Change chart directory structure
This commit is contained in:
@@ -0,0 +1 @@
|
||||
tests
|
||||
@@ -0,0 +1,146 @@
|
||||
# Rancher 버전 갱신 가이드
|
||||
|
||||
## 1. git 작업 환경 구성
|
||||
|
||||
- 서비스 카탈로그 git 다운로드
|
||||
```
|
||||
$ git clone https://github.com/paasup/service-catalog.git
|
||||
```
|
||||
|
||||
- 작업 브랜치로 체크아웃
|
||||
```
|
||||
$ git checkout -b update-rancher/2.10.1
|
||||
```
|
||||
|
||||
|
||||
|
||||
## 2. helm 차트 버전 업데이트
|
||||
|
||||
### 1) 차트 버전 변경
|
||||
|
||||
- rancher 차트에 추가한 파일을 제외한 나미지 파일을 삭제한다.
|
||||
|
||||
- 삭제 제외 파일,디렉토리 목록
|
||||
|
||||
- BUILD-README.md
|
||||
- CUSTOM-README.md
|
||||
- custom-values.yaml
|
||||
|
||||
- templates/preinstallHook/*
|
||||
|
||||
- 삭제 명령어.
|
||||
|
||||
``` sh
|
||||
# chart 디렉토리로 이동
|
||||
cd ~/service-catalog/charts/rancher
|
||||
|
||||
# 파일 삭제 전 삭제할 파일 목록 확인
|
||||
find . -type f -not \( -name "CUSTOM-README.md" -o -name "BUILD-README.md" -o -name "custom-values.yaml" -o -path "./scripts/cleanup-rancher.sh" -o -path "./scripts/README.md" -o -path "*/templates/preinstallHook/*" \)
|
||||
|
||||
# 파일 삭제
|
||||
find . -type f -not \( -name "CUSTOM-README.md" -o -name "BUILD-README.md" -o -name "custom-values.yaml" -o -path "./scripts/cleanup-rancher.sh" -o -path "./scripts/README.md" -o -path "*/templates/preinstallHook/*" \) -delete
|
||||
```
|
||||
|
||||
- 변경할 rancher 버전의 차트를 다운로드
|
||||
``` sh
|
||||
# charts 디렉토리로 이동
|
||||
cd ~/service-catalog/charts
|
||||
|
||||
# helm repo 추가
|
||||
helm repo add rancher-latest https://releases.rancher.com/server-charts/latest
|
||||
helm repo update
|
||||
|
||||
# helm 차트
|
||||
helm pull rancher-latest/rancher --version="2.10.1"
|
||||
|
||||
# 차트 변경
|
||||
tar xzvf rancher*.tgz
|
||||
|
||||
# 필요 없는 파일 삭제
|
||||
rm rancher-*.tgz
|
||||
```
|
||||
|
||||
### 2) 차트 수정
|
||||
- post delete hook 파일 삭제(argocd에서 실행시 문제 발생 > 해당 문제 해결 시 제외)
|
||||
``` sh
|
||||
rm -f templates/post-delete-hook*
|
||||
```
|
||||
- post-delete-hook.sh 수정
|
||||
``` sh
|
||||
# line 81에 kubectl delete 문 추가
|
||||
kubectl --ignore-not-found=true delete secret tls-ca -n ${rancher_namespace}
|
||||
...
|
||||
# 스크립트 마지막에 아래 내용 추가
|
||||
for ns in $(kubectl get namespaces -o jsonpath='{.items[*].metadata.name}'); do
|
||||
# Remove finalizers from the namespace itself
|
||||
kubectl patch namespace "$ns" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
|
||||
# Remove finalizers from all roles in the namespace
|
||||
for role in $(kubectl get roles -n "$ns" -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch role "$role" -n "$ns" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
|
||||
# Remove finalizers from all rolebindings in the namespace
|
||||
for rolebinding in $(kubectl get rolebindings -n $ns -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch rolebinding "$rolebinding" -n "$ns" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
done
|
||||
|
||||
for cr in $(kubectl get clusterroles -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch clusterrole "$cr" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
|
||||
for crb in $(kubectl get clusterrolebindings -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch clusterrolebinding "$crb" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
```
|
||||
|
||||
- values.yaml에 `preinstallHook: false` 추가
|
||||
``` yaml
|
||||
# 문서 마지막에 아래 값 추가
|
||||
preinstallHook: false
|
||||
```
|
||||
|
||||
## 3. git push 및 tag 추가
|
||||
|
||||
- 갱신작업 진행후 commit
|
||||
```
|
||||
$ git add .
|
||||
$ git commit -m "update rancher/2.10.1"
|
||||
```
|
||||
|
||||
- main 브랜치에 체크아웃 후 merge
|
||||
```
|
||||
$ git checkout main
|
||||
$ git merge update-rancher/2.10.1
|
||||
```
|
||||
|
||||
- git에 push 후 작업 브랜치 삭제
|
||||
```
|
||||
$ git push -u origin main
|
||||
$ git branch -d update-rancher/2.10.1
|
||||
```
|
||||
|
||||
- git tag 추가 후 push
|
||||
```
|
||||
$ git tag rancher/2.10.1
|
||||
$ git push origin rancher/2.10.1
|
||||
```
|
||||
|
||||
|
||||
|
||||
## 4. 차트 버전 정보
|
||||
|
||||
- rancher/2.10.1
|
||||
- 서비스 배포를 위하여 custom-values.yam에 정의하였다.
|
||||
- 차트의 빌드 방법과 배포 방법을 BUILD-README.md, CUSTOM-README.md 문서에 작성하였다.
|
||||
- rancher/2.10.1-1
|
||||
- 사설 인증서 사용시 전처리를 위한 Helm preinstall Hook을 추가하였다.
|
||||
- 변경 사항을 BUILD-README.md, CUSTOM-README.md 문서에 반영하였다.
|
||||
- rancher/2.10.1-2
|
||||
- Helm preinstall Hook에 rancher labels 추가
|
||||
- Helm preinstall Hook으로 생성된 자원을 삭제하기 위해 Helm postdelete Hook을 추가하였다.
|
||||
- 변경 사항을 BUILD-README.md 문서에 반영하였다.
|
||||
- rancher/2.10.1-3
|
||||
- Argocd post-delete Hook 이슈로 Hook을 삭제하였다.
|
||||
- Rancher 삭제 후처리를 위한 스크립트 수정 및 추가하였다.
|
||||
@@ -0,0 +1,103 @@
|
||||
|
||||
# Rancher 배포
|
||||
|
||||
## 1. 배포시 주의 사항
|
||||
- ingress 배포를 위해서는 인증서가 [secret으로 배포](#인증서-secret-생성)되어 있어야 한다.
|
||||
- [사설 인증서 사용](#사설-인증서-사용)시 ca를 secret으로 배포되어 있어야 한다.
|
||||
|
||||
## 2.custom-values.yaml 설명
|
||||
|
||||
- custom-values.yaml에 정의된 값에 대한 설명이다.
|
||||
|
||||
### 1) 오프라인 설정
|
||||
- private 환경 배포시 사용한다.
|
||||
|
||||
| Name | 설명 | 기본값 |
|
||||
| ---------------------- | ------------------------------------------------------------ | ------ |
|
||||
| `systemDefaultRegistry` | 오프라인 설치 시에 설정. <br />paasup 설치시에는 "paasup.io"로 설정 | `""` |
|
||||
| `rancherImage` | 오프라인 설치 시에 설정. <br />paasup 설치시에는 "paasup.io/rancher/rancher"로 설정 | `""` |
|
||||
|
||||
|
||||
### 2) Pod 설정
|
||||
|
||||
| Name | 설명 | 기본값 |
|
||||
| ------------------------ | ---------------------------------- | --------- |
|
||||
| `extraEnv` | rancher pod의 replicas 설정. | "1" |
|
||||
| `replicas` | rancher pod의 replicas 설정. | "1" |
|
||||
| `tolerations` | rancher pod의 toleration 설정. | `[]` |
|
||||
| `nodeSelector` | rancher pod의 nodeSelector 설정. | `{}` |
|
||||
| `resources.request.cpu` | rancher pod의 cpu requst 설정. | `"100m"` |
|
||||
| `resources.request.memory` | rancher pod의 memory requst 설정. | `"300Mi"` |
|
||||
| `resources.limits.cpu` | rancher pod의 cpu limits 설정. | `"300m"` |
|
||||
| `resources.limits.memory` | rancher pod의 memory limits 설정. | `500Mi` |
|
||||
|
||||
### 3) Timezone 설정
|
||||
|
||||
- pod의 기본 timezone 설정을 위해 추가.
|
||||
- 기본값으로 KST를 사용하기 위하여 Asia/Seolul로 설정하였다.
|
||||
|
||||
``` yaml
|
||||
extraEnv:
|
||||
- name: TZ
|
||||
value: Asia/Seoul
|
||||
```
|
||||
|
||||
### 4) Ingress 설정
|
||||
|
||||
#### 4.1) tls 시크릿 직접 생성
|
||||
|
||||
|
||||
- Rancher에서 ingress 사용을 위해서는 다음과 같이 설정할 수 있다.
|
||||
``` yaml
|
||||
# ingress 배포 전 인증서 secret 배포 필요(secret 이름은 platform)
|
||||
hostname: rancher.example.org
|
||||
ingress:
|
||||
enable: true
|
||||
tls:
|
||||
source: secret
|
||||
secretName: rancher-tls-ingress
|
||||
extraAnnotations:
|
||||
konghq.com/connect-timeout: "30000"
|
||||
konghq.com/read-timeout: "1800000"
|
||||
konghq.com/write-timeout: "1800000"
|
||||
|
||||
# 사설인증서 사용시 true 설정
|
||||
## privateCA를 true로 설정
|
||||
privateCA: true
|
||||
```
|
||||
|
||||
- ingress 사용을 위해서는 인증서를 secret으로 제공해야한다. 로컬 파일을 이용해 secret을 생성하는 방법은 다음과 같다.
|
||||
``` sh
|
||||
kubectl create secret tls rancher-tls-ingress --cert=<path-to-cert-file> --key=<path-to-key-file> -n <namespace>
|
||||
```
|
||||
|
||||
- 사설 인증서 사용시에는 ca를 secret으로 생성해야 한다. 로컬 파일을 이용해 secret을 생성하는 방법은 다음과 같다. secret의 이름은 `tls-ca`로 생성해야 한다.
|
||||
``` sh
|
||||
kubectl create secret generic tls-ca --from-file=${CERT_FILE} -n ${NAMESPACE}
|
||||
```
|
||||
|
||||
|
||||
#### 4.2) cert-manager를 이용한 자동 생성
|
||||
|
||||
|
||||
- cert manager를 통해 인증서 자동 생성 시 `custom-values.yaml` 수정한다.
|
||||
``` yaml
|
||||
# ingress 배포 전 인증서 secret 배포 필요(secret 이름은 platform)
|
||||
hostname: rancher.example.org
|
||||
ingress:
|
||||
enable: true
|
||||
tls:
|
||||
source: secret
|
||||
secretName: rancher-tls-secret
|
||||
extraAnnotations:
|
||||
konghq.com/connect-timeout: "30000"
|
||||
konghq.com/read-timeout: "1800000"
|
||||
konghq.com/write-timeout: "1800000"
|
||||
|
||||
|
||||
# 사설인증서 사용시 추가 설정
|
||||
## privateCA를 true로 설정
|
||||
privateCA: true
|
||||
## 사설인증서 사용을 위한 전처리 작업을 true로 설정
|
||||
preinstallHook: true
|
||||
```
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: v2
|
||||
appVersion: v2.10.1
|
||||
description: Install Rancher Server to manage Kubernetes clusters across providers.
