation: + description: |- + AllowPrivilegeEscalation controls whether a process can gain more + privileges than its parent process. This bool directly controls if + the no_new_privs flag will be set on the container process. + AllowPrivilegeEscalation is true always when the container is: + 1) run as Privileged + 2) has CAP_SYS_ADMIN + Note that this field cannot be set when spec.os.name is windows. + type: boolean + appArmorProfile: + description: |- + appArmorProfile is the AppArmor options to use by this container. If set, this profile + overrides the pod's appArmorProfile. + Note that this field cannot be set when spec.os.name is windows. + properties: + localhostProfile: + description: |- + localhostProfile indicates a profile loaded on the node that should be used. + The profile must be preconfigured on the node to work. + Must match the loaded name of the profile. + Must be set if and only if type is "Localhost". + type: string + type: + description: |- + type indicates which kind of AppArmor profile will be applied. + Valid options are: + Localhost - a profile pre-loaded on the node. + RuntimeDefault - the container runtime's default profile. + Unconfined - no AppArmor enforcement. + type: string + required: + - type + type: object + capabilities: + description: |- + The capabilities to add/drop when running containers. + Defaults to the default set of capabilities granted by the container runtime. + Note that this field cannot be set when spec.os.name is windows. + properties: + add: + description: Added capabilities + items: + description: Capability represent POSIX capabilities + type + type: string + type: array + x-kubernetes-list-type: atomic + drop: + description: Removed capabilities + items: + description: Capability represent POSIX capabilities + type + type: string + type: array + x-kubernetes-list-type: atomic + type: object + privileged: + description: |- + Run container in privileged mode. + Processes in privileged containers are essentially equivalent to root on the host. + Defaults to false. + Note that this field cannot be set when spec.os.name is windows. + type: boolean + procMount: + description: |- + procMount denotes the type of proc mount to use for the containers. + The default value is Default which uses the container runtime defaults for + readonly paths and masked paths. + This requires the ProcMountType feature flag to be enabled. + Note that this field cannot be set when spec.os.name is windows. + type: string + readOnlyRootFilesystem: + description: |- + Whether this container has a read-only root filesystem. + Default is false. + Note that this field cannot be set when spec.os.name is windows. + type: boolean + runAsGroup: + description: |- + The GID to run the entrypoint of the container process. + Uses runtime default if unset. + May also be set in PodSecurityContext. If set in both SecurityContext and + PodSecurityContext, the value specified in SecurityContext takes precedence. + Note that this field cannot be set when spec.os.name is windows. + format: int64 + type: integer + runAsNonRoot: + description: |- + Indicates that the container must run as a non-root user. + If true, the Kubelet will validate the image at runtime to ensure that it + does not run as UID 0 (root) and fail to start the container if it does. + If unset or false, no such validation will be performed. + May also be set in PodSecurityContext. If set in both SecurityContext and + PodSecurityContext, the value specified in SecurityContext takes precedence. + type: boolean + runAsUser: + description: |- + The UID to run the entrypoint of the container process. + Defaults to user specified in image metadata if unspecified. + May also be set in PodSecurityContext. If set in both SecurityContext and + PodSecurityContext, the value specified in SecurityContext takes precedence. + Note that this field cannot be set when spec.os.name is windows. + format: int64 + type: integer + seLinuxOptions: + description: |- + The SELinux context to be applied to the container. + If unspecified, the container runtime will allocate a random SELinux context for each + container. May also be set in PodSecurityContext. If set in both SecurityContext and + PodSecurityContext, the value specified in SecurityContext takes precedence. + Note that this field cannot be set when spec.os.name is windows. + properties: + level: + description: Level is SELinux level label that applies + to the container. + type: string + role: + description: Role is a SELinux role label that applies + to the container. + type: string + type: + description: