-
Notifications
You must be signed in to change notification settings - Fork 104
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Generate KUDO Manifests #1582
Merged
Merged
Generate KUDO Manifests #1582
Changes from 2 commits
Commits
Show all changes
9 commits
Select commit
Hold shift + click to select a range
58b8576
Generate KUDO Manifests
kensipe ec6b69e
correcting webhook replacement
kensipe 6b6bd42
No need for secrets and service. These manifests are solely to help …
kensipe 2dab072
adding readme to the manifest dir
kensipe 304dce1
cleaning up whitespace
kensipe 462434f
shellcheck issues resolved
kensipe 7b01acf
removing manifests from git repo moved to manifest cache
kensipe 60e243d
adding updates for webhook
kensipe d60c380
adding make targets for quick and easy local dev and debugging
kensipe File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -2,6 +2,7 @@ | |
bin/ | ||
vendor/ | ||
hack/code-gen | ||
hack/manifest-gen | ||
hack/controller-gen | ||
test/.git-credentials | ||
reports/ | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
apiVersion: v1 | ||
kind: Service | ||
metadata: | ||
creationTimestamp: null | ||
labels: | ||
app: kudo-manager | ||
control-plane: controller-manager | ||
name: kudo-controller-manager-service | ||
namespace: kudo-system | ||
spec: | ||
ports: | ||
- name: kudo | ||
port: 443 | ||
targetPort: webhook-server | ||
selector: | ||
app: kudo-manager | ||
control-plane: controller-manager | ||
status: | ||
loadBalancer: {} | ||
|
23 changes: 23 additions & 0 deletions
23
config/manifests/kudo-manager-instance-admission-webhook-config.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
apiVersion: admissionregistration.k8s.io/v1beta1 | ||
kind: MutatingWebhookConfiguration | ||
metadata: | ||
creationTimestamp: null | ||
name: kudo-manager-instance-admission-webhook-config | ||
webhooks: | ||
- clientConfig: | ||
url: https://replace-url.com | ||
failurePolicy: Fail | ||
matchPolicy: Equivalent | ||
name: instance-admission.kudo.dev | ||
rules: | ||
- apiGroups: | ||
- kudo.dev | ||
apiVersions: | ||
- v1beta1 | ||
operations: | ||
- CREATE | ||
- UPDATE | ||
resources: | ||
- instances | ||
scope: Namespaced | ||
sideEffects: None |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,14 @@ | ||
apiVersion: rbac.authorization.k8s.io/v1 | ||
kind: ClusterRoleBinding | ||
metadata: | ||
creationTimestamp: null | ||
name: kudo-manager-rolebinding | ||
roleRef: | ||
apiGroup: rbac.authorization.k8s.io | ||
kind: ClusterRole | ||
name: cluster-admin | ||