|
||||
home: https://rancher.com
|
||||
icon: https://raw.githubusercontent.com/rancher/ui/master/public/assets/images/logos/welcome-cow.svg
|
||||
keywords:
|
||||
- rancher
|
||||
kubeVersion: < 1.32.0-0
|
||||
maintainers:
|
||||
- email: charts@rancher.com
|
||||
name: Rancher Labs
|
||||
name: rancher
|
||||
sources:
|
||||
- https://github.com/rancher/rancher
|
||||
- https://github.com/rancher/server-chart
|
||||
version: 2.10.1
|
||||
@@ -0,0 +1,208 @@
|
||||
By installing this application, you accept the [End User License Agreement & Terms & Conditions](https://www.suse.com/licensing/eula/).
|
||||
|
||||
# Rancher
|
||||
|
||||
***Rancher*** is open source software that combines everything an organization needs to adopt and run containers in production. Built on Kubernetes, Rancher makes it easy for DevOps teams to test, deploy and manage their applications.
|
||||
|
||||
### Introduction
|
||||
|
||||
This chart bootstraps a [Rancher Server](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster) on a Kubernetes cluster using the [Helm](https://helm.sh/) package manager. For a Rancher Supported Deployment please follow our [HA install instructions](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/kubernetes-cluster-setup/high-availability-installs).
|
||||
|
||||
|
||||
### Prerequisites Details
|
||||
|
||||
*For installations covered under [Rancher Support SLA](https://www.suse.com/suse-rancher/support-matrix/all-supported-versions) the target cluster must be **[RKE1](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/kubernetes-cluster-setup/rke1-for-rancher)**, **[RKE2](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/kubernetes-cluster-setup/rke2-for-rancher)**, **[K3s](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/kubernetes-cluster-setup/k3s-for-rancher)**, **[AKS](https://ranchermanager.docs.rancher.com/getting-started/installation-and-upgrade/install-upgrade-on-a-kubernetes-cluster/rancher-on-aks)**, **[EKS](https://ranchermanager.docs.rancher.com/getting-started/installation-and-upgrade/install-upgrade-on-a-kubernetes-cluster/rancher-on-amazon-eks)**, or **[GKE](https://ranchermanager.docs.rancher.com/getting-started/installation-and-upgrade/install-upgrade-on-a-kubernetes-cluster/rancher-on-gke)**.*
|
||||
|
||||
Make sure the node(s) for the Rancher server fulfill the following requirements:
|
||||
|
||||
[Operating Systems and Container Runtime Requirements](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#operating-systems-and-container-runtime-requirements)
|
||||
[Hardware Requirements](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#hardware-requirements)
|
||||
|
||||
- [CPU and Memory](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#cpu-and-memory)
|
||||
- [Ingress](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#ingress)
|
||||
- [Disks](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#disks)
|
||||
|
||||
[Networking Requirements](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#networking-requirements)
|
||||
- [Node IP Addresses](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#node-ip-addresses)
|
||||
- [Port Requirements](https://ranchermanager.docs.rancher.com/pages-for-subheaders/installation-requirements#port-requirements)
|
||||
|
||||
[Install the Required CLI Tools](https://ranchermanager.docs.rancher.com/pages-for-subheaders/cli-with-rancher)
|
||||
|
||||
- [kubectl](https://ranchermanager.docs.rancher.com/reference-guides/cli-with-rancher/kubectl-utility) - Kubernetes command-line tool.
|
||||
- [helm](https://docs.helm.sh/using_helm/#installing-helm) - Package management for Kubernetes. Refer to the [Helm version requirements](https://ranchermanager.docs.rancher.com/getting-started/installation-and-upgrade/resources/helm-version-requirements) to choose a version of Helm to install Rancher.
|
||||
|
||||
For a list of best practices that we recommend for running the Rancher server in production, refer to the [best practices section](https://ranchermanager.docs.rancher.com/pages-for-subheaders/best-practices).
|
||||
|
||||
## Installing Rancher
|
||||
|
||||
For production environments, we recommend installing Rancher in a [high-availability Kubernetes installation](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/kubernetes-cluster-setup/high-availability-installs) so that your user base can always access Rancher Server. When installed in a Kubernetes cluster, Rancher will integrate with the cluster’s etcd database and take advantage of Kubernetes scheduling for high-availability.
|
||||
|
||||
Optional: Installing Rancher on a [Single-node](https://ranchermanager.docs.rancher.com/pages-for-subheaders/rancher-on-a-single-node-with-docker) Kubernetes Cluster
|
||||
|
||||
#### Add the Helm Chart Repository
|
||||
|
||||
Use [helm repo add](https://helm.sh/docs/helm/helm_repo_add/) command to add the Helm chart repository that contains charts to install Rancher. For more information about the repository choices and which is best for your use case, see Choosing a Version of Rancher.
|
||||
|
||||
```bash
|
||||
helm repo add rancher-latest https://releases.rancher.com/server-charts/latest
|
||||
```
|
||||
|
||||
#### Create a Namespace for Rancher
|
||||
|
||||
We’ll need to define a Kubernetes namespace where the resources created by the Chart should be installed. This should always be cattle-system:
|
||||
|
||||
```bash
|
||||
kubectl create namespace cattle-system
|
||||
```
|
||||
|
||||
#### Choose your SSL Configuration
|
||||
|
||||
The Rancher management server is designed to be secure by default and requires SSL/TLS configuration.
|
||||
|
||||
There are three recommended options for the source of the certificate used for TLS termination at the Rancher server:
|
||||
|
||||
- [Rancher-generated TLS certificate](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#3-choose-your-ssl-configuration)
|
||||
- [Let’s Encrypt](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#3-choose-your-ssl-configuration)
|
||||
- [Bring your own certificate](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#3-choose-your-ssl-configuration)
|
||||
|
||||
#### Install cert-manager
|
||||
|
||||
This step is only required to use certificates issued by Rancher’s generated CA **`(ingress.tls.source=rancher)`** or to request Let’s Encrypt issued certificates **`(ingress.tls.source=letsEncrypt)`**.
|
||||
|
||||
[These instructions are adapted from the official cert-manager documentation.](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#4-install-cert-manager)
|
||||
|
||||
#### Install Rancher with Helm and Your Chosen Certificate Option
|
||||
|
||||
- [Rancher to generated certificates](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#5-install-rancher-with-helm-and-your-chosen-certificate-option)
|
||||
```bash
|
||||
helm install rancher rancher-latest/rancher \
|
||||
--namespace cattle-system \
|
||||
--set hostname=rancher.my.org
|
||||
```
|
||||
|
||||
- [Let’s Encrypt](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#5-install-rancher-with-helm-and-your-chosen-certificate-option)
|
||||
|
||||
```bash
|
||||
helm install rancher rancher-latest/rancher \
|
||||
--namespace cattle-system \
|
||||
--set hostname=rancher.my.org \
|
||||
--set ingress.tls.source=letsEncrypt \
|
||||
--set letsEncrypt.email=me@example.org
|
||||
```
|
||||
|
||||
- [Certificates from Files](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#5-install-rancher-with-helm-and-your-chosen-certificate-option)
|
||||
|
||||
```bash
|
||||
helm install rancher rancher-latest/rancher \
|
||||
--namespace cattle-system \
|
||||
--set hostname=rancher.my.org \
|
||||
--set ingress.tls.source=secret
|
||||
```
|
||||
|
||||
*If you are using a Private CA signed certificate , add **--set privateCA=true** to the command:`*
|
||||
|
||||
```bash
|
||||
helm install rancher rancher-latest/rancher \
|
||||
--namespace cattle-system \
|
||||
--set hostname=rancher.my.org \
|
||||
--set ingress.tls.source=secret \
|
||||
--set privateCA=true
|
||||
```
|
||||
|
||||
#### Verify that the Rancher Server is Successfully Deployed
|
||||
|
||||
After adding the secrets, check if Rancher was rolled out successfully:
|
||||
|
||||
```bash
|
||||
kubectl -n cattle-system rollout status deploy/rancher
|
||||
Waiting for deployment "rancher" rollout to finish: 0 of 3 updated replicas are available...
|
||||
deployment "rancher" successfully rolled out
|
||||
```
|
||||
|
||||
If you see the following **`error: error: deployment "rancher" exceeded its progress deadline`**, you can check the status of the deployment by running the following command:
|
||||
|
||||
```bash
|
||||
kubectl -n cattle-system get deploy rancher
|
||||
NAME DESIRED CURRENT UP-TO-DATE AVAILABLE AGE
|
||||
rancher 3 3 3 3 3m
|
||||
```
|
||||
|
||||
It should show the same count for **`DESIRED`** and **`AVAILABLE`**.
|
||||
|
||||
#### Save Your Options
|
||||
|
||||
Make sure you save the **`--set`** options you used. You will need to use the same options when you upgrade Rancher to new versions with Helm.
|
||||
|
||||
#### Finishing Up
|
||||
|
||||
That’s it. You should have a functional Rancher server.
|
||||
|
||||
In a web browser, go to the DNS name that forwards traffic to your load balancer. Then you should be greeted by the colorful login page.
|
||||
|
||||
Doesn’t work? Take a look at the [Troubleshooting Page](https://ranchermanager.docs.rancher.com/troubleshooting/general-troubleshooting)
|
||||
|
||||
***All of these instructions are defined in detailed in the [Rancher Documentation](https://ranchermanager.docs.rancher.com/pages-for-subheaders/install-upgrade-on-a-kubernetes-cluster#install-the-rancher-helm-chart).***
|
||||
|
||||
### Helm Chart Options for Kubernetes Installations
|
||||
|
||||
The full [Helm Chart Options](https://ranchermanager.docs.rancher.com/getting-started/installation-and-upgrade/installation-references/helm-chart-options) can be found here.
|
||||
|
||||
Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`.
