Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
132 commits
Select commit Hold shift + click to select a range
8646601
no message
itmwiw Jul 20, 2021
dc9a526
no message
itmwiw Jul 20, 2021
6301945
no message
itmwiw Jul 20, 2021
061a2e9
no message
itmwiw Jul 21, 2021
b6a3752
add eventsource
itmwiw Jul 21, 2021
c9b9d3c
no message
itmwiw Jul 21, 2021
4805b65
no message
itmwiw Jul 22, 2021
b7b50a6
no message
itmwiw Jul 22, 2021
e3990c0
no message
itmwiw Jul 22, 2021
85ff8b8
no message
itmwiw Jul 22, 2021
c76d9f6
no message
itmwiw Jul 22, 2021
74319a9
no message
itmwiw Jul 22, 2021
32559a5
no message
itmwiw Jul 22, 2021
9b67895
no message
itmwiw Jul 22, 2021
90d13bf
no message
itmwiw Jul 22, 2021
bf5f322
no message
itmwiw Jul 22, 2021
844166e
no message
itmwiw Jul 22, 2021
19249cf
no message
itmwiw Jul 22, 2021
263467e
no message
itmwiw Jul 22, 2021
18e1163
no message
itmwiw Jul 23, 2021
bf8c9f1
no message
itmwiw Jul 23, 2021
c2d9dbb
no message
itmwiw Jul 23, 2021
e206bdc
no message
itmwiw Jul 23, 2021
3fe76fa
no message
itmwiw Jul 23, 2021
f8db748
no message
itmwiw Jul 23, 2021
767d837
no message
itmwiw Jul 23, 2021
efee3ac
no message
itmwiw Jul 23, 2021
787e474
no message
itmwiw Jul 23, 2021
80c4179
no message
itmwiw Jul 23, 2021
c80057e
no message
itmwiw Jul 23, 2021
34155f2
no message
itmwiw Jul 23, 2021
90739a0
no message
itmwiw Jul 23, 2021
f319048
no message
itmwiw Jul 23, 2021
d950470
no message
itmwiw Jul 23, 2021
47c70af
no message
itmwiw Jul 23, 2021
a06fa6a
no message
itmwiw Jul 23, 2021
b53aed7
no message
itmwiw Jul 23, 2021
f199515
no message
itmwiw Jul 24, 2021
4f5139e
no message
itmwiw Jul 24, 2021
937ec71
no message
itmwiw Jul 24, 2021
bd3754b
no message
itmwiw Jul 24, 2021
8414230
no message
itmwiw Jul 24, 2021
88bbdee
no message
itmwiw Jul 24, 2021
beceb16
no message
itmwiw Jul 24, 2021
ea48ef3
no message
itmwiw Jul 24, 2021
8e814f7
no message
itmwiw Jul 24, 2021
7e503d8
no message
itmwiw Jul 24, 2021
9a1e904
no message
itmwiw Jul 24, 2021
c27f6db
no message
itmwiw Jul 24, 2021
23d188c
no message
itmwiw Jul 24, 2021
e5b60eb
no message
itmwiw Jul 24, 2021
d1365b4
no message
itmwiw Jul 24, 2021
2aecbac
no message
itmwiw Jul 24, 2021
ba88d63
no message
itmwiw Jul 24, 2021
d170d3d
no message
itmwiw Jul 24, 2021
48b88a6
no message
itmwiw Jul 24, 2021
1e34f0f
no message
itmwiw Jul 25, 2021
90d685a
no message
itmwiw Jul 25, 2021
53cee8d
no message
itmwiw Jul 25, 2021
85f0197
no message
itmwiw Jul 25, 2021
b37b87a
no message
itmwiw Jul 25, 2021
02e69f0
no message
itmwiw Jul 25, 2021
4d23d57
no message
itmwiw Jul 25, 2021
f9bdc28
no message
itmwiw Jul 25, 2021
a356432
no message
itmwiw Jul 25, 2021
b118221
no message
itmwiw Jul 25, 2021
5c7b2a1
no message
itmwiw Jul 25, 2021
b766a60
no message
itmwiw Jul 25, 2021
54f4210
no message
itmwiw Jul 25, 2021
b64f29a
no message
itmwiw Jul 25, 2021
82456fd
no message
itmwiw Jul 25, 2021
f98b319
no message
itmwiw Jul 25, 2021
25efadf
no message
itmwiw Jul 25, 2021
a09be48
no message
itmwiw Jul 25, 2021
c8fbbf2
no message
itmwiw Jul 25, 2021
78f1c30
no message
itmwiw Jul 25, 2021
fa00840
no message
itmwiw Jul 25, 2021
77fc7ea
no message
itmwiw Jul 25, 2021
b1aa26b
no message
itmwiw Jul 25, 2021
a0d6ff1
