Skip to content

Commit

Permalink
feat(charts): import the oz-charts repo for singular releases (#318)
Browse files Browse the repository at this point in the history
I'll be working on deprecating the https://github.com/diranged/oz-charts
repo.

---------

Co-authored-by: Matt Wise <[email protected]>
  • Loading branch information
diranged and diranged authored Dec 3, 2024
1 parent 5b40e86 commit d5dd126
Show file tree
Hide file tree
Showing 34 changed files with 1,283 additions and 0 deletions.
10 changes: 10 additions & 0 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -52,3 +52,13 @@ jobs:
uses: ./.github/workflows/publish.yaml
with:
publish: false

helm-docs:
needs: build
if: needs.detect-noop.outputs.noop != 'true'
uses: ./.github/workflows/helm-docs.yaml

helm-test:
needs: build
if: needs.detect-noop.outputs.noop != 'true'
uses: ./.github/workflows/helm-test.yaml
15 changes: 15 additions & 0 deletions .github/workflows/helm-docs.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
name: Helm-Docs
on:
workflow_call: {}
jobs:
helm-docs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v1

- name: Set up Go
uses: actions/setup-go@v3

- name: Run helm-docs
run: make helm-docs
39 changes: 39 additions & 0 deletions .github/workflows/helm-release.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
name: Helm Chart Release

on:
workflow_call: {}

jobs:
release:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v2
with:
fetch-depth: 0

- name: Configure Git
run: |
git config user.name "$GITHUB_ACTOR"
git config user.email "[email protected]"
- name: Update Helm Chart version
run: |
NEW_VERSION="${{ github.event.release.tag_name }}"
sed -i "s/^version:.*/version: $NEW_VERSION/" charts/oz/Chart.yaml
sed -i "s/^appVersion:.*/appVersion: $NEW_VERSION/" charts/oz/Chart.yaml
make helm-docs
- name: Install Helm
uses: azure/setup-helm@v3
with:
version: 3.10.2

- name: Run chart-releaser
uses: helm/[email protected]
with:
charts_dir: charts
env:
CR_SKIP_EXISTING: "true"
CR_TOKEN: "${{ secrets.GITHUB_TOKEN }}"
CR_RELEASE_NAME_TEMPLATE: "oz-chart-{{ .Version }}"
46 changes: 46 additions & 0 deletions .github/workflows/helm-test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
name: Chart Test
on:
workflow_call: {}
jobs:
helm-test:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v1

- name: Set up Helm
uses: azure/setup-helm@v3
with:
version: 3.10.2

- uses: actions/setup-python@v4
with:
python-version: 3.7

- name: Set up chart-testing
uses: helm/[email protected]

- name: Run chart-testing (list-changed)
id: list-changed
run: |
changed=$(ct --config ct.yaml list-changed)
if [[ -n "$changed" ]]; then
echo "changed=true" >> ${GITHUB_OUTPUT}
fi
- name: Run chart-testing (lint)
run: ct --config ct.yaml lint

- name: Create kind cluster
if: steps.list-changed.outputs.changed == 'true'
uses: helm/[email protected]

- name: Install cert-manager
if: steps.list-changed.outputs.changed == 'true'
run: |
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.10.1/cert-manager.yaml
kubectl wait deployment -l app.kubernetes.io/instance=cert-manager -n cert-manager --for=condition=Available=True
- name: Run chart-testing (install)
if: steps.list-changed.outputs.changed == 'true'
run: ct --config ct.yaml install
4 changes: 4 additions & 0 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,7 @@ jobs:
uses: ./.github/workflows/publish.yaml
with:
publish: true

helm-publish:
needs: publish
uses: ./.github/workflows/helm-release.yaml
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -30,3 +30,6 @@ dist
*.swp
*.swo
*~

# chart releaser
.cr-release-packages
17 changes: 17 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# Tool Binaries
HELM_DOCS_VER ?= v1.11.0
HELM_DOCS ?= $(LOCALBIN)/helm-docs

# VERSION defines the project version for the bundle.
# Update this value when you upgrade the version of your project.
# To re-generate a bundle for another specific version without changing the standard setup, you can:
Expand Down Expand Up @@ -64,6 +68,19 @@ SHELL = /usr/bin/env bash -o pipefail
.PHONY: all
all: build

