/
argocd_controller.go
227 lines (190 loc) · 9.69 KB
/
argocd_controller.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
/*
Copyright 2019, 2021.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package argocd
import (
"context"
"fmt"
"time"
"github.com/prometheus/client_golang/prometheus"
argoproj "github.com/argoproj-labs/argocd-operator/api/v1beta1"
corev1 "k8s.io/api/core/v1"
"k8s.io/apimachinery/pkg/api/errors"
"k8s.io/apimachinery/pkg/labels"
"k8s.io/apimachinery/pkg/runtime"
ctrl "sigs.k8s.io/controller-runtime"
"sigs.k8s.io/controller-runtime/pkg/client"
logr "sigs.k8s.io/controller-runtime/pkg/log"
"sigs.k8s.io/controller-runtime/pkg/reconcile"
)
// blank assignment to verify that ReconcileArgoCD implements reconcile.Reconciler
var _ reconcile.Reconciler = &ReconcileArgoCD{}
// ArgoCDReconciler reconciles a ArgoCD object
// TODO(upgrade): rename to ArgoCDRecoonciler
type ReconcileArgoCD struct {
client.Client
Scheme *runtime.Scheme
ManagedNamespaces *corev1.NamespaceList
// Stores a list of ApplicationSourceNamespaces as keys
ManagedSourceNamespaces map[string]string
// Stores a list of ApplicationSetSourceNamespaces as keys
ManagedApplicationSetSourceNamespaces map[string]string
// Stores label selector used to reconcile a subset of ArgoCD
LabelSelector string
}
var log = logr.Log.WithName("controller_argocd")
// Map to keep track of running Argo CD instances using their namespaces as key and phase as value
// This map will be used for the performance metrics purposes
// Important note: This assumes that each instance only contains one Argo CD instance
// as, having multiple Argo CD instances in the same namespace is considered an anti-pattern
var ActiveInstanceMap = make(map[string]string)
//+kubebuilder:rbac:groups=rbac.authorization.k8s.io,resources=clusterroles;clusterrolebindings,verbs=*
//+kubebuilder:rbac:groups="",resources=configmaps;endpoints;events;persistentvolumeclaims;pods;namespaces;secrets;serviceaccounts;services;services/finalizers,verbs=*
//+kubebuilder:rbac:groups=apps.openshift.io,resources=deploymentconfigs,verbs=*
//+kubebuilder:rbac:groups=apps,resources=deployments;replicasets;daemonsets;statefulsets,verbs=*
//+kubebuilder:rbac:groups=apps,resourceNames=argocd-operator,resources=deployments/finalizers,verbs=update
//+kubebuilder:rbac:groups=argoproj.io,resources=argocds;argocds/finalizers;argocds/status,verbs=*
//+kubebuilder:rbac:groups=autoscaling,resources=horizontalpodautoscalers,verbs=*
//+kubebuilder:rbac:groups=batch,resources=cronjobs;jobs,verbs=*
//+kubebuilder:rbac:groups=config.openshift.io,resources=clusterversions,verbs=get;list;watch
//+kubebuilder:rbac:groups=networking.k8s.io,resources=ingresses,verbs=*
//+kubebuilder:rbac:groups=monitoring.coreos.com,resources=prometheuses;prometheusrules;servicemonitors,verbs=*
//+kubebuilder:rbac:groups=route.openshift.io,resources=routes;routes/custom-host,verbs=*
//+kubebuilder:rbac:groups=argoproj.io,resources=applications;appprojects,verbs=*
//+kubebuilder:rbac:groups=rbac.authorization.k8s.io,resources=*,verbs=*
//+kubebuilder:rbac:groups="",resources=pods;pods/log,verbs=get
//+kubebuilder:rbac:groups=template.openshift.io,resources=templates;templateinstances;templateconfigs,verbs=*
//+kubebuilder:rbac:groups="oauth.openshift.io",resources=oauthclients,verbs=get;list;watch;create;delete;patch;update
// +kubebuilder:rbac:groups=argoproj.io,resources=notificationsconfigurations;notificationsconfigurations/finalizers,verbs=*
// Reconcile is part of the main kubernetes reconciliation loop which aims to
// move the current state of the cluster closer to the desired state.
// the ArgoCD object against the actual cluster state, and then
// perform operations to make the cluster state reflect the state specified by
// the user.
//
// For more details, check Reconcile and its Result here:
// - https://pkg.go.dev/sigs.k8s.io/controller-runtime@v0.9.2/pkg/reconcile
func (r *ReconcileArgoCD) Reconcile(ctx context.Context, request ctrl.Request) (ctrl.Result, error) {
reconcileStartTS := time.Now()
defer func() {
ReconcileTime.WithLabelValues(request.Namespace).Observe(time.Since(reconcileStartTS).Seconds())
}()
reqLogger := logr.FromContext(ctx, "namespace", request.Namespace, "name", request.Name)
reqLogger.Info("Reconciling ArgoCD")
argocd := &argoproj.ArgoCD{}
err := r.Client.Get(ctx, request.NamespacedName, argocd)
if err != nil {
if errors.IsNotFound(err) {
// Request object not found, could have been deleted after reconcile request.
// Owned objects are automatically garbage collected. For additional cleanup logic use finalizers.