|
||||
|
||||
#### Common Options
|
||||
|
||||
| Parameter | Default Value | Description |
|
||||
| ------------------------- | ------------- | -------------------------------------------------------------------------------------------- |
|
||||
| `hostname` | " " | ***string*** - the Fully Qualified Domain Name for your Rancher Server |
|
||||
| `ingress.tls.source` | "rancher" | ***string*** - Where to get the cert for the ingress. - "***rancher, letsEncrypt, secret***" |
|
||||
| `letsEncrypt.email` | " " | ***string*** - Your email address |
|
||||
| `letsEncrypt.environment` | "production" | ***string*** - Valid options: "***staging, production***" |
|
||||
| `privateCA` | false | ***bool*** - Set to true if your cert is signed by a private CA |
|
||||
|
||||
#### Advanced Options
|
||||
|
||||
| Parameter | Default Value | Description |
|
||||
| ---------------------------------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `additionalTrustedCAs` | false | ***bool*** - [See Additional Trusted CAs Server](https://ranchermanager.docs.rancher.com/getting-started/installation-and-upgrade/installation-references/helm-chart-options#additional-trusted-cas) |
|
||||
| `addLocal` | "true" | ***string*** - As of Rancher v2.5.0 this flag is deprecated and must be set to "true" |
|
||||
| `antiAffinity` | "preferred" | ***string*** - AntiAffinity rule for Rancher pods - *"preferred, required"* |
|
||||
| `replicas` | 3 | ***int*** - Number of replicas of Rancher pods |
|
||||
| `auditLog.destination` | "sidecar" | ***string*** - Stream to sidecar container console or hostPath volume - *"sidecar, hostPath"* |
|
||||
| `auditLog.hostPath` | "/var/log/rancher/audit" | ***string*** - log file destination on host (only applies when **auditLog.destination** is set to **hostPath**) |
|
||||
| `auditLog.level` | 0 | ***int*** - set the [API Audit Log level](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log#audit-log-levels). 0 is off. [0-3] |
|
||||
| `auditLog.maxAge` | 1 | ***int*** - maximum number of days to retain old audit log files (only applies when **auditLog.destination** is set to **hostPath**) |
|
||||
| `auditLog.maxBackup` | 1 | int - maximum number of audit log files to retain (only applies when **auditLog.destination** is set to **hostPath**) |
|
||||
| `auditLog.maxSize` | 100 | ***int*** - maximum size in megabytes of the audit log file before it gets rotated (only applies when **auditLog.destination** is set to **hostPath**) |
|
||||
| `auditLog.image.repository` | "rancher/mirrored-bci-micro" | ***string*** - Location for the image used to collect audit logs *Note: Available as of v2.7.0* |
|
||||
| `auditLog.image.tag` | "15.4.14.3" | ***string*** - Tag for the image used to collect audit logs *Note: Available as of v2.7.0* |
|
||||
| `auditLog.image.pullPolicy` | "IfNotPresent" | ***string*** - Override imagePullPolicy for auditLog images - *"Always", "Never", "IfNotPresent"* *Note: Available as of v2.7.0* |
|
||||
| `busyboxImage` | "" | ***string*** - *Deprecated `auditlog.image.repository` should be used to control auditing sidecar image.* Image location for busybox image used to collect audit logs *Note: Available as of v2.2.0, and Deprecated as of v2.7.0* |
|
||||
| `busyboxImagePullPolicy` | "IfNotPresent" | ***string*** - - *Deprecated `auditlog.image.pullPolicy` should be used to control auditing sidecar image.* Override imagePullPolicy for busybox images - *"Always", "Never", "IfNotPresent"* *Deprecated as of v2.7.0* |
|
||||
| `debug` | false | ***bool*** - set debug flag on rancher server |
|
||||
| `certmanager.version` | " " | ***string*** - set cert-manager compatibility |
|
||||
| `extraEnv` | [] | ***list*** - set additional environment variables for Rancher Note: *Available as of v2.2.0* |
|
||||
| `imagePullSecrets` | [] | ***list*** - list of names of Secret resource containing private registry credentials |
|
||||
| `ingress.enabled` | true | ***bool*** - install ingress resource |
|
||||
| `ingress.ingressClassName` | " " | ***string*** - class name of ingress if not set manually or by the ingress controller's defaults |
|
||||
| `ingress.includeDefaultExtraAnnotations` | true | ***bool*** - Add default nginx annotations |
|
||||
| `ingress.extraAnnotations` | {} | ***map*** - additional annotations to customize the ingress |
|
||||
| `ingress.configurationSnippet` | " " | ***string*** - Add additional Nginx configuration. Can be used for proxy configuration. Note: *Available as of v2.0.15, v2.1.10 and v2.2.4* |
|
||||
| `service.annotations` | {} | ***map*** - annotations to customize the service |
|
||||
| `service.type` | " " | ***string*** - Override the type used for the service - *"NodePort", "LoadBalancer", "ClusterIP"* |
|
||||
| `letsEncrypt.ingress.class` | " " | ***string*** - optional ingress class for the cert-manager acmesolver ingress that responds to the Let’s *Encrypt ACME challenges* |
|
||||
| `proxy` | " " | ***string** - HTTP[S] proxy server for Rancher |
|
||||
| `noProxy` | "127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.svc,.cluster.local" | ***string*** - comma separated list of hostnames or ip address not to use the proxy |
|
||||
| `resources` | {} | ***map*** - rancher pod resource requests & limits |
|
||||
| `rancherImage` | "rancher/rancher" | ***string*** - rancher image source |
|
||||
| `rancherImageTag` | same as chart version | ***string*** - rancher/rancher image tag |
|
||||
| `rancherImagePullPolicy` | "IfNotPresent" | ***string*** - Override imagePullPolicy for rancher server images - *"Always", "Never", "IfNotPresent"* |
|
||||
| `tls` | "ingress" | ***string*** - See External TLS Termination for details. - *"ingress, external"* |
|
||||
| `systemDefaultRegistry` | "" | ***string*** - private registry to be used for all system Docker images, e.g., [http://registry.example.com/] *Available as of v2.3.0* |
|
||||
| `useBundledSystemChart` | false | ***bool*** - select to use the system-charts packaged with Rancher server. This option is used for air gapped installations. *Available as of v2.3.0* |
|
||||
| `customLogos.enabled` | false | ***bool*** - Enabled [Ember Rancher UI (cluster manager) custom logos](https://github.com/rancher/ui/tree/master/public/assets/images/logos) and [Vue Rancher UI (cluster explorer) custom logos](https://github.com/rancher/dashboard/tree/master/shell/assets/images/pl) persistence volume |
|
||||
| `customLogos.volumeSubpaths.emberUi` | "ember" | ***string*** - Volume subpath for [Ember Rancher UI (cluster manager) custom logos](https://github.com/rancher/ui/tree/master/public/assets/images/logos) persistence |
|
||||
| `customLogos.volumeSubpaths.vueUi` | "vue" | ***string*** - Volume subpath for [Vue Rancher UI (cluster explorer) custom logos](https://github.com/rancher/dashboard/tree/master/shell/assets/images/pl) persistence |
|
||||
| `customLogos.volumeName` | "" | ***string*** - Use an existing volume. Custom logos should be copied to the proper `volume/subpath` folder by the user. Optional for persistentVolumeClaim, required for configMap |
|
||||
| `customLogos.storageClass` | "" | ***string*** - Set custom logos persistentVolumeClaim storage class. Required for dynamic pv |
|
||||
| `customLogos.accessMode` | "ReadWriteOnce" | ***string*** - Set custom persistentVolumeClaim access mode |
|
||||
| `customLogos.size` | "1Gi" | ***string*** - Set custom persistentVolumeClaim size |
|
||||
@@ -0,0 +1,43 @@
|
||||
## 오프라인 환경에서 rancher의 기본 registry 설정
|
||||
# systemDefaultRegistry: paasup.io
|
||||
# rancherImage: paasup.io/rancher/rancher
|
||||
|
||||
## ingress 설정
|
||||
hostname: rancher.example.org
|
||||
ingress:
|
||||
enable: true
|
||||
tls:
|
||||
source: secret
|
||||
secretName: rancher-tls-ingress
|
||||
extraAnnotations:
|
||||
konghq.com/connect-timeout: "30000"
|
||||
konghq.com/read-timeout: "1800000"
|
||||
konghq.com/write-timeout: "1800000"
|
||||
# cert-manager 사용시
|
||||
cert-manager.io/cluster-issuer: "selfsigned-issuer"
|
||||
cert-manager.io/duration: 8760h
|
||||
cert-manager.io/renew-before: 720h
|
||||
|
||||
|
||||
# 사설 인증서 사용시 true
|
||||
privateCA: true
|
||||
|
||||
replicas: 1
|
||||
|
||||
tolerations: []
|
||||
|
||||
nodeSelector: {}
|
||||
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 500Mi
|
||||
limits:
|
||||
cpu: 1000m
|
||||
memory: 1000Mi
|
||||
|
||||
extraEnv:
|
||||
- name: TZ
|
||||
value: Asia/Seoul
|
||||
|
||||
preinstallHook: true
|
||||
@@ -0,0 +1,30 @@
|
||||
# Rancher 삭제 후처리 스크립트
|
||||
|
||||
- 해당 문서는 rancher 삭제 이후 지워지지 않은 리소스를 삭제하기 위해 실행해야 할 스크립트에 대한 설명이다.
|
||||
|
||||
### 필요 사항
|
||||
|
||||
- 관리자 권한을 가지고 kubectl 실행.
|
||||
|
||||
### 실행 방법
|
||||
|
||||
``` sh
|
||||
# 1. post-delete-hook.sh 실행
|
||||
## RANCHER_NAMESPACE에 rancher가 배포된 namespace를 설정
|
||||
export RANCHER_NAMESPACE="rancher"
|
||||
export NAMESPACES="cattle-fleet-system cattle-system rancher-operator-system"
|
||||
export TIMEOUT="120"
|
||||
export IGNORETIMEOUTERROR="false"
|
||||
./post-delete-hook.sh
|
||||
|
||||
# 2. cleanup-rancher.sh
|
||||
./cleanup-rancher.sh
|
||||
Do you want to continue (y/n)? y
|
||||
```
|
||||
|
||||
### 스크립트 설명
|
||||
#### 1) post-delete-hook.sh
|
||||
- rancher 사용 중 생성한 app 삭제, helm 배포 중 생성한 리소스 삭제 등의 작업을 진행한다.
|
||||
|
||||
#### 2) cleanup-rancher
|
||||
- rancher가 실행하며 생성한 CRD와 Namespace를 삭제한다.
|
||||
@@ -0,0 +1,452 @@
|
||||
#!/bin/bash
|
||||
# Overridden on package
|
||||
SCRIPT_VERSION="unreleased"
|
||||
echo "Running cleanup.sh version ${SCRIPT_VERSION}"
|
||||
|
||||
# Warning
|
||||
echo "==================== WARNING ===================="
|
||||
echo "THIS WILL DELETE ALL RESOURCES CREATED BY RANCHER"
|
||||
echo "MAKE SURE YOU HAVE CREATED AND TESTED YOUR BACKUPS"
|
||||
echo "THIS IS A NON REVERSIBLE ACTION"
|
||||
echo "==================== WARNING ===================="
|
||||
|
||||
# Linux only for now
|
||||
if [ "$(uname -s)" != "Linux" ]; then
|
||||
echo "Must be run on Linux"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check kubectl existence
|
||||
if ! type kubectl >/dev/null 2>&1; then
|
||||
echo "kubectl not found in PATH, make sure kubectl is available"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check timeout existence
|
||||
if ! type timeout >/dev/null 2>&1; then
|
||||
echo "timeout not found in PATH, make sure timeout is available"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
|
||||
# Test connectivity
|
||||
if ! kubectl get nodes >/dev/null 2>&1; then
|
||||
echo "'kubectl get nodes' exited non-zero, make sure environment variable KUBECONFIG is set to a working kubeconfig file"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "=> Printing cluster info for confirmation"
|
||||
kubectl cluster-info
|
||||
kubectl get nodes -o wide
|
||||
|
||||
if [ "$1" != "force" ]; then
|
||||
echo "Do you want to continue (y/n)?"