no message
itmwiw Jul 25, 2021
4797a8d
no message
itmwiw Jul 25, 2021
d288e71
no message
itmwiw Jul 25, 2021
f14410f
no message
itmwiw Jul 25, 2021
1364af5
no message
itmwiw Jul 25, 2021
bd3f5fe
no message
itmwiw Jul 25, 2021
9cee94a
no message
itmwiw Jul 25, 2021
33f3e58
no message
itmwiw Jul 25, 2021
adb11cb
no message
itmwiw Jul 25, 2021
1cf0650
no message
itmwiw Jul 25, 2021
2ded889
no message
itmwiw Jul 25, 2021
58553f4
no message
itmwiw Jul 25, 2021
b39593c
no message
itmwiw Jul 25, 2021
5a8497d
no message
itmwiw Jul 25, 2021
2dd80ad
no message
itmwiw Jul 25, 2021
c806a9b
no message
itmwiw Jul 25, 2021
28f97ca
no message
itmwiw Jul 25, 2021
5846484
no message
itmwiw Jul 26, 2021
3aae1f3
no message
itmwiw Jul 26, 2021
4185caa
no message
itmwiw Jul 26, 2021
ac5d627
no message
itmwiw Jul 26, 2021
3e0078f
no message
itmwiw Jul 26, 2021
868ac70
no message
itmwiw Jul 26, 2021
9bc3729
no message
itmwiw Jul 26, 2021
48ba49b
no message
itmwiw Jul 26, 2021
b1addde
supress unused manifests
itmwiw Jul 30, 2021
34d7861
supress unused steps
itmwiw Jul 30, 2021
e2eb9c4
change RBACs: ClusterRoles and ClusterRoleBindings instead of Roles …
itmwiw Jul 30, 2021
83486c2
change from watching multiple repos to watching only 1 repo.
itmwiw Jul 30, 2021
b4ee37c
add .Release.Namespace for ClusterRoleBindings' SA
itmwiw Jul 30, 2021
6e71e49
typo correcting
itmwiw Jul 30, 2021
8e0f6c3
add rbac's rule to grant sensor's sa namespaces creation
itmwiw Jul 30, 2021
15801c5
adding trigger's template for namespace creation -> sensor
itmwiw Jul 30, 2021
237f307
add get and watch namespaces rbac
itmwiw Jul 30, 2021
c5c8796
reduce name and namespace length
itmwiw Jul 30, 2021
4dc1086
correct typo
itmwiw Jul 30, 2021
b20cb58
generate ns from argo-workflows instead of events: there seems to be …
itmwiw Jul 31, 2021
255c040
add retry strategy to wait for the namespace to be created
itmwiw Jul 31, 2021
4b2f395
typo
itmwiw Jul 31, 2021
4985641
test workflow of workflows
itmwiw Jul 31, 2021
d8c06e7
add clusterscope to workflowTemplate
itmwiw Jul 31, 2021
9bc5a59
add kyverno policy to clone secrets
itmwiw Jul 31, 2021
9bf269a
typo
itmwiw Jul 31, 2021
87d0245
test vault integration
itmwiw Aug 1, 2021
36d436c
regroup all secrets in one
itmwiw Aug 1, 2021
b780871
add rbacs to operate-workflow-sa: create and watch secrets and rolebi…
itmwiw Aug 1, 2021
c85d081
add rbac: bind clusterRole
itmwiw Aug 1, 2021
2d42221
split manifest creation (ns, secret, rb) in 3
itmwiw Aug 1, 2021
8abc2ba
update successCondition
itmwiw Aug 1, 2021
b845ac8
generate git secret from vault
itmwiw Sep 17, 2021
01e49b7
change routes default values to sandbox openshift cluster (instead of…
itmwiw Sep 17, 2021
ae7d313
pull from commited branch + comment oci username and password for now
itmwiw Oct 20, 2021
a7cfc67
typo correction
itmwiw Oct 20, 2021
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions chartmuseum-config/chartmuseum-secret.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
#secret for basic auth
apiVersion: v1
kind: Secret
metadata:
name: chartmuseum-secret
namespace: chartmuseum
type: Opaque
stringData:
CHARTMUSEUM_USERNAME: "chartmuseum_username"
CHARTMUSEUM_PASSWORD: "chartmuseum_password"

