-
Notifications
You must be signed in to change notification settings - Fork 10
/
Makefile
284 lines (233 loc) · 11.2 KB
/
Makefile
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
# Copyright 2020 IBM Corporation
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
.DEFAULT_GOAL:=help
# Specify whether this repo is build locally or not, default values is '1';
# If set to 1, then you need to also set 'DOCKER_USERNAME' and 'DOCKER_PASSWORD'
# environment variables before build the repo.
BUILD_LOCALLY ?= 1
VCS_URL ?= https://github.com/IBM/ibm-iam-policy-operator
VCS_REF ?= $(shell git rev-parse HEAD)
VERSION ?= $(shell cat ./version/version.go | grep "Version =" | awk '{ print $$3}' | tr -d '"')
LOCAL_OS := $(shell uname)
ifeq ($(LOCAL_OS),Linux)
TARGET_OS ?= linux
XARGS_FLAGS="-r"
STRIP_FLAGS=
else ifeq ($(LOCAL_OS),Darwin)
TARGET_OS ?= darwin
XARGS_FLAGS=
STRIP_FLAGS="-x"
else
$(error "This system's OS $(LOCAL_OS) isn't recognized/supported")
endif
ARCH := $(shell uname -m)
LOCAL_ARCH := "amd64"
ifeq ($(ARCH),x86_64)
LOCAL_ARCH="amd64"
else ifeq ($(ARCH),ppc64le)
LOCAL_ARCH="ppc64le"
else ifeq ($(ARCH),s390x)
LOCAL_ARCH="s390x"
else
$(error "This system's ARCH $(ARCH) isn't recognized/supported")
endif
ifeq ($(BUILD_LOCALLY),0)
IMAGE_REPO ?= "hyc-cloud-private-integration-docker-local.artifactory.swg-devops.com/ibmcom"
else
IMAGE_REPO ?= "quay.io/hbradfield"
endif
OPERAND_REGISTRY ?= $(IMAGE_REPO)
# Current Operator image name
IMAGE_NAME ?= ibm-iam-policy-operator
# Current Operator bundle image name
BUNDLE_IMAGE_NAME ?= ibm-iam-policy-operator-bundle
# Current Operator version
OPERATOR_VERSION ?= $(VERSION)
CSV_VERSION ?= $(OPERATOR_VERSION)
# The namespce that operator and policycontroller will be deployed in
NAMESPACE=ibm-common-services
# Image URL to use all building/pushing image targets
IMG ?= $(IMAGE_NAME):latest
# Options for 'bundle-build'
ifneq ($(origin CHANNELS), undefined)
BUNDLE_CHANNELS := --channels=$(CHANNELS)
endif
ifneq ($(origin DEFAULT_CHANNEL), undefined)
BUNDLE_DEFAULT_CHANNEL := --default-channel=$(DEFAULT_CHANNEL)
endif
BUNDLE_METADATA_OPTS ?= $(BUNDLE_CHANNELS) $(BUNDLE_DEFAULT_CHANNEL)
# Produce CRDs that work back to Kubernetes 1.11 (no version conversion)
CRD_OPTIONS ?= "crd:trivialVersions=true"
ifeq ($(BUILD_LOCALLY),0)
export CONFIG_DOCKER_TARGET = config-docker
export CONFIG_DOCKER_TARGET_QUAY = config-docker-quay
endif
include common/Makefile.common.mk
##@ Development
install-controller-gen: ## Install controller-gen
ifeq (, $(shell which controller-gen))
@{ \
set -e ;\
CONTROLLER_GEN_TMP_DIR=$$(mktemp -d) ;\
cd $$CONTROLLER_GEN_TMP_DIR ;\
go mod init tmp ;\
go get sigs.k8s.io/controller-tools/cmd/controller-gen@v0.3.0 ;\
rm -rf $$CONTROLLER_GEN_TMP_DIR ;\
}
endif
install-kustomize: ## Install kustomize
ifeq (, $(shell which kustomize))
@{ \
set -e ;\
KUSTOMIZE_GEN_TMP_DIR=$$(mktemp -d) ;\
cd $$KUSTOMIZE_GEN_TMP_DIR ;\
go mod init tmp ;\
go get sigs.k8s.io/kustomize/kustomize/v3@v3.5.4 ;\
rm -rf $$KUSTOMIZE_GEN_TMP_DIR ;\
}
endif
# find or download kubebuilder
# download kubebuilder if necessary
kube-builder:
ifeq (, $(wildcard /usr/local/kubebuilder))
@./common/scripts/install-kubebuilder.sh
endif
install-operator-sdk: ## Install operator-sdk
@operator-sdk version 2> /dev/null ; if [ $$? -ne 0 ]; then ./common/scripts/install-operator-sdk.sh; fi
check: lint-all ## Check all files for lint error
code-dev: ## Run the default dev commands (go tidy, fmt, vet) then execute $ make code-gen
@echo Running the common required commands for developments purposes
- make code-tidy
- make code-fmt
- make code-vet
@echo Running the common required commands for code delivery
- make check
- make test
manager: generate code-fmt code-vet ## Generate code e.g. API etc and build manager binary
go build -o bin/manager main.go
run: generate code-fmt code-vet manifests ## Run against the configured Kubernetes cluster in ~/.kube/config
WATCH_NAMESPACE="ibm-common-services" go run ./main.go
install-crd: manifests ## Install CRDs into a cluster
kustomize build config/crd | kubectl apply -f -
uninstall-crd: manifests ## Uninstall CRDs from a cluster
kustomize build config/crd | kubectl delete -f -
install: ## Install all resources (CR/CRD's, RBCA and Operator)
@echo ....... Creating namespace .......