|
||||
read -r answer
|
||||
|
||||
if [ "$answer" != "y" ]; then
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
kcd()
|
||||
{
|
||||
i="0"
|
||||
while [ $i -lt 4 ]; do
|
||||
if timeout 21 sh -c 'kubectl delete --ignore-not-found=true --grace-period=15 --timeout=20s '"$*"''; then
|
||||
break
|
||||
fi
|
||||
i=$((i+1))
|
||||
done
|
||||
}
|
||||
|
||||
kcpf()
|
||||
{
|
||||
FINALIZERS=$(kubectl get -o jsonpath="{.metadata.finalizers}" "$@")
|
||||
if [ "x${FINALIZERS}" != "x" ]; then
|
||||
echo "Finalizers before for ${*}: ${FINALIZERS}"
|
||||
kubectl patch -p '{"metadata":{"finalizers":null}}' --type=merge "$@"
|
||||
echo "Finalizers after for ${*}: $(kubectl get -o jsonpath="{.metadata.finalizers}" "${@}")"
|
||||
fi
|
||||
}
|
||||
|
||||
kcdns()
|
||||
{
|
||||
if kubectl get namespace "$1"; then
|
||||
kcpf namespace "$1"
|
||||
FINALIZERS=$(kubectl get -o jsonpath="{.spec.finalizers}" namespace "$1")
|
||||
if [ "x${FINALIZERS}" != "x" ]; then
|
||||
echo "Finalizers before for namespace ${1}: ${FINALIZERS}"
|
||||
kubectl get -o json namespace "$1" | tr -d "\n" | sed "s/\"finalizers\": \[[^]]\+\]/\"finalizers\": []/" | kubectl replace --raw /api/v1/namespaces/$1/finalize -f -
|
||||
echo "Finalizers after for namespace ${1}: $(kubectl get -o jsonpath="{.spec.finalizers}" namespace ${1})"
|
||||
fi
|
||||
i="0"
|
||||
while [ $i -lt 4 ]; do
|
||||
if timeout 21 sh -c 'kubectl delete --ignore-not-found=true --grace-period=15 --timeout=20s namespace '"$1"''; then
|
||||
break
|
||||
fi
|
||||
i=$((i+1))
|
||||
done
|
||||
fi
|
||||
}
|
||||
|
||||
printapiversion()
|
||||
{
|
||||
if echo "$1" | grep -q '/'; then
|
||||
echo "$1" | cut -d'/' -f1
|
||||
else
|
||||
echo ""
|
||||
fi
|
||||
}
|
||||
|
||||
set -x
|
||||
# Namespaces with resources that probably have finalizers/dependencies (needs manual traverse to patch and delete else it will hang)
|
||||
CATTLE_NAMESPACES="local cattle-system cattle-impersonation-system cattle-global-data cattle-global-nt cattle-provisioning-capi-system cattle-ui-plugin-system"
|
||||
TOOLS_NAMESPACES="istio-system cattle-resources-system cis-operator-system cattle-dashboards cattle-gatekeeper-system cattle-alerting cattle-logging cattle-pipeline cattle-prometheus rancher-operator-system cattle-monitoring-system cattle-logging-system cattle-elemental-system"
|
||||
FLEET_NAMESPACES="cattle-fleet-clusters-system cattle-fleet-local-system cattle-fleet-system fleet-default fleet-local fleet-system"
|
||||
|
||||
# Delete rancher install to not have anything running that (re)creates resources
|
||||
kcd "-n cattle-system deploy,ds --all"
|
||||
kubectl -n cattle-system wait --for delete pod --selector=app=rancher
|
||||
# Delete the only resource not in cattle namespaces
|
||||
kcd "-n kube-system configmap cattle-controllers"
|
||||
|
||||
# Delete any blocking webhooks from preventing requests
|
||||
if kubectl get mutatingwebhookconfigurations -o name | grep -q cattle\.io; then
|
||||
kcd "$(kubectl get mutatingwebhookconfigurations -o name | grep cattle\.io)"
|
||||
fi
|
||||
if kubectl get validatingwebhookconfigurations -o name | grep -q cattle\.io; then
|
||||
kcd "$(kubectl get validatingwebhookconfigurations -o name | grep cattle\.io)"
|
||||
fi
|
||||
|
||||
# Delete any monitoring webhooks
|
||||
if kubectl get mutatingwebhookconfigurations -o name | grep -q rancher-monitoring; then
|
||||
kcd "$(kubectl get mutatingwebhookconfigurations -o name | grep rancher-monitoring)"
|
||||
fi
|
||||
if kubectl get validatingwebhookconfigurations -o name | grep -q rancher-monitoring; then
|
||||
kcd "$(kubectl get validatingwebhookconfigurations -o name | grep rancher-monitoring)"
|
||||
fi
|
||||
# Delete any gatekeeper webhooks
|
||||
if kubectl get validatingwebhookconfigurations -o name | grep -q gatekeeper; then
|
||||
kcd "$(kubectl get validatingwebhookconfigurations -o name | grep gatekeeper)"
|
||||
fi
|
||||
|
||||
# Delete any istio webhooks
|
||||
if kubectl get mutatingwebhookconfigurations -o name | grep -q istio; then
|
||||
kcd "$(kubectl get mutatingwebhookconfigurations -o name | grep istio)"
|
||||
fi
|
||||
if kubectl get validatingwebhookconfigurations -o name | grep -q istio; then
|
||||
kcd "$(kubectl get validatingwebhookconfigurations -o name | grep istio)"
|
||||
fi
|
||||
|
||||
# Cluster api
|
||||
if [ -n "$(kubectl get validatingwebhookconfiguration.admissionregistration.k8s.io/validating-webhook-configuration)" ]; then
|
||||
kcd validatingwebhookconfiguration.admissionregistration.k8s.io/validating-webhook-configuration
|
||||
fi
|
||||
if [ -n "$(kubectl get mutatingwebhookconfiguration.admissionregistration.k8s.io/mutating-webhook-configuration)" ]; then
|
||||
kcd mutatingwebhookconfiguration.admissionregistration.k8s.io/mutating-webhook-configuration
|
||||
fi
|
||||
|
||||
# Delete generic k8s resources either labeled with norman or resource name starting with "cattle|rancher|fleet"
|
||||
# ClusterRole/ClusterRoleBinding
|
||||
kubectl get clusterrolebinding -l cattle.io/creator=norman --no-headers -o custom-columns=NAME:.metadata.name | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^cattle- | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep rancher | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^fleet- | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^gitjob | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^pod-impersonation-helm- | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^gatekeeper | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^cis | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^istio | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterrolebinding --no-headers -o custom-columns=NAME:.metadata.name | grep ^elemental | while read -r CRB; do
|
||||
kcpf clusterrolebindings "$CRB"
|
||||
kcd "clusterrolebindings ""$CRB"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles -l cattle.io/creator=norman --no-headers -o custom-columns=NAME:.metadata.name | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^cattle- | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep rancher | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^fleet | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^gitjob | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^pod-impersonation-helm | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^logging- | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^monitoring- | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^gatekeeper | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^cis | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^istio | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
kubectl get clusterroles --no-headers -o custom-columns=NAME:.metadata.name | grep ^elemental | while read -r CR; do
|
||||
kcpf clusterroles "$CR"
|
||||
kcd "clusterroles ""$CR"""
|
||||
done
|
||||
|
||||
# Bulk delete data CRDs
|
||||
# Saves time in the loop below where we patch/delete individual resources
|
||||
DATACRDS="settings.management.cattle.io authconfigs.management.cattle.io features.management.cattle.io rkeaddons.management.cattle.io rkek8sserviceoptions.management.cattle.io rkek8ssystemimages.management.cattle.io catalogtemplateversions.management.cattle.io catalogtemplates.management.cattle.io rkeaddons.management.cattle.io tokens.management.cattle.io elemental.cattle.io"
|
||||
for CRD in $DATACRDS; do
|
||||
kcd "crd $CRD"
|
||||
done
|
||||
|
||||
# Delete apiservice
|
||||
for APISERVICE in $(kubectl get apiservice -o name | grep cattle | grep -v k3s\.cattle\.io | grep -v helm\.cattle\.io) $(kubectl get apiservice -o name | grep gatekeeper\.sh) $(kubectl get apiservice -o name | grep istio\.io) $(kubectl get apiservice elemental-operator) apiservice\.apiregistration\.k8s\.io\/v1beta1\.custom\.metrics\.k8s\.io; do
|
||||
kcd "$APISERVICE"
|
||||
done
|
||||
|
||||
# Pod security policies
|
||||
#Check if psps are available on the target cluster
|
||||
kubectl get podsecuritypolicy > /dev/null 2>&1
|
||||
|
||||
# Check the exit code and only run if there are psps available on the cluster
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "Removing PSPs"
|
||||
|
||||
# Rancher logging
|
||||
for PSP in $(kubectl get podsecuritypolicy -o name -l app.kubernetes.io/name=rancher-logging) podsecuritypolicy.policy/rancher-logging-rke-aggregator; do
|
||||
kcd "$PSP"
|
||||
done
|
||||
|
||||
# Rancher monitoring
|
||||
for PSP in $(kubectl get podsecuritypolicy -o name -l release=rancher-monitoring) $(kubectl get podsecuritypolicy -o name -l app=rancher-monitoring-crd-manager) $(kubectl get podsecuritypolicy -o name -l app=rancher-monitoring-patch-sa) $(kubectl get podsecuritypolicy -o name -l app.kubernetes.io/instance=rancher-monitoring); do
|
||||
kcd "$PSP"
|
||||
done
|
||||
|
||||
# Rancher OPA
|
||||
for PSP in $(kubectl get podsecuritypolicy -o name -l release=rancher-gatekeeper) $(kubectl get podsecuritypolicy -o name -l app=rancher-gatekeeper-crd-manager); do
|
||||
kcd "$PSP"
|
||||
done
|
||||
|
||||
# Backup restore operator
|
||||
for PSP in $(kubectl get podsecuritypolicy -o name -l app.kubernetes.io/name=rancher-backup); do
|
||||
kcd "$PSP"
|
||||
done
|
||||
|
||||
# Istio
|
||||
for PSP in istio-installer istio-psp kiali-psp psp-istio-cni; do
|
||||
kcd "podsecuritypolicy $PSP"
|
||||
done
|
||||
else
|
||||
echo "Kubernetes version v1.25 or higher, skipping PSP removal"
|
||||
fi
|
||||
|
||||
# Get all namespaced resources and delete in loop
|
||||
# Exclude helm.cattle.io and k3s.cattle.io to not break K3S/RKE2 addons
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep cattle\.io | grep -v helm\.cattle\.io | grep -v k3s\.cattle\.io | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
# Logging
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep logging\.banzaicloud\.io | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name | grep -v events\.events\.k8s\.io | grep -v ^events$ | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | grep rancher-monitoring | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
# Monitoring
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep monitoring\.coreos\.com | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
# Gatekeeper
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep gatekeeper\.sh | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
# Cluster-api
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep cluster\.x-k8s\.io | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
# Get all non-namespaced resources and delete in loop
|