Type is a SELinux type label that applies + to the container. + type: string + user: + description: User is a SELinux user label that applies + to the container. + type: string + type: object + seccompProfile: + description: |- + The seccomp options to use by this container. If seccomp options are + provided at both the pod & container level, the container options + override the pod options. + Note that this field cannot be set when spec.os.name is windows. + properties: + localhostProfile: + description: |- + localhostProfile indicates a profile defined in a file on the node should be used. + The profile must be preconfigured on the node to work. + Must be a descending path, relative to the kubelet's configured seccomp profile location. + Must be set if type is "Localhost". Must NOT be set for any other type. + type: string + type: + description: |- + type indicates which kind of seccomp profile will be applied. + Valid options are: + + Localhost - a profile defined in a file on the node should be used. + RuntimeDefault - the container runtime default profile should be used. + Unconfined - no profile should be applied. + type: string + required: + - type + type: object + windowsOptions: + description: |- + The Windows specific settings applied to all containers. + If unspecified, the options from the PodSecurityContext will be used. + If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. + Note that this field cannot be set when spec.os.name is linux. + properties: + gmsaCredentialSpec: + description: |- + GMSACredentialSpec is where the GMSA admission webhook + (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the + GMSA credential spec named by the GMSACredentialSpecName field. + type: string + gmsaCredentialSpecName: + description: GMSACredentialSpecName is the name of the + GMSA credential spec to use. + type: string + hostProcess: + description: |- + HostProcess determines if a container should be run as a 'Host Process' container. + All of a Pod's containers must have the same effective HostProcess value + (it is not allowed to have a mix of HostProcess containers and non-HostProcess containers). + In addition, if HostProcess is true then HostNetwork must also be set to true. + type: boolean + runAsUserName: + description: |- + The UserName in Windows to run the entrypoint of the container process. + Defaults to the user specified in image metadata if unspecified. + May also be set in PodSecurityContext. If set in both SecurityContext and + PodSecurityContext, the value specified in SecurityContext takes precedence. + type: string + type: object + type: object + type: object + extraDNSLabels: + description: ExtraDNSLabels assigns additional DNS names to peers + beyond their default hostname. + items: + type: string + type: array + injectionMode: + default: Sidecar + description: InjectionMode defines whether the sidecar is injected + as a native Kubernetes sidecar container or as a regular container. + enum: + - Sidecar + - Container + type: string + podSelector: + description: |- + PodSelector determines which pods the profile should apply to. + An empty slector means the profile will apply to all pods in the namespace. + properties: + matchExpressions: + description: matchExpressions is a list of label selector requirements. + The requirements are ANDed. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key that the selector applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + matchLabels: + additionalProperties: + type: string + description: |- + matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels + map is equivalent to an element of matchExpressions, whose key field is "key", the + operator is "In", and the values array contains only "value". The requirements are ANDed. + type: object + type: object + x-kubernetes-map-type: atomic + setupKeyRef: + description: SetupKeyRef is the reference to the setup key used in + the client. + properties: + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + type: object + x-kubernetes-map-type: atomic + required: + - setupKeyRef + type: object + status: + default: {} + description: SidecarProfileStatus defines the observed state of SidecarProfile. + properties: + conditions: + description: Conditions holds the conditions for the SidecarProfile. + items: + description: Condition contains details for one aspect of the current + state of this API Resource. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + description: |- + message is a human readable message indicating details about the transition. + This may be an empty string. + maxLength: 32768 + type: string + observedGeneration: + description: |- + observedGeneration represents the .metadata.generation that the condition was set based upon. + For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date + with respect to the current state of the instance. + format: int64 + minimum: 0 + type: integer + reason: + description: |- + reason contains a programmatic identifier indicating the reason for the condition's last transition. + Producers of specific condition types may define expected values and meanings for this field, + and whether the values are considered a guaranteed API. + The value should be a CamelCase string. + This field may not be empty. + maxLength: 1024 + minLength: 1 + pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - message + - reason + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/charts/kubernetes-operator/templates/deployment.yaml b/charts/kubernetes-operator/templates/deployment.yaml index 27e03c0..31fe20b 100644 --- a/charts/kubernetes-operator/templates/deployment.yaml +++ b/charts/kubernetes-operator/templates/deployment.yaml @@ -61,7 +61,7 @@ spec: {{- if .Values.cluster.dns }} - --cluster-dns={{.Values.cluster.dns}} {{- end }} - {{- if or .Values.netbirdAPI.key .Values.netbirdAPI.keyFromSecret }} + {{- if .Values.netbirdAPI.keyFromSecret }} - --netbird-api-key=$(NB_API_KEY) {{- end }} {{- if .Values.ingress.allowAutomaticPolicyCreation }} @@ -96,7 +96,7 @@ spec: valueFrom: fieldRef: fieldPath: metadata.namespace - {{- if or .Values.netbirdAPI.key .Values.netbirdAPI.keyFromSecret }} + {{- if .Values.netbirdAPI.keyFromSecret }} - name: NB_API_KEY valueFrom: secretKeyRef: diff --git a/charts/kubernetes-operator/templates/kubernetes-nbresource.yaml b/charts/kubernetes-operator/templates/kubernetes-nbresource.yaml deleted file mode 100644 index 3448f74..0000000 --- a/charts/kubernetes-operator/templates/kubernetes-nbresource.yaml +++ /dev/null @@ -1,71 +0,0 @@ -{{- if and .Values.ingress.enabled .Values.ingress.kubernetesAPI.enabled }} -{{- $routerNS := .Release.Namespace }} -{{- if .Values.ingress.namespacedNetworks }} -{{- $routerNS = "default" }} -{{- end }} -apiVersion: batch/v1 -kind: Job -metadata: - name: {{ include "kubernetes-operator.fullname" . }}-kubernetes-service-expose - labels: - app.kubernetes.io/component: operator - {{- include "kubernetes-operator.labels" . | nindent 4 }} - annotations: - helm.sh/hook: post-upgrade,post-install - helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded -spec: - backoffLimit: 3 - template: - metadata: - name: {{ include "kubernetes-operator.fullname" . }} - labels: - app.kubernetes.io/component: operator - {{- include "kubernetes-operator.labels" . | nindent 8 }} - {{- with .Values.operator.podLabels }} - {{- toYaml . | nindent 8 }} - {{- end }} - spec: - initContainers: - - name: wait-network-ready - image: "netbirdio/kubectl:latest" - command: - - sh - - -c - args: - - kubectl wait --for 'jsonpath={.status.networkID}' -n {{ $routerNS }} nbroutingpeer router; - containers: - - name: apply-nbresource - image: "netbirdio/kubectl:latest" - env: - - name: NBRESOURCE_VALUE - value: | - apiVersion: netbird.io/v1 - kind: NBResource - metadata: - finalizers: - - netbird.io/cleanup - name: kubernetes - namespace: default - spec: - address: kubernetes.default.{{.Values.cluster.dns}} - groups: - {{- if .Values.ingress.kubernetesAPI.groups }} - {{ toYaml .Values.ingress.kubernetesAPI.groups }} - {{- else }} - - {{ .Values.cluster.name }}-default-api-access - {{- end }} - name: {{ .Values.ingress.kubernetesAPI.resourceName | default "default-kubernetes-api" }} - networkID: ${NETWORK_ID} - {{- if .Values.ingress.kubernetesAPI.policies }} - policyName: "{{ join "," .Values.ingress.kubernetesAPI.policies }}" - {{- end }} - tcpPorts: - - 443 - command: - - sh - - -c - args: - - kubectl delete NBResource --ignore-not-found -n default kubernetes; export NETWORK_ID=$(kubectl get NBRoutingPeer -n {{ $routerNS }} router -o 'jsonpath={.status.networkID}'); echo "$NBRESOURCE_VALUE" | envsubst | kubectl apply -f - - serviceAccountName: {{ include "kubernetes-operator.serviceAccountName" . }} - restartPolicy: Never -{{- end }} diff --git a/charts/kubernetes-operator/templates/rbac.yaml b/charts/kubernetes-operator/templates/rbac.yaml index ad12f47..50ec2a0 100644 --- a/charts/kubernetes-operator/templates/rbac.yaml +++ b/charts/kubernetes-operator/templates/rbac.yaml @@ -27,7 +27,6 @@ rules: - get - patch - update -{{- if or .Values.netbirdAPI.key .Values.netbirdAPI.keyFromSecret }} - apiGroups: - netbird.io resources: @@ -35,6 +34,11 @@ rules: - nbresources - nbroutingpeers - nbpolicies + - setupkeys + - groups + - networkrouters + - networkresources + - sidecarprofiles verbs: - get - patch @@ -50,6 +54,11 @@ rules: - nbresources/status - nbroutingpeers/status - nbpolicies/status + - setupkeys/status + - groups/status + - networkrouters/status + - networkresources/status + - sidecarprofiles/status verbs: - get - patch @@ -61,6 +70,11 @@ rules: - nbresources/finalizers - nbroutingpeers/finalizers - nbpolicies/finalizers + - setupkeys/finalizers + - groups/finalizers + - networkrouters/finalizers + - networkresources/finalizers + - sidecarprofiles/finalizers verbs: - update - apiGroups: @@ -99,7 +113,6 @@ rules: - watch - create - delete -{{- end }} - apiGroups: - "" resources: @@ -108,7 +121,7 @@ rules: - get - list - watch -{{- if or (or .Values.netbirdAPI.key .Values.netbirdAPI.keyFromSecret) .Values.clusterSecretsPermissions.allowAllSecrets }} +{{- if or .Values.netbirdAPI.keyFromSecret .Values.clusterSecretsPermissions.allowAllSecrets }} - apiGroups: - "" resources: @@ -117,7 +130,7 @@ rules: - get - list - watch -{{- if or .Values.netbirdAPI.key .Values.netbirdAPI.keyFromSecret }} +{{- if .Values.netbirdAPI.keyFromSecret }} - patch - update - create diff --git a/charts/kubernetes-operator/templates/secret.yaml b/charts/kubernetes-operator/templates/secret.yaml deleted file mode 100644 index 099517e..0000000 --- a/charts/kubernetes-operator/templates/secret.yaml +++ /dev/null @@ -1,11 +0,0 @@ -{{- if .Values.netbirdAPI.key }} -apiVersion: v1 -kind: Secret -metadata: - name: {{ include "kubernetes-operator.fullname" . }} - labels: - app.kubernetes.io/component: operator - {{- include "kubernetes-operator.labels" . | nindent 4 }} -stringData: - NB_API_KEY: {{ .Values.netbirdAPI.key }} -{{- end }} \ No newline at end of file diff --git a/charts/kubernetes-operator/templates/webhook.yaml b/charts/kubernetes-operator/templates/webhook.yaml index 9209de9..fc12f4f 100644 --- a/charts/kubernetes-operator/templates/webhook.yaml +++ b/charts/kubernetes-operator/templates/webhook.yaml @@ -51,7 +51,7 @@ webhooks: resources: - pods sideEffects: None -{{- if and $.Values.ingress.enabled (or .Values.netbirdAPI.key .Values.netbirdAPI.keyFromSecret) }} +{{- if and $.Values.ingress.enabled .Values.netbirdAPI.keyFromSecret }} --- apiVersion: admissionregistration.k8s.io/v1 kind: ValidatingWebhookConfiguration diff --git a/charts/kubernetes-operator/values.yaml b/charts/kubernetes-operator/values.yaml index f773c93..b9464f9 100644 --- a/charts/kubernetes-operator/values.yaml +++ b/charts/kubernetes-operator/values.yaml @@ -133,6 +133,7 @@ operator: affinity: {} +# DEPRECATED: Use NetworkRouters and NetworkResources instead. ingress: # Enable ingress capabilities to expose services enabled: false @@ -140,52 +141,6 @@ ingress: namespacedNetworks: false # Allow creating policies through Service annotations allowAutomaticPolicyCreation: false - kubernetesAPI: # DEPRECATED: Use netbirdio/netbird-operator-configs Chart instead - enabled: false - groups: [] - # - group1 - # - group2 - policies: [] - # - default - router: # DEPRECATED: Use netbirdio/netbird-operator-configs Chart instead - # Deploy routing peer(s) - enabled: false - # replicas: 3 - # resources: - # requests: - # cpu: 100m - # memory: 100Mi - # limits: - # cpu: 100m - # memory: 100Mi - # labels: {} - # annotations: {} - # nodeSelector: {} - # tolerations: [] - # Only needed if namespacedNetworks is set to true - namespaces: {} - # default: - # replicas: 3 - # resources: - # requests: - # cpu: 100m - # memory: 100Mi - # limits: - # cpu: 100m - # memory: 100Mi - # labels: {} - # annotations: {} - # nodeSelector: {} - # tolerations: [] - # NetBird Policies for use with exposed services - policies: {} # DEPRECATED: Use netbirdio/netbird-operator-configs Chart instead - # default: - # name: Kubernetes Default Policy - # sourceGroups: - # - All - -gatewayAPI: - enabled: false cluster: # Cluster DNS name (used for webhooks certificates and for network resource DNS names) @@ -193,15 +148,16 @@ cluster: # Cluster name (used for generating network and network resource names in NetBird) name: kubernetes -netbirdAPI: {} - # NetBird Service Account Token - # key: "nbp_m0LM9ZZvDUzFO0pY50iChDOTxJgKFM3DIqmZ" - #keyFromSecret: - # name: "Secret name" - # key: "NB_API_KEY" +netbirdAPI: + keyFromSecret: + name: "netbird-mgmt-api-key" + key: "NB_API_KEY" #routingClientImage: "netbirdio/netbird:latest" +gatewayAPI: + enabled: false + general: # General labels, applied to all created K8s resources labels: {}