subjects: | ||
- kind: ServiceAccount | ||
name: kudo-manager | ||
namespace: kudo-system | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,9 @@ | ||
apiVersion: v1 | ||
kind: ServiceAccount | ||
metadata: | ||
creationTimestamp: null | ||
labels: | ||
app: kudo-manager | ||
name: kudo-manager | ||
namespace: kudo-system | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,10 @@ | ||
apiVersion: v1 | ||
kind: Namespace | ||
metadata: | ||
creationTimestamp: null | ||
labels: | ||
app: kudo-manager | ||
name: kudo-system | ||
spec: {} | ||
status: {} | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,11 @@ | ||
apiVersion: v1 | ||
data: | ||
tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURwRENDQW95Z0F3SUJBZ0lCQVRBTkJna3Foa2lHOXcwQkFRc0ZBREE2TVRnd05nWURWUVFERXk5cmRXUnYKTFdOdmJuUnliMnhzWlhJdGJXRnVZV2RsY2kxelpYSjJhV05sTG10MVpHOHRjM2x6ZEdWdExuTjJZekFlRncweQpNREEzTURrd01USTBNalZhRncweU1EQTNNVFl3TVRJME1qVmFNRG94T0RBMkJnTlZCQU1UTDJ0MVpHOHRZMjl1CmRISnZiR3hsY2kxdFlXNWhaMlZ5TFhObGNuWnBZMlV1YTNWa2J5MXplWE4wWlcwdWMzWmpNSUlCSWpBTkJna3EKaGtpRzl3MEJBUUVGQUFPQ0FROEFNSUlCQ2dLQ0FRRUF1dUROUUV3aXNYRnlUR3RCZkcwZ0N6QUNFeS90OEtJbQo2TFp3K3ZWQnFCMVh5am81SVRVTUNPeU0yRmlhTDA2UUdSWDY2QzR4c1ltSkNpYXhaa0ZtWGN4VHdGZHlYZ1BlCklMK0U4VkdLWU03US95am1wYWVKOXFrWnJQNW85bTdFN1dSeWFPc1g1S2VpSHljNlpzUzZqaFhxdFVNVmpxL1kKTjNwYlIxVWpPYjRPTVFGOFJkc3ZMTEtBL1RLbUgwbWdPcEFuZmVMWWJ5ZzBKMjllam96V0Vmb25LUGhDRVZNagpnaEVZK1JHdlpTbUNiQTVCeXlMeFh6MVM0M0YvYUswaTdnR0xRM1NBaVpVNWlnY003S1lTMlR0ckRWS2YvQ3N6Ck1Yb0VnRVBuZTFic0VLVGtFeFNMTFVXWitMWE9iMlBwNklvN1JwM1FNakRqM1pNSHMxNlZad0lEQVFBQm80RzAKTUlHeE1BNEdBMVVkRHdFQi93UUVBd0lGb0RBVEJnTlZIU1VFRERBS0JnZ3JCZ0VGQlFjREFUQ0JpUVlEVlIwUgpCSUdCTUgrQ0gydDFaRzh0WTI5dWRISnZiR3hsY2kxdFlXNWhaMlZ5TFhObGNuWnBZMldDSzJ0MVpHOHRZMjl1CmRISnZiR3hsY2kxdFlXNWhaMlZ5TFhObGNuWnBZMlV1YTNWa2J5MXplWE4wWlcyQ0wydDFaRzh0WTI5dWRISnYKYkd4bGNpMXRZVzVoWjJWeUxYTmxjblpwWTJVdWEzVmtieTF6ZVhOMFpXMHVjM1pqTUEwR0NTcUdTSWIzRFFFQgpDd1VBQTRJQkFRQXdoMTFKNnBTeERnZ3ViM2h1bGRFZjF3QTVraGtNVHR0MnJ5M0FBTVdJMGhQSExHT1hHYmFBCndrbEJYazFJdUJZeHFYN3BSbWVjWGthSVRUelZYMzFTNEhjUEQvM01QUkh4UUI3cnpSb0wxRzh0eWRQUDJkRnQKUVZ2RWRQMkFOdW5xd2I0eDJ6TzF6NEFPM1RZQzZLWnJPcEJYVlROaWFKbVhiWGRHRkFOZjlOYXFnMG9uUjNZbgphYVl6NjlacUg5NENCWmE5aUpmUWZxbE5uSkNYaExEUUZ0Yzc3blFLWFlGYktXMWZybTRiYXFpRnRmdHFkWEw5Cmxhc3dscTlKVmhYdzI4b2t5aEx5MzAzRm5STlRDWEdtaGo2YktxcDlZc2NRaDRxczIwY2Nlb3YzQ2VFRmN1TysKY2txcTc0NE9ZOWViaUhlMHpXenNxZTNRZWFvUi94REwKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= | ||