||||
kubectl get "$(kubectl api-resources --namespaced=false --verbs=delete -o name| grep cattle\.io | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o name | while read -r NAME; do
|
||||
kcpf "$NAME"
|
||||
kcd "$NAME"
|
||||
done
|
||||
|
||||
# Logging
|
||||
kubectl get "$(kubectl api-resources --namespaced=false --verbs=delete -o name| grep logging\.banzaicloud\.io | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o name | while read -r NAME; do
|
||||
kcpf "$NAME"
|
||||
kcd "$NAME"
|
||||
done
|
||||
|
||||
# Gatekeeper
|
||||
kubectl get "$(kubectl api-resources --namespaced=false --verbs=delete -o name| grep gatekeeper\.sh | tr "\n" "," | sed -e 's/,$//')" -A --no-headers -o name | while read -r NAME; do
|
||||
kcpf "$NAME"
|
||||
kcd "$NAME"
|
||||
done
|
||||
|
||||
# Delete istio certs
|
||||
for NS in $(kubectl get ns --no-headers -o custom-columns=NAME:.metadata.name); do
|
||||
kcd "-n ${NS} configmap istio-ca-root-cert"
|
||||
done
|
||||
|
||||
# Delete all cattle namespaces, including project namespaces (p-),cluster (c-),cluster-fleet and user (user-) namespaces
|
||||
for NS in $TOOLS_NAMESPACES $FLEET_NAMESPACES $CATTLE_NAMESPACES; do
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep -v events\.events\.k8s\.io | grep -v ^events$ | tr "\n" "," | sed -e 's/,$//')" -n "$NS" --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
kcdns "$NS"
|
||||
done
|
||||
|
||||
for NS in $(kubectl get namespace --no-headers -o custom-columns=NAME:.metadata.name | grep "^cluster-fleet"); do
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep -v events\.events\.k8s\.io | grep -v ^events$ | tr "\n" "," | sed -e 's/,$//')" -n "$NS" --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
kcdns "$NS"
|
||||
done
|
||||
|
||||
for NS in $(kubectl get namespace --no-headers -o custom-columns=NAME:.metadata.name | grep "^p-"); do
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep -v events\.events\.k8s\.io | grep -v ^events$ | tr "\n" "," | sed -e 's/,$//')" -n "$NS" --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
kcdns "$NS"
|
||||
done
|
||||
|
||||
for NS in $(kubectl get namespace --no-headers -o custom-columns=NAME:.metadata.name | grep "^c-"); do
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep -v events\.events\.k8s\.io | grep -v ^events$ | tr "\n" "," | sed -e 's/,$//')" -n "$NS" --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
kcdns "$NS"
|
||||
done
|
||||
|
||||
for NS in $(kubectl get namespace --no-headers -o custom-columns=NAME:.metadata.name | grep "^user-"); do
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep -v events\.events\.k8s\.io | grep -v ^events$ | tr "\n" "," | sed -e 's/,$//')" -n "$NS" --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
kcdns "$NS"
|
||||
done
|
||||
|
||||
for NS in $(kubectl get namespace --no-headers -o custom-columns=NAME:.metadata.name | grep "^u-"); do
|
||||
kubectl get "$(kubectl api-resources --namespaced=true --verbs=delete -o name| grep -v events\.events\.k8s\.io | grep -v ^events$ | tr "\n" "," | sed -e 's/,$//')" -n "$NS" --no-headers -o custom-columns=NAME:.metadata.name,NAMESPACE:.metadata.namespace,KIND:.kind,APIVERSION:.apiVersion | while read -r NAME NAMESPACE KIND APIVERSION; do
|
||||
kcpf -n "$NAMESPACE" "${KIND}.$(printapiversion "$APIVERSION")" "$NAME"
|
||||
kcd "-n ""$NAMESPACE"" ${KIND}.$(printapiversion "$APIVERSION") ""$NAME"""
|
||||
done
|
||||
|
||||
kcdns "$NS"
|
||||
done
|
||||
|
||||
# Delete logging CRDs
|
||||
for CRD in $(kubectl get crd -o name | grep logging\.banzaicloud\.io); do
|
||||
kcd "$CRD"
|
||||
done
|
||||
|
||||
# Delete monitoring CRDs
|
||||
for CRD in $(kubectl get crd -o name | grep monitoring\.coreos\.com); do
|
||||
kcd "$CRD"
|
||||
done
|
||||
|
||||
# Delete OPA CRDs
|
||||
for CRD in $(kubectl get crd -o name | grep gatekeeper\.sh); do
|
||||
kcd "$CRD"
|
||||
done
|
||||
|
||||
# Delete Istio CRDs
|
||||
for CRD in $(kubectl get crd -o name | grep istio\.io); do
|
||||
kcd "$CRD"
|
||||
done
|
||||
|
||||
# Delete cluster-api CRDs
|
||||
for CRD in $(kubectl get crd -o name | grep cluster\.x-k8s\.io); do
|
||||
kcd "$CRD"
|
||||
done
|
||||
|
||||
# Delete all cattle CRDs
|
||||
# Exclude helm.cattle.io and addons.k3s.cattle.io to not break RKE2 addons
|
||||
for CRD in $(kubectl get crd -o name | grep cattle\.io | grep -v helm\.cattle\.io | grep -v k3s\.cattle\.io); do
|
||||
kcd "$CRD"
|
||||
done
|
||||
@@ -0,0 +1,119 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
namespaces="${NAMESPACES}"
|
||||
rancher_namespace="${RANCHER_NAMESPACE}"
|
||||
timeout="${TIMEOUT}"
|
||||
ignoreTimeoutError="${IGNORETIMEOUTERROR}"
|
||||
|
||||
if [[ -z ${namespaces} ]]; then
|
||||
echo "No namespace is provided."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ -z ${rancher_namespace} ]]; then
|
||||
echo "No rancher namespace is provided."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ -z ${timeout} ]]; then
|
||||
echo "No timeout value is provided."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [[ -z ${ignoreTimeoutError} ]]; then
|
||||
echo "No ignoreTimeoutError value is provided."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
succeeded=()
|
||||
failed=()
|
||||
|
||||
get_pod_count() {
|
||||
kubectl get pods --selector app="${1}" -n "${2}" -o json | jq '.items | length'
|
||||
}
|
||||
|
||||
echo "Uninstalling Rancher resources in the following namespaces: ${namespaces}"
|
||||
|
||||
for namespace in ${namespaces}; do
|
||||
for app in $(helm list -n "${namespace}" -q); do
|
||||
if [[ ${app} =~ .crd$ ]]; then
|
||||
echo "--- Skip the app [${app}] in the namespace [${namespace}]"
|
||||
continue
|
||||
fi
|
||||
echo "--- Deleting the app [${app}] in the namespace [${namespace}]"
|
||||
if [[ ! $(helm uninstall "${app}" -n "${namespace}") ]]; then
|
||||
failed=("${failed[@]}" "${app}")
|
||||
continue
|
||||
fi
|
||||
|
||||
t=0
|
||||
while true; do
|
||||
if [[ $(get_pod_count "${app}" "${namespace}") -eq 0 ]]; then
|
||||
echo "successfully uninstalled [${app}] in the namespace [${namespace}]"
|
||||
succeeded=("${succeeded[@]}" "${app}")
|
||||
break
|
||||
fi
|
||||
if [[ ${t} -ge ${timeout} ]]; then
|
||||
echo "timeout uninstalling [${app}] in the namespace [${namespace}]"
|
||||
failed=("${failed[@]}" "${app}")
|
||||
break
|
||||
fi
|
||||
# by default, wait 120 seconds in total for an app to be uninstalled
|
||||
echo "waiting 5 seconds for pods of [${app}] to be terminated ..."
|
||||
sleep 5
|
||||
t=$((t + 5))
|
||||
done
|
||||
done
|
||||
|
||||
# delete the helm operator pods
|
||||
for pod in $(kubectl get pods -n "${namespace}" -o name); do
|
||||
if [[ ${pod} =~ ^pod\/helm-operation-* ]]; then
|
||||
echo "--- Deleting the pod [${pod}] in the namespace [${namespace}]"
|
||||
kubectl delete "${pod}" -n "${namespace}"
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
echo "Removing Rancher bootstrap secret in the following namespace: ${rancher_namespace}"
|
||||
kubectl --ignore-not-found=true delete secret bootstrap-secret -n "${rancher_namespace}"
|
||||
kubectl --ignore-not-found=true delete secret tls-ca -n ${rancher_namespace}
|
||||
|
||||
echo "------ Summary ------"
|
||||
if [[ ${#succeeded[@]} -ne 0 ]]; then
|
||||
echo "Succeeded to uninstall the following apps:" "${succeeded[@]}"
|
||||
fi
|
||||
|
||||
if [[ ${#failed[@]} -ne 0 ]]; then
|
||||
echo "Failed to uninstall the following apps:" "${failed[@]}"
|
||||
if [[ "${ignoreTimeoutError}" == "false" ]]; then
|
||||
exit 2
|
||||
fi
|
||||
else
|
||||
echo "Cleanup finished successfully."
|
||||
fi
|
||||
|
||||
|
||||
for ns in $(kubectl get namespaces -o jsonpath='{.items[*].metadata.name}'); do
|
||||
# Remove finalizers from the namespace itself
|
||||
kubectl patch namespace "$ns" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
|
||||
# Remove finalizers from all roles in the namespace
|
||||
for role in $(kubectl get roles -n "$ns" -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch role "$role" -n "$ns" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
|
||||
# Remove finalizers from all rolebindings in the namespace
|
||||
for rolebinding in $(kubectl get rolebindings -n $ns -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch rolebinding "$rolebinding" -n "$ns" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
done
|
||||
|
||||
for cr in $(kubectl get clusterroles -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch clusterrole "$cr" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
|
||||
for crb in $(kubectl get clusterrolebindings -o jsonpath='{.items[*].metadata.name}'); do
|
||||
kubectl patch clusterrolebinding "$crb" -p '{"metadata":{"finalizers":[]}}' --type=merge
|
||||
done
|
||||
@@ -0,0 +1,22 @@
|
||||
Rancher Server has been installed.
|
||||
|
||||
NOTE: Rancher may take several minutes to fully initialize. Please standby while Certificates are being issued, Containers are started and the Ingress rule comes up.
|
||||
|
||||
Check out our docs at https://rancher.com/docs/
|
||||
|
||||
If you provided your own bootstrap password during installation, browse to https://{{ .Values.hostname }} to get started.
|
||||
|
||||
If this is the first time you installed Rancher, get started by running this command and clicking the URL it generates:
|
||||
|
||||
```
|
||||
echo https://{{ .Values.hostname }}/dashboard/?setup=$(kubectl get secret --namespace cattle-system bootstrap-secret -o go-template='{{ "{{" }}.data.bootstrapPassword|base64decode{{ "}}" }}')
|
||||
```
|
||||
|
||||
To get just the bootstrap password on its own, run:
|
||||
|
||||
```
|
||||
kubectl get secret --namespace cattle-system bootstrap-secret -o go-template='{{ "{{" }}.data.bootstrapPassword|base64decode{{ "}}" }}{{ "{{" }} "\n" {{ "}}" }}'
|
||||
```
|
||||
|
||||
|
||||
Happy Containering!
|
||||
@@ -0,0 +1,89 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "rancher.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
*/}}
|
||||
{{- define "rancher.fullname" -}}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||
{{- if contains $name .Release.Name -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified chart name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
*/}}
|
||||
{{- define "rancher.chartname" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Render Values in configurationSnippet
|
||||
*/}}
|
||||
{{- define "configurationSnippet" -}}
|
||||
{{- tpl (.Values.ingress.configurationSnippet) . | nindent 6 -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Generate the labels.