- kubectl create namespace ${NAMESPACE}
@echo ....... Creating OperatorGroup .......
- cp common/util/operator_group.yaml og.yaml
- yq w -i og.yaml spec.targetNamespaces[+] ${NAMESPACE}
- oc create -f og.yaml -n ${NAMESPACE}
@echo ....... Applying manifests .......
- kubectl create sa ibm-iam-policy-operator -n ${NAMESPACE}
- kubectl create sa ibm-iam-policy-controller -n ${NAMESPACE}
- kubectl create -f config/rbac/role.yaml
- kubectl create -f config/rbac/role_binding.yaml
- kubectl create -f config/rbac/leader_election_role.yaml
- kubectl create -f config/rbac/leader_election_role_binding.yaml
- for manifest in $(shell ls bundle/manifests/*.yaml); do kubectl apply -f $${manifest} -n ${NAMESPACE}; done
@echo ....... Creating the Instances .......
- kubectl apply -f config/samples/operator_v1_policycontroller.yaml -n ${NAMESPACE}
uninstall: ## Uninstall all resources (CR/CRD's, RBCA and Operator)
@echo ....... Deleting namespace .......
# - kubectl delete namespace ${NAMESPACE}
@echo ....... Deleting the Instances .......
- kubectl delete --all policycontroller --all-namespaces
- kubectl delete --all iampolicy --all-namespaces
@echo ....... Deleting manifests .......
- kubectl delete sa ibm-iam-policy-operator -n ${NAMESPACE}
- kubectl delete sa ibm-iam-policy-controller -n ${NAMESPACE}
- kubectl delete -f config/rbac/role.yaml
- kubectl delete -f config/rbac/role_binding.yaml
- kubectl delete -f config/rbac/leader_election_role.yaml
- kubectl delete -f config/rbac/leader_election_role_binding.yaml
- for manifest in $(shell ls bundle/manifests/*.yaml); do kubectl delete -f $${manifest} -n ${NAMESPACE}; done
@echo ....... Deleting OperatorGroup .......
- oc delete -f og.yaml -n ${NAMESPACE}
- rm og.yaml
deploy: manifests ## Deploy controller in the configured Kubernetes cluster in ~/.kube/config
cd config/manager && kustomize edit set image controller=$(IMAGE_REPO)/$(IMAGE_NAME):$(VERSION)
kustomize build config/default | kubectl apply -f -
##@ Generate code and manifests
manifests: ## Generate manifests e.g. CRD, RBAC etc.
controller-gen $(CRD_OPTIONS) rbac:roleName=ibm-iam-policy-operator webhook paths="./..." output:crd:artifacts:config=config/crd/bases
generate: ## Generate code e.g. API etc.
controller-gen object:headerFile="hack/boilerplate.go.txt" paths="./..."
bundle-manifests: ## Generate bundle manifests
kustomize build config/manifests | operator-sdk generate bundle \
-q --overwrite --version $(CSV_VERSION) $(BUNDLE_METADATA_OPTS)
operator-sdk bundle validate ./bundle
generate-all: manifests ## Generate bundle manifests, metadata and package manifests
operator-sdk generate kustomize manifests -q
- make bundle-manifests CHANNELS=beta,stable-v1 DEFAULT_CHANNEL=stable-v1
##@ Test
test: ## Run unit test on prow
@echo "Running unit tests for the controllers."
@go test -v ./controllers/...
unit-test: generate code-fmt code-vet manifests ## Run unit test
ifeq (, $(USE_EXISTING_CLUSTER))
- make kube-builder
endif
@echo "Running unit tests for the controllers."