##@ Docs
LOCALBIN ?= $(shell pwd)/bin
$(LOCALBIN):
mkdir -p $(@)

$(HELM_DOCS): $(LOCALBIN) Makefile
GO111MODULE=on GOBIN=$(LOCALBIN) go install github.com/norwoodj/helm-docs/cmd/helm-docs@$(HELM_DOCS_VER)

.PHONY: helm-docs
helm-docs: $(HELM_DOCS)
$(HELM_DOCS)
git diff --exit-code

##@ General

# The help target prints out all targets with their descriptions organized
Expand Down
25 changes: 25 additions & 0 deletions charts/oz/.helmignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/
new
orig
18 changes: 18 additions & 0 deletions charts/oz/Chart.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
apiVersion: v2
name: oz
description: Installation for the Oz RBAC Controller
version: 0.0.0
appVersion: latest
kubeVersion: ">=1.26.0-0"
home: https://github.com/diranged/oz
sources:
- https://github.com/diranged/oz
keywords:
- rbac
- kubernetes
- oz
- exec
- kubectl
maintainers:
- name: diranged
url: https://github.com/diranged
61 changes: 61 additions & 0 deletions charts/oz/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# oz

![Version: 0.0.0](https://img.shields.io/badge/Version-0.0.0-informational?style=flat-square) ![AppVersion: latest](https://img.shields.io/badge/AppVersion-latest-informational?style=flat-square)

Installation for the Oz RBAC Controller

**Homepage:** <https://github.com/diranged/oz>

## Maintainers

| Name | Email | Url |
| ---- | ------ | --- |
| diranged | | <https://github.com/diranged> |