|
||||
*/}}
|
||||
{{- define "rancher.labels" -}}
|
||||
app: {{ template "rancher.fullname" . }}
|
||||
chart: {{ template "rancher.chartname" . }}
|
||||
heritage: {{ .Release.Service }}
|
||||
release: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
|
||||
# Windows Support
|
||||
|
||||
{{/*
|
||||
Windows cluster will add default taint for linux nodes,
|
||||
add below linux tolerations to workloads could be scheduled to those linux nodes
|
||||
*/}}
|
||||
|
||||
{{- define "linux-node-tolerations" -}}
|
||||
- key: "cattle.io/os"
|
||||
value: "linux"
|
||||
effect: "NoSchedule"
|
||||
operator: "Equal"
|
||||
{{- end -}}
|
||||
|
||||
{{- define "linux-node-selector-terms" -}}
|
||||
{{- $key := "kubernetes.io/os" -}}
|
||||
- matchExpressions:
|
||||
- key: {{ $key }}
|
||||
operator: NotIn
|
||||
values:
|
||||
- windows
|
||||
{{- end -}}
|
||||
|
||||
{{- define "system_default_registry" -}}
|
||||
{{- if .Values.systemDefaultRegistry -}}
|
||||
{{- if hasSuffix "/" .Values.systemDefaultRegistry -}}
|
||||
{{- printf "%s" .Values.systemDefaultRegistry -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s/" .Values.systemDefaultRegistry -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Select correct auditLog image
|
||||
*/}}
|
||||
{{- define "auditLog_image" -}}
|
||||
{{- if .Values.busyboxImage }}
|
||||
{{- .Values.busyboxImage}}
|
||||
{{- else }}
|
||||
{{- .Values.auditLog.image.repository -}}:{{- .Values.auditLog.image.tag -}}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,14 @@
|
||||
kind: ClusterRoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: ClusterRole
|
||||
name: cluster-admin
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: rancher-config
|
||||
labels: {{ include "rancher.labels" . | nindent 4 }}
|
||||
app.kubernetes.io/part-of: "rancher"
|
||||
data:
|
||||
priorityClassName: {{ .Values.priorityClassName }}
|
||||
{{- if and .Values.webhook (kindIs "string" .Values.webhook) }}
|
||||
rancher-webhook: {{ .Values.webhook | quote }}
|
||||
{{- else if .Values.webhook }}
|
||||
rancher-webhook: {{ toYaml .Values.webhook | quote }}
|
||||
{{- end }}
|
||||
{{- if and .Values.fleet (kindIs "string" .Values.fleet) }}
|
||||
fleet: {{ .Values.fleet | quote }}
|
||||
{{- else if .Values.fleet }}
|
||||
fleet: {{ toYaml .Values.fleet | quote }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,259 @@
|
||||
kind: Deployment
|
||||
apiVersion: apps/v1
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
annotations:
|
||||
{{- if (lt (int .Values.replicas) 0) }}
|
||||
management.cattle.io/scale-available: "{{ sub 0 (int .Values.replicas)}}"
|
||||
{{- end }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
spec:
|
||||
{{- if (gt (int .Values.replicas) 0) }}
|
||||
replicas: {{ .Values.replicas }}
|
||||
{{- end }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ template "rancher.fullname" . }}
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxSurge: 1
|
||||
{{- if (eq (int .Values.replicas) 1) }}
|
||||
maxUnavailable: 0
|
||||
{{- else }}
|
||||
maxUnavailable: 1
|
||||
{{- end }}
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ template "rancher.fullname" . }}
|
||||
release: {{ .Release.Name }}
|
||||
spec:
|
||||
priorityClassName: {{ .Values.priorityClassName }}
|
||||
serviceAccountName: {{ template "rancher.fullname" . }}
|
||||
{{- if .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{ toYaml .Values.imagePullSecrets | indent 6 }}
|
||||
{{- end }}
|
||||
affinity:
|
||||
podAntiAffinity:
|
||||
{{- if eq .Values.antiAffinity "required" }}
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
- labelSelector:
|
||||
matchExpressions:
|
||||
- key: app
|
||||
operator: In
|
||||
values:
|
||||
- {{ template "rancher.fullname" . }}
|
||||
topologyKey: {{ .Values.topologyKey | default "kubernetes.io/hostname" }}
|
||||
{{- else }}
|
||||
preferredDuringSchedulingIgnoredDuringExecution:
|
||||
- weight: 100
|
||||
podAffinityTerm:
|
||||
labelSelector:
|
||||
matchExpressions:
|
||||
- key: app
|
||||
operator: In
|
||||
values:
|
||||
- {{ template "rancher.fullname" . }}
|
||||
topologyKey: {{ .Values.topologyKey | default "kubernetes.io/hostname" }}
|
||||
{{- end }}
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms: {{ include "linux-node-selector-terms" . | nindent 14 }}
|
||||
tolerations: {{ include "linux-node-tolerations" . | nindent 8 }}
|
||||
{{- if .Values.extraTolerations }}
|
||||
{{ toYaml .Values.extraTolerations | indent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- image: {{ .Values.rancherImage }}:{{ default .Chart.AppVersion .Values.rancherImageTag }}
|
||||
imagePullPolicy: {{ default "IfNotPresent" .Values.rancherImagePullPolicy }}
|
||||
name: {{ template "rancher.name" . }}
|
||||
ports:
|
||||
- containerPort: 80
|
||||
protocol: TCP
|
||||
{{- if (and .Values.hostPort (gt (int .Values.hostPort) 0)) }}
|
||||
- containerPort: 444
|
||||
hostPort: {{ int .Values.hostPort }}
|
||||
protocol: TCP
|
||||
{{- end}}
|
||||
args:
|
||||
{{- if .Values.debug }}
|
||||
- "--debug"
|
||||
{{- end }}
|
||||
{{- if .Values.privateCA }}
|
||||
# Private CA - don't clear ca certs
|
||||
{{- else if and (eq .Values.tls "ingress") (eq .Values.ingress.tls.source "rancher") }}
|
||||
# Rancher self-signed - don't clear ca certs
|
||||
{{- else }}
|
||||
# Public trusted CA - clear ca certs
|
||||
- "--no-cacerts"
|
||||
{{- end }}
|
||||
- "--http-listen-port=80"
|
||||
- "--https-listen-port=443"
|
||||
- "--add-local={{ .Values.addLocal }}"
|
||||
env:
|
||||
- name: CATTLE_NAMESPACE
|
||||
value: {{ .Release.Namespace }}
|
||||
- name: CATTLE_PEER_SERVICE
|
||||
value: {{ template "rancher.fullname" . }}
|
||||
{{- if .Values.features }}
|
||||
- name: CATTLE_FEATURES
|
||||
value: "{{ .Values.features }}"
|
||||
{{- end}}
|
||||
{{- if .Values.noDefaultAdmin }}
|
||||
- name: CATTLE_NO_DEFAULT_ADMIN
|
||||
value: "{{ .Values.noDefaultAdmin }}"
|
||||
{{- end}}
|
||||
{{- if gt (int .Values.auditLog.level) 0 }}
|
||||
- name: AUDIT_LEVEL
|
||||
value: {{ .Values.auditLog.level | quote }}
|
||||
- name: AUDIT_LOG_MAXAGE
|
||||
value: {{ .Values.auditLog.maxAge | quote }}
|
||||
- name: AUDIT_LOG_MAXBACKUP
|
||||
value: {{ .Values.auditLog.maxBackup | quote }}
|
||||
- name: AUDIT_LOG_MAXSIZE
|
||||
value: {{ .Values.auditLog.maxSize | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.proxy }}
|
||||
- name: HTTP_PROXY
|
||||
value: {{ .Values.proxy }}
|
||||
- name: HTTPS_PROXY
|
||||
value: {{ .Values.proxy }}
|
||||
- name: NO_PROXY
|
||||
value: {{ .Values.noProxy }}
|
||||
{{- end }}
|
||||
{{- if .Values.systemDefaultRegistry }}
|
||||
- name: CATTLE_SYSTEM_DEFAULT_REGISTRY
|
||||
value: {{ .Values.systemDefaultRegistry }}
|
||||
{{- end }}
|
||||
{{- if .Values.useBundledSystemChart }}
|
||||
- name: CATTLE_SYSTEM_CATALOG
|
||||
value: bundled
|
||||
{{- end }}
|
||||
{{- if .Values.restrictedAdmin }}
|
||||
- name: CATTLE_RESTRICTED_DEFAULT_ADMIN
|
||||
value: "true"
|
||||
{{- end}}
|
||||
{{- if .Values.bootstrapPassword }}
|
||||
- name: CATTLE_BOOTSTRAP_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: "bootstrap-secret"
|
||||
key: "bootstrapPassword"
|
||||
{{- end }}
|
||||
{{- if .Values.agentTLSMode }}
|
||||
- name: CATTLE_AGENT_TLS_MODE
|
||||
value: "{{ .Values.agentTLSMode }}"
|
||||
{{- end }}
|
||||
{{- if .Values.extraEnv }}
|
||||
{{ toYaml .Values.extraEnv | indent 8}}
|
||||
{{- end }}
|
||||
startupProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: 80
|
||||
timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.startupProbe.failureThreshold }}
|
||||
periodSeconds: {{ .Values.startupProbe.periodSeconds }}
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: 80
|
||||
{{- with .Values.livenessProbe.initialDelaySeconds}}
|
||||
initialDelaySeconds: {{ . }}
|
||||
{{- end }}
|
||||
timeoutSeconds: {{.Values.livenessProbe.timeoutSeconds }}
|
||||
periodSeconds: {{ .Values.livenessProbe.periodSeconds }}
|
||||
failureThreshold: {{.Values.livenessProbe.failureThreshold }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: 80
|
||||
{{- with .Values.readinessProbe.initialDelaySeconds}}
|
||||
initialDelaySeconds: {{ . }}
|
||||
{{- end }}
|
||||
timeoutSeconds: {{.Values.readinessProbe.timeoutSeconds }}
|
||||
periodSeconds: {{ .Values.readinessProbe.periodSeconds }}
|
||||
failureThreshold: {{.Values.readinessProbe.failureThreshold }}
|
||||
resources:
|
||||
{{ toYaml .Values.resources | indent 10 }}
|
||||
volumeMounts:
|
||||
{{- if .Values.additionalTrustedCAs }}
|
||||
- mountPath: /etc/pki/trust/anchors/ca-additional.pem
|
||||
name: tls-ca-additional-volume
|
||||
subPath: ca-additional.pem
|
||||
readOnly: true
|
||||
- mountPath: /etc/rancher/ssl/ca-additional.pem
|
||||
name: tls-ca-additional-volume
|
||||
subPath: ca-additional.pem
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
{{- if .Values.privateCA }}
|
||||
# Pass CA cert into rancher for private CA
|
||||
- mountPath: /etc/rancher/ssl/cacerts.pem
|
||||
name: tls-ca-volume
|
||||
subPath: cacerts.pem
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
{{- if and .Values.customLogos.enabled (or (eq .Values.customLogos.volumeKind "persistentVolumeClaim") (and (eq .Values.customLogos.volumeKind "configMap") (.Values.customLogos.volumeName))) }}
|
||||
# Mount rancher custom-logos volume
|
||||
- mountPath: /usr/share/rancher/ui/assets/images/logos
|
||||
name: custom-logos
|
||||
subPath: {{ .Values.customLogos.volumeSubpaths.emberUi | default "ember" | quote }}
|
||||
- mountPath: /usr/share/rancher/ui-dashboard/dashboard/_nuxt/assets/images/pl
|
||||
name: custom-logos
|
||||
subPath: {{ .Values.customLogos.volumeSubpaths.vueUi | default "vue" | quote }}
|
||||
{{- end }}
|
||||
{{- if gt (int .Values.auditLog.level) 0 }}
|
||||
- mountPath: /var/log/auditlog
|
||||
name: audit-log
|
||||
{{- end }}
|
||||
{{- if eq .Values.auditLog.destination "sidecar" }}
|
||||
{{- if gt (int .Values.auditLog.level) 0 }}
|
||||
# Make audit logs available for Rancher log collector tools.
|
||||
- image: {{ include "auditLog_image" . }}
|
||||
imagePullPolicy: {{ default .Values.auditLog.image.pullPolicy .Values.busyboxImagePullPolicy }}
|
||||
name: {{ template "rancher.name" . }}-audit-log
|
||||
command: ["tail"]
|
||||
args: ["-F", "/var/log/auditlog/rancher-api-audit.log"]
|
||||
volumeMounts:
|
||||
- mountPath: /var/log/auditlog
|
||||
name: audit-log
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
{{- if .Values.additionalTrustedCAs }}
|
||||
- name: tls-ca-additional-volume
|
||||
secret:
|
||||
defaultMode: 0400
|
||||
secretName: tls-ca-additional
|
||||
{{- end }}
|
||||
{{- if .Values.privateCA }}
|
||||
- name: tls-ca-volume
|
||||
secret:
|
||||
defaultMode: 0400
|
||||
secretName: tls-ca
|
||||
{{- end }}
|
||||
{{- if gt (int .Values.auditLog.level) 0 }}
|
||||
{{- if eq .Values.auditLog.destination "hostPath" }}
|
||||
- name: audit-log
|
||||
hostPath:
|
||||
path: {{ .Values.auditLog.hostPath }}
|
||||
type: DirectoryOrCreate
|
||||
{{- else }}
|
||||
- name: audit-log
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if and .Values.customLogos.enabled (or (eq .Values.customLogos.volumeKind "persistentVolumeClaim") (and (eq .Values.customLogos.volumeKind "configMap") (.Values.customLogos.volumeName))) }}
|
||||
- name: custom-logos
|
||||
{{- if (eq .Values.customLogos.volumeKind "persistentVolumeClaim") }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ .Values.customLogos.volumeName | default (printf "%s-custom-logos" (include "rancher.fullname" .)) }}
|
||||
{{- else if (eq .Values.customLogos.volumeKind "configMap") }}
|
||||
configMap:
|
||||
name: {{ .Values.customLogos.volumeName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,66 @@
|
||||
{{- if .Values.ingress.enabled }}
|
||||
{{- if or (.Capabilities.APIVersions.Has "networking.k8s.io/v1/Ingress") (not (.Capabilities.APIVersions.Has "networking.k8s.io/v1beta1/Ingress")) }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
{{- else }}
|
||||
apiVersion: networking.k8s.io/v1beta1
|
||||
{{- end }}
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
annotations:
|
||||
{{- if .Values.ingress.configurationSnippet }}
|
||||
nginx.ingress.kubernetes.io/configuration-snippet: |
|
||||
{{- template "configurationSnippet" . }}
|
||||
{{- end }}
|
||||
{{- if eq .Values.tls "external" }}
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "false" # turn off ssl redirect for external.
