/
defaults.go
161 lines (125 loc) · 6.51 KB
/
defaults.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
// SPDX-License-Identifier: Apache-2.0
// Copyright Authors of Cilium
package defaults
import (
"time"
)
const (
CiliumPodSelector = "app.kubernetes.io/part-of=cilium"
AgentContainerName = "cilium-agent"
AgentClusterRoleName = "cilium"
AgentDaemonSetName = "cilium"
AgentPodSelector = "k8s-app=cilium"
EnvoyDaemonSetName = "cilium-envoy"
EnvoyConfigMapName = "cilium-envoy-config"
CASecretName = "cilium-ca"
CASecretCertName = "ca.crt"
EncryptionSecretName = "cilium-ipsec-keys"
OperatorPodSelector = "io.cilium/app=operator"
OperatorContainerName = "cilium-operator"
OperatorMetricsPortName = "prometheus"
OperatorDeploymentName = "cilium-operator"
RelayContainerName = "hubble-relay"
RelayDeploymentName = "hubble-relay"
RelayConfigMapName = "hubble-relay-config"
HubbleUIDeploymentName = "hubble-ui"
ClusterMeshDeploymentName = "clustermesh-apiserver"
ClusterMeshContainerName = "apiserver"
ClusterMeshPodSelector = "k8s-app=clustermesh-apiserver"
ClusterMeshMetricsPortName = "apiserv-metrics"
ClusterMeshKVStoreMeshContainerName = "kvstoremesh"
ClusterMeshKVStoreMeshMetricsPortName = "kvmesh-metrics"
ClusterMeshEtcdContainerName = "etcd"
ClusterMeshEtcdMetricsPortName = "etcd-metrics"
ClusterMeshServiceName = "clustermesh-apiserver"
ClusterMeshSecretName = "cilium-clustermesh" // Secret which contains the clustermesh configuration
ClusterMeshServerSecretName = "clustermesh-apiserver-server-cert"
ClusterMeshAdminSecretName = "clustermesh-apiserver-admin-cert"
ClusterMeshClientSecretName = "clustermesh-apiserver-client-cert"
ClusterMeshRemoteSecretName = "clustermesh-apiserver-remote-cert"
ClusterMeshExternalWorkloadSecretName = "clustermesh-apiserver-external-workload-cert"
SPIREServerStatefulSetName = "spire-server"
SPIREServerConfigMapName = "spire-server"
SPIREAgentDaemonSetName = "spire-agent"
SPIREAgentConfigMapName = "spire-agent"
ConnectivityCheckNamespace = "cilium-test"
// renovate: datasource=docker
ConnectivityCheckAlpineCurlImage = "quay.io/cilium/alpine-curl:v1.9.0@sha256:e9f5bd17e6fe42f56d926674624dc915e4d3ff3d3c42f4d9c2f10c72ee9993ff"
// renovate: datasource=docker
ConnectivityPerformanceImage = "quay.io/cilium/network-perf:a816f935930cb2b40ba43230643da4d5751a5711@sha256:679d3a370c696f63884da4557a4466f3b5569b4719bb4f86e8aac02fbe390eea"
// renovate: datasource=docker
ConnectivityCheckJSONMockImage = "quay.io/cilium/json-mock:v1.3.8@sha256:5aad04835eda9025fe4561ad31be77fd55309af8158ca8663a72f6abb78c2603"
// renovate: datasource=docker
ConnectivityDNSTestServerImage = "docker.io/coredns/coredns:1.11.1@sha256:1eeb4c7316bacb1d4c8ead65571cd92dd21e27359f0d4917f1a5822a73b75db1"
ConfigMapName = "cilium-config"
StatusWaitDuration = 5 * time.Minute
WaitRetryInterval = 2 * time.Second
WaitWarningInterval = 10 * time.Second
FlowWaitTimeout = 10 * time.Second
FlowRetryInterval = 500 * time.Millisecond
PolicyWaitTimeout = 15 * time.Second
ConnectRetry = 3
ConnectRetryDelay = 3 * time.Second
ConnectTimeout = 2 * time.Second
RequestTimeout = 10 * time.Second
UninstallTimeout = 5 * time.Minute
IngressClassName = "cilium"
HelmValuesSecretName = "cilium-cli-helm-values"
CiliumNoScheduleLabel = "cilium.io/no-schedule"
// ClustermeshMaxConnectedClusters is the default number of the maximum
// number of clusters that should be allowed to connect to the Clustermesh.
ClustermeshMaxConnectedClusters = 255
// Default timeout for Connectivity Test Suite (disabled by default)
ConnectivityTestSuiteTimeout = 0 * time.Minute
)
var (
// renovate: datasource=github-releases depName=cilium/cilium
Version = "v1.15.3"
// HelmRepository specifies Helm repository to download Cilium charts from.
HelmRepository = "https://helm.cilium.io"
// CiliumScheduleAffinity is the node affinity to prevent Cilium from being schedule on
// nodes labeled with CiliumNoScheduleLabel.
CiliumScheduleAffinity = []string{
"affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].key=" + CiliumNoScheduleLabel,
"affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].operator=NotIn",
"affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].values[0]=true",
}
// CiliumOperatorScheduleAffinity is the node affinity to prevent Cilium from being schedule on
// nodes labeled with CiliumNoScheduleLabel.
CiliumOperatorScheduleAffinity = []string{
"operator.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].key=" + CiliumNoScheduleLabel,
"operator.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].operator=NotIn",
"operator.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].values[0]=true",
}
// SpireAgentScheduleAffinity is the node affinity to prevent the SPIRE agent from being scheduled on
// nodes labeled with CiliumNoScheduleLabel.
SpireAgentScheduleAffinity = []string{
"authentication.mutual.spire.install.agent.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].key=" + CiliumNoScheduleLabel,
"authentication.mutual.spire.install.agent.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].operator=NotIn",
"authentication.mutual.spire.install.agent.affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].values[0]=true",
}
ExpectedDropReasons = []string{
"Policy denied",
"Policy denied by denylist",
"Unsupported L2 protocol",
"Unsupported L3 protocol",
"Stale or unroutable IP",
"Authentication required",
"Service backend not found",
"Unsupported protocol for NAT masquerade",
"Invalid source ip",
"Unknown L3 target address",
"No tunnel/encapsulation endpoint (datapath BUG!)",
"Host datapath not ready",
"Unknown ICMPv4 code",
"Forbidden ICMPv6 message",
}
ExpectedXFRMErrors = []string{
"inbound_forward_header", // XfrmFwdHdrError
"inbound_other", // XfrmInError
"inbound_state_invalid", // XfrmInStateInvalid
}
// The following variables are set at compile time via LDFLAGS.
// CLIVersion is the software version of the Cilium CLI.
CLIVersion string
)