## Source Code

* <https://github.com/diranged/oz>

## Requirements

Kubernetes: `>=1.26.0-0`

## Values

| Key | Type | Default | Description |
|-----|------|---------|-------------|
| controllerManager.kubeRbacProxy.image.repository | string | `"gcr.io/kubebuilder/kube-rbac-proxy"` | |
| controllerManager.kubeRbacProxy.image.tag | string | `"v0.13.0"` | |
| controllerManager.kubeRbacProxy.resources.limits.cpu | string | `"500m"` | |
| controllerManager.kubeRbacProxy.resources.limits.memory | string | `"128Mi"` | |
| controllerManager.kubeRbacProxy.resources.requests.cpu | string | `"5m"` | |
| controllerManager.kubeRbacProxy.resources.requests.memory | string | `"64Mi"` | |
| controllerManager.manager.image.repository | `string` | `"ghcr.io/diranged/oz"` | Docker Image repository and name to use for the controller. |
| controllerManager.manager.image.tag | `string` | `nil` | If set, overrides the .Chart.AppVersion field to set the target image version for the Oz controller. |
| controllerManager.manager.resources.limits.cpu | string | `"500m"` | |
| controllerManager.manager.resources.limits.memory | string | `"128Mi"` | |
| controllerManager.manager.resources.requests.cpu | string | `"10m"` | |
| controllerManager.manager.resources.requests.memory | string | `"64Mi"` | |
| controllerManager.nodeSelector | `map` | `nil` | A nodeSepector to apply to the controller-manager pods. See https://kubernetes.io/docs/tasks/configure-pod-container/assign-pods-nodes/. |
| controllerManager.replicas | `int` | `1` | Number of Oz Controllers to run. If more than one is used, leader-election is used to ensure only one controller is operating at a time. |
| controllerManager.tolerations | `[]map]` | `[]` | A list of Tolerations that will be applied to the controller-manager pods. See https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/. |
| kubernetesClusterDomain | `string` | `"cluster.local"` | Configures the KUBERNETES_CLUSTER_DOMAIN environment variable. |
| metricsService.ports[0].name | string | `"https"` | |
| metricsService.ports[0].port | int | `8443` | |
| metricsService.ports[0].protocol | string | `"TCP"` | |
| metricsService.ports[0].targetPort | string | `"https"` | |
| metricsService.type | string | `"ClusterIP"` | |
| rbac.create | `bool` | `true` | If true, the chart will create aggregated roles for accessing the access templates and access request resources. |
| rbac.requestAccess.aggregateTo | `map` | `{"rbac.authorization.k8s.io/aggregate-to-admin":"true","rbac.authorization.k8s.io/aggregate-to-edit":"true"}` | These labels are applied to the "request-access" ClusterRole and are intended to grant developers the permission to make an Access Request. These can be fairly widely granted because the true permissions for who has access to use an Access Request are defined in the Access Template resouces themselves. |
| rbac.templateManager.aggregateTo | `map` | `{"rbac.authorization.k8s.io/aggregate-to-admin":"true","rbac.authorization.k8s.io/aggregate-to-edit":"true"}` | These labels are applied to the "template-manager" ClusterRole and are used to define how to aggregate up the privileges for managing Access Templates. |
| rbac.viewAccess.aggregateTo | `map` | `{"rbac.authorization.k8s.io/aggregate-to-admin":"true","rbac.authorization.k8s.io/aggregate-to-edit":"true","rbac.authorization.k8s.io/aggregate-to-view":"true"}` | These labels are applied to the "view-access" ClusterRole and are used to define how to aggregate up the privileges to your RBAC system. The default settings here are reasonably sane. |
| webhook.certManager | `bool` | `true` | By default, use the [Cert-Manager](https://cert-manager.io) to manage `Certificate` and `Issuer` resouces, which will ultimately populate the `Secret` for the manager service. If you disable this, you must populate the `Secret` yourself. |
| webhook.create | `bool` | `true` | Whether or not to create the `Certificate` and `ValidatingWebhookConfiguration` and `MutatingWebhookConfiguration` resources or not. If not, significant audit and granular permissions functionality of *Oz* will be lost. |
| webhook.podExecWatcher.create | `bool` | `true` | Whether or not to create the webhook configuration. |
| webhook.podExecWatcher.failurePolicy | `string` | `"Fail"` | Either `Fail` or `Ignore`. Defines what happens to an `Exec` request if the Webhook endpoint fails to respond. |
| webhook.secret.name | `string` | `"oz-serving-cert"` | Configures the name of a Secret (type: `kubernetes.io/tls`) within the Namespace that holds a valid private key, certificate and CA bundle. The default behavior is for this to be created by a third party plugin (https://cert-manager.io/) that is extremely common and considered the defacto standard for certificate management within Kubernetes. |
| webhookService.ports[0].name | string | `"https"` | |
| webhookService.ports[0].port | int | `443` | |
| webhookService.ports[0].protocol | string | `"TCP"` | |
| webhookService.ports[0].targetPort | string | `"webhook-server"` | |
| webhookService.type | string | `"ClusterIP"` | |
16 changes: 16 additions & 0 deletions charts/oz/README.md.gotmpl
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{{ template "chart.header" . }}
{{ template "chart.deprecationWarning" . }}

{{ template "chart.badgesSection" . }}

{{ template "chart.description" . }}

{{ template "chart.homepageLine" . }}

{{ template "chart.maintainersSection" . }}

{{ template "chart.sourcesSection" . }}

{{ template "chart.requirementsSection" . }}

{{ template "chart.valuesSection" . }}
1 change: 1 addition & 0 deletions charts/oz/crds/crds.wizardofoz.co_execaccessrequests.yaml
1 change: 1 addition & 0 deletions charts/oz/crds/crds.wizardofoz.co_execaccesstemplates.yaml
1 change: 1 addition & 0 deletions charts/oz/crds/crds.wizardofoz.co_podaccessrequests.yaml
1 change: 1 addition & 0 deletions charts/oz/crds/crds.wizardofoz.co_podaccesstemplates.yaml
64 changes: 64 additions & 0 deletions charts/oz/templates/_helpers.tpl
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "oz.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}

{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "oz.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}

{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "oz.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}

{{/*
Common labels
*/}}
{{- define "oz.labels" -}}
helm.sh/chart: {{ include "oz.chart" . }}
app.kubernetes.io/created-by: oz
app.kubernetes.io/part-of: oz
{{ include "oz.selectorLabels" . }}
{{- with .Chart.Version }}
app.kubernetes.io/version: {{ . | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}

{{/*
Selector labels
*/}}
{{- define "oz.selectorLabels" -}}
app.kubernetes.io/name: {{ include "oz.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

{{/*
Create the name of the service account to use
*/}}
{{- define "oz.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "oz.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}
Loading

0 comments on commit d5dd126

Please sign in to comment.