17 changes: 17 additions & 0 deletions chartmuseum/Chart.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
apiVersion: v2
name: chartmuseum
description: Install chartmuseum on Openshift clusters
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application

# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
37 changes: 37 additions & 0 deletions chartmuseum/templates/chartmuseum.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
{{- $relname := .Release.Name -}}
{{- $targetNamespace := .Values.argocdConfig.targetNamespace -}}
{{- $project := .Values.argocdConfig.project.name -}}
{{- $repourl := .Values.chartmuseum.repository.url -}}
{{- $repoversion := .Values.chartmuseum.repository.version -}}
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: "{{ $relname }}-chartmuseum"

spec:
generators:
{{ toYaml .Values.argocdConfig.generators | nindent 4 }}

template:
metadata:
name: 'chartmuseum-{{ "{{" }}name{{ "}}" }}'
spec:
destination:
namespace: 'chartmuseum'
server: '{{ "{{" }}server{{ "}}" }}'
project: '{{ $project }}'
source:
repoURL: 'https://chartmuseum.github.io/charts' #'{{ $repourl }}'
targetRevision: '{{ $repoversion }}'
chart: chartmuseum

helm:
releaseName: 'chartmuseum'
values: |
{{ toYaml .Values.chartmuseum.config | indent 12 }}

syncPolicy:
automated:
prune: true
syncOptions:
- CreateNamespace=true
43 changes: 43 additions & 0 deletions chartmuseum/values.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
chartmuseum:
repository:
version: 3.1.0
config:
env:
open:
# storage backend, can be one of: local, alibaba, amazon, google, microsoft, oracle
STORAGE: local
DISABLE_API: false
# allow anonymous GET operations when auth is used
AUTH_ANONYMOUS_GET: false
# enable bearer auth
BEARER_AUTH: false
# auth realm used for bearer auth
AUTH_REALM:
# auth service used for bearer auth
AUTH_SERVICE:
existingSecret: chartmuseum-secret
existingSecretMappings:
# username for basic http authentication
BASIC_AUTH_USER: CHARTMUSEUM_USERNAME
# password for basic http authentication
BASIC_AUTH_PASS: CHARTMUSEUM_PASSWORD
bearerAuth:
secret:
enabled: false
publicKeySecret: chartmuseum-public-key
securityContext:
enabled: true
fsGroup: null
runAsNonRoot: true
persistence:
enabled: true
accessMode: ReadWriteOnce
size: 8Gi
storageClass: "gp2"


argocdConfig:
generators: []
project:
create: false
name: default
17 changes: 17 additions & 0 deletions helm-pipelines/Chart.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
apiVersion: v2
name: helm-pipelines
description: Install all the necessary ressources to automate helm charts pipeline on Openshift clusters
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application

# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
2 changes: 1 addition & 1 deletion README.md → helm-pipelines/README.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# helm-pipelines
# helm-pipelines

## ARGO helm package registry

Expand Down
20 changes: 20 additions & 0 deletions helm-pipelines/templates/event-source/github-route.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
{{- if eq .Values.github.webhook.route "true" }}
kind: Route
apiVersion: route.openshift.io/v1
metadata:
name: {{ .Release.Name }}-github-event
labels:
app.kubernetes.io/instance: helm-pipeline
controller: eventsource-controller
eventsource-name: {{ .Release.Name }}-github-events

spec:
host: {{ .Values.github.webhook.url }}
to:
kind: Service
name: {{ .Release.Name }}-github-events-eventsource-svc
weight: 100
port:
targetPort: 12000
wildcardPolicy: None
{{- end }}
105 changes: 105 additions & 0 deletions helm-pipelines/templates/event-source/github.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,105 @@
# Info on GitHub Webhook: https://developer.github.com/v3/repos/hooks/#create-a-hook
apiVersion: argoproj.io/v1alpha1
kind: EventSource
metadata:
name: {{ .Release.Name }}-github-events
spec:
eventBusName: {{ if eq .Values.eventbus.enabled "true" }}{{ .Release.Name }}-default{{ else }}{{ .Values.eventbus.eventbusName }}{{ end }}
service:
ports:
- port: 12000
targetPort: 12000
github:
push:
repositories:
- owner: {{ .Values.github.repository.owner }}
names:
- {{ .Values.github.repository.name }}
# Github will send events to following port and endpoint
webhook:
# endpoint to listen to events on
endpoint: /push
# port to run internal HTTP server on
port: "12000"
# HTTP request method to allow. In this case, only POST requests are accepted
method: POST
# url the event-source will use to register at Github.
# This url must be reachable from outside the cluster.
# The name for the service is in `<event-source-name>-eventsource-svc` format.
# You will need to create an Ingress or Openshift Route for the event-source service so that it can be reached from GitHub.
url: http://{{ .Values.github.webhook.url }}
# type of events to listen to.
# following listens to everything, hence *
# You can find more info on https://developer.github.com/v3/activity/events/types/
events:
- "push"
- "pull_request"
# apiToken refers to K8s secret that stores the github api token
# if apiToken is provided controller will create webhook on GitHub repo
# +optional
apiToken:
# Name of the K8s secret that contains the access token
name: git-secret
# Key within the K8s secret whose corresponding value (must be base64 encoded) is access token
key: GIT_TOKEN