|
||||
{{- else }}
|
||||
{{- if ne .Values.ingress.tls.source "secret" }}
|
||||
{{- $certmanagerVer := split "." .Values.certmanager.version -}}
|
||||
{{- if or (.Capabilities.APIVersions.Has "certmanager.k8s.io/v1alpha1") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (lt (int $certmanagerVer._1) 11)) }}
|
||||
certmanager.k8s.io/issuer: {{ template "rancher.fullname" . }}
|
||||
{{- else }}
|
||||
cert-manager.io/issuer: {{ template "rancher.fullname" . }}
|
||||
cert-manager.io/issuer-kind: Issuer
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.ingress.includeDefaultExtraAnnotations }}
|
||||
nginx.ingress.kubernetes.io/proxy-connect-timeout: "30"
|
||||
nginx.ingress.kubernetes.io/proxy-read-timeout: "1800"
|
||||
nginx.ingress.kubernetes.io/proxy-send-timeout: "1800"
|
||||
{{- end }}
|
||||
{{- if .Values.ingress.extraAnnotations }}
|
||||
{{ toYaml .Values.ingress.extraAnnotations | indent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if .Values.ingress.ingressClassName }}
|
||||
ingressClassName: {{ .Values.ingress.ingressClassName }}
|
||||
{{- end }}
|
||||
rules:
|
||||
- host: {{ .Values.hostname }} # hostname to access rancher server
|
||||
http:
|
||||
paths:
|
||||
- backend:
|
||||
{{- if or (.Capabilities.APIVersions.Has "networking.k8s.io/v1/Ingress") (not (.Capabilities.APIVersions.Has "networking.k8s.io/v1beta1/Ingress")) }}
|
||||
service:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
port:
|
||||
number: {{ .Values.ingress.servicePort }}
|
||||
{{- else }}
|
||||
serviceName: {{ template "rancher.fullname" . }}
|
||||
servicePort: {{ .Values.ingress.servicePort }}
|
||||
{{- end }}
|
||||
{{- if or (.Capabilities.APIVersions.Has "networking.k8s.io/v1/Ingress") (not (.Capabilities.APIVersions.Has "networking.k8s.io/v1beta1/Ingress")) }}
|
||||
pathType: ImplementationSpecific
|
||||
path: "/"
|
||||
{{- end }}
|
||||
{{- if eq .Values.tls "ingress" }}
|
||||
tls:
|
||||
- hosts:
|
||||
- {{ .Values.hostname }}
|
||||
secretName: {{ .Values.ingress.tls.secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,37 @@
|
||||
{{- if eq .Values.tls "ingress" -}}
|
||||
{{- if eq .Values.ingress.tls.source "letsEncrypt" -}}
|
||||
{{- $certmanagerVer := split "." .Values.certmanager.version -}}
|
||||
{{- if or (.Capabilities.APIVersions.Has "cert-manager.io/v1beta1") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (ge (int $certmanagerVer._1) 16)) }}
|
||||
apiVersion: cert-manager.io/v1beta1
|
||||
{{- else if or (.Capabilities.APIVersions.Has "cert-manager.io/v1alpha2") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (ge (int $certmanagerVer._1) 11)) }}
|
||||
apiVersion: cert-manager.io/v1alpha2
|
||||
{{- else if or (.Capabilities.APIVersions.Has "certmanager.k8s.io/v1alpha1") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (lt (int $certmanagerVer._1) 11)) }}
|
||||
apiVersion: certmanager.k8s.io/v1alpha1
|
||||
{{- else }}
|
||||
apiVersion: cert-manager.io/v1
|
||||
{{- end }}
|
||||
kind: Issuer
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
spec:
|
||||
acme:
|
||||
{{- if eq .Values.letsEncrypt.environment "production" }}
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
{{- else }}
|
||||
server: https://acme-staging-v02.api.letsencrypt.org/directory
|
||||
{{- end }}
|
||||
email: {{ .Values.letsEncrypt.email }}
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-{{ .Values.letsEncrypt.environment }}
|
||||
{{- if or (.Capabilities.APIVersions.Has "certmanager.k8s.io/v1alpha1") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (lt (int $certmanagerVer._1) 11)) }}
|
||||
http01: {}
|
||||
{{- else }}
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
class: {{ .Values.letsEncrypt.ingress.class }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,22 @@
|
||||
{{- if eq .Values.tls "ingress" -}}
|
||||
{{- if eq .Values.ingress.tls.source "rancher" -}}
|
||||
{{- $certmanagerVer := split "." .Values.certmanager.version -}}
|
||||
{{- if or (.Capabilities.APIVersions.Has "cert-manager.io/v1beta1") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (ge (int $certmanagerVer._1) 16)) }}
|
||||
apiVersion: cert-manager.io/v1beta1
|
||||
{{- else if or (.Capabilities.APIVersions.Has "cert-manager.io/v1alpha2") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (ge (int $certmanagerVer._1) 11)) }}
|
||||
apiVersion: cert-manager.io/v1alpha2
|
||||
{{- else if or (.Capabilities.APIVersions.Has "certmanager.k8s.io/v1alpha1") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (lt (int $certmanagerVer._1) 11)) }}
|
||||
apiVersion: certmanager.k8s.io/v1alpha1
|
||||
{{- else }}
|
||||
apiVersion: cert-manager.io/v1
|
||||
{{- end }}
|
||||
kind: Issuer
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
spec:
|
||||
ca:
|
||||
secretName: tls-rancher
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,32 @@
|
||||
{{- if .Values.preinstallHook }}
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}-create-tls-ca-job
|
||||
labels: {{ include "rancher.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": pre-install
|
||||
"helm.sh/hook-weight": "2" # Certificate 생성 후 실행되도록 우선순위 설정
|
||||
"helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded,hook-failed
|
||||
spec:
|
||||
backoffLimit: 4
|
||||
template:
|
||||
spec:
|
||||
serviceAccountName: {{ template "rancher.fullname" . }}-create-tls-ca-sa
|
||||
containers:
|
||||
- name: create-secret
|
||||
image: bitnami/kubectl:latest
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- |
|
||||
echo "Waiting for {{ .Values.ingress.tls.secretName }} to be created..."
|
||||
while [ $(kubectl get secret {{ .Values.ingress.tls.secretName }} -n {{ .Release.Namespace }} --ignore-not-found | wc -l) -lt 2 ]; do
|
||||
sleep 1
|
||||
done
|
||||
echo "Creating new secret with custom key..."
|
||||
RANCHER_CA_CERT=$(kubectl get secret {{ .Values.ingress.tls.secretName }} -o jsonpath='{.data.ca\.crt}' -n {{ .Release.Namespace }} | base64 -d)
|
||||
kubectl create secret generic tls-ca --from-literal=cacerts\.pem="${RANCHER_CA_CERT}" -n {{ .Release.Namespace }}
|
||||
restartPolicy: OnFailure
|
||||
{{- end }}
|
||||
@@ -0,0 +1,72 @@
|
||||
{{- if .Values.preinstallHook }}
|
||||
{{- if .Values.ingress.enabled }}
|
||||
{{- if or (.Capabilities.APIVersions.Has "networking.k8s.io/v1/Ingress") (not (.Capabilities.APIVersions.Has "networking.k8s.io/v1beta1/Ingress")) }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
{{- else }}
|
||||
apiVersion: networking.k8s.io/v1beta1
|
||||
{{- end }}
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": pre-install
|
||||
"helm.sh/hook-weight": "0" # Certificate 생성 후 실행되도록 우선순위 설정
|
||||
"helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded,hook-failed
|
||||
{{- if .Values.ingress.configurationSnippet }}
|
||||
nginx.ingress.kubernetes.io/configuration-snippet: |
|
||||
{{- template "configurationSnippet" . }}
|
||||
{{- end }}
|
||||
{{- if eq .Values.tls "external" }}
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "false" # turn off ssl redirect for external.
|
||||
{{- else }}
|
||||
{{- if ne .Values.ingress.tls.source "secret" }}
|
||||
{{- $certmanagerVer := split "." .Values.certmanager.version -}}
|
||||
{{- if or (.Capabilities.APIVersions.Has "certmanager.k8s.io/v1alpha1") (and (gt (len $certmanagerVer._0) 0) (eq (int $certmanagerVer._0) 0) (lt (int $certmanagerVer._1) 11)) }}
|
||||
certmanager.k8s.io/issuer: {{ template "rancher.fullname" . }}
|
||||
{{- else }}
|
||||
cert-manager.io/issuer: {{ template "rancher.fullname" . }}
|
||||
cert-manager.io/issuer-kind: Issuer
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.ingress.includeDefaultExtraAnnotations }}
|
||||
nginx.ingress.kubernetes.io/proxy-connect-timeout: "30"
|
||||
nginx.ingress.kubernetes.io/proxy-read-timeout: "1800"
|
||||
nginx.ingress.kubernetes.io/proxy-send-timeout: "1800"
|
||||
{{- end }}
|
||||
{{- if .Values.ingress.extraAnnotations }}
|
||||
{{ toYaml .Values.ingress.extraAnnotations | indent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if .Values.ingress.ingressClassName }}
|
||||
ingressClassName: {{ .Values.ingress.ingressClassName }}
|
||||
{{- end }}
|
||||
rules:
|
||||
- host: {{ .Values.hostname }} # hostname to access rancher server
|
||||
http:
|
||||
paths:
|
||||
- backend:
|
||||
{{- if or (.Capabilities.APIVersions.Has "networking.k8s.io/v1/Ingress") (not (.Capabilities.APIVersions.Has "networking.k8s.io/v1beta1/Ingress")) }}
|
||||
service:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
port:
|
||||
number: {{ .Values.ingress.servicePort }}
|
||||
{{- else }}
|
||||
serviceName: {{ template "rancher.fullname" . }}
|
||||
servicePort: {{ .Values.ingress.servicePort }}
|
||||
{{- end }}
|
||||
{{- if or (.Capabilities.APIVersions.Has "networking.k8s.io/v1/Ingress") (not (.Capabilities.APIVersions.Has "networking.k8s.io/v1beta1/Ingress")) }}
|
||||
pathType: {{ .Values.ingress.pathType }}
|
||||
path: {{ .Values.ingress.path }}
|
||||
{{- end }}
|
||||
{{- if eq .Values.tls "ingress" }}
|
||||
tls:
|
||||
- hosts:
|
||||
- {{ .Values.hostname }}
|
||||
secretName: {{ .Values.ingress.tls.secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
{{- if .Values.preinstallHook }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}-create-tls-ca-role
|
||||
labels: {{ include "rancher.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": pre-install
|
||||
"helm.sh/hook-weight": "-2"
|
||||
"helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded,hook-failed
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["secrets"]
|
||||
verbs: ["get", "create", "update", "patch", "list"]
|
||||
{{- end }}
|
||||
@@ -0,0 +1,18 @@
|
||||
{{- if .Values.preinstallHook }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}-create-tls-ca-rolebinding
|
||||
labels: {{ include "rancher.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": pre-install
|
||||
"helm.sh/hook-weight": "-1"
|
||||
"helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded,hook-failed
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ template "rancher.fullname" . }}-create-tls-ca-sa
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: Role
|
||||
name: {{ template "rancher.fullname" . }}-create-tls-ca-role
|
||||
{{- end }}
|
||||
@@ -0,0 +1,11 @@
|
||||
{{- if .Values.preinstallHook }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}-create-tls-ca-sa
|
||||
labels: {{ include "rancher.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": pre-install
|
||||
"helm.sh/hook-weight": "-3"
|
||||
"helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded,hook-failed
|
||||
{{- end }}
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: scheduling.k8s.io/v1
|
||||
kind: PriorityClass
|
||||
metadata:
|
||||
name: rancher-critical
|
||||
labels: {{ include "rancher.labels" . | nindent 4 }}
|
||||
value: 1000000000
|
||||
globalDefault: false
|
||||
description: "Priority class used by pods critical to rancher's functionality."
