update kubeflow dip-catalog

This commit is contained in:
ChanghoWoo
2025-01-13 02:31:27 +00:00
parent 1dc1181a03
commit 5451f16d72
1959 changed files with 602337 additions and 0 deletions
@@ -0,0 +1,15 @@
---
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
name: katib-ui
namespace: kubeflow
spec:
action: ALLOW
selector:
matchLabels:
katib.kubeflow.org/component: ui
rules:
- from:
- source:
principals: ["cluster.local/ns/istio-system/sa/istio-ingressgateway-service-account"]
@@ -0,0 +1,66 @@
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeflow-katib-admin
labels:
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-admin: "true"
aggregationRule:
clusterRoleSelectors:
- matchLabels:
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-katib-admin: "true"
rules: []
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeflow-katib-edit
labels:
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-edit: "true"
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-katib-admin: "true"
rules:
- apiGroups:
- kubeflow.org
resources:
- experiments
- trials
- suggestions
verbs:
- get
- list
- watch
- create
- delete
- deletecollection
- patch
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- list
- apiGroups:
- ""
resources:
- pods/log
verbs:
- get
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeflow-katib-view
labels:
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-view: "true"
rules:
- apiGroups:
- kubeflow.org
resources:
- experiments
- trials
- suggestions
verbs:
- get
- list
- watch
@@ -0,0 +1,56 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: kubeflow
resources:
- ../katib-cert-manager
# Kubeflow Katib components.
- kubeflow-katib-roles.yaml
- ui-virtual-service.yaml
- istio-authorizationpolicy.yaml
images:
- name: docker.io/kubeflowkatib/katib-controller
newName: docker.io/kubeflowkatib/katib-controller
newTag: v0.17.0
- name: docker.io/kubeflowkatib/katib-db-manager
newName: docker.io/kubeflowkatib/katib-db-manager
newTag: v0.17.0
- name: docker.io/kubeflowkatib/katib-ui
newName: docker.io/kubeflowkatib/katib-ui
newTag: v0.17.0
patchesStrategicMerge:
- patches/remove-namespace.yaml
patches:
# Extend RBAC permission list of katib-ui so it can
# create SubjectAccessReview resources.
- target:
kind: ClusterRole
name: katib-ui
group: rbac.authorization.k8s.io
version: v1
path: patches/ui-rbac.yaml
# Enable RBAC authz checks in UI's backend.
- target:
version: v1
kind: Deployment
name: katib-ui
path: patches/enable-ui-authz-checks.yaml
# Allow istio sidecar injection in katib-UI Pod.
- target:
kind: Deployment
name: katib-ui
path: patches/istio-sidecar-injection.yaml
vars:
- fieldref:
fieldPath: metadata.namespace
name: KATIB_UI_NAMESPACE
objref:
apiVersion: apps/v1
kind: Deployment
name: katib-ui
configurations:
- params.yaml
@@ -0,0 +1,4 @@
---
varReference:
- path: spec/http/route/destination/host
kind: VirtualService
@@ -0,0 +1,6 @@
---
- op: add
path: /spec/template/spec/containers/0/env/-
value:
name: APP_DISABLE_AUTH
value: "false"
@@ -0,0 +1,10 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: "katib-ui"
spec:
template:
metadata:
annotations:
sidecar.istio.io/inject: "true"
@@ -0,0 +1,6 @@
---
$patch: delete
apiVersion: v1
kind: Namespace
metadata:
name: kubeflow
@@ -0,0 +1,7 @@
---
- op: add
path: /rules/-
value:
apiGroups: [authorization.k8s.io]
resources: [subjectaccessreviews]
verbs: [create]
@@ -0,0 +1,21 @@
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: katib-ui
spec:
gateways:
- kubeflow-gateway
hosts:
- "*"
http:
- match:
- uri:
prefix: /katib/
rewrite:
uri: /katib/
route:
- destination:
host: katib-ui.$(KATIB_UI_NAMESPACE).svc.cluster.local
port:
number: 80