// Return and don't requeue
return reconcile.Result{}, nil
}
// Error reading the object - requeue the request.
return reconcile.Result{}, err
}
// Fetch labelSelector from r.LabelSelector (command-line option)
labelSelector, err := labels.Parse(r.LabelSelector)
if err != nil {
reqLogger.Info(fmt.Sprintf("error parsing the labelSelector '%s'.", labelSelector))
return reconcile.Result{}, err
}
// Match the value of labelSelector from ReconcileArgoCD to labels from the argocd instance
if !labelSelector.Matches(labels.Set(argocd.Labels)) {
reqLogger.Info(fmt.Sprintf("the ArgoCD instance '%s' does not match the label selector '%s' and skipping for reconciliation", request.NamespacedName, r.LabelSelector))
return reconcile.Result{}, fmt.Errorf("error: failed to reconcile ArgoCD instance: '%s'", request.NamespacedName)
}
newPhase := argocd.Status.Phase
// If we discover a new Argo CD instance in a previously un-seen namespace
// we add it to the map and increment active instance count by phase
// as well as total active instance count
if _, ok := ActiveInstanceMap[request.Namespace]; !ok {
if newPhase != "" {
ActiveInstanceMap[request.Namespace] = newPhase
ActiveInstancesByPhase.WithLabelValues(newPhase).Inc()
ActiveInstancesTotal.Inc()
}
} else {
// If we discover an existing instance's phase has changed since we last saw it
// increment instance count with new phase and decrement instance count with old phase
// update the phase in corresponding map entry
// total instance count remains the same
if oldPhase := ActiveInstanceMap[argocd.Namespace]; oldPhase != newPhase {
ActiveInstanceMap[argocd.Namespace] = newPhase
ActiveInstancesByPhase.WithLabelValues(newPhase).Inc()
ActiveInstancesByPhase.WithLabelValues(oldPhase).Dec()
}
}
ActiveInstanceReconciliationCount.WithLabelValues(argocd.Namespace).Inc()
if argocd.GetDeletionTimestamp() != nil {
// Argo CD instance marked for deletion; remove entry from activeInstances map and decrement active instance count
// by phase as well as total
delete(ActiveInstanceMap, argocd.Namespace)
ActiveInstancesByPhase.WithLabelValues(newPhase).Dec()
ActiveInstancesTotal.Dec()
ActiveInstanceReconciliationCount.DeleteLabelValues(argocd.Namespace)
ReconcileTime.DeletePartialMatch(prometheus.Labels{"namespace": argocd.Namespace})
if argocd.IsDeletionFinalizerPresent() {
if err := r.deleteClusterResources(argocd); err != nil {
return reconcile.Result{}, fmt.Errorf("failed to delete ClusterResources: %w", err)
}
if isRemoveManagedByLabelOnArgoCDDeletion() {
if err := r.removeManagedByLabelFromNamespaces(argocd.Namespace); err != nil {
return reconcile.Result{}, fmt.Errorf("failed to remove label from namespace[%v], error: %w", argocd.Namespace, err)
}
}
if err := r.removeUnmanagedSourceNamespaceResources(argocd); err != nil {
return reconcile.Result{}, fmt.Errorf("failed to remove resources from sourceNamespaces, error: %w", err)
}
if err := r.removeUnmanagedApplicationSetSourceNamespaceResources(argocd); err != nil {
return reconcile.Result{}, fmt.Errorf("failed to remove resources from applicationSetSourceNamespaces, error: %w", err)
}
if err := r.removeDeletionFinalizer(argocd); err != nil {
return reconcile.Result{}, err
}
// remove namespace of deleted Argo CD instance from deprecationEventEmissionTracker (if exists) so that if another instance
// is created in the same namespace in the future, that instance is appropriately tracked
delete(DeprecationEventEmissionTracker, argocd.Namespace)
}
return reconcile.Result{}, nil
}
if !argocd.IsDeletionFinalizerPresent() {
if err := r.addDeletionFinalizer(argocd); err != nil {
return reconcile.Result{}, err
}
}
// get the latest version of argocd instance before reconciling
if err = r.Client.Get(ctx, request.NamespacedName, argocd); err != nil {
return reconcile.Result{}, err
}
if err = r.setManagedNamespaces(argocd); err != nil {
return reconcile.Result{}, err
}
if err = r.setManagedSourceNamespaces(argocd); err != nil {
return reconcile.Result{}, err
}
if err = r.setManagedApplicationSetSourceNamespaces(argocd); err != nil {
return reconcile.Result{}, err
}
if err := r.reconcileResources(argocd); err != nil {
// Error reconciling ArgoCD sub-resources - requeue the request.
return reconcile.Result{}, err
}
// Return and don't requeue
return reconcile.Result{}, nil
}
// SetupWithManager sets up the controller with the Manager.
func (r *ReconcileArgoCD) SetupWithManager(mgr ctrl.Manager) error {
bldr := ctrl.NewControllerManagedBy(mgr)
r.setResourceWatches(bldr, r.clusterResourceMapper, r.tlsSecretMapper, r.namespaceResourceMapper, r.clusterSecretResourceMapper, r.applicationSetSCMTLSConfigMapMapper)
return bldr.Complete(r)
}