|
||||
@@ -0,0 +1,19 @@
|
||||
{{- if and (.Values.customLogos.enabled) (eq .Values.customLogos.volumeKind "persistentVolumeClaim") (not .Values.customLogos.volumeName) }}
|
||||
kind: PersistentVolumeClaim
|
||||
apiVersion: v1
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}-custom-logos
|
||||
spec:
|
||||
accessModes:
|
||||
- {{ .Values.customLogos.accessMode | quote }}
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.customLogos.size | quote }}
|
||||
storageClassName: {{ if .Values.customLogos.storageClass }}
|
||||
{{- if (eq "-" .Values.customLogos.storageClass) -}}
|
||||
""
|
||||
{{- else }}
|
||||
{{- .Values.customLogos.storageClass }}
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,25 @@
|
||||
{{/* Use the bootstrap password from values.yaml if an existing secret is not found */}}
|
||||
{{- $bootstrapPassword := .Values.bootstrapPassword -}}
|
||||
{{- $existingSecret := lookup "v1" "Secret" .Release.Namespace "bootstrap-secret" -}}
|
||||
{{- if $existingSecret -}}
|
||||
{{- if $existingSecret.data -}}
|
||||
{{- if $existingSecret.data.bootstrapPassword -}}
|
||||
{{- $bootstrapPassword = $existingSecret.data.bootstrapPassword | b64dec -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{/* If a bootstrap password was found in the values or an existing password was found create the secret */}}
|
||||
{{- if $bootstrapPassword }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: "bootstrap-secret"
|
||||
namespace: {{ .Release.Namespace }}
|
||||
annotations:
|
||||
"helm.sh/hook": pre-install,pre-upgrade
|
||||
"helm.sh/hook-weight": "-5"
|
||||
"helm.sh/resource-policy": keep
|
||||
type: Opaque
|
||||
data:
|
||||
bootstrapPassword: {{ $bootstrapPassword | b64enc | quote }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,28 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
{{- if .Values.service.annotations }}
|
||||
annotations:
|
||||
{{ toYaml .Values.service.annotations | indent 4 }}
|
||||
{{- end }}
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
spec:
|
||||
{{- /*
|
||||
If service.type is not provided this attribute is ommitted and k8s default of ClusterIP is used.
|
||||
*/}}
|
||||
{{- if .Values.service.type }}
|
||||
type: {{ .Values.service.type }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 80
|
||||
protocol: TCP
|
||||
name: http
|
||||
- port: 443
|
||||
targetPort: 444
|
||||
protocol: TCP
|
||||
name: https-internal
|
||||
selector:
|
||||
app: {{ template "rancher.fullname" . }}
|
||||
@@ -0,0 +1,6 @@
|
||||
kind: ServiceAccount
|
||||
apiVersion: v1
|
||||
metadata:
|
||||
name: {{ template "rancher.fullname" . }}
|
||||
labels:
|
||||
{{ include "rancher.labels" . | indent 4 }}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"$schema": "https://json-schema.org/draft-07/schema#",
|
||||
"properties": {
|
||||
"agentTLSMode": {
|
||||
"type": ["string", "null"],
|
||||
"enum": ["strict", "system-store", "", null],
|
||||
"description": "agentTLSMode must be 'strict' or 'system-store' or null (defaults to system-store)"
|
||||
},
|
||||
"auditLog": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"destination": {
|
||||
"type": "string",
|
||||
"enum": ["sidecar", "hostPath"],
|
||||
"description": "auditLog.destination must be either 'sidecar' or 'hostPath'"
|
||||
},
|
||||
"level": {
|
||||
"type": "integer",
|
||||
"enum": [0, 1, 2, 3],
|
||||
"description": "auditLog.level must be a number 0-3; 0 to disable, 3 for most verbose"
|
||||
}
|
||||
}
|
||||
},
|
||||
"busyboxImage": {
|
||||
"type": "string",
|
||||
"description": "[DEPRECATED] This value is deprecated, use `auditLog.image.repository` & `auditLog.image.tag` instead.",
|
||||
"deprecated": true
|
||||
},
|
||||
"busyboxImagePullPolicy": {
|
||||
"type": "string",
|
||||
"description": "[DEPRECATED] This value is deprecated, use `auditLog.image.pullPolicy` instead.",
|
||||
"deprecated": true
|
||||
}
|
||||
},
|
||||
"required": [],
|
||||
"title": "Rancher Chart Values",
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,202 @@
|
||||
# Additional Trusted CAs.
|
||||
# Enable this flag and add your CA certs as a secret named tls-ca-additional in the namespace.
|
||||
# See README.md for details.
|
||||
additionalTrustedCAs: false
|
||||
|
||||
antiAffinity: preferred
|
||||
topologyKey: kubernetes.io/hostname
|
||||
|
||||
# Audit Logs
|
||||
# Source: https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log
|
||||
# The audit log is piped to the console of the rancher-audit-log container in the rancher pod.
|
||||
# level: Verbosity of logs, 0 to 3. 0 is off, 3 most verbose.
|
||||
# Docs: https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log#audit-log-levels
|
||||
auditLog:
|
||||
destination: sidecar
|
||||
hostPath: /var/log/rancher/audit/
|
||||
level: 0
|
||||
maxAge: 1
|
||||
maxBackup: 1
|
||||
maxSize: 100
|
||||
|
||||
# Image for collecting rancher audit logs.
|
||||
# Important: update pkg/image/export/resolve.go when this default image is changed, so that it's reflected accordingly in rancher-images.txt generated for air-gapped setups.
|
||||
image:
|
||||
repository: "rancher/mirrored-bci-micro"
|
||||
tag: 15.6.24.2
|
||||
# Override imagePullPolicy image
|
||||
# options: Always, Never, IfNotPresent
|
||||
pullPolicy: "IfNotPresent"
|
||||
|
||||
# As of Rancher v2.5.0 this flag is deprecated and must be set to 'true' in order for Rancher to start
|
||||
addLocal: "true"
|
||||
|
||||
# Add debug flag to Rancher server
|
||||
debug: false
|
||||
|
||||
# When starting Rancher for the first time, bootstrap the admin as restricted-admin
|
||||
restrictedAdmin: false
|
||||
|
||||
# Control how the Rancher agents validate TLS connections
|
||||
# Valid options: strict, or system-store
|
||||
# Note, for new installations empty will default to strict on 2.9+, or system-store on 2.8 or older
|
||||
agentTLSMode: ""
|
||||
|
||||
# Extra environment variables passed to the rancher pods.
|
||||
# extraEnv:
|
||||
# - name: CATTLE_TLS_MIN_VERSION
|
||||
# value: "1.0"
|
||||
|
||||
# Fully qualified name to reach your Rancher server
|
||||
# hostname: rancher.my.org
|
||||
|
||||
## Optional array of imagePullSecrets containing private registry credentials
|
||||
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||
imagePullSecrets: []
|
||||
# - name: secretName
|
||||
|
||||
### ingress ###
|
||||
# Readme for details and instruction on adding tls secrets.
|
||||
ingress:
|
||||
# If set to false, ingress will not be created
|
||||
# Defaults to true
|
||||
# options: true, false
|
||||
enabled: true
|
||||
includeDefaultExtraAnnotations: true
|
||||
extraAnnotations: {}
|
||||
ingressClassName: ""
|
||||
# backend port number
|
||||
servicePort: 80
|
||||
|
||||
# configurationSnippet - Add additional Nginx configuration. This example statically sets a header on the ingress.
|
||||
# configurationSnippet: |
|
||||
# more_set_input_headers "X-Forwarded-Host: {{ .Values.hostname }}";
|
||||
|
||||
tls:
|
||||
# options: rancher, letsEncrypt, secret
|
||||
source: rancher
|
||||
secretName: tls-rancher-ingress
|
||||
|
||||
### service ###
|
||||
# Override to use NodePort or LoadBalancer service type - default is ClusterIP
|
||||
service:
|
||||
type: ""
|
||||
annotations: {}
|
||||
|
||||
### LetsEncrypt config ###
|
||||
# ProTip: The production environment only allows you to register a name 5 times a week.
|
||||
# Use staging until you have your config right.
|
||||
letsEncrypt:
|
||||
# email: none@example.com
|
||||
environment: production
|
||||
ingress:
|
||||
# options: traefik, nginx
|
||||
class: ""
|
||||
# If you are using certs signed by a private CA set to 'true' and set the 'tls-ca'
|
||||
# in the 'rancher-system' namespace. See the README.md for details
|
||||
privateCA: false
|
||||
|
||||
# http[s] proxy server passed into rancher server.
|
||||
# proxy: http://<username>@<password>:<url>:<port>
|
||||
|
||||
# comma separated list of domains or ip addresses that will not use the proxy
|
||||
noProxy: 127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.svc,.cluster.local
|
||||
|
||||
# Override rancher image location for Air Gap installs
|
||||
rancherImage: rancher/rancher
|
||||
# rancher/rancher image tag. https://hub.docker.com/r/rancher/rancher/tags/
|
||||
# Defaults to .Chart.appVersion
|
||||
# rancherImageTag: v2.0.7
|
||||
|
||||
# Override imagePullPolicy for rancher server images
|
||||
# options: Always, Never, IfNotPresent
|
||||
# Defaults to IfNotPresent
|
||||
# rancherImagePullPolicy: <pullPolicy>
|
||||
|
||||
# Number of Rancher server replicas. Setting to negative number will dynamically between 0 and the abs(replicas) based on available nodes.
|
||||
# of available nodes in the cluster
|
||||
replicas: 3
|
||||
|
||||
# Set priorityClassName to avoid eviction
|
||||
priorityClassName: rancher-critical
|
||||
|
||||
# Set pod resource requests/limits for Rancher.
|
||||
resources: {}
|
||||
|
||||
#
|
||||
# tls
|
||||
# Where to offload the TLS/SSL encryption
|
||||
# - ingress (default)
|
||||
# - external
|
||||
tls: ingress
|
||||
|
||||
systemDefaultRegistry: ""
|
||||
|
||||
# Set to use the packaged system charts
|
||||
useBundledSystemChart: false
|
||||
|
||||
# Certmanager version compatibility
|
||||
certmanager:
|
||||
version: ""
|
||||
|
||||
# Rancher custom logos persistence
|
||||
customLogos:
|
||||
enabled: false
|
||||
volumeSubpaths:
|
||||
emberUi: "ember"
|
||||
vueUi: "vue"
|
||||
## Volume kind to use for persistence: persistentVolumeClaim, configMap
|
||||
volumeKind: persistentVolumeClaim
|
||||
## Use an existing volume. Custom logos should be copied to the volume by the user
|
||||
# volumeName: custom-logos
|
||||
## Just for volumeKind: persistentVolumeClaim
|
||||
## To disables dynamic provisioning, set storageClass: "" or storageClass: "-"
|
||||
# storageClass: "-"
|
||||
accessMode: ReadWriteOnce
|
||||
size: 1Gi
|
||||
|
||||
# Rancher post-delete hook
|
||||
postDelete:
|
||||
enabled: true
|
||||
image:
|
||||
repository: rancher/shell
|
||||
tag: v0.3.0
|
||||
namespaceList:
|
||||
- cattle-fleet-system
|
||||
- cattle-system
|
||||
- rancher-operator-system
|
||||
# Number of seconds to wait for an app to be uninstalled
|
||||
timeout: 120
|
||||
# by default, the job will fail if it fail to uninstall any of the apps
|
||||
ignoreTimeoutError: false
|
||||
|
||||
# Set a bootstrap password. If leave empty, a random password will be generated.
|
||||
bootstrapPassword: ""
|
||||
|
||||
startupProbe:
|
||||
## should be ready within 2 minutes
|
||||
timeoutSeconds: 5
|
||||
periodSeconds: 10
|
||||
failureThreshold: 12
|
||||
|
||||
# Additional taints to tolerate
|
||||
extraTolerations: {}
|
||||
|
||||
livenessProbe:
|
||||
timeoutSeconds: 5
|
||||
periodSeconds: 30
|
||||
failureThreshold: 5
|
||||
readinessProbe:
|
||||
timeoutSeconds: 5
|
||||
periodSeconds: 30
|
||||
failureThreshold: 5
|
||||
|
||||
# helm values to use when installing the rancher-webhook chart.
|
||||
# helm values set here will override all other global values used when installing the webhook such as priorityClassName and systemRegistry settings.
|
||||
webhook: ""
|
||||
|
||||
# helm values to use when installing the fleet chart.
|
||||
# helm values set here will override all other global values used when installing the fleet chart.
|
||||
fleet: ""
|
||||
|
||||
preinstallHook: false
|
||||
Reference in New Issue
Block a user