tls.key: LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUV2Z0lCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQktnd2dnU2tBZ0VBQW9JQkFRQzY0TTFBVENLeGNYSk0KYTBGOGJTQUxNQUlUTCszd29pYm90bkQ2OVVHb0hWZktPamtoTlF3STdJellXSm92VHBBWkZmcm9Makd4aVlrSwpKckZtUVdaZHpGUEFWM0plQTk0Z3Y0VHhVWXBnenREL0tPYWxwNG4ycVJtcy9tajJic1R0WkhKbzZ4ZmtwNklmCkp6cG14THFPRmVxMVF4V09yOWczZWx0SFZTTTV2ZzR4QVh4RjJ5OHNzb0Q5TXFZZlNhQTZrQ2Q5NHRodktEUW4KYjE2T2pOWVIraWNvK0VJUlV5T0NFUmo1RWE5bEtZSnNEa0hMSXZGZlBWTGpjWDlvclNMdUFZdERkSUNKbFRtSwpCd3pzcGhMWk8yc05VcC84S3pNeGVnU0FRK2Q3VnV3UXBPUVRGSXN0UlpuNHRjNXZZK25vaWp0R25kQXlNT1BkCmt3ZXpYcFZuQWdNQkFBRUNnZ0VCQUxJZVRHUEpiWlBWUG8wSitjdmZzeGdXdFJPV3JtS2FHeDNacm92ME1aVk0KQ240TXlxRVZENWg5NXF6YW5uTVNuWlBiZUYvT2o3elpDMDRxblJHS3FrZ2kxWHpSbklkeGhrbU9ZZWNrd2hFTgpidlNWQm1uRDYySzN3R283dnMyTHZKVk1GU1JkVjFPd1YzejhCZFVvRTJ3VUJiYW83eVltQXA2Mk44UWdxTWVCCjludmdzVGNoQWh6RU92NXk2NG5Vd2duZ2JHdi9LNUVwQUZIcEZTbjRndVAvVSszeGJHZUU5cUFKY09IeU9JRDAKc2lzZ2pFUmVuSFpJSW4renRJYnFkQm1GTGV0TWRiWGVCSldoWEZJaGUzc1BjbWIrWVEzbXlYeWp0T1VYYmV5cgpIVnhvSVl6L3pJRjVWRXBmSmRLMEFkbHVzdjlLME9uQ0FaWVJjMysvYTRrQ2dZRUEwa0hkNnV6QTJOa2tuZGdFCk0zck1pS1dieGF0MTlPTWRtWCtwa1d1SXo5TkFXZy82MzN5M1g4ZndXZE1FY0pYTG8zclE4cjZvR014THN5Tm8KN0hWUzZOQjBodjNGR3hrNlJ3RllTc1cyT2VKTS9qRkVhUVdodDBEalRrckd4OGhGeURzYVhITDlMdU5uWmlRbgpDbFp5NGhnZzljY1h2VCtzUjlhTzFNWnFFaXNDZ1lFQTQ0alpUM1RXMTJZbGxTS3dwWWcybWhzWkhqWHZBZVhNCnlaNDY3UnB2YXF2eHg3TDFDaDU1UFd2OVUxQU9BNVNyaW84bDRKRTNTRDJkYWNTZmJGSlZxVlM2cVdVSURPOVQKWGlnV0NCTS8zMWJjUmFELy8xMUtSMVVULzZCcWdtSEY1QnlaZGNYTVdPc3JXcFMyYjh2TjJrT0w1VzRYSU5OdQp5ZXQ0dTB1cHQ3VUNnWUVBeXkwL0oxODFVOWN4blI0N29RdVBUcFRLSEkvOTRuRCtEM0RnQ1ZoaTBvR1BjL2h4Ck16bXZjZTBoZzR0NGhOc2I5NVFkQ2hYWEZtK0V6MHp1ZldFNmh5TzVGeUZ2TVNxRnVFdkNhQzc2VXFFdVNZeU8KVVBaU09XV0l3Z1ZjWlg1UWdKY3NlQjNlTDBzc2hmVjFqSFhSZWs1YXUyWnl1RHdwWFJvbTE5SU1laFVDZ1lCNQpQS25OMUl2RktnQk1mcmR3L0N0YjRhUjRuSFJGcHBSL3VYZmNib0YvYlM3ZklWTy9tSTB4VlNFZUMwSHNWb013CnlTVjlpdUxSODBLMDRMZXhtQTFjdEhEaFladndpSFQ3YnBDT3JQTVRwY3lvclNpNmdKTGJmMUd3bTJFbEo4T3gKMEN0VXZaZ3NxT0hvMmVSN25UU0tZQU5pdEU1T2gxbzQ3T2JmcFdsQklRS0JnQWY1SGM1Y1M4aU1zZkJRQ2FXdgpZRDd6YlRucGJ3Tjh2RktCdFRVZ1RJNjZKSGp3anpoYVpCUlBXRGZzM1M5eWhZUHNmODRsL01TZER6SWh0QTcvCmlkSTdYcVBPZEtzb3Ixd3NLTE92b2dhWTh0NmNRbmZ5U2lvalMvVGxoS1I0QVVLM0lmZzVQRElmS2JUd1FBeGMKUE5qTGxnTXIxYnlPOHo4cStVNW82SlFFCi0tLS0tRU5EIFBSSVZBVEUgS0VZLS0tLS0K | ||
kind: Secret | ||
metadata: | ||
creationTimestamp: null | ||
name: kudo-webhook-server-secret | ||
namespace: kudo-system | ||
type: kubernetes.io/tls | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,71 @@ | ||
#!/usr/bin/env bash | ||
kensipe marked this conversation as resolved.
