Change chart directory structure

This commit is contained in:
wbsong111
2026-01-19 16:11:44 +09:00
parent 0f2284bf35
commit 0436749932
5948 changed files with 119 additions and 79 deletions
@@ -0,0 +1,5 @@
approvers:
- juliusvonkohout
reviewers:
- juliusvonkohout
@@ -0,0 +1,13 @@
# Kubeflow Spark Operator
Derived from https://github.com/kubeflow/spark-operator/
## What is Spark Operator?
The Kubernetes Operator for Apache Spark aims to make specifying and running [Spark](https://github.com/apache/spark) applications as easy and idiomatic as running other workloads on Kubernetes. It uses [Kubernetes custom resources](https://kubernetes.io/docs/concepts/extend-kubernetes/api-extension/custom-resources/) for specifying, running, and surfacing status of Spark applications.
## Update
Please use the synchronization script in /scripts.
@@ -0,0 +1,69 @@
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeflow-spark-admin
labels:
app: spark-operator
app.kubernetes.io/name: spark-operator
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-admin: "true"
rules: []
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeflow-spark-edit
labels:
app: spark-operator
app.kubernetes.io/name: spark-operator
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-edit: "true"
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-admin: "true"
rules:
- apiGroups:
- sparkoperator.k8s.io
resources:
- sparkapplications
- scheduledsparkapplications
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- sparkoperator.k8s.io
resources:
- sparkapplications/status
- scheduledsparkapplications/status
verbs:
- get
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeflow-spark-view
labels:
app: spark-operator
app.kubernetes.io/name: spark-operator
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-view: "true"
rules:
- apiGroups:
- sparkoperator.k8s.io
resources:
- sparkapplications
- scheduledsparkapplications
verbs:
- get
- list
- watch
- apiGroups:
- sparkoperator.k8s.io
resources:
- sparkapplications/status
- scheduledsparkapplications/status
verbs:
- get
---
@@ -0,0 +1,65 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- resources.yaml
- aggregated-roles.yaml
namespace: kubeflow
patches:
- target:
kind: Deployment
name: spark-operator-webhook
patch: |-
- op: add
path: /spec/template/spec/containers/0/securityContext
value:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
privileged: false
readOnlyRootFilesystem: true
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault # Only this is missing upstream!
- target:
kind: Deployment
name: spark-operator-controller
patch: |-
- op: add
path: /spec/template/spec/containers/0/securityContext
value:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
privileged: false
readOnlyRootFilesystem: true
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault # only this is missing upstream!
- target:
kind: Deployment
name: spark-operator-webhook
patch: |-
apiVersion: apps/v1
kind: Deployment
metadata:
name: spark-operator-webhook
spec:
template:
metadata:
labels:
sidecar.istio.io/inject: "false"
- target:
kind: Deployment
name: spark-operator-controller
patch: |-
apiVersion: apps/v1
kind: Deployment
metadata:
name: spark-operator-controller
spec:
template:
metadata:
labels:
sidecar.istio.io/inject: "false"
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,3 @@
namespace: kubeflow
resources:
- ../../base
@@ -0,0 +1,3 @@
namespace: kubeflow
resources:
- ../../base
@@ -0,0 +1,46 @@
apiVersion: sparkoperator.k8s.io/v1beta2
kind: SparkApplication
metadata:
name: spark-pi-python
labels:
sidecar.istio.io/inject: "false"
spec:
type: Python
pythonVersion: "3"
mode: cluster
image: spark:3.5.2
imagePullPolicy: IfNotPresent
mainApplicationFile: local:///opt/spark/examples/src/main/python/pi.py
sparkVersion: 3.5.2
driver:
cores: 1
memory: 512m
serviceAccount: default-editor
labels:
sidecar.istio.io/inject: "false"
securityContext:
capabilities:
drop:
- ALL
runAsUser: 185
runAsGroup: 0
runAsNonRoot: true
allowPrivilegeEscalation: false
seccompProfile:
type: RuntimeDefault
executor:
instances: 1
cores: 1
memory: 512m
labels:
sidecar.istio.io.inject: "false"
securityContext:
capabilities:
drop:
- ALL
runAsUser: 185
runAsGroup: 0
runAsNonRoot: true
allowPrivilegeEscalation: false
seccompProfile:
type: RuntimeDefault