@go test -v ./controllers/... -coverprofile cover.out
scorecard: operator-sdk ## Run scorecard test
@echo ... Running the scorecard test
- operator-sdk scorecard --verbose
##@ Build
ifeq ($(BUILD_LOCALLY),0)
export CONFIG_DOCKER_TARGET = config-docker
endif
build: ## Build operator binary
@echo "Building the ibm-iam-policy-operator binary"
@CGO_ENABLED=0 GOOS=linux GO111MODULE=on go build -a -o bin/manager main.go
build-bundle-image: ## Build operator bundle image
$(eval ARCH := $(shell uname -m|sed 's/x86_64/amd64/'))
docker build -f bundle.Dockerfile -t $(IMAGE_REPO)/$(BUNDLE_IMAGE_NAME)-$(ARCH):$(VERSION) .
build-image-amd64: ## Build amd64 operator image
@docker build -t $(IMAGE_REPO)/$(IMAGE_NAME)-amd64:$(VERSION) \
--build-arg VCS_REF=$(VCS_REF) --build-arg VCS_URL=$(VCS_URL) -f Dockerfile .
build-image-ppc64le: ## Build ppcle64 operator image
@docker run --rm --privileged multiarch/qemu-user-static:register --reset
@docker build -t $(IMAGE_REPO)/$(IMAGE_NAME)-ppc64le:$(VERSION) \
--build-arg VCS_REF=$(VCS_REF) --build-arg VCS_URL=$(VCS_URL) -f Dockerfile.ppc64le .
build-image-s390x: ## Build s390x operator image
@docker run --rm --privileged multiarch/qemu-user-static:register --reset
@docker build -t $(IMAGE_REPO)/$(IMAGE_NAME)-s390x:$(VERSION) \
--build-arg VCS_REF=$(VCS_REF) --build-arg VCS_URL=$(VCS_URL) -f Dockerfile.s390x .
push-image-amd64: $(CONFIG_DOCKER_TARGET) build-image-amd64 ## Push amd64 operator image
@docker push $(IMAGE_REPO)/$(IMAGE_NAME)-amd64:$(VERSION)
push-image-ppc64le: $(CONFIG_DOCKER_TARGET) build-image-ppc64le ## Push ppc64le operator image
@docker push $(IMAGE_REPO)/$(IMAGE_NAME)-ppc64le:$(VERSION)
push-image-s390x: $(CONFIG_DOCKER_TARGET) build-image-s390x ## Push s390x operator image
@docker push $(IMAGE_REPO)/$(IMAGE_NAME)-s390x:$(VERSION)
push-bundle-image: $(CONFIG_DOCKER_TARGET) build-bundle-image ## Push operator bundle image
@docker push $(IMAGE_REPO)/$(BUNDLE_IMAGE_NAME)-$(ARCH):$(VERSION)
##@ Release
images: push-image-amd64 push-image-ppc64le push-image-s390x multiarch-image ## Generate all images
multiarch-image: ## Generate multiarch images for operator image
@curl -L -o /tmp/manifest-tool https://github.com/estesp/manifest-tool/releases/download/v1.0.3/manifest-tool-linux-amd64
@chmod +x /tmp/manifest-tool
/tmp/manifest-tool push from-args --platforms linux/amd64,linux/ppc64le,linux/s390x --template $(IMAGE_REPO)/$(IMAGE_NAME)-ARCH:$(VERSION) --target $(IMAGE_REPO)/$(IMAGE_NAME) --ignore-missing
/tmp/manifest-tool push from-args --platforms linux/amd64,linux/ppc64le,linux/s390x --template $(IMAGE_REPO)/$(IMAGE_NAME)-ARCH:$(VERSION) --target $(IMAGE_REPO)/$(IMAGE_NAME):$(VERSION) --ignore-missing
multiarch-bundle-image: ## Generate multiarch images for operator bundle image
@curl -L -o /tmp/manifest-tool https://github.com/estesp/manifest-tool/releases/download/v1.0.3/manifest-tool-linux-amd64
@chmod +x /tmp/manifest-tool
/tmp/manifest-tool push from-args --platforms linux/amd64,linux/ppc64le,linux/s390x --template $(IMAGE_REPO)/$(BUNDLE_IMAGE_NAME):$(VERSION) --target $(IMAGE_REPO)/$(BUNDLE_IMAGE_NAME) --ignore-missing
/tmp/manifest-tool push from-args --platforms linux/amd64,linux/ppc64le,linux/s390x --template $(IMAGE_REPO)/$(IMAGE_NAME)-ARCH:$(VERSION) --target $(IMAGE_REPO)/$(IMAGE_NAME):$(VERSION) --ignore-missing
##@ Help
help: ## Display this help
@echo "Usage:\n make \033[36m<target>\033[0m"
@awk 'BEGIN {FS = ":.*##"}; \
/^[a-zA-Z0-9_-]+:.*?##/ { printf " \033[36m%-20s\033[0m %s\n", $$1, $$2 } \
/^##@/ { printf "\n\033[1m%s\033[0m\n", substr($$0, 5) } ' $(MAKEFILE_LIST)