Show resolved
Hide resolved
|
||
|
||
if ! command -v yq &> /dev/null | ||
then | ||
echo "required yq command NOT found" | ||
exit 1 | ||
fi | ||
|
||
if ! command -v awk &> /dev/null | ||
then | ||
echo "required awk command NOT found" | ||
exit 1 | ||
fi | ||
|
||
# hack/manifest-gen is the build folder | ||
mkdir -p hack/manifest-gen | ||
mkdir -p config/manifests | ||
|
||
# gen manifests to hack/manifest-gen/manifests.yaml | ||
go run cmd/kubectl-kudo/main.go init --dry-run --version dev --unsafe-self-signed-webhook-ca -o yaml > hack/manifest-gen/manifests.yaml | ||
|
||
cd hack/manifest-gen/ | ||
|
||
# separate the manifests | ||
awk 'BEGIN{file = 0; filename = "output_" file ".txt"} | ||
/---$/ {getline; file ++; filename = "output_" file ".txt"} | ||
{print $0 > filename}' manifests.yaml | ||
cd - | ||
|
||
# loop through all the files | ||
for f in hack/manifest-gen/*.txt; | ||
do | ||
KIND=`yq r $f kind` | ||
|
||
case "$KIND" in | ||
"CustomResourceDefinition") | ||
NAME=`yq r $f spec.names.kind` | ||
echo "skip '$NAME' crd" | ||
continue;; | ||
|
||
"StatefulSet") | ||
echo "skipping statefulset" | ||
continue;; | ||
"Namespace") | ||
KIND=ns;; | ||
"ServiceAccount") | ||
KIND=sa;; | ||
*) | ||
KIND="";; | ||
esac | ||
|
||
NAME=`yq r $f metadata.name` | ||
|
||
if [ ! -z "$KIND" ] | ||
then | ||
NAME="$NAME-$KIND" | ||
fi | ||
NAME="$NAME.yaml" | ||
|
||
echo "Working with $NAME" | ||
|
||
cp $f config/manifests/$NAME | ||
done | ||
|
||
# update webhook (add config.url and remove config.caBundle and config.service) | ||
yq w -i config/manifests/kudo-manager-instance-admission-webhook-config.yaml webhooks[0].clientConfig.url https://replace-url.com | ||
yq d -i config/manifests/kudo-manager-instance-admission-webhook-config.yaml webhooks[0].clientConfig.caBundle | ||
yq d -i config/manifests/kudo-manager-instance-admission-webhook-config.yaml webhooks[0].clientConfig.service | ||
|
||
rm -rf hack/manifest-gen | ||
echo "Finished" |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This target makes a lot of sense to me but why do we need to commit the manifests as part of the repo? We should have only one source of truth and that's
kudo init
for now.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this is exactly consistent with our CRD generation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
if anything, I'd like to get rid of the
config/crds
folder altogether. we only need for tests but once we have abeforeAll
step in kuttl, we could remove the in favor ofkudo init
call. I'd rather not add new manifests thereThere was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I mostly agree - things that can be generated shouldn't be checked in usually.
I'm ok with having them checked in, especially the CRDs, as the controller-gen step takes quite a while. Would be nicer to not have them checked in though.