# # webhookSecret refers to K8s secret that stores the github hook secret
# # +optional
# webhookSecret:
# # Name of the K8s secret that contains the hook secret
# name: github-access
# # Key within the K8s secret whose corresponding value (must be base64 encoded) is hook secret
# key: secret

# type of the connection between event-source and Github.
# You should set it to false to avoid man-in-the-middle and other attacks.
insecure: true
# Determines if notifications are sent when the webhook is triggered
active: true
# The media type used to serialize the payloads
contentType: json

# example-without-api-credentials:
# owner: "argoproj"
# repository: "argo"
# webhook:
# endpoint: "/push"
# port: "13000"
# method: "POST"
# events:
# - "*"
# webhookSecret:
# name: github-access
# key: secret
# insecure: true
# active: true
# contentType: "json"

# example-with-secure-connection:
# owner: "argoproj"
# repository: "argo"
# webhook:
# endpoint: "/push"
# port: "13000"
# method: "POST"
# url: "http://myargofakeurl.fake"
# # k8s secret that contains the cert
# serverCertSecret:
# name: my-secret
# key: cert-key
# # k8s secret that contains the private key
# serverKeySecret:
# name: my-secret
# key: pk-key
# events:
# - "push"
# - "delete"
# apiToken:
# name: github-access
# key: token
# webhookSecret:
# name: github-access
# key: secret
# insecure: true
# active: true
# contentType: "json"
23 changes: 23 additions & 0 deletions helm-pipelines/templates/eventbus/eventBus.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
{{- if eq .Values.eventbus.enabled "true" }}
apiVersion: argoproj.io/v1alpha1
kind: EventBus
metadata:
name: {{ .Release.Name }}-default
spec:
nats:
native:
# Optional, defaults to 3. If it is < 3, set it to 3, that is the minimal requirement.
replicas: {{ .Values.eventbus.replicas }}
# Optional, authen strategy, "none" or "token", defaults to "none"
auth: token
containerTemplate:
{{ toYaml .Values.eventbus.containerTemplate | indent 8 }}

# metricsContainerTemplate:
# resources:
# requests:
# cpu: "10m"
# antiAffinity: false
persistence:
{{ toYaml .Values.eventbus.persistence | indent 8 }}
{{- end }}
39 changes: 39 additions & 0 deletions helm-pipelines/templates/rbac/RBAC-default.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
{{- if eq .Values.rbac.default "true" }}
# Similarly you can use a Role and RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ .Release.Name }}-workflow-cluster-role
rules:
# pod get/watch is used to identify the container IDs of the current pod
# pod patch is used to annotate the step's outputs back to controller (e.g. artifact location)
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- watch
- patch
# logs get/watch are used to get the pods logs for script outputs, and for log archival
- apiGroups:
- ""
resources:
- pods/log
verbs:
- get
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: {{ .Release.Name }}-workflow-role-cluster-binding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ .Release.Name }}-workflow-cluster-role
subjects:
- kind: ServiceAccount
name: default
namespace: {{ .Release.Namespace }}
{{- end }}
65 changes: 65 additions & 0 deletions helm-pipelines/templates/rbac/sa-sensor.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
{{- if eq .Values.rbac.operateWorkflow "true" }}
#sa used by the sensor to create workflows
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ .Release.Name }}-operate-workflow-sa
---
# Similarly you can use a Role and RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ .Release.Name }}-operate-workflow-cluster-role
rules:
- apiGroups:
- argoproj.io
verbs:
- "*"
resources:
- workflows
- workflowtemplates
- cronworkflows
- clusterworkflowtemplates
- apiGroups:
- ""
resources:
- namespaces
verbs:
- create
- get
- watch
- apiGroups:
- "rbac.authorization.k8s.io"
resources:
- rolebindings
verbs:
- create
- get
- watch
- apiGroups:
- ""
resources:
- secrets
verbs:
- create
- get
- watch
- apiGroups: ["rbac.authorization.k8s.io"]
resources: ["clusterroles"]
verbs: ["bind"]
# omit resourceNames to allow binding any ClusterRole
resourceNames: ["{{ .Release.Name }}-workflow-cluster-role"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ .Release.Name }}-operate-workflow-cluster-role-binding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ .Release.Name }}-operate-workflow-cluster-role
subjects:
- kind: ServiceAccount
name: {{ .Release.Name }}-operate-workflow-sa
namespace: {{ .Release.Namespace }}
{